Metaverses may present innovative channels for business and finance , education, and workplaces. Drawing from the Diffusion of Innovation Theory and the Unified Theory of Acceptance and Use of Technology (UTAUT) as well as the literature on digital equality, this research attempts to unravel the dynamics of digital equality and trust in AI-empowered metaverses for various industry sectors. Three cross-sectional surveys ( N Total = 1086) examined US Internet users' intention to adopt metaverses for business, education, and workplaces. Structural equation models were estimated using Mplus 8.8. Study 1 indicates dynamic relationships among digital equality (commerce dimension), blockchain transparency, privacy concerns, and adoption intention. Study 2 shows dynamic associations among digital equality (educational, social, and political dimensions), digital adaptability, loneliness, and adoption intention. Study 3 demonstrates dynamic interconnections among digital equality (labor, government, and health dimensions), digital adaptability, identity threat, and adoption intention. Across three datasets, trust mediates the relationship between digital equality and adoption intention. Theoretical contributions to the emerging literature on decentralized finance (DeFi), AI-driven digital transformation, and AI-VR-convergence are discussed. DeFi businesses, enterprises, policy makers, educators, professional training providers, and workforce developers need to consider third-level digital (in)equality and digital adaptability in developing equitable, sustainable, and inclusive user experience (UX) in AI-empowered metaverses.
This study aims to identify and assess AI and blockchain solutions in relation to journalistic authenticity and integrity. Central to our exploration is the role of blockchain technology in verifying content provenance. As a key component of a global Web3 framework, blockchain could offer a foundation for authenticating the origins of content. In this article, we explore how blockchain, with its capacity for creating immutable and cryptographically signed data records, could be applied by journalists to verify photos, videos and documents. Our analysis identified nine blockchain-based solutions for content verification, with three platformsâAttestiv, OriginStamp, and Fact Protocolâshowing particular promise for journalistic workflows. We conclude that while AI and blockchain solutions are currently available to journalists today, they require high-level technical expertise. Many media companies are now venturing into this field as well, thus affecting the professional role of journalists in general. In our study, it is evident that integrating AI and blockchain in journalism is not merely about adopting new tools but also about understanding their broader implications for journalism as a profession and the convergence in society. The focus must remain on enhancing journalistic integrity and public trust to ensure that these technological advances benefit the field of journalism and, by extension, the democratic processes it supports.
Md. Rafiqul Islam, Muhammad Haseeb, Hina Batool, Nasir Ahtasham ¡ 5 authors
The integrity of global elections is increasingly under threat from artificial intelligence (AI) technologies. As AI continues to permeate various aspects of society, its influence on political processes and elections has become a critical area of concern. This is because AI language models are far from neutral or objective; they inherit biases from their training data and the individuals who design and utilize them, which can sway voter decisions and affect global elections and democracy. In this research paper, we explore how AI can directly impact election outcomes through various techniques. These include the use of generative AI for disseminating false political information, favoring certain parties over others, and creating fake narratives, content, images, videos, and voice clones to undermine opposition. We highlight how AI threats can influence voter behavior and election outcomes, focusing on critical areas, including political polarization, deepfakes, disinformation, propaganda, and biased campaigns. In response to these challenges, we propose a Blockchain-based Deepfake Authenticity Verification Framework (B-DAVF) designed to detect and authenticate deepfake content in real time. It leverages the transparency of blockchain technology to reinforce electoral integrity. Finally, we also propose comprehensive countermeasures, including enhanced legislation, technological solutions, and public education initiatives, to mitigate the risks associated with AI in electoral contexts, proactively safeguard democracy, and promote fair elections.
Ken Huang, Youwei Yang, Fan Zhang, Xi Chen ¡ 5 authors
Chapter 5 explores the interconnected ecosystem enabling feature-rich smart contracts. It first covers oracles, which provide external data to blockchains, outlining use cases, design considerations, and business decisions around oracle solutions. It then discusses interoperability, explaining atomic swaps and various cross-chain bridge designs such as lock/mint, liquidity pools, and zkBridge for trustless transfers. Next, it examines the ecosystem for mitigating Miner Extractable Value (MEV), categorizing solutions into auctions, time/content-based ordering, and application-specific designs. It also highlights other vital components such as user-friendly wallets, performant RPC nodes, governance mechanisms for collective decision-making, and privacy-preserving techniques such as zero-knowledge proofs. By delving into these key building blocks, this chapter offers readers a comprehensive understanding of the dynamic smart contract ecosystem. It emphasizes how components such as oracles, bridges, MEV mitigation, governance, and privacy-preservation enable richer functionality, interoperability, fairness, and user experience, shaping decentralized applicationsâ future.
