International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News

If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.

Here you can see all recent updates to the IACR webpage. These updates are also available:

email icon
via email
RSS symbol icon
via RSS feed

08 May 2026

Shweta Agrawal, Kaartik Bhushan, Geoffroy Couteau, Mahshid Riahinia
ePrint Report ePrint Report
Public-key pseudorandom correlation functions (PK-PCF) are an exciting recent primitive introduced to enable "non-interactive key exchange for secure computation". Despite significant advances in the group-based setting, success in the post-quantum regime has been much more limited. To the best of our knowledge, there does not exist even a single efficient candidate post-quantum PK-PCF for the standard string oblivious transfer (OT) correlation. In this work, we address this gap by constructing the first efficient lattice-based public-key PCF for the string OT correlation. Our PK-PCF generates a few hundred OTs per second, and requires a large but manageable public key size (a few hundred megabytes). In contrast, the only previous lattice-based non-public-key PCF, proposed in the very recent work of Hasler, Reisert and Küsters (Asiacrypt 2025), can generate up to 9 OT/s and has key sizes of several gigabytes. At the heart of our result lie several technical contributions that might be of independent interest. In particular, we introduce the first efficient lattice-based constrained pseudorandom functions for low-degree polynomials, from a new but natural "secret-power" variant of ring learning with errors. Our assumption is non-interactive and falsifiable, and we carefully analyze it for attacks. Additionally, we introduce a new packing mechanism compatible with local rounding of noisy shares from a "truncated" variant of our previous assumption, which allows further efficiency. We remark that in the pre-quantum regime, the state of art for PK-PCF only two years ago was 1 OT/s, while they now clock at ~30k OT/s. We are optimistic that our construction will follow a similar trajectory.
Expand
Daniel Aronoff, Nut Chukamphaeng, Phoochit Witchutanon, Samiran Chanseewong, Koravich Sangkaew, Tutanon Sinthupraisth
ePrint Report ePrint Report
Credit scoring plays a critical role in the financial industry, allowing institutions to evaluate the creditworthiness of potential borrowers. Typically, a model is estimated from repositories of attributes of past borrowers linked to their loan and payments performance. The model is then used to compute an applicant's score. The training and customer data are subject to regulations that require privacy of financial records. This creates a tension between the full utilization of available data and the prevention of leakage. Recently, the tension has intensified from, on one hand, improvement in AI methods to utilize data from nontraditional sources to develop prediction models and, on the other hand, increased concern over the vulnerability of encrypted data to penetration from quantum computers. We present a credit score workflow that addresses both issues by using AI methods to estimate a credit score model in a collaborative setting, combined with post-quantum cryptographic methods to protect data. We develop a ``toy'' workflow which can form a base for more complex ``real world'' implementations. We provide links to a code-base.
Expand
Halil İbrahim Kaplan
ePrint Report ePrint Report
This paper provides a performance comparison of five MILP solvers applied to related-key differential cryptanalysis of ITUbee [10]. We evaluate three open-source solvers (GLPK, HiGHS, SCIP) and two commercial solvers (Gurobi, CPLEX) using MILP models for 8, 10, and 12-round attacks. As rounds increase, the number of equations and con- straints grows exponentially. Experiments used an 11th Gen Intel Core i7-1165G7 processor with 32 GB of RAM. Commercial solvers (Gurobi and CPLEX) perform better than open-source options, achieving up to 94× speedup compared to GLPK for the 12-round model. This work provides guidance for choosing a solver for MILP-based cryptanalysis.
Expand
Rio Kanehiro, Yohei Watanabe, Mitsugu Iwamoto
ePrint Report ePrint Report
Proof of Assets (PoA) protocols enable custodians to prove ownership of digital assets without revealing their account addresses or corresponding balances. While existing PoA protocols focused on either private or public balances, hybrid-state blockchains such as the Aztec Network involve both. In these systems, private balances are managed by encrypted notes that work similarly to the UTXO model, with only commitments stored on-chain. We present a PoA protocol that supports hybrid balances by combining public-state membership proofs with proofs of ownership over private notes. Since a custodian may control multiple accounts and numerous notes, we employ hierarchical proof-carrying data via recursive zk-SNARK, enabling scalable proving and efficient batch verification. We implement our system using the Noir DSL with the UltraHonk proving backend, and evaluate the performance.
Expand
Adrian Cinal, Oliwer Sobolewski
ePrint Report ePrint Report
