Papers
Topics
Authors
Recent
Search
2000 character limit reached

Multivalued Consensus: General Adversaries Require More Communication

Published 18 Aug 2026 in cs.DC, cs.CR, and cs.IT | (2608.17998v1)

Abstract: We study nn-party fault-tolerant consensus against general (non-threshold) adversaries. We describe an infinite family Zproj<sup>n,dZ_\mathsf{proj}<sup>{n,d} of Q<sup>dQ<sup>d-satisfying nn-party adversary structures based on finite projective geometry which cause error-free RR-round protocols for interactive consistency on LL-bit inputs to require Ω(Ln<sup>2+1/d)Ω(Ln<sup>{2+1/d}) bits of expected communication. Likewise, Zproj<sup>n,dZ_\mathsf{proj}<sup>{n,d} causes error-free byzantine agreement and broadcast to cost Ω(Ln<sup>1+1/d)Ω(Ln<sup>{1+1/d}) bits. In every case, the lower bound is Ω(Loutn<sup>1+1/d)Ω(L_{\mathsf{out}} \cdot n<sup>{1+1/d}) bits, where LoutL_{\mathsf{out}} is the output length. The family Zproj<sup>n,dZ_\mathsf{proj}<sup>{n,d} also causes reliable broadcast and byzantine agreement to cost Ω(Ln<sup>1+1/d)Ω(Ln<sup>{1+1/d}) bits of expected communication in asynchronous networks. Moreover, there exists a related family Z2-proj<sup>n,dZ_\mathsf{2\textsf-proj}<sup>{n,d} of Q<sup>dQ<sup>d-satisfying adversary structures that make core set agreement cost Ω(Ln<sup>2+1/d)Ω(Ln<sup>{2+1/d}) bits. These asynchronous lower bounds hold against send-omission adversaries, even if the protocol uses cryptography. Their basis is that if a quorum of non-faulty parties agree on an output and terminate, then the messages they sent before terminating must suffice for the parties outside the quorum to also terminate with the same output. Surprisingly, if we do not require the parties to terminate (stop sending messages) after they output, then these bounds no longer hold. We show this by designing a non-terminating omission-tolerant reliable broadcast protocol that can for any parameter $δ&gt; 1$ be tuned to cost (1+1δ1)Ln+O(δn<sup>2log(δn))(1 + \frac{1}{δ- 1})Ln + O(δn<sup>2\log(δn)) bits, which is of independent interest. Lastly, we show how to get termination with O(Ln<sup>1+1/d</sup>+n<sup>2log</sup>n)O(Ln<sup>{1+1/d}</sup> + n<sup>2\log</sup> n) bits (assuming the Q<sup>dQ<sup>d condition), and thus prove our asynchronous lower bounds tight.

Summary

  • The paper establishes error-free communication lower bounds of Ω(Ln^(1+1/d)) for multivalued agreement against general Q^d adversaries, a factor of Ω(n^(1/d)) above threshold-adversary costs.
  • It uses finite projective geometries, entropy arguments, and cut-and-paste indistinguishability to prove lower bounds for broadcast, Byzantine agreement, interactive consistency, and core set agreement.
  • The paper shows that termination causes the asynchronous bottleneck: non-terminating protocols can approach baseline costs, while a termination wrapper achieves the matching O(Ln^(1+1/d) + n² log n) bound.

This paper establishes communication complexity lower bounds for multivalued agreement tasks against general (non-threshold) adversaries, showing that for every integer d1d \geq 1, QdQ^d-satisfying adversary structures exist that force error-free agreement on LL-bit inputs to cost Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d}) bits, where LoutL_{\mathsf{out}} is the output length. This is a factor of Ω(n1/d)\Omega(n^{1/d}) above the baseline Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n) bound that is tight against threshold adversaries corrupting Θ(n)\Theta(n) parties. The paper also identifies termination as the precise bottleneck in the asynchronous setting and demonstrates, via a non-terminating reliable broadcast protocol, that this bottleneck can be circumvented entirely if parties are allowed to run forever.

Background and motivation

An adversary structure Z\mathcal{Z} is a down-closed family of subsets of the party set [n][n], and it satisfies the QdQ^d0 condition if no QdQ^d1 or fewer sets in QdQ^d2 cover QdQ^d3. Threshold adversaries tolerating QdQ^d4 faults are special cases of QdQ^d5 adversaries. While feasibility of agreement against general adversaries is well understood—each task studied here requires QdQ^d6 exactly when its threshold analogue requires QdQ^d7—the efficiency question had not been resolved. Existing efficient protocols for long inputs rely on erasure/error-correcting code techniques that exploit threshold structure; translating them naively to general adversaries degrades complexity from QdQ^d8 to QdQ^d9 because the guaranteed number of correct parties inside a quorum can drop to LL0. The paper answers whether this degradation is fundamental.

Adversary structures from projective geometry

The lower bounds rest on two families of adversary structures built from the LL1-dimensional finite projective geometry LL2 for prime powers LL3, inspired by Maekawa's use of projective lines for mutual exclusion quorums.

