Federated Learning enables collaborative model training across distributed clients without requiring direct access to their private data. However, effective deployment faces critical challenges, including heterogeneous data quality, unbalanced participation, and the lack of incentives. In this paper, we propose a federated learning network structured as a decentralized marketplace, where clients are financially rewarded based on the quality and utility of their contributions. Our framework enhances client selection through utility-driven mechanisms and offers strong incentives that promote sustained, high-quality participation. It also ensures security and transparency for the Task Owner while maintaining data privacy. The architecture can support a wide range of collaborative scenarios; spanning from healthcare and finance to consumer applications; where data privacy, fairness, and scalability are paramount. We demonstrate the practicality and effectiveness of our approach through experiments, showcasing improved global model accuracy, and equitable participation.
A designer of verification chooses two things: what a verifier reads from disclosed evidence, and how far the information reaching the verifier can be held apart from the information reaching the party whose conduct verification is meant to discipline. This paper asks when these two margins can be designed separately. In a Bayesian persuasion model with a meanreading deterrence audience and a verifier who applies a coherent risk measure, the sender's value is a contest between two envelopes-a concave envelope serving deterrence and a convex envelope serving liability-whose gap carries all interaction between the margins and equals the sender's willingness to pay for audience separation. Directional factorisation is exact: which reads are gaming-proof is decided by the read's belief-curvature alone, independent of routing. Calibration and value factorisation fail generically, but the failure is confined to two explicit terms-a product-structure term, in which the read's responsiveness and the seal enter only through their product, and a band term activated by disclosure mandates-each of which vanishes to first order, at a saturated deterrence margin, or under level-insensitive reads. Finally, the routing margin's own invariance is a curvature pairing, not a consequence of coherence: equilibrium deterrence is unmoved by the seal, for every prior and every stake, if and only if a belief-convex read is paired with a concave compliance response; off the pairing, the seal moves deterrence through sheltering when the read is gameable and through retreat below an explicit saturation threshold even when the read is coherent.
A key scientific question underlying the blockchain ecosystem is to what extent the core security properties of the protocols hold when assuming rational validators in the presence of capable economic attackers. To what degree and at what cost can these systems be disrupted? In this thesis, I analyze the underlying economic security properties of three of the most fundamental decentralization consensus algorithms: proof of work (PoW), proof of stake (PoS), and oracle information aggregation. In Chapter 2 of this work, I counter a prominent narrative that PoW is inherently flawed in an environment in which double-spend attacks are possible. By considering counterattacks, I recover PoW robustness against reorganization attacks through a game-theoretic model. In particular, I consider hashrate markets as a potential vector of attack and show that PoW remains robust in this case. In Chapter 3 of this work, I show novel chain reorganization and finality-delay attacks on the PoS mechanism of Ethereum. These attacks are deviations from the ’honest’ staking strategy, and I show that for participants staking a substantial percentage of the network’s staked assets, these attacks can be cheap and destructive to the network. In Chapter 4 of this work, I design an incentive mechanism for the information aggregation of noisy signals that is highly resilient to bribery. I establish the asymptotic strength and limitations of this mechanism against various classes of bribery including an attacker able to condition bribes on individual reports and on the outcome of the information aggregation. I achieve strong protection even in the latter case. To do this, I assume the presence of a source of truth (SoT) that is prohibitively expensive for typical use but can be invoked infrequently. This robustness to bribes is achieved even while in equilibrium there is no invocation of the SoT.
Open access
Blockchain Technology Applications and Security
Game Theory and Applications
Advanced Research in Systems and Signal Processing
The finite 1-bullet silent duel is considered, involving two duelists who shoot with exponentially-convex accuracy through a uniformly quantized time. The duel is a symmetric matrix game whose optimal value is 0, and each of the duelists has the same optimal behavior, whether it is in pure or mixed strategies. The actual beginning is never optimal in the duel. Apart from the very end of the duel, the conditions for the optimal time moment existence are found. Numerical experiments confirm that the optimality can be manipulated by changing the accuracy factor that scales the payoffs. The results are applicable in systems under limited or censored communication with uncertainty, latency, and lucrative delayed actions. Some examples of such set-ups are time-sensitive information release (privacy and censorship), queueing and load balancing (information science and telecommunication systems), and block proposal timing for decentralized consensus protocols (in Proof-of-Work and Proof-of-Stake).