Smart contracts form the core of Web3 applications. Contracts mediate the transfer of cryptocurrency, making them irresistible targets for hackers. We introduce ASP, a system aimed at easing the construction of provably secure contracts. The Asp system consists of three closely-linked components: a programming language, a defensive compiler, and a proof checker. The language semantics guarantee that Asp contracts are free of commonly exploited vulnerabilities such as arithmetic overflow and reentrancy. The defensive compiler enforces the semantics and translates Asp to Solidity, the most popular contract language. Deductive proofs establish functional correctness and freedom from critical vulnerabilities such as unauthorized access.
Christian Esposito, Gianluca Attademo, Francesco Miano
At present, blockchain solutions are drawing the attention of researchers and industrial practitioners due to their potential cross-sectorial applications beyond finance where it emerged, to implement decentralized data handling, guarantee data confidentiality and integrity using cryptography, and create trust in digital data. In Defence, as in other domains, blockchain is a promising solution for manufacturers and suppliers to âhardenâ the supply chain and logistics by improving operational performance through the entire life cycle, from raw material to retired assets. Furthermore, the decentralized data management has attracted interest to device improved battlefield operations management, border protection, swarm assistance for rescue, as well as military, operations. As the domain is starting to be more dependent on blockchain, and its decentralized and algorithmic-centered decision-making, people are starting the question the ethics of such a solution, following the similar debate around AI applications in general, and in defence also. This paper presents the overall topic and the late conclusions eminent researchers have reached so far.
Blockchain Technology Applications and Security
Ethics and Social Impacts of AI
Neuroethics, Human Enhancement, Biomedical Innovations
In museums, heritage, and non-profit cultural organisations, thought leadership on the ethical implications of AI is gathering speed. Notable initiatives include the Network of European Museum Organisations (NEMO)'s efforts to address the uptake of AI in museums (2024) and the UK's Arts and Humanities Research Council's BRAID programme dedicated to integrating Arts and Humanities research into the 'Responsible AI' ecosystem (2022). This is a fast-evolving area with new analysis and calls to action appearing with frequency. As yet however, little attention has been given to how AI is emotionally impacting lived experiences of cultural workers as organisations seek to operationalise it. This paper highlights the need to consider such impacts, as well as the general-purpose technologies AI builds upon, such as biotechnology and a connected ecosystem of devices, on cultural workers and their practices. The convergence of these technologies signals what futurist Amy Webb calls a technology "supercycle" with far-reaching implications (Aiello, 2024).This paper does not present new empirical evidence but rather portends the need for more research on the relationship between wellbeing, AI, and work in cultural organisations. Based in the UK and the Netherlands, the authors are researcher-practitioners who explore the impact of digital technology on cultural workforces. This paper critically anticipates the implications of AI on those working on the ground in cultural organisations. Our ideas and examples draw from the UK, Europe and the United States, but we hope they speak to experiences of cultural workers across the globe.In what follows, a strategic foresight method known as the "Futures Triangle" (Inayatullah, 2023) will be deployed to consider the plausible future of AI-driven cultural work that might emerge between three pushing and pulling cornersthe past, the present, and the futureeach of which is shaping the adoption of AI in our cultural organisations. This framework helps raise awareness of the trends, drivers, and signals of which cultural organisations need to be aware to ensure an integration of AI that empowers workers to engage effectively while addressing the ethical dilemmas involved. This structure recognises the history that has shaped our current decisions, determines what to carry forward or leave behind, and confronts present challenges. We must consider the impact of our choices and how they will resonate into the future, ensuring they reflect the people and context of multiple possible futures.In Future Thinking, trends refer to long-term patterns that can be carried forward into the future. There are two trends that have impacted cultural work, wellbeing, and AI: digital transformation and decolonisation.The recent history of digital transformation in museums, heritage and cultural organisations is convoluted. Many associate momentum to a 2017 review of English museums which argued for "dynamic data for dynamic collections" (DCMS, 2017: 64). The following year, the UK's Department for Culture, Media, and Sport (DCMS) launched Culture is Digital, a report calling for "practitioners and organisations across the cultural and tech sectors" (2018: 17) to develop "digital thinking" (ibid: 9) stating that organisations felt "held back" by a lack of infrastructure, resources, digital skills and leadership training, resulting in "a fragmented approach" to technology (ibid: 