Can Coding Agents Migrate to Post-Quantum Cryptography?
cs.MA, cs.CR
Submitted: 2025-12-15
Updated: 2026-09-20
Comments: Substantially revised scope and experiments: coding-agent evaluation of post-quantum migration. 11 pages, 5 figures, 6 tables. Code: https://github.com/aalquwayfili/pqc-migration
Code: https://github.com/aalquwayfili/pqc-migration
License: http://creativecommons.org/licenses/by/4.0/
The gist: A program migrated to post-quantum cryptography can verify its own signatures while producing keys or signatures that another implementation rejects.
Terminology
Abstract
A program migrated to post-quantum cryptography can verify its own signatures while producing keys or signatures that another implementation rejects. We introduce a contract-based task for migrating a Go file signer from RSA to ML-DSA-44, and compare coding agents with and without structured checker feedback. Both conditions receive the contract, compiler, documentation, and OpenSSL. Across 160 attempts in four local-agent configurations, twelve final patches pass local verification but fail external requirements. Checker access does not increase the observed completion rate in any comparison. Recorded traces show unresolved defects and checks invoked only after a patch is correct. Serving settings also affect completion: reducing only Qwen3.8's context window from 128K to 32K lowers full passes from 36/40 to 4/40. Four exploratory trials using GPT-6 Astra through Codex and Claude Fable 5.1 through Claude Code pass all 40 checks, including both baselines. These findings support evaluating interoperability separately from local agreement and reporting harness and serving limits alongside agent results.
Sources
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- CAI: An Open, Bug Bounty-Ready Cybersecurity AI
- Empirical Evaluation of Large Language Models for Migration of Code Fragments to Post-Quantum Cryptography
- Qwen3 Technical Report
- Agent Laboratory: Using LLM Agents as Research Assistants
- Quantum-Safe Code Auditing: LLM-Assisted Static Analysis and Quantum-Aware Risk Scoring for Post-Quantum Cryptography Migration
- Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
- Toward Quantum-Safe Software Engineering: A Vision for Post-Quantum Cryptography Migration
- TrustRAG: Enhancing Robustness and Trustworthiness in Retrieval-Augmented Generation
- CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities
- PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
Related papers
- Highway Congestion Reduction through Reinforcement Learning Based Eulerian Headway Control
- You Only Align Once: Propagating Cooperative Behaviors in Multi-Agent Systems through Seed Agents
- Deny Without Disabling: Authorization-Paired Evaluation and Control for Multi-Agent Systems
- MA-SAPO: Multi-Agent Reasoning for Score-Aware Prompt Optimization
- PeroMAS: A Multi-agent System of Perovskite Material Discovery
- StitchCUDA: An Automated Multi-Agents End-to-End GPU Programing Framework with Rubric-based Agentic Reinforcement Learning