Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

5,430 papersLast indexed Aug 31, 2026
Search papers

Paper index

5,430 results · page 53 of 227

Clear filters
Apr 18, 2024·arXiv (Cornell University)
0 cites
Privacy-Preserving UCB Decision Process Verification via zk-SNARKs

Xikun Jiang, He Lyu, Chenhao Ying, Yibin Xu · 6 authors

With the increasingly widespread application of machine learning, how to strike a balance between protecting the privacy of data and algorithm parameters and ensuring the verifiability of machine learning has always been a challenge. This study explores the intersection of reinforcement learning and data privacy, specifically addressing the Multi-Armed Bandit (MAB) problem with the Upper Confidence Bound (UCB) algorithm. We introduce zkUCB, an innovative algorithm that employs the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARKs) to enhance UCB. zkUCB is carefully designed to safeguard the confidentiality of training data and algorithmic parameters, ensuring transparent UCB decision-making. Experiments highlight zkUCB's superior performance, attributing its enhanced reward to judicious quantization bit usage that reduces information entropy in the decision-making process. zkUCB's proof size and verification time scale linearly with the execution steps of zkUCB. This showcases zkUCB's adept balance between data security and operational efficiency. This approach contributes significantly to the ongoing discourse on reinforcing data privacy in complex decision-making processes, offering a promising solution for privacy-sensitive applications.

Open access
Information and Cyber Security
Access Control and Trust
Privacy-Preserving Technologies in Data
Original source
Apr 18, 2024·Computers
7 cites
Using Privacy-Preserving Algorithms and Blockchain Tokens to Monetize Industrial Data in Digital Marketplaces

Borja Bordel, Ramón Alcarria, Latif Ladid, Aurel Machalek

The data economy has arisen in most developed countries. Instruments and tools to extract knowledge and value from large collections of data are now available and enable new industries, business models, and jobs. However, the current data market is asymmetric and prevents companies from competing fairly. On the one hand, only very specialized digital organizations can manage complex data technologies such as Artificial Intelligence and obtain great benefits from third-party data at a very reduced cost. On the other hand, datasets are produced by regular companies as valueless sub-products that assume great costs. These companies have no mechanisms to negotiate a fair distribution of the benefits derived from their industrial data, which are often transferred for free. Therefore, new digital data-driven marketplaces must be enabled to facilitate fair data trading among all industrial agents. In this paper, we propose a blockchain-enabled solution to monetize industrial data. Industries can upload their data to an Inter-Planetary File System (IPFS) using a web interface, where the data are randomized through a privacy-preserving algorithm. In parallel, a blockchain network creates a Non-Fungible Token (NFT) to represent the dataset. So, only the NFT owner can obtain the required seed to derandomize and extract all data from the IPFS. Data trading is then represented by NFT trading and is based on fungible tokens, so it is easier to adapt prices to the real economy. Auctions and purchases are also managed through a common web interface. Experimental validation based on a pilot deployment is conducted. The results show a significant improvement in the data transactions and quality of experience of industrial agents.

Open access
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
FinTech, Crowdfunding, Digital Finance
Original source
Apr 18, 2024·Proceedings of the Nineteenth European Conference on Computer Systems
62 cites
ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs

Bing-Jyue Chen, Suppakit Waiwitlikhit, Ion Stoica, Daniel Kang

Machine learning (ML) is increasingly used behind closed systems and APIs to make important decisions. For example, social media uses ML-based recommendation algorithms to decide what to show users, and millions of people pay to use ChatGPT for information every day. Because ML is deployed behind these closed systems, there are increasing calls for transparency, such as releasing model weights. However, these service providers have legitimate reasons not to release this information, including for privacy and trade secrets. To bridge this gap, recent work has proposed using zero-knowledge proofs (specifically a form called ZK-SNARKs) for certifying computation with private models but has only been applied to unrealistically small models.

