The rapid development of blockchain has given rise to smart contracts that challenge traditional legal doctrine, even though the technology is crucial to supporting SDGs (Sustainable Development Goals) 9 and 16. Purpose: This study aims to analyze smart contract governance in Indonesia, Malaysia, and Thailand to support the achievement of the SDGs in the region. Method: A normative-comparative legal method is used with a socio-legal approach. This study examines the synchronization of regulations and the socio-institutional impacts. Results: The validity of smart contracts in the three countries is interpretative due to the lack of specific regulations. The self-executing and immutable nature triggers doctrinal tensions related to agreements and consumer protection, which are increased by the digital literacy gap. Conclusion: Smart contract governance in Southeast Asia requires an adaptive regulatory strategy that balances innovation and legal certainty. Suggestion: Authorities are expected to develop co-regulation-based regulations, strengthen digital institutions, and initiate regional legal standardization across ASEAN (Association of Southeast Nations). Contributions: The contribution is in the development of a blueprint for regional digital law harmonization that integrates aspects of dogmatic law with legal sociology. This study offers a model for ASEAN legal standardization that bridges technological innovation with social justice and provides indicators of institutional readiness replicated by developing countries in embracing an inclusive and sustainable digital economy.
Md. Safaet Hossain, Mohammad Shakibul Hasan Sakib, Md. Rayhan Ahmed Shis, Sakib Ahmed · 5 authors
Modern food supply chains, particularly those involving essential commodities like rice, often suffer from major challenges such as product fraud, inefficient record-keeping, and a lack of consumer trust. Traditional centralized systems are prone to data tampering, limited transparency, and poor traceability, making it difficult to verify the authenticity and origin of goods. To address these issues, our research introduces TraceRoot, a blockchain-based traceability framework designed to enhance transparency, accountability, and trust in agricultural supply chains.TraceRoot leverages the immutability and decentralization of blockchain technology to maintain a secure, distributed ledger that records every transaction and movement of goods across the supply chain. Each stakeholder including farmers, distributors, retailers, and consumers has role-based access to authenticated data through a user-friendly interface. The framework integrates smart contracts to automate transactions and digital signatures to verify the integrity of the data being uploaded, minimizing the risk of human error or manipulation
Smart contracts have attracted rapid development and widespread application. Due to the complexity of real-world smart contracts, it is error-prone to correctly enforce all intended functionalities in code implementations, resulting in unintended functional behaviors and security issues in practice. Code-comment inconsistency detection has emerged as an important solution to these issues, which leverages the redundant functional specifications in comments to detect code implementations that violate developers' intentions. However, existing inconsistency detection solutions are typically pattern-based and limited to fixed types of inconsistencies, which prevents them from detecting the diverse inconsistencies between real-world code implementations and casually written comments. To bridge the gap, this paper presents SmartComment, the first technique that combines LLMs with program analysis techniques for detecting code-comment inconsistencies in smart contracts. SmartComment introduces an LLM-driven workflow which simulates real-world interactions between code reviewers and developers to identify inconsistencies. It incorporates various program analysis techniques into the workflow, including comment propagation and code context extraction for generating input context for inconsistency detection, as well as program variant generation and differential analysis for inconsistency confirmation. Our evaluation results show that SmartComment detects 203 valid inconsistencies from a dataset of 1,000 real-world contracts with a precision of 79.9%, highlighting its effectiveness in detecting prevalent and diverse real-world inconsistencies. Compared to previous work, SmartComment achieves both higher precision and recall, detecting over 90% of inconsistencies that existing methods fail to identify. Furthermore, an ablation experiment demonstrates the effectiveness of incorporating program analysis techniques into SmartComment, improving the F1-score from 58.7% to 81.3%.
The global dairy industry confronts a persistent structural challenge in operationalising food safety and animal welfare compliance. Manual inspection regimes and intermittent audits are demonstrably inadequate for the heterogeneous, geographically dispersed landscape of small-scale farming, where data integrity, real-time monitoring capability, and regulatory transparency are simultaneously compromised. This article presents GreenDairyChain, an integrated compliance innovation framework that synthesises four enabling technologies: GreenEdgeML (a lightweight TinyML inference engine optimised for microcontroller-class devices), Privacy-Preserving Federated Learning (FL) with Graph Attention Network (GAT)-based dynamic clustering, Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge (ZK-SNARKs) for cryptographic compliance verification, and a Layer-2 Polygon zkEVM Blockchain with domain-specific smart contracts governing farm identity, violation detection, audit triggers, and licence management. GreenEdgeML executes multimodal sensor fusion across four signal modalities (body temperature, accelerometer activity, ammonia concentration, and milk pH) entirely on-device using 8-bit integer quantisation, consuming 64.6 KB RAM and 82.7 mW per inference cycle on the ESP32 platform. The FL engine employs GAT-based farm clustering with DBSCAN outlier exclusion to address non-IID data heterogeneity while maintaining Byzantine fault resilience. Compliance inferences are encoded as R1CS arithmetic circuits (14,240 constraints) and verified on-chain at O(1) cost through ZK-SNARK proofs generated in 1.25 seconds. Evaluated on the Shahhet28121 benchmark dataset across 16 biomarkers, the full system achieves 96.94% global classification accuracy, a 97.7% reduction in per-round communication payload (4.25 KB), and maintains classification accuracy above 90% under 20% Gaussian sensor noise. Ablation experiments confirm that each architectural component contributes independently to system performance. The findings carry implications for green business innovation, sustainable agriculture governance, and the design of trustworthy AI ecosystems in resource-constrained rural contexts.
Jianzhong Su, Mingxi Ye, Jiachi Chen, Yuhong Nan · 7 authors
With the rapid development of decentralized applications, many malicious actors exploit smart contract vulnerabilities for launching attacks. Moreover, as smart contracts utilize more state variables to support complex functionalities, some vulnerabilities require specific states to trigger (marked as vulnerable states), bringing new challenges to the vulnerability detection task. Although many smart contract fuzzers have been proposed for this task, they face limitations due to their inability to efficiently explore smart contract states. To address this challenge, we propose a novel fuzzer, Odyssey, with fine-grained state modeling and exploration, which increases the probability of reaching vulnerable states. We improve the efficacy of the fuzzer with two key mechanisms: (1) modeling an essential state space consisting of the variables related to sensitive operations to compress the exploration scope; (2) designing state-aware exploration strategies to identify test seeds that cover new state scope or cause new state transitions, to improve the efficiency of exploration. To evaluate the performance in vulnerability detection, we adopt Odyssey to a labeled benchmark consisting of 130 vulnerable contracts. Odyssey detects at least 70% more vulnerabilities than other fuzzers. Moreover, we evaluate Odyssey on a dataset that consists of 143 DApps (involving 437 contracts) from real-world security incidents. The experimental results demonstrate that state-aware feedback enhances the ability of Odyssey in state exploration by achieving 19% higher state coverage. Meanwhile, Odyssey totally finds 15 exploits of vulnerabilities from real-world attacks, showing its advantage in detecting real-world vulnerabilities.
Victoria Kovalenko, Sergii Sheludko, Elena Sergeeva
In the context of the unprecedented pace of digital transformation and the escalation of geopolitical risks, traditional methods of monetary regulation require a fundamental reconsideration. Problem statement. The evolution of cyber threats – from financial fraud to complex operations involving artificial intelligence – poses significant risks to macroeconomic stability. The development of an integrated protection system based on central bank digital currencies (CBDCs) and SupTech instruments constitutes a critical prerequisite for preserving financial sovereignty, particularly for Ukraine in the context of European integration and martial law. Unresolved aspects of the problem. The theoretical substantiation and development of practical recommendations for integrating advanced digital instruments (CBDC, artificial intelligence, distributed ledger technology (DLT), and SupTech) into monetary and prudential policy mechanisms in order to form a comprehensive cybersecurity framework for the financial sector remain insufficiently addressed. Purpose of the article. The purpose of this article is to provide a theoretical substantiation and to develop practical recommendations for integrating modern digital instruments (such as artificial intelligence, blockchain technologies, and SupTech) into monetary and prudential policy mechanisms in order to establish a comprehensive cybersecurity system for the financial sector. The study is grounded in a systemic approach to analysing the coordination of regulatory policies. The methodology includes comparative legal analysis (comparing the models of the e-hryvnia and the Digital Euro), structural and functional modelling (two-tier CBDC architecture), and scenario analysis to identify cyber risks (including DDoS attacks and smart contract vulnerabilities) and methods for their mitigation. Presentation of the main material. A model of hybrid coordination has been developed, in which cybersecurity is integrated directly into the mechanism of monetary transmission. It has been demonstrated that the programmability of the e-hryvnia and the application of Zero-Knowledge Proofs (ZKP) technologies enable the automation of prudential supervision while preserving user privacy. Global case studies (China, the European Union, and the Bahamas) have been analysed, and the specific features of the Ukrainian e-hryvnia project have been identified as instruments for enhancing transparency and cyber resilience. For the first time, it is proposed to consider a central bank digital currency not only as a means of payment but also as an active element of the cyber-prudential system, enabling the dynamic adjustment of liquidity and limits under conditions of real cyberattacks. The concept of convergence between SupTech and RegTech systems based on unified distributed ledgers has been further developed. The proposed architectural model and cyber-risk matrix may be utilised by the National Bank of Ukraine in the finalisation of the e-hryvnia project and in the development of digital operational resilience standards in accordance with the DORA regulation. Conclusions. It has been demonstrated that digitalisation transforms the regulator into an architect of a secure financial environment. Further research will focus on the interoperability of CBDCs across countries and the role of artificial intelligence in preventing manipulation in digital asset markets.
