Mixnets on a Tightrope: Quantifying the Leakage of Mix Networks Using a Provably Optimal Heuristic Adversary
Sebastian Meiser, Debajyoti Das, Moritz Kirschte, Esfandiar Mohammadi, Aniket Kate
Abstract
Mixnets are widely believed to hide communication metadata of individuals. We show that there are various pitfalls when designing mixnet topologies and routing strategies, in particular when choosing mixnets with low delays. We introduce a tool that empirically evaluates such a leakage in mixnets and show that this tool precisely estimates this leakage for recipient anonymity, up to an error introduced by sampling. First, we introduce a novel generic attack strategy that we even prove to be optimal for breaking recipient anonymity. In contrast to prior work, our attack strategy incorporates the severity of each observation's leakage, via its so-called privacy loss. Second, our tool provides a lower bound on an attacker's advantage against recipient anonymity by sampling a large set of observations; if a significant number of observations with high privacy loss is observed, the tool outputs a lower bound on the leakage by providing a lower bound on the mass of the tail of the distribution of privacy losses. From the literature, we study the topology and routing strategies of the Karaoke and Atom protocols, provide bounds on their leakage and recommend design choices based on the analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c322c1d8-edbc-43cc-b66f-481a38dc6bc3Builds on8
- The Loopix Anonymity SystemAnia M. Piotrowska, Jamie Hayes, Tariq Elahi, Sebastian Meiser et al.USENIX Security 2017 · 214 citations
- Anonymity Trilemma: Strong Anonymity, Low Bandwidth Overhead, Low Latency - Choose TwoDebajyoti Das, Sebastian Meiser, Esfandiar Mohammadi, Aniket KateS&P 2018 · 99 citations
- Express: Lowering the Cost of Metadata-hiding Communication with Cryptographic PrivacySaba Eskandarian, Henry Corrigan-Gibbs, Matei Zaharia, Dan BonehUSENIX Security 2021 · 98 citations
- XRD: Scalable Messaging System with Cryptographic PrivacyAlbert Kwon, David Lu, Srinivas DevadasNSDI 2020 · 87 citations
- DP-Finder: Finding Differential Privacy Violations by Sampling and OptimizationBenjamin Bichsel, Timon Gehr, Dana Drachsler-Cohen, Petar Tsankov et al.CCS 2018 · 82 citations
Related papers
- OptiMix: Scalable and Distributed Approaches for Latency Optimization in Modern MixnetsMahdi RahimiNDSS 2026 · 3 citations
- LARMix: Latency-Aware Routing in Mix NetworksMahdi Rahimi, Piyush Kumar Sharma, Claudia DíazNDSS 2024
- LAMP: Lightweight Approaches for Latency Minimization in Mixnets with Practical Deployment ConsiderationsMahdi Rahimi, Piyush Kumar Sharma, Claudia DíazNDSS 2025
- Rollercoaster: An Efficient Group-Multicast Scheme for Mix NetworksDaniel Hugenroth, Martin Kleppmann, Alastair R. BeresfordUSENIX Security 2021 · 5 citations
- No Right to Remain Silent: Isolating Malicious MixesHemi Leibowitz, Ania M. Piotrowska, George Danezis, Amir HerzbergUSENIX Security 2019 · 23 citations
