Sep 2026· International Conference on Automated Software Engineering· Vol 33· 0 citations· 64 references
TL;DR
SE4SC-LLM, an LLM-augmented symbolic execution framework for smart contracts that achieves 95.1% average CFG coverage, a 6.5 percentage point improvement over the strongest baseline, and detects 11.2% more vulnerabilities.
As Solidity smart contracts become central to decentralized finance and governance, the exploitation of critical vulnerabilities has repeatedly resulted in severe financial losses. Existing state-of-the-art methods that rely on symbolic execution or syntactic patterns are unable to model the language semantics accurate...
The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in decentralized applications. However, the increasing complexity and financial value of these contracts make them prime targets for cyber attacks. In this work, we present a transform...
Djamel Eddine Hakim Ghorab, Farid Mokhati, Mostafa Anouar Ghorab· International Joint Conferen...· 0 citations
Security testing of REST APIs remains difficult because real-world OpenAPI specifications are often incomplete, many flaws are inherently stateful, and prevailing stateful fuzzers optimize for structural exploration rather than OWASP-aligned risk. This paper presents APIGFUZZ, a graph-driven, OWASP-aware black-box REST...
K. Ngo, Long Huynh Pham Trieu, Van Nguyen Truong et al.· International Conference on...· 0 citations
A unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network for detection with Large Language Models for explanation form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.
Large language models (LLMs) are increasingly used in software pipelines, raising concerns about harmful behaviors in security-critical domains. Existing safety evaluations predominantly probe models with single prompts or short interactions, and therefore do not capture how safety behaves under multi-step workflows wh...
Lu Yan, Zhuo Zhang, Xiang-Zhe Xu et al.· Proceedings of the ACM on So...· 0 citations
A lightweight method for generating fuzz test cases under bytecode-level static guidance, and results indicate that static guidance, directed seed generation, and vulnerability-specific oracles each contribute to the final performance.
Shiting Yu, Rundong Wei, Xiaoqi Li· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.