Blockchains offer a decentralized and secure execution environment strong enough to host cryptocurrencies, but the state-replication model makes on-chain computation expensive. To avoid heavy on-chain workloads, systems like Truebit and optimistic rollups use challenge-based protocols, performing computations off-chain and invoking the chain only when challenged. This keeps normal-case costs low and, if at least one honest challenger exists, can catch fraud. What has been less clear is whether honest challengers are actually incentivized and a dishonest proposer is properly damaged under the worst case environment. We build a model with a colluding minority, heterogeneous costs, and three ordering modes. We then ask whether two goals can be met together: honest non-loss and fraud deterrence. Our results are clear: in single-winner designs, the incentive design is impossible or limited in scale. By contrast, in multi-winner designs, we obtain simple, explicit conditions under which both goals hold.
翻译:区块链提供了一个去中心化且安全的执行环境,其强度足以承载加密货币,但状态复制模型使得链上计算成本高昂。为了避免繁重的链上工作负载,诸如Truebit和乐观汇总等系统采用挑战型协议,将计算移至链下执行,仅在受到挑战时才调用链上验证。这使常态成本保持在较低水平,并且只要存在至少一个诚实的挑战者,就能发现欺诈行为。然而,此前尚不清楚的是:在最坏情况下,诚实的挑战者是否真正受到激励,以及不诚实的提议者是否受到应有的惩罚。我们构建了一个包含合谋少数派、异构成本和三种排序模式的模型,进而探讨两个目标能否同时实现:诚实方无损失与欺诈威慑。我们的结果明确表明:在单赢家设计中,激励设计要么不可能实现,要么在规模上受限。相比之下,在多赢家设计中,我们获得了简单且明确的条件,使得两个目标均可达成。