IronDict: Transparent Dictionaries from Polynomial Commitments
We present IronDict, a transparent dictionary construction based on polynomial commitment schemes. Transparent dictionaries enable an untrusted server to maintain a mutable dictionary and provably serve clients lookup queries. A major open challenge is supporting…
Lattice-Based Accumulator and Application to Anonymous Credential Revocation
An accumulator is a cryptographic system for compactly representing a set of elements such that every element in the set has a short membership witness. A dynamic accumulator, furthermore, allows elements to be added to…
Efficient Secure Aggregation for Federated Learning
Federated Learning (FL) trains a global model by having each selected device push only its model update to a central server, keeping raw data local. However, those updates can still leak sensitive information unless the server…
Evaluating Privacy Policies under Modern Privacy Laws At Scale: An LLM-Based Automated Approach
Website privacy policies detail an online service’s information practices, including how they handle user data and rights. For many sites, these disclosures are now necessitated by a growing set of privacy regulations, such as GDPR…
Paraphrase Project
The Paraphrase Project addresses a critical and emerging risk: as generative AI and synthetic biology advance, there is a growing possibility that open-source AI tools could be misused to design biological toxins that evade current…
Detecting Compromise of Passkey Storage on the Cloud
FIDO synced passkeys address account recovery challenges by enabling users to back up their FIDO2 private signing keys to the cloud storage of passkey management services (PMS). However, it introduces a serious security risk —…
Encrypted Access Logging for Online Accounts: Device Attributions without Device Tracking
Despite improvements in authentication mechanisms, compromise of online accounts remains prevalent. Therefore, technologies to detect compromise retroactively are also necessary. Service providers try to help users diagnose the security status of their accounts via account…