Ankit Agrawal, Ashutosh Bhatia, Kamlesh Tiwari
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,600 results ¡ page 17 of 67
Ankit Agrawal, Ashutosh Bhatia, Kamlesh Tiwari
No abstract is available for this record.
S. B. Indra, S. Harshini, R. Sabitha
No abstract is available for this record.
Hao Sui, Jiale Zhang, Bing Chen, Di Wu ¡ 6 authors
No abstract is available for this record.
Jerry Huang, Ken Huang
No abstract is available for this record.
Jingjing Yang, Jieli Liu, Dan Lin, Jiajing Wu ¡ 7 authors
With the popularity of Non-Fungible Tokens (NFTs), the high value of NFTs makes them a target for phishing scammers, which harms the security and reliability of the Web3 NFT ecosystem. Despite the significance of this issue, there is a lack of systematic research in the area of emerging NFT phishing scams. To address this gap, we are the first to conduct a case retrospective analysis and empirical measurement study of real-world historical NFT phishing scams on Ethereum. We collect and publicly release the first NFT phishing dataset which includes 1,625 NFT phishing accounts and transaction records as of August 2023. We further categorize the existing scams into four phishing patterns and investigate their distinguishable behaviors. Then, we reveal the modus operandi preferences and economic impacts to characterize NFT phishing scams. We find that NFT phishers stole 67,188 NFTs, with a total direct selling profit of${\$}$20.92 million. We also observe that scammers favor certain categories and collections of NFTs, coupled with signs of gang theft. Furthermore, we design a variety of account features for the classification task of NFT phishers based on empirical conclusions. Experimental results on real-world NFT transaction data demonstrate the effectiveness of these features in detecting NFT phishing accounts, and outperform traditional phishing detection methods with 41% average Precision and 44% average Recall.
Jingjing Yang, Wenjia Yu, Jiajing Wu, Dan Lin ¡ 6 authors
In recent years, phishing scams have emerged as one of the most serious crimes on Ethereum. Existing phishing scam detection methods typically model public transaction records on the blockchain as a graph, and then identify phishing addresses through manual feature extraction or graph learning frameworks. Meanwhile, these methods model transactions within a period as a static network for analysis. Therefore, these methods lack the ability to capture fine-grained time dynamics, and on the other hand, they cannot handle the large-scale and continuously growing transaction data on the Ethereum blockchain, resulting in lower scalability and efficiency. In this paper, we propose a two-dimensional streaming framework 2DynEthNet for Ethereum phishing scam detection. First, we cast the transaction series into 6 slices according to block numbers, treating each as a separate task. In the first dimension, we treat transaction features as edge features instead of node features within one task, allowing each transaction to be streamed in 2DynEthNet, aiming to capture the evolutionary features of the Ethereum transaction network at a fine-grained level in continuous time. In the second dimension, we adopt the strategy of incremental information training between tasks, which utilizes meta-learning to quickly update the model parameters under new slices, thus effectively improving the scalability of the model. Finally, experimental results on large-scale real Ethereum phishing scam datasets show that our 2DynEthNet outperforms the state-of-the-art methods with 28.44% average Recall and achieves the most efficient training speed, proving the effectiveness of both temporal edge representation and meta-learning. In addition, we provide an Ethereum large-scale dynamic graph transaction dataset, ETGraph, which aligns with the data distribution in real transaction scenarios without sampling and filtering unlabeled accounts.
Jieli Liu, J. Chen, Jiajing Wu, Zhiying Wu ¡ 6 authors
As one of the most typical cybercrime types, phishing scams have extended the devilâs hand to the emerging blockchain ecosystem in recent years. Especially, huge economic losses have been caused by phishing scams in Ethereum, the second-largest blockchain system. Existing approaches for Ethereum phishing detection, however, typically use machine learning or transaction graph embedding methods to identify phishers in isolation and do not effectively uncover the group of transaction accounts linked to scams (which we term a âgangâ). Since accounts are pseudonymous in Ethereum, these undisclosed conspirator accounts have potential risks to the system. In this paper, we conduct the first study that characterizes and detects Ethereum phishing gangs. We first investigate the transaction behaviors in phishing gangs from the perspectives of individuals, pairs, and higher-order patterns. Our analysis reveals that although the Ethereum transaction graph is sparse with a highly skewed degree distribution, phishing accounts in the same gang have closer relationships and share specific transaction patterns. Based on our findings, we formalize the phishing gang detection problem and introduce a novel detection model named PGDetector. Given a risky phishing account as a seed, PGDetector can find out the potential risky accounts sharing close relationships within the seedâs community based on genetic algorithm optimization. Experimental results on large-scale Ethereum transaction data demonstrate the effectiveness of PGDetector.
