SALSA: Attacking Lattice Cryptography with Transformers
Emily Wenger, Mingjie Chen, François Charton, Kristin E. Lauter
Abstract
Currently deployed public-key cryptosystems will be vulnerable to attacks by fullscale quantum computers. Consequently, "quantum resistant" cryptosystems are in high demand, and lattice-based cryptosystems, based on a hard problem known as Learning With Errors (LWE), have emerged as strong contenders for standardization. In this work, we train transformers to perform modular arithmetic and combine half-trained models with statistical cryptanalysis techniques to propose SALSA: a machine learning attack on LWE-based cryptographic schemes. SALSA can fully recover secrets for small-to-mid size LWE instances with sparse binary secrets, and may scale to attack real-world LWE-based cryptosystems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 66dd7332-abd6-4dde-a3a4-a4c0f05318a2Cited by top-tier papers4
- Learning to compute Gröbner basesHiroshi Kera, Yuki Ishihara, Yuta Kambe, Tristan Vaccon et al.NeurIPS 2024 · 9 citations
- Computational Algebra with Attention: Transformer Oracles for Border Basis AlgorithmsHiroshi Kera, Nico Pelleriti, Yuki Ishihara, Max Zimmer et al.NeurIPS 2025 · 8 citations
- Learning Plaintext-Ciphertext Cryptographic Problems via ANF-based SAT Instance RepresentationXinhao Zheng, Yang Li, Cunxin Fan, Huaijin Wu et al.NeurIPS 2024 · 7 citations
- Cool + Cruel = Dual, and New Benchmarks for Sparse LWEAlexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite et al.EUROCRYPT 2026 · 1 citation
Builds on7
- Deep Learning For Symbolic MathematicsGuillaume Lample, François ChartonICLR 2020 · 477 citations
- Neural Symbolic Regression that scalesLuca Biggio, Tommaso Bendinelli, Alexander Neitz, Aurélien Lucchi et al.ICML 2021 · 251 citations
- A Deeper Look at Machine Learning-Based CryptanalysisAdrien Benamira, David Gérault, Thomas Peyrin, Quan Quan TanEUROCRYPT 2021 · 119 citations
- The Neural Data Router: Adaptive Control Flow in Transformers Improves Systematic GeneralizationRóbert Csordás, Kazuki Irie, Jürgen SchmidhuberICLR 2022 · 70 citations
- Symbolic Brittleness in Sequence Models: On Systematic Generalization in Symbolic MathematicsSean Welleck, Peter West, Jize Cao, Yejin ChoiAAAI 2022 · 32 citations
Related papers
- SalsaPicante: A Machine Learning Attack on LWE with Binary SecretsCathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou et al.CCS 2023 · 11 citations
- SALSA VERDE: a machine learning attack on LWE with sparse small secretsCathy Yuanchen Li, Emily Wenger, Zeyuan Allen-Zhu, François Charton et al.NeurIPS 2023 · 13 citations
- Making Hard Problems Easier with Custom Data Distributions and Loss Regularization: A Case Study in Modular ArithmeticEshika Saxena, Alberto Alfarano, Emily Wenger, Kristin E. LauterICML 2025
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu et al.S&P 2025
- Continuous LWEJoan Bruna, Oded Regev, Min Jae Song, Yi TangSTOC 2021 · 18 citations
