Linear Extractors Overview
- Linear extractors are deterministic linear maps that transform weak random sources into nearly uniform outputs by applying fixed matrices over finite fields.
- They employ methods such as sparse random matrices, BCH code-based constructions, and weight-spectrum analysis to ensure minimal bias across diverse source models.
- Practical implementations balance computational speed with accuracy, using sparse constructions for efficiency and code-based approaches for strong algebraic guarantees.
Linear extractors are randomness extractors whose extraction map is linear over a finite field or vector space. In the binary setting, the canonical form is a fixed matrix applied to a weak source , producing over and aiming for to be -close to uniform in statistical distance. Within this broad class fall deterministic linear transformations for independent, bit-fixing, and hidden-Markov sources; code-based binary extractors whose performance is governed by code spectra; affine and directional affine extractors over ; deterministic extractors for additive sources such as arithmetic progressions and generalized arithmetic progressions; and seeded lossless rank extractors over (Zhou et al., 2012, Meneghetti et al., 2014, Gryaznov et al., 2022, Bhowmick et al., 2014, Guo et al., 15 Apr 2026).
1. Formal notion and parameters
A deterministic linear extractor is defined by a fixed binary matrix of size , applied to a weak source 0 by
1
with all arithmetic modulo 2. The extraction objective is that 3 be 4-close to the uniform distribution 5 in statistical distance:
6
The standard parameters are 7 for input length, 8 for output length, 9 for min-entropy, and 0 for allowable error (Zhou et al., 2012).
In the code-based formulation, a 1 binary matrix 2 defines
3
Each output bit is the modulo-4 sum of some subset of the input bits. The quality measure is total-variation distance:
5
where
6
This formulation emphasizes that linear binary extractors are deterministic post-processors that compress biased input bits into fewer output bits while attempting to reduce residual bias (Meneghetti et al., 2014).
The literature considered here treats several source models. For independent sources, 7 has independent coordinates with arbitrary bias, and
8
For bit-fixing sources, exactly 9 positions are uniform and independent, while the remaining 0 bits are arbitrary. For hidden-Markov sources, an underlying Markov chain 1 produces 2, subject to the bounded-noise condition
3
which implies that sums of 4 bits have bias at most 5 (Zhou et al., 2012).
2. Sparse linear transformations and extraction from weak binary sources
A central construction uses a random binary matrix 6 whose entries are i.i.d. Bernoulli7 with
8
Here “sparse” means 9 but 0. A Fourier-analytic bound gives
1
reducing extraction analysis to the biases of nonzero linear forms of the output (Zhou et al., 2012).
For independent sources with 2, the main asymptotic statement is that if 3, then for such sparse random 4,
5
in probability as 6. In this sense, one can extract up to nearly 7 uniform bits. For uniformly random 8 with 9, the expectation bound
0
is obtained directly, while the sparse case is handled by a small-weight and large-weight partition of the nonzero vectors 1 (Zhou et al., 2012).
For bit-fixing sources, the rate is again 2, but the behavior is stronger: with high probability over 3, one gets 4 as soon as 5. The reason is structural: any nonzero linear form on 6 must involve at least one of the 7 uniform bits, which ensures unbiasedness (Zhou et al., 2012).
For hidden-Markov sources, the same sparse-linear framework remains effective but is no longer stated as asymptotically optimal. The extractable rate is
8
and 9 in probability whenever
0
The proofs again use the partition into small-weight and large-weight contributions (Zhou et al., 2012).
| Source model | Condition on output length | Asymptotic guarantee |
|---|---|---|
| Independent source | 1 | 2 in probability |
| Bit-fixing source | 3 | With high probability, 4 |
| Hidden-Markov source | 5 | 6 in probability |
The same work also analyzes explicit matrices. If 7 is the generator matrix of a primitive BCH code whose row-weight distribution is asymptotically binomial, and each input bit has bias at most 8, then for
9
the output 0 satisfies 1. The accompanying trade-off is computational: primitive BCH generator matrices are dense, with approximately 2 ones per row, so they require more computation than sparse random matrices (Zhou et al., 2012).
