Fine-Tuned Large Language Model for Securing Ethereum Smart Contracts with Real-Time VSCode Auditing
Abstract
• Created a refined, expanded, and precisely labeled dataset with explanations, risk assessments, and fixes for each vulnerability • Fine-tuned an open-source LLM: LLaMA-3.1-8B using parameter-efficient techniques (LoRA) for smart contract vulnerability detection • Fine-tuned GPT-4o-mini on the same corpus for comparative analysis • Developed a real-time Visual Studio Code (VSCode) plugin integrating GPT-4o-mini for smart contract auditing • Released the datasets, tool, and fine-tuned model to advance research in smart contract security Since the advent of Ethereum, ensuring the security of smart contracts has become imperative. Integer overflow and underflow, reentrancy, and timestamp dependency remain the three most prevalent vulnerabilities in deployed contracts. Existing static-analysis tools often yield insufficient accuracy, and datasets derived from them inherit the same shortcomings. Moreover, the smart contract ecosystem lacks a dependable, real-time auditing aid for developers and a fine-tuned model trained on a truly comprehensive corpus. In this paper, we present three main contributions. (1) Dataset curation: the state-of-the-art vulnerability datasets are aggregated and harmonized, producing a clean, fully labeled dataset that integrates detailed explanations, potential security risks, vulnerable line ranges, code snippets, and corresponding fixes. The dataset is publicly available via our GitHub repository. (2) Model fine-tuning: the LLaMA-3.1-8B model as well as GPT-4o-mini are fine-tuned on this corpus and evaluated with both standard classification metrics and text-quality measures. The fine-tuned LLaMA-3.1 model achieves a precision of 93.55%, an average semantic similarity of 77.48%, and a code similarity of 87.25%. (3) IDE integration: We implement a real-time Visual Studio Code extension, backed by the GPT-4o API, that highlights, explains, and automatically patches vulnerabilities as the developer writes. Together, these contributions deliver a rigorously validated model and a practical developer toolchain that markedly advance the state of smart contract security research and practice.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.