IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
12 August 2026
Boston University
We are hiring two postdoctoral researchers at Boston University to work at the intersection of systems and applied cryptography.
About the role. We are building secure and scalable computing infrastructure using secure multiparty computation (MPC), fully homomorphic encryption (FHE), and trusted execution environments (TEEs). We seek candidates who combine strong foundations with hands-on systems engineering and want to help build an open-source system for deploying secure data workflows in the cloud. This NSF-funded project (https://www.nsf.gov/awardsearch/show-award/?AWD_ID=2613424) builds upon years of research by the PIs, and we already have an exciting set of real use cases from stakeholders eager to adopt the system.
The positions are initially offered for 1 year, with possibility of renewal for 1 additional year. The start date can be September 2026, January 2027, or September 2027.
Responsibilities
- Collaborate with faculty members, PhD students, and our academic and industry partners
- Contribute to research spanning systems, cryptography, data analytics, and machine learning
- Design and implement cryptographic protocols and full-stack software solutions
- Mentor graduate and undergraduate students
- Participate in a vibrant, interdisciplinary research environment
Requirements
- PhD in Computer Science, Computer Engineering, or closely related field
- Experience with MPC, FHE, TEEs, or related technologies
- Excellent programming skills in one or more of the following languages: C++, Rust, or Go
- Strong academic record with publications and presentations at top-tier security and/or systems venues
- (Optional) Experience with open-source software development practices and/or contributions to open-source projects
Closing date for applications:
Contact: Interested candidates should email Vasia Kalavri ([email protected]), Mayank Varia ([email protected]), and John Liagouris ([email protected]) with a detailed CV and a 2-page research statement. Applications will be reviewed on a rolling basis starting August 15 and until the positions are filled.
Moritz Peters, Jens Alich, Ashwin Jha, Gregor Leander, Yuval Yarom, Tim Güneysu
In this work, we propose an efficient approach for eliminating most of the overhead of fetching the aforementioned freshness. Our core idea is to repurpose the ECC memory area to efficiently store random nonces or counters. We propose a range of implementations with varying trade-offs between security guarantees and performance overhead, and demonstrate that we can achieve a solid baseline security even with small random nonces. By leaving a portion of ECC memory unused, we show that it is possible to efficiently integrate protection mechanisms such as memory integrity and memory tagging, while limiting the overall performance overhead to approximately 2%.
10 August 2026
Tanping Zhou, Xiaoyi Wang, Yi Qu, Wenchao Liu, Long Chen, Zhenfeng Zhang
However, despite its broad applicability, existing PFE schemes often exhibit inefficiencies, even in relatively straightforward scenarios such as the evaluation of lookup tables. To mitigate these limitations, we propose a novel variant of PFE, termed Preprocessed Private Function Evaluation (PPFE), which leverages preprocessing techniques to significantly enhance the efficiency of online computations. Within this framework, we introduce a specialized construction tailored specifically for lookup table operations, achieving sublinear complexity during the online computation phase.
The efficacy of the proposed approach is demonstrated through experimental evaluations. For a lookup table of size $2^{24}$, the online computation time required to process a single query is about 3 milliseconds, representing a performance improvement of more than an order of magnitude compared to existing results. Furthermore, the proposed scheme exhibits strong scalability, effectively handling thousands of adaptive queries within the same framework.
Ashrujit Ghoshal, Yuval Ishai, Aayush Jain, Nuozhou Sun
Our distinguishing attack originated from a failed attempt to construct doubly efficient private information retrieval (PIR) protocols from algebraic locally decodable codes, and can be intuitively explained from the PIR perspective. We extend this provable algorithm to a heuristic $n^{{\mathcal O}(\log n)}$-time ciphertext-decryption attack that recovers the message from a noisy codeword.
09 August 2026
Colin Finkbeiner, Connor Shaw, Ghada Almashaqbeh
In this paper, we present a holistic study of the time-to-profitability (TTP) of existing selfish mining strategies structured around four contributions. First, in the single-attacker setting, we characterize TTP across the full strategy space and find that TTP-minimizing and profit-maximizing strategies frequently diverge, making attack horizon a critical metric. In particular, under realistic fee dynamics, the use of incentive transactions to recruit honest-but-rational miners enable incentivized strategies to reach profitability up to $15\times$ faster than classic selfish mining at the same hash rate. Second, we explore TTP for the first time in the multi-attacker setting, showing that the difference in strategies between opposing attackers has a dramatic impact on joint-profitability lag. Third, we generalize intermittent selfish mining by exploring temporal composition over the full strategy space and show that its purported benefits are largely overstated. That is, alternating strategies rarely outperform the best static strategy in terms of either TTP or long-term profits. Finally, and building off our earlier findings, we explore adaptive, state-conditioned strategy selection at the difficulty adjustment period (DAP) level. We compare a general-purpose LLM agent against a fixed decision-tree selector, both implementing the same selection criteria. We find that both selectors reliably identify profit-maximizing strategies from observed network conditions, at a low operating cost, lowering the expertise barrier to exploiting adaptive selfish mining.
Dmytro Zakharov, Mikhail Kudinov, Viktoria Balatska, Yaroslava Chopa
No prior exposure to lattice-based cryptography is assumed: all the required background is developed within the document.
Yunxin Zhang, Yunxiao Zhou, Shuai Han, Shengli Liu, Xinyi Huang
In this paper, we resolve the above open problem by proposing three adaptively secure (t,N)-TD schemes based on the LWE assumption, all with polynomial modulus under appropriate settings. - TD0: an adaptively CPA-secure scheme in the asynchronous setting in the standard model, whose modulus is polynomial for small number of users N. - TD1: an adaptively CCA-secure scheme in the asynchronous setting in the standard model, whose modulus is polynomial for small N and bounded decryption queries. - TD2: an adaptively CCA-secure scheme in the synchronous setting in the random oracle (RO) model, whose modulus is polynomial for bounded decryption queries.
The main technical challenge is to limit the leakage of secret key shares arising from decryption queries, while keeping the modulus a polynomial. To overcome this barrier, we develop a refined polynomial noise flooding technique based on a detailed min-entropy analysis of secret shares conditioned on linear matrix hints, leveraging recent advances on Matrix-Hint LWE. Based on our new technique, we build TD1 using the replicated secret sharing (RSS) scheme, hence supporting only small N. To enable larger N, we design TD2 using the Shamir secret sharing scheme, in which we further integrate our new technique with the zero-sum masking technique [Katsumata et al., CRYPTO 2024] to restrict the secret key leakage. To the best of our knowledge, our TD1 and TD2 are the first non-interactive lattice-based threshold decryption schemes achieving adaptive CCA security and polynomial modulus, simultaneously. Moreover, they achieve the strongest notion of adaptive CCA security among those compared in [Brzuska et al., PKC 2026]. We further establish robustness for both TD0 and TD1 via publicly verifiable partial decryptions, ensuring that the combination either outputs the correct plaintext or aborts.
Seongbong Choi, Jiseung Kim, Hyung Tae Lee
08 August 2026
Seattle, USA, 6 May - 7 May 2027
Submission deadline: 30 November 2026
Notification: 11 January 2027
Leuven, Belgium, 16 September - 18 September 2026
Hasso Plattner Institute, University of Potsdam (Germany)
In our research clusters "Systems," "Data and AI," "Foundations," "Digital Health," "Security," and "Business and Society" researchers from various disciplines work together on topics relevant to solving the challenges facing society. The Digital Engineering Faculty of the University of Potsdam and HPI offers a computer science engineering degree program that is unique in Germany.
In the course of its strong growth, the Hasso Plattner Institute is offering a PhD position in the research group Cybersecurity - High-Assurance Systems, led by Prof. Dr. Chitchanok Chuengsatiansup, which investigates mechanisms to safeguard our digital information with the focus on cryptographic engineering, side-channel analysis, implementation optimization, and post-quantum cryptography.
The application deadline is 20 September 2026.
For further information and how to apply, please visit:
https://jobs.plattnerfoundation.org/HPI/job/Potsdam-PhD-position-%28fmx%29-High-Assurance-Systems-14482/1362941055/
Closing date for applications:
Contact: Chitchanok Chuengsatiansup
More information: https://jobs.plattnerfoundation.org/HPI/job/Potsdam-PhD-position-%28fmx%29-High-Assurance-Systems-14482/1362941055/
Chalmers University of Technology
We are looking for a PhD student to join the Crypto Team and Security Group at Chalmers with Christoph Egger as main supervisor. The position is fully funded for 5 years and comes with 20% teaching duties in the department. The Crypto Team currently has 2 faculty members, one Post-Doc and 4 PhD students and is embedded in the security group that captures a wide range of topics.
