VLDB 2026 Research / reviewers in the wild / expert
Shweta Agrawal 0001
dblp:74/6138-1
· DBLP profile ↗
53ranked-venue papers
48as first author
23since 2021 · last 2026
0000-0002-7692-4686ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 42 first-author · 21 since 2021Theory of computation · 15 · 14 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Post-quantum Public-Key Pseudorandom Correlation Functions for OT
Shweta Agrawal 0001, Kaartik Bhushan, Geoffroy Couteau, Mahshid Riahinia |
CRYPTO (8) | 1 |
| 2025 | Pseudorandom FE, iO and Applications
Shweta Agrawal 0001, Simran Kumari, Shota Yamada 0001 |
TCC (2) | 1 |
| 2025 | Zeroizing Attacks Against Evasive and Circular Evasive LWE
Shweta Agrawal 0001, Anuja Modi, Anshu Yadav, Shota Yamada 0001 |
TCC (2) | 1 |
| 2024 | Attribute Based Encryption for Turing Machines from Lattices
Shweta Agrawal 0001, Simran Kumari, Shota Yamada 0001 |
CRYPTO (3) | 1 |
| 2024 | k-SUM in the Sparse Regime: Complexity and Applications
Shweta Agrawal 0001, Sagnik Saha, Nikolaj I. Schwartzbach, Akhil Vanukuri, Prashant Nalini Vasudevan |
CRYPTO (2) | 1 |
| 2024 | Time-Lock Puzzles from Lattices
Shweta Agrawal 0001, Giulio Malavolta |
CRYPTO (3) | 1 |
| 2023 | Constant Input Attribute Based (and Predicate) Encryption from Evasive and Tensor LWE
Shweta Agrawal 0001, Melissa Rossi, Anshu Yadav, Shota Yamada 0001 |
CRYPTO (4) | 1 |
| 2023 | Attribute-Based Multi-input FE (and More) for Attribute-Weighted Sums
Shweta Agrawal 0001, Junichi Tomida, Anshu Yadav |
CRYPTO (4) | 1 |
| 2023 | Public Key Encryption with Secure Key Leasing
Shweta Agrawal 0001, Fuyuki Kitagawa, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
EUROCRYPT (1) | 1 |
| 2023 | Broadcast, Trace and Revoke with Optimal Parameters from Polynomial Hardness
Shweta Agrawal 0001, Simran Kumari, Anshu Yadav, Shota Yamada 0001 |
EUROCRYPT (3) | 1 |
| 2023 | Quadratic Functional Encryption for Secure Training in Vertical Federated LearningabstractVertical federated learning (VFL) enables the collaborative training of machine learning (ML) models in settings where the data is distributed amongst multiple parties who wish to protect the privacy of their individual data. Notably, in VFL, the labels are available to a single party and the complete feature set is formed only when data from all parties is combined. Recently, Xu et al. [1] proposed a new framework called FedV for secure gradient computation for VFL using multi-input functional encryption. In this work, we explain how some of the information leakage in Xu et al. can be avoided by using Quadratic functional encryption when training generalized linear models for vertical federated learning. Shuangyi Chen, Anuja Modi, Shweta Agrawal 0001, Ashish Khisti |
ISIT | 3 |
| 2023 | CASE: A New Frontier in Public-Key Authenticated Encryption
Shashank Agrawal, Shweta Agrawal 0001, Manoj Prabhakaran 0001, Rajeev Raghunath, Jayesh Singla |
TCC (2) | 2 |
| 2022 | Practical, Round-Optimal Lattice-Based Blind SignaturesabstractBlind signatures are a fundamental cryptographic primitive with numerous practical applications. While there exist many practical blind signatures from number-theoretic assumptions, the situation is far less satisfactory from post-quantum assumptions. In this work, we provide the first overall practical, lattice-based blind signature, supporting an unbounded number of signature queries and additionally enjoying optimal round complexity. We provide a detailed estimate of parameters achieved -- we obtain a signature of size slightly above 45KB, for a core-SVP hardness of 109 bits. The run-times of the signer, user and verifier are also very small. Shweta Agrawal 0001, Elena Kirshanova, Damien Stehlé, Anshu Yadav |
