{"id":"1541bd40-3397-40f1-bd59-489847e941b3","arxiv_id":"2504.15233","paper_version":1,"verdict":"UNVERDICTED","confidence":"MODERATE","novelty_score":2.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey of privacy challenges and cryptographic privacy techniques in DAG-based distributed ledgers, with a table of existing and potential implementations.","lead":"This preprint surveys privacy problems and possible fixes for DAG-based distributed ledgers, a class of blockchain alternatives that prioritize speed. It catalogs cryptographic tools such as zero-knowledge proofs, mixing, and encryption, and maps current and proposed uses across DAG projects.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The §I-C claim that no prior work focuses on privacy notions in DAG-based DLTs is contradicted by the paper's own cited instances, and no search methodology is provided to support the negative claim.","rationale":"The reader's weakest assumption was the survey's completeness, and I agree that this is the central vulnerability. The strongest evidence is not an absence of proof but the paper's own textual record: §I-C asserts that no prior work focuses on privacy notions in DAG-based DLTs, while §IV lists multiple works that do exactly that, and Table I omits or mislabels at least the HE instances named in §IV-E. Because the paper's value as a survey depends on being comprehensive and on correctly establishing the novelty of its scope, this inconsistency directly undermines the central claim. I do not recommend outright rejection: the survey organizes challenges and candidate techniques usefully, and most of the cryptographic descriptions are standard. The path to a sound verdict is to correct or qualify the negative claim, fix Table I, and document the literature-search protocol. Hence the verdict should move from UNVERDICTED to CONDITIONAL, conditioned on those revisions. I also note the IOTA Ecosystem Development grant in the Acknowledgements as a disclosure to keep in mind when checking whether IOTA-specific coverage is balanced, but it is not the basis of the technical objection.","tokens_in":13412,"tokens_out":5336,"duration_ms":48747,"concrete_test":"Run an independent bibliographic check: enumerate every reference in the paper that describes a privacy property (confidentiality, anonymity, unlinkability, or deanonymization) in an IOTA/Tangle, Nano, Vite, blockDAG, or DAG-consensus system, and compare this list against §I-C and Table I. Concretely, fill Table I's 'Existing Instances' from the paper's own §IV text: if [52] and [53] are not entered in the Homomorphic Encryption row, or if [26], [27], [31], and [34] are missing from the relevant rows, then Table I is internally inconsistent.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The central novelty claim is the negative assertion in §I-C: 'to the best of our knowledge, no prior work focuses on privacy notions in DAG-based DLTs.' This is load-bearing because the paper presents itself as the first comprehensive treatment of privacy in this ledger class. The claim is not backed by any search methodology, and it is internally contradicted by works the paper itself surveys. §IV-A cites Sarfraz et al. [31], which 'provides unlinkability property' for IOTA 1.0 transactions; §III-A cites Yang et al. [26] on deanonymization of IOTA tip selection; §IV-A cites Werner et al. [34] anonymizing Nano transactions; §IV-E states that Dero [52] and Xelis [53] are blockDAG systems employing homomorphic encryption for transaction privacy; §IV-F lists MACT [58], an anonymous consensus mechanism whose ledger is a DAG, and Teegraph [61]/TEEDAG [62] using TEE for confidentiality in DAG systems. Each of these addresses privacy notions (Definitions 2-4) in DAG-structured ledgers. Moreover, Table I's Homomorphic Encryption row lists no existing instances, yet §IV-E names [52] and [53] as existing blockDAG applications of HE. Unless the phrase 'privacy notions in DAG-based DLTs' is arbitrarily narrowed, the central negative claim and Table I completeness fail. The reader's completeness concern is therefore not merely hypothetical; it is evidenced by the paper's own references.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper is a review/survey of privacy in DAG-based distributed ledger technologies (DLTs). It informally defines three privacy notions (confidentiality, anonymity/unlinkability), discusses generic and DAG-specific privacy challenges, and surveys cryptographic mechanisms (transaction mixing, zero-knowledge proofs, digital signatures, encryption, homomorphic encryption, anonymous broadcast, and trusted execution environments). For each mechanism it lists privacy notions captured, challenges, existing instances, and possible instances in DAG-based DLTs. The paper's central claim, stated in Section I-C, is that \"to the best of our knowledge, no prior work focuses on privacy notions in DAG-based DLTs,\" making this the first comprehensive examination of the area.","tokens_in":13729,"tokens_out":4935,"duration_ms":43252,"significance":"If the survey's claims were sustained, it would provide a useful entry point to privacy in DAG-based ledgers. The paper does offer a clear informal taxonomy of privacy notions, a structured review of cryptographic techniques with standard definitions, and a summary table (Table I) that could help practitioners and researchers map techniques to candidate DAG-based DLTs. The paper also correctly identifies several DAG-specific challenges (e.g., tip-selection privacy, conflict resolution with encrypted transactions, and performance overheads). However, the significance is substantially weakened by the overstated novelty claim: the paper's own references include multiple works that directly address privacy notions in DAG-structured ledgers. Moreover, no literature-search methodology is provided, so the survey's completeness claims cannot be independently assessed. These issues are fixable with a more careful framing and greater methodological transparency, but as written they undermine the central contribution.","major_comments":[{"comment":"The central novelty claim, \"to the best of our knowledge, no prior work focuses on privacy notions in DAG-based DLTs,\" is contradicted by several works cited in the same paper. Section III-A cites Yang et al. [26] on a deanonymization attack against IOTA tip selection and proposes improvements to IOTA light-node privacy; Section III-E cites Tennant [27] on theoretical privacy analyses in IOTA; Section IV-A cites Sarfraz et al. [31] for a privacy-aware IOTA ledger providing unlinkability, and Werner et al. [34] for anonymizing Nano transactions; Section IV-E names Dero [52] and Xelis [53] as blockDAG systems using homomorphic encryption for transaction privacy; Section IV-F lists MACT [58], an anonymous consensus mechanism whose ledger is a DAG, and Teegraph [61]/TEEDAG [62] using TEEs for confidentiality. These works address Definitions 2-4 in DAG-structured ledgers. Unless \"privacy notions\" is arbitrarily narrowed to exclude these, the claim is false. The paper should either reject the claim or qualify it, e.g., by stating that no prior work offers a comprehensive cross-system survey of privacy in DAG-based DLTs.","section":"Section I-C"},{"comment":"The paper claims to provide a \"comprehensive examination\" and a state-of-the-art table (Table I), but no search methodology is reported. There is no description of databases queried, search strings, inclusion/exclusion criteria, or the time window of the literature search. Without such information, neither the completeness of Table I nor the negative gap claim can be assessed by readers or reviewers. A review paper making a negative claim about the absence of prior work should document its search strategy.","section":"Methodology (abstract and Section I-C)"},{"comment":"Table I lists Homomorphic Encryption with no existing instances (\"-\"), but Section IV-E explicitly states that \"there have been a few works in DLTs using blockDAG structure that employ homomorphic encryption to provide privacy on transaction data [52], [53]\" and names Dero and Xelis. This is an internal inconsistency. The table should list these works (or the text should clarify why blockDAG systems are excluded from the table, and state that criterion explicitly).","section":"Section IV-E vs Table I"},{"comment":"The final sentence of Section I-B says that \"in the current landscape of DAG-based DLT, the solutions and the associated challenges to achieve privacy notions have not been explored.\" This is a similarly broad negative assertion that is contradicted by the cited works in Sections III and IV. Please harmonize all novelty claims across the paper; as written, the repeated overstatement will mislead readers about the state of the art.","section":"Section I-B"}],"minor_comments":[{"comment":"The manuscript contains typographical artifacts (e.g., \"blockcha ins\" and \"Y et\" in the abstract, \"speciﬁcally\" in the introduction) and inconsistent spelling of author names (\"Sarfaraz\" in Section IV-A vs. \"Sarfraz\" in reference [31]). Please proofread and standardize.","section":"Throughout"},{"comment":"The year for Zama is given as \"20123\"; it should be \"2023\".","section":"Reference [51]"},{"comment":"Table I lists [48] (Fino) under existing instances for Digital Signature, but the text in Section IV-C describes Fino only as a possible instance where blind signatures could be applied; the same work is also cited under Encryption (Section IV-D), where encrypted mempool transactions are described. Please clarify whether [48] is an existing digital-signature-based privacy implementation or an encryption-based one, and