Your Keywords Know Each Other: Breaking SSE with <1% Leaked Documents
Mingyu Bian, Jiabei Wang, Dandan Xu, Guangyu Huang, Yongbin Zhou
摘要
Searchable symmetric encryption (SSE) schemes inevitably leak search, access, and volume patterns, which adversaries can exploit along with partial knowledge of the data to recover documents and queries. Prior passive attacks rely on document-keyword occurrence matching, but under realistic low leakage, many keywords induce identical patterns, forming large ambiguous groups that sharply limit recovery.
We observe this failure arises from missing relational signals among keywords. Keywords, however, exhibit stable semantic regularities across corpora even when direct co-occurrence is sparse, allowing external linguistic knowledge to augment observed leakage. Based on this insight, we present Whisper, a staged co-occurrence augmented query recovery framework that weaves LLM-synthesized corpora with pre-trained embeddings to densify co-occurrence matrices and disambiguate otherwise indistinguishable candidates.
We evaluate Whisper on six diverse real-world datasets, including three collected in late 2025 to test generalization beyond LLM training cutoffs. At 0.1% leakage, previously considered safe, Whisper boosts correct query recovery from 17-27% under current SOTA to 36-49% across all datasets, a 2-2.5× improvement. Even at 1% leakage, Whisper approaches near-complete recovery, exceeding 80% on most datasets and peaking at 95%, while remaining effective against padding and volume hiding defenses, exposing a previously underestimated vulnerability in SSE.
Unique Match Found?
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah 等NeurIPS 2020 · 被引用 64,255 次
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt 等S&P 2022 · 被引用 725 次
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 被引用 152 次
- The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable EncryptionDavid Pouliot, Charles V. WrightCCS 2016 · 被引用 132 次
相关 Paper
- Query Recovery from Easy to Hard: Jigsaw Attack against SSEHao Nie, Wei Wang, Peng Xu, Xianglong Zhang 等USENIX Security 2024 · 被引用 13 次
- A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed DocumentsMarc Damie, Florian Hahn, Andreas PeterUSENIX Security 2021 · 被引用 46 次
- LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known DatasetJianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan 等CCS 2021 · 被引用 32 次
- Rethinking Searchable Symmetric EncryptionZichen Gui, Kenneth G. Paterson, Sikhar PatranabisS&P 2023
- ALERT: Machine Learning-Enhanced Risk Estimation for Databases Supporting Encrypted QueriesLongxiang Wang, Lei Xu, Yufei Chen, Ying Zou 等USENIX Security 2025
