Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

824 papersLast indexed Aug 31, 2026
Search papers

Paper index

824 results ¡ page 5 of 35

Clear filters
Jan 1, 2025¡IEEE Access
0 cites
Blockchain-Based Anonymous Reputation System for Performance Appraisal

Hye Jin Lee, Duc Anh Luong, Jong Hwan Park, Hyoseung Kim

Performance appraisal is crucial in human resource management to identify areas within organizations. Ensuring anonymity and confidentiality is important to obtain honest feedback and prevent retaliation. Although blockchain-based anonymous reputation systems have been discussed, permissioned blockchains are susceptible to Sybil attack vulnerabilities, while permissionless private blockchains do not provide full anonymity. We present the Anonymous Reputation System for Performance Appraisal (ARSPA), which uses a permissionless public blockchain. This system is designed for upward feedback in performance appraisals, employing cryptographic techniques such as non-interactive zero-knowledge proofs, public key encryption, and Merkle trees to ensure security. Our protocol addresses the risks of Sybil attacks, ensures review limitation and unforgeability. We validate the security of ARSPA through analysis and demonstrate its feasibility through proof-of-concept on Ethereum test networks. ARSPA provides a secure and efficient approach to improve the reliability and fairness of performance appraisal.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Organizational and Employee Performance
Original source
Jan 1, 2025¡Procedia Computer Science
2 cites
Efficient Miner Selection in Blockchain Based on Predicted Transaction Time

Manjula K. Pawar, Prakashgoud Patil, D. G. Narayan, Vasundhara Pandey ¡ 6 authors

Blockchain’s decentralized, transparent, and immutable nature has revolutionized digital transactions by removing the need for central authorities. Ethereum stands out among blockchain platforms for facilitating secure peer-to-peer transactions via smart contracts. Despite its transformative potential, blockchain faces challenges, particularly with the PoW consensus algorithm, which demands high energy consumption and raises centralization concerns. This affects the scalability of Blockchain by reducing the throughput. This paper explores machine learning (ML) integration to address these challenges, specifically focusing on optimizing miner selection in the Ethereum blockchain based on predicted transaction times. The study compares the performance of various machine learning models, including ElasticNet, Lasso Regression, Multilayer Perceptron (MLP) Regression in optimizing miner selection for reduced transaction times on the Ethereum blockchain. This study advances the ongoing research on integrating machine learning with blockchain to address the shortcomings of traditional Proof of Work (PoW) systems. It emphasizes the potential of machine learning to propel future innovations in blockchain technology.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Brain Tumor Detection and Classification
Original source
Jan 1, 2025¡arXiv (Cornell University)
5 cites
Fast, Private and Regulated Payments in Asynchronous Networks

Brugeres, Maxence, Languille, Victor, Kuznetsov, Petr, Zarfaoui, Hamza

We propose a decentralized asset-transfer system that enjoys full privacy: no party can learn the details of a transaction, except for its issuer and its recipient. Furthermore, the recipient is not aware of the sender’s identity. Our system does not rely on consensus or synchrony assumptions, and therefore, it is responsive, since it runs at the actual network speed. Under the hood, every transaction creates a consumable coin equipped with a non-interactive zero-knowledge proof (NIZK) that confirms that the issuer has sufficient funds without revealing any information about her identity, the recipient’s identity, or the payment amount. Moreover, we equip our system with a regulatory enforcement mechanism that can be used to regulate transfer limits or restrict specific addresses from sending or receiving funds, while preserving the system’s privacy guarantees. Finally, we report on PaxPay, our implementation of Fully Private Asset Transfer (FPAT) that uses the Gnark library for the NIZKs. In our benchmark, PaxPay exhibits better performance than earlier proposals that either ensure only partial privacy, require some kind of network synchrony or do not implement regulation features. Our system thus reconciles privacy, responsiveness, regulation enforcement and performance.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Jan 1, 2025¡International Journal of Intelligent Systems
4 cites
Cryptocurrency Trend Prediction Through Hybrid Deep Transfer Learning

Kia Jahanbin, Mohammad Ali Zare Chahooki

The impact of sentiment analysis of comments on social networks such as X (Twitter) on the cryptocurrency market’s behavior has been proven. Also, traditional sentiment analysis and not considering the possible aspects of tweets can cause the deep model to be misleading in predicting the price trend of cryptocurrencies. In this research, a model using transfer learning and the combination of pretrained DistilBERT networks, BiGRU deep neural network, and attention layer is presented to analyze the sentiments based on the aspect of tweets and predict the price trend of eight cryptocurrencies. These tweets are the opinions of 70 cryptocurrency expert influencers. After preprocessing, these tweets are injected into the hybrid model of DistilBERT, BiGRU, and attention layer (HDBA) to extract the aspect and determine the polarity of each aspect. The output of the HDBA model is entered into the combined model of BiGRU and the attention layer (HBA) to predict the price trend of each cryptocurrency in intervals of 1–10 days. The output of the HBA model is the best time interval of the influence of the sentiments of tweets on the price trend of cryptocurrencies. The results show that the HDBA model has improved the performance of the aspect‐based sentiment analysis task by an average of 3% in the benchmark datasets. The results of the HBA model also show that this model has been able to predict the best time frame of the impact of sentiments on the behavior of the cryptocurrency market with an average accuracy of 68% and a precision of 73%.

Open access
Blockchain Technology Applications and Security
Stock Market Forecasting Methods
Spam and Phishing Detection
Original source
Jan 1, 2025¡arXiv (Cornell University)
0 cites
Hello, won't you tell me your name?: Investigating Anonymity Abuse in IPFS

Christos Karapapas, Iakovos Pittaras, George C. Polyzos, Constantinos Patsakis

The InterPlanetary File System~(IPFS) offers a decentralized approach to file storage and sharing, promising resilience and efficiency while also realizing the Web3 paradigm. Simultaneously, the offered anonymity raises significant questions about potential misuse. In this study, we explore methods that malicious actors can exploit IPFS to upload and disseminate harmful content while remaining anonymous. We evaluate the role of pinning services and public gateways, identifying their capabilities and limitations in maintaining content availability. Using scripts, we systematically test the behavior of these services by uploading malicious files. Our analysis reveals that pinning services and public gateways lack mechanisms to assess or restrict the propagation of malicious content.

Open access
3 source records
Digital and Cyber Forensics
Security and Verification in Computing
Advanced Data Storage Technologies
Original source
Jan 1, 2025¡SSRN Electronic Journal
0 cites
User Voting Behaviour in Reward-Based Social Networks

Alessia Galdeman, Luca Maria Aiello, Matteo Zignani, Sabrina Gaito

No abstract is available for this record.

Open access
2 source records
Opinion Dynamics and Social Influence
Complex Network Analysis Techniques
Spam and Phishing Detection
Original source
Dec 24, 2024¡Security and Privacy
1 cites
Design of an Iterative Method for Blockchain Optimization Incorporating DeepMiner and AnoBlock

Shipra Ravi Kumar, Mukta Goyal

ABSTRACT The burgeoning demand for blockchain technology in diverse sectors requires advanced optimization methods to improve the performance, security and privacy. However, today common blockchain mechanisms are effected by problems like suboptimal miner selection processes, susceptibility to abnormal transactions and types of attacks affecting non‐negligible parts of the ecosystem, performance bottlenecks and so forth, rendering them far from scalability and real‐world usage. This paper addresses the problem, by introducing a set of sophisticated methods that solve recent issues and enhances the robustness, scalability, confidentiality in blockchain networks. Firstly, we present “DeepMiner”, a deep learning‐based solution that leverages historical blockchain data samples to infer optimal miner nodes. This method improves the block generation efficiency by optimizing miner node selection in real‐time, which is an essential addition to traditional random or otherwise static methods for selecting miners. Secondly, “AnoBlock” which uses anomaly detection model to detect fraud in blockchain transactions using the statistical methods like Gaussian mixture models and isolation forests. Thirdly, “OptiChain” uses data analytics to dynamically optimize blockchain performance by continuously evaluating live network metrics and the transaction throughout. Lastly, “PrivyChain” which uses privacy preservation techniques such as zero‐knowledge proofs and homomorphic encryption to achieve transaction confidentiality while retaining blockchain transparency. Their solution addresses these issues with a dual approach to protect any sensitive transaction details from being leaked and make it feasible for computations over encrypted data, the result of which aligns blockchain technology with stringent privacy standards.

