Andrea Pelosi, Claudio Felicioli, Andrea Canciani, Fabio Severino
While Artificial Intelligence (AI) is making significant strides in a variety of sectors, an exclusive focus on accuracy can overlook the critical aspect of trustworthiness, especially in contexts where it should be a primary concern. In this paper, we propose a novel framework for the development of trustworthy AI systems, leveraging Hybrid Distributed Ledger Technology (Hybrid DLT). We explore the concept of shifting from an accuracy-based paradigm to an approach where trustworthiness is an integral part of the design. Our framework facilitates collaboration between different entities across the data preparation, model training, and the classification phase of a supervised learning ML solution. It uses a shared ledger which offers a tamper-resistant audit log of every operation, ensuring non-repudiation and replicability. We discuss how employing our proposed framework leads to significantly enhanced trustworthiness in AI systems.
Rim Ben Fekih, Mariam Lahami, Mohamed JmaĂŻel, Salma Bradai
Focusing on important features in blockchain applications, smart contracts are one of the most studied in the literature. Despite the trusted implementations that smart contracts offer, different security problems and vulnerabilities are rising during their development and execution. Trying to deal with such issues, different researches are proposed to give eventual solutions. Such studies focus on the verification of smart contracts and adopt different techniques. While various formal methods are considered significant effective to ensure the trustworthiness and correctness of smart contracts, this work deals with formal verification of smart contracts using model checking. In this survey, we conduct an overview on smart contracts verification using model checking. We analyze and classify each study according to four main aspects; the adopted formalism, the verified properties, the system under verification and to which blockchain platform the contribution is dedicated. Finally, we suggest some promising future directions to stir research efforts into this area.
El artĂculo presenta al lector las caracterĂsticas y el contexto histĂłrico en el que surgieron los smart contracts, luego los clasifica y describe su incidenÂcia en la teorĂa general de los contratos, para lo cual distingue entre sistemas de automatizaciĂłn de la ejecuciĂłn contractual y contratos inteligentes en sentido estricto, afirmando que estos Ășltimos requieren del uso de inteligencia artificial. Lo anterior conduce al abordaje del concepto de consentimiento algorĂtmico y, finalmente, permite ofrecer algunas conclusiones acerca de su impacto en el derecho del consumo y el mercado financiero colombiano.
Abstract The use of computer technology to automate the enforcement of law is a promising alternative to simplify bureaucratic procedures. However, careless automation might result in an inflexible and dehumanized law enforcement system driven by algorithms that do not account for the particularities of individuals or minorities. In this article, we argue that hybrid smart contracts deployed to monitor rather than blindly enforce regulations can be used to add flexibility. Enforcement is a suitable alternative only when prevention is strictly necessary; however, we argue that in many situations a corrective approach based on monitoring is more flexible and suitable. To add more flexibility, the hybrid smart contract can be programmed to stop to request the intervention of a human or of a group of them when human judgment is needed.
As blockchain smart contracts become more widespread and carry more valuable digital assets, they become an increasingly attractive target for attackers. Over the past few years, smart contracts have been subject to a plethora of devastating attacks, resulting in billions of dollars in financial losses. There has been a notable surge of research interest in identifying defects in smart contracts. However, existing smart contract fuzzing tools are still unsatisfactory. They struggle to screen out meaningful transaction sequences and specify critical inputs for each transaction. As a result, they can only trigger a limited range of contract states, making it difficult to unveil complicated vulnerabilities hidden in the deep state space. In this paper, we shed light on smart contract fuzzing by employing a sequence-aware mutation and seed mask guidance strategy. In particular, we first utilize data-flow-based feedback to determine transaction orders in a meaningful way and further introduce a sequence-aware mutation technique to explore deeper states. Thereafter, we design a mask-guided seed mutation strategy that biases the generated transaction inputs to hit target branches. In addition, we develop a dynamic-adaptive energy adjustment paradigm that balances the fuzzing resource allocation during a fuzzing campaign. We implement our designs into a new smart contract fuzzer named MuFuzz, and extensively evaluate it on three benchmarks. Empirical results demonstrate that MuFuzz outperforms existing tools in terms of both branch coverage and bug finding. Overall, MuFuzz achieves higher branch coverage than state-of-the-art fuzzers (up to 25%) and detects 30 % more bugs than existing bug detectors.
