Vigil: Accountable Liveness against Selective Silence

arXiv:2609.18778 · cs.DC, cs.CR · Submitted 2026-09-16 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "Vigil: Accountable Liveness against Selective Silence".

Elias: Selective silence stalls victims while preserving an attacker’s standing, and this work introduces Vigil, a Tendermint variant that matches established lower bounds for accountability against selective silence.

Nadia: First, who's behind it and why it matters.

Paper summary: Nadia: So we're looking at the paper "Vigil: Accountable Liveness against Selective Silence," which tackles this tricky issue of adversaries who withhold messages from some honest nodes while acting correctly towards others, stalling consensus. The main point they're making is that selective silence can evade existing accountability mechanisms, so they’ve created a new Tendermint variant to handle it systematically.

Elias: I see, so the core thesis seems to be addressing how selective silence stalls liveness violations that other mechanisms miss because an adversary can essentially hide by being silent only to specific honest nodes. The paper claims this work is important because it identifies the limits of finding adversaries who withhold messages from certain nodes while maintaining good behavior elsewhere, which gives us a framework to price this residual surface and ensure accountability even when no actual violation materializes, according to the summary.

Priya: From a privacy and measurement standpoint, I'm interested in what this means for the data we're actually collecting on these networks. If an attacker can remain silent toward a specific set of nodes without being detected, how much verifiable information is actually lost or skewed in those interactions?

Nadia: That’s exactly what we need to figure out, Priya; the paper sets up a universal lower bound for this silence identification threshold, which they define as KSI at least f+one where f is the number of honest nodes an attacker can be silent toward without being distinguishable from honesty. This means if an attacker is silent toward at most f honest nodes, they look just like a perfectly honest node in terms of their behavior.

Elias: And that lower bound directly leads to Vigil matching this by setting tau A = f, achieving KSI = tau A+one. That’s the mathematical match they’re aiming for against the known limits of silence identification.

Priya: So, if an attacker is silent toward f nodes, Vigil is designed to detect that level of silence and force a repair process, which sounds like it’s about quantifying the cost associated with this untracked surface.

Nadia: Exactly; the paper systematically prices this "residual surface," meaning they're not just saying silence is bad, but they’re putting a concrete cost on it. They show that under link non-observability, a lone attacker’s silence toward at most f honest nodes is indistinguishable from honesty.

Paper summary: Elias: But the paper also points out that this leads to a specific cost structure; when no actual violation occurs under sub-threshold silence, the per-view authenticator overhead is O(n) authenticators per node plus (n two) metadata bits.

Priya: That’s a lot of metadata overhead for what sounds like an accounting mechanism; does this cubic cost structure they mention apply to every scenario where silence is present, or just when a violation actually materializes?

Nadia: It applies when the silence exceeds the threshold tau A, specifically in the excessive-fault regime where t at least n/three > f, which forces a majority accusation of at least n/three nodes, matching what Theorem seven guarantees.

Elias: And that’s where the worst-case cost for one-shot, feedback-free repair comes in, which is stated as (n three) authenticators, with a closed form C = f(n-f) two/four at t=f. That cubic cost is only incurred when an adversary mounts a maximal selective-silence attack against a targeted third of the honest nodes, which is pretty specific.

Priya: I wonder if this (n three) cost is manageable in practice for large networks, and what that implies for the real-world utility of this accountability framework we're discussing in "Vigil: Accountable Liveness against Selective Silence."

Nadia: The paper addresses that concern by incorporating cross-attestation and windowed conviction through BlameAccounting to handle real-world conditions. They prove under x < one/two asynchrony, no honest node is ever convicted, showing a trade-off between online per-view accusations and those transferable certificates controlled by an opening threshold AccK.

Elias: And the results on the three-region WAN experiments confirm these theoretical bounds; they show that for t=f=eight convictions flip from zero to all t exactly when silence reaches tau A+one validating Theorem five. That’s strong validation for the core identification logic.

Priya: So, the data really shows that raising that threshold tau A can actually restore soundness when the asynchrony x is small enough, which suggests there's a tunable parameter here for network deployment.

