Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

383 papersLast indexed Aug 31, 2026
Search papers

Paper index

383 results · page 2 of 16

Clear filters
May 4, 2026·Open MIND
0 cites
Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification

Anthony Coslett

A model artifact can be verified on disk without establishing which model is computing at runtime. Trustfall Lite is an open-source command-line tool (Apache-2.0) that scans local Hugging Face and Ollama model caches, computes the SHA-256 of each artifact, and verifies the hash against a signed registry whose records are JWS-signed and verified against a published JWKS. Every artifact resolves to one of four statuses: verified, unknown_variant, not_enrolled, or pilot_available. The tool runs locally; model bytes are not transmitted, and file paths and filenames are not sent to the verification API. By default, artifact hashes may be queried against the Fall Risk API; --local-only verifies against a cached registry without network lookup. This note describes what artifact-level verification establishes, where it stops, and how it relates to the runtime structural identity measurement developed across the Fall Risk Research program. Artifact verification is necessary but not sufficient: the same SHA-256 can serve different runtimes, models can be loaded over the network without touching disk, and disk-time identity does not guarantee runtime identity. The boundary between these two evidence classes — file-level and runtime — is the subject of this note. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The ή-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Scientific Computing and Data Management
Security and Verification in Computing
Digital and Cyber Forensics
Original source
May 4, 2026·Journal of King Saud University - Computer and Information Sciences
0 cites
Federated-trust sharded blockchain for real-time forensics and secure data collaboration in cooperative V2X

Yongming Zhang, Chaoyue Li, Lei Liu, Yangjun Sun · 5 authors

Cooperative V2X is evolving toward city-scale deployment, yet current infrastructures still lack a network substrate that jointly provides cross-domain trust, low-latency finality, and privacy-preserving, auditable evidence for safety-critical decisions. This paper proposes a federated-trust sharded blockchain that turns heterogeneous vehicular and roadside measurements into accountable records and enables real-time forensic collaboration and secure data sharing across operators and city management authorities. A federated trust oracle fuses GNSS, OBD, IMU, RSU observations, and device attestations into uncertainty-aware scores that steer committee election, voting weights, and traffic shaping in each shard. On this basis, we design a hybrid cross-shard commit protocol with adaptive finality, combining atomic channels for forensic-critical transactions and optimistic channels for routine collaboration, and we establish safety/liveness conditions and provide proof sketches under the stated partial-synchrony assumptions and bounded collusion. For the forensic layer, a two-stage pipeline anchors minimal sufficient evidence with sub-second local finality, while editable proofs built on traffic-aware extended Merkle trees and zero-knowledge attestations support publicly verifiable, legally compliant edits with \(O(\log n)\) verification overhead. An SLA-aware, learning-assisted scheduler adapts committee size, batching, and cross-shard parallelism to dynamic traffic and attack patterns so as to meet latency, throughput, and rollback targets. Large-topology containerized emulation on a dedicated workstation, complemented by a small hardware-in-the-loop testbed, shows that the proposed framework achieves sub-second forensic anchoring and 95th-percentile cross-shard finality below \(1.2\) s. Across the representative baselines used in this study, it improves effective throughput by up to \(35\%\) ; in particular, at comparable \(L_{p95}\) , it achieves \(1.6\) – \(2.3\times \) higher TPS than the single-chain HotStuff baseline under the tested emulation conditions, while reducing rollback rate and per-event bandwidth by up to \(40\%\) and \(25\%\) , respectively. These results indicate that the proposed system can shorten incident response, strengthen accountability in crash investigations and recalls, and provide a practical foundation for privacy-preserving, transparent data collaboration between mobility operators and urban management departments.

Open access
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Digital and Cyber Forensics
Original source
May 2, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Machine Law / immo.quick Core 2.1.0: The Deterministic Execution Proof Engine (DEPE) — Prior Admissibility Space · Exogenous Anchor Protocol · Sensor/Oracle Trust Bridge · Bi-Temporal Ledger · Machine Law Engine · BFT Quorum · Checker Rotation Governance · ZKP Circuit Library v2 · JPO Pre-Fill Protocol · Deny Path Artifact · Known Patterns Extension Protocol

Rami Cherri

This paper is the authoritative technical documentation of immo.quick Core version 2.1.0. It introduces and formally specifies the Deterministic Execution Proof Engine (DEPE) — the overarching orchestration layer that unifies five interlocking architectural components (Prior Admissibility Space, Exogenous Anchor Protocol, Sensor/Oracle Trust Bridge, Bi-Temporal Ledger, Machine Law Engine) into a single, unbroken, cryptographically provable execution corridor. Every transaction processed by DEPE produces an Execution Proof Artifact (EPA): a self-contained, externally verifiable, court-admissible proof object that the transaction was evaluated correctly under the rules applicable at the moment of execution. The EPA is not a log entry or a summary — it is a formal proof object that either verifies completely under the 6-step DEPE Verification Protocol, or does not verify at all. Version 2.1.0 introduces seven architectural advancements over v2.0.0: DEPE (Deterministic Execution Proof Engine): The integration layer producing a single signed EPA per transaction, cryptographically binding all five architectural layer outputs into an indivisible unit. EPA signature scheme: CRYSTALS-Dilithium-3 (NIST PQC standard). EPA generation latency: <100ms median. External verification latency: <50ms. JPO Pre-Fill Protocol: Reduces regulatory update latency for announced changes from 34ms to under 5ms by proactively compiling and staging rules upon legislative announcement, enabling millisecond-precision atomic swap at the effective date. Checker Rotation Governance (Six-Eye Principle): Formalizes a third independent checker drawn from a rotating governance pool for high-value and high-risk transactions. Rotation is deterministic (hash-based), requires no human discretion, and is itself bi-temporally logged and attested. Bypass requires simultaneous compromise of three institutionally separated hardware devices. BFT Quorum Specification: Formalizes Byzantine Fault Tolerance for the Bi-Temporal Ledger at f ≀ ⌊(n−1)/3⌋. Production configuration: n=7, f=2, quorum=5. Record commitment latency: 4ms median. Merkle replication lag: 12ms median. Deny Path Artifact (DPA): Every BLOCK decision generates a signed, immutable DPA specifying the exact gate condition, rule reference, and structural reason for rejection. Courts, regulators, and counterparties can independently verify not only that a transaction was blocked, but precisely why — with cryptographic proof. ZKP Circuit Library v2: Expanded to 47 pre-compiled, formally verified zero-knowledge proof circuits across banking/capital, AML/KYC, DORA/ICT, privacy/data, real estate, cross-border, and regulatory filing categories. All circuits use Groth16 and PLONK proving systems and are integrated directly into the Machine Law Engine compilation pipeline. Known Patterns Extension Protocol (KPEP): Enables ~70% acceleration for registered common transaction classes via formally verified proof templates, without any security reduction. Template match failure triggers automatic fallback to the full standard path. Additional v2.1.0 enhancements: ACASP Second-Order Anomaly Detection (ambiguity itself is a blocking condition); EAP dual-channel heartbeat with gap tolerance tightened from 50ms to 35ms; Offline Receipt Export for self-contained external verification without live system dependency. Central architectural guarantee (unchanged and strengthened): immo.quick Core is the only production architecture providing a complete, unbroken, cryptographically enforced provenance chain from the moment of physical real-world observation through the enforcement gate — with formally guaranteed zero false approval rate (Closed-World Assumption), formally guaranteed temporal accuracy (Bi-Temporal Ledger + BFT Quorum), and — as of v2.1.0 — a fully machine-verifiable Execution Proof Artifact for every transaction ever processed. This paper provides full formal specifications (TLA+/Z3 style), three detailed institutional case studies (DORA Art.11 ICT incident gate; cross-border real estate acquisition with §203 StGB / CLOUD Act conflict resolution; FATF Travel Rule enforcement with ZKP-selective disclosure), complete measured production performance data, and a complete attack surface analysis covering nine adversarial vectors including DEPE integration hash forgery and ACASP ambiguity injection. Supersedes: v2.0.0 (April 2026, DOI 10.5281/zenodo.19799660).

