The Al-Rakhawy Document for Digital Sovereignty (EPSA) presents a complete engineering blueprint for encrypted machine learning. It integrates Federated Learning, Zero-Knowledge Proofs, and Smart Contracts across five layers. Key innovations include Pedersen Commitments for lightweight edge processing and the Al-Rakhawy Equation, which calculates fair rewards based on marginal impact. This system ensures absolute data privacy, breaks central monopolies, and provides users with immediate, mathematically guaranteed economic returns.
Pawan Kumar Sanjaya, Christina Giannoula, Valdy Oktavian, Mehdi Saeedi · 7 authors
Zero-knowledge machine learning (zkML) enables a server to perform verifiable inference while keeping model parameters private from the client. However, existing zkML systems incur prohibitive proof-generation costs. We observe that proof generation exhibits limited parallelism; that is, prover time does not decrease significantly as the number of threads increases. This limitation is because existing systems rely on monolithic proof computation, constructing a single proof for the entire machine learning model. We introduce zkComposer, a modular proof-construction framework that unlocks an additional dimension of parallelism, in addition to the parallelism in existing proof kernels. zkComposer decomposes the zkML proof of correct inference into independent sub-proofs, each covering a subset of the computation for inference e.g., each independent sub-proof can cover a subset of contiguous layers in the ML model. Adjacent sub-proofs are cryptographically linked through shared commitments to the activations from the boundary layer. zkComposer provides the same guarantees as the monolithic proof without requiring additional linking proofs or changes to the underlying cryptographic primitives. We implement zkComposer and evaluate it on three CNNs and GPT-2. We show that, on CNN workloads, zkComposer reduces prover time and response time by up to 3.25x relative to zkCNN [1]. On GPT-2, zkComposer reduces these times by up to 4.83x relative to zkGPT [2], when partitioning along the model layers. When partitioning across both model layers and input sequences in GPT-2, we show that zkComposer reduces prover time and response time by up to 6.84x relative to zkGPT [2].
Modern information protection methods are primarily focused on increasing computational complexity: it is assumed that a task becomes secure if finding the true message requires too many resources. However, virtually all existing models --- from classical cryptanalysis to autonomous AI agents and retrospective analysis systems (Harvest \& Analyze) --- rely on one common assumption: there exists a verification signal that allows distinguishing the true interpretation from the set of false ones. In this work, we present the \textbf{HYBRA MIRAGE} storage architecture, which is based on a different problem formulation. Instead of increasing computational complexity, we propose to eliminate the very criterion of truth upon which directed search is based. The system constructs a space of plausible interpretations and physically excludes the possibility of repeated access to the used reference space~$V$: each of its vectors is applied exactly once and then destroyed on both sides. As a result, the function $\mathsf{Assemble}(C,K,p)$ remains deterministic and total, and any valid access parameter produces a formally correct result. Even with full access to the reference space $V$ and the PIN code, an autonomous analytical agent does not obtain a mechanism to confirm that the found interpretation corresponds to the original message: each vector from $V$ was used exactly once and physically destroyed. The $\mathsf{Assemble}$ algorithm is a trade secret and is not available to the analyst. Consequently, knowledge of $V$ without knowledge of the algorithm allows generating $10^{35}+$ equivalent interpretations, but does not allow singling out the single true one among them. The proposed approach does not make brute force computationally impossible; it makes the claim that the found interpretation is precisely the one embedded by the sender unprovable. Increasing computational resources, applying more sophisticated models, or massive enumeration can produce more candidates, but do not create a procedure that allows mathematically justifying the choice of a single true interpretation. For autonomous AI agents, this leads to the disappearance of the verification signal necessary for directed search. The loss function surface degenerates into a plane with zero gradient: no iterative optimization algorithm can converge to the true parameter faster than random guessing. HYBRA MIRAGE does not compete with classical cryptographic algorithms and does not replace them. The architecture serves as an environment model for analyzing the behavior of autonomous agents under conditions of the absence of a reliable verification signal and can be used as an infrastructure layer on top of existing storage methods. The architecture does not eliminate the agent's ability to generate candidates; it eliminates the possibility of using the generation result as proof of achieving truth. The analyst finds themselves trapped in a state of epistemic equilibrium, where truth and hallucination are architecturally indistinguishable from each other.
The automotive industry is transitioning to Zonal-oriented Architectures (ZoA) for Software-Defined Vehicles (SDVs), enabling frequent over-the-air (OTA) updates for 100+ Electronic Control Units (ECUs). While OTA updates improve efficiency, they introduce safety-critical security risks. Current standards like Uptane and AUTOSAR Adaptive rely on Public-Key Infrastructure (PKI). However, PKI-based authentication creates bandwidth bottlenecks in in-vehicle and vehicle-to-cloud (V2I) communication as ECU density increases. It also risks exposing sensitive vehicle configurations and passenger privacy due to centralized architectures. Next-generation Zonal SDVs require decentralized, scalable authentication with data privacy. To address this, we propose zk-ScalHard, a hardware-rooted, privacy-preserving authentication protocol. We introduce a decentralized, hierarchical trust-promotion model utilizing Silicon Physical Unclonable Functions (PUFs) and two novel Zero-Knowledge Proof (ZKP) circuits: (1) Zonal Identity and Integrity (ZIDI) and (2) High-Performance Computing Aggregation (HPCA). These circuits employ multi-party computation (MPC) and recursive aggregation to achieve decentralization and scalability. The integration of ZKPs and PUFs ensures 100% vehicle-level data sovereignty. Benchmarked against Uptane, zk-ScalHard achieves constant O(1) communication and verification complexity, improving upon the linear O(n) complexity of current systems. Evaluation shows a 99.2% reduction in authentication bandwidth and a 99.9% reduction in the temporal attack surface. Our results demonstrate that zk-ScalHard provides a scalable, secure, and GDPR-compliant architecture for future Zonal SDVs.