5). Despite digital developments in many cultural organisations the story remained patchy, with funding tending to prioritise "shiny" short-term over long-term infrastructure projects, an ongoing deficit of digital literacy, cataloguing backlogs, and a predominance of non-interoperable systems and formats. This often led to reluctance, fear, and apathy when it came to instilling digital change up to and since the Covid-19 pandemic. As a respondent in a survey on AI in heritage organisations stated: even if AI has the potential "to revolutionise the heritage sector", there remain "real problems that are affecting us, like skills shortages, funding shortages and volunteer shortages" (Oates, 2023). They continued: "the obsession with 'digital' is unhelpful, especially when digital is so poorly defined that the adjective is arbitrarily used as a meaningless noun" (ibid). However, as John Stack, Director of Digital Innovation and Technology at The National Gallery, notes: "Unlike previous recent waves of technology (crypto currency, web3, NFTs, etc.) the AI revolution feels different -there's a sense in which it seems likely to change many things, but we don't fully understand the potential and implications" (Stack, J. (2024) Email to Sophie Frost, 9 January).Trend 2: Decolonisation Often founded on colonial principles, cultural organisations carry legacies that have both hindered and guided their embrace of new technologies. Decolonisation initiatives have burgeoned in recent years with bodies such as UNESCO, International Council of Museums (ICOM), American Alliance of Museums, and Museums Association supporting the need to "recognise the integral role of empire in museumsfrom their creation to the present day" (Museums Association, 2024). While actions for enhanced traceability and diligence in the acquisition of cultural objects has grown, there has been less vigilance regarding the integration of emerging technologies which invite new, equally problematic, forms of coded gaze into legacy institutions. Despite conversations amongst museum and heritage practitioners on the dangers of commercial technologies (Pratty, 2019), there have been few practical attempts to source long-term ethical alternatives. As Oonagh Murphy, editor of this Issue, points out: there is a need to "engage in a broader conversation about the power and impact" of digital tools and products (2024: 73). NEMO has implied that museums have the "potential" to be "partners in the development of ethical practices related to emerging technologies" ( 2024), but there is more work to be done to link decolonisation efforts with the integration of AI.Drivers are broad long-term forces that are likely to have a significant impact on the future. Drawing on research exploring AI in the global workplace, we locate the following as shaping how we imagine the signals to emerge in the future.Research suggests that AI will predominantly result in augmentation rather than automation (International Labour Organization, 2024: 6). Clerical work will be most exposed to automation because of generative AI, with 24% of tasks "highly exposed" (ibid). This is a gendered issue. As women tend to be overrepresented in the clerical field, women's jobs may be "twice as likely to be exposed" as men's (Muldoon et al., 2024: 53). Museum and heritage environments have long been recognised as "pink collar" workplaces (GEMM, 2019) whereby women undertake most administrative roles. In the USA, 58.6% of the workforce is female across archival, curatorial and museum technician roles (DataUSA, 2022) while a UK report on the arts, culture and heritage workforce found only 34% of women occupy managerial or director positions with the majority in junior roles (PEC, 2024). Jobs in areas such as collections management could have large components of their roles augmented by AI. Large Language Models excel at "formal, standardised tasks with clear objectives and large amounts of text data" (Muldoon et al. 2024: 53). In cultural organisations, this form of digital data entry is typically done by women on relatively low pay (Frost, 2022). Generative AI is also valuable in content creation, meaning that marketing and social media roles may be affected.Driver 2: Demand for AI Literacy Discussions of AI workplace integration emphasise reskilling workforces to support its effective use. In the context of cultural organisations, stakeholders are recognising AI literacy as an opportunity to reshape digital work, introduce new efficiencies, whilst emphasise the value of employee agency to digitally experiment through AI methods. Industry specialist Jocelyn Burnham, who offers AI workshops for the cultural and creative sectors, recognises AI as a tool for experimenting with what new technologies might offer, rather than being anxious about how they might disrupt the status quo. AI prompts us to ask more critically engaged questions, to understand our own needs and the needs of audiences in different ways. Large Language Models (LLMs) are helping workforces augment their digital skills, enabling those who have not been able to use new technologies so easily in the past to do so, whilst helping staff learn in different ways (Burnham, J. (2024) Interview with Sophie Frost, 17 January 2024).There is a flipside. The International Labour Organization notes that some parts of the world are at risk of an "AI divide" whereby "high income nations disproportionately benefit from AI advancements" (2024: 5). This could be the case