The protection of the privacy, integrity, and auditability of big data has emerged as a significant concern as organizations are growing more dependent on multi-cloud data ecosystems which are decentralized in nature. The problems that traditional data governance models are not able to deal with are a lack of transparency, distrust towards information sharing, inconsistent access control, and their tendency to be tampered with. In order to close these shortcomings, the paper presents a Privacy-Aware Big Data Governance Framework (PBGF) which uses blockchain technology, distributed access control, and fine-grained privacy preservation to safeguard the total data lifecycle. The framework has incorporated smart contracts to automate governance policies, decentralized identity to ensure security in the authentication process, and differential privacy to safeguard sensitive attributes in analytics. A multilayer architecture is created to make sure that there is trusted data ingestion, provenance tracking, compliance, and verifiable data use across the stakeholders. Experimental considered performances indicate better data integrity, traceability, and accountability of access with minimal overhead in analytics performance. The solution is a scalable, tamper-resistant, and privacy-compliant governance model that proposed can be used in large big data systems in the fields of finance, healthcare, and smart cities.
A system design built on blockchain technology presents a fundamental challenge: the inherent transparency of the blockchain conflicts with the growing need for user privacy. This dissertation explores how Zero-Knowledge Proofs (ZKPs) can be strategically combined with blockchain to strike a balance between these competing demands. The dissertation analyzes the challenges of privacy and transparency and provides an overview of solutions across the privacy-transparency solution space, drawing from the author’s original research and the broader academic landscape. On the privacy-centric side, it proposes a privacy-preserving design that utilizes off-chain ZKPs. In contrast, on the transparency-centric side, it presents a transparency-enhancing design that leverages on-chain data to build trust. In the middle, it discusses a taxonomy of hybrid applications whose unique combination of on-chain privacy (via ZKPs) and blockchain transparency reveals both a disruptive potential and significant regulatory challenges.
Stepan Bakhaev, Jos� Carlos Camposano, Annika Wolff, Kari Smolander
This paper analyzes stakeholders’ understanding of an electronic identification (e-ID) system based on artificial intelligence and distributed ledger technology. We address the question "How is the trustworthiness of a novel information system for e-ID influenced by the stakeholders’ understanding of its base technologies?". Our findings are based on a qualitative analysis of a questionnaire and interviews with stakeholders from a system development project focused on e-ID for online public services. We found that current e-ID systems have good usability but lack dialog and feedback mechanisms, whereas technical robustness and data protection are deemed essential attributes of emerging solutions. We identified four profiles of prospective users according to variations of trust in the new e-ID system. These findings suggest the need for greater transparency to facilitate the adoption of nascent digital identity solutions.
Thanassis Tiropanis, George Roussos, Mohammad Bahrani, Mohamed Ragab
The growing demand for data ownership and privacy is reshaping how information is accessed, managed, integrated, and recommended. Building on the inaugural DESERE workshop at The Web Conference 2024, this second edition advances research on Decentralised Search and Recommendation platforms such as Personal Online Datastores (PODs), where users retain control of their data and explicitly manage permissions. As ecosystems decentralise, traditional information retrieval must be revisited while standards for new techniques and system designs are developed to ensure efficient, accurate, and privacy-preserving search. The Second DESERE workshop at CIKM 2025 focuses on infrastructures and retrieval algorithms for user-controlled data. It convenes a cross-disciplinary community spanning data retrieval, management and integration, semantic technologies, recommendation systems, privacy-aware computing, and search efficiency to explore approaches that prioritize user agency, data ownership, and scalable retrieval across PODs and related architectures. Through paper presentations, panels, and interactive sessions, the workshop will highlight challenges, opportunities, and solutions for privacy-preserving IR. These discussions are especially relevant to domains where user-centric design and data stewardship are critical-such as personal finance, education, and high-stakes areas like criminal justice and health.
