Federated Learning (FL) enables resource-constrained nodes in edge intelligence to train a global model using local data under the coordination of a server without the risk of privacy disclosure. Secure aggregation employs security primitives to encrypt and compute local gradients, enhancing the security attributes of vanilla FL. However, server-driven FL faces communication bottlenecks and high trust risks when coordinating large-scale distributed devices, and the existing secure aggregation with input validation schemes can only verify input vectors of lengths that are powers of 2. In this work, we propose VerifyDFL, a distributed secure aggregation protocol with input validation, which enables clients to locally validate the gradients of others within the decentralized federated learning (DFL) paradigm. Specifically, we propose a distributed proof approach based on Springproofs that supports arbitrary-length input validation. Clients locally verify the Lâ and L2 norms of othersâ inputs with a zero-knowledge manner. Furthermore, we employ k-regular graphs to enhance the communication topology of DFL, which guarantees that each client can securely aggregate gradients locally even when corrupted or dropped clients participate in federated training. The security analysis and proofs ensure that VerifyDFL meets the privacy protection requirements of DFL. We conduct real benchmark experiments to show that VerifyDFL optimizes the computational cost by approximately 20% over the state-of-the-art input validation protocols. Additionally, VerifyDFL enforces Lâ and L2 norm correctness verification on encrypted model gradients in edge intelligence.
Blockchain and smart contracts are widely used in IoT access control to create decentralized, trustworthy environments for secure access and record management. However, their application introduces a dual challenge: The transparency of blockchain and the use of addresses as identifiers can expose account privacy. To tackle this issue, this paper proposes a blockchain-based IoT access control system that enhances account anonymity and preserves privacy, particularly regarding user behavior, habits, and access records through the use of zero-knowledge proofs. The system incorporates an access control mechanism that combines access control lists with capability-based access control, enabling ownership verification of access rights without disclosing identity information. To evaluate the systemâs feasibility, we conduct experiments in a smart building scenario, including both qualitative comparisons with existing methods and quantitative analyses of performance in terms of time, space, and gas consumption. The results indicate that our scheme achieves the best time efficiency in the proof generation and authorization phases, completing them in just 7 and 10 s, respectivelyârepresenting half the time required by the second-best approach. These findings underscore the systemâs superior cost efficiency and enhanced security compared to existing solutions.
ABSTRACT The rise of cyber threats has underscored the critical need for robust intrusion detection systems (IDS). While traditional approaches, including statistical, knowledgeâbased, and AIâdriven methods, have been pivotal, they often face limitations such as data privacy concerns, scalability challenges, and low detection accuracy on unfamiliar threats. This paper addresses these issues by adopting a federated learning (FL) paradigm for collaborative intrusion detection, allowing data to remain local and enhancing privacy protection. The proposed solution integrates advanced encryption techniques and differential privacy to safeguard confidentiality while ensuring system scalability and adaptability. By introducing a robust separation of agents' roles and leveraging FL's decentralized architecture, the system overcomes the limitations of centralized learning, including single points of failure and communication overhead. Experimental results validate the proposed architecture, demonstrating significant improvements in performance and offering a promising direction for modern network security. This work not only highlights the potential of FLâbased IDS but also explores the integration of distributed ledger technologies to further enhance trust and security. These findings contribute to the growing field of privacyâpreserving computing and lay the groundwork for future innovations in scalable, secure, and efficient intrusion detection systems.
Victoria L. Lemieux, Rosa Gil, Faith Molosiwa, Qizheng Zhou · 8 authors
As archives turn to artificial intelligence to manage growing volumes of digital records, privacy risks inherent in current AI data practices raise critical concerns about data sovereignty and ethical accountability. This paper explores how privacy-enhancing technologies (PETs) and Web3 architectures can support archives to preserve control over sensitive content while still being able to make it available for access by researchers. We present Clio-X, a decentralized, privacy-first Web3 digital solution designed to embed PETs into archival workflows and support AI-enabled reference and access. Drawing on a user evaluation of a medium-fidelity prototype, the study reveals both interest in the potential of the solution and significant barriers to adoption related to trust, system opacity, economic concerns, and governance. Using Rogers' Diffusion of Innovation theory, we analyze the sociotechnical dimensions of these barriers and propose a path forward centered on participatory design and decentralized governance through a Clio-X Decentralized Autonomous Organization. By integrating technical safeguards with community-based oversight, Clio-X offers a novel model to ethically deploy AI in cultural heritage contexts.
