{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:12:52Z","timestamp":1785831172713,"version":"3.56.0"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031385476","type":"print"},{"value":"9783031385483","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-38548-3_2","type":"book-chapter","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T19:02:27Z","timestamp":1691521347000},"page":"37-69","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["Does the\u00a0Dual-Sieve Attack on\u00a0Learning with\u00a0Errors Even Work?"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2510-4829","authenticated-orcid":false,"given":"L\u00e9o","family":"Ducas","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8014-9221","authenticated-orcid":false,"given":"Ludo N.","family":"Pulles","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"key":"2_CR1","doi-asserted-by":"crossref","unstructured":"Abramowitz, M., Stegun, I.A.: Handbook of mathematical functions with formulas, graphs, and mathematical tables. Nat. Bureau Stan. Appl. Math. Ser. 55 (1964). https:\/\/archive.org\/details\/AandS-mono600","DOI":"10.1115\/1.3625776"},{"key":"2_CR2","doi-asserted-by":"publisher","unstructured":"Aharonov, D., Regev, O.: Lattice problems in NP cap coNP. In: 45th Annual Symposium on Foundations of Computer Science, pp. 362\u2013371. IEEE Computer Society Press, Rome, Italy, 17\u201319 October 2004. https:\/\/doi.org\/10.1109\/FOCS.2004.35","DOI":"10.1109\/FOCS.2004.35"},{"key":"2_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1007\/978-3-319-56614-6_4","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"MR Albrecht","year":"2017","unstructured":"Albrecht, M.R.: On dual lattice attacks against small-secret LWE and parameter choices in HElib and SEAL. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. LNCS, vol. 10211, pp. 103\u2013129. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56614-6_4"},{"key":"2_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1007\/978-3-030-17656-3_25","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2019","author":"MR Albrecht","year":"2019","unstructured":"Albrecht, M.R., Ducas, L., Herold, G., Kirshanova, E., Postlethwaite, E.W., Stevens, M.: The general sieve kernel and new records in lattice reduction. In: Ishai, Y., Rijmen, V. (eds.) EUROCRYPT 2019. LNCS, vol. 11477, pp. 717\u2013746. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-17656-3_25"},{"key":"2_CR5","unstructured":"Albrecht, M.R., Shen, Y.: Quantum augmented dual attack. arXiv preprint arXiv:2205.13983 (2022)"},{"key":"2_CR6","unstructured":"Alkim, E., Ducas, L., P\u00f6ppelmann, T., Schwabe, P.: Post-quantum key exchange - a New Hope. In: USENIX security symposium, vol. 2016 (2016)"},{"key":"2_CR7","doi-asserted-by":"publisher","unstructured":"Arpin, S., Billingsley, T.R., Hast, D.R., Lau, J.B., Perlner, R., Robinson, A.: A study of error floor behavior in QC-MDPC codes. In: Cheon, J.H., Johansson, T. (eds.) Post-Quantum Cryptography: 13th International Workshop, PQCrypto 2022, Virtual Event, 28\u201330 September 2022, Proceedings. LNCS, pp. 89\u2013103. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-17234-2_5","DOI":"10.1007\/978-3-031-17234-2_5"},{"issue":"4","key":"2_CR8","first-page":"1","volume":"2","author":"R Avanzi","year":"2019","unstructured":"Avanzi, R., et al.: CRYSTALS-Kyber algorithm specifications and supporting documentation. NIST PQC Round 2(4), 1\u201343 (2019)","journal-title":"NIST PQC Round"},{"key":"2_CR9","doi-asserted-by":"publisher","unstructured":"Bai, S., Laarhoven, T., Stehl\u00e9, D.: Tuple lattice sieving. LMS J. Comput. Math. 19(A), 146\u2013162 (2016). https:\/\/doi.org\/10.1112\/S1461157016000292","DOI":"10.1112\/S1461157016000292"},{"key":"2_CR10","doi-asserted-by":"publisher","unstructured":"Becker, A., Ducas, L., Gama, N., Laarhoven, T.: New directions in nearest neighbor searching with applications to lattice sieving. In: Krauthgamer, R. (ed.) 27th Annual ACM-SIAM Symposium on Discrete Algorithms, pp. 10\u201324. ACM-SIAM, Arlington, VA, USA, 10\u201312 January 2016. https:\/\/doi.org\/10.1137\/1.9781611974331.ch2","DOI":"10.1137\/1.9781611974331.ch2"},{"key":"2_CR11","unstructured":"Carrier, K., Shen, Y., Tillich, J.P.: Faster dual lattice attacks by using coding theory. Cryptology ePrint Archive, Paper 2022\/1750 (2022). https:\/\/eprint.iacr.org\/2022\/1750"},{"key":"2_CR12","unstructured":"Debris-Alazard, T., Ducas, L., Resch, N., Tillich, J.P.: Smoothing codes and lattices: systematic study and new bounds. Cryptology ePrint Archive, Paper 2022\/615 (2022). https:\/\/eprint.iacr.org\/2022\/615"},{"key":"2_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-319-78381-9_5","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"L Ducas","year":"2018","unstructured":"Ducas, L.: Shortest vector from lattice sieving: a few dimensions for free. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10820, pp. 125\u2013145. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78381-9_5"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Ducas, L., Pulles, L.: Does the dual-sieve attack on learning with errors even work? Cryptology ePrint Archive, Paper 2023\/302 (2023). https:\/\/eprint.iacr.org\/2023\/302","DOI":"10.1007\/978-3-031-38548-3_2"},{"key":"2_CR15","doi-asserted-by":"crossref","unstructured":"Duhamel, P., Vetterli, M.: Fast Fourier transforms: a tutorial review and a state of the art. Sig. Process. 19(4), 259\u2013299 (1990). https:\/\/infoscience.epfl.ch\/record\/59946","DOI":"10.1016\/0165-1684(90)90158-U"},{"key":"2_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1007\/978-3-030-65277-7_20","volume-title":"Progress in Cryptology \u2013 INDOCRYPT 2020","author":"T Espitau","year":"2020","unstructured":"Espitau, T., Joux, A., Kharchenko, N.: On a Dual\/Hybrid approach to small secret LWE. In: Bhargavan, K., Oswald, E., Prabhakaran, M. (eds.) INDOCRYPT 2020. LNCS, vol. 12578, pp. 440\u2013462. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-65277-7_20"},{"issue":"1","key":"2_CR17","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1109\/TIT.1962.1057683","volume":"8","author":"R Gallager","year":"1962","unstructured":"Gallager, R.: Low-density parity-check codes. IRE Trans. Inf. Theory 8(1), 21\u201328 (1962). https:\/\/doi.org\/10.1109\/TIT.1962.1057683","journal-title":"IRE Trans. Inf. Theory"},{"key":"2_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-3-030-92068-5_2","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"Q Guo","year":"2021","unstructured":"Guo, Q., Johansson, T.: Faster dual lattice attacks for\u00a0solving LWE with\u00a0applications to\u00a0CRYSTALS. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 33\u201362. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_2"},{"issue":"1","key":"2_CR19","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/BF02122554","volume":"8","author":"J H\u00e5stad","year":"1988","unstructured":"H\u00e5stad, J.: Dual vectors and lower bounds for the nearest lattice point problem. Combinatorica 8(1), 75\u201381 (1988). https:\/\/doi.org\/10.1007\/BF02122554","journal-title":"Combinatorica"},{"key":"2_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-662-54365-8_2","volume-title":"Public-Key Cryptography \u2013 PKC 2017","author":"G Herold","year":"2017","unstructured":"Herold, G., Kirshanova, E.: Improved algorithms for the approximate k-list problem in Euclidean Norm. In: Fehr, S. (ed.) PKC 2017. LNCS, vol. 10174, pp. 16\u201340. Springer, Heidelberg (2017). https:\/\/doi.org\/10.1007\/978-3-662-54365-8_2"},{"key":"2_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/978-3-540-74143-5_9","volume-title":"Advances in Cryptology - CRYPTO 2007","author":"N Howgrave-Graham","year":"2007","unstructured":"Howgrave-Graham, N.: A hybrid lattice-reduction and meet-in-the-middle attack against NTRU. In: Menezes, A. (ed.) CRYPTO 2007. LNCS, vol. 4622, pp. 150\u2013169. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74143-5_9"},{"key":"2_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-45325-3_1","volume-title":"Cryptography and Coding","author":"AA Jabri","year":"2001","unstructured":"Jabri, A.A.: A statistical decoding algorithm for general linear block codes. In: Honary, B. (ed.) Cryptography and Coding 2001. LNCS, vol. 2260, pp. 1\u20138. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45325-3_1"},{"key":"2_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"478","DOI":"10.1007\/978-3-030-75539-3_20","volume-title":"Topics in Cryptology \u2013 CT-RSA 2021","author":"T Laarhoven","year":"2021","unstructured":"Laarhoven, T., Walter, M.: Dual lattice attacks for closest vector problems (with preprocessing). In: Paterson, K.G. (ed.) CT-RSA 2021. LNCS, vol. 12704, pp. 478\u2013502. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-75539-3_20"},{"key":"2_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"348","DOI":"10.1007\/11832072_24","volume-title":"Security and Cryptography for Networks","author":"\u00c9 Levieil","year":"2006","unstructured":"Levieil, \u00c9., Fouque, P.