PARI is a recent SNARK based on equifficient polynomial commitments, giving an exceptionally compact proof of just 1280 bits over the BLS12-381 curve, which is the smallest among all the known SNARKs in the literature. However, PARI does not achieve the zero-knowledge property; despite being very efficient, it is therefore less suitable for applications requiring witness privacy. In this work, we propose a zero-knowledge extension of PARI making it ideal for privacy-centric applications yet keeping the proof size compact. We prove perfect completeness, perfect zero-knowledge in the random-oracle model with challenge space <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:mi>𝔽</mml:mi> <mml:mi>⧵</mml:mi> <mml:mi>K</mml:mi> </mml:mrow> </mml:math> , and knowledge soundness in the algebraic group model with random oracles under the SDH assumption.
Zero-knowledge proofs (ZKPs) are a fundamental building block in cryptography, enabling powerful privacy-preserving and verifiable computations. In the post-quantum era, hash-based ZKPs have emerged as a promising direction due to their conjectured resistance to quantum attacks, along with their simplicity and efficiency. In this work, we introduce SmallWood, a hash-based polynomial commitment scheme (PCS) and zero-knowledge argument system optimized for relatively small instances. Building on the recent degree-enforcing commitment scheme (DECS) from the Threshold-Computation-in-the-Head (TCitH) framework, we refine its formalization and combine it with techniques from Brakedown. This results in a new hash-based PCS that is particularly efficient for polynomials of relatively small degree –typically up to <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msup> <mml:mn>2</mml:mn> <mml:mrow> <mml:mn>16</mml:mn> </mml:mrow> </mml:msup> </mml:mrow> </mml:math> – outperforming existing approaches in this range. Leveraging this new PCS, we design a hash-based zero-knowledge argument system that outperforms the state-of-the-art in terms of proof sizes for witness sizes ranging from <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msup> <mml:mn>2</mml:mn> <mml:mn>6</mml:mn> </mml:msup> </mml:mrow> </mml:math> to <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML"> <mml:mrow> <mml:msup> <mml:mn>2</mml:mn> <mml:mrow> <mml:mn>16</mml:mn> </mml:mrow> </mml:msup> </mml:mrow> </mml:math> . Additionally, we present exact zero-knowledge arguments for lattice-based problems using SmallWood, demonstrating highly competitive performance: our scheme yields proof sizes under 25 KB across a wide range of lattice parameters, including Kyber and Dilithium instances.
This paper assesses the adequacy of technology-neutral privacy frameworks in addressing quantum threats to zero-knowledge proofs (ZKPs) and other privacy-enhancing technologies (PETs) in global data protection regimes. Challenging assumptions that cryptographic innovation inherently bolsters privacy rights, the analysis demonstrates how post-quantum migration, absent binding regulatory duties, risks entrenching a ‘quantum divide’ in access and liability. Grounded in legal frameworks and actual deployments, including Zcash’s classical Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge (ZK-SNARKs) and NantHealth Inc.’s quantum-aware homomorphic encryption systems, the paper contends that access to PETs is becoming ever more determined by institutional capability and geopolitical factors, as illustrated by comparative case studies. This research evaluates the efficacy of statutes such as the European Union’s (EU) General Data Protection Regulation (GDPR) (Article 32), the California Consumer Privacy Act (CCPA) (§ 1798.150), and the Health Insurance Portability and Accountability Act (HIPAA) (45 C.F.R. § 164.308) in imposing liability for quantum vulnerable systems, using the cases to illustrate gaps in mandating equitable post-quantum migration. The conclusion reflects upon legal gaps enabling unequal protections, advocating reforms including mandatory quantum risk assessments. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Financial settlement systems rely heavily on institutional trust: intermediaries maintain ledgers, certifycompliance, and prevent unauthorized creation or movement of value. Zero-knowledge (ZK) techniques make itpossible to replace part of that trust with verifiable properties. This paper presents a minimal ZK settlementlayer designed around a simple principle: prove what must be true, disclose only what must be seen, anddeclare remaining trust explicitly.We describe an architecture in which transfers preserve value, spending authority is proven without sharingspending keys with the operator, double-spending is prevented, and supervisors can verify balance bands orthresholds without receiving the full ledger. We also map the residual trust surface: the operator of a singlenode can still see balances, order transactions, and censor. The contribution is not a claim of full sovereignty ordecentralization. It is a precise shift from opaque institutional faith toward a smaller, named set of trustassumptions, with cryptographic checks covering the rest.We compare this model conceptually with core banking systems and permissioned blockchains, and argue thatthe main institutional value of ZK settlement is not “trustlessness,” but trust minimization with honestresidual boundaries.This revision subjects that claim to its own standard. An audit pass against the reference implementation foundresidual dependencies the first version of this paper had not named: a confidentiality leak toward thecounterparty rather than the operator, three quantified capacity bounds, and a privilege that is counted butnever expires. We report them in §4.4 and §4.5, because a paper whose contribution is naming residual trust isfalsified by the trust it failed to name.
Blockchain can secure and verify electronic health records (EHRs) for multi-institution healthcare systems, but Layer-1 storage costs and throughput limitations make full on-chain EHR storage impractical. A new model is proposed named FZRP (Federated-ZK-Rollup Pipeline). It is a hybrid methodology combining Federated Learning (FL), off-chain storage (IPFS), zk-rollup batching with adaptive batch sizing, and parallel proof pipelines to minimize per-record transaction cost while preserving auditability and privacy. Using a synthetic dataset of 50,000 EHRs, it quantifies cost reductions under realistic assumptions and demonstrate orders-of-magnitude per-record savings. A formal cost model, latency and security analyses, and sensitivity studies are provided. The experimental evaluation demonstrates that adaptive batching significantly reduces per-record transaction cost under conservative Layer-1 cost assumptions to as low as $0.000024, achieving over 99.999% cost reduction while maintaining scalability and privacy. The limitations, regulatory considerations, and paths for future work are discussed.
The advent of fault-tolerant quantum computing represents the most significant and schedulable threat to the cryptographic foundations of blockchain infrastructure. Over $3.2 trillion in digital assets are currently secured by RSA, Elliptic Curve Cryptography (ECC), and ECDSA: algorithms provably broken by Shor's algorithm running on a Cryptographically Relevant Quantum Computer (CRQC). The Harvest Now, Decrypt Later (HNDL) threat means this risk is not future-dated. Adversaries with archival capability are already harvesting public blockchain data for retrospective decryption. In August 2024, NIST published three finalized post-quantum cryptographic standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). In 2025, NIST standardized HQC, providing code-based cryptographic diversity alongside the lattice-based primary algorithms. These standards are mandated for U.S. national security systems under NSA CNSA 2.0 and for high-risk sector operators in the EU under the EU PQC Roadmap. This paper introduces QubitChain.io: a natively quantum-safe Layer 1 blockchain implementing all four NIST post-quantum standards from genesis block. The protocol employs hardware Quantum Random Number Generator (QRNG) entropy at both key generation and consensus randomness levels, and introduces Proof of Quantum Entropy (PoQE), a novel consensus mechanism whose validator selection cannot be predicted or manipulated by any adversary regardless of computational capability. The paper provides the complete technical, economic, and governance specification for the QubitChain.io protocol, covering cryptographic architecture, QRNG system design, consensus mechanism, network protocol, tokenomics, governance, and regulatory compliance.
The exponential emergence of cross-chain data sharing in blockchain-enabled IoT and cloud systems creates vital challenges in the scalability, privacy, and post-quantum security landscapes. To tackle these problems, we propose a hierarchical attribute clustering-attribute-based encryption (HAC-ABE) scheme in this paper, which offers a secure post-quantum cross-blockchain data exchange framework. The method utilizes hierarchical attribute clustering and lattice-based encryption to reduce the computation overhead while supporting fine-grained access control. It utilizes IPFS decentralized storage and smart contracts to achieve a transparent data exchange across chains. Experimental results show 9.7% faster computation time and much lower communication overheads than state-of-the-art ABE-based approaches, verifying its effectiveness and scalability for practical decentralized environments.
Newborn misidentification poses serious patient safety and accountability problems, but errors can be traced through the use of a blockchain to create an audit trail. However, a blockchain storing raw or even hashed biometric templates for individual identities is not acceptable for privacy reasons. This work redefines our prior work (1) to form a privacy-preserving audit protocol that isolates the processes of capturing a biometric and matching it against a database of known identities to an external Service Provider and the processing of the blockchain to a permissioned Ledger that contains only pseudonymous audit commitments related to keyed entries on the Ledger. This work describes an implementation of this protocol in Solidity 0.8.30 and provides metrics for the gas use and latency of the smart contract for 100 iterations of 100 total Enrollment and Verification Workflows each. Twenty Adversarial Functional Tests are also described that attempt to place the system into an invalid state, as well as four additional tests that assess the effect of batched submission to the smart contract of multiple keyed audit commitments. The smart contract processing throughput is also determined for a batch of submissions, finding a maximum local throughput of 60.2 tx/s. A further 50,000 randomized reference-model transitions of the system’s internal reference-model were then made (involving a total of 57,345,087 invariant checks, all of which passed), as well as a measurement of the time taken to generate an HMAC-SHA-256-sized commitment for 10,000 iterations (local median time = 0.002 ms). The results of this work provide a solid foundation for the blockchain component of BIBIS, but it is not intended to provide any insights into the accuracy of neonatal biometric matching, the presentation attack resistance of the system, or even the usability of BIBIS by clinical end-users. The results also do not comment on the finality of QBFT-based commits to a blockchain.
