Pith. sign in

REVIEW 4 major objections 2 minor 104 references

Clinically-guided Data Synthesis for Laryngeal Lesion Detection

T0 review · 4 major / 2 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read Adding 10% synthetic endoscopic images to training improves laryngeal lesion detection by 9% internally and 22.1% on out-of-domain data.

desk verdict The abstract promises a useful synthetic-data result for laryngeal detection, but the submitted full text is an unrelated smart-contract paper, so there is nothing to review. read the letter →

arxiv 2508.06182 v1 pith:BZGIFXCA submitted 2025-08-08 eess.IV cs.CV

classification eess.IVcs.CV
keywords laryngeallesionssyntheticdatalatentdiffusionmodelControlNetscarcitycomputer-aideddetectionendoscopicimaging
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper claims that a diffusion-based generative pipeline can manufacture realistic laryngeal endoscopy images together with lesion annotations, and that mixing only 10% of these synthetic image-annotation pairs into real training data materially improves downstream lesion detection. Internally, detection improves by 9%; on an external, out-of-domain dataset, the improvement is 22.1%. The method targets the data scarcity bottleneck that keeps computer-aided detection out of otorhinolaryngology, where diagnosis still relies heavily on operator expertise and biopsy. If the claim holds, synthetic data becomes a practical lever for building automated detection systems in specialized medical fields with few annotated examples.

What carries the argument

The machinery is a Latent Diffusion Model coupled with a ControlNet adapter. The diffusion model generates images in a compressed latent space, while ControlNet injects conditioning signals, here clinical observations, so that generated images carry specified anatomical and lesional features while remaining photorealistic. The same pipeline yields paired annotations, producing image-annotation pairs that can be mixed into training sets for downstream detection models.

What would settle it

Train the same detection model on the real-only training set and on the real-plus-10%-synthetic set, then evaluate both on an independent external laryngoscopy dataset with verified non-overlapping patients and sites; if the 22.1% gain does not reproduce, the core claim fails. A complementary check is to measure the feature-distribution shift between synthetic and real images and compare it with the shift between internal and external real datasets, or to have a larger panel of clinicians classify real versus synthetic images in a forced-choice test.

Watch

Extended reading notes

Core claim

The central discovery is that clinically conditioned synthetic data can substitute for a small but highly effective fraction of real training data in a specialized endoscopic detection task. A Latent Diffusion Model, steered by a ControlNet adapter and guided by clinical observations, generates paired laryngeal images and annotations; the paper reports that adding 10% of such pairs improves detection of laryngeal lesions by 9% on internal testing and 22.1% on out-of-domain external data. Realism was assessed by five expert otorhinolaryngologists who rated their confidence in distinguishing synthetic from real images.

Load-bearing premise

The central claim stands on the premise that the synthetic endoscopic images faithfully preserve the clinically relevant visual features of real laryngeal lesions, and that the external test set is genuinely out-of-domain, so that the reported gains reflect real transfer rather than distributional artifact.

Editorial extensions

If this is right

  • If correct, small synthetic augmentation can improve external generalization in laryngeal lesion detection without hurting internal performance.
  • This offers a route toward reducing reliance on biopsy by making automated endoscopic assessment more viable in laryngology.
  • The approach points to a general strategy for other data-scarce specialized imaging domains where annotated datasets are hard to obtain.
  • The reported 10% synthetic-data ratio could serve as a practical starting point for augmenting medical imaging training sets.
  • Expert realism ratings suggest synthetic images may pass visual scrutiny, supporting further clinical-facing evaluation.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The abstract does not provide training protocols, dataset details, or external test-set characteristics, so an independent reproduction is needed before the 22.1% gain can be separated from dataset-specific effects.
  • If the clinical-conditioning mechanism is the key, a testable extension is to probe whether gains concentrate on rare or visually subtle lesion subtypes, which the paper does not examine.
  • The same conditioning approach may transfer to other endoscopic domains, such as colonoscopy or bronchoscopy, where clinical descriptors could similarly guide synthetic image generation.
  • A direct comparison against classic augmentation and against sampling additional real data would isolate whether the value comes from synthetic content itself or from simple training-set enlargement.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 2 minor

Summary. The submitted material for arXiv:2508.06182 consists of an abstract proposing a clinical-conditioned Latent Diffusion Model with ControlNet to synthesize laryngeal endoscopic image-annotation pairs, plus a full text that is a completely unrelated manuscript on smart-contract vulnerabilities (arXiv:2508.06192). The abstract reports that adding 10% synthetic data improves laryngeal lesion detection by 9% internally and 22.1% on out-of-domain external data, and that five expert otorhinolaryngologists evaluated the realism of generated images. No methods, datasets, experimental protocols, baseline comparisons, or statistical analyses for these medical-imaging claims appear anywhere in the submitted manuscript.

