Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

266 papersLast indexed Aug 31, 2026
Search papers

Paper index

266 results · page 4 of 12

Clear filters
Dec 1, 2025·2025 International Conference on Decision Aid Sciences and Applications (DASA)
0 cites
Evaluating Blockchain Approaches for Secure and Efficient Management of Electronic Health Records: A Decision-Making View

Amit Sharma, K A Balaji, Jitha Janardhanan, Ranganathaswamy Madihalli Kenchappa · 6 authors

With the rapid expansion of healthcare data, especially Electronic Health Records (EHRs), there are significant concerns about data security, privacy, interoperability, and accessibility. When utilizing conventional centralized EHR systems, patients usually lack transparency and control over their medical data. In order to handle data safely, this study proposes the B-DECIDE (Blockchain-Driven Electronic Health Record Control, Integrity, and Data Efficiency framework), a decision-making paradigm that leverages the immutability, decentralization, and cryptography aspects of blockchain technology. B-DECIDE evaluates a number of blockchain topologies, including as public, private, and consortium, together with consensus algorithms like Proof of Work (PoW) and Proof of Stake (PoS), in order to determine how effective healthcare is. The findings indicate that a hybrid on-chain/off-chain storage approach maintains scalability, enhances data integrity, reduces latency, and ensures regulatory compliance.

Blockchain Technology Applications and Security
Electronic Health Records Systems
Information and Cyber Security
Original source
Nov 28, 2025·2025 IEEE 1st International Conference on Smart Innovations in Systems, Infrastructure, Mechanical, Power, AI and Computing Technologies (SISIMPACT)
0 cites
Privacy-Preserving Identity Management using Blockchain in Cybersecurity Systems

Sudha P, Raghu Narayana Reddy, N. Balasundaram, Lovish Dhingra · 6 authors

The proposed privacy-preserving identity management framework in this research is the combination of blockchain technology, zero-knowledge proofs, and adaptive sharding, which improves security, scalability and regulatory compliance and cybersecurity system. In contrast to current blockchain-based identity mechanisms, the presented mechanism involves encryption of identity attributes and distributes them on dynamic permissioned shards with the ability to selectively disclose identity information without leaking sensitive information. Comparison to Sovrin SSI, uPort and Civic show off impressive results, with a$33-63$percent increase in the transaction rate, 32 percent reduction in the duration of verification and 27 percent less time to generate the proofs. Compliance is achieved by reducing the storage overhead during which the immutability is preserved with chameleon hash-based redaction. There is a huge probability of leakage of privacy and efficiency of the consensus is 97 percent, so identity operations are sound and resistant to tampering. The architecture even makes it possible to have safe cross-domain authentication within heterogeneous environment. These results reassure that the framework will provide secure, efficient, and privacy-compliant identity management and thus will be very useful in enterprise, government, and IoT-based cybersecurity environments.

Blockchain Technology Applications and Security
Information and Cyber Security
Cloud Data Security Solutions
Original source
Nov 27, 2025·Frontiers in Blockchain
2 cites
Cybersecurity crimes in cryptocurrency exchanges (2009–2024) and emerging quantum threats: the largest unified dataset of CEX and DEX incidents

Akinlemi Olushola, S. P. Meenakshi

Cryptocurrency exchanges are integral to the digital asset economy; however, their rapid growth has been accompanied by recurrent high-impact cyberattacks that erode trust and inflict substantial losses. Guided by the PRISMA-ScR framework, this review systematically screened peer-reviewed and industry sources to construct a validated dataset of 220 major incidents (2009–2024) across centralized (CEX) and decentralized (DEX) exchanges. We classify attack vectors, analyze repeated high-impact patterns, and identify systemic vulnerabilities spanning cryptographic mechanisms and exchange infrastructure. Across CEX platforms, four of ten identified attack types accounted for 62 of the 80 incidents and approximately $1.764 billion in losses (42.1% of the $4.191 billion CEX total). Across DEX platforms, five of eighteen attack types were responsible for 120 of 140 incidents, totaling $3.755 billion (87.3% of the $4.303 billion DEX total). The overall losses sum to $8.494 billion across 220 incidents (80 CEX; 140 DEX). Repeated vectors comprised 182/220 incidents and $5.519 billion (65.0%) of losses, dominated by wallet/key compromise (78 incidents; $2.394 billion) and DEX system/server/protocol exploits (56 incidents; $1.939 billion); these two classes account for 134/182 repeated incidents (79.1%) and $4.333 billion (78.5%) of repeated losses. We examine the susceptibility of cryptographic defenses to emerging quantum adversaries and assess the exchange readiness for post-quantum threats. This study is the first to systematically compile and quantitatively analyze cybercrime incidents affecting both centralized and decentralized cryptocurrency exchanges in a unified dataset, enabling unprecedented comparability of systemic risks with actionable insights for cybersecurity researchers, regulators, and exchange operators seeking quantum-safe infrastructure evolution.

