Oversized salary
Submit 4,000,000,000 into a 24-bit Sum circuit. The malicious client constructs a malformed encoding directly.
PRIVATE AGGREGATION, PROVEN
Verifiable aggregation · Prio3 · VDAF
Split a salary into two shares, send each with part of a fully linear proof, and watch two aggregators accept the total without either reading the report.
Secret sharing hides one measurement and still adds it perfectly, even when the measurement is a lie. Prio3 adds a proof to those shares so the servers can jointly answer one narrow question: is this report shaped correctly?
Choose a measurement, split it, then let both aggregators contribute a verifier share. Only their combined verifier can accept.
24-bit range: 0 to 16,777,215. Client-side limits are convenience, not the defense.
The protocol result is computed from output shares. The plain sum is computed separately and compared.
These controls bypass the friendly input path and attack the real proof preparation code.
Submit 4,000,000,000 into a 24-bit Sum circuit. The malicious client constructs a malformed encoding directly.
Flip one Field64 element after sharding. The salary shares are untouched; proof consistency fails.
Send the identical report twice. Preparation verifies it again and accepts it again; only this lab's nonce registry, outside the VDAF, refuses the duplicate.
TRUST ASSUMPTION
One aggregator sees only a random-looking share. If both aggregators collude, their shares add back to the encoded input.
A validity proof checks the circuit statement, not the world outside it.
NEGATIVE CLAIM 01
Prio3 checks that a report is in range and correctly shared. It cannot check that the report is true.
NEGATIVE CLAIM 02
Prio3 does not add differential privacy. With one accepted report, the aggregate is the report.
Runtime checks use the same deterministic inputs as the committed unit tests.
src/flp/circuit.tsunshard()