Sijo K. Joseph, Priyank Pandey, Manju Khari, Kapil Kumar ¡ 5 authors
Voting is a crucial part of democracy because it gives people the chance to voice their opinions, hold elected officials responsible, encourage diversity in the government, cultivate civic participation, and defend themselves from tyranny. Existing electronic voting (e-voting) systems do in fact suffer a number of important obstacles, with security difficulties and a lack of transparency ranking as two of the most important problems. Given the significance of elections in democracies and the likelihood of fraud or other forms of manipulation in electronic voting procedures, these issues are extremely pressing. Systems used for electronic voting heavily rely on software, which might occasionally have vulnerabilities that hackers can exploit. Any weak point in the system can be used to sway elections or jeopardize its security. To address these issues, a strong, secure electronic voting system (EVS), an open system design, impartial audits, and a dedication to inclusion and accessibility are required. For democratic processes to continue to be trusted and the right to vote to be protected, e-voting system integrity must be ensured. It is necessary to create a new Electronic Voting System (EVS) that can offer greater security, speed, and accuracy than the EVS used in the past. The authors of this research suggested a blockchain-based secure EVS. Immutable, transparent, and secure distributed ledger technology named as blockchain. Blockchain used to implement an E-Voting system that is transparent, tamper-proof, and can guarantee the correctness and integrity of the voting process.
Lejun Zhang, Junjie Zhang, Kentaroh Toyoda, Yuan Liu ¡ 7 authors
Bitcoin is widely used as the most classic electronic currency for various electronic services such as exchanges, gambling, marketplaces, and also scams such as high-yield investment projects. Identifying the services operated by a Bitcoin address can help determine the risk level of that address and build an alert model accordingly. Feature engineering can also be used to flesh out labeled addresses and to analyze the current state of Bitcoin in a small way. In this paper, we address the problem of identifying multiple classes of Bitcoin services, and for the poor classification of individual addresses that do not have significant features, we propose a Bitcoin address identification scheme based on joint multi-model prediction using the mapping relationship between addresses and entities. The innovation of the method is to (1) Extract as many valuable features as possible when an address is given to facilitate the multi-class service identification task. (2) Unlike the general supervised model approach, this paper proposes a joint prediction scheme for multiple learners based on address-entity mapping relationships. Specifically, after obtaining the overall features, the address classification and entity clustering tasks are performed separately, and the results are subjected to graph-based maximization consensus. The final result is made to baseline the individual address classification results while satisfying the constraint of having similarly behaving entities as far as possible. By testing and evaluating over 26,000 Bitcoin addresses, our feature extraction method captures more useful features. In addition, the combined multi-learner model obtained results that exceeded the baseline classifier reaching an accuracy of 77.4%.
Istiaque Ahmed, Kai Fumimoto, Tadashi Nakano, Thi Hong Tran
The charity sector impacts society significantly in many areas, including providing education, healthcare, hunger relief, drinking water, disaster relief, environmental preservation, and assistance to underserved people. The existing charity organizations have numerous limitations, such as poor management, high operation costs, and a lack of transparency in the donation execution flow. The authentication of users and institutions is a big problem in the existing system. This research resolves the issues of transparency and reliability with an immutable and traceable distributed ledger. We empower the existing centralized charity works with the electronic know-your-customer (eKYC) authentication approach and cryptographic HASH. Information privacy is implemented using the filters within smart contracts. The implementation of eKYC to ensure authenticity and to secure data flow through the channel are two significant contributions of this work. A coin-toss function for data selection and a random time delay between pieces of data are used to avoid attacks based on guesswork. We aim for this framework to send 100% of donations to the beneficiaries and become a hyper-liquid medium to fill the United Nations Sustainable Development Goals (SDG) funding gap. We also introduce the concept of service charity to broaden the ability for people to offer their services and skills as charity.
