Themis Consensus Extension v1: MEV Mitigation by Randomized Delayed Execution and Intent-Hiding Transactions in Application-Specific Blockchains
Shoeb Siddiqui, Mateusz Nowakowski, Stanislav Vozarik, Gleb Urvanov, Peter Kris
https://arxiv.org/abs/2607.21406 https://arxiv.org/pdf/2607.21406 https://arxiv.org/html/2607.21406
arXiv:2607.21406v1 Announce Type: new
Abstract: Maximal extractable value (MEV) arises when privileged participants select, exclude, insert, or reorder pending transactions for private gain. We specify and analyze the Themis Consensus Extension v1, first published by Mangata in 2021. The design separates value extraction by reordering (VER) from value extraction by denial (VED). For VER, block construction and execution occur across consecutive producers: one producer commits a transaction set, and the next derives a publicly verifiable, deterministic, previously un- predictable seed and executes a seed-determined, dependency-preserving permutation. For selective VED, a user may encrypt a transaction for a designated builder and executor. The builder removes an outer layer and commits the opaque inner ciphertext; the executor reveals and executes the plaintext only after commitment. Under selfish but non-colluding validators, an adversary below the underlying consensus fault threshold, secure cryptography, and accountable role performance, the construction limits unilateral post-commit ordering control and hides transaction intent from relays and the builder. It does not provide send-order or receive-order fairness, complete censorship resistance, resistance to builder-executor collusion, or per-transaction price guarantees. We analyze probabilistic extraction, spam, dependent transactions, decryption liveness, session boundaries, total denial, and threshold coalitions. We also document the initial Aura-based Substrate implementation and its subsequent transition to a BABE-based sr25519/VRF seed path, together with delayed execution, Fisher-Yates shuffling, and Xoshiro256 . The result preserves the original proposal while narrowing its claims to explicit assumptions.
toXiv_bot_toot
Which Model Is Actually Serving You? IRIS: Budgeted Black-Box Auditing of Model Substitution and Routing Dilution in LLM Gateways
Yuewei Zhang, Zhi-Hai Zhang, Hanzhang Qin
https://arxiv.org/abs/2607.20860 https://arxiv.org/pdf/2607.20860 https://arxiv.org/html/2607.20860
arXiv:2607.20860v1 Announce Type: new
Abstract: Commercial LLM gateways mediate access to hosted models, but the served backend may not match the advertised one: it may substitute a cheaper model on every request or route only a fraction $\epsilon$ of requests to it. Prior black-box auditors often need a privileged signal (log-probabilities, token ranks, or reference samples) or a target-specific probe, fix the query budget in advance, and return a yes/no verdict. We present $\mathrm{IRIS}$, an audit that needs only the returned text: it asks endpoints to generate random numbers or strings, fingerprints the backend, and is the first to combine, in one text-only audit, detection of whole-stream substitution and fractional dilution, attribution of the served backend, routing-fraction ($\epsilon$) estimation, and a query budget it sizes itself. A cheap pilot fits the exponential query-error decay and freezes that budget before any suspect query is issued. On an intra-family Qwen3 ladder $\mathrm{IRIS}$ verifies the backend at $0.99$ AUROC and sharpens attribution as queries accumulate; across a commercial OpenRouter library it catches $\epsilon{=}0.3$ dilution on margin-qualified pairs at $0.85$ mean power ($0.017$ false-positive rate) and recovers $\epsilon$ to within $0.04$ for enrolled diluents; and a live cross-provider audit flags $14$ of $15$ same-model provider pairs by genuine quantization and kernel deviations, corroborated on third-party MET traces. Against comparable black-box auditors, $\mathrm{IRIS}$ matches or beats detection on shared tasks, and adaptive allocation lifts the matched-budget target-hit rate from $73$% to $87$%. Further experiments cover adversarial gateways, knob identifiability, unseen diluents, and false-positive control.
toXiv_bot_toot
Ireland’s basic income for artists
has been made permanent
after research showed that it boosted the economy.
Other nations have similar schemes.
With more homegrown artists now coming from privileged backgrounds
and AI disrupting the creative industries,
there are calls for the UK to follow suit
Buzz to Boom: Detecting Message Progression Vulnerabilities in Electron Applications via Segmented Directed Fuzzing
Jianjia Yu, Zhengyu Liu, Ziyang Li, Yu Sun, Yinzhi Cao
https://arxiv.org/abs/2607.20698 https://arxiv.org/pdf/2607.20698 https://arxiv.org/html/2607.20698
arXiv:2607.20698v1 Announce Type: new
Abstract: Electron is a popular framework for building cross-platform desktop applications using web technologies. Such applications consist of multiple processes with different privilege levels that communicate via message passing. When inter-process messages carry attacker-controlled inputs, they can propagate across processes and reach privileged APIs, e.g., command execution. Such a message propagation behavior is characterized as Message Progression Vulnerabilities (MPVs). The exploitation of MPVs is challenging because it often requires multiple steps, e.g., first arbitrary code execution in one process via message passing, and then command injection in another process using another message crafted in the first process. To our knowledge, existing works on Electron security only study unsafe configurations and malicious Document Object Model (DOM) content, i.e., they cannot detect or exploit these vulnerabilities that need to be triggered by complex cross-process exploits via message passing. We present Proton, a segmented directed fuzzing framework for detecting MPVs. Our key insight is to decompose end-to-end fuzzing into per-process segments along message-passing boundaries, where the goals of fuzzing each segment are either: (i) reaching a sink in the current process or (ii) propagating the payload to the next process, to enable the exploration of another process. In the second case, the messages seed the corpus of the next segment. Finally, Proton synthesizes crash inputs from each process to validate end-to-end exploits. We evaluate Proton against 589 real-world Electron applications, resulting in 23 zero-day MPVs. Among them, 22 lead to OS command execution, including projects with over 50k GitHub stars. We responsibly disclosed all findings. To date, we have received 13 acknowledgments, 11 fixes, and 11 CVEs, including a bug bounty from Vercel.
toXiv_bot_toot
RE: https://mastodon.world/@mmotherps/116657572396305174
It blows my mind how ignorant (gullible? privileged?) people in the West can be.
How can you believe the genocide is over and everything’s just great now in Gaza?
I know I'm in a ridiculously privileged situation to be able to moan about this, but work has really felt like **work** recently. Endless marking, paper revisions, reviewing, and admin. It seems that all of the crap tasks have basically bunched together in the last couple of weeks.
14yo (to my wife): "You know, you're real lucky to have a teenager who wants to hang out with you. Don't know how lucky and privileged you are. You don't appreciate what you have. Lots of people have teenagers that don't want to hang out with their parents, but not you.. "
My wife went to do yoga on the beach this morning... Accordingly to her it was such a terrible experience: sun recently rising was already shining strong, the sand was making changing postures difficult, noises made by the sea were distracting... and sand everywhere was just so annoying...
I like to say: typical problems of the "privileged" people!
Contrary, I love the beach, especially in the morning, because there is hardly anyone and it's not too hot yet.
It …
RE: https://mastodon.scot/@IndyRichard/116645632714298777
How privileged, ignorant, or callous do you have to be to holiday in the US in 2026?
A super closeup of yoga narasimha of Kaniyooru Matha, Udupi. Not my picture.
BTW presently only nine people in this world are allowed to even touch this idol. (There'll ever be at most 16.) That's a truly exclusive and privileged group but also one with a lot of responsibility. #ama
#art #sculpture #Udupi #India
A cruelty of all this is that it rewards the people who are already the most privileged, the most likely to believe in their own ability / worth regardless of external cues, perhaps the most likely to overestimate themselves.
When a job says “5 years of FancyFramework experience,” I guarantee you that there is a lopsided distribution of identity traits (male, white, etc) to those people who are applying anyway despite only using FancyFramework for 2-3 years. And I guarantee you some of those people who don’t meet the “requirements” will be under real consideration for the hire.
It’s a self-selection process that amplifies any inequality a person can internalize.
8/