Digital twins are digital representations that enable real-time monitoring, analysis, andprediction of outcomes of physical systems. They depend on continuous communicationto work, which increases the attack surface of the system and introduces security risks,especially regarding unauthorized access to digital twin data and operations. This thesisinvestigates how blockchain-based smart contracts can be used as an authorization mech-anism for a digital twin, by implementing a digital twin for a Crazyflie 2.1 and controllingaccess to it through a smart contract-based authorization layer.A prototype of this system was developed using Python and connected to the physicalUAV using the Crazyradio interface. Flight data was collected and used to identify a sim-plified digital twin representing the vertical subsystem. A blockchain-based authorizationlayer with role-based permissions was then implemented using Solidity smart contracts ina local Hardhat environment.The findings from this thesis show that such a system is feasible to implement. Flighttest runs show that the twin remained numerically stable at all times and estimated thephysical UAV’s state with bounded error. The authorization mechanism enforced the de-fined role-based access-control rules in the tested scenarios, with measured authorizationlatency in the local environment around 14–15 ms. Gas measurements were also used toestimate the relative computational cost of the smart contract operations.
Smart contract security research has historically emphasized exploit-driven threat models developed for open, permissionless blockchain environments. While effective for identifying adversarial attacks and loss-of-funds scenarios, these models are insufficient for institutional blockchain systems supporting Real-World Assets (RWAs). In regulated and asset-backed deployments, threats frequently arise from non-adversarial actors, design assumptions, operational dependencies, and compliance enforcement failures rather than from direct malicious exploitation.This paper presents a structured threat taxonomy tailored to institutional RWA smart contract systems. The taxonomy classifies threats according to origin, intent, capability, and impact, explicitly incorporating adversarial, non-adversarial, and systemic threat sources. By decoupling threat analysis from exploit-centric assumptions, the taxonomy enables correctness-oriented risk assessment, formal specification of threat boundaries, and alignment with institutional audit and compliance requirements. The proposed framework provides a foundation for secure system design, verification, and operational governance in regulated blockchain environments.
Reentrancy remains one of the most persistent and damaging vulnerabilities in Ethereum smart contracts, enabling adversaries to recursively drain funds despite the presence of static and runtime defenses. Existing studies mainly focus on detection or program analysis, but they do not explain why and under what conditions attackers decide to exploit. In this work, we introduce a decision-theoretic framework that models reentrancy as a profit-maximizing problem under gas, risk, and atomicity constraints. Our framework derives the conditions under which reentrancy attacks are economically viable and provides an algorithm for computing optimal exploit strategies. We further extend the analysis to multi-contract attacks, capturing sequential, parallel, and optimized execution strategies. A simulation environment evaluates profitability across varying balances and gas configurations, highlighting thresholds where attacks become infeasible. Finally, we translate attacker decision profiles into practical defense recommendations for developers, auditors, and DeFi system designers. This framework bridges the gap between exploit detection and adversarial economics, offering a rigorous basis for strengthening smart contract security. This framework establishes a theoretical baseline for adversarial economics in smart contract security, forming a foundation for future MEV-aware exploitability models and Layer-2 risk analysis.
<b><i>Bribe-Based Oracle Echoes</i></b> describe a class of incentive-layer attacks in which economically rational adversaries influence oracle participants to repeatedly reinforce distorted data outputs without directly compromising oracle infrastructure. Unlike overt oracle manipulation, these attacks exploit incentive alignment and tolerance-band logic to create feedback loops in which biased signals are echoed, amplified, and normalized across decentralized finance (DeFi) and stablecoin systems. This paper formalizes the threat model, identifies structural enablers, and demonstrates why decentralization alone is insufficient to prevent economically induced oracle drift.
Ambati Satya Sai Vaishnavi, M. Veera kumari, K. Akash Sai, G. Pavan Kiran · 7 authors
Peer-to-peer (P2P) energy trading has emerged as an innovative solution to modern energy challenges by enabling decentralized electricity exchange among users. The Small-scale market allows prosumers to sell excess energy directly to consumers without relying on centralized authorities. Blockchain ensures transparency, security, and immutability of transactions, while smart contracts automate trading operations based on predefined conditions. A MATLAB-based simulation environment is developed to model energy generation, consumption, and transaction processes, along with a digital ledger for recording trades. The results of different case studies demonstrate efficient energy utilization, reduced transaction costs, and improved reliability. The system promotes renewable energy adoption and supports the transition toward decentralized smart grids. This work highlights the feasibility of integrating blockchain technology with energy systems for sustainable and scalable power trading solutions.
