Evidence · DiggingBeagle record
DG-VDT: Dynamic Graph-Guided Reinforcement Learning for Low-Latency Vulnerability Detection and Attack Traceability in Ethereum Smart Contracts
Applied Sciences article published September 30, 2026 describing DG-VDT, a graph-guided reinforcement-learning framework that operates on EVM execution traces. The paper reports zero-shot detection results on SolidiFI-Bench and SmartBugs Wild, architecture and reward ablations, traceability experiments, training cost, leakage controls, statistical tests, adversarial-obfuscation considerations and explicit limitations. Its strongest public generalization evidence remains author-run evaluation on third-party corpora; the complete experimental pipeline, author-constructed datasets and pretrained weights are not publicly deposited.
- Published
- Sep 30, 2026
- Publisher
- Applied Sciences / MDPI
- Source role
- primary disclosure
Evidence record
Applied Sciences article published September 30, 2026 describing DG-VDT, a graph-guided reinforcement-learning framework that operates on EVM execution traces. The paper reports zero-shot detection results on SolidiFI-Bench and SmartBugs Wild, architecture and reward ablations, traceability experiments, training cost, leakage controls, statistical tests, adversarial-obfuscation considerations and explicit limitations. Its strongest public generalization evidence remains author-run evaluation on third-party corpora; the complete experimental pipeline, author-constructed datasets and pretrained weights are not publicly deposited.
Claim-level citations (16)
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The reported detection results are limited to reentrancy, short-address attack and timestamp dependence on EVM-based chains; the paper explicitly leaves broader classes including flash-loan and access-control attacks, adversarially robust reference-graph construction and non-EVM scenarios for future work.
Abstract; Conclusions, limitations and future-work discussion
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The paper reports approximately 6 GPU-hours on one RTX 3090 for RGCN pre-training, about 48 GPU-hours on 4xA100-80GB for DG-VDT-7B GRPO training, and about 180 GPU-hours on 8xA100-80GB for DG-VDT-32B. These are one-time training costs and are distinct from the reported per-trace inference latency.
Methodology, 'Computational cost' paragraph
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The authors report approximately 180 ms model inference latency per trace on a single RTX 3090-class consumer GPU. This is not end-to-end smart-contract audit latency: the SolidiFI protocol first compiles and deploys contracts, uses a transaction-generation harness to trigger known vulnerable paths, and extracts EVM traces before DG-VDT inference.
Abstract latency result; comparison-systems latency note; Section 4.3.1 SolidiFI-Bench evaluation protocol
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: On the author-independent SolidiFI-Bench zero-shot evaluation covering 3,942 instances in the three target categories, the authors report 87.7% macro-F1 for DG-VDT-7B, 6.8 points above their fine-tuned GPT-4o baseline.
Abstract; Section 4.3.1 'SolidiFI-Bench: Fault-Injection Ground Truth'; Table 4
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: DG-VDT represents each EVM execution trace as three complementary graphs - fund flow, contract creation and contract calls - and trains a policy with a dual-stage graph reward that transitions from embedding similarity to strict subgraph-isomorphism matching.
Abstract; Sections 3.1-3.3 describing the multi-graph representation, reference graphs, dual-stage reward and GRPO training
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The Applied Sciences article is publicly published with a September 30, 2026 publication date, while the checked DG-VDT repository still describes the manuscript as under review and says the unreleased datasets, full training/evaluation pipeline and pretrained weights will be released upon acceptance. The public record therefore shows a release-status lag or stale repository wording, not completion of the promised reproducibility release.
Article header and Data Availability Statement
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: On 11,423 SmartBugs Wild contracts evaluated zero-shot for the three target categories, the authors report 84.0% macro-F1 for DG-VDT-7B with a 95% bootstrap interval of 83.4-84.7%, 6.3 points above their fine-tuned GPT-4o baseline; the paper treats this dataset as a robustness signal because its ground truth uses noisier Slither single-tool labels.
Section 4.3.2 'SmartBugs Wild: Large-Scale In-the-Wild Validation'; Table 5
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The comparison against fine-tuned GPT-4o is not training-data matched: the paper states that GPT-4o was fine-tuned on 500 BlockTrace-500k examples while DG-VDT was trained on 489,939 traces, so the reported 6.8- and 6.3-point margins do not isolate architecture under equal training-data exposure.
Baseline comparison / training-data parity note and Section 4.3 discussion of comparison limitations
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The authors publicly expose the reward engine, graph schema, RGCN encoder, canonical reference graphs and unit tests, but the author-constructed datasets, full GRPO training/evaluation pipeline and pretrained model weights are not yet publicly deposited; the paper and repository say they are available to editors/reviewers and are planned for later release.
Data Availability Statement
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: DG-VDT is a defensive research and benchmark result for detection and traceability from execution traces; the cited material does not establish autonomous exploit generation, production exploitation, victim impact or realized financial loss caused by the system.
Abstract, experimental scope and Conclusions
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The paper does not provide an author-independent benchmark for attacker traceability: traceability is evaluated on ScamTrace-2024 and CrossChainAtt, both assembled with author involvement, and the authors characterize those traceability results as preliminary.
Limitations discussion headed 'Independent evaluation of attacker traceability'
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The paper reports a 13.9 macro-F1-point drop when the multi-graph representation is removed from the 7B configuration, supporting the authors' claim that the reported gain is not explained only by the language-model backbone.
Abstract; ablation analysis and Conclusions discussing the text-only ablation and contribution of the multi-graph representation
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: SolidiFI-Bench, SmartBugs Curated and SmartBugs Wild are third-party corpora independent of the DG-VDT authors, but their use does not constitute independent reproduction of DG-VDT: the reported runs and metrics are still produced by the authors, while the public repository does not yet include the complete experimental pipeline or pretrained weights.
Sections 4.3.1-4.3.2 and Conclusions describing author-independent public benchmarks; Data Availability Statement
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: The paper reports transaction-hash and contract-address-level deduplication between BlockTrace-500k and evaluation corpora. After removing overlaps, the final training corpus contains 489,939 traces, and the authors state that contracts appearing in EthVulBench, SmartBugs Curated, Etherscan-Public-1k, SolidiFI-Bench or SmartBugs Wild are removed from BlockTrace-500k training components.
Methodology, train/test separation and contract-level deduplication paragraphs immediately before comparison-systems description
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: DG-VDT operates on runtime EVM execution traces rather than Solidity source code. The paper therefore treats source-oriented GPTScan as complementary: GPTScan addresses pre-deployment static analysis, while DG-VDT addresses post-deployment runtime trace analysis, so neither system's native task subsumes the other.
Section 2.4 'LLM-Assisted Smart Contract Auditing'; comparison-systems discussion of GPTScan and architectural boundary
- supportsDG-VDT uses multi-graph reinforcement learning for Ethereum vulnerability detection and attacker traceability: For SmartBugs Wild, the paper evaluates 11,423 contracts carrying Slither annotations for at least one target category and excludes conflicting-tool annotations. The authors explicitly characterize the labels as noisy single-tool ground truth and use the result as a large-scale robustness signal rather than the same kind of exact ground truth provided by SolidiFI fault injection.
Section 4.3.2 'SmartBugs Wild: Large-Scale In-the-Wild Validation' and Conclusions
Cite this record
DiggingBeagle. “DG-VDT: Dynamic Graph-Guided Reinforcement Learning for Low-Latency Vulnerability Detection and Attack Traceability in Ethereum Smart Contracts.” Published Sep 30, 2026. https://diggingbeagle.com/sources/dg-vdt-dynamic-graph-guided-reinforcement-learning-for-low-latency-vulnerability/