CCS | 1 |
| 2022 | Multi-input Attribute Based Encryption and Predicate Encryption
Shweta Agrawal 0001, Anshu Yadav, Shota Yamada 0001 |
CRYPTO (1) | 1 |
| 2022 | Round-Optimal Lattice-Based Threshold Signatures, RevisitedabstractThreshold signature schemes enable distribution of the signature issuing capability to multiple users, to mitigate the threat of signing key compromise. Though a classic primitive, these signatures have witnessed a surge of interest in recent times due to relevance to modern applications like blockchains and cryptocurrencies. In this work, we study round-optimal threshold signatures in the post-quantum regime and improve the only known lattice-based construction by Boneh et al. [CRYPTO'18] as follows: - Efficiency. We reduce the amount of noise flooding used in the construction from 2^Ω(λ) down to √Q, where Q is the bound on the number of generated signatures and λ is the security parameter. By using lattice hardness assumptions over polynomial rings, this allows to decrease the signature bit-lengths from Õ(λ³) to Õ(λ), bringing them significantly closer to practice. Our improvement relies on a careful analysis using Rényi divergence rather than statistical distance in the security proof. - Instantiation. The construction of Boneh et al. requires a standard signature scheme to be evaluated homomorphically. To instantiate this, we provide a homomorphism-friendly variant of Lyubashevsky’s signature [EUROCRYPT '12] which achieves low circuit depth by being "rejection-free" and uses an optimal, moderate noise flooding of √Q, matching the above. - Towards Adaptive Security. The construction of Boneh et al. satisfies only selective security, where all the corrupted parties must be announced before any signing query is made. We improve this in two ways: in the Random Oracle Model, we obtain partial adaptivity where signing queries can be made before the corrupted parties are announced but the set of corrupted parties must be announced all at once. In the standard model, we obtain full adaptivity, where parties can be corrupted at any time but this construction is in a weaker pre-processing model where signers must be provided correlated randomness of length proportional to the number of signatures, in an offline preprocessing phase. Shweta Agrawal 0001, Damien Stehlé, Anshu Yadav |
ICALP | 1 |
| 2022 | Multi-Input Quadratic Functional Encryption: Stronger Security, Broader Functionality
Shweta Agrawal 0001, Rishab Goyal, Junichi Tomida |
TCC (1) | 1 |
| 2022 | Bounded Functional Encryption for Turing Machines: Adaptive Security from General Assumptions
Shweta Agrawal 0001, Fuyuki Kitagawa, Anuja Modi, Ryo Nishimaki, Shota Yamada 0001, Takashi Yamakawa |
TCC (1) | 1 |
| 2022 | Cryptanalysis of Boyen's attribute-based encryption scheme in TCC 2013
Shweta Agrawal 0001, Rajarshi Biswas, Ryo Nishimaki, Keita Xagawa, Shota Yamada 0001 |
Des. Codes Cryptogr. | 1 |
| 2021 | Deniable Fully Homomorphic Encryption from Learning with Errors
Shweta Agrawal 0001, Shafi Goldwasser, Saleet Mossel |
CRYPTO (2) | 1 |
| 2021 | Multi-input Quadratic Functional Encryption from Pairings
Shweta Agrawal 0001, Rishab Goyal, Junichi Tomida |
CRYPTO (4) | 1 |
| 2021 | Secure Computation from One-Way Noisy Communication, or: Anti-correlation via Anti-concentration
Shweta Agrawal 0001, Yuval Ishai, Eyal Kushilevitz, Varun Narayanan, Manoj Prabhakaran 0001, Vinod M. Prabhakaran, Alon Rosen |
CRYPTO (2) | 1 |
| 2021 | Functional Encryption for Turing Machines with Dynamic Bounded Collusion from LWE
Shweta Agrawal 0001, Monosij Maitra, Narasimha Sai Vempati, Shota Yamada 0001 |
