papers

Publications (13)

cs.CC2020

Arithmetic Expression Construction

Leo Alcock, Sualeh Asif, Jeffrey Bosboom +10

When can given numbers be combined using arithmetic operators from a given subset of to obtain a given target number? We study three variations of this p…

cs.MA2026

Architecture Matters for Multi-Agent Security

Ben Hagag, William L. Anderson, Christian Schroeder de Witt +1

Multi-agent systems (MAS), composed of networks of two or more autonomous AI agents, have become increasingly popular in production deployments, yet introduce security risks that d…

cs.CY2022

Can the Government Compel Decryption? Don't Trust -- Verify

Aloni Cohen, Sarah Scheffler, Mayank Varia

If a court knows that a respondent knows the password to a device, can the court compel the respondent to enter that password into the device? In this work, we propose a new approa…

cs.CR2026

Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents

Christian Schroeder de Witt, Klaudia Krawiecka, Igor Krawczuk +21

AI agents are beginning to interact with each other directly and across internet platforms and physical environments, creating security challenges beyond traditional cybersecurity…

cs.CY2022

Formalizing Human Ingenuity: A Quantitative Framework for Copyright Law's Substantial Similarity

Sarah Scheffler, Eran Tromer, Mayank Varia

A central notion in U.S. copyright law is judging the substantial similarity between an original and an (allegedly) derived work. Capturing this notion has proven elusive, and the…

cs.CY2025

When Anti-Fraud Laws Become a Barrier to Computer Science Research

Madelyne Xiao, Andrew Sellars, Sarah Scheffler

Computer science research sometimes brushes with the law, from red-team exercises that probe the boundaries of authentication mechanisms, to AI research processing copyrighted mate…

cs.CR2024

Mind the Gap: Securely modeling cyber risk based on security deviations from a peer group

Taylor Reynolds, Sarah Scheffler, Daniel J. Weitzner +1

There are two strategic and longstanding questions about cyber risk that organizations largely have been unable to answer: What is an organization's estimated risk exposure and how…

cs.CY2019

Case Study: Disclosure of Indirect Device Fingerprinting in Privacy Policies

Julissa Milligan, Sarah Scheffler, Andrew Sellars +3

Recent developments in online tracking make it harder for individuals to detect and block trackers. Some sites have deployed indirect tracking methods, which attempt to uniquely id…

cs.LG2019

From Soft Classifiers to Hard Decisions: How fair can we be?

Ran Canetti, Aloni Cohen, Nishanth Dikkala +3

A popular methodology for building binary decision-making classifiers in the presence of imperfect information is to first construct a non-binary "scoring" classifier that is calib…

cs.CR2025

Synopsis: Secure and private trend inference from encrypted semantic embeddings

Madelyne Xiao, Palak Jain, Micha Gorelick +1

WhatsApp and many other commonly used communication platforms guarantee end-to-end encryption (E2EE), which requires that service providers lack the cryptographic keys to read comm…

cs.CC2022

PSPACE-completeness of Pulling Blocks to Reach a Goal

Hayashi Ani, Sualeh Asif, Erik D. Demaine +5

We prove PSPACE-completeness of all but one problem in a large space of pulling-block problems where the goal is for the agent to reach a target destination. The problems are param…

cs.CR2023

SoK: Content Moderation for End-to-End Encryption

Sarah Scheffler, Jonathan Mayer

Popular messaging applications now enable end-to-end-encryption (E2EE) by default, and E2EE data storage is becoming common. These important advances for security and privacy creat…

cs.CY2026

Adequately Tailoring Age Verification Regulations

Shuang Liu, Sarah Scheffler

The Supreme Court decision in Free Speech Coalition v. Paxton upheld the constitutionality of Texas H.B. 1181, one of the most constitutionally vulnerable of these age verification…