{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T13:16:04Z","timestamp":1777554964911,"version":"3.51.4"},"reference-count":100,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Academic Research Fund Tier 1","award":["RG96\/23"],"award-info":[{"award-number":["RG96\/23"]}]},{"name":"AI Singapore Programme","award":["AISG Award No: AISG2-GC-2023-008-1B"],"award-info":[{"award-number":["AISG Award No: AISG2-GC-2023-008-1B"]}]},{"name":"National Cybersecurity R&#x0026;D Programme","award":["NCRP25-P04-TAICeN"],"award-info":[{"award-number":["NCRP25-P04-TAICeN"]}]},{"name":"Campus for Research Excellence and Technological Enterprise (CREATE) Programme"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tse.2025.3590108","type":"journal-article","created":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T18:04:17Z","timestamp":1753207457000},"page":"2512-2532","source":"Crossref","is-referenced-by-count":12,"title":["ACFix: Guiding LLMs With Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts"],"prefix":"10.1109","volume":"51","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3087-9645","authenticated-orcid":false,"given":"Lyuye","family":"Zhang","sequence":"first","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3517-353X","authenticated-orcid":false,"given":"Kaixuan","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2510-3684","authenticated-orcid":false,"given":"Kairan","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3752-0718","authenticated-orcid":false,"given":"Daoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, Hong Kong, SAR, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6709-3721","authenticated-orcid":false,"given":"Ye","family":"Liu","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8049-3997","authenticated-orcid":false,"given":"Haoye","family":"Tian","sequence":"additional","affiliation":[{"name":"University of Luxembourg, luxembourg, luxembourg"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Ethereum: A secure decentralised generalised transaction ledger","author":"Wood","year":"2014"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3558535.3559780"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559342"},{"key":"ref4","article-title":"Solidity"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00036"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23082"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00040"},{"key":"ref8","article-title":"DeFiRanger: Detecting price manipulation attacks on DeFi applications","author":"Wu","year":"2021"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00087"},{"key":"ref10","article-title":"Parity wallet attack"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3385990"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534372"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598125"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616341"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00057"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SANER48275.2020.9054825"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3402450"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3123170"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545975"},{"key":"ref20","first-page":"1289","article-title":"$\\{${EVMPatch$\\}$}: Timely and automated patching of Ethereum smart contracts","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Rodler","year":"2021"},{"key":"ref21","article-title":"Smart contract initialization"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274743"},{"key":"ref23","article-title":"Unchecked low-level call"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/s0065-2458(08)60206-5"},{"key":"ref25","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023"},{"key":"ref26","article-title":"GPT-4 technical report","year":"2023"},{"key":"ref27","article-title":"Is ChatGPT the ultimate programming assistant \u2013 How far is it?","author":"Tian","year":"2023"},{"key":"ref28","article-title":"ChatGPT hallucination"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.992"},{"key":"ref30","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Wei","year":"2022"},{"key":"ref31","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2019"},{"key":"ref32","article-title":"Improving language understanding by generative pre-training","author":"Radford"},{"key":"ref33","article-title":"ChatGPT"},{"key":"ref34","article-title":"GPT3.5"},{"key":"ref35","article-title":"Mistral 7b","author":"Jiang","year":"2023"},{"key":"ref36","article-title":"Llama3"},{"key":"ref37","article-title":"Smart contracts: Building blocks for digital markets","author":"Szabo","year":"1997"},{"key":"ref38","article-title":"ERC 20","year":"2024"},{"key":"ref39","article-title":"OpenZepplin Access Control"},{"key":"ref40","article-title":"GYMNetwork attack","year":"2023"},{"key":"ref41","article-title":"Example address"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ase56229.2023.00047"},{"key":"ref43","article-title":"Toolformer: Language models can teach themselves to use tools","author":"Schick","year":"2023"},{"key":"ref44","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive NLP tasks","volume-title":"Proc. NeurIPS","author":"Lewis","year":"2020"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.matching-1.7"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.15"},{"key":"ref47","article-title":"Improving factuality and reasoning in language models through multiagent debate","author":"Du","year":"2023"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-024-4222-0"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3318162"},{"key":"ref50","article-title":"Ethereum contracts"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678597"},{"key":"ref52","article-title":"Open card sorting"},{"key":"ref53","article-title":"Do you still need a manual smart contract audit?","author":"David","year":"2023"},{"key":"ref54","article-title":"LLM4Vuln: A unified evaluation framework for decoupling and enhancing LLMs\u2019 vulnerability reasoning","author":"Sun","year":"2024"},{"key":"ref55","article-title":"No more manual tests? Evaluating and improving ChatGPT for unit test generation","author":"Yuan","year":"2023"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639117"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3702973"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1984.5010248"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/WPC.1996.501116"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409757"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00057"},{"key":"ref62","first-page":"1165","article-title":"$\\{${MVP$\\}$}: Detecting vulnerabilities using $\\{${patch-enhanced$\\}$} vulnerability signatures","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur.)","author":"Xiao","year":"2020"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556956"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24222"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/24039.24041"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/WETSEB.2019.00008"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1002\/spe.4380250705"},{"key":"ref68","doi-asserted-by":"crossref","first-page":"530","DOI":"10.1145\/3377811.3380364","article-title":"Empirical review of automated analysis tools on 47,587 Ethereum smart contracts","volume-title":"Proc. ACM\/IEEE 42nd Int. Conf. Softw. Eng.","author":"Durieux","year":"2020"},{"key":"ref69","article-title":"National vulnerability database","year":"2023"},{"key":"ref70","article-title":"DeFi hack labs"},{"key":"ref71","article-title":"Tintinweb Vul Dataset"},{"key":"ref72","article-title":"Blocksec building blockchain security infrastructure","year":"2023"},{"key":"ref73","article-title":"SlowMist","year":"2023"},{"key":"ref74","article-title":"Medium","year":"2023"},{"key":"ref75","article-title":"ACFix Website"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243780"},{"key":"ref77","first-page":"9","article-title":"SmartCheck: Static analysis of Ethereum smart contracts","volume-title":"Proc. 1st Int. Workshop Emerg. trends in Softw. Eng. Blockchain","author":"Tikhomirov","year":"2018"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/3641846"},{"key":"ref79","article-title":"Practical mitigation of smart contract bugs","author":"Giesen","year":"2022"},{"key":"ref80","first-page":"2350","article-title":"ContractTinker: LLM-empowered vulnerability repair for real-world smart contracts","volume-title":"Proc. 39th IEEE\/ACM Int. Conf. Autom. Softw. Eng.","author":"Wang","year":"2024"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/Blockchain62396.2024.00064"},{"key":"ref82","article-title":"OpenAI Formatting"},{"key":"ref83","article-title":"Etherscan"},{"key":"ref84","article-title":"How much does GPT-4 cost?"},{"key":"ref85","article-title":"Quitoxic"},{"key":"ref86","article-title":"Guardian role for ERC20"},{"key":"ref87","article-title":"Fix me up: Repairing access-control bugs in web applications","volume-title":"Proc. NDSS","author":"Son","year":"2013"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00129"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680323"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616271"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3156637"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3147265"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1145\/3213846.3213871"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606626"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786811"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1145\/2837614.2837617"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070536"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00181"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00125"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/32\/11172729\/11086587.pdf?arnumber=11086587","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T04:57:36Z","timestamp":1758257856000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11086587\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":100,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tse.2025.3590108","relation":{},"ISSN":["0098-5589","1939-3520","2326-3881"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"},{"value":"2326-3881","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}