Beyond Anonymity Sets: A Security Model for Distributed Shuffling in Adversarial Environments
Adrian Cinal, Oliwer Sobolewski, Gabriel Wechta, Filip Zagórski
Abstract
Distributed shuffling is a core primitive underlying mix-nets, electronic voting, and, more recently, single secret leader election (SSLE) protocols for proof-of-stake blockchains. In these settings, a collection of resource-constrained parties jointly permutes a list of ciphertexts or commitments in order to conceal the correspondence between inputs and outputs. Existing security analyzes of such protocols typically rely on heuristic anonymity measures or implicitly assume honest behavior; therefore, they fail to capture statistical dependencies that arise when shuffling is partial and some participants are corrupted. In this work, we introduce a new security model for distributed shuffling that explicitly accounts for adversarial corruption and information leakage. Our model allows an adversary to corrupt a subset of shufflers and to track selected elements throughout the execution, and defines anonymity in terms of statistical distance from the uniform distribution over permutations. This yields a quantitative, composable notion of security that subsumes commonly used anonymity-set arguments and aligns with standard cryptographic indistinguishability frameworks. Using this model, we analyze Whisk, the shuffle-based SSLE mechanism proposed for Ethereum. We show that, under realistic protocol parameters and even in the absence of adaptive attacks, the induced distribution over permutations deviates significantly from the uniform distribution. Consequently, the resulting anonymity guaranties are substantially weaker than what is suggested by heuristic analyzes. We show how to modify the scheme parameters to meet the security requirements.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 542e87f4-26f4-47c2-8ff4-7c6560154c2dBuilds on2
- ThorPIR: Single Server PIR via Homomorphic Thorp ShufflesBen Fisch, Arthur Lazzaretti, Zeyu Liu, Charalampos PapamanthouCCS 2024 · 9 citations
- Deanonymizing Ethereum Validators: The P2P Network Has a Privacy IssueLioba Heimbach, Yann Vonlanthen, Juan Villacis, Lucianna Kiffer et al.USENIX Security 2025
Related papers
- Mobius: Enabling Byzantine-Resilient Single Secret Leader Election with Uniquely Verifiable StateHanyue Dou, Peifang Ni, Yingzi Gao, Jing XuNDSS 2026
- Shuffling Is Universal: Statistical Additive Randomized Encodings for All FunctionsNir Bitansky, Saroja Erabelli, Rachit Garg, Yuval IshaiSTOC 2026 · 2 citations
- FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State ChannelsRuonan Chen, Ye Dong, Yizhong Liu, Tingyu Fan et al.WWW 2025 · 6 citations
- Computationally Secure Aggregation and Private Information Retrieval in the Shuffle ModelAdrià Gascón, Yuval Ishai, Mahimna Kelkar, Baiyu Li et al.CCS 2024 · 4 citations
- Private Proof-of-Stake Blockchains using Differentially-Private Stake DistortionChenghong Wang, David Pujol, Kartik Nayak, Ashwin MachanavajjhalaUSENIX Security 2023
