TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across Transactions

Decentralized Applications (DApps) serve as a critical technical underpinning for business logic and user interaction within the blockchain-powered Web3 ecosystem. However, DApps are prone to faults, and localizing these faults within their intricate and often interconnected logic is a particularly time-consuming process, frequently taking tens of hours and leading to substantial economic losses for developers. Existing state-of-the-art DApp fault localization methods, e.g., FaultSeeker, cannot capture cross-transaction fault logic and produce verifiable diagnostic reports. Therefore, security experts have to spend substantial time manually verifying results and devising fixes. In this paper, we present TracePilot, a large language model (LLM)-based framework that automates DApp fault localization in two phases: distilling global fault insights from transaction sequences and then performing focused trace exploration to isolate the faulty logic. Crucially, we propose a patch verification mechanism that treats attack-blocking patches as executable evidence for fault localization while flagging potential overfitting risks for expert review. This mechanism improves result trustworthiness and reduces manual verification costs. Evaluated on a dataset of 149 real-world cases, TracePilot achieves a 71.14% Top-1 Recall. In the single-transaction fair comparison, it achieves 72.73%, substantially outperforming the state-of-the-art method at 32.23%. On cross-transaction cases, TracePilot achieves a 64.29% Top-1 Recall. The proposed algorithm is being integrated into the contract security agent developed by Ant Digital Technologies. Moreover, to facilitate further research, our code and dataset are publicly available online: https://github.com/feiqiuaaaa/TracePilot.

Authors

Institutions

Publication Details

Journal
Proceedings of the ACM on software engineering.
Published
2026-10-01
DOI
https://doi.org/10.1145/3832292
Primary Topic
Software System Performance and Reliability
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across Transactions

Zibin Zheng, Jiajing Wu, Zhiying Wu, Zigui Jiang et al.
Proceedings of the ACM on software engineering.
Software System Performance and Reliability
article

TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across Transactions

Zibin Zheng, Jiajing Wu, Zhiying Wu, Zigui Jiang, Ying Yan, Tao Wang, Xuanyu Zhu, Wei Zhou
article en

Abstract

Decentralized Applications (DApps) serve as a critical technical underpinning for business logic and user interaction within the blockchain-powered Web3 ecosystem. However, DApps are prone to faults, and localizing these faults within their intricate and often interconnected logic is a particularly time-consuming process, frequently taking tens of hours and leading to substantial economic losses for developers. Existing state-of-the-art DApp fault localization methods, e.g., FaultSeeker, cannot capture cross-transaction fault logic and produce verifiable diagnostic reports. Therefore, security experts have to spend substantial time manually verifying results and devising fixes. In this paper, we present TracePilot, a large language model (LLM)-based framework that automates DApp fault localization in two phases: distilling global fault insights from transaction sequences and then performing focused trace exploration to isolate the faulty logic. Crucially, we propose a patch verification mechanism that treats attack-blocking patches as executable evidence for fault localization while flagging potential overfitting risks for expert review. This mechanism improves result trustworthiness and reduces manual verification costs. Evaluated on a dataset of 149 real-world cases, TracePilot achieves a 71.14% Top-1 Recall. In the single-transaction fair comparison, it achieves 72.73%, substantially outperforming the state-of-the-art method at 32.23%. On cross-transaction cases, TracePilot achieves a 64.29% Top-1 Recall. The proposed algorithm is being integrated into the contract security agent developed by Ant Digital Technologies. Moreover, to facilitate further research, our code and dataset are publicly available online: https://github.com/feiqiuaaaa/TracePilot.

Proceedings of the ACM on software engineering.Vol. 3(ISSTA)
Sun Yat-sen University (CN)
Openalex Percentile: Top 9%
Software System Performance and Reliability
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.