Papers
Topics
Authors
Recent
Search
2000 character limit reached

Cyclic Addition Tables in PDMM

Updated 19 April 2026
  • Cyclic Addition Tables (CAT) are structured degree-table codes that use cyclic group operations and modulo addition to enhance private distributed matrix multiplication.
  • Their construction partitions the addition table into disjoint quadrants, ensuring perfect T-privacy and exact decodability in encoding and decoding processes.
  • Quantum extensions of CAT achieve rate-doubling by leveraging interference criteria and cyclical exponent packing, outperforming conventional schemes in low-privacy regimes.

Cyclic Addition Tables (CAT) are a family of degree-table codes for private distributed matrix multiplication (PDMM), extending conventional integer-based degree-table frameworks by implementing a cyclic group structure on polynomial exponents. CATs utilize modulo addition (over Zq\mathbb{Z}_q for suitable qq) and roots of unity as evaluation points, achieving improved worker-efficiency through denser packing of sum exponents. The framework enables perfect TT-privacy and exact decodability, particularly benefiting low-privacy regimes (i.e., Tmin(K,L)T \ll \min(K,L)), and has quantum extensions that admit rate-doubling via feasibility criteria that depend on the distribution of "interference" exponents (Hofmeister et al., 21 Jan 2025, Nomeir et al., 28 Nov 2025).

1. Formal Definition and Structural Properties

Given integers K,L,T1K,L,T\geq 1, a Cyclic Addition Table for parameters (K,L,T)(K,L,T) with NN unique entries is a tuple (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)}) where

  • α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K and α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T encode the "product" and "secret" exponents for qq0,
  • qq1 and qq2 are analogous for qq3,
  • qq4 is the modulus,
  • All additions are over qq5.

The combined set of all possible sums,

qq6

with qq7 denoting the vector of residues in increasing order, partitions the qq8 addition table into four quadrants. The structural requirements are:

  1. All four quadrants collectively produce exactly qq9 distinct residues modulo TT0.
  2. The top-left quadrant defines TT1 distinct residues, with each representing a desired outer block-product.
  3. Off-diagonal quadrants (top-right, bottom-left, bottom-right) must be disjoint from each other and from the top-left (i.e., product terms never mix with noise/randomization terms).
  4. A field TT2 is chosen so that TT3, ensuring the existence of a primitive TT4-th root of unity TT5. Evaluation at TT6 for TT7 yields invertibility in the corresponding Vandermonde matrices for both decoding (entire degree table) and for TT8-privacy (any TT9 submatrix in Tmin(K,L)T \ll \min(K,L)0 or Tmin(K,L)T \ll \min(K,L)1).

This structure ensures that decoding via polynomial interpolation is unambiguous, and that Tmin(K,L)T \ll \min(K,L)2-privacy is information-theoretically enforced (Hofmeister et al., 21 Jan 2025).

2. Explicit CAT Construction and Parameter Computation

The canonical construction, denoted CATTmin(K,L)T \ll \min(K,L)3, is defined as follows for Tmin(K,L)T \ll \min(K,L)4:

  • Define Tmin(K,L)T \ll \min(K,L)5;
  • Find the smallest nonnegative integers Tmin(K,L)T \ll \min(K,L)6, Tmin(K,L)T \ll \min(K,L)7 such that Tmin(K,L)T \ll \min(K,L)8 and Tmin(K,L)T \ll \min(K,L)9 are co-prime with K,L,T1K,L,T\geq 10;
  • Set K,L,T1K,L,T\geq 11;
  • Choose K,L,T1K,L,T\geq 12 coprime to K,L,T1K,L,T\geq 13, then solve K,L,T1K,L,T\geq 14 for K,L,T1K,L,T\geq 15;
  • Set exponents:
    • K,L,T1K,L,T\geq 16,
    • K,L,T1K,L,T\geq 17,
    • K,L,T1K,L,T\geq 18,
    • K,L,T1K,L,T\geq 19,
    • all modulo (K,L,T)(K,L,T)0.

The degree table defines the exponents for encoding polynomials. Each entry in the block-product quadrant maps uniquely to one of (K,L,T)(K,L,T)1 mod (K,L,T)(K,L,T)2, with noise and cross terms mapped to disjoint intervals according to the combinatorial construction, ensuring the separation properties (Hofmeister et al., 21 Jan 2025, Nomeir et al., 28 Nov 2025).

