IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
26 January 2026
Bin Xie, Tianyu Zheng, Rui Song, Shang Gao, Bin Xiao
The Italian Institute of Artificial Intelligence (AI4I)
Funded by: The Italian Institute of Artificial Intelligence (AI4I), in collaboration with Bocconi University
Supervisors: Dr. Tamer Mour (AI4I)
Co-advisor from Bocconi University (to be defined upon agreement)
The Italian Institute of Artificial Intelligence for Industry (AI4I), in collaboration with Bocconi University, invites applications for a PhD position at its upcoming Crypto4AI Lab (launching March 2026).
The Crypto4AI Lab will conduct cutting-edge research grounded in computer science theory and mathematics, aiming to establish solid foundations for next-generation cryptographic solutions tailored to artificial intelligence systems. Research topics include, but are not limited to:
- Private inference
- Model integrity
- Watermarking
The research activity will span:
- Cryptographic design
- Cryptanalysis (analytical and experimental)
- Mathematical foundations of cryptography
- Experimentation with machine learning models
- Protocol implementation and optimization across different hardware architectures
The PhD position is hosted within the Bocconi University PhD program, with research activities jointly supervised and co-developed with AI4I.
Required qualifications:
- MSc (or equivalent) in computer science, mathematics or related fields.
- Strong background in at least one of: theoretical computer science, cryptography (theoretical and/or applied), machine learning, mathematics, statistical physics.
- Fluent English.
- Ability to work both autonomously and in teams. Application:
- CV (including publications if applicable)
- Cover letter (max 1 page)
- Academic transcripts
- Contact information of three references
- Important: Candidates must also apply in parallel to the Bocconi University PhD program and meet its eligibility requirements https://www.unibocconi.it/en/programs/phd/admissions
Closing date for applications:
Contact: https://ai4i.it/phd-in-cryptography-for-machine-learning-january-2026/
More information: https://app.ncoreplat.com/jobsharingredirect/777335/phd-in-cryptography-for-machine-learning-it/research-and-development?type=1&platform=19&sharing=4967665
25 January 2026
Matteo Campanelli
Xiao Huang, Zhuo Huang, Yituo He, Quan Yuan, Chao Sun, Mehdi Tibouchi, Yu Yu
In Fiat--Shamir-based signatures, it is well-known that key material will be leaked if an attacker can somehow obtain what amounts, in the sigma protocol, to the responses to different challenges with respect to the same commitment. This idea is for example at the basis of a famous differential fault attack against deterministic Fiat--Shamir-based signatures like EdDSA. It is usually difficult to mount a fault injection attack based on that principle against a properly randomized Fiat--Shamir-based scheme however (at least with single faults): since commitment collisions are ruled out, it typically involves obtaining the responses to multiple challenges with respect to the same commitment within a single execution of the signature, which is often impossible by construction (e.g., because the extra information will not fit in a single signature, or because it is hard to force the computation of both responses).
Due to the comparative inefficiency of signatures based on Stern-like protocols with parallel repetition, candidate constructions are led to use clever compression techniques to reduce signature size, in a way that increases the attack surface for physical attacks. In this paper, we demonstrate this against the LESS signature scheme, which uses so-called GGM trees for signature compression. We propose a simple fault attack on the construction of a binary array used to build the GGM tree, and show that a small number of faulty signatures suffice for full key recovery.
We provide a thorough mathematical model of the attack as well as extensive experimental validation with glitch attacks on a ChipWhisperer board, showing that, depending on the target parameter set and the precise fault model we consider, full key recovery can very often be achieved with just one or two faulty signatures, and never more than a couple hundred even in the least favorable scenario for the attacker.
Chao Sun, Thomas Espitau, Junjie Song, Jinguang Han, Mehdi Tibouchi
Dong-Jie Guo, Qun-Xiong Zheng, Zhong-Xiao Wang, Xiao-Xin Zhao
Pierrick Dartois, Max Duparc
Cruz Barnum, David Heath
Point (1) places the primitive into Minicrypt, point (2) implies that OIHFs exist as long as OT exists, and point (3) shows that this primitive circumvents the barrier imposed by Impagliazzo and Rudich by implying public-key primitives -- specifically OT -- anyway.
Antonio Guimarães, Gabriela M. Jacob, Hilder V. L. Pereira
Mingshu Cong, Sherman S. M. Chow, Tsz Hon Yuen, Siu-Ming Yiu
Motivated by this gap, we introduce matrix-circuit satisfiability (Mat-Circ-SAT) and a high-dimensional variant of R1CS, termed high-dimensional R1CS (HD-R1CS), for Mat-Circ-SAT. Architecturally, HD-R1CS encodes NN architectures via sparse matrices whose dimensions scale with the number of matrices, rather than with the total number of scalar entries, as in R1CS. Notably, we present zkSMART (zero-knowledge sparse matrix argument via restructuring transform) as a zkSNARK protocol for HD-R1CS.
Compared to Evalyn (Asiacrypt '25), which hides the NN architecture using the proof-of-proof technique, zkSMART performs better in concrete prover time for deep NNs. More precisely, for NN computations with $M$ matrices of size $n \times n$, we achieve $O(n^2 M)$ prover time, $O(\log(nM))$ proof size and verifier time, and $O(n^2 M)$ RAM usage with a small constant factor. Such asymptotic efficiency enables our protocol to scale to NNs with up to a billion parameters.
Razvan Barbulescu, Mugurel Barcau, Vicentiu Pasol, George Turcas
Carsten Baum, Marvin Beckmann, Ward Beullens, Shibam Mukherjee, Christian Rechberger
In this work, we propose an alternative direction with a plausibly post-quantum Blind signature scheme called PoMFRIT. It builds on top of the VOLE-in-the-head Zero-Knowledge proof system (Baum et al. CRYPTO 2023), which we combine with the MAYO digital signature scheme (Beullens, SAC 2021). We implement multiple versions of PoMFRIT to demonstrate security and performance trade-offs, and provide detailed benchmarks of our constructions. Signature issuance requires \(0.45\) KB communication for Blind signatures of size \(6.7\) KB. Showing a Blind signature can be done in $<76$ ms even for a conservative construction with $128$ bit security. As a building block for our Blind signature scheme, we implement the first VOLE-in-the-head proof for hash functions in the SHA-3 family, which we consider of independent interest.
Isaar Ahmad, Hao Cheng, Johann Großschädl, Daniel Page
Wrenna Robson, Samuel Kelly
Hyunji Kim, Kyungbae Jang, Siyi Wang, Anubhab Baksi, Gyeongju Song, Hwajeong Seo, Anupam Chattopadhyay
Using our quantum circuits, we newly assess the post-quantum security of elliptic curve cryptography. Under the MAXDEPTH constraint proposed by NIST, which limits the maximum circuit depth to $2^{40}$, the maximum depth in our work is $2^{28}$ for the P-521 curve (well below this threshold). For the total gate count and full depth product, a metric defined by NIST for evaluating quantum attack resistance, the maximum complexity for the same curve is $2^{65}$, far below the post-quantum security level 1 requirement of $2^{157}$.
Beyond these logical analyses, we estimate the fault-tolerant costs (i.e., at the level of physical resources) for breaking elliptic curve cryptography. As one of our results, the P-224 curve (comparable to RSA-2048 in security) can be broken in 34 minutes using 19.1 million physical qubits, or in 96 minutes using 6.9 million physical qubits under our two optimization approaches.