Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection

Qiyang Song (PhD student · Institute of Information Engineering, Chinese Academy of Sciences)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Blockchain Security 2

Overview

The proliferation of smart contracts on platforms like Ethereum has introduced novel security challenges, with reentrancy remaining one of the most infamous and financially devastating vulnerabilities. This talk, presented by Qiyang Song from the Institute of Information Engineering, Chinese Academy of Sciences, addresses a critical limitation in current reentrancy detection tools: their propensity for generating a high volume of false positives. While existing tools boast high recall rates, the sheer number of false alarms overwhelms security teams, diminishing the practical utility of these essential safeguards.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to re-entrancy attacks and impact
  2. 2:00 Problem: Existing tools' false positives; anti-reentrancy patterns
  3. 4:00 Deep learning solution for identifying anti-reentrancy patterns
  4. 5:45 Specialized data structures: Rent PDG and reachability analysis
  5. 7:45 Training the anti-reentrancy pattern recognition model
  6. 8:30 Evaluation: Discovery of 8 new anti-reentrancy patterns
  7. 10:00 System performance and significant false positive reduction
  8. 11:00 Conclusion and summary of key contributions

Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection

Speakers: Qiyang Song, PhD student, Institute of Information Engineering, Chinese Academy of Sciences

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=-A7AE0gYKck

Overview

The proliferation of smart contracts on platforms like Ethereum has introduced novel security challenges, with reentrancy remaining one of the most infamous and financially devastating vulnerabilities. This talk, presented by Qiyang Song from the Institute of Information Engineering, Chinese Academy of Sciences, addresses a critical limitation in current reentrancy detection tools: their propensity for generating a high volume of false positives. While existing tools boast high recall rates, the sheer number of false alarms overwhelms security teams, diminishing the practical utility of these essential safeguards.

The core of Song's work lies in the premise that many seemingly vulnerable smart contracts are, in fact, protected by specific code structures known as anti-reentrancy patterns. By failing to recognize these intentional or unintentional safeguards, existing static analysis and symbolic execution tools misclassify safe contracts as vulnerable. This research introduces an innovative, deep learning-based approach to automatically identify these protective patterns, thereby significantly reducing false positives without compromising the detection of genuine reentrancy vulnerabilities. The implications are profound, promising more efficient and accurate smart contract security audits.

Background

▶ Watch: Introduction to re-entrancy attacks and impact (0:00)

Reentrancy is a critical vulnerability that has plagued smart contracts since the early days of blockchain, leading to substantial financial losses, notably highlighted by the 2016 attack on The DAO. The mechanism of a reentrancy attack is deceptively simple yet highly effective: an attacker calls a vulnerable function within a smart contract. This function typically performs a check, transfers funds to an external account, and then updates a state variable. The vulnerability arises when the attacker's external account is itself a malicious contract. During the fund transfer, before the original contract updates its state variable, the attacker's contract can call the vulnerable function again. Since the state variable has not yet been updated, the function passes its checks once more, transferring additional funds. This process can be repeated recursively, allowing the attacker to drain a massive amount of money from the contract.

To combat this, the industry and academia have developed various tools, predominantly relying on static analysis and symbolic execution. These tools typically identify reentrancy by looking for a classical pattern: a read or write operation on a state variable that coincides with an external call. While these methods have achieved high recovery rates for reentrancy vulnerabilities, they also suffer from a significant drawback: an abundance of false positives. Recent studies indicate that this high rate of false alarms stems from the tools' inability to recognize anti-reentrancy patterns. These are specific code structures, whether intentionally designed or organically evolved, that prevent malicious re-entry attempts. A common example is a check on the sender's identity (e.g., require(msg.sender == owner);), which, if ignored by a detection tool, could lead to a false positive classification for a contract that is, in fact, protected. The challenge, therefore, is to develop automated methods to accurately identify these protective patterns.

Key Findings

▶ Watch: Deep learning solution for identifying anti-reentrancy patterns (4:00)

The research presented by Qiyang Song introduces a novel, automated system designed to identify anti-reentrancy patterns on Ethereum smart contracts, addressing the pervasive issue of false positives in existing reentrancy detection tools. The system's core contribution is its ability to learn and recognize these protective code structures from real-world contracts using deep learning.

A crucial finding from their evaluation, conducted on 40,000 real-world Ethereum smart contracts, was the discovery and characterization of 12 distinct anti-reentrancy patterns. Among these, a significant eight patterns were newly explored by their system, demonstrating its capability to uncover previously undocumented defensive mechanisms. Examples of these newly identified patterns include:

  • EOA Restriction: This pattern restricts function access to Externally Owned Accounts (EOAs). Since EOAs do not contain code, they cannot execute recursive calls required for a reentrancy attack, effectively preventing malicious contracts from re-entering.
  • Access Frequency Limitation: This pattern implements checks to control how frequently a function can be called by a specific address within a short timeframe. By limiting the rate of access, it thwarts attackers from repeatedly re-entering the function to drain funds.

A comparative analysis revealed that existing reentrancy detection tools could, at most, identify only four of these 12 patterns, underscoring the limitations of current approaches and the novelty of this research.

The effectiveness of their anti-reentrancy pattern recognition model was rigorously evaluated, demonstrating impressive performance metrics. The system achieved a recall rate of over 85% and a precision of 100% in accurately detecting these protective patterns.

The most impactful finding is the system's ability to significantly refine the output of existing reentrancy detection tools. By integrating their anti-reentrancy pattern identification into the workflow of these tools, the researchers achieved a remarkable reduction in false positives by at least 85%. Critically, this substantial reduction was accomplished without compromising the original tools' capability to detect genuine reentrancy vulnerabilities, meaning no true positives were sacrificed. This dual benefit—drastically cutting down noise while maintaining detection accuracy—represents a significant leap forward for smart contract security auditing.

Technical Deep Dive

▶ Watch: Training the anti-reentrancy pattern recognition model (7:45)

The core technical challenge addressed by this research is the precise identification of anti-reentrancy patterns within the complex and varied code of Ethereum smart contracts. The proposed solution leverages a combination of specialized data structures and deep learning models to capture the most relevant semantic information.

The methodology unfolds in three key stages:

  1. Filtering Smart Contracts for Relevance:

The first step involves identifying a subset of smart contracts that are most likely to contain anti-reentrancy patterns. The intuition here is that contracts prone to reentrancy vulnerabilities are also those most likely to implement defensive measures. The researchers utilize existing knowledge and techniques for reentrancy detection to filter a large corpus of Ethereum smart contracts, focusing on those exhibiting characteristics associated with reentrancy risk, as these are prime candidates for also incorporating protective patterns. This pre-filtering step ensures that the subsequent, more computationally intensive analysis is applied to the most pertinent data.

  1. Designing Specialized Data Structures: The Rent PDG:

Recognizing that anti-reentrancy patterns primarily impose data and control dependency constraints around external calls, the researchers initially considered using Program Dependency Graphs (PDGs). PDGs are powerful representations that capture both data and control flow dependencies within a program. However, standard PDGs can be overly verbose, containing much irrelevant information that is not directly pertinent to anti-reentrancy logic.

To overcome this, they propose a novel, highly focused variant called the Reentrancy Program Dependency Graph (Rent PDG). The Rent PDG is meticulously designed to preserve only those components of the program dependency graph that are directly related to external calls. This significantly reduces noise and isolates the semantic core of anti-reentrancy mechanisms.

Constructing an accurate Rent PDG is non-trivial. A straightforward approach using depth-first search (DFS) on an interprocedural PDG might incorrectly include nodes from infeasible paths that are not genuinely connected to external calls in a meaningful execution context. To ensure precision, the researchers employ a sophisticated context-sensitive reachability analysis. This method combines the analytical power of context-free languages—which are adept at modeling and analyzing program paths—with adjacency matrix-based reachability analysis. This combination allows for a highly accurate analysis of path feasibility, ensuring that the constructed Rent PDGs precisely capture only the dependencies relevant to reentrancy and its prevention, accounting for the intricate interprocedural calling contexts within smart contracts.

