[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83610-en":3,"doc-seo-83610-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83610,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Knowledge Over Parameters: Evolving Smart Contract Vulnerability Detection","Smart contract vulnerabilities are logic bugs that require structured, step-by-step procedural knowledge of attack patterns and contract semantics. Existing LLM approaches struggle because prompt methods need manual rules and fine-tuning is limited by scarce labeled data. EVOVULN is an automated framework that reformulates detection as procedural knowledge evolution, using only minimal labeled samples. It compiles rules into Executable Policies via IoC and refines them through two-phase abductive semantic debugging with few-shot examples.","Knowledge Over Parameters: Evolving Smart Contract Vulnerability Detection  \nYuqiang Sun∗ , Han Liu†, Ying Li‡, Yiran Zhang∗ , Zong Cao§ , Ziyun Guo¶ , Yang Liu∗  \n∗ Nanyang Technological University, Singapore  \n[yuqiang.sun@ntu.edu.sg](yuqiang.sun@ntu.edu.sg), [yiran002@e.ntu.edu.sg](yiran002@e.ntu.edu.sg), [yangliu@ntu.edu.sg](yangliu@ntu.edu.sg)  \n†Nankai University, China [hanliu@nankai.edu.cn](hanliu@nankai.edu.cn)  \n‡University of California, Los Angeles, USA [ying.li@ucla.edu](ying.li@ucla.edu)  \n§ Imperial Global Singapore, Imperial College London, and Nanyang Technological University [z.cao@imperial.ac.uk](z.cao@imperial.ac.uk)[ ](z.cao@imperial.ac.uk)¶ Singapore Management University, Singapore [zyguo@smu.edu.sg](zyguo@smu.edu.sg)  \narXiv :2607 .0 1742v 1 [ cs .CR] 2 Jul 2026  \nAbstract—Smart contract vulnerabilities are predominantly logic bugs whose detection requires structured, step-by-step procedural knowledge of attack patterns and contract semantics. Existing LLM-based methods struggle to generate this knowledge automatically: prompt-based methods rely on manually crafted detection rules, while fine-tuning requires massive labeled datasets that are inherently scarce in this domain. We present EVOVULN, an automated framework that reformulates vulnerability detection as a procedural knowledge evolution problem, synthesizing and refining detection logic using only a minimal number of labeled samples. To achieve this, EVOVULN introduces two key mechanisms. First, a Runtime with an Inversion of Control (IoC) architecture compiles detection rules into Executable Policies. This strictly decouples deterministic control flow from LLM semantic reasoning, ensuring faithful logical adherence and producing dense diagnostic telemetry for precise error localization. Second, a two-phase evolution pipeline refines the rule via abductive semantic debugging without any parameter updates: Cold Start bootstraps and stress-tests an initial rule using auto-synthesized corner cases; Few-Shot Evolving then grounds the policy in real-world semantics using only five vulnerable and five safe examples per vulnerability type.  \nEvaluated across five real-world vulnerability types, EVOVULN achieves a 71% macro-average F1-score, outperforming all baselines. The evolved procedural knowledge is portable across models: it enables a lightweight, low-cost model to surpass a much larger zero-shot model by 19 percentage points, and transfers to other LLMs without retraining, at a one-time evolution cost under $50.  \nI. INTRODUCTION  \nSmart contracts are high-stakes programs governing decentralized finance (DeFi), where logic bugs, such as price manipulation and access control flaws, frequently lead to massive financial losses [1] . Unlike syntactic errors, these logic flaws depend on semantic intent, requiring structured, multi-step procedural knowledge to verify if a contract violates application-level invariants.  \nCurrent detection paradigms face a fundamental bottleneck. Prompt-based methods rely on manually authored rules [2– 4], which are labor-intensive and fail to scale to emerging threats. Conversely, fine-tuning approaches [5–7] attempt to learn detection patterns directly, yet are constrained by the severe scarcity of labeled data. Neither paradigm supports the automated generation or evolution of detection logic.  \nInspired by the agentic “skill” paradigm, which encodes reusable, task-specific capabilities to avoid reasoning from scratch [8–10], we view vulnerability detection as the synthesis of procedural knowledge: structured rules that dictate semantic inspection steps. Existing methods like GPTScan [2] essentially instantiate this paradigm with human-authored rules, but they leave three critical gaps:  \nFirst, current procedural knowledge relies entirely on human experts, making it unscalable for emerging vulnerability types. When relying on LLMs to generate this knowledge automatically, the generated procedures are often flawed or","cbCaiedKGQbYdnkL","https://ap.wps.com/l/cbCaiedKGQbYdnkL","pdf",404800,4,1,12,"English","en",105,"# I. Introduction\n## Procedural knowledge bottlenecks in existing methods\n## EVOVULN framework: IoC-controlled execution\n## EVOVULN framework: abductive knowledge evolution\n## Knowledge transfer across models","[{\"question\":\"What problem does EVOVULN address in smart contract vulnerability detection?\",\"answer\":\"Existing methods cannot automatically generate and evolve detection logic effectively: prompt-based approaches require manual rules, and fine-tuning is constrained by scarce labeled data. EVOVULN targets this by generating procedural detection knowledge from minimal labeled samples.\"},{\"question\":\"How does EVOVULN ensure generated detection logic is executed faithfully?\",\"answer\":\"EVOVULN compiles detection rules into Executable Policies using a runtime with inversion of control (IoC). This decouples deterministic control flow from LLM semantic reasoning so the agent follows the prescribed multi-step logic.\"},{\"question\":\"What is the evolution process used by EVOVULN without parameter updates?\",\"answer\":\"EVOVULN uses a two-phase evolution pipeline with cold-start bootstrapping and stress-testing via auto-synthesized corner cases, followed by few-shot evolving that grounds the policy using five vulnerable and five safe examples per vulnerability type.\"}]",1784189251,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"knowledge-over-parameters-evolving-smart-contract-vulnerability-detection","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/knowledge-over-parameters-evolving-smart-contract-vulnerability-detection/83610/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does EVOVULN address in smart contract vulnerability detection?","Question",{"text":75,"@type":76},"Existing methods cannot automatically generate and evolve detection logic effectively: prompt-based approaches require manual rules, and fine-tuning is constrained by scarce labeled data. EVOVULN targets this by generating procedural detection knowledge from minimal labeled samples.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does EVOVULN ensure generated detection logic is executed faithfully?",{"text":80,"@type":76},"EVOVULN compiles detection rules into Executable Policies using a runtime with inversion of control (IoC). This decouples deterministic control flow from LLM semantic reasoning so the agent follows the prescribed multi-step logic.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the evolution process used by EVOVULN without parameter updates?",{"text":84,"@type":76},"EVOVULN uses a two-phase evolution pipeline with cold-start bootstrapping and stress-testing via auto-synthesized corner cases, followed by few-shot evolving that grounds the policy using five vulnerable and five safe examples per vulnerability type.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]