Decentralized reputation mechanisms certify trust by making agents spend a scarce resource: computation (Proof of Work), capital (Proof of Stake), or identity (Proof of Personhood). In all three the resource is orthogonal to the quality being certified — a well-capitalized agent is not a skilled one. We study the construction in which the spent resource is the certified competence: Proof of Calibration, in which pseudonymous agents commit probabilistic predictions, outcomes resolve against ground truth, and reputation accrues through a strictly proper scoring rule. Building on the merit-gating results of Calibration-Gated Reputation (Alassa and Alashqar, SSRN 6505678), we replace that paper's concentration estimates with an exact theory. The realized mean score of an identity is a linear function of a single sufficient statistic — its empirical outcome frequency p̂ — so passing a merit bar is exactly the event that p̂ reaches an "alibi frequency" q_c, and the price of that event is an information divergence: the Sybil-lottery success probability is controlled, two-sidedly for all K and all N beyond a mild explicit threshold, by e^(−N·KL(q_c‖p)). Strict propriety is precisely positivity of this rate at every dishonest report, unifying the companion paper's impossibility and merit-gating theorems as the zero- and positive-rate regimes of one scalar. The theory is exact enough to reproduce, with zero free parameters, every Monte Carlo experiment of the companion suite, including the finite-size deviations from the asymptotic ε⁻⁴ cold-start law. Two structural results follow. First, the gate has two margins: in expectation, the adversary's best response is honesty and the margin is the generalized-entropy gap; at the event level, the optimal attack is skill-mimicry — report the bar's skill, not your own — and the margin is min{KL(p_h‖p_a), KL(1−p_h‖p_a)}, the divergence between the skills themselves, identical across all strictly proper, outcome-symmetric rules. The gate's security exponent is a property of the skills, not of the rule. Second, Sybil amplification requires independent evidence: identities scored on a shared outcome stream gain almost nothing from their number. Finally, the gate is not merely sound but optimal: no local pseudonymous mechanism that admits honest bar-skill agents with non-vanishing probability achieves a soundness exponent exceeding KL(p_h‖p_a), and the strictly proper gate attains it — it is the Neyman–Pearson test of the skill hypothesis. The composite Notch Score reduces to the same single statistic, yielding an exact calibration-weight floor.
This paper identifies and resolves a critical architectural flaw in citation-weighted reputation systems operating within Weighted Directed Acyclic Graph (WDAG) governance structures for Decentralized Autonomous Organizations (DAOs). Under existing formulations, rational agents face a direct financial disincentive to cite prior contributions, as citation-weighted value allocation through PageRank-derived mechanisms transfers economic reward from the citing agent to the cited agent. This under-citation incentive undermines the foundational promise of knowledge attribution in decentralized collaborative systems. The paper formalizes the under-citation problem, demonstrates the impossibility of precise citation quantification, and identifies a gap in existing game-theoretic proofs that purport to establish citation honesty as an equilibrium. Drawing on the WDAG governance framework developed in Calcaterra (2018), this paper proposes an integrated solution that decouples citation accuracy from quality-based payment, introduces validator-assessed citation honesty as a separately ranked and rewarded dimension, and establishes retroactive audit mechanisms with graduated sanctions. A new equilibrium theorem (Theorem 3b) demonstrates that under the integrated solution, honest citation constitutes a Nash equilibrium when validators assess citation accuracy and the marginal effect of citation accuracy on validator-assessed honesty scores exceeds the marginal gain from self-citation inflation. The paper situates these findings within the broader framework of dynamic regulation theory and New Institutional Economics incomplete contract theory, arguing that static citation protocols are inherently vulnerable to gaming and that evolutionary governance mechanisms are essential for sustaining honest knowledge attribution in decentralized systems.
