Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

646 papersLast indexed Aug 31, 2026
Search papers

Paper index

646 results · page 3 of 27

Clear filters
Oct 11, 2025·Cryptography
1 cites
A Two-Layer Transaction Network-Based Method for Virtual Currency Address Identity Recognition

Lingling Xia, Tao Zhu, Zhengjun Jing, Qun Wang · 7 authors

Digital currencies, led by Bitcoin and USDT, are characterized by decentralization and anonymity, which obscure the identities of traders and create a conducive environment for illicit activities such as drug trafficking, money laundering, cyber fraud, and terrorism financing. Focusing on the USDT-TRC20 token on the Tron blockchain, we propose a two-layer transaction network-based approach for virtual currency address identity recognition for digging out hidden relationships and encrypted assets. Specifically, a two-layer transaction network is constructed: Layer A describes the flow of USDT-TRC20 between on-chain addresses over time, while Layer B represents the flow of TRX between on-chain addresses over time. Subsequently, an identity metric is proposed to determine whether a pair of addresses belongs to the same user or group. Furthermore, transaction records are systematically acquired through blockchain explorers, and the efficacy of the proposed recognition method is empirically validated using dataset from the Key Laboratory of Digital Forensics. Finally, the transaction topology is visualized using Neo4j, providing a comprehensive and intuitive representation of the traced transaction pathways.

Open access
Blockchain Technology Applications and Security
Currency Recognition and Detection
Network Security and Intrusion Detection
Original source
Oct 8, 2025·International Journal of Basic and Applied Sciences
0 cites
DDoS Amplification Attack Mitigation in 5G/6G Networks: A Taxonomy, Evaluation, and Defense Framework

Hani Al‐Balasmeh

The evolution of 5G and emerging 6G networks has introduced unprecedented opportunities for connectivity, but also expanded the attack ‎surface for Distributed Denial of Service (DDoS) amplification attacks. Service-Based Architecture (SBA), network slicing, and massive ‎IoT (mMTC) environments create new vectors for reflection and amplification, making conventional defenses inadequate. This paper proposes a novel layered defense framework that integrates edge filtering, AI-driven anomaly detection, slice isolation, cloud scrubbing, and quantum-safe cryptography to mitigate DDoS amplification attacks in 5G/6G environments.‎ The framework is theoretically modeled through equations for amplification, mitigation efficiency, resilience, and defense cost, and evaluated experimentally using simulated signaling floods, IoT-driven amplification, slice-targeted floods, and hybrid attacks. Performance was ‎measured using detection rate, false alarm rate, service availability, resilience score, and resource overhead. Two algorithms—‎pseudonymous authentication with zero-knowledge proof (ZKP) and layered mitigation orchestration—were implemented to operationalize ‎the defense strategy.‎ The results demonstrate that the proposed framework achieves a detection accuracy of 95–97%, reduces false positives to 2%, and maintains ‎a service availability of over 85% under prolonged amplification attacks. It scales efficiently in scenarios with up to 10,000 simulated IoT ‎devices, retaining 70–80% throughput, and maintains URLLC latency below 10 ms, outperforming baseline defenses (firewalls, scrubbing, ‎and AI-only) and state-of-the-art defenses from the literature. These findings validate the framework as a scalable, efficient, and future-ready ‎solution for mitigating amplification attacks in 5G/6G networks, with strong alignment with 3GPP, GSMA, and NIST post-quantum standards‎.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
Oct 8, 2025·Entropy
2 cites
Balanced-BiEGCN: A Bidirectional EvolveGCN with a Class-Balanced Learning Network for Dynamic Anomaly Detection in Bitcoin

Bo Xiao, Wei Yin

Bitcoin transaction anomaly detection is essential for maintaining financial market stability. A significant challenge is capturing the dynamically evolving transaction patterns within transaction networks. Dynamic graph models are effective for characterizing the temporal evolution of transaction systems. However, current methods struggle to mine long-range temporal dependencies and address the class imbalance caused by the scarcity of abnormal samples. To address these issues, we propose a novel approach, the Bidirectional EvolveGCN with Class-Balanced Learning Network (Balanced-BiEGCN), for Bitcoin transaction anomaly detection. This model integrates two key components: (1) a bidirectional temporal feature fusion mechanism (Bi-EvolveGCN) that enhances the capture of long-range temporal dependencies and (2) a Sample Class Transformation (CSCT) classifier that generates difficult-to-distinguish abnormal samples to balance the positive and negative class distribution. The generation of these samples is guided by two loss functions: the adjacency distance adaptive loss function and the symmetric space adjustment loss function, which optimize the spatial distribution and confusion of abnormal samples. Experimental results on the Elliptic dataset demonstrate that Balanced-BiEGCN outperforms existing baseline methods in anomaly detection.