3. Encoding, Evaluation, Decoding, and Privacy

For PDMM applications, let (K,L,T)(K,L,T)3 and (K,L,T)(K,L,T)4 over (K,L,T)(K,L,T)5 be partitioned into outer-product blocks:

(K,L,T)(K,L,T)6

with (K,L,T)(K,L,T)7 random masks (K,L,T)(K,L,T)8 for (K,L,T)(K,L,T)9 and NN0 for NN1. Encoding polynomials are formed as:

NN2

Each worker NN3 evaluates NN4. The exponents in NN5 are segregated by the CAT table. The coefficients indexed by the top-left quadrant NN6 recover NN7. Upon collecting NN8 responses, the system in the worker evaluation points is invertible, guaranteeing perfect recovery.

NN9-privacy is achieved since any (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})0 workers only see (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})1 masked evaluations, and the mask randomness is protected by the invertibility property of the (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})2 submatrices, thus leaking no information about (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})3 (Hofmeister et al., 21 Jan 2025).

4. Worker Count and Comparisons with Conventional Schemes

The number of workers required, denoted (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})4, is given by:

(q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})5

where (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})6 and (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})7 are as previously defined.

Comparison with GASP and DOG codes:

  • GASP requires (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})8 workers.
  • CAT reduces worker count by (q,α(p),α(s),β(p),β(s))(q, \alpha^{(p)}, \alpha^{(s)}, \beta^{(p)}, \beta^{(s)})9 (numerically up to α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K0 when α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K1), particularly when α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K2.
  • When α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K3 becomes comparable to α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K4 or α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K5, conventional schemes may regain the advantage.

Asymptotically, for fixed α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K6:

  • α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K7
  • α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K8 CAT achieves its efficiency in the low-privacy regime by efficiently exploiting the cyclic structure of the exponents to compress noise terms (Hofmeister et al., 21 Jan 2025, Nomeir et al., 28 Nov 2025).

5. Field Requirements and Evaluation Points

The CAT scheme necessitates a field α(p)ZK\alpha^{(p)} \in \mathbb{Z}^K9 such that α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T0 is divisible by α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T1, ensuring the existence of a primitive α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T2-th root of unity α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T3. Worker α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T4 is assigned the evaluation point α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T5. For any exponent α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T6,

α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T7

Thus, exponent addition for encoded polynomial terms is performed modulo α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T8, not over the integers, permitting “wrap-around” and greater flexibility in assignment and separation of noise and product terms.

In practice, selection of α(s)ZT\alpha^{(s)} \in \mathbb{Z}^T9 occurs via a short search for a prime qq00 (Hofmeister et al., 21 Jan 2025).

6. Quantum Extensions and Feasibility Conditions

CAT codes extend to the quantum PDMM context. The feasibility of such an extension is controlled via the structure of the "interference subspace" qq01, where qq02 is the set of exponents corresponding to valid block-products. The quantum extension, enabling two independent qq03 decodings via super-dense coding, is available if the longest consecutive chain in qq04, qq05, satisfies qq06.

Upload/download rates in the quantum regime are doubled (i.e., qq07) when the feasibility test holds. This feasibility criterion unifies that for all rank-based OPP codes (GASP, DOG, CAT), and is especially notable as CATqq08 codes provide the first known nontrivial low-privacy example passing this test. When feasibility fails, quantum-native PDMM schemes may still exist but will typically require increased server randomness or dimensional embedding (Nomeir et al., 28 Nov 2025).

7. Use Cases, Applications, and Limitations

CATs are optimally suited for PDMM and SDMM scenarios where:

  • The privacy threshold qq09 is strictly smaller than both qq10 and qq11 (low-privacy regime).
  • Worker minimization is desired, as the modulo structure can result in smaller qq12 than non-cyclic schemes.
  • Quantum communication infrastructure is available, and feasibility for rate-doubling is satisfied.

When qq13 approaches qq14 or qq15, or when the field-size constraint is prohibitive, conventional schemes such as GASP, rs/GASPqq16, or PoleGap may outperform CATs.

A phase diagram of applicable regimes and numerical evaluations of cross-over points are given in the literature (Hofmeister et al., 21 Jan 2025, Nomeir et al., 28 Nov 2025).


References

Definition Search Book Streamline Icon: https://streamlinehq.com
References (2)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Cyclic Addition Tables (CAT).