Preprint
Article

This version is not peer-reviewed.

Hardness of Euclidean Closest Vector Within n1/2−ϵ and Binary Nearest Codeword Within n1−ϵ

Submitted:

26 August 2026

Posted:

02 September 2026

You are already at the latest version

Abstract
We prove two deterministic inapproximability results. First, for every fixed \(0<\epsilon<1/2\), Euclidean \(\mathrm{GapCVP}^{(2)}\) is NP-hard with gap factor \(n^{1/2-\epsilon}\) under deterministic polynomial-time many-one reductions, where \(n\) denotes the lattice rank. Consequently, the Euclidean closest vector problem is NP-hard to approximate within the same factor. This improves the previous \(n^{1/400}\) hardness factor in Chapter 7 of the OpenAI report [Ope25]. Aharonov and Regev gave short certificates for both the YES and the NO case of \(\operatorname{GapCVP}^{(2)}\) at gap factor \( C\sqrt n \), placing that problem in \(\mathrm{NP}\cap\mathrm{coNP}\) for an absolute constant \(C>0\) [AR05]. An NP-hard problem lying in \(\mathrm{coNP}\) would give \(\mathrm{NP}=\mathrm{coNP}\), so the factor \(n^{1/2-\epsilon}\) above cannot be improved to \( C\sqrt n \) unless the two classes coincide. Second, for every fixed \(0<\epsilon<1\), the gap versions of binary nearest codeword and binary syndrome decoding are NP-hard with factor \(n^{1-\epsilon}\) under deterministic polynomial-time many-one reductions, where \(n\) denotes the binary block length. Consequently, both optimization problems are NP-hard to approximate within the same factor. This improves the previous \(n^{1/200}\) hardness factor in Chapter 7 of the OpenAI report [Ope26].
Keywords: 
;  

1. Introduction

The gap version of the closest vector problem provides the standard decision formulation for studying approximation hardness. Let B ∈ Z n × n be nonsingular. Its columns generate the full-rank lattice L ( B ) : = B Z n , whose rank is n. Given a target t ∈ Q n and a norm ∥ · ∥ , the optimization version of the closest vector problem asks for z ∈ Z n minimizing ∥ t − B z ∥ ; see Micciancio and Goldwasser [MG02, Chapter 3] for standard background.
For an approximation factor γ : N → [ 1 , ∞ ) and a positive rational radius r, the promise problem GapCVP γ ∥ · ∥ asks one to distinguish
dist ∥ · ∥ ( t , L ( B ) ) ≤ r from dist ∥ · ∥ ( t , L ( B ) ) > γ ( n ) r ,
where dist ∥ · ∥ ( t , L ( B ) ) : = min z ∈ Z n ∥ t − B z ∥ . Instances whose optimum lies between the two thresholds are outside the promise. A γ ( n ) -approximation algorithm for the optimization problem solves this promise problem by comparing the distance of its output with γ ( n ) r . Thus NP-hardness of GapCVP γ ∥ · ∥ rules out such an approximation algorithm unless P = NP .
The Euclidean closest vector problem is the specialization to the ℓ 2 norm. We write
dist 2 ( t , L ( B ) ) : = min z ∈ Z n ∥ t − B z ∥ 2
and denote its gap version by GapCVP γ ( 2 ) . Van Emde Boas [vEB81] proved NP-hardness of exact Euclidean CVP. Arora, Babai, Stern, and Sweedyk [ABSS97] established hardness within every fixed constant. For every fixed ϵ > 0 , they also proved hardness within 2 ( log n ) 1 − ϵ under the assumption NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) [ABSS97]. Dinur, Kindler, and Safra [DKS98], in work subsequently refined by Dinur, Kindler, Raz, and Safra [DKRS03], strengthened this to n a / log log n for some absolute constant a > 0 . Although this factor dominates every fixed power of log n , its exponent tends to zero and hence does not give n c hardness for any fixed c > 0 . The OpenAI report [Ope26, Chapter 7] subsequently obtained the fixed polynomial factor n 1 / 400 by a deterministic reduction from 3SAT. Fixed-polynomial lattice inapproximability had previously been obtained conditionally on the Projection Games Conjecture by Moshkovitz [Mos15, Section 5.1] and Mukhopadhyay [Muk22]. Those conditional results are qualitatively different from the unconditional deterministic reduction from ordinary 3SAT proved here. The Exponential Time Hypothesis (ETH), introduced by Impagliazzo and Paturi [IP01], has also served as the basis for recent fine-grained lower bounds for constant-factor approximations of CVP and related problems [AGMZ26,HKW26]. These results concern the running time of constant-factor approximation rather than unconditional NP-hardness for polynomial approximation factors.
The square-root scale forms a complexity-theoretic barrier. Goldreich and Goldwasser [GG00] established interactive-proof upper bounds that constrain the nonapproximability of lattice problems. Aharonov and Regev [AR05] subsequently proved that, for some absolute constant C > 0 ,
GapCVP C n ( 2 ) ∈ NP ∩ coNP .
Consequently, NP-hardness at that scale under deterministic polynomial-time many-one reductions would imply NP = coNP . The reduction given here achieves every fixed exponent below 1 / 2 .
Binary nearest codeword is an optimization problem over F 2 . Given a k-dimensional binary linear code C ⊆ F 2 n and a target word y ∈ F 2 n , the task is to find a codeword in C minimizing its Hamming distance from y [BMT78]. Binary syndrome decoding takes as input a binary parity-check matrix H and a syndrome s ∈ im H , and asks for a minimum-weight binary vector e satisfying H e = s [BMT78]. The two formulations are equivalent. Indeed, if C = ker H and s = H y , then the map c ↦ y − c identifies codewords c ∈ C with vectors e satisfying H e = s . Consequently, the two instances have the same optimum value, and the correspondence preserves approximation ratios. Conversely, given a consistent syndrome instance ( H , s ) , Gaussian elimination finds y with H y = s , and the same correspondence reduces it to nearest codeword for ker H .
Berlekamp, McEliece, and van Tilborg [BMT78] proved that binary syndrome decoding is NP-complete. For binary nearest codeword, Arora, Babai, Stern, and Sweedyk [ABSS97] proved unconditional NP-hardness of approximation within every constant factor. For every fixed ϵ > 0 , they also proved hardness within 2 ( log n ) 1 − ϵ under the assumption that NP has no quasipolynomial-time algorithms, namely NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) . Arora’s thesis [Aro94, Section 6.4] gives a contemporaneous account and explicitly records the stronger 1 − ϵ exponent for nearest codeword. For nearest codeword with preprocessing, Alekhnovich, Khot, Kindler, and Vishnoi [AKKV05] proved hardness within ( log n ) 1 − ϵ under the same quasipolynomial-time assumption. Khot, Popat, and Vishnoi [KPV14] strengthened the factor to 2 ( log n ) 1 − ϵ under NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 / ϵ ) ) . For ordinary nearest codeword, Bhattiprolu, Guruswami, and Ren [BGR25] subsequently gave a PCP-free proof of the same two bounds: unconditional NP-hardness within every constant factor and 2 ( log n ) 1 − ϵ = n o ( 1 ) hardness under the assumption that NP has no quasipolynomial-time algorithms. Their contribution is a new proof rather than a stronger approximation factor. Bhattiprolu, Guruswami, Lee, and Ren [BGLR25] subsequently studied the inapproximability of finding sparse vectors in codes, subspaces, and lattices via randomized reductions; their lattice result does not yield deterministic fixed-polynomial hardness for Euclidean CVP. Methodologically, Bennett and Peikert [BP23] also combine Reed–Solomon codes [RS60] with an integer-lattice lift to obtain randomized hardness for approximate SVP and identify derandomization as a central obstacle.
Bitansky, Harsha, Ishai, Rothblum, and Wu [BHI+24] showed that ETH rules out 2 o ( n ) -time approximation within a certain constant factor, using the equivalent formulation that minimizes the number of unsatisfied linear equations. Subsequently, Corollary 15 of the OpenAI report [Ope26] established, without an additional complexity assumption, NP-hardness of approximation within n 1 / 200 for binary nearest codeword and binary syndrome decoding under deterministic polynomial-time many-one reductions. The result proved here uses the same unconditional reduction model and improves the approximation factor to n 1 − ϵ for every fixed 0 < ϵ < 1 .
On the algorithmic side, Alon, Panigrahy, and Yekhanin gave several deterministic approximation algorithms and time–ratio tradeoffs [APY10]. Their general polynomial-time algorithm achieves an O ( n / log n ) approximation. Berman and Karpinski gave, for every fixed constant c > 0 , a deterministic algorithm with approximation factor O ( k / c ) and a randomized algorithm with factor O ( k / log k ) [BK02]. Alon, Panigrahy, and Yekhanin observed that the latter analysis yields approximation factor O ( k / log n ) [APY10].

1.1. Our Results

We first record the two Euclidean lattice problems used below.
Definition 
(Euclidean closest vector). An instance consists of a nonsingular matrix B ∈ Z n × n and a target t ∈ Q n . The matrix B generates the full-rank lattice L ( B ) : = B Z n . The objective is to output a vector z ∈ Z n minimizing ∥ t − B z ∥ 2 . Its optimum value is dist 2 ( t , L ( B ) ) : = min z ∈ Z n ∥ t − B z ∥ 2 .
Definition 
(Euclidean GapCVP). Let γ : N → [ 1 , ∞ ) . An instance of GapCVP γ ( 2 ) consists of a nonsingular matrix B ∈ Z n × n , a target t ∈ Q n , and a radius r ∈ Q > 0 . It is promised that either dist 2 ( t , L ( B ) ) ≤ r , which is the YES case, or dist 2 ( t , L ( B ) ) > γ ( n ) r , which is the NO case. The task is to distinguish the two cases.
We now state our main Euclidean result. It improves the n 1 / 400 hardness factor in Theorem 1 on page 184 of the OpenAI report [Ope26].
Theorem 1.3
(Euclidean closest vector, informal version of Theorem 8.1). For every fixed 0 < ϵ < 1 / 2 , there is a deterministic polynomial-time mapping that assigns to each 3SAT formula φ a nonsingular matrix B ∈ Z n × n , a target t ∈ Z n , and a radius r ∈ Q > 0 such that
φ satisfiable ⇒ dist 2 ( t , L ( B ) ) ≤ r , φ unsatisfiable ⇒ dist 2 ( t , L ( B ) ) > n 1 / 2 − ϵ r .
Consequently, GapCVP n 1 / 2 − ϵ ( 2 ) is NP-hard under deterministic polynomial-time many-one reductions.
Remark 1.4.
Our Theorem improves the n 1 / 400 Euclidean closest-vector hardness factor established in Theorem 1 of the OpenAI report [Ope26] to n 1 / 2 − ϵ . Aharonov and Regev proved that GapCVP C n ( 2 ) lies in NP ∩ coNP for an absolute constant C > 0 [AR05]. No NP-hardness result under deterministic polynomial-time many-one reductions can reach that scale unless NP = coNP .
We next formally define the two binary problems.
Definition 
(Binary nearest codeword). An instance consists of a binary linear code C ⊆ F 2 n , given by a generator matrix, and a target word y ∈ F 2 n . The objective is to output a codeword c ∈ C minimizing wt ( y − c ) . We denote the optimum value by opt nc ( C , y ) : = min c ∈ C wt ( y − c ) .
Definition 
(Binary syndrome decoding). An instance consists of a binary matrix H ∈ F 2 r × n and a syndrome s ∈ im H . The objective is to output a vector e ∈ F 2 n of minimum Hamming weight subject to H e = s . We denote the optimum value by opt sd ( H , s ) : = min { wt ( e ) : e ∈ F 2 n , H e = s } .
To state approximation hardness, we use the gap versions of these two optimization problems. Both are promise problems parameterized by a radius and an approximation factor.
Definition 
(Binary gap nearest codeword and gap syndrome decoding). Let γ : N → [ 1 , ∞ ) . An instance of GapNCP γ is a binary nearest-codeword instance ( C , y ) together with a positive integer radius R; it is promised that either opt nc ( C , y ) ≤ R or opt nc ( C , y ) > γ ( n ) R . An instance of GapSD γ is a binary syndrome-decoding instance ( H , s ) together with a positive integer radius R and the analogous promise opt sd ( H , s ) ≤ R or opt sd ( H , s ) > γ ( n ) R . In both cases n is the binary block length, and the task is to distinguish the two promised cases.
The following theorem improves the n 1 / 200 hardness factor established by Corollary 15 on page 213 of the OpenAI report [Ope26].
Theorem 1.8
(Main result, informal version of Theorem 7.1). For every fixed 0 < ϵ < 1 , GapNCP n 1 − ϵ and GapSD n 1 − ϵ are NP-hard under deterministic polynomial-time many-one reductions, where n is the binary block length. Consequently, binary nearest codeword (Definition 1.5) and binary syndrome decoding (Definition 1.6) are NP-hard to approximate within n 1 − ϵ .
Remark 1.9.
The general polynomial-time algorithm of Alon, Panigrahy, and Yekhanin [APY10] approximates binary nearest codeword within O ( n / log n ) , so the factor n 1 − ϵ is optimal up to n ϵ . This improves the n 1 / 200 hardness factor established in Corollary 15 of Chapter 7 of the OpenAI report [Ope26].

