Side-Channel Attacks on Shared Search Indexes
Liang Wang, Paul Grubbs, Jiahui Lu, Vincent Bindschaedler, David Cash, Thomas Ristenpart
Abstract
Full-text search systems, such as Elasticsearch and Apache Solr, enable document retrieval based on keyword queries. In many deployments these systems are multi-tenant, meaning distinct users' documents reside in, and their queries are answered by, one or more shared search indexes. Large deployments may use hundreds of indexes across which user documents are randomly assigned. The results of a search query are filtered to remove documents to which a client should not have access. We show the existence of exploitable side channels in modern multi-tenant search. The starting point for our attacks is a decade-old observation that the TF-IDF scores used to rank search results can potentially leak information about other users' documents. To the best of our knowledge, no attacks have been shown that exploit this side channel in practice, and constructing a working side channel requires overcoming numerous challenges in real deployments. We nevertheless develop a new attack, called STRESS (Search Text RElevance Score Side channel), and in so doing show how an attacker can map out the number of indexes used by a service, obtain placement of a document within each index, and then exploit co-tenancy with all other users to (1) discover the terms in other tenants' documents or (2) determine the number of documents (belonging to other tenants) that contain a term of interest. In controlled experiments, we demonstrate the attacks on popular services such as GitHub and Xen.do. We conclude with a discussion of countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ca9b2e0a-40a9-43cc-b5a2-73616309d65aCited by top-tier papers6
- Injection Attacks Against End-to-End Encrypted ApplicationsAndrés Fábrega, Carolina Ortega Pérez, Armin Namavari, Ben Nassi et al.S&P 2024 · 9 citations
- RLS Side Channels: Investigating Leakage of Row-Level Security Protected Data Through Query Execution TimeChen Dar, Moshik Hershcovitch, Adam MorrisonSIGMOD 2023 · 6 citations
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin OgierS&P 2026 · 1 citation
- Prefix Siphoning: Exploiting LSM-Tree Range Filters For Information DisclosureAdi Kaufman, Moshik Hershcovitch, Adam MorrisonUSENIX ATC 2023
- Metal: A Metadata-Hiding File-Sharing SystemWeikeng Chen, Raluca Ada PopaNDSS 2020
Related papers
- Plaintext Recovery Against Post-Filtering Access ControlZachary Espiritu, David CashUSENIX Security 2026
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 46 citations
- Searching Encrypted Data with Size-Locked IndexesMin Xu, Armin Namavari, David Cash, Thomas RistenpartUSENIX Security 2021 · 10 citations
- Ohm's Law in Data Centers: A Voltage Side Channel for Timing Power AttacksMohammad A. Islam, Shaolei RenCCS 2018 · 27 citations
- I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM ServingGuanlong Wu, Zheng Zhang, Yao Zhang, Weili Wang et al.NDSS 2025
