Implementation Attacks on ML-KEM: Analysis, Practical Assessment, and Recommendations

  • Vitor Hugo Galhardo Moia Instituto de Pesquisas Eldorado
  • Kevin Pires Novaes Instituto de Pesquisas Eldorado
  • Vinicius de Paula Rossetto Instituto de Pesquisas Eldorado

Resumo


ML-KEM is the NIST-standardized key encapsulation mechanism derived from CRYSTALS-Kyber, a post-quantum cryptographic algorithm designed to provide security against both classical and quantum computers. However, implementation attacks threaten the adoption of this algorithm, specially in constrained environments (e.g., IoT, OT/ICS, and other embedded applications). In this work, we present an analysis of Side-Channel and Fault Injection attacks, demonstrating which algorithm operations are targeted by adversaries, practical experiments to detect side-channel leakage, adversary capabilities required to perform attacks, and recommendations for securing implementations.

Referências

Alagic, G., Alagic, G., Apon, D., Cooper, D., Dang, Q., Dang, T., Kelsey, J., Lichtinger, J., Liu, Y.-K., Miller, C., et al. (2022). Status report on the third round of the nist post-quantum cryptography standardization process. NIST.

Alagic, G., Dang, Q., Moody, D., Robinson, A., Silberg, H., Smith-Tone, D., et al. (2024). Module-lattice-based key-encapsulation mechanism standard. NIST Pubs.

Gilbert Goodwill, B. J., Jaffe, J., Rohatgi, P., et al. (2011). A testing methodology for side-channel resistance validation. In NIST non-invasive attack testing workshop, volume 7, pages 115–136.

Hermelink, J., Pessl, P., and Pöppelmann, T. (2021). Fault-enabled chosen-ciphertext attacks on kyber. In Inter. Conf. on Cryptology in India, pages 311–334. Springer.

Kannwischer, M. J., Pessl, P., and Primas, R. (2020). Single-trace attacks on keccak. Cryptology ePrint Archive.

Kannwischer, M. J., Rijneveld, J., Schwabe, P., and Stoffelen, K. (2019). Pqm4: Post-quantum crypto library for the arm cortex-m4. Accessed: July. 12, 2026.

Meng, Y., Wang, B., Xing, Q., Wang, X., Zhou, D., and Liu, L. (2026). Deep learning based side-channel attack on polynomial multiplication in post-quantum cryptography. ACM TECS, 25(4):1–28.

Primas, R., Pessl, P., and Mangard, S. (2017). Single-trace side-channel attacks on masked lattice-based encryption. In CHES, pages 513–533. Springer.

Prokop, L. and Peßl, P. (2021). Fault attacks on cca-secure lattice kems. TCHES, 2021(2):37–60.

Qin, Y., Cheng, C., Zhang, X., Pan, Y., Hu, L., and Ding, J. (2021). A systematic approach and analysis of key mismatch attacks on lattice-based nist candidate kems. In ASIACRYPT, pages 92–121. Springer.

Ravi, P., Bhasin, S., Roy, S. S., and Chattopadhyay, A. (2021). On exploiting message leakage in (few) nist pqc candidates for practical message recovery attacks. IEEE TIFS, 17:684–699.

Ravi, P., Chattopadhyay, A., D’Anvers, J. P., and Baksi, A. (2024a). Side-channel and fault-injection attacks over lattice-based post-quantum schemes (kyber, dilithium): Survey and new results. ACM TECS, 23(2):1–54.

Ravi, P., Paiva, T., Jap, D., D’anvers, J.-P., and Bhasin, S. (2024b). Defeating low-cost countermeasures against side-channel attacks in lattice-based encryption. TCHES.

Ravi, P., Roy, D. B., Bhasin, S., Chattopadhyay, A., and Mukhopadhyay, D. (2019). Number “not used” once-practical fault attack on pqm4 implementations of nist candidates. In COSADE, pages 232–250. Springer.

Ravi, P., Yang, B., Bhasin, S., Zhang, F., and Chattopadhyay, A. (2023). Fiddling the twiddle constants-fault injection analysis of the number theoretic transform. TCHES, 2023(2):447–481.

Renita, J., Annadurai, S., et al. (2025). Side-channel and fault attacks on ml-kem: A survey of vulnerabilities and countermeasures. In WISPNET, pages 1–6. IEEE.

Roy, K. S., SL, S. D., Mishra, T. K., Hassan, M., and Hazarika, R. A. (2024). Analyzing crystals-kyber’s susceptibility to side channel attacks: An empirical exploration.

Sim, B.-Y., Kwon, J., Lee, J., Kim, I.-J., Lee, T.-H., Han, J., Yoon, H., Cho, J., and Han, D.-G. (2020). Single-trace attacks on message encoding in lattice-based kems. IEEE Access, 8:183175–183191.

Teague, T. (2022). Side-channel analysis on post-quantum cryptography algorithms.

Wang, R., Brisfors, M., and Dubrova, E. (2023). A side-channel attack on a bitsliced higher-order masked crystals-kyber implementation. Cryptology ePrint Archive.

Wang, R. and Dubrova, E. (2023). A side-channel secret key recovery attack on crystalskyber using k chosen ciphertexts. In C2SI, pages 109–128. Springer.

Xagawa, K., Ito, A., Ueno, R., Takahashi, J., and Homma, N. (2021). Fault-injection attacks against nist’s post-quantum cryptography round 3 kem candidates. In ASIACRYPT, pages 33–61. Springer.

Xu, Z., Pemberton, O., Roy, S. S., Oswald, D., Yao, W., and Zheng, Z. (2021). Magnifying side-channel leakage of lattice-based cryptosystems with chosen ciphertexts: The case study of kyber. IEEE Transactions on Computers, 71(9):2163–2176.

Zhao, Y., Pan, S., Ma, H., Gao, Y., Song, X., He, J., and Jin, Y. (2023). Side channel security oriented evaluation and protection on hardware implementations of kyber. IEEE TCAS-I, 70(12):5025–5035.
Publicado
01/09/2026
MOIA, Vitor Hugo Galhardo; NOVAES, Kevin Pires; ROSSETTO, Vinicius de Paula. Implementation Attacks on ML-KEM: Analysis, Practical Assessment, and Recommendations. In: WORKSHOP CIBERSEGURANÇA QUÂNTICA: TEORIA, TECNOLOGIAS E APLICAÇÕES - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 829-835. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33066.