Abstract Zero knowledge succinct non-interactive arguments of knowledge protocol (zk-SNARK) is an application oriented variant of zero knowledge proof, which enables a prover to convince a verifier that a statement is true, without revealing any other information beyond the correctness of the statement itself. Due to its powerful capabilities and high efficiency, it has been widely deployed in various blockchain based applications to provide privacy and scalability. While these applications place high demands on small proof size, fast verification and decentralization, currently available zk-SNARK with the shortest proof size and the fastest verification speed is in the common reference string (CRS) model, that is they require the trusted setup. After the pioneering results proposed by Bellare et al. in ASIACRYPT 2016, there have been lots of efforts to construct zk-SNARKs that satisfy subversion zero knowledge (S-ZK) and standard soundness from the zk-SNARK in the CRS model. These constructions could be regarded secure in the bare public key (BPK) model because that the equivalence between S-ZK in the CRS model, and uniform non-black-box zero knowledge in the BPK model has been proved by Abdolmaleki et al. in PKC 2020. Thus, compared to the CRS model, the BPK model better characterizes decentralized blockchain based application such as cryptocurrencies and anonymous credentials. In this study, by leveraging the power of random oracle (RO) model, we proposed the first publicly verifiable non-uniform ZK zk-SNARK scheme in the BPK model maintaining comparable efficiency with its conventional counterpart, which can also be compatible with the well-known transformation proposed by Bitansky et al. in TCC 2013 to obtain an efficient designated-verifier zk-SNARK. We achieve this goal by only adding a constant number of elements into the CRS, and using an unconventional but natural method to transform Grothâs zk-SNARK in EUROCRYPT 2016. In addition, we propose a new speed-up technique that provides a trade-off. Specifically, if a logarithmic number of elements are added into the CRS, according to different circuits, the CRS verification time in our construction could be approximately 9â23% shorter than that in the conventional counterpart.
The widespread adoption of cryptocurrencies has transformed the financial landscape by enabling swift, decentralised transactions. However, the pseudonymous nature of digital currencies has also fuelled illicit activities, such as money laundering. Criminals perform money laundering to access illicitly acquired funds without detection and convert illegally obtained assets into untraceable commodities, seamlessly integrated into the financial system. Although new regulatory measures have been introduced, illicit actors continue to exploit various methods, from peer-to-peer exchanges to cryptocurrency mixing services, to obscure the origins of illegal funds. This study presents a parametric analysis of these methods, examining dimensions such as duration, number of actors, contextual requirements, operational difficulty, traceability, and costs across each stage of the money laundering process: placement, layering, and integration. The analysis indicates that, while more sophisticated techniques may provide a higher degree of anonymity, they simultaneously require specialised technical expertise and meticulous planning. Consequently, there is a trade-off between the level of privacy attainable and the operational complexity inherent to each method. By systematically comparing these strategies, this analysis aims to contribute to a deeper understanding of cryptocurrency-based money laundering techniques, providing insight for more effective prevention and mitigation measures for both regulatory authorities and the financial sector.
With the increasing maturity of blockchain technology, its characteristics such as decentralization, data immutability, and consensus mechanisms can effectively address issues in supply chain finance, including high risk control costs, difficulties in credit endorsement for small and medium-sized enterprises, and cumbersome operational processes. By synthesizing research on the integration of blockchain technology into supply chain financial services and analyzing a case study of JD.comâs application of blockchain technology in supply chain finance ABS business, this paper proposes future development prospects for âblockchain technology + financial servicesâ. The aim is to provide decision-making references for the modern financial services industry to expand operations, improve service performance, and reduce financial risks.
