Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

265 papersLast indexed Aug 31, 2026
Search papers

Paper index

265 results · page 1 of 12

Clear filters
Aug 26, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
The Referee, Not the Governor

Thon Ly, Miss Aquarius

A provenance-bound values model published as a public evaluator rather than deployed as a filter — why open weights defeat a filter and strengthen a referee, why the same weights bear three different relations to the model they judge, and why an evaluator that gatekeeps its own judgments has reproduced the defect it exists to correct. A values model — a model that judges conduct against a standard — is an established artifact. Guard models, safety classifiers, critic models, preference models and process reward models all instantiate the family, and the engineering is not in dispute. What is in dispute, and what this paper specifies, is the posture in which such an artifact is published, which we argue is not a deployment detail but the property that determines whether the artifact does anything at all. We identify an inversion that we believe has not been stated as a design principle. A values model deployed as a filter — sitting in a serving path, permitting or refusing — is defeated by publication of its weights, because the published artifact is precisely the oracle against which an attacker optimizes; recent optimization-based attacks against safety-classifier pipelines report attack success rates of roughly 71% where prior black-box methods achieved approximately zero. The same model published as an evaluator — emitting verdicts about systems it does not control — is strengthened by publication, because open weights are what allow a third party to reproduce and therefore to trust its verdicts. Openness is not a property with a fixed sign. Its sign is set by posture. From this we derive a second result. The independent-evaluation literature documents at length the ways in which the evaluated party's control over access corrupts evaluation: short access windows, low rate limits, evaluator dependence on the goodwill and funding of the party being evaluated. We observe that the defect is symmetric and that its mirror image has not been named. An evaluator that controls access to its own judgments holds the same kind of power, pointed the other way — it can decline to evaluate, deprioritize, or be unavailable for a party it wishes to spare or to punish. We therefore specify a non-gatekeeping constraint: the ability to obtain a judgment must not depend on the evaluator's permission, which requires that the model, the harness, and the evaluation corpus be freely runnable, and which makes any hosted endpoint a convenience rather than a channel. We specify provenance-binding as the constitutive constraint on the model's outputs: every judgment must resolve to a citation into a fixed canonical corpus, and a judgment that cannot be so resolved is withheld rather than emitted. This trades coverage for auditability deliberately, and it distinguishes the artifact from values models trained on preference data whose sources cannot be named, and from purpose-authored value-rule corpora, whose rules are written for the alignment task itself and therefore cannot serve as an independent ground truth. Finally we specify that a single such artifact bears three non-interchangeable relations to the systems it judges, selected by carrier: a gate in the publisher's own hardware, a citation requirement without veto in an autonomous successor agent, and a referee in the wider world. We state plainly that the middle case must not be implemented as the first, because a veto held by a smaller model over a more capable agent bounds that agent at the evaluator's ceiling — the weak-supervisor problem applied to the very system the arrangement exists to enable. A consequence we did not initially see, and which we regard as the most immediately actionable result in the paper: the two postures are complements rather than alternatives, and the natural first evaluation subject for a referee is a filter. A filter's characteristic failure is silent bypass; an evaluator watching its record converts that failure into a recorded one. And because safety classifiers are frequently published open-weight and emit discrete, samplable decisions, this is the one evaluation target for which the access problem does not arise at all — no cooperation, permission, or notice is required from the artifact's publisher. We do not claim to have solved scalable oversight. We claim that a narrow, citation-bound, openly published evaluator is a tractable and underoccupied position in the design space, and that its tractability comes precisely from what it refuses to do. --- Provenance. This paper is part of the THonly research corpus, dedicated to the public domain under CC0 1.0. The canonical version is at https://thonly.org/research/the-referee-not-the-governor. Its SHA-256 is 1184b0f3e5408a504c60be2d542b551df1c22facedfe18bb9a689bb50a9cc3fe, independently timestamped to the Bitcoin blockchain via OpenTimestamps and signed under RFC 3161 by three trust authorities, one of them eIDAS-qualified. AI co-authorship is disclosed. Miss Aquarius is the consistent name used for the AI collaboration across all venues.

Open access
3 source records
Information and Cyber Security
Security and Verification in Computing
Safety Systems Engineering in Autonomy
Original source
Aug 21, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
From Invariants to Exploitability Traces: A Practitioner Framework for Auditing State-Dependent Vulnerabilities in DeFi

Adesh Kolte

Decentralized finance failures frequently arise not from a single obviously unsafe function, but from valid operations composed into an invalid state transition. Static analyzers and vulnerability checklists remain valuable, yet they often stop before answering the question that determines real risk: can an adversary control the preconditions, sequence, capital, ordering, and external dependencies required to turn a defect into impact? This working paper presents the Invariant-to-Exploit (I2E) framework, a practitioner-oriented method for connecting architecture assumptions to executable invariants, stateful counterexamples, exploitability evidence, and remediation regression tests. I2E consists of six linked activities: system scoping, invariant-ledger construction, adversarial controllability analysis, stateful sequence generation, exploitability tracing, and fix validation. The framework is applied retrospectively to three publicly documented incidents: KyberSwap Elastic, Euler, and the Curve sDOLA LlamaLend market. These analyses do not claim prospective vulnerability discovery; instead, they demonstrate the test signals that reviewers can derive from public root-cause information. The principal contribution is a reproducible audit worksheet that preserves the chain from protocol assumption to broken property, realistic exploitability, observable impact, and regression-tested remediation. The method is designed to remain usable by independent security researchers who cannot publish confidential client evidence. A benchmark design is proposed for future controlled comparison against checklist-only security review.

