Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

643 papersLast indexed Aug 31, 2026
Search papers

Paper index

643 results · page 2 of 27

Clear filters
Feb 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing

Anthony Coslett

Recent disclosures of industrial-scale knowledge distillation — including campaigns comprising millions of fraudulent API exchanges targeting frontier models [Anthropic, 2026] — have made post-hoc detection of model theft a critical security requirement. Building on a formally-verified framework of log-prob order-statistic geometry, we investigate the adversarial resilience of neural network identity across 72 experimental checkpoints. We establish a Two-Layer Identity Hypothesis: a model’s structural identity (weights-regime geometry) is empirically invariant to distillation (within acceptance threshold epsilon across all 18 protocols), while its functional identity (API-regime Poisson Point Process residuals) predictably transfers to the student, converging up to 52% toward the teacher’s template. Stress-testing this forensic channel against a white-box adversary, we find that functional provenance is geometrically coupled to the knowledge transfer objective. Adversarial erasure gradients are consistently dominated by the distillation loss, achieving only a transient suppression that rebounds within one epoch. Passive fine-tuning on fresh data erases the trace more effectively than any adversarial method, but at a measurable cost to general capability — revealing a Pareto frontier with no favorable region for the adversary. This establishes API forensics as a time-sensitive detective control (“The Tripwire”) and weights-regime identity as the immutable anchor (“The Vault”). Finally, we observe an apparent vulnerability: a cross-family adversarial spoofing attack achieves 69.4% convergence toward a decoy’s fingerprint, while same-family spoofing catastrophically fails. We resolve this paradox by mapping the PPP-residual vector space, revealing that models cluster by capability topology, not corporate lineage. Cross-family “spoofing” is a spatial illusion caused by a narrow 7.8 degree alignment between the decoy and the primary distillation trajectory (R2 = 0.995), whereas same-family decoys are anti-aligned. Across all adversarial interventions, the underlying Gumbel universality (delta_norm) remains invariant (CV = 1.9%). We conclude that during active distillation, an adversary cannot simultaneously acquire a teacher’s capabilities and erase or redirect the forensic trace. In this setting, the geometry forbids it. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Adversarial Robustness in Machine Learning
Digital and Cyber Forensics
Network Security and Intrusion Detection
Original source
Feb 24, 2026·International Journal of Scientific and Research Publications
0 cites
Adaptive Cybersecurity Mechanisms for Climate- Resilient Agricultural IoT Systems

Mansi Dilip Shriwastav, Madhavi Satish Avhankar

The increasing deployment of Agricultural Internet of Things (Ag-IoT) systems is transforming food production and enabling climate-resilient farming practices.However, the growing reliance on interconnected sensing, automation, and cloud platforms significantly expands the attack surface, exposing agricultural operations to cyber threats that can disrupt critical processes, compromise data integrity, and undermine food security.This paper explores adaptive cybersecurity mechanisms designed to enhance the resilience of Ag-IoT ecosystems operating under climate-induced environmental and network constraints.The proposed approach integrates context-aware access control, federated threat learning, zero-trust architectures, and distributed ledger technologies to secure dataflows, device interactions, and supply-chain processes.Experimental evaluations and simulated farm scenarios demonstrate improved attack detection, operational continuity, and system reliability during extreme weather events and adversarial conditions.The results suggest that adaptive cybersecurity strategies are essential for protecting next-generation digital agriculture and ensuring resilient, secure, and sustainable food systems in an era of accelerating climate variability.

Open access
Network Security and Intrusion Detection
IoT and Edge/Fog Computing
Smart Grid Security and Resilience
Original source
Feb 19, 2026·International Conference on Cyber Warfare and Security
0 cites
Systematic Literature Review: Challenges And Issues in the Adoption of SOAR Technology in Cybersecurity

Turki Alshammari, Talal Albalawi

With the increase in the rate of cyber threats, such as ransomware, social engineering, and zero-day exploits, it is urgent to adopt new security mechanisms like Security Orchestration, Automation, and Response (SOAR) systems. The increase in cyber threats has not only amplified in frequency but also in sophistication. This escalation has forced organizations to rethink traditional defense strategies. SOAR has shown itself to be an important solution by automating repetitive tasks and helping security teams in focusing on strategic threat hunting as well as mitigation. The integration of AI and ML in SOAR frameworks helps in predictive analytics, in which systems can anticipate potential breaches based on pattern recognition from vast datasets. The role of blockchain is to enhance data integrity and help enable secure and decentralized threat intelligence sharing between stakeholders. This paper presents a systematic literature review (SLR) on recent advancements in SOAR technologies, especially the incorporation of artificial intelligence (AI), machine learning (ML), and blockchain; it also reviews case studies across various industry sectors, such as healthcare, finance, industrial control systems, and critical infrastructures, as well as the challenges facing SOAR adoption. By examining 29 studies from academic research, industry case studies, and technical reports, the review synthesizes methodologies, architectures, and performance outcomes to summarize the current state of SOAR systems. The research found that SOAR can significantly reduce incident response times and improve threat detection accuracy, with findings indicating that SOAR can lower response times by up to 80% compared to legacy systems, although implementation costs may reach as high as $5 million. Additionally, specialized personnel are still needed to operate these systems. The skills gap increases barriers to adoption, as few professionals possess expertise in cybersecurity as well as in automation tools. Future directions emphasize developing hybrid models that blend human intuition with machine efficiency for more robust defenses. Finally, the review discusses future research directions to help SOAR further scale, interoperate across platforms, and enable autonomous decision-making

