New paper shows Fiat-Shamir transformation breaks soundness for program-generated R1CS proof systems
jedisct1 · x · 2026-09-02
EPFL researcher Giacomo Fenzi released a new paper showing the Fiat-Shamir transformation is insecure for a class of proof systems whose instances are generated by running a program, including variants of commonly deployed R1CS protocols.
- Building on CRYPTO 2025 work showing natural GKR-based protocols are unsound with any concrete hash function, the attack extends to settings where computation is described by a (potentially adversarially generated) program compiled into R1CS instances
- When the conversion process is expressive enough, an adversary controlling the program code can break soundness of the non-interactive proof system
- Attacks generalize to any protocol where a cheating prover can prepare an accepting transcript before the statement is bound; variants of Spartan (CRYPTO 2020) and Aurora (EUROCRYPT 2019) fall in this class
- The paper also formalizes a mitigation: deriving the first Fiat-Shamir challenge from the public statement
More from Research
- NASA-IBM AI model maps Asian rice paddies at 30m resolution to track water and methane — anselm · 2026-09-02
- By LeCun's math definition of extrapolation, everything a neural net does is extrapolation — burny_tech · 2026-09-02
- GPT-5.6 Solves Decades-Old Information Theory Conjecture in Yale Professor's arXiv Paper — burny_tech · 2026-09-02
- Google Research's TimesFM time-series foundation model draws renewed GitHub attention — google-research · 2026-09-02
- Most open-source AI text detectors can't hold a 0.5% false-positive rate — grumpyp2 · 2026-09-02
- Preference models to triage AI research ideas win praise from DeepMind's Edward Hughes — j_foerst · 2026-09-02