VLDB 2026 Research / reviewers in the wild / expert
Pratik Soni
dblp:168/9476
· DBLP profile ↗
19ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0002-3225-3323ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 11 since 2021Theory of computation · 6 · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Poster: EPIC - When Learners Disagree, Campaigns Speak; Perceiving Structure in Unfolding SSH EpisodesabstractSSH attacks do not arrive; they unfold episodically: credential pools rotate, infrastructure persists, coordinated bursts surface and dissolve across windows, each episode a fragment of a larger campaign geometry. EPIC watches these unfolding episodes and translates it into advanced structural warnings for downstream actors (firewalls, BGP controllers, and AI-driven orchestrators) before campaigns solidify. It does not detect; it perceives. Built on the principle of structural dissonance as perception, EPIC preserves inter-model disagreement (rather than collapsing it into a formal ensemble) as the primary sensor of campaign phase transitions. Therefore, when learners diverge, the system is not failing; it is listening. Relational cues (Spearman, Cosine, Pearson) re-injected over predicted trajectories reveal what each episode means (e.g. monotonic escalation, geometric stability, algebraic collapse), each enabling graded autonomy over downstream responses. Ghazal Abdollahi, Hamid Asadi, Devagopal Sreenivas, Pratik Soni, Robert Ricci |
SIGCOMM | 4 |
| 2026 | New Constructions of Functional Adaptor Signatures: Broader Functions and Improved Efficiency
Nikhil Vanjani, Garrett Greiner, Sri Aravinda Krishnan Thyagarajan, Pratik Soni |
SP | 4 |
| 2026 | HyperVerITAS: Verifying Image Transformations at Scale on Boolean HypercubesabstractWe present HyperVerITAS, a new zero-knowledge proof (ZKP) system for image provenance that enables scalable, efficient, and privacy-preserving verification of image transformations. HyperVerITAS builds upon the same minimal trust model as VerITAS (IEEE S&P '25), requiring trust only in the image source device, while treating the editing software as untrusted. Unlike VerITAS, which relies on FFT-intensive SNARKs and suffers from high memory overhead (up to 120 GB), HyperVerITAS leverages multilinear polynomial encodings over the Boolean hypercube to dramatically reduce both proving time and memory usage. Our design cleanly separates signature verification from image transformation, supports modular integration of multiple polynomial commitment schemes (including post-quantum constructions) and naturally extends to a wide range of affine image transformations. We implement HyperVerITAS with two distinct commitment schemes (Brakedown and multilinear KZG) and evaluate it on full-system pipelines involving cropping and grayscaling. On commodity hardware (Apple M3, 36 GB RAM), HyperVerITAS generates proofs for 33 MP images using only 27 GB of RAM and 6.6 minutes of proving time, whereas VerITAS fails to scale beyond 4 MP. These results establish HyperVerITAS as a practical and scalable ZKP system for secure and efficient image provenance. Garrett Greiner, Toshi Mowery, Pratik Soni |
Proc. Priv. Enhancing Technol. | 3 |
| 2026 | Sensor Privacy as a Spectrum: Quantifying Privacy in Edge and Multimodal Systems through GamesabstractEdge intelligence is often assumed to improve privacy because raw sensor streams remain local and only constrained outputs (e.g., binary events, compressed embeddings, or coarse labels) are exposed. We show this assumption is misleading: even minimal on-device outputs can retain structured semantics that enable adversaries to infer sensitive behaviors under realistic context and access regimes. We introduce a game-based framework that separates two sources of leakage: statistical leakage, bounded by the information capacity of the observable channel, and algorithmic leakage, unlocked when adversaries exploit temporal coherence, multi-channel structure, or auxiliary context within that bound. Across embedded, smartphone, and multimodal sensing datasets, we find that a quantized motion interface can preserve 70–75% of behavioral structure (via information- and divergence-based scores) and enable ∼65% activity inference accuracy (about 4× random guessing) once temporal continuity is restored. Exposing richer continuous channels further increases in-domain leakage but becomes strongly placement- and device-specific, degrading transfer across sensors and datasets. Finally, we show that representation learning can induce cross-modal bridges that erode sensing-layer constraints, making seemingly low-sensitivity IMU signals more predictive of private semantic attributes associated with hidden high-fidelity modalities. Together, these results show that privacy in edge AI is shaped by an interaction between physical constraints and observable-interface design, motivating co-designed sensing, model, and evaluation choices that quantify and limit interface-induced leakage rather than assuming locality implies privacy. Jainta Paul, Miles Bovero, Swapnil Saha, Mahesh Chowdhary, Pratik Soni |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Efficient Distributed Randomness Generation from Minimal Assumptions Where PArties Speak Sequentially Once