BACKGROUND The convergence of AI, Blockchain (BC) technology, and healthcare represents one of the most transformative but technically challenging frontiers in computational medicine. As healthcare systems worldwide transition toward data-driven paradigms for precision medicine, clinical decision support, and population health management, the imperative for secure, privacy-preserving, and collaborative learning frameworks has reached critical importance. This tutorial presents the first comprehensive framework integrating Federated Learning (FL) and BC} for secure, privacy-preserving healthcare analytics. While FL offers collaborative training across distributed institutions without raw data sharing (aligning with HIPAA/GDPR), it faces vulnerabilities like model poisoning and gradient leakage. We introduce Blockchain-based Federated Learning (BCFL), leveraging BC's immutable ledger and decentralized consensus for enhanced trust, verifiability, and auditability. Our key contributions include: (1) a systematic taxonomy of diverse medical data types and their FL requirements; (2) three novel integration architectures (fully, semi, loosely coupled) with rigorous analysis of security, scalability, and regulatory compliance; (3) comprehensive security analysis of healthcare-specific vulnerabilities and mitigation via advanced cryptography like zero-knowledge proofs, homomorphic encryption and differential privacy; and (4) a regulatory compliance framework addressing HIPAA, GDPR, and FDA guidelines for AI/Achine-Learning (ML) medical devices. We demonstrate BCFL's effectiveness across critical healthcare applications (e.g., disease prediction, medical imaging, patient monitoring, drug discovery) and identify emerging research frontiers including quantum-resilient cryptography, scalable interoperability, healthcare-specific incentives, and automated compliance. This tutorial serves as a foundational resource for advancing secure, compliant, collaborative AI in healthcare, accelerating privacy-preserving analytics, and ultimately improving patient outcomes. OBJECTIVE The objective of the paper is to present the first comprehensive tutorial on integrating Federated Learning (FL) and Blockchain (BC) technologies specifically for secure, privacy-preserving healthcare analytics. The motivation stems from the growing need for collaborative healthcare data analysis that adheres to stringent privacy regulations like HIPAA and GDPR, especially as traditional centralized models pose significant data security risks. The authors aim to address the vulnerabilities of FL, such as model poisoning and gradient leakage, by leveraging BCâs features like decentralization, immutability, and auditability. The tutorial is designed to guide researchers, practitioners, and policymakers in understanding and implementing secure AI systems in the medical domain. METHODS To achieve this goal, the authors develop a multi-faceted framework by first creating a comprehensive taxonomy of medical data types and their specific requirements for FL deployment. They then propose three novel integration architecturesâfully coupled, semi-coupled, and loosely coupledâeach analyzed for its security, scalability, and compliance with healthcare regulations. The tutorial includes an in-depth security analysis addressing threats unique to healthcare, and explores privacy-enhancing technologies such as zero-knowledge proofs, homomorphic encryption, and differential privacy. It also introduces a regulatory compliance framework aligned with HIPAA, GDPR, and FDA guidelines for AI/ML-based medical devices. Throughout, the methodology integrates technical depth with practical implementation advice. RESULTS The results of this study are delivered through a set of clearly articulated contributions. The proposed architectures and frameworks are demonstrated to significantly enhance trust, verifiability, and auditability in healthcare FL systems, making them more robust against known threats. The paper effectively showcases how BCFL (Blockchain-based Federated Learning) can be applied to real-world healthcare use cases such as disease prediction, patient monitoring, medical imaging, and drug discovery. Additionally, it outlines emerging research directions, including quantum-resilient cryptography, scalable interoperability, incentive mechanisms for healthcare data sharing, and automated compliance monitoring. These outcomes position the tutorial as a foundational reference for advancing secure and compliant collaborative AI in healthcare. CONCLUSIONS This tutorial presented the first comprehensive framework integrating FL and BC for secure, privacy-preserving healthcare analytics. We demonstrated how FL enables decentralized model training across healthcare institutions while maintaining data locality, and how BC enhances trust, integrity, and auditability through immutable ledgers and decentralized consensus mechanisms. Our key contributions include: (1) a systematic taxonomy of diverse medical data types and their FL requirements; (2) three novel integration architectures (fully coupled, semi-coupled, and loosely coupled) with rigorous analysis of security, scalability, and regulatory compliance trade-offs; (3) comprehensive security analysis identifying healthcare-specific vulnerabilities and mitigation strategies using advanced cryptographic techniques including zero-knowledge proofs, homomorphic encryption, and differential privacy; and (4) a practical regulatory compliance framework addressing HIPAA, GDPR, and FDA guidelines for AI}/ML-based medical devices. We validated BCFL effectiveness across critical healthcare applications including disease prediction, medical imaging analysis, patient monitoring, and drug discovery. Looking ahead, crucial research frontiers involve quantum-resilient cryptography, scalable interoperable infrastructure, healthcare-specific consensus mechanisms, and automated compliance frameworks. This tutorial serves as a foundational reference for developing trustworthy, interoperable, and patient-centric AI systems that transform healthcare delivery while ensuring privacy protection and regulatory compliance. The successful realization of secure collaborative healthcare analytics through BCFL will drive improved patient outcomes and accelerate medical discoveries in an increasingly connected healthcare ecosystem. CLINICALTRIAL N/A
