arrow
Return

fFuzz: A State-Aware Function-Level Fuzzing Framework for Smart Contract Vulnerabilities Detection

delete2026-01-01
delete0
PRE
AI
C
Chang Li
L
Lu, Binqin
W
Wenyang Zhang
K
Kaixuan Yang
H
Huijuan Zhu *
DOI:10.1007/978-981-95-3543-9_2delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Smart contract vulnerabilities have resulted in substantial financial losses in recent years. Fuzzing, an effective technique for detecting vulnerabilities, has rapidly emerged as a key approach for safeguarding the security of smart contracts. However, due to the complexity and unique stateful nature of smart contracts, existing fuzzing tools struggle to detect sophisticated vulnerabilities, particularly those requiring specific transaction sequences to trigger. In this work, we propose fFuzz, a novel function-level fuzzer for smart contract vulnerability detection. Unlike conventional fuzzers that generate transaction sequences for the entire smart contract, fFuzz targets precise and effective sequences at the function level, streamlining and improving the fuzzing process. In addition, fFuzz incorporates a state-aware signature generation mechanism and a historical transaction-guided strategy to effectively generate vulnerable transaction sequences, which are further used to trigger vulnerabilities. We evaluated fFuzz on real-world smart contracts, and the experimental results demonstrate that it outperforms state-of-the-art methods in both effectiveness and efficiency.
Keywords:
Smart Contract
Vulnerability Detection
Fuzzing

Journal

I
INFORMATION AND COMMUNICATIONS SECURITY, ICICS 2025, PT II
IF:
0
Papers:
25
Citations:
0

Organization

J
jiangsu university
Scholars:
9.2K
Papers: 2.7K
Citations: 1