GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis
Abstract
Smart contracts are prone to various vulnerabilities, leading to substantial financial losses over time. Current analysis tools mainly target vulnerabilities with fixed control- or data-flow patterns, such as re-entrancy and integer overflow. However, a recent study on Web3 security bugs revealed that about 80% of these bugs cannot be audited by existing tools due to the lack of domain-specific property description and checking. Given recent advances in Large Language Models (LLMs), it is worth exploring how Generative Pre-training Transformer (GPT) could aid in detecting logic vulnerabilities.
BibTeX
@inproceedings{Sun-al:ICSE24,
author = {Yuqiang Sun and
Daoyuan Wu and
Yue Xue and
Han Liu and
Haijun Wang and
Zhengzi Xu and
Xiaofei Xie and
Yang Liu},
title = {{GPTScan:} Detecting Logic Vulnerabilities in Smart Contracts by Combining {GPT} with Program Analysis},
booktitle = {ICSE},
pages = {166:1--166:13},
publisher = {{ACM}},
year = {2024},
}