  1. Training the Recognition Model with Deep Learning:

Once the Rent PDGs are constructed, they serve as input for a deep learning model designed to automatically learn and recognize anti-reentrancy semantics.

The core of this recognition model is a Graph Autoencoder. Graph autoencoders are neural networks specifically tailored to process graph-structured data. They learn to encode the structural and semantic information of a graph into a compact, low-dimensional graph-level embedding vector, and then decode it back to reconstruct the original graph. By training a graph autoencoder on the Rent PDGs, the model learns to capture the inherent characteristics and patterns indicative of anti-reentrancy mechanisms.

After training, the learned embedding vectors for numerous Rent PDGs are then subjected to clustering algorithms. This process groups similar embedding vectors together, effectively mining typical and recurring anti-reentrancy patterns present across the dataset of smart contracts. Each cluster represents a distinct anti-reentrancy pattern.

Finally, for recognizing anti-reentrancy patterns in new, unseen smart contracts, the process is reversed. A new contract's Rent PDG is constructed, its embedding vector is generated by the trained graph autoencoder, and this embedding is then checked against the learned clusters. If the new embedding falls within one of the established clusters, the smart contract is identified as being protected by a recognized anti-reentrancy pattern. This allows the system to accurately classify contracts as safe from reentrancy, even if they exhibit features that might otherwise trigger a false positive in traditional detection tools.

Demo / Proof of Concept

▶ Watch: Evaluation: Discovery of 8 new anti-reentrancy patterns (8:30)

While the talk did not feature a live, interactive demonstration of the system in action, the speakers presented a robust evaluation of their methodology and its practical impact. The "Proof of Concept" was effectively showcased through their extensive experimental results, which validate the system's ability to identify anti-reentrancy patterns and reduce false positives.

The evaluation was conducted using a dataset of 40,000 real-world smart contracts deployed on Ethereum. This substantial dataset provided a realistic and diverse environment for testing the system's efficacy. The system's output was 12 distinct clusters, each representing a unique anti-reentrancy pattern. To validate these clusters, the researchers randomly selected smart contracts from each cluster and manually reviewed their code patterns. This human-in-the-loop validation confirmed the existence and nature of the 12 identified anti-reentrancy patterns.

Crucially, the evaluation highlighted the discovery of eight novel anti-reentrancy patterns that had not been previously documented or systematically identified by existing tools. Examples such as EOA restriction (limiting function calls to externally owned accounts, which lack code for reentrancy) and access frequency limitation (restricting how often a function can be called within a short period) were presented, illustrating the practical relevance of these new findings.

The performance metrics for their anti-reentrancy recognition system were also presented: it achieved a recall rate of over 85% and an impressive 100% precision. This indicates that not only can the system find most of the existing anti-reentrancy patterns, but every pattern it identifies is genuinely an anti-reentrancy mechanism.

The ultimate proof of concept was the demonstration of how integrating their system with existing reentrancy detection tools significantly enhances their utility. By filtering out contracts identified as protected by anti-reentrancy patterns, the system was able to reduce false positives by at least 85% without compromising the original tools' ability to detect actual reentrancy vulnerabilities. This quantitative result serves as compelling evidence of the system's practical value in refining smart contract security analysis.

Defensive Implications

▶ Watch: Conclusion and summary of key contributions (11:00)

The findings presented in this talk have profound implications for smart contract security, offering tangible benefits for developers, auditors, and platform maintainers.

