Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

889 papersLast indexed Aug 31, 2026
Search papers

Paper index

889 results · page 16 of 38

Clear filters
Jun 4, 2025·IEEE Transactions on Industrial Informatics
61 cites
RAT Ring: Event Driven Publish/Subscribe Communication Protocol for IIoT by Report and Traceable Ring Signature

Gang Xu, Shiyuan Xu, Xinyu Fan, Yibo Cao · 7 authors

The Industrial Internet of Things (IIoT) has been widely studied, which dramatically enhanced the manufacturing efficiency and service elasticity. However, how to ensure the data confidentiality and security in the event-driven publish/subscribe communication model becomes a cumbersome problem. To address this concern, ring signatures have been researched deeply. Nevertheless, existing solutions have large computational burdens and neglect to incorporate reporting and tracing features, which makes it impractical for IIoT. In this way, research focus on designing an efficient report and traceable ring signature is still far-reaching. In this article, we propose RAT ring, a novel report and traceable ring signature, which provides publisher authentication, anonymous communication, reporting, and tracing. To achieve this, we adopt the zero knowledge proof to verify the authenticity of publisher data, and the signature of knowledge to trace the signature. Then, we formalize and prove the security of our scheme. Eventually, through comprehensive performance evaluation, our scheme outperforms prior works by approximately up to 51 times in terms of total computational overhead. These results demonstrate that our design is practical and effective for data privacy-preserving in IIoT.

Access Control and Trust
Cryptography and Data Security
Distributed systems and fault tolerance
Original source
May 26, 2025·2025 28th International Symposium on Real-Time Distributed Computing (ISORC)
0 cites
User-Centric and Privacy-Preserving Attribute-Based Authentication in Healthcare Systems Leveraging zk-SNARKs and Soulbound Tokens

Biagio Boi, Franco Cirillo, Marco De Santis, Christian Esposito

Digital health services for disease diagnosis, followup, and patient empowerment manage data that belongs to a special class of personal information, according to the General Data Protection Regulation (GDPR). For this reason, user authentication and access control are among the key security measures suggested for their protection. However, in the medical context, it is crucial to balance security and privacy support with timeliness and ease of access, which requires innovative solutions. This manuscript introduces an innovative approach leveraging Soulbound Tokens (SBTs) and Zero-Knowledge Proofs (ZKPs), particularly zk-SNARKs, to provide a privacy-aware mechanism for patient authentication in the medical domain. SBTs are utilized within an Attribute-Based Access Control (ABAC) model, ensuring that only eligible patients can access specific medical treatments. In a treatment-specific model, an SBT is issued for each diagnosis, allowing precise control but increasing management complexity. Alternatively, in a diagnosis-categorybased model, SBTs are grouped by diagnostic categories. This reduces the number of tokens and optimizes the space in the patient's wallet but sacrifices some precision in the information. Results demonstrate the timeliness of the proposed approach, with an average time of 6.82s for the release of an SBT and a maximum on-chain verification time of 15.04ms, showcasing their future adoption in a real-time environment, such as the medical context.

User Authentication and Security Systems
Data Quality and Management
Access Control and Trust
Original source
May 21, 2025·2025 Third International Conference on Augmented Intelligence and Sustainable Systems (ICAISS)
2 cites
A Blockchain-based Multi-Metric Trust Management Framework for Secure and Scalable Vehicular Ad-Hoc Networks

R Boopathi, P. Ramakrishnan, M. Jamuna Rani, Pandi Vijayakumar · 6 authors

With Vehicular Ad-Hoc Networks (VANETs) now integrated into intelligent transportation systems, obtaining critical security and trust in such environments where vehicles often exchange sensitive information is becoming a challenge. The paper proposes a new best effort blockchain based trust management framework for the real time data integrity, authentication vehicular identities and malicious behaviors detections. Based on the operating manufacturing environment context, a distributed ledger is applied as a trusted method to immutably store trust scores obtained by the multi-metric evaluation, which include message consistency, transmission reliability, location verification, as well as behavioral patterns. Both direct and indirect trust will be calculated in a hybrid trust model that combines both techniques, and consensus mechanisms will be used to screen transactions and trust updates. The performance in terms of detection of malicious nodes, false positives and whole network stability is compared with the conventional trust models using a simulated VANET environment. A set of comprehensive metrics including latency, throughput, trust convergence, as well as packet delivery ratio are presented, rendering the proposed solution feasible and robust.

Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Access Control and Trust
Original source
May 15, 2025·World Journal of Advanced Engineering Technology and Sciences
0 cites
Decentralized trust frameworks for cross-enterprise integration

K. Muralidharan

Decentralized trust frameworks represent a fundamental transformation in cross-enterprise integration, addressing longstanding challenges in business-to-business interactions. These frameworks leverage Web3 technologies, specifically, Distributed Ledger Technology, Decentralized Identifiers, and Verifiable Credentials to establish inherent trust between organizations without relying on centralized intermediaries. Through cryptographic verification mechanisms, organizations gain enhanced security, verifiable data provenance, reduced reconciliation overhead, and improved operational resilience. The architectural components include a decentralized identity layer providing 99.98% authentication accuracy, credential exchange mechanisms enabling selective disclosure with 99.87% privacy preservation, shared ledger infrastructure ensuring immutable audit trails, and enterprise integration components bridging with existing systems. Implementation patterns such as credential-based API authorization, event-triggered credential issuance, ledger-anchored business processes, and credential-based data exchange deliver substantial improvements in security posture and operational efficiency. Despite significant benefits including 87.3% security enhancement and 73.4% reduction in reconciliation efforts, adoption challenges remain around technical complexity, standards maturity, legacy system integration, and governance frameworks. By addressing these challenges through phased implementation focusing on high-value integration points, organizations can gradually transform their integration landscape toward more secure, transparent, and resilient models that fundamentally change how trust is established in digital business ecosystems.

Open access
Access Control and Trust
Original source
May 12, 2025·The Computer Journal
0 cites
AVPEU: anonymous verifiable presentations with extended usability

Yalan Wang, Liqun Chen, Yangguang Tian, Long Meng · 5 authors

Abstract The World Wide Web Consortium (W3C) has established standards for decentralized identities (DIDs) and verifiable credentials (VCs). A DID serves as a unique identifier for an entity, while a VC validates specific attributes associated with the DID holder. To prove ownership of credentials, users generate verifiable presentations (VPs). To enhance privacy, the W3C standards advocate for randomizable signatures in VC creation and zero-knowledge proofs for VP generation. However, these standards face a significant limitation: they cannot effectively verify cross-domain credentials while maintaining anonymity. In this paper, we present Anonymous Verifiable Presentations with Extended Usability (AVPEU), a novel framework that addresses this limitation through the introduction of a notary system. At the technical core of AVPEU lies our proposed randomizable message-hiding signature scheme. We provide both a generic construction of AVPEU and specific implementations based on Boneh–Boyen–Shacham, Camenisch–Lysyanskaya, and Pointcheval–Sanders signature. Our experimental results demonstrate the feasibility of these schemes.

Cryptography and Data Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
May 9, 2025·2025 IEEE 11th Conference on Big Data Security on Cloud (BigDataSecurity)
0 cites
Relationship Sharing-based Trustworthy Verifiable Multi-Party Verification in Decentralized Identity

Yuqing Zhang, Keke Gai, Jing Yu, Kai Ding

Decentralized Identity (DID) management is pivotal for data security and privacy-preserving in the digital era, yet existing systems face critical challenges, including single point of failure, privacy leakage, and high computational overhead. To address these limitations, this paper proposes a multi-party verifiable trust validation mechanism based on Verifiable Relation Sharing (VRS). The mechanism skillfully integrates Multi-Verifier Zero-Knowledge proofs (MVZK) with Verifiable Secret Sharing (VSS) to securely share secret attribute vectors among multiple verifiers. This enables the generation of Zero-Knowledge Proof (ZKP) of relationships without revealing the actual data. This mechanism ensures that each verifier obtains partial information, thereby effectively defending against single-point attacks, and reducing computational and communication costs through distributed verification. Experimental results confirm the practicality within DID ecosystems, offering a scalable and privacy-preserving solution for multi-party verification and a foundational framework for secure DID verification in blockchain.