Open access
Anomaly Detection Techniques and Applications
Data Stream Mining Techniques
Network Security and Intrusion Detection
Original source
Sep 15, 2025·Journal of Organizational and End User Computing
2 cites
Neighborhood Subgraph-Based Illicit Transaction Detection in Cryptocurrency Networks

Shenghao Jin, Hui Zhang, Qiwen Yang, Shengyu Chen · 7 authors

With the rise of cryptocurrencies, illicit activities such as money laundering, fraud, and Ponzi schemes have gained attention. Traditional methods using graph neural networks (GNNs) to detect illicit transactions treat the entire transaction network as input, which works well on small networks but struggles with large-scale blockchain data. To address this limitation, the authors propose a neighborhood subgraph-based method that combines GCN and LSTM. The GCN captures information from neighboring nodes for each transaction, enhancing the understanding of the network structure, while the LSTM tracks the sequence and variations of fund flows. Experimental results show that by using 3-hop neighborhood subgraphs, the method outperforms other baseline models while requiring data from only an average of 80 nodes, thereby significantly improving efficiency compared to methods that process the entire transaction network.

Open access
Complex Network Analysis Techniques
Network Security and Intrusion Detection
Advanced Graph Neural Networks
Original source
Sep 13, 2025·International Journal of Innovative Science and Research Technology
2 cites
Federated Learning Based Privacy Preservation Intrusion Detection Using Blockchain Technology

Geetanjali Popat Rokade, Ruturaj Hendre, Vaishnavi Deshmukh, Sejal Wavhal · 5 authors

Integration of Federated Learning (FL) with Blockchain technology to decentralized privacy-preserving, and scalable framework for strengthening cybersecurity. As cyber threats like ransomware, malware, and network intrusions grow in complexity, there is an increasing need for collaborative threat detection and mitigation. However, traditional collaborative approaches often involve sharing sensitive information across organizations, raising significant privacy concerns and regulatory challenges under frameworks like GDPR and HIPAA. FL works to solve these problems through enabling multiple entities to work together on training machine learning models without sharing their original information. Despite its advantages, FL faces challenges such as the risk of model tampering, trust deficits between participants, and dependence on a centralized server for model aggregation. To overcome these limitations the Blockchain technologies will be in used so blockchain technology provides a distributed, transparent, and non-mutable ledger that safely manages FL operations. It helps preserve the accuracy and trustworthiness of model updates via smart contracts along with consensus mechanisms, bypassing the requirement fora central aggregator. In addition, blockchain enables incentivization by introducing token-based rewards, encouraging active participation in collaborative threat detection networks. Privacy- preserving techniques to boost information security, techniques like differential privacy and homomorphic encryption are also put into practice. Such a integration of FL and blockchain is particularly impactful in securing distributed systems such as IoT devices, critical infrastructure, and enterprise networks, where privacy, trust, and scalability are crucial. This project aims to demonstrate the practical implementation of this framework, paving the way for adaptive and globally scalable cyber security systems to combat evolving threats.

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Original source
Aug 29, 2025·Eastern-European Journal of Enterprise Technologies
1 cites
Design of a QKD protocol resistant to insider attacks in fully connected decentralized networks

Yenlik Begimbayeva, Temirlan Zhaxalykov, Amir Akhtanov, Ruslan Pashkevich · 6 authors

This research focuses on enhancing the security of decentralized quantum key distribution (QKD) networks, where the absence of a central authority creates significant challenges such as malicious node infiltration, undetected key leakage, and unauthorized re-entry of revoked participants. Traditional authentication and trust models are insufficient for fully distributed QKD topologies, which remain highly vulnerable to insider threats and persistent compromise. To address these risks, let’s propose a layered security framework composed of three integrated components: Challenge-Response Authentication (CRA), Dynamic Trust Scoring (DTS), and Blockchain-Based Access Control (BBAC). CRA verifies node legitimacy through randomized quantum-state interactions, significantly reducing impersonation and quantum replay attacks. DTS implements real-time trust evaluation using anomaly detection to dynamically downgrade compromised nodes based on their behavioral deviations. BBAC maintains an immutable and tamper-proof trust ledger to block revoked nodes from re-entering under falsified identities and resists Sybil attacks using post-quantum cryptographic primitives. Simulation results confirm that the system improves detection rates of covert threats, ensures authentication latency under 10 ms, and reduces re-entry success to zero. The proposed architecture ensures long-term scalability and resilience, making it applicable to critical domains such as finance, national infrastructure, and military communication. This work contributes a novel, verifiable, and scalable solution to one of the most pressing open problems in distributed quantum networks

