LPN-friendliness and decoding hardness of RAA codes

Establish that Repeat-Accumulate-Accumulate (RAA) codes admit no efficient decoding algorithm and are LPN-friendly, thereby validating their use in the dual-LPN-based privacy construction for private and verifiable matrix--vector multiplication delegation.

Background

The paper instantiates its privacy mechanism with RAA codes because they support linear-time encoding and are believed to satisfy the dual-LPN assumption. The security of this construction depends on the difficulty of decoding these codes and on their LPN-friendliness.

The paper notes that prior minimum-distance analyses establish security against linear tests and asymptotic goodness, but these properties do not by themselves prove the broader conjecture that RAA codes resist efficient decoding and furnish LPN-friendly instances. Consequently, the hardness and LPN-friendliness of RAA codes remain unresolved assumptions underlying the construction.

References

As such, it is conjectured that no efficient decoding algorithm exists, and that RAA codes are LPN-friendly.

Maverick: Private and Verifiable LLM Inference Made Practical via Matrix-Vector Multiplication Delegation  (2609.10264 - Merbaum et al., 9 Sep 2026) in Appendix, Section “Repeat-Accumulate-Accumulate Codes,” subsection “LPN friendliness and asymptotic goodness”