Blog Article

Two 2026 Papers Put ML-DSA Implementations to the Test. Here Is What That Means, and What It Does Not

October 6, 2026
4 min read
Expert Content

Published on

October 6, 2026

September 2026 brought two notable academic results against ML-DSA, the lattice-based signature algorithm NIST standardized as FIPS 204. Both deserve attention from anyone planning post-quantum signatures. Neither breaks the algorithm. The distinction matters, and it is the subject of this article.

The first paper, published on the IACR ePrint archive on September 7, 2026, is titled "When Module Lattice Leaks: Horizontal Fusion Attacks on ML-DSA Implementation". Its authors come from the Nanjing University of Science and Technology, Télécom Paris, and the Chinese Academy of Sciences. According to the paper, their power-analysis attack achieves full private key recovery from the traces of just 4 signatures on an unprotected ML-DSA-87 implementation. The authors also report defeating a first-order masked implementation with about 90 traces.

The second, from researchers at the University of Lübeck, the Max Planck Institute for Security and Privacy, Fraunhofer AISEC and Ruhr-University Bochum, is titled "Keep Track of Your Errors: Solving ILWE and Improving Attacks on ML-DSA". It improves how attackers can exploit partial leakage, such as timing. According to the authors, their solver reduces the signatures needed in one noise-free setting from roughly 139 million to 2.25 million, a 62-fold improvement.

What These Results Are, and Are Not

Both are implementation attacks. They exploit how specific hardware or software executes the algorithm: the power it draws, the time it takes. They say nothing against the mathematics of ML-DSA itself. The lattice problem underneath is exactly as hard as it was before these papers.

This is worth stating plainly, because the nuance tends to get lost. Side-channel research of exactly this kind accompanied RSA and ECC for three decades. Timing attacks, power analysis and fault attacks against those algorithms filled conference proceedings for years. The result was not the abandonment of RSA or ECC. It was hardened implementations: masking, constant-time code, certified hardware. The same maturation process has now begun for the post-quantum generation, in public, which is how it works best.

Take control of your PKI infrastructure

See how Evertrust simplifies certificate lifecycle management.

Get Started

The honest reading cuts both ways. Reassuring: the algorithm holds, and the research community is probing implementations early and openly. Sobering: four signatures is a strikingly low bar for an unprotected implementation, and first-order masking alone did not stop the first attack. ML-DSA implementations are young. The protections that took RSA implementations years to accumulate are still being built and tested here.

The Practical Question for Buyers

For organizations planning post-quantum issuance, these papers translate into one concrete procurement question. Signing keys for a certificate authority live in HSMs and similar hardware. That hardware executes ML-DSA somewhere physical, where power and timing can leak.

Want to master certificate management?

Browse our resources on PKI best practices.

Education Center

So before offering or consuming ML-DSA-based certificate services, the question worth putting to any HSM or key-management vendor is simple. What evidence exists of side-channel resistance for their ML-DSA implementation, against attacks of precisely this class? A mature vendor will have an answer: independent evaluation, certification in progress, masking strategy, test results. The question costs nothing to ask. Asking it now, while plans are still on paper, is considerably cheaper than discovering the answer later.

The Standards Bodies Are Not Rushing, and That Is Consistent

September 2026 was a quiet month at the CA/Browser Forum, and the quiet is part of this same story. Only small cleanup ballots passed. The ballot that would allow ML-DSA in publicly trusted TLS certificates did not advance, and the schedule reducing certificate lifetimes stayed unchanged.

Seen next to the research above, that patience looks less like delay and more like sequencing. The ecosystem is letting implementation security mature before anchoring public trust to it. It is also consistent with the posture European agencies have recommended throughout: hybrid constructions during the transition, so that no single young implementation carries the whole weight of trust. Defense in depth was designed for exactly this period, when the mathematics is standardized and the engineering around it is still earning confidence.

Closing Thoughts

These papers are the system working. Algorithms get standardized, implementations get attacked in the open, and the next generation of implementations gets stronger for it. For planners, the takeaway is not to pause post-quantum preparation. Inventory, governance and migration planning lose none of their urgency. The takeaway is to plan with implementation maturity in view: favor hybrid approaches during the transition, and put the side-channel question to hardware vendors early. The organizations that ask it early will be the comfortable ones when ML-DSA certificates arrive at scale.

Was this helpful?
Back to blog

Table of Contents

Stay Updated

Get the latest PKI insights delivered to your inbox.

By subscribing you accept to receive our communications. You can unsubscribe at any moment.

Related Articles

Evertrust PQC

Are European enterprises ready for Post-Quantum Cryptography (PQC) migration? The gaps and the path forward

September 10, 2025
1 min

Explore why PQC adoption lags in Europe, the real blockers, and how to achieve quantum-safe security.

Read more
Evertrust PQC

NIST Releases New Post-Quantum Cryptography Standards

September 10, 2025
1 min

Discover NIST’s new Post-Quantum Cryptography standards (FIPS 203, 204, 205) and how Evertrust is preparing to integrate them for enhanced cybersecurity.

Read more
Evertrust ACME

ACME Clients on Linux

February 12, 2024
1 min

The ACME protocol is a network protocol designed to automate the process of domain validation, deliverance and renewal of X.509 certificates. The process is set up between an ACME server and an ACME client.

Read more
Get started

Ready to take back control over your certificates?

Talk to our experts and discover how Evertrust can help you implement best practices in PKI and certificate lifecycle management.