Minh Vu Nguyen, Ngoc Thuy Le, Dung Hoang Duong, Yannan Li · 5 authors
This paper presents a comprehensive investigation into the role, functionalities, and complexities of blockchain oracles, focusing particularly on the implications for smart contracts in legal reasoning contexts. Oracles serve as a vital bridge to smart contractsâ inability to interact with external or âoff-chainâ data, enabling them to be used in a variety of real-world situations. Oracleâs integration, however, introduces a number of complexities, including security vulnerabilities, collectively referred to as the Oracle Problem. In addition to a review of existing literature, we also provide a mathematical analysis quantifying the computational complexity associated with automating legal reasoning and a novel design framework aimed at establishing oracles that are secure, efficient, and legally compliant. The paper aims to serve as a foundational text for researchers, legal practitioners, and blockchain developers, advancing the academic discourse surrounding blockchain oracles and their role in smart contracts.
Since years the hackers' movement warns about it. For a huge cultural misunderstanding, we are going on trying to learn new technologies according to the rules of the old school or using them as if we could learn directly from the market. The most cannot properly use the present devices too powerful and easy, and many ideas on the future come from science fiction. It's difficult to understand that the Web is made by each of us and depends on what we put in it, more than on our visits online. Once the Internet was attended by a small vanguard capable of managing websites and blogs, gathering in communities, innovating audiovisual and media, sharing experiences and knowledge. Since several years we are billions crowded in networks much more commercial than social, where no technical skills or references to reality are required: Really âreadyâ for the incoming metaverse, AI and the Web3?
Rajendra Hegadi, Syam Sankar Karthik Akella, K. Om Prakash Reddy, C. Pavan Kumar
As we enter a new era of decentralized applications and blockchain technology, the issue of Web3 security becomes crucial and requires immediate attention. Given the growing popularity of using smart contracts in web3, it is vital to ensure the protection of digital assets and user data online. This paper aims to examine the different security risks associated with smart contracts in web3 and propose measures to mitigate them. This research article delves into the identification, causes, and potential mitigation steps for common vulnerabilities found in smart contracts in web3. Specifically, we focus on six major vulnerabilities: overflow and underflow, access control vulnerabilities, re-entrancy attacks, price manipulation attacks, signature reply attacks and self-destruct attacks. By comprehensively discussing these vulnerabilities and offering mitigation strategies, this research aims to disseminate the security vulnerabilities in smart contracts in Web3 ecosystem and provides a path way for adoption of blockchain technology.
