1

On practical privacy challenges of medical research in the US

The progression of medical research depends on access to sensitive health data, creating an inherent tension between patient privacy and public health. National and local policy in the US mandates protection of patient privacy, but largely leaves …

Privacy audits for clinical large language models

Large language models (LLMs) fine-tuned on de-identified clinical notes raise privacy concerns because automated de-identification can leave residual patient identifiers in the training data. We study whether such identifiers can be recovered from a …

Authenticated private information retrieval

This paper introduces protocols for _authenticated_ private information retrieval. These schemes enable a client to fetch a record from a remote database server such that (a) the server does not learn which record the client reads, and (b) the …

Replicated state machines without replicated execution

This paper introduces a new approach to reduce end-to-end costs in large-scale replicated systems built under a Byzantine fault model. Specifically, our approach transforms a given replicated state machine (RSM) to another RSM where nodes incur lower …

CHAINIAC: Proactive software-update transparency via collectively signed skipchains and verified builds

Software-update mechanisms are critical to the security of modern systems, but their typically centralized design presents a lucrative and frequently attacked target. In this work, we propose CHAINIAC, a decentralized software-update framework that …