Zero-knowledge proof (ZKP) mixers are one of the most widely-used blockchain privacy solutions, operating on top of smart contract-enabled blockchains. We find that ZKP mixers are tightly intertwined with the growing number of Decentralized Finance (DeFi) attacks and Blockchain Extractable Value (BEV) extractions. Through coin flow tracing, we discover that 205 blockchain attackers and 2,595 BEV extractors leverage mixers as their source of funds, while depositing a total attack revenue of 412.87M USD. Moreover, the US OFAC sanctions against the largest ZKP mixer, Tornado.Cash, have reduced the mixer's daily deposits by more than 80%. Further, ZKP mixers advertise their level of privacy through a so-called anonymity set size, which similarly to k-anonymity allows a user to hide among a set of k other users. Through empirical measurements, we, however, find that these anonymity set claims are mostly inaccurate. For the most popular mixers on Ethereum (ETH) and Binance Smart Chain (BSC), we show how to reduce the anonymity set size on average by 27.34% and 46.02% respectively. Our empirical evidence is also the first to suggest a differing privacy-predilection of users on ETH and BSC. State-of-the-art ZKP mixers are moreover interwoven with the DeFi ecosystem by offering anonymity mining (AM) incentives, i.e., users receive monetary rewards for mixing coins. However, contrary to the claims of related work, we find that AM does not necessarily improve the quality of a mixer's anonymity set. Our findings indicate that AM attracts privacy-ignorant users, who then do not contribute to improving the privacy of other mixer users.
Amir Afaq, Zeeshan Ahmed, Noman Haider, Muhammad Ali Imran
Federated Learning (FL) provides privacy preservation by allowing the model training at edge devices without the need of sending the data from edge to a centralized server. FL has distributed the implementation of ML. Another variant of FL which is well suited for the Internet of Things (IoT) is known as Collaborated Federated Learning (CFL), which does not require an edge device to have a direct link to the model aggregator. Instead, the devices can connect to the central model aggregator via other devices using them as relays. Although, FL and CFL protect the privacy of edge devices but raises security challenges for a centralized server that performs model aggregation. The centralized server is prone to malfunction, backdoor attacks, model corruption, adversarial attacks and external attacks. Moreover, edge device to centralized server data exchange is not required in FL and CFL, but model parameters are sent from the model aggregator (global model) to edge devices (local model), which is still prone to cyber-attacks. These security and privacy concerns can be potentially addressed by Blockchain technology. The blockchain is a decentralized and consensus-based chain where devices can share consensus ledgers with increased reliability and security, thus significantly reducing the cyberattacks on an exchange of information. In this work, we will investigate the efficacy of blockchain-based decentralized exchange of model parameters and relevant information among edge devices and from a centralized server to edge devices. Moreover, we will be conducting the feasibility analysis for blockchain-based CFL models for different application scenarios like the internet of vehicles, and the internet of things. The proposed study aims to improve the security, reliability and privacy preservation by the use of blockchain-powered CFL.
Jie Yin, Yang Xiao, Qingqi Pei, Ying Ju · 7 authors
Internet of Things (IoT) applications have penetrated into all aspects of human life. Millions of IoT users and devices, online services, and applications combine to create a complex and heterogeneous network, which complicates the digital identity management. Distributed identity is a promising paradigm to solve IoT identity problems and allows users to have soverignty over their private data. However, the existing state-of-the-art methods are unsuitable for IoT due to continuing issues regarding resource limitations for IoT devices, security and privacy issues, and lack of a systematic proof system. Accordingly, in this article, we propose SmartDID, a novel blockchain-based distributed identity aimed at establishing a self-sovereign identity and providing strong privacy preservation. First, we configure IoT devices as light nodes and design a Sybil-resistant, unlinkable, and supervisable distributed identity that does not rely on central identity providers. We further develop a dual-credential model based on commitment and zero-knowledge proofs to protect the privacy of sensitive attributes, on-chain identity data, and linkage of credentials. Moreover, we combine the basic credential proofs to prove the knowledge of solutions to more complex problems and create a systematic proof system. We go on to provide the security analysis of SmartDID. Experimental analysis shows that our scheme achieves better performance in terms of both credential generation and proof generation when compared with CanDID.
