Dates are inconsistent

Dates are inconsistent

734 results sorted by ID

2026/1595 (PDF) Last updated: 2026-08-04
Budget Allocation in Neural Differential Distinguishers
Alireza Gholizadeh Shahrbejari, Reza Ebrahimi Atani
Attacks and cryptanalysis

Neural differential distinguishers are usually compared at a fixed number of labeled samples. However, different input representations may require different numbers of ciphertexts per sample, making fixed-sample comparisons potentially misleading from a cryptanalytic data-complexity perspective. In this paper, we study neural differential distinguishers under a fixed ciphertext budget. We ask whether the available encryption queries should be spent on more independent plaintext bases, or on...

2026/1549 (PDF) Last updated: 2026-07-29
The Cross-ratio Property and Its Use for Cryptanalysis of Round-reduced AES
Zhenzhen Bao, Jian Guo, Eik List, Haoyang Wang
Secret-key cryptography

In this work, we propose three techniques for advancing cryptanalysis of round-reduced AES, two of which exploit the multiplicative inverse, and a third, structural, property that generalizes the S-box switch to multiple quartets. Firstly, we formalize the cross-ratio property for tracing a nonlinear equation over $F_{2^8}$ from the differences of four distinct inputs or their respective outputs through the key-wrapped multiplicative inverse. While the underlying properties of the...

2026/1530 (PDF) Last updated: 2026-07-26
Rich Input Representations in Neural Differential Cryptanalysis: A Taxonomy and Survey
Alireza Gholizadeh Shahrbejari, Reza Ebrahimi Atani
Attacks and cryptanalysis

Neural differential distinguishers have become an active research direction in​ symmetric-key cryptanalysis since the introduction of deep-learning-based attacks on​ round-reduced SPECK. Early neural distinguishers typically used a single ciphertext pair​ or ciphertext difference as input. Recent studies, however, show that richer input​ representations can substantially affect the information available to the classifier, the data​ cost of each labeled sample, and the relevance of the...

2026/1527 (PDF) Last updated: 2026-07-25
Shuffling is Not Enough: Breaking Permutation-Based Model Confidentiality in Hybrid FHE Inference
Jiseung Kim, Hyung Tae Lee
Attacks and cryptanalysis

Hybrid fully homomorphic encryption (FHE) inference improves the practicality of private inference by letting the server evaluate linear layers homomorphically while the client decrypts and applies nonlinearities. Recent schemes attempt to protect model confidentiality by returning noisy, output-permuted responses and appealing to shuffle-model differential privacy (DP). We show that this protection fails in the correctness regime required by hybrid FHE systems. For a $d$-input linear layer,...

2026/1505 (PDF) Last updated: 2026-07-23
Conditional-Affine Redundant Clauses for SHA-256 Differential SAT
Jiqiang Feng, Kun Gao
Attacks and cryptanalysis

Standard Tseitin encodings of the SHA-256 nonlinear functions Ch and Maj can hide conditioned differential projections from Boolean Constraint Propagation (BCP). We materialize them as short, semantically redundant CNF clauses. A cofactor theorem characterizes all controlled differential linear forms; its implemented unit-vector specialization returns exactly all minimum-control projections, yielding four Ch and twelve Maj clauses per bit. The clauses preserve models, introduce no variables,...

2026/1456 (PDF) Last updated: 2026-07-16
QuantumScouter: Reinforcement Learning-Based Optimization of Variational Quantum Circuits for Differential Cryptanalysis
Gilsang Ahn, Jiwoo Baek, Donggun Lee, Insung Kim, Changmin Lee, Seokhie Hong, Dongjae Lee
Applications

Classical deep learning for differential cryptanalysis requires millions of ciphertext pairs, rendering attacks infeasible or easily detectable. This work overcomes this data limitation by introducing quantum differential distinguishers, enabling a practical attacker model where executing few queries is feasible. We design these distinguishers via quantum machine learning based on variational quantum circuits. To address circuit design challenges, we propose QuantumScouter, a reinforcement...

2026/1393 (PDF) Last updated: 2026-07-08
On the Differential Uniformity of Polynomials over Galois Rings
Sondre Rønjom, Arne Sandrib
Foundations

Design of hash functions and pseudo-random permutations over Galois extensions of $\mathbb Z_q$ for prime powers $q$ has recently gained some interest in relation to recent directions in advanced cryptography, such as multiparty computation and zero-knowledge protocol design. Thus investigating optimality of cryptographic properties of S-boxes defined by polynomials over Galois rings is of interest. Of particular interest is the differential uniformity of such functions. To our knowledge,...

2026/1303 (PDF) Last updated: 2026-06-22
Subspace Differential Uniformity
Sondre Rønjom, Arne Sandrib, Joakim Sunde
Secret-key cryptography

The main contribution of this paper is to introduce Subspace Differential Uniformity (SDU) for S-boxes and block ciphers. The SDU is essentially a measure of how well any function spreads input differences clustered in affine subspaces away from affine clusters in output differences. We provide some lower bounds for the SDU and describe an efficient algorithm for computing the SDU. Moreover, we provide results for some popular classes of S-boxes up to $n=8$.

2026/1193 (PDF) Last updated: 2026-07-27
Cryptanalytic Properties of Mealy Machines
Zhongfeng Niu, Tim Beyne, Kai Hu, Meiqin Wang
Secret-key cryptography

This paper proposes a systematic approach to compute cryptanalytic properties of arbitrary Mealy machines or S-functions. Based on the geometric approach to cryptanalysis, we provide a uniform formula for any cryptanalytic property of such a function, as long as the property is compatible with the way its input and output are split into chunks. Examples include linear, (quasi) differential, (ultrametric) integral, differential-linear, and boomerang properties. To illustrate our results,...

2026/1162 (PDF) Last updated: 2026-06-03
Finer-Grained Fixed-Key Differential Probability Distributions via Quasidifferential Decoupling
Kai Hu, Thomas Peyrin, Quan Quan Tan, Hongyi Zhang, Chunning Zhou
Attacks and cryptanalysis

The recent study of fixed-key differential probabilities mainly follows two complementary approaches. The first derives key-dependent constraints from the internal structure of the primitive. This approach is intuitive, but a complete theory is difficult to build. The second approach is based on quasidifferentials. It is complete in theory when all quasidifferentials are considered, but exhaustive enumeration is usually infeasible in practice. In this paper, we relate quasidifferentials to...

2026/1158 (PDF) Last updated: 2026-06-09
A Geometric Approach to Quantum Distinguishers
Zhili Wu, Zhenzhen Bao
Attacks and cryptanalysis

This paper introduces a geometric framework for Q2 quantum distinguishers by combining the geometric approach to classical symmetric-key cryptanalysis with the generalized correlation extraction algorithm. Our main technical tool shows that one superposition query, followed by appropriate (unitary) change-of-basis operations, prepares a ``correlation state'' whose amplitudes are the entries of the geometric correlation matrix in the chosen basis. This yields a unified preparation-measurement...

2026/875 (PDF) Last updated: 2026-05-05
Comparative Performance Analysis of MILP Solvers for Cryptanalysis
Halil İbrahim Kaplan
Attacks and cryptanalysis

This paper provides a performance comparison of five MILP solvers applied to related-key differential cryptanalysis of ITUbee [10]. We evaluate three open-source solvers (GLPK, HiGHS, SCIP) and two commercial solvers (Gurobi, CPLEX) using MILP models for 8, 10, and 12-round attacks. As rounds increase, the number of equations and con- straints grows exponentially. Experiments used an 11th Gen Intel Core i7-1165G7 processor with 32 GB of RAM. Commercial solvers (Gurobi and CPLEX)...

