ML-DSA on x86-64: sample verification's  as one run of entries (verify −8% with AVX2, −9% baseline ML-DSA-87) - #544
Merged
reaperhulk merged 9 commits intoOct 2, 2026
Conversation
Verification kept Â[r, s] at polynomial 20 + 8r + s, so a group of four entries of vg_mldsa_rej_ntt_poly4 could not cross a row: for ℓ = 7 the second group of each row sampled entry 3 again, and for ℓ = 5 the last entry of each row was sampled alone. Â[r, s] is now entry e = ℓr + s at polynomial 20 + e, and verification samples the kℓ entries as key generation and signing do: kℓ/4 groups of four (each seed's indices are e mod ℓ and e / ℓ), then the last kℓ mod 4 one at a time. ML-DSA-87 (56 entries) has no duplicate, and ML-DSA-65 makes 7 four-way calls and 2 single ones instead of 6 and 6. The proofs of the samplers (StageA, CTSample) now count sampled entries by their number, Done ℓ e r' c' := ℓr' + c' < e; the rest only pass ℓ to pA. The working space of vg_mldsa_rej_ntt_poly4 stays at polynomial 20 + 8k, after  for every ℓ. Instructions per verification (callgrind, 20 verifications less key generation and one signature): AVX2 ML-DSA-65 1.061M → 0.977M (−7.9%), ML-DSA-87 1.677M → 1.540M (−8.1%); baseline ML-DSA-87 3.276M → 2.971M (−9.3%, undoing the duplicate's cost); ML-DSA-44 and the ML-DSA-65 baseline are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
…-einstein-ukl7t7-rej4v Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
reaperhulk
merged commit Oct 2, 2026
551c0ef
into
claude/fervent-einstein-ukl7t7-em4
58 checks passed
alex
pushed a commit
that referenced
this pull request
Oct 2, 2026
…e merge of #526 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #537; the diff shows only this change. This is the follow-up promised in #534. It removes the duplicated entry that made the baseline ML-DSA-87 verification 7% slower there.
What
Verification kept
Â[r, s]at polynomial20 + 8r + s, so a group of four entries forvg_mldsa_rej_ntt_poly4could not cross a row:Â[r, s]is now entrye = ℓr + s, at polynomial20 + e(pA l r s). Verification samples the kℓ entries as key generation and signing do:kℓ/4groups of four (aGrp), where each seed's index bytes aree mod ℓande / ℓ;kℓ mod 4entries one at a time (aOne).As a result:
The working space of
vg_mldsa_rej_ntt_poly4stays at polynomial20 + 8k, which is afterÂfor every ℓ, so the scratch layout is otherwise unchanged.Proofs (untrusted)
StageAandCTSamplenow count sampled entries by number:Done ℓ e r' c' := ℓr' + c' < e, withrc_eqrecovering(r', c')frome.aGrp_ok/aGrp_trcover entries4g … 4g + 3, andaOne_ok/aOne_trcover entrye.StageC,CorrectandCTComputeonly pass ℓ topA.Instrsfollows the newsamples.There are no TCB or Spec changes.
Performance
Instructions per verification (callgrind: 20 verifications, minus key generation and one signature; base is #537's head):
VG_CPU_FEATURES=none)Checks run
lake buildand the emittercheck_lean_imports,check_lean_speed,check_vectors,check_arch_gates,check_variants,check_mcdtcargo fmt --checkandcargo clippy --all-targets -D warningscargo test --releasewith Wycheproof, both on the default path and withVG_CPU_FEATURES=none --features cpu-features-env🤖 Generated with Claude Code
https://claude.ai/code/session_01Ddof3szoTi7HB8iCsM2MCr
Generated by Claude Code