Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

325 papersLast indexed Aug 31, 2026
Search papers

Paper index

325 results · page 7 of 14

Clear filters
Dec 1, 2024·DOAJ (DOAJ: Directory of Open Access Journals)
0 cites
Fraud detection in supplementary health insurance based on smart contract in blockchain network

Abbas Raad, Reza Ofoghi, Ghadir Mahdavi

This study aims to examine the function of blockchain technology to detect fraud in health insurance. we consider the literature on fraud in health insurance, blockchain, and smart contracts to to test a newly structured software system based on blockchain technology for this purpose. Different blockchain platforms, consensus algorithms, and structures have been used to pick the proposed system’s best structure based on blockchain. Eventually, the best techniques to put the system to the test and evaluate the findings were assessed. we propose a standardized system, where blockchain is applied to store data and smart contracts are used to automate insurance policies. Furthermore, a web-based application, which acts as core insurance software, is proposed for all stakeholders to communicate with the blockchain and smart contracts. Therefore, the proposed system comprises a blockchain, web app, and standardized smart contracts. The proposed system mainly focuses on fraud detection in insurance claims while maintaining a standard data storage and transfer structure. The system proved to be thriving once claim data can be created, read, and analyzed (i.e. fraudulent data are caught) effectively in a standard way. The web app consists of a front-end and back-end section. The front-end enables users to interact with the proposed system, and the back-end allows the insurance company to store records on the blockchain and increase the chances of detecting fraud in insurance claims, especially Digital Insurance Claims. Finally, a blockchain-based web application that can be used as core insurance software for any health insurance company is proposed.

Open access
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Advanced Technologies in Various Fields
Original source
Nov 2, 2024·Journal of Metaverse
15 cites
SmartLLMSentry: A Comprehensive LLM Based Smart Contract Vulnerability Detection Framework

Oualid Zaazaa, Hanan El Bakkali

Smart contracts are essential for managing digital assets in blockchain networks, highlighting the need for effective security measures. This paper introduces SmartLLMSentry, a novel framework that leverages large language models (LLMs), specifically ChatGPT with in-context training, to advance smart contract vulnerability detection. Traditional rule-based frameworks have limitations in integrating new detection rules efficiently. In contrast, SmartLLMSentry utilizes LLMs to streamline this process. We created a specialized dataset of five randomly selected vulnerabilities for model training and evaluation. Our results show an exact match accuracy of 91.1% with sufficient data, although GPT-4 demonstrated reduced performance compared to GPT-3 in rule generation. This study illustrates that SmartLLMSentry significantly enhances the speed and accuracy of vulnerability detection through LLM-driven rule integration, offering a new approach to improving Blockchain security and addressing previously underexplored vulnerabilities in smart contracts.

Open access
4 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Original source
Oct 28, 2024·arXiv (Cornell University)
1 cites
Clean Up the Mess: Addressing Data Pollution in Cryptocurrency Abuse Reporting Services

Gibran Gómez, Kevin van Liebergen, Davide Sanvito, Giuseppe Siracusano · 6 authors

Cryptocurrency abuse reporting services are a valuable data source about abusive blockchain addresses, prevalent types of cryptocurrency abuse, and their financial impact on victims. However, they may suffer data pollution due to their crowd-sourced nature. This work analyzes the extent and impact of data pollution in cryptocurrency abuse reporting services and proposes a novel LLM-based defense to address the pollution. We collect 289K abuse reports submitted over 6 years to two popular services and use them to answer three research questions. RQ1 analyzes the extent and impact of pollution. We show that spam reports will eventually flood unchecked abuse reporting services, with BitcoinAbuse receiving 75% of spam before stopping operations. We build a public dataset of 19,443 abuse reports labeled with 19 popular abuse types and use it to reveal the inaccuracy of user-reported abuse types. We identified 91 (0.1%) benign addresses reported, responsible for 60% of all the received funds. RQ2 examines whether we can automate identifying valid reports and their classification into abuse types. We propose an unsupervised LLM-based classifier that achieves an F1 score of 0.95 when classifying reports, an F1 of 0.89 when classifying out-of-distribution data, and an F1 of 0.99 when identifying spam reports. Our unsupervised LLM-based classifier clearly outperforms two baselines: a supervised classifier and a naive usage of the LLM. Finally, RQ3 demonstrates the usefulness of our LLM-based classifier for quantifying the financial impact of different cryptocurrency abuse types. We show that victim-reported losses heavily underestimate cybercriminal revenue by estimating a 29 times higher revenue from deposit transactions. We identified that investment scams have the highest financial impact and that extortions have lower conversion rates but compensate for them with massive email campaigns.

