Lingling Xia, Tao Zhu, Zhengjun Jing, Qun Wang · 7 authors
Digital currencies, led by Bitcoin and USDT, are characterized by decentralization and anonymity, which obscure the identities of traders and create a conducive environment for illicit activities such as drug trafficking, money laundering, cyber fraud, and terrorism financing. Focusing on the USDT-TRC20 token on the Tron blockchain, we propose a two-layer transaction network-based approach for virtual currency address identity recognition for digging out hidden relationships and encrypted assets. Specifically, a two-layer transaction network is constructed: Layer A describes the flow of USDT-TRC20 between on-chain addresses over time, while Layer B represents the flow of TRX between on-chain addresses over time. Subsequently, an identity metric is proposed to determine whether a pair of addresses belongs to the same user or group. Furthermore, transaction records are systematically acquired through blockchain explorers, and the efficacy of the proposed recognition method is empirically validated using dataset from the Key Laboratory of Digital Forensics. Finally, the transaction topology is visualized using Neo4j, providing a comprehensive and intuitive representation of the traced transaction pathways.
The evolution of 5G and emerging 6G networks has introduced unprecedented opportunities for connectivity, but also expanded the attack surface for Distributed Denial of Service (DDoS) amplification attacks. Service-Based Architecture (SBA), network slicing, and massive IoT (mMTC) environments create new vectors for reflection and amplification, making conventional defenses inadequate. This paper proposes a novel layered defense framework that integrates edge filtering, AI-driven anomaly detection, slice isolation, cloud scrubbing, and quantum-safe cryptography to mitigate DDoS amplification attacks in 5G/6G environments. The framework is theoretically modeled through equations for amplification, mitigation efficiency, resilience, and defense cost, and evaluated experimentally using simulated signaling floods, IoT-driven amplification, slice-targeted floods, and hybrid attacks. Performance was measured using detection rate, false alarm rate, service availability, resilience score, and resource overhead. Two algorithms—pseudonymous authentication with zero-knowledge proof (ZKP) and layered mitigation orchestration—were implemented to operationalize the defense strategy. The results demonstrate that the proposed framework achieves a detection accuracy of 95–97%, reduces false positives to 2%, and maintains a service availability of over 85% under prolonged amplification attacks. It scales efficiently in scenarios with up to 10,000 simulated IoT devices, retaining 70–80% throughput, and maintains URLLC latency below 10 ms, outperforming baseline defenses (firewalls, scrubbing, and AI-only) and state-of-the-art defenses from the literature. These findings validate the framework as a scalable, efficient, and future-ready solution for mitigating amplification attacks in 5G/6G networks, with strong alignment with 3GPP, GSMA, and NIST post-quantum standards.
Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Physical Unclonable Functions (PUFs) and Hardware Security
Bitcoin transaction anomaly detection is essential for maintaining financial market stability. A significant challenge is capturing the dynamically evolving transaction patterns within transaction networks. Dynamic graph models are effective for characterizing the temporal evolution of transaction systems. However, current methods struggle to mine long-range temporal dependencies and address the class imbalance caused by the scarcity of abnormal samples. To address these issues, we propose a novel approach, the Bidirectional EvolveGCN with Class-Balanced Learning Network (Balanced-BiEGCN), for Bitcoin transaction anomaly detection. This model integrates two key components: (1) a bidirectional temporal feature fusion mechanism (Bi-EvolveGCN) that enhances the capture of long-range temporal dependencies and (2) a Sample Class Transformation (CSCT) classifier that generates difficult-to-distinguish abnormal samples to balance the positive and negative class distribution. The generation of these samples is guided by two loss functions: the adjacency distance adaptive loss function and the symmetric space adjustment loss function, which optimize the spatial distribution and confusion of abnormal samples. Experimental results on the Elliptic dataset demonstrate that Balanced-BiEGCN outperforms existing baseline methods in anomaly detection.
With the rise of cryptocurrencies, illicit activities such as money laundering, fraud, and Ponzi schemes have gained attention. Traditional methods using graph neural networks (GNNs) to detect illicit transactions treat the entire transaction network as input, which works well on small networks but struggles with large-scale blockchain data. To address this limitation, the authors propose a neighborhood subgraph-based method that combines GCN and LSTM. The GCN captures information from neighboring nodes for each transaction, enhancing the understanding of the network structure, while the LSTM tracks the sequence and variations of fund flows. Experimental results show that by using 3-hop neighborhood subgraphs, the method outperforms other baseline models while requiring data from only an average of 80 nodes, thereby significantly improving efficiency compared to methods that process the entire transaction network.
