Limitations#
The tool reports a security level, so it is worth being precise about what that number does and does not cover.
What is not modelled#
Dual attacks. Only primal attacks are considered. The efficient dual attacks of [GJ21] and [MATZOV] rely on heuristics shown to fail in [DP23], and the provable variants are weaker than the primal attacks at these parameters. If a corrected dual analysis lands, these estimates would need revisiting.
Quantum attacks. All costs are classical, in the core-SVP model with the BDGL16 sieving cost.
Correctness of decryption. The tool answers only the security question. Whether a parameter set supports the circuit you want to evaluate depends on noise growth in your scheme, which is out of scope.
Where the formulas apply#
The constants in src/const.py were fitted against Lattice Estimator data
at \(\sigma_e = 3.19\), for binary and ternary secrets, over
\(n \in [2^{10}, 2^{15}]\). They hold up beyond that range – the paper
checks \(n = 2^{16}\) and \(2^{17}\) – but the further you go, the
more you are extrapolating. Outside the fitted setting the tool falls back to
the numerical solvers automatically.
The model was tuned to slightly under-estimate security rather than over- estimate it. Discrepancies of a few bits against the Lattice Estimator are expected and acceptable.
Known weaknesses#
The hybrid log q search is not reliable. --param "logq" with
--secret "sparse" can return a modulus whose measured security is below
the target. The solver checks each candidate against its own lambda model, but
that model and the Lattice Estimator disagree by anywhere from 2 to 100 bits,
so the check cannot underwrite the answer. Always run this combination with
-v and compare est hybrid against your target.
The Lattice Estimator loses precision for large errors. When
\(\sigma_e\) is far from 3.19 – as it is for much of
--param "std_e" – the est columns should be read as indicative.
Numerical solvers can fail to converge. They restart from randomised
initial points and give up after a bounded number of attempts. A failure is
reported as a fallback value with an estimator verdict of 0, which is a
signal to rerun with a different --seed or to use the closed forms.
Local optima. The solvers may settle on a solution that is not the best
available. Restarting with a different --seed, or raising --nrestart
for the hybrid, sometimes finds a better one.
Verifying a result#
The tool is a fast way to narrow the search, not a replacement for an estimator. Once you have candidate parameters, confirm them:
fastparams --param "lambda" --n "1024" --logq "27" \
--secret "binary" --error "gaussian" --std "3.19" --table -v
The est columns are the Lattice Estimator’s verdict under the BDGL16 cost
model. You can also check against an independent tool such as the
Leaky-LWE Estimator.
Guo and Johansson, Faster dual lattice attacks for solving LWE with applications to CRYSTALS, ASIACRYPT 2021.
MATZOV, Report on the security of LWE: improved dual lattice attack, 2022.
Ducas and Pulles, Does the dual-sieve attack on learning with errors even work?, CRYPTO 2023.