The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS 204 Parameter Sets
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.
Elias: Today's paper: "The Hint Weight of ML-DSA Signatures Is Key-Dependent".
Nadia: The gist Every ML-DSA (FIPS 204) signature carries a public hint vector h,
Elias: First, who's behind it and why it matters.
Paper summary: Nadia: So we're wrapping up this discussion on "The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS two hundred four Parameter Sets <ref:2610.10992#pg1,The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical>." We saw that the total hint weight is only weakly key-dependent, explaining just zero point five percent to one point five percent of the variance in the data <ref:2610.10992#pg3>.
Elias: The authors found that a single signature can identify its key among two hundred with an accuracy of one point one to one point three times chance using just the total weight, but that accuracy jumps to one point five to one point eight times when looking at the per-polynomial weight vector <ref:2610.10992#pg1>.
Priya: So what this paper really means for us is that we have a weak statistical fingerprint in ML-DSA signatures that lets an observer test if two batches of signatures come from the same key without needing the public key <ref:2610.10992#pg2>.
Nadia: That's the practical relevance, Priya. It means filtering on total weight reduces that total-weight channel, but you still have to deal with the per-polynomial channel because that's where the key dependence stays intact <ref:2610.10992#pg3>.
Elias: The conclusion is that this hint weight does not endanger the signing key because (t0) is known to be recoverable from signatures, and the Dilithium designers don't treat it as secret <ref:2610.10992#pg3>.
Priya: So, in short, we have identified a weak linkability fingerprint that exists in ML-DSA signatures and shown how countermeasures like bounded-weight signing affect that fingerprint by measuring the effect on the total versus per-polynomial channels <ref:2610.10992#pg3>.
Conclusion: Nadia: So we're looking at "The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS two hundred four Parameter Sets." This paper is about whether that public hint vector carries some secret information about the private key used to sign a message.
Elias: Right, it's checking if the weight of each part of that signature hints at something specific about how you generated your key. The authors are looking at three different parameter sets from FIPS two hundred four which is just Dilithium.
Priya: So they measured the Hamming weight, which is just a count of those bits in the hint vector, and they found it's not completely random across different keys. It’s weak but it exists.
Nadia: Weak is the word. They say the key only explains about half a percent to one and a half percent of why the total weight changes between keys. That’s a tiny bit of variance.
Elias: But they also pointed out that if you look at each individual polynomial in that hint vector, every single one of them is dependent on the key on its own. That’s interesting because it means it's not just a random aggregate number messing things up.
Priya: What does this actually mean for someone who isn't a cryptographer? It suggests that if you collect enough signatures, you could theoretically test if two different batches of messages came from the same signing key without even knowing the public key.
Nadia: That’s the practical relevance—a weak linkability fingerprint. But they also showed that countermeasures like bounded-weight signing can actually remove a huge chunk of that difference, eighty-six to ninety-one percent of it.
Elias: They found that bounded-weight signing really kills the total weight channel, but the per-polynomial channel stays pretty much untouched. So if you only look at the total weight, you lose most of this information.
Priya: It’s a trade-off then—you can filter for some noise reduction, but you still have to deal with that fine detail in the polynomial weights if you want to maintain security guarantees on your own.
Nadia: Exactly. This whole study boils down to this idea: the hint weight doesn't actually compromise the signing key itself, because we already know how to recover parts of it from signatures. But it does give us a statistical tool for testing key reuse in real-world scenarios.
Elias: So we’ve established that this fingerprint is weak and that some defenses can hide it, but the underlying mechanism still exists within the signature structure. Next up, we're going to look at how those countermeasures actually perform on paper.
Dominik Blain
cs.CR
Submitted: 2026-10-07
Updated: 2026-10-07
Comments: 9 pages, 4 tables
Code: https://github.com/dom-omg/ml-dsa-hint-weight
License: http://creativecommons.org/licenses/by/4.0/
The gist: The gist Every ML-DSA (FIPS 204) signature carries a public hint vector h, and an empirical study finds that the Hamming weight of each hint polynomial hk depends on the signing key, which is a weak
Key concepts
- ML-DSA (FIPS 204) Signature
- This is a digital signature scheme standardized by NIST. Each signature includes a public hint vector 'h' used by the verifier to correct rounding errors when reconstructing the compressed public key. The paper examines how the properties of this hint vector relate to the private signing key.
- Hint Weight (wt(hk))
- This refers to the Hamming weight, or the number of '1's, in each polynomial within the hint vector 'h'. The research found that this weight is not random; it depends on which specific private signing key was used to generate the signature.
- (t0)k Euclidean Norm
- The authors model the key dependence by relating the expected hint weight to the Euclidean norm of a specific part of the private key, denoted as (t0)k. This term represents a low-order part of the private key that is not kept secret but can be recovered from signatures.
