signature algorithm, one of the third round finalists of the national institute of standards and
technology (NIST) standardization project. We attack the number-theoretic transform (NTT)
in the signing procedure and key generation of to obtain a secret key. When targeting the
signing procedure, we can recover both secret key vectors and. This enables forgery of
signatures. However, only the secret key vector can be recovered when targeting the key …