2026/856 (PDF) Last updated: 2026-07-01
MERIDIAN: A Toroid-Inspired Permutation Block Cipher for Constrained Environments
Basker Palaniswamy, Paolo Palmieri, Ashok Kumar Das
Foundations

We introduce MERIDIAN, a 128-bit block cipher designed for resource-constrained environments as a lightweight alternative to AES-128. MERIDIAN retains the AES-128 interface, including a 128-bit block, 128-bit key, and 4×4 byte state, while reusing the standard AES S-box. This enables compatibility with existing AES-128 modes such as ECB, CBC, CFB, OFB, CTR, XTS, CMAC, CCM, and GCM, and allows implementations to reuse established S-box ROMs and GF(28) inverse circuits. The cipher is based on...

2026/775 (PDF) Last updated: 2026-04-20
Differential and Linear Cryptanalysis of Modular Addition
Halil İbrahim Kaplan, Ali Doğan, Gökçe Yetişer
Secret-key cryptography

This paper presents a comprehensive analysis of modular addition from a cryptanalytic perspective, focusing on both linear and differential cryptanalysis techniques. We examine the probability distribution of carry bits in modular addition operations and demonstrate how these probabilities affect linear approximations. The paper provides detailed algorithms for constructing Linear Approximation Tables (LAT) and Difference Distribution Tables (DDT) for modular addition operations, along with...

2026/748 (PDF) Last updated: 2026-05-26
Related-Key Multi-Pair Neural Distinguishers: Analysis and Applications to Lightweight Block Ciphers
Thanh-Phong Nguyen, Nguyen Tan Cam, Van-Than Huynh, Hieu-Minh Nguyen
Attacks and cryptanalysis

Neural differential cryptanalysis has recently been extended to related-key and multi-pair settings, enabling neural distinguishers to aggregate weak statistical biases across multiple ciphertext pairs. However, the statistical origin of the exploited signal remains insufficiently understood. In this work, we present a signal-centric analysis of related-key, multi-pair neural distinguishers across four block ciphers: PRESENT-80, SIMECK-32/64, LEA-128, and HIGHT. We characterize ciphertext...

2026/696 (PDF) Last updated: 2026-04-08
A Key Schedule Design and Evaluation under Boundary Round-Key Leakage
Yu Morishima, Hideki Yoshikawa, Masahiro Kaminaga
Secret-key cryptography

We study key-schedule design under boundary round-key leakage, namely leakage of the first round key, the last round key, or both end round keys. We propose the nonlinear key-schedule $\mathrm{RK}_i = K \oplus F\bigl(K \oplus T(i)\bigr)$, where $K$ is the master key, $T(i)$ is a public domain separation value, and $F$ is a public SPN-based permutation parameterized by its round count $N_F$. Under the boundary-leakage model considered in this paper, leakage of one end round key yields an...

2026/535 (PDF) Last updated: 2026-03-17
Improved Related-Key Differential Neural Distinguishers for SPN Block Ciphers
Chuchu Ge, Qichun Wang
Attacks and cryptanalysis

Related-key differential neural distinguishers have recently attracted increasing attention in block-cipher cryptanalysis, yet their construction still relies heavily on cipher-specific manual design. In this paper, we study the systematic construction of related-key differential neural distinguishers for lightweight substitution–permutation network (SPN) block ciphers and propose a unified framework covering difference selection, dataset construction, network architecture, and training and...

2026/501 (PDF) Last updated: 2026-04-28
More Brisés in Ballet: Extending Differential and Linear Cryptanalysis
Emanuele Bellini, Gabriele Bellini, Alessandro De Piccoli, Michela Gallone, David Gerault, Yun Ju Huang, Paul Huynh, Matteo Onger, Simone Pelizzola, Andrea Visconti
Attacks and cryptanalysis

In this work, we present new cryptanalytic results on the Ballet block cipher family, a simplified Lay-Massey ARX construction with a linear key schedule, winner of the symmetric algorithm category in the 2018–2020 Chinese National Cryptographic Algorithm Competition. Despite winning the competition, the cipher has received limited attention outside the Chinese Association for Cryptologic Research (CACR) community. We provide the first classical key recovery attacks in the literature, new...

