Lukasz Krzywiecki

dblp:40/2852 · DBLP profile ↗
← Back
38ranked-venue papers
20as first author
16since 2021 · last 2025
0000-0002-5326-3627ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 14 first-author · 14 since 2021Computer networks · 4 · 1 first-authorTheory of computation · 2Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Hierarchical Ring Signatures with Hidden Signature Functionality over Blockchain Infrastructure
abstract
In this paper, we propose a modification to the hierarchical signature scheme that enhances the scalability and integrity of the resulting anonymous signature hierarchy, while introducing a new feature: the ability to hide additional signatures. We leverage blockchain infrastructure and smart contracts to improve the integrity of the hierarchy, address scalability challenges, and facilitate efficient node verification. We conceptualize the blockchain as a management layer that enables the selective revelation of non-signers within a ring of nodes by disclosing their ephemeral values. This process refines the anonymity set and allows for the recovery of hidden signatures. Furthermore, we present a performance analysis based on a proof-of-concept implementation of hierarchical signatures on the Ethereum blockchain, evaluating operational costs to demonstrate the scheme's efficiency.
Lukasz Krzywiecki, Witold Karas, Adam Niezgoda, Karol Niczyj
TrustCom1
2025 Verifiable and Robust Distributed Deep Learning based on Blockchain Infrastructure
abstract
In this paper we propose a novel method for achieving verifiable and robust distributed deep learning. Agents verify model correctness and detect attacks, while a blockchain enforces consensus. The approach comprises two core elements: a suite of local validation mechanisms that produce unique "integrity signatures" from trained models, and a smart contract-driven protocol for managing node participation and collective validation. We designed and assessed several validator types, including those analyzing confusion matrices, model parameters, and responses to targeted input perturbations. A prototype was implemented with TensorFlow and Ethereum to evaluate the system’s resilience. Through extensive experiments on Fashion-MNIST with MLP and CNN models under data poisoning attacks, we demonstrate the method’s efficacy. A key finding is that a validator using test set confusion matrices can reliably identify malicious nodes, achieving perfect recall and a low false positive rate against single-class poisoning attacks. Our method successfully identifies and rejects malicious contributions, ensuring the integrity of the collaborative learning process.
Mikolaj Pietrek, Lukasz Krzywiecki, Karol Niczyj, Witold Karas
TrustCom2
2025 Privacy for AI Generated Images: Conditional Generative Adversarial Networks Trained Over Obfuscated Data
abstract
Training machine learning models on sensitive data within cloud environments introduces substantial privacy risks. This paper addresses this challenge by introducing and analyzing a privacy-preserving method for training generative neural networks on obfuscated data. We investigate the security implications of training Conditional Generative Adversarial Networks (CGANs) utilizing an enhanced permutation-based technique. Our method transforms training images via histogram equalization, noise addition, and a pixel permutation function, πimg, while simultaneously obfuscating conditional labels with a function πlabel. Motivated by the need to retain data utility where conventional encryption methods prove insufficient, we demonstrate that this dual approach provides significant operational security for the trained model, M. Specifically, an adversary possessing only the trained model, without knowledge of the functions πimgand πlabel, is computationally prevented from performing meaningful generation. We formalize this notion of security, highlighting its importance for protecting intellectual property and controlling the deployment and usage of trained models.
Krzysztof Talalaj, Lukasz Krzywiecki, Marcin Zawada
TrustCom2
2024 Distributed Data Possession - Blockchain Based Scalability
abstract
Provable Data Possession (PDP) mechanisms allows for efficient verification of data integrity in remote storage platforms. In this paper, we show an efficient way to use a secure PDP scheme for cloud storage with blockchain technology. In our system, verification nodes in the blockchain network challenge data centers through distributed PDP transactions. We show that our method is effective, which is confirmed by experimental results.
Bartlomiej Dzikowski, Lukasz Krzywiecki, Ksawery Mozdzynski, Karol Niczyj, Hannes Salin
TrustCom2
2024 Privacy-Preserving Real-Time Gesture Recognition using Cloud-Trained Neural Networks
abstract
This paper presents a novel approach to privacy-preserving gesture recognition using a remotely trained neural network. Our method ensures the protection of sensitive user data from potential threats, thereby mitigating concerns about data privacy and security. By utilizing encryption techniques, we enable organizations to train complex machine learning models on large-scale datasets without compromising data integrity. We demonstrate the feasibility of this approach through the implementation of proposed models for gesture classification, which achieved high accuracy in both encrypted and plain modes. Our results show that these models are suitable for embedded devices, making them a viable option for commercial or industrial applications such as smart car navigation systems.
