Wei Liang, Yaqin Liu, Ce Yang, Songyou Xie · 6 authors
Blockchain is a decentralized distributed ledger that combines multiple technologies, including chain data structures, P2P networks, consensus algorithms, cryptography, and smart contracts. This gives the blockchain the characteristics of decentralization, immutability, and traceability. However, blockchain stores smart contracts and transactions in blocks publicly, which poses the risk of data leakage and misuse. For example, by mining and analyzing blockchain transaction information, attackers can correlate transactions with user information, resulting in the disclosure of user privacy. Many current reviews focus on the privacy of permissionless blockchains or cryptocurrencies, requiring more in-depth investigations and detailed categorical analysis. To fill this gap, this work comprehensively reviews the latest and traditional methods related to identity, transaction, and smart contract privacy within permissioned and permissionless blockchains. Additionally, we summarize the existing problems, threats, and challenges of data management in different blockchain architectures. Last, we discuss future research directions for blockchain privacy protection technology, which can offer feasible ideas for researchers to explore further.
The anonymity, multi-show unlinkability, and selective disclosure property of anonymous credentials enables users to access third-party services without revealing unnecessary details or being profiled. Threshold-based anonymous credentials provide a distributed framework to issue these credentials. While all of this enhances privacy, anonymity can also be misused and some schemes, therefore, have an opening mechanism, which enables the authorities to trace a user's identity. Nevertheless, relying solely on this measure is inadequate as the users can continue to use their previously issued anonymous credentials to authenticate themselves successfully with the service providers. To address this issue, we propose a revocation mechanism for such schemes using dynamic threshold accumulators (DTA) (Helminger et al. 2021). We first formally define a generic threshold-based anonymous credentials with an opening scheme (TACO) and subsequently propose an extension of TACO, "Revocable TACO (RTACO)" - revocable threshold-based credentials over blockchains - that integrates a revocation mechanism based on DTAs to the TACO system. In RTACO, we integrate a revocation handle into the credential as an extra attribute, allowing the disclosure of this attribute during the opening phase, which is then used to blocklist the credential, preventing its further use. We formally prove the security of this scheme in the universal composability (UC) framework. We also give a proof-of-concept implementation of RTACO over the Ethereum blockchain.
Biometric authentication has been used in applications in various environments as a secure authentication method in computing systems.When combined with blockchain technology, the security of the biometric authentication system can be further enhanced.In this paper, we propose a biometric authentication system that does not expose the original biometric information during the user's biometric authentication process by utilizing a fully homomorphic encryption.In addition, our proposed authentication system utilizes Ethereum's smart contract, which is one of the most famous public blockchains, to record the authentication log between the user and the service provider in a distributed ledger to enhance accountability and traceability.The system is designed to be used only after obtaining the consent of the biometric data subject(user) to comply with the privacy law represented by the European General Data Protection Regulation (GDPR).Finally, we show that the proposed system can process biometric information while maintaining confidentiality, integrity, and accountability of users via security analysis.The cost of maintaining the proposed system is acceptable by analyzing computation time and blockchain maintenance cost.
The widespread developments of blockchain bring about diverse blockchain networks, where each stands as an isolated data island and operates independently. The need of interoperability and interconnection among kinds of blockchains inspires the emergence of the cross-chain technology. It enables the asset transfer and information interaction via crosschain transactions. The previous cross-chain transaction systems are almost implemented over the plain data, fully exposing the transaction-associated information. Cryptographic techniques such as non-interactive zero-knowledge proof can be used to protect the transaction privacy, while its high complexity incurs heavy running cost. The privacy of cross-chain transactions is still a challenging issue. In this paper, we propose a lightweight crosschain transaction privacy-preserving method named PTCross. It embeds Bulletproofs and Pedersen commitment to hide crosschain transaction information, meanwhile combining off-chain computation and on-chain contract verification. We instantiate and implement PTCross between ChainMaker and Bitcoin. The experimental results show that the proposed PTCross achieves both lightweight performance and strong privacy.