Blockchain technology improves supply chain management by ensuring the immutability of transaction records and facilitating process tracking. However, the transparency of blockchain raises significant privacy concerns, as sensitive information such as buyer and supplier qualifications, product specifications, and transaction amounts is often exposed. Compliance verification, which needs access to specific sensitive data for compliance checks, becomes challenging in blockchain-based privacy-preserving supply chains. This paper introduces ZKVeil, an innovative scheme utilizing zero-knowledge proof technology to maintain the confidentiality of sensitive information while ensuring compliance verification. Additionally, ZKVeil uses decentralized identifiers and verifiable credentials to ensure the authenticity of transaction data. A theoretical security analysis demonstrates the effectiveness of ZKVeil in safeguarding real sensitive data and ensuring compliance with regulations. To evaluate the performance of our scheme, we implement ZKVeil on a private blockchain of 100 nodes. Taking the shipbuilding supply chain transaction as an example, the experimental results demonstrate that ZKVeil incurs low gas consumption, execution time, and memory overhead.
Blockchain-based decentralized identity (DID) technology provides a more secure and efficient paradigm for identity verification. However, along with the promotion of applications, data storage of DID has gradually become one of the restrictions for the implementation due to the dramatically increasing size of the distributed ledger, and the issue becomes more complicated when considering the diversity of practical conditions and interoperability. In this article, we propose a scalable on-chain-off-chain storage for decentralized identity (SCOOP) scheme to minimize the total storage cost of blockchain-based DID while guaranteeing the efficiency of the implementation. The proposed scheme consists of a two-phase decision-making process, and a method that integrates the on-chain storage with off-chain storage in a scalable manner, so that an optimal storage task scheduling can be generated. In addition, to reduce on-chain storage overhead, we propose a multilinear tree-based commitment scheme that supports sublinear proof aggregation and updates. Our experiment evaluations have demonstrated that the proposed scheme can successfully achieve a superior performance in storage saving for DID while considering the time constraint.
Shraddha M. Naik, Huned Materwala, Davor Svetinović
Maximal Extractable Value (MEV) poses significant threats to the security and fairness of Ethereum's decentralized finance ecosystem by enabling participants to exploit transaction ordering to extract profits at the expense of others. Heuristic-based detection methods have been widely adopted to identify MEV transactions such as sandwich, arbitrage, and liquidation. However, a lack of standardized evaluation across heuristics limits the ability to compare their detection behavior and computational characteristics. This paper presents a unified experimental framework to systematically evaluate the detection capabilities, agreement rates, and resource efficiency of existing heuristic approaches. An agreement metric is introduced to quantify consistency across detection methods. Additionally, we assessed resource utilization and execution time to evaluate computational scalability. Our empirical findings reveal that while these approaches exhibit scalability, their reliability, measured in terms of detection consistency, varies significantly across different MEV types. Agreement rates averaged 0.53 for sandwich detection, 0.40 for arbitrage, and 0.81 for liquidation, highlighting substantial differences in detection capabilities and heuristic formulations. These findings offer valuable insights into the practical challenges of achieving consistent MEV detection and highlight the need for developing more robust security countermeasures.
The increasing complexity of cyber threats across IoT-cloud infrastructures necessitates the use of innovative, flexible, and confidentiality-preserving prevention techniques. The Blockchain-Assisted Hybrid Attention-Based Intrusion Detection and Access Control System (BHA-IDACS) is presented in this paper. The primary detection module employs an Adaptive Spatio-Temporal Representation Architecture-Self-Attention and Intersample Attention Transformer (Astra-SAINT) to precisely detect evolving intrusion tendencies. A heron optimization algorithm (HOA) is utilized for tuning the model thereby improving accuracy of detection and convergence. Fully Homomorphic Encryption (FHE) maintains the security of data and storage of encrypted data in unsecured cloud and blockchain circumstances. On a Consortium Blockchain, all encrypted transactions and audit trails are maintained by a Proof-of-Stake Authority (PoSA) consensus method. Additionally, based on user behavior and trust level, Smart Contract-Based Dynamic Access Control independently enforces permission and authentication regulations. The suggested model provides better precision, recall, F1-score, F2-score, specificity, and Cohen's Kappa values in addition to a mean accuracy of 99.16%. Furthermore, statistical analysis using confidence intervals and low standard deviation values demonstrates that Astra-SAINT is reliable and consistent across all validation folds. These results demonstrate the efficacy of the suggested Astra-SAINT framework as a scalable and dependable intrusion detection method for protecting IoT environments of the next decade.