Open access
Blockchain Technology Applications and Security
Data Stream Mining Techniques
Spam and Phishing Detection
Original source
Dec 23, 2024¡Electronics
1 cites
Detection of Ethereum Phishing Fraud Nodes Based on Feature Enhancement Strategy and GBM

Sheng-Zheng Liu, Xinyue Yu, Yating Li, Hao Zhang ¡ 7 authors

With the rapid development of blockchain technology and the popularity of cryptocurrency, phishing scams pose an increasingly severe threat to the security of cryptocurrency transactions. Existing fraud detection methods have not accurately identified phishing behaviors, especially failing to capture key neighbor information and its impact effectively. To address this problem, we proposed a phishing detection framework based on FAAN-GBM (Feature and Attention Augmented Network with Gradient Boosting Machine), which aims to improve phishing fraud detection effectiveness on the Ethereum platform by further refining the extraction of phishing account features. This framework integrates basic features, transaction features, and interaction features of nodes, optimizes feature aggregation through importance analysis and attention mechanism of neighbor node, and uses autoencoders to deepen the nonlinear expression of node features. Through extensive testing on real Ethereum datasets, FAAN-GBM has demonstrated superior performance over existing methods, effectively improving the identification accuracy of phishing fraud nodes.

Open access
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Text and Document Classification Technologies
Original source
Dec 16, 2024¡IEEE Transactions on Information Forensics and Security
7 cites
Selfish Mining Time-Averaged Analysis in Bitcoin: Is Orphan Reporting an Effective Countermeasure?

Roozbeh Sarenche, Ren Zhang, Svetla Nikova⋆, Bart Preneel

A Bitcoin miner who owns a sufficient amount of mining power can perform selfish mining to increase its relative revenue. Studies have demonstrated that the time-averaged profit of a selfish miner starts to rise once the mining difficulty level gets adjusted in favor of the attacker. Selfish mining profitability lies in the fact that orphan blocks are not incorporated into the current version of Bitcoin’s difficulty adjustment mechanism (DAM). Therefore, it is believed that considering the count of orphan blocks in the DAM can result in complete unprofitability for selfish mining. In this paper, we disprove this belief by providing a formal analysis of the selfish mining time-averaged profit. We present a precise definition of the orphan blocks that can be incorporated into calculating the next epoch’s target and then introduce two modified versions of DAM in which both main-chain blocks and orphan blocks are incorporated. We propose two versions of smart intermittent selfish mining, where the first one dominates the normal intermittent selfish mining, and the second one results in selfish mining profitability under the modified DAMs. Moreover, we present the orphan exclusion attack with the help of which the attacker can stop honest miners from reporting the orphan blocks. Using combinatorial tools, we analyze the profitability of selfish mining accompanied by the orphan exclusion attack under the modified DAMs. Our results show that even when considering orphan blocks in the DAM, selfish mining can still be profitable. However, the level of profitability under the modified DAMs is significantly lower than that observed under the current version of Bitcoin DAM, suggesting that orphan reporting can be an effective countermeasure against a payoff-maximizing selfish miner.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Dec 16, 2024¡arXiv (Cornell University)
3 cites
Scam Detection for Ethereum Smart Contracts: Leveraging Graph Representation Learning for Secure Blockchain

Yihong Jin, Ze Yang, Xinhe Xu

As more and more attacks have been detected on Ethereum smart contracts, it has seriously affected finance and credibility. Current anti-fraud detection techniques, including code parsing or manual feature extraction, still have some shortcomings, although some generalization or adaptability can be obtained. In the face of this situation, this paper proposes to use graphical representation learning technology to find transaction patterns and distinguish malicious transaction contracts, that is, to represent Ethereum transaction data as graphs, and then use advanced ML technology to obtain reliable and accurate results. Taking into account the sample imbalance, we treated with SMOTE-ENN and tested several models, in which MLP performed better than GCN, but the exact effect depends on its field trials. Our research opens up more possibilities for trust and security in the Ethereum ecosystem.

