the collision side of lattice hardness: given a random matrix over a module of polynomial rings, find a short nonzero vector it maps to zero. an attacker who forges a lattice signature or finds a hash collision has solved it β so its hardness prices unforgeability module-SIS is the signingβ¦