One Node, Two Roles: Simultaneous Contests for Validation and Attention in Rollups
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "One Node, Two Roles".
Elias: The gist One Node,
Nadia: First, who's behind it and why it matters.
Paper summary: Nadia: So to recap this paper, they introduce a new modeling framework to look at how attention mechanisms interact with validation roles in optimistic rollups by treating them as coupled Tullock-like contests.
Elias: The thesis is that they formalize the underlying cryptographic primitive as arguments with registered provers, which has a non-amortizability property that hadn't been studied much for modern succinct cryptographic proofs before.
Priya: So what’s the central claim they are making about this framework? Is it just a mathematical curiosity, or does it change how we think about safety assumptions in rollups?
Nadia: They derive conditions on the entry and marginal sybil costs that support a given target execution diversity in equilibrium. They model operators assuming they are risk-neutral and pay based on expected payout.
Elias: The crucial claim is comparing TRACE and Proof of Diligence using this new framework to see which one offers better cryptographic guarantees for attention mechanisms.
Priya: How does that comparison manifest in the results? Are there specific numbers showing one is inherently better than the other?
Nadia: They show that in TRACE, the marginal cost can be adjusted to support a higher execution diversity compared to Proof of Diligence. That’s a key difference.
Elias: They also sketch a construction with stronger non-amortizability guarantees than both TRACE and Proof of Diligence, but that specific construction requires a more expensive prover than what's currently available.
Priya: So, if I’m just listening to this paper today, what is the practical implication for someone who cares about privacy or measurement research?
Nadia: It shows how the cryptographic assumptions directly dictate the achievable diversity of execution in these systems. The security primitive isn't just a black box; it’s part of a game that has limits.
Elias: It moves the discussion from just "is this proof safe?" to "how much work does it cost to get what we need, given the structure of the competition?"
Conclusion: Nadia: So looking at the full picture of "One Node, Two Roles: Simultaneous Contests for Validation and Attention in Rollups," the authors are essentially mapping out the limits of operational choices within these rollup systems.
Elias: They’re showing that you can model these complex interactions through a game-theoretic lens to understand how validation and attention roles compete for resources like execution diversity.
Priya: For someone who listens to this show, what is the simple summary of why this work matters outside of the dense math? What's the real-world concept it points toward?
Nadia: It points toward understanding that every component you add to a rollup, whether it’s validation or attention, introduces a specific cost and constraint on what you can achieve in terms of how many different people can actually run things independently.
Elias: It’s about making sure that when we design these systems, we aren't just optimizing for one thing while ignoring the other role's demands.
Priya: So, what should I take away about this paper? What’s the most important concept to carry with you as you go?
Nadia: The most important thing is recognizing that execution diversity isn't a free variable; it's constrained by the costs of deploying those attention identities.
Elias: Exactly. It’s not just about having a big number; it’s about understanding the underlying cost structure that limits what you can actually build efficiently.
Pranay Anchuri, Ben Berger, Matteo Campanelli, Akaki Mamageishvili
Offchain Labs
cs.CR
Submitted: 2026-10-08
Updated: 2026-10-08
License: http://creativecommons.org/licenses/by/4.0/
The gist: The gist One Node, Two Roles Simultanous Contests for Validation and Attention in Rollups provides a new modeling framework to analyze how attention mechanisms interact with validation roles in
Key concepts
- Coupled Tullock-like Contests
- This is a game theory model where an operator pays a single entry cost for execution, then decides how many identities to use in two roles (validation and attention). The shared entry cost links the two contests, meaning the decision in one role affects the other. It helps predict how operators will distribute their resources based on costs.
- Arguments with Registered Provers
- This is a new cryptographic framework used to model attention mechanisms. It formalizes 'non-amortizability,' which measures the per-identity work required for these proofs. This concept allows the authors to rigorously analyze the computational cost associated with deploying extra attention identities.
- Execution Diversity (A)
- This refers to the range of different execution strategies an operator can employ while maintaining a target number of identities. The analysis shows that under certain conditions, operators can achieve a higher diversity by adjusting costs, specifically comparing non-decreasing vs. decreasing reward functions.