With the rapid development of embedded smart devices, a new data collection paradigm, mobile crowd-sensing (MCS), has been proposed. MCS allows individuals from the crowd to act as sensors and contribute their observation data. However, existing MCS systems are mostly based on third-party platforms, and there is no guarantee that a center is completely credible. In addition, security and privacy issues should not be ignored. During MCS’ execution, the participants’ various information and truth value are usually exposed, and the computation related to data privacy cannot be verified. In this paper, we integrate the blockchain into the MCS scenario to design a blockchain based privacy-preserving quality control mechanism, which prevents data from being tampered with, and denied, ensuring that the reward is distributed fairly. In the new system, we propose a privacy preserving participant selection scheme and the result can be verified (i.e., security against malicious node) without any third-party arbiter. Finally, considering the issues with sensing data privacy and efficiency in the truth discovery process, we propose a new privacy-aware crowdsensing design with iterative truth discovery based on rational secure multi-party computation. The experimental results show that compared to the prior result, the proposed solutions are highly practical and facilitate quality control without violating the participant’s privacy.
Sin Kit Lo, Yue Liu, Qinghua Lu, Chen Wang · 7 authors
Federated learning is an emerging privacy-preserving AI technique where clients (i.e., organizations or devices) train models locally and formulate a global model based on the local model updates without transferring local data externally. However, federated learning systems struggle to achieve trustworthiness and embody responsible AI principles. In particular, federated learning systems face accountability and fairness challenges due to multistakeholder involvement and heterogeneity in client data distribution. To enhance the accountability and fairness of federated learning systems, we present a blockchain-based trustworthy federated learning architecture. We first design a smart contract-based data-model provenance registry to enable accountability. Additionally, we propose a weighted fair data sampler algorithm to enhance fairness in training data. We evaluate the proposed approach using a COVID-19 X-ray detection use case. The evaluation results show that the approach is feasible to enable accountability and improve fairness. The proposed algorithm can achieve better performance than the default federated learning setting in terms of the model’s generalization and accuracy.
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Artificial Intelligence in Healthcare and Education
With the rise of blockchain technology, the peer-to-peer (P2P) network system has once again caught people's attention to equipping a blockchain with a big storage capacity. In the traditional P2P file-sharing network systems, such as InterPlanetary File System (IPFS), data stored in the other nodes cannot be revoked by the owner and can only be removed by other nodes themselves. To comply with the criteria of the European Union's General Data Protection Regulation, it is important to ensure that personal data can be completely removed by their owners. To improve the privacy and security of the P2P file-sharing system, we propose a revocable and monitorable P2P file-sharing system over a consortium blockchain to achieve revocation of files in the decentralized environment. By using a trusted execution environment, such as Intel Software Guard Extensions (SGX), the proposed scheme can verify the integrity of the executables of the P2P file-sharing system and generate a file authentication code for each IPFS node to make sure that the system is synchronized correctly. This scheme elaborately integrates the autonomous smart contracts and Intel SGX hardware to obtain the monitorable merit. The experimental results suggest that enhancing the security and privacy take modest computing costs into consideration. To the best of our knowledge, this scheme is the first attempt to achieve the P2P file-sharing system with securely revocable functions.
The purpose of a reputation system is to hold the users of a distributed application accountable for their behavior. The reputation of a user is computed as an aggregate of the feedback provided by fellow users in the system. Truthful feedback is clearly a prerequisite for computing a reputation score that accurately represents the behavior of a user. However, it has been observed that users can hesitate in providing truthful feedback because, for example, of fear of retaliation. Privacy-preserving reputation systems enable users to provide feedback in a private and thus uninhibited manner. In this survey, we propose analysis frameworks for privacy-preserving reputation systems. We use these analysis frameworks to review and compare the existing approaches. Emphasis is placed on blockchain-based systems as they are a recent significant development in the area. Blockchain-based privacy-preserving reputation systems have properties, such as trustlessness, transparency, and immutability, which prior systems do not have. Our analysis provides several insights and directions for future research. These include leveraging blockchain to its full potential in order to develop truly trustless systems, to achieve some important security properties, and to include defenses against common attacks that have so far not been addressed by most current systems.