An adaptor signature scheme can be seen as committing to a signature using an NP statement, in such a way that (1) the commitment, called a presignature, is verifiable, (2) the corresponding witness enables opening the commitment (adapting the presignature), and (3) seeing a valid commitment-opening (presignature-signature) pair leaks the witness. In the blockchain space, where signatures (signed transactions) must be broadcast to the public to take effect, this last property allows "forcing" a party to leak a witness for possibly multiple presignatures issued for the same NP statement. This then gives rise to many applications such as atomic swaps or payment channels. Importantly, in prevailing adaptor signature schemes, presignatures are already technically signatures, in that they are non-interactive zero-knowledge proofs of knowledge of the signing key. This has a number of consequences, most important being that the presignature constitutes evidence of intent to participate in a protocol based on adaptor signatures. Perhaps surprisingly, however, for practical applications, this strong "binding" of presignatures turns out to be non-essential. In this work, we revisit the definitions of adaptor signature schemes, demonstrating that prevailing security requirements are too strict for practical applications. To this end, we formally define fair signature exchange (FSE) and abandon the assumption implicit in prior work that adaptor-based FSE must be "symmetric" with both parties using the same adaptor signature scheme. The resulting relaxation of security requirements leads us to the notion of presignature deniability, an extension to adaptor signature schemes that we define formally and construct from various assumptions.
Expand
Adrian Cinal
ePrint Report ePrint Report
Anonymity guarantees of privacy-oriented cryptocurrencies are garnering negative attention from lawmakers who view them as antinomic to accountability. Having recognized their potential for innovation, however, regulators may not want to outright ban privacy coins but instead seek a middle ground where financial oversight is effective, and still a modicum of privacy is maintained. Mature designs, such as Zcash, Monero, or Firo, facilitate this through so-called viewing keys that can be disclosed to third parties for the purpose of supervision. This paper initiates the study of the issues of security, privacy, and fungibility that privacy coins face in the non-custodial setting with the legal obligation on users to surrender their viewing keys to the authorities. In doing so, it fills the gap in provable anonymity guarantees for Zcash and, at the same time, exposes non-trivial gaps for Monero and Firo. Of independent interest is that the naturally defined notion of spend indistinguishability is shown to imply practical anamorphic spending as introduced by Cinal et al. (ESORICS'25), and a novel perspective is presented, framing UTXO-based privacy coins under viewing key compromise as transparent account-based cryptocurrencies instead.
Expand
Md Saidul Islam, Syed Mohammed Shamsul Islam, Md Zakir Hossain, Mohiuddin Ahmed, Iqbal H. Sarker
ePrint Report ePrint Report
The rapid adoption of blockchain-based financial systems has been accompanied by a surge in illicit activities, including money laundering, ransomware payments, phishing scams, and terrorist financing, necessitating robust anomalous transaction detection mechanisms. Detecting anomalies in cryptocurrency transactions is critical, as undetected illicit activity can result in significant economic losses and undermine trust in digital financial systems. This systematic review examines the state-of-the-art in cryptocurrency anomaly detection, with particular focus on methodological developments between 2008 and December 2025. A PRISMA-guided systematic literature search was conducted across IEEE Xplore, Scopus, Web of Science, ACM Digital Library, Google Scholar, and SpringerLink. From an initial set of 450 records, 32 empirical studies were selected after rigorous screening and eligibility assessment and included in the qualitative synthesis. Unlike prior surveys, this review provides a focused synthesis of empirical cryptocurrency transaction studies, a taxonomy of anomaly types, and a critical assessment of dataset bias and evaluation practices. The literature reveals a clear methodological shift from traditional feature-engineered machine learning approaches (e.g., Random Forest, XGBoost, and Support Vector Machines) toward graph-based deep learning architectures. Graph Neural Networks (GNNs), particularly Graph Convolutional Networks (GCNs) and Graph Attention Networks (GATs), demonstrate competitive performance by capturing relational dependencies among blockchain addresses, while temporal graph models and hybrid GNN–transformer architectures enhance the detection of evolving, multi-hop laundering schemes. Unsupervised and semi-supervised approaches address the challenge of limited labeled data but introduce trade-offs in interpretability. Emerging research directions include privacy-preserving federated learning and cross-chain detection frameworks. Despite some studies reporting accuracies exceeding 90%, the field faces several limitations, including dataset bias, lack of standardized multi-chain benchmarks, inconsistency in evaluation metrics, limited adversarial robustness testing, scalability constraints, and insufficient explainability for regulatory compliance. This review aims to provide researchers and practitioners with a structured synthesis of current methodologies, a comprehensive taxonomy of anomalies, and a detailed roadmap for transitioning from experimental validation to real-world, scalable deployment.
Expand
Andrea Flamini, Karla Friedrichs, Jonathan Katz, Watson Ladd, Anja Lehmann, Marek Sefranek
ePrint Report ePrint Report
Anonymous-credential (AC) schemes equip users with credentials on attested attributes such that users can later prove possession of a credential certifying (a subset of) those attributes without revealing anything else. In standard AC schemes, such proofs reveal the issuer of the credential, which may be more information than intended or necessary. Lately, there has been significant interest in designing stronger issuer-hiding anonymous-credential schemes that only reveal that the user has a credential from an issuer in a certain policy set.