Open access
Digital Transformation in Financial Services
Legal, Health, Environmental and COVID-19 Challenges
Smart contracts underpin a wide range of decentralized applications—from financial services to supply-chain management—but their immutability and direct control of assets magnify the impact of any security bugs. Although many fuzz approaches have been proposed and have demonstrated their effectiveness in uncovering vulnerabilities, existing methods often rely on unguided random mutation scheduling, generate redundant inputs, and fail to adapt to smart contract-specific characteristics. To overcome these challenges, we present FuzzMaster, a feedback-driven fuzzing framework that combines deep reinforcement learning (DRL) with lightweight probabilistic scheduling to steer mutation selection at runtime intelligently. By continuously analyzing execution feedback—code coverage, function-call sequences, and vulnerability signals—FuzzMaster’s DRL agent and probabilistic tables prioritize high-impact mutations and avoid wasted effort on redundant seeds. On standard VeriSmart and SmartBugs benchmarks, FuzzMaster achieves a 66.2% detection rate with 100% precision (versus 46.9% for ItyFuzz and 43.1% for Confuzzius) and uncovers most bugs within the first second of execution. Meanwhile, in real-world Ethereum contracts, FuzzMaster identified 97 vulnerabilities in 6 categories. These results demonstrate that dynamic, vulnerability-aware mutation scheduling can dramatically improve both the efficiency and effectiveness of smart contract fuzz testing.
The rapid increase in distributed mobile e-learning systems has resulted in numerous security threats, including student data protection, secure access, transparency, and decentralized education management. Traditional cloud-based e-learning systems have been prone to various risks, such as centralization vulnerability, data access violations, identity theft, and lack of scalability in a highly variable wireless learning environment. This paper proposes a blockchain-integrated, privacy-preserving, distributed mobile e-learning architecture for securely and autonomously managing student data. In this framework, blockchain technology will be used for ensuring a decentralized ledger, lightweight cryptography, smart contract-based authentication, and distributed data storage. Blockchain transaction verification, data encryption and sharing, distributed data storage, and smart contract execution are the methodologies utilized by this system to ensure secure academic record and activity management in a mobile environment. The evaluation of the proposed architecture will involve performance measurement of the following parameters: authentication accuracy, privacy protection capability, transaction processing speed, throughput, and data storage efficiency. It was revealed from experimental studies that the suggested approach provided 98.3% in terms of identification, 97.5% in relation to data privacy protection, and 91.8% concerning storage efficiency compared to other methods, including traditional cloud-based learning systems and previous blockchain-based education platforms. In addition, the suggested system enabled reducing the transaction time to 190 ms and increasing the throughput speed up to 465 transactions per second, which proves its high efficiency and capability of functioning in a distributed wireless environment. Therefore, it can be stated that introducing blockchain technology in distributed mobile e-learning systems enhances the level of privacy, resilience against malicious attacks, traceability, and autonomy in controlling personal information. The introduced concept provides a basis for designing a highly reliable and scalable framework for the future generation of wireless educational communities based on the management of decentralized and reliable data.
