Paper 2025/2161

Attacks and Remedies for Randomness in AI (and with AI): Cryptanalysis of PHILOX and THREEFRY

Jens Alich, Ruhr University Bochum
Thomas Eisenbarth, University of Lübeck
Hosein Hadipour, Ruhr University Bochum
Stefan Kölbl, Google (Switzerland)
Gregor Leander, Ruhr University Bochum
Felix Mächtle, University of Lübeck
Yevhen Perehuda, Ruhr University Bochum
Shahram Rasoolzadeh, Ruhr University Bochum
Jonas Sander, University of Lübeck
Cihangir Tezcan, Middle East Technical University
Abstract

In this work, we address the critical yet understudied question of the security of the most widely deployed pseudorandom number generators (PRNGs) in AI applications. We show that these generators are vulnerable to practical and low-cost attacks by introducing both manual and automated cryptanalysis techniques. For this we partially, and to the best of our knowledge for the first time, take advantage of AlphaEvolve, a novel evolutionary coding agent guided by Large Language Models, to automate the discovery of complex cryptographic distinguishers. Finally, we present a cryptographically secure and well-understood alternative, which has a negligible effect on the overall AI/ML workloads. More generally, we recommend the use of cryptographically strong PRNGs in all contexts where randomness is required, as past experience has repeatedly shown that security requirements may arise unexpectedly even in applications that appear uncritical at first.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
PRNGGPUPhiloxThreefrySpeckdifferential-linear cryptanalysismultiplicative differentialsAlphaEvolve
Contact author(s)
jens alich @ ruhr-uni-bochum de
thomas eisenbarth @ uni-luebeck de
hossein hadipour @ rub de
kste @ mailbox org
gregor leander @ rub de
f maechtle @ uni-luebeck de
yevhen perehuda @ rub de
shahram rasoolzadeh @ rub de
j sander @ uni-luebeck de
cihangir @ metu edu tr
History
2026-09-08: last of 4 revisions
2025-11-28: received
See all versions
Short URL
https://ia.cr/2025/2161
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2161,
      author = {Jens Alich and Thomas Eisenbarth and Hosein Hadipour and Stefan Kölbl and Gregor Leander and Felix Mächtle and Yevhen Perehuda and Shahram Rasoolzadeh and Jonas Sander and Cihangir Tezcan},
      title = {Attacks and Remedies for Randomness in {AI} (and with {AI}): Cryptanalysis of {PHILOX} and {THREEFRY}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2161},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2161}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.