Weave: Efficient and Expressive Oblivious Analytics at Scale
Mahdi Soleimani, Grace Jia, Anurag Khandelwal
Abstract
Many distributed analytics applications offloaded to the cloud operate on sensitive data. Even when the computations for such analytics workloads are confined to trusted hardware enclaves, and all stored data and network communications are encrypted, several studies have shown that they are still vulnerable to access pattern attacks. Prior efforts to prevent access pattern leakage often incur network and compute overheads that are logarithmic in dataset size while also limiting the functionality of supported analytics jobs.
We present Weave, an efficient, expressive, and secure analytics platform that scales to large datasets. Weave employs a combination of noise injection and hardware memory isolation to reduce the network and compute overheads for oblivious analytics to a constant factor. Weave also employs several optimizations and extensions that exploit dataset and workload-specific properties to ensure performance at scale without compromising functionality. Weave reduces the endto-end execution time for a wide range of analytics jobs on large real-world datasets by 4-10× compared to prior stateof-the-art while providing strong obliviousness guarantees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d4486449-8ccc-4aca-94cf-59463f2f693eCited by top-tier papers2
- Osprey: Transparent and Efficient Virtual Memory for Secure ComputationYicheng Liu, Alice Yeh, Harry Xu, Raluca Ada Popa et al.OSDI 2026
- Found in Translation: A Generative Language Modeling Approach to Memory Access Pattern AttacksGrace Jia, Alex Wong, Anurag KhandelwalUSENIX Security 2025
Builds on11
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
- TRUSTORE: Side-Channel Resistant Storage for SGX using Intel Hybrid CPU-FPGAHyunyoung Oh, Adil Ahmad, Seonghyun Park, Byoungyoung Lee et al.CCS 2020 · 28 citations
Related papers
- SODA: A Set of Fast Oblivious Algorithms in Distributed Secure Data AnalyticsXiang Li, Nuozhou Sun, Yunqian Luo, Mingyu GaoVLDB 2023 · 2 citations
- Jodes: Efficient Oblivious Join in the Distributed SettingYilei Wang, Xiangdong Zeng, Sheng Wang, Feifei LiVLDB 2025 · 1 citation
- Oblivious coopetitive analytics using hardware enclavesAnkur Dave, Chester Leung, Raluca Ada Popa, Joseph E. Gonzalez et al.EuroSys 2020 · 26 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
- SGX-BigMatrix: A Practical Encrypted Data Analytic Framework With Trusted ProcessorsFahad Shaon, Murat Kantarcioglu, Zhiqiang Lin, Latifur KhanCCS 2017 · 83 citations
