Principal Applied Scientist · AWS AI Security

Tancrède Lepoint.

I build security grounded in proofs,
tested in practice.

AI security, post-quantum cryptography, and privacy.
From formal guarantees to standards and production.

Tancrède Lepoint
Cryptographer. Builder. Curious by default.
Selected work

Deploying research in production.

All publications
01 / AI SECURITY

Making AI systems easier to trust.

LLM applications can fail without a useful trace. I work on methods that make those failures easier to isolate, and combine language models with symbolic engines to check answers.

As tech lead and science lead at AWS AI Security, I set technical direction across research and engineering. My current work spans testing LLM-integrated applications, agent security, and privacy.

See how it works & related research
From a question to a complete answer. An under-specified question leaves date and territory free. Symbolic execution finds 17 outcomes; one targeted follow-up reduces them to two cited answers, checked against the rule engine (NeSy 2026).
  • The question is a region Under-specified questions to rule engines define regions, not points. An LLM maps the stated facts to a symbolic region; concolic execution covers every reachable outcome, and Z3 verifies the resulting cited partition. When it is too large, the system asks one targeted follow-up. NeSy 2026.
  • Delta debugging for LLM-integrated systems LLM applications fail opaquely: no execution paths, no stack traces, non-deterministic outputs. We wrap each input segment in a verifiable semantic marker, have the model cite markers in its reasoning, and use delta debugging to shrink hundreds of segments to the few that cause the failure. ICSE-SEIP 2026.
  • Advances and open problems in federated learning The foundational survey of federated learning, covering privacy, robustness, and systems challenges. Foundations and Trends in Machine Learning, 2021.
02 / POST-QUANTUM CRYPTOGRAPHY

Building for a post-quantum world.

The internet needs cryptography that can withstand quantum attacks. I co-designed CRYSTALS-Kyber and CRYSTALS-Dilithium with an international team of cryptographers.

My work connects lattice-based design, security analysis, and implementation, deploying cryptographic systems in production.

A little noise, a hard problem: explore the cryptography
The hard problem underneath. Learning With Errors: multiply a public matrix A by a secret vector s, add small noise e, publish the result b. Recovering s from (A, b) is believed hard, even for a quantum computer. ML-KEM and ML-DSA are built on lattice problems of this shape.
03 / PRIVACY-ENHANCING TECHNOLOGIES

Using data without exposing it.

Useful data should not require giving up privacy. I build cryptographic and differential-privacy systems that let organizations compute, query, and learn while protecting sensitive information.

Across Google, Apple, and AWS, I contributed to private information retrieval, secure aggregation, anonymous credentials, and verified foundations for differential privacy.

Explore the protocols & deployments
Private information retrieval. The client’s query travels encrypted; the server computes over its whole database under homomorphic encryption and returns one encrypted record, without ever learning which one (Usenix 2021).
About & approach

From the proof to the product.

I’m a researcher and engineer who likes seeing a rigorous idea survive contact with the real world. I lead technical work across research, engineering, security, and legal teams, from setting direction to building and operating production systems.

The tools change: security reductions in lattice cryptography, machine-checked proofs in differential privacy, symbolic verification in AI. The discipline stays the same: explicit threat models, formal guarantees, and honest claims about what is and isn’t proven.

My Ph.D. at École Normale Supérieure and the University of Luxembourg received the Gilles Kahn Dissertation Award in 2014. Read the thesis ↗

A small graph-theory detour: my Erdős number is 3, through Claire Mathieu and Eli Upfal.

A path through research & engineering

  1. 2022–presentAmazon Web Services

    Principal Applied Scientist
    AI Security; previously Provable Security & Automation

  2. 2021–2022Apple

    Cryptographic Engineer

  3. 2018–2021Google

    Senior Research Scientist

  4. 2016–2018SRI International

    Senior Computer Scientist

  5. 2011–2016CryptoExperts

    Junior Security Expert

Download my CV (PDF) ↓
Open source

I build things, too.

fhe.rs is my fully homomorphic encryption library in pure Rust, implementing the BFV scheme. I also contributed to Google’s shell-encryption library.

Explore fhe.rs on GitHub ↗
Recently

News & milestones

Appointed IACR IT Manager, a board-appointed position.

Professional service

IT Manager IACR 2026–present (board-appointed)
Director IACR 2018–2024
Co-editor Cryptology ePrint Archive 2016–2023
General Chair CRYPTO 2024
Program Chair WAHC 2020WAHC 2019
Program committees & past service

Get in touch

Have a question about my work, an idea to explore together, or a role in mind? Feel free to email me.