Send email Copy Email Address
2026-10-06
Eva Michely

"There is no reason for me to be in this field other than love for it": In Conversation with Dhekra Mahmoud 

Dhekra Mahmoud has been recognized by the “L'Oréal-UNESCO For Women in Science – Young Talents France” program. This prestigious program is dedicated to supporting outstanding young female researchers working in STEM fields. Now a postdoctoral researcher at CISPA, Dhekra is honored for her work on the formal verification on cryptographic protocols, which she conducted during her PhD and early postdoc at the University Clermont Auvergne. In this interview, we talk to Dhekra not only about the research that won her this award, but also about her early fascination for cryptography and the importance of female role models in computer science.

Dhekra, your PhD has recently been recognized by the L’Oréal-UNESCO For Women in Science – Young Talents France program. What does this honor mean to you?

If it wasn’t an award for female researchers, I would not have applied for it. I am in this field because I love what I do and there is no reason for me to be in this field other than love for it. It’s not about money or recognition.

In a perfect world, there wouldn’t be a set of awards dedicated to women in science. In a perfect world, I would even object to the very term “women in science.” But during most of my academic career, I’ve felt that women are not being taken seriously. When I say something and a male researcher says something, I have to say it louder, or I have to say it twice.

When I saw the other recipients, I was really impressed by what these women are doing in medicine, in biology, in many different fields. The problem is that we are not that many compared to men, and so we are in the background of the picture. It’s a good thing to try and strike a balance and pay more attention to women.

"The absence of female role models I think can lead to doubt in other women. When I wake up in the morning, I don’t think of myself as a woman. When I enter the lab, I don’t think of myself as a woman. I think of myself as me. But ours is a very male field.”

In the acknowledgements of your PhD thesis, you write that you “hope for a future where [gender] parity is the norm.” Has there been a lack of female role models throughout your academic career?

I’d like to put it this way: I cannot recall a single female computer scientist who is famous in the way Alan Turing is famous, much less a famous female cryptographer. The absence of female role models I think can lead to doubt in other women. When I wake up in the morning, I don’t think of myself as a woman. When I enter the lab, I don’t think of myself as a woman. I think of myself as me. But ours is a very male field, and for some women this can lead to questions such as, “am I going to find my place, am I going to be taken seriously?” Having more female role models would help other women to see, “oh, if they did it, then maybe I can do it too.”

How did you find your way into academia, and into cryptography in particular?

Even when I was studying for my first degree in engineering, I already wanted to do cryptography. I liked abstract mathematics like algebra and the algorithmic aspect of computer science, so I searched for a field that combines both and found cryptography. Unfortunately, in Tunisia, there is no university that offers courses in cryptography, so I studied applied mathematics, which was at least halfway there.

After I finished engineering school, I decided to focus on cryptography properly and applied to the University of Bordeaux, where they have a very cool MA program on cryptoanalysis and cryptology. It was there, when I was writing my master’s thesis under the supervision of Pascal Lafourcade, that I was introduced to formal methods in applied cryptography. Pascal then also suggested that I do a PhD with him and I was like, “yes, that’s cool!”

Where did your early fascination with cryptography come from? 

I didn’t know exactly what cryptography was at the time, but I did understand that it was a field where algebra and computer science were combined, and combining those two fields was my main interest. And it was also considered kind of cool to do crypto—it was something you saw in the movies.

"I didn’t know exactly what cryptography was at the time, but I did understand that it was a field where algebra and computer science were combined, and combining those two fields was my main interest."

In France, a PhD has to be completed within three years. That’s a limited time span for a substantial piece of research.

Before I started the PhD, I had no way of knowing whether it was sufficient time or not. At the beginning, three years sounded like a lot. Especially to me, because I had already done five years of engineering school plus two years of the MA program. But then, in the first year, all I did was bibliographic research and reading, and at the end of that, there were only two years left. And in France, your defense also has to take place within those three years.

Very impressively, you actually published five papers during your PhD.

It was hard work, it really was. But I wasn’t alone, I collaborated with other people on some of my papers, so it’s a story of collaboration. It is frustrating to many PhD students when they see someone like me with five publications, but the number and rank of your publications is actually the wrong measurement for good science. Many papers that get submitted are not actually ready for publication. We can work the whole three years extensively on a topic and publish a paper, and we can also work six months on a topic and publish a paper, and it’s just not the same quality of research that results from this. There are many people who have only had one single publication during their PhD and I assume that they have been more impactful than other people who have had five.

Your PhD thesis is based on the papers that you published during that time. What is one of the main findings that you arrived at during your PhD?

I will have to provide some context before answering your question: If I give you a protocol written by a human being and ask you to assess what security property this protocol guarantees, there is a problem: This protocol was described in human language, which is very interpretable. This means that you might miss something or interpret something the wrong way. So, we need to describe this protocol in a language that is clear and unambiguous, that is not open to different interpretations. This is where formal languages come in: Once we have described the protocol in formal language, we are also able to analyze the security properties.

In this field, which is called formal verification, we have two main models. One is symbolic, and the other one is computational or cryptographic. During my PhD, I mainly worked on the symbolic model. If the protocol contains a function that encrypts a secret, there is just going to be a symbol that stands in for this function. Based on this symbolic abstraction, we can then analyze the protocol. But one thing the symbolic model cannot do is deal with the details of cryptographic primitives. Many attacks, which are attacks on the protocol itself, are based on these primitives, and they remain hidden when we analyze protocols in the symbolic model.

One of the contributions I made in my thesis was that I proposed many more details; a more refined and complex symbolic model of those primitives. I was thus able to catch many attacks that the more abstract model had previously missed. Someone contacted me recently who was analyzing an electronic voting protocol and he said that with the usual equational theory, he couldn’t find anything, but when he copy-pasted my refined equational theory, he found that the protocol was actually subject to an attack.

"The way the field is shaped and the way other researchers treat you should have no impact on you. So, my advice would be, be confident, don’t doubt yourself. But if you do want to doubt yourself, do it for reasons that matter, not for absurd ones."

Does your postdoctoral project build on the work you did during your PhD?

During my PhD, I figured out that I really loved analyzing protocols. This is a bit of a cliché, but I love case studies. All protocols are not the same, and even their patterns and security properties are not the same. So, for me, this is challenging. My PhD was mainly focused on the analysis of protocols, which means that there was no big theoretical framework. During my postdoc, I want to also work on something more theoretical, which is what Cas Cremers and I agreed on before I came to CISPA earlier this year.

What advice would you like to share with female scientists who are just starting out on their career?

Since primary school, I had always been at the top of my class, but even with that experience I started to doubt myself at some point, for example, when some researcher was treating me differently from my male colleagues. I compared the way they treated me to how they were treating the others around me, but the way the field is shaped and the way other researchers treat you should have no impact on you. So, my advice would be, be confident, don’t doubt yourself. But if you do want to doubt yourself, do it for reasons that matter, not for absurd ones.