BRLF: Using Conditional Branch Embedding and DRL for Fuzzing Ethereum Smart Contracts
Abstract
Smart contracts (SCs) implemented on blockchain represent a breakthrough in decentralized applications, enabling a range of functions such as managing supply chains and handling elections. As the adoption of SCs increases, the need to detect flaws and vulnerabilities in their execution grows. To address this challenge, we present Branch Reinforcement Learning Fuzzer (BRLF), a deep reinforcement learning-based solution for the detection of vulnerabilities in SCs. The novelty of our method is threefold: first, our deep model uses text-based embeddings of conditional branches to enhance its adaptability and flexibility. Secondly, we propose a reward function that considers multiple aspects of fuzzing, such as opcode analysis and gas usage. Finally, we incorporate evolutionary algorithms into our approach, which significantly bolsters its ability to produce varied outputs. Extensive evaluation on three datasets of Ethereum-based SCs shows that BRLF outperforms state-of-the-art methods, detecting more vulnerabilities and achieving higher code coverage than existing solutions. Our code and data are available at: https://zenodo.org/records/15022152
Community
0 commentsNo discussion yet
Be the first to share a question or observation.