SearcharxivSearch

arXiv subjects

Oded Regev

Publications and source records attributed to Oded Regev.

At least 19 recordsLinked to original sources

On Lattices, Learning with Errors, Random Linear Codes, and Cryptography

Our main result is a reduction from worst-case lattice problems such as GapSVP and SIVP to a certain learning problem. This learning problem is a natural extension of the `learning from parity with error' problem to higher moduli. It can also be viewed as the problem of decoding from a random linear code. This, we believe, gives a strong indication that these problems are hard. Our reduction, however, is quantum. Hence, an efficient solution to the learning problem implies a quantum algorithm for GapSVP and SIVP. A main open question is whether this reduction can be made classical (i.e., non-quantum). We also present a (classical) public-key cryptosystem whose security is based on the hardness of the learning problem. By the main result, its security is also based on the worst-case quantum hardness of GapSVP and SIVP. The new cryptosystem is much more efficient than previous lattice-based cryptosystems: the public key is of size $\tilde{O}(n^2)$ and encrypting a message increases its size by a factor of $\tilde{O}(n)$ (in previous cryptosystems these values are $\tilde{O}(n^4)$ and $\tilde{O}(n^2)$, respectively). In fact, under the assumption that all parties share a random bit string of length $\tilde{O}(n^2)$, the size of the public key can be reduced to $\tilde{O}(n)$.

cs.CR

An Efficient Quantum Factoring Algorithm

We show that $n$-bit integers can be factorized by independently running a quantum circuit with $\tilde{O}(n^{3/2})$ gates for $\sqrt{n}+4$ times, and then using polynomial-time classical post-processing. The correctness of the algorithm relies on a number-theoretic heuristic assumption reminiscent of those used in subexponential classical factorization algorithms. It is currently not clear if the algorithm can lead to improved physical implementations in practice.

quant-ph

Bounds on the density of smooth lattice coverings

Let $K$ be a convex body in $\mathbb{R}^n$, let $L$ be a lattice with covolume one, and let $η>0$. We say that $K$ and $L$ form an $η$-smooth cover if each point $x \in \mathbb{R}^n$ is covered by $(1 \pm η) vol(K)$ translates of $K$ by $L$. We prove that for any positive $σ, η$, asymptotically as $n \to \infty$, for any $K$ of volume $n^{3+σ}$, one can find a lattice $L$ for which $L, K$ form an $η$-smooth cover. Moreover, this property is satisfied with high probability for a lattice chosen randomly, according to the Haar-Siegel measure on the space of lattices. Similar results hold for random construction A lattices, albeit with a worse power law, provided the ratio between the covering and packing radii of $\mathbb{Z}^n$ with respect to $K$ is at most polynomial in $n$. Our proofs rely on a recent breakthrough by Dhar and Dvir on the discrete Kakeya problem.

math.NT

A simple proof of a reverse Minkowski theorem for integral lattices

We prove that for any integral lattice $\mathcal{L} \subset \mathbb{R}^n$ (that is, a lattice $\mathcal{L}$ such that the inner product $\langle \mathbf{y}_1,\mathbf{y}_2 \rangle$ is an integer for all $\mathbf{y}_1, \mathbf{y}_2 \in \mathcal{L}$) and any positive integer $k$, \[ |\{ \mathbf{y} \in \mathcal{L} \ : \ \|\mathbf{y}\|^2 = k\}| \leq 2 \binom{n+2k-2}{2k-1} \; , \] giving a nearly tight reverse Minkowski theorem for integral lattices.

math.MG

An integer parallelotope with small surface area

We prove that for any $n\in \mathbb{N}$ there is a convex body $K\subseteq \mathbb{R}^n$ whose surface area is at most $n^{\frac12+o(1)}$, yet the translates of $K$ by the integer lattice $\mathbb{Z}^n$ tile $\mathbb{R}^n$.

math.MG

A Tight Reverse Minkowski Inequality for the Epstein Zeta Function

We prove that if $\mathcal{L} \subset \mathbb{R}^n$ is a lattice such that $\det(\mathcal{L}') \geq 1$ for all sublattices $\mathcal{L}' \subseteq \mathcal{L}$, then \[ \sum_{\substack{\mathbf{y}\in\mathcal{L}\\\mathbf{y}\neq\mathbf0}} (\|\mathbf{y}\|^2+q)^{-s} \leq \sum_{\substack{\mathbf{z} \in \mathbb{Z}^n\\\mathbf{z}\neq\mathbf{0}}} (\|\mathbf{z}\|^2+q)^{-s} \] for all $s > n/2$ and all $0 \leq q \leq (2s-n)/(n+2)$, with equality if and only if $\mathcal{L}$ is isomorphic to $\mathbb{Z}^n$.

math.MG

A Reverse Minkowski Theorem

$ \newcommand{\R}{\mathbb{R}} \newcommand{\lat}{\mathcal{L}} $We prove a conjecture due to Dadush, showing that if $\lat \subset \R^n$ is a lattice such that $\det(\lat') \ge 1$ for all sublattices $\lat' \subseteq \lat$, then \[ \sum_{\vec y \in \lat} e^{-πt^2 \|\vec y\|^2} \le 3/2 \; , \] where $t := 10(\log n + 2)$. From this we derive bounds on the number of short lattice vectors, which can be viewed as a partial converse to Minkowski's celebrated first theorem. We also derive a bound on the covering radius.