Terminology
Summary
The gist
Every ML-DSA (FIPS 204) signature carries a public hint vector h, and an empirical study finds that the Hamming weight of each hint polynomial hk depends on the signing key, which is a weak statistical fingerprint
How it works
The paper investigates whether the total hint weight of ML-DSA signatures is key-dependent across three FIPS 204 parameter sets The researchers observe that the expected weight of each hint polynomial depends on the key, modeling this relationship as proportional to the Euclidean norm of (t0)k, denoted by E[wt(hk)] is proportional to ∥(t0)k∥2
The study measures this effect using 200 keys and 2,000 signatures per key for each parameter set The analysis shows that the key explains only between 0.5% to 1.5% of the variance of the total weight
A single signature can identify its key among 200 with 1.1 to 1.3 times chance accuracy from the total weight, and 1.5 to 1.8 times from the per-polynomial weight vector
Key Findings on Key Dependence
The first-order model predicts that for a key with uniform t0 it predicts a total weight of 63.4, 38.7 and 57.1 for the three parameter sets
When comparing the prediction of Equation (1) with the mean weight observed over 2,000 signatures, the model overestimates the mean by 0.9% to 1.4%
Crucially, when analyzing per-polynomial weights, Every coordinate is key-dependent on its own
The per-coordinate F values lie between specific ranges for each parameter set, and every p-value is below 10−270
Analysis of Observables
The study compares the total weight and the per-polynomial weight vector as observables The vector gives a higher lift than the total weight because two keys can have the same total weight and different per-polynomial norms
The pooled within-key covariance for ML-DSA-44 is nearly diagonal, with small negative off-diagonal terms consistent with the bound wt(h) ≤ ω
Effect of Countermeasures
The paper examines countermeasures to key dependence and finds that fixed-iteration signing cannot change the hint-weight distribution
Furthermore, bounded-weight signing removes 86–91% of the between-key spread of the total weight but leaves the per-polynomial channel largely intact
Bounded-weight signing results in a cost is 2.3 to 2.8 signing runs per output signature
Conclusion and Practical Relevance
The hint weight does not endanger the signing key, as The Dilithium designers do not treat t0 as secret, and t0 is known to be recoverable from signatures
The practical relevance identified is a weak linkability fingerprint
Fixed-iteration signing cannot change this fingerprint, and filtering on the total weight reduces the total-weight channel but leaves the per-polynomial one The work concludes that The hint weight does not endanger the signing key
--- Page 1 ---
The Hint Weight of ML-DSA Signatures Is Key-Dependent Key-Dependent An Empirical Study across the Three FIPS 204 Parameter Sets Dominik Blain1 Ironproof dominik@ironproof.ai Ironproof-PQC Research Report IPQ-2026-01 — May 2026, revised October 2026 Abstract Every ML-DSA (FIPS 204) signature carries a public hint vector h. We find that the Hamming weight of each hint polynomial hk depends on the signing key: to first order it measures the Euclidean norm of (t0)k, the low-order part of t that key generation leaves out of the public key. A closed-form model predicts the per-key mean weight with Pearson r between 0.95 and 0.98; once the norm is accounted for, we detect no key-dependent signal above sampling noise. We measure the effect on the reference C implementation, with 200 keys and 2,000 signatures per key for each parameter set. A one-way ANOVA rejects key-independence of the total hint weight for ML-DSA-44, ML-DSA-65 and ML-DSA-87 (F = 30.1, 10.3, 11.1). The effect is weak: the key explains 0.5% to 1.5% of the variance of the total weight. A single signature identifies its key among 200 with 1.1 to 1.3 times chance accuracy from the total weight, and 1.5 to 1.8 times from the per-polynomial weight vector. A one-sided test at significance 0.001 separates two typical keys with probability one half after about 1,300 to 3,700 signatures per key. The hint weight does not endanger the signing key. The Dilithium designers do not treat t0 as secret, and t0 is known to be recoverable from signatures [4]. The hint weight is, however, a weak statistical fingerprint: with enough signatures, it can be used to test whether they come from a common key, without the public key. Bounded-weight signing, a backward-compatible filter whose effect on the security argument we did not analyze, removes 86–91% of the between-key spread of the total weight but leaves the per-polynomial channel largely intact. 1 Introduction ML-DSA (formerly CRYSTALS-Dilithium [2]) was standardized by NIST in 2024 as FIPS 204 [1]. Each signature σ = (˜c, z, h) contains a hint vector h ∈ K×N that lets the verifier correct the rounding error caused by compressing the public key. The standard bounds the total weight, wt(h) ≤ ω, but does not fix it. Observation. The expected weight of each hint polynomial depends on the key. Section 3 gives a firstorder model in which E[wt(hk)] is proportional to ∥(t0)k∥2, and Section 4 measures the effect on all three parameter sets. Status of t0. t0 is stored in the ML-DSA private key, but it is not a secret on which security rests. The Dilithium specification states: “The security of our scheme does not rely on the part of the public key t0 being secret and so we will be assuming that the public key is t rather than t1” [3, Appendix B]. Azevedo Oliveira et al. show that each signature leaks information on t0 and recover it in full from 200,000 to 500,000 signatures [4]. Berman et al. note likewise that the hint test “may leak information about c t1, but this value is not secret” [5, Section 2.4]. Our observation is consistent with this line of work and does not contradict the security claims of FIPS 204. 1 Practical relevance A signature is normally verified under a known public key, so the signer is not hidden. The hint weight matters only where signatures are collected without reliable key attribution: it lets an observer test whether two batches of signatures come from the same key, using a few thousand signatures and only the K boundary bytes of each, without the public key. ML-DSA makes no unlinkability claim, and we know of no deployed protocol that relies on one. Contributions • A first-order model of the hint weight as a function of ∥(t0)k∥2, checked against the reference implementation, with a residual analysis (Section 3). • A measurement of the between-key effect on ML-DSA-44, ML-DSA-65 and ML-DSA-87, with effect sizes and sample complexity (Section 4). • A comparison of the per-polynomial weight vector with the total weight as an observable (Section 4.3). • Two negative results on countermeasures: fixed-iteration signing cannot change the hint-weight distribution, by argument (Section 5), and bounded-weight signing suppresses the total-weight channel but not the per-polynomial one (Section 7.1). • A statement, under an explicitly idealized oracle, of what exact leakage of c t0 and c s1 gives (Section 6) What this paper does not claim. No key recovery from public signatures. No weakness in Module-LWE or Module-SIS. No physical side-channel measurement: the oracle of Section 6 is simulated in software. The limits of our data are listed in Section 9 arXiv:2610.10992v1 [cs.CR] 7 Oct 2026
--- Page 2 ---
Practical relevance A signature is normally verified under a known public key, so the signer is not hidden.
Improvements for AI systems
-
Confidence in key attribution via hint weight measurement: An improved system can use
a single signature identifies its key among 200 with 1.1 to 1.3 times chance accuracy from the total weight,
allowing for weak linkability fingerprinting when signatures are collected without a reliable public key, as thehint weight does not endanger the signing key.
-
Robustness against total-weight attacks: By employing bounded-weight signing, an improved system can suppress the
between-key spread of the total weight
by 86–91%, making it significantly harder for an observer to distinguish between keys based on that metric. -
Enhanced key discrimination using weight vectors: The system can utilize a
nearest-centroid classifier on the weight vector in Mahalanobis distance,
which is shown to achieve alift over the 0.5% baseline
compared to classifiers based only on the total weight, as the vector captures differences that the total weight alone misses. -
Improved key recovery potential under idealized conditions: If an adversary gains
exact access to c t0 and c s1 at one signing attempt,
a simulated system can recover the full key material using linear algebra methods like(t0)k = M(c)−1 c (t0)k
and subsequently reconstruct the secret key. -
Accurate estimation of secret components: An improved system can use a
passive estimate of t0
by correlatinglow bits with the challenge over M signatures,
which yields a Pearson correlation of 0.99 with the true (t0)k, serving as an independent confirmation method for key leakage analysis.
Abstract
Every ML-DSA (FIPS 204) signature carries a public hint vector h. We find that the Hamming weight of each hint polynomial h k depends on the signing key: to first order it measures the Euclidean norm of (t0) k, the low-order part of t that key generation leaves out of the public key. A closed-form model predicts the per-key mean weight with Pearson r between 0.95 and 0.98; once the norm is accounted for, we detect no key-dependent signal above sampling noise. We measure the effect on the reference C implementation, with 200 keys and 2,000 signatures per key for each parameter set. A one-way ANOVA rejects key-independence of the total hint weight for ML-DSA-44, ML-DSA-65 and ML-DSA-87 (F = 30.1, 10.3, 11.1). The effect is weak: the key explains 0.5% to 1.5% of the variance of the total weight. A single signature identifies its key among 200 with 1.1 to 1.3 times chance accuracy from the total weight, and 1.5 to 1.8 times from the per-polynomial weight vector. A one-sided test at significance 0.001 separates two typical keys with probability one half after about 1,300 to 3,700 signatures per key. The hint weight does not endanger the signing key. The Dilithium designers do not treat t0 as secret, and t0 is known to be recoverable from signatures. The hint weight is, however, a weak statistical fingerprint: with enough signatures, it can be used to test whether they come from a common key, without the public key. Bounded-weight signing, a backward-compatible filter whose effect on the security argument we did not analyze, removes 86-91% of the between-key spread of the total weight but leaves the per-polynomial channel largely intact.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs