At CRYPTO 2020, Liu et al. demonstrated that many differentials on Gimli are, in fact, incompatible. Similar incompatibilities also arise in related-key differentials on AES, which are typically addressed in an ad-hoc manner by incorporating additional constraints into the searching models. However…