Xiguo Gu

dblp:355/8160 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
8since 2021 · last 2025
0009-0004-2618-946XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 SCoVerLLM: Smart Contract Vulnerability Detection via LLM-Based In-Context and Chain-of-Thought Prompts
abstract
As a key application of the blockchain technology, smart contracts have been adopted in various domains such as finance and the Internet of Things. However, their potential vulnerabilities can lead to significant economic losses, efficient and accurate vulnerability detection methods are essential to guarantee their security. Existing methods mostly rely on predefined rules or classification models, which suffer from high maintenance costs and limited semantic understanding about the smart contracts. To address this issue, this paper proposes SCoVerLLM (Smart Contract Vulnerability Detection via LLM-Based In-Context and Chain-of-Thought Prompts), which is designed to enhance the performance of smart contract vulnerability detection by using LLMs. SCoVerLLM combines prediction information generated by deep learning models with similar contract examples, and leverages In-Context Learning prompts and structured Chain-of-Thought templates to guide LLMs in step-by-step analyzing the logic of contracts for vulnerability detection. Experimental results show that SCoVerLLM outperforms existing four methods, including MANDO and Mythril, in terms of multiple metrics, with improvements of 10.72% to 19.20% in Accuracy, 8.70% to 18.51% in Precision, and 10.09% to 25.08% in F1.
Xiguo Gu, Weili Xu, Zhanqi Cui, Liwei Zheng
SMC2
2025 A Change-Level Defect Prediction Approach based on Teacher-Student Network
abstract
Change-level defect prediction, also known as just-in-time (JIT) defect prediction, concentrates on predicting if a specific commit is likely to introduce defects. It effectively alleviates the limitations of traditional file-level defect prediction techniques, such as coarse-grained, hard to trace and poor timeliness. Currently, most change-level defect prediction techniques construct defect prediction models by using either expert features or semantic features. Recent studies have shown that the defect prediction performance can be enhanced by integrating these two types of features. However, obtaining expert features is not an easy task, due to missing historical data in real projects. To address the aforementioned problem, this paper proposes TS-SDP (Teacher–Student based Software Defect Prediction) based on teacher–student network. First, the source code is analyzed to extract expert features and semantic features. Then, a teacher–student network framework is constructed. In this framework, both features are used as inputs to the teacher network and only semantic features are used as inputs to the student network. The student network is enabled to learn about the expert features from the teacher network through the loss function. Finally, the student network is used to differentiate commits that are defect-inducing and those that are not, in the presence of only semantic features. The results of the experiments carried out on a dataset containing 21 different projects show that, when only semantic features are available, the cross-network knowledge dissemination between the teacher and student network makes it possible to predict defects. When compared to the state-of-the-art change-level defect prediction method, JIT-Fine, TS-SDP is 0.130, 0.114, 0.123 and 0.016 greater in [Formula: see text], [Formula: see text], F-measure and [Formula: see text], respectively.
Xinhong Duan, Xiguo Gu, Jiale Zhang 0002, Zhanqi Cui
Int. J. Softw. Eng. Knowl. Eng.2
2024 Detecting Smart Contract Vulnerabilities based on Fusing Semantic and Syntax Structure Information
abstract
Due to the widespread application and economic value of smart contracts, they have become targets for attackers, leading to significant economic losses from vulnerabilities. Therefore, it is crucial to detect potential vulnerabilities in smart contracts before they are deployed. However, existing machine learning approaches often overlook the type information of nodes and edges, while those based on heterogeneous graphs only utilize the semantic information of smart contracts, neglecting the syntax structure information. This oversight compromises the performance in detecting vulnerabilities. To address these issues, we propose a novel smart contract vulnerability detection approach named HG-Detector(Heterogeneous Graph Detector), which stands for Heterogeneous Graph Detector. This approach integrates semantic and syntax structure information by employing a heterogeneous graph neural network to analyze the source code of smart contracts. It extracts both semantic and syntax structure information and then uses a classifier to detect potential vulnerabilities. Experimental results on a dataset comprising 1269 smart contracts show that, compared to MANDO, HG-Detector has achieved an average increase of 10.06% in Precision, an average increase of 1.61% in Recall, an average increase of 2.29% in the F1, and an average increase of 4.78% in Accuracy across seven types of vulnerabilities
Xiguo Gu, Xinhong Duan, Senlin Ren, Jiale Zhang 0002, Zhanqi Cui
ISPA1
2024 Combining Deep Learning and Expert Rules for Smart Contract Vulnerability Detection
abstract
Smart contracts usually hold a large amount of digital assets, which can cause substantial losses if these contracts have vulnerabilities. Thus, it is essential to adequately detect possible vulnerabilities in smart contracts before deployment. There are many types of vulnerabilities in smart contracts, and different detection methods have their own unique advantages, some vulnerabilities may be more suitable for expert rule-based methods, while some vulnerabilities are more suitable for deep learning-based methods. A single detection method usually fails to fully use its ability to detect vulnerabilities. To address the above problems, we propose a composite approach named CDE-VD (Combining Deep Learning and Expert Rules for Smart Contract Vulnerability Detection) to improve the performance of vulnerability detection. The method divides smart contract samples into deep learning-prone sam-ples and expert rule-prone samples by classifying them before detection, and extracts expert rule features to train the smart contract detection method classifier to predict the category of the samples under analysis, then selects the suitable method for detection. The experimental results show that the vulnerability detection performance of CDE-VD outperforms that of single detection methods. Compared with the SOTA method MANDO, CDE-VD achieves average improvements of 3.22%, 2.32%, 9.25%, and 6.54% in terms of the Accuracy, Precision, Recall, and F1-score for five categories of vulnerabilities such as access control and time manipulation, respectively, which indicates that category prediction of the smart contract samples could improve vulnerability detection performance.
