When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation
Yuhan Zhao, Dalin He, Wei Cheng, Yuejun Liu, Jingdian Ming, Yongbin Zhou
Abstract
The standardization of ML-DSA has shifted the cryptographic community's focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations.
We expose a structural vulnerability in the module lattice from a side-channel perspective. In particular, in ML-DSA's matrix-vector multiplication (), the row-wise reuse of the ephemeral secret vector indicates that one single signature generation exposes (the row-wise size of ) leakage instances of the same secret-dependent intermediate value, each with a distinct and known coefficient of . However, exploiting this in practice is highly non-trivial due to noise and/or compiler optimizations. To overcome this, we propose a variance-based weighted fusion strategy. This approach weights each operation by how far its leading candidate is separated from the runner-up candidates, and the signing relation () lets us extract the signed coefficients of the secret key. Moreover, we introduce a fast, INTT-based algebraic sieve that further increases the success rate of key recovery.
Putting together, we achieve full key recovery using merely 4 traces against ML-DSA-87 (the highest security parameter set) with non-profiling correlation analysis. On the state-of-the-art first-order masked ML-DSA implementation, our attack extracts the secret key using no more than 90 traces. To the best of our knowledge, these non-profiling results establish a new record in trace complexity for both unprotected and first-order masked ML-DSA implementations, even comparable to these profiling-based attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e397282f-acc4-4e38-a643-4801481fb662Related papers
- Finding and Protecting the Weakest Link - On Side-Channel Attacks on in Masked ML-DSAJulius Hermelink, Kai-Chun Ning, Richard PetriCRYPTO 2025 · 4 citations
- Uncompressing Dilithium's Public KeyPaco Azevedo Oliveira, Andersson Calle Viera, Benoît Cogliati, Louis GoubinCRYPTO 2025 · 10 citations
- Halfspace Learning for Lattice Signature Key Recovery from SignsMarcus Brinkmann, Nicolai Kraus, Alexander MayCRYPTO 2026 · 1 citation
- Attacking OpenSSL Implementation of ECDSA with a Few SignaturesShuqin Fan, Wenbo Wang, Qingfeng ChengCCS 2016 · 44 citations
- Deep Learning Multi-Channel Fusion Attack Against Side-Channel Protected HardwareBenjamin Hettwer, Daniel Fennes, Sebastien Leger, Jan Richter-Brockmann et al.DAC 2020 · 11 citations
