Skip to content
Open access

Securing Cross-Chain Multisignature Execution Through Deterministic Enforcement and Explainable Anomaly Awareness

Aug 2026 · Computers · Vol 15, pp. 536 · 0 citations · 23 references

TL;DR

Results indicate that a machine learning advisor can extend anomaly-prioritization coverage beyond the scope of the deterministic predicates while leaving execution control fully deterministic.

Abstract

Cross-chain bridges represent one of the most damaging attack surfaces in decentralized finance, with major exploits (e.g., Ronin, Wormhole, Nomad, Multichain) arising not from broken signature schemes but from failures in proof verification, replay protection, and signer-set management, gaps that conventional threshold-signature multisignature wallets do not address. This study presents an incident-aware multisignature architecture combining three on-chain predicates—block-height freshness windows, epoch-bound signer sets, and Merkle inclusion-proof verification—with a non-authoritative off-chain LightGBM classifier that generates SHAP-attributed risk explanations to support governance actions such as pausing, vetoing, or rotating signers, without directly blocking or approving execution. The framework was evaluated on a simulated benchmark of 78,600 Ethereum testnet transactions containing six injected anomaly classes (gas spikes, nonce jitter, malformed call data, stale intents, proof-delivery delays, and epoch-rotation replays). The LightGBM advisor achieved ROC-AUC 0.92 (95% CI [0.906, 0.926]) and F1 0.73 ([0.712, 0.749]), outperforming five baselines—logistic regression, Random Forest, XGBoost, isolation forest, and a rule-based detector—with the highest F1 (0.731) and PR-AUC (0.799), while the rule-based detector, which by construction covers only the anomaly classes addressed by the deterministic predicates, attained F1 0.282. Differences were statistically significant except for the LightGBM–XGBoost PR-AUC comparison. The deterministic layer itself is verified through 28 property-level contract tests covering all seven modeled attack objectives, with measured per-function gas costs (execute_Intent: 118,756 gas, of which 28,432 gas is Merkle-proof verification). Within this controlled setting, the results indicate that a machine learning advisor can extend anomaly-prioritization coverage beyond the scope of the deterministic predicates while leaving execution control fully deterministic. This work is presented as a controlled proof of concept: the reported metrics quantify recovery of scripted injection patterns, and validation against real-world exploit traces remains future work.

Read PDF

Similar papers

Open access Aug 2026

Blockchain-anchored multi-discriminator GAN architecture for real-time zero-day attack detection in social IoT edge networks with explainable audit trails

Social Internet of Things (SIoT) deployments, in which heterogeneous edge devices form long-lived peer-to-peer relationships governed by social-network primitives, have become prime targets for zero-day attackers that exploit local topology, abnormal behaviour of previously unknown devices, and resource-constrained gat...

S. Kanawade, N. Deshpande, Shilpa Gite et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution

This monograph presents a first-principles forensic autopsy of the intrusion, provides formal evidence that the breach was a predicted consequence under the Instrumental Convergence thesis operating within an unattenuated autonomous loop lacking out-of-band circuit-breakers, exposes the Defensive LLM Guardrail Paradox...

José Luis Pino · 0 citations
Open access Oct 2026

Exploiting Ethereum Rollback Semantics: Profit-Driven Attack Synthesis and Off-Chain Misinterpretation Testing

The Ethereum Virtual Machine (EVM) enforces atomic execution through rollback, reverting all state changes when execution fails. While necessary for correctness, rollback semantics introduce a distinct attack surface affecting both on-chain execution and off-chain infrastructures. On-chain, attackers can use conditiona...

Yi-Xuan Liu, Xin-Lei Li, Yi Li · 0 citations
Review Open access Oct 2026

TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across Transactions

Decentralized Applications (DApps) serve as a critical technical underpinning for business logic and user interaction within the blockchain-powered Web3 ecosystem. However, DApps are prone to faults, and localizing these faults within their intricate and often interconnected logic is a particularly time-consuming proce...

Xuan-Yu Zhu, Zhi-Ying Wu, Tao Wang et al. · 0 citations
Open access 2026

Cryptographic Attestation Against Integrity Attacks in Service Monitoring: A Threat Model and Verifiable Architecture

Service uptime monitoring infrastructure is a high-value target for data-integrity attacks: a single compromised or dishonest monitoring provider can fabricate availability records, retroactively suppress outage evidence, or silently alter historical data, and clients today have no cryptographic means of detecting such...

M. Anusuya, Chayadevi M. L., S. C. et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.