in the cultural field also where AI training is inconsistent. As Angie Judge, CEO of Dexibit, notes: "AI will quickly create a world of the haves and have nots. I hope the museum sector will find itself on the right side of that equation" (Styx, 2024). For Stack, "best practice is still emerging and much of the work is 'bottom up' with museum practitioners exploring the potential, rather than top down with managers and leaders directing this work". He continues: "museums are starting to recognise the need for a policy document that is set for internal review every six months or so, while other internal museum policies often go years before review" (Stack, J. ( 2024) Email to Sophie Frost, 9 January). Such need for agility in the creation of AI policy has been recognised by the UK government also: their Generative AI Framework for HMG describes itself as "necessarily incomplete and dynamic" (Gov.uk, 2024).The most consequential driver for cultural organisations may be the inherent bias embedded within and potential misuse of LLM training data. Many have documented the ways AI datasets have been drawn through the rules and algorithms of those who trained them, leading to race and gender discrimination across multiple online platforms (Leavy et. al., 2020;Buolamwini, 2023). Much of this software has been invested in by legacy tech companies and it is widely recognised that technological development is under the control of those "with strong imperatives to continue expanding their operations and increasing their profits" (Muldoon et al. 2024: 161). New government guidelines for the public sector emphasise the need, when working with AI, "to establish and communicate how you will address ethical concerns from the start" (Gov.uk, 2024) but how can smaller, less powerful organisations reclaim power when limited by the options available to them? Helpfully, the European Commission's recent foresight report focused on the future of Big Tech in Europe and its implications for research and innovation (R&I). Using a scenario-based approach, it offers recommendations to guide the EU's R&I policy. Significantly, all four imagined scenarios indicated "varieties of high tech capitalism" with only one emphasising the prosperity of civil society over Big Tech (2024: 8). Cultural organisations can use such resources to understand the current landscape and strategically respond not only to present developments but anticipate alternative futures of information control.There is an additionally troubling aspect regarding the increased risk of copyright infringement for cultural organisations who make income from their picture libraries through licensing for reproduction and commercial research. This issue gained attention in the UK through high-profile publications such as the House of Commons Culture, Media and Sport Committee report on Content Remuneration, which calls on government "to ensure that creators have proper mechanisms to enforce their content and receive fair compensation when their works are used by AI systems" (House of Commons, 2024). If this driver is not managed proactively, what might be its effects on income in years to come?The exponential growth of AI-related employment has surfaced questions regarding its hidden human costs (Muldoon, Graham & Cant, 2024;Gray & Suri, 2022;Catanzariti et al., 2021). Attention is being paid to how human labour plays a pivotal role in enabling AI technology, particularly generative AI, through the paid, piecework of collecting, processing, and labelling of datasets needed by models such as ChatGPT for training. Our research has observed the emotional toll of digitally driven labour in museums, heritage, and cultural organisations (Frost, 2021 and2022;Vargas, 2020). Daily tasks such as establishing suitable naming conventions, cleaning up and figuring out problems in the data, and dealing with acquisition backlogs, require persistence, care, clarity, and impartiality. Those who promote digital change experience personal, psychological costs and ethical dilemmas consistent with other types of cultural and creative work (see Banks, 2017;Belfiore, 2021). When it comes to AI, the concern of many digital staff is, as Steven Franklin, Social Media Manager at The Royal Institution explains, "if you've got technology that is inherently designed to increase individuals' productivity then the demands of the job will probably go up with it. So, you're going to be expecting more people to do more" (Franklin, S. ( 2024) Interview with Sophie Frost, 12 January).A recent study explored the "dark side effects of digital working" of 142 workers, specifically their levels of stress, overload, anxiety and Fear of Missing Out on Information (Marsh et. al., 2024). It found that "employees who are overloaded by information or worried about missing out on it in the digital workplace face risks to their well-being at work" (2024: 12) and stated that greater consideration of the digital workplace "is essential to not only employee productivity but also wellbeing in modern organisations" (ibid). Cultural workplaces similarly need to reflect on how AI will impact well-being, and how the information overload of working with new technology has emotional consequences for workers.It is easy to suggest that AI poses a threat to those who have spent years honing their skills as cultural workers, drawing on data suggesting that those with higher qualifications are more exposed to AI (Department for Education 2023: 18). We propose instead