Access Control and Trust
Cloud Data Security Solutions
Original source
May 8, 2025·2025 Crypto Valley Conference (CVC)
5 cites
SoK: A Taxonomy for Distributed-Ledger-Based Identity Management

Awid Vaziry, Sandro Rodriguez Garzon, Patrick Herbke, Carlo Segat · 5 authors

The intersection of blockchain (distributed ledger) and identity management lacks a comprehensive framework for classifying distributed-ledger-based identity solutions. This paper introduces a methodologically developed taxonomy derived from the analysis of 390 scientific papers and expert discussions. The resulting framework consists of 22 dimensions with 113 characteristics, organized into three groups: trust anchor implementations, identity architectures (identifiers and credentials), and ledger specifications. This taxonomy facilitates the systematic analysis, comparison, and design of distributed-ledger-based identity solutions, as demonstrated through its application to two distinct architectures. As the first methodology-driven taxonomy in this field, this work advances standardization and enhances understanding of distributed-ledger-based identity architectures. It provides researchers and practitioners with a structured framework for evaluating design decisions and implementation approaches.

Open access
2 source records
Blockchain Technology Applications and Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
Apr 28, 2025·arXiv (Cornell University)
0 cites
From Paper Trails to Trust on Tracks: Adding Public Transparency to Railways via zk-SNARKs

Tarek Galal, Valeria Tisch, Katja Assaf, Andreas Polze

Railways provide a critical service and operate under strict regulatory frameworks for implementing changes or upgrades. Despite their impact on the public, these frameworks do not define means or mechanisms for transparency towards the public, leading to reduced trust and complex tracking processes. We analyse the German guideline for railway-infrastructural modifications from proposal to approval, using the guideline as a motivating example for modelling decisions in processes using digital signatures and zero-knowledge proofs. Therein, a verifier can verify that a process was executed correctly by the involved parties and according to specification without learning confidential information such as trade secrets or identities of the participants. We validate our system by applying it to the railway process, demonstrating how it realises various rules, and we evaluate its scalability with increased process complexities. Our solution is not railway-specific but also applicable to other contexts, helping leverage zero-knowledge proofs for public transparency and trust.

Open access
3 source records
cs.CR
Safety Systems Engineering in Autonomy
Access Control and Trust
Original source
Apr 24, 2025·arXiv (Cornell University)
2 cites
Federated Learning: A Survey on Privacy-Preserving Collaborative Intelligence

Ratun Rahman

Federated Learning (FL) has emerged as a transformative paradigm in the field of distributed machine learning, enabling multiple clients such as mobile devices, edge nodes, or organizations to collaboratively train a shared global model without the need to centralize sensitive data. This decentralized approach addresses growing concerns around data privacy, security, and regulatory compliance, making it particularly attractive in domains such as healthcare, finance, and smart IoT systems. This survey provides a concise yet comprehensive overview of Federated Learning, beginning with its core architecture and communication protocol. We discuss the standard FL lifecycle, including local training, model aggregation, and global updates. A particular emphasis is placed on key technical challenges such as handling non-IID (non-independent and identically distributed) data, mitigating system and hardware heterogeneity, reducing communication overhead, and ensuring privacy through mechanisms like differential privacy and secure aggregation. Furthermore, we examine emerging trends in FL research, including personalized FL, cross-device versus cross-silo settings, and integration with other paradigms such as reinforcement learning and quantum computing. We also highlight real-world applications and summarize benchmark datasets and evaluation metrics commonly used in FL research. Finally, we outline open research problems and future directions to guide the development of scalable, efficient, and trustworthy FL systems.

Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Access Control and Trust
Original source
Apr 21, 2025·Electronics
1 cites
RBFAC: A Redactable Blockchain Framework with Fine-Grained Access Control Based on Flexible Policy Chameleon Hash

Shunqing Wu, Lifei Wei, Sean M. Wu, Lei Zhang

While blockchain’s immutability ensures data integrity, it also poses significant challenges when dealing with illegal or erroneous data that require modification. The concept of redactable blockchain has emerged, utilizing Chameleon Hash (CH) and subsequent Policy-based Chameleon Hash (PCH) for controlled data editing. However, current redactable blockchain implementations exhibit significant limitations, particularly in their inability to separate data editing from policy modification and their insufficient support for decentralized management of diverse editing operations. To address these issues, this paper initially introduces the concept of Flexible Policy Chameleon Hash (FPCH), which integrates PCH with non-interactive zero-knowledge proofs to enable enhanced policy management flexibility. Moreover, this paper proposes a Redactable Blockchain Framework with Fine-grained Access Control (RBFAC) based on FPCH. The RBFAC framework employs a hybrid cryptographic approach to separate the right of data editing from policy modification. The framework also provides essential functionalities, including editing accountability, key tracking and revocation mechanisms, and policy privacy protection. Finally, experimental evaluations demonstrate that the RBFAC framework maintains acceptable performance overhead while delivering these advanced features. The results indicate that the proposed solution addresses the limitations of existing redactable blockchain systems, offering a more flexible and secure approach to controlled data editing in blockchain environments.

Open access
Access Control and Trust
Cryptography and Data Security
Cloud Data Security Solutions
Original source
Apr 15, 2025·International Journal on Advanced Electrical and Computer Engineering
0 cites
Distributed Ledger Technology for Decentralized Identity Management

Adam Bennett, Jennifer Clarke

The rapid advancement of digital services and online interactions has highlighted the need for secure, user-centric identity management systems. Traditional identity solutions, often centralized and dependent on trusted third parties, pose challenges related to privacy, security, and control over personal data. Distributed Ledger Technology (DLT), particularly blockchain, offers a promising solution for decentralized identity management by enabling self-sovereign identities (SSI). Through the use of decentralized identifiers (DIDs) and verifiable credentials (VCs), DLT allows individuals to maintain full control over their personal information, eliminating the need for intermediaries while ensuring data integrity and privacy. This paper explores the key principles of DLT-based decentralized identity management, discussing its potential to enhance privacy, security, and interoperability in digital ecosystems. We examine the various technical frameworks, challenges, and standards in the field, with a focus on the integration of DLT with emerging technologies such as zero-knowledge proofs (ZKPs) and secure multiparty computation (SMPC). Additionally, we evaluate real-world use cases, from financial services to healthcare, and the role of regulatory frameworks in shaping the future of decentralized identity systems. Ultimately, DLT presents a paradigm shift in identity management, offering scalable, transparent, and trusted solutions for the digital age.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Access Control and Trust
Original source
Apr 14, 2025·International Journal of Web Information Systems
5 cites
Integrating zero-knowledge proofs into federated learning: a path to on-chain verifiable and privacy-preserving federated learning frameworks

Chunlei Li, Zhibo Xing, Jiamou Liu, Giovanni Russello · 8 authors

Purpose The growing concern over privacy leakage has led to reduced user participation in data sharing, prompting the exploration of novel techniques such as federated learning (FL). Meanwhile, existing FL solutions often overlook the validation of the training process, leaving room for malicious trainers to introduce false or toxic local models, detrimental to the global model’s utility. This study aims to propose a zero-knowledge proof-based verifiable federated learning (ZKP-FL) framework on the blockchain. Design/methodology/approach ZKP-FL leverages zero-knowledge proofs to verify the extensive local training process without threatening the local privacy. To reduce the memory and runtime overhead, the authors divide the training algorithm to be proven into smaller pieces and generating proofs for each segment. The authors leverage sigma-protocol to ensure the consistency and reliability of these proofs. Moreover, they design a secure model aggregation protocol that matches the local proofs, safeguarding the data privacy of individual local models throughout the process. Furthermore, this aggregation protocol can also guarantee the correctness of the aggregation. Findings To establish the effectiveness and security of ZKP-FL, the authors conduct a formal security analysis in terms of completeness, soundness and zero-knowledge properties. Experimental evaluations with different algorithms and models within the ZKP-FL framework demonstrate that with parallel execution the additional proof time per round is minimal. Originality/value This paper offers a novel perspective on security and privacy of FL, providing valuable insights that extend the current understanding of verifiable FL. The findings contribute to the ZKP-FL, highlighting areas for future research and practical applications.

Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source
Apr 3, 2025·2025 2nd International Conference on Trends in Engineering Systems and Technologies (ICTEST)
6 cites
EduChain: A Blockchain-Based System for Efficient and Secure Certificate Verification

B. Anandapadmanaban, Athira V Umesh, A Anilkumar, Arun K. Das · 5 authors

The rapid development of blockchain technology opens up trends and new directions in securing, authenticating and decentralizing data. EduChain allows for two demonstration areas, namely, use of blockchain and NFTs in certification solutions for more reliable certificate checking and certificate storage. Built on Ethereum blockchain and utilizing IPFS, from the perspective of universities, colleges, and other institutions, EduChain facilitates issuance of secure and tamper-proof NFT certificates for sensitive information. It has MetaMask-Like login and easy integration with the Ethereum platform and has several other advanced characteristics. EduChain responds to relevant issues with conventional certification solutions, which include fake certifications and certifications based on fake documents, time-consuming examinations of documents, and insufficient control of one’s own data. Turing tests conducted on Sepolia testnet established that the system provides for immutable, verifiable and decentralized certification. Further improvements could be real-time notifications or other applications that would work in conjunction with Revizto; analysis tools that would produce even more meaningful information. EduChain can be considered as the good example of how using NFTs can improve the processes of documents verification in various sectors.

Cloud Data Security Solutions
Cryptography and Data Security
Access Control and Trust
Original source
Mar 21, 2025·Crypto Valley Conference (CVC), 2025, pp. 44-55
3 cites
Governance of Ledger-Anchored Decentralized Identifiers

Sandro Rodriguez Garzon, Carlo Segat, Axel Küpper

A Decentralized Identifier (DID) empowers an entity to prove control over a unique and self-issued identifier without relying on any identity provider. The public key material for the proof is encoded into an associated DID document (DDO). This is preferable shared via a distributed ledger because it guarantees algorithmically that everyone has access to the latest state of any tamper-proof DDO but only the entities in control of a DID are able to update theirs. Yet, it is possible to grant deputies the authority to update the DDO on behalf of the DID owner. However, the DID specification leaves largely open on how authorizations over a DDO are managed and enforced among multiple deputies. This article investigates what it means to govern a DID and discusses various forms of how a DID can be controlled by potentially more than one entity. It also presents a prototype of a DID-conform identifier management system where a selected set of governance policies are deployed as Smart Contracts. The article highlights the critical role of governance for the trustworthy and flexible deployment of ledger-anchored DIDs across various domains.

Open access
3 source records
Privacy-Preserving Technologies in Data
Access Control and Trust
Cryptography and Data Security
Original source
Mar 20, 2025·Electronics
0 cites
Performance Modeling of Distributed Ledger-Based Authentication in Cyber–Physical Systems Using Colored Petri Nets

Michał Jarosz, Konrad Wrona, Zbigniew Zieliński

Federated cyber–physical systems (CPSs) present unique security challenges due to their distributed nature and the need for secure communication between components from different administrative domains. Distributed ledger technology (DLT) offers a promising approach to implementing a resilient authentication and authorization mechanism and an immutable record of CPS identities and transactions in federated environments. However, using Distributed Ledger (DL) within a CPS raises some important questions regarding scalability, throughput, latency, and potential bottlenecks, which require effective modeling of DL performance. This paper proposes a novel approach to modeling distributed ledgers using Colored Timed Petri Nets (CPNs). We focus on the performance modeling of Hyperledger Fabric (HLF), a permissioned distributed ledger technology which provides a backbone for a Lightweight Authentication and Authorization Framework for Federated IoT (LAAFFI), a novel framework for secure communication between CPS devices. We implement our model using CPN Tools, a widely adopted CPN modeling software that provides advanced simulation, analysis, and performance monitoring features. Our model offers a robust framework for studying distributed ledger systems’ synchronization, throughput, and response time. It supports flexibility in modeling transaction validation and consensus algorithms, which provides an opportunity for adapting the model to future changes in HLF and modeling other DLs. We successfully validate our CPN model by comparing simulation results with experimental measurements obtained from a LAAFFI prototype.

