EDBT 2026 Demo / reviewers in the wild / expert
Thomas Espitau
dblp:164/3319
· DBLP profile ↗
31ranked-venue papers
11as first author
15since 2021 · last 2026
0000-0002-7655-9594ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 10 first-author · 15 since 2021Theory of computation · 5Software engineering, systems software and programming languages · 3Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Maskaglia: A New, Efficient Approach to Masked Discrete Gaussian Sampling
Calvin Abou Haidar, Thomas Espitau, Clément Hoffmann, Mehdi Tibouchi |
CRYPTO (7) | 2 |
| 2026 | Generating Falcon Trapdoors via Gibbs Sampler
Thomas Espitau, Junjie Song, Jinguang Han, Mehdi Tibouchi |
PQCrypto (1) | 2 |
| 2025 | Poster: Efficient Threshold ML-DSA up to 6 PartiesabstractThreshold signature schemes enable a group of users to collaboratively produce digital signatures without revealing any individual share. With the current NIST post-quantum standardization underway, the lack of efficient and practical threshold variants of standardized schemes hinders adoption. We introduce the first threshold signature scheme compatible with the ML-DSA standard (Module-Lattice-based Digital Signature Algorithm), supporting up to 6 parties, while retaining efficient signing. Our work uses advanced short secret sharing techniques and optimized rejection sampling to balance communication and correctness in distributed settings. We implement our construction in Go and benchmark it in local, LAN, and WAN deployments. Results show that our threshold ML-DSA is both practical and compatible with real-world applications such as multi-device cryptocurrency wallets, threshold TLS, and Tor's directory authorities. Sofía Celi, Rafaël Del Pino, Thomas Espitau, Guilhem Niot, Thomas Prest |
CCS | 3 |
| 2025 | A Reduction from Hawk to the Principal Ideal Problem in a Quaternion Algebra
Clémence Chevignard, Guilhem Mureau, Thomas Espitau, Alice Pellet-Mary, Heorhii Pliatsok, Alexandre Wallet |
EUROCRYPT (2) | 3 |
| 2025 | Two-Round Threshold Signature from Algebraic One-More Learning with Errors
Thomas Espitau, Shuichi Katsumata, Kaoru Takemure |
J. Cryptol. | 1 |
| 2024 | Two-Round Threshold Signature from Algebraic One-More Learning with Errors
Thomas Espitau, Shuichi Katsumata, Kaoru Takemure |
CRYPTO (7) | 1 |
| 2024 | Flood and Submerse: Distributed Key Generation and Robust Threshold Signature from Lattices
Thomas Espitau, Guilhem Niot, Thomas Prest |
CRYPTO (7) | 1 |
| 2024 | Plover: Masking-Friendly Hash-and-Sign Lattice Signatures
Muhammed F. Esgin, Thomas Espitau, Guilhem Niot, Thomas Prest, Amin Sakzad, Ron Steinfeld |
EUROCRYPT (6) | 2 |
| 2024 | Masking the GLP Lattice-Based Signature Scheme at Any Order
Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Benjamin Grégoire, Melissa Rossi, Mehdi Tibouchi |
J. Cryptol. | 3 |
| 2023 | Antrag: Annular NTRU Trapdoor Generation - Making Mitaka as Secure as Falcon
Thomas Espitau, Thi Thu Quyen Nguyen, Mehdi Tibouchi, Alexandre Wallet |
ASIACRYPT (7) | 1 |
| 2023 | On Gaussian Sampling, Smoothing Parameter and Application to Signatures
Thomas Espitau, Alexandre Wallet, Yang Yu 0008 |
ASIACRYPT (7) | 1 |
| 2023 | Finding Short Integer Solutions When the Modulus Is Small
Léo Ducas, Thomas Espitau, Eamonn W. Postlethwaite |
CRYPTO (3) | 2 |
| 2022 | Shorter Hash-and-Sign Lattice-Based Signatures
Thomas Espitau, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008 |
CRYPTO (2) | 1 |
| 2022 | Mitaka: A Simpler, Parallelizable, Maskable Variant of FalconabstractThis work describes the Mitaka signature scheme: a new hash-and-sign signature scheme over NTRU lattices which can be seen as a variant of NIST finalist Falcon . It achieves comparable efficiency but is considerably simpler, online/offline, and easier to parallelize and protect against side-channels, thus offering significant advantages from an implementation standpoint. It is also much more versatile in terms of parameter selection. We obtain this signature scheme by replacing the FFO lattice Gaussian sampler in Falcon by the “hybrid” sampler of Ducas and Prest, for which we carry out a detailed and corrected security analysis. In principle, such a change can result in a substantial security loss, but we show that this loss can be largely mitigated using new techniques in key generation that allow us to construct much higher quality lattice trapdoors for the hybrid sampler relatively cheaply. This new approach can also be instantiated on a wide variety of base fields, in contrast with Falcon ’s restriction to power-of-two cyclotomics. We also introduce a new lattice Gaussian sampler with the same quality and efficiency, but which is moreover compatible with the integral matrix Gram root technique of Ducas et al., allowing us to avoid floating point arithmetic. This makes it possible to realize the same signature scheme as Mitaka efficiently on platforms with poor support for floating point numbers. Finally, we describe a provably secure masking of Mitaka . More precisely, we introduce novel gadgets that allow provable masking at any order at much lower cost than previous masking techniques for Gaussian sampling-based signature schemes, for cheap and dependable side-channel protection. Thomas Espitau, Pierre-Alain Fouque, François Gérard, Melissa Rossi, Akira Takahashi 0002, Mehdi Tibouchi, Alexandre Wallet, Yang Yu 0008 |
EUROCRYPT (3) | 1 |
| 2021 | Towards Faster Polynomial-Time Lattice Reduction
Paul Kirchner, Thomas Espitau, Pierre-Alain Fouque |
CRYPTO (2) | 2 |
| 2020 | Fast Reduction of Algebraic Lattices over Cyclotomic Fields
Paul Kirchner, Thomas Espitau, Pierre-Alain Fouque |
CRYPTO (2) | 2 |
| 2019 | GALACTICS: Gaussian Sampling for Lattice-Based Constant- Time Implementation of Cryptographic Signatures, RevisitedabstractIn this paper, we propose a constant-time implementation of the BLISS lattice-based signature scheme. BLISS is possibly the most efficient lattice-based signature scheme proposed so far, with a level of performance on par with widely used pre-quantum primitives like ECDSA. It is only one of the few postquantum signatures to have seen real-world deployment, as part of the strongSwan VPN software suite. The outstanding performance of the BLISS signature scheme stems in large part from its reliance on discrete Gaussian distributions, which allow for better parameters and security reductions. However, that advantage has also proved to be its Achilles' heel, as discrete Gaussians pose serious challenges in terms of secure implementations. Implementations of BLISS so far have included secret-dependent branches and memory accesses, both as part of the discrete Gaussian sampling and of the essential rejection sampling step in signature generation. These defects have led to multiple devastating timing attacks, and were a key reason why BLISS was not submitted to the NIST postquantum standardization effort. In fact, almost all of the actual candidates chose to stay away from Gaussians despite their efficiency advantage, due to the serious concerns surrounding implementation security. Moreover, naive countermeasures will often not cut it: we show that a reasonable-looking countermeasure suggested in previous work to protect the BLISS rejection sampling can again be defeated using novel timing attacks, in which the timing information is fed to phase retrieval machine learning algorithm in order to achieve a full key recovery. Fortunately, we also present careful implementation techniques that allow us to describe an implementation of BLISS with complete timing attack protection, achieving the same level of efficiency as the original unprotected code, without resorting on floating point arithmetic or platform-specific optimizations like AVX intrinsics. These techniques, including a new approach to the polynomial approximation of transcendental function, can also be applied to the masking of the BLISS signature scheme, and will hopefully make more efficient and secure implementations of lattice-based cryptography possible going forward. Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Melissa Rossi, Mehdi Tibouchi |
CCS | 3 |
| 2019 | Relational ⋆⋆\star-Liftings for Differential PrivacyabstractRecent developments in formal verification have identified approximate liftings (also known as approximate couplings) as a clean, compositional abstraction for proving differential privacy. This construction can be defined in two styles. Earlier definitions require the existence of one or more witness distributions, while a recent definition by Sato uses universal quantification over all sets of samples. These notions have each have their own strengths: the universal version is more general than the existential ones, while existential liftings are known to satisfy more precise composition principles. We propose a novel, existential version of approximate lifting, called $\star$-lifting, and show that it is equivalent to Sato's construction for discrete probability measures. Our work unifies all known notions of approximate lifting, yielding cleaner properties, more general constructions, and more precise composition theorems for both styles of lifting, enabling richer proofs of differential privacy. We also clarify the relation between existing definitions of approximate lifting, and consider more general approximate liftings based on $f$-divergences. Gilles Barthe, Thomas Espitau, Justin Hsu, Tetsuya Sato 0001, Pierre-Yves Strub |
Log. Methods Comput. Sci. | 2 |
| 2018 | LWE Without Modular Reduction and Improved Side-Channel Attacks Against BLISS
Jonathan Bootle, Claire Delaplace, Thomas Espitau, Pierre-Alain Fouque, Mehdi Tibouchi |
ASIACRYPT (1) | 3 |
| 2018 | An Assertion-Based Program Logic for Probabilistic ProgramsabstractWe present Ellora , a sound and relatively complete assertion-based program logic, and demonstrate its expressivity by verifying several classical examples of randomized algorithms using an implementation in the EasyCrypt proof assistant. Ellora features new proof rules for loops and adversarial code, and supports richer assertions than existing program logics. We also show that Ellora allows convenient reasoning about complex probabilistic concepts by developing a new program logic for probabilistic independence and distribution law, and then smoothly embedding it into Ellora . These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Gilles Barthe, Thomas Espitau, Marco Gaboardi, Benjamin Grégoire, Justin Hsu, Pierre-Yves Strub |
ESOP | 2 |
| 2018 | Masking the GLP Lattice-Based Signature Scheme at Any Order
Gilles Barthe, Sonia Belaïd, Thomas Espitau, Pierre-Alain Fouque, Benjamin Grégoire, Melissa Rossi, Mehdi Tibouchi |
EUROCRYPT (2) | 3 |
| 2018 | Proving expected sensitivity of probabilistic programsabstractProgram sensitivity, also known as Lipschitz continuity, describes how small changes in a program’s input lead to bounded changes in the output. We propose an average notion of program sensitivity for probabilistic programs—expected sensitivity—that averages a distance function over a probabilistic coupling of two output distributions from two similar inputs. By varying the distance, expected sensitivity recovers useful notions of probabilistic function sensitivity, including stability of machine learning algorithms and convergence of Markov chains. Furthermore, expected sensitivity satisfies clean compositional properties and is amenable to formal verification. We develop a relational program logic called EpRHL for proving expected sensitivity properties. Our logic features two key ideas. First, relational pre-conditions and post-conditions are expressed using distances, a real-valued generalization of typical boolean-valued (relational) assertions. Second, judgments are interpreted in terms of expectation coupling, a novel, quantitative generalization of probabilistic couplings which supports compositional reasoning. We demonstrate our logic on examples beyond the reach of prior relational logics. Our main example formalizes uniform stability of the stochastic gradient method. Furthermore, we prove rapid mixing for a probabilistic model of population dynamics. We also extend our logic with a transitivity principle for expectation couplings to capture the path coupling proof technique by Bubley and Dyer, and formalize rapid mixing of the Glauber dynamics from statistical physics. Gilles Barthe, Thomas Espitau, Benjamin Grégoire, Justin Hsu, Pierre-Yves Strub |
Proc. ACM Program. Lang. | 2 |
| 2018 | Loop-Abort Faults on Lattice-Based Signature Schemes and Key Exchange ProtocolsabstractAlthough postquantum cryptography is of growing practical concern, not many works have been devoted to implementation security issues related to postquantum schemes. In this paper, we look in particular at fault attacks against implementations of lattice-based signatures and key exchange protocols. For signature schemes, we are interested both in Fiat-Shamir type constructions (particularly BLISS, but also GLP, PASSSign, and Ring-TESLA) and in hash-and-sign schemes (particularly the GPV-based scheme of Ducas-Prest-Lyubashevsky). For key exchange protocols, we study the implementations of NewHope, Frodo, and Kyber. These schemes form a representative sample of modern, practical lattice-based signatures and key exchange protocols, and achieve a high level of efficiency in both software and hardware. We present several fault attacks against those schemes that recover the entire key recovery with only a few faulty executions (sometimes only one), show that those attacks can be mounted in practice based on concrete experiments in hardware, and discuss possible countermeasures against them. Thomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi Tibouchi |
IEEE Trans. Computers | 1 |
| 2017 | Side-Channel Attacks on BLISS Lattice-Based Signatures: Exploiting Branch Tracing against strongSwan and Electromagnetic Emanations in MicrocontrollersabstractIn this paper, we investigate the security of the BLISS lattice-based signature scheme, one of the most promising candidates for postquantum-secure signatures, against side-channel attacks. Several works have been devoted to its efficient implementation on various platforms, from desktop CPUs to microcontrollers and FPGAs, and more recent papers have also considered its security against certain types of physical attacks, notably fault injection and cache attacks. We turn to more traditional side-channel analysis, and describe several attacks that can yield a full key recovery. Thomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi Tibouchi |
CCS | 1 |
| 2017 | Computing Generator in Cyclotomic Integer Rings - A Subfield Algorithm for the Principal Ideal Problem in L|Δ𝕂|(½) and Application to the Cryptanalysis of a FHE Scheme
Jean-François Biasse, Thomas Espitau, Pierre-Alain Fouque, Alexandre Gélin, Paul Kirchner |
EUROCRYPT (1) | 2 |
| 2017 | *-Liftings for Differential Privacy
Gilles Barthe, Thomas Espitau, Justin Hsu, Tetsuya Sato 0001, Pierre-Yves Strub |
ICALP | 2 |
| 2017 | Proving uniformity and independence by self-composition and couplingabstractProof by coupling is a classical proof technique for establishing probabilistic properties of two probabilistic processes, like stochastic dominance and rapid mixing of Markov chains. More recently, couplings have been investigated as a useful abstraction for formal reasoning about relational properties of probabilistic programs, in particular for modeling reduction-based cryptographic proofs and for verifying differential privacy. In this paper, we demonstrate that probabilistic couplings can be used for verifying non-relational probabilistic properties. Specifically, we show that the program logic pRHL—whose proofs are formal versions of proofs by coupling—can be used for formalizing uniformity and probabilistic independence. We formally verify our main examples using the EasyCrypt proof assistant. Gilles Barthe, Thomas Espitau, Benjamin Grégoire, Justin Hsu, Pierre-Yves Strub |
LPAR | 2 |
| 2016 | Synthesizing Probabilistic Invariants via Doob's Decomposition
Gilles Barthe, Thomas Espitau, Luis María Ferrer Fioriti, Justin Hsu |
CAV (1) | 2 |
| 2016 | Loop-Abort Faults on Lattice-Based Fiat-Shamir and Hash-and-Sign Signatures
Thomas Espitau, Pierre-Alain Fouque, Benoît Gérard, Mehdi Tibouchi |
SAC | 1 |
| 2015 | Higher-Order Differential Meet-in-the-middle Preimage Attacks on SHA-1 and BLAKE
Thomas Espitau, Pierre-Alain Fouque, Pierre Karpman |
CRYPTO (1) | 1 |
| 2015 | Relational Reasoning via Probabilistic CouplingabstractProbabilistic coupling is a powerful tool for analyzing pairs of probabilistic processes. Roughly, coupling two processes requires finding an appropriate witness process that models both processes in the same probability space. Couplings are powerful tools proving properties about the relation between two processes, include reasoning about convergence of distributions and stochastic dominance —a probabilistic version of a monotonicity property. While the mathematical definition of coupling looks rather complex and cumbersome to manipulate, we show that the relational program logic pRHL—the logic underlying the EasyCrypt cryptographic proof assistant—already internalizes a generalization of probabilistic coupling. With this insight, constructing couplings is no harder than constructing logical proofs. We demonstrate how to express and verify classic examples of couplings in pRHL, and we mechanically verify several couplings in EasyCrypt. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Gilles Barthe, Thomas Espitau, Benjamin Grégoire, Justin Hsu, Léo Stefanesco, Pierre-Yves Strub |
LPAR | 2 |