Ilmu Komputer & AI editorial
Dependency-Aware ROM/CBD Correctness Bounds for ML-KEM-768 at the Heuristic Failure Scale
The core problem
Innovation
The main result is a certified upper bound on the honest-decapsulation failure probability for ML-KEM-768 within the ROM/CBD abstraction. Specifically, the reduced rational certificate yields:
and the certified exponent is
The bound is tight at the heuristic failure scale: the certified exponent exceeds 164.81 by only about 0.0007162 bit, and the next threshold 164.82 is not certified. This means the result sits extremely close to the 164.81 boundary, reflecting the precision of the dependency-aware analysis. The upper bound holds for an arbitrary message fixed independently of the public and secret randomness, under honest encryption and decapsulation. The authors stress that this is not an exact DFR, not a fixed-SHAKE equivalence theorem, not a new IND-CCA reduction, and not an adaptive delta-correctness result. The numerical tightness underscores the care required when interpreting the heuristic scale.
Why it matters
Who should read this
Opening member content…