VLDB 2026 Research / reviewers in the wild / expert
Seny Kamara
dblp:66/664
· DBLP profile ↗
43ranked-venue papers
14as first author
16since 2021 · last 2026
0009-0000-1804-769XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 38 · 12 first-author · 13 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leafblower: a Leakage Attack Against Tee-Based Encrypted Databases
Zachary Espiritu, Seny Kamara, Tarik Moataz, Valentin Ogier |
SP | 2 |
| 2026 | tigro: Trust Infrastructure for Grassroots Organizing via Grounded Digital AnnotationsabstractGrassroots organizing requires establishing trust in digital artifacts (like event announcements or calls to action) while navigating significant security threats including surveillance, infiltration, and state violence. Traditional trust infrastructures like PKI and Web of Trust fail to address these specific needs, as they create public records of trust relationships that can expose activist networks and require institutional involvement that may be inaccessible or dangerous for marginalized communities. To address this, we introduce tigro, a novel trust infrastructure and system designed specifically for grassroots organizing contexts. Unlike conventional trust infrastructures, tigro implements a two-tier trust model: ground trust, which cryptographically binds digital annotations to physically vetted individuals, and artifact trust, which enables private, need-to-know sharing of assessments about digital content via annotations. Our protocol begins with an in-person key exchange that establishes a shared cryptographic key, creating a secure bridge between activists' existing physical vetting practices and their digital trust needs. To realize this approach, we define a new cryptographic primitive called an encrypted annotation system (EAS) and construct tigro using structured encryption and anonymous channels. We present two implementations with different security-performance tradeoffs: an efficient version for practical deployment that handles annotations in under a second, and a subliminal version that reveals virtually no metadata. Through this design, tigro enables activists to securely verify digital content without compromising relationship privacy or creating surveillance vulnerabilities, addressing a critical gap in existing trust infrastructure. Leah Namisa Rosenbloom, Seny Kamara, Zachary Espiritu, Tarik Moataz, Amine Bahi, John Wilkinson |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Structured Encryption and Distribution-Aware Leakage Suppression
Marilyn George, Seny Kamara, Tarik Moataz, Zachary Espiritu |
ASIACRYPT (2) | 2 |
| 2025 | PolySys: an Algebraic Leakage Attack Engine
Zachary Espiritu, Seny Kamara, Tarik Moataz |
USENIX Security Symposium | 2 |
| 2024 | Concurrent Encrypted Multimaps
Archita Agarwal, Seny Kamara, Tarik Moataz |
ASIACRYPT (4) | 2 |
| 2024 | Synq: Public Policy Analytics Over Encrypted DataabstractData analytics is a core part of modern decision making, especially in public policy. However, there exists a tension between data privacy and otherwise socially beneficial analytics when data sources contain personal information. We design Synq, a system that supports analytics over encrypted data while accounting for the usability considerations institutions may have when conducting studies that affect public policy. We specifically use an application-centric approach and model Synq’s design requirements from a large-scale series of studies conducted on the opioid epidemic in Massachusetts. We systematize the design considerations of the public policy context and demonstrate how the combination of design considerations that Synq addresses is novel through a survey of the literature. We then present our protocol which combines structured encryption, somewhat homomorphic encryption, and oblivious pseudorandom functions to support a complex query language that includes filtering (retrieving rows by attribute/value pairs), linking (merging rows from different tables that represent the same individual) and aggregate functions (sum, count, average, variance, regression). We formally express the security of our protocol and show that Synq is efficient in practice while satisfying usability considerations that are critical to deployment in the setting of public policy studies. Zachary Espiritu, Marilyn George, Seny Kamara, Lucy Qin |
SP | 3 |