Federated learning (FL), which allows collaborative machine learning without requiring the centralisation of sensitive data, has become a game-changing concept for private and safe data analysis in decentralised networks. FL enables edge devices or local nodes, such as smartphones, IoT devices, or healthcare facilities, to learn shared models remotely and send only model changes to a central server, in contrast to traditional methods that call for raw data aggregation. This framework lowers communication overhead, mitigates regulatory problems, and greatly improves data privacy and security. FL provides a workable and scalable way to create superior machine learning models in decentralised networks, where data is naturally dispersed and frequently subject to stringent privacy laws. Nevertheless, there are still issues to be resolved, such as managing non-IID data, making sure that systems are resilient to hostile attacks, and preserving effective communication. To further improve FL's privacy-preserving capabilities, recent developments like homomorphic encryption, safe multiparty computation, and differential privacy are being incorporated. This study examines the fundamentals of federated learning, goes over important methods for improving its security and privacy, and talks about how it may be used in a variety of industries, including as healthcare, finance, and smart cities. FL is one of the most important steps to safe and ethical AI in decentralized environments because it allows the collaboration of intelligence and preserves data ownership.
Traditional zero trust architectures (ZTA) rely on centralized policy engines and mutable audit logs, creating single points of failure and limiting forensic integrity. We present a novel blockchain-secured zero trust network architecture that integrates distributed ledger technology, machine learning-based threat detection, and zero-knowledge proof authentication to eliminate the se limitations. Our five-layer framework comprises a user access layer, a zero-trust core (policy engine, administrator, and enforcement points), a blockchain security layer (smart con- tracts, consensus engine, and audit trail), a decentralized identity layer (W3CDIDs and zero-knowledge proof authentication), and protected network resources. Access requests are validated via zero-knowledge proofs; trust scores are computed dynamically using Random Forest classifiers achieving 96.3% accuracy; policy decisions are executed through Practical Byzantine Fault Tolerance (PBFT) consensus; and all security events are recorded immutably on Hyperledger Fabric. Smart contracts create automated incident response, which isolates malicious parties in less than 500 ms without human interference. Experiments on a 50-node testbed during simulated attacks show an authentication latency of < 100 ms, a throughput of > 1,000transactions per second (TPS), a threat-detection accuracy of > 95%, and a false-positive rate of < 5%. Our solution reduces the latency by 30% and the operating overhead by 60% and offers 100% integrity of the audit trail compared to traditional zero-trust implementations. This publication represents the first end-to-end integration of blockchain and zero-trust systems, providing a privacy-preserving, scalable, and resilient security architecture for enterprise environments and next-generation networks.
The increasing use of decentralized finance (DeFi) accelerates the demand for trustless, secure mechanisms for crosschain token exchange. This paper outlines a complete model for atomic token swaps based on the Hashed Timelock Contract (HTLC) scheme, allowing for intermediary-free token exchanges across disparate blockchain systems. The system makes use of the local blockchain simulation framework, Ganache, to design and test cross-chain interactions in a sandbox environment. To improve the decision-making capabilities for users, a real-time cryptocurrency price forecasting subsystem is added which utilizes machine learning models to analyze and predict the market and its volatility. Additionally, the system harnesses Generative AI capabilities through prompt engineering to tailor investment advice for individual users by analyzing the market, their preferred risk level, expected returns, and provide investment strategies aligned with users' preferences. Apart from sophisticated trading algorithms, the solution also offers a simple dashboard for market price monitoring and performs rapid token swaps at the user's command. Smart contracts are implemented using Solidity, token and price feeds are ports to Web3.js, predictive analytics is done in Python, while the frontend and backend are structured in Next.js alongside Node.js. System testing validates hypotheses on the provision of secure cross-chain swaps within one transaction without compromising.
Health system resilience (HSR) is essential to sustaining equitable essential functions under acute and chronic stressors in decentralized systems. We developed and validated a Brazil-tailored HSR framework that distinguishes steady-state performance from resilience-specific capacities and assigns responsibilities across federal, state, regional, and municipal levels. Using a three-phase qualitative deductive-inductive approach with 48 international and national experts, we identified nine dimensions, 18 subdimensions, and 65 indicators that prioritise governance coherence, surge workforce strategies, emergency regulation, real-time monitoring, and access to critical technologies. The framework clarifies boundaries between general health system performance and adaptive, absorptive, and transformative functions, and specifies how managers can apply it in practice through structured scoping, mapping, scoring, prioritisation, planning, and monitoring steps. Although designed for Brazil's Unified Health System (SUS), the development logic generalises to other decentralised contexts with appropriate re-allocation of responsibilities and calibration to national financing rules. This policy-facing tool supports actionable resilience strengthening in complex, multi-level systems.
