A History of the PCP Theorem
Total Page:16
File Type:pdf, Size:1020Kb
Load more
Recommended publications
-
Arxiv:2104.04742V2 [Quant-Ph] 13 Apr 2021 Keywords: Quantum Cryptography, Remote State Preparation, Zero-Knowledge, Learning with Errors Table of Contents
Non-Destructive Zero-Knowledge Proofs on Quantum States, and Multi-Party Generation of Authorized Hidden GHZ States Léo Colisson 1, Frédéric Grosshans 1, Elham Kashefi1,2 1 Laboratoire d’Informatique de Paris 6 (LIP6), Sorbonne Université, 4 Place Jussieu, 75252 Paris CEDEX 05, France {leo.colisson, frederic.grosshans}@lip6.fr 2 School of Informatics, University of Edinburgh, 10 Crichton Street, Edinburgh EH8 9AB, UK Abstract. Due to the special no-cloning principle, quantum states appear to be very useful in cryptography. But this very same property also has drawbacks: when receiving a quantum state, it is nearly impossible for the receiver to efficiently check non-trivial properties on that state without destroying it. This allows a malicious sender to send maliciously crafted states without being detected. The natural (destructive) method for testing a quantum state is the “cut-and-choose” method. However, this method has many drawbacks: the security is only linear, and the class of states and properties that can be tested is quite restricted. In this work, we propose a different approach, and we initiate the study of Non-Destructive Zero-Knowledge Proofs on Quantum States. Our method binds a quantum state to a classical encryption of that quantum state. That way, the receiver can obtain guarantees on the quantum state by asking to the sender to prove properties directly on the classical encryption. This method is therefore non-destructive, and it is possible to verify a very large class of properties. For instance, we can force the sender to send different categories of states depending on whether they know a classical password or not. -
Zig-Zag Product
High Dimensional Expanders Lecture 12: Agreement Tests Lecture by: Irit Dinur Scribe: Irit Dinur In this lecture we describe agreement tests, which are a generalization of direct product tests and low degree tests, both of which play a role in PCP constructions. It turns out that the underlying structures that support agreement tests are invariably some kind of high dimensional expander, as we shall see. 1 General Setup It is a basic fact of computation that any global computation can be broken down into a sequence of local steps. The PCP theorem [AS98, ALM+98] says that moreover, this can be done in a robust fashion, so that as long as most steps are correct, the entire computation checks out. At the heart of this is a local-to-global argument that allows deducing a global property from local pieces that fit together only approximately. In an agreement test, a function is given by an ensemble of local restrictions. The agreement test checks that the restrictions agree when they overlap, and the main question is whether typical agreement of the local pieces implies that there exists a global function that agrees with most local restrictions. Let us describe the basic framework, consisting of a quadruple (V; X; fFSgS2X ; D). • Ground set: Let V be a set of n points (or vertices). • Collection of small subsets: Let X be a collection of subsets S ⊂ V , typically for each S 2 X we have jSj n. • Local functions: for each subset S 2 X, there is a space FS ⊂ ff : S ! Σg of functions on S. -
Interactive Proof Systems and Alternating Time-Space Complexity
Theoretical Computer Science 113 (1993) 55-73 55 Elsevier Interactive proof systems and alternating time-space complexity Lance Fortnow” and Carsten Lund** Department of Computer Science, Unicersity of Chicago. 1100 E. 58th Street, Chicago, IL 40637, USA Abstract Fortnow, L. and C. Lund, Interactive proof systems and alternating time-space complexity, Theoretical Computer Science 113 (1993) 55-73. We show a rough equivalence between alternating time-space complexity and a public-coin interactive proof system with the verifier having a polynomial-related time-space complexity. Special cases include the following: . All of NC has interactive proofs, with a log-space polynomial-time public-coin verifier vastly improving the best previous lower bound of LOGCFL for this model (Fortnow and Sipser, 1988). All languages in P have interactive proofs with a polynomial-time public-coin verifier using o(log’ n) space. l All exponential-time languages have interactive proof systems with public-coin polynomial-space exponential-time verifiers. To achieve better bounds, we show how to reduce a k-tape alternating Turing machine to a l-tape alternating Turing machine with only a constant factor increase in time and space. 1. Introduction In 1981, Chandra et al. [4] introduced alternating Turing machines, an extension of nondeterministic computation where the Turing machine can make both existential and universal moves. In 1985, Goldwasser et al. [lo] and Babai [l] introduced interactive proof systems, an extension of nondeterministic computation consisting of two players, an infinitely powerful prover and a probabilistic polynomial-time verifier. The prover will try to convince the verifier of the validity of some statement. -
On the Randomness Complexity of Interactive Proofs and Statistical Zero-Knowledge Proofs*
On the Randomness Complexity of Interactive Proofs and Statistical Zero-Knowledge Proofs* Benny Applebaum† Eyal Golombek* Abstract We study the randomness complexity of interactive proofs and zero-knowledge proofs. In particular, we ask whether it is possible to reduce the randomness complexity, R, of the verifier to be comparable with the number of bits, CV , that the verifier sends during the interaction. We show that such randomness sparsification is possible in several settings. Specifically, unconditional sparsification can be obtained in the non-uniform setting (where the verifier is modelled as a circuit), and in the uniform setting where the parties have access to a (reusable) common-random-string (CRS). We further show that constant-round uniform protocols can be sparsified without a CRS under a plausible worst-case complexity-theoretic assumption that was used previously in the context of derandomization. All the above sparsification results preserve statistical-zero knowledge provided that this property holds against a cheating verifier. We further show that randomness sparsification can be applied to honest-verifier statistical zero-knowledge (HVSZK) proofs at the expense of increasing the communica- tion from the prover by R−F bits, or, in the case of honest-verifier perfect zero-knowledge (HVPZK) by slowing down the simulation by a factor of 2R−F . Here F is a new measure of accessible bit complexity of an HVZK proof system that ranges from 0 to R, where a maximal grade of R is achieved when zero- knowledge holds against a “semi-malicious” verifier that maliciously selects its random tape and then plays honestly. -
Ab Pcpchap.Pdf
i Computational Complexity: A Modern Approach Sanjeev Arora and Boaz Barak Princeton University http://www.cs.princeton.edu/theory/complexity/ [email protected] Not to be reproduced or distributed without the authors’ permission ii Chapter 11 PCP Theorem and Hardness of Approximation: An introduction “...most problem reductions do not create or preserve such gaps...To create such a gap in the generic reduction (cf. Cook)...also seems doubtful. The in- tuitive reason is that computation is an inherently unstable, non-robust math- ematical object, in the the sense that it can be turned from non-accepting to accepting by changes that would be insignificant in any reasonable metric.” Papadimitriou and Yannakakis [PY88] This chapter describes the PCP Theorem, a surprising discovery of complexity theory, with many implications to algorithm design. Since the discovery of NP-completeness in 1972 researchers had mulled over the issue of whether we can efficiently compute approxi- mate solutions to NP-hard optimization problems. They failed to design such approxima- tion algorithms for most problems (see Section 1.1 for an introduction to approximation algorithms). They then tried to show that computing approximate solutions is also hard, but apart from a few isolated successes this effort also stalled. Researchers slowly began to realize that the Cook-Levin-Karp style reductions do not suffice to prove any limits on ap- proximation algorithms (see the above quote from an influential Papadimitriou-Yannakakis paper that appeared a few years before the discoveries described in this chapter). The PCP theorem, discovered in 1992, gave a new definition of NP and provided a new starting point for reductions. -
Challenges in Web Search Engines
Challenges in Web Search Engines Monika R. Henzinger Rajeev Motwani* Craig Silverstein Google Inc. Department of Computer Science Google Inc. 2400 Bayshore Parkway Stanford University 2400 Bayshore Parkway Mountain View, CA 94043 Stanford, CA 94305 Mountain View, CA 94043 [email protected] [email protected] [email protected] Abstract or a combination thereof. There are web ranking optimiza• tion services which, for a fee, claim to place a given web site This article presents a high-level discussion of highly on a given search engine. some problems that are unique to web search en• Unfortunately, spamming has become so prevalent that ev• gines. The goal is to raise awareness and stimulate ery commercial search engine has had to take measures to research in these areas. identify and remove spam. Without such measures, the qual• ity of the rankings suffers severely. Traditional research in information retrieval has not had to 1 Introduction deal with this problem of "malicious" content in the corpora. Quite certainly, this problem is not present in the benchmark Web search engines are faced with a number of difficult prob• document collections used by researchers in the past; indeed, lems in maintaining or enhancing the quality of their perfor• those collections consist exclusively of high-quality content mance. These problems are either unique to this domain, or such as newspaper or scientific articles. Similarly, the spam novel variants of problems that have been studied in the liter• problem is not present in the context of intranets, the web that ature. Our goal in writing this article is to raise awareness of exists within a corporation. -
Lecture 19,20 (Nov 15&17, 2011): Hardness of Approximation, PCP
,20 CMPUT 675: Approximation Algorithms Fall 2011 Lecture 19,20 (Nov 15&17, 2011): Hardness of Approximation, PCP theorem Lecturer: Mohammad R. Salavatipour Scribe: based on older notes 19.1 Hardness of Approximation So far we have been mostly talking about designing approximation algorithms and proving upper bounds. From no until the end of the course we will be talking about proving lower bounds (i.e. hardness of approximation). We are familiar with the theory of NP-completeness. When we prove that a problem is NP-hard it implies that, assuming P=NP there is no polynomail time algorithm that solves the problem (exactly). For example, for SAT, deciding between Yes/No is hard (again assuming P=NP). We would like to show that even deciding between those instances that are (almost) satisfiable and those that are far from being satisfiable is also hard. In other words, create a gap between Yes instances and No instances. These kinds of gaps imply hardness of approximation for optimization version of NP-hard problems. In fact the PCP theorem (that we will see next lecture) is equivalent to the statement that MAX-SAT is NP- hard to approximate within a factor of (1 + ǫ), for some fixed ǫ> 0. Most of hardness of approximation results rely on PCP theorem. For proving a hardness, for example for vertex cover, PCP shows that the existence of following reduction: Given a formula ϕ for SAT, we build a graph G(V, E) in polytime such that: 2 • if ϕ is a yes-instance, then G has a vertex cover of size ≤ 3 |V |; 2 • if ϕ is a no-instance, then every vertex cover of G has a size > α 3 |V | for some fixed α> 1. -
2020 SIGACT REPORT SIGACT EC – Eric Allender, Shuchi Chawla, Nicole Immorlica, Samir Khuller (Chair), Bobby Kleinberg September 14Th, 2020