Chen-Da Liu-Zhang, Elisaweta Masserova, João Ribeiro 0002, Pratik Soni, Sri Aravinda Krishnan Thyagarajan |
EUROCRYPT (5) | 4 |
| 2024 | Functional Adaptor Signatures: Beyond All-or-Nothing Blockchain-based PaymentsabstractIn scenarios where a seller holds sensitive data x, like employee / patient records or ecological data, and a buyer seeks to obtain an evaluation of specific function f on this data, solutions in trustless digital environments like blockchain-based Web3 systems typically fall into two categories: (1) Smart contract-powered solutions and (2) cryptographic solutions leveraging tools such as adaptor signatures. The former approach offers atomic transactions where the buyer learns the function evaluation f(x) (and not x entirely) upon payment. However, this approach is often inefficient, costly, lacks privacy for the seller's data, and is incompatible with systems that do not support smart contracts with required functionalities. In contrast, the adaptor signature-based approach addresses all of the above issues but comes with an "all-or-nothing" guarantee, where the buyer fully extracts x and does not support functional extraction of the sensitive data. In this work, we aim to bridge the gap between these approaches, developing a solution that enables fair functional sales of information while offering improved efficiency, privacy, and compatibility similar to adaptor signatures. Nikhil Vanjani, Pratik Soni, Sri Aravinda Krishnan Thyagarajan |
CCS | 2 |
| 2024 | Game-Theoretically Fair Distributed Sampling
Sri Aravinda Krishnan Thyagarajan, Pratik Soni |
CRYPTO (8) | 2 |
| 2024 | Foundations of Adaptor Signatures
Paul Gerhart, Dominique Schröder, Pratik Soni, Sri Aravinda Krishnan Thyagarajan |
EUROCRYPT (2) | 3 |
| 2024 | Improved YOSO Randomness Generation with Worst-Case Corruptions
Chen-Da Liu-Zhang, Elisaweta Masserova, João Ribeiro 0002, Pratik Soni, Sri Aravinda Krishnan Thyagarajan |
FC (2) | 4 |
| 2023 | Distributed-Prover Interactive Proofs
Sourav Das 0001, Rex Fernando, Ilan Komargodski, Elaine Shi, Pratik Soni |
TCC (1) | 5 |
| 2023 | Non-Interactive Anonymous Router with Quasi-Linear Router Computation
Rex Fernando, Elaine Shi, Pratik Soni, Nikhil Vanjani, Brent Waters |
TCC (3) | 3 |
| 2022 | Time-Traveling Simulators Using Blockchains and Their Applications
Vipul Goyal, Justin Raizes, Pratik Soni |
ITCS | 3 |
| 2021 | Time- and Space-Efficient Arguments from Groups of Unknown Order
Alexander R. Block, Justin Holmgren, Alon Rosen, Ron Rothblum, Pratik Soni |
CRYPTO (4) | 5 |
| 2020 | Public-Coin Zero-Knowledge Arguments with (almost) Minimal Time and Space Overheads
Alexander R. Block, Justin Holmgren, Alon Rosen, Ron Rothblum, Pratik Soni |
TCC (2) | 5 |
| 2020 | Two-Round and Non-Interactive Concurrent Non-Malleable Commitments from Time-Lock PuzzlesabstractNon-malleable commitments are a fundamental cryptographic tool for preventing (concurrent) man-in-the-middle attacks. Since their invention by Dolev, Dwork, and Naor in 1991, their round-complexity has been extensively studied, leading up to constant-round protocols based on one-way functions (OWFs), and three-round protocols based on sub-exponential OWFs, and standard polynomial-time hardness assumptions such as decisional Diffie--Hellman (DDH) and ZAPs (i.e., two-round witness-indistinguishable proofs). But constructions of two-round, or non-interactive, non-malleable commitments have so far remained elusive; the only known construction relied on a strong and non-falsifiable assumption with a non-malleability flavor. Additionally, a recent result by Pass shows the impossibility of basing two-round non-malleable commitments on falsifiable assumptions using a polynomial-time black-box security reduction. In this work, we show how to overcome this impossibility using super-polynomial-time hardness assumptions. Our main result demonstrates the existence of two-round concurrent non-malleable commitments based on the following four primitives (all with sub-exponential security): (1) non-interactive commitments, (2) ZAPs (i.e., 2-round witness indistinguishable proofs), (3) collision-resistant hash functions, and (4) a “weak” time-lock puzzle. Primitives (1), (2), and (3) can be based on, e.g., the discrete log and the RSA assumption. Time-lock puzzles---puzzles that can be solved by “brute-force” in time $2^t$, but cannot be solved significantly faster even using parallel computers---were proposed by Rivest, Shamir, and Wagner in 1996 and have been extensively studied since. We additionally obtain a non-interactive (i.e., one-message) version of our protocol satisfying concurrent non-malleability w.r.t. uniform attackers and show that our non-malleable commitments satisfy an even stronger notion of chosen commitment attack security. Huijia Lin, Rafael Pass, Pratik Soni |
