Xingyu Liang, Sen Wang, Ling Xiong, Zhicai Liu · 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
8,502 results · page 114 of 355
Xingyu Liang, Sen Wang, Ling Xiong, Zhicai Liu · 5 authors
No abstract is available for this record.
Aditya Vadluri, Snehanshu Ayer
The integration of Zero-Trust Architecture (ZTA) and Blockchain-based Security Models in IoT-driven industrial power electronics systems has emerged as a transformative approach to mitigating cyber threats and ensuring robust access control. Traditional security mechanisms, which rely on perimeter-based defenses, are increasingly ineffective against advanced persistent threats (APTs), insider attacks, and lateral movement techniques within industrial IoT (IIoT) environments. Zero-Trust security enforces continuous verification, least-privilege access, and micro-segmentation, ensuring that no device or user was inherently trusted. Implementing ZTA in resource-constrained IoT ecosystems presents significant challenges related to computational overhead, authentication latency, and secure data transmission. To address these limitations, blockchain technology enhances decentralized identity management, immutable access logs, and tamper-resistant security frameworks, fortifying Zero-Trust-based access control. Privacy-preserving cryptographic techniques, including zero-knowledge proofs (ZKPs) and homomorphic encryption, safeguard sensitive industrial data while maintaining compliance with evolving regulatory frameworks. AI-driven anomaly detection models reinforce continuous authentication and behavior-based threat monitoring, enabling proactive defense mechanisms against zero-day exploits and sophisticated cyber intrusions. This chapter presents a comprehensive analysis of Zero-Trust implementation models for IIoT systems, highlighting the role of secure communication protocols, distributed ledger-based identity verification, and adaptive security automation. The integration of blockchain-enabled access control and AI-powered real-time security analytics ensures a resilient security posture for industrial power electronics networks, mitigating risks associated with unauthorized access, data breaches, and operational disruptions. The proposed framework enhances scalability, privacy, and computational efficiency, paving the way for next-generation cybersecure industrial ecosystems.
Bingxue Zhang, Guangguang Lu, Yuncheng Wu, Kunpeng Ren · 5 authors
Federated learning (FL) is an emerging paradigm that enables multiple clients to collaboratively train a machine learning (ML) model without the need to exchange their raw data. However, it relies on a centralized authority to coordinate participants’ activities. This not only interrupts the entire training task in case of a single point of failure, but also lacks an effective regulatory mechanism to prevent malicious behavior. Although blockchain, with its decentralized architecture and data immutability, has significantly advanced the development of FL, it still struggles to withstand poisoning attacks and faces limitations in computational scalability. We propose Zkfhed, a verifiable and scalable FL system that overcomes the limitations of blockchain-based FL in poison attacks and computational scalability. First, we propose a two-stage audit scheme based on zero-knowledge proofs (ZKPs), which verifies that the training data are extracted from trusted organizations and that computations on the data exactly follow the specified training protocols. Second, we propose a homomorphic encryption delegation learning (HEDL), based on fully homomorphic encryption (FHE). It is capable of outsourcing complex computing to external computing resources without sacrificing the client's data privacy. Final, extensive experiments on real-world datasets demonstrate that Zkfhed can effectively identify malicious clients and is highly efficient and scalable in terms of online time and communication efficiency.
R. Zhang, Yi Li, Li Fang
With the development of communication infrastructure and the popularity of smart devices, e-commerce is presenting in more diverse forms and attracting the attention of more and more users. Since e-commerce transactions usually involve sensitive information of a large number of users, privacy and security have become increasingly important issues. Despite certain advantages (e.g., trading security), the privacy protection capability and efficiency of blockchain is still limited by some key factors, especially of its architecture. In this paper, we propose a blockchain-based privacy protection system named PBTMS that integrates zero-knowledge proofs, hybrid encryption, and Pedersen commitments as foundational mechanisms to ensure robust privacy protection for transaction data and user information. To achieve secure, reliable, and efficient e-commerce transactions, the PBTMS employs blockchain technology and consensus mechanisms to enable distributed storage, thereby mitigating single points of failure and addressing the risks posed by malicious nodes. Moreover, by integrating on-chain storage with off-chain computation, the system substantially reduces blockchain-related overheads, including processing time, gas consumption, and storage costs. This design establishes the PBTMS as a highly adaptable and efficient system for the evolving requirements of secure and privacy-preserving e-commerce platforms. Theoretical analysis and experimental validation demonstrate that PBTMS reduces decryption and authentication times by 79.2% and 52.6%, respectively, while cutting encrypted data size by 52.5% and overall gas consumption by 55.4%, outperforming state-of-the-art solutions. These results indicate that PBTMS is a reliable and efficient system for secure e-commerce transaction platforms and provides a novel approach to enhancing privacy protection in e-commerce.
