Waqas Amin, Qi Huang, Jianping Li, Abdullah Aman Khan · 6 authors
An increase in the popularity of peer-to-peer energy trading in smart grids due to the massive integration of renewable energy sources demands effective and competitive pricing and energy allocation policies to ensure fairness within the market framework. Considering the scalability issues, technical complexity, and operational costs of distributed ledger technology such as blockchain, the reputation of the participants becomes a prominent factor to ensure trustworthiness, reduce risk, and increase market efficiency. This paper proposes a novel method to determine the reputation of participants within the energy market. Based on the evaluated reputation of the participants, an effective pricing method along with an energy distribution technique is devised by considering several market dynamics that significantly affect the pricing and energy allocation method. Extensive experiments have been conducted to validate the effectiveness of the proposed model. The results demonstrate that through the proposed model, the energy bills of the buyers can be reduced by 44%. This highlights the tangible benefits and practical applicability of the proposed approach in optimizing energy costs for consumers in the P2P energy trading ecosystem.
Amulyashree Sridhar, Kalyan Nagaraj, S. Ravi, Sindhu Kurup
The current research aims to discover applications of QML approaches in realizing liabilities within smart contracts. These contracts are essential commodities of the blockchain interface and are also decisive in developing decentralized products. But liabilities in smart contracts could result in unfamiliar system failures. Presently, static detection tools are utilized to discover accountabilities. However, they could result in instances of false narratives due to their dependency on predefined rules. In addition, these policies can often be superseded, failing to generalize on new contracts. The detection of liabilities with ML approaches, correspondingly, has certain limitations with contract size due to storage and performance issues. Nevertheless, employing QML approaches could be beneficial as they do not necessitate any preconceived rules. They often learn from data attributes during the training process and are employed as alternatives to ML approaches in terms of storage and performance. The present study employs four QML approaches, namely, QNN, QSVM, VQC, and QRF, for discovering susceptibilities. Experimentation revealed that the QNN model surpasses other approaches in detecting liabilities, with a performance accuracy of 82.43%. To further validate its feasibility and performance, the model was assessed on a several-partition test dataset, i.e., SolidiFI data, and the outcomes remained consistent. Additionally, the performance of the model was statistically validated using McNemar's test.
The paper explores the prospects for utilizing cryptocurrencies (digital currencies) within the context of foreign economic activity and analyzes the key legal challenges in this area. Currently, the use of digital currencies in cross-border transactions stands out as one of the most effective mechanisms for countering economic sanctions imposed by unfriendly states. In pursuit of these objectives, the Russian Federation has implemented an experimental legal framework for transactions involving cryptocurrencies. Furthermore, it has been established that cross-border settlements in cryptocurrencies were practiced prior to the initiation of this experimental regime, often in defiance of the existing prohibition on accepting digital currencies as consideration. It has been established that the state must ensure the simultaneous implementation of two public interests, which do not contradict each other: upholding legality and countering economic sanctions. This objective is to be achieved through amendments to legislation that introduce liability for violations of the aforementioned prohibition. Terminological inaccuracies within the digital currency legislation have been identified, specifically the inability to incorporate stablecoins with centralized issuers—which have become the primary instrument for cross-border settlements—into the legal concept of “digital currency.” The author substantiated the rationale for conducting a controlled experiment on the use of digital currencies in cross-border settlements.
Blockchain serves as a transformative mechanism for enabling secure, transparent, and privacy-preserving control over data used to train artificial intelligence (AI) models. This paper explores blockchain-enabled frameworks—including data provenance, smart contracts, federated learning integration, Non-Fungible Tokens (NFTs)/DataTokens, and token-based incentive structures—to address data ownership, access governance, contribution compensation, and accountability. We survey platforms such as Ocean Protocol, federated learning with blockchain architectures, and decentralized compute networks. Through analysis of methodologies and case studies across healthcare, IoT, and AI marketplaces, we assess system performance, privacy protection, trust, and regulatory alignment. Our results indicate blockchain facilitates granular data control, immutable provenance, and fair compensation models, yet challenges persist around scalability, incentive fairness, and legal interoperability. We conclude with a roadmap outlining standards, hybrid computations, legal frameworks, and governance models to foster robust "Data-AI-Blockchain" ecosystems.
Smart contracts are software that runs in blockchain and expresses the rules of an agreement between parties. An incorrect smart contract might allow blockchain users to violate its rules and even jeopardize its expected security. Smart contracts cannot be easily replaced to patch a bug since the nature of contracts requires them to be immutable. More problems occur when a smart contract is written in a general-purpose language, such as Java, whose executions, in a blockchain, could hang the network, break consensus or violate data encapsulation. To limit these problems, there exist automatic static analyzers that find bugs before smart contracts are installed in the blockchain. This so-called off-chain verification is optional because programmers are not forced to use it. This paper presents a general framework for the verification of smart contracts, instead, that is part of the protocol of the nodes and applies when the code of the smart contracts gets installed. It is a mandatory entry filter that bans code that does not abide by the verification rules. Consequently, such rules become part of the consensus rules of the blockchain. Therefore, an improvement in the verification protocol entails a consensus update of the network. This paper describes an implementation of a smart contracts application layer with protocol-based verification for smart contracts written in the Takamaka subset of Java, that filters only those smart contracts whose execution in blockchain is not dangerous. This application layer runs on top of a consensus engine such as Tendermint and its derivatives Ignite and CometBFT (proof of stake), or Mokamint (proof of space). This paper provides examples of actual implementations of verification rules that check if the smart contracts satisfy some constraints required by the Takamaka language. This paper shows that protocol-based verification works and reports how consensus updates are implemented. It shows actual experiments as well as limits to its use, mainly related to the fact that protocol-based verification must be fast and its complexity must never explode, or otherwise, it would compromise the performance of the blockchain network.
Introduction Decentralized Autonomous Organizations (DAOs), digital organizations governed by code and community, offer new paradigms for collective governance; yet many early examples have reproduced the power asymmetries, exclusionary participation models, and inefficiencies found in traditional systems. This study examines how DAO governance can evolve to support fair, inclusive, and regenerative capital flows across distributed ecosystems, particularly in contexts where traditional coordination infrastructure is limited. Methods A qualitative case study was conducted on Hypha, an organisation that evolved from a classic DAO to a Decentralized Human Organization (DHO) and subsequently to an Adaptable Organization, or DAO 3.0. Data was collected through semi-structured interviews and document analysis, then interpreted using a People–Process–Technology framework to identify governance design principles. This was supported by a comparative taxonomy mapping the evolution from DAO 1.0 to DAO 3.0. Results Findings show a progression from early token-weighted DAO 1.0 models, through protocol-optimized DAO 2.0 structures, to DAO 3.0’s modular, relational, and context-adaptive designs. Hypha’s governance innovations include multi-layer modular voting, “leadership without control” protocols, real-time capital flow mechanisms, and trust-based safeguards that address fairness failures, enhance adaptability, and enable governance to respond dynamically to human complexity and local contexts. Discussion The Hypha case study positions DAO 3.0 as a prototype for regenerative coordination infrastructure where governance operates as a living system, balancing technological automation with human-centered design. This research expands DAO governance theory by clarifying conceptual boundaries, integrating recent literature, and providing practical guidance for policymakers, developers, and capital providers seeking to design equitable, regenerative governance and coordination systems.
M Savitha Devi, Ningthoujam Chidananda Singh, Thoudam Basanta Singh
Abstract - Blockchain enabled systems are more and more adopted in healthcare for secured processing of data, but current smart contract usage in healthcare leaks private patient data on execution. The contributions of this paper are two-fold: (1) it proposes a new framework that combines ZKPs with healthcare smart contracts/transactions to achieve full privacy preservation and (2) it discusses the security, usability, and the efficiency of the framework at the same time. Our proposed framework is based on zero-knowledge proof systems zkSNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge) and zkSTARKs (Zero-Knowledge Scalable Transparent Argument of Knowledge) tailored for computer on medical data without revealing effectively. We conduct extensive analysis and prototype implementation to show that our framework is able to achieve perfect privacy preservation at a 1.87% computational overhead increase with respect to standard smart contracts. The system processes over 10,000 medical records with sub-second verification times and that meet the HIPAA requirements. Experimental results in diverse healthcare applications attest to the efficacy of the approach in practice, and show the substantial gain of privacy preservation (99.8% retention rate) and computational efficiency over the state-of-art algorithms. This paper bridges the gap between blockchain’s transparency and healthcare’s privacy requirements, laying the groundwork for secure and privacy-preserving blockchain based healthcare applications. Key Words: Zero-knowledge proofs, Smart contracts, Healthcare blockchain, Privacy preservation, zkSNARKs, zkSTARKs, Medical data security, HIPAA compliance
Minjung Park, Gyuyeon Na, Soyoun Kim, Sunyoung Moon · 6 authors
Abnormal cryptocurrency transactions - such as mixing services, fraudulent transfers, and pump-and-dump operations -- pose escalating risks to financial integrity but remain notoriously difficult to detect due to class imbalance, temporal volatility, and complex network dependencies. Existing approaches are predominantly model-centric and post hoc, flagging anomalies only after they occur and thus offering limited preventive value. This paper introduces HyPV-LEAD (Hyperbolic Peak-Valley Lead-time Enabled Anomaly Detection), a data-driven early-warning framework that explicitly incorporates lead time into anomaly detection. Unlike prior methods, HyPV-LEAD integrates three innovations: (1) window-horizon modeling to guarantee actionable lead-time alerts, (2) Peak-Valley (PV) sampling to mitigate class imbalance while preserving temporal continuity, and (3) hyperbolic embedding to capture the hierarchical and scale-free properties of blockchain transaction networks. Empirical evaluation on large-scale Bitcoin transaction data demonstrates that HyPV-LEAD consistently outperforms state-of-the-art baselines, achieving a PR-AUC of 0.9624 with significant gains in precision and recall. Ablation studies further confirm that each component - PV sampling, hyperbolic embedding, and structural-temporal modeling - provides complementary benefits, with the full framework delivering the highest performance. By shifting anomaly detection from reactive classification to proactive early-warning, HyPV-LEAD establishes a robust foundation for real-time risk management, anti-money laundering (AML) compliance, and financial security in dynamic blockchain environments.
In recent years, Femtech has emerged as a growing market category dedicated to women’s health technologies. Despite its rapid expansion, this relatively new and largely unregulated sector has experienced several concerning security breaches that compromise user privacy and intimacy. To address this critical gap between innovation and protection, we propose a novel blockchain-based consent management framework specifically designed for Femtech applications. Our solution leverages distributed ledger technology and smart contracts to create a transparent, immutable system where users can granularly control access to their sensitive health data.
Ioannis Sfyrakis, Paolo Modesti, Lewis Golightly, Minaro Ikegima
Blockchain and smart contracts have transformed industries by automating complex processes and transactions. However, this innovation has introduced significant security concerns, potentially leading to loss of financial assets and data integrity. The focus of this research is to address these challenges by developing a tool that can enable developers and testers to detect vulnerabilities in smart contracts in an efficient and reliable way. The research contributions include an analysis of existing literature on smart contract security, along with the design and implementation of a lightweight vulnerability detection tool called LightCross. This tool runs two well-known detectors, Slither and Mythril, to analyse smart contracts. Experimental analysis was conducted using the SmartBugs curated dataset, which contains 143 vulnerable smart contracts with a total of 206 vulnerabilities. The results showed that LightCross achieves the same detection rate as SmartBugs when using the same backend detectors (Slither and Mythril) while eliminating SmartBugs’ need for a separate Docker container for each detector. Mythril detects 53% and Slither 48% of the vulnerabilities in the SmartBugs curated dataset. Furthermore, an assessment of the execution time across various vulnerability categories revealed that LightCross performs comparably to SmartBugs when using the Mythril detector, while LightCross is significantly faster when using the Slither detector. Finally, to enhance user-friendliness and relevance, LightCross presents the verification results based on OpenSCV, a state-of-the-art academic classification of smart contract vulnerabilities, aligned with the industry-standard CWE and offering improvements over the unmaintained SWC taxonomy.
Md. Rafid Haque, Sakibul Islam Munna, Sabbir Ahmed, Md. Tariqul Islam · 6 authors
Centralized version control systems (VCS) are vital for software development but pose risks of data loss and ownership disputes. While blockchain offers a decentralized alternative, existing solutions are often hindered by high latency, compromising the real-time collaboration essential for modern workflows. This study introduces a novel hybrid architecture combining the security of the Ethereum blockchain and the InterPlanetary File System (IPFS) with two key contributions: 1) Shamir's Secret Sharing (SSS) to create a trust-minimized model for key distribution, and 2) an authoritative-first, optimistic-fallback retrieval protocol utilizing a temporary middleware to decouple the user experience from blockchain confirmation delays. We implemented a full prototype and conducted a comprehensive performance evaluation on the public Sepolia testnet. Our results demonstrate that this architecture not only provides a secure, auditable, and resilient platform for source code hosting but also achieves highly competitive user-perceived performance. Our user-perceived push time reduces submission latency by up to 49% compared to a standard git push for common repository sizes, proving that a well-designed decentralized VCS can balance the core tenets of security and decentralization with the practical need for speed and efficiency.
Michael Herbert Ziegler, Mariusz Nowostawski, Basel Katt
In this literature review, we critically examine the evolving landscape of privacy in blockchain systems, with a particular focus on the differentiation of privacy attacks and protective measures across three distinct layers: the on-chain layer; the off-chain layer; and on the infrastructure, i.e., peer-to-peer network layer. In this review, we categorize prevalent privacy attacks, such as transaction tracing, data leakage, and network surveillance, highlighting their implications at each layer. In addition, we evaluate a range of protective techniques, including cryptographic methods, zero-knowledge proofs, and other privacy-preserving protocols. We explore the compatibility of these privacy techniques with existing blockchain systems. By synthesizing current research and practical implementations, our aims are to provide a comprehensive understanding of privacy challenges and solutions in blockchain environments, identify gaps, and guide future developments in privacy-enhancing technologies within the blockchain ecosystem.
Ethereum smart contracts hold tens of billions of USD in DeFi and NFTs, yet comprehensive security analysis remains difficult due to unverified code, proxy-based architectures, and the reliance on manual inspection of complex execution traces. Existing approaches fall into two main categories: anomaly transaction detection, which flags suspicious transactions but offers limited insight into specific attack strategies hidden in execution traces inside transactions, and code vulnerability detection, which cannot analyze unverified contracts and struggles to show how identified flaws are exploited in real incidents. As a result, analysts must still manually align transaction traces with contract code to reconstruct attack scenarios and conduct forensics. To address this gap, TraceLLM is proposed as a framework that leverages LLMs to integrate execution trace-level detection with decompiled contract code. We introduce a new anomaly execution path identification algorithm and an LLM-refined decompile tool to identify vulnerable functions and provide explicit attack paths to LLM. TraceLLM establishes the first benchmark for joint trace and contract code-driven security analysis. For comparison, proxy baselines are created by jointly transmitting the results of three representative code analysis along with raw traces to LLM. TraceLLM identifies attacker and victim addresses with 85.19\% precision and produces automated reports with 70.37\% factual precision across 27 cases with ground truth expert reports, achieving 25.93\% higher accuracy than the best baseline. Moreover, across 148 real-world Ethereum incidents, TraceLLM automatically generates reports with 66.22\% expert-verified accuracy, demonstrating strong generalizability.
Aleksandr Kormiltsyn, Sowelu Avanzo, Vimal Dwivedi, Alex Norta · 5 authors
This paper explores conflict resolution in decentralized e-health prescription creation workflows, necessary for secure and efficient multi-stakeholder data sharing. Consensus mechanisms ensure consistency and enable trust across distributed systems. Decentralized Autonomous Organizations (DAOs) are adopted for decentralized decision-making in several domains but remain unexplored in e-healthcare. Current consensus mechanisms lack integration with governance models, limiting their adaptability to domain-specific requirements. Moreover, there is no existing consensus algorithm adapted for e-health, resulting in the lack of privacy, interoperability, and patient-centered data ownership. As a result, automatic conflict resolution in interorganizational e-health processes is complicated or almost impossible. To address this gap, we propose a domain-specific consensus algorithm adapted to the requirements of the e-health domain. The algorithm is embedded within a DAO-based governance framework, enabling transparency in decision-making among e-health stakeholders. Such integration enables automated, privacy-preserving conflict resolution in interorganizational e-health workflows. Following the Design Science methodology, the consensus algorithm for e-health DAO is based on stakeholder-driven requirements and evaluated using Colored Petri Nets (CPN). The evaluation shows the solution improves conflict resolution enabling fair, efficient, and privacy-aware collaboration in decentralized e-health.