Senlin Ren, Xiguo Gu, Liwei Zheng, Zhanqi Cui
SMC3
2024 CrossFuzz: Cross-contract fuzzing for smart contract vulnerability detection
abstract
Smart contracts are computer programs that run on a blockchain. As the functions implemented by smart contracts become increasingly complex, the number of cross-contract interactions within them also rises. Consequently, the combinatorial explosion of transaction sequences poses a significant challenge for smart contract security vulnerability detection. Existing static analysis-based methods for detecting cross-contract vulnerabilities suffer from high false-positive rates and cannot generate test cases, while fuzz testing-based methods exhibit low code coverage and may not accurately detect security vulnerabilities. The goal of this paper is to address the above limitations and efficiently detect cross-contract vulnerabilities. To achieve this goal, we present CrossFuzz, a fuzz testing-based method for detecting cross-contract vulnerabilities. First, CrossFuzz generates parameters of constructors by tracing data propagation paths. Then, it collects inter-contract data flow information. Finally, CrossFuzz optimizes mutation strategies for transaction sequences based on inter-contract data flow information to improve the performance of fuzz testing. We implemented CrossFuzz, which is an extension of ConFuzzius, and conducted experiments on a real-world dataset containing 396 smart contracts. The results show that CrossFuzz outperforms xFuzz, a fuzz testing-based tool optimized for cross-contract vulnerability detection, with a 10.58% increase in bytecode coverage. Furthermore, CrossFuzz detects 1.82 times more security vulnerabilities than ConFuzzius. Our method utilizes data flow information to optimize mutation strategies. It significantly improves the efficiency of fuzz testing for detecting cross-contract vulnerabilities.
Huiwen Yang, Xiguo Gu, Xiang Chen 0005, Liwei Zheng, Zhanqi Cui
Sci. Comput. Program.2
2023 Smart Contract Vulnerability Detection Based on Clustering Opcode Instructions
abstract
Smart contracts are programs running on the blockchain.In recent years, due to the continuous occurrence of smart contract security accidents, how to effectively detect vulnerabilities in smart contracts has received extensive attention.Machine learning-based vulnerability detection techniques have the advantage of not requiring expert rules.However, existing approaches have limitations in identifying vulnerabilities caused by version updates of smart contract compilers.In this paper, we propose OC-Detector, a smart contract vulnerabilities detection approach based on opcode instruction clustering.OC-Detector learns the characteristics of opcode instructions to cluster them and replaces opcode instructions belonging to the same cluster with the cluster number.After that, the similarity is calculated against the contract in the vulnerability database to identify vulnerabilities.Experimental results demonstrate that OC-Detector improves the F 1 value of detecting vulnerabilities from 0.04 to 0.40 compared to DC-Hunter, Securify, SmartCheck, and Osiris.Additionally, compared to DC-Hunter, F 1 value is improved by 0.27 when detecting vulnerabilities in smart contracts compiled by different version compilers.
Xiguo Gu, Huiwen Yang, Shifan Liu, Zhanqi Cui
SEKE1
2023 Fuzz Testing Based on Seed Diversity Analysis
abstract
Fuzz testing is a widely used technique to detect software defects and vulnerabilities. Coverage-guided fuzzing aims to improve code coverage by generating offspring test cases through mutation, executing the program under test, and retaining interesting seeds for subsequent mutations using customized genetic algorithms. However, existing fuzzing tools rarely consider the similarity between seeds during mutation. Mutating similar seeds frequently generates similar offspring test cases, which results in similar coverage and reduces the efficiency of fuzz testing. To alleviate the impact of this problem on fuzz testing, this paper proposes a fuzz testing method based on seed diversity analysis, which focuses on the characteristics of seeds and uses byte sequences as a feature to measure the similarity between seeds. It collects seeds that can cover new edges and constructs a shorter seed queue with significant differences based on this feature, which replaces the original seed queue for mutation. Based on the proposed method, we implement the prototype tools AFL-Varied and Neuzz-Varied. Compared with AFL and Neuzz on six projects, the edge coverage and basic block coverage can be increased by 214.57% and 233.33 % at most, respectively.
Wenwei Lan, Zhanqi Cui, Jiaming Zhang 0008, Xiguo Gu
SMC5
2023 OC-Detector: Detecting Smart Contract Vulnerabilities Based on Clustering Opcode Instructions
abstract
Smart contracts are programs running on blockchain. In recent years, due to the persistent occurrence of security-related accidents in smart contracts, the effective detection of vulnerabilities in smart contracts has received extensive attention from researchers and engineers. Machine learning-based vulnerability detection techniques have the advantage that they do not need expert rules for determining vulnerabilities. However, existing approaches cannot identify vulnerabilities when the versions of smart contract compilers are updated. In this paper, we propose OC-Detector (Opcode Clustering Detector), a smart contract vulnerability detection approach based on clustering opcode instructions. OC-Detector learns the characteristics of opcode instructions to cluster them and replaces opcode instructions belonging to the same cluster with the ID of the cluster. After that, the similarity between the contract under analysis and contracts in the vulnerability database is calculated to identify vulnerabilities. The experimental results demonstrate that OC-Detector improves the F1 value of detecting vulnerabilities from 0.04 to 0.40 compared to DC-Hunter, Securify, SmartCheck and Osiris. Additionally, compared to DC-Hunter, the F1 value is improved by 0.27 when detecting vulnerabilities in smart contracts compiled by different versions of compilers.
Xiguo Gu, Liwei Zheng, Huiwen Yang, Shifan Liu, Zhanqi Cui
Int. J. Softw. Eng. Knowl. Eng.1