VLDB 2026 Research / reviewers in the wild / expert
Antonio Faonio
dblp:138/9001
· DBLP profile ↗
26ranked-venue papers
15as first author
12since 2021 · last 2026
0000-0002-7152-6478ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 12 first-author · 11 since 2021Theory of computation · 7 · 4 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Updatable Private Set Intersection and Beyond: Efficient Constructions via Circuit PSI
Ferran Alborch Escobar, Tom Chauvier, Antonio Faonio, Alexandre Fontaine, Ferhat Karakoç, Alptekin Küpçü, Camille Malek, Melek Önen |
ACNS (1) | 3 |
| 2026 | Sumcheck-Based zkSNARKs are Non-malleable
Antonio Faonio, Luigi Russo 0001 |
CRYPTO (9) | 1 |
| 2025 | SNARKs for Virtual Machines Are Non-malleable
Matteo Campanelli, Antonio Faonio, Luigi Russo 0001 |
EUROCRYPT (4) | 2 |
| 2024 | Real-World Universal zkSNARKs are Non-MalleableabstractSimulation extractability is a strong security notion of zkSNARKs that guarantees that an attacker who produces a valid proof must know the corresponding witness, even if the attacker had prior access to proofs generated by other users. Notably, simulation extractability implies that proofs are non-malleable and is of fundamental importance for applications of zkSNARKs in distributed systems. In this work, we study sufficient and necessary conditions for constructing simulation-extractable universal zkSNARKs via the popular design approach based on compiling polynomial interactive oracle proofs (PIOP). Our main result is the first security proof that popular universal zkSNARKs, such as PLONK and Marlin, as deployed in the real world, are simulation-extractable. Our result fills a gap left from previous work (Faonio et al. TCC'23, and Kohlweiss et al. TCC'23) which could only prove the simulation extractability of the "textbook" versions of these schemes and does not capture their optimized variants, with all the popular optimization tricks in place, that are eventually implemented and deployed in software libraries. Antonio Faonio, Dario Fiore 0001, Luigi Russo 0001 |
CCS | 1 |
| 2023 | From Polynomial IOP and Commitments to Non-malleable zkSNARKs
Antonio Faonio, Dario Fiore 0001, Markulf Kohlweiss, Luigi Russo 0001, Michal Zajac 0001 |
TCC (3) | 1 |
| 2022 | Auditable Asymmetric Password Authenticated Public Key Establishment
Antonio Faonio, María Isabel González Vasco, Claudio Soriente, Hien Thi Thu Truong |
CANS | 1 |
| 2022 | Subversion-Resilient Enhanced Privacy ID
Antonio Faonio, Dario Fiore 0001, Luca Nizzardo, Claudio Soriente |
CT-RSA | 1 |
| 2022 | The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for FreeabstractWe show that the most common flavors of noisy leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to a small statistical simulation error and a slight loss in the leakage parameter. The latter holds true in particular for one of the most used noisy-leakage models, where the noisiness is measured using the conditional average min-entropy (Naor and Segev, CRYPTO’09 and SICOMP’12). Our reductions between noisy and bounded leakage are achieved in two steps. First, we put forward a new leakage model (dubbed the dense leakage model) and prove that dense leakage can be simulated in the information-theoretic setting using a single query of bounded leakage, up to small statistical distance. Second, we show that the most common noisy-leakage models fall within the class of dense leakage, with good parameters. Third, we prove lower bounds on the amount of bounded leakage required for simulation with sub-constant error, showing that our reductions are nearly optimal. In particular, our results imply that useful general simulation of noisy leakage based on statistical distance and mutual information is impossible. We also provide a complete picture of the relationships between different noisy-leakage models. Our result finds applications to leakage-resilient cryptography, where we are often able to lift security in the presence of bounded leakage to security in the presence of noisy leakage, both in the information-theoretic and in the computational setting. Remarkably, this lifting procedure makes only black-box use of the underlying schemes. Additionally, we show how to use lower bounds in communication complexity to prove that bounded-collusion protocols (Kumar, Meka, and Sahai, FOCS’19) for certain functions do not only require long transcripts, but also necessarily need to reveal enough information about the inputs. Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001 |
