VLDB 2026 Research / reviewers in the wild / expert
Raluca A. Popa
dblp:91/275 · also Raluca Ada Popa
· DBLP profile ↗
61ranked-venue papers
7as first author
26since 2021 · last 2026
0000-0001-8899-801XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 3 first-author · 17 since 2021Computer networks · 8 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 5 since 2021Systems, architecture and hardware · 5 · 2 first-authorArtificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CHORUS: Secret Recovery with Ephemeral Client Committees
Deevashwer Rathee, Emma Dauterman, Allison Li, Raluca A. Popa |
SP | 4 |
| 2026 | Verifiable PIR with Small Client Storage
Mayank 0002, Keewoo Lee, Raluca A. Popa |
SP | 3 |
| 2025 | LegoLog: A configurable transparency logabstractTransparency logs are critical for a wide range of applications, from web certificates to end-to-end encrypted messaging. Today, many transparency log designs exist for various applications and workloads, and developers must fully understand the design space to find the best design for their needs. Worse, if a developer needs a transparency log for an application and workload without an existing transparency log, the developer (who might not be an expert) must design a new log. To address these challenges, we introduce the paradigm of a configurable transparency log, which takes as input a description of the application work-load and constraints of different entities and automatically outputs a transparency log uniquely suited to the application. We present the first configurable transparency log design, LegoLog, which we implement and empirically evaluate end-to-end for three specialized transparency logs. We also show that LegoLog can express six different applications, and we compare the asymptotic complexity of LegoLog and existing transparency logs tailored to individual applications. We find that configurability does not come at the cost of performance: LegoLog can capture a variety of applications while performing comparably to existing, special-purpose transparency logs. Vivian Fang, Emma Dauterman, Akshay Ravoor, Akshit Dewan, Raluca A. Popa |
EuroS&P | 5 |
| 2025 | JudgeBench: A Benchmark for Evaluating LLM-Based JudgesabstractLLM-based judges have emerged as a scalable alternative to human evaluation and are increasingly used to assess, compare, and improve models. However, the reliability of LLM-based judges themselves is rarely scrutinized. As LLMs become more advanced, their responses grow more sophisticated, requiring stronger judges to evaluate them. Existing benchmarks primarily focus on a judge’s alignment with human preferences, but often fail to account for more challenging tasks where crowdsourced human preference is a poor indicator of factual and logical correctness. To address this, we propose a novel evaluation framework to objectively evaluate LLM-based judges. Based on this framework, we propose JudgeBench, a benchmark for evaluating LLM-based judges on challenging response pairs spanning knowledge, reasoning, math, and coding. JudgeBench leverages a novel pipeline for converting existing difficult datasets into challenging response pairs with preference labels reflecting objective correctness. Our comprehensive evaluation on a collection of prompted judges, fine-tuned judges, multi-agent judges, and reward models shows that JudgeBench poses a significantly greater challenge than previous benchmarks, with many strong models (e.g. GPT-4o) performing just slightly better than random guessing. Overall, JudgeBench offers a reliable platform for assessing increasingly advanced LLM-based judges. Data and code are available at \url{https://github.com/ScalerLab/JudgeBench}. Sijun Tan, Siyuan Zhuang, Kyle Montgomery, William Yuan Tang, Alejandro Cuadron, Chenguang Wang 0001, Raluca A. Popa, Ion Stoica |
ICLR | 7 |
| 2025 | Compass: Encrypted Semantic Search with High Accuracy
Jinhao Zhu, Liana Patel, Matei Zaharia, Raluca A. Popa |
OSDI | 4 |
| 2025 | Myco: Unlocking Polylogarithmic Accesses in Metadata-Private MessagingabstractAs billions of people rely on end-to-end encrypted messaging, the exposure of metadata, such as communication timing and participant relationships, continues to deanonymize users. Asynchronous metadata-hiding solutions with strong cryptographic guarantees have historically been bottlenecked by quadratic$O(N^{2})$server computation in the number of users$N$due to reliance on private information retrieval (PIR). We present Myco, a metadata-private messaging system that preserves strong cryptographic guarantees while achieving$O(N\log^{2}N)$efficiency. To achieve this, we depart from PIR and instead introduce an oblivious data structure through which senders and receivers privately communicate. To unlink reads and writes, we instantiate Myco in an asymmetric two-server distributed-trust model where clients write messages to one server tasked with obliviously transmitting these messages to another server, from which clients read. Myco achieves throughput improvements of up to 302x over multi-server and 2,219x over single-server state-of-the-art systems based on PIR. Darya Kaviani, Deevashwer Rathee, Bhargav Annem, Raluca A. Popa |
SP | 4 |
| 2024 | LLoCO: Learning Long Contexts OfflineabstractSijun Tan, Xiuyu Li, Shishir G Patil, Ziyang Wu, Tianjun Zhang, Kurt Keutzer, Joseph E. Gonzalez, Raluca Ada Popa. Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing. 2024. Sijun Tan, Xiuyu Li, Shishir G. Patil, Ziyang Wu, Tianjun Zhang, Kurt Keutzer, Joseph Gonzalez 0001, Raluca A. Popa |
