EDBT 2026 Demo / reviewers in the wild / expert
Sophia Yakoubov
dblp:152/5292
· DBLP profile ↗
17ranked-venue papers
0as first author
13since 2021 · last 2026
0000-0001-7958-8537ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 11 since 2021Theory of computation · 7 · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Ciphers to Future Cybersecurity: Engaging High School Students with Emerging Cryptographic Techniques through Hands-on ActivitiesabstractEmerging cryptographic techniques have the potential to transform foundational societal infrastructures, creating a need to teach their possibilities and limitations to support children’s and youths’ agency in this transformation. With this aim, we first surveyed cryptography experts (n=10) about which cryptographic techniques high school students should be taught. Next, we explored how one of the identified techniques, multi-party computation (MPC), can be taught in high school through a co-design process with five teachers. This process led to the design of four hands-on activities, which were evaluated with 96 high school students. Our findings demonstrate how high-school students can engage with an emerging cryptographic technique through hands-on activities that strategically black-box mathematics. We outline future research directions for teaching emerging cryptographic techniques in K-12 education and discuss how child-computer interaction can support children and youth in exploring future opportunities of cybersecurity. Mille Skovhus Lunding, Karl-Emil Kjær Bilstrup, Line Have Musaeus, Anna Hallenberg, Anne Kirstine Overgaard, Sophia Yakoubov, Marianne Graves Petersen |
IDC | 6 |
| 2025 | Asynchronous Algorand: Reaching Agreement with Near Linear Communication and Constant Expected TimeabstractThe celebrated Algorand protocol solves validated byzantine agreement in a scalable manner in the synchronous setting. In this paper, we study the feasibility of similar solutions in the asynchronous setting. Our main result is an asynchronous validated byzantine agreement protocol that we call Asynchronous Algorand. As with Algorand, it terminates in an expected constant number of rounds, and honest parties send an expected O(n polylog n) bits, where n is the number of parties. The protocol is resilient to a fully-asynchronous weak-adaptive adversary that can corrupt a near-optimal number of parties (< (1/3 - ϵ)n) and requires just a verifiable random function (VRF) setup and secure erasures. Ittai Abraham, Eli Chouatt, Yossi Gilad, Gilad Stern, Sophia Yakoubov |
PODC | 5 |
| 2025 | Deniable Secret Sharing
Ran Canetti, Ivan Damgård, Sebastian Kolby, Divya Ravi 0001, Sophia Yakoubov |
TCC (2) | 5 |
| 2025 | Information-Theoretic Broadcast-Optimal MPC
Michele Ciampi, Ivan Damgård, Divya Ravi 0001, Luisa Siniscalchi, Sophia Yakoubov |
TCC (1) | 5 |
| 2024 | Efficient Secure Communication over Dynamic Incomplete Networks with Minimal Connectivity
Ivan Damgård, Divya Ravi 0001, Lawrence Roy, Daniel Tschudi, Sophia Yakoubov |
TCC (4) | 5 |
| 2023 | Minimizing Setup in Broadcast-Optimal Two Round MPC
Ivan Damgård, Divya Ravi 0001, Luisa Siniscalchi, Sophia Yakoubov |
EUROCRYPT (2) | 4 |
| 2023 | Taming Adaptivity in YOSO Protocols: The Modular Way
Ran Canetti, Sebastian Kolby, Divya Ravi 0001, Eduardo Soria-Vazquez, Sophia Yakoubov |
TCC (2) | 5 |
| 2023 | Broadcast-Optimal Four-Round MPC in the Plain Model
Michele Ciampi, Ivan Damgård, Divya Ravi 0001, Luisa Siniscalchi, Yu Xia 0008, Sophia Yakoubov |
TCC (2) | 6 |
| 2022 | Distributed (Correlation) Samplers: How to Remove a Trusted Dealer in One Round
Damiano Abram, Peter Scholl, Sophia Yakoubov |
EUROCRYPT (1) | 3 |
| 2021 | Broadcast-Optimal Two Round MPC with an Honest Majority
Ivan Damgård, Bernardo Magri, Divya Ravi 0001, Luisa Siniscalchi, Sophia Yakoubov |
CRYPTO (2) | 5 |
| 2021 | YOSO: You Only Speak Once - Secure MPC with Stateless Ephemeral Roles
Craig Gentry, Shai Halevi, Hugo Krawczyk, Bernardo Magri, Jesper Buus Nielsen, Tal Rabin, Sophia Yakoubov |
CRYPTO (2) | 7 |
| 2021 | The Rise of Paillier: Homomorphic Secret Sharing and Public-Key Silent OT
Claudio Orlandi, Peter Scholl, Sophia Yakoubov |
EUROCRYPT (1) | 3 |