math.MG

Near-Optimal and Explicit Bell Inequality Violations

Entangled quantum systems can exhibit correlations that cannot be simulated classically. For historical reasons such correlations are called "Bell inequality violations." We give two new two-player games with Bell inequality violations that are stronger, fully explicit, and arguably simpler than earlier work. The first game is based on the Hidden Matching problem of quantum communication complexity, introduced by Bar-Yossef, Jayram, and Kerenidis. This game can be won with probability 1 by a strategy using a maximally entangled state with local dimension $n$ (e.g., $\log n$ EPR-pairs), while we show that the winning probability of any classical strategy differs from ${1}/{2}$ by at most $O((\log n)/\sqrt{n})$. The second game is based on the integrality gap for Unique Games by Khot and Vishnoi and the quantum rounding procedure of Kempe, Regev, and Toner. Here $n$-dimensional entanglement allows the game to be won with probability $1/(\log n)^2$, while the best winning probability without entanglement is $1/n$. This near-linear ratio is almost optimal, both in terms of the local dimension of the entangled state, and in terms of the number of possible outputs of the two players.

quant-ph

Efficient Rounding for the Noncommutative Grothendieck Inequality

$ \newcommand{\cclass}[1]{\textsf{#1}} $The classical Grothendieck inequality has applications to the design of approximation algorithms for $\cclass{NP}$-hard optimization problems. We show that an algorithmic interpretation may also be given for a noncommutative generalization of the Grothendieck inequality due to Pisier and Haagerup. Our main result, an efficient rounding procedure for this inequality, leads to a polynomial-time constant-factor approximation algorithm for an optimization problem which generalizes the Cut Norm problem of Frieze and Kannan, and is shown here to have additional applications to robust principal component analysis and the orthogonal Procrustes problem.

cs.DS

Tight Hardness of the Non-commutative Grothendieck Problem

$\newcommand{\eps}{\varepsilon} $We prove that for any $\eps > 0$ it is $\textsf{NP}$-hard to approximate the non-commutative Grothendieck problem to within a factor $1/2 + \eps$, which matches the approximation ratio of the algorithm of Naor, Regev, and Vidick (STOC'13). Our proof uses an embedding of $\ell_2$ into the space of matrices endowed with the trace norm with the property that the image of standard basis vectors is longer than that of unit vectors with no large coordinates. We also observe that one can obtain a tight $\textsf{NP}$-hardness result for the commutative Little Grothendieck problem; previously, this was only known based on the Unique Games Conjecture (Khot and Naor, Mathematika 2009).

cs.CC

On the Gaussian surface area of spectrahedra

We show that for sufficiently large $n\geq 1$ and $d=C n^{3/4}$ for some universal constant $C>0$, a random spectrahedron with matrices drawn from Gaussian orthogonal ensemble has Gaussian surface area $Θ(n^{1/8})$ with high probability.

math.PR

Continuous LWE

We introduce a continuous analogue of the Learning with Errors (LWE) problem, which we name CLWE. We give a polynomial-time quantum reduction from worst-case lattice problems to CLWE, showing that CLWE enjoys similar hardness guarantees to those of LWE. Alternatively, our result can also be seen as opening new avenues of (quantum) attacks on lattice problems. Our work resolves an open problem regarding the computational complexity of learning mixtures of Gaussians without separability assumptions (Diakonikolas 2016, Moitra 2018). As an additional motivation, (a slight variant of) CLWE was considered in the context of robust machine learning (Diakonikolas et al.~FOCS 2017), where hardness in the statistical query (SQ) model was shown; our work addresses the open question regarding its computational hardness (Bubeck et al.~ICML 2019).

cs.CC

New bounds on the density of lattice coverings

We obtain new upper bounds on the minimal density of lattice coverings of Euclidean space by dilates of a convex body K. We also obtain bounds on the probability (with respect to the natural Haar-Siegel measure on the space of lattices) that a randomly chosen lattice L satisfies that L+K is all of space. As a step in the proof, we utilize and strengthen results on the discrete Kakeya problem.

math.NT

Nearly Optimal Embeddings of Flat Tori

We show that for any $n$-dimensional lattice $\mathcal{L} \subseteq \mathbb{R}^n$, the torus $\mathbb{R}^n/\mathcal{L}$ can be embedded into Hilbert space with $O(\sqrt{n\log n})$ distortion. This improves the previously best known upper bound of $O(n\sqrt{\log n})$ shown by Haviv and Regev (APPROX 2010) and approaches the lower bound of $Ω(\sqrt{n})$ due to Khot and Naor (FOCS 2005, Math. Annal. 2006).

math.MG

Concentration of Markov chains with bounded moments

Let $\{W_t\}_{t=1}^{\infty}$ be a finite state stationary Markov chain, and suppose that $f$ is a real-valued function on the state space. If $f$ is bounded, then Gillman's expander Chernoff bound (1993) provides concentration estimates for the random variable $f(W_1)+\cdots+f(W_n)$ that depend on the spectral gap of the Markov chain and the assumed bound on $f$. Here we obtain analogous inequalities assuming only that the $q$'th moment of $f$ is bounded for some $q \geq 2$. Our proof relies on reasoning that differs substantially from the proofs of Gillman's theorem that are available in the literature, and it generalizes to yield dimension-independent bounds for mappings $f$ that take values in an $L_p(μ)$ for some $p\ge 2$, thus answering (even in the Hilbertian special case $p=2$) a question of Kargin (2007).

math.PR

Bounds on Dimension Reduction in the Nuclear Norm

$ \newcommand{\schs}{\scriptstyle{\mathsf{S}}_1} $For all $n \ge 1$, we give an explicit construction of $m \times m$ matrices $A_1,\ldots,A_n$ with $m = 2^{\lfloor n/2 \rfloor}$ such that for any $d$ and $d \times d$ matrices $A'_1,\ldots,A'_n$ that satisfy \[ \|A'_i-A'_j\|_{\schs} \,\leq\, \|A_i-A_j\|_{\schs}\,\leq\, (1+δ) \|A'_i-A'_j\|_{\schs} \] for all $i,j\in\{1,\ldots,n\}$ and small enough $δ= O(n^{-c})$, where $c> 0$ is a universal constant, it must be the case that $d \ge 2^{\lfloor n/2\rfloor -1}$. This stands in contrast to the metric theory of commutative $\ell_p$ spaces, as it is known that for any $p\geq 1$, any $n$ points in $\ell_p$ embed exactly in $\ell_p^d$ for $d=n(n-1)/2$. Our proof is based on matrices derived from a representation of the Clifford algebra generated by $n$ anti-commuting Hermitian matrices that square to identity, and borrows ideas from the analysis of nonlocal games in quantum information theory.

math.MG

On the Hardness of Satisfiability with Bounded Occurrences in the Polynomial-Time Hierarchy

$ \newcommand{\eps}ε \newcommand{\NP}{\mathsf{NP}} \newcommand{\YES}{\mathsf{YES}} \newcommand{\NO}{\mathsf{NO}} \newcommand{\myminus}{\text{-}}\newcommand{\Bsat}{\mathsf{B}} \newcommand{\threesat}{\rm{3}\myminus\mathsf{SAT}} \newcommand{\gapthreesat}{\mathsf{\forall\exists}\myminus{\rm{3}}\myminus\mathsf{SAT}} $In 1991, Papadimitriou and Yannakakis gave a reduction implying the $\NP$-hardness of approximating the problem $\threesat$ with bounded occurrences. Their reduction is based on expander graphs. We present an analogue of this result for the second level of the polynomial-time hierarchy based on superconcentrator graphs. This resolves an open question of Ko and Lin (1995) and should be useful in deriving inapproximability results in the polynomial-time hierarchy. More precisely, we show that given an instance of $\gapthreesat$ in which every variable occurs at most $\Bsat$ times (for some absolute constant $\Bsat$), it is $Π_2$-hard to distinguish between the following two cases: $\YES$ instances, in which for any assignment to the universal variables there exists an assignment to the existential variables that satisfies all the clauses, and $\NO$ instances in which there exists an assignment to the universal variables such that any assignment to the existential variables satisfies at most a $1-\eps$ fraction of the clauses. We also generalize this result to any level of the polynomial-time hierarchy.

cs.CC

Tensor-based Hardness of the Shortest Vector Problem to within Almost Polynomial Factors

$ \newcommand{\SVP}{\mathsf{SVP}} \newcommand{\NP}{\mathsf{NP}} \newcommand{\RTIME}{\mathsf{RTIME}} \newcommand{\RSUBEXP}{\mathsf{RSUBEXP}} \newcommand{\eps}ε \newcommand{\poly}{\mathop{\mathrm{poly}}} $We show that unless $\NP \subseteq \RTIME (2^{\poly(\log{n})})$, there is no polynomial-time algorithm approximating the Shortest Vector Problem ($\SVP$) on $n$-dimensional lattices in the $\ell_p$ norm ($1 \leq p< \infty$) to within a factor of $2^{(\log{n})^{1-\eps}}$ for any $\eps > 0$. This improves the previous best factor of $2^{(\log{n})^{1/2-\eps}}$ under the same complexity assumption due to Khot (J. ACM, 2005). Under the stronger assumption $\NP \nsubseteq \RSUBEXP$, we obtain a hardness factor of $n^{c/\log\log{n}}$ for some $c> 0$. Our proof starts with Khot's $\SVP$ instances that are hard to approximate to within some constant. To boost the hardness factor we simply apply the standard tensor product of lattices. The main novelty is in the analysis, where we show that the lattices of Khot behave nicely under tensorization. At the heart of the analysis is a certain matrix inequality which was first used in the context of lattices by de Shalit and Parzanchevski (2006).

cs.CC