Internet of medical things (IoMT) has made it possible to collect applications and medical devices to improve healthcare information technology. Since the advent of the pandemic of coronavirus (COVID-19) in 2019, public health information has become more sensitive than ever. Moreover, different news items incorporated have resulted in differing public perceptions of COVID-19, especially on the social media platform and infrastructure. In addition, the unprecedented virality and changing nature of COVID-19 makes call centres to be likely overstressed, which is due to a lack of authentic and unregulated public media information. Furthermore, the lack of data privacy has restricted the sharing of COVID-19 information among health institutions. To resolve the above-mentioned limitations, this paper is proposing a privacy infrastructure based on federated learning and blockchain. The proposed infrastructure has the potentials to enhance the trust and authenticity of public media to disseminate COVID-19 information. Also, the proposed infrastructure can effectively provide a shared model while preserving the privacy of data owners. Furthermore, information security and privacy analyses show that the proposed infrastructure is robust against information security-related attacks.
Sai Batchu, Karan Patel, Owen S. Henry, Aleem Mohamed · 9 authors
Introduction The emergence and rapid spread of the coronavirus disease 2019 (COVID-19) pandemic have revealed the limitations in current healthcare systems to handle patient records securely and transparently, and novel protocols are required to address these shortcomings. An attractive option is the use of Ethereum smart contracts to secure the storage of medical records and concomitant data logs. Ethereum is an open-source platform that can be used to construct smart contracts, which are collections of code that allow transactions under certain parameters and are self-executable. Methods The present study developed a proof-of-concept smart contract that stores COVID-19 patient data such as the patient identifier (ID), variant, chest CT grade, and significant comorbidities. A sample, fictitious patient data for the purpose of testing was configured to a private network. A smart contract was created in the Ethereum state and tested by measuring the time to insert and query patient data. Results Testing with a private, Proof of Authority (PoA) network required only 191 milliseconds and 890 MB of memory per insertion to insert 50 records while inserting 350 records required 674 milliseconds and similar memory per insertion, as memory per insertion was nearly constant with the increasing number of records inserted. Retrieving required 912 MB for a query involving all three fields and no wildcards in a 350-record database. Only 883 MB was needed to procure a similar observation from a 50-record database. Conclusion This study exemplifies the use of smart contracts for efficient retrieval/insertion of COVID-19 patient data and provides a case use of secure and efficient data logging for sensitive COVID-19 data.
As promising privacy-preserving machine learning technology, federated learning enables multiple clients to train the joint global model via sharing model parameters. However, inefficiency and vulnerability to poisoning attacks significantly reduce federated learning performance. To solve the aforementioned issues, we propose a dynamic asynchronous anti poisoning federated deep learning framework to pursue both efficiency and security. This paper proposes a lightweight dynamic asynchronous algorithm considering the averaging frequency control and parameter selection for federated learning to speed up model averaging and improve efficiency, which enables federated learning to adaptively remove the stragglers with low computing power, bad channel conditions, or anomalous parameters. In addition, a novel local reliability mutual evaluation mechanism is presented to enhance the security of poisoning attacks, which enables federated learning to detect the anomalous parameter of poisoning attacks and adjust the weight proportion of in model aggregation based on evaluation score. The experiment results on three datasets illustrate that our design can reduce the training time by 30% and is robust to the representative poisoning attacks significantly, confirming the applicability of our scheme.
Recently, access control systems have incorporated blockchain technology to overcome inherent issues in conventional access control schemes in IoT. However, when applied to the smart home system, the existing blockchain-based access control systems generally have limitations, such as limited distribution, lack of security, and privacy. Here, we provide a solution based on the Hyperledger Fabric platform. This solution includes a trust management center and multiple smart contracts. Specifically, an identity contract is used for device registration. The trust contract records the access behavior and evaluation value of the device, from which the trust management center calculates the trust value of the device. And the access control contract makes logical judgments on the access request. Finally, we designed an experiment to verify the algorithm of the trust management center. The function of the smart contract is testified, which ensures that the T-DCAC model can be applied to the smart home environment.