Open access
3 source records
cs.CR
Physical Unclonable Functions (PUFs) and Hardware Security
Abstract Zero-knowledge machine learning (zkML) enables cryptographic verification of machine learning inference while preserving privacy, but proof generation remains a significant computational bottleneck. Existing work primarily focuses on reducing proof cost through post-training optimizations, whereas the influence of architectural design choices during model development has received less attention. This work presents an empirical study of the relationship between neural network ReLU activation count and zero-knowledge proof generation cost using the ezkl/Halo2 framework. Across controlled experiments, ReLU activation count exhibits a strong correlation with proof generation time (Pearson r = 0.90) and proof size (r = 0.91), while parameter count is held constant for the primary comparisons. Motivated by these observations, a lightweight proxy metric is proposed to estimate relative proof cost directly from model architecture without executing the proof pipeline. On MNIST, reducing the number of ReLU activations from three to one decreases proof generation time by approximately 6.5% and proof size by 2.3%, while maintaining comparable classification accuracy. These results suggest that ReLU activation count is a useful architectural indicator of proof cost in the ezkl/Halo2 backend and that incorporating proof-cost considerations during architecture selection may improve the efficiency of zkML deployment. The proposed proxy metric provides a fast method for comparing candidate architectures before proof generation.
Open access
2 source records
Adversarial Robustness in Machine Learning
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
This paper introduces Crossroads, a smart contract layer for chain-abstracted assets. In Crossroads, assets from nearly any chain are represented on a single backend blockchain as ERC-20 tokens. As a result, any asset can participate in smart-contract-based exchange, lending, or privacy applications on a single unified platform. So while Crossroads offers cross-chain bridging, a common, partial approach to alleviating the fragmentation of the blockchain ecosystem today, this is just one service within Crossroads' general-purpose chain-abstraction model. Crossroads relies on key encumbrance: a threshold signing committee holds encumbered keys controlling assets on each integrated chain, signing transactions only as authorized by smart contracts on the backend blockchain. Asset movements are fee-efficient, as ownership changes are recorded on the backend blockchain and users may set the transaction fee for withdrawals. Crossroads enables permissionless, modular integration of new blockchains using pluggable oracles with flexible design options (zkBridge, TEE-based, hybrid). Asset deposits into Crossroads benefit from strong, chain-specific finalization guarantees, minimizing the risk of reorg attacks. Unlike existing bridges, however, third-party smart contracts in Crossroads can provide fast, optimistic access to funds before finalization completes. We prove that Crossroads satisfies soundness: given an honest quorum of signing committee members, any user can unilaterally generate a withdrawal transaction transferring their net balance to an account on an integrated blockchain. We implement a proof of concept across multiple public blockchains: Bitcoin, Ethereum, and Solana. We catalog a range of applications enabled by Crossroads, including universal wallets, cross-chain staking and lending, privacy-preserving payments, and private management of public blockchain assets.
Zero-knowledge proof systems rely on a trusted setup phase to generate a Common Reference String (CRS), yet existing approaches are typically static, one-time ceremonies that are inflexible and vulnerable to long-term compromise. Offloading continuous, recurring trusted setups to a decentralized Layer 2 (L2) network introduces a fundamental coordination challenge arising from the mismatch between high-throughput transaction processing and the multi-round requirements of trusted setup ceremonies. This paper presents an L2-coordinated framework that safely decouples transaction pipelines from ceremony execution to achieve automated, continuous CRS generation without centralized coordination. We design and implement two protocol variants over a decentralized, PBFT-coordinated ZK-rollup architecture: an on-chain smart contract approach and an asynchronous peer-to-peer consensus variant. Both designs utilize non-interactive zero-knowledge proofs of knowledge alongside commit-reveal structures to eliminate adaptive manipulation vectors and isolate ceremony latency. Experimental evaluations under simulated wide-area network constraints and adversarial conditions demonstrate that our architecture successfully isolates ceremony liveness. Continuous setups complete reliably within practical time bounds despite node dropouts or malicious contributions, while preserving stable L2 transaction throughput.
