Pith. sign in

REVIEW 3 major objections 4 minor 62 references

Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations

T0 review · 3 major / 4 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read Intermittent observation of encrypted search leakage is enough to recover the underlying queries with around 90% accuracy.

desk verdict Genuinely new attacker model, solid experiments, but the padding claim is overstated and the co-occurrence-stability assumption needs a stress test. read the letter →

arxiv 2509.03806 v1 pith:AMUDDRPH submitted 2025-09-04 cs.CR

classification cs.CR
keywords DynamicSearchableSymmetricEncryptionleakageabuseattackintermittentobservationsearchpatternrecoveryqueryco-occurrencematrixquadraticassignmentproblempassive
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper asks whether a passive attacker who only observes the leakage of a dynamic encrypted search system during short, separated time windows can still recover what the client is searching for. It argues yes: even when the attacker cannot link queries across rounds by matching files, the stable co-occurrence of keywords inside the documents lets the attacker regroup queries round by round and then run standard query-recovery attacks on the merged groups. On email corpora the claimed result is an adjusted rand index above 0.9 for recovering the search pattern and roughly 90% query-recovery accuracy with access-pattern leakage, compared with about 30% for the previous FMA attack. If true, intermittent observation does not meaningfully protect DSSE users: the threat model assumed by earlier attacks is not needed for highly effective query recovery.

What carries the argument

The load-bearing object is the co-occurrence matrix of query groups: entry (i,j) is the normalized count of files returned in common by queries of group i and group j within a round. Because file identities are refreshed between rounds, the paper replaces identity matching with graph matching: it builds a co-occurrence matrix for each round's groups and aligns matrices across rounds by solving a quadratic assignment problem (using the IHOP heuristic), pruning low-confidence matches. This carries the whole external search-pattern inference; everything else—frequency, volume, and co-occurrence for query recovery—is derived from these merged groups.

What would settle it

A decisive test is to run Peekaboo on a DSSE trace where between every observation round the corpus is replaced by documents with unrelated keyword co-occurrence, for example messages on disjoint topics. If the adjusted rand index for search-pattern recovery stays above 0.9, the co-occurrence assumption is not actually load-bearing; if it collapses, the premise is confirmed as what makes the attack work.

Watch

Extended reading notes

Core claim

Peekaboo's central claim is that the search pattern—the partition of observed queries by the keyword they issue for—is inferable even under intermittent observation. Within one observation round, queries are grouped by similarity of their access pattern or file-volume pattern. The key step for cross-round linkage is that groups from different rounds are matched not by file identity (which changes with updates and re-encryption) but by their co-occurrence matrix, i.e., how often two query groups return files in common; this matrix is assumed stable across rounds. Matching is then a quadratic assignment problem solved with the IHOP heuristic. Once rounds are stitched together, the attacker der

Load-bearing premise

Keyword co-occurrence in the client's document collection stays stable across observation rounds, even though which files contain which keywords changes; if the topic mix shifts greatly between rounds, the graph matching used to align rounds breaks down.

Editorial extensions

If this is right

  • Search-pattern recovery with ARI above 0.9 means the internal and external search pattern cannot be treated as concealed from intermittent observers.
  • Query recovery reaches about 90% accuracy with access-pattern leakage and about 50% with file-volume-pattern leakage on tested email corpora, roughly tripling the accuracy of the previous FMA attack.
  • Accuracy grows with the number of observation rounds and the number of observed queries, so even short repeated observation windows are dangerous.
  • File-size padding degrades the attack only partially, and access-pattern obfuscation at tested parameters leaves Jigsaw+ near 90% accuracy.
  • The framework is generic: any similar-data attack that relies on frequency, volume, or co-occurrence can be instantiated as an 'Attack+' variant for intermittent observation.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Inference: If co-occurrence stability holds beyond the tested email corpora, similar attacks should transfer to other encrypted-search settings that leak access or file-volume patterns, such as structured encryption or encrypted databases, not just DSSE.
  • Inference: The defensive lesson is that countermeasures must perturb the co-occurrence structure between rounds, not merely pad file sizes; padding only removes a portion of the file-volume signal.
  • Inference: A testable extension is to measure how much topic drift between rounds is needed to break the attack; the paper's stability assumption predicts a threshold beyond which graph matching fails, and that threshold could be measured on real document streams.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper introduces a passive attack framework, Peekaboo, against Dynamic Searchable Symmetric Encryption (DSSE) under an intermittent-observation attacker (IOA) model. The attacker observes leakage in short, separated rounds rather than continuously. Peekaboo infers the search pattern (SP) in two steps: internal SP via response-similarity grouping (Algorithm 1) and external SP via co-occurrence matrices matched across rounds with a quadratic assignment problem (Algorithm 2). It then instantiates query recovery by adapting two prior similar-data attacks, Sap and Jigsaw, into Sap+ and Jigsaw+ (Algorithm 3). The evaluation on Enron, Lucene, and Wikipedia reports adjusted Rand index above 0.9 for SP inference in most settings, query accuracy around 90% with AP leakage and around 50% with FVP on Enron/Lucene, and comparisons against FMA and against idealized 'with SP' baselines. The paper also evaluates countermeasures (file-size padding and access-pattern obfuscation) and provides public code.

