I have written an elementary tutorial and a first proof of concept
about how to backdoor a block cipher in a quite general setting.
Potentially it applies to any block cipher.
Success is not guaranteed though, see the paper.
ADDED 2 JAN 2019:
a new paper shows that invariants of higher degree are substantially more powerful. Instead of a progression, we have a qualitative leap in what can be now achieved: see new paper.
ADDED 4 April 2019: here are slides presented at WCC 2019.
ADDED 18 October 2019. Here are slides presented at NSA Crypto History Conference on 18 Oct 2019.