VLDB 2026 Research / reviewers in the wild / expert
Léo Perrin
dblp:145/1633
· DBLP profile ↗
31ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-4722-7005ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 3 first-author · 9 since 2021Theory of computation · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The XHash family for ZK-friendly hash functions
Tomer Ashur, Amit Singh Bhati, Al Kindi, Mohammad Mahzoun, Léo Perrin, Sundas Tariq |
Des. Codes Cryptogr. | 5 |
| 2025 | Transistor: a TFHE-Friendly Stream Cipher
Jules Baudrin, Sonia Belaïd, Nicolas Bon 0001, Christina Boura, Anne Canteaut, Gaëtan Leurent, Pascal Paillier, Léo Perrin, Matthieu Rivain, Yann Rotella, Samuel Tap |
CRYPTO (5) | 8 |
| 2025 | ChiLow and ChiChi: New Constructions for Code Encryption
Yanis Belkheyar, Patrick Derbez, Shibam Ghosh, Gregor Leander, Silvia Mella, Léo Perrin, Shahram Rasoolzadeh, Lukas Stennes, Siwei Sun, Gilles Van Assche, Damian Vizár |
EUROCRYPT (1) | 6 |
| 2025 | Commutative cryptanalysis as a generalization of differential cryptanalysisabstractAbstract Recently, Baudrin et al. analyzed a special case of Wagner’s commutative diagram cryptanalysis, referred to as commutative cryptanalysis. For a family $$(E_k)_k$$ ( E k ) k of permutations on a finite vector space G, commutative cryptanalysis exploits the existence of affine permutations $$A,B :G \rightarrow G$$ A , B : G → G , $$I \notin \{A,B\}$$ I ∉ { A , B } such that $$E_k \circ A (x) = B \circ E_k(x)$$ E k ∘ A ( x ) = B ∘ E k ( x ) holds with high probability, taken over inputs x, for a significantly large set of weak keys k. Several attacks against symmetric cryptographic primitives can be formulated within the framework of commutative cryptanalysis, most importantly differential attacks, as well as rotational and rotational-differential attacks. Besides, the notion of c-differentials on S-boxes can be analyzed as a special case within this framework. We discuss the relations between a general notion of commutative cryptanalysis, with A and B being arbitrary functions over a finite Abelian group, and differential cryptanalysis, both from the view of conducting an attack on a symmetric cryptographic primitive, as well as from the view of a theoretical study of cryptographic S-boxes. Jules Baudrin, Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Léo Perrin, Lukas Stennes |
Des. Codes Cryptogr. | 6 |
| 2024 | The Algebraic FreeLunch: Efficient Gröbner Basis Attacks Against Arithmetization-Oriented Primitives
Augustin Bariant, Aurélien Boeuf, Axel Lemoine, Irati Manterola Ayala, Morten Øygarden, Léo Perrin, Håvard Raddum |
CRYPTO (4) | 6 |
| 2023 | New Design Techniques for Efficient Arithmetization-Oriented Hash Functions: ttAnemoi Permutations and ttJive Compression Mode
Clémence Bouvier, Pierre Briaud, Pyrros Chaidos, Léo Perrin, Robin Salen, Vesselin Velichkov, Danny Willems |
CRYPTO (3) | 4 |
| 2023 | On the algebraic degree of iterated power functions
Clémence Bouvier, Anne Canteaut, Léo Perrin |
Des. Codes Cryptogr. | 3 |
| 2022 | Trims and extensions of quadratic APN functionsabstractAbstract In this work, we study functions that can be obtained by restricting a vectorial Boolean function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n to an affine hyperplane of dimension $$n-1$$ n-1 and then projecting the output to an $$n-1$$ n-1 -dimensional space. We show that a multiset of $$2 \cdot (2^n-1)^2$$ 2·(2n-1)2 EA-equivalence classes of such restrictions defines an EA-invariant for vectorial Boolean functions on $$\mathbb {F}_{2}^n$$ F2n . Further, for all of the known quadratic APN functions in dimension $$n < 10$$ n<10 , we determine the restrictions that are also APN. Moreover, we construct 6368 new quadratic APN functions in dimension eight up to EA-equivalence by extending a quadratic APN function in dimension seven. A special focus of this work is on quadratic APN functions with maximum linearity. In particular, we characterize a quadratic APN function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n with linearity of $$2^{n-1}$$ 2n-1 by a property of the ortho-derivative of its restriction to a linear hyperplane. Using the fact that all quadratic APN functions in dimension seven are classified, we are able to obtain a classification of all quadratic 8-bit APN functions with linearity $$2^7$$ 27 up to EA-equivalence. Christof Beierle, Gregor Leander, Léo Perrin |
Des. Codes Cryptogr. | 3 |
| 2022 | Recovering or Testing Extended-Affine EquivalenceabstractExtended Affine (EA) equivalence is the equivalence relation between two vectorial Boolean functions$F$and$G$such that there exist two affine permutations$A$,$B$, and an affine function$C$satisfying$G = A \circ F \circ B + C$. While the problem has a simple formulation, it is very difficult in practice to test whether two functions are EA-equivalent. This problem has two variants:EA-partitioningdeals with partitioning a set of functions into disjoint EA-equivalence classes, andEA-recoveryis about recovering the tuple$(A,B,C)$if it exists. In this paper, we present a new algorithm that efficiently solves the EA-recovery problem for quadratic functions. Although its worst-case complexity occurs when dealing with APN functions, it supersedes, in terms of performance, all previously known algorithms for solving this problem for all quadratic functions and in any dimension, even in the case of APN functions. This approach is based on the Jacobian matrix of the functions, a tool whose study in this context can be of independent interest. The best approach for EA-partitioning in practice mainly relies on class invariants. We provide an overview of the known invariants along with a new one based on theortho-derivative. This new invariant is applicable to quadratic APN functions, a specific type of functions that is of great interest, and of which tens of thousands need to be sorted into distinct EA-classes. Our ortho-derivative-based invariant is very fast to compute, and it practically always distinguishes between EA-inequivalent quadratic APN functions. Anne Canteaut, Alain Couvreur, Léo Perrin |
IEEE Trans. Inf. Theory | 3 |
| 2021 | Internal Symmetries and Linear Properties: Full-permutation Distinguishers and Improved Collisions on Gimli
Antonio Flórez-Gutiérrez, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, André Schrottenloher, Ferdinand Sibleyras |
J. Cryptol. | 4 |
| 2020 | New Results on Gimli: Full-Permutation Distinguishers and Improved Collisions
Antonio Flórez-Gutiérrez, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, André Schrottenloher, Ferdinand Sibleyras |
ASIACRYPT (1) | 4 |
| 2020 | Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001 |
CRYPTO (3) | 5 |
| 2020 | Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer |
CRYPTO (3) | 8 |
| 2020 | Cryptanalysis Results on Spook - Bringing Full-Round Shadow-512 to the Light
Patrick Derbez, Paul Huynh, Virginie Lallemand, María Naya-Plasencia, Léo Perrin, André Schrottenloher |
CRYPTO (3) | 5 |
| 2020 | On Subspaces of Kloosterman Zeros and Permutations of the Form L1(x-1)+L2(x)
Faruk Göloglu, Lukas Kölsch, Gohar M. Kyureghyan, Léo Perrin |
WAIFI | 4 |
| 2020 | Boomerang uniformity of popular S-box constructions
Shizhu Tian, Christina Boura, Léo Perrin |
Des. Codes Cryptogr. | 3 |
| 2020 | Meet-in-the-Middle Attacks and Structural Analysis of Round-Reduced PRINCE
Patrick Derbez, Léo Perrin |
J. Cryptol. | 2 |
| 2019 | Anomalies and Vector Space Search: Tools for S-Box Analysis
Xavier Bonnetain, Léo Perrin, Shizhu Tian |
ASIACRYPT (1) | 2 |
| 2019 | Feistel Structures for MPC, and More
Martin R. Albrecht, Lorenzo Grassi 0001, Léo Perrin, Sebastian Ramacher, Christian Rechberger, Dragos Rotaru, Arnab Roy 0005, Markus Schofnegger |
ESORICS (2) | 3 |
| 2017 | Symmetrically and Asymmetrically Hard Cryptography
Alex Biryukov, Léo Perrin |
ASIACRYPT (3) | 2 |