CRYPTO (4) | 1 |
| 2021 | Multi-Party Functional Encryption
Shweta Agrawal 0001, Rishab Goyal, Junichi Tomida |
TCC (2) | 1 |
| 2020 | Cryptography from One-Way Communication: On Completeness of Finite Channels
Shweta Agrawal 0001, Yuval Ishai, Eyal Kushilevitz, Varun Narayanan, Manoj Prabhakaran 0001, Vinod M. Prabhakaran, Alon Rosen |
ASIACRYPT (3) | 1 |
| 2020 | A Practical Model for Collaborative Databases: Securely Mixing, Searching and Computing
Shweta Agrawal 0001, Rachit Garg 0001, Nishant Kumar 0001, Manoj Prabhakaran 0001 |
ESORICS (1) | 1 |
| 2020 | Optimal Broadcast Encryption from Pairings and LWE
Shweta Agrawal 0001, Shota Yamada 0001 |
EUROCRYPT (1) | 1 |
| 2020 | Indistinguishability Obfuscation Without Maps: Attacks and Fixes for Noisy Linear FE
Shweta Agrawal 0001, Alice Pellet-Mary |
EUROCRYPT (1) | 1 |
| 2020 | Ad Hoc Multi-Input Functional EncryptionabstractConsider sources that supply sensitive data to an aggregator. Standard encryption only hides the data from eavesdroppers, but using specialized encryption one can hope to hide the data (to the extent possible) from the aggregator itself. For flexibility and security, we envision schemes that allow sources to supply encrypted data, such that at any point a dynamically-chosen subset of sources can allow an agreed-upon joint function of their data to be computed by the aggregator. A primitive called multi-input functional encryption (MIFE), due to Goldwasser et al. (EUROCRYPT 2014), comes close, but has two main limitations: - it requires trust in a third party, who is able to decrypt all the data, and - it requires function arity to be fixed at setup time and to be equal to the number of parties. To drop these limitations, we introduce a new notion of ad hoc MIFE. In our setting, each source generates its own public key and issues individual, function-specific secret keys to an aggregator. For successful decryption, an aggregator must obtain a separate key from each source whose ciphertext is being computed upon. The aggregator could obtain multiple such secret-keys from a user corresponding to functions of varying arity. For this primitive, we obtain the following results: - We show that standard MIFE for general functions can be bootstrapped to ad hoc MIFE for free, i.e. without making any additional assumption. - We provide a direct construction of ad hoc MIFE for the inner product functionality based on the Learning with Errors (LWE) assumption. This yields the first construction of this natural primitive based on a standard assumption. At a technical level, our results are obtained by combining standard MIFE schemes and two-round secure multiparty computation (MPC) protocols in novel ways highlighting an interesting interplay between MIFE and two-round MPC. Shweta Agrawal 0001, Michael Clear, Ophir Frieder, Sanjam Garg, Adam O'Neill, Justin Thaler |
ITCS | 1 |
| 2020 | CP-ABE for Circuits (and More) in the Symmetric Key Setting
Shweta Agrawal 0001, Shota Yamada 0001 |
TCC (1) | 1 |
| 2020 | Optimal Broadcast Encryption from LWE and Pairings in the Standard Model
Shweta Agrawal 0001, Daniel Wichs, Shota Yamada 0001 |
TCC (1) | 1 |
| 2019 | Attribute Based Encryption (and more) for Nondeterministic Finite Automata from LWE
Shweta Agrawal 0001, Monosij Maitra, Shota Yamada 0001 |
CRYPTO (2) | 1 |
| 2019 | Indistinguishability Obfuscation Without Multilinear Maps: New Methods for Bootstrapping and Instantiation
Shweta Agrawal 0001 |
EUROCRYPT (1) | 1 |
| 2019 | Attribute Based Encryption for Deterministic Finite Automata from \mathsfDLIN
Shweta Agrawal 0001, Monosij Maitra, Shota Yamada 0001 |
TCC (2) | 1 |