The increasing use of localization devices for location-based services has led to an explosion in user location data. This raises significant privacy concerns that often conflict with the need for identification and accountability in critical scenarios like criminal investigations or public health emergencies. Research is facing the challenge of balancing privacy with data utility, guaranteeing trust in verification. This paper proposes a novel blockchain-based solution to reconcile the conflicting requirements of user privacy and accountability in localization. Our scheme leverages the transparency and immutability of blockchain to record verifiable location proofs. To ensure user privacy against routine disclosure, the solution integrates elliptic curve cryptography and Zero-Knowledge Proofs, allowing a verifier to confirm a user's presence without revealing sensitive information. Our solution also prevents the verifier from disclosing proof of a user's past presence to third parties, further enhancing privacy. Moreover, the proposed system provides a mechanism for accountability, allowing a designated authority to override privacy safeguards and access location data when legally mandated for public interest reasons, thereby reconciling privacy and identification needs.
Evidence plays a crucial role in judicial systems, and managing it securely and efficiently ensures justice. This paper introduces Decentralized Trust, a framework that combines blockchain technology, Non-Fungible Tokens (NFTs), and fog computing to address common issues like tampering, delays, and reliance on centralized systems. Traditional methods that depend on cloud computing often face high latency and slow processing, especially in remote areas. This research also builds upon the challenges identified in previous studies, such as tampering vulnerabilities, inefficiencies in evidence processing, and accessibility issues in underserved regions, providing a novel and comprehensive solution through Decentralized Trust. Fog computing handles tasks closer to where data is created, reducing delays and improving response times. Blockchain ensures that evidence records cannot be altered, while NFTs make each piece of evidence unique and tamper-proof. The framework is organized into layers: edge nodes at police stations capture evidence, fog nodes process the data and create NFTs, and cloud storage, supported by the Interplanetary File System (IPFS), provides secure long-term storage. Results demonstrate that the framework achieves average transaction delays of 24.5 seconds on low-performance devices (Node A) and 168.9 seconds on high-performance devices (Node B), with margins of error showing efficient scalability even under significant processing loads. The observed transaction delays are due to differences in system architecture and processing priorities. High-performance devices (Node B) have more complex validation processes, increased security checks, or resource contention, contributing to longer transaction times. By combining these technologies, Decentralized Trust offers a reliable, fast, and secure way to manage judicial evidence, building trust in the framework while addressing the needs of remote and underserved areas.
Shahida Hafeezan Qureshi, Saif Ur Rehman Malik, Junaid Haseeb, Syed Atif Moqurrab · 6 authors
ABSTRACT Federated Learning (FL) is emerging as a premier paradigm for privacyâpreserved Machine Learning (ML), enabling devices to train models without central data pooling collaboratively. In the contemporary Internet of Things (IoT) landscape, characterized by escalating energy consumption and associated carbon footprint, FL is recognized not merely for its privacy features. Intrinsic to decentralized architectures such as FL, secure communication is based on digital signatures to guarantee integrity. This is particularly evident in sensitive sectors such as the Internet of Vehicles (IoV), banking, and healthcare. Integrating FL becomes imperative and intricate as these sectors are intertwined with the IoT fabric. Our study unveils âSecure Federated Learning Framework (SecFL),â a pioneering decentralized framework combining FL and sustainable computing. SecFL offers defences against adversarial attacks such as data poisoning and label flipping. Utilizing the RivestâShamirâAdleman (RSA) asymmetric encryption algorithm for securing digital communications and transactions, combined with ElGamal encryption and a private Ethereum blockchain, ensures enhanced clientâspecific security. Our research emphasizes the formal modeling of adversarial dynamics using HighâLevel Petri nets (HLPN) within the FLâIoT ecosystem, balancing system dynamics and energy conservation. Our model consistently outperforms contemporary solutions in accuracy and time efficiency after validation. As IoT burgeons into domains like environmental monitoring, smart cities, and energy grids, the SecFL framework, fostering FL, optimizes energy utilization and bolsters resource efficiency. In our comparative analysis, the Elliptic Curve Digital Signature Algorithm (ECDSA) algorithm demonstrates superior transaction latency and verification time compared to RSA and Elliptic Curve Cryptography (ECC).
The Internet of Things (IoT) has become an integral part of daily life, making the protection of user privacy increasingly important. In gateway-based IoT systems, user data is transmitted through gateways to platforms, pushing the data to various applications, widely used in smart cities, industrial IoT, smart farms, healthcare IoT, and other fields. Threshold Public Key Encryption (TPKE) provides a method to distribute private keys for decryption, enabling joint decryption by multiple parties, thus ensuring data security during gateway transmission, platform storage, and application access. However, existing TPKE schemes face several limitations, including vulnerability to quantum attacks, failure to meet Simulation-Security (SS) requirements, lack of verifiability, and inefficiency, which results in gateway-based IoT systems still being not secure and efficient enough. To address these challenges, we propose a Verifiable Simulation-Secure Threshold PKE scheme based on standard Module-LWE (VSSTPM). Our scheme resists quantum attacks, achieves SS, and incorporates Non-Interactive Zero-Knowledge (NIZK) proofs. Implementation and performance evaluations demonstrate that VSSTPM offers 112-bit quantum security and outperforms existing TPKE schemes in terms of efficiency. Compared to the ECC-based TPKE scheme, our scheme reduces the time cost for decryption participants by 72.66%, and the decryption verification of their scheme is 11 times slower than ours. Compared with the latest lattice-based TPKE scheme, our scheme reduces the time overhead by 90% and 48.9% in system user encryption and decryption verification, respectively, and their scheme is 13 times slower than ours in terms of decryption participants.
With the rapid growth of healthcare data and the need for secure, interpretable, and decentralized machine learning systems, Federated Learning (FL) has emerged as a promising solution. However, FL models often face challenges regarding privacy preservation, transparency, and resistance to adversarial attacks. To address these limitations, this paper proposes the Privacy Preserving Federated Blockchain Explainable Artificial Intelligence Optimization (PPFBXAIO) framework, which integrates blockchain technology, Explainable AI (XAI), and optimization techniques to ensure privacy, traceability, and robustness in FL-based systems. PPFBXAIO employs Secure Hash Algorithm 256 (SHA-256) for blockchain-backed secure model updates, Min-Max normalization for feature scaling, and the Levy Grasshopper Optimization Algorithm (LGOA) for optimal feature selection and federated model tuning. The Entropy Deep Belief Network (EDBN) is used as the classifier to enhance classification accuracy and detect attacks. XAI tools like SHAP are utilized to improve model interpretability. Experimental validation was conducted using the Heart Disease dataset from Kaggle and the Wisconsin Breast Cancer dataset. Results showed that PPFBXAIO achieved 95.07% accuracy, 95.44% precision, 96.54% recall, 95.98% F1 score, and reduced training loss by 4.93% for Breast Cancer Wisconsin and achieved 93.07% accuracy, 91.19% precision, 95.39% recall, 93.24% F1 score for Heart Disease dataset. Proposed system has reduced latency by 81 ms, and improved throughput by 109 transactions per second for 100 rounds as compared to traditional models like FedAvg, FL-MPC, FL-RAEC, and PEFL. These results highlight the framework's superior performance, privacy preservation, and practical applicability in decentralized healthcare AI systems.
Open access
Privacy-Preserving Technologies in Data
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
With the advancement of blockchain technology, smart contracts are increasingly applied in finance, supply chain, healthcare, and other domains. However, the demand for multi-party data joint analysis within these contracts faces challenges of privacy leakage and malicious deception. This paper applies secure multi-party computation (MPC) to smart contracts, based on the secure computation of intersection, union, and difference of multi-party multisets (IUDMM), to protect data privacy while supporting joint analysis. Existing multiset computation protocols are primarily designed for two-party scenarios under the semi-honest model, which are unsuitable for applications involving multiple participants in smart contracts. This paper introduces a protocol for IUDMM under the semi-honest model, utilizing the multi-key NTRU encryption algorithm and a novel vector encoding method. Furthermore, to address potential malicious behaviors, an IUDMM protocol under the malicious model is designed by incorporating digital commitment method. The protocolâs correctness is analyzed, and its security is proven using the real/ideal model paradigm. Additionally, it also resists collusion attacks by any party. Finally, efficiency analysis and experimental simulations demonstrate that the proposed protocols are efficient, reliable, and fair, providing a secure and practical solution for multi-party data joint analysis and privacy protection in smart contracts.
Blockchain has become a cornerstone of trustworthy, decentralised information governance. Consensus protocols and cryptographic linkages guarantee data integrity, immutability, and verifiable provenance, eliminating reliance on a single trusted authority and mitigating data fragmentation. Within smartâhealthcare ecosystems, these capabilities enable the shift from siloed, centralised repositories to distributed, patientâcentric infrastructures. Because clinical data are highly sensitive and strictly regulated, robust assurances of integrity, confidentiality, and fineâgrained authorisation are essential. Integrating blockchain and smart contracts with technologies such as distributed offâchain storage and the Internet of Medical Things (IoMT) creates a resilient, scalable, and interoperable foundation for nextâgeneration healthcare data management. This research introduces hChain, a fourâgeneration family of distributedâledger frameworks that progressively strengthen security, intelligence, and scalability in smartâhealthcare environments. hChain 1.0 lays the groundwork with a blockchain architecture that safeguards patient data, supports realâtime clinical telemetry, and enables seamless interâinstitutional exchange. Building on this foundation, hChain 2.0 integrates InterPlanetary File System (IPFS) storage and smartâcontract enforcement to deliver tamperâproof, fineâgrained access control. hChain 3.0 embeds onâchain deepâlearning analytics, providing proactive, automated decision support across the care continuum while preserving data integrity. Finally, hChain 4.0 introduces a highly scalable, permissioned ledger augmented by an AttributeâBased Access Control (ABAC) layer, ensuring dynamic, contextâaware authorisation in complex organisational settings. The results demonstrate practical solutions for transforming data infrastructures from centralised to decentralised architectures, providing techniques that facilitate seamless integration with existing systems while enhancing blockchain scalability and privacy.
In this framework, Blockchain-Integrated Access Control for Wireless Edge Networks intends to attempt authentication and authorization by using smart contracts and immutable ledgers making it secure and decentralized. It increases trust among edge nodes by connecting them, thereby creating a single point of failure, while providing transparent and tamper-resistant enforcement of policies, which improves scalability, resilience, and performance, ultimately making it the Mold for IoT and edge computing environments. The objectives that the system intends to apply towards are design and implement decentralized access control for wireless edge networks using Blockchain, to provide tamper-proof identity verification solutions, to ensure dynamic access policies enforced through smart contracts, to reduce dependency on central authorities, and also to increase security and privacy, scaling trust, and transparency in the distributed IoT and edge environments. The proposed system proposed to implement decentralized access control via private Blockchain in wireless edge networks. Smart contracts are crafted to dynamically facilitate identity authentication, access rights, and the enforcement of policies. Edge nodes interface with the Blockchain to verify credentials and log access attempts immutably. To curb latency and overhead, lightweight cryptography schemes and consensus algorithms such as PBFT are employed. Simulation in a wireless edge environment showed improvements in access request validation by 35%, unauthorized access attempts down by 42%, and improved scalability with respect to conventional centralized models, showing that the model is effectual and robust in secure access control.
Zhi Lu, Mengyuan Zou, Samir M. Umran, Yuhao Long · 7 authors
Federated learning, as an emerging distributed machine learning approach, enables collaborative model training while protecting data privacy. However, federated learning is vulnerable to Byzantine attacks and inference attacks. Existing solutions typically require semi-honest servers to perform secure aggregation or lack effective input validation mechanisms. To address these issues, we propose RIDE, a secure aggregation protocol for decentralized federated learning with input validation. RIDE utilizes pedersen commitments and efficient zero-knowledge proofs to verify whether model updates comply with predefined constraints, ensuring client input privacy and integrity. Additionally, RIDE employs a publicly verifiable secret sharing scheme, ensuring that only validated model updates are aggregated, even in the presence of malicious clients or client dropouts. Experimental results on four real datasets demonstrate the effectiveness of our solution. For example, RIDE has a maximum bandwidth overhead of 7.11MB, which is only 1.31Ă that of the most popular secure aggregation protocol (CCS 2020), and the computational cost of RIDEâs execution on the CIFAR-10 L dataset is 109.88s, which is 7.28Ă faster than the current state-of-the-art protocol RoFL (S&P 2023).