Open access
2 source records
cs.CR
cs.CL
Cybercrime and Law Enforcement Studies
Original source
Oct 25, 2024·International journal of intelligent engineering and systems
1 cites
Zero-knowledge Proof Based Federated Learning with Blockchain for COVID-19 Classification

Authors unavailable

The diversity and scarcity of the medical information makes it difficult to create precise global classification approach for the healthcare applications.The main motive is the privacy issue that restricts the data exchanging scope between healthcare institutions.On the contrary, an information from single source is not adequate for developing the worldwide diagnosis approach.The Federated Learning (FL) is a promising solution for privacy and data multiplicity issues, an appropriate aggregation model for multi class and dissimilar medical information is still challenging task in the recognition.Moreover, the FL approaches does not effectively analyzes the each participant execution in the local model and secures the user data.In order to overcome this issue, the Zero-Knowledge Proof (ZKP) based FL approach is developed over blockchain (BC) for performing the COVID-19 classification.The global model of FL uses the two layer Long Short Term Memory (2LLSTM) with federated proximal term (FedProx) namely 2LLSTMFP while the Convolutional Neural Network (CNN) is used in the local model.The integration ZKP and BS is used to improve the data confidentiality while the immutability of BC helps to prevent unauthorized variations for the ledger.The developed FLBC-ZKP is analyzed with two datasets such as COVID-19 Radiography, and CXR images pneumonia and COVID-19.The FLBC-ZKP is evaluated using accuracy, recall, precision, specificity, F1-score, False Negative Rate (FNR) and False Positive Rate (FPR).The existing researches such as WMT, MCCF, 3SFDL and TOTL are used to compare the FLBC-ZKP method.The FLBC-ZKP achieves improved accuracy of 98.34 % for COVID-19 Radiography dataset that is better than the MCCF and 3SFDL.

Open access
Privacy-Preserving Technologies in Data
COVID-19 diagnosis using AI
Imbalanced Data Classification Techniques
Original source
Oct 22, 2024·INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
0 cites
Indentity Management System Using Blockchain and Survey

Udayveer Singh Virk, Devansh Verma, Gagandeep Singh, Prof. Sheetal Laroiya Prof. Sheetal Laroiya

Abstract—This project aims to develop a web3 platform that stores user credentials on the blockchain, providing high levels of security and privacy. Using a range of tools and technologies, including Metamask, RemixIDE, Ganache, Node.js, Solidity for smart contracts, HTML, and CSS, the platform offers a user-friendly interface that enhances the user experience. Smart contracts are used to ensure that user credentials are only visible to the individual user, providing a high level of security and privacy. This platform has the ability to revolutionize how users interact with online services and manage their digital identities, reducing costs, increasing trust, and improving expandability. The implementation of this project has demonstrated the overall benefits of blockchain and smart contracts in virtual identity management, including increased security, improved privacy, and enhanced user experience. The platform has the potential for further development and expansion, including the integration of biometric authentication, artificial intelligence and machine learning algorithms, and the expansion to include a range of online services. Overall, this project has demonstrated the significant potential of blockchain technology and smart contracts in digital identity management and has the ability to shift the way users communicate with online services, offering a one-stop-shop for their online needs. Keywords—Block chain, metamask, ganache, remix ide, solidity

Open access
Currency Recognition and Detection
Imbalanced Data Classification Techniques
Smart Systems and Machine Learning
Original source
Oct 8, 2024·arXiv (Cornell University)
1 cites
SC-Bench: A Large-Scale Dataset for Smart Contract Auditing

Shihao Xia, Mengting He, Linhai Song, Yiying Zhang

There is a huge demand to ensure the compliance of smart contracts listed on blockchain platforms to safety and economic standards described in natural languages. Today, manual efforts in the form of auditing are commonly used to achieve this goal. ML-based automated techniques have the promise to alleviate human efforts and the resulting monetary costs. However, unlike other domains where ML techniques have had huge successes, no systematic ML techniques have been proposed or applied to smart contract auditing. We present SC-Bench, the first dataset for automated smart-contract auditing research. SC-Bench consists of 5,377 real-world smart contracts running on Ethereum, a widely used blockchain platform, and 15,975 violations of standards on Ehereum called ERCs. Out of these violations, 139 are real violations programmers made. The remaining are errors systematically injected by us to reflect the violations of different ERC rules. We evaluate SC-Bench using GPT-4 by prompting it with both the contracts and ERC rules. In addition, we manually identify each violated rule and the corresponding code site (i.e., oracle) and prompt GPT-4 with the information asking for a True-or-False question. Our results show that without the oracle, GPT-4 can only detect 0.9% violations, and with the oracle, it detects 22.9% violations. These results show the potential room for improvement in ML-based techniques for smart-contract auditing.

