{"id":"34088035-8998-43e2-99c7-1855140ba3e4","arxiv_id":"2504.17809","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Using k-core decomposition, the authors report that Monero's P2P network has a core-periphery structure dominated by 14 super-peers.","lead":"This paper analyzes the peer-to-peer network of the Monero cryptocurrency and reports that it has a core-periphery structure, with a small group of high-degree super-peers at the center. The finding matters because it suggests how robust Monero's network is to targeted attacks and where its structural vulnerabilities lie.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Central claim rests on the unpublished network map from [22]; if that map is incomplete or biased, the k=16 core and super-peer findings are not properties of the live Monero network.","rationale":"The reader's weakest_assumption identifies the same load-bearing gap: the paper treats the prior unpublished map [22] as ground truth, and every downstream conclusion depends on it. My analysis confirms this is the single most critical point. The paper provides no way to check the map's completeness or accuracy, and the central claim is an empirical claim about the live Monero network, not about a reconstructed graph. A secondary concern is that k-core decomposition, even on a perfect graph, does not by itself establish core-periphery structure without a null model or comparison to a random graph baseline; however, that is subordinate to the graph-validity issue because if the graph is wrong the k-core result is meaningless. The reader's verdict of CONDITIONAL is appropriate: the analysis is plausible and the methods are standard, but the load-bearing evidence is unavailable. A concrete validation of the network map, or at least publication of the data and reconstruction code, would resolve the concern. I agree with the reader rather than only partially because the weakest assumption stated in the reader's report is exactly the one I would stress-test first, and it is the same concern that blocks full acceptance.","tokens_in":5450,"tokens_out":2173,"duration_ms":22554,"concrete_test":"Request the network dataset and reconstruction code from the authors (the artifact of [22]) and independently validate it by running an instrumented Monero node during the same observation window, recording all peer-list responses. Compare edge-level precision and recall against the reconstructed graph, then recompute the k-core and super-peer sets on the validated graph. If precision or recall is below 90%, or if the k=16 core changes by more than 10% of its nodes, the paper's central core-periphery claim is not established.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"Section 2 states that the Monero P2P graph was mapped in the authors' prior work [22] using the classic k-means method, and the rest of the paper analyzes only that reconstructed graph. The k-core decomposition (Section 3), the 178-node k=16 core, the 14 super-peers, and the Knn(k) disassortativity are all computed on this graph, yet [22] is under review and no validation is presented: no ground-truth comparison, no sensitivity analysis, no error bounds. Because k-means clustering is used to infer peer identities and edges, systematic errors such as merging distinct peers behind NAT or dropping short-lived connections would directly alter core membership and degree distributions. The authors themselves only claim 'relatively high accuracy' without evidence. If the map is incomplete or biased, the asserted core-periphery structure could be an artifact of the reconstruction rather than a property of the actual Monero network. This concern is not about consensus or style; it is about whether the central empirical claim is supported by the evidence provided.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper analyzes the topology of the Monero peer-to-peer network, building on the authors' prior unpublished work [22] that reconstructed the network graph using a k-means method. The authors compute nearest-neighbor degree correlations, report a negative assortativity of -0.28, and apply k-core decomposition, finding a k=16 core of 178 peers and 14 super-peers. They interpret these observations as evidence of a core-periphery structure and claim that this structure explains resilience against targeted attacks on central nodes. The paper is short, presents a small number of figures, and relies entirely on the reconstructed graph from [22] without providing validation, null models, or uncertainty quantification.","tokens_in":5647,"tokens_out":3878,"duration_ms":36219,"significance":"If the reconstructed Monero network graph is faithful, the paper's identification of a core-periphery structure and a small set of super-peers would be a meaningful empirical contribution to understanding the architecture and attack resilience of privacy-focused cryptocurrency networks. The topic is relevant to the network-science and blockchain communities, and the use of k-core decomposition is methodologically standard. However, the central empirical claim depends critically on the unpublished companion paper [22], and the paper does not provide the validation or baselines needed to establish that the observed structure is a genuine property of the live Monero network rather than an artifact of the reconstruction method.","major_comments":[{"comment":"The entire analysis rests on the Monero network map reconstructed in the authors' prior unpublished work [22], which is described as having 'relatively high accuracy' without evidence. Because the mapping uses a k-means method to infer peer identities and edges from address-list samples, systematic errors—such as merging distinct peers behind NAT, missing short-lived connections, or misclassifying seed nodes—would directly alter the degree distribution, k-core sizes, super-peer identification, and assortativity. No ground-truth comparison, sensitivity analysis, or error bounds are provided. If the reconstructed graph is incomplete or biased, the reported k=16 core of 178 peers and the 14 super-peers may not be properties of the actual Monero network. The central claim is therefore not supported by the evidence supplied in this manuscript.","section":"Section 3, paragraphs 'The k-core algorithm partitions...' and 'By detailed checking...'"},{"comment":"The k-core decomposition is used to 'confirm' a core-periphery structure, but k-core decomposition by construction always yields a nested hierarchy of densely connected subgraphs for any graph with sufficient degree heterogeneity. No null model is used: the authors do not compare the observed k-core size or the core-periphery pattern against a random graph with the same degree sequence, nor do they compute a quantitative core-periphery fit (for example, the Borgatti-Everett correlation with a core-periphery ideal). Without such a baseline, the claim that Monero's network exhibits a core-periphery structure is not tested against the natural alternative that the observed k-core is an expected feature of a heavy-tailed random network. This is a load-bearing point because the paper's main conclusion is the existence of core-periphery organization.","section":"Section 3, 'The k-core algorithm partitions...' "},{"comment":"The abstract states that the core-periphery structure 'explains why targeting central nodes does not easily lead to the rapid disintegration of the network's largest connected component,' and Section 3 claims that removing the 14 super-peers 'drastically reduces the connectivity of the remaining peers.' However, no attack simulation, percolation analysis, or quantitative robustness metric is presented in this paper; the referenced resilience finding appears to come from the unpublished work [22]. The resilience claim in the abstract is therefore not demonstrated by the results reported here and should either be supported with concrete simulations or removed from the abstract.","section":"Abstract and Section 3, super-peer removal"},{"comment":"The assortativity coefficient of -0.28 is reported without confidence intervals, significance testing, or any discussion of how the uncertainty in the reconstructed graph affects this point estimate. Because the graph itself is the output of an inference method with unknown error, the precision implied by reporting a single value is misleading. At minimum, the authors should provide a measure of uncertainty or a sensitivity analysis with respect to the mapping parameters.","section":"Fig. 1 and Section 3, first paragraph"}],"minor_comments":[{"comment":"There are typographical errors: 'T opology' in the keywords, 'Alogrithm' in the Section 2.2 heading, and 'classick-means' in Section 2. These should be corrected.","section":"Keywords and Section 2.2 heading"},{"comment":"The notation in Eq. (1) is inconsistent: the left-hand side uses K while the right-hand side uses k, and the section text alternates between 'K' and 'k'. Please standardize the notation and define all symbols in one place.","section":"Section 2.1, Eq. (1)"},{"comment":"The statement that '3,153 neighbors are directly connected to the 14 super nodes' and that their 'mutual connections represent 82.1% of the entire network' is not clearly defined. What does 'directly connected' mean exactly, and how is the 82.1% computed? Please clarify the definitions and show the calculation.","section":"Section 3, fourth paragraph"},{"comment":"The text says there are 'two dashed reference lines are plotted at x = 8' while the caption mentions 'Dashed red and purple lines' marking 'the reference thresholds at x = 8.' It is unclear whether there are two distinct lines at x=8 or a single line; please make the figure and caption consistent.","section":"Fig. 4 caption and text"},{"comment":"Reference [22] is listed as '(under review)' and is the foundation of the empirical analysis. If possible, provide a preprint identifier (e.g., arXiv number) or make the dataset and reconstruction code available so that the current paper's results can be independently checked.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The core issue is the heavy dependence on the unpublished companion paper [22] for the network graph, without which the empirical claims cannot be evaluated. I would recommend requiring the authors to either (a) provide the reconstructed graph and full mapping methodology in a way that reviewers can assess, or (b) include validation against independently obtained Monero network data and a clearly described null-model comparison for the core-periphery claim. The paper is also very short for the scope of its claims; the resilience argument is not supported by experiments in this manuscript and should be removed or substantiated. If the authors can address the validation and baseline concerns, the paper could be a useful contribution, but as it stands the central finding is not sufficiently established."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe one thing you should know: this is the first published k-core decomposition of the Monero P2P network, with a concrete structural claim (16-core of 178 nodes, 14 super-peers, negative assortativity). The analysis is clean as far as it goes. But the empirical foundation is the authors' own unpublished network map from [22], and they do not provide the data, the inference code, or any validation against ground truth. Until that map is available and its error characteristics are quantified, the core-periphery result is a property of their reconstruction, not necessarily of the live network.\n\nWhat the paper does well: it clearly motivates why Monero's protocol evolution makes network inference hard, it explains the k-means detection method (though briefly), and it gives a readable visual account of the core structure. The observation that most nodes hover around 8 connections—likely the default outgoing connection count—and that core nodes share over 91% of neighbors with the top-14 is genuinely interesting. The assortativity value −0.28 and the Knn(k) curve are consistent with a disassortative, hub-spoke topology, and that part of the analysis is reasonable.\n\nWhere it falls short: the reliance on [22] is load-bearing. The authors say 'relatively high accuracy' but give no accuracy measurement, and k-means clustering to infer peer identities could easily merge NAT'd peers or miss short-lived connections. A sensitivity analysis—e.g., edge rewiring, node subsampling, or comparing against an independently collected snapshot—would be needed to see if the 16-core and the 14 super-peers are stable. Second, the k-core decomposition by construction returns a dense subgraph, so calling the result a 'confirmation' of core-periphery is close to circular. A null model (configuration model or degree-preserving randomization) would show whether the observed k-core size is larger than expected by chance. Third, the paper claims the structure 'explains' resilience to targeted attack, but no attack simulation is performed; the conclusion even acknowledges that super-peers are attack vectors. That's fine as a hypothesis, but it should be labeled as such.\n\nNone of these flaws are fatal to the basic descriptive claim—Monero's network looks core-periphery—but they make it impossible to assess confidence from this paper alone.\n\nThis is worth a serious referee, but the paper needs major revision: make [22] public, add validation and a null model, and tone down the resilience language unless you simulate attacks. A network scientist studying cryptocurrency P2P systems will want to read this; I would not cite it for the specific numbers until the underlying map is released.","headline":"First k-core view of Monero's P2P topology, but it rests on an unpublished map and a tautological core-periphery read; deserves review with major revisions.","tokens_in":6167,"tokens_out":2504,"would_cite":false,"duration_ms":23618,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Monero's P2P network is a core-periphery structure with 178 core peers.","keywords":["Monero","peer-to-peer network","network topology","core-periphery structure","k-core decomposition","super-peers","disassortativity","cryptocurrency privacy"],"falsifier":"Run k-core decomposition on a Monero P2P graph collected independently from multiple vantage points during the same period; if the largest $k$ with a sizable core is not 16, or if the 14 highest-degree super-peers do not appear as hubs, the paper's core-periphery claim is undercut. The most direct check is whether removing those 14 nodes from an independent full-network map reduces the largest connected component's size by the expected amount.","tokens_in":5275,"feed_emoji":"🕸️","tokens_out":4896,"duration_ms":44743,"temperature":0.7,"pith_summary":"This paper tries to establish that Monero's peer-to-peer network has a core-periphery topology rather than a flat or modular structure. Using k-core decomposition of a graph mapped in prior work, it finds a 178-peer core at $k=16$ and identifies 14 super-peers that act as hubs: peripheral peers connect preferentially to these hubs, while the hubs themselves are only sparsely connected to each other. The authors argue that this structure explains a previously observed resilience result: the largest connected component does not rapidly disintegrate when central nodes are targeted, because the core retains alternate paths through non-super-peer core members. A reader should care because the result shows where Monero's decentralization actually lives and where a targeted attack would bite.","feed_headline":"Monero's P2P network hides a core of 178 hubs","feed_subtitle":"K-core analysis finds 14 super-peers hold Monero's network together, and removing them would fragment it.","key_machinery":"The load-bearing tool is k-core decomposition. A $k$-core is the maximal subgraph in which every node has degree at least $k$ within that subgraph; iteratively peeling nodes below the threshold exposes nested layers from periphery to core. Complementing this, the paper uses the nearest-neighbour degree $K_{nn}(k)$, the average degree of the neighbours of nodes of degree $k$, and the assortativity coefficient to show that low-degree peers attach to high-degree peers. The $k=16$ core of 178 peers is the concrete object that carries the core-periphery claim, and the scatter of connections from nodes to the top-14 hubs quantifies how peripheral nodes depend on the core.","core_discovery":"The central claim is that Monero's P2P network is organized as a core and a periphery. The mapped network has 4,837 nodes, and k-core decomposition yields a most interconnected subgraph of 178 peers at $k=16$. The 14 highest-degree super-peers connect to 3,153 neighbors, and their mutual connections represent 82.1% of the entire network. Despite this, the super-peers do not form a clique: in the k-core adjacency matrix, connectivity among super-peers is sparse relative to their connections to non-super-peers, indicating a hierarchical relay topology. Removing the 14 super-peers leaves many remaining core members isolated or weakly connected, so the core's robustness depends heavily on those hubs. Degree correlation is disassortative, with an assortativity coefficient of $-0.28$, meaning low-degree peers attach preferentially to high-degree peers, and a dense cluster of nodes near degree 8 suggests a default configuration of eight outgoing connections.","pith_inferences":["The paper does not test what happens when the 14 super-peers are removed from the full network rather than from the k-core; a natural extension is to simulate targeted attacks on the full graph and compare the size of the largest connected component before and after removal.","Because the map comes from a single prior snapshot, the k-core level and the identities of the super-peers may drift over time; re-running the same decomposition on later snapshots would show whether the core is persistent or transient.","The same core-periphery lens could be applied to other privacy-oriented cryptocurrencies whose peer discovery was hardened, to check whether the observed hierarchy is a general consequence of anti-enumeration protocol updates rather than Monero-specific."],"forward_implications":["For Monero operations, the result implies that ordinary peer churn among low-degree nodes should not fragment the network; the 178-peer core can sustain connectivity as long as the core stays intact.","For attackers, the result implies that the most efficient disruption is not random node removal but targeted removal of the 14 super-peers or of core nodes with many edges to the periphery, since their removal sharply reduces core connectivity.","For protocol design, the dense cluster near degree 8 indicates that default connection counts shape the topology, so changing the auto-peering default would shift the core-periphery boundary.","For network science, Monero joins other real-world networks whose resilience comes from a small interconnected core, meaning that robustness and decentralization can coexist only if the core is itself distributed."],"supporting_citations":[{"why":"Supplies the Monero P2P network graph and the initial super-peer and connectivity findings that this paper extends.","marker":"[22]"},{"why":"Documents the pre-2019 peer-list disclosure and the protocol update that made earlier inference methods ineffective, motivating the need for a new network map.","marker":"[16]"},{"why":"Provides the k-core decomposition algorithm used to detect the core-periphery structure.","marker":"[19]"},{"why":"Defines core/periphery models that frame the hypothesis being tested.","marker":"[17]"},{"why":"Establishes core-periphery organization in complex networks as a measurable structural pattern.","marker":"[18]"},{"why":"Supplies the nearest-neighbour degree and assortativity definitions used in the degree-correlation analysis.","marker":"[20]"}],"fun_headline_variants":["Monero's P2P core: 178 peers, 14 super-peers","14 super-peers anchor Monero's P2P network","Monero P2P hierarchy: 14 hubs hold the core","Monero network's core-periphery: 178 nodes, 14 key hubs","Monero's disassortative core: 14 vital peers"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The central claim rests on the completeness and accuracy of the Monero network graph taken from the authors' prior work [22]; if that map is incomplete or biased, the k-core layers, the 178-peer core, and the 14 super-peers could all change.","fun_headline_variants_meta":{"raw":{"variants":["Monero's P2P core: 178 peers, 14 super-peers","14 super-peers anchor Monero's P2P network","Monero P2P hierarchy: 14 hubs hold the core","Monero network's core-periphery: 178 nodes, 14 key hubs","Monero's disassortative core: 14 vital peers"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000468,"raw_usage":{"total_tokens":2311,"prompt_tokens":904,"completion_tokens":1407,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":520,"completion_tokens_details":{"reasoning_tokens":1309}},"tokens_in":520,"tokens_out":1407,"duration_ms":11791,"temperature":1.0,"reasoning_tokens":1309,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T11:10:25.604053+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run k-core decomposition on a Monero P2P graph collected independently from multiple vantage points during the same period; if the largest $k$ with a sizable core is not 16, or if the 14 highest-degree super-peers do not appear as hubs, the paper's core-periphery claim is undercut. The most direct check is whether removing those 14 nodes from an independent full-network map reduces the largest connected component's size by the expected amount.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the Monero P2P network graph and the initial super-peer and connectivity findings that this paper extends."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Documents the pre-2019 peer-list disclosure and the protocol update that made earlier inference methods ineffective, motivating the need for a new network map."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines core/periphery models that frame the hypothesis being tested."},{"cited_title":"Holme, ”Core-periphery organization of complex networks,” Phys","cited_arxiv_id":null,"evidence_quote":"Establishes core-periphery organization in complex networks as a measurable structural pattern."},{"cited_title":"Barab ´asi, ”Network science,” *Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences*, vol","cited_arxiv_id":null,"evidence_quote":"Supplies the nearest-neighbour degree and assortativity definitions used in the degree-correlation analysis."}],"review_version":1}