2 source records
Cryptography and Data Security
Privacy-Preserving Technologies in Data
Adversarial Robustness in Machine Learning
Original source
Apr 17, 2024·arXiv (Cornell University)
0 cites
OmniLytics+: A Secure, Efficient, and Affordable Blockchain Data Market for Machine Learning through Off-Chain Processing

Songze Li, Mingzhe Liu, Mengqi Chen

The rapid development of large machine learning (ML) models requires a massive amount of training data, resulting in booming demands of data sharing and trading through data markets. Traditional centralized data markets suffer from low level of security, and emerging decentralized platforms are faced with efficiency and privacy challenges. In this paper, we propose OmniLytics+, the first decentralized data market, built upon blockchain and smart contract technologies, to simultaneously achieve 1) data (resp., model) privacy for the data (resp. model) owner; 2) robustness against malicious data owners; 3) efficient data validation and aggregation. Specifically, adopting the zero-knowledge (ZK) rollup paradigm, OmniLytics+ proposes to secret share encrypted local gradients, computed from the encrypted global model, with a set of untrusted off-chain servers, who collaboratively generate a ZK proof on the validity of the gradient. In this way, the storage and processing overheads are securely offloaded from blockchain verifiers, significantly improving the privacy, efficiency, and affordability over existing rollup solutions. We implement the proposed OmniLytics+ data market as an Ethereum smart contract [41]. Extensive experiments demonstrate the effectiveness of OmniLytics+ in training large ML models in presence of malicious data owner, and the substantial advantages of OmniLytics+ in gas cost and execution time over baselines.

Open access
2 source records
cs.CR
cs.LG
Blockchain Technology Applications and Security
Original source
Apr 17, 2024·2024 International Conference on Cognitive Robotics and Intelligent Systems (ICC - ROBINS)
3 cites
A Systematic Review on Privacy Preservation Techniques for Smart Contracts in Blockchain using Machine Learning

Haseeba Yaseen, Syed Imtiyaz Hassan

Smart contracts are algorithmic descriptions of self-executing transaction protocols, that get automatically executed, based on the information provided by the entities involved. They are written in a specialized programming language for a specific domain and must adhere to relevant legislation. In addition to being formally correct and unambiguous, smart contracts rely on the trustworthiness, safety, and security of the platform on which they are executed. One of the emerging challenges is to protect the privacy of data. Privacy preserving in smart contracts refers to the ability of a smart contract to protect the personal information of the parties involved. Ensuring the security of sensitive data within Ethereum smart contracts is crucial due to the frequent use of these contracts for facilitating exchanges or transactions of sensitive information. If proper measures are not taken to protect this data, it may be susceptible to unauthorized access or disclosure, potentially leading to detrimental outcomes for the parties involved. This literature review work embarks on a comprehensive examination of the evolving landscape of data privacy within the realm of smart contracts, transcending the intrinsic transparency that characterizes blockchain technology.

Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Privacy, Security, and Data Protection
Original source
Apr 16, 2024·Frontiers in Blockchain
39 cites
Integrated cybersecurity for metaverse systems operating with artificial intelligence, blockchains, and cloud computing

Petar Radanliev

In the ever-evolving realm of cybersecurity, the increasing integration of Metaverse systems with cutting-edge technologies such as Artificial Intelligence (AI), Blockchain, and Cloud Computing presents a host of new opportunities alongside significant challenges. This article employs a methodological approach that combines an extensive literature review with focused case study analyses to examine the changing cybersecurity landscape within these intersecting domains. The emphasis is particularly on the Metaverse, exploring its current state of cybersecurity, potential future developments, and the influential roles of AI, blockchain, and cloud technologies. Our thorough investigation assesses a range of cybersecurity standards and frameworks to determine their effectiveness in managing the risks associated with these emerging technologies. Special focus is directed towards the rapidly evolving digital economy of the Metaverse, investigating how AI and blockchain can enhance its cybersecurity infrastructure whilst acknowledging the complexities introduced by cloud computing. The results highlight significant gaps in existing standards and a clear necessity for regulatory advancements, particularly concerning blockchain’s capability for self-governance and the early-stage development of the Metaverse. The article underscores the need for proactive regulatory involvement, stressing the importance of cybersecurity experts and policymakers adapting and preparing for the swift advancement of these technologies. Ultimately, this study offers a comprehensive overview of the current scenario, foresees future challenges, and suggests strategic directions for integrated cybersecurity within Metaverse systems utilising AI, blockchain, and cloud computing.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Ethics and Social Impacts of AI
Original source
Apr 15, 2024·Journal of Medical Internet Research
14 cites
Integration of Federated Learning and Blockchain in Healthcare: A Tutorial

