Skip to main navigation Skip to search Skip to main content

Advanced Smart Contract Vulnerability Detection via LLM-Powered Multi-Agent Systems

  • Zhiyuan WEI
  • , Jing SUN
  • , Yuqiang SUN
  • , Ye LIU
  • , Daoyuan WU
  • , Zijian ZHANG
  • , Xianhao ZHANG
  • , Meng LI
  • , Yang LIU
  • , Chunmiao LI
  • , Mingchao WAN
  • , Jin DONG
  • , Liehuang ZHU

Research output: Journal PublicationsJournal Article (refereed)peer-review

Abstract

Blockchain’s inherent immutability, while transformative, creates critical security risks in smart contracts, where undetected vulnerabilities can result in irreversible financial losses. Current auditing tools and approaches often address specific vulnerability types, yet there is a need for a comprehensive solution that can detect a wide range of vulnerabilities with high accuracy. We propose LLM-SmartAudit, a novel framework that leverages Large Language Models (LLMs) to automate smart contract vulnerability detection and analysis. Using a multi-agent conversational architecture with a bufferof-thought mechanism, LLM-SmartAudit maintains a dynamic record of insights generated throughout the audit process. This enables a collaborative system of specialized agents to iteratively refine their assessments, enhancing the accuracy and depth of vulnerability detection. To evaluate its effectiveness, LLMSmartAudit was tested on three datasets: a benchmark for common vulnerabilities, a real-world project corpus, and a CVE dataset. It outperformed existing tools with 98% accuracy on common vulnerabilities and demonstrates higher accuracy in real-world scenarios. Additionally, it successfully identifies 12 out of 13 CVEs, surpassing other LLM-based methods. These results demonstrate the effectiveness of multi-agent collaboration in automated smart contract auditing, offering a scalable, adaptive, and highly efficient solution for blockchain security analysis.
Original languageEnglish
Pages (from-to)2830-2846
Number of pages17
JournalIEEE Transactions on Software Engineering
Volume51
Issue number10
Early online date11 Aug 2025
DOIs
Publication statusPublished - Oct 2025

Bibliographical note

Publisher Copyright:
© 1976-2012 IEEE.

Keywords

  • LLMs
  • Smart contract auditing
  • multi-agent
  • vulnerability detection

Fingerprint

Dive into the research topics of 'Advanced Smart Contract Vulnerability Detection via LLM-Powered Multi-Agent Systems'. Together they form a unique fingerprint.

Cite this