Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,600 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,600 results · page 10 of 67

Clear filters
Nov 22, 2024·Electronics
6 cites
MultiTagging: A Vulnerable Smart Contract Labeling and Evaluation Framework

Shikah J. Alsunaidi, Hamoud Aljamaan, Mohammad Hammoudeh

Identifying vulnerabilities in Smart Contracts (SCs) is crucial, as they can lead to significant financial losses if exploited. Although various SC vulnerability identification methods exist, selecting the most effective approach remains challenging. This article examines these challenges and introduces solutions to enhance SC vulnerability identification. It introduces MultiTagging, a modular SC multi-labeling framework designed to overcome limitations in existing SC vulnerability identification approaches. MultiTagging automates SC vulnerability tagging by parsing analysis reports and mapping tool-specific tags to standardized labels, including SC Weakness Classification (SWC) codes and Decentralized Application Security Project (DASP) ranks. Its mapping strategy and the proposed vulnerability taxonomy resolve tool-level labeling inconsistencies, where different tools use distinct labels for identical vulnerabilities. The framework integrates an evaluation module to assess SC vulnerability identification methods. MultiTagging enables both tool-based and vote-based SC vulnerability labeling. To improve labeling accuracy, the article proposes Power-based voting, a method that systematically defines voter roles and voting thresholds for each vulnerability. MultiTagging is used to evaluate labeling across six tools: MAIAN, Mythril, Semgrep, Slither, Solhint, and VeriSmart. The results reveal high coverage for Mythril, Slither, and Solhint, which identified eight, seven, and six DASP classes, respectively. Tool performance varied, underscoring the impracticality of relying on a single tool to identify all vulnerability classes. A comparative evaluation of Power-based voting and two threshold-based methods—AtLeastOne and Majority voting—shows that while voting methods can increase vulnerability identification coverage, they may also reduce detection performance. Power-based voting proved more effective than pure threshold-based methods across all vulnerability classes.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Nov 21, 2024·Cambridge University Press eBooks
0 cites
Foundations of Web3

Ken Huang, Youwei Yang, Fan Zhang, Xi Chen · 5 authors

This chapter establishes the intellectual groundwork for the shift from traditional web paradigms to a decentralized digital future. It begins by tracing the evolution from Web1 – a static, information-centric era – to Web2, characterized by interactive, user-generated content and the rise of social media. The chapter then introduces Web3 as a transformative leap, driven by blockchain technology, digital wallets, and decentralized applications (dApps) that empower individuals with true ownership over their digital assets and data. Real-world examples in decentralized finance, non-fungible tokens, and social networks illustrate how these innovations challenge centralization and reshape online interactions. Additionally, the discussion highlights ongoing challenges such as usability, security, and regulatory uncertainty, laying a solid foundation for understanding Web3’s revolutionary potential.

2 source records
Peer-to-Peer Network Technologies
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Nov 14, 2024·2024 8th International Conference on Information Technology (InCIT)
0 cites
Blockchain-Based Auxiliary Systems for Password Management

Thiwhat Vilaidaraga, Anucha Aribag, Chetneti Srisa-An

Authentication usually involves a combination of a username and password for the identity information process. Historically, users have had to find ways to manage them, typically by memorizing or noting them down separately. Blockchain-based Auxiliary System for Password Management (BAS-PM), which evolved from Distributed Ledger Technology (DLT) Frameworks, is designed to help users store their passwords securely and permanently. Passwords have been a simple yet effective means to protect systems from unauthorized access for years. They are also sensitive personal data that need to be protected by data privacy laws such as the GDPR. For cybersecurity and data privacy purposes, this research aims to propose a Blockchain-based Auxiliary System for Password Management (BAS-PM). The cost-effectiveness and robustness of blockchain technology make it an attractive solution for global password management. This article explores the use of blockchain in password management applications without relying on a centralized server. Experimental results indicate that blockchain-based methods have outperformed traditional methods.