Katz and Sefranek recently showed how to add issuer hiding to BBS-based anonymous credentials. However, their scheme requires per-verifier policy keys with corresponding secret keys needed for verification; this means proofs are no longer publicly verifiable, and may pose a barrier to practical deployment. As another drawback, security of their scheme relies on the generic group model (GGM).

In this work, we propose a template for constructing issuer-hiding, BBS-based anonymous credentials that does not require policy keys and whose security can be reduced to security of the BBS signature scheme (in particular, without relying on the GGM). At the core of our template is a technique to randomize BBS public keys and adapt signatures accordingly, which we show also has applications to tight multi-user security of BBS signatures. We design, implement, optimize, and experimentally compare various instantiations of our template that offer tradeoffs in proving time, verification time, and proof size. All instantiations offer good performance for policy sets of up to 64 issuers.
Expand
Ge Gao, Haining Yu, Yue Sun, Zhongyun Hua
ePrint Report ePrint Report
Trustworthy federated learning requires both update privacy and aggregate integrity. While secure aggregation protects the confidentiality of client updates, it does not prevent a malicious server from tampering with the final aggregate. Existing verifiable schemes typically address this limitation by introducing separate integrity-verification layers, such as zero-knowledge proofs, homomorphic hashes, and commitmentbased mechanisms. However, these approaches either require clients to remain online after uploading their updates for additional verification or recovery procedures, or incur substantial computation overhead that scales linearly with the model dimension. To address these limitations, we propose SealAgg, a one-shot verifiable secure aggregation framework that simultaneously guarantees update confidentiality and aggregate integrity against a malicious server. SealAgg allows clients to disconnect immediately after uploading their updates and introduces an aggregatenative auditing mechanism that enables lightweight integrity verification without a separate costly verification pipeline. Specifically, each client embeds dual hidden finite-field linear projections and a context-binding heartbeat value into its update before encryption, so that the audit material is co-aggregated with the gradients along the same path. Moreover, we design an asymmetric three-server architecture that confines integrity validation entirely to the server side, thereby fully supporting one-shot client participation. We provide formal analyses of the correctness and security of SealAgg. Extensive experiments show that SealAgg achieves practical end-to-end efficiency, incurs only a small auditing overhead relative to the total cost, and outperforms state-of-the-art schemes.
Expand
Jasmin Zalonis, Frederik Armknecht, Linda Scheu-Hachtel
ePrint Report ePrint Report
We address the question of realizing privacy preserving analysis of user data. The abstract scenario considered is that an analyst aims to evaluate a function $f$ on some user data $X$. To achieve comprehensive privacy, it is necessary to protect the input $X$ directly. However, it is known that $f(X)$ may leak too much information about $X$ as well. A common approach to mitigate such risks is to make the computation differentially private. In practice, this is often accomplished by replacing $f$ by a noisy variant $f^*$.

We investigate the use of multi-input functional encryption (MIFE) for achieving input and output privacy in one cryptographic mechanism. In an MIFE scheme, a setup authority can generate restricted decryption keys which enable to learn specific functions of encrypted messages, without revealing any additional information. To achieve differential privacy in this process, we introduce as a new cryptographic primitive: noisy multi-input functional encryption (NMIFE). It extends the concept of MIFE such that the decryption key may also encode a noisy function where the noise value is secret.

While the change from MIFE to NMIFE is rather straightforward, the challenge is to come up with precise and workable definitions of correctness and security that we propose and explain in this work. Here, the security definition is tailored to the use case of differential privacy. As it is a special case of the established notion of full-hiding security, we present a generic transformation that enables turning any full-hiding MIFE scheme into a secure NMIFE scheme that has practically the same performance as the initial MIFE scheme.

