ConGradetect: Solving the Privacy Paradox in Blockchain Crowdsourced Security

ConGradetect: Blockchain-based detection of code and identity privacy vulnerabilities in crowdsourcing

2020-10-14
Jitao Wang, Guozi Sun, Yu Gu, Kun Liu
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces ConGradetect, a blockchain-based crowdsourcing system designed for smart contract vulnerability detection. It integrates dynamic fake identities, local code granulation, proxy re-encryption, and zk-SNARKs to ensure code privacy and identity anonymity while preventing reward preemption.

TL;DR

ConGradetect is a decentralized framework that enables secure crowdsourcing for code vulnerability detection. By combining Dynamic Fake Identities, Local Code Granulation, and zk-SNARKs, it allows organizations to outsource code auditing without exposing full source code to workers or leaking identities on the transparent Ethereum ledger.

Background: The Trust Deficit in Crowdsourcing

Crowdsourcing platforms like Amazon Mechanical Turk or specialized security response centers are historically centralized. This creates a "black box" where the platform controls all data, often leading to untrusted reward distributions and potential identity leaks.

While Blockchain 2.0 (Smart Contracts) offers a decentralized alternative for transparency, it introduces a new paradox: How do you keep private code and identities secure on a ledger where every transaction is public?

The ConGradetect Architecture

The authors propose a multi-layered approach to handle three core tensions: code complexity vs. detection efficiency, anonymity vs. certification, and transparency vs. privacy.

Vulnerability detection crowdsourcing architecture

1. Code Privacy through Granulation

Instead of uploading the entire smart contract, a Local Code Granulation Tool splits the code into smaller, non-contiguous blocks. Each block is encrypted using AES.

  • The Insight: An individual worker only sees a fragment (a "granule") of the code. They cannot reconstruct the full logic or identify the owner, significantly reducing the risk of IP theft.

2. Identity Privacy: Dynamic Fake Identity (FID)

Standard blockchain addresses are pseudonymous, not anonymous. Analyzing transaction chains can reveal a user's real-world identity. ConGradetect generates a Dynamic Fake Identity based on timestamps and system keys that changes with every operation, effectively breaking the linkability for malicious forensic investigators.

3. Preventing Reward Preemption with zk-SNARKs

One major threat in decentralized crowdsourcing is "Reward Preemption"—where a malicious actor intercepts a result and tries to claim the reward.

  • The Solution: The system uses zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) to prove a binding relationship between a specific task and a specific worker without revealing the worker's FID or the task's cleartext on-chain.

Technical Deep Dive: The Logic Flow

The protocol follows a strictly defined lifecycle:

  1. Task Publication: The owner granulates code locally, encrypts blocks with AES, and uses Proxy Re-Encryption (PRE) to set up the key conversion rules in the smart contract.
  2. Task Acceptance: When a worker picks a task, the contract performs a "trusted key conversion." The worker receives a re-encrypted key that only their private key can unlock.
  3. Proof Submission: The worker submits the detection result alongside a zk-SNARK proof of the Task-User binding.
  4. Reward: If the proof is valid, the contract automatically releases the escrowed funds.

Protocol process

Performance Benchmarks

A critical challenge in early blockchain privacy designs was the heavy computational overhead of encryption. The authors optimized this by selecting Golang's PBC library over Java/JS implementations, resulting in a dramatic reduction in re-encryption time.

Gas consumption of execution

  • Latency: The end-to-end task publishing process takes approximately 11 to 13 seconds, fitting well within typical Ethereum block times.
  • Scalability: Gas consumption grows linearly with the number of tasks, proving the efficiency of the smart contract's logic for moderate loads.

Critical Insight & Future Outlook

ConGradetect moves beyond simple "anonymization" and addresses the structural problem of code security in a shared environment. However, the authors admit a limitation: the Correctness of Results. Currently, they rely on a "majority rules" Boolean logic, which might not capture the nuance of complex software bugs.

The future of this work lies in integrating Natural Language Processing (NLP) to automatically verify the qualitative descriptions of vulnerabilities submitted by workers, creating a fully automated, private, and intelligent security auditing ecosystem.

Conclusion

By bridging the gap between local processing and on-chain verification, ConGradetect provides a viable template for any industry needing to balance collaborative efficiency with high-stakes data privacy.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize zero-knowledge proofs (zk-SNARKs/STARKs) specifically for identity preservation in blockchain-based crowdsourcing systems.
  • Which study first introduced the concept of code granulation for secure multi-party code auditing, and how does it compare to the local granulation tool in this paper?
  • Investigate the application of Proxy Re-Encryption in decentralized storage networks (like IPFS or Filecoin) for fine-grained access control of sensitive technical documents.
Contents
ConGradetect: Solving the Privacy Paradox in Blockchain Crowdsourced Security
1. TL;DR
2. Background: The Trust Deficit in Crowdsourcing
3. The ConGradetect Architecture
3.1. 1. Code Privacy through Granulation
3.2. 2. Identity Privacy: Dynamic Fake Identity (FID)
3.3. 3. Preventing Reward Preemption with zk-SNARKs
4. Technical Deep Dive: The Logic Flow
5. Performance Benchmarks
6. Critical Insight & Future Outlook
7. Conclusion