IACR News
If you have a news item you wish to distribute, they should be sent to the communications secretary. See also the events database for conference announcements.
Here you can see all recent updates to the IACR webpage. These updates are also available:
10 September 2026
Tim Beyne, Gregor Leander, Patrick Neumann, Yevhen Perehuda, Michiel Verbauwhede
Pierre Meyer
Our paper stands at the intersection of cryptography, complexity theory, and graph theory, but our main technical contribution is one to extremal combinatorics: we establish that every order-$n$ $2$-degenerate graph admits a planarising set of size at most $\lfloor n/3 \rfloor$.
Our main conceptual contribution is to relate the existence of sublinear-size (directed) $k$-path transversals to well-studied graph parameters. Along the way, we uncover a recurringly overstated lemma throughout the literature on sublinear-size vertex-separators and hyperfinite graphs. According to this lemma, any monotone graph class admitting sublinear-size balanced vertex separators should be weakly hyperfinite. However, this is contradicted by a graph class put forward by [Moshkovitz and Shapira, Random Structures \& Algorithms'15]. Unfortunately, the lemma appears in highly influencial works such as [Henzinger, Klein, Rao, and Subramanian, STOC'94 \& JCSS'97], or the textbook of Nešetřil and Ossona de Mendez [\emph{Sparsity}, Springer'12], and in turn it is used in a significant number of papers. Thankfully a slightly weaker version of this lemma is true, with a caveat on how sublinear the vertex separators needs to be, and we provide the correction as a service to the community.
Pratish Datta, Yannis Rouselakis, Junichi Tomida, Nikhil Vanjani
Scott Duke Kominers, Justin Thaler, Kai Zhe Zheng
09 September 2026
Zhao Song, Song Yue
08 September 2026
Accra Beach Hotel & Spa, Barbados, 8 February - 12 February 2027
Submission deadline: 24 September 2026
Notification: 12 November 2026
RWTH Aachen University, Aachen, Germany
I would like to announce the openings of PhD or postdoc positions relating to formal verification and quantum crypto in Dominique Unruh's group, the Chair for Quantum Information Systems, RWTH Aachen, Germany.
Feel free to share this in your network (especially with gifted master students who may not yet be in this channel).
- PhD position “Verification of Quantum Cryptography”
Other similar projects are possible, too. Postdocs are also welcome on these or similar topics, please provide your own research proposal.
We also have positions related to certified quantum compilation and type-systems for quantum programming languages (https://qis.rwth-aachen.de/positions/), though they are not directly related to cryptography.
Closing date for applications:
Contact: Dominique Unruh, Chair of Quantum Information Systems, RWTH Aachen
[email protected]
More information: https://qis.rwth-aachen.de/positions/verify-qcrypto.html
Aarhus University, Department of Computer Science; Aarhus, Denmark
How to Apply
Please apply here: https://phd.nat.au.dk/for-applicants/apply-here
After applying, please email a copy of your application materials to [email protected].
The deadline is November 1, 2026.
(Note that the application has several unusual fields. Under 'sources of financial support', click 'research council funds'. For the project description, please describe one or more directions within the focus areas mentioned above which you find interesting.)
Feel free to reach out with any questions.
Responsibilities of a PhD Student
- Collaborating with faculty members and fellow researchers to develop and possibly implement novel cryptographic protocols.
- Publishing research findings in top-tier conferences and journals in computer science and related fields.
- Participating in academic activities such as seminars, workshops, and conferences to stay informed of the latest developments in the field.
- Supporting teaching activities in the department by serving as TA.
We are a highly collaborative research group with eight faculty members and 30ish people total, with interests spanning many diverse areas of cryptography. You can learn a bit more about us here: https://users-cs.au.dk/orlandi/cryptogroup/
We are based in Aarhus, which is known as "the world's smallest big city," and "the city of smiles".
Closing date for applications:
Contact: Sophia Yakoubov ([email protected])
More information: https://phd.nat.au.dk/for-applicants/apply-here
KTH Royal Institute of Technology
Since this position requires a Swedish citizenship the description of the position is only available in Swedish.
