MANDO-LLM: Heterogeneous Graph Transformers with Large Language Models for Smart Contract Vulnerability Detection

Dec 1, 2025·
Nhat-Minh Nguyen
Nhat-Minh Nguyen
,
Hoang h. nguyen
,
Long le thanh
,
Zahra ahmadi
,
Thanh nam doan
,
Daoyuan wu
,
Lingxiao jiang
· 0 min read
Abstract
Detecting vulnerabilities in smart contracts is vital for the security and reliability of decentralized apps. To facilitate vulnerability detection, contract codes, including bug patterns, are represented as heterogeneous graphs with various nodes and edges, like control-flow and function-call graphs. However, existing graph learning techniques struggle with large, complex graphs. This paper presents MANDO-LLM, a novel framework that combines heterogeneous graph transformers (HGTs) with large language models (LLMs) for detecting vulnerabilities in smart contracts represented as heterogeneous contract graphs built upon control-flow and call graphs. MANDO-LLM uses LLMs to capture code features from control-flow and call data, customizes HGTs to learn embeddings with specific node-edge meta relations, and employs classifiers for vulnerability detection in Solidity code at both contract and line levels. Our evaluation shows that MANDO-LLM significantly outperforms existing methods on real-world large-scale imbalanced datasets, with F1-score improvements from 0.59% to 80.72% at the contract level. It is also one of the first effective methods for identifying line-level vulnerabilities, with performance boosts ranging from 3.09% to over 95% across different vulnerability types. MANDO-LLM’s versatility allows easy retraining for various vulnerabilities without needing manually defined patterns.
Type
Publication
ACM Transactions on Software Engineering and Methodology
publications
Nhat-Minh Nguyen
Authors
Research Engineer
I’m passionate about intelligent agents for software engineering — bridging the gap between complex code and AI. I received my B.Eng in Computer Science and Engineering from Ho Chi Minh City University of Technology (HCMUT). Currently, I’m a Research Engineer at the SMU School of Computing and Information Systems, under the supervision of Professor Lingxiao JIANG. My work focuses on the critical domain of security, specifically smart contract vulnerability analysis by utilizing Graph Learning and Large Language Models (LLMs). Beyond security, I am exploring the broader AI4SE domain to develop Trustworthy Holistic AI Agents for software engineering challenges, such as bug fixing, code completion/generation, enhanced CI/CDs, and operation monitoring. Balancing academic rigor with entrepreneurial ambition, I am also co-founding MANDO (mandoscan.com) to bring these advanced research solutions to the industry.
Authors