智能合约与DeFi协议漏洞检测技术综述
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家重点研发计划(2022ZD0116800); 国家自然科学基金(62141605, 62372493); 中国博士后科学基金(373500); 北京市自然科学基金(Z230001); 未来区块链与隐私计算高精尖创新中心建设项目(GJJ-23-001, GJJ-23-002); 北航敢为行动计划(KG16336101)


Survey on Vulnerability Detection Techniques for Smart Contract and DeFi Protocol
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    智能合约作为区块链核心的可编程组件, 承担了资产管理和复杂业务逻辑处理的功能, 它们共同构成了去中心化金融(decentralized finance, DeFi)协议. 然而, 随着区块链的快速发展, 智能合约和DeFi协议的安全问题日益凸显, 吸引了大量攻击者利用其漏洞牟取利益. 近年来, 多起涉及智能合约和DeFi协议的重大安全事件强调了漏洞检测技术研究的必要性, 已成为安全防护的重中之重. 系统性地总结了现有工作, 提出了智能合约与DeFi协议漏洞检测技术研究框架, 分别从智能合约和DeFi协议两个层面对漏洞类型和检测技术进行梳理. 在智能合约方面, 重点分析了大语言模型(large language model, LLM)作为主要检测引擎和与传统方法结合的漏洞检测技术应用情况; 在DeFi协议方面, 系统性地分类并整理了DeFi协议层的漏洞及其检测方法, 并探讨了攻击发生前后检测方法的优势与局限性, 弥补了现有综述在DeFi协议漏洞检测方面的不足. 最后, 对现有检测方法面临的挑战进行总结, 并展望了未来的研究方向, 旨在为智能合约与DeFi协议的安全检测提供新的思路和理论支持.

    Abstract:

    As core programmable components of blockchain, smart contracts are responsible for asset management and the execution of complex business logic, forming the foundation of decentralized finance (DeFi) protocols. However, with the rapid advancement of blockchain technology, security issues related to smart contracts and DeFi protocols have become increasingly prominent, attracting numerous attackers seeking to exploit vulnerabilities for illicit gains. In recent years, several major security incidents involving smart contracts and DeFi protocols have highlighted the importance of vulnerability detection research, making it a critical area for security defense. This study systematically reviews existing literature and proposes a comprehensive framework for research on vulnerability detection in smart contracts and DeFi protocols. Specifically, vulnerabilities and detection techniques are categorized and analyzed for both domains. For smart contracts, the study focuses on the application of large language models (LLM) as primary detection engines and their integration with traditional methods. For DeFi protocols, it categorizes and details various protocol-level vulnerabilities and their detection methods, analyzing the strengths and limitations of detection strategies before and after attacks, addressing gaps in existing reviews on DeFi vulnerability detection. Finally, this study summarizes the challenges faced by current detection approaches and outlines future research directions, aiming to provide new insights and theoretical support for the security detection of smart contracts and DeFi protocols.

    参考文献
    相似文献
    引证文献
引用本文

揭晚晴,邱望洁,黄鑫鹏,杨浩甫,赵冠球,张沁楠,夏清,郑宏威,郑志明.智能合约与DeFi协议漏洞检测技术综述.软件学报,2026,37(1):344-377

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-11-13
  • 最后修改日期:2024-12-26
  • 录用日期:
  • 在线发布日期: 2025-09-24
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号