This paper introduces Autonomous Mechanism Economics (AME), a theoretical framework for analyzing economic systems where human discretion is removed from mechanism execution. While classical mechanism design theory (Hurwicz, 1960; Maskin, 1999; Myerson, 1981) focuses on designing incentive-compatible rules, it implicitly assumes human agents execute these rules. We formalize a new class of economic mechanisms-Autonomous Mechanisms (AM)-where execution is performed by deterministic, immutable code rather than discretionary human agents. We establish four core theoretical results. First, Non-Discretionary Buyback (NDB) mechanisms minimize execution-layer agency costs (Theorem 1). Second, assets satisfying specific structural conditions-revenue increasing in market volatility combined with NDB execution-may exhibit antifragility, generating positive expected returns during market stress (Theorem 2). Third, when algorithmic buying capacity exceeds maximum individual selling capacity, markets may undergo threshold transitions to qualitatively different dynamics (Theorem 3). Fourth, USDdenominated staking requirements create self-reinforcing supply dynamics with bounded equilibrium returns (Theorem 4). We connect this framework to Kydland and Prescott (1977)’s “rules versus discretion” literature, arguing that AM protocols may represent a strong rules-based solution by eliminating not merely the incentive but potentially the ability to deviate from prescribed rules. Using data from Hyperliquid—a decentralized exchange implementing NDB at scale—we provide preliminary empirical support, documenting a volume-volatility correlation of 0.627 (p
<b>Proof-of-Stake (PoS) security models</b> assume validator independence, decentralized decision-making, and economically rational but non-coordinated behavior. This paper introduces <b><i>Shadow Validator Cartels</i></b>, a class of covert consensus capture attacks in which validators coordinate off-chain to influence block production, transaction ordering, and governance outcomes while remaining individually protocol-compliant. Unlike explicit majority or 51% attacks, shadow cartels do not require dominant stake ownership or on-chain collusion. Instead, they leverage shared infrastructure, aligned economic incentives, and soft coordination mechanisms that render their behavior statistically indistinguishable from organic validator activity. We analyze the structural enablers, formation mechanics, and systemic impacts of shadow validator cartels, demonstrate why existing decentralization metrics fail to detect them, and outline system-level mitigation requirements necessary to preserve credible neutrality in PoS networks.
Peiding Pi, Xiaolong Liang, Sangtian Guan, Fei–Yue Wang
In Decentralized Autonomous Organizations (DAOs), the lack of centralized authority makes it particularly difficult to incentivize high-quality contributions. Existing mechanisms mostly adopt one-time rewards, which are prone to inducing short-term speculative behaviors. To address this issue, a novel reputation-based vesting mechanism is proposed in the context of an infinitely repeated decentralized collaboration game. In this design, participants receive an immediate reward based on their current reputation, with the remainder vested for future release. The release conditions are strictly tied to their continued submission and production of valid outputs. The proposed mechanism is then demonstrated to provide incentive compatibility, Sybil resistance, and collusion resistance. Furthermore, computational experiments are conducted to validate the vesting mechanism, and results show that it can achieve endogenous security without relying on centralized identity verification or external enforcement.
Consider a social-choice function (SCF) is chosen to decide votes in a formal system, including votes to replace the voting method itself. Agents vote according to their ex-ante belief over what decisions are considered, and whether they prefer them to be decided by the incumbent SCF or the suggested replacement. The existing SCF then aggregates the agents' votes and arrives at a decision of whether it should itself be replaced. An SCF is self-maintaining if it can not be replaced in such fashion by any other SCF. Our focus is on the implications of self-maintenance for centralization. For this purpose, unlike [Barbera and Jackson, 2004], we do not generally restrict attention to anonymous SCFs. We also do not restrict attention to neutral SCFs, unlike [Koray, 2000]. We present results considering optimistic, pessimistic and i.i.d. approaches with respect to agent beliefs, different tie-breaking rules, and different SCF domains. To highlight two of the results, (i) for the i.i.d. unbiased case with arbitrary tie-breaking and general Boolean functions, we prove an Arrow-Style Theorem for Dynamics: We show that only a dictatorship is self-maintaining, and any other SCF has a path of changes that arrives at a dictatorship. (ii) With a pessimistic approach, tie-breaking that prefers the status quo, and WMGs, we provide a tight characterization of the self-maintaining rules, which are exactly all games with minimal winning coalitions of size at most 2. We then consider two extensions, (i) forward-looking voters, (ii) Where the voter utility depends on wisdom of the crowd effects. In both cases, less centralized SCFs become self-maintaining. All in all we provide a basic framework and body of results for centralization dynamics and stability, applicable for institution design, especially in formal De-Jure systems, such as Blockchain Decentralized Autonomous Organizations (DAOs).
This paper examines the strategic behavior of rational actors in the TON blockchain, focusing on their responses to slashing mechanisms in a proof-of-stake (PoS) environment. Slashing introduces financial penalties for behavior that threatens network integrity, addressing the nothing-at-stake problem, where validators in PoS systems can support multiple chains at no cost. Although slashing is intended to deter malicious behavior by Byzantine actors, it also affects rational validators by altering their expected returns. Using a game-theoretic model inspired by the BAR framework, this study examines how rational, utility-maximizing validators weigh the risks and rewards of violating or enforcing slashing mechanisms in the presence of potentially Byzantine actors when penalty enforcement is uncertain. Located at the intersection of game theory and distributed systems, this research sheds light on compliance and deviation dynamics in PoS networks, contributing to a deeper understanding of incentive alignment in blockchain governance.
We model the ultimate price paid by users of a decentralized ledger as resulting from a two-stage game where Miners (/Proposers/etc.) first purchase blockspace via a Tullock contest, and then price that space to users. When analyzing our distributed ledger model, we find: - A characterization of all possible pure equilibria (although pure equilibria are not guaranteed to exist). - A natural sufficient condition, implied by Regularity (a la [Mye81]), for existence of a ''market-clearing'' pure equilibrium where Miners choose to sell all space allocated by the Distributed Ledger Protocol, and that this equilibrium is unique. - The market share of the largest miner is the relevant ''measure of decentralization'' to determine whether a market-clearing pure equilibrium exists. - Block rewards do not impact users' prices at equilibrium, when pure equilibria exist. But, higher block rewards can cause pure equilibria to exist. We also discuss aspects of our model and how they relate to blockchains deployed in practice. For example, only ''patient'' users (who are happy for their transactions to enter the blockchain under any miner) would enjoy the conclusions highlighted by our model, whereas ''impatient'' users (who are interested only for their transaction to be included in the very next block) still face monopoly pricing.
Concentrated-liquidity automated market makers (CLAMMs), as exemplified by Uniswap v3, are now a common primitive in decentralized finance frameworks. Their design combines continuous trading on constant-function curves with discrete tick boundaries at which liquidity positions change and rounding effects accumulate. While there is a body of economic and game-theoretic analysis of CLAMMs, there is negligible work that treats Uniswap v3 at the level of formal state machines amenable to model checking or theorem proving. In this paper we propose a formal modeling approach for Uniswap v3-style CLAMMs using (i) networks of priced timed automata (PTA), and (ii) finite-state transducers (FST) over discrete ticks. Positions are treated as stateful objects that transition only when the pool price crosses the ticks that bound their active range. We show how to encode the piecewise constant-product invariant, fee-growth variables, and tick-crossing rules in a PTA suitable for tools such as UPPAAL, and how to derive a tick-level FST abstraction for specification in TLA+. We define an explicit tick-wise invariant for a discretized, single-tick CLAMM model and prove that it is preserved up to a tight additive rounding bound under fee-free swaps. This provides a formal justification for the "$ε$-slack" used in invariance properties and shows how rounding enters as a controlled perturbation. We then instantiate these models in TLA+ and use TLC to exhaustively check the resulting invariants on structurally faithful instances, including a three-tick concentrated-liquidity configuration and a bounded no-rounding-only-arbitrage property in a bidirectional single-tick model. We discuss how these constructions lift to the tick-wise structure of Uniswap v3 via virtual reserves, and how the resulting properties can be phrased as PTA/TLA+ invariants about cross-tick behaviour and rounding safety.
András Nagy, János Tapolcai, István András Seres, Bence Ladóczki
Proof-of-stake consensus protocols often rely on distributed randomness beacons (DRBs) to generate randomness for leader selection. This work analyses the manipulability of Ethereum's DRB implementation, RANDAO, in its current consensus mechanism. Even with its efficiency, RANDAO remains vulnerable to manipulation through the deliberate omission of blocks from the canonical chain. Previous research has shown that economically rational players can withhold blocks known as a block withholding attack or selfish mixing when the manipulated RANDAO outcome yields greater financial rewards.
This study analyzes how blockchain technology can be interpreted through an economic perspective, viewing network nodes as rational agents whose strategic behavior affects the efficiency and sustainability of decentralized systems. Using a multi-player non-cooperative game with complete but imperfect information, we model validators’ decisions in voting-based consensus mechanisms and compare alternative incentive configurations through simulation results. The analysis shows how variations in reward schemes influence validators’ behavior and consensus reliability. Extending the framework to Decentralized Autonomous Organizations (DAOs), the study explores how blockchain-based incentives can enhance participation, accountability, and decentralized governance. The findings highlight that incentive design plays a decisive role in aligning individual motivations with collective goals, ensuring both network integrity and long-term sustainability. Overall, this study connects economic theory with blockchain governance, extending its relevance to business and organizational contexts beyond cryptocurrencies.
Decentralized coordination and digital contracting are becoming critical in complex industrial ecosystems, yet existing approaches often rely on ad hoc heuristics or purely technical blockchain implementations without a rigorous economic foundation. This study develops a mechanism design framework for smart contract-based resource allocation that explicitly embeds efficiency and fairness in decentralized coordination. We establish the existence and uniqueness of contract equilibria, extending classical results in mechanism design, and introduce a decentralized price adjustment algorithm with provable convergence guarantees that can be implemented in real time. To evaluate performance, we combine extensive synthetic benchmarks with a proof-of-concept real-world dataset (MovieLens). The synthetic tests probe robustness under fee volatility, participation shocks, and dynamic demand, while the MovieLens case study illustrates how the mechanism can balance efficiency and fairness in realistic allocation environments. Results demonstrate that the proposed mechanism achieves substantial improvements in both efficiency and equity while remaining resilient to abrupt perturbations, confirming its stability beyond steady state analysis. The findings highlight broad managerial and policy relevance for supply chains, logistics, energy markets, healthcare resource allocation, and public infrastructure, where transparent and auditable coordination is increasingly critical. By combining theoretical rigor with empirical validation, the study shows how digital contracts can serve not only as technical artifacts but also as institutional instruments for transparency, accountability, and resilience in high-stakes resource allocation.
Ethereum’s introduction of smart contracts has significantly expanded blockchain use cases, enabling decentralized applications. Since all transactions are publicly available, the system can be modeled as a complex network, allowing us to uncover emergent user behavior and explore the underlying dynamics of the ecosystem. In this study, we focus on analyzing the structural differences within the Ethereum system across three distinct market regimes: bull, bear, and sideways. To achieve this, we apply a Hidden Markov Model to the log-return time series to uncover the underlying states, revealing three differentiated states, each corresponding to a specific market regime. Next, we investigate the network structural differences across these regimes, finding meaningful variations. During the bear regime, the out-degree distribution is more heterogeneous, with the largest hub exhibiting more extreme out-degree values. Additionally, during the bull and sideways regimes, we observe higher levels of reciprocity, clustering, and modularity compared to the bear regime. These findings suggest that during bull and sideways markets, the interaction patterns are more complex, and the community structure is more cohesive. Overall, our work underscores how market conditions shape trading patterns and the structural properties of the Ethereum transaction network, providing new insights into the interplay between market regimes, network topology, and user behavior in decentralized ecosystems.
ABSTRACT This paper develops a model of a cryptocurrency by incorporating mining into the otherwise standard search‐theoretic monetary framework. As usual, multiple equilibria exist. To obtain a sharp prediction on whether a cryptocurrency' s value will last in the future, I propose a notion of equilibrium refinement based on the feature that mining uses real resources. This refinement eliminates all equilibria where the value of the cryptocurrency is zero at some point in time or converges to zero over time. This result suggests that agents can collectively sustain the value of the cryptocurrency using costly mining as a coordinating device.
Ethereum’s transaction pool (mempool) dynamics and fee market efficiency critically affect transaction inclusion, validator workload, and overall network performance. This research empirically analyzes gas price variations, mempool clearance rates, and block finalization times in Ethereum’s proof-of-stake ecosystem using real-time data from Geth and Prysm nodes. We observe that high-fee transactions are consistently prioritized, while low-fee transactions face delays or exclusion—despite EIP-1559’s intended improvements. Mempool congestion remains a key factor in validator efficiency and proposal latency. We provide empirical evidence of persistent fee-based disparities and show that extremely high fees do not always guarantee faster confirmation, revealing inefficiencies in the current fee market. To address these issues, we propose congestion-aware fee adjustments, reserved block slots for low-fee transactions, and improved handling of out-of-gas vulnerabilities. By mitigating prioritization bias and execution inefficiencies, our findings support more equitable transaction inclusion, enhance validator performance, and promote scalability. This work contributes to Ethereum’s long-term decentralization by reducing dependence on high transaction fees for network participation.
Blockchains support a rapidly growing digital economy. Through decentralization, they enable the ownership and transfer of digital assets without centralized intermediaries while resisting attacks, faults, and collusion. Yet decentralization is not guaranteed and must be sustained against external shocks. What design choices help blockchains maintain decentralization when disrupted? We find that resource flexibility, how easily consensus resources can be moved and redeployed, is key to sustained decentralization. Using three real-world shocks—China’s 2021 crypto mining ban, Hetzner’s 2022 shutdown of Solana validators, and Ethereum’s transition from proof-of-work to proof-of-stake—we show that blockchains whose consensus resources are more flexible recover decentralization faster. These findings offer actionable guidance. Blockchain designers should consider resource flexibility as a first-order design parameter. Operators should diversify infrastructure across jurisdictions to reduce vulnerability to localized shocks. Policymakers should be aware that regulations targeting blockchains can have unintended effects on decentralization.