Submitted:
04 August 2026
Posted:
05 August 2026
You are already at the latest version
Abstract
This paper investigates the use of genetic algorithms to search for collisions in internal hash-like transformations of the Data Encryption Standard (DES). Two approaches are considered. The first searches directly for two message--key pairs that produce identical outputs under the DES round function. Although this strategy rapidly reduces the Hamming distance between candidate outputs, it does not consistently reach an exact collision within practical time. The second removes the simultaneous key-search requirement and searches for message pairs that collide at the DES S-box layer, after which a compatible key is derived algebraically. This second strategy is substantially more successful and identifies colliding message pairs within minutes for sufficiently large populations. The effects of mutation rate and mating-pool size are also examined. The results show that adaptive mutation and larger populations improve convergence and that genetic search can be an effective approximate method for discovering collisions in constrained cryptographic components.
Keywords:
genetic algorithm
; DES
; collision search
; S-box
; cryptanalysis
; Hamming distance
; evolutionary computation
1. Introduction
Digital signatures authenticate electronic documents and verify their origin. Their security depends not only on the encryption method but also on the hash function used to represent the message. A cryptographic hash function maps an arbitrary-length input to a fixed-length output, and a collision occurs when two distinct inputs produce the same result [1,2,3].
Collision analysis is useful both for evaluating cryptographic robustness and for revealing structural weaknesses. Traditional approaches include birthday attacks, differential cryptanalysis, and linear cryptanalysis. Linear cryptanalysis has been studied extensively for DES-like block ciphers and related constructions [4,5]. These techniques can become computationally expensive as the output size grows.
Evolutionary algorithms provide an alternative because they can explore large search spaces without requiring a complete analytical model of the target function. Genetic algorithms have been applied to cryptographic key generation and cryptanalysis, including DES-like systems [6,7]. Related artificial-life methods have also been investigated for automated test-data generation [8].
More broadly, evolutionary computation and machine learning have demonstrated considerable success in solving complex optimization and search problems across diverse domains. Fundamental developments in genetic algorithms and evolutionary computation have established powerful frameworks for exploring large, nonlinear, and highly constrained search spaces [9,10,11,12]. These methods have subsequently been applied successfully to face detection and recognition [13,14,15,16], biometric identification [17,18], computer vision and deformable texture analysis [19,20], healthcare prediction and intelligent medical image analysis [21,22,23,24,25,26,27], autonomous decision making using deep reinforcement learning [28], and machine-learning software development [29,30]. Similar optimization principles have also played an important role in modern cryptography and security analysis [31]. Collectively, these studies demonstrate that evolutionary search provides an effective framework for solving difficult optimization problems, motivating its application to collision discovery in nonlinear cryptographic transformations such as the DES round function and its S-boxes.
This study applies a genetic algorithm to collision search in internal DES transformations. The first approach searches simultaneously for two colliding message–key pairs at the DES round-function level. The second searches for collisions at the S-box level and then derives a compatible key. The second approach is considerably more practical.
2. DES Encryption
DES is a symmetric block cipher operating on 64-bit blocks with a 56-bit effective key. It was standardized in the United States as Federal Information Processing Standard Publication 46 [32]. Although DES is no longer considered secure for modern applications, its Feistel structure and substitution boxes remain important in the study of block-cipher design [2,3].
A plaintext block is first processed by an initial permutation, divided into left and right halves, and passed through 16 Feistel rounds. In round i,
where is the 48-bit round key.
Figure 1.
Overall DES structure with initial permutation, 16 Feistel rounds, and inverse initial permutation.
Figure 1.
Overall DES structure with initial permutation, 16 Feistel rounds, and inverse initial permutation.

2.1. DES Round Function
The DES round function has five principal stages:
- 1.
- expansion of the 32-bit right half to 48 bits;
- 2.
- bitwise exclusive-OR with the 48-bit round key;
- 3.
- division into eight 6-bit blocks;
- 4.
- substitution through eight S-boxes, each mapping 6 bits to 4 bits; and
- 5.
- permutation of the resulting 32-bit output.
The round function is
where E is the expansion permutation, S denotes the eight S-box transformations, and P is the final permutation.
Figure 2.
Internal structure of the DES round function.

