Xiaoyang Dong 0001

dblp:148/1597 · DBLP profile ↗
← Back
48ranked-venue papers
11as first author
30since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 9 first-author · 24 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 2 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Algebraic Attack on Convolutional Neural Networks with Max Pooling
Shi Tang, Zhengchao Gao, Yongjia Su, Lingyue Qin, Xiaoyang Dong 0001
CRYPTO (7)6
2026 Guess-and-Determine Rebound Revisited: Full Quantum Collision Attack on AES-256 in DM Hash Mode
Liyuan Tang, Lingyue Qin, Shiqi Hou, Xiaoyang Dong 0001
CRYPTO (5)4
2026 New Records in Collision Attacks on SHA-2
Yingxin Li, Fukang Liu, Gaoli Wang, Haifeng Qian, Xiaoyang Dong 0001, Siwei Sun, Danping Shi
J. Cryptol.5
2025 Delving into Cryptanalytic Extraction of PReLU Neural Networks
Yi Chen 0011, Xiaoyang Dong 0001, Yantian Shen, Anyu Wang 0001, Xiaoyun Wang 0001
ASIACRYPT (2)2
2025 Towards Combined Countermeasures against Differential Computation and Fault Analyses: An Approach with the ASASA Structure
Yufeng Tang, Jian Guo 0001, Xiaoyang Dong 0001, Liangju Zhao
ASIACRYPT (2)4
2025 Guess-and-Determine Rebound: Applications to Key Collisions on AES
Lingyue Qin, Wenquan Bi, Xiaoyang Dong 0001
CRYPTO (5)3
2025 Triangulating Meet-in-the-Middle Attack
Boxin Zhao, Qingliang Hou, Lingyue Qin, Xiaoyang Dong 0001
CRYPTO (5)4
2025 Meet-in-the-Middle Attack on Primitives with Binary Matrix Linear Layer
Qingliang Hou, Kuntong Li, Guoyan Zhang, Yanzhao Shen, Qidi You, Xiaoyang Dong 0001
CT-RSA6
2025 Exploiting output bits and the χ operation in MitM preimage attacks on Keccak
Tianling Weng, Gaoli Wang, Keting Jia, Xiaoyang Dong 0001, Siwei Sun, Tingting Cui
Des. Codes Cryptogr.4
2025 Quantum rectangle attack and its application on Deoxys-BC
Yinsong Xu 0001, Yi-Bo Luo, Qidi You, Xiaoyang Dong 0001
Des. Codes Cryptogr.7
2024 Hard-Label Cryptanalytic Extraction of Neural Network Models
Yi Chen 0011, Xiaoyang Dong 0001, Jian Guo 0001, Yantian Shen, Anyu Wang 0001, Xiaoyun Wang 0001
ASIACRYPT (8)2
2024 The First Practical Collision for 31-Step SHA-256
Yingxin Li, Fukang Liu, Gaoli Wang, Xiaoyang Dong 0001, Siwei Sun
ASIACRYPT (7)4
2024 Generic MitM Attack Frameworks on Sponge Constructions
Xiaoyang Dong 0001, Boxin Zhao, Lingyue Qin, Qingliang Hou, Xiaoyun Wang 0001
CRYPTO (4)1
2024 Improved Related-Key Rectangle Attacks On GIFT
abstract
Abstract GIFT is a lightweight cipher proposed by Banik et al. at CHES’17, motivated by the design strategy of PRESENT. GIFT-64[2021] is a variant of GIFT proposed by Sun et al. at EUROCRYPT’22 to achieve better resistance against differential attack while maintaining a similar security level against linear attack. At EUROCRYPT’22, Dong et al. proposed a new rectangle framework considering the key guessing strategies for linear key-schedule ciphers, and established a uniform automatic search model for the whole rectangle attack. In this paper, we extend it to be applicable to bit-oriented ciphers, and construct an automatic search model involved in the distinguisher and key-recovery phase for GIFT. Moreover, we utilize the key relations of the linear key-schedule to the model, and find some new distinguishers both for GIFT-64 and GIFT-64[2021]. To evaluate the probability more accurately, we propose a method to calculate the probability of the 2-round middle part which connects the boomerang distinguisher for GIFT, and apply it with the SAT method to evaluate the probability of the whole distinguishers. As a result, we search out a new 20-round related-key boomerang distinguisher for GIFT-64, and achieve a 26-round attack with better time complexity than the best previous attack. For GIFT-64[2021], we find a 20-round boomerang distinguisher and give the first 26-round rectangle attack under related-key scenario.