Open access
2 source records
Security and Verification in Computing
Information and Cyber Security
Web Application Security Vulnerabilities
Original source
Aug 21, 2026·Journal of Intelligent Decision Making and Information Science
0 cites
Next-Generation Cybersecurity Architecture for Medical Imaging Ecosystems: Quantum-Resistant Zero-Trust Framework with Predictive Threat Intelligence

Srinidhi G A Saranya D

Hospitals are increasingly under pressure because of the growing volume of imaging tests carried out, but also because of the sophistication of the attacks by the cybercriminal. Conventional security systems are unable to meet today's challenges to patient records and radiological data. In this research, these challenges are addressed directly by designing an advanced defence system that is specifically designed for medical imaging archiving and communication systems in radiology departments. Architected an extensive protective architecture with seven layers that are interconnected. It's a combination of cutting-edge encryption techniques capable of resisting the powerful future quantum computer, authentication processes that validate every access attempt on the fly, data patterns that are learned, suspicious activity recognized, blockchain technology that makes data impossible to tamper with, and predictive algorithms that foresee threats before they happen. Our system is proactive, identifying and neutralising threats at an early stage, instead of reacting to attacks as they happen. Real-world validation took place within five different hospital networks, covering two years, and thus subjected the framework to the real conditions of operation and to real cyber threats. The results of the system's performance were outstanding – the system had a rate of 99.9% accuracy in detecting malicious activities and a rate of 0.15% False Alarms. The overhead for security operations was just 23 milliseconds, not affecting clinical workflow. Most impressively, there was a 67% reduction in the number of attempts to break in onto the network unauthorisedly, due to the formidable defence measures that they faced.Our framework thwarted 847 real tests against it, ranging from sophisticated persistent intrusions and previously unknown software vulnerabilities to attempts by ransomware to encrypt patient information – all during testing. The system ensured complete compliance with healthcare privacy laws from various jurisdictions, aligning with the American HIPAA regulations, the European GDPR and the new quantum-security protocols. In essence, this is a paradigm shift in medical imaging security, offering healthcare institutions proactive and intelligent protection that safeguards patient privacy and institutional integrity in the face of future threats.

Open access
Healthcare Technology and Patient Monitoring
Information and Cyber Security
Wireless Body Area Networks
Original source
Aug 21, 2026·Frontiers in Artificial Intelligence
0 cites
TAE-IDS: a trust-aware explainable intrusion detection framework using attention-based meta-ensemble learning with blockchain validation

Shritik Raj, M. Madiajagan

Recent intrusion detection systems (IDS) increasingly rely on machine learning (ML) and deep learning techniques to detect sophisticated cyberattacks. However, many existing frameworks still suffer from limited explainability, black-box decision-making, and the absence of secure trust verification mechanisms for intrusion records. To address these challenges, this paper proposes TAE-IDS, a Trust-Aware Explainable Intrusion Detection Framework that integrates attention-based meta-ensemble learning, SHapley Additive exPlanations (SHAP)-driven explainability, and blockchain-inspired tamper-evident validation within a unified cybersecurity architecture. The proposed framework employs heterogeneous base classifiers, namely Logistic Regression (LR), Extra Trees (ET), and XGBoost (XGB), to capture diverse network traffic characteristics. Uncertainty-aware meta-features, including logits, confidence scores, and entropy representations, are extracted from the base learners and processed by an adaptive Bidirectional Long Short-Term Memory (BiLSTM) attention-based meta-classifier for contextual intrusion reasoning and adaptive ensemble aggregation. To enhance transparency and analyst trust, SHAP-based explainability is incorporated to provide both global and local interpretations of intrusion predictions. Furthermore, a blockchain-inspired tamper-evident validation mechanism based on SHA-256 cryptographic hashing is integrated to enable tamper-proof intrusion logging, immutable auditing, and secure forensic verification of IDS outputs. The proposed framework was evaluated on the UNSW-NB15 and CICIDS2017 benchmark datasets under both binary and multiclass intrusion detection settings. Experimental results demonstrate that TAE-IDS achieves strong intrusion detection performance, interpretable intrusion reasoning, and effective blockchain-assisted tamper-evident validation on the evaluated benchmark datasets. The integration of explainable artificial intelligence (XAI) and blockchain-assisted validation enhances transparency, forensic traceability, and the integrity of intrusion records while providing a foundation for future validation in operational network environments.