Moreover, we make use of the fact that the proposed security definition is less restrictive and present a new concrete NMIFE scheme for evaluating the inner product. It is dubbed DiffPIPE (short for DIFFerentially Private Inner Product Evaluation). DiffPIPE is not the result from the transformation and outperforms all from existing full-hiding MIFE schemes constructed NMIFE schemes. In experiments, we demonstrate its applicability for realizing privacy preserving counting queries on data sets.
Expand
Christian Knabenhans, Shannon Veitch, Mathilde Raynal, Theresa Stadler, Sylvain Chatel, Wouter Lueks, Carmela Troncoso
ePrint Report ePrint Report
As digital identity systems gain traction around the world, many see privacy-enhancing technologies (PETs) as the key to ensuring safe deployment. We critically examine whether this is the case using the European Digital Identity Framework (EUDIF) as an example. We leverage techniques from cryptographic modeling to formally capture the necessary leakage of the functionality of the EUDIF and its proposed applications. Then, we develop a harm analysis methodology that illustrates, using harm trees, how this leakage — and other constraints stemming from design decisions or the context of deployment — lead to harms. Moreover, our harm modeling enables us to distinguish between which pathways to harm are inherent to the core functionality, and which pathways can be prevented with PETs. Our analysis shows that, while PETs can reduce information flows, they fall short in mitigating the harms that deploying digital identity can bring to individuals and society.
Expand
José Luis Delgado
ePrint Report ePrint Report
Post-quantum migration in Transport Layer Security (TLS) requires evidence-aware measurements that distinguish session negotiation, endpoint capability, certificate-chain evidence, and the provenance of missing observations. This distinction is essential under TLS 1.3 encryption, resumption, mutual TLS, trace truncation, fragmentation, coalescing, active certificate retrieval, and temporal drift. We present a multi-surface framework for post-quantum TLS observability. The framework separates passive session evidence, active probing, certificate-chain evidence, and registry knowledge, and maps them onto measurement planes for session behavior, key establishment, endpoint capability, authentication, lifecycle, observability, and policy. We instantiate it as a reproducible artifact with schema-enforced observations and results, versioned registries, auditable inference rules, stress contracts, and baseline adapters. We evaluate the framework on 29 controlled scenarios spanning TLS 1.2 and TLS 1.3, classical and hybrid key establishment, mutual TLS, resumption, HelloRetryRequest, truncation, fragmentation and coalescing, temporal drift, IPv6, and chain-depth variation. Passive evidence closes session-level planes, active probing establishes capability lower bounds, and multi-surface evidence closes the full measurement object while preserving uncertainty and contradiction when required. Against an inherited TLS quantum-vulnerability analyzer, the baseline detects 2 of 29 runs and 0 of 23 TLS 1.3 runs. In a stratified public campaign over 1000 targets and 2000 fresh probes, the framework completes 1971 handshakes, collects 1368 chain artifacts, confirms hybrid capability for 310 targets, and identifies 310 cases where endpoint capability exceeds what any single classical session view reveals. These results support post-quantum TLS readiness assessment as a structured observability problem based on explicit evidence surfaces, per-plane closure, active corroboration, source linkage, and first-class treatment of unknown, na, ambiguity, and contradiction.
Expand

06 May 2026

Koç University, İstanbul, Türkiye
Job Posting Job Posting
Cryptography, Security & Privacy Research Group at Koç University has multiple openings for summer research interns (at both undergraduate and graduate level). Topics include cryptography, cyber security, blockchains, artificial intelligence and machine learning, game theory and mechanism design. Apply via:

https://research.ku.edu.tr/research-outreach/summer-research/kusrp/

For more information about joining our group and projects, visit

https://crypto.ku.edu.tr/

All applications must be completed online. Applications with missing documents will not be considered. Applications via e-mail will not be considered. Application Requirements:
  1. CV
  2. 2 Recommendation Letters
  3. Official transcripts from all the universities attended
  4. Statement of Purpose
Internships are unpaid, on a voluntary basis, but can be performed remotely.

Deadline is 16 May 2026.

Closing date for applications:

Contact: https://research.ku.edu.tr/research-outreach/summer-research/kusrp/

More information: https://research.ku.edu.tr/research-outreach/summer-research/kusrp/

Expand
Koç University, İstanbul, Türkiye
Job Posting Job Posting
Cryptography, Security & Privacy Research Group at Koç University has multiple openings at every level. Accepted Computer Science and Engineering applicants may receive competitive scholarships including monthly stipend, tuition waiver, housing (accommodation) support, health insurance, computer, travel support, and lunch meal card.

Your duties include performing research on cryptography, cyber security, and privacy in line with our research group's focus, assisting teaching, as well as collaborating with other graduate and undergraduate students. Computer Science, Mathematics, Cryptography, or related background is necessary.

