The role of digital identity systems in today’s cyber infrastructure is pivotal to providing secure access to online services. Privacy-preserving mechanisms, however, are becoming more important as cyber threats develop. Especially in large networks, zero-knowledge proofs (ZKPs) are an effective way to enhance privacy in digital identity systems. When used during authentication, they protect the privacy of user data by verifying knowledge to another entity without unveiling the actual data. A ZKP can also reduce identity theft risks, mitigate man-in-the-middle attacks, and enhance security when integrated into privacy-preserving networks. In this paper, we examine the role that ZKPs play in privacy-preserving networks and the possibility of using them in this regard, in order to gain insight into their application in digital identity systems.
Yogesh Kisan Mali, Vijay U. Rathod, Nilesh P. Sable, Rahul Ramkishan Rathod · 6 authors
Any wireless network is built on the mutually reinforcing pillars of privacy and security. Security measures often cover data connections, physical security, outside threats, and internal node operations. Whereas privacy covers the selective exchange of data among a network’s various entities. To provide privacy to networks, a large number of algorithms have been proposed by researchers in the past. Most of these algorithms utilize Graph-based anonymization approaches like l-diversity, k-anonymity, etc. These models do not scale well. Thus, this text proposes a machine learning-based block chain-powered privacy preservation protocol. The proposed protocol will perform attribute-based privacy with high efficiency due to the use of block chain architecture and will improve the overall Quality of Service of the network due to the integration of machine learning in the system.
In this paper, we propose zero-knowledge named proof, a replay attack prevention scheme that ensures the user's anonymity against malicious administrators. We begin with adopting the zero-knowledge set-membership proof into an authentication setting in which users would delegate their requests to an agent that obstructs the user's identity from the administrator. This anonymous agent carries the guarantee of authenticity, which the administrator through the set-membership proof can confirm. Next, we prevent replay attacks from other parties by binding the agent's identity to the delegation request verifiable by the administrators. By leveraging these properties, a blockchain-based authentication scheme is then built. We quantitatively evaluate the security, cost-efficiency, and performance of our scheme and provide a third-party authorization scheme from our authentication framework to demonstrate its real-world relevancy.
In response to the challenge of low accuracy in node trust evaluation due to the high dynamics of entry and exit of drone cluster nodes, we propose a hierarchical blockchain-based trust measurement method for drone cluster nodes. This method overcomes the difficulties related to trust inheritance for dynamic nodes, trust re-evaluation of dynamic clusters, and integrated trust calculation for drone nodes. By utilizing a multi-layer unmanned cluster blockchain for trusted historical data storage and verification, we achieve scalability in measuring intermittent trust across time intervals, ultimately improving the accuracy of trust measurement for drone cluster nodes. We design a resource-constrained multi-layer unmanned cluster blockchain architecture, optimize the computing power balance within the cluster, and establish a collaborative blockchain mechanism. Additionally, we construct a dynamic evaluation method for trust in drone nodes based on task perception, integrating and calculating the comprehensive trust of drone nodes. This approach addresses trusted sharing and circulation of task data and resolves the non-inheritability of historical data. Experimental simulations conducted using NS3 and MATLAB demonstrate the superior performance of our trust value measurement method for unmanned aerial vehicle cluster nodes in terms of accurate malicious node detection, resilience to trust value fluctuations, and low resource delay retention.
Oct 7, 2023·Adjunct Proceedings of the 2023 ACM International Joint Conference on Pervasive and Ubiquitous Computing & the 2023 ACM International Symposium on Wearable Computing
The significant increase in data production resulting from the widespread adoption of mobile and IoT technologies has revolutionized healthcare but also presents significant privacy and ethical challenges. The field of medical data collection is no exception and has limitations in terms of the source, variety and quantity of records from studies on healthcare and wellness. One way to address this dilemma is the use of the Blockchain for patient data collection and use. The anonymity of a centralized network allows the patient’s identity to be protected. The structure formed by nodes allows the information to be always available and does not depend on a main server. The immutability of records in the chain ensures unambiguous traceability of information flow by the healthcare provider. Finally, the network’s consensus and reward mechanisms could motivate new users to participate in active sensing. In this article we will expose the architecture of an application that relies on the Blockchain to meet the above information needs by leveraging the potential of the Ethereum network. In addition, we present a use case where consciously collected data from our platform is used to train a machine learning model automatically, using a P2P Browser-Based Computational Notebook as execution and distribution environment.