EMNLP | 8 |
| 2024 | Retcon: Live Updates for Embedded Event-Driven ApplicationsabstractEmbedded systems are deeply integrated into critical applications but, despite their importance, lack an effective means to apply over-the-air software patches without significant downtime. Standard mechanisms for firmware updates require device reboots that wipe important in-memory state. Prior efforts have proposed "live" updates to address this problem, applying patches to an embedded application without a reset, but they tackle a limited set of applications or propose a clean-slate design. In this paper, we present Retcon, a live update toolchain for embedded systems that supports a familiar event-driven programming model and does not require application code changes. Retcon leverages static analysis at compile time to determine when it will be safe to update a device. To find safe update points in the presence of complex asynchronous behavior, we define a novel system state, asynchronous quiescence, in which an update can be applied. We evaluate Retcon on a set of embedded event-driven applications – a dual-chamber pacemaker model, a programmable logic controller runtime, an artificial pancreas system, and a sensing node – and demonstrate Retcon’s ability to make low-overhead updates in less than one millisecond. Jean-Luc Watson, Saharsh Agrawal, Ryan Tsang, Sherry Luo, Raluca A. Popa, Prabal Dutta |
IPSN | 5 |
| 2024 | Secret Key Recovery in a Global-Scale End-to-End Encryption System
Graeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman, Raluca A. Popa |
OSDI | 5 |
| 2024 | Flock: A Framework for Deploying On-Demand Distributed Trust
Darya Kaviani, Sijun Tan, Pravein G. Kannan, Raluca A. Popa |
OSDI | 4 |
| 2024 | Private Analytics via Streaming, Sketching, and Silently Verifiable ProofsabstractWe present Whisper, a system for privacy-preserving collection of aggregate statistics. Like prior systems, a Whisper deployment consists of a small set of non-colluding servers; these servers compute aggregate statistics over data from a large number of users without learning the data of any individual user. Whisper’s main contribution is that its server-to-server communication cost and its server-side storage costs scale sublinearly with the total number of users. In particular, prior systems required the servers to exchange a few bits of information to verify the well-formedness of each client submission. In contrast, Whisper uses silently verifiable proofs, a new type of proof system on secret-shared data that allows the servers to verify an arbitrarily large batch of proofs by exchanging a single 128-bit string. This improvement comes with increased client-to-server communication, which, in cloud computing, is typically cheaper (or even free) than the cost of egress for server-to-server communication. To reduce server storage, Whisper approximates certain statistics using smallspace sketching data structures. Applying randomized sketches in an environment with adversarial clients requires a careful and novel security analysis. In a deployment with two servers and 100,000 clients of which 1% are malicious, Whisper can improve server-to-server communication for vector sum by three orders of magnitude while each client’s communication increases by only 10%. Mayank 0002, Henry Corrigan-Gibbs, Raluca A. Popa |
SP | 4 |
| 2024 | Nebula: A Privacy-First Platform for Data BackhaulabstractImagine being able to deploy a small, battery- powered device nearly anywhere on earth that humans frequent and having it be able to send data to the cloud without needing to provision a network—without buying a physical gateway, setting up WiFi credentials, or acquiring a cellular SIM. Such a capability would address one of the greatest bottlenecks to deploying the long-tail of small, embedded, and power-constrained IoT devices in nearly any setting. Unfortunately, decoupling the device deployment from the network configuration needed to transmit, or backhaul, sensor data to the cloud remains a tricky challenge, but the success of Tile and AirTag offers hope. They have shown that mobile phones can crowd-source worldwide local network coverage to find lost items, yet expanding these systems to enable general-purpose backhaul raises privacy concerns for network participants. In this work, we present Nebula, a privacy-focused architecture for global, intermittent, and low-rate data backhaul to enable nearly any thing to eventually connect to the cloud while (i) preserving the privacy of the mobile network participants from the platform provider by decentralizing data flow through the system, (ii) incentivizing participation through micropayments, and (iii) preventing system abuse. Jean-Luc Watson, Tess Despres, Alvin Tan, Shishir G. Patil, Prabal Dutta, Raluca A. Popa |
SP | 6 |