Significance. If the claims were fully supported, the work would be potentially significant for a data-scarce specialty: a 22.1% out-of-domain detection gain from 10% synthetic augmentation is a strong and falsifiable result, and the expert-realism study is an appropriate additional validation layer. However, as submitted the paper contains no evidence for these claims. There are no reproducible artifacts, no derivation, no code, and no experimental details; the only quantitative statements are the two improvement percentages and the mention of five experts. The significance therefore cannot be assessed beyond the abstract level.

major comments (4)
  1. [Abstract / submitted full text] The central claims—9% internal and 22.1% external detection improvement from 10% synthetic data—are unsupported by the submission. There is no Methods or Results section for laryngeal imaging: the real dataset, the LDM/ControlNet architecture, the clinical-conditioning protocol, the detection model, the training schedule, and the internal/external test splits are all absent. The full text that follows the abstract is arXiv:2508.06192, 'Understanding Inconsistent State Update Vulnerabilities in Smart Contracts', which has no connection to laryngeal endoscopy. These figures therefore cannot be reproduced, checked for leakage, or compared with baselines.
  2. [Abstract / realism evaluation] The realism evaluation is described only as asking '5 expert otorhinolaryngologists' to rate confidence in distinguishing synthetic from real images. The submission does not report the number of real and synthetic images, the rating scale, whether experts were blinded, inter-rater agreement, or any statistical test. Without this protocol the claim that generated images are 'realistic, high-quality, and clinically relevant' is not established.
  3. [Abstract / external-domain claim] The 22.1% external improvement depends on the external test being genuinely out-of-domain. The submission gives no provenance for the external dataset, no image counts, no acquisition-site information, and no statement on whether patient or site overlap was excluded. This makes it impossible to separate a genuine generalization benefit from hidden corpus similarity, evaluation-protocol artifacts, or label mismatch.
  4. [Abstract / 'only 10%' claim] The claim that 'only 10% synthetic data' improves detection is not substantiated without ablations over the synthetic mixing ratio and without variance or confidence intervals for the improvement figures. As written, the numbers could reflect a single favorable run rather than a stable effect.
minor comments (2)
  1. [Title / full-text match] The title and abstract describe a laryngeal imaging study, while the full text is a smart-contract security paper. If this is a file-upload or metadata error, the correct full text must be supplied before any further review.
  2. [General formatting] The submitted material has no author list, affiliation, references, figures, or tables for the laryngeal paper. A resubmission would need the standard manuscript structure and an explicit related-work discussion for diffusion-based medical image synthesis and lesion-detection CADe.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity found: the central claim is an empirical benchmark result, not a derivation that reduces to its inputs.

full rationale

The submitted material contains only an abstract with an empirical claim: adding 10% synthetic data improved detection by 9% internally and 22.1% on external data. There is no derivation chain, equation, fitted parameter, or self-citation that could be examined for circularity. The full text is an unrelated smart-contract paper, so no methods, dataset splits, or evaluation protocol are available to check whether the reported gains were forced by construction. The absence of evidence is a verifiability and manuscript-integrity problem, not a circularity problem: nothing in the abstract defines the synthetic-data pipeline in terms of the detection outcome, and no fitted input is renamed as a prediction. Under the hard rule that circularity must be exhibited by quoting the paper and showing a specific reduction, no circular step can be identified. The honest finding is therefore no significant circularity, score 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

No free parameters can be identified because the methods and results sections are absent from the submitted material. The abstract implies three domain assumptions about synthetic image realism, transferability, and the validity of expert realism ratings. No new physical or conceptual entities are introduced.

assumptions (3)
  • domain assumption Latent diffusion models with ControlNet can generate realistic and clinically relevant laryngeal endoscopic images.
    The abstract asserts this capability without providing evidence in the submitted text.
  • domain assumption A 10% addition of synthetic data to a training set improves real-world detection without introducing harmful distribution shift.
    The headline result depends on this; no experimental details are provided.
  • domain assumption Expert ratings of image realism are a valid proxy for clinical utility.
    The abstract reports expert confidence in distinguishing synthetic vs real as an evaluation of realism.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Clinically-guided Data Synthesis for Laryngeal Lesion Detection." pith.science (2026). https://pith.science/paper/BZGIFXCA

@misc{pith2026250806182,
  author       = {Pith},
  title        = {Pith review of: Clinically-guided Data Synthesis for Laryngeal Lesion Detection},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/BZGIFXCA}},
  note         = {Machine review of arXiv:2508.06182}
}
read the original abstract

Although computer-aided diagnosis (CADx) and detection (CADe) systems have made significant progress in various medical domains, their application is still limited in specialized fields such as otorhinolaryngology. In the latter, current assessment methods heavily depend on operator expertise, and the high heterogeneity of lesions complicates diagnosis, with biopsy persisting as the gold standard despite its substantial costs and risks. A critical bottleneck for specialized endoscopic CADx/e systems is the lack of well-annotated datasets with sufficient variability for real-world generalization. This study introduces a novel approach that exploits a Latent Diffusion Model (LDM) coupled with a ControlNet adapter to generate laryngeal endoscopic image-annotation pairs, guided by clinical observations. The method addresses data scarcity by conditioning the diffusion process to produce realistic, high-quality, and clinically relevant image features that capture diverse anatomical conditions. The proposed approach can be leveraged to expand training datasets for CADx/e models, empowering the assessment process in laryngology. Indeed, during a downstream task of detection, the addition of only 10% synthetic data improved the detection rate of laryngeal lesions by 9% when the model was internally tested and 22.1% on out-of-domain external data. Additionally, the realism of the generated images was evaluated by asking 5 expert otorhinolaryngologists with varying expertise to rate their confidence in distinguishing synthetic from real images. This work has the potential to accelerate the development of automated tools for laryngeal disease diagnosis, offering a solution to data scarcity and demonstrating the applicability of synthetic data in real-world scenarios.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

104 extracted references · 71 canonical work pages

  1. [1]

    A. M. Antonopoulos and G. Wood,Mastering Ethereum: Building Smart Contracts and DApps. O’Reilly Media, Incorporated, 2018. [Online]. Available: https://books.google.com.hk/books?id=SedSMQAACAAJ