Kewin Ignasiak, Wojciech Kowalczyk, Lukasz Krzywiecki, Mateusz Nasewicz, Hannes Salin, Marcin Zawada
TrustCom3
2024 Detectable Mislabeling - Can Faulty AI Models be Recognized from Incomplete Memory Traces?
abstract
Machine Leaning outsourced to remote cloud environments is prone to injections attacks when, e.g. in the communication channel, some fraction of a training set is contaminated, i.e. replaced with some "malicious" data or just mislabeled. In this paper, we research the detection of such injections attacks, based on inevitable, slight but detectable changes of weights in contaminated models. This involves the design of a Convolutional Neural Network super-model, called doctor, able to distinguish between healthy networks - trained on clean data, vs unhealthy networks - trained on data contaminated in injection attacks. Our approach for analyzing the network involves extraction of post-training weights, which undergo a CNN classification. The research proves that the reliability of remotely trained models can undergo efficient post-training verification based on images arbitrarily sliced from tested model weights.
Lukasz Krzywiecki, Tadeusz Kulczycki, Christian Emmanuel Nteranya, Andrzej Stos
TrustCom1
2024 Privacy Preservation in Cloud-Based Distributed Learning through Data Encoding and Partitioning
abstract
This paper explores privacy-preserving training methods for machine learning models, crucial for protecting sensitive data during cloud-based model training. We propose a novel approach utilizing image encoding and partitioning to train models on remote servers. By partitioning images into encoded patches distributed across servers, each training an independent model, we ensure privacy and resilience against attacks. Our findings demonstrate the feasibility of training private datasets on cloud platforms with minimal accuracy loss, offering a high level of privacy at low cost. A critical aspect of our approach lies in its ability to uphold privacy without any modifications to the training software on cloud servers, unlike methods such as homomorphic encryption, which demand the utilization of specialized software.
Lukasz Krzywiecki, Krzysztof Szymaniak, Marcin Zawada
TrustCom1
2023 Cryptanalysis of Human Identification Protocol with Human-Computable Passwords
Maciej Grzeskowiak, Lukasz Krzywiecki, Karol Niczyj
ISPEC2
2023 A Source Hiding Protocol for Cooperative Intelligent Transportation Systems (C-ITS)
Hannes Salin, Lukasz Krzywiecki
ISPEC2
2023 Enhancing Tunnel Safety for Dangerous Goods Vehicles through Blockchain-Based Time-Stamping
abstract
In this study, we explore the potential of integrating blockchain technology and cryptographic primitives such as Schnorr signatures and Pedersen commitments, via a Stamp and Extend scheme, in order to develop a trusted and reliable timestamping system. Our proposed architecture aims to facilitate the safe and reliable platooning of dangerous goods vehicles in C-ITS enabled tunnels. We have implemented a proof-of-concept on the Ethereum platform, demonstrating the feasibility and survivability of our proposed architecture. A series of performance experiments further underscore the potential of our system, reinforcing its value in fostering secure and trusted coordination of dangerous goods transport in connected vehicle tunnels.
Karolina Bak, Hannes Salin, Karol Niczyj, Lukasz Krzywiecki
TrustCom4
2023 Too Noisy, or Not Too Noisy? A Private Training in Machine Learning
abstract
Ensuring privacy while outsourcing the training of machine learning (ML) models to cloud-based platforms is a critical concern. Although cryptographic solutions have been proposed, they often result in a substantial reduction in training accuracy and require modifications to the backend architecture. In this paper, we address the challenge of developing privacy-preserving techniques that offer adequate privacy without significantly impacting the accuracy of the ML model or the accuracy of the training process. We demonstrate that training private datasets on existing cloud-based platforms can be achieved with a high level of privacy and at a minimal cost in accuracy.