Open access
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Cybersecurity and Cyber Warfare Studies
Original source
Nov 20, 2025·2025 33rd National Conference with International Participation (TELECOM)
0 cites
Research on Design, Security and Vulnerability Analysis in WEB3 Applications

Stanimir Sadinov, Krasen Angelov, Росен Пасарелски, Yoana Ivanova

The main objective of the report is to demonstrate the creation and vulnerability testing of a web3 application for a decentralized system that integrates three key processes – membership management, automatic revenue distribution, and participation in the governance of the organization – within a secure, transparent, and immutable blockchain infrastructure. An analysis is demonstrated to detect and eliminate potential vulnerabilities and integration tests to confirm the correct interaction between the system modules.

Web Application Security Vulnerabilities
Information and Cyber Security
Security and Verification in Computing
Original source
Nov 16, 2025·arXiv (Cornell University)
1 cites
SSR: Safeguarding Staking Rewards by Defining and Detecting Logical Defects in DeFi Staking

Zewei Lin, Ting Chen, Jingwen Zhang, Zexu Wang · 7 authors

Decentralized Finance (DeFi) staking is one of the most prominent applications within the DeFi ecosystem, where DeFi projects enable users to stake tokens on the platform and reward participants with additional tokens. However, logical defects in DeFi staking could enable attackers to claim unwarranted rewards by manipulating reward amounts, repeatedly claiming rewards, or engaging in other malicious actions. To mitigate these threats, we conducted the first study focused on defining and detecting logical defects in DeFi staking. Through the analysis of 64 security incidents and 144 audit reports, we identified six distinct types of logical defects, each accompanied by detailed descriptions and code examples. Building on this empirical research, we developed SSR (Safeguarding Staking Reward), a static analysis tool designed to detect logical defects in DeFi staking contracts. SSR utilizes a large language model (LLM) to extract fundamental information about staking logic and constructs a DeFi staking model. It then identifies logical defects by analyzing the model and the associated semantic features. We constructed a ground truth dataset based on known security incidents and audit reports to evaluate the effectiveness of SSR. The results indicate that SSR achieves an overall precision of 92.31%, a recall of 87.92%, and an F1-score of 88.85%. Additionally, to assess the prevalence of logical defects in real-world smart contracts, we compiled a large-scale dataset of 15,992 DeFi staking contracts. SSR detected that 3,557 (22.24%) of these contracts contained at least one logical defect.

Open access
4 source records
cs.SE
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Nov 6, 2025·2025 International Conference on Emerging Engineering Technologies and Applications (IC-EETA)
0 cites
Architecting Ethical and Scalable Artificial Intelligence Systems: A Secure Deployment Model with Real-World Benchmarking

Arvinder Singh, Mudit Singh, Manpreet Kaur, Vikas Attri · 6 authors

The sheer rampant growth of artificial intelligence (AI) systems in the safety-critical, regulated, and large-scale areas of infrastructures has enhanced the demand of deployment models that are secure, ethical compliant, and scalable in terms of operation. The proposed research aims to develop a layered AI system architecture with verifiable privacy, federated orchestration, and explanation of decision-making as the first principles, as opposed to an afterthought. The framework consists of three modular parts, namely a privacy preserving computational substrate based on holomorphic encryption (HE) and differential privacy (DP), a distributed trust model that is enforced by a zero knowledge proofs (ZKP) and decentralized authentication protocols, and an ethical governance layer that includes policy-aware execution and explainable AI (XAI) reasoning. In contrast to the isolated sandbox setup, this architecture was tried in the realistic environment of a deployment using the representative of the domain data, such as OpenAQ sensor telemetry, MIMIC-III health logs, or smart energy grid datasets. The simulations were performed on 60-node Docker Swarm cluster using orchestrated adversarial attacks such as input reconstruction, consensus disruption, and metadata inference. Based on empirical evidence, the results indicate the latency stabilization at less than 140 ms, the cryptographic computation overhead at less than 22 percent and the privacy leakage reduction at more than 83 percent compared to centralized conventional baselines. These results confirm the correctness of implementing scalable AI solutions and not compromising ethical outcomes, regulatory guidance, and computational performance. This is the stepping block of future AI infrastructures that will have to be at scale, constrained, and in a similar spirit as the human-centric values.

Ethics and Social Impacts of AI
Information and Cyber Security
Advanced Software Engineering Methodologies
Original source
Nov 1, 2025·Computer law & security review
1 cites
Raising the bar: Assessing historical cryptocurrency exchange practices in light of the EU’s MiCA and DORA regulation

Marilyne Ordekian, Ingolf Becker, Tyler Moore, Marie Vasek

Centralized cryptocurrency exchanges have quickly become internal components of the digital finance ecosystem, mirroring traditional institutions by offering custody, investments, and transactional services. Despite their increasing prominence, the regulatory oversight has historically been fragmented and inadequate, leaving them largely relying on self-regulation. The resulting environment has been marked by exchange collapses, connections to criminal activities, cyber attacks, and poor operational security. High-profile failures, such as Mt. Gox and FTX, highlight the systemic risks and failure of internal governance models to properly mitigate or protect user funds from cascading risks or security breaches. In response, the European Union introduced the Markets in Crypto-Assets (MiCA) regulation and the Digital Operational Resilience Act (DORA), intending to standardize regulatory oversight and enhance user protection. This paper presents the first comprehensive interdisciplinary analysis of centralized exchanges under the MiCA and DORA frameworks. Drawing on methods from both law and computer science, we systematically translate regulatory requirements into measurable compliance standards, and develop a novel doctrinal and empirical methodology to evaluate current self-regulatory practices of 75 centralized exchanges operating in Europe. Through a detailed analysis of 143 exchange legal documents, we identify major compliance gaps and regulatory uncertainties. Our findings indicate significant shortcomings in exchange practices relating to asset custody, cybersecurity, and liability. This suggests that serious efforts are needed to change these practices and ensure their alignment with regulatory requirements. Our framework enables a systemic comparison between regulation and practice, and establishes a baseline for evaluating the effectiveness of regulatory measures. This approach can be replicated to study other self-regulating emerging sectors. • We conduct a doctrinal analysis on recent EU regulations, the Markets in Crypto-Assets Regulation (MiCA) and Digital Operational Resilience Act (DORA). We identify requirements for centralized cryptocurrency exchanges and systematically extract them and create a standard framework comprising 53 criteria. • We conduct the first comprehensive empirical study of self-regulation practices among all 75 fiat-dealing exchanges in Europe, analyzing 143 documents, including terms and conditions (T&Cs) and security policies. We compile a dataset of 371 hand-coded variables across 14 themes describing exchange practices. • We use the extracted legal standards to evaluate exchange practices, assessing their compliance posture with recent regulations. This study provides a baseline to gauge the effectiveness of MiCA/DORA in the long term and track changes compared to the pre-regulation era. Additionally, it provides a tool to understand the areas currently lacking or that need more attention in industry practices. • We show that many exchanges face challenges in effectively self-regulating, fulfill their custodial duties, maintaining robust security measures, and (may) use T&Cs to shift liability. By documenting these practices and shortcomings, we provide regulators and the industry actionable and tailored recommendations for improvements. We also provide a replicable methodology to investigate the self-regulation and governance of service providers in other emerging self-regulating technologies. • An earlier draft of this research was communicated with the EU’s European Securities and Markets Authority (ESMA) and European Banking Authority (EBA) in a closed meeting. We were recommended to expand the scope of the study to include DORA provisions in addition to MiCa. It was also suggested that this study could act as the ground truth baseline for pre-MiCA industry practices. A final version has been requested by said authorities. Additionally, findings from this paper have been submitted as evidence for consultation calls in the, UK. For intance, the FCA and HM Treasury. One of the authors recently presented the high-level implications of this study in an invited and closed conference organized by the FCA.

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Cybersecurity and Cyber Warfare Studies
Original source
Oct 31, 2025·2025 IEEE DELCON - International Conference on Recent Smart Technologies in Engineering for Sustainable Development
0 cites
Blockchain-Enabled Academic Assessment for Secure, Scalable, and Tokenized Evaluation on Ethereum and Polygon

Poornima G. Naik, Rajani S. Kamath, S. S. Jamsandekar

Blockchain technology has gained prominence in academia as a promising solution to strengthen security, transparency, and interoperability in academic assessment systems. The current research presents the design and implementation of a decentralized Ethereum based examination framework using Ethereum smart contracts, role-based access control (RBAC), and ERC20-based fungible tokenization for academic credits. In contrast to prior works which focus primarily on conceptual frameworks, the proposed system is deployed and evaluated on the Ethereum and Polygon (Layer2) test networks. Further, the architecture integrates off-chain storage via IPFS to minimize gas consumption, while role-specific smart contracts ensure data privacy and regulatory compliance. To enhance trust and confidentiality, zero-knowledge proofs (ZKPs) are incorporated for privacy-preserving answer verification, and decentralized identity (DID) standards are applied for student authentication. Experimental results demonstrate that Layer-2 deployment reduces transaction costs by up to 65% compared with Ethereum mainnet, and the system achieves stable throughput of 42 transactions per second (TPS) under simulated student workloads. Security validation using Slither and MythX confirms resistance to re-entrancy, double-spending, and unauthorized access attacks. The proposed framework establishes a quantifiable, fraud-resistant, and efficient academic assessment model, paving the way for scalable blockchain adoption in higher education.

Blockchain Technology Applications and Security
Academic integrity and plagiarism
Information and Cyber Security
Original source
Oct 18, 2025·Machine Learning with Applications
1 cites
A machine learning approach to vulnerability detection combining software metrics and topic modelling: Evidence from smart contracts

Giacomo Ibba, Rumyana Neykova, Marco Ortu, Roberto Tonelli · 6 authors

This paper introduces a methodology for software vulnerability detection that combines structural and semantic analysis through software metrics and topic modelling. We evaluate the approach using smart contracts as a case study, focusing on their structural properties and the presence of known security vulnerabilities. We identify the most relevant metrics for vulnerability detection, evaluate multiple machine learning classifiers for both binary and multi-label classification, and improve classification performance by integrating topic modelling techniques. Our analysis shows that metrics such as cyclomatic complexity, nesting depth, and function calls are strongly associated with vulnerability presence. Using these metrics, the Random Forest classifier achieved strong performance in binary classification (AUC: 0.982, accuracy: 0.977, F1-score: 0.808) and multi-label classification (AUC: 0.951, accuracy: 0.729, F1-score: 0.839). The addition of topic modelling using Non-Negative Matrix Factorization further improved results, increasing the F1-score to 0.881. The evaluation is conducted on Ethereum smart contracts written in Solidity.