Xin Hao, Phee Lep Yeoh, Zijie Ji, Yao Yu · 6 authors
In this article, we present practical stochastic modeling and detailed performance analysis of our double blockchain (DBC) from Haoet al.(2021) for secure information and reputation data management in large-scale wireless Internet of Things (IoT) networks. Specifically, the DBC is a private blockchain deployed on a cloud-fog communication network which is composed of an information blockchain (IBC) storing large amounts of IoT data in the cloud layer and a reputation blockchain (RBC) storing reputation data of the IoT devices in the near-terminal fog layer. The locations of the fog layer nodes are modeled according to a random Poisson point process (PPP) over a given 2-D area to approximate the stochastic property of real-world wireless node deployments. Furthermore, we assume that the number of IoT devices transmitting to the fog nodes also follow a random Poisson distribution. Based on these models, we derive novel closed-form expressions for the storage size, transmission latency, and tampering time of the IoT fog nodes in our DBC architecture. Numerical simulations highlight high storage scalability, low latency, and superior security of the DBC design, and provide insights into the performance gains for different fog node and IoT device densities.
With the rapid deployment of Internet of Things (IoT) devices in various industries and fields, the massive amount of data produced by these devices can yield greater value through sharing. A critical challenge in the data-sharing process is ensuring that the data are high quality. However, the quality of data provided by a large number of IoT devices is impacted by the variability of factors contributing to the data quality (DQ). Effective and safe sharing of perception data by the limited resources of IoT devices is a problem worth investigating. In this article, we propose a smart contract-based and DQ-driven incentive mechanism. First, a smart contract is proposed to realize security in the data-sharing process, while the proposed DQ evaluation mechanism ensures the quality of the shared data. Second, a two-layer Stackelberg game of nested coalitional (TLSNC) scheme is designed to obtain the maximum overall social welfare according to the trust score obtained during DQ evaluation while satisfying the limitation of loose and insufficient computing resources. Moreover, we designed a smart contract for automatic execution of the data-sharing transaction and used a trusted execution environment (TEE) to complete the security calculation of shared data. Finally, the numerical results reveal the effectiveness of the DQ evaluation mechanism and the security of our TEE-based model. Based on the proposed scheme, sustainable incentives for user participation and high-quality data sharing can be achieved. In addition, our system can significantly improve the overall social welfare compared to traditional solutions.
Mukhammaddiyor Khaydaraliev, Min-Hyung Rhie, Ki‐Hyung Kim
Internet of Things (IoT) devices is being conveyed at an enormous scope, with many experts predicting the deployment of 500 billion devices by 2030. Because the IoT devices have limited capabilities and are being deployed in a large amount shortly, current traditional IoT platforms may not be able to handle access control effectively in terms of scalability, reliability, and real-time response. On the other hand, with the advancement of blockchain technology, edge computing, and role-based IoT networks, we can produce a secure access control scheme in a distributed manner with higher reliability, scalability, and real-time response. Therefore, we proposed a decentralized IoT access control system based on blockchain, fog nodes, and the role of things utilizing Ethereum smart contracts for secure device-to-device access. The paper presents overall platform architecture, use case scenarios, crucial evaluation results identified with security analyses, and implementation of the proposed work.
Eranga Bandara, Sachin Shetty, Abdul Rahman, Ravi Mukkamala · 6 authors
Federated learning is a collaborative/distributed machine learning system which is designed to address the privacy issues in centralized machine learning systems. The transparency and provenance of a machine learning model are important aspects of federated learning systems since they impact peoples’ lives in various domains (e.g., from healthcare to personal finance to employment). However, most of the existing federated learning systems deal with centralized coordinators which are vulnerable to attacks and privacy breaches. Also, they do not provide any standard transparency and provenance mechanisms for the resulting models. In this paper, we propose a blockchain and Model Card-based integrated federated learning system "Bassa-ML" providing enhanced transparency and trust for the models. Model parameter sharing, local model generation, model averaging, and model sharing functions are implemented using smart contracts. The generated models, model training information, and model reports are stored in the blockchain ledger as Model Card Objects. This results in enhanced transparency and auditability to the federated learning process.
