I’m a doctoral student at , working broadly on security and privacy topics. I am fortunate to be co-advised by Alessandro Chiesa (COMPSEC lab) and Carmela Troncoso (SPRING lab). My research aims to close the gap between the theory and practice of advanced cryptographic primitives, with a focus on efficiency and meaningful security guarantees against real-world threats. I work with at-risk populations such as humanitarian aid organizations (Terre des Hommes, International Committee of the Red Cross) and journalists (International Consortium of Investigative Journalists, European Broadcasting Union). In interactions with these populations, I surface security and privacy problems that have remained unaddressed, along with realistic threat models. I then formalize these requirements, design privacy-preserving systems to address them, and implement and evaluate these systems. As part of this work, I improve underlying cryptographic primitives, in particular zero-knowledge and succinct arguments.
I’m presenting our paper on minimal cryptographic properties needed to build SNARKs at Crypto 🌴!
Aug 12, 2026
Our paper on End-to-End Encrypted Documents won the 2026 Internet Defense Prize and is a Distinguished Paper runner-up at USENIX Security 2026! (MPI-SP announcement, EPFL announcement)
Jul 20, 2026
I’m going to PETS 🇨🇦 to talk about my work in collaboration with the International Committee of the Red Cross, and to talk about privacy harms of digital identity frameworks at the policy-relevant research workshop!
Jul 09, 2026
I’m talking about the EU digital identity framework and the proposed German implementing law in front of the digital commission of the German Bundestag’s 🇩🇪 Linksfraktion (check out articles in taz, heise online and Tagesspiegel).
Jun 11, 2026
Just started my summer internship at Microsoft Research in Redmond, WA 🇺🇸, working on encrypted spaces!
As digital identity systems gain traction around the world, many see privacy-enhancing technologies (PETs) as the key to ensuring safe deployment. We critically examine whether this is the case using the European Digital Identity Framework (EUDIF) as an example. We leverage techniques from cryptographic modeling to formally capture the necessary leakage of the functionality of the EUDIF and its proposed applications. Then, we develop a harm analysis methodology that illustrates, using harm trees, how this leakage — and other constraints stemming from design decisions or the context of deployment — lead to harms. Moreover, our harm modeling enables us to distinguish between which pathways to harm are inherent to the core functionality, and which pathways can be prevented with PETs. Our analysis shows that, while PETs can reduce information flows, they fall short in mitigating the harms that deploying digital identity can bring to individuals and society.
On the Fiat–Shamir Security of Succinct Arguments from Functional Commitments
Alessandro Chiesa, Ziyi Guan, Christian Knabenhans, and Zihan Yu
We study the security of a popular paradigm for constructing SNARGs, closing a key security gap left open by prior work. The paradigm consists of two steps: first, construct a public-coin succinct interactive argument by combining a functional interactive oracle proof (FIOP) and a functional commitment scheme (FC scheme); second, apply the Fiat–Shamir transformation in the random oracle model. Prior work did not consider this generalized setting nor prove the security of this second step (even in special cases). We prove that the succinct argument obtained in the first step satisfies state-restoration security, thereby ensuring that the second step does in fact yield a succinct non-interactive argument. This is provided the FIOP satisfies state-restoration security and the FC scheme satisfies a natural state-restoration variant of function binding (a generalization of position binding for vector commitment schemes). Moreover, we prove that notable FC schemes satisfy state-restoration function binding, allowing us to establish, via our main result, the security of several SNARGs of interest (in the random oracle model). This includes a modular security proof of Plonk, in the ROM based on falsifiable Diffie–Hellman assumptions.
End-to-End Encrypted Collaborative Documents
Christian Knabenhans, Zayd Maradni, and Carmela Troncoso
2026 Internet Defense Prize; USENIX Security 2026 Distinguished Paper Award runner-up
Collaborative documents (e.g., Google Docs, Microsoft 365) often contain sensitive information such as personal or financial data. In this work, we extend the protection of E2EE encryption, currently (mostly) restricted to the use case of messaging, to collaborative documents. We elicit and formalize the security and functional requirements of End-to-End Encrypted Collaborative Documents (E2EE-CD). We then put forth a generic framework to realize E2EE-CD, by combining an end-to-end encrypted asynchronous broadcast channel with any edit reconciliation mechanism which ensures globally consistent views of a document. We give formal proofs that directly relate the security of our E2EE-CD solution to the security of the underlying end-to-end encrypted communication channel. We then elicit additional deployment requirements for E2EE-CD for investigative journalists and design SignalCD, an E2EE-CD system built on top of Signal’s group messaging protocol tailored for this setting. We analyze the security guarantees of SignalCD, implement a prototype, and empirically show that our solution is efficient enough to permit real-time collaboration.