Significance. The intermittent-observation threat model is a meaningful extension of prior persistent-attacker models, and the idea of using stable keyword co-occurrence to bridge observation gaps is novel and plausible. The framework is general in that it can be instantiated on multiple similar-data attacks, and the evaluation includes useful upper-bound comparisons with oracle SP knowledge. The code is provided, and the experiments cover multiple datasets and leakage types. If the results are representative, the attack is a clear improvement over FMA, which is the main prior DSSE passive attack in the same setting. However, the central co-occurrence-stability assumption is empirical and not stress-tested beyond the particular update schedules used, and some headline claims in the abstract outrun the reported numbers.

major comments (3)
  1. [Abstract and §6 (Figure 10)] The abstract claims '>40% accuracy against file size padding', but §6 reports that both Jigsaw+ and Sap+ drop from roughly 50% to about 20% accuracy under padding on Enron and Lucene, with FMA at about 20%–35%. The >40% figure appears to hold only for the 'with SP' baselines or for particular configurations, not for the actual Peekaboo instantiations. This is a direct contradiction between the advertised robustness and the evaluation. The abstract and the contribution list should be corrected or the claim should be restricted to the settings that support it.
  2. [§3.2, Eq. (4), Algorithm 2, Fig. 5, Appendix J] The external-SP inference relies on the premise stated in §3.2 that keyword co-occurrence remains stable across rounds. This is an empirical assumption about the document corpus, not a property of the DSSE leakage. The QAP matching in Eq. (4) aligns C1 and C2, but if the joint distribution of keywords and documents drifts due to deletions, topic change, or large re-encryption, the matrices are no longer close up to permutation and the matching will systematically misalign groups. The paper's own Figure 5 shows ARI decreasing as the number of rounds grows, and Appendix J reports only about 40% FVP accuracy on Wikipedia. Because Algorithm 3 consumes the merged groups produced by Algorithm 2, errors in external SP propagate into query recovery. The authors should quantify the stability regime (e.g., measure co-occurrence matrix drift under their update schedules) and either add topic-shift/
  3. [§5.3, Figs. 6–9, Appendix J] The headline '90% query accuracy vs. FMA's 30%' is reported for AP leakage on Enron/Lucene with the default keyword universe. The same section reports FVP accuracy of only about 50% for Jigsaw+, and Appendix J gives about 40% FVP and around 80% AP on Wikipedia. Figure 9 also shows accuracy degrading sharply as |W| grows (e.g., Enron AP from >95% at |W|=500 to 70% at |W|=3000). The summary claims should therefore be stated as conditional on leakage type, dataset, and keyword universe, not as universal properties of Peekaboo. This is a reporting/scope issue, but it affects the abstract and the paper's central message.
minor comments (4)
  1. [Appendix F] The text says Jigsaw+ and Sap+ 'have the best accuracy of above 90% and 0.6%, respectively.' The '0.6%' is presumably a typo for '60%' or similar; as written it is inconsistent with the figures and with the accuracy values reported elsewhere.
  2. [§3.2] The sentence 'the attacker cannot distinguish whether two encrypted files from two rounds are under the same file' should read '... are the same file' or '... belong to the same file.' The current phrasing is confusing.
  3. [Abstract] The symbol '∽' before percentages is nonstandard; use '~' or 'approximately' consistently.
  4. [§5.3 and Appendix J] The Wikipedia results are confined to an appendix, but they materially qualify the main claims (especially the FVP results). Consider presenting at least the Wikipedia summary in the main body or explicitly flagging in Section 5 that the headline numbers are dataset-specific.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: Peekaboo's SP inference is an independent statistical attack; query recovery is evaluated against ground truth and an external FMA baseline.

full rationale

The paper's central derivation is an intermittent-observation attack with three components: (i) internal SP inference via response similarity (Eqs. 1–3, Algorithm 1); (ii) external SP inference by matching co-occurrence matrices across rounds via a QAP (Eq. 4, Algorithm 2); and (iii) query recovery via adapted versions of Sap and Jigsaw (Eqs. 5–8, Algorithm 3). None of these steps defines its target in terms of its conclusion. The co-occurrence persistence assumption ('the co-occurrence of queries (i.e., the probability of two queries appearing in the same file) remains across different rounds') is an explicit empirical premise about the dataset, not a consequence of the attack; it is falsifiable, and the paper itself reports degradation with more rounds (Fig. 5) and lower FVP accuracy on Wikipedia (App. J). The auxiliary knowledge (half of the dataset as a similar dataset and true PageViews query frequencies) is a standard similar-data input, not an output fitted to the evaluation; the attack's accuracy is measured against the true keyword partition and against the external FMA baseline. Hyperparameters (δ, maxlevel, pg) are tuned, but they are not the recovered keywords and the paper reports sensitivity analyses. The only self-citation is the use of the authors' prior Jigsaw [34] as the base for Jigsaw+; this is an implementation choice, not an unverified premise used to forbid alternatives or to import uniqueness. Hence no circular step is present.

Assumptions & free parameters 6 free parameters · 5 assumptions · 0 invented entities

The attack's success depends on three classes of inputs: (1) data-distribution assumptions about co-occurrence stability and within-round response similarity; (2) auxiliary knowledge of a similar dataset and keyword frequencies, standard in similar-data attacks; and (3) the correctness of the QAP solver (IHOP). The paper contributes heuristics, not proofs, so these are the axioms on which the empirical claims rest. The fitted hyperparameters are listed in free_parameters.

free parameters (6)
  • delta (response similarity threshold) = 0.95 (default); sensitivity 0.6-0.95
    Controls whether two queries are grouped as same keyword; tuned on Enron/Lucene (Appendix F, Fig. 12a).
  • maxlevel = 5
    Limits cross-round matching; tuned to near-maximum accuracy (Appendix F, Fig. 12b).
  • pg (ratio of removed matches) = 0.05 default; 0.15 under padding
    Discards low-confidence group matches; tuned on datasets (Appendix F, Fig. 12c-12d).
  • alpha (Jigsaw+ distance weight) = 0.5
    Inherited from Jigsaw and left at the recommended value.
  • beta (Jigsaw+ weight between co-occurrence and distance) = 0.9 (AP default), 0.7 (large universe/padding)
    Inherited from Jigsaw; adjusted per experiment (Section 5.3, Section 6).
  • BaseRec, ConfRec (Jigsaw+ seeding parameters) = BaseRec=25/15, ConfRec=10/5 for AP/FVP
    Set differently for AP vs FVP experiments (Section 5.3).
assumptions (5)
  • domain assumption Co-occurrence of keywords in the database persists across rounds and updates.
    Stated in Section 3.2: 'the co-occurrence of queries ... remains across different rounds'. This is the basis for matching groups across rounds with QAP; if the co-occurrence structure changes substantially, external SP inference fails.
  • domain assumption Queries for the same keyword within a short observation round produce similar AP/FVP leakage above threshold delta.
    Used in Algorithm 1 (Section 3.1); assumes limited database changes within a round.
  • domain assumption The attacker has a similar auxiliary dataset and the true query frequency distribution of keywords.
    Standard in similar-data attacks (Sap, Jigsaw); used in P2 for query recovery (Section 4.1).
  • domain assumption The DSSE leaks AP or FVP to an eavesdropper but conceals the SP across rounds.
    Section 2.1; needed for both P1 and P2. Not proven for all DSSE schemes.
  • standard math The QAP solver (IHOP) finds a mapping close to the true correspondence between co-occurrence matrices.
    The paper invokes existing algorithms (Section 3.2, Appendix E) without proof of correctness in this setting; empirical validation only.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations." pith.science (2026). https://pith.science/paper/AMUDDRPH

@misc{pith2026250903806,
  author       = {Pith},
  title        = {Pith review of: Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/AMUDDRPH}},
  note         = {Machine review of arXiv:2509.03806}
}
read the original abstract