User Authentication and Security Systems
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Nov 14, 2024·Blockchain Research and Applications
2 cites
New Ethereum-based distributed PKI with a reward-and-punishment mechanism

Chong-Gee Koa, Swee‐Huay Heng, Ji‐Jian Chin

This paper explores the critical role of Public Key Infrastructure (PKI) in ensuring the security of electronic transactions, particularly in validating the authenticity of websites in online environments. Traditional Centralised PKIs (CPKIs) relying on Certificate Authorities (CAs) face a significant drawback due to their susceptibility to a single point of failure. To address this concern, Decentralised PKIs (DPKIs) have emerged as an alternative. However, both centralised and decentralised approaches encounter specific challenges. Researchers have made several attempts using blockchain-based PKI, which implements a reward and punishment mechanism to enhance the security of traditional PKI. Most of the attempts are focused on CA-based PKI, which still suffers from the risk of a single point of failure. Inspired by ETHERST, which is a blockchain-based PKI that implements Web of Trust (WoT) with reward and punishment, we introduce ETHERST version 3.0, with improvements in its secure level algorithm that enhances trustworthiness measurement. Comparative simulations between ETHERST version 2.0 and ETHERST version 3.0 reveal the superior performance of the latter in trustworthiness measurement and ensure the higher security of a virtual community. The new simulation algorithm with different node type definitions and assumptions presents results through tables and graphs, showing that ETHERST version 3.0 outperforms ETHERST version 2.0. This research contributes to advancing the field by introducing an innovative PKI solution with enhanced trustworthiness and security features. • Comparison of blockchain-based PKIs which implement reward and punishment mechanism. • Reward and punishment with blockchain-based PKI with an improved new algorithm. • Definition of bad( B ), normal( N ) and good( G ) nodes to improve simulations algorithm.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Network Security and Intrusion Detection
Original source
Nov 2, 2024·Journal of Metaverse
15 cites
SmartLLMSentry: A Comprehensive LLM Based Smart Contract Vulnerability Detection Framework

Oualid Zaazaa, Hanan El Bakkali

Smart contracts are essential for managing digital assets in blockchain networks, highlighting the need for effective security measures. This paper introduces SmartLLMSentry, a novel framework that leverages large language models (LLMs), specifically ChatGPT with in-context training, to advance smart contract vulnerability detection. Traditional rule-based frameworks have limitations in integrating new detection rules efficiently. In contrast, SmartLLMSentry utilizes LLMs to streamline this process. We created a specialized dataset of five randomly selected vulnerabilities for model training and evaluation. Our results show an exact match accuracy of 91.1% with sufficient data, although GPT-4 demonstrated reduced performance compared to GPT-3 in rule generation. This study illustrates that SmartLLMSentry significantly enhances the speed and accuracy of vulnerability detection through LLM-driven rule integration, offering a new approach to improving Blockchain security and addressing previously underexplored vulnerabilities in smart contracts.

Open access
4 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Original source
Oct 31, 2024·arXiv (Cornell University)
0 cites
Across-Platform Detection of Malicious Cryptocurrency Transactions via Account Interaction Learning

Zheng Che, Meng Shen, Zhehui Tan, Hanbiao Du · 9 authors

With the rapid evolution of Web3.0, cryptocurrency has become a cornerstone of decentralized finance. While these digital assets enable efficient and borderless financial transactions, their pseudonymous nature has also attracted malicious activities such as money laundering, fraud, and other financial crimes. Effective detection of malicious transactions is crucial to maintaining the security and integrity of the Web 3.0 ecosystem. Existing malicious transaction detection methods rely on large amounts of labeled data and suffer from low generalization. Label-efficient and generalizable malicious transaction detection remains a challenging task. In this paper, we propose ShadowEyes, a novel malicious transaction detection method. Specifically, we first propose a generalized graph structure named TxGraph as a representation of malicious transaction, which captures the interaction features of each malicious account and its neighbors. Then we carefully design a data augmentation method tailored to simulate the evolution of malicious transactions to generate positive pairs. To alleviate account label scarcity, we further design a graph contrastive mechanism, which enables ShadowEyes to learn discriminative features effectively from unlabeled data, thereby enhancing its detection capabilities in real-world scenarios. We conduct extensive experiments using public datasets to evaluate the performance of ShadowEyes. The results demonstrate that it outperforms state-of-the-art (SOTA) methods in four typical scenarios. Specifically, in the zero-shot learning scenario, it can achieve an F1 score of 76.98% for identifying gambling transactions, surpassing the SOTA method by12.05%. In the scenario of across-platform malicious transaction detection, ShadowEyes maintains an F1 score of around 90%, which is 10% higher than the SOTA method.