Lukasz Krzywiecki, Grzegorz Zaborowski, Marcin Zawada
TrustCom1
2022 How to Design Authenticated Key Exchange for Wearable Devices: Cryptanalysis of AKE for Health Monitoring and Countermeasures via Distinct SMs with Key Split and Refresh
Lukasz Krzywiecki, Hannes Salin
CANS1
2022 Short Signatures via Multiple Hardware Security Modules with Key Splitting in Circuit Breaking Environments
abstract
A Circuit Breaking Environment (CBE) for Connected Railway Infrastructures (CRI) requires that high sensitive cargos are bound to the transportation train carriges. This implies a continous verification of the connectivity and rapid identification of potenital disconnections. For that purpose we consider signatures run on devices with multiple Hardware Security Modules (HSM) architectures. We propose a modification of BLS signatures with an additive key split augumented with a refresh technique. This protects against a powerful adversary that can control distinct HSMs in different signing sessions. Thus, we consider our scheme to be secure even if the adversary switches between chosen HSMs for leakage of partial secrets, from session to session. Finally, we provide promising results from a proof-of- concept implementation, tested on several different type of low- powered devices for comparison. These indicate the feasibility of our constructions.
Lukasz Krzywiecki, Hannes Salin
TrustCom1
2021 Multi-Signature Scheme Resistant to Randomness Injection Attacks - A Bitcoin Case
abstract
We propose a modification of a multi-signature scheme, which was previously used as an enhancement of multi-signatures for the Bitcoin cryptocurrency. Our scheme is secure in a new stronger security model in which we allow the forger to inject or control the ephemeral (randomness) values in the end-user's signing device. Thus, our modified scheme is resistant to ephemeral key leakage attacks. We also provide a proof of concept implementation of our scheme, providing a time complexity and performance analysis.
Lukasz Krzywiecki, Adam Polubek, Hannes Salin
NCA1
2021 Certificateless Multi-Party Authenticated Encryption Mitigating Ephemeral Key Leakage
abstract
We propose two secure modifications of a multi-party authenticated encryption scheme with aggregation, mitigating ephemeral leakage attacks on narrowband Internet of Things devices and sensor equipment, used in different type of connected infrastructures. Our schemes are provably secure in a stronger security model where a set of nodes in a 5G-based architecture can produce authenticated and encrypted signcryption messages, aggregated into one verifiable cipher text. We provide benchmarks from a proof of concept implementation, showing the feasibility of our solutions.
Lukasz Krzywiecki, Hannes Salin, Mateusz Jachniak
NCA1
2021 Cryptanalysis of Deterministic and Probabilistic Multi-Copy PDP Schemes For Cloud Storage - Attacks and Countermeasures
abstract
We provide cryptanalysis of two versions of Provable Data Possession (PDP) constructions. These schemes are proposed for efficient verification of the availability of unmodified data stored in a remote cloud computing platform. We identify problems in the original constructions, as well as the source of errors in the proving methodology. Addressing this, we propose new improved schemes and subsequently, prove their security. To achieve this we reduce the problem of attacking our schemes into breaking the$\top \ell$-assumption, related to the coCDH problem. A benchmark analysis is conducted from proof-of-concept implementations in Python.
Bartosz Drzazga, Lukasz Krzywiecki, Hannes Salin
TrustCom2
2020 Proxy Signcryption Scheme for Vehicle Infrastructure Immune to Randomness Leakage and Setup Attacks
abstract
We propose a proxy signcryption scheme for a multi-party setting, resistant to randomness leakage and setup attacks. Our scheme is an alternative to typical constructions, based on a double Schnorr signature approach, where the linear combination of long term secrets and ephemeral random values occurs both at the initiator and proxy nodes. Our scheme is provably secure in a new stronger model, where the adversary can control the randomness of both parties. Moreover, our proposition is well suited for networks of many independent and moving nodes; especially modern railway infrastructure and vehicle-to-vehicle/infrastructure (V2X) environments, where a broad range of devices with potentially weak computational power and inadequate randomness, is used. Early benchmarks and performance analysis from our proof of concept implementation, suggest that nodes, which use regular Schnorr based schemes, could be successfully upgraded to our more secure alternative construction. Collected timings are still at the acceptable level, proving the applicability of our scheme in modern railway and V2X environments.