This study explores the automation of smart contract generation in construction, leveraging Large Language Models (LLMs) like OpenAIâs ChatGPT. Traditional construction contracts often suffer from delays and disputes, particularly in payment processes. The paper investigates automating the transformation of these traditional contracts into smart contracts, which promise enhanced efficiency and transparency. By conducting an extensive literature review and analyzing various contract types, the study identifies critical elements that are translatable into smart contracts. The experimental phase demonstrates the effective use of the ChatGPT API in extracting necessary contract information for conversion. This approach aims to streamline contract management, reduce disputes, and improve overall project execution. The potential of LLMs in this context is significant, indicating a shift towards more automated, reliable, and transparent contract management in the construction industry.
Blockchain Technology Applications and Security
Artificial Intelligence in Healthcare and Education
Tanim Hasan Ovi, Ifftekher Hossain Mrida, Fatema Tuj Tarannom Esty, Safayet Ahmed ¡ 5 authors
Regular crowdfunding platforms are excited by the mystery, centralization, and abnormally high rates, and, in turn, the search for less traditional ways for this purpose. In this paper, we present the work of designing and evaluating a donation system to leverage the Ethereum-supported blockchain along with emerging web tools. The objective is a transparent, auditable system. Users can launch fundraisers, donate Ethereum, and monitor their progress. Actors are struggling to keep up. The core mechanical pieces are driven by smart contracts written in Ethereumâs Solidity. These contracts define the driving terms of the agreement, including funding amounts, degree of wet service access, and agreed-upon payment plan, cash call, and payback. The front end is integrated with React.js, and Ethers.js is an easy-to-use client library that uses blockchain to communicate with MetaMask. Functionality was tested with starting drives, donations, and withdrawals using development environments of Hardhat, Ganache, and Remix IDE. Avg. Transaction processing costs were in the ballpark of 200,000 Gas units, which was acceptable for Layer-1 Ethereum networks. The system is designed with security features, implementing access control, timestamp verification, and reentrancy protection as a step toward addressing common smart contract vulnerabilities. We will soon integrate DAO governance, the ability to convert fiat to crypto, phone support, and enhanced Layer- 2 scaling.
Existing agent communication frameworks face critical limitations in providing verifiable audit trails without compromising the privacy and confidentiality of agent interactions. The protection of agent communication privacy while ensuring auditability emerges as a fundamental challenge for applications requiring accurate billing, compliance verification, and accountability in regulated environments. We introduce a framework for auditing agent communications that keeps messages private while still checking they follow expected rules. It pairs zero-knowledge proofs with the existing Model Context Protocol (MCP) so messages can be verified without revealing their contents. The approach runs in lightweight networks, stays compatible with standard MCP exchanges, and adds asynchronous audit verification to confirm format and general message types without exposing specifics. The framework enables mutual audits between agents: one side can check communication content and quality while the other verifies usage metrics, all without revealing sensitive information. We formalize security goals and show that zk-MCP provides data authenticity and communication privacy, achieving efficient verification with negligible latency overhead. We fully implement the framework, including Circom-based zero-knowledge proof generation and an audit protocol integrated with MCP's bidirectional channel, and, to our knowledge, this is the first privacy-preserving audit system for agent communications that offers verifiable mutual auditing without exposing message content or compromising agent privacy.
