This study explores the information security strategy in digital currency and decentralized international trade from the theoretical and application levels. This strategy can solve the application layer security issues of blockchain technology in cross-border trade. This study proposes a blockchain-based digital currency security improvement framework by combining model analysis with actual needs. The research method includes the improvement of evolutionary game analysis of 51 % double-spending attack, the response strategy of complex double-spending attack and the privacy protection mechanism based on zero-knowledge proof. This fusion gap framework can improve the security of model to the greatest extent. The experimental results numerically show that by reasonably setting the number of transaction confirmations ($M$value), the success rate of double-spending attacks can be significantly reduced. Specifically, when$M=6$, the attack success rate drops to 0.21 %. In addition, the zero-knowledge proof encryption scheme performs well in privacy protection experiments. The accuracy of experimental results has been remained above 99.35 %, and with highest reaching 99.83 %. This result is better than the traditional homomorphic encryption and cipher-text encryption methods.
Ensuring consistent progress toward cities’ net-zero emission goals requires understanding key dimensions of urban climate governance—particularly the motivations driving municipalities toward net zero and the critical barriers and enablers along this pathway. Current knowledge on these critical aspects is fragmented, lacking a holistic framework and empirical prioritization of key factors. We developed an integrated analytical framework and empirically distilled the most salient motivations, barriers, and enablers through a large-scale survey targeting 489 net-zero-committed municipalities—known as “Zero Carbon Cities”—across Japan. With responses from 309 municipalities, we deliver the first systematic mapping of factors perceived as most influential by Japanese local authorities. The results indicate that municipalities are primarily motivated by seizing local economic development opportunities (enhanced local energy conditions, financial gains and savings, and local industry revitalization), future-proofing communities against disasters, and enhancing the local quality of life. Key barriers and enablers were identified across four categories: municipal resources and authority (budgets, dedicated staff, and empowered climate agencies), knowledge and expertise (staff climate competence), institutional coherence (cross-departmental coordination and stakeholder involvement), and political will and leadership (the presence of climate champions and awareness within city halls and among residents). Accordingly, we discuss implications and derive recommendations toward strengthened local action in Japan and beyond.
As privacy and security concerns increase, Zero Knowledge Proof (ZKP) technology offers a promising solution for secure digital verification. ZKP addresses key privacy and security challenges across individual, business, and public sectors by enabling data protection without revealing sensitive information. The aim of this study is to analyse ZKP’s application areas by reviewing current literature and case studies, examining its strengths, limitations, and potential risks. Findings highlight the capability of ZKP to enhance privacy, security, and verification processes across various fields, including blockchain technology, identity authentication, secure data sharing, and digital voting systems. The paper provides a balanced perspective on ZKP’s benefits and challenges, including computational complexity and scalability issues. By suggesting practical use cases, this work aims to contribute to a deeper understanding of how ZKP technology can support innovation across various industries while addressing critical privacy and security needs.
Daniël Reijsbergen, Eyasu Getahun Chekole, Howard Halim, Jianying Zhou
Biometric authentication relies on physiological or behavioral traits that are inherent to a user, making them difficult to lose, forge or forget. Biometric data with a temporal component enable the following authentication protocol: recent readings of the underlying biometrics are encoded as time series and compared to a set of base readings. If the distance between the new readings and the base readings falls within an acceptable threshold, then the user is successfully authenticated. Various methods exist for comparing time series data, such as Dynamic Time Warping (DTW) and the Time Warp Edit Distance (TWED), each offering advantages and drawbacks depending on the context. Moreover, many of these techniques do not inherently preserve privacy, which is a critical consideration in biometric authentication due to the complexity of resetting biometric credentials. In this work, we propose ZK-SERIES to provide privacy and efficiency to a broad spectrum of time series-based authentication protocols. ZK-SERIES uses the same building blocks, i.e., zero-knowledge multiplication proofs and efficiently batched range proofs, to ensure consistency across all protocols. Furthermore, it is optimized for compatibility with low-capacity devices such as smartphones. To assess the effectiveness of our proposed technique, we primarily focus on two case studies for biometric authentication: shake-based and blow-based authentication. To demonstrate ZK-SERIES's practical applicability even in older and less powerful smartphones, we conduct experiments on a 5-year-old low-spec smartphone using real data for two case studies alongside scalability assessments using artificial data. Our experimental results indicate that the privacy-preserving authentication protocol can be completed within 1.3 seconds on older devices.
