VLDB 2026 Research / reviewers in the wild / expert
Rafael Dowsley
dblp:37/391
· DBLP profile ↗
36ranked-venue papers
7as first author
11since 2021 · last 2024
0000-0002-7588-2410ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 6 · 2 since 2021Theory of computation · 6 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 1 first-authorDatabases, data management, data science and information retrieval · 3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | SePEnTra: A Secure and Privacy-Preserving Energy Trading Mechanism in the Transactive Energy Market
Rumpa Dasgupta, Amin Sakzad, Carsten Rudolph, Rafael Dowsley |
ProvSec (2) | 4 |
| 2022 | Post-Quantum Verifiable Random Function from Symmetric Primitives in PoS Blockchain
Maxime Buser, Rafael Dowsley, Muhammed F. Esgin, Shabnam Kasra Kermanshahi, Veronika Kuchta, Joseph K. Liu, Raphael C.-W. Phan, Zhenfei Zhang |
ESORICS (1) | 2 |
| 2022 | (Public) Verifiability for Composable Protocols Without Adaptivity or Zero-Knowledge
Carsten Baum, Bernardo Machado David, Rafael Dowsley |
ProvSec | 3 |
| 2022 | A Spendable Cold Wallet from QR VideoabstractHot/cold wallet refers to a widely used paradigm to enhance the security level of cryptocurrency applications that was proposed on Bitcoin Improvement Proposal 32. In a nutshell, after performing an initial setup in which the hot wallet receives partial information of the cold wallet in order to hierarchically generate (transaction receiving) addresses, the cold wallet stays offline, whereas the hot wallet is kept online. The initial transferred information enables the hot wallet to generate receiving addresses for both wallets, but it can only spend its own funds, i.e., it cannot spend the funds in the cold wallet. This design conveniently mimics money storage in daily life: pocket money is kept in a less safe location, e.g., a regular wallet, while life savings are kept in a more safe environment, e.g., banking account. Note that the funds that land in offline addresses cannot be spent if the cold wallet is kept permanently offline. We propose a protocol and a technical solution to spend funds from a cold wallet without physically connecting it to any network. We designed and implemented a prototype for a system based on Optical Camera Communication (OCC) in a screen to camera setting, which can receive messages from a computer screen at the rate of over 150kB per second. Our system consists of a sequence of QR codes – a QR video. Our solution minimizes the possible attack vectors, including malware, by relying on optical communication yet providing a larger bandwidth than regular QR code based solutions. Rafael Dowsley, Mylène C. Q. Farias, Mario Larangeira, Anderson Nascimento, Jot Virdee |
SECRYPT | 1 |
| 2022 | Range search on encrypted spatial data with dynamic updatesabstractDriven by the cloud-first initiative taken by various governments and companies, it has become a common practice to outsource spatial data to cloud servers for a wide range of applications such as location-based services and geographic information systems. Searchable encryption is a common practice for outsourcing spatial data which enables search over encrypted data by sacrificing the full security via leaking some information about the queries to the server. However, these inherent leakages could equip the server to learn beyond what is considered in the scheme, in the worst-case allowing it to reconstruct of the database. Recently, a novel form of database reconstruction attack against such kind of outsourced spatial data was introduced (Markatou and Tamassia, IACR ePrint 2020/284), which is performed using common leakages of searchable encryption schemes, i.e., access and search pattern leakages. An access pattern leakage is utilized to achieve an order reconstruction attack, whereas both access and search pattern leakages are exploited for the full database reconstruction attack. In this paper, we propose two novel schemes for outsourcing encrypted spatial data supporting dynamic range search. Our proposed schemes leverage R+tree to partition the dataset and binary secret sharing to support secure range search. They further provide backward and content privacy and do not leak the access pattern, therefore being resilient against the above mentioned database reconstruction attacks. The evaluations and results on the real-world dataset demonstrate the practicality of our schemes, due to (a) the minimal round-trip between the client and server, and (b) the low computation and storage overhead on the client side. Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi, Shangqi Lai |
J. Comput. Secur. | 2 |