This project embarks on a spatial inquiry into Web3. Often hailed as the next iteration of the internet, Web3 is more than a facelift; itâs a calculated unveil that prompts us to re-examine Web2âs participatory past. Importantly, Web3âs algorithmic architecture both expands the webâs horizons and reflexively delineates its own perceptual identity. As it rises alongside digital platformsâ hegemony, we must scrutinize the territories it foregrounds â the very âwheresââ and the underlying âwhysâ that sculpt its distinct vantage for vested agendas. Drawing insights from media studies, critical data studies, and STS, this project focuses on influential powers sculpting the interplay between corporate developers and the Web3 landscape. The theoretical framework is primarily organized around the concepts of news cartography, architectsâ gaze, and software performativity. Methodologically, this tripartite study leans on multiple ethnographic works to go beyond just studying tech structures, capturing both material and discursive forces that mold them. My empirical focus is grounded in specialist journalistic publications (in chapter 1), ethnographic observations, and aggregated data of sites (in chapters 2 and 3). Each chapter underscores its rationale for data collection, yet aliging with the ethos of infrastructure ethnography. My research pivots on the argument that Web3 gives rise to âalgorithmic spatiality.â It extends beyond softwareâs materiality, echoing geographersâ assertions that (digital) space is programmed, assembled, and arranged. Thus, I view Web3 not just as a deliberate construct, but also as a dialogical practice of shaping and organizing its very essence. Influenced by Masseyâs (1999) portrayal of power as spatial-relational dynamics, I employ âpower-geometriesâ as a foundational lens to discern the varied influences of Web3 on sociality. This juxtaposes with the pervasive power of existing digital platforms, often termed the Web2 status quo, awaiting transition. For new media research, approaching Web3 with an algorithmic and spatial lens invites us to see sociality as a dynamic reshaping, subtly directed by coded practices, often obscuring their corporate genesis. I argue that to truly fathom our unfolding digital landscape, itâs imperative to closely scrutinize the pivotal roles of key actors. Especially, the corporate-scripted agents, in all their forms, actively molding these emerging topographies.
Said A. Salloum, Khalaf Tahat, Dina Tahat, Ahmed Mansoori · 5 authors
In the burgeoning Metaverse, an intricate digital realm sculpted by the convergence of physical virtual reality and enduring virtual spaces, there lies unprecedented potential for revolutionary social and economic interactions. However, despite its growing influence in our daily lives, there exists a notable research gap: a comprehensive understanding of the security and privacy facets inherent to the Metaverse. This study endeavors to bridge this gap by examining the pivotal dimensions of security and privacy within this nascent domain. As the distinctions between physical and digital realms fade, comprehending and addressing vulnerabilities becomes vital to preempt threats and uphold individual freedoms. Our findings elucidate not only the continuous threats, such as unauthorized data breaches and virtual reality hardware susceptibilities but also spotlight promising countermeasures. The utility of blockchain for decentralized identity protection and zero-knowledge proofs for enhancing transactional privacy without excessive data exposure are exemplary solutions. Additionally, the emergence of AI-driven security offers the potential for defenses that adapt to shifting threats. Yet, relying exclusively on technological innovations is insufficient. The Metaverse's enduring success and safety rest on a symbiotic relationship among technology, regulatory frameworks, and informed user participation. This requires developers to be proactive in integrating security, regulators to formulate and enforce robust standards, and users to stay vigilant. To conclude, the Metaverse, with its transformative potential, can only flourish within a trustworthy and secure environment. It necessitates a collaborative effort from all stakeholders to foster a Metaverse that truly enriches, empowers, and connects users in this expansive digital landscape.
Nov 14, 2023·2023 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech)
Reentrancy is a type of attack that can occur in smart contracts, enabling untrusted external code execution within the contract. This method exploits a vulnerability that allows an attacker to repeatedly invoke a function in the contract, resulting in an infinite loop and potentially leading to fund theft. Therefore, the reentrancy attack represents a critical concern in blockchain security, prompting the development of various methods for analyzing and detecting reentrancy vulnerabilities over the last decade. Among these methods, the most recent ones leverage the advantages of AI and deep learning techniques. Nonetheless, several limitations persist in existing approaches. Many current methods rely on complex code analysis rules, resulting in a high number of false positives and false negatives. Additionally, the feature engineering process involving word embedding techniques can lead to the loss of critical information. Lastly, the majority of proposed methods necessitate access to the actual source code of the smart contracts for analysis. In this study, we introduce a straightforward and lightweight approach to address these limitations in reentrancy detection. Our approach employs an image-based detection method utilizing deep learning. The pipeline of our method involves disassembling the smart contracts into opcodes and transforming them into RGB images. These images are then used to train a VGG16 CNN model to detect similarities between images labeled as either âVulnerableâ or âNot Vulnerableâ. To address class imbalance, we implement image augmentation techniques to expand the training dataset. Experimental results conducted on a publicly available dataset demonstrate that our model achieves a significantly high accuracy rate of 99.07%.
