MANDO-GURU: vulnerability detection for smart contract source code by heterogeneous graph embeddings

Nov 1, 2022·
Hoang h. nguyen
Nhat-Minh Nguyen
Nhat-Minh Nguyen
,
Hong phuc doan
,
Zahra ahmadi
,
Thanh nam doan
,
Lingxiao jiang
· 0 min read
Abstract
Smart contracts are increasingly used with blockchain systems for high-value applications. It is highly desired to ensure the quality of smart contract source code before they are deployed. This paper proposes a new deep learning-based tool, MANDO-GURU, that aims to accurately detect vulnerabilities in smart contracts at both coarse-grained contract-level and fine-grained line-level. Using a combination of control-flow graphs and call graphs of Solidity code, we design new heterogeneous graph attention neural networks to encode more structural and potentially semantic relations among different types of nodes and edges of such graphs and use the encoded embeddings of the graphs and nodes to detect vulnerabilities. Our validation of real-world smart contract datasets shows that MANDO-GURU can significantly improve many other vulnerability detection techniques by up to 24% in terms of the F1-score at the contract level, depending on vulnerability types. It is the first learning-based tool for Ethereum smart contracts that identify vulnerabilities at the line level and significantly improves the traditional code analysis-based techniques by up to 63.4%. Our tool is publicly available at https://github.com/MANDO-Project/ge-sc-machine. A test version is currently deployed at http://mandoguru.com, and a demo video of our tool is available at http://mandoguru.com/demo-video.
Type
Publication
the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering
publications
Nhat-Minh Nguyen
Authors
Research Engineer
I’m passionate about intelligent agents for software engineering — bridging the gap between complex code and AI. I received my B.Eng in Computer Science and Engineering from Ho Chi Minh City University of Technology (HCMUT). Currently, I’m a Research Engineer at the SMU School of Computing and Information Systems, under the supervision of Professor Lingxiao JIANG. My work focuses on the critical domain of security, specifically smart contract vulnerability analysis by utilizing Graph Learning and Large Language Models (LLMs). Beyond security, I am exploring the broader AI4SE domain to develop Trustworthy Holistic AI Agents for software engineering challenges, such as bug fixing, code completion/generation, enhanced CI/CDs, and operation monitoring. Balancing academic rigor with entrepreneurial ambition, I am also co-founding MANDO (mandoscan.com) to bring these advanced research solutions to the industry.