Pratik Thantharate, Divya Ananth Todurkar, T Anurag
Differential privacy offers rigorous protections for emerging paradigms like federated machine learning, decentralized analytics, and web3 applications. The parameters E (epsilon) and5)-differential privacy while sustaining utility with an average error of only 4.5% compared to non-private histograms, underscoring the importance of formally tracking cumulative privacy loss. Our framework provides a practical solution for measurable privacy-preserving machine learning pipelines without degrading accuracy or utility. By interfacing with diverse mechanisms and adapting noise to empirical sensitivities, we facilitate precise reasoning of privacy risks throughout model life cycles. We also analyze privacy parameter implications across application domains. This paper lays a rigorous foundation for developing trustworthy AI systems that protect sensitive data.
Rihab Saidi, Ines Rahmany, Salah Dhahri, Tarek Moulahi
This study presents a novel approach for the early diagnosis of prevalent chest diseases, including COVID-19, pneumonia, and lung cancer, utilizing advanced machine learning techniques. The research focuses on addressing the limitations of traditional diagnostic methods by introducing Federated Learning as a collaborative and privacy-preserving solution. By leveraging Federated Learning, stakeholders can collectively develop accurate diagnostic models without directly sharing sensitive medical data, ensuring both privacy and diagnostic accuracy. Furthermore, the study proposes a multi-classification Federated Learning method enhanced by blockchain technology to reinforce data security and privacy. Experimental results demonstrate the effectiveness of this approach compared to centralized models, showcasing comparable performance in terms of accuracy and superior achievement in terms of privacy preservation. The integration of blockchain into the Federated Learning framework holds promise for a robust system prioritizing data privacy and security in the healthcare domain. This innovative combination not only advances machine learning in medical diagnostics but also sets a forward-looking approach for safeguarding patient information in today’s data-driven healthcare landscape.
Gulshan Kumar, Rahul Saha, Manish Gupta, Tai-hoon Kim
The correctness and the true validated data in Human Resource Management (HRM) are important for organizations as the data plays an impactful role in recruiting, developing, and retaining a skilled workforce. On one hand, the validated data in an organization helps in recruiting legitimate skillful employees; on the other hand, keeping the employee's data safe and maintaining privacy laws such as compliance with the General Data Protection Regulation (GDPR) is also an organization's responsibility. Besides, transparency in human resource management operations is crucial because it promotes trust and fairness within an organization. The present HRM systems are centralized in nature and their verifiable credential system is ineffective; this leads to the intentions of internal data sabotage or internal threats. Besides, the organizations' biases also become more prominent. In this paper, we address the above-mentioned problems with a blockchain framework for HRM to utilize the privacy of data access through a Privacy Information Retrieval (PIR) process. To be specific, our proposed framework called Blockchained piR of resOurces as humaN (BRON) , is the first blockchain framework to show an effective mechanism to access data from organizations globally without hampering privacy. BRON uses a generalized user registration process to use the services of data access and in the background, it uses Zero-Knowledge Proofs (ZKPs) for global verification and PIR for privacy-based data retrieval. More specifically, credential verification and ZKP-based PIR are the highlights of our proposed BRON. Another interesting aspect of BRON is the use of Proof-of-Authority (PoA) to validate the anonymity and unlinkability of any HR operation. Finally, BRON has also contributed with a smart contract to incentivize the employees. BRON is very generic and easily be customizable as per the HR requirements. We run a set of experiments on BRON and observe that it is successful in providing privacy-assured data access and decentralized human resource data management. Overall, BRON provides 30% reduced latency and 35% better throughput as compared to the existing blockchain solutions in the direction of HRM.