Abstract Providing trust in machine learning (ML) systems and their fairness is a socio-technical challenge, and while the use of ML continues to rise, there is lack of adequate processes and governance practices to assure their fairness. In this paper, we propose FaaS, a novel privacy-preserving, end-to-end verifiable solution, that audits the algorithmic fairness of ML systems. FaaS offers several features, which are absent from previous designs. The FAAS protocol is model-agnostic and independent of specific fairness metrics and can be utilised as a service by multiple stakeholders. FAAS uses zero knowledge proofs to assure the well-formedness of the cryptograms and provenance in the steps of the protocol. We implement a proof of concept of the FaaS architecture and protocol using off-the-shelf hardware, software, and datasets and run experiments to demonstrate its practical feasibility and to analyse its performance and scalability. Our experiments confirm that our proposed protocol is scalable to large-scale auditing scenarios (e.g. over 1000 participants) and secure against various attack vectors.
Identity theft is one of the fastest-growing forms of cybercrime, driven by large-scale data breaches, phishing, and increasingly sophisticated impersonation attacks. Traditional identity verification methods such as passwords, PINs, and physical documents have proven inadequate in ensuring security at scale. Artificial Intelligence (AI) has emerged as a transformative enabler of next-generation identity verification by leveraging multimodal techniques, including facial recognition, voice biometrics, and document authentication. The paper discusses how AI- based verification systems can be used to prevent identity theft and how the system is used in real-time adaptive, and frictionless authentication over high-stakes areas, including banking, healthcare, e-commerce, and government services. We introduce a multi-layered verification system that combines the facial, voice and document verification modules in a single decision layer to minimize the false positives and negative but enhances the system resistance to spoofing and adversarial attacks. Practical implementations, advantages and governance are described using case studies of financial institutions, e-commerce websites and national identity programs. Nevertheless, there are still obstacles, such as demographic bias, privacy risks, adversarial vulnerability and lack of a coherent regulatory framework that makes it difficult to achieve mass adoption. In the future, we will address future directions in the area of decentralized identity, federated learning, zero-knowledge proofs, explainable AI, and international regulatory alignment. These innovations will work towards building trust, fairness and interoperability in digital identity ecosystems. Finally, this paper shows that AI-based identity verification is not merely a technological breakthrough but one of the essential needs to protect individuals, organizations, and governments against identity theft during the digital age.
Marielle S. Gross, Amelia Hood, William Lancelot Sanchez
Decentralized biobanking âde-biâ applies blockchain technology and web3 values to embed the procedural principles of transparency, accountability, and inclusion into the biomedical research ecosyst...
Recent developments in the field of AI and the public availability of remarkably powerful AI tools, such as the chatbot ChatGPT, have sparked mass interest in AI, raised the possibility of timely emergence of an artificial general intelligence, and thus increased the urgency for AI safety. As AI alignment lags behind other developments in AI, this work explores how blockchain technology can support AI safety. Other works propose the use of distributed ledger technology for this purpose, but mostly without referring to novel consensus mechanisms. This paper suggests to write AI alignment rules in a blockchain that can only be updated by humans using a Proof of Personhood consensus mechanism in combination with, for instance, identity mechanisms and biometric features. Thus, relevant technologies are identified and combined to propose a system that is protected from AI interference and suitable to govern its behavior. Designing such a system is of great importance at a time when an artificial general intelligence could emerge that might one day reject human ethics, goals, and principles.
