EDBT 2026 Demo / reviewers in the wild / expert
Thomas Peyrin
dblp:p/ThomasPeyrin
· DBLP profile ↗
74ranked-venue papers
10as first author
12since 2021 · last 2026
0000-0002-2690-9197ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 10 first-author · 10 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Navigating the Deep: End-to-End Extraction on Deep Neural Networks
Adrien Siproudhis, Samuel Experton, Peter Lorenz, Christina Boura, Thomas Peyrin |
EUROCRYPT | 6 |
| 2025 | Unlocking Mix-Basis Potential: Geometric Approach for Combined Attacks
Kai Hu 0001, Chengcheng Chang, Jiashu Zhang, Meiqin Wang 0001, Thomas Peyrin |
CRYPTO (5) | 6 |
| 2025 | The Window Heuristic: Automating Differential Trail Search in ARX Ciphers with Partial Linearization Trade-offs
Emanuele Bellini 0002, David Gérault, Juan Grados 0002, Thomas Peyrin |
CT-RSA | 4 |
| 2024 | Truth Table Net: Scalable, Compact & Verifiable Neural Networks with a Dual Convolutional Small Boolean Circuit Networks Form
Adrien Benamira, Thomas Peyrin, Trevor Yap, Tristan Guérand, Bryan Hooi |
IJCAI | 2 |
| 2023 | Revisiting Higher-Order Differential-Linear Attacks from an Algebraic Perspective
Kai Hu 0001, Thomas Peyrin, Quan Quan Tan, Trevor Yap |
ASIACRYPT (3) | 2 |
| 2023 | Fully Automated Differential-Linear Attacks Against ARX Ciphers
Emanuele Bellini 0002, David Gérault, Juan Grados 0002, Rusydi H. Makarim, Thomas Peyrin |
CT-RSA | 5 |
| 2023 | Neural Network-Based Rule Models with Truth TablesabstractUnderstanding the decision-making process of a machine/deep learning model is crucial, particularly in security-sensitive applications. In this study, we introduce a neural network framework that combines the global and exact interpretability properties of rule-based models with the high performance of deep neural networks. Our proposed framework, called Truth Table rules (TT-rules), is built upon Truth Table nets (TTnets), a family of deep neural networks initially developed for formal verification. By extracting the set of necessary and sufficient rules R from the trained TTnet model (global interpretability), yielding the same output as the TTnet (exact interpretability), TT-rules effectively transforms the neural network into a rule-based model. This rule-based model supports binary classification, multi-label classification, and regression tasks for tabular datasets. Furthermore, our TT-rules framework optimizes the rule set R into Ropt by reducing the number and size of the rules. To enhance model interpretation, we leverage Reduced Ordered Binary Decision Diagrams (ROBDDs) to visualize these rules effectively. After outlining the framework, we evaluate the performance of TT-rules on seven tabular datasets from finance, healthcare, and justice domains. We also compare the TT-rules framework to state-of-the-art rule-based methods. Our results demonstrate that TT-rules achieves equal or higher performance compared to other interpretable methods while maintaining a balance between performance and complexity. Notably, TT-rules presents the first accurate rule-based model capable of fitting large tabular datasets, including two real-life DNA datasets with over 20K features. Finally, we extensively investigate a rule-based model derived from TT-rules using the Adult dataset. Adrien Benamira, Tristan Guérand, Thomas Peyrin, Hans Soegeng |
ECAI | 3 |
| 2022 | Finding All Impossible Differentials When Considering the DDT
Kai Hu 0001, Thomas Peyrin, Meiqin Wang 0001 |