Dynamic Searchable Symmetric Encryption (DSSE) allows secure searches over a dynamic encrypted database but suffers from inherent information leakage. Existing passive attacks against DSSE rely on persistent leakage monitoring to infer leakage patterns, whereas this work targets intermittent observation - a more practical threat model. We propose Peekaboo - a new universal attack framework - and the core design relies on inferring the search pattern and further combining it with auxiliary knowledge and other leakage. We instantiate Peekaboo over the SOTA attacks, Sap (USENIX' 21) and Jigsaw (USENIX' 24), to derive their "+" variants (Sap+ and Jigsaw+). Extensive experiments demonstrate that our design achieves >0.9 adjusted rand index for search pattern recovery and 90% query accuracy vs. FMA's 30% (CCS' 23). Peekaboo's accuracy scales with observation rounds and the number of observed queries but also it resists SOTA countermeasures, with >40% accuracy against file size padding and >80% against obfuscation.

Figures

Figures reproduced from arXiv: 2509.03806 by the authors.

Figure 1
Figure 1. Intermittent observations: Case I, the attacker can [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Internal and external SP of search queries. The [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 1
Figure 1. We refer to each online-then-offline cycle as a round and [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figures from the paper (14 more)
Figure 3
Figure 3. Figure 3: Overview: the Peekaboo attack. Moreover, additions and deletions on files make the patterns from two rounds more distorted, making it more difficult to correlate patterns across different observation periods. Differences between the persistent attacker and the IOA. We …
Figure 4
Figure 4. Figure 4: The ARI of the search pattern inferring of Peekaboo [PITH_FULL_IMAGE:figures/full_fig_p010_4.png]
Figure 5
Figure 5. Figure 5: The ARI of the search pattern inferring of Peekaboo [PITH_FULL_IMAGE:figures/full_fig_p010_5.png]
Figure 6
Figure 6. Figure 6: The accuracy results of Jigsaw+, Sap+, FMA, Jigsaw+ with SP, and Sap+ with SP in Enron and Lucene with different [PITH_FULL_IMAGE:figures/full_fig_p011_6.png]
Figure 7
Figure 7. Figure 7: The accuracy results of Jigsaw+, Sap+, FMA, Jigsaw+ with SP, and Sap+ with SP in Enron and Lucene with different [PITH_FULL_IMAGE:figures/full_fig_p011_7.png]
Figure 8
Figure 8. Figure 8: The accuracy results of Jigsaw+, Sap+, FMA, Jigsaw+ with SP, and Sap+ with SP in Enron and Lucene with different [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]
Figure 9
Figure 9. Figure 9: The accuracy of Jigsaw+, Sap+, FMA, Jigsaw+ with [PITH_FULL_IMAGE:figures/full_fig_p012_9.png]
Figure 10
Figure 10. Figure 10: The accuracy of Jigsaw+, Sap+, FMA, Jigsaw+ with [PITH_FULL_IMAGE:figures/full_fig_p013_10.png]
Figure 11
Figure 11. Figure 11: The accuracy of Jigsaw+, Sap+, FMA, Jigsaw+ with [PITH_FULL_IMAGE:figures/full_fig_p013_11.png]
Figure 12
Figure 12. Figure 12: The accuracy of Jigsaw+ and Sap+ with different [PITH_FULL_IMAGE:figures/full_fig_p018_12.png]
Figure 14
Figure 14. Figure 14: The accuracy of Jigsaw+ and Jigsaw+ without query [PITH_FULL_IMAGE:figures/full_fig_p019_14.png]
Figure 13
Figure 13. Figure 13: The accuracy of Jigsaw+ and IHOP+ in Enron with [PITH_FULL_IMAGE:figures/full_fig_p019_13.png]
Figure 15
Figure 15. Figure 15: The accuracy of Jigsaw+, Sap+, Jigsaw+ with SP, and Sap+ with SP in Wikipedia under varying conditions, i.e., number [PITH_FULL_IMAGE:figures/full_fig_p020_15.png]
Figure 16
Figure 16. Figure 16: The accuracy of Jigsaw+, Sap+, Jigsaw+ with SP, and Sap+ with SP in Enron and Lucene with different number of [PITH_FULL_IMAGE:figures/full_fig_p020_16.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

62 extracted references · 47 canonical work pages

  1. [1]

    Latest Trickbot Variant has New Tricks Up Its Sleeve

    2018. Latest Trickbot Variant has New Tricks Up Its Sleeve. https://www.cyberbit. com/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/

  2. [2]