-A.: An improved LPN algorithm. In: De Prisco, R., Yung, M. (eds.) SCN 2006. LNCS, vol. 4116, pp. 348\u2013359. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11832072_24"},{"key":"2_CR25","doi-asserted-by":"publisher","unstructured":"MATZOV: Report on the security of LWE: Improved dual lattice attack, April 2022. https:\/\/doi.org\/10.5281\/zenodo.6493704","DOI":"10.5281\/zenodo.6493704"},{"key":"2_CR26","unstructured":"Micciancio, D.: Lattice algorithms and applications, lecture 3: the dual lattice (2014). https:\/\/cseweb.ucsd.edu\/classes\/sp14\/cse206A-a\/lec3.pdf"},{"key":"2_CR27","doi-asserted-by":"publisher","unstructured":"Micciancio, D., Regev, O.: Lattice-based cryptography. In: Bernstein, D.J., Buchmann, J., Dahmen, E. (eds.) Post-Quantum Cryptography, pp. 147\u2013191. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-540-88702-7_5","DOI":"10.1007\/978-3-540-88702-7_5"},{"key":"2_CR28","doi-asserted-by":"publisher","unstructured":"Micciancio, D., Voulgaris, P.: Faster exponential time algorithms for the shortest vector problem. In: Charika, M. (ed.) 21st Annual ACM-SIAM Symposium on Discrete Algorithms, pp. 1468\u20131480. ACM-SIAM (2010). https:\/\/doi.org\/10.1137\/1.9781611973075.119","DOI":"10.1137\/1.9781611973075.119"},{"key":"2_CR29","doi-asserted-by":"publisher","unstructured":"Neyman, J., Pearson, E.S.: On the problem of the most efficient tests of statistical hypotheses. Philos. Trans. Roy. Soc. London Ser. A Containing Papers Math. Phys. Charact. 231(694\u2013706), 289\u2013337 (1933). https:\/\/doi.org\/10.1098\/rsta.1933.0009","DOI":"10.1098\/rsta.1933.0009"},{"issue":"2","key":"2_CR30","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1515\/JMC.2008.009","volume":"2","author":"PQ Nguyen","year":"2008","unstructured":"Nguyen, P.Q., Vidick, T.: Sieve algorithms for the shortest vector problem are practical. J. Math. Cryptol. 2(2), 181\u2013207 (2008). https:\/\/doi.org\/10.1515\/JMC.2008.009","journal-title":"J. Math. Cryptol."},{"key":"2_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/11780656_24","volume-title":"Information Security and Privacy","author":"R Overbeck","year":"2006","unstructured":"Overbeck, R.: Statistical decoding revisited. In: Batten, L.M., Safavi-Naini, R. (eds.) ACISP 2006. LNCS, vol. 4058, pp. 283\u2013294. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11780656_24"},{"issue":"6","key":"2_CR32","doi-asserted-by":"publisher","first-page":"1107","DOI":"10.1109\/PROC.1968.6477","volume":"56","author":"CM Rader","year":"1968","unstructured":"Rader, C.M.: Discrete Fourier transforms when the number of data samples is prime. Proc. IEEE 56(6), 1107\u20131108 (1968)","journal-title":"Proc. IEEE"},{"key":"2_CR33","unstructured":"Richter, G.: Finding small stopping sets in the Tanner graphs of LDPC codes. In: 4th International Symposium on Turbo Codes & Related Topics; 6th International ITG-Conference on Source and Channel Coding, pp. 1\u20135. VDE, Munich, Germany, 3\u20137 April 2006"},{"key":"2_CR34","unstructured":"The FPLLL development team: FPyLLL, a Python wrapper for the FPLLL lattice reduction library, Version: 0.5.9 (2023). https:\/\/github.com\/fplll\/fpylll"},{"key":"2_CR35","doi-asserted-by":"publisher","unstructured":"Vasi\u0107, B., Chilappagari, S.K., Nguyen, D.V.: Failures and error floors of iterative decoders. In: Declerq, D., Fossorier, M., Biglieri, E. (eds.) Channel Coding: Theory, Algorithms, and Applications: Academic Press Library in Mobile and Wireless Communications, pp. 299\u2013341. Academic Press, December 2014. https:\/\/doi.org\/10.1016\/B978-0-12-396499-1.00006-6","DOI":"10.1016\/B978-0-12-396499-1.00006-6"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-38548-3_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T22:02:30Z","timestamp":1753567350000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-38548-3_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031385476","9783031385483"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-38548-3_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"9 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 August 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"43","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"479","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"124","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}