| 2022 | Privacy-preserving training of tree ensembles over continuous data
Samuel Adams, Chaitali Choudhary, Martine De Cock, Rafael Dowsley, David Melanson, Anderson C. A. Nascimento, Davis Railsback, Jianwei Shen 0002 |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | Fast Privacy-Preserving Text Classification Based on Secure Multiparty ComputationabstractWe propose a privacy-preserving Naive Bayes classifier and apply it to the problem of private text classification. In this setting, a party (Alice) holds a text message, while another party (Bob) holds a classifier. At the end of the protocol, Alice will only learn the result of the classifier applied to her text input and Bob learns nothing. Our solution is based on Secure Multiparty Computation (SMC). Our Rust implementation provides a fast and secure solution for the classification of unstructured text. Applying our solution to the case of spam detection (the solution is generic, and can be used in any other scenario in which the Naive Bayes classifier can be employed), we can classify an SMS as spam or ham in less than 340ms in the case where the dictionary size of Bob’s model includes all words ($n = 5200$) and Alice’s SMS has at most$m = 160$unigrams. In the case with$n = 369$and$m = 8$(the average of a spam SMS in the database), our solution takes only 21ms. Amanda Cristina Davi Resende, Davis Railsback, Rafael Dowsley, Anderson C. A. Nascimento, Diego F. Aranha |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Geo-DRS: Geometric Dynamic Range Search on Spatial Data with Backward and Content Privacy
Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi |
ESORICS (2) | 2 |
| 2021 | TARDIS: A Foundation of Time-Lock Puzzles in UC
Carsten Baum, Bernardo Machado David, Rafael Dowsley, Jesper Buus Nielsen, Sabine Oechsner |
EUROCRYPT (3) | 3 |
| 2021 | Privacy-Preserving Feature Selection with Secure Multiparty ComputationabstractExisting work on privacy-preserving machine learning with Secure Multiparty Computation (MPC) is almost exclusively focused on model training and on inference with trained models, thereby overlooking the important data pre-processing stage. In this work, we propose the first MPC based protocol for private feature selection based on the filter method, which is independent of model training, and can be used in combination with any MPC protocol to rank features. We propose an efficient feature scoring protocol based on Gini impurity to this end. To demonstrate the feasibility of our approach for practical data science, we perform experiments with the proposed MPC protocols for feature selection in a commonly used machine-learning-as-a-service configuration where computations are outsourced to multiple servers, with semi-honest and with malicious adversaries. Regarding effectiveness, we show that secure feature selection with the proposed protocols improves the accuracy of classifiers on a variety of real-world data sets, without leaking information about the feature values or even which features were selected. Regarding efficiency, we document runtimes ranging from several seconds to an hour for our protocols to finish, depending on the size of the data set and the security settings. Xiling Li, Rafael Dowsley, Martine De Cock |
ICML | 2 |
| 2021 | Privacy-Preserving Video Classification with Convolutional Neural NetworksabstractMany video classification applications require access to personal data, thereby posing an invasive security risk to the users’ privacy. We propose a privacy-preserving implementation of single-frame method based video classification with convolutional neural networks that allows a party to infer a label from a video without necessitating the video owner to disclose their video to other entities in an unencrypted manner. Similarly, our approach removes the requirement of the classifier owner from revealing their model parameters to outside entities in plaintext. To this end, we combine existing Secure Multi-Party Computation (MPC) protocols for private image classification with our novel MPC protocols for oblivious single-frame selection and secure label aggregation across frames. The result is an end-to-end privacy-preserving video classification pipeline. We evaluate our proposed solution in an application for private human emotion recognition. Our results across a variety of security settings, spanning honest and dishonest majority configurations of the computing parties, and for both passive and active adversaries, demonstrate that videos can be classified with state-of-the-art accuracy, and without leaking sensitive user information. Sikha Pentyala, Rafael Dowsley, Martine De Cock |
