VLDB 2026 Research / reviewers in the wild / expert
Paola de Perthuis
dblp:303/4547
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-4222-522XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Post-quantum Privacy for Traceable Receipt-Free Encryption
Paola de Perthuis, Thomas Peters |
PKC (4) | 1 |
| 2026 | Refined Modelling of the Primal Attack, and Variants Against Module-LWE
Paola de Perthuis, Filip Trenkic |
PQCrypto (2) | 1 |
| 2025 | Predicting Module-Lattice ReductionabstractIs module-lattice reduction better than unstructured lattice reduction? This question was highlighted as ‘Q8’ in the Kyber NIST standardization submission (Avanzi et al., 2021), as potentially affecting the concrete security of Kyber and other module-lattice-based schemes. Foundational works on module-lattice reduction (Lee, Pellet-Mary, Stehlé, and Wallet, ASIACRYPT 2019; Mukherjee and Stephens-Davidowitz, CRYPTO 2020) confirmed the existence of such module variants of LLL and block-reduction algorithms, but focus only on provable worst-case asymptotic behavior. In this work, we present a concrete average-case analysis of module-lattice reduction. Specifically, we address the question of the expected slope after running module-BKZ, and pinpoint the discriminant $$\varDelta _K$$ of the number field at hand as the main quantity driving this slope. We convert this back into a gain or loss on the blocksize $$\beta $$ : module-BKZ in a number field K of degree d requires an SVP oracle of dimension $$\beta + \ln (|\varDelta _K| / d^d)\beta /(d\ln \beta ) + o(\beta / \ln \beta )$$ to reach the same slope as unstructured BKZ with blocksize $$\beta $$ . This asymptotic summary hides further terms that we predict concretely using experimentally verified heuristics. Incidentally, we provide the first open-source implementation of module-BKZ for some cyclotomic fields. For power-of-two cyclotomic conductors, we have $$|\varDelta _K| = d^d$$ , and conclude that module-BKZ needs a blocksize larger than its unstructured counterpart. On the contrary, for all other cyclotomic fields, $$|\varDelta _K| < d^d$$ , so module-BKZ provides a sublinear $$\varTheta (\beta /\ln \beta )$$ gain on the required blocksize, yielding a subexponential speedup of $$\exp (\varTheta (\beta /\ln \beta ))$$ . Léo Ducas, Lynn Engelberts, Paola de Perthuis |
ASIACRYPT (3) | 3 |
| 2025 | Security Analysis of Covercrypt: A Quantum-Safe Hybrid Key Encapsulation Mechanism for Hidden Access Policies
Théophile Brézot, Chloé Hébant, Paola de Perthuis, David Pointcheval |
ESORICS (2) | 3 |
| 2023 | Cuckoo Commitments: Registration-Based Encryption and Key-Value Map Commitments for Large Spaces
Dario Fiore 0001, Dimitris Kolonelos, Paola de Perthuis |
ASIACRYPT (5) | 3 |
| 2023 | Covercrypt: An Efficient Early-Abort KEM for Hidden Access Policies with Traceability from the DDH and LWE
Théophile Brézot, Paola de Perthuis, David Pointcheval |
ESORICS (1) | 2 |
| 2022 | Two-Client Inner-Product Functional Encryption with an Application to Money-Laundering DetectionabstractIn this paper, we extend Inner-Product Functional Encryption (IPFE), where there is just a vector in the key and a vector in the single sender's ciphertext, to two-client ciphertexts. More precisely, in our two-client functional encryption scheme, there are two Data Providers who can independently encrypt vectors x and y for a data consumer who can, from a functional decryption key associated to a vector α, compute ∑αi xiyi = x ⋅ Diag(α) ⋅ yT. Ciphertexts are linear in the dimension of the vectors, whereas the functional decryption keys are of constant size. We study two interesting particular cases: Paola de Perthuis, David Pointcheval |
CCS | 1 |