Open access
Security in Wireless Sensor Networks
Energy Efficient Wireless Sensor Networks
Network Security and Intrusion Detection
Original source
Aug 25, 2025·Discover Computing
0 cites
Design and implementation of a real-time detection system for multi-token sandwich attacks in Ethereum based on Geth client

Jinyu Bai, Dongze Li, Zhenxuan Jiang, Gang Du

The Ethereum platform is booming with growing richness and variety in decentralized finance (DeFi) products. However, this progress comes with sophisticated threats, such as sandwich attacks, where attackers exploit the openness and certainty of blockchain technology to manipulate market prices and secure illegal financial rewards through a strategically planned series of transactions. The existing sandwich attack detection methods are ineffective at detecting multi-token transactions and fail to identify multi-token sandwich attacks. To tackle this challenge, this study improves the original detector’s algorithm to identify both traditional single-token and multi-token sandwich attacks. The enhanced system is not only responsive and accurate but also capable of detecting and alerting potential multi-token sandwich attacks. It has been successfully integrated with the go-Ethereum client (Geth). The system is performance-optimized with an average processing time of 0.81 seconds per block and an accuracy rate of 96.17%. The response time for detecting new blocks in real-time is usually no more than 4 seconds, with most between 2 and 3 seconds, which meets practical application requirements. By carefully analyzing the transaction data flow, this system is not only able to identify the traditional front-running attack and sandwich attack, but also extends to multi-currency complex attack strategies. The core innovation lies in the system’s ability to accurately detect and provide early warnings of multi-token sandwich attacks through real-time analysis of in-block transactions, all while maintaining the overall operational efficiency of the node.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Aug 6, 2025·International Journal of Science and Research Archive
1 cites
Confidential-computing cyber defense platform sharing threat intelligence, fortifying critical infrastructure against emerging cryptographic attacks nationwide

Yusuff Taofeek Adeshina, Desmond Ohene Poku

In an era marked by increasingly sophisticated cyber threats and growing vulnerabilities in national critical infrastructure, this study explores the transformative role of confidential computing in defending against emerging cryptographic attacks and enabling secure threat intelligence sharing. Traditional cybersecurity measures, while effective for protecting data at rest and in transit, fall short in securing data during active processingan area exploited by advanced persistent threats, quantum computing, and side-channel attacks. This research investigates how hardware-based trusted execution environments (TEEs), homomorphic encryption, and zero-knowledge proofs embedded in confidential-computing platforms can preserve the confidentiality of sensitive operations even within potentially compromised environments. Through detailed case studies of major U.S. institutionsincluding PGandE, Exelon, JPMorgan Chase, Wells Fargo, and Kaiser Permanentethe paper demonstrates significant improvements in detection speed, false positive reduction, and operational efficiency. Furthermore, it proposes a scalable, privacy-preserving framework for collaborative cyber defense across critical sectors such as energy, finance, and healthcare. The findings underscore that integrating confidential computing with decentralized intelligence sharing networks not only enhances cybersecurity resilience but also yields substantial economic and regulatory benefits. This work advocates for a national, and eventually global, shift toward confidential-computing-enabled infrastructures to achieve robust, cooperative, and future-proof cyber defense ecosystems.

Open access
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Aug 4, 2025·Cluster Computing
59 cites
Federated learning in intrusion detection: advancements, applications, and future directions

Büşra Büyüktanır, Şahsene Altınkaya, Gozde Karatas Baydoğmus, Kazım Yıldız

Abstract Federated Learning (FL) has emerged as a promising distributed machine learning approach that addresses confidentiality and integrity concerns in various sectors, including Internet of Things (IoT), healthcare, finance, and cybersecurity. In order to improve privacy protection and detection accuracy in decentralized systems, this study investigates the incorporation of FL into Intrusion Detection Systems (IDS). FL is especially useful in situations where data security and privacy are crucial because it allows for the cooperative training of models without centralizing sensitive data. We examine many FL-based IDS solutions across several domains, emphasizing how well they mitigate data breaches, maintain confidentiality, and enhance intrusion detection capabilities. The use of Generative Adversarial Networks (GANs), artificial immune systems, and hybrid deep learning techniques to maximize IDS performance are among the current developments in FL methodology that are covered in the paper. We also look at issues like the requirement for effective aggregation procedures and non-independent and identically distributed (non-IID) data. Finally, we outline future directions and open research topics to improve the scalability, resilience, and effectiveness of FL-based IDS solutions in practical applications.

