VLDB 2026 Research / reviewers in the wild / expert
Michele Ciampi
dblp:167/2878
· DBLP profile ↗
36ranked-venue papers
27as first author
28since 2021 · last 2026
0000-0001-5062-0388ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 27 first-author · 27 since 2021Theory of computation · 9 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Crypto-Asset Collateralised Loans in Open Finance via Robust Fully Homomorphic Encryption
Lorenzo Martinico, Raffaella Calabrese, Tzameret Rubin, Michele Ciampi |
ACNS (2) | 4 |
| 2026 | PrivaDE: Privacy-preserving Data Evaluation for Blockchain-based Data MarketplacesabstractEvaluating the usefulness of data before purchase is essential when obtaining data for high-quality machine learning models, yet both model builders and data providers are often unwilling to reveal their proprietary assets. Wan Ki Wong, Sahel Torkamani, Michele Ciampi, Rik Sarkar |
AsiaCCS | 3 |
| 2026 | On the Adaptive Security of Key-Unique Threshold Signatures
Michele Ciampi, Elizabeth C. Crites, Chelsea Komlo, Mary Maller |
CRYPTO (2) | 1 |
| 2026 | Round-Optimal GUC-Secure Blind Signatures From Minimal Computational and Setup Assumptions - From Minimal Computational and Setup Assumptions
Michele Ciampi, Pierpaolo Della Monica, Ivan Visconti |
CRYPTO (7) | 1 |
| 2026 | Robust Non-interactive Zero-Knowledge Combiners
Michele Ciampi, Lorenzo Magliocco, Daniele Venturi 0001, Yu Xia 0008 |
EUROCRYPT (7) | 1 |
| 2025 | Delayed-Input Multi-party ComputationabstractIn this work, we consider the setting where the process of securely evaluating a multi-party functionality is divided into two phases: offline (or preprocessing ) and online . The offline phase is independent of the parties’ inputs, whereas the online phase does require the knowledge of the inputs. We consider the problem of minimizing the round of communication required in the online phase and propose a round preserving compiler that can turn a big class of multi-party computation (MPC) protocols into protocols in which only the last two rounds are input-dependent. Our compiler can be applied to a big class of MPC protocols, and in particular to all existing round-optimal MPC protocols. All our results assume no setup and are proven in the dishonest majority setting with black-box simulation. As part of our contribution, we propose a new definition we call Multi-Party Computation with Adaptive-Input Selection , which allows the distinguisher to craft the inputs the honest parties should use during the online phase, adaptively on the offline phase. This new definition is needed to argue that not only are the messages of the offline phase input-independent but also that security holds even in the stronger (and realistic) adversarial setting where the inputs may depend on some of the offline-phase protocol messages. We argue that this is the definition that any protocol should satisfy to be securely used while preprocessing part of the rounds. We are the first to study this definition in a setting where there is no setup, and the majority of the parties can be corrupted. Prior definitions have been presented in the Universal Composable framework, which is unfortunately not well suited for our setting (i.e., no setup and dishonest majority). As a corollary, we obtain the first four-round (which is optimal) MPC protocol, where the first two rounds can be preprocessed, and its security holds against adaptive-input selection. Michele Ciampi, Jure Sternad, Yu Xia 0008 |
ACNS (1) | 1 |
| 2025 | Two-Tier Black-Box Blockchains and Application to Instant Layer-1 PaymentsabstractCommon blockchain protocols are monolithic, i.e., their security relies on a single assumption, e.g., honest majority of hashing power (Bitcoin) or stake (Cardano, Algorand, Ethereum). In contrast, so-called optimistic approaches (Thunderella, Meshcash) rely on a combination of assumptions to achieve faster transaction liveness. We revisit, redesign, and augment the optimistic paradigm to a tiered approach. Our design assumes a primary (Tier 1) and a secondary (Tier 2, also referred to as fallback) blockchain, and achieves full security also in a tiered fashion: If the assumption underpinning the primary chain holds, then we guarantee safety, liveness and censorship resistance, irrespectively of the status of the fallback chain. And even if the primary assumption fails, all security properties are still satisfied (albeit with a temporary slow down) provided the fallback assumption holds. To our knowledge, no existing optimistic or tiered approach preserves both safety and liveness when any one of its underlying blockchain (assumptions) fails. The above is achieved by a new detection-and-recovery mechanism that links the two blockchains, so that any violation of safety, liveness, or censorship resistance on the (faster) primary blockchain is temporary - it is swiftly detected and recovered on the secondary chain - and thus cannot result in a persistent fork or halt of the blockchain ledger. We instantiate the above paradigm using a primary chain based on proof of reputation (PoR) and a fallback chain