2.2. DES S-Boxes
Substitution boxes are central to the nonlinear security properties of block ciphers. S-box design criteria and construction methods have therefore been studied extensively [1,33].
Each DES S-box maps a 6-bit input to a 4-bit output. Since 64 possible inputs map to only 16 outputs, collisions necessarily exist at the S-box level. For an input , the row is determined by and the column by .
For example, if the S-box input is 011011, then the row is and the column is . The S-box output is obtained from the corresponding lookup-table entry.
This many-to-one mapping makes the S-box layer a natural location for collision search.
3. Genetic-Algorithm-Based Collision Search
3.1. First Approach: Message–Key Pair Search
The first approach searches for
such that
Each chromosome contains two messages and two keys. Fitness is based on the Hamming distance between the corresponding outputs:
where is the indicator function. The objective is to minimize to zero.
3.1.1. Fitness Function
A simplified version of the implemented fitness function is shown below.

3.1.2. Mutation
Mutation flips message and key bits with a specified probability. A high mutation rate is used initially to encourage broad exploration. As the Hamming distance decreases, the mutation rate is reduced to support local refinement.
3.1.3. Crossover
A crossover operator exchanges chromosome segments between parent candidates. Similar genetic operators have been used in cryptographic search and DES-like cryptanalysis [6,7]. Although crossover increases diversity, it can also cause rapid population uniformity if combined with overly aggressive selection.
3.1.4. Immigration
An immigration operator replaces a small percentage of chromosomes with newly generated random candidates. In the experiments, the immigration probability was approximately 5%. This mechanism helps prevent premature convergence and mating-pool stagnation.
3.1.5. Selection
Chromosomes are ranked by fitness, and the stronger candidates are retained. To preserve diversity, a small probability is assigned to retaining lower-ranked candidates, because weak parents may still generate useful offspring.
3.1.6. Outcome of the First Approach
The first approach reduced Hamming distance quickly, often from approximately 20 bits to 4 or 5 bits. Extended runs reached distances of 1 or 2 bits, but exact collisions were not obtained reliably within practical computation times. This indicates that simultaneous optimization over two messages and two keys produces a very large search space.
3.2. Second Approach: S-Box Collision Search
The second approach selects a random message and key and computes
The genetic algorithm searches for such that
After identifying a colliding S-box input, a compatible key is derived by
Thus,
Figure 3.
Second collision-search approach. A colliding S-box input is identified and a compatible key is then derived.
Figure 3.
Second collision-search approach. A colliding S-box input is identified and a compatible key is then derived.

3.3. Genetic Operators in the Second Approach
The chromosomes in the second approach contain candidate messages rather than complete message–key pairs. Mutation, crossover, immigration, and fitness-based selection are applied in each generation.

