Code Sentinel: AI-Driven Smart Contract Attack Simulation for Vulnerability Detection

Authors

  • Sandip Shinde Department of Computer Engineering, Vishwakarma Institute of Technology, Pune, India Author
  • Harsh Manjramkar Department of Computer Engineering, Vishwakarma Institute of Technology, Pune, India Author
  • Vedant Gaidhani Department of Computer Engineering, Vishwakarma Institute of Technology, Pune, India Author
  • Vineet Wagh Department of Computer Engineering, Vishwakarma Institute of Technology, Pune, India Author
  • Arjun Joshi Department of Computer Engineering, Vishwakarma Institute of Technology, Pune, India Author

DOI:

https://doi.org/10.63503/acset.117

Keywords:

Smart Contracts, Blockchain Security, Vulnerability Detection, Deep Learning, Attack Simulation, Solidity

Abstract

Smart contracts are the cornerstone of the swelling network of decentralized applications (dApps), but their mutability is a major security issue. After deployment, any vulnerability in the smart contract code cannot be easily fixed, resulting in high-profile exploits and significant monetary losses. Existing security analysis tools primarily rely on static analysis and symbolic execution, producing abstract warnings and vulnerability reports. There is, however, a gap in these tools: they do not show how an identified vulnerability can be practically exploited, leaving developers with no real sense of the actual risk or attack vehicle. To mitigate this shortcoming, we present Code Sentinel, a new system that combines AI-based vulnerability identification with an automated attack simulation engine. Code Sentinel uses a supervised learning algorithm, trained on large datasets of vulnerable and secure Solidity contracts, to provide precise classification of a wide range of security flaws. More importantly, it uses a reinforcement learning-driven engine that can model the attacker's behaviour and identify the best exploit strategies for the vulnerabilities it identifies. This process creates concrete exploit scenarios that show the exact sequence of transactions and state changes that lead to a compromise. Deep learning-enabled Code Sentinel offers interactive, actionable insights to developers by shifting the paradigm from passively signalling vulnerabilities to demonstratively analysing security, building a safer dApp ecosystem.

References

[1] G. Wood, "Ethereum: A secure decentralised generalised transaction ledger," Ethereum Project Yellow Paper, 2014.

[2] N. Atzei, M. Bartoletti, and T. Cimoli, "A survey of attacks on ethereum smart contracts (sok)," in International Conference on Principles of Security and Trust. Springer, 2017, pp. 164-186.

[3] S. Sayeed, H. Marco-Gisbert, and T. Caira, "Smart contract: Attacks and protections," IEEE Access, vol. 8, pp. 24416-24427, 2020.

[4] A. Mense and M. Flatscher, "Security vulnerabilities in ethereum smart contracts," in Proceedings of the 20th International Conference on Information Integration and Web-based Applications & Services, 2018, pp. 435-440.

[5] C. Sendner et al., "Smarter contracts: Detecting vulnerabilities in smart contracts with deep transfer learning," in NDSS, 2023.

[6] L. Luu, D.-H. Chu, H. Olickel, P. Saxena, and A. Hobor, "Making smart contracts smarter," in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 2016, pp. 254-269.

[7] N. Dimitrijević and N. Zdravković, "A review on security vulnerabilities of smart contracts written in solidity," Preprint, 2023.

[8] P. Zhang, F. Xiao, and X. Luo, "SolidityCheck: Quickly detecting smart contract problems through regular expressions," arXiv preprint arXiv:1911.09425, 2019.

[9] N. Matulevicius and L. C. Cordeiro, "Verifying security vulnerabilities for blockchain-based smart contracts," in 2021 XI Brazilian Symposium on Computing Systems Engineering (SBESC), 2021, pp. 1-8.

[10] S. T. Gandhi, "AI-driven smart contract security: A deep learning approach to vulnerability detection," International Journal of Advanced Research in Computer Science & Technology, vol. 8, no. 1, 2025.

[11] P. Tantikul and S. Ngamsuriyaroj, "Exploring vulnerabilities in solidity smart contract," in Proceedings of the 6th International Conference on Information Systems Security and Privacy, 2020.

Downloads

Published

2026-09-15

Conference Proceedings Volume

Section

Articles

How to Cite

Sandip Shinde, Harsh Manjramkar, Vedant Gaidhani, Vineet Wagh, & Arjun Joshi. (2026). Code Sentinel: AI-Driven Smart Contract Attack Simulation for Vulnerability Detection . Adroid Conference Series: Engineering and Technology, 2(3), 125-131. https://doi.org/10.63503/acset.117