Blockchain-based financial systems increasingly intersect with regulated domains, including stablecoins, real-world asset (RWA) tokenization, decentralized finance (DeFi), decentralized autonomous organizations (DAOs), and ESG-linked financial instruments. Existing blockchain insurance and underwriting models rely predominantly on probabilistic risk pricing derived from historical data, oracle-fed inputs, and machine learning inference. While sufficient for limited-scale applications, these approaches exhibit structural limitations when applied to high-volume, regulation-intensive systems. This paper demonstrates that probabilistic risk pricing alone imposes a fundamental scalability ceiling, as residual risk grows unbounded with system volume. We introduce a control-oriented risk mitigation framework based on the Crystal Validator (CV), which enforces execution-level compliance constraints prior to transaction finalization. By reducing compliance entropy through deterministic validation, CV bounds residual risk independently of transaction volume. We formalize this distinction using control theory, information theory, and cyber-physical systems (CPS) principles, and show why improved machine learning alone cannot resolve these limitations. The results establish control-oriented validation as a necessary architectural primitive for sustainable blockchain insurance and regulated on-chain finance.
This paper presents Zero-Knowledge Federated Learning Guard (ZK-FLGuard), a privacy-preserving and verifiable federated learning framework for real-time anomaly detection in Fifth-Generation Mobile Network (5G)-enabled Internet of Things (IoT) environments. Building on the integration of zero-knowledge proofs (zk-SNARK—Zero-Knowledge Succinct Non-interactive Argument of Knowledge) and blockchain-based access control, ZK-FLGuard ensures the integrity of model updates without exposing private data. Using real-world intrusion detection datasets (CICIDS2017—Canadian Institute for Cybersecurity Intrusion Detection System 2017, TON_IoT—Telecommunications Organisation of the National Security—IoT) and a synthetic adversarial dataset, our evaluation shows that ZK-FLGuard achieves up to 0.96 F1-score (harmonic mean of precision and recall), improves recall in low-frequency attack detection, and introduces less than 10% additional latency overhead compared to standard Federated Learning (FL). Compared with centralized Long Short-Term Memory (LSTM) and FL without Zero-Knowledge Proof (ZKP), ZK-FLGuard provides competitive accuracy while ensuring verifiable computation and strong privacy guarantees. We address the critical challenge of securing federated anomaly detection in 5G-enabled IoT systems against data leakage, model poisoning, and unauthorized access. While FL preserves privacy by keeping raw data local, it remains vulnerable to gradient leakage and adversarial manipulation. Our hypothesis is that combining zero-knowledge proofs and blockchain with FL can deliver a scalable, tamper-resistant, and privacy-preserving detection pipeline suitable for resource-constrained edge environments.
The increasing number of behind-the-meter distributed energy resources (DERs) is changing traditional distribution systems in a big way by adding new ways to control and monitor them. But the effectiveness and dependability of these systems depend heavily on the accuracy of the data (like measurements, control commands, etc.) that the prosumers, aggregators, and grid operators share with each other. In addition, traditional power systems rely entirely on trusted aggregators to gather data from these DERs. If these aggregators are hacked, the whole system could be at risk. In this paper, we respond to these concerns by suggesting a hierarchical blockchain-based framework that includes a distributed integrity auditing system for measuring DERs. By using hash functions and Merkle trees, a secure and lightweight blockchain-based hash aggregation protocol is made to make sure that behind-the-meter DERs' measurements are real. Also, an automated distributed sanity check of DERs' set points (control commands) is suggested to lower the risk of coordinated cyber attacks on a large number of DERs. The suggested framework is put into action and tested in a number of different situations to see how well it works and how safe it is. The results show that the framework can handle more work because it can cut its runtime and storage costs by about 47% and 44%, respectively.
