
BosonSampling and Random Circuit Sampling are important both as a theoretical tool for separating quantum and classical computation, and as an experimental means of demonstrating quantum speedups. Prior works have shown that average-case hardness of sampling follows from certain unproven conjectures about the hardness of computing output probabilities, such as the Permanent-of-Gaussians Conjecture (PGC), which states that e(-n log n-n-O(log n)) additive-error estimates to the output probability of most random BosonSampling experiments are #P-hard. Prior works have only shown weaker average-case hardness results that do not imply sampling hardness. Proving these conjectures has become a central question in quantum complexity. In this work, we show that e(-n log n-n-O(n delta)) additive-error estimates to output probabilities of most random BosonSampling experiments are #P-hard for any delta > 0, exponentially improving on prior work. In the process, we circumvent all known barrier results for proving PGC. The remaining hurdle to prove PGC is now "merely" to show that the O(n(delta)) in the exponent can be improved to O(log n). We also obtain an analogous result for Random Circuit Sampling. We then show, for the first time, a hardness of average-case classical sampling result for BosonSampling, under an anticoncentration conjecture. Specifically, we prove the impossibility of multiplicative-error sampling from random BosonSampling experiments with probability 1 - 2(-(O) over tilde (N1/3)) for input size N, unless the Polynomial Hierarchy collapses. This exponentially improves upon the state-of-the-art. To do this, we introduce new proof techniques which tolerate exponential loss in the worstto-average-case reduction. This opens the possibility to show the hardness of average-case sampling without ever proving PGC.
The problem of studying k-wise correlations in product spaces, i.e., correlations of the form E-(x1,E- ... ,E- xk)similar to mu circle times n[f(1)(x(1)) ... f(x(k))] where f(i) : Sigma(n)(i) -> C are all 1-bounded functions and mu is a distribution over Sigma(1) x ... x Sigma(k), appears in many different contexts throughout discrete mathematics. Examples include additive combinatorics, extremal combinatorics, hardness of approximation and probability. The goal in an inverse theorem is to characterize the type of functions f(1), ... , f(k) that achieve non-trivial correlations, under minimal assumptions on the distribution mu. We give new inverse theorems for k-wise correlations for all k >= 3. For k = 3, our inverse theorem works for any distribution mu which is pairwise-connected, which is essentially the minimal assumption required for a nontrivial inverse theorem to hold. For k > 3, our inverse theorem applies for distributions mu satisfying the stronger condition of not having any Abelian embeddings. This resolves a conjecture from [Bhangale-Khot-Minzer, STOC 2022]. We give applications of our inverse theorems to additive combinatorics, hardness of approximation, and property testing. First, we show that there exists c > 0 such that any set A subset of {0, 1, 2}(n) with density at least Omega((log log log log n)(-c)) must contain a combinatorial line, i.e., x, y, z is an element of {0, 1, 2}(n), not all equal, such that x(i) = y(i) = z(i) or (x(i), y(i), z(i)) = (0, 1, 2) for all i = 1, 2, ... , n. In other words, we give "reasonable bounds" for the density Hales-Jewett theorem of length 3. This involves combining our inverse theorems with several additional insights, motivated by Shkredov's proof of the corners theorem and Polymath's combinatorial proof of the density Hales-Jewett theorem. Second, we show how to construct a dictatorship vs quasi-random test that has perfect completeness and soundness s + epsilon from integrality gap instances with similar parameters, provided that its local distributions have no Abelian embeddings. Third, we analyze the direct-sum tester of [Dinur-Golubev, RANDOM 2019] in the low-soundness regime.
Suppose that an untrusted analyst claims that it ran a distribution tester and determined that an unknown distribution has a certain property. Can the untrusted analyst prove that its assertion is correct to a verifier that does not have sufficient samples and computational resources to run the tester on its own? In this work, we are interested in proofs that can be generated very efficiently, with minimal overhead over running the distribution tester. In particular, since the distribution tester is sublinear (in the domain size), at the very least we also want the sample complexity for generating the proof to be sublinear. Do natural properties that have sublinear testers admit such proof systems?Our main result answers this question negatively for several natural properties. For these properties, if the verifier’s sample complexity is non-trivial (smaller than just running the tester on its own), then the (honest) prover must draw a linear number of samples. We show this result for the problem of testing whether the distribution is uniform over its support, for specifying the distribution’s k-collision probability (or its Lk norm), and for other natural properties.Our results shed light on a recent line of work showing that if we allow the prover to draw a quasi-linear number of samples, then many distribution properties have proof-systems with very efficient verification. Our negative results imply that the super-linear sample complexity of the prover in those proof-systems is inherent.
