Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

824 papersLast indexed Aug 31, 2026
Search papers

Paper index

824 results · page 13 of 35

Clear filters
May 1, 2023·2023 IEEE/ACM 45th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP)
7 cites
DAppHunter: Identifying Inconsistent Behaviors of Blockchain-based Decentralized Applications

Jianfei Zhou, Tianxing Jiang, Haijun Wang, Meng Wu · 5 authors

A blockchain-based decentralized application (DApp) refers to an application typically using web pages or mobile applications as the front-end and smart contracts as the back-end. The front-end of the DApp helps users generate transactions and send them to the user’s blockchain wallet. After the user signs and confirms the transaction using the blockchain wallet, the transaction will invoke the smart contract of the DApp. However, users bear the following risks when using DApps because of the potential inconsistent behaviors in DApps. First, the DApp front-end may generate incorrect transactions inconsistent with users’ intentions. Second, the smart contract may have misbehaviors when executing the transactions. Inconsistent behaviors of DApps not only lead to user confusion but also cause significant financial losses. In this paper, we proposed a novel approach to identify inconsistent behaviors of DApps on EVM-compatible blockchains by contrasting the behaviors of DApps that derived from the front-end, blockchain wallet, and smart contracts, respectively. We implemented our approach into a prototype named DAppHunter. We have applied DAppHunter on 92 real-world DApps of Ethereum and Binance Smart Chain and successfully identified 37 DApps with inconsistent behaviors. We confirmed that 35 of them are scam DApps and over 5 million blockchain addresses are at risk of becoming victims of these inconsistent DApps.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
May 1, 2023·2023 IEEE/ACM 20th International Conference on Mining Software Repositories (MSR)
21 cites
MANDO-HGT: Heterogeneous Graph Transformers for Smart Contract Vulnerability Detection

Hoang H. Nguyen, Nhat-Minh Nguyen, Chunyao Xie, Zahra Ahmadi · 7 authors

Smart contracts in blockchains have been increasingly used for high-value business applications. It is essential to check smart contracts' reliability before and after deployment. Although various program analysis and deep learning techniques have been proposed to detect vulnerabilities in either Ethereum smart contract source code or bytecode, their detection accuracy and scalability are still limited. This paper presents a novel framework named MANDO-HGT for detecting smart contract vulnerabilities. Given Ethereum smart contracts, either in source code or bytecode form, and vulnerable or clean, MANDO-HGT custom-builds heterogeneous contract graphs (HCGs) to represent control-flow and/or function-call information of the code. It then adapts heterogeneous graph transformers (HGTs) with customized meta relations for graph nodes and edges to learn their embeddings and train classifiers for detecting various vulnerability types in the nodes and graphs of the contracts more accurately. We have collected more than 55K Ethereum smart contracts from various data sources and verified the labels for 423 buggy and 2,742 clean contracts to evaluate MANDO-HGT. Our empirical results show that MANDO-HGT can significantly improve the detection accuracy of other state-of-the-art vulnerability detection techniques that are based on either machine learning or conventional analysis techniques. The accuracy improvements in terms of F1-score range from 0.7% to more than 76% at either the coarse-grained contract level or the fine-grained line level for various vulnerability types in either source code or bytecode. Our method is general and can be retrained easily for different vulnerability types without the need for manually defined vulnerability patterns.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
May 1, 2023·IEEE BigDataSecurity 2023
5 cites
Exploring Downvoting in Blockchain-based Online Social Media Platforms

Rui Sun, Chao Li, Jingyu Liu, X.-L. Sun

In recent years, Blockchain-based Online Social Media (BOSM) platforms have evolved fast due to the advancement of blockchain technology. BOSM can effectively overcome the problems of traditional social media platforms, such as a single point of trust and insufficient incentives for users, by combining a decentralized governance structure and a cryptocurrency-based incentive model, thereby attracting a large number of users and making it a crucial component of Web3. BOSM allows users to downvote low-quality content and aims to decrease the visibility of low-quality content by sorting and filtering it through downvoting. However, this feature may be maliciously exploited by some users to undermine the fairness of the incentive, reduce the quality of highly visible content, and further reduce users' enthusiasm for content creation and the attractiveness of the platform. In this paper, we study and analyze the downvoting behavior using four years of data collected from Steemit, the largest BOSM platform. We discovered that a significant number of bot accounts were actively downvoting content. In addition, we discovered that roughly 9% of the downvoting activity might be retaliatory. We did not detect any significant instances of downvoting on content for a specific topic. We believe that the findings in this paper will facilitate the future development of user behavior analysis and incentive pattern design in BOSM and Web3.