that cultural roles will be positively augmented by AI, creating opportunities for better discoverability and searchability in daily operations as well as in creative reuse and reimagination within the interpretation of collections and audience engagement. AI will need to be accommodated and understood within all job roles in the cultural workplace; it will become the responsibilityand the possibility -of all (and yes, this will require consistent resourcing of time, people, energy, and moneyas does all digital maturity work).More concerning for us is a wider existential issue: if AI, as has been argued by many in the creative industries, is devaluing creativity as a specifically human endeavour, will this deprioritise the importance of the institutions that care for it? We have heard outcries, in areas such as screenwriting, music production, video games and the visual arts regarding the use of generative AI and other digital technologies to replicate human creative outputs (SAG-AFTRA, 2024;Weiss, 2023;The Art Newspaper, 2023). As the quality of generative AI develops, will there not be a moment when even experts are unable to distinguish between AI and human generated cultural artefacts? What might this mean for history itself, for the historical record? Nick Bostrom's Deep Utopia ( 2024) offers one answerhe invites us to rethink the complexity of utopia and confront the unintended consequences of our pursuit for better representation and justice, challenging the binary thinking of utopian vs. dystopian outcomes. He argues that true progress instead requires moving beyond fixed notions of perfection to consider multifaceted possibilities and risks of future realities.Signals represent small, local innovations or disruptions that have the potential to grow in scale and distribution (Howard, 2021). Below are five signals, posed as 'What if?' questions, that critically anticipate how cultural workplaces might tackle the present and reimagine a future with AI. "What if" questions encourage creative thinking, challenge assumptions, and open alternative possibilities. For futurist Peter Schwartz, they are part of scenario planning, a strategic tool to prepare for uncertainty by imagining diverse future scenarios (1991).1. What if we developed greater "coopetition" -cooperating with our competitors to achieve a common goal -as we integrate AI in our cultural workplaces? Our sector must radically cooperate with other stakeholders on the ethics of AI -from corporations to governments, from other cultural organisations to grassroots bodies.workplaces? The integration of AI in our cultural workplaces has required on-the-job learning. New technological developments mean greater demand for new digital literacies in our workplaces; it is imperative to embrace lifelong learning and the upskilling of workforces.technology, climate change, and social justice, and acknowledged more openly how they in our cultural workplaces? are trends and thinking about can reshape and of and What if we that the emotional and psychological of digital work to employment practices in our cultural workplaces? the wellbeing of cultural workers and and by recognising the human AI, cultural organisations will ensure that AI both work and public What if we the enabling AI, their impact on cultural workers, our role as cultural to the global conversation on AI in ways that reflect and lived experience in our cultural workplaces? This encourage us to the AI development and consider how cultural can their to guide practices that the future of the cultural is needed is more empirical research on how employee wellbeing and job quality in to AI innovation are being in museums, heritage and cultural more with other parts of the cultural and creative as we operationalise and more at the of leadership and -of how AI and within a of and cultural we need to learn to better and this ensuring that the integration of AI and lived experiences of cultural workers rather than
Xiaohai Ji, Zequan Zhou, Ting He, Xiling Luo ¡ 6 authors
Blockchain-based Internet of Drones (B-IoD) is a digital infrastructure that utilizes blockchain for the secure management and operation of drones. Through smart contracts (immutable on-chain programs), B-IoD can automate a variety of applications such as drone logistics, data analysis, and situation monitoring. In B-IoD systems, miners provide computing power to generate new blocks. This leads to contracts prone to blockchain-level vulnerabilities, where miners may control the transaction order and block information in new blocks to jeopardize system stability. Auditing blockchain-level vulnerabilities in contracts is a crucial problem. Existing methods employ symbolic execution to audit contracts. However, inaccurate execution modeling, such as memory and storage, leads existing methods to have inferior detection accuracy. For such, in this paper, we propose an effective static audit method for detecting blockchain-level vulnerabilities in smart contracts of B-IoD. Our method accurately models the executive data structure to capture contract state changes and uses symbolic execution to search for execution paths. We implement an automatic audit tool, ScAudit, which inputs Solidity source code and reports if the contract is vulnerable to blockchain-level vulnerabilities. We evaluate ScAudit on real-world contracts and compare it with existing tools. The experiment results show that ScAudit performs well and accurately detects blockchain-level vulnerabilities.