Norah Alrebdi, Abdulatif Alabdulatif, Celestine Iwendi, Zhuotao Lian
Central management of electronic medical systems faces a major challenge because it requires trust in a single entity that cannot effectively protect files from unauthorized access or attacks. This challenge makes it difficult to provide some services in central electronic medical systems, such as file search and verification, although they are needed. This gap motivated us to develop a system based on blockchain that has several characteristics: decentralization, security, anonymity, immutability, and tamper-proof. The proposed system provides several services: storage, verification, and search. The system consists of a smart contract that connects to a decentralized user application through which users can transact with the system. In addition, the system uses an interplanetary file system (IPFS) and cloud computing to store patients' data and files. Experimental results and system security analysis show that the system performs search and verification tasks securely and quickly through the network.
Traditional centralized access control faces data security and privacy problems. The core server is the main target to attack. Single point of failure risk and load bottleneck are difficult to solve effectively. And the third-party data center cannot protect data owners. Traditional distributed access control faces the problem of how to effectively solve the scalability and diversified requirements of IoT (Internet of Things) applications. SCAC (Smart Contract-based Access Control) is based on ABAC (Attributes Based Access Control) and RBAC (Role Based Access Control). It can be applied to various types of nodes in different application scenarios that attributes are used as basic decision elements and authorized by role. The research objective is to combine the efficiency of service orchestration in edge computing with the security of consensus mechanism in blockchain, making full use of smart contract programmability to explore fine grained access control mode on the basis of traditional access control paradigm. By designing SSH-based interface for edge computing and blockchain access, SCAC parameters can be found and set to adjust ACLs (Access Control List) and their policies. The blockchain-edge computing combination is powerful in causing significant transformations across several industries, paving the way for new business models and novel decentralized applications. The rationality on typical process behavior of management services and data access control be verified through CPN (Color Petri Net) tools 4.0, and then data statistics on fine grained access control, decentralized scalability, and lightweight deployment can be obtained by instance running in this study. The results show that authorization takes into account both security and efficiency with the “blockchain-edge computing” combination.
Machine learning (ML) has been pervasively researched nowadays and it has been applied in many aspects of real life. Nevertheless, issues of model and data still accompany the development of ML. For instance, training of traditional ML models is limited to the access of data sets, which are generally proprietary; published ML models may soon be out of date without an update of new data and continuous training; malicious data contributors may upload wrongly labeled data that leads to undesirable training results; and the abuse of private data and data leakage also exit. With the utilization of blockchain, an emerging and swiftly developing technology, these problems can be efficiently solved. In this paper, we survey the convergence of collaborative ML and blockchain. Different ways of the combination of these two technologies are investigated and their fields of application are examined. Discussion on the limitations of current research and their future directions are also included.
Priyan Malarvizhi Kumar, Bharat S. Rawal, Jiechao Gao
The development of sensor technologies and an explosion of the inexpensive electronic circuit, the Internet of Things (IoT) is emergent as an encouraging innovation to comprehend sustainable smart city. Smart cities can bid various intelligent applications like smart transportation, smart banking, and industry 4.0, among others, to boost citizens' life quality. However, security is one of the critical problems of a smart city. These emerging smart infrastructure and applications based on IoT can benefit users only if vital private and secure features are guaranteed. Hence, in this paper, Blockchain-enabled Privacy-Preserving Access Control System (BPACS) has been suggested for IoT data in a smart city environment. This study utilizes blockchain methods to construct a reliable and secure data-sharing policy between numerous data providers, where IoT information is encoded and then verified on disseminated ledgers. Furthermore, this study design protected construction blocks, like secure comparison and secure polynomial multiplications, by retaining cryptosystems and build a secure Support Vector Machine (SVM) and Principle Component Analysis (PCA) training algorithms. Hard security analysis proves that the suggested model guarantees the privacy of the sensitive information for every data provider and the SVM and PCA model variables for data analysts.