Olumide Samuel Ogungbemi
Property transactions in the UK are increasingly adopting blockchain technology to enhance efficiency, transparency, and security. However, the inherent transparency of blockchain raises significant data privacy risks and regulatory compliance challenges, particularly under the UK General Data Protection Regulation (UK GDPR). This study examines the role of Zero-Knowledge Proofs (ZKPs) in addressing these concerns by enabling transaction validation while preserving confidentiality. Using entropy measures, k-anonymity analysis, and logistic regression, this research quantitatively assesses the privacy risks, effectiveness of ZKPs, and regulatory acceptance in blockchain-based property transactions. The findings reveal that 65.5% of transactions remain highly or moderately identifiable, posing privacy vulnerabilities under UK data protection laws. ZKP-enabled transactions significantly enhance confidentiality, achieving a 92.5% transaction privacy score, compared to 48.3% for non-ZKP transactions. However, these privacy gains come at a 67.8% increase in transaction costs, highlighting a critical trade-off between security and efficiency. Regulatory approval rates for ZKP-based blockchain platforms stand at 72.5%, suggesting a strong potential for compliance advantages. While ZKPs improve privacy and regulatory alignment, challenges remain in terms of computational overhead, transaction costs, and adoption barriers. To facilitate large-scale implementation, this study recommends optimizing zk-Rollups for efficiency, developing clear policy frameworks, and enhancing collaboration between regulators, industry stakeholders, and blockchain developers. These steps are essential to ensuring a balance between privacy, scalability, and compliance, paving the way for secure and legally sound blockchain-based property transactions in the UK.
Vaishnav Pradeep Menon, Aluru Sai Tharshith, Priyanshu Aryan, Kirti S. Pande · 5 authors
The solution offered by Blockchain technology fixes electronic voting problems by tackling the vulnerabilities of Votes, eliminating transparency problems, and improving EVM machine scalability issues. This study creates a dual voting system that unites Ethereum smart contracts for both protected candidate enrollment and voting confirmation along with authentication functions and election results counting. This framework incorporates an oversight feature for election officials who can monitor votes live so they can verify operations while improving both security and transparency. The Ganache implementation of the prototype required $\mathbf{3 8 7, 9 5 7}$ gas units for each vote to maintain decentralization as well as optimize resource usage. This frame- work links blockchain innovation to offline voting procedures to create an operable solution that substitutes standard voting technologies. Future developments will include work on both scalability improvements and user accessibility enhancements together with the integration of zero-knowledge-proof technology to guarantee voter privacy at the operational level of this framework.
Atsuki Koyama, Kentaroh Toyoda, Manato Fujimoto, Thi Hong Tran
The rapid advancement of deepfake technology poses serious risks, including financial fraud and political misinformation, demanding robust methods for verifying image content authenticity. While the C2PA standard and zero-knowledgeproof-based methods provide an image content authenticity proving mechanism, the existing solutions struggle to efficiently support privacy-preserving edits and iterative modifications. To address these challenges, we propose zk-REAL (Zero-Knowledge-Based Protocol for Repeated Image Edit Authenticity Proof with Lattice Hashing), a framework that leverages a lightweight lattice-based hashing scheme within a zero-knowledge proof system. Our approach significantly reduces computational overhead, enabling faster proof generation and smaller proof size even for high-resolution images. Additionally, the updatability of our hashing method supports iterative edits, such as mosaicking or partial modifications, by minimizing redundant computations. Finally, to ensure compatibility with the C2PA ecosystem and conventional signature verifications, we integrate SHA-256 outside of the zero-knowledge circuit. Our evaluation shows up to a 29% reduction in computational costs for proof generation, showcasing the potential of zk-REAL in practical content authenticity verification scenarios.
