Score
Designs and implements mechanisms that compute, store, and organize cryptographic content hashes to create tamper‑evident provenance for artifacts, including binding measurements to verifiable digests and maintaining opaque provenance slots and version metadata indexed by hashes. Also selects or designs hashing algorithms and techniques and analyzes their security properties (collision and preimage resistance), performance, and compactness tradeoffs when integrated into provenance systems.
This work proposes a blockchain-based trusted registration and verification mechanism to address the challenges of misinformation and source tracing posed by the proliferation of AI-generated images. At the time of image generation, a perceptual hash fingerprint is assigned and immutably recorded using a hybrid on-chain/off-chain architecture, where the fingerprint is stored in a Merkle Patricia Trie. To enable efficient similarity search despite benign transformations or partial modifications, the system integrates a Burkhard–Keller tree. This approach ensures tamper-resistant, platform-agnostic provenance tracking that remains robust under common image alterations. By overcoming the limitations of conventional watermarking and detection techniques, the proposed framework significantly enhances the ability of large-scale online platforms to verify the authenticity of AI-generated content.
To address challenges of insufficient scientific data provenance integrity and weak cross-organizational interoperability in multi-institutional collaborative research, this paper proposes a federated provenance architecture integrated with a permissioned blockchain. The architecture adopts a modular, domain-agnostic design, incorporating persistent identifiers (PIDs), versioned provenance graph modeling, and federated computation mechanisms—ensuring decentralized interaction while guaranteeing immutability, long-term auditability, and cross-platform verifiability of provenance data. Unlike existing approaches, our work is the first to deeply embed a permissioned blockchain into the federated provenance workflow, thereby overcoming provenance consistency bottlenecks imposed by organizational boundaries. Evaluation of a prototype system demonstrates significant improvements in transparency, accountability, and reproducibility of cross-institutional research data, establishing foundational infrastructure for trustworthy large-scale scientific data analysis.
This study addresses a critical gap in blockchain research, which has predominantly focused on on-chain transactions while neglecting the comprehensive lifecycle management of cryptographic assets. For the first time, the paper introduces the ISO 15489-1:2016 records management standard into the blockchain domain, leveraging records lifecycle theory to propose a seven-stage data lifecycle framework spanning from creation to disposition. The applicability of this model is demonstrated through case studies involving Bitcoin, fungible tokens, and non-fungible tokens. By elucidating the inherent characteristics of blockchain as a records management system, the framework clarifies the boundaries between on-chain and off-chain data and examines how privacy-enhancing technologies affect lifecycle visibility. This structured perspective offers valuable insights for the governance of crypto-assets, regulatory compliance, and forensic investigations.
This work addresses a critical security gap in existing vector databases, which lack native support for embedding integrity, anomaly detection, and provenance authentication, rendering them vulnerable to attackers with write access who can exploit subtle perturbations—such as orthogonal rotations or scaling—to steganographically exfiltrate sensitive data through embeddings. We present the first systematic demonstration and validation of steganographic attacks at the embedding layer in Retrieval-Augmented Generation (RAG) systems. To counter this threat, we propose VectorPin, an embedding-level integrity protection mechanism that cryptographically binds each embedding to its source content via Ed25519 digital signatures, enabling verifiable provenance. Experiments show that minor orthogonal rotations can evade conventional distribution-based detectors, whereas VectorPin reliably identifies any post-embedding tampering across diverse models, corpora, and seven vector database configurations, thereby fundamentally mitigating this class of attacks.
Hardware benchmarking often suffers from limited verifiability, hindering reproducibility and auditability, and is vulnerable to silent computational errors. This work proposes the first end-to-end verifiable measurement logging system, which integrates transparent logs, probabilistic verification (e.g., Freivalds’ algorithm), and an adversarial-aware Fiat-Shamir challenge mechanism to bind all observations into an append-only hash chain via content-based hashing, enabling offline auditing. The system incorporates algebraic checks, floating-point error tolerance calibration, and di/dt power and thermal stress testing to effectively distinguish physical faults from malicious tampering. Experiments on Blackwell and Hopper GPUs demonstrate that the approach accurately characterizes residual noise floors across varying precisions and scales, detects no undetected silent errors, and thereby validates its effectiveness and robustness.
This study addresses the challenge that organizations lack structured awareness of cryptographic assets in software, which impedes effective security governance and post-quantum migration. To bridge this gap, the authors propose a static analysis approach that introduces the first taxonomy tailored for Cryptographic Bill of Materials (CBOM) and designs an extensible, scanner-agnostic rule library to enable efficient discovery and risk assessment of cryptographic assets. Empirical evaluation demonstrates that the method processes 57,610 files within six minutes, accurately identifying 370 cryptographic assets with an F1 score of 0.75. It further uncovers six CVE-listed vulnerabilities and 52 candidates requiring post-quantum migration, achieving a vulnerability labeling accuracy of 91%.
This study addresses the significant dependence of provenance-based intrusion detection system (PIDS) evaluations on dataset and protocol choices, which often leads to misleading performance comparisons. Conducting a systematic re-evaluation of representative PIDS under a unified temporal split testing protocol and hyperparameter tuning restricted to the validation set—using publicly available datasets that satisfy auditability, labeling, and calibration requirements—the authors find that most reported performance gains stem from lexical novelty in executable names or paths rather than sophisticated provenance modeling. They propose quantifying dataset semantic signal quality via feature completeness and field entropy, which explain model sensitivity to architectural choices. On three of four widely used datasets, a simple allowlist matches or outperforms learning-based methods; only Theia, exhibiting the strongest semantic signals, effectively reveals model advantages in alert prioritization and node recovery.