Publication:
Detecting smart contract vulnerabilities with Explainable AI

dc.conference.dateMAY 21–23, 2026
dc.conference.locationAnkara
dc.contributor.coauthorTahir, M. U.
dc.contributor.coauthorKhalid, U.
dc.contributor.departmentDepartment of Electrical and Electronics Engineering
dc.contributor.departmentGraduate School of Sciences and Engineering
dc.contributor.departmentKUIS AI (Koç University & İş Bank Artificial Intelligence Center)
dc.contributor.kuauthorÖrsdemir, Alperen
dc.contributor.kuauthorKüpçü, Alptekin
dc.contributor.schoolcollegeinstituteGRADUATE SCHOOL OF SCIENCES AND ENGINEERING
dc.contributor.schoolcollegeinstituteCollege of Engineering
dc.contributor.schoolcollegeinstituteResearch Center
dc.date.accessioned2026-08-14T11:21:41Z
dc.date.issued2026
dc.description.abstractThe rapid adoption of blockchain technologies has intensified the need for robust security mechanisms in Ethereum smart contracts (SC). Due to immutability, vulnerabilities cannot be patched after deployment, leading to significant financial losses. While traditional static and dynamic analysis tools are widely used, recent research has explored Machine Learning (ML) and Deep Learning (DL) techniques for automated vulnerability detection. However, many existing approaches focus on single-vulnerability detection or suffer from high false positive rates and limited interpretability. To address these challenges, this study proposes an interpretable DL framework for multi-vulnerability detection in SC. The proposed model employs a lightweight One-Dimensional Convolutional Neural Network (1D-CNN) integrated with Integrated Gradients from Explainable AI (XAI) to provide transparent model decisions. SC opcode sequences are transformed into RGB-encoded sequential representations, preserving execution order while enabling efficient feature extraction. This study adopts a multi-class classification setting to evaluate generalization across diverse vulnerability types. The framework is evaluated using the publicly available Messi-Q dataset, containing labeled samples across multiple vulnerability types. Experimental results demonstrate effective multi-class detection, with performance varying across vulnerability types due to dataset imbalance and structural similarities. The model maintains efficiency while providing interpretable insights for selected vulnerability classes. The model provides opcode-level attribution, revealing localized patterns for certain vulnerabilities and more distributed attention for others. These findings demonstrate the practicality of lightweight and interpretable DL methods for scalable SC security analysis.
dc.description.harvestedfromManual
dc.description.indexedbyScopus
dc.description.publisherscopeInternational
dc.description.readpublishN/A
dc.description.sponsoredbyTubitakEuTÜBİTAK
dc.description.sponsorshipScientific and Technological Research Council of Türkiye (Grant: 123E462,124N941)
dc.description.versionPublished Version
dc.identifier.ScopusPercentileN/A
dc.identifier.ScopusQuartileN/A
dc.identifier.WoSPercentileN/A
dc.identifier.WoSQuartileN/A
dc.identifier.doi10.1109/ichora69329.2026.11537218
dc.identifier.embargoN/A
dc.identifier.endpage6
dc.identifier.grantno123E462
dc.identifier.grantno124N941
dc.identifier.isbn9798331581503
dc.identifier.scopus2-s2.0-105042066678
dc.identifier.startpage1
dc.identifier.urihttp://doi.org/10.1109/ichora69329.2026.11537218
dc.identifier.urihttps://hdl.handle.net/20.500.14288/34384
dc.keywordsBlockchain
dc.keywordsEthereum
dc.keywordsSmart contracts
dc.keywordsSolidity
dc.keywordsXAI
dc.languageeng
dc.publisherIEEE
dc.relation.affiliationKoç University
dc.relation.collectionKoç University Institutional Repository
dc.relation.ispartof2026 8Th International Congress on Human-Computer Interaction, Optimization and Robotic Applications (Ichora)
dc.relation.openaccessN/A
dc.rightsN/A
dc.rights.uriN/A
dc.subjectPhysical sciences
dc.subjectComputer science
dc.subjectArtificial intelligence
dc.titleDetecting smart contract vulnerabilities with Explainable AI
dc.typeConference Proceeding
dspace.entity.typePublication
relation.isOrgUnitOfPublication21598063-a7c5-420d-91ba-0cc9b2db0ea0
relation.isOrgUnitOfPublication3fc31c89-e803-4eb1-af6b-6258bc42c3d8
relation.isOrgUnitOfPublication77d67233-829b-4c3a-a28f-bd97ab5c12c7
relation.isOrgUnitOfPublication.latestForDiscovery21598063-a7c5-420d-91ba-0cc9b2db0ea0
relation.isParentOrgUnitOfPublication434c9663-2b11-4e66-9399-c863e2ebae43
relation.isParentOrgUnitOfPublication8e756b23-2d4a-4ce8-b1b3-62c794a8c164
relation.isParentOrgUnitOfPublicationd437580f-9309-4ecb-864a-4af58309d287
relation.isParentOrgUnitOfPublication.latestForDiscovery434c9663-2b11-4e66-9399-c863e2ebae43

Files