Zhangyan Lin

dblp:397/3718 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 83% Compilers and program optimization · 17%
Network and information security
1 paper
Blockchain and cryptocurrency security · 100%

Topics — the 7 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Blockchain and cryptocurrency security › smart contract analysis
smart contract defect detection
0.912025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Blockchain and cryptocurrency security
smart contract security
0.912025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Program analysis
smart contract analysis
0.912025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Program analysis
static analysis
0.912025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Program analysis › static analysis
taint analysis
0.912025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Compilers and program optimization
intermediate representation
0.312025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025
Compilers and program optimization › intermediate representation
static single assignment form
0.312025
Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects · ICSE 2025

Methods — techniques the papers use, named apart from their topics

taint analysis · 1.7static analysis · 1.7data dependency analysis · 1.7control flow graph · 1.7
YearPublicationVenuePosition
2025 Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects
abstract
The Open Network (TON), designed to support Telegram's extensive user base of hundreds of millions, has garnered considerable attention since its launch in 2022. FunC is the most popular programming language for writing smart contracts on TON. It is distinguished by a unique syntax compared to other smart contract languages. Despite growing interest, research on the practical defects of TON smart contracts is still in its early stages. In this paper, we summarize eight smart contract defects identified from TON's official blogs and audit reports, each with detailed definitions and code examples. Furthermore, we propose a static analysis framework called TONScanner to facilitate the detection of these defects. Specifically, TONScanner reuses FunC compiler's frontend code to transform the FunC source code into FunC intermediate representation (IR) in the form of a directed acyclic graph (DAG). Based on this IR, TONScanner constructs a control flow graph (CFG), then transforms it into a static single assignment (SSA) form to simplify further analysis. TONScanner also integrates Data Dependency, Call Graph, Taint Analysis, and Cell Construct, which are specifically tailored for TON blockchain's unique data structures. These components finally facilitate the identification of the eight defects. We evaluate the effectiveness of TONScanner by applying it to 1,640 smart contracts and find a total of 14,995 defects. Through random sampling and manual labeling, we find that TONScanner achieves an overall precision of 97.49%. The results reveal that current TON contracts contain numerous defects, indicating that developers are prone to making errors. TONScanner has proven its ability to accurately identify these defects, thereby aiding in their correction.
Jiachi Chen, Ting Chen 0002, Beibei Li 0002, Zhangyan Lin, Xihan Zhou
ICSE6
2025 Exploring the potential of ChatGPT in detecting logical vulnerabilities in smart contracts
abstract
With the rapid expansion of blockchain applications, smart contracts are becoming increasingly complex, making the automated detection of contract vulnerabilities more critical than ever. Large language models, due to their advanced code comprehensive ability, are considered to have the potential to undertake the task of automated software vulnerability discovery. Although there have been empirical studies on ChatGPT's automated discovery of contract vulnerabilities, the current empirical research has not addressed how well ChatGPT can detect logical vulnerabilities in smart contracts or whether ChatGPT's detection performance for logical vulnerabilities can be improved. To fill this gap, this study collected and organized seven types of logical vulnerability source codes from 6165 real smart contract audit reports and three datasets, such as Web3Bugs, and used this database to validate ChatGPT's detection capability for logical vulnerabilities. To improve ChatGPT's accuracy in detecting logical vulnerabilities, we fine-tuned ChatGPT with a dataset marked with a specific method, achieving an average accuracy rate of 95% for single vulnerability detection per training session. We improved the original marking method to increase further the number of vulnerabilities that a single model can detect. We used a specific completion marking format, ultimately enabling ChatGPT to detect various logical vulnerabilities. In terms of enhancing model scalability, we found a special training set marking method that allows for the addition of detectable vulnerability types through secondary training.
Jiachi Chen, Ting Chen 0002, Renkai Jiang, Yuqiao Yang, Zhangyan Lin, Yuanyao Cheng
Blockchain Res. Appl.8
2025 Phone-to-EDU: A Smart Contract-Based Framework for Comprehensive Management of GAI-Assisted Programming Courses
abstract
Smartphones are widely used Internet of Things (IoT) devices in higher education, but relying on them alone does not sufficiently aid teachers in managing courses or improving student learning. For teachers, managing course progress through predefined rules and safeguarding student privacy at key stages is challenging. Likewise, students lack targeted learning assistance to enhance their capabilities. Therefore, a comprehensive scheme is essential to address these challenges effectively. In this paper, we propose a novel framework based on smart contracts and integrated with generative artificial intelligence (GAI) assistance. This framework manages programming courses and enhances student learning, with smartphones serving as access points. It leverages smart contracts to dynamically manage the entire course lifecycle, with contracts built upon access control policies to ensure that only authorized roles can access course resources via smartphone. The proposed framework is based on a consortium network. GAI model-ChatGPT-4o provides code generation and code explanation assistance in programming courses. We select the optimal prompt templates and store them on the blockchain, allowing GAI to provide more precise services using them. We implement and evaluate the proposed framework using the Hyperledger Fabric blockchain, demonstrating its effectiveness and scalability in real-world scenarios. Additionally, we evaluate the code-related content generated by the prompt templates using three criteria: pass rate, time spent, and number of votes. This evaluation confirms that the templates selected and recorded on the blockchain are optimal. The framework can be easily adapted to other scenarios such as course management, record management, and research collaboration.
Leixin Guo, Beibei Li 0002, Zhangyan Lin, Wenfei Ge
IEEE Internet Things J.5