Open access
2 source records
cs.SI
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Apr 30, 2023·Lecture notes in computer science
1 cites
Breaking Blockchain Rationality with Out-of-Band Collusion

Haoqian Zhang, Mahsa Bastankhah, Louis-Henri Merino, Vero Estrada-Galiñanes · 5 authors

Blockchain systems often rely on rationality assumptions for their security, expecting that nodes are motivated to maximize their profits. These systems thus design their protocols to incentivize nodes to execute the honest protocol but fail to consider out-of-band collusion. Existing works analyzing rationality assumptions are limited in their scope, either by focusing on a specific protocol or relying on non-existing financial instruments. We propose a general rational attack on rationality by leveraging an external channel that incentivizes nodes to collude against the honest protocol. Our approach involves an attacker creating an out-of-band bribery smart contract to motivate nodes to double-spend their transactions in exchange for shares in the attacker's profits. We provide a game theory model to prove that any rational node is incentivized to follow the malicious protocol. We discuss our approach to attacking the Bitcoin and Ethereum blockchains, demonstrating that irrational behavior can be rational in real-world blockchain systems when analyzing rationality in a larger ecosystem. We conclude that rational assumptions only appear to make the system more secure and offer a false sense of security under the flawed analysis.

Open access
2 source records
cs.GT
cs.CR
Blockchain Technology Applications and Security
Original source
Apr 30, 2023·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Custom Blockchain Approach for Identification of Fake Product in Supply Chain Management of E-Commerce Portals

Dr. P. N. Fale, Payal Dahe, Namita Shendre, Priyanshu Khadaskar · 6 authors

Fake products create a huge negative impact in the market for both buyers and sellers. The sellers fails to deliver the product as per the consumers expectations and the consumers starts to doubt the quality and standards of the company which ultimately results in the negative marketing of the brand whose fake products are being circulated in the market. The most critical part about counterfeit products is that it can be harmful for the consumers. Since, the fake or counterfeit products are not restricted to any particular sector in the market therefore it has become important for us to detect these products and find a way to keep them out of the market. These products can be dangerous if we consider very dominating sectors of market like pharmaceutical and food supplies. To tackle such problems, we need to maintain a data, which is easily accessible to consumers where they can verify the details about the products and build a level of trust regarding the product authenticity. As we all know that no product is safe from counterfeiting due to the continuous growth in counterfeit products in the supply chain. It is degrading company's name and their profit; it also affects the customer, for example if this counterfeiting is done in pharmaceutical field, then it will directly affect the customer's health. To counter this problem, the research work has been proposed but not perfected. In this proposed approach, we will be using Blockchain technology to find genuineness of the product. Blockchain technology is generally a ledger system, which holds all the data of the transactions that take place on it. The unique thing about this technology is that the ledger that we mentioned here is a distributed ledger across a peer-to-peer network. Also, we propose a system where we store product's detail and its ownership status on architecture provided by Ethereum. We will be using QR code, which will be scanned by customer such that he/she will be able to find out the details of the product as manufacturing details, current owner etc. and will be able to determine whether the product is fake or real.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
RFID technology advancements
Original source
Apr 29, 2023·arXiv
6 cites
A technique to avoid Blockchain Denial of Service (BDoS) and Selfish Mining Attack

Md. Ahsan Habib, Md. Motaleb Hossen Manik

Blockchain denial of service (BDoS) and selfish mining are the two most crucial attacks on blockchain technology. A classical DoS attack targets the computer network to limit, restrict, or stop accessing the system of authorized users which is ineffective against renowned cryptocurrencies like Bitcoin, Ethereum, etc. Unlike the conventional DoS, the BDoS affects the system's mechanism design to manipulate the incentive structure to discourage honest miners to participate in the mining process. In contrast, in a selfish mining attack, the adversary miner keeps its discovered block private to fork the chain intentionally that aiming to increase the incentive of the adversary miner. This paper proposed a technique to successfully avoid BDoS and selfish mining attacks. The existing infrastructure of blockchain technology does not need to be changed a lot to incorporate the proposed solution.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Apr 28, 2023·International Journal of Advanced Research in Science Communication and Technology
1 cites
Financial Transaction Management for NGO using Block Chain

