Project Details
Description
Encrypted key–value stores (KVS), lightweight encrypted services for associative data storage and retrieval, have become essential to modern secure infrastructures, supporting applications from cloud databases and web services to sensitive domains like healthcare, finance, and large language model (LLM) caching. Despite offering confidentiality through encryption, these systems inevitably leak observable side information, which in practice can be exploited to recover statistical properties of the data or even individual records, such as inferring frequently queried keys or distinguishing rare, sensitive queries from common ones. While similar concerns have been extensively studied in specific encrypted indexing primitives like searchable symmetric encryption (SSE), encrypted KVS as full-fledged storage systems pose a more complex challenge that remains largely unexplored, because their implementation-level behaviors such as caching, compaction, and timing leak richer and noisier information beyond the application-level patterns typically modeled in SSE. Moreover, existing analytical approaches mainly rely on manually hand-crafted features (e.g., access patterns, result sizes) that generalize poorly, scale inadequately, depend on rigid statistical pipelines or idealized threat models that degrade under dynamic or noisy conditions. Beyond this traditional focus on recovery accuracy, we are yet to gain a deeper understanding of leakage itself and its impact, which, in turn, can inform the design of effective defenses.In light of the limitations described above, this project seeks to establish a learning-centric framework for security profiling and hardening of encrypted KVS, advancing new theories and methods for modeling, quantifying, and mitigating leakage through automated analysis, strong generalization across real-world workloads, and adaptive defenses resilient to evolving adversaries. To achieve this, our research includes three tightly coupled tasks: 1) Modeling and quantifying leakage in encrypted KVS through learned representations that automatically extract predictive signals from raw responses and translate them into measurable privacy risks, thereby moving beyond manually hand-crafted leakage dimensions; 2) Building realistic adversarial models and attacks that generalize across real-world workloads by integrating passive and active inference with the reasoning and abstraction power of LLMs; and 3) Designing automatic defenses that adapt dynamically to evolving adversaries. We will refine security notions specific to KVS and construct countermeasures that continuously obfuscate leakage in response to adversarial success. We believe that the above results will provide theoretical benefits for designing encrypted data structures and algorithms with precisely quantified leakage impacts, privacy guarantees, and adaptive defenses, while also laying infrastructural foundations for future encrypted data services built atop.
| Project number | 9044018 |
|---|---|
| Grant type | GRF |
| Status | Not started |
| Effective start/end date | 1/01/27 → … |
Fingerprint
Explore the research topics touched on by this project. These labels are generated based on the underlying awards/grants. Together they form a unique fingerprint.