Open access
Network Security and Intrusion Detection
Information and Cyber Security
Smart Grid Security and Resilience
Original source
Feb 14, 2026·Applied Sciences
0 cites
Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis

José-María Oliet-Villalba, Jose-Amelio Medina-Merodio, Mikel Ferrer-Oliva, José-Javier Martínez-Herráiz

The rapid growth of cryptocurrencies and non-fungible tokens (NFTs) has expanded technological opportunities, but it has also increased the exposure surface to cyber threats, creating a need for a more precise understanding of the field’s scientific evolution. This study aims to systematically analyse academic output related to cybersecurity and cyber threats within cryptocurrency and NFT ecosystems, identifying central themes, the most influential authors, and emerging trends. A bibliometric methodology was employed, based on the PRISMA 2020 protocol and scientific mapping tools such as SciMAT (v1.1.06) and VOSviewer (v1.6.20), using a corpus of 337 articles published between 2014 and 2025. The findings indicate sustained growth in the literature, a marked geographical and editorial concentration, and the presence of motor themes such as blockchain, cybersecurity, emerging technologies and illegal mining, alongside emerging areas such as intrusion detection. The results also reveal a progressive integration of artificial intelligence techniques in the detection and prevention of attacks. In conclusion, this study provides a comprehensive overview of the state of the art, identifies critical gaps, and underscores the need for interdisciplinary approaches to strengthen security in decentralised environments.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Internet of Things and AI
Original source
Feb 11, 2026·Proceedings of the 2026 Australasian Information Security Conference
0 cites
Adaptive Detection of DeFi SLID Scams: A Data-Driven and Industry-Oriented Framework for Large-Scale DeFi Security

Minh Trung Tran, Brayden Killeen, Tony McGrath

Slow Liquidity Drain (SLID) scams have recently emerged as a subtle and persistent threat within the decentralized finance (DeFi) environment. While prior studies have introduced heuristic and machine learning techniques for identifying SLID behaviors, deploying these methods in real-world industrial systems reveals substantial challenges. In particular, updated large-scale datasets collected from operational DeFi platforms show that SLID behaviors and their effective detection time-range evolve over time, rendering previously reported fixed thresholds unreliable for production use. This work presents a data-driven reassessment of SLID detection under contemporary DeFi conditions and demonstrates that the observation window required for reliable detection shifts as new data and new scam behaviors emerge. Building on these findings, we introduce an industry-oriented detection framework that decouples machine learning models from time-range selection and supports adaptive operation without retraining or feature redesign. Rather than proposing a single deployment strategy, we outline two practical operating modes: a slow-adaptive mode that prioritizes stability and auditability through periodic window updates, and a fast-adaptive mode that enables flexible sensitivity and tiered alerts for security-driven environments. Together, these designs translate empirical insights into concrete system architectures suitable for large-scale DeFi monitoring, bridging the gap between academic SLID detection research and production deployment requirements.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Smart Grid Security and Resilience
Original source
Feb 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
METHOD AND SYSTEM FOR LOCAL AUTONOMOUS INTERNAL PENETRATION TESTING USING RETRIEVAL-AUGMENTED ARTIFICIAL INTELLIGENCE AGENTS

Ruslan Tiahniienko

Description of the Invention The present invention relates to the field of cybersecurity and artificial intelligence, and more particularly to a method and system for local autonomous internal penetration testing using artificial intelligence agents augmented by retrieval-based knowledge mechanisms. The invention discloses a technical solution in which one or more autonomous artificial intelligence agents operate within an internal enterprise environment to continuously assess the security posture of information systems, networks, services, and configurations. Unlike conventional penetration testing approaches that rely on manual effort, predefined scripts, or static rule-based scanners, the proposed system dynamically adapts its behavior based on observed system states, retrieved security knowledge, and learned experience. The system employs reinforcement learning to model penetration testing as a sequential decision-making problem, wherein an agent observes an environment state, selects an action from a defined action space, receives a reward based on the outcome, and updates its policy to maximize an expected cumulative reward associated with discovering security weaknesses, misconfigurations, or policy violations. The environment may include hosts, network topology, authentication mechanisms, access control rules, and security monitoring components. To overcome the limitations of fixed context windows and static knowledge in machine learning models, the invention integrates retrieval-augmented mechanisms. At each decision step, the agent retrieves relevant contextual information from a locally stored vector database containing embeddings of security documentation, vulnerability descriptions, configuration policies, compliance requirements, historical findings, and system metadata. The retrieval process is performed using approximate nearest neighbor search, enabling low-latency access to relevant knowledge at scale. The retrieved contextual data is used to augment the agent’s internal state representation and, in some embodiments, to construct augmented prompts for a local large language model responsible for high-level planning, reasoning, or task decomposition. This combination enables the agent to make informed decisions grounded in both learned behavior and up-to-date domain-specific knowledge. In certain embodiments, the system supports multiple cooperating agents, each specializing in a subset of penetration testing activities, such as reconnaissance, vulnerability identification, exploitation simulation, lateral movement analysis, or compliance auditing. Coordination between agents is achieved through a centralized planner or critic during training, while execution may occur in a decentralized manner. A key feature of the invention is that all data processing, retrieval, learning, and inference are performed locally within the organization’s infrastructure, without transmitting sensitive information to external systems. This design preserves confidentiality, complies with regulatory and organizational privacy requirements, and enables deployment in restricted or high-security environments. The disclosed method and system provide continuous, adaptive, and knowledge-informed internal security assessment, improving the detection of security weaknesses while reducing reliance on manual testing and static tools.