In a time of rising cyber threats and widespread digital communication, protecting sensitive information is crucial. This paper offers a detailed survey and analysis of current methods in secure communication, focusing on the relationship between cryptographic systems and steganographic techniques. We base our work on foundational mathematics, especially commutative algebra, and use modern technologies like Generative Adversarial Networks (GANs), zero-knowledge proofs, and quantum-resistant algorithms. We present a layered approach to information security. We discuss how combining classical and modern cryptography with improved steganographic embedding and signal processing techniques highlights the need for hybrid and adaptable models to protect communication. This study aims to be a reference point for future research and development in secure digital systems. Key Words: Cryptography : from classical to post-quantum, Steganography and Data hiding Techniques, GAN-Based Steganography in wireless sensor network , Methodology Overview.
Machine learning providers commonly distribute global models to edge devices, which subsequently personalize these models using local data. However, issues such as copyright infringements, biases, or regulatory requirements may require the verifiable removal of certain data samples across all edge devices. Ensuring that edge devices correctly execute such unlearning operations is critical to maintaining integrity. In this work, we introduce a verification framework leveraging zero-knowledge proofs, specifically zk-SNARKs, to confirm data unlearning on personalized edge-device models without compromising privacy. We have developed algorithms explicitly designed to facilitate unlearning operations that are compatible with efficient zk-SNARK proof generation, ensuring minimal computational and memory overhead suitable for constrained edge environments. Furthermore, our approach carefully preserves personalized enhancements on edge devices, maintaining model performance post-unlearning. Our results affirm the practicality and effectiveness of this verification framework, demonstrating verifiable unlearning with minimal degradation in personalization-induced performance improvements. Our methodology ensures verifiable, privacy-preserving, and effective machine unlearning across edge devices.
Open access
2 source records
cs.LG
cs.CR
Intelligent Tutoring Systems and Adaptive Learning
Cinthia Paola Pascual Cáceres, José Vicente Berná-Martínez, María Esther Almaral Martínez, Lucía Arnau Muñoz
This study introduces Fort2BCK, an advanced security framework designed to mitigate critical vulnerabilities in healthcare blockchain implementation, specifically data manipulation, unauthorised access and weaknesses in consensus protocols. Fort2BCK employs a dual verification mechanism, combining native consensus algorithm validation with the application of advanced cryptographic signatures (RSA, ECDSA and zero knowledge proofs, ZKPs), thus providing an additional layer of authentication, auditing and resistance to malicious attacks. In contrast to traditional approaches, Fort2BCK significantly reduces the risks of fraud and forgery by independently cryptographically verifying each block before it is integrated into the blockchain, strengthening security in scenarios where conventional consensus models may be vulnerable. In addition, its interoperability with multiple blockchain architectures, including proof of work (PoW), proof of stake (PoS) and delegated proof of stake (DPoS), allows it to effectively mitigate attacks such as the 51% attack in PoW and the nothing-at-stake problem in PoS, through an integrated external validation layer. To evaluate the effectiveness of Fort2BCK, experiments were conducted on a simulated hybrid blockchain network with 100 nodes and 50,000 transactions. The results revealed that Fort2BCK increases security by 35% against block rewrite attacks and decreases the rate of fraudulent transactions by 42%, compared to conventional blockchain systems, while maintaining a computational overhead of less than 8%. Additionally, Fort2BCK ensures compliance with regulations such as HIPAA and GDPR, ensuring that blockchain systems for the healthcare sector meet legal and privacy requirements. These findings demonstrate that Fort2BCK optimises the security, scalability and privacy of medical blockchains, facilitating the secure digitisation of healthcare systems and strengthening trust in clinical data management.