The Borsuk-Ulam theorem states that every continuous odd function f : S-n -> R-n must have a zero, i.e., an x is an element of S-n such that f(x) = 0. While such a zero is guaranteed to exist, finding it is known to be computationally intractable: it is PPA-complete already for n = 2. In this work, we show that the problem remains just as hard even if the function is mapping from a higher to a lower dimensional space. Namely, we prove that it is PPA-complete to find a zero of f : S-k -> R-n for any constants k >= n >= 2. This result has very appealing consequences for other flagship PPA-complete problems such as Tucker, Consensus Halving, and Ham Sandwich. For example, in the Consensus Halving problem from fair division, we show that finding a partition that satisfies three agents with monotone valuations is PPA-complete, even if we allow any arbitrarily large constant number of cuts.
Trevisan and Vadhan (FOCS 2000) introduced the notion of (seedless) extractors for samplable distributions. They showed that under a very strong complexity theoretic hardness assumption (specifically, that there exists a problem in E = DTIME(2(O(n))) that cannot be computed by size 2(Omega(n)) circuits that have an oracle to Sigma(P)(6)) there are extractors for samplable distributions with large min-entropy of k = (1 - gamma) center dot n, for some small constant gamma > 0. Recently, Ball, Shaltiel and Silbak (STOC 2025) were able to reduce the min-entropy threshold to k = n(1 - gamma). Ball et al., point out that their approach does not work for k < root n (and this holds even for stronger hardness assumptions, in which 6 is replaced with any other constant). In this paper, we show how to further reduce the min-entropy threshold to k = n(0.34) < root n under the same hardness assumption used by Trevisan and Vadhan. More generally, for every positive integer i >= 2, and every alpha > 1/i, we construct an extractor for samplable distributions with min-entropy k = n(alpha), under a hardness assumption in which 6 is replaced with i+3 (the aforementioned result is a obtained for i = 3). We also provide a multiplicative version of our extractors (under a stronger hardness assumption) addressing an open problem of Ball et al. Our work builds on the approach of Ball et al., who reduced the task of constructing extractors for samplable distributions with min-entropy k, to the task of constructing errorless condensers for samplable distributions with min-entropy k. Our main technical contribution is a new construction of errorless condensers for samplable distributions with k = n(alpha) under the hardness assumption stated above, improving upon the minentropy threshold achieved in Ball et al. (which cannot achieve k < root n). Our insight is that the technique used by Ball et al. to reduce the task of constructing extractors to that of constructing errorless condensers, can itself be used to construct errorless condensers for polynomially small min-entropy when combined with "win-win analysis" approaches that are inspired by some early work on seeded extractors and dispersers. In order to do this, we adapt these approaches from the information theoretic scenario of seeded extractors and dispersers to the computational scenario of errorless condensers for samplable distributions.
We study the structure of the set of priority-neutral matchings. These matchings, introduced by [Ren22], generalize stable matchings by allowing for priority violations in a principled way that enables Paretoimprovements to stable matchings. Known results show that the set of priority-neutral matchings is a lattice, suggesting that these matchings may enjoy the same tractable theoretical structure as stable matchings. In this paper, we characterize priority-neutral matching lattices, and show that their structure is considerably more intricate than that of stable matching lattices. To begin, we show priority-neutral lattices are not distributive, an important property that characterizes stable lattices and is satisfied by many other lattice structures considered in matching theory and algorithm design. Then, in our main result, we show that priority-neutral lattices are in fact characterized by a more-involved property which we term being a “movement lattice,” which allows for significant departures from the order theoretic properties of distributive (and hence stable) lattices. While our results show that priority-neutrality is more intricate than stability, they also establish tractable properties. Indeed, as a corollary of our main result, we obtain the first known polynomialtime algorithm for checking whether a given matching is priority-neutral.
Whether the Minimum Circuit Size Problem (MCSP) is NP-hard or not is a long-standing open question. Indeed, Levin delayed the publication of his fundamental work on the theory of NP-completeness because he hoped to prove NP-completeness of MCSP. In this paper, we present the first plausible assumptions under which MCSP is NP-hard. Specifically, we prove that MCSP is NP-hard under deterministic quasi-polynomial-time nonadaptive reductions, assuming: subexponentially-secure non-interactive witness indistinguishable proof systems for SAT exist, coNP requires subexponential-size non-deterministic circuits, and P-NP /poly requires circuits of size Omega(2(n) /n). This is arguably the first evidence that MCSP is not in coNP, which indicates that there is no short proof that witnesses the hardness of a function.
