AI Exposes Flaw in Leiden's Cryptographic Method

An AI model helped uncover a weakness in HAWK, an experimental digital signature system designed to protect online communications. HAWK was developed by a team including researchers at Leiden University and Centrum Wiskunde & Informatica. The finding highlights both the promise of AI and the challenges of future-proof digital security.

American tech company Anthropic reported that its AI system Claude helped discover an attack on HAWK, an experimental digital signature system used to verify the authenticity of digital information and designed to remain secure against attacks from future quantum computers. HAWK was developed by an international team including Leo Ducas. Ducas is part of the Cryptology group at Centrum Wiskunde & Informatica (CWI) and is also professor of Mathematical cryptology at Leiden University.

'We wanted to explore a completely new direction in lattice-based cryptography,' Ducas explains (see box). 'HAWK succeeded in attracting attention to that idea and getting people to test it seriously.'

What is lattice-based cryptography?

Lattice-based cryptography protects digital information using mathematical puzzles that are believed to remain difficult even for future quantum computers. These puzzles are based on lattices: regular grids of points extending through very high-dimensional space.

HAWK used a novel approach. Instead of relying on random mathematical structures, it started with a highly structured lattice and hid it through a transformation. Its security depended on the difficulty of recognising when two lattices are actually the same shape viewed in different ways, a challenge known as the lattice isomorphism problem.

The story has a strong Leiden connection. Ducas and former Leiden student Wessel van Woerden helped develop HAWK, while later research into possible attacks involved Leiden and CWI cryptographers Daan van Gent and Ludo Pulles.

Looking back, Van Gent believes there was only one modest step missing.

AI found the missing piece

Trying to break digital signature schemes is a normal part of cryptographic research. The more attacks a scheme survives, the more confidence researchers have in its security. Van Gent had already made progress towards an attack on HAWK together with Pulles. Looking back, Van Gent believes there was only one modest step missing. 'That final step has now been found with AI assistance.'

Not a crisis for cryptography

The attack ultimately led the team to withdraw HAWK from the international standardisation process. According to Ducas, HAWK was not completely broken: the attack showed that HAWK's specific design was less secure than hoped, not that the underlying mathematics had failed. 'There were three or four attacks by other researchers prior to the current one that came very close,' says Ducas. 'This time, an attack succeeded.' While HAWK can still be used in a secure way, doing so makes it not efficient enough to be competitive.

The researchers intentionally pushed the design towards maximum efficiency, knowing that doing so involved risk. 'We went one step too far in comparison with the now standardised methods,' Ducas says.

'The harder part is finding the right direction in the first place.'

What AI can - and cannot - do

Both Ducas and Van Gent are impressed by Claude's contribution but caution against exaggerated claims about AI replacing scientists.

Ducas believes the attack built on ideas researchers such as Van Gent were already exploring. 'The final step is often easier because you know where you want to go,' he says. 'The harder part is finding the right direction in the first place.' This is illustrated by the fact that a human reached similar results as the AI model later that week.

The broader perspective of knowledge is especially important in mathematics, says Ducas. 'Mathematics is built on centuries of accumulated knowledge. To remain usable, it requires constant maintenance: classification, unification, comparison.' While AI can learn from papers and books, and now even produce new knowledge, it has not yet inherited that critical research culture of doing it diligently. That is something we should be careful not to lose, says Ducas. The issue is also raised in the recently published Leiden Declaration on Artificial Intelligence and Mathematics.

Back to the drawing board

Despite HAWK's withdrawal, the researchers remain optimistic. The attack exposed a weakness in one experimental design, but not in the broader research direction or current NIST standardised post-quantum cryptography. 'We need to do more research,' says Ducas. 'Now that the pressure of standardisation is gone, we can take the time to understand these ideas properly.' And in a field that helps keep the internet secure, every lesson learned helps shape the next generation of encryption.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.