Momna Akhtar, Muhammad Rahim, Agaeb Mahal Alanzi, Sadique Ahmad ¡ 7 authors
This paper presents novel operational laws forp,q,râspherical fuzzy sets (p,q,râSFSs) by harnessing the Dombi t-norm (DTN) and t-conorm (DTCN). These laws serve as the foundation for a set of aggregation operators (AOs) designed to consolidatep,q,râspherical fuzzy (p,q,râSF) information. Additionally, a multi-criteria decision-making (MCDM) method is outlined for addressing practical decision-making (DM) challenges. To demonstrate the application of the proposed approach, a numerical example is offered. Furthermore, we conducted a comparative study to validate the efficacy of the suggested approach. Finally, we discuss both the advantages and limitations of this innovative approach.
Siwei Wu, Zhou Yu, Dabao Wang, Yajin Zhou ¡ 7 authors
The rapid growth of Decentralized Finance (DeFi) boosts the blockchain ecosystem. At the same time, attacks on DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot directly detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pairXandYin a Decentralized EXchange (DEX). In this work, we focus on the detection of two new types of price manipulation attacks. To this end, we propose a platform-independent method to identify high-level DeFi semantics. Specifically, we first construct the Cash Flow Tree (CFT) from a raw transaction and then lifting the low-level semantics to high-level ones, including five advanced DeFi actions. Finally, we use patterns expressed with the recovered DeFi semantics to detect price manipulation attacks. We implemented a prototype namedDeFiRangerthat detected 14zero-daysecurity incidents. These findings were reported to affected parties or/and the community for the first time. Furthermore, the backtest experiment discovered 15 unknown historical security incidents. We further performed an attack analysis to shed light on the root causes of vulnerabilities incurring price manipulation attacks.
Yanhua Liu, Zhihuang Liu, Qiu Zhang, Jinshu Su ¡ 6 authors
Blockchain-based healthcare IoT technology research enhances security for smart healthcare services such as real-time monitoring and remote disease diagnosis. To incentivize positive behavior among participants within a blockchain-based smart healthcare system, existing efforts employ benefit distribution and reputation assessment methods to enhance performance. Yet, there remains a significant gap in multidimensional assessment strategies and consensus improvements in addressing complex healthcare scenarios. In this paper, we propose a blockchain and trusted reputation assessment-based incentive mechanism for healthcare services (BtRaI). BtRaI provides a realistic and comprehensive reputation assessment with feedback to motivate blockchain consensus node participation, thus effectively defending against malicious behavior in the healthcare service system. Specifically, BtRaI first introduces multiple moderation factors for comprehensive multidimensional reputation assessment and credibly records the assessment results on the blockchain. Then, we propose an improved PBFT algorithm, grounded in the reputation assessment, to augment blockchain consensus efficiency. Finally, BtRaI designs a token-based reward and punishment mechanism to motivate honest participation in the blockchain, inhibit potential misbehavior, and promote enhanced service quality in the healthcare system. Theoretical analysis and simulation experiments conducted across various scenarios demonstrate that BtRaI effectively suppresses malicious attacks in healthcare services , improves blockchain node fault tolerance rates, and achieves blockchain transaction processing efficiency within 0.5 s in a 100-node consortium chain. BtRaIâs reputation assessment and token incentive mechanism, characterized by realistic differentiation granularity and change curves, are well-suited for dynamic and complex healthcare service environments.
Thuat Do, Do Van Dung, Linh Nguyen
Reputation is a fundamental concept in human social interactions and inter-relationship. Blockchain and Web3 have been rapidly growing, involving multi-millions of users, billions of transactions, and hundreds of millions of addresses onchain (i.e. on-blockchain). Decentralized identity and onchain reputation will play a critical role in defining each individual's persona, and natively supporting onchain entities to build trust in the Web3 space, while preserving user privacy and autonomy. This paper presents a novel reputation ranking method to address the problem. We leverage adaptive weighted Page Rank algorithms to assess and rank the reputation of participants within various public blockchains. We assign reputation scores to onchain entities based on their historical transaction behaviors, taking transaction volume, activeness, and network contributions into account. In addition to describing the theoretical framework of our reputation ranking, this paper provides empirical insights into its implementation on transactional datasets of Ethereum and BNB Chain. The results and findings presented herein offer a foundation for further research and development of onchain reputation systems in public blockchains and its applications in decentralized finance and Web3 ecosystems.