2. Technique Overview

This section compares the mechanism behind the OpenAI reduction [Ope26] with the two quadratic estimates that permit a sharper choice of parameters. We focus on the reduction to binary nearest codeword and syndrome decoding (Theorem 1.8). The Euclidean closest-vector result (Theorem 1.3) then follows from the dimension-preserving parity-lift reduction, which converts a binary weight gap into the square root of that gap in Euclidean distance. Section 2.1 reviews the approach in the OpenAI report, whereas Section 2.2 explains how our sharper analysis improves the resulting hardness factors.

2.1. Overview of the OpenAI Approach

Chapter 7 of the OpenAI report [Ope26] factors the reduction as
3 SAT ⟶ binary affine decoding ⟶ binary nearest codeword ⟶ Euclidean CVP .
The first arrow contains the main algebraic construction. Let φ be the input formula, let s be its encoding length, and let m and ℓ be its numbers of variables and clauses. We define N : = 100 + s + m + ℓ and D RS : = m . The variables are indexed by [ m ] : = { 1 , … , m } and represented by distinct anchors a 1 , … , a m in a characteristic-two field F q . A Boolean assignment σ ∈ { 0 , 1 } m determines the unique polynomial Q σ ∈ F q [ X ] of degree less than m satisfying Q σ ( a i ) = σ i , where σ i is the bit assigned to variable i. The reduction evaluates this polynomial on P : = F q ∖ { a 1 , … , a m } .
The binary variables are arranged into evaluation tables. For a clause C, let I C ⊆ [ m ] be the set of its variable indices and let B C ⊆ { 0 , 1 } I C be its satisfying local assignments. The table types are Θ : = { 0 } ∪ { ( C , β ) : β ∈ B C } : type 0 is the global table, and ( C , β ) is the subtype asserting that clause C receives the local assignment β . Write x τ , p , w for the binary coordinate selecting the field value w ∈ F q in table τ ∈ Θ at p ∈ P , and define its fiber by S τ ( p ) : = { w ∈ F q : x τ , p , w = 1 } .
Fix a moment budget T. For 0 ≤ j ≤ T , the ordinary power sum of table τ at p is
μ τ , j ( p ) : = ∑ w ∈ S τ ( p ) w j .
For τ = ( C , β ) , i ∈ I C , and 0 ≤ j ≤ T , the shifted power sum is
η τ , i , j ( p ) : = ∑ w ∈ S τ ( p ) ( w − β i p − a i ) j ,
where β i is the bit assigned to variable i by β . The affine constraints require these pointwise quantities to be evaluations of low-degree polynomials and require the clause tables to reproduce the global table modulo two. Let H x = b denote the resulting binary affine system, let M : = | Θ | | P | q be its number of binary coordinates, and, when the system is consistent, define W ( H , b ) : = min { wt ( x ) : H x = b } . If σ satisfies the formula, each active fiber is the singleton { Q σ ( p ) } , exactly one subtype is active for every clause, and the resulting binary solution has weight R 1 : = ( ℓ + 1 ) | P | .
For soundness, start with a low-weight binary solution. For a fiber cutoff κ , define the good evaluation set of table τ by P τ : = { p ∈ P : | S τ ( p ) | ≤ κ } . Markov’s inequality shows that P τ contains all but a small set of evaluation points. Reed–Solomon interpolation turns the pointwise moments into polynomials μ τ , j ( X ) in the indeterminate X. Lemma 10 of the OpenAI report [Ope26] uses the associated Hankel matrix to construct a monic separable polynomial G τ ∈ F q ( X ) [ Y ] . Its roots in a common splitting field have the prescribed power sums. The shifted moments are then examined using a valuation above X − a i . They force every root associated with subtype ( C , β ) to reduce to the bit β i at the anchor a i . Finally, the clause decomposition and a Vandermonde argument match a global root with a satisfying subtype for every clause. Using the same valuation for a variable wherever it occurs makes these local assignments consistent, producing a global satisfying assignment.
The three parameters κ , T, and q serve different purposes, but the soundness proof couples them. The cutoff κ must be large enough that a low-weight solution has few heavy fibers: if wt ( x ) ≤ 4 M 1 / 200 R 1 , then
| P ∖ P τ | ≤ 4 M 1 / 200 R 1 κ .
Increasing κ improves this estimate, but it makes both algebraic steps more expensive. Thus one cannot choose the cutoff, the moment budget, and the field size independently.
Lemma 12 of the OpenAI report [Ope26] uses a large moment budget because of its local valuation argument. For a reconstructed polynomial of degree h ≤ κ , it first bounds the coefficients of an inverse Vandermonde matrix. In the notation of that argument, the successive bounds are
D 0 : = D RS h 2 + h , U h : = h 2 D 0 + D RS h 2 + 1 , z : = h U h + 1 .
With D RS ≤ N and h ≤ κ = N 4 , these quantities have scales N 9 , N 17 , and N 21 , respectively. The proof uses the moments with indices from z through z + h − 1 to isolate one root at a time. Consequently, the moment budget must be larger than this range; the choice T = N 30 provides ample slack. This is the local-valuation moment cost; it does not come from the Reed–Solomon encoding itself.
Lemma 10 of the OpenAI report [Ope26] imposes two further costs, both quadratic in the fiber cutoff. Its Hankel determinant Δ h has degree at most D RS h ( h − 1 ) ; hence, uniformly for h ≤ κ , as many as D RS κ ( κ − 1 ) retained sample points may fail to have maximum fiber size. Moreover, after clearing the common denominator Δ h , the j-th root-moment discrepancy has degree at most 2 D RS h 2 j , which is bounded by 2 D RS κ 2 T for j ≤ T . Thus the reconstruction lemma requires
| P τ | − D RS κ ( κ − 1 ) > 2 D RS κ 2 T .
We call the subtractive term the determinant-zero cost and the right-hand term the denominator-clearing cost. For D RS ≤ N , κ = N 4 , and T = N 30 , the right-hand side is of order N 39 . Hence the field must be substantially larger than N 39 . Moreover, it must remain large after the heavy fibers are discarded. Taking q = Θ ( N 200 ) makes both requirements hold with considerable uniform slack: since M = O ( N q 2 ) and R 1 = O ( N q ) , the preceding discarded-point bound is o ( q ) for the target factor M 1 / 200 . The exact exponents 30 and 200 are therefore deliberately generous choices, but the original proof genuinely requires a large separation among these scales.
Finally, q = Θ ( N 200 ) gives M = O ( N q 2 ) = O ( N 401 ) . Soundness against solutions of weight O ( M 1 / 200 R 1 ) yields the M 1 / 200 coding gap. The standard parity lift outputs a lattice basis B and a target t satisfying dist 2 ( t , L ( B ) ) 2 = W ( H , b ) , so this becomes the M 1 / 400 Euclidean gap.

