Ben Charoenwong, Pratik Soni, Varun Shankar, Robert M. Kirby ¡ 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
824 results ¡ page 5 of 35
Ben Charoenwong, Pratik Soni, Varun Shankar, Robert M. Kirby ¡ 5 authors
No abstract is available for this record.
Vsevolod Kachan
No abstract is available for this record.
Hye Jin Lee, Duc Anh Luong, Jong Hwan Park, Hyoseung Kim
Performance appraisal is crucial in human resource management to identify areas within organizations. Ensuring anonymity and confidentiality is important to obtain honest feedback and prevent retaliation. Although blockchain-based anonymous reputation systems have been discussed, permissioned blockchains are susceptible to Sybil attack vulnerabilities, while permissionless private blockchains do not provide full anonymity. We present the Anonymous Reputation System for Performance Appraisal (ARSPA), which uses a permissionless public blockchain. This system is designed for upward feedback in performance appraisals, employing cryptographic techniques such as non-interactive zero-knowledge proofs, public key encryption, and Merkle trees to ensure security. Our protocol addresses the risks of Sybil attacks, ensures review limitation and unforgeability. We validate the security of ARSPA through analysis and demonstrate its feasibility through proof-of-concept on Ethereum test networks. ARSPA provides a secure and efficient approach to improve the reliability and fairness of performance appraisal.
Manjula K. Pawar, Prakashgoud Patil, D. G. Narayan, Vasundhara Pandey ¡ 6 authors
Blockchainâs decentralized, transparent, and immutable nature has revolutionized digital transactions by removing the need for central authorities. Ethereum stands out among blockchain platforms for facilitating secure peer-to-peer transactions via smart contracts. Despite its transformative potential, blockchain faces challenges, particularly with the PoW consensus algorithm, which demands high energy consumption and raises centralization concerns. This affects the scalability of Blockchain by reducing the throughput. This paper explores machine learning (ML) integration to address these challenges, specifically focusing on optimizing miner selection in the Ethereum blockchain based on predicted transaction times. The study compares the performance of various machine learning models, including ElasticNet, Lasso Regression, Multilayer Perceptron (MLP) Regression in optimizing miner selection for reduced transaction times on the Ethereum blockchain. This study advances the ongoing research on integrating machine learning with blockchain to address the shortcomings of traditional Proof of Work (PoW) systems. It emphasizes the potential of machine learning to propel future innovations in blockchain technology.
Brugeres, Maxence, Languille, Victor, Kuznetsov, Petr, Zarfaoui, Hamza
We propose a decentralized asset-transfer system that enjoys full privacy: no party can learn the details of a transaction, except for its issuer and its recipient. Furthermore, the recipient is not aware of the senderâs identity. Our system does not rely on consensus or synchrony assumptions, and therefore, it is responsive, since it runs at the actual network speed. Under the hood, every transaction creates a consumable coin equipped with a non-interactive zero-knowledge proof (NIZK) that confirms that the issuer has sufficient funds without revealing any information about her identity, the recipientâs identity, or the payment amount. Moreover, we equip our system with a regulatory enforcement mechanism that can be used to regulate transfer limits or restrict specific addresses from sending or receiving funds, while preserving the systemâs privacy guarantees. Finally, we report on PaxPay, our implementation of Fully Private Asset Transfer (FPAT) that uses the Gnark library for the NIZKs. In our benchmark, PaxPay exhibits better performance than earlier proposals that either ensure only partial privacy, require some kind of network synchrony or do not implement regulation features. Our system thus reconciles privacy, responsiveness, regulation enforcement and performance.
