Jie Cai 0006

dblp:95/3916-6 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
7since 2021 · last 2025
0009-0000-9578-8985ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 4 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Detecting Reentrancy Vulnerabilities for Solidity Smart Contracts With Contract Standards-Based Rules
abstract
The reentrancy vulnerability is one of the most notorious vulnerabilities of smart contracts. It enables attackers to hijack the control flow of a smart contract by invoking a function as the entry point and then re-invoking a function as the reentry point before the execution of the entry point ends. Although several approaches have been proposed to detect this vulnerability, they still face two main limitations. Firstly, existing approaches oversimplify the rules for identifying entry and reentry points, and many even neglect reentry point identification during vulnerability detection. Secondly, most existing approaches overlook the flow of state variables that are not promptly updated, a critical aspect of the reentrancy vulnerability. To address the limitations mentioned above, this article proposes a novel static analysis framework for reentry vulnerability detection. We formulate the reentrancy vulnerability detection as entry and reentry point identification with the state variable flow tracking. Based on the insight that most smart contracts are implemented following various technical standards, we utilize static analysis with standard-based rules to identify potential entry and reentry points. This is achieved by detecting the presence of hijackable and exploitable operations inside the smart contract. Meanwhile, we also conduct state variable flow tracking by the static taint analysis. To verify the effectiveness of our proposed approach, we construct three different datasets. Then We compare our approach with eight state-of-the-art smart contract vulnerability detectors, and our tool outperforms these baselines in detecting more vulnerable samples with fewer false positive samples. Meanwhile, our approach achieves a relatively shorter detection time with better detection results, striking a trade-off between effectiveness and efficiency.
Jie Cai 0006, Jiachi Chen, Tao Zhang 0001, Xiapu Luo, Xiaobing Sun 0001, Bin Li 0006
IEEE Trans. Inf. Forensics Secur.1
2024 Fine-grained smart contract vulnerability detection by heterogeneous code feature learning and automated dataset construction
Jie Cai 0006, Bin Li 0006, Tao Zhang 0001, Jiale Zhang 0001, Xiaobing Sun 0001
J. Syst. Softw.1
2024 Application programming interface recommendation for smart contract using deep learning from augmented code representation
abstract
Abstract Application programming interface (API) recommendation plays a crucial role in facilitating smart contract development by providing developers with a ranked list of candidate APIs for specific recommendation points. Deep learning‐based approaches have shown promising results in this field. However, existing approaches mainly rely on token sequences or abstract syntax trees (ASTs) for learning recommendation point‐related features, which may overlook the essential knowledge implied in the relations between or within statements and may include task‐irrelevant components during feature learning. To address these limitations, we propose a novel code graph called pruned and augmented AST (pa‐AST). Our approach enhances the AST by incorporating additional knowledge derived from the control and data flow relations between and within statements in the smart contract code. Through this augmentation, the pa‐AST can better represent the semantic features of the code. Furthermore, we conduct AST pruning to eliminate task‐irrelevant components based on the identified flow relations. This step helps mitigate the interference caused by these irrelevant parts during the model feature learning process. Additionally, we extract the API sequence surrounding the recommendation point to provide supplementary knowledge for the model learning. The experimental results demonstrate our proposed approach achieving an average mean reciprocal rank (MRR) of 68.02%, outperforming the baselines' performance. Furthermore, through ablation experiments, we explore the effectiveness of our proposed code representation approach. The results indicate that combining pa‐AST with the API sequence yields improved performance compared with using them individually. Moreover, our AST augmentation and pruning techniques significantly contribute to the overall results.
Jie Cai 0006, Qian Cai, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001
J. Softw. Evol. Process.1
2024 Ponzi Scheme Detection in Smart Contract via Transaction Semantic Representation Learning
abstract
The Ponzi scheme implemented through smart contracts is one of the most common scams on the blockchain platform. Although various learning-based Ponzi smart contract detection approaches have been proposed, they still suffer from several limitations, i.e., 1) extracting insufficient semantics and gathering Ponzi irrelevant components from the smart contract during feature engineering, and 2) underutilizing structured semantic features during model training. As the Ponzi scheme is an economic crime with the typical Rob-Peter-to-Pay-Paul transaction pattern, we propose a transaction semantic learning based approach to mitigate the above limitations. The fundamental idea of our approach is to represent the transaction-related semantics of a smart contract as a graph and utilize a graph convolutional network (GCN) to learn the potential Ponzi-like transaction pattern from it. We define a novel code representation named slice transaction property graph (sTPG) to represent the transaction-related semantics, which can encode multiple transaction-related semantics inside a smart contract function into a graph and eliminate other irrelevant fragments. Then, we propose a relation-sensitive GCN as the learning model to identify potential Ponzi-scheme-like transaction patterns from sTPG by considering both nodes and edges features in sTPG. We evaluate our approach on two datasets: 1) smart contracts collected from Forum and Public datasets, and 2) really deployed smart contracts on the Ethereum blockchain. The experiment results show that our approach outperforms the state-of-the-art learning-based approaches.
Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001
IEEE Trans. Reliab.1
2023 Extended Abstract of Combine Sliced Joint Graph with Graph Neural Networks for Smart Contract Vulnerability Detection
abstract
Existing smart contract vulnerability detection efforts heavily rely on fixed rules defined by experts, which are inefficient and inflexible. To overcome the limitations of existing vulnerability detection approaches, we propose a GNN based approach. First, we construct a graph representation for a smart contract function with syntactic and semantic features by combining abstract syntax tree (AST), control flow graph (CFG), and program dependency graph (PDG). To further strengthen the presentation ability of our approach, we perform program slicing to normalize the graph and eliminate the redundant information unrelated to vulnerabilities. Then, we use a Bidirectional Gated Graph Neural-Network model with hybrid attention pooling to identify potential vulnerabilities in smart contract functions. Experiment results show that our approach can achieve 89.2% precision and 92.9% recall in smart contract vulnerability detection on our dataset and reveal the effectiveness and efficiency of our approach.
Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002
SANER1
2023 ASSBert: Active and semi-supervised bert for smart contract vulnerability detection
Xiaobing Sun 0001, Liangqiong Tu, Jiale Zhang 0001, Jie Cai 0006, Bin Li 0006, Yu Wang 0017
J. Inf. Secur. Appl.4
2023 Combine sliced joint graph with graph neural networks for smart contract vulnerability detection
Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002
J. Syst. Softw.1