Renaud Sirdey

dblp:43/138 · DBLP profile ↗
← Back
40ranked-venue papers
0as first author
16since 2021 · last 2025
0000-0003-4720-9269ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 11 since 2021Systems, architecture and hardware · 4Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Theory of computation · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Unveiling the (in)Security of Threshold FHE-Based Federated Learning: The Practical Impact of Recent CPAD Attacks
abstract
The security of Fully Homomorphic Encryption (FHE) has received a lot of attention in recent years with new security notions emerging to better understand the practical attacks that may threaten the real-world deployments of passively secure FHE schemes. One such new notions is CPAD a slight extension of CPA security modelling a passive adversary who is granted access to a decryption oracle accepting only well-formed ciphertexts. While successful CPAD attacks have initially been performed on approximate FHE schemes such as CKKS, recent works have also demonstrated practical CPAD attacks on all mainstream non-approximate FHE, such as BFV, BGV or TFHE. Despite their clear computational practicality, these latter attacks however focus on the abstract security game defining CPAD security. In this paper, we show how to concretely build on these to mount successful FHE key recovery attacks in the Federated Learning (FL) setting, an application scenario of choice for FHE techniques. In FL, participating entities or workers encrypt successive model updates based on their local training data, enabling a central server to aggregate them in order to homomorphically update a global model. As this paper demonstrates, this environment provides a playground for an attacker to launch key recovery attacks against the FHE underlying the secure aggregation mechanism. As such, our findings reveal substantial stealthy key-recovery threats from both the server and a single worker, with very limited impact on the FL training progression or final model quality.
Adda-Akram Bendoukha, Renaud Sirdey, Aymen Boudguiga, Nesrine Kaaniche
CSF2
2025 FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation (Extended Abstract)
abstract
Algorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by 45%.
Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey
IJCAI4
2025 Downlink (T)FHE Ciphertexts Compression
Antonina Bondarchuk, Olive Chakraborty, Geoffroy Couteau, Renaud Sirdey
SAC4
2025 Towards Privacy-preserving and Fairness-aware Federated Learning Framework
abstract
Federated Learning (FL) enables the distributed training of a model across multiple data owners under the orchestration of a central server responsible for aggregating the models generated by the different clients. However, the original approach of FL has significant shortcomings related to privacy and fairness requirements. Specifically, the observation of the model updates may lead to privacy issues, such as membership inference attacks, while the use of imbalanced local datasets can introduce or amplify classification biases, especially for minority groups. In this work, we show that these biases can be exploited to increase the likelihood of privacy attacks against these groups. To do so, we propose a novel inference attack exploiting the knowledge of group fairness metrics during the training of the global model. Then to thwart this attack, we define a fairness-aware encrypted-domain aggregation algorithm that is differentially-private by design thanks to the approximate precision loss of the threshold multi-key CKKS homomorphic encryption scheme. Finally, we demonstrate the good performance of our proposal both in terms of fairness and privacy through experiments conducted over three real datasets.
Adda-Akram Bendoukha, Didem Demirag, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey, Sébastien Gambs
Proc. Priv. Enhancing Technol.5
2024 On the Practical CPAD Security of "exact" and Threshold FHE Schemes and Libraries
Marina Checri, Renaud Sirdey, Aymen Boudguiga, Jean-Paul Bultel
CRYPTO (3)2
2024 FairCognizer: A Model for Accurate Predictions with Inherent Fairness Evaluation
abstract
Algorithmic fairness is a critical challenge in building trustworthy Machine Learning (ML) models. ML classifiers strive to make predictions that closely match real-world observations (ground truth). However, if the ground truth data itself reflects biases against certain sub-populations, a dilemma arises: prioritize fairness and potentially reduce accuracy, or emphasize accuracy at the expense of fairness. This work proposes a novel training framework that goes beyond achieving high accuracy. Our framework trains a classifier to not only deliver optimal predictions but also to identify potential fairness risks associated with each prediction. To do so, we specify a dual-labeling strategy where the second label contains a per-prediction fairness evaluation, referred to as an unfairness risk evaluation. In addition, we identify a subset of samples as highly vulnerable to group-unfair classifiers. Our experiments demonstrate that our classifiers attain optimal accuracy levels on both the Adult-Census-Income and Compas-Recidivism datasets. Moreover, they identify unfair predictions with nearly 75% accuracy at the cost of expanding the size of the classifier by a mere 45%.
