Jennifer Bala, Sikiru O. SUBAIRU, Noel M. DOGONYARO, Joseph A. OJENIYI · 5 authors
Blockchain technology, particularly Ethereum, has revolutionized decentralized finance by enabling transparent, secure, and programmable smart contracts. However, these same features have created avenues for financial crimes such as Ponzi schemes, where fraudulent actors exploit pseudonymity and the absence of centralized oversight to deceive investors. This study develops an optimized hybrid detection model that combines eXtreme Gradient Boosting (XGBoost) and Gated Recurrent Units (GRU) to identify Ponzi schemes in Ethereum transaction networks. The model integrates XGBoostâs capability for structured feature learning with GRUâs temporal sequence modeling to capture both static and dynamic behavioral patterns of smart contracts. Using a dataset of 3,866 labeled Ethereum contracts obtained from Kaggle, the research employed advanced preprocessing, temporal sequence enrichment, and class balancing through SMOTE-TS to mitigate data imbalance. Bidirectional optimization, incorporating attention-enhanced GRUs and Bayesian hyperparameter tuning for XGBoost, further improved learning performance and generalization. The model was evaluated using precision, recall, F1-score, ROC-AUC, and PR-AUC, achieving higher detection accuracy of 99% (F1-score = 0.945, ROC-AUC = 0.983) than standalone XGBoost or GRU models. Results demonstrate the hybrid modelâs superior ability to detect temporal and statistical anomalies, reducing false negatives and improving early detection of fraudulent contracts. The approach contributes a scalable and interpretable framework for real-time Ponzi detection in blockchain ecosystems. This research not only enhances the reliability of Ethereumâs financial ecosystem but also offers regulators and developers a novel tool for proactive fraud prevention. Future work could extend this framework to multi-chain detection systems and real-time forensic monitoring.
Fuzzing is a widely used technique for detecting vulnerabilities in smart contracts, which generates transaction sequences to explore the execution paths of smart contracts. However, existing fuzzers are falling short in detecting sophisticated vulnerabilities that require specific attack transaction sequences with proper inputs to trigger, as they (i) prioritize code coverage over vulnerability discovery, wasting considerable effort on non-vulnerable code regions, and (ii) lack semantic understanding of stateful contracts, generating numerous invalid transaction sequences that cannot pass runtime execution. In this paper, we propose SmartFuzz, a novel collaborative reflective fuzzer for smart contract vulnerability detection. It employs large language model-driven agents as the fuzzing engine and continuously improves itself by learning and reflecting through interactions with the environment. Specifically, we first propose a new Continuous Reflection Process (CRP) for fuzzing smart contracts, which reforms the transaction sequence generation as a self-evolving process through continuous reflection on feedback from the runtime environment. Then, we present the Reactive Collaborative Chain (RCC) to orchestrate the fuzzing process into multiple sub-tasks based on the dependencies of transaction sequences. Furthermore, we design a multi-agent collaborative team, where each expert agent is guided by the RCC to jointly generate and refine transaction sequences from both global and local perspectives. We conduct extensive experiments to evaluate SmartFuzz's performance on real-world contracts and DApp projects. The results demonstrate that SmartFuzz outperforms existing state-of-the-art tools: (i) it detects 5.8\%-74.7\% more vulnerabilities within 30 minutes, and (ii) it reduces false negatives by up to 80\%.
Bitcoin's (BTC) Difficulty Adjustment Algorithm (DAA) has been a source of vulnerability for incentive attacks such as selfish mining, block withholding and coin hopping strategies. In this paper, first, we rigorously study the short-term revenue change per hashpower of the adversarial and honest miners for these incentive attacks. To study the long-term effects, we introduce a new efficiency metric defined as the revenue/cost per hashpower per time for the attacker and the honest miners. Our results indicate that the short-term benefits of intermittent mining strategies are negligible compared to the original selfish mining attack, and in the long-term, selfish mining provides better efficiency. We further demonstrate that a coin hopping strategy between BTC and Bitcoin Cash (BCH) relying on BTC DAA benefits the loyal honest miners of BTC in the same way and to the same extent per unit of computational power as it does the hopper in the short-term. For the long-term, we establish a new boundary between the selfish mining and coin hopping attack, identifying the optimal efficient strategy for each parameter. For block withholding strategies, it turns out, the honest miners outside the pool profit from the attack, usually even more than the attacker both in the short-term and the long-term. Moreover, a Power Adjusting Withholding (PAW) attacker does not necessarily observe a profit lag in the short-term. In other words, even without a difficulty adjustment, a PAW attacker makes profits. It has been long thought that the profit lag of selfish mining is among the main reasons why such an attack has not been observed in practice. We show that such a barrier does not apply to PAW and relatively small pools are at an immediate threat.
