{"id":"W3172830517","doi":"10.46586/tosc.v2021.i2.389-422","title":"Algorithm Substitution Attacks: State Reset Detection and Asymmetric Modifications","year":2021,"lang":"en","type":"article","venue":"IACR Transactions on Symmetric Cryptology","topic":"Cryptographic Implementations and Security","field":"Computer Science","cited_by":7,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Stateful firewall; Computer science; Substitution (logic); Semantic security; Scheme (mathematics); Symmetric-key algorithm; Cryptography; State (computer science); Computer security; Adversary; Encryption; Simple (philosophy); Theoretical computer science; Cryptographic protocol; Reset (finance); Algorithm; Public-key cryptography; Mathematics; Programming language; Philosophy; Attribute-based encryption","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.004446446,0.0009942325,0.001087656,0.001425347,0.001078876,0.003113016,0.001946265,0.002719256,0.002624049],"category_scores_gemma":[0.03825611,0.0008375536,0.00125304,0.0009722002,0.006064114,0.01151616,0.004172017,0.004646561,0.0005604851],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001006056,"about_ca_system_score_gemma":0.001097264,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0003267833,"about_ca_topic_score_gemma":0.000186771,"domain_scores_codex":[0.9900191,0.00339294,0.0008119768,0.001936862,0.002917818,0.0009213187],"domain_scores_gemma":[0.9552821,0.01882559,0.005352303,0.01796543,0.002008104,0.0005664831],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001049061,0.0003550531,0.01575752,0.0004752493,0.0002032445,0.001611691,0.002142223,0.04979637,0.04721311,0.755607,0.002475954,0.1233135],"study_design_scores_gemma":[0.0001431934,0.0008454449,0.002751564,0.0002093436,0.0002345651,0.003283867,0.0004906819,0.4201575,0.09447826,0.4673629,0.009876809,0.0001658671],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2034216,0.0006863638,0.7811832,0.001279415,0.0001750419,0.0003480453,0.0001446867,0.002118513,0.01064316],"genre_scores_gemma":[0.9602982,0.0001827669,0.03735432,0.0002414067,0.00008175585,0.0001209322,0.00006375756,0.0001119977,0.001544878],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004446446,"threshold_uncertainty_score":0.02351534,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02404941094490313,"score_gpt":0.285916197675827,"score_spread":0.2618667867309238,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}