Semi-Supervised and Transfer Learning-Based Smart Contract Vulnerability Detection
Abstract
Smart contracts are crucial for managing sensitive financial transactions. However, these contracts are inherently vulnerable which can cause significant security risks. Traditional methods for detecting smart contract vulnerabilities depend on expert-defined rules, which are often complicated and limited by human experts' individual experience. In contrast, deep learning-based approaches automatically extract intricate feature representations, greatly improving detection efficiency and accuracy. Nevertheless, these approaches rely on access to large amounts of high-quality labeled data. They are less effective when facing new types of vulnerabilities where labeled data are scarce. To this end, we propose the Semi-supervised Tuning (SST) approach for smart contract vulnerability detection. It first leverages a source model trained on labeled source data to extract features for new vulnerabilities. Subsequently, it performs semi-supervised learning to explore the feature structure of unlabeled data. In particular, SST groups contract code features and constructs a shared feature queue containing labeled and unlabeled contracts to explore the complete feature structure and guide model training. Extensive experimental evaluations based on two real-world datasets containing eleven smart contract vulnerabilities demonstrate that SST is significantly more advantageous compared to eight state-of-the-art baseline methods, outperforming them by 24.12% in terms of F1 scores.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.