Lune

CCS2026Top-tier venue

When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation

Yuhan Zhao, Dalin He, Wei Cheng, Yuejun Liu, Jingdian Ming, Yongbin Zhou

2026Year

Abstract

The standardization of ML-DSA has shifted the cryptographic community's focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations.

We expose a structural vulnerability in the module lattice from a side-channel perspective. In particular, in ML-DSA's matrix-vector multiplication (A^∘y^\hat{\mathbf{A}} \circ \hat{\mathbf{y}}), the row-wise reuse of the ephemeral secret vector y^\hat{\mathbf{y}} indicates that one single signature generation exposes kk (the row-wise size of A^\hat{\mathbf{A}}) leakage instances of the same secret-dependent intermediate value, each with a distinct and known coefficient of A^\hat{\mathbf{A}}. However, exploiting this in practice is highly non-trivial due to noise and/or compiler optimizations. To overcome this, we propose a variance-based weighted fusion strategy. This approach weights each operation by how far its leading candidate is separated from the runner-up candidates, and the signing relation (y=z−c⋅s1\mathbf{y} = \mathbf{z} - c \cdot \mathbf{s}_1) lets us extract the signed coefficients of the secret key. Moreover, we introduce a fast, INTT-based algebraic sieve that further increases the success rate of key recovery.

Putting together, we achieve full key recovery using merely 4 traces against ML-DSA-87 (the highest security parameter set) with non-profiling correlation analysis. On the state-of-the-art first-order masked ML-DSA implementation, our attack extracts the secret key using no more than 90 traces. To the best of our knowledge, these non-profiling results establish a new record in trace complexity for both unprotected and first-order masked ML-DSA implementations, even comparable to these profiling-based attacks.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get e397282f-acc4-4e38-a643-4801481fb662

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines