Vulnerability Detection in Ethereum Smart Contracts via Machine Learning: A Qualitative Analysis

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ressi, Dalila, Spanò, Alvise, Benetollo, Lorenzo, Piazza, Carla, Bugliesi, Michele, Rossi, Sabina
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914063044313088
author Ressi, Dalila
Spanò, Alvise
Benetollo, Lorenzo
Piazza, Carla
Bugliesi, Michele
Rossi, Sabina
author_facet Ressi, Dalila
Spanò, Alvise
Benetollo, Lorenzo
Piazza, Carla
Bugliesi, Michele
Rossi, Sabina
contents Smart contracts are central to a myriad of critical blockchain applications, from financial transactions to supply chain management. However, their adoption is hindered by security vulnerabilities that can result in significant financial losses. Most vulnerability detection tools and methods available nowadays leverage either static analysis methods or machine learning. Unfortunately, as valuable as they are, both approaches suffer from limitations that make them only partially effective. In this survey, we analyze the state of the art in machine-learning vulnerability detection for Ethereum smart contracts, by categorizing existing tools and methodologies, evaluating them, and highlighting their limitations. Our critical assessment unveils issues such as restricted vulnerability coverage and dataset construction flaws, providing us with new metrics to overcome the difficulties that restrain a sound comparison of existing solutions. Driven by our findings, we discuss best practices to enhance the accuracy, scope, and efficiency of vulnerability detection in smart contracts. Our guidelines address the known flaws while at the same time opening new avenues for research and development. By shedding light on current challenges and offering novel directions for improvement, we contribute to the advancement of secure smart contract development and blockchain technology as a whole.
format Preprint
id arxiv_https___arxiv_org_abs_2407_18639
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Vulnerability Detection in Ethereum Smart Contracts via Machine Learning: A Qualitative Analysis
Ressi, Dalila
Spanò, Alvise
Benetollo, Lorenzo
Piazza, Carla
Bugliesi, Michele
Rossi, Sabina
Cryptography and Security
Machine Learning
Smart contracts are central to a myriad of critical blockchain applications, from financial transactions to supply chain management. However, their adoption is hindered by security vulnerabilities that can result in significant financial losses. Most vulnerability detection tools and methods available nowadays leverage either static analysis methods or machine learning. Unfortunately, as valuable as they are, both approaches suffer from limitations that make them only partially effective. In this survey, we analyze the state of the art in machine-learning vulnerability detection for Ethereum smart contracts, by categorizing existing tools and methodologies, evaluating them, and highlighting their limitations. Our critical assessment unveils issues such as restricted vulnerability coverage and dataset construction flaws, providing us with new metrics to overcome the difficulties that restrain a sound comparison of existing solutions. Driven by our findings, we discuss best practices to enhance the accuracy, scope, and efficiency of vulnerability detection in smart contracts. Our guidelines address the known flaws while at the same time opening new avenues for research and development. By shedding light on current challenges and offering novel directions for improvement, we contribute to the advancement of secure smart contract development and blockchain technology as a whole.
title Vulnerability Detection in Ethereum Smart Contracts via Machine Learning: A Qualitative Analysis
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2407.18639