2026/328 (PDF) Last updated: 2026-03-17
NeuralCPA: A Deep Learning Perspective on Chosen-Plaintext Attacks
Xuanya Zhu, Liqun Chen, Yangguang Tian, Gaofei Wu, Xiatian Zhu
Attacks and cryptanalysis

A Chosen-Plaintext Attack (CPA) is a cryptographic analysis game for encryption, where an adversary queries an encryption oracle with plaintexts and observes the mapping to their ciphertexts. At an arbitrary time, it provides two challenge plaintexts but receives only one ciphertext, and finally guesses which of the two challenge plaintexts has been encrypted. Neural distinguishers, as a powerful representative of Artificial Intelligence (AI) methods, have been recently used in cryptographic...

2026/305 (PDF) Last updated: 2026-02-18
Quantum Truncated Differential Attacks using Convolutions
Aurel Pichollet--Mugnier, André Schrottenloher
Attacks and cryptanalysis

This paper focuses on quantum key-recovery attacks on block ciphers. Previous works on quantum differential and truncated differential attacks like [Kaplan et al., ToSC 2016] have shown that classical algorithms for key-recovery, typically based on generating differential pairs and sieving them, can be accelerated by up to a quadratic speedup using variants of quantum search, quantum amplitude amplification, and quantum collision-finding. In this paper, we introduce a new quantum...

2026/296 (PDF) Last updated: 2026-02-18
Navigating the Deep: End-to-End Extraction on Deep Neural Networks
Haolin Liu, Adrien Siproudhis, Samuel Experton, Peter Lorenz, Christina Boura, Thomas Peyrin
Attacks and cryptanalysis

Neural network model extraction has recently emerged as an important security concern, as adversaries attempt to recover a network’s parameters via black-box queries. Carlini et al. proposed in CRYPTO’20 a model extraction approach inspired by differential cryptanalysis, consisting of two steps: signature extraction, which extracts the absolute values of network weights layer by layer, and sign extraction, which determines the signs of these signatures. However, in practice this...

2026/224 (PDF) Last updated: 2026-02-17
Usage of Mixed Integer Linear Programming in Cryptanalysis of Block Ciphers
Halil İbrahim Kaplan
Attacks and cryptanalysis

This paper presents a comprehensive approach to the cryptanalysis of block ciphers using Mixed Integer Linear Programming (MILP). By formulating the cipher’s components including substitution boxes, linear layers, and key schedules as systems of linear inequalities, MILP enables the automated discovery of optimal cryptanalytic characteristics. Our methodology is demonstrate the MILP modelling through the analysis of the ITUbee cipher under three attack models: differential, linear, and...

2026/121 (PDF) Last updated: 2026-01-25
Integrating Boomerang into TAGADA
Rocco Brunelli, Marine Minier, Loïc Rouquette
Attacks and cryptanalysis

Since 2009, the cryptographic community has its eyes fixed on automatic tools based on solvers to help the cryptanalysts trying to attack symmetric cryptographic schemes. Among those automatic tools, TAGADA is dedicated to search for a particular kind of cryptanalysis called differential cryptanalysis. It is of major importance for the cryptographic community to have automatic tools dedicated to the analysis of security of symmetric key primitives to be convince about what symmetric key...

2025/2334 (PDF) Last updated: 2025-12-29
Moving a Step of ChaCha in Syncopated Rhythm (Extended Version)
Shichang Wang, Meicheng Liu, Shiqi Hou, Chengan Hou, Dongdai Lin
Attacks and cryptanalysis

The stream cipher ChaCha is one of the most widely used ciphers in the real world, such as in TLS, SSH and so on. In this paper, we study the security of ChaCha via differential cryptanalysis based on probabilistic neutral bits (PNBs). We introduce the syncopation technique for the PNB-based approximation in the backward direction, which significantly amplifies its correlation by utilizing the property of ARX structure. In virtue of this technique, we present a new and efficient method for...

2025/2291 (PDF) Last updated: 2026-06-12
Key Recovery Attacks on ZIP Ciphers: Application to ZIP-AES and ZIP-GIFT
Marcel Nageler, Debasmita Chakraborty, Simon Scherer, Maria Eichlseder
Attacks and cryptanalysis

The construction of building beyond-birthday-bound secure pseudorandom functions (PRFs) from the Xor-sum of 2 pseudorandom permutations (PRPs) has been known since EUROCRYPT 1998. However, the first concrete instance was only published recently at FSE 2022: the low-latency PRF Orthros. Subsequently, at ASIACRYPT 2024, Flórez-Gutiérrez et al. proposed the general framework of ZIP ciphers, where a block cipher $E_{1} \circ E_{0}$ is used to construct the PRF $E_{0} \oplus E_{1}^{-1}$. They...

2025/2282 (PDF) Last updated: 2026-02-24
When Simple Permutations Mix Poorly: Limited Independence Does Not Imply Pseudorandomness
Jesko Dujmovic, Angelos Pelecanos, Stefano Tessaro
Secret-key cryptography

Over the past two decades, several works have used (almost) $k$-wise independence as a proxy for pseudorandomness in block ciphers, since it guarantees resistance against broad classes of statistical attacks. For example, even the case $k = 2$ already implies security against differential and linear cryptanalysis. Hoory, Magen, Myers, and Rackoff (ICALP ’04; TCS ’05) formulated an appealing conjecture: if the sequential composition of $T$ independent local randomized permutations is...

2025/2205 (PDF) Last updated: 2025-12-06
ML-Guided Beam Search for Differential Trail Discovery in SPN Ciphers: A Case Study on GIFT-64
Alireza Gholizadeh Shahrbejari, Reza Ebrahimi Atani
Attacks and cryptanalysis

This paper introduces an ML-guided scoring heuristic for differential trail beam search in substitution--permutation network (SPN) ciphers. Instead of replacing classical search procedures or relying on heavy learning architectures, we take a residual-learning approach: a gradient boosting regressor is trained to predict the error of a simple nibble-count lower bound on the remaining trail cost. At search time, the predicted residual is fused multiplicatively into the beam scoring function,...

2025/2161 (PDF) Last updated: 2026-05-10
Attacks and Remedies for Randomness in AI: Cryptanalysis of PHILOX and THREEFRY
Jens Alich, Thomas Eisenbarth, Hosein Hadipour, Gregor Leander, Felix Mächtle, Yevhen Perehuda, Shahram Rasoolzadeh, Jonas Sander, Cihangir Tezcan
Applications

In this work, we address the critical yet understudied question of the security of the most widely deployed pseudorandom number generators (PRNGs) in AI applications. We show that these generators are vulnerable to practical and low-cost attacks. With this in mind, we conduct an extensive survey of randomness usage in current applications to understand the efficiency requirements imposed in practice. Finally, we present a cryptographically secure and well-understood alternative, which has a...

2025/2149 (PDF) Last updated: 2026-02-24
Weak Tweak-Key Analysis Of Blink Via Superbox
Shiyao Chen, Jian Guo, Tianyu Zhang
Attacks and cryptanalysis

This work presents the first third-party cryptanalysis of \textsf{Blink}, a recent tweakable block cipher built on the Three-Hash Framework with a long-key design. Leveraging the idea of Superbox, we develop a lightweight theoretical model capturing the value correlations, weak-key conditions, fixed-key probabilities and the local clustering behaviors inside a \textsf{Blink} Superbox when the value spaces are affine. This model is intended as a concrete, easy-to-follow specialization of...