Developing intelligent healthcare solutions in the quickly changing world of communication technologies-driven smart cities depends heavily on data. Our work aims to protect user data, which is essential to intelligent healthcare in these kinds of urban areas, in the face of mounting worries about data privacy. However, serious privacy issues are raised by the sensitive nature of health data. Federated Learning (FL) is a potentially useful method that allows cooperative model training over several servers or devices while maintaining localized training data. However, serious privacy issues are raised by the sensitive nature of health data. In this work, we present a novel framework to improve secure healthcare data analytics in Blockchain systems by integrating FL with blockchain technology and the Interplanetary File System (IPFS). To balance privacy and data utility, our method makes use of adaptive noise distribution techniques and dynamic customization. IPFS aids in lowering the cost of data storage, while blockchain technology offers safe and transparent model update aggregation and storage. The results of our experiments show that our approach maintains excellent accuracy with 99.04% for healthcare data security analytics tasks and provides strong privacy protection against different types of attacks. Blockchain integration using Ethereum and IPFS demonstrates the usefulness and viability of our platform.
M. Sharmitha, M. P. Theeraj, P. V. Ranjith, S. Anitha
Individual health records (IHRs) hold paramount significance for individuals, serving as vital tools for the management and oversight of their medical data. Through electronic platforms, IHRs empower patients by granting them authority over their health information, thereby revolutionizing the conventional dynamics of the healthcare provider-patient relationship. Nonetheless, existing systems for managing IHRs face obstacles in providing patients with dependable, trackable, and secure control over their medical records, potentially compromising their authenticity and precision. Furthermore, the prevalent centralized methods of IHR management hinder the seamless exchange of medical data and introduce the risk of a singular point of failure.To address these challenges, a proposal is presented to utilize Ethereum blockchain-based smart contracts, providing patients with decentralized, immutable, and transparent management of their medical data. This solution also incorporate the decentralized storage feature of interplanetary file systems (IPFS). These integrated components collaborate effectively to securely access, store, and exchange patients’ medical information, with the overarching goal of enhancing the integrity and security of patient-controlled health records.
The lack of privacy-preserving capabilities hinders the further development of blockchains and smart contracts. While numerous privacy solutions have been proposed, limitations persist. First, most existing solutions focus on specific privacy protections such as anonymous payments, private data, or multi-party computation tasks. However, these solutions lack a general privacy ability, allowing users to deploy applications with diverse privacy requirements. Second, existing solutions have limited customizability, which means users cannot easily customize and adapt the privacy policies according to their specific demands or preferences. In this article, we present EtherCloak, which adopts trusted execution environments (TEEs) to achieve a general and customizable privacy policy on account model blockchains, enabling users to conceal any on-chain information. To address the security issues caused by the unreliability of the host the TEE runs on, we design the enclave state check and crash recovery mechanisms and employ them in the block generation process. In addition, we propose an access control mechanism for privacy policy management and data query. We prove that EtherCloak offers general and customizable privacy protection with a minimal increase in transaction size (less than triple) and communication overhead (approximately 10%) compared to Ethereum.
Blockchain innovation has as of late drawn in a great deal of interest as a potential major advantage for various applications. By the by, there are as yet significant snags with blockchain organizations’ presentation and versatility. AI approaches give possible solutions to improving and advancing blockchain network activities around here. There is an additional opportunity for supporting the proficiency of blockchain networks: choice tree calculations. These calculations are prestigious for being basic, interpretable, and adaptable. This study dives into choice tree-based AI procedures that are planned in light of blockchain networks. We go over the hypothesis behind choice trees and how they work comparable to blockchain innovation. We likewise give a careful survey of the writing on blockchain network issues settled by choice tree calculations, including pertinent exploration, strategies, and contextual investigations. We trust that by doing this examination, we will show how choice tree AI approaches might work on the proficiency, security, and adaptability of blockchain networks.
