发表机构
CNRS, Université Paris Cité, IRIF(法国国家科学研究中心,巴黎西岱大学,IRIF)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对碰撞寻找与元素区分性问题,在标签对称算法类内证明了最优的查询-空间权衡下界,并开发了空间敏感的压缩预言机技术。
AI 中文摘要
碰撞寻找需要多少内存才能保持量子加速?对于均匀随机函数 $f:[N]\to [N]$,BHT 算法使用 $O(N^{1/3})$ 次查询和一个包含 $O(N^{1/3})$ 个输入-输出对的可量子访问的经典表来找到碰撞,而对数空间 Grover 搜索则使用 $O(\sqrt N)$ 次查询。确定这两个极端之间的最优查询-空间权衡仍然是一个重大的开放问题。我们在标签对称算法类别内解决了这个问题,这类算法将函数 $f$ 的输出标签视为可互换的。我们证明,此类算法若进行 $T$ 次查询、使用 $S$ 个量子比特,并以常数概率在均匀随机函数 $f:[M]\to [N]$ 中找到碰撞,则满足 $$T=\Omega(N^{1/3}) \qquad\text{和}\qquad T^2S=\Omega(N\log N).$$ 对于 $M=N$ 的情形,这些界由 BHT 算法的空间高效实现所匹配。作为我们权衡的结果,任何用于 $f: [n] \to [n^2]$ 上元素区分性搜索版本的标签对称算法必须满足 $$T=\Omega(n^{2/3}) \qquad\text{和}\qquad T^2S=\Omega(n^2\log n),$$ 这与 Ambainis 的量子游走相匹配。因此,这两个权衡在标签对称算法类别内都是最优的。为了证明这些结果,我们开发了压缩预言机技术的空间敏感版本。压缩预言机在数据库的演化叠加中记录算法所学到的信息。利用标签对称性和表示论,我们证明使用 $S$ 个量子比特的算法只能有效保留关于 $O(S/\log N)$ 个无碰撞数据库条目的信息。将此估计代入压缩预言机技术,即可得出所陈述的权衡。
英文摘要
How much memory is needed to retain the quantum speedup for collision finding? For a uniformly random function $f:[N]\to [N]$, the BHT algorithm finds a collision using $O(N^{1/3})$ queries and a quantumly accessible classical table containing $O(N^{1/3})$ input-output pairs, whereas a logarithmic-space Grover search uses $O(\sqrt N)$ queries. Determining the optimal query-space tradeoff between these extremes remains a major open problem. We resolve this equation within the class of label-symmetric algorithms, which treat the function $f$'s output labels as interchangeable. We prove that such algorithm that makes $T$ queries, uses $S$ qubits, and finds a collision in a uniformly random function $f:[M]\to [N]$ with constant probability satisfies $$T=Ω(N^{1/3}) \qquad\text{and}\qquad T^2S=Ω(N\log N).$$ For the setting where $M=N$, these bounds are matched by a space-efficient implementation of the BHT algorithm. As a consequence of our tradeoff, any label-symmetric algorithm for the search version of Element Distinctness on $f: [n] \to [n^2]$ must satisfy $$T=Ω(n^{2/3}) \qquad\text{and}\qquad T^2S=Ω(n^2\log n),$$ matching Ambainis's quantum walk. Thus, both tradeoffs are optimal within the class of label-symmetric algorithms. To prove these results, we develop a space-sensitive version of the compressed oracle technique. The compressed oracle records the information learned by the algorithm in an evolving superposition of databases. Using label symmetry and representation theory, we show that an algorithm using $S$ qubits can effectively retain information about only $O(S/\log N)$ collision-free database entries. Substituting this estimate into the compressed oracle technique yields the stated tradeoffs.
CommentsAddition of an example of an application to algorithms with intermediate measurements, together with minor edits