    DBIR: Data Breach Investigations Report

    2022. DBIR: Data Breach Investigations Report. https://www.verizon.com/ business/en-gb/resources/2022-data-breach-investigations-report-dbir.pdf

  3. [3]

    WHO Model List of Essential Medicines

    2023. WHO Model List of Essential Medicines. https://www.who.int/publications/ i/item/WHO-MHP-HPS-EML-2023.02

  4. [4]

    DBIR: 2024 Data Breach Investigations Report

    2024. DBIR: 2024 Data Breach Investigations Report. https: //www.verizon.com/business/resources/T16f/reports/2024-dbir-data-breach- investigations-report.pdf

  5. [5]

    State of Security 2024

    2024. State of Security 2024. https://www.splunk.com/en_us/pdfs/gated/ebooks/ state-of-security-2024.pdf

  6. [6]

    Almuthanna Alageel, Sergio Maffeis, and Imperial College London. 2025. Investi- gation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures. CoRR abs/2502.08830 (2025). arXiv:2502.08830 doi:10.48550/ARXIV. 2502.08830

  7. [7]

    N Ambika. 2020. Improved Methodology to Detect Advanced Persistent Threat Attacks. In Quantum Cryptography and the Future of Cyber Security

  8. [8]

    Ghous Amjad, Seny Kamara, and Tarik Moataz. 2019. Breach-Resistant Structured Encryption. Proc. Priv. Enhancing Technol. 2019, 1 (2019), 245–265. doi:10.2478/ POPETS-2019-0014

Show all 62 references
  1. [9]

    Laura Blackstone, Seny Kamara, and Tarik Moataz. 2020. Revisiting Leakage Abuse Attacks. In 27th Annual Network and Distributed System Security Sympo- sium. https://www.ndss-symposium.org/ndss-paper/revisiting-leakage-abuse- attacks/

  2. [10]

    Raphael Bost. 2016. Ío𝜑o𝜍: Forward Secure Searchable Encryption. In Pro- ceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 1143–1154. doi:10.1145/2976749.2978303

  3. [11]

    Raphaël Bost, Brice Minaud, and Olga Ohrimenko. 2017. Forward and Backward Private Searchable Encryption from Constrained Cryptographic Primitives. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 1465–1482. doi:10.1145/3133956.3133980

  4. [12]

    David Cash, Paul Grubbs, Jason Perry, and Thomas Ristenpart. 2015. Leakage- Abuse Attacks Against Searchable Encryption. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security . 668–679. doi:10. 1145/2810103.2813700

  5. [13]

    Reiter, and Yinqian Zhang

    Guoxing Chen, Ten-Hwang Lai, Michael K. Reiter, and Yinqian Zhang. 2018. Differentially Private Access Patterns for Searchable Symmetric Encryption. In 2018 IEEE Conference on Computer Communications . 810–818. doi:10.1109/ INFOCOM.2018.8486381

  6. [14]

    Tianyang Chen, Peng Xu, Stjepan Picek, Bo Luo, Willy Susilo, Hai Jin, and Kaitai Liang. 2023. The Power of Bamboo: On the Post-Compromise Security for Searchable Symmetric Encryption. In30th Annual Network and Distributed System Security Symposium. https://www.ndss-symposium.o...

  7. [15]

    Yihao Chen, Qilei Yin, Qi Li, Zhuotao Liu, Ke Xu, Yi Xu, Mingwei Xu, Ziqian Liu, and Jianping Wu. 2024. Learning with Semantics: Towards a Semantics- Aware Routing Anomaly Detection System. In 33rd USENIX Security Symposium . https://www.usenix.org/conference/usenixsecurity24/...

  8. [16]

    Reza Curtmola, Juan Garay, Seny Kamara, and Rafail Ostrovsky. 2006. Searchable symmetric encryption: improved definitions and efficient constructions. In Pro- ceedings of the 13th ACM Conference on Computer and Communications Security . 79–88. doi:10.1145/1180405.1180417

  9. [17]

    Marc Damie, Florian Hahn, and Andreas Peter. 2021. A Highly Accurate Query-Recovery Attack against Searchable Encryption using Non-Indexed Doc- uments. In 30th USENIX Security Symposium . 143–160. https://www.usenix.org/ conference/usenixsecurity21/presentation/damie

  10. [18]

    Haochen Dou, Zhenwu Dan, Peng Xu, Wei Wang, Shuning Xu, Tianyang Chen, and Hai Jin. 2024. Dynamic Searchable Symmetric Encryption With Strong Security and Robustness. IEEE Trans. Inf. Forensics Secur. 19 (2024), 2370–2384. doi:10.1109/TIFS.2024.3350330

  11. [19]

    Yang Du, Daniel Genkin, and Paul Grubbs. 2022. Snapshot-Oblivious RAMs: Sub- logarithmic Efficiency for Short Transcripts. In Advances in Cryptology - CRYPTO 2022 - 42nd Annual International Cryptology Conference , Vol. 13510. 152–181. doi:10.1007/978-3-031-15985-5_6

  12. [20]

    Apache Foundation. 1999. Mail Archieves of Lucene. https://mailarchives.apache. org/mod_mbox/#lucene

  13. [21]

    Wikipedia Foundation. 2020. Wikipedia databases. https://www.wikipedia.org

  14. [22]

    Javad Ghareh Chamani, Dimitrios Papadopoulos, Charalampos Papamanthou, and Rasool Jalili. 2018. New Constructions for Forward and Backward Private Symmetric Searchable Encryption. InProceedings of the 2018 ACM SIGSAC Confer- ence on Computer and Communications Security . 1038–...

  15. [23]

    Paterson, and Sikhar Patranabis

    Zichen Gui, Kenneth G. Paterson, and Sikhar Patranabis. 2023. Rethinking Searchable Symmetric Encryption. In 44th IEEE Symposium on Security and Privacy. 1401–1418. doi:10.1109/SP46215.2023.10179460

  16. [24]

    Jacob Haltiwanger and Thang Hoang. 2024. Exploiting Update Leakage in Search- able Symmetric Encryption. In Proceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy . 115–126. doi:10.1145/3626232.3653260

  17. [25]

    Lawrence Hubert and Phipps Arabie. 1985. Comparing partitions. Journal of classification 2 (1985), 193–218

  18. [26]

    Mohammad Saiful Islam, Mehmet Kuzu, and Murat Kantarcioglu. 2012. Ac- cess Pattern disclosure on Searchable Encryption: Ramification, Attack and Mitigation. In 19th Annual Network and Distributed System Security Sympo- sium. https://www.ndss-symposium.org/ndss2012/access-patte...

  19. [27]

    Seny Kamara, Abdelkarim Kati, Tarik Moataz, Jamie DeMaria, Andrew Park, and Amos Treiber. 2024. MAPLE: MArkov Process Leakage attacks on Encrypted Search. Proc. Priv. Enhancing Technol. 2024, 1 (2024), 430–446. doi:10.56553/ POPETS-2024-0025

  20. [28]

    Seny Kamara, Charalampos Papamanthou, and Tom Roeder. 2012. Dynamic searchable symmetric encryption. In Proceedings of the 2012 ACM Conference on Computer and Communications Security . 965–976. doi:10.1145/2382196.2382298

  21. [29]

    Harold W Kuhn. 1955. The Hungarian method for the assignment problem.Naval research logistics quarterly 2, 1-2 (1955), 83–97

  22. [30]

    Shaofei Li, Feng Dong, Xusheng Xiao, Haoyu Wang, Fei Shao, Jiedong Chen, Yao Guo, Xiangqun Chen, and Ding Li. 2024. NODLINK: An Online System for Fine-Grained APT Attack Detection and Investiga- tion. In 31st Annual Network and Distributed System Security Sympo- sium. https://...

  23. [31]

    Chang Liu, Liehuang Zhu, Mingzhong Wang, and Yu-an Tan. 2014. Search pattern leakage in searchable encryption: Attacks and new construction. Inf. Sci. 265 (2014), 176–188. doi:10.1016/J.INS.2013.11.021

  24. [32]

    Marcel Ruiz Forns MusikAnimal, Kaldari. 2015. Pageviews Toolforge. https: //pageviews.toolforge.org/

  25. [33]

    Muhammad Naveed, Manoj Prabhakaran, and Carl A. Gunter. 2014. Dynamic Searchable Encryption via Blind Storage. In 2014 IEEE Symposium on Security and Privacy. 639–654. doi:10.1109/SP.2014.47

  26. [34]

    Yang, and Kaitai Liang

    Hao Nie, Wei Wang, Peng Xu, Xianglong Zhang, Laurence T. Yang, and Kaitai Liang. 2024. Query Recovery from Easy to Hard: Jigsaw Attack against SSE. In 33rd USENIX Security Symposium . https://www.usenix.org/conference/ usenixsecurity24/presentation/nie

  27. [35]

    Jianting Ning, Xinyi Huang, Geong Sen Poh, Jiaming Yuan, Yingjiu Li, Jian Weng, and Robert H. Deng. 2021. LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known Dataset. In Proceedings of the 2021 ACM SIGSAC Conference on C...

