Skip to content

Vigil: Accountable Liveness against Selective Silence

Jiawei Cheng, Huiping Sun, Rui Zhou, Jinjue Zhou, Zhong Chen

cs.DCarXiv:2609.18778

Abstract

BFT accountability is well understood for safety violations, and recent work attributes global liveness violations; recipient-selective silence remains unresolved. A selectively silent adversary withholds messages from some honest nodes while behaving correctly toward others. It can stall consensus yet evade every existing mechanism. We initiate a systematic study of accountability against selective silence. Negatively, a lone attacker silent toward at most f honest nodes is indistinguishable from an honest node, yielding a universal lower bound KSI f+1 on the silence identification threshold; moreover, any feedback-free repair after a silence-induced violation costs Θ(n3). Positively, Vigil, a Tendermint variant, matches these bounds with attack-adaptive forwarding, via bitmap cross-attestation, core-based membership, and challenge--response auditing. It pays O(n) authenticators per node when no selective silence occurs (plus Θ(n2) bitmap metadata bits per node), relays in proportion to the attack's width (sub-threshold silence can force up to n3/27 relays per view, a cost we price exactly), and majority-accuses any node silent toward more than a tunable resilience τA of honest peers (KSI = τA+1, optimal at τA = f). We also price the residual sub-threshold griefing surface exactly and extend identification to x-partial synchrony. Real-network experiments on a three-region WAN, together with a simulator held to exact equality with every closed form, confirm each threshold and cost: at 2\% loss, an f+1 accusation bar falsely accuses 91.2\% of honest nodes, while our majority bar accuses 0.002\%.

Create a lesson