Enhancing Reliability of Symbolic Execution Tools for Smart Contract Analysis through Rule-Based False Positive Reduction

📅 2026-08-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the high false positive rate of Mythril, a symbolic execution tool for Ethereum smart contract vulnerability detection. It presents the first systematic analysis of the root causes behind these false positives and introduces a novel rule-based filtering mechanism. By integrating symbolic execution with static analysis and employing tailored rules, the proposed approach accurately distinguishes genuine vulnerabilities from spurious reports across major vulnerability categories. Experimental results demonstrate that the method substantially reduces false positives without compromising detection completeness, thereby enhancing both the reliability and practical utility of Mythril in real-world smart contract analysis.
📝 Abstract
A blockchain is a decentralized, secure ledger system that enables transparent and immutable record-keeping, essential for trust and security in digital transactions. Smart contracts are self-executing agreements encoded on a blockchain, enabling different parties to fulfill the terms of the agreement automatically. These contracts trigger corresponding actions when conditions are met, ensuring decentralized and transparent transactions. Writing reliable smart contracts is challenging due to the lack of standardization. To find security vulnerabilities, tools based on various approaches, including symbolic execution, are used. However, these tools often report a large number of false positives, raising concerns about their reliability. The time and effort spent investigating false positives diverts resources from addressing actual vulnerabilities. Therefore, such tools must also be evaluated according to the rate of false positives they exhibit. More importantly, the algorithms and heuristics used by the tools must be enhanced to distinguish between true vulnerabilities and false alarms. In this paper, we first demonstrate the prevalence of false positives in vulnerability reports generated by Mythril, a symbolic execution-based analysis tool for Ethereum smart contracts. We analyze the root causes of these inaccuracies and devise a rule-based approach based on the gained insight to reduce false positives. We implement our rules for the most impactful vulnerabilities in Mythril and assess the effectiveness of our approach. Our results show a significant reduction in false positives without compromising the detection of true vulnerabilities, thus enhancing the tool's reliability.
Problem

Research questions and friction points this paper is trying to address.

symbolic execution
smart contracts
false positives
vulnerability analysis
blockchain security
Innovation

Methods, ideas, or system contributions that make the work stand out.

symbolic execution
false positive reduction
smart contract analysis
rule-based filtering
Mythril
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Muhammad Ali Hassan Ahmad
Lakehead University, Ontario, Canada
M
Muhammad Hashim Ali
National University of Computer and Emerging Sciences, Pakistan
M
Muhammad Ali Amer
National University of Computer and Emerging Sciences, Pakistan
Muhammad Naiman Jalil
Muhammad Naiman Jalil
College of Business and Economics - United Arab Emirates University
supply chain managementride sharing systemsspare parts logisticsafter sales servicerevenue management
M
Muhammad Hassan
German Research Center for Artificial Intelligence, Germany
A
Affan Rauf
National University of Computer and Emerging Sciences, Pakistan