based on proof of stake (PoS). Our construction uses the PoR and PoS blockchains in a mostly black-box manner - where rather than assuming a concrete construction we distil abstract properties on the two blockchains that are sufficient for applying our tiered methodology. In fact, choosing reputation as the resource of the primary chain opens the door to an incentive mechanism - which we devise and analyze - that tokenizes reputation in order to deter cheating and boost participation (on both the primary/PoR and the fallback/PoS blockchain). As we demonstrate, such tokenization in combination with interpreting reputation as a built-in system-wide credit score, allows for embedding in our two-tiered methodology a novel mechanism which provides collateral-free, multi-use payment-channel-like functionality where payments can be instantly confirmed. Michele Ciampi, Yun Lu 0001, Rafail Ostrovsky, Vassilis Zikas |
AFT | 1 |
| 2025 | Universally Composable Transaction Order Fairness: Refined Definitions and Adaptive Security
Michele Ciampi, Aggelos Kiayias, Yu Shen 0002 |
ASIACRYPT (2) | 1 |
| 2025 | Broadcast-Optimal Secure Computation from Black-Box Oblivious Transfer
Michele Ciampi, Divya Ravi 0001, Luisa Siniscalchi, Yu Xia 0008 |
ASIACRYPT (5) | 1 |
| 2025 | Universally Composable SNARKs with Transparent Setup without Programmable Random Oracle
Christian Badertscher, Matteo Campanelli, Michele Ciampi, Luigi Russo 0001, Luisa Siniscalchi |
CRYPTO (7) | 3 |
| 2025 | Universal Adaptor Signatures from Blackbox Multi-party Computation
Michele Ciampi, Ioannis Tzannetos, Vassilis Zikas |
CT-RSA | 1 |
| 2025 | Black-Box Constant-Round Secure 2PC with Succinct Communication
Michele Ciampi, Ankit Kumar Misra, Rafail Ostrovsky, Akash Shah |
EUROCRYPT (5) | 1 |
| 2025 | Round-Optimal Black-Box Multiparty Computation from Polynomial-Time Assumptions
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Hendrik Waldner |
EUROCRYPT (5) | 1 |
| 2025 | Information-Theoretic Broadcast-Optimal MPC
Michele Ciampi, Ivan Damgård, Divya Ravi 0001, Luisa Siniscalchi, Sophia Yakoubov |
TCC (1) | 1 |
| 2024 | Black-Box (and Fast) Non-malleable Zero Knowledge
Vincenzo Botta, Michele Ciampi, Emmanuela Orsini, Luisa Siniscalchi, Ivan Visconti |
CRYPTO (9) | 2 |
| 2024 | Universal Composable Transaction Serialization with Order Fairness
Michele Ciampi, Aggelos Kiayias, Yu Shen 0002 |
CRYPTO (2) | 1 |
| 2023 | Multi-Theorem Fiat-Shamir Transform from Correlation-Intractable Hash Functions
Michele Ciampi, Yu Xia 0008 |
ACNS | 1 |
| 2023 | List Oblivious Transfer and Applications to Round-Optimal Black-Box Multiparty Coin Tossing
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Hendrik Waldner |
CRYPTO (1) | 1 |
| 2023 | Agile Cryptography: A Universally Composable Approach
Christian Badertscher, Michele Ciampi, Aggelos Kiayias |
TCC (4) | 2 |
| 2023 | Broadcast-Optimal Four-Round MPC in the Plain Model
Michele Ciampi, Ivan Damgård, Divya Ravi 0001, Luisa Siniscalchi, Yu Xia 0008, Sophia Yakoubov |
TCC (2) | 1 |
| 2023 | Etherless Ethereum tokens: Simulating native tokens in EthereumabstractStandardized Ethereum tokens, e.g., ERC-20 tokens, have become the norm in fundraising (through ICOs) and kicking off blockchain-based DeFi applications. However, they require the user's wallet to hold both tokens and ether to pay the gas fee for making a transaction. This makes for a cumbersome user experience, and complicates, from the user perspective, the process of transitioning to a different smart-contract enabled blockchain, or to a newly launched blockchain. We formalize, instantiate, and analyze in a composable manner a system that we call Etherless Ethereum Tokens (in short, EETs), which allows the token users to transact in a closed-economy manner, i.e., having only tokens on their wallet and paying any transaction fees in tokens rather than Ether/Gas. In the process, we devise a methodology for capturing Ethereum token-contracts in the Universal Composability (UC) framework, which can be of independent interest. John Andrews, Michele Ciampi, Vassilis Zikas |
J. Comput. Syst. Sci. | 2 |
| 2022 | Efficient NIZK Arguments with Straight-Line Simulation and Extraction
Michele Ciampi, Ivan Visconti |
CANS | 1 |
| 2022 | Collusion-Preserving Computation without a MediatorabstractCollusion-free (CF) and collusion-preserving (CP) protocols enrich the standard security offered by multi-party computation (MPC), to tackle settings where subliminal communication is undesirable. However, all existing solutions make arguably unrealistic assumptions on setups, such as physical presence of the parties, access to physical envelopes, or extreme isolation, where the only means of communication is a star-topology network. The above state of affairs remained a limitation of such protocols, which was even reinforced by impossibility results. Thus, for years, it has been unclear if and how the above setup assumptions could be relaxed towards more realistic scenarios. Motivated also by the increasing interest in using hardware tokens for cryptographic applications, in this work we provide the first solution to collusion preserving computation which uses weaker and more common assumptions than the state of the art, i.e., an authenticated broadcast functionality and access to honestly generated trusted hardware tokens. We prove that our protocol is collusion-preserving (in short, CP) secure as long as no parties abort. In the case of an aborting adversary, our protocol still achieves standard (G)UC security with identifiable (and unanimous) abort. Leveraging the above identifiability property, we augment our protocol with a penalization scheme which ensures that it is not profitable to abort, thereby obtaining CP security against incentive-driven attackers. To define (and prove) this latter result, we combine the Rational Protocol Design (RPD) methodology by Garay et al. [FOCS 2013] with the CP framework of Alwen et al. [CRYPTO 2012] to derive a definition of security in the presence of incentive-driven local adversaries which can be of independent interest. Similar to existing CP/CF solutions, our protocol preserves, as a fallback, security against monolithic adversaries, even when the setup (i.e., the hardware tokens) is compromised or corrupted. In addition, our fallback solution achieves identifiable and unanimous abort, which we prove are impossible in previous CP solutions. Michele Ciampi, Yun Lu 0001, Vassilis Zikas |
CSF | 1 |
| 2022 | Round-Optimal and Communication-Efficient Multiparty Computation
Michele Ciampi, Rafail Ostrovsky, Hendrik Waldner, Vassilis Zikas |
EUROCRYPT (1) | 1 |
| 2022 | Round-Optimal Multi-party Computation with Identifiable AbortabstractSecure multi-party computation (MPC) protocols that are resilient to a dishonest majority allow the adversary to get the output of the computation while, at the same time, forcing the honest parties to abort. Aumann and Lindell introduced the enhanced notion of security with identifiable abort , which still allows the adversary to trigger an abort but, at the same time, it enables the honest parties to agree on the identity of the party that led to the abort. More recently, in Eurocrypt 2016, Garg et al. showed that, assuming access to a simultaneous message exchange channel for all the parties, at least four rounds of communication are required to securely realize non-trivial functionalities in the plain model. Following Garg et al., a sequence of works has matched this lower bound, but none of them achieved security with identifiable abort. In this work, we close this gap and show that four rounds of communication are also sufficient to securely realize any functionality with identifiable abort using standard and generic polynomial-time assumptions. To achieve this result we introduce the new notion of bounded-rewind secure MPC that guarantees security even against an adversary that performs a mild form of reset attacks. We show how to instantiate this primitive starting from any MPC protocol and by assuming trapdoor-permutations. The notion of bounded-rewind secure MPC allows for easier parallel composition of MPC protocols with other (interactive) cryptographic primitives. Therefore, we believe that this primitive can be useful in other contexts in which it is crucial to combine multiple primitives with MPC protocols while keeping the round complexity of the final protocol low. Michele Ciampi, Divya Ravi 0001, Luisa Siniscalchi, Hendrik Waldner |
EUROCRYPT (1) | 1 |
| 2022 | Four-Round Black-Box Non-malleable Schemes from One-Way Permutations
Michele Ciampi, Emmanuela Orsini, Luisa Siniscalchi |
TCC (2) | 1 |
| 2021 | Threshold Garbled Circuits and Ad Hoc Secure Computation
Michele Ciampi, Vipul Goyal, Rafail Ostrovsky |
EUROCRYPT (3) | 1 |
| 2021 | Oblivious Transfer from Trapdoor Permutations in Minimal Rounds
Arka Rai Choudhuri, Michele Ciampi, Vipul Goyal, Abhishek Jain 0002, Rafail Ostrovsky |
TCC (2) | 2 |
| 2020 | Timed Signatures and Zero-Knowledge Proofs - Timestamping in the Blockchain Era -
Aydin Abadi, Michele Ciampi, Aggelos Kiayias, Vassilis Zikas |
ACNS (1) | 2 |
| 2020 | Updatable Blockchains
Michele Ciampi, Nikos Karayannidis, Aggelos Kiayias, Dionysis Zindros |
ESORICS (2) | 1 |
| 2020 | Round Optimal Secure Multiparty Computation from Minimal Assumptions
Arka Rai Choudhuri, Michele Ciampi, Vipul Goyal, Abhishek Jain 0002, Rafail Ostrovsky |
TCC (2) | 2 |
| 2017 | Four-Round Concurrent Non-Malleable Commitments from One-Way Functions
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti |
CRYPTO (2) | 1 |
| 2017 | Round-Optimal Secure Two-Party Computation from Trapdoor Permutations
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti |
TCC (1) | 1 |
| 2017 | Delayed-Input Non-Malleable Zero Knowledge and Multi-Party Coin Tossing in Four Rounds
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti |
TCC (1) | 1 |
| 2016 | Concurrent Non-Malleable Commitments (and More) in 3 Rounds
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti |
CRYPTO (3) | 1 |
| 2016 | Online/Offline OR Composition of Sigma Protocols
Michele Ciampi, Giuseppe Persiano, Alessandra Scafuro, Luisa Siniscalchi, Ivan Visconti |
EUROCRYPT (2) | 1 |