Paper 2026/1366

Halfspace Learning for Lattice Signature Key Recovery from Signs

Marcus Brinkmann, Ruhr University Bochum
Nicolai Kraus, Ruhr University Bochum
Alexander May, Ruhr University Bochum
Abstract

Any signature scheme has to protect its secret key via some properly chosen, secret randomness. We show that, for the lattice signatures \textsf{HAWK}, Falcon and ML-DSA, even minimal leakage of this randomness suffices for secret key recovery. In particular, leaking either the Hamming weight or a single bit of any randomness coordinate allows an attacker to infer the sign of that coordinate. This corresponds to learning $\textrm{sign}(\langle \mathbf b, \mathbf w \rangle)$, where $\mathbf b$ is the secret key and $\mathbf w$ is public. We model key recovery from such sign information as an instance of Learning a Halfspace. This well-studied problem from learning theory provides a rich solution machinery, which we adapt for the cryptanalysis of lattice-based signatures. As a first main result, we resolve the open problem of recovering the secret key in \textsf{HAWK} from sign leakage. At the 128-bit security level and in the noise-free setting, we recover the secret key from only 30 signatures in 10 minutes. As a second main result, we recover the secret key in Falcon via sign leakage from only 100 signatures in under a minute. In comparison to existing attacks, this reduces the number of required signatures by a factor of $250$. As a third result, we show the first ML-DSA secret key recovery from sign leakage, which requires 190,000 signatures and completes within seconds. In comparison to existing ML-DSA attacks, we require a comparable amount of signatures, but utilize a less restrictive leakage model. In addition, our attack is alarmingly noise-tolerant, succeeding with up to 35\% noise for \textsf{HAWK}, 30\% for Falcon, and 35\% for ML-DSA, albeit requiring significantly more signatures in the noisy case.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in CRYPTO 2026
Keywords
HAWKFalconML-DSAcryptanalysislatticesignaturehalfspaceside-channel
Contact author(s)
marcus brinkmann @ rub de
nicolai kraus @ rub de
alex may @ rub de
History
2026-07-06: approved
2026-07-02: received
See all versions
Short URL
https://ia.cr/2026/1366
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1366,
      author = {Marcus Brinkmann and Nicolai Kraus and Alexander May},
      title = {Halfspace Learning for Lattice Signature Key Recovery from Signs},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1366},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1366}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.