Caspar Barnes, Mateo Aboy, Timo Minssen, Jemima Winifred Allen ¡ 7 authors
Participation in research is supposed to be voluntary and informed. Yet it is difficult to ensure people are adequately informed about the potential uses of their biological materials when they donate samples for future research. We propose a novel consent framework which we call "demonstrated consent" that leverages blockchain technology and generative AI to address this problem. In a demonstrated consent model, each donated sample is associated with a unique non-fungible token (NFT) on a blockchain, which records in its metadata information about the planned and past uses of the sample in research, and is updated with each use of the sample. This information is accessible to a large language model (LLM) customized to present this information in an understandable and interactive manner. Thus, our model uses blockchain and generative AI technologies to track, make available, and explain information regarding planned and past uses of donated samples.
Open access
Ethics in Clinical Research
Artificial Intelligence in Healthcare and Education
S. Balaji, Ram Dantu, Kritagya Upadhyay, Thomas McCullough
Many people find the legal system to be convoluted and resource-intensive with all of the complications, which often derive from the vagueness and ambiguity of legal texts, that arise in its processes. Oftentimes, legal processes become inconvenient or even inaccessible to parts of the general population. The integration of artificial intelligence (AI) and blockchain technology into legal processes, particularly in the interpretation of contract transactions, promises to revolutionize the legal field by enhancing efficiency and reducing human intervention. The conversion of legal contracts into smart contracts specifically has the power to make legal transactions auto-executable and instantaneous. However, this convergence introduces a significant challenge in how to automate the process of converting a legal contract, written in text, into a smart contract, written in code. This paper presents a comprehensive evaluation of how artificial intelligence can achieve complete automation of this conversion by generating legal contract interpretations and employing a dual-framework analysis based on the metrics of Enforceability and Acceptability. Through an in-depth examination of the opinions of legal professionals and AI-generated contract interpretations, we explore the extent to which AI can reliably interpret the vagueness and ambiguity in legal texts through interpretations and translate legal language into smart contract code while adhering to legal standards and ethical considerations. This paper contributes to the ongoing discourse on the role of AI and smart contracts in law, proposing a strategy to make the legal system more accessible and offering insights for legal practitioners, AI developers, and policymakers on navigating the complexities of AI-driven legal interpretations.
ABSTRACT Smart contracts are turingâcomplete computer programs running on blockchains. Like traditional programs, smart contracts are also vulnerable. However, unlike traditional programs, it is very difficult to modify smart contracts once they are deployed on the blockchain. Therefore, reducing potential vulnerabilities in contracts before deployment to the blockchain is very important. The existing smart contract detection tools mostly fail to fully consider the complex control flow relationships within smart contracts, leading to false positives and false negatives. To address these problems, we propose FlawCheck, a vulnerability detection tool based on symbolic execution. First, it compiles smart contract source code into bytecode. Then, it disassembles bytecode into an opcode sequence, building the dependencies of contract control flow. Next, it performs preliminary analysis on the information generated during the simulated execution on the Ethereum virtual machine to identify suspicious vulnerability paths. Finally, it detects these suspicious paths by using symbolic execution. We verified that FlawCheck can detect five types of smart contract vulnerabilities. Experimental results on a dataset of 13016 real contracts shows that FlawCheck has higher accuracy than other tools.
This paper presents an approach for the verification of access control in smart contracts written in the Digital Asset Modeling Language (DAML). The approach utilizes Colored Petri Nets (CPNs) and their analysis tool CPN Tools. It is a model-driven-based approach that employs a new meta-model for capturing access control requirements in DAML contracts. The approach is supported by a suite of tools that fully automates all of the steps: parsing DAML code, generating DAML model instances, transforming the DAML models into CPN models, and model checking the generated CPN models. The approach is tested using several DAML scripts involving access control extracted from different domains of blockchain applications.
The vision of Web3 is to improve user control over data and assets, but one challenge that complicates this vision is the prevalence of non-transparent, scam-prone applications and vulnerable smart contracts that put Web3 users at risk.While code audits are one solution to this problem, the lack of smart contracts source code on many blockchain platforms, such as Sui, hinders the ease of auditing.A promising approach to this issue is the use of a decompiler to reverse-engineer smart contract bytecode.However, existing decompilers for Sui produce code that is difficult to understand and cannot be directly recompiled.To address this, we developed the SuiGPT Move AI Decompiler (MAD), a Large Language Model (LLM)-powered web application that decompiles smart contract bytecodes on Sui into logically correct, human-readable, and recompilable source code with prompt engineering.Our evaluation shows that MAD's output successfully passes original unit tests and achieves a 73.33% recompilation success rate on real-world smart contracts.Additionally, newer models tend to deliver improved performance, suggesting that MAD's approach will become increasingly effective as LLMs continue to advance.In a user study involving 12 developers, we found that MAD significantly reduced the auditing workload compared to using traditional decompilers.Participants found MAD's outputs comparable to the original source code, improving accessibility for understanding and auditing non-open-source smart contracts.Through qualitative interviews with these developers and Web3 projects, we further discussed the strengths and concerns of MAD.MAD has practical implications for blockchain smart contract transparency, auditing, and education.It empowers users to easily and independently review and audit non-open-source smart contracts, fostering accountability and decentralization.Moreover, MAD's methodology could potentially extend to other smart contract languages, like Solidity, further enhancing Web3 transparency.