ICML | 2 |
| 2020 | Efficient Composable Oblivious Transfer from CDH in the Global Random Oracle Model
Bernardo Machado David, Rafael Dowsley |
CANS | 2 |
| 2020 | On the Commitment Capacity of Unfair Noisy ChannelsabstractNoisy channels are a valuable resource from a cryptographic point of view. They can be used for exchanging secret-keys as well as realizing other cryptographic primitives such as commitment and oblivious transfer. To be really useful, noisy channels have to be considered in the scenario where a cheating party has some degree of control over the channel characteristics. Damgård et al. (EUROCRYPT 1999) proposed a more realistic model where such level of control is permitted to an adversary, the so called unfair noisy channels, and proved that they can be used to obtain commitment and oblivious transfer protocols. Given that noisy channels are a precious resource for cryptographic purposes, one important question is determining the optimal rate in which they can be used. The commitment capacity has already been determined for the cases of discrete memoryless channels and Gaussian channels. In this work we address the problem of determining the commitment capacity of unfair noisy channels. We compute a single-letter characterization of the commitment capacity of unfair noisy channels. In the case where an adversary has no control over the channel (the fair case) our capacity reduces to the well-known capacity of a discrete memoryless binary symmetric channel. Claude Crépeau, Rafael Dowsley, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 2 |
| 2019 | Efficient UC Commitment Extension with Homomorphism for Free (and Applications)
Ignacio Cascudo, Ivan Damgård, Bernardo Machado David, Nico Döttling, Rafael Dowsley, Irene Giacomelli |
ASIACRYPT (2) | 5 |
| 2019 | Privacy-Preserving Classification of Personal Text Messages with Secure Multi-Party ComputationabstractClassification of personal text messages has many useful applications in surveillance, e-commerce, and mental health care, to name a few. Giving applications access to personal texts can easily lead to (un)intentional privacy violations. We propose the first privacy-preserving solution for text classification that is provably secure. Our method, which is based on Secure Multiparty Computation (SMC), encompasses both feature extraction from texts, and subsequent classification with logistic regression and tree ensembles. We prove that when using our secure text classification method, the application does not learn anything about the text, and the author of the text does not learn anything about the text classification model used by the application beyond what is given by the classification result itself. We perform end-to-end experiments with an application for detecting hate speech against women and immigrants, demonstrating excellent runtime results without loss of accuracy. Devin Reich, Ariel Todoki, Rafael Dowsley, Martine De Cock, Anderson C. A. Nascimento |
NeurIPS | 3 |
| 2019 | On the Impossibility of Structure-Preserving Deterministic Primitives
Masayuki Abe, Jan Camenisch, Rafael Dowsley, Maria Dubovitskaya |
J. Cryptol. | 3 |
| 2019 | Efficient and Private Scoring of Decision Trees, Support Vector Machines and Logistic Regression Models Based on Pre-ComputationabstractMany data-driven personalized services require that private data of users is scored against a trained machine learning model. In this paper we propose a novel protocol for privacy-preserving classification of decision trees, a popular machine learning model in these scenarios. Our solutions is composed out of building blocks, namely a secure comparison protocol, a protocol for obliviously selecting inputs, and a protocol for multiplication. By combining some of the building blocks for our decision tree classification protocol, we also improve previously proposed solutions for classification of support vector machines and logistic regression models. Our protocols are information theoretically secure and, unlike previously proposed solutions, do not require modular exponentiations. We show that our protocols for privacy-preserving classification lead to more efficient results from the point of view of computational and communication complexities. We present accuracy and runtime results for seven classification benchmark datasets from the UCI repository. Martine De Cock, Rafael Dowsley, Caleb Horst, Rajendra S. Katti, Anderson C. A. Nascimento, Wing-Sea Poon, Stacey Truex |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | 21 - Bringing Down the Complexity: Fast Composable Protocols for Card Games Without Secret State
