EDBT 2026 Demo / reviewers in the wild / expert
Tancrède Lepoint
dblp:08/11136
· DBLP profile ↗
37ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0003-3796-042XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 2 first-author · 7 since 2021Systems, architecture and hardware · 2Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Mario: Multi-round Multiple-Aggregator Secure Aggregation with Robustness against Malicious ActorsabstractFederated Learning (FL) enables multiple clients to collaboratively train a machine learning model while keeping their data private, eliminating the need for data sharing. Two common approaches to secure aggregation (SA) in FL are the single-aggregator and multiple-aggregator models. This work focuses on improving the multiple-aggregator model.Existing multiple-aggregator protocols such as Prio (NSDI 2017), Prio+ (SCN 2022), Elsa (S&P 2023) either offer robustness only in the presence of semi-honest servers or provide security without robustness and are limited to two aggregators. We introduce Mario, the first multiple-aggregator Secure Aggregation protocol that is both secure and robust in a malicious setting. Similar to prior work of Prio and Prio+, Mario provides secure aggregation in a setup of n servers and m clients. Unlike previous work, Mario removes the assumption of semi-honest servers, and provides a complete protocol with robustness under malicious clients and malicious servers. Our implementation shows that Mario is 3.40× and 283.4× faster than Elsa and Prio+, respecitively. Truong Son Nguyen, Tancrède Lepoint, Ni Trieu |
EuroS&P | 2 |
| 2025 | Verified Foundations for Differential PrivacyabstractDifferential privacy (DP) has become the gold standard for privacy-preserving data analysis, but implementing it correctly has proven challenging. Prior work has focused on verifying DP at a high level, assuming either that the foundations are correct or that a perfect source of random noise is available. However, the underlying theory of differential privacy can be very complex and subtle. Flaws in basic mechanisms and random number generation have been a critical source of vulnerabilities in real-world DP systems. In this paper, we present SampCert, the first comprehensive, mechanized foundation for executable implementations of differential privacy. SampCert is written in Lean with over 12,000 lines of proof. It offers a generic and extensible notion of DP, a framework for constructing and composing DP mechanisms, and formally verified implementations of Laplace and Gaussian sampling algorithms. SampCert provides (1) a mechanized foundation for developing the next generation of differentially private algorithms, and (2) mechanically verified primitives that can be deployed in production systems. Indeed, SampCert’s verified algorithms power the DP offerings of Amazon Web Services, demonstrating its real-world impact. SampCert’s key innovations include: (1) A generic DP foundation that can be instantiated for various DP definitions (e.g., pure, concentrated, Rényi DP); (2) formally verified discrete Laplace and Gaussian sampling algorithms that avoid the pitfalls of floating-point implementations; and (3) a simple probability monad and novel proof techniques that streamline the formalization. To enable proving complex correctness properties of DP and random number generation, SampCert makes heavy use of Lean’s extensive Mathlib library, leveraging theorems in Fourier analysis, measure and probability theory, number theory, and topology. Markus de Medeiros, Tancrède Lepoint, Temesghen Kahsai, Tristan Ravitch, Stefan Zetzsche, Anjali Joshi, Joseph Tassarotti, Aws Albarghouthi, Jean-Baptiste Tristan |
Proc. ACM Program. Lang. | 3 |
| 2023 | ACORN: Input Validation for Secure Aggregation
James Bell-Clark, Adrià Gascón, Tancrède Lepoint, Baiyu Li, Sarah Meiklejohn, Mariana Raykova 0001, Cathie Yun |
USENIX Security Symposium | 3 |
