EDBT 2026 Demo / reviewers in the wild / expert
Subhadeep Banik
dblp:20/3093
· DBLP profile ↗
25ranked-venue papers
14as first author
9since 2021 · last 2025
0000-0001-6310-0154ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 14 first-author · 5 since 2021Systems, architecture and hardware · 5 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cryptanalysis of Fruit-F: Exploiting Key-Derivation Weaknesses and Initialization Vulnerabilities
Subhadeep Banik, Hailun Yan |
ACISP (1) | 1 |
| 2025 | SEDX: Seasonal Encoder-Decoder for ForecastingabstractRecurrent neural networks (RNNs) have been a very popular predictive modelling choice for sequence based applications. Here we consider RNNs for time series forecasting. The proposed distinct architecture is based on Seq2Seq OR encoder-decoder (ED) framework, capturing (stochastic) seasonal correlations intelligently with accurate multi-step forecasting ability. We derive our nonlinear architecture from the classic linear multiplicative seasonal auto-regressive model. Unlike existing RNN approaches, it (i)places equal emphasis on each cycle of input window, (ii)contains vanishing gradients and (iii)has accurate multi-step forecast feature in the presence (or absence) of exogenous inputs. It can be used on both single or multiple sequence data. For the multiple sequence case, we also propose a novel greedy recursive procedure to build (one or more) predictive models across sequences when per-sequence data is less. Our experiments demonstrate the utility of our proposed architecture both in single and multiple sequence scenarios. Avinash Achar, Soumen Pachal, Subhadeep Banik |
IJCNN | 3 |
| 2024 | A System Development Kit for Big Data Applications on FPGA-based Clusters: The EVEREST ApproachabstractModern big data workflows are characterized by computationally intensive kernels. The simulated results are often combined with knowledge extracted from AI models to ultimately support decision-making. These energy-hungry workflows are increasingly executed in data centers with energy-efficient hard-ware accelerators since FPG As are well-suited for this task due to their inherent parallelism. We present the H2020 project EVEREST, which has developed a system development kit (SDK) to simplify the creation of FPGA-accelerated kernels and manage the execution at runtime through a virtualization environment. This paper describes the main components of the EVEREST SDK and the benefits that can be achieved in our use cases. Christian Pilato, Subhadeep Banik, Jakub Beránek, Fabien Brocheton, Jerónimo Castrillón, Riccardo Cevasco, Radim Cmar, Serena Curzel, Fabrizio Ferrandi, Karl F. A. Friebel, Antonella Galizia, Matteo Grasso, Paulo Silva 0002, Jan Martinovic, Gianluca Palermo, Michele Paolino, Andrea Parodi, Antonio Parodi, Fabio Pintus, Raphael Polig, David Poulet, Francesco Regazzoni 0001, Burkhard Ringlein, Roberto Rocco, Katerina Slaninová, Tom Slooff, Stephanie Soldavini, Felix Suchert, Mattia Tibaldi, Beat Weiss, Christoph Hagleitner |
DATE | 2 |
| 2023 | Near Collision Attack Against Grain V1
Subhadeep Banik, Daniel Collins 0001, Willi Meier |
ACNS (1) | 1 |
| 2023 | Resource-Constrained Encryption: Extending Ibex with a QARMA Hardware AcceleratorabstractThe increasing prevalence of IoT devices calls for the need for strong, but efficient cryptography. In this paper we present two instruction set extensions for the lightweight encryption cipher QARMA-64 to the RISC-V instruction set, implemented for the Ibex core. The first extension performs the entire algorithm in hardware, divided over ten instructions. The second extension takes a more granular approach and instead implements the basic operations that the algorithm uses as custom instructions. The first extension achieves a speedup of ~600x over the software implementation and a binary size reduction of over 2x. It achieves these results at the cost of an added field-programmable gate array (FPGA) utilization over the base Ibex design of 43.9% and 18.7% for, respectively, the number of lookup tables (LUTs) and flip-flops (FFs). The application-specific integrated circuit (ASIC) area for synthesis is increased by 92.4% over the base design. The second extension achieves a speedup of ~19x over the software version while roughly maintaining the same binary size. This extension increases the number of utilized LUTs and FFs respectively by only 0.1% and 4.9%. The ASIC area for this design is increased by only 5.1%. The power consumption for the first extension is estimated at$543\mu \mathrm{W}$and for the second extension at$468\mu \mathrm{W}$. Mathijs De Kremer, Marco Brohet, Subhadeep Banik, Roberto Maria Avanzi, Francesco Regazzoni 0001 |
ASAP | 3 |
| 2023 | An Ultra-High Throughput AES-Based Authenticated Encryption Scheme for 6G: Design and Implementation
Ravi Anand, Subhadeep Banik, Andrea Caforio, Kazuhide Fukushima, Takanori Isobe 0001, Shinsaku Kiyomoto, Fukang Liu, Yuto Nakano, Kosei Sakamoto, Nobuyuki Takeuchi |
ESORICS (1) | 2 |
| 2021 | New Attacks on LowMC Instances with a Single Plaintext/Ciphertext Pair
Subhadeep Banik, Khashayar Barooti, Serge Vaudenay, Hailun Yan |
ASIACRYPT (1) | 1 |
| 2021 | Complete Practical Side-Channel-Assisted Reverse Engineering of AES-Like Ciphers
Andrea Caforio, Fatih Balli, Subhadeep Banik |
CARDIS | 3 |
| 2021 | A Deeper Look at the Energy Consumption of Lightweight Block CiphersabstractIn the last few years, the field of lightweight cryptography has seen an influx in the number of block ciphers and hash functions being proposed. In the past there have been numerous papers that have looked at circuit level implementation of block ciphers with respect to lightweight metrics like area power and energy. In the paper by Banik et al. (SAC‘15), for example, by studying the energy consumption model of a CMOS gate, it was shown that the energy consumed per cycle during the encryption operation of an r-round unrolled architecture of any block cipher is a quadratic function in r. However, most of these explorative works were at a gate level, in which a circuit synthesizer would construct a circuit using gates from a standard cell library, and the area power and energy would be estimated by estimating the switching statistics of the nodes in the circuit. Since only a part of the EDA design flow was done, it did not account for issues that might arise when the circuit is finally mapped into silicon post route. Metrics like area, power and energy would need to be re-estimated due to the effect of the parasitics introduced in the circuit by the connecting wires, nodes and interconnects. In this paper, we look to plug this very gap in literature by re-examining the designs of lightweight block ciphers with respect to their performances after completing the placement and routing process. This is a timely exercise to do since three of the block ciphers we analyze in the paper are used in around 13 of the 32 candidates in the second round of the NIST lightweight competition being conducted currently. Andrea Caforio, Fatih Balli, Subhadeep Banik, Francesco Regazzoni 0001 |
DATE | 3 |
| 2020 | Energy Analysis of Lightweight AEAD Circuits
Andrea Caforio, Fatih Balli, Subhadeep Banik |
CANS | 3 |
| 2020 | WARP : Revisiting GFN for Lightweight 128-Bit Block Cipher
Subhadeep Banik, Zhenzhen Bao, Takanori Isobe 0001, Hiroyasu Kubo, Fukang Liu, Kazuhiko Minematsu, Kosei Sakamoto, Nao Shibata, Maki Shigeri |
SAC | 1 |
| 2020 | Synthesis of Flexible Accelerators for Early Adoption of Ring-LWE Post-quantum CryptographyabstractThe advent of the quantum computer makes current public-key infrastructure insecure. Cryptography community is addressing this problem by designing, efficiently implementing, and evaluating novel public-key algorithms capable of withstanding quantum computational power. Governmental agencies, such as NIST, are promoting standardization of quantum-resistant algorithms that is expected to run for 7 years. Several modern applications must maintain permanent data secrecy; therefore, they ultimately require the use of quantum-resistant algorithms. Because algorithms are still under scrutiny for eventual standardization, the deployment of the hardware implementation of quantum-resistant algorithms is still in early stages. In this article, we propose a methodology to design programmable hardware accelerators for lattice-based algorithms, and we use the proposed methodology to implement flexible and energy efficient post-quantum cache-based accelerators for NewHope , Kyber , Dilithium , Key Consensus from Lattice ( KCL ), and R.EMBLEM submissions to the NIST standardization contest. To the best of our knowledge, we propose the first efficient domain-specific, programmable cache-based accelerators for lattice-based algorithms. We design a single accelerator for a common kernel among various schemes with different kernel sizes, i.e., loop count, and data types. This is in contrast to the traditional approach of designing one special purpose accelerators for each scheme. We validate our methodology by integrating our accelerators into an HLS-based SoC infrastructure based on the X86 processor and evaluate overall performance. Our experiments demonstrate the suitability of the approach and allow us to collect insightful information about the performance bottlenecks and the energy efficiency of the explored algorithms. Our results provide guidelines for hardware designers, highlighting the optimization points to address for achieving the highest energy minimization and performance increase. At the same time, our proposed design allows us to specify and execute new variants of lattice-based schemes with superior energy efficiency compared to the main application processor without changing the hardware acceleration platform. For example, we manage to reduce the energy consumption up to 2.1× and energy-delay product (EDP) up to 5.2× and improve the speedup up to 2.5×. Hamid Nejatollahi, Felipe Valencia, Subhadeep Banik, Francesco Regazzoni 0001, Rosario Cammarota, Nikil Dutt |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2019 | Cryptanalysis of ForkAES