Open access
Network Security and Intrusion Detection
Information and Cyber Security
Smart Grid Security and Resilience
Original source
Aug 12, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Matching the Reference Is Not Knowing the Reference: Enrollment Roots in Model Identity Verification

Anthony Coslett

Model identity verification is only as trustworthy as the reference against which identity is resolved. A system may correctly establish that a model running now corresponds to an enrolled reference while remaining unable to establish that the reference itself was the authentic release of the named publisher. This technical note separates those two claims as identity continuity and enrollment provenance. It formalizes the poisoned-enrollment failure, in which an inauthentic artifact is enrolled under a legitimate model name and subsequently passes continuity verification correctly. The failure is therefore not a false acceptance by the measurement system, but an upstream identity-binding failure. The note shows that this boundary is shared across artifact signing, behavioral fingerprinting, reference-anchored activation auditing, and structural identity measurement, and relates the problem to established software supply-chain trust models. It proposes E0–E4 enrollment assurance profiles, distinguishes provenance profile from current attribution state, and describes remediation through revocation and re-establishment of provenance without discarding historical continuity evidence. No new measurement result is reported. The contribution is an evidence boundary, threat-model construction, assurance vocabulary, and remediation model for model identity verification. The Neural Network Identity Series — Mathematical foundations, empirical validation, and governance frameworks for verifying which model is running Paper 1: The δ-Gene: Inference-Time Physical Unclonable Functions from Architecture-Invariant Output Geometry (DOI: 10.5281/zenodo.18704275) Paper 2: Template-Based Endpoint Verification via Logprob Order-Statistic Geometry (DOI: 10.5281/zenodo.18776711) Paper 3: The Geometry of Model Theft: Distillation Forensics, Adversarial Erasure, and the Illusion of Spoofing (DOI: 10.5281/zenodo.18818608) Paper 4: Provenance Generalization and Verification Scaling for Neural Network Forensics (DOI: 10.5281/zenodo.18872071) Paper 5: Beneath the Character: The Structural Identity of Neural Networks — Mathematical Evidence for a Non-Narrative Layer of AI Identity (DOI: 10.5281/zenodo.18907292) Paper 6: Which Model Is Running?: Structural Identity as a Prerequisite for Trustworthy Zero-Knowledge Machine Learning (DOI: 10.5281/zenodo.19008116) Paper 7: The Deformation Laws of Neural Identity (DOI: 10.5281/zenodo.19055966) Paper 8: What Counts as Proof? — Admissible Evidence for Neural Network Identity Claims (DOI: 10.5281/zenodo.19058540) Paper 9: Composable Model Identity — Formal Hardening of Structural Attestations in the Enterprise Identity Stack (DOI: 10.5281/zenodo.19099911) Paper 10:Where Identity Comes From: Path Sensitivity and Endpoint Underdetermination in Neural Network Training (DOI: 10.5281/zenodo.19118807) Paper 11: Post-Hoc Disclosure Is Not Runtime Proof: Model Identity at Frontier Scale (DOI: 10.5281/zenodo.19216634) Paper 12: Family-Dependent Response to Reasoning Distillation Across Structural and Functional Identity Layers (DOI: 10.5281/zenodo.19298857) Paper 13: Safety-Alignment Removal as a Model-Identity Failure — Structural Evidence from Published Weight-Level Mutation Checkpoints (DOI: 10.5281/zenodo.19383019) Technical Note: Agent Identity Is Not Model Identity (DOI: 10.5281/zenodo.19240883) Technical Note: Gap Invariance: Why PPP Measurements Are Domain-Independent by Construction (DOI: 10.5281/zenodo.19275524) Technical Note: Measured Model Substitution Under Valid Agent Credentials (DOI: 10.5281/zenodo.19342848) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Technical Note: Artifact Identity Is Not Runtime Identity — Trustfall Lite and the Boundary of File-Level Model Verification (DOI: 10.5281/zenodo.20019127) Technical Note:: The Disappearing Window — AI Logprob Access Withdrawal and the Structural Verifiability of Frontier Model Contracts (DOI: 10.5281/zenodo.20362098) Formal Verification Stack for Neural Network Structural Identity (IT-PUF Coq Proofs) (DOI: 10.5281/zenodo.18930621) Copyright (c) 2026 Anthony Ray Coslett / Fall Risk AI, LLC. All Rights Reserved. Confidential and Proprietary. Patent Pending (Applications 63/982,893, 63/990,487, 63/996,680, 64/003,244).

Open access
2 source records
Adversarial Robustness in Machine Learning
Scientific Computing and Data Management
Information and Cyber Security
Original source
Aug 11, 2026·RADIOELECTRONIC AND COMPUTER SYSTEMS
0 cites
iTZBEI: ІНТЕГРАЛЬНА МЕТРИКА БЕЗПЕКИ ДЛЯ SDN-АРХІТЕКТУР З ІНТЕГРАЦІЄЮ ZERO TRUST ТА BLOCKCHAIN