Open access
Smart Grid Security and Resilience
Petri Nets in System Modeling
Access Control and Trust
Original source
Mar 12, 2025·arXiv (Cornell University)
1 cites
RaceTEE: Enabling Interoperability of Confidential Smart Contracts

Keyu Zhang, Andrew Martin

Decentralized smart contracts enable trustless collaboration but suffer from limited privacy and scalability, which hinders broader adoption. Trusted Execution Environment (TEE) based off-chain execution frameworks offer a promising solution to both issues. Although TEE-based frameworks have made significant progress, prior work has yet to fully explore contract interoperability, a critical foundation for building complex real-world decentralized applications. This paper identifies the key challenges impeding such interoperability and presents practical solutions. Based on these insights, we introduce RaceTEE, a novel framework that leverages off-chain TEE-enabled nodes to efficiently execute confidential, long-lived smart contracts with interactions of arbitrary complexity among contracts. We implement a RaceTEE prototype using Intel SGX, integrate it with Ethereum, and release it as open source. Evaluation across diverse use cases demonstrates its practicality and effectiveness.

Open access
4 source records
cs.CR
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Original source
Mar 11, 2025·Electronics
1 cites
Embedding Security Awareness into a Blockchain-Based Dynamic Access Control Framework for the Zero Trust Model in Distributed Systems

Avoy Mohajan, Sharmin Jahan

The Zero Trust (ZT) model is pivotal in enhancing the security of distributed systems by emphasizing rigorous identity verification, granular access control (AC), and continuous monitoring. To address the complexity and scalability challenges of modern distributed systems, we propose a blockchain-based dynamic access control scheme (DACS) as a practical solution for implementing ZT principles. This framework dynamically manages access control lists (ACLs) and enforces policies through smart contracts. In the DACS framework, each blockchain node maintains an object list specifying access permissions within its ACL and incorporates a minimum trust metric (TM) threshold to evaluate access requests. The TM assigned to each node reflects its trustworthiness. To further enhance security, the framework includes security awareness, enabling the dynamic assessment of the risk factor (RF), which reflects the operational risk level. The TM of access-requesting nodes is updated at runtime based on their behavior, with penalties imposed for malicious actions according to the prevailing RF. Access control policies are dynamically adjusted, mitigating risks posed by potentially untrustworthy users with valid credentials. Implemented and tested on the Ethereum blockchain, the proposed DACS framework demonstrates its efficiency and effectiveness in securing distributed systems.

Open access
Blockchain Technology Applications and Security
Access Control and Trust
Security and Verification in Computing
Original source
Mar 10, 2025·2025 International Conference on Machine Learning and Autonomous Systems (ICMLAS)
2 cites
Cloud based Private Authorisation Scheme Oriented Service Providers

S. Sharmila Sathyanathan, Samanvitha. Sree, F. Sophiya Theresa, S Vaishali · 5 authors

Client safety and privacy will be maintained through secure security access systems, which are necessary in light of the great dependence on digital benefits. During the age of digital help, secure and confidential access control is most important for customers as well as providers. Through guaranteeing that only clients possessing specific resources are certified, access control ensures secret data and discourages unlawful actions. Widespread centralized authorization systems usually expose users' sensitive data, enabling data breaches, abuse, and espionage. To solve all of the above problems and establish a trust less system in which clients can provide access to their data or services without revealing sensitive information, we propose a decentralized code that is used to establish an authorized, secure, private, and scalable service access. Decentralized technologies such as blockchain and distributed ledgers are employed within this system. By decoupling authorization from centralized organizations, the Inter-Planetary File System (IPFS) enhances user control over personal information, diminishes the attack surface for service providers, and enhances client privacy. The protocol is secure and accommodates a broad set of service providers, ranging from digital platforms to decentralized apps, and utilizes cryptographic methods such as symmetric encryption and proxy re-encryption to see that only approved recipients have access to specific resources. This provides perfect access control while maintaining client data security. The decentralized access control and zero knowledge proof architecture is explained here along with its primary security and privacy features and uses to file storage and service scenarios.