| 2017 | A Generalisation of Dillon's APN Permutation With the Best Known Differential and Nonlinear Properties for All Fields of Size 24k+2abstractThe existence of almost perfect nonlinear (APN) permutations operating on an even number of variables was a long-standing open problem, until an example with six variables was exhibited by Dillon et al. in 2009. However it is still unknown whether this example can be generalized to any even number of inputs. In a recent work, Perrin et al. described an infinite family of permutations, named butterflies, operating on (4k+2) variables and with differential uniformity at most 4, which contains the Dillon APN permutation. In this paper, we generalize this family, and we completely solve the two open problems raised by Perrin et al. Indeed we prove that all functions in this larger family have the best known nonlinearity. We also show that this family does not contain any APN permutation besides the Dillon permutation, implying that all other functions have differential uniformity exactly four. Anne Canteaut, Sébastien Duval, Léo Perrin |
IEEE Trans. Inf. Theory | 3 |
| 2016 | Design Strategies for ARX with Provable Bounds: Sparx and LAXabstractWe present, for the first time, a general strategy for designing ARX symmetric-key primitives with provable resistance against single-trail differential and linear cryptanalysis. The latter has been a long standing open problem in the area of ARX design. The wide-trail design strategy (WTS), that is at the basis of many S-box based ciphers, including the AES, is not suitable for ARX designs due to the lack of S-boxes in the latter. In this paper we address the mentioned limitation by proposing the long trail design strategy (LTS) – a dual of the WTS that is applicable (but not limited) to ARX constructions. In contrast to the WTS, that prescribes the use of small and efficient S-boxes at the expense of heavy linear layers with strong mixing properties, the LTS advocates the use of large (ARX-based) S-Boxes together with sparse linear layers. With the help of the so-called long-trail argument , a designer can bound the maximum differential and linear probabilities for any number of rounds of a cipher built according to the LTS. To illustrate the effectiveness of the new strategy, we propose Sparx – a family of ARX-based block ciphers designed according to the LTS. Sparx has 32-bit ARX-based S-boxes and has provable bounds against differential and linear cryptanalysis. In addition, Sparx is very efficient on a number of embedded platforms. Its optimized software implementation ranks in the top 6 of the most software-efficient ciphers along with Simon , Speck , Chaskey, LEA and RECTANGLE. As a second contribution we propose another strategy for designing ARX ciphers with provable properties, that is completely independent of the LTS. It is motivated by a challenge proposed earlier by Wallén and uses the differential properties of modular addition to minimize the maximum differential probability across multiple rounds of a cipher. A new primitive, called LAX , is designed following those principles. LAX partly solves the Wallén challenge. Daniel Dinu, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Johann Großschädl, Alex Biryukov |
ASIACRYPT (1) | 2 |
| 2016 | Cryptanalysis of a Theorem: Decomposing the Only Known Solution to the Big APN Problem
Léo Perrin, Aleksei Udovenko, Alex Biryukov |
CRYPTO (2) | 1 |
| 2016 | Reverse-Engineering the S-Box of Streebog, Kuznyechik and STRIBOBr1
Alex Biryukov, Léo Perrin, Aleksei Udovenko |
EUROCRYPT (1) | 2 |
| 2016 | Algebraic Insights into the Secret Feistel Network
Léo Perrin, Aleksei Udovenko |
FSE | 1 |
| 2015 | On Reverse-Engineering S-Boxes with Hidden Design Criteria or Structure
Alex Biryukov, Léo Perrin |
CRYPTO (1) | 2 |
| 2015 | Differential Analysis and Meet-in-the-Middle Attack Against Round-Reduced TWINE
Alex Biryukov, Patrick Derbez, Léo Perrin |
FSE | 3 |
| 2015 | Meet-in-the-Middle Attacks and Structural Analysis of Round-Reduced PRINCE
Patrick Derbez, Léo Perrin |
FSE | 2 |
| 2015 | Cryptanalysis of Feistel Networks with Secret Round Functions
Alex Biryukov, Gaëtan Leurent, Léo Perrin |
SAC | 3 |
| 2014 | Collision Spectrum, Entropy Loss, T-Sponges, and Cryptanalysis of GLUON-64
Léo Perrin, Dmitry Khovratovich |
FSE | 1 |
| 2014 | More differentially 6-uniform power functions
Céline Blondeau, Léo Perrin |
Des. Codes Cryptogr. | 2 |