Open access
Network Security and Intrusion Detection
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Aug 1, 2025·Journal of Cybersecurity and Privacy
2 cites
AI-Driven Security for Blockchain-Based Smart Contracts: A GAN-Assisted Deep Learning Approach to Malware Detection

Imad Bourian, Lahcen Hassine, Khalid Chougdali

In the modern era, the use of blockchain technology has been growing rapidly, where Ethereum smart contracts play an important role in securing decentralized application systems. However, these smart contracts are also susceptible to a large number of vulnerabilities, which pose significant threats to intelligent systems and IoT applications, leading to data breaches and financial losses. Traditional detection techniques, such as manual analysis and static automated tools, suffer from high false positives and undetected security vulnerabilities. To address these problems, this paper proposes an Artificial Intelligence (AI)-based security framework that integrates Generative Adversarial Network (GAN)-based feature selection and deep learning techniques to classify and detect malware attacks on smart contract execution in the blockchain decentralized network. After an exhaustive pre-processing phase yielding a dataset of 40,000 malware and benign samples, the proposed model is evaluated and compared with related studies on the basis of a number of performance metrics including training accuracy, training loss, and classification metrics (accuracy, precision, recall, and F1-score). Our combined approach achieved a remarkable accuracy of 97.6%, demonstrating its effectiveness in detecting malware and protecting blockchain systems.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Original source
Jul 30, 2025·International Journal for Research in Applied Science and Engineering Technology
0 cites
Blockchain-Based Secure Identity for IoT Networks

M. Rupasri

This review article examines the state of blockchain-enabled identity management in Internet of Things (IoT) networks, focusing on decentralized and secure mechanisms for device identification, authentication, and access control. Traditional centralized identity systems face limitations such as single points of failure, scalability bottlenecks, and vulnerability to breaches. We systematically survey recent literature on blockchain-based frameworks applied to IoT, categorizing approaches by blockchain platform, identity credential models, consensus mechanisms, and smart contract implementations. The analysis highlights key performance metrics such as system latency, throughput, resource overhead, and energy consumption, and compares existing prototypes deployed across diverse IoT scenarios. We assess the security and privacy implications, including resistance to spoofing, Sybil attacks, unauthorized access, data tampering, and insider threats. Additionally, the review identifies open research challenges such as managing identity lifecycle in constrained devices, achieving interoperability across heterogeneous networks, balancing decentralization with scalability, and integrating with emerging technologies like edge computing and zero-knowledge proofs. Finally, we offer recommendations for future research directions and practical deployment strategies to advance blockchain-based identity solutions in IoT ecosystems. Our comprehensive synthesis aims to guide researchers and practitioners in developing robust, scalable, and trustworthy identity frameworks using blockchain for the evolving IoT landscape.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
IoT and Edge/Fog Computing
Original source
Jul 18, 2025·arXiv (Cornell University)
0 cites
The CryptoNeo Threat Modelling Framework (CNTMF): Securing Neobanks and Fintech in Integrated Blockchain Ecosystems

Serhan W. Bahar

The rapid integration of blockchain, cryptocurrency, and Web3 technologies into digital banks and fintech operations has created an integrated environment blending traditional financial systems with decentralised elements. This paper introduces the CryptoNeo Threat Modelling Framework (CNTMF), a proposed framework designed to address the risks in these ecosystems, such as oracle manipulation and cross-chain exploits. CNTMF represents a proposed extension of established methodologies like STRIDE, OWASP Top 10, NIST frameworks, LINDDUN, and PASTA, while incorporating tailored components including Hybrid Layer Analysis, the CRYPTOQ mnemonic for cryptocurrency-specific risks, and an AI-Augmented Feedback Loop. Drawing on real-world data from 2025 incidents, CNTMF supports data-driven mitigation to reduce losses, which totalled approximately $2.47 billion in the first half of 2025 across 344 security events (CertiK via GlobeNewswire, 2025; Infosecurity Magazine, 2025). Its phases guide asset mapping, risk profiling, prioritisation, mitigation, and iterative feedback. This supports security against evolving risks like state-sponsored attacks.

