SalsaPicante: A Machine Learning Attack on LWE with Binary Secrets
Cathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou, Evrard Garcelon, François Charton, Kristin E. Lauter
Abstract
Learning With Errors (LWE) is a hard math problem underpinning many proposed post-quantum cryptographic (PQC) systems. The only PQC Key Exchange Mechanism (KEM) standardized by NIST [13] is based on module LWE, and current publicly available PQ Homomorphic Encryption (HE) libraries are based on ring LWE [2]. The security of LWE-based PQ cryptosystems is critical, but certain implementation choices could weaken them. One such choice is sparse binary secrets, desirable for PQ HE schemes for efficiency reasons. Prior work S [51] demonstrated a machine learningbased attack on LWE with sparse binary secrets in small dimensions ( ≤ 128) and low Hamming weights (ℎ ≤ 4). However, this attack assumes access to millions of eavesdropped LWE samples and fails at higher Hamming weights or dimensions. We present P , an enhanced machine learning attack on LWE with sparse binary secrets, which recovers secrets in much larger dimensions (up to = 350) and with larger Hamming weights (roughly /10, and up to ℎ = 60 for = 350). We achieve this dramatic improvement via a novel preprocessing step, which allows us to generate training data from a linear number of eavesdropped LWE samples (4 ) and changes the distribution of the data to improve transformer training. We also improve the secret recovery methods of S and introduce a novel cross-attention recovery mechanism allowing us to read off the secret directly from the trained models. While P does not threaten NIST's proposed * Co-first authors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- SALSA VERDE: a machine learning attack on LWE with sparse small secretsCathy Yuanchen Li, Emily Wenger, Zeyuan Allen-Zhu, François Charton et al.NeurIPS 2023 · 13 citations
- AICrypto: Evaluating Cryptography Capabilities of Large Language ModelsYu Wang, Yijian Liu, Liheng Ji, Han Luo et al.ICML 2026 · 3 citations
- Cool + Cruel = Dual, and New Benchmarks for Sparse LWEAlexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite et al.EUROCRYPT 2026 · 1 citation
- Making Hard Problems Easier with Custom Data Distributions and Loss Regularization: A Case Study in Modular ArithmeticEshika Saxena, Alberto Alfarano, Emily Wenger, Kristin E. LauterICML 2025
Builds on1
Related papers
- SALSA: Attacking Lattice Cryptography with TransformersEmily Wenger, Mingjie Chen, François Charton, Kristin E. LauterNeurIPS 2022 · 61 citations
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu et al.S&P 2025
- Improving ML Attacks on LWE with Data Repetition and Stepwise RegressionAlberto Alfarano, Eshika Saxena, Emily Wenger, Francois Charton et al.ICML 2026
- Provable Dual Attacks on Learning with ErrorsAmaury Pouly, Yixin ShenEUROCRYPT 2024 · 18 citations
- A Systematic Study of Sparse LWEAayush Jain, Huijia Lin, Sagnik SahaCRYPTO 2024 · 8 citations