Chong Zhang, Xun Gong, Yunfeng Hu, Hong Chen
Various discrete-time zeroing neural network (DTZNN) models have been developed for solving dynamic constrained quadratic programming. However, two challenges persist within the DTZNN framework: first, the theoretical analysis of robustness in disturbance suppression remains insufficient; second, to the best of authors' knowledge, existing DTZNN models have yet to provide a theoretical proof of finite-step convergence. Inspired by the inherent robustness and finite-step convergence of discrete sliding-mode control based on the reaching-law, this article is the first work to integrate reaching-law theory into the DTZNN framework to address the aforementioned challenges, ensuring that the resulting DTZNN exhibits both robustness and finite-step convergence. In addition, a novel hyperbolic type reaching law (HTRL) is designed, which offers advantages in reducing the width of the quasi-sliding-mode region and suppressing chattering. The zeroing neural network (ZNN) based on this HTRL (HTRL-ZNN) is rigorously proven to exhibit effective disturbance suppression robustness and finite-step convergence, with an explicit expression provided for the convergence step length. Finally, the effectiveness and advantages of HTRL-ZNN in solving dynamic constrained quadratic programming are validated through both a numerical example and an application-oriented case.
Xingchen Chen, Baizhu Wang, Mengjun Zhang, Yaqin Cao · 5 authors
In recent years, web application development has become more efficient, yet vulnerabilities still pose significant risks. Traditional static and dynamic detection techniques are prone to false positives and negatives, making it challenging for small and medium-sized developers with limited security knowledge to accurately assess the results. To address these challenges, we introduced VulKiller, an automated vulnerability detection tool powered by large language models (LLM). VulKiller leverages static analysis to convert application code into Code Property Graphs (CPG) and utilizes Neo4j to identify high-risk method call chains. By designing structured interactions with ChatGPT, these call chains and corresponding code are transformed into Proofs of Concept (PoCs), which are then parsed into attack payloads and evaluated by a vulnerability monitor for effectiveness. In comparison with traditional tools, VulKiller excels in reducing false positives and negatives. Additionally, in zero-day vulnerability detection experiments, VulKiller identified 12 zero-day vulnerabilities. Our results offer significant encouragement for using LLM to enhance vulnerability detection.
Xianrong Zhang, Yue‐Jiao Gong, Zhong, Yuan-Ting, Huang, Ting · 5 authors
In many-task optimization scenarios, surrogate models are valuable for mitigating the computational burden of repeated fitness evaluations across tasks. This study proposes a novel meta-surrogate framework to assist many-task optimization, by leveraging the knowledge transfer strengths and emergent capabilities of large language models (LLMs). We formulate a unified framework for many-task fitness prediction, by defining a universal model with metadata to fit a group of problems. Fitness prediction is performed on metadata and decision variables, enabling efficient knowledge sharing across tasks and adaptability to new tasks. The LLM-based meta-surrogate treats fitness prediction as conditional probability estimation, employing a unified token sequence representation for task metadata, inputs, and outputs. This approach facilitates efficient inter-task knowledge sharing through shared token embeddings and captures complex task dependencies via multi-task model training. Experimental results demonstrate the model's emergent generalization ability, including zero-shot performance on problems with unseen dimensions. When integrated into evolutionary transfer optimization (ETO), our framework supports dual-level knowledge transfer -- at both the surrogate and individual levels -- enhancing optimization efficiency and robustness. This work establishes a novel foundation for applying LLMs in surrogate modeling, offering a versatile solution for many-task optimization.
Muhammad ElSheikh, Amr Youssef, M.A. Hasan
Achieving fairness, verifiability, and abandon resistance poses challenges within e-voting protocols. This paper introduces a privacy-preserving self-tallying e-voting system leveraging blockchain technology. The system supports diverse e-voting models, including ‘Yes/No’, approval voting with multiple candidates, and score voting. By employing linearly homomorphic time-lock puzzles (LHTLPs) along with verifiable delay functions (VDFs) and zero-knowledge Succinct Non-interactive Argument of Knowledge schemes (zk-SNARKs), the proposed system ensures crucial security properties, including voter anonymity and eligibility, as well as ballot privacy and validity. It also provides efficient individual and universal verifiability (end-to-end verifiability), and dispute-freeness. More importantly, the system demonstrates fairness and abandon resistance. Furthermore, the evaluation of the proof-of-concept implementation on the Ethereum blockchain indicates that on-chain gas costs are either fixed or increasing slowly and logarithmically with the number of voters.