Daniela PĂśhn, Michael Grabatin, Wolfgang Hommel
Self-sovereign identity (SSI) is a digital identity management model managed in a decentralized manner. It allows identity owners to manage and store their digital identities in a software wallet, for example, on a smartphone, without relying on centralized providers. This approach tries to enhance the security and privacy of digital identities and, thereby, their owners. With the new eIDAS regulation, elements of SSI, such as the wallet, are being pushed onto the market. However, since the model is relatively new, the security threats are still not fully known. This is shown by a brief security analysis of selected existing SSI wallets. In order to get a picture of the known threats, we systematically analyze and categorize related work in the field of SSI and elements applied by SSI. We then evaluate their application to current SSI systems and identify future work.
Nan Sun, Wei Wang, Yongxin Tong, Kexin Liu
No abstract is available for this record.
Shahnawaz Khan
Zakat is one of the five mandatory pillars of Islam. It plays a vital role in addressing the social issues such as wealth inequality and supporting the less fortunate. Any Muslim whose wealth and assets exceeds the Nisab value must pay zakat. However, unlike taxes, zakat is not collected by government or authorities. Therefore, every eligible individual is responsible for its calculation and distribution independently. Hence, there are several issues and challenges associated with its collection and distribution, especially in non-Islamic countries. This research paper proposes a blockchain-based online platform for zakat collection and distribution, addressing these challenges. Blockchain can help to ensure that zakat funds are distributed to beneficiaries in an efficient manner. The system allows zakat payers to select and allocate funds to the verified beneficiaries while ensuring Sharia compliance. The proposed system uses a blockchain ledger to enhances transparency, and accountability. It minimizes the associated collection and distribution costs by removing intermediaries. This research aims to contribute to the efficient and secure management of zakat funds, promoting social justice, and responsible zakat practices in the Muslim community.
Mingshun Ye, Mingdong Tang, Weili Chen
With the rapid advancement of blockchain technology, cryptocurrencies based on blockchain have become a hot topic. However, various issues accompany this development, with phishing scams emerging as a severe financial crime within the blockchain ecosystem, causing significant economic losses to both blockchain platforms and users. In order to address this threat, this essay proposes a phishing scam account identification model based on Bidirectional Long Short-Term Memory Networks (BiLSTM) named BILAM. The model has been validated on the Ethereum platform and has been proven to be effective.This study proposes a novel approach by using transaction records for the first time to construct a time series, and it leverages the BILAM model to learn latent information. Experimental results demonstrate the effectiveness of this method in constructing transaction time series. Moreover, the BILAM model shows excellent performance, with its predictive accuracy significantly surpassing other models, particularly achieving an AUC index of 92.8%.
Chibuzo Obi-Okoli, Olamide Jogunola, Bamidele Adebisi, Mohammad Ali A. Hammoudeh
The rapid growth and psudonomity inherent in blockchain technology such as in Bitcoin and Ethereum has marred its original intent to reduce dependant on centralised system, but created an avenue for illicit activities, including fraud, phishing, scams, etc. This undermines the reputation of blockchain network, giving rise to the need to identify these illicit activities within the blockchain network. This current work tackles this crucial problem by investigating and implementing six machine learning algorithms with a particular emphasis on striking a balance between accuracy, precision and recall. The novelty of the work lies in the utilising of the synthetic minority over-sampling technique to handle data imbalance. Thus, increasing the accuracy of the light gradient boosting machine classifier to 98.4%. The outcome of this work holds great potential for enhancing the security and credibility of blockchain ecosystems paving the way for a more secure and dependable digital future in the age of decentralised and trustless systems.
Shaoxuan Zhuo, Guang Li, Weigang Wu, Jing Bian
Cryptocurrency phishing scams is a significant treat to Ethereum, one of the most popular blockchain platforms. Most of existing Ethereum phishing detection methods are based on traditional machine learning or graph representation learning, which mostly rely on only statistical and structural features in local scope. In this paper, we propose Multi-transaction-view Graph Attention Network (MTvGAT), a novel phishing scam detection model that can make use of transaction patterns of different scopes. To obtain global-view information, we apply graph clustering and construct the global-view graph with multiple clusters, including all the nodes of the original transaction network. To obtain local view information, we apply neighborhood sampling, and construct local-view graphs with target nodes and their neighborhood nodes. Then, node features, edge features, and attention coefficients are aggregated to merge multi-view information into representation of nodes. We further combine global-view and local-view representations to finally identify phishing addresses from target nodes. Extensive experiments demonstrate that the proposed method can outperform existing ones with significant improvement.
