The Learning with Errors (LWE) problem is a hard math problem in lattice-based cryptography. In the simplest case of binary secrets, it is the subset sum problem, with error. Effective ML attacks on LWE were demonstrated in the case of binary, ternary, and small secrets, succeeding on fairly sparse secrets. The ML attacks recover secrets with up to 3 active bits in the "cruel region" (Nolte et al., 2024) on samples pre-processed with BKZ. We show that using larger training sets and repeated examples enables recovery of denser secrets. Empirically, we observe a power-law relationship between model-based attempts to recover the secrets, dataset size, and repeated examples. We introduce a stepwise regression technique to recover the "cool bits" of the secret.
翻译:学习带错误(LWE)问题是格密码学中的一个困难数学问题。在二进制密钥的最简单情形下,该问题等价于带误差的子集和问题。针对二进制、三进制及小型密钥的有效机器学习攻击已被证实,可成功恢复相当稀疏的密钥。这类机器学习攻击能够恢复"残酷区域"(Nolte等人, 2024)中最多包含3个活动比特的密钥,攻击对象为经BKZ预处理的样本。我们证明,采用更大规模训练集与重复样本可实现更密集密钥的恢复。通过实验观察,我们发现模型恢复密钥的尝试次数、数据集规模与重复样本之间存在幂律关系。我们引入一种逐步回归技术以恢复密钥的"冷比特"。