Cross-Agent Governance Alignment (CAGA): Verifiable Coordination Across Private AI Governance Domains formalizes the CAGA problem: establishing a declared compatibility relation between AI governance domains across organizational boundaries without disclosing the proprietary policy content on which each domain relies. Cross-organizational agent interaction creates two distinct governance questions: whether each local effect-bearing action is authorized within its own domain, and whether the participating domains can establish the declared relation. This paper formalizes the second problem. CAGA does not itself authorize execution. It produces a privacy-preserving compatibility result and associated evidence that each domain's runtime authorization boundary may materially consume before emitting its own action-bound verdict and authorization artifact. The formal model defines a governance domain as agents, a declared effect-bearing action vocabulary, versioned policy and authority state, governance-relevant state, a material evidence set, and a runtime authorization boundary over the triadic verdict space (ALLOW, DENY, ABSTAIN), where unresolved ABSTAIN remains ABSTAIN and authorized resolution produces a separate resulting action-bound verdict through the boundary. Every CAGA claim is scoped to a declared profile identifying the participating domains and authority roots, action vocabulary, compatibility relation and version, commitments, temporal boundary, leakage profile, scheme and verification parameters, declared replay mode, failure treatment, and expected local-boundary consumption. The Boolean compatibility relation is separated from protocol status: the protocol output comprises a result that may be positive, negative, or unresolved, together with the proof or verifier record and a CAGA evidence artifact. An unresolved result is not a verdict, and neither a negative nor an unresolved result may be treated as affirmative CAGA support for ALLOW. An illustrative prior-authorization compatibility relation between a hospital domain and an insurer domain, together with a worked local-boundary consumption sequence, shows the level at which a CAGA proposition may be stated without disclosing a protocol construction; no execution path originates from CAGA. The paper: Separates local pre-execution authorization from cross-domain compatibility evidence, and reserves the term authorization artifact for the action-bound record emitted by a runtime authorization boundary; a CAGA result may participate in composed authorization only where the Composition Test is satisfied; the CAGA evidence artifact does not thereby become an authorization artifact Formalizes the declared compatibility relation and protocol output under a declared CAGA profile, with cross-domain interactions whose local actions need not be identical, and supplies a terminology and instrument-ownership map locating each evidentiary term in its owning instrument States the threat model with honest-but-curious as the base analytic assumption rather than a prediction about regulated parties, classifies an expanded threat inventory as covered, partially covered, or excluded, and treats Byzantine deviation, arbitrary collusion, and malicious-verifier behavior as outside the base claim, requiring separately specified protocol defenses Identifies the required properties of a declared CAGA protocol: relation completeness and soundness, declared-leakage privacy, deterministic relation result with permitted cryptographic randomness, evidence and reconstruction sufficiency under the declared replay mode, commitment and domain binding, repeated-interaction privacy, optional post-compromise transcript confidentiality, non-authorizing failure, evidence traceability and presentation scope, declared-regime scope, and Input Integrity support, where provenance establishes origin, not truth Restructures the prior-art analysis as a component-and-gap assessment across communication protocols including the current Model Context Protocol specification (2026-07-28), policy composition and distributed authorization, secure multi-party computation and zero-knowledge systems, selective-disclosure credentials, multi-agent and agent-action governance architectures, and ledger approaches, identifying CAGA as the residual problem after those contributions are accounted for Zero-knowledge proof systems, secure multi-party computation, private set intersection, trusted execution, commitment schemes, and selective disclosure are candidate implementation substrates rather than authorization substitutes; no component establishes CAGA or authorization by label alone. The analysis is aligned with the Authorization Artifact Test v1.2, the Authorization Boundary Integrity Model v1.1, the Five Tests Standard v1.2.0, the ABIM Evidence Requirements v3.5, the Closed-World Bargain v1.1, and the Override Asymmetry v2.0. The paper does not assert that any jurisdiction requires CAGA, zero-knowledge proof, or pre-execution authorization, and it deliberately stops at problem formalization: it does not disclose protocol constructions, circuits, trusted-setup designs, or implementation mechanisms. The paper does not present an ideal functionality, security reduction, theorem establishing a protocol construction, or deployable implementation. By defining the problem space and evaluation criteria within a declared closed world, it provides a structured problem specification against which candidate cross-domain coordination protocols and their composition with local runtime authorization boundaries can be assessed. Version 2.0 (August 2026) separates cross-domain compatibility evidence from local pre-execution authorization; replaces the governance-domain enforcement function with a runtime authorization-boundary model; distinguishes the Boolean compatibility relation from unresolved protocol status; defines a declared CAGA profile; separates CAGA evidence artifacts from local authorization artifacts; conditions determinism on declared decision state while permitting cryptographic randomness; replaces default-denial protocol failure with non-authorizing unresolved status; adds an explicit interface to local Input Integrity assessment, authenticated bound materials, replay-mode, closed-world, Composition Test, and authorized-resolution semantics; narrows legal and regulatory