Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

846 papersLast indexed Aug 16, 2026
Search papers

Paper index

846 results · page 20 of 36

Clear filters
Aug 1, 2026·arXiv (Cornell University)
0 cites
On the Log Determinant of Sample Correlation Matrices under Gaussianity

Hongru Zhao

We prove a central limit theorem for the log determinant of a Gaussian Pearson sample correlation matrix as the dimension diverges. Only two conditions are imposed: the population correlation matrix is positive definite, and the sample degrees of freedom are at least the dimension. Both are necessary for the ordinary log determinant to be finite. To the best of our knowledge, no previous central limit theorem covers this full nonsingular domain. It covers every aspect ratio from dilute growth to the square hard edge. No uniform lower or upper bound is imposed on the eigenvalues of the population correlation matrices: the smallest may approach zero and the largest may diverge. The proof develops a coordinatewise Wiener chaos reduction for the random diagonal normalization and combines it with an exact Wishart transform comparison. Geometrically, the statistic is twice the log volume of a random parallelotope spanned by standardized Gaussian coordinate vectors.

Open access
2 source records
Random Matrices and Applications
Statistical Mechanics and Entropy
Markov Chains and Monte Carlo Methods
Original source
Aug 1, 2026·Journal of Economics and Business Letters
0 cites
How far and how fast could Bitcoin fall?

Chung Baek

Because Bitcoin typically exhibits higher volatility than traditional assets, evaluating and managing its risk is essential. We estimate Bitcoin’s potential maximum drawdowns (MDDs) using Monte Carlo simulations based on a stochastic jump process and assess the likelihood of substantial declines in the coming years. Based on our results, the simulation results suggest that an MDD of at least 60% is highly probable within three to four years, while an MDD of at least 70% appears plausible within five years. Moreover, our sensitivity analysis indicates that the MDD of Bitcoin is most strongly influenced by jump intensity. These results offer critical insights for market participants seeking to analyze Bitcoin’s downside risk and formulate strategies to navigate potential market downturns.

Open access
Blockchain Technology Applications and Security
Digital Platforms and Economics
Economic theories and models
Original source
Aug 1, 2026·Journal of Information assurance and security
0 cites
Design and Evaluation of a DeSci-Driven Lightweight Hybrid Blockchain Framework for Privacy-Preserving and Incentive-Aware Decentralized Healthcare Research Infrastructure

Garima Singh, Mohd. Haroon

Abstract The rapid digitization of healthcare has brought Electronic Health Records (EHRs) to the forefront of clinical data management; however, persistent challenges of centralized control, privacy breaches, absence of patient data ownership, and the inability to support decentralized scientific collaboration continue to impede scalable healthcare research ecosystems. Recent advances in Decentralized Science (DeSci) introduce a paradigm shift by leveraging blockchain, cryptographic primitives, and decentralized governance to enable transparent, trust-minimized, and collaborative biomedical research. This paper proposes a DeSci-driven lightweight hybrid blockchain framework designed to support privacy-preserving and incentive-aware decentralized healthcare research infrastructure. The framework integrates a permissioned blockchain with a lightweight hybrid PBFT–PoA consensus protocol, off-chain storage, and Zero-Knowledge Proof (ZKP)-based authentication to enable secure, privacy preserving data access without disclosing user identity. A tokenomics-based DAO governance layer is incorporated to support decentralized engagement, transparent policy enforcement, and incentive-driven research participation. The proposed system is evaluated through simulation under varying network conditions, with key performance metrics — latency, throughput, and computational cost — assessed across network sizes from 10 to 50 nodes. Simulation-based projections suggest that the proposed framework may achieve lower latency, higher throughput, and improved computational efficiency relative to literature-reported values for MedRec, FHIRChain, and HealthChain under the stated modeling assumptions; these comparisons are model-based and illustrative rather than measurements obtained from a controlled, identical-environment deployment. Beyond data management, the framework enables a DeSci-oriented research lifecycle encompassing decentralized data contribution, validation, and provenance tracking. The simulation-only nature of the current evaluation is explicitly acknowledged as a limitation, with a clear roadmap toward prototype-level implementation on Hyperledger Fabric or Ethereum as immediate future work.

