Validity of the XL/relinearization attack tradeoff
Establish whether the XL/relinearization attack for binary-error Learning-with-Errors over \(\mathbb{F}_3\) achieves the same sample–time tradeoff as the quotient decoder.
References
However we conjecture that the XL/relinearization attack may work just as well.
— Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE
(2609.40321 - Kothari et al., 30 Sep 2026) in Acknowledgments and AI disclosure, footnote following the discussion of the quotient decoder
Based on the experiments, we make the following conjecture. For q=3 and all sufficiently large n, degree-3 XL solves \Cref{prob:pointwise-binary-error-lwe} with probability at least 0.99 whenever m\ge\begin{cases} m_{\mathrm{pred}}(n) & n\not\equiv\pm1\pmod6,\ m_{\mathrm{pred}}(n)+1 & n\equiv\pm1\pmod6. \end{cases}
— Exponential quantum speedup for $\mathbb{F}_3^n$-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE
(2609.40321 - Kothari et al., 30 Sep 2026) in Appendix, Section “Degree-3 XL experiments,” conjecture labeled Conjecture \ref{conj:deg3}