Many smart contracts are prone to exploits, which has given rise to analysis tools that try to detect and fix vulnerabilities. Such analysis tools are often trained and evaluated on limited data sets, which has the following drawbacks: 1. The ground truth is often based on the verdict of related tools rather than an actual verification result; 2. Data sets focus on low-level vulnerabilities like reentrancy and overflow; 3. Data sets lack concrete exploit examples. To address these shortcomings, we introduce XploGen, which uses a model-based oracle specification of the business logic of the smart contracts to synthesize valid exploits using LLMs. Our experiments, involving 104 synthesized vulnerability-exploit pairs, demonstrated a 57% success rate in exploiting targeted aspects of the contract. They achieved exploit efficiency with an average of only 3.5 transactions per exploit, highlighting the effectiveness of our methodology.
The detection of vulnerabilities in smart contracts remains a significant challenge. While numerous tools are available for analyzing smart contracts in source code, only about 1.79% of smart contracts on Ethereum are open-source. For existing tools that target bytecodes, most of them only consider the semantic logic context and disregard function interface information in the bytecodes. In this paper, we propose COBRA, a novel framework that integrates semantic context and function interfaces to detect vulnerabilities in bytecodes of the smart contract. To our best knowledge, COBRA is the first framework that combines these two features. Moreover, to infer the function signatures that are not present in signature databases, we present SRIF (Signatures Reverse Inference from Functions), automatically learn the rules of function signatures from the smart contract bytecodes. The bytecodes associated with the function signatures are collected by constructing a control flow graph (CFG) for the SRIF training. We optimize the semantic context using the operation code in the static single assignment (SSA) format. Finally, we integrate the context and function interface representations in the latent space as the contract feature embedding. The contract features in the hidden space are decoded for vulnerability classifications with a decoder and attention module. Experimental results demonstrate that SRIF can achieve 94.76% F1-score for function signature inference. Furthermore, when the ground truth ABI exists, COBRA achieves 93.45% F1-score for vulnerability classification. In the absence of ABI, the inferred function feature fills the encoder, and the system accomplishes an 89.46% recall rate.
The chapter explores the profound implications of non-fungible tokens (NFTs) within the context of the Web 3.0 movement and the burgeoning metaverse landscape. While NFTs have already found some economic traction in analog settings, their potential is most transformative in a purely digital realm. NFTs offer unparalleled provenance and tradability for digital assets, circumventing centralized intermediaries. The metamorphosis of NFTs and their role in the emergence of the metaverse will determine their full impact. As metaverse platforms evolve, enabled by NFT interoperability and consumer trust, they are poised to reshape the leisure economy and extend into education and employment. The true value of NFTs lies in their integration into an interconnected, dynamic virtual world revolutionizing various facets of society. While existing regulations provide a framework, they will inevitably adapt if and as the metaverse gains prominence, necessitating agile regulatory responses to this transformative landscape.
This chapter explains how truth must be the central goal of any resistance to corporate totalitarianism. Yuval Harari (2011) claims that humanity has been living in a post-truth world for some time and that creating collective narratives is essential for religion, politics, and nation building. He also claims that truth and power cannot travel on the same road together but must diverge because power is not possible without the creation of fictions. But Yuval is a historian and not a scientist. What is fundamental to human progress, and life without the horrors and uncertainties of hunter-gatherer existence and cave dwelling, is technological progress, which is possible only with scientific method and commitment to truth. The first casualty of war is truth, and so indeed, was the response to the COVID-19 pandemic. The challenge for humanity is not to allow truth, and true scientific method, to be dispensed with in the quest for power; otherwise, liberty and comfort will be lost. Developments in distributed ledger technology (DLT) supported by blockchain can be used as a powerful defence of truth and potentially an end to corruption and lies.