Integration of Federated Learning (FL) with Blockchain technology to decentralized privacy-preserving, and scalable framework for strengthening cybersecurity. As cyber threats like ransomware, malware, and network intrusions grow in complexity, there is an increasing need for collaborative threat detection and mitigation. However, traditional collaborative approaches often involve sharing sensitive information across organizations, raising significant privacy concerns and regulatory challenges under frameworks like GDPR and HIPAA. FL works to solve these problems through enabling multiple entities to work together on training machine learning models without sharing their original information. Despite its advantages, FL faces challenges such as the risk of model tampering, trust deficits between participants, and dependence on a centralized server for model aggregation. To overcome these limitations the Blockchain technologies will be in used so blockchain technology provides a distributed, transparent, and non-mutable ledger that safely manages FL operations. It helps preserve the accuracy and trustworthiness of model updates via smart contracts along with consensus mechanisms, bypassing the requirement fora central aggregator. In addition, blockchain enables incentivization by introducing token-based rewards, encouraging active participation in collaborative threat detection networks. Privacy- preserving techniques to boost information security, techniques like differential privacy and homomorphic encryption are also put into practice. Such a integration of FL and blockchain is particularly impactful in securing distributed systems such as IoT devices, critical infrastructure, and enterprise networks, where privacy, trust, and scalability are crucial. This project aims to demonstrate the practical implementation of this framework, paving the way for adaptive and globally scalable cyber security systems to combat evolving threats.
Yenlik Begimbayeva, Temirlan Zhaxalykov, Amir Akhtanov, Ruslan Pashkevich · 6 authors
This research focuses on enhancing the security of decentralized quantum key distribution (QKD) networks, where the absence of a central authority creates significant challenges such as malicious node infiltration, undetected key leakage, and unauthorized re-entry of revoked participants. Traditional authentication and trust models are insufficient for fully distributed QKD topologies, which remain highly vulnerable to insider threats and persistent compromise. To address these risks, let’s propose a layered security framework composed of three integrated components: Challenge-Response Authentication (CRA), Dynamic Trust Scoring (DTS), and Blockchain-Based Access Control (BBAC). CRA verifies node legitimacy through randomized quantum-state interactions, significantly reducing impersonation and quantum replay attacks. DTS implements real-time trust evaluation using anomaly detection to dynamically downgrade compromised nodes based on their behavioral deviations. BBAC maintains an immutable and tamper-proof trust ledger to block revoked nodes from re-entering under falsified identities and resists Sybil attacks using post-quantum cryptographic primitives. Simulation results confirm that the system improves detection rates of covert threats, ensures authentication latency under 10 ms, and reduces re-entry success to zero. The proposed architecture ensures long-term scalability and resilience, making it applicable to critical domains such as finance, national infrastructure, and military communication. This work contributes a novel, verifiable, and scalable solution to one of the most pressing open problems in distributed quantum networks
The Ethereum platform is booming with growing richness and variety in decentralized finance (DeFi) products. However, this progress comes with sophisticated threats, such as sandwich attacks, where attackers exploit the openness and certainty of blockchain technology to manipulate market prices and secure illegal financial rewards through a strategically planned series of transactions. The existing sandwich attack detection methods are ineffective at detecting multi-token transactions and fail to identify multi-token sandwich attacks. To tackle this challenge, this study improves the original detector’s algorithm to identify both traditional single-token and multi-token sandwich attacks. The enhanced system is not only responsive and accurate but also capable of detecting and alerting potential multi-token sandwich attacks. It has been successfully integrated with the go-Ethereum client (Geth). The system is performance-optimized with an average processing time of 0.81 seconds per block and an accuracy rate of 96.17%. The response time for detecting new blocks in real-time is usually no more than 4 seconds, with most between 2 and 3 seconds, which meets practical application requirements. By carefully analyzing the transaction data flow, this system is not only able to identify the traditional front-running attack and sandwich attack, but also extends to multi-currency complex attack strategies. The core innovation lies in the system’s ability to accurately detect and provide early warnings of multi-token sandwich attacks through real-time analysis of in-block transactions, all while maintaining the overall operational efficiency of the node.