S. Sharmila Sathyanathan, Samanvitha. Sree, F. Sophiya Theresa, S Vaishali · 5 authors
Client safety and privacy will be maintained through secure security access systems, which are necessary in light of the great dependence on digital benefits. During the age of digital help, secure and confidential access control is most important for customers as well as providers. Through guaranteeing that only clients possessing specific resources are certified, access control ensures secret data and discourages unlawful actions. Widespread centralized authorization systems usually expose users' sensitive data, enabling data breaches, abuse, and espionage. To solve all of the above problems and establish a trust less system in which clients can provide access to their data or services without revealing sensitive information, we propose a decentralized code that is used to establish an authorized, secure, private, and scalable service access. Decentralized technologies such as blockchain and distributed ledgers are employed within this system. By decoupling authorization from centralized organizations, the Inter-Planetary File System (IPFS) enhances user control over personal information, diminishes the attack surface for service providers, and enhances client privacy. The protocol is secure and accommodates a broad set of service providers, ranging from digital platforms to decentralized apps, and utilizes cryptographic methods such as symmetric encryption and proxy re-encryption to see that only approved recipients have access to specific resources. This provides perfect access control while maintaining client data security. The decentralized access control and zero knowledge proof architecture is explained here along with its primary security and privacy features and uses to file storage and service scenarios.
Biswaranjan Senapati, Bharat S. Rawal
In distributed computing, data trading mechanisms are essential for ensuring the sharing of data across multiple computing nodes. Nevertheless, they currently encounter considerable obstacles, including low accuracy in matching trading parties, ensuring fairness in transactions, and safeguarding data privacy throughout the trading process. To address these issues, we put forward a data trading security scheme based on zero-knowledge proofs and smart contracts. In the phase of preparing the security parameters, the objective is to reduce the complexity of generating non-interactive zero-knowledge proofs and to enhance the efficiency of data trading. In the pre-trading phase, we come up with attribute atomic matching smart contracts that are based on precise data property alignment. The goal is to get trading parties to match data attributes in a very specific way. During the trading execution phase, we use lightweight cryptographic algorithms based on Elliptic Curve Cryptography (ECC) and non-interactive zero-knowledge proofs to encrypt trading data twice and make attribute proof contracts. This keeps the data safe and private. The results of experiments conducted on the Ethereum platform in an industrial Internet of Things (IoT) scenario demonstrate that our scheme maintains stable and low-cost consumption while ensuring accuracy in matching and privacy protection. Especially in battery industrial manufacturing, the application of distributed computing is in huge demand and essential to maintaining a healthier technology integration among various systems and technological nodes to perform the better management of energy cells within the battery management system.
Chii Liang Ng, Denis Chee-Keong Wong, Gek L. Chia, Bok‐Min Goi · 6 authors
No abstract is available for this record.
Sanjeev Kumar Pellikoduku -
This article presents a novel framework for decentralized artificial intelligence model training that combines federated learning with blockchain technology in cloud environments. By integrating these cutting-edge technologies, the article addresses critical challenges in collaborative AI development, including data privacy, secure model sharing, and participant incentivization. The article framework leverages Zero Knowledge Proofs (ZKPs) for enhanced privacy guarantees while utilizing blockchain-based smart contracts to ensure transparent and automated governance of the training process. The implementation demonstrates significant improvements in data transfer efficiency, privacy preservation, system reliability, and participant diversity compared to traditional centralized approaches. The results validate the effectiveness of combining federated learning with blockchain technology for secure, scalable, and efficient distributed AI model training.
