Paper 2026/1838
How to prove more false statements: Fiat–Shamir limitations on (generated) R1CS
Abstract
The Fiat--Shamir (FS) transformation is a technique that converts interactive protocols into non-interactive ones. FS is secure in idealized models such as the random oracle model (ROM) (if the interactive protocol satisfies a condition known as state-restoration soundness). It is known that there are protocols whose FS transformation is secure in the ROM, yet insecure when instantiated with any concrete hash function. Historically, these protocols were contrived (as in, they were designed so their FS transformation would be unsound). Khovratovich, Rothblum and Soukhanov (CRYPTO 2025) showed that a class of natural (and practically deployed) protocols based on a protocol of Goldwasser, Kalai and Rothblum (JACM 2015) was also unsound when compiled with FS and any concrete hash function. We extend the attack to a different class of protocols: those whose instances are generated by running a program. This setting covers concrete trends in modern proof systems, in which the computation to be proven is described by a program (often adversarialy generated) which is then either compiled or autonomously converted into an instance of target relation such as rank-1 constraint satisfaction (R1CS). We show that, when the conversion process is "expressive enough", an adversary controlling the program code can break soundness of the non-interactive proof system. The attacks generalize to a wide class of protocols: any protocol in which a cheating prover can prepare an accepting transcript before the statement is bound. We show that variants of the Spartan (CRYPTO 2020) and Aurora (EUROCRYPT 2019) proof systems for R1CS fall in this class. Complementing the attacks, we formalize a mitigation: deriving the first Fiat--Shamir challenge from the generated statement, rather than from the program that generates it, provably reduces the soundness of the compiled protocol to that of the underlying protocol for the non-generated relation.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Preprint.
- Keywords
- succinct argumentsFiat-Shamirdiagonalization
- Contact author(s)
- giacomo fenzi @ epfl ch
- History
- 2026-09-01: approved
- 2026-08-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1838
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1838,
author = {Giacomo Fenzi},
title = {How to prove more false statements: Fiat–Shamir limitations on (generated) {R1CS}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1838},
year = {2026},
url = {https://eprint.iacr.org/2026/1838}
}