  1. Reduced Alert Fatigue for Security Teams: The most immediate and significant implication is the drastic reduction in false positives. By integrating the proposed anti-reentrancy pattern identification system, existing reentrancy detection tools can decrease false alarms by at least 85%. This directly translates to less "alert fatigue" for security analysts, allowing them to focus their limited time and resources on investigating genuine, high-risk vulnerabilities rather than sifting through numerous benign warnings.
  1. Improved Efficiency and Accuracy of Audits: For smart contract auditing firms and internal security teams, this work provides a powerful new capability. Audits become more efficient as automated tools produce cleaner, more actionable results. The increased precision means that when a reentrancy vulnerability is flagged, it is far more likely to be a true positive, leading to more accurate risk assessments and remediation efforts.
  1. Enhanced Smart Contract Design Patterns: The identification of 12 distinct anti-reentrancy patterns, especially the eight newly explored ones, enriches the collective knowledge base for secure smart contract development. Developers now have a broader and more nuanced understanding of effective defensive strategies. They can intentionally incorporate these validated patterns—such as EOA restrictions or access frequency limitations—into their contract designs from the outset, proactively building more robust and secure applications. This also encourages the standardization of secure coding practices.
  1. Refinement of Existing Security Tools: The methodologies, particularly the Rent PDG and the deep learning approach, offer a blueprint for enhancing existing static analysis and symbolic execution tools. Tool developers can integrate these components to improve the intelligence of their analyzers, moving beyond simplistic pattern matching to a more semantically aware understanding of contract security. This represents an evolution in automated vulnerability detection, making tools more sophisticated and less prone to over-reporting.
  1. Better Resource Allocation: For blockchain platforms and ecosystems, understanding prevalent anti-reentrancy patterns can inform resource allocation for security research and development. By knowing which protective measures are commonly (and effectively) employed, efforts can be directed towards new, unmitigated threats or further strengthening existing defenses.

In essence, this research empowers defenders by providing them with a clearer, more accurate lens through which to view smart contract security, ultimately fostering a safer blockchain environment.

Key Takeaways

  • Reentrancy Detection's False Positive Problem: Existing smart contract reentrancy detection tools, while effective at identifying potential vulnerabilities, suffer from a high rate of false positives, leading to developer fatigue and inefficient security audits.
  • Anti-Reentrancy Patterns as a Solution: Many contracts contain specific code structures, termed anti-reentrancy patterns, designed to prevent re-entry attacks. Current tools often fail to recognize these, leading to misclassifications.
  • Automated Deep Learning Approach: The presented research introduces a novel, automated system that utilizes deep learning to identify these crucial anti-reentrancy patterns.
  • Specialized Data Structures (Rent PDG): A key innovation is the Reentrancy Program Dependency Graph (Rent PDG), a specialized data structure that precisely captures program dependencies relevant to external calls, filtering out irrelevant information for effective pattern learning.
  • Discovery of New Patterns: The system successfully identified 12 anti-reentrancy patterns from 40,000 real-world Ethereum smart contracts, with 8 of these being newly explored (e.g., EOA restriction, access frequency limitation).
  • Significant False Positive Reduction: By integrating this system, existing reentrancy detection tools can achieve at least an 85% reduction in false positives with 100% precision and over 85% recall for pattern recognition, without compromising their original detection capabilities.

About the Speaker(s)

Qiyang Song is a PhD student affiliated with the Institute of Information Engineering at the Chinese Academy of Sciences. His research focuses on critical areas of smart contract security, particularly in refining vulnerability detection methodologies. His work, as presented at the NDSS Symposium, highlights an innovative approach to addressing long-standing challenges in blockchain security through the application of deep learning and advanced program analysis techniques. He also indicated an interest in exploring the use of large language models for future work in this domain.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate academic research with a clear problem statement, a novel intermediate representation (Rent PDG), and respectable empirical results on a real-world dataset. The contribution is incremental rather than transformative — reducing false positives in a narrow domain via graph autoencoders plus clustering is solid engineering, not a field-redefining insight — but it's honest work that belongs at NDSS.

Heather Calloway (CISO) — PASS

Technically credible PhD research on reducing false positives in Ethereum smart contract reentrancy detection. Outside my lane — no governance angle, no enterprise security relevance, no institutional accountability dimension.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025