Syed Muhammad Nadeem Kadery, Rafat Arrahman Al Haque, Md. Mamun Habib
The global apparel industry is highly competitive, demanding innovation and cost-effective production models. Bangladesh, a leading textile exporter, struggles with long lead times (90â100 days) compared to rivals like China and Pakistan. Relying only on cheap labor makes it difficult to sustain market leadership, especially as Cambodia and Vietnam rise. The COVID-19 crisis accelerated blockchain adoption worldwide, particularly in apparel, where it enhances transparency, authentication, and efficiency, strengthening brand image and profits. Blockchain, introduced by Satoshi Nakamoto, offers secure, decentralized data sharing, preventing breaches and fostering trust. For Bangladesh, integrating blockchain into the RMG supply chain could reduce costs, improve stakeholder collaboration, and ensure competitiveness. Research highlights that traditional supply chains depend heavily on labor and contractors, but blockchainâs distributed ledger can streamline information flow among stakeholders. To maintain dominance in the digitized 21st century, Bangladesh must embrace blockchain, ensuring sustainability, customer satisfaction, and global relevance.
10.5281/zenodo.17605813 chaos structure complexity sequences / test files / public domain Chaos Complexity Domain Sequencing"Maximum Entropy Equilibrium"sha384sum OUTFN_BASE-OUTFN_VER-OUTFN_VERMIN-20221230191340.OUTFN_EXT.1069cbf8cebedf73040848960d915d728f8ebce64de339e57c03984b9b125065571ee73cba2fbe8324d57770631f22d3c27download Value Char Occurrences Fraction 0 4000000106 0.500000 1 3999999894 0.500000Total: 8000000000 1.000000Entropy = 1.000000 bits per bit.Optimum compression would reduce the sizeof this 8000000000 bit file by 0 percent.Chi square distribution for 8000000000 samples is 0.00, and randomlywould exceed this value 99.81 percent of the times.Arithmetic mean value of data bits is 0.5000 (0.5 = random).Monte Carlo value for Pi is 3.141394237 (error 0.01 percent).Serial correlation coefficient is 0.000013 (totally uncorrelated = 0.0).sha384sum OUTFN_BASE-OUTFN_VER-OUTFN_VERMIN-20230103155948.OUTFN_EXT.107d6275873f72a0edc7585db17bba50cdfb4a5097f3f50ac7b69eaa85ae8ec95975fb187579a5b05ff0c69ca71378fe71d download Value Char Occurrences Fraction 0 4000000107 0.500000 1 3999999893 0.500000Total: 8000000000 1.000000Entropy = 1.000000 bits per bit.Optimum compression would reduce the sizeof this 8000000000 bit file by 0 percent.Chi square distribution for 8000000000 samples is 0.00, and randomlywould exceed this value 99.81 percent of the times.Arithmetic mean value of data bits is 0.5000 (0.5 = random).Monte Carlo value for Pi is 3.141257485 (error 0.01 percent).Serial correlation coefficient is 0.000004 (totally uncorrelated = 0.0). DATA MORGANA COMMUNICATIONS AUTHOR/ EDWIN J. VENINGEDITOR EDWIN J. VENINGCORRESPONDENCE ADMIN@DATAMORGANA.NETWEBSITE SPAWN HTTPS://WWW.DATAMORGANA.NETRELEASED DD 20230525 [ YYYYMMDD ]EDIT REV.DD 20231208 over 20230726REF <symbolic base> See addendum:- binary ambiguity is expectedIntroduction in Dutch : page 2 20230726 crt0 Addendum: The test vectors presented here stem from the design of a custom generator, originally intended to outperform competitors in various categories of "randomness" generation. The goal was to achieve chaotic streams that exceeded the capabilities of other contenders, without relying on traditional methods for balancing distribution qualities. The resulting system incorporates parametric high-gain, maximum entropy equilibrium functions and methods, with output files available for download from this page. These files are derived from this work and should be used with caution. Historical Context: In 2019, a proposal was made to enhance the cryptographic subsystem of operating systems through a novel approach. This concept involved hardening the system with a new cryptographic processing "idea" of operation(s), integrated within a fresh confidence model. This idea was presented as the open-source project: /dev/entropy, a Unix non-blocking character device designed for non-disclosed ZKP (Zero-Knowledge Proof) seasonal or projected transactions/operations. The goal was to bootstrap system entropy pools using unique host identification, confidence constraints, and host signature processing in its own ZKP design (a system verifier capsule). /dev/entropy was intended to serve as the system entropy pool, which would be well-documented and securely stored. The author and programmer asserted that chaining cryptographic functions could weaken their security, leading to a proposal for entropy pools that would re-seed cryptographic