SAC | 2 |
| 2021 | DEFAULT: Cipher Level Resistance Against Differential Fault Attack
Anubhab Baksi, Shivam Bhasin, Jakub Breier, Mustafa Khairallah, Thomas Peyrin, Sumanta Sarkar, Siang Meng Sim |
ASIACRYPT (2) | 5 |
| 2021 | On the Cost of ASIC Hardware Crackers: A SHA-1 Case Study
Anupam Chattopadhyay, Mustafa Khairallah, Gaëtan Leurent, Zakaria Najm, Thomas Peyrin, Vesselin Velichkov |
CT-RSA | 5 |
| 2021 | A Deeper Look at Machine Learning-Based Cryptanalysis
Adrien Benamira, David Gérault, Thomas Peyrin, Quan Quan Tan |
EUROCRYPT (1) | 3 |
| 2021 | The Deoxys AEAD Family
Jérémy Jean, Ivica Nikolic, Thomas Peyrin, Yannick Seurin |
J. Cryptol. | 3 |
| 2020 | The MALICIOUS Framework: Embedding Backdoors into Tweakable Block Ciphers
Thomas Peyrin, Haoyang Wang 0001 |
CRYPTO (3) | 1 |
| 2020 | SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and Application to the PGP Web of Trust
Gaëtan Leurent, Thomas Peyrin |
USENIX Security Symposium | 2 |
| 2019 | SoK: On DFA Vulnerabilities of Substitution-Permutation NetworksabstractRecently, the NIST launched a competition for lightweight cryptography and a large number of ciphers are expected to be studied and analyzed under this competition. Apart from the classical security, the candidates are desired to be analyzed against physical attacks. Differential Fault Analysis (DFA) is an invasive physical attack method for recovering key information from cipher implementations. Up to date, almost all the block ciphers have been shown to be vulnerable against DFA, while following similar attack patterns. However, so far researchers mostly focused on particular ciphers rather than cipher families, resulting in works that reuse the same idea for different ciphers. In this article, we aim at bridging this gap, by providing a generic DFA attack method targeting Substitution-Permutation Network (SPN) based families of symmetric block ciphers. We provide the overview of the state-of-the-art of the fault attacks on SPNs, followed by generalized conditions that hold on all the ciphers of this design family. We show that for any SPN, as long as the fault mask injected before a non-linear layer in the last round follows a non-uniform distribution, the key search space can always be reduced. This shows that it is not possible to design an SPN-based cipher that is completely secure against DFA, without randomization. Furthermore, we propose a novel approach to find good fault masks that can leak the key with a small number of instances. We then developed a tool, called Joint Difference Distribution Table (JDDT) for pre-computing the solutions for the fault equations, which allows us to recover the last round key with a very small number of pairs of faulty and non-faulty ciphertexts. We evaluate our methodology on various block ciphers, including PRESENT-80, PRESENT-128, GIFT-64, GIFT-128, AES-128, LED-64, LED-128, Skinny, Pride and Prince. The developed technique would allow automated DFA analysis of several candidates in the NIST competitio Mustafa Khairallah, Xiaolu Hou, Zakaria Najm, Jakub Breier, Shivam Bhasin, Thomas Peyrin |
AsiaCCS | 6 |
| 2019 | From Collisions to Chosen-Prefix Collisions Application to Full SHA-1
Gaëtan Leurent, Thomas Peyrin |
EUROCRYPT (3) | 2 |
| 2018 | Boomerang Connectivity Table: A New Cryptanalysis Tool
Carlos Cid, Tao Huang 0015, Thomas Peyrin, Yu Sasaki 0001, Ling Song 0001 |
EUROCRYPT (2) | 3 |
| 2017 | GIFT: A Small Present - Towards Reaching the Limit of Lightweight Encryption
Subhadeep Banik, Sumit Kumar Pandey, Thomas Peyrin, Yu Sasaki 0001, Siang Meng Sim, Yosuke Todo |
CHES | 3 |
| 2017 | Bit-Sliding: A Generic Technique for Bit-Serial Implementations of SPN-based Primitives - Applications to AES, PRESENT and SKINNY
Jérémy Jean, Amir Moradi 0001, Thomas Peyrin, Pascal Sasdrich |
CHES | 3 |
| 2017 | ZMAC: A Fast Tweakable Block Cipher Mode for Highly Secure Message Authentication
Tetsu Iwata, Kazuhiko Minematsu, Thomas Peyrin, Yannick Seurin |
CRYPTO (3) | 3 |
| 2016 | The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim |
CRYPTO (2) | 6 |
| 2016 | Counter-in-Tweak: Authenticated Encryption Modes for Tweakable Block Ciphers
Thomas Peyrin, Yannick Seurin |
CRYPTO (1) | 1 |
| 2016 | Freestart Collision for Full SHA-1
Marc Stevens 0001, Pierre Karpman, Thomas Peyrin |
EUROCRYPT (1) | 3 |
| 2016 | Cryptanalysis of Full RIPEMD-128
Franck Landelle, Thomas Peyrin |
J. Cryptol. | 2 |
| 2015 | Known-Key Distinguisher on Full PRESENT
Céline Blondeau, Thomas Peyrin, Lei Wang 0031 |
CRYPTO (1) | 2 |
| 2015 | Practical Free-Start Collision Attacks on 76-step SHA-1
Pierre Karpman, Thomas Peyrin, Marc Stevens 0001 |
CRYPTO (1) | 2 |
| 2015 | Cryptanalysis of JAMBU
Thomas Peyrin, Siang Meng Sim, Lei Wang 0031, Guoyan Zhang |
FSE | 1 |
| 2015 | Lightweight MDS Involution Matrices
Siang Meng Sim, Khoongming Khoo, Frédérique E. Oggier, Thomas Peyrin |
FSE | 4 |
| 2015 | Collision Attack on Grindahl
Thomas Peyrin |
J. Cryptol. | 1 |
| 2014 | Tweaks and Keys for Block Ciphers: The TWEAKEY FrameworkabstractWe propose the TWEAKEY framework with goal to unify the design of tweakable block ciphers and of block ciphers resistant to related-key attacks. Our framework is simple, extends the key-alternating construction, and allows to build a primitive with arbitrary tweak and key sizes, given the public round permutation (for instance, the AES round). Increasing the sizes renders the security analysis very difficult and thus we identify a subclass of TWEAKEY , that we name STK , which solves the size issue by the use of finite field multiplications on low hamming weight constants. Overall, this construction allows a significant increase of security of well-known authenticated encryptions mode like Θ CB3 from birthday-bound security to full security, where a regular block cipher was used as a black box to build a tweakable block cipher. Our work can also be seen as advances on the topic of secure key schedule design. Jérémy Jean, Ivica Nikolic, Thomas Peyrin |
ASIACRYPT (2) | 3 |
| 2014 | FOAM: Searching for Hardware-Optimal SPN Structures and Components with a Fair Comparison
Khoongming Khoo, Thomas Peyrin, Axel Poschmann, Huihui Yap |
CHES | 2 |
| 2014 | Updates on Generic Attacks against HMAC and NMAC
Jian Guo 0001, Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031 |
CRYPTO (1) | 2 |
| 2014 | Generic Universal Forgery Attack on Iterative Hash-Based MACs
Thomas Peyrin, Lei Wang 0031 |
EUROCRYPT | 1 |
| 2014 | The Usage of Counter Revisited: Second-Preimage Attack on New Russian Standardized Hash Function
Jian Guo 0001, Jérémy Jean, Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031 |
Selected Areas in Cryptography | 4 |
| 2014 | Improved Cryptanalysis of AES-like Permutations
Jérémy Jean, María Naya-Plasencia, Thomas Peyrin |
J. Cryptol. | 3 |
| 2013 | Limited-Birthday Distinguishers for Hash Functions - Collisions beyond the Birthday Bound Can Be Meaningful
Mitsugu Iwamoto, Thomas Peyrin, Yu Sasaki 0001 |
