[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121647-en":3,"doc-seo-121647-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121647,1099513958762,"Logic","https://ap-avatar.wpscdn.com/avatar/1000023916a998db790?x-image-process=image/resize,m_fixed,w_180,h_180&k=1784791008015729253",8,"Research & Report","Salsa Picante - a machine learning attack on LWE with binary secrets","Learning With Errors (LWE) underpins many post-quantum cryptography (PQC) proposals, including the NIST-standardized key encapsulation mechanism derived from module LWE and many homomorphic encryption libraries based on ring LWE. Security hinges on correct parameter and implementation choices, and prior attacks showed vulnerabilities for sparse binary secrets only in small dimensions and very low Hamming weights. Picante improves secret recovery to far larger dimensions and higher Hamming weights via preprocessing, efficient training-data generation, and cross-attention recovery, strengthening evidence for further investigation into ML attacks on sparse-binary LWE.","Salsa Picante: a machine learning a􀀝ack on LWE with binary  \nsecrets  \narXiv :2303 .04178v2 [ cs .CR] 9 May 2023  \nCathy Li∗  \nMeta AI  \nMohmed Malhou Meta AI  \nJana Sotáková∗  \nMeta AI  \nEvrard Garcelon ENSAE-CREST  \nEmily Wenger  \nUniversity of Chicago Francois Charton† Meta AI  \nKristin Lauter†  \nMeta AI  \nABSTRACT  \nLearning With Errors (LWE) is a hard math problem underpinning many proposed post-quantum cryptographic (PQC) systems. The only PQC Key Exchange Mechanism (KEM) standardized by NIST [13] is based on module LWE, and current publicly available PQ Homomorphic Encryption (HE) libraries are based on ring LWE [2] . The security of LWE-based PQ cryptosystems is critical, but certain implementation choices could weaken them. One such choice is sparse binary secrets, desirable for PQ HE schemes for eﬃciency reasons. Prior work Salsa [49] demonstrated a machine learningbased attack on LWE with sparse binary secrets in small dimensions (􀀽 ≤ 128) and low Hamming weights (ℎ ≤ 4) . However, this attack assumes access to millions of eavesdropped LWE samples and fails at higher Hamming weights or dimensions.  \nWe present Picante, an enhanced machine learning attack on LWE with sparse binary secrets, which recovers secrets in much larger dimensions (up to 􀀽 = 350) and with larger Hamming weights (roughly 􀀽/10, and up to ℎ = 60 for 􀀽 = 350) . We achieve this dramatic improvement via a novel preprocessing step, which allows us to generate training data from a linear number of eavesdropped LWE samples (4􀀽) and changes the distribution of the data to improve transformer training. We also improve the secret recovery methods of Salsa and introduce a novel cross-attention recovery mechanism allowing us to read oﬀ the secret directly from the trained models. While Picante does not threaten NIST’s proposed LWE standards, it demonstrates signiﬁcant improvement over Salsa and could scale further, highlighting the need for future investigation into machine learning attacks on LWE with sparse binary secrets.  \n1 INTRODUCTION  \nThe race for post-quantum cryptography (PQC) is well underway. A large-scale quantum computer could solve the hard math problems underpinning most deployed public-key cryptographic systems, like RSA [40], in polynomial time. Small-scale quantum computers have already been built. Consequently, new post-quantum cryptographic systems were proposed and considered for standardization by US National Institute ofStandards and Technology(NIST) in the 5-year PQC competition. In July 2022, NIST standardized 4 schemes from the PQC competition [13] . The only key encapsulation mechanism selected—CRYSTALS-Kyber [6]—and one of the  \n∗ Co-ﬁrst authors.  \n†Co-senior authors, corresponding author: [fcharton@meta.com](fcharton@meta.com)  \nthree signature schemes—CRYSTALS-Dilithium [25]—are based on the mathematical hardness assumption known as Learning With Errors (LWE) [39] . LWE is also used in proposed PQ homomorphic encryption schemes [2] .  \nLWE works as follows: given an integer modulus􀁀, a dimension 􀀽, and a secret vector s ∈ Z􀀽􀁀, the Learning With Errors problem is to recover s given many random vectors and their noisy inner products with s. These noisy inner products are computed by taking random vector a ∈ Z􀀽􀁀 and producing 􀀱 := a · s + 􀀴 mod 􀁀, where 􀀴 is an “error” term sampled from a narrow discrete Gaussian distribution (i.e. taking small values). The adversary is then given the samples (a, 􀀱) and attempts to use these to recover s.  \nThe basic LWE problem is assumed to be hard for both classical and quantum adversaries [9, 31, 33, 38, 39] . Variants of LWE, like module-LWE or ring-LWE—on which the NIST-standards and HE schemes are based—add structure to the basic LWE problem, making them potentially easier than LWE. Classical attacks on LWE and its variants typically rely on algebraic techniques for lattice reduction to recover the secret s from pairs (a, 􀀱) [14, 30] . The error 􀀴 added to a · s to compute 􀀱 adds noise, ","cbCaien5sMoH2RR1","https://ap.wps.com/l/cbCaien5sMoH2RR1","pdf",700136,1,15,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What problem does LWE support in post-quantum cryptography?\",\"answer\":\"LWE is a foundational hard mathematical problem used in multiple PQC systems, including mechanisms based on module LWE and homomorphic encryption schemes based on ring LWE.\"},{\"question\":\"What are the main limitations of the prior Salsa attack?\",\"answer\":\"Salsa works only for small dimensions and very low Hamming weights, and it needs millions of eavesdropped LWE samples, making it difficult to scale to realistic attacker capabilities.\"},{\"question\":\"How does Picante improve upon Salsa for recovering sparse binary secrets?\",\"answer\":\"Picante uses a novel preprocessing step to generate training data from a linear number of samples, improves transformer training through a changed data distribution, upgrades the recovery methods, and adds a cross-attention mechanism that reads the secret directly from trained models.\"}]","Salsa Picante - a machine learning attack on LWE with binary secrets | PDF",1785805914,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"salsa-picante-a-machine-learning-attack-on-lwe-with-binary-secrets","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/salsa-picante-a-machine-learning-attack-on-lwe-with-binary-secrets/121647/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does LWE support in post-quantum cryptography?","Question",{"text":75,"@type":76},"LWE is a foundational hard mathematical problem used in multiple PQC systems, including mechanisms based on module LWE and homomorphic encryption schemes based on ring LWE.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the main limitations of the prior Salsa attack?",{"text":80,"@type":76},"Salsa works only for small dimensions and very low Hamming weights, and it needs millions of eavesdropped LWE samples, making it difficult to scale to realistic attacker capabilities.",{"name":82,"@type":73,"acceptedAnswer":83},"How does Picante improve upon Salsa for recovering sparse binary secrets?",{"text":84,"@type":76},"Picante uses a novel preprocessing step to generate training data from a linear number of samples, improves transformer training through a changed data distribution, upgrades the recovery methods, and adds a cross-attention mechanism that reads the secret directly from trained models.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]