Yahya Shahsavari, Yaser Baseri, Abdelhakim Hafid, Oussama Abderrahmane Dambri · 5 authors

Unlabelled: The convergence of artificial intelligence (AI), blockchain technology, and health care represents one of the most transformative yet technically challenging frontiers in computational medicine. As health care systems adopt data-driven paradigms for precision medicine and clinical decision support, the need for secure, privacy-preserving, and collaborative learning frameworks has become critical. This tutorial introduces a comprehensive, clinically oriented, and compliance-aware framework integrating federated learning (FL) and blockchain for secure and privacy-preserving health care analytics. FL enables collaborative training across distributed institutions without raw data sharing, in alignment with privacy regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and the General Data Protection Regulation (GDPR). However, FL remains vulnerable to model poisoning and gradient leakage. To address these risks, we introduce blockchain-based FL (BCFL), which leverages blockchain's immutable ledger and decentralized consensus to enhance trust, verifiability, and auditability. The tutorial's main contributions include (1) a taxonomy of diverse medical data types and their FL requirements; (2) three integration architectures (fully coupled, semicoupled, and loosely coupled) analyzed for security, scalability, and regulatory compliance; (3) a security analysis of health care-specific vulnerabilities and mitigation strategies using advanced cryptography, such as zero-knowledge proofs, homomorphic encryption, and differential privacy; and (4) a regulatory compliance framework addressing HIPAA, GDPR, and United States Food and Drug Administration guidelines for AI-enabled medical devices. We demonstrate BCFL's relevance across major health care applications, including disease prediction, medical imaging, patient monitoring, and drug discovery, and highlight emerging research directions such as quantum-resilient cryptography, scalable interoperability, and automated compliance. This tutorial serves as a foundational resource for advancing secure, compliant, and collaborative AI in health care; fostering privacy-preserving analytics; and improving patient outcomes.

Open access
4 source records
cs.CR
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Apr 14, 2024·International Journal For Multidisciplinary Research
0 cites
Access Control System Using AI and Blockchain

SAQIB AHAD KHAN -, Sona Mohammad Idrees Shamshuddin -, N. Srinivasan, G Kalaiarasi - · 5 authors

The demands of a hyperconnected society that demand increased security, transparency, and user autonomy cause traditional access control to crumble. This abstract investigates how combining blockchain technology with artificial intelligence could revolutionize access control systems. By removing single points of failure and increasing accountability, blockchain's distributed ledger technology (DLT) creates irreversible trust via a shared, tamper-proof database of rights and transactions. By automating policies, smart contracts give people command over their digital assets. AI adds intelligence and flexibility. Real-time machine learning systems detect anomalies, dynamically assess behavior, and modify policy. Access requests are filtered by AI-driven risk assessment, and sensitive resources are protected by improved identity verification. The combination of AI's dynamic powers and blockchain's unchangeable base opens the door to a future where safe, user-focused access is commonplace.

