arXiv:2604.06942cs.CRcs.IT2026-04

用深度学习检测后量子加密的密文不可区分性,验证混合与级联方案的安全性。

Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning

论文配图:Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning
图 1 · 摘自论文原文
  • 将IND-CPA游戏建模为二分类任务,用DNN分析密文区分特征。
  • 在3种PQC KEM、组合和级联加密中均未发现显著可区分性。
  • 方法适用于实际系统验证,补充传统理论分析,适合密码学评估者使用。

确保密文不可区分是密码安全的基础,但在真实实现和混合场景中实证验证该性质面临挑战。随着后量子密码(PQC)的发展,其混合构造结合经典与抗量子原语,使得实证验证方法愈发重要。本文将IND-CPA游戏建模为二分类任务,利用带交叉熵损失(BCE)的深度神经网络(DNN)对标注的密文数据进行训练,研究密文不可区分性的判别器。方法应用于多种PQC KEM,包括用于构建ML-KEM、BIKE、HQC的公钥加密(PKE)方案。此外,提出一种DNN模型的扩展,用于混合KEM的实证可区分性测试,涵盖与纯RSA、RSA-OAEP及明文的组合。进一步将该框架应用于级联对称加密,测试了AES-CTR、AES-CBC、AES-ECB、ChaCha20和DES-ECB的组合。在所有实验中,无任何算法或组合在双侧二项检验(α=0.01)下表现出显著优势,与理论保证一致:只要混合结构包含至少一个IND-CPA安全组件,即可保持不可区分性,且在所考虑的DNN对抗模型下不存在可被利用的模式。结果表明,深度学习可作为通用、自适应且实用的实证指标,用于更广泛的IND-CPA场景中的不可区分性评估,支持对实现与组合的数据驱动验证,补充分析性安全分析。

原文摘要 · Abstract (English)

Ensuring ciphertext indistinguishability is fundamental to cryptographic security, but empirically validating this property in real implementations and hybrid settings presents practical challenges. The transition to post-quantum cryptography (PQC), with its hybrid constructions combining classical and quantum-resistant primitives, makes empirical validation approaches increasingly valuable. By modeling IND-CPA games as binary classification tasks and training on labeled ciphertext data with BCE loss, we study deep neural network (DNN) distinguishers for ciphertext indistinguishability. We apply this methodology to PQC KEMs. We specifically test the public-key encryption (PKE) schemes used to construct examples such as ML-KEM, BIKE, and HQC. Moreover, a novel extension of this DNN modeling for empirical distinguishability testing of hybrid KEMs is presented. We implement and test this on combinations of PQC KEMs with plain RSA, RSA-OAEP, and plaintext. Finally, methodological generality is illustrated by applying the DNN IND-CPA classification framework to cascade symmetric encryption, where we test combinations of AES-CTR, AES-CBC, AES-ECB, ChaCha20, and DES-ECB. In our experiments on PQC algorithms, KEM combiners, and cascade encryption, no algorithm or combination of algorithms demonstrates a significant advantage (two-sided binomial test, significance level $α= 0.01$), consistent with theoretical guarantees that hybrids including at least one IND-CPA-secure component preserve indistinguishability, and with the absence of exploitable patterns under the considered DNN adversary model. These illustrate the potential of using deep learning as an adaptive, practical, and versatile empirical estimator for indistinguishability in more general IND-CPA settings, allowing data-driven validation of implementations and compositions and complementing the analytical security analysis.

后量子密码深度学习安全验证密文区分

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。