Open access
2 source records
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Economic and Technological Systems Analysis
Original source
Jul 4, 2025·World Journal of Advanced Research and Reviews
4 cites
Enhancing malware detection using federated learning and explainable AI for privacy-preserving threat intelligence

Kigbu Shallom, Chukwujekwu Damian Ikemefuna

The escalating complexity and frequency of malware attacks pose a significant challenge to conventional cybersecurity frameworks, particularly in scenarios demanding high data privacy and cross-organizational threat intelligence sharing. Traditional centralized machine learning models for malware detection often rely on aggregating data in a central server, thereby increasing the risk of data breaches and limiting the deployment of models in privacy-sensitive environments such as healthcare, finance, and critical infrastructure. To address these limitations, this study explores an integrated approach that combines Federated Learning (FL) with Explainable Artificial Intelligence (XAI) for enhancing malware detection while preserving user privacy and system confidentiality. Federated learning enables the collaborative training of robust malware classifiers across multiple decentralized nodes without sharing raw data, thus maintaining local data sovereignty and complying with data protection regulations. The proposed framework incorporates deep learning architectures such as convolutional neural networks (CNNs) trained in a federated environment using feature vectors extracted from malicious binaries and behavior logs. To ensure transparency and trust in model predictions, explainable AI techniques specifically SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) are integrated, providing actionable insights into the model’s decision-making process. This study also presents a comprehensive evaluation using a benchmark malware dataset distributed across simulated client environments, measuring detection accuracy, communication overhead, privacy leakage, and interpretability performance. Results demonstrate that the FL-XAI approach achieves detection rates comparable to centralized models while ensuring data confidentiality and interpretability. The research contributes to the evolving field of privacy-preserving threat intelligence by offering a scalable and explainable framework suitable for real-time cybersecurity applications.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Digital and Cyber Forensics
Original source
Jul 1, 2025·EPJ Data Science
0 cites
Bitcoin transaction behavior modes exploration based on balance data

Yu Zhang, Yafei Li, Jufang Zhang, Claudio J. Tessone

When analyzing the balance distribution of Bitcoin users, we found that it follows a log-normal pattern based on a rigorous Uniformly-Most-Powerful-Unbiased test. Drawing parallels from the successful application of Gibrat’s law in explaining city size and word frequency distributions, we tested whether a similar principle could account for the log-normal distribution in Bitcoin balances. However, our calculations revealed that the exponent parameters in both the drift and variance terms deviate slightly from 1 when applying Geometric-Brownian-Motion on the Bitcoin balance, which means that Bitcoin users’ balance distribution cannot be explained only by the proportional growth rule alone. During this exploration, Bitcoin users’ behaviors are also investigated. We discovered an intriguing phenomenon: Bitcoin users tend to fall into two distinct categories based on their transaction behavior, which we refer to as “poor” and “wealthy” users. Poor users who initially purchase only a small amount of Bitcoin tend to buy more Bitcoins first and then sell out all their holdings over time. The certainty of selling all their coins is higher and higher with time. In contrast, wealthy users who acquire a large amount of Bitcoin from the start tend to sell off their holdings over time. The speed at which they sell their Bitcoins is lower and lower over time. The wealthier the user, the larger the proportion of their balance and the higher the certainty they tend to sell their holdings. This research provided a new perspective to explore Bitcoin users’ behaviors which may apply to other finance markets.

Open access
Blockchain Technology Applications and Security
Data Stream Mining Techniques
Network Security and Intrusion Detection
Original source
Jul 1, 2025·Forensic Science International Digital Investigation
0 cites
Improved Bitcoin simulation model and address heuristic method

Yanan Gong, K. P. Chow, Siu Ming Yiu

Cryptocurrency-related crimes are on the rise and have a wide-ranging impact across various areas. To effectively combat and prevent such crimes, cryptocurrency forensics, which relies on blockchain analysis, is essential. Despite advancements in Bitcoin de-anonymization techniques, several challenges persist. The absence of authentic data labels introduces uncertainty in de-anonymization results, especially in the context of address clustering. This issue is further compounded by the development of privacy-enhancing technologies that obscure address linkages, thus undermining the reliability of outcomes as forensic evidence. To address these limitations, this study focuses on Bitcoin blockchain analysis and the improvement of address clustering. Specifically, the work presents an enhanced simulation model designed to accurately simulate real Bitcoin transactions, offering a stable platform for evaluating address clustering algorithms that utilize transaction details, thereby facilitating the assessment of the admissibility of clustering results. Meanwhile, we introduce a new heuristic algorithm aimed at identifying one-time change addresses, with experimental results demonstrating that it achieves more precise clustering outcomes than existing heuristic methods. Furthermore, our blockchain analysis reveals overarching patterns and recent changes in the Bitcoin blockchain, particularly following the introduction of the BRC-20 token.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Caching and Content Delivery
Original source
Jul 1, 2025·International Journal of Advances in Soft Computing and its Applications
3 cites
Enhancing VANET Security with Lattice-Based Cryptography and Dynamic Pseudonym Updates