Humanitarian Aid Distribution with Privacy-Preserving Assessment Capabilities
Christian Knabenhans, Lucy Qin, Justinas Sukaitis, Vincent Graf Narbel, and Carmela Troncoso
In times of crisis, humanitarian organizations bring aid to those affected (e.g., water, food, medical supplies, cash assistance). Prior works introduced privacy-preserving systems for digitizing the aid distribution process, increasing their efficiency and security. These solutions, by design, do not allow humanitarian organizations to collect metrics about the aid distribution process. Such assessments (e.g., the proportion of aid distributed to a minority) are crucial to enable the organizations to improve their operations, to perform their duty of care, and to enable transparency and accountability towards recipients, donors, and the public in general. In partnership with the International Committee of the Red Cross (ICRC), we identify assessments relevant to humanitarian aid deployments and these assessments’ security and privacy requirements. We introduce a generic framework that augments existing privacy-preserving humanitarian aid distributions with such assessments. This framework enables the collection of aggregate statistics about the aid distribution process without compromising the privacy of recipients, and without requiring any changes to the existing protocols. To realize our framework we introduce one-time functional encryption (1FE), for which we propose efficient realizations from standard cryptographic primitives. We design and implement two variants of our framework: a more efficient one, secure against semi-honest adversaries; and a more robust one, secure against malicious adversaries. We also introduce the novel notions of threat model agility and graceful degradation. These notions enable us to model the unstable environment of humanitarian aid distribution, where the capabilities of the adversary may change suddenly (e.g., when a militia takes over a region in conflict), invalidating the threat model under which the system was originally deployed. We believe these notions are of independent interest for other privacy-preserving applications deployed in unstable environments.
Participant, on invitation of MEP Maria Guzenina, Vice-Chair of the Child Rights Intergroup.
Privacy Analysis of a Case Management Tool for a Children Safety NGO
Terre des Hommes
Privacy analysis of a deployment of the Primero™ tool for the Terre des Hommes NGO, which supports case workers in protecting children from abuse and exploitation.
Saiid El Hajj Chehade, Christian Knabenhans, and Carmela Troncoso
Position paper presented at the Internet Architecture Board (IAB) and World Wide Web Consortium (W3C) Workshop on Age-Based Restrictions on Content Access.
Sylvain Chatel, Christian Knabenhans, Wouter Lueks, Mathilde Raynal, Carmela Troncoso, and Ádám Vécsi
Position paper presented at the Internet Architecture Board (IAB) and World Wide Web Consortium (W3C) Workshop on Age-Based Restrictions on Content Access.
Sofía Celi, Kyle den Hartog, Hamed Haddadi, Christian Knabenhans, and Elizabeth Margolin
Privacy Vulnerabilities in C2PA Content Provenance Systems: Privacy Analysis and Recommendations for News Media Workflow
SMPTE MTS'25
Paper accepted and presented at the 2025 Media Technology Summit, a global conference on media technologies, organized by the Society of Motion Picture and Television Engineers (SMPTE).
Mohamed Badr Taddist, Christian Knabenhans, Lucille Verbaere, and Carmela Troncoso
Paper accepted and presented at the 2025 International Broadcasting Convention, a global conference for the media, entertainment, and broadcasting industries.
Mohamed Badr Taddist, Christian Knabenhans, Lucille Verbaere, and Carmela Troncoso
As digital identity systems gain traction around the world, many see privacy-enhancing technologies (PETs) as the key to ensuring safe deployment. We critically examine whether this is the case using the European Digital Identity Framework (EUDIF) as an example. We leverage techniques from cryptographic modeling to formally capture the necessary leakage of the functionality of the EUDIF and its proposed applications. Then, we develop a harm analysis methodology that illustrates, using harm trees, how this leakage — and other constraints stemming from design decisions or the context of deployment — lead to harms. Moreover, our harm modeling enables us to distinguish between which pathways to harm are inherent to the core functionality, and which pathways can be prevented with PETs. Our analysis shows that, while PETs can reduce information flows, they fall short in mitigating the harms that deploying digital identity can bring to individuals and society.
