Validating Solidity Code Defects using Symbolic and Concrete Execution powered by Large Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Susan, Ştefan-Claudiu, Arusoaie, Andrei, Lucanu, Dorel
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915497315926016
author Susan, Ştefan-Claudiu
Arusoaie, Andrei
Lucanu, Dorel
author_facet Susan, Ştefan-Claudiu
Arusoaie, Andrei
Lucanu, Dorel
contents The high rate of false alarms from static analysis tools and Large Language Models (LLMs) complicates vulnerability detection in Solidity Smart Contracts, demanding methods that can formally or empirically prove the presence of defects. This paper introduces a novel detection pipeline that integrates custom Slither-based detectors, LLMs, Kontrol, and Forge. Our approach is designed to reliably detect defects and generate proofs. We currently perform experiments with promising results for seven types of critical defects. We demonstrate the pipeline's efficacy by presenting our findings for three vulnerabilities -- Reentrancy, Complex Fallback, and Faulty Access Control Policies -- that are challenging for current verification solutions, which often generate false alarms or fail to detect them entirely. We highlight the potential of either symbolic or concrete execution in correctly classifying such code faults. By chaining these instruments, our method effectively validates true positives, significantly reducing the manual verification burden. Although we identify potential limitations, such as the inconsistency and the cost of LLMs, our findings establish a robust framework for combining heuristic analysis with formal verification to achieve more reliable and automated smart contract auditing.
format Preprint
id arxiv_https___arxiv_org_abs_2509_13023
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Validating Solidity Code Defects using Symbolic and Concrete Execution powered by Large Language Models
Susan, Ştefan-Claudiu
Arusoaie, Andrei
Lucanu, Dorel
Software Engineering
Artificial Intelligence
I.2.2;D.2.5;D.2.4;D.4.6
The high rate of false alarms from static analysis tools and Large Language Models (LLMs) complicates vulnerability detection in Solidity Smart Contracts, demanding methods that can formally or empirically prove the presence of defects. This paper introduces a novel detection pipeline that integrates custom Slither-based detectors, LLMs, Kontrol, and Forge. Our approach is designed to reliably detect defects and generate proofs. We currently perform experiments with promising results for seven types of critical defects. We demonstrate the pipeline's efficacy by presenting our findings for three vulnerabilities -- Reentrancy, Complex Fallback, and Faulty Access Control Policies -- that are challenging for current verification solutions, which often generate false alarms or fail to detect them entirely. We highlight the potential of either symbolic or concrete execution in correctly classifying such code faults. By chaining these instruments, our method effectively validates true positives, significantly reducing the manual verification burden. Although we identify potential limitations, such as the inconsistency and the cost of LLMs, our findings establish a robust framework for combining heuristic analysis with formal verification to achieve more reliable and automated smart contract auditing.
title Validating Solidity Code Defects using Symbolic and Concrete Execution powered by Large Language Models
topic Software Engineering
Artificial Intelligence
I.2.2;D.2.5;D.2.4;D.4.6
url https://arxiv.org/abs/2509.13023