A TANULMÁNY CÉLJAA tanulmány célja a Bitcoin buborékok kialakulásának vizsgálata, megértése. A buborékok erős hasonlóságot mutatnak a Gartner-féle hype-görbe alakjával, ezért az egyes buborékok és a hype-görbe kapcsolata is ismertetésre kerül. Ezek mellett a Bitcoin-buborékok kialakulását elősegítő tényezők feltárására törekedtünk. ALKALMAZOTT MÓDSZERTAN A Bitcoin árfolyamának historikus adatait elemeztük, melyek alapján a buborékok kirajzolódnak. A buborékok létezésének alátámasztására, illetve a Gartner-féle hype-görbével való azonosítás érdekében kiszámoltuk az egyes buborékok különböző időszakaihoz tartozó kockázatokat, hozamokat is. Illesztettük a hype-görbét a Bitcoin árfolyamának alakulására, illetve a korrelációs kapcsolatot is vizsgáltuk. LEGFONTOSABB EREDMÉNYEK A szórásból számított kockázatok, illetve a relatív szórások is alátámasztották a feltételezést, mely szerint az egyes Bitcoin-buborékok követik a Gartner-féle hype-görbe alakját. A görbék illesztése és a korreláció vizsgálata pedig kimutatta, hogy van kapcsolat a hype és az árfolyam alakulása között. A szabályozás szerepe kritikus lehet a kriptovaluták árfolyamának alakulásában, és a különböző országokban bevezetett szabályozó intézkedések jelentős hatást gyakorolhatnak a befektetői bizalomra és az árfolyamokra. A Bitcoin-bányászat felezése szintén fontos esemény, amely befolyásolhatja a kínálatot és keresletet és ennek megfelelően az árfolyamokat is. Az utánzó magatartás, vagyis a befektetők tendenciája arra, hogy mások viselkedését másolják, szintén jelentős tényező a buborékok kialakulásában. Végül az intézményi szereplők stabilizáló hatását ismertettük. GYAKORLATI JAVASLATOK A tanulmányból kiderül, hogy a fent említett tényezők igen nagy befolyást gyakorolnak a Bitcoin árfolyamának alakulására, melyek közül a bányászatért járó jutalmak felezése a leginkább szembetűnő, illetve számítással alátámasztható. Az új szabályozások megjelenésével nem tudunk számolni, viszont a felezéssel járó árfolyamváltozással igen, melynek fő indikátora az utánzó magatartás, hiszen a befektetők hozamaik maximalizálására törekednek. Ezek alapján a tanulmány rávilágít, hogy egy igen kockázatos befektetési formáról van szó, melynek előrejelzése igen nehéz feladat.
Blockchain technology has revolutionized digital transactions by offering decentralization, transparency, and immutability. However, its inherent transparency often conflicts with the need for user privacy and anonymity, raising significant concerns regarding accountability, especially in regulatory and legal contexts. This study explores the delicate balance between anonymity and accountability in blockchain systems, proposing a framework that ensures both privacy and compliance with regulatory requirements. The research addresses key challenges in balancing these two aspects, evaluates the effectiveness of existing privacy-preserving technologies such as zero-knowledge proofs and ring signatures, and introduces the Privacy-Accountability Balanced Blockchain (PABB) Framework. This framework integrates Selective De-Anonymization, Self-Sovereign Identity (SSI), and the Adaptive Privacy-Accountability Control (APAC) Algorithm to dynamically adjust privacy levels based on regulatory conditions. Through theoretical analysis, mathematical modeling, and empirical validation, preserving privacy for 92% of transactions while enabling selective de-anonymization in high-risk cases, the study demonstrates that the APAC Algorithm effectively balances privacy and compliance needs. The findings suggest that privacy-conscious blockchain systems can coexist with accountability mechanisms, paving the way for ethical and legally sound blockchain applications. The study concludes that the PABB Framework offers a practical and scalable approach to achieving this balance, fostering trust among users and regulators alike.