Cloud Data Security Solutions
Access Control and Trust
Cryptography and Data Security
Original source
Feb 22, 2025·Future Generation Computer Systems
2 cites
A Trust-Aware and Cost-Optimized Blockchain Oracle Selection Model with Deep Reinforcement Learning

H.C. Zhang, Shike Li, Shike Li, Hang Bao · 6 authors

The rapid development of blockchain technology has driven the widespread application of decentralized applications (DApps) across various fields. However, DApps cannot directly access external data and rely on oracles to interact with off-chain data. As a bridge between blockchain and external data sources, oracles pose potential risks of malicious behavior, which may inject incorrect or harmful data, leading to trust and security issues. Additionally, with the surge in data requests, the disparity in oracle trustworthiness and costs has increased, making the dynamic selection of the most suitable oracle for each request a critical challenge. To address these issues, this paper proposes a Trust-Aware and Cost-Optimized Blockchain Oracle Selection Model with Deep Reinforcement Learning (TCO-DRL). The model incorporates a comprehensive trust management mechanism to evaluate oracle reputation from multiple dimensions and employs an improved sliding time window to monitor reputation changes in real time, enhancing resistance to malicious attacks. Moreover, TCO-DRL uses deep reinforcement learning algorithms to dynamically adapt to fluctuations in oracle reputation, ensuring the selection of high-reputation oracles while optimizing node selection, thereby reducing costs without compromising data quality. We implemented and validated TCO- DRL on Ethereum. Experimental results show that, compared to existing methods, TCO-DRL reduces the allocation rate to malicious oracles by more than 39.10% and saves over 12.00% in costs. Furthermore, simulated experiments on various malicious attacks further validate the robustness and effectiveness of TCO-DRL

Open access
3 source records
cs.CE
cs.ET
Blockchain Technology Applications and Security
Original source
Feb 10, 2025·arXiv
5 cites
Generating Privacy-Preserving Personalized Advice with Zero-Knowledge Proofs and LLMs

Hiroki Watanabe, Motonobu Uchikoshi

Large language models (LLMs) are increasingly utilized in domains such as finance, healthcare, and interpersonal relationships to provide advice tailored to user traits and contexts. However, this personalization often relies on sensitive data, raising critical privacy concerns and necessitating data minimization. To address these challenges, we propose a framework that integrates zero-knowledge proof (ZKP) technology, specifically zkVM, with LLM-based chatbots. This integration enables privacy-preserving data sharing by verifying user traits without disclosing sensitive information. Our research introduces both an architecture and a prompting strategy for this approach. Through empirical evaluation, we clarify the current constraints and performance limitations of both zkVM and the proposed prompting strategy, thereby demonstrating their practical feasibility in real-world scenarios.

Open access
2 source records
Privacy-Preserving Technologies in Data
Cryptography and Data Security
Access Control and Trust
Original source
Feb 10, 2025·IEEE Transactions on Services Computing
2 cites
AiRacleX: Automated Detection of Price Oracle Manipulations via LLM-Driven Knowledge Mining and Prompt Generation

Bo Gao, Yuan Wang, Qingsong Wei, Yong Liu · 6 authors

Decentralized finance (DeFi) applications depend on accurate price oracles to ensure secure and fair transactions. However, poorly integrated oracles remain susceptible to manipulation, enabling attackers to exploit smart contract logic for unfair asset valuation and financial gain. While many such vulnerabilities are only detected after deployment, smart contracts are typically immutable once deployed, making post-hoc fixes costly or infeasible. This highlights the critical need for detecting oracle manipulation risks before deployment. In this paper, we propose$AiRacleX$, a novel LLM-driven framework that enables pre-deployment detection of price oracle manipulation vulnerabilities by leveraging the complementary strengths of multiple large language models (LLMs). Our approach begins with domain-specific knowledge extraction, where an LLM model synthesizes precise insights about price oracle vulnerabilities, eliminating the need for profound expertise from developers or auditors. This knowledge forms the foundation for a second LLM model to generate structured, context-aware Chain-of-Thought prompts, which guide a third LLM model in accurately identifying manipulation patterns in smart contracts. We evaluate$AiRacleX$on 60 known vulnerabilities from 44 real-world DeFi exploits and Code4rena projects spanning 2021-2023. The results show that$AiRacleX$achieves a 2.58 times improvement in recall over the state-of-the-art GPTScan, with comparable precision. Our framework also demonstrates strong extensibility and efficiency, and supports deployment with open-source LLMs to enhance security and reduce operational cost.