Rodrigo Jara Espinoza, Yohamin Nafit Pimentel Alarcon, Angelo Rodrigo Taco Jiménez, Fabricio Martin Chavez Rodriguez
Quantum computing poses a significant threat to classical asymmetric cryptography, which is essential for ensuring confidentiality, authentication, and key exchange in contemporary digital infrastructures. Although post-quantum cryptography (PQC) provides mechanisms that resist quantum attacks, its implementation in Internet of Things (IoT) systems is challenged by constrained resources, including limitations in computation, memory, energy, latency, and bandwidth, and the heterogeneity of devices. This paper offers a comprehensive narrative review of PQC approaches applicable to IoT, systematically organizing 30 peer-reviewed studies published between 2022 and 2026 across four layers: device, communication, distributed trust, and application. Additionally, the review examines two cross-cutting dimensions, privacy and side-channel resistance. The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures. Notably, key gaps remain in side-channel evaluation, migration pathways, deployment costs, and real-world validation—issues that are particularly critical given the long lifecycles of IoT devices and the ongoing threat of “harvest now, decrypt later” attacks.
With the advent of digital services, various vulnerabilities in centralized identity management systems such as Single Point of Failure (SPOF), data leakage, and user privacy invasion are evident. In this paper, an architecture framework for designing Decentralized Identity Management System (DIDMS) by leveraging blockchain technologies is proposed for privacy preserving authentication in digital age. The DIDMS framework makes use of Decentralized Identifier (DID) with Verifiable Credentials (VC) and Zero Knowledge Proof (ZKP) techniques to implement the concept of self-sovereign identity. Four phases of framework including registration, credential issuance, authentication and storage is designed and tested. The performance results obtained from the experimentation indicate that the proposed framework gives an authentication latency of 320 ms, storage overhead reduction of 42%, and verification accuracy of 98.6% with 31% gas optimization over conventional smart contract approaches. The comparative evaluation with existing frameworks indicates improvement in the areas of privacy protection, scalability and user control.
Supervisors need reliable assurance over balances, issuance, and transaction integrity. Institutions need toprotect sensitive financial data. Traditional audit practice often resolves this tension by granting broad accessto ledgers. That approach is effective, but costly in privacy, operational risk, and cross-border data exposure.This note presents a settlement architecture in which compliance statements can be proven cryptographicallywithout disclosing the full ledger. A supervised entity can demonstrate that a balance equals a value, exceeds athreshold, or lies within a band. Verifiers check the proof without receiving account-level books. Spending keysremain on the client side and do not travel to the operator to authorize a transfer.A second confidentiality property is reported that is easy to miss in architectural summaries: in a settlementthat updates both accounts in a single transition, the payer must know the recipient’s balance in order toconstruct the proof. Paying someone therefore reveals what they hold. The architecture addresses this with atwo-phase transfer, at a stated cost in finality latency.The paper is deliberately non-utopian. It specifies which properties become demonstrable and which residualtrust remains—especially in a single-node deployment where the operator may still observe state, sequencetransactions, or censor. The institutional claim is modest: zero-knowledge settlement can reduce routine fullledgerdisclosure while improving the quality of evidence for specific supervisory questions.
Decentralized manufacturing faces a pre-contractual impasse: a Provider cannot price a service accurately without inspecting the design file, yet the Consumer cannot share that file without exposing intellectual property. We introduce the Optimistic Verifiable Claim (OVC), a blockchain protocol that lets a Consumer publish a verifiable claim about a concealed design (such as the material it consumes) and a Provider price and bid on it without seeing the design. The claim is committed when the service is posted and stands unless the selected Provider challenges it; a challenge triggers a deterministic on-chain check that exposes any dishonesty, and the design is disclosed only to settle a dispute, never on the honest path. We implement four checks (authorized key access, delivery-channel integrity, syntactic conformance, and declared material consumption) in Solidity and measure them on a real 6.41 MB G-code file, the 3DBenchy, across Ethereum, Arbitrum, and opBNB. Every service incurs the cost of posting the encrypted design, with or without a dispute. For the 3DBenchy, the no-dispute outcome costs \$7,207 in up to 9 hours on Ethereum, \$288 in 3 min on Arbitrum, and \$2.87 in 2 min on opBNB, and a fully contested dispute costs \$49,660 in up to 57 hours on Ethereum, \$1,988 in 19 min on Arbitrum, and \$19.73 in 13 min on opBNB. Costs and times grow with size: for a 50 MB industrial design, an undisputed service reaches \$56,173 and up to 3 days on Ethereum against \$22.36 and 16 min on opBNB, and a fully contested dispute reaches \$488,440 over up to 18 days on Ethereum against \$195 and 1.6 hours on opBNB. Of the four, the material-consumption check is the costliest, its predicate being the most expensive to evaluate on-chain. OVC makes confidential, claim-based bidding economically feasible on Arbitrum and opBNB, but not on Ethereum at industrial scale.
Vabuk Pahari, B. Chandrasekaran, Johnnatan Messias, Krishna P. Gummadi · 5 authors
A decentralized autonomous organization (DAO) is a governance entity that allows its stakeholders to manage blockchain-based protocols through smart contracts. The DAO explicitly specifies how stakeholders make and enforce decisions concerning a protocol's operation in a smart contract, aptly referred to as its governance contract. The design of this governance contract, therefore, has far-reaching implications for the security (trust) and privacy (transparency) of the smart contracts managed by the DAO and its stakeholders. In this work, we (i) explicate the trust and transparency trade-offs of the design choices in implementing a DAO and (ii) highlight how poor choices introduce critical vulnerabilities, using real-world examples as case studies. To this end, we analyze $48$ public, actively used Ethereum-based DAOs that control a vast capital. We classify the design choices into a handful of key dimensions that succinctly capture how a DAO's stakeholders initiate a protocol change, vote on it, and, based on the voting outcome, execute that change. Our analyses crucially uncover a new class of attacks, which we call governance attacks, that directly exploit the fundamental design of a DAO's governance mechanisms, even if we assume bug-free implementations.
Harlequin is a blockchain protocol in which the right to take part in consensus, governance and adjudication comes solely from reputation earned by verifiable acts — never from capital (proof of stake) or expended computation (proof of work). Reputation is a four-dimensional quantity ("the four suits"), computed deterministically from a public evidence record by a damped trust-propagation function, aggregated conservatively (a strong dimension cannot buy authority in a weak one), and subject to time decay so that standing must be continually re-earned. Block authorship and committee/jury membership are assigned by reputation-weighted cryptographic sortition; finality is provided by a Byzantine-safe gadget over signed votes; disputes are judged by sortitioned juries with interest-exclusion, and the only enforced consequence is reputational — the protocol applies no coercive force. We give the system model, the consensus and justice mechanisms, and a security analysis against a state-level adversary whose goal is capture, censorship or de-anonymization rather than direct theft. Two results are emphasized for their honesty. First, steady-state Sybil resistance is strong: a Sybil farm without earned evidence obtains about 0% of consensus power (17/17 adversarial tests). Second, the cold-start window is not unconditionally safe: a competent adversary present at genesis can capture the bootstrap; we show the security of that window is a race between honest onboarding and adversary mass — bounded, not eliminated, by non-operator personhood verification, an automatic ceiling-halt and the onboarding rate, with the residual risk declared. We report an implementation in Rust (dependency-free cores cross-validated against FRAME pallets) and a reproducible validation record spanning unit tests and multi-node hardware runs. v3 — post-launch revision. The network described here is no longer a design: the chain launched on 18 July 2026, with its genesis seed anchored to Bitcoin block 958536, and has been sealing blocks under the mechanisms this paper describes since. This revision corrects the emission schedule (per-era public ratios: 15/16 for HLQ, 3/4 for SOV, decoupled from the reputational decay constant), documents the launch facts and the first on-chain runtime upgrade executed through the paper's governance mechanism, and updates the evaluation with the live chain's validation record. Both English and Spanish editions are included; the English edition is the primary text.
Electronic voting has become an important digital governance mechanism for remote elections, institutional decision-making, shareholder voting, public consultations, and large-scale Internet-based democratic participation. Despite its growing relevance, secure electronic voting remains difficult to implement because a practical system must simultaneously preserve voter anonymity, verify voter eligibility, prevent double voting, ensure ballot integrity, support public auditability, and maintain acceptable transaction throughput. To address these challenges, this study proposes a post-quantum secure and privacy-preserving blockchain-based electronic voting framework that integrates Dilithium digital signatures, zero-knowledge proofs, nullifier-based double voting prevention, encrypted ballot submission, smart contract-based election rule enforcement, and a Byzantine fault-tolerant consensus mechanism. In the proposed architecture, Dilithium signatures are used for post-quantum authentication of voter transactions and validator messages, whereas the zero-knowledge proof layer is used separately to verify voter eligibility, candidate validity, credential ownership, and correct nullifier generation without revealing the voter identity or ballot choice. Dilithium verification is performed externally at the transaction authentication layer, while the zero-knowledge circuit handles privacy-preserving voting logic. Each voter locally generates a private credential and submits only a public commitment during registration, thereby reducing the risk of authority-based impersonation or identity-to-vote linkage. Smart contracts verify the proof, reject reused nullifiers, enforce voting rules, and record auditable election events on the permissioned blockchain ledger. Experimental evaluation demonstrates that the proposed prototype achieves an average throughput of 408 transactions per second and an average block finalization time of 2.18 s under stress testing. The results indicate that the framework can provide a practical balance between post-quantum security, privacy preservation, verifiability, and transaction efficiency in permissioned electronic voting environments.
Hayder A. Nahi, Rusul A. Salman, Awring Falah Hassan, Ebtehal Akeel Hamed · 7 authors
Abstract The Internet of Things look out on growing security and privacy defies, principally in light of the up growth of quantum threats. To handle these defies, we suggest a unified security framework that merges post-quantum blockchain technologies and zero-knowledge proofs (ZKPs) to attain secure authentication, decentralized identity management, and advanced data protection. The provided system based on a power-weighted consensus mechanism, compressed and overlapping recursive ZKPs, and transaction batching to decrease on-chain load. The outcomes display that the suggested system outperforms conventional systems and state-of-the-art solutions, with response time reduced to 92 ms, transaction throughput increased to 735 tx/s, energy consumption reduced to 0.37 J/op, and authentication accuracy increased to 97.6%, achieving a privacy score of 0.91.These outcomes emphasize that the offered framework not only attains superior performance but as well supplies strong resistance to quantum attacks and high privacy warranties, making it a promising solution for securing future IoT environments.
Cüneyt Gürcan Akçora, Murat Kantarcioglu, Yulia R. Gel
In this chapter, you will explore the vulnerabilities and attack surfaces of blockchain systems that arise from their open, permissionless nature. You will learn how privacy and security issues manifest at different layers of blockchain architecture, including peer-to-peer networking, transaction propagation, block mining, and smart contract execution. The chapter introduces you to key privacy challenges such as identity leakage, transaction linkability, and deanonymization in UTXO and account-based systems. You will also study how adversaries can mount attacks that exploit consensus protocols, timestamp synchronization, and transaction ordering. The chapter concludes with detailed examples of smart contract vulnerabilities, including reentrancy, front-running, and oracle manipulation, and highlights the economic and technical incentives that make these attacks feasible in Decentralized Finance ecosystems.
Cüneyt Gürcan Akçora, Murat Kantarcioglu, Yulia R. Gel
In this chapter, you will learn about the privacy limitations of public blockchains such as Bitcoin and Ethereum, and how these limitations have led to the development of privacy-focused cryptocurrencies. You will study the motivations for privacy coins and the risks posed by government-issued digital currencies. The chapter introduces and compares three major privacy coins: Zcash, Dash, and Monero. For each, you will explore their underlying technologies, including zero-knowledge proofs (zk-SNARKs), CoinJoin-style mixing, and ring signatures with RingCT and stealth addresses. You will also learn about consensus protocols, supply models, and the trade-offs each project makes between privacy, usability, and scalability. Finally, you will analyze the comparative strengths and weaknesses of these systems and understand the broader implications of privacy on blockchains.
This study examines the potential of Zero-Knowledge Protocols (ZKPs) as cryptographic mechanisms that enhance privacy and security in the context of advancing quantum technologies. Rather than accepting current legal safe guards and regulatory structures at face value, the study critically evaluates their effectiveness, particularly in healthcare environments where highly sensitive data frequently encounters inadequate protection. The methodology employs a multifaceted approach, integrating qualitative insights, legal case studies, and framework analysis. The findings indicate that zero-knowledge proof techniques can significantly enhance the protection of personal health information. A case study of NantHealth Inc.’s quantum-safe healthcare data protection framework illustrates the practical implementation of post-quantum cryptography and homomorphic encryption, demonstrating how health care organizations may proactively address quantum computing threats while enabling secure data collaboration. The study further demonstrates that incorporating these cryptographic methods into existing legal frameworks not only addresses immediate privacy concerns but also facilitates compliance with evolving data protection standards. The study also suggests that healthcare organizations should reconsider their data security approaches by implementing advanced cryptographic measures while maintaining regulatory compliance.
Christian Cachin, David Lehnherr, Juan Villacis, François-Xavier Wicht
Sender untraceability hides the account spent by a cryptocurrency transfer among a set of candidates, its masking set. What a transfer does to that set separates two designs: classical schemes retain the whole set and append a nullifier marking the spent account, so the ledger grows with every transfer; constant-state schemes instead consume and replace the entire set. We ask how this choice affects synchronization. We formalize the two designs as the linear and constant untraceable asset transfer objects (LUAT and CUAT) and locate them in the consensus hierarchy. In LUAT, transfers from distinct accounts commute. Its consensus number is 2, compared with 1 for standard asset transfer, independently of the masking-set size and of the untraceability notion, and LUAT is starvation-free. Partitioning the accounts into fixed masking sets lets exhausted sets be garbage-collected without increasing that number. In CUAT, a transfer consumes and replaces every account of its masking set, so two transfers whose sets intersect cannot both take effect. We formalize this with the conflict graph on masking sets, whose edges join sets sharing an account. Under weak untraceability, which protects a transaction in isolation, the consensus number is unbounded already for one-round protocols. Under strong untraceability, which protects against an observer of the complete history, untraceability holds on a history exactly when any two accounts sharing a masking set occur in the same number of the masking sets in it. This uniform incidence bounds the conflict graph, and matching constructions attain it, so the consensus number is determined exactly and grows quadratically in the masking-set size. Finally, CUAT is not starvation-free. The two objects therefore pay for the same privacy differently: LUAT in storage, CUAT in synchronization and fairness.
Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data. This makes them especially attractive for auditing models deployed in sensitive domains such as healthcare or finance. For these protocols to be meaningful in real-world audit settings, though, their guarantees must reflect how the model will behave once deployed, rather than merely certifying its behavior during an audit. Existing security definitions often miss this mark: most certify model behavior only on a fixed audit dataset, without ensuring that the same guarantees generalize to other datasets drawn from the same distribution. As we show, this gap allows a model provider to attack many cryptographic model certification (CMC) schemes built on secure zero knowledge proofs (ZKP) by carefully engineering training data, resulting in models that exhibit benign behavior during an audit, but pathological behavior in practice. For example, we empirically demonstrate that an attacker can certify that a model achieves over 99% accuracy on an audit dataset, but less than 30% accuracy on fresh samples from the same distribution. To address this gap, we formalize rigorous cryptographic security notions tailored to CMC frameworks, introduce a generic protocol template, and prove that it satisfies these requirements. Our results thus offer both cautionary evidence about existing approaches and constructive guidance for designing secure, privacy-preserving ML auditing protocols.
Junhong Liu, Qinfei Long, Alex Pengfei Zhao, X Zhong · 7 authors
Multi-region unit commitment with reserve sharing requires coordinated optimization across jurisdictionally distinct system operators, exposing sensitive cost curves, topology, and dispatch decisions to inference attacks. The accelerating progress of quantum computing further compounds this threat. As quantum hardware matures, current classically-encrypted data flow becomes vulnerable to retrospective decryption. To enable post-quantum-secure distributed optimization, we propose a customized Benders decomposition-based approach with the global summation structure to share aggregated cuts and variables. By exploiting this structure, we further develop a multi-layer quantum-resilient secure aggregation protocol comprising additive masking for information-theoretic content privacy, affine variable transformation hiding individual sensitive data flows, and reveal-bound lattice-based zero-knowledge proofs providing resilience against active adversaries. Simulation results show that the proposed approach achieves the mean suboptimality of 0.09%-0.22% with lightweight computational overhead, recovers up to 51% of system cost via inter-regional reserve sharing, and imposes no measurable cost-quality trade-off, whereas the noisy ADMM degrades monotonically under tightening privacy budgets and becomes structurally infeasible on combinatorially dense systems.