Abstract Bitcoin is a decentralized P2P cryptocurrency. It supports users to use pseudonyms instead of network addresses to send and receive transactions at the data layer, hiding users’ real network identities. Traditional transaction tracing attack cuts through the network layer to directly associate each transaction with the network address that issued it, thus revealing the sender’s network identity. But this attack can be mitigated by Bitcoin’s network layer privacy protections. Since Bitcoin protects the unlinkability of Bitcoin addresses and there may be a many-to-one relationship between addresses and nodes, transactions sent from the same node via different addresses are seen as coming from different nodes because attackers can only use addresses as node identifiers. In this paper, we proposed the evicting and filling attack to expose the correlations between addresses and cluster transactions sent from different addresses of the same node. The attack exploited the unisolation of Bitcoin’s incoming connection processing mechanism. In particular, an attacker can utilize the shared connection pool and deterministic connection eviction strategy to infer the correlation between incoming and evicting connections, as well as the correlation between releasing and filling connections. Based on inferred results, different addresses of the same node with these connections can be linked together, whether they are of the same or different network types. We designed a multi-step attack procedure, and set reasonable attack parameters through analyzing the factors that affect the attack efficiency and accuracy. We mounted this attack on both our self-run nodes and multi-address nodes in real Bitcoin network, achieving an average accuracy of 96.9% and 82%, respectively. Furthermore, we found that the attack is also applicable to Zcash, Litecoin, Dogecoin, Bitcoin Cash, and Dash. We analyzed the cost of network-wide attacks, the application scenario, and proposed countermeasures of this attack.
Rahul Mishra, Dharavath Ramesh, Paolo Bellavista, Damodar Reddy Edla
Internet-of-Farming Things (IoFT)-enabled smart agriculture can collect data more reliably and frequently to track the crop’s status and other significant information. Considering that smart agriculture requires working with substantial amounts of sensitive data. In light of this, frequent data processing may threaten the confidentiality and integrity of data and IoFT device privacy. Although numerous privacy-preserving data aggregation methods have been implemented to address these issues, they also have certain security vulnerabilities, such as inadequate data confidentiality, collusion attacks, and malicious data mining attacks. Therefore, we introduce a three-tier architecture-assisted redactable blockchain-based secure data aggregation method with source authentication for the fog-enabled IoFT. This work provides an efficient and secure two-level data aggregation model. The proposed model supports resistance to collusion and malicious data mining threats launched by internal or external attackers. It can also achieve perfect data confidentiality and integrity against a malicious aggregator and an inquisitive control center for an authorized IoFT device. Specifically, the detailed performance analysis and theoretical concrete security proofs demonstrate the practicability and efficiency of the proposed model.
Anusha Iyer, Chloe Lee, T. Uday Kiran Reddy, Cyrus Rosenberg · 6 authors
With the rise in prominence of crowdsourced datasets in machine learning, data poisoning attacks pose a considerable threat. Many current defenses fall short because they are overly specialized for certain attacks, lack contribution incentives, and are difficult to integrate into current platforms. This paper explores the underaddressed system security problem posed by data poisoning through SeBRUS, a comprehensive data contribution application that leverages Ethereum smart contracts to secure crowdsourced datasets. SeBRUS introduces a voting network and poisoned data detection model, allowing for easy implementation with current platforms to defend against label-flipping, clean-label, and backdoor attacks.
