Peilin Zheng

dblp:217/4364 · DBLP profile ↗
← Back
15ranked-venue papers
8as first author
14since 2021 · last 2026
0000-0002-4897-9276ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 5 first-author · 8 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Understanding Functional Bugs in EVM-Based Blockchain Systems
abstract
Functional bugs within blockchain systems have led to financial losses exceeding millions of dollars. Blockchain systems, such as Ethereum, play a critical role in supporting decentralized applications and managing significant financial assets. Despite the urgent need for enhanced security, relatively few studies have systematically investigated the functional bugs specific to blockchain systems. Unlike in conventional software, functional bugs in blockchain systems are often domain-specific and linked to core blockchain functionalities, necessitating a comprehensive understanding.In this study, we conduct a systematic analysis of functional bugs in Ethereum Virtual Machine (EVM)-based blockchain systems. We focus on the EVM-based architecture, as it is one of the most widely adopted models for blockchain systems. Specifically, we analyze bug-related issues reported in the GitHub repositories of leading blockchain systems, building a dataset of 205 real-world bugs classified into 18 categories. We investigate these collected bugs with respect to their taxonomies, root causes, and detection methods. From this analysis, we summarize eight key findings for enhancing blockchain security. The discovery of seven previously unknown bugs, yielding approximately $12,000 in bug bounties, demonstrates the practical impact of this work. A further investigation of state-of-the-art tools highlights the limitations of existing detection and analysis research.
Mingxi Ye, Yuhong Nan, Jianzhong Su, Yuming Xiao, Peilin Zheng, Zibin Zheng
IEEE Trans. Software Eng.6
2025 To healthier Ethereum: a comprehensive and iterative smart contract weakness enumeration
abstract
With the increasing popularity of cryptocurrencies and blockchain technologies, smart contracts have become a prominent feature in developing decentralized applications. However, these smart contracts are susceptible to vulnerabilities that hackers can exploit, resulting in significant financial losses. In response to this growing concern, various initiatives have emerged. Notably, the Smart Contract Weakness Classification (SWC) list plays an important role in raising awareness and understanding of smart contract weaknesses. However, the SWC list lacks maintenance and has not been updated with new vulnerabilities since 2020. To address this gap, this paper introduces the Smart Contract Weakness Enumeration (SWE), a comprehensive and practical vulnerability list up until 2023. We collect 273 vulnerability descriptions from 86 top conference papers and journal papers, employing the open card-sorting method to deduplicate and categorize these descriptions. This process results in the identification of 40 common contract weaknesses, which are further classified into 20 sub-research fields through thorough discussion and analysis. The SWE provides a systematic and comprehensive list of smart contract vulnerabilities, covering existing and emerging vulnerabilities in the last few years. Moreover, the SWE is a scalable and continuously iterative program. We propose two update mechanisms for the maintenance of the SWE. Regular updates involve the inclusion of new vulnerabilities from future top papers, while irregular updates enable individuals to report new weaknesses for review and potential addition to the SWE.
Jiachi Chen, Mingyuan Huang, Zewei Lin, Peilin Zheng, Zibin Zheng
Blockchain Res. Appl.4
2025 DAppCheat: Detecting Cheating Robots for DApps on Multiple Blockchains
abstract
Recent years have witnessed a rapid increase in the number of blockchain-based decentralized applications (DApps). As reported by DAppRadar, there are more than 5,000 DApps with more than 17.2 million daily Unique Active Wallets (users). However, it is also reported that some robots are used to manipulate the ranking, attract more users, cheat investors, etc. Hence, it is necessary to detect those robots. Unlike traditional robots or spam detection on Internet, each blockchain has its specific data structure with the impacts of exchanges and whales, leading to the challenges of detecting DApp robots. In this paper, we conduct the first systematic investigation on DApps robots, named DAppCheat. We first collect and release the first multi-blockchain DApp-user dataset, including 4,857 DApps and 99,758,959 users from Ethereum, EOSIO, TRON, and BSC. We propose a general parent account mechanism for multiple blockchains in order to find anonymous user collusion. We define the creating account weight and the used DApp volume weight to reduce the impacts of exchanges and whales. Extensive experimental results show the effectiveness of DAppCheat.
