<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malicious data owners &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/malicious-data-owners/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Fri, 09 Oct 2026 11:53:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>malicious data owners &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>New Security Framework Guards Shared Encrypted Databases Against Their Own Owners</title>
		<link>https://scienmag.com/new-security-framework-guards-shared-encrypted-databases-against-their-own-owners/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Fri, 09 Oct 2026 11:53:02 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[Byzantine consensus]]></category>
		<category><![CDATA[collaborative cybersecurity solutions]]></category>
		<category><![CDATA[collaborative encrypted databases]]></category>
		<category><![CDATA[cryptographic data sharing]]></category>
		<category><![CDATA[cryptography in shared databases]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data integrity]]></category>
		<category><![CDATA[encrypted database security protocols]]></category>
		<category><![CDATA[fraud detection in financial institutions]]></category>
		<category><![CDATA[malicious data owners]]></category>
		<category><![CDATA[multi-party computation]]></category>
		<category><![CDATA[outsourced databases]]></category>
		<category><![CDATA[privacy-preserving computation]]></category>
		<category><![CDATA[privacy-preserving query frameworks]]></category>
		<category><![CDATA[privacy-preserving set computation]]></category>
		<category><![CDATA[private set intersection]]></category>
		<category><![CDATA[query governance]]></category>
		<category><![CDATA[safeguarding data owners' integrity]]></category>
		<category><![CDATA[secret sharing]]></category>
		<category><![CDATA[secure multi-party computation]]></category>
		<category><![CDATA[security against malicious insiders]]></category>
		<category><![CDATA[verifiable privacy-preserving data analysis]]></category>
		<category><![CDATA[verifiable secret sharing]]></category>
		<category><![CDATA[zero-knowledge proofs]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=253661</guid>

					<description><![CDATA[Researchers have unveiled a security framework that protects privacy-preserving, secret-shared databases against malicious data owners by combining verifiable secret sharing, zero-knowledge proofs, and lightweight query-level consensus with only moderate overhead.]]></description>
										<content:encoded><![CDATA[<p>When rival banks pool their data for fraud detection, they face an uncomfortable paradox: the analytics only work if everyone contributes honestly, yet every participant has an incentive to cheat. A new study published in the journal Cybersecurity tackles this paradox head-on, presenting a security-enhanced query framework that protects collaborative, privacy-preserving databases not only from prying outsiders and untrusted servers, but from the data owners themselves. The work, led by Lili Gu, Jinguo Li, and Jiaqi Shi of Shanghai University of Electric Power, extends an existing privacy-preserving computation system into territory that cryptography alone could not reach.</p>
<p>The starting point is PRISM, a framework for privacy-preserving set computation over outsourced secret-shared databases. In PRISM, multiple data owners split their records into cryptographic shares and distribute them across servers that never see plaintext data. The servers can execute private set intersection and aggregation queries directly over the shares, and the system offers verifiability guarantees against dishonest servers. But PRISM, like most systems in this family, rests on a quiet assumption: that the data owners themselves behave honestly and follow the protocol. In real consortiums of competing organizations, that assumption is often unrealistic.</p>
<p>The researchers catalog the ways a malicious owner can sabotage a query without ever breaking encryption. An owner might distribute inconsistent secret shares so that different servers hold contradictory versions of the same record. It might outsource values that violate declared attribute-level constraints, such as a numeric field exceeding its permitted range, quietly poisoning every aggregate computed downstream. It might issue unauthorized queries that breach the consortium&#8217;s access policies. Or it might interfere at the final stage, selectively approving or refusing to confirm aggregation results, or sending conflicting confirmations to different participants. Each of these attacks preserves data confidentiality while corrupting the correctness of the answers everyone relies on.</p>
<p>To close these gaps, the team built a framework that combines verifiable data outsourcing with query-level governance. The first pillar uses verifiable secret sharing, based on Pedersen commitments, to guarantee that every accepted share is consistent with a single committed plaintext value. When a data owner distributes shares of a value, it also publishes commitments derived from the sharing polynomial&#8217;s coefficients. Each server can then check locally, through a simple algebraic relation, whether the share it received matches the committed value. A malicious owner cannot hand out mutually inconsistent shares that still pass this check, and the verification requires no interaction between servers.</p>
