Optimality of the classical polynomial-time threshold for F3-subset-sum

Determine whether the constant c_\star=(8\log(3)-9)/36\approx0.1022 achieved by the described classical algorithm for average-case \(\mathbb{F}_3^n\)-Subset-Sum is optimal.

Background

The paper presents a classical algorithm for average-case F3n\mathbb{F}_3^n-Subset-Sum using m=c⋆n2m=c_\star n^2 input vectors, where c⋆≈0.1022c_\star\approx0.1022. This improves the prior polynomial-time threshold of approximately n2/3n^2/3, but remains above the quantum algorithm’s threshold for every fixed positive constant multiplying n2n^2.

The authors explicitly state that they do not know, and do not expect, that the constant is optimal. Determining its optimality would clarify how close the current classical algorithm is to the best possible polynomial-time sample threshold and whether a classical algorithm can match the quantum threshold.

References

Naturally, we do not know (or expect) that this constant is optimal, but achieving a similar sample--time tradeoff as we do in the quantum case (and in particular a classical algorithm for any fixed > 0) seems to require substantially new ideas.

— Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE  (2609.40321 - Kothari et al., 30 Sep 2026) in Section 1, paragraph “Our contribution”; Section 1, subsection “Classical algorithms for Fq-Subset-Sum”