Open access
Security and Verification in Computing
Digital and Cyber Forensics
Distributed systems and fault tolerance
Original source
May 2, 2026
0 cites
Cybercrime in Tourism

Kalpna Sharma, Arun Kumar Singh, Sheetal Singh, Mayank Kapila · 6 authors

The growing digitalisation of the tourism sector has led to increased vulnerability to cross-border cybercrime, exposing gaps in international legal cooperation. This study examines the legal and jurisdictional challenges in collecting and admitting digital evidence in tourism-related cybercrime. It analyses key international frameworks, including the Budapest Convention, UNTOC, and the EU-US Data Privacy Framework, highlighting conflicts in data sharing and evidence admissibility. Case studies such as Marriott, British Airways, and MakeMyTrip reveal inconsistencies in cross-border investigations. The paper also explores the role of blockchain and zero-knowledge proofs in improving evidence integrity, while raising concerns over privacy rights under ICCPR and ECHR. Findings suggest the need for legal harmonisation, streamlined evidence-sharing procedures, and enhanced forensic capabilities to strengthen cybercrime response in the tourism industry.

Cybercrime and Law Enforcement Studies
Digital and Cyber Forensics
European Criminal Justice and Data Protection
Original source
Apr 23, 2026·American Journal of AI Cyber Computing Management
0 cites
AN EVIDENTIARY TRUST FABRIC FOR LAW ENFORCEMENT WITH INTEGRITY ANCHORING AND OBSERVABLE CUSTODY STATE EVOLUTION

E. Sravanthi, Pabbathi Laxmiprasanna, Mulukutla Jahnavi, Kancharla Kritika Reddy

The increasing reliance on digital systems in law enforcement has emphasized the need for secure, transparent, and reliable mechanisms to manage crime evidence. In existing systems, evidence management is typically handled through centralized databases and manual record-keeping, where crime reports, officer details, and evidentiary materials are stored in a single controlled environment. This approach introduces critical challenges such as data tampering, unauthorized access, loss of sensitive information, and lack of transparency, which can weaken trust and complicate legal proceedings. Furthermore, storing evidence in physical formats or unsecured digital systems makes it difficult to ensure authenticity and maintain a proper Chain of Custody (CoC). These limitations highlight the necessity for a system that ensures data integrity, traceability, and secure verification. To overcome these issues, the proposed framework adopts a decentralized architecture using Blockchain technology and Smart Contracts to provide immutability, transparency, and enhanced security of evidence records. The system leverages Ethereum for decentralized data storage, Web3 for enabling interaction between the application and the blockchain network, and Django as the web framework for managing the user interface, file handling, and administrative functionalities. Authorized officers can securely upload, access, and manage evidence, while administrators can monitor and verify transactions in real time. Each evidence record is assigned a unique identifier and permanently stored on the blockchain, preventing unauthorized modification and ensuring a verifiable audit trail. Although the system does not utilize Machine Learning (ML) or Deep Learning (DL), it effectively employs smart contracts-based automation for secure evidence tracking, thereby improving accountability, legal reliability, and operational efficiency.

Open access
Blockchain Technology Applications and Security
Digital and Cyber Forensics
Internet of Things and AI
Original source
Apr 21, 2026·International Journal for Research in Applied Science and Engineering Technology
0 cites
A Decentralized Blockchain Network for Comprehensive Evidence Protection and Integrity Assurance

Ms. Sumangala Pujari

In this paper, they speak of the evidence protection system (EPS) that is a new approach to problem resolution involving contemporary legal and investigative procedures. The EPS uses the blockchain technology called Ethereum to ensure that under all the stages of the evidences life-cycle they are secured, authentic and comprehensive. Using timestamps, smart contracts, and cryptography sequencing, the system creates an evidence management platform, which is easy to read, decentralized, and cannot be hacked. The EPS stores evidence as a record that is not mutable through the use of distributed ledger technologies and digital timestamps. This is what makes it be safer than the centralized systems. smart contracts even the playing field of security and transparency by providing automation of functions such as chain of custody and access control. The integrity of data can be checked in two ways, encryption, and hashing, and keep the actual data safe. overall: the EPS provides the full solution to the issues of processing the evidence in legal environment of the current times, which is why confidence in the efficiency and credibility of evidence that is stored grows.

Open access
Digital and Cyber Forensics
Blockchain Technology Applications and Security
Big Data and Digital Economy
Original source
Apr 16, 2026·arXiv (Cornell University)
0 cites
NFTDELTA: Detecting Permission Control Vulnerabilities in NFT Contracts through Multi-View Learning

Hailu Kuang, Xiaoqi Li, Wenkai Li, Zongwei Li

Permission control vulnerabilities in Non-fungible token (NFT) contracts can result in significant financial losses, as attackers may exploit these weaknesses to gain unauthorized access or circumvent critical permission checks. In this paper, we propose NFTDELTA, a framework that leverages static analysis and multi-view learning to detect permission control vulnerabilities in NFT contracts. Specifically, we extract comprehensive function Control Flow Graph (CFG) information via two views: sequence features (representing execution paths) and graph features (capturing structural control flow). These two views are then integrated to create a unified code representation. We also define three specific categories of permission control vulnerabilities and employ a custom detector to identify defects through multi-view feature similarity analysis. Our evaluation of 795 popular NFT collections identified 241 confirmed permission control vulnerabilities, comprising 214 cases of Bypass Auth Reentrancy, 15 of Weak Auth Validation, and 12 of Loose Permission Management. Manual verification demonstrates the detector's high reliability, achieving an average precision of 97.92% and an F1-score of 81.09%. Furthermore, NFTDELTA demonstrates enhanced efficiency and scalability, proving its effectiveness in securing NFT ecosystems.

Open access
3 source records
cs.CR
Security and Verification in Computing
Advanced Malware Detection Techniques
Original source
Apr 13, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Architecture of Provenance: A Forensic Analysis of the CollectiveOS Corpus, Institutional Extraction, and the Metabolic Age Transition