4. Experimental Results
4.1. Effect of Mutation Rate
Mutation rate had a strong effect on convergence. Very high mutation rates improved global exploration but disrupted promising partial solutions. Lower and adaptive mutation rates generally produced faster convergence.
The most effective observed schedule was approximately:
- 40% at the beginning;
- 30% when Hamming distance was below 10;
- 20% when Hamming distance was below 5; and
- 10% when Hamming distance was below 4.
This schedule balanced global exploration and local refinement.
4.2. Effect of Population Size
Increasing the mating-pool population substantially improved the probability and speed of convergence. Populations near 800–900 chromosomes often produced collisions within several minutes.
4.3. Collision Examples
One observed collision pair was
with the common S-box output
Another observed pair was
with the common output
4.4. Software Output
Figure 4 shows a successful collision with zero Hamming distance.
Figure 5 shows the derived key and colliding message pair.
5. Implementation
The algorithm was implemented in C# using the Microsoft .NET environment. The implementation follows an object-oriented design.
5.1. Main Classes
The software contains five principal classes:
- Chromosome, which stores candidate messages, keys, outputs, fitness values, and mutation logic;
- Pool, which manages sorting, crossover, immigration, mutation, and selection;
- Form1, which provides the graphical user interface and controls execution;
- RandNum, which generates pseudo-random numbers; and
- HashDESOne, which implements the internal DES transformation used in collision search.
The modular structure allows the DES-specific transformation to be replaced by another hash or substitution function.
5.2. Execution Procedure
The user first selects the population size and monitoring interval. A random mating pool is then generated, and the genetic algorithm runs until either a collision is found or the process is manually stopped.
The Hamming distance is displayed continuously, and the target value is zero. Because the method is stochastic, convergence time varies. Typical successful runs required approximately 10–20 minutes, although some runs did not converge within several hours.
6. Discussion
The first approach searches a very large space because it evolves two messages and two keys simultaneously. Although it reduces Hamming distance effectively, it does not consistently find exact collisions.
The second approach is more successful because it exploits the many-to-one structure of DES S-boxes. By finding a colliding S-box input first and deriving a compatible key afterward, the dimensionality of the search is reduced substantially.
The results also show that adaptive mutation is more effective than a uniformly high mutation rate and that larger populations improve diversity and convergence. These observations are consistent with previous uses of genetic search in cryptography [6,7].
This work does not imply that modern cryptographic systems can be broken using the presented implementation. DES is obsolete, and S-box-level collisions are structurally inevitable because each S-box maps 64 possible inputs to 16 outputs. The contribution is methodological: evolutionary search can be applied to constrained nonlinear cryptographic transformations.
7. Conclusions
This paper investigated genetic-algorithm-based collision search in DES internal transformations. Two approaches were evaluated. The first searched for colliding message–key pairs at the round-function level but did not reliably produce exact collisions. The second searched for collisions at the S-box level and then derived compatible keys. This strategy was successful within practical time for sufficiently large populations. Future work should investigate parallel implementations, more advanced evolutionary operators, multi-objective fitness functions, and reduced-round modern cryptographic structures.
References
- Preneel, B. Analysis and Design of Cryptographic Hash Functions. PhD Thesis, Katholieke Universiteit Leuven 1993.
- Buchmann, J.A. Introduction to Cryptography; Springer, 2000.
- Stallings, W. Network Security Essentials: Applications and Standards, 4 ed.; Pearson, 2011.
- Matsui, M. Linear Cryptanalysis Method for DES Cipher. In Proceedings of the Advances in Cryptology – EUROCRYPT ’93. Springer, 1994, pp. 386–397.
- Matsui, M. The First Experimental Cryptanalysis of the Data Encryption Standard. In Proceedings of the Advances in Cryptology – CRYPTO ’94. Springer, 1994, pp. 1–11.
- Jawaid, M.; Shah, T. A Best-Fit Genetic Algorithm for Cryptanalysis of DES. International Journal of Computer Applications 2014, 95, 1–8.
- Hassan, M.; Youssef, A. Genetic Algorithms in Cryptanalysis. International Journal of Network Security 2009, 8, 123–130.
