VLDB 2026 Research / reviewers in the wild / expert
Jonas Thietke
dblp:394/6678
· DBLP profile ↗
4ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0001-9388-5324ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | One (Noisy) Bit to Rule Them All: Key Recovery from Randomness Leakage in ML-DSAabstractAbstract The Fiat-Shamir transform is one of the most widely applied methods for secure signature construction. Fiat-Shamir starts with an interactive zero-knowledge identification protocol and transforms this via a hash function into a non-interactive signature. The protocol’s zero-knowledge property ensures that a signature does not leak information on its secret key $${\textbf{s}}$$ s , which is achieved by blinding $$\vec {s}$$ s → via proper randomness $${\textbf{y}}$$ y . Most prominent Fiat-Shamir examples are EC-DSA signatures and the new post-quantum standard ML-DSA (aka Dilithium). In practice, EC-DSA signatures have experienced fatal attacks via leakage of a few bits of the randomness $${\textbf{y}}$$ y per signature. Similar attacks now emerge for lattice-based signatures, such as ML-DSA. We build on, improve and generalize the pioneering leakage attack on ML-DSA by Liu, Zhou, Sun, Wang, Zhang, and Ming. Using a transformation to Integer LWE (ILWE), their attack can recover a 256-dimensional subkey of ML-DSA-44 from leakage in a single bit of $$\textbf{y}$$ y per signature, in any bit position $$j \ge 6$$ j ≥ 6 . However, the number of required signatures grows exponentially as $$4^j$$ 4 j . In this work, we show that not all leaky signatures carry information about the secret subkey. We introduce the notion of informative signature relations. This notion allows us to define a preprocessing step, called filter-and-shift that leads to ILWE instances that require a smaller sample amount. Unlike the standard ILWE transformation, filter-and-shift exploits the smallness of secret keys, and therefore might be of independent cryptanalytic interest. In comparison to Liu et al., for $$j=6$$ j = 6 we require only a quarter of the signatures and reduce the exponential growth to $$2^j$$ 2 j . In addition, we show that the secret subkey can be recovered even with a leak bit corrupted by a large amount of noise, in theory up to the maximum of $$50\%$$ 50 % . Experimentally, we still recover the secret with $$43\%$$ 43 % noise, where we need 170 times as many signatures as in the noise-free setting. The attack applies more generally to all Fiat-Shamir-type lattice-based signatures. For a signature scheme based on module LWE over an $$\ell $$ ℓ -dimensional module, the attack uses a 1-bit leak per signature to efficiently recover a $$\frac{1}{\ell }$$ 1 ℓ -fraction of the secret key. In the ring LWE setting, which can be seen as module LWE with $$\ell = 1$$ ℓ = 1 , the attack recovers the whole key. Simon Damm, Nicolai Kraus, Alexander May 0001, Julian Nowakowski, Jonas Thietke |
J. Cryptol. | 5 |
| 2025 | Solving Concealed ILWE and Its Application for Breaking Masked Dilithium
Simon Damm, Asja Fischer, Alexander May 0001, Soundes Marzougui, Leander Schwarz, Henning Seidler, Jean-Pierre Seifert, Jonas Thietke, Vincent Ulitzsch |
ASIACRYPT (2) | 8 |
| 2025 | Black-Box Forgery Attacks on Semantic Watermarks for Diffusion ModelsabstractIntegrating watermarking into the generation process of latent diffusion models (LDMs) simplifies detection and attribution of generated content. Semantic watermarks, such as Tree-Rings and Gaussian Shading, represent a novel class of watermarking techniques that are easy to implement and highly robust against various perturbations. However, our work demonstrates a fundamental security vulnerability of semantic watermarks. We show that attackers can leverage unrelated models, even with different latent spaces and architectures (UNet vs DiT), to perform powerful and realistic forgery attacks. Specifically, we design two watermark forgery attacks. The first imprints a targeted watermark into real images by manipulating the latent representation of an arbitrary image in an unrelated LDM to get closer to the latent representation of a watermarked image. We also show that this technique can be used for watermark removal. The second attack generates new images with the target watermark by inverting a watermarked image and re-generating it with an arbitrary prompt. Both attacks just need a single reference image with the target watermark. Overall, our findings question the applicability of semantic watermarks by revealing that attackers can easily forge or remove these watermarks under realistic conditions.Github: https://github.com/and-mill/semantic-forgery Andreas Müller 0025, Denis Lukovnikov, Jonas Thietke, Asja Fischer, Erwin Quiring |
CVPR | 3 |
| 2025 | One Bit to Rule Them All - Imperfect Randomness Harms Lattice Signatures
Simon Damm, Nicolai Kraus, Alexander May 0001, Julian Nowakowski, Jonas Thietke |
PKC (1) | 5 |