Bernardo Machado David, Rafael Dowsley, Mario Larangeira |
ACISP | 2 |
| 2018 | Privacy-Preserving Linear Regression for Brain-Computer Interface ApplicationsabstractMany machine learning (ML) applications rely on large amounts of personal data for training and inference. Among the most intimate exploited data sources is electroencephalogram (EEG) data. The emergence of consumer -grade, low-cost brain -computer interfaces (BCIs) and corresponding software development kits' is bringing the use of BCI within reach of application developers. The access that BCI applications have to neural signals rightly raises privacy concerns. Application developers can easily gain knowledge beyond the professed scope from unprotected EEG signals, including passwords, ATM PINs, and other personal data. The challenge is how to engage in meaningful ML with EEG data while protecting the privacy of users. Anisha Agarwal, Rafael Dowsley, Nicholas D. McKinney, Dongrui Wu, Chin-Teng Lin, Martine De Cock, Anderson C. A. Nascimento |
IEEE BigData | 2 |
| 2018 | Privacy-Preserving User Profiling with Facebook LikesabstractThe content generated by users on social media is rich in personal information that can be mined to construct accurate user profiles, and subsequently used for tailored advertising or other personalized services. Facebook has recently come under scrutiny after a third party gained access to the data of millions of users and mined it to construct psychographical profiles, which were allegedly used to influence voters in elections. As part of a possible solution to avoid data breaches while still being able to perform meaningful machine learning (ML) on social media data, we propose a privacy-preserving algorithm for k-nearest neighbor (kNN) [1] , one of the oldest ML methods, used traditionally in collaborative filtering recommender systems. Sanchya Bhagat, Keerthanaa Saminathan, Anisha Agarwal, Rafael Dowsley, Martine De Cock, Anderson C. A. Nascimento |
IEEE BigData | 4 |
| 2018 | Privacy-Preserving Scoring of Tree Ensembles: A Novel Framework for AI in HealthcareabstractMachine Learning (ML) techniques now impact a wide variety of domains. Highly regulated industries such as healthcare and finance have stringent compliance and data governance policies around data sharing. Advances in secure multiparty computation (SMC) for privacy-preserving machine learning (PPML) can help transform these regulated industries by allowing ML computations over encrypted data with personally identifiable information (PII). Yet very little of SMC-based PPML has been put into practice so far. In this paper we present the very first framework for privacy-preserving classification of tree ensembles with application in healthcare. We first describe the underlying cryptographic protocols that enable a healthcare organization to send encrypted data securely to a ML scoring service and obtain encrypted class labels without the scoring service actually seeing that input in the clear. We then describe the deployment challenges we solved to integrate these protocols in a cloud based scalable risk-prediction platform with multiple ML models for healthcare AI. Included are system internals, and evaluations of our deployment for supporting physicians to drive better clinical outcomes in an accurate, scalable, and provably secure manner. To the best of our knowledge, this is the first such applied framework with SMC-based privacy-preserving machine learning for healthcare. Kyle Fritchman, Keerthanaa Saminathan, Rafael Dowsley, Tyler Hughes, Martine De Cock, Anderson C. A. Nascimento, Ankur Teredesai |
IEEE BigData | 3 |
| 2018 | Commitment and Oblivious Transfer in the Bounded Storage Model With ErrorsabstractThe bounded storage model restricts the memory of an adversary in a cryptographic protocol, rather than restricting its computational power, making information theoretically secure protocols feasible. We present the first protocols for commitment and oblivious transfer in the bounded storage model with errors, i.e., the model where the public random sources available to the two parties are not exactly the same, but instead are only required to have a small Hamming distance between themselves. Commitment and oblivious transfer protocols were known previously only for the error-free variant of the bounded storage model, which is harder to realize. Rafael Dowsley, Felipe Lacerda, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 1 |