S Nandini, S Chandana, P M Charanya, Dhanya Suryamath · 5 authors

Non-governmental organizations or NGOs, are primarily nonprofit groups, and a large portion of them are supported by members of NGO and public donations. The credibility of an NGO is substantially enhanced and donor confidence is greatly increased by maintaining transparency regarding how donations are used. Donor organizations provide funding to non-governmental organizations(NGOs) in developing various initiatives such as economic development, women’s empowerment, promoting education, responding to calamities and natural disasters. Due to some NGOs’ involvement in the misuse of funds, some donor agencies cease to have faith in NGOs method of operation. This system is decentralized, not owned or operated by a single person or organization but rather shared among users. We have developed a blockchain-based Donation System capable of decentralizing the resources used by a given organization. The user may create any new organization and others will be allowed to donate money in the organization. As a result, the public become the true owners of the resources, and the charity fund system as a whole becomes more transparent. Blockchain technology and distributed ledgers can reduce operational costs and bring us closer to real-time transactions between financial institutions. System uses cross chain protocol for reliably exchanging information without third party in a multiple Blockchain system

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Spam and Phishing Detection
Original source
Apr 27, 2023·arXiv
1 cites
Bitcoin Double-Spending Attack Detection using Graph Neural Network

Changhoon Kang, Jong-Soo Woo, James Won‐Ki Hong

Bitcoin transactions include unspent transaction outputs (UTXOs) as their inputs and generate one or more newly owned UTXOs at specified addresses. Each U TXO can only be used as an input in a transaction once, and using it in two or more different transactions is referred to as a double-spending attack. Ultimately, due to the characteristics of the Bitcoin protocol, double-spending is impossible. However, problems may arise when a transaction is considered final even though i ts finality has not been fully guaranteed in order to achieve fast payment. In this paper, we propose an approach to detecting Bitcoin double-spending attacks using a graph neural network (GNN). This model predicts whether all nodes in the network contain a given payment transaction in their own memory pool (mempool) using information only obtained from some observer nodes in the network. Our experiment shows that the proposed model can detect double-spending with an accuracy of at least 0.95 when more than about 1% of the entire nodes in the network are observer nodes.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Original source
Apr 26, 2023·Proceedings of the ACM Web Conference 2023
14 cites
Bad Apples: Understanding the Centralized Security Risks in Decentralized Ecosystems

Kailun Yan, Jilian Zhang, Xiangyu Liu, Wenrui Diao · 5 authors

The blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion.

Open access
Blockchain Technology Applications and Security
Privacy, Security, and Data Protection
Spam and Phishing Detection
Original source
Apr 26, 2023·Proceedings of the ACM Web Conference 2023
36 cites
Know Your Transactions: Real-time and Generic Transaction Semantic Representation on Blockchain & Web3 Ecosystem

Zhiying Wu, Jieli Liu, Jiajing Wu, Zibin Zheng · 6 authors

Web3, based on blockchain technology, is the evolving next generation Internet of value. Massive active applications on Web3, e.g. DeFi and NFT, usually rely on blockchain transactions to achieve value transfer as well as complex and diverse custom logic and intentions. Various risky or illegal behaviors such as financial fraud, hacking, money laundering are currently rampant in the blockchain ecosystem, and it is thus important to understand the intent behind the pseudonymous transactions. To reveal the intent of transactions, much effort has been devoted to extracting some particular transaction semantics through specific expert experiences. However, the limitations of existing methods in terms of effectiveness and generalization make it difficult to extract diverse transaction semantics in the rapidly growing and evolving Web3 ecosystem. In this paper, we propose the Motif-based Transaction Semantics representation method (MoTS), which can capture the transaction semantic information in the real-time transaction data workflow. To the best of our knowledge, MoTS is the first general semantic extraction method in Web3 blockchain ecosystem. Experimental results show that MoTS can effectively distinguish different transaction semantics in real-time, and can be used for various downstream tasks, giving new insights to understand the Web3 blockchain ecosystem. Our codes are available at https://github.com/wuzhy1ng/MoTS.

Open access
2 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Spam and Phishing Detection
Original source
Apr 25, 2023·arXiv (Cornell University)
15 cites
Blockchain Large Language Models

Yu Gai, Liyi Zhou, Kaihua Qin, Dawn Song · 5 authors

This paper presents a dynamic, real-time approach to detecting anomalous blockchain transactions. The proposed tool, BlockGPT, generates tracing representations of blockchain activity and trains from scratch a large language model to act as a real-time Intrusion Detection System. Unlike traditional methods, BlockGPT is designed to offer an unrestricted search space and does not rely on predefined rules or patterns, enabling it to detect a broader range of anomalies. We demonstrate the effectiveness of BlockGPT through its use as an anomaly detection tool for Ethereum transactions. In our experiments, it effectively identifies abnormal transactions among a dataset of 68M transactions and has a batched throughput of 2284 transactions per second on average. Our results show that, BlockGPT identifies abnormal transactions by ranking 49 out of 124 attacks among the top-3 most abnormal transactions interacting with their victim contracts. This work makes contributions to the field of blockchain transaction analysis by introducing a custom data encoding compatible with the transformer architecture, a domain-specific tokenization technique, and a tree encoding method specifically crafted for the Ethereum Virtual Machine (EVM) trace representation.

Open access
2 source records
cs.CR
cs.LG
Blockchain Technology Applications and Security
Original source
Apr 25, 2023·IEEE Transactions on Software Engineering
36 cites
Demystifying Random Number in Ethereum Smart Contract: Taxonomy, Vulnerability Identification, and Attack Detection

Peng Qian, Jianting He, Lingling Lu, Siwei Wu · 8 authors

Recent years have witnessed explosive growth in blockchain smart contract applications. As smart contracts become increasingly popular and carry trillion dollars worth of digital assets, they become more of an appealing target for attackers, who have exploited vulnerabilities in smart contracts to cause catastrophic economic losses. Notwithstanding a proliferation of work that has been developed to detect an impressive list of vulnerabilities, the bad randomness vulnerability is overlooked by many existing tools. In this paper, we make the first attempt to provide a systematic analysis of random numbers in Ethereum smart contracts, by investigating the principles behind pseudo-random number generation and organizing them into a taxonomy. We also lucubrate various attacks against bad random numbers and group them into four categories. Furthermore, we present RNVulDet - a tool that incorporates taint analysis techniques to automatically identify bad randomness vulnerabilities and detect corresponding attack transactions. To extensively verify the effectiveness of RNVulDet, we construct three new datasets: i) 34 well-known contracts that are reported to possess bad randomness vulnerabilities, ii) 214 popular contracts that have been rigorously audited before launch and are regarded as free of bad randomness vulnerabilities, and iii) a dataset consisting of 47,668 smart contracts and 49,951 suspicious transactions. We compare RNVulDet with three state-of-the-art smart contract vulnerability detectors, and our tool significantly outperforms them. Meanwhile, RNVulDet spends 2.98s per contract on average, in most cases orders-of-magnitude faster than other tools. RNVulDet successfully reveals 44,264 attack transactions. Our implementation and datasets are released, hoping to inspire others.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Apr 8, 2023·International Journal of Scientific Research in Computer Science Engineering and Information Technology
0 cites
Decentralised Techniques Based White Paper Publication Portal

Hemang Joshi, Hitesh Mewada, Chandan Gupta, Zeyan Ansari · 5 authors

This paper presents the development of a web application, which aims to provide a platform for white paper authors to upload and have their documents reviewed by industry experts and scholars. The web app will utilize Ethereum block chain technology to provide security and authenticity to the uploaded white papers, which will be converted into non-fungible tokens to ensure their uniqueness. The authors will have the ability to self-upload their white papers onto a secured IPFS (Inter Planetary File System) database and use ERC721 (Ethereum Request for Comments) protocols to mint them as non-fungible tokens. In addition, the web app will allow white paper authors to receive crowdfunded support from users holding ETH in their web3 wallets. With our unique authentication system utilizing decentralized techniques, the Paper Publication Portal ensures that only verified authors can publish their work, enhancing both the security and credibility of the platform.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Spam and Phishing Detection
Original source
Apr 6, 2023·arXiv (Cornell University)
5 cites
A Comprehensive Survey of Upgradeable Smart Contract Patterns

Sajad Meisami, William Edward Bodell

In this work, we provide a comprehensive survey of smart contract upgradability patterns using proxies. A primary characteristic of smart contracts on the Ethereum blockchain is that they are immutable once implemented, no changes can be made. Taking human error into account, as well as technology improvements and newly discovered vulnerabilities, there has been a need to upgrade these smart contracts, which may hold enormous amounts of Ether and hence become the target of attacks. Several such attacks have caused tremendous losses in the past, as well as millions of dollars in Ether which has been locked away in broken contracts. Thus far we have collected many upgradable proxy patterns and studied their features to build a comprehensive catalog of patterns. We present a summary of these upgradable proxy patterns which we collected and studied. We scraped the source code for approximately 100000 verified contracts from Etherscan.io, the most popular block explorer for Ethereum, out of which we extracted around 64k unique files - most containing multiple contracts. We have begun to automate the analysis of these contracts using the popular static analysis tool Slither, while at the same time implementing much more robust detection of upgradable proxies using this framework. Comparing the results of the original implementation to our own, we have found that approximately 70 percent of the contracts which were initially flagged as upgradeable proxies are false positives which we have eliminated.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Mar 29, 2023·arXiv (Cornell University)
85 cites
BERT4ETH: A Pre-trained Transformer for Ethereum Fraud Detection

Sihao Hu, Zhen Zhang, Bingqiao Luo, Shengliang Lu · 6 authors

As various forms of fraud proliferate on Ethereum, it is imperative to safeguard against these malicious activities to protect susceptible users from being victimized. While current studies solely rely on graph-based fraud detection approaches, it is argued that they may not be well-suited for dealing with highly repetitive, skew-distributed and heterogeneous Ethereum transactions. To address these challenges, we propose BERT4ETH, a universal pre-trained Transformer encoder that serves as an account representation extractor for detecting various fraud behaviors on Ethereum. BERT4ETH features the superior modeling capability of Transformer to capture the dynamic sequential patterns inherent in Ethereum transactions, and addresses the challenges of pre-training a BERT model for Ethereum with three practical and effective strategies, namely repetitiveness reduction, skew alleviation and heterogeneity modeling. Our empirical evaluation demonstrates that BERT4ETH outperforms state-of-the-art methods with significant enhancements in terms of the phishing account detection and de-anonymization tasks. The code for BERT4ETH is available at: https://github.com/git-disl/BERT4ETH.

Open access
4 source records
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Mar 25, 2023·Advanced Information Technologies and Applications
2 cites
GSVD: Common Vulnerability Dataset for Smart Contracts on BSC and Polygon

Ziniu Shen, Yunfang Chen, Wei Zhang

The blockchain 2.0 age, marked by smart contract and Ethereum, has arrived couple years ago. Its technologies have expanded the application scenarios of blockchain technology and driven the boom of decentralized Finance. However, smart contract vulnerabilities and security issues are also emerging one after another. Hackers have exploited these vulnerabilities to cause huge economic losses. In recent years, a large amount of research on the analysis and detection of smart contract vulnerabilities has emerged, but there has been no common detection tool and corresponding test dataset. In this paper, we build GSVD dataset (Generalized Smart Contract Vulnerability Dataset) consisting four offline datasets using smart contracts on two chains, Polygon and BSC: two small Solidity datasets consisting of 153 labeled smart contract source codes, which can be used to test the performance of vulnerability mining tools; two large Solidity datasets consisting of 52,202 un labeled real smart contract source codes that can be used to verify the correctness of various theories and tools under a large number of real data conditions. At the same time, this paper integrates the scripting framework accompanying the GSVD dataset, which can execute a variety of popular automated vulnerability detection tools on top of these datasets and generate analysis results of contracts and potential vulnerabilities. We tested the Minor dataset under GSVD using three tools (Slither, Manticore, Mythril) that are kept up to date and found that the combined use of all tools detected 61.1% of labeled vulnerabilities, of which Mythril has the highest detection rate of 42.6%. It is not difficult to conclude that there`re still ample room for advancement for current smart contract vulnerability mining tools because of their underlying methods. Besides, our dataset can contribute to the ultimate target greatly by providing mining tools plenty real contracts information.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Mar 25, 2023·Empirical Software Engineering
27 cites
OpenSCV: an open hierarchical taxonomy for smart contract vulnerabilities

