VLDB 2026 Research / reviewers in the wild / expert
Yosuke Todo
dblp:44/10381
· DBLP profile ↗
47ranked-venue papers
15as first author
17since 2021 · last 2026
0000-0002-6839-4777ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 43 · 14 first-author · 16 since 2021Systems, architecture and hardware · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Is the Hard-Label Cryptanalytic Model Extraction Really Polynomial?
Akira Ito 0002, Takayuki Miura, Yosuke Todo |
CRYPTO (7) | 3 |
| 2026 | Practical committing attacks against Rocca-SabstractThis paper shows practical committing attacks against Rocca-S, an authenticated encryption with associated data scheme designed for 6G applications. Previously, the best complexity of the attack was 2 64 by Derbez et al. in ToSC 2024(1)/FSE 2024. We show that the committing attack against Rocca by Takeuchi et al. in ToSC 2024(2)/FSE 2025 can be applied to Rocca-S, where Rocca is an earlier version of Rocca-S. We show a concrete test vector of our attack. We also point out a committing attack that exploits equivalent keys. Ryunosuke Takeuchi, Yosuke Todo, Tetsu Iwata |
Inf. Process. Lett. | 2 |
| 2025 | Divide-and-Conquer Trail Enumeration Puncturing: Application to Salsa and ChaCha
Antonio Flórez-Gutiérrez, Yosuke Todo |
ASIACRYPT (1) | 2 |
| 2025 | Improved Cryptanalysis of ChaCha: Beating PNBs with Bit Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo |
EUROCRYPT (1) | 2 |
| 2025 | Improving Linear Key Recovery Attacks using Walsh Spectrum Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo |
J. Cryptol. | 2 |
| 2024 | Multiple-Tweak Differential Attack Against SCARF
Christina Boura, Shahram Rasoolzadeh, Dhiman Saha, Yosuke Todo |
ASIACRYPT (7) | 4 |
| 2024 | General Practical Cryptanalysis of the Sum of Round-Reduced Block Ciphers and ZIP-AES
Antonio Flórez-Gutiérrez, Lorenzo Grassi 0001, Gregor Leander, Ferdinand Sibleyras, Yosuke Todo |
ASIACRYPT (9) | 5 |
| 2024 | Improving Linear Key Recovery Attacks Using Walsh Spectrum Puncturing
Antonio Flórez-Gutiérrez, Yosuke Todo |
EUROCRYPT (1) | 2 |
| 2023 | Keyed Sum of Permutations: A Simpler RP-Based PRF
Ferdinand Sibleyras, Yosuke Todo |
CT-RSA | 2 |
| 2023 | SCARF - A Low-Latency Block Cipher for Secure Cache-Randomization
Federico Canale, Tim Güneysu, Gregor Leander, Jan Philipp Thoma, Yosuke Todo, Rei Ueno |
USENIX Security Symposium | 5 |
| 2022 | A Modular Approach to the Incompressibility of Block-Cipher-Based AEADs
Akinori Hosoyamada, Takanori Isobe 0001, Yosuke Todo, Kan Yasuda |
ASIACRYPT (2) | 3 |
| 2022 | New Attacks from Old Distinguishers Improved Attacks on Serpent
Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo |
CT-RSA | 7 |
| 2022 | Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo |
J. Cryptol. | 8 |
| 2021 | Strong and Tight Security Guarantees Against Integral Distinguishers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo |
ASIACRYPT (1) | 4 |
| 2021 | Massive Superpoly Recovery with Nested Monomial Predictions
Kai Hu 0001, Siwei Sun, Yosuke Todo, Meiqin Wang 0001, Qingju Wang 0001 |
ASIACRYPT (1) | 3 |
| 2021 | Designing S-Boxes Providing Stronger Security Against Differential Cryptanalysis for Ciphers Using Byte-Wise XOR
Yosuke Todo, Yu Sasaki 0001 |
SAC | 1 |
| 2021 | Modeling for Three-Subset Division Property without Unknown Subset
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
J. Cryptol. | 4 |
| 2020 | Lower Bounds on the Degree of Block Ciphers
Phil Hebborn, Baptiste Lambin, Gregor Leander, Yosuke Todo |
ASIACRYPT (1) | 4 |
| 2020 | Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Gregor Leander, Yosuke Todo |
CRYPTO (3) | 3 |
| 2020 | Out of Oddity - New Cryptanalytic Techniques Against Symmetric Primitives Optimized for Integrity Proof Systems
Tim Beyne, Anne Canteaut, Itai Dinur, Maria Eichlseder, Gregor Leander, Gaëtan Leurent, María Naya-Plasencia, Léo Perrin, Yu Sasaki 0001, Yosuke Todo, Friedrich Wiemer |
CRYPTO (3) | 10 |
| 2020 | Modeling for Three-Subset Division Property Without Unknown Subset - Improved Cube Attacks Against Trivium and Grain-128AEAD
Yonglin Hao, Gregor Leander, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
EUROCRYPT (1) | 4 |
| 2020 | PRINCEv2 - More Security for (Almost) No Overhead
Dusan Bozilov, Maria Eichlseder, Miroslav Knezevic, Baptiste Lambin, Gregor Leander, Thorben Moos, Ventzislav Nikov, Shahram Rasoolzadeh, Yosuke Todo, Friedrich Wiemer |