Depending on the interests of the applicant, possible research topics include fine-grained and bounded space cryptography, realization of idealized models, relationship between cryptographic notions, and similar topics in foundational cryptography. Alternatively, a focus on formal methods for Cryptography is possible. One or two extended research visits are encouraged during the doctoral study. Applicants should have a strong interest in the mathematical analysis of algorithms in general and cryptography in particular. A master's degree in mathematics, computer science, or a related discipline is required. The working language in the department is English, and applicants are expected to be fluent both in written and spoken English. Swedish courses are available for interested students.
Applications are due August 14 (or until filled)Closing date for applications:
Contact: Christoph Egger: [email protected]
More information: https://www.chalmers.se/om-chalmers/arbeta-hos-oss/lediga-tjanster/?rmpage=apply&rmjob=15017
Institute for Computer Science, Artificial Intelligence and Technology; Sofia, Bulgaria
We are looking for outstanding PhD students and postdoctoral researchers to join the cryptography group led by Dr. Michael Reichle at INSAIT in Sofia, Bulgaria. INSAIT is already a top research institute in AI and Theory and you have the opportunity to help shape INSAIT into a world-class research institute for Cryptography and Security. Sofia offers great gastronomy, an affordable cost of living and quick access to nature, with many parks and Vitosha Mountain just outside the city.
Topics. Research areas include post-quantum cryptography, protocols for signatures and encryption, and zero-knowledge proofs. Applicants with interests in related areas of cryptography are also encouraged to apply.
PhD applicants. You should hold (or be close to completing) a Master's degree and have a strong background in cryptography, theoretical computer science, mathematics, or a related field. You will be co-supervised by Mariana Raykova under the Google PhD fellowship program.
Postdoctoral applicants. You should hold (or be close to completing) a PhD in a related field. A strong research record, ideally including publications at IACR conferences or leading security venues, is preferred.
The positions are well funded and come with no teaching obligations. The start date is flexible, with positions available from October 2026 onward. Applications will be considered on a rolling basis until the positions are filled.
Closing date for applications:
Contact: Please apply via https://insait.ai/information-security-and-cryptography. For questions, please contact Michael Reichle ([email protected]).
More information: https://insait.ai/information-security-and-cryptography
Department of Computing, The Hong Kong Polytechnic University; Hong Kong SAR
- Blockchain security and privacy
- Distributed computing and consensus
- Secure multi-party computation, cryptographic protocols, and game theory
- Quantum cryptography
The PhD positions are fully funded for 3–4 years, with a competitive monthly stipend. Detailed information on scholarships and tuition fees is available at: https://www.polyu.edu.hk/cee/prospective-students/research-postgraduate-programme/scholarships-and-tuition-fee/
Eligibility Requirements
Applicants should have:- A strong background in cryptography, cybersecurity, theoretical computer science, or related areas; and
- Fulfilled the general PhD admission requirements of PolyU: https://www.polyu.edu.hk/study/pg/research-postgraduate
Application Procedure
Interested candidates are invited to send the following materials to Dr. Yu Shen at [email protected]:- Curriculum vitae (CV)
- Academic transcripts
- A brief statement describing research interests and relevant experience
Closing date for applications:
Contact: Yu Shen ([email protected])
Luxium AG Zug Switzerland
Closing date for applications:
Contact: Daniel Gagnidze
More information: https://www.jobs.ch/en/vacancies/detail/f7defdb8-bc1e-4fe0-9c00-d1b2d358e4e8/
07 August 2026
Matthieu Rivain
06 August 2026
Donnie Y. Xu, Rajeev Gore, Amin Sakzad, Ron Steinfeld, Raymond K. Zhao
Yi-Fu Lai, Yu Yu, Xiaogang Zhou
We present a two-stage attack on this construction. The first stage concerns the unspecified representation of the public key. The reported key size indicates that the public curve is stored as a \(j\)-invariant, whereas both the specified radical-CGL computation use two coefficients to represent a curve. By exploiting this form we can produce two different VRF outputs under the same public key and message, breaking the unique provability. Hence, the output of the radical-CGL computation must follow the specification.
In the second stage, we exploit these coefficients to recover the VRF secret key. With \(1536\) queries, our implementation recovers the complete \(256\)-bit secret in 30 minutes, thereby breaking residual pseudorandomness. Interestingly, we also observe that the using public key alone without queries can sometimes reveal one or two bits of the secret walk.
Besides, we extend Lai's observation to obtain a one-query attack on the group-action-based VRF proposed in the same paper with advantage closed to 1/2. Together, these constitute three attacks on their work.