Qingyuan Yu, Lingyue Qin, Xiaoyang Dong 0001, Keting Jia
Comput. J.3
2023 Quantum Attacks on Hash Constructions with Low Quantum Random Access Memory
Xiaoyang Dong 0001, Shun Li 0004, Phuong Pham, Guoyan Zhang
ASIACRYPT (3)1
2023 Automated Meet-in-the-Middle Attack Goes to Feistel
Qingliang Hou, Xiaoyang Dong 0001, Lingyue Qin, Guoyan Zhang, Xiaoyun Wang 0001
ASIACRYPT (3)2
2023 Quantum Attacks: A View of Data Complexity on Offline Simon's Algorithm
Tairong Shi, Xiaoyang Dong 0001, Xuan Shen, Yiyuan Luo
Inscrypt (2)3
2023 Meet-in-the-Middle Preimage Attacks on Sponge-Based Hashing
Lingyue Qin, Jialiang Hua, Xiaoyang Dong 0001, Hailun Yan, Xiaoyun Wang 0001
EUROCRYPT (4)3
2023 Low-Data Cryptanalysis On SKINNY Block Cipher
abstract
Abstract At CRYPTO 2021, Dong et al. proposed an automatic method of Meet-in-the-Middle (MITM) key-recovery attacks. In this paper, we further extend it to a new automatic model which can be used to find low-data complexity attacks. With the help of the automatic model, we propose MITM attacks against reduced-round versions of all the six members of the SKINNY family with extremely low-data complexity. More precisely, we present MITM attacks against 19-round SKINNY-$n$-$3n$, 15-round SKINNY-$n$-$2n$, 11-round SKINNY-$n$-$n$ with three, two, one plaintext-ciphertext pairs, separately. In addition, we can attack two more rounds and three more rounds with no more than $2^8$ and $2^{32}$ data complexity, respectively.
Jialiang Hua, Tai Liu, Yulong Cui, Lingyue Qin, Xiaoyang Dong 0001, Huiyong Cui
Comput. J.5
2023 Differential-Aided Preimage Attacks On Round-Reduced Keccak
abstract
Abstract At FSE 2008, Leurent introduced the preimage attack on MD4 by exploiting differential trails. In this paper, we apply the differential-aided preimage attack to Keccak with the message modification techniques. Instead of directly finding the preimage, we exploit differential characteristics to modify the messages, so that the differences of their hashing values and the changes of given target can be controlled. By adding some constraints, a trail can be used to change one bit at a time and reduce the time complexity by a factor of 2. When the number of rounds increases, we introduce two-stage modification techniques to satisfy part of constraints as well. In order to solve other constraints, we also combine the linear-structure technique and accordingly give a preimage attack on 5-round Keccak[$r=1440,c=160,l=80$].
