EDBT 2026 Demo / reviewers in the wild / expert
Danilo Francati
dblp:231/4539
· DBLP profile ↗
18ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0002-4639-0636ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 9 first-author · 13 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Coding Limits of Robust Watermarking for Generative ModelsabstractWe study a basic question about cryptographic watermarking for generative models: how reliable can a watermark remain when an adversary is allowed to corrupt the encoded signal? To address this question, we introduce a minimal coding abstraction that we call a zero-bit tamper-detection code. This is a secret-key procedure that samples a pseudorandom codeword and, given a candidate word, decides whether it should be treated as unmarked content or as the result of tampering with a valid codeword. It captures the two core requirements of robust watermarking: soundness and tamper detection. Within this abstraction we prove a sharp unconditional limit on robustness to independent symbol corruption. For an alphabet of size $q$, there is a critical corruption rate of $1-1/q$ such that no scheme with soundness, even relaxed to allow a fixed constant false positive probability on random content, can reliably detect tampering once an adversary can change more than this fraction of symbols. In particular, in the binary case no cryptographic watermark can remain robust if more than half of the encoded bits are modified. We also show that this threshold is tight by giving simple information-theoretic constructions that achieve soundness and tamper detection for all strictly smaller corruption rates. We then test experimentally whether this limit appears in practice by looking at the recent watermarking for images of Gunn, Zhao, and Song (ICLR 2025). We show that a simple crop and resize operation reliably flipped about half of the latent signs and consistently prevented belief-propagation decoding from recovering the codeword, erasing the watermark while leaving the image visually intact. Danilo Francati, Yevin Nikhel Goonatilake, Shubham Vivek Pawar, Daniele Venturi 0001, Giuseppe Ateniese |
EuroS&P | 1 |
| 2025 | Registered Matchmaking Encryption
Danilo Francati, Valeria Huang, Daniele Venturi 0001 |
ACNS (1) | 1 |
| 2025 | Taming Adaptive Security and New Access Structures in Evolving Secret Sharing
Danilo Francati, Sara Giammusso, Daniele Venturi 0001 |
ASIACRYPT (8) | 1 |
| 2025 | Evolving secret sharing revisited: computational security and succinctnessabstractAbstract Evolving secret sharing (Komargodski, Naor, and Yogev, TCC’16) generalizes the notion of secret sharing to the setting of evolving access structures, in which the share holders are added to the system in an online manner, and where the dealer does not know neither the access structure nor the maximum psnber of parties in advance. Here, the main difficulty is to distribute shares to the new players without updating the shares of old players; moreover, one would like to minimize the share size as a function of the psnber of players. In this paper, we initiate a systematic study of evolving secret sharing in the computational setting, where the maximum psnber of parties is polynomial in the security parameter, but the dealer still does not know this value, neither it knows the access structure in advance. Moreover, the privacy guarantee only holds against computationally bounded adversaries corrupting an unauthorized subset of the players. Our main result is that for many interesting, and practically relevant, evolving access structures, under standard hardness assumptions, there exist efficient secret sharing schemes with computational privacy and in which the shares are succinct (i.e., much smaller compared to the size of a natural computational representation of the evolving access structure). These access structures include evolving graphs access structures, threshold access structures, and monotone circuits/DNF/CNF access structures meeting an additional rigidity property that we show to be necessary if one wants to avoid updating the shares of old parties. Danilo Francati, Daniele Venturi 0001 |
Des. Codes Cryptogr. | 1 |
| 2024 | Non-malleable Fuzzy Extractors
Danilo Francati, Daniele Venturi 0001 |
ACNS (1) | 1 |
| 2024 | Evolving Secret Sharing Made Short
Danilo Francati, Daniele Venturi 0001 |
ASIACRYPT (7) | 1 |
| 2024 | Advancing Scalability in Decentralized Storage: A Novel Approach to Proof-of-Replication via Polynomial Evaluation
Giuseppe Ateniese, Foteini Baldimtsi, Matteo Campanelli, Danilo Francati, Ioanna Karantaidou |
CRYPTO (2) | 4 |
| 2024 | Watermarks in the Sand: Impossibility of Strong Watermarking for Language ModelsabstractWatermarking generative models consists of planting a statistical signal (watermark) in a model’s output so that it can be later verified that the output was generated by the given model. A strong watermarking scheme satisfies the property that a computationally bounded attacker cannot erase the watermark without causing significant quality degradation. In this paper, we study the (im)possibility of strong watermarking schemes. We prove that, under well-specified and natural assumptions, strong watermarking is impossible to achieve. This holds even in the private detection algorithm setting, where the watermark insertion and detection algorithms share a secret key, unknown to the attacker. To prove this result, we introduce a generic efficient watermark attack; the attacker is not required to know the private key of the scheme or even which scheme is used. Our attack is based on two assumptions: (1) The attacker has access to a "quality oracle" that can evaluate whether a candidate output is a high-quality response to a prompt, and (2) The attacker has access to a "perturbation oracle" which can modify an output with a nontrivial probability of maintaining quality, and