08:45-08:50 (PDT) Opening Remarks
Opening Remarks by Daniele Micciancio, Ted Chinburg and Frauke Bleher
08:50-09:35 (PDT) Leo Ducas: Predicting module-lattice reduction
09:40-10:25 (PDT) Daniel van Gent: HAWK: a post-mortem
Abstract: On July 28th, Anthropic researchers Straznickas and Weis and its Claude AI published a successful attack on NIST-candidate post-quantum digital signature scheme HAWK. They proceed by computing a new automorphism of the HAWK lattice on the public basis, which by previous work of G–Pulles suffices to halve the security parameter of the scheme. In this talk I will explain the attack assuming little prior knowledge on module-LIP-based schemes, and if time permits propose a potential direction towards a new scheme.
10:30-10:50 (PDT) Coffee break
10:50-11:35 (PDT) Carlo Pagano: Pseudo-randomness and rigidity in the nilpotent closure
Abstract: Several recent results in arithmetic statistics have stimulated the investigation of the structure of the pro-nilpotent tower of a number field and how this structure is informed by the underlying randomness. A precise instance of this was established in 2023 in joint work with Koymans where we proved that the 2-step nilpotent closure (of certain number fields) can be encoded in a decorated graph on the set of primes, we have shown that this graph is pseudo-random, and with that we deduced that the isomorphism class of the group admits an explicit combinatorial description. This shows that distinct number fields can have isomorphic 2-nilpotent Galois groups, upon matching the primes in a graph-preserving manner. Building on this description, in joint work in progress with Zuccon, we establish that these are (in a precise sense) the only possible identifications between these Galois groups. In other words, the 2-step nilpotent group "knows" about the totality of the primes in the abelianization: they form a rigid set that can be at most permuted. The key idea of the proof of this rigidity result was discovered by Aletheia, an internal agent at Google DeepMind.
11:40-12:25 (PDT) Daqing Wan: NP-hardness of SVP in Euclidean space
Abstract: In 1981, van Emde Boas conjectured that computing a shortest non-zero vector of a lattice in a Euclidean space is NP-hard. In this talk, we outline a proof of this conjecture. We follow the derandomization program as formulated by Micciancio (1998–2014) who conjectured the existence of an efficient deterministic construction of locally dense lattices . The main part of our work is to resolve this conjecture. Our proof builds on the construction of locally dense lattices via Reed-Solomon codes by Bennett and Peikert (2023), and depends crucially on Deligne's work on the Weil conjectures for higher-dimensional varieties over finite fields.
12:30-14:00 (PDT) Lunch break
14:00-14:45 (PDT) Xuxi Ding and Adam Suhl: Covering radius and algorithmic construction of multiquadratic extension towers
Abstract: In this talk, we measure a number field not by its degree or discriminant, but by its covering radius. We show that this is bounded by n^{0.661} for infinitely many fields of increasing degree n for the L_2 norms. By contrast, for ϵ > 0, there are only finitely many cyclotomic fields with L_2 covering radius less than n^{1−ϵ}.
14:50-15:35 (PDT) Phong Nguyen: Adelic reduction of module lattices
Abstract:
15:40-16:10 (PDT) Coffee break
16:10-16:55 (PDT) Christopher Peikert: New directions in fully homomorphic encryption
Abstract: I will do a high-level view of the key ideas behind two recent papers on new, complementary ways of SIMD packing (TCC) and handling large plaintext moduli (Crypto).
17:00-17:30 (PDT) Open Discussion on AI and Lattices
Discussion of AI and the future of lattice cryptography