  2. [2]

    Smart contracts in banking: Enhancing efficiency and security in financial transactions,

    P. Ferreira, “Smart contracts in banking: Enhancing efficiency and security in financial transactions, ” https://defillama.com/chain/Ethereum, 2025, [Online] accessed 2025-04-15

  3. [3]

    Gaming with smart contracts: Rewards and ownership made simple,

    M. Editorial, “Gaming with smart contracts: Rewards and ownership made simple, ” https://metana.io/blog/gaming-with-smart-contracts-rewards- and-ownership-made-simple/, 2025, [Online] accessed 2025-04-15

  4. [4]

    Smart contracts for government processes: Case study and prototype implementation (short paper),

    M. Krogsbøll, L. H. Borre, T. Slaats, and S. Debois, “Smart contracts for government processes: Case study and prototype implementation (short paper), ” inFinancial Cryptography and Data Security: 24th International Conference, FC 2020 , Kota Kinabalu, Malaysia, February 10–14, 2020 Revised Selected Papers. Berlin, Heidelberg: Springer-Verlag, 2020, p. 67...

  5. [5]

    Use of blockchain-based smart contracts in logistics and supply chains,

    M. A. Alqarni, M. S. Alkatheiri, S. H. Chauhdary, and S. Saleem, “Use of blockchain-based smart contracts in logistics and supply chains, ” Electronics, vol. 12, no. 6, 2023. [Online]. Available: https://www.mdpi.com/2079-9292/12/6/1340

  6. [6]

    Understanding the dao attack,

    D. Siegel, “Understanding the dao attack, ” https://www.coindesk.com/learn/understanding-the-dao-attack, 2025, [Online] accessed 2025-04-15

  7. [7]

    The parity wallet hack explained,

    S. Palladino, “The parity wallet hack explained, ” https://blog.openzeppelin.com/on-the-parity-wallet-multisig-hack-405a8c12e8f7, 2025, [Online] accessed 2025-04-15

  8. [8]

    A survey of attacks on ethereum smart contracts sok,

    N. Atzei, M. Bartoletti, and T. Cimoli, “A survey of attacks on ethereum smart contracts sok, ” inProceedings of the 6th International Conference on Principles of Security and Trust - Volume 10204. Berlin, Heidelberg: Springer-Verlag, 2017, p. 164–186. [Online]. Available: https://doi.org/10.1007/978-3-662-54455-6_8

Show all 104 references
  1. [9]

    Proxy hunting: Understanding and characterizing proxy-based upgradeable smart contracts in blockchains,

    W. E. Bodell III, S. Meisami, and Y. Duan, “Proxy hunting: Understanding and characterizing proxy-based upgradeable smart contracts in blockchains, ” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1829–1846. Manuscript submitted to ACM Understanding Inconsist...

  2. [10]

    Sailfish: Vetting smart contract state-inconsistency bugs in seconds,

    P. Bose, D. Das, Y. Chen, Y. Feng, C. Kruegel, and G. Vigna, “Sailfish: Vetting smart contract state-inconsistency bugs in seconds, ” in2022 IEEE Symposium on Security and Privacy (SP). IEEE, 2022, pp. 161–178

  3. [11]

    Confuzzius: A data dependency-aware hybrid fuzzer for smart contracts,

    C. F. Torres, A. K. Iannillo, A. Gervais, and R. State, “Confuzzius: A data dependency-aware hybrid fuzzer for smart contracts, ” in2021 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 2021, pp. 103–119

  4. [12]

    Common solidity security vulnerabilities,

    dedaub, “Common solidity security vulnerabilities, ” https://dedaub.com/blog/solidity-security-vulnerabilities, 2025, [Online] accessed 2025-08-28

  5. [13]

    common solidity vulnerabilities on ethereum,

    quicknode, “common solidity vulnerabilities on ethereum, ” https://www.quicknode.com/guides/ethereum-development/smart-contracts/common- solidity-vulnerabilities-on-ethereum, 2025, [Online] accessed 2025-08-28

  6. [14]

    Demystifying exploitable bugs in smart contracts,

    Z. Zhang, B. Zhang, W. Xu, and Z. Lin, “Demystifying exploitable bugs in smart contracts, ” in2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2023, pp. 615–627

  7. [15]

    Ethainter: a smart contract security analyzer for composite vulnerabilities,

    L. Brent, N. Grech, S. Lagouvardos, B. Scholz, and Y. Smaragdakis, “Ethainter: a smart contract security analyzer for composite vulnerabilities, ” in Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation, 2020, pp. 454–469

  8. [16]

    Smart contract vulnerabilities: Vulnerable does not imply exploited,

    D. Perez and B. Livshits, “Smart contract vulnerabilities: Vulnerable does not imply exploited, ” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 1325–1341

  9. [17]

    Wiener doge exploit,

    certik, “Wiener doge exploit, ” https://www.certik.com/resources/blog/Br4j8oVnz9zKqW3okCyD9-wiener-doge-exploit, 2025, [Online] accessed 2025-04-15

  10. [18]

    Did this hacker get away with a $3.8 million nft hack?

    S. Kiran, “Did this hacker get away with a $3.8 million nft hack?” https://watcher.guru/news/did-this-hacker-get-away-with-a-3-8-million-nft-hack, 2025, [Online] accessed 2025-04-15

  11. [19]

    Pancakeswap content injection bugfix review,

    Immunefi, “Pancakeswap content injection bugfix review, ” https://medium.com/immunefi/pancakeswap-content-injection-bug-fix-postmortem- e9058cfc7451, 2025, [Online] accessed 2025-04-15

  12. [20]

    Empirical evaluation of smart contract testing: What is the best choice?

