
Let be an irreducible polynomial of degree . Let be a uniformly random polynomial, be a small error polynomial, and be a small secret polynomial. The pair is an MLWE pair.

Remarks on MLWE

Learning with Errors (LWE) is MLWE with . RLWE is MLWE with . CRYSTALS-Kyber, the only PKE/KEM among the NIST PQC round 1 winners, is an MLWE-based key encapsulation scheme.