Improved Hardness of BDD and SVP Under Gap-(S)ETH

πŸ“… 2021-09-09
πŸ›οΈ Information Technology Convergence and Services
πŸ“ˆ Citations: 10
✨ Influential: 1
πŸ“„ PDF
πŸ€– AI Summary
This work establishes fine-grained complexity lower bounds for the Bounded Distance Decoding (BDD) and Shortest Vector Problem (SVP) on β„“β‚š-lattices. Using variants of the Gap-(Strong) Exponential Time Hypothesis (Gap-(S)ETH), the authors employ reductions, kissing number analysis, and randomized/non-uniform complexity techniques. They derive, for the first time, a unified hardness threshold Ξ±β€ β‚š for BDDβ‚š,Ξ± across all p ∈ [1, ∞): Ξ±β€ β‚š < 1 for p > 2 and converges to 1/2 as p β†’ ∞. They prove that for any C > 1, BDDβ‚š,Ξ± admits no 2βΏβ„αΆœ-time algorithm when Ξ± > Ξ±β€ β‚š,𝒸; moreover, no 2ᡒ⁽ⁿ⁾ algorithm exists when Ξ± > Ξ±β‚–β‚™ β‰ˆ 0.9849. Additionally, they extend the 2βΏβ„αΆœ-hardness of SVPβ‚š,Ξ³ to all non-even p > 2.1397β€”previously known only for even p. These results significantly strengthen exponential-time lower bounds for β„“β‚š-lattice problems.
πŸ“ Abstract
We show improved fine-grained hardness of two key lattice problems in the $ell_p$ norm: Bounded Distance Decoding to within an $alpha$ factor of the minimum distance ($mathrm{BDD}_{p, alpha}$) and the (decisional) $gamma$-approximate Shortest Vector Problem ($mathrm{SVP}_{p,gamma}$), assuming variants of the Gap (Strong) Exponential Time Hypothesis (Gap-(S)ETH). Specifically, we show: 1. For all $p in [1, infty)$, there is no $2^{o(n)}$-time algorithm for $mathrm{BDD}_{p, alpha}$ for any constant $alpha>alpha_mathsf{kn}$, where $alpha_mathsf{kn} = 2^{-c_mathsf{kn}}<0.98491$ and $c_mathsf{kn}$ is the $ell_2$ kissing-number constant, unless non-uniform Gap-ETH is false. 2. For all $p in [1, infty)$, there is no $2^{o(n)}$-time algorithm for $mathrm{BDD}_{p, alpha}$ for any constant $alpha>alpha^ddagger_p$, where $alpha^ddagger_p$ is explicit and satisfies $alpha^ddagger_p = 1$ for $1 leq p leq 2$, $alpha^ddagger_p<1$ for all $p>2$, and $alpha^ddagger_p o 1/2$ as $p o infty$, unless randomized Gap-ETH is false. 3. For all $p in [1, infty) setminus 2 mathbb{Z}$ and all $C>1$, there is no $2^{n/C}$-time algorithm for $mathrm{BDD}_{p, alpha}$ for any constant $alpha>alpha^dagger_{p, C}$, where $alpha^dagger_{p, C}$ is explicit and satisfies $alpha^dagger_{p, C} o 1$ as $C o infty$ for any fixed $p in [1, infty)$, unless non-uniform Gap-SETH is false. 4. For all $p>p_0 approx 2.1397$, $p otin 2mathbb{Z}$, and all $C>C_p$, there is no $2^{n/C}$-time algorithm for $mathrm{SVP}_{p, gamma}$ for some constant $gamma>1$, where $C_p>1$ is explicit and satisfies $C_p o 1$ as $p o infty$, unless randomized Gap-SETH is false.
Problem

Research questions and friction points this paper is trying to address.

Hardness of BDD problem in β„“_p norm under Gap-ETH
Hardness of SVP problem in β„“_p norm under Gap-SETH
Time complexity lower bounds for lattice problems
Innovation

Methods, ideas, or system contributions that make the work stand out.

Improved hardness proofs for BDD and SVP
Assumes variants of Gap-(S)ETH for complexity
Explicit bounds on approximation factors
πŸ”Ž Similar Papers
No similar papers found.