[Paper Review] Quantifying the computational security of multi-user systems
This paper extends the guesswork framework to multi-user systems, showing that the asymptotic average number of guesses needed to identify U out of V users' strings grows exponentially at a rate determined by the specific Rényi entropy of order (V−U+1)/(V−U+2). It establishes a large deviation principle for guesswork, proves the Shannon entropy is a universal lower bound on guesswork growth, and characterizes the optimal strategy class in the asymptotic regime.
The Guesswork problem was originally motivated by a desire to quantify computational security for single user systems. Leveraging recent results from its analysis, we extend the remit and utility of the framework to the quantification of the computational security for multi-user systems. In particular, assume that V users independently select strings stochastically from a finite, but potentially large, list. An inquisitor who does not know which strings have been selected wishes to identify U of them. The inquisitor knows the selection probabilities of each user and is equipped with a method that enables the testing of each (user, string) pair, one at a time, for whether that string had been selected by that user. Here we establish that, unless U = V, there is no general strategy that minimizes the distribution of the number of guesses, but in the asymptote as the strings become long we prove the following: by construction, there is an asymptotically optimal class of strategies; the number of guesses required in an asymptotically optimal strategy satisfies a large deviation principle with a rate function, which is not necessarily convex, that can be determined from the rate functions of optimally guessing individual users’ strings; if all user’s selection statistics are identical, the exponential growth rate of the average guesswork as the string-length increases is determined by the specific Rényi entropy of the string-source with parameter (V −U +1)/(V −U +2), generalizing the known V = U = 1 case; and that the Shannon entropy of the source is a lower bound on the average guesswork growth rate for all U and V, thus providing a bound on computational security for multi-user systems. Examples are presented to illustrate these results and their ramifications for systems design. I.
Motivation & Objective
- To quantify computational security in multi-user systems where an inquisitor guesses user-selected strings.
- To analyze the number of guesses required to identify U out of V users' strings when selection probabilities are known.
- To determine the asymptotic behavior of guesswork growth as string length increases.
- To establish a lower bound on guesswork growth using Shannon entropy and characterize optimal strategies.
Proposed method
- Uses large deviation theory to analyze the distribution of the number of guesses required to identify U users' strings.
- Constructs an asymptotically optimal class of guessing strategies for the multi-user setting.
- Derives the rate function for guesswork using the rate functions of individual user string guessing.
- Applies Rényi entropy of order (V−U+1)/(V−U+2) to characterize the exponential growth rate of average guesswork.
- Establishes that the Shannon entropy provides a universal lower bound on guesswork growth for all U and V.
- Employs asymptotic analysis to show convergence to optimal strategies as string length tends to infinity.
Experimental results
Research questions
- RQ1What is the asymptotic growth rate of the average number of guesses required to identify U out of V users’ strings in a multi-user system?
- RQ2How does the structure of the selection probabilities affect the distribution of guesswork in multi-user settings?
- RQ3Can a universal lower bound on guesswork growth be derived using Shannon entropy for any U and V?
- RQ4What is the role of Rényi entropy in characterizing the optimal guessing strategy for multi-user systems?
- RQ5Is there a general strategy that minimizes the guesswork distribution across all multi-user configurations?
Key findings
- The exponential growth rate of the average guesswork as string length increases is determined by the specific Rényi entropy of the string-source with parameter (V−U+1)/(V−U+2).
- The Shannon entropy of the source is a universal lower bound on the average guesswork growth rate for all values of U and V.
- There is no general strategy that minimizes the guesswork distribution unless U = V, but an asymptotically optimal class of strategies exists in the limit of long strings.
- The number of guesses in an asymptotically optimal strategy satisfies a large deviation principle with a rate function that is not necessarily convex.
- The rate function for the multi-user guesswork can be constructed from the rate functions of individual user string guessing.
- When all users have identical selection statistics, the guesswork growth rate is fully characterized by the Rényi entropy of order (V−U+1)/(V−U+2).
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.