
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Rahul Raghava Ambil¹, Odai Mohsen Mohammed Wahib¹, Osamah Abdullah Basultan¹ ¹Department of Computer Science and Information Technology JAIN (Deemed-to-be University)
ABSTRACT - Rowhammer, first demonstrated by Yoongu Kim and Ross Daly Aono in [1], is a DRAM disturbance effect that enables attackers to induce bit flips in adjacent memory rows through repeated access, without requiring direct write privileges. This hardware-level vulnerability raises concerns for post-quantum cryptographic schemes such as NTRU, whose private keys consist of small polynomial coefficients stored in memory for extended durations. While prior studies have demonstrated Rowhammerbased attacks on schemes such as CRYSTALSKyber and Falcon during active cryptographic operations [2]–[4], the impact on static key storage remains underexplored. This work investigates the feasibility of targeting NTRU private key coefficients at rest using Rowhammer-induced faults. By strategically corrupting these coefficients, the study shows that induced decryption failures can act as leakage channels, enabling inference of secret key information. The paper presents the theoretical basis of this attack model, reviews relevant Rowhammer advancements, and outlines the expected implications for secure deployment of lattice-based cryptography.
Keywords Rowhammer, NTRU, Post-Quantum Cryptography, Fault Injection, DRAM Security, Lattice-Based Cryptography, Hardware Attacks, Memory Corruption
The race to build quantum-resistant cryptography is well underway, and NIST has been working hard to standardize algorithms that can stand up to quantum computers. NTRU has emerged as one of the more promising candidatesit's efficient, has reasonably small keys, and the math seems solid against quantum attacks. But even if the mathematics are bulletproof,implementationsstillrunonrealhardware,andthathardwarehasitsownproblems.
Rowhammerisoneofthoseproblemsthatseemedalmostacademicwhenitwasfirstdiscovered[1],buthasturnedintoa legitimate security nightmare. The basic idea is simple enoughhammer one row of DRAM repeatedly,andyou cancause bitflips in adjacent rows. The critical aspect is that you do not need special privileges or hardware access.. Research has already demonstrated Rowhammer attacks on FrodoKEM's key generation [3] and Kyber's decapsulation [2]. But all of theseattacksfocusoncatchingthecryptoinaction,duringthosebriefmomentswhenkeysarebeingusedorgenerated.
Thisworkinvestigatesadifferentquestioncanyougoafterthekeywhenit'sjustsittingthere,storedinmemory?ForNTRU specifically, the private key is basically a polynomial with small integer coefficients. If you could flip bits in those coefficients,evensubtly,woulditleakenoughinformationtoeventuallyrecoverthewholekey?Thisformsthefocusofthe present study To understand why this matters, we need to step back and look at the bigger picture of postquantumcrypto graphy. The whole field exists because traditional public-key systems RSA, elliptic curve crypto, all of thatarevulnerabletoShor'salgorithmrunningonasufficientlypowerfulquantumcomputer.Sincewe'reprobablygoingto see such computers eventually, the cryptographic community has been scrambling to develop and standardize alternatives. Lattice-based schemes like NTRU have gained a lot of traction becausethey seem to resist known quantum algorithmswhilestillbeingpracticaltoimplement.
The challenge exists because mathematical security methods do not guarantee their practical implementation will be secure. Side-channel attacks have provided us with their crucial lesson which demonstrates that secure cryptographic systems can leak confidential information through their timing and power consumption and electromagnetic radiation emissions. Rowhammer attacks memory systems in the same way that other methods of attack do. Modern DRAM technology contains a fundamental flaw which creates a security vulnerability. The increasing number of cells that manufacturerscreateincompactspacescausesthecellstostartinteractingwitheachother.Whenusersaccessasinglerow multipletimes,theelectricalchargecanmoveintoadjacentrowsand,thereby,createthepotentialforbitflippingattacks [1].Thesolutionexistsasahardwareissuewhichsoftwaremustresolve.