Peilin Zheng, Xiapu Luo, Weilin Zheng, Zibin Zheng
IEEE Trans. Serv. Comput.1
2025 ASTRO: Detecting Access Control Vulnerabilities in Smart Contracts via Graph Similarity Comparison
abstract
Smart contracts are programs running on blockchains, managing substantial volumes of wealth stored within the blockchain platforms. To safeguard these assets, developers design and implement access control policies. However, incomplete and incorrect access control policies allow malicious attackers to gain unauthorized access and exploit additional assets. Previous tools for detecting access control vulnerabilities in smart contracts rely on predefined patterns, specifications, or mining access control policies from historical transactions. However, these methods are constrained due to their predetermined nature and the diversity and complexity of smart contracts.In this paper, we presentASTRO, a new framework employing code similarity to detect access control vulnerabilities in smart contracts. In contrast to prior approaches that heavily rely on predefined, vulnerable code samples,ASTROdetects whether a target contract has access control vulnerabilities by comparing it against a database of audited contracts. Moreover, to mitigate the impact of language-specific features (e.g., diverse conditional statements and modifiers) and writing style characteristics, we integrate pruning and normalization techniques. We evaluateASTROon a total of 22 smart contracts with assigned access control CVEs and those attacked because of access control vulnerabilities from the past two years. Evaluation results demonstrate that, compared to state-of-the-art tools (i.e., AChecker, SpCon),ASTROsurpasses all tools in recall and achieves an improvement in recall by at least 2.8 times. In addition,ASTROachieves a precision of 78.33% on a dataset consisting of real-wild contracts. Furthermore,ASTROsuccessfully identified 19 exploitable vulnerable contract that can be used to directly gain access to the contract’s permissions and obtain benefits.
Wei Li 0121, Yuhong Nan, Mingxi Ye, Peilin Zheng, Zibin Zheng
IEEE Trans. Software Eng.5
2025 Unity is Strength: Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis Tools
abstract
Reentrancy is one of the most notorious vulnerabilities in smart contracts, resulting in significant digital asset losses. However, many previous works indicate that current Reentrancy detection tools suffer from high false positive rates. Even worse, recent years have witnessed the emergence of new Reentrancy attack patterns fueled by intricate and diverse vulnerability exploit mechanisms. Unfortunately, current tools face a significant limitation in their capacity to adapt and detect these evolving Reentrancy patterns. Consequently, ensuring precise and highly extensible Reentrancy vulnerability detection remains critical challenges for existing tools. To address this issue, we propose a tool named ReEP, designed to reduce the false positives for Reentrancy vulnerability detection. Additionally, ReEP can integrate multiple tools, expanding its capacity for vulnerability detection. It evaluates results from existing tools to verify vulnerability likelihood and reduce false positives. ReEP also offers excellent extensibility, enabling the integration of different detection tools to enhance precision and cover different vulnerability attack patterns. We perform ReEP to eight existing state-of-the-art Reentrancy detection tools. The average precision of these eight tools increased from the original 0.5% to 73% without sacrificing recall. Furthermore, ReEP exhibits robust extensibility. By integrating multiple tools, the precision further improved to a maximum of 83.6%. These results demonstrate that ReEP effectively unites the strengths of existing works, enhances the precision of Reentrancy vulnerability detection tools.
Zexu Wang, Jiachi Chen, Peilin Zheng, Yu Zhang 0036, Weizhe Zhang, Zibin Zheng
IEEE Trans. Software Eng.3
2024 LENT-SSE: Leveraging Executed and Near Transactions for Speculative Symbolic Execution of Smart Contracts
abstract
Symbolic execution has proven effective for code analytics in smart contracts. However, for smart contracts, existing symbolic tools use multiple-transaction symbolic execution, which differs from traditional symbolic tools and also exacerbates the path explosion problem. In this paper, we first quantitatively analyze the bottleneck of symbolic execution in multiple transactions (TXs), finding the redundancy of the paths of TXs. Based on this finding, we propose LENT-SSE as a new speculation heuristic for Speculative Symbolic Execution of smart contracts, which leverages the executed and near TXs for skipping and recalling the SMT solving of paths. LENT-SSE uses an executed-transaction-based skipping algorithm to reduce the time required for SMT solving by leveraging the redundancy between executed and executing paths. Moreover, LENT-SSE uses a near-transaction-based recalling algorithm to reduce false skipping of the solving paths. Experimental results on the SmartBugs dataset show that LENT-SSE can reduce the total time by 37.4% and the solving time of paths by 65.2% on average without reducing the reported bugs. On the other dataset of 1000 realistic contracts, the total time and solving time are reduced by 38.1% and 54.7%.