Jens Ernstberger, Jan Lauinger, Yulin Wu, Arthur Gervais · 5 authors
Transport Layer Security (TLS) is foundational for safeguarding client-server communication. However, it does not extend integrity guarantees to third-party verification of data authenticity. If a client wants to present data obtained from a server, it cannot convince any other party that the data has not been tampered with. TLS oracles ensure data authenticity beyond the client-server TLS connection, such that clients can obtain data from a server and ensure provenance to any third party, without server-side modifications. Generally, a TLS oracle involves a third party, the verifier, in a TLS session to verify that the data obtained by the client is accurate. Existing protocols for TLS oracles are communication-heavy, as they rely on interactive protocols. We present ORIGO, a TLS oracle with constant communication. Similar to prior work, ORIGO introduces a third party in a TLS session, and provides a protocol to ensure the authenticity of data transmitted in a TLS session, without forfeiting its confidentiality. Compared to prior work, we rely on intricate details specific to TLS 1.3, which allow us to prove correct key derivation, authentication and encryption within a Zero Knowledge Proof (ZKP). This, combined with optimizations for TLS 1.3, leads to an efficient protocol with constant communication in the online phase. Our work reduces online communication by 375× and online runtime by up to 4.6×, compared to prior work.
Xingwang Wang, Peng Zeng, Jiaying Luo
No abstract is available for this record.
Tung Chou, Edoardo Persichetti, Paolo Santini
No abstract is available for this record.
Stefan Dziembowski, Shahriar Ebrahimi, Parisa Hassanizadeh
Ensuring the authenticity and credibility of daily media on internet is an ongoing problem. Meanwhile, genuinely captured images often require refinements before publication. Zero-knowledge proofs (ZKPs) offer a solution by verifying edited image without disclosing the original source. However, ZKPs typically come with high costs, particularly in terms of prover complexity and proof size. This paper presents VIMz, a framework for efficiently proving the authenticity of high-resolution images using folding-based zkSNARKs; a type of proving system that minimizes computational overhead by recursively folding multiple evaluations of the same constraints into a compact proof. As a complete proof system, VIMz proves the integrity of both the original and edited images, as well as the correctness of the transformation without revealing intermediate images within a chain of edits--only the final result is disclosed. Moreover, VIMz maintains the anonymity of the original signer and all subsequent editors while proving the authenticity of the final image. We also compare VIMz with the system model in Coalition for Content Provenance and Authenticity (C2PA) from different perspectives and show that VIMz offers higher level of security guarantee by eliminating the need to trust the editing environment. Experimental results show that VIMz performs efficiently in both prover and verifier sides. It can prove the transformations on 8K (33MP,i.e., 100MB) images with up to 13%~25% faster than the competition, while reaching to a peak memory of only 10 GB. Moreover, VIMz has a verification time of under 1 second and achieves succinct proofs of less than 11 KB for all resolutions, which is more than 90% improvement compared to the competition. VIMz's low memory complexity allows for proving multiple transformations in parallel to achieve a 3.5x additional speedup on average.
Agon Kokaj, Elissa Mollakuqe
This work presents a mathematical solution to data privacy and integrity issues in Split Learning which uses Homomorphic Encryption (HE) and Zero-Knowledge Proofs (ZKP). It allows calculations to be conducted on encrypted data, keeping the data private, while ZKP ensures the correctness of these calculations without revealing the underlying data. Our proposed system, HavenSL, combines HE and ZKP to provide strong protection against attacks. It uses Discrete Cosine Transform (DCT) to analyze model updates in the frequency domain to detect unusual changes in parameters. HavenSL also has a rollback feature that brings the system back to a verified state if harmful changes are detected. Experiments on CIFAR-10, MNIST, and Fashion-MNIST datasets show that using Homomorphic Encryption and Zero-Knowledge Proofs during training is feasible and accuracy is maintained. This mathematical-based approach shows how crypto-graphic can protect decentralized learning systems. It also proves the practical use of HE and ZKP in secure, privacy-aware collaborative AI.
H. Y. Fu, Kieran Mastel, Xingjian Zhang
In their recent breakthrough result, Slofstra and the second author show that there is a two-player one-round perfect zero-knowledge MIP* protocol for RE (STOC'24). We build on their result to show that there exists a succinct two-player one-round perfect zero-knowledge MIP* protocol for RE against dishonest verifiers with polylog question size and O(1) answer size, or with O(1) question size and polylog answer size. To prove our result, we study the three central compression techniques underlying the MIP*=RE proof (Ji et al. '20): question reduction, oracularization, and answer reduction. We show that question reduction preserves the perfect (as well as statistical and computational) zero-knowledge properties of the original protocol against dishonest verifiers, and oracularization and answer reduction preserve the perfect (as well as statistical and computational) zero-knowledge properties of the original protocol against honest verifiers. Secondly, we show that every constraint-constraint binary constraint system (BCS) nonlocal game, which provides a quantum information characterization of MIP*, can be converted to a synchronous constraint-variable BCS game to preserve perfect completeness for our compression. Lastly, we present a parametrized perfect-zero-knowledge transformation of MIP* protocols, which generalizes the transformation in (Slofstra and Kieran STOC'24) . This transformation allows us to preserve the zero-knowledge property against dishonest verifiers in the recursively oracularized protocols in our compression.
Lucien K. L. Ng, Pedro Moreno-Sánchez, Mohsen Minaei, Panagiotis Chatzigiannis · 6 authors
Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK) schemes have gained significant adoption in privacy-preserving applications, decentralized systems (e.g., blockchain), and verifiable computation due to their efficiency. However, the most efficient zk-SNARKs often rely on a one-time trusted setup to generate a public parameter, often known as the ``Powers of Tau" (PoT) string. The leakage of the secret parameter, $τ$, in the string would allow attackers to generate false proofs, compromising the soundness of all zk-SNARK systems built on it. Prior proposals for decentralized setup ceremonies have utilized blockchain-based smart contracts to allow any party to contribute randomness to $τ$ while also preventing censorship of contributions. For a PoT string of $d$-degree generated by the randomness of $m$ contributors, these solutions required a total of $O(md)$ on-chain operations (i.e., in terms of both storage and cryptographic operations). These operations primarily consisted of costly group operations, particularly scalar multiplication on pairing curves, which discouraged participation and limited the impact of decentralization In this work, we present Lite-PoT, which includes two key protocols designed to reduce participation costs: \emph{(i)} a fraud-proof protocol to reduce the number of expensive on-chain cryptographic group operations to $O(1)$ per contributor. Our experimental results show that (with one transaction per update) our protocol enables decentralized ceremonies for PoT strings up to a $2^{15}$ degree, an $\approx 16x$ improvement over existing on-chain solutions; \emph{(ii)} a proof aggregation technique that batches $m$ randomness contributions into one on-chain update with only $O(d)$ on-chain operations, independent of $m$. This significantly reduces the monetary cost of on-chain updates by $m$-fold via amortization.
Siddhant Sonkar
This comprehensive article explores recent advancements in privacy-preserving technologies within artificial intelligence systems, focusing on five key approaches: federated learning, differential privacy, homomorphic encryption, privacy-preserving machine learning (PPML), and zero-knowledge proofs. The article examines how these technologies address critical privacy challenges in machine learning environments while maintaining model performance and utility. The article highlights the implementation of these approaches across various domains, particularly in healthcare and financial services, demonstrating their effectiveness in protecting sensitive data throughout the machine learning lifecycle. The article reveals how these technologies complement each other to create robust privacy protection frameworks while enabling organizations to leverage the power of AI without compromising data confidentiality.
Jules Maire, Damien Vergnaud
We present a communication-efficient zero-knowledge proof of knowledge for the factorization of Blum integers, a special class of integers of the form n = p q , where p and q are distinct prime numbers satisfying p ≡ q ≡ 3 mod 4 and p ≃ q ≃ n . Existing protocols for proving such statements often incur significant communication costs, especially when demonstrating that p and q are of nearly equal size. We leverage the MPC-in-the-head paradigm, a cryptographic technique that transforms secure multi-party computation protocols into efficient zero-knowledge proof systems. In our protocol, the prover uses additive sharing of p and q over the integers. This approach simplifies proving the size relationship p ≃ q ≃ n and the congruence p ≡ q ≡ 3 mod 4 without requiring costly range proofs. To verify the primality of p and q , we employ the Boneh-Franklin biprimality test. Our protocol achieves a significant reduction in communication complexity. For a 2048-bit integer n and 128-bit security, we construct a proof as small as 12.3 KB, with prover and verifier computational costs comparable to existing protocols that require over 131 KB.