Papers
Topics
Authors
Recent
Search
2000 character limit reached

SLS-INDEX: Secure Learned Spatial Index

Updated 10 December 2025
  • The paper introduces SLS-INDEX, a secure indexing framework combining hierarchical learned predictors with Paillier homomorphic encryption to support privacy-preserving spatial range queries.
  • It employs a robust two-server semi-honest model with secure bucketing, permutation-based bucket prediction, and noise padding to protect data and query access patterns.
  • Empirical evaluations show sub-second query latency and 2–3× faster range queries on real datasets compared to traditional ciphertext-only approaches.

The Secure Learned Spatial Index (SLS-INDEX) is a privacy-preserving indexing framework for range queries over encrypted spatial datasets. Designed to address the dual challenges of access-pattern privacy and query efficiency, SLS-INDEX integrates a hierarchical learned predictor architecture with Paillier homomorphic encryption and includes protocols for secure bucket prediction and point extraction. The construction achieves strong formal privacy guarantees under a robust two-server semi-honest adversarial model, while supporting practical sub-second query latency at scale (Wang et al., 3 Dec 2025).

1. Threat Model and Security Framework

SLS-INDEX is evaluated in the standard two-server semi-honest model. The Data Service Provider (DSP) and Data Assistance Provider (DAP) are assumed to be non-colluding and semi-honest: they may follow the protocol but attempt to glean additional information from observed data and protocol transcripts. The Data Owner (DO) and Client are fully trusted, and all inter-party channels are authenticated.

Adversarial Views:

  • DSP: Observes the encrypted index IeI^e, encrypted queries ⟦Q⟧\llbracket Q\rrbracket, transcripts of all homomorphic computations, outputs of secure shuffles (permutations), and garbled indicator vectors.
  • DAP: Possesses the secret Paillier key sksk, receives randomized ciphertexts from DSP, and accesses decrypted intermediate values (under controlled opening semantics) and noise-perturbed buckets or points.
  • Neither DSP nor DAP learns underlying plaintext data, queries, result values, or true access patterns beyond what is captured by the explicitly defined leakage functions.

Leakage Functions:

  • Build: LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi) with nn (point count), dd (dimensionality), and Ψ\Psi (the sorted order of Z-curve ranks).
  • Update: LUpdate(Ie,op)=(pos,bid,Ï–)\mathcal L_{\mathsf{Update}}(I^e, \mathsf{op}) = (\mathit{pos}, \mathit{bid}, \varpi) for operation position, bucket identifier, and type (insert\mathrm{insert}, delete\mathrm{delete}).
  • Query: ⟦Q⟧\llbracket Q\rrbracket0 for the encrypted bucket scan-range and result ciphertext volume.

The security property is defined by indistinguishability between real and ideal experiments: for any PPT adversary, there exists a simulator such that distinguishing real from ideal outputs is negligible in the security parameter ⟦Q⟧\llbracket Q\rrbracket1.

2. Index Construction and System Components

SLS-INDEX organizes encrypted spatial data using a hierarchical learned index with a three-stage prediction pipeline. The structure enables efficient pruning and bucket localization in the encrypted domain.

2.1 Z-curve Mapping and Bucketing

  • Spatial Encoding: Each ⟦Q⟧\llbracket Q\rrbracket2-dimensional point ⟦Q⟧\llbracket Q\rrbracket3 is mapped to a 1D Z-curve value ⟦Q⟧\llbracket Q\rrbracket4.
  • Ordering: The points are sorted by ⟦Q⟧\llbracket Q\rrbracket5, assigned order indices ⟦Q⟧\llbracket Q\rrbracket6.
  • Bucketing: With fixed capacity ⟦Q⟧\llbracket Q\rrbracket7, each point's bucket ID is determined as

⟦Q⟧\llbracket Q\rrbracket8

  • Storage: Each bucket contains encrypted points ⟦Q⟧\llbracket Q\rrbracket9 and an encrypted minimum bounding rectangle (MBR) sksk0.

2.2 Hierarchical Predictors

  • Head Level (Level 0): The space is partitioned into sksk1 grid cells. An MLP (sksk2) is trained for cell ID prediction, with parameter encryption as SMLPsksk3 (biases encrypted; weights plaintext with additive noise).
  • Intermediate Levels: Recursion is performed on any grid cell exceeding threshold sksk4, with new SMLPsksk5 models trained per refined partition.
  • Leaf Level: For partitions with sksk6 points, sksk7 predicts the final bucket ID. Here, all model parameters are fully encrypted (SMLPsksk8). Secure ReLU (sksk9) is evaluated via secure integer comparison (SIC).

2.3 Bucket Padding

Each bucket is padded with dummy points LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)0 up to the fixed capacity LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)1, obfuscating true data distribution and bucket sizes.

