EDBT 2026 Demo / reviewers in the wild / expert
Melissa Chase
dblp:06/1661 · also Melissa Erin Chase
· DBLP profile ↗
40ranked-venue papers
26as first author
7since 2021 · last 2024
0009-0003-8333-3942ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 26 first-author · 7 since 2021Theory of computation · 5 · 3 first-author · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Precio: Private Aggregate Measurement via Oblivious ShufflingabstractWe introduce Precio, a new secure aggregation method for computing layered histograms and sums over secret shared data in a client-server setting. Precio is motivated by ad conversion measurement scenarios, where online advertisers and ad networks want to measure the performance of ad campaigns without requiring privacy-invasive techniques, such as third-party cookies. Erik Anderson, Melissa Chase, F. Betül Durak, Kim Laine, Chenkai Weng |
CCS | 2 |
| 2024 | Combing for Credentials: Active Pattern Extraction from Smart ReplyabstractPre-trained large language models, such as GPT-2 and BERT, are often fine-tuned to achieve state-of-the-art performance on a downstream task. One natural example is the "Smart Reply" application where a pre-trained model is tuned to provide suggested responses for a given query message. Since the tuning data is often sensitive data such as emails or chat transcripts, it is important to understand and mitigate the risk that the model leaks its tuning data. We investigate potential information leakage vulnerabilities in a typical Smart Reply pipeline. We consider a realistic setting where the adversary can only interact with the underlying model through a frontend interface that constrains what types of queries can be sent to the model. Previous attacks do not work in these settings, but require the ability to send unconstrained queries directly to the model. Even when there are no constraints on the queries, previous attacks typically require thousands, or even millions, of queries to extract useful information, while our attacks can extract sensitive data in just a handful of queries. We introduce a new type of active extraction attack that exploits canonical patterns in text containing sensitive data. We show experimentally that it is possible for an adversary to extract sensitive user information present in the training data, even in realistic settings where all interactions with the model must go through a front-end that limits the types of queries. We explore potential mitigation strategies and demonstrate empirically how differential privacy appears to be a reasonably effective defense mechanism to such pattern extraction attacks. Bargav Jayaraman, Esha Ghosh, Melissa Chase, Sambuddha Roy, Wei Dai 0007, David Evans 0001 |
SP | 3 |
| 2024 | OPTIKS: An Optimized Key Transparency System
Julia Len, Melissa Chase, Esha Ghosh, Kim Laine, Radames Cruz Moreno |
USENIX Security Symposium | 2 |
| 2023 | ELEKTRA: Efficient Lightweight multi-dEvice Key TRAnsparencyabstractKey Transparency (KT) systems enable service providers of end-to-end encrypted communication (E2EE) platforms to maintain a Verifiable Key Directory (VKD) that maps each user's identifier, such as a username or email address, to their identity public key(s). Users periodically monitor the directory to ensure their own identifier maps to the correct keys, thus detecting any attempt to register a fake key on their behalf to Meddler-in-the-Middle (MitM) their communications. Julia Len, Melissa Chase, Esha Ghosh, Daniel Jost 0001, Balachandar Kesavan, Antonio Marcedone |
CCS | 2 |
| 2023 | Anonymous Tokens with Stronger Metadata Bit Hiding from Algebraic MACs
Melissa Chase, F. Betül Durak, Serge Vaudenay |
CRYPTO (2) | 1 |
| 2022 | Property Inference from PoisoningabstractProperty inference attacks consider an adversary who has access to a trained ML model and tries to extract some global statistics of the training data. In this work, we study property inference in scenarios where the adversary can maliciously control a part of the training data (poisoning data) with the goal of increasing the leakage. Previous works on poisoning attacks focused on trying to decrease the accuracy of models. Here, for the first time, we study poisoning attacks where the goal of the adversary is to increase the information leakage of the model. We show that poisoning attacks can boost the information leakage significantly and should be considered as a stronger threat model in sensitive applications where some of the data sources may be malicious.We theoretically prove that our attack can always succeed as long as the learning algorithm used has good generalization properties. Then we experimentally evaluate our on different datasets (Census dataset, Enron email dataset, MNIST and CelebA), properties (that are present in the training data as features, that are not present as features, and properties that are uncorrelated with the rest of the training data or classification task) and model architectures (including Resnet-18 and Resnet-50). We were able to achieve high attack accuracy with relatively low poisoning rate, namely, 2–3% poisoning in most of our experiments. We also evaluated our attacks on models trained with DP and we show that even with very small values for $\epsilon$, the attack is still quite successful1.1Code is available at https://github.com/smahloujifar/PropertyInferenceFromPoisoning.git Saeed Mahloujifar, Esha Ghosh, Melissa Chase |
