-
1982 – 1986
Cryptographic foundations
Probabilistic encryption and the definition of semantic security; digital signatures secure against adaptive chosen-message attack; and pseudorandom functions indistinguishable from truly random ones, built from any one-way function. These are the definitions the field still uses.
Goldwasser–Micali, JCSS 1984 · Goldwasser–Micali–Rivest, SICOMP 1988 · Goldreich–Goldwasser–Micali, JACM 1986
-
1985 – 1988
Probabilistic and interactive proof systems
Zero-knowledge interactive proofs, now the mechanism behind verified smart contracts, and multi-prover interactive proofs, later shown equivalent to probabilistically checkable proofs and central to the quantum result MIP* = RE. Gödel Prize, 1993.
Goldwasser–Micali–Rackoff, SICOMP 1989 · Ben-Or–Goldwasser–Kilian–Wigderson, STOC 1988
-
1988
Information-theoretically secure multi-party computation
Unconditionally secure protocols for general multi-party computation, assuming only secure channels between pairs of users. Because their efficiency does not degrade with the difficulty of a hardness assumption, these remain the backbone of MPC as it is actually deployed.
Ben-Or–Goldwasser–Wigderson, STOC 1988
-
1986
Primality proving
Elliptic curves used to construct the most succinct NP proofs of primality known, and, at the time, the first primality proof finder running in expected polynomial time.
Goldwasser–Kilian, JACM 1999
-
1992 – 1998
Hardness of approximation
Connected the complexity of multi-prover proofs to the intractability of approximating NP-hard problems, opening the decade of work that produced the PCP theorem — and, in the other direction, limited the approximate hardness of the shortest and closest vector problems on lattices by placing them in AM ∩ coAM.
Feige–Goldwasser–Lovász–Safra–Szegedy, JACM 1996 · Goldreich–Goldwasser, JCSS 2000
-
1998 – 2000
Combinatorial property testing
Founded graph and combinatorial property testing — deciding global properties of enormous objects from a handful of queries. Now a field with its own conferences and workshops. Gödel Prize, 2001.
Goldreich–Goldwasser–Ron, JACM 1998 · Goldreich–Goldwasser–Lehman–Ron–Samorodnitsky, Combinatorica 2000
-
2008
Delegating computation
Doubly efficient delegation for NC computations, in which the honest prover costs roughly what the computation itself costs. Since reduced to practice in several implementations.
Goldwasser–Kalai–Rothblum, JACM 2015 (STOC 2008)
-
2009 – 2012
Leakage resilience
Launched the theoretical study of encryption, authentication, and secure computation that stay secure when private keys partially leak, so long as some entropy remains hidden.
Akavia–Goldwasser–Vaikuntanathan, TCC 2009 · Boyle–Goldwasser–Jain–Kalai, STOC 2012 · Goldwasser–Rothblum, SICOMP 2015
-
2011 – 2021
Pseudo-determinism
Probabilistic algorithms for search problems that return the same solution on the same input whatever randomness they draw — achieved for perfect matching in NC, and extended to streaming and to interactive proofs in which a prover helps a verifier find a provably canonical solution. Because outputs are almost independent of the randomness, that randomness can be recycled. A question posed in this line was recently settled by a pseudo-deterministic construction of large primes.
Gat–Goldwasser 2011 · Goldwasser–Grossman, ICALP 2017 · Goldwasser–Grossman–Holden, ITCS 2018 · Goldwasser–Grossman–Mohanty–Woodruff, ITCS 2020 · Goldwasser–Impagliazzo–Pitassi–Santhanam, CCC 2021
-
2026
Sum-Check Protocol for Approximate Computations
with Dor Bitan, Zachary DeStefano, Yuval Ishai, Yael Tauman Kalai and Justin Thaler · Eurocrypt — Carrying verification over to computation on real numbers rather than finite fields.
-
2026
Private Proofs of When and Where
with Uma Girish, Greg Gluch, Tal Malkin, Leo Orshansky and Henry Yuen · CRYPTO
-
2026
The Computational Intractability of Filtering for AI Alignment
with Sarah Ball, Greg Gluch, Frauke Kreuter, Omer Reingold and Guy Rothblum · ICLR — Why safety filters built outside the model cannot work.