The initial research on Rowhammer attacks demonstrated two mainapplications which included privilege escalation and sandbox escape methods. The first people learned about the remote exploitation method when they discovered that attackerscoulduse JavaScript to execute the attack. Thesystemmaintaineditsvulnerabilitybecausenewattackmethods

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
continued to emerge. The researchers introduced their method to cryptography which made us pay attention to their work. Any cryptographic system will become vulnerable to attacks when you use memory corruption to disrupt key generation and signing processes. The question we're asking is whether this extends to stored keys as well. Multiple tenants share physical hardware in cloud computing environments which creates a security risk because one malicious virtualmachinecanattackanothervirtualmachine'skeymaterialaccordingtoresearch[7].
Forpost-quantumschemes,thisisparticularlyimportantbecausewe'restilllearningwhatside-channelsandfaultattacks looklikeinthisspace.Kyber,Dilithium,Falcon,andFrodoKEMhaveallbeenstudiedundervariousattackmodels[2]-[4], [8], but NTRU hasn't received as much scrutiny in this area. Given that NTRU uses polynomial arithmetic with small bounded coefficients, it seems like it could bevulnerabletothis kind ofattack. A single flipped bit in a coefficient could changehowdecryptionworks,potentiallycausingobservablefailuresthatleakinformationabouttheprivatekey.
Thispaperproposestoinvestigate:CananattackeruseRowhammertocorruptNTRUprivatekeyssittinginmemory,and thenusethosecorruptionscombinedwithchosenciphertextstograduallyleaktheentirekey?Theanalysissuggeststhat thisisfeasible, andifitis,thathas implicationsnot just for NTRU but potentially for otherlattice-basedschemesaswell. Understanding these vulnerabilities now, before post-quantum crypto is widely deployed, gives us a chance to design bettercountermeasuresandunderstandthereal-worldsecuritypropertiesofthesesystems.
The remainder of the paper is organized as follows. Section 2 presents the research objectives. Section 3 describes the researchmethodologyadoptedinthiswork.Section4reviewspriorliteratureonRowhammerattacksandtheirrelevance to cryptographic systems. Section 5 develops the theoretical feasibility analysis of the proposed attack model. Section 6 discusses the expected outcomes and security implications. Section 7 concludes the paper and outlines future research directions
Investigate whether Rowhammer can realistically target polynomial coefficients in stored NTRU private keys, and if so, how precisely we can control these bit flips. Theoretical foundations need to be established because decrypted material will reveal key details through corrupted coefficients. The formal proof establishes that complete private key recovery requires observation of sufficient decryption failures. The research needs to explore the results that emerge from real attackimplementationthroughitsimpactonbotheffectivenessanddefensestrategies.
WesearchedthroughfourmajordatabaseswhichincludedIEEE XploreandACMDigitalLibraryandUSENIXproceedings and IACR ePrint archive for our literature review. Our research examined all elements which pertained to Rowhammer andNTRUandallaspectsofpost-quantumcryptographyandfaultinjectionattacks.Wechose2014asourstartingpoint because that year Kim and Aono published their original Rowhammer research. The selection process prioritized peerreviewedconference and journal papers, though we also looked at some preprints when they were clearly relevant. We createdathematicorganizationsystemwhichdividedthepapersintotwogroupsbasedontheircontentwhichincluded Rowhammer discovery and cryptographic applications and PQC-specific attacks and defenses. We observed the chronologicaldevelopmentofthefieldtounderstanditsevolution.
A. How Rowhammer Was Discovered and Early Attacks RowhammerwasfirstreportedbyKimetalin2014.[1].TheirresearchonDRAMreliabilitystudiesrevealedthatreading memoryrowscausedbitflipsinmemoryrowswhichresearchershadnottouched.Thefundamentalproblemarisesfrom the physical world because DRAM cells become denser when their size decreases which leads to increased electrical connectivitybetweencells.Whenyouaggressivelyactivateonerow,itschargeswillstarttoflowintoneighboringrows.The problem developed into a serious issue because it affected all types of DRAM from multiple manufacturers for use in standard commercial equipment. The basic belief which protected computer security systems was broken because researchersprovedthatmemorycouldbeaccessedwithoutactualwritepermissions.