Fernando Richter Vidal, Naghmeh Ivaki, Nuno Laranjeiro

Abstract Smart contracts are nowadays at the core of most blockchain systems. Like all computer programs, smart contracts are subject to the presence of residual faults, including severe security vulnerabilities. However, the key distinction lies in how these vulnerabilities are addressed. In smart contracts, when a vulnerability is identified, the affected contract must be terminated within the blockchain, as due to the immutable nature of blockchains, it is impossible to patch a contract once deployed. In this context, research efforts have been focused on proactively preventing the deployment of smart contracts containing vulnerabilities, mainly through the development of vulnerability detection tools. Along with these efforts, several heterogeneous vulnerability classification schemes appeared (e.g., most notably DASP and SWC). At the time of writing, these are mostly outdated initiatives, even though new smart contract vulnerabilities are consistently uncovered. In this paper, we propose OpenSCV, a new and Open hierarchical taxonomy for Smart Contract vulnerabilities, which is open to community contributions and matches the current state of the practice while being prepared to handle future modifications and evolution. The taxonomy was built based on the analysis of the existing research on vulnerability classification, community-maintained classification schemes, and research on smart contract vulnerability detection. We show how OpenSCV covers the announced detection ability of the current vulnerability detection tools and highlight its usefulness in smart contract vulnerability research. To validate OpenSCV, we performed an expert-based analysis wherein we invited multiple experts engaged in smart contract security research to participate in a questionnaire. The feedback from these experts indicated that the categories in OpenSCV are representative, clear, easily understandable, comprehensive, and highly useful. Regarding the vulnerabilities, the experts confirmed that they are easily understandable.

Open access
4 source records
Blockchain Technology Applications and Security
Smart Grid Security and Resilience
Network Security and Intrusion Detection
Original source
Mar 21, 2023·Academic Platform Journal of Engineering and Smart Systems
1 cites
Improving the Prediction Accuracy in Deep Learning-based Cryptocurrency Price Prediction

Furkan BALCI

Cryptocurrencies are popular today even though they do not have a physical form with their high profit rates and increasing usage day by day. However, the volatility of cryptocurrencies is higher than physical currencies. These volatilities change with the effect of social media rather than changes in exchange rates of physical currencies. For this reason, in this study, using Twitter data, one of the most widely used social media tools, real-time analysis on the values of four cryptocurrencies with the highest market value and the change in the estimated success compared to classical approaches were examined. The basic steps of this study: Obtaining Twitter data and financial data, performing sentiment analysis using Twitter data, making predictions on MM-LSTM architecture. The approach is aimed to be a predictive method open to online learning. Various filter steps were applied to remove the effect of bot users on Twitter that could prevent the prediction performance on the created data set, and the effect of the method on accuracy rate was tried to be reduced by eliminating the activity of bot accounts.

Open access
Blockchain Technology Applications and Security
Stock Market Forecasting Methods
Spam and Phishing Detection
Original source
Mar 2, 2023·arXiv (Cornell University)
3 cites
Exploring Unconfirmed Transactions for Effective Bitcoin Address Clustering

Kai Wang, Maike Tong, Changhao Wu, Jun Pang · 7 authors

The development of clustering heuristics has demonstrated that Bitcoin is not completely anonymous. Currently, existing clustering heuristics only consider confirmed transactions recorded in the Bitcoin blockchain. However, unconfirmed transactions in the mempool have yet to be utilized to improve the performance of the clustering heuristics. In this paper, we bridge this gap by combining unconfirmed and confirmed transactions for clustering Bitcoin addresses effectively. First, we present a data collection system for capturing unconfirmed transactions. Two case studies are performed to show the presence of user behaviors in unconfirmed transactions not present in confirmed transactions. Next, we apply the state-of-the-art clustering heuristics to unconfirmed transactions, and the clustering results can reduce the number of entities after applying, for example, the co-spend heuristics in confirmed transactions by 2.3%. Finally, we propose three novel clustering heuristics to capture specific behavior patterns in unconfirmed transactions, which further reduce the number of entities after the application of the co-spend heuristics by 9.8%. Our results demonstrate the utility of unconfirmed transactions in address clustering and further shed light on the limitations of anonymity in cryptocurrencies. To the best of our knowledge, this paper is the first to apply the unconfirmed transactions in Bitcoin to cluster addresses.