SP | 3 |
| 2021 | Amortizing Rate-1 OT and Applications to PIR and PSI
Melissa Chase, Sanjam Garg, Mohammad Hajiabadi, Peihan Miao 0001 |
TCC (3) | 1 |
| 2020 | Secret-Shared Shuffle
Melissa Chase, Esha Ghosh, Oxana Poburinnaya |
ASIACRYPT (3) | 1 |
| 2020 | The Signal Private Group System and Anonymous Credentials Supporting Efficient Verifiable EncryptionabstractIn this paper we present a system for maintaining a membership list of users in a group, designed for use in the Signal Messenger secure messaging app. The goal is to support private groups where membership information is readily available to all group members but hidden from the service provider or anyone outside the group. In the proposed solution, a central server stores the group membership in the form of encrypted entries. Members of the group authenticate to the server in a way that reveals only that they correspond to some encrypted entry, then read and write the encrypted entries. Melissa Chase, Trevor Perrin, Gregory M. Zaverucha |
CCS | 1 |
| 2020 | Private Set Intersection in the Internet Setting from Lightweight Oblivious PRF
Melissa Chase, Peihan Miao 0001 |
CRYPTO (3) | 1 |
| 2019 | SEEMless: Secure End-to-End Encrypted Messaging with less</> TrustabstractEnd-to-end encrypted messaging (E2E) is only secure if participants have a way to retrieve the correct public key for the desired recipient. However, to make these systems usable, users must be able to replace their keys (e.g. when they lose or reset their devices, or reinstall their app), and we cannot assume any cryptographic means of authenticating the new keys. In the current E2E systems, the service provider manages the directory of public keys of its registered users; this allows a compromised or coerced service provider to introduce their own keys and execute a man in the middle attack. Building on the approach of CONIKS (Melara et al, USENIX Security '15), we formalize the notion of a Privacy-Preserving Verifiable Key Directory (VKD): a system which allows users to monitor the keys that the service is distributing on their behalf. We then propose a new VKD scheme which we call SEEMless, which improves on prior work in terms of privacy and scalability. In particular, our new approach allows key changes to take effect almost immediately; we show experimentally that our scheme easily supports delays less than a minute, in contrast to previous work which proposes a delay of one hour. Melissa Chase, Apoorvaa Deshpande, Esha Ghosh, Harjasleen Malvai |
CCS | 1 |
| 2019 | Reusable Non-Interactive Secure Computation
Melissa Chase, Yevgeniy Dodis, Yuval Ishai, Daniel Kraschewski, Tianren Liu, Rafail Ostrovsky, Vinod Vaikuntanathan |
CRYPTO (3) | 1 |
| 2017 | FAME: Fast Attribute-based Message EncryptionabstractTime and again, attribute-based encryption has been shown to be the natural cryptographic tool for building various types of conditional access systems with far-reaching applications, but the deployment of such systems has been very slow. A central issue is the lack of an encryption scheme that can operate on sensitive data very efficiently and, at the same time, provides features that are important in practice. Shashank Agrawal, Melissa Chase |
CCS | 2 |
| 2017 | Post-Quantum Zero-Knowledge and Signatures from Symmetric-Key PrimitivesabstractWe propose a new class of post-quantum digital signature schemes that: (a) derive their security entirely from the security of symmetric-key primitives, believed to be quantum-secure, and (b) have extremely small keypairs, and, (c) are highly parameterizable. Melissa Chase, David Derler, Steven Goldfeder, Claudio Orlandi, Sebastian Ramacher, Christian Rechberger, Daniel Slamanig, Gregory M. Zaverucha |
CCS | 1 |
| 2017 | Simplifying Design and Analysis of Complex Predicate Encryption Schemes
Shashank Agrawal, Melissa Chase |
EUROCRYPT (1) | 2 |
| 2016 | Déjà Q All Over Again: Tighter and Broader Reductions of q-Type Assumptions
Melissa Chase, Mary Maller, Sarah Meiklejohn |
ASIACRYPT (2) | 1 |
