Ahmed Sayed M. Metwally, Yazeed Alhumaidan, Saad Alzahrani, Mohamed H. Abdelati
Implementing artificial intelligence (AI) and blockchain technology in management systems transforms traditional libraries into advanced information centers that are data-driven and effectively managed. While these technologies enhance efficiency and operational capabilities, they also present two critical challenges: data privacy and ethical concerns. This study examines the role of AI and blockchain in library management, focusing on issues related to data privacy and ethical challenges that arise from their use. It also offers best practices to ensure safe implementation. The research adopts a comprehensive mixed-methods approach, involving qualitative interviews and quantitative surveys to identify these challenges within the system architecture, assess the effectiveness of current designs, and propose a complete framework using privacy-preserving technologies. This framework incorporates innovative cryptographic techniques, including homomorphic encryption, differential privacy, and zero-knowledge proofs, providing a novel model for the ethical use of AI in libraries. The findings indicate that robust data protection, transparency, and accountability are essential to building trust in AI-powered library services.
G. Ramesh, Kiran Raj K M, Anagha Ankolekar, Gautam Kamath · 5 authors
Social media has significantly altered the way we interact and connect. However, with unprecedented connectivity and information availability, significant challenges arise concerning data privacy, ethics, and transparency. The paper explores the intersection of data ethics and privacy within social media, particularly unclear privacy policies, biased algorithms, and the spread of misinformation. This paper not only explores these challenges but also examines emerging solutions such as Self-Sovereign Identity (SSI) and regulatory measures like GDPR. It emphasizes the need for clear consent, openness, and accountability from platform providers to protect user data and ensure fairness. The paper also explores how emerging technologies like SelfSovereign Identity (SSI) and Web3 can give users more control over their data, helping to reduce misuse. In addition, it discusses ethical challenges related to algorithmic decision-making and misinformation, proposing ways to detect and prevent harm. Lastly, the paper calls for a rethink of “Tech Ethics>” that is more focused on social welfare and redressing inequalities. Using a thorough and analytical approach, this paper aims to create a culture of privacy that encourages participation and supports stronger regulations to address data ethics issues in today's fastevolving digital landscape.
In an increasingly digital world, establishing secure and reliable methods for verifying identity has become a critical priority across sectors such as finance, healthcare, education, and e-governance. Traditional authentication mechanisms—relying on passwords, personal identification numbers, and physical documents—are increasingly susceptible to fraud, data breaches, and user inconvenience. This paper presents a multi-modal biometric framework for digital identity management, integrating facial recognition and fingerprint verification to enhance accuracy, reduce fraud, and ensure user-centric security. The proposed system includes modules for data acquisition, preprocessing, feature extraction using Convolutional Neural Networks (CNNs) and minutiae detection, score-level fusion, and final authentication decisions. Security and privacy are ensured through AES-256 encryption, differential privacy techniques, and decentralized blockchain-based data storage. This research contributes a scalable, privacy-aware, and highly accurate digital identity model capable of addressing challenges such as interoperability, user trust, and regulatory compliance. Future enhancements include the integration of additional biometric modalities and deployment in mobile and IoT environments.
The rapid adoption of Federated Learning (FL) in privacy-sensitive domains such as healthcare, IoT, and smart cities underscores its potential to enable collaborative machine learning without compromising data ownership. However, conventional FL frameworks face several critical challenges: high computational overhead on edge devices, significant communication latency due to frequent model updates, vulnerability to model and data poisoning attacks, and limited privacy-preserving mechanisms that expose systems to inference risks. These issues hinder the scalability, efficiency, and trustworthiness of FL in real-world, large-scale deployments-particularly in domains like Electronic Health Records (EHR) management, where data sensitivity is paramount. To address these challenges, this paper introduces the Enhanced Privacy-Preserving Blockchain-Enabled Federated Learning (EPP-BCFL) framework, which integrates blockchain with hybrid privacy mechanisms and intelligent aggregation strategies. The architecture comprises three layers: (1) an Edge Nodes Layer for on-device learning; (2) a Federated Aggregation Layer using Secure Multi-Party Computation (SMPC) and Differential Privacy (DP); and (3) a Blockchain Layer with a lightweight PoS + BFT consensus mechanism. Experimental evaluation on CIFAR-10 demonstrates 95.2% accuracy, a 43% reduction in communication latency, a 37% decrease in computational cost, and robust defense against data/model poisoning and adversarial attacks. Attack resilience improved accuracy from 72.5 to 93.2%, while privacy budget tuning achieved 90.3% accuracy at ε = 1.0. Compared to state-of-the-art models, EPP-BCFL exhibits superior performance in terms of security, scalability, and support for edge device heterogeneity, validating its applicability in secure EHR management.
