VLDB 2026 Research / reviewers in the wild / expert
Thomas Attema
dblp:171/2268
· DBLP profile ↗
15ranked-venue papers
13as first author
11since 2021 · last 2026
0000-0002-8289-6853ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 12 first-author · 10 since 2021Theory of computation · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Fiat - Shamir Transformation of $(\varGamma _1,\dots ,\varGamma _\mu )$-Special-Sound Interactive ProofsabstractAbstract The Fiat–Shamir transformation is a general principle to turn any public-coin interactive proof into non-interactive one (with security then typically analyzed in the random oracle model). While initially used for 3-round protocols, many recent constructions use it for multi-round protocols. However, in general the soundness error of the Fiat–Shamir transformed protocol degrades exponentially in the number of rounds. On the positive side, it was shown that for the special class of $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound $$\varSigma $$ Σ -protocols, which is a natural multi-round generalization of the well-known class of special-sound protocols, the loss is actually only linear in the number of random oracle queries, and independent of the number of rounds, which is optimal. A natural next question is whether this positive result extends to the Fiat–Shamir transformation of so-called $$(\varGamma _1,\dots ,\varGamma _\mu )$$ ( Γ 1 , ⋯ , Γ μ ) -special-sound protocols. This notion was recently defined and analyzed in the interactive case; it captures a larger class of protocols, namely where the special-soundness property is characterized by a general access structure, rather than a threshold. We show in this work that this is indeed the case. Concretely, we show that the Fiat–Shamir transformation of any $$(\varGamma _1, \ldots , \varGamma _\mu )$$ ( Γ 1 , … , Γ μ ) -special-sound interactive proof is knowledge sound under the same condition on $$\varGamma _1,\dots ,\varGamma _\mu $$ Γ 1 , ⋯ , Γ μ for which the original interactive proof is knowledge sound. Furthermore, also here the loss is linear in the number of random oracle queries and independent of the number of rounds. In light of the above, one might suspect that our argument follows as a straightforward combination of the above mentioned prior works. However, this is not the case. The approach used for $$(k_1,\dots ,k_\mu )$$ ( k 1 , ⋯ , k μ ) -special-sound protocols, which is based on an extractor that samples without replacement, does not (seem to) generalize; on the other hand, the other approach, which uses an extractor based on sampling with replacement, comes with an additional loss that would blow up in the recursive multi-round analysis. Thus, new techniques are necessary to handle the above complications. Thomas Attema, Serge Fehr, Michael Klooß, Nicolas Resch |
J. Cryptol. | 1 |
| 2023 | Generalized Special-Sound Interactive Proofs and Their Knowledge Soundness
Thomas Attema, Serge Fehr, Nicolas Resch |
TCC (3) | 1 |
| 2023 | Fiat-Shamir Transformation of Multi-Round Interactive Proofs (Extended Version)abstractAbstract The celebrated Fiat–Shamir transformation turns any public-coin interactive proof into a non-interactive one, which inherits the main security properties (in the random oracle model) of the interactive version. While originally considered in the context of 3-move public-coin interactive proofs, i.e., so-called $$\varSigma $$ Σ -protocols, it is now applied to multi-round protocols as well. Unfortunately, the security loss for a $$(2\mu + 1)$$ (2μ+1) -move protocol is, in general, approximately $$Q^\mu $$ Qμ , whereQis the number of oracle queries performed by the attacker. In general, this is the best one can hope for, as it is easy to see that this loss applies to the $$\mu $$ μ -fold sequential repetition of $$\varSigma $$ Σ -protocols, but it raises the question whether certain (natural) classes of interactive proofs feature a milder security loss. In this work, we give positive and negative results on this question. On the positive side, we show that for $$(k_1, \ldots , k_\mu )$$ (k1,…,kμ) -special-sound protocols (which cover a broad class of use cases), the knowledge error degrades linearly inQ, instead of $$Q^\mu $$ Qμ . On the negative side, we show that fort-foldparallel repetitionsof typical $$(k_1, \ldots , k_\mu )$$ (k1,…,kμ) -special-sound protocols with $$t \ge \mu $$ t≥μ (and assuming for simplicity thattandQare integer multiples of $$\mu $$ μ ), there is an attack that results in a security loss of approximately $$\frac{1}{2} Q^\mu /\mu ^{\mu +t}$$ 12Qμ/μμ+t . Thomas Attema, Serge Fehr, Michael Klooß |
J. Cryptol. | 1 |
| 2022 | Efficient Compiler to Covert Security with Public Verifiability for Honest Majority MPC
Thomas Attema, Vincent Dunning, Maarten H. Everts, Peter Langenkamp |
ACNS | 1 |
| 2022 | Parallel Repetition of (k1, đots , kμ )-Special-Sound Multi-round Interactive Proofs
Thomas Attema, Serge Fehr |
CRYPTO (1) | 1 |
| 2022 | Vector Commitments over Rings and Compressed $\varSigma $-Protocols
Thomas Attema, Ignacio Cascudo, Ronald Cramer, Ivan Damgård, Daniel Escudero 0001 |
TCC (1) | 1 |
| 2022 | Fiat-Shamir Transformation of Multi-round Interactive Proofs
Thomas Attema, Serge Fehr, Michael Klooß |
TCC (1) | 1 |
| 2021 | Compressed $\varSigma $-Protocols for Bilinear Group Arithmetic Circuits and Application to Logarithmic Transparent Threshold Signatures
Thomas Attema, Ronald Cramer, Matthieu Rambaud |
