S-Leak: Leakage-Abuse Attack Against Efficient Conjunctive SSE via s-term Leakage
Yue Su, Meng Shen, Cong Zuo, Yuzhi Liu, Liehuang Zhu

TL;DR
This paper introduces S-Leak, a passive attack exploiting s-term leakage in conjunctive searchable encryption, revealing significant vulnerabilities and challenging existing security assumptions in multi-keyword search schemes.
Contribution
It presents the first attack framework that effectively recovers conjunctive queries by exploiting s-term leakage, highlighting a critical security flaw in current CSSE schemes.
Findings
Achieves over 95% accuracy in recovering at least one keyword in queries.
Remains effective against defenses like padding and obfuscation.
Reveals the need to reconsider leakage models in multi-keyword searchable encryption.
Abstract
Conjunctive Searchable Symmetric Encryption (CSSE) enables secure conjunctive searches over encrypted data. While leakage-abuse attacks (LAAs) against single-keyword SSE have been extensively studied, their extension to conjunctive queries faces a critical challenge: the combinatorial explosion of candidate keyword combinations, leading to enormous time and space overhead for attacks. In this paper, we reveal a fundamental vulnerability in state-of-the-art CSSE schemes: s-term leakage, where the keyword with the minimal document frequency in a query leaks distinct patterns. We propose S-Leak, the first passive attack framework that progressively recovers conjunctive queries by exploiting s-term leakage and global leakage. Our key innovation lies in a three-stage approach: identifying the s-term of queries, pruning low-probability keyword conjunctions, and reconstructing full queries. We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
