Algorithm Substitution Attacks from a Steganographic Perspective
Sebastian Berndt, Maciej Liskiewicz
Abstract
The goal of an algorithm substitution attack (ASA), also called a subversion attack (SA), is to replace an honest implementation of a cryptographic tool by a subverted one which allows to leak private information while generating output indistinguishable from the honest output. Bellare, Paterson, and Rogaway provided at CRYPTO '14 a formal security model to capture this kind of attacks and constructed practically implementable ASAs against a large class of symmetric encryption schemes. At CCS'15, Ateniese, Magri, and Venturi extended this model to allow the attackers to work in a fully-adaptive and continuous fashion and proposed subversion attacks against digital signature schemes. Both papers also showed the impossibility of ASAs in cases where the cryptographic tools are deterministic. Also at CCS'15, Bellare, Jaeger, and Kane strengthened the original model and proposed a universal ASA against sufficiently random encryption schemes. In this paper we analyze ASAs from the perspective of steganography - the well known concept of hiding the presence of secret messages in legal communications. While a close connection between ASAs and steganography is known, this lacks a rigorous treatment. We consider the common computational model for secret-key steganography and prove that successful ASAs correspond to secure stegosystems on certain channels and vice versa. This formal proof allows us to conclude that ASAs are stegosystems and to "rediscover" several results concerning ASAs known in the steganographic literature.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1bec0863-fd6f-4870-8565-dfb99ebcaeadCited by top-tier papers3
- Wink: Deniable Secure MessagingAnrin Chakraborti, Darius Suciu, Radu SionUSENIX Security 2023
- Provably Robust and Secure Steganography in Asymmetric Resource ScenarioMinhao Bai, Jinshuai Yang, Kaiyi Pang, Xin Xu et al.S&P 2025
- A Real-World Law-Enforcement Hack: The Case of EncrochatMartin R. Albrecht, Sunoo Park, Michael A. Specter, Douglas StebilaCRYPTO 2026
Related papers
- Look Ahead! Practical CCA-Secure Steganography: Cover-Source Switching Meets Lattice Gaussian SamplingRussell W. F. Lai, Ivy K. Y. Woo, Hoover H. F. YinEUROCRYPT 2026
- Generic Semantic Security against a Kleptographic AdversaryAlexander Russell, Qiang Tang, Moti Yung, Hong-Sheng ZhouCCS 2017 · 71 citations
- SpecStega: Provably Secure Linguistic Steganography Based on Speculative Sampling in Asymmetric Resource ScenariosJun Jiang, Kejiang Chen, Yuang Qi, Jiawei Zhao et al.CCS 2026
- Image Disentanglement Autoencoder for Steganography without EmbeddingXiyao Liu, Ziping Ma, Junxing Ma, Jian Zhang et al.CVPR 2022 · 85 citations
- Dig a Hole and Fill in Sand: Adversary and Hiding Decoupled SteganographyWeixuan Tang, Haoyu Yang, Yuan Rao, Zhili Zhou et al.ACM MM 2024 · 5 citations