functions in the host stack using non-linear, complexity-driven methods. These operations were intentionally designed to be opaque to prevent exposure, aiming to mitigate known mechanical noise attack vectors and thwart binary dissection. The processing would involve a novel use of "RAM" or "held latent memory." The project concluded in 2019 but remains a significant influence on the development of unique event processing and symbolic information transformations. As for the test vectors, no claims are made regarding their randomness or indexing properties. Envisioned Applications for the Methods and Functions: High-speed calibration of scientific instruments High-gain precision, offering persistent increases in resolution for guidance systems, telemetry, and high-availability scheduling (real-time systems) Persistence of identification tokens, tokenizing information by range, sequence hinting (*), as suggested in the ZKP paper ZKP 'circuitry' / 'gadgets' with enhanced properties, allowing for directional confidence balancing and omni-directional jumps, encoding with unique event processing such as spacetime locality encoding Real-time processing improvements, introducing new priority-type scheduling and domain sequencing (correlated context, with no known limits or recursion results) Application of "lossy" parity and "hashing" in new contexts, utilizing range hinting or the development of a symbolic encoded sequence that persists in noisy systems. The ratio is under testing. Expected hardware development: Domain sequencing through event processors with hardened/optical circuitry and one-way functions These methods aim to serve as a critical infrastructure carrier post-quantum Cryptography (PQC), offering potential solutions for complex network topologies and signal semantics for future interstellar applications. This approach leverages spatial and referential qualities without sudden collapse, adding the Temporal Domain Cryptography from 2015 as part of the ongoing evolution. DISCLAIMER: The contents of these vectors may contain the densest information to date, with an inherent carbon footprint that requires careful handling. Due to the dense nature of this data, it may cause local mechanical friction and, in extreme cases, could lead to combustion. As with any significant discovery, proceed with caution. Note: This is not the recommended practice in the narrowing binary domain of information. For reference: CACert Random Number Results â "No Entropy Here" home https://www.datamorgana.net
Incident reporting systems are integral to maintaining accountability and transparency across critical domains such as cybersecurity, healthcare, and public governance. However, existing centralized mechanisms are prone to manipulation, data loss, and unauthorized modifications. This paper proposes 'IntegriChain', an intelligent and decentralized incident reporting framework that combines Blockchain technology and Artificial Intelligence (AI). The system ensures tamper-proof data storage through SHA-256 hashing and distributed ledger technology while leveraging AI for incident classification, anomaly detection, and risk prediction. This hybrid approach improves security, reliability, and efficiency in reporting workflows. The framework is designed to serve as a scalable solution applicable to multi-domain reporting systems where trust, immutability, and intelligent analysis are critical.
Krithika Rao, Shakil Khan, Bruce Singh, Nagulapati Kiran · 5 authors
Regulatory sandboxesâcontrolled environments where firms test innovations under regulatory supervisionâhave been adopted globally to manage fintech and crypto experimentation. This paper compares sandbox approaches and policy effectiveness for decentralized finance (DeFi) across the European Union, the United States, and the Asia-Pacific. Using a mixed-methods design (document analysis, stakeholder reports, and an illustrative quantitative model), we assess objectives, design choices, risk controls, and outcomes (market access, investor protection, and innovation diffusion). Findings show the EUâs pan-European coordination aims to harmonize testing and legal clarity; the US displays fragmented, agency-led pilot initiatives with stronger enforcement posture; Asia-Pacific exhibits rapid, varied adoption with jurisdictional leaders (Singapore, Hong Kong, Australia) using sandboxes as precursors to more formal rulebooks. Policy effectiveness depends on clarity of legal scope, cross-agency coordination, and well-designed exit and scaling rules. We conclude with policy recommendations and a research agenda for empirically measuring sandbox effectiveness for DeFi.
Arthur Carvalho, Ewerton VinĂcius Pereira da Silva, Gustavo Carvalho Hamade
This scientific article analyzes Law No. 14,478/2022, the âLegal Framework for Cryptocurrenciesâ in Brazil. Adopting a legal-dogmatic approach, the study maps the regulatory advances, such as the creation of an initial normative framework, the criminalization of certain conducts, and the formalization of consumer protection. Conversely, it explores the lawâs limits and gaps, emphasizing the omission of asset segregation and the challenges posed by the decentralized nature of Decentralized Finance (DeFi) and tax uncertainties. A comparative analysis with the European Unionâs MiCA Regulation contextualizes Brazilâs choice for a principles-based model. The study concludes that the lawâs effectiveness will depend on infra-legal regulation and the legal systemâs ability to adapt to the marketâs dynamism.
Abstract - Donation fraud and lack of transparency are major challenges in traditional charity systems, where donors often have limited visibility into how their contributions are utilized. Centralized platforms are prone to data manipulation, unauthorized fund usage, and security breaches, reducing donor confidence. This study explores blockchain-based approaches for securing and accurately managing donation transactions. We review various systems that implement smart contracts, decentralized ledgers, and cryptographic techniques to ensure transparency, traceability, and accuracy in fund distribution. The analysis compares architectural designs, data validation mechanisms, accuracy levels, and security models across existing frameworks. Finally, we highlight current limitations and propose future enhancements to improve scalability, privacy, and real-world implementation of blockchain-based donation management systems. Keywords: Blockchain, Smart Contracts, Donation Security, Transparency, Decentralized Ledger, Cryptography, Ethereum, Zero-Knowledge Proofs, Data Accuracy, Trust Management.
Nan Geng, Can Zhou, Jiafeng Feng, Xin Zhang · 7 authors
The advancing integration of Cyber-Physical-Social Systems (CPSS) within the modern power industry has highlighted the need for enhanced data integrity and multi-entity coordination. In this context, the pursuit of secure and trustworthy lifecycle management for power materials, regarded as a foundational component in ensuring system stability and operational efficiency, has attracted increasing attention. However, existing systems often face limitations such as information opacity, insufficient data accuracy, and the absence of a secure trust mechanism, hindering intelligent development and long-term sustainability. Blockchain technology, distinguished by its distributed ledger, transparency, immutability, and smart contract capabilities, offers a promising solution by enhancing data security and ensuring information reliability. This study introduces a blockchain-based framework for the secure and trustworthy lifecycle management of power materials within CPSS environments, which ensures lifecycle traceability, real-time monitoring, and trustworthy information exchange. By integrating key application scenarios, such as refined equipment management and paperless execution of contracts, the proposed approach addresses crucial operational needs. A multidimensional analysis with conventional systems reveals its advantages in improving management efficiency, optimizing resource allocation, enhancing data security, and reducing operational costs. The proposed framework thus provides both theoretical foundations and practical pathways for leveraging blockchain in power material lifecycle management, enabling digital transformation, managerial innovation, and collaborative industry development.
Mohammed Al Ghafari, Badar Al Alawi, Idris Aal Jumaa, Salah Al Awaidy
Background/Objectives: Oman Vision 2040, the national blueprint for socio-economic transformation, aims to elevate the Sultanate to developed nation status, with the âHealthâ priority committed to building a âLeading Healthcare System with International Standardsâ via a Health in All Policies (HiAP) approach. This paper critically reviews Omanâs strategic health directions and implementation frameworks under Vision 2040, assessing their alignment with global Sustainable Development Goals (SDGs) and serving as a case model for health system transformation. Methods: This study employs a critical narrative synthesis based on a comprehensive literature search that included academic, official government reports, and international organization sources. The analysis is guided by the World Health Organizationâs (WHO) Health Systems Framework, providing a structured interpretation of progress across its six building blocks. Results: Key interventions implemented include integrated governance (e.g., Committee for Managing and Regulating Healthcare), diversified health financing (e.g., public private partnership (PPPs), Health Endowment Foundation), and strategic digital transformation (e.g., Al-Shifa system, AI diagnostics). Performance metrics show progress, with a rise in the Legatum Prosperity Index ranking and an increase in the Community Satisfaction Rate. However, critical challenges persist, including resistance to change during governance restructuring, cybersecurity risks from digital adoption, and system fragmentation that complicates a unified Non-Communicable Disease (NCD) response. Conclusions: Omanâs integrated approach, emphasizing decentralization, quality improvement, and investment in preventive health and human capital, positions it for sustained progress. The transformation offers generalizable insights. Successfully realizing Vision 2040 demands rigorous, evidence-informed policymaking to effectively address equity implications and optimize resource allocation.
Federated learning (FL) offers a distributed approach for the collaborative training of machine learning models across decentralized clients while safeguarding data privacy. This characteristic makes FL well suited for privacy-sensitive fields such as healthcare and finance. However, addressing the heterogeneity caused by nonindependent and identically distributed (non-IID) data remains a significant challenge for traditional FL methods. To address these issues, the enhancing clustered federated learning with adaptive similarity (AS-CFL) algorithm, which dynamically forms client clusters based on model update similarity and uses a forward-incentive mechanism to improve collaborative training efficiency among similar clients, is proposed in this study. Experimental results on the MNIST and EMNIST datasets reveal that compared with baseline methods such as the CFL, IFCA, and FedAvg models, the AS-CFL algorithm achieves faster convergenceâreducing the number of communication rounds by approximately 20%âwhile maintaining competitive accuracy, demonstrating its effectiveness in heterogeneous FL scenarios.
Multi-agent systems (MAS) have emerged as a critical paradigm for distributed problem-solving in complex environments. However, their deployment in mission-critical applications faces significant challenges regarding trust, security, and adversarial robustness. This paper presents TrustOrch, a novel dynamic trust-aware orchestration framework designed to enhance the resilience of multi-agent collaboration against adversarial attacks. TrustOrch introduces five key innovations: (1) a dynamic trust assessment mechanism that evaluates agent reliability in real-time using multi-dimensional metrics, (2) an adversary-aware orchestration strategy combining reinforcement learning and game theory to detect and mitigate prompt injection attacks, (3) an adaptive collaboration topology that dynamically adjusts agent communication structures based on task complexity and trust levels, (4) explainable decision tracing for complete audit chains, and (5) a layered security architecture leveraging blockchain technology for decentralized trust verification. Our experimental evaluation demonstrates that TrustOrch reduces collision rates by 62%, achieves 91.7% robustness under adversarial attacks, and reduces communication overhead by 39.8% compared to baseline approaches. The framework achieves robust performance under various adversarial scenarios while maintaining transparency and regulatory compliance, making it particularly suitable for deployment in high-risk domains such as finance, healthcare, and autonomous systems.
The integration of Bitcoin into corporate treasuries constitutes a critical strategic choice, motivated by its capacity to bolster liquidity and serve as an inflation hedge, while simultaneously being encumbered by pronounced financial volatility and regulatory ambiguity. This investigation examines sectoral variations in Bitcoin adoption, with particular attention to the manner in which financial risks, regulatory structures, and decentralized governance mechanisms shape corporate conduct across the technology, cryptocurrency mining, retail, healthcare, and e-commerce sectors. Drawing on a cross-sectional dataset encompassing 102 publicly traded firms collectively holding 1,001,861 BTC, the analysis employs MAD-based volatility, Firth logistic regression incorporating a U.S. regulatory dummy to account for the BITCOIN Act of 2025, and heatmap visualization to evaluate risk profiles and adoption patterns. Results demonstrate marked sectoral disparities: the technology and mining sectors command predominant holdings yet confront heightened risk exposure, whereas retail and healthcare sectors proceed with greater caution, guided by considerations of cost-value efficiency and regulatory adherence. The U.S. regulatory dummy is significant, indicating the BITCOIN Act facilitates high Bitcoin adoption, while recent transactional activity is marginally significant. The heatmap accentuates the technology sectorâs pre-eminence in aggregate Bitcoin reserves and illuminates the differential influence of regulatory frameworks in non-U.S. jurisdictions. Anchored in Institutional Theory, the Technology Acceptance Model, and Transaction Cost Economics, the study advances the field by quantifying sector-specific risks and visually representing regulatory impacts, thereby furnishing actionable insights for treasury risk management and regulatory policy formulation within a decentralized financial ecosystem.