Iván Abellán Álvarez, Pol Hölzmer, Johannes Sedlmeir
Digital identity wallets promise significant advancements in digital identity management by offering users a high degree of convenience, security, and control over their data disclosure. However, there is also criticism regarding their privacy guarantees, especially when used in regulated use cases that require high levels of assurance on the correctness and binding of a legal identity. In this paper, we present a comprehensive privacy model and analysis of one of the most prominent digital wallets – the European Digital Identity Wallet (EUDIW) – as specified by the Architecture and Reference Framework (ARF) and the eIDAS 2.0 regulation. We employ a suite of qualitative privacy risk assessment methods to systematically map and evaluate information flows in three key use cases. Our analysis identifies multiple privacy risks – including linkability, identifiability, and excessive attribute data disclosure – and reveals that although the ARF is designed to comply with privacy-by-design principles, inherent design choices, such as the reliance on SD-JWT and mDOC data formats, as well as the concept of a Wallet Unit Attestation (WUA), retain risks to user privacy. Building on our findings, we then highlight how advanced Privacy-Enhancing Technologies (PETs), such as (general-purpose) Zero-Knowledge Proofs (ZKPs), can reduce or mitigate some of these risks.
Cross chain interoperability in blockchain systems exposes a fundamental tension between user privacy and regulatory accountability. Existing solutions enforce an all or nothing choice between full anonymity and mandatory identity disclosure, which limits adoption in regulated financial settings. We present VeilAudit, a cross chain auditing framework that introduces Auditor Only Linkability, which allows auditors to link transaction behaviors that originate from the same anonymous entity without learning its identity. VeilAudit achieves this with a user generated Linkable Audit Tag that embeds a zero knowledge proof to attest to its validity without exposing the user master wallet address, and with a special ciphertext that only designated auditors can test for linkage. To balance privacy and compliance, VeilAudit also supports threshold gated identity revelation under due process. VeilAudit further provides a mechanism for building reputation in pseudonymous environments, which enables applications such as cross chain credit scoring based on verifiable behavioral history. We formalize the security guarantees and develop a prototype that spans multiple EVM chains. Our evaluation shows that the framework is practical for today multichain environments.
The rise of centralised social networks has consolidated power among a few major technology companies, raising critical concerns about privacy, censorship, and transparency. In response, decentralised alternatives, including Web3 platforms like Decentralised Social (DeSo) and Fediverse platforms such as Mastodon, have gained increasing attention. While prior research has explored individual aspects of decentralised networks, comparisons between Fediverse and Web3 platforms remain limited, and the unique dynamics of Web3 networks like DeSo are not well understood. This study provides the first in-depth study of DeSo, characterising user behaviour, discourse, and economic activities, and compares these with Mastodon and memo.cash . We collected over 3.1M posts from 13K users on DeSo and Mastodon, along with 11M DeSo on-chain transactions via public APIs. Our analysis reveals that while DeSo and Mastodon share similarities in passive content engagement, they differ in their use of URLs, hashtags, and community focus. DeSo is primarily oriented around Decentralised Finance (DeFi) topics, whereas Mastodon hosts diverse discussions with an emphasis on news and politics. Despite DeSo’s decentralised social graph, its transaction graph remains centralised, underscoring the need for further decentralisation in Web3 platforms. Additionally, while wealth inequality exists on DeSo, low transaction fees promote user participation irrespective of financial status. These findings provide new insights into the evolving landscape of decentralised social networks and highlight critical areas for future research and platform development.
S. Vishnu Murthy, Panduranga Vital Terlapu, Rakesh Salakapuri, R. S. S. Devi Ganesh · 6 authors
Web3 technology is changing social media. It helps solve problems like data ownership and censorship. This research paper presents a new decentralized social media system. It uses blockchain to focus on user privacy and trust. The study describes a Web3 platform. It uses Next.js for the front end. Solidity is used for smart contracts. Hardhat is for local deployment. IPFS provides decentralized storage. Web3.js helps with blockchain interactions. The platform allows user registration, post creation, liking, commenting, and sharing. It keeps user data secure with blockchain's immutability and encryption. The authors look at ways to make money and manage the ecosystem and also focus on making the platform easy to use. Our research shows that the platform gives users more control, keeps their information private, and prevents censorship. These features solve some problems with centralized systems. However, the authors also discuss challenges like scalability and getting users to adopt the platform and suggest future research to address these issues. This work highlights how Web3 can change social media by fostering a secure, transparent, and user-centric digital community.