Abstract The demand for secure, effective, and scalable payment systems has increased due to the rise of Internet-based financial transactions. Through traditional techniques, such as Proof of Work (PoW), conventional financial systems often encounter issues with high transaction latency, concerns about fraud, and excessive energy consumption. These problems are widespread in traditional systems. This research proposes a Secure Hybrid Consensus Protocol (SHCP) with the intention of enhancing the effectiveness, velocity, and reliability of financial transactions based on Blockchain technology. The Proof of Stake (PoS) protocol is combined with the Byzantine Fault Tolerance (BFT) protocol by SHCP. Through the utilization of adaptive prioritization, Bayesian inference, and anomaly recognition, SHCP can incorporate the most advanced fraud detection technology. The SHCP framework uses anomaly recognition to identify fraud with 92% accuracy, 38% faster validation, and 43% less energy than PoW-based systems. The system delivers ~ 7,000 TPS (Transactions Per Second) and a 27% increase in decision risk prediction stability. Anomaly scoring, Bayesian inference, and adaptive prioritization aid fraud detection. These advances enable safe, rapid, and affordable financial transactions, creating a sustainable Blockchain-based payment ecosystem.
Ethereum has become a significant trading platform for financial activities such as Dapps, ICOs, and DeFi. However, it has also become a hub for criminal activities such as fraud, money laundering, and illicit fundraising. The construction of fraud detection models employing machine learning techniques is currently a mainstream research direction. Nevertheless, existing studies face significant challenges, including class imbalance in data samples and a lack of model interpretability. In this content, this work proposes a novel explainable model for Ethereum illicit account detection, ETHIAD (Ethereum Illicit Account Detection). Firstly, we pre-process the dataset by ADASYN oversampling and Lasso feature selection, etc., to more efficiently achieve feature modeling of transaction structures. Then, the ETHIAD model is trained using the XGboost algorithm, with an accuracy, precision, recall, F1 score, and AUC value of 99.70%, 99.51%, 99.02%, 99.26%, and 99.45%, respectively, the model outperforms the existing SOTA model by 0.05%-1.1%. Finally, we introduce SHAP framework to analyze the key influencing factors of illicit accounts from multiple perspectives, and the conclusions strongly enhance the explainability of the model.
Blockchain is a revolutionary technology now a days. It has opened various platforms for research too. Blockchain is decentralized distributed network system with no central authorization. Because of its inherent features it has been used in various applications. Features are immutability, anonymity, transparency, decentralized etc. This study gives the basic idea about blockchain technology. The study also investigates consensus mechanisms to add transactions in the network. This study gives an idea about what the various frameworks are and how consensus protocols work under various frameworks. Bitcoin, Ethereum are the common frameworks used in blockchain technology. Proof of Work (PoF) and Proof of Stake (PoS) are the commonly used consensus types in blockchain. The analysis includes considerations about blockchain process, types of blockchain, layered architecture of blockchain, consensus protocols, blockchain framework, applications of blockchain. This study emphasizes the need for better scalability, security and integrity options. In future, Blockchain technology has the potential to integrate with many technologies like Artificial Intelligence (AI), Cloud Computing, Internet of Things (IoT) etc.
High-value payment transactions (HVTs) face heightened exposure to money laundering risks due to their large monetary volumes, cross-jurisdictional nature, and the increasing complexity of financial networks. Traditional Anti-Money Laundering (AML) procedures rely heavily on sharing customer identities, transactional attributes, and risk-model outputs across institutions and regulatorsâcreating substantial privacy, security, and data-handling risks. Zero-Knowledge Proofs (ZKPs) offer a transformative alternative by enabling financial institutions to prove compliance with AML requirements without revealing the underlying sensitive information. This paper examines the design and application of ZKP-based compliance frameworks for HVT ecosystems, detailing how AML checksâincluding KYC verification, sanctions screening, transaction-amount threshold validation, behavioral-risk scoring, and source-of-funds assessmentâcan be cryptographically attested through privacy-preserving proofs. We propose a hybrid architecture that combines off-chain AML computation with an on-chain ZKP verification and audit layer supported by secure regulatory nodes. Through structured workflows and proof types such as range proofs, list membership proofs, and rule-compliance circuits, the model ensures regulatory oversight while maintaining strict confidentiality. The study also evaluates the performance implications of ZKP systems in high-volume transaction environments and addresses security, interoperability, and oracle-reliability concerns. Ultimately, ZKP-enabled AML frameworks demonstrate significant potential to enhance compliance efficiency, reduce data-exposure risk, and strengthen trust across global payment networks. The paper concludes by outlining future research opportunities, including AI-driven AML circuits, cross-border ZKP interoperability standards, and integration with decentralized identity solutions.
