Online voting promises greater convenience and accessibility, but moving from supervised polling places to unsupervised settings magnifies the risk of coercion and vote buying. A compelling strategy is to give voters fake credentials: credentials that look and behave like real voting credentials but whose ballots are silently excluded from the tally. Despite its conceptual appeal, practical realizations and usability evidence for fake credentials have remained limited. This dissertation presents Votegral, the first end-to-end verifiable, coercion-resistant online voting system with empirical evidence towards practical usability. Votegral has two components: TRIP and VLT. TRIP is a trust-limited, in-person registration scheme that issues voters a real credential and any number of fake credentials on paper, without trusted hardware. TRIP embeds an interactive zero-knowledge proof into the physical printing process so that real credentials carry sound proof transcripts while fake credentials carry identically formatted but unsound proof transcripts -- distinguishable only by the voter during issuance and not transferable thereafter. VLT is a tallying scheme that constrains ballots to registrar-issued credentials to enable linear-time filtering of fake ballots. VLT also introduces standing votes: a voter facing extreme coercion can, at registration, delegate their voting rights to a publicly registered political party and leave the booth with only fake credentials. Tallying then credits the party's ballot by the number of such delegations and publishes publicly auditable proofs, resulting in both transparency and coercion evidence -- evidence that an aggregate number of voters felt unsafe to leave the registrar with a real credential. Our prototype tallies 1 million ballots in about 14 hours on a 128 core, 256 GB RAM machine; this puts Votegral on par with modern end-to-end verifiable systems such as Swiss Post, while significantly outperforming prior JCJ-style systems such as Civitas. TRIP's end-to-end, voter-observable registration session completes in under 20 seconds on resource-constrained hardware. In our main user study with 150 demographically diverse participants recruited in Boston, Massachusetts, 83% successfully registered and cast a ballot in our mock election. Among the 120 participants exposed to fake credentials, 96% correctly understood the purpose of fake credentials. These promising results suggest a path for practical viability of coercion-resistant, end-to-end verifiable online voting using fake credentials.
The decentralized, transparent, and immutable ledger system of blockchain has fundamentally changed data security and digital transactions. Blockchain has built-in security safeguards, yet it is still vulnerable to flaws and attacks. In this review paper, the authors will examine the threats and vulnerabilities that blockchain technology faces and the mitigation factors that can be used to overcome these issues. The authors discuss the significant threats like the 51% attack, double spending attack and many more that compromise the integrity of blockchain technology further authors discusses the vulnerabilities that are present in consensus mechanisms, smart contracts, network level, cryptography and privacy. These vulnerabilities expose blockchain networks to potential exploits and operational risks. To overcome these threats and challenges, the paper also discusses several countermeasures that are used for strengthening the blockchain network. It includes consensus mechanism enhancement through hybrid models and enhancing network-level protection against DDoS and routing attacks. This paper also discusses about the significance of quantum resistance cryptographic algorithms, privacy-enhancing technologies like zero-knowledge proofs, and scalability solutions such as layer 2 protocols and sidechains. This review paper also includes the current research and advancements in security blocks and provides a detailed understanding of the present work and future initiatives in the blockchain system.
Hye Jin Lee, Duc Anh Luong, Jong Hwan Park, Hyoseung Kim
Performance appraisal is crucial in human resource management to identify areas within organizations. Ensuring anonymity and confidentiality is important to obtain honest feedback and prevent retaliation. Although blockchain-based anonymous reputation systems have been discussed, permissioned blockchains are susceptible to Sybil attack vulnerabilities, while permissionless private blockchains do not provide full anonymity. We present the Anonymous Reputation System for Performance Appraisal (ARSPA), which uses a permissionless public blockchain. This system is designed for upward feedback in performance appraisals, employing cryptographic techniques such as non-interactive zero-knowledge proofs, public key encryption, and Merkle trees to ensure security. Our protocol addresses the risks of Sybil attacks, ensures review limitation and unforgeability. We validate the security of ARSPA through analysis and demonstrate its feasibility through proof-of-concept on Ethereum test networks. ARSPA provides a secure and efficient approach to improve the reliability and fairness of performance appraisal.