Federated learning has found extensive application in the multimedia domain. However, due to its distributed nature, it is vulnerable to attacks such as Byzantine poisoning. To counteract malicious attacks, the secure aggregation process in federated learning requires input validation from participants. Existing input verification schemes, such as ACORN (USENIX Security 2023), ROFL (S&P 2023), et al., efficiently assess the validity of client inputs, but they fail to account for the impact of weights and do not support weighted secure aggregation. To address these issues, we propose α-SAV, an efficient weighted input verification scheme that utilizes Pedersen commitments to encrypt both privacy and weighted gradients. Our scheme incorporates a non-interactive zero-knowledge proof, the Sigma protocol, allowing clients to generate input proofs without interacting with the server. Verified inputs can then contribute to weighted aggregation. α-SAV is highly compatible, seamlessly integrating into existing federated learning frameworks with minimal additional cost. Experimental results demonstrate that the cost of α-SAV is linear. When trained on the MNIST dataset, the client computation time for α-SAV is 1.6 seconds, resulting in only 24% additional cost compared to ACORN and 3% compared to ROFL.
Alejandro Guerra-Manzanares, Omar El-Herraoui, Michail Maniatakos, Farah E. Shamout
One of the key challenges of collaborative machine learning, without data sharing, is multimodal data heterogeneity in real-world settings. While Federated Learning (FL) enables model training across multiple clients, existing frameworks, such as horizontal and vertical FL, are only effective in âidealâ settings that meet specific assumptions. Hence, they struggle to address scenarios where neither all modalities nor all samples are represented across the participating clients. To address this gap, we propose BlendFL, a novel FL framework that seamlessly blends the principles of horizontal and vertical FL in a synchronized and non-restrictive fashion despite the asymmetry across clients. Specifically, any client within BlendFL can benefit from either of the approaches, or both simultaneously, according to its available dataset. In addition, BlendFL features a decentralized inference mechanism, empowering clients to run collaboratively trained local models using available local data, thereby reducing latency and reliance on central servers for inference. We also introduce BlendAvg, an adaptive global model aggregation strategy that prioritizes collaborative model updates based on each clientâs performance. We trained and evaluated BlendFL and other state-of-the-art baselines on three classification tasks using a large-scale real-world multimodal medical dataset and a popular multimodal benchmark. Our results highlight BlendFLâs superior performance for both multimodal and unimodal classification. Ablation studies demonstrate BlendFLâs faster convergence compared to traditional approaches, accelerating collaborative learning. Overall, in our study we highlight the potential of BlendFL for handling multimodal data heterogeneity for collaborative learning in real-world settings where data privacy is crucial, such as in healthcare and finance.
While Federated learning (FL) is considered privacy-preserving by nature, it remains vulnerable to many attacks, such as data and model poisoning, that compromise data integrity and model accuracy. Conventional privacy-preserving federated learning (PPFL) mechanisms, including homomorphic encryption (HE), secure aggregation, and secure multiparty computation (SMPC) demonstrate several limitations, such as high computational complexity, significant communication overhead, and scalability challenges. To overcome the aforementioned issues, we propose an end-to-end secure FL architecture that integrates differential privacy (DP), zero-knowledge proof (ZKP), and median aggregation. DP prevents data leakage during model updates by introducing Laplacian noise for privacy preservation. ZKP is implemented through Schnorrâs protocol, which enables lightweight and efficient client authentication without revealing sensitive information. Finally, median aggregation is incorporated to mitigate the impact of outliers and adversarial updates, ensuring robust prediction aggregation. The experimental results indicate that the proposed approach outperforms other well-known PPFL methods including partially homomorphic encryption (PHE), fully homomorphic encryption (FHE) and SMPC. It delivers substantial improvements in global accuracy, especially for larger client counts, with gains of 10%-30% over the other methods. The client training time is significantly reduced by 70%-90%, ensuring faster processing. The approach also excels at reducing average round latency by 80%-95%, enhancing the overall efficiency of the system. Communication overhead is significantly reduced by 65%-85%, lowering data transfer costs per round. Furthermore, the size of the model is minimized by 60%-85%, making it more resource efficient and scalable for larger deployments.