Peilin Zheng, Bowei Su, Xiapu Luo, Ting Chen 0002, Neng Zhang 0001, Zibin Zheng
ISSTA1
2023 BSHUNTER: Detecting and Tracing Defects of Bitcoin Scripts
abstract
Supporting the most popular cryptocurrency, the Bitcoin platform allows its transactions to be programmable via its scripts. Defects in Bitcoin scripts will make users lose their bitcoins. However, there are few studies on the defects of Bitcoin scripts. In this paper, we conduct the first systematic investigation on the defects of Bitcoin scripts through three steps, including defect definition, defect detection, and exploitation tracing. First, we define six typical defects of scripts in Bitcoin history, namely unbinded-txid, simple-key, useless-sig, uncertain-sig, impossible-key, and never-true. Three are inspired by the community, and three are new from us. Second, we develop a tool to discover Bitcoin scripts with any of typical defects based on symbolic execution and enhanced by historical exact scripts. By analyzing all Bitcoin transactions from Oct. 2009 to Aug. 2022, we find that 383,544 transaction outputs are paid to the Bitcoin scripts with defects. The total amount of them is 3,115.43 BTC, which is around 60 million dollars at present. Third, in order to trace the exploitation of the defects, we instrument the Bitcoin VM to record the traces of the real-world spending transactions of the buggy scripts. We find that 84,130 output scripts are exploited. The implementation and non-harmful datasets are released.
Peilin Zheng, Xiapu Luo, Zibin Zheng
ICSE1
2023 Selecting reliable blockchain peers via hybrid blockchain reliability prediction
abstract
Abstract Blockchain and blockchain‐based decentralised applications have been attracting increasing attention recently. In public blockchain systems, users usually connect to third‐party peers or run a peer to join the P2P blockchain network. However, connecting to unreliable blockchain peers will lead to resource waste and even loss of cryptocurrencies by repeated transactions. In order to select reliable blockchain peers, it is urgently needed to evaluate and predict their reliability of them. Faced with this problem, we propose hybrid blockchain reliability prediction (H‐BRP), a Hybrid Blockchain Reliability Prediction model, to extract the blockchain reliability factors and then make the personalised prediction for each user. Comprehensive experiments conducted on 100 blockchain requesters and 200 blockchain peers demonstrate the effectiveness of the proposed H‐BRP model. Further, the implementation and dataset of 2,000,000 test cases are released.
Peilin Zheng, Zibin Zheng, Liang Chen 0001
IET Softw.1
2022 Lock-Based Proof of Authority: A Faster and Low-Forking PoA Fault Tolerance Protocol for Blockchain Systems
Zhenbang Huang, Peilin Zheng, Zibin Zheng
BlockSys2
2022 Park: accelerating smart contract vulnerability detection via parallel-fork symbolic execution
abstract
Symbolic detection has been widely used to detect vulnerabilities in smart contracts. Unfortunately, as reported, existing symbolic tools cost too much time, since they need to execute all paths to detect vulnerabilities. Thus, their accuracy is limited by time. To tackle this problem, in this paper, we propose Park, the first general framework of parallel-fork symbolic execution for smart contracts. The main idea is to use multiple processes during symbolic execution, leveraging multiple CPU cores to enhance efficiency. Firstly, we propose a fork-operation based dynamic forking algorithm to achieve parallel symbolic contract execution. Secondly, to address the SMT performance loss problem in parallelization, we propose an adaptive processes restriction and adjustment algorithm. Thirdly, we design a shared-memory based global variable reconstruction method to collect and rebuild the global variables from different processes. We implement Park as a plug-in and apply it to two popular symbolic execution tools for smart contracts: Oyente and Mythril. The experimental results with third-party datasets show that Park-Oyente and Park-Mythril can provide up to 6.84x and 7.06x speedup compared to original tools, respectively.
Peilin Zheng, Zibin Zheng, Xiapu Luo
ISSTA1
2022 Meepo: Multiple Execution Environments per Organization in Sharded Consortium Blockchain
abstract
Blockchain performance cannot meet the requirement nowadays. One of the crucial ways to improve performance is sharding. However, most blockchain sharding research focuses on the public blockchain. As for consortium blockchain, previous studies cannot support high cross-shard efficiency, multiple-shard contract calling, strict transaction atomicity, and shard availability, which are essential requirements but also challenges in consortium blockchain systems. Facing these challenges, we propose Meepo, a systematic study on sharded consortium blockchain. Meepo enhances cross-shard efficiency via the cross-epoch and cross-call. Moreover, a partial cross-call merging strategy is designed to handle the multi-state dependency in contract calls, achieving flexible multiple-shard contract calling. Meepo employs a replay-epoch to ensure strict transaction atomicity, and it also uses a backup algorithm called shadow shard based recovery to improve the shard robustness. On a test-bed of 128 AliCloud servers, setting 32 shards and 4 consortium members, Meepo-OpenEtheruem can achieve more than 140,000 cross-shard TPS under the workload of 100,000,000 asset transactions. It also shows more than 50,000 TPS under the transactions of real-world shopping behaviors.
