Benchmarking Attacks on Learning with Errors
Emily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu, Kristin E. Lauter
Abstract
Lattice cryptography schemes based on the learning with errors (LWE) hardness assumption have been standardized by NIST for use as post-quantum cryptosystems, and by HomomorphicEncryption.org for performing encrypted computations on sensitive data. Thus, understanding their concrete security is critical. Most work on LWE security focuses on theoretical estimates of attack performance, which is important but may overlook attack nuances arising in real-world implementations. The sole existing concrete benchmarking effort, the Darmstadt Lattice Challenge, does not include benchmarks relevant to the standardized LWE parameter choices-such as small secret and small error distributions, and Ring-LWE (RLWE) and Module-LWE (MLWE) variants. To improve our understanding of concrete LWE security, we provide the first benchmarks for LWE secret recovery on standardized parameters, for small and low-weight (sparse) secrets. We evaluate four LWE attacks in these settings to serve as a baseline: the Search-LWE attacks uSVP [9], SALSA [51], and Cool&Cruel [44], and the Decision-LWE attack: Dual Hybrid Meet-in-the-Middle (MitM) [21]. We extend the SALSA and Cool&Cruel attacks in significant ways, and implement and scale up MitM attacks for the first time. For example, we recover hamming weight 9 - 11 binomial secrets for KYBER parameters in 28 - 36 hours with SALSA and Cool&Cruel, while we find that MitM can solve Decision-LWE instances for hamming weights up to 4 in under an hour for Kyber parameters, while uSVP attacks do not recover any secrets after running for more than 1100 hours. We also compare concrete performance against theoretical estimates. Finally, we open source the code to enable future research.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5f9967a7-fbb6-4cd3-90c1-a5d9248ecde0Cited by top-tier papers3
- Cool + Cruel = Dual, and New Benchmarks for Sparse LWEAlexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite et al.EUROCRYPT 2026 · 1 citation
- Improving ML Attacks on LWE with Data Repetition and Stepwise RegressionAlberto Alfarano, Eshika Saxena, Emily Wenger, Francois Charton et al.ICML 2026
- Making Hard Problems Easier with Custom Data Distributions and Loss Regularization: A Case Study in Modular ArithmeticEshika Saxena, Alberto Alfarano, Emily Wenger, Kristin E. LauterICML 2025
Builds on5
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- LWE with Side Information: Attacks and Concrete Security EstimationDana Dachman-Soled, Léo Ducas, Huijing Gong, Mélissa RossiCRYPTO 2020 · 162 citations
- Advanced Lattice Sieving on GPUs, with Tensor CoresLéo Ducas, Marc Stevens, Wessel P. J. van WoerdenEUROCRYPT 2021 · 44 citations
- Lattice Reduction with Approximate Enumeration Oracles - Practical Algorithms and Concrete PerformanceMartin R. Albrecht, Shi Bai, Jianwei Li, Joe RowellCRYPTO 2021 · 29 citations
- Fast Practical Lattice Reduction Through Iterated CompressionKeegan Ryan, Nadia HeningerCRYPTO 2023 · 28 citations
Related papers
- SALSA VERDE: a machine learning attack on LWE with sparse small secretsCathy Yuanchen Li, Emily Wenger, Zeyuan Allen-Zhu, François Charton et al.NeurIPS 2023 · 13 citations
- SalsaPicante: A Machine Learning Attack on LWE with Binary SecretsCathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou et al.CCS 2023 · 11 citations
- SALSA: Attacking Lattice Cryptography with TransformersEmily Wenger, Mingjie Chen, François Charton, Kristin E. LauterNeurIPS 2022 · 61 citations
- Assessing the Impact of a Variant of MATZOV's Dual Attack on KyberKévin Carrier, Charles Meyer-Hilfiger, Yixin Shen, Jean-Pierre TillichCRYPTO 2025 · 3 citations
- Module Learning With Errors and Structured Extrapolated Dihedral CosetsWeiqiang Wen, Jinwei ZhengCRYPTO 2026 · 1 citation