Open access
3 source records
cs.CR
cs.AI
Artificial Intelligence in Law
Original source
Oct 3, 2024·arXiv (Cornell University)
0 cites
RiskSEA : A Scalable Graph Embedding for Detecting On-chain Fraudulent Activities on the Ethereum Blockchain

Ayush Agarwal, Lu Lv, Arjun Maheswaran, Mahadevan, Varsha · 5 authors

Like any other useful technology, cryptocurrencies are sometimes used for criminal activities. While transactions are recorded on the blockchain, there exists a need for a more rapid and scalable method to detect addresses associated with fraudulent activities. We present RiskSEA, a scalable risk scoring system capable of effectively handling the dynamic nature of large-scale blockchain transaction graphs. The risk scoring system, which we implement for Ethereum, consists of 1. a scalable approach to generating node2vec embedding for entire set of addresses to capture the graph topology 2. transaction-based features to capture the transactional behavioral pattern of an address 3. a classifier model to generate risk score for addresses that combines the node2vec embedding and behavioral features. Efficiently generating node2vec embedding for large scale and dynamically evolving blockchain transaction graphs is challenging, we present two novel approaches for generating node2vec embeddings and effectively scaling it to the entire set of blockchain addresses: 1. node2vec embedding propagation and 2. dynamic node2vec embedding. We present a comprehensive analysis of the proposed approaches. Our experiments show that combining both behavioral and node2vec features boosts the classification performance significantly, and that the dynamic node2vec embeddings perform better than the node2vec propagated embeddings.

Open access
2 source records
cs.CR
cs.AI
cs.LG
Original source
Sep 30, 2024·arXiv (Cornell University)
0 cites
Smart Contract Vulnerability Detection based on Static Analysis and Multi-Objective Search

Dongcheng Li, W. Eric Wong, Xiaodan Wang, Sean Pan · 5 authors

This paper introduces a method for detecting vulnerabilities in smart contracts using static analysis and a multi-objective optimization algorithm. We focus on four types of vulnerabilities: reentrancy, call stack overflow, integer overflow, and timestamp dependencies. Initially, smart contracts are compiled into an abstract syntax tree to analyze relationships between contracts and functions, including calls, inheritance, and data flow. These analyses are transformed into static evaluations and intermediate representations that reveal internal relations. Based on these representations, we examine contract's functions, variables, and data dependencies to detect the specified vulnerabilities. To enhance detection accuracy and coverage, we apply a multi-objective optimization algorithm to the static analysis process. This involves assigning initial numeric values to input data and monitoring changes in statement coverage and detection accuracy. Using coverage and accuracy as fitness values, we calculate Pareto front and crowding distance values to select the best individuals for the new parent population, iterating until optimization criteria are met. We validate our approach using an open-source dataset collected from Etherscan, containing 6,693 smart contracts. Experimental results show that our method outperforms state-of-the-art tools in terms of coverage, accuracy, efficiency, and effectiveness in detecting the targeted vulnerabilities.

Open access
2 source records
cs.SE
Imbalanced Data Classification Techniques
Artificial Intelligence in Law
Original source
Sep 30, 2024·IEICE Transactions on Information and Systems
5 cites
Smart Contract Timestamp Vulnerability Detection Based on Code Homogeneity

Weizhi Wang, L. Xia, Zhuo Zhang, Xiankai Meng

Smart contracts, as a form of digital protocol, are computer programs designed for the automatic execution, control, and recording of contractual terms. They permit transactions to be conducted without the need for an intermediary. However, the economic property of smart contracts makes their vulnerabilities susceptible to hacking attacks, leading to significant losses. In this paper, we introduce a smart contract timestamp vulnerability detection technique HomoDec based on code homogeneity. The core idea of this technique involves comparing the homogeneity between the code of the test smart contract and the existing smart contract vulnerability codes in the database to determine whether the tested code has a timestamp vulnerability. Specifically, HomoDec first explores how to vectorize smart contracts reasonably and efficiently, representing smart contract code as a high-dimensional vector containing features of code vulnerabilities. Subsequently, it investigates methods to determine the homogeneity between the test codes and the ones in vulnerability code base, enabling the detection of potential timestamp vulnerabilities in smart contract code.

