ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil

This program is tentative and subject to change.

Fri 17 Apr 2026 16:15 - 16:30 at Oceania X - Dependability and Security 11

Smart contracts are susceptible to various security issues, among which access control (AC) vulnerabilities are particularly critical. While existing research has proposed multiple detection tools, automatic and appropriate repair of AC vulnerabilities in smart contracts remains a challenge. Unlike commonly supported vulnerability types by existing repair tools, such as reentrancy, which are usually fixed by template-based approaches, the main obstacle of repairing AC vulnerabilities lies in identifying the appropriate roles or permissions amid a long list of non-AC-related source code to generate proper patch code, a task that demands human-level intelligence.

In this paper, we employ the state-of-the-art GPT-4 model and enhance it with a novel approach called ACFix. The key insight is that we can mine common AC practices for major categories of code functionality and use them to guide LLMs in fixing code with similar functionality. To this end, ACFix involves offline and online phases. In the offline phase, ACFix mines a taxonomy of common Role-based Access Control practices from 344,251 onchain contracts, categorizing 49 role-permission pairs from the top 1,000 unique samples. In the online phase, ACFix tracks AC-related elements across the contract and uses this context information along with a Chain-of-Thought pipeline to guide LLMs in identifying the most appropriate role-permission pair for the subject contract and subsequently generating a suitable patch. To evaluate ACFix, we built the first benchmark dataset of 118 real-world AC vulnerabilities, and our evaluation revealed that ACFix successfully repaired 94.92% of them, a major improvement compared to the baseline GPT-4 at only 52.54%. We also conducted a human study to understand the value of ACFix’s repairs and their differences from human repairs.

This program is tentative and subject to change.

Fri 17 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

16:00 - 17:30
16:00
15m
Talk
AtomGraph: Tackling Atomicity Violation in Smart Contracts using Multimodal GCNs
New Ideas and Emerging Results (NIER)
Xiaoqi Li Hainan University, Zongwei Li Hainan University, Wenkai Li Hainan University, Zeng Zhang Hainan University, Lei Xie Hainan University
16:15
15m
Talk
ACFix: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
Journal-first Papers
Lyuye Zhang Nanyang Technological University, Kaixuan Li Nanyang Technological University, Kairan Sun Nanyang Technological University, Daoyuan Wu Lingnan University, Ye Liu Singapore Management University, Haoye Tian Aalto University, Yang Liu Nanyang Technological University
16:30
15m
Talk
Do Automated Fixes Truly Mitigate Smart Contract Exploits?
Journal-first Papers
Sofia Bobadilla KTH Royal Institute of Technology, Sweden, Mónica Jin KTH Royal Institute of Technology, Martin Monperrus KTH Royal Institute of Technology
16:45
15m
Talk
CKG-LLM: LLM-Assisted Detection of Smart Contract Access Control Vulnerabilities Based on Knowledge Graphs
New Ideas and Emerging Results (NIER)
Xiaoqi Li Hainan University, Hailu Kuang Hainan University, Wenkai Li Hainan University, Zongwei Li Hainan University, Shipeng Ye Hainan University
17:00
15m
Talk
One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart Contracts
Research Track
Zexu Wang Sun Yat-sen University, Jiachi Chen Sun Yat-sen University, Zewei Lin Sun Yat-sen University, Wenqing Chen Sun Yat-sen University, Kaiwen Ning Sun Yat-sen University, Jianxing Yu Sun Yat-sen University, Yuming Feng Peng Cheng Laboratory, Yu Zhang Harbin Institute of Technology, Weizhe Zhang Harbin Institute of Technology, Zibin Zheng Sun Yat-sen University
Pre-print
17:15
15m
Talk
USCSA: Evolution-Aware Security Analysis for Proxy-Based Upgradeable Smart Contracts
New Ideas and Emerging Results (NIER)
Xiaoqi Li Hainan University, Lei Xie Hainan University, Wenkai Li Hainan University, Zongwei Li Hainan University