S-Leak: Leakage-Abuse Attack Against Efficient Conjunctive SSE via s-term Leakage

📅 2025-07-05
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the leakage-abuse attack (LAA) risk arising from *s*-term leakage in efficient conjunctive searchable symmetric encryption (CSSE). We first identify and systematically exploit statistical patterns of the least-frequent keyword in queries, combined with globally leaked information, to propose S-Leak—a novel passive LAA framework. S-Leak comprises three stages: *s*-term identification, low-probability combination pruning, and query reconstruction, integrating global leakage analysis with statistical probability modeling—without requiring active data tampering. To tackle combinatorial explosion, we introduce new evaluation metrics that overcome limitations of prior LAA approaches. Experiments on real-world datasets show 95.15% accuracy for single-keyword recovery and 58% full recovery rate for three-keyword queries. Crucially, S-Leak remains highly effective against state-of-the-art defenses, including SEAL padding and CLRZ obfuscation.

Technology Category

Application Category

📝 Abstract
Conjunctive Searchable Symmetric Encryption (CSSE) enables secure conjunctive searches over encrypted data. While leakage-abuse attacks (LAAs) against single-keyword SSE have been extensively studied, their extension to conjunctive queries faces a critical challenge: the combinatorial explosion of candidate keyword combinations, leading to enormous time and space overhead for attacks. In this paper, we reveal a fundamental vulnerability in state-of-the-art CSSE schemes: s-term leakage, where the keyword with the minimal document frequency in a query leaks distinct patterns. We propose S-Leak, the first passive attack framework that progressively recovers conjunctive queries by exploiting s-term leakage and global leakage. Our key innovation lies in a three-stage approach: identifying the s-term of queries, pruning low-probability keyword conjunctions, and reconstructing full queries. We propose novel metrics to better assess attacks in conjunctive query scenarios. Empirical evaluations on real-world datasets demonstrate that our attack is effective in diverse CSSE configurations. When considering 161,700 conjunctive keyword queries, our attack achieves a 95.15% accuracy in recovering at least one keyword, 82.57% for at least two, 58% for all three keywords, and maintains efficacy against defenses such as SEAL padding and CLRZ obfuscation. Our work exposes the underestimated risks of s-term leakage in practical SSE deployments and calls for a redesign of leakage models for multi-keyword search scenarios.
Problem

Research questions and friction points this paper is trying to address.

Exploits s-term leakage in conjunctive SSE schemes
Addresses combinatorial explosion in leakage-abuse attacks
Recovers conjunctive queries with high accuracy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Exploits s-term leakage for query recovery
Uses three-stage approach for efficient attack
Introduces novel metrics for attack assessment
🔎 Similar Papers
No similar papers found.
Y
Yue Su
Beijing Institute of Technology, Beijing, China
M
Meng Shen
Beijing Institute of Technology, Beijing, China
Cong Zuo
Cong Zuo
Beijing Institute of Technology
Cryptography
Y
Yuzhi Liu
Beijing Institute of Technology, Beijing, China
L
Liehuang Zhu
Beijing Institute of Technology, Beijing, China