USENIX Security2026Top-tier venue
Your Keywords Know Each Other: Breaking SSE with <1% Leaked Documents
Mingyu Bian, Jiabei Wang, Dandan Xu, Guangyu Huang, Yongbin Zhou
Abstract
Searchable symmetric encryption (SSE) schemes inevitably leak search, access, and volume patterns, which adversaries can exploit along with partial knowledge of the data to recover documents and queries. Prior passive attacks rely on document-keyword occurrence matching, but under realistic low leakage, many keywords induce identical patterns, forming large ambiguous groups that sharply limit recovery.
We observe this failure arises from missing relational signals among keywords. Keywords, however, exhibit stable semantic regularities across corpora even when direct co-occurrence is sparse, allowing external linguistic knowledge to augment observed leakage. Based on this insight, we present Whisper, a staged co-occurrence augmented query recovery framework that weaves LLM-synthesized corpora with pre-trained embeddings to densify co-occurrence matrices and disambiguate otherwise indistinguishable candidates.
We evaluate Whisper on six diverse real-world datasets, including three collected in late 2025 to test generalization beyond LLM training cutoffs. At 0.1% leakage, previously considered safe, Whisper boosts correct query recovery from 17-27% under current SOTA to 36-49% across all datasets, a 2-2.5× improvement. Even at 1% leakage, Whisper approaches near-complete recovery, exceeding 80% on most datasets and peaking at 95%, while remaining effective against padding and volume hiding defenses, exposing a previously underestimated vulnerability in SSE.
Unique Match Found?
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on15
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt et al.S&P 2022 · 725 citations
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 152 citations
- The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable EncryptionDavid Pouliot, Charles V. WrightCCS 2016 · 132 citations
Related papers
- Query Recovery from Easy to Hard: Jigsaw Attack against SSEHao Nie, Wei Wang, Peng Xu, Xianglong Zhang et al.USENIX Security 2024 · 13 citations
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 46 citations
- LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetJianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan et al.CCS 2021 · 32 citations
- Rethinking Searchable Symmetric EncryptionZichen Gui, Kenneth G. Paterson, Sikhar PatranabisS&P 2023
- ALERT: Machine Learning-Enhanced Risk Estimation for Databases Supporting Encrypted QueriesLongxiang Wang, Lei Xu, Yufei Chen, Ying Zou et al.USENIX Security 2025