Open access
Software Engineering Research
Advanced Malware Detection Techniques
Information and Cyber Security
Original source
Oct 17, 2025·2025 2nd International Conference on Artificial Intelligence, Metaverse, and Cybersecurity (ICAMAC)
0 cites
Leveraging Blockchain for Secure and Transparent Patient Case Data Management: Insights from System Implementation and Use Cases

Maheswari. S, Sumaiya Thaseen, Varun Dev Sahu, Pritish Dipak Divate · 5 authors

The safe handling of patient information is essential in the healthcare industry, particularly as the quantity and sensitivity of health records increase. Present systems frequently depend on centralized databases that are susceptible to unauthorized access and data manipulation, thereby restricting transparency and security. Furthermore, these systems lack the traceability required for efficient patient data management, making them prone to errors and inefficiencies in data processing. This paper proposes a patient data ledger built on blockchain technology, incorporating decentralized data management and secure transactions via Ethereum to enhance patient data handling. By leveraging blockchain, we achieve immutable records and ensure transparent, secure, and tamperresistant data storage. Unlike conventional systems that depend heavily on intermediaries for trust, our blockchain-based ledger minimizes human intervention and employs smart contracts to automate data security and access. Utilizing Ethereum's blockchain along with Web3 and MetaMask, the system enables secure, user-friendly access and effective data logging. This approach provides a reliable and scalable solution, ensuring real-time transparency and efficient handling of patient information while significantly enhancing security.

Blockchain Technology Applications and Security
Electronic Health Records Systems
Information and Cyber Security
Original source
Oct 14, 2025·2025 7th International Conference on Blockchain Computing and Applications (BCCA)
0 cites
A Risk Analysis of Non-custodial Staking in Ethereum

Daniel Molina, Jordi Herrera-Joancomartí

Non-custodial staking in Ethereum empowers users to participate in securing the network without transferring their funds to any entity other than the official deposit contract. This approach minimizes the need for trust in third parties, aligning with the core principles of decentralization. However, there is a lack of studies to understand the risk that a staker takes when choosing a non-custodial solution. Furthermore, non-custodial staking may be difficult for non-technical users. In this paper, we analyze the risk of non-custodial staking in Ethereum and we provide some tools to simplify some of the processes for non-technical users. We introduce a detailed threat model in which an attacker gains access to a validator’s private key, and evaluate both the direct financial losses due to slashing and the potential economic incentives for an attacker. Two attack scenarios are explored-targeting solo stakers and coordinated attacks on non-custodial services-quantifying their impact and feasibility. We also provide lightweight Python scripts that enable users to generate and validate voluntary exit messages without deploying a full Ethereum node. These tools are especially relevant for increasing the resilience of non-custodial staking, particularly in the event of service disruption. Our results suggest that while validator key exposure is a serious risk, rational non-custodial providers are economically disincentivized from behaving maliciously.

Information and Cyber Security
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Oct 14, 2025·2025 3rd International Conference on Intelligent Metaverse Technologies & Applications (iMETA)
0 cites
Securing the Metaverse and Medical MeTAI: Threat Taxonomy, Adversary Models, Risk Quantification, and a Data-Driven Defense Architecture

Mohammad Alja’afreh, Sarah Tarawneh, Hikmat Adhami, Ali Karime · 5 authors

The metaverse—a persistent, multiuser fusion of digitally augmented reality and computer-generated virtuality— is emerging as a programmable substrate for identity, assets, and interaction. Its heterogeneous stack (XR clients, engines/SDKs, Web3 rails, wallets, marketplaces) enlarges the attack surface. This paper contributes: (i) a structured threat taxonomy specialized for Web3/XR platforms; (ii) explicit system and adversary models; (iii) a risk quantification scheme combining behavioral and on-chain signals; and (iv) a data-driven defense architecture aligning decentralized identity, wallet/custody guardrails, analytics, AI-aided detection, and policy instrumentation. We further instantiate these controls in the Medical MeTAI context, where confidentiality, integrity, and provenance requirements are stringent.

