ConGradetect: Solving the Privacy Paradox in Blockchain Crowdsourced Security
ConGradetect: Blockchain-based detection of code and identity privacy vulnerabilities in crowdsourcing
This paper introduces ConGradetect, a blockchain-based crowdsourcing system designed for smart contract vulnerability detection. It integrates dynamic fake identities, local code granulation, proxy re-encryption, and zk-SNARKs to ensure code privacy and identity anonymity while preventing reward preemption.
TL;DR
ConGradetect is a decentralized framework that enables secure crowdsourcing for code vulnerability detection. By combining Dynamic Fake Identities, Local Code Granulation, and zk-SNARKs, it allows organizations to outsource code auditing without exposing full source code to workers or leaking identities on the transparent Ethereum ledger.
Background: The Trust Deficit in Crowdsourcing
Crowdsourcing platforms like Amazon Mechanical Turk or specialized security response centers are historically centralized. This creates a "black box" where the platform controls all data, often leading to untrusted reward distributions and potential identity leaks.
While Blockchain 2.0 (Smart Contracts) offers a decentralized alternative for transparency, it introduces a new paradox: How do you keep private code and identities secure on a ledger where every transaction is public?
The ConGradetect Architecture
The authors propose a multi-layered approach to handle three core tensions: code complexity vs. detection efficiency, anonymity vs. certification, and transparency vs. privacy.

1. Code Privacy through Granulation
Instead of uploading the entire smart contract, a Local Code Granulation Tool splits the code into smaller, non-contiguous blocks. Each block is encrypted using AES.
- The Insight: An individual worker only sees a fragment (a "granule") of the code. They cannot reconstruct the full logic or identify the owner, significantly reducing the risk of IP theft.
2. Identity Privacy: Dynamic Fake Identity (FID)
Standard blockchain addresses are pseudonymous, not anonymous. Analyzing transaction chains can reveal a user's real-world identity. ConGradetect generates a Dynamic Fake Identity based on timestamps and system keys that changes with every operation, effectively breaking the linkability for malicious forensic investigators.
3. Preventing Reward Preemption with zk-SNARKs
One major threat in decentralized crowdsourcing is "Reward Preemption"—where a malicious actor intercepts a result and tries to claim the reward.
- The Solution: The system uses zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) to prove a binding relationship between a specific task and a specific worker without revealing the worker's FID or the task's cleartext on-chain.
Technical Deep Dive: The Logic Flow
The protocol follows a strictly defined lifecycle:
- Task Publication: The owner granulates code locally, encrypts blocks with AES, and uses Proxy Re-Encryption (PRE) to set up the key conversion rules in the smart contract.
- Task Acceptance: When a worker picks a task, the contract performs a "trusted key conversion." The worker receives a re-encrypted key that only their private key can unlock.
- Proof Submission: The worker submits the detection result alongside a zk-SNARK proof of the Task-User binding.
- Reward: If the proof is valid, the contract automatically releases the escrowed funds.

Performance Benchmarks
A critical challenge in early blockchain privacy designs was the heavy computational overhead of encryption. The authors optimized this by selecting Golang's PBC library over Java/JS implementations, resulting in a dramatic reduction in re-encryption time.

- Latency: The end-to-end task publishing process takes approximately 11 to 13 seconds, fitting well within typical Ethereum block times.
- Scalability: Gas consumption grows linearly with the number of tasks, proving the efficiency of the smart contract's logic for moderate loads.
Critical Insight & Future Outlook
ConGradetect moves beyond simple "anonymization" and addresses the structural problem of code security in a shared environment. However, the authors admit a limitation: the Correctness of Results. Currently, they rely on a "majority rules" Boolean logic, which might not capture the nuance of complex software bugs.
The future of this work lies in integrating Natural Language Processing (NLP) to automatically verify the qualitative descriptions of vulnerabilities submitted by workers, creating a fully automated, private, and intelligent security auditing ecosystem.
Conclusion
By bridging the gap between local processing and on-chain verification, ConGradetect provides a viable template for any industry needing to balance collaborative efficiency with high-stakes data privacy.
