Paper 2026/1904
When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation
Abstract
The standardization of ML-DSA has shifted the cryptographic community's focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations. We expose a structural vulnerability in the module lattice from a side-channel perspective. In particular, in ML-DSA's matrix-vector multiplication ($\hat{\mathbf{A}} \circ \hat{\mathbf{y}}$), the row-wise reuse of the ephemeral secret vector $\hat{\mathbf{y}}$ indicates that one single signature generation exposes $k$ (the row-wise size of $\hat{\mathbf{A}}$) leakage instances of the same secret-dependent intermediate value, each with a distinct and known coefficient of $\hat{\mathbf{A}}$. However, exploiting this in practice is highly non-trivial due to noise and/or compiler optimizations. To overcome this, we propose a variance-based weighted fusion strategy. This approach weights each operation by how far its leading candidate is separated from the runner-up candidates, and the signing relation ($\mathbf{y} = \mathbf{z} - c \cdot \mathbf{s}_1$) lets us extract the signed coefficients of the secret key. Moreover, we introduce a fast, INTT-based algebraic sieve that further increases the success rate of key recovery. Putting together, we achieve full key recovery using merely 4 traces against ML-DSA-87 (the highest security parameter set) with non-profiling correlation analysis. On the state-of-the-art first-order masked ML-DSA implementation, our attack extracts the secret key using no more than 90 traces. To the best of our knowledge, these non-profiling results establish a new record in trace complexity for both unprotected and first-order masked ML-DSA implementations, even comparable to these profiling-based attacks.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2026B
- DOI
- 10.1145/3830454.3846766
- Keywords
- Post-quantum cryptographySide-channel analysisML-DSAHorizontal attackLeakage fusionNumber theoretic transform
- Contact author(s)
-
yhzhao96 @ njust edu cn
hedalin @ njust edu cn
wei cheng @ njust edu cn
liuyuejun @ njust edu cn
mingjingdian @ njust edu cn
zhouyongbin @ njust edu cn - History
- 2026-09-11: revised
- 2026-09-07: received
- See all versions
- Short URL
- https://ia.cr/2026/1904
- License
-
CC BY-NC
BibTeX
@misc{cryptoeprint:2026/1904,
author = {Yuhan Zhao and Dalin He and Wei Cheng and Yuejun Liu and Jingdian Ming and Yongbin Zhou},
title = {When Module Lattice Leaks: Horizontal Fusion Attacks on {ML}-{DSA} Implementation},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1904},
year = {2026},
doi = {10.1145/3830454.3846766},
url = {https://eprint.iacr.org/2026/1904}
}