This analysis focuses on password-free Electronic IDentity (eID) solutions for eGovernment services under the federated identity management framework Electronic IDentification, Authentication and trust Services (eIDAS). The scope of eID systems is centred on their alignment of the associated technical, legal, and procedural challenges. Through an analysis of five password-free eID solutions—Fast IDentity Online 2 (FIDO2) tokens, Secure Identity Across Borders Linked (STORK), distributed ledgers, mobile authenticators, and eID cards—the study evaluates their compliance with eIDAS standards and identifies key gaps in their design and implementation. While certain solutions, such as FIDO2 tokens and mobile authenticators, demonstrate full compliance, others, including STORK and distributed ledger-based systems, face challenges in achieving interoperability, privacy, and regulatory alignment. This research contributes to the discourse on digital identity management by offering insights into current limitations and recommending pathways for advancing the design, standardization, and deployment of eID systems. These results support the larger objectives of the European digital single market by highlighting the significance of regulations, innovations, and user-oriented design in creating password-free eID systems.
Eugenio Felipe Merlano, Glenn Parry, Abubakar-Sadiq Shehu, Steve Schneider
Global labour markets face significant disruption from the rapid advance of artificial intelligence (AI) and automation. Digital or gig economy workers, like freelancers and online independent contractors, are more exposed to the disruptive impacts of technological changes due to their flexible working conditions, which often come with flexible contracts, less robust legal agreements and other unstable working conditions. This study explores how gig economy workers benefit from alternative privacy-enhancing decentralised reputation systems and technologies that enable them to manage information like education, certifications, credentials, and professional experience, both by collecting and sharing information with employers. We propose a blockchain framework comprising three components: (1) Self-sovereign identity (SSI) enabling cryptographically secured, portable control over credentials via decentralised storage; (2) Immutable reputation registries leveraging consensus mechanisms to secure tamper-proof work histories; and (3) Privacy-preserving signalling using zero-knowledge proofs (ZKPs) to let workers selectively disclose reputation metrics without revealing sensitive details. We combine Signalling Theory (ST) and the Unified Theory of Acceptance and Use of Technology (UTAUT) to empirically assess real workers’ intentions to use this type of decentralised reputation system. Our framework enhances transparency, worker autonomy, and privacy in the digital economy.
The rapid progress of large-scale models, including foundational and generative, brings to the forefront the tension between data-driven innovation and core privacy concerns. Such contracts as the GDPR and the undue privacy threats of data aggregation make centralized training approaches less desirable. To analyze the data’s distributed characteristics and their application to FLO, we investigate the role of federation analytics in a plausible paradigm that shunts data. In this paper, we present a new federated learning (FL) framework enhanced with cutting-edge privacy technologies (PET) such as Differential privacy for user-level formal guarantees of confidentiality, and strengthened secure Multi-Party Computation (SMPC), which guards the model updates. This paper studies more recent approaches to resolving the principal challenges of FL: statistical heterogeneity, communication bottlenecks, and vulnerability to adversarial attacks. We greatly appreciate what this new method portends, especially for training large language models (LLMs) and the more delicate areas of healthcare and finance. By evaluating certain existing limitations, such as the complexities of federated fine- tuning and model fairness, it is clear that an architecture with exemplary performance in FL serves as a model for scalable, secure, and privacy cop.