We present the first polynomial-time approximation scheme (PTAS) for the stochastic knapsack problem that does not relax the knapsack's capacity. Given n items with known arbitrary independent size distributions and fixed profits, an accuracy parameter epsilon is an element of(0, 1), and an overflow probability bound alpha, our algorithm computes a set of items with profit at least (1-epsilon) times optimal, while ensuring the probability of exceeding the capacity is at most 4 root alpha + epsilon. Prior to our work, no PTAS was known without either allowing a (1+ epsilon) capacity expansion or restricting to special distribution classes (such as Poisson or Gaussian). A key tool in our algorithm is an anti-concentration result that allows us to handle "low-profit" items by adapting a known PTAS result for the case when we are allowed to expand knapsack capacity by a (1+ epsilon) factor. We then show that we are able to convert this solution into another solution with a similar profit which strictly obeys the knapsack capacity, but requires that we relax the overflow probability to a 4 root alpha + epsilon factor. In the special case where the item sizes are scaled Bernoulli random variables (which have support on 0 and exactly one other value), we extend our approach to obtain an improved overflow probability guarantee of a + epsilon. We make this improvement by exploiting the fact that these random variables are defined by only two parameters (the probability of being non-zero and the non-zero value in the support), which allows us to avoid some of the complexity and overhead of our algorithm for arbitrary distributions.
We study the robust local testability of tensor products of two Algebraic-Geometry (AG) codes. In particular, we prove that constant rate AG codes are robust locally testable. This significantly generalizes the seminal result of Polishchuk-Spielman (1994), which proved robust local testability of Reed-Solomon codes. We establish an algebraic-geometric framework that enables us to geometrically interpret codewords in tensor products of AG codes. Thereby, we use tools from intersection theory of algebraic surfaces to prove a divisibility criterion for AG codes, that generalizes the bivariate divisibility result of Polishchuk-Spielman. Over the years, robust local testability of tensor products has played a key role in the development of classical locally testable codes (LTCs) as well as quantum Low Density Parity Check (qLDPC) codes and quantum Locally Testable Codes (qLTCs). To the best of our knowledge, after Reed-Solomon codes, our result provides the first explicit family of robustly locally testable codes with constant rate and linear dual-distance. Moreover, our result, when combined with Golowich-Guruswami (2024), yields new explicit families of good quantum CSS codes of length N which are locally testable with locality O(root N) and constant soundness.
Is a two-party function, possibly with randomized output, securely computable? We provide a finite procedure to answer this question, thereby settling a foundational, three-decade-old open problem in secure computation and information complexity.Beaver-Chor-Kushilevitz [11], [22], [8] answered this question for deterministic output functions. Basu et al. [3] recently gave a geometric characterization of randomized functions securely computable with bounded communication complexity. Randomized functions can have arbitrarily high communication complexity, even for fixed input-output sets [5]. Without an upper bound on the communication complexity, the decidability of the question of whether a given two-party function with randomized output is securely computable was a formidable challenge.We reduce answering this question to proving specific lamination hulls are semi-algebraic. Lamination hulls are an infinite union of recursively defined sets independently motivated by the hydrodynamics literature. We connect this technical objective to solving a system of linear inequalities over convex sets in high dimensions, where inequalities represent the natural containment relation. We present a Gaussian elimination-inspired algorithm to compute the smallest simultaneous solutions to such systems. After that, using these solutions, we prove that our lamination hulls are semi-algebraic.Our technical solution introduces a novel set operator called positive geometric join. In our application context, it characterizes algebraically well-behaved sets that generalize polytopes, which we call hemihedra. The positive geometric join operator and hemihedral sets should interest the broader mathematics and computer science community. These advancements should help further information complexity investigations more broadly via the recently established connection by Basu et al. [3].
We prove a non-linear Edelstein-Kelly theorem for polynomials of constant degree, fully settling a stronger form of Conjecture 30 in Gupta (2014), and generalizing the main result of Peleg and Shpilka (STOC 2021) from quadratic polynomials to polynomials of any constant degree. As a consequence of our result, we obtain constant rank bounds for depth-4 circuits with top fanin 3 and constant bottom fan-in which compute the zero polynomial. This settles a stronger form of Conjecture 1 in Gupta (2014) when k=3, for any constant degree bound; additionally this also makes progress on Conjecture 28 in Beecken, Mittmann, and Saxena (Information & Computation, 2013). Our rank bounds, when combined with Theorem 2 in Beecken, Mittmann, and Saxena (Information & Computation, 2013) yield the first deterministic, polynomial time PIT algorithm for these circuits.