| 2021 | Random-Index PIR and ApplicationsabstractPrivate information retrieval (PIR) lets a client retrieve an entry from a database without the server learning which entry was retrieved. Here we study a weaker variant that we call random-index PIR (RPIR), where the retrieved index is an output rather than an input of the protocol, and is chosen at random. RPIR is clearly weaker than PIR, but it suffices for some interesting applications and may be realized more efficiently than full-blown PIR.We report here on two lines of work, both tied to RPIR but otherwise largely unrelated. The first line of work studies RPIR as a primitive on its own. Perhaps surprisingly, we show that RPIR is in fact equivalent to PIR when there are no restrictions on the number of communication rounds. On the other hand, RPIR can be implemented in a “noninteractive” setting (with pre-processing), which is clearly impossible for PIR. For two-server RPIR we even show a truly noninteractive solution, offering information-theoretic security without any pre-processing.The other line of work, which was the original motivation for our work, uses RPIR to improve on the recent work of Benhamouda et al. (TCC’20) for maintaining secret values on public blockchains. Their solution depends on a method for selecting many random public keys from a PKI while hiding most of the selected keys from an adversary. However, the method they proposed is vulnerable to a double-dipping attack, limiting its resilience. Here we observe that a RPIR protocol, where the client is implemented via secure MPC, can eliminate that vulnerability. We thus get a secrets-on-blockchain protocol (and more generally large-scale MPC) which is resilient to any fraction \(f < 1/2\) of corrupted parties, resolving the main open problem left from the work of Benhamouda et al.As the client in this solution is implemented via secure MPC, it really brings home the need to make it as efficient as possible. We thus strive to explore whatever efficiency gains we can get by using RPIR rather than PIR. We achieve more gains by using batch RPIR where multiple indexes are retrieved at once. Lastly, we observe that this application can make do with a weaker security guarantee than full RPIR, and show that this weaker variant can be realized even more efficiently. We discuss one protocol in particular that may be attractive for practical implementations. Craig Gentry, Shai Halevi, Bernardo Magri, Jesper Buus Nielsen, Sophia Yakoubov |
TCC (3) | 5 |
| 2020 | Universally Composable Accumulators
Foteini Baldimtsi, Ran Canetti, Sophia Yakoubov |
CT-RSA | 3 |
| 2020 | Stronger Security and Constructions of Multi-designated Verifier Signatures
Ivan Damgård, Helene Haagh, Rebekah Mercer, Anca Nitulescu, Claudio Orlandi, Sophia Yakoubov |
TCC (2) | 6 |
| 2018 | Fuzzy Password-Authenticated Key Exchange
Pierre-Alain Dupont, Julia Hesse, David Pointcheval, Leonid Reyzin, Sophia Yakoubov |
EUROCRYPT (3) | 5 |
| 2017 | Accumulators with Applications to Anonymity-Preserving RevocationabstractMembership revocation is essential for cryptographic applications, from traditional PKIs to group signatures and anonymous credentials. Of the various solutions for the revocation problem that have been explored, dynamic accumulators are one of the most promising. We propose Braavos, a new, RSA-based, dynamic accumulator. It has optimal communication complexity and, when combined with efficient zero-knowledge proofs, provides an ideal solution for anonymous revocation. For the construction of Braavos we use a modular approach: we show how to build an accumulator with better functionality and security from accumulators with fewer features and weaker security guarantees. We then describe an anonymous revocation component (ARC) that can be instantiated using any dynamic accumulator. ARC can be added to any anonymous system, such as anonymous credentials or group signatures, in order to equip it with a revocation functionality. Finally, we implement ARC with Braavos and plug it into Idemix, the leading implementation of anonymous credentials. This work resolves, for the first time, the problem of practical revocation for anonymous credential systems. Foteini Baldimtsi, Jan Camenisch, Maria Dubovitskaya, Anna Lysyanskaya, Leonid Reyzin, Kai Samelin, Sophia Yakoubov |
EuroS&P | 7 |