Nadia: And they show adaptive white-box adversaries gain nothing against Vigil’s defenses because strategies like "threshold-pinned silence at s = tau A " induce exactly the guaranteed cost C(t, tau A). This confirms that the defense is robust against sophisticated attacker tactics.

Elias: The paper also makes a structural statement about ethics and pricing, suggesting that sub-threshold silence is just a "pure resource-griefing surface" present in any protocol matching Theorem two. Vigil prices this grief exactly through the relay rule, which is interesting for how we view inherent protocol limitations.

Paper summary: Priya: If we think about the broader impact, does this framework suggest a new way to design consensus protocols where accountability against these subtle liveness attacks is built in from the start rather than bolted on later?

Nadia: The implication is that setting tau A to the largest corruption the deployment can survive accountably makes sense because bandwidth isn't a binding constraint in this regime. This gives us a clear metric for what level of silent disagreement we can tolerate without needing expensive repairs.

Elias: For cryptographers, the focus is on the proof assumptions; they established that even with these complex mechanisms, an honest node that never hears from another cannot easily tell silence from a complete loss of communication or verify third-party claims about that silence.

Priya: Ultimately, this paper suggests that the way we measure and price accountability against selective silence is a crucial piece of infrastructure for building more resilient decentralized systems.

Nadia: Indeed, "Vigil: Accountable Liveness against Selective Silence" provides a concrete mechanism to move beyond just detecting safety violations to actively managing and pricing the cost of liveness stalls caused by selective silence.

Elias: So, the core contribution is providing a Tendermint variant that matches established lower bounds for accountability against selective silence, specifically identifying KSI = tau A+one as the universal threshold.

Priya: The data strongly supports the theoretical findings, showing how measurable parameters like asynchrony affect the system's ability to convict honest nodes under cross-view aggregation.

Nadia: We’ve established that sub-threshold silence is unaccusable but must be repaired, and Vigil prices this grief exactly through the relay rule, which is a key finding from this work.

Nadia: So, to wrap up on "Vigil: Accountable Liveness against Selective Silence," the authors introduce a Tendermint variant that systematically identifies adversaries who withhold messages from specific honest nodes while behaving correctly toward others.

Elias: Their main claim is that they match established lower bounds for accountability against selective silence, achieving an identification threshold of exactly KSI = tau A+one.

Priya: The practical implication we see from the data is that this framework allows us to price this residual surface and ensure accountability even when no violation materializes, which is significant for understanding network dynamics.

Nadia: In simple terms, the paper shows how to handle the problem where an attacker stalls consensus by being silent selectively, and it prices that silence exactly through a relay rule.

Conclusion: Nadia: So we've looked at how this paper, "Vigil: Accountable Liveness against Selective Silence," tackles that stubborn problem of attackers who just stay quiet about some messages while still being honest elsewhere.

Elias: Yeah, I mean it sets up this Tendermint variant to specifically match the established lower bounds for accountability against that kind of selective silence we talked about.

Priya: From a measurement standpoint, what’s really striking is how they manage to price this "residual surface" of unaccounterable silence without making things overly complicated or computationally expensive in every situation.

Nadia: Exactly, it seems they've found a way to make accountability less about finding outright violations and more about systematically managing the cost of potential liveness stalls.

Elias: The authors are quite clear on the mathematical parameters, focusing on identifying that universal threshold where an attacker’s silence becomes indistinguishable from being honest.

Priya: That identification threshold, KSI equals tauA plus one, is a key metric because it gives us a concrete limit for how much "silence griefing" we can structurally expect in any protocol matching their model.

Nadia: And that's where the real impact comes in; if we can quantify and price that silence, we move from just hoping things stay alive to actually engineering systems that survive them accountably.

Elias: It suggests a path forward for designing consensus mechanisms where we build this accountability pricing directly into the relay rules, rather than trying to patch it on later.

Priya: So, the paper’s conclusion points toward making tau A a tunable parameter based on how much corruption we decide our deployment can actually tolerate before things become unmanageable.

