Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

7 papersLast indexed Aug 31, 2026
Search papers

Paper index

7 results · page 1 of 1

Clear filters
Aug 29, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Decentralized Software Version Control System Based on Blockchain

Jincheng Zhang

This paper proposes a decentralized software version control system leveraging blockchain technology. Traditional version control systems suffer from central points of failure, lack of transparency, and limited traceability. This system addresses these shortcomings by utilizing a blockchain to immutably record and manage software version information. The core mechanism involves hashing software versions and storing these hashes on a blockchain, ensuring data integrity and providing a transparent, auditable trail. This approach enhances security, improves transparency, and offers enhanced traceability compared to centralized solutions. The system utilizes a distributed consensus mechanism to maintain blockchain integrity, mitigating the risks associated with a single point of failure. This research explores the feasibility and potential benefits of applying blockchain technology to software version control, representing a novel approach to managing software evolution.

Open access
Blockchain Technology Applications and Security
Software System Performance and Reliability
Software Engineering Research
Original source
Aug 28, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Blockchain-Based Software Version Control System

Jincheng Zhang

This paper proposes a novel approach to software version control leveraging the inherent properties of blockchain technology. Traditional version control systems suffer from centralized vulnerabilities and single points of failure, leading to potential data loss and compromised integrity. This system addresses these limitations by utilizing blockchain's immutable ledger and distributed storage capabilities. Each software code version is recorded as a transaction on the blockchain, secured by a consensus mechanism. This ensures a complete and verifiable history of code changes, dramatically enhancing security, reliability, and transparency compared to conventional methods. The core claim of this work is that the combination of blockchain's features provides a significantly more robust and trustworthy software version control solution. The system's design incorporates key mechanisms such as transaction hashing, smart contracts for version management, and a distributed consensus protocol to guarantee data integrity and consistency. The resulting architecture offers a compelling alternative for organizations seeking a secure and resilient software development environment.

Open access
2 source records
Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Software System Performance and Reliability
Original source
Aug 27, 2026·Research Square
0 cites
Investigating the application of differential fuzzing to support the identification and suppression of equivalent mutants: An experimental study

Bruno Ely Reis Garcia, Simone R. S. Souza

Abstract Mutation testing is widely used to assess the adequacy of test suite; however, its practical adoption is constrained by the persistent problem of equivalent mutants, i.e., mutants whose observable behavior is indistinguishable from the original program and therefore cannot be killed by any test case. Prior studies report that identifying equivalent mutants often requires substantial manual effort. Meanwhile, fuzzing is increasingly used in real-world systems, especially security-critical software. However, conventional fuzzing oracles typically detect only crash-like failures, thereby missing many behavioral changes introduced by mutants. In this paper, we investigate differential fuzzing as a practical, language-agnostic approach to support mutant classification, focusing on identifying (and confirming) equivalent mutants. We conduct a multi-project study across Bitcoin Core (C++), OpenSSL (C), LND (Go), and Arrow (Python), mutating six real functions with 1,090 valid mutants generated by the universalmutator. We compare unit/functional testing, seed-corpus-only fuzzing, time-bounded fuzzing, and two differential fuzzing configurations (seed-corpus-only and time-bounded). Our results show that conventional fuzzing yields the lowest mutation scores, while time-bounded differential fuzzing (5 minutes per mutant) achieves 98–100\% mutation score in five of six targets, and exposes cases where seed corpora contain valuable test inputs not covered by unit/functional suites. We further analyze runtime variability and observe log-normal behavior in difficult cases, providing practical guidance on stopping criteria (time/execution budgets), as well as evidence that dictionaries and parallel fuzzing can significantly improve effectiveness. Overall, our findings indicate that differential fuzzing is simple to implement and can classify mutants efficiently in practice, while also producing actionable artifacts (seed corpus inputs) to strengthen traditional test suites.

Open access
Software Testing and Debugging Techniques
Software Engineering Research
Software System Performance and Reliability
Original source
Aug 26, 2026·Research Square
0 cites
Architectural Framework for ERP-WMS Integration: Mitigating Data Latency and Transactional Asymmetry in Integrated Logistics Systems

Arijit Das

Abstract This paper presents a novel, vendor-agnostic stateful orchestration architecture designed to mitigate systemic data latency and transactional asymmetry within integrated enterprise-level logistics frameworks. In multi-enterprise distributed environments, the decoupling of decentralized physical Warehouse Management Systems (WMS) from centralized Enterprise Resource Planning (ERP) database cores introduces severe synchronization boundary failures. We systematically analyze three critical points of operational vulnerability: serialization asymmetry in distributed tracking, atomic transaction failures during partial outbound executions, and inventory record propagation delay within reverse logistics matrices. To resolve these vulnerabilities, we introduce the State-Aware, Automated Alignment, Integration Integrity, and Logistics Cost Optimization (SAIL) framework. By transitioning integration middleware from stateless message routing pipes to active, state-retaining orchestration layers, the SAIL framework leverages an automated Heuristic Validation Buffer (HVB), an asynchronous Dual-Handshake Programmatic Lock protocol, and multi-variable cost-weight heuristic models. Field evaluation validates that the proposed architecture eliminates up to 90% of manual inventory remediation transactions while maintaining strict end-to-end ledger integrity across completely decoupled data systems.

Open access
Software System Performance and Reliability
Distributed systems and fault tolerance
Mobile Agent-Based Network Management
Original source
Aug 21, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Commitment Lifetime Analysis in Decentralized Finance

Jincheng Zhang

This paper investigates the concept of "commitment lifetime" within the context of decentralized finance (DeFi) protocols, specifically focusing on the variability in the duration a user's commitment to a collateralized asset remains valid. The commitment lifetime, denoted as *LC(P)*, is defined as the difference between the release time and the birth time of the commitment, where *trelease* and *tbirth* represent the respective timestamps. The core objective is to analyze the probability distribution of commitment lifetimes, denoted as *P(LC > t)*, for different algorithmic approaches used in managing collateralized positions. We demonstrate that despite potentially differing underlying mechanisms, various DeFi protocols can arrive at identical conclusions regarding commitment lifetimes. This highlights the importance of understanding the mathematical representation of commitment lifetime distributions, which we term the "commitment lifetime distribution." This analysis provides a foundational understanding for risk management and parameter optimization within DeFi systems.

Open access
2 source records
Software System Performance and Reliability
Advanced Queuing Theory Analysis
Age of Information Optimization
Original source
Aug 7, 2026·arXiv (Cornell University)
0 cites
Dual-Node NVIDIA DGX Spark over Tailscale: A Remote-Access Testbed for Distributed LLM Training and Cyber-Threat-Intelligence Fine-Tuning

Vasanth Iyer

Compact AI systems make local language-model experimentation increasingly accessible, yet practical evidence for multi-node training on desktop-class accelerators remains limited. This report presents a proof-of-concept deployment of distributed NanoChat pretraining across two NVIDIA DGX Spark systems, each with a GB10 Grace Blackwell system-on-chip and 128 GB of unified memory, administered remotely over a Tailscale mesh VPN and connected for training by a dedicated 200 Gb/s QSFP56 direct fiber link. PyTorch torchrun, DDP, and NCCL were configured with one process per node, a depth-20 NanoChat model, a local batch size of 32 per node, and a 2,048-token context, giving a global batch of 131,072 tokens per step. The run sustained a step time of about 69.4 s (about 1,890 tokens/s), processing about 653 million tokens over four days. We document link configuration, container setup, interface binding, a step-zero evaluation bug that triggered NCCL timeouts, checkpointing, and troubleshooting lessons, as a reproducibility reference for small labs. We also built a cybersecurity fine-tuning dataset from 77 CISA advisories (338 training, 37 validation conversations) and ran a 17-question held-out evaluation comparing a baseline SFT checkpoint against a CTI-augmented checkpoint with an Ollama-hosted LLM judge. CTI-specific categories improved while general-knowledge categories regressed, for a small overall change from 2.06 to 2.29 on a 0-10 scale. The same cluster supports a 400-level AI course (CS 426) and a query engine for CompTIA Security+ POGIL activities in CBS 255, showing modest local infrastructure can serve both research and teaching. The study establishes feasibility rather than a scaling-efficiency claim, since single-node throughput used for comparison was estimated, not measured under matched conditions. Runbook and scripts are available (see Code Availability).

Open access
Scientific Computing and Data Management
Parallel Computing and Optimization Techniques
Software System Performance and Reliability
Original source
Aug 5, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
DROS-6P: A Unified Deterministic Runtime Governance Architecture Closing the Six Fundamental Trust Boundaries of Enterprise AI Agents / DROS-6P:閉環企業級AI Agent 六大信任邊界之 確定性執行期治理架構

Chun-Cheng (Jimmy) Chen

Abstract—As Autonomous AI Agents transition from conversational prototypes to enterprise-grade execution agents, currentsecurity architectures face a fundamental breakdown. Enterprise deployment demands unequivocal answers to six core trust questions: Principal (who does the agent represent?), Authorization (what is it allowed to do?), Tool/Action Bound (which API calls are safe?), Policy Gate (how are high-risk actions controlled?), Audit Log (how are actions traced immutably?), and Expiry/Revocation (how is authorization revoked instantly?). Existing enterprise solutions address at best one or two boundaries: IAM frameworks resolve identity but fail at granular tool execution; prompt guardrails handle basic content filtering but lack real-time authorization or cryptographic auditability; SIEM platforms store logs post-hoc without real-time interception capabilities. This paper introduces DROS-6P, a unified, deterministic runtime governance kernel designed to enforce all six fundamental trust boundaries within a single C-ABI and eBPF in-band execution layer. To prevent the security control plane from becoming a throughput bottleneck or a single point of failure under high-frequency system calls (Syscalls) generated by enterprise, third-party, or malicious agents—thereby mitigating self-induced Denial-of-Service (DDoS) degradation—runtime governance requires microsecondlevel evaluation capability. Empirical benchmark evaluations demonstrate that the DROS-6P in-band kernel achieves an average decision latency of approximately 26.1 μs. Specifically, DROS-6P enforces: (1) Principal via 3-tier PKI-signed DROS Identity Tokens (DIT); (2) Authorization via Capability Bitmaps mapping roles to deterministic execution vectors; (3) Tool/Action Bound via in-band C-ABI interceptors at the FFI boundary; (4) Policy Gate via dynamic data redaction, Human-In-The-Loop (HITL) suspension, and ZKP-Lite zero-knowledge proofs; (5) Audit Log via tamper-evident SHA-256 Merkle Hash Chains and Ed25519 signatures; and (6) Expiry/Revocation via O(1) Read-Copy-Update (RCU) atomic pointer swaps providing instant HTTP 403 enforcement. We validate DROS-6P across six heterogeneous domain tracks (Carbon DPP, Fintech AML, HIPAA Healthcare, Government Proxy Services, Inclusive Migrant Finance, and RBA Supply Chain Compliance), providing a fully reproducible testbed with 100% automated test assertions passed (0.004s), demonstrating that unified physical-layer governance is necessary and sufficient for safe enterprise AI agent deployment.Abstract—隨著自主AI Agent(自主智能體)從對話式原型走向企業級執行場景,傳統資安架構正面臨根本性的崩潰。企業部署AI Agent 時,必須對六大核心信任問題給出明確答案:Principal(Agent 代表誰?)、Authorization(被授權做什麼?)、Tool/Action Bound(哪些API 呼叫安全?)、Policy Gate(高風險動作如何控制?)、Audit Log(行動如何不可篡改地追溯?)以及Expiry/Revocation(授權何時失效且如何即時停止?)。然而,現有的企業安全處方最多只能回應一至兩個邊界:IAM 系統解決了身份認證,卻對動態Tool 呼叫束手無策;Prompt 防火牆(Guardrails)僅能處理文字層提示,缺乏執行期動態授權與密碼學稽核能力;SIEM 平台僅提供事後日誌紀錄,缺乏帶內即時攔截與防衛能力。本論文提出DROS-6P ——旨在單一C-ABI與 eBPF 帶內執行層中,同時強制執行這六大信任邊界之確定性執行期治理微內核。為確保安全控制面本身不會在企業內部、外部或惡意Agent 產生高頻系統呼叫(Syscalls)時成為效能瓶頸或單點故障點,進而防範自我引發的服務阻斷(Self-induced DDoS)與系統衰退,執行期治理必須具備「微秒級(μs)」的評估能力。實證基準測試顯示,DROS-6P 帶內微內核在測試環境中達到約26.1 μs 的平均決策延遲。具體而言,DROS-6P 強制執行:(1) Principal:透過3 階PKI 簽章之DROS 身份標籤(DIT);(2) Authorization:透過將角色精確映射至執行向量的確定性Capability Bitmaps;(3) Tool/Action Bound:透過FFI 邊界處的帶內C-ABI 攔截器;(4) Policy Gate:透過動態資料遮蔽(Redaction)、人工懸停審查(HITL) 與ZKP-Lite 零知識證明;(5) Audit Log:透過不可篡改的SHA-256 Merkle 雜湊鏈與Ed25519 數位簽章;以及(6) Expiry/Revocation:透過Read-Copy-Update (RCU) 原子指針交換實現O(1) 常數時間動態撤銷與秒級HTTP 403 阻斷。我們提供完全可重現的本地測試環境(test_verification_suite.py),100% 通過自動化斷言測試(耗時0.004s),並在六個異質產業賽道中驗證了DROS-6P,證明統合物理層治理是企業安全部署AI Agent 的充要條件。

Open access
3 source records
Access Control and Trust
Security and Verification in Computing
Mobile Agent-Based Network Management
Original source