Dincy R. Arikkat, Mert Cihangiroglu, Mauro Conti, Rafidha Rehiman K. A. · 7 authors
The rise of IT-dependent operations in modern organizations has heightened their vulnerability to cyberattacks. Organizations are inadvertently enlarging their vulnerability to cyber threats by integrating more interconnected devices into their operations, which makes these threats both more sophisticated and more common. Consequently, organizations have been compelled to seek innovative approaches to mitigate the menaces inherent in their infrastructure. In response, considerable research efforts have been directed towards creating effective solutions for sharing Cyber Threat Intelligence (CTI). Current information-sharing methods lack privacy safeguards, leaving organizations vulnerable to proprietary and confidential data leaks. To tackle this problem, we designed a novel framework called SeCTIS (Secure Cyber Threat Intelligence Sharing), integrating Swarm Learning and Blockchain technologies to enable businesses to collaborate, preserving the privacy of their CTI data. Moreover, our approach provides a way to assess the data and model quality and the trustworthiness of all the participants leveraging some validators through Zero Knowledge Proofs. Extensive experimentation has confirmed the accuracy and performance of our framework. Furthermore, our detailed attack model analyzes its resistance to attacks that could impact data and model quality. • Definition of a Swarm Learning approach for collaborative CTI. • Definition of a Blockchain-based solution for privacy preservation in CTI sharing. • Secure CTI validation using a consensus mechanism and Zero-Knowledge Proof.
The increasing integration of the Internet of Health Things (IoHT) in the eHealth sector has significantly advanced the collection of Electronic Health Records (EHR). While blockchain technology offers enhanced data integrity and traceability for EHR, its inherent immutability often clashes with user concerns regarding security and privacy and prevents records from being securely updated. To address these challenges, our paper presents an innovative redactable blockchain mechanism tailored for EHR management. This approach leverages a decentralized, attribute-based chameleon hash function, enabling transaction-level redactions without succumbing to the vulnerabilities of a single point of failure. We implemented the proposed system based on the Charm cryptographic library and revocable IPFS scheme. The Chameleon hash function can support redactable operation for on-chain EHR-related information in seconds level. We also conducted extensive experiments on blockchain performance and IPFS performance, highlighting that the proposed redactable blockchain is efficient in practice for EHR management.
Abstract The Internet of Things (IoT) is a new well‐structured emerging technology with communication of smart devices using the 5G technology, infrastructures of roads, vehicles, smart cities, traffic systems and user applications. The IoT applications facilitate providing prompt emergency responses, and improved quality of vehicles, and road services, with cost‐effective activities in the intelligent transportation systems. Federated Learning (FL) enhances privacy and security in intelligent transportation systems and the Internet of Vehicles (IoV), using advanced prediction methods. Integrating blockchain with IoT, particularly in FL for transportation systems and IoV, bolsters security and data integrity. This approach keeps data local while only sharing model updates, enhancing privacy. Blockchain's transparency aids in efficient IoT collaboration, crucial for accountability. Its consensus algorithms further ensure network integrity, validating transactions and updates across devices, protecting against attacks, and fostering a transparent, collaborative environment. This comprehensive review paper delves into the innovative integration of blockchain technology with federated learning and the dynamic domain of IoV. It extensively analyzes the primary concepts, methodologies, and challenges associated with the deployment of FL in IoVs. This review presents a novel categorization examining three main types of blockchain‐based FL approaches vertical, horizontal, and decentralized each tailored to specific IoV communication scenarios like Vehicle‐to‐Vehicle (V2V), Vehicle‐to‐Infrastructure (V2I), and Vehicle‐to‐Cloud (V2C). It highlights FL applications in cyber‐attack detection, data sharing, traffic prediction, and privacy, considering Quality of Service factors. Finally, some main challenges and new open issues are discussed and assessed for federated machine learning approaches in the IoV.
Auditability and verifiability are critical elements in establishing trustworthiness in federated learning (FL). These principles promote transparency, accountability, and independent validation of FL processes. Incorporating auditability and verifiability is imperative for building trust and ensuring the robustness of FL methodologies. Typical FL architectures rely on a trustworthy central authority to manage the FL process. However, reliance on a central authority could become a single point of failure, making it an attractive target for cyber-attacks and insider frauds. Moreover, the central entity lacks auditability and verifiability, which undermines the privacy and security that FL aims to ensure. This article proposes an auditable and verifiable decentralized FL (DFL) framework. We first develop a smart-contract-based monitoring system for DFL participants. This monitoring system is then deployed to each DFL participant and executed when the local model training is initiated. The monitoring system records necessary information during the local training process for auditing purposes. Afterward, each DFL participant sends the local model and monitoring system to the respective blockchain node. The blockchain nodes representing each DFL participant exchange the local models and use the monitoring system to validate each local model. To ensure an auditable and verifiable decentralized aggregation procedure, we record the aggregation steps taken by each blockchain node in the aggregation contract. Following the aggregation phase, each blockchain node applies a multisignature scheme to the aggregated model, producing a globally verifiable model. Based on the signed global model and the aggregation contract, each blockchain node implements a consensus protocol to store the validated global model in tamper-proof storage. To evaluate the performance of our proposed model, we conducted a series of experiments with different machine learning architectures and datasets, including CIFAR-10, F-MNIST, and MedMNIST. The experimental results indicate a slight increase in time consumption compared with the state-of-the-art, serving as a tradeoff to ensure auditability and verifiability. The proposed blockchain-enabled DFL also saves up to 95% communication costs for the participant side.
