VLDB 2026 Research / reviewers in the wild / expert
Michael Rosenberg
dblp:122/5145
· DBLP profile ↗
11ranked-venue papers
4as first author
10since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 10 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Hybrid Obfuscated Key Exchange and KEMs
Felix Günther 0001, Michael Rosenberg, Douglas Stebila, Shannon Veitch |
CRYPTO (3) | 2 |
| 2025 | PAKE Combiners and Efficient Post-quantum Instantiations
Julia Hesse, Michael Rosenberg |
EUROCRYPT (2) | 2 |
| 2025 | zk-promises: Anonymous Moderation, Reputation, and Blocking from Anonymous Credentials with Callbacks
Maurice Shih, Michael Rosenberg, Hari Kailad, Ian Miers |
USENIX Security Symposium | 2 |
| 2025 | ZIPNet: Low-bandwidth anonymous broadcast from (dis)Trusted Execution EnvironmentsabstractAnonymous Broadcast Channels (ABCs) allow a group of clients to announce messages without revealing the exact author. Modern ABCs operate in a client-server model, where anonymity depends on some threshold (e.g, 1 of 2) of servers being honest. ABCs are an important application in their own right, e.g., for activism and whistleblowing. Recent work on ABCs (Riposte, Blinder) has focused on minimizing the bandwidth cost to clients and servers when supporting large broadcast channels for such applications. But, particularly for low bandwidth settings, they impose large costs on servers, make cover traffic costly, and make volunteer operators unlikely. In this paper, we describe the design, implementation, and evaluation of ZipNet, an anonymous broadcast channel that: 1) scales to hundreds of anytrust servers by minimizing the computational costs of each server, 2) substantially reduces the servers' bandwidth costs by outsourcing the aggregation of client messages to untrusted (for privacy) infrastructure, and 3) supports cover traffic that is both cheap for clients to produce and for servers to handle. Michael Rosenberg, Maurice Shih, Ian Miers, Fan Zhang 0022 |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Hekaton: Horizontally-Scalable zkSNARKs Via Proof AggregationabstractZero-knowledge Succinct Non-interactive ARguments of Knowledge (zkSNARKs) allow a prover to convince a verifier of the correct execution of a large computation in private and easily-verifiable manner.These properties make zkSNARKs a powerful tool for adding accountability, scalability, and privacy to numerous systems such as blockchains and verifiable key directories.Unfortunately, existing zkSNARKs are unable to scale to large computations due to time and space complexity requirements for the prover algorithm.As a result, they cannot handle real-world instances of the aforementioned applications.In this work, we introduce Hekaton, a zkSNARK that overcomes these barriers and can efficiently handle arbitrarily large computations.We construct Hekaton via a new "distribute-and-aggregate" framework that breaks up large computations into small chunks, proves these chunks in parallel in a distributed system, and then aggregates the resulting chunk proofs into a single succinct proof.Underlying this framework is a new technique for efficiently handling data that is shared between chunks that we believe could be of independent interest.We implement a distributed prover for Hekaton, and evaluate its performance on a compute cluster.Our experiments show that Hekaton achieves strong horizontal scalability (proving time decreases linearly as we increase the number of nodes in the cluster), and is able to prove large computations quickly: it can prove computations of size 2 35 gates in under an hour, which is much faster than prior work.Finally, we also apply Hekaton to two applications of realworld interest: proofs of batched insertion for a verifiable key directory and proving correctness of RAM computations.In both cases, Hekaton is able to scale to handle realistic workloads with better efficiency than prior work. Michael Rosenberg, Tushar Mopuri, Hossein Hafezi, Ian Miers, Pratyush Mishra 0001 |
CCS | 1 |
| 2024 | LATKE: A Framework for Constructing Identity-Binding PAKEs
Jonathan Katz, Michael Rosenberg |
CRYPTO (2) | 2 |
| 2023 | zk-creds: Flexible Anonymous Credentials from zkSNARKs and Existing Identity InfrastructureabstractFrequently, users on the web need to show that they are, for example, not a robot, old enough to access an age restricted video, or eligible to download an ebook from their local public library without being tracked. Anonymous credentials were developed to address these concerns. However, existing schemes do not handle the realities of deployment or the complexities of real-world identity. Instead, they implicitly make assumptions such as there being an issuing authority for anonymous credentials that, for real applications, requires the local department of motor vehicles to issue sophisticated cryptographic tokens to show users are over 18. In reality, there are multiple trust sources for a given identity attribute, their credentials have distinctively different formats, and many, if not all, issuers are unwilling to adopt new protocols.We present and build zk-creds, a protocol that uses general-purpose zero-knowledge proofs to 1) remove the need for credential issuers to hold signing keys: credentials can be issued to a bulletin board instantiated as a transparency log, Byzantine system, or even a blockchain; 2) convert existing identity documents into anonymous credentials without modifying documents or coordinating with their issuing authority; 3) allow for flexible, composable, and complex identity statements over multiple credentials. Concretely, identity assertions using zk-creds take less than 150ms in a real-world scenario of using a passport to anonymously access age-restricted videos. Michael Rosenberg, Jacob D. White, Christina Garman, Ian Miers |
SP | 1 |
| 2022 | SNARKBlock: Federated Anonymous Blocklisting from Hidden Common Input Aggregate ProofsabstractZero-knowledge blocklists allow cross-platform blocking of users but, counter-intuitively, do not link users identities inter- or intra-platform, or to the fact they were blocked. Unfortunately, existing approaches (Tsang et al. ’10) require that servers do work linear in the size of the blocklist for each verification of a non-membership proof.We design and implement SNARKBLOCK, a new protocol for zero-knowledge blocklisting with server-side verification that is logarithmic in the size of the blocklist. SNARKBLOCK is also the first approach to support ad-hoc, federated blocklisting: websites can mix and match their own blocklists from other blocklists and dynamically choose which identity providers they trust.Our core technical advance, of separate interest, is the HICIAP zero-knowledge proof system, which addresses a common problem in privacy-preserving protocols: using zero-knowledge proofs for repeated but unlinakble interactions. Rerandomzing a Groth16 proof achieves unlinkability without the need to recompute the proof for every interaction. But this technique does not apply to applications where each interaction includes multiple Groth16 proofs over a common hidden input (e.g., the user’s identity). Here, the best known approach is to commit to the hidden input and feed it to each proof, but this creates a persistent identifier, forcing recomputation. HICIAP resolves this problem by aggregating n Groth16 proofs into one $O(\log n) -$sized, $O(\log n) -$verification time proof which also shows that the input proofs share a hidden input. Because HICIAP is zero-knowledge, repeated shows of the same aggregate or an updated aggregate are unlinkable even though the underlying Groth16 proofs are never recomputed. Michael Rosenberg, Mary Maller, Ian Miers |
SP | 1 |
| 2021 | Boosting the Security of Blind Signature Schemes
Jonathan Katz, Julian Loss, Michael Rosenberg |
ASIACRYPT (4) | 3 |
| 2021 | Labeled PSI from Homomorphic Encryption with Reduced Computation and CommunicationabstractIt is known that fully homomorphic encryption (FHE) can be used to build efficient (labeled) Private Set Intersection protocols in the unbalanced setting, where one of the sets is much larger than the other~(Chen et al. (CCS'17, CCS'18)). In this paper we demonstrate multiple algorithmic improvements upon these works. In particular, our protocol has an asymptotically better computation cost, requiring only O(√|X| ) homomorphic multiplications, and communication complexity sublinear in the larger set size|X|. We demonstrate that our protocol is significantly better than that of Chen et al. (CCS'18) for many practical parameters, especially in terms of online communication cost. For example, when intersecting $228 and 2048 item sets, our protocol reduces the online computation time by more than 71% and communication by more than 63%. When intersecting 224 and 4096 item sets, our protocol reduces the online computation time by 27% and communication by 63%. Our comparison to other state-of-the-art unbalanced PSI protocols shows that our protocol has the best total communication complexity when |X| ≥ 224. For labeled PSI our protocol also outperforms Chen et al. (CCS'18). When intersecting 220 and 256 item sets, with the larger set having associated 288-byte labels, our protocol reduces the online computation time by more than 67% and communication by 34%. Finally, we demonstrate a modification that results in nearly constant communication cost in the larger set size |X|, but impractically high computation complexity on today's CPUs. For example, to intersect a 210-item set with sets of size 222, 224, or 226, our proof-of-concept implementation requires only 0.76 MB of online communication, which is more than a 24-fold improvement over Chen et al. (CCS'18). Kelong Cong, Radames Cruz Moreno, Mariana Gama, Wei Dai 0007, Ilia Iliashenko, Kim Laine, Michael Rosenberg |
CCS | 7 |
| 2012 | Creating intelligent environments to monitor and manipulate physical activity and sedentary behavior in public health and clinical settingsabstractIt is generally agreed, that an active lifestyle promotes healthy living across different age groups. It helps to combat obesity, reduce the risk of diabetes and heart disease, and support independent living as we age. However, it is difficult to quantify a direct correlation between physical activity and health outcomes. Given that obesity and lifestyle-related illnesses occur over years in contrast to days, weeks or months seeing the effects activity and sedentary behaviour has on individuals in the short term is not always possible. The ubiquitous nature of physical activity makes it extremely difficult to capture as people go about their lives. Consequently, there has been a great deal of debate on the frequency intensity time, and the type of physical activity required by different groups (pre-schoolers, children, adults, older adults, obese, infirm, disabled, and depressed). There is a need to provide effective mechanisms to monitor and manipulate physical activity and sedentary behaviour. Whilst several commercially available products exist to achieve this, compliance is poor. The challenge is to use new and novel technologies that are unobtrusive and natural adjunct to a persons day-to-day activity. This paper builds on existing ideas and explores how activity and sedentary behaviour information can be collected from different environments. We have developed an initial working prototype to evaluate the applicability of our approach. Gareth Stratton, Rebecca Murphy, Michael Rosenberg, Paul Fergus, Andrew Attwood |
ICC | 3 |