Adi El‐Dalahmeh

Ensuring secure and efficient authentication in Vehicular Ad Hoc Networks (VANETs) is vital for real-time communication and network resilience. However, traditional authentication mechanisms, such as Elliptic Curve Cryptography (ECC) and Public Key Infrastructure (PKI), face significant challenges, including high computational overhead, complex certificate revocation, and vulnerability to quantum attacks. To overcome these limitations, we propose a lattice-based authentication protocol that integrates post-quantum cryptography (PQC), zero-knowledge proofs (ZKPs), and fog computing for secure Vehicle-to-Roadside (V2R) communication. Our protocol offers quantum resistance, decentralized authentication, and dynamic pseudonym updates, enhancing both security and privacy in VANETs. Performance evaluations demonstrate that our approach achieves lower message delay (0.8), reduced packet loss ratio (0.6), minimal communication overhead (0.7), and the fastest authentication delay (0.5) compared to ECC and Physically Unclonable Function (PUF)-based methods. Additionally, formal security analysis confirms that our scheme effectively mitigates impersonation, replay, tracking, and quantum attacks, ensuring a scalable and future-proof authentication mechanism for next-generation VANETs.

Open access
Vehicular Ad Hoc Networks (VANETs)
Advanced Authentication Protocols Security
Network Security and Intrusion Detection
Original source
Jul 1, 2025·Scientific Reports
36 cites
Enhancing anomaly detection and prevention in Internet of Things (IoT) using deep neural networks and blockchain based cyber security

A. R. Sathyabama, Jeevaa Katiravan

The rapid adoption of Internet of Things (IoT) devices has significantly increased cybersecurity risks, making them vulnerable to anomalies, attacks, and unauthorized access. Traditional security mechanisms struggle to handle the massive data flow, real-time processing requirements, and evolving cyber threats in IoT networks. This paper presents an integrated approach using Deep Neural Networks and Blockchain technology (DNNs-BCT) to enhance anomaly detection and prevention in IoT environments. Our proposed framework employs DNNs for intelligent anomaly detection, leveraging multi-layer feature extraction and adaptive learning mechanisms. The DNN model is trained on IoT traffic datasets to classify network behavior as normal or anomalous, effectively detecting threats such as Distributed Denial of Service (DDoS) attacks, malware injections, and insider threats. Unlike traditional rule-based intrusion detection systems (IDS), the DNN continuously learns and adapts to new attack patterns, improving detection accuracy and false-positive reduction. This study integrates Blockchain technology into the IoT ecosystem to ensure data integrity, transparency, and decentralized security. Each IoT device logs its activity onto a private blockchain network, preventing data tampering, unauthorized access, and single points of failure. The blockchain employs smart contracts for automated threat response, instantly mitigating malicious activity without human intervention. This distributed ledger approach enhances trust, authentication, and secure communication across IoT devices. The synergy between DNN-based anomaly detection and Blockchain-based security provides a robust, scalable, and adaptive solution for real-time cybersecurity threats in IoT networks. With a low false-positive rate of 15.42% and a strong detection accuracy of 99.18%, the proposed model successfully identifies malicious activity, including malware injections and Distributed Denial of Service (DDoS) assaults. Blockchain technology replaces single points of failure and forbids illegal changes by providing data integrity, openness, and decentralizing powers. Furthermore, smart contracts allow autonomous, real-time attack responses, enhancing reaction time efficiency (95.25%) and general system scalability (94.96%).

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Anomaly Detection Techniques and Applications
Original source
Jun 27, 2025·International Journal of Science and Research Archive
1 cites
A swarm Intelligence-Driven Collaborative Intrusion Detection System (CIDS) for 6G-IoT networks

Mohamed Mahmoud Alkabir, Mohamed Taher R Nashnosh, Tarek Ayad H Shaladi

6G wireless networks introduce revolutionary features beyond 5G by providing human-focused services and extended IoT battery life and holographic telepresence and tactile Internet capabilities. 6G enables terahertz (THz) spectrum together with pervasive AI and intelligent spectrum management to deliver unmatched reliability and complete 3D coverage. The AI-native architecture and distributed intelligence of 6G networks create new security risks because they make systems more vulnerable to adversarial attacks and scalability limitations. A Swarm Intelligence-Driven Collaborative Intrusion Detection System (CIDS) for 6G-IoT networks addresses security challenges through the combination of ant colony optimization (ACO) with Edge Blockchain for decentralized adaptive threat detection. The framework includes three main components: (1) autonomous ant agents spread anomaly signatures through pheromone trails and (2) lightweight Hyperledger Fabric provides tamper-proof logging of threat intelligence and (3) smart contracts execute mitigation actions based on dynamic trust threshold values. The 50-node UAV-ground sensor testbed results show that the system detects DDoS attacks with 98.7% accuracy while achieving 47% lower latency than federated learning baselines and 73% storage efficiency through IPFS-backed hashing. The system decreases false positives by 62% while maintaining blockchain transaction rates of 420 per second at large scales. The proposed framework swarm intelligence with distributed ledger technology solves essential 6G security challenges regarding autonomy and scalability and resilience which enables trustworthy AI-driven networks.

Open access
Network Security and Intrusion Detection
Original source
Jun 25, 2025·Computers
12 cites
Machine Learning for Anomaly Detection in Blockchain: A Critical Analysis, Empirical Validation, and Future Outlook

Fouzia Jumani, Muhammad Ahsan Raza

Blockchain technology has transformed how data are stored and transactions are processed in a distributed environment. Blockchain assures data integrity by validating transactions through the consensus of a distributed ledger involving several miners as validators. Although blockchain provides multiple advantages, it has also been subject to some malicious attacks, such as a 51% attack, which is considered a potential risk to data integrity. These attacks can be detected by analyzing the anomalous node behavior of miner nodes in the network, and data analysis plays a vital role in detecting and overcoming these attacks to make a secure blockchain. Integrating machine learning algorithms with blockchain has become a significant approach to detecting anomalies such as a 51% attack and double spending. This study comprehensively analyzes various machine learning (ML) methods to detect anomalies in blockchain networks. It presents a Systematic Literature Review (SLR) and a classification to explore the integration of blockchain and ML for anomaly detection in blockchain networks. We implemented Random Forest, AdaBoost, XGBoost, K-means, and Isolation Forest ML models to evaluate their performance in detecting Blockchain anomalies, such as a 51% attack. Additionally, we identified future research directions, including challenges related to scalability, network latency, imbalanced datasets, the dynamic nature of anomalies, and the lack of standardization in blockchain protocols. This study acts as a benchmark for additional research on how ML algorithms identify anomalies in blockchain technology and aids ongoing studies in this rapidly evolving field.

Open access
Blockchain Technology Applications and Security
Anomaly Detection Techniques and Applications
Network Security and Intrusion Detection
Original source
Jun 21, 2025·Sensors
1 cites
Among the DLTs: Holochain for the Security of IoT Distributed Networks—A Review and Conceptual Framework

Shereen Ismail, Raouf Mehannaoui, Eden Teshome Hunde, Hassan Reza

IoT devices are typically resource-constrained, with limited computational power, storage, and energy. Holochain, an emerging distributed ledger technology (DLT), offers the benefits of blockchain while overcoming its limitations, such as the reliance on consensus algorithms and a globally synchronized ledger. As a result, Holochain has garnered attention in the research community as a promising solution for distributed IoT applications. This paper reviews various DLTs in IoT distributed networks, focusing on the motivation for utilizing Holochain in these environments. We explore its key applications, challenges, and research insights. We propose the HoloSec framework, a conceptual security framework for IoT distributed networks that leverages Holochain’s agent-centric architecture, advanced cryptography, and machine learning (ML). The paper also illustrates the setup and implementation of a Holochain-based IoT network for a healthcare scenario and compares the performance of Holochain with traditional blockchain solutions. Initial experimental results show that Holochain achieves a latency of around 50 ms for data publishing and 30 ms for retrieval, with a throughput of approximately 20 transactions per second (TPS) on a single node, significantly outperforming blockchain, which shows higher latency (200 ms publish, 100 ms retrieve) and lower throughput (10 TPS). Finally, we examine key challenges associated with Holochain and outline future research directions aimed at enhancing its interoperability, scalability, security, and regulatory compliance in IoT environments.

Open access
Blockchain Technology Applications and Security
IoT and Edge/Fog Computing
Network Security and Intrusion Detection
Original source
Jun 19, 2025·EURASIP Journal on Wireless Communications and Networking
6 cites
Enhancing the reliability and accuracy of wireless sensor networks using a deep learning and blockchain approach with DV-HOP algorithm for DDoS mitigation and node localization

Bhupinder Kaur, Deepak Prashar, Leo Mršić, Ahmad Almogren · 7 authors

Wireless sensor networks (WSNs) are subject to distributed denial-of-service (DDoS) attacks that impact data dependability, mobility of nodes, and energy drain. The remedy to these challenges in this work is a solution based on deep learning integrated with a blockchain-aided distance-vector hop (DV-HOP) localization algorithm for reliable and secure node localization. Incorporating a blockchain ledger makes the network more trustworthy as it verifies usual and unusual system activities, whereas the DV-HOP algorithm mitigates localization inaccuracies and enhances node placement. The system is evaluated according to different performance measures like localization error, accuracy ratio, average localization error (ALE), probability of location, false positive rate (FPR), false negative rate (FNR), energy utilization, network stability, node failure rate, node recovery rate, and malicious node detection rate. Experimental results reveal improved security, accuracy, and efficiency with 17% FPR and 15% FNR, outperforming the conventional methods. This model enhances WSN performance in different environments via precise data transmission from the source to the destination. The results confirm that integrating deep learning with blockchain and DV-HOP increases network robustness, thus making WSNs more secure against security attacks while reducing energy consumption and localization accuracy. The proposed model presents a strong solution for real-world applications in wireless network environments.