Lei Liu, Junqi Fu, Jie Feng, Guopeng Wang · 6 authors
Being the main starting point for intelligent transportation systems, internet of vehicles has entered a rapid development period. This motivates a large number of novel vehicular applications with diversified and personalized demands. Distributed collaborative computing provides a promising solution to meet these applications by on-demand resource management, but is faced with tremendous challenges in achieving trusted resource cooperation and accurate decision making. In this paper, we propose a blockchain-based vehicular digital twin architecture for distributed collaborative computing. In this architecture, blockchain facilitates the opening and sharing of vehicular resources, while digital twin enables the accurate management decision. Then, we investigate the computation offloading in blockchain-based vehicular digital twin networks to demonstrate the effectiveness of the proposed architecture. Finally, several important open issues are discussed in detail for further investigation on blockchain-based vehicular digital twin.
Muhammad Asad, Saima Shaukat, Ehsan Javanmardi, Jin Nakazato · 6 authors
The rapid increase in the number of connected vehicles on roads has made vehicular ad-hoc networks (VANETs) an attractive target for malicious actors. As a result, VANETs require secure data transmission to maintain the network’s integrity. Federated learning (FL) has been proposed as a secure data-sharing method for VANETs, but it is limited in its ability to protect sensitive data. This article proposes integrating Blockchain technology into FL to provide an additional layer of security for VANETs. In particular, we propose a secure and efficient blockchain-based FL (SEBFL) approach to ensure communication efficiency and data privacy in VANETs. To this end, we use the FL model for VANETs, where computation tasks are decomposed from a base station to individual vehicles. This effectively reduces the congestion delay and communication overhead. Integrating blockchain with the FL model provides a reliable and secure data communication system between vehicles, roadside units, and a cloud server. Additionally, we use a homomorphic encryption system (HES) that effectively preserves the confidentiality and credibility of vehicles. Besides, the proposed SEBFL leverages the asynchronous FL model, minimizing the long delay while avoiding possible threats and attacks using HES. The experimental results show that the proposed SEBFL achieves 0.87% accuracy while a model inversion attack and 0.86% accuracy while a membership inference attack.
Zhipeng Wang, Nanqing Dong, Jiahao Sun, William J. Knottenbelt · 5 authors
Federated learning (FL) is a machine learning paradigm, which enables multiple and decentralized clients to collaboratively train a model under the orchestration of a central aggregator. FL can be a scalable machine learning solution in big data scenarios. Traditional FL relies on the trust assumption of the central aggregator, which forms cohorts of clients honestly. However, a malicious aggregator, in reality, could abandon and replace the client's training models, or insert fake clients, to manipulate the final training results. In this work, we introduce zkFL, which leverages zero-knowledge proofs to tackle the issue of a malicious aggregator during the training model aggregation process. To guarantee the correct aggregation results, the aggregator provides a proof per round, demonstrating to the clients that the aggregator executes the intended behavior faithfully. To further reduce the verification cost of clients, we use blockchain to handle the proof in a zero-knowledge way, where miners (i.e., the participants validating and maintaining the blockchain data) can verify the proof without knowing the clients' local and aggregated models. The theoretical analysis and empirical results show that zkFL achieves better security and privacy than traditional FL, without modifying the underlying FL network structure or heavily compromising the training speed.
Federated learning (FL) is a distributed learning process that uses a trusted aggregation server to allow multiple parties (or clients) to collaboratively train a machine learning model without having them share their private data. Recent research, however, has demonstrated the effectiveness of inference and poisoning attacks on FL. Mitigating both attacks simultaneously is very challenging. State-of-the-art solutions have proposed the use of poisoning defenses with Secure Multi-Party Computation (SMPC) and/or Differential Privacy (DP). However, these techniques are not efficient and fail to address the malicious intent behind the attacks, i.e., adversaries (curious servers and/or compromised clients) seek to exploit a system for monetization purposes. To overcome these limitations, we present a ledger-based FL framework known as FLEDGE that allows making parties accountable for their behavior and achieve reasonable efficiency for mitigating inference and poisoning attacks. Our solution leverages crypto-currency to increase party accountability by penalizing malicious behavior and rewarding benign conduct. We conduct an extensive evaluation on four public datasets: Reddit, MNIST, Fashion-MNIST, and CIFAR-10. Our experimental results demonstrate that (1) FLEDGE provides strong privacy guarantees for model updates without sacrificing model utility; (2) FLEDGE can successfully mitigate different poisoning attacks without degrading the performance of the global model; and (3) FLEDGE offers unique reward mechanisms to promote benign behavior during model training and/or model aggregation.
Decentralized identity (DID) is an identity management framework aiming to return the ownership of an identity to its corresponding user. Recent studies propose to store the identifiers of DID issuers and implement identity management systems based on blockchain. However, existing systems cannot avoid identity tampering and verifiable credential abuse of decentralized identities, which makes the identity management opaque. In this paper, we propose TDID, a Transparent and efficient Decentralized IDentity management system with blockchain. The key insight behind TDID is to manage the registration and authentication of DIDs via smart contracts, and design Structured Merkle Patricia Tree (SMPT) as an underlying data structure to store identity data on blockchain. The smart contract based processes can improve transparency of decentralized identity management, while the SMPT data structure can realize efficient storage of DID data. We implement and evaluate TDID on different identity management operations, and the experimental results show that TDID can achieve about 3.1 times for write operation and 6.3 times for read operation while improving the transparency of DID management.
Nowadays, researchers have started to conceptualize Metaverse with the vision of constituting a fully immersive, hyper spatiotemporal, and persistent interconnected virtualized world. Such network evolution poses sustainability concerns due to its enabling technologies, such as compute-intensive Artificial Intelligence (AI) and energy-consuming blockchain. Combining distributed learning and blockchain shows great potential to solve the energy efficiency issues in Metaverse through secure resource scheduling and decentralization of computing. However, with the expansion of the Metaverse scale, the increased energy consumption and storage of blockchain are still intolerable. Sharding blockchain becomes a feasible solution to efficiently improve energy efficiency and scalability by dividing blockchain into multiple smaller groups called shards. Toward this end, we have proposed a sustainable Metaverse architecture, combining distributed learning and sharding blockchain to tackle the energy efficiency challenges. The proposed sharding mechanism with incentive achieves the parallelization of computing and storage in Metaverse, while guaranteeing the security and activity of distributed learning. Numerical results show that the proposed framework improves energy efficiency and eases pressure on data storage.
AI has found widespread application across various sectors, including security, healthcare, finance, and national defense. However, alongside its transformative advancements, there has been an unfortunate trend of malicious exploitation of AI capabilities. Concurrently, the rapid evolution of cloud computing technology has introduced cloud-based AI systems. Regrettably, vulnerabilities inherent in cloud computing infrastructure also pose risks to the security of AI services. We observe that the integrity of training data is pivotal, as any compromise therein directly impacts the efficacy of AI systems. Against this backdrop, we assert the paramount importance of preserving data integrity within AI systems. To address this imperative, we propose a data integrity architecture guided by the National Institute of Standards and Technology (NIST) cyber security framework. Leveraging block chain technology and smart contracts emerges as a fitting solution to tackle integrity challenges, owing to their characteristics of shared and decentralized ledgers. Smart contracts facilitate automated policy enforcement, enable continuous monitoring of data integrity, and mitigate the risk of data tampering.
Timed data release refers to protecting sensitive data that can be accessed only after a pre-determined amount of time has passed. While blockchain-based solutions for timed data release provide a promising approach for decentralizing the process, designing an attack-resilient timed-release service that is resilient to malicious adversaries in a blockchain network is inherently challenging. A timed-release service on a blockchain network is inevitably exposed to the risk of post-facto attacks where adversaries may launch attacks after the data is released in the blockchain network. Existing incentive-based solutions for timed data release in Ethereum blockchains guarantee protection under the assumption of a fully rational adversarial environment in which every peer acts rationally. However, these schemes fail invariably when even a single participating peer node in the protocol starts acting maliciously and deviates from the rational behavior. In this paper, we propose a systematic solution for attack-resilient and practical blockchain-based timed data release in a mixed adversarial environment, where both malicious adversaries and rational adversaries exist. We first propose an effective uncertainty-aware reputation measure to capture the behaviors of the peer involved in timed data release activities in the network. In light of such a measure, we present the design of a basic protocol that consists of two critical ingredients, namely reputation-aware peer recruitment and verifiable enforcement protocols. The former, prior to the start of the enforcement protocols, performs peer recruitment based on the reputation measure to make the design probabilistically attack-resilient to the post-facto attacks. The latter is responsible for contractually guarding the recruited peers at runtime by transparently reporting observed adversarial behaviors. However, the basic recruitment design is only aware of the reputation of the peers and it does not consider the working time schedule of the participating peers and as a result, it results in lower attack-resilience. To enhance the attack resilience further without impacting the verifiable enforcement protocols, we propose a temporal graph-based reputation-aware peer recruitment algorithm that carefully determines the peer recruitment plan to make the service more attack-resilient. In our proposed approach, we formally capture the timed data release service as a temporal graph and we develop a novel maximal attack-resilient path-finding algorithm on the temporal graph for the participating peers. We implement a prototype of the proposed approach using Smart Contracts and deploy it on the Ethereum official test network, Rinkeby. For extensively evaluating the proposed techniques, we perform simulation experiments to validate the effectiveness of the reputation-aware timed data release protocols as well as our proposed temporal-graph-based improvements. The results demonstrate the effectiveness and strong attack resilience of the proposed mechanisms and our approach incurs only a modest gas cost.