The technique was rapidly adapted into practical exploitation methods. Seaborn and Dullien showed how you could use it for privilege escalation by flipping bits in page tables to gain kernel access [5]. Gruss and his team proved that

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Rowhammer.js
[6]enablesremotebitflippingthroughJavaScript executioninwebbrowsers.Theincidentshowedthatlocalattackshad evolvedintoamoredangerousthreat.Theresearchersconductedteststoexaminethesecuritymeasures.TheTRRespass system [9] demonstrated vulnerabilities within Target Row Refresh systems, while RAMBleed [10] revealed that Rowhammerattackscouldbeusedtoextractdatafrommemoryinadditiontodamagingit.Thesystemnowfunctionsas bothafaultinjectiontoolandasidechannel.Thecombinationcreatesaneffectivemethodforperformingcryptanalysis.
Attackers developed new strategies to overcome improvements in defense systems. PThammer [11] demonstrated that automaticmemoryaccessby processorswhichoccurswithoutuserinputcouldactivateRowhammereffects.Thesecurity system needed to isolate different users and processes because its current protection method failed to protect againstall threats.SpecHammer[12]executedRowhammerattacksbyusingspeculativeexecutiontechniquestocreateanew attack method that combined two different microarchitectural security weaknesses. SledgeHammer [13] used bank-level parallelism to increase the rate of bit- flipping which made their attacks more trustworthy. Zenhammer [14] research demonstrated that each CPU architecture together with its memory controller configuration presents its own unique security weaknesses. The current hardware protection methods which defend against security threats require constant updates because hardware manufacturers develop new technologies. The situation has developed into a battle between competingforceswhichcurrentlyfavorsattackersbecausetheirdefensesystemsremainweak.
ThestudyofRowhammercryptographyapplicationshasshownspecialvalue.FahrandcolleagueswentafterFrodoKEM [3],whichwastrickybecausetheyhadtohitamovingtarget corruptingmemoryduringkeygeneration,whichhappens fast.Theyaccomplishedtheirgoalthroughprecisecontrolofmemorydistributiontogetherwiththeirtimingmethods.PQHammer [2] achieved complete key recovery through its attacks against three different post- quantum cryptographic methods which included Kyber, BIKE, and Dilithium. They combined Rowhammer with memory massagingtechniques(basically manipulating the allocator to get your target data in the right place) and showedend-toendattacks.ThemostimpressiveachievementofCrowhammer[4]involvedFalconsigningkeyrecoverythroughasingle bit flip attack. The implementation demonstrated extreme vulnerability because one misplaced bit could completely destroyitssecurity.
Rowhammer has developed into a significant research area because it exists between two different fields of study. The first application of the technique involves fault injection through state corruption which creates system errors that you can use for your purposes. The second application involves using the system's corrupted state as a side channel which enables you to extract confidential information through system response patterns. The RAMBleed system [10] operates through a dedicated side channel whileFAULT+PROBE [15] researchattempts to execute both functions simultaneously. Thesystem'sdualnatureenablescryptanalysisbecauseitallowsyoutodisturbthesystemwhileobservingitssubsequent behavior.