Open access
Privacy-Preserving Technologies in Data
Original source
Apr 13, 2024·IEEE Transactions on Mobile Computing
23 cites
ProSecutor: Protecting Mobile AIGC Services on Two-Layer Blockchain via Reputation and Contract Theoretic Approaches

Yinqiu Liu, Hongyang Du, Dusit Niyato, Jiawen Kang · 7 authors

Mobile AI-Generated Content (AIGC) has achieved great attention in unleashing the power of generative AI and scaling the AIGC services. By employing numerous Mobile AIGC Service Providers (MASPs), ubiquitous and low-latency AIGC services for clients can be realized. Nonetheless, the interactions between clients and MASPs in public mobile networks, pertaining to three key mechanisms, namely MASP selection, payment scheme, and fee-ownership transfer, are unprotected. In this paper, we design the above mechanisms using a systematic approach and present the first blockchain to protect mobile AIGC, called ProSecutor. Specifically, by roll-up and layer-2 channels, ProSecutor forms a two-layer architecture, realizing tamper-proof data recording and atomic fee-ownership transfer with high resource efficiency. Then, we present the Objective-Subjective Service Assessment (OS^{2}A) framework, which effectively evaluates the AIGC services by fusing the objective service quality with the reputation-based subjective experience of the service outcome (i.e., AIGC outputs). Deploying OS^{2}A on ProSecutor, firstly, the MASP selection can be realized by sorting the reputation. Afterward, the contract theory is adopted to optimize the payment scheme and help clients avoid moral hazards in mobile networks. We implement the prototype of ProSecutor on BlockEmulator.Extensive experiments demonstrate that ProSecutor achieves 12.5x throughput and saves 67.5\% storage resources compared with BlockEmulator. Moreover, the effectiveness and efficiency of the proposed mechanisms are validated.

Open access
2 source records
cs.NI
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Apr 12, 2024·IEEE Transactions on Intelligent Transportation Systems
22 cites
Post-Quantum Anonymous, Traceable and Linkable Authentication Scheme Based on Blockchain for Intelligent Vehicular Transportation Systems

Shiwei Xu, Tao Wang, Ao Sun, Yan Tong · 7 authors

As the Internet of Vehicles (IoV) has become the critical part of Intelligent Vehicular Transportation Systems (IVTS), massive IoV entities (e.g., RSU, OBU, pedestrians’ mobile devices, etc.) get involved into IVTS. At present, one of the biggest challenges with IoV/IVTS is how to maintain a balance between security and privacy. The receivers need to be sure that they are receiving reliable messages from the origin and could trace or link the attacker’s identity, but the tracing or linking may work against the sender’s need for identity privacy. To solve the security and privacy problem, most of current works have proposed authentication solutions to provide anonymous, traceable and unlinkable schemes, which are still vulnerable to either Sybil attacks or quantum attacks. Therefore, we propose the blockchain-based post-quantum anonymous, traceable and linkable authentication scheme by utilizing NIST winner post-quantum algorithms and related post-quantum linkable ring signature. Grounded on the authentication scheme, we also develop key exchange mechanism, which help IoV entities perform efficient message authentication encryption/decryption during P2P communication and broadcast. The security analysis shows that our proposal is resistant to Sybil attack and provides other essential security characteristics including man-in-the-middle-proof and anti-replay. Finally, we perform detailed performance evaluation including each on-chain API execution time, the off-chain communication time and the on-board/on-chain storage requirements. To further evaluate the feasibility of our scheme in the IoV/IVTS environment, we also show the effectiveness of our proposal in a blockchain-based simulation study.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
Privacy-Preserving Technologies in Data
Original source
Apr 11, 2024·IEEE Transactions on Vehicular Technology
55 cites
Zero-X: A Blockchain-Enabled Open-Set Federated Learning Framework for Zero-Day Attack Detection in IoV