On the Fiat–Shamir Security of Succinct Arguments from Functional Commitments
Alessandro Chiesa, Ziyi Guan, Christian Knabenhans, and Zihan Yu
We study the security of a popular paradigm for constructing SNARGs, closing a key security gap left open by prior work. The paradigm consists of two steps: first, construct a public-coin succinct interactive argument by combining a functional interactive oracle proof (FIOP) and a functional commitment scheme (FC scheme); second, apply the Fiat–Shamir transformation in the random oracle model. Prior work did not consider this generalized setting nor prove the security of this second step (even in special cases). We prove that the succinct argument obtained in the first step satisfies state-restoration security, thereby ensuring that the second step does in fact yield a succinct non-interactive argument. This is provided the FIOP satisfies state-restoration security and the FC scheme satisfies a natural state-restoration variant of function binding (a generalization of position binding for vector commitment schemes). Moreover, we prove that notable FC schemes satisfy state-restoration function binding, allowing us to establish, via our main result, the security of several SNARGs of interest (in the random oracle model). This includes a modular security proof of Plonk, in the ROM based on falsifiable Diffie–Hellman assumptions.
End-to-End Encrypted Collaborative Documents
Christian Knabenhans, Zayd Maradni, and Carmela Troncoso
2026 Internet Defense Prize; USENIX Security 2026 Distinguished Paper Award runner-up
Collaborative documents (e.g., Google Docs, Microsoft 365) often contain sensitive information such as personal or financial data. In this work, we extend the protection of E2EE encryption, currently (mostly) restricted to the use case of messaging, to collaborative documents. We elicit and formalize the security and functional requirements of End-to-End Encrypted Collaborative Documents (E2EE-CD). We then put forth a generic framework to realize E2EE-CD, by combining an end-to-end encrypted asynchronous broadcast channel with any edit reconciliation mechanism which ensures globally consistent views of a document. We give formal proofs that directly relate the security of our E2EE-CD solution to the security of the underlying end-to-end encrypted communication channel. We then elicit additional deployment requirements for E2EE-CD for investigative journalists and design SignalCD, an E2EE-CD system built on top of Signal’s group messaging protocol tailored for this setting. We analyze the security guarantees of SignalCD, implement a prototype, and empirically show that our solution is efficient enough to permit real-time collaboration.
Humanitarian Aid Distribution with Privacy-Preserving Assessment Capabilities
Christian Knabenhans, Lucy Qin, Justinas Sukaitis, Vincent Graf Narbel, and Carmela Troncoso
In times of crisis, humanitarian organizations bring aid to those affected (e.g., water, food, medical supplies, cash assistance). Prior works introduced privacy-preserving systems for digitizing the aid distribution process, increasing their efficiency and security. These solutions, by design, do not allow humanitarian organizations to collect metrics about the aid distribution process. Such assessments (e.g., the proportion of aid distributed to a minority) are crucial to enable the organizations to improve their operations, to perform their duty of care, and to enable transparency and accountability towards recipients, donors, and the public in general. In partnership with the International Committee of the Red Cross (ICRC), we identify assessments relevant to humanitarian aid deployments and these assessments’ security and privacy requirements. We introduce a generic framework that augments existing privacy-preserving humanitarian aid distributions with such assessments. This framework enables the collection of aggregate statistics about the aid distribution process without compromising the privacy of recipients, and without requiring any changes to the existing protocols. To realize our framework we introduce one-time functional encryption (1FE), for which we propose efficient realizations from standard cryptographic primitives. We design and implement two variants of our framework: a more efficient one, secure against semi-honest adversaries; and a more robust one, secure against malicious adversaries. We also introduce the novel notions of threat model agility and graceful degradation. These notions enable us to model the unstable environment of humanitarian aid distribution, where the capabilities of the adversary may change suddenly (e.g., when a militia takes over a region in conflict), invalidating the threat model under which the system was originally deployed. We believe these notions are of independent interest for other privacy-preserving applications deployed in unstable environments.