VLDB 2026 Research / reviewers in the wild / expert
Kristin E. Lauter
dblp:08/1510
· DBLP profile ↗
35ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-1320-696XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Making Hard Problems Easier with Custom Data Distributions and Loss Regularization: A Case Study in Modular ArithmeticabstractRecent work showed that ML-based attacks on Learning with Errors (LWE), a hard problem used in post-quantum cryptography, outperform classical algebraic attacks in certain settings. Although promising, ML attacks struggle to scale to more complex LWE settings. Prior work connected this issue to the difficulty of training ML models to do modular arithmetic, a core feature of the LWE problem. To address this, we develop techniques that significantly boost the performance of ML models on modular arithmetic tasks—enabling the models to sum up to $N=128$ elements modulo $q \le 974269$. Our core innovation is the use of custom training data distributions and a carefully designed loss function that better represents the problem structure. We apply an initial proof of concept of our techniques to LWE specifically and find that they allow recovery of 2x harder secrets than prior work. Our techniques also help ML models learn other well-studied problems better, including copy, associative recall, and parity, motivating further study. Eshika Saxena, Alberto Alfarano, Emily Wenger, Kristin E. Lauter |
ICML | 4 |
| 2025 | TAPAS: Datasets for Learning the Learning with Errors ProblemabstractAI-powered attacks on Learning with Errors (LWE)—an important hard math problem in post-quantum cryptography—rival or outperform "classical" attacks on LWE under certain parameter settings. Despite the promise of this approach, a dearth of accessible data limits AI practitioners' ability to study and improve these attacks. Creating LWE data for AI model training is time- and compute-intensive and requires significant domain expertise. To fill this gap and accelerate AI research on LWE attacks, we propose the TAPAS datasets, a ${\bf t}$oolkit for ${\bf a}$nalysis of ${\bf p}$ost-quantum cryptography using ${\bf A}$I ${\bf s}$ystems. These datasets cover several LWE settings and can be used off-the-shelf by AI practitioners to prototype new approaches to cracking LWE. This work documents TAPAS dataset creation, establishes attack performance baselines, and lays out directions for future work. Eshika Saxena, Alberto Alfarano, François Charton, Emily Wenger, Kristin E. Lauter |
NeurIPS | 5 |
| 2025 | AI for Code-based Cryptography
Mohamed Malhou, Ludovic Perret, Kristin E. Lauter |
SAC | 3 |
| 2025 | Benchmarking Attacks on Learning with ErrorsabstractLattice cryptography schemes based on the learning with errors (LWE) hardness assumption have been standardized by NIST for use as post-quantum cryptosystems, and by HomomorphicEncryption.org for performing encrypted computations on sensitive data. Thus, understanding their concrete security is critical. Most work on LWE security focuses on theoretical estimates of attack performance, which is important but may overlook attack nuances arising in real-world implementations. The sole existing concrete benchmarking effort, the Darmstadt Lattice Challenge, does not include benchmarks relevant to the standardized LWE parameter choices-such as small secret and small error distributions, and Ring-LWE (RLWE) and Module-LWE (MLWE) variants. To improve our understanding of concrete LWE security, we provide the first benchmarks for LWE secret recovery on standardized parameters, for small and low-weight (sparse) secrets. We evaluate four LWE attacks in these settings to serve as a baseline: the Search-LWE attacks uSVP [9], SALSA [51], and Cool&Cruel [44], and the Decision-LWE attack: Dual Hybrid Meet-in-the-Middle (MitM) [21]. We extend the SALSA and Cool&Cruel attacks in significant ways, and implement and scale up MitM attacks for the first time. For example, we recover hamming weight 9 - 11 binomial secrets for KYBER$(\kappa=2)$parameters in 28 - 36 hours with SALSA and Cool&Cruel, while we find that MitM can solve Decision-LWE instances for hamming weights up to 4 in under an hour for Kyber parameters, while uSVP attacks do not recover any secrets after running for more than 1100 hours. We also compare concrete performance against theoretical estimates. Finally, we open source the code to enable future research. Emily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu, Kristin E. Lauter |