Terminology
Summary
The gist One Node, Two Roles Simultanous Contests for Validation and Attention in Rollups provides a new modeling framework to analyze how attention mechanisms interact with validation roles in optimistic rollups by treating them as coupled Tullock-like contests. This research is significant because it quantifies the attainable range of execution diversities based on the marginal cost of deploying extra attention identities, comparing existing mechanisms like TRACE and Proof of Diligence.
Modeling Validation and Attention Contests
The authors formalize the underlying cryptographic primitive as a new notion, arguments with registered provers, whose properties include a form of non-amortizability that has not been studied for modern succinct cryptographic proofs before<ref:2610.12220#pg4> They design validation and attention reward mechanisms and analyze them as two coupled Tullock-like contests, in which an operator pays once for the required execution and then chooses how many identities to deploy in each role Assuming risk-neutral operators, we model their utilities by their expected payout, so that every sybil receives, in expectation, an equal share of its role’s reward The resulting game resembles two simultaneous Tullock-like contests coupled through the shared entry cost.
Cryptographic Framework for Attention Mechanisms
The authors introduce arguments with registered provers, a cryptographic framework for attention mechanisms, and formalize non-amortizability, which captures the per-identity work needed by our game-theoretic analysis. They compare TRACE [Anc26] and Proof of Diligence [SRB+24] using this framework. In TRACE, the marginal cost mentioned above can be adjusted to support a higher execution diversity as opposed to Proof of Diligence.
Analysis of Execution Diversity
The game models how operators respond to a reward paid per sybil, where an operator pays a cost c once and each attention sybil costs da. The outcome the rollup wants is one identity per operator, as this would result in the minimal offered reward for otherwise the same amount of independent operators. The condition for a good equilibrium in the attention game is that c ≤ 2da/A-1.
Performance on Arbitrum One
Applying theoretical results to Arbitrum One, measurements put the attention sybil cost at da = 0.91 per hour at the default trace length of N = 220. At this cost, non-decreasing reward functions support an execution diversity of at most A = 2. Increasing the trace length to N = 224 raises this maximum to A = 29, while reward functions that decrease beyond some threshold support A = 30 at the baseline cost.
Non-Amortizability and Construction
The TRACE construction is cast as an argument with registered provers, and it is shown to be non-amortizable with overhead ∆ = Ω(log N · λ) (Theorem 3.9). This overhead stems from the argument system underlying TRACE, a Bulletproofslike inner-product argument. A stronger construction with more expensive prover can yield a linear overhead in the trace length, O˜(N2/3) per identity.
Conclusion on Trade-offs
The paper demonstrates that under non-decreasing reward functions, one identity per operator requires A ≤ 1 + 2da/c. A decreasing reward can support a larger target without raising da, but it moves the constraint to the reward curve. The proven overhead for TRACE is logarithmic in the trace length, and the best sharing known costs N0.936 per identity. The gap between this and the honest prover's cost Θ(N) is a factor of N0.064, which is 2.4 at N = 220.
How it works
The authors model the situation as two coupled Tullock-like contests where an operator pays a single entry cost for execution and then chooses how many identities to deploy in each role. They derive conditions on the entry and marginal sybil costs that support a given target execution diversity in equilibrium. The game is modeled by utility functions based on expected payouts, resembling simultaneous Tullock-like contests coupled through the shared entry cost.
Cryptographic Framework for Attention Mechanisms
The authors introduce arguments with registered provers, a cryptographic framework for attention mechanisms, and formalize non-amortizability. They compare TRACE [Anc26] and Proof of Diligence [SRB+24] using this framework. The TRACE construction is cast as an argument with registered provers, and it is shown to be non-amortizable with overhead ∆ = Ω(log N · λ) (Theorem 3.9).
Analysis of Execution Diversity
The game models how operators respond to a reward paid per sybil, where an operator pays a cost c once and each attention sybil costs da. The condition for a good equilibrium in the attention game is that c ≤ 2da/A-1.
