International Association for Cryptologic Research

International Association
for Cryptologic Research

Eurocrypt 2026

Cool + Cruel = Dual, and New Benchmarks for Sparse LWE


Alexander Karenin
Technology Innovation Institute

Elena Kirshanova
Technology Innovation Institute

Julian Nowakowski
Ruhr University Bochum

Eamonn W. Postlethwaite
King's College London

Ludo Pulles
Centrum Wiskunde & Informatica

Paul Vié
Télécom Paris

Fernando Virdia
University of Surrey, Guildford


Keywords: bounded distance decoding, sparse LWE, cryptanalysis, lattice cryptography, benchmarks


Abstract

The sparse secret Learning with Errors (LWE) problem is a widely used assumption in efficient fully homomorphic constructions. In [Wenger et al. IEEE S\&P 2025] two approaches, `Cool and Cruel’ (C+C) and the machine learning based `SALSA', were benchmarked against the well established primal attack on sparse secrets. The authors concluded that C+C outperforms SALSA and both outperform the primal attack.

In this work we show that the apparently novel C+C is an instantiation of a known dual attack [Albrecht, EUROCRYPT 2017]. To argue this we introduce a framework for dimension reduction in the bounded distance decoding problem that may be of independent interest. Furthermore we prove that the C+C `phenomenon' is an expression of the geometry of the well known Z-shape basis in $q$-ary lattices, despite claims to the contrary.

We also show that a correctly parametrised primal attack outperforms C+C both in parameter regimes studied by Wenger et al. and in new parameter regimes. To support this claim, we provide an open source implementation of two variants of the primal attack that are relevant for sparse secret LWE: Drop+Solve [May--Silverman, CaLC 2001] and Guess+Verify [Albrecht et al. SAC 2019].

Publication

EUROCRYPT 2026, LNCS 16544

Paper

Artifact

Artifact number
eurocrypt/2026/a11

Artifact published
July 25, 2026

Badge
🏆 IACR EUROCRYPT Results Reproduced

README

ZIP (2.53 KB)  

View on Github

License
GPLv3 This work is licensed under the GNU General Public License version 3.

Note that license information is supplied by the authors and has not been confirmed by the IACR.


BibTeX How to cite

Alexander Karenin, Elena Kirshanova, Julian Nowakowski, Eamonn W. Postlethwaite, Ludo Pulles, Paul Vié, and Fernando Virdia. (2026). Cool + Cruel = Dual, and New Benchmarks for Sparse LWE. In Advances in Cryptology – EUROCRYPT 2026, Lecture Notes in Computer Science vol. 16544, pp. 304–333, Springer. https://doi.org/10.1007/978-3-032-25327-9_11. Artifact at https://artifacts.iacr.org/eurocrypt/2026/a11.