| 2017 | On the Oblivious Transfer Capacity of Generalized Erasure Channels Against Malicious Adversaries: The Case of Low Erasure ProbabilityabstractNoisy channels are a powerful resource for cryptography as they can be used to obtain information-theoretic secure key agreement, commitment, and oblivious transfer protocols, among others. Oblivious transfer (OT) is a fundamental primitive, since it is complete for secure multi-party computation, and the OT capacity characterizes how efficiently a channel can be used for obtaining string oblivious transfer. Ahlswede and Csiszár (ISIT'07) presented upper and lower bounds on the OT capacity of generalized erasure channels (GECs) against passive adversaries. In the case of GEC with erasure probability at least 1/2, the upper and lower bounds match and, therefore, the OT capacity was determined. It was later proved by Pinto et al. [IEEE Trans. Inf. Theory 57(8)] that the OT capacity is identical for passive and malicious adversaries. In the case of GEC with erasure probability smaller than 1/2, the known lower bound against passive adversaries that was established by Ahlswede and Csiszár does not match their upper bound and it was unknown whether this OT rate could be achieved against malicious adversaries as well. In this paper, we show that there is a protocol against malicious adversaries achieving the same OT rate that was obtained against passive adversaries. We obtain our results by a new combination of interactive hashing and typicality tests that are suitable for dealing with the case of low erasure probability (p* <;1/2 ). Rafael Dowsley, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 1 |
| 2016 | A Distributed Key Management ApproachabstractCloud computing provides reliable and highlyscalable access to resources over the internet. But outsourcing sensitive data to an probably untrusted cloud provider (third party) requires cryptographic methods like encryption. This paper presents a novel approach to a distributed cloud key management scheme. In a setting with a public cloud application, data is encrypted by a separate trusted adapter before storing somewhere else. The encryption key is not persistently stored at the adapter. Several entities share parts of the key that is computed and temporarily stored at the adapter if needed. This work describes how the key management is working during bootstrapping and runtime as well as how key recovery can be performed. Rafael Dowsley, Matthias Gabel, Gerald Hübsch, Gunther Schiefer, Antonia Schwichtenberg |
CloudCom | 1 |
| 2016 | A Database Adapter for Secure OutsourcingabstractThe advent of cloud computing and storage provides numerous opportunities for better management of resources, with the potential of drastically reducing costs. However, when data is outsourced to the cloud, new security vulnerabilities emerge, as the cloud provider (and its employees) are normally not completely trusted by the party that is outsourcing the data. Therefore additional security mechanisms are needed in order to prevent against internal attacks in the cloud provider. Nonetheless, the performance and functionality should be impacted as less as possible. This work presents a database adapter for the secure outsourcing of data that aims at achieving a good performance-security trade-off. Rafael Dowsley, Matthias Gabel, Kateryna Yurchenko, Valentin Zipf |
CloudCom | 1 |
| 2016 | Unconditionally Secure, Universally Composable Privacy Preserving Linear AlgebraabstractLinear algebra operations on private distributed data are frequently required in several practical scenarios (e.g., statistical analysis and privacy preserving databases). We present universally composable two-party protocols to compute inner products, determinants, eigenvalues, and eigenvectors. These protocols are built for a two-party scenario where the inputs are provided by mutually distrustful parties. After execution, the protocols yield the results of the intended operation while preserving the privacy of their inputs. Universal composability is obtained in the trusted initializer model, ensuring information theoretical security under arbitrary protocol composition in complex environments. Furthermore, our protocols are computationally efficient since they only require field multiplication and addition operations. Bernardo Machado David, Rafael Dowsley, Jeroen van de Graaf, Davidson Marques, Anderson C. A. Nascimento, Adriana C. B. Pinto |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Efficient Unconditionally Secure Comparison and Privacy Preserving Machine Learning Classification Protocols
Bernardo Machado David, Rafael Dowsley, Rajendra S. Katti, Anderson C. A. Nascimento |
ProvSec | 2 |