Kia Jahanbin, Mohammad Ali Zare Chahooki
The impact of sentiment analysis of comments on social networks such as X (Twitter) on the cryptocurrency marketâs behavior has been proven. Also, traditional sentiment analysis and not considering the possible aspects of tweets can cause the deep model to be misleading in predicting the price trend of cryptocurrencies. In this research, a model using transfer learning and the combination of pretrained DistilBERT networks, BiGRU deep neural network, and attention layer is presented to analyze the sentiments based on the aspect of tweets and predict the price trend of eight cryptocurrencies. These tweets are the opinions of 70 cryptocurrency expert influencers. After preprocessing, these tweets are injected into the hybrid model of DistilBERT, BiGRU, and attention layer (HDBA) to extract the aspect and determine the polarity of each aspect. The output of the HDBA model is entered into the combined model of BiGRU and the attention layer (HBA) to predict the price trend of each cryptocurrency in intervals of 1â10 days. The output of the HBA model is the best time interval of the influence of the sentiments of tweets on the price trend of cryptocurrencies. The results show that the HDBA model has improved the performance of the aspectâbased sentiment analysis task by an average of 3% in the benchmark datasets. The results of the HBA model also show that this model has been able to predict the best time frame of the impact of sentiments on the behavior of the cryptocurrency market with an average accuracy of 68% and a precision of 73%.
Yaqoob Alshamsi
No abstract is available for this record.
Christos Karapapas, Iakovos Pittaras, George C. Polyzos, Constantinos Patsakis
The InterPlanetary File System~(IPFS) offers a decentralized approach to file storage and sharing, promising resilience and efficiency while also realizing the Web3 paradigm. Simultaneously, the offered anonymity raises significant questions about potential misuse. In this study, we explore methods that malicious actors can exploit IPFS to upload and disseminate harmful content while remaining anonymous. We evaluate the role of pinning services and public gateways, identifying their capabilities and limitations in maintaining content availability. Using scripts, we systematically test the behavior of these services by uploading malicious files. Our analysis reveals that pinning services and public gateways lack mechanisms to assess or restrict the propagation of malicious content.
Alessia Galdeman, Luca Maria Aiello, Matteo Zignani, Sabrina Gaito
No abstract is available for this record.
Shipra Ravi Kumar, Mukta Goyal
ABSTRACT The burgeoning demand for blockchain technology in diverse sectors requires advanced optimization methods to improve the performance, security and privacy. However, today common blockchain mechanisms are effected by problems like suboptimal miner selection processes, susceptibility to abnormal transactions and types of attacks affecting nonânegligible parts of the ecosystem, performance bottlenecks and so forth, rendering them far from scalability and realâworld usage. This paper addresses the problem, by introducing a set of sophisticated methods that solve recent issues and enhances the robustness, scalability, confidentiality in blockchain networks. Firstly, we present âDeepMinerâ, a deep learningâbased solution that leverages historical blockchain data samples to infer optimal miner nodes. This method improves the block generation efficiency by optimizing miner node selection in realâtime, which is an essential addition to traditional random or otherwise static methods for selecting miners. Secondly, âAnoBlockâ which uses anomaly detection model to detect fraud in blockchain transactions using the statistical methods like Gaussian mixture models and isolation forests. Thirdly, âOptiChainâ uses data analytics to dynamically optimize blockchain performance by continuously evaluating live network metrics and the transaction throughout. Lastly, âPrivyChainâ which uses privacy preservation techniques such as zeroâknowledge proofs and homomorphic encryption to achieve transaction confidentiality while retaining blockchain transparency. Their solution addresses these issues with a dual approach to protect any sensitive transaction details from being leaked and make it feasible for computations over encrypted data, the result of which aligns blockchain technology with stringent privacy standards.
Sheng-Zheng Liu, Xinyue Yu, Yating Li, Hao Zhang ¡ 7 authors
With the rapid development of blockchain technology and the popularity of cryptocurrency, phishing scams pose an increasingly severe threat to the security of cryptocurrency transactions. Existing fraud detection methods have not accurately identified phishing behaviors, especially failing to capture key neighbor information and its impact effectively. To address this problem, we proposed a phishing detection framework based on FAAN-GBM (Feature and Attention Augmented Network with Gradient Boosting Machine), which aims to improve phishing fraud detection effectiveness on the Ethereum platform by further refining the extraction of phishing account features. This framework integrates basic features, transaction features, and interaction features of nodes, optimizes feature aggregation through importance analysis and attention mechanism of neighbor node, and uses autoencoders to deepen the nonlinear expression of node features. Through extensive testing on real Ethereum datasets, FAAN-GBM has demonstrated superior performance over existing methods, effectively improving the identification accuracy of phishing fraud nodes.