Health care data management comes with numerous barriers as a result of the use of different systems of record keeping, which are not compatible and increase the risks for data protection and privacy. Medical records are frequently distributed throughout various clinics and hospitals, and due to this it is hard to share information when patients are being treated. Centralized record systems bring unauthorized access to records and the problems related to the safety of data. In order to enhance the level of confidence of people and improve the level of transparency of health care data, advanced people choose decentralized technologies and uses cryptography for these purposes. Blockchain technology offers an unchangeable and decentralized ledger that guarantees safe monitoring of all information despite the presence of any centralized body. Coupled with sophisticated encryption methods, it provides the ability to limit access to private health information. In order to provide secure and respect privacy regarding medical data sharing, an Electronic Health Record (EHR) system powered by blockchain technologies is proposed. Patient record metadata is recorded on-chain while health data itself is stored on encrypted off-chain storage. In the realm of access management, smart contracts facilitate patients in designating by whom their records can be accessed and modified. The privacy of information is further strengthened by advanced cryptographic techniques like attribute-based encryption and zero-knowledge proofs. The system provides seamless interoperability among hospitals, laboratories, and telemedicine systems while ensuring high levels of security. The results of performance evaluation demonstrate that this method facilitates reliable transaction processing while providing better security, transparency and control than traditional centralized EHR systems.
Smart contracts have achieved significant success, however, their security remains a long-standing challenge. The immutability and transparency of smart contracts require establishing a strong mechanism to prevent private leakage and trusted data tampering. Apart from traditional logic and code-level vulnerabilities arising from insufficient control over contract variables and function parameters, smart contracts may store private-dependent information in blockchain records, which is a critical type of vulnerability, but often overlooked in existing security analysis. In this paper, we present an automated approach for synthesizing security policies, named SmartIFSyn, to eliminate information flow vulnerabilities in smart contracts. We formalize the semantics of Solidity, the most widely used smart contract language, and analyze information flow security of Solidity smart contracts from two perspectives: local-variable security and global-interaction security. We present a type system to guide the elimination of local-variable vulnerabilities by inferring a policy and resort to constraint solving to synthesize a desired policy in case that the type system fails. The policy ensures both local-variable and global-interaction security while it is maximally aligned with user preference. Furthermore, the policy can be subsequently converted into enforceable specifications. We implement our approach in a tool and evaluate it on 17,160 real-world Ethereum smart contracts. The experimental results demonstrate the efficacy of our approach, e.g., detected 243 vulnerabilities in 223 real-world Ethereum smart contracts.
Lei Yu, Jingyuan Zhang, Xin Wang, Li Yang · 6 authors
Smart contracts automate the management of high-value assets, where vulnerabilities can lead to catastrophic financial losses. In the task of automated smart contract generation using Large Language Models (LLMs), this challenge is amplified by two interconnected failures: first, they operate as unauditable "black boxes" by failing to produce a transparent reasoning process, and second, as a consequence, they generate code riddled with critical security vulnerabilities. To address both issues, we propose SmartCoder-R1 based on Qwen2.5-Coder-7B, a novel framework for secure and explainable smart contract generation. It begins with Continual Pre-training (CPT) to specialize the base model on the nuances of smart contract code. To construct the data for subsequent stages, we first prompt the DeepSeek model to generate reasoning-and-code samples from verified on-chain contracts, followed by a rigorous validation process where each sample is manually reviewed by security experts for compilability, functionality, security, and reasoning completeness. Based on this, we then apply Long Chain-of-Thought Supervised Fine-Tuning (L-CoT SFT) on 7,998 of these expert-validated samples to train the model to emulate human security analysis. Finally, to directly mitigate vulnerabilities, we employ Security-Aware Group Relative Policy Optimization (S-GRPO), a reinforcement learning phase that refines the generation policy using 1,691 samples by optimizing a weighted reward signal for compilation success, security compliance, and format correctness. Evaluated against 18 state-of-the-art baselines on a challenging benchmark of 756 real-world functions from 289 deployed contracts, SmartCoder-R1 establishes a new state of the art by achieving top performance across five key metrics: a ComPass of 87.70%, a VulRate of 8.60%, a SafeAval of 80.16%, a FuncRate of 53.84%, and a FullRate of 50.53%. This FullRate marks a 45.79% relative improvement over the strongest baseline, DeepSeek-R1. Crucially, its generated reasoning also excels in human evaluations, achieving high-quality ratings for Functionality (82.7%), Security (85.3%), and Clarity (90.7%).
We present SmarTrim, a new symbolic execution technique for detecting vulnerabilities in smart contracts. Smart contracts require rigorous safety validation since flaws in them can cause significant financial loss. Numerous symbolic execution techniques, which generate vulnerable transaction sequences to trigger and help understand vulnerabilities, have been extensively studied to enhance the security and safety of smart contracts. However, their performance remains unsatisfactory due to the extremely large search space for transaction sequences. To mitigate this issue, SmarTrim introduces a novel technique that safely reduces the search space by detecting and pruning redundant transaction sequences. Experimental results show that SmarTrim greatly outperforms eleven state-of-the-art analyzers in detecting critical vulnerabilities in real-world smart contracts.
