USENIX Security2026Top-tier venue
Unlocking the True Potential of Decryption Failure Oracles: A Hybrid Adaptive-LDPC Attack on ML-KEM Using Imperfect Oracles
Qian Guo, Denis Nabokov, Thomas Johansson
Abstract
Side-channel attacks exploiting Plaintext-Checking (PC) and Decryption Failure (DF) oracles are a pressing threat to deployed post-quantum cryptography. These oracles can be instantiated from tangible leakage sources like timing, power, and microarchitectural behaviors, making them a practical concern for leading schemes based on lattices, codes, and isogenies. In this paper, we revisit chosen-ciphertext sidechannel attacks that leverage the DF oracle on ML-KEM. While DF oracles are often considered inefficient compared to their binary PC counterparts in lattice-based schemes, we demonstrate that their full potential has been largely unrealized. We introduce a novel attack framework that combines adaptive query generation with belief propagation for Low-Density Parity-Check (LDPC) codes. Our methodology crafts carefully balanced parity checks over multiple secret coefficients, maximizing the Shannon information extracted from each oracle query, even in the presence of significant noise. This approach dramatically reduces the number of queries required for a full key recovery, achieving near-optimal efficiency by approaching the theoretical Shannon information bound. For ML-KEM-768 with an oracle accuracy of 95%, our attack requires only 2 950 queries (a 1.35 ratio to the Shannon lower bound), establishing that a well-designed DF attack can surpass the efficiency of state-of-the-art binary PC attacks. To validate the practical impact of our findings, we apply our framework to the recent GoFetch attack, showing significant gains in this real-world, microarchitectural sidechannel scenario. Our method reduces the required measurement traces by over an order of magnitude and eliminates the need for computationally expensive post-processing, enabling a full key recovery on higher-security schemes previously considered intractable. * Equal contribution, alphabetical order.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d2fe00e-e9f5-469f-aaac-d3f7f56f4c44Builds on7
- A Key-Recovery Timing Attack on Post-quantum Primitives Using the Fujisaki-Okamoto Transformation and Its Application on FrodoKEMQian Guo, Thomas Johansson, Alexander NilssonCRYPTO 2020 · 84 citations
- GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent PrefetchersBoru Chen, Yingchen Wang, Pradyumna Shome, Christopher W. Fletcher et al.USENIX Security 2024 · 52 citations
- Divide and Surrender: Exploiting Variable Division Instruction Timing in HQC Key Recovery AttacksRobin Leander Schröder, Stefan Gast, Qian GuoUSENIX Security 2024 · 12 citations
- The Insecurity of Masked Comparisons: SCAs on ML-KEM's FO-TransformJulius Hermelink, Kai-Chun Ning, Richard Petri, Emanuele StriederCCS 2024 · 3 citations
- CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNPStefan Gast, Hannes Weissteiner, Robin Leander Schröder, Daniel GrussNDSS 2025
Related papers
- Finding and Protecting the Weakest Link - On Side-Channel Attacks on in Masked ML-DSAJulius Hermelink, Kai-Chun Ning, Richard PetriCRYPTO 2025 · 4 citations
- CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production SoftwareYuanyuan Yuan, Zhibo Liu, Shuai WangUSENIX Security 2023
- Partial Key Exposure Attacks on BIKE, Rainbow and NTRUAndre Esser, Alexander May, Javier A. Verbel, Weiqiang WenCRYPTO 2022 · 22 citations
- Cryptanalysis of LEDAcryptDaniel Apon, Ray A. Perlner, Angela Robinson, Paolo SantiniCRYPTO 2020 · 16 citations
- Uncompressing Dilithium's Public KeyPaco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis GoubinCRYPTO 2025 · 10 citations