| 2018 | Wiretap Polar Codes in Encryption Schemes Based on Learning with Errors ProblemabstractThe Learning with Errors (LWE) problem has been extensively studied in cryptography due to its strong hardness guarantees, efficiency and expressiveness in constructing advanced cryptographic primitives. In this work, we show that using polar codes in conjunction with LWE-based encryption yields several advantages. To begin, we demonstrate the obvious improvements in the efficiency or rate of information transmission in the LWE-based scheme by leveraging polar coding (with no change in the cryptographic security guarantee). Next, we integrate wiretap polar coding with LWE-based encryption to ensure provable semantic security over a wiretap channel in addition to cryptographic security based on the hardness of LWE. To the best of our knowledge this is the first wiretap code to have cryptographic security guarantees as well. Finally, we study the security of the private key used in LWE-based encryption with wiretap polar coding, and propose a key refresh method using random bits used in wiretap coding. Under a known-plaintext attack, we show that non-vanishing information-theoretic secrecy can be achieved for the key. We believe our approach is at least as interesting as our final results: our work combines cryptography and coding theory in a novel “non blackbox-way” which may be relevant to other scenarios as well. Aswin Rajagopalan, Andrew Thangaraj, Shweta Agrawal 0001 |
ISIT | 3 |
| 2018 | FE and iO for Turing Machines from Minimal Assumptions
Shweta Agrawal 0001, Monosij Maitra |
TCC (2) | 1 |
| 2017 | Efficient Public Trace and Revoke from Standard Assumptions: Extended AbstractabstractWe provide efficient constructions for trace-and-revoke systems with public traceability in the black-box confirmation model. Our constructions achieve adaptive security, are based on standard assumptions and achieve significant efficiency gains compared to previous constructions. Shweta Agrawal 0001, Sanjay Bhattacherjee, Duong Hieu Phan, Damien Stehlé, Shota Yamada 0001 |
CCS | 1 |
| 2017 | Stronger Security for Reusable Garbled Circuits, General Definitions and Attacks
Shweta Agrawal 0001 |
CRYPTO (1) | 1 |
| 2017 | Functional Encryption for Bounded Collusions, Revisited
Shweta Agrawal 0001, Alon Rosen |
TCC (1) | 1 |
| 2016 | Fully Secure Functional Encryption for Inner Products, from Standard Assumptions
Shweta Agrawal 0001, Benoît Libert, Damien Stehlé |
CRYPTO (3) | 1 |
| 2016 | Adaptive protocols for interactive communicationabstractHow much adversarial noise can protocols for interactive communication tolerate? This question was examined by Braverman and Rao (IEEE Trans. Inf. Theory, 2014) for the case of “robust” protocols, where each party sends messages only in fixed and predetermined rounds. We consider a new class of protocols for interactive communication, which we call adaptive protocols. Such protocols adapt structurally to the noise induced by the channel in the sense that both the order of speaking, and the length of the protocol may vary depending on observed noise. We define models that capture adaptive protocols and study upper and lower bounds on the permissible noise rate in these models. When the length of the protocol may adaptively change according to the noise, we demonstrate a protocol that tolerates noise rates up to 1/3. When the order of speaking may adaptively change as well, we demonstrate a protocol that tolerates noise rates up to 2/3. Hence, adaptivity circumvents an impossibility result of 1/4 on the fraction of tolerable noise (Braverman and Rao, 2014). Shweta Agrawal 0001, Ran Gelles, Amit Sahai |
ISIT | 1 |
