acceptodds
Under review as a conference paper at ICLR 2027

CryptHarness: A Harness for Agent-Assisted Cryptanalytic Research

Abstract

Cryptanalysis typically requires both a mathematical model and code, making it a natural testbed for research agents. We present _CryptHarness_, a command-line agent for cryptanalytic research, built from reusable domain skills. Given only a researcher's intuition for how a cryptographic scheme might be attacked, CryptHarness develops the attack and produces a paper-style report. The report comes with three artifacts. First, a mathematical model of the underlying problem to support a theoretical analysis of the attack. Second, a proof of concept implementation designed for readability by abstracting away nonessential details. Third, an implementation of the scheme exactly according to the specification, and of the attack itself, allowing rigorous evaluation across experiments. As a case study, we apply CryptHarness to public-key decompression for ML-DSA, the new primary post-quantum signature standard. Given only the initial idea and minimal guidance, our agent reduced the required number of signatures of the state-of-the-art decompression method by a factor of three and provided a mathematical analysis. In a separate verification layer, we formally verify a central finite-size first-moment theorem in Lean 4, providing an (almost) matching lower bound on the number of signatures required to decompress an ML-DSA-44 public key. In a second case study, we apply CryptHarness to secret-key recovery from randomness leakage in Falcon, a secondary post-quantum signature standard. The agent identified three improvements to the state-of-the-art attack, reducing the number of signatures required for key recovery by factors of 2 and 3.7 for the two existing parameter sets, respectively.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.