- Bhasin, H.; Sharma, P. Automatic Test Data Generation Using Genetic Algorithms. International Journal of Computer Applications 2014, 98, 15–21.
- Holland, J.H. Adaptation in Natural and Artificial Systems; University of Michigan Press, 1975.
- Goldberg, D.E. Genetic Algorithms in Search, Optimization, and Machine Learning; Addison-Wesley, 1989.
- Koza, J.R. Genetic Programming: On the Programming of Computers by Means of Natural Selection; MIT Press, 1992.
- Bäck, T. Evolutionary Algorithms in Theory and Practice; Oxford University Press, 1996.
- Hajati, F.; Faez, K.; Pakazad, S.K. An Efficient Method for Face Localization and Recognition in Color Images. In Proceedings of the Systems, Man and Cybernetics, 2006. SMC’06. IEEE International Conference on. IEEE, 2006, Vol. 5, pp. 4214–4219.
- Pakazad, S.K.; Faez, K.; Hajati, F. Face Detection Based on Central Geometrical Moments of Face Components. In Proceedings of the Systems, Man and Cybernetics, 2006. SMC’06. IEEE International Conference on, 2006, pp. 4225–4230.
- Hajati, F.; Raie, A.A.; Gao, Y. Pose-invariant 2.5 D face recognition using geodesic texture warping. In Proceedings of the 2010 11th International Conference on Control Automation Robotics & Vision. IEEE, 2010, pp. 1837–1841.
- Ayatollahi, F.; Raie, A.A.; Hajati, F. Expression-invariant face recognition using depth and intensity dual-tree complex wavelet transform features. Journal of Electronic Imaging 2015, 24, 023031–023031.
- Shojaiee, F.; Hajati, F. Local composition derivative pattern for palmprint recognition. In Proceedings of the 2014 22nd Iranian Conference on Electrical Engineering (ICEE). IEEE, 2014, pp. 965–970.
- Abdoli, S.; Hajati, F. Offline signature verification using geodesic derivative pattern. In Proceedings of the 2014 22nd Iranian Conference on Electrical Engineering (ICEE). IEEE, 2014, pp. 1018–1023.
- Hajati, F.; Cheraghian, A.; Gheisari, S.; Gao, Y.; Mian, A.S. Surface geodesic pattern for 3D deformable texture matching. Pattern Recognition 2017, 62, 21–32.
- Cremers, D.; Reid, I.; Saito, H.; Yang, M.H. Computer Vision–ACCV 2014: 12th Asian Conference on Computer Vision, Singapore, Singapore, November 1-5, 2014, Revised Selected Papers, Part V; Springer, 2015.
- Fiorini, S.; Hajati, F.; Barla, A.; Girosi, F. Predicting diabetes second-line therapy initiation in the Australian population via timespan-guided neural attention network. PLOS ONE 2019, 10, e0211844.
- Lu, H.; Uddin, S.; Hajati, F.; Khushi, M.; Moni, M.A. Predictive risk modelling in mental health issues using machine learning on graphs. In Proceedings of the 2022 Australasian Computer Science Week; 2022; pp. 168–175.
- Tavakolian, A.; Hajati, F.; Rezaee, A.; Fasakhodi, A.O.; Uddin, S. Fast COVID-19 versus H1N1 screening using optimized parallel inception. Expert systems with applications 2022, 204, 117551.
- Tavakolian, A.; Rezaee, A.; Hajati, F.; Uddin, S. Hospital readmission and length-of-stay prediction using an optimized hybrid deep model. Future Internet 2023, 15, 304.
- Khan, M.W.; Sheng, H.; Zhang, H.; Du, H.; Wang, S.; Coroneo, M.; Hajati, F.; Shariflou, S.; Kalloniatis, M.; Phu, J.; et al. RVD: a handheld device-based fundus video dataset for retinal vessel segmentation. In Proceedings of the NeurIPS, 2024.
- Zobeiri, A.; Rezaee, A.; Hajati, F.; Argha, A.; Alinejad-Rokny, H. Post-cardiac arrest outcome prediction using machine learning: a systematic review and meta-analysis. International journal of medical informatics 2025, 193, 105659.
- Jamshidiha, S.; Rezaee, A.; Hajati, F.; Golzan, M.; Chiong, R. An explainable transformer model for Alzheimer’s disease detection using retinal imaging. Scientific reports 2025, 15, 26773.
- Rafiei, A.; Fasakhodi, A.O.; Hajati, F. Pedestrian collision avoidance using deep reinforcement learning. International journal of automotive technology 2022, 23, 613–622.
- Tavakolian, A.; Hajati, F.; Rezaee, A.; Fasakhodi, A.O.; Uddin, S. Source code for optimized parallel inception: A fast COVID-19 screening software. Software Impacts 2022, 13, 100337.
- Wang, S.; Lu, H.; Khan, A.; Hajati, F.; Khushi, M.; Uddin, S. A machine learning software tool for multiclass classification. Software Impacts 2022, 13, 100383.
- Schneier, B. Applied Cryptography: Protocols, Algorithms, and Source Code in C, 2 ed.; John Wiley & Sons, 1996.
- National Bureau of Standards. Data Encryption Standard (DES), 1977. Federal Information Processing Standards Publication 46.
- Sadeghiyan, B.; Dakhilalian, M.R. A New Method for Designing Cryptographically Strong S-Boxes. Proceedings of ISCISC 1997.
Figure 4.
Software interface showing a successful collision with zero Hamming distance.

Figure 5.
Software interface showing colliding messages, corresponding keys, and identical DES S-box outputs.
Figure 5.
Software interface showing colliding messages, corresponding keys, and identical DES S-box outputs.

Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.