IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
19 September 2026
Zhen Yu Xiong, Mingsheng Wang, Zhedong Wang, Han Wang
We propose a symmetry-graded framework that views the two evaluation routes as commuting group actions on the digit-extraction polynomial. Under this unified perspective, the existing evaluators correspond to different specializations of $\mathrm{cost}(D;r,d)$. For lower degree, we identify a novel rank-two lattice structure underlying digit extraction. The crystallographic restriction limits the filter order to $r\in\{1,2,3,4,6\}$. In particular, the methods of Ma et al. and Xiong et al. correspond to $r=2$ and $r=4$, respectively. Moreover, our framework derives a sparser order-six digit-extraction polynomial, enabling order-six symmetry for Mersenne primes. For lower evaluation cost, we construct a composed evaluator that first folds $P_A$ using the scalar filter and then evaluates the folded polynomial via the slot ring's Galois norm map. Since the rotation and Frobenius actions commute, the two optimizations can be combined within the same framework. Consequently, for any $(p,m)$ we select the optimal $(r,d)$ and evaluate digit extraction in $2\sqrt{D/(rd)}+O(\log D)$ non-scalar multiplications.
On 13 general cyclotomic rings at $\geq 80$-bit verified security, our single-threaded HElib implementation improves upon the state-of-the-art evaluator of Ma et al., accelerating digit extraction by $2.4$–$4.9\times$ and thin bootstrapping by $1.3$–$2.8\times$, while modifying only the digit-extraction stage. In particular, on Ma et al.'s set IV with the Mersenne prime $p=8191$ and set V with $p=65537$, digit extraction is accelerated by $3.6\times$ and $3.8\times$, respectively, reducing the total bootstrapping time from 180.4 s to 85.5 s and from 217.6 s to 103.1 s. The implementation is publicly available, and the core analysis is machine-checked in Lean 4.
Yvonne Zhou, Mingyu Liang, Ivan Brugere, Danial Dervovic, Antigoni Polychroniadou, Min Wu, Dana Dachman-Soled
Ananya Appan, Pranav Shriram Arunachalaramanan, David Heath, Ling Ren
Many private aggregation schemes assume two non-colluding servers and aim to guarantee privacy even when one server is malicious, i.e., the malicious server learns an aggregation result that includes all honest client inputs. However, many private aggregation schemes in the literature fail to achieve privacy, which we believe is in large part due to a lack of formalism for the nuanced variations of privacy guarantees.
In this work, we present ideal functionalities for several variants of private aggregation. We also formalize a common paradigm underlying most prior private aggregation schemes. The formal treatment helps us identify security flaws or underspecifications in existing private aggregation schemes. We then present modular modifications or fill in critical details to help prior schemes in the share-aggregate paradigm securely realize the private aggregation functionalities we formally define, including in settings where clients may have unreliable networks.
Yvonne Zhou, Mingyu Liang, Ivan Brugere, Danial Dervovic, Yue Guo, Antigoni Polychroniadou, Min Wu, Dana Dachman-Soled
Aarushi Goel, Gabriel Kaptchuk, Yuange Li
In this work, we introduce a cryptographic framework called Sunshine Systems, designed to constrain government actors' ability to circumvent freedom of information laws. At a high level, Sunshine Systems enable agencies to prove, in zero knowledge, that they have produced the complete and correct set of documents responsive to a given request. We instantiate a Sunshine System that supports keyword queries, building on recent advances in lookup arguments. We implement and evaluate our approach on low-cost hardware, demonstrating its practicality even for small government agencies.
Maxime Lecomte, Julien Maillard, Antoine Moran, Guénaël Renault, Benjamin Smith
Zhao Song, Song Yue
Anirudh Jaiswal, Abhilash Kumar Das, Dhiman Saha
Elette Boyle, Lalita Devadas
A significant body of work has gone toward developing and understanding limitations of distributed certification schemes, predominantly in the setting of information-theoretic soundness, and recently with computational soundness, achieving a form of distributed (locally verifiable) Succinct Non-interactive Arguments (SNARGs) (Aldema Tshuva et al, TCC 2023). As is standard in the model, soundness holds in existing constructions assuming that all verifiers in the network are honest.
In this work, we introduce and explore the notion of robust distributed SNARGs (rdSNARGs) which retain (computational) soundness guarantees even when the cheating prover can collude with some nodes in the network. Addressing cheating verifiers presents several challenges. We construct rdSNARGs for any distributed language in P with succinct certificate size and communication from extended versions of RAM SNARGs (Kalai et al, STOC 2023), where the level of succinctness scales with the threshold of corrupt nodes. Complementarily, we demonstrate a lower bound showing that an rdSNARG with significantly smaller certificates and communication implies a SNARG for NP.
Katarina Cheng, Wilson Nguyen, Nirvan Tyagi
JunHyeok Choi, DongHyun Shin, Seog Chung Seo
James Bell-Clark, Albert Cheu, Adria Gascon, Jonathan Katz, Lukas Gerlach
We introduce ROGA, a scheme for Resizable Oblivious Group-by Aggregation. ROGA uses an extension of oblivious single-access machines and thus improves performance, both asymptotically and concretely, relative to using ORAM. It also incorporates a novel, differentially oblivious resizing mechanism that ensures the allocated memory is within a constant factor of the memory used by a non-oblivious solution. ROGA also parallelizes cleanly across multiple cores for improved performance.