The structure LL4 partitions parties into sets LL5 and LL6 of size LL7. Parties in LL8 are bijected with points of LL9; the adversary may always corrupt any subset of Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})0, and additionally may pick any hyperplane Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})1 and corrupt all points of Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})2 not incident to Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})3. Each party of Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})4 lies in exactly a Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})5 fraction of the hyperplane quorums—a property central to all double-counting arguments. Note that obtaining such a quorum structure requires letting the adversary corrupt Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})6 parties, which is why these bounds genuinely require general adversaries.

The structure Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})7 uses three sets Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})8 of size Ω(Loutn1+1/d)\Omega(L_{\mathsf{out}} \cdot n^{1+1/d})9, with points of LoutL_{\mathsf{out}}0 labeling pairs of parties across LoutL_{\mathsf{out}}1 and LoutL_{\mathsf{out}}2. The adversary gets two "hits," each consisting of picking a hyperplane and corrupting non-incident parties in one of LoutL_{\mathsf{out}}3 or LoutL_{\mathsf{out}}4. Its key additional feature is a minimal quorum LoutL_{\mathsf{out}}5 of size LoutL_{\mathsf{out}}6, which is needed to force large core sets in the core set agreement lower bound.

Both structures satisfy LoutL_{\mathsf{out}}7 because hyperplanes of LoutL_{\mathsf{out}}8 form a LoutL_{\mathsf{out}}9-wise intersecting family. Although each structure exists only for specific values of Ω(n1/d)\Omega(n^{1/d})0 (of the form Ω(n1/d)\Omega(n^{1/d})1 or Ω(n1/d)\Omega(n^{1/d})2), an appendix argument using the prime number theorem shows the bounds extend to all sufficiently large Ω(n1/d)\Omega(n^{1/d})3 for fixed Ω(n1/d)\Omega(n^{1/d})4.

Synchronous lower bounds

For interactive consistency (all-to-all broadcast of Ω(n1/d)\Omega(n^{1/d})5-bit inputs), the paper proves that for all Ω(n1/d)\Omega(n^{1/d})6, any Ω(n1/d)\Omega(n^{1/d})7-round randomized error-free protocol tolerating byzantine Ω(n1/d)\Omega(n^{1/d})8-adversaries requires Ω(n1/d)\Omega(n^{1/d})9 bits of expected communication whenever Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)0. Reductions then yield Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)1 bits for byzantine agreement and broadcast when Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)2: interactive consistency reduces to Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)3 sequential broadcast instances, and broadcast reduces to agreement plus one round of direct sender transmission costing Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)4 bits.

The proof combines three ingredients. A combinatorial lemma shows that if expected cross-communication between every (quorum, outside-party) pair exceeds some value Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)5, total communication must be Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)6, since each party belongs to only Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)7 quorums. An entropy argument establishes that the bidirectional transcript between any minimal quorum Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)8 and any party Ω(Loutn)\Omega(L_{\mathsf{out}} \cdot n)9 must carry at least Θ(n)\Theta(n)0 bits of entropy under i.i.d. uniform inputs. Finally, a cut-and-paste indistinguishability argument proves the entropy claim: if the transcript entropy were smaller, two input assignments Θ(n)\Theta(n)1 would share a transcript, and byzantine parties could simulate world Θ(n)\Theta(n)2 toward Θ(n)\Theta(n)3 while simulating Θ(n)\Theta(n)4 toward Θ(n)\Theta(n)5, forcing disagreement on some input—breaking error-freedom.

Two restrictions deserve emphasis. First, the error-free requirement is essential: authenticated protocols with negligible failure probability achieve Θ(n)\Theta(n)6 bits against any adversary structure, so hashing defeats the lower bound. Second, the minimum input length Θ(n)\Theta(n)7 exists because untagged silence can encode metadata (e.g., a round number and sender ID in a single bit); the paper notes the restriction disappears in a tagged-message model or under entropy-based accounting, where the bounds hold for all Θ(n)\Theta(n)8 and even Las Vegas round complexities.

Asynchronous lower bounds

In the asynchronous setting, the paper proves three lower bounds against efficient send-omission adversaries, holding even if output safety need only hold with constant probability (Θ(n)\Theta(n)9 for reliable broadcast, Z\mathcal{Z}0 for byzantine agreement, Z\mathcal{Z}1 for core set agreement), and even though explicit efficient adversaries preclude cryptographic circumvention:

Task Structure Bound Condition
Reliable broadcast Z\mathcal{Z}2, Z\mathcal{Z}3 Z\mathcal{Z}4 Z\mathcal{Z}5
Byzantine agreement Z\mathcal{Z}6, Z\mathcal{Z}7 Z\mathcal{Z}8 Z\mathcal{Z}9
Core set agreement [n][n]0, [n][n]1 [n][n]2 all [n][n]3

All three require terminating protocols—correct parties must stop sending messages upon outputting. The proofs use a scheduling strategy in which the adversary lets traffic flow freely within a quorum set until its members terminate, exploiting the fact that they cannot distinguish fault-free execution from one where outsiders are silent faulty parties. Once the quorum terminates, agreement forces outsiders to learn the output from quorum messages alone, and Fano's inequality plus the data processing inequality yield transcript entropy lower bounds converted to bit complexity via a prefix-free encoding argument. For core set agreement, an additional scheduling phase forces the agreed core set to be the large quorum [n][n]4 of size [n][n]5, with a careful union-bound analysis over validity-violation events showing each party's output must contain all [n][n]6 bits of correct tuples with probability at least [n][n]7.

