Skip to main content

Table 7 Kyber’s secret distribution

From: Hybrid dual attack on LWE with arbitrary secrets

Name n k Probability of
0 \(\pm 1\) \(\pm 2\) \(\pm 3\)
Kyber512 256 2 \(\frac{5}{16}\) \(\frac{15}{64}\) \(\frac{3}{32}\) \(\frac{1}{64}\)
Kyber768 256 3 \(\frac{3}{8}\) \(\frac{1}{4}\) \(\frac{1}{16}\)
Kyber1024 256 4 \(\frac{3}{8}\) \(\frac{1}{4}\) \(\frac{1}{16}\)