Open access
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
FinTech, Crowdfunding, Digital Finance
Original source
Dec 14, 2024¡arXiv
4 cites
Serial Scammers and Attack of the Clones: How Scammers Coordinate Multiple Rug Pulls on Decentralized Exchanges

Phuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak ¡ 8 authors

We explored the ubiquitous phenomenon of serial scammers, each of whom deployed dozens to thousands of addresses to conduct a series of similar Rug Pulls on popular decentralized exchanges. We first constructed two datasets of around 384,000 scammer addresses behind all one-day Simple Rug Pulls on Uniswap (Ethereum) and Pancakeswap (BSC), and identified distinctive scam patterns including star, chain, and major (scam-funding) flow. These patterns, which collectively cover about $40\%$ of all scammer addresses in our datasets, reveal typical ways scammers run multiple Rug Pulls and organize the money flow among different addresses. We then studied the more general concept of scam cluster, which comprises scammer addresses linked together via direct ETH/BNB transfers or behind the same scam pools. We found that scam token contracts are highly similar within each cluster (average similarities $>70\%$) and dissimilar across different clusters (average similarities $<30\%$), corroborating our view that each cluster belongs to the same scammer/scam organization. Lastly, we analyze the scam profit of individual scam pools and clusters, employing a novel cluster-aware profit formula that takes into account the important role of wash traders. The analysis shows that the existing formula inflates the profit by at least $32\%$ on Uniswap and $24\%$ on Pancakeswap.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Dec 14, 2024¡SSRN Electronic Journal
0 cites
CAPTCHA Mechanism to Protect User Information on Online Platforms

Oqeili Saleh, Abu-alzanat Thamer, Alkaraimah Qutaibah, al smadi Takialddin

CAPTCHA, which stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart, is a commonly employed security measure to distinguish between humans and computers. The Turing Test, designed to guarantee network security, is the foundation of this security technique. Usability is a crucial concern that can prevent human users from engaging in laborious and time-consuming tasks. When designing CAPTCHA, security and usability must be addressed simultaneously. When designing CAPTCHA, it is crucial to address security and usability simultaneously. A concerted effort is required to protect online data and guarantee privacy and security. The personal information of Internet users remains susceptible to theft. This study uses an information extraction technique called CAPTCHA to investigate the hazards associated with violating user privacy. It is a highly harmful process due to hacking, theft, unauthorized reuse, and the breach of user information. This study proposes a privacy preservation system employing concurrent encryption techniques, multilateral security computing, and zero-knowledge proof. The objective is to create a system that allows for uncomplicated and secure puzzle-solving using dice gas. CAPTCHA limits access to users' information. In the overview and application of evidentiary measurable methods, we can draw significant conclusions about the more extensive client group's discernments and encounters with CAPTCHA as a privacy-preserving component.

Open access
2 source records
User Authentication and Security Systems
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Dec 12, 2024¡IEEE Transactions on Visualization and Computer Graphics
2 cites
PonziLens+: Visualizing Bytecode Actions for Smart Ponzi Scheme Identification

Xiaolin Wen, Tai D. Nguyen, Shaolun Ruan, Qiaomu Shen ¡ 7 authors

With the prevalence of smart contracts, smart Ponzi schemes have become a common fraud on blockchain and have caused significant financial loss to cryptocurrency investors in the past few years. Despite the critical importance of detecting smart Ponzi schemes, a reliable and transparent identification approach adaptive to various smart Ponzi schemes is still missing. To fill the research gap, we first extract semantic-meaningful actions to represent the execution behaviors specified in smart contract bytecodes, which are derived from a literature review and in-depth interviews with domain experts. We then propose PonziLens+, a novel visual analytic approach that provides an intuitive and reliable analysis of Ponzi-scheme-related features within these execution behaviors. PonziLens+ has three visualization modules that intuitively reveal all potential behaviors of a smart contract, highlighting fraudulent features across three levels of detail. It can help smart contract investors and auditors achieve confident identification of any smart Ponzi schemes. We conducted two case studies and in-depth user interviews with 12 domain experts and common investors to evaluate PonziLens+. The results demonstrate the effectiveness and usability of PonziLens+ in achieving an effective identification of smart Ponzi schemes.