Amid the rapid development of e-commerce and logistics, enterprises urgently require advanced digital technologies to achieve modernization and intelligent transformation, thereby meeting the fast-changing market demands. Within the logistics Internet of Things (IoT), companies face numerous scenarios that necessitate quantifying the degree of data overlap, where only acquiring statistical information suffices. The Private Set Intersection Cardinality (PSI-CA) technology offers an almost ideal solution. However, an effective approach must not only safeguard privacy but also enable companies to demonstrate their data protection capabilities to consumers. Existing PSI-CA solutions neglect the sustainable development needs of enterprises in terms of data correctness, integrity, management transparency, and user retention. Therefore, this paper proposes, for the first time, a trackable and verifiable authorized cloud-assisted PSI-CA (TVACPSI-CA) protocol, upon which a multi-threaded intelligent logistics system (ILS) is designed to harmonize data privacy protection with operational efficiency in logistics enterprises. The protocol employs accumulators, oblivious pseudorandom function (OPRF), zero-knowledge proof, digital signatures and blockchain technology to achieve objectives such as data privacy protection, access control, correctness verification of delegated computation, data integrity protection, abuse resistance, and traceability. This facilitates enterprises in mitigating security risks and enhancing customer trust. We rigorously analyze and prove the security of our solution. Finally, a comparative analysis with existing approaches demonstrates that the proposed scheme balances between high security and low communication/computational overhead. This provides the logistics industry with a secure, efficient, and scalable data-sharing solution, thereby enabling operational optimization.
Federated Learning (FL) offers an attractive framework for collaboratively training AI models while preserving data privacy. However, it also introduces challenges in verifying the integrity and authenticity of model updates across diverse clients. Zero-Knowledge Proofs (ZKP) provide a promising means to address these issues by verifying computations without revealing underlying data. Yet, global verification using ZKP remains computationally expensive and does not scale well. To overcome these limitations, we propose a novel approach grounded in two key principles: (a) partial verification, targeting carefully selected subsets of data, can effectively mitigate adversarial attacks; and (b) robust data verification is essential, ensuring not only the consistency of model parameters but also the authenticity of the underlying data. We highlight the potential operation of this partial verification system, discuss novel research directions, and outline strategies for a wider integration into FL architectures.
Merkle Tree is a fundamental cryptographic primitive in Zero-Knowledge Proof (ZKP) protocols, sharing significant computational workloads with the Number Theoretic Transform (NTT) in zkSTARK schemes. Merkle Tree is a tree structure where nodes are primarily generated through hash computations. Among them, Poseidon Hash, as a ZK-friendly hash function, has emerged as one of the most widely adopted choices. Therefore, hardware acceleration of building Merkle Tree based on Poseidon Hash can significantly enhance the performance of ZKP protocols. We propose AcclMT, a highly resourceefficient and flexible Poseidon Hash-based Merkle Tree architecture. Our design employs hardware-software co-design and optimizes the hashing data flow, resulting in an area-efficient Poseidon Hash engine that improves modular multiplication resource utilization. Furthermore, AcclMT uses these engines alongside hierarchical on-chip cache and optimized task scheduling for building large Merkle Trees. It also supports flexible parameter configurations for various requirements. Experimental results show that our proposed Poseidon Hash engine achieves a $14.3 \times$ speedup compared to the latest FPGA-based work. By improving resource utilization, it also reduces area usage by 14.8% compared to unoptimized design. AcclMT achieves up to $1665 \times$ speedup over software implementations in building Merkle tree, with average utilization of 95.9% and 99.2% for the two hash engines.
Modular arithmetic, particularly modular reduction, is widely used in cryptographic applications such as homomorphic encryption (HE) and zero-knowledge proofs (ZKP). High-bit-width operations are crucial for enhancing security; however, they are computationally intensive due to the large number of modular operations required. The lookup-table-based (LUT-based) approach, a “space-for-time” technique, reduces computational load by segmenting the input number into smaller bit groups, pre-computing modular reduction results for each segment, and storing these results in LUTs. While effective, this method incurs significant hardware overhead due to extensive LUT usage. In this paper, we introduce ALLMod, a novel approach that improves the area efficiency of LUT-based largenumber modular reduction by employing hybrid workloads. Inspired by the iterative method, ALLMod splits the bit groups into two distinct workloads, achieving lower area costs without compromising throughput. We first develop a template to facilitate workload splitting and ensure balanced distribution. Then, we conduct design space exploration to evaluate the optimal timing for fusing workload results, enabling us to identify the most efficient design under specific constraints. Extensive evaluations show that ALLMod achieves up to $\lt sup\gt1\lt/sup\gt|.65 \times$ and $3 \times$ improvements in area efficiency over conventional LUT-based methods for bit-widths of 128 and 8,192, respectively.
Zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK) schemes have been a promising technique in verified computation. Zk-SNARK schemes were designed to be mathematically secure against cryptographic attacks and it remains unclear whether they are vulnerable to fault injection attacks. In this work, we provide a positive answer by presenting ZK-Hammer, which leaks secrets from zk-SNARK schemes via Rowhammer. We incur faults in the exponentiate variables in the Quadratic Arithmetic Program (QAP) problem. Then we analyze the faulty proof using the bilinear pairing technique and manage to recover the secret. We employ a Rowhammer fault evaluation in libsnark and identify 3 CVEs.
Benford’s Law and Fraud Detection
Cryptographic Implementations and Security
Advanced Steganography and Watermarking Techniques
The rapid proliferation of the Internet of Things (IoT) and the increasing heterogeneity of connected devices have exposed the limitations of traditional centralized authentication and access control systems. These conventional approaches struggle to meet the demands of high concurrency, cross-domain interoperability, and decentralized trust. To address these challenges, this paper proposes a distributed security authentication and access control framework that integrates blockchain and edge computing technologies. The proposed model introduces Decentralized Identifiers (DID) and zero-knowledge proofs (ZKP) to enhance identity authentication privacy and integrity. Additionally, it adopts a hybrid access control mechanism that combines Attribute-Based Access Control (ABAC) with Role-Based Access Control (RBAC), enabling fine-grained and dynamic policy enforcement. The system is structured in a three-tier architecture, where smart contracts deployed on a consortium blockchain ensure tamper-proof policy execution and auditability. Experimental evaluations show that the model significantly improves authentication latency, accuracy, and resilience against various attack scenarios, while maintaining policy flexibility and scalability. This work provides a practical and effective solution for secure and trustworthy device access management in complex IoT environments.