Clustering is a basic task in data analysis and machine learning, and the optimization of clustering objectives are well-studied optimization problems; amongst these, the k-Means objective is arguably the most well known. Given a collection of points in a metric space, the goal is to partition them into k clusters, each with an associated center, so as to minimize the sum of squared distances of points to their cluster centers. In this paper, we present a polynomial-time 3 + 2 root 2 + epsilon < 5.83-approximation algorithm for k-Means in general metrics. This substantially improves on the current-best (9 + epsilon)-approximation in [Ahmadian, Norouzi-Fard, Svensson, Ward - FOCS'17, SICOMP'20], and even slightly improves on the 5.92-approximation in [Cohen-Addad, Esfandiari, Mirrokni, Narayanan - STOC'22] for the Euclidean special case. A natural approach for k-Means is to leverage Lagrangian Multiplier Preserving (LMP) approximations for the facility location problem. The previous best results for k-Means build upon an adaptation of an LMP 3-approximation for facility location with metric connection costs in [Jain, Vazirani - J.ACM'01] based on a primal-dual method, rather than on the improved LMP greedy 2-approximation for the same problem in [Jain, Mahdian, Markakis, Saberi, Vazirani - J.ACM'03]. The barrier to using the improved LMP algorithm was that no adaptation of this algorithm and its analysis to the case of squared metric connection costs was known (since squared distances violate triangle inequality). Our main contribution is overcoming this barrier by providing such an adaptation. This new LMP approximation algorithm is then combined with the framework recently introduced in [Cohen-Addad, Grandoni, Lee, Schwiegelshohn, Svensson - STOC'25] for the related (metric) k-Median problem.
We introduce the notion of metric embeddings into a similarity measure over R-+(m), such as the weighted Jaccard coefficient. We develop average embeddings into such similarity measures for a number of metric spaces, with (appropriately defined) distortion that is smaller than the best possible or known distortion of embedding into l(1) or l(2) spaces (biLipschitz or average). We complement our embeddings with a new algorithm for Approximate Nearest Neighbor Search (ANNS) that leverages such an embedding in a black box fashion. Combining these results, we obtain new efficient algorithms for ANNS under the following two classic metrics, achieving an exponential improvement to longstanding prior work: center dot Edit distance over length-k strings: poly(log k) approximation; center dot l(p) over R-d, for p > 2: O(log p) approximation (known to be asymptotically optimal in relevant models of computation).
We study the inherent barriers to constructing non-adaptively sound succinct non-interactive arguments (SNARGs) for NP with a CRS whose length is sublinear in the witness length. Our results cover both the standard SNARGs and SNARGs with an additional updatable feature (i.e. incrementally verifiable computation for NP). For updatable SNARGs, we show a black-box separation from falsifiable assumptions for uniform polynomial-time reductions, assuming sub-exponential hardness of learning with error. For general SNARGs, we show a black-box separation from falsifiable assumptions for non-uniform polynomial-time reductions that only make one query to the adversary, assuming the existence of sub-exponentially secure super-bit generators. We observe that all known SNARG constructions from polynomial hardness of standard assumptions have 1-query soundness reductions. Thus, our result complements existing constructions. Previously, the seminal work [Gentry-Wichs, STOC'11] showed a black-box separation of SNARGs from falsifiable assumptions in the adaptive soundness setting. We explore whether any barriers exist in the non-adaptive setting. To obtain our result, we derive a simulation lemma for unbounded polynomial-length auxiliary inputs assuming super-bit generators.
Homomorphic message authentication codes (HMACs) allow users to authenticate data using a shared secret key, while supporting computation over authenticated data. Given data (m(1),..., m(n)) and their tags (sigma(1),..., sigma(n)), anyone can evaluate a circuit C on the data and tags to produce a succinct tag authenticating the output C(m(1),..., m(n)). Importantly, tags remain succinct-of size polynomial in the security parameter lambda-regardless of the size of C. This work introduces an enhanced variant of HMACs called algebraic HMAC (aHMAC), in which all tags (input and output) take the form (Delta) over right arrow center dot m + (K) over right arrow, as in standard information-theoretic MACs. We construct an aHMAC from group-based assumptions, including variants of the DDH and DCR assumptions, and use it to obtain group-based constructions of several cryptographic primitives: center dot Succinct CDS for circuits. For any P : [N](k) -> [N] represented by circuit, we obtain a Conditional Disclosure of Secrets protocol with poly(lambda, k, logN) communication. center dot Succinct PSM for simple programs. For any P : [N](k) -> [N] represented by a truth-table or shallow branching program, we obtain a Private Simultaneous Messages protocol or a garbling scheme with poly(lambda, k, logN) communication. center dot Constrained PRFs for circuits. We obtain the first groupbased constrained pseudorandom functions for general circuits, improving over a previous construction for NC1 circuits.