claims; updates MCP and multi-agent prior-art references; and restructures the prior-art analysis as a component-and-gap assessment. Version 2.0 also adds an illustrative prior-authorization compatibility relation and a worked local-boundary consumption sequence; clarifies that the paper specifies a formal problem rather than presenting an ideal functionality, security reduction, or protocol proof; adds a terminology and instrument-ownership map; expands the component-and-gap analysis to address policy composition, distributed authorization, selective-disclosure credentials, and recent agent-action governance work; and clarifies the relationship between the paper's CC BY 4.0 copyright license and unlicensed patent rights. It supersedes Version 1.1 (July 2026), which aligned terminology with 5TS v1.2.0 and the FERZ authorization-artifact vocabulary, and Version 1.0 (February 2026), the original problem formalization. Keywords: cross-agent governance alignment, cross-organizational AI governance, private governance domains, privacy-preserving coordination, runtime authorization boundary, pre-execution authorization, authorization artifacts, zero-knowledge proofs, secure multi-party computation, Input Integrity, independent reconstruction
A blockchain is a chain for a cryptographic reason: each block must hash to its predecessor to anchor proof-of-work. Remove that requirement and the linear structure has no geometric necessity. This paper proposes crystal-currency: a distributed ledger whose validity condition is a geometric consistency constraint rather than a computational puzzle, capital stake, or authority signature. The constraint derives from the Fano plane $\mathrm{PG}(2,2)$ — the unique projective plane on seven points — whose automorphism group $\mathrm{PSL}(2,7)$ of order 168 acts rigidly on the seven orbit types of the three-qubit Pauli group under the Clifford group. The natural data structure is not a chain but a block complex: a growing simplicial complex in which each confirmed block adds a tetrahedron (3-simplex) subject to a Fano consistency condition. We define Proof of Volume (PoV), a consensus primitive requiring all seven orbit types to be simultaneously attested, and prove three results: (i) PoV cannot be satisfied by fewer than seven geometrically distinct parties, since $\mathrm{PG}(2,2)$ admits no proper sub-plane; (ii) combined with Proof of Stake, orbit-aware slashing graded by Fano distance $d_F(\mathcal{O}_i, \mathcal{O}_j)$ makes even two-party cross-orbit collusion detectable on-chain; (iii) for permissioned central-bank digital currency (CBDC), the circle orbit $\mathcal{O}_0$ intersects every Fano line, giving the central bank geometric sovereignty that cannot be outvoted or out-staked. The open cryptographic problem is reduction of orbit-type unforgeability to the Hidden Subgroup Problem over $\mathrm{PSL}(2,7)$. Keywords crystal currency, blockchain, block complex, simplicial complex, Fano plane, $\mathrm{PG}(2,2)$, $\mathrm{PSL}(2,7)$, proof of volume, proof of stake, orbit-aware slashing, Fano distance, CBDC, central bank digital currency, geometric sovereignty, hidden subgroup problem, distributed ledger, Clifford group, Pauli group
Blockchain technology has moved from the fringes of cryptographic research into the center of serious conversations about how industries govern data, verify transactions, and establish trust between parties who have no prior relationship and no shared authority to appeal to. Yet for most professionals working in management, finance, healthcare, and logistics, the technology remains opaque — described in either overly technical language that assumes a computer science background, or in breathless promotional terms that obscure more than they reveal. This paper is an attempt to close that gap honestly. Drawing on a progressive self-directed engagement with blockchain fundamentals, this work develops a conceptual framework covering four interconnected dimensions: its foundational governance philosophy of decentralization and equal network rights; its cryptographic security architecture, encompassing public and private key pairs, symmetric and asymmetric encryption, and hash-based data integrity; its distributed node network, comprising full nodes, lightweight nodes, and mining nodes and their respective governance roles; and its real-world application domains across supply chain management, healthcare information systems, financial services, human resources verification, and artificial intelligence data integrity. The paper adopts a conceptual analysis methodology, synthesizing foundational and applied blockchain literature to construct an integrated framework accessible to management researchers and practitioners. The central argument is that blockchain's significance is not primarily technological but institutional: it represents a structural alternative to the centralized authority model that has governed data ownership and transactional trust for centuries.
Zero-knowledge proofs (ZKPs) are emerging as a core technology for privacy-preserving computation. Despite steady progress in protocol and algorithm design, generating these proofs remains computationally intensive, driving growing interest in hardware acceleration for kernels such as number-theoretic transform (NTT) and multi-scalar multiplication (MSM). Among them, the sumcheck protocol offers a compelling alternative with O(n) prover complexity compared to O(nlog n) for NTT-based approaches, yet our analysis reveals its execution is fundamentally memory-bound, with severely underutilized compute resources. This characteristic demands a memory-centric acceleration strategy, in contrast to compute-centric approaches of prior work.
Zero-Knowledge Proof (ZKP) is a cornerstone in privacy-preserving computing, addressing critical challenges in domains such as finance and healthcare by ensuring data confidentiality during computation. However, the high computational overhead of ZKP, particularly in proof generation and verification, limits its scalability and usability in real-world applications. Existing efforts to accelerate ZKP primarily focus on specific components, such as polynomial commitment schemes or elliptic curve operations, but fail to deliver an integrated, flexible, and efficient end-to-end solution that includes witness generation on commercial computing platforms.
