Yingye Chen

dblp:348/0852 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2024
0009-0004-6465-7412ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 since 2021
YearPublicationVenuePosition
2024 Smart Contract Code Repair Recommendation based on Reinforcement Learning and Multi-metric Optimization
abstract
A smart contract is a kind of code deployed on the blockchain that executes automatically once an event triggers a clause in the contract. Since smart contracts involve businesses such as asset transfer, they are more vulnerable to attacks, so it is crucial to ensure the security of smart contracts. Because a smart contract cannot be tampered with once deployed on the blockchain, for smart contract developers, it is necessary to fix vulnerabilities before deployment. Compared with many vulnerability detection tools for smart contracts, the amount of automatic fix approaches for smart contracts is relatively limited. These approaches mainly use defined pattern-based methods or heuristic search algorithms for vulnerability repairs. In this article, we propose RLRep , a reinforcement learning-based approach to provide smart contract repair recommendations for smart contract developers automatically. This approach adopts an agent to provide repair action suggestions based on the vulnerable smart contract without any supervision, which can solve the problem of missing labeled data in machine learning-based repair methods. We evaluate our approach on a dataset containing 853 smart contract programs (programming language: Solidity) with different kinds of vulnerabilities. We split them into training and test sets. The result shows that our approach can provide 54.97% correct repair recommendations for smart contracts.
Hanyang Guo, Yingye Chen, Xiangping Chen, Yuan Huang 0002, Zibin Zheng
ACM Trans. Softw. Eng. Methodol.2
2023 Security Code Recommendations for Smart Contract
abstract
A smart contract is a self-executing program that is stored on the blockchain and runs when predetermined conditions are satisfied. Many frequent transactions involving asset transfers rely on smart contracts deployed on the blockchain, making them highly vulnerable to attack, thus it is essential to ensure the security of smart contracts. Since the smart contract is immutable once deployed, developers must try their best to fix existing vulnerabilities in advance to ensure security. Current approaches for automatic program repair on the smart contracts have mainly adopted the heuristic search algorithms or defined patterns to fix several well-defined types of vulnerabilities. They can only provide security code recommendations for developers in specific scenarios. We explore more general automated program repair of smart contracts in software history.To pave the way for studying code changes related to bug fix of smart contracts in software history, we present a labeled public dataset for method-level program repair task, containing over 12 typical insecure code patterns. Unlike bugs in traditional software, the vulnerabilities of smart contracts are more associated with access control and conditional statements as smart contracts pertain to financial assets. For this problem, we devise a novel double-encoder network and use a code representation designed for the smart contract based on syntax information to repair program. By implementing and evaluating our approach on new dataset comprised of over 10,000 program pairs, we demonstrate the superiority of our approach in both qualitative and quantitative aspects.
Xiaocong Zhou, Yingye Chen, Hanyang Guo, Xiangping Chen, Yuan Huang 0002
SANER2
2023 MDRL-IR: Incentive Routing for Blockchain Scalability With Memory-Based Deep Reinforcement Learning
abstract
Blockchain-based cryptocurrencies have developed rapidly in recent years, however, scalability is one of the biggest challenge. Payment channel networks (PCNs) are one of the important solutions to blockchain scalability and routing is the most critical problem in PCN. Routing algorithms in PCNs have evolved fast and achieved high throughput. However, most of these routing algorithms are designed from the perspective of technical feasibility, and few algorithms focus on the incentives of each off-chain participant, especially the economic incentives for intermediate routing nodes. Besides, due to the highly dynamic nature of off-chain channel deposits, existing routing algorithms rely heavily on channel deposit probing in order to ensure high throughput. In this article, we design routing algorithms from an incentive perspective to improve the profit of intermediate nodes and use deep learning to reduce the dependency of off-chain routing on channel deposit probing. Our experiments show that under the same model, MDRL-IR can increase the profit of intermediate nodes by up to 1.87x and increase the throughput by up to 2.0x compared to the state-of-the-art routing algorithm, while ensuring that the user routing cost per unit throughput remains unchanged. Moreover, approximate performance can be achieved when deposit probing is greatly reduced.
Bingxin Tang, Junyuan Liang, Zhongteng Cai, Ting Cai 0002, Xiaocong Zhou, Yingye Chen
IEEE Trans. Serv. Comput.6