arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37483cs.CRcs.CGcs.DSmath.MG

对偶格攻击用于有界距离解码,再探

Dual lattice attacks for bounded distance decoding, revisited

Thijs Laarhoven

AI总结:

本文在 Haar 随机格模型中,无需启发式假设,证明了带预处理的决策有界距离解码的显式渐近权衡,其权衡与 Ducas-Pulles 条件模型预测一致。

AI中文摘要:

对偶格攻击的分析常常假设与短对偶向量相关的个体分数是相互独立的。Laarhoven-Walter 利用这一启发式方法,为带预处理的有界距离解码(BDD)推导了目标半径与查询时间之间的显式权衡。Ducas-Pulles 随后证明了该启发式在理论和实验上的失败,并提出了一个以目标范数为条件的替代模型。在本笔记中,我们在 Haar 随机格模型中,无需启发式假设,证明了带预处理的(决策)BDD 的显式渐近权衡。利用 Siegel 和 Rogers 的矩恒等式,我们分析了完整对偶球上的余弦分数,并界定了在区分以规定半径植入的目标与模格均匀目标时两种错误概率。优化对偶半径得到了目标半径与查询时间之间的权衡,该权衡与 Ducas-Pulles 条件模型的渐近预测相匹配。

英文摘要:

Analyses of dual lattice attacks have often assumed that the individual scores associated with short dual vectors are mutually independent. Laarhoven-Walter used this heuristic to derive explicit trade-offs between the target radius and query time for bounded distance decoding (BDD) with preprocessing. Ducas-Pulles subsequently demonstrated theoretical and experimental failures of this heuristic and proposed an alternative model conditioned on the target norm. In this note, we prove an explicit asymptotic trade-off for (decision-)BDD with preprocessing in the Haar-random lattice model, without heuristic assumptions. Using moment identities of Siegel and Rogers, we analyze cosine scores over complete dual balls and bound both error probabilities when distinguishing targets planted at a prescribed radius from uniform targets modulo the lattice. Optimizing the dual radius yields a trade-off between target radius and query time that matches the asymptotic prediction from the conditional model of Ducas-Pulles.

补充信息

↑