The attacker's toolkit — algorithms like LLL and BKZ that find short lattice vectors and set the security bar every lattice scheme is measured against.
Core Principles & Analysis
The Lenstra–Lenstra–Lovász algorithm of 1982 reduces lattice bases in polynomial time, but only approximately.
BKZ trades running time for quality; its required 'block size' is how lattice security levels are estimated.
Parameter sets for ML-KEM and ML-DSA are chosen so even quantum-accelerated BKZ falls short.