<p>Consistency alone, however, is not enough. A malicious owner could share a perfectly consistent value that is simply wrong, such as an out-of-range cost figure or a Boolean indicator that is neither zero nor one. The framework therefore layers zero-knowledge proofs on top of the commitments. For Boolean attributes, the owner proves that the committed value satisfies the equation v times (v minus 1) equals zero, which holds only for zero or one, without revealing which. For numeric attributes, the owner supplies a range proof demonstrating that the committed value lies between zero and a public bound. The same commitment anchors both the share-consistency check and the validity proof, so the two guarantees are cryptographically bound to one another. In experiments, these mechanisms detected every injected malicious input, including tampered shares, invalid Boolean values, and out-of-range numbers, with a false-positive rate of zero.</p>
<p>The second pillar, called Adaptive Query Consensus or AQC, governs the query lifecycle itself. Rather than deploying heavyweight Byzantine fault-tolerant protocols that replicate an entire system state, AQC operates strictly per query under an honest-majority assumption, tolerating fewer than one third malicious owners. Before any query reaches the servers, data owners collectively vote on its admissibility against a consortium-wide policy. Only when at least a two-thirds quorum signs the same query descriptor does the coordinator assemble an authorization certificate, and servers refuse to execute anything without one. For aggregation queries, a second certificate confirms the final result: at least Q owners must sign the same result digest before the answer is accepted.</p>
<p>The safety argument is elegant. Because any two valid quorums must overlap in at least one honest owner, and honest owners sign at most one authorization and one result digest per query instance, two conflicting queries or two conflicting results can never both obtain valid certificates. The coordinator, notably, is not trusted at all; it merely collects votes and cannot determine outcomes without sufficient honest signatures. To handle unstable or malicious coordinators, AQC selects them adaptively based on observed behavior, such as vote-collection latency and certificate-assembly success. Certified timeouts or provable equivocation exclude a coordinator for the remainder of that query phase, and the protocol retries with growing timeout windows, guaranteeing eventual progress when the network stabilizes and enough honest owners participate.</p>
<p>The experimental evaluation is striking for its scale and restraint. Using a Python prototype with datasets drawn from the TPC-H benchmark, the team tested workloads of up to 50 data owners and datasets of up to 5 million records. The cryptographic machinery added only moderate cost: query-computation overhead over the PRISM baseline ranged from roughly 5.3 to 7.9 percent and stayed below 8 percent in every tested configuration. Signature processing contributed just 18 milliseconds to the critical path of a two-phase query, and coordinator selection cost less than a millisecond of local computation. Under congested networks and a 30 percent malicious-owner ratio, full two-phase queries completed in under two seconds. Because verification happens during data outsourcing, its cost amortizes across many subsequent queries.</p>
<p>The adaptive coordinator selection proved its worth in adversarial settings. At a 30 percent malicious ratio, adaptive selection cut completion times by roughly 18.6 to 30.5 percent compared with round-robin and random strategies, required about 0.15 to 0.26 retries per query instead of roughly 0.8, and maintained completion rates between 99 and 99.9 percent. A static-leader strategy, by contrast, collapsed to a 70 percent completion rate when its fixed leader turned malicious. The authors are careful about limits: the framework verifies protocol-level integrity, not the real-world truthfulness of syntactically valid data, and its guarantees hold only under the honest-majority assumption, with the 40 percent malicious setting reported purely as a stress test.</p>
<p>The broader significance lies in reframing where trust must be established in collaborative analytics. Cryptographic privacy has long been treated as sufficient protection for multi-party computation, yet the integrity of shared answers depends on participants who may be strategically misaligned, compromised, or simply unreliable. By binding verifiable secret sharing, zero-knowledge validity proofs, and lightweight query-scoped consensus into a single lifecycle-aware workflow, the researchers show that outsourced multi-owner databases can survive their own owners&#8217; misbehavior without the crushing overhead of full Byzantine replication. The team plans to extend the work toward stronger robustness beyond honest majorities, real cloud deployments with heterogeneous latency, and richer query types and policy constraints, pointing toward consortium analytics that are resilient from data submission to confirmed result.</p>
<p><strong>Subject of Research:</strong> Verifiable and robust query processing for multi-owner secret-shared databases under malicious data owners</p>
<p><strong>Article Title:</strong> Verifiable and robust query processing for multi-owner secret-shared databases under malicious owners</p>
<p><strong>Article References:</strong> Gu, L., Li, J., &amp; Shi, J. (2026). Verifiable and robust query processing for multi-owner secret-shared databases under malicious owners. <em>Cybersecurity, 9</em>(1), Article 231. <a href="https://doi.org/10.1186/s42400-026-00674-4" rel="noopener noreferrer">https://doi.org/10.1186/s42400-026-00674-4</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1186/s42400-026-00674-4" rel="noopener noreferrer">10.1186/s42400-026-00674-4</a></p>
<p><strong>Keywords:</strong> privacy-preserving computation, secret sharing, verifiable secret sharing, zero-knowledge proofs, private set intersection, outsourced databases, Byzantine consensus, query governance, malicious data owners, data integrity, multi-party computation, cybersecurity</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">253661</post-id>	</item>
	</channel>
</rss>