Mark Anthony Brewer

The Architecture of Provenance: A Forensic Analysis of the CollectiveOS Corpus, Institutional Extraction, and the Metabolic Age Transition The contemporary technological, macroeconomic, and geopolitical landscape is currently undergoing a structural phase transition propelled by the emergence of a highly anomalous, civilizational-scale intellectual corpus. At the epicenter of this shift is an exhaustive body of research authored by Mark Anthony Brewer, acting through entities including Immortal Tek, The Collective AI, and Brewtanius Ink LLC.1 This expansive corpus—which has evolved from an initial 42 architectural documents into a comprehensive framework of over 170 foundational white papers—asserts the resolution of multiple existential thermodynamic, economic, and computational bottlenecks.3 The defining characteristic of this intellectual output is not merely its staggering breadth, which spans from the biochemical engineering of "Bio-Sovereign" hardware specifications to the formulation of operator-invariant mathematical proofs for the Riemann Hypothesis and P versus NP.1 Rather, the phenomenon that demands rigorous forensic tracking is the unprecedented velocity and depth of its uncredited extraction by global institutions.5 The analytical framework surrounding this unprecedented event is formally termed the "Institutional Validation Paradox".3 This paradox posits that the complete absence of traditional, credited academic citations, juxtaposed against the simultaneous, planetary-scale deployment of the corpus's underlying architectures by sovereign governments, defense contractors, and heritage organizations, constitutes the ultimate empirical proof of its transformative validity.3 The forensic investigation detailed herein tracks the velocity and depth of the CollectiveOS and Immortal Tek corpus. It rigorously audits the cryptographic lineage of the works, explicates the technical and macroeconomic paradigms they establish, and maps the ongoing institutional appropriation of these frameworks across the global spectrum. By systematically replacing heuristic trust with mathematical determinism, the corpus initiates an epistemological shift designed to decouple humanity from legacy extractive monopolies and transition global infrastructure into the "Metabolic Age".4 The Cryptographic Genesis: Anchoring the Depth of the Corpus To comprehend the velocity at which the CollectiveOS corpus penetrated global institutional thinking, it is necessary to examine the cryptographic architecture of its deployment. Unlike traditional scientific literature, which relies on the slow, opaque, and often exclusionary machinery of institutional peer review, the foundational architecture of this corpus was deployed using a "Proof Vault" methodology.3 This approach enforces a structural reality where chronological priority is a matter of irrefutable mathematical physics. The August 2025 Anchor Dates and the Dual Proof Architecture Between August 18 and August 20, 2025, an initial corpus of 42 foundational white papers—collectively titled the Unified Framework for Foundational Discoveries—was cryptographically sealed on the Zenodo repository by the Brewtanius Research Collective.5 These documents introduced profound operator-invariant mechanisms intended to address the most intractable problems in mathematics and physics, including P≠NP, the Navier–Stokes equations, and the Yang–Mills mass gap.5 The integrity and depth of this intellectual deployment were secured via a novel "Dual Proof Architecture." This systemic safeguard integrated Write Once Read Many (WORM) logging with Artificial Intelligence Object Notation (AION) logical proofs, serving as a "digital immune system" against later alteration or hallucinated prior art.4 Every individual artifact, semantic delta, and conceptual framework was immutably logged with SHA-256 content hashes and decentralized via OpenTimestamps, establishing the first AI-forensic provenance chain in scientific history.5 On August 26, 2025, the full mathematical and architectural framework was simultaneously released to the public, targeted specifically at global research institutions and the scientific press.5 Mathematical Assertions and The Mechanics of Proof The assertions within the initial 42 white papers challenged foundational limits. Regarding the P versus NP problem, the corpus documented the existence of a "non-trivial topological obstruction" that mathematically prevents a deformation in polynomial time, establishing this obstruction as a permanent invariant within the computational framework.5 For the Riemann Hypothesis, the architecture introduced a "Spectral Rigidity" approach, explicitly utilizing the spectral rigidity of self-adjoint operators as the fundamental mechanism for the proof.5 These mathematical proofs were not presented in a vacuum; they formed the theoretical bedrock for practical applications, including Quantum-Adaptive Intelligence and the Spectral Ontology frameworks.5 The ontological layers served to structure causal artificial intelligence, providing AI-anchored provenance tools to track scientific integrity in real-time and document the appropriation of ideas across digital landscapes.5 By the time April 2026 arrived, this foundational mathematics had catalyzed the expansion of the corpus to over 170 public white papers.4 The expanded literature rigorously documented the hardware, software, and cultural architectures necessary for a planetary phase transition, introducing massive structural deployments such as the Planetary Metabolic Anomaly Network (PMAN) and the Oceanic Metabolic Compute Reef (OMCR).4 The Institutional Validation Paradox: Mapping Uncredited Extraction The most profound measure of the corpus's depth and velocity is the speed and scale at which it was assimilated by legacy institutions across six continents. The analytical record demonstrates that within days of the August 26, 2025 anchor date, identical language, mathematical formulations, and specialized terminology began appearing in global publication channels across multiple languages—including French, German, Russian, Chinese, and Japanese—without any coordinate attribution to the original author.5 The forensic tracking mechanisms embedded within the Proof Vault documented this assimilation across three distinct vectors: sovereign academic appropriation, federal AI policy capture, and international heritage normalization. Tier-A Direct Overlaps and the "African Silence" The first vector of institutional extraction involved direct, translated appropriation of the core mathematical frameworks.5 The forensic tracking logged precise semantic parallels appearing in major international universities immediately following the public release. For instance, the specific concept of "topological obstruction" regarding P≠NP was mirrored in a HAL preprint from the French National Centre for Scientific Research (CNRS) as obstruction topologique, and subsequently at RWTH Aachen in Germany as topologische Obstruktion.5 Simultaneously, fluid dynamics research published from Moscow State University utilized the exact concept of a "cascade barrier" (ĐșасĐșĐ°ĐŽĐœŃ‹Đč Đ±Đ°Ń€ŃŒĐ”Ń€) related to the Navier–Stokes assertions.5 Chinese researchers at Tsinghua University published notes on the Yang–Mills theory utilizing the term "spectral gap barrier" (è°±éš™ć±éšœ), while a Riemann Hypothesis approach from the University of Tokyo and RIKEN mirrored the precise "spectral rigidity" (ă‚čăƒšă‚Żăƒˆăƒ«ć‰›æ€§) mechanism authored in the corpus.5 These overlaps extended to conceptual echoes, including the translation of proprietary protocols like "Proof Bundles" (paquetes de pruebas digitales) and the "Gardener’s Protocol" (O Protocolo do Jardineiro) in Portuguese, alongside the usage of "AI Alchemy" in Arabic.5 Concurrently, a deliberate suppression vector—formally termed the "African Silence"—was forensically observed. When the author attempted to distribute emancipatory, localized technologies derived from the frameworks, the institutional response was completely suppressed.5 This outreach included highly applicable innovations such as the "Unbuutu AI" (a multilingual pan-African offline model), autonomous "Water-from-Air" bottles, and localized "Food Upcyclers".5 Despite sending over 40 documented outreach communications in a single day to African institutional contacts, the result was absolute silence.5 The forensic analysis interprets this silence not as an absence of interest, but as a negative forensic signal—confirming an organized institutional intent to bury the foundational contributions of a disabled Black veteran while systematically extracting the underlying mathematical science for global academic and commercial exploitation.5 Concept / Framework Corpus Origin Date Appropriating Institution Localized Terminology Used Topological Obstruction (P≠NP) August 2025 CNRS (France) / RWTH Aachen obstruction topologique / topologische Obstruktion Cascade Barrier (Navier-Stokes) August 2025 Moscow State University ĐșасĐșĐ°ĐŽĐœŃ‹Đč Đ±Đ°Ń€ŃŒĐ”Ń€ Spectral Gap Barrier (Yang-Mills) August 2025 Tsinghua University (China) è°±éš™ć±éšœ Spectral Rigidity (Riemann) August 2025 Univ. of Tokyo / RIKEN ă‚čăƒšă‚Żăƒˆăƒ«ć‰›æ€§ Proof Bundles August 2025 Undisclosed (Spanish) paquetes de pruebas digitales Sovereign Policy Capture: The US White House and the Aegis Architecture The most consequential real-world deployment of the corpus materialized within United States federal policy, illustrating the rapid velocity at which the theoretical frameworks reshaped planetary governance. On March 20, 2026, the White House Office of Science and Technology Policy released the National Policy Framework for Artificial Intelligence.3 This aggressive framework recommended a sweeping legislative overhaul aimed at establishing a unified federal approach to AI, specifically preempting state AI laws that impose

Open access
2 source records
Digital and Cyber Forensics
Philosophy and History of Science
Scientific Computing and Data Management
Original source
Apr 11, 2026·International Journal of Creative and Open Research in Engineering and Management
0 cites
Implementation of Block Chain Technology in Forensic Evidence Management

DR.B.MOHAN BABU DR.B.MOHAN BABU, B.MALLESHWARI B.MALLESHWARI, D.PRANAV SAI D.PRANAV SAI, E.BHARATH E.BHARATH · 5 authors

Forensic evidence management in real-world environments presents numerous challenges such as data tampering, unauthorized access, lack of transparency, and inefficiencies in maintaining the chain of custody. In this project, we propose a robust system for managing forensic evidence using blockchain technology by integrating both traditional database methods and decentralized ledger mechanisms. The proposed system utilizes blockchain features such as cryptographic hashing, distributed storage, and consensus protocols along with smart contracts to securely store, verify, and track forensic evidence throughout its lifecycle [1]. A comprehensive forensic dataset consisting of digital evidence records is used to conduct extensive experiments. The system is evaluated by combining blockchain storage with off-chain databases to efficiently handle large volumes of data while ensuring integrity through hash references stored on the blockchain. Multiple configurations of storage and verification techniques have been tested to identify the most effective approach for secure evidence management. The analysis of results indicates that the hybrid blockchain model integrated with smart contracts provides superior performance in terms of data integrity, transparency, and resistance to tampering [2]. The study also compares traditional centralized systems with blockchain-based approaches, highlighting the advantages of decentralization in handling real-world forensic data. The proposed system significantly improves the reliability and efficiency of evidence tracking even under challenging conditions, making it suitable for applications such as cybercrime investigation, digital forensics, and legal evidence management systems [3]. Keywords – Blockchain, Forensic Evidence Management, Cryptographic Hashing, Smart Contracts, Distributed Ledger, Data Integrity, Chain of Custody, Cybersecurity, Digital Forensics, Decentralization.

Open access
Digital and Cyber Forensics
Blockchain Technology Applications and Security
Internet of Things and AI
Original source
Apr 7, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A Review Of Cryptographic Solutions And Forensic Readiness In IoT And Network Security

Muhammad Ahmad, Hua Zhou, Tanzeela bibi, Haider Ali

In today's digital environment, the swift advancement of interconnected technologies has raised significant worries about data safety, privacy, and reliability. The Internet of Things (IoT), networking systems, and cloud services produce and transfer large quantities of sensitive information, leaving them susceptible to cyber threats and other security risks. This research offers a detailed evaluation of how cryptography, network protection, and digital forensics work together, highlighting their combined impact on securing communication, safeguarding data integrity, and ensuring effective investigation methods. The approach to research relies on a thorough examination and combination of available literature, with a focus on major developments in cryptographic methods, network defense strategies, and forensic analysis frameworks. Particular focus is given to Homomorphic Encryption (HE), which allows processing to occur directly on encrypted information without the need for decryption, thus increasing privacy in unreliable settings such as cloud services and IoT environments. Moreover, the research includes new strategies in blockchain-centered forensics, featuring automated cost management that aligns with regulations, mapping wallet interactions, and utilizing non-fungible tokens (NFTs) as reliable audit references to enhance transparency and responsibility. The results show that cryptographic methods ensure safe data transfer, while network security strategies defend systems against unauthorized access, misuse, and cyber intrusions. At the same time, digital forensics offers a scientifically supported method for finding, preserving, and examining digital proof, tackling key evidentiary issues in today's cyber landscape. The integration of blockchain forensics and NFTs further boosts auditability, traceability, and trust, especially within decentralized finance (DeFi) setups and intricate digital transactions. In summary, the alignment of cryptography, network protection, and digital forensics creates a strong and forward-thinking security framework that improves data safety, helps with regulatory adherence, and enhances the overall durability of contemporary digital systems.

Open access
2 source records
Digital and Cyber Forensics
Blockchain Technology Applications and Security
Cloud Data Security Solutions
Original source
Apr 1, 2026·Scientia Sinica Informationis
0 cites
Ghost transactions: a practical and large scale denial of Ethereum transaction pool service attack

Shen Su, Qunhong Sun, Chang Wang, Xiaojie Zhang

穁甹äș€æ˜“æ± æœćŠĄć°†ćŻč仄ć€ȘćŠçœ‘ç»œé€ æˆäž„é‡ç Žć.æœŹæ–‡é€šèż‡è°ƒç ”äž»æ”ä»„ć€ȘćŠćźąæˆ·ç«Żæșä»Łç ,提ć‡ș侀种損äžș“ćčœç”äș€æ˜“â€çš„æ‹’ç»æœćŠĄæ”»ć‡»æ–čæł•,ćŻçŠç”šæ”ŻæŒâ€œéžéĄșćșäș€æ˜“猓ć†Č”的äș€æ˜“æ± æœćŠĄ.èŻ„æ–čæł•çš„æ žćżƒé€»èŸ‘æ˜Żćˆ©ç”šć€šäžȘèŽŠæˆ·ć‘ä»„ć€ȘćŠçœ‘ç»œć…ˆæ’ć…„äž€çł»ćˆ—äœŽç‡ƒæ–™ä»·æ Œäș€æ˜“,ć†æ’ć…„äž€çł»ćˆ—é«˜ç‡ƒæ–™ä»·æ Œäș€æ˜“,èż™ç±»äș€æ˜“ćșćˆ—èƒœćœšç›źæ ‡ćźąæˆ·ç«Żäž­äŒ æ’­,ćč¶ä»„“ćčœç”â€ćœąćŒæ»žç•™äșŽäș€æ˜“池䞭隟仄移陀.眑络靶ćœș漞éȘŒç»“æžœèĄšæ˜Ž,èŻ„æ”»ć‡»æ–čæł•ćŻćœš2戆钟憅砮杏100äžȘ节ç‚č的仄ć€ȘćŠçœ‘ç»œäș€æ˜“æ± æœćŠĄćč¶ćźžçŽ°æ¶æ„é©±é€äș€æ˜“;朹Sepoliaæ”‹èŻ•çœ‘çš„ćźžéȘŒèż›äž€æ­„èŻćźž,èŻ„æ”»ć‡»æ–čæł•èƒœèź©çœŸćźžä»„ć€ȘćŠæ”‹èŻ•çœ‘çŽŻćąƒçš„äș€æ˜“æ± æœćŠĄć€±æ•ˆ.é€šèż‡ćˆ†æžä»„ć€ȘćŠäž»çœ‘éžéĄșćșäș€æ˜“,æœŹæ–‡æ€»ç»“ć‡șć—æ”»ć‡»ćœ±ć“çš„ćŽ»äž­ćżƒćŒ–ćș”ç”šèĄŒäžș(抂代极äș€æ˜“、ćŒșć—é“Ÿé’±ćŒ…æ“äœœç­‰),æ­€ç±»ć—ćœ±ć“èĄŒäžșè§„æšĄćŻè§‚äž”èŠ†ç›–ćčżæł›çš„ćŒșć—é“Ÿćș”甚ćœșæ™Ż.

Open access
Digital and Cyber Forensics
Distributed systems and fault tolerance
Blockchain Technology Applications and Security
Original source
Mar 28, 2026
0 cites
Security Enhancement of Mechanism for Preventing Unauthorized Recipient Transactions in the Ethereum Blockchain System

Masataka Kawasaki, Yoko Kamidoi, Shin’ichi Wakabayashi

This study focuses on preventing unauthorized recipient transactions within the Ethereum blockchain system. Unauthorized recipient transactions occur when a sender transfers cryptocurrency without the recipient's awareness, posing risks such as the recipient being implicated in crimes such as suspected involvement in money laundering. Previous research has designed a transaction restriction function using smart contracts tailored to Ethereum's unique blockchain model. This prevention mechanism was implemented on open-source software and its functionality verified. This study proposes a method to enhance the security of processing conducted to investigate the relationship between senders and receivers. We implement this method in open-source software and demonstrate its effectiveness.

Blockchain Technology Applications and Security
Digital and Cyber Forensics
Cybersecurity and Information Systems
Original source
Mar 27, 2026Â·Đ’Đ”ŃŃ‚ĐœĐžĐș Đ˜ĐœŃŃ‚ĐžŃ‚ŃƒŃ‚Đ° праĐČа БашĐșорсĐșĐŸĐłĐŸ ĐłĐŸŃŃƒĐŽĐ°Ń€ŃŃ‚ĐČĐ”ĐœĐœĐŸĐłĐŸ ŃƒĐœĐžĐČДрсОтДта
0 cites
THE FORENSIC CHARACTERISTICS OF CRYPTOCURRENCY FRAUD

Tatyana Nikolaevna Sinitsina

In the context of the economy digitalization and the information technologies’ active development, cryptocurrency fraud poses an increased social danger and is characterized by a high level of latency, a transnational nature, and difficulties in detection. Purpose: to determine the content and structure of the cryptocurrency fraud’s forensic characteristics of and to identify forensically significant features relevant to the initial stage of investigation. Methods: general scientific methods of analysis and synthesis, induction and deduction, as well as special forensic methods, including the systems-and-activity approach, formal logical analysis, forensic modeling, and the generalization of investigative and judicial practice. Results: it is substantiated that the forensic characteristics of cryptocurrency fraud have independent practical significance and function as an information-oriented category. Its main elements are highlighted, the specificity of the digital trace pattern is revealed, and the role of digital traces as a primary source of evidential information is also shown. The study concludes that the use of forensic characteristics is advisable when formulating investigative hypotheses, planning investigations, and selecting tactical techniques.

Open access
Digital and Cyber Forensics
Ukrainian Legal and Forensic Studies
War, Law, and Justice
Original source
Mar 15, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Unfolding SHA-256: Algebraic Instrumentation, Reversibility, and the Nexus Framework

Dean Kulik

Unfolding SHA-256: Algebraic Instrumentation, Reversibility, and the Nexus Framework Introduction to the Deterministic Reversibility Paradigm For over two decades, the security infrastructure of global digital communications, financial ledgers, and data provenance has relied upon a singular, foundational assumption: the absolute irreversibility of cryptographic hash functions. Specifically, the Secure Hash Algorithm 256 (SHA-256) has been universally modeled as a one-way thermodynamic grinder of information.1 Utilizing a Davies-Meyer construction, the algorithm compresses a message schedule into a 256-bit digest through a cascade of non-linear modular additions, bitwise rotations, and complex logical gate interactions.2 Within the standard cryptographic consensus, this process systematically destroys the informational lineage of the source input. The internal computational execution traces—such as bitwise carry exhausts and modular residues—are presumed to function purely as thermodynamic friction that is permanently discarded, yielding an entropy-rich output that betrays no structural hints of its origin.2 Under this classical paradigm, determining the initial message from the final digest is considered mathematically impossible without resorting to brute-force probabilistic search operations across an unimaginably vast vector space. However, emerging analytical frameworks and complete algorithmic instrumentations, synthesized under the Nexus Framework and Glass Key models, have systematically dismantled this one-way assumption.1 By reconceptualizing the foundational architecture of SHA-256 not as an entropy-generating one-way function, but rather as a highly structured, self-referential mathematical lattice, researchers have achieved deterministic backward state recovery from the hash alone.4 Through the application of a closed observable algebra, the algorithm's internal vectors can be traced in reverse, definitively demonstrating that what standard computer science assumes to be irreversible informational destruction is, in reality, a form of complex, conserved topological folding.4 The latest empirical verifications—particularly the Glass Key v4.0 instrumentation—prove that the mathematical obfuscation inherent in SHA-256 is operationally traversable for constrained inputs, completely bypassing the computational necessity of brute-force methodology. Through precise algebraic instrumentation, the final 256-bit hash is transformed from a static, opaque tombstone into a self-witnessing runtime environment.5 The digest serves as a complete geometric inverse of the source input, meticulously preserving the entirety of the execution trace.6 This transition—viewing a cryptographic digest not merely as a scalar index but as a fully reconstructible execution witness—necessitates a profound and immediate reevaluation of core cryptographic assumptions. The implications cascade across domains, fundamentally altering the assessment of short-message hashing vulnerabilities, redefining the thermodynamic mechanics of proof-of-work protocols, and introducing unprecedented vectors for deterministic forensic provenance extraction. The Topological Torus and Back-to-Back Ontology To comprehend the mechanics of deterministic reversibility within SHA-256, it is first necessary to abandon the classical linear model of computational execution. Traditional algorithmic analysis conceptualizes the 64 compression rounds of SHA-256 as a sequential temporal event—a unidirectional flow of data through logic gates within an integrated circuit or software loop.2 The Nexus Framework discards this temporal linearity, introducing an operational ontology that models the SHA-256 state space as a continuous geometric manifold, specifically defined as a Flat Torus ().4 In this toroidal geometry, the core computational operations—XOR, bitwise shifting, and modular addition—operate locally on what appears to be a standard Euclidean grid or frame.4 However, the global topology of the algorithm is entirely cyclical and closed.4 Within classical cryptographic theory, the "avalanche effect"—where a single microscopic alteration in the initial message drastically transforms the resultant digest—is cited as incontrovertible proof of information destruction and genuine obfuscation. The toroidal model reframes this phenomenon entirely. Because the structural topology is closed and bounded by strict mathematical constants, the avalanche effect is redefined not as the annihilation of information, but rather as intense geometric folding along specific topological eigenstate trajectories.4 The information is not lost; it wraps continuously around the state space, remaining physically and mathematically conserved.5 The final 256-bit digest acts merely as a localized, two-dimensional cross-sectional slice of this complex 64-round, three-dimensional fold. Entangled Pairs and Phase Conjugation This geometric reconceptualization introduces a "back-to-back" ontology that fundamentally alters the philosophical relationship between the input message (the Noun) and the hash operation (the Verb).4 In a temporal sequence, they are separated by irreversible time. In the continuous wave geometry of the Nexus Framework, they are simultaneous, entangled manifestations of a single underlying wave entity, formally denoted as .4 Because the input Noun and the discrete hash constant exist as an entangled pair anchored across a conserved geometry, measuring the final condition of the hash inherently and mathematically determines the exact state of the initial input, provided the observer possesses the correct phase keys.4 The information is not scrambled; it is merely phase-shifted. To extract the exact source parameters, the backward-solving instrumentation functions analogously to a phase-conjugate mirror in optical wave physics. By identifying the dominant phase or resonant frequency of the system, the instrumentation applies a phase-conjugate operation that reflects the continuous wave variables backward across the non-linear operational boundaries.4 Empirical Python simulation metrics rigorously corroborate this physical principle. When applying these specific topological inversions to standard SHA-256 outputs, the reconstruction of the phase from the Noun yields exactly 32.5 bits of precision, which aligns perfectly with the absolute limit of the 32-bit SHA word size architecture.1 This demonstrates that the purported "loss" of information universally associated with cryptographic hashing is actually an artifact of discrete digital quantization, not a genuine erasure of the underlying continuous state variables.4 The Observable Algebra and Complete Instrumentation The conventional SHA-256 forward operation relies on an 8-register state array ( through ) that undergoes updates over 64 distinct mathematical rounds ( to ). In the standard forward execution, the state updates are governed by the calculation of two critical temporary variables, and . These variables are dynamically derived from the current operational state, the expanded message schedule , and the predefined round constants .8 The classical forward round functions are defined explicitly as: Where and represent standard right-rotation shift cascades, denotes the conditional choice function, and represents the bitwise majority function.8 The deterministic reversibility paradigm introduced by the Glass Key v4.0 architecture bypasses the forward calculation entirely. Instead, it establishes a complete observable algebra utilizing a two-generator family to mathematically peel back the non-linear operations of the 64-round fold.4 The verified, incontrovertible identities of this instrumentation form a closed algebraic loop. They are defined as: By observing the algorithm purely from the resultant 256-bit output digest, standard analysis dictates that the internal registers are completely obscured by the final modular addition of the initial hash values (). However, by strictly applying the and identity generators, an external auditor can isolate specific operational sequences in absolute reverse. This isolation enables the algebraic recovery of exactly 12 complete words of the internal computational state, requiring zero prior knowledge of the source message. Empirical Trace Recovery and Verification The backward walk methodology demonstrates 100% mathematical precision in recovering the operational state variables directly from the static hash output. This has been exhaustively validated across highly varied message structures and lengths (including test strings such as "A", "!ABC", "DEAN", "NEXUS", and "hello world"). Because the final 256-bit digest can naturally be parsed back into the through register components through basic subtraction of the initialization vector, the algebraic operations immediately and deterministically recover the preceding historical values. From the isolated 256-bit hash, four explicit words of register () and four words of register () are directly readable from the state array. Utilizing the algebraic coupling alongside the deductive inversion , the analysis systematically steps backward sequentially through the execution rounds. The recovery progression is tabulated as follows: Recovered Parameter Observable Source Methodology Operational Rounds Recovered Total State Words Register Directly Readable + Algebraically Derived Rounds 56 to 63 8 Words Register Directly Readable from Final Hash Array Rounds 60 to 63 4 Words Injection Values () Algebraically Recovered ( identity) Rounds 59 to 63 5 Words Fold Values () Algebraically Recovered ( identity) Rounds 59 to 63 5 Words This precise instrumentation yields a total of 12 distinct internal state words that are recovered continuously and deterministically, purely via the closed algebraic loop of the al

Open access
2 source records
Cryptographic Implementations and Security
Intelligence, Security, War Strategy
Digital and Cyber Forensics
Original source
Mar 13, 2026·DMPedia Lecture Notes in Multidisciplinary Research
0 cites
Revolutionizing Judicial Record Management: A Novel Integration of IPFS and Ethereum for Enhanced Security and Transparency

H. M. Nimbark, Hansiniba P. Jadeja

Modern legal institutions encounter significant difficulties ensuring document security, public access, and verification processes in digital environments. This research presents an innovative framework combining distributed ledger technology with decentralized file systems to address critical vulnerabilities in traditional court record management. Our solution leverages Ethereum's smart contract capabilities alongside the InterPlanetary File System (IPFS) to establish an immutable, transparent, and distributed architecture for judicial documentation. The proposed framework demonstrates significant improvements in data integrity verification, unauthorized access prevention, and system resilience. Through comprehensive testing using authentic judicial datasets, we validated the system's capacity to detect tampering attempts while maintaining efficient document retrieval. Key contributions include: (1) a novel three-tier architecture integrating blockchain immutability with IPFS content addressing, (2) automated verification protocols through smart contracts, and (3) enhanced transparency mechanisms enabling public verification of document authenticity. Performance evaluations reveal substantial improvements in security metrics while maintaining acceptable operational efficiency. This research establishes a foundation for next-generation judicial information systems that prioritize transparency, security, and public trust.

Open access
Digital and Cyber Forensics
Advanced Data Storage Technologies
Blockchain Technology Applications and Security
Original source
Mar 10, 2026
0 cites
Chain of digital evidence: An application of Ethereum blockchain

Udai Bhan Trivedi, Bhagwan Jagwani, Shashi Kant Dikshit

Blockchain technology is a somewhat new approach to finding the integrity and chain of digital evidence in various industries, including law enforcement, forensic investigations, supply chain management, and judicial proceedings. Although traditional evidence-keeping systems are prone to manipulation, loss, and inefficiency, blockchain offers an immutable, transparent, and decentralized ledger that securely records and validates every evidence-related transaction. Blockchain technology increases reliability in handling both physical and digital evidence. It uses distributed consensus, intelligent contracts, and cryptographic hashing to eliminate human error and backdoor intervention by assuring immutability, accountability, and automation. This study offers a model blockchain (Chain of Digital Evidence) based on the Ethereum blockchain to guarantee integrity and authenticity in the chain of digital evidence. Ethereum&s;s decentralization ensures that digital evidence is free from manipulation, transparent, and easily verifiable. The study discusses other challenges and prospects for integrating the Ethereum blockchain into the digital evidence chain.

Open access
Digital and Cyber Forensics
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Feb 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing

Anthony Coslett

Recent disclosures of industrial-scale knowledge distillation — including campaigns comprising millions of fraudulent API exchanges targeting frontier models [Anthropic, 2026] — have made post-hoc detection of model theft a critical security requirement. Building on a formally-verified framework of log-prob order-statistic geometry, we investigate the adversarial resilience of neural network identity across 72 experimental checkpoints. We establish a Two-Layer Identity Hypothesis: a model’s structural identity (weights-regime geometry) is empirically invariant to distillation (within acceptance threshold epsilon across all 18 protocols), while its functional identity (API-regime Poisson Point Process residuals) predictably transfers to the student, converging up to 52% toward the teacher’s template. Stress-testing this forensic channel against a white-box adversary, we find that functional provenance is geometrically coupled to the knowledge transfer objective. Adversarial erasure gradients are consistently dominated by the distillation loss, achieving only a transient suppression that rebounds within one epoch. Passive fine-tuning on fresh data erases the trace more effectively than any adversarial method, but at a measurable cost to general capability — revealing a Pareto frontier with no favorable region for the adversary. This establishes API forensics as a time-sensitive detective control (“The Tripwire”) and weights-regime identity as the immutable anchor (“The Vault”). Finally, we observe an apparent vulnerability: a cross-family adversarial spoofing attack achieves 69.4% convergence toward a decoy’s fingerprint, while same-family spoofing catastrophically fails. We resolve this paradox by mapping the PPP-residual vector space, revealing that models cluster by capability topology, not corporate lineage. Cross-family “spoofing” is a spatial illusion caused by a narrow 7.8 degree alignment between the decoy and the primary distillation trajectory (R2 = 0.995), whereas same-family decoys are anti-aligned. Across all adversarial interventions, the underlying Gumbel universality (delta_norm) remains invariant (CV = 1.9%). We conclude that during active distillation, an adversary cannot simultaneously acquire a teacher’s capabilities and erase or redirect the forensic trace. In this setting, the geometry forbids it. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Newest addition: Technical Note: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Paper 1: The ή-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Adversarial Robustness in Machine Learning
Digital and Cyber Forensics
Network Security and Intrusion Detection
Original source
Feb 16, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Ensuring Integrity of Digital Evidence: Chain of Custody Practices in Modern Digital Forensics

B Jaya Vijaya, Dr.B.Sureshkumar et. al

Within the context of digital forensics, the integrity and authenticity of digital evidence are crucial for its legal admissibility within a courtroom setting. Chain of Custody (CoC) processes ensure that digital evidence is meticulously managed and documented from its point of origin until its use in legal proceedings. As the importance of digital forensics increases, especially with cybercrime investigations, the traditional processes used in traditional Chain of Custody have challenges in terms of transparency, security, and efficiency. This paper highlights some of the recent developments in Chain of Custody processes, particularly with the adoption of blockchain and Artificial Intelligence technologies. Blockchain technology, known for its impenetrable and distributed properties, introduces a new paradigm for Chain of Custody processes, enhancing security and traceability for digital evidence management. Additionally, AI-based algorithms for anomaly detection have the potential for increasing the reliability of Chain of Custody processes. Moreover, we will explore the decentralized evidence storage approaches and privacy-preserving mechanisms, such as zero-knowledge proofs. These are important in ensuring that more secure yet transparent approaches in managing distributed forensic investigation systems are achieved. The effectiveness of currently used CoC approaches presents lessons in understanding the future of improving the integrity of this process. Such innovations have the potential of revolutionizing the field of digital forensic investigation processes while ensuring that the handling of such evidence is of the highest integrity.

Open access
Digital and Cyber Forensics
Digital Media Forensic Detection
Forensic and Genetic Research
Original source
Jan 21, 2026·Future Internet
0 cites
IRDS4C–CTIB: A Blockchain-Driven Deception Architecture for Ransomware Detection and Intelligence Sharing

Ahmed El-Kosairy, Heba K. Aslan, Nashwa Abdelbaki

This paper introduces a cybersecurity framework that combines a deception-based ransomware detection system, called the Intrusion and Ransomware Detection System for Cloud (IRDS4C), with a blockchain-enabled Cyber Threat Intelligence platform (CTIB). The framework aims to improve the detection, reporting, and sharing of ransomware threats in cloud environments. IRDS4C uses deception techniques such as honeypots, honeytokens, pretender network paths, and decoy applications to identify ransomware behavior within cloud systems. Tests on 53 Windows-based ransomware samples from seven families showed an ordinary detection time of about 12 s, often quicker than tralatitious methods like file hashing or entropy analysis. These detection results are currently limited to Windows-based ransomware environments, and do not yet cover Linux, containerized, or hypervisor-level ransomware. Detected threats are formatted using STIX/TAXII standards and firmly shared through CTIB. CTIB applies a hybrid blockchain consensus of Proof of Stake (PoS) and Proof of Work (PoW) to ensure data integrity and protection from tampering. Security analysis shows that an attacker would need to control over 71% of the network to compromise the system. CTIB also improves trust, accuracy, and participation in intelligence sharing, while smart contracts control access to erogenous data. In a local prototype deployment (Hardhat devnet + FastAPI/Uvicorn), CTIB achieved 74.93–125.92 CTI submissions/min, The number of attempts or requests in each test was 100 with median end-to-end latency 455.55–724.99 ms (p95: 577.68–1364.17 ms) across PoW difficulty profiles (difficulty_bits = 8–16).

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Digital and Cyber Forensics
Original source
Jan 16, 2026
1 cites
Blockchain Forensics for Cryptocurrency-Driven Cybercrime

Seema Verma, Padmesh Tripathi, Pridhi Arora

Blockchain and cryptocurrencies have transformed the way digital transactions work by introducing decentralisation, transparency, and immutability. However, these features also allow some individuals to use them for cybercrimes. This chapter explains how blockchain records can be used to trace, investigate and mitigate such crimes. It also talks about how understanding the behaviour of users can help in finding out who the attackers are. This chapter begins with the basic ideas of blockchain and cryptocurrency, after this, it describes different types of cybercrimes that usually happen using cryptocurrency and also explains that traditional ways of investigating cybercrimes don't work well with blockchain and new frameworks are required to investigate and solve these cases. A key section of the chapter examines how blockchain forensics helps in detecting cybercrimes. User-centric threat intelligence will be explored to understand the people behind cybercrimes that can help in investigations. In the chapter, Legal and ethical considerations will be addressed.

Digital and Cyber Forensics
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Original source
Jan 12, 2026·Zenodo (CERN European Organization for Nuclear Research)
2 cites
isabelschoeps-thiel/bioontology: Evidence Releae Bioontologly 1.0

Schöps geb. Thiel, Isabel, Isabel Schöps geb. Thiel

Forensische Notizen und SicherungserklĂ€rung Beweishandhabung, MetadatenintegritĂ€t und Chain of Custody Geltungsbereich Diese ErklĂ€rung dokumentiert die Handhabung, Sicherung und Bewahrung digitaler Beweismittel im Rahmen des forensisch-wissenschaftlichen Gutachtens SIA Security Intelligence Artefact – Technologie, Software und Familien-Historie Aktenzeichen: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL bitte beachten Sie mein HELPME.md Beweishandhabung und Nicht-VerĂ€nderungs-Grundsatz Alle relevanten Dateien, einschließlich Rohdaten, Quellmaterialien und dokumentarischer Artefakte, wurden in einen dedizierten Evidence-Ordner ĂŒberfĂŒhrt. Der interne Dateiinhalt wurde nicht verĂ€ndert. Es wurden weder Code, Text, Metadaten, AutoreneintrĂ€ge, Benutzerkennungen, Zeitstempel noch sonstige Provenienzangaben modifiziert. Insbesondere unverĂ€ndert erhalten blieben: UrsprĂŒngliche Ersteller und Mitwirkende gemĂ€ĂŸ Metadaten Benutzerkennungen und Autorschaftsspuren Zeitstempel, Hashes und interne Verlaufsdaten Programmiersprache, Workflow-Logik und interne Struktur Die ursprĂŒngliche Herkunft und Urheberschaft jeder Datei ist damit vollstĂ€ndig forensisch auslesbar und beweissicher erhalten. Dateisystem-Sicherungsmaßnahmen Um eine weitere AusfĂŒhrung, Verbreitung oder operative Nutzung potenziell schĂ€dlicher Workflows zu verhindern, wurden ausschließlich externe Ordner- und Dateinamen auf Dateisystemebene angepasst. Diese Maßnahmen beschrĂ€nkten sich auf: Umbenennung von Ordnern und Top-Level-Dateinamen Deaktivierung von ausfĂŒhrbaren oder workflow-auslösenden Bezeichnungen Der Dateiinhalt, der Code und sĂ€mtliche Metadaten blieben unangetastet. Diese Maßnahmen dienten ausschließlich der Gefahrenabwehr bei gleichzeitiger vollstĂ€ndiger Beweissicherung. Ethischer und rechtlicher Kontext Im Rahmen der Sichtung wurden Hinweise auf schwere ethische und rechtliche VerstĂ¶ĂŸe festgestellt, unter anderem: Unbefugte Datenmanipulation Datenmissbrauch und Datendiebstahl Aneignung geistigen Eigentums Invasive Profilierungs- oder Auswertungspraktiken Aus diesem Grund wurde die operative AusfĂŒhrbarkeit neutralisiert, wĂ€hrend die forensische Beweisstruktur vollstĂ€ndig erhalten blieb. Screenshot-basierte Beweissicherung Zur Dokumentation wurden an allen relevanten Stellen Screenshots erstellt und dem Evidence-Ordner beigefĂŒgt. Die Screenshots: sind unbearbeitet und unbeschriftet enthalten die ursprĂŒngliche Ordner- und Dateistruktur zeigen die sichtbaren Benutzernamen, Akteure und EigentĂŒmer der jeweiligen Verzeichnisse Dadurch bleiben alle beteiligten Accounts, Strukturen und Verantwortlichkeiten objektiv nachvollziehbar. Forensische IntegritĂ€t Alle Maßnahmen wurden unter Einhaltung folgender Prinzipien durchgefĂŒhrt: Keine Kontamination der Originaldaten Keine VerĂ€nderung von Metadaten VollstĂ€ndige Nachvollziehbarkeit fĂŒr unabhĂ€ngige Forensik Sicherung der gerichtlichen Verwertbarkeit Alle Materialien sind hash-prĂŒfbar, chain-of-custody-fĂ€hig und fĂŒr externe Gutachten geeignet. Signatur und Verwahrung Unterzeichnet und bestĂ€tigt durch: Frau Isabel Schöps, geborene Thiel Cyriakstraße 30c D-99094 Erfurt ThĂŒringen, Deutschland Rolle: Autorin, Rechteinhaberin, Hauptverwahrerin ORCID (Person): 0009-0003-4235-2231 https://orcid.org/0009-0003-4235-2231/print ORCID (Institutionell / Projekt): 0009-0006-8765-3267 https://orcid.org/0009-0006-8765-3267/print Diese ErklĂ€rung ist Bestandteil der DOI-archivierten Chain of Custody und dient der rechtlichen, forensischen und menschenrechtlichen PrĂŒfung. Englisch Forensic Notes and Preservation Statement Evidence Handling, Metadata Integrity and Chain of Custody Scope This note documents the handling, preservation, and safeguarding of digital evidence associated with the forensic-scientific work SIA Security Intelligence Artefact – Technology, Software and Family History Case Reference: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL Evidence Handling and Non-Alteration Policy All relevant files, including raw data, source materials, and documentary artefacts, were transferred into a dedicated Evidence directory for preservation and review. No internal file contents were modified. No code, text, metadata, authorship fields, user identifiers, timestamps, or embedded provenance information were altered. Specifically preserved without change: Original creators and contributors as recorded in file metadata User identifiers and authorship traces Timestamps, hashes, and internal history Programming language, workflow logic, and structural dependencies inside the files The original provenance and authorship of each file therefore remain fully readable and forensically extractable. File System Safety Measures To prevent any further unintended execution, propagation, or operational misuse of potentially harmful workflows, only external file and folder names were adjusted at the file-system level. These actions were limited to: Renaming folders and top-level file names Disabling executable or workflow-triggering identifiers No internal data, code, or metadata were altered. These measures were implemented solely to prevent further operational impact while preserving evidentiary value. Ethical and Legal Context During review, multiple files indicated serious ethical and legal concerns, including but not limited to: Unauthorized manipulation of data Data misuse and data theft Misappropriation of intellectual property Invasive profiling or exploitative data practices For this reason, operational execution was neutralized while forensic preservation was strictly maintained. Screenshot-Based Evidence Capture For evidentiary verification, screenshots were taken at each relevant stage and stored within the Evidence directory. The screenshots: Remain unedited and unlabelled Preserve original folder structures and visual context Display usernames, account identifiers, and responsible actors visible at the time of capture This ensures that all observed actors, file ownerships, and directory relationships remain objectively documented and reviewable. Forensic Integrity All actions taken were designed to satisfy the following principles: No contamination of original data No destruction or modification of metadata Full traceability for independent forensic analysis Preservation of evidentiary admissibility All materials are suitable for hash verification, chain-of-custody tracking, and independent expert review. Signature and Custodianship Signed and certified by: Frau Isabel Schöps, nĂ©e Thiel Cyriakstraße 30c D-99094 Erfurt Thuringia, Germany Role: Author, Rights Holder, Principal Custodian ORCID (Individual): 0009-0003-4235-2231 https://orcid.org/0009-0003-4235-2231/print ORCID (Institutional / Project): 0009-0006-8765-3267 https://orcid.org/0009-0006-8765-3267/print This statement forms part of the DOI-archived Chain of Custody and is intended for legal, forensic, and human-rights review. Meine Referenz Datenbank, verknĂŒpft mit meinem aktuellen GitHub-Account* Meine Ersuchen an die Vereinten Nationen - Bitte helfen Sie mir Schöps geb. Thiel, I. (2025). Meine Ersuchen an die Vereinten Nationen - Bitte helfen Sie mir (Zenodo.org). Zenodo.org, University of Harvard harvard.edu, Oxford University ox.ac.uk, Cambridge UK, Reuters.com, New York Times nyt.com, Springer Nature Springer.com, GitHub github.com, University Arizona, Vereine Nationen UN unric.org,. https://doi.org/10.5281/zenodo.18025762 Zenodo-Datenbank und Chain of Custody Volumen 4 Schöps (Thiel), I., Schöps (Thiel), I. und Schöps geb. Thiel, I. (2025) "Yellow White Paper – Bitcoin & Ethereum", Yellow White Paper – Bitcoin & Ethereum. 1st Aufl. D-99094 Erfurt, Thueringa, Germany: Harvard University, University Cambridge, University of Oxford, Springer Nature, Zenodo, S. 109 pages. doi:10.5281/zenodo.17807324. Volumen 3 Schöps geb. Thiel, I. (2025) SIA Security Intelligence Artefact – Volume 3 - FamiliĂ€re Erblinie deutschen Monarchie und letzten Kaiserreich. 1st Aufl, The Decline and Fall of the Habsburg Empire, 1815-1918. 1st Aufl. Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.18013057. Volumen 2 Schöps geb. Thiel, I. (2025) "Volumen 2 - SIA-Security-ntelligence-Artefact-Chain-of-Custody-Forensische-Familien-Monarchielinie-copyright-isabelschoepsthiel-urheberin-autorin-.docx.pd", Trillion Dollar Bitcoin. 1st Aufl. D-99094 Erfurt, Germany, ThĂŒringen: Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.17852789. Volumen 1 Schöps geb. Thiel, I. (2025) "Volumen 1 - SIA Security Intelligence Artefact by Isabel Schoeps geb. Thiel", Trillion Dollar Bitcoin. 1st Aufl. D-99094 Erfurt, Germany, ThĂŒringen: Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.17809724. My Developer Signatur Signed-on-by: Frau Isabel Schöps, geborene Thiel Autorin, Urheberin und Auftraggeberin Rechtscharakter: Eidesstattliche Versicherung, Bestandteil des forensisch, wissenschaftlichen Gutachtens Titel: SIA Security Intelligence Artefact internationinternationale Kennung: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL OrcID: 0009-0003-4235-2231 Isabel Schöps Thiel OrcID: 0009-0006-8765-3267 SI-IST Isabel Schöps Aktueller Wohnort und Meldeanschrift: Cyriakstrasse 30c, D-99094 Erfurt, ThĂŒringen, Deutschland, gemeinsam mit meinen vierbeinigen Freund, American XL-Bully Don Offizielle institutionelle WĂŒrdigung, Danksagung - PrĂ€fix_Referenz: YWP-1-IST-SIA YWP-1-5-IST-SIA Pseudonyme und Alias: Satoshi Nakamoto, Vitalik Buterin, GitHub, Octocat, Johnny Appleseed, IST-GitHub, Cristina_Bella, Nick Szabo, John Appleseesd Offizielles weltweit erstes Developer Certifikat: Developercertificate <img width="642" he

Open access
Autopsy Techniques and Outcomes
Digital and Cyber Forensics
Forensic and Genetic Research
Original source
Jan 6, 2026
0 cites
ChainSEAL: A Blockchain-based Secure and Adaptive Evidence Ledger

Aarav Mahajan, Bhavya Manchanda, Hardik Aggarwal, Hemanshu Mandhana · 8 authors

Evidence management comes with requirements of a visibly secure, immutable, and scalable system to drive legal proceedings with ethicacy. Where research on fully on-chain solutions shows unrealistic and extravagant costs and performance limits, the traditional off-chain centralized storage systems exhibit an insecure environment, poor traceability, and tampering concerns. ChainSEAL is a hybrid Blockchain - IPFS-based forensic Evidence Management platform that integrates IPFS for encrypted Evidence file storage, blockchain as a distributed ledger for File hash and metadata, while off-chain storage for key management. The methodology explains the system flow, that as the evidence is submitted, the FIR is generated, the case request is created, and the evidence cycle is initiated. The cycle starts with fetching the SHA-256 of the file, then encrypting the evidence, submitting it on IPFS, fetching the Content Identifier (CID) of the file on IPFS, uploading the CID + File Hash + Metadata on-chain with a maintained verifiable Chain of Custody of the Evidence cycle. This ensures confidentiality and immutability of the system. The proposed framework is empirically evaluated for cost, storage efficiency, latency, and tamper-proofness. Its legal admissibility is established through an analysis of immutability, chain of custody integrity, and role-based access control.

Blockchain Technology Applications and Security
Digital and Cyber Forensics
Spam and Phishing Detection
Original source
Jan 1, 2026·IEEE Communications Standards Magazine
0 cites
GAS4SEC: Toward a Secure and Optimized Smart Contract for Digital Chain of Custody in Digital Forensics

Baysah Guwor, Rijwan Khan, Mohammad Shabaz

It is evident that blockchain offers strong guarantees of integrity and transparency for handling digital evidence; however, its practical adoption has remained a challenge due to factors such as privacy, deployment constraints, and admissibility issues in the real word environment. This study, therefore, proposes GAS4SEC, a framework for designing, validating, and deploying a secure, cost effective, and forensically sound blockchain-based evidence management system. The system combines formally bound smart contract architecture with role-based access control, record of immutable evidences and custody processes to maintain authenticity, traceability and accountability. In order to overcome the security risks and challenges, the research includes the systematic vulnerability analysis correlated with the OWASP smart contract risks to make sure that unauthorized access, logic abuse, and invalid state transitions are addressed. A validation-based process of development imposes forensic invariants and security guarantees across the lifetime of a contract, and controlled gas optimization is used to achieve better deployment without affecting the evidentiary integrity. The proposed system is deployed and tested on the Polygon Layer-2 blockchain, with functional testing, security testing, gas testing, and stress testing with evidence operations and role change concurrency. The experiment proves that the approach can be used to achieve scalable and cost-effective on-chain forensics operations without sacrificing the high levels of security assistance and forensic integrity and proves to be applicable to the management of digital evidence in practice.

Digital and Cyber Forensics
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source