SAC | 9 |
| 2019 | On the Data Limitation of Small-State Stream Ciphers: Correlation Attacks on Fruit-80 and Plantlet
Yosuke Todo, Willi Meier, Kazumaro Aoki |
SAC | 1 |
| 2019 | Nonlinear Invariant Attack: Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001 |
J. Cryptol. | 1 |
| 2019 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of SuperpolyabstractAt CRYPTO 2017 and IEEE Transactions on Computers in 2018, Todo et al. proposed the division property based cube attack method making it possible to launch cube attacks with cubes of dimensions far beyond practical reach. However, assumptions are made to validate their attacks. In this paper, we further formulate the algebraic properties of the superpoly in one framework to facilitate cube attacks in more successful applications: we propose the “flag” technique to enhance the precision of MILP models, which enable us to identify proper non-cube IV assignments; a degree evaluation algorithm is presented to upper bound the degree of the superpoly s.t. the superpoly can be recovered without constructing its whole truth table and overall complexity of the attack can be largely reduced; we provide a divide-and-conquer strategy to Trivium-like stream ciphers namely Trivium, Kreyvium, TriviA-SC1/2 so that the large scale MILP models can be split into several small solvable ones enabling us to analyze Trivium-like primitives with more than 1000 initialization rounds; finally, we provide a term enumeration algorithm for finding the monomials of the superpoly, so that the complexity of many attacks can be further reduced. We apply our techniques to attack the initialization of several ciphers namely 839-round Trivium, 891-round Kreyvium, 1009-round TriviA-SC1, 1004-round TriviA-SC2, 184-round Grain-128a and 750-round Acorn respectively. Yonglin Hao, Takanori Isobe 0001, Lin Jiao, Chaoyun Li, Willi Meier, Yosuke Todo, Qingju Wang 0001 |
IEEE Trans. Computers | 6 |
| 2018 | Programming the Demirci-Selçuk Meet-in-the-Middle Attack with Constraints
Danping Shi, Siwei Sun, Patrick Derbez, Yosuke Todo, Bing Sun 0001, Lei Hu 0003 |
ASIACRYPT (2) | 4 |
| 2018 | Several MILP-Aided Attacks Against SNOW 2.0
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii |
CANS | 2 |
| 2018 | Fast Correlation Attack Revisited - Cryptanalysis on Full Grain-128a, Grain-128, and Grain-v1
Yosuke Todo, Takanori Isobe 0001, Willi Meier, Kazumaro Aoki, Bin Zhang 0003 |
CRYPTO (2) | 1 |
| 2018 | Improved Division Property Based Cube Attacks Exploiting Algebraic Properties of Superpoly
Qingju Wang 0001, Yonglin Hao, Yosuke Todo, Chaoyun Li, Takanori Isobe 0001, Willi Meier |
CRYPTO (1) | 3 |
| 2018 | On the Complexity of Impossible Differential CryptanalysisabstractWhile impossible differential attack is one of the most well-known and familiar techniques for symmetric-key cryptanalysts, its subtlety and complicacy make the construction and verification of such attacks difficult and error-prone. We introduce a new set of notations for impossible differential analysis. These notations lead to unified formulas for estimation of data complexities of ordinary impossible differential attacks and attacks employing multiple impossible differentials. We also identify an interesting point from the new formulas: in most cases, the data complexity is only related to the form of the underlying distinguisher and has nothing to do with how the differences at the beginning and the end of the distinguisher propagate in the outer rounds. We check the formulas with some examples, and the results are all matching. Since the estimation of the time complexity is flawed in some situations, in this work, we show under which condition the formula is valid and give a simple time complexity estimation for impossible differential attack which is always achievable. Qianqian Yang 0003, Lei Hu 0003, Danping Shi, Yosuke Todo, Siwei Sun |
Secur. Commun. Networks | 4 |