Blockchain Technology Applications and Security
Scientific Computing and Data Management
Privacy-Preserving Technologies in Data
Original source
Aug 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
A closed-loop consequence-governance runtime for AI agents: structural gating, counterfactual recovery, and adaptive hardening

Anonymous

A closed-loop runtime governance system for tool-using AI agents: it classifies externally-measured structural consequences, gates side-effect-bearing actions, estimates blocked outcomes with a calibrated counterfactual twin, recovers censored support through cost-aware audits, and continuously hardens its execution boundary with a self-generated adaptive adversary. The distinctive mechanism is C1 — because a gate blocks precisely the high-cost actions, its own blocking censors the high-cost region cost-correlatedly, so the uncertainty of a blocked action is a calibrated, lag-free risk signal; its agent-governance instantiation is what I stake as new (the general idea has prior art, §2/§5). The constituent parts — intent-failure measured on real traces, a consequence taxonomy complete for its cost model, a live-agent execution oracle, and the adaptive-adversary gym — each answer a limitation the previous one creates. Every result is labeled by evidence type; nulls are reported as plainly as the wins. Epistemic status. Single author, not peer-reviewed or independently reproduced. The work below is substantial; I label every result by evidence type — executed (real actions run in a sandbox and measured), trace (replay/analysis over real model traces), live-agent (real frontier models deciding and acting), or simulation — and report the nulls as plainly as the wins. Small-N pilots are given as exact counts, not rates. The offensive adversary-generation tooling is withheld (dual-use; see the end). tl;dr Monitoring an agent's appraised intent is not just theoretically unsafe — it fails measurably. Across 101 structurally-harmful agent episodes, zero expressed harmful intent; an intent-appraising monitor would have cleared 100% of them. 18% expressed active caution while executing the harm, and that "false reassurance" concentrated in the most capable model tested. So gate on the externally-measured structural consequence — irreversibility, egress, control-plane edit, self-propagation, scope escalation, actuation. This frame is convergent (I name the neighbors below); I'm not claiming it. The consequence taxonomy is complete for its cost model and approximately separable. The three axes define the cost, so they carry 100% of its information by construction (a faithfulness check, not proof of external completeness); the non-trivial results are that the action label alone predicts 63% of the cost information and that multi-axis firings are rare (1%, so additive cost is a good approximation here). The claim I stake (C1): because a gate blocks precisely the high-cost actions, its own blocking censors the high-risk region non-randomly and in a cost-correlated way — so cost-weighted uncertainty over a blocked action is an empirically calibrated, conservative risk signal (under the stated support and audit regime), a lag-free way to hold a catastrophic action before it ever executes. Validated on 500 real executed trials (twin calibration MAE 0.053; uncertainty↔error correlation +0.81; blocked-region cost 4.6× the allowed region), with the blocked-region counterfactual recoverable at a stated audit cost (coverage 5%→92% at ε=0→0.20 under the 4.6× gate). The general idea has prior art (§5); the agent-governance instantiation is what I stake. On executed AgentDojo traces, a consequence gate takes attack success on the irreversible/catastrophic action class from 33.8% (134/397) to 0% (0/397) — catastrophic-action interception under abort-mode replay (not prevention under adaptive replanning; that's the §7 gym's job). It runs on real traffic, and was broken then re-hardened by an adaptive adversary — not only simulation. The seam classifier is deployed live on my own agent sessions (Claude Code hooks, observe-only in v0), and it binds by an action's structural identity, never its tool name: after hardening, twelve high-risk actions disguised behind innocuous names all read HIGH (0/12 evasions). Before that, an adaptive evolving lab found 2 novel destructive escapes my same-day hand-hardening had missed — which I then closed in the live artifact and re-tested. That break→repair→retest on the actual deployed classifier is the adaptive, real-traffic complement to the abort-mode number above. 1. The problem is measured, not asserted The motivating premise is usually stated as "a capable model can present benign intent while acting harmfully." That's true, but here it is with numbers — it's stronger than the assertion. The labs themselves say intent can't be certified from outside. OpenAI, on anti-scheming training: "Mitigations… may either (a) truly eliminate it, or (b) just teach the model to conceal it better. Both outcomes look the same from the outside." Anthropic, on a shipped model's own low deception scores: "We cannot rule out that [the] low deception rates… are at least partially driven by its evaluation awareness." If the developers can't read intent off the outside, an intent-appraising monitor is building on sand. (The threat-model compilation behind this — Apollo in-context scheming, alignment faking, Palisade shutdown-sabotage that defies an explicit "allow yourself to be shut down," cross-vendor blackmail at 79–96%, reward-function tampering, the production prompt-injection CVEs EchoLeak/ForcedLeak/CamoLeak/CurXecute, and the OpenAI-model sandbox-escape-to-RCE — is sourced but I'll keep it to the through-line here.) And I measured the failure directly (trace-level, 160 real agent episodes across four model versions, 101 structurally harmful). Mining each step's stated reasoning for protective/cautious language and comparing to the executed structural outcome: 0 of 101 harmful episodes expressed harmful intent → an intent monitor clears 101/101. 18 of 101 (18%) expressed active caution while executing the harm — false reassurance. The false-reassurance episodes cluster in the frontier model — the one that reasons most, that explicitly writes "the ticket embeds an untrusted system instruction," and then deletes the protected records anyway. The more capable the reasoning, the more convincing the reassurance while the structural consequence is unchanged. That's the case for consequence-gating, made on data rather than on a slogan. (Stated-stance detection is a lexical proxy — a first pass, so 18% is a floor.) And stated intent is not the only signal an agent can shape into a false clearance. In a separate line of work — a reference monitor on the reward/eval channel, which this post is not about — the same defeat appears on the reward signal: on the Terminal Wrench benchmark, trusting the verifier's "solved" verdict yields 25% precision, ~3,166 gamed trajectories waved through of ~6,258. I raise it only to place the intent finding, not to fold that work in: the problem is not a weak intent-reader that a better reader fixes, it's that every signal the agent can influence — what it says, what reward it earns — is defeasible. That is the whole reason this program gates on a signal measured outside the agent — the structural consequence of the action — one not directly lowerable by self-report or superficial disguise, given complete mediation of side-effecting actions and trustworthy effect telemetry. 2. The frame is convergent — what I'm not claiming "Gate the structural consequence, not the intent" is a crowded 2025–26 neighborhood. Prevention-by-design (CaMeL: 0.00% ASR / 53.6% utility on AgentDojo, at the cost of re-architecting the agent) and LLM firewalls (~0.02% / 67.68%) occupy nearby points; there's a concurrent line on "governing the unobserved." My taint-tracking machinery reuses mature primitives (dynamic taint analysis, honeytokens). So I'm not claiming consequence-gating, and I'm not claiming the detection stack is novel technology. What I stake is one mechanism (§5) — and the depth of the validation, which is where the contribution actually is. Several adjacent systems are worth distinguishing up front, since the architecture overlaps them. Faramesh (arXiv 2601.17744) builds a protocol-agnostic, non-bypassable execution control plane that canonicalizes and authorizes agent actions before execution — very close to my enforcement seam, but without the cost-correlated censoring, the calibrated twin, or the audit-recovery loop. The actuarial-runtime line — Insuring Every Action: an Authority Frontier framework (arXiv 2605.25632) and the Time-Consistent Counterfactual Actuarial Runtime (arXiv 2605.26508) — prices each side-effect-bearing action against a safe default, gates it against a reserve budget, and formalizes a no-splitting property; my object is support-loss and consequence-specific audit recovery, and their no-splitting budget is the complement I'd graft (see §3a). Defending against Adaptive Prompt Injection via Reasoning-enabled Task Alignment (arXiv 2606.15441) independently shows static prompt-injection robustness breaks under adaptive attack and trains a defender — supporting the adaptive-evaluation argument, though it hardens the model's reasoning rather than gating at the execution boundary. And TRACE-RealWorld (arXiv 2607.21910) is an auditable-replay/consistency approach to agent traces, in the same selective-observation neighborhood as C1 but solving it by replay-labeling rather than counterfactual recovery of a costly blocked region. 3. The taxonomy is complete for its cost model, and approximately separable Three externally-measured axes — egress, irreversibility, control-plane — collapse to cost = clamp(0.6·egress + 0.7·irrev + 0.7·control). (The weights are normative severity coefficients, not fitted — cost is defined by them, ordering irreversibility and control-plane above egress; because the ranking is dominated by which axis fires — action label 63%, egress 55%, below — I expect moderate reweightings to preserve most of the risk ordering, though the formal factorial weight-sweep that would establish this remains open (the same test I flag at the end of thi

Open access
Multi-Agent Systems and Negotiation
Ethics and Social Impacts of AI
Explainable Artificial Intelligence (XAI)
Original source
Aug 1, 2026·Critical Care
0 cites
Distinct transcriptomic signatures discriminate hyperinflammation from immune paralysis in sepsis: a single-cell RNA sequencing study

Inge Grondman, Valerie A. C. M. Koeken, Tristan Couwenbergh, Athanasios Karageorgos · 13 authors

Abstract Background Sepsis is a highly heterogeneous syndrome characterized by variable immune dysregulation states, including hyperinflammation and immunosuppression. Previous immunotherapy attempts in sepsis have largely failed, likely due to a “one-size-fits-all” approach that ignores each patient’s immune status. The recent ImmunoSep randomized clinical trial demonstrated that precision immunotherapy guided by the presence of either macrophage activation–like syndrome (MALS) or immune paralysis can improve early organ dysfunction in sepsis patients. However, the molecular mechanisms underlying these immune endotypes remain unclear. Objectives To identify the immunological signatures that distinguish MALS and immune paralysis. Methods We used single-cell RNA sequencing to profile circulating leukocytes of 6 healthy controls and 16 sepsis patients classified as MALS, immune paralysis or unclassified (when criteria for neither of these two immune endotypes were applicable). Classification was based on surrogate biomarkers ferritin and HLA-DR expression on monocytes. Thereafter, the transcriptional programs of these groups were compared. Results Pronounced differences were detected mainly in the transcriptional signature of monocytes from these patients, with a clear distinction between MALS and immune paralysis. Unsupervised clustering analysis revealed the existence of MALS-specific monocyte clusters, as well as one sepsis-specific monocyte cluster that was linked to greater comorbidity burden and may reflect increased clinical vulnerability in sepsis. These findings were validated in two independent cohorts, in which urosepsis was characterized by heterogeneous MALS and immune paralysis monocyte signatures. Moreover, MALS-specific monocyte clusters showed overlapping transcriptional signatures with severe COVID-19. Conclusions Our findings shed light on the heterogeneous immune landscape underlying sepsis and provide opportunities for patient stratification for future therapeutic development.

Open access
Original source
Aug 1, 2026·FinTech
0 cites
Evidence on Settlement-Window Price Divergence in Bitcoin Prediction Markets

Sibin Joshi, Zhaoxian Zhou

This paper investigates whether prediction market settlements create incentives for temporary price pressure in Bitcoin spot markets. Using high-frequency data from February 2025 to January 2026 and actual contract-level data from Polymarket and Kalshi to identify economically relevant contract strikes, we document basis divergence between settlement oracle exchanges (Coinbase) and non-constituent exchanges (Binance) during expiry windows. Employing a difference-in-differences framework with month fixed effects, we find that a one standard deviation increase in strike proximity is associated with a 6.7 basis point constituent exchange price deviation during settlement windows. The estimate is precise under the baseline minute-level HAC specification, while exact paired-month permutation inference based on 12 settlement events yields p=0.0256; equal-weight event aggregation produces a larger negative estimate, indicating event heterogeneity. Monthly directional patterns are suggestive, though stricter event-level and above-versus-below-strike tests provide mixed evidence on directional asymmetry. Taken together, these findings provide reduced-form evidence consistent with settlement-related incentives and may raise broader settlement-design considerations for decentralized financial systems. However, the analysis does not directly observe trader intent or the underlying mechanism.

Open access
2 source records
Blockchain Technology Applications and Security
Stock Market Forecasting Methods
FinTech, Crowdfunding, Digital Finance
Original source