Combining Fine-Tuning and LLM-Based Agents for Intuitive Smart Contract Auditing with Justifications

审计 计算机科学 智能合约 计算机安全 互联网隐私 人机交互 业务 会计 块链
作者
Wei Ma,Daoyuan Wu,Yuqiang Sun,Tianwen Wang,Shangqing Liu,Jian Zhang,Yue Xue,Yang Liu
标识
DOI:10.1109/icse55347.2025.00027
摘要

Smart contracts are decentralized applications built atop blockchains like Ethereum. Recent research has shown that large language models (LLMs) have potential in auditing smart contracts, but the state-of-the-art indicates that even GPT-4 can achieve only 30% precision (when both decision and justification are correct). This is likely because off-the-shelf LLMs were primarily pre-trained on a general text/code corpus and not fine-tuned on the specific domain of Solidity smart contract auditing. In this paper, we propose iAudit, a general framework that combines fine-tuning and LLM-based agents for intuitive smart contract auditing with justifications. Specifically, iAudit is inspired by the observation that expert human auditors first perceive what could be wrong and then perform a detailed analysis of the code to identify the cause. As such, iAudit employs a two-stage fine-tuning approach: it first tunes a Detector model to make decisions and then tunes a Reasoner model to generate causes of vulnerabilities. However, fine-tuning alone faces challenges in accurately identifying the optimal cause of a vulnerability. Therefore, we introduce two LLM-based agents, the Ranker and Critic, to iteratively select and debate the most suitable cause of vulnerability based on the output of the fine-tuned Reasoner model. To evaluate iAudit, we collected a balanced dataset with 1,734 positive and 1,810 negative samples to fine-tune iAudit. We then compared it with traditional fine-tuned models (CodeBERT, GraphCodeBERT, CodeT5, and UnixCoder) as well as prompt learning-based LLMs (GPT4, GPT-3.5, and CodeLlama-13b/34b). On a dataset of 263 real smart contract vulnerabilities, iAudit achieves an F1 score of 91.21% and an accuracy of 91.11%. The causes generated by iAudit achieved a consistency of about 38% compared to the ground truth causes.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
慕青应助xty采纳,获得10
1秒前
无语的书兰完成签到,获得积分10
1秒前
Ava应助安谢采纳,获得10
1秒前
止观完成签到,获得积分10
1秒前
木子李完成签到,获得积分10
2秒前
畔畔发布了新的文献求助30
2秒前
HHH发布了新的文献求助10
2秒前
康康发布了新的文献求助10
2秒前
chenyy完成签到,获得积分10
3秒前
3秒前
4秒前
无花果应助370086320采纳,获得10
4秒前
MRIG给MRIG的求助进行了留言
4秒前
暗部完成签到,获得积分10
5秒前
与你共奋完成签到,获得积分10
5秒前
所所应助liuxinyi010采纳,获得10
5秒前
6秒前
科研小王完成签到,获得积分10
6秒前
7秒前
7秒前
xin发布了新的文献求助10
7秒前
8秒前
谢鹏飞完成签到,获得积分10
8秒前
Shamy完成签到 ,获得积分10
8秒前
早睡早起完成签到,获得积分10
9秒前
chenyy发布了新的文献求助10
9秒前
852应助xiaot采纳,获得10
10秒前
liulu完成签到,获得积分10
10秒前
L050完成签到,获得积分10
10秒前
852应助江月晃重山采纳,获得10
10秒前
10秒前
10秒前
野性的迎海完成签到 ,获得积分10
10秒前
谦谦呆滴完成签到 ,获得积分10
11秒前
赫鲁晓楠发布了新的文献求助10
11秒前
June完成签到 ,获得积分10
11秒前
橙子完成签到,获得积分10
12秒前
13秒前
14秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Principles of town planning: translating concepts to applications 1000
1 Peter and Christ's Descent to the Dead in Its Early Christian Reception 700
Perfectionism in School 600
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7727714
求助须知:如何正确求助?哪些是违规求助? 9280203
关于积分的说明 20136430
捐赠科研通 7305346
什么是DOI,文献DOI怎么找? 3302562
关于科研通互助平台的介绍 2455803
邀请新用户注册赠送积分活动 2310718