American tech company Anthropic reported that its AI system Claude helped discover an attack on HAWK, an experimental digital signature system used to verify the authenticity of digital information and designed to remain secure against attacks from future quantum computers. HAWK was developed by an international team including Léo Ducas. Ducas is part of the Cryptology group at Centrum Wiskunde & Informatica (CWI) and is also professor of Mathematical cryptology at Leiden University.
‘We wanted to explore a completely new direction in lattice-based cryptography,’ Ducas explains (see box). ‘HAWK succeeded in attracting attention to that idea and getting people to test it seriously.’
The story has a strong Dutch connection. Ducas and Wessel van Woerden (who did his PhD at CWI and in Leiden) helped develop HAWK, while later research into possible attacks involved Leiden and CWI cryptographers Daan van Gent and Ludo Pulles.
AI found the missing piece
Trying to break digital signature schemes is a normal part of cryptographic research. The more attacks a scheme survives, the more confidence researchers have in its security. Van Gent had already made progress towards an attack on HAWK together with Pulles. Looking back, Van Gent believes there was only one modest step missing. ‘That final step has now been found with AI assistance.’
Not a crisis for cryptography
The attack ultimately led the team to withdraw HAWK from the international standardization process. According to Ducas, HAWK was not completely broken: the attack showed that HAWK’s specific design was less secure than hoped, not that the underlying mathematics had failed. ‘There were three or four attacks by other researchers prior to the current one that came very close,’ says Ducas. ‘This time, an attack succeeded.’ While HAWK can still be used in a secure way, doing so makes it not efficient enough to be competitive.
The researchers intentionally pushed the design towards maximum efficiency, knowing that doing so involved risk. ‘We went one step too far in comparison with the now standardized methods,’ Ducas says.
What AI can – and cannot – do
Both Ducas and Van Gent are impressed by Claude’s contribution but caution against exaggerated claims about AI replacing scientists.
Ducas believes the attack built on ideas researchers such as Van Gent were already exploring. ‘The final step is often easier because you know where you want to go,’ he says. ‘The harder part is finding the right direction in the first place.’ This is illustrated by the fact that a human reached similar results as the AI model later that week.
The broader perspective of knowledge is especially important in mathematics, says Ducas. ‘Mathematics is built on centuries of accumulated knowledge. To remain usable, it requires constant maintenance: classification, unification, comparison.’ While AI can learn from papers and books, and now even produce new knowledge, it has not yet inherited that critical research culture of doing it diligently. That is something we should be careful not to lose, says Ducas. The issue is also raised in the recently published Leiden Declaration on Artificial Intelligence and Mathematics.
Back to the drawing board
Despite HAWK's withdrawal, the researchers remain optimistic. The attack exposed a weakness in one experimental design, but not in the broader research direction or current NIST standardized post-quantum cryptography. ‘We need to do more research,’ says Ducas. ‘Now that the pressure of standardization is gone, we can take the time to understand these ideas properly.’ And in a field that helps keep the internet secure, every lesson learned helps shape the next generation of encryption.