Distribution-free future-ciphertext coverage under arbitrary encryption distributions

Determine whether a span learned from independently sampled public states under an arbitrary, potentially highly non-uniform encryption-induced distribution can contain an independently generated future ciphertext with sufficiently high probability to enable linear-decomposition recovery, without requiring recovery of the entire algebraic span.

Background

The paper distinguishes its setting from earlier linear-decomposition attacks that use an explicitly constructed basis or assume sampling conditions sufficient to recover an entire algebraic span. Honest public-key encryption may instead induce an arbitrary and highly non-uniform distribution over public states, so rare directions can make full-span recovery require exponentially many samples even when most future ciphertexts lie in a much smaller subspace.

The unresolved issue is whether public samples alone can provide attack-relevant coverage of independently generated future ciphertexts under such arbitrary distributions. The paper subsequently formalizes this question through the future-sample failure probability of the span generated by sampled public states and develops distribution-free guarantees for that quantity.

References

It leaves open, however, a different question. Honest encryption does not generally provide a uniform sampler over an entire algebraic span. Instead, it induces some possibly highly non-uniform distribution 𝜇 over public states 𝑋𝜌 . Moreover, an attacker need not recover the entire span in order to break a future encryption, but only the span learned from public samples to contain an independently generated future target𝑋★ ∼ 𝜇.

— Beyond Explicit Generators: Distribution-Free Linear-Decomposition Attacks on Public-Key Encryption  (2608.20798 - Chen et al., 21 Aug 2026) in Section 1, subsection “From random spanning to future-ciphertext coverage” (p. 2)