Can I Get More? An Incremental Inference Attack on Encrypted SQL
Xiaoqian Sun, Ruiqi He, Yang Zhang, Siyi Lv, Guiyun Qin, Fangzhou Yi, Zheli Liu, Xiaofeng Chen
Abstract
Effective leakage-abuse attacks on encrypted SQL query schemes primarily focus on column equality leakage or cross-column equality leakage. However, these approaches fail to effectively leverage the joint distribution information among correlated columns that are often revealed in multi-attribute queries. This limitation leads to an underestimation of the actual security risks in real-world deployments. This paper presents Anchor-Joint Attack, an incremental inference framework that more effectively exploits joint distribution leakage to achieve superior plaintext recovery. We design an anchor-based incremental strategy that first extracts a set of high-confidence ciphertext plaintext mappings from column equality leakage and treats them as anchors. Guided by these anchors, the framework then incrementally incorporates joint distribution information to expand the recovered mappings in an iterative manner. Moreover, we formulate the recovery procedure as an optimal transport problem based on the Earth Mover's Distance (EMD), which naturally accommodates partial domain overlap and supports iterative error detection and correction. This design avoids explicitly constructing the full joint distribution in a single step, thereby maintaining high recovery rates, robustness, and efficiency even under incomplete leakage conditions. Extensive experiments on real-world data demonstrate that our attack outperforms existing state-of-the-art methods. In the encrypted boolean query scenario, our method achieves an optimal value recovery rate of 71.68% and an optimal row recovery rate of 95.45%, surpassing the Jigsaw attack (Nie et al., USENIX'24) by approximately and , respectively. In the encrypted join query scenario, our method attains an optimal value recovery rate of 97.4%, exceeding the attacks proposed by Hoover et al. (USENIX'24) by about , while improving runtime by approximately .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Leakage-Abuse Attacks Against Structured Encryption for SQLAlexander Hoover, Ruth Ng, Daren Khu, Yao'an Li et al.USENIX Security 2024 · 3 citations
- Query Recovery from Easy to Hard: Jigsaw Attack against SSEHao Nie, Wei Wang, Peng Xu, Xianglong Zhang et al.USENIX Security 2024 · 13 citations
- The State of the Uniform: Attacks on Encrypted Databases Beyond the Uniform Query DistributionEvgenios M. Kornaropoulos, Charalampos Papamanthou, Roberto TamassiaS&P 2020 · 104 citations
- LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetJianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan et al.CCS 2021 · 32 citations
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 46 citations