ABSTRACT In the contemporary digital landscape, high-profile individuals including celebrities, executives, political leaders, and public officials face unprecedented threats from online impersonation, sophisticated misinformation campaigns, AI-generated deepfakes, and fraudulent social media profiles. The convergence of generative artificial intelligence technologies and social media platforms has dramatically expanded the attack surface, enabling malicious actors to create synthetic identities, manipulate multimedia content, and spread false narratives with alarming ease and speed. Existing security solutions remain fragmented, requiring extensive manual intervention and lacking the capability for real-time monitoring and automated threat response, thereby leaving critical gaps in digital protection for vulnerable public figures. This research paper presents GuardIQ, an integrated, fully automated, end-to-end VIP Threat Detection and Monitoring Platform that combines post-quantum cryptography, multi-factor biometric authentication, artificial intelligence-powered threat detection, and blockchain-based evidence preservation. The platform architecture is built upon seven core pillars: quantum-secure biometric registration utilizing Kyber Key Encapsulation Mechanism (KEM), real-time threat detection engine monitoring multiple social media platforms, AI-powered content verification distinguishing authentic media from AI-generated deepfakes, automated fake profile detection comparing discovered accounts against registered handles, live analyzer for instant authenticity verification, immutable evidence collection using Web3 technologies, and unified dashboard providing comprehensive threat intelligence visualization. GuardIQ employs CRYSTALS-Kyber post-quantum cryptographic algorithms (Kyber512 for lightweight mobile endpoints and Kyber768/1024 for enterprise deployments) combined with AES-256-GCM symmetric encryption to ensure quantum-resistant data protection. The biometric registration module captures facial recognition data, voice patterns, gesture signatures, and official social media handles, all protected through quantum-safe encryption. Large Language Models (LLMs) integrated within the threat detection engine perform real-time classification of suspicious content, achieving 92-97% accuracy in identifying impersonation attempts, misinformation campaigns, and image misuse across platforms including Twitter, Facebook, Instagram, and LinkedIn. The AI content detection module leverages advanced deep learning architectures including Convolutional Neural Networks (CNNs) for image analysis, Recurrent Neural Networks (RNNs) for sequential pattern detection, and transformer-based models for multimedia authenticity verification. Experimental results demonstrate the system's capability to distinguish AI-generated content from authentic material with confidence scores exceeding 94%, providing early detection of deepfakes and synthetic media targeting VIP credibility. The fake profile detection algorithm analyzes multiple parameters including account creation timestamps, username patterns, biographical information, follower-to-following ratios, engagement metrics, and posting behavior patterns to identify fraudulent accounts with 89% precision. Evidence collection is facilitated through Web3-based blockchain infrastructure ensuring tamper-proof, immutable storage of all flagged incidents, suspicious posts, and detected impersonations. This cryptographically verifiable evidence chain supports legal proceedings and investigative actions by providing irrefutable proof of malicious activities. The unified dashboard aggregates threat intelligence from all modules, presenting real-time alerts, authenticity scores, risk assessments, and recommended remediation actions through intuitive visualizations requiring minimal manual oversight. Performance evaluation reveals that post-quantum TLS handshakes introduce only 5-10 milliseconds additional latency compared to classical TLS implementations, demonstrating practical feasibility for production deployment. The automated threat detection pipeline reduces incident response time by 72% compared to manual monitoring approaches, while the quantum-resistant encryption framework ensures long-term security against emerging quantum computing threats. System architecture supports horizontal scalability through microservices deployment, containerization using Docker and Kubernetes orchestration, and cloud-native infrastructure compatible with AWS, Azure, and Google Cloud Platform. This research addresses the urgent need for comprehensive digital protection solutions in an era where AI-generated content, quantum computing capabilities, and sophisticated social engineering attacks converge to create unprecedented risks for public figures. GuardIQ represents a paradigm shift from reactive security measures to proactive, automated threat intelligence platforms capable of defending high-profile individuals against modern digital adversaries while maintaining usability, scalability, and legal compliance. Keywords : VIP Protection, Post-Quantum Cryptography, Kyber KEM, Deepfake Detection, AI Content Verification, Biometric Authentication, Threat Intelligence, Social Media Monitoring, Blockchain Evidence, Web3 Security, Impersonation Detection, Misinformation Prevention, Large Language Models, Zero- Trust Architecture, Quantum-Safe Encryption, Identity Verification, Automated Security Response, Digital Reputation Management