SP | 5 |
| 2023 | SalsaPicante: A Machine Learning Attack on LWE with Binary SecretsabstractLearning with Errors (LWE) is a hard math problem underpinning many proposed post-quantum cryptographic (PQC) systems. The only PQC Key Exchange Mechanism (KEM) standardized by NIST [13] is based on module LWE [2], and current publicly available PQ Homomorphic Encryption (HE) libraries are based on ring LWE. The security of LWE-based PQ cryptosystems is critical, but certain implementation choices could weaken them. One such choice is sparse binary secrets, desirable for PQ HE schemes for efficiency reasons. Prior work SALSA[51] demonstrated a machine learning-based attack on LWE with sparse binary secrets in small dimensions (n ≤ = 128) and low Hamming weights (h ≤ = 4). However, this attack assumes access to millions of eavesdropped LWE samples and fails at higher Hamming weights or dimensions. Cathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou, Evrard Garcelon, François Charton, Kristin E. Lauter |
CCS | 7 |
| 2023 | SALSA VERDE: a machine learning attack on LWE with sparse small secretsabstractLearning with Errors (LWE) is a hard math problem used in post-quantum cryptography. Homomorphic Encryption (HE) schemes rely on the hardness of the LWE problem for their security, and two LWE-based cryptosystems were recently standardized by NIST for digital signatures and key exchange (KEM). Thus, it is critical to continue assessing the security of LWE and specific parameter choices. For example, HE uses secrets with small entries, and the HE community has considered standardizing small sparse secrets to improve efficiency and functionality. However, prior work, SALSA and PICANTE, showed that ML attacks can recover sparse binary secrets. Building on these, we propose VERDE, an improved ML attack that can recover sparse binary, ternary, and narrow Gaussian secrets. Using improved preprocessing and secret recovery techniques, VERDE can attack LWE with larger dimensions ($n=512$) and smaller moduli ($\log_2 q=12$ for $n=256$), using less time and power. We propose novel architectures for scaling. Finally, we develop a theory that explains the success of ML LWE attacks. Cathy Yuanchen Li, Emily Wenger, Zeyuan Allen Zhu, François Charton, Kristin E. Lauter |
NeurIPS | 5 |
| 2022 | SALSA: Attacking Lattice Cryptography with TransformersabstractCurrently deployed public-key cryptosystems will be vulnerable to attacks by full-scale quantum computers. Consequently, "quantum resistant" cryptosystems are in high demand, and lattice-based cryptosystems, based on a hard problem known as Learning With Errors (LWE), have emerged as strong contenders for standardization. In this work, we train transformers to perform modular arithmetic and mix half-trained models and statistical cryptanalysis techniques to propose SALSA: a machine learning attack on LWE-based cryptographic schemes. SALSA can fully recover secrets for small-to-mid size LWE instances with sparse binary secrets, and may scale to attack real world LWE-based cryptosystems. Emily Wenger, François Charton, Kristin E. Lauter |
NeurIPS | 4 |
| 2019 | CHET: an optimizing compiler for fully-homomorphic neural-network inferencingabstractFully Homomorphic Encryption (FHE) refers to a set of encryption schemes that allow computations on encrypted data without requiring a secret key. Recent cryptographic advances have pushed FHE into the realm of practical applications. However, programming these applications remains a huge challenge, as it requires cryptographic domain expertise to ensure correctness, security, and performance. Roshan Dathathri, Olli Saarikivi, Hao Chen 0030, Kim Laine, Kristin E. Lauter, Saeed Maleki, Madan Musuvathi, Todd Mytkowicz |
PLDI | 5 |
| 2019 | XONN: XNOR-based Oblivious Deep Neural Network Inference
M. Sadegh Riazi, Mohammad Samragh Razlighi, Hao Chen 0030, Kim Laine, Kristin E. Lauter, Farinaz Koushanfar |
USENIX Security Symposium | 5 |
