AI 中文总结
本研究针对DeFi中基于UTXO的隐私保护协议缺失统一分析框架的问题,提出分层系统模型与分析流程,在Railgun和Hinkal池的链上历史上验证了匿名集大小减少40.1%-59.0%的结论,揭示了匿名性损失模式。
AI 中文摘要
基于UTXO的隐私保护协议正成为DeFi隐私基础设施的核心形式。与主要围绕存款和取款组织隐私的混币器不同,这些协议允许资产进入隐私保护池后继续在隐藏状态中转移和被重新花费,仅在用户取款或与公开DeFi协议交互时才会变为公开。因此,它们的匿名性不再是单纯的池大小问题,而是在注意/UTXO、证明和交易层传播的来源问题。然而,针对该场景的统一分析框架仍然缺失。我们提出了一个分层系统模型和分析流程,该流程将先前历史作为时间基线,对每个证明的承诺集应用累积修剪和跨证明传播,并通过历史隐藏状态转换递归追踪幸存者,以得出最终交易级匿名集大小。我们在六条EVM链上所有四个Railgun生产部署和五个独立Hinkal池的完整链上历史上评估了我们的方法,分析了186,356笔取消隐私保护的花费交易。仅使用公开协议轨迹和约束,我们的非启发式分析得出,相对于每个部署的时间基线,匿名集大小平均减少了40.1%-59.0%;3,679笔交易最多保留10个地址,其中包括1,228个单例。公共代币约束是两种协议中最强且最稳定的修剪来源,而树数量、证明根和价值约束的影响则随协议设计和历史状态而变化。这些结果结合代表性案例,揭示了可解释的匿名性损失模式及其对用户行为和未来协议设计的启示。
英文摘要
Shielded UTXO-based protocols are becoming a core form of privacy infrastructure for DeFi. Unlike mixers that organize privacy mainly around deposits and withdrawals, these protocols allow assets, once inside the shielded pool, to continue moving and being re-spent within the hidden state, and to become public only when users withdraw or interact with public DeFi protocols. Their anonymity is therefore no longer a flat pool-size problem, but a provenance problem that propagates across the note/UTXO, proof, and transaction layers. Yet, a unified analysis framework for this setting is still missing. We propose a layered system model and an analysis pipeline that uses prior history as the temporal baseline, applies cumulative pruning and cross-proof propagation to each proof's Commitment Set, and recursively traces the survivors through historical hidden-state transitions to derive the final transaction-level Anonymity Set Size. We evaluate our methodology on the complete on-chain histories of all four Railgun production deployments and five independent Hinkal pools across six EVM chains, analyzing 186,356 unshielding spend transactions. Using only public protocol traces and constraints, our non-heuristic analysis yields mean Anonymity Set Size reductions of 40.1%-59.0% relative to each deployment's temporal baseline; 3,679 transactions retain at most 10 addresses, including 1,228 singletons. Public token constraints are the strongest and most stable source of pruning in both protocols, while the effects of tree number, proof roots, and value constraints vary with protocol design and historical state. Together with representative cases, these results reveal interpretable anonymity-loss patterns and implications for user behavior and future protocol design.