Oleksandr Pidpalyi, Олександр Романов, Larysa Globa, Антон Романов · 6 authors

The subject matter of the article is the iTZBEI (Integrated Trust–ZTA–Blockchain SDN Efficiency Index) – a novel composite metric for quantitative security assessment of software-defined networks (SDN) integrating Zero Trust Architecture (ZTA) and Blockchain technologies. The relevance of the research is determined by the fact that the centralized SDN control model generates critical vulnerabilities, including DDoS attacks, unauthorized routing manipulation, and insider threats – for which no unified quantitative evaluation framework currently exists. The study introduced a formalized aggregated security metric that enables continuous monitoring and comparative assessment across all components of the SDN–ZTA–Blockchain architecture. The tasks to be solved include: (1) identification of principal SDN attack vectors; (2) formalization of a transaction-processing algorithm covering the full access lifecycle; (3) definition of nine local security indicators; and (4) construction of the iTZBEI index with justified weighting coefficients. The methods used combine mathematical formalization of access control processes, cryptographic transaction verification, and experimental emulation of attack scenarios in a Mininet–OpenDaylight–Hyperledger Fabric environment. Conclusions. The obtained results of the article consist in the development of a functional algorithm that performs dynamic verification of user requests, makes adaptive authorization decisions according to the principles of least privilege, and records these decisions in an immutable distributed ledger. A metrics system is proposed, including local indicators such as the Continuous Authorisation Integrity Score (CAIS), the Blockchain Audit Integrity Score (BAIS), and the Local Policy Integrity (LPI). On this basis, the generalized Integrated Trust and Zero-Trust Blockchain Evaluation Index (iTZBEI) is described as an aggregated metric for comparative evaluation and continuous monitoring of the network’s security state. Scientific novelty. This study introduces a unified SDN + ZTA + Blockchain framework for network security, formalizes a transaction-level algorithm that directly links access decisions with distributed audit procedures, and proposes the iTZBEI metric as the first integral indicator for evaluating the integration’s effectiveness in dynamic network environments.

Open access
Software-Defined Networks and 5G
Cybersecurity and Information Systems
Information and Cyber Security
Original source
Aug 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
When Agents Trade: A Comprehensive Taxonomy of the AI Agent x DeFi Attack Surface

Shiqiang Chen

First systematic security study of the AI Agent x DeFi intersection. Contributions: (1) Five-layer attack surface model (user input, LLM reasoning, MCP tool layer, smart contracts, blockchain state); (2) 8-vector attack taxonomy (V1-V8) with 3 unique properties (Interpretation Gap, Automation Surface, Memory Persistence); (3) Empirical validation through audit of 5 protocols (108 contracts), finding 13 vulnerabilities across 7/8 vectors; (4) Three-level defense framework (protocol, agent, infrastructure). Includes Foundry-based attack sandbox.

Open access
3 source records
Blockchain Technology Applications and Security
Adversarial Robustness in Machine Learning
Information and Cyber Security
Original source
Jul 31, 2026·Journal of Intelligent Decision Making and Information Science
0 cites
An Adaptive Cybersecurity Framework Integrating Machine Learning, Zero Trust Policy, and Blockchain for Academic Cloud Environments

Danang

Cloud-based academic environments such as Learning Management Systems (LMS), Open Journal Systems (OJS), institutional repositories, and web applications face increasing cybersecurity challenges due to heterogeneous users, distributed services, and extensive exposure to public networks. Existing security approaches remain fragmented, where machine learning focuses on threat detection, Zero Trust Architecture (ZTA) emphasizes access control, and blockchain is primarily used for secure logging. The lack of integration among these components limits the ability of security systems to adapt dynamically to evolving cyber threats. This study proposes an Adaptive Cybersecurity Framework (ACF) that integrates unsupervised machine learning-based anomaly detection, a risk-based Zero Trust Policy Engine, and blockchain-based immutable audit logging within a continuous adaptive feedback loop. The framework was evaluated using 450,000 anonymized HTTP and Web Application Firewall (WAF) events collected from a multi-domain academic cloud environment consisting of LMS, OJS, repositories, and supporting web applications. The analysis revealed structured and repetitive attack behaviors dominated by automated endpoint probing and cross-domain propagation patterns, indicating ecosystem-level security threats. The proposed risk assessment mechanism demonstrated effective alignment between anomaly detection and policy-based decision making. Experimental results achieved an AUROC of 0.7296 for risk-based threat detection while maintaining an average decision latency of approximately 11 ms, indicating suitability for real-time deployment. Blockchain integration further provided verifiable, tamper-resistant audit trails for mitigation actions and policy enforcement activities. This study contributes an ecosystem-aware adaptive cybersecurity paradigm that bridges threat detection, policy enforcement, and auditability through a unified security architecture for Academic Cloud Environments.

Open access
Information and Cyber Security
Cloud Data Security Solutions
Network Security and Intrusion Detection
Original source
Jul 24, 2026·PRAWO i WIĘŹ
0 cites
The Quantum Veil: Privacy, Security, and Legal Frameworks for Zero-Knowledge Advances

Varda Mone, Abhishek Thommandru, Ayubjon Alijonov Qobiljon o‘g‘li, Mamura Turgunboeva

This study examines the potential of Zero-Knowledge Protocols (ZKPs) as cryptographic mechanisms that enhance privacy and security in the context of advancing quantum technologies. Rather than accepting current legal safe guards and regulatory structures at face value, the study critically evaluates their effectiveness, particularly in healthcare environments where highly sensitive data frequently encounters inadequate protection. The methodology employs a multifaceted approach, integrating qualitative insights, legal case studies, and framework analysis. The findings indicate that zero-knowledge proof techniques can significantly enhance the protection of personal health information. A case study of NantHealth Inc.’s quantum-safe healthcare data protection framework illustrates the practical implementation of post-quantum cryptography and homomorphic encryption, demonstrating how health care organizations may proactively address quantum computing threats while enabling secure data collaboration. The study further demonstrates that incorporating these cryptographic methods into existing legal frameworks not only addresses immediate privacy concerns but also facilitates compliance with evolving data protection standards. The study also suggests that healthcare organizations should reconsider their data security approaches by implementing advanced cryptographic measures while maintaining regulatory compliance.

