EDBT 2026 Demo / reviewers in the wild / expert
Julian Nowakowski
dblp:298/9340
· DBLP profile ↗
11ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0003-3066-0133ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 1 first-author · 11 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Super-Quadratic Quantum Speed-ups and Guessing Many Likely Keys
Kaveh Bashiri, Timo Glaser, Alexander May 0001, Julian Nowakowski |
EUROCRYPT (1) | 4 |
| 2026 | Cool + Cruel = Dual, and New Benchmarks for Sparse LWE
Alexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite, Ludo N. Pulles, Fernando Virdia, Paul Vié |
EUROCRYPT (4) | 3 |
| 2026 | One (Noisy) Bit to Rule Them All: Key Recovery from Randomness Leakage in ML-DSAabstractAbstract The Fiat-Shamir transform is one of the most widely applied methods for secure signature construction. Fiat-Shamir starts with an interactive zero-knowledge identification protocol and transforms this via a hash function into a non-interactive signature. The protocol’s zero-knowledge property ensures that a signature does not leak information on its secret key $${\textbf{s}}$$ s , which is achieved by blinding $$\vec {s}$$ s → via proper randomness $${\textbf{y}}$$ y . Most prominent Fiat-Shamir examples are EC-DSA signatures and the new post-quantum standard ML-DSA (aka Dilithium). In practice, EC-DSA signatures have experienced fatal attacks via leakage of a few bits of the randomness $${\textbf{y}}$$ y per signature. Similar attacks now emerge for lattice-based signatures, such as ML-DSA. We build on, improve and generalize the pioneering leakage attack on ML-DSA by Liu, Zhou, Sun, Wang, Zhang, and Ming. Using a transformation to Integer LWE (ILWE), their attack can recover a 256-dimensional subkey of ML-DSA-44 from leakage in a single bit of $$\textbf{y}$$ y per signature, in any bit position $$j \ge 6$$ j ≥ 6 . However, the number of required signatures grows exponentially as $$4^j$$ 4 j . In this work, we show that not all leaky signatures carry information about the secret subkey. We introduce the notion of informative signature relations. This notion allows us to define a preprocessing step, called filter-and-shift that leads to ILWE instances that require a smaller sample amount. Unlike the standard ILWE transformation, filter-and-shift exploits the smallness of secret keys, and therefore might be of independent cryptanalytic interest. In comparison to Liu et al., for $$j=6$$ j = 6 we require only a quarter of the signatures and reduce the exponential growth to $$2^j$$ 2 j . In addition, we show that the secret subkey can be recovered even with a leak bit corrupted by a large amount of noise, in theory up to the maximum of $$50\%$$ 50 % . Experimentally, we still recover the secret with $$43\%$$ 43 % noise, where we need 170 times as many signatures as in the noise-free setting. The attack applies more generally to all Fiat-Shamir-type lattice-based signatures. For a signature scheme based on module LWE over an $$\ell $$ ℓ -dimensional module, the attack uses a 1-bit leak per signature to efficiently recover a $$\frac{1}{\ell }$$ 1 ℓ -fraction of the secret key. In the ring LWE setting, which can be seen as module LWE with $$\ell = 1$$ ℓ = 1 , the attack recovers the whole key. Simon Damm, Nicolai Kraus, Alexander May 0001, Julian Nowakowski, Jonas Thietke |
J. Cryptol. | 4 |
| 2025 | Fast Slicer for Batch-CVP: Making Lattice Hybrid Attacks Practical
Alexander Karenin, Elena Kirshanova, Julian Nowakowski, Alexander May 0001 |
ASIACRYPT (3) | 3 |
| 2025 | One Bit to Rule Them All - Imperfect Randomness Harms Lattice Signatures
Simon Damm, Nicolai Kraus, Alexander May 0001, Julian Nowakowski, Jonas Thietke |
PKC (1) | 4 |
| 2025 | An Improved Algorithm for Code Equivalence
Julian Nowakowski |
PQCrypto (1) | 1 |
| 2023 | Too Many Hints - When LLL Breaks LWE
Alexander May 0001, Julian Nowakowski |
ASIACRYPT (4) | 2 |
| 2023 | Solving the Hidden Number Problem for CSIDH and CSURF via Automated Coppersmith
Jonas Meers, Julian Nowakowski |
ASIACRYPT (4) | 2 |
| 2023 | New NTRU Records with Improved Lattice Bases
Elena Kirshanova, Alexander May 0001, Julian Nowakowski |
PQCrypto | 3 |
| 2022 | Approximate Divisor Multiples - Factoring with Only a Third of the Secret CRT-Exponents
Alexander May 0001, Julian Nowakowski, Santanu Sarkar 0001 |
EUROCRYPT (3) | 2 |
| 2021 | Partial Key Exposure Attack on Short Secret Exponent CRT-RSA
Alexander May 0001, Julian Nowakowski, Santanu Sarkar 0001 |
ASIACRYPT (1) | 2 |