emekaphilians/trustchainai-codebert
019
trustchainai-codebert
Fine-tuned CodeBERT for Solidity smart contract vulnerability detection.
Part of the TrustChainAI project — an AI-powered smart contract auditor with explainability and ethics monitoring, built to make blockchain security accessible to African and emerging-market Web3 ecosystems.
Model Performance
How to Use
from transformers import pipeline
classifier = pipeline(
"text-classification",
model="emekaphilians/trustchainai-codebert"
)
contract = """
pragma solidity ^0.8.0;
contract Vulnerable {
mapping(address => uint) public balances;
function withdraw() external {
uint amt = balances[msg.sender];
(bool ok,) = msg.sender.call{value: amt}("");
balances[msg.sender] = 0;
}
}
"""
result = classifier(contract[:512])
print(result)
# [{'label': 'reentrancy', 'score': 0.997}]Label Schema
Training Data
Assembled from four open-source sources using the prepare_datasets.py pipeline:
Split: 70% train / 15% val / 15% test (stratified by label).
Training Details
Intended Use
- Pre-deployment security screening of Solidity smart contracts
- Automated vulnerability triage for DeFi protocols
- Research baseline for smart contract security ML benchmarks
- Integration into the TrustChainAI multi-agent audit pipeline
Out-of-Scope Use
- This model is not a substitute for a full professional security audit on high-value contracts
- Performance on Vyper, Yul, or non-EVM contracts is untested
- The
tx_origin_phishingclass has limited real training samples (28); treat predictions for this class with extra caution
Limitations & Bias
- Synthetic augmentation was used for 9 of 13 classes to compensate for dataset scarcity. Synthetic contracts may not fully capture real-world obfuscation patterns.
- The
tx_origin_phishingclass had only 28 real-world training samples; model confidence for this class may be lower in practice. - Training data skews toward older Solidity vulnerability patterns (pre-0.8). Newer attack vectors may be underrepresented.
Citation
@misc{trustchainai2025,
author = {Emeka Philian},
title = {TrustChainAI: AI-Powered Smart Contract Auditor},
year = {2025},
url = {https://github.com/emekaphilian/TrustChainAI}
}Links
- 🔗 GitHub: emekaphilian/TrustChainAI
- 🤗 Profile: emekaphilians
- 📄 Architecture: docs/ARCHITECTURE.md
