{
 "check": "tightness_numeric",
 "verdict": "real",
 "bound": "Adv_envelope <= Adv_CCA + Adv_EUF + Adv_CPAeph + Adv_sepPRF; Adv_CCA <= 2*q_H*sqrt(Adv_MLWE + delta) + q_dec*delta",
 "inputs": {
  "kem_alg": "ML-KEM-768",
  "kem_quantum_bits": 164,
  "kem_classical_bits": 181,
  "kem_anchor_source": "CRYSTALS-Kyber round-3 spec (EuroS&P'18, arXiv:1801.03017)",
  "sig_alg": "ML-DSA-65",
  "sig_anchor_quantum_bits": null,
  "delta_correctness_log2": -164,
  "delta_source": "FIPS 203 Table 2 (ML-KEM-768 delta = 2^-164)",
  "q_H_log2": 64,
  "q_dec_log2": 40,
  "sep_prf_assumption_log2": -128
 },
 "terms": {
  "Adv_CCA_log2": -16.5,
  "Adv_CCA_o2h_term_log2": -16.5,
  "Adv_CCA_qdec_term_log2": -124,
  "Adv_CPAeph_log2": -164,
  "Adv_sepPRF_log2": -128,
  "Adv_EUF": "symbolic"
 },
 "envelope_excluding_sig_log2": -16.5,
 "dominant_term": "Adv_CCA",
 "q_H_log2_at_which_bound_reaches_1": 80.5,
 "honest_scope": "The KEM-side envelope is ~2^-16.5 at 2^64 hash queries, not ~2^-164: the QROM FO loss that tightness_bounds_ci.json's tightness_gap concedes, now as a number. The signature term is symbolic because no core-SVP anchor for ML-DSA-65 is in the estate's artifacts; adding it can only make the envelope larger. A tighter FO analysis (e.g. explicit-rejection / measure-rewinding bounds) would move this number and is not claimed here."
}