| 2016 | Transparency Overlays and ApplicationsabstractIn this paper, we initiate a formal study of transparency, which in recent years has become an increasingly critical requirement for the systems in which people place trust. We present the abstract concept of a transparency overlay, which can be used in conjunction with any system to give it provable transparency guarantees, and then apply the overlay to two settings: Certificate Transparency and Bitcoin. In the latter setting, we show that the usage of our transparency overlay eliminates the need to engage in mining and allows users to store a single small value rather than the entire blockchain. Our transparency overlay is generically constructed from a signature scheme and a new primitive we call a dynamic list commitment, which in practice can be instantiated using a collision-resistant hash function. Melissa Chase, Sarah Meiklejohn |
CCS | 1 |
| 2016 | Efficient Zero-Knowledge Proof of Algebraic and Non-Algebraic Statements with Applications to Privacy Preserving Credentials
Melissa Chase, Chaya Ganesh, Payman Mohassel |
CRYPTO (3) | 1 |
| 2016 | Constant-Size Structure-Preserving Signatures: Generic Constructions and Simple Assumptions
Masayuki Abe, Melissa Chase, Bernardo Machado David, Markulf Kohlweiss, Ryo Nishimaki, Miyako Ohkubo |
J. Cryptol. | 2 |
| 2015 | Executable Proofs, Input-Size Hiding Secure Computation and a New Ideal World
Melissa Chase, Rafail Ostrovsky, Ivan Visconti |
EUROCRYPT (2) | 1 |
| 2015 | Substring-Searchable Symmetric EncryptionabstractAbstract In this paper, we consider a setting where a client wants to outsource storage of a large amount of private data and then perform substring search queries on the data – given a data string s and a search string p, find all occurrences of p as a substring of s. First, we formalize an encryption paradigm that we call queryable encryption, which generalizes searchable symmetric encryption (SSE) and structured encryption. Then, we construct a queryable encryption scheme for substring queries. Our construction uses suffix trees and achieves asymptotic efficiency comparable to that of unencrypted suffix trees. Encryption of a string of length n takes O(λn) time and produces a ciphertext of size O(λn), and querying for a substring of length m that occurs k times takes O(λm+k) time and three rounds of communication. Our security definition guarantees correctness of query results and privacy of data and queries against a malicious adversary. Following the line of work started by Curtmola et al. (ACM CCS 2006), in order to construct more efficient schemes we allow the query protocol to leak some limited information that is captured precisely in the definition. We prove security of our substring-searchable encryption scheme against malicious adversaries, where the query protocol leaks limited information about memory access patterns through the suffix tree of the encrypted string. Melissa Chase, Emily Shen |
Proc. Priv. Enhancing Technol. | 1 |
| 2014 | Algebraic MACs and Keyed-Verification Anonymous CredentialsabstractWe consider the problem of constructing anonymous credentials for use in a setting where the issuer of credentials is also the verifier, or more generally where the issuer and verifier have a shared key. In this setting we can use message authentication codes (MACs) instead of public key signatures as the basis for the credential system. Melissa Chase, Sarah Meiklejohn, Gregory M. Zaverucha |
CCS | 1 |
| 2014 | Malleable Signatures: New Definitions and Delegatable Anonymous CredentialsabstractA signature scheme is malleable if, on input a message and a signature, it is possible to efficiently compute a signature on a related message, for a transformation that is allowed with respect to this signature scheme. In this paper, we first provide new definitions for malleable signatures that allow us to capture a broader range of transformations than was previously possible. We then give a generic construction based on malleable zero-knowledge proofs that allows us to construct malleable signatures for a wide range of transformation classes, with security properties that are stronger than those that have been achieved previously. Finally, we construct delegatable anonymous credentials from signatures that are malleable with respect to an appropriate class of transformations (that we show our malleable signature supports). The resulting instantiation satisfies a stronger security notion than previous schemes while also scaling linearly with the number of delegations. Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Sarah Meiklejohn |
CSF | 1 |
| 2014 | Déjà Q: Using Dual Systems to Revisit q-Type Assumptions
Melissa Chase, Sarah Meiklejohn |
EUROCRYPT | 1 |
| 2013 | Succinct Malleable NIZKs and an Application to Compact Shuffles
Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Sarah Meiklejohn |
TCC | 1 |
| 2013 | Mercurial Commitments with Applications to Zero-Knowledge Sets
Melissa Chase, Alexander Healy, Anna Lysyanskaya, Tal Malkin, Leonid Reyzin |
J. Cryptol. | 1 |
| 2012 | Constant-Size Structure-Preserving Signatures: Generic Constructions and Simple Assumptions
Masayuki Abe, Melissa Chase, Bernardo Machado David, Markulf Kohlweiss, Ryo Nishimaki, Miyako Ohkubo |
ASIACRYPT | 2 |
| 2012 | Secure Database Commitments and Universal Arguments of Quasi Knowledge
Melissa Chase, Ivan Visconti |
CRYPTO | 1 |
| 2012 | Malleable Proof Systems and Applications
Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Sarah Meiklejohn |
EUROCRYPT | 1 |
| 2012 | Inspection resistant memory: Architectural support for security from physical examinationabstractThe ability to safely keep a secret in memory is central to the vast majority of security schemes, but storing and erasing these secrets is a difficult problem in the face of an attacker who can obtain unrestricted physical access to the underlying hardware. Depending on the memory technology, the very act of storing a 1 instead of a 0 can have physical side effects measurable even after the power has been cut. These effects cannot be hidden easily, and if the secret stored on chip is of sufficient value, an attacker may go to extraordinary means to learn even a few bits of that information. Solving this problem requires a new class of architectures that measurably increase the difficulty of physical analysis. In this paper we take a first step towards this goal by focusing on one of the backbones of any hardware system: on-chip memory. We examine the relationship between security, area, and efficiency in these architectures, and quantitatively examine the resulting systems through cryptographic analysis and microarchitectural impact. In the end, we are able to find an efficient scheme in which, even if an adversary is able to inspect the value of a stored bit with a probabilistic error of only 5%, our system will be able to prevent that adversary from learning any information about the original un-coded bits with 99.9999999999% probability. Jonathan Valamehr, Melissa Chase, Seny Kamara, Andrew Putnam, Daniel Shumow, Vinod Vaikuntanathan, Timothy Sherwood |
ISCA | 2 |
| 2012 | Functional Re-encryption and Collusion-Resistant Obfuscation
Nishanth Chandran, Melissa Chase, Vinod Vaikuntanathan |
TCC | 2 |
| 2010 | Structured Encryption and Controlled Disclosure
Melissa Chase, Seny Kamara |
ASIACRYPT | 1 |
| 2009 | Improving privacy and security in multi-authority attribute-based encryptionabstractAttribute based encryption (ABE) [13] determines decryption ability based on a user's attributes. In a multi-authority ABE scheme, multiple attribute-authorities monitor different sets of attributes and issue corresponding decryption keys to users, and encryptors can require that a user obtain keys for appropriate attributes from each authority before decrypting a message. Chase [5] gave a multi-authority ABE scheme using the concepts of a trusted central authority (CA) and global identifiers (GID). However, the CA in that construction has the power to decrypt every ciphertext, which seems somehow contradictory to the original goal of distributing control over many potentially untrusted authorities. Moreover, in that construction, the use of a consistent GID allowed the authorities to combine their information to build a full profile with all of a user's attributes, which unnecessarily compromises the privacy of the user. In this paper, we propose a solution which removes the trusted central authority, and protects the users' privacy by preventing the authorities from pooling their information on particular users, thus making ABE more usable in practice. Melissa Chase, Sherman S. M. Chow |
CCS | 1 |
| 2009 | Randomizable Proofs and Delegatable Anonymous Credentials
Mira Belenkiy, Jan Camenisch, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya, Hovav Shacham |
CRYPTO | 3 |
| 2009 | Compact E-Cash and Simulatable VRFs Revisited
Mira Belenkiy, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya |
Pairing | 2 |
| 2008 | P-signatures and Noninteractive Anonymous Credentials
Mira Belenkiy, Melissa Chase, Markulf Kohlweiss, Anna Lysyanskaya |
TCC | 2 |
| 2007 | Simulatable VRFs with Applications to Multi-theorem NIZK
Melissa Chase, Anna Lysyanskaya |
CRYPTO | 1 |
| 2007 | Multi-authority Attribute Based Encryption
Melissa Chase |
TCC | 1 |
| 2006 | On Signatures of Knowledge
Melissa Chase, Anna Lysyanskaya |
CRYPTO | 1 |
| 2005 | Mercurial Commitments with Applications to Zero-Knowledge Sets
Melissa Chase, Alexander Healy, Anna Lysyanskaya, Tal Malkin, Leonid Reyzin |
EUROCRYPT | 1 |