Open access
Imbalanced Data Classification Techniques
Blockchain Technology Applications and Security
Artificial Intelligence in Law
Original source
Sep 22, 2024·Lecture notes in computer science
2 cites
ZK-SNARKs for Ballot Validity: A Feasibility Study

Nicolas Huber, Ralf Küsters, Julian Liedtke, Daniel Rausch

Abstract Electronic voting (e-voting) systems have become more prevalent in recent years, but security concerns have also increased, especially regarding the privacy and verifiability of votes. As an essential ingredient for constructing secure e-voting systems, designers often employ zero-knowledge proofs (ZKPs), allowing voters to prove their votes are valid without revealing them. Invalid votes can then be discarded to protect verifiability without compromising the privacy of valid votes. General purpose zero-knowledge proofs (GPZKPs) such as ZK-SNARKs can be used to prove arbitrary statements, including ballot validity. While a specialized ZKP that is constructed only for a specific election type/voting method, ballot format, and encryption/commitment scheme can be more efficient than a GPZKP, the flexibility offered by GPZKPs would allow for quickly constructing e-voting systems for new voting methods and new ballot formats. So far, however, the viability of GPZKPs for showing ballot validity for various ballot formats, in particular, whether and in how far they are practical for voters to compute, has only recently been investigated for ballots that are computed as Pedersen vector commitments in an ACM CCS 2022 paper by Huber et al. Here, we continue this line of research by performing a feasibility study of GPZKPs for the more common case of ballots encrypted via Exponential ElGamal encryption. Specifically, building on the work by Huber et al., we describe how the Groth16 ZK-SNARK can be instantiated to show ballot validity for arbitrary election types and ballot formats encrypted via Exponential ElGamal. As our main contribution, we implement, benchmark, and compare several such instances for a wide range of voting methods and ballot formats. Our benchmarks not only establish a basis for protocol designers to make an educated choice for or against such a GPZKP, but also show that GPZKPs are actually viable for showing ballot validity in voting systems using Exponential ElGamal.

Open access
Imbalanced Data Classification Techniques
Privacy-Preserving Technologies in Data
Internet Traffic Analysis and Secure E-voting
Original source
Sep 9, 2024·Information Fusion
32 cites
Ethereum fraud detection via joint transaction language model and graph representation learning

Jianguo Sun, Yifan Jia, Yanbin Wang, Yiwei Liu · 6 authors

Ethereum faces growing fraud threats. Current fraud detection methods, whether employing graph neural networks or sequence models, fail to consider the semantic information and similarity patterns within transactions. Moreover, these approaches do not leverage the potential synergistic benefits of combining both types of models. To address these challenges, we propose TLMG4Eth that combines a transaction language model with graph-based methods to capture semantic, similarity, and structural features of transaction data in Ethereum. We first propose a transaction language model that converts numerical transaction data into meaningful transaction sentences, enabling the model to learn explicit transaction semantics. Then, we propose a transaction attribute similarity graph to learn transaction similarity information, enabling us to capture intuitive insights into transaction anomalies. Additionally, we construct an account interaction graph to capture the structural information of the account transaction network. We employ a deep multi-head attention network to fuse transaction semantic and similarity embeddings, and ultimately propose a joint training approach for the multi-head attention network and the account interaction graph to obtain the synergistic benefits of both.

Open access
4 source records
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Blockchain Technology Applications and Security
Original source
Aug 28, 2024·Mathematics
15 cites
An Enhanced Credit Risk Evaluation by Incorporating Related Party Transaction in Blockchain Firms of China

Ying Chen, Lingjie Liu, Libing Fang

Related party transactions (RPTs) can serve as channels for the spread of credit risk events among blockchain firms. However, current credit risk-assessment models typically only consider a firm’s individual characteristics, overlooking the impact of related parties in the blockchain. We suggest incorporating RPT network analysis to improve credit risk evaluation. Our approach begins by representing an RPT network using a weighted adjacency matrix. We then apply DANE, a deep network embedding algorithm, to generate condensed vector representations of the firms within the network. These representations are subsequently used as inputs for credit risk-evaluation models to predict the default distance. Following this, we employ SHAP (Shapley Additive Explanations) to analyze how the network information contributes to the prediction. Lastly, this study demonstrates the enhancing effect of using DANE-based integrated features in credit risk assessment.