In an era marked by increasingly sophisticated cyber threats and growing vulnerabilities in national critical infrastructure, this study explores the transformative role of confidential computing in defending against emerging cryptographic attacks and enabling secure threat intelligence sharing. Traditional cybersecurity measures, while effective for protecting data at rest and in transit, fall short in securing data during active processingan area exploited by advanced persistent threats, quantum computing, and side-channel attacks. This research investigates how hardware-based trusted execution environments (TEEs), homomorphic encryption, and zero-knowledge proofs embedded in confidential-computing platforms can preserve the confidentiality of sensitive operations even within potentially compromised environments. Through detailed case studies of major U.S. institutionsincluding PGandE, Exelon, JPMorgan Chase, Wells Fargo, and Kaiser Permanentethe paper demonstrates significant improvements in detection speed, false positive reduction, and operational efficiency. Furthermore, it proposes a scalable, privacy-preserving framework for collaborative cyber defense across critical sectors such as energy, finance, and healthcare. The findings underscore that integrating confidential computing with decentralized intelligence sharing networks not only enhances cybersecurity resilience but also yields substantial economic and regulatory benefits. This work advocates for a national, and eventually global, shift toward confidential-computing-enabled infrastructures to achieve robust, cooperative, and future-proof cyber defense ecosystems.
Büşra Büyüktanır, Şahsene Altınkaya, Gozde Karatas Baydoğmus, Kazım Yıldız
Abstract Federated Learning (FL) has emerged as a promising distributed machine learning approach that addresses confidentiality and integrity concerns in various sectors, including Internet of Things (IoT), healthcare, finance, and cybersecurity. In order to improve privacy protection and detection accuracy in decentralized systems, this study investigates the incorporation of FL into Intrusion Detection Systems (IDS). FL is especially useful in situations where data security and privacy are crucial because it allows for the cooperative training of models without centralizing sensitive data. We examine many FL-based IDS solutions across several domains, emphasizing how well they mitigate data breaches, maintain confidentiality, and enhance intrusion detection capabilities. The use of Generative Adversarial Networks (GANs), artificial immune systems, and hybrid deep learning techniques to maximize IDS performance are among the current developments in FL methodology that are covered in the paper. We also look at issues like the requirement for effective aggregation procedures and non-independent and identically distributed (non-IID) data. Finally, we outline future directions and open research topics to improve the scalability, resilience, and effectiveness of FL-based IDS solutions in practical applications.
In the modern era, the use of blockchain technology has been growing rapidly, where Ethereum smart contracts play an important role in securing decentralized application systems. However, these smart contracts are also susceptible to a large number of vulnerabilities, which pose significant threats to intelligent systems and IoT applications, leading to data breaches and financial losses. Traditional detection techniques, such as manual analysis and static automated tools, suffer from high false positives and undetected security vulnerabilities. To address these problems, this paper proposes an Artificial Intelligence (AI)-based security framework that integrates Generative Adversarial Network (GAN)-based feature selection and deep learning techniques to classify and detect malware attacks on smart contract execution in the blockchain decentralized network. After an exhaustive pre-processing phase yielding a dataset of 40,000 malware and benign samples, the proposed model is evaluated and compared with related studies on the basis of a number of performance metrics including training accuracy, training loss, and classification metrics (accuracy, precision, recall, and F1-score). Our combined approach achieved a remarkable accuracy of 97.6%, demonstrating its effectiveness in detecting malware and protecting blockchain systems.
This review article examines the state of blockchain-enabled identity management in Internet of Things (IoT) networks, focusing on decentralized and secure mechanisms for device identification, authentication, and access control. Traditional centralized identity systems face limitations such as single points of failure, scalability bottlenecks, and vulnerability to breaches. We systematically survey recent literature on blockchain-based frameworks applied to IoT, categorizing approaches by blockchain platform, identity credential models, consensus mechanisms, and smart contract implementations. The analysis highlights key performance metrics such as system latency, throughput, resource overhead, and energy consumption, and compares existing prototypes deployed across diverse IoT scenarios. We assess the security and privacy implications, including resistance to spoofing, Sybil attacks, unauthorized access, data tampering, and insider threats. Additionally, the review identifies open research challenges such as managing identity lifecycle in constrained devices, achieving interoperability across heterogeneous networks, balancing decentralization with scalability, and integrating with emerging technologies like edge computing and zero-knowledge proofs. Finally, we offer recommendations for future research directions and practical deployment strategies to advance blockchain-based identity solutions in IoT ecosystems. Our comprehensive synthesis aims to guide researchers and practitioners in developing robust, scalable, and trustworthy identity frameworks using blockchain for the evolving IoT landscape.
