N. J. Alfardan and K. G. Paterson, Lucky Thirteen: Breaking the TLS and DTLS Record Protocols, IEEE Symposium on Security and Privacy, p.2013, 2013.

G. Bertoni, J. Daemen, M. Peeters, and G. V. Assche, On the Indifferentiability of the Sponge Construction, Lecture Notes in Computer Science, vol.4965, pp.181-197, 2008.
DOI : 10.1007/978-3-540-78967-3_11

P. Flajolet and A. M. Odlyzko, Random Mapping Statistics, p.75445, 2006.
DOI : 10.1007/3-540-46885-4_34

URL : https://hal.archives-ouvertes.fr/inria-00075445

T. Fuhr and G. Leurent, Observation on ?-Cipher. CAESAR's competition mailing list, 2014.

G. Leurent, Tag Second-preimage Attack against ?-cipher. https, 2014.
URL : https://hal.archives-ouvertes.fr/hal-00966794

H. Mihajloska, M. El-hadedy, D. Gligoroski, and K. Skadron, Lightweight version of ?-cipher, In: NIST Lightweight Cryptography Workshop, p.2015, 2015.