Open access
2 source records
cs.CR
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Oct 30, 2024
1 cites
Ethereum Phishing Detection Using Hyperbolic Neural Networks and Temporal Information

Renyuan Xu, Jun Zhang, Xiaoyue Zhu, Zhaoxiong Song · 5 authors

In recent years, the frequent occurrence of phishing scams on Ethereum has posed serious threats to transaction security and the financial safety of users. This paper proposes an Ethereum phishing scam detection method based on Hyperbolic Neural Networks (HGNNs) and temporal information. The method maps the Ethereum transaction network to hyperbolic space for structural feature extraction, effectively capturing hierarchical structures and complex relationships within the graph, thereby improving the accuracy of phishing scam detection. The model includes a structural feature extraction module and a temporal feature extraction module. It uses HGNN and self-attention mechanism to extract the structural features of the transaction graph, and uses a multi-head attention mechanism to capture the dynamic evolution pattern of the graph. Experimental validation on real Ethereum datasets demonstrates that the proposed model outperforms benchmark models, showcasing its effectiveness.

Spam and Phishing Detection
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Oct 28, 2024·2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)
2 cites
A Privacy-Preserving Cyber Threat Intelligence Sharing System

Philip Huff, Spencer Massengale, Tran Viet Xuan Phuong, Sri Nikhil Gupta Gourisetti

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. We propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

Cryptography and Data Security
Privacy-Preserving Technologies in Data
Spam and Phishing Detection
Original source
Oct 25, 2024·2024 Global Conference on Communications and Information Technologies (GCCIT)
0 cites
A Hybrid Blockchain for User Rating in Social Media

Sameera Abeysekara, Sónia Silva, K.P.P. Tilanka, Kadt Kulawansa · 5 authors

Social networks have made a revolution in the way how people connect, communicate and share information with each other by leveraging the Internet as the platform. Social networks are open platforms where users can enjoy their freedom of expression to the maximum for posting anything online. Except for a few occasions, censorship play minimum or no role in the social media networks. Hence, it is the responsibility of the reader to identify and choose the content that is suitable for him to read or repost. Some researchers have created mechanisms for evaluating the contents posted. But, presently there is no mechanism for rating users based on the type of material they post online. In this research, a blockchain powered mechanism is proposed for rating users based on the comments received for their posts. The proposed mechanism leverages the advantages of blockchain including transparency, immutability, traceability and security. The proposed mechanism rewards users for their good behavior using non-fungible tokens and revoking them for misbehavior. The proposed mechanism has been tested using publicly available data and a set of students in a simulated environment. The evaluation results are promising as it can identify users who continuously post good or malicious contents online and rank them accordingly.

Blockchain Technology Applications and Security
Digital Marketing and Social Media
Spam and Phishing Detection
Original source
Oct 19, 2024·2024 6th Novel Intelligent and Leading Emerging Sciences Conference (NILES)
2 cites
Advanced Phishing Detection in Ethereum Blockchain Transactions Using Machine Learning Models

Mohamed Ibrahim Ragab, Rawan Osama Bakr, Heba K. Aslan

Deceptive phishing attacks greatly endanger blockchain security, tricking miners into adding harmful blocks to the chain. Current methods of detection and agreement protocols are frequently not enough, especially if authorized miners accidentally include these blocks. Despite the potential for improving detection capabilities, the adoption of zero-trust policies is still restricted. This paper explores different machine learning techniques, like k-Nearest Neighbors (k-NN), Decision Trees (DT), Random Forest (RF), and XGBoost, to predict phishing attacks. It also evaluates feature selection methods such as Principal Component Analysis (PCA) and Decision Trees, ultimately recommending the Random Forest (RF) model as the most effective for phishing detection. The RF model, assessed using metrics such as accuracy, precision, recall, and evaluation time, demonstrates superior performance, achieving up to 99% accuracy. Consequently, the RF model emerges as the optimal choice for accurately and efficiently identifying phishing threats, thereby enhancing the security of blockchain networks.

Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Oct 18, 2024·arXiv (Cornell University)
2 cites
Detecting Malicious Accounts in Web3 through Transaction Graph

Wenkai Li, Zhijie Liu, Xiaoqi Li, Sen Nie

The web3 applications have recently been growing, especially on the Ethereum platform, starting to become the target of scammers. The web3 scams, imitating the services provided by legitimate platforms, mimic regular activity to deceive users. The current phishing account detection tools utilize graph learning or sampling algorithms to obtain graph features. However, large-scale transaction networks with temporal attributes conform to a power-law distribution, posing challenges in detecting web3 scams. In this paper, we present ScamSweeper, a novel framework to identify web3 scams on Ethereum. Furthermore, we collect a large-scale transaction dataset consisting of web3 scams, phishing, and normal accounts. Our experiments indicate that ScamSweeper exceeds the state-of-the-art in detecting web3 scams.

Open access
3 source records
Spam and Phishing Detection
Network Security and Intrusion Detection
Advanced Graph Neural Networks
Original source
Oct 11, 2024·Cybersecurity
4 cites
MVD-HG: multigranularity smart contract vulnerability detection method based on heterogeneous graphs

Jingjie Xu, Ting Wang, Mingqi Lv, Tieming Chen · 6 authors

Abstract Smart contracts have significant losses due to various types of vulnerabilities. However, traditional vulnerability detection methods rely extensively on expert rules, resulting in low detection accuracy and poor adaptability to novel attacks. To address these problems, in this paper, deep learning methods are combined with smart contract vulnerability code detection approaches. Abstract syntax trees (ASTs), which are special isomorphic graph structures, are an important bridge between source code and graph neural networks. By learning the AST, the model can understand the semantics of the source code. Moreover, graph neural networks have an increasing ability to address complex heterogeneous graphs. Therefore, control flow graphs are fused with data flow graphs on the basis of the ASTs to build heterogeneous graphs with richer code semantics. Furthermore, multigranularity analysis of the vulnerability detection results is performed, including coarse-grained contract-level vulnerability detection and fine-grained line-level vulnerability detection. Through this multigranularity detection approach, vulnerabilities in contracts can be identified and analysed more comprehensively, providing a richer perspective and more solutions for vulnerability detection. The experimental results show that the proposed multigranularity vulnerability detection method based on heterogeneous graphs (MVD-HG) improves both the accuracy and range of the detected vulnerability types in contract-level vulnerability detection tasks; moreover, in the line-level vulnerability detection task, the MVD-HG model achieves significant results and addresses the shortcomings of existing methods. In addition, based on code generation methods used in related fields, a data enhancement method based on the source code is developed, which effectively expands the experimental dataset to address the reduced credibility of the results due to insufficient amounts of data.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Smart Grid Security and Resilience
Original source
Oct 4, 2024·IEEE Transactions on Computational Social Systems
8 cites
SpaTeD: Sparsity-Aware Tensor Decomposition-Based Representation Learning Framework for Phishing Scams Detection

M. K. Ghosh, Raju Halder, Joydeep Chandra

In recent years, the consequences of phishing scams on Ethereum have adversely affected the stability of the cryptocurrency environment. Numerous incidents have been reported that have resulted in a substantial loss of cryptocurrency. The existing literature in this area primarily leverages traditional feature engineering or network representation learning to recover crucial information from transaction records to identify suspected users. However, these methods mainly rely on handcrafted feature engineering or conventional node representation learning from a static network while ignoring the network dynamism and inherent temporal sparsity in the user behavior that results in underperformance after an extended period. This article proposes a novel sparsity-aware tensor decomposition-based architecture:SpaTeD, which retrieves efficient user representation utilizing the evolving transaction and structural information and subsequently mitigates the temporal sparsity problem. Our model is evaluated on a real-world Ethereum phishing scam dataset and reports a significant performance improvement over the baselines (96%recalland 96%F1-score). We have conducted an extensive set of experiments to verify the temporal robustness of the model. Additionally, we have provided the ablation study to demonstrate the contribution of each component of the framework.