| 2023 | ELSA: Secure Aggregation for Federated Learning with Malicious ActorsabstractFederated learning (FL) is an increasingly popular approach for machine learning (ML) in cases where the training dataset is highly distributed. Clients perform local training on their datasets and the updates are then aggregated into the global model. Existing protocols for aggregation are either inefficient, or don’t consider the case of malicious actors in the system. This is a major barrier in making FL an ideal solution for privacy-sensitive ML applications. We present Elsa, a secure aggregation protocol for FL, which breaks this barrier - it is efficient and addresses the existence of malicious actors at the core of its design. Similar to prior work on Prio and Prio+, Elsa provides a novel secure aggregation protocol built out of distributed trust across two servers that keeps individual client updates private as long as one server is honest, defends against malicious clients, and is efficient end-to-end. Compared to prior works, the distinguishing theme in Elsa is that instead of the servers generating cryptographic correlations interactively, the clients act as untrusted dealers of these correlations without compromising the protocol’s security. This leads to a much faster protocol while also achieving stronger security at that efficiency compared to prior work. We introduce new techniques that retain privacy even when a server is malicious at a small added cost of 7-25% in runtime with negligible increase in communication over the case of semi-honest server. Our work improves end-to-end runtime over prior work with similar security guarantees by big margins - single-aggregator RoFL by up to 305x (for the models we consider), and distributed trust Prio by up to 8x. Mayank 0002, Conghao Shen, Sameer Wagh, Raluca A. Popa |
SP | 4 |
| 2023 | MPCAuth: Multi-factor Authentication for Distributed-trust SystemsabstractSystems with distributed trust have attracted growing research attention and seen increasing industry adoptions. In these systems, critical secrets are distributed across N servers, and computations are performed privately using secure multi-party computation (SMPC). Authentication for these distributed-trust systems faces two challenges. The first challenge is ease-of-use. Namely, how can an authentication protocol maintain its user experience without sacrificing security? To avoid a central point of attack, a client needs to authenticate to each server separately. However, this would require the client to authenticate N times for each authentication factor, which greatly hampers usability. The second challenge is privacy, as the client’s sensitive profiles are now exposed to all N servers under different trust domains, which creates N times the attack surface for the profile data.We present MPCAuth, a multi-factor authentication system for distributed-trust applications that address both challenges. Our system enables a client to authenticate to N servers independently with the work of only one authentication. In addition, our system is profile hiding, meaning that the client’s authentication profiles such as her email username, phone number, passwords, and biometric features are not revealed unless all servers are compromised. We propose secure and practical protocols for an array of widely adopted authentication factors, including email passcodes, SMS messages, U2F, security questions/passwords, and biometrics. Our system finds practical applications in the space of cryptocurrency custody and collaborative machine learning, and benefits future adoptions of distributed-trust applications. Sijun Tan, Weikeng Chen, Ryan Deng, Raluca A. Popa |
SP | 4 |
| 2023 | HOLMES: Efficient Distribution Testing for Secure Collaborative Learning
Ian Chang, Katerina Sotiraki, Weikeng Chen, Murat Kantarcioglu, Raluca A. Popa |
USENIX Security Symposium | 5 |
| 2022 | CostCO: An automatic cost modeling framework for secure multi-party computationabstractThe last decade has seen an explosion in the number of new secure multi-party computation (MPC) protocols that enable collaborative computation on sensitive data. No single MPC protocol is optimal for all types of computation. As a result, researchers have created hybrid-protocol compilers that translate a program into a hybrid protocol that mixes different MPC protocols. Hybrid-protocol compilers crucially rely on accurate cost models, which are handwritten by the compilers' developers, to choose the correct schedule of protocols. In this paper, we propose CostCO, the first automatic MPC cost modeling framework. CostCO develops a novel API to interface with a variety of MPC protocols, and leverages domain-specific properties of MPC in order to enable efficient and automatic cost-model generation for a wide range of MPC protocols. CostCO employs a two-phase experiment design to efficiently synthesize cost models of the MPC protocol's runtime as well as its memory and network usage. We verify CostCO's modeling accuracy for several full circuits, characterize the engineering effort required to port existing MPC protocols, and demonstrate how hybrid-protocol compilers can leverage CostCO's cost models. Vivian Fang, Lloyd Brown, William Lin, Wenting Zheng, Aurojit Panda, Raluca A. Popa |
EuroS&P | 6 |
| 2022 | Reflections on trusting distributed trustabstractMany systems today distribute trust across multiple parties such that the system provides certain security properties if a subset of the parties are honest. In the past few years, we have seen an explosion of academic and industrial cryptographic systems built on distributed trust, including secure multi-party computation applications (e.g., private analytics, secure learning, and private key recovery) and blockchains. These systems have great potential for improving security and privacy, but face a significant hurdle on the path to deployment. We initiate study of the following problem: a single organization is, by definition, a single party, and so how can a single organization build a distributed-trust system where corruptions are independent? We instead consider an alternative formulation of the problem: rather than ensuring that a distributed-trust system is set up correctly by design, what if instead, users can audit a distributed-trust deployment? We propose a framework that enables a developer to efficiently and cheaply set up any distributed-trust system in a publicly auditable way. To do this, we identify two application-independent building blocks that we can use to bootstrap arbitrary distributed-trust applications: secure hardware and an append-only log. We show how to leverage existing implementations of these building blocks to deploy distributed-trust systems, and we give recommendations for infrastructure changes that would make it easier to deploy distributed-trust systems in the future. Emma Dauterman, Vivian Fang, Natacha Crooks, Raluca A. Popa |
HotNets | 4 |
| 2022 | Waldo: A Private Time-Series Database from Function Secret SharingabstractApplications today rely on cloud databases for storing and querying time-series data. While outsourcing storage is convenient, this data is often sensitive, making data breaches a serious concern. We present Waldo, a time-series database with rich functionality and strong security guarantees: Waldo supports multi-predicate filtering, protects data contents as well as query filter values and search access patterns, and provides malicious security in the 3-party honest-majority setting. In contrast, prior systems such as Timecrypt and Zeph have limited functionality and security: (1) these systems can only filter on time, and (2) they reveal the queried time interval to the server. Oblivious RAM (ORAM) and generic multiparty computation (MPC) are natural choices for eliminating leakage from prior work, but both of these are prohibitively expensive in our setting due to the number of roundtrips and bandwidth overhead, respectively. To minimize both, Waldo builds on top of function secret sharing, enabling Waldo to evaluate predicates non-interactively. We develop new techniques for applying function secret sharing to the encrypted database setting where there are malicious servers, secret inputs, and chained predicates. With 32-core machines, Waldo runs a query with 8 range predicates over 218records in 3.03s, compared to 12.88s or an MPC baseline and 16.56s for an ORAM baseline. Compared to Waldo, the MPC baseline uses $9-82 \times$ more bandwidth between servers (for different numbers of records), while the ORAM baseline uses $20-152 \times$ more bandwidth between the client and server(s) (for different numbers of predicates). Emma Dauterman, Mayank 0002, Raluca A. Popa, Ion Stoica |
SP | 3 |
| 2022 | Piranha: A GPU Platform for Secure Computation
Jean-Luc Watson, Sameer Wagh, Raluca A. Popa |
USENIX Security Symposium | 3 |
| 2021 | MAGE: Nearly Zero-Cost Virtual Memory for Secure Computation
Sam Kumar, David E. Culler, Raluca A. Popa |
OSDI | 3 |
| 2021 | Snoopy: Surpassing the Scalability Bottleneck of Oblivious StorageabstractExisting oblivious storage systems provide strong security by hiding access patterns, but do not scale to sustain high throughput as they rely on a central point of coordination. To overcome this scalability bottleneck, we present Snoopy, an object store that is both oblivious and scalable such that adding more machines increases system throughput. Snoopy contributes techniques tailored to the high-throughput regime to securely distribute and efficiently parallelize every system component without prohibitive coordination costs. These techniques enable Snoopy to scale similarly to a plaintext storage system. Snoopy achieves 13.7x higher throughput than Obladi, a state-of-the-art oblivious storage system. Specifically, Obladi reaches a throughput of 6.7K requests/s for two million 160-byte objects and cannot scale beyond a proxy and server machine. For the same data size, Snoopy uses 18 machines to scale to 92K requests/s with average latency under 500ms. Emma Dauterman, Vivian Fang, Ioannis Demertzis, Natacha Crooks, Raluca A. Popa |
SOSP | 5 |
| 2021 | Merkle2: A Low-Latency Transparency Log SystemabstractTransparency logs are designed to help users audit untrusted servers. For example, Certificate Transparency (CT) enables users to detect when a compromised Certificate Authority (CA) has issued a fake certificate. Practical state-of-the-art transparency log systems, however, suffer from high monitoring costs when used for low-latency applications. To reduce monitoring costs, such systems often require users to wait an hour or more for their updates to take effect, inhibiting low-latency applications. We propose Merkle2, a transparency log system that supports both efficient monitoring and low-latency updates. To achieve this goal, we construct a new multi-dimensional, authenticated data structure that nests two types of Merkle trees, hence the name of our system, Merkle2. Using this data structure, we then design a transparency log system with efficient monitoring and lookup protocols that enables low-latency updates. In particular, all the operations in Merkle2are independent of update intervals and are (poly)logarithmic to the number of entries in the log. Merkle2not only has excellent asymptotics when compared to prior work, but is also efficient in practice. Our evaluation shows that Merkle2propagates updates in as little as 1 second and can support 100× more users than state-of-the-art transparency logs. Yuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang, Raluca A. Popa |
SP | 5 |
| 2021 | Muse: Secure Inference Resilient to Malicious Clients
Ryan Lehmkuhl, Pratyush Mishra 0001, Akshayaram Srinivasan, Raluca A. Popa |
USENIX Security Symposium | 4 |
| 2021 | Senate: A Maliciously-Secure MPC Platform for Collaborative Analytics
Rishabh Poddar, Sukrit Kalra, Avishay Yanai, Ryan Deng, Raluca A. Popa, Joseph M. Hellerstein |
USENIX Security Symposium | 5 |
| 2021 | ObliCheck: Efficient Verification of Oblivious Algorithms with Unobservable State
Jeongseok Son, Griffin Prechter, Rishabh Poddar, Raluca A. Popa, Koushik Sen |
USENIX Security Symposium | 4 |
| 2021 | Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning
Wenting Zheng, Ryan Deng, Weikeng Chen, Raluca A. Popa, Aurojit Panda, Ion Stoica |
USENIX Security Symposium | 4 |
| 2020 | PPMLP 2020: Workshop on Privacy-Preserving Machine Learning In PracticeabstractWith the rapid development of technology, data is becoming ubiquitous. User privacy and data security are drawing much attention over the recent years, especially with the European Union's General Data Protection Regulation (GDPR) and other laws coming into force. On one hand, from the customers' perspective, how to protect user privacy while making use of customers? data is a challenging task. On the other hand, data silos are becoming one of the most prominent issues for the society. From the business? perspective, how to bridge these isolated data islands to build better AI systems while meeting the data privacy and regulatory compliance requirements has imposed great challenges to the traditional machine learning paradigm. PPMLP will provide an opportunity to connect researchers from both CCS community and machine learning community to tackle these challenges. Benyu Zhang, Matei Zaharia, Shouling Ji, Raluca A. Popa, Guofei Gu |
CCS | 4 |
| 2020 | Practical Volume-Based Attacks on Encrypted DatabasesabstractRecent years have seen an increased interest towards strong security primitives for encrypted databases (such as oblivious protocols) that hide the access patterns of query execution and reveal only the volume of results. However recent work has shown that even volume leakage can enable the reconstruction of entire columns in the database. Yet existing attacks rely on a set of assumptions that are unrealistic in practice for example they (i) require a large number of queries to be issued by the user or (ii) assume certain distributions on the queries or underlying data (e.g. that the queries are distributed uniformly at random or that the database does not contain missing values). In this work we present new attacks for recovering the content of individual user queries assuming no leakage from the system except the number of results and avoiding the limiting assumptions above. Unlike prior attacks our attacks require only a single query to be issued by the user for recovering the keyword. Furthermore our attacks make no assumptions about the distribution of issued queries or the underlying data. Instead our key insight is to exploit the behavior of real-world applications. We start by surveying 11 applications to identify two key characteristics that can be exploited by attackers-(l) file injection and (ii) automatic query replay. We present attacks that leverage these two properties in concert with volume leakage independent of the details of any encrypted database system. Subsequently we perform an attack on the real Gmail web client by simulating a server-side adversary. Our attack on Gmail completes within a matter of minutes demonstrating the feasibility of our techniques. We also present three ancillary attacks for situations when certain mitigation strategies are employed. Rishabh Poddar, Stephanie Wang, Jianan Lu, Raluca A. Popa |
EuroS&P | 4 |
| 2020 | Oblivious coopetitive analytics using hardware enclavesabstractCoopetitive analytics refers to cooperation among competing parties to run queries over their joint data. Regulatory, business, and liability concerns prevent these organizations from sharing their sensitive data in plaintext. Ankur Dave, Chester Leung, Raluca A. Popa, Joseph Gonzalez 0001, Ion Stoica |
EuroSys | 3 |
| 2020 | Metal: A Metadata-Hiding File-Sharing System
Weikeng Chen, Raluca A. Popa |
NDSS | 2 |
| 2020 | Ghostor: Toward a Secure Data-Sharing System from Decentralized Trust
Yuncong Hu, Sam Kumar, Raluca A. Popa |
NSDI | 3 |
| 2020 | DORY: An Encrypted Search System with Distributed Trust
Emma Dauterman, Eric Feng, Ellen Luo, Raluca A. Popa, Ion Stoica |
OSDI | 4 |
| 2020 | An Off-Chip Attack on Hardware Enclaves via the Memory Bus
Dayeol Lee, Dongha Jung, Ian T. Fang, Chia-Che Tsai, Raluca A. Popa |
USENIX Security Symposium | 5 |
| 2020 | Delphi: A Cryptographic Inference Service for Neural Networks
Pratyush Mishra 0001, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, Raluca A. Popa |
USENIX Security Symposium | 5 |
| 2020 | Visor: Privacy-Preserving Video Analytics as a Cloud Service
Rishabh Poddar, Ganesh Ananthanarayanan, Srinath Setty, Stavros Volos, Raluca A. Popa |
USENIX Security Symposium | 5 |
| 2020 | Civet: An Efficient Java Partitioning Framework for Hardware Enclaves
Chia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey, Raluca A. Popa, Donald E. Porter |
USENIX Security Symposium | 5 |
