Skip to main content

Benchmark Results

Performance of all attacks on benchmark settings. Best Hamming weight (h) for secret recovered per setting/attack, time in hours needed to recover this secret, and machines used. Highest h per setting is bold. All Kyber secrets are binomial, and HE secrets are ternary. First three attacks (uSVP, SALSA, CC) solve Search-LWE; MITM* solves Decision LWE. "Total hrs" is total attack time assuming full parallelization.

Please see our paper for more detailed benchmark results and more information on how these results were obtained.

AttackResultsn=256, k=2, logq=12
binomial
n=256, k=2, logq=28
binomial
n=256, k=3, logq=35
binomial
n=1024, logq=26
ternary
n=1024, logq=29
ternary
n=1024, logq=50
ternary
uSVPBest h------
Recover hrs
(1 CPU)
>1100>1100>1100>1300>1300>1300
SALSABest h9181681017
Total hrs36273934.949.429.1
CCBest h112519121220
Total hrs28.1533421.531.728
MiTM
(Decision LWE)
Best h412149916
Total hrs0.71.6129.4651315.5