Roozbeh Sarenche, Ren Zhang, Svetla Nikovaâ, Bart Preneel
A Bitcoin miner who owns a sufficient amount of mining power can perform selfish mining to increase its relative revenue. Studies have demonstrated that the time-averaged profit of a selfish miner starts to rise once the mining difficulty level gets adjusted in favor of the attacker. Selfish mining profitability lies in the fact that orphan blocks are not incorporated into the current version of Bitcoinâs difficulty adjustment mechanism (DAM). Therefore, it is believed that considering the count of orphan blocks in the DAM can result in complete unprofitability for selfish mining. In this paper, we disprove this belief by providing a formal analysis of the selfish mining time-averaged profit. We present a precise definition of the orphan blocks that can be incorporated into calculating the next epochâs target and then introduce two modified versions of DAM in which both main-chain blocks and orphan blocks are incorporated. We propose two versions of smart intermittent selfish mining, where the first one dominates the normal intermittent selfish mining, and the second one results in selfish mining profitability under the modified DAMs. Moreover, we present the orphan exclusion attack with the help of which the attacker can stop honest miners from reporting the orphan blocks. Using combinatorial tools, we analyze the profitability of selfish mining accompanied by the orphan exclusion attack under the modified DAMs. Our results show that even when considering orphan blocks in the DAM, selfish mining can still be profitable. However, the level of profitability under the modified DAMs is significantly lower than that observed under the current version of Bitcoin DAM, suggesting that orphan reporting can be an effective countermeasure against a payoff-maximizing selfish miner.
Yihong Jin, Ze Yang, Xinhe Xu
As more and more attacks have been detected on Ethereum smart contracts, it has seriously affected finance and credibility. Current anti-fraud detection techniques, including code parsing or manual feature extraction, still have some shortcomings, although some generalization or adaptability can be obtained. In the face of this situation, this paper proposes to use graphical representation learning technology to find transaction patterns and distinguish malicious transaction contracts, that is, to represent Ethereum transaction data as graphs, and then use advanced ML technology to obtain reliable and accurate results. Taking into account the sample imbalance, we treated with SMOTE-ENN and tested several models, in which MLP performed better than GCN, but the exact effect depends on its field trials. Our research opens up more possibilities for trust and security in the Ethereum ecosystem.
Phuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak ¡ 8 authors
We explored the ubiquitous phenomenon of serial scammers, each of whom deployed dozens to thousands of addresses to conduct a series of similar Rug Pulls on popular decentralized exchanges. We first constructed two datasets of around 384,000 scammer addresses behind all one-day Simple Rug Pulls on Uniswap (Ethereum) and Pancakeswap (BSC), and identified distinctive scam patterns including star, chain, and major (scam-funding) flow. These patterns, which collectively cover about $40\%$ of all scammer addresses in our datasets, reveal typical ways scammers run multiple Rug Pulls and organize the money flow among different addresses. We then studied the more general concept of scam cluster, which comprises scammer addresses linked together via direct ETH/BNB transfers or behind the same scam pools. We found that scam token contracts are highly similar within each cluster (average similarities $>70\%$) and dissimilar across different clusters (average similarities $<30\%$), corroborating our view that each cluster belongs to the same scammer/scam organization. Lastly, we analyze the scam profit of individual scam pools and clusters, employing a novel cluster-aware profit formula that takes into account the important role of wash traders. The analysis shows that the existing formula inflates the profit by at least $32\%$ on Uniswap and $24\%$ on Pancakeswap.
Oqeili Saleh, Abu-alzanat Thamer, Alkaraimah Qutaibah, al smadi Takialddin
CAPTCHA, which stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart, is a commonly employed security measure to distinguish between humans and computers. The Turing Test, designed to guarantee network security, is the foundation of this security technique. Usability is a crucial concern that can prevent human users from engaging in laborious and time-consuming tasks. When designing CAPTCHA, security and usability must be addressed simultaneously. When designing CAPTCHA, it is crucial to address security and usability simultaneously. A concerted effort is required to protect online data and guarantee privacy and security. The personal information of Internet users remains susceptible to theft. This study uses an information extraction technique called CAPTCHA to investigate the hazards associated with violating user privacy. It is a highly harmful process due to hacking, theft, unauthorized reuse, and the breach of user information. This study proposes a privacy preservation system employing concurrent encryption techniques, multilateral security computing, and zero-knowledge proof. The objective is to create a system that allows for uncomplicated and secure puzzle-solving using dice gas. CAPTCHA limits access to users' information. In the overview and application of evidentiary measurable methods, we can draw significant conclusions about the more extensive client group's discernments and encounters with CAPTCHA as a privacy-preserving component.
Xiaolin Wen, Tai D. Nguyen, Shaolun Ruan, Qiaomu Shen ¡ 7 authors
With the prevalence of smart contracts, smart Ponzi schemes have become a common fraud on blockchain and have caused significant financial loss to cryptocurrency investors in the past few years. Despite the critical importance of detecting smart Ponzi schemes, a reliable and transparent identification approach adaptive to various smart Ponzi schemes is still missing. To fill the research gap, we first extract semantic-meaningful actions to represent the execution behaviors specified in smart contract bytecodes, which are derived from a literature review and in-depth interviews with domain experts. We then propose PonziLens+, a novel visual analytic approach that provides an intuitive and reliable analysis of Ponzi-scheme-related features within these execution behaviors. PonziLens+ has three visualization modules that intuitively reveal all potential behaviors of a smart contract, highlighting fraudulent features across three levels of detail. It can help smart contract investors and auditors achieve confident identification of any smart Ponzi schemes. We conducted two case studies and in-depth user interviews with 12 domain experts and common investors to evaluate PonziLens+. The results demonstrate the effectiveness and usability of PonziLens+ in achieving an effective identification of smart Ponzi schemes.
Yufeng Hu, Yingshi Sun, Lei Wu, Yajin Zhou ¡ 5 authors
In this paper, we examine a novel category of services in the blockchain ecosystem termed Instant Cryptocurrency Exchange (ICE) services. Originally conceived to facilitate cross-chain asset transfers, ICE services have, unfortunately, been abused for money laundering activities due to two key features: the absence of a strict Know Your Customer (KYC) policy and incomplete on-chain data of user requests. As centralized and non-transparent services, ICE services pose considerable challenges in the tracing of illicit fund flows laundered through them. Our comprehensive study of ICE services begins with an analysis of their features and workflow. We classify ICE services into two distinct types: Standalone and Delegated. We then perform a measurement analysis of ICE services, paying particular attention to their usage in illicit activities. Our findings indicate that a total of 12,473,290 illegal funds have been laundered through ICE services, and 432 malicious addresses were initially funded by ICE services. Based on the insights from measurement analysis, we propose a matching algorithm designed to evaluate the effectiveness of ICE services in terms of efficiency and prevention of traceability. Our evaluation reveals that 92% of the user requests analyzed were completed in less than three minutes, underscoring the efficiency of ICE services. In addition, we demonstrate that the algorithm is effective in tracing illicit funds in situations where ICE services are used in malicious activities. To engage the community, the entire dataset used in this study is open-source.
Xiaohui Hu, Hang Feng, Pengcheng Xia, Gareth Tyson ¡ 7 authors
The Web3 ecosystem is increasingly evolving to multi-chain, with decentralized applications (dApps) distributing across different blockchains, which drives the need for cross-chain bridges for blockchain interoperability. However, it further opens new attack surfaces, and media outlets have reported serious attacks related to cross-chain bridges. Nevertheless, few prior research studies have studied cross-chain bridges and their related transactions, especially from a security perspective. To fill the void, this paper presents the first comprehensive analysis of cross-chain transactions. We first make efforts to create by far the largest cross-chain transaction dataset based on semantic analysis of popular cross-chain bridges, covering 13 decentralized bridges and 7 representative blockchains, with over 80 million transactions in total. Based on this comprehensive dataset, we present the landscape of cross-chain transactions from angles including token usage, user profile and the purposes of transactions, etc. We further observe that cross-chain bridges can be abused for malicious/aggressive purposes, thus we design an automated detector and deploy it in the wild to flag misbehaviors from millions of cross-chain transactions. We have identified hundreds of abnormal transactions related to exploits and arbitrages, etc. Our research underscores the prevalence of cross-chain ecosystems, unveils their characteristics, and proposes an effective detector for pinpointing security threats.
