The GMiMC defined over , is unbalanced Feistel network with an expanding round function (ERF). One round of GMiMC is depicted as in the following figure (b)

It can be described as

The round function \(F(\cdot)\) in round \(i\) defined as

where \(k_i\) and \(c_i\) denote the round constant and the round key in round (i), respectively. When the secret key , the round key .