Abstract
Abstract only The Large Norm attacks of Ducas-Espitau-Postlethwaite (CRYPTO 2023) on the ISIS problem showed that small moduli q can be exploited to recover short solutions, as applied to Falcon and Mitaka. Two gaps remained: the cost model oversimplifies the BDGL sieve, ignoring how sieve-output lengths are distributed and treating two dependent probabilistic events as independent, which overestimates the attack cost; and the analysis is restricted to the l2 norm and was not extended to ISIS-infinity, which underlies Dilithium-type systems. In this work, we address both. First, we sharpen the cost model by integrating the success probability over the full sieve length distribution and by using a joint rather than an approximate probability, reusing the existing theta-convolution framework. This yields an about 11 times cheaper cost model on Falcon-256 and forges a Mitaka-512 signature in about 4.5 seconds at a higher success rate. Second, we introduce a closed-form l-infinity Z-shape attack against Dilithium-type ISIS-infinity at small-to-moderate modulus, which succeeds in under 1.6 seconds across three scaled-down presets.