| 2018 | Secure Outsourced Matrix Computation and Application to Neural NetworksabstractHomomorphic Encryption (HE) is a powerful cryptographic primitive to address privacy and security issues in outsourcing computation on sensitive data to an untrusted computation environment. Comparing to secure Multi-Party Computation (MPC), HE has advantages in supporting non-interactive operations and saving on communication costs. However, it has not come up with an optimal solution for modern learning frameworks, partially due to a lack of efficient matrix computation mechanisms. In this work, we present a practical solution to encrypt a matrix homomorphically and perform arithmetic operations on encrypted matrices. Our solution includes a novel matrix encoding method and an efficient evaluation strategy for basic matrix operations such as addition, multiplication, and transposition. We also explain how to encrypt more than one matrix in a single ciphertext, yielding better amortized performance. Our solution is generic in the sense that it can be applied to most of the existing HE schemes. It also achieves reasonable performance for practical use; for example, our implementation takes 9.21 seconds to multiply two encrypted square matrices of order 64 and 2.56 seconds to transpose a square matrix of order 64. Our secure matrix computation mechanism has a wide applicability to our new framework E2DM, which stands for encrypted data and encrypted model. To the best of our knowledge, this is the first work that supports secure evaluation of the prediction phase based on both encrypted data and encrypted model, whereas previous work only supported applying a plain model to encrypted data. As a benchmark, we report an experimental result to classify handwritten images using convolutional neural networks (CNN). Our implementation on the MNIST dataset takes 28.59 seconds to compute ten likelihoods of 64 input images simultaneously, yielding an amortized rate of 0.45 seconds per image. Xiaoqian Jiang, Miran Kim, Kristin E. Lauter, Yongsoo Song |
CCS | 3 |
| 2018 | Supersingular Isogeny Graphs and Endomorphism Rings: Reductions and Solutions
Kirsten Eisenträger, Sean Hallgren, Kristin E. Lauter, Travis Morrison, Christophe Petit 0001 |
EUROCRYPT (3) | 3 |
| 2018 | ReDCrypt: Real-Time Privacy-Preserving Deep Learning Inference in Clouds Using FPGAsabstractArtificial Intelligence (AI) is increasingly incorporated into the cloud business in order to improve the functionality (e.g., accuracy) of the service. The adoption of AI as a cloud service raises serious privacy concerns in applications where the risk of data leakage is not acceptable. Examples of such applications include scenarios where clients hold potentially sensitive private information such as medical records, financial data, and/or location. This article proposes ReDCrypt, the first reconfigurable hardware-accelerated framework that empowers privacy-preserving inference of deep learning models in cloud servers. ReDCrypt is well-suited for streaming (a.k.a., real-time AI) settings where clients need to dynamically analyze their data as it is collected over time without having to queue the samples to meet a certain batch size. Unlike prior work, ReDCrypt neither requires to change how AI models are trained nor relies on two non-colluding servers to perform. The privacy-preserving computation in ReDCrypt is executed using Yao’s Garbled Circuit (GC) protocol. We break down the deep learning inference task into two phases: (i) privacy-insensitive (local) computation, and (ii) privacy-sensitive (interactive) computation. We devise a high-throughput and power-efficient implementation of GC protocol on FPGA for the privacy-sensitive phase. ReDCrypt’s accompanying API provides support for seamless integration of ReDCrypt into any deep learning framework. Proof-of-concept evaluations for different DL applications demonstrate up to 57-fold higher throughput per core compared to the best prior solution with no drop in the accuracy. Bita Darvish Rouhani, Siam U. Hussain, Kristin E. Lauter, Farinaz Koushanfar |
ACM Trans. Reconfigurable Technol. Syst. | 3 |
| 2017 | Quantum Resource Estimates for Computing Elliptic Curve Discrete Logarithms
Martin Rötteler, Michael Naehrig, Krysta M. Svore, Kristin E. Lauter |
ASIACRYPT (2) | 4 |