The integration of artificial intelligence into high-stakes governance has produced a widening âgovernance gapâ between rapid technological capability and slow-moving institutional wisdom. Contemporary alignment approachesâmost notably Reinforcement Learning from Human Feedback (RLHF)âframe safety as a behavioral training problem, yielding agents that perform compliant behaviors without developing structural understanding. This work introduces the Wisdom Forcing Function (WFF), a neurosymbolic architecture implementing alignment-by-architecture, in which democratic principles operate as survival laws rather than optimization targets. Building on Velozâs (2025) theory of aitiopoietic cognition, we hypothesize that robust alignment requires systems to preserve their own organization through causal understanding of viability conditions. We experimentally validate this through a controlled Great Filter test, in which a governance-generating AI faces an abrupt shift from soft to hard constitutional constraints at Generation 4. Upon activation, the system exhibited 100% initial mortality (6/6 frames, fitness = 0.0) caused by metabolic-closure failuresâspecifically, incomplete capital-interaction matrices violating the Wholeness principle. Rather than accepting extinction, the system initiated a rapid homeostatic repair sequence lasting 4.9 seconds, representing a ~10Ă spike in computational work (P_work) relative to baseline fitness evaluation. This thermodynamic event was tightly coupled to diagnostic analysis: the system identified missing capital interactions, generated targeted mutations restoring metabolic closure, and revalidated these repairs against constitutional constraints. One frame (ScaffoldedFrame_5_gen4) successfully recovered, achieving fitness = 0.641âa 63.1% improvement over the previous maximum (0.537)âand enabling evolutionary rescue in subsequent generations. These results provide the first empirical demonstration that artificial systems can bridge Velozâs âthermodynamic disconnect,â exhibiting energy expenditure intrinsically coupled to organizational maintenance rather than output maximization. We show that democratic principles can be encoded not as aspirational norms but as the non-negotiable physics of computational survivalâsupporting systems that are not merely intelligent, but constitutionally alive. SIGNIFICANCE This work represents the first empirical demonstration of aitiopoietic cognition (self-production via causal knowledge) in an artificial system. Unlike current AI alignment approaches that optimize for behavioral compliance, Constitutional Physics treats democratic principles as survival requirementsâviolations cause ontological death, not merely lower scores. VALIDATION - 100% detection rate across 36 governance configurations- 4.9-second autonomous repair (10x computational work increase)- 63.1% fitness improvement through targeted structural reorganization- Complete evolutionary rescue from population bottleneck- Endorsed by Audrey Tang (Taiwan's former Digital Minister)- 140+ downloads in initial 6-day release PRACTICAL APPLICATIONS The system is immediately applicable to:- Decentralized Autonomous Organizations (DAOs) managing $24-35B in treasuries- AI safety research requiring runtime constitutional enforcement - Impact/ESG verification requiring continuous compliance assurance- Community Land Trusts preventing mission drift TECHNICAL AVAILABILITY Implementation code, experimental protocols, and complete session logs available upon request. Commercial pilots available for organizations seeking constitutional governance systems. Contact: c.arleo@localis-ai.uk
Trust management systems (TMS) are crucial for managing trust in distributed environments. The rise of decentralized systems and blockchain has sparked interest in credential-based decentralized trust management systems (DTMS). This paper bridges the gap between theory and practice through a systematic review of credential-based DTMS. We analyze existing DTMS solutions through multiple dimensions, including their architectural designs, credential mechanisms, and trust evaluation models. Our survey provides a detailed taxonomy of credential-based DTMS approaches and establishes comprehensive evaluation criteria for assessing DTMS implementations. Through extensive analysis of current systems and implementations, we identify critical challenges and promising research directions in the field. Our examination offers valuable insights for researchers and practitioners working on DTMS, particularly in areas such as access control, reputation systems, and blockchain-based trust frameworks.