IEEE Trans. Inf. Theory | 2 |
| 2021 | Lunar: A Toolbox for More Efficient Universal and Updatable zkSNARKs and Commit-and-Prove Extensions
Matteo Campanelli, Antonio Faonio, Dario Fiore 0001, Anaïs Querol, Hadrián Rodríguez |
ASIACRYPT (3) | 2 |
| 2021 | Practical Continuously Non-malleable Randomness Encoders in the Random Oracle Model
Antonio Faonio |
CANS | 1 |
| 2021 | The Mother of All Leakages: How to Simulate Noisy Leakages via Bounded Leakage (Almost) for Free
Gianluca Brian, Antonio Faonio, Maciej Obremski, João Ribeiro 0002, Mark Simkin 0001, Maciej Skorski, Daniele Venturi 0001 |
EUROCRYPT (2) | 2 |
| 2021 | Continuously Non-malleable Secret Sharing: Joint Tampering, Plain Model and Capacity
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001 |
TCC (2) | 2 |
| 2020 | Improving the Efficiency of Re-randomizable and Replayable CCA Secure Public Key Encryption
Antonio Faonio, Dario Fiore 0001 |
ACNS (1) | 1 |
| 2020 | Non-malleable Secret Sharing Against Bounded Joint-Tampering Attacks in the Plain Model
Gianluca Brian, Antonio Faonio, Maciej Obremski, Mark Simkin 0001, Daniele Venturi 0001 |
CRYPTO (3) | 2 |
| 2019 | Rate-Optimizing Compilers for Continuously Non-malleable Codes
Sandro Coretti, Antonio Faonio, Daniele Venturi 0001 |
ACNS | 2 |
| 2019 | Structure-Preserving and Re-randomizable RCCA-Secure Public Key Encryption and Its Applications
Antonio Faonio, Dario Fiore 0001, Javier Herranz, Carla Ràfols |
ASIACRYPT (3) | 1 |
| 2019 | Non-malleable Secret Sharing in the Computational Setting: Adaptive Tampering, Noisy-Leakage Resilience, and Improved Rate
Antonio Faonio, Daniele Venturi 0001 |
CRYPTO (2) | 1 |
| 2019 | Efficient Fully-Leakage Resilient One-More Signature Schemes
Antonio Faonio |
CT-RSA | 1 |
| 2019 | Continuously Non-malleable Secret Sharing for General Access Structures
Gianluca Brian, Antonio Faonio, Daniele Venturi 0001 |
TCC (2) | 2 |
| 2019 | Continuously non-malleable codes with split-state refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
Theor. Comput. Sci. | 1 |
| 2018 | Continuously Non-malleable Codes with Split-State Refresh
Antonio Faonio, Jesper Buus Nielsen, Mark Simkin 0001, Daniele Venturi 0001 |
ACNS | 1 |
| 2017 | Fully leakage-resilient signatures revisited: Graceful degradation, noisy leakage, and construction in the bounded-retrieval model
Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
Theor. Comput. Sci. | 1 |
| 2016 | Efficient Public-Key Cryptography with Bounded Leakage and Tamper Resilience
Antonio Faonio, Daniele Venturi 0001 |
ASIACRYPT (1) | 1 |
| 2015 | Mind Your Coins: Fully Leakage-Resilient Signatures with Graceful DegradationabstractWe construct a new leakage-resilient signature scheme. Our scheme remains unforgeable in the noisy leakage model, where the only restriction on the leakage is that it does not decrease the min-entropy of the secret key by too much. The leakage information can depend on the entire state of the signer; this property is sometimes known as fully leakage resilience. An additional feature of our construction, is that it offers a graceful degradation of security in situations where standard existential unforgeability is impossible. This property was recently put forward by Nielsen et al. (PKC 2014) in the bounded leakage model, to deal with settings in which the secret key is much larger than the size of a signature. For security parameter $$\kappa $$ , our scheme tolerates leakage on the entire state of the signer until $$\omega (\log \kappa )$$ bits of min-entropy are left in the secret key, and is proven secure in the standard model. While we describe our scheme in terms of generic building blocks, we also explain how to instantiate it efficiently under fairly standard number-theoretic assumptions. Antonio Faonio, Jesper Buus Nielsen, Daniele Venturi 0001 |
ICALP (1) | 1 |
| 2015 | Leakage-Resilient Identification Schemes from Zero-Knowledge Proofs of Storage
Giuseppe Ateniese, Antonio Faonio, Seny Kamara |
IMACC | 2 |
| 2014 | Certified Bitcoins
Giuseppe Ateniese, Antonio Faonio, Bernardo Magri, Breno de Medeiros |
ACNS | 2 |