2.4 Paillier Homomorphic Encryption

SLS-INDEX leverages the Paillier cryptosystem for all index and data encryption—with additive homomorphic properties enabling secure arithmetic over ciphertexts:

  • Encryption: LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)2 for message LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)3 and randomness LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)4.
  • Homomorphic Addition: LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)5.

3. Secure Range Query Protocols

SLS-INDEX employs two key protocols to handle range queries without leaking access patterns or sensitive structural information.

3.1 Permutation-Based Secure Bucket Prediction (SBP)

SBP allows secure index traversal from the head to leaf predictor, hiding the real search path and bucket identifiers using a combination of model encryption, shuffling, and PRF masking:

  • The Client sends LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)6 to DSP.
  • DSP traverses SMLPLBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)7 predictors, switching to a leaf-level SMLPLBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)8 when appropriate.
  • DSP introduces a dummy bucket and randomization, then shuffles candidate bucket ciphertexts with a random permutation LBuild(⟦P⟧)=(n,d,Ψ)\mathcal L_{\mathsf{Build}}(\llbracket P\rrbracket) = (n, d, \Psi)9 and sends them to DAP.
  • DAP decrypts, repermutes, and returns results to DSP, who then accesses, perturbs, and returns buckets' encrypted contents and query to DAP.
  • DAP checks for membership using plaintext, sets a flag, and sends the result back to DSP, who finalizes the relevant bucket ID.

This protocol restricts leakage to information allowed by the leakage function, ensuring that bucket selection and search path remain hidden.

3.2 Secure Point Extraction (SPE)

SPE retrieves all encrypted points in a bucket range covering a query's scan region:

  • DSP obtains span bucket IDs and masks them before sending to DAP.
  • DAP decrypts and unmasks, returning the actual bucket-range to DSP.
  • For each relevant bucket, DSP perturbs, shuffles, and sends obfuscated points and MBRs to DAP, who tests intersection and sets indicator vectors.
  • DSP inverts the shuffle, computes a denoising factor, removes perturbations, and reconstructs the set of result ciphertexts.
  • This process avoids reliance on heavy MPC, using authorized openings and homomorphic operations for practical performance.

4. Formal Security and Privacy Guarantees

SLS-INDEX's security is formally proven under the semantic security of Paillier encryption, PRF pseudorandomness, and oblivious shuffling:

  • A simulator using only values revealed by the leakage functions can produce simulated protocol transcripts indistinguishable from real executions.
  • Each stage—from index construction to update and query—preserves computational indistinguishability when replacing real values with random ones encrypted under fresh randomness.
  • The main result is that SLS-INDEX is nn0-secure in the two-server semi-honest setting, with negligible advantage for PPT adversaries.

5. Empirical Evaluation and Efficiency

Experiments for SLS-INDEX were conducted on synthetic (UNI, NOR, SKE) and real datasets (CAR, GOW) with up to nn1 two-dimensional points. Baseline comparisons included TRQEDnn2 and SRQnn3.

Metric SLS-INDEX TRQEDnn4 SRQnn5
Construction Time 125 s 90 s 40 s
Storage (for nn6) 120 MB (not specified) (not specified)
Query Latency (UNI) < 1 s 3–5 s 2–4 s
Query Latency (CAR/GOW) 2–3× faster than baselines — —
Recall nn7100% — —
  • Construction time is linear in nn8.
  • Storage overhead is nn9 ciphertexts.
  • Query Latency: For area=0.005%, queries complete in under 1 second for dd0, compared with 3–5 s (TRQEDdd1), 2–4 s (SRQdd2). On large real datasets (CAR, GOW), SLS-INDEX achieves 2–3× faster queries.
  • Communication: dd3 bits per query; accounts for 40–60% of latency.
  • Updates: Each insert or delete takes dd4 to rerandomize a leaf predictor.

A plausible implication is that the practical deployment of SLS-INDEX can result in substantial efficiency improvements for privacy-preserving spatial range queries in cloud settings, outperforming previous ciphertext-only approaches by a factor of two to three while retaining rigorous privacy properties.

6. Context, Limitations, and Significance

SLS-INDEX demonstrates that learned index structures, when combined with homomorphic encryption and secure protocol design, can offer both strong privacy guarantees and query performance suitable for interactive encrypted data analytics. By exposing only rigorously bounded leakage, SLS-INDEX prevents inference of dataset content, queries, individual results, or access patterns except for clearly defined volume and structure information.

  • The index accommodates efficient dynamic updates and scales with data dimensionality and dataset size.
  • Limitations include the cryptographic performance overhead intrinsic to public-key homomorphic encryption and the requirement of a two-server non-colluding model.
  • The introduction of bucket noise and secure point extraction protocols reduces information revealed via side channels.

The design principles underlying SLS-INDEX are likely to influence future research in encrypted database indexing and privacy-preserving spatial query processing (Wang et al., 3 Dec 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Secure Learned Spatial Index (SLS-INDEX).