Nadia: Right, so setting that limit gives us a clear understanding of what level of silent disagreement we can handle without needing massive repair overhead.

Elias: That's the big picture for the cryptographer—it shows us how to make liveness guarantees robust against these subtle forms of adversary behavior under specific assumptions.

Priya: And honestly, I'm really excited about how they framed sub-threshold silence as a measurable resource griefing surface, which gives us a new way to think about protocol limitations.

Jiawei Cheng, Huiping Sun, Rui Zhou, Jinjue Zhou, Zhong Chen

School of Software & Microelectronics, Peking University · School of Computer Science, Peking University · School of AI and Liberal Art, Beijing Normal-Hong Kong Baptist University

cs.DC, cs.CR

Submitted: 2026-09-16

Updated: 2026-09-16

Comments: 20 pages, 8 figures

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 92/100

The gist: Selective silence stalls victims while preserving an attacker’s standing, and this work introduces Vigil, a Tendermint variant that matches established lower bounds for accountability against

Key concepts

Selective Silence
This occurs when an attacker intentionally stops sending messages to a subset of honest nodes while continuing normal communication with the rest of the network. Vigil aims to identify this specific behavior even if no outright violation occurs.
KSI = τA+1
This is the identification threshold for selective silence. KSI represents how many nodes need to be identified for accountability. Vigil sets this threshold precisely at one more than the number of honest nodes that can remain silent without detection.
Core Extraction (Kp)
This algorithm identifies a specific, highly connected subset of honest nodes within the network. It is computed from a graph representing mutual attestations, ensuring that every node in this core has a high degree relative to the total number of honest nodes.
Cubic Cost
This represents the worst-case cost for repairing a violation under sub-threshold silence. It occurs when an attacker targets a significant portion of honest nodes, requiring cubic resources (O(n^3)) for one-shot, feedback-free repair.

Terminology

Summary

Selective silence stalls victims while preserving an attacker’s standing, and this work introduces Vigil, a Tendermint variant that matches established lower bounds for accountability against selective silence. This research matters because it systematically identifies the limits of identifying adversaries who withhold messages from specific honest nodes while behaving correctly toward others, providing a framework to price this residual surface and ensure accountability even when no violation materializes.

How it works

Vigil is a Tendermint variant designed to match the universal lower bounds for accountability against selective silence, achieving an identification threshold of exactly KSI = τA+1. The protocol operates by broadcasting a signed bitmap of received votes after each round, which nodes assemble into a graph of mutual attestations. This process extracts a deterministic membership core, denoted as Kp, which is computed using the CoreExtract algorithm.

The key mechanisms include:

  1. Symmetrization: For every pair (u, w), an edge survives only by mutual attestation (if bmu[w] = 1 but bmw[u] = 0, reset bmu[w] ← 0).

  2. Validity Filter: Nodes are discarded if their bitmap is of the wrong length or if their vote/bitmap attestation of a peer is missing.

  3. Core Extraction: The membership set Kp is defined as the (n−τA −1)-core of the symmetrized attestation graph Gp, computed in O(n 2) time. This core extraction ensures that every honest vertex has degree ≥ n−τA − 1 within H alone.

Identification and Thresholds

The paper establishes several critical quantitative limits for accountability. Under link non-observability, a lone attacker’s silence toward ≤ f honest nodes is indistinguishable from honesty. The universal lower bound on the silence identification threshold is KSI ≥ f+1. Vigil matches this by setting τA = f, achieving KSI = τA+1. Furthermore, in the excessive-fault regime where t ≥ ⌈n/3⌉ > f, a violation forces majority accusation of at least ⌈n/3⌉ nodes, matching the cap guaranteed by Theorem 7.

Cost and Forwarding Necessity

The paper precisely prices the costs associated with defense against selective silence. When no silence occurs, the per-view authenticator overhead is O(n) authenticators per node (plus Θ(n 2) metadata bits). However, when a violation occurs under sub-threshold silence (s > τA), honest nodes must forward votes specific to core members. The worst-case cost for one-shot, feedback-free repair is Θ(n 3) authenticators, with the closed form being C = f(n−f) 2/4 at t=f. This cubic cost is incurred only when an adversary mounts a maximal selective-silence attack against a targeted third of the honest nodes.

Cross-View Aggregation and Robustness

To handle real-world network conditions, Vigil incorporates cross-attestation and windowed conviction via BlameAccounting. This mechanism aggregates signed accusation bitmaps across multiple views into transferable certificates. Theorem 10 proves that under x < 1/2 asynchrony, no honest node is ever convicted. The system manages the trade-off between online per-view accusations and transferable certificates, using an opening threshold AccK to control sensitivity against cost.

Evaluation and Results

Real-network experiments on a three-region WAN confirm the theoretical bounds. They show that for t=f=8, convictions flip from 0 to all t exactly at s = τA+1 = 16, validating Theorem 5. Furthermore, the analysis of cross-view certificates under measured asynchrony (xˆ) shows that raising the threshold τA restores soundness when xˆ is small enough. Adaptive white-box adversaries are shown to gain nothing against Vigil’s defenses, confirming that strategies like threshold-pinned silence at s = τA induce exactly the guaranteed cost C(t, τA).

Ethics and Structural Pricing

The work concludes that sub-threshold silence is a pure resource-griefing surface, structurally present in any protocol matching Theorem 2. While this griefing cannot be prevented, Vigil prices it exactly through the relay rule. The ethical considerations emphasize that the analysis strengthens defenses without introducing new attack capabilities, and the structural pricing does not disadvantage attackers over existing protocols. The findings suggest setting τA to the largest corruption the deployment should survive accountably, as bandwidth is not a binding constraint in this regime.

The gist

Vigil matches established lower bounds for accountability against selective silence by majority-accusing every node silencing more than τA honest peers and forwarding only in proportion to actual attacks. The paper establishes that sub-threshold silence is unaccusable yet must be repaired, and it prices this grief exactly through the relay rule.

Improvements for AI systems

Based on the provided scientific paper, here are specific improvements that can be made to AI systems (specifically those underpinning Blockchain/BFT consensus and distributed ledger technologies) by implementing the concepts from VIGIL:


  1. Acknowledge and Price Selective Silence in Consensus Mechanisms: The system can now be designed to explicitly detect and quantify an adversary who selectively withholds messages from a specific subset of honest nodes while appearing honest to others.

  2. Implement an Information-Theoretic Identification Threshold (KSI): The AI system can establish a precise, information-theoretic lower bound for identifying such silence, setting the minimum number of honest peers required to trigger accountability (KSI ≥ f+1). This moves beyond simple failure detection.

  3. Develop Attack-Adaptive Forwarding: The consensus protocol can dynamically adjust its communication and verification overhead based on the measured width of a suspected attack (the degree of selective silence). This ensures resources are only spent when an actual, high-impact attack is occurring.

  4. Enforce Cost-Effective Accountability: The system will only incur the full worst-case communication cost (Θ(n3) for feedback-free repair) when a violation actually occurs and requires repair, rather than paying it constantly during normal operation. This optimizes resource allocation while maintaining strong accountability guarantees.

  5. Ensure Soundness Against False Accusations: By using a majority-accusation bar (> n/2), the system is robust against false accusations even under adversarial noise or jitter, ensuring that honest nodes are never wrongly convicted unless overwhelming evidence exists.

  6. Enable Cross-View Robust Conviction (Transferable Certificates): The system can aggregate evidence across multiple asynchronous views to generate transferable certificates. This allows for long-term conviction of persistent attackers, even when network conditions change or asynchrony is present (x < 1/2).

  7. Provide Structural Resilience Against Denial and Griefing: The protocol incorporates mechanisms that price griefing (residual sub-threshold silence) exactly, meaning small, continuous attacks are detectable and accounted for structurally within the protocol’s cost model.

These improvements enable an AI system to transition from merely achieving basic safety/liveness guarantees to providing high-fidelity, economically optimized, and structurally resilient accountability in decentralized environments.

Sources

Related papers