  28. [36]

    Simon Oya and Florian Kerschbaum. 2021. Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable Encryption. In 30th USENIX Security Symposium . 127–142. https://www.usenix.org/conference/ usenixsecurity21/presentation/oya

  29. [37]

    Simon Oya and Florian Kerschbaum. 2022. IHOP: Improved Statistical Query Recovery against Searchable Symmetric Encryption through Quadratic Optimiza- tion. In 31st USENIX Security Symposium . 2407–2424. https://www.usenix.org/ conference/usenixsecurity22/presentation/oya

  30. [38]

    Giuseppe Persiano and Kevin Yeo. 2023. Limits of Breach-Resistant and Snapshot- Oblivious RAMs. In Advances in Cryptology - CRYPTO 2023 - 43rd Annual Interna- tional Cryptology Conference, Vol. 14084. 161–196. doi:10.1007/978-3-031-38551- 3_6

  31. [39]

    Rishabh Poddar, Stephanie Wang, Jianan Lu, and Raluca Ada Popa. 2020. Practical Volume-Based Attacks on Encrypted Databases. In IEEE European Symposium on Security and Privacy. 354–369. doi:10.1109/EUROSP48549.2020.00030

  32. [40]

    David Pouliot and Charles V. Wright. 2016. The Shadow Nemesis: Inference At- tacks on Efficiently Deployable, Efficiently Searchable Encryption. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security . 1341–1352. doi:10.1145/2976749.2978401

  33. [41]

    William M Rand. 1971. Objective criteria for the evaluation of clustering methods. Journal of the American Statistical association 66, 336 (1971), 846–850

  34. [42]

    Mati Ur Rehman, Hadi Ahmadi, and Wajih Ul Hassan. 2024. Flash: A Com- prehensive Approach to Intrusion Detection via Provenance Graph Repre- sentation Learning. In IEEE Symposium on Security and Privacy . 3552–3570. doi:10.1109/SP54263.2024.00139

  35. [43]

    Khosro Salmani and Ken Barker. 2021. Don’t fool yourself with Forward Privacy, Your queries STILL belong to us!. In CODASPY ’21: Eleventh ACM Conference on Data and Application Security and Privacy . 131–142. doi:10.1145/3422337.3447838

  36. [44]

    Zhiwei Shang, Simon Oya, Andreas Peter, and Florian Kerschbaum. 2021. Ob- fuscated Access and Search Patterns in Searchable Encryption. In 28th Annual Network and Distributed System Security Symposium, NDSS 2021, virtually, Febru- ary 21-25, 2021. The Internet Society. https:/...

  37. [45]

    Wagner, and Adrian Perrig

    Dawn Xiaodong Song, David A. Wagner, and Adrian Perrig. 2000. Practical Techniques for Searches on Encrypted Data. In 2000 IEEE Symposium on Security and Privacy. 44–55. doi:10.1109/SECPRI.2000.848445

  38. [46]

    Emil Stefanov, Charalampos Papamanthou, and Elaine Shi. 2014. Practical Dy- namic Searchable Encryption with Small Leakage. In 21st Annual Network and Distributed System Security Symposium . https://www.ndss-symposium.org/ ndss2014/practical-dynamic-searchable-encryption-small-leakage

  39. [47]

    Liu, Ron Steinfeld, Amin Sakzad, Viet Vo, and Surya Nepal

    Shi-Feng Sun, Xingliang Yuan, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, Viet Vo, and Surya Nepal. 2018. Practical Backward-Secure Searchable Encryption from Symmetric Puncturable Encryption. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Secur...