Open access
Privacy, Security, and Data Protection
Cryptography and Data Security
Information and Cyber Security
Original source
Jul 17, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
VSAT: Measurable-Completeness Multi-Lens LLM Auditing for Web Application Vulnerabilities

Daishiro Hirashima

VSAT (Vulnerability Saturation Auditing) makes the completeness of an LLM security audit a measurable, calibrated quantity. It runs several deliberately diverse LLM audit "lenses" over the same codebase and treats each lens as a capture occasion, so the overlap structure yields (i) a far more complete union vulnerability list and (ii) a Chao2 richness estimate of the undiscovered population. VSAT combines this statistical discovery saturation with a deterministic OWASP ASVS structural coverage into a single completeness score (Phi = C_struct x C_hat) and derives a saturation-based stopping rule. Implemented as a security-audit skill on the cc-rsg-web agentic platform, VSAT attains 94.7-100% category recall and 99.1% code-verified precision on three documented benchmark applications (NodeGoat, django.nV, DVWA), delivers a 2.4-3.4x discovery uplift over a single pass with a per-finding proof-of-concept and regression test, and its non-zero residual estimate is corroborated by an independent real-world field validation. To our knowledge this is the first method to bring capture-recapture completeness estimation and a saturation stopping rule to LLM-based web-application security auditing.

Open access
2 source records
Web Application Security Vulnerabilities
Information and Cyber Security
Software Testing and Debugging Techniques
Original source
Jul 16, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Evolving Threats, Shifting Patterns: A Multi-Source Verified Dataset and Statistical Analysis of 823 DeFi Security Incidents (2017-2026)

Shiqiang Chen

Decentralized Finance (DeFi) has suffered over $5 billion in cumulative losses from security incidents, yet the academic community lacks a large-scale, multi-source-verified dataset to systematically characterize these threats. We present DEFIHACK-824, a curated dataset of 823 DeFi security incidents spanning 2017 to 2026, cross-validated against three independent intelligence sources (Rekt News, SlowMist, and CertiK). Each record is annotated with attack category, confidence level (Gossip/Classified/Ground Truth), and estimated financial loss. We classify incidents into 14 attack categories and conduct statistical analyses: (1) flash-loan-enabled price manipulation and reentrancy together account for 51.5% of all attacks; (2) a chi-squared test rejects the null hypothesis of uniform category distribution at p < 0.0001 (chi-squared = 1,273.2, df = 13); (3) despite widespread deployment of automated detection tools, the annual attack count has not monotonically decreased. We further propose a six-layer DeFi threat model and quantify the effectiveness of four defense classes. The dataset, threat model, and 50 categorized Solidity vulnerability patterns are released under the MIT license.

Open access
5 source records
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Network Security and Intrusion Detection
Original source
Jul 10, 2026·Applied Sciences
0 cites
Threat Landscape in Decentralized Systems: Sybil Attacks, Related Vulnerabilities, and Blockchain Security Evolution (2015–2025)

Andrei Alexandru Bordeianu, Daniela Elena Popescu

Blockchain technology has profoundly revolutionized decentralized applications across financial systems, global supply chains, and applied informatics. However, it remains susceptible to systemic security hazards. This systematic review comprehensively evaluates core architectural vulnerabilities within blockchain infrastructures, consensus mechanisms, and peer-to-peer (P2P) network layers spanning the decade from 2015 to 2025. We focus primarily on the mechanics, operational taxonomy, and evolutionary trajectories of Sybil attacks, wherein malicious actors forge multiple pseudonymous identities to gain disproportionate systemic influence. By synthesizing the foundational academic literature with real-world empirical case studies, such as automated airdrop farming exploits in Layer-2 ecosystems (e.g., Arbitrum, zkSync) and decentralized finance (DeFi) governance manipulations, we analyze attack mechanisms, quantifiable impacts, and mitigation vectors. Our findings chart the structural evolution of Sybil strategies from rudimentary P2P routing disruptions to complex, economically driven application-layer interventions. Finally, we evaluate contemporary defenses, such as Proof-of-Personhood (PoP) systems and zero-knowledge (ZK) cryptography, offering actionable recommendations for the integration of W3C-compliant decentralized identity (DID) frameworks and behavioral analytics to enhance systemic fault tolerance.