2.2. Overview of Our Approach

We retain the outer reduction through a sparse binary affine system, but replace its inner encoding and soundness mechanism. Multi-axis exponent reconstruction replaces anchor-based interpolation, and soundness is proved by a high-rank/low-rank dichotomy combining rank charging with short-recurrence atomization.
Sparse quadratic encoding and assignment compression. Instead of interpolating an assignment by a polynomial through anchors, we first replace the formula by a system of homogeneous quadratic forms in which each form has at most five monomials (Lemma 3.2), and we then compress an assignment into one field element, enc ( x ) : = ∑ i = 1 n y i x i ∈ E where the y i are independent over F 2 , so that x ↦ enc ( x ) is injective. Consistency between occurrences of a variable is enforced by linear equations in the quadratic encoding rather than by a valuation at an anchor, so no local analysis at anchors is needed at any point below.
Axis-wise interpolation and multi-axis exponent reconstruction. Fix a power of two d and a number of axes r, and put κ : = d r . For each axis j the reduction uses the polynomial P x , j of degree less than [ E : F q ] with P x , j ( ζ ) = enc ( x ) d j , which exists because { 1 , ζ , … } is a basis, and whose coefficients are F 2 -linear in x because d j is a power of two and the Frobenius map is additive (Lemma 3.3). Writing an exponent in base d as k = ∑ h = 0 r − 1 p h d h gives ∏ h = 0 r − 1 P x , h ( ζ ) p h = enc ( x ) k by Lemma 3.4. This is the quantitative heart of the construction: r axis polynomials represent κ = d r consecutive powers of the assignment encoding, while the interpolation degree needed to carry them grows only linearly in d. Thus the construction represents d r consecutive powers while the interpolation-degree dependence on the radix remains linear in d.
The table has one block T i , j , ℓ , s for every pair 0 ≤ i , j ≤ n , every label ℓ in the label set L : = F q r , and every sample point s in the sample set S : = F q ; for fixed ℓ and s these form a block T ℓ , s ∈ F 2 ( n + 1 ) × ( n + 1 ) .
Definitions 3.7 and 3.9 introduce the derived quantities f, F, and u.
From interpolants to exponent-indexed moments. Definition 3.8 controls how the table is converted into scalar moments. The degree bound keeps interpolation within the available budget, while the consistency condition ensures that F i , j , p ( ζ ) depends only on the scalar exponent ind ( p ) = ∑ h = 0 r − 1 p h d h . Thus the exponent-indexed moments u i , j , k are well defined.
Algebraic identities of honest moments. Definition 3.10 imposes the three algebraic identities satisfied by honest moments. Doubling an exponent squares the moment, the linear-combination identity advances the exponent through the assignment encoding, and matrix-inner-product vanishing enforces every quadratic encoding form. These constraints are affine over F 2 ; in particular, squaring is affine because it is the Frobenius automorphism (Lemma 3.12).
Direct constraints on table blocks. Definition 3.11 acts directly on the table blocks. Symmetry makes each block behave like a matrix of pairwise products, while anchor normalization fixes the homogenizing coordinate and removes the scaling ambiguity. Accordingly, the completeness witness places one rank-one block z z ⊤ at the honest label of each sample point (Lemma 3.13).
Charging rank instead of discarding a discriminant. Soundness splits on the rank of the polynomial moment matrix U ( X ) over K ( X ) . If that rank is at least κ , we do not ask any determinant to be nonzero at any particular sample point. Instead we choose one κ × κ minor with nonzero determinant Δ , note that the rank lost at a sample point s divides Δ to that order, and sum:
∑ s ∈ S δ s ≤ deg Δ ≤ κ W deg , wt ( T ) ≥ ∑ s ∈ S rank U ( s ) ≥ κ ( q − W deg ) ,
Here the Kronecker factorization U ( s ) = ∑ ℓ ∈ L T ℓ , s ⊗ w ℓ ( w ℓ ′ ) ⊤ gives the first inequality (Lemma 4.1). Determinantal divisibility gives the second: if δ s : = κ − rank C ( s ) , then ( X − s ) δ s ∣ Δ , and therefore ∑ s δ s ≤ deg Δ ≤ κ W deg (Lemma 4.3). For fixed r, W deg = 2 r ( n + 2 ) ( d − 1 ) ( c − 1 ) is linear in the radix d, equivalently proportional to κ 1 / r up to the displayed n , c , r factors; in particular, no quadratic κ -factor appears. Thus the high-rank branch replaces the determinant-zero cost D RS κ ( κ − 1 ) in Eq. (1). Rather than discarding every sample point where a maximal-fiber Hankel determinant vanishes, it charges each pointwise rank deficit to the vanishing order of one fixed nonzero minor.
Atomization instead of local valuation. In the complementary case the rank is below κ , so every scalar moment sequence obeys a short linear recurrence (Lemma 5.2). View the sequence as a functional g on the finite-dimensional recurrence algebra it generates. Before passing to the reduced algebra, generalized nilpotent components may still occur, while arbitrary coefficients could permit cancellation between candidate assignments. The doubling-is-squaring identity in Definition 3.10-(a) removes exactly these freedoms: the identity g ( ψ 2 ) = g ( ψ ) 2 makes g vanish on the nilradical and forces the idempotent values to satisfy c 2 = c , hence to lie in { 0 , 1 } . So every moment sequence is a plain sum ∑ ξ ∈ Ξ i , j ξ k over an entrywise set of distinct atoms with all coefficients equal to one (Lemma 5.3). Constraint-local Vandermonde isolation then synchronizes these entrywise atom sets and decodes a satisfying assignment (Lemma 6.2). This low-rank branch avoids the denominator-clearing cost 2 D RS κ 2 T in Eq. (1): the atom identities are proved inside the recurrence algebra and synchronized by a constraint-local Vandermonde system, rather than by inverse-Vandermonde local valuation followed by interpolation of a denominator-cleared global root identity.
Nearest codeword and syndrome decoding. A light table therefore yields a satisfying assignment, so an unsatisfiable formula forces weight at least R 0 = κ ( q − W deg ) , whereas completeness costs only R 1 = q ( n + 1 ) 2 . The block length is M = ( n + 1 ) 2 q r + 1 , because the table has one sample coordinate, r label coordinates, and one matrix block. The actual gap satisfies R 0 / R 1 ≥ 3 κ / [ 4 ( n + 1 ) 2 ] . With d = Θ ( n B ) and q = Θ ( r d n 2 ) , the block length is M = n B ( r + 1 ) + 2 r + 4 + o ( 1 ) , whereas R 0 / R 1 = n B r − 2 + o ( 1 ) . Thus the gap exponent is δ r , B = ( B r − 2 ) / ( B ( r + 1 ) + 2 r + 4 ) , which approaches r / ( r + 1 ) as B → ∞ for fixed r and then can be made arbitrarily close to 1 by choosing r large. Consequently, for every fixed 0 < ϵ < 1 , the reduction gives an M 1 − ϵ gap for binary nearest codeword and syndrome decoding (Theorem 7.1).
Euclidean GapCVP. The parity-kernel lattice lift identifies Hamming weight with squared Euclidean distance exactly, through dist 2 ( t , L ( B ) ) 2 = W ( H , b ) . Taking square roots halves the binary gap exponent. Because the binary theorem permits arbitrary slack, reserving part of it for radius rounding yields an M 1 / 2 − ϵ hardness factor for Euclidean GapCVP for every fixed 0 < ϵ < 1 / 2 (Theorem 8.1). That endpoint is the square-root scale of Aharonov and Regev [AR05], which no reduction of this kind can reach unless NP = coNP .

