Explorerβ€ΊComputer Scienceβ€ΊCybersecurity
Research PaperResearchia:202610.01013

Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE

Robin Kothari

Abstract

We study vector subset sum over $\mathbb{F}_3^n$: given $m$ random vectors from $\mathbb{F}_3^n$, find a nonempty subset that sums to zero; the smaller $m$, the more difficult it is to find such a subset. Chen, Liu, and Zhandry (EUROCRYPT'22) introduced an efficient quantum algorithm that solves this problem when $m\approx n^2/2$, where a naive classical algorithm would require exponential time. Subsequently, Kothari, O'Donnell, and Wu (STOC'2026) gave an efficient classical algorithm that only ...

Submitted: October 1, 2026Subjects: Cybersecurity; Computer Science

Description / Details

We study vector subset sum over F3n\mathbb{F}_3^n: given mm random vectors from F3n\mathbb{F}_3^n, find a nonempty subset that sums to zero; the smaller mm, the more difficult it is to find such a subset. Chen, Liu, and Zhandry (EUROCRYPT'22) introduced an efficient quantum algorithm that solves this problem when mβ‰ˆn2/2m\approx n^2/2, where a naive classical algorithm would require exponential time. Subsequently, Kothari, O'Donnell, and Wu (STOC'2026) gave an efficient classical algorithm that only requires mβ‰ˆn2/3m \approx n^2/3 vectors, thus removing the hope for an exponential quantum advantage in this parameter regime. Using the framework of Chen, Liu, and Zhandry, we give quantum algorithms that require much fewer input vectors, renewing the possibility of an exponential quantum speedup: for any fixed Ξ΅>0Ξ΅>0, our quantum algorithm solves F3\mathbb{F}_3-subset sum in polynomial time with m=Ξ΅β‹…n2m=Ξ΅\cdot n^2 vectors. More generally, we establish a full sample--time tradeoff that interpolates between exponential and polynomial runtime. The main ingredient is a deterministic classical algorithm for the binary-error Learning-with-Errors problem, which is of independent cryptographic interest. For this, we rigorously establish a sample--time tradeoff that was predicted by earlier algebraic heuristics. For vector subset sums over larger fields, we also significantly improve classical algorithms in Kothari, O'Donnell, and Wu (STOC'2026).


Source: arXiv:2609.40321v1 - http://arxiv.org/abs/2609.40321v1 PDF: https://arxiv.org/pdf/2609.40321v1 Original Link: http://arxiv.org/abs/2609.40321v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Oct 1, 2026
Topic:
Computer Science
Area:
Cybersecurity
Comments:
0
Bookmark
Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE | Researchia