A class of cryptanalytic methods that gives the analyst pairs of plaintext as well as ciphertext, and attempts to derive the key. As Lars Knudsen's Journal of Craptology calls it: "Faking the ability to break a cipher when one already knows the answer." Compare chosen plaintext attack.

Linear cryptanalysis is an example of an attack that falls into this category.