| 2024 | MAPLE: MArkov Process Leakage attacks on Encrypted SearchabstractEncrypted search algorithms (ESAs) enable private search on encrypted data and can be constructed from a variety of cryptographic primitives. All knownsub-linear ESA algorithms leak information and, therefore, the design of leakage attacks is an important way to ascertain whether a given leakage profile is exploitable in practice. Recently,Oya and Kerschbaum(Usenix '22) presented an attack called IHOP that targets the query equality pattern which reveals if and when two queries are for the same keyword of a sequence of dependent queries. In this work, we continue the study of query equality leakage on dependent queries and present two new attacks in this setting which can work either as known-distribution or known-sample attacks. They model query distributions as Markov processes and leverage insights and techniques from stochastic processes and machine learning. We implement our attacks and evaluate them on real-world query logs. Our experiments show that they outperform the state-of-the-art in most settings but also have limitations inpractical settings. Seny Kamara, Abdelkarim Kati, Tarik Moataz, Jamie DeMaria, Amos Treiber |
Proc. Priv. Enhancing Technol. | 1 |
| 2023 | Injection-Secure Structured and Searchable Symmetric Encryption
Ghous Amjad, Seny Kamara, Tarik Moataz |
ASIACRYPT (6) | 2 |
| 2022 | Adversarial Level Agreements for Two-Party ProtocolsabstractAdversaries in cryptography have traditionally been modeled as either semi-honest or malicious. Over the years, however, several works have investigated the design of cryptographic protocols against rational adversaries. The most well-known example are covert adversaries in secure computation (Aumann & Lindell, TCC '07) which are adversaries that wish to deviate from the protocol but without being detected. Protocols secure against such covert adversaries guarantee that deviations are detected with probability at least - which is known as the deterrence factor. Marilyn George, Seny Kamara |
AsiaCCS | 2 |
| 2022 | SoK: Cryptanalysis of Encrypted Search with LEAKER - A framework for LEakage AttacK Evaluation on Real-world dataabstractAn encrypted search algorithm (ESA) allows a user to encrypt its data while preserving the ability to search over it. As all practical solutions leak some information, cryptanalysis plays an important role in the area of encrypted search. Starting with the work of Islam et al. (NDSS'12), many attacks have been proposed that exploit different leakage profiles under various assumptions. While these attacks improve our understanding of leakage, it can sometimes be difficult to draw definite conclusions about their practical performance. This is due to several reasons, including a lack of open-source implementations (which are needed to reproduce results), empirical evaluations that are conducted on restricted datasets, and in some cases reliance on relatively strong assumptions that can significantly affect accuracy. In this work, we address these limitations. First, we design and implement LEAKER, an open-source framework that evaluates the major leakage attacks against any dataset and that we hope will serve the community as a common way to evaluate leakage attacks. We identify new real-world datasets that capture different use cases for ESAs and, for the first time, include real-world user queries. Finally, we use LEAKER to systematically evaluate known attacks on our datasets, uncovering sometimes unexpected properties that increase or diminish accuracy. Our evaluation shows that some attacks work better on real-world data than previously thought and that others perform worse. Seny Kamara, Abdelkarim Kati, Tarik Moataz, Thomas Schneider 0003, Amos Treiber, Michael Yonli |
EuroS&P | 1 |
| 2022 | Encrypted Distributed SystemsabstractDistributed computing is at the heart of modern system architectures and infrastructures. But as security and privacy have increasingly become critical to every organization, modern cryptography is making its way into core systems. In this talk, I will describe work that focuses on using modern cryptographic techniques in large scale practical distributed systems in order to improve their security and privacy guarantees. I will show how both cryptographic techniques and distributed systems need to be adapted to make this work and how to think about the security of these new encrypted distributed systems. Seny Kamara |
PODC | 1 |
| 2021 | Efficient Graph Encryption Scheme for Shortest Path QueriesabstractGraph encryption schemes (introduced by [Chase and Kamara, 2010]) have been receiving growing interest across various disciplines due to their attractive tradeoff between functionality, efficiency and privacy. In this paper, we advance the state of the art on encrypted graph search by providing an efficient graph encryption scheme for shortest path queries. The preprocessing time and space and the query time are proportional to those for building and querying the search structure for the unencrypted graph. Hence, the overhead of providing structured encryption is asymptotically optimal. We implement our scheme and experimentally validate its performance on real world networks. Furthermore, we extend our scheme to support verifiability. Esha Ghosh, Seny Kamara, Roberto Tamassia |
AsiaCCS | 2 |
| 2021 | Encrypted Databases: From Theory to Systems
Zheguang Zhao, Seny Kamara, Tarik Moataz, Stanley B. Zdonik |
CIDR | 2 |
| 2021 | Structured Encryption and Dynamic Leakage Suppression
Marilyn George, Seny Kamara, Tarik Moataz |
EUROCRYPT (3) | 2 |
| 2021 | Algorithms for the People
Seny Kamara |
FMCAD | 1 |
| 2021 | A Decentralized and Encrypted National Gun RegistryabstractGun violence results in a significant number of deaths in the United States. Starting in the 1960’s, the US Congress passed a series of gun control laws to regulate the sale and use of firearms. One of the most important but politically fraught gun control measures is a national gun registry. A US Senate office is currently drafting legislation that proposes the creation of a voluntary national gun registration system. At a high level, the bill envisions a decentralized system where local county officials would control and manage the registration data of their constituents. These local databases could then be queried by other officials and law enforcement to trace guns. Due to the sensitive nature of this data, however, these databases should guarantee the confidentiality of the data.In this work, we translate the high-level vision of the proposed legislation into technical requirements and design a crypto- graphic protocol that meets them. Roughly speaking, the protocol can be viewed as a decentralized system of locally-managed end-to-end encrypted databases. Our design relies on various cryptographic building blocks including structured encryption, secure multi-party computation and secret sharing. We propose a formal security definition and prove that our design meets it. We implemented our protocol and evaluated its performance empirically at the scale it would have to run if it were deployed in the United States. Our results show that a decentralized and end-to-end encrypted national gun registry is not only possible in theory but feasible in practice. Seny Kamara, Tarik Moataz, Lucy Qin |
SP | 1 |
| 2020 | Encrypted Blockchain DatabasesabstractBlockchain databases are storage systems that combine properties of blockchains and databases like decentralization, tamperproofness, low query latency and support for complex queries. Blockchain databases are an emerging and important class of blockchain technology that is critical to the development of non-trivial smart contracts, distributed applications and decentralized marketplaces. Daniel Adkins, Archita Agarwal, Seny Kamara, Tarik Moataz |
AFT | 3 |
| 2020 | Revisiting Leakage Abuse Attacks
Laura Blackstone, Seny Kamara, Tarik Moataz |
NDSS | 2 |
| 2019 | Computationally Volume-Hiding Structured Encryption
Seny Kamara, Tarik Moataz |
EUROCRYPT (2) | 1 |
| 2019 | Encrypted Databases for Differential PrivacyabstractAbstract The problem of privatizing statistical databases is a well-studied topic that has culminated with the notion of differential privacy. The complementary problem of securing these differentially private databases, however, has—as far as we know—not been considered in the past. While the security of private databases is in theory orthogonal to the problem of private statistical analysis (e.g., in the central model of differential privacy the curator is trusted) the recent real-world deployments of differentially-private systems suggest that it will become a problem of increasing importance. In this work, we consider the problem of designing encrypted databases (EDB) that support differentially-private statistical queries. More precisely, these EDBs should support a set of encrypted operations with which a curator can securely query and manage its data, and a set of private operations with which an analyst can privately analyze the data. Using such an EDB, a curator can securely outsource its database to an untrusted server (e.g., on-premise or in the cloud) while still allowing an analyst to privately query it. We show