Paper 2026/1333

Apples, Oranges, and Signatures: Pitfalls and Methodology in ML-DSA Benchmarking

Sebastien Riou, PQShield
Jong-Yeon Park, University of the Bundeswehr Munich
Liga Anwar, University of the Bundeswehr Munich
Axel Poschmann, PQShield
Michael Hutter, University of the Bundeswehr Munich, PQShield
Abstract

Cryptographic migration, particularly in the post-quantum setting, poses significant practical challenges and requires reliable performance data to support sound engineering decisions. For ML-DSA, however, existing benchmarking practices often produce misleading or non-comparable results, complicating migration and cryptographic agility efforts. This paper analyzes common pitfalls in benchmarking ML-DSA signature operations, including subtle inconsistencies when comparing security levels. We show that execution-time variability of the ML-DSA signing algorithm - an inherent property due to rejection sampling and other data-dependent components - makes commonly used straightforward metrics, e.g., min/average/max, unsuitable for migration planning. To address this gap, we propose a robust benchmarking methodology based on standardized input data sets and clearly qualified reporting metrics. The proposed approach enables fair comparison across hardware and software implementations and supports designers of real-time systems to assess the worst-case execution time.

Metadata
Available format(s)
PDF
Category
Implementation
Publication info
Published elsewhere. This paper is published in Springer CCIS under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License (CC BY-NC-ND 4.0).
Keywords
Post-Quantum Cryptography (PQC)ML-DSACryptographic MigrationASILBenchmarking MethodologyCryptographic Agility.
Contact author(s)
sebastien riou @ pqshield com
jongyoun park @ unibw de
liga anwar @ unibw de
axel poschmann @ pqshield com
michael hutter @ unibw de
History
2026-07-06: revised
2026-06-29: received
See all versions
Short URL
https://ia.cr/2026/1333
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2026/1333,
      author = {Sebastien Riou and Jong-Yeon Park and Liga Anwar and Axel Poschmann and Michael Hutter},
      title = {Apples, Oranges, and Signatures: Pitfalls and Methodology in {ML}-{DSA} Benchmarking},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1333},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1333}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.