Open access
Financial Distress and Bankruptcy Prediction
Credit Risk and Financial Regulations
Imbalanced Data Classification Techniques
Original source
Aug 19, 2024·IEEE Transactions on Information Forensics and Security
52 cites
Vulseye: Detect Smart Contract Vulnerabilities via Stateful Directed Graybox Fuzzing

Ruichao Liang, Jing Chen, Cong Wu, Kun He · 9 authors

Smart contracts, the cornerstone of decentralized applications, have become increasingly prominent in revolutionizing the digital landscape. However, vulnerabilities in smart contracts pose great risks to user assets and undermine overall trust in decentralized systems. Fuzzing, a prominent security testing technique, is extensively explored to detect vulnerabilities. But current smart contract fuzzers fall short of expectations in testing efficiency for two primary reasons. Firstly, smart contracts are stateful programs, and existing approaches, primarily coverage-guided, lack effective feedback from the contract state. Consequently, they struggle to effectively explore the contract state space. Secondly, coverage-guided fuzzers, aiming for comprehensive program coverage, may lead to a wastage of testing resources on benign code areas. This wastage worsens in smart contract testing, as the mix of code and state spaces further complicates comprehensive testing. To address these challenges, we propose Vulseye, a stateful directed graybox fuzzer for smart contracts guided by vulnerabilities. Different from prior works, Vulseyeachieves stateful directed fuzzing by prioritizing testing resources to code areas and contract states that are more prone to vulnerabilities. We introduceCode TargetsandState Targetsinto fuzzing loops as the testing targets of Vulseye. We use static analysis and pattern matching to pinpointCode Targets, and propose a scalable backward analysis algorithm to specifyState Targets. We design a novel fitness metric that leverages feedback from both the contract code space and state space, directing fuzzing toward these targets. With the guidance of code and state targets, Vulseyealleviates the wastage of testing resources on benign code areas and achieves effective stateful fuzzing. In comparison with state-of-the-art fuzzers, Vulseyedemonstrated superior effectiveness and efficiency. Notably, it uncovered 4,845 vulnerabilities in 42,738 real-world smart contracts, outperforming existing approaches by up to$9.7\times $, and identified 11 previously unknown vulnerabilities within the top 50 Ethereum DApps, involving approximately 2,500,000 USD.

Open access
3 source records
Imbalanced Data Classification Techniques
Artificial Intelligence in Law
Cybercrime and Law Enforcement Studies
Original source
Aug 8, 2024·Proceedings of the 2024 Sixteenth International Conference on Contemporary Computing
6 cites
Blockchain Fraud Detection Using Unsupervised Learning: Anomalous Transaction Patterns Detection Using K-Means Clustering

Geeta Sandeep Nadella, Karthik Meduri, Hari Gonaygunta, Snehal Satish · 5 authors

In the dynamic and rapidly evolving landscape of blockchain technology, traditional fraud detection methods, which often rely on labeled data, face limitations due to the diverse and adaptive nature of fraud. This study introduces a novel framework that employs the K-Means clustering algorithm, a technique celebrated for its unsupervised learning capabilities, to detect anomalous transaction patterns indicative of potential fraud, such as unusually high transaction volumes or rapid transfers between wallets. By circumventing the need for pre-labeled examples of fraudulent activity, our approach significantly enhances adaptability and applicability across various blockchain contexts. We apply this framework to a comprehensive dataset encompassing multiple cryptocurrencies, including Bitcoin, Ethereum, Doge Coins, and Tether, analyzing attributes such as closing prices, volatility, and market volume. The results demonstrate the framework’s effectiveness in isolating outliers and identifying transactions that bear hallmarks of suspicious activity, thereby contributing a powerful tool for proactive fraud detection. This research not only paves the way for future advancements in blockchain security but also reinforces the trustworthiness and integrity of blockchain systems by providing a robust mechanism for identifying and mitigating fraudulent activities without the constraints of traditional, supervised methods.