ASIACRYPT (2) | 2 |
| 2013 | New Generic Attacks against Hash-Based MACs
Gaëtan Leurent, Thomas Peyrin, Lei Wang 0031 |
ASIACRYPT (2) | 2 |
| 2013 | Improved Cryptanalysis of Reduced RIPEMD-160
Florian Mendel, Thomas Peyrin, Martin Schläffer, Lei Wang 0031, Shuang Wu 0004 |
ASIACRYPT (2) | 2 |
| 2013 | Structural Evaluation of AES and Chosen-Key Distinguisher of 9-Round AES-128
Pierre-Alain Fouque, Jérémy Jean, Thomas Peyrin |
CRYPTO (1) | 3 |
| 2013 | Security challenges in automotive hardware/software architecture designabstractThis paper is an introduction to security challenges for the design of automotive hardware/software architectures. State-of-the-art automotive architectures are highly heterogeneous and complex systems that rely on distributed functions based on electronics and software. As cars are getting more connected with their environment, the vulnerability to attacks is rapidly growing. Examples for such wireless communication are keyless entry systems, WiFi, or Bluetooth. Despite this increasing vulnerability, the design of automotive architectures is still mainly driven by safety and cost issues rather than security. In this paper, we present potential threats and vulnerabilities, and outline upcoming security challenges in automotive architectures. In particular, we discuss the challenges arising in electric vehicles, like the vulnerability to attacks involving tampering with the battery safety. Finally, we discuss future automotive architectures based on Ethernet/IP and how formal verification methods might be used to increase their security. Florian Sagstetter, Martin Lukasiewycz, Sebastian Steinhorst, Marko Wolf, Alexandre Bouard, William R. Harris, Somesh Jha, Thomas Peyrin, Axel Poschmann, Samarjit Chakraborty |
DATE | 8 |
| 2013 | Cryptanalysis of Full RIPEMD-128
Franck Landelle, Thomas Peyrin |
EUROCRYPT | 2 |
| 2013 | Security Analysis of PRINCE
Jérémy Jean, Ivica Nikolic, Thomas Peyrin, Lei Wang 0031, Shuang Wu 0004 |
FSE | 3 |
| 2013 | Implementing Lightweight Block Ciphers on x86 Architectures
Ryad Benadjila, Jian Guo 0001, Victor Lomné, Thomas Peyrin |
Selected Areas in Cryptography | 4 |
| 2013 | Multiple Limited-Birthday Distinguishers and ApplicationsabstractIn this article, we propose a new improvement of the rebound techniques, used for cryptanalyzing AES -like permutations during the past years. Our improvement, that allows to reduce the complexity of the attacks, increases the probability of the outbound part by considering a new type of differential paths. Moreover, we propose a new type of distinguisher, the multiple limited-birthday problem, based on the limited-birthday one, but where differences on the input and on the output might have randomized positions. We also discuss the generic complexity for solving this problem and provide a lower bound of it as well as we propose an efficient and generic algorithm for solving it. Our advances lead to improved distinguishing or collision results for many AES -based functions such as AES , ECHO , Grøstl , LED , PHOTON and Whirlpool . Jérémy Jean, María Naya-Plasencia, Thomas Peyrin |
Selected Areas in Cryptography | 3 |
| 2012 | Generic Related-Key Attacks for HMAC
Thomas Peyrin, Yu Sasaki 0001, Lei Wang 0031 |
ASIACRYPT | 1 |
| 2012 | On the (In)Security of IDEA in Various Hashing Modes
Lei Wei 0001, Thomas Peyrin, Przemyslaw Sokolowski, San Ling, Josef Pieprzyk, Huaxiong Wang |
FSE | 2 |
| 2012 | Unaligned Rebound Attack: Application to Keccak