Open access
Security in Wireless Sensor Networks
Network Security and Intrusion Detection
IoT and Edge/Fog Computing
Original source
Jun 13, 2025·Digital Technologies Research and Applications
4 cites
A Blockchain‑Enhanced Deep Learning Approach for Intrusion Detection in Trusted Execution Environments

Ahmed Abubakar Aliyu, Mohammed Ibrahim, Sa’adatu Abdulkadir

Traditional Intrusion Detection Systems (IDSs) face significant challenges in keeping pace with the rapidly evolving landscape of cyber threats, primarily due to limitations in continuous learning and the accuracy of data classification and analysis. This often results in delayed detection and leaves networks susceptible to severe attacks. This paper introduces an innovative IDS empowered by blockchain technology to mitigate these shortcomings, leveraging continuous learning and self‑adaptive neural networks. The proposed system adopts a proactive approach by continuously assimilating intrusion logs, utilizing a Long Short‑Term Memory (LSTM) core to discern patterns and enhance its real‑time threat detection capabilities, removing a major bottleneck in traditional IDS models by eliminating the need for manual tagging. To further strengthen the security measures, self‑updating neural networks are embedded in each block of the blockchain, forming a decentralized “brain” that evolves defences against even the most sophisticated adversaries. These networks are securely housed in Trusted Execution Environments (TEEs) to maintain operational integrity, enabling tamper‑proof operation and effective threat detection. Real‑world evaluations conducted on the Binance Smart Chain and Ethereum Classic datasets demonstrate the system’s superior performance. With an impressive accuracy rate of 98.50% and a minimal false positive rate of 1.50%, the model demonstrates a remarkable ability to distinguish legitimate network activity from malicious intrusions.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Jun 7, 2025·ACM Transactions on Internet Technology
1 cites
The Blockchain Warfare: Investigating the Ecosystem of Sniper Bots on Ethereum and BNB Smart Chain

Federico Cernera, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini · 5 authors

In the world of cryptocurrencies, the public listing of a new token often generates significant hype. In many cases, the price of the token skyrockets in a few seconds, and timing is crucial to determine the success or failure of an investment opportunity. In this work, we present an in-depth analysis of sniper bots, automated tools designed to buy tokens as soon as they are listed on the market. We leverage GitHub open-source repositories of sniper bots to analyze their features and how they are implemented. Then, we build a dataset of Ethereum and BNB Smart Chain (BSC) liquidity pools to identify operations performed using sniper bots. Our findings reveal 352,413 sniping operations on Ethereum and 1,716,917 on BSC for a total turnaround of $155,630,184 and $137,548,859, respectively. We find that Ethereum operations have a higher success rate but require a larger investment. Finally, we analyze possible countermeasures and mechanisms used in token smart contracts that can reduce the negative impact of sniper bots.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Original source
Jun 4, 2025·Romanian Cyber Security Journal
1 cites
Cybersecurity Challenges in Managing Domain Names. From DNS to ENS in the Web3 Era

Adrian Victor VEVERA, Andreea Cătălina CRĂCIUN, Mihail Dumitrache, Ionut SANDU · 6 authors

The Domain Name System (DNS) remains a foundational component of the Internet infrastructure, which is frequently exploited by cybercriminals through increasingly diverse and sophisticated attack vectors.This paper explores the evolving cybersecurity challenges faced by domain name systems (DNSs) and their decentralized counterparts in the Web3 ecosystem, particularly the Ethereum Name Service (ENS), as such, it surveys both the established and novel attack patterns.Furthermore, it explores the implications of decentralized naming systems like the ENS, which introduced novel cybersecurity challenges within the Web3 environments and it highlights the future risks and possible research directions related to the transition to decentralized web services.This study provides a comparative analysis of the cyberattacks targeting the DNS and the ENS, highlighting the evolving threat landscape for each of the two ecosystems.By examining the architectural differences between the DNS and ENS, their common attack vectors, and their security mechanisms, it underscores both the distinct vulnerabilities inherent to each ecosystem and the overlapping risks they share.

Open access
Network Security and Intrusion Detection
IPv6, Mobility, Handover, Networks, Security
Original source