Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study investigates the feasibility and theoretical limits of quantum speedups for the subset sum problem over finite fields and the binary error Learning with Errors (LWE) problem. By integrating quantum computing, algebraic heuristic analysis, and LWE cryptographic techniques, this work constructs a novel quantum algorithmic framework and derives rigorous sample-time trade-offs for classical algorithms. The proposed approach achieves polynomial-time quantum solutions to the subset sum problem under minimal input vector conditions, thereby revitalizing the prospect of exponential quantum advantage. Furthermore, the established theoretical trade-off framework significantly surpasses the performance bottlenecks of existing classical algorithms, substantially improving solving efficiency in large-domain settings.
📝 Abstract
We study vector subset sum over $\mathbb{F}_3^n$: given $m$ random vectors from $\mathbb{F}_3^n$, find a nonempty subset that sums to zero; the smaller $m$, the more difficult it is to find such a subset. Chen, Liu, and Zhandry (EUROCRYPT'22) introduced an efficient quantum algorithm that solves this problem when $m\approx n^2/2$, where a naive classical algorithm would require exponential time. Subsequently, Kothari, O'Donnell, and Wu (STOC'2026) gave an efficient classical algorithm that only requires $m \approx n^2/3$ vectors, thus removing the hope for an exponential quantum advantage in this parameter regime. Using the framework of Chen, Liu, and Zhandry, we give quantum algorithms that require much fewer input vectors, renewing the possibility of an exponential quantum speedup: for any fixed $ε>0$, our quantum algorithm solves $\mathbb{F}_3$-subset sum in polynomial time with $m=ε\cdot n^2$ vectors. More generally, we establish a full sample--time tradeoff that interpolates between exponential and polynomial runtime. The main ingredient is a deterministic classical algorithm for the binary-error Learning-with-Errors problem, which is of independent cryptographic interest. For this, we rigorously establish a sample--time tradeoff that was predicted by earlier algebraic heuristics. For vector subset sums over larger fields, we also significantly improve classical algorithms in Kothari, O'Donnell, and Wu (STOC'2026).
Innovation

Methods, ideas, or system contributions that make the work stand out.

Quantum Speedup
Subset-Sum
Binary-Error LWE
Sample-Time Tradeoff
Deterministic Classical Algorithm
🔎 Similar Papers
2024-05-22Neural Information Processing SystemsCitations: 0