Open access
3 source records
cs.CR
cs.AI
Blockchain Technology Applications and Security
Original source
Feb 10, 2025·HAL (Le Centre pour la Communication Scientifique Directe)
0 cites
Proving e-voting mixnets in the CCSA model: zero-knowledge proofs and rewinding

Margot Catinaud, Caroline Fontaine, Guillaume Scerri

<div> Mixnet protocols are used in electronic voting protocols to mix the ballot box before the tally, to preserve ballots privacy and unlinkabiliy. Whereas proving security properties of the other components of the electronic voting protocols has globally already been done in several logical frameworks and tools, proofs of mixnets remain a real challenge to handle. In this paper we focus on the quite recent CCSA logic, which enables handling of computational security proofs with first-order logics facilities. We enrich the logic to be able to deal with zero-knowledge proofs and rewinding techniques, and provide the first complete proof of Terelius-Wikström mixnet protocol. </div>

Open access
Internet Traffic Analysis and Secure E-voting
Access Control and Trust
Privacy, Security, and Data Protection
Original source
Feb 6, 2025·arXiv (Cornell University)
1 cites
ExpProof : Operationalizing Explanations for Confidential Models with ZKPs

Chhavi Yadav, Evan Monroe Laufer, Dan Boneh, Kamalika Chaudhuri

In principle, explanations are intended as a way to increase trust in machine learning models and are often obligated by regulations. However, many circumstances where these are demanded are adversarial in nature, meaning the involved parties have misaligned interests and are incentivized to manipulate explanations for their purpose. As a result, explainability methods fail to be operational in such settings despite the demand \cite{bordt2022post}. In this paper, we take a step towards operationalizing explanations in adversarial scenarios with Zero-Knowledge Proofs (ZKPs), a cryptographic primitive. Specifically we explore ZKP-amenable versions of the popular explainability algorithm LIME and evaluate their performance on Neural Networks and Random Forests. Our code is publicly available at https://github.com/emlaufer/ExpProof.

Open access
2 source records
cs.LG
cs.AI
cs.CR
Original source
Feb 5, 2025·IEEE Transactions on Services Computing
5 cites
A False Positive Resilient Distributed Trust Management Framework for Collaborative Intrusion Detection Systems

Kadhim Hayawi, Imran Makhdoom, Saifullah Khalid, Richard A. Ikuesan · 6 authors

Collaborative Intrusion Detection System (CIDS) protect large networks against distributed attacks. However, a CIDS is vulnerable to insider attacks that decrease the mutual trust among the CIDS nodes. Most existing trust management approaches rely on a central authority, trusted third parties or network peers for managing trust. The current techniques are prone to high false positives and vulnerable to various reputation attacks. For instance, device attestation manages trust among CIDS nodes by verifying the integrity of a node’s hardware and software configuration. However, it lacks real-time monitoring of the dynamic state, limiting its effectiveness against ongoing attacks and malware. Therefore, incorporating the system’s dynamic state in the trust framework is crucial, but it causes false positives requiring corrective mechanisms. To address these challenges, this paper proposes a blockchain-based integrated trust management framework for CIDS, incorporating the device’s genome attestation, the system’s dynamic parameters, and a false positive resilient reputation mechanism. By storing the reputation scores on the blockchain, the framework alleviates the need for a third party for trust management and thus mitigates attacks applicable to reputation-based systems. The paper performs a comprehensive security and performance analysis of the proposed framework to gauge its efficiency and study the effects of a penalty on a node’s reputation during the recovery and rally phases. We also study the impact of false positives on the reputation of a node. The results show that Hyperledger Fabric offers lower transaction latency and low CPU utilization compared to Ethereum Blockchain.

Access Control and Trust
Network Security and Intrusion Detection
Smart Grid Security and Resilience
Original source