-
2026
Learning Randomized Reductions and Program Properties
with Ferhat Erata, Orr Paradise, Timos Antonopoulos, ThanhVu Nguyen and Ruzica Piskac · ICML — Spotlight
-
2026
Efficient Public Verification of Private ML via Regularization
with Zoë Ruha Bell, Anvith Thudi, Olive Franzese-McLaughlin and Nicolas Papernot · ICML
-
2026
Proofs of Ownership for Machine Learning Models
with Ran Canetti and Or Zamir · Preprint
-
2026
Investigating the Development of Task-Oriented Communication in Vision-Language Models
with Boaz Carmeli, Orr Paradise, Yonatan Belinkov and Ron Meir · Preprint
-
2025
A Theory for Worst-Case vs. Average-Case Guarantees for LLMs
with Noga Amit, Orr Paradise and Guy Rothblum · NeurIPS — Self-proving models: training a model to accompany each answer with an interactive proof of its correctness, so the guarantee holds for the input in front of you rather than on average.
-
2025
Oblivious Defense in ML Models: Backdoor Removal Without Detection
with Jonathan Shafer, Neekon Vafa and Vinod Vaikuntanathan · STOC — The counterpart to the undetectability result: backdoors whose effects can be removed even though they cannot be found.
-
2025
Unsupervised Translation of Emergent Communication
with Ido Levy, Orr Paradise, Boaz Carmeli, Ron Meir and Yonatan Belinkov · AAAI — Translating a code that a population of agents invented for itself.
-
2025
A Cryptographic Perspective on Mitigation vs. Detection in Machine Learning
with Greg Gluch · Preprint — Detecting an adversarial input and repairing it are equivalent for classification, and provably are not for generation.
-
2024
Certifying Private Probabilistic Mechanisms
with Zoë Ruha Bell, Michael P. Kim and Jean-Luc Watson · CRYPTO — Proving that a mechanism really did add the randomness it claims.
-
2023
Collaborative Privacy-Preserving Analysis of Oncological Data Using Multiparty Encryption
with R. Geva and colleagues · PNAS — Encrypted analysis at clinical scale.
-
2022
Planting Undetectable Backdoors in Machine Learning Models
with Michael P. Kim, Vinod Vaikuntanathan and Or Zamir · FOCS — A backdoor that cannot be found without breaking cryptography, even given full access to the predictor.
-
2022
Deniable Encryption in a Quantum World
with Andrea Coladangelo and Umesh Vazirani · STOC — Quantum encryption makes coercion impossible even before the message is sent.
-
2022
Verification Dilemmas in Law and the Promise of Zero-Knowledge Proofs
with Kenneth Bamberger, Ran Canetti, Rebecca Wexler and Evan Zimmerman · Berkeley Technology Law Journal
-
2022
Using Zero-Knowledge to Reconcile Law Enforcement Secrecy and Fair Trial Rights
with Dor Bitan, Ran Canetti and Rebecca Wexler · CSLAW — A working prototype, built on real cases.
-
2021
Interactive Proofs for Verifying Machine Learning
with Guy Rothblum, Jonathan Shafer and Amir Yehudayoff · ITCS — PAC verification: checking an untrusted learner’s hypothesis with far less data than training took.
-
2021
Universal Adaptability: Target-Independent Inference That Competes with Propensity Scoring
with Michael P. Kim, Christoph Kern, Frauke Kreuter and Omer Reingold · PNAS — Statistical inference without random samples of the target population, via multi-calibration.
-
2020
Beyond Perturbations: Learning Guarantees with Arbitrary Adversarial Test Examples
with Omar Montasser, Adam Kalai and Yael Tauman Kalai · NeurIPS — Classifiers that may abstain, with no restriction on the test distribution.
-
2020
Formalizing Data Deletion in the Context of the Right to Be Forgotten
with Sanjam Garg and Prashant Nalini Vasudevan · Eurocrypt — A mathematical statement of a GDPR provision, and ways to satisfy it.
-
2020
Secure Large-Scale Genome-Wide Association Studies Using Homomorphic Encryption
with Marcelo Blatt, Alexander Gusev and Yuriy Polyakov · PNAS
-
2018
Practical Accountability of Secret Processes
with Jonathan Frankle, Sunoo Park, Daniel Shaar and Daniel Weitzner · USENIX Security — Accountable electronic surveillance at the scale of the federal court system.
-
2015
Machine Learning Classification over Encrypted Data
with Raphael Bost, Raluca Ada Popa and Stephen Tu · NDSS — The first treatment of ML classification on encrypted inputs.
Project CETI
Listening to sperm whales
Shafi Goldwasser leads the theoretical analysis group of the Cetacean Translation Initiative, a nonprofit founded in 2020 that applies machine learning, robotics, and underwater acoustics to record and interpret the communication of sperm whales, working from a field site in Dominica.
The theoretical question is what makes translation possible at all when there is no parallel corpus, no bilingual speaker, and very little shared world between the two parties — which conditions must hold for the problem to be solvable, and how much data any method would need. The answers depend on what the recordings actually contain, so the theoretical work runs alongside the acoustic and behavioural analysis coming off the water in Dominica.