Rana Alaa, Darío González-Ferreiro, Carlos Beis-Penedo, Manuel Fernández‐Veiga · 6 authors
Split learning is an approach to collaborative learning in which a deep neural network is divided into two parts: client-side and server-side at a cut layer. The client side executes its model using its raw input data and sends the intermediate activation to the server side. This configuration architecture is very useful for enabling collaborative training when data or resources are separated between devices. However, split learning lacks the ability to verify the correctness and honesty of the computations that are performed and exchanged between the parties. To this purpose, this paper proposes a verifiable split learning framework that integrates a zk-SNARK proof to ensure correctness and verifiability. The zk-SNARK proof and verification are generated for both sides in forward propagation and backward propagation on the server side, guaranteeing verifiability on both sides. The verifiable split learning architecture is compared to a blockchain-enabled system for the same deep learning network, one that records updates but without generating the zero-knowledge proof. From the comparison, it can be deduced that applying the zk-SNARK test achieves verifiability and correctness, while blockchains are lightweight but unverifiable.
Shashank Motepalli, N. Garg, Gengrui Zhang, Hans‐Arno Jacobsen
Geospatial decentralization is essential for blockchains, ensuring regulatory resilience, robustness, and fairness. We empirically analyze five major Proof of Stake (PoS) blockchains: Aptos, Avalanche, Ethereum, Solana, and Sui, revealing that a few geographic regions dominate consensus voting power, resulting in limited geospatial decentralization. To address this, we propose Geospatially aware Proof of Stake (GPoS), which integrates geospatial diversity with stake-based voting power. Experimental evaluation demonstrates an average 45% improvement in geospatial decentralization, as measured by the Gini coefficient of Eigenvector centrality, while incurring minimal performance overhead in BFT protocols, including HotStuff and CometBFT. These results demonstrate that GPoS can improve geospatial decentralization {while, in our experiments, incurring minimal overhead} to consensus performance.
Mohammed Abdelhamid Nedioui, Ali Khechekhouche, Konstantinos Κarampidis, Giorgos Papadourakis · 5 authors
The integration of artificial intelligence (AI) and blockchain technology opens new avenues for decentralized, transparent, and secure data-driven systems. However, ensuring privacy and verifiability in collaborative AI environments remains a key challenge, especially when model updates or decisions must be recorded immutably on-chain. In this paper, we propose a novel privacy-preserving framework that leverages an ElGamal-based aggregate signature scheme with aggregate public keys to enable secure, verifiable, and unlinkable multi-party contributions in blockchain-based AI ecosystems. This approach allows multiple AI agents or data providers to jointly sign model updates or decisions, producing a single compact signature that can be publicly verified without revealing the identities or individual public keys of contributors. The design is particularly well-suited to resource-constrained or privacy-sensitive applications such as federated learning in healthcare or finance. We analyze the security of the scheme under standard assumptions and evaluate its efficiency in different terms. The study and experimental results demonstrate the potential of our framework to enhance trust and privacy in AI collaborations over decentralized networks.
Flavio Corradini, Alessio Galassi, Alessandro Marcelletti, Barbara Re
Blockchain has been largely adopted in several sectors through decentralized applications. These rely on smart contracts, whose implementation can diverge from the intended logic, leading to unexpected behaviors. Such behaviors can be identified by observing the data produced within smart contracts’ execution, employing compliance checking techniques. Their adoption poses a main limitation since the traditional rule specification languages do not explicitly refer to the blockchain. To address this limitation, we propose a domain-specific language, called CoBlock , to define compliance rules by relying on blockchain characterizations as a first-class citizen. This enables a tailored framework for compliance checking, supporting the definition of rules to check smart contract execution data. The framework is implemented as a web application. We demonstrate and evaluate the applicability of the language and the accuracy and feasibility of the framework using two real-world decentralized applications, namely Augur and PancakeSwap.
The rapid evolution of blockchain technology has revolutionized digital asset ownership through NonFungible Tokens (NFTs). NFTs enable creators to tokenize unique digital assets such as art, music, and collectibles, ensuring authenticity, transparency, and verifiable ownership. This research paper presents the design and development of a decentralized NFT Marketplace using Solidity Smart Contracts and Pinata IPFS (InterPlanetary File System) integration. The proposed system eliminates the need for intermediaries by leveraging blockchain-based automation, allowing creators to mint, list, and sell NFTs securely while maintaining full ownership control. The marketplace integrates MetaMask wallet authentication for secure transactions and employs Solidity smart contracts to handle NFT minting, transfer, and royalty distribution on the Ethereum blockchain. Additionally, Pinata IPFS provides decentralized storage for digital media and metadata, ensuring data permanence and tamper-proof accessibility. The system architecture combines transparency, security, and user-friendliness, empowering creators with fair compensation and buyers with verifiable proof of ownership. Experimental implementation results demonstrate that the proposed NFT Marketplace provides a reliable, transparent, and scalable environment for digital asset exchange. This study highlights the potential of decentralized systems in reshaping the digital economy and sets the foundation for future enhancements such as multi-chain support, AI-based recommendations, and mobile integration.
