Latest
Call for Papers: Vol. 42 closes 30 JuneNew: Quantum Security Summit registration openAxiom Standard 7042-2024 now ratifiedGrant cycle 2025 — $4.2M committedFellows election voting opens 15 JulyCall for Papers: Vol. 42 closes 30 JuneNew: Quantum Security Summit registration openAxiom Standard 7042-2024 now ratifiedGrant cycle 2025 — $4.2M committedFellows election voting opens 15 July
Digital Library

Research Archive

Search across 2.4 million peer-reviewed documents from journals, conferences, and standards.

Showing 2 of 2,418,902 results

Journal Article Open Access Blockchain

Decentralized Finance Protocol Security: Formal Verification of Automated Market Maker Invariants, Flash Loan Attack Surfaces, and Governance Mechanism Vulnerabilities

Decentralized Finance (DeFi) protocols collectively managing hundreds of billions of dollars in on-chain value have suffered over 3.8 billion USD in losses to exploits between 2020 and 2022, with a significant proportion attributable to formally verifiable protocol invariant violations. This paper presents a formal verification framework for DeFi protocol security, applied to three core protocol categories: Automated Market Makers (AMMs), lending protocols, and governance systems. Using the K Framework for reachability logic verification and the Certora Prover for Solidity specification checking, we formalize and verify 34 safety properties across Uniswap V3 AMM invariants, Compound lending protocol solvency conditions, and Governor Bravo governance mechanism integrity. Formal verification identifies 7 previously undisclosed vulnerability classes, including a novel AMM sandwich attack surface arising from tick-boundary liquidity discontinuities and a governance quorum bypass exploitable through flash loan-amplified voting. We introduce the DeFi Protocol Security Score (DPSS), a composite metric aggregating formal property coverage, attack surface exposure, and economic incentive alignment, and apply it to rate 18 production DeFi protocols. We release formal specifications and verification toolchains as open-source artifacts to lower the barrier for security-rigorous DeFi protocol development.

Tunde Adesanya, Frida Lindberg, Takashi Okamoto, Mariam Khalil· Jan 2021· 509 citations
Journal Article Open Access Healthcare Informatics

DevOps in Regulated Industries: Reconciling Deployment Agility with Compliance Requirements in Healthcare IT Systems

Healthcare IT organizations face a unique tension: the operational benefits of DevOps demand deployment agility, while regulatory frameworks such as HIPAA, FDA 21 CFR Part 11, and SOX impose stringent change management, audit trail, and validation requirements that are difficult to reconcile with continuous delivery practices. This paper presents a systematic examination of this tension through a combination of regulatory analysis and a cross-sectional survey of 198 healthcare IT practitioners. We identify 23 specific regulatory requirements that conflict with or require adaptation of standard DevOps practices, and categorize them into four conflict types: Change Velocity Conflicts, Evidence Integrity Conflicts, Environment Separation Conflicts, and Accountability Attribution Conflicts. We then evaluate four regulatory-DevOps reconciliation strategies — Compliance-as-Code, Immutable Audit Pipelines, Policy-Gated Deployment Gates, and Automated Validation Evidence Generation — through case evidence from three healthcare organizations that have achieved both compliance and DevOps maturity. Our analysis demonstrates that all four conflict types are addressable through thoughtful toolchain design, and that compliance instrumentation can be largely automated without sacrificing delivery speed. We provide a compliance-aware DevOps implementation blueprint validated against the identified regulatory requirements.

Adaeze Obi, Patrick Steinmann, Lisa Johansson, Manish Gupta· Jan 2021· 412 citations