Social media platforms rely heavily on user interaction data to personalize content and advertisements, raising concerns regarding user privacy and data misuse. Although regulations such as the General Data Protection Regulation (GDPR) aim to address these concerns, enforcement remains under the control of the platforms themselves. To address these issues, this paper proposes a privacy-preserving recommender system that minimizes personal preference data exposure while maintaining the potential for equivalent personalization accuracy (including for advertisements) through local data processing, which could access the same amount or more of pure user data than server-side models. This system integrates a lightweight client-based machine learning model to infer user preferences locally, combined with Merkle tree-based Zero-Knowledge Proof (ZKP) scheme to anonymously authenticate user requests. The authors develop a working web app prototype and evaluate performance across a range of user devices. Results show minimal latency for the client-based model (under 5 milliseconds on most devices) and diverse proof generation times, ranging from 2.6 seconds to over 18 seconds, depending on hardware capability. Server-side verification remains consistent and fast under 250 milliseconds. Although proof generation latency remains a bottleneck for real-time applications, optimization strategies such as proof-caching, cross-application preferences synchronization, and native implementation provides a promising path toward privacy-preserving personalization in social media systems.
This paper proposes a hybrid access control system that integrates the usability of Web2 authentication (Google Login) with the transparency and integrity of Web3 technologies (blockchain and smart contracts). The system enables users to authenticate via their existing Google accounts without managing crypto wallets or private keys, while access permissions are securely recorded on-chain through smart contracts. To ensure cryptographic key security without relying on a centralized authority, the design incorporates Distributed Key Management (DKM). This approach addresses the challenge of balancing usability with verifiability in data access control. By embedding decentralized guarantees within a centralized web service interface, the system enables practical and transparent access control. The proposed architecture demonstrates the potential for a general-purpose, auditable module that facilitates user-consented data sharing with third parties.
Although the P2P power transactions using the multiagent deep deterministic policy gradient (MADDPG) algorithm has been extensively studied, there are still challenges in privacy protection and training incentives. Furthermore, the stability and efficiency of the strategy decreases when dealing with nonindependent identically distribution (Non-IID) data from heterogeneous prosumers. Therefore, this article proposes a blockchain-enabled asynchronous federated learning-MADDPG (BEAFL-MADDPG) framework designed to enhance the training efficiency of heterogeneous prosumers while safeguarding data privacy. The framework includes a novel P2P energy trading model that facilitates energy trading amidst incomplete information while ensuring privacy assurances. In addition, a BEAFL-MADDPG algorithm is proposed, which accelerates training processes and enables parallel computation among agents. This algorithm enhances the efficiency of algorithm and empowers the training of diverse prosumers. Furthermore, a blockchain-enabled training mechanism and prosumer incentive scheme are proposed that not only encourage prosumer engagement in training but also ensure traceable transactions without the need for trust among participants. These mechanisms promote transparency and integrity, fostering a collaborative and secure environment for energy trading. Simulation results demonstrate that the framework achieves peak load reduction through optimized P2P trading, maintains computation efficiency across discount rates, and ensures secure transactions via blockchain-based incentives. These practical benefits support scalable and sustainable community microgrid operations.
Decentralized technologies such as blockchain and federated learning have emerged as promising solutions to improve privacy, transparency, and security in distributed environments. This paper aims to provide updated research directions concerning the unresolved issues of linkability and traceability in decentralized technology transactions. A systematic review was conducted using Scopus and Web of Science databases, covering studies published between 2017 and 2023. A total of 313 papers were initially identified, screened, and filtered based on inclusion and exclusion criteria, resulting in 29 relevant studies. The analysis indicates that most prior works focused on privacy preservation and incentive mechanisms but neglected linkability and traceability concerns. Several approaches, including ring signatures, CryptoNote protocols, and smart contract-based incentives, were identified as potential solutions. While blockchain–federated learning integration enhances privacy, unresolved traceability and linkability issues still pose significant risks in sensitive domains such as healthcare and finance. Future work should prioritize addressing these issues to ensure secure, anonymous, and scalable decentralized transactions.