how to design an EDB that supports private histogram queries. As a building block, we introduce a differentially-private encrypted counter based on the binary mechanism of Chan et al. (ICALP, 2010). We then carefully combine multiple instances of this counter with a standard encrypted database scheme to support differentially-private histogram queries. Archita Agarwal, Maurice Herlihy, Seny Kamara, Tarik Moataz |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | Breach-Resistant Structured EncryptionabstractAbstract Motivated by the problem of data breaches, we formalize a notion of security for dynamic structured encryption (STE) schemes that guarantees security against a snapshot adversary; that is, an adversary that receives a copy of the encrypted structure at various times but does not see the transcripts related to any queries. In particular, we focus on the construction of dynamic encrypted multi-maps which are used to build efficient searchable symmetric encryption schemes, graph encryption schemes and encrypted relational databases. Interestingly, we show that a form of snapshot security we refer to as breach resistance implies previously-studied notions such as a (weaker version) of history independence and write-only obliviousness. Moreover, we initiate the study of dual-secure dynamic STE constructions: schemes that are forward-private against a persistent adversary and breach-resistant against a snapshot adversary. The notion of forward privacy guarantees that updates to the encrypted structure do not reveal their association to any query made in the past. As a concrete instantiation, we propose a new dual-secure dynamic multi-map encryption scheme that outperforms all existing constructions; including schemes that are not dual-secure. Our construction has query complexity that grows with the selectivity of the query and the number of deletes since the client executed a linear-time rebuild protocol which can be de-amortized. We implemented our scheme (with the de-amortized rebuild protocol) and evaluated its concrete efficiency empirically. Our experiments show that it is highly efficient with queries taking less than 1 microsecond per label/value pair. Ghous Amjad, Seny Kamara, Tarik Moataz |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | DogFish: Decentralized Optimistic Game-theoretic FIle SHaring
Seny Kamara, Alptekin Küpçü |
ACNS | 1 |
| 2018 | SQL on Structurally-Encrypted Databases
Seny Kamara, Tarik Moataz |
ASIACRYPT (1) | 1 |
| 2018 | Structured Encryption and Leakage Suppression
Seny Kamara, Tarik Moataz, Olga Ohrimenko |
CRYPTO (1) | 1 |
| 2017 | Boolean Searchable Symmetric Encryption with Worst-Case Sub-linear Complexity
Seny Kamara, Tarik Moataz |
EUROCRYPT (3) | 1 |
| 2015 | GRECS: Graph Encryption for Approximate Shortest Distance QueriesabstractWe propose graph encryption schemes that efficiently support approximate shortest distance queries on large-scale encrypted graphs. Shortest distance queries are one of the most fundamental graph operations and have a wide range of applications. Using such graph encryption schemes, a client can outsource large-scale privacy-sensitive graphs to an untrusted server without losing the ability to query it. Other applications include encrypted graph databases and controlled disclosure systems. We propose GRECS (stands for GRaph EnCryption for approximate Shortest distance queries) which includes three oracle encryption schemes that are provably secure against any semi-honest server. Our first construction makes use of only symmetric-key operations, resulting in a computationally-efficient construction. Our second scheme makes use of somewhat-homomorphic encryption and is less computationally-efficient but achieves optimal communication complexity (i.e. uses a minimal amount of bandwidth). Finally, our third scheme is both computationally-efficient and achieves optimal communication complexity at the cost of a small amount of additional leakage. We implemented and evaluated the efficiency of our constructions experimentally. The experiments demonstrate that our schemes are efficient and can be applied to graphs that scale up to 1.6 million nodes and 11 million edges. Xianrui Meng, Seny Kamara, Kobbi Nissim, George Kollios |
CCS | 2 |