Lukasz Krzywiecki, Hannes Salin, Nisha Panwar, Mykola Pavlov
NCA1
2020 Schnorr-like identification scheme resistant to malicious subliminal setting of ephemeral secret
abstract
In this paper we analyze security of Schnorr Identification Scheme (IS) against subliminal setting of ephemeral secrets. We introduce a new strong security model, which allows the adversary to learn or set ephemeral values on the side of the prover. In this model, we define an IS scheme to be secure, if such an adversary, playing role of a verifier, cannot later impersonate the prover. The model primarily reflects a scenario, where the random number generator used for ephemeral secrets has been maliciously implemented or integrated. After showing that the original Schnorr IS is not secure in our model, we propose a modification, immune to such malicious activity. We prove the security of the modified construction in our new strong model. To prove the construction is practical, we provide an implementation and performance comparison with the original construction.
Lukasz Krzywiecki, Adam Bobowski, Marta Slowik, Marcin Slowik, Patryk Koziel
Comput. Networks1
2019 Identity-Based Signature Scheme Secure in Ephemeral Setup and Leakage Scenarios
Lukasz Krzywiecki, Marta Slowik, Michal Szala
ISPEC1
2019 Signature Based Authentication for Ephemeral Setup Attacks in Vehicular Sensor Networks
abstract
In this paper, we focus on the communication security perspective for connected vehicles that can be categorized into: V2V (Vehicle to Vehicle), V2I (Vehicle to Infrastructure - such as with road side units or a cloud) and the internal vehicle network connections. V2V and V2I improve driving safety and comfort through the dissemination of critical warning messages. We propose a scheme resistant to ephemeral key leakage attacks that imposes pre-computation threat with respect to the static secret key. In particular, the pseudorandom generators that are implemented into the hardware are non-verifiable with respect to sustaining the true randomness while choosing ephemeral keys. We present a formal security model in which the adversary has power to inject ephemeral values of her choice to the protocol and still cannot deduce the static secret keys.
Lukasz Krzywiecki, Patryk Koziel, Nisha Panwar
NCA1
2018 Privacy-oriented dependency via deniable SIGMA protocol
Lukasz Krzywiecki, Kamil Kluczniak, Patryk Koziel, Nisha Panwar
Comput. Secur.1
2017 Deniable Key Establishment Resistance against eKCI Attacks
abstract
In extended Key Compromise Impersonation (eKCI) attack against authenticated key establishment (AKE) protocols the adversary impersonates one party, having the long term key and the ephemeral key of the other peer party. Such an attack can be mounted against variety of AKE protocols, including 3-pass HMQV. An intuitive countermeasure, based on BLS (Boneh–Lynn–Shacham) signatures, for strengthening HMQV was proposed in literature. The original HMQV protocol fulfills the deniability property: a party can deny its participation in the protocol execution, as the peer party can create a fake protocol transcript indistinguishable from the real one. Unfortunately, the modified BLS based version of HMQV is not deniable. In this paper we propose a method for converting HMQV (and similar AKE protocols) into a protocol resistant to eKCI attacks but without losing the original deniability property. For that purpose, instead of the undeniable BLS, we use a modification of Schnorr authentication protocol, which is deniable and immune to ephemeral key leakages.
Lukasz Krzywiecki, Tomasz Wlislocki
Secur. Commun. Networks1
2017 Dynamic attribute based vehicle authentication
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001
Wirel. Networks2
2016 RFID Tags Batch Authentication Revisited - Communication Overhead and Server Computational Complexity Limits
Przemyslaw Blaskiewicz, Lukasz Krzywiecki, Piotr Syga
ISPEC2
2016 Optical PUF for Non-Forwardable Vehicle Authentication
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001
Comput. Commun.2
2016 Vehicle authentication via monolithically certified public key and attributes
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001
Wirel. Networks2
2015 Optical PUF for Non Forwardable Vehicle Authentication
abstract
Modern vehicles are configured to exchange warning messages through IEEE 1609 Dedicated Short Range Communication (DSRC) over IEEE 802.11p Wireless Access in Vehicular Environment (WAVE). Essentially, these warning messages must associate an authentication factor such that the verifier authenticates the message origin via visual binding. Interestingly, the existing vehicle communication incorporates the message forward-ability as a requested feature for numerous applications. On the contrary, the vehicle security infrastructure is vulnerable to message forwarding i.e., Messages seem to originate from a malicious vehicle (due to non-detectable message relaying) instead of the actual message sender. We introduce the non forward-able authentication to avoid an adversary coalition attack scenario. These messages should be identifiable with respect to the immediate sender at every hop. We propose to utilize immediate optical response verification in association with the authenticated key exchange over radio channel. These optical responses are generated through hardware means, i.e., A certified Physically Unclonable Function (PUF) device embedded on the front and rear of the vehicle.