Abdelaziz Amara Korba, Abdelwahab Boualouache, Yacine Ghamri-Doudane

The Internet of Vehicles (IoV) is a crucial technology for Intelligent Transportation Systems (ITS) that integrates vehicles with the Internet and other entities. The emergence of 5 G and the forthcoming 6 G networks presents an enormous potential to transform the IoV by enabling ultra-reliable, low-latency, and high-bandwidth communications. Nevertheless, as connectivity expands, cybersecurity threats have become a significant concern. The issue has been further exacerbated by the rising number of zero-day (0-day) attacks, which can exploit unknown vulnerabilities and bypass existing Intrusion Detection Systems (IDSs). In this paper, we propose Zero-X, an innovative security framework that effectively detects both 0-day and N-day attacks. The framework achieves this by combining deep neural networks with Open-Set Recognition (OSR). Our approach introduces a novel scheme that uses blockchain technology to facilitate trusted and decentralized federated learning (FL) of the Zero-X framework. This scheme also prioritizes privacy preservation, enabling both CAVs and Security Operation Centers (SOCs) to contribute their unique knowledge while protecting the privacy of their sensitive data. To the best of our knowledge, this is the first work to leverage OSR in combination with privacy-preserving FL to identify both 0-day and N-day attacks in the realm of IoV. The in-depth experiments on two recent network traffic datasets show that the proposed framework achieved a high detection rate while minimizing the false positive rate. Comparison with related work showed that the Zero-X framework outperforms existing solutions.

Open access
2 source records
cs.CR
cs.AI
Privacy-Preserving Technologies in Data
Original source
Apr 10, 2024·Computer Communications
1 cites
Trajectory privacy protection method with smart contract-based query exchange in the Social Internet of Vehicles

L. Liu, Ling Xing, Jianping Gao, Honghai Wu · 5 authors

Query exchange in the Social Internet of Vehicles (SIoV) can protect users’ trajectory information. However, this method lacks an appropriate incentive mechanism, which leads to cooperative users refusing to participate in query exchange. In order to provide cooperative users with incentives to participate in query exchange, this paper proposes a smart contract-based query exchange (SC-QE) trajectory privacy protection method. By creating a many-to-many smart contract, the method encourages the cooperative users to bid to the requesting users. Subsequently, in order to select a Best Similarity Deviation User (BSDU) for the requesting user to perform query exchange, the users in the smart contract are modeled as a weighted bipartite graph, and the matching between the requesting users and BSDUs is realized by means of a weighted bipartite graph best matching algorithm. Following successful verification of the query exchange transaction in the smart contract, the base station distributes rewards to the BSDU and uploads the query exchange transaction to the consortium blockchain. Experimental results show that compared with the deviation-based query exchange (DQE) method, the proposed method reduces the user processing time by 12% while increasing the continuous anonymous success rate by 29%. Therefore, the proposed method can reduce the service query time and improve the level of trajectory privacy protection.

Open access
Privacy-Preserving Technologies in Data
Vehicular Ad Hoc Networks (VANETs)
Blockchain Technology Applications and Security
Original source
Apr 10, 2024·ACM Computing Surveys
118 cites
Security, Privacy, and Decentralized Trust Management in VANETs: A Review of Current Research and Future Directions

Mishri Saleh Al-Marshoud, Mehmet Sabır Kiraz, Ali H. Al-Bayati

Vehicular Ad Hoc Networks (VANETs) are powerful platforms for vehicular data services and applications. The increasing number of vehicles has made the vehicular network diverse, dynamic, and large-scale, making it difficult to meet the 5G network’s demanding requirements. Decentralized systems are interesting and provide attractive services because they are publicly available (transparency), have an append-only ledger (robust integrity protection), remove single points of failure, and enable distributed key management and communication in a peer-to-peer network. Researchers dedicated substantial efforts to advancing vehicle communications, however conventional cryptographic mechanisms are insufficient which enabled us to look at decentralized technologies. Therefore, we revisit decentralized approaches with VANETs. Endpoint devices hold a wallet which may incorporate threshold key management methods like MPC wallets, HD Wallets, or multi-party threshold ECDSA/EdDSA/BLS. We also discuss trust management approaches and demonstrate how decentralization can improve integrity, security, privacy, and resilience to single points of failure. We also conduct a comprehensive review, comparing them with current requirements, and the latest authentication and secure communication architectures, which require the involvement of trusted but non-transparent authorities in certificate issuance/revocation. We highlight the limitations of these schemes from PKI deployment and recommend future research, particularly in the realm of quantum cryptography.

