USENIX Security2023Top-tier venue
McFIL: Model Counting Functionality-Inherent Leakage
Maximilian Zinkus, Yinzhi Cao, Matthew D. Green
Abstract
Protecting the confidentiality of private data and using it for useful collaboration have long been at odds. Modern cryptography is bridging this gap through rapid growth in secure protocols such as multi-party computation, fully-homomorphic encryption, and zero-knowledge proofs. However, even with provable indistinguishability or zero-knowledgeness, confidentiality loss from leakage inherent to the functionality may partially or even completely compromise secret values without ever falsifying proofs of security. In this work, we describe McFIL, an algorithmic approach and accompanying software implementation which automatically quantifies intrinsic leakage for a given functionality. Extending and generalizing the Chosen-Ciphertext attack framework of Beck et al. with a practical heuristic, our approach not only quantifies but maximizes functionality-inherent leakage using Maximum Model Counting within a SAT solver. As a result, McFIL automatically derives approximately-optimal adversary inputs that, when used in secure protocols, maximize information leakage of private values.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7fa6fc6f-d1d3-4db6-aa4f-06180b4ad9efCited by top-tier papers3
- Auditable Algorithms for Approximate Model CountingKuldeep S. Meel, Supratik Chakraborty, S. AkshayAAAI 2024 · 2 citations
- PolySys: an Algebraic Leakage Attack EngineZachary Espiritu, Seny Kamara, Tarik Moataz, Andrew ParkUSENIX Security 2025
- Learning from Functionality Outputs: Private Join and Compute in the Real WorldFrancesca Falzon, Tianxin TangUSENIX Security 2025
Builds on3
- Bulletproofs: Short Proofs for Confidential Transactions and MoreBenedikt Bünz, Jonathan Bootle, Dan Boneh, Andrew Poelstra et al.S&P 2018 · 1,285 citations
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Automating the Development of Chosen Ciphertext AttacksGabrielle Beck, Maximilian Zinkus, Matthew GreenUSENIX Security 2020
Related papers
- Cheesecloth: Zero-Knowledge Proofs of Real World VulnerabilitiesSantiago Cuéllar, Bill Harris, James Parker, Stuart Pernsteiner et al.USENIX Security 2023
- PELTA - Shielding Multiparty-FHE against Malicious AdversariesSylvain Chatel, Christian Mouchet, Ali Utkan Sahin, Apostolos Pyrgelis et al.CCS 2023 · 12 citations
- Multi-Party Private Set Operations from Predicative Zero-SharingMinglang Dong, Yu Chen, Cong Zhang, Yujie Bai et al.CCS 2025
- Feedback-driven side-channel analysis for networked applicationsIsmet Burak Kadron, Nicolás Rosner, Tevfik BultanISSTA 2020 · 9 citations
- PoS4MPC: Automated Security Policy Synthesis for Secure Multi-party ComputationYuxin Fan, Fu Song, Taolue Chen, Liangfeng Zhang et al.CAV 2022 · 4 citations