| 2022 | Communication-Efficient Proactive MPC for Dynamic Groups with Dishonest Majorities
Karim M. El Defrawy, Tancrède Lepoint, Antonin Leroux |
ACNS | 2 |
| 2022 | On the (in)Security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova 0001 |
J. Cryptol. | 2 |
| 2021 | Private Join and Compute from PIR with Default
Tancrède Lepoint, Sarvar Patel, Mariana Raykova 0001, Karn Seth, Ni Trieu |
ASIACRYPT (2) | 1 |
| 2021 | On the (in)security of ROS
Fabrice Benhamouda, Tancrède Lepoint, Julian Loss, Michele Orrù, Mariana Raykova 0001 |
EUROCRYPT (1) | 2 |
| 2021 | Communication-Computation Trade-offs in PIR
Asra Ali, Tancrède Lepoint, Sarvar Patel, Mariana Raykova 0001, Phillipp Schoppmann, Karn Seth, Kevin Yeo |
USENIX Security Symposium | 2 |
| 2020 | Communication-Efficient Proactive Secret Sharing for Dynamic Groups with Dishonest Majorities
Karim M. El Defrawy, Tancrède Lepoint, Antonin Leroux |
ACNS (1) | 2 |
| 2020 | Secure Single-Server Aggregation with (Poly)Logarithmic OverheadabstractSecure aggregation is a cryptographic primitive that enables a server to learn the sum of the vector inputs of many clients. Bonawitz et al. (CCS 2017) presented a construction that incurs computation and communication for each client linear in the number of parties. While this functionality enables a broad range of privacy preserving computational tasks, scaling concerns limit its scope of use. We present the first constructions for secure aggregation that achieve polylogarithmic communication and computation per client. Our constructions provide security in the semi-honest and the semi-malicious settings where the adversary controls the server and a δ-fraction of the clients, and correctness with up to δ-fraction dropouts among the clients. Our constructions show how to replace the complete communication graph of Bonawitz et al., which entails the linear overheads, with a k-regular graph of logarithmic degree while maintaining the security guarantees. Beyond improving the known asymptotics for secure aggregation, our constructions also achieve very efficient concrete parameters. The semi-honest secure aggregation can handle a billion clients at the per-client cost of the protocol of Bonawitz et al. for a thousand clients. In the semi-malicious setting with 10 4 clients, each client needs to communicate only with 3% of the clients to have a guarantee that its input has been added together with the inputs of at least 5000 other clients, while withstanding up to 5% corrupt clients and 5% dropouts. We also show an application of secure aggregation to the task of secure shuffling which enables the first cryptographically secure instantiation of the shuffle model of differential privacy. James Bell-Clark, Kallista A. Bonawitz, Adrià Gascón, Tancrède Lepoint, Mariana Raykova 0001 |
CCS | 4 |
| 2020 | Anonymous Tokens with Private Metadata Bit
Ben Kreuter, Tancrède Lepoint, Michele Orrù, Mariana Raykova 0001 |
CRYPTO (1) | 2 |
| 2019 | Public-Key Function-Private Hidden Vector Encryption (and More)
James Bartusek, Brent Carmer, Abhishek Jain 0002, Zhengzhong Jin, Tancrède Lepoint, Fermi Ma, Tal Malkin, Alex J. Malozemoff, Mariana Raykova 0001 |
ASIACRYPT (3) | 5 |
| 2019 | WAHC'19: 7th Workshop on Encrypted Computing & Applied Homomorphic CryptographabstractThe 7th Workshop on Encrypted Computing & Applied Homomorphic Cryptography (WAHC) will be held in London, United Kingdom, on November 11th, 2019, co-located with the ACM Conference on Computer and Communications Security (CCS). The purpose of the WAHC 2019 workshop is to bring together professionals, researchers and practitioners from academia, industry and government, to present, discuss and share the latest progress in the field of encrypted computing. Encrypted computing is a particular subfield of the area of computer security and applied cryptography, with an interest in practical applications of homomorphic encryption, multiparty computation, functional encryption, secure function evaluation, private information retrieval and searchable encryption. The workshop features an invited talk, that discusses how advanced cryptography is on its way to practice, a demonstration of an homomorphic encryption evaluation platform, and 6 exciting talks on different encrypting computing topics: homomorphic encryption standardization, multiparty computation, and applications. Michael Brenner 0003, Tancrède Lepoint, Kurt Rohloff |
CCS | 2 |
| 2019 | New Techniques for Obfuscating Conjunctions
James Bartusek, Tancrède Lepoint, Fermi Ma, Mark Zhandry |
EUROCRYPT (3) | 2 |
| 2019 | SNUSE: A secure computation approach for large-scale user re-enrollment in biometric authentication systems
Ivan Oliveira Nunes, Karim M. El Defrawy, Tancrède Lepoint |
Future Gener. Comput. Syst. | 3 |
| 2018 | Callisto: A Cryptographic Approach to Detecting Serial Perpetrators of Sexual MisconductabstractSexual misconduct is prevalent in workplace and education settings but stigma and risk of further damage deter many victims from seeking justice. Callisto, a non-profit that has created an online sexual assault reporting platform for college campuses, is expanding its work to combat sexual assault and harassment in other industries. In this new product, users will be invited to an online "matching escrow" that will detect repeat perpetrators and create pathways to support for victims. Users submit encrypted data about their perpetrator, and this data can only be decrypted by the Callisto Options Counselor (a lawyer), when another user enters the identity of the same perpetrator. If the perpetrator identities match, both users will be put in touch independently with the Options Counselor, who will connect them to each other (if appropriate) and help them determine their best path towards justice. The client relationships with the Options Counselors are structured so that any client-counselor communications would be privileged. A combination of client-side encryption, encrypted communication channels, oblivious pseudo-random functions, key federation, and Shamir Secret Sharing keep data confidential in transit, at rest, and during the matching process with the guarantee that only the lawyer ever has access to user submitted data, and even then only when a match is identified. Anjana Rajan, Lucy Qin, David W. Archer, Dan Boneh, Tancrède Lepoint, Mayank Varia |
COMPASS | 5 |
| 2018 | CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEMabstractRapid advances in quantum computing, together with the announcement by the National Institute of Standards and Technology (NIST) to define new standards for digitalsignature, encryption, and key-establishment protocols, have created significant interest in post-quantum cryptographic schemes. This paper introduces Kyber (part of CRYSTALS - Cryptographic Suite for Algebraic Lattices - a package submitted to NIST post-quantum standardization effort in November 2017), a portfolio of post-quantum cryptographic primitives built around a key-encapsulation mechanism (KEM), based on hardness assumptions over module lattices. Our KEM is most naturally seen as a successor to the NEWHOPE KEM (Usenix 2016). In particular, the key and ciphertext sizes of our new construction are about half the size, the KEM offers CCA instead of only passive security, the security is based on a more general (and flexible) lattice problem, and our optimized implementation results in essentially the same running time as the aforementioned scheme. We first introduce a CPA-secure public-key encryption scheme, apply a variant of the Fujisaki-Okamoto transform to create a CCA-secure KEM, and eventually construct, in a black-box manner, CCA-secure encryption, key exchange, and authenticated-key-exchange schemes. The security of our primitives is based on the hardness of Module-LWE in the classical and quantum random oracle models, and our concrete parameters conservatively target more than 128 bits of postquantum security. Joppe W. Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, Damien Stehlé |