    M. Ren, Z. Yin, F. Ma, Z. Xu, Y. Jiang, C. Sun, H. Li, and Y. Cai, “Empirical evaluation of smart contract testing: What is the best choice?” in Proceedings of the 30th ACM SIGSOFT international symposium on software testing and analysis, 2021, pp. 566–579

  13. [21]

    Large-scale study of vulnerability scanners for ethereum smart contracts,

    C. Sendner, L. Petzi, J. Stang, and A. Dmitrienko, “Large-scale study of vulnerability scanners for ethereum smart contracts, ” in2024 IEEE Symposium on Security and Privacy (SP). IEEE, 2024, pp. 2273–2290

  14. [22]

    Are we there yet? unraveling the state-of-the-art smart contract fuzzers,

    S. Wu, Z. Li, L. Yan, W. Chen, M. Jiang, C. Wang, X. Luo, and H. Zhou, “Are we there yet? unraveling the state-of-the-art smart contract fuzzers, ” in Proceedings of the IEEE/ACM 46th International Conference on Software Engineering, 2024, pp. 1–13

  15. [23]

    Code4rena, https://code4rena.com, 2025, [Online] accessed 2024-10-18

  16. [24]

    Leaderboard, https://code4rena.com/leaderboard, 2025, [Online] accessed 2024-10-18

  17. [25]

    An empirical analysis of source code metrics and smart contract resource consumption,

    N. Ajienka, P. Vangorp, and A. Capiluppi, “An empirical analysis of source code metrics and smart contract resource consumption, ”Journal of Software: Evolution and Process, vol. 32, no. 10, p. e2267, 2020

  18. [26]

    sfuzz: An efficient adaptive fuzzer for solidity smart contracts,

    T. D. Nguyen, L. H. Pham, J. Sun, Y. Lin, and Q. T. Minh, “sfuzz: An efficient adaptive fuzzer for solidity smart contracts, ” inProceedings of the ACM/IEEE 42nd international conference on software engineering, 2020, pp. 778–788

  19. [27]

    Idol: Improved different optimization levels testing for solidity compilers,

    L. Li, Y. Liang, and Z. Yu, “Idol: Improved different optimization levels testing for solidity compilers, ” 2025. [Online]. Available: https://arxiv.org/abs/2506.12760

  20. [28]

    Solsmith: Solidity random program generator for compiler testing,

    L. Li, Z. Liu, and Z. Yu, “Solsmith: Solidity random program generator for compiler testing, ” 2025. [Online]. Available: https://arxiv.org/abs/2506.03909

  21. [29]

    soliditylang, https://docs.soliditylang.org/en/latest/contracts.html, 2025, [Online] accessed 2025-03-15

  22. [30]

    Beyond “protected

    Y. Fang, D. Wu, X. Yi, S. Wang, Y. Chen, M. Chen, Y. Liu, and L. Jiang, “Beyond “protected” and “private”: An empirical security analysis of custom function modifiers in smart contracts, ” inProceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and An...

  23. [31]

    Detecting smart contract state-inconsistency bugs via flow divergence and multiplex symbolic execution,

    Y. Liu, W. Meng, and Y. Zhang, “Detecting smart contract state-inconsistency bugs via flow divergence and multiplex symbolic execution, ” Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, 2025

  24. [32]

    Smart contract parallel execution with fine-grained state accesses,

    X. Qi, J. Jiao, and Y. Li, “Smart contract parallel execution with fine-grained state accesses, ” in2023 IEEE 43rd International Conference on Distributed Computing Systems (ICDCS). IEEE, 2023, pp. 841–852

  25. [33]

    A solution for state conflicts of smart contract in interaction with non-blockchain,

    H. Su, B. Guo, Y. Shen, T. Li, C. Qing, and Z. Zhang, “A solution for state conflicts of smart contract in interaction with non-blockchain, ” inIEEE INFOCOM 2020-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). IEEE, 2020, pp. 382–387

  26. [34]

    Gptscan: Detecting logic vulnerabilities in smart contracts by combining gpt with program analysis,

    Y. Sun, D. Wu, Y. Xue, H. Liu, H. Wang, Z. Xu, X. Xie, and Y. Liu, “Gptscan: Detecting logic vulnerabilities in smart contracts by combining gpt with program analysis, ” inProceedings of the IEEE/ACM 46th International Conference on Software Engineering, 2024, pp. 1–13

  27. [35]

    Pomabuster: Detecting price oracle manipulation attacks in decentralized finance,

    R. Xi, Z. Wang, and K. Pattabiraman, “Pomabuster: Detecting price oracle manipulation attacks in decentralized finance, ” in2024 IEEE Symposium on Security and Privacy (SP). IEEE, 2024, pp. 3923–3942

  28. [36]

    Contracttinker: Llm-empowered vulnerability repair for real-world smart contracts,

    C. Wang, J. Zhang, J. Gao, L. Xia, Z. Guan, and Z. Chen, “Contracttinker: Llm-empowered vulnerability repair for real-world smart contracts, ” in Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, 2024, pp. 2350–2353

  29. [37]

    Using my functions should follow my checks: understanding and detecting insecure openzeppelin code in smart contracts,

    H. Liu, D. Wu, Y. Sun, H. Wang, K. Li, Y. Liu, and Y. Chen, “Using my functions should follow my checks: understanding and detecting insecure openzeppelin code in smart contracts, ” in33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, 2024, pp. 3585–3601

  30. [38]

    A coefficient of agreement for nominal scales,

    J. Cohen, “A coefficient of agreement for nominal scales, ”Educational and psychological measurement, vol. 20, no. 1, pp. 37–46, 1960

  31. [39]

    Understanding solidity event logging practices in the wild,

    L. Li, Y. Liang, Z. Liu, and Z. Yu, “Understanding solidity event logging practices in the wild, ” inProceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 2023, pp. 300–312. Manuscript submitted to ...

  32. [40]

    Studying test annotation maintenance in the wild,

    D. J. Kim, N. Tsantalis, T.-H. P. Chen, and J. Yang, “Studying test annotation maintenance in the wild, ” inProceedings of the 43rd International Conference on Software Engineering, ser. ICSE ’21. IEEE Press, 2021, p. 62–73. [Online]. Available: https://doi.org/10.1109/ICSE439...

  33. [41]

    Are comments on stack overflow well organized for easy retrieval by developers?

    H. Zhang, S. Wang, T.-H. P. Chen, and A. E. Hassan, “Are comments on stack overflow well organized for easy retrieval by developers?”ACM Trans. Softw. Eng. Methodol., vol. 30, no. 2, Feb. 2021. [Online]. Available: https://doi.org/10.1145/3434279

  34. [42]

    Characterizing the usage, evolution and impact of java annotations in practice,

    Z. Yu, C. Bai, L. Seinturier, and M. Monperrus, “Characterizing the usage, evolution and impact of java annotations in practice, ”IEEE Transactions on Software Engineering, vol. 47, no. 5, pp. 969–986, 2021

  35. [43]

    How to protect your smart contracts from state bloating and gas griefing attacks,

    codebyankita, “How to protect your smart contracts from state bloating and gas griefing attacks, ” https://medium.com/@ankitacode11/part-2-how- to-protect-your-smart-contracts-from-state-bloating-and-gas-griefing-attacks-2a0be91e249e, 2025, [Online] accessed 2025-11-13

  36. [44]

    Best practices for smart contract security,

    Kaia, “Best practices for smart contract security, ” https://docs.kaia.io/build/best-practices/smart-contract-security-best-practices/, 2025, [Online] accessed 2025-11-13

  37. [45]

    Does the failing test execute a single or multiple faults? an approach to classifying failing tests,

    Z. Yu, C. Bai, and K.-Y. Cai, “Does the failing test execute a single or multiple faults? an approach to classifying failing tests, ” inProceedings of the 37th International Conference on Software Engineering - Volume 1, ser. ICSE ’15. IEEE Press, 2015, p. 924–935

  38. [46]

    Mutation-oriented test data augmentation for gui software fault localization,

    ——, “Mutation-oriented test data augmentation for gui software fault localization, ”Inf. Softw. Technol., vol. 55, no. 12, p. 2076–2098, dec 2013. [Online]. Available: https://doi.org/10.1016/j.infsof.2013.07.004

  39. [47]

    Pre-training code representation with semantic flow graph for effective bug localization,

    Y. Du and Z. Yu, “Pre-training code representation with semantic flow graph for effective bug localization, ” inProceedings of the 31th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 2023

  40. [48]

    A survey on software fault localization,

    W. E. Wong, R. Gao, Y. Li, R. Abreu, and F. Wotawa, “A survey on software fault localization, ”IEEE Transactions on Software Engineering, vol. 42, no. 8, pp. 707–740, 2016

  41. [49]

    Gui software fault localization using n-gram analysis,

    Z. Yu, H. Hu, C. Bai, K.-Y. Cai, and W. E. Wong, “Gui software fault localization using n-gram analysis, ” in2011 IEEE 13th International Symposium on High-Assurance Systems Engineering, 2011, pp. 325–332

  42. [50]

    Genprog: A generic method for automatic software repair,

    C. Le Goues, T. Nguyen, S. Forrest, and W. Weimer, “Genprog: A generic method for automatic software repair, ”IEEE Transactions on Software Engineering, vol. 38, no. 1, pp. 54–72, 2012

  43. [51]

    Automatic software repair: a bibliography,

    M. Monperrus, “Automatic software repair: a bibliography, ”ACM Computing Surveys (CSUR), vol. 51, no. 1, pp. 1–24, 2018

  44. [52]

    Alleviating patch overfitting with automatic test generation: A study of feasibility and effectiveness for the nopol repair system,

    Z. Yu, M. Martinez, B. Danglot, T. Durieux, and M. Monperrus, “Alleviating patch overfitting with automatic test generation: A study of feasibility and effectiveness for the nopol repair system, ”Empirical Softw. Engg., vol. 24, no. 1, p. 33–67, feb 2019. [Online]. Available: ...

  45. [53]

    Learning the relation between code features and code transforms with structured prediction,

    Z. Yu, M. Martinez, Z. Chen, T. F. Bissyandé, and M. Monperrus, “Learning the relation between code features and code transforms with structured prediction, ”IEEE Transactions on Software Engineering, vol. 49, no. 7, pp. 3872–3900, 2023

  46. [54]

    Parameter-efficient fine-tuning with attributed patch semantic graph for automated patch correctness assessment,

    Z. Yang, J. Wu, Z. Yang, and Z. Yu, “Parameter-efficient fine-tuning with attributed patch semantic graph for automated patch correctness assessment, ”arXiv preprint arXiv:2505.02629, 2025

  47. [55]

    S. Urli, Z. Yu, L. Seinturier, and M. Monperrus, “How to design a program repair bot? insights from the repairnator project. in 2018 ieee/acm 40th international conference on software engineering: Software engineering in practice track (icse-seip), ”IEEE Computer Society, Los ...