| 2017 | PRINCESS: Privacy-protecting Rare disease International Network Collaboration via Encryption through Software guard extensionSabstractMotivation: We introduce PRINCESS, a privacy-preserving international collaboration framework for analyzing rare disease genetic data that are distributed across different continents. PRINCESS leverages Software Guard Extensions (SGX) and hardware for trustworthy computation. Unlike a traditional international collaboration model, where individual-level patient DNA are physically centralized at a single site, PRINCESS performs a secure and distributed computation over encrypted data, fulfilling institutional policies and regulations for protected health information. Results: To demonstrate PRINCESS' performance and feasibility, we conducted a family-based allelic association study for Kawasaki Disease, with data hosted in three different continents. The experimental results show that PRINCESS provides secure and accurate analyses much faster than alternative solutions, such as homomorphic encryption and garbled circuits (over 40 000× faster). Availability and Implementation: https://github.com/achenfengb/PRINCESS_opensource. Contact: [email protected]. Supplementary information: Supplementary data are available at Bioinformatics online. Feng Chen 0016, Shuang Wang 0002, Xiaoqian Jiang, Sijie Ding, Yao Lu 0006, Jihoon Kim 0001, Süleyman Cenk Sahinalp, Chisato Shimizu, Jane C. Burns, Victoria J. Wright, Eileen Png, Martin L. Hibberd, David D. Lloyd, Amalio Telenti, Cinnamon S. Bloss, Dov Fox, Kristin E. Lauter, Lucila Ohno-Machado |
Bioinform. | 18 |
| 2017 | Manual for Using Homomorphic Encryption for BioinformaticsabstractBiological data science is an emerging field facing multiple challenges for hosting, sharing, computing on, and interacting with large data sets. Privacy regulations and concerns about the risks of leaking sensitive personal health and genomic data add another layer of complexity to the problem. Recent advances in cryptography over the last five years have yielded a tool, homomorphic encryption, which can be used to encrypt data in such a way that storage can be outsourced to an untrusted cloud, and the data can be computed on in a meaningful way in encrypted form, without access to decryption keys. This paper introduces homomorphic encryption to the bioinformatics community, and presents an informal “manual” for using the Simple Encrypted Arithmetic Library (SEAL), which we have made publicly available for bioinformatic, genomic, and other research purposes. Nathan Dowlin, Ran Gilad-Bachrach, Kim Laine, Kristin E. Lauter, Michael Naehrig, John Robert Wernsing |
Proc. IEEE | 4 |
| 2016 | CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and AccuracyabstractApplying machine learning to a problem which involves medical, financial, or other types of sensitive data, not only requires accurate predictions but also careful attention to maintaining data privacy and security. Legal and ethical requirements may prevent the use of cloud-based machine learning solutions for such tasks. In this work, we will present a method to convert learned neural networks to CryptoNets, neural networks that can be applied to encrypted data. This allows a data owner to send their data in an encrypted form to a cloud service that hosts the network. The encryption ensures that the data remains confidential since the cloud does not have access to the keys needed to decrypt it. Nevertheless, we will show that the cloud service is capable of applying the neural network to the encrypted data to make encrypted predictions, and also return them in encrypted form. These encrypted predictions can be sent back to the owner of the secret key who can decrypt them. Therefore, the cloud service does not gain any information about the raw data nor about the prediction it made. We demonstrate CryptoNets on the MNIST optical character recognition tasks. CryptoNets achieve 99% accuracy and can make around 59000 predictions per hour on a single PC. Therefore, they allow high throughput, accurate, and private predictions. Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin E. Lauter, Michael Naehrig, John Robert Wernsing |
ICML | 4 |
| 2016 | Security Considerations for Galois Non-dual RLWE Families
Hao Chen 0030, Kristin E. Lauter, Katherine E. Stange |
SAC | 2 |