Open access
Information and Cyber Security
Web Application Security Vulnerabilities
Network Security and Intrusion Detection
Original source
Feb 1, 2026·AIP Advances
0 cites
HoloCyberChain: A distributed entropy-fingerprint blockchain for global cyber threat intelligence

Muhammad Arshad, Ali Algarni

This study presents HoloCyberChain, an entropy-driven blockchain framework for decentralized cyber-threat intelligence with formal verification and privacy preservation. Each cyber event is encoded as a four-dimensional entropy fingerprint capturing structural, temporal, behavioral, and propagation uncertainty. A novel Shannon–β hybrid distance integrates residual-entropy geometry with β-divergence-based distributional separation, yielding a unified statistical–topological measure of threat dissimilarity. Residuals are transformed into calibrated novelty probabilities through a logistic uniqueness gate, while a proof-of-detection consensus protocol enables publicly verifiable and Byzantine-resilient acceptance of novel intelligence. Privacy is maintained using zero-knowledge entropy proofs, and accepted threats are organized into a spectral threat-intelligence graph that preserves family-level separability. Simulation experiments demonstrate reliable discrimination (ROC-AUC ≈0.81, PR-AUC ≈0.77) and stable calibration under noise and concept drift. Real-world validation using the CICIDS-2017 dataset (225 745 flows, 79 features; 97 718 benign and 128 027 DDoS flows) confirms that DDoS traffic exhibits higher Shannon–β entropy, with right-shifted density profiles, higher medians, and tighter interquartile ranges relative to benign traffic, indicating that the proposed entropy formulation preserves separability under realistic traffic imbalance. These empirical results align with theoretical guarantees and simulation findings, establishing HoloCyberChain as a reproducible, entropy-verified foundation for scalable and privacy-preserving cyber-threat intelligence sharing.

Open access
Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Privacy-Preserving Technologies in Data
Original source
Jan 28, 2026·Journal of Reliable and Secure Computing
1 cites
Blockchain Consensus Mechanisms and Enhancement Techniques for Federated Learning-Based Intrusion Detection Systems in IoT Smart Homes

Amro Alghamdi, Ismail Keshta

The rapid proliferation of smart home IoT devices has introduced unprecedented cybersecurity vulnerabilities, necessitating scalable and privacy-preserving intrusion detection systems (IDS). Federated Learning (FL) offers a promising decentralized approach by training models locally without sharing raw data, but it remains susceptible to poisoning attacks and relies on a vulnerable central aggregator. This paper presents a novel blockchain-enhanced FL framework tailored for smart home IDS, integrating multiple consensus mechanisms—Proof-of-Stake (PoS), Practical Byzantine Fault Tolerance (PBFT), and Proof-of-Authority (PoA)—for the first time in this context. Our approach uniquely combines differential privacy (DP) and secure aggregation (SA) within a blockchain-managed workflow to mitigate gradient inversion and membership inference attacks while ensuring tamper-resistant, decentralized trust. Experimental evaluation using the N-BaIoT dataset demonstrates that the proposed system achieves up to 88.3% detection accuracy with manageable latency (~200 ms/round) and formal privacy guarantees ($\varepsilon$=1.0 DP). The framework introduces 52.8% system overhead compared to vanilla FL—a reasonable trade-off for enhanced security and privacy. This work establishes a robust, transparent, and scalable security infrastructure for smart homes, effectively addressing the limitations of both centralized and conventional FL-based IDS.

Open access
Network Security and Intrusion Detection
Privacy-Preserving Technologies in Data
Smart Grid Security and Resilience
Original source
Jan 21, 2026·Future Internet
0 cites
IRDS4C–CTIB: A Blockchain-Driven Deception Architecture for Ransomware Detection and Intelligence Sharing

Ahmed El-Kosairy, Heba K. Aslan, Nashwa Abdelbaki

This paper introduces a cybersecurity framework that combines a deception-based ransomware detection system, called the Intrusion and Ransomware Detection System for Cloud (IRDS4C), with a blockchain-enabled Cyber Threat Intelligence platform (CTIB). The framework aims to improve the detection, reporting, and sharing of ransomware threats in cloud environments. IRDS4C uses deception techniques such as honeypots, honeytokens, pretender network paths, and decoy applications to identify ransomware behavior within cloud systems. Tests on 53 Windows-based ransomware samples from seven families showed an ordinary detection time of about 12 s, often quicker than tralatitious methods like file hashing or entropy analysis. These detection results are currently limited to Windows-based ransomware environments, and do not yet cover Linux, containerized, or hypervisor-level ransomware. Detected threats are formatted using STIX/TAXII standards and firmly shared through CTIB. CTIB applies a hybrid blockchain consensus of Proof of Stake (PoS) and Proof of Work (PoW) to ensure data integrity and protection from tampering. Security analysis shows that an attacker would need to control over 71% of the network to compromise the system. CTIB also improves trust, accuracy, and participation in intelligence sharing, while smart contracts control access to erogenous data. In a local prototype deployment (Hardhat devnet + FastAPI/Uvicorn), CTIB achieved 74.93–125.92 CTI submissions/min, The number of attempts or requests in each test was 100 with median end-to-end latency 455.55–724.99 ms (p95: 577.68–1364.17 ms) across PoW difficulty profiles (difficulty_bits = 8–16).

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Digital and Cyber Forensics
Original source
Jan 1, 2026·ITEGAM- Journal of Engineering and Technology for Industrial Applications (ITEGAM-JETIA)
0 cites
Blockchain-Driven Transformer-Based Intrusion Detection and Access Control System (BDL-IDACS)

C. Ramya, A. Suphalakshmi

The increasing complexity of cyber threats across IoT-cloud infrastructures necessitates the use of innovative, flexible, and confidentiality-preserving prevention techniques. The Blockchain-Assisted Hybrid Attention-Based Intrusion Detection and Access Control System (BHA-IDACS) is presented in this paper. The primary detection module employs an Adaptive Spatio-Temporal Representation Architecture-Self-Attention and Intersample Attention Transformer (Astra-SAINT) to precisely detect evolving intrusion tendencies. A heron optimization algorithm (HOA) is utilized for tuning the model thereby improving accuracy of detection and convergence. Fully Homomorphic Encryption (FHE) maintains the security of data and storage of encrypted data in unsecured cloud and blockchain circumstances. On a Consortium Blockchain, all encrypted transactions and audit trails are maintained by a Proof-of-Stake Authority (PoSA) consensus method. Additionally, based on user behavior and trust level, Smart Contract-Based Dynamic Access Control independently enforces permission and authentication regulations. The suggested model provides better precision, recall, F1-score, F2-score, specificity, and Cohen's Kappa values in addition to a mean accuracy of 99.16%. Furthermore, statistical analysis using confidence intervals and low standard deviation values demonstrates that Astra-SAINT is reliable and consistent across all validation folds. These results demonstrate the efficacy of the suggested Astra-SAINT framework as a scalable and dependable intrusion detection method for protecting IoT environments of the next decade.

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Smart Grid Security and Resilience
Original source
Jan 1, 2026·International Journal of Computer Theory and Engineering
0 cites
ZK-FLGuard: Verifiable Privacy via Zero-Knowledge Proofs in Federated Anomaly Detection for 5G Edge-IoT Systems

Mariana Reis

This paper presents Zero-Knowledge Federated Learning Guard (ZK-FLGuard), a privacy-preserving and verifiable federated learning framework for real-time anomaly detection in Fifth-Generation Mobile Network (5G)-enabled Internet of Things (IoT) environments. Building on the integration of zero-knowledge proofs (zk-SNARK—Zero-Knowledge Succinct Non-interactive Argument of Knowledge) and blockchain-based access control, ZK-FLGuard ensures the integrity of model updates without exposing private data. Using real-world intrusion detection datasets (CICIDS2017—Canadian Institute for Cybersecurity Intrusion Detection System 2017, TON_IoT—Telecommunications Organisation of the National Security—IoT) and a synthetic adversarial dataset, our evaluation shows that ZK-FLGuard achieves up to 0.96 F1-score (harmonic mean of precision and recall), improves recall in low-frequency attack detection, and introduces less than 10% additional latency overhead compared to standard Federated Learning (FL). Compared with centralized Long Short-Term Memory (LSTM) and FL without Zero-Knowledge Proof (ZKP), ZK-FLGuard provides competitive accuracy while ensuring verifiable computation and strong privacy guarantees. We address the critical challenge of securing federated anomaly detection in 5G-enabled IoT systems against data leakage, model poisoning, and unauthorized access. While FL preserves privacy by keeping raw data local, it remains vulnerable to gradient leakage and adversarial manipulation. Our hypothesis is that combining zero-knowledge proofs and blockchain with FL can deliver a scalable, tamper-resistant, and privacy-preserving detection pipeline suitable for resource-constrained edge environments.

Open access
Network Security and Intrusion Detection
Adversarial Robustness in Machine Learning
Smart Grid Security and Resilience
Original source
Jan 1, 2026·Computer Modeling in Engineering & Sciences
0 cites
Constructing a Dynamic Trust Assessment Mechanism Combining Zero Knowledge Proof with Unsupervised Learning

Nai‐Wei Lo, Cheng-I Lin, Chih-Chieh Chang, Chi-Yang Chang · 5 authors

The growing frequency of malicious attacks on Internet of Things (IoT) devices has rendered conventional approaches with static label-dependent risk assessment models obsolete, especially when coping with unknown and continuo... | Find, read and cite all the research you need on Tech Science Press

Open access
Security and Verification in Computing
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Jan 1, 2026·SSRN Electronic Journal
0 cites
Counter-Swarm Cyber Operations: A Contemporary Analysis of Autonomous Offensive and Defensive Agent Architectures, Attack Taxonomies, and the Emerging AI Arms Race in Cyberspace

Vishal Chaudhary

The emergence of coordinated, multi-agent offensive systems in cyberspace—variously manifesting as distributed reconnaissance campaigns, AI-assisted vulnerability discovery pipelines, adaptive lateral movement swarms, and cross-domain settlement attacks—has outpaced the formal theoretical treatment necessary for principled defence. This monograph addresses that gap with five primary contributions. First, we model swarm versus counter- swarm interaction as a two-player partially observable stochastic game (POSG) and derive equilibrium conditions under asymmetric information. A sufficient condition is established, via Fano’s inequality, under which an ambiguity-preserving offensive policy becomes dominant on the induced information set; the general exact-solution problem is shown to be intractable unless P = NEXP, because the POSG family strictly contains finite-horizon decentralised partially observable Markov decision processes as a special case. Second, we introduce a formal taxonomy of five autonomous cyber swarm attack classes—distributed reconnaissance, adaptive lateral movement, threshold-splitting exfiltration, semantic service exhaustion, and cross-domain settlement—each coupled to an exact detection decision problem with a worst- case complexity lower bound, an information-theoretic defender error floor, and a formal evasion condition. Third, we propose AEGIS-MESH (Attested Evidence-Gated Interdiction System for Multi-domain Event-Synchronized HotStuff), a new counter-swarm architecture specified as a process-algebraic state machine family, with Byzantine fault tolerance for committees of n ≥ 3f + 1 replicas and five temporal-logic safety invariants enforcing evidence gating, mandatory human approval for destructive actions, and causal auditability. Fourth, we prove that the swarm attribution problem is NP-complete by reduction from Subgraph Isomorphism and derive a closed-form sensor-density lower bound required to guarantee attribution error at most δ. Fifth, we conduct a parametric numerical analysis of the dominance condition, a systematic capability evaluation of contemporary autonomous defence systems against a proposed reproducibility and external-validity framework, and a formal treatment of three Web3 security problems—bridge validator-threshold compromise, blind signing, and TWAP oracle manipulation—before closing with treaty-grade draft governance language and an auditable definition of meaningful human control.

Open access
Infrastructure Resilience and Vulnerability Analysis
Information and Cyber Security
Network Security and Intrusion Detection
Original source
Dec 12, 2025·Proceedings of the 9th International Conference on Algorithms, Computing and Systems
0 cites
Bioluminescent Filament-Inspired AI for Adaptive Smart Contract Intrusion Detection

Love Allen Chijioke Ahakonye, Hamza Ibrahim, Jae-Min Lee, Dong‐Seong Kim

Smart contract environments are increasingly targeted by stealthy, adaptive attacks that evade conventional rule-based or static anomaly detection systems. Inspired by the anglerfish’s bioluminescent filament, which perceives and lures activity in dark, dynamic environments, this research introduces a Bioluminescent Filament-Inspired Artificial Intelligence Perception framework for smart contract intrusion detection. The proposed model emulates biological sensory adaptation through multi-modal attention layers that dynamically illuminate anomalous behaviors in contract execution flows. By integrating self-supervised temporal perception with context-driven feedback, the framework continuously refines its detection sensitivity while maintaining low computational overhead. We evaluate the framework using fuzz-tested smart contract vulnerability datasets that simulate diverse malicious execution behaviors observed in Ethereum environments, demonstrating over 98% detection accuracy with a 40% reduction in latency compared to traditional deep learning-based IDS models. This biologically inspired perception paradigm offers a scalable, energy-efficient solution for securing blockchain-based decentralized systems against evolving threat vectors.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Security and Verification in Computing
Original source
Dec 7, 2025·International Journal of Apllied Mathematics
0 cites
MITIGATING CYBER THREATS THROUGH BLOCK CHAIN BASED INTRUSION DETECTION SYSTEM

T.Pandiselvi

The rapid evolution of cyber threats has exposed fundamental weaknesses in traditional intrusion detection systems, particularly those dependent on centralized architectures vulnerable to data tampering, single-point failures, and delayed threat response. As organizations face increasingly sophisticated attacks, a resilient and transparent framework for detecting and validating abnormal activity has become essential. This study examines the design and effectiveness of a blockchain-based intrusion detection system (BIDS) that leverages distributed consensus, immutable logging, and cooperative threat intelligence to enhance the reliability and responsiveness of security operations. By integrating blockchain technology with anomaly-based and signature-based identification methods, the proposed model establishes a secure environment where intrusion data cannot be altered, suppressed, or manipulated by internal or external adversaries. Through experimental evaluation across simulated network environments, the blockchain-enabled detection model demonstrates significant improvements in event accuracy, traceability, and coordination between participating nodes. The decentralized ledger structure ensures that alerts are validated collectively, reducing false positives and limiting the adversary’s ability to compromise the detection process. The integrity of recorded events also enhances forensic analysis, allowing security teams to reconstruct attack sequences with greater confidence. Additionally, the study reveals that the distributed nature of the system provides high fault tolerance, enabling continuous operation even under attempted denial-of-service conditions or node outages. Performance analysis indicates that blockchain integration does introduce additional computational overhead; however, the trade-off is compensated by the increased transparency, data authenticity, and resistance to insider threats that the system delivers. The research further highlights that smart contracts can automate rule enforcement and improve response mechanisms by triggering protective actions when predefined thresholds are met. This automation contributes to shortening detection-to-response timelines, a critical factor in mitigating fast-moving cyberattacks. Overall, the findings suggest that blockchain-powered intrusion detection represents a promising direction for strengthening network security in decentralized, cloud-based, and large-scale enterprise environments. By combining autonomous threat identification with tamper-proof logging and distributed validation, the proposed approach offers a comprehensive pathway for defending modern digital infrastructures against evolving cyber risks. The study concludes that integrating blockchain technology with intrusion detection principles not only reinforces system resilience but also lays the groundwork for more collaborative, transparent, and secure cybersecurity ecosystems.

Open access
Network Security and Intrusion Detection
Organizational and Employee Performance
Internet of Things and AI
Original source
Dec 5, 2025·Scientific Reports
3 cites
BlockIntelChain: a blockchain-based cyber threat intelligence sharing architecture

Alaa Tolah

The exponential growth of sophisticated cyber threats in Internet of Things (IoT) environments has exposed fundamental weaknesses in existing Cyber Threat Intelligence (CTI) platforms, including centralized architectures, trust deficits, privacy vulnerabilities, and single points of failure. To overcome these limitations, this paper proposes BlockIntelChain, a blockchain-based framework for secure, scalable, and collaborative CTI sharing across distributed IoT networks. The system integrates a hybrid consensus mechanism that combines Proof-of-Stake with reputation-based validator selection, supported by a multi-layered privacy framework employing Differential Privacy (DP), Zero-Knowledge Proofs (ZKP), Homomorphic Encryption, and Secure Multi-Party Computation. BlockIntelChain further embeds Federated Learning (FL) to enable distributed model training directly on IoT edge nodes without exposing raw threat telemetry. Comprehensive evaluations on real-world Malware Information Sharing Platform (MISP) datasets show that BlockIntelChain achieves 923 Transactions per Second at 500 nodes with 99.6% consensus success, while maintaining resilience against 51% and Byzantine attacks tolerating up to 33% malicious validators. Privacy analysis confirms an optimized utility-privacy trade-off, with DP (ε = 0.1) preserving 92% data utility and ZKP achieving 94% verification accuracy. The FL-based models outperform centralized baselines, reaching 96.4% accuracy for IoT malware classification, 94.7% for phishing detection, and 95.2% for network anomaly identification. Economic modeling validates sustainability through contributor growth (156 → 1,245 in 12 months) and improved contribution quality (0.73 → 0.92). The proposed framework directly benefits Security Operation Centers and edge-deployed IoT systems by enabling real-time threat intelligence exchange with strong security, privacy, and efficiency. Comparative benchmarking demonstrates BlockIntelChain's superiority over MISP, ThreatConnect, and IBM X-Force in decentralization, privacy, and cost efficiency, positioning it as a transformative solution for next-generation privacy-aware CTI ecosystems.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Dec 1, 2025·Indonesian Journal of Electrical Engineering and Computer Science
0 cites
SCADE: a deep learning ensemble for semantic flow analysis in smart contract vulnerability detection

Muralidhara Srirama, Usha Banavikal Ajay

A vulnerability in smart contracts refers to weaknesses in the code that can be exploited by attackers, leading to security breaches and unintended behavior. With the growing use of smart contracts in decentralized blockchain systems, particularly in internet of things (IoT) environments, ensuring their security has become increasingly critical. Traditional vulnerability detection techniques, such as formal verification and symbolic execution, face significant limitations, including high rates of false positives and negatives, scalability issues, and difficulty in detecting complex vulnerabilities. To address these challenges, this paper proposes semantic contract flow analysis and deep learning ensemble (SCADE) for smart contract vulnerability detection. SCADE leverages semantic flow analysis combined with an ensemble of deep learning models, including convolutional neural networks (CNN), bidirectional sequence encoder (BSE), layered probabilistic neural network (LPNN), and adaptive context learning network (ACLN), to detect vulnerabilities effectively. The methodology breaks down the smart contract code into structured components through a contract structure mapper, followed by extracting semantic paths and converting them into sequential vector representations. These representations are then processed through a deep learning ensemble to identify potential vulnerabilities such as reentrancy, timestamp dependency, code injection, and hardcoded gas amounts.

Open access
Network Security and Intrusion Detection
Security and Verification in Computing
Advanced Malware Detection Techniques
Original source
Nov 24, 2025·International Journal For Multidisciplinary Research
0 cites
Intelligent and Auditable: A Hybrid AI and Distributed Ledger Framework for Modern Cybersecurity

Naresh Kalimuthu

Modern cyber threats, known for their complexity and constant change, surpass traditional intrusion detection systems (IDS). This paper explores a new security approach that combines Artificial Intelligence (AI) with decentralized architectures to develop IDS that are robust, scalable, and protect user privacy. It examines the core roles of Federated Learning (FL) and Blockchain, highlighting three main research challenges: The vulnerability of AI models to adversarial attacks, privacy and data integrity concerns in collaborative learning, and performance limitations in distributed systems. To address these issues, we suggest solutions such as adversarial training, differential privacy, and lightweight consensus mechanisms. Our analysis of case studies shows that hybrid FL-Blockchain systems outperform traditional methods in practical application environments.