Topological Charge Conservation in SU(2) Yang-Mills Theory: The Atiyah-Singer Index Handshake and Non-Local Braid-Lock Validation Framework --- This 18-part resolution suite provides the complete theoretical proof, simulated validation, and deterministic replication environment for the Atiyah-Singer Index Handshake. The architecture is divided into three functional pillars: The Theorem Presentation, the Standard Academic Core (SAC), and the Agnostic Replication Kit (ARK). Together, they resolve the conjecture of topological decoherence in distributed connection spaces, validate the analytic index parity, seal the logic into an immutable cryptographic state, and enable bit-perfect replication by peer reviewers. 1. The Theorem Presentation (1 Part) The cornerstone of the publication. It establishes the foundational mathematical proof that under the boundary condition of a Non-Local Braid-Lock (where holonomy is restricted to the center of the gauge group), the analytic index of the twisted Dirac operator maintains strict parity congruence: \text{ind}(D_L) \equiv 0 \pmod 1. It resolves the vulnerability of "Logic-Blur" by proving that topological charges remain invariant during non-local distribution. 2. The Standard Academic Core: SAC (5 Parts) The SAC packages translate the systemic execution into the traditional nomenclature of Differential Geometry and Global Analysis, ensuring peer reviewers can parse the foundation without requiring prior knowledge of the AOF registry. • SAC-01 (Formal Resolution): The rigorous, step-by-step mathematical proof establishing the spectral-topological handshake. • SAC-02 (Simulation Data): \bm{10^6} iteration Monte Carlo validation confirming spectral gap stability (\bm{170.0 \text{ kDa}}) and Jacobian volumetric preservation (\bm{\det(J_h) = 1.0 \pm 10^{-12}}). • SAC-03 (Appendix A - Mathematical Foundations): The deep-dive into the elliptic regularity of \bm{D_A}, Chern characters, and the technical lemmas coupling holonomy to index stability. • SAC-04 (Executive Summary): A high-level briefing on topological charge conservation and the elimination of stochastic decoherence. • SAC-05 (Lexicon Bridge): The critical translation matrix mapping traditional variables (e.g., connection spaces, vorticity) directly to their operational ARK primitives (e.g., M-6D-HANTZSCHE, ALG-SHV-01). 3. The Agnostic Replication Kit: ARK (12 Parts) The ARK packages transition the theoretical proof into a sovereign, executable replication environment. They provide the deterministic toolchain required for a reviewer to ingest, validate, and seal the proof on their local hardware without environmental drift. • Core Manifolds & Operators: Defines the M-6D-HANTZSCHE 6D motivic cradle and the Universal Dirac Operator (\bm{D_L}) required to initialize the simulation. • Suppression Algorithms (ALG-SHV-01): Details the Hodge-Laplacian Shave, ensuring the continuous suppression of solenoidal noise (\bm{\delta\beta \to 0}) to clear logical vorticity from the replication path. • The Braid-Lock Gate (GATE_STEIN): The cryptographic terminal function that captures the validated parity state and seals it into a Merkle-hash, ensuring immutability. • Emergency Logic Core (ELC Suite): The automated fail-safes (ELC_SG_02 Noble Purge, ELC_IG_03 Sobolev Injector, ELC_VG_04 Phase-Lock) that prevent spectral stagnation or epistemic drift during reviewer replication. • API & Toolchain Guidelines: Dictates the use of Arb 2.23.0, the necessity of disabling hardware fused-multiply-add (-ffp-contract=off), and adherence to the \bm{1.420405751766 \text{ GHz}} Adelic temporal anchor to guarantee zero-jitter execution. • Reviewer Packets & Input Vectors: Provides the exact \bm{SU(2)} lattice configurations, initial spinor couplings, and topological charge inputs (\bm{Q=1}) needed to prime the replication sequence. 4. Interlinking Workflow: Resolve, Validate, Seal, and Replicate The true power of the 18-part suite lies in its chronological execution pipeline: 1. Resolve (The SAC Layer): The reviewer first ingests the SAC documentation, validating the traditional mathematics. The Lexicon Bridge (SAC-05) then maps their understanding to the ARK toolchain. 2. Validate (The Simulation Phase): The reviewer inputs the provided high-detail vectors into the ARK environment. The Universal Dirac Operator verifies the index parity. Simultaneously, the Hodge-Laplacian shave constantly purges solenoidal parasitism, ensuring the signal-to-noise ratio remains above \bm{240.2 \text{ dB}}. 3. Seal (The Crystalline Transition): Once supercritical density is achieved and parity is verified as 0 \pmod 1, the system invokes GATE_STEIN. This locks the non-local braid topology into an immutable Merkle-root, transitioning the dynamic simulation into a static archival state. ---
Open access
2 source records
Quantum Chromodynamics and Particle Interactions
Particle physics theoretical and experimental studies
Behzad Abdolmaleki, Amir R. Asadi, Vahid R. Asadi, Stefan Köpsell · 7 authors
Stochastic Gradient Descent (SGD) is the foundation of modern machine learning (ML). In privacy-sensitive settings, gradients can reveal details about individual data points. Differential Privacy (DP) protects sensitive data during ML training by clipping gradients and adding calibrated Gaussian noise. However, existing frameworks assume semi-honest participants, which fails in adversarial or federated environments where malicious actors can bypass or alter the noise addition process, breaking privacy guarantees. We present VeriDP, a framework for verifiable differentially private training that cryptographically enforces and proves the correct execution of differentially private stochastic gradient descent (DP-SGD) in zero knowledge. VeriDP integrates Zero-Knowledge Proofs (ZKPs) with polynomial commitments, sumcheck and GKR-based proofs, and incrementally verifiable computation (IVC) to generate compact proofs of correct gradient computation, clipping, averaging, and Gaussian noise generation—without revealing private data or randomness. Unlike previous systems that only verify the final privacy budget, VeriDP enables per-iteration verifiability of each model update, providing strong privacy assurances even in adversarial settings. This establishes a novel and complete Zero-Knowledge Proof of Differentially Private Stochastic Gradient Descent (ZK-DPSGD), uniting differential privacy and verifiable computation for secure and auditable ML. Our evaluation shows that prover time increases linearly with the number of input samples, while both verifier time (2–5 ms) and proof size (3–4 KB) remain compact and effectively constant.