Smart Contract Reusable Components(SCRs) play a vital role in accelerating the development of business-specific contracts by promoting modularity and code reuse. However, the risks associated with SCR usage violations have become a growing concern. One particular type of SCR usage violation, known as a logic-level usage violation, is becoming especially harmful. This violation occurs when the SCR adheres to its specified usage rules but fails to align with the specific business logic of the current context, leading to significant vulnerabilities. Detecting such violations necessitates a deep semantic understanding of the contract's business logic, including the ability to extract implicit usage patterns and analyze fine-grained logical behaviors. To address these challenges, we propose SCRUTINEER, the first automated and practical system for detecting logic-level usage violations of SCRs. First, we design a composite feature extraction approach that produces three complementary feature representations, supporting subsequent analysis. We then introduce a Large Language Model-powered knowledge construction framework, which leverages comprehension-oriented prompts and domain-specific tools to extract logic-level usage and build the SCR knowledge base. Next, we develop a Retrieval-Augmented Generation-driven inspector, which combines a rapid retrieval strategy with both comprehensive and targeted analysis to identify potentially insecure logic-level usages. Finally, we implement a logic-level usage violation analysis engine that integrates a similarity-based checker and a snapshot-based inference conflict checker to enable accurate and robust detection. We evaluate SCRUTINEER from multiple perspectives on 3 ground-truth datasets. The results show that SCRUTINEER achieves a precision of 80.77%, a recall of 82.35%, and an F1-score of 81.55% in detecting logic-level usage violations of SCRs.
This paper presents a secure aggregation system Armadillo that has disruptive resistance against adversarial clients, such that any coalition of malicious clients can affect the aggregation result only by misreporting their private inputs in a pre-defined legitimate range. Armadillo is designed for federated learning setting, where a single powerful server interacts with many weak clients iteratively to train models on client's private data. While a few prior works consider disruption resistance under such setting, for an aggregation on n clients they either require high cost per client (Chowdhury et al. CCS '22) or concretely many rounds that is logarithmic in n (Bell et al. USENIX Security '23). Although disruption resistance can be achieved generically with zero-knowledge proof techniques (which we also use in this paper), we realize an efficient system with two new designs: 1) a simple two-layer secure aggregation protocol that requires only simple arithmetic computation; 2) an agreement protocol that removes the effect of malicious clients from the aggregation with low round complexity. With these techniques, Armadillo runs in 3 rounds per aggregation (our round complexity is independent of n) with computationally lightweight server and clients.
J. Wenzel, Alam, Syeda Umaima, Andreas Schmidt, Hanwei Zhang · 5 authors
An ever increasing number of high-stake decisions are made or assisted by automated systems employing brittle artificial intelligence technology. There is a substantial risk that some of these decision induce harm to people, by infringing their well-being or their fundamental human rights. The state-of-the-art in AI systems makes little effort with respect to appropriate documentation of the decision process. This obstructs the ability to trace what went into a decision, which in turn is a prerequisite to any attempt of reconstructing a responsibility chain. Specifically, such traceability is linked to a documentation that will stand up in court when determining the cause of some AI-based decision that inadvertently or intentionally violates the law. This paper takes a radical, yet practical, approach to this problem, by enforcing the documentation of each and every component that goes into the training or inference of an automated decision. As such, it presents the first running workflow supporting the generation of tamper-proof, verifiable and exhaustive traces of AI decisions. In doing so, we expand the DBOM concept into an effective running workflow leveraging confidential computing technology. We demonstrate the inner workings of the workflow in the development of an app to tell poisonous and edible mushrooms apart, meant as a playful example of high-stake decision support.
Consensus algorithms are essential for blockchain networks to achieve agreement on transaction outcomes. However, mainstream algorithms like Proof of Work (PoW) and Proof of Stake (PoS) exhibit significant limitations in security and efficiency, including high energy consumption, wealth centralization, and a lack of effective node behavior evaluation to guard against internal attacks. To address these issues, this paper proposes an intelligent reputation-based consensus mechanism leveraging a Long Short-Term Memory (LSTM) network. This mechanism analyzes multi-dimensional node attributes (e.g., hostname, country, event sequence, timestamp) to model behavioral patterns using the LSTM, enabling accurate reputation quantification and early detection of malicious intent. Furthermore, we design a dynamic reputation scoring system that calculates a composite reputation score by weighting the LSTMâs predicted score against the nodeâs historical behavior score. This composite score is directly applied to the dynamic election of authoritative nodes and their role assignment within the consensus process. Simulation results demonstrate that, compared to traditional PoW and PoS mechanisms, our approach significantly reduces the attack success rate of malicious nodes attempting to form monopolies, thereby enhancing the fairness of the consensus process and the overall robustness of the system.