Subhadeep Banik, Jannis Bossert, Amit Jana, Eik List, Stefan Lucks, Willi Meier, Mostafizar Rahman, Dhiman Saha, Yu Sasaki 0001 |
ACNS | 1 |
| 2017 | Related-Key Impossible-Differential Attack on Reduced-Round Skinny
Ralph Ankele, Subhadeep Banik, Avik Chakraborti, Eik List, Florian Mendel, Siang Meng Sim, Gaoli Wang |
ACNS | 2 |
| 2017 | GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption
Subhadeep Banik, Sumit Kumar Pandey, Thomas Peyrin, Yu Sasaki 0001, Siang Meng Sim, Yosuke Todo |
CHES | 1 |
| 2016 | Cryptanalysis of the Full Spritz Stream Cipher
Subhadeep Banik, Takanori Isobe 0001 |
FSE | 1 |
| 2016 | Hold Your Breath, PRIMATEs Are Lightweight
Danilo Sijacic, Andreas B. Kidmose, Bohan Yang 0001, Subhadeep Banik, Begül Bilgin, Andrey Bogdanov, Ingrid Verbauwhede |
SAC | 4 |
| 2015 | Midori: A Block Cipher for Low Energy
Subhadeep Banik, Andrey Bogdanov, Takanori Isobe 0001, Kyoji Shibutani, Harunaga Hiwatari, Toru Akishita, Francesco Regazzoni 0001 |
ASIACRYPT (2) | 1 |
| 2015 | Exploring Energy Efficiency of Lightweight Block Ciphers
Subhadeep Banik, Andrey Bogdanov, Francesco Regazzoni 0001 |
SAC | 1 |
| 2015 | Some security results of the RC4+ stream cipherabstractAbstract The RC4+ stream cipher was proposed as an alternative to the well known RC4 stream cipher. It was claimed by the authors that this new stream cipher was designed to overcome all the weaknesses reported against the alleged RC4 stream cipher. In the design specifications of RC4+, the authors make use of an 8‐bit design parameter called pad that is fixed to the value 0xAA. The first distinguishing attack on RC4+ based on the bias of its first output byte was shown in a previous paper. In this paper, it was also mentioned that the distinguishing attack would still hold if the pad used in RC4+ is fixed to any even 8‐bit constant other than 0xAA. Therefore, the question that naturally arises is whether the design of RC4+ can be protected by fixing the pad parameter to some constant odd value. In this paper, we try to answer this very question. We show that the design is still vulnerable by mounting a distinguishing attack even if the pad is fixed to some constant 8‐bit odd value. Surprisingly, we find that if the value of the pad is made equal to 0x03, the design provides maximum resistance to distinguishing attacks. Lastly, we return to the original cipher, that is, in which pad is set to 0xAA and unearth another bias in the second output byte of the cipher. Thereafter, we will present a generalized way of finding biases in every M‐th output byte (M≥3) of RC4+, that is, ZM, based on the Hamming weight of m ≡ MmodN. Finally, we improve the differential fault attack on RC4+ proposed in a previous paper, both in terms of number of faults required and the computational complexity. In fact, we reduce the number of faults by around 11264 on average, and our algorithm is around 26 times faster. Copyright © 2015 John Wiley & Sons, Ltd. Subhadeep Banik, Sonu Jha |
Secur. Commun. Networks | 1 |
| 2015 | Differential Fault Attack against Grain Family with Very Few Faults and Minimal AssumptionsabstractThe series of published works, related to differential fault attack (DFA) against the Grain family, require quite a large number (hundreds) of faults and also several assumptions on the locations and the timings of the faults injected. In this paper, we present a significantly improved scenario from the adversarial point of view for DFA against the Grain family of stream ciphers. Our model is the most realistic one so far as it considers that the cipher has to be re-keyed only a few times and faults can be injected at any random location and at any random point of time, i.e., no precise control is needed over the location and timing of fault injections. We construct equations based on the algebraic description of the cipher by introducing new variables so that the degrees of the equations do not increase. In line of algebraic cryptanalysis, we accumulate such equations based on the fault-free and faulty key-stream bits and solve them using the SAT Solver Cryptominisat-2.9.5 installed with SAGE 5.7. In a few minutes we can recover the state of Grain v1, Grain-128 and Grain-128a with as little as 10, 4 and 10 faults respectively. Santanu Sarkar 0001, Subhadeep Banik, Subhamoy Maitra |
IEEE Trans. Computers | 2 |
| 2014 | Some Insights into Differential Cryptanalysis of Grain v1
Subhadeep Banik |
ACISP | 1 |
| 2013 | A Chosen IV Related Key Attack on Grain-128a
Subhadeep Banik, Subhamoy Maitra, Santanu Sarkar 0001, Meltem Sönmez Turan |
ACISP | 1 |
| 2013 | A Differential Fault Attack on MICKEY 2.0
Subhadeep Banik, Subhamoy Maitra |
CHES | 1 |
| 2012 | A Differential Fault Attack on the Grain Family of Stream Ciphers
Subhadeep Banik, Subhamoy Maitra, Santanu Sarkar 0001 |
CHES | 1 |