Dingde Jiang, Zhihao Wang, Ye Wang, Lizhuang Tan · 6 authors
Federated learning (FL) in Industrial IoT (IIoT) facilitates collaborative model training across distributed edge devices, ensuring data privacy and localized insights without centralized data aggregation. However, the networked parameter sharing mechanism in FL renders it vulnerable to exploitation by man-in-the-middle (MITM) attackers, potentially disrupting the model training process. To mitigate this threat, this article presents a novel blockchain-reinforced FL architecture aimed at enabling cooperative intrusion detection. Initially, FL is leveraged to aggregate all learned information from edge servers, thereby disseminating extracted attack characteristics to all participants through gradient sharing. Subsequently, a blockchain-based parameter verification scheme is introduced to safeguard against tampered local parameters affecting the global model. Clients record model parameters in smart contracts deployed on a private chain, and parameter servers verify parameter confidentiality before aggregation, ensuring only valid parameters are considered. Finally, extensive experiments are conducted using an edge IIoT cybersecurity data set comprising 61 features spanning ten protocol layers and five attacks targeting IIoT connectivity protocols. Simulation results demonstrate that the proposed scheme significantly enhances intrusion detection accuracy, achieving a threefold improvement when two-thirds of federated nodes are subjected to MITM attacks.
Federated learning (FL) represents an advanced approach to tackling the issues linked with training machine learning (ML) models using distributed data while upholding privacy and security. It functions by enabling collaborative model training across a network of edge devices or servers, all without the need to transfer raw data. In place of sending data to a central server, which could potentially compromise privacy, federated learning empowers individual devices to conduct local training on their respective data. These updates are subsequently combined to develop an enhanced global model over multiple iteration. Additionally, as artificial intelligence (AI) becomes pervasive in novel application areas, concerns about the privacy of data and users are on the rise. This article offers an in-depth analysis of the advancements in FL, covering a wide array of topics including methodologies, applications, and challenges. By sidestepping the need to transfer raw data and instead focusing on sharing model updates or gradients, FL ensures the preservation of privacy and the efficient utilization of resources. Additionally, we investigate the diverse spectrum of application domains where FL holds significance. Instances encompass healthcare, finance, agriculture, education, Internet of Things (IoT), and industrial processes, all benefiting from the capacity of federated learning to harness data from decentralized sources without compromising data security. This article addresses complications such as model diversity, Non-IID (independent and identically distributed) data distribution, communication complexities, and security vulnerabilities. Furthermore, we discuss considerations related to regulatory compliance and ethics within the context of federated learning, particularly as data privacy regulations intensify.
