Papers
Topics
Authors
Recent
Search
2000 character limit reached

Exponential quantum speedup for F3n\mathbb{F}_3^n-Subset-Sum? Or, rigorous classical algorithms for Binary-Error LWE

Published 30 Sep 2026 in quant-ph, cs.CR, and cs.DS | (2609.40321v1)

Abstract: We study vector subset sum over F3<sup>n\mathbb{F}_3<sup>n: given mm random vectors from F3<sup>n\mathbb{F}_3<sup>n, find a nonempty subset that sums to zero; the smaller mm, the more difficult it is to find such a subset. Chen, Liu, and Zhandry (EUROCRYPT'22) introduced an efficient quantum algorithm that solves this problem when m≈n<sup>2/2m\approx n<sup>2/2, where a naive classical algorithm would require exponential time. Subsequently, Kothari, O'Donnell, and Wu (STOC'2026) gave an efficient classical algorithm that only requires m≈n<sup>2/3m \approx n<sup>2/3 vectors, thus removing the hope for an exponential quantum advantage in this parameter regime. Using the framework of Chen, Liu, and Zhandry, we give quantum algorithms that require much fewer input vectors, renewing the possibility of an exponential quantum speedup: for any fixed $ε&gt;0$, our quantum algorithm solves F3\mathbb{F}_3-subset sum in polynomial time with m=ε⋅n<sup>2m=ε\cdot n<sup>2 vectors. More generally, we establish a full sample--time tradeoff that interpolates between exponential and polynomial runtime. The main ingredient is a deterministic classical algorithm for the binary-error Learning-with-Errors problem, which is of independent cryptographic interest. For this, we rigorously establish a sample--time tradeoff that was predicted by earlier algebraic heuristics. For vector subset sums over larger fields, we also significantly improve classical algorithms in Kothari, O'Donnell, and Wu (STOC'2026).

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.