Reinforcement Learning-Guided Symbolic Execution for Efficient and Exploitable Smart Contract Analysis
Abstract
Currently, frequent security incidents of Ethereum contracts have caused billions of dollars in losses. There is a pressing need to identify defective contract code and generate exploit call sequences to reproduce attacks and ensure detection accuracy. Nevertheless, the state-of-the-art (SOTA) detection methods based on symbolic execution and fuzzy testing cannot achieve the desired performance due to the state explosion problem caused by contract characteristics such as cross-contract calls and loop branches, especially in large wild contracts. To tackle this problem, we propose RSymX, an assembly strategy-guided symbolic execution for contracts that leverages reinforcement learning to dynamically balance code coverage and vulnerability discovery. Extensive experiments on open-sourced datasets demonstrate that RSymX achieves an overlap score of 92.39% and identifies many vulnerable wild instances that SOTAs misreport. Especially, its dynamic strategies improve the efficiency of state exploration by 2x~4x, and in some cases up to 10x, offering guidance for future symbolic-execution-based analyzers. The code and data are available in https://github.com/ContractAudit/Code.