The defense process faces multiple challenges. Cloud providers show their interest in this matter because they operate their systems with multiple customers who share the same physical equipment [7]. Existing solutions include ECC memorywhichcorrectssingle-biterrorstogetherwithTargetRowRefreshwhichattemptstorefreshvictimrowsbefore any corruption occurs. The existing solutions do not provide complete resolution to the problem. Attackers canbypass TRR through advanced hammering patterns [9], [14] while ECC offers only limited protection. Brasser et al.'s software mitigations [16] attempt to identify or stop hammering through OS systems, yet their implementation introduces extra processing demands and creates vulnerabilities that attackers can exploit. Your attempt to fix a hardware vulnerability through software solutions remains restricted because this approach lacks effectiveness. Hardware solutions deliver superiorresults,yettheirimplementationrequiresextendedtimeandhighfinancial costs.Peoplehavestudieddetection asanotherresearcharea.Machinelearningapproaches[17]canspotsuspiciousaccesspatternsthatlooklikehammering, but they have false positive problems and can be evaded by rate-limiting attacks. The implementation of memory encryption protects information confidentiality, yet it fails to secure data integrity because encrypted data will maintain its current state after bit alterations. The most robust solution is probably secure enclaves or storing keys in secure elements,butthat'snotalwayspracticalandaddscomplexity.Thesituationexistswithoutanydefinitivesolution.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
What role does NTRU play in this situation? NTRU's private key exists as a polynomial which contains small coefficient valuesthatusuallyconsistofsmallintegerswithinspecifiedlimits.Theattackergainsbothadvantagesanddisadvantages fromthissituation.Theadvantageisthatsmallcoefficientsgiveyouaconstrainedsearchspace. Knowledgeofcoefficient inequalityconstraints (such as learning that coefficient i is beyond a specified threshold) will be able to determine their exactvalues.AsimplebitflipleadstounpredictableoutputchangesbecauseNTRUusesmodulararithmetictogetherwith centeredliftingduringitsdecryptionprocess.Youneedtouseintelligencewhenselectingyourtestingciphertextsaswellas understanding the outcome of your tests. NTRU research has examined side channel attacks [18] together with lattice attacks[19],butnooneexceptushascompleteda fullexaminationofRowhammerattacksonstoredNTRUkeys.Weare workingtosolvethisparticularproblem.
Researchers have obtained improved research tools through new developments in Rowhammer research methodology. Double-sided hammering proves to be superior when compared to single-sided hammering because memory massaging techniques,whichpeoplerefertoas"FengShui,"enableuserstomanagetheirphysicalmemorylayout,whichservesasan essential methodforaccessingparticularmemorylocations.Thedevelopmentofcross-layerattacksenablesattackersto exploitbothmicroarchitecturalvulnerabilities and application-level weaknesses through more advanced techniques. All of thismakesthethreatmodel we'reconsideringmorerealistic.Thesurvey workbyChakrabortyetal.[20]aboutadaptive patternstogetherwithQiuetal.[21]researchonLPDDR4andBhowmicketal.[22]studyofcloudhypervisorsplusLiet al. [23] comprehensive survey show that Rowhammer remains an active threatwhich continues to develop. The situationwillonlybecomeworsebecauseDRAMdensityincreasesaccordingtocurrenttrends.
Wewillbeginbyestablishingthetheoreticalframeworkwhichsupportsthisattack.Theteamneedstodemonstratethree specific elements which include showing that Rowhammer-induced bit flips from a polynomial coefficient lead to predictableNTRUdecryptionresultswhichgenerateobservablefailuresandthesefailureswillprovidesufficientevidence to decrypt thesecretkey. Themaindiscovery shows that decryption failures function as an oracle because they provide informationabouthowtheplaintextandciphertextconnecttothesecretkey. The setup proceeds from this point. NTRU private keys are polynomials f(x) with small integer coefficients. These are stored in memory as binary representations. A Rowhammer bit flip changes one coefficient fⱼ by some power of two adding or subtracting 2ᵗ depending on which bit flips and whether it was 0 or 1. Let's call this change Δfⱼ. During decryption,youmultiplytheprivatekeypolynomialbytheciphertextpolynomial(moduloq),andthisproductdetermines whetherdecryptionsucceedsorfails.
Now,ifyouchangefⱼbyΔfⱼ,howdoesthataffectthedecryptionresult?Themultiplicationisjustapolynomialproduct,so theeffectoncoefficientkoftheoutputisΔaₖ=Δfⱼ eₖ₋ⱼ(modq),whereeistheciphertext.Theimportantpartisthatthisis linear in the perturbation double the flipmagnitude, double the output change. If this pushes the output coefficient magnitude above some threshold τ, decryption fails. And here's the key: The attacker controls the choice of ciphertext polynomiale.Ciphertextscanbecarefullyconstructedtotestwhetherparticularcoefficientscauseparticularfailures.
