Bounded Distance Decoding for Random Lattices

📅 2025-06-20
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work studies the Bounded Distance Decoding (BDD) problem for random lattices with sub-Gaussian generating matrices. We first establish that BDD is NP-hard in the worst case—challenging the long-standing “average-case hardness implies worst-case hardness” paradigm prevalent in lattice-based cryptography. Second, we propose a polynomial-time algorithm based on singular value decomposition (SVD) and probabilistic analysis, which solves BDD exactly with high probability on random instances. Theoretical analysis and empirical evaluation jointly confirm that the algorithm achieves polynomial average-case time complexity and success probability tending to one. To our knowledge, this is the first rigorous demonstration of a separation between worst-case NP-hardness and average-case tractability for any lattice problem. Our results provide new insights into the foundational security assumptions of lattice cryptography and open avenues for efficient algorithm design.

Technology Category

Search and Optimization: Mixed Discrete/Continuous SearchConstraint Satisfaction and Optimization: Distributed CSP/OptimizationKnowledge Representation and Reasoning: Computational Complexity of Reasoning

Application Category

Security and Privacy: Applications of cryptographyGraph Algorithms and Modeling for the Web: Algorithms and analysis for incomplete, noisy, or partially observed Web-related graphsSystems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deployments
📝 Abstract
The current paper investigates the bounded distance decoding (BDD) problem for ensembles of lattices whose generator matrices have sub-Gaussian entries. We first prove that, for these ensembles the BDD problem is NP-hard in the worst case. Then, we introduce a polynomial-time algorithm based on singular value decomposition (SVD) and establish, both theoretically and through extensive experiments, that, for a random selected lattice from the same ensemble, the algorithm solves the BDD problem with high probability. To the best of our knowledge, this work provides the first example of a lattice problem that is NP-hard in the worst case yet admits a polynomial time algorithm on the average case.
Problem

Research questions and friction points this paper is trying to address.

Proves BDD is NP-hard for sub-Gaussian lattices
Introduces SVD-based polynomial-time BDD algorithm
Solves average-case BDD efficiently despite worst-case hardness
Innovation

Methods, ideas, or system contributions that make the work stand out.

SVD-based polynomial-time BDD algorithm
NP-hard worst case but average solvable
Sub-Gaussian lattice ensembles analysis
🔎 Similar Papers
No similar papers found.