Paper 2025/2161
Attacks and Remedies for Randomness in AI (and with AI): Cryptanalysis of PHILOX and THREEFRY
Abstract
In this work, we address the critical yet understudied question of the security of the most widely deployed pseudorandom number generators (PRNGs) in AI applications. We show that these generators are vulnerable to practical and low-cost attacks by introducing both manual and automated cryptanalysis techniques. For this we partially, and to the best of our knowledge for the first time, take advantage of AlphaEvolve, a novel evolutionary coding agent guided by Large Language Models, to automate the discovery of complex cryptographic distinguishers. Finally, we present a cryptographically secure and well-understood alternative, which has a negligible effect on the overall AI/ML workloads. More generally, we recommend the use of cryptographically strong PRNGs in all contexts where randomness is required, as past experience has repeatedly shown that security requirements may arise unexpectedly even in applications that appear uncritical at first.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- PRNGGPUPhiloxThreefrySpeckdifferential-linear cryptanalysismultiplicative differentialsAlphaEvolve
- Contact author(s)
-
jens alich @ ruhr-uni-bochum de
thomas eisenbarth @ uni-luebeck de
hossein hadipour @ rub de
kste @ mailbox org
gregor leander @ rub de
f maechtle @ uni-luebeck de
yevhen perehuda @ rub de
shahram rasoolzadeh @ rub de
j sander @ uni-luebeck de
cihangir @ metu edu tr - History
- 2026-09-08: last of 4 revisions
- 2025-11-28: received
- See all versions
- Short URL
- https://ia.cr/2025/2161
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2161,
author = {Jens Alich and Thomas Eisenbarth and Hosein Hadipour and Stefan Kölbl and Gregor Leander and Felix Mächtle and Yevhen Perehuda and Shahram Rasoolzadeh and Jonas Sander and Cihangir Tezcan},
title = {Attacks and Remedies for Randomness in {AI} (and with {AI}): Cryptanalysis of {PHILOX} and {THREEFRY}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2161},
year = {2025},
url = {https://eprint.iacr.org/2025/2161}
}