Open access
Vehicular Ad Hoc Networks (VANETs)
Privacy-Preserving Technologies in Data
Advanced Authentication Protocols Security
Original source
Apr 9, 2024·High-Confidence Computing
31 cites
An attribute-based access control scheme using blockchain technology for IoT data protection

Zenghui Yang, Xiu‐Bo Chen, Yunfeng He, Luxi Liu · 8 authors

With the wide application of the Internet of Things (IoT), storing large amounts of IoT data and protecting data privacy has become a meaningful issue. In general, the access control mechanism is used to prevent illegal users from accessing private data. However, traditional data access control schemes face some non-ignorable problems, such as only supporting coarse-grained access control, the risk of centralization, and high trust issues. In this paper, an attribute-based data access control scheme using blockchain technology is proposed. To address these problems, attribute-based encryption (ABE) has become a promising solution for encrypted data access control. Firstly, we utilize blockchain technology to construct a decentralized access control scheme, which can grant data access with transparency and traceability. Furthermore, our scheme also guarantees the privacy of policies and attributes on the blockchain network. Secondly, we optimize an ABE scheme, which makes the size of system parameters smaller and improves the efficiency of algorithms. These optimizations enable our proposed scheme supports large attribute universe requirements in IoT environments. Thirdly, to prohibit attribute impersonation and attribute replay attacks, we design a challenge-response mechanism to verify the ownership of attributes. Finally, we evaluate the security and performance of the scheme. And comparisons with other related schemes show the advantages of our proposed scheme. Compared to existing schemes, our scheme has more comprehensive advantages, such as supporting a large universe, full security, expressive policy, and policy hiding.

Open access
Cryptography and Data Security
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source
Apr 9, 2024·IEEE Internet of Things Journal
49 cites
TrustBCFL: Mitigating Data Bias in IoT Through Blockchain-Enabled Federated Learning

Sisi Zhou, Kuanching Li, Yuxiang Chen, Ce Yang · 6 authors

The development of the Internet of Things (IoT), Big Data, and deep learning technologies has brought convenience to people’s lives. As personal privacy data protection laws and regulations tighten, the cost of acquiring high-quality annotated data from vast IoT datasets has significantly increased, resulting in prevalent issues such as data acquisition challenges and label noise in training data. In this work, we focus on the demand for privacy protection and trustworthy sharing of IoT data, and propose a method for addressing data bias in IoT through federated learning and blockchain by utilizing the theory of local intrinsic dimension (LID), incorporating committee consensus to achieve noise label identification and correction at the data level, reducing information loss in the training data. Additionally, it performs screening of low-quality local model updates at the model level, leveraging blockchain technology that addresses the single point of failure issues in traditional federated learning, ensuring the performance and security of the federated learning models. Analysis, proof of convergence, and experimentations on the proposed framework demonstrate good security and robustness in noisy environments, effectively addressing data bias in intelligent IoT settings. In scenarios with a noise level of 0.3, 0.6, and 0.9, the average model accuracy improved respectively by 7.75%, 7.30%, and 14.04% compared to FedAvg. Similarly, when compared to FedCorr, the average improvement in model accuracy is 5.19%, 3.63%, and 8.74% respectively. Moreover, the training time remains within an acceptable range for all cases.

Privacy-Preserving Technologies in Data
Cryptography and Data Security
Blockchain Technology Applications and Security
Original source
Apr 9, 2024·IEEE Internet of Things Journal
7 cites
Futuristic Decentralized Vehicular Network Architecture and Repairing Management System on Blockchain