2.2.0.1. Roadmap.

Section 3 defines basic notation, reduces 3SAT to a sparse quadratic system, introduces the assignment encoding and the folded axis polynomials, defines the binary affine system, and proves completeness. Section 4 proves the rank-charging bound for tables whose moment matrix has large rank. Section 5 proves that in the complementary case the moment sequences are sums over entrywise sets of fewer than κ atoms with unit coefficients. Section 6 combines the two cases and decodes an atom into a satisfying assignment. Section 7 chooses the parameters and proves the n 1 − ϵ hardness result for binary nearest codeword and binary syndrome decoding. Section 8 lifts the binary instance to a full-rank integer lattice while preserving the optimum as a squared Euclidean distance, which gives the n 1 / 2 − ϵ hardness result for Euclidean GapCVP.

3. Preliminaries and The Binary Affine System

Section 3.1 defines basic notation and field conventions. Section 3.2 introduces index maps and bounded lifts; Section 3.3 converts 3SAT into a sparse quadratic encoding; Section 3.4 develops axis-wise interpolation and multi-axis exponent reconstruction; and Section 3.5 assembles these ingredients into the binary affine system and establishes its completeness properties.

3.1. Notation

For a positive integer n, we define [ n ] : = { 1 , … , n } . We write Z for the integers and R for the real numbers. For a matrix A, A ⊤ denotes its transpose and rank ( A ) its rank. If A is square, det ( A ) denotes its determinant. For matrices A and B, A ⊗ B denotes their Kronecker product, so that ( A ⊗ B ) ( i , a ) , ( j , b ) = A i , j B a , b .
For a vector x = ( x 1 , … , x n ) , its Hamming weight is wt ( x ) : = | { i ∈ [ n ] : x i ≠ 0 } | , and the same notation is used for the number of nonzero entries of a matrix. For binary vectors x , y ∈ F 2 n , their Hamming distance is dist H ( x , y ) : = wt ( x − y ) . For a nonempty set C ⊆ F 2 n , we define dist H ( x , C ) : = min y ∈ C dist H ( x , y ) . For x ∈ R n , its Euclidean norm is ∥ x ∥ 2 : = ∑ i = 1 n x i 2 , and for t ∈ R n and a nonempty V ⊆ R n we define dist 2 ( t , V ) : = inf v ∈ V ∥ t − v ∥ 2 . In every application below, V is a lattice or a finite set, so the infimum is attained.
Throughout, q is a power of two and K : = F q . We write K [ X ] and K ( X ) for the polynomial ring and the rational-function field over K . For a nonzero ψ ∈ K [ X ] , deg ψ denotes its degree, and we set deg 0 : = − ∞ . defines basic notation and field conventionsFor ψ ∈ K [ X ] , ord X − s ( ψ ) denotes the order of vanishing of ψ at X = s .

3.2. Index Maps and Bounded Lifts

To formulate the affine system, we need to translate bounded multi-indices into scalar exponents and back. The following index and lift maps provide this translation while respecting the prescribed coordinate range.
Definition 
(Index map and bounded lift). Fix a power of two d ≥ 2 , an integer r ≥ 1 , and an integer J ≥ 1 . For a multi-index p ∈ Z ≥ 0 r , its exponent index is
ind ( p ) : = ∑ h = 0 r − 1 p h d h .
For every integer 0 ≤ a ≤ J ( d r − 1 ) , the bounded lift
lift J ( a ) ∈ { 0 , … , J ( d − 1 ) } r
is the multi-index obtained by greedily expanding a from the highest base-d position to the lowest. It is chosen so that
ind ( lift J ( a ) ) = a .
Thus ind converts a multi-index into its scalar exponent, while lift J selects a bounded multi-index representing a given scalar exponent.
The bounded lift exists throughout the stated range. Indeed, the largest attainable index is J ( d − 1 ) ∑ h = 0 r − 1 d h = J ( d r − 1 ) . Set a r − 1 : = a and process h = r − 1 , r − 2 , … , 0 , maintaining 0 ≤ a h ≤ J ( d h + 1 − 1 ) . At position h, choose
p h : = min { J ( d − 1 ) , ⌊ a h / d h ⌋ } , a h − 1 : = a h − p h d h .
If the cap is inactive, then a h − 1 ≤ d h − 1 ≤ J ( d h − 1 ) . If it is active, then a h − 1 ≤ J ( d h + 1 − 1 ) − J ( d − 1 ) d h = J ( d h − 1 ) . Thus the invariant propagates, and at h = 0 it gives a − 1 = 0 . When J = 1 , this is the ordinary base-d expansion. Moreover, linearity of the index map gives
ind ( lift J ( a ) + lift J ( b ) ) = a + b
whenever both bounded lifts are defined.