Peilin Zheng, Quanqing Xu, Zibin Zheng, Ying Yan 0002, Hui Zhang 0002
IEEE J. Sel. Areas Commun.1
2022 Aeolus: Distributed Execution of Permissioned Blockchain Transactions via State Sharding
abstract
Blockchain has attracted lots of attention in recent years. However, the performance of blockchain cannot meet the requirement of massive Internet of Things (IoT) devices. One of the important bottlenecks of blockchain is the limited computing resources on a single server while executing transactions. To address this issue, we propose Aeolus blockchain to achieve the distributed execution of blockchain transactions. There are two key challenges to achieving this for IoT blockchain: transaction structure and state consistency. Facing these challenges, we first propose a distributed blockchain transaction structure, which imports extra parameters to divide the transaction execution into different stages to enable distributed execution. Second, we propose distributed state update sharding, which equips each blockchain peer with its own master and shard servers. In this way, each blockchain peer can be considered as a cluster that distributes the transaction to shorten the processing time and reach the consensus finally. We implement Aeolus on Go-Ethereum to evaluate its feasibility, on a testbed including 132 cloud servers. Our system runs stably for more than 8 h under the workload of 190 000 000 real-world user transactions. Experimental results show the efficiency that Aeolus can achieve more than 100 000 transactions/s of blockchain transactions, which is 15.6 times the throughput of the original blockchain.
Peilin Zheng, Quanqing Xu, Xiapu Luo, Zibin Zheng, Weilin Zheng, Xu Chen 0004, Ying Yan 0002, Hui Zhang 0002
IEEE Trans. Ind. Informatics1
2021 Meepo: Sharded Consortium Blockchain
abstract
Blockchain performance cannot meet the requirement nowadays. One of the crucial ways to improve performance is sharding. However, most blockchain sharding research focuses on public blockchain. As for consortium blockchain, previous studies cannot support high cross-shard efficiency, cross-contract flexibility, shard availability, and strict transaction atomicity, which are the essential requirements but also the challenges in consortium blockchain systems. Facing these challenges, we propose Meepo, a systematic study on sharded consortium blockchain. Meepo enhances cross-shard efficiency via the cross-epoch and cross-call. Moreover, a partial cross-call merging strategy is designed to handle the multi-state dependency in contract calls, achieving cross-contract flexibility. Meepo employs a replay-epoch to ensure strict transaction atomicity, and it also uses a backup algorithm called shadow shard based recovery to improve the shard robustness. We implement Meepo on the AliCloud, using 32 shards in maximum, achieving more than 120,000 cross-shard TPS under the workload of 100,000,000 asset transactions.
Peilin Zheng, Quanqing Xu, Zibin Zheng, Ying Yan 0002, Hui Zhang 0002
ICDE1
2021 XBlock-EOS: Extracting and exploring blockchain data from EOSIO
Weilin Zheng, Zibin Zheng, Hongning Dai, Xu Chen 0004, Peilin Zheng
Inf. Process. Manag.5
2018 Detecting Ponzi Schemes on Ethereum: Towards Healthier Blockchain Technology
abstract
Blockchain technology becomes increasingly popular. It also attracts scams, for example, Ponzi scheme, a classic fraud, has been found making a notable amount of money on Blockchain, which has a very negative impact. To help dealing with this issue, this paper proposes an approach to detect Ponzi schemes on blockchain by using data mining and machine learning methods. By verifying smart contracts on Ethereum, we first extract features from user accounts and operation codes of the smart contracts and then build a classification model to detect latent Ponzi schemes implemented as smart contracts. The experimental results show that the proposed approach can achieve high accuracy for practical use. More importantly, the approach can be used to detect Ponzi schemes even at the moment of its creation. By using the proposed approach, we estimate that there are more than 400 Ponzi schemes running on Ethereum. Based on these results, we propose to build a uniform platform to evaluate and monitor every created smart contract for early warning of scams.
Weili Chen, Zibin Zheng, Jiahui Cui, Edith C. H. Ngai, Peilin Zheng
WWW5