Vid Center för cyberförsvar och informationssäkerhet (CDIS) samarbetar KTH, Försvarsmakten och andra myndigheter i syfte att stärka och bredda forskningen inom cyberförsvar och cybersäkerhet. Däri omfattas forskning för skydd av kritiska samhällsfunktioner och förbättrad förmåga att försvåra för aktörer som överväger att angripa Sverige. Cyberförsvar och -säkerhet är ämnen vars betydelse vuxit snabbt i samhället i takt med den hastiga digitaliseringen och den ökande insikten om de sårbarheter som digitaliseringen medför.
KTH bedriver sedan ett antal år tillbaka inom ramen för CDIS, och i nära samarbete med avdelningen för krypto och IT-säkerhet vid Must (som är en del av Försvarsmakten), spetsforskning som syftar till att möta de utmaningar som följer av kvantdatorutvecklingen. KTH söker nu en doktorand i kryptologi som kan bidra till den forskningen.
Tjänsten kommer att omfatta 80% doktorandstudier vid KTH och 20% placering vid Must där möjlighet ges att arbeta med några av Sveriges främsta kryptologer. Resultatet för doktoranden blir en unik kombination av teori och praktik inom kryptologiområdet.
Johan Håstad och Martin Ekerå föreslås handleda doktoranden. Beslut tas vid antagning.
Sista ansökningsdag: 2026-09-16
För mer information, se den publicerade annonsen.
Closing date for applications:
Contact: Martin Ekerå ([email protected]) or Johan Håstad ([email protected])
More information: https://kth.varbi.com/what:job/jobID:965397
Martí Batista, Álvaro Montes, Nikitas Paslis, Carla Ràfols
As is the case for universal zkSNARKs, dynamic ones can be built from dynamic arguments for Hadamard products and linear relations. Wang et al. handle the latter in the particular case of a permutation matrix, via a sparse argument---a protocol whose prover runs in time proportional to the Hamming weight of the witness. Nevertheless, their techniques do not directly extend to the arbitrary matrices arising in constraint systems such as R1CS or CCS. Furthermore, the standard approach for proving general linear relations is unsuitable for the sparse setting because of a witness-independent step: the prover commits to an auxiliary polynomial determined by the matrices alone, and is hence dense regardless of how sparse the witness might be.
Our first contribution is a sparse zkSNARK for linear relations, which we build from a fully witness-dependent argument together with what we call a rational encoding of the matrices. As our second contribution, we develop a compiler that turns any sparse argument for a linear relation into a dynamic one, while preserving the zero-knowledge property of the underlying scheme.
Instantiated for Plonk and R1CS-lite, our techniques yield universal dynamic zkSNARKs with at most $20$ group elements per proof and $23$ verifier pairings---over $6.5\times$ and $7.8\times$ fewer than the state of the art---as well as asymptotically faster updates. We also show how both of our constructions can be de-amortized.
07 September 2026
Guoqiang Liu, Suping Liu, Wuyou Zhang
Christodoulos Pappas, Zhuo Cai, Dimitrios Papadopoulos
Nico Döttling, Sri AravindaKrishnan Thyagarajan, Pratik Soni, Jay Taylor, Hendrik Waldner, Riccardo Zanotto
Kanchan Bisht, Keerthi Aiswarya Varshini, Shivam Sethi, Maria Francis, R. Kabaleeshwaran
Soumi Chatterjee, Debadrita Talapatra, Nimish Mishra, Debdeep Mukhopadhyay
In this work, we introduce VERA, a framework for verifiable and privacy-preserving adversarial detection at the edge. VERA combines lightweight Hardware Performance Counter (HPC) monitoring with Zero-Knowledge Range Proofs (ZKRPs). Adversarial perturbations can alter internal activation patterns and consequently the microarchitectural behavior of inference, which can be captured through HPC measurements. Rather than revealing these potentially sensitive measurements, VERA allows an edge device to prove that a committed HPC value lies within a calibrated benign range without disclosing the value itself. This avoids the overhead of general-purpose zk-SNARKs and enables lightweight verification on resource-constrained devices.
We formalize VERA as a black-box framework that can combine an HPC-based adversarial detector with an interactive ZKRP, which can also be made non-interactive using the Fiat--Shamir transform. We evaluate VERA against multiple adversarial attacks on MNIST and CIFAR-10. Our results show millisecond-scale verification overhead, with proof-generation costs amortizable across batches of inferences. To the best of our knowledge, VERA is the first framework to provide privacy-preserving cryptographic evidence that an edge inference exhibits microarchitectural behavior within a calibrated benign regime.
Charanjit S. Jutla, Arnab Roy
The matched Groth16 prover derives three length-$n$ vectors from the R1CS instance, converts each between coefficient and evaluation form, and commits the quotient with a size-$n$ coset-Lagrange column, resulting in six FFTs in total. Its usual monomial quotient column has one fewer CRS element but requires a final inverse FFT.
Symplex instead uses the partial-fraction techniques of Jutla, Nema, Roy (EuroCrypt 2026) allowing the output-wire selector polynomials to be precomputed into the per-wire CRS bundles during setup. So, only the left- and right-wire vectors require FFT-based processing at proving time. The verifier is unchanged (three pairings, one public-input MSM). On a BLS12-381 prototype of Symplex that shares sparse R1CS, FFT, and pairing code with Groth16, a Circom circuit chaining SHA-256 ten times gives a $1.84\times$ prover speedup with online verification at $\approx 2.6\,\mathrm{ms}$ for both schemes. The uniform algebraic extraction argument, perfect completeness, and perfect zero-knowledge are machine-checked in Lean~4.
Polymath (Lipmaa, CRYPTO 2024) and PARI (Dellepere, Mishra, and Shirzad, USENIX Security 2026) shrink the proof using a squared R1CS arithmetization. Polymath proves soundness in the AGMOS model, and PARI does not provide zero-knowledge in the stated construction. Symplex keeps Groth16's proof shape and standard R1CS arithmetization, and is proved knowledge-sound in the standard Generic Group Model.
Nam Tran, Khoa Nguyen, Dongxi Liu, Josef Pieprzyk, Willy Susilo
We introduce the first \emph{compact lattice-based NIZK arguments for set membership in the standard model} with proof size logarithmic in the set cardinality. Our construction matches the logarithmic proof size of accumulator-based ROM constructions while achieving post-quantum security without random oracles. The main technical ingredient is a new trapdoor $\Sigma$-protocol supporting linear relations modulo multiple heterogeneous moduli, allowing such relations to be handled at their native moduli without homogenization. This yields a modular approach to compact proofs compatible with lattice accumulators.
As an application, we construct lattice-based ring signatures of size $O(\log R)\cdot \widetilde{O}(\lambda^{2})$ bits, improving the dependence on the security parameter $\lambda$ quadratically over the plain-model construction of Chatterjee et al. (CRYPTO~2021) while retaining optimal logarithmic dependence on the ring size $R$. Our construction is in the CRS model, which partly enables this improvement. The scheme achieves statistical anonymity and unforgeability under standard Module-LWE and Module-SIS assumptions.
We also develop two additional tools of independent interest: (i) a generalized Merkle-tree accumulator over module lattices with base-$B$ decomposition, enabling finer efficiency--assumption trade-offs; and (ii) a message-binding technique that removes the need for costly lattice one-time signatures in standard-model ring signatures.
Corrigendum to: Computing Optimal Ate Pairings on Elliptic Curves with Embedding Degree 9, 15 and 27
Walid Haddaji
Minzhang Li, Feng-Hao Liu, Guangbei Yi
In this work, we present a novel and practical Keyword PIR framework that addresses these limitations. Our construction extends the hintless KsPIR scheme of Luo et al. (CCS 2024) to the keyword setting, ensuring that a semi-honest client retrieves only the value corresponding to the queried keyword. The construction leverages the linear homomorphic technique of Peikert and Pepin (TCC 2025). To accelerate homomorphic evaluation, we design a baby-step giant-step (BSGS) implementation and an offline/online decomposition based on a Galois-theoretic formulation. Experimental results show a mean online speedup of $2.65\times$ over the generic framework when instantiated with the same index-PIR scheme, for databases containing up to $2^{22}$ entries.