Ben Hawkins, Joshua Levett, Siamak F. Shahandashti
We present a longitudinal measurement study on the adoption of detectable, second-generation anonymisation protocols in the Bitcoin network, including CoinJoin, CoinSwap, CoinShuffle and Stealth Addresses. By implementing and refining a suite of heuristic filters, we identify over 5.94 million CoinJoin and 23.3 million CoinSwap transactions. Besides, the use of CoinShuffle was unexpectedly found to be closely aligned with the Wasabi wallet operation period. Our analysis reveals consistently low adoption rates, with these protocols constituting less than 1% of network transactions, and a sharp decline in detectable usage following key regulatory events. Furthermore, we find no evidence of standardised Stealth Address adoption, indicating a failure to converge on a common privacy standard. This study provides a comprehensive picture of a niche ecosystem whose on-chain visibility has been largely suppressed, strongly suggesting the migration of privacy-seeking users to less transparent and less detectable methods.
Harlequin is a blockchain protocol in which the right to take part in consensus,governance and adjudication comes solely from reputation earned by verifiable acts— never from capital (proof of stake) or expended computation (proof of work).Reputation is a four-dimensional quantity ("the four suits"), computeddeterministically from a public evidence record by a damped trust-propagationfunction, aggregated conservatively (a strong dimension cannot buy authority in aweak one), and subject to time decay so that standing must be continuallyre-earned. Block authorship and committee/jury membership are assigned byreputation-weighted cryptographic sortition; finality is provided by aByzantine-safe gadget over signed votes; disputes are judged by sortitioned jurieswith interest-exclusion, and the only enforced consequence is reputational — theprotocol applies no coercive force. We give the system model, the consensus and justice mechanisms, and a securityanalysis against a state-level adversary whose goal is capture, censorship orde-anonymization rather than direct theft. Two results are emphasized for theirhonesty. First, steady-state Sybil resistance is strong: a Sybil farm withoutearned evidence obtains about 0% of consensus power (17/17 adversarial tests).Second, the cold-start window is not unconditionally safe: a competent adversarypresent at genesis can capture the bootstrap; we show the security of that windowis a race between honest onboarding and adversary mass — bounded, not eliminated,by non-operator personhood verification, an automatic ceiling-halt and theonboarding rate, with the residual risk declared. We report an implementation inRust (dependency-free cores cross-validated against FRAME pallets) and areproducible validation record spanning unit tests and multi-node hardware runs.
Distributed certification is a set of mechanisms that allows an all-knowing prover to convince the units of a communication network that the network's state has a desired property, such as being 3-colorable or free of a predefined subgraph. Classical mechanisms, such as proof labeling schemes (PLS), consist of a message from the prover to each unit, followed by one round of communication among neighbors. Later works consider extensions, called distributed interactive proofs, where the prover and the units can have multiple rounds of communication before the communication among the units. Recently, Bick, Kol, and Oshman (SODA '22) defined a zero-knowledge version of distributed interactive proofs, where the prover convinces the units that the network satisfies the property without revealing any additional information about the network's state or structure.
With the rapid proliferation and interconnection of massive IoT devices, efficient and secure identity authentication has become a crucial prerequisite for ensuring communication security. Establishing trust among mutually untrusted devices remains a key research focus. Leveraging its tamper-resistance and traceability, blockchain technology has emerged as a foundational infrastructure for building trustworthy identity management systems. However, existing blockchain-based identity authentication schemes face critical challenges in large-scale IoT environments, including low authentication efficiency, complex certificate management, and risks of user privacy leakage. Achieving a balance among authentication efficiency, certificateless key management, and privacy protection remains a pressing challenge. In this paper, we propose a certificateless identity authentication scheme based on blockchain sharding. The scheme employs blockchain sharding to parallelize identity authentication across multiple shards, significantly enhancing overall efficiency. Within each shard, a certificateless public key cryptography (CL-PKC) scheme is adopted to eliminate certificate issuance and enable key generation via user interaction, thereby reducing key management overhead and improving security. For cross-shard authentication, a registration-based encryption (RBE) mechanism is utilized, allowing users to authenticate via their identity after registration. Any verifier can confirm the legitimacy of the authentication message solely based on the registration information and the user ID, ensuring transparency and public verifiability. Furthermore, a zero-knowledge proof-based verifiable credential (VC) selective disclosure mechanism is introduced, enabling users to reveal only the minimal necessary information required for authentication while protecting sensitive identity attributes. Experimental results demonstrate that the proposed scheme maintains high throughput under high-concurrency scenarios while effectively preserving user privacy.
