J. Aumasson and W. Meier, Zero-sum distinguishers for reduced Keccak-f and for the core functions of Luffa and Hamsi, Presented at the rump session of Cryptographic Hardware and Embedded Systems - CHES 2009, 2009.

G. Bertoni, J. Daemen, M. Peeters, and G. Van-assche, Keccak sponge function family main document, 2009.

C. Boura and A. Canteaut, Zero-Sum Distinguishers for Iterated Permutations and Application to Keccak-f and Hamsi-256, SAC 2010 -Selected Areas in Cryptography, 2010.
DOI : 10.1007/3-540-45708-9_19

URL : https://hal.archives-ouvertes.fr/hal-00738200

C. Decannì-ere, H. Sato, and D. Watanabe, The reasons for the change of Luffa

C. Decannì-ere, H. Sato, and D. Watanabe, Hash Function Luffa: Specification, 2008.

C. Decannì-ere, H. Sato, and D. Watanabe, Hash Function Luffa: Specification. Submission to NIST, 2009.

A. Canteaut and M. Videau, Degree of Composition of Highly Nonlinear Functions and Applications to Higher Order Differential Cryptanalysis, Advances in Cryptology -EUROCRYPT 2002, pp.518-533, 2002.
DOI : 10.1007/3-540-46035-7_34

D. Khovratovich, M. Naya-plasencia, A. Röck, and M. Schläffer, Cryptanalysis of Luffa v2 Components, SAC 2010 -Selected Areas in Cryptography, 2010.
DOI : 10.1007/3-540-45708-9_19

L. R. Knudsen, Truncated and higher order differentials, Fast Software Encryption -FSE'94, pp.196-211, 1995.
DOI : 10.1007/3-540-60590-8_16

L. R. Knudsen and V. Rijmen, Known-Key Distinguishers for Some Block Ciphers, Advances in cryptology -ASIACRYPT 2007, pp.315-324, 2007.
DOI : 10.1007/978-3-540-76900-2_19

X. Lai, Higher order derivatives and differential cryptanalysis on the occasion of his 60'th birthday, Proc. " Symposium on Communication, Coding and Cryptography, 1994.

D. Watanabe, Y. Hatano, T. Yamada, and T. Kaneko, Higher Order Differential Attack on Step-Reduced Variants of Luffa??v1, Fast Software Encryption -FSE 2010, pp.270-285, 2010.
DOI : 10.1007/978-3-642-13858-4_15