Minh-Dai Tran-Duong, Nguyen Hai Phong, Nguyen Chi Thanh, Doan Minh Trung, Tram Truong-Huu, Van-Hau Pham, Phan The Duy · Singapore Institute of Technology 2026 · 2026
DOI: 10.25447/sit.24219670
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Smart contracts are increasingly targeted by adversaries employing obfuscation techniques such as bogus code injection and control-flow manipulation to evade vulnerability detection. Existing multimodal methods often process semantic, temporal, and structural features in isolation and fuse them using simple strategies such as concatenation. This limits cross-modal interaction and weakens robustness when one modality is obfuscated. To address these challenges, we propose ContractShield, a multimodal framework with a three-stage hierarchical fusion mechanism. The first stage refines each modality independently, the second enables directed pairwise information exchange across modalities, and the final stage applies adaptive weighting to the three representations, recomputed for each contract. ContractShield encodes (1) Solidity source code with sliding-window CodeBERT, (2) opcode sequences with xLSTM (Extended Long Short-Term Memory), and (3) bytecode-derived control flow graphs (CFGs) with Graph Attention Network version 2 (GATv2). On clean data, ContractShield achieves an 89% Hamming Score and a 91% F1-score across five vulnerability types. Under obfuscation, its Hamming Score decreases by only 1.22–3.42 percentage points while remaining above 73%, compared with 4.10–5.30 for concatenation-based fusion using the same three encoders and 2.24–20.84 for single-stage attention-based fusion baselines, whose Hamming Score falls as low as 39.27%. ContractShield also outperforms the strongest baseline by 3.66–11.82 F1-score points across all obfuscation settings and test sets. These results demonstrate that hierarchical cross-modal fusion improves robustness to obfuscation and supports more reliable smart contract vulnerability detection.
No comments yet — start the discussion below.