  48. [56]

    A software-repair robot based on continual learning,

    B. Baudry, Z. Chen, K. Etemadi, H. Fu, D. Ginelli, S. Kommrusch, M. Martinez, M. Monperrus, J. Ron, H. Ye, and Z. Yu, “A software-repair robot based on continual learning, ”IEEE Software, vol. 38, no. 4, pp. 28–35, 2021

  49. [57]

    Towards speeding up program repair with non-autoregressive model,

    Z. Yang, Y. Pan, Z. Yang, and Z. Yu, “Towards speeding up program repair with non-autoregressive model, ” 2025. [Online]. Available: https://arxiv.org/abs/2510.01825

  50. [58]

    Exploring and lifting the robustness of llm-powered automated program repair with metamorphic testing,

    P. Xue, L. Wu, Z. Yang, Z. Yu, Z. Jin, G. Li, Y. Xiao, S. Liu, X. Li, H. Lin, and J. Wu, “Exploring and lifting the robustness of llm-powered automated program repair with metamorphic testing, ” 2025. [Online]. Available: https://arxiv.org/abs/2410.07516

  51. [59]

    Have things changed now? an empirical study of bug characteristics in modern open source software,

    Z. Li, L. Tan, X. Wang, S. Lu, Y. Zhou, and C. Zhai, “Have things changed now? an empirical study of bug characteristics in modern open source software, ” inProceedings of the 1st Workshop on Architectural and System Support for Improving Software Dependability, ser. ASID ’06....

  52. [60]

    Understanding real-world concurrency bugs in go,

    T. Tu, X. Liu, L. Song, and Y. Zhang, “Understanding real-world concurrency bugs in go, ” inProceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems, ser. ASPLOS ’19. New York, NY, USA: Association for C...

  53. [61]

    Understanding and detecting real-world performance bugs,

    G. Jin, L. Song, X. Shi, J. Scherpelz, and S. Lu, “Understanding and detecting real-world performance bugs, ” inProceedings of the 33rd ACM SIGPLAN Conference on Programming Language Design and Implementation, ser. PLDI ’12. New York, NY, USA: Association for Computing Machine...

  54. [62]

    solidity-parser/parser,

    solidity parser, “solidity-parser/parser, ” https://www.npmjs.com/package/@solidity-parser/parser, 2025, [Online] accessed 2025-02-24

  55. [63]

    How early participation determines long-term sustained activity in github projects?

    W. Xiao, H. He, W. Xu, Y. Zhang, and M. Zhou, “How early participation determines long-term sustained activity in github projects?” inProceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 2023, pp. 29–41

  56. [64]

    What’s in a github star? understanding repository starring practices in a social coding platform,

    H. Borges and M. T. Valente, “What’s in a github star? understanding repository starring practices in a social coding platform, ”Journal of Systems and Software, vol. 146, pp. 112–129, 2018

  57. [65]

    foundry, https://book.getfoundry.sh, 2025, [Online] accessed 2025-02-24

  58. [66]

    Manuscript submitted to ACM Understanding Inconsistent State Update Vulnerabilities in Smart Contracts 37

    hardhat, https://hardhat.org/docs, 2025, [Online] accessed 2025-02-24. Manuscript submitted to ACM Understanding Inconsistent State Update Vulnerabilities in Smart Contracts 37

  59. [67]

    A fly in the ointment: an empirical study on the characteristics of ethereum smart contract code weaknesses,

    M. Soud, G. Liebel, and M. Hamdaqa, “A fly in the ointment: an empirical study on the characteristics of ethereum smart contract code weaknesses, ” Empirical Software Engineering, vol. 29, no. 1, p. 13, 2024

  60. [68]

    An empirical study on real bug fixes from solidity smart contract projects,

    Y. Wang, X. Chen, Y. Huang, H.-N. Zhu, J. Bian, and Z. Zheng, “An empirical study on real bug fixes from solidity smart contract projects, ”Journal of Systems and Software, vol. 204, p. 111787, 2023

  61. [69]

    Demystifying invariant effectiveness for securing smart contracts,

    Z. Chen, Y. Liu, S. M. Beillahi, Y. Li, and F. Long, “Demystifying invariant effectiveness for securing smart contracts, ”Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, pp. 1772–1795, 2024

  62. [70]

    Revealing hidden threats: An empirical study of library misuse in smart contracts,

    M. Huang, J. Chen, Z. Jiang, and Z. Zheng, “Revealing hidden threats: An empirical study of library misuse in smart contracts, ” inProceedings of the 46th IEEE/ACM International Conference on Software Engineering, 2024, pp. 1–12

  63. [71]

    Understanding code reuse in smart contracts,

    X. Chen, P. Liao, Y. Zhang, Y. Huang, and Z. Zheng, “Understanding code reuse in smart contracts, ” in2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 2021, pp. 470–479

  64. [72]

    Smartfast: an accurate and robust formal analysis tool for ethereum smart contracts,

    Z. Li, S. Lu, R. Zhang, R. Xue, W. Ma, R. Liang, Z. Zhao, and S. Gao, “Smartfast: an accurate and robust formal analysis tool for ethereum smart contracts, ”Empirical Software Engineering, vol. 27, no. 7, p. 197, 2022