| 2019 | Securing Data in Compromised CloudsabstractClouds store a lot of sensitive data. Traditional cloud security relies on building software walls around sensitive data to prevent attackers from breaking in. Nevertheless, attackers always manage to break in because software is complex and thus cannot be exploit-free. A line of cryptographic systems, however, departs from this approach, and provides security guarantees even when attackers have compromised the cloud. In this talk, I will survey a decade of such cryptographic systems, highlighting the main design principles and lessons learned, and pointing to the state-of-the-art systems that one can use today. Raluca A. Popa |
SoCC | 1 |
| 2019 | Helen: Maliciously Secure Coopetitive Learning for Linear ModelsabstractMany organizations wish to collaboratively train machine learning models on their combined datasets for a common benefit (e.g., better medical research, or fraud detection). However, they often cannot share their plaintext datasets due to privacy concerns and/or business competition. In this paper, we design and build Helen, a system that allows multiple parties to train a linear model without revealing their data, a setting we call coopetitive learning. Compared to prior secure training systems, Helen protects against a much stronger adversary who is malicious and can compromise m−1 out of m parties. Our evaluation shows that Helen can achieve up to five orders of magnitude of performance improvement when compared to training using an existing state-of-the-art secure multi-party computation framework. Wenting Zheng, Raluca A. Popa, Joseph Gonzalez 0001, Ion Stoica |
IEEE Symposium on Security and Privacy | 2 |
| 2019 | WAVE: A Decentralized Authorization Framework with Transitive Delegation
Michael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro, John Kolb, Hyung-Sin Kim, David E. Culler, Raluca A. Popa |
USENIX Security Symposium | 8 |
| 2019 | JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoT
Sam Kumar, Yuncong Hu, Michael P. Andersen, Raluca A. Popa, David E. Culler |
USENIX Security Symposium | 4 |
| 2019 | Arx: An Encrypted Database using Semantically Secure EncryptionabstractIn recent years, encrypted databases have emerged as a promising direction that provides data confidentiality without sacrificing functionality: queries are executed on encrypted data. However, many practical proposals rely on a set of weak encryption schemes that have been shown to leak sensitive data. In this paper, we propose Arx, a practical and functionally rich database system that encrypts the data only with semantically secure encryption schemes. We show that Arx supports real applications such as ShareLaTeX with a modest performance overhead. Rishabh Poddar, Tobias Boelter, Raluca A. Popa |
Proc. VLDB Endow. | 3 |
| 2018 | SafeBricks: Shielding Network Functions in the Cloud
Rishabh Poddar, Chang Lan, Raluca A. Popa, Sylvia Ratnasamy |
NSDI | 3 |
| 2018 | Oblix: An Efficient Oblivious Search IndexabstractSearch indices are fundamental building blocks of many systems, and there is great interest in running them on encrypted data. Unfortunately, many known schemes that enable search queries on encrypted data achieve efficiency at the expense of security, as they reveal access patterns to the encrypted data. In this paper we present Oblix, a search index for encrypted data that is oblivious (provably hides access patterns), is dynamic (supports inserts and deletes), and has good efficiency. Oblix relies on a combination of novel oblivious-access techniques and recent hardware enclave platforms (e.g., Intel SGX). In particular, a key technical contribution is the design and implementation of doubly-oblivious data structures, in which the client's accesses to its internal memory are oblivious, in addition to accesses to its external memory at the server. These algorithms are motivated by hardware enclaves like SGX, which leak access patterns to both internal and external memory. We demonstrate the usefulness of Oblix in several applications: private contact discovery for Signal, private retrieval of public keys for Key Transparency, and searchable encryption that hides access patterns and result sizes. Pratyush Mishra 0001, Rishabh Poddar, Jerry Chen, Alessandro Chiesa, Raluca A. Popa |
IEEE Symposium on Security and Privacy | 5 |
| 2018 | DIZK: A Distributed Zero Knowledge Proof System
Howard Wu, Wenting Zheng, Alessandro Chiesa, Raluca A. Popa, Ion Stoica |
USENIX Security Symposium | 4 |
| 2017 | MiniCrypt: Reconciling Encryption and Compression for Big Data StoresabstractWe propose MiniCrypt, the first key-value store that reconciles encryption and compression without compromising performance. At the core of MiniCrypt is an observation on data compressibility trends in key-value stores, which enables grouping key-value pairs into small key packs, together with a set of distributed systems techniques for retrieving, updating, merging and splitting encrypted packs. Our evaluation shows that MiniCrypt compresses data by as much as 4 times with respect to the vanilla key-value store, and can increase the server's throughput by up to two orders of magnitude by fitting more data in main memory. Wenting Zheng, Frank Li 0001, Raluca A. Popa, Ion Stoica, Rachit Agarwal 0001 |
EuroSys | 3 |
| 2017 | Opaque: An Oblivious and Encrypted Distributed Analytics Platform
Wenting Zheng, Ankur Dave, Jethro G. Beekman, Raluca A. Popa, Joseph Gonzalez 0001, Ion Stoica |
NSDI | 4 |
| 2016 | Embark: Securely Outsourcing Middleboxes to the Cloud