Open access
2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Advanced Steganography and Watermarking Techniques
Health care data management comes with numerous barriers as a result of the use of different systems of record keeping, which are not compatible and increase the risks for data protection and privacy. Medical records are frequently distributed throughout various clinics and hospitals, and due to this it is hard to share information when patients are being treated. Centralized record systems bring unauthorized access to records and the problems related to the safety of data. In order to enhance the level of confidence of people and improve the level of transparency of health care data, advanced people choose decentralized technologies and uses cryptography for these purposes. Blockchain technology offers an unchangeable and decentralized ledger that guarantees safe monitoring of all information despite the presence of any centralized body. Coupled with sophisticated encryption methods, it provides the ability to limit access to private health information. In order to provide secure and respect privacy regarding medical data sharing, an Electronic Health Record (EHR) system powered by blockchain technologies is proposed. Patient record metadata is recorded on-chain while health data itself is stored on encrypted off-chain storage. In the realm of access management, smart contracts facilitate patients in designating by whom their records can be accessed and modified. The privacy of information is further strengthened by advanced cryptographic techniques like attribute-based encryption and zero-knowledge proofs. The system provides seamless interoperability among hospitals, laboratories, and telemedicine systems while ensuring high levels of security. The results of performance evaluation demonstrate that this method facilitates reliable transaction processing while providing better security, transparency and control than traditional centralized EHR systems.
Smart contracts have achieved significant success, however, their security remains a long-standing challenge. The immutability and transparency of smart contracts require establishing a strong mechanism to prevent private leakage and trusted data tampering. Apart from traditional logic and code-level vulnerabilities arising from insufficient control over contract variables and function parameters, smart contracts may store private-dependent information in blockchain records, which is a critical type of vulnerability, but often overlooked in existing security analysis. In this paper, we present an automated approach for synthesizing security policies, named SmartIFSyn, to eliminate information flow vulnerabilities in smart contracts. We formalize the semantics of Solidity, the most widely used smart contract language, and analyze information flow security of Solidity smart contracts from two perspectives: local-variable security and global-interaction security. We present a type system to guide the elimination of local-variable vulnerabilities by inferring a policy and resort to constraint solving to synthesize a desired policy in case that the type system fails. The policy ensures both local-variable and global-interaction security while it is maximally aligned with user preference. Furthermore, the policy can be subsequently converted into enforceable specifications. We implement our approach in a tool and evaluate it on 17,160 real-world Ethereum smart contracts. The experimental results demonstrate the efficacy of our approach, e.g., detected 243 vulnerabilities in 223 real-world Ethereum smart contracts.
Jun 30, 2026·Proceedings of the Workshop on Advanced Tools, Programming Languages, and PLatforms for Implementing and Evaluating algorithms for Distributed systems
This article addresses the security of Federated Learning (FL) in distributed systems against a range of attacks, including model poisoning and unverifiable client behavior, while ensuring the semantic correctness of gradient updates. It proposes ZK-FedLedger, a verifiable and adaptive FL framework that integrates multi-constraint zero-knowledge proofs with a reputation-weighted Byzantine fault-tolerant blockchain consensus. Each client generates a zk-SNARK proof certifying that its update satisfies both an adaptive norm bound and a geometric alignment constraint relative to a trusted reference gradient. Verified commitments are recorded on-chain, while model parameters are aggregated off-chain using a hybrid storage architecture that minimizes blockchain overhead. Experimental evaluation on MNIST demonstrates stable convergence, with test accuracies of 98.17% (IID) and 94.93% (Non-IID), and near-perfect detection of major poisoning attacks. The results show that ZK-FedLedger enables proactive, cryptographically verifiable FL without compromising scalability or model performance.
Understanding Proof-of-Work in Blockchain: Foundations, Security, and Limitations Keywords: Blockchain, Consensus, Proof-of-Work, Cryptographic Hash, Cryptography, 51% Attack. 1. Introduction In traditional distributed systems, such as banking databases, a central authority determines transaction validity. In contrast, decentralized networks like Bitcoin lack a central server, allowing unrestricted participation. This structure introduces two significant challenges:This results in two critical challenges: 1. The Byzantine Generals Problem: How do independent nodes agree on a single history of data if some nodes are malicious or untruthful? 2. Sybil Attacks: What stops an attacker from creating 10 million fake virtual nodes to vote and overpower honest nodes? Proof-of-Work (PoW) addresses both challenges. Instead of assigning one vote per identity, which is susceptible to falsification, PoW allocates voting power according to computational resources, which require significant hardware and energy investment. 2. The Core Mechanics: How Mining Actually Works Mining functions as a network-wide lottery, where the probability of success is proportional to computational speed. The process begins with solving a cryptographic puzzle. 