  65. [73]

    Efficiently detecting reentrancy vulnerabilities in complex smart contracts,

    Z. Wang, J. Chen, Y. Wang, Y. Zhang, W. Zhang, and Z. Zheng, “Efficiently detecting reentrancy vulnerabilities in complex smart contracts, ” Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, pp. 161–181, 2024

  66. [74]

    Nyx: Detecting exploitable front-running vulnerabilities in smart contracts,

    W. Zhang, Z. Zhang, Q. Shi, L. Liu, L. Wei, Y. Liu, X. Zhang, and S.-C. Cheung, “Nyx: Detecting exploitable front-running vulnerabilities in smart contracts, ” in2024 IEEE Symposium on Security and Privacy (SP). IEEE, 2024, pp. 2198–2216

  67. [75]

    All your tokens are belong to us: Demystifying address verification vulnerabilities in solidity smart contracts,

    T. Sun, N. He, J. Xiao, Y. Yue, X. Luo, and H. Wang, “All your tokens are belong to us: Demystifying address verification vulnerabilities in solidity smart contracts, ” in33rd USENIX Security Symposium (USENIX Security 24), 2024, pp. 3567–3584

  68. [76]

    Confusum contractum: Confused deputy vulnerabilities in ethereum smart contracts,

    F. Gritti, N. Ruaro, R. McLaughlin, P. Bose, D. Das, I. Grishchenko, C. Kruegel, and G. Vigna, “Confusum contractum: Confused deputy vulnerabilities in ethereum smart contracts, ” in32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 1793–1810

  69. [77]

    Park: accelerating smart contract vulnerability detection via parallel-fork symbolic execution,

    P. Zheng, Z. Zheng, and X. Luo, “Park: accelerating smart contract vulnerability detection via parallel-fork symbolic execution, ” inProceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, 2022, pp. 740–751

  70. [78]

    Graph-of-code: Semantic clone detection using graph fingerprints,

    E. A. Alhazami and A. M. Sheneamer, “Graph-of-code: Semantic clone detection using graph fingerprints, ”IEEE Transactions on Software Engineering, vol. 49, no. 8, pp. 3972–3988, 2023

  71. [79]

    Achecker: Statically detecting smart contract access control vulnerabilities. in 2023 ieee/acm 45th international conference on software engineering (icse),

    A. Ghaleb, J. Rubin, and K. Pattabiraman, “Achecker: Statically detecting smart contract access control vulnerabilities. in 2023 ieee/acm 45th international conference on software engineering (icse), ” 2023

  72. [80]

    A solicitous approach to smart contract verification,

    R. Otoni, M. Marescotti, L. Alt, P. Eugster, A. Hyvärinen, and N. Sharygina, “A solicitous approach to smart contract verification, ”ACM Transactions on Privacy and Security, vol. 26, no. 2, pp. 1–28, 2023

  73. [81]

    Metamorphic testing: A review of challenges and opportunities,

    T. Y. Chen, F.-C. Kuo, H. Liu, P.-L. Poon, D. Towey, T. H. Tse, and Z. Q. Zhou, “Metamorphic testing: A review of challenges and opportunities, ” ACM Comput. Surv., vol. 51, no. 1, Jan. 2018. [Online]. Available: https://doi.org/10.1145/3143561

  74. [82]

    Chapter six - mutation testing advances: An analysis and survey,

    M. Papadakis, M. Kintis, J. Zhang, Y. Jia, Y. L. Traon, and M. Harman, “Chapter six - mutation testing advances: An analysis and survey, ” ser. Advances in Computers, A. M. Memon, Ed. Elsevier, 2019, vol. 112, pp. 275–378. [Online]. Available: https: //www.sciencedirect.com/sc...

  75. [83]

    The emerging field of test amplification: A survey,

    B. Danglot, O. Vera Pérez, Z. Yu, M. Monperrus, and B. Baudry, “The emerging field of test amplification: A survey, ” 05 2017

  76. [84]

    Compiler optimization testing based on optimization-guided equivalence transformations,

    J. Wu, J. Zheng, Z. Yang, and Z. Yu, “Compiler optimization testing based on optimization-guided equivalence transformations, ” inFSE, 2025

  77. [85]

    3-way gui test cases generation based on event-wise partitioning,

    J. Feng, B.-B. Yin, K.-Y. Cai, and Z.-X. Yu, “3-way gui test cases generation based on event-wise partitioning, ” in2012 12th International Conference on Quality Software, 2012, pp. 89–97

  78. [86]

    Unity is strength: enhancing precision in reentrancy vulnerability detection of smart contract analysis tools,

    Z. Wang, J. Chen, P. Zheng, Y. Zhang, W. Zhang, and Z. Zheng, “Unity is strength: enhancing precision in reentrancy vulnerability detection of smart contract analysis tools, ”IEEE Transactions on Software Engineering, 2024

  79. [87]

    Static analysis of integer overflow of smart contracts in ethereum,

    E. Lai and W. Luo, “Static analysis of integer overflow of smart contracts in ethereum, ” inProceedings of the 2020 4th International Conference on Cryptography, Security and Privacy, 2020, pp. 110–115

  80. [88]

    Security threat mitigation for smart contracts: A comprehensive survey,

    N. Ivanov, C. Li, Q. Yan, Z. Sun, Z. Cao, and X. Luo, “Security threat mitigation for smart contracts: A comprehensive survey, ”ACM Computing Surveys, vol. 55, no. 14s, pp. 1–37, 2023