Adda-Akram Bendoukha, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey
ECAI4
2024 Towards Practical Homomorphic Aggregation in Byzantine-Resilient Distributed Learning
abstract
The growing availability of distributed data has led to the increased use of machine learning (ML) algorithms in distributed topologies, where multiple nodes collaborate to train models under the coordination of a central server. However, distributed learning faces two significant challenges: the risk of Byzantine nodes corrupting the learning process by sending incorrect information, and the potential for a curious server to violate the privacy of individual nodes, even reconstructing their private data. While homomorphic encryption (HE) has been a promising solution for privacy preservation in distributed settings, its high computational cost, especially for high-dimensional ML models, has made it challenging to design robust (non-linear) Byzantine-resilient algorithms using HE.
Antoine Choffrut, Rachid Guerraoui, Rafael Pinot, Renaud Sirdey, John Stephan, Martin Zuber
Middleware4
2023 Optimized Stream-Cipher-Based Transciphering by Means of Functional-Bootstrapping
Adda-Akram Bendoukha, Pierre-Emmanuel Clet, Aymen Boudguiga, Renaud Sirdey
DBSec4
2023 Combining homomorphic encryption and differential privacy in federated learning
abstract
Recent works have investigated the relevance and practicality of using techniques such as Differential Privacy (DP) or Homomorphic Encryption (HE) to strengthen training data privacy in the context of Federated Learning protocols. As these two techniques cover different sources of confidentiality threats (other clients/end-users for the former, aggregation server for the latter), there is a need to consistently combine them in order to bridge the gap towards more realistic deployment scenarios. In this paper, we achieve that goal by means of a novel stochastic quantization operator which allows us to establish DP guarantees when the noise is both quantized and bounded due to the use of HE. The paper is concluded by experiments on the FEMNIST dataset which show that the precision required to get state-of-the art privacy/utility trade-off (which directly impacts HE parameters and, hence, HE operations performances) results in a computation time overhead between 0.2% and 1.1% imputable to HE (depending on the key setup, either single key or threshold), for the whole training of a 500k parameters model and state-of-the-art privacy/utility trade-off.
Arnaud Grivet Sébert, Marina Checri, Oana Stan, Renaud Sirdey, Cédric Gouy-Pailler
PST4
2023 Lightweight FHE-based Protocols Achieving Results Consistency for Data Encrypted Under Different Keys
abstract
International audience
Marina Checri, Jean-Paul Bultel, Renaud Sirdey, Aymen Boudguiga
SECRYPT3
2022 SecTL: Secure and Verifiable Transfer Learning-based inference
abstract
International audience
Abbass Madi, Oana Stan, Renaud Sirdey, Cédric Gouy-Pailler
ICISSP3
2022 A Secure Federated Learning: Analysis of Different Cryptographic Tools
abstract
International audience
Oana Stan, Vincent Thouvenot, Aymen Boudguiga, Katarzyna Kapusta, Martin Zuber, Renaud Sirdey
SECRYPT6
2021 Cloud-based Private Querying of Databases by Means of Homomorphic Encryption
abstract
International audience
Yassine Abbar, Pascal Aubry, Sergiu Carpov, Sayanta Mallick, Mariem Krichen, Damien Ligier, Sergey Shpak, Renaud Sirdey
IoTBDS9
2021 RandSolomon: Optimally Resilient Random Number Generator with Deterministic Termination
abstract
International audience
Luciano Freitas de Souza, Andrei Tonkikh, Sara Tucci Piergiovanni, Renaud Sirdey, Oana Stan, Nicolas Quero, Petr Kuznetsov
OPODIS4
2021 SPEED: secure, PrivatE, and efficient deep learning
Arnaud Grivet Sébert, Rafael Pinot, Martin Zuber, Cédric Gouy-Pailler, Renaud Sirdey
Mach. Learn.5
2021 Efficient homomorphic evaluation of k-NN classifiers
abstract
Abstract We design and implement an efficient, secure, homomorphic k-Nearest Neighbours determination algorithm, to be used for regression or classification over private data. Our algorithm runs in quadratic complexity with regard to the size of the database but is the only one in the literature to make the secure determination completely non-interactively. We show that our secure algorithm is both efficient and accurate when applied to classification problems requiring a small set of model vectors, and still scales to larger sets of model vectors with high accuracy yet at greater (sequential) computational costs.
Martin Zuber, Renaud Sirdey
Proc. Priv. Enhancing Technol.2
2020 Faster Homomorphic Encryption is not Enough: Improved Heuristic for Multiplicative Depth Minimization of Boolean Circuits
Pascal Aubry, Sergiu Carpov, Renaud Sirdey
CT-RSA3
2020 Towards Real-Time Hidden Speaker Recognition by Means of Fully Homomorphic Encryption
Martin Zuber, Sergiu Carpov, Renaud Sirdey
ICICS3
2020 Illuminating the Dark or how to recover what should not be seen in FE-based classifiers
abstract
Abstract Classification algorithms/tools become more and more powerful and pervasive. Yet, for some use cases, it is necessary to be able to protect data privacy while benefiting from the functionalities they provide. Among the tools that may be used to ensure such privacy, we are focusing in this paper on functional encryption. These relatively new cryptographic primitives enable the evaluation of functions over encrypted inputs, outputting cleartext results. Theoretically, this property makes them well-suited to process classification over encrypted data in a privacy by design’ rationale, enabling to perform the classification algorithm over encrypted inputs (i.e. without knowing the inputs) while only getting the input classes as a result in the clear. In this paper, we study the security and privacy issues of classifiers using today practical functional encryption schemes. We provide an analysis of the information leakage about the input data that are processed in the encrypted domain with state-of-the-art functional encryption schemes. This study, based on experiments ran on MNIST and Census Income datasets, shows that neural networks are able to partially recover information that should have been kept secret. Hence, great care should be taken when using the currently available functional encryption schemes to build privacy-preserving classification services. It should be emphasized that this work does not attack the cryptographic security of functional encryption schemes, it rather warns the community against the fact that they should be used with caution for some use cases and that the current state-ofthe-art may lead to some operational weaknesses that could be mitigated in the future once more powerful functional encryption schemes are available.
Sergiu Carpov, Caroline Fontaine, Damien Ligier, Renaud Sirdey
Proc. Priv. Enhancing Technol.4
2019 Practical Fully Homomorphic Encryption for Fully Masked Neural Networks
Malika Izabachène, Renaud Sirdey, Martin Zuber
CANS2
2019 On the limitations of the chimera graph topology in using analog quantum computers
abstract
This paper investigates the possibility of using an analog quantum computer as commercialized by D-Wave to solve large QUBO problems by means of a single invocation of the quantum annealer. Indeed this machine solves a spin glass problem with programmable coefficients but subject to quite strong topology restrictions on the set of non-zero coefficients. Rather than mapping problem variables onto multiple qbits, an approach which requires many invocations of the annealer to solve small size problems, it is tempting to investigate the existence of sparse relaxations compliant with the qbits interconnection topology of the machine, hence solvable in one invocation of the annealing oracle, but still providing good-quality solutions to the original problem. This paper provides an experimental setup which aims to determine whether or not such convenient relaxations do exist or, rather, are easy to find. Our experiments suggest that it is not the case and, therefore, that solving even moderate size arbitrary problems with a single call to a quantum annealer is not possible at least within the constraints of the so-called Chimera topology. We conclude the paper with a number of perspectives that this results imply on the design of heuristics taking profit of a quantum annealing oracle to solve large scale problems.
Daniel Vert, Renaud Sirdey, Stéphane Louise
CF2
2018 Towards Video Compression in the Encrypted Domain: A Case-Study on the H264 and HEVC Macroblock Processing Pipeline
Donald Nokam Kuate, Sébastien Canard, Renaud Sirdey
CANS3
2018 Thwarting Fault Attacks against Lightweight Cryptography using SIMD Instructions
abstract
A growing number of connected objects, with their high performance and low-resources constraints, are embedding lightweight ciphers for protecting the confidentiality of the data they manipulate or store. Since those objects are easily accessible, they are prone to a whole range of physical attacks, one of which are fault attacks against which countermeasures are usually expensive to implement, especially on off-the-shelf devices. For such devices, we propose a new generic software countermeasure, using SIMD instructions available in almost any off-the-shelf devices, to thwart most fault attacks while preserving the performances of the targeted cipher.
Benjamin Lac, Anne Canteaut, Jacques J. A. Fournier, Renaud Sirdey
ISCAS4
2018 Stream Ciphers: A Practical Solution for Efficient Homomorphic-Ciphertext Compression
Anne Canteaut, Sergiu Carpov, Caroline Fontaine, Tancrède Lepoint, María Naya-Plasencia, Pascal Paillier, Renaud Sirdey
J. Cryptol.7
2017 Privacy Preserving Data Classification using Inner-product Functional Encryption
Damien Ligier, Sergiu Carpov, Caroline Fontaine, Renaud Sirdey
ICISSP4
2017 Towards Confidentiality-strengthened Personalized Genomic Medicine Embedding Homomorphic Cryptography
abstract
International audience
Renaud Sirdey, François Artiguenave, Sergiu Carpov
ICISSP2
2017 A Multi-start Heuristic for Multiplicative Depth Minimization of Boolean Circuits
Sergiu Carpov, Pascal Aubry, Renaud Sirdey
IWOCA3
2017 Running Compression Algorithms in the Encrypted Domain: A Case-Study on the Homomorphic Execution of RLE
abstract
This paper is devoted to the study of the problem of running compression algorithms in the encrypted domain, using a (somewhat) fully homomorphic encryption (FHE) scheme. We do so with a particular focus on conservative compression algorithms. Despite of the encrypted domain Turingcompleteness which comes with the magic of FHE operators, we show that a number of subtleties crop up when it comes to running compression algorithms and, in particular, that guaranteed conservative compression is not possible to achieve in the FHE setting. To illustrate these points, we analyze the most elementary conservative compression algorithm of all, namely Run-Length Encoding (RLE). We first study the way to regularize this algorithm in order to make it (meaningfully) fit within the constraints of a FHE execution. Secondly, we analyze it from the angle of optimizing the resulting structure towards (as much as possible) FHE execution efficiency. The paper is concluded by concrete experimental results obtained using the Fan-Vercauteren cryptosystem as well as the Armadillo FHE compiler. It is also this paper intent to share the concrete return on experience we gained in attempting to run a simple yet practically significant algorithm over FHE.
Sébastien Canard, Sergiu Carpov, Donald Nokam Kuate, Renaud Sirdey
PST4
2017 Information Leakage Analysis of Inner-Product Functional Encryption Based Data Classification
abstract
In this work, we study the practical security of inner-product functional encryption. We left behind the mathematical security proof of the schemes, provided in the literature, and focus on what attackers can use in realistic scenarios without tricking the protocol, and how they can retrieve more than they should be able to. This study is based on the proposed protocol from [1]. We generalize the scenario to an attacker possessing n secret keys. We propose attacks based on machine learning, and experiment them over the MNIST dataset [2].
Damien Ligier, Sergiu Carpov, Caroline Fontaine, Renaud Sirdey
PST4
2016 Practical Privacy-Preserving Medical Diagnosis Using Homomorphic Encryption
abstract
The use of remote services offered by cloud providers have been popular in the last lustrum. Services allow users to store remote files, or to analyze data for several purposes, like health-care or message analysis. However, when personal data are sent to the Cloud, users may lose privacy on the data-content, and on the other side cloud providers may use those data for their own businesses. In this paper, we present our solution to analyze users health-data directly into the Cloud while preserving users privacy. Our solution makes use of homomorphic encryption to protect users data during the analysis. In particular, we developed a mobile application that offloads users data into the Cloud, and a homomorphic encryption algorithm that processes those data without leaking any information to the Cloud provider. Performed empirical tests show that our HE algorithm is able to evaluate users data in reasonable time proving the feasibility of this emerging way of private-data evaluation.
Sergiu Carpov, Renaud Sirdey, Gianpiero Costantino, Fabio Martinelli
CLOUD3
2016 An Architecture for Practical Confidentiality-Strengthened Face Authentication Embedding Homomorphic Cryptography
abstract
In this paper, we propose and experiment a system architecture which intends to significantly strengthen the security of biometric authentication with respect to the confidentiality(-by-design) of the users' references needed to perform such a function. Our architecture has been designed to ensure that these biometric references are permanently encrypted and that the (single) server processing them has no decryption capability (in particular, does not have access to any decryption key). In order to do so, we use homomorphic encryption techniques which allow to perform calculations directly over encrypted data. We report on the careful architectural choices and agressive optimizations we had to make in order to be able to deploy an off-the-shelf face recognition module into this architecture. As the performance results presented in the paper demonstrate, we claim to have achieved practically relevant levels of performance and security in a realistic setting.
Nabil Bouzerna, Renaud Sirdey, Oana Stan, Philippe Wolf
CloudCom2
2016 A First DFA on PRIDE: From Theory to Practice
Benjamin Lac, Marc Beunardeau, Anne Canteaut, Jacques J. A. Fournier, Renaud Sirdey
CRiSIS5
2016 Stream Ciphers: A Practical Solution for Efficient Homomorphic-Ciphertext Compression
Anne Canteaut, Sergiu Carpov, Caroline Fontaine, Tancrède Lepoint, María Naya-Plasencia, Pascal Paillier, Renaud Sirdey
FSE7
2016 Privacy Preserving Data Classification Using Inner Product Encryption
Damien Ligier, Sergiu Carpov, Caroline Fontaine, Renaud Sirdey
SecureComm4
2015 Blind hypervision to protect virtual machine privacy against hypervisor escape vulnerabilities
abstract
Hypervision is being widely implemented in an effort to control costs and to simplify management through consolidation of servers. It has been recently unraveled that well over a third of virtualization vulnerabilities reside in the hyper-visor, mostly due to hypervisor escape. The exploitation of these vulnerabilities allows an attacker, among other things, to access and/or modify data of other Virtual Machines (VMs) by escaping from its VM and executing malicious code in the hypervisor. This paper introduces the general idea of blind hypervision, a hardware/software co-design to prevent such attackers to access private elements of other VMs. Blind hypervision limits the rights of the hypervisor regarding memory access, so that a malicious agent executing with hypervisor rights cannot access the data of the VMs.
Paul Dubrulle, Renaud Sirdey, Philippe Dore, M. Aichouch, Emmanuel Ohayon
INDIN2
2014 An Approximate Method for Throughput Evaluation of Cyclo-static Dataflow Programs
abstract
Because of the multiplication of multi-core architecture, dataflow programming languages regained interest during the last years. In the case of massively multi-core embedded system architectures, the computation of throughput is used for buffer sizing under time constraints. This paper introduces an approximate method for the throughput evaluation for cyclostatic dataflow graphs.
Pascal Aubry, Mohamed Benazouz, Renaud Sirdey
CISIS3
2012 A low-overhead dedicated execution support for stream applications on shared-memory cmp
abstract
The ever-growing number of cores in Chip Multi-Processors (CMP) brings a renewed interest in stream programming to solve the programmability issues raised by massively parallel architectures. Stream programming languages are flourishing (StreaMIT, Brook, ∑C, etc.). Nonetheless, their execution support have not yet received enough attention, in particular regarding the new generation of many-cores.
Paul Dubrulle, Stéphane Louise, Renaud Sirdey, Vincent David
EMSOFT3
2011 Task Ordering and Memory Management Problem for Degree of Parallelism Estimation
Sergiu Carpov, Jacques Carlier, Dritan Nace, Renaud Sirdey
COCOON4
2011 ΣC: A Programming Model and Language for Embedded Manycores
Thierry Goubier, Renaud Sirdey, Stéphane Louise, Vincent David
ICA3PP (1)2
2010 Minimizing Task Preemptions and Migrations in Multiprocessor Optimal Real-Time Schedules
abstract
We present a new approach to decrease task preemptions and migrations in optimal global real-time schedules on symmetric multiprocessors. Contrary to classical approaches, our method proceeds in two steps, one off-line to place jobs on intervals and one on-line to schedule them dynamically inside each interval. We propose a new linear programming formulation and a local scheduler which exhibits low complexity and produces few task preemptions and migrations. We compare our approach with other optimal scheduling algorithms, using the implicit-deadline periodic task model. Simulation results illustrate the competitiveness of our approach with respect to task preemptions and migrations.
Thomas Megel, Renaud Sirdey, Vincent David
RTSS2