Ankenbrand, Thomas, Bieri, Denis, Ferrazzini, Stefano, Hoehener, Johannes
Tokenised money encompasses a broad range of digital monetary instruments issued on distributed ledger technology, including Central Bank Digital Currencys (CBDCs), deposit tokens, stablecoins, and decentralised protocol-based designs. Despite their shared monetary function, these instruments differ markedly in issuer structure, collateralisation, stability mechanisms, governance, and technological embedding, creating conceptual ambiguity. This paper proposes a concise taxonomy spanning twelve key design dimensions, offering a systematic framework for comparing heterogeneous forms of tokenised money. The taxonomy clarifies how different design choices shape monetary properties, risks, and policy implications, supporting clearer analysis and dialogue across academia, industry, and regulation.
Non-Fungible Tokens (NFTs) have transformed digital ownership, offering unique representations of assets such as art, collectibles, and virtual property. However, pricing NFTs remains a complex and underexplored issue. This study addresses two core questions: what determines NFT prices? And how are prices set in NFT markets? We conduct a comprehensive literature review and market analysis to identify both endogenous and exogenous price determinants. Trait rarity emerges as the most influential intrinsic factor, while cryptocurrency value stands out as a major external influence, albeit with ambiguous effects. Other factors include visual aesthetics, scarcity, utility in games, social media engagement, and broader market sentiment. As to pricing mechanisms, aside from fixed pricing (which is accepted in all marketplaces), NFT marketplaces primarily utilise auctions for art pieces and collectiblesâ especially English and Dutch formatsâwhich are effective at capturing the buyerâs willingness-to-pay.
Abstract Decentralized finance (DeFi) is rapidly transforming financial systems, yet its environmental, social, and economic sustainability implications remain underexplored. To address this gap, we conducted a structured review of peer-reviewed literature published between 2022 and 2025, drawing on 239 records retrieved from Scopus and Web of Science and screened through the PRISMA 2020 protocol in Covidence. The review combined bibliometric analysis, thematic mapping, and a systematic review to synthesize patterns, clusters, and critical insights. Bibliometric results show a sharp post-2023 rise in outputs, with China leading in publication volume and Switzerland achieving the highest citation impact, although collaboration networks remain fragmented and weakly connected. Thematic analysis reveals three dominant clusters: blockchain-driven financial innovation, AI and fintech applications for sustainability, and green economy transitions, highlighting DeFiâs dual role as a driver of transparency and inclusion but also a source of energy inefficiency and systemic risk. The systematic review further identifies regulatory gaps, particularly around Maximal Extractable Value (MEV), and emphasizes the need for energy-efficient consensus mechanisms, standardized ESG metrics for tokenized assets, and inclusive platform designs to bridge digital divides. By aligning DeFiâs disruptive potential with sustainability objectives, the study proposes hybrid governance models and interdisciplinary collaboration to foster a resilient, equitable, and low-carbon financial ecosystem, underscoring the urgency of balancing technological innovation with planetary boundaries to realize DeFiâs promise as a catalyst for sustainable development.
High-frequency trading, in both traditional and decentralized markets, induces latency races and redundant order flow as traders spend resources to win time-sensitive opportunities. We show that auctioning artificial time priority can redirect resources away from wasteful speed races toward auction payments. While such waste is difficult to measure in traditional markets, blockchain transactions provide transparent records of these competitive costs through observable duplicate submissions. We study the introduction of Timeboost, a time-priority auction mechanism on Arbitrum, a blockchain that batches transactions before settlement on Ethereum, as a natural experiment. We find that redundant transactions decrease and platform revenue increases relative to comparable networks, consistent with our theoretical predictions.