Modeling Validation and Attention Contests
The authors formalize the underlying cryptographic primitive as a new notion, arguments with registered provers, whose properties include a form of non-amortizability that has not been studied for modern succinct cryptographic proofs before. They design validation and attention reward mechanisms and analyze them as two coupled Tullock-like contests, in which an operator pays once for the required execution and then chooses how many identities to deploy in each role. Assuming risk-neutral operators, we model their utilities by their expected payout, so that every sybil receives, in expectation, an equal share of its role’s reward. The resulting game resembles two simultaneous Tullock-like contests coupled through the shared entry cost.
Cryptographic Framework for Attention Mechanisms
The authors introduce arguments with registered provers, a cryptographic framework for attention mechanisms, and formalize non-amortizability. They compare TRACE [Anc26] and Proof of Diligence [SRB+24] using this framework. In TRACE, the marginal cost mentioned above can be adjusted to support a higher execution diversity as opposed to Proof of Diligence.
Improvements for AI systems
-
The system can deploy a significantly higher number of independent attention nodes compared to existing mechanisms by leveraging non-decreasing reward functions, as shown by Proposition 4.1:
Condition (11) is necessary for a good equilibrium to exist for any non-decreasing reward function.
This allows the system to sustain an execution diversity up toA ≤ 2 at N = 220
when using a fixed trace length, which can be increased substantially by adjusting the reward curve. -
The system's operational cost per identity is precisely quantified by the marginal cost of deploying an extra attention identity, as derived in Section 5:
The bound on that overshoot and its derivation are in Section C.1.
This allows operators to make informed trade-offs between proving work and execution diversity, specifically showing thatA longer trace raises both the cost of deploying identities and the bound on A.
-
By adopting a stronger cryptographic primitive, the system can achieve better security guarantees than Proof of Diligence by utilizing arguments with registered provers:
TRACE in this framework [is] non-amortizable with overhead ∆ = omega(log N · λ1−ϵ).
This provides a more robust mechanism for incentivizing execution, as TRACE's properties are superior to Proof of Diligence's, which only certifies roots rather than the trace. -
The system can efficiently manage high-volume claims by employing optimized sharing techniques: "After k rounds every identity’s folded vector is a combination of the same B pieces, so producing all n of them at once is a matrix product of shape (n × B)(B × N/B), which fast matrix multiplication computes in fewer than the obvious nN operations [Str69].
This allows an operator to compute proofs for many identities simultaneously, reducing the cost per identity to
O(N0.936)." -
The system can adapt its incentive structure dynamically based on market conditions or desired diversity by utilizing non-monotonic reward functions:
A decreasing reward supports the desired equilibrium even when da is small.
This enables an operator to achieve a larger target population, as demonstrated by the example whereA = 30 attention nodes out of which V = 5 are validators
can be sustained under specific concave reward functions.
Abstract
An optimistic rollup is safe as long as at least one honest validator executes its state transition function (STF) and disputes any assertion that is inconsistent with the result of the execution. Allowing anyone to participate, however, does not give incentive to do so: as long as every assertion is correct, verifying assertion correctness goes unpaid. Attention mechanisms address this by paying nodes to execute the rollup's STF, regardless of whether they participate in the validation process. Since a single node operator can back many registered identities with a single execution, paying per identity does not buy execution diversity, that is, the number of operators that independently execute. In this work we provide a new modeling framework for this problem. We formalize the underlying cryptographic primitive as a new notion, arguments with registered provers, whose properties include a form of non-amortizability that, to our knowledge, has not been studied for modern succinct cryptographic proofs before. We design validation and attention reward mechanisms and analyze them as two coupled Tullock-like contests, in which an operator pays once for the required execution and then chooses how many identities to deploy in each role. We quantify the attainable range of execution diversities in equilibrium as a function of the marginal cost of deploying an extra attention identity. We use our framework as a lens through which we compare two attention mechanisms, TRACE (MARBLE 2026) and Proof of Diligence (AFT 2024). In particular, we show that as opposed to Proof of Diligence, in TRACE the marginal cost mentioned above can be adjusted to support a higher execution diversity. As a case study, we apply our results to Arbitrum One, a widely deployed optimistic rollup.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs