Applied Cryptography
Cryptanalysis of real-world protocols and cryptographic schemes, with a focus on post-quantum candidates, zk-SNARKs and blockchain applications.
Lili Tang (唐雳雳)
I am a Ph.D. student in Cybersecurity at the University of Chinese Academy of Sciences (UCAS), advised by Prof. Xiaorui Gong. I received my B.Sc. degree in information security from the University of Science and Technology of China (USTC) in 2022. In parallel, I was a core member of the NeSE CTF team from 2022 to 2026, focusing on crypto and blockchain in international CTF competitions.
My doctoral research primarily focuses on the Generalized Birthday Problem and Wagner’s algorithm. More broadly, I maintain strong research interests in post-quantum cryptography (especially code-based), incremental cryptography, and blockchain security.
Updates
I expect to complete my Ph.D. after June, 2027. Currently, I’m looking for postdoctoral or other research positions (Crypto/LLM/Security/AI4S). If you find my research areas matching any opportunity, please feel free to contact me via email.
Our joint work on using LLM agents to discover vulnerabilities in cryptographic libraries will be presented at the Black Hat USA 2026 Briefings. See the talk page for details.
Focus Areas
Cryptanalysis of real-world protocols and cryptographic schemes, with a focus on post-quantum candidates, zk-SNARKs and blockchain applications.
Automatic vulnerability discovery, especially for cryptographic protocols and implementations. Vibe research in the realms of cryptography and security.
Selected Work
TL;DR: We study structural regularity in the Generalized Birthday Problem and its impact on practical schemes including incremental hashing and Equihash. The main contribution of this work is the complexity analysis of regular and non-regular GBP, with important implications for the $k$-$\textsf{XOR}$ and $k$-$\textsf{SUM}$ problems.
TL;DR: We propose a new list-item-reduction framework that reduces the memory complexity of Wagner’s algorithm from $2nN$ to $nN$ bits, thereby weakening the ASIC resistance of Equihash. This optimization has important implications for the efficient implementation of Wagner-style algorithms.
TL;DR: We extend post-retrieval to Wagner’s $k$-tree algorithm, reducing peak memory from exponential in $k$ to $O(k^2\ell N)$ with only linear time overhead. Applied to preimage attacks on incremental hashes, this trade-off can substantially reduce their memory–time cost.
Talks
Guannan Wang, Lili Tang, and Guancheng Li Speakers
Selected Awards
NeSE’s crypto team: tl2cents (me), deebato, and Threonine.
Team: Lili Tang, Chenyu Li, and Hao Jiang
First independent team from mainland China to qualify for DEFCON Finals.