Paper 2026/2166

A Provable Correctness Analysis of the MATZOV-Style FFT Dual Attack on ML-KEM

Jiale Li, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Li-Ping Wang, State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences
Huaxiong Wang, School of Physical \& Mathematical Sciences, Nanyang Technological University, Singapore
Abstract

The dual attack is a central tool for evaluating the concrete security of the Learning with Errors (LWE) problem, which underlies lattice-based cryptosystems such as ML-KEM. The MATZOV-style FFT dual attack combines dual distinguishing with an FFT-accelerated guessing phase and provides one of the main frameworks for concrete attack estimates against ML-KEM. However, its correctness analysis has traditionally relied on heuristic independence assumptions, leaving a gap between practical attack estimates and provable guarantees. In this work, we give a rigorous correctness analysis of a MATZOV-style FFT-based dual attack for the ML-KEM parameter sets. The analysis treats the correct and incorrect candidates separately and applies different conditioning arguments on the two sides, because the former requires a provable lower bound on the score of the true candidate, while the latter requires a uniform upper bound for all wrong recovered guesses. Combining these two parts, we obtain an explicit success criterion and a provable threshold separation for the FFT score. For concrete cost estimation, we follow the same cost-estimation convention as previous provable dual-attack analyses whenever the same subroutine is involved, using Pouly and Shen's estimates (EUROCRYPT 2024) as our main baseline. We obtain attack costs of 210, 300, and 410 bits for ML-KEM-512, ML-KEM-768, and ML-KEM-1024, respectively. Relative to this baseline, our estimates reduce the attack costs by 28, 47, and 68 bits for ML-KEM-512, ML-KEM-768, and ML-KEM-1024, respectively.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Learning with ErrorsProvable dual attackFFT-based dual attackML-KEM.
Contact author(s)
lijiale @ iie ac cn
wangliping @ iie ac cn
hxwang @ ntu edu sg
History
2026-09-26: approved
2026-09-23: received
See all versions
Short URL
https://ia.cr/2026/2166
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2166,
      author = {Jiale Li and Li-Ping Wang and Huaxiong Wang},
      title = {A Provable Correctness Analysis of the {MATZOV}-Style {FFT} Dual Attack on {ML}-{KEM}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2166},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2166}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.