发表机构
Boston College; Sun Yat-sen University; University of Wisconsin–Madison; Adrasteia Labs(波士顿学院; 中山大学; 威斯康星大学麦迪逊分校; 阿德拉西亚实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文研究阈值加密内存池中解密委员会共谋的威慑问题,提出重复博弈模型,证明惩罚需覆盖泄露最大折现值,并设计覆盖线性规划以最小化质押成本,扩展至拍卖与联邦学习。
AI 中文摘要
一个联盟若偏离一次,当其出售的产品持续有效时,可多次获利。在阈值加密内存池(一种针对最大可提取价值(MEV)的主要防御机制)中,解密委员会中一个法定人数将解密能力出售给抢跑者,则该能力仍可解密的后续每个区块都会暴露。我们研究多大的惩罚(如可削减的质押金)能够威慑此类共谋。在我们的重复博弈中,单调授权联盟族(例如,n 个委员会成员中的任意 k 个)中任何联盟的一次泄露会解锁一系列未来回合,产生一次性惩罚,并终止该联盟的参与。我们证明,每个动态偏离都归结为选择泄露时间,因此威慑成立当且仅当每个联盟的惩罚覆盖单次泄露所能达到的最大折现值。在不考虑折现的情况下,在 T 个回合中,单位价值的完全重用需要惩罚 T,而将每次泄露绑定到其自身回合需要 1,因此没有在时间范围上恒定的惩罚能威慑无界重用;重用窗口为 w 个回合的成本至多为最大每回合价值的 w 倍。威慑每个联盟的最便宜的每方质押配置求解一个覆盖线性规划。对于区块链设计,每纪元密钥将所需质押从密钥生命周期的价值削减到一个纪元的价值;我们在以太坊抢跑数据上校准差距,并将 Ferveo 和 Shutter 置于模型中。该分析扩展到密封拍卖、多权威投票以及共享密钥下的联邦学习。
英文摘要
A coalition that deviates once can profit many times when what it sells keeps working. In a threshold-encrypted mempool, a leading defense against maximal extractable value (MEV), a quorum of the decryption committee that sells its decryption capability to a front-runner exposes every later block that the capability still decrypts. We ask how large a penalty, such as slashable stake, deters this kind of collusion. In our repeated game, a single leak by any coalition in a monotone family of authorized coalitions (for example, any $k$ of the $n$ committee members) unlocks a set of future rounds, costs a one-time penalty, and ends the coalition's participation. We show that every dynamic deviation reduces to choosing a leak time, so deterrence holds if and only if each coalition's penalty covers the largest discounted value that a single leak reaches. Without discounting, over $T$ rounds of unit value full reuse needs a penalty of $T$ while binding each leak to its own round needs $1$, so no penalty that is constant in the horizon deters unbounded reuse; a reuse window of $w$ rounds costs at most $w$ times the largest per-round value. The cheapest profile of per-party stakes that deters every coalition solves a covering linear program. For blockchain design, per-epoch keys cut the required stake from the value of a key's lifetime to the value of one epoch; we calibrate the gap on Ethereum front-running data and place Ferveo and Shutter in the model. The analysis extends to sealed-bid auctions, multi-authority voting, and federated learning under a shared key.
CommentsAccepted at NeurIPS 2026