Paper 2026/1838

How to prove more false statements: Fiat–Shamir limitations on (generated) R1CS

Giacomo Fenzi, École Polytechnique Fédérale de Lausanne
Abstract

The Fiat--Shamir (FS) transformation is a technique that converts interactive protocols into non-interactive ones. FS is secure in idealized models such as the random oracle model (ROM) (if the interactive protocol satisfies a condition known as state-restoration soundness). It is known that there are protocols whose FS transformation is secure in the ROM, yet insecure when instantiated with any concrete hash function. Historically, these protocols were contrived (as in, they were designed so their FS transformation would be unsound). Khovratovich, Rothblum and Soukhanov (CRYPTO 2025) showed that a class of natural (and practically deployed) protocols based on a protocol of Goldwasser, Kalai and Rothblum (JACM 2015) was also unsound when compiled with FS and any concrete hash function. We extend the attack to a different class of protocols: those whose instances are generated by running a program. This setting covers concrete trends in modern proof systems, in which the computation to be proven is described by a program (often adversarialy generated) which is then either compiled or autonomously converted into an instance of target relation such as rank-1 constraint satisfaction (R1CS). We show that, when the conversion process is "expressive enough", an adversary controlling the program code can break soundness of the non-interactive proof system. The attacks generalize to a wide class of protocols: any protocol in which a cheating prover can prepare an accepting transcript before the statement is bound. We show that variants of the Spartan (CRYPTO 2020) and Aurora (EUROCRYPT 2019) proof systems for R1CS fall in this class. Complementing the attacks, we formalize a mitigation: deriving the first Fiat--Shamir challenge from the generated statement, rather than from the program that generates it, provably reduces the soundness of the compiled protocol to that of the underlying protocol for the non-generated relation.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
succinct argumentsFiat-Shamirdiagonalization
Contact author(s)
giacomo fenzi @ epfl ch
History
2026-09-01: approved
2026-08-31: received
See all versions
Short URL
https://ia.cr/2026/1838
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1838,
      author = {Giacomo Fenzi},
      title = {How to prove more false statements: Fiat–Shamir limitations on (generated) {R1CS}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1838},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1838}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.