  40. [48]

    Liu, Surya Nepal, and Cong Wang

    Viet Vo, Xingliang Yuan, Shi-Feng Sun, Joseph K. Liu, Surya Nepal, and Cong Wang. 2023. ShieldDB: An Encrypted Document Database With Padding Countermeasures. IEEE Trans. Knowl. Data Eng. 35, 4 (2023), 4236–4252. doi:10.1109/TKDE.2021.3126607

  41. [49]

    Cohen, MLD

    CMU William W. Cohen, MLD. 2015. Enron Email Datasets. https://www.cs. cmu.edu/~./enron/

  42. [50]

    Xiaoshuang Xing, Gaofei Sun, Jin Qian, Dongxiao Yu, and Xiuzhen Cheng. 2022. Intermittent jamming for eavesdropping defense in WAVE based vehicular net- works. Veh. Commun. 38 (2022), 100542. doi:10.1016/J.VEHCOM.2022.100542

  43. [51]

    Lei Xu, Leqian Zheng, Chengzhi Xu, Xingliang Yuan, and Cong Wang. 2023. Leakage-Abuse Attacks Against Forward and Backward Private Searchable Sym- metric Encryption. In Proceedings of the 2023 ACM SIGSAC Conference on Com- puter and Communications Security . 3003–3017. doi:10....

  44. [52]

    Lei Xu, Anxin Zhou, Huayi Duan, Cong Wang, Qian Wang, and Xiaohua Jia. 2024. Toward Full Accounting for Leakage Exploitation and Mitigation in Dynamic Encrypted Databases. IEEE Trans. Dependable Secur. Comput. 21, 4 (2024), 1918–

  45. [53]

    Peng Xu, Willy Susilo, Wei Wang, Tianyang Chen, Qianhong Wu, Kaitai Liang, and Hai Jin. 2022. ROSE: Robust Searchable Encryption With Forward and Backward Security. IEEE Trans. Inf. Forensics Secur. 17 (2022), 1115–1130. doi:10. 1109/TIFS.2022.3155977

  46. [54]

    Yang, and Kaitai Liang

    Xianglong Zhang, Wei Wang, Peng Xu, Laurence T. Yang, and Kaitai Liang

  47. [55]

    Yupeng Zhang, Jonathan Katz, and Charalampos Papamanthou. 2016. All Your Queries Are Belong to Us: The Power of File-Injection Attacks on Searchable Encryption. In 25th USENIX Security Symposium . 707–720. https://www.usenix. org/conference/usenixsecurity16/technical-sessions/...

  48. [56]

    George Kingsley Zipf. 2016. Human behavior and the principle of least effort: An introduction to human ecology . Ravenio books. A Background A.1 SSE and DSSE An SSE scheme [ 10, 11, 14, 16, 18, 22, 28, 33, 45–47, 53] allows a client to perform keyword search over an encrypted ...

  49. [59]

    known-data

    exploit the file volume pattern and proposed the FMA. The attacker first calculates the similarity between search queries to deduce the search pattern and query frequency and then uses both the query frequency and the auxiliary frequency to match the queries with keywords. Sal...

  50. [60]

    Jigsaw [34] leverages the search, volume, and access pattern to recover queries

    and get a mapping from the queries to keywords. Jigsaw [34] leverages the search, volume, and access pattern to recover queries. In [ 34], Nie et al. show that the frequency and volume of queries follow Zipf’s law, from which they conclude that a part of queries with high freq...

  51. [61]

    For each of the unmatched queries 𝑡𝑑, Jigsaw computes the𝑠𝑐𝑜𝑟𝑒 of each keyword𝑤 as 𝑠𝑐𝑜𝑟𝑒 =− ln(𝛽|| C𝑟𝑠[𝑡𝑑]− C𝑠𝑠[𝑤]||+( 1−𝛽)𝑠(𝑡𝑑,𝑤))

    by extracting the C𝑟𝑠 and C𝑠𝑠 from C𝑟 and C𝑠, where C𝑟𝑠 is the co-occurrence matrix between unmatched queries and known queries and C𝑠𝑠 is the co-occurrence matrix between the matched keywords and those unmatched. For each of the unmatched queries 𝑡𝑑, Jigsaw computes the𝑠𝑐𝑜𝑟𝑒 ...

  52. [62]

    search pattern

    The accuracy of IHOP+ is comparable to that of Jigsaw+ and declines as the number of rounds increases. H Peekaboo and Known-data Attacks In Section 4, Peekaboo calls the similar-data attacks to recover search queries. Previous known-data attacks can probably be mod- ified and ...

  53. [1934]

    doi:10.1109/TDSC.2023.3296189

  54. [2023]

    In 32nd USENIX Security Symposium

    High Recovery with Fewer Injections: Practical Binary Volumetric Injec- tion Attacks against Dynamic Searchable Encryption. In 32nd USENIX Security Symposium. 5953–5970. https://www.usenix.org/conference/usenixsecurity23/ presentation/zhang-xianglong

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.