Blockchain technology, originally developed for cryptocurrencies, has evolved into a powerful tool for enhancing humanitarian aid distribution in conflict zones, where traditional centralized systems frequently fail due to corruption, inefficiencies, and trust deficits. This research presents an integrated framework leveraging blockchain’s immutable ledger, advanced cryptographic security, and decentralized consensus, alongside smart contract automation to ensure tamper-proof records and secure, real-time tracking of aid. The system incorporates biometric identity verification and zero-knowledge proofs to safeguard sensitive beneficiary data, minimizing fraud risks while enhancing transparency. Extensive laboratory simulations, controlled pilot studies, and field experiments conducted under varying network conditions demonstrate improvements in transaction throughput, reduced latency in intermittent connectivity scenarios, and enhanced operational resilience. IoT-driven sensor integration ensures continuous monitoring, while automated rule execution streamlines aid distribution by eliminating manual errors, bureaucratic overhead, and delays. The system enables rapid beneficiary verification and transparent reporting, fostering trust among donors, aid organizations, and recipients. Experimental results indicate that even under severe resource constraints, the framework scales effectively to serve large populations while addressing ethical concerns and digital exclusion issues. Future advancements will focus on refining privacy protocols, achieving cross-chain interoperability, and optimizing consensus algorithms for ultra-lightweight performance in resource-constrained environments, ensuring efficiency, accountability, and reliability in humanitarian aid operations. Keywords, Humanitarian Aid, Blockchain Technology, Decentralized Validation, Supply Chain Transparency, Smart Contracts, Biometric Verification, Zero Knowledge Proofs, IoT Integration
The article investigates the problem of ensuring the veracity and traceability of production data in digital factories, where EU regulatory requirements and a high level of counterfeiting create a critical deficit of trust in source information. The objective of this study is to analyze the architectures of blockchain solutions for data verification in supply chains and to develop a phased implementation plan that considers regulatory obligations and the protection of trade secrets. The novelty lies in a combined approach: classification of DLT networks according to scalability, cost, and privacy criteria; use of Merkle trees and zero-knowledge proofs to preserve confidential data while proving authenticity; and justification of architecture choice through practical case studies (IBM Food Trust, VeChain, Airbus/Circularise, SAP). The study demonstrates that blockchain enables a reduction in batch traceability time from days to seconds, a reduction in manual operations to 67%, and an increase in data matching accuracy to 92%. However, the immutability of the ledger does not eliminate the immutable garbage problem: the veracity of records depends on sensor calibration and procedural control, which requires preliminary semantic normalization and master data management. A phased implementation enables the minimization of risks and the assessment of economic impacts. To comply with DPP, it is recommended to introduce decentralized identifiers (DID) and Verifiable Credentials, as well as the integration of zero-knowledge proofs. Thus, blockchain transitions from a trial technology to a necessary component of the practical infrastructure for sustainable production chains. This article will help managers and experts in digitalization and supply chain management.
Ridesharing and on-demand mobility systems offer societal benefits that include reduced traffic, lower parking demand and less environmental impact from vehicle usage. However, the problem of user impersonation has compromised the safety of both riders and drivers, sometimes ending in fatal tragedy. To address the safety concerns resulting from user impersonation, this paper proposes a blockchain-based and zero-knowledge approach for decentralized and privacy-preserving identity verification in ridesharing. The proposed permissioned blockchain facilitates our privacy-aware verification scheme and provides fine-grained access control policies to protect on-chain trip records. We developed the proposed system on the Hyperledger Fabric platform, with Chaincode smart contracts and Hyperledger Ursa cryptographic library. To measure the performance of the system, we conduct extensive experiments utilizing the Hyperledger Caliper benchmark tool. Our results show that the zero-knowledge proof module can perform the privacy-preserving identity verification at the millisecond level while the blockchain network offers low latency and high throughput for transactions. The non-resource-intensive authentication scheme and the proposed secure-by-design blockchain with access control policies make the proposed approach fitting for application in real-world ridesharing environments.
With the rapid advancement of blockchain technology and modern cryptographic methods, achieving efficient privacy preservation while maintaining robust security has become a critical challenge. To address this issue, this paper proposes a blockchain-based aggregated zero-knowledge proof (ZKP) scheme tailored for electronic voting applications. The proposed scheme leverages zero-knowledge proof techniques to authenticate voter identities while preserving privacy by preventing the disclosure of any sensitive voter information. Furthermore, it supports the aggregation of multiple ZKPs, significantly enhancing verification efficiency. To improve system synchronization and security, the scheme incorporates the Chinese cryptographic algorithm ZUC for dynamic updates of shared secret information. A comprehensive security analysis demonstrates that the scheme is secure under the Computational Diffie-Hellman (CDH) assumption. Performance evaluation indicates that, under the condition of updating shared secrets twice every 24 hours and with a voting population of 20, the proposed approach reduces communication overhead by 33.3% and computation overhead by 37.1% to 89.5% compared to existing methods. These results demonstrate that the proposed scheme outperforms comparable solutions in both communication and computational efficiency, making it well-suited for electronic voting scenarios that demand frequent identity verification and strong privacy guarantees.