The traditional e-voting systems face a lot of challenges like unauthorized access to the data and there is no mechanism to self-verify the voter and has to depend on others for verification like election authorities. The election conducted through traditional e-voting system requires a lot of human interventions for conducting various processes like registration, tallying etc.). The current e-voting is also prone to hacking and has a lot of vulnerabilities. These vulnerabilities significantly weaken the electoral process integrity and efficiency. In order to address these issues, this research involves the development of a permissioned smart contract-based e-voting system for academic institutions suitable for the small size and medium size environments like universities etc. An Electronic voting(e-voting) system is a digital process where the elections are conducted through the electronics instead of the traditional voting system. The e-voting system provides transparency and increases the efficiency of the election process and also allows the people with disabilities to cast their votes remotely. The integration of blockchain technology with smart contracts is able to address the challenges of the traditional electronic system. The proposed system, i.e., permissioned smart contract e-voting system can maintain the transparency during the whole election process and prevent unauthorized access to the data and the fraudulent activities like voter tampering and fraudulent votes. This proposed system uses features or capabilities of blockchain technology specifically Hyperledger Fabric to establish a immutable and decentralized ledger. It also ensures the participation of the voters in a well-managed and controlled manner. It also eliminates the need for human intervention in the election process. Smart Contracts automates the whole election process and is responsible for voter registration, verification and vote tallying process. Voter data and credentials are secured and encrypted with the help of an encryption algorithm, i.e. Advanced Encryption System (AES) throughout the whole electoral process. Furthermore, this research contributes to the digital governance by demonstrating the practical use of this proposed system, i.e. permissioned blockchain system under a controlled environment. Compared to the traditional systems, the proposed framework or system can provide or demonstrate 45% improvement in operational efficiency, human intervention can also be reduced to 60% and there is a slightly huge decrease in the vote tampering and data breaches i.e. by 70%. Future enhancements includes biometric integration for voter authentication or voter verification. AI integrated, permissioned smart contract based e-voting system could be the future or future enhancement that uses facial recognition in order to improve voter authentication uses anomaly detection models to identify the potential threats.
Abstract— This research introduces a Blockchain-based Decentralized Application designed to address these issues. Leveraging Ethereum smart contracts and decentralized storage via IPFS, the application ensures secure peer-to-peer communication, immutable data storage, and enhanced transparency. By eliminating the need for centralized intermediaries, the Blockchain-based Decentralized Application empowers users, prioritizes data privacy, and fosters trust. This research introduces a Blockchain-based Decentralized Application designed to address these issues. Leveraging Ethereum smart contracts and decentralized storage via IPFS, the application ensures secure peer-to-peer communication, immutable data storage, and enhanced transparency. By eliminating the need for centralized intermediaries, the Blockchain-based Decentralized Application empowers users, prioritizes data privacy, and fosters trust. Index Terms—Distributed Ledger Technology(DLT), Smart Contracts, InterPlanetary File System(IPFS), Cryptographic Security.
Online growth leads organizations to demand protected systems that protect privacy while managing identities. Traditional identity systems maintain centralized control that exposes users to data breaches while requiring new security solutions. A blockchain-enabled identity management solution was designed to implement zero-knowledge proofs (ZKP) for authentication methods with distributed execution of user credentials. The system uses Ethereum alongside Hyperledger Fabric platforms and runs simulations through Hyperledger Caliper platforms. The results demonstrate significant improvements in key performance metrics: The system delivered verification accuracy at 98.7% privacy leakage reached 0.05% while transaction latency fell under 125 ms and TPS scalability reached 950. The proposed model delivered superior privacy guarantees and operating efficiency. Future advancements in decentralized identity management build upon a reliable platform that ensures both privacy preservation and secure identity solutions.
Bitcoin is a decentralized, pseudonymous ledger-based cryptocurrency where all transactions are public. Over time, various privacy-preserving techniques have emerged to address the de-anonymization of Bitcoin users. Meanwhile, newer cryptocurrencies have been developed with enhanced privacy features. This paper evaluates major privacy-focused strategies in Bitcoin and beyond, focusing on techniques still relevant as of 2025. We summarize well-known privacy attacks that de-anonymize Bitcoin, and analyze countermeasures deployed or proposed to protect user privacy. We also examine privacy mechanisms in other cryptocurrencies (e.g., Monero, Zcash) and compare their effectiveness. Finally, we discuss the current state of privacy in cryptocurrency usage, including key technical and regulatory challenges.
S. M. Dilip Kumar, Namrta Tanwar, Namrta Tanwar, Aakarsh Chandna · 5 authors
The blockchain technology has disrupted the earlyage digital banking through concepts like bitcoin and ether [1,3].In this study, some major elements of the blockchain technology are examined-decentralized networks, smart contracts, cryptographic techniques, and consensus mechanisms of Proof of Work and Proof of Stake usage-and understanding how they contribute to safe, peer-to-peer transactions without intermediaries [2,5].Bitcoin can do no more than about seven transactions a second (TPS) is a very paltry competition of an impressive 30 to 40 TPS of Ethereum.This depicts the ongoing scalability challenges that need to be tackled by initiatives linked with Ethereum 2.0 and the Lightning Network [4,9].While most industries, apart from banking, have effectively made their blockchain applications and transparency useful-Supply Chain Management, Healthcare, and DeFi-currently poses challenges of transaction speed limitations, the vagueness of regulations, and energy consumption by mining [8].Emerging trends include Non-Fungible Tokens (NFTs), Central Bank Digital Currencies (CBDCs), and privacy enhanced through zero-knowledge proofs.There is hope for excellent feedback on the future of the blockchain from these and other initiatives yet to come into reality.
Smart contracts have been a topic of interest in blockchain research and are a key enabling technology for Connected Autonomous Vehicles (CAVs) in the era of Web 3.0. These contracts enable trustless interactions without the need for intermediaries, as they operate based on predefined rules encoded on the blockchain. However, smart contacts face significant challenges in cross-contract communication and information sharing, making it difficult to establish seamless connectivity and collaboration among CAVs with Web 3.0. In this paper, we propose DeFeed , a novel secure protocol that incorporates various gas-saving functions for CAVs, originated from in-depth research into the interaction among smart contracts for decentralized cross-contract data feed in Web 3.0. DeFeed allows smart contracts to obtain information from other contracts efficiently in a single click, without complicated operations. We judiciously design and complete various functions with DeFeed , including a pool function and a cache function for gas optimization, a subscribe function for facilitating data access, and an update function for the future iteration of our protocol. Tailored for CAVs with Web 3.0 use cases, DeFeed enables efficient data feed between smart contracts underpinning decentralized applications and vehicle coordination. Implemented and tested on the Ethereum official test network, DeFeed demonstrates significant improvements in contract interaction efficiency, reducing computational complexity and gas costs. Our solution represents a critical step towards seamless, decentralized communication in Web 3.0 ecosystems.
Marco A. C. da Silva, Luis Hideo Vasconcelos Nakamura, Geraldo P. Rocha Filho, Luís Veiga · 5 authors
With the advancement of technologies for data registration in distributed networks, the concern of users and developers of computerized solutions with the privacy of sensitive data has increased. Thus, this work addresses a conceptual solution for an ontology-based framework so that any entity willing to provide a service using Distributed Ledger Technology (DLT) networks can model the set of privacy attributes of its system according to the business rules of its service. The solution proposed in this work encompasses the development of an architecture aimed at providing computational support for the privacy design of the actors involved in the offering and consumption of services implemented in DLTs. The architecture also includes a framework called ONSPRIDE, which uses previously stored domain ontologies to translate business rules into requirements and privacy. We conducted a proof of context by comparing the performance of two Hyperledger Fabric networks. For this purpose, we conducted a controlled experiment in which both networks operate a smart contract that manages attendance records for outdoor events. The main difference between the networks is that one uses a Certificate Authority (CA) to issue access certificates, while the other issues certificates manually. We compared the results obtained through the reports generated by the Hyperledger Caliper tool. In addition, the performance of the initialization and connection of agents in a Self-Sovereign Identity system was measured. The results of this study provide valuable insight that can help developers choose the most suitable ledger type for their Hyperledger projects and support decision-making regarding adopting a Self-Sovereign Identity system.
Stablecoins, a type of cryptocurrency pegged to another asset to maintain a stable price, have become an important part of the cryptocurrency ecosystem. Prior studies have primarily focused on examining the security of stablecoins from technical and theoretical perspectives, with limited investigation into users' risk perceptions and security behaviors in stablecoin practices. To address this research gap, we conducted a mixed-method study that included constructing a stablecoin interaction framework based on the literature, which informed the design of our interview protocol, semi-structured interviews (n=21), and Reddit data analysis (9,326 posts). We found that participants see stable value and regulatory compliance as key security advantages of stablecoins over other cryptocurrencies. However, participants also raised concerns about centralization risks in fiat-backed stablecoins, perceived challenges in crypto-backed stablecoins due to limited reliance on fully automated execution, and confusion regarding the complex mechanisms of algorithmic stablecoins. We proposed improving user education and optimizing mechanisms to address these concerns and promote the safer use of stablecoins.
Traditional voting systems face significant challenges in transparency, security, and trust, compromising their credibility and effectiveness. To address these issues, this study proposes a lightweight voting system that integrates blockchain technology with a simplified Multifactor Authentication (MFA) model, relying solely on voter ID verification and One-Time Password (OTP) mechanisms. By leveraging blockchain's decentralized and immutable ledger, the system ensures secure, tamper-proof recording of votes while maintaining transparency. The lightweight authentication approach balances security and efficiency, with voter ID verifying eligibility and OTP adding a real-time layer of authentication without the need for additional hardware or complex biometrics. Smart contracts automate voting operations, providing auditable results while reducing reliance on intermediaries. This streamlined integration significantly improved accuracy by 25%, reduced processing times by 30%, and strengthened voter trust by 40% compared to traditional systems. The proposed solution demonstrates a practical, scalable framework for secure and transparent voting, with potential applications in corporate governance, online referenda, and decentralized autonomous organizations (DAOs).
As healthcare systems evolve and healthcare data grows, the need for cross-domain collaboration treatment has become more complex, necessitating fine-grained access control to enhance privacy and security. Blockchain provides a distributed trusted platform without third parties, but the current blockchain-based access control systems lack efficiency and sufficient privacy protection in cross-domain collaboration. To address these challenges, we propose SWIFTGUARD, an efficient and fine-grained access control system based on a master-slave chain to strengthen the security and privacy of cross-domain healthcare collaboration. SWIFTGUARD incorporates a zero-knowledge proof protocol for cross-domain authentication with-out exposing sensitive data and leverages quantitative attribute weights for efficient access control. Through game-based security proof, we demonstrate the zero knowledge and soundness of the system. Extensive experiments evaluate that SWIFTGUARD reduces the time complexity of access authorization from O($n$) to O(log$n$), with improved throughput and stable performance in cross-domain collaboration. Our comprehensive evaluation confirms that SWIFTGUARD provides a secure and efficient access control system for cross-domain healthcare collaboration.
This article explores the complex intersection of technological innovation and privacy considerations in cloud identity management systems. It traces the evolution from traditional authentication methods to sophisticated cloud-based frameworks that now incorporate adaptive authentication, federation protocols, biometric verification, and behavioral analytics. While these advances enhance security and user experience, they simultaneously introduce profound privacy challenges regarding data collection scope, user profiling, and cross-platform tracking. The article examines how regulatory frameworks, industry self-regulation, and stakeholder perspectives shape the governance landscape of digital identity. Drawing on interdisciplinary research, the article reveals how trust formation in digital environments correlates with transparency practices and how trust erosion carries consequences beyond immediate user relationships. Looking forward, emerging technologies like decentralized identity and zero-knowledge proofs offer promising privacy-preserving alternatives, while evolving market dynamics and user expectations create both challenges and opportunities. The article concludes with actionable recommendations for designing and implementing identity systems that achieve an optimal balance between robust security, operational efficiency, and respect for individual privacy rights—a critical imperative for sustainable digital ecosystems in increasingly connected societies.
Tarek Galal, Valeria Tisch, Katja Assaf, Andreas Polze
Railways provide a critical service and operate under strict regulatory frameworks for implementing changes or upgrades. Despite their impact on the public, these frameworks do not define means or mechanisms for transparency towards the public, leading to reduced trust and complex tracking processes. We analyse the German guideline for railway-infrastructural modifications from proposal to approval, using the guideline as a motivating example for modelling decisions in processes using digital signatures and zero-knowledge proofs. Therein, a verifier can verify that a process was executed correctly by the involved parties and according to specification without learning confidential information such as trade secrets or identities of the participants. We validate our system by applying it to the railway process, demonstrating how it realises various rules, and we evaluate its scalability with increased process complexities. Our solution is not railway-specific but also applicable to other contexts, helping leverage zero-knowledge proofs for public transparency and trust.
Hao Wu, Maha Abdallah, Yuanfang Chi, Lehao Lin · 5 authors
In the Web3 ecosystem, multimedia applications exhibit significant potential by leveraging decentralization, regarded as the core spirit of Web3. This survey aims to provide a comprehensive overview of the potential of decentralization in shaping multimedia applications in the Web3 ecosystem. Through a systematic review of the academic research conducted over the past decade on Web3 decentralization, we identify the two key distinctive decentralization characteristics (decentralized assets and decentralized participation). Subsequently, we comprehensively analyze Web3 applications from both technology and application dimensions. Building upon this, we focus on multimedia-related aspects and propose an architecture for Web3 multimedia applications. In contrast to the broader scope of Web3 applications, the unique aspects of Web3 multimedia applications reside in their core application components (non-fungible tokens and smart contract-based rules) and core application domains (art, games, and social media). Based on this architecture, we provide a precise definition of Web3 multimedia applications. Lastly, through the lens of the two identified distinctive decentralization characteristics, we investigate the advantages, development, and limitations of Web3 multimedia applications within the three core application domains, namely crypto art, blockchain games, and blockchain on social media (BOSM). Furthermore, we share our insights into several promising yet challenging directions, covering the interoperability and potential of increasingly valuable multimedia content, as well as the delicate balance between centralization and decentralization.
Federated Learning (FL) has emerged as a transformative paradigm in the field of distributed machine learning, enabling multiple clients such as mobile devices, edge nodes, or organizations to collaboratively train a shared global model without the need to centralize sensitive data. This decentralized approach addresses growing concerns around data privacy, security, and regulatory compliance, making it particularly attractive in domains such as healthcare, finance, and smart IoT systems. This survey provides a concise yet comprehensive overview of Federated Learning, beginning with its core architecture and communication protocol. We discuss the standard FL lifecycle, including local training, model aggregation, and global updates. A particular emphasis is placed on key technical challenges such as handling non-IID (non-independent and identically distributed) data, mitigating system and hardware heterogeneity, reducing communication overhead, and ensuring privacy through mechanisms like differential privacy and secure aggregation. Furthermore, we examine emerging trends in FL research, including personalized FL, cross-device versus cross-silo settings, and integration with other paradigms such as reinforcement learning and quantum computing. We also highlight real-world applications and summarize benchmark datasets and evaluation metrics commonly used in FL research. Finally, we outline open research problems and future directions to guide the development of scalable, efficient, and trustworthy FL systems.
Recently, the DAO (Decentralized Autonomous Organization), where participants make decisions equally through online voting, has been gaining attention, while traditional methods involve a multi-stage approach, beginning with discussions among stakeholders to extract key issues and followed by evaluations from randomly selected citizens. However, it remains unclear which issues will gain social acceptance under these different methods. This study investigates whether the evaluation of these processes differs depending on the type of issues. A web-based questionnaire survey was conducted using a between-participants two-factor design with a scenario experiment. Participants read scenarios on local community issues (whether to build a geothermal power plant or how to revitalize a shopping district) and decision frameworks (decentralized online or multi-stage decision-making) and responded to related questions. The results indicated that decentralized online struggles with issues involving significant conflicts of interest. However, it is more accepted when applied to relatively low-conflict issues where participants feel empowered.
Mary C. Lacity, Dan Conway, Kiran Garimella, Erran Carmel
This chapter has two purposes. First, we describe how information system (IS) scholars approach privacy research and summarize major findings. IS scholars are concerned with information privacy and have discovered that individuals have serious information privacy concerns. These concerns, however, do not prevent individuals from disclosing personal identifiable information (PII) to centralized platform providers, a phenomenon called the privacy paradox . We highlight four common explanations for the privacy paradox: privacy calculus, privacy fatigue, trust, and lack of choice. Most IS privacy research, to date, has investigated Web2 applications – which is the foundation for today’s global online economy. With Web2, users rely on centralized platforms for online searching, shopping, banking, data storage, social media, and other services. Second, we introduce scholars to the next frontiers of human privacy with three emerging solutions: decentralization (Web3), multi-party computation (MPC), and zero-knowledge proofs (ZKPs). Web3 applications enhance information privacy compared to Web2 because individuals can access services without disclosing PII to a central authority. The privacy objective is achieved technically through a combination of digital wallets, cryptography, and distributed ledgers (a.k.a. blockchain). Multi-party computation is an innovative approach to calculating information among trusted parties without revealing anyone’s confidential data. It’s a way to answer common questions among trusted parties, such as “Am I paying the same for materials?” and “Does anyone else see suspicious cybersecurity activity on their networks?” Finally, we explain ZKP as a method by which one party can prove to another that they possess a particular identity, item, or piece of knowledge without revealing the specifics of what that identity, item, or knowledge is. Unlike MPC, some types of ZKPs do not require a priori trust; instead, trading partners trust mathematical proofs. Together, Web3, MPC, and ZKPs potentially offer organizations and individuals enhanced online privacy but collectively require more research and field experience.
The collection and application of health care data are crucial for advancing research and improving healthcare. However, privacy and security concerns, particularly with sensitive data, pose significant challenges. Traditional identity-based verification systems, which rely on centralized servers, struggle in medical contexts due to regional data management complexities and the vulnerabilities of centralized models. In this paper, we propose MedZKChain, a privacy-preserving health care device verification system designed to address these challenges. By combining blockchain technology with zero-knowledge proofs, MedZKChain enables decentralized device attribute verification while ensuring data integrity and privacy. The system provides a solution for managing the access of medical records in different regions. MedZKChain leverages decentralized storage to reduce blockchain burden and uses zero-knowledge proofs to allow for secure verification and access authorization without revealing sensitive data. Experimental results demonstrate that, when authorized querying 1,500 patient data records, the proof size in MedZKChain remains less than 100 KB, the proving time is less than 3 seconds, and the verification time is below 0.8 seconds. These results highlight the system efficiency, scalability, and its effectiveness in enabling decentralized, verifiable.
Joy Nnenna Okolo, Adesola Adul-Gafar Arowogbadamu, Samuel Adetayo Adeniji, Rhoda Kalu Tasie
The rapid adoption of mobile AI applications in areas such as healthcare, finance, and personalized services has raised significant concerns about data privacy and security. Traditional centralized machine learning (ML) models require mobile devices to transmit user data to cloud servers, posing risks of data breaches and regulatory non-compliance. Federated learning (FL) addresses these concerns by allowing decentralized AI model training directly on user devices, ensuring that raw data remains private and never leaves the device. However, FL faces security vulnerabilities and performance limitations, including model inversion attacks, data poisoning risks, and high computational overhead. This paper explores key privacy-preserving techniques such as differential privacy, secure aggregation, and homomorphic encryption, which enhance FL security while maintaining model accuracy. Additionally, emerging trends such as blockchain-integrated FL, post-quantum cryptography, and AI-driven optimization are analyzed to highlight the future of privacy-preserving mobile AI ecosystems. By integrating advanced cryptographic techniques and decentralized verification mechanisms, FL can enable scalable, secure, and regulation-compliant AI applications, ensuring a balance between data privacy and AI innovation.