Paper 2026/2091

Keep Track of Your Errors: Solving ILWE and Improving Attacks on ML-DSA

Mohamed ElGhamrawy, University of Luebeck
Thomas Eisenbarth, University of Luebeck, DFKI
Julius Hermelink, Max Planck Institute for Security and Privacy
Anja Rabich, University of Luebeck
Florian Sieck, University of Luebeck
Silvan Streit, Fraunhofer AISEC, Technical University of Munich
Jonas Thietke, Ruhr-University Bochum
Zhiyuan Zhang, Max Planck Institute for Security and Privacy
Abstract

With the widespread adoption of NIST's new signature standard ML-DSA imminent, understanding its vulnerability to side-channel attacks is increasingly important. Current approaches that are based on deriving (Concealed) Integer Learning with Errors (ILWE) samples from side information require hundreds of thousands of signatures even in noise-free conditions, limiting their practicality. In this work, we show that the number of signatures required in these attacks has been drastically overestimated. Keeping track of the error probability distribution when deriving ILWE samples allows for a soft-analytic approach to solving ILWE. Concretely, we show that distribution hints (Eurocrypt 2025) may be derived from ILWE samples and the corresponding belief propagation-based solver can recover the secret key efficiently. We then conceptually compare previous solvers to our soft-analytic approach. Furthermore, we provide an information-theoretic analysis and answer an open question---on how to filter out relations---posed in a different line of attacks against ML-DSA (Crypto 2025); thereby, we can propose improvements in the application of these solvers. We evaluate our approach across various ILWE and Concealed ILWE parameter sets. In addition, we analyze a recently discovered timing leakage in ML-DSA and show how to solve for the secret key with far fewer signatures. In a noise-free attack setting, our approach reduces the average number of signatures required by a factor of 62---from 139 million to 2.25 million---compared with linear regression, as originally proposed, with larger improvements under noise. Thus, we show that attacks that derive ILWE and Concealed ILWE instances require far fewer signatures than previously believed, and their impact has been underestimated.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Post-Quantum CryptographySide-Channel AttacksFault AttacksML-DSACRYSTALS-DilithiumInteger Learning with Errors
Contact author(s)
mohamed elghamrawy @ uni-luebeck de
thomas eisenbarth @ uni-luebeck de
julius hermelink @ mpi-sp org
a rabich @ uni-luebeck de
florian sieck @ uni-luebeck de
silvan streit @ aisec fraunhofer de
jonas thietke @ rub de
zhiyuan zhang @ mpi-sp org
History
2026-09-22: approved
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2091
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2091,
      author = {Mohamed ElGhamrawy and Thomas Eisenbarth and Julius Hermelink and Anja Rabich and Florian Sieck and Silvan Streit and Jonas Thietke and Zhiyuan Zhang},
      title = {Keep Track of Your Errors: Solving {ILWE} and Improving Attacks on {ML}-{DSA}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2091},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2091}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.