3.3. Sparse Quadratic Encoding

Let φ be a 3SAT formula of encoding length N. Delete tautological clauses, repeated literals, and unused variables. If deleting repeated literals leaves a clause with fewer than three literals, repeat one of the survivors until it has exactly three; this changes neither the truth value of the clause nor the analysis below, in which two of the three falsity bits then coincide. The cases of an empty clause and of no remaining clauses are handled by fixed promise instances.
Give every occurrence of a variable its own bit, and tie the occurrences of one global variable to its lexicographically first occurrence by equalities. This keeps the number of equalities linear in the number of occurrences, rather than quadratic. For a clause with falsity bits β 0 , β 1 , β 2 , introduce one auxiliary bit y and impose y + β 0 β 1 = 0 and y β 2 = 0 . Adjoin one homogenizing coordinate and let z = ( z 0 , z 1 , … , z n ) collect it together with all occurrence and auxiliary bits, where z 0 is the homogenizing coordinate. For each falsity bit β t , let β ˜ t be z a or z a + z 0 , according as the corresponding literal is negated or unnegated. The clause equations become y z 0 + β ˜ 0 β ˜ 1 = 0 and y β ˜ 2 = 0 , while an occurrence equality becomes z 0 ( z a + z b ) = 0 . Thus every constraint above becomes a homogeneous quadratic form h ( z ) : = ∑ i = 0 n ∑ j = 0 n h i , j z i z j with at most five nonzero coefficients, since each falsity bit is either a coordinate or the sum of a coordinate and z 0 . Let h ( 1 ) , … , h ( L ) be the encoding forms. Both n and L are O ( N ) .
Lemma 
(Sparse quadratic encoding). The formula φ is satisfiable if and only if there is x ∈ F 2 n such that z : = ( 1 , x ) satisfies h ( m ) ( z ) = 0 for every m ∈ [ L ] .
Proof. 
Set z 0 = 1 . The equalities force all occurrences of one global variable to agree, so the occurrence bits define a Boolean assignment, and conversely. Fix a clause and its falsity bits. If β 0 β 1 = 0 , then the first equation forces y = 0 and the second holds for every β 2 . If β 0 = β 1 = 1 , then the first equation forces y = 1 and the second forces β 2 = 0 , so the third literal is true. If β 0 = β 1 = β 2 = 1 , the two equations are inconsistent. Hence the pair is solvable in y exactly when β 0 β 1 β 2 = 0 , which is exactly the condition that the clause is satisfied. □

3.4. Axis-Wise Interpolation and Multi-Axis Exponent Reconstruction

Let E be an extension of K of degree c : = [ E : K ] , generated by ζ , and chosen so that c log 2 q ≥ n . Fix y 1 , … , y n ∈ E that are linearly independent over F 2 ; such elements exist because [ E : F 2 ] = c log 2 q ≥ n . For x ∈ F 2 n , we define the assignment encoding
enc ( x ) : = ∑ i = 1 n y i x i ∈ E .
Since the y i are independent over F 2 , the map x ↦ enc ( x ) is injective.
We define the moment threshold κ : = d r . The point of the reconstruction is that κ consecutive powers of enc ( x ) are carried by r axis polynomials whose degrees grow only with d.
Lemma 
(Axis-wise interpolation). For every x ∈ F 2 n and every 0 ≤ j < r there is a unique P x , j ∈ K [ X ] with deg P x , j < c and P x , j ( ζ ) = enc ( x ) d j . Its coefficients are F 2 -linear functions of x.
Proof. 
The set { 1 , ζ , … , ζ c − 1 } is a K -basis of E , so every element of E is ψ ( ζ ) for a unique ψ ∈ K [ X ] of degree less than c, which gives existence and uniqueness. Since d j is a power of two and x i d j = x i , the Frobenius map gives
enc ( x ) d j = ∑ i = 1 n y i d j x i .
Writing y i d j = ∑ l = 0 c − 1 γ i , j , l ζ l with γ i , j , l ∈ K gives P x , j ( X ) = ∑ l = 0 c − 1 ( ∑ i = 1 n γ i , j , l x i ) X l , whose coefficients are F 2 -linear in x. □
Lemma 
(Multi-axis exponent reconstruction). For every x ∈ F 2 n and every p ∈ Z ≥ 0 r ,
∏ h = 0 r − 1 P x , h ( ζ ) p h = enc ( x ) ind ( p ) .
Proof. 
By Lemma 3.3, the h-th factor contributes exponent p h d h to enc ( x ) . The total exponent is therefore ∑ h = 0 r − 1 p h d h = ind ( p ) , proving the claim. □