adjust the table accordingly.","section":"Section IV-C/Table I"},{"comment":"In the discussion of anonymity, \"untraceable\" is used where \"unlinkable to identity\" may be more precise given Definitions 2-4; consider aligning the terminology throughout for consistency.","section":"Section II-A"}],"recommendation":"major_revision","confidential_remarks":"The paper is within scope for a security/cryptography venue, and the underlying survey, once corrected, could be a useful reference. The central novelty claim is overstated and must be revised; the internal inconsistency in Table I also needs attention. The author discloses IOTA Ecosystem Development grant funding, and the paper gives substantial coverage to IOTA-related privacy work; this is reasonable given the literature, but the editor may wish to be aware of the funding source. No concerns about misconduct are raised by the manuscript itself."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Read this as a catalog, not as a research claim. The survey is genuinely useful: it organizes privacy notions (confidentiality, anonymity, unlinkability), walks through the main techniques — mixing, ZKPs, signatures, encryption, homomorphic encryption, anonymous broadcast, TEEs — and for each gives challenges and instances in DAG-based DLTs. Table I is a handy snapshot, and the discussion of MEV resistance and performance trade-offs is a sensible framing. If you are new to privacy in DAG ledgers, this is a reasonable first stop.\n\nThe problem is the packaging. Section I-C says 'to the best of our knowledge, no prior work focuses on privacy notions in DAG-based DLTs,' and the paper leans on that to justify its existence. The stress-test note is right: the paper's own citations contradict it. [26] is a de-anonymization attack on IOTA's tip selection. [27] is a theoretical privacy analysis of IOTA. [30] and [31] propose mixers for IOTA privacy. [34] anonymizes Nano transactions. [52] and [53] are blockDAG systems using homomorphic encryption for transaction privacy. [58] is an anonymous consensus mechanism with a DAG ledger. Unless 'privacy notions' is narrowed to something like 'a systematic formal treatment of all three notions across the whole family,' the claim fails on contact. And there is no search methodology — no databases, inclusion criteria, or time window — so the negative claim is unreproducible.\n\nThere are also a couple of internal table/text inconsistencies. Table I's Homomorphic Encryption row says no existing instances, but Section IV-E names Dero [52] and Xelis [53] as working blockDAG applications. The Digital Signature row lists [48] as an existing instance, yet the text says no work exists on ring signatures in DAG-based DLTs and only suggests blind signatures as a possible fit for Fino [48]. These are fixable, but they underscore that the survey was assembled faster than it was checked.\n\nNone of this sinks the useful core. The synthesis is plausible and the topic is underserved. The fix is to reframe the contribution as 'a consolidated overview and mapping,' drop or soften the 'no prior work' assertion, add a short methodology paragraph, and reconcile the table with the text. With those changes it becomes a legitimate entry point for both researchers and practitioners.\n\nVerdict: worth a serious referee, but it needs major revision before publication. If I were editing, I would send it out — surveys like this are valuable when they are honest about scope.","headline":"Useful survey of privacy techniques for DAG-based ledgers, but the 'no prior work' novelty claim collapses against the paper's own reference list.","tokens_in":14243,"tokens_out":2110,"would_cite":false,"duration_ms":19633,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This review claims that privacy in DAG-based distributed ledgers has been largely overlooked, and it offers the first organized map of privacy notions, challenges, and cryptographic tools for these systems.","keywords":["DAG-based DLT","distributed ledger privacy","confidentiality","anonymity","unlinkability","zero-knowledge proofs","transaction mixing","MEV resistance"],"falsifier":"A systematic literature search with explicit databases, queries, and inclusion criteria that locates a published privacy-preserving DAG-based DLT—or a dedicated study of privacy notions in DAG-based DLTs—predating this review would refute the paper's central 'no prior work' claim. The paper's own examples, such as the privacy-aware IOTA ledger with decentralized mixing [31], set the bar: any predecessor satisfying unlinkability or anonymity would count.","tokens_in":13225,"feed_emoji":"🔐","tokens_out":6611,"duration_ms":58382,"temperature":0.7,"pith_summary":"Existing blockchains have a large body of privacy work, but DAG-based distributed ledgers were built for throughput and largely ignore privacy. This paper tries to close that gap by defining the three core privacy notions—confidentiality, anonymity/untraceability, and unlinkability—cataloging the obstacles created by the DAG structure, and mapping the cryptographic tools that could deliver privacy in these systems. The reason to care is practical: without privacy, DAG ledgers cannot serve applications that require confidential transactions, and public metadata exposes users to tracking, deanonymization, and manipulation of transaction ordering. If the paper is right, the missing piece is not new cryptography but focused engineering and research on applying known techniques to DAG-specific constraints.","feed_headline":"Survey finds DAG-based ledgers skip privacy, maps fixes","feed_subtitle":"Existing tools like zero-knowledge proofs and mixing could close the confidentiality gap.","key_machinery":"The analytical apparatus is a three-part taxonomy: the privacy notions (confidentiality, anonymity/untraceability, and unlinkability), the DAG-specific obstacles (tip selection, conflict resolution, performance, consensus, anonymization analysis, and attack vectors), and seven cryptographic solution families. The taxonomy is summarized in a matrix that lets each DAG-based DLT be assessed against which privacy notion it could satisfy and where it would break down, which is the mechanism that carries the survey's argument that privacy in DAG-based DLTs is an open and underexplored problem.","core_discovery":"The paper's central claim is that no currently deployed DAG-based DLT is privacy-centric, and that, to the best of the author's knowledge, no prior work focuses on privacy notions in DAG-based DLTs. It argues that current DAG ledgers expose plaintext transaction data with pseudonymous addresses, so adversaries can track accounts through address reuse, taint analysis, transaction analysis, and metadata analysis. It then reviews seven families of cryptographic mechanisms used in blockchains—transaction mixing, zero-knowledge proofs, digital signatures, encryption, homomorphic encryption, anonymous broadcast, and trusted execution environments—and identifies where each could or already does provide privacy in DAG systems. The intended conclusion is that privacy in DAG-based DLTs is feasible but requires balancing DAG-specific consensus, performance, and conflict-resolution constraints.","pith_inferences":["We infer that the 'no prior work' claim is best read as a gap claim about full DLT-level privacy rather than about individual privacy techniques, since the paper itself cites earlier work such as PDAG and privacy-aware IOTA mixing.","We infer that the same seven solution families can be tested immediately in DAG-based consensus protocols like Narwhal/Tusk and Bullshark, because their mempool and ordering layers already lend themselves to encrypted transactions and order-fairness.","We infer that the absence of a privacy-centric DAG DLT is a falsifiable prediction: the publication or release of such a system after this survey would directly change the landscape the paper describes.","We infer that the central research bottleneck is the privacy-versus-performance tradeoff, so benchmark studies of zero-knowledge proof and homomorphic encryption overhead on existing DAG systems would be a natural next step."],"forward_implications":["Transaction mixing, zero-knowledge proofs, encryption, homomorphic encryption, anonymous broadcast, and trusted execution environments can each contribute at least one of the three privacy notions to DAG-based DLTs without inventing new cryptographic primitives.","Privacy in DAG ledgers directly reduces miner extractable value (MEV) attacks: hiding transaction contents before ordering makes transaction-order manipulation harder and improves fairness.","DAG-specific mechanisms—tip selection, conflict resolution, ordering, and consensus—are the points where privacy implementations break down, so privacy cannot be ported blindly from blockchains.","Current DAG-based systems with privacy features are few, for example Aleph Zero, Fino, MACT, Teegraph/TEEDAG, and privacy-aware IOTA and Nano mixers, confirming the paper's picture of an early-stage field.","A concrete research path is combining zero-knowledge proofs with signatures or encryption to reduce proof-generation cost while preserving privacy."],"supporting_citations":[{"why":"Establishes the DAG-based DLT definition and consensus background the survey builds on.","marker":"[16]"},{"why":"Provides the prior privacy-preserving transaction DAG model (PDAG) that the paper distinguishes from a full privacy-preserving DAG DLT.","marker":"[17]"},{"why":"Documents a deanonymization attack on IOTA's tip selection, grounding the tip-selection privacy challenge.","marker":"[26]"},{"why":"Gives earlier theoretical analysis of IOTA privacy issues, grounding the anonymization-challenge discussion.","marker":"[27]"},{"why":"Describes a privacy-aware IOTA ledger with decentralized mixers, an existing DAG privacy instance.","marker":"[31]"},{"why":"Describes centrally administered coinmixers for Nano, another existing DAG privacy instance.","marker":"[34]"},{"why":"Uses zero-knowledge proofs for level-1 privacy on a DAG-based protocol, an existing instance.","marker":"[37]"},{"why":"Presents Fino, which encrypts mempool transactions on a DAG for MEV resistance, supporting the encryption and fairness argument.","marker":"[48]"},{"why":"Presents MACT, a Tor-based anonymous consensus mechanism with a DAG ledger, supporting the anonymous-broadcast solution category.","marker":"[58]"},{"why":"Presents Teegraph, a TEE-and-DAG consensus algorithm, supporting the trusted execution environment solution category.","marker":"[61]"}],"fun_headline_variants":["DAG ledgers lack privacy; review proposes crypto fixes","No DAG DLT is privacy-centric, review finds","Privacy gap in DAG DLTs: review maps seven fix families","DAG-based ledgers expose data; tools to fix it reviewed"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The survey's conclusion that no prior work focuses on privacy in DAG-based DLTs rests entirely on the author's literature search, and the paper gives no search methodology; if a relevant privacy-preserving DAG-based DLT or study was missed, the claimed gap and the state-of-the-art table are incomplete.","fun_headline_variants_meta":{"raw":{"variants":["DAG ledgers lack privacy; review proposes crypto fixes","No DAG DLT is privacy-centric, review finds","Privacy gap in DAG DLTs: review maps seven fix families","DAG-based ledgers expose data; tools to fix it reviewed"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000542,"raw_usage":{"total_tokens":2534,"prompt_tokens":818,"completion_tokens":1716,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":434,"completion_tokens_details":{"reasoning_tokens":1644}},"tokens_in":434,"tokens_out":1716,"duration_ms":12628,"temperature":1.0,"reasoning_tokens":1644,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T11:29:08.427668+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A systematic literature search with explicit databases, queries, and inclusion criteria that locates a published privacy-preserving DAG-based DLT—or a dedicated study of privacy notions in DAG-based DLTs—predating this review would refute the paper's central 'no prior work' claim. The paper's own examples, such as the privacy-aware IOTA ledger with decentralized mixing [31], set the bar: any predecessor satisfying unlinkability or anonymity would count.","supporting_citations":[{"cited_title":"Sok: Dag-ba sed consensus protocols,","cited_arxiv_id":null,"evidence_quote":"Establishes the DAG-based DLT definition and consensus background the survey builds on."},{"cited_title":"A transact ion-level model for blockchain privacy,","cited_arxiv_id":null,"evidence_quote":"Provides the prior privacy-preserving transaction DAG model (PDAG) that the paper distinguishes from a full privacy-preserving DAG DLT."},{"cited_title":"A Tip for IOTA Privacy: IOTA Light Node Deanonymization via Tip Selection","cited_arxiv_id":"2403.11171","evidence_quote":"Documents a deanonymization attack on IOTA's tip selection, grounding the tip-selection privacy challenge."},{"cited_title":"Improving the anonymity of the iota crypto currency,","cited_arxiv_id":null,"evidence_quote":"Gives earlier theoretical analysis of IOTA privacy issues, grounding the anonymization-challenge discussion."},{"cited_title":"Privacy a ware iota ledger: Decentralized mixing and unlinkable iota transact ions,","cited_arxiv_id":null,"evidence_quote":"Describes a privacy-aware IOTA ledger with decentralized mixers, an existing DAG privacy instance."},{"cited_title":"Anonymization of transactions in distributed ledger technologies,","cited_arxiv_id":null,"evidence_quote":"Describes centrally administered coinmixers for Nano, another existing DAG privacy instance."},{"cited_title":"Fundamentals: Aleph zero and its dag implemen tation,","cited_arxiv_id":null,"evidence_quote":"Uses zero-knowledge proofs for level-1 privacy on a DAG-based protocol, an existing instance."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Presents Fino, which encrypts mempool transactions on a DAG for MEV resistance, supporting the encryption and fairness argument."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Presents MACT, a Tor-based anonymous consensus mechanism with a DAG ledger, supporting the anonymous-broadcast solution category."},{"cited_title":"Mact: A multi -channel anonymous consensus based on tor,","cited_arxiv_id":null,"evidence_quote":"Presents Teegraph, a TEE-and-DAG consensus algorithm, supporting the trusted execution environment solution category."}],"review_version":1}