This paper explores how zero-knowledge proofs can enhance Bitcoin's functionality and privacy. First, we consider Proof-of-Reserve schemes: by using zk-STARKs, a custodian can prove its Bitcoin holdings are more than a predefined threshold X, without revealing addresses or actual balances. We outline a STARK-based protocol for Bitcoin UTXOs and discuss its efficiency. Second, we examine ZK Light Clients, where a mobile or lightweight device verifies Bitcoin's proof-of-work chain using succinct proofs. We propose a protocol for generating and verifying a STARK-based proof of a chain of block headers, enabling trust-minimized client operation. Third, we explore Privacy-Preserving Rollups via BitVM: leveraging BitVM, we design a conceptual rollup that keeps transaction data confidential using zero-knowledge proofs. In each case, we analyze security, compare with existing approaches, and discuss implementation considerations. Our contributions include the design of concrete protocols adapted to Bitcoin's UTXO model and an assessment of their practicality. The results suggest that while ZK proofs can bring powerful features (e.g., on-chain reserve audits, trustless light clients, and private layer-2 execution) to Bitcoin, each application requires careful trade-offs in efficiency and trust assumptions.
The rapid evolution of phishing attacks targeting email, chat, and social media platforms poses a significant threat to digital security, with a reported 667% surge in spear-phishing during the 2020 COVID-19 crisis [1]. Current AI-based detection systems face challenges in dataset diversity, adversarial robustness, computational scalability, model interpretability, and privacy preservation, limiting their efficacy in real-time, multi-platform environments. This paper introduces PhishGuard, an innovative framework for real-time phishing detection, designed to overcome these limitations. PhishGuard integrates lightweight transformer models (e.g., distilled BERT), hybrid detection techniques combining natural language processing (NLP), propagation analysis, and user behavior analysis, and explainable AI (XAI) methods like SHAP and LIME for transparent decision-making. Privacy-preserving techniques, including federated learning and local differential privacy, ensure secure processing of sensitive user data. Evaluated on diverse datasets such as PhiKitA, Enron, and a custom social media corpus, PhishGuard achieves up to 97.5% accuracy, 94% F1-score, and inference times below 5 ms, demonstrating scalability for resource-constrained devices. The framework also incorporates zero-knowledge proofs for verifiable inference, addressing trust and integrity concerns. By tackling cross-domain generalization, adversarial robustness, and real-time performance, PhishGuard offers a scalable, user centric solution for secure digital communications, with applications in finance, healthcare, and social media platforms. Future enhancements include multilingual support and image based phishing detection, paving the way for a comprehensive defense against evolving cyber threats.
Jessica Man, Sadiq Jaffer, Patrick Ferris, Martin Kleppmann · 5 authors
Information and Communication Technologies (ICT) have a significant climate impact, and data centres account for a large proportion of the carbon emissions from ICT. To achieve sustainability goals, it is important that all parties involved in ICT supply chains can track and share accurate carbon emissions data with their customers, investors, and the authorities. However, businesses have strong incentives to make their numbers look good, whilst less so to publish their accounting methods along with all the input data, due to the risk of revealing sensitive information. It would be uneconomical to use a trusted third party to verify the data for every report for each party in the chain. As a result, carbon emissions reporting in supply chains currently relies on unverified data. This paper proposes a methodology that applies cryptography and zero-knowledge proofs for carbon emissions claims that can be subsequently verified without the knowledge of the private input data. The proposed system is based on a zero-knowledge Succinct Non-interactive ARguments of Knowledge (zk-SNARK) protocol, which enables verifiable emissions reporting mechanisms across a chain of energy suppliers, cloud data centres, cloud services providers, and customers, without any company needing to disclose commercially sensitive information. This allows customers of cloud services to accurately account for the emissions generated by their activities, improving data quality for their own regulatory reporting. Cloud services providers would also be held accountable for producing accurate carbon emissions data.