Inundating networks with traffic to cripple service availability defines a DDoS attack. Traditional defences, like firewalls and centralized scrubbing centers, can suffer from single points of failure during large-scale attacks. Enter new blockchain technology, with Ethereum probably leading the way in decentralized solutions. Since Ethereum smart contracts enable DDoS detection and enforcement of validation rules, events can be managed automatically, applying rewards or penalties without a central authority. In this way it leverages the positive aspects of crypto-economic mechanisms and reputation systems; giving people an incentive to honestly participate while making abusing the system unprofitable, creating a trustless, transparent, resilient decentralized defence against cyber threats. The architecture of a blockchain-validated system that gates access to services includes a back-end gateway responsible for verifying transactions on the blockchain before processing user queries. The off-chain detection algorithm identifies unexpected traffic spikes that exceed a predefined threshold. Attackers were deterred by cost, the system itself stayed up and running, and the smart contract worked autonomously. The suggested approach maintained 96% access success for authorized users, successfully blocked 92% of DDoS traffic, and guaranteed 98% uptime during simulated attacks. All validated access attempts were 100% immutably recorded on-chain, and attackers had to pay 300% more employs transparent on-chain rules and Ethereum smart contracts to manage access. Because every access attempt is permanently documented on the blockchain, it is difficult to alter logs or stop denial-of-service attacks without detection.
Andika Pratama, Dewi Nur Lestari, Bambang Hartono, Sri Wahyuni · 5 authors
Modern bioinformatics has entered a multi-omics era in which genomic, transcriptomic, proteomic, and metabolomic datasets accumulate at unprecedented velocity, volume, and variety. Conventional centralized governance — institutional databases protected by role-based access control — struggles with single points of failure, opaque consent enforcement, weak provenance, and brittle interoperability across jurisdictions. Blockchain technology has been proposed as an alternative substrate for trustworthy multi-omics data sharing, but the literature remains fragmented across isolated mechanisms (immutability, smart contracts, on-chain storage) without a coherent system view. This article systematically reviews 82 peer-reviewed studies published between 2017 and 2025, indexed in Scopus, IEEE Xplore, ScienceDirect, SpringerLink, and the ACM Digital Library, using a five-stage screening protocol and a five-question quality assessment rubric. Building on the synthesis, we propose a six-layer architectural framework that combines a permissioned blockchain ledger, smart-contract-based consent and access control, privacy-preserving cryptography (zero-knowledge proofs, homomorphic encryption, differential privacy), decentralized identity, off-chain storage on the InterPlanetary File System, and native interoperability with HL7 FHIR-compliant electronic health records. A multi-criterion comparison shows that Practical Byzantine Fault Tolerance is best suited to the latency, throughput, and energy constraints of multi-omics workflows, outperforming Proof-of-Work and Proof-of-Stake on five of six evaluation dimensions. Compared with traditional security baselines, blockchain delivers measurable advantages in tamper-resistance, provenance, and patient-centric consent, but does not universally dominate on confidentiality and scalability. The framework offers a practical roadmap for big-data governance in life-science research while highlighting open problems in standardization, regulatory alignment, and energy efficiency.
Decentralized finance systems manage vast assets without central authority, creating a borderless economy that defies traditional legal boundaries. While fostering innovation, this independence invites global criminal activities, as perpetrators exploit automated, anonymous smart contracts to evade detection. Current international legal frameworks remain ill-equipped to address the complexities of cross-border digital fraud or assign liability within immutable, machine-run protocols. This research examines the jurisdictional conflicts and attribution challenges inherent in decentralized financial systems. Utilizing a qualitative doctrinal analysis of recent legislative initiatives and international legal standards, this article evaluates the viability of a functional equivalence model for assigning criminal responsibility. The findings suggest that harmonizing global regulatory requirements is essential to bridge the gap between technical execution and legal accountability. This study proposes a framework that integrates human-led dispute resolution with automated transparency to ensure stability, protect market participants, and foster long-term confidence in the global digital economy.
As blockchain technology and smart contracts gain widespread adoption, ensuring their security is essential to prevent financial and operational risks. Detecting vulnerabilities in smart contracts using automated techniques provides a reliable and scalable solution. This study utilizes the Smart Contract Vulnerabilities Dataset from Kaggle, containing annotated smart contracts with labeled vulnerabilities. Preprocessing includes tokenization and exploratory data analysis to extract meaningful textual patterns. Deep learning models such as LSTM and BERT are trained and evaluated using accuracy, precision, recall, and F1-score. To further improve detection performance, BERT embeddings are combined with BiLSTM and CNN + LSTM architectures. A Flask-based user interface enables real-time vulnerability prediction. Experimental results show that the CNN + LSTM model outperforms all other models, achieving 95 percent accuracy and demonstrating strong capability in identifying smart contract vulnerabilities.
