EDBT 2026 Demo / reviewers in the wild / expert
Zhenzhe Shao
dblp:401/9761
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0009-2993-7482ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Blockchain and cryptocurrency security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Program synthesis and code generation · 100% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Blockchain and cryptocurrency security
smart contract security |
0.9 | 1 | 2025 | NumScout: Unveiling Numerical Defects in Smart Contracts Using LLM-Pruning Symbolic Execution · IEEE Trans. Software Eng. 2025 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
0.9 | 1 | 2025 | NumScout: Unveiling Numerical Defects in Smart Contracts Using LLM-Pruning Symbolic Execution · IEEE Trans. Software Eng. 2025 |
Program synthesis and code generation
code generation evaluation |
0.9 | 1 | 2025 | SolContractEval: A Benchmark for Evaluating Contract-Level Solidity Code Generation · ASE 2025 |
Methods — techniques the papers use, named apart from their topics
transaction replay · 0.9symbolic execution · 0.9large language model pruning · 0.9large language model · 0.9dynamic evaluation · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SolContractEval: A Benchmark for Evaluating Contract-Level Solidity Code GenerationabstractThe rise of blockchain has brought smart contracts into mainstream use, creating a demand for smart contract generation tools. While large language models (LLMs) excel at generating code in general-purpose languages, their effectiveness on Solidity, the primary language for smart contracts, remains underexplored. Solidity constitutes only a small portion of typical LLM training data and differs from general-purpose languages in its version-sensitive syntax and limited flexibility. These factors raise concerns about the reliability of existing LLMs for Solidity code generation. Critically, existing evaluations, focused on isolated functions and synthetic inputs, fall short of assessing models’ capabilities in real-world contract development.To bridge this gap, we introduce SolContractEval, the first contract-level benchmark for Solidity code generation. It comprises 124 tasks drawn from real on-chain contracts across nine major domains. Each task input, consisting of complete context dependencies, a structured contract framework, and a concise task prompt, is independently annotated and cross-validated by experienced developers. To enable precise and automated evaluation of functional correctness, we also develop a dynamic evaluation framework based on historical transaction replay. Building on SolContractEval, we perform a systematic evaluation of six mainstream LLMs. We find that Claude-3.7-Sonnet achieves the highest overall performance, though evaluated models underper-form relative to their capabilities on class-level generation tasks in general-purpose programming languages. Second, current models perform better on tasks that follow standard patterns but struggle with complex logic and inter-contract dependencies. Finally, they exhibit limited understanding of Solidity-specific features and contextual dependencies. Zhifan Ye, Jiachi Chen, Zhenzhe Shao, Lingfeng Bao, Xiaohu Yang 0001, Zhongxin Liu 0002 |
ASE | 3 |
| 2025 | NumScout: Unveiling Numerical Defects in Smart Contracts Using LLM-Pruning Symbolic ExecutionabstractIn recent years, the Ethereum platform has witnessed a proliferation of smart contracts, accompanied by exponential growth in total value locked (TVL). High-TVL smart contracts often require complex numerical computations, particularly in mathematical financial models used by many decentralized applications (DApps). Improper calculations can introduce numerical defects, posing potential security risks. Existing research primarily focuses on traditional numerical defects like integer overflow, and there is currently a lack of systematic research and effective detection methods targeting new types of numerical defects. In this paper, we identify five new types of numerical defects through the analysis of 1,199 audit reports by utilizing the open card method. Each defect is defined and illustrated with a code example to highlight its features and potential consequences. We also propose NumScout, a symbolic execution-based tool designed to detect these five defects. Specifically, the tool combines information from source code and bytecode, analyzing key operations such as comparisons and transfers, to effectively locate defects and report them based on predefined detection patterns. Furthermore, NumScout uses a large language model (LLM) to prune functions which are unrelated to numerical operations. This step allows symbolic execution to quickly enter the target function and improve runtime speed by 28.4%. We run NumScout on 6,617 real-world contracts and evaluated its performance based on manually labeled results. We find that 1,774 contracts contained at least one of the five defects, and the tool achieved an overall precision of 89.7%. Jiachi Chen, Zhenzhe Shao, Shuo Yang 0012, Yanlin Wang 0001, Ting Chen 0002, Zhenyu Shan, Zibin Zheng |
IEEE Trans. Software Eng. | 2 |