AI 中文总结
研究在按份额付费(PPS)和完全PPS(FPPS)方案下,区块扣留(BWH)攻击的最优策略为全力攻击(AoA),攻击者将全部算力投入受害矿池,仅提交部分工作量证明(pPoW)而扣留全部有效区块,在难度调整后获得相对收益,并证明这些机制并非激励相容。
AI 中文摘要
经典的区块扣留(BWH)攻击已在依赖区块的奖励方案中得到广泛研究,在该方案中,矿池成员在矿池内发现区块后获得补偿。然而,大多数现代矿池采用基于份额的方案,参与者提交有效份额后立即获得报酬。本文分析了中本聪式区块链在按份额付费(PPS)和完全PPS(FPPS)方案下的BWH攻击,并证明这些机制并非激励相容——与先前文献中的说法相反。在PPS/FPPS下,BWH攻击者的最优策略是全力攻击(AoA):攻击者将其全部算力分配给受害矿池,仅提交部分工作量证明(pPoW)份额,同时扣留所有有效区块,即完整工作量证明(fPoW)。在AoA下,在第一次难度调整之前,攻击者因扣留fPoW而遭受的损失可忽略不计。在第一次难度调整(降低区块难度)之后,攻击者单位时间生成更多pPoW,相对于调整前的速率获得$\frac{\alpha}{1-\alpha}$的相对增益,其中$\alpha$是攻击者算力占比。此外,单位时间和单位算力下,所有诚实矿工与攻击者获得相同收益。相反,受害矿池运营者遭受损失:它为攻击者提交的pPoW支付报酬,但未获得任何fPoW补偿。最后,BWH的高级变体(如扣留后分叉(FAW))不会为攻击者带来额外利润。
英文摘要
Classical Block Withholding (BWH) attacks have been extensively studied in block-dependent reward schemes, where pool members are compensated upon a block discovery within the pool. However, most contemporary mining pools operate under share-based schemes, wherein participants are paid immediately upon submission of valid shares. In this paper, we analyze BWH under Pay-Per-Share (PPS) for Nakamoto-style blockchains and prove that these mechanisms are not incentive compatible, contrary to claims in prior literature. Under PPS, the optimal strategy for a BWH attacker is the All-out Attack (AoA): the adversary allocates its entire hashpower toward the victim pool, submitting only partial Proof-of-Work shares (pPoW) while withholding all valid blocks, i.e., full Proof-of-Work (fPoW). Prior to the first difficulty adjustment, the adversary incurs negligible loss from withheld fPoWs. After the adjustment reduces block difficulty, the adversary either generates more pPoWs per unit time when the pPoW difficulty is reduced accordingly or, if the pPoW difficulty is held fixed, earns a higher reward per share. In both cases, it achieves a post-adjustment reward rate of $\fracα{1-α}$ per target epoch, compared with the honest baseline rate of $α$. Remarkably, this gain matches the theoretical upper bound achieved by optimal selfish mining in Nakamoto consensus under perfect network influence. The results further indicate that BWH is substantially more profitable under PPS than under mainstream block-dependent payout schemes, even when compared with advanced BWH variants. Honest miners benefit at the same rate as the adversary per unit hashpower, while the victim pool operator bears all losses, paying out-of-pocket for pPoW submissions without receiving fPoW compensation in return.