- The paper proves that non-adaptive, fully black-box constructions of weak PRFs from PRGs require at least Ω(n/log n) calls when reductions are query-bounded, ruling out constant-call designs for input lengths growing faster than log n.
- The authors use meta-reductions, seed-collision analysis, concentration bounds, and randomized thresholds to simulate ideal adversaries efficiently and separate constructions making too few PRG queries.
- A separate entropy-based result rules out adaptive constructions using fewer than out/(r + ω(log n)) calls for long-output weak PRFs, narrowing the gap with GGM while leaving unrestricted reductions, standard PRFs, and exact optimality open.
Context and motivation
The GGM construction of pseudorandom functions from pseudorandom generators [GGM86] remains the canonical black-box reduction between these two primitives. Combined with Levin's domain extension trick, it requires ω(logn) invocations of an n-bit PRG per evaluation, where n is the PRG seed length. Whether this call complexity is optimal has been open since the construction was introduced: prior to this work, Beimel, Malkin, and Mazor [BMM24] had established optimality only for the restricted class of "tree constructions," and no previous result ruled out a single-call construction. The paper under review, by Alon, Dinur, and Venkitasubramaniam (arXiv (2608.14501)), makes substantial progress on this question by proving the first lower bounds that apply beyond tree constructions.
The paper works in the fully black-box model of Reingold–Trevisan–Vadhan [RTV04]: both the construction F and the security reduction R treat the underlying primitive as an oracle. Following the meta-reduction paradigm of Boneh–Venkatesan [BV98], the authors construct inefficient "ideal" adversaries and simulate them efficiently via "real" adversaries that exploit the transcript of the reduction's interaction with the PRG oracle.
Main result: non-adaptive constructions
The central theorem states that there is no fully black-box construction of a weak PRF with input length in from an arbitrary-stretch PRG using c non-adaptive calls, whenever c=o(n/logn) and c=o(in/login), provided the reduction is query-bounded. A reduction is (d,α)-query-bounded if its number of calls to any distinguishing adversary with advantage at least n0 is bounded by n1. Notably:
- The impossibility holds even for weak PRFs, where the adversary makes only i.i.d. uniform queries, and even for one-bit output PRFs.
- As a corollary, constant-call constructions are ruled out entirely for query-bounded reductions when n2 — in particular, resolving the single-call case for this class of reductions.
- The bounds are incomparable in strength to GGM's n3 calls: GGM uses fewer calls asymptotically but is a tree construction; the new result covers all non-tree constructions as well, at the cost of the query-bounded restriction on the reduction.
Proof technique for the main result
A naive random-oracle-based separation fails here for an instructive reason: constructions such as n4 are information-theoretically secure against polynomial-query adversaries when n5 is instantiated by a random function, so no efficient oracle-aided distinguisher can break them. The authors instead use meta-reductions.
An ideal adversary queries n6 on all inputs and checks whether some key is consistent with a large fraction of the oracle's answers on n7 fixed inputs. A real adversary must emulate this without querying n8, using only the reduction's own PRG query-answer pairs. Two technical obstacles arise: (i) outputs of the PRF may be dependent across inputs when seeds collide, breaking concentration arguments; (ii) the reduction can implant the challenge string n9 into one answer, perturbing the ideal score by 1 while leaving the real score nearly unchanged.
Both issues are resolved by identifying, per key, either a set of frequent seeds (whose PRG values are replaced by fixed values maximizing the score, removing entropy contributions) or a large set of inputs with mutually disjoint seeds (via a greedy independent-set argument on a collision graph). On disjoint-seed sets, the relevant indicators become independent, so Hoeffding's inequality shows the real score tracks the expected ideal score within n0 except with probability n1, where n2. A uniformly random threshold n3 smooths residual discrepancies between the two scores.
Parameter choices require n4, which is at most n5 precisely because n6; similarly, the reduction's total PRG query count n7 stays below n8 because n9. Instantiating the PRG as a random function then contradicts the fact that a random function is a PRG against F0-query adversaries (proved via lazy sampling).
The query-bounded restriction
The proof requires that the number F1 of reduction-to-adversary interactions be fixed independently of the adversary's query count F2: since the statistical distance per interaction is only inverse-polynomial (not negligible), one needs F3 small relative to the precision achievable with large F4. Under the standard fully black-box definition, a reduction could adaptively increase its number of interactions based on the adversary's behavior, creating a circular dependence between F5 and F6. The authors argue that all reductions in the literature — including GGM, Goldreich–Levin, and Waters' IBE — are query-bounded, and note that if one could achieve negligible statistical distance between the two adversaries, the restriction would disappear. Extending the lower bound to all black-box reductions remains open.
Lower bound for long outputs with adaptive calls
The second result removes both the non-adaptivity and the query-boundedness assumptions, at the cost of restricting the output length. Specifically, there is no fully black-box construction of a weak PRF with output length F7 from an F8-bit stretch PRG using at most F9 calls. The proof is an entropy argument: consider a PRG that applies genuine randomness only to the first R0 bits of the seed (its existence relative to a suitable oracle follows from a lemma of BMM24). Then R1 evaluations of the PRF carry at most R2 bits of entropy, versus R3 for a random function; taking R4 yields a distinguishing gap of R5 via a union bound over keys and intermediate strings.
Comparing to GGM: composing GGM (with Levin's trick) with the Goldreich–Levin hardcore-bit construction yields an R6-bit output PRF from a 1-bit stretch PRG using R7 calls, whereas the lower bound requires R8 calls. Thus GGM is optimal up to a factor of R9 in this regime.
Limitations and open questions
Several restrictions qualify the results and should be stated plainly. First, the main theorem applies only to non-adaptive constructions; adaptive constructions are covered only in the long-output regime. Second, the main theorem requires query-bounded reductions, a strictly smaller class than all fully black-box reductions, though the authors contend it captures every reduction known. Third, both results concern weak PRFs; extending to standard PRFs is not addressed. Fourth, the gap between the upper bound (in0 calls for GGM-type constructions) and the lower bound (in1 calls impossible) leaves the exact optimum unresolved, and the single-call question for general reductions remains open. Finally, the statistical-distance argument inherently produces only inverse-polynomial closeness between the real and ideal adversaries; whether this can be improved to negligible distance — which would eliminate the query-bounded assumption — is left unanswered.
Conclusion
This work substantially broadens the known impossibility landscape for black-box PRF constructions from PRGs, moving beyond tree constructions to rule out all non-adaptive constructions with in2 calls under a natural and widely satisfied restriction on reductions, and ruling out sub-in3-call constructions even adaptively for long-output PRFs. The combination of meta-reduction techniques with combinatorial seed-collision analysis appears likely to be useful for further separations, though closing the remaining gaps — adaptivity, unrestricted reductions, and the exact call-complexity threshold — remains open.