EDBT 2026 Demo / reviewers in the wild / expert
Zachary Ratliff
dblp:364/9508
· DBLP profile ↗
5ranked-venue papers
5as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 first-author · 5 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mirage: Private, Mobility-based Routing for Censorship Evasion
Zachary Ratliff, RuoxingYang, Avery Bai, Harel Berger, Micah Sherr, James W. Mickens |
NDSS | 1 |
| 2025 | Timing Attacks on Differential Privacy are PracticalabstractDifferential privacy (DP) has become a standard approach for computing privacy-preserving statistics. However, in interactive settings, the observable runtime of DP queries can inadvertently leak sensitive information, violating privacy guarantees. Prior work has shown that timing side channels can undermine DP in specific settings. In this work, we show that popular libraries for implementing differential privacy, including diffprivlib, OpenDP, and PyDP, frequently introduce such timing side channels, leading to measurable privacy degradation. Our analysis reveals timing vulnerabilities not only within commonly used DP mechanisms (e.g., private sums, counts, means, and selection) but also in commonly used pre-processing steps such as filtering and sorting. We show that these seemingly innocuous operations frequently exhibit runtimes that are sensitive not only to the presence of an individual's data in the input but also to the ordering of the input data. Zachary Ratliff, Nicolás Berrios, James W. Mickens |
CCS | 1 |
| 2025 | Securing Unbounded Differential Privacy Against Timing Attacks
Zachary Ratliff, Salil P. Vadhan |
TCC (4) | 1 |
| 2024 | A Framework for Differential Privacy Against Timing AttacksabstractThe standard definition of differential privacy (DP) ensures that a mechanism's output distribution on adjacent datasets is indistinguishable. However, real-world implementations of DP can, and often do, reveal information through their runtime distributions, making them susceptible to timing attacks. Zachary Ratliff, Salil P. Vadhan |
CCS | 1 |
| 2024 | Holepunch: Fast, Secure File Deletion with Crash ConsistencyabstractA file system provides secure deletion if, after a file is deleted, an attacker with physical possession of the storage device cannot recover any data from the deleted file. Unfortunately, secure deletion is not provided by commodity file systems. Even file systems which explicitly desire to provide secure deletion are challenged by the subtleties of hardware controllers on modern storage devices; those controllers obscure the mappings between logical blocks and physical blocks, silently duplicate physical blocks, and generally make it hard for host-level software to make reliable assumptions about how file data is kept on the device. State-of-the-art frameworks for secure deletion also have no crash consistency, meaning that an ill-timed power outage or software fault will desynchronize keys and the associated encrypted file data, corrupting the file system.In this paper, we present Holepunch, a new software-level approach for implementing secure deletion. Holepunch treats the storage device as a black box, providing secure deletion via cryptographic erasure. Holepunch uses per-file keys to transparently encrypt outgoing file writes and decrypt incoming file reads, ensuring that all physical data in the storage device is always encrypted. Holepunch uses puncturable pseudorandom functions (PPRFs) to quickly access file keys; upon the deletion of file f, Holepunch updates the PPRF so that, even if the PPRF is recovered, the PPRF cannot be used to generate f’s key. By using PPRFs instead of the key trees leveraged by prior work, Holepunch reduces both the memory pressure caused by key management and the number of disk IOs needed to access files. Holepunch stores its master key in secure TPM storage, and uses a novel journaling scheme to provide crash consistency between TPM state and on-disk state. Zachary Ratliff, Wittmann Goh, Abe Wieland, James W. Mickens |
SP | 1 |