2020 SIGACT REPORT SIGACT EC – Eric Allender, Shuchi Chawla, Nicole Immorlica, Samir Khuller (chair), Bobby Kleinberg September 14th, 2020 SIGACT Mission Statement: The primary mission of ACM SIGACT (Association for Computing Machinery Special Interest Group on Algorithms and Computation Theory) is to foster and promote the discovery and dissemination of high quality research in the domain of theoretical computer science. The field of theoretical computer science is the rigorous study of all computational phenomena - natural, artificial or man-made. This includes the diverse areas of algorithms, data structures, complexity theory, distributed computation, parallel computation, VLSI, machine learning, computational biology, computational geometry, information theory, cryptography, quantum computation, computational number theory and algebra, program semantics and verification, automata theory, and the study of randomness. Work in this field is often distinguished by its emphasis on mathematical technique and rigor. 1. Awards ▪ 2020 Gödel Prize: This was awarded to Robin A. Moser and Gábor Tardos for their paper “A constructive proof of the general Lovász Local Lemma”, Journal of the ACM, Vol 57 (2), 2010. The Lovász Local Lemma (LLL) is a fundamental tool of the probabilistic method. It enables one to show the existence of certain objects even though they occur with exponentially small probability. The original proof was not algorithmic, and subsequent algorithmic versions had significant losses in parameters. This paper provides a simple, powerful algorithmic paradigm that converts almost all known applications of the LLL into randomized algorithms matching the bounds of the existence proof. The paper further gives a derandomized algorithm, a parallel algorithm, and an extension to the “lopsided” LLL. -
Program Sunday Evening: Welcome Recep- Tion from 7Pm to 9Pm at the Staff Lounge of the Department of Computer Science, Ny Munkegade, Building 540, 2Nd floor
Computational ELECTRONIC REGISTRATION Complexity The registration for CCC’03 is web based. Please register at http://www.brics.dk/Complexity2003/. Registration Fees (In Danish Kroner) Eighteenth Annual IEEE Conference Advance† Late Members‡∗ 1800 DKK 2200 DKK ∗ Sponsored by Nonmembers 2200 DKK 2800 DKK Students+ 500 DKK 600 DKK The IEEE Computer Society ∗The registration fee includes a copy of the proceedings, Technical Committee on receptions Sunday and Monday, the banquet Wednesday, and lunches Monday, Tuesday and Wednesday. Mathematical Foundations +The registration fee includes a copy of the proceedings, of Computing receptions Sunday and Monday, and lunches Monday, Tuesday and Wednesday. The banquet Wednesday is not included. †The advance registration deadline is June 15. ‡ACM, EATCS, IEEE, or SIGACT members. Extra proceedings/banquet tickets Extra proceedings are 350 DKK. Extra banquet tick- ets are 300 DKK. Both can be purchased when reg- istering and will also be available for sale on site. Alternative registration If electronic registration is not possible, please con- tact the organizers at one of the following: E-mail: [email protected] Mail: Complexity 2003 c/o Peter Bro Miltersen In cooperation with Department of Computer Science University of Aarhus ACM-SIGACT and EATCS Ny Munkegade, Building 540 DK 8000 Aarhus C, Denmark Fax: (+45) 8942 3255 July 7–10, 2003 Arhus,˚ Denmark Conference homepage Conference Information Information about this year’s conference is available Location All sessions of the conference and the on the Web at Kolmogorov workshop will be held in Auditorium http://www.brics.dk/Complexity2003/ F of the Department of Mathematical Sciences at Information about the Computational Complexity Aarhus University, Ny Munkegade, building 530, 1st conference is available at floor. -
Interactive Proofs
Interactive proofs April 12, 2014 [72] L´aszl´oBabai. Trading group theory for randomness. In Proc. 17th STOC, pages 421{429. ACM Press, 1985. doi:10.1145/22145.22192. [89] L´aszl´oBabai and Shlomo Moran. Arthur-Merlin games: A randomized proof system and a hierarchy of complexity classes. J. Comput. System Sci., 36(2):254{276, 1988. doi:10.1016/0022-0000(88)90028-1. [99] L´aszl´oBabai, Lance Fortnow, and Carsten Lund. Nondeterministic ex- ponential time has two-prover interactive protocols. In Proc. 31st FOCS, pages 16{25. IEEE Comp. Soc. Press, 1990. doi:10.1109/FSCS.1990.89520. See item 1991.108. [108] L´aszl´oBabai, Lance Fortnow, and Carsten Lund. Nondeterministic expo- nential time has two-prover interactive protocols. Comput. Complexity, 1 (1):3{40, 1991. doi:10.1007/BF01200056. Full