Open access
2 source records
cs.HC
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Dec 10, 2024¡Proceedings of the ACM on Measurement and Analysis of Computing Systems
1 cites
Towards Understanding and Analyzing Instant Cryptocurrency Exchanges

Yufeng Hu, Yingshi Sun, Lei Wu, Yajin Zhou ¡ 5 authors

In this paper, we examine a novel category of services in the blockchain ecosystem termed Instant Cryptocurrency Exchange (ICE) services. Originally conceived to facilitate cross-chain asset transfers, ICE services have, unfortunately, been abused for money laundering activities due to two key features: the absence of a strict Know Your Customer (KYC) policy and incomplete on-chain data of user requests. As centralized and non-transparent services, ICE services pose considerable challenges in the tracing of illicit fund flows laundered through them. Our comprehensive study of ICE services begins with an analysis of their features and workflow. We classify ICE services into two distinct types: Standalone and Delegated. We then perform a measurement analysis of ICE services, paying particular attention to their usage in illicit activities. Our findings indicate that a total of 12,473,290 illegal funds have been laundered through ICE services, and 432 malicious addresses were initially funded by ICE services. Based on the insights from measurement analysis, we propose a matching algorithm designed to evaluate the effectiveness of ICE services in terms of efficiency and prevention of traceability. Our evaluation reveals that 92% of the user requests analyzed were completed in less than three minutes, underscoring the efficiency of ICE services. In addition, we demonstrate that the algorithm is effective in tracing illicit funds in situations where ICE services are used in malicious activities. To engage the community, the entire dataset used in this study is open-source.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Spam and Phishing Detection
Original source
Dec 10, 2024¡Proceedings of the ACM on Measurement and Analysis of Computing Systems
11 cites
Piecing Together the Jigsaw Puzzle of Transactions on Heterogeneous Blockchain Networks

Xiaohui Hu, Hang Feng, Pengcheng Xia, Gareth Tyson ¡ 7 authors

The Web3 ecosystem is increasingly evolving to multi-chain, with decentralized applications (dApps) distributing across different blockchains, which drives the need for cross-chain bridges for blockchain interoperability. However, it further opens new attack surfaces, and media outlets have reported serious attacks related to cross-chain bridges. Nevertheless, few prior research studies have studied cross-chain bridges and their related transactions, especially from a security perspective. To fill the void, this paper presents the first comprehensive analysis of cross-chain transactions. We first make efforts to create by far the largest cross-chain transaction dataset based on semantic analysis of popular cross-chain bridges, covering 13 decentralized bridges and 7 representative blockchains, with over 80 million transactions in total. Based on this comprehensive dataset, we present the landscape of cross-chain transactions from angles including token usage, user profile and the purposes of transactions, etc. We further observe that cross-chain bridges can be abused for malicious/aggressive purposes, thus we design an automated detector and deploy it in the wild to flag misbehaviors from millions of cross-chain transactions. We have identified hundreds of abnormal transactions related to exploits and arbitrages, etc. Our research underscores the prevalence of cross-chain ecosystems, unveils their characteristics, and proposes an effective detector for pinpointing security threats.

Open access
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Data Stream Mining Techniques
Original source
Dec 2, 2024¡Proceedings of the ACM Conext-2024 Workshop on the Decentralization of the Internet
2 cites
Towards a Decentralized Internet Namespace

Yekta Kocaoğullar, Eric Osterweil, Lixia Zhang

The Domain Name System (DNS) has been providing a decentralized global namespace to support all Internet applications and usages over the last few decades. In the recent years, a number of blockchain-based name systems have emerged with the claim of providing better namespace decentralization than DNS. The community at large seems uncertain with regard to which of these systems is the best in providing decentralized Internet namespace control. In this paper, we first deconstruct the design of DNS, identify its three essential components and explain who controls each of them. We then examine the Ethereum Name Service (ENS) as a representative example of blockchain-based naming systems, gauge the degree of its decentralization. Finally, we conduct a comparative analysis between DNS and ENS to assess the validity and affordability of each design and the (de)centralization in their namespace control and name system operations.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Spam and Phishing Detection
Original source
Dec 2, 2024¡Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security
7 cites
Characterizing Ethereum Address Poisoning Attack