3. Code spectra, minimum distance, and entropy bounds
A linear extractor defined by a binary matrix 3 can be studied through the linear code it generates. If 4 generates an 5 binary linear code, then a classical minimum-distance-only bound gives
6
where 7 is the bias of each independent input bit. This estimate depends only on the minimum distance 8 (Meneghetti et al., 2014).
The sharper bound introduced later uses the full weight distribution of the code. If 9 denotes the number of codewords of Hamming weight 0, then
1
This makes the distance spectrum, not merely the minimum distance, the controlling object. A code with the same 2 but fewer low-weight codewords has a smaller right-hand side, and when the bulk of the spectrum lies well above 3, the improvement over the minimum-distance bound can be substantial (Meneghetti et al., 2014).
The same analysis yields a lower bound on the Shannon-entropy rate of the output. For 4 and 5 for the uniform distribution on 6,
7
with
8
This converts a total-variation estimate into an entropy-rate guarantee (Meneghetti et al., 2014).
The code-spectrum viewpoint also changes code-selection criteria. Classical distance-optimal codes, including BCH codes, Reed–Solomon binary images, and some LDPC ensembles, are singled out because sparse low-weight spectra improve the bound. Numerical illustrations using the Reed–Muller 9 and 0 codes show that the spectrum-based right-hand side can be orders of magnitude smaller than 1 for moderate 2 (Meneghetti et al., 2014).
Taken together with the sparse-matrix analysis, these results show two distinct mechanisms for linear extraction. Random sparse transformations rely on probabilistic structure and asymptotic bias decay, whereas fixed code-based maps are governed by algebraic invariants of the underlying code. The latter perspective is especially relevant when deterministic post-processing is required and the matrix cannot be resampled (Zhou et al., 2012, Meneghetti et al., 2014).
4. Affine, additive, and directional forms of linear extraction
Affine sources and additive sources provide a different seedless regime for linear extractors. A line source in 3 is the uniform distribution on an affine line
4
and has min-entropy 5. For every 6 and prime power 7, there is an explicit deterministic extractor
8
such that for every line source 9,
00
By the XOR lemma, this extends to
01
with
02
The construction is based on a norm-polynomial of degree 03 that remains nonconstant on every affine line, reducing the field-size requirement from 04 in earlier work to 05 (Bhowmick et al., 2014).
The same polynomial-plus-Weil-bound method extends to short arithmetic progressions and to constant-dimensional generalized arithmetic progressions. The additive-source model includes arithmetic progressions, generalized arithmetic progressions, and Bohr sets, each of which generalizes affine sources. Over both 06 and 07, explicit extractors are obtained for additive sources with linear min-entropy, although the results over 08 require a list-decodability condition (Bhowmick et al., 2014).
Directional affine extractors strengthen standard affine extractors by requiring pseudorandomness of every nonzero directional derivative. For a function 09 and nonzero direction 10, the derivative is
11
The function is an 12 directional affine extractor if for every nonzero 13 and every affine subspace 14 of dimension at least 15, the distribution 16 has error at most 17 from uniform. In the one-bit case, Gryaznov, Pudlák, and Talebanfard give an explicit triple-trace construction on 18 bits:
19
which is a directional affine extractor with extractor dimension 20, output length 21, and bias 22 (Gryaznov et al., 2022).
A later explicit construction is stated as
23
such that for every 24-dimensional affine source 25 and every nonzero 26,
27
Its parameters are
28
A key ingredient is a new linear somewhere condenser for affine sources based on dimension expanders (Li et al., 2023).
These directional constructions have average-case complexity consequences. If 29 is an 30 directional affine extractor with 31, then any strongly read-once linear branching program 32 of size
33
computes 34 with advantage at most 35 over random guessing:
36
In the later framework, if 37 is a 38-directional affine extractor, then any strongly read-once linear branching program that agrees with 39 on more than 40 fraction of inputs must have size at least 41 (Gryaznov et al., 2022, Li et al., 2023).
5. Rank extractors and linear-algebraic pseudorandomness over finite fields
A seeded lossless rank extractor is a family of linear maps
42
such that, for each seed 43, the map 44 is an 45 matrix over 46, and for every full-rank matrix 47 the number of bad seeds satisfying
48
is at most 49. Equivalently, for every 50-dimensional subspace 51,
52
When only existence of one good seed is required for every 53, the object is called a lossless rank disperser (Guo et al., 15 Apr 2026).
Recent work gives explicit constructions in the small-field regime, where the field size depends only on the rank parameter and is independent of the ambient dimension. Over every non-prime field 54 of size 55, there exist infinitely many 56 for which one gets an explicit 57 lossless extractor with
58
Over prime fields 59 with 60, a similar extractor exists with
61
Over arbitrary small 62, including 63, one can build 64 lossless rank dispersers of size
65
These are the first explicit constructions of lossless rank extractors and weak subspace designs for 66 over fields 67 with 68 and 69 non-prime (Guo et al., 15 Apr 2026).
The constructions are algebraic. One replaces classical polynomial-method constructions by analogues over a function field 70 of genus 71 with many rational places, chooses functions from suitable Riemann–Roch spaces, and evaluates them at rational places to form the extractor matrices. The losslessness argument expands 72 via Cauchy–Binet, uses valuations at a distinguished place 73, and bounds the number of bad seeds by the pole order of a nonzero determinant function. For prime fields, the construction passes through a quadratic extension and then uses explicit hitting sets for symbolic determinants of the form
74
with each 75 of rank at most 76 (Guo et al., 15 Apr 2026).
A complementary Fourier-analytic framework uses 77-biased sets in 78. If 79, then such a set meets every codimension-80 affine subspace. If 81, then its projectivization is a strong 82-blocking set in 83. Through these connections, explicit rank extractors yield weak subspace designs and strong blocking sets, including constructions of size 84 for sufficiently large non-prime fields 85 and 86 for arbitrary 87 via the 88-biased method (Guo et al., 15 Apr 2026).
6. Computational trade-offs and relation to seeded extraction
One motivation for linear extractors is implementation speed. Sparse random matrices are computationally fast, easy to implement using hardware like FPGAs, and attractive in high-speed random number generation. In block-processing mode, one partitions the input stream into blocks of length 89 and computes 90 by a matrix-vector XOR. In streaming mode, one keeps a rolling vector 91 and updates
92
for each new bit 93. The total cost for an 94 extraction is 95 XORs, and with 96 this becomes 97 (Zhou et al., 2012).
The density of the matrix determines the speed trade-off. Sparse-random 98 has density approximately 99, with per-bit processing cost 00 and a simple XOR network. A primitive BCH generator matrix has density 01 and per-bit cost 02. In FPGA terms, sparse-random 03 can be implemented with 04 XOR gates, whereas BCH-based matrices require 05 gates and therefore higher area and power (Zhou et al., 2012).
These deterministic and fixed-matrix approaches sit alongside seeded extractors. A strong seeded extractor is a function
06
such that for every distribution 07 on 08 with 09 and independent uniform seed 10,
11
Recent constructions achieve, for all 12 and 13,
14
with running time 15 after a one-time preprocessing step in the low-16 regime. The same work gives an instantiation of Trevisan’s extractor with evaluation time
17
and therefore truly linear time 18 when
19
These seeded constructions directly yield privacy amplification protocols with communication equal to the seed length (Doron et al., 2024).
The contrast is structural. Sparse linear transformations require no external seed, no look-ahead, and no multiprecision arithmetic, while seeded extractors are defined for every source of min-entropy at least 20 and achieve strong guarantees conditioned on the seed. Within the linear-extractor landscape, the principal axes are therefore the source model, whether a seed is available, the algebraic structure of the map, and the trade-off between explicitness, extraction rate, and evaluation complexity (Zhou et al., 2012, Doron et al., 2024).