
Machine learning models are growing, with some large language models reaching a scale of billions of trainable parameters. Training these models has since become one of the most data-hungry and computation-heavy tasks. Efforts to distribute the training task mostly follow a federated approach, where a central server oversees the training process. This approach: 1) raises concerns about data privacy; and 2) creates a single point of failure. Current proposals for a fully decentralized approach often rely on costly broadcasts to disseminate model updates and do not tolerate heterogeneity in the training data, as it makes detecting Byzantine contributions harder. We propose BLADE, a generalized fully decentralized (and asynchronous) Byzantine fault-tolerant machine learning algorithm. BLADE was designed to be configurable and adapt to harsh environments, and significantly reduces the communication overhead compared to the state of the art. We performed a comprehensive empirical evaluation, and results confirm models trained with BLADE can achieve an accuracy comparable to a centralized training instance, even if the data distribution among peers is heterogeneous, and robustly aggregate model updates in the presence of Byzantine attacks, and even against sporadic Byzantine majorities.
Decentralized exchanges are one of the most remarkable revolutionary inventions in cryptocurrency trading. Decentralized exchanges present a way to set prices mathematically without maintaining the order book-based trading system. The order book-based trading system has been a widely-known method to determine prices in the stock markets for over 400 years. Recently, a new type of decentralized exchange has devised a constant function market maker to determine prices mathematically. Among them, the method of constant product market makers is the most widely used one. In addition, several constant function market makers have been proposed. However, there was little discussion about the desirable properties of a constant function market maker regarding price and impermanent loss. In this paper, we discuss the desirable price and its effects on impermanent loss. This study considers two types of prices: the reference price and the actual price. We show that impermanent gain can be achievable under certain conditions and prove it mathematically. Two examples are provided to show that impermanent gain is achievable. One question is whether there is agreement on applying actual price when calculating value gains.
Web applications are widely used to access and manage services, including databases to store and retrieve data. However, these applications have suffered from vulnerability issues in their source code, which represents a serious threat to information protection, such as the exploitation of the SQL injection vulnerability that allows access unduly to data from databases. This paper addresses the web vulnerability problem by using Natural Language Processing (NLP) models to detect vulnerabilities in an Intermediate Language (IL) representation of web application source code. The focus on using an IL is to represent the code in a generic language that can be used to train different NLP models, such as sequential (e.g. Hidden Markov Models) and neural network (e.g. Transformers), with the goal of detecting vulnerabilities in several manners and explaining their existence. A vulnerability detection tool will combine these models to check if the code is absent of vulnerabilities or not, stating where they are posed in the code. Preliminary results show that neural network models are able to interpret IL code as being original code and detect vulnerabilities through it.
Integrating air and rail transportation systems offers a significant opportunity to enhance global mobility and operational efficiency. This study explores the role of Artificial Intelligence (AI) in addressing passenger behaviour and interoperability in air-rail networks. Advanced AI techniques are employed to analyse passenger behaviour patterns and optimize multimodal integration. Findings emphasize the importance of tailored solutions for diverse passenger groups, as universal approaches prove inadequate. Methodologically, this paper employs a systematic literature review to synthesize insights and identify trends, focusing on AI applications in air-rail systems. Ethical and technical challenges, including data integration, algorithmic bias, and privacy concerns, are addressed, highlighting the need for robust governance mechanisms. The study advocates for advancements in joint ticketing, baggage handling, AI-driven personalized services, and global standards for multimodal transportation. The findings underscore the potential of AI to revolutionize air-rail networks, offering actionable insights for stakeholders to improve passenger experience and operational efficiency.