Mohamad Sheikho Al Jasem, Trevor De Clark, Ajay Kumar Shrestha
The convergence of decentralized artificial intelligence (DAI), blockchain technology, and smart contracts is reshaping the design and governance of intelligent systems. As these technologies rapidly evolve, addressing privacy within their architecture, usage models, and associated risks has become increasingly critical. This systematic literature review examines architectural patterns, governance frameworks, real-world applications, and persistent challenges in DAI systems. It identifies prevailing designs such as federated learning integrated with consensus protocols, smart contract-based incentive mechanisms, and decentralized verification methods. Drawing from a diverse body of recent literature, the review highlights implementations across sectors, including healthcare, finance, IoT, autonomous systems, and intelligent infrastructure, each demonstrating significant contributions to privacy, security, and collaborative innovation. Despite these advancements, DAI systems face ongoing obstacles such as scalability limitations, privacy trade-offs, and difficulties with regulatory compliance. The review emphasizes the need for integrative governance approaches that balance transparency, accountability, incentive alignment, and ethical oversight. These elements are proposed as co-evolving pillars essential to establishing trustworthiness in decentralized AI ecosystems. This work offers a comprehensive review for understanding the current landscape and guiding the development of responsible and effective DAI systems in the Web3 era.
Andrea Michienzi, Laura Pollacci, Barbara Guidi, Francesco Maggio
Nowadays, Social Media represents an important window to address societal issues and promote social causes. However, Social Media suffer from several issues concerning fake news, misinformation, disinformation, etc. To address these issues, decentralization has been proposed to overcome current limitations. Blockchain-based Online Social Media (BOSM) offer verifiable platforms, usually enriched with reward systems that allow users to get paid according to the social value they create. Reward systems can economically empower creators and other individuals beyond high-quality content, allowing content creators to earn income. Considering the widespread use of BOSM platforms and various incentive methods, tools are needed to analyze and guide these rewarding strategies to avoid the risk of speculative mechanisms. In this paper, we propose BISON, a predictive and interpretable framework for identifying the drivers of success in blockchain-native articles. BISON can model success not as a purely financial outcome, but as a composite function of content attributes and user engagement patterns, as recorded on the blockchain. Its modular architecture allows for empirical validation across multiple datasets and makes it adaptable to other Web3 platforms. Additionally, our framework introduces Explainable AI into the blockchain content domain.
Decentralized Autonomous Organizations (DAOs) are a class of Decentralized Applications (DApps) using smart contracts to facilitate governance processes. The design of DAOs is affected by additional complexity compared to other DApps due to the need to specify organizational roles, permissions, and control relations early in the early development stages of the system. In addition, DAOs face scalability challenges. While existing Model-Driven Development (MDD) tools support general smart contract and DApp design, they lack constructs tailored to the organizational and governance features unique to DAOs. To bridge this gap, we develop a code generation approach for DAO-ML, a visual modeling language for DAO design. The translator we implement for this method generates smart contracts of DAOs with suitably configured roles and permissions from visual models. The generated smart contracts particularly optimize the representation of roles and permissions to improve the system scalability and handle complex governance structures, necessary to increase the utility of DAO systems. The approach is evaluated in the context of an in vivo case study on the development of a DAO for the disintermediated management of local tourism. This work advances MDD for decentralized systems by bridging high-level governance modeling with executable, gas-efficient smart contract code generation.
Ramesh Adhikari, Costas Busch, Dariusz R. Kowalski
In blockchain sharding, $n$ processing nodes are divided into $s$ shards, and each shard processes transactions in parallel. A key challenge in such a system is to ensure system stability for any ``tractable'' pattern of generated transactions; this is modeled by an adversary generating transactions with a certain rate of at most $ρ$ and burstiness $b$. This model captures worst-case scenarios and even some attacks on transactions' processing, e.g., DoS. A stable system ensures bounded transaction queue sizes and bounded transaction latency. It is known that the absolute upper bound on the maximum injection rate for which any scheduler could guarantee bounded queues and latency of transactions is $\max\left\{ \frac{2}{k+1}, \frac{2}{ \left\lfloor\sqrt{2s}\right\rfloor}\right\}$, where $k$ is the maximum number of shards that each transaction accesses. Here, we first provide a single leader scheduler that guarantees stability under injection rate $ρ\leq \max\left\{ \frac{1}{16k}, \frac{1}{16\lceil \sqrt{s} \rceil}\right\}$. Moreover, we also give a distributed scheduler with multiple leaders that guarantees stability under injection rate $ρ\leq \frac{1}{16c_1 \log D \log s}\max\left\{ \frac{1}{k}, \frac{1}{\lceil \sqrt{s} \rceil} \right\}$, where $c_1$ is some positive constant and $D$ is the diameter of shard graph $G_s$. This bound is within a poly-log factor from the optimal injection rate, and significantly improves the best previous known result for the distributed setting by Adhikari et al., SPAA 2024.