Manjula K. Pawar, Prakashgoud Patil, D. G. Narayan, Vasundhara Pandey · 6 authors
Blockchain’s decentralized, transparent, and immutable nature has revolutionized digital transactions by removing the need for central authorities. Ethereum stands out among blockchain platforms for facilitating secure peer-to-peer transactions via smart contracts. Despite its transformative potential, blockchain faces challenges, particularly with the PoW consensus algorithm, which demands high energy consumption and raises centralization concerns. This affects the scalability of Blockchain by reducing the throughput. This paper explores machine learning (ML) integration to address these challenges, specifically focusing on optimizing miner selection in the Ethereum blockchain based on predicted transaction times. The study compares the performance of various machine learning models, including ElasticNet, Lasso Regression, Multilayer Perceptron (MLP) Regression in optimizing miner selection for reduced transaction times on the Ethereum blockchain. This study advances the ongoing research on integrating machine learning with blockchain to address the shortcomings of traditional Proof of Work (PoW) systems. It emphasizes the potential of machine learning to propel future innovations in blockchain technology.
Brugeres, Maxence, Languille, Victor, Kuznetsov, Petr, Zarfaoui, Hamza
We propose a decentralized asset-transfer system that enjoys full privacy: no party can learn the details of a transaction, except for its issuer and its recipient. Furthermore, the recipient is not aware of the sender’s identity. Our system does not rely on consensus or synchrony assumptions, and therefore, it is responsive, since it runs at the actual network speed. Under the hood, every transaction creates a consumable coin equipped with a non-interactive zero-knowledge proof (NIZK) that confirms that the issuer has sufficient funds without revealing any information about her identity, the recipient’s identity, or the payment amount. Moreover, we equip our system with a regulatory enforcement mechanism that can be used to regulate transfer limits or restrict specific addresses from sending or receiving funds, while preserving the system’s privacy guarantees. Finally, we report on PaxPay, our implementation of Fully Private Asset Transfer (FPAT) that uses the Gnark library for the NIZKs. In our benchmark, PaxPay exhibits better performance than earlier proposals that either ensure only partial privacy, require some kind of network synchrony or do not implement regulation features. Our system thus reconciles privacy, responsiveness, regulation enforcement and performance.
The impact of sentiment analysis of comments on social networks such as X (Twitter) on the cryptocurrency market’s behavior has been proven. Also, traditional sentiment analysis and not considering the possible aspects of tweets can cause the deep model to be misleading in predicting the price trend of cryptocurrencies. In this research, a model using transfer learning and the combination of pretrained DistilBERT networks, BiGRU deep neural network, and attention layer is presented to analyze the sentiments based on the aspect of tweets and predict the price trend of eight cryptocurrencies. These tweets are the opinions of 70 cryptocurrency expert influencers. After preprocessing, these tweets are injected into the hybrid model of DistilBERT, BiGRU, and attention layer (HDBA) to extract the aspect and determine the polarity of each aspect. The output of the HDBA model is entered into the combined model of BiGRU and the attention layer (HBA) to predict the price trend of each cryptocurrency in intervals of 1–10 days. The output of the HBA model is the best time interval of the influence of the sentiments of tweets on the price trend of cryptocurrencies. The results show that the HDBA model has improved the performance of the aspect‐based sentiment analysis task by an average of 3% in the benchmark datasets. The results of the HBA model also show that this model has been able to predict the best time frame of the impact of sentiments on the behavior of the cryptocurrency market with an average accuracy of 68% and a precision of 73%.
Zheng Che, Meng Shen, Zhehui Tan, Hanbiao Du · 9 authors
With the rapid evolution of Web3.0, cryptocurrency has become a cornerstone of decentralized finance. While these digital assets enable efficient and borderless financial transactions, their pseudonymous nature has also attracted malicious activities such as money laundering, fraud, and other financial crimes. Effective detection of malicious accounts is crucial to maintaining the security and integrity of the Web 3.0 ecosystem. Existing malicious account detection methods rely on large amounts of labeled data and suffer from low generalization. Label-efficient and generalizable malicious account detection remains a challenging task. In this paper, we propose ShadowEyes, a framework for detecting malicious accounts by leveraging interaction feature learning with only a small labeled dataset. Specifically, We first propose a generalized account representation named TxGraph, which captures the universal interaction features of Ethereum and Bitcoin. Then we carefully design an account representation augmentation method tailored to simulate the evolution of malicious accounts to generate positive pairs. We conduct extensive experiments using public datasets to evaluate the performance of ShadowEyes. The results demonstrate that it outperforms state-of-the-art (SOTA) methods in four typical scenarios. Specifically, in the scenario of acrossplatform malicious account detection, ShadowEyes maintains an F1 score of around 90%, which is 10% higher than the SOTA method. In the zero-shot learning scenario, it can achieve an F1 score of 79.56% for detecting gambling accounts, surpassing the SOTA method by 10.44%.