3.5. The Binary Affine System

We define the sample set S : = K and the label set L : = K r . The synchronization step of Section 6 isolates atoms against a union of at most n + 1 atom sets, so the moment window has to be wider than ( n + 1 ) κ . We collect the resulting budgets in one definition.
Definition 
(Window and degree parameters). We use four named budgets because different stages of the proof require different ranges.
First, define the synchronization factor by
W syn : = n + 2 .
It provides enough slack to combine the atom sets arising from the at most n + 1 matrix entries in a linear-combination equation.
Second, define the isolation-window length by
W iso : = W syn ( κ − 1 ) + 1 .
This is the number of Hankel rows. The soundness proof uses the consecutive moments with indices 0 ≤ k < W iso for recurrence propagation and Vandermonde isolation.
Third, define the largest exposed moment index by
W ind : = 2 W syn ( κ − 1 ) .
The affine system exposes moments with indices 0 ≤ k ≤ W ind . Thus W ind is an endpoint, rather than the length of an isolation window.
Finally, define the degree budget by
W deg : = 2 r W syn ( d − 1 ) ( c − 1 ) .
It bounds the degrees of the interpolants obtained from products of the r axis polynomials: each admissible exponent is at most 2 W syn ( d − 1 ) and each axis polynomial has degree less than c.
We require q > 2 W deg and κ ≥ n + 1 . The latter condition gives ( n + 1 ) κ ≤ W iso .
These four budgets determine both the allowed digit range and the moment indices exposed by the affine system. We now collect the multi-indices whose coordinates respect that range.
Definition 
(Admissible multi-indices). The admissible multi-index set is
P : = { p ∈ Z ≥ 0 r : p h ≤ 2 W syn ( d − 1 ) for all h } .
For every p ∈ P , we have ind ( p ) ≤ W ind , so every admissible exponent lies in the exposed moment range.
For the row and column indices used below, we abbreviate lift ( a ) : = lift W syn ( a ) for 0 ≤ a < W iso .
For every ℓ ∈ L and s ∈ S the system has one binary variable
T i , j , ℓ , s ∈ F 2 ( 0 ≤ i , j ≤ n ) ,
so a coordinate of the system is named by a row index i, a column index j, a label ℓ, and a sample point s. For fixed ℓ and s these variables form the block T ℓ , s ∈ F 2 ( n + 1 ) × ( n + 1 ) whose ( i , j ) entry is T i , j , ℓ , s , and the whole table is denoted T . The number of binary coordinates is therefore
M : = ( n + 1 ) 2 q r + 1 .
Definition 
(Weighted interpolants).
The following quantities are derived linearly from the table T . For 0 ≤ i , j ≤ n , p ∈ P , and s ∈ S , the table is read through
f i , j , p ( s ) : = ∑ ℓ ∈ L T i , j , ℓ , s ∏ h = 0 r − 1 ℓ h p h ∈ K .
For every i , j and every p ∈ P , let F i , j , p ∈ K [ X ] be the unique polynomial of degree less than q satisfying F i , j , p ( s ) = f i , j , p ( s ) for every s ∈ S . Such a polynomial exists and is unique because S = K has q distinct points.
These interpolants package the dependence on the sample point s into the polynomial variable X. We next bound their degrees and require that evaluation at ζ depend only on the exponent encoded by the multi-index.
Definition 
(Degree and exponent consistency). The following two families constrain the interpolants.
(a)
Bounded degree. For every i , j and every p ∈ P ,
deg F i , j , p ≤ W deg .
(b)
Index-fiber consistency. For every 0 ≤ i , j ≤ n and all p , p ′ ∈ P with ind ( p ) = ind ( p ′ ) ,
F i , j , p ( ζ ) = F i , j , p ′ ( ζ ) .
When these constraints hold, any two multi-indices with the same ind give the same value at ζ . This allows us to replace the multi-indexed evaluations by a single sequence indexed by the scalar exponent k.
Definition 
(Exponent-indexed moments). For each 0 ≤ k ≤ W ind , fix once and for all a representative p ( k ) ∈ P with ind ( p ( k ) ) = k ; such representatives exist by the greedy construction above with J = 2 W syn . For every 0 ≤ i , j ≤ n , we define
u i , j , k : = F i , j , p ( k ) ( ζ ) .
Whenever the index-fiber consistency constraint holds, this equals F i , j , p ( ζ ) for every p ∈ P with ind ( p ) = k .
The quantities u i , j , k are the scalar moments used in the soundness argument. We now impose the algebraic identities satisfied by the honest moments, coming from the doubling-is-squaring identity, the linear-combination identity, and the quadratic encoding.
Definition 
(Algebraic moment constraints). These three families constrain the moments. Let W ind be the index budget defined in Definition 3.5.
(a)
Doubling is squaring. For every 0 ≤ i , j ≤ n and every k with 2 k ≤ W ind ,
u i , j , 2 k = u i , j , k 2 .
(b)
Linear combination. For every 0 ≤ j ≤ n and every k with k + 1 ≤ W ind ,
u 0 , j , k + 1 = ∑ i = 1 n y i u i , j , k .
(c)
Matrix inner product is zero. For every m ∈ [ L ] and every k ≤ W ind ,
∑ i = 0 n ∑ j = 0 n h i , j ( m ) u i , j , k = 0 .
The preceding conditions constrain the table only through its derived moments. Two final conditions act directly on the table blocks, enforcing symmetry and normalizing the anchor entry.
Definition 
(Table symmetry and normalization). The following two families constrain the entries of the table T directly, without passing through the moments.
(a)
Symmetry in the matrix indices. T i , j , ℓ , s = T j , i , ℓ , s for all i, j, ℓ ∈ L and s ∈ S .
(b)
Row summation in L is one. ∑ ℓ ∈ L T 0 , 0 , ℓ , s = 1 for every s ∈ S .
The binary affine system H θ = b consists of the two families of Definition 3.8, the three families of Definition 3.10, and the two families of Definition 3.11.
Lemma 
(The system is affine). Every condition in Definitions 3.8, 3.10, and 3.11 is an affine condition over F 2 on the table bits.
Proof. 
Each f i , j , p ( s ) is a fixed K -linear combination of table bits, hence an F 2 -linear function of them; interpolation on S and evaluation at ζ are K -linear and therefore F 2 -linear. Writing
F i , j , p ( X ) = ∑ a = 0 q − 1 F ^ i , j , p , a X a ,
each coefficient F ^ i , j , p , a ∈ K is an F 2 -linear function of the table bits. Family Definition 3.8-[item:degree](a) is precisely the vanishing of these coefficients for W deg < a < q . Evaluation also shows that every u i , j , k is an F 2 -linear function of the table bits. The remaining families Definition 3.8-[item:folding](b), Definition 3.10-[item:identifier](b), Definition 3.10-[item:source](c), Definition 3.11-[item:symmetry](a), and Definition 3.11-[item:anchor](b) are then F 2 -linear or affine by inspection. For Definition 3.10-[item:frobenius](a), the map λ ↦ λ 2 is the Frobenius automorphism of E , which is F 2 -linear, so u i , j , k 2 is an F 2 -linear function of the table bits as well. Expanding each E -valued equation in an F 2 -basis of E turns every family into binary affine equations. □
Let H θ = b denote the resulting binary affine system, where θ collects the table bits.
Lemma 
(Completeness). If φ is satisfiable, then H θ = b has a binary solution of weight at most
R 1 : = q ( n + 1 ) 2 .
Proof. 
Let x ∈ F 2 n be as in Lemma 3.2 and put z : = ( 1 , x ) . At each sample point s, we define the honest label
ℓ x ( s ) : = ( P x , 0 ( s ) , … , P x , r − 1 ( s ) ) ∈ L ,
and we set T ℓ x ( s ) , s : = z z ⊤ and T ℓ , s : = 0 for ℓ ≠ ℓ x ( s ) . Exactly one block is nonzero at each sample point, so the weight is q wt ( z ) 2 ≤ R 1 , which gives Eq. (3).
We verify the seven families. For every p ∈ P ,
f i , j , p ( s ) = z i z j ∏ h = 0 r − 1 P x , h ( s ) p h ,
and the polynomial z i z j ∏ h = 0 r − 1 P x , h p h has degree at most ( ∑ h = 0 r − 1 p h ) ( c − 1 ) ≤ 2 r W syn ( d − 1 ) ( c − 1 ) = W deg by Lemma 3.3, so it is the unique interpolant of Definition 3.7, so F i , j , p = z i z j ∏ h = 0 r − 1 P x , h p h ; in particular, Definition 3.8-[item:degree](a) holds. Evaluating at ζ and applying Lemma 3.4 gives
u i , j , k = z i z j enc ( x ) k ( 0 ≤ k ≤ W ind ) ,
which depends only on ind ( p ) = k and hence gives Definition 3.8-[item:folding](b). For Definition 3.10-[item:frobenius](a),
u i , j , 2 k = z i z j enc ( x ) 2 k = ( z i z j enc ( x ) k ) 2 = u i , j , k 2 ,
where the first step follows from Eq. (4), the second step follows from z i 2 = z i and z j 2 = z j together with the fact that squaring is additive in characteristic two, and the third step follows again from Eq. (4). For Definition 3.10-[item:identifier](b),
∑ i = 1 n y i u i , j , k = z j enc ( x ) k ∑ i = 1 n y i x i = z j enc ( x ) k + 1 = u 0 , j , k + 1 ,
where the first step follows from Eq. (4) and z i = x i for i ≥ 1 , the second step follows from the definition of enc ( x ) , and the third step follows from Eq. (4) and z 0 = 1 . For Definition 3.10-[item:source](c), ∑ i = 0 n ∑ j = 0 n h i , j ( m ) u i , j , k = enc ( x ) k h ( m ) ( z ) = 0 by Lemma 3.2. Family Definition 3.11-[item:symmetry](a) holds because z z ⊤ is symmetric, and Definition 3.11-[item:anchor](b) holds because z 0 2 = 1 . □