A consequence of the reliable broadcast bound is that the echo-based protocol of Hadzilacos and Toueg is optimal among terminating protocols tolerating up to [n][n]8 send-omission faults, since such an adversary subsumes [n][n]9.

Non-terminating reliable broadcast: PullCast

To show termination is essential, the paper presents PullCast, a deterministic, perfectly secure reliable broadcast protocol against any general-omission adversary that does not terminate. For any parameter QdQ^d00, PullCast costs QdQ^d01 bits and QdQ^d02 messages, with latency QdQ^d03. It uses Reed-Solomon erasure codes with parameters QdQ^d04 and a dynamic pull-based symbol request mechanism: each party tracks how many symbols it has received and requests the next needed symbol from whichever party last served it, so fast responders serve more requests—a pattern familiar from BitTorrent but uncommon in fault-tolerant consensus literature.

Because servers must remain alive indefinitely to answer dynamic requests, no terminating lower bound applies. The paper sketches how PullCast could be hardened against byzantine faults (assuming QdQ^d05) via Merkle-tree proofs attached to symbols and a fault-tolerant request deduplication mechanism, at a cost increase to QdQ^d06 overhead terms. Compositions sketched in the discussion show that non-terminating core set agreement and byzantine agreement also admit QdQ^d07 and QdQ^d08 bit solutions respectively for large QdQ^d09.

Two implications follow. First, Locher's QdQ^d10 bit lower bound for a restricted class of reliable broadcast protocols does not extend to all non-terminating protocols, contradicting his conjecture. Second, the paper gives a simple terminating crash-fault-tolerant reliable broadcast protocol costing QdQ^d11 bits (sender sends input, then reliably broadcasts "OK"), showing the lower bounds do not transfer to crash faults either—so Locher's bound fails to generalize in both directions.

Tightness via a termination protocol

The asynchronous lower bounds are shown tight for all sufficiently large QdQ^d12 against any QdQ^d13 send-omission adversary. The paper first proves that every QdQ^d14-satisfying structure admits a non-empty set QdQ^d15 with QdQ^d16 for all QdQ^d17, via a greedy peeling argument. The termination protocol Term then has each party in QdQ^d18 distribute an erasure-coded symbol of the agreed output using a QdQ^d19-code, with a relay step ensuring totality. Composed after any uniform-agreement protocol QdQ^d20 (such as PullCast), Term guarantees that if any correct party outputs from QdQ^d21, every correct party terminates with the same output, at a cost of QdQ^d22 bits and latency 2. Thus terminating reliable broadcast against QdQ^d23 general-omission adversaries costs QdQ^d24 bits, matching the lower bound. A byzantine-tolerant variant for QdQ^d25 is sketched using Merkle proofs and a quadratic reliable agreement instance on root hashes.

Limitations and open questions

Several caveats qualify the results. The synchronous lower bounds apply only to error-free protocols, and the paper can only conjecture—not prove—that they are tight; matching synchronous upper bounds remain open. The asynchronous lower bounds require termination with probability 1; extension to high-probability termination is conjectured but not formalized, and would require conditioning input distributions on good termination events. The minimum-input-length requirements stem from the untagged communication model and vanish under tagged messaging or entropy-based accounting. The paper also leaves open whether the Dolev-Reischuk-style quadratic message lower bounds apply to its adversary structures—it suspects they do not, and that QdQ^d26-message byzantine broadcast may be possible—and poses the unstudied question of when general-adversary-tolerant protocols can balance communication load evenly across correct parties. Regarding the QdQ^d27 threshold, the authors report believing based on subsequent work that Locher's bound holds for all well-balanced reliable broadcast protocols, deferring formal treatment.

Conclusion

This paper demonstrates that general QdQ^d28 adversaries fundamentally inflate the communication cost of multivalued agreement by a factor of QdQ^d29 over threshold adversaries, through explicit projective-geometry adversary structures and entropy-based double-counting arguments covering five classical tasks in both synchronous and asynchronous models. It further isolates termination as the exact source of the asynchronous lower bounds, exhibiting a near-baseline-cost non-terminating protocol and a matching QdQ^d30 termination wrapper that together render the asynchronous bounds tight. The main unresolved question is whether the synchronous error-free lower bounds admit matching protocols.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Tweets

Sign up for free to view the 1 tweet with 6 likes about this paper.