Chang Lan, Justine Sherry, Raluca A. Popa, Sylvia Ratnasamy |
NSDI | 3 |
| 2016 | Verena: End-to-End Integrity Protection for Web ApplicationsabstractWeb applications rely on web servers to protect the integrity of sensitive information. However, an attacker gaining access to web servers can tamper with the data and query computation results, and thus serve corrupted web pages to the user. Violating the integrity of the web page can have serious consequences, affecting application functionality and decision-making processes. Worse yet, data integrity violation may affect physical safety, as in the case of medical web applications which enable physicians to assign treatment to patients based on diagnostic information stored at the web server. This paper presents Verena, a web application platform that provides end-to-end integrity guarantees against attackers that have full access to the web and database servers. In Verena, a client's browser can verify the integrity of a web page by verifying the results of queries on data stored at the server. Verena provides strong integrity properties such as freshness, completeness, and correctness for a common set of database queries, by relying on a small trusted computing base. In a setting where there can be many users with different write permissions, Verena allows a developer to specify an integrity policy for query results based on our notion of trust contexts, and then enforces this policy efficiently. We implemented and evaluated Verena on top of the Meteor framework. Our results show that Verena can support real applications with modest overhead. Nikolaos Karapanos, Alexandros Filios, Raluca A. Popa, Srdjan Capkun |
IEEE Symposium on Security and Privacy | 3 |
| 2015 | Machine Learning Classification over Encrypted Data
Raphael Bost, Raluca A. Popa, Stephen Tu, Shafi Goldwasser |
NDSS | 2 |
| 2015 | BlindBox: Deep Packet Inspection over Encrypted TrafficabstractMany network middleboxes perform deep packet inspection (DPI), a set of useful tasks which examine packet payloads. These tasks include intrusion detection (IDS), exfiltration detection, and parental filtering. However, a long-standing issue is that once packets are sent over HTTPS, middleboxes can no longer accomplish their tasks because the payloads are encrypted. Hence, one is faced with the choice of only one of two desirable properties: the functionality of middleboxes and the privacy of encryption. We propose BlindBox, the first system that simultaneously provides {\em both} of these properties. The approach of BlindBox is to perform the deep-packet inspection {\em directly on the encrypted traffic. BlindBox realizes this approach through a new protocol and new encryption schemes. Justine Sherry, Chang Lan, Raluca A. Popa, Sylvia Ratnasamy |
SIGCOMM | 3 |
| 2014 | Building Web Applications on Top of Encrypted Data Using Mylar
Raluca A. Popa, Emily Stark 0001, Steven Valdez, Jonas Helfer, Nickolai Zeldovich, Hari Balakrishnan |
NSDI | 1 |
| 2013 | How to Run Turing Machines on Encrypted Data
Shafi Goldwasser, Yael Tauman Kalai, Raluca A. Popa, Vinod Vaikuntanathan, Nickolai Zeldovich |
CRYPTO (2) | 3 |
| 2013 | An Ideal-Security Protocol for Order-Preserving EncodingabstractOrder-preserving encryption - an encryption scheme where the sort order of ciphertexts matches the sort order of the corresponding plaintexts - allows databases and other applications to process queries involving order over encrypted data efficiently. The ideal security guarantee for order-preserving encryption put forth in the literature is for the ciphertexts to reveal no information about the plaintexts besides order. Even though more than a dozen schemes were proposed, all these schemes leak more information than order. This paper presents the first order-preserving scheme that achieves ideal security. Our main technique is mutable ciphertexts, meaning that over time, the ciphertexts for a small number of plaintext values change, and we prove that mutable ciphertexts are needed for ideal security. Our resulting protocol is interactive, with a small number of interactions. We implemented our scheme and evaluated it on microbenchmarks and in the context of an encrypted MySQL database application. We show that in addition to providing ideal security, our scheme achieves 1 - 2 orders of magnitude higher performance than the state-of-the-art order-preserving encryption scheme, which is less secure than our scheme. Raluca A. Popa, Frank Li 0001, Nickolai Zeldovich |
IEEE Symposium on Security and Privacy | 1 |
| 2013 | Reusable garbled circuits and succinct functional encryptionabstractGarbled circuits, introduced by Yao in the mid 80s, allow computing a function f on an input x without leaking anything about f or x besides f(x). Garbled circuits found numerous applications, but every known construction suffers from one limitation: it offers no security if used on multiple inputs x. In this paper, we construct for the first time reusable garbled circuits. The key building block is a new succinct single-key functional encryption scheme. Shafi Goldwasser, Yael Tauman Kalai, Raluca A. Popa, Vinod Vaikuntanathan, Nickolai Zeldovich |
STOC | 3 |