We implement ROGA in Rust and use Binsec/Rel to verify trace noninterference of its compiled fixed-capacity operations, resize estimator, and fixed-work noise sampler, showing that executions with equal public parameters have identical branch-target and memory-address traces for all secret inputs. The only data-dependent branch is the differentially private resize decision. Compared to state-of-the-art oblivious schemes for confidential analytics (which do not support private resizing), ROGA is up to 50.4$\times$ faster when sharded across 64 logical cores, and private resizing cuts memory by up to 14$\times$ compared to domain-provisioned instances. In a case study, ROGA using 16 cores processes the standard network statistics of a 277-million-packet backbone trace with $5.3\times$ end-to-end overhead over a non-oblivious pipeline while exactly matching the reference output.
Esra Yeniaras
Zhengzhong Jin
Central to our result is the first Karp-Levin reduction from satisfiability for circuits of size $\mathrm{polylog}(\lambda)$ to the minimum-distance problem for linear codes (GapMDP) over a prime field of size $\lambda^{\omega(1)}$, with an approximation factor of $\omega(\log \lambda)$, where $\lambda$ is the security parameter. We obtain this reduction by adapting Hair and Sahai's recent hardness result for GapSVP. Combining our reduction with the witness encryption framework due to Barta, Ishai, Ostrovsky, and Wu [CRYPTO 2020], we obtain the first unconditional extractable witness encryption for circuits of size $\mathrm{polylog}(\lambda)$ in the generic group model. These techniques may be of independent interest.
Roberto La Scala, Marco Marchesin, Sharwan K. Tiwari
Building on this modeling, we generalize the ISD paradigm through an ISD-like decoding strategy, implemented by the GBDecode algorithm, in which only a subset of an information set is fixed. This approach reduces the size of the combinatorial search space at the cost of solving the associated multivariate nonlinear systems. To handle this algebraic component, we employ the MultiSolve algorithm, which replaces a single Grobner basis computation with a collection of computations on simpler systems, obtained by exhaustively assigning a varying number of indeterminates over the finite field. This provides a tunable balance between combinatorial search and algebraic solving.
We evaluate the resulting approach experimentally on instances of the Syndrome Decoding Problem for random binary linear codes, using parameters corresponding to the NIST Security Category 1 parameter set of the Classic McEliece cryptosystem. The experiments assess the feasibility of this combinatorial-algebraic approach and provide insights into the practical behavior of Grobner basis techniques within an ISD-like decoding framework.
Shi Tang, Zirui Chen, Yongjia Su, Zhengchao Gao, Lingyue Qin, Xiaoyang Dong
This work presents {\em Normal Alignment}, a novel statistical sign‑recovery approach for S1 DNNs. Drawing on the expected length difference between projected normals of adjacent decision facets at dual points, our method infers neuron signs via normal‑signature alignment. It delivers higher voting accuracy and pushes erroneous predictions to low‑confidence ranks, which further enables a more efficient combined method, {\em eSOE + Alignment}, by combining {\em Normal Alignment} with the hard‑label {SOE} extension. This combined strategy removes heavy enumeration overhead and realizes exact polynomial‑time full sign recovery.
Experiments demonstrate the effectiveness of our method, especially for deep layers. For example, with our method, the signs for CIFAR-10 (architecture 192-64$\times$8-10) and MNIST (architecture 64-96$\times$3-32-10) models can be fully recovered in polynomial time; in contrast, Carlini {\em et al.}'s sign‑recovery method would require exponential‑time enumerations involving $2^{52}$ or $2^{82}$ guesses of the signs, respectively.
Rong Qian, Yu Cheng, Lingyu Gao, Yuchang Zhang, Zengli Guo
18 September 2026
Fredrik Meisingseth
First, we propose an idealized model of aborts, where an aborter is leaked some information about a DP mechanism execution and then chooses whether or not to let an independent malicious analyst learn the mechanism output. We bound the effects of aborts according to what information (the database, randomness, output, or any combination of these) is leaked. These bounds are not only applicable to multiparty DP via general-purpose multiparty computation (MPC) but may also be used in the analysis of other methods to certify DP properties of a protocol. Second, we apply these bounds to analyze ideal protocol executions in MPC. We show, for the first time, that the ideal execution with fairness gives strictly stronger DP guarantees than that for security-with-abort, for the outputs to the honest parties. Further, solitary-output functionalities satisfy guarantees similar to those of the execution with fairness.
Finally, we analyze multiparty protocols with respect to the way in which they realize the respective ideal functionalities. We show that partially fair and fully fair protocols have very similar DP guarantees. Since partial fairness, as opposed to full fairness, can be achieved in dishonest-majority settings, and in particular the two-party setting, this opens up for enhanced DP guarantees in two-party computation.
Dong Jin Park, Hyunseok Jeong, Minwook Jeong, Jaeky Oh, Yongwoo Lee, Young-Sik Kim
RISE Research Institutes of Sweden, Stockholm, Sweden
As AI agents start acting in groups, delegating, negotiating, and relying on each other's inputs and outputs, the security assumptions behind single-model systems stop holding. This project develops principled and scalable foundations for trustworthy collaboration between AI agents, sitting at the intersection of AI and cybersecurity. It is funded by the Swedish Foundation for Strategic Research (SSF) under a programme building research ties between Sweden and Taiwan, including opportunities for research visits among the participants.
We are looking for a dedicated PhD student to strengthen our research in trustworthy multi-agent AI systems. Example research topics include evaluating the robustness of multi-agent systems under adversarial manipulation, designing secure and privacy-preserving multi-agent collaborative mechanisms, and verifiable decision-making under uncertainty and adversarial influence. You will be based in the RISE office at Kista, Stockholm for 4 years, and you will be enrolled as a doctoral student at a Swedish University. PhD education also involves participation in relevant university courses.
Closing date for applications:
Contact: Dr. Apostolos Pyrgelis -- apostolos.pyrgelis(at)ri(dot)se
More information: https://www.ri.se/en/about-rise/work-with-us/open-job-positions/phd-student-in-security-and-privacy-of-multi-agent-ai