PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 7, 2026IACR Communications in Cryptology0 citationsOpen Access

A Practical Neighborhood Search Attack on Oracle MLWE

View Full Paper
HWH WangMEMuhammed EsginRSRon Steinfeld

Key Points

  • The research aims to expose the vulnerabilities of Oracle MLWE through a practical cryptanalytic approach.
  • Introduced a neighborhood search attack on Oracle MLWE.
  • Exploited adversarially-chosen matrices and small-norm secrets.
  • Implemented the attack using SageMath to demonstrate its effectiveness.
  • Showed that rounding errors can be exploited to recover the underlying MLWE secret.
  • Demonstrated recovery of encapsulated keys in seconds on standard PCs under certain parameters.

Abstract

The Oracle Module Learning with Errors (Oracle MLWE) assumption, recently introduced by Liu et al. (Asiacrypt 2025), strengthens standard (Module) LWE by allowing masked linear leakages of the secret under an adversarially-chosen challenge matrix. This feature is used for the construction of new efficient primitives such as Oracle MLWE-based multi-message multi-recipient KEM/PKE (mmKEM/mmPKE) without requiring public-key well-formedness proofs. In this work, we present a practical cryptanalytic attack on Oracle MLWE, which we call a neighborhood search attack. Our attack exploits adversarially-chosen matrices (or maliciously generated public keys), together with the small ring dimension and small-norm secrets required for correctness, showing that rounding errors can be recovered via a bounded search, leading to recovery of the underlying MLWE secret. To demonstrate the effectiveness of our attack, we apply it against the Oracle MLWE-based mmKEM of Liu et al. (Asiacrypt 2025), proving that its recommended parameter sets do not achieve the claimed security level. We further implement the attack in SageMath and report concrete timings, showing that an adversary controlling a moderate number of recipients can recover other recipients' encapsulated keys within a few seconds on a standard PC under the proposed parameters, which were claimed to achieve a 128-bit security level.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Wang et al. (2026) studied this question.

synapsesocial.com/papers/69fbe357164b5133a91a2a5ehttps://doi.org/10.62056/ab0l5w4e-
Ask AI
Helpful
Bookmark
Share
View Full Paper