Derivation of the carry-predicate adaptive-hardcore-bit assumption from LWE

Prove that the adaptive-hardcore-bit assumption for LWE with adaptively chosen carry predicates follows from standard LWE.

Background

The main soundness theorem relies on a nonstandard carry-predicate extension of the adaptive-hardcore-bit assumption. Standard LWE suffices for the ordinary adaptive-hardcore-bit property governing linear predicates, but the paper does not establish security when an adversary may include carry bits of partial LWE sums in the predicted parity. Deriving this stronger assumption from standard LWE would substantially reduce the nonstandard assumptions needed for the protocol.

References

A separate cryptographic open problem is to derive \Cref{ass:carry-ahcb} from standard LWE.

Verifiable quantum advantage in extremely low depth  (2609.01448 - Gheorghiu, 1 Sep 2026) in Section 5, Discussion