Open access
Network Security and Intrusion Detection
Privacy-Preserving Technologies in Data
Adversarial Robustness in Machine Learning
Original source
Nov 5, 2025·Scientific Reports
3 cites
Quantum deep learning-enhanced ethereum blockchain for cloud security: intrusion detection, fraud prevention, and secure data migration

A. Venkata Nagarjun, R. Sujatha

Because of the rapid acceleration of cloud computing, data transfer security and intrusion detection in cloud networks have become emerging areas of concern. All traditional security mechanisms have central vulnerabilities, cannot detect real-time threats, and are ineffective against zero-day attacks. Signature-based approaches of existing intrusion detection systems (IDS) do not cover the dynamically changing nature of cyber threats. Conventional blockchain security methods suffer from poor scalability and dynamic threat analysis. Therefore, this research proposes integrating Ethereum Blockchain and Deep Learning to construct a well-founded security framework for cloud networks with data migration security and real-time intrusion detection. The architecture has five distinct methods, each of which deals with particular security issues. Blockchain-Aware Federated Learning for Secure Model Training (BAFL SMT) guarantees tamper-proof and decentralized deep learning model training, which reduces model poisoning attacks by 98.4%. Graph Neural Networks for Adaptive Intrusion Detection (GNN-AID) captures graph structures for real-time anomaly detection in networks while reducing false positives to 1.2%. Quantum-inspired Variational Autoencoders (QI VAE ZDAD) provide enhanced zero-day attack detection, with an improved detection rate of 92%. Self-Supervised Contrastive Learning for Blockchain Security Auditing (SSCL-BSA) detects smart contract vulnerabilities automatically, resulting in an 87% reduction in fraud risk. Finally, Hierarchical Transformers for Secure Data Migration (HT SDM) enhance the transfer security of large-scale cloud data, achieving an attack classification accuracy of 99.1%. Overall, this multi-layer security framework will greatly enhance cloud security by preserving data integrity, cutting down the intrusion detection time by up to 65%, and enhancing response mechanisms. By marrying the immutable transparency of blockchain with superior anomaly detection at deep learning, this research provides a scalable, real-time, and intelligent approach to strengthening security against the backed-up transfer of data within cloud networks.

Open access
Network Security and Intrusion Detection
Advanced Graph Neural Networks
Big Data and Digital Economy
Original source
Nov 2, 2025·Journal of Reliable and Secure Computing
10 cites
Privacy and Trust in Blockchain-Federated Intrusion Detection Systems: Taxonomy, Challenges and Perspectives

Cao Yuan, Chin Soon Ku, Rahul Kumar, Arshad Khan

Intrusion Detection Systems (IDS) play a critical role in protecting modern networks, but traditional centralized designs raise serious concerns regarding data privacy, trust, and scalability. Federated Learning (FL) reduces privacy risks through decentralized model training, and blockchain enhances trust by providing immutability and transparency. Combining these technologies creates a promising paradigm for secure and trustworthy IDS. This paper presents a comprehensive survey of blockchain-federated IDS with a particular focus on privacy and trust. The key contribution is a multi-dimensional taxonomy that integrates IDS architectures, FL strategies, blockchain types, and consensus mechanisms, providing a clear and structured view of this emerging field. We categorize threats into data, communication, and model levels, and map representative defense mechanisms to each. We also review applications in vehicular networks, industrial and medical Internet of Things (IoT), and metaverse scenarios. Finally, we highlight key challenges, including non-IID data, lightweight consensus, incentive mechanisms, and poisoning-resilient aggregation, and outline future research directions.

Open access
Privacy-Preserving Technologies in Data
Vehicular Ad Hoc Networks (VANETs)
Network Security and Intrusion Detection
Original source
Oct 27, 2025·Distributed Ledger Technologies Research and Practice
2 cites
Identifying Suspicious Blockchain Transactions Using Clustering with Explainability

Jeyakumar Samantha Tharani, E.Y.A. Charles, Punit Rathore, Zhé Hóu · 6 authors

Blockchain is a distributed ledger technology that provides pseudo-anonymity among participants to maintain privacy. However, malicious actors utilise this property to hide their illegal rewards received through cyber attacks, dark market trades, money laundering and Ponzi schemes. The recent confiscation by the FBI of more than $4 million USD worth of bitcoin from the ‘Silk Road’ dark marketplace indicates the scale of the problem faced by financial regulators and law enforcement authorities. Analysing and identifying harmful actors is, therefore, necessary to regulate the transactions of digital assets. Machine learning models can assist in detecting patterns and correlations between the actors in blockchain networks that may not be apparent through traditional methods. In blockchain networks, the number of actors linked to illegal activities is significantly smaller than that of regular activities. Also, only very limited labelled transaction data is available about these malicious actors. These limitations make it harder to train supervised learning models to provide real-time proactive responses. This article represents a pioneering effort in thoroughly examining the different unsupervised learning methods for clustering suspicious behaviour of actors within blockchain networks. The proposed unsupervised learning-based analysis considers metadata and interconnectivity information of blockchain transactions. The metadata contains time-based and amount-based information. Interconnectivity data represents centrality measures and embedding vectors of the blockchain network. The quality of the identified clusters is validated using internal and external cluster validation measures. The validation results were used to identify influential features using the eXplainable AI technique Shapley (ShAP) values. The results reveal that the features related to the spending and receiving transactions strongly influenced cluster identification. Overall, the centroid-based and connectivity-based approaches identified well-separated clusters for metadata and centrality-based features of blockchain transactions.

Open access
Anomaly Detection Techniques and Applications
Network Security and Intrusion Detection
Imbalanced Data Classification Techniques
Original source
Oct 22, 2025·Automated Software Engineering
5 cites
ByteEye: A smart contract vulnerability detection framework at bytecode level with graph neural networks

Jinni Yang, Shuang Liu, Surong Dai, Yaozheng Fang · 6 authors

Smart contract vulnerability detection has attracted increasing attention due to billions of economic losses caused by vulnerabilities. Existing smart contract vulnerability detection methods have high false negative and high false positive rates. To address these issues, we present ByteEye, a bytecode level smart contract vulnerability detection framework with Graph Neural Networks (GNNs). ByteEye first constructs an edge-enhanced Control Flow Graph (CFG) to maintain rich information from the low-level bytecode with low latency. ByteEye also designs and incorporates both general information and vulnerability-specific information into its detection method as bytecode level features. Furthermore, ByteEye flexibly supports machine/deep learning models, especially with graph neural networks, which can facilitate vulnerability detection precisely. The extensive experimental results highlight that ByteEye outperforms the state-of-the-art approaches on all three types of vulnerability detection. ByteEye can achieve an average of 35.29%, 43.95%, and 6.38% higher on F1 than the bytecode level best-performed baseline on reentrancy vulnerability, timestamp dependency vulnerability, and integer overflow/underflow vulnerability, respectively. Moreover, ByteEye can detect 361 new vulnerabilities in real-world smart contracts, which are reported for the first time. ByteEye enhances control flow information, designs general bytecode-level features with expert knowledge, and flexibly supports deep learning models, particularly GNNs, thus achieving high detection effectiveness.

Open access
2 source records
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Oct 21, 2025·Discover Computing
9 cites
Secure blockchain based intrusion detection for IoT networks

Atul Kumar, Bhisham Sharma, Ajit Noonia

A blockchain-enabled Model integrates blockchain technology with Intrusion Detection Systems to enhance the security of Internet of Things (IoT) networks. It ensures data integrity, decentralization, and tamper-proof logging of intrusion detection. The approach improves trust, transparency, and real-time threat detection in distributed IoT environments. The existing blockchain-based IDS approaches, Blockchain Enabled (BCE-IoT), uniquely integrate blockchain consensus with federated-style local training, lightweight cryptography, and Shapley Additive Explanations (SHAP)-based explainability, ensuring both security and interpretability in IoT environments. The proposed work combines Blockchain technology with explainable artificial intelligence solutions to create a new cybersecurity Model that strengthens intrusion detection within IoT networks. The proposed model enhances transparency in tracking cyberattacks by combining blockchain security storage capabilities with SHAP, an explainable AI. This research utilises machine learning and artificial intelligence to detect threats in real-time, countering Distributed Denial of Service (DDoS), Denial of Service (DoS), scanning, Cross-Site Scripting (XSS), injection, password, and backdoor attacks. BCE-IoT delivers more precise security by combining blockchain’s permanent data features and AI anomaly detectors, thereby reducing security alert mistakes. The performance effectiveness of Blockchain-Enabled IoT surpasses that of the Content Integrity Detection System. It combines Blockchain and Software-Defined Networking to enhance security in network environments, utilising blockchain-based mutual confirmation for software-defined networking to detect and block cyber threats. The evaluation establishes BCE-IoT as an effective IoT network security solution that delivers strong cybersecurity features, is adaptable to modern connected environments, and offers interpretable security solutions. The performance evaluations demonstrate that BCE-IoT provides a robust, flexible, and interpretable cybersecurity solution suitable for modern IoT environments.

Open access
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Oct 17, 2025·Distributed Ledger Technologies Research and Practice
1 cites
Comprehensive Evaluation of Adversarial Perturbations against ML-Based Ethereum Phishing Detection Systems

Ahod Alghuried, Ali Alkinoon, Abdulaziz Alghamdi, Soohyeon Choi · 7 authors

Machine Learning (ML) models are increasingly deployed to detect fraudulent activities in Ethereum, where phishing and scamming attacks pose serious security risks. Despite their promise, these models remain susceptible to adversarial manipulations. In this article, we present a comprehensive evaluation of ML-based Ethereum phishing detectors under a spectrum of adversarial perturbations. Our study examines multiple classifiers, including Random Forest, Decision Tree, K-Nearest Neighbors, Graph Neural Networks, and XGBoost, against rule-based, gradient-based, and black-box adversarial attacks. We conduct detailed feature-level analyses to identify transaction attributes most vulnerable to manipulation, and we evaluate the comparative robustness of classifiers under both targeted and untargeted attack scenarios. To strengthen model resilience, we assess mitigation techniques such as adversarial training and randomized smoothing, demonstrating their effectiveness in improving robustness without significant performance degradation.

Open access
2 source records
Adversarial Robustness in Machine Learning
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source