Halfspace Learning for Lattice Signature Key Recovery from Signs
Marcus Brinkmann, Nicolai Kraus, Alexander May
Abstract
Any signature scheme has to protect its secret key via some properly chosen, secret randomness. We show that, for the lattice signatures HAWK, Falcon and ML-DSA, even minimal leakage of this randomness suffices for secret key recovery.
In particular, leaking either the Hamming weight or a single bit of any randomness coordinate allows an attacker to infer the sign of that coordinate. This corresponds to learning , where is the secret key and is public. We model key recovery from such sign information as an instance of Learning a Halfspace. This well-studied problem from learning theory provides a rich solution machinery, which we adapt for the cryptanalysis of lattice-based signatures.
As a first main result, we resolve the open problem of recovering the secret key in HAWK from sign leakage. At the 128-bit security level and in the noise-free setting, we recover the secret key from only 30 signatures in 10 minutes.
As a second main result, we recover the secret key in Falcon via sign leakage from only 100 signatures in under a minute. In comparison to existing attacks, this reduces the number of required signatures by a factor of .
As a third result, we show the first ML-DSA secret key recovery from sign leakage, which requires 190,000 signatures and completes within seconds. In comparison to existing ML-DSA attacks, we require a comparable amount of signatures, but utilize a less restrictive leakage model.
In addition, our attack is alarmingly noise-tolerant, succeeding with up to 35% noise for HAWK, 30% for Falcon, and 35% for ML-DSA, albeit requiring significantly more signatures in the noisy case.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 45c9676c-cd00-477b-aa50-c3fcc699ed2dRelated papers
- HAWK with Hint: Algebraic Key Recovery from Side-Channel LeakageByoungchan Chi, Changmin Lee, Inhun LeeCCS 2026
- Key Recovery from Gram-Schmidt Norm Leakage in Hash-and-Sign Signatures over NTRU LatticesPierre-Alain Fouque, Paul Kirchner, Mehdi Tibouchi, Alexandre Wallet et al.EUROCRYPT 2020 · 19 citations
- Improved Power Analysis Attacks on FalconShiduo Zhang, Xiuhan Lin, Yang Yu, Weijia WangEUROCRYPT 2023 · 26 citations
- A Little LESS Secure - Side-Channel Attacks Exploiting Randomness LeakageDina Hesse, Elisabeth Krahmer, Yi-Fu Lai, Jonas MeersCRYPTO 2026
- Uncompressing Dilithium's Public KeyPaco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis GoubinCRYPTO 2025 · 10 citations
