Paper 2026/2166
A Provable Correctness Analysis of the MATZOV-Style FFT Dual Attack on ML-KEM
Abstract
The dual attack is a central tool for evaluating the concrete security of the Learning with Errors (LWE) problem, which underlies lattice-based cryptosystems such as ML-KEM. The MATZOV-style FFT dual attack combines dual distinguishing with an FFT-accelerated guessing phase and provides one of the main frameworks for concrete attack estimates against ML-KEM. However, its correctness analysis has traditionally relied on heuristic independence assumptions, leaving a gap between practical attack estimates and provable guarantees. In this work, we give a rigorous correctness analysis of a MATZOV-style FFT-based dual attack for the ML-KEM parameter sets. The analysis treats the correct and incorrect candidates separately and applies different conditioning arguments on the two sides, because the former requires a provable lower bound on the score of the true candidate, while the latter requires a uniform upper bound for all wrong recovered guesses. Combining these two parts, we obtain an explicit success criterion and a provable threshold separation for the FFT score. For concrete cost estimation, we follow the same cost-estimation convention as previous provable dual-attack analyses whenever the same subroutine is involved, using Pouly and Shen's estimates (EUROCRYPT 2024) as our main baseline. We obtain attack costs of 210, 300, and 410 bits for ML-KEM-512, ML-KEM-768, and ML-KEM-1024, respectively. Relative to this baseline, our estimates reduce the attack costs by 28, 47, and 68 bits for ML-KEM-512, ML-KEM-768, and ML-KEM-1024, respectively.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Learning with ErrorsProvable dual attackFFT-based dual attackML-KEM.
- Contact author(s)
-
lijiale @ iie ac cn
wangliping @ iie ac cn
hxwang @ ntu edu sg - History
- 2026-09-26: approved
- 2026-09-23: received
- See all versions
- Short URL
- https://ia.cr/2026/2166
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/2166,
author = {Jiale Li and Li-Ping Wang and Huaxiong Wang},
title = {A Provable Correctness Analysis of the {MATZOV}-Style {FFT} Dual Attack on {ML}-{KEM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/2166},
year = {2026},
url = {https://eprint.iacr.org/2026/2166}
}