Healthcare supply chains face increasing challenges related to counterfeit products, fragmented information flows, limited traceability, and insufficient coordination among distributed stakeholders.Existing centralized and partially decentralized approaches still encounter difficulties in maintaining immutable records, real-time verification, and trusted operational transparency across the pharmaceutical distribution process.This study investigates a distributed medical supply chain framework that improves traceability, compliance control, and operational reliability in healthcare logistics.A blockchain-enabled architecture was developed by integrating dynamic quick response (QR)-based identification, customizable smart contracts, and a hybrid consensus mechanism combining Proof-of-Work (PoW) and Proof-of-Stake (PoS).The framework assigned a unique cryptographic identity to each medicine unit and supported end-to-end verification through blockchain-linked QR validation.Smart contracts were designed to automate ownership transfer, compliance checking, and counterfeit detection throughout the supply chain workflow.The framework was implemented and evaluated in a simulated distributed environment using pharmaceutical transaction scenarios.The experimental results showed that the proposed approach achieved average validation accuracy of approximately 98.1%, maintained transaction throughput between 150 and 320 transactions per second (TPS), and reduced consensus delay through adaptive PoW-PoS coordination.The system also demonstrated strong resistance to forgery attempts and stable operational performance across repeated validation experiments.The results indicate that integrating blockchain governance mechanisms with QR-enabled authentication can improve transparency, trust, and traceability in distributed healthcare supply chains.The proposed framework provides a scalable systems engineering solution for pharmaceutical logistics management and offers a practical foundation for compliance-oriented digital transformation in healthcare supply networks.
Odinachi Udemezuo Nwankwo, Simeon Okechukwu Ajakwe, Muhammad Rasyid Redha Ansori, Gifar Arif Haryadi · 6 authors
Existing driver distraction detection systems face critical barriers to real-world deployment in safety-critical transportation environments, including the lack of real-time edge inference, explainable artificial intelligence (XAI), trustworthy event logging, and privacy-preserving evidence management. To overcome these challenges, this paper presents an integrated framework, termed DRIVERDAPP , that unifies real-time edge-based detection, AI explainability, and secure, auditable event management. Red–green–blue (RGB) in-cabin image frames captured by a dashboard camera are processed locally on an NVIDIA Jetson Nano edge device, where a fine-tuned You Only Look Once version 11 small (YOLOv11s) model classifies ten driver behavior states and triggers in-vehicle audio alerts for unsafe activities. To suppress transient misclassifications under edge constraints, distraction persistence is verified using a lightweight temporal confirmation strategy. Confirmed distraction events are immutably recorded via Solidity-based smart contracts and submitted through the Web3.py interface to a permissioned Hyperledger Besu consortium blockchain operating under Quorum Byzantine Fault Tolerance (QBFT) consensus. Privacy is preserved by retaining raw visual data off-chain, while only pseudo-anonymous identifiers and event metadata are stored on-chain under controlled access policies. Model interpretability is enabled using Gradient-weighted Class Activation Mapping (Grad-CAM), providing transparent visual explanations of distraction-related predictions. The framework is evaluated using the State Farm Distracted Driver and American University in Cairo datasets, demonstrating stable real-time edge operation, negligible blockchain query latency, and secure smart contract execution. These results confirm the suitability of DRIVERDAPP for secure, explainable, and deployable driver monitoring in intelligent transportation systems.
Blockchain technology and smart contracts are profoundly reshaping contract law by partially replacing traditional legal rules with algorithmic norms based on automation and self-execution. By embedding the parties' agreement into computer code deployed on a distributed ledger, these technologies promise enhanced security, certainty of performance, and the reduction of traditional intermediaries. However, this emerging algorithmic normativity confronts fundamental requirements of contract law, particularly those relating to validity, flexibility in the face of unforeseen events, and the protection of contracting parties. While automatic execution strengthens technical efficiency, it also exposes significant legal limitations, including the rigidity of code, the absence of interpretative mechanisms, and the difficulty of integrating traditional corrective tools. This article therefore highlights the need for an appropriate legal framework capable of reconciling legal norms with algorithmic rules, ensuring that technological innovation contributes to, rather than undermines, legal certainty in contractual relations.
Hüseyin Ahmet Cemil Özaslan, Şafak Durukan-Odabaşı
Smart contracts have become a fundamental component of blockchain ecosystems, and their reliability is strongly shaped by the programming languages in which they are written. While prior studies have classified vulnerabilities, fewer have quantitatively examined how language design and secure coding practices affect performance and resilience. To address this gap, this study empirically compares Solidity and Vyper under controlled conditions and complements these experiments with a literature-based evaluation of Rust and Move. Test scenarios included deployment, deposits, withdrawals, arithmetic overflow, reentrancy, and transaction origin misuse. For both vulnerable and secure variants in Solidity and Vyper, metrics such as gas consumption, deployment size, and runtime execution time were collected. The results indicate that deployment costs differ substantially between the two languages (Solidity ≈ 177 k gas vs Vyper ≈ 135 k gas, ~24% lower), whereas runtime performance is mixed: deposit calls are nearly identical (Δ ≈ 0.02 ms), whereas withdraw shows a noticeable gap (Δ ≈ 4.97 ms) favoring Vyper; nevertheless, these call-level differences remain small relative to the larger deployment-time gap. Importantly, secure coding practices such as explicit arithmetic checks and the Checks–Effects–Interactions pattern eliminate critical vulnerabilities while adding less than 1% to the overall execution cost. Although Rust and Move are considered through a literature-based review, they illustrate alternative approaches that embed security guarantees directly into the language. Based on these observations, this study proposes a measurable framework to understand how different smart contract programming languages vary in terms of security and efficiency, emphasizing the role of language design and secure coding practices in shaping contract development.
Yaiza Cabedo, Tommaso Mancini-Griffoli, Fabian Schär, Nicolas Zhang
This paper examines how tokenization and distributed ledger technology may transform Financial Market Infrastructures (FMIs) by enabling smart contracts to perform a growing share of functions traditionally undertaken by central securities depositories, central counterparties, and trade repositories. It argues that while record-keeping, settlement, collateral management, and reporting can increasingly be executed on-chain, key functions requiring legal certainty, governance, accountability, and discretion remain institutional in nature. The analysis assesses which activities across issuance, clearing, settlement, and reporting can migrate to code, where limitations persist, and how risks evolve in tokenized environments. It finds that tokenization is more likely to reconfigure than eliminate FMIs, creating new efficiencies while introducing novel operational and governance risks. The most plausible outcome is a hybrid FMI model in which technology and institutions jointly provide the trust, resilience, and oversight required for financial stability.
Arwen Dewi Ferlang Anna, Angela Gracia Anna, Nandang Kusnadi
Perkembangan teknologi digital telah mendorong perubahan dalam praktik kontrak, salah satunya dengan adanya penggunaan kontrak pintar yang didasarkan pada teknologi blockchain. Kontrak pintar muncul sebagai bentuk kesepakatan modern yang dapat melaksanakan ketentuan kontrak secara otomatis tanpa perlu intervensi dari pihak ketiga. Munculnya teknologi ini menimbulkan berbagai isu hukum, terutama mengenai status, legitimasi, dan kekuatan mengikatnya dalam sistem hukum kontrak baik di tingkat nasional maupun internasional. Untuk itu, penelitian ini bertujuan untuk mengevaluasi keberadaan kontrak pintar sebagai bentuk perjanjian modern serta meneliti kesesuaiannya dengan prinsip-prinsip hukum kontrak yang berlaku di kedua tingkatan tersebut. Studi ini memanfaatkan metode penelitian hukum normatif dengan pendekatan undang-undang, konsep, dan perbandingan. Sumber hukum yang dianalisis mencakup berbagai regulasi, instrumen hukum internasional, literatur terkait hukum, serta hasil penelitian yang relevan dengan kemajuan teknologi kontrak digital. Penelitian dilakukan dengan analisis kualitatif untuk menilai implementasi elemen-elemen perjanjian dalam kontrak pintar serta tantangan yang dihadapi dalam praktik antar negara. Hasil penelitian menunjukkan bahwa kontrak pintar pada dasarnya mampu memenuhi syarat-syarat sahnya perjanjian seperti yang ditetapkan dalam hukum kontrak nasional, selama terdapat kesepakatan antara pihak-pihak yang terlibat, kemampuan hukum, objek yang jelas, dan alasan yang sah. Di tingkat internasional, keberadaan kontrak pintar juga semakin diakui melalui berbagai regulasi dan pedoman terkait transaksi daring, meskipun belum ada pengaturan standar yang diterapkan di semua negara. Selain menyediakan efisiensi, transparansi, dan keamanan dalam pelaksanaan kontrak, kontrak pintar juga menghadapi tantangan terkait yurisdiksi, penyelesaian sengketa, perlindungan konsumen, dan kepastian hukum terhadap kode perangkat lunak yang berfungsi sebagai alat kontraktual.
Il contributo analizza il processo di piattaformizzazione della pubblica amministrazione, evidenziando come l’adozione di infrastrutture digitali avanzate rappresenti non soltanto una sfida tecnologica, ma anche un’occasione per ridefinire il rapporto tra Stato, cittadini e imprese. L’Autrice esamina il ruolo delle piattaforme pubbliche nella semplificazione dell’azione amministrativa, nella digitalizzazione dei servizi e nella costruzione di un’amministrazione più efficiente, accessibile e trasparente. Particolare attenzione è dedicata al concetto di fiducia digitale, intesa come dimensione ulteriore rispetto alla mera sicurezza informatica, fondata su trasparenza, protezione dei dati, responsabilità istituzionale e tutela dei diritti fondamentali. Il saggio approfondisce poi l’impatto delle piattaforme digitali nel settore degli appalti pubblici, con riferimento all’e-procurement, alla Banca Dati Nazionale dei Contratti Pubblici, alle Piattaforme di Approvvigionamento Digitale, al Fascicolo Virtuale dell’Operatore Economico e alla Piattaforma Unica della Trasparenza. Vengono inoltre esaminate le potenzialità del Web3, della blockchain e degli smart contracts nelle procedure di gara, con particolare riguardo alla tracciabilità , alla prevenzione della corruzione e alla verificabilità delle garanzie. Il contributo conclude evidenziando che la trasformazione digitale della pubblica amministrazione richiede ecosistemi resilienti, interoperabili e sicuri, capaci di rafforzare la fiducia dei cittadini nell’amministrazione digitale. The contribution analyses the platformisation of public administration, highlighting how the adoption of advanced digital infrastructures is not only a technological challenge, but also an opportunity to redefine the relationship between the State, citizens and businesses. The Author examines the role of public platforms in simplifying administrative action, digitising services and building a more efficient, accessible and transparent administration. Particular attention is devoted to the concept of digital trust, understood as a dimension that goes beyond cybersecurity, based on transparency, data protection, institutional responsibility and the safeguarding of fundamental rights. The essay then explores the impact of digital platforms in the field of public procurement, with reference to e-procurement, the National Public Contracts Database, Digital Procurement Platforms, the Virtual Company Dossier and the Single Transparency Platform. It also examines the potential of Web3, blockchain and smart contracts in tender procedures, particularly with regard to traceability, corruption prevention and the verification of guarantees. The contribution concludes by emphasizing that the digital transformation of public administration requires resilient, interoperable and secure ecosystems, capable of strengthening citizens’ trust in digital administration.
This paper develops a document management system model intended for environments in which the integrity of document history, control of the document lifecycle, and the possibility of independent verification of performed operations are critically important. The relevance of the study is determined by the fact that traditional electronic document management systems mainly rely on centralized event logs and application logic, which does not eliminate the risks of retrospective modification of document history and a reduction in its evidential value. The aim of the work is to construct a document management system model in which the integrity of document history is ensured through a cryptographically verifiable chain of document states and the recording of evidential event attributes in a permissioned distributed ledger. The proposed model combines architectural and formal levels of system representation. At the architectural level, the user, application, evidential, and content layers are distinguished. At the formal level, a document is represented as a sequence of cryptographically linked states, in which each new state contains the state hash, metadata, timestamp, content hash, and a reference to the previous state, thus ensuring the integrity and traceability of the entire document history. To implement the evidential layer, a smart contract for registering document states and a permissioned distributed ledger based on Hyperledger Besu are used. Experimental validation of the model was carried out on a local testbed using the QBFT consensus mechanism, external storage, and software modules for generating and fully verifying document history. The experimental results confirmed the ability of the model to detect retrospective changes in content, metadata, signatures, and temporal attributes, to localize the first compromised state, and to provide near-linear growth in full verification time as the length of the state chain increases. Comparative evaluation against centralized logging demonstrated the advantage of the proposed approach in terms of tamper detection, localization of violations, and independent verifiability of results. The practical significance of the work lies in the possibility of using the proposed model as a basis for building corporate document management systems.