Blockchain technology has emerged as a transformative solution for decentralized and secure data management. However, the security of blockchain networks heavily relies on robust cryptographic protocols. This article provides a comprehensive analysis of key cryptographic techniques employed in blockchain security, including hash functions, digital signatures, consensus algorithms, and zero-knowledge proofs. We evaluate their roles in ensuring data integrity, authentication, confidentiality, and resistance to common attacks such as double-spending and Sybil attacks. A comparative study highlights the strengths and limitations of these protocols, guiding future enhancements for blockchain security frameworks
The increasing value of data as a digital asset has motivated research on secure and privacy-preserving data trading frameworks. Traditional data exchange models expose raw datasets directly, leading to privacy leakage and unclear ownership attribution. This paper presents a blockchain-based data trading framework that integrates Non-Fungible Tokens (NFTs) for ownership verification and Generative Adversarial Networks (GANs) for privacy-preserving synthetic data generation. By leveraging differential privacy during GAN training, the framework ensures data usability while providing provable privacy guarantees. Experimental results on benchmark datasets demonstrate that the proposed model achieves a favorable trade-off between privacy and utility, supporting secure and efficient data circulation in decentralized environments.
Arfa Mahvish, V Surekha, K Archana, Vaseem Ahmed Qureshi · 6 authors
The fast spurts of Internet of Things (IoT) devices have brought new challenges in security and privacy, such as data breaches, unauthorized access, and vulnerability of centralized systems. Traditional IoT security models are based on the centralized architectures and, therefore, have a lack of redundancy and a vulnerability to cyber-attacks. This paper introduces a secured decentralized IoT network based on blockchain technology to improve trust, integrity of data, and security in IoT ecosystem. The distributed ledger technology (DLT) of blockchain makes data transactions tamper-proof, access control transparent and based on decentralized authentication. By integrating smart contracts, the system automates secure device-to-device communication without intermediaries, reducing latency and improving efficiency. The proposed approach eliminates data silos, enhances network resilience, and mitigates security threats such as data manipulation, DDoS attacks, and unauthorized access. Performance analysis demonstrates that blockchain-based IoT security significantly improves data integrity, transaction transparency, and system reliability, making it an ideal solution for smart cities, healthcare, and industrial IoT applications.
Introduction: Ensuring secure and efficient identity management is crucial in an era where digital identities support numerous online services. Traditional Identity Management Systems (IDMS) face challenges such as data breaches, lack of user autonomy, and centralization risks, necessitating the exploration of decentralized alternatives. The review paper assesses blockchain-based IDMS as a potential solution, examining its benefits, challenges, and the role in improving security and privacy. Methods: This study conducts a systematic literature review of recent advancements in blockchain- based IDMS, drawing from peer-reviewed sources published between 2017 and 2024. The analysis focuses on security mechanisms, integration challenges, technological innovations, and their implications for digital identity management. Results: Blockchain-based IDMS offer many significant advantages, like enhanced security and privacy protection of identity data by the users. However, many challenges remain ahead, including the issue of scalability, interoperability with existing systems, and issues of regulatory acceptance. The advancements in this space are driven forward by recent innovations, such as zero-knowledge proofs and decentralized identifiers. Discussion: The review highlights blockchain’s transformative potential in addressing the flaws of traditional IDMS. While it offers notable improvements in privacy and user autonomy, successful real-world deployment requires overcoming technical and legal hurdles. These include adapting to existing standards and gaining acceptance among regulatory bodies. Conclusion: Blockchain technology has the potential to revolutionize digital identity management by overcoming several traditional IDMS limitations. While promising, further research is needed to overcome integration challenges and ensure regulatory compliance for real-world deployment.
Self-Sovereign Identity (SSI) frameworks enable individuals to receive and present digital credentials in a user-controlled way. Revocation mechanisms ensure that invalid or withdrawn credentials cannot be misused. These revocation mechanisms must be scalable (e.g., at national scale) and preserve core SSI principles such as privacy, user control, and interoperability. Achieving both is hard, and finding a suitable trade-off remains a key challenge in SSI research.This paper introduces UPPR, a revocation mechanism for One-Show Verifiable Credentials (oVCs) and unlinkable Anonymous Credentials (ACs). Revocations are managed using percredential Verifiable Random Function (VRF) tokens, which are published in a Bloom filter cascade on a blockchain. Holders prove non-revocation via a VRF proof for oVCs or a single Zero-Knowledge Proof for ACs. The construction prevents revocation status tracking, allows holders to stay offline, and hides issuer revocation behavior. We analyze the privacy properties of UPPR and provide a prototype implementation on Ethereum. Our implementation enables off-chain verification at no cost. On-chain checks cost 0.56–0.84 USD, while issuers pay only 0.00002–0.00005 USD per credential to refresh the revocation state.
In 2023, over 15 million health records were exposed, highlighting vulnerabilities in traditional Electronic Health Records (EHRs). This paper proposes a novel Ethereum-based decentralized EHR system to enhance security, privacy, and patient agency in Healthcare 4.0. Unlike prior systems like MedRec and Patientory, our framework introduces a time-bound emergency access protocol, reducing critical care response time by$\mathbf{2 0 \%}$, and an AI-driven module for digitizing paper records. ZeroKnowledge Proofs (ZKPs) ensure privacy-preserving verification, while the InterPlanetary File System (IPFS) provides scalable, tamper-proof storage. A ReactJS application with MetaMask empowers patients with data ownership. Integrated with FHIR/HL7 standards and GDPR-compliant, the system supports smart city initiatives. Prototype testing demonstrates robust scalability, paving the way for patient-centric national digital health frameworks.
Anders Malta Jakobsen, Oliver Holmgaard, Daniele Dell’Aglio, Michele Albano
As Ethereum is one of the most popular blockchains, it is naturally targeted by various attacks, aiming, for example, to disrupt the service or steal tokens. Among these, in deanonymization attacks, an adversary can obtain validator IP addresses and then perform a Denial-of-Service attack on them. To mitigate this attack, the Ethereum foundation is proposing Whisk, a Single Secret Leader Election protocol that uses a zero-knowledge proof called Curdleproofs to prove the validity of a shuffle of validators. One limitation of Curdleproofs is the shuffle size, which must be a power of two, restricting the number of validators that can be included. This paper overcomes this limitation by proposing CAAUrdleproofs, a modified version of Curdleproofs that incorporates Springproofs. Our experiments show that CAAUrdleproofs offers a performance advantage for any shuffle size that is not a power of two and that this advantage increases as the shuffle size decreases below a power of two.
Zeinab Alipanahloo, Michael Duchesne, Kaiwen Zhang
RzkFL is an end-to-end, privacy-preserving machine-learning framework that fuses Federated Learning (FL) with recursive zero-knowledge proofs (ZKPs) to protect data, models, and users while unlocking verifiable inference. Models are trained entirely on local devices, so sensitive data never leave the premises. The resulting model can be monetized by offering verifiable predictions on a pay-per-use basis. During inference, each customer independently computes predictions using private data, making it essential to verify that these inference results are computed correctly and honestly. Unlike existing approaches that rely on heavy communication or centralized trust assumptions, RzkFL allows each customer to generate a cryptographic proof of correct local inference, which can be succinctly verified without revealing input data or model parameters either by the customer or a third party. The core innovation lies in the use of recursive ZKPs, enabling each customer to generate small, composable proofs for intermediate layers of neural network inference. These proofs are then recursively aggregated into a single succinct proof using the Nova proof folding scheme. Nova’s design eliminates the traditional sequential dependency of recursive proofs by enabling incrementally verifiable computation through a folding scheme. RzkFL supports on-chain verification via Ethereum smart contracts, allowing AI results to flow directly into financial workflows. A decentralized file storage system maintains the integrity and availability of the global model. We introduce specialized circuits for input, hidden, and output layers to optimize proof generation time and gas costs. The customer can generate proof for the entire inference computation or delegate the proof generation for the intermediate layers and the output layer to another party. The design suits privacy-preserving machine learning scenarios where customer devices are resource-constrained. Our results show that RzkFL can significantly reduce proof size and verification costs while maintaining privacy, integrity, and scalability in federated inference. This makes it a compelling approach for real-world decentralized AI systems requiring strong verifiability guarantees.