Christos Karapapas, Iakovos Pittaras, George C. Polyzos, Constantinos Patsakis
The InterPlanetary File System~(IPFS) offers a decentralized approach to file storage and sharing, promising resilience and efficiency while also realizing the Web3 paradigm. Simultaneously, the offered anonymity raises significant questions about potential misuse. In this study, we explore methods that malicious actors can exploit IPFS to upload and disseminate harmful content while remaining anonymous. We evaluate the role of pinning services and public gateways, identifying their capabilities and limitations in maintaining content availability. Using scripts, we systematically test the behavior of these services by uploading malicious files. Our analysis reveals that pinning services and public gateways lack mechanisms to assess or restrict the propagation of malicious content.
Jieli Liu, Jiajing Wu, J. Chen, Yiyue Cao · 5 authors
In recent years, phishing scams have caused huge economic losses in Ethereum, the largest blockchain platform enabling smart contracts. Many new sorts of phishing attacks based on smart contracts, specifically targeting Ethereum assets such as Ether and tokens, are emerging. Existing Ethereum phishing detection methods usually mine the transaction relationships among accounts from block data, while neglecting to mine the temporal transaction patterns inherent in the accounts themselves in different transaction types introduced by smart contracts. Such information provides a new perspective for analyzing account transaction preferences. However, since this information is hidden in heterogeneous data such as trace data and event logs, it is difficult to analyze and mine the information. In this paper, we contribute Trans2Graph, a novel graph-based framework for Ethereum data modeling and phishing detection, to fully exploit the massively heterogeneous temporal transaction data. We propose a new paradigm for the fusion of heterogeneous Ethereum data and model the implicit transition relationships among multiple heterogeneous transactions of each Ethereum account into a heterogeneous, temporal, directed multigraph called transaction state transition graph. Empirical analysis shows that phishing accounts have unique patterns in both the heterogeneity and time dynamics of transaction state transition graphs. Based on the analysis, we develop a novel attention-based graph neural network for the learning of heterogeneous temporal state transition graphs and phishing detection. Experiments on a large-scale real-world dataset demonstrate that Trans2Graph achieves a minimum 52.57% improvement in the average precision metric on state-of-the-art account interaction graph-based methods and a minimum 11.52% improvement in average precision on transaction sequence-based methods.
Ethereum, as one of the most active cryptocurrency trading platforms, has garnered significant academic interest due to its transparent and accessible transaction data. In recent years, phishing scams have emerged as a serious criminal activity on Ethereum. Although most studies model Ethereum account transactions as networks and analyze them using traditional machine learning or network representation learning techniques, these approaches often rely solely on the latest static transaction records or use manually designed features while neglecting transaction histories, thus failing to fully capture the dynamic interactions and potential trading patterns between accounts. This article introduces an innovative multiperspective cascaded dynamic graph neural network model named DMPCG, which extracts phishing transaction data from authoritative databases like blockchain explorers to construct transaction network graphs. The model elevates the analysis from the microscopic features of nodes to the macroscopic dynamics of the entire network, integrating the attributes of static snapshot graphs with the evolution of dynamic trading networks, significantly enhancing the accuracy of phishing detection. Experimental results demonstrate that the DMPCG method achieves an impressive precision of 92.6% and an F1-score of 90.9%, outperforming existing baseline models and traditional subgraph sampling techniques.
Decentralized and distributed systems, like those based on Blockchain technology, are vulnerable to a form of attack called as the Sybil attack. It leads to initiate acute effect as well as initiate numerous other attacks like Denial of Service, Distributed Denial of Service, and majority attack etc. In Sybil attack, an adversary or a malicious user creates multiple fake “identities” in the system. Preventing Sybil attacks is a difficult in systems without a central trusted node. Various protocols based on social networks have been proposed by the research community to mitigate the influence of malicious nodes creating multiple identities, which differ in multiple ways in their approaches and guarantees. We explore these protocols in depth, including their assumptions, procedure, and results. Bitcoin and other traditional blockchain architectures use protocols like Proof of Work and Proof of Stake to make Sybil attacks expensive and impractical. This article provides a comprehensive survey of such techniques as applied in various cryptocurrencies.