Open access
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Artificial Intelligence in Healthcare and Education
Federated Learning (FL) was first introduced as an idea by Google in 2016, in which multiple devices jointly train a machine learning model without sharing their data under the supervision of a central server. This offers big opportunities in critical areas like healthcare, industry, and finance, where sharing information with other organizations’ devices is completely prohibited. The combination of Federated Learning with Blockchain technology has led to the so-called Blockchain Federated learning (B.F.L.) which operates in a distributed manner and offers enhanced trust, improved security and privacy, improved traceability and immutability and at the same time enables dataset monetization through tokenization. Unfortunately, vulnerabilities of the blockchain-based solutions have been identified while the implementation of blockchain introduces significant energy consumption issues. There are many solutions that also offer personalized ideas and uses. In the field of security, solutions such as security against model-poisoning backdoor assaults with poles and modified algorithms are proposed. Defense systems that identify hostile devices, Against Phishing and other social engineering attack mechanisms that could threaten current security systems after careful comparison of mutual systems. In a federated learning system built on blockchain, the design of reward mechanisms plays a crucial role in incentivizing active participation. We can use tokens for rewards or other cryptocurrency methods for rewards to a federated learning system. Smart Contracts combined with proof of stake with performance-based rewards or (and) value of data contribution. Some of them use games or game theory-inspired mechanisms with unlimited uses even in other applications like games. All of the above is useless if the energy consumption exceeds the cost of implementing a system. Thus, all of the above is combined with algorithms that make simple or more complex hardware and software adjustments. Heterogeneous data fusion methods, energy consumption models, bandwidth, and controls transmission power try to solve the optimization problems to reduce energy consumption, including communication and compute energy. New technologies such as quantum computing with its advantages such as speed and the ability to solve problems that classical computers cannot solve, their multidimensional nature, analyze large data sets more efficiently than classical artificial intelligence counterparts and the later maturity of a technology that is now expensive will provide solutions in areas such as cryptography, security and why not in energy autonomy. The human brain and an emerging technology can provide solutions to all of the above solutions due to the brain's decentralized nature, built-in reward mechanism, negligible energy use, and really high processing power In this paper we attempt to survey the currently identified threats, attacks and defenses, the rewards and the energy efficiency issues of BFL in order to guide the researchers and the designers of FL based solution to adopt the most appropriate of each application approach.
Lu Wei, Yongjuan Zhang, Jie Cui, Hong Zhong · 6 authors
The authentication and key agreement (AKA) scheme for VANETs can produce a series of short-term session keys, which can be used to secure the vehicular communications across open and insecure wireless channels. Traditional VANETs AKA schemes tend to employ the centralized trust architecture as the core authentication backend, which raises concerns about system security and reliability. Recently, several VANETs AKA schemes that are constructed on decentralized trust architecture have been proposed. However, these schemes do not achieve full decentralization and tend to suffer from key exposure issues, insufficient performance, and lack of optimization for on-chain storage costs. To address these shortcomings, we propose a threshold-based full-decentralized VANETs AKA scheme that is powered by consortium blockchain. In our proposed scheme, the threshold-based voting concept is employed to mitigate the key exposure issue inherent to the network infrastructure. Furthermore, we leverage lightweight cryptography in conjunction with the Cuckoo filter to reduce computational, communication, and on-chain operation costs brought by cryptographic operations and smart contracts. The security proof together with the cryptographic protocol validation tool prove the security of our proposed scheme, whereas the simulation experiment demonstrates the efficiency of our proposed scheme.
Mobile crowdsourcing aims to recruit enough workers holding mobile devices to collect data. Nevertheless, the platform will have cold start problems when the number of workers is limited. Existing studies have proposed solving this problem by propagating tasks to social networks for social recruitment. However, they neglect to verify workers’ propagation, leading to malicious workers reducing the platform's utility. Furthermore, during propagation verification, it is imperative to protect the privacy of social relationships among workers, as it can significantly influence the propagation. Therefore, this paper proposes Zero-knowledge Propagation Verification based on Social Relationship Encryption (ZPV-SRE) to improve the platform's utility. Specifically, we transform the propagation verification problem into a problem of computing the solution of the function. Then, the Zero-knowledge proof is used to prove the propagation, in which the worker's social relationship is protected through homomorphic encryption. Considering that ZPV-SRE will incur a significant time cost, we propose Trust-guided Zero-knowledge Propagation Verification based on Social Relationship Encryption (TZPV-SRE), which updates the worker's trust based on the verification results and selects suspicious workers for verification. The experimental results show ZPV-SRE improves the platform's utility as high as 104.05% over the state-of-the-art methods, while TZPV-SRE reduces time costs and ensures improvement.