arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

$\mathbb{F}_3^n$-子集和的指数级量子加速?或,二进制误差LWE的严格经典算法

Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE

Robin Kothari, Tony Metger, Ryan O'Donnell, Noah Shutty, Kewen Wu

arXiv 2609.40321首次发表:更新:

发表机构

Google Quantum AI; Courant Institute of Mathematical Sciences and Department of Physics, New York University; Computer Science Department, Carnegie Mellon University; Department of Computing and Mathematical Sciences, California Institute of Technology(谷歌量子人工智能; 纽约大学柯朗数学科学研究所和物理系; 卡内基梅隆大学计算机科学系; 加州理工学院计算与数学科学系)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出量子算法,在$\mathbb{F}_3^n$子集和问题上用更少输入向量实现指数级加速,并建立样本-时间权衡,核心是二进制误差LWE的确定性经典算法。

AI 中文摘要

我们研究$\mathbb{F}_3^n$上的向量子集和问题:给定来自$\mathbb{F}_3^n$的$m$个随机向量,找到一个非空子集使其和为零;$m$越小,找到这样的子集就越困难。Chen、Liu和Zhandry(EUROCRYPT'22)引入了一种高效的量子算法,当$m\approx n^2/2$时能解决此问题,而朴素的经典算法需要指数时间。随后,Kothari、O'Donnell和Wu(STOC'2026)给出了一种高效的经典算法,仅需$m \approx n^2/3$个向量,从而消除了在该参数范围内指数级量子优势的可能性。利用Chen、Liu和Zhandry的框架,我们给出了需要更少输入向量的量子算法,重新点燃了指数级量子加速的可能性:对于任意固定的$\epsilon>0$,我们的量子算法在$m=\epsilon\cdot n^2$个向量时能在多项式时间内解决$\mathbb{F}_3$-子集和问题。更一般地,我们建立了完整的样本-时间权衡,在指数和多项式运行时间之间插值。主要成分是二进制误差学习问题(LWE)的确定性经典算法,这具有独立的密码学意义。为此,我们严格建立了先前代数启发式所预测的样本-时间权衡。对于更大域上的向量子集和问题,我们也显著改进了Kothari、O'Donnell和Wu(STOC'2026)中的经典算法。

英文摘要

We study vector subset sum over $\mathbb{F}_3^n$: given $m$ random vectors from $\mathbb{F}_3^n$, find a nonempty subset that sums to zero; the smaller $m$, the more difficult it is to find such a subset. Chen, Liu, and Zhandry (EUROCRYPT'22) introduced an efficient quantum algorithm that solves this problem when $m\approx n^2/2$, where a naive classical algorithm would require exponential time. Subsequently, Kothari, O'Donnell, and Wu (STOC'2026) gave an efficient classical algorithm that only requires $m \approx n^2/3$ vectors, thus removing the hope for an exponential quantum advantage in this parameter regime. Using the framework of Chen, Liu, and Zhandry, we give quantum algorithms that require much fewer input vectors, renewing the possibility of an exponential quantum speedup: for any fixed $ε>0$, our quantum algorithm solves $\mathbb{F}_3$-subset sum in polynomial time with $m=ε\cdot n^2$ vectors. More generally, we establish a full sample--time tradeoff that interpolates between exponential and polynomial runtime. The main ingredient is a deterministic classical algorithm for the binary-error Learning-with-Errors problem, which is of independent cryptographic interest. For this, we rigorously establish a sample--time tradeoff that was predicted by earlier algebraic heuristics. For vector subset sums over larger fields, we also significantly improve classical algorithms in Kothari, O'Donnell, and Wu (STOC'2026).

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