Oct 7, 2023·Adjunct Proceedings of the 2023 ACM International Joint Conference on Pervasive and Ubiquitous Computing & the 2023 ACM International Symposium on Wearable Computing
The significant increase in data production resulting from the widespread adoption of mobile and IoT technologies has revolutionized healthcare but also presents significant privacy and ethical challenges. The field of medical data collection is no exception and has limitations in terms of the source, variety and quantity of records from studies on healthcare and wellness. One way to address this dilemma is the use of the Blockchain for patient data collection and use. The anonymity of a centralized network allows the patientâs identity to be protected. The structure formed by nodes allows the information to be always available and does not depend on a main server. The immutability of records in the chain ensures unambiguous traceability of information flow by the healthcare provider. Finally, the networkâs consensus and reward mechanisms could motivate new users to participate in active sensing. In this article we will expose the architecture of an application that relies on the Blockchain to meet the above information needs by leveraging the potential of the Ethereum network. In addition, we present a use case where consciously collected data from our platform is used to train a machine learning model automatically, using a P2P Browser-Based Computational Notebook as execution and distribution environment.
Federated learning (FL) is a distributed learning process that uses a trusted aggregation server to allow multiple parties (or clients) to collaboratively train a machine learning model without having them share their private data. Recent research, however, has demonstrated the effectiveness of inference and poisoning attacks on FL. Mitigating both attacks simultaneously is very challenging. State-of-the-art solutions have proposed the use of poisoning defenses with Secure Multi-Party Computation (SMPC) and/or Differential Privacy (DP). However, these techniques are not efficient and fail to address the malicious intent behind the attacks, i.e., adversaries (curious servers and/or compromised clients) seek to exploit a system for monetization purposes. To overcome these limitations, we present a ledger-based FL framework known as FLEDGE that allows making parties accountable for their behavior and achieve reasonable efficiency for mitigating inference and poisoning attacks. Our solution leverages crypto-currency to increase party accountability by penalizing malicious behavior and rewarding benign conduct. We conduct an extensive evaluation on four public datasets: Reddit, MNIST, Fashion-MNIST, and CIFAR-10. Our experimental results demonstrate that (1) FLEDGE provides strong privacy guarantees for model updates without sacrificing model utility; (2) FLEDGE can successfully mitigate different poisoning attacks without degrading the performance of the global model; and (3) FLEDGE offers unique reward mechanisms to promote benign behavior during model training and/or model aggregation.
Kawsalya Maharajan, A. V. Senthil Kumar, Ibrahiem M. M. El Emary, Priyanka Sharma · 9 authors
Blockchain encourages artificial intelligence towards intelligence while also increasing its autonomy and credibility. In this chapter, the authors examine the relationship between blockchain technology and artificial intelligence from a more thorough and three-dimensional standpoint. One of the greatest problems with blockchain implementations in IoV is that they cannot meet the computational and energy needs of conventional blockchain systems since IoV nodes are limited in their ability to use resources. A marketplace that enables stakeholders (CSPs, asset suppliers, service providers, regulators, etc.) to interact and exchange value with confidence based on smart provenance and governance may be developed using blockchain and distributed ledger technologies (DLT). These innovations offer a decentralised audit architecture that is safe. Such transactions (who uses what) can be kept on a distributed ledger marketplace in an immutable setting. A decentralised consensus process that does not need mining or incentivization in a permissionless architecture ensures data integrity.
Fair machine learning is a thriving and vibrant research topic. In this paper, we propose Fairness as a Service (FaaS), a secure, verifiable and privacy-preserving protocol to computes and verify the fairness of any machine learning (ML) model. In the deisgn of FaaS, the data and outcomes are represented through cryptograms to ensure privacy. Also, zero knowledge proofs guarantee the well-formedness of the cryptograms and underlying data. FaaS is model--agnostic and can support various fairness metrics; hence, it can be used as a service to audit the fairness of any ML model. Our solution requires no trusted third party or private channels for the computation of the fairness metric. The security guarantees and commitments are implemented in a way that every step is securely transparent and verifiable from the start to the end of the process. The cryptograms of all input data are publicly available for everyone, e.g., auditors, social activists and experts, to verify the correctness of the process. We implemented FaaS to investigate performance and demonstrate the successful use of FaaS for a publicly available data set with thousands of entries.