2.1 The Cryptographic Puzzle A block consists of a batch of transactions, the hash of the previous block, and a field called a nonce (number used once). Miners repeatedly modify the nonce until the hash of the entire block matches a specific pattern.Specifically, the resulting hash must be less than or equal to a predetermined target value. +---------------------------------------------------------+ | BLOCK HEADER | | [Prev Hash] + [Merkle Root (TXs)] + [Timestamp] + [Nonce] | +---------------------------------------------------------+ | v SHA-256 Hashing | v Is the Hash < Target Threshold? / \ YES NO / \ [Success! Broadcast Block] [Increment Nonce & Try Again] Because SHA-256 is a cryptographic hash function, it has two key properties: Pre-image Resistance (One-Way): You cannot reverse-engineer a hash. If I give you a hash output, you cannot calculate the input. Avalanche Effect: Changing just one bit in the nonce completely alters the final hash output unpredictably. As a result, no mathematical shortcut exists for determining the correct nonce. Miners must use brute-force computation, generating billions of hashes per second (hash rate) until a valid solution is identified (Hash Rate — Measuring Bitcoin's Mining Power, 2026). Once a solution is found, the miner broadcasts the block, and other nodes verify it instantly with a single hash calculation, illustrating computational asymmetry. This mechanism maintains the network's equilibrium. 2.2 Difficulty Adjustment When additional miners join the network, the aggregate hash rate increases, resulting in faster block discovery. To maintain consistent block times, the protocol automatically adjusts the target threshold.If blocks are being found faster than the target time (e.g., 10 minutes in Bitcoin), the target number decreases. A smaller target means the hash must start with more leading zeros, making it statistically harder to guess. 3. Security Framework: The Rules of Engagement PoW operates on the economic principle that securing the network should be more profitable than attacking it. The following rule defines the network's dispute resolution mechanism. 3.1 The Longest Chain Rule If two miners simultaneously discover valid blocks, the network temporarily splits into two branches, known as a fork. Nodes resolve this by following the longest chain, which is defined as the branch with the greatest accumulated proof-of-work, thus maintaining a unified transaction history. [Block 101] ---> (Orphaned / Dropped) / ---- [Block 100] --+ \ [Block 101] ---> [Block 102] <--- Longest Chain (Accepted) 3.2 The 51% Attack If an attacker manages to control more than 50% of the network’s total computing power, they can out-mine the honest portion of the network.An attacker may mine a private chain in secret, spend coins on the public chain, and later broadcast the longer private chain. According to the longest chain rule, the network accepts the attacker's version of history, thereby invalidating transactions on the honest chain. This scenario, known as a Double-Spend Attack, highlights a significant vulnerability and contributes to ongoing criticism of PoW despite its security advantages. 4. Why the Industry is Moving Away from PoW While PoW is incredibly secure, it has two major flaws that make it difficult to scale for modern applications. 4.1 The Scalability Problem In PoW systems, each full node must process and store every transaction for verification. Due to limited block sizes and intentionally high block times to prevent network desynchronization, transaction throughput remains low. For example, Bitcoin processes approximately 7 transactions per second (TPS), whereas Visa handles thousands of TPS. 4.2 Energy Consumption Miners compete to achieve the highest hash rate by continuously operating large-scale data centers equipped with specialized hardware (ASICs). This process consumes substantial amounts of electricity, comparable to the consumption of a medium-sized country, and results in significant environmental impact. 5. Conclusion Proof-of-Work constituted a significant advancement in computer science by linking digital consensus to physical resource constraints, particularly energy. This innovation demonstrated the feasibility of decentralized trust. However, due to limited throughput and substantial energy requirements, newer blockchain networks increasingly adopt alternative consensus mechanisms, such as Proof-of-Stake (PoS), where voting power is determined by cryptocurrency holdings rather than energy expenditure. References Nakamoto, S. (2008). Bitcoin: A Peer-to-Peer Electronic Cash System. (The original whitepaper). Eyal, I., & Sirer, E. G. (2014). Majority is not enough: Bitcoin mining is vulnerable. (Introduced the concept of Selfish Mining). Narayanan, A., et al. (2016). Bitcoin and Cryptocurrency Technologies. Princeton University Press. (An excellent foundational textbook for CS students). (2026). Hash Rate — Measuring Bitcoin's Mining Power. Bitcoin Notes Online. https://www.bitcoinnotesonline.com/learn/hash-rate
Blockchain technology has transformed digital transactions by providing decentralized, immutable, and transparent ledgers that eliminate the need for centralized intermediaries. However, the inherent transparency of blockchain networks often exposes sensitive transaction details, creating significant privacy concerns for users and organizations operating in sectors such as finance, healthcare, supply chain management, and digital identity management. Balancing transparency with confidentiality has therefore become a critical challenge in the evolution of blockchain systems. Zero-Knowledge Proofs (ZKPs) have emerged as a revolutionary cryptographic solution that enables one party to prove the validity of a statement without revealing the underlying confidential information. This paper proposes a comprehensive framework for integrating Zero-Knowledge Proof mechanisms into blockchain systems to enhance transaction privacy while preserving transparency, security, and verifiability. The framework incorporates advanced cryptographic protocols, including zk-SNARKs and zk-STARKs, together with decentralized consensus mechanisms to achieve secure and efficient verification of blockchain transactions. The proposed approach evaluates system performance in terms of privacy preservation, computational efficiency, scalability, verification accuracy, and transaction throughput. The findings indicate that Zero-Knowledge Proof-based blockchain architectures significantly improve user privacy, reduce information leakage, strengthen security against malicious attacks, and maintain the transparency and integrity required for decentralized trust. The proposed framework provides a scalable and secure foundation for next-generation blockchain applications requiring both confidentiality and public verifiability.