| 2015 | Public-Key Encryption Schemes with Bounded CCA Security and Optimal Ciphertext Length Based on the CDH and HDH AssumptionsabstractIn Cramer et al. (2007, Bounded CCA2-Secure Encryption. In Kurosawa, K. (ed.), Advances in Cryptology – ASIACRYPT 2007, Kuching, Malaysia, December 2–6, Lecture Notes in Computer Science, Vol. 4833, pp. 502–518. Springer, Berlin, Germany) proposed a public-key encryption scheme secure against adversaries with a bounded number of decryption queries based on the decisional Diffie–Hellman problem. In this paper, we show that the same result can be obtained based on weaker computational assumptions, namely: the computational Diffie–Hellman and the hashed Diffie–Hellman assumptions. Mayana Pereira, Rafael Dowsley, Anderson C. A. Nascimento, Goichiro Hanaoka |
Comput. J. | 2 |
| 2014 | Universally Composable Oblivious Transfer Based on a Variant of LPN
Bernardo Machado David, Rafael Dowsley, Anderson C. A. Nascimento |
CANS | 2 |
| 2014 | Oblivious transfer in the bounded storage model with errorsabstractIn the bounded storage model the memory of the adversarial parties is restricted, instead of their computational power. This different restriction allows the construction of protocols with information-theoretical (instead of only computational) security. We present the first protocol for oblivious transfer in the bounded storage model with errors, i.e., where the public random sources available to the two parties are not exactly the same, but instead are only required to have a small Hamming distance between themselves, and the memory of the (adversarial) receiver is limited. Oblivious transfer protocols were known previously only for the error-free variant of the bounded storage model, which is harder to realize. Rafael Dowsley, Felipe Lacerda, Anderson C. A. Nascimento |
ISIT | 1 |
| 2014 | On the Impossibility of Structure-Preserving Deterministic Primitives
Masayuki Abe, Jan Camenisch, Rafael Dowsley, Maria Dubovitskaya |
TCC | 3 |
| 2012 | Standard Security Does Not Imply Security against Selective-Opening
Mihir Bellare, Rafael Dowsley, Brent Waters, Scott Yilek |
EUROCRYPT | 2 |
| 2012 | A CCA2 Secure Variant of the McEliece CryptosystemabstractThe McEliece public-key encryption scheme has become an interesting alternative to cryptosystems based on number-theoretical problems. Different from RSA and ElGamal, McEliece PKC is not known to be broken by a quantum computer. Moreover, even though McEliece PKC has a relatively big key size, encryption and decryption operations are rather efficient. In spite of all the recent results in coding-theory-based cryptosystems, to the date, there are no constructions secure against chosen ciphertext attacks in the standard model-the de facto security notion for public-key cryptosystems. In this paper, we show the first construction of a McEliece-based public-key cryptosystem secure against chosen ciphertext attacks in the standard model. Our construction is inspired by a recently proposed technique by Rosen and Segev. Nico Döttling, Rafael Dowsley, Jörn Müller-Quade, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 2 |
| 2011 | Achieving Oblivious Transfer Capacity of Generalized Erasure Channels in the Malicious ModelabstractInformation-theoretically secure string oblivious transfer (OT) can be constructed based on discrete memoryless channel (DMC). The oblivious transfer capacity of a channel characterizes - similarly to the (standard) information capacity - how efficiently it can be exploited for secure oblivious transfer of strings. The OT capacity of a generalized erasure channel (GEC) - which is a combination of a (general) DMC with the erasure channel - has been established by Ahlswede and Csizar at ISIT'07 in the case of passive adversaries. In this paper, we present the protocol that achieves this capacity against malicious adversaries for GEC with erasure probability at least 1/2. Our construction is based on the protocol of Crepeau and Savvides from Eurocrypt'06 which uses interactive hashing (IH). We solve an open question posed by the above paper, by basing it upon a constant round IH scheme (previously proposed by Ding et al. at TCC'04). As a side result, we show that the Ding et al. IH protocol can deal with transmission errors. Adriana C. B. Pinto, Rafael Dowsley, Kirill Morozov, Anderson C. A. Nascimento |
IEEE Trans. Inf. Theory | 2 |
| 2010 | Public Key Encryption Schemes with Bounded CCA Security and Optimal Ciphertext Length Based on the CDH Assumption
Mayana Pereira, Rafael Dowsley, Goichiro Hanaoka, Anderson C. A. Nascimento |
ISC | 2 |
| 2009 | A CCA2 Secure Public Key Encryption Scheme Based on the McEliece Assumptions in the Standard Model
Rafael Dowsley, Jörn Müller-Quade, Anderson C. A. Nascimento |
CT-RSA | 1 |