In their seminal paper, Lubotzky, Phillips and Sarnak (LPS) defined the notion of regular Ramanujan graphs and gave a strongly-explicit construction of infinite families of ($p+1$)regular Ramanujan Cayley graphs, for infinitely many primes p. In this paper we extend the work of LPS and its successors to bigraphs (biregular bipartite graphs): we investigate the combinatorial properties of various generalizations of the notion of Ramanujan graphs, define a notion of Cayley bigraphs, and give strongly-explicit constructions of infinite families of ($p^{3}+1, p+1$)-regular Ramanujan Cayley bigraphs, for infinitely many primes p. In addition, we present a pseudorandomness characterization of Ramanujan bigraphs, and a more general notion of biexpanders. We also show that the graphs we construct exhibit the cutoff phenomenon with bounded window size for the mixing time of non-backtracking random walks, and present some other applications, such as optimal unitary gates in quantum computation.
A central line of inquiry in the study of indistinguishability obfuscation (IO) is to minimize the size of the obfuscation. Today we know how to obfuscate programs represented as Turing machines, where the size of the obfuscation grows only with the input size and not with the machine's running time. Jain and Jin [FOCS 2022] showed how to remove the dependency on the input size for functionally equivalent programs where equivalence can be proven in Cook's theory PV. In this work we investigate the limits of the pursuit of succinct obfuscation. We consider the task of obfuscating a program with a large description, most of which can be made public while some portion of the description is secret. We put forth a new notion of fully succinct IO where the size of obfuscated program only grows with the size of the program's secret part and not with the public part or with the input size. Starting with input-succinct IO for PV-equivalent machines, which is known from super-polynomially hard IO for circuits and LWE, we construct fully succinct IO for the same class of programs. We refer to such an obfuscation as fully succinct pv-IO. Next, we show how to bootstrap our fully succinct pv-IO to achieve full IO security. Our bootstrapping theorems are based on succinct cryptographic primitives with seemingly weaker functionality: either succinct witness encryption or SNARGs for NP with unique proofs. We also require that the correctness of these primitives can be proven in theory PV. We show that these assumptions are sufficient and necessary. We demonstrate several applications of fully succinct IO and pv-IO: (i) We give the first IO construction where the size of the obfuscated program is less than twice the size of the original program for a large class of useful programs. (ii) We show how to avoid padding the program before obfuscating it - a step often necessitated by security analysis - by replacing the padding with a public random string. (iii) We give the first construction of succinct computational secret sharing for access structures represented by polynomial-size monotone circuits where the share size does not grow with the size of the access structure.
Can the n-party broadcast channel, where any symbol sent by one party is received by all, be made resilient to noise with low overhead? Namely, is it possible to construct interactive error-correcting codes that convert any protocol designed for the noiseless broadcast channel into one that works over the noisy broadcast channel and is not much longer than the original protocol? [12, STOC 2018] showed that such interactive codes with constant multiplicative overhead are possible under the assumption that the noiseless protocol being simulated is non-adaptive, meaning that it is restricted to have a pre-determined order of turns. Their noise resilient simulating protocols, however, require adaptivity, where each party can decide whether or not to broadcast given all the information available to them, including their input and received transcript. The question of whether such a simulation is possible for general, potentially adaptive, noiseless protocols was left open. We resolve this question negatively, proving that any interactive code that converts adaptive noiseless broadcast protocols into adaptive broadcast protocols resilient to stochastic errors must incur a multiplicative overhead of Omega(log n/log log n), which is nearly tight.
Program obfuscation aims to hide the inner workings of a program while preserving its functionality. In the quantum setting, recent works have obtained obfuscation schemes for specialized classes of quantum circuits. For instance, Bartusek, Brakerski, and Vaikuntanathan (STOC 2024) constructed a quantum state obfuscation scheme, which supports the obfuscation of quantum programs represented as quantum states for pseudo-deterministic quantum programs with classical inputs and outputs in the classical oracle model. In this work, we improve upon existing results by constructing the first quantum state obfuscation scheme for unitary (or approximately unitary) quantum programs supporting quantum inputs and outputs in the classical oracle model. At the core of our obfuscation scheme are two novel ingredients: a functional quantum authentication scheme that allows key holders to learn specific functions of the authenticated quantum state with simulationbased security, and a compiler that represents an arbitrary quantum circuit as a projective linear-plus-measurement quantum program described by a sequence of non-adaptive Clifford gates interleaved with adaptive and compatible measurements.