Open access
Blockchain Technology Applications and Security
Currency Recognition and Detection
Imbalanced Data Classification Techniques
Original source
Aug 6, 2024·arXiv (Cornell University)
2 cites
Simple Perturbations Subvert Ethereum Phishing Transactions Detection: An Empirical Analysis

Ahod Alghureid, Aziz Mohaisen

This paper explores the vulnerability of machine learning models, specifically Random Forest, Decision Tree, and K-Nearest Neighbors, to very simple single-feature adversarial attacks in the context of Ethereum fraudulent transaction detection. Through comprehensive experimentation, we investigate the impact of various adversarial attack strategies on model performance metrics, such as accuracy, precision, recall, and F1-score. Our findings, highlighting how prone those techniques are to simple attacks, are alarming, and the inconsistency in the attacks' effect on different algorithms promises ways for attack mitigation. We examine the effectiveness of different mitigation strategies, including adversarial training and enhanced feature selection, in enhancing model robustness.

Open access
4 source records
Spam and Phishing Detection
Internet Traffic Analysis and Secure E-voting
Imbalanced Data Classification Techniques
Original source
Aug 1, 2024·IEEE Transactions on Information Forensics and Security
23 cites
Enhancing Ethereum Fraud Detection via Generative and Contrastive Self-Supervision

Chengxiang Jin, Jiajun Zhou, Chenxuan Xie, Shanqing Yu · 6 authors

The rampant fraudulent activities on Ethereum hinder the healthy development of the blockchain ecosystem, necessitating the reinforcement of regulations. However, multiple imbalances involving account interaction frequencies and interaction types in the Ethereum transaction environment pose significant challenges to data mining-based fraud detection research. To address this, we first propose the concept of meta-interactions to refine interaction behaviors in Ethereum, and based on this, we present a dual self-supervision enhanced Ethereum fraud detection framework, named Meta-IFD. This framework initially introduces a generative self-supervision mechanism to augment the interaction features of accounts, followed by a contrastive self-supervision mechanism to differentiate various behavior patterns, and ultimately characterizes the behavioral representations of accounts and mines potential fraud risks through multi-view interaction feature learning. Extensive experiments on real Ethereum datasets demonstrate the effectiveness and superiority of our framework in detecting common Ethereum fraud behaviors such as Ponzi schemes and phishing scams. Additionally, the generative module can effectively alleviate the interaction distribution imbalance in Ethereum data, while the contrastive module significantly enhances the framework's ability to distinguish different behavior patterns. The source code will be available in https://github.com/GISec-Team/Meta-IFD.

Open access
3 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Original source
Jul 23, 2024·arXiv (Cornell University)
10 cites
Utilizing Blockchain and Smart Contracts for Enhanced Fraud Prevention and Minimization in Health Insurance through Multi-Signature Claim Processing

Al Amin, Rushabh Shah, Hemanth Tummala, Indrajit Ray

Healthcare insurance provides financial support to access medical services for patients while ensuring timely and guaranteed payment for providers. Insurance fraud poses a significant challenge to insurance companies and policyholders, leading to increased costs and compromised healthcare treatment and service delivery. Most frauds, like phantom billing, upcoding, and unbundling, happen due to the lack of required entity participation. Also, claim activities are not transparent and accountable. Fraud can be prevented and minimized by involving every entity and making actions transparent and accountable. This paper proposes a blockchain-powered smart contract-based insurance claim processing mechanism to prevent and minimize fraud in response to this prevailing issue. All entities-patients, providers, and insurance companies-actively participate in the claim submission, approval, and acknowledgment process through a multi-signature technique. Also, every activity is captured and recorded in the blockchain using smart contracts to make every action transparent and accountable so that no entity can deny its actions and responsibilities. Blockchains' immutable storage property and strong integrity guarantee that recorded activities are not modified. As healthcare systems and insurance companies continue to deal with fraud challenges, this proposed approach holds the potential to significantly reduce fraudulent activities, ultimately benefiting both insurers and policyholders. The average gas costs for smart contract deployment, claim submission, and multi-signature for the Ethereum network: $80.22, $20.60, and $6.47, and for the Optimism network: $0.35, $0.089, and $0.028. They are feasible for the proposed approach.

