---
title: 'MT-GAIP: Multi-Target Group Action Inverse Problem'
url: https://www.emergentmind.com/topics/multi-target-group-action-inverse-problem-mt-gaip
type: topic
---

# MT-GAIP: Multi-Target Group Action Inverse Problem

The Multi-Target Group Action Inverse Problem (MT-GAIP) is a multi-instance inversion problem for a group action. In the isogeny-based cryptographic setting of CSIDH and CSI-FiSh, it asks for a hidden class-group relation connecting some pair among several supersingular elliptic curves, and it functions as the explicit privacy assumption behind the isogeny-based strong designated verifier signature scheme $\mathsf{CSI\text{-}SDVS}$ [2507.14893]. In a broader orbit-recovery usage, the same viewpoint treats MT-GAIP as recovery of an orbit representative from invariant statistics of many transformed copies under a group action, such as translations and rotations in multi-target detection [2101.07709, 2509.11397].

## 1. Formal definition in the class-group action setting

In the CSIDH/CSI-FiSh framework, the algebraic environment is an order $\mathfrak{O}\subset \mathbb{Q}(\sqrt{-p})$ in an imaginary quadratic field, its ideal class group $\mathrm{Cl}(\mathfrak{O})$, and the set $\mathcal{E}ll_p(\mathfrak{O})$ of $\mathbb{F}_p$-isomorphism classes of supersingular elliptic curves $E/\mathbb{F}_p$ satisfying
\[
\operatorname{End}_{\mathbb{F}_p}(E)\cong \mathfrak{O}.
\]
The class group acts on $\mathcal{E}ll_p(\mathfrak{O})$ through
\[
*:\mathrm{Cl}(\mathfrak{O})\times \mathcal{E}ll_p(\mathfrak{O})\to \mathcal{E}ll_p(\mathfrak{O}),
\]
via $\mathfrak{a}*E:=E/S_{\mathfrak{a}}$, where the subgroup
\[
S_{\mathfrak{a}}:=\bigcap_{\alpha\in \mathfrak{a}}\ker(\alpha)
\]
defines an isogeny with kernel $S_{\mathfrak{a}}$. This action is free and transitive, hence a principal homogeneous action [2507.14893].

In the CSIDH-friendly case described for $\mathsf{CSI\text{-}SDVS}$, $\mathrm{Cl}(\mathfrak{O})$ is cyclic with generator $\mathfrak{g}$. Writing $N=\#\mathrm{Cl}(\mathfrak{O})$, every class is $\mathfrak{g}^a$ for some $a\in \mathbb{Z}/N\mathbb{Z}$, and the shorthand
\[
[a]:=\mathfrak{g}^a,\qquad [a]E:=\mathfrak{g}^a * E,\qquad [a][b]E=[a+b]E
\]
is adopted [2507.14893].

Against this background, the single-target Group Action Inverse Problem (GAIP) asks: given curves $E$ and $E'$ with endomorphism ring $\mathfrak{O}$, find an ideal $\mathfrak{a}\subset \mathfrak{O}$ such that
\[
E'=\mathfrak{a}*E.
\]
MT-GAIP generalizes this to several targets. Given supersingular elliptic curves $E_0,E_1,\ldots,E_k$ over $\mathbb{F}_p$ with $\operatorname{End}_{\mathbb{F}_p}(E_i)\cong \mathfrak{O}$ for all $i$, the problem is to find an ideal $\mathfrak{a}\subset \mathfrak{O}$ such that
\[
E_i=\mathfrak{a}*E_j \qquad \text{for some distinct } i,j\in \{0,\ldots,k\}.
\]
Equivalently, in the abstract notation $X=\mathcal{E}ll_p(\mathfrak{O})$ and $G=\mathrm{Cl}(\mathfrak{O})$, one is given multiple targets $E_0,\dots,E_k\in X$ and must recover a nontrivial relation between two of them under the action of $G$ [2507.14893].

The $\mathsf{CSI\text{-}SDVS}$ instantiation fixes a prime
\[
p=4\ell_1\ell_2\cdots \ell_n -1,
\]
with small distinct odd primes $\ell_i$ and $n=74$, and uses the base supersingular curve
\[
E_0: y^2=x^3+x \quad \text{over }\mathbb{F}_p.
\]
Its class number satisfies $N\approx 2^\lambda \approx p^{1/2}$. Concretely, each public curve has the form $[x_i]E_0$ for an unknown exponent $x_i\in \mathbb{Z}_N$, and an MT-GAIP solver must detect indices $i\neq j$ and a class $[a]$ such that
\[
[x_i]E_0=[a][x_j]E_0,
\]
or equivalently $x_i\equiv x_j+a \pmod N$ [2507.14893].