| 2015 | Inference Attacks on Property-Preserving Encrypted DatabasesabstractMany encrypted database (EDB) systems have been proposed in the last few years as cloud computing has grown in popularity and data breaches have increased. The state-of-the-art EDB systems for relational databases can handle SQL queries over encrypted data and are competitive with commercial database systems. These systems, most of which are based on the design of CryptDB (SOSP 2011), achieve these properties by making use of property-preserving encryption schemes such as deterministic (DTE) and order- preserving encryption (OPE). In this paper, we study the concrete security provided by such systems. We present a series of attacks that recover the plaintext from DTE- and OPE-encrypted database columns using only the encrypted column and publicly-available auxiliary information. We consider well-known attacks, including frequency analysis and sorting, as well as new attacks based on combinatorial optimization. Muhammad Naveed 0001, Seny Kamara, Charles V. Wright |
CCS | 2 |
| 2015 | Leakage-Resilient Identification Schemes from Zero-Knowledge Proofs of Storage
Giuseppe Ateniese, Antonio Faonio, Seny Kamara |
IMACC | 3 |
| 2013 | Tight bounds for online vector bin packingabstractIn the d-dimensional bin packing problem (VBP), one is given vectors x1,x2, ... ,xn ∈ Rd and the goal is to find a partition into a minimum number of feasible sets: {1,2 ... ,n} = ∪is Bi. A set Bi is feasible if ∑j ∈ Bi xj ≤ 1, where 1 denotes the all 1's vector. For online VBP, it has been outstanding for almost 20 years to clarify the gap between the best lower bound Ω(1) on the competitive ratio versus the best upper bound of O(d). We settle this by describing a Ω(d1-ε) lower bound. We also give strong lower bounds (of Ω(d1/B-ε) ) if the bin size B ∈ Z+ is allowed to grow. Finally, we discuss almost-matching upper bound results for general values of B; we show an upper bound whose exponent is additively "shifted by 1" from the lower bound exponent. Yossi Azar, Ilan Reuven Cohen, Seny Kamara, F. Bruce Shepherd |
STOC | 3 |
| 2012 | 4th cloud computing security workshop (CCSW 2012)abstractNotwithstanding the latest buzzword (grid, cloud, utility computing, SaaS, etc.), large-scale computing and cloud-like infrastructures are here to stay. How exactly they will look like tomorrow is still for the markets to decide, yet one thing is certain: clouds bring with them new untested deployment and associated adversarial models and vulnerabilities. It is essential that our community becomes involved at this early stage. The CCSW workshop aims to bring together researchers and practitioners in all security aspects of cloud-centric and outsourced computing to act as a fertile ground for creative debate and interaction in security-sensitive areas of computing impacted by clouds. Srdjan Capkun, Seny Kamara |
CCS | 2 |
| 2012 | Salus: a system for server-aided secure function evaluationabstractSecure function evaluation (SFE) allows a set of mutually distrustful parties to evaluate a function of their joint inputs without revealing their inputs to each other. SFE has been the focus of active research and recent work suggests that it can be made practical. Unfortunately, current protocols and implementations have inherent limitations that are hard to overcome using standard and practical techniques. Among them are: (1) requiring participants to do work linear in the size of the circuit representation of the function; (2) requiring all parties to do the same amount of work; and (3) not being able to provide complete fairness. Seny Kamara, Payman Mohassel, Ben Riva |
CCS | 1 |
| 2012 | Dynamic searchable symmetric encryptionabstractSearchable symmetric encryption (SSE) allows a client to encrypt its data in such a way that this data can still be searched. The most immediate application of SSE is to cloud storage, where it enables a client to securely outsource its data to an untrusted cloud provider without sacrificing the ability to search over it. Seny Kamara, Charalampos Papamanthou, Tom Roeder |
CCS | 1 |
| 2012 | Inspection resistant memory: Architectural support for security from physical examinationabstractThe ability to safely keep a secret in memory is central to the vast majority of security schemes, but storing and erasing these secrets is a difficult problem in the face of an attacker who can obtain unrestricted physical access to the underlying hardware. Depending on the memory technology, the very act of storing a 1 instead of a 0 can have physical side effects measurable even after the power has been cut. These effects cannot be hidden easily, and if the secret stored on chip is of sufficient value, an attacker may go to extraordinary means to learn even a few bits of that information. Solving this problem requires