Usama Arshad, Zahid Halim, Hisham Alasmary, Muhammad Waqas

Blockchain technology is used often as a merger with other technologies to achieve a high level of security, privacy, and robustness and to handle issues such as maliciousness of nodes, privacy leakage, the selfishness of nodes, communication delays, and high execution and transaction costs. There is currently a lack of a comprehensive system for automating and cost-effectively managing vehicle repairs, maintenance, and other associated services. To solve such issues we proposed a novel futuristic comprehensive model that integrates a blockchain-based framework to safely record vehicle maintenance, validate repair services, and oversee parts inventory. It employs smart contracts and consensus protocols to secure communications and data storage, thus reducing data breaches and vulnerabilities from single-point failures. A reward system is embedded within the network to encourage positive behavior and deter detrimental actions. We also incorporated advanced privacy-ensuring methods, like zero-knowledge proofs and secure multi-party computation, to safeguard sensitive data while preserving its utility. Our model features automatic detection and response mechanisms for node failure, improving network resilience by 25% thus also providing a 20% reduction in execution, operational costs, and scalability with an enhancement of 15%, underscoring the model’s efficiency in vehicular repair and maintenance activities. Results and simulations clearly depict the overall performance and efficiency in terms of security, privacy, node failure, and the management of vehicle repairs with respect to other closely related models.

Open access
Blockchain Technology Applications and Security
Vehicular Ad Hoc Networks (VANETs)
Privacy-Preserving Technologies in Data
Original source
Apr 9, 2024·IACR Communications in Cryptology
18 cites
Simple Three-Round Multiparty Schnorr Signing with Full Simulatability

Yehuda Lindell

In a multiparty signing protocol, also known as a threshold signature scheme, the private signing key is shared amongst a set of parties and only a quorum of those parties can generate a signature. Research on multiparty signing has been growing in popularity recently due to its application to cryptocurrencies. Most work has focused on reducing the number of rounds to two, and as a result: (a) are not fully simulatable in the sense of MPC real/ideal security definitions, and/or (b) are not secure under concurrent composition, and/or (c) utilize non-standard assumptions of different types in their proofs of security. In this paper, we describe a simple three-round multiparty protocol for Schnorr signatures that is secure for any number of corrupted parties; i.e., in the setting of a dishonest majority. The protocol is fully simulatable, secure under concurrent composition, and proven secure in the standard model or random-oracle model (depending on the instantiations of the commitment and zero-knowledge primitives). The protocol realizes an ideal Schnorr signing functionality with perfect security in the ideal commitment and zero-knowledge hybrid model (and thus the only assumptions needed are for realizing these functionalities). In our presentation, we do not assume that all parties begin with the message to be signed, the identities of the participating parties and a unique common session identifier, since this is often not the case in practice. Rather, the parties achieve consensus on these parameters as the protocol progresses.

Open access
Cryptography and Data Security
Complexity and Algorithms in Graphs
Privacy-Preserving Technologies in Data
Original source
Apr 8, 2024·Proceedings of the 39th ACM/SIGAPP Symposium on Applied Computing
15 cites
VulnHunt-GPT: a Smart Contract vulnerabilities detector based on OpenAI chatGPT

Biagio Boi, Christian Esposito, Sokjoon Lee

Smart contracts are self-executing programs that can run on a blockchain. Due to the fact of being immutable after their deployment on blockchain, it is crucial to ensure their correctness. For this reason, various approaches for static analysis of smart contracts have been proposed, but they may be on the one hand imprecise or on the other hand difficult to train. In this paper, we propose a novel approach for detecting smart contract vulnerabilities using OpenAI's Generative Pre-trained Transformer 3 (GPT-3) language model. Our approach, called VulntHunt-GPT, uses GPT-3 to examine Ethereum smart contracts in order to identify the most popular vulnerabilities according to OWASP. We train VulntHunt-GPT on a dataset of smart contract functions and vulnerabilities to improve its accuracy. Our experiments show that VulntHunt-GPT outperforms almost all the existing state-of-the-art approaches in detecting a variety of vulnerabilities, including reentrancy attacks, integer overflow, and uninitialized storage. In addition, we conduct a case study to demonstrate the effectiveness of VulntHunt-GPT in detecting real-world smart contract vulnerabilities. We show that VulntHunt-GPT can identify previously unknown vulnerabilities in popular smart contracts, highlighting its potential for improving smart contract security. Our approach provides a promising direction for using natural language processing techniques to improve smart contract security and reduce the risk of smart contract exploits.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Privacy-Preserving Technologies in Data
Original source