version of 1990.99. [136] Sanjeev Arora, L´aszl´oBabai, Jacques Stern, and Z. (Elizabeth) Sweedyk. The hardness of approximate optima in lattices, codes, and systems of linear equations. In Proc. 34th FOCS, pages 724{733, Palo Alto CA, 1993. IEEE Comp. Soc. Press. doi:10.1109/SFCS.1993.366815. Conference version of item 1997:160. [160] Sanjeev Arora, L´aszl´oBabai, Jacques Stern, and Z. (Elizabeth) Sweedyk. The hardness of approximate optima in lattices, codes, and systems of linear equations. J. Comput. System Sci., 54(2):317{331, 1997. doi:10.1006/jcss.1997.1472. Full version of 1993.136. [111] L´aszl´oBabai, Lance Fortnow, Noam Nisan, and Avi Wigderson. BPP has subexponential time simulations unless EXPTIME has publishable proofs. In Proc. -
Input-Oblivious Proof Systems and a Uniform Complexity Perspective on P/Poly
Electronic Colloquium on Computational Complexity, Report No. 23 (2011) Input-Oblivious Proof Systems and a Uniform Complexity Perspective on P/poly Oded Goldreich∗ and Or Meir† Department of Computer Science Weizmann Institute of Science Rehovot, Israel. February 16, 2011 Abstract We initiate a study of input-oblivious proof systems, and present a few preliminary results regarding such systems. Our results offer a perspective on the intersection of the non-uniform complexity class P/poly with uniform complexity classes such as NP and IP. In particular, we provide a uniform complexity formulation of the conjecture N P 6⊂ P/poly and a uniform com- plexity characterization of the class IP∩P/poly. These (and similar) results offer a perspective on the attempt to prove circuit lower bounds for complexity classes such as NP, PSPACE, EXP, and NEXP. Keywords: NP, IP, PCP, ZK, P/poly, MA, BPP, RP, E, NE, EXP, NEXP. Contents 1 Introduction 1 1.1 The case of NP ....................................... 1 1.2 Connection to circuit lower bounds ............................ 2 1.3 Organization and a piece of notation ........................... 3 2 Input-Oblivious NP-Proof Systems (ONP) 3 3 Input-Oblivious Interactive Proof Systems (OIP) 5 4 Input-Oblivious Versions of PCP and ZK 6 4.1 Input-Oblivious PCP .................................... 6 4.2 Input-Oblivious ZK ..................................... 7 Bibliography 10 ∗Partially supported by the Israel Science Foundation (grant No. 1041/08). †Research supported by the Adams Fellowship Program of the Israel Academy of Sciences and Humanities. ISSN 1433-8092 1 Introduction Various types of proof systems play a central role in the theory of computation. -
Calibrating Noise to Sensitivity in Private Data Analysis
Calibrating Noise to Sensitivity in Private Data Analysis Cynthia Dwork1, Frank McSherry1, Kobbi Nissim2, and Adam Smith3? 1 Microsoft Research, Silicon Valley. {dwork,mcsherry}@microsoft.com 2 Ben-Gurion University. [email protected] 3 Weizmann Institute of Science. [email protected] Abstract. We continue a line of research initiated in [10, 11] on privacy- preserving statistical databases. Consider a trusted server that holds a database of sensitive information. Given a query function f mapping databases to reals, the so-called true answer is the result of applying f to the database. To protect privacy, the true answer is perturbed by the addition of random noise generated according to a carefully chosen distribution, and this response, the true answer plus noise, is returned to the user. Previous work focused on the case of noisy sums, in which f = P i g(xi), where xi denotes the ith row of the database and g maps database rows to [0, 1]. We extend the study to general functions f, proving that privacy can be preserved by calibrating the standard devi- ation of the noise according to the sensitivity of the function f. Roughly speaking, this is the amount that any single argument to f can change its output. The new analysis shows that for several particular applications substantially less noise is needed than was previously understood to be the case. The first step is a very clean characterization of privacy in terms of indistinguishability of transcripts. Additionally, we obtain separation re- sults showing the increased value of interactive sanitization mechanisms over non-interactive.