In the era of digital healthcare, biomedical data sharing is of paramount importance for the advancement of research and personalised healthcare. However, sharing such data while preserving user privacy and ensuring data security poses significant challenges. This paper introduces BioChainReward (BCR), a blockchain-based framework designed to address these concerns. BCR offers enhanced security, privacy, and incentivisation for data sharing in biomedical applications. Its architecture consists of four distinct layers: data, blockchain, smart contract, and application. The data layer handles the encryption and decryption of data, while the blockchain layer manages data hashing and retrieval. The smart contract layer includes an AI-enabled privacy-preservation sublayer that dynamically selects an appropriate privacy technique, tailored to the nature and purpose of each data request. This layer also features a feedback and incentive mechanism that incentivises patients to share their data by offering rewards. Lastly, the application layer serves as an interface for diverse applications, such as AI-enabled apps and data analysis tools, to access and utilise the shared data. Hence, BCR presents a robust, comprehensive approach to secure, privacy-aware, and incentivised data sharing in the biomedical domain.
Although vehicular ad hoc networks (VANETs) significantly enhance traffic convenience, the propagation of erroneous information by malicious vehicles remains a challenging issue. To maintain message reliability, it is crucial to establish a trust management model that can promptly detect malicious vehicles and identify false messages. This article presents a novel trust management model based on blockchain, machine learning, and active detection technology. In the proposed model, we designed a trust evaluation scheme to evaluate the credibility by calculating the direct and indirect trust of the vehicle. To achieve this goal, we use active detection technology to detect indirect trust in vehicles, and then store it in the blockchain. The direct trust of the vehicle is calculated using a Bayesian classifier. The use of active detection technology speeds up the process of filtering out malicious vehicles. Machine learning technology simplifies the complex iterations involved in computing the trust value. Finally, the use of blockchain ensures the consistency and tamper-proofing of the trusted data. The simulation outcomes demonstrate that our approach outperforms the present trust management models.
Federated Learning (FL) is a well-known paradigm of distributed machine learning on mobile and IoT devices, which preserves data privacy and optimizes communication efficiency. To avoid the single point of failure problem in FL, decentralized federated learning (DFL) has been proposed to use peer-to-peer communication for model aggregation, which has been considered an attractive solution for machine learning tasks on distributed personal devices. However, this process is vulnerable to attackers who share false models and data. If there exists a group of malicious clients, they might harm the performance of the model by carrying out a poisoning attack. In addition, in DFL, clients often lack the incentives to contribute their computing powers to do model training. In this paper, we proposed Blockchain-based Decentralized Federated Learning (BDFL), which leverages a blockchain for decentralized model verification and auditing. BDFL includes an auditor committee for model verification, an incentive mechanism to encourage the participation of clients, a reputation model to evaluate the trustworthiness of clients, and a protocol suite for dynamic network updates. Evaluation results show that, with the reputation mechanism, BDFL achieves fast model convergence and high accuracy on real datasets even if there exist 30\% malicious clients in the system.