On Approximating the Covering Radius and Finding Dense Lattice Subspaces
|
|
- Cecil Shelton
- 5 years ago
- Views:
Transcription
1 On Approximating the Covering Radius and Finding Dense Lattice Subspaces Daniel Dadush Centrum Wiskunde & Informatica (CWI) ICERM April 2018
2 Outline 1. Integer Programming and the Kannan-Lovász (KL) Conjecture. 2. l 2 KL Conjecture & the Reverse Minkowski Conjecture. 3. Finding dense lattice subspaces.
3 Integer Programming (IP) min cx s.t. Ax b x ε Z n n variables, m constraints K c Open Question: Is there a 2 O(n) time algorithm? First result: 2 O(n2) [Lenstra `83] Best known complexity: n O(n) [Kannan `87]
4 Main Dichotomy μ K, Z n every shift smallest scaling s such that sk + t contains an integer point. K Z 2 Either covering radius μ K, Z n 1.
5 Main Dichotomy μ K, Z n every shift smallest scaling s such that sk + t contains an integer point. K Z 2 Either covering radius μ K, Z n 1.
6 Main Dichotomy μ K, Z n every shift smallest scaling s such that sk + t contains an integer point. K Z 2 Either covering radius μ K, Z n 1.
7 Main Dichotomy μ K, Z n every shift smallest scaling s such that sk + t contains an integer point. μ K, Z 2 = K Z 2 Either covering radius μ K, Z n 1.
8 Main Dichotomy Can find integer point in 2 O(n) time [D. 12] K Z 2 Either covering radius μ K, Z n 1.
9 Main Dichotomy Or K is flat : Projection on y-axis P = (0 1) K Z 2 There exists rank k 1 integer projection P Z n k such vol k PK 1 k is small.
10 Main Dichotomy Or K is flat : Projection on y-axis P = (0 1) K Z 2 There exists rank k 1 integer projection P Z n k such vol k PK 1 k is small.
11 Main Dichotomy Or K is flat : Recurse on vol k PK subproblems [D. 12] K Z 2 There exists rank k 1 integer projection P Z n k such vol k PK 1 k is small.
12 Duality Relation 1 μ K, Z n min P Z k n rk P =k 1 vol k PK 1 k? Easy side Hard side Either covering radius μ(k, Z n ) is small or K is flat.
13 Khinchine Flatness Theorem K 1 μ K, Z n 4 min vol P Z 1 n 1 (PK) O(n Τ3 ) rk P =1 [Khinchine `48, Babai `86, Hastad `86, Lenstra-Lagarias- Schnorr `87, Kannan-Lovasz `88, Banaszczyk `93-96, Banaszczyk-Litvak-Pajor-Szarek `99, Rudelson `00]
14 Kannan-Lovász Flatness Theorem K 1 μ K, Z n min P Z k n rk P =k 1 vol k PK 1 k n [Kannan `87, Kannan-Lovász `88]
15 Kannan-Lovász (KL) Conjecture K 1 μ K, Z n min vol k PK 1 k O log n!! P Z k n rk P =k 1
16 Faster Algorithm for IP? 1 μ K, Z n min P Z k n rk P =k 1 vol k PK 1 k O log n D. `12: Assuming KL conjecture + P computable in (log n) O(n) time then there is log n O(n) time algorithm for IP.
17 l 2 Kannan-Lovász Conjecture Does the conjecture hold for ellipsoids? E 0 Z n An ellipsoid is E = TB 2 n
18 l 2 Kannan-Lovász Conjecture Answer: YES* [Regev-S.Davidowitz 17] 0 E * up to polylogarithmic factors Z n
19 l 2 Kannan-Lovász Conjecture Can we compute the projection P? E 0 Z n THIS TALK: YES, in 2 O(n) time.
20 Outline 1. Integer Programming and the Kannan-Lovász (KL) Conjecture. 2. l 2 KL Conjecture & the Reverse Minkowski Conjecture. 3. Finding dense lattice subspaces.
21 l 2 Kannan-Lovász Conjecture Easier to think of Euclidean ball vs general lattice. TE = B 2 n 0 L = TZ n
22 Lattices A lattice L R n is BZ n for a basis B = b 1,, b n. L(B) denotes the lattice generated by B. Note: a lattice has many equivalent bases. b 1 b 1 b 2 b 2 b 2 L
23 Lattices A lattice L R n is BZ n for a basis B = b 1,, b n. L(B) denotes the lattice generated by B. The determinant of L is det B. b 1 b 2 L
24 Lattices A lattice L R n is BZ n for a basis B = b 1,, b n. L(B) denotes the lattice generated by B. The determinant of L is det B. Equal to volume of any tiling set. b 1 b 2 L
25 l 2 Covering Radius μ L μ B 2 n, L Distance of farthest point to the lattice L. μ V L Voronoi cell V all points closer to 0
26 Volumetric Lower Bounds vol n B 2 n μ L vol n V = det(l) μ V Voronoi cell V all points closer to 0 L
27 Volumetric Lower Bounds μ(l) vol n B 2 n 1 n det L 1 n μ V L Voronoi cell V all points closer to 0
28 Volumetric Lower Bounds μ(l) n det L 1 n μ V Voronoi cell V all points closer to 0 L
29 Volumetric Lower Bounds μ L μ L W μ W μ W L L W projection onto W
30 Volumetric Lower Bounds μ L μ L W k det L W 1 k μ W μ W L L W projection onto W dim(w) = k 1
31 Volumetric Lower Bounds μ L max dim W =k 1 k det L W 1 k μ W μ W L L W projection onto W dim(w) = k 1
32 l 2 Kannan-Lovász Conjecture Define C KL,2 (n) to be smallest number such that μ L C KL,2 (n) max dim W =k 1 k det L W 1 k for all lattices of dimension at most n. C KL,2 n = Ω( log n) Lower bound for L with basis e 1, 1 2 e 2,, 1 n e n.