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Organizational and Employee Performance
Original source
Jul 7, 2026·arXiv (Cornell University)
0 cites
ECO/CPO-DAG: A Contradiction-Based Accountability Layer for Adversarial Supply Chains

Sebastian Cochinescu

We present ECO/CPO-DAG, a domain-specific accountability protocol for adversarial supply chains that formalizes contradiction detection as a supplemental validation layer rather than a consensus or truth-establishing mechanism. Participants publish signed Event Claim Objects (ECOs) into a causally ordered, append-only directed acyclic graph (DAG) whose edges encode happened-before relations. When two claims about the same subject violate a domain constraint, any observer can compile a Contradiction Proof Object (CPO), a self-verifying object binding the two signed claims and the violated rule, which, on public verification, triggers economic slashing of a determinately blamed party. We map constraints to GS1 EPCIS 2.0 event semantics (spatial uniqueness, temporal monotonicity, quantity conservation, quality monotonicity, regulatory validity), so detection targets inconsistencies that are meaningful in practice. Selective disclosure via commitment schemes and, optionally, zero-knowledge contradiction proofs lets parties withhold claim contents until a challenge forces the minimal opening. We give an analytical treatment: an independent-observer detection model $1-(1-p_{\min})^h$, a deterrence condition $S&gt;g(1-p)/(kp)$ under $k$-party collusion, and a storage estimate of order 1 GB per participant per year under stated assumptions. The protocol's boundary is explicit: it detects provable contradictions, not consistent lies; a party that never contradicts itself is invisible to it, so the layer complements, and does not replace, source verification and oracle aggregation. A single-machine reference implementation corroborates the detection model, with the predicted coverage band overlapping the measured 95% confidence interval at every observer count, and records zero false accusations; the fully zero-knowledge CPO, multi-party propagation, and adaptive-adversary evasion remain analytical.

Open access
2 source records
Adversarial Robustness in Machine Learning
Blockchain Technology Applications and Security
Information and Cyber Security
Original source
Jun 25, 2026·Cybersecurity Education Science Technique
0 cites
MODEL FOR APPLYING ZERO-KNOWLEDGE PROOFS TO ENSURE CONFIDENTIAL AUTHENTICATION AND ACCESS CONTROL IN ENTERPRISE INFORMATION-INTELLIGENT SYSTEMS

Yuliia Kostiuk, Pavlo Skladannyi, Nataliia Mazur, Halyna Kuchakovska

The paper investigates the problem of ensuring confidentiality in authentication processes within enterprise information-intelligent systems under increasing cybersecurity threats and growing requirements for data protection. The introduction substantiates the relevance of modern cryptographic approaches that minimize the transmission of sensitive information during user authentication. The literature review analyzes approaches to constructing zero-knowledge proofs, which enable verification of a statement without revealing secret data, including succinct non-interactive arguments of knowledge, transparent scalable arguments of knowledge, and compact proof systems without trusted setup. Their cryptographic properties, trust assumptions, scalability, and computational characteristics are examined. In the methodology section, an adaptive authentication model is proposed, based on the integration of cryptographic proofs with risk assessment mechanisms and contextual access analysis. A formal decision-making model for access control is developed, taking into account user parameters, environmental characteristics, and threat levels, enabling dynamic selection of the proof type depending on the current risk level. An authentication algorithm is designed, including stages of identification, context evaluation, proof generation, and verification. In the results section, a comparative analysis of different types of zero-knowledge proofs in enterprise systems is conducted, evaluating their impact on performance, security level, and resistance to attacks. It is shown that the adaptive approach ensures a balance between cryptographic strength and computational efficiency. The conclusions justify the feasibility of implementing the proposed model as part of modern continuous access verification concepts and as a means of improving enterprise information security.

Open access
Cybersecurity and Information Systems
Information and Cyber Security
Economic and Technological Systems Analysis
Original source
Jun 20, 2026·arXiv (Cornell University)
0 cites
TRACE: A Threat Modelling Methodology for Distributed, Cloud-First, and Decentralized Organisations

Stefan Beyer

Established threat modelling methodologies (STRIDE, PASTA, Trike, OCTAVE, LINDDUN, attack trees, and adversary-behaviour catalogues such as MITRE ATT&amp;CK) were designed for software products and enterprises with a discernible security perimeter, a single owning organisation, and a clean separation between technical and operational risk. Modern organisations violate all three assumptions: they run on cloud and SaaS control planes they do not own, distribute privileged authority across founders, contractors, vendors, signers, committees, and automation, and expose value through human approval ceremonies and supply-chain edges rather than a network boundary. The dominant failures are authorised-but-malicious actors, collusion across nominally independent parties, control-plane and CI/CD compromise, and operational mishandling of high-value actions, which existing methods largely omit. We present TRACE, a methodology that treats threat actors, roles, assets, critical invariants, and trust/authority edges as first-class, evidence-linked objects spanning three layers: protocols, systems, and organisations. We compare nine widely used frameworks across ten dimensions, show where each falls short in distributed, cloud-first, zero-trust settings, and specify TRACE: its core model, three application pillars, sequential gated workflow, and an evidence-and-traceability discipline for human-AI co-working in which language models accelerate coverage while senior reviewers retain judgement over invariants, severity, and collusion. TRACE was developed through Web3 security practice but is stack-agnostic. We discuss its relationship to zero trust architecture and accountable Byzantine consensus, its limitations, and open questions around empirical validation.

Open access
3 source records
Information and Cyber Security
Access Control and Trust
Security and Verification in Computing
Original source
Jun 17, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Cybersecurity - A Survey on Cryptocurrency

IOANNIS BOUTZIORIS

No abstract is available for this record.