As Large Language Models (LLMs) become increasingly integrated into real-world applications and are made more accessible to the general public, significant concerns regarding their security and the safety of the content they output arise. Recent research demonstrates that these models are vulnerable to adversarial techniques, which can manipulate them into generating harmful or biased outputs. These risks highlight the need for robust evaluation methods to assess the resilience of LLMs against these threats. While some efforts have been done to benchmark LLMs' robustness against adversarial prompt-based attacks, these approaches are often highly context-specific and lack the comprehensive components required for a robust and systematic evaluation. In this work we present a benchmarking framework for systematically evaluating the adversarial robustness of LLMs' built-in security and safety measures against text-based prompt attacks during inference time. The proposed framework is composed of the key components that make up a reliable benchmark, including scenarios, workloads, metrics and attack loads and is designed to ensure its representativeness, usefulness and adaptability to different contexts.
This paper investigates the impact of cross-chain deployment on the market performance of decentralized applications (Dapps) within the evolving multichain Web3 ecosystem. While cross-chain Dapps benefit from broader user reach, improved scalability, and enhanced resilience, they also face significant challenges, including technical complexities, security risks, and fragmented liquidity. This paper analyses how Dapps' transaction distribution across multiple blockchains influences their market performance. Preliminary findings reveal that Dapps operating on multiple chains tend to underperform in terms of market capitalization, token price, and transaction volume compared to those concentrated on a single or few chains. These results highlight critical concerns about the effectiveness of cross-chain strategies.
This paper presents a practical experience report on top of the application of Independent Software Verification and Validation (ISVV) in the space domain, specifically on the Galileo Second Generation satellites, and proposes a methodology for security analysis that can be transferred to the Unmanned Aerial Vehicles (UAV) domain. We explore the application of security assessments, similar to ISVV processes. The proposed methodology for security analysis and validation includes security checklists, source code security analysis and various security validation techniques. We expect significant cybersecurity improvements, a contribution to the specification of secure design and security requirements (system and software), and the implementation of comprehensive testing campaigns covering the known space systems threats and vulnerabilities, including mutation and sensitivity analysis, to reduce security threats and risks. Future work involves applying these methods to a UAV case study, collecting relevant metrics, and providing feedback to international standards to further enhance security and safety in these critical domains.
This paper proposes the concept of a unified intelligent platform aimed at standardizing the logistics processes of railway transportation in Ukraine. The objective of this development is to automate transportation planning and optimize the utilization of railway resources. The proposed unified intelligent platform focuses on data exchange standardization and enhancing the efficiency of transport and logistics operations. The platform improves timetable accuracy, reduces transit times, and lowers overall logistics costs. The results obtained confirm the effectiveness of the approach, demonstrating the feasibility of integrating artificial intelligence technologies into modern railway infrastructure.
Promissory Notes (PN) are essential financial instruments that formalize an entity's commitment to repay another party. Despite their widespread use, reliance on paper-based documentation presents significant inefficiencies. This work addresses these limitations by fully digitalizing the whole process in a dependable manner. In detail, we propose a framework build upon a permissioned forkless blockchain. The system provides an application programming interface (API) to enhance efficiency, reduce processing time, and support future scalability, and a Web application to offer intuitive and user-friendly interfaces that represent the full spectrum of PN business processes operations while ensuring the security, integrity, and compliance with legal requirements inherent to blockchain technology. The blockchain ensures data integrity by securely storing immutable records of PN transactions, while the API provides a customizable mechanism to enforce security and confidentiality. The web application will improve operational efficiency and will reduce processing times by providing user interfaces for every stakeholder and collaborators involved in the PN Business Processes.
Distributed Intrusion Detection Systems (DIDS) in resource-constrained edge environments have become increasingly important due to the development of the Industrial Internet of Things (IIoT). In this paper, we have identified several key and relevant challenges in developing the DIDS in edge environments, by reviewing related works on different issues. The results of this work can provide references for future research.
The real estate sector plays a vital role in today's economy and society. However, the current system for managing real estate transactions remains heavily reliant on manual document handling and verification processes, which are often inefficient and vulnerable to fraud, underscoring the need for innovative solutions. This position paper proposes a system that integrates Optical Character Recognition (OCR), Natural Language Processing (NLP), and Verifiable Credentials (VCs) to automate document extraction, verification, and management within real estate transactions. Key goals include (1) a comprehensive workflow to transform diverse document formats into standardized VCs and (2) an automated data matching mechanism to identify inconsistencies and potential fraud indicators. The approach involves using the potential of blockchain and Web3 technologies as a decentralized trust layer to improve data integrity and transparency. This solution holds significant promise for streamlining real estate processes, fostering trust among stakeholders, and establishing a scalable framework for secure and efficient digital transactions.
Error Correction Codes (ECCs) are increasingly used in safety-critical systems, such as hardware accelerators for cryptographic computations and neural network inference. These systems require high reliability, making ECCs essential for mitigating soft errors and improving fault tolerance. Thus, the demand for efficient ECC implementations is rising, necessitating faster design and deployment processes. Traditional hardware design approaches, such as Register-Transfer Level (RTL) development, can be time-consuming and very complex. High-Level Synthesis (HLS) enables the automatic transformation of C-based ECC models into hardware descriptions, reducing development effort while allowing design-space exploration. This methodology facilitates rapid prototyping and optimization, enabling the evaluation of different architectural choices without manually modifying the RTL code. However, coding styles, algorithmic transformations, and optimization strategies in C-based can directly affect the synthesized hardware's performance metrics, including area utilization, power consumption, and latency. This work provides initial insights into how different C-based ECC design choices influence the final hardware implementation. To do this, we have analyzed synthesis results under various ECC configurations.
The rising sophistication of cyberattacks demands innovative solutions to safeguard system security and dependability. Traditional honeypots, while essential for malware collection, fall short in addressing modern threats like file-less malware and multi-stage attacks. This work presents a novel high-interaction honeypot architecture with integrated real-time analysis that allows for more accurate machine learning-based malware classification. The preliminary results of the proposed honeypot showed that such a novel architecture can detect and classify malware.
In the last decade, blockchain interoperability solutions, especially cross-chain bridges, have become increasingly popular. However, the field still has considerable room for growth in addressing vulnerabilities and preventing system exploitation. In this work, we propose a novel classification scheme for evaluating and benchmarking blockchain interoperability visualization mechanisms and identifying key gaps on cross-chain information availability. We also propose two mechanisms to streamline the cross-chain operation analysis process. The first is a dataset generation framework for cross-chain transactions that can fetch blockchain events from blockchains, aggregate them into cross-chain transactions, and record these transactions in an organized format for data analysis. The second is a visualization tool that shows users information on cross-chain operations based on an existing dataset. This position paper aims to bring to light and address gaps in blockchain interoperability with the intention of enabling and catalyzing the development of future solutions, ultimately contributing to a more mature blockchain interoperability ecosystem.
Accurate detection and prediction of railway track geometry defects is critical for ensuring safety, reliability and efficiency in rail operations. In Europe, traditional track geometry monitoring relies heavily on diagnostic trains, which are costly and operate infrequently if compared with commercial trains. This work presents a novel methodology to synchronise signals from onboard monitoring using sensors installed on commercial trains, as a part of the data cleansing needed to prepare for Machine Learning prediction of track geometry evolution. The sensor setup utilises accelerometers, gyroscopes and Global Navigation Satellite System (GNSS) to estimate track geometry features, but it faces inherent challenges due to inevitable differences in sensor placement between runs, different starting points for data recording and GNSS misalignments, particularly in tunnels. To overcome these challenges, an innovative data synchronisation methodology is introduced, leveraging cross-level references combined with a peak finder algorithm to ensure precise alignment across multiple recordings. This synchronisation is crucial for accurately tracking the temporal evolution of defects at specific locations, enabling effective predictive maintenance through advanced machine learning and AI technologies. By integrating AI-driven models with synchronised data, this work supports enhancements of the accuracy of defect detection and prediction, in a view to establish a scalable, data-driven approach for railway maintenance.
As cyber threats continue to grow in complexity, traditional security mechanisms struggle to keep up. Large language models (LLMs) offer significant potential in cybersecurity due to their advanced capabilities in text processing and generation. This paper explores the use of LLMs with retrieval-augmented generation (RAG) to obtain threat intelligence by combining real-time information retrieval with domain-specific data. The proposed system, RAGRecon, uses a LLM with RAG to answer questions about cybersecurity threats. Moreover, it makes this form of Artificial Intelligence (AI) explainable by generating and visually presenting to the user a knowledge graph for every reply. This increases the transparency and interpretability of the reasoning of the model, allowing analysts to better understand the connections made by the system based on the context recovered by the RAG system. We evaluated RAGRecon experimentally with two datasets and seven different LLMs and the responses matched the reference responses more than 91% of the time for the best combinations.
Safety engineering and assurance of autonomous systems involve many research challenges. Key challenges stem from the complex environment in which autonomous systems should behave flexibly, performatively, and safely. Conventional safety based on worst-case assumptions cannot reach the required performance and can even contribute to hazardous situations. For instance, an autonomous vehicle that keeps a too large distance to its vehicle in front might cause other vehicles to cut in. In this paper, we provide an overview of the layers of protection architecture for autonomous systems (LOPAAS), which deals with this issue by dynamically adapting safety restrictions to meet the current situation's safety and performance demands. We illustrate the application of our framework with a highway pilot use case and discuss the safety and performance benefits of LOPAAS using this example.
This paper presents SPATRA's solution concept for estimating rail buckling risk using Earth Observation (EO) satellite data and artificial intelligence (AI). The rail buckling is a critical issue exacerbated by rising global temperatures. By integrating high-resolution land surface temperature (LST) satellite data, rail track temperature prediction models, and AI-driven lateral displacement estimation, the proposed approach would enable proactive railway infrastructure management, as it allows for early identification of high-risk rail segments, reducing the likelihood of track deformation and train derailments. Initial SPATRA findings demonstrate the feasibility of using EO-based monitoring for real-time risk assessment, minimizing maintenance costs and operational disruptions. The proposed solution improves upon traditional ground-based methods by providing large-scale, continuous monitoring. Future validation efforts will refine prediction models and enhance their adaptability to various railway networks.
Event Sourcing (ES) is a design pattern rooted in Domain-Driven Design (DDD) that preserves an audit trail of state changes in the form of an event log. It relies on single-threaded Aggregates to encapsulate business logic and handle commands sequentially as they are received, enforcing strong consistency within their boundaries. Consequently, ES does not tolerate Aggregate failures. To improve availability, Aggregates must be replicated. In this work, we outline five replication methods based on well-known communication primitives—Reliable Broadcast (RB) and Atomic Broadcast (AB)—as well as Conflict-free Replicated Data Types (CRDTs), Sagas, and escrow-based operations. We discuss the implications of each approach in terms of the tradeoffs between consistency, latency, and availability, considering them in light of the PACELC theorem.
The growing expansion of the Internet of Things (IoT) has introduced significant challenges in the security field, demanding the adoption of innovative methodologies to ensure the integrity and confidentiality of interconnected devices. Protecting these devices is a complex challenge since it requires security solutions that are not only customizable to each device's specificities but also adaptable to the different operating environments in which they are used. In this context, it is essential to investigate effective methodologies for identifying vulnerabilities. Although several promising techniques have been proposed, the heterogeneity of IoT devices requires a combination of approaches to adequately deal with this ecosystem's diversity. A practical method for a given device may not be suitable for another, highlighting the need for segmented strategies to implement security measures, especially in smart homes. Dynamic analysis, in particular, presents itself as a viable approach for detecting vulnerabilities that manifest themselves during the operational execution of devices. Given this scenario, this project aims to develop a solution based on dynamic analysis for the security of IoT devices in the context of smart homes, emphasizing identifying and examining the vulnerabilities described in the OWASP Top 10 IoT list. To achieve this goal, techniques, methodologies, and strategies will be investigated, considering the specific characteristics of smart homes and the diversity of IoT devices, promoting effective vulnerability detection and improving security in this environment.