33 KL Bounds μ L C KL,2 (n) max dim W =k 1 k det L W 1 k Kannan-Lovász `88: n D. Regev `16: log O(1) n Assuming Reverse Minkowski Conjecture. Regev, S.Davidowitz `17: log Τ 3 2 n Reverse Minkowski Conjecture is proved!
34 Our Results n dimensional lattice L L(B) 1. Can compute subspace W, dim W = k 1 μ L O(log n) k det L W k in 2 O(n) time with high probability. Prior work: Kannan Lovász `88: n in 2 O(n) time. D. Micciancio `13: best subspace in n O(n2) time.
35 Our Results n dimensional lattice L L(B) 2. Can combine lower bounds over different subspaces to certify μ L up to the slicing constant L n for stable Voronoi cells*. * If vol n V = 1 can find hyperplane H s.t. vol n 1 V H = Ω( 1 Ln ) H V
36 Our Results n dimensional lattice L L(B) 2. Can combine lower bounds over different subspaces to certify μ L up to the slicing constant L n for stable Voronoi cells*. Slicing Conjecture: L n = O(1) for all convex bodies! For stable Voronoi cells: L n = O(log n) [RS `17] H V
37 Notation M L sublattice of dimension k Convention: M = {0} then det M 1. Normalized Determinant: nd M det M Τ 1 k Projected Sublattice: LΤM L projected onto span M
38 Lower Bounds for Chains Theorem [D. 17]: For 0 = L 0 L 1 L k = L then μ L 2 σk i=1 dim( L i ΤL i 1 ) nd LΤL 2 i 1 Only missing ingredient : Combined with techniques from [R.S. `17] easily get tightness within slicing constant L n.
39 Lower Bounds for Chains Theorem [D. 17]: For 0 = L 0 L 1 L k = L then μ L 2 σk i=1 dim( L i ΤL i 1 ) nd LΤL 2 i 1 Proof Idea: 1. Establish SDP based lower bound: [D.R. `16] μ L 2 max σ i rk P i nd P i L 2 s.t. σ i P i P i I n 2. Build solution to above starting from any chain.
40 Lattice Density lim r L rb 2 n vol n (rb 2 n ) = 1 det L r L
41 Lattice Density lim r L rb 2 n vol n (rb 2 n ) = 1 det L r Global density of lattice points per unit volume L
42 Minkowski s First Theorem L rb 2 n 2 n vol n(rb 2 n ) det L 1889 Global density implies local density r L
43 Reverse Minkowski Theorem Regev-S.Davidowitz `17: L lattice dimension n. If all sublattices of L have determinant at least 1 then: L has at most 2 O(log2 n r 2) points at distance r. Almost tight: Z n has n Ω(k) points at distance r for k n.
44 Outline 1. Integer Programming and the Kannan-Lovász (KL) Conjecture. 2. l 2 KL Conjecture & the Reverse Minkowski Conjecture. 3. Finding dense lattice subspaces.
45 Notation M L sublattice of dimension k Convention: M = {0} then det M 1. Normalized Determinant: nd M det M Τ 1 k Projected Sublattice: LΤM L projected onto span M
46 Densest Subspace Problem nd L min M L M {0} nd(m) α-dsp: Given L find M L, M {0} such that nd M α nd (L). Remark: dimension of M is not fixed! Key primitive for finding sparse lattice projections. Will focus on this problem.
47 Densest Subspace Problem Theorem: Can solve O(log n)-dsp in 2 O(n) time with high probability. High Level Approach: If L is not approximate minimizer: find y 0, orthogonal to actual minimizer, and recurse on L y
48 Canonical Polytope [Stuhler 76] n dimensional lattice L Log det P(L) (0,0) (n, log det L) dim n-1 n { k, log det M : sublattice M L, dim M = k}
49 Canonical Filtration [Stuhler 76] n dimensional lattice L Log det Vertices of P(L) L L 2 (n, log det L) (0,0) L 1 {0} dim n-1 n Form Chain: 0 = L 0 L 1 L k = L
50 Canonical Filtration [Stuhler 76] n dimensional lattice L Log det Slope: ln nd( L 2 ΤL 1 ) L L 2 (n, log det L) (0,0) L 1 {0} dim n-1 n Form Chain: 0 = L 0 L 1 L k = L
51 Stable Lattice [Stuhler 76] Log det n dimensional lattice L is stable I.e. no dense sublattices L (n, log det L) (0,0) {0} dim n-1 n If canonical filtration is trivial: 0 L
52 Stable Lattice [Stuhler 76] Example: L = Z n Log det P(L) (0,0) {0} dim n-1 Z n has trivial filtration: 0 Z n n
53 Canonical Filtration [Stuhler 76] L {0} L 1 L n-1 n 1. Form Chain: 0 = L 0 L 1 L k = L. 2. Blocks L i ΤL i 1 are stable. 3. Slope increasing: nd L i ΤL i 1 < nd L i+1 ΤL i.
