arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.30648cs.CRcs.SE

欺骗我:通过对抗性见证注入发现零知识领域特定语言工具链中的漏洞

Lie to Me: Finding Bugs in ZK DSL Toolchains with Adversarial Witness Injection

Sebastian Watzinger, Christoph Hochrainer, Valentin Wüstholz, Maria Christakis

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出测试框架Liezz,通过对抗性见证注入发现Circom等ZK DSL工具链的健全性漏洞,发现13个漏洞,其中7个具健全性影响,该方法可触及有效执行测试遗漏的失败。

中文摘要 AI 辅助

零知识领域特定语言(ZK DSL)工具链将程序编译为约束系统,并为密码学证明生成见证。这些工具链中的漏洞可能会使强制约束弱于源程序语义,从而允许为无效执行生成证明。这类健全性漏洞可能对有效执行测试保持不可见,因为所有有效执行仍会表现正常。我们提出了Liezz,一个用于生成ZK DSL程序并通过对抗性见证注入暴露这些漏洞的测试框架。对于每个生成的确定性程序,Liezz执行两个具有不同输出的公共输入分配,并拼接它们的见证,将一个执行的输入与另一个执行的输出相结合。由此产生的见证在构造上是无效的,正确的工具链必须拒绝它;若接受则表明存在健全性漏洞。受控发散和多种见证拼接策略保留了足够的一致性,以暴露缺失的约束。Liezz还生成参数化的标准库调用以实现复杂功能,它支持Circom、Corset、Gnark和Noir,共发现13个漏洞,其中7个具有健全性影响,部分漏洞仅能通过生成的标准库调用被触及。在相同的测试预算下,有效执行基线未暴露任何被接受的注入见证所揭示的健全性失败,表明对抗性见证注入能够触及有效执行测试遗漏的失败。

英文摘要

Zero-knowledge domain-specific language (ZK DSL) toolchains compile programs into constraint systems and generate witnesses for cryptographic proofs. Bugs in these toolchains can leave the enforced constraints weaker than the source-program semantics, admitting proofs for invalid executions. Such soundness bugs may remain invisible to valid-execution testing because all valid executions still behave correctly. We present Liezz, a testing framework that generates ZK DSL programs and exposes these bugs through adversarial witness injection. For each generated deterministic program, Liezz executes two public input assignments with different outputs and splices their witnesses, combining the input of one execution with the output of the other. The resulting witness is invalid by construction. A correct toolchain must reject it; acceptance exposes a soundness bug. Controlled divergence and multiple witness-splicing strategies preserve enough consistency to expose missing constraints. Liezz also generates parameterized standard-library calls to reach complex functionality. Liezz supports Circom, Corset, Gnark, and Noir. It finds 13 bugs, including seven with soundness impact. Several are reachable only through generated standard-library calls. Under the same testing budget, a valid-execution baseline does not expose any of the soundness failures revealed by accepted injected witnesses, showing that adversarial witness injection reaches failures missed by valid-execution testing.

发表机构

  • TU Wien, Austria(维也纳工业大学)
  • Consensys Diligence, Austria(Consensys Diligence)

机构由 AI 辅助整理,请以论文原文为准。

↑