  81. [89]

    Contractfuzzer: Fuzzing smart contracts for vulnerability detection,

    B. Jiang, Y. Liu, and W. K. Chan, “Contractfuzzer: Fuzzing smart contracts for vulnerability detection, ” inProceedings of the 33rd ACM/IEEE international conference on automated software engineering, 2018, pp. 259–269

  82. [90]

    Smartian: Enhancing smart contract fuzzing with static and dynamic data-flow analyses,

    J. Choi, D. Kim, S. Kim, G. Grieco, A. Groce, and S. K. Cha, “Smartian: Enhancing smart contract fuzzing with static and dynamic data-flow analyses, ” in2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE). IEEE, 2021, pp. 227–239

  83. [91]

    Automated test generation for smart contracts via on-chain test case augmentation and migration,

    J. Zhang, J. Chen, J. Grundy, J. Gao, Y. Wang, T. Chen, Z. Guan, and Z. Chen, “Automated test generation for smart contracts via on-chain test case augmentation and migration, ” in2025 IEEE/ACM 47th International Conference on Software Engineering (ICSE). IEEE Computer Society...

  84. [92]

    Fuzzing: a survey,

    J. Li, B. Zhao, and C. Zhang, “Fuzzing: a survey, ”Cybersecurity, vol. 1, pp. 1–13, 2018

  85. [93]

    The art, science, and engineering of fuzzing: A survey,

    V. J. Manès, H. Han, C. Han, S. K. Cha, M. Egele, E. J. Schwartz, and M. Woo, “The art, science, and engineering of fuzzing: A survey, ”IEEE Transactions on Software Engineering, vol. 47, no. 11, pp. 2312–2331, 2019

  86. [94]

    Cute: a concolic unit testing engine for c,

    K. Sen, D. Marinov, and G. Agha, “Cute: a concolic unit testing engine for c, ” inProceedings of the 10th European Software Engineering Conference Held Jointly with 13th ACM SIGSOFT International Symposium on Foundations of Software Engineering, ser. ESEC/FSE-13. New York, NY,...

  87. [95]

    Exe: Automatically generating inputs of death,

    C. Cadar, V. Ganesh, P. M. Pawlowski, D. L. Dill, and D. R. Engler, “Exe: Automatically generating inputs of death, ”ACM Trans. Inf. Syst. Secur., vol. 12, no. 2, Dec. 2008. [Online]. Available: https://doi.org/10.1145/1455518.1455522

  88. [96]

    Dart: directed automated random testing,

    P. Godefroid, N. Klarlund, and K. Sen, “Dart: directed automated random testing, ” inProceedings of the 2005 ACM SIGPLAN Conference on Programming Language Design and Implementation, ser. PLDI ’05. New York, NY, USA: Association for Computing Machinery, 2005, p. 213–223. [Onli...

  89. [97]

    Manticore: A user-friendly symbolic execution framework for binaries and smart contracts,

    M. Mossberg, F. Manzano, E. Hennenfent, A. Groce, G. Grieco, J. Feist, T. Brunson, and A. Dinaburg, “Manticore: A user-friendly symbolic execution framework for binaries and smart contracts, ” in2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE...

  90. [98]

    {SmarTest}: Effectively hunting vulnerable transaction sequences in smart contracts through language{Model-Guided} symbolic execution,

    S. So, S. Hong, and H. Oh, “{SmarTest}: Effectively hunting vulnerable transaction sequences in smart contracts through language{Model-Guided} symbolic execution, ” in30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 1361–1378

  91. [99]

    A survey of symbolic execution techniques,

    R. Baldoni, E. Coppa, D. C. D’elia, C. Demetrescu, and I. Finocchi, “A survey of symbolic execution techniques, ”ACM Computing Surveys (CSUR), vol. 51, no. 3, pp. 1–39, 2018

  92. [100]

    Symbolic execution for software testing in practice: preliminary assessment,

    C. Cadar, P. Godefroid, S. Khurshid, C. S. Păsăreanu, K. Sen, N. Tillmann, and W. Visser, “Symbolic execution for software testing in practice: preliminary assessment, ” inProceedings of the 33rd International Conference on Software Engineering, 2011, pp. 1066–1071

  93. [101]

    Empirical review of automated analysis tools on 47,587 ethereum smart contracts,

    T. Durieux, J. F. Ferreira, R. Abreu, and P. Cruz, “Empirical review of automated analysis tools on 47,587 ethereum smart contracts, ” inProceedings of the ACM/IEEE 42nd International conference on software engineering, 2020, pp. 530–541

  94. [102]

    How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injection,

    A. Ghaleb and K. Pattabiraman, “How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injection, ” inProceedings of the 29th ACM SIGSOFT international symposium on software testing and analysis, 2020, pp. 415–427

  95. [103]

    Gap between theory and practice: An empirical study of security patches in solidity,

    S. Hwang and S. Ryu, “Gap between theory and practice: An empirical study of security patches in solidity, ” inProceedings of the ACM/IEEE 42nd International Conference on Software Engineering, 2020, pp. 542–553

  96. [104]

    Static application security testing (sast) tools for smart contracts: How far are we?

    K. Li, Y. Xue, S. Chen, H. Liu, K. Sun, M. Hu, H. Wang, Y. Liu, and Y. Chen, “Static application security testing (sast) tools for smart contracts: How far are we?”Proceedings of the ACM on Software Engineering, vol. 1, no. FSE, pp. 1447–1470, 2024. Manuscript submitted to ACM

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.