Shixuan Guan, Kai Li

This paper presents the first comprehensive analysis of the address poisoning attack surged on the Ethereum blockchain. This phishing attack typically exploits the address shortening feature of Ethereum explorers and digital wallets (e.g., Etherscan and MetaMask) by crafting token transfer events with a seemingly correct address to poison victims' transfer history, waiting for them to mistakenly transfer assets to the attacker's address.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cryptography and Data Security
Original source
Dec 2, 2024¡Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security
41 cites
TokenScout: Early Detection of Ethereum Scam Tokens via Temporal Graph Learning

Cong Wu, Jing Chen, Ziming Zhao, Kun He ¡ 10 authors

Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Spam and Phishing Detection
Original source
Nov 22, 2024¡Investment Analysts Journal
5 cites
Gender preferences in cryptocurrency systems: Sentiment analysis and predictive modelling

Samer Muthana Sarsam, Ahmed Ibrahim Alzahrani, Hosam Al‐Samarraie, Fahad Alblehai

This study explored the role of gender preferences in cryptocurrency investments using sentiment analysis. X (Twitter) users’ gender (male/female) together with relevant sentiments (positive/negative) were extracted and investigated in this study. The Latent Dirichlet Allocation technique was utilised to model gender-related topics in an attempt to understand male and female users’ preferences to invest in cryptocurrency. The Apriori algorithm was employed to predict the highly associated investment terminologies with each gender. A predictive model was built to predict the type of digital currency preferred by X users. Using sentiment-based gender data, the results showed a high prediction accuracy (98.64%) of digital currency preferences. The study demonstrated that male users would most likely use Bitcoin, compared to female users who preferred Ethereum. This study further offers a novel mechanism to predict users’ preferences for cryptocurrency platforms using their sentiment features. It extends the knowledge of cryptocurrencies in the financial business profile by revealing how investors’ gender contributes to investment-related decisions.

Open access
Opinion Dynamics and Social Influence
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Nov 22, 2024¡Electronics
6 cites
MultiTagging: A Vulnerable Smart Contract Labeling and Evaluation Framework

Shikah J. Alsunaidi, Hamoud Aljamaan, Mohammad Hammoudeh

Identifying vulnerabilities in Smart Contracts (SCs) is crucial, as they can lead to significant financial losses if exploited. Although various SC vulnerability identification methods exist, selecting the most effective approach remains challenging. This article examines these challenges and introduces solutions to enhance SC vulnerability identification. It introduces MultiTagging, a modular SC multi-labeling framework designed to overcome limitations in existing SC vulnerability identification approaches. MultiTagging automates SC vulnerability tagging by parsing analysis reports and mapping tool-specific tags to standardized labels, including SC Weakness Classification (SWC) codes and Decentralized Application Security Project (DASP) ranks. Its mapping strategy and the proposed vulnerability taxonomy resolve tool-level labeling inconsistencies, where different tools use distinct labels for identical vulnerabilities. The framework integrates an evaluation module to assess SC vulnerability identification methods. MultiTagging enables both tool-based and vote-based SC vulnerability labeling. To improve labeling accuracy, the article proposes Power-based voting, a method that systematically defines voter roles and voting thresholds for each vulnerability. MultiTagging is used to evaluate labeling across six tools: MAIAN, Mythril, Semgrep, Slither, Solhint, and VeriSmart. The results reveal high coverage for Mythril, Slither, and Solhint, which identified eight, seven, and six DASP classes, respectively. Tool performance varied, underscoring the impracticality of relying on a single tool to identify all vulnerability classes. A comparative evaluation of Power-based voting and two threshold-based methods—AtLeastOne and Majority voting—shows that while voting methods can increase vulnerability identification coverage, they may also reduce detection performance. Power-based voting proved more effective than pure threshold-based methods across all vulnerability classes.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source