The demand for privacy-preserving machine learning has led to the rise of Federated Learning (FL), where multiple clients collaboratively train a model without sharing raw data. Despite its privacy benefits, FL is vulnerable to Byzantine failures, where malicious or faulty participants inject corrupted updates, threatening model integrity. To address this, a range of Byzantine-resilient aggregation techniques have been proposed, including statistical filters (e.g., Trimmed Mean, Krum), trust-based weighting, cryptographic protocols, and hybrid strategies. This paper presents a systematic literature review (SLR) of these defenses, evaluating their robustness, scalability, and suitability for real-world applications. Challenges such as non-IID data, adaptive attacks, and trade-offs between security and efficiency are critically examined. In addition, we explore emerging trends such as domain-specific defenses, energy-aware FL, quantum-resilient methods, and federated zero-knowledge proofs. A novel classification of hybrid approaches and a standardized benchmarking framework are proposed to guide future research. This review aims to support the development of resilient, efficient and scalable decentralized learning systems in adversarial environments.
Blockchain technology presents transformative opportunities for secure personal data sharing, particularly in healthcare, finance, and identity management. However, its widespread adoption is constrained by challenges such as limited scalability, privacy concerns, and conflicts with regulatory frameworks like the General Data Protection Regulation (GDPR). This study introduces a novel hybrid framework that integrates the InterPlanetary File System (IPFS) for off-chain storage with Zero-Knowledge Proofs (ZKPs) to enhance privacy, ensure regulatory compliance, and reduce on-chain storage demands. Employing a Design Science Research (DSR) methodology, the framework was developed and validated using Ethereum and Hyperledger Fabric, guided by insights from a systematic review of 180 studies from 2018 to 2023. Empirical evaluations revealed a 75% reduction in blockchain storage, 98% GDPR compliance, and zk-SNARK proof verification times below one second. The framework also enables GDPR-compliant erasure by removing encrypted off-chain data while preserving on-chain auditability. Despite challenges such as IPFS latency and trusted setup complexities, the solution offers a scalable and privacy-preserving architecture applicable to real-world domains, especially in privacy-critical environments like healthcare and finance by resolving blockchainâs GDPR compliance paradox.
Bo-Sian Liao, JungâShian Li, IâHsien Liu, Chuan-Kang Liu
Federated Learning (FL) has emerged as an innovative paradigm that enables heterogeneous and geographically distributed clients to collaboratively train models in a decentralized and privacy-preserving manner. However, FL systems face numerous challenges in real-world deployments, particularly passive participation caused by malicious attacks, where clients drop out due to attacks. This issue, though not intentionally designed by the system, significantly impacts training stability. In this study, we propose BAHA-FL (Blockchain-based Adaptive Historical Averaging Federated Learning. Our approach integrates adaptive historical averaging with exponential decay weighting to effectively compensate for missing parameters due to client dropouts. Our blockchainbased solution ensures the immutability and traceability of model update records, leveraging Distributed Ledger Technology (DLT) to maintain model integrity.
Syed Abrar Ahmed, Ricardo Correia, Anderson Oliveira do Carmo, Henrique Martins
Increasingly, across geographies, citizens are requiring access to and control of their health data. This paper examines the "Logging Component" proposed by the European Health Data Space (EHDS) regulation and its crucial role in facilitating secure and transparent access to electronic health records (EHR) and health data. We analysed the proposal for the five elements of the Logging Component (LC): identification of data accessors, identification of data subjects, categorisation of accessed data, temporal logging, and data origin tracking. Explored how these elements contribute towards enhanced accountability and compliance in health data management. We experimented with distributed ledger technology (DLT) to support the "data origin tracking element", reaching the demonstration level which can be presented. We used hybrid DLT to develop a system for immutable storage of access logs, and for using smart contracts to maintain a self-governing decentralised access control list (ACL) directly integrated with EHR and PHR systems. We found that the LC is more than a regulatory requirement. It can serve as a framework for the integration of advanced technologies, e.g. DLT and others, increasingly mature and potentially foundational to building new networks of trust among stakeholders, while ensuring data privacy in cross-border and intra-border healthcare scenarios. The study also identified shortcomings of the LC, such as the absence of "purpose logging", which was conceptualised and proposed. This study contributes to the understanding of how logging mechanisms can enhance transparency and accountability in electronic health record systems within the European healthcare landscape, but with potential usefulness for the "Global EHR". In conclusion, our findings suggest that the successful implementation of the five elements of the Logging Component are mandatory and can benefit from mature advance technologies, but the sixth element proposed by us would be critical for achieving the EHDS's broader objectives of harmonised health data sharing in Europe and beyond while maintaining robust security standards.
Advancements in personalized medicine require secure, transparent, and privacy-preserving genomic data management systems. This study proposes a novel hybrid blockchain-based genomic data model integrating Self-Sovereign Identity (SSI), Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and decentralized storage Interplanetary File System (IPFS) to enable secure, privacy-compliant, patient-controlled genomic data exchange. The model leverages Polygon Proof-of-Stake (PoS) blockchain by deploying a smart contract that enforces fully access control functions applied on 100 samples of synthetic genomic data, ensuring only authorized researchers with valid DIDs and VCs can retrieve genomic data. Later, we performed five tests to evaluate our model performance. Security evaluations confirmed 100% data integrity validation through SHA-256 hash validation on-chain, ensuring tamper-proof genomic data storage. Unauthorized access attempts resulted in zero successful breaches, demonstrating the robustness of SSI-based authentication by showing revoked access. Additionally, IPFS data availability testing confirmed reliable and decentralized data retrieval through the Content Identifier (CID) on-chain. The model's access revocation mechanism enabled real-time patient control over genomic data access, ensuring compliance with GDPR privacy regulations. The proposed model provides a scalable, secure, and privacy-compliant solution for genomic data sharing in precision medicine, empowering patients with full control over their genetic data while facilitating researchers to trustworthy, decentralized data useability for precision research.
Bhatt Vinayak Vishwanath, Nishanth Kumar Pathi, Shinu Abhi
Zero Knowledge Proof (ZKP) is a cryptographic method that allows a prover to demonstrate to a verifier that a statement is true without revealing any additional information. This is highly relevant in healthcare, where data privacy is critical. By integrating ZKP into healthcare applications, sensitive patient data can be securely verified without exposing unnecessary information. In healthcare, protecting sensitive data while enabling seamless collaboration between doctors, laboratories, and other entities is crucial. Sharing or verifying data often leads to privacy risks. The project aims to develop a ZKP protocol for a healthcare system, allowing secure and private verification of sensitive medical data between doctors and laboratories. The ZKP protocol is implemented using a hybrid system with cloud services and local machines for secure computation. AWS Key Management Service (KMS) handles encryption and decryption. The protocol creates cryptographic proof for verifiers to confirm data validity without accessing the data itself. Established cryptographic libraries and healthcare test data are used in the implementation. The system ensures scalability and security by leveraging AWS infrastructure and MySQL database integration for proof storage. The ZKP protocol successfully verified health care data without exposing sensitive information, reducing the risk of data breaches. This approach improves data security without compromising functionality, setting new privacy standards in healthcare data management.
Over the course of more than a decade, blockchain technology has made significant advancements and found applications in various domains. Smart contract, as an integral component of blockchain technology, plays a pivotal role in ensuring the security and robustness of blockchainâs development and diverse applications. Currently, smart contract vulnerabilities have caused millions of dollars in economic losses. Due to the inherent immutability of blockchain technology, once smart contracts are deployed on the blockchain, effecting changes becomes a formidable task. Most of the vulnerability detection tools currently available employ traditional security technologies, which require high expertise and have unsatisfactory detection results. In recent years, deep learning technologies have emerged. Although they do not require extensive expert knowledge, they do require a large amount of labeled data for training. The biggest issue in this field is the lack of a large-scale, accurately annotated public dataset. Hence, we propose a method for detecting smart contract vulnerabilities by leveraging federated learning and BiLSTM, called FASCVD. Our approach not only utilizes federated learning technology to aggregate multiple small datasets while ensuring data privacy but also introduces a bidirectional information extraction technique based on BiLSTM, thereby significantly enhancing the accuracy of vulnerability detection. The experimental results show that our method has already surpassed the best existing methods in terms of accuracy, precision, recall, F1-score, and so on, with an accuracy rate of 95.04%.