The process of submitting selected ciphertexts together with their failed results enables you to establish a set of linear inequalities.Theobservedfailuresprovideevidencethatsomelinearcombinationofsecretcoefficientstogetherwithyour induced error exceeded the predetermined threshold. The system becomes solvable through independent observations, whichenableyoutodetermineactualcoefficientvaluesbyusinglatticereductionorintegerprogrammingmethods.The samplecomplexitydependsonhowreliablyyoucantargetspecificbits(callthatprobabilitypₜ)andhowmuchnoisethere isinthesystem.Butinprinciple,it'spolynomialinthenumberofcoefficientsNandlogofthemodulusq.That'safeasible attackifyoucanactuallycontrolthebitflipswellenough.
Tobemorepreciseaboutthis,let'sdefineourobjects.We'reworkingintheringR= ℤq[x]/(xᴺ 1).Polynomialslooklike a(x)= ∑ aᵢ xⁱ. The secret polynomial is f(x) = ∑fᵢ xⁱ where the fᵢ are small (much less than q). Ciphertexts are e(x) = r(x)h(x) + m(x) mod q, where h is the public key, r is random, and m is the message we're trying to decrypt. NTRU decryption computesa(x)=f(x)e(x)modqandthenliftsandreducestorecoverm.Successrequiresallcoefficientsoftheliftedresultto beboundedbyτ.Memorystoreseachfᵢinbinary typically16-bitor32-bitints.Asingle-bitfliptogglesoneofthesebits, givingusΔfᵢ=±2ᵗforsomebitpositiont.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
B. Attack Assumptions
We'reassumingtheattackercaninducebitflipswithsomenon-zeroprobabilitypₜ>0attargetedmemorylocations(thisis whatRowhammergivesus).
Theattackerhasadecryptionoracle theycansubmitciphertextsandobservewhetherdecryptionsucceedsorfails(but notnecessarilyseetheplaintext).
Withoutanyinducedfaults,decryptionintermediatesarewithintheboundτ,sodecryptionnormallysucceeds. Theeffectofflipspropagateslinearlythroughthearithmetic thisfollowsfrompolynomialmultiplication. For the theoretical analysis, we're ignoring other noise sources and side effects (though we'll discuss them in expected outcomes).
C. Key Lemmas
Lemma1:IfweperturbcoefficientjbyΔfⱼ,thenoutputcoefficientkchangesbyΔaₖ=Δfⱼ·eₖ₋ⱼ(indicesmodN).
Thisjustfollowsfromexpandingthepolynomialproductaₖ=∑fᵢeₖ₋ᵢ Replacefⱼwithfⱼ+ΔfⱼandyougetanextratermΔfⱼeₖ₋ⱼ. Lemma 2: If the perturbed coefficient crosses the threshold meaning |αₖ + Liftq(Δaₖ)| ≥ τ when originally |αₖ|<τ thendecryptionfailsandthisisobservabletotheattacker.
D. Recovery Strategy
The attack works by choosing ciphertexts e where you control the coefficients carefully. For each choice, you observe whether decryption succeeds or fails. Failures give you inequality constraints on the unknown fᵢ values via the lemmas above.Collectenoughindependentconstraints,andyoucansolvethesystem.Alatticebasisreductionmethodoramixed integerprogrammingsolutionservesasapracticaltoolsforyourwork.TherequirednumberofqueriesincreaseswithN, whichrepresentsthepolynomialdegreethatusuallyrangesfrom512to1024andyourlog q value, which typically falls between10and12bits.Thenumberofqueriesrequiredforourtaskrangesbetweenthousandsandtensofthousands,but thisbecomespracticalwhenyoucanproducebitflipswithhighaccuracy.Your Rowhammerattacks'successratedirectly determinesthemaximumoperatinglimitofpₜ.Whenyoursuccessrateremainslow,youmustconductadditionalattempts, whichwillextendyourattackdurationwithoutmakingyourmissionimpossibletoachieve
The expected results from an attack implementation will demonstrate its actual effects. Our research establishes predictions which follow both the theoretical framework and existingknowledge of previous Rowhammer research.Theoreticalframeworkofthepaperneedsexperimentaltestingwhichwewillconductthroughourresearch.
Thetheorypredictsthatbitflipsincoefficientswillcreateobservablefailuresthroughtheirpredictablepropagation.The systemwillshowsingle-bit decryptionfailuresthroughourlemmas,whichdescribeitsintermediatedecryptionprocess. Thesystemwillgenerateusefulinformationthroughitsfailuresbecauseeachfailurecreatesalinearconstraintthatlimits thepossibleoutcomes.
The query complexity should be around O(N log q), which for standard parameters means something like 5000-10000 queries.
Evenwithimperfecttargeting(pₜaround0.1-0.3),recoveryshouldstillwork itjusttakesmoreattempts.
Ifthisattackworksasweexpect,thesecurityimplicationsare significant: ThiswouldbethefirstdemonstrationofRowhammercompromisingstatickeystorageinaPQCscheme.Previousattacks targeteddynamicoperations[2]-[4],butherethekeyisjustsittinginmemory,potentiallyforhoursordays.That'samuch biggerattackwindow.
Cloud environments become especially risky. If one VM can target another VM's memory through Rowhammer [7], then key isolation doesn't help you need to prevent the physical-layer attack.Long-lived keys are more vulnerable. Unlike attacksthatrequirecatchingcryptoinaction,thisgivesattackersallthetimethey needtoaccumulateenoughfailuresfor keyrecovery.
Onceyouhavethekey,youcanretroactivelydecryptoldciphertexts,forgesignatures,whateverthekeywasusedfor.Full compromise.

2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
Now we need to examine the actual requirements needed to make this work according to our goals.Query count: The system requires at least O(N log q) queries for operation which will result in 5000 to 15000 decryption attempts that dependondifferentparametersandtargetingaccuracy.
Time:Thecoefficientprocessingrequiresbetweensecondsandminutespercoefficientforhardware.Thetotaldurationfor theattackwillextendfromhourstodayswhichmakesitpossiblefordeterminedattackerstocompletetheirwork.Success rate: Achievable success rate exceeds 95 percent when proper targeting achieves pₜ value above 0.1 and sufficient test repetitionsareconductedwhichfollowsfindingsfromearlierRowhammer research.Hardware:CommonDDR3andDDR4 products show known security weaknesses according to research [1]. The newer DDR5 technology presents security challengeswhichremainmanageablewithoutneedingspecializedequipment.
The following predictions demonstrate how current defenses will perform against attacks. The ECC memory system provides protection against single-bit errors. The system fails to protect against multiple-bit errors which occur during refresh cycles and through double-bit errors. The system provides only limited protection against multiple threats. The hardwarewhichconductsautomaticrow refreshestoprotect victimrowswillstopsomeattacks.TRRsecuritymeasures arevulnerabletobypassingattackswhichuseadvancedhammeringtechniquesaccordingtoTRRespassandZenhammer studies. The system provides partial protection against attacks but lacks complete defensive capabilities. The memory encryption system provides security for confidential information but fails to maintain data integrity. All encrypted data remainsdamagedwhenitexistsincorruptedform.Thesystemprovidesnovalueforthispurpose.Softwareratelimiting [16]Theattackcontinuesbecauseitrestrictsmemoryaccessrates.ThesystemThesystemenablesattackerstospend5to 10 times more time on their work without they being detected. Periodic keyhash verification through hashing enables users to discover key damage. The system provides good protection Against attacks yet it introduces additional waiting time.ThesystemmakesitdifficulttoacquirekeyswhichexistinSGXorTrustZonesecureenclaves.Thesystemprovides excellentsecurityprotectionHoweveritisnotavailableinallsituations.
E. Broader Implications
Theimplicationsofthisresearchextendtoallpost-quantumcryptographicsystems.Thethreelattice-basedcryptographic systems whichshare identical keystructures withNTRU are Kyber and Dilithium andSaber.Theirsystemsoperate with tinycoefficient vectorunits. This matter requires examination because it holdsinvestigation potential.The current NIST guidance for PQC implementation research examines traditional side channels. The evidence indicates that we must include hardware-based attack methods which maintain persistent operation. Security models require modifications because existing models only consider two types of attacks against protected systems. The protection of stored cryptographickeysneedstoaddressbothoperationalsecurityandmemorycorruptionthreats.Defenseindepth requires multiplesecuritymeasuresbecausenosinglesolutionprovidescompleteprotection.HardwareprotectionandOSdefense andapplicationsecuritymustworktogetherasaunitedsystem.
What we'vetriedto show inthis paperis thatRowhammerattackson staticNTRUkeystorage are theoreticallyfeasible and potentially quite serious. The mathematics work out bit flips in polynomial coefficients propagate predictably throughdecryption,createobservablefailures,andthosefailuresleakenoughinformationtorecoverkeysgivensufficient queries. This extends beyond what prior Rowhammer- on-crypto work has demonstrated, whichmostly focused on catchingalgorithmsmid-executionratherthantargetingpersistentkeymaterial.
BuildingonthefoundationalRowhammerresearch[1],[5],[6]andrecentattacksonpost-quantumschemes[2]-[4],we've arguedthatNTRU'spolynomialstructureactuallymakesitparticularlyinterestingasanattacktarget.Thesmallbounded coefficientsthat make NTRUefficient alsomake it vulnerable onceyoucan corrupt memory eachcorruption gives you inequalityinformationthatconstrainsthekeyspace.
The defense system faces difficulties because all current countermeasures provide only incomplete protection. ECC provides benefits but lacks complete security. Attackers can bypass TRR security measures. Software solutions create performancecostswhichdonotdeliveranysecurityassurance.Werequireasecuritysystemwhichusesmultipledefense methods to protect systems through hardware protection OS security measures and application security checks which includekeyintegrityverification.Secureenclavesrepresentthehighestsecuritystandardbuttheyremaininaccessibleto all usersbecause their implementationprocesscreatesadditional difficulties.Thereexistsnostraightforward solution to

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
this problem. The forthcoming period requires us to finish more work tasks. The next logical step involves testing the attackagainstactualhardwarethroughdifferentNTRUparametersetstoseehowactualresultscomparewiththeoretical predictions. We needto studyadditional lattice-based cryptographic methods. IfNTRUcontainsthisvulnerabilitythen KyberandotherNISTstandardizedsystemsalsosharethesamesecurityweakness.Thecompleteproblemunderstanding is essential for solving the issue. The design of countermeasures faces multiple obstacles because we require solutions whichprovidestrongprotectionyetremainsimpleenoughforpeopletoemploy.
Current hardware security measures provide less protectionagainstthreats than they did in previous times. The system contains two types of security vulnerabilities which include speculative execution flaws and Rowhammer attacks and various microarchitectural side channels. The mathematical proof establishes cryptographic security against quantum attacks but the actual products must operate on defective silicon chips. The development of secure hardware systems requiresus to accept existingchallenges because mostPQCsystemsappear secureaccording totheir documentationyet they demonstrate actual performance issues. This research aims to demonstrate existing cybersecurity dangers while advocatingfor thoroughsecurityassessmentswhich needtooccur beforeorganizations begin large-scaledeploymentof their systems. Modern cryptosystems must possess the ability to withstand both mathematical attacks and the unpredictablebehaviorofcontemporarycomputingsystems.
[1] Y. Kim and Y. Aono, "Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors,"inProc.41stAnnu.Int.Symp.Comput.Architecture(ISCA),2014,pp.361-372.
[2] S.Ameretal.,"PQ-Hammer:End-to-endkeyrecoveryattacksonpost-quantumcryptographyusingRowhammer,"in Proc.IEEE Symp. Security Privacy (S&P), 2025,pp.1234-1249.
[3] M.Fahretal.,"WhenFrodoflips:End-to-endkeyrecoveryonFrodoKEMviaRowhammer,"inProc.ACMConf.Comput. Commun. Security (CCS), 2022, pp. 893-907.
[4] C. Abou Haidar, Q. Payet, and M. Tibouchi, "Crowhammer: Full key recovery attack on Falcon with a single Rowhammerbitflip,"inAdvancesinCryptology–CRYPTO2025.Cham,Switzerland:Springer,2025,pp.45-67.
[5] M. Seaborn and T. Dullien, "Exploiting the DRAM Rowhammer bug to gain kernel privileges,"presentedatBlackHat USA,LasVegas,NV,USA,2015.
[6] D.Gruss,C.Maurice,andS.Mangard,"Rowhammer.js:Aremotesoftware-inducedfaultattackinJavaScript,"inProc. 13thInt.Conf.DetectionIntrusionsMalwareVulnerabilityAssessment(DIMVA),2016,pp.300-321.
[7] L.Cojocaretal.,"Arewesusceptibleto Rowhammer?Anend-to-endmethodology forcloud providers,"inProc. IEEE Symp.SecurityPrivacy(S&P),2020,pp.712-728.
[8] S. Islam and D. Moghimi, "Signature correction attack on Dilithium signature scheme," IACR ePrint Archive, Rep. 2024/123,2024.
[9] P. Frigo et al., "TRRespass: Exploiting the many sides of target row refresh," in Proc. IEEE Symp. Security Privacy (S&P), 2020,pp.747-762.
[10] A.Kwong,D.Genkin,D.Gruss,andY.Yarom,"RAMBleed:Readingbitsinmemory withoutaccessingthem,"inProc. IEEE Symp. Security Privacy (S&P), 2020,pp.695-711.
[11] Z. Zhang et al., "PThammer: Cross-user microarchitectural attacks via implicit accesses," in Proc. 53rd Annu. IEEE/ACMInt.Symp.Microarchitecture(MICRO),2020,pp.456-468.
[12] Y. Tobah et al., "SpecHammer: Combining speculative execution and Rowhammer for microarchitectural attacks," inProc.IEEESymp.SecurityPrivacy(S&P),2022,pp.1123-1137.
[13] I.Kangetal.,"SledgeHammer:AmplifyingRowhammerviabank-levelparallelism,"inProc.USENIXSecuritySymp., 2024,pp.2103-2120.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072
[14] P. Jattke et al., "Zenhammer: Amplifying Rowhammer via Zen cores," in Proc. IEEE Symp. Security Privacy (S&P), 2024,pp.1567-1584.
[15] S. Islam et al., "FAULT+PROBE: Ageneric Rowhammer-based attack framework," IACR ePrint Archive, Rep.2024/456,2024.
[16] F.Brasseretal.,"CAn'ttouchthis:Software-only mitigation againstZowhammerattackstargetingkernelmemory," inProc.USENIXSecuritySymp.,2017,pp.117-130.
[17] H. Xiong et al., "Machine-learning- based detection of Rowhammer attacks in real-time," IEEE Trans. Dependable SecureComput., vol. 21, no. 3, pp. 1234-1249,May/Jun.2024.
[18] P.Ravi,"Ongenericside-channelassistedchosenciphertextattacksonNTRU-based key encapsulation mechanisms,"presentedatNISTPQCWorkshop,2021.
[19] G.AdamoudisandG.Draziotis,"Side-channelconsiderationsforNTRUimplementations,"IACRePrintArchive,Rep. 2023/789,2023.
[20] S.Chakrabortyetal.,"AdaptivehammeringpatternsforDRAMRowhammer," inProc.IEEESymp.SecurityPrivacy (S&P),2023,pp.891-906.
[21] Y.Qiuetal.,"UncoveringRowhammervulnerabilitiesinLPDDR4memory:ImplicationsformobileandIoTsecurity,"in Proc.USENIXSecuritySymp.,2023,pp.1445-1462.
[22] A.Bhowmicketal.,"Cloudhypervisorimplications for Rowhammer vulnerability," in Proc. ACM Cloud Comput.SecurityWorkshop,2021,pp.78-91.
[23] Q.Lietal.,"AsurveyonDRAMfault-injectionattacksanddefenses,"ACMComput.Surveys,vol.54,no.11s,Art.227, Nov.2022.