1. Andreeva, E., Bogdanov, A., Mennink, B.: Towards Understanding the Known-Key Security of Block Ciphers. In: FSE 2013, volume 8424 of LNCS, pp. 348–366, (2013)
2. Aumasson, J.-P., Meier, W.: Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi, 2009. In: Presented at the Rump Session of Cryptographic Hardware and Embedded Systems—CHES (2009)
3. Bellare, M., Micciancio, D.: A New Paradigm for Collision-Free Hashing: Incrementality at Reduced Cost. In: EUROCRYPT 1997, vol. 1233 of LNCS, pp. 163–192 (1997).
4. Bertoni, G., Daemen, J., Peeters, M., Van Assche, G.: Note on zero-sum distinguishers of Keccak-f. 2010. Unpublished, http://keccak.noekeon.org/NoteZeroSum.pdf.
5. Biryukov, A., Khovratovich, D., Nikolić, I.: Distinguisher and Related-Key Attack on the Full AES-256. In: CRYPTO 2009, volume 5677 of LNCS, pp. 231–249, (2009)