ASIACRYPT (4) | 1 |
| 2021 | Compressing Proofs of k-Out-Of-n Partial Knowledge
Thomas Attema, Ronald Cramer, Serge Fehr |
CRYPTO (4) | 1 |
| 2021 | A Compressed $\varSigma $-Protocol Theory for Lattices
Thomas Attema, Ronald Cramer, Lisa Kohl |
CRYPTO (2) | 1 |
| 2021 | Brief Announcement: Malicious Security Comes for Free in Consensus with LeadersabstractWe consider consensus protocols in the model that is most commonly considered for use in state machine replication, as initiated by Dwork-Lynch-Stockmeyer, then by Castro-Liskov in 1999 with "PBFT." Such protocols guarantee, assuming n players out of which t < n/3 are maliciously corrupted, that the honest players output the same valid value within a finite number of messages, after the (unknown) point in time where both: the network becomes synchronous, and a designated player (the leader) is honest. The state of the art (Hotstuff, PODC'19), achieves linear communication complexity, but at the cost of additional latency, due to one more round-trip with the leader. Furthermore, it relies on constant-size threshold signatures schemes (TSS), for which all prior-known constructions require a costly interactive (or trusted) setup. We remove all of these limitations. The communication bottleneck of PBFT lies in the subprotocol, denoted as "view change," in which the leader forwards 2t+1 signed messages to each player. Then, each player checks that these 2t+1 messages satisfy some predicate, which we denote "non-supermajority''. We replace this with a responsive subprotocol, with linear communication complexity, that enables players to check this predicate. Its construction is elementary, since it requires only black box use of any TSS. In the full version of our paper \citemalicious2 we achieve three things. Firstly, we further optimize this subprotocol from succinct arguments of many signed messages, which we instantiate from Attema-Cramer-Rambaud \cite[2021-3-9 version]ACR20. As an introduction to these methods, we discuss here the simplest case, which is the construction in \citeACR20 of the first logarithmic-sized TSS with transparent setup. Second, we also address another complexity challenge pointed in Hotstuff, namely, that protocols with fast termination in favorable runs, have so far quadratic complexity, due to an even more complex view change. Third, we enable halting in finite time with (amortized) linear complexity, which was an unsolved question so far when external validity is required. Mark Abspoel, Thomas Attema, Matthieu Rambaud |
PODC | 2 |
| 2020 | Compressed $\varSigma $-Protocol Theory and Practical Application to Plug & Play Secure Algorithmics
Thomas Attema, Ronald Cramer |
CRYPTO (3) | 1 |
| 2020 | Practical Product Proofs for Lattice Commitments
Thomas Attema, Vadim Lyubashevsky, Gregor Seiler |
CRYPTO (2) | 1 |
| 2017 | Internal Network Monitoring and Anomaly Detection through Host ClusteringabstractInternal network traffic is an undervalued source of information for detecting targeted attacks. Whereas most systems focus on the external border of the network, we observe that targeted attacks campaigns often involve internal network activity. To this end, we have developed techniques capable of detecting anomalous internal network behaviour. As a second contribution we propose an additional step in the model-based anomaly detection involving host clustering. Through host clustering, individual hosts are grouped together on the basis of their internal network behaviour. We argue that a behavioural model for each cluster, compared to a model for each host or a single model for all hosts, performs better in terms of detecting potentially malicious behaviour. We show that by applying this concept to internal network traffic, the detection performance for identifying malicious flows and hosts increases. Copyright © 2017 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved. Institute for Systems and Technologies of Information, Control and Communication (INSTICC) Wietze J. B. Beukema, Thomas Attema, Harm A. Schotanus |
ICISSP | 2 |
| 2015 | Development and Evaluation of Multi-Agent Models Predicting Twitter Trends in Multiple DomainsabstractThis paper concerns multi-agent models predicting Twitter trends. We use a step-wise approach to develop a novel agent-based model with the following properties: (1) it uses individual behavior parameters for a set of Twitter users and (2) it uses a retweet graph to model the underlying social network structure of these Twitter users to predict trends. The model parameters can be optimized using empirical data. To investigate to what extend this agent-based model can predict Twitter trends, we validate the model performance on two case studies using real Twitter data: tweets on banks and tweets on universities. We furthermore compare a version of the model that only uses the retweet graph (PM1) with the model that also simulates individual behavior (PM2) for small to larger prediction time intervals. For both case studies the results show that PM1 performs better for small prediction time intervals (up to one day in the future), while PM2 performs better for larger time intervals (from a day to a week). We think this opens up the possibility to use similar models for helping organizations to extend their monitoring capabilities of social media with predictive modeling and to become more pro-active and less reactive. Thomas Attema, Peter-Paul van Maanen, Erik Meeuwissen |
ASONAM | 1 |