The rapid integration of blockchain, cryptocurrency, and Web3 technologies into digital banks and fintech operations has created an integrated environment blending traditional financial systems with decentralised elements. This paper introduces the CryptoNeo Threat Modelling Framework (CNTMF), a proposed framework designed to address the risks in these ecosystems, such as oracle manipulation and cross-chain exploits. CNTMF represents a proposed extension of established methodologies like STRIDE, OWASP Top 10, NIST frameworks, LINDDUN, and PASTA, while incorporating tailored components including Hybrid Layer Analysis, the CRYPTOQ mnemonic for cryptocurrency-specific risks, and an AI-Augmented Feedback Loop. Drawing on real-world data from 2025 incidents, CNTMF supports data-driven mitigation to reduce losses, which totalled approximately $2.47 billion in the first half of 2025 across 344 security events (CertiK via GlobeNewswire, 2025; Infosecurity Magazine, 2025). Its phases guide asset mapping, risk profiling, prioritisation, mitigation, and iterative feedback. This supports security against evolving risks like state-sponsored attacks.
The escalating complexity and frequency of malware attacks pose a significant challenge to conventional cybersecurity frameworks, particularly in scenarios demanding high data privacy and cross-organizational threat intelligence sharing. Traditional centralized machine learning models for malware detection often rely on aggregating data in a central server, thereby increasing the risk of data breaches and limiting the deployment of models in privacy-sensitive environments such as healthcare, finance, and critical infrastructure. To address these limitations, this study explores an integrated approach that combines Federated Learning (FL) with Explainable Artificial Intelligence (XAI) for enhancing malware detection while preserving user privacy and system confidentiality. Federated learning enables the collaborative training of robust malware classifiers across multiple decentralized nodes without sharing raw data, thus maintaining local data sovereignty and complying with data protection regulations. The proposed framework incorporates deep learning architectures such as convolutional neural networks (CNNs) trained in a federated environment using feature vectors extracted from malicious binaries and behavior logs. To ensure transparency and trust in model predictions, explainable AI techniques specifically SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) are integrated, providing actionable insights into the model’s decision-making process. This study also presents a comprehensive evaluation using a benchmark malware dataset distributed across simulated client environments, measuring detection accuracy, communication overhead, privacy leakage, and interpretability performance. Results demonstrate that the FL-XAI approach achieves detection rates comparable to centralized models while ensuring data confidentiality and interpretability. The research contributes to the evolving field of privacy-preserving threat intelligence by offering a scalable and explainable framework suitable for real-time cybersecurity applications.
Yu Zhang, Yafei Li, Jufang Zhang, Claudio J. Tessone
When analyzing the balance distribution of Bitcoin users, we found that it follows a log-normal pattern based on a rigorous Uniformly-Most-Powerful-Unbiased test. Drawing parallels from the successful application of Gibrat’s law in explaining city size and word frequency distributions, we tested whether a similar principle could account for the log-normal distribution in Bitcoin balances. However, our calculations revealed that the exponent parameters in both the drift and variance terms deviate slightly from 1 when applying Geometric-Brownian-Motion on the Bitcoin balance, which means that Bitcoin users’ balance distribution cannot be explained only by the proportional growth rule alone. During this exploration, Bitcoin users’ behaviors are also investigated. We discovered an intriguing phenomenon: Bitcoin users tend to fall into two distinct categories based on their transaction behavior, which we refer to as “poor” and “wealthy” users. Poor users who initially purchase only a small amount of Bitcoin tend to buy more Bitcoins first and then sell out all their holdings over time. The certainty of selling all their coins is higher and higher with time. In contrast, wealthy users who acquire a large amount of Bitcoin from the start tend to sell off their holdings over time. The speed at which they sell their Bitcoins is lower and lower over time. The wealthier the user, the larger the proportion of their balance and the higher the certainty they tend to sell their holdings. This research provided a new perspective to explore Bitcoin users’ behaviors which may apply to other finance markets.
Cryptocurrency-related crimes are on the rise and have a wide-ranging impact across various areas. To effectively combat and prevent such crimes, cryptocurrency forensics, which relies on blockchain analysis, is essential. Despite advancements in Bitcoin de-anonymization techniques, several challenges persist. The absence of authentic data labels introduces uncertainty in de-anonymization results, especially in the context of address clustering. This issue is further compounded by the development of privacy-enhancing technologies that obscure address linkages, thus undermining the reliability of outcomes as forensic evidence. To address these limitations, this study focuses on Bitcoin blockchain analysis and the improvement of address clustering. Specifically, the work presents an enhanced simulation model designed to accurately simulate real Bitcoin transactions, offering a stable platform for evaluating address clustering algorithms that utilize transaction details, thereby facilitating the assessment of the admissibility of clustering results. Meanwhile, we introduce a new heuristic algorithm aimed at identifying one-time change addresses, with experimental results demonstrating that it achieves more precise clustering outcomes than existing heuristic methods. Furthermore, our blockchain analysis reveals overarching patterns and recent changes in the Bitcoin blockchain, particularly following the introduction of the BRC-20 token.
Ensuring secure and efficient authentication in Vehicular Ad Hoc Networks (VANETs) is vital for real-time communication and network resilience. However, traditional authentication mechanisms, such as Elliptic Curve Cryptography (ECC) and Public Key Infrastructure (PKI), face significant challenges, including high computational overhead, complex certificate revocation, and vulnerability to quantum attacks. To overcome these limitations, we propose a lattice-based authentication protocol that integrates post-quantum cryptography (PQC), zero-knowledge proofs (ZKPs), and fog computing for secure Vehicle-to-Roadside (V2R) communication. Our protocol offers quantum resistance, decentralized authentication, and dynamic pseudonym updates, enhancing both security and privacy in VANETs. Performance evaluations demonstrate that our approach achieves lower message delay (0.8), reduced packet loss ratio (0.6), minimal communication overhead (0.7), and the fastest authentication delay (0.5) compared to ECC and Physically Unclonable Function (PUF)-based methods. Additionally, formal security analysis confirms that our scheme effectively mitigates impersonation, replay, tracking, and quantum attacks, ensuring a scalable and future-proof authentication mechanism for next-generation VANETs.
The rapid adoption of Internet of Things (IoT) devices has significantly increased cybersecurity risks, making them vulnerable to anomalies, attacks, and unauthorized access. Traditional security mechanisms struggle to handle the massive data flow, real-time processing requirements, and evolving cyber threats in IoT networks. This paper presents an integrated approach using Deep Neural Networks and Blockchain technology (DNNs-BCT) to enhance anomaly detection and prevention in IoT environments. Our proposed framework employs DNNs for intelligent anomaly detection, leveraging multi-layer feature extraction and adaptive learning mechanisms. The DNN model is trained on IoT traffic datasets to classify network behavior as normal or anomalous, effectively detecting threats such as Distributed Denial of Service (DDoS) attacks, malware injections, and insider threats. Unlike traditional rule-based intrusion detection systems (IDS), the DNN continuously learns and adapts to new attack patterns, improving detection accuracy and false-positive reduction. This study integrates Blockchain technology into the IoT ecosystem to ensure data integrity, transparency, and decentralized security. Each IoT device logs its activity onto a private blockchain network, preventing data tampering, unauthorized access, and single points of failure. The blockchain employs smart contracts for automated threat response, instantly mitigating malicious activity without human intervention. This distributed ledger approach enhances trust, authentication, and secure communication across IoT devices. The synergy between DNN-based anomaly detection and Blockchain-based security provides a robust, scalable, and adaptive solution for real-time cybersecurity threats in IoT networks. With a low false-positive rate of 15.42% and a strong detection accuracy of 99.18%, the proposed model successfully identifies malicious activity, including malware injections and Distributed Denial of Service (DDoS) assaults. Blockchain technology replaces single points of failure and forbids illegal changes by providing data integrity, openness, and decentralizing powers. Furthermore, smart contracts allow autonomous, real-time attack responses, enhancing reaction time efficiency (95.25%) and general system scalability (94.96%).
Mohamed Mahmoud Alkabir, Mohamed Taher R Nashnosh, Tarek Ayad H Shaladi
6G wireless networks introduce revolutionary features beyond 5G by providing human-focused services and extended IoT battery life and holographic telepresence and tactile Internet capabilities. 6G enables terahertz (THz) spectrum together with pervasive AI and intelligent spectrum management to deliver unmatched reliability and complete 3D coverage. The AI-native architecture and distributed intelligence of 6G networks create new security risks because they make systems more vulnerable to adversarial attacks and scalability limitations. A Swarm Intelligence-Driven Collaborative Intrusion Detection System (CIDS) for 6G-IoT networks addresses security challenges through the combination of ant colony optimization (ACO) with Edge Blockchain for decentralized adaptive threat detection. The framework includes three main components: (1) autonomous ant agents spread anomaly signatures through pheromone trails and (2) lightweight Hyperledger Fabric provides tamper-proof logging of threat intelligence and (3) smart contracts execute mitigation actions based on dynamic trust threshold values. The 50-node UAV-ground sensor testbed results show that the system detects DDoS attacks with 98.7% accuracy while achieving 47% lower latency than federated learning baselines and 73% storage efficiency through IPFS-backed hashing. The system decreases false positives by 62% while maintaining blockchain transaction rates of 420 per second at large scales. The proposed framework swarm intelligence with distributed ledger technology solves essential 6G security challenges regarding autonomy and scalability and resilience which enables trustworthy AI-driven networks.
Blockchain technology has transformed how data are stored and transactions are processed in a distributed environment. Blockchain assures data integrity by validating transactions through the consensus of a distributed ledger involving several miners as validators. Although blockchain provides multiple advantages, it has also been subject to some malicious attacks, such as a 51% attack, which is considered a potential risk to data integrity. These attacks can be detected by analyzing the anomalous node behavior of miner nodes in the network, and data analysis plays a vital role in detecting and overcoming these attacks to make a secure blockchain. Integrating machine learning algorithms with blockchain has become a significant approach to detecting anomalies such as a 51% attack and double spending. This study comprehensively analyzes various machine learning (ML) methods to detect anomalies in blockchain networks. It presents a Systematic Literature Review (SLR) and a classification to explore the integration of blockchain and ML for anomaly detection in blockchain networks. We implemented Random Forest, AdaBoost, XGBoost, K-means, and Isolation Forest ML models to evaluate their performance in detecting Blockchain anomalies, such as a 51% attack. Additionally, we identified future research directions, including challenges related to scalability, network latency, imbalanced datasets, the dynamic nature of anomalies, and the lack of standardization in blockchain protocols. This study acts as a benchmark for additional research on how ML algorithms identify anomalies in blockchain technology and aids ongoing studies in this rapidly evolving field.
Shereen Ismail, Raouf Mehannaoui, Eden Teshome Hunde, Hassan Reza
IoT devices are typically resource-constrained, with limited computational power, storage, and energy. Holochain, an emerging distributed ledger technology (DLT), offers the benefits of blockchain while overcoming its limitations, such as the reliance on consensus algorithms and a globally synchronized ledger. As a result, Holochain has garnered attention in the research community as a promising solution for distributed IoT applications. This paper reviews various DLTs in IoT distributed networks, focusing on the motivation for utilizing Holochain in these environments. We explore its key applications, challenges, and research insights. We propose the HoloSec framework, a conceptual security framework for IoT distributed networks that leverages Holochain’s agent-centric architecture, advanced cryptography, and machine learning (ML). The paper also illustrates the setup and implementation of a Holochain-based IoT network for a healthcare scenario and compares the performance of Holochain with traditional blockchain solutions. Initial experimental results show that Holochain achieves a latency of around 50 ms for data publishing and 30 ms for retrieval, with a throughput of approximately 20 transactions per second (TPS) on a single node, significantly outperforming blockchain, which shows higher latency (200 ms publish, 100 ms retrieve) and lower throughput (10 TPS). Finally, we examine key challenges associated with Holochain and outline future research directions aimed at enhancing its interoperability, scalability, security, and regulatory compliance in IoT environments.
Bhupinder Kaur, Deepak Prashar, Leo Mršić, Ahmad Almogren · 7 authors
Wireless sensor networks (WSNs) are subject to distributed denial-of-service (DDoS) attacks that impact data dependability, mobility of nodes, and energy drain. The remedy to these challenges in this work is a solution based on deep learning integrated with a blockchain-aided distance-vector hop (DV-HOP) localization algorithm for reliable and secure node localization. Incorporating a blockchain ledger makes the network more trustworthy as it verifies usual and unusual system activities, whereas the DV-HOP algorithm mitigates localization inaccuracies and enhances node placement. The system is evaluated according to different performance measures like localization error, accuracy ratio, average localization error (ALE), probability of location, false positive rate (FPR), false negative rate (FNR), energy utilization, network stability, node failure rate, node recovery rate, and malicious node detection rate. Experimental results reveal improved security, accuracy, and efficiency with 17% FPR and 15% FNR, outperforming the conventional methods. This model enhances WSN performance in different environments via precise data transmission from the source to the destination. The results confirm that integrating deep learning with blockchain and DV-HOP increases network robustness, thus making WSNs more secure against security attacks while reducing energy consumption and localization accuracy. The proposed model presents a strong solution for real-world applications in wireless network environments.
Ahmed Abubakar Aliyu, Mohammed Ibrahim, Sa’adatu Abdulkadir
Traditional Intrusion Detection Systems (IDSs) face significant challenges in keeping pace with the rapidly evolving landscape of cyber threats, primarily due to limitations in continuous learning and the accuracy of data classification and analysis. This often results in delayed detection and leaves networks susceptible to severe attacks. This paper introduces an innovative IDS empowered by blockchain technology to mitigate these shortcomings, leveraging continuous learning and self‑adaptive neural networks. The proposed system adopts a proactive approach by continuously assimilating intrusion logs, utilizing a Long Short‑Term Memory (LSTM) core to discern patterns and enhance its real‑time threat detection capabilities, removing a major bottleneck in traditional IDS models by eliminating the need for manual tagging. To further strengthen the security measures, self‑updating neural networks are embedded in each block of the blockchain, forming a decentralized “brain” that evolves defences against even the most sophisticated adversaries. These networks are securely housed in Trusted Execution Environments (TEEs) to maintain operational integrity, enabling tamper‑proof operation and effective threat detection. Real‑world evaluations conducted on the Binance Smart Chain and Ethereum Classic datasets demonstrate the system’s superior performance. With an impressive accuracy rate of 98.50% and a minimal false positive rate of 1.50%, the model demonstrates a remarkable ability to distinguish legitimate network activity from malicious intrusions.
Federico Cernera, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini · 5 authors
In the world of cryptocurrencies, the public listing of a new token often generates significant hype. In many cases, the price of the token skyrockets in a few seconds, and timing is crucial to determine the success or failure of an investment opportunity. In this work, we present an in-depth analysis of sniper bots, automated tools designed to buy tokens as soon as they are listed on the market. We leverage GitHub open-source repositories of sniper bots to analyze their features and how they are implemented. Then, we build a dataset of Ethereum and BNB Smart Chain (BSC) liquidity pools to identify operations performed using sniper bots. Our findings reveal 352,413 sniping operations on Ethereum and 1,716,917 on BSC for a total turnaround of $155,630,184 and $137,548,859, respectively. We find that Ethereum operations have a higher success rate but require a larger investment. Finally, we analyze possible countermeasures and mechanisms used in token smart contracts that can reduce the negative impact of sniper bots.
Adrian Victor VEVERA, Andreea Cătălina CRĂCIUN, Mihail Dumitrache, Ionut SANDU · 6 authors
The Domain Name System (DNS) remains a foundational component of the Internet infrastructure, which is frequently exploited by cybercriminals through increasingly diverse and sophisticated attack vectors.This paper explores the evolving cybersecurity challenges faced by domain name systems (DNSs) and their decentralized counterparts in the Web3 ecosystem, particularly the Ethereum Name Service (ENS), as such, it surveys both the established and novel attack patterns.Furthermore, it explores the implications of decentralized naming systems like the ENS, which introduced novel cybersecurity challenges within the Web3 environments and it highlights the future risks and possible research directions related to the transition to decentralized web services.This study provides a comparative analysis of the cyberattacks targeting the DNS and the ENS, highlighting the evolving threat landscape for each of the two ecosystems.By examining the architectural differences between the DNS and ENS, their common attack vectors, and their security mechanisms, it underscores both the distinct vulnerabilities inherent to each ecosystem and the overlapping risks they share.