a new class of architectures that measurably increase the difficulty of physical analysis. In this paper we take a first step towards this goal by focusing on one of the backbones of any hardware system: on-chip memory. We examine the relationship between security, area, and efficiency in these architectures, and quantitatively examine the resulting systems through cryptographic analysis and microarchitectural impact. In the end, we are able to find an efficient scheme in which, even if an adversary is able to inspect the value of a stored bit with a probabilistic error of only 5%, our system will be able to prevent that adversary from learning any information about the original un-coded bits with 99.9999999999% probability. Jonathan Valamehr, Melissa Chase, Seny Kamara, Andrew Putnam, Daniel Shumow, Vinod Vaikuntanathan, Timothy Sherwood |
ISCA | 3 |
| 2011 | Searchable symmetric encryption: Improved definitions and efficient constructionsabstractSearchable symmetric encryption (SSE) allows a party to outsource the storage of his data to another party in a private manner, while maintaining the ability to selectively search over it. This problem has been the focus of active research and several security definitions and constructions have been proposed. In this paper we begin by reviewing existing notions of security and propose new and stronger security definitions. We then present two constructions that we show secure under our new definitions. Interestingly, in addition to satisfying stronger security guarantees, our constructions are more efficient than all previous constructions. Further, prior work on SSE only considered the setting where only the owner of the data is capable of submitting search queries. We consider the natural extension where an arbitrary group of parties other than the owner can submit search queries. We formally define SSE in this multi-user setting, and present an efficient construction. Reza Curtmola, Juan A. Garay 0001, Seny Kamara, Rafail Ostrovsky |
J. Comput. Secur. | 3 |
| 2010 | Structured Encryption and Controlled Disclosure
Melissa Chase, Seny Kamara |
ASIACRYPT | 2 |
| 2009 | Proofs of Storage from Homomorphic Identification Protocols
Giuseppe Ateniese, Seny Kamara, Jonathan Katz |
ASIACRYPT | 2 |
| 2008 | Towards practical biometric key generation with randomized biometric templatesabstractAlthough biometrics have garnered significant interest as a source of entropy for cryptographic key generation, recent studies indicate that many biometric modalities may not actually offer enough uncertainty for this purpose. In this paper, we exploit a novel source of entropy that can be used with any biometric modality but that has yet to be utilized for key generation, namely associating uncertainty with the way in which the biometric input is measured. Our construction poses only a modest requirement on a user: the ability to remember a low-entropy password. We identify the technical challenges of this approach, and develop novel techniques to overcome these difficulties. Our analysis of this approach indicates that it may offer the potential to generate stronger keys: In our experiments, 40% of the users are able to generate keys that are at least 230 times stronger than passwords alone. Lucas Ballard, Seny Kamara, Fabian Monrose, Michael K. Reiter |
CCS | 2 |
| 2008 | How to Encrypt with a Malicious Random Number Generator
Seny Kamara, Jonathan Katz |
FSE | 1 |
| 2008 | The Practical Subtleties of Biometric Key Generation
Lucas Ballard, Seny Kamara, Michael K. Reiter |
USENIX Security Symposium | 2 |
| 2006 | Searchable symmetric encryption: improved definitions and efficient constructionsabstractSearchable symmetric encryption (SSE) allows a party to outsource the storage of its data to another party (a server) in a private manner, while maintaining the ability to selectively search over it. This problem has been the focus of active research in recent years. In this paper we show two solutions to SSE that simultaneously enjoy the following properties: Reza Curtmola, Juan A. Garay 0001, Seny Kamara, Rafail Ostrovsky |
CCS | 3 |
| 2006 | Key Regression: Enabling Efficient Key Distribution for Secure Distributed Storage
Kevin Fu, Seny Kamara, Yoshi Kohno |
NDSS | 2 |
| 2005 | Achieving Efficient Conjunctive Keyword Searches over Encrypted Data
Lucas Ballard, Seny Kamara, Fabian Monrose |
ICICS | 2 |
| 2003 | Analysis of vulnerabilities in Internet firewalls
Seny Kamara, Sonia Fahmy, E. Eugene Schultz, Florian Kerschbaum, Michael Frantzen |
Comput. Secur. | 1 |