Bit-level randomized encoding with constant locality

Construct a polynomial-length randomized encoding for the affine maps used in the encoded LWE sampling protocol whose individual encoded bits and source bits have constant output and input locality, while also providing efficient decoding, perfect privacy, unique randomness reconstruction, and constant-depth bounded-arity preparation of the coherent encoding randomness and function-noise superpositions.

Background

The paper's randomized encoding is local at the level of qq-ary symbols, but each symbol contains L=polylog(λ)L=\operatorname{polylog}(\lambda) bits. This bit length causes the bounded-arity implementation to have depth O(loglogλ)O(\log\log\lambda). A bit-level encoding with the same structural and cryptographic properties would potentially yield a constant-depth bounded-arity QNC implementation of the protocol.

References

We were not able to find a randomized encoding satisfying all of these properties.

Verifiable quantum advantage in extremely low depth  (2609.01448 - Gheorghiu, 1 Sep 2026) in Section 5, Discussion