The growing use of digital payments still depends on centralized intermediaries which raises issues of trust, transaction costs, delays, and vulnerability of the system as a whole. This paper describes the development of a mobile app to implement decentralized payments through blockchain. The proposed system uses a permissioned distributed ledger and smart contracts to facilitate secure, peer-to-peer, and highly independent transactions. This work explain the system's architecture and design reasoning as well as assess the focus on security and performance with respect to transaction latency, scalability, and costs. Data from prototype implementation demonstrates mobile app payments with the proposed solution and a considerable reduction in costs in comparison to traditional payments. This mobile payment solution demonstrated the system to meet transaction latency of mobile payments within the targeted range. This paper identifies issues and obstacles within the domain of decentralized mobile payments such as scalability, regulation, and user acceptance and proposes possible refinements and research opportunities in DeFi. This work enhances the set of blockchain-powered mobile payment systems, adding to the knowledge on the possible use of decentralized systems in the finances of the economy.
Rana Hassam Ahmed, Muhammad Zeeshan, Unais Ali, Muhammad Sarfraz Khan ¡ 7 authors
Smart contracts power decentralised applications, but once deployed, their flaws stay exploitable. Existing fuzzers such as ConFuzzius, Smartian, and VULSEYE use hybrid static and dynamic analysis but depend on fixed heuristics and lack adaptive learning. AI-FUZZ is an adaptive machine learning guided fuzzing framework that pairs deep reinforcement learning with stateful graybox fuzzing. It learns from execution traces to improve input generation, focus on high-risk contract states, and cut redundant executions. The framework also includes static analysis, adaptive mutation, and an oracle-based validation to boost accuracy and reduce false positives. Tested on 42,738 real-world contracts, AI-FUZZ achieved a 96.8% true positive rate, 4.2% false positive rate, 27% higher detection coverage than leading fuzzers, and a 33% reduction in average detection time. It scales across small, medium, and large contracts and offers a self-improving, efficient, and reliable approach for large-scale blockchain security audits.
The transition to electric vehicles (EVs) plays a critical role in reducing global carbon emissions. However, the end-of-life management of electric vehicle batteries (EVBs) presents significant sustainability and operational challenges. This study proposes a blockchain-based framework that enables full lifecycle tracking of EVBs, from production to disposal or reuse, while addressing issues of transparency, efficiency, and regulatory compliance. The framework incorporates a multi-criteria decision model to guide data-driven end-of-life routingâwhether for second-life reuse or direct recyclingâbased on technical, environmental, and economic indicators. By integrating smart contracts with a hybrid web/mobile platform, the system ensures tamper-proof documentation, stakeholder accountability, and compliance with the EU battery passport regulation. A detailed cost analysis of deploying the framework on Ethereum is also presented. The proposed solution aims to enhance the sustainability of EVB management, reduce environmental impact, and promote circular economy practices within the EV industry.
The widespread deployment of Internet of Things (IoT) devices has driven their segmentation into distinct trust domains for the purpose of governance, creating a critical need for secure cross-domain authentication (CDA). CDA must preserve both anonymity and traceability of device identities to enable trustworthy data exchange. However, existing approaches, while exploring this trade-off, remain vulnerable to single points of failure and Sybil attacksâthreats that are especially severe for unattended and resource-constrained devices. In this paper, we propose a Self-Sovereign and Supervised Cross-domain authentication scheme (SCross) to tackle these issues. The main building block we designed is a pseudonym management scheme (PMS) that allows devices to generate and use pseudonyms without relying on a trusted party. Although devices has full control of their identities, PMS still ensures traceability, Sybil resistance, and revocability. We define the formal security models of PMS, instantiate it under two different approaches, namely group signature (SCross-GS) and zero-knowledge succinct non-interactive arguments of knowledge (zkSNARKs, SCross-ZK), and present security proofs for our proposal. We implemented and evaluated SCross. The result shows that our scheme achieves an effective trade-off between security and efficiency.