EuroS&P | 4 |
| 2018 | Risks and Benefits of Side-Channels in BattlefieldsabstractAs networked devices and applications make their way into our battlefields, their behaviors need to take into account these highly adversarial cyber-physical environments. On the dark side of the spectrum, undesired side-channels put our sensitive data at risk; hence, side-channel-protected devices and implementations should be promoted. On the bright side of the spectrum, side-channel analysis may be correlated with observed and hidden events, and enable causality inference and watermarking. This paper describes some unique risks and benefits that may be obtained from side-channel analyses in battlefields. Ioannis Agadakos, Gabriela F. Ciocarlie, Bogdan Copos, Tancrède Lepoint, Ulf Lindqvist, Michael E. Locasto, James Michaelis |
FUSION | 4 |
| 2018 | BlockCIS - A Blockchain-Based Cyber Insurance SystemabstractWhile the cyber insurance market has been growing significantly in recent years, its insurance providers face several challenges: first, there is a lack of standardized frameworks to rate ""cyber""; second, there's a shortage of relevant data to calculate premiums; and third, security postures of insured organizations constantly change. Unlike other types of insurance, cyber insurance requires creating a continuous feedback loop between customers and insurers. In this article, we introduce BlockCIS, a blockchain-based continuous monitoring and processing system for cyber insurance. BlockCIS aims to realize an automated, real-time, and immutable feedback loop between the insurer, its customer, third parties and potential auditors. As an example instantiation, we prototype BlockCIS using the open source Hyperledger Composer blockchain framework. Tancrède Lepoint, Gabriela F. Ciocarlie, Karim M. El Defrawy |
IC2E | 1 |
| 2018 | Will Distributed Computing Revolutionize Peace? The Emergence of Battlefield IoTabstractAn upcoming frontier for distributed computing might literally save lives in future military operations. In civilian scenarios, significant efficiencies were gained from interconnecting devices into networked services and applications that automate much of everyday life from smart homes to intelligent transportation. The ecosystem of such applications and services is collectively called the Internet of Things (IoT). Can similar benefits be gained in a military context by developing an IoT for the battlefield? This paper describes unique challenges in such a context as well as potential risks, mitigation strategies, and benefits. Tarek F. Abdelzaher, Nora Ayanian, Tamer Basar, Suhas N. Diggavi, Jana Diesner, Deepak Ganesan, Ramesh Govindan, Susmit Jha, Tancrède Lepoint, Benjamin M. Marlin, Klara Nahrstedt, David M. Nicol, Ragunathan Rajkumar, Stephen Russell 0001, Sanjit A. Seshia, Fei Sha, Prashant J. Shenoy, Mani Srivastava 0001, Gaurav S. Sukhatme, Ananthram Swami, Paulo Tabuada, Don Towsley, Nitin H. Vaidya, Venugopal V. Veeravalli |
ICDCS | 9 |
| 2018 | Improved Security Proofs in Lattice-Based Cryptography: Using the Rényi Divergence Rather than the Statistical Distance
Shi Bai 0001, Tancrède Lepoint, Adeline Roux-Langlois, Amin Sakzad, Damien Stehlé, Ron Steinfeld |
J. Cryptol. | 2 |
| 2018 | Stream Ciphers: A Practical Solution for Efficient Homomorphic-Ciphertext Compression
Anne Canteaut, Sergiu Carpov, Caroline Fontaine, Tancrède Lepoint, María Naya-Plasencia, Pascal Paillier, Renaud Sirdey |
J. Cryptol. | 4 |
| 2017 | Optimization of Bootstrapping in CircuitsabstractIn 2009, Gentry proposed the first Fully Homomorphic Encryption (FHE) scheme, an extremely powerful cryptographic primitive that enables to perform computations, i.e., to evaluate circuits, on encrypted data without decrypting them first. This has many applications, particularly in cloud computing. In all currently known FHE schemes, encryptions are associated with some (non-negative integer) noise level. At each evaluation of an AND gate, this noise level increases. This increase is problematic because decryption succeeds only if the noise level stays below some maximum level L at every gate of the circuit. To ensure that property, it is possible to perform an operation called bootstrapping to reduce the noise level. Though critical, boostrapping is a time-consuming operation. This expense motivates a new problem in discrete optimization: minimizing the number of bootstrappings in a circuit while still controlling the noise level. In this paper, we (1) formally define the bootstrap problem, (2) design a polynomial-time L-approximation algorithm using a novel method of rounding of a linear program, and (3) show a matching hardness result: (L — ∊)- inapproximability for any ∊ > 0. Fabrice Benhamouda, Tancrède Lepoint, Claire Mathieu, Hang Zhou 0001 |
SODA | 2 |
| 2016 | Cryptanalysis of GGH15 Multilinear Maps
Jean-Sébastien Coron, Moon Sung Lee, Tancrède Lepoint, Mehdi Tibouchi |
CRYPTO (2) | 3 |
| 2016 | NFLlib: NTT-Based Fast Lattice Library
Carlos Aguilar Melchor, Joris Barrier, Serge Guelton, Adrien Guinet, Marc-Olivier Killijian, Tancrède Lepoint |
CT-RSA | 6 |
| 2016 | Stream Ciphers: A Practical Solution for Efficient Homomorphic-Ciphertext Compression
Anne Canteaut, Sergiu Carpov, Caroline Fontaine, Tancrède Lepoint, María Naya-Plasencia, Pascal Paillier, Renaud Sirdey |
FSE | 4 |
| 2015 | Improved Security Proofs in Lattice-Based Cryptography: Using the Rényi Divergence Rather Than the Statistical Distance
Shi Bai 0001, Adeline Roux-Langlois, Tancrède Lepoint, Damien Stehlé, Ron Steinfeld |
ASIACRYPT (1) | 3 |
| 2015 | Zeroizing Without Low-Level Zeroes: New MMAP Attacks and their Limitations
Jean-Sébastien Coron, Craig Gentry, Shai Halevi, Tancrède Lepoint, Hemanta K. Maji, Eric Miles, Mariana Raykova 0001, Amit Sahai, Mehdi Tibouchi |
CRYPTO (1) | 4 |
| 2015 | New Multilinear Maps Over the Integers
Jean-Sébastien Coron, Tancrède Lepoint, Mehdi Tibouchi |
CRYPTO (1) | 2 |
| 2015 | Cryptanalysis of the Co-ACD Assumption
Pierre-Alain Fouque, Moon Sung Lee, Tancrède Lepoint, Mehdi Tibouchi |
CRYPTO (1) | 3 |
| 2013 | Practical Multilinear Maps over the Integers
Jean-Sébastien Coron, Tancrède Lepoint, Mehdi Tibouchi |
CRYPTO (1) | 2 |
| 2013 | Lattice Signatures and Bimodal Gaussians
Léo Ducas, Alain Durmus, Tancrède Lepoint, Vadim Lyubashevsky |
CRYPTO (1) | 3 |
| 2013 | Batch Fully Homomorphic Encryption over the Integers
Jung Hee Cheon, Jean-Sébastien Coron, Moon Sung Lee, Tancrède Lepoint, Mehdi Tibouchi, Aaram Yun |
EUROCRYPT | 5 |
| 2013 | White-Box Security Notions for Symmetric Encryption Schemes
Cécile Delerablée, Tancrède Lepoint, Pascal Paillier, Matthieu Rivain |
Selected Areas in Cryptography | 2 |
| 2013 | Two Attacks on a White-Box AES Implementation
Tancrède Lepoint, Matthieu Rivain, Yoni De Mulder, Peter Roelse, Bart Preneel |
Selected Areas in Cryptography | 1 |
| 2012 | Partial Key Exposure on RSA with Private Exponents Larger Than N
Marc Joye, Tancrède Lepoint |
ISPEC | 2 |
| 2011 | Traitor tracing schemes for protected software implementationsabstractThis paper considers the problem of converting an encryption scheme into a scheme in which there is one encryption process but several decryption processes. Each decryption process is made available as a protected software implementation (decoder). So, when some digital content is encrypted, a legitimate user can recover the content in clear using its own private software implementation. Moreover, it is possible to trace a decoder in a black-box fashion in case it is suspected to be an illegal copy. Our conversions assume software tamper-resistance. Marc Joye, Tancrède Lepoint |
Digital Rights Management Workshop | 2 |