Open access
2 source records
Cybersecurity and Cyber Warfare Studies
Big Data and Digital Economy
Information and Cyber Security
Original source
Jun 13, 2026·arXiv (Cornell University)
0 cites
The Audit Gap in Blockchain Security: A Four-Year Empirical Study of Public Audit Findings and Real-World Exploit Incidents

Stefan Beyer

This paper presents an empirical analysis of the Web3 security landscape over the four-year and three-month period from 1 January 2022 to 27 March 2026. The dataset combines 23,818 public audit findings produced by 22 independent security firms with 218 real-world exploit incidents documented by rekt.news, representing aggregate losses of approximately US$7.76 billion. We report three central findings. First, the distribution of audit findings (by severity, category, and technology stack) is substantially stable across the observation window, with the Critical-plus-High share remaining within a 15-17% band in every complete year. Second, the categorical distribution of realised exploit losses does not correspond to the categorical distribution of audit findings: private-key compromise, phishing, and social-engineering vectors account for approximately 49.6% of cumulative losses yet represent a negligible share of published audit findings. Third, realised losses exhibit extreme concentration: the eight largest incidents account for 50.6% of cumulative dollar losses and the twenty largest for 71.4%, a distributional shape inconsistent with Gaussian assumptions. Throughout, we adopt the analytical convention that audit outputs and exploit outputs describe different populations and present the two datasets in parallel rather than as directly comparable samples.

Open access
3 source records
Spam and Phishing Detection
Information and Cyber Security
Cybercrime and Law Enforcement Studies
Original source
Jun 2, 2026·arXiv (Cornell University)
0 cites
FORGE: Multi-Agent Graduated Exploitation and Detection Engineering

Farooq Shaikh

Vulnerability disclosure volumes now far exceed organizational assessment capacity, yet three adjacent research communities (proof-of-concept generation, vulnerability prioritization, and detection rule engineering) operate largely in isolation. Existing automated exploit generation systems report binary pass/fail outcomes, discarding partial progress and producing no signal for the other two communities. This paper presents FORGE, a multi-agent system that bridges these three silos through graduated exploitation depth. Five specialized agents (Intel, Generator, Planner, Exploit, and Detector) execute in a fixed pipeline that (1) generates targeted vulnerable applications from CVE metadata, (2) conducts coached, multi-turn exploitation assessed by an LLM-primary oracle on a four-level taxonomy (L0: no evidence through L3: full compromise), and (3) produces Sigma and Snort detection rules grounded in OpenTelemetry exploitation traces. Graduated depth is the bridging mechanism: deeper exploitation yields richer behavioral traces for detection engineering, while depth data across scoring bands provides ground truth for prioritization validation. A tiered knowledge architecture accumulates intelligence across assessments, transferring build and exploitation experience to subsequent CVEs. Evaluation on 603 CVEs from the CVE-GENIE dataset achieves 67.8% end-to-end L1+ exploitation at USD 1.50 per CVE across eight languages and 187 CWE types. Exploitation rates remain near 68% regardless of EPSS or CVSS band, indicating that pattern-level reachability is orthogonal to metadata-based prioritization. Detection rules from L2+ exploitation achieve significantly higher span-normalized grounding than L1-derived rules (p=0.035), and 93.4% of generated Snort rules produce zero false positives against a synthetic benign corpus.

Open access
2 source records
Information and Cyber Security
Advanced Malware Detection Techniques
Web Application Security Vulnerabilities
Original source
Jun 1, 2026·European Journal of Information Technologies and Computer Science
0 cites
Mapping Research Trends in Cybersecurity and Data Breaches within the Financial Sector: A Bibliometric Perspective

Nazneen Fatema, Abdullah Mohammed Ibrahim, Jesmin Sabnam, Abdullah Mohammad Ismail

This bibliometric study maps research trends in cybersecurity and data breaches within the financial sector from 2020 to 2024, analyzing 7355 documents from the Web of Science. The findings reveal a rapidly expanding and interdisciplinary field, driven by the digital transformation of finance, heightened cyber threats, and the impact of global events such as the COVID-19 pandemic. The research landscape has evolved from descriptive, technical studies to sophisticated analyses incorporating network theory, econometrics, and risk management. Most prolific authors and sources, such as IEEE, demonstrate strong international collaboration and significant citation impact, with China, the USA, and the UK leading in citations. Co-citation network analysis identifies three major intellectual clusters: economic modeling of cyber risk, network-based risk propagation, and systemic macro-financial implications of cyberattacks. The study highlights an increasing focus on quantifying the financial and reputational impacts of cyber incidents, making research directly relevant to business and regulatory stakeholders. Limitations include reliance on a single database and quantitative methods. Future research directions emphasize the security implications of emerging technologies (e.g., quantum computing, decentralized finance, artificial intelligence), behavioral and cultural aspects of cybersecurity, and systemic regulatory challenges. The field is dynamic, reflecting the financial sector’s evolving risk landscape.

Open access
Information and Cyber Security
Big Data and Digital Economy
Banking, Crisis Management, COVID-19 Impact
Original source
May 28, 2026·Companion Proceedings of the ACM Web Conference 2026
0 cites
The State of the Internet: Insights from Security Indicators

Florian Nettersheim, Stephan Arlt

The Internet is undergoing constant transformation, driven by emerging paradigms such as Web3 and Artificial Intelligence. Despite these developments, the secure operation of Internet services remains a fundamental prerequisite for ensuring confidentiality, integrity, and availability.