Congming Wei, Xiaoyang Dong 0001, Willi Meier, Lingyue Qin, Ximing Fu
Comput. J.2
2023 Improved attacks against reduced-round Whirlwind
Congming Wei, Bingyou Dong, Jialiang Hua, Xiaoyang Dong 0001, Guoyan Zhang
Des. Codes Cryptogr.4
2022 Mind the TWEAKEY Schedule: Cryptanalysis on SKINNYe-64-256
Lingyue Qin, Xiaoyang Dong 0001, Anyu Wang 0001, Jialiang Hua, Xiaoyun Wang 0001
ASIACRYPT (1)2
2022 Triangulating Rebound Attack on AES-like Hashing
Xiaoyang Dong 0001, Jian Guo 0001, Shun Li 0004, Phuong Pham
CRYPTO (1)1
2022 Key Guessing Strategies for Linear Key-Schedule Algorithms in Rectangle Attacks
Xiaoyang Dong 0001, Lingyue Qin, Siwei Sun, Xiaoyun Wang 0001
EUROCRYPT (3)1
2021 Automatic Classical and Quantum Rebound Attacks on AES-Like Hashing by Exploiting Related-Key Differentials
Xiaoyang Dong 0001, Zhiyu Zhang 0009, Siwei Sun, Congming Wei, Xiaoyun Wang 0001, Lei Hu 0003
ASIACRYPT (1)1
2021 Meet-in-the-Middle Attacks Revisited: Key-Recovery, Collision, and Preimage Attacks
Xiaoyang Dong 0001, Jialiang Hua, Siwei Sun, Zheng Li 0008, Xiaoyun Wang 0001, Lei Hu 0003
CRYPTO (3)1
2021 Machine Learning Assisted Differential Distinguishers For Lightweight Ciphers
Anubhab Baksi, Jakub Breier, Yi Chen 0011, Xiaoyang Dong 0001
DATE4
2021 Automatic Search of Meet-in-the-Middle Preimage Attacks on AES-like Hashing
Zhenzhen Bao, Xiaoyang Dong 0001, Jian Guo 0001, Zheng Li 0008, Danping Shi, Siwei Sun, Xiaoyun Wang 0001
EUROCRYPT (1)2
2021 Key-dependent cube attack on reduced Frit permutation in Duplex-AE modes
Lingyue Qin, Xiaoyang Dong 0001, Keting Jia, Rui Zong
Sci. China Inf. Sci.2
2021 Interpolation Attacks on Round-Reduced Elephant, Kravatte and Xoofff
abstract
Abstract We introduce an interpolation attack using the Moebius Transform. This can reduce the time complexity to get a linear system of equations for specified intermediate state bits, which is general to cryptanalysis of some ciphers with update function of low algebraic degree. Along this line, we perform an interpolation attack against Elephant-Delirium, a round 2 submission of the ongoing national institute of standards and technology (NIST) lightweight cryptography project. This is the first third-party cryptanalysis on this cipher. Moreover, we promote the interpolation attack by applying it to the Farfalle pseudo-random constructions Kravatte and Xoofff. Our attacks turn out to be the most efficient method for these ciphers thus far.
Rui Zong, Xiaoyang Dong 0001, Keting Jia, Willi Meier
Comput. J.3
2020 Quantum Collision Attacks on AES-Like Hashing with Low Quantum Random Access Memories
Xiaoyang Dong 0001, Siwei Sun, Danping Shi, Xiaoyun Wang 0001, Lei Hu 0003
ASIACRYPT (2)1
2020 Practical Key-Recovery Attacks On Round-Reduced Ketje Jr, Xoodoo-AE And Xoodyak
abstract
Abstract A new conditional cube attack was proposed by Li et al. at ToSC 2019 for cryptanalysis of Keccak keyed modes. In this paper, we find a new property of Li et al.’s method. The conditional cube attack is modified and applied to cryptanalysis of 5-round Ketje Jr, 6-round Xoodoo-AE and Xoodyak, where Ketje Jr is among the third round CAESAR competition candidates and Xoodyak is a Round 2 submission of the ongoing NIST lightweight cryptography project. For the updated conditional cube attack, all our results are shown to be of practical time complexity with negligible memory cost, and test codes are provided. Notably, our results on Xoodyak represent the first third-party cryptanalysis for Xoodyak.