SIAM J. Comput. | 3 |
| 2018 | Naor-Reingold Goes Public: The Complexity of Known-Key Security
Pratik Soni, Stefano Tessaro |
EUROCRYPT (3) | 1 |
| 2017 | Public-Seed Pseudorandom Permutations
Pratik Soni, Stefano Tessaro |
EUROCRYPT (2) | 1 |
| 2017 | Two-Round and Non-Interactive Concurrent Non-Malleable Commitments from Time-Lock PuzzlesabstractNon-malleable commitments are a fundamental cryptographic tool for preventing against (concurrent) man-in-the-middle attacks. Since their invention by Dolev, Dwork, and Naor in 1991, the round-complexity of non-malleable commitments has been extensively studied, leading up to constant-round concurrent non-malleable commitments based only on one-way functions, and even 3-round concurrent non-malleable commitments based on subexponential one-way functions. But constructions of two-round, or non-interactive, nonmalleable commitments have so far remained elusive; the only known construction relied on a strong and non-falsifiable assumption with a non-malleability flavor. Additionally, a recent result by Pass shows the impossibility of basing two-round non-malleable commitments on falsifiable assumptions using a polynomial-time black-box security reduction. In this work, we show how to overcome this impossibility, using super-polynomial-time hardness assumptions. Our main result demonstrates the existence of a two-round concurrent non-malleable commitment based on subexponential “standard-type” assumptions-notably, assuming the existence of the following primitives (all with subexponential security): (1) non-interactive commitments, (2) ZAPs (i.e., 2-round witness indistinguishable proofs), (3) collision-resistant hash functions, and (4) a “weak” time-lock puzzle. Primitives (1),(2),(3) can be based on e.g., the discrete log assumption and the RSA assumption. Time-lock puzzles-puzzles that can be solved by “brute-force” in time 2t, but cannot be solved significantly faster even using parallel computers-were proposed by Rivest, Shamir, and Wagner in 1996, and have been quite extensively studied since; the most popular instantiation relies on the assumption that 2t repeated squarings mod N = pq require “roughly” 2t parallel time. Our notion of a “weak” time-lock puzzle, requires only that the puzzle cannot be solved in parallel time 2tϵ(and thus we only need to rely on the relatively mild assumption that there are no huge improvements in the parallel complexity of repeated squaring algorithms). We additionally show that if replacing assumption (2) for a non-interactive witness indistinguishable proof (NIWI), and (3) for a uniform collision-resistant hash function, then a non-interactive (i.e., one-message) version of our protocol satisfies concurrent non-malleability w.r.t. uniform attackers. Huijia Lin, Rafael Pass, Pratik Soni |
FOCS | 3 |
| 2015 | The SICILIAN Defense: Signature-based Whitelisting of Web JavaScriptabstractWhitelisting has become a common practice to ensure the execution of trusted applications. However, its effectiveness in protecting client-side web application code has not yet been established. In this paper, we seek to study the efficacy of signature-based whitelisting approach in preventing script injection attacks. This includes a recently-proposed W3C recommendation called Subresource Integrity (SRI), which is based on raw text signatures of scripts. Our 3-month long measurement study shows that applying such raw signatures require signature updates at an impractical rate. We then present SICILIAN, a novel multi-layered approach for whitelisting scripts that can tolerate changes in them without sacrificing the security. Our solution comes with a deployment model called progressive lockdown, which lets browsers assist the server in composing the whitelist. Such assistance from the browser minimizes the burden of building the signature-based whitelist. Our evaluation on Alexa's top 500 sites and 15 popular PHP applications shows that SICILIAN can be fully applied to 84.7% of the sites and all the PHP applications with updates to the whitelist required roughly once in a month.SICILIAN incurs an average performance overhead of 7.02%. Pratik Soni, Enrico Budianto, Prateek Saxena |
CCS | 1 |