Ileana Maria Muntean, Radu Tîrnovan, Horia G. Beleiu
As renewable generation becomes increasingly deployed at the local level, the reliability of microgrids depends not only on physical infrastructure but also on the credibility of the measurement data driving energy control decisions. In conventional Energy Management Systems (EMS) architectures, monitoring is implicitly assumed to be correct, even though no mechanism exists to verify the authenticity or integrity of the received data. This gap can lead to suboptimal or misleading control actions, especially in distributed environments involving multiple stakeholders. This paper introduces a trust-by-design approach in which monitoring and energy management processes are natively supported by a lightweight Distributed Ledger Technology (DLT) layer embedded within the EMS. Rather than relying on external trust assumptions, the proposed mechanism ensures built-in traceability and tamper-evidence, enabling independent validation of the microgrid’s operational history. A simple renewable microgrid with battery storage is used as a demonstrative case study to show how a DLT-based ledger can safeguard measurement integrity and control decisions without adding technical complexity to the EMS itself. The results demonstrate that verifiable data flows and tamper detection significantly enhance the transparency and robustness of EMS architectures, while enabling future extensions towards predictive or AI-assisted control strategies.
Kent Douglas Lambert, Tom Bradley, John M. Borky, Steve Simske · 6 authors
This research identifies a set of practical solutions to the uncontrolled growth of malicious cross-industry cybersecurity threats. Given the presence of the behaviors and negative effects of cyber threats, the research seeks to understand the effects of three eco-system-wide strategies for cyber defense: Defense-in-Depth (DiD), Zero-Trust Architectures (ZTA), and secure cryptographic key provisioning. These strategies are developed using the BlockFrame, Inc., Eco-Secure Provisioning™ (ESP™) Framework, blockchain-assisted digital logistics management and governance, and the application of Emergence Theory and Uniformity. The research addresses five specific questions to organize the approach, with practical translations of this research to selected industrial use cases.
Open access
Systems Engineering Methodologies and Applications
Infrastructure Resilience and Vulnerability Analysis
A infraestrutura das redes de registro distribuído (DLT) atravessa uma fase de escrutínio rigoroso quanto à sua viabilidade ambiental e eficiência operacional. Este relatório técnico analisa exaustivamente os três principais paradigmas de consenso contemporâneos: Proof of Work (PoW), Proof of Stake (PoS) e Proof of History (PoH), sob a ótica do custo-benefício energético e da segurança sistêmica. O Proof of Work, embora detentor de uma robustez histórica inigualável, apresenta um consumo elétrico de proporções nacionais, demandando cerca de 1.375 kWh por transação na rede Bitcoin. O Proof of Stake, consolidado pela transição do Ethereum, reduziu o dispêndio energético em 99,95%, operando com uma média de 0,0026 kWh por transação através da substituição da exaustão computacional pelo compromisso de capital. O Proof of History, atuando como um relógio criptográfico integrado ao PoS na rede Solana, otimiza a ordenação temporal e a escalabilidade, resultando em um consumo marginal de 0,00051 kWh por transação, o mais eficiente entre os protocolos de alta performance. O estudo conclui que a migração para modelos de baixo consumo e alta vazão (throughput) é impulsionada não apenas por avanços técnicos, mas por marcos regulatórios como o MiCA da União Europeia, que exige transparência absoluta sobre o impacto climático dos ativos digitais.<br>
Madina Konyrova, Katipa Chezhimbayeva, Abdul Razaque, Dina S.M. Hassan
The integration of renewable resources and prosumers into smart grids poses challenges related to scalability, transparency, and transmission efficiency. Centralized routing frequently depends on expensive technology and experiences significant losses. This study presents a blockchain-based smart contract system (BSCS) that reduces transmission losses while guaranteeing secure and decentralized energy transfers. The smart grid is represented as a weighted directed graph, with edges denoting actual power losses. Dijkstra’s shortest path algorithm generates optimal paths from the generator to the consumer with minimal loss. These optimal pathways are permanently documented and regulated by permissioned blockchain smart contracts, ensuring tamper-proof and verifiable energy settlement. Validation is performed using an enhanced IEEE 58-bus test system, which is based on the standard IEEE 57-bus network, by incorporating an additional synthetic consumer node (Bus 58) linked to Bus 12 to simulate a flexible prosumer load of 1.5 MW + 0.5 Mvar. Additionally, the synthetic consumer node employs Ganache, Truffle, and Solidity for its implementation. This modification facilitates the assessment of dynamic energy routing and decentralized transaction settlement in extended topology scenarios. The proposed BSCS demonstrates substantial enhancements compared to baseline blockchain systems. Active power losses in transmission lines are diminished, gas consumption declines by approximately 12%, latency is enhanced by as much as 21%, and throughput increases by more than 30%. The rapid deployment and execution of smart contracts within sub-second intervals validate the system's appropriateness for real-time grid operations. The proposed technique combines graph-theoretic optimization with blockchain governance to provide a safe, scalable, and hardware-independent framework for decentralized energy markets.