Eurocrypt 2017: On dual lattice attacks against small-secret LWE and parameter choices in HElib and SEAL
Unknown (noreply@blogger.com)
This morning, Martin gave a great talk on lattice attacks and parameter choices for Learning With Errors (LWE) with small and sparse secret. The work presents new attacks on LWE instances, yielding revised security estimates. This leads to a revised exponent of the dual lattice attack by a factor of 2L/(2L+1) , for log q = Θ(L*log n) . The paper exploits the fact that most lattice-based FHE schemes use short and sparse secret. We will write q to denote the LWE modulus throughout. Let's first hav