which induces an efficiently mixing random walk on high-quality outputs. We argue that both assumptions can be satisfied in practice by an attacker with weaker computational capabilities than the watermarked model itself, to which the attacker has only black-box access. Furthermore, our assumptions will likely only be easier to satisfy over time as models grow in capabilities and modalities. We demonstrate the feasibility of our attack by instantiating it to attack three existing watermarking schemes for large language models: Kirchenbauer et al. (2023), Kuditipudi et al. (2023), and Zhao et al. (2023), and include preliminary results on vision-language models. The same attack successfully removes the watermarks planted by all schemes, with only minor quality degradation. Hanlin Zhang 0002, Benjamin L. Edelman, Danilo Francati, Daniele Venturi 0001, Giuseppe Ateniese, Boaz Barak |
ICML | 3 |
| 2024 | Breach Extraction Attacks: Exposing and Addressing the Leakage in Second Generation Compromised Credential Checking ServicesabstractCredential tweaking attacks use breached passwords to generate semantically similar passwords and gain access to victims’ services. These attacks sidestep the first generation of compromised credential checking (C3) services. The second generation of compromised credential checking services, called “Might I Get Pwned” (MIGP), is a privacy-preserving protocol that defends against credential tweaking attacks by allowing clients to query whether a password or a semantically similar variation is present in the server’s compromised credentials dataset. The desired privacy requirements include not revealing the user’s entered password to the server and ensuring that no compromised credentials are disclosed to the client.In this work, we formalize the cryptographic leakage of the MIGP protocol and perform a security analysis to assess its impact on the credentials held by the server. We focus on how this leakage aids breach extraction attacks, where an honest-but-curious client interacts with the server to extract information about the stored credentials. Furthermore, we discover additional leakage that arises from the implementation of Cloudflare’s deployment of MIGP. We evaluate how the discovered leakage affects the guessing capability of an attacker in relation to breach extraction attacks. Finally, we propose MIGP 2.0, a new iteration of the MIGP protocol designed to minimize data leakage and prevent the introduced attacks. Dario Pasquini, Danilo Francati, Giuseppe Ateniese, Evgenios M. Kornaropoulos |
SP | 2 |
| 2024 | Multi-key and Multi-input Predicate Encryption (for Conjunctions) from Learning with ErrorsabstractAbstract We put forward two natural generalizations of predicate encryption (PE), dubbed multi-key and multi-input PE. More in details, our contributions are threefold. Definitions. We formalize security of multi-key PE and multi-input PE following the standard indistinguishability paradigm, and modeling security both against malicious senders (i.e., corruption of encryption keys) and malicious receivers (i.e., collusions). Constructions. We construct adaptively secure multi-key and multi-input PE supporting the conjunction of poly-many arbitrary single-input predicates, assuming the sub-exponential hardness of the learning with errors (LWE) problem. Applications. We show that multi-key and multi-input PE for expressive enough predicates suffices for interesting cryptographic applications, including non-interactive multi-party computation (NI-MPC) and matchmaking encryption (ME). In particular, plugging in our constructions of multi-key and multi-input PE, under the sub-exponential LWE assumption, we obtain the first ME supporting arbitrary policies with unbounded collusions, as well as robust (resp. non-robust) NI-MPC for so-called all-or-nothing functions satisfying a non-trivial notion of reusability and supporting a constant (resp. polynomial) number of parties. Prior to our work, both of these applications required much heavier tools such as indistinguishability obfuscation or compact functional encryption. Danilo Francati, Daniele Friolo, Giulio Malavolta, Daniele Venturi 0001 |
J. Cryptol. | 1 |
| 2023 | Registered (Inner-Product) Functional Encryption
Danilo Francati, Daniele Friolo, Monosij Maitra, Giulio Malavolta, Ahmadreza Rahimi, Daniele Venturi 0001 |
ASIACRYPT (5) | 1 |
| 2023 | Multi-key and Multi-input Predicate Encryption from Learning with Errors
Danilo Francati, Daniele Friolo, Giulio Malavolta, Daniele Venturi 0001 |
EUROCRYPT (3) | 1 |
| 2022 | Eluding Secure Aggregation in Federated Learning via Model InconsistencyabstractSecure aggregation is a cryptographic protocol that securely computes the aggregation of its inputs. It is pivotal in keeping model updates private in federated learning. Indeed, the use of secure aggregation prevents the server from learning the value and the source of the individual model updates provided by the users, hampering inference and data attribution attacks. Dario Pasquini, Danilo Francati, Giuseppe Ateniese |
CCS | 2 |
| 2021 | Match Me if You Can: Matchmaking Encryption and Its Applications
Giuseppe Ateniese, Danilo Francati, David Nuñez 0001, Daniele Venturi 0001 |
J. Cryptol. | 2 |
| 2021 | Immunization against complete subversion without random oracles
Giuseppe Ateniese, Danilo Francati, Bernardo Magri, Daniele Venturi 0001 |
Theor. Comput. Sci. | 2 |
| 2020 | Arcula: A Secure Hierarchical Deterministic Wallet for Multi-asset Blockchains
Adriano Di Luzio, Danilo Francati, Giuseppe Ateniese |
CANS | 2 |
| 2019 | Public Immunization Against Complete Subversion Without Random Oracles
Giuseppe Ateniese, Danilo Francati, Bernardo Magri, Daniele Venturi 0001 |
ACNS | 2 |
| 2019 | Match Me if You Can: Matchmaking Encryption and Its Applications
Giuseppe Ateniese, Danilo Francati, David Nuñez 0001, Daniele Venturi 0001 |
CRYPTO (2) | 2 |