| 2018 | Tight Bounds of Differentially and Linearly Active S-Boxes and Division Property of LilliputabstractThis paper provides security analysis of a lightweight block cipher called LILLIPUT, which was proposed in IEEE Transactions on Computers in 2015. LILLIPUT adopts an extended generalized Feistel network (EGFN). EGFN consists of non-linear, linear, and permutation layers, and the linear layer updates a part of the state only linearly, which causes several security concerns. Our first discovery is that the lower bounds of the number of differentially active S-boxes provided by the designers are incorrect. Thus the new bounds are derived by using mixed integer linear programming (MILP). We apply a two-stage search procedure introduced by Sun et al. that leads to tight bounds even for a large number of rounds. The search tool is then converted for linear cryptanalysis. With those updates, the challenging problem of evaluating LILLIPUT's security against differential and linear cryptanalysis is closed. Another contribution is the best third-party cryptanalysis. The designers expected EGFN to efficiently enhance security against integral cryptanalysis. However, security is not as enhanced as the designers expected. In fact, division property finds a 13-round distinguisher that improves on the previous distinguisher by 4 rounds. The distinguisher is further extended to a 17-round key recovery that improves on the previous best attack by 3 rounds. Yu Sasaki 0001, Yosuke Todo |
IEEE Trans. Computers | 2 |
| 2018 | Cube Attacks on Non-Blackbox Polynomials Based on Division PropertyabstractThe cube attack is a powerful cryptanalytic technique and is especially powerful against stream ciphers. Since we need to analyze the complicated structure of a stream cipher in the cube attack, the cube attack basically analyzes it by regarding it as a blackbox. Therefore, the cube attack is an experimental attack, and we cannot evaluate the security when the size of cube exceeds an experimental range, e.g., 40. In this paper, we propose cube attacks on non-blackbox polynomials. Our attacks are developed by using the division property, which is recently applied to various block ciphers. The clear advantage is that we can exploit large cube sizes because it never regards the cipher as a blackbox. We apply the new cube attack to Trivium, Grain128a, ACORN and Kreyvium. As a result, the secret keys of 832-round Trivium, 183-round Grain128a, 704-round ACORN and 872-round Kreyvium are recovered. These attacks are the current best key-recovery attack against these ciphers. Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier |
IEEE Trans. Computers | 1 |
| 2017 | Improved Integral Attack on HIGHT
Yuki Funabiki, Yosuke Todo, Takanori Isobe 0001, Masakatu Morii |
ACISP (1) | 2 |
| 2017 | GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption
Subhadeep Banik, Sumit Kumar Pandey, Thomas Peyrin, Yu Sasaki 0001, Siang Meng Sim, Yosuke Todo |
CHES | 6 |
| 2017 | Gimli : A Cross-Platform Permutation
Daniel J. Bernstein, Stefan Kölbl, Stefan Lucks, Pedro Maat Costa Massolino, Florian Mendel, Kashif Nawaz, Tobias Schneider 0002, Peter Schwabe, François-Xavier Standaert, Yosuke Todo, Benoît Viguier |
CHES | 10 |
| 2017 | Cube Attacks on Non-Blackbox Polynomials Based on Division Property
Yosuke Todo, Takanori Isobe 0001, Yonglin Hao, Willi Meier |
CRYPTO (3) | 1 |
| 2017 | New Impossible Differential Search Tool from Design and Cryptanalysis Aspects - Revealing Structural Properties of Several Ciphers
Yu Sasaki 0001, Yosuke Todo |
EUROCRYPT (3) | 2 |
| 2017 | Integral Cryptanalysis on Full MISTY1
Yosuke Todo |
J. Cryptol. | 1 |
| 2016 | Wide Trail Design Strategy for Binary MixColumns - Enhancing Lower Bound of Number of Active S-boxes
Yosuke Todo, Kazumaro Aoki |
ACNS | 1 |
| 2016 | Nonlinear Invariant Attack - Practical Attack on Full SCREAM, iSCREAM, and Midori64
Yosuke Todo, Gregor Leander, Yu Sasaki 0001 |
ASIACRYPT (2) | 1 |
| 2016 | Compact Representation for Division Property
Yosuke Todo, Masakatu Morii |
CANS | 1 |
| 2016 | Bit-Based Division Property and Application to Simon Family
Yosuke Todo, Masakatu Morii |
FSE | 1 |
| 2016 | New Differential Bounds and Division Property of Lilliput: Block Cipher with Extended Generalized Feistel Network
Yu Sasaki 0001, Yosuke Todo |
SAC | 2 |
| 2015 | Integral Cryptanalysis on Full MISTY1
Yosuke Todo |
CRYPTO (1) | 1 |
| 2015 | Structural Evaluation by Generalized Integral Property
Yosuke Todo |
EUROCRYPT (1) | 1 |
| 2014 | FFT Key Recovery for Integral Attack
Yosuke Todo, Kazumaro Aoki |
CANS | 1 |
| 2013 | Upper Bounds for the Security of Several Feistel Networks
Yosuke Todo |
ACISP | 1 |