Yekta KocaoÄullar, Eric Osterweil, Lixia Zhang
The Domain Name System (DNS) has been providing a decentralized global namespace to support all Internet applications and usages over the last few decades. In the recent years, a number of blockchain-based name systems have emerged with the claim of providing better namespace decentralization than DNS. The community at large seems uncertain with regard to which of these systems is the best in providing decentralized Internet namespace control. In this paper, we first deconstruct the design of DNS, identify its three essential components and explain who controls each of them. We then examine the Ethereum Name Service (ENS) as a representative example of blockchain-based naming systems, gauge the degree of its decentralization. Finally, we conduct a comparative analysis between DNS and ENS to assess the validity and affordability of each design and the (de)centralization in their namespace control and name system operations.
Shixuan Guan, Kai Li
This paper presents the first comprehensive analysis of the address poisoning attack surged on the Ethereum blockchain. This phishing attack typically exploits the address shortening feature of Ethereum explorers and digital wallets (e.g., Etherscan and MetaMask) by crafting token transfer events with a seemingly correct address to poison victims' transfer history, waiting for them to mistakenly transfer assets to the attacker's address.
Cong Wu, Jing Chen, Ziming Zhao, Kun He ¡ 10 authors
Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks.
Gogulakrishnan Thiyagarajan
No abstract is available for this record.
Samer Muthana Sarsam, Ahmed Ibrahim Alzahrani, Hosam AlâSamarraie, Fahad Alblehai
This study explored the role of gender preferences in cryptocurrency investments using sentiment analysis. X (Twitter) usersâ gender (male/female) together with relevant sentiments (positive/negative) were extracted and investigated in this study. The Latent Dirichlet Allocation technique was utilised to model gender-related topics in an attempt to understand male and female usersâ preferences to invest in cryptocurrency. The Apriori algorithm was employed to predict the highly associated investment terminologies with each gender. A predictive model was built to predict the type of digital currency preferred by X users. Using sentiment-based gender data, the results showed a high prediction accuracy (98.64%) of digital currency preferences. The study demonstrated that male users would most likely use Bitcoin, compared to female users who preferred Ethereum. This study further offers a novel mechanism to predict usersâ preferences for cryptocurrency platforms using their sentiment features. It extends the knowledge of cryptocurrencies in the financial business profile by revealing how investorsâ gender contributes to investment-related decisions.
Shikah J. Alsunaidi, Hamoud Aljamaan, Mohammad Hammoudeh
Identifying vulnerabilities in Smart Contracts (SCs) is crucial, as they can lead to significant financial losses if exploited. Although various SC vulnerability identification methods exist, selecting the most effective approach remains challenging. This article examines these challenges and introduces solutions to enhance SC vulnerability identification. It introduces MultiTagging, a modular SC multi-labeling framework designed to overcome limitations in existing SC vulnerability identification approaches. MultiTagging automates SC vulnerability tagging by parsing analysis reports and mapping tool-specific tags to standardized labels, including SC Weakness Classification (SWC) codes and Decentralized Application Security Project (DASP) ranks. Its mapping strategy and the proposed vulnerability taxonomy resolve tool-level labeling inconsistencies, where different tools use distinct labels for identical vulnerabilities. The framework integrates an evaluation module to assess SC vulnerability identification methods. MultiTagging enables both tool-based and vote-based SC vulnerability labeling. To improve labeling accuracy, the article proposes Power-based voting, a method that systematically defines voter roles and voting thresholds for each vulnerability. MultiTagging is used to evaluate labeling across six tools: MAIAN, Mythril, Semgrep, Slither, Solhint, and VeriSmart. The results reveal high coverage for Mythril, Slither, and Solhint, which identified eight, seven, and six DASP classes, respectively. Tool performance varied, underscoring the impracticality of relying on a single tool to identify all vulnerability classes. A comparative evaluation of Power-based voting and two threshold-based methodsâAtLeastOne and Majority votingâshows that while voting methods can increase vulnerability identification coverage, they may also reduce detection performance. Power-based voting proved more effective than pure threshold-based methods across all vulnerability classes.