| 2011 | Privacy and accountability for location-based aggregate statisticsabstractA significant and growing class of location-based mobile applications aggregate position data from individual devices at a server and compute aggregate statistics over these position streams. Because these devices can be linked to the movement of individuals, there is significant danger that the aggregate computation will violate the location privacy of individuals. This paper develops and evaluates PrivStats, a system for computing aggregate statistics over location data that simultaneously achieves two properties: first, provable guarantees on location privacy even in the face of any side information about users known to the server, and second, privacy-preserving accountability (i.e., protection against abusive clients uploading large amounts of spurious data). PrivStats achieves these properties using a new protocol for uploading and aggregating data anonymously as well as an efficient zero-knowledge proof of knowledge protocol we developed from scratch for accountability. We implemented our system on Nexus One smartphones and commodity servers. Our experimental results demonstrate that PrivStats is a practical system: computing a common aggregate (e.g., count) over the data of 10,000 clients takes less than 0.46 s at the server and the protocol has modest latency (0.6 s) to upload data from a Nexus phone. We also validated our protocols on real driver traces from the CarTel project. Raluca A. Popa, Andrew J. Blumberg, Hari Balakrishnan, Frank Li 0001 |
CCS | 1 |
| 2011 | Relational Cloud: a Database Service for the cloud
Carlo Curino, Evan P. C. Jones, Raluca A. Popa, Nirmesh Malviya, Eugene Wu 0002, Samuel Madden 0001, Hari Balakrishnan, Nickolai Zeldovich |
CIDR | 3 |
| 2011 | CryptDB: protecting confidentiality with encrypted query processingabstractOnline applications are vulnerable to theft of sensitive information because adversaries can exploit software bugs to gain access to private data, and because curious or malicious administrators may capture and leak data. CryptDB is a system that provides practical and provable confidentiality in the face of these attacks for applications backed by SQL databases. It works by executing SQL queries over encrypted data using a collection of efficient SQL-aware encryption schemes. CryptDB can also chain encryption keys to user passwords, so that a data item can be decrypted only by using the password of one of the users with access to that data. As a result, a database administrator never gets access to decrypted data, and even if all servers are compromised, an adversary cannot decrypt the data of any user who is not logged in. An analysis of a trace of 126 million SQL queries from a production MySQL server shows that CryptDB can support operations over encrypted data for 99.5% of the 128,840 columns seen in the trace. Our evaluation shows that CryptDB has low overhead, reducing throughput by 14.5% for phpBB, a web forum application, and by 26% for queries from TPC-C, compared to unmodified MySQL. Chaining encryption keys to user passwords requires 11--13 unique schema annotations to secure more than 20 sensitive fields and 2--7 lines of source code changes for three multi-user web applications. Raluca A. Popa, Catherine M. S. Redfield, Nickolai Zeldovich, Hari Balakrishnan |
SOSP | 1 |
| 2011 | Enabling Security in Cloud Storage SLAs with CloudProof
Raluca A. Popa, Jacob R. Lorch, David Molnar, Helen J. Wang, Li Zhuang |
USENIX ATC | 1 |
| 2009 | Census: Location-Aware Membership Management for Large-Scale Distributed Systems
James A. Cowling, Dan R. K. Ports, Barbara Liskov, Raluca A. Popa, Abhijeet Gaikwad |
USENIX ATC | 4 |
| 2009 | VPriv: Protecting Privacy in Location-Based Vehicular Services
Raluca A. Popa, Hari Balakrishnan, Andrew J. Blumberg |
USENIX Security Symposium | 1 |
| 2007 | MUVI: automatically inferring multi-variable access correlations and detecting related semantic and concurrency bugsabstractSoftware defects significantly reduce system dependability. Among various types of software bugs, semantic and concurrency bugs are two of the most difficult to detect. This paper proposes a novel method, called MUVI, that detects an important class of semantic and concurrency bugs. MUVI automatically infers commonly existing multi-variable access correlations through code analysis and then detects two types of related bugs: (1) inconsistent updates--correlated variables are not updated in a consistent way, and (2) multi-variable concurrency bugs--correlated accesses are not protected in the same atomic sections in concurrent programs.We evaluate MUVI on four large applications: Linux, Mozilla,MySQL, and PostgreSQL. MUVI automatically infers more than 6000 variable access correlations with high accuracy (83%).Based on the inferred correlations, MUVI detects 39 new inconsistent update semantic bugs from the latest versions of these applications, with 17 of them recently confirmed by the developers based on our reports.We also implemented MUVI multi-variable extensions to tworepresentative data race bug detection methods (lock-set and happens-before). Our evaluation on five real-world multi-variable concurrency bugs from Mozilla and MySQL shows that the MUVI-extension correctly identifies the root causes of four out of the five multi-variable concurrency bugs with 14% additional overhead on average. Interestingly, MUVI also helps detect four new multi-variable concurrency bugs in Mozilla that have never been reported before. None of the nine bugs can be identified correctly by the original race detectors without our MUVI extensions. Shan Lu 0001, Chongfeng Hu, Xiao Ma 0014, Weihang Jiang, Zhenmin Li, Raluca A. Popa, Yuanyuan Zhou 0001 |
SOSP | 7 |