arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.30509cs.GTcs.CR

太晚削减:协调无风险的双重签名攻击

Too Late to Slash: Coordinating a Risk-Free Equivocation Attack

  • Layerzero Labs
  • Lucerne University of Applied Sciences and Arts(卢塞恩应用科学与艺术大学)

机构由 AI 辅助整理,请以论文原文为准。

Hao Chung, Chen-Da Liu-Zhang

AI总结:

本研究证明算法削减无法阻止理性验证者协调无风险双重签名攻击,其策略构成事后纳什均衡,揭示仅靠削减不能保障经济安全。

AI中文摘要:

削减(Slashing)通常被认为通过没收行为不当验证者的质押来保障权益证明区块链的安全。通常的理由是,如果没有削减,验证者可以通过签署冲突区块来发起双重签名攻击:如果足够多的其他人加入,攻击成功;否则,尝试不会造成损失。削减旨在使此类尝试代价高昂,从而保障经济价值与质押金额相当的应用程序的安全性。然而,这一理由依赖于启发式论证,而非正式博弈论保证。我们通过构建一个在算法削减下理性验证者的无风险协调协议来挑战这一理由。我们表明,所规定的策略组合——理性验证者诱使其他验证者进行双重签名——构成事后纳什均衡,即使验证者事先不知道有多少其他人会参与。该均衡对成功双重签名的任何收益$\u03b5>0$都成立,无论该收益相对于质押金额有多小。因此,仅靠削减并不能保证与质押金额成比例的经济安全。我们的结果揭示了算法削减的根本局限性。而在现实世界的许多场景中,传统抵押安排可以依赖外部执行(例如通过法院),算法削减却依赖于攻击者所控制的同一共识过程。这些发现呼吁对削减的安全性进行正式分析,而非依赖从具有独立执行的金融系统中得出的过于简单的论证。

英文摘要:

Slashing is commonly argued to secure proof-of-stake blockchains by confiscating the stake of misbehaving validators. The usual justification is that, without slashing, validators can solicit an equivocation attack by signing conflicting blocks: if enough others join, the attack succeeds; otherwise, the attempt incurs no loss. Slashing is intended to make such attempts costly and thereby guarantee the security of applications whose economic value is comparable to the bonded stake. This rationale, however, rests on heuristic arguments rather than a formal game-theoretic guarantee. We challenge this rationale by constructing a risk-free coordination protocol for rational validators under algorithmic slashing. We show that the prescribed strategy profile, in which rational validators solicit other validators to equivocate, constitutes an ex post Nash equilibrium, even when validators do not know in advance how many others will participate. The equilibrium holds for any gain $ε>0$ from successful equivocation, however small relative to the bonded stake. Thus, slashing alone does not guarantee economic security proportional to the value of bonded stake. Our results expose a fundamental limitation of algorithmic slashing. Whereas conventional collateral arrangements in many real-world scenarios can rely on external enforcement, for example through courts, algorithmic slashing depends on the same consensus process that the attackers control. These findings call for a formal analysis of slashing's security, rather than overly simplistic arguments drawn from financial systems with independent enforcement.

↑