Assessing the Impact of a Variant of MATZOV's Dual Attack on Kyber
Kévin Carrier, Charles Meyer-Hilfiger, Yixin Shen, Jean-Pierre Tillich
Abstract
. The dual attacks on the Learning With Errors ( LWE ) problem are currently a subject of controversy. In particular, the results of [MAT22], which claim to significantly lower the security level of Kyber [SAB + 20], a lattice-based cryptosystem currently being standardized by NIST, are not widely accepted. The analysis behind their attack depends on a series of assumptions that, in certain scenarios, have been shown to contradict established theorems or well-tested heuristics [DP23b]. In this paper, we introduce a new dual lattice attack on LWE , drawing from ideas in coding theory. Our approach revisits the dual attack proposed by [MAT22], replacing modulus switching with an efficient decoding algorithm. This decoding is achieved by generalizing polar codes over Z q , and we confirm their strong distortion properties through benchmarks. This modification enables a reduction from small-LWE to plain-LWE , with a notable decrease in the secret dimension. Additionally, we replace the enumeration step in the attack by assuming the secret is zero for the portion being enumerated, iterating this assumption over various choices for the enumeration part. We make an analysis of our attack without using the flawed independence assumptions used in [MAT22] and we fully back up our analysis with experimental evidences. Lastly, we assess the complexity of our attack on Kyber ; showing that the security levels for Kyber -512/768/1024 are 3.5/11.9/12.3 bits below the NIST requirements (143/207/272 bits) in the same nearest-neighbor cost model as in [SAB + 20,MAT22]. All in all the cost of our attack matches and even slightly beat in some cases the complexities originally claimed by the attack of [MAT22].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dcfd2882-32cd-4dad-9826-a3dac8c4fd7bCited by top-tier papers1
Ask how each one uses itBuilds on4
- Post-quantum Key Exchange - A New HopeErdem Alkim, Léo Ducas, Thomas Pöppelmann, Peter SchwabeUSENIX Security 2016 · 972 citations
- Does the Dual-Sieve Attack on Learning with Errors Even Work?Léo Ducas, Ludo N. PullesCRYPTO 2023 · 32 citations
- Provable Dual Attacks on Learning with ErrorsAmaury Pouly, Yixin ShenEUROCRYPT 2024 · 18 citations
- Reduction from Sparse LPN to LPN, Dual Attack 3.0Kévin Carrier, Thomas Debris-Alazard, Charles Meyer-Hilfiger, Jean-Pierre TillichEUROCRYPT 2024 · 13 citations
Related papers
- Benchmarking Attacks on Learning with ErrorsEmily Wenger, Eshika Saxena, Mohamed Malhou, Ellie Thieu et al.S&P 2025
- A Quasi-polynomial Time Algorithm for the Extrapolated Dihedral Coset Problem over Power-of-Two ModuliShi Bai, Hansraj Jangir, Elena Kirshanova, Tran Ngo et al.CRYPTO 2025 · 3 citations
- SalsaPicante: A Machine Learning Attack on LWE with Binary SecretsCathy Yuanchen Li, Jana Sotáková, Emily Wenger, Mohamed Malhou et al.CCS 2023 · 11 citations
- (One) Failure Is Not an Option: Bootstrapping the Search for Failures in Lattice-Based Encryption SchemesJan-Pieter D'Anvers, Mélissa Rossi, Fernando VirdiaEUROCRYPT 2020 · 2 citations
- MPC-in-the-Head Framework without Repetition and its Applications to the Lattice-based CryptographyWeihao Bai, Long Chen, Qianwen Gao, Zhenfeng ZhangS&P 2024 · 2 citations