54 Densest Subspace Problem n dimensional lattice L Log det Want sublattice with approx. minimum slope. L L 2 (0,0) L 1 {0} dim (n, log det L) n-1 n
55 Densest Subspace Problem High Level Approach: If L is not approximate minimizer: find y 0, orthogonal to actual minimizer, and recurse on L y Q: Where to find y? A: The dual lattice L Q: How to find it in L? A: Discrete Gaussian sampling
56 Dual Lattice A lattice L R n is BZ n for a basis B = b 1,, b n. The dual lattice is L = {y span L : y T x Z x L} L is generated by B T. Remark: Z n = Z n y L y T x = 0 y T x = 1 y T x = 2 y T x = 3 y T x = 4 L
57 Dual Lattice A lattice L R n is BZ n for a basis B = b 1,, b n. The dual lattice is L = {y span L : y T x Z x L} L is generated by B T. det L = 1/det(L) y L y T x = 0 y T x = 1 y T x = 2 y T x = 3 y T x = 4 L
58 Discrete Gaussian Distribution
59 Discrete Gaussian Distribution ADRS `15: Can sample in 2 n+o(n) time for any parameter.
60 Main Procedure Repeat until L = {0} s nd L Update M L if nd M > s Sample y D L,c/s until y 0 L L y Main Lemma: At any iteration, if L not O(log n) approximate minimizer, then L y contains minimizer w.p. Ω 1. Proc. finds apx minimizer with prob. 2 O(n).
61 Proof of Main Lemma wlog det L = det(l ) = 1 L 1 L densest sublattice sample y D L,c If nd L 1 1 log n must show that y 0 and y L 1 w.p. Ω(1).
62 det L = det L = 1 L 1 L densest sublattice, nd L 1 1 log n Sample y D L,c Want: 1. Pr y = 0 ε 2. Pr y L L 1 1 ε
63 det L = det L = 1 1. Pr y D L,c y = 0 = 1 ρ c (L ) (By Minkowski) 1 L nb n 2 e nτc n e Τ n c 2 = o(1) ρ c A σ x A e xτc 2
64 det L = det L = 1 L 1 L densest sublattice, nd L 1 1Τlog n W L 1 2. Pr y D L,c y W (ortho. is worst-case) = ρ c(l W) ρ c (L ) = ρ c (L W) ρ c L W ρ c ( L ΤW) 1 ρ c (L /W) ρ c A σ x A e xτc 2
65 det L = det L = 1 L 1 L densest sublattice, nd L 1 1Τlog n W L 1 2. Need to show ρ c L ΤW 1 + o(1) Key: nd Τ L W = Τ 1 nd(l 1 ) log n Reverse-Minkowski ( Τ L W) rb 2 n e o r2, r 0 ρ c A σ x A e xτc 2
66 Canonical Polytope of L? det L = 1 Log det {0} L (n, 0) Slope: ln nd(l 1 ) L 1 L 2 dim n-1 n Assumption: det L = 1
67 Canonical Polytope of L? det L = 1 Log det {0} L L 2 L L 1 L (n, 0) dim n-1 n Map M L M
68 Canonical Polytope of L? det L = 1 Log det {0} Slope: ln nd(l 1 ) L L 2 L L 1 L ΤW L (n, 0) dim n-1 n P(L ) is reflection of P(L)
69 Conclusions 1. Algorithmic version of l 2 Kannan-Lovász conjecture via discrete Gaussian sampling. 2. Lower bound certificates for covering radius that are tight within O(1) under slicing conjecture. Open Problem 1. Prove KL conjecture for general convex bodies. 2. Prove Slicing conjecture for Voronoi cells.
New Conjectures in the Geometry of Numbers
New Conjectures in the Geometry of Numbers Daniel Dadush Centrum Wiskunde & Informatica (CWI) Oded Regev New York University Talk Outline 1. A Reverse Minkowski Inequality & its conjectured Strengthening.
More informationCOS 598D - Lattices. scribe: Srdjan Krstic
COS 598D - Lattices scribe: Srdjan Krstic Introduction In the first part we will give a brief introduction to lattices and their relevance in some topics in computer science. Then we show some specific
More informationCentrum Wiskunde & Informatica, Amsterdam, The Netherlands
Logarithmic Lattices Léo Ducas Centrum Wiskunde & Informatica, Amsterdam, The Netherlands Workshop: Computational Challenges in the Theory of Lattices ICERM, Brown University, Providence, RI, USA, April
More informationHard Instances of Lattice Problems
Hard Instances of Lattice Problems Average Case - Worst Case Connections Christos Litsas 28 June 2012 Outline Abstract Lattices The Random Class Worst-Case - Average-Case Connection Abstract Christos Litsas
More informationCSE 206A: Lattice Algorithms and Applications Spring Basis Reduction. Instructor: Daniele Micciancio
CSE 206A: Lattice Algorithms and Applications Spring 2014 Basis Reduction Instructor: Daniele Micciancio UCSD CSE No efficient algorithm is known to find the shortest vector in a lattice (in arbitrary
More informationsatisfying ( i ; j ) = ij Here ij = if i = j and 0 otherwise The idea to use lattices is the following Suppose we are given a lattice L and a point ~x
Dual Vectors and Lower Bounds for the Nearest Lattice Point Problem Johan Hastad* MIT Abstract: We prove that given a point ~z outside a given lattice L then there is a dual vector which gives a fairly