In recent years, the use of deep learning models in sensitive applications increased exponentially. There is a strong need of having a mechanisms for a transparent and secure inference verification. To this end, we propose a system leveraging Zero-Knowledge Proofs (ZKPs) and Blockchain technologies to ensure the validity of model inferences without revealing neither input data nor model details.In this paper, we propose a system that is capable of making non-interactive proofs that are verified on a Blockchain thus creating a trustless environment between the prover and the verifier. The solution is based on the Easy Zero-Knowledge Inference (EZKL) [1] library and leverages ZK-SNARK [2] proofs. We provide a detailed descriptions of the systemâs architecture, the implementation as well as the benefits of this approach in enhancing transparency and security in Artificial Intelligence (AI) applications.
Since funds or tokens in smart contracts are maintained through specific state variables, contract audit, an effective means for security assurance, particularly focuses on these variables and their related operations. However, the absence of publicly accessible source code for numerous contracts, with only bytecode exposed, hinders audit efforts. Recovering variables and their types from Solidity bytecode is thus a critical task in smart contract analysis and audit, yet this is a challenging task because the bytecode loses variable and type information, only with low-level data operated by stack manipulations and untyped memory/storage accesses. The state-of-the-art smart contract decompilers miss identifying many variables and incorrectly infer the types for many identified variables. To this end, we propose VarLifter , a lifter dedicated to the precise and efficient recovery of typed variables. VarLifter interprets every read or written field of a data region as at least one potential variable, and after discarding falsely identified variables, it progressively refines the variable types based on the variable behaviors in the form of operation sequences. We evaluate VarLifter on 34,832 real-world Solidity smart contracts. VarLifter attains a precision of 97.48% and a recall of 91.84% for typed variable recovery. Moreover, VarLifter finishes analyzing 77% of smart contracts in around 10 seconds per contract. If VarLifter is used to replace the variable recovery modules of the two state-of-the-art Solidity bytecode decompilers, 52.4%, and 74.6% more typed variables will be correctly recovered, respectively. The applications of VarLifter to contract decompilation, contract audit, and contract bytecode fuzzing illustrate that the recovered variable information improves many contract analysis tasks.
Shelly Grossman, John Toman, Alexander Bakst, Sameer Arora ¡ 6 authors
SMT-based verification of low-level code requires modeling and reasoning about memory operations. Prior work has shown that optimizing memory representations is beneficial for scaling verificationâpointer analysis, for example can be used to split memory into disjoint regions leading to faster SMT solving. However, these techniques are mostly designed for C and C++ programs with explicit operations for memory allocation which are not present in all languages. For instance, on the Ethereum virtual machine, memory is simply a monolithic array of bytes which can be freely accessed by Ethereum bytecode, and there is no allocation primitive. In this paper, we present a memory splitting transformation guided by a conservative memory analysis for Ethereum bytecode generated by the Solidity compiler. The analysis consists of two phases: recovering memory allocation and memory regions, followed by a pointer analysis. The goal of the analysis is to enable memory splitting which in turn speeds up verification. We have implemented both the analysis and the memory splitting transformation as part of a verification tool, CertoraProver, and show that the transformation speeds up SMT solving by up to 120Ă and additionally mitigates 16 timeouts when used on 229 real-world smart contract verification tasks.
Abstract Rarely any study investigates how information gatekeeping through the solutions and services enabled by algorithms, hereafter referred to as algorithmic technologies (AT), creates negative consequences for the users. To fill this gap, this stateâofâtheâart review analyzes 229 relevant articles from diverse academic disciplines. We employed thematic analysis to identify, analyze, classify, and reveal the chain reactions among the negative consequences. We found that the gatekeeping of information (text, audio, video, and graphics) through AT like artificial intelligence (e.g., chatbots, large language models, machine learning, robots), decision support systems (used by banks, grocery stores, police, etc.), hashtags, online gaming platforms, search technologies (e.g., voice assistants, ChatGPT), and Web 3.0 (e.g., Internet of Things, nonâfungible tokens) creates or reinforces cognitive vulnerability, economic divide and financial vulnerability, information divide, physical vulnerability, psychological vulnerability, and social divide virtually and in the offline world. Theoretical implications include the hierarchical depiction of the chain reactions among the primary, secondary, and tertiary divides and vulnerabilities. To mitigate these negative consequences, we call for concerted efforts using topâdown strategies for governments, organizations, and technology experts to attain more transparency, accountability, ethical behavior, and moral practices, and bottomâup strategies for users to be more alert, discerning, critical, and proactive.