Papers1 provider · 1 record
January 1, 2026· SSRN Electronic Journal
preprint
Open access

A Multi-Agent and Explainable Semantic-Guided Smart Contract Fuzzing with LLMs

Authors:Leanne NgoTran Tien Nhatanon anonTriet Huynh Minh LeMuhammad Ali BabarVan-Hau PhamNguyen Tan Cam *

Abstract

Smart contracts underpin modern blockchain ecosystems, enabling decentralized applications in DeFi and digital asset management. However, their immutability exacerbates programming errors and vulnerabilities, leading to unpatchable flaws and significant financial losses, as seen in high-profile exploits. Current vulnerability detection methods including static and dynamic analysis—face critical limitations: (1) static analysis suffers from state-space explosion, control-flow complexity, over-approximation, and high false positives; (2) dynamic fuzzing relies on syntactic/random mutations lacking semantic awareness, inefficiently exploring deep state-dependent paths and complex transaction sequences; (3) both static and dynamic approaches overlook semantic-structural gaps, such as execution order semantics in reentrancy vulnerabilities; (4) fuzzing reports lack explainability, hindering practical auditing. To address these challenges, we propose MAESFuzz1, a multi-agent semantic-guided smart contract fuzzing framework that integrates static structural analysis, dynamic execution feedback, and Large Language Model (LLM)–assisted reasoning within a closed-loop architecture. MAESFuzz employs LLMs as semantic advisors to guide seed generation, transaction sequence construction, and mutation refinement, enabling effective exploration of deep state-dependent behaviors and complex multi-transaction vulnerabilities. Extensive evaluation on the SoliAudit benchmark and a real-world dataset of deployed Ethereum contracts shows that MAESFuzz improves vulnerability detection by up to 28.7% relative to state-of-the-art (SOTA) smart contract fuzzers on SoliAudit. On real-world contracts, MAESFuzz uncovers 25 more expert-validated vulnerabilities than the strongest SOTA baseline while maintaining 94.38% precision and competitive execution coverage. In addition, MAESFuzz generates structured, execution-grounded audit reports to enhance interpretability and support practical security auditing.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.