| 2015 | Cryptographic Agents: Towards a Unified Theory of Computing on Encrypted Data
Shashank Agrawal, Shweta Agrawal 0001, Manoj Prabhakaran 0001 |
EUROCRYPT (2) | 2 |
| 2015 | Statistical Randomized Encodings: A Complexity Theoretic View
Shweta Agrawal 0001, Yuval Ishai, Dakshita Khurana, Anat Paskin-Cherniavsky |
ICALP (1) | 1 |
| 2013 | On Continual Leakage of Discrete Log Representations
Shweta Agrawal 0001, Yevgeniy Dodis, Vinod Vaikuntanathan, Daniel Wichs |
ASIACRYPT (2) | 1 |
| 2013 | Discrete Gaussian Leftover Hash Lemma over Infinite Domains
Shweta Agrawal 0001, Craig Gentry, Shai Halevi, Amit Sahai |
ASIACRYPT (1) | 1 |
| 2013 | Functional Encryption: New Perspectives and Lower Bounds
Shweta Agrawal 0001, Sergey Gorbunov 0001, Vinod Vaikuntanathan, Hoeteck Wee |
CRYPTO (2) | 1 |
| 2012 | New Impossibility Results for Concurrent Composition and a Non-interactive Completeness Theorem for Secure Computation
Shweta Agrawal 0001, Vipul Goyal, Abhishek Jain 0002, Manoj Prabhakaran 0001, Amit Sahai |
CRYPTO | 1 |
| 2011 | Functional Encryption for Inner Product Predicates from Learning with Errors
Shweta Agrawal 0001, David Mandell Freeman, Vinod Vaikuntanathan |
ASIACRYPT | 1 |
| 2011 | Secrecy using compressive sensingabstractThis paper uses the compressive sensing framework to establish secure physical layer communication over a Wyner wiretap channel. The idea, at its core, is simple - the paper shows that compressive sensing can exploit channel asymmetry so that a message, encoded as a sparse vector, is decodable with high probability at the legitimate receiver while it is impossible to decode it with high probability at the eavesdropper. Shweta Agrawal 0001, Sriram Vishwanath |
ITW | 1 |
| 2010 | Lattice Basis Delegation in Fixed Dimension and Shorter-Ciphertext Hierarchical IBE
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen |
CRYPTO | 1 |
| 2010 | Efficient Lattice (H)IBE in the Standard Model
Shweta Agrawal 0001, Dan Boneh, Xavier Boyen |
EUROCRYPT | 1 |
| 2010 | On algebraic traceback in dynamic networksabstractThis paper presents the concept of incremental traceback for determining changes in the trace of a network as it evolves with time. A distributed algorithm, based on the methodology of algebraic traceback developed by Dean et al., is proposed that can determine a path of d nodes using O(d) marked packets, and subsequently determine the changes in it using O(log d) marked packets. The algorithm is established to be order-wise optimal, i.e. no other distributed algorithm can determine changes in the path topology using lesser order of bits (or marked packets). The algorithm is shown to have a computational complexity of O(d log d), which is significantly less than that of any existing non-incremental algorithm for algebraic traceback. The extension of the traceback mechanism to systems deploying network coding is also considered. Abhik Kumar Das, Shweta Agrawal 0001, Sriram Vishwanath |
ISIT | 2 |
| 2009 | Homomorphic MACs: MAC-Based Integrity for Network Coding
Shweta Agrawal 0001, Dan Boneh |
ACNS | 1 |
| 2009 | On the secrecy rate of interference networks using structured codesabstractThis paper shows that structured transmission schemes are a good choice for secret communication over interference networks with an eavesdropper. Structured transmission is shown to exploit channel asymmetries and thus perform better than randomly generated codebooks for such channels. For a class of interference channels, we show that an equivocation sum-rate that is within two bits of the maximum possible legitimate communication sum-rate is achievable using lattice codes. Shweta Agrawal 0001, Sriram Vishwanath |
ISIT | 1 |