This paper considers five extensions for Chromium-based browsers in order to determine how effective can browser-based defenses against cryptojacking available to regular users be. We've examined most popular extensions - MinerBlock, AdGuard AdBlocker, Easy Redirect && Prevent Cryptojacking, CoinEater and Miners Shield, which claim to be designed specifically to identify and stop illegal cryptocurrency mining. An empirically confirmed dataset of 373 distinct cryptojacking-infected websites which was assembled during multi-stage procedure, was used to test those extensions. The results showed that all plugins in question had significant performance limits. Easy Redirect and Miners Shield only blocked 6 and 5 websites respectively, while MinerBlock had the greatest detection rate at only 27% (101/373 sites blocked). Most concerningly, despite promises of cryptojacking prevention, AdGuard (which has over 13 million users) and CoinEater were unable to identify any of the compromised websites. These results demonstrate serious flaws in cryptojacking detection products targeted for regular users, since even the best-performing specimen failed to detect 73% of attacks. The obvious difference between advertised capabilities and real performance highlights the urgent need for either accessibility improvements for laboratory-grade detection technologies that show 90%+ efficiency in controlled environment or fundamental upgrades to current commonly used extensions.
Statistical witness indistinguishability is a relaxation of statistical zero-knowledge which guarantees that the transcript of an interactive proof reveals no information about which valid witness the prover used to generate it. In this paper we define and initiate the study of QSWI, the class of problems with quantum statistically witness indistinguishable proofs. Using inherently quantum techniques from Kobayashi (TCC 2008), we prove that any problem with an honest-verifier quantum statistically witness indistinguishable proof has a 3-message public-coin malicious-verifier quantum statistically witness indistinguishable proof. There is no known analogue of this result for classical statistical witness indistinguishability. As a corollary, our result implies SWI is contained in QSWI. Additionally, we extend the work of Bitansky et al. (STOC 2023) to show that quantum batch proofs imply quantum statistically witness indistinguishable proofs with inverse-polynomial witness indistinguishability error.
This paper investigates the dependence structure between returns and trading volumes for five major cryptocurrencies: Bitcoin, Cardano, Ethereum, Litecoin, and Ripple. Using a copula-based framework, we focus on a mixture of the Joe copula and its 90-degree rotation to capture asymmetric relationships, especially in the tails of the distribution. Our findings reveal significant upper and lower–upper tail dependencies, suggesting that extreme trading volumes are associated with both positive and negative return extremes. The results confirm a nonlinear and asymmetric volume–return relationship, which traditional linear models fail to capture.
The rapid growth of Ethereum has spurred widespread adoption of smart contracts, enabling substantial financial transactions. Once deployed on the blockchain, smart contracts are immutable, rendering them unmodifiable even if vulnerabilities are present. In recent years, numerous attacks exploiting these vulnerabilities have caused significant financial losses. Although prior research has improved vulnerability detection in source code or bytecode before deployment, identifying attacks that exploit vulnerabilities during the execution phase after deployment remains a significant challenge. These challenges arise from the limited adaptability of predefined detection rules and an overreliance on opcode sequence names, which often neglects a comprehensive analysis of opcode sequence properties. In this study, we propose an advanced multidimensional feature fusion technique designed to detect attacks during the execution phase of smart contracts. By leveraging deep learning, our approach enhances detection accuracy through a comprehensive analysis of attack behaviors across four dimensions: operation objects, action behaviors, functional categories, and gas consumption. Extensive experiments demonstrate that our method achieves a detection accuracy of 97.21% and a weighted F1-score of 97.21%, confirming its effectiveness in identifying attacks.