AI 中文总结
针对选择性沉默攻击,提出Tendermint变体Vigil,通过攻击自适应转发和多数指控机制,在最优阈值下实现可问责活性,并大幅降低误报率。
AI 中文摘要
BFT问责制在安全性违规方面已被充分理解,近期工作将全局活性违规归因;然而,接收者选择性沉默仍未解决。选择性沉默的对手对某些诚实节点隐瞒消息,同时对其他节点表现正常。它能使共识停滞,却能逃避所有现有机制。我们首次系统研究针对选择性沉默的问责制。负面结果:一个仅对至多f个诚实节点沉默的孤立攻击者与诚实节点不可区分,从而得出沉默识别阈值的通用下界K_SI ≥ f+1;此外,任何在沉默引发的违规后无反馈的修复代价为Θ(n^3)。正面结果:Vigil,一个Tendermint变体,通过攻击自适应转发、基于位图交叉证明、基于核心的成员资格以及挑战-响应审计,达到这些界限。当无选择性沉默发生时,每个节点支付O(n)个认证器(加上每个节点Θ(n^2)位图元数据位),中继与攻击宽度成比例(亚阈值沉默可迫使每视图最多n^3/27次中继,我们精确计算此代价),并对任何对超过可调韧性τ_A的诚实对等节点沉默的节点进行多数指控(K_SI = τ_A+1,在τ_A = f时最优)。我们还精确计算了残余亚阈值 griefing 攻击面,并将识别扩展到x-部分同步。在三区域广域网上的真实网络实验,以及一个与每个闭式精确相等的模拟器,确认了每个阈值和代价:在2%丢包率下,f+1指控标准错误指控91.2%的诚实节点,而我们的多数标准指控0.002%。
英文摘要
BFT accountability is well understood for safety violations, and recent work attributes global liveness violations; \emph{recipient-selective} silence remains unresolved. A selectively silent adversary withholds messages from some honest nodes while behaving correctly toward others. It can stall consensus yet evade every existing mechanism. We initiate a systematic study of accountability against selective silence. Negatively, a lone attacker silent toward at most $f$ honest nodes is indistinguishable from an honest node, yielding a universal lower bound $K_{\mathrm{SI}} \ge f{+}1$ on the \emph{silence identification threshold}; moreover, any feedback-free repair after a silence-induced violation costs $Θ(n^3)$. Positively, \textsc{Vigil}, a Tendermint variant, matches these bounds with attack-adaptive forwarding, via bitmap cross-attestation, core-based membership, and challenge--response auditing. It pays $O(n)$ authenticators per node when no selective silence occurs (plus $Θ(n^2)$ bitmap metadata bits per node), relays in proportion to the attack's width (sub-threshold silence can force up to $n^3/27$ relays per view, a cost we price exactly), and majority-accuses any node silent toward more than a tunable resilience $τ_A$ of honest peers ($K_{\mathrm{SI}} = τ_A{+}1$, optimal at $τ_A = f$). We also price the residual sub-threshold griefing surface exactly and extend identification to $x$-partial synchrony. Real-network experiments on a three-region WAN, together with a simulator held to exact equality with every closed form, confirm each threshold and cost: at $2\%$ loss, an $f{+}1$ accusation bar falsely accuses $91.2\%$ of honest nodes, while our majority bar accuses $0.002\%$.
Comments20 pages, 8 figures