Dingsen Shi, Chris Tsu, Ying He, Alex Goss · 8 authors
Zero-Knowledge Proofs (ZKPs) are becoming a foundational technology for scalable and privacy-preserving blockchain systems, especially through applications like zkRollups. However, the computational intensity of proof generation continues to limit real-world deployment. We present ZKPU, a hardware-software co-designed ZK accelerator that combines native NVMe integration—ensuring seamless compatibility across existing server and edge infrastructure—with a modular RISC-V System-on-Chip (SoC) architecture that opens the path to eliminating host–device communication bottlenecks. ZKPU is designed to flexibly support a wide range of ZK workloads; in this work, we demonstrate its capabilities by implementing and optimizing multi-scalar multiplication (MSM), a core bottleneck in many zk-SNARK systems. Built using the Chipyard framework and equipped with dedicated modular arithmetic units, ZKPU achieves significant performance and energy efficiency improvements over CPU, GPU, and FPGA baselines. Our results highlight ZKPU as a practical and forward-compatible foundation for scalable ZK acceleration in modern decentralized systems.
Shivakumar M, Rakshitha N, Ruqsar, Sahana M · 5 authors
In today's hyperconnected digital environment, authentication and security are paramount. As technology evolves, traditional methods of authentication such as usernames and passwords have proven increasingly vulnerable to cyberattacks, phishing scams, and identity theft. This has led to a growing need for a more secure, decentralized, and tamper-proof system to safeguard digital identities. This paper titled “NextGen Security: A secure and Decentralized authentication protocol using Non- transferable Blockchain-based Tokens” addresses this concern by proposing an innovative framework that leverages blockchain technology to implement a robust, distributed authentication mechanism. This paper envisions a future where authentication is not controlled by a centralized authority, but is instead managed through a distributed ledger. Blockchain, with its decentralized and immutable nature, ensures that user credentials and identity records are stored securely across multiple nodes, eliminating the single point of failure problem that plagues traditional systems. The proposed framework integrates Ethereum-based smart contracts, Keccak-256 (SHA- 3) hashing, and non-transferable Soulbound Tokens (SBTs) to ensure secure and decentralized identity verification. The system leverages wallet-based authentication through MetaMask and Web3.py, enabling cryptographically verifiable and tamper- proof login events on the blockchain.
Redactable blockchains enable controlled removal or modification of data to meet regulatory demands, but existing solutions often sacrifice decentralization or auditability. This paper presents a redactable blockchain architecture that combines a Redaction Policy Engine (RPE), multi-party validator voting, and post-quantum chameleon hash functions. We introduce a structured lifecycle—from submission and policy validation to execution and logging—anchored by cryptographic enforcement and on-chain governance. Our design supports GDPR-aligned features such as audit trails, user appeals, and purpose limitation enforcement. Implemented on a permissioned Ethereum network, our system demonstrates lower latency (1.82s), gas cost (128.5k), and storage overhead (1.2%) compared to prior solutions. A detailed security and compliance analysis confirms resilience against validator collusion and quantum threats. This work offers a practical framework for deploying redactable blockchains in regulated environments while preserving verifiability and decentralization.
Healthcare data sharing is fundamental for advancing medical research and enhancing patient care, yet it faces significant challenges in privacy, data ownership, and interoperability due to fragmented data silos across institutions and strict regulations (e.g., GDPR, HIPAA). Patients possess distributed records across multiple hospitals, each maintaining autonomous databases. Access to consolidated records by secondary entities mandates explicit patient consent while ensuring strict isolation between multi-tenant datasets, requiring fine-grained access control across organizational boundaries. Existing solutions exhibit critical limitations: blockchain-based databases lack robust fine-grained cryptographic enforcement of dynamic access policies, while TEE-enhanced systems suffer from synchronization overhead and poor scalability in distributed deployments. To bridge these gaps, we propose MtDB, a novel decentralized database architecture addressing secure data sharing in multi-tenant database ecosystems. MtDB employs blockchain for metadata coordination and sharing, IPFS for distributed data addressing, a universal SQL query interface for data access, and Intel SGX for integrity-protected query execution with enforced access control. We provide an open-source implementation demonstrating MtDB’s capabilities for secure, patient-centric healthcare data sharing while preserving ownership and enforcing policies. Experimental results show MtDB achieves 35 milliseconds query latency for indexed queries over 400M multi-tenant medical records while maintaining cryptographic security guarantees, with only 1.2–1.3× performance overhead compared to non-secure baselines.