Jakob Svennevik Notland

dblp:259/0937 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0001-7406-7038ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 SoK: cross-chain bridging architectural design flaws and mitigations
abstract
Cross-chain bridges are solutions that enable interoperability between heterogeneous blockchains. In contrast to the underlying blockchains, the bridges often provide inferior security guarantees and have been targets of hacks, causing damage in the range of 1.5 to 2 billion USD in 2022. The current state of bridge architectures is that they are ambiguous, and the relation between overarching architectures, underlying components, and exploits is shallow. We address this gap through a multivocal literature review covering 64 different bridges, including 31 exploits and four known bugs over three years (2021-2023). Our analysis identifies 13 architectural components of blockchain bridges. We link the components to eight types of vulnerabilities, also called design flaws. Furthermore, we identified prevention measures and proposed 11 impact reduction measures based on existing and possible countermeasures to address the imminent exploitation of design flaws. The results present an overview of the state of the art in bridge security, future research directions, and guidelines for designing and implementing secure cross-chain bridge architectures.
Jakob Svennevik Notland, Jingyue Li, Mariusz Nowostawski, Peter Halland Haro
Blockchain Res. Appl.1
2025 An empirical study on deployment in cross-chain decentralised autonomous organisations
abstract
Decentralised Autonomous Organisations (DAOs) are self-governing democratic entities that operate and provide services via smart contracts on behalf of their users. Certain DAOs, particularly Decentralised Exchanges (DEXs), have recently expanded their market reach through cross-chain deployment and integration, giving rise to Cross-chain DAOs (XDAOs). These XDAOs face unique governance, deployment, and operations challenges, introducing added complexity and risks compared to traditional single-chain DAOs. While existing research has focused primarily on single-chain DAOs, we observe a shift in practice with DAOs to favour cross-chain deployments. The three largest protocols, Uniswap, Curve, and PancakeSwap, which together represent over half of the total value locked in DEXs, have been deployed across 22, 17, and 9 chains, respectively. This creates a research gap that our study addresses. In this study, we review 48 cross-chain deployments and numerous XDAO interactions, using data primarily from their respective discussion forums. Through thematic and root cause analysis, we identify eight requirements, deviations between DEXs, seven lessons learned for cross-chain deployment, and a framework to generalise the governance and deployment processes in XDAOs. As a result, we provide an improved classification of XDAO governance, highlighting limitations and future directions for cross-chain expansion. • A comprehensive study on cross-chain decentralised protocols and XDAO expansion. • Exploring and identifying diverse requirements of cross-chain deployments. • Exploring and inspecting various patterns of inconsistent enforcement. • Summary of lessons learned from the expansion of leading XDAOs. • Highlighting future research on XDAOs and cross-chain decentralised deployments.
Jakob Svennevik Notland, Jingyue Li, Mariusz Nowostawski
Blockchain Res. Appl.1
2025 An Empirical Study on Governance in Bitcoin's Consensus Evolution
abstract
Consensus rule changes in public permissionless blockchains are challenging. Changes can be contentious, and getting all participants to agree could be tedious. Notably, Bitcoin has seen centralisation tendencies in mining and development. However, how these tendencies influence governance processes of consensus evolution has received minimal attention. We explore how the evolution of blockchain systems and the governance of consensus intertwine from socio-technical aspects. Our study analyses the governmental structures in blockchain by looking into Bitcoin. We investigate consensus change processes through grounded theory, comprising quantitative and qualitative data from 34 consensus forks in two different blockchains, Bitcoin Core and Bitcoin Cash. We explore how decentralisation and governance unfold in practice. In contrast to existing studies, we revealed that centralisation tendencies among miners and developers have no direct control over consensus rules in a blockchain. Furthermore, centralisation tendencies do not affect decision-making for consensus evolution governance in the same way as they facilitate consensus attacks, such as 51% attacks. We also discovered that consensus governance is constrained by the technicalities of change and deployment techniques. Consequently, even though miners have the authority to make consensus changes and propose new blocks, they are restricted by deployment techniques and dependence on user adoption.
Jakob Svennevik Notland, Mariusz Nowostawski, Jingyue Li
ACM Trans. Softw. Eng. Methodol.1
2023 Evaluating the Impact of ChatGPT on Exercises of a Software Security Course
abstract
Along with the development of large language models (LLMs), e.g., ChatGPT, many existing approaches and tools for software security are changing. It is, therefore, essential to understand how security-aware these models are and how these models impact software security practices and education. In exercises of a software security course at our university, we ask students to identify and fix vulnerabilities we insert in a web application using state-of-the-art tools. After ChatGPT, especially the GPT-4 version of the model, we want to know how the students can possibly use ChatGPT to complete the exercise tasks. We input the vulnerable code to ChatGPT and measure its accuracy in vulnerability identification and fixing. In addition, we investigated whether ChatGPT can provide a proper source of information to support its outputs. Results show that ChatGPT can identify 20 of the 28 vulnerabilities we inserted in the web application in a white-box setting, reported three false positives, and found four extra vulnerabilities beyond the ones we inserted. ChatGPT makes nine satisfactory penetration testing and fixing recommendations for the ten vulnerabilities we want students to fix and can often point to related sources of information.
Jingyue Li, Per Håkon Meland, Jakob Svennevik Notland, André Storhaug, Jostein Hjortland Tysse
ESEM3
2023 Runtime Evolution of Bitcoin's Consensus Rules
abstract
The runtime evolution of a system concerns the ability to make changes during runtime without disrupting the service. Blockchain systems need to provide continuous service and integrity. Similar challenges have been observed in centrally controlled distributed systems or mobile applications that handle runtime evolution, mainly by supporting compatible changes or running different versions concurrently. However, these solutions are not applicable in the case of blockchains, and thus, new solutions are required. This study investigates Bitcoin consensus evolution by analysing over a decade of data from Bitcoin's development channels using Strauss’ grounded theory approach and root cause analysis. The results show nine deployment features which form nine deployment techniques and ten lessons learned. Our results illustrate how different deployment techniques fit different contexts and pose different levels of consensus failure risks. Furthermore, we provide guidelines for risk minimisation during consensus rule deployment for blockchain in general and Bitcoin in particular.
Jakob Svennevik Notland, Mariusz Nowostawski, Jingyue Li
IEEE Trans. Software Eng.1
2020 The Minimum Hybrid Contract (MHC): Combining Legal and Blockchain Smart Contracts
abstract
Corruption is a major global financial problem with billions of dollars rendered lost or unaccountable annually. Corruption through contract fraud is often conducted by withholding and/or altering financial information. When such scandals are investigated by authorities, financial and legal documents are usually altered to conceal the paper trail.
Jørgen Svennevik Notland, Jakob Svennevik Notland, Donn Morrison
EASE2