## 2. Relation to GAIP and hardness assumptions

Conceptually, GAIP is a single-pair inversion problem, while MT-GAIP is a multi-target or multi-instance variant in which the adversary may succeed on any one of many possible pairs. In the class-group notation above, GAIP fixes one pair $(E,E')$ and asks for $\mathfrak{a}$ with $E'=\mathfrak{a}*E$; MT-GAIP receives $(E_0,\dots,E_k)$ and asks for indices $i\neq j$ and $\mathfrak{a}$ with $E_i=\mathfrak{a}*E_j$ [2507.14893].

A central point in the CSIDH-based setting is that MT-GAIP is not presented as a fundamentally stronger assumption than GAIP. The cited SeaSign analysis is summarized by the statement that MT-GAIP is tightly reducible to GAIP when the structure of the class group is known, which is the case when $\mathrm{Cl}(\mathfrak{O})$ is known and cyclic. In that regime, solving MT-GAIP efficiently implies an efficient solution to GAIP, and conversely, up to tight reductions. The role of MT-GAIP is therefore not to postulate extra asymptotic hardness, but to capture the natural security condition that arises when many group-action instances are simultaneously present [2507.14893].

The scheme parameters are chosen so that $\#\mathrm{Cl}(\mathfrak{O})=N\approx 2^\lambda$, while the number of targets $k$, or effectively the coordinate count $\eta$, is polynomial in $\lambda$. Within this parameterization, the best known classical algorithms for GAIP and MT-GAIP have complexity $O(\sqrt{N})$, reflecting square-root behavior typical of hidden-shift or group-action inversion problems. The best known quantum algorithms are described through Kuperberg’s hidden shift algorithm, which yields subexponential complexity; the paper further notes that concrete security analyses for this setting study the impact of those attacks on CSIDH parameter choices [2507.14893].

This relation between GAIP and MT-GAIP is directly reflected in the protocol structure. In $\mathsf{CSI\text{-}SDVS}$, the signer public key, verifier public key, and ephemeral or simulated curves all live in the same action space:
\[
\mathsf{pk_S}=\{E_i\}_{i=1}^{\eta},\quad E_i=[s_i]E_0,
\]
\[
\mathsf{pk_V}=\{\hat{E}_i\}_{i=1}^{\eta},\quad \hat{E}_i=[v_i]E_0,
\]
\[
Y_i=[b_i]\hat{E}_i=[b_i+v_i]E_0,
\]
and, in simulation,
\[
Y_i=[r_i]E_i=[r_i+s_i]E_0.
\]
From an adversarial viewpoint, these form a pool of curves of the form $[x]E_0$ for many unknown exponents $x$, and MT-GAIP abstracts the difficulty of discovering any nontrivial action relation among them [2507.14893].

## 3. Role in $\mathsf{CSI\text{-}SDVS}$ security

The isogeny-based strong designated verifier signature scheme $\mathsf{CSI\text{-}SDVS}$ is built from the CSIDH ideal class group action and CSI-FiSh-style signature techniques, and its security claims are Strong Unforgeability under Chosen-Message Attacks (SUF-CMA), Non-Transferability (NT), and Privacy of Signer’s Identity (PSI), all in the random oracle model [2507.14893].

For SUF-CMA, the proof is phrased in the Hard Homogeneous Space model. A successful forger enables the simulator to solve the parallelization problem $(x,y,z)\mapsto g*z$ given $y=g*x$. In the concrete protocol, a valid forgery $\sigma^*=(h^*,\mathbf{z}^*)$ on a message $m^*$ satisfies
\[
Y_i^*=[v_i+z_i^*]E_i,\qquad
h^*=\mathcal{H}(Y_1^*\|\cdots\|Y_\eta^*\|m^*),
\]
and for the correct forgery one can derive
\[
Y_i^*=[b_i^*]\hat{E}_i=[b_i^*+v_i]E_0,\qquad
z_i^*=b_i^*-s_i \bmod N.
\]
Hence
\[
[-z_i^*]Y_i^*=[s_i-b_i^*][b_i^*]\hat{E}_i=[s_i]\hat{E}_i=[s_i+v_i]E_0.
\]
Recovering $[s_i+v_i]E_0$ from the public curves $[s_i]E_0$ and $[v_i]E_0$ is a nontrivial instance of parallelization or vectorization in the same group action. The proof is therefore framed in HHS language, but the underlying hardness is again the same class-group inversion phenomenon captured by GAIP-type assumptions [2507.14893].