With the rapid development of the Internet of Things (IoT), Location-Based Services (LBS) have been widely applied in smart transportation, mobile social networking, and urban sensing. However, the high sensitivity of precise location data makes it a primary source of privacy breaches. Existing privacy-preserving solutionsâsuch as k-anonymity, differential privacy, homomorphic encryption, or decentralized architecturesâthough partially mitigating risks, still rely on trusted third parties for anonymous set generation, key management, or query scheduling, leading to single points of failure, centralized trust, and potential misuse. Even decentralized proposals struggle to balance service quality with strong privacy guarantees, efficient verification, and lightweight deployment. To address this, this paper proposes a lightweight blockchain-based decentralized LBS privacy-preserving framework. This solution eliminates trusted intermediaries: users locally generate privacy-constrained fuzzy regions and construct zero-knowledge proofs (ZKPs) to cryptographically verify their actual locations within these regions. The proofs are submitted to blockchain smart contracts for public verification; only upon successful validation do distributed LBS nodes respond with candidate results, which are finalized through local user filtering. Theoretical analysis and experiments demonstrate that our framework effectively resists privacy inference from semi-honest service providers and external attackers, achieving a balance among query accuracy, response latency, and computational overhead. This provides a viable path for building secure, efficient, and user-centric LBS systems.
Access control is a security mechanism designed to ensure that only authorized users can access specific resources. Cross-domain access control involves access to resources across different organizations, institutions, or applications. Traditional access control, however, which handles authentication and authorization separately in centralized environments, faces challenges in identity dispersion, privacy leakage, and diversified permission requirements, failing to adapt to cross-domain scenarios. Thus, there is an urgent need for a new access control mechanism that empowers autonomous control over user identity and resources, addressing the demands for privacy-preserving authentication and flexible authorization in cross-domain scenarios.To address cross-domain access control challenges, we propose POLARIS, a unified and extensible architecture that enables policy-based, verifiable and privacy-preserving access control across different domains. POLARIS features a structured commitment mechanism for reliable, fine-grained, policy-based identity disclosure. It further introduces VPPL, a lightweight policy language that supports issuer-bound evaluation of selectively revealed attributes. A dedicated session-level security mechanism ensures binding between authentication and access, enhancing confidentiality and resilience to replay attacks.We implement a working prototype and conduct comprehensive experiments, demonstrating that POLARIS effectively provides scalable, privacy-preserving, and interoperable access control across heterogeneous domains. Our results highlight the practical viability of POLARIS for enabling secure and privacy-preserving access control in decentralized, cross-domain environments.
Background: Decentralization in health systems enhances responsiveness and equity but is often accompanied by uneven implementation and resource disparities. Greece' health system has undergone successive phases of decentralization, culminating in a transformation in 2015 when regional health authorities (RHAs) assumed operational responsibility for public primary healthcare (PHC). This study presents the first comprehensive assessment of this transition, examining funding adequacy and resource allocation across RHAs. Methods: Financial and operational analyses were performed to assess disparities among RHAs and between RHAs and hospitals. Data were drawn from publicly available sources, including financial statements, reports from the Ministry of Health, and national statistics. The analysis examined patient visits, staffing levels, infrastructure, funding, labor productivity, and efficiency across health regions. Results: Between 2018 and 2023, patient visits declined at most RHAs. Staffing composition shifted toward nursing personnel, while medical staff numbers declined. Substantial intraregional and interregional disparities were observed in service utilization, staffing, infrastructure, funding, labor productivity, and efficiency. Hospitals continued to absorb a large share of PHC demand and funding, whereas RHA units held markedly fewer assets and received lower financial support. Funding imbalances among RHAs were evident, and the overall negative return on assets indicated systemic underfunding of public PHC. Conclusion: The ongoing decentralization of Greece's health system faces structural challenges, including overlapping territorial jurisdictions and uneven, occasionally insufficient, resource allocation. These challenges hinder progress toward health equity. Policy interventions should prioritize evidence-based resource allocation, standardized financing frameworks, and strengthened PHC integration to promote equitable and sustainable healthcare delivery under decentralized governance.