Paper 2026/1904

When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation

Yuhan Zhao, School of Cyber Science and Engineering, Nanjing University of Science and Technology
Dalin He, School of Cyber Science and Engineering, Nanjing University of Science and Technology
Wei Cheng, School of Cyber Science and Engineering, Nanjing University of Science and Technology, Télécom Paris, Institut Polytechnique de Paris
Yuejun Liu, School of Cyber Science and Engineering, Nanjing University of Science and Technology
Jingdian Ming, School of Cyber Science and Engineering, Nanjing University of Science and Technology
Yongbin Zhou, School of Cyber Science and Engineering, Nanjing University of Science and Technology, Institute of Information Engineering, Chinese Academy of Sciences
Abstract

The standardization of ML-DSA has shifted the cryptographic community's focus toward its practical security. While profiled attacks against its implementations are well studied with a few traces, non-profiling attacks are widely assumed to require large trace complexity. We challenge this by introducing horizontal fusion attacks, demonstrating that non-profiling, few-trace key recovery is highly practical against ML-DSA, even against masked implementations. We expose a structural vulnerability in the module lattice from a side-channel perspective. In particular, in ML-DSA's matrix-vector multiplication ($\hat{\mathbf{A}} \circ \hat{\mathbf{y}}$), the row-wise reuse of the ephemeral secret vector $\hat{\mathbf{y}}$ indicates that one single signature generation exposes $k$ (the row-wise size of $\hat{\mathbf{A}}$) leakage instances of the same secret-dependent intermediate value, each with a distinct and known coefficient of $\hat{\mathbf{A}}$. However, exploiting this in practice is highly non-trivial due to noise and/or compiler optimizations. To overcome this, we propose a variance-based weighted fusion strategy. This approach weights each operation by how far its leading candidate is separated from the runner-up candidates, and the signing relation ($\mathbf{y} = \mathbf{z} - c \cdot \mathbf{s}_1$) lets us extract the signed coefficients of the secret key. Moreover, we introduce a fast, INTT-based algebraic sieve that further increases the success rate of key recovery. Putting together, we achieve full key recovery using merely 4 traces against ML-DSA-87 (the highest security parameter set) with non-profiling correlation analysis. On the state-of-the-art first-order masked ML-DSA implementation, our attack extracts the secret key using no more than 90 traces. To the best of our knowledge, these non-profiling results establish a new record in trace complexity for both unprotected and first-order masked ML-DSA implementations, even comparable to these profiling-based attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. ACM CCS 2026B
DOI
10.1145/3830454.3846766
Keywords
Post-quantum cryptographySide-channel analysisML-DSAHorizontal attackLeakage fusionNumber theoretic transform
Contact author(s)
yhzhao96 @ njust edu cn
hedalin @ njust edu cn
wei cheng @ njust edu cn
liuyuejun @ njust edu cn
mingjingdian @ njust edu cn
zhouyongbin @ njust edu cn
History
2026-09-11: revised
2026-09-07: received
See all versions
Short URL
https://ia.cr/2026/1904
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1904,
      author = {Yuhan Zhao and Dalin He and Wei Cheng and Yuejun Liu and Jingdian Ming and Yongbin Zhou},
      title = {When Module Lattice Leaks: Horizontal Fusion Attacks on {ML}-{DSA} Implementation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1904},
      year = {2026},
      doi = {10.1145/3830454.3846766},
      url = {https://eprint.iacr.org/2026/1904}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.