Zheng Li 0008, Xiaoyang Dong 0001, Keting Jia, Willi Meier
Comput. J.3
2020 Quantum attacks on some feistel block ciphers
Xiaoyang Dong 0001, Bingyou Dong, Xiaoyun Wang 0001
Des. Codes Cryptogr.1
2020 Generalized related-key rectangle attacks on block ciphers with linear key schedule: applications to SKINNY and GIFT
Boxin Zhao, Xiaoyang Dong 0001, Willi Meier, Keting Jia, Gaoli Wang
Des. Codes Cryptogr.2
2019 MILP-Based Differential Attack on Round-Reduced GIFT
Baoyu Zhu, Xiaoyang Dong 0001
CT-RSA2
2019 Improved Differential Attacks on GIFT-64
Huaifeng Chen, Rui Zong, Xiaoyang Dong 0001
ICICS3
2019 Quantum cryptanalysis on some generalized Feistel schemes
Xiaoyang Dong 0001, Zheng Li 0008, Xiaoyun Wang 0001
Sci. China Inf. Sci.1
2019 Related-tweakey impossible differential attack on reduced-round Deoxys-BC-256
Rui Zong, Xiaoyang Dong 0001, Xiaoyun Wang 0001
Sci. China Inf. Sci.2
2019 MILP-aided cube-attack-like cryptanalysis on Keccak Keyed modes
Wenquan Bi, Xiaoyang Dong 0001, Zheng Li 0008, Rui Zong, Xiaoyun Wang 0001
Des. Codes Cryptogr.2
2018 A Key-Recovery Attack on 855-round Trivium
Ximing Fu, Xiaoyun Wang 0001, Xiaoyang Dong 0001, Willi Meier
CRYPTO (2)3
2018 Quantum key-recovery attack on Feistel structures
Xiaoyang Dong 0001, Xiaoyun Wang 0001
Sci. China Inf. Sci.1
2018 Impossible differential attack on Simpira v2
Rui Zong, Xiaoyang Dong 0001, Xiaoyun Wang 0001
Sci. China Inf. Sci.2
2018 Conditional cube attack on round-reduced River Keyak
Wenquan Bi, Zheng Li 0008, Xiaoyang Dong 0001, Lu Li 0006, Xiaoyun Wang 0001
Des. Codes Cryptogr.3
2018 Improved integral attacks without full codebook
abstract
The integral attack, exploits the balanced property of the output in the distinguisher. Usually, adversaries append some rounds after the distinguisher, guess the corresponding key bits and check whether the target bits are balanced. Few works add rounds before the distinguisher to make the key recovery attack. In the first full‐round attack on MISTY1, Todo adds one FL layer (key‐dependent linear function) before the distinguisher. In this study, the authors extend his method and give a general method, which they can use to extend some rounds (non‐linear) before the distinguisher to attack more rounds with data complexity smaller than the whole space and little extra time consumption. The basic idea is that for different subkeys guessed in the forward rounds, they set different constant values for the input of the distinguisher. Finally, the selected data space is not full. For substitution permutation network (SPN) (Feistel with SPN round function) structures with 4 bit S‐box and bit permutation, they estimate the data complexity when adding one round before the distinguishers for all 4 bit S‐boxes. Using the method, they improve the integral attacks on PRESENT, RECTANGLE, TWINE and LBlock, and their results could cover one more round.
Zhihui Chu, Huaifeng Chen, Xiaoyun Wang 0001, Lu Li 0006, Xiaoyang Dong 0001, Yaoling Ding, Yonglin Hao
IET Inf. Secur.5
2018 Improved Integral Attacks on SIMON32 and SIMON48 with Dynamic Key-Guessing Techniques
abstract
Dynamic key-guessing techniques, which exploit the property of AND operation, could improve the differential and linear cryptanalytic results by reducing the number of guessed subkey bits and lead to good cryptanalytic results for SIMON. They have only been applied in differential and linear attacks as far as we know. In this paper, dynamic key-guessing techniques are first introduced in integral cryptanalysis. According to the features of integral cryptanalysis, we extend dynamic key-guessing techniques and get better integral cryptanalysis results than before. As a result, we present integral attacks on 24-round SIMON32, 24-round SIMON48/72, and 25-round SIMON48/96. In terms of the number of attacked rounds, our attack on SIMON32 is better than any previously known attacks, and our attacks on SIMON48 are the same as the best attacks.
Zhihui Chu, Huaifeng Chen, Xiaoyun Wang 0001, Xiaoyang Dong 0001, Lu Li 0006
Secur. Commun. Networks4
2017 Improved Conditional Cube Attacks on Keccak Keyed Modes with MILP Method
Zheng Li 0008, Wenquan Bi, Xiaoyang Dong 0001, Xiaoyun Wang 0001
ASIACRYPT (1)3
2015 Improved Attacks on Reduced-Round Camellia-128/192/256
Xiaoyang Dong 0001, Leibo Li, Keting Jia, Xiaoyun Wang 0001
CT-RSA1
2015 Meet-in-the-Middle Technique for Truncated Differential and Its Applications to CLEFIA and Camellia
Leibo Li, Keting Jia, Xiaoyun Wang 0001, Xiaoyang Dong 0001
FSE4