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001
NCA2
2014 Forbidden City Model - Towards a Practice Relevant Framework for Designing Cryptographic Protocols
Miroslaw Kutylowski, Lucjan Hanzlik, Kamil Kluczniak, Przemyslaw Kubiak 0001, Lukasz Krzywiecki
ISPEC5
2014 Dynamic Attribute Based Vehicle Authentication
abstract
In the near future, vehicles will establish a spontaneous connection over a wireless radio channel, coordinating actions and information. Security infrastructure is most important in such a hazardous scope of vehicles communication for coordinating actions and avoiding accidents on the roads. One of the first security issues that need to be established is authentication. Vehicle authentication with visual binding prior to establishing a wireless radio channel of communication is useful only when the vehicles possess unique visual attributes. These vehicle static attributes (e.g., Licence number, brand and color) are certified together with the vehicle public key. Therefore, we consider the case of multiple malicious vehicles with identical visual static attributes. Apparently, dynamic attributes (e.g., Location and direction) can uniquely define a vehicle and can be utilized to resolve the true identity of vehicles. However, unlike static attributes, dynamic attributes cannot be signed by a trusted authority beforehand. We propose an approach to verify the coupling between non-certified dynamic attributes and certified static attributes on an auxiliary communication channel, for example, a modulated laser beam. Furthermore, we illustrate that the proposed approach can be used to facilitate the usage of existing authentication protocols such as NAXOS, in the new scope of ad-hoc vehicle networks.
Shlomi Dolev, Lukasz Krzywiecki, Nisha Panwar, Michael Segal 0001
NCA2
2014 Deniable Version of SIGMA Key Exchange Protocol Resilient to Ephemeral Key Leakage
Lukasz Krzywiecki
ProvSec1
2014 Probabilistic Admissible Encoding on Elliptic Curves - Towards PACE with Generalized Integrated Mapping
Lukasz Krzywiecki, Przemyslaw Kubiak 0001, Miroslaw Kutylowski
SOFSEM1
2013 Simplified PACE|AA Protocol
Lucjan Hanzlik, Lukasz Krzywiecki, Miroslaw Kutylowski
ISPEC2
2012 Proof of Possession for Cloud Storage via Lagrangian Interpolation Techniques
Lukasz Krzywiecki, Miroslaw Kutylowski
NSS1
2010 Private Information Retrieval with a Trusted Hardware Unit - Revisited
Lukasz Krzywiecki, Miroslaw Kutylowski, Hubert Misztela, Tomasz Struminski
Inscrypt1
2008 Step-Out Ring Signatures
Marek Klonowski, Lukasz Krzywiecki, Miroslaw Kutylowski, Anna Lauks-Dutka
MFCS2
2008 General anonymous key broadcasting via Lagrangian interpolation
abstract
The authors presents a key management scheme for broadcast networks, which is a combination of broadcast encryption protocols of different kinds: an exclusion scheme based on Lagrangian interpolation in the exponent and a non-exclusion scheme. The authors show how to combine these techniques into one scheme in such a way that information on who is excluded and when they are excluded is hidden under certain adversary models, and communication overhead is independent of the system dynamics. Thus, the scheme is well suited for the general cases where the maximum number of excluded users is unpredictable.
Lukasz Krzywiecki, Miroslaw Kutylowski, Maciej Nikodem
IET Inf. Secur.1
2007 Random Subsets of the Interval and P2P Protocols
Jacek Cichon, Marek Klonowski, Lukasz Krzywiecki, Bartlomiej Rózanski, Pawel Zielinski 0001
APPROX-RANDOM3
2006 A Revocation Scheme Preserving Privacy
Lukasz Krzywiecki, Przemyslaw Kubiak 0001, Miroslaw Kutylowski
Inscrypt1