All applications must be completed online. Applications with missing documents or exam scores will not be considered. Applications via e-mail will not be considered. Application Requirements:
  1. CV
  2. Recommendation Letters (2 for MSc, 3 for PhD)
  3. TOEFL score (for everyone whose native language is not English, Internet Based: Minimum Score 80)
  4. GRE score
  5. Official transcripts from all the universities attended
  6. Statement of Purpose
https://gsse.ku.edu.tr/en/application/

Deadline: 15 May 2026.

For more information about joining our group and projects, visit

https://crypto.ku.edu.tr/

Closing date for applications:

Contact: https://gsse.ku.edu.tr/en/application/

More information: https://gsse.ku.edu.tr/en/application/

Expand
IBM Research Zurich
Job Posting Job Posting
The cryptography group at IBM Research in Zurich is looking to hire a Ph.D. student to work on constructions and applications of lattice-based zero knowledge proofs. The group is one of the world-leaders in quantum-safe cryptography research and has significantly contributed to all three lattice-based NIST quantum-safe standards. Our current research emphasis is on practical zero-knowledge proofs based on the same foundations and their application to privacy-preserving cryptography. A motivated researcher should find this to be a very exciting environment to work in. A strong background in (applied) mathematics and some experience with cryptography is desirable. Additionally, the ideal candidate is someone who has a strong interest in high-performance implementations on modern CPU and/or GPU architectures. Zurich is consistently ranked as one of the top cities for living standards and the immediate proximity of lakes and mountains to the lab allows for the pursuit of numerous hobbies. IBM is committed to fostering diversity and inclusion in the workplace. You will join an open, multicultural research environment that values different perspectives and supports flexible working arrangements. Our goal is to help all genders and backgrounds thrive professionally while maintaining a healthy work–life balance.

Closing date for applications:

Contact: Please apply via our career webpage: https://www.zurich.ibm.com/careers/2026_013.html

More information: https://www.zurich.ibm.com/careers/2026_013.html

Expand
Fraunhofer Institute for Secure Information Technology SIT
Job Posting Job Posting
The Fraunhofer-Gesellschaft (www.fraunhofer.com) is one of the world's leading organizations for application-oriented research. 75 institutes develop pioneering technologies for our economy and society – more precisely: 32 000 people from technology, science, administration and IT. They know: Anyone who comes to Fraunhofer wants to and can make a difference. For themselves, for us and for the markets of today and tomorrow. ATHENE is the National Research Center for Applied Cybersecurity and is one of the leading institutions in Europe and worldwide. Our contributors include the Fraunhofer Institutes SIT and IGD as well as TU Darmstadt, Goethe University Frankfurt, and Darmstadt University of Applied Sciences. Through excellence-driven research, we jointly develop innovative solutions to pressing security and data protection challenges and work closely with national and international partners, including leading companies, universities, and research institutions in Europe, the USA, and Israel. Our department, Applied Cybersecurity, focuses cutting-edge problems in the foundations and applications of cryptography, including privacy‑enhancing technologies, secure and verifiable computation, and securing AI-driven system operating in adversarial environments. The department offers a dynamic and growing research team, with a collaborative and supportive environment for research and learning.

Closing date for applications:

Contact: Prof. Dr. Adi Akavia

More information: https://jobs.fraunhofer.de/job/Darmstadt-Postdoctoral-Researcher-Cryptography-&-AI-%28Foundations-and-Applications%29-64295/1377969033/

Expand
Nokia Bell Labs (Belgium)
Job Posting Job Posting
We have a PhD internship position at Nokia Bell Labs in Belgium (Antwerp) for the autumn (September onwards):

Your profile (at least 3 of these):

  • You have experience with FHE (+ applications).
  • You have experience with MPC (preferred).
  • You have good knowledge of lattices, and you are interested in PQ protocols.
  • Not afraid of programming, using your favourite AI.

Our offer (at least 3 of these):

  • 3 to 4 months internship.
  • Fully paid.
  • Office side by side with the Antwerp Zoo, working next to the rhinos.
  • Helicopter landing pad for your vehicle.
You must be enrolled as a PhD student at a university. The salaries are on a European scale (at the Belgian PhD scholarship level).

Closing date for applications:

Contact: Emad Heydari Beni ([email protected])

Expand
Aksu, Turchia, 11 October 2026
Event Calendar Event Calendar
Event date: 11 October 2026
Submission deadline: 30 June 2026
Notification: 21 August 2026
Expand
Rome, Italy, 10 May -
Event Calendar Event Calendar
Event date: 10 May to
Expand
Warangal, India, 26 November - 28 November 2026
Event Calendar Event Calendar
Event date: 26 November to 28 November 2026
Submission deadline: 15 July 2026
Notification: 20 September 2026
Expand
◄ Previous Next ►