More informationFundamental Domains, Lattice Density, and Minkowski Theorems
New York University, Fall 2013 Lattices, Convexity & Algorithms Lecture 3 Fundamental Domains, Lattice Density, and Minkowski Theorems Lecturers: D. Dadush, O. Regev Scribe: D. Dadush 1 Fundamental Parallelepiped
More informationOn the Rational Polytopes with Chvátal Rank 1
On the Rational Polytopes with Chvátal Rank 1 Gérard Cornuéjols Dabeen Lee Yanjun Li December 2016, revised May 2018 Abstract We study the following problem: given a rational polytope with Chvátal rank
More informationDimension-Preserving Reductions Between Lattice Problems
Dimension-Preserving Reductions Between Lattice Problems Noah Stephens-Davidowitz Courant Institute of Mathematical Sciences, New York University. noahsd@cs.nyu.edu Last updated September 6, 2016. Abstract
More informationSolving All Lattice Problems in Deterministic Single Exponential Time
Solving All Lattice Problems in Deterministic Single Exponential Time (Joint work with P. Voulgaris, STOC 2010) UCSD March 22, 2011 Lattices Traditional area of mathematics Bridge between number theory
More informationThe Dual Lattice, Integer Linear Systems and Hermite Normal Form
New York University, Fall 2013 Lattices, Convexity & Algorithms Lecture 2 The Dual Lattice, Integer Linear Systems and Hermite Normal Form Lecturers: D. Dadush, O. Regev Scribe: D. Dadush 1 Dual Lattice
More informationThe Euclidean Distortion of Flat Tori
The Euclidean Distortion of Flat Tori Ishay Haviv Oded Regev June 0, 010 Abstract We show that for every n-dimensional lattice L the torus R n /L can be embedded with distortion O(n log n) into a Hilbert
More informationCSC 2414 Lattices in Computer Science September 27, Lecture 4. An Efficient Algorithm for Integer Programming in constant dimensions
CSC 2414 Lattices in Computer Science September 27, 2011 Lecture 4 Lecturer: Vinod Vaikuntanathan Scribe: Wesley George Topics covered this lecture: SV P CV P Approximating CVP: Babai s Nearest Plane Algorithm
More informationCSE 206A: Lattice Algorithms and Applications Winter The dual lattice. Instructor: Daniele Micciancio
CSE 206A: Lattice Algorithms and Applications Winter 2016 The dual lattice Instructor: Daniele Micciancio UCSD CSE 1 Dual Lattice and Dual Basis Definition 1 The dual of a lattice Λ is the set ˆΛ of all
More informationConvex Geometry. Otto-von-Guericke Universität Magdeburg. Applications of the Brascamp-Lieb and Barthe inequalities. Exercise 12.
Applications of the Brascamp-Lieb and Barthe inequalities Exercise 12.1 Show that if m Ker M i {0} then both BL-I) and B-I) hold trivially. Exercise 12.2 Let λ 0, 1) and let f, g, h : R 0 R 0 be measurable
More information1 Shortest Vector Problem
Lattices in Cryptography University of Michigan, Fall 25 Lecture 2 SVP, Gram-Schmidt, LLL Instructor: Chris Peikert Scribe: Hank Carter Shortest Vector Problem Last time we defined the minimum distance
More informationInteger knapsacks and the Frobenius problem. Lenny Fukshansky Claremont McKenna College
Integer knapsacks and the Frobenius problem Lenny Fukshansky Claremont McKenna College Claremont Statistics, Operations Research, and Math Finance Seminar April 21, 2011 1 Integer knapsack problem Given
More informationFaster Deterministic Volume Estimation in the Oracle Model via Thin Lattice Coverings
Faster Deterministic Volume Estimation in the Oracle Model via Thin Lattice Coverings Daniel Dadush Centrum Wiskunde & Informatica, The Netherlands dadush@cwi.nl Abstract We give a 2 O(n) (1+1/ε) n time
More informationTrapdoors for Lattices: Simpler, Tighter, Faster, Smaller
Trapdoors for Lattices: Simpler, Tighter, Faster, Smaller Daniele Micciancio 1 Chris Peikert 2 1 UC San Diego 2 Georgia Tech April 2012 1 / 16 Lattice-Based Cryptography y = g x mod p m e mod N e(g a,
More informationand the polynomial-time Turing p reduction from approximate CVP to SVP given in [10], the present authors obtained a n=2-approximation algorithm that
Sampling short lattice vectors and the closest lattice vector problem Miklos Ajtai Ravi Kumar D. Sivakumar IBM Almaden Research Center 650 Harry Road, San Jose, CA 95120. fajtai, ravi, sivag@almaden.ibm.com
More informationSolving the Closest Vector Problem in 2 n Time The Discrete Gaussian Strikes Again!
Solving the Closest Vector Problem in n Time The Discrete Gaussian Strikes Again! Divesh Aggarwal Divesh.Aggarwal@epfl.ch Daniel Dadush dadush@cwi.nl Noah Stephens-Davidowitz noahsd@cs.nyu.edu Abstract
More information47-831: Advanced Integer Programming Lecturer: Amitabh Basu Lecture 2 Date: 03/18/2010
47-831: Advanced Integer Programming Lecturer: Amitabh Basu Lecture Date: 03/18/010 We saw in the previous lecture that a lattice Λ can have many bases. In fact, if Λ is a lattice of a subspace L with
More informationA Note on the Distribution of the Distance from a Lattice
Discrete Comput Geom (009) 4: 6 76 DOI 0007/s00454-008-93-5 A Note on the Distribution of the Distance from a Lattice Ishay Haviv Vadim Lyubashevsky Oded Regev Received: 30 March 007 / Revised: 30 May
More informationLecture 5: CVP and Babai s Algorithm
NYU, Fall 2016 Lattices Mini Course Lecture 5: CVP and Babai s Algorithm Lecturer: Noah Stephens-Davidowitz 51 The Closest Vector Problem 511 Inhomogeneous linear equations Recall that, in our first lecture,
More informationCSE 206A: Lattice Algorithms and Applications Spring Basic Algorithms. Instructor: Daniele Micciancio
CSE 206A: Lattice Algorithms and Applications Spring 2014 Basic Algorithms Instructor: Daniele Micciancio UCSD CSE We have already seen an algorithm to compute the Gram-Schmidt orthogonalization of a lattice
More informationDwork 97/07, Regev Lyubashvsky-Micciancio. Micciancio 09. PKE from worst-case. usvp. Relations between worst-case usvp,, BDD, GapSVP
The unique-svp World 1. Ajtai-Dwork Dwork 97/07, Regev 03 PKE from worst-case usvp 2. Lyubashvsky-Micciancio Micciancio 09 Shai Halevi, IBM, July 2009 Relations between worst-case usvp,, BDD, GapSVP Many
More informationON FREE PLANES IN LATTICE BALL PACKINGS ABSTRACT. 1. Introduction
ON FREE PLANES IN LATTICE BALL PACKINGS MARTIN HENK, GÜNTER M ZIEGLER, AND CHUANMING ZONG ABSTRACT This note, by studying relations between the length of the shortest lattice vectors and the covering minima
More informationSolving Closest Vector Instances Using an Approximate Shortest Independent Vectors Oracle
Tian CL, Wei W, Lin DD. Solving closest vector instances using an approximate shortest independent vectors oracle. JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY 306): 1370 1377 Nov. 015. DOI 10.1007/s11390-015-
More informationON THE ISOTROPY CONSTANT OF PROJECTIONS OF POLYTOPES
ON THE ISOTROPY CONSTANT OF PROJECTIONS OF POLYTOPES DAVID ALONSO-GUTIÉRREZ, JESÚS BASTERO, JULIO BERNUÉS, AND PAWE L WOLFF Abstract. The isotropy constant of any d-dimensional polytope with n vertices
More informationHigh-dimensional distributions with convexity properties
High-dimensional distributions with convexity properties Bo az Klartag Tel-Aviv University A conference in honor of Charles Fefferman, Princeton, May 2009 High-Dimensional Distributions We are concerned
More informationNote on shortest and nearest lattice vectors
Note on shortest and nearest lattice vectors Martin Henk Fachbereich Mathematik, Sekr. 6-1 Technische Universität Berlin Straße des 17. Juni 136 D-10623 Berlin Germany henk@math.tu-berlin.de We show that
More informationarxiv: v1 [cs.ds] 2 Nov 2013
On the Lattice Isomorphism Problem Ishay Haviv Oded Regev arxiv:1311.0366v1 [cs.ds] 2 Nov 2013 Abstract We study the Lattice Isomorphism Problem (LIP), in which given two lattices L 1 and L 2 the goal
More informationLattices Part II Dual Lattices, Fourier Transform, Smoothing Parameter, Public Key Encryption
Lattices Part II Dual Lattices, Fourier Transform, Smoothing Parameter, Public Key Encryption Boaz Barak May 12, 2008 The first two sections are based on Oded Regev s lecture notes, and the third one on
More informationThe Lovasz-Vempala algorithm for computing the volume of a convex body in O*(n^4) - Theory and Implementation
The Lovasz-Vempala algorithm for computing the volume of a convex body in O*(n^4) - Theory and Implementation Mittagsseminar, 20. Dec. 2011 Christian L. Müller, MOSAIC group, Institute of Theoretical Computer
More informationSimultaneous Diophantine Approximation with Excluded Primes. László Babai Daniel Štefankovič
Simultaneous Diophantine Approximation with Excluded Primes László Babai Daniel Štefankovič Dirichlet (1842) Simultaneous Diophantine Approximation Given reals integers α,,...,, 1 α 2 α n Q r1,..., r n
More informationSUCCESSIVE-MINIMA-TYPE INEQUALITIES. U. Betke, M. Henk and J.M. Wills
SUCCESSIVE-MINIMA-TYPE INEQUALITIES U. Betke, M. Henk and J.M. Wills Abstract. We show analogues of Minkowski s theorem on successive minima, where the volume is replaced by the lattice point enumerator.
More informationAuerbach bases and minimal volume sufficient enlargements
Auerbach bases and minimal volume sufficient enlargements M. I. Ostrovskii January, 2009 Abstract. Let B Y denote the unit ball of a normed linear space Y. A symmetric, bounded, closed, convex set A in
More informationHereditary discrepancy and factorization norms
Hereditary discrepancy and factorization norms organized by Aleksandar Nikolov and Kunal Talwar Workshop Summary Background and Goals This workshop was devoted to the application of methods from functional
More informationLATTICE POINT COVERINGS
LATTICE POINT COVERINGS MARTIN HENK AND GEORGE A. TSINTSIFAS Abstract. We give a simple proof of a necessary and sufficient condition under which any congruent copy of a given ellipsoid contains an integral
More informationApproximately Gaussian marginals and the hyperplane conjecture
Approximately Gaussian marginals and the hyperplane conjecture Tel-Aviv University Conference on Asymptotic Geometric Analysis, Euler Institute, St. Petersburg, July 2010 Lecture based on a joint work
More informationTopics in Basis Reduction and Integer Programming
Topics in Basis Reduction and Integer Programming Mustafa Kemal Tural A dissertation submitted to the faculty of the University of North Carolina at Chapel Hill in partial fulfillment of the requirements
More informationM4. Lecture 3. THE LLL ALGORITHM AND COPPERSMITH S METHOD
M4. Lecture 3. THE LLL ALGORITHM AND COPPERSMITH S METHOD Ha Tran, Dung H. Duong, Khuong A. Nguyen. SEAMS summer school 2015 HCM University of Science 1 / 31 1 The LLL algorithm History Applications of
More informationBackground: Lattices and the Learning-with-Errors problem
Background: Lattices and the Learning-with-Errors problem China Summer School on Lattices and Cryptography, June 2014 Starting Point: Linear Equations Easy to solve a linear system of equations A s = b
More informationThe Johnson-Lindenstrauss Lemma for Linear and Integer Feasibility
The Johnson-Lindenstrauss Lemma for Linear and Integer Feasibility Leo Liberti, Vu Khac Ky, Pierre-Louis Poirion CNRS LIX Ecole Polytechnique, France Rutgers University, 151118 The gist I want to solve
More information19. Basis and Dimension
9. Basis and Dimension In the last Section we established the notion of a linearly independent set of vectors in a vector space V and of a set of vectors that span V. We saw that any set of vectors that
More informationA strongly polynomial algorithm for linear systems having a binary solution
A strongly polynomial algorithm for linear systems having a binary solution Sergei Chubanov Institute of Information Systems at the University of Siegen, Germany e-mail: sergei.chubanov@uni-siegen.de 7th
More informationEnumeration. Phong Nguyễn
Enumeration Phong Nguyễn http://www.di.ens.fr/~pnguyen March 2017 References Joint work with: Yoshinori Aono, published at EUROCRYPT 2017: «Random Sampling Revisited: Lattice Enumeration with Discrete
More informationLattice Sparsification and the Approximate Closest Vector Problem
Lattice Sparsification and the Approximate Closest Vector Problem Daniel Dadush Gábor Kun December 30, 2012 Abstract We give a deterministic algorithm for solving the (1 + ε) approximate Closest Vector
More informationk times l times n times
1. Tensors on vector spaces Let V be a finite dimensional vector space over R. Definition 1.1. A tensor of type (k, l) on V is a map T : V V R k times l times which is linear in every variable. Example
More informationA Randomized Sieving Algorithm for Approximate Integer Programming
Noname manuscript No. (will be inserted by the editor) A Randomized Sieving Algorithm for Approximate Integer Programming Daniel Dadush the date of receipt and acceptance should be inserted later Abstract
More information1: Introduction to Lattices
CSE 206A: Lattice Algorithms and Applications Winter 2012 Instructor: Daniele Micciancio 1: Introduction to Lattices UCSD CSE Lattices are regular arrangements of points in Euclidean space. The simplest
More informationLattice Basis Reduction Part 1: Concepts
Lattice Basis Reduction Part 1: Concepts Sanzheng Qiao Department of Computing and Software McMaster University, Canada qiao@mcmaster.ca www.cas.mcmaster.ca/ qiao October 25, 2011, revised February 2012
More informationRandom Matrices: Invertibility, Structure, and Applications
Random Matrices: Invertibility, Structure, and Applications Roman Vershynin University of Michigan Colloquium, October 11, 2011 Roman Vershynin (University of Michigan) Random Matrices Colloquium 1 / 37
More informationLecture 7 Limits on inapproximability
Tel Aviv University, Fall 004 Lattices in Computer Science Lecture 7 Limits on inapproximability Lecturer: Oded Regev Scribe: Michael Khanevsky Let us recall the promise problem GapCVP γ. DEFINITION 1
More informationSome Sieving Algorithms for Lattice Problems
Foundations of Software Technology and Theoretical Computer Science (Bangalore) 2008. Editors: R. Hariharan, M. Mukund, V. Vinay; pp - Some Sieving Algorithms for Lattice Problems V. Arvind and Pushkar
More informationSemidefinite Programming
Chapter 2 Semidefinite Programming 2.0.1 Semi-definite programming (SDP) Given C M n, A i M n, i = 1, 2,..., m, and b R m, the semi-definite programming problem is to find a matrix X M n for the optimization
More informationHouston Journal of Mathematics. c 2002 University of Houston Volume 28, No. 3, 2002
Houston Journal of Mathematics c 00 University of Houston Volume 8, No. 3, 00 QUOTIENTS OF FINITE-DIMENSIONAL QUASI-NORMED SPACES N.J. KALTON AND A.E. LITVAK Communicated by Gilles Pisier Abstract. We
More informationAffine Geometry and the Discrete Legendre Transfrom
Affine Geometry and the Discrete Legendre Transfrom Andrey Novoseltsev Department of Mathematics University of Washington April 25, 2008 Andrey Novoseltsev (UW) Affine Geometry April 25, 2008 1 / 24 Outline
More informationi=1 β i,i.e. = β 1 x β x β 1 1 xβ d
66 2. Every family of seminorms on a vector space containing a norm induces ahausdorff locally convex topology. 3. Given an open subset Ω of R d with the euclidean topology, the space C(Ω) of real valued
More informationMeasuring Ellipsoids 1
Measuring Ellipsoids 1 Igor Rivin Temple University 2 What is an ellipsoid? E = {x E n Ax = 1}, where A is a non-singular linear transformation of E n. Remark that Ax = Ax, Ax = x, A t Ax. The matrix Q
More informationapproximation algorithms I
SUM-OF-SQUARES method and approximation algorithms I David Steurer Cornell Cargese Workshop, 201 meta-task encoded as low-degree polynomial in R x example: f(x) = i,j n w ij x i x j 2 given: functions
More informationThe Shortest Vector Problem (Lattice Reduction Algorithms)
The Shortest Vector Problem (Lattice Reduction Algorithms) Approximation Algorithms by V. Vazirani, Chapter 27 - Problem statement, general discussion - Lattices: brief introduction - The Gauss algorithm
More informationLecture 5. Theorems of Alternatives and Self-Dual Embedding
IE 8534 1 Lecture 5. Theorems of Alternatives and Self-Dual Embedding IE 8534 2 A system of linear equations may not have a solution. It is well known that either Ax = c has a solution, or A T y = 0, c
More informationCrystals, Quasicrystals and Shape
Crystals, Quasicrystals and Shape by Azura Newman Table of contents 1) Introduction 2)Diffraction Theory 3)Crystals 4)Parametric Density 5) Surface Energy and Wulff-Shape 6) Quasicrystals 7) The Bound
More informationLecture notes on the ellipsoid algorithm
Massachusetts Institute of Technology Handout 1 18.433: Combinatorial Optimization May 14th, 007 Michel X. Goemans Lecture notes on the ellipsoid algorithm The simplex algorithm was the first algorithm
More informationThe Ellipsoid Algorithm
The Ellipsoid Algorithm John E. Mitchell Department of Mathematical Sciences RPI, Troy, NY 12180 USA 9 February 2018 Mitchell The Ellipsoid Algorithm 1 / 28 Introduction Outline 1 Introduction 2 Assumptions
More informationLattice closures of polyhedra
Lattice closures of polyhedra Sanjeeb Dash IBM Research sanjeebd@us.ibm.com Oktay Günlük IBM Research gunluk@us.ibm.com April 10, 2017 Diego A. Morán R. Universidad Adolfo Ibañez diego.moran@uai.cl Abstract
More informationIdeal Lattices and Ring-LWE: Overview and Open Problems. Chris Peikert Georgia Institute of Technology. ICERM 23 April 2015
Ideal Lattices and Ring-LWE: Overview and Open Problems Chris Peikert Georgia Institute of Technology ICERM 23 April 2015 1 / 16 Agenda 1 Ring-LWE and its hardness from ideal lattices 2 Open questions
More informationLattice methods for algebraic modular forms on orthogonal groups
Lattice methods for algebraic modular forms on orthogonal groups John Voight Dartmouth College joint work with Matthew Greenberg and Jeffery Hein and Gonzalo Tornaría Computational Challenges in the Theory
More informationAn example of a convex body without symmetric projections.
An example of a convex body without symmetric projections. E. D. Gluskin A. E. Litvak N. Tomczak-Jaegermann Abstract Many crucial results of the asymptotic theory of symmetric convex bodies were extended
More informationParametric Integer Programming in Fixed Dimension
arxiv:0801.4336v1 [math.oc] 28 Jan 2008 Parametric Integer Programming in Fixed Dimension Friedrich Eisenbrand and Gennady Shmonin Institut für Mathematik, Universität Paderborn, D-33095 Paderborn, Germany
More informationApplication of the LLL Algorithm in Sphere Decoding
Application of the LLL Algorithm in Sphere Decoding Sanzheng Qiao Department of Computing and Software McMaster University August 20, 2008 Outline 1 Introduction Application Integer Least Squares 2 Sphere
More informationA Fast Phase-Based Enumeration Algorithm for SVP Challenge through y-sparse Representations of Short Lattice Vectors
A Fast Phase-Based Enumeration Algorithm for SVP Challenge through y-sparse Representations of Short Lattice Vectors Dan Ding 1, Guizhen Zhu 2, Yang Yu 1, Zhongxiang Zheng 1 1 Department of Computer Science
More informationLower Bounds of Shortest Vector Lengths in Random NTRU Lattices
Lower Bounds of Shortest Vector Lengths in Random NTRU Lattices Jingguo Bi 1,2 and Qi Cheng 2 1 School of Mathematics Shandong University Jinan, 250100, P.R. China. Email: jguobi@mail.sdu.edu.cn 2 School
More informationHard equality constrained integer knapsacks
Hard equality constrained integer knapsacks Karen Aardal Arjen K. Lenstra February 17, 2005 Abstract We consider the following integer feasibility problem: Given positive integer numbers a 0, a 1,...,
More informationLattice Cryptography
CSE 206A: Lattice Algorithms and Applications Winter 2016 Lattice Cryptography Instructor: Daniele Micciancio UCSD CSE Lattice cryptography studies the construction of cryptographic functions whose security
More informationFaster Fully Homomorphic Encryption
Faster Fully Homomorphic Encryption Damien Stehlé Joint work with Ron Steinfeld CNRS ENS de Lyon / Macquarie University Singapore, December 2010 Damien Stehlé Faster Fully Homomorphic Encryption 08/12/2010
More informationLecture 18: March 15
CS71 Randomness & Computation Spring 018 Instructor: Alistair Sinclair Lecture 18: March 15 Disclaimer: These notes have not been subjected to the usual scrutiny accorded to formal publications. They may
More informationA Deterministic Single Exponential Time Algorithm for Most Lattice Problems based on Voronoi Cell Computations
Electronic Colloquium on Computational Complexity, Revision 1 of Report No. 14 (2010) A Deterministic Single Exponential Time Algorithm for Most Lattice Problems based on Voronoi Cell Computations Daniele
More informationLocally convex spaces, the hyperplane separation theorem, and the Krein-Milman theorem
56 Chapter 7 Locally convex spaces, the hyperplane separation theorem, and the Krein-Milman theorem Recall that C(X) is not a normed linear space when X is not compact. On the other hand we could use semi
More informationMSRI Summer Graduate Workshop: Algebraic, Geometric, and Combinatorial Methods for Optimization. Part IV
MSRI Summer Graduate Workshop: Algebraic, Geometric, and Combinatorial Methods for Optimization Part IV Geometry of Numbers and Rational Generating Function Techniques for Integer Programming Matthias
More informationLocally Dense Codes. Daniele Micciancio. August 26, 2013
Electronic Colloquium on Computational Complexity, Report No. 115 (2013) Locally Dense Codes Daniele Micciancio August 26, 2013 Abstract The Minimum Distance Problem (MDP), i.e., the computational task
More informationOn the Closest Vector Problem with a Distance Guarantee
On the Closest Vector Problem with a Distance Guarantee Daniel Dadush dadush@cwi.nl Oded Regev Noah Stephens-Davidowitz noahsd@cs.nyu.edu Abstract We present a substantially more efficient variant, both
More informationApproximating Submodular Functions. Nick Harvey University of British Columbia
Approximating Submodular Functions Nick Harvey University of British Columbia Approximating Submodular Functions Part 1 Nick Harvey University of British Columbia Department of Computer Science July 11th,
More informationPreliminary/Qualifying Exam in Numerical Analysis (Math 502a) Spring 2012
Instructions Preliminary/Qualifying Exam in Numerical Analysis (Math 502a) Spring 2012 The exam consists of four problems, each having multiple parts. You should attempt to solve all four problems. 1.
More informationDiscrete Optimization 2010 Lecture 7 Introduction to Integer Programming
Discrete Optimization 2010 Lecture 7 Introduction to Integer Programming Marc Uetz University of Twente m.uetz@utwente.nl Lecture 8: sheet 1 / 32 Marc Uetz Discrete Optimization Outline 1 Intro: The Matching
More informationLower bounds of shortest vector lengths in random knapsack lattices and random NTRU lattices
Lower bounds of shortest vector lengths in random knapsack lattices and random NTRU lattices Jingguo Bi 1 and Qi Cheng 2 1 Lab of Cryptographic Technology and Information Security School of Mathematics
More informationProbabilistic Methods in Asymptotic Geometric Analysis.
Probabilistic Methods in Asymptotic Geometric Analysis. C. Hugo Jiménez PUC-RIO, Brazil September 21st, 2016. Colmea. RJ 1 Origin 2 Normed Spaces 3 Distribution of volume of high dimensional convex bodies
More informationApproximating the Radii of Point Sets
Approximating the Radii of Point Sets Kasturi Varadarajan S. Venkatesh Yinyu Ye Jiawei Zhang April 17, 2006 Abstract We consider the problem of computing the outer-radii of point sets. In this problem,
More informationPolynomiality of Linear Programming
Chapter 10 Polynomiality of Linear Programming In the previous section, we presented the Simplex Method. This method turns out to be very efficient for solving linear programmes in practice. While it is
More information7. Lecture notes on the ellipsoid algorithm
Massachusetts Institute of Technology Michel X. Goemans 18.433: Combinatorial Optimization 7. Lecture notes on the ellipsoid algorithm The simplex algorithm was the first algorithm proposed for linear
More informationDISCRETE SUBGROUPS, LATTICES, AND UNITS.
DISCRETE SUBGROUPS, LATTICES, AND UNITS. IAN KIMING 1. Discrete subgroups of real vector spaces and lattices. Definitions: A lattice in a real vector space V of dimension d is a subgroup of form: Zv 1
More informationLattice closures of polyhedra
Lattice closures of polyhedra Sanjeeb Dash IBM Research sanjeebd@us.ibm.com Oktay Günlük IBM Research gunluk@us.ibm.com October 27, 2016 Diego A. Morán R. Universidad Adolfo Ibañez diego.moran@uai.cl Abstract
More informationHardness of the Covering Radius Problem on Lattices
Hardness of the Covering Radius Problem on Lattices Ishay Haviv Oded Regev June 6, 2006 Abstract We provide the first hardness result for the Covering Radius Problem on lattices (CRP). Namely, we show
More informationKadets-Type Theorems for Partitions of a Convex Body
Discrete Comput Geom (2012) 48:766 776 DOI 10.1007/s00454-012-9437-1 Kadets-Type Theorems for Partitions of a Convex Body Arseniy Akopyan Roman Karasev Received: 18 November 2011 / Revised: 4 June 2012
More informationOn The Hardness of Approximate and Exact (Bichromatic) Maximum Inner Product. Lijie Chen (Massachusetts Institute of Technology)
On The Hardness of Approximate and Exact (Bichromatic) Maximum Inner Product Max a,b A B a b Lijie Chen (Massachusetts Institute of Technology) Max-IP and Z-Max-IP (Boolean) Max-IP: Given sets A and B
More informationRecovering Short Generators of Principal Ideals in Cyclotomic Rings
Recovering Short Generators of Principal Ideals in Cyclotomic Rings Ronald Cramer Chris Peikert Léo Ducas Oded Regev University of Leiden, The Netherlands CWI, Amsterdam, The Netherlands University of
More informationComputing Unit Groups of Orders
Computing Unit Groups of Orders Gabriele Nebe, Oliver Braun, Sebastian Schönnenbeck Lehrstuhl D für Mathematik Bad Boll, March 5, 2014 The classical Voronoi Algorithm Around 1900 Korkine, Zolotareff, and
More informationAffine Geometry and Discrete Legendre Transform
Affine Geometry and Discrete Legendre Transform Andrey Novoseltsev April 24, 2008 Abstract The combinatorial duality used in Gross-Siebert approach to mirror symmetry is the discrete Legendre transform
More informationMinimal inequalities for an infinite relaxation of integer programs
Minimal inequalities for an infinite relaxation of integer programs Amitabh Basu Carnegie Mellon University, abasu1@andrew.cmu.edu Michele Conforti Università di Padova, conforti@math.unipd.it Gérard Cornuéjols
More information