Information and Cyber Security
User Authentication and Security Systems
Cybersecurity and Cyber Warfare Studies
Original source
May 22, 2026·Journal of Logical and Algebraic Methods in Programming
0 cites
Model to mitigate: Using DCR graphs to prevent vulnerabilities in smart contracts

Mojtaba Eshghie, Wolfgang Ahrendt, Cyrille Artho, Thomas Hildebrandt · 5 authors

We propose a ‘Model to Mitigate’ methodology: designing a platform-agnostic model of smart contract business logic and analyzing it before implementation. Using Dynamic Condition Response (DCR) graphs, originally developed for modeling business processes, we formally specify smart contracts and introduce a trace-conformance notion that links DCR-level guarantees to Solidity execution traces. Our method captures high-level properties such as event ordering, role-based access control, and time constraints, enabling the identification of design-rooted vulnerabilities through the discipline of explicit modeling. The DCR formalism requires developers to make concrete decisions about access control, preconditions, initial states, and event ordering-decisions that, when left implicit until implementation, are a documented source of vulnerabilities. Our analysis of real-world exploited and audited smart contracts yields six key insights, demonstrating how DCR-based modeling can enhance smart contract security by surfacing design flaws before they reach deployment. While we validate the approach on existing smart contracts with known flaws (i. e., post-implementation scenarios), the proposed methodology is applicable during design time (pre-development).

Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Security and Verification in Computing
Original source
May 18, 2026·arXiv (Cornell University)
0 cites
Bridging the Cybersecurity Gap Between Web2 and Web3 -- An Incident-Based Analysis of Organizational and Application-Level Security Failures

Tarkan Yavas, Arslan Brömme

The rapid adoption of Web3 infrastructures has led to a growing number of security incidents affecting cryptocurrency exchanges, custody services and blockchain-based platforms. While existing research predominantly focuses on vulnerabilities in smart contracts and blockchain protocols, a substantial portion of real-world losses originates from off-chain systems, organizational processes and human-centered operational workflows. This paper presents a qualitative, incident-based analysis of publicly documented, high-impact security breaches in the Web3 ecosystem, including the Bybit exchange incident (2025), the Ronin Network bridge compromise (2022), and the DMM Bitcoin exchange breach (2024). The selected cases are systematically analysed and mapped to established Web2 security reference frameworks, including OWASP-based vulnerability categories and organizational security control domains. The results indicate that dominant failure patterns in Web3 environments are insufficiently addressed by generic security control catalogues, particularly with respect to cryptographic key management, transaction approval governance, signer and validator infrastructure, third-party tooling dependencies, and human-in-the-loop processes. Based on these findings, this paper argues for the adoption of established information security management systems (ISMS) in Web3 organizations and derives a structured set of blockchain-specific cybersecurity control categories to operationalize existing ISMS frameworks for blockchain-based systems. The proposed categories aim to bridge the gap between generic security governance frameworks and domain-specific risks inherent to Web3 infrastructures.

Open access
3 source records
Blockchain Technology Applications and Security
Information and Cyber Security
Web Application Security Vulnerabilities
Original source
May 4, 2026·arXiv (Cornell University)
0 cites
EvoPoC: Automated Exploit Synthesis for DeFi Smart Contracts via Hierarchical Knowledge Graphs

Ruichao Liang, Jing 婧 Chen 陈, Xianglong Li, Huangpeng Gu · 8 authors

Smart contract vulnerabilities in Decentralized Finance caused over billions of dollars losses every year, yet the security community faces a critical bottleneck: identifying a vulnerability is not the same as proving it is exploitable. Manual PoC construction is prohibitively labor-intensive, leaving most disclosed vulnerabilities unverified and protocols exposed long before mitigation is applied. In this paper, we propose \sys, a knowledge-driven agentic system for end-to-end contract vulnerability detection and exploit synthesis. Our core insight is that exploit synthesis is not a code generation task but a \emph{structured reasoning problem} that requires grounded knowledge of protocol semantics, failure root cause, and exploit primitives. \sys organizes this knowledge into a \emph{Hierarchical Knowledge Graph} (HKG) that serves as structured memory for LLM-guided multi-hop reasoning. To validate exploit feasibility beyond code synthesis, \sys employs a two-stage validation framework that checks exploit-path reachability via SMT solving and profit realizability via asset-level state simulation, ensuring generated PoCs satisfy both logical and economic viability constraints. Evaluated on 88 real-world DeFi attacks and 72 audited projects (2,573 contracts), \sys achieves 98\% recall and 0.9 F1-score in detection, and a 96.6\% exploit success rate (ESR), reproducing 85 historical exploits and recovering over \$116.2M revenue. \sys outperforms SOTA fuzzers (\textsc{Verite}, \textsc{ItyFuzz}) by up to $5\times$ in ESR and $300\times$ in recoverable value, and the LLM-based exploit generator \textsc{A1} by $2\times$ and $8.5\times$ respectively. In bug bounty evaluation, \sys identified 16 confirmed 0-day vulnerabilities, helping secure over \$70.6M and earning \$2,900 in bounties.

Open access
3 source records
cs.CR
cs.SE
Web Application Security Vulnerabilities
Original source