Alexandre Duc, Jian Guo 0001, Thomas Peyrin, Lei Wei 0001 |
FSE | 3 |
| 2012 | Improved Rebound Attack on the Finalist Grøstl
Jérémy Jean, María Naya-Plasencia, Thomas Peyrin |
FSE | 3 |
| 2012 | Practical Cryptanalysis of ARMADILLO2
María Naya-Plasencia, Thomas Peyrin |
FSE | 2 |
| 2011 | The LED Block Cipher
Jian Guo 0001, Thomas Peyrin, Axel Poschmann, Matthew J. B. Robshaw |
CHES | 2 |
| 2011 | The PHOTON Family of Lightweight Hash Functions
Jian Guo 0001, Thomas Peyrin, Axel Poschmann |
CRYPTO | 2 |
| 2011 | Analysis of Reduced-SHAvite-3-256 v2
Marine Minier, María Naya-Plasencia, Thomas Peyrin |
FSE | 3 |
| 2010 | Distinguishers for the Compression Function and Output Transformation of Hamsi-256
Jean-Philippe Aumasson, Emilia Käsper, Lars R. Knudsen, Krystian Matusiewicz, Rune Steinsmo Ødegård, Thomas Peyrin, Martin Schläffer |
ACISP | 6 |
| 2010 | A Forward-Secure Symmetric-Key Derivation Protocol - How to Improve Classical DUKPT
Eric Brier, Thomas Peyrin |
ASIACRYPT | 2 |
| 2010 | Side-Channel Analysis of Six SHA-3 Candidates
Olivier Benoît, Thomas Peyrin |
CHES | 2 |
| 2010 | Improved Differential Attacks for ECHO and Grøstl
Thomas Peyrin |
CRYPTO | 1 |
| 2010 | Super-Sbox Cryptanalysis: Improved Attacks for AES-Like Permutations
Henri Gilbert, Thomas Peyrin |
FSE | 2 |
| 2010 | Cryptanalysis of ESSENCE
María Naya-Plasencia, Andrea Röck, Jean-Philippe Aumasson, Yann Laigle-Chapuy, Gaëtan Leurent, Willi Meier, Thomas Peyrin |
FSE | 7 |
| 2009 | Inside the Hypercube
Jean-Philippe Aumasson, Eric Brier, Willi Meier, María Naya-Plasencia, Thomas Peyrin |
ACISP | 5 |
| 2009 | Cryptanalysis of CubeHash
Eric Brier, Thomas Peyrin |
ACNS | 2 |
| 2009 | Linearization Framework for Collision Attacks: Application to CubeHash and MD6
Eric Brier, Shahram Khazaei, Willi Meier, Thomas Peyrin |
ASIACRYPT | 4 |
| 2009 | Cryptanalysis of the ESSENCE Family of Hash Functions
Nicky Mouha, Gautham Sekar, Jean-Philippe Aumasson, Thomas Peyrin, Søren S. Thomsen, Meltem Sönmez Turan, Bart Preneel |
Inscrypt | 4 |
| 2009 | Cryptanalysis of RadioGatún
Thomas Fuhr 0001, Thomas Peyrin |
FSE | 2 |
| 2008 | Slide Attacks on a Class of Hash Functions
Michael Gorski, Stefan Lucks, Thomas Peyrin |
ASIACRYPT | 3 |
| 2008 | Collisions on SHA-0 in One Hour
Stéphane Manuel, Thomas Peyrin |
FSE | 2 |
| 2008 | How to Use Merkle-Damgård - On the Security Relations between Signature Schemes and Their Inner Hash Functions
Emmanuel Bresson, Benoît Chevallier-Mames, Christophe Clavier, Aline Gouget, Pascal Paillier, Thomas Peyrin |
ProvSec | 6 |
| 2007 | On Building Hash Functions from Multivariate Quadratic Equations
Olivier Billet, Matthew J. B. Robshaw, Thomas Peyrin |
ACISP | 3 |
| 2007 | Cryptanalysis of Grindahl
Thomas Peyrin |
ASIACRYPT | 1 |
| 2007 | Hash Functions and the (Amplified) Boomerang Attack
Antoine Joux, Thomas Peyrin |
CRYPTO | 2 |
| 2007 | Cryptanalysis of FORK-256
Krystian Matusiewicz, Thomas Peyrin, Olivier Billet, Scott Contini, Josef Pieprzyk |
FSE | 2 |
| 2007 | Security Analysis of Constructions Combining FIL Random Oracles
Yannick Seurin, Thomas Peyrin |
FSE | 2 |
| 2006 | Combining Compression Functions and Block Cipher-Based Hash Functions
Thomas Peyrin, Henri Gilbert, Frédéric Muller, Matthew J. B. Robshaw |
ASIACRYPT | 1 |
| 2005 | Linear Cryptanalysis of the TSC Family of Stream Ciphers
Frédéric Muller, Thomas Peyrin |
ASIACRYPT | 2 |
| 2005 | The Pairing Problem with User Interaction
Thomas Peyrin, Serge Vaudenay |
SEC | 1 |