Open access
3 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Cybercrime and Law Enforcement Studies
Original source
Mar 1, 2023·Blockchain Research and Applications
19 cites
Security challenges and defense approaches for blockchain-based services from a full-stack architecture perspective

Hongsong Chen, Xietian Luo, Lei Shi, Yongrui Cao · 5 authors

As an advantageous technique and service, the blockchain has shown great development and application prospects. However, its security has also met great challenges, and many security vulnerabilities and attack issues in blockchain-based services have emerged. Recently, security issues of blockchain have attracted extensive attention. However, there is still a lack of blockchain security research from a full-stack architecture perspective, as well as representative quantitative experimental reproduction and analysis. We aim to provide a security architecture to solve security risks in blockchain services from a full-stack architecture perspective. Meanwhile, we propose a formal definition of the full-stack security architecture for blockchain-based services, and we also propose a formal expression of security issues and defense solutions from a full-stack security perspective. We use ConCert to conduct a smart contract formal verification experiment by property-based testing. The security vulnerabilities of blockchain services in the Common Vulnerabilities and Exposures (CVE) and China Nation Vulnerability Database (CNVD) are selected and enumerated. Additionally, three real contract-layer real attack events are reproduced by an experimental approach. Using Alibaba's blockchain services and Identity Mixer in Hyperledger Fabric as a case study, the security problems and defense techniques are analyzed and researched. At last, the future research directions are proposed.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Spam and Phishing Detection
Original source
Feb 16, 2023·Electronics
24 cites
Detecting Phishing Accounts on Ethereum Based on Transaction Records and EGAT

Xuanchen Zhou, Wenzhong Yang, Xiaodan Tian

In recent years, the losses caused by scams on Ethereum have reached a level that cannot be ignored. As one of the most rampant crimes, phishing scams have caused a huge economic loss to blockchain platforms and users. Under these circumstances, to address the threat to the financial security of blockchain, an Edge Aggregated Graph Attention Network (EGAT) based on the static subgraph representation of the transaction network is proposed. This study intends to detect Ethereum phishing accounts through the classification of transaction network subgraphs with the following procedures. Firstly, the accounts are used as nodes and the flow of transaction funds is used as directed edges to construct the transaction network graph. Secondly, the transaction record data of phishing accounts in the publicly available Ethereum are analyzed and statistical features of Value, Gas, and Timestamp values are manually constructed as node and edge features of the graph. Finally, the features are extracted and classified using the EGAT network. According to the experimental results, the Recall of the proposed method from the article is 99.3% on the dataset of phishing accounts. As demonstrated, the EGAT is more efficient and accurate compared with Graph2Vec and DeepWalk, and the graph structure features can express semantics better than manual features and simple transaction networks, which effectively improves the performance of phishing account detection.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Feb 11, 2023·International Journal for Research in Applied Science and Engineering Technology
1 cites
Detection of Counterfeit Medical Products

K M Ramya, L Rachana, Ranjita Kiran Naik, Rashmika Satish · 5 authors

Abstract: Medical product counterfeiting is one of the many major problems facing the healthcare sector. It is estimated that 10 to 30 percent of medical products sold are fake. Because they do not have access to quality healthcare, these issues are more prevalent in undeveloped and developing nations. As the healthcare supply chain is centralised and the procedure from the product's creation to its delivery to the user is opaque, it is challenging to identify counterfeit goods. As a result, the traceability of medicinal products becomes crucial. In addition to the difficulties of data privacy, data authenticity, and adaptability, traditional methods have not been very effective in resolving these problems. In this study, we reviewed several blockchain-based approaches for detecting fake medical items that employ the Ethereum blockchain, Hyperledger fabric, etc. The adoption of innovative ideas, like the inclusion of a QR code which enables customers to discover more about medical products are also studied. We also discuss the various architectures and techniques that are employed. The key challenges faced, and the research gaps are also analysed.

Open access
Pharmaceutical Quality and Counterfeiting
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Feb 10, 2023·International Journal of Reliable and Quality E-Healthcare
12 cites
Blockchain-Based Traceability of Counterfeited Drugs

Bipin Kumar, Shivya Srivastava, Shruti Arora

In the healthcare industry, providing a vital backbone for services is critical. The supply chain is a complex network that crosses organizational and geographical borders. In the healthcare business, counterfeit pills are one of the primary reasons for the harmful impact on human health and financial loss. Thus, pharmaceutical supply chains and end-to-end tracking systems are the recent research in healthcare. In this paper, the authors propose blockchain-based traceability of counterfeited drugs (BBTCD) that implements tracking of counterfeited drugs using smart contracts on the Ethereum blockchain. They offer a solution to fully decentralize the tracking by storing BBTCD on IPFS (inter planetary file system) to provide transparency and cost-effectiveness.

Open access
Blockchain Technology Applications and Security
Pharmaceutical Quality and Counterfeiting
Spam and Phishing Detection
Original source