Chong Chen, Jianzhong Su, Jiachi Chen, Yanlin Wang · 10 authors
With the development of blockchain technology, smart contracts have become an important component of blockchain applications. Despite their crucial role, the development of smart contracts may introduce vulnerabilities and potentially lead to severe consequences, such as financial losses. Meanwhile, large language models, represented by ChatGPT, have gained great attention, showcasing great capabilities in code analysis tasks. In this article, we presented an empirical study to investigate the performance of ChatGPT in identifying smart contract vulnerabilities. Initially, we evaluated ChatGPTâs effectiveness using a publicly available smart contract dataset. Our findings discover that while ChatGPT achieves a high recall rate, its precision in pinpointing smart contract vulnerabilities is limited. Furthermore, ChatGPTâs performance varies when detecting different vulnerability types. We delved into the root causes for the false positives generated by ChatGPT, and categorized them into four groups. Second, by comparing ChatGPT with other state-of-the-art smart contract vulnerability detection tools, we found that ChatGPTâs F-score is lower than others for 3 out of the 7 vulnerabilities. In the case of the remaining 4 vulnerabilities, ChatGPT exhibits a slight advantage over these tools. Finally, we analyzed the limitation of ChatGPT in smart contract vulnerability detection, revealing that the robustness of ChatGPT in this field needs to be improved from two aspects: its uncertainty in answering questions; and the limited length of the detected code. In general, our research provides insights into the strengths and weaknesses of employing large language models, specifically ChatGPT, for the detection of smart contract vulnerabilities.
Pursuing âintelligent justiceâ necessitates an impartial, productive, and technologically driven methodology for judicial determinations. This scholarly composition proposes a framework that harnesses Artificial Intelligence (AI) innovations such as Natural Language Processing (NLP), ChatGPT, ontological alignment, and the semantic web, in conjunction with blockchain and privacy techniques, to examine, deduce, and proffer recommendations for the administration of justice. Specifically, through the integration of blockchain technology, the system affords a secure and transparent infrastructure for the management of legal documentation and transactions while preserving data confidentiality. Privacy approaches, including differential privacy and homomorphic encryption techniques, are further employed to safeguard sensitive data and uphold discretion. The advantages of the suggested framework encompass heightened efficiency and expediency, diminished error propensity, a more uniform approach to judicial determinations, and augmented security and privacy. Additionally, by utilizing explainable AI methodologies, the ethical and legal ramifications of deploying intelligent algorithms and blockchain technologies within the legal domain are scrupulously contemplated, ensuring a secure, efficient, and transparent justice system that concurrently protects sensitive information upholds privacy.
With the increasing popularity of cryptocurrencies and blockchain technologies, smart contracts have become a prominent feature in developing decentralized applications. However, these smart contracts are susceptible to vulnerabilities that hackers can exploit, resulting in significant financial losses. In response to this growing concern, various initiatives have emerged. Notably, the Smart Contract Weakness Classification (SWC) list plays an important role in raising awareness and understanding of smart contract weaknesses. However, the SWC list lacks maintenance and has not been updated with new vulnerabilities since 2020. To address this gap, this paper introduces the Smart Contract Weakness Enumeration (SWE), a comprehensive and practical vulnerability list up until 2023. We collect 273 vulnerability descriptions from 86 top conference papers and journal papers, employing the open card-sorting method to deduplicate and categorize these descriptions. This process results in the identification of 40 common contract weaknesses, which are further classified into 20 sub-research fields through thorough discussion and analysis. The SWE provides a systematic and comprehensive list of smart contract vulnerabilities, covering existing and emerging vulnerabilities in the last few years. Moreover, the SWE is a scalable and continuously iterative program. We propose two update mechanisms for the maintenance of the SWE. Regular updates involve the inclusion of new vulnerabilities from future top papers, while irregular updates enable individuals to report new weaknesses for review and potential addition to the SWE.