NT is established differently. The real-signature and simulated-signature experiments are shown to be identically distributed. In the real case, the signer samples $b_i$ uniformly in $\mathbb{Z}_N$, sets $z_i^{(0)}=b_i^{(0)}-s_i \bmod N$, and hashes curve coefficients corresponding to $[b_i^{(0)}]E_0$. In the simulation, the verifier samples $r_i$ uniformly in $\mathbb{Z}_N$, sets $z_i^{(1)}=r_i^{(1)}-v_i \bmod N$, and hashes curves of the form $[r_i^{(1)}-v_i+s_i]E_0$. In both distributions, each $z_i$ is uniform over $\mathbb{Z}_N$, each curve input to the hash is uniformly distributed in $\mathcal{E}ll_p(\mathfrak{O})$, and the hash output is a random oracle value. NT therefore relies on distributional equivalence rather than directly invoking MT-GAIP [2507.14893].

PSI is the property for which MT-GAIP is invoked explicitly. The PSI game uses two signers with secrets $\{s_i^{(0)}\}$ and $\{s_i^{(1)}\}$, one verifier with secret $\{v_i\}$, both signer key pairs, and the verifier public key. The adversary receives a challenge signature produced by one of the two signers and must identify which signer generated it. A natural distinguishing strategy would be to compute
\[
X_i^{(j)}:=[z_i^{(b)}]E_i^{(j)}
\]
for each candidate signer $j\in\{0,1\}$ and then, if the verifier secret were known, derive
\[
Y_i^{(j)}:=[v_i]X_i^{(j)}
\]
and test whether the corresponding hash value matches the challenge. The obstacle is that the adversary does not know $\{v_i\}$ [2507.14893].

Without $\mathsf{sk_V}$, the adversary only sees many curves of the form
\[
E_i^{(0)}=[s_i^{(0)}]E_0,\qquad
E_i^{(1)}=[s_i^{(1)}]E_0,\qquad
\hat{E}_i=[v_i]E_0,
\]
together with
\[
[z_i^{(b)}]E_i^{(j)}=[z_i^{(b)}+s_i^{(j)}]E_0.
\]
To succeed, it would need to compute, for the correct signer index $j=b$,
\[
Y_i^{(b)}=[v_i]X_i^{(b)}=[v_i+z_i^{(b)}+s_i^{(b)}]E_0,
\]
or equivalently recover
\[
[s_i^{(b)}+v_i]E_0=[-z_i^{(b)}]Y_i^{(b)}.
\]
That task is precisely the recovery of a hidden action relation among multiple observed curves. The theorem is therefore stated as: if MT-GAIP is hard, then $\mathsf{CSI\text{-}SDVS}$ satisfies PSI security [2507.14893].

## 4. Multi-target structure, compactness, and protocol design

The “multi-target” qualifier is technically motivated by the protocol architecture. $\mathsf{CSI\text{-}SDVS}$ employs vectors of size $\eta$ in keys and signatures:
\[
\mathsf{sk_S}=\{s_i\}_{i=1}^{\eta},\quad
\mathsf{pk_S}=\{[s_i]E_0\}_{i=1}^{\eta},
\]
\[
\mathsf{sk_V}=\{v_i\}_{i=1}^{\eta},\quad
\mathsf{pk_V}=\{[v_i]E_0\}_{i=1}^{\eta},
\]
and signatures contain $\mathbf{z}=\{z_i\}_{i=1}^{\eta}$, while the hash input depends on $\eta$ curves $Y_i$. The adversary thus observes many simultaneously related curves of the form $[x]E_0$, and MT-GAIP is the natural abstraction for exploiting any relation among them [2507.14893].

The same abstraction extends to a multi-key, multi-signature environment. Public curves arise from multiple signers, multiple verifiers, and multiple transcripts, so the relevant attack surface is a large pool of group-action instances rather than a single isolated inversion problem. PSI, in particular, compares two candidate signers simultaneously and turns anonymity into a question of identifying which signer’s public curves are related to the verifier’s curves through hidden exponents. The use of MT-GAIP therefore reflects protocol semantics rather than merely proof convenience [2507.14893].

