[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83014-en":3,"doc-seo-83014-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83014,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","From Regression to Prior-Aware Inference: Solving the ILWE Family in Randomness Leakage Attacks against ML-DSA","ML-DSA is an NIST-standardized post-quantum lattice-based signature scheme whose security depends on signing randomness and rejection sampling keeping public signatures statistically independent from the secret key. Real implementations can leak partial randomness information, turning public signatures into ILWE-type problems and enabling secret key disclosure. Randomness leakage attacks can be cast as a two-stage key recovery pipeline: instance construction from leakage and signatures, followed by recovery solving. This work proposes a unified framework to evaluate recovery solvers across ILWE variants and shows that solver choice strongly affects efficiency.","From Regression to Prior-Aware Inference: Solving the ILWE Family in Randomness Leakage Attacks against ML-DSA  \nPeiheng Zhang , Yuejun Liu , Member, IEEE, Wei Cheng , Member, IEEE,  \nMuye Li, Honglin Shao , Yongbin Zhou , Member, IEEE  \narXiv :2607 .0592 1v2 [ cs .CR] 13 Jul 2026  \nAbstract—ML-DSA is a representative lattice-based signature scheme in post-quantum cryptography standardized by NIST. It relies on signing randomness and rejection sampling to ensure that released signatures are statistically independent of the secret key. Practical implementations, however, may leak partial information about this randomness, and such leakage can transform public signatures into Integer Learning with Errors (ILWE)-type problems, resulting in secret key disclosure risks.  \nSuch randomness leakage attack can be formulated as a twostage key-recovery procedure, in which leaked partial information and public signatures are first transformed into an ILWEfamily instance, and then a recovery solver is applied to recover the secret key. Existing work has mainly focused on the first stage by constructing such instances under different leakage models. By contrast, the role of solver in the subsequent instancesolving stage remains under-explored, and existing attacks often rely on ad-hoc model-specific solvers. To address this gap, we propose a unified framework to systematically evaluate different recovery solvers on leakage-derived ILWE-family instances. The framework covers three ILWE instances, including the ordinary ILWE, Fiat-Shamir ILWE (FS-ILWE) and Concealed ILWE (CILWE) under different scenarios.  \nWithin our framework, we explore three classes of solvers. Specifically, the first class is the least-squares regression solvers using ordinary least squares (OLS) and likelihood-based ℓ2-estimators. The second class is the robust regression solvers with Huber regression and Cauchy regression. The last class is the prior-aware discrete-inference solvers by using belief propagation (BP), objective-induced greedy search, and bounded-error hillclimbing. Our experiments show that the solver has a significant impact on the secret-key recovery efficiency. In particular, on FS-ILWE, prior-aware discrete-inference reduces the number of informative relations by one to two orders of magnitude compared to the baselines: (i) compared with OLS, BP constitutes a reduction by a factor of 15.4 ×-64 .9 × in noise-free settings, and by a factor of 10.5 ×-73 .9 × in noisy settings. (ii) compared with hill-climbing, BP reduces the number of required relations by a factor of up to 7.6 ×. On CILWE, BP is more effective with the concealment rate lower than 0.9, while Cauchy regression is more stable for higher rates. Overall, this work provides a systematic evaluation on different solvers in randomness leakage attacks, and presents new benchmarks for future analysis on ML-DSA.  \nIndex Terms—Post-Quantum Cryptography, ML-DSA, Integer Learning with Errors, Randomness Leakage Attack.  \nI. INTRODUCTION  \nPeiheng zhang, Yuejun Liu, Wei Cheng, Muye Li, Honglin Shao, and Yongbin Zhou are with the School of Cyber Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094, China (email: {zhangpeiheng, liuyuejun, wei.cheng, limuye, shaohonglin, zhouyong[bin](bin}@njust.edu.cn)[}](bin}@njust.edu.cn)[@njust.edu.cn](bin}@njust.edu.cn)). Corresponding authors: Yuejun Liu and Yongbin Zhou.  \nThis is a preprint version. This work has been submitted to the IEEE for possible publication.  \nML-DSA, formerly known as CRYSTALS-Dilithium,  \nwas selected by the National Institute of Standards and Technology (NIST) as the primary post-quantum digital signature standard and published as FIPS 204 [1] in August 2024. The theoretical security of ML-DSA relies on modulelattice assumptions such as Module-LWE [2] and Short Integer Solution (SIS) [3], while its concrete implementation security also depends on whether intermediate signing values are protected against ","cbCaieveg3VPrQuq","https://ap.wps.com/l/cbCaieveg3VPrQuq","pdf",932053,2,1,14,"English","en",105,"# Introduction\n## ML-DSA and randomness leakage background\n## Two-stage key-recovery view of the attacks\n# Unified framework and ILWE instances\n## Ordinary ILWE\n## Fiat-Shamir ILWE (FS-ILWE)\n## Concealed ILWE (CILWE)\n# Solver classes and evaluation\n## Least-squares regression solvers\n## Robust regression solvers\n## Prior-aware discrete-inference solvers\n# Experimental results and benchmarks\n## FS-ILWE performance findings\n## CILWE behavior under concealment rates\n# Conclusion","[{\"question\":\"What causes secrecy risk in ML-DSA when randomness leakage occurs?\",\"answer\":\"ML-DSA relies on randomness and rejection sampling to decorrelate released signatures from the secret key. When implementations leak partial information about the signing randomness, the public signatures can be transformed into ILWE-type problems, enabling secret-key recovery.\"},{\"question\":\"How are randomness leakage attacks against ML-DSA structured?\",\"answer\":\"They can be formulated as a two-stage key-recovery procedure: first, leaked partial randomness and public signatures are used to construct an ILWE-family instance; second, a recovery solver is applied to recover the secret key.\"},{\"question\":\"Why is solver choice important in solving ILWE-family instances?\",\"answer\":\"The document shows solver choice significantly changes recovery efficiency. Prior-aware discrete-inference can reduce the number of informative relations by one to two orders of magnitude on FS-ILWE, and different solvers exhibit different effectiveness across CILWE concealment rates.\"}]",1784184670,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"from-regression-to-prior-aware-inference-solving-the-ilwe-family-in-randomness-leakage-attacks-against-ml-dsa","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/from-regression-to-prior-aware-inference-solving-the-ilwe-family-in-randomness-leakage-attacks-against-ml-dsa/83014/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What causes secrecy risk in ML-DSA when randomness leakage occurs?","Question",{"text":75,"@type":76},"ML-DSA relies on randomness and rejection sampling to decorrelate released signatures from the secret key. When implementations leak partial information about the signing randomness, the public signatures can be transformed into ILWE-type problems, enabling secret-key recovery.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How are randomness leakage attacks against ML-DSA structured?",{"text":80,"@type":76},"They can be formulated as a two-stage key-recovery procedure: first, leaked partial randomness and public signatures are used to construct an ILWE-family instance; second, a recovery solver is applied to recover the secret key.",{"name":82,"@type":73,"acceptedAnswer":83},"Why is solver choice important in solving ILWE-family instances?",{"text":84,"@type":76},"The document shows solver choice significantly changes recovery efficiency. Prior-aware discrete-inference can reduce the number of informative relations by one to two orders of magnitude on FS-ILWE, and different solvers exhibit different effectiveness across CILWE concealment rates.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]