| 2016 | HEALER: homomorphic computation of ExAct Logistic rEgRession for secure rare disease variants analysis in GWASabstractMOTIVATION: Genome-wide association studies (GWAS) have been widely used in discovering the association between genotypes and phenotypes. Human genome data contain valuable but highly sensitive information. Unprotected disclosure of such information might put individual's privacy at risk. It is important to protect human genome data. Exact logistic regression is a bias-reduction method based on a penalized likelihood to discover rare variants that are associated with disease susceptibility. We propose the HEALER framework to facilitate secure rare variants analysis with a small sample size. RESULTS: We target at the algorithm design aiming at reducing the computational and storage costs to learn a homomorphic exact logistic regression model (i.e. evaluate P-values of coefficients), where the circuit depth is proportional to the logarithmic scale of data size. We evaluate the algorithm performance using rare Kawasaki Disease datasets. AVAILABILITY AND IMPLEMENTATION: Download HEALER at http://research.ucsd-dbmi.org/HEALER/ CONTACT: [email protected] SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Shuang Wang 0002, Wenrui Dai, Kristin E. Lauter, Miran Kim, Yuzhe Tang, Hongkai Xiong, Xiaoqian Jiang |
Bioinform. | 4 |
| 2016 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
J. Cryptol. | 4 |
| 2016 | Privately Evaluating Decision Trees and Random ForestsabstractAbstract Decision trees and random forests are common classifiers with widespread use. In this paper, we develop two protocols for privately evaluating decision trees and random forests. We operate in the standard two-party setting where the server holds a model (either a tree or a forest), and the client holds an input (a feature vector). At the conclusion of the protocol, the client learns only the model’s output on its input and a few generic parameters concerning the model; the server learns nothing. The first protocol we develop provides security against semi-honest adversaries. We then give an extension of the semi-honest protocol that is robust against malicious adversaries. We implement both protocols and show that both variants are able to process trees with several hundred decision nodes in just a few seconds and a modest amount of bandwidth. Compared to previous semi-honest protocols for private decision tree evaluation, we demonstrate a tenfold improvement in computation and bandwidth. David J. Wu 0001, Tony Feng, Michael Naehrig, Kristin E. Lauter |
Proc. Priv. Enhancing Technol. | 4 |
| 2015 | Provably Weak Instances of Ring-LWE
Yara Elias, Kristin E. Lauter, Ekin Ozman, Katherine E. Stange |
CRYPTO (1) | 2 |
| 2014 | Weak Instances of PLWE
Kirsten Eisenträger, Sean Hallgren, Kristin E. Lauter |
Selected Areas in Cryptography | 3 |
| 2014 | Private predictive analysis on encrypted medical data
Joppe W. Bos, Kristin E. Lauter, Michael Naehrig |
J. Biomed. Informatics | 2 |
| 2013 | High-Performance Scalar Multiplication Using 8-Dimensional GLV/GLS Decomposition
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
CHES | 4 |
| 2013 | Fast Cryptography in Genus 2
Joppe W. Bos, Craig Costello, Hüseyin Hisil, Kristin E. Lauter |
EUROCRYPT | 4 |
| 2013 | Improved Security for a Ring-Based Fully Homomorphic Encryption Scheme
Joppe W. Bos, Kristin E. Lauter, Jake Loftus, Michael Naehrig |
IMACC | 2 |
| 2013 | Generating pairing-friendly parameters for the CM construction of genus 2 curves over prime fields
Kristin E. Lauter |
Des. Codes Cryptogr. | 1 |
| 2012 | Affine Pairings on ARM
Tolga Acar, Kristin E. Lauter, Michael Naehrig, Daniel Shumow |
Pairing | 2 |
| 2010 | An Analysis of Affine Coordinates for Pairing Computation
Kristin E. Lauter, Peter L. Montgomery, Michael Naehrig |
Pairing | 1 |
| 2009 | Cryptographic Hash Functions from Expander Graphs
Denis Xavier Charles, Kristin E. Lauter, Eyal Z. Goren |
J. Cryptol. | 2 |
| 2008 | Evaluating Large Degree Isogenies and Applications to Pairing Based Cryptography
Reinier Bröker, Denis Xavier Charles, Kristin E. Lauter |
Pairing | 3 |
| 2008 | Computing the Cassels Pairing on Kolyvagin Classes in the Shafarevich-Tate Group
Kirsten Eisenträger, Dimitar Jetchev, Kristin E. Lauter |
Pairing | 3 |
| 2007 | Stronger Security of Authenticated Key Exchange
Brian A. LaMacchia, Kristin E. Lauter, Anton Mityagin |
ProvSec | 2 |
| 2006 | Trading Inversions for Multiplications in Elliptic Curve Cryptography
Mathieu Ciet, Marc Joye, Kristin E. Lauter, Peter L. Montgomery |
Des. Codes Cryptogr. | 3 |
| 2003 | Fast Elliptic Curve Arithmetic and Improved Weil Pairing Evaluation
Kirsten Eisenträger, Kristin E. Lauter, Peter L. Montgomery |
CT-RSA | 2 |