This architecture is also tied to the compactness claim of the scheme. The class-group action permits a scalar-like representation of secrets, with
\[
s_i,v_i,z_i\in \mathbb{Z}_N,
\]
and curves represented by a single Montgomery coefficient $A\in \mathbb{F}_p$. Since $\log N=\lambda$ and $\log p=\Theta(\lambda)$, the sizes are linear in $\lambda$:
\[
\text{secret key size}=\eta\cdot \lambda=\mathcal{O}(\lambda),
\]
\[
\text{public key size}=\eta\cdot \log p=\mathcal{O}(\lambda),
\]
\[
\text{signature size}=\lambda+\eta\cdot \lambda=\mathcal{O}(\lambda).
\]
The paper contrasts this with the typical $\mathcal{O}(\lambda^2)$ size behavior of existing post-quantum SDVS constructions based on lattices, where dimensions scale with $\lambda$ [2507.14893].

The concrete parameter choice follows CSI-FiSh and CSI-SharK by taking $\eta=16$ for 128-bit security, balancing soundness, key size, and computation; larger values such as $\eta=32$ are noted as a way to reduce statistical soundness error at linear size cost. On this basis, $\mathsf{CSI\text{-}SDVS}$ is described as having both keys and signatures of size $\mathcal{O}(\lambda)$, as among the most compact PQC-based SDVS schemes, and as the only post-quantum secure construction based on isogenies [2507.14893].

## 5. Complexity-theoretic status and related problem variants

A complementary line of work studies GAIP-type problems as computational problems for effective group actions. In that framework, a group action $(G,X,\star)$ is required to support polynomial-time membership, equality, sampling, group operations, inversion, and action evaluation, while $X$ has efficient membership testing and unique representation. For regular actions, the map $f_x:G\to X$, $g\mapsto g\star x$, is a bijection, and GAIP is the total search problem: given $x,y\in X$, find $g\in G$ such that
\[
x=g\star y.
\]
The paper also defines the Multiple Group Action Inverse Problem (mGAIP), in which one receives polynomially many pairs
\[
Q=\{(x_i,y_i)\}_{i=1}^{q(\lambda)}
\]
and must find a single $g\in G$ satisfying
\[
x_i=g\star y_i \quad \text{for all } i,
\]
as well as the Pseudorandom Group Action Inverse Problem (pGAIP) and the orbit-membership decision problem dGAIP for non-transitive actions [2202.13810].

For regular effective actions, GAIP, mGAIP, and pGAIP are shown to be nonadaptively $1$-random self-reducible. This yields a worst-case/average-case equivalence: solving a noticeable fraction of random instances suffices, via self-reduction, to solve arbitrary instances with high probability. The same work concludes that if GAIP, mGAIP, or pGAIP were NP-hard, then the Polynomial Hierarchy would collapse at the third level. For dGAIP, an interactive proof places the problem in $\co\mathrm{AM}$, and since dGAIP is also in $\mathrm{NP}$, it lies in $\mathrm{NP}\cap \co\mathrm{AM}\subseteq \mathrm{L}_2^P$; if dGAIP were NP-complete, then the Polynomial Hierarchy would collapse to the second level [2202.13810].

These results position GAIP-type assumptions as structurally similar to Graph Isomorphism and other NP-intermediate candidates rather than as NP-complete problems. Indeed, dGAIP subsumes orbit problems such as Graph Isomorphism, permutation code equivalence, deck checking, and Boolean isomorphism under suitable group actions [2202.13810].

That paper does not formally define the cryptographic MT-GAIP of the CSIDH literature. Instead, it introduces mGAIP, where many pairs share one hidden group element, and then describes a more general multi-target GAIP with independent secrets as a natural extension. The stated guidance is that the same random self-reduction ideas operate componentwise and that decision analogues would likely inherit similar $\mathrm{AM}$ or $\co\mathrm{AM}$ upper bounds. This suggests that multi-target GAIP variants should be viewed as parallel or multi-instance extensions of GAIP rather than as qualitatively different complexity classes [2202.13810].

## 6. Broader orbit-recovery interpretations in signal processing and inverse problems

Outside isogeny-based cryptography, group-action inversion appears in multi-target detection and related orbit-recovery models. In the two-dimensional detection model with rotations, the measurement is
\[
M(x)=\sum_{j=1}^p F_{\phi_j}(x-x_j)+\varepsilon(x),\qquad x\in \{1,\dots,m\}^2,
\]
where $f:\mathbb{R}^2\to \mathbb{R}$ is a single underlying target, $F_\phi$ is its discretized rotation, $\phi_j$ are i.i.d. uniform on $[0,2\pi)$, translations satisfy a separation condition, and the noise is i.i.d. Gaussian. This can be written as a group-action model with
\[
G=\mathbb{Z}^2\rtimes SO(2),
\]
acting by $(g\cdot F)(x)=F_\phi(x-t)$. In that paper’s terminology, “multi-target” means many occurrences of one target in the measurement rather than multiple distinct templates [2101.07709].

The principal methodological move is to avoid estimating the individual group elements and instead estimate group-invariant statistics. The invariant features are rotationally and translationally averaged first-, second-, and third-order autocorrelations. In one dimension, the third-order invariant
\[
V_F(x_1,x_2)
\]
determines $F$ up to circular shift when the discrete Fourier coefficients are all nonzero. The empirical third-order autocorrelation of the measurement,
\[
A_M(x_1,x_2)=\frac{1}{m}\sum_{x=1}^m M(x)M(x+x_1 \bmod m)M(x+x_2 \bmod m),
\]
has expectation proportional to $V_F$ up to explicit noise-bias terms, and its variance decays like
\[
\mathcal{O}\!\left(\frac{n}{m}(\gamma F_{\max}^6+\sigma^6)\right).
\]
Thus, for fixed noise variance, density, and support size, the target is consistently estimable as the measurement size grows, without recovering the shifts or rotations of individual copies [2101.07709].

In two dimensions, the analogous invariant is the discrete rotationally averaged third-order autocorrelation
\[
S_F(x_1,x_2)=\frac{1}{2\pi}\int_0^{2\pi}\frac{1}{4n^2}\sum_{x\in \mathbb{Z}^2} F_\phi(x)F_\phi(x+x_1)F_\phi(x+x_2)\,d\phi,
\]
and the reconstruction algorithm expands the target in a steerable Dirichlet eigenbasis
\[
\psi_{\nu,q}(r,\theta)=J_\nu(\lambda_{\nu,q}r)e^{i\nu\theta},
\]
expresses the Fourier transform of $S_F$ as a rotation-averaged bispectrum, and minimizes a nonconvex least-squares objective by BFGS. The 2D theory is not accompanied by a full identifiability theorem analogous to the 1D theorem, but noise-free and noisy experiments show accurate recovery from the invariant statistics [2101.07709].

A subsequent moment-based line of work casts multi-target detection explicitly as recovery from low-order moments, again in a translation group-action model
\[
y[\ell]=\sum_{m=1}^M x[\ell-\ell_m]+\varepsilon[\ell],
\]
or, in super-resolution form,
\[
y[\ell]=\sum_{m=1}^M x^{\mathrm{low}}[\ell-\ell_m]+\varepsilon[\ell],\qquad x^{\mathrm{low}}=Px.
\]
The order-$q$ autocorrelations $a_x^q$ are homogeneous polynomials of degree $q$ in the pixels of $x$, and the inverse problem is formulated through the moment equations
\[
a_y^q[\ell_1,\ldots,\ell_{q-1}]
=
\gamma\, a_x^q[\ell_1,\ldots,\ell_{q-1}] + b_q[\ell_1,\ldots,\ell_{q-1}],
\qquad q=1,2,3.
\]
The corresponding loss
\[
\mathcal{L}_\gamma(x,y)
=
\sum_{q=1}^3
\sum_{\ell_1,\dots,\ell_{q-1}}
\big(
a_y^q-\gamma a_x^q-b_q
\big)^2
\]
defines a polynomial inverse problem whose conditioning deteriorates in high noise and in super-resolution settings [2509.11397].

That work regularizes the invariant-matching problem with a score-based diffusion prior. The optimization target is
\[
\hat{x}=\arg\min_x \left\{\mathcal{L}_\gamma(x,y)-\lambda \log p(x)\right\},
\]
where the prior gradient is approximated by a score network $s_\theta(x)\approx \nabla_x \log p(x)$. The proposed accelerated gradient scheme combines the moment gradient with an adaptively scaled score term. Empirically, the paper reports two main findings: diffusion priors substantially improve recovery from third-order moments, and they make the super-resolution multi-target detection problem feasible, while the underlying identifiability basis remains the earlier result that autocorrelations up to third order uniquely determine a generic two-dimensional target in the well-separated model [2509.11397].

Taken together, these signal-processing papers suggest a broader use of the MT-GAIP viewpoint: a group action generates many transformed copies of an unknown object, low-order invariants are estimated directly from aggregate noisy data, and inversion proceeds by recovering the orbit representative rather than the individual nuisance transformations. In cryptography, MT-GAIP names a precise class-group inversion problem; in orbit recovery, it serves as a natural conceptual template for invariant-based reconstruction under group actions [2101.07709, 2509.11397].

Source: https://www.emergentmind.com/topics/multi-target-group-action-inverse-problem-mt-gaip