Adversarial Robustness in Machine Learning
Information and Cyber Security
Smart Grid Security and Resilience
Original source
Oct 11, 2025·2025 IEEE 2nd International Conference on Green Industrial Electronics and Sustainable Technologies (GIEST)
0 cites
A3TH: An Adaptive AI-Driven Autonomous Threat Hunting Framework for Proactive Cyber Defense in Evolving Digital Environments

Nisha Milind Shrirao, R. Ahila, Haider Alabdeli, Vivekananad Aelgani · 7 authors

The vulnerabilities in this vigorous digital landscape are taking a more sophisticated shape as the nature and danger of cyber threats and the nature of cyber threats are taking new forms as a zero-day attack, polymorphic malware, insider threat and advanced social engineering methodologies and where traditional reactive security measures are no longer relevant. This issue of organizations detecting the threat, and that they need to mitigate the threat in real time is rather of a challenge in the light of the fact the behaviour of the adversaries is very much similar to that of legitimate user behaviour and as such will create ambiguity issues that will make an organization believe that it has hit a false positive or missed a threat. A proactive approach to cyber threat countering, the Adaptive AI-Driven Autonomous Threat Hunting (ADCH) Framework, is the focus of this paper as it will be able to monitor, analyse, and mitigate the development of the new threats far before it becomes reality. Behavioural profiling and reinforcement learning are employed at ADCH to differentiate between innocent and harmful actors on the fly even in the ambiguous or complex situation, and ethical precautions are taken so that the deepfake interaction modules are tightly regulated and privacy safeguarding. The framework brings together automated threat intelligence extraction where Indicators of compromise (IoCs) are extracted, classified and pooled across different sources and offer rapid and actionable information. Additionally, ADCH is compatible with Siem and SOAR, automates the incident response and mitigation process to minimise latency and dependency on people. Secure logging provides auditability resistant to tampering and transparent recording of events without de-anonymization of sensitive operational data, with blockchain used to enforce the use of permissioned ledger systems, smart contracts, and zero-knowledge proofs. The results of simulation testify that ADCH has been doing consistently well in terms of detection performance and accuracy, precision, recall and F1 scores, the results stand at $80-90$ and far better than the traditional threat hunting systems. Autonomous AI-controlled detection, ethical simulation, automated intelligence extraction, coordinated response, and blockchain-based logging can be combined to help in establishing a strong and intelligent paradigm of defense against the emergent and advanced cyberspace threats and ensure the safety of the digital infrastructures, transparency, accountability and ethical standards.

Cybercrime and Law Enforcement Studies
Information and Cyber Security
Network Security and Intrusion Detection
Original source
Oct 1, 2025·Risk Management and Healthcare Policy
19 cites
AI-Induced Cybersecurity Risks in Healthcare: A Narrative Review of Blockchain-Based Solutions Within a Clinical Risk Management Framework

Gianmarco Di Palma, Roberto Scendoni, Davide Ferorelli, Anna De Benedictis · 6 authors

Background/Objectives: Artificial intelligence (AI) is revolutionizing the healthcare industry, improving diagnoses, treatments, and clinical processes. However, its integration poses significant cybersecurity risks, including data breaches, algorithmic opacity, and vulnerabilities in AI-controlled medical devices. This narrative review analyzes these threats and evaluates blockchain technology as a potential mitigation strategy within a Clinical Risk Management framework. Methods: The literature search was conducted on PubMed, Scopus, and Web of Science, considering peer-reviewed publications from 2000 to January 2025. 1,204 articles were identified. Inclusion criteria included studies on cybersecurity risks in healthcare, blockchain applications in the clinical setting, and regulatory references (eg, General Data Protection Regulation). Conference abstracts, non-English articles, and non-peer-reviewed contributions were excluded. To ensure methodological rigor, the Scale for the Assessment of Narrative Review Articles criteria were applied. Results: The thematic analysis highlighted recurring critical issues: difficulties with informed consent, unauthorized access to sensitive data, and systemic vulnerabilities in hospital digital infrastructures. Blockchain presents a promising solution thanks to its decentralization, immutability, and transparency. Integration with smart contracts enables dynamic consent management, secure data sharing, and real-time monitoring of medical devices. Permissioned networks improve traceability and regulatory compliance, while Layer 2 solutions and optimized consent protocols address scalability challenges. Conclusion: Despite its potential, blockchain adoption faces obstacles: high costs, regulatory rigidity, and poor acceptance among healthcare professionals. The review highlights the need for pilot projects, interdisciplinary collaboration, and regulatory updates for effective integration. Combining AI and blockchain in Clinical Risk Management can transform clinical risk management from reactive to proactive, improving patient safety, data governance, and accountability.

Open access
Artificial Intelligence in Healthcare and Education
Information and Cyber Security
Blockchain Technology Applications and Security
Original source
Sep 29, 2025·arXiv (Cornell University)
0 cites
Secret Leader Election in Ethereum PoS: An Empirical Security Analysis of Whisk and Homomorphic Sortition under DoS on the Leader and Censorship Attacks