Spam and Phishing Detection
Original source
Oct 3, 2024·IEEE Internet of Things Journal
11 cites
TSFF: A Triple-Stream Feature Fusion Method for Ethereum Phishing Scam Detection

Wenhan Hou, Bo Cui, Yongxin Chen, Ru Li · 5 authors

As a representative of the public blockchain, Ethereum has been applied in various industries. However, the vast number of transactions on the platform has also brought a number of illegal activities, such as phishing scams, which have caused significant damage to the Ethereum ecosystem. Due to anonymity of the blockchain, it is difficult for detectors to extract features that can be directly applied to phishing scams detection. Existing studies mainly model Ethereum transaction records as a network and mine key information from them to identify phishing addresses. However, these methods usually employ traditional feature engineering or network embedding, ignoring the fine-grained features in the transaction network. In addition, since the original network is too large to make learning difficult, existing work usually uses random walk (RW) to sample a part of nodes for training, thus ignoring the multiplicity of the network. To address these issues, in this article, we propose a three-stream feature fusion (TSFF) approach to enhance the feature representation of nodes. Specifically, we construct node states to guide RW sampling, and manually extracted 8-D features from the resulting dataset as basic features. Temporal features are jointly learned through long short-term memory network and contrastive learning. We combine residual blocks and graph convolutional network to extract fine-grained structural features from transactional networks. Finally, we fuse these three types of features and input them into a downstream classifier. Experiments show that our TSFF (85.3% Precision) outperforms the state-of-the-art methods, and the effectiveness of each feature is demonstrated.

Spam and Phishing Detection
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Original source
Sep 29, 2024·Security informatics and law enforcement
0 cites
Kriptosare: Behavior Analysis in Cryptocurrency Transactions

Francesco Zola, Jon Elduayen, Igor Pallin, Raúl Orduna-Urrutia

Abstract Despite being backed by blockchain technology that promises security, immutability, and full transparency, some cryptocurrencies such as Bitcoin have been used as enablers for many licit and illicit activities such as money laundering, terrorism financing, and ransomware payments. In this scenario, the analysis of the transactions, as well as the entities that have generated them, became a crucial step for law enforcement officer (LEO) investigations. However, the (pseudo) anonymity of the network, the lack of regulatory authority, the employment of anonymizer mechanisms, the evolution of entities’ behavior, and the emergence of new dynamics are just five of the main elements that make this task challenging. At the same time, the huge amount of information to be analyzed can result in a waste of time and resources, slowing the investigations. For this reason, in this work, we present Kriptosare, a tool able to classify entity behaviors belonging to Bitcoin, Bitcoin Cash, and Litecoin. On the one hand, the tool makes use of state-of-the-art machine learning techniques to reduce anonymity in the considered cryptocurrencies. This model extracts behaviors from interactions and dynamics of different known entities involved in the transactions and then predicts the behaviors of new unseen entities. On the other hand, Kriptosare includes a crypto simulator able to create and control a private Bitcoin, Bitcoin Cash, or Litecoin network. This unit allows the simulation of crypto transactions in a controlled way for evaluating hypotheses and/or enriching the input data. The presented tool can be used by LEOs to search and highlight the most important red flag indicators that could suggest criminal behavior, and to support their analysis by optimizing their investigation resources.

Open access
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Spam and Phishing Detection
Original source
Sep 21, 2024·2024 IEEE North Karnataka Subsection Flagship International Conference (NKCon)
1 cites
VeriTrace: A Web3 Based Fake Product Identification System Using Blockchain

Akhilraj V. Gadagkar, Shifana Begum

The proliferation of counterfeit items in the worldwide market has emerged as a pressing concern for consumers, manufacturers, and regulatory agencies alike. Counterfeiting not only results in monetary damages for enterprises but also presents significant hazards to customer well-being and brand standing. Conventional techniques for identifying and verifying products are frequently inadequate in detecting and stopping counterfeit goods, necessitating the development of novel solutions. Blockchain technology has emerged as a viable method for tackling the problem of counterfeit product identification. Blockchain is a decentralised and secure ledger that enables the recording and verification of transactions in a distributed, visible, and unchangeable manner. By utilising the distinct characteristics of blockchain, such as its transparency, consensus mechanism, and cryptographic hashing, it is feasible to establish a resilient system for product identification that may efficiently address the issue of counterfeiting.

Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Sep 18, 2024·2024 7th International Conference on Contemporary Computing and Informatics (IC3I)
3 cites
Comparative Sentiment Analysis of Cryptocurrency Apps Using BERT

Mohd Danish, Mohammad Amjad, Tanvir Ahmad

Natural Language Processing (NLP) has significantly advanced the ability to analyse and interpret textual data, playing a crucial role in understanding user sentiments. This study applies cutting-edge NLP techniques to perform sentiment analysis on reviews from India’s top cryptocurrency apps and Twitter data. Given the growing interest in cryptocurrencies, understanding user sentiment is vital for market insights and product improvement. We collected a diverse dataset from the Google Play store and Twitter, encompassing 7,197 reviews and numerous tweets. Utilizing the BERT (Bidirectional Encoder Representations from Transformers) model, known for its deep learning capabilities, we processed and analysed the data. The dataset underwent thorough pre-processing, including tokenization and the removal of irrelevant elements. Our analysis compared the BERT model’s performance with traditional classifiers such as Naive Bayes and Support Vector Machines (SVM). Findings show that BERT significantly outperformed other models, achieving superior precision, recall, accuracy and F1-scores. These results underscore the effectiveness of advanced NLP models in sentiment analysis, particularly for understanding public sentiment towards cryptocurrency apps in India. Future research will explore sentiment analysis on a broader range of platforms and fine-tuning BERT model parameters to further enhance performance and accuracy.

Advanced Text Analysis Techniques
Sentiment Analysis and Opinion Mining
Spam and Phishing Detection
Original source
Sep 11, 2024·arXiv
3 cites
Analyzing the Impact of Copying-and-Pasting Vulnerable Solidity Code Snippets from Question-and-Answer Websites

Konrad Weiss, Christof Ferreira Torres, Florian Wendland

Ethereum smart contracts are executable programs deployed on a blockchain. Once deployed, they cannot be updated due to their inherent immutability. Moreover, they often manage valuable assets that are worth millions of dollars, making them attractive targets for attackers. The introduction of vulnerabilities in programs due to the reuse of vulnerable code posted on Q&A websites such as Stack Overflow is not a new issue. However, little effort has been made to analyze the extent of this issue on deployed smart contracts. In this paper, we conduct a study on the impact of vulnerable code reuse from Q&A websites during the development of smart contracts and provide tools uniquely fit to detect vulnerable code patterns in complete and incomplete Smart Contract code. This paper proposes a pattern-based vulnerability detection tool that is able to analyze code snippets (i.e., incomplete code) as well as full smart contracts based on the concept of code property graphs. We also propose a methodology that leverages fuzzy hashing to quickly detect code clones of vulnerable snippets among deployed smart contracts. Our results show that our vulnerability search, as well as our code clone detection, are comparable to state-of-the-art while being applicable to code snippets. Our large-scale study on 18,660 code snippets reveals that 4,596 of them are vulnerable, out of which 616 can be found in 7,852 deployed smart contracts. These results highlight that the reuse of vulnerable code snippets is indeed an issue in currently deployed smart contracts.

Open access
2 source records
cs.CR
Spam and Phishing Detection
Web Data Mining and Analysis
Original source
Sep 9, 2024·Information Fusion
32 cites
Ethereum fraud detection via joint transaction language model and graph representation learning

Jianguo Sun, Yifan Jia, Yanbin Wang, Yiwei Liu · 6 authors

Ethereum faces growing fraud threats. Current fraud detection methods, whether employing graph neural networks or sequence models, fail to consider the semantic information and similarity patterns within transactions. Moreover, these approaches do not leverage the potential synergistic benefits of combining both types of models. To address these challenges, we propose TLMG4Eth that combines a transaction language model with graph-based methods to capture semantic, similarity, and structural features of transaction data in Ethereum. We first propose a transaction language model that converts numerical transaction data into meaningful transaction sentences, enabling the model to learn explicit transaction semantics. Then, we propose a transaction attribute similarity graph to learn transaction similarity information, enabling us to capture intuitive insights into transaction anomalies. Additionally, we construct an account interaction graph to capture the structural information of the account transaction network. We employ a deep multi-head attention network to fuse transaction semantic and similarity embeddings, and ultimately propose a joint training approach for the multi-head attention network and the account interaction graph to obtain the synergistic benefits of both.

Open access
4 source records
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source