The Boomerang Attack on 5 and 6-Round Reduced AES

In this note we study security of 128-bit key 10-round AES against the boomerang attack. We show attacks on AES reduced to 5 and 6 rounds, much faster than the exhaustive key search and twice faster than the Square attack of the AES designers. The attacks are structural and apply to other SPN ciphers with incomplete diffusion.