Tereza Burianová, Martin Perešíni, Ivan Homoliak

Proposer anonymity in Proof-of-Stake (PoS) blockchains is a critical concern due to the risk of targeted attacks such as malicious denial-of-service (DoS) and censorship attacks. While several Secret Single Leader Election (SSLE) mechanisms have been proposed to address these threats, their practical impact and trade-offs remain insufficiently explored. In this work, we present a unified experimental framework for evaluating SSLE mechanisms under adversarial conditions, grounded in a simplified yet representative model of Ethereum's PoS consensus layer. The framework includes configurable adversaries capable of launching targeted DoS and censorship attacks, including coordinated strategies that simultaneously compromise groups of validators. We simulate and compare key protection mechanisms - Whisk, and homomorphic sortition. To the best of our knowledge, this is the first comparative study to examine adversarial DoS scenarios involving multiple attackers under diverse protection mechanisms. Our results show that while both designs offer strong protection against targeted DoS attacks on the leader, neither defends effectively against coordinated attacks on validator groups. Moreover, Whisk simplifies a DoS attack by narrowing the target set from all validators to a smaller list of known candidates. Homomorphic sortition, despite its theoretical strength, remains impractical due to the complexity of cryptographic operations over large validator sets.

Open access
2 source records
Information and Cyber Security
cs.CR
Original source
Sep 8, 2025·Journal of Information Systems Engineering & Management
0 cites
Next-Generation Security Architecture for DeFi Platforms: A Framework for Global Financial Resilience

Gresshma Atluri

This paper introduces a pioneering multi-layered cybersecurity framework for Decentralized Finance (DeFi) platforms, fundamentally transforming traditional financial infrastructure by operating without centralized intermediaries through blockchain-based smart contracts, creating unprecedented accessibility while simultaneously introducing complex security challenges requiring specialized defense mechanisms. The immutable nature of blockchain technology necessitates comprehensive proactive security measures, as deployed smart contracts cannot be easily modified to address discovered vulnerabilities. Multi-layered security frameworks encompass pre-deployment foundations, including rigorous smart contract auditing by multiple independent firms, formal verification processes that mathematically prove contract behavior alignment with intended specifications, and transparent code documentation enabling thorough community security reviews. Runtime protection mechanisms incorporate time-locks enforcing mandatory delays before implementing critical protocol changes, circuit breakers serving as emergency stops when suspicious activity is detected, and rate limiting controls preventing flash loan attacks through transaction volume restrictions. Access control systems utilize multi-signature wallets requiring multiple authorized parties for transaction approval, while progressive decentralization strategies enable structured transitions from centralized development teams to distributed community governance. Financial protection frameworks integrate insurance protocols providing coverage against successful exploits, treasury management systems maintaining reserve funds through secure multi-signature mechanisms, and comprehensive risk management frameworks enabling continuous monitoring and threat identification. Community-driven security initiatives leverage distributed expertise through bug bounty programs offering competitive rewards for responsible vulnerability disclosure, collaborative security reviews identifying issues missed by formal auditing, and educational programs enhancing user awareness of security best practices and threat recognition capabilities.

Open access
Information and Cyber Security
Original source
Sep 5, 2025·International Journal Of Engineering & Applied Sciences
3 cites
Transforming European Cybersecurity: AI-Powered Threat Analysis, Quantum Age, Blockchain/Crypto Risks, and Regulatory Strategies

Recep Arslan, Mustafa Özseven, Metin Mutlu Aydın

European cybersecurity is rapidly evolving to address complex and emerging threats fueled by advancements in technology. AI-powered threat analysis has become a cornerstone, enabling faster detection of anomalies, predictive threat modeling, and real-time incident response. As Europe enters the quantum age, cybersecurity strategies are increasingly focused on quantum-resistant encryption to protect critical infrastructure and sensitive data from future quantum attacks. Simultaneously, the rise of blockchain technologies and cryptocurrencies introduces new vulnerabilities, such as smart contract exploits and decentralized finance (DeFi) fraud, requiring targeted regulatory oversight. In response, the EU is strengthening its regulatory frameworks, such as the NIS2 Directive and the Digital Operational Resilience Act (DORA), to ensure a harmonized, proactive approach to cybersecurity governance, resilience, and accountability across sectors. This multifaceted strategy reflects Europe’s commitment to safeguarding digital sovereignty and fostering trust in its digital ecosystem. The study deals with the transformation of the European cyber security ecosystem within the framework of artificial intelligence (AI) supported threat analysis. The paper discusses the security risks that arise in the quantum and post-quantum era, the possibility of blockchain/crypto systems being broken by quantum computers, the limitations of the existing data set, and the need for human-like thinking skills. In addition, the European Union's (EU) cybersecurity policies, data privacy principles, ethical standards, transparency, accountability, and human-centered AI design approaches are examined within the scope of the EU's global norm-setting role. This article also aims to shed light on the strategic steps that will shape the future of AI-powered cyber defense. Study shows that Europe should develop artificial intelligence (AI)-powered cybersecurity solutions in its preparations for the post-quantum era, it also should invest in AI models that transcend current data set limits and have humanoid thinking capacities.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Aug 26, 2025·Journal of Computational Methods in Sciences and Engineering
0 cites
Navigating cyberspace governance with the global digital compact: A cybersecurity perspective

Zhi Li, Weichen Jia, Runhua Tang

The global cyberspace faces many cybersecurity challenges, including illegal changes to contract terms and loopholes in the smart contract framework itself. This study adopts the automatic execution and intelligence of digital contracts, uses public key infrastructure technology digital certificates to establish trust relationships, encrypts data, and improves network security; the distributed ledger adopts the Byzantine fault-tolerant algorithm to prevent data from being tampered with, solving the problems of low efficiency and low security of traditional cyberspace manual governance. The study shows that after 28 companies applied digital contracts in 2023, the average authenticity of the data was 50.95% higher than the average authenticity of the data in 2022, the average integrity of the data was 36.44% higher than the average integrity of the data in 2022, and the average security of the data was 110.22% higher than the average security of the data in 2022. The findings highlight the critical role of digital contract implementation in enhancing the security and operational efficiency of global cyberspace governance, offering an effective solution to address the complex challenges inherent in managing today’s interconnected digital environment.

Cybersecurity and Cyber Warfare Studies
Misinformation and Its Impacts
Information and Cyber Security
Original source
Aug 26, 2025·2025 22nd Annual International Conference on Privacy, Security, and Trust (PST)
0 cites
Stateless Decentralized Authentication Using Segmented ZKPs for Microservices Architectures

Vinh Quach, Ram Dantu, Sirisha Talapuru, Apurba Pokharel · 5 authors

The growing integration of microservices exacerbates the mounting concern over privacy and trust caused by frequent data leaks and breaches. These systems are inherently decentralized, making them harder to manage, increasing the attack surface, and complicating trust between independently deployed services. Despite these persistent challenges, trust and authentication are often handled using centralized and stateful methods that require storing extensive state information. Existing so-called stateless authentication methods typically shift state storage from the server to the client side rather than detaching from state dependency. To address this challenge, we propose a lightweight, scalable, and truly stateless authentication approach that is non-idempotent and utilizes self-resetting nested Zero-Knowledge Proofs (ZKPs) to eliminate reliance on past actions. This platform anticipates user intentions and rigorously monitors them, ensuring bidirectional operational integrity while preserving privacy. Specifically, the self-resetting ZKP mechanism leverages the dynamic nature of microservices and incorporates random proof segmentation as a random generator to ensure each request is unique. Our tests using the OpenTelemetry Demo confirm its functionality and the independence between requests. Furthermore, security analysis demonstrates comprehensive security through non-idempotent authentication and the uniqueness of proof segmentation for each request.

Software System Performance and Reliability
Security and Verification in Computing
Information and Cyber Security
Original source
Aug 16, 2025·arXiv (Cornell University)
0 cites
Ethereum Crypto Wallets under Address Poisoning: How Usable and Secure Are They?

Shixuan Guan, Kai Li

Blockchain address poisoning is an emerging phishing attack that crafts "similar-looking" transfer records in the victim's transaction history, which aims to deceive victims and lure them into mistakenly transferring funds to the attacker. Recent works have shown that millions of Ethereum users were targeted and lost over 100 million US dollars. Ethereum crypto wallets, serving users in browsing transaction history and initiating transactions to transfer funds, play a central role in deploying countermeasures to mitigate the address poisoning attack. However, whether they have done so remains an open question. To fill the research void, in this paper, we design experiments to simulate address poisoning attacks and systematically evaluate the usability and security of 53 popular Ethereum crypto wallets. Our evaluation shows that there exist communication failures between 12 wallets and their transaction activity provider, which renders them unable to download the users' transaction history. Besides, our evaluation also shows that 16 wallets pose a high risk to their users due to displaying fake token phishing transfers. Moreover, our further analysis suggests that most wallets rely on transaction activity providers to filter out phishing transfers. However, their phishing detection capability varies. Finally, we found that only three wallets throw an explicit warning message when users attempt to transfer to the phishing address, implying a significant gap within the broader Ethereum crypto wallet community in protecting users from address poisoning attacks. Overall, our work shows that more efforts are needed by the Ethereum crypto wallet developer community to achieve the highest usability and security standard. Our bug reports have been acknowledged by the developer community, who are currently developing mitigation solutions.

Open access
2 source records
Digital and Cyber Forensics
Advanced Malware Detection Techniques
Information and Cyber Security
Original source
Aug 6, 2025·International Journal of Science and Research Archive
1 cites
Confidential-computing cyber defense platform sharing threat intelligence, fortifying critical infrastructure against emerging cryptographic attacks nationwide

Yusuff Taofeek Adeshina, Desmond Ohene Poku

In an era marked by increasingly sophisticated cyber threats and growing vulnerabilities in national critical infrastructure, this study explores the transformative role of confidential computing in defending against emerging cryptographic attacks and enabling secure threat intelligence sharing. Traditional cybersecurity measures, while effective for protecting data at rest and in transit, fall short in securing data during active processingan area exploited by advanced persistent threats, quantum computing, and side-channel attacks. This research investigates how hardware-based trusted execution environments (TEEs), homomorphic encryption, and zero-knowledge proofs embedded in confidential-computing platforms can preserve the confidentiality of sensitive operations even within potentially compromised environments. Through detailed case studies of major U.S. institutionsincluding PGandE, Exelon, JPMorgan Chase, Wells Fargo, and Kaiser Permanentethe paper demonstrates significant improvements in detection speed, false positive reduction, and operational efficiency. Furthermore, it proposes a scalable, privacy-preserving framework for collaborative cyber defense across critical sectors such as energy, finance, and healthcare. The findings underscore that integrating confidential computing with decentralized intelligence sharing networks not only enhances cybersecurity resilience but also yields substantial economic and regulatory benefits. This work advocates for a national, and eventually global, shift toward confidential-computing-enabled infrastructures to achieve robust, cooperative, and future-proof cyber defense ecosystems.

Open access
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Jul 30, 2025·Sensors
0 cites
SSB: Smart Contract Security Detection Tool Suitable for Industrial Control Scenarios

Ci Tao, Shuai He, Xingqiu Shen

The results of this study highlight the effectiveness of the proposed semantic security detection framework, SSB, in identifying a wide range of vulnerabilities in smart contracts tailored for industrial control scenarios. Compared to existing tools like ZEUS, Securify, and VULTRON, SSB demonstrates superior logical coverage across various vulnerability types, as evidenced by its performance on smart contract samples. This suggests that semantic-based approaches, which integrate domain-specific invariants and runtime monitoring, can address the unique challenges of ICS, such as real-time constraints and semantic consistency between code and physical control logic. The framework's ability to model industrial invariants-covering security, functionality, consistency, time-related, and resource consumption aspects-provides a robust mechanism to prevent critical errors like unauthorized access or premature equipment operation. However, the lack of real-world ICS validation due to confidentiality constraints limits the generalizability of these findings. Future research should focus on adapting SSB for real industrial deployments, exploring scalability across diverse ICS architectures, and integrating advanced AI techniques for dynamic invariant adjustment. Additionally, addressing cross-chain interoperability and privacy concerns could further enhance the framework's applicability in complex industrial ecosystems.

Open access
Blockchain Technology Applications and Security
Adversarial Robustness in Machine Learning
Information and Cyber Security
Original source
Jun 26, 2025·Smarter Cyber Physical Systems
0 cites
Privacy-Aware Control of Cyber Physical Systems

Matt Tsao, Karthik Gopalakrishnan, Kaidi Yang, Marco Pavone

Networked Unmanned Aerial Vehicles (UAVs) can be used for complex tasks such as surveillance and reconnaissance, inspection of dangerous environments, and target pursuit. Typically, coordination between multiple UAVs has been shown to improve the ability and performance of accomplishing such tasks. However, networked UAVs introduce new vulnerabilities enabling cyber-attacks which can target critical elements and prevent the UAVs from achieving their goal. This chapter presents a distributed system architecture for coordination of UAVs that provides resilience against denial-of-service and integrity cyber-attacks. The developed architecture consists of a distributed ledger implementing an asynchronous Byzantine fault tolerant protocol exchanging data between distributed agents and a distributed learning algorithm based on vector consensus implemented on top of the distributed ledger. Performance and resilience of the architecture are evaluated using a target pursuit case study based on a hardware-in-the-loop testbed. The experimental results demonstrate that that the UAVs that are not under attack are still able to successfully cooperate and accomplish the desired task. [160 words] privacy risks to users. If left unaddressed, potential privacy risks may deter users from contributing their data to cyber-physical systems, thereby limiting the effectiveness of data-driven tools employed by the systems. To ensure that users are protected from privacy risks and feel comfortable sharing their data with cyber-physical systems, this chapter discusses how differential privacy and cryptography, techniques originally developed for privacy in health care and computer systems respectively, can be used to conduct data analysis and optimization with principled privacy guarantees in cyber-physical systems. Along the way, we will discuss and compare the properties, strengths and weaknesses of these approaches. We will also show why these techniques address many of the privacy-related issues that arise when using data anonymization and data aggregation, two of the most common approaches to privacy-aware data sharing.

Smart Grid Security and Resilience
Blockchain Technology Applications and Security
Information and Cyber Security
Original source
Jun 19, 2025·2025 IEEE 2nd International Conference on Blockchain, Smart Healthcare and Emerging Technologies (SmartBlock4Health)
0 cites
Decentralized prescription management and emergency vital data through distributed ledger technology

Dinu-Ştefan Rusu, Emilia-Oana MÎŞŞ, Andrei Vasilățeanu

Ownership of medical data is one of the most important things a person should aim to achieve. An application that allows the patient to be in full control of his data whilst allowing medical personnel to see it such that they can respond accordingly represents a milestone in the development of a smart and integrated emergency system. Such a system should hold the entire patient data, such as prescriptions, vital data and doctor appointments. In this paper we present a system that uses distributed ledger technology to handle medical data such as prescriptions and patient vital data and we showcase how large language models can be used with these technologies to provide a natural interface for the users whilst allowing the user to be in-control of his data. We have also studied how zero knowledge proofs would improve the use case in which a user presents his prescription to a pharmacist.

Access Control and Trust
Electronic Health Records Systems
Information and Cyber Security
Original source