Open access
3 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Imbalanced Data Classification Techniques
Original source
Jul 20, 2024·arXiv (Cornell University)
2 cites
Retrieval Augmented Generation Integrated Large Language Models in Smart Contract Vulnerability Detection

Jeffy Yu

The rapid growth of Decentralized Finance (DeFi) has been accompanied by substantial financial losses due to smart contract vulnerabilities, underscoring the critical need for effective security auditing. With attacks becoming more frequent, the necessity and demand for auditing services has escalated. This especially creates a financial burden for independent developers and small businesses, who often have limited available funding for these services. Our study builds upon existing frameworks by integrating Retrieval-Augmented Generation (RAG) with large language models (LLMs), specifically employing GPT-4-1106 for its 128k token context window. We construct a vector store of 830 known vulnerable contracts, leveraging Pinecone for vector storage, OpenAI's text-embedding-ada-002 for embeddings, and LangChain to construct the RAG-LLM pipeline. Prompts were designed to provide a binary answer for vulnerability detection. We first test 52 smart contracts 40 times each against a provided vulnerability type, verifying the replicability and consistency of the RAG-LLM. Encouraging results were observed, with a 62.7% success rate in guided detection of vulnerabilities. Second, we challenge the model under a "blind" audit setup, without the vulnerability type provided in the prompt, wherein 219 contracts undergo 40 tests each. This setup evaluates the general vulnerability detection capabilities without hinted context assistance. Under these conditions, a 60.71% success rate was observed. While the results are promising, we still emphasize the need for human auditing at this time. We provide this study as a proof of concept for a cost-effective smart contract auditing process, moving towards democratic access to security.

Open access
2 source records
cs.CR
cs.AI
Imbalanced Data Classification Techniques
Original source
Jul 2, 2024·Proceedings of the 6th ACM International Symposium on Blockchain and Secure Critical Infrastructure
2 cites
Anomaly Detection in Bitcoin Network: Using Distance-based and Tree-based Unsupervised Learning Methods

Yossapol Witayanont, Waraporn Viyanon

Anomaly detection in the financial system has been studied for decades. Anomalies refer to irregular items or events that are different from the majority. Therefore, illegal activities are anomalous by nature because it is opposed to the norm. Preventive actions like anomalous detection play an important role in avoiding incidents that damage people's property. In this paper, the Bitcoin network is the subject of the study. We consider the effectiveness of two unsupervised learning algorithms, Histogram-based Outlier Score (HBOS) and Isolation Forest, for detecting anomalous transactions and wallet addresses. Providing insights into the strengths and weaknesses of HBOS and Isolation Forest for anomaly detection. We also analyze which features are the most important for each algorithm in identifying anomalies. The result shows similar detection for both algorithms. While HBOS has higher wallet visualization score at 0.423, Isolation Forest yields better scores on transaction visualization, dual, and known-thieves evaluations with score of 0.713, 0.681, and 0.035, respectively.

Open access
Anomaly Detection Techniques and Applications
Network Security and Intrusion Detection
Imbalanced Data Classification Techniques
Original source
Jul 1, 2024·Journal of Medical Internet Research
8 cites
Automatic Recommender System of Development Platforms for Smart Contract–Based Health Care Insurance Fraud Detection Solutions: Taxonomy and Performance Evaluation

Rima Kaafarani, Leila Ismail, Oussama Zahwe

BACKGROUND: Health care insurance fraud is on the rise in many ways, such as falsifying information and hiding third-party liability. This can result in significant losses for the medical health insurance industry. Consequently, fraud detection is crucial. Currently, companies employ auditors who manually evaluate records and pinpoint fraud. However, an automated and effective method is needed to detect fraud with the continually increasing number of patients seeking health insurance. Blockchain is an emerging technology and is constantly evolving to meet business needs. With its characteristics of immutability, transparency, traceability, and smart contracts, it demonstrates its potential in the health care domain. In particular, self-executable smart contracts are essential to reduce the costs associated with traditional paradigms, which are mostly manual, while preserving privacy and building trust among health care stakeholders, including the patient and the health insurance networks. However, with the proliferation of blockchain development platform options, selecting the right one for health care insurance can be difficult. This study addressed this void and developed an automated decision map recommender system to select the most effective blockchain platform for insurance fraud detection. OBJECTIVE: This study aims to develop smart contracts for detecting health care insurance fraud efficiently. Therefore, we provided a taxonomy of fraud scenarios and implemented their detection using a blockchain platform that was suitable for health care insurance fraud detection. To automatically and efficiently select the best platform, we proposed and implemented a decision map-based recommender system. For developing the decision-map, we proposed a taxonomy of 102 blockchain platforms. METHODS: We developed smart contracts for 12 fraud scenarios that we identified in the literature. We used the top 2 blockchain platforms selected by our proposed decision-making map-based recommender system, which is tailored for health care insurance fraud. The map used our taxonomy of 102 blockchain platforms classified according to their application domains. RESULTS: The recommender system demonstrated that Hyperledger Fabric was the best blockchain platform for identifying health care insurance fraud. We validated our recommender system by comparing the performance of the top 2 platforms selected by our system. The blockchain platform taxonomy that we created revealed that 59 blockchain platforms are suitable for all application domains, 25 are suitable for financial services, and 18 are suitable for various application domains. We implemented fraud detection based on smart contracts. CONCLUSIONS: Our decision map recommender system, which was based on our proposed taxonomy of 102 platforms, automatically selected the top 2 platforms, which were Hyperledger Fabric and Neo, for the implementation of health care insurance fraud detection. Our performance evaluation of the 2 platforms indicated that Fabric surpassed Neo in all performance metrics, as depicted by our recommender system. We provided an implementation of fraud detection based on smart contracts.

Open access
2 source records
Imbalanced Data Classification Techniques
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare
Original source
Jun 20, 2024·Sensors
23 cites
Ethereum Phishing Scam Detection Based on Data Augmentation Method and Hybrid Graph Neural Network Model

Zhe Chen, Sheng-Zheng Liu, Jia Huang, Yu-Han Xiu · 6 authors

The rapid advancement of blockchain technology has fueled the prosperity of the cryptocurrency market. Unfortunately, it has also facilitated certain criminal activities, particularly the increasing issue of phishing scams on blockchain platforms such as Ethereum. Consequently, developing an efficient phishing detection system is critical for ensuring the security and reliability of cryptocurrency transactions. However, existing methods have shortcomings in dealing with sample imbalance and effective feature extraction. To address these issues, this study proposes an Ethereum phishing scam detection method based on DA-HGNN (Data Augmentation Method and Hybrid Graph Neural Network Model), validated by real Ethereum datasets to prove its effectiveness. Initially, basic node features consisting of 11 attributes were designed. This study applied a sliding window sampling method based on node transactions for data augmentation. Since phishing nodes often initiate numerous transactions, the augmented samples tended to balance. Subsequently, the Temporal Features Extraction Module employed Conv1D (One-Dimensional Convolutional neural network) and GRU-MHA (GRU-Multi-Head Attention) models to uncover intrinsic relationships between features from the time sequences and to mine adequate local features, culminating in the extraction of temporal features. The GAE (Graph Autoencoder) concept was then leveraged, with SAGEConv (Graph SAGE Convolution) as the encoder. In the SAGEConv reconstruction module, by reconstructing the relationships between transaction graph nodes, the structural features of the nodes were learned, obtaining reconstructed node embedding representations. Ultimately, phishing fraud nodes were further identified by integrating temporal features, basic features, and embedding representations. A real Ethereum dataset was collected for evaluation, and the DA-HGNN model achieved an AUC-ROC (Area Under the Receiver Operating Characteristic Curve) of 0.994, a Recall of 0.995, and an F1-score of 0.994, outperforming existing methods and baseline models.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Imbalanced Data Classification Techniques
Original source
Jun 14, 2024·IEEE Transactions on Software Engineering
5 cites
SmartOracle: Generating Smart Contract Oracle via Fine-Grained Invariant Detection

Jianzhong Su, Jiachi Chen, Zhiyuan Fang, Xingwei Lin · 6 authors

As decentralized applications (DApps) proliferate, the increased complexity and usage of smart contracts have heightened their susceptibility to security incidents and financial losses. Although various vulnerability detection tools have been developed to mitigate these issues, they often suffer poor performance in detecting vulnerabilities, as they either rely on simplistic and general-purpose oracles that may be inadequate for vulnerability detection, or require user-specified oracles, which are labor-intensive to create. In this paper, we introduce SmartOracle, a dynamic invariant detector that automatically generates fine-grained invariants as application-specific oracles for vulnerability detection. From historical transactions, SmartOracle uses pattern-based detection and advanced inference to construct comprehensive properties, and mines multi-layer likely invariants to accommodate the complicated contract functionalities. After that, SmartOracle identifies smart contract vulnerabilities by hunting the violated invariants in new transactions. In the field of invariant detection, SmartOracle detects 50% more ERC20 invariants than existing dynamic invariant detection and achieves 96% precision rate. Furthermore, we build a dataset that contains vulnerable contracts from real-world security incidents. SmartOracle successfully detects 466 abnormal transactions with an acceptable precision rate 96%, involving 31 vulnerable contracts. The experimental results demonstrate its effectiveness in detecting smart contract vulnerabilities, especially those related to complicated contract functionalities.

Open access
3 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
cs.SE
Original source