Feng Zhao, Hui Li, Shaoliang Peng, Xiyu Wang ¡ 13 authors
The decentralized nature of blockchain technology has received increasing attention in recent years. Several researchers have explored improving legacy Domain Name System (DNS) via blockchain to address security vulnerabilities and trust risks due to its centralized management. However, these DNS alternatives mainly focus on managing and resolving specific types of resources with predefined identifiers, such as domain names in the TCP/IP architecture. As a result, they are not suitable for the future Internet with diverse identifiers. To address this issue, we propose an Ethereum-based Multi-Identifier System named EMIS to uniformly manage and resolve multiple types of identifiers such as identity, content, and geographical coordinate. It consists of four modules, namely, identifier contracts, an EMIS contract, an index system, and off-chain storage, each of which can be evolved and upgraded independently. In particular, identifier contracts are designed based on our classification of existing identifier types associated with off-chain resource data. Each identifier contract enables different functionality and is aggregated by a uniform EMIS contract. Finally, we deploy the proposed EMIS on Ganache, and the experimental results demonstrate our advantage in terms of write performance with low Gas fees.
Yang Xikang, Biyu Zhou, Xuehai Tang, Zhang Xiao-dan ¡ 6 authors
In recent years, the cryptocurrency platform becomes a prime target of various cybercrimes. Criminals use phishing fraud to commit massive scams on Ethereum (one of the most widely used cryptocurrency platforms), which poses a significant threat to the security of the cryptocurrency ecosystem. In this context, the use of Ethereum transaction information to detect and identify phishing fraud accounts is essential to ensure a secure and regulated trading platform. However, the previous proposals do not explore the behavior patterns of phishing accounts in depth, and also lack interpretability. To address this problem, we propose a novel and interpretable Ethereum phishing fraud detection method by extracting more fine-grained and interpretable account transaction features. The key idea is to extract both the spatial structure and temporal behavior patterns of the Ethereum transaction network as the âTransletsâ features via the highly interpretable attribute sub graphs and subsequences. Based on these features, a classifier with good interpretability is adopted, and the proposed interpreter is combined to interpret the detection outputs. The experimental results on real-world Ethereum phishing fraud account datasets demonstrate that our method not only has advantages in precision, recall, and F1 score but also provides interpretability in recognizing Ethereum phishing accounts.
Hou-Wan Long, Xiongfei Zhao, YainâWhar Si
Decentralized Finance (DeFi), propelled by Blockchain technology, has revolutionized traditional financial systems, improving transparency, reducing costs, and fostering financial inclusion. However, transaction activities i n these systems fluctuate significantly and the throughput can be effected. To address this issue, we propose a Dynamic Mining Interval (DMI) mechanism that adjusts mining intervals in response to block size and trading volume to enhance the transaction throughput of Blockchain platforms. Besides, in the context of public Blockchains such as Bitcoin, Ethereum, and Litecoin, a shift towards transaction fees dominance over coin-based rewards is projected in near future. As a result, the ecosystem continues to face threats from deviant mining activities such as Undercutting Attacks, Selfish Mining, and Pool Hopping, among others. In recent years, Dynamic Transaction Storage (DTS) strategies were proposed to allocate transactions dynamically based on fees thereby stabilizing block incentives. However, DTSâ utilization of Merkle tree leaf nodes can reduce system throughput. To alleviate this problem, in this paper, we propose an approach for combining DMI and DTS. Besides, we also discuss the DMI selection mechanism for adjusting mining intervals based on various factors.
Zhiju Yang, Gaoyuan Man, Songqing Yue
As decentralized finance (DeFi) built on blockchain grows rapidly, the security of smart contracts underpinning DeFi has become a major concern due to exploits leading to billions in damages. Although tools exist for automated vulnerability detection in smart contracts, studies show that most vulnerabilities remain undetected. In this work, we propose using fine-tuned large language models (LLMs) for enhanced automated detection of vulnerabilities in smart contracts. We collected over 26,727 labeled smart contract vulnerabilities and fine-tuned the 13B parameter Llama-2 model. Evaluation of 1,000 unseen functions shows promising precision of 31-36% in predicting vulnerability categories. The fine-tuned LLM demonstrates potential as an auxiliary tool to identify vulnerable code and assist auditors. Future work is outlined for improving performance via larger models, higher-quality data, and specialized binary detection models. We present promising preliminary results on integrating LLMs into smart contract analysis and motivate further research at the intersection of LLMs and blockchain security.