4. Rank Loss and Determinantal Charging

A low-weight table cannot support a moment matrix of large rank. The reason is that rank is subadditive and is bounded by the number of nonzero bits, while a determinant of a large minor cannot vanish to high order at too many sample points. Charging the amount of rank lost at each sample point, rather than merely whether rank is lost there, is what keeps the estimate linear in the moment threshold.
We define the polynomial block matrix U ( X ) , with rows indexed by ( i , a ) and columns by ( j , b ) for 0 ≤ i , j ≤ n , 0 ≤ a < W iso , and 0 ≤ b < κ , by
U ( X ) ( i , a ) , ( j , b ) : = F i , j , lift ( a ) + lift ( b ) ( X ) .
This is well defined: the entries of lift ( a ) + lift ( b ) are at most 2 W syn ( d − 1 ) , so lift ( a ) + lift ( b ) ∈ P , and ind ( lift ( a ) + lift ( b ) ) = a + b . Consequently, whenever the index-fiber consistency family Definition 3.8-[item:folding](b) holds, U ( ζ ) ( i , a ) , ( j , b ) = u i , j , a + b . The row window is wider than the column window, which is what the synchronization step of Section 6 consumes.
Lemma 
(Specialization). For every ℓ ∈ L , define w ℓ ∈ K W iso and w ℓ ′ ∈ K κ by ( w ℓ ) a : = ∏ h = 0 r − 1 ℓ h lift ( a ) h and ( w ℓ ′ ) b : = ∏ h = 0 r − 1 ℓ h lift ( b ) h . Then, for every s ∈ S ,
U ( s ) = ∑ ℓ ∈ L T ℓ , s ⊗ w ℓ ( w ℓ ′ ) ⊤ , and hence rank U ( s ) ≤ ∑ ℓ ∈ L wt ( T ℓ , s ) .
Proof. 
By Definition 3.7, the polynomial F i , j , p agrees with f i , j , p at every s ∈ S , so
U ( s ) ( i , a ) , ( j , b ) = ∑ ℓ ∈ L T i , j , ℓ , s ∏ h = 0 r − 1 ℓ h lift ( a ) h + lift ( b ) h = ∑ ℓ ∈ L T i , j , ℓ , s ( w ℓ ) a ( w ℓ ′ ) b ,
where the first step follows from the definition of f i , j , p applied to p = lift ( a ) + lift ( b ) , and the second step follows from the definitions of w ℓ and w ℓ ′ . This is the asserted Kronecker decomposition. Taking ranks,
rank U ( s ) ≤ ∑ ℓ ∈ L rank ( T ℓ , s ⊗ w ℓ ( w ℓ ′ ) ⊤ ) ≤ ∑ ℓ ∈ L rank ( T ℓ , s ) ≤ ∑ ℓ ∈ L wt ( T ℓ , s ) ,
where the first step follows from subadditivity of rank, the second step follows because a Kronecker product with a rank-one matrix does not increase rank, and the third step follows because every matrix is the sum of as many rank-one matrices as it has nonzero entries. □
To aggregate rank losses across the sample points, we need a local connection between specialization rank and determinant vanishing. The next lemma provides this connection: a rank deficit δ s forces the determinant to vanish to order at least δ s at X = s .
Lemma 
(Determinantal divisor). Let C ∈ K [ X ] κ × κ and s ∈ K , and define δ s : = κ − rank C ( s ) . If det C ≠ 0 , then ( X − s ) δ s divides det C .
Proof. 
Localize at X − s . The ring K [ X ] ( X − s ) is a discrete valuation ring, so C admits a Smith normal form C = E 1 Λ E 2 with E 1 , E 2 invertible over that ring and Λ diagonal with entries ( X − s ) e 1 , … , ( X − s ) e κ . Specializing at X = s gives rank C ( s ) = | { t : e t = 0 } | , so at least δ s of the exponents are positive, and therefore ord X − s ( det C ) = ∑ t = 1 κ e t ≥ δ s . □
The preceding lemma measures the rank lost at a sample point by the zero multiplicity of a nonzero minor. Summing these multiplicities over all sample points charges the total rank deficit to the degree of that minor, yielding the global weight bound below.
Lemma 
(Rank charging). Suppose the table satisfies Definition 3.8-[item:degree](a) and rank K ( X ) U ( X ) ≥ κ . Define R 0 : = κ ( q − W deg ) . Then
wt ( T ) ≥ R 0 .
Proof. 
Since the rank is at least κ , there is a κ × κ submatrix C ( X ) of U ( X ) with Δ : = det C ≠ 0 . Every entry of U ( X ) has degree at most W deg by Definition 3.8-[item:degree](a), so deg Δ ≤ κ W deg . Setting δ s : = κ − rank C ( s ) , Lemma 4.2 gives ( X − s ) δ s ∣ Δ for every s ∈ S , and distinct sample points give coprime factors, so
∑ s ∈ S δ s ≤ deg Δ ≤ κ W deg .
Therefore
wt ( T ) = ∑ s ∈ S ∑ ℓ ∈ L wt ( T ℓ , s ) ≥ ∑ s ∈ S rank U ( s ) ≥ ∑ s ∈ S rank C ( s ) = κ q − ∑ s ∈ S δ s ≥ κ ( q − W deg ) ,
where the first step is the definition of the total weight, the second step follows from Lemma 4.1, the third step follows because C ( s ) is a submatrix of U ( s ) , the fourth step follows from the definition of δ s and | S | = q , and the fifth step follows from the displayed bound on ∑ s ∈ S δ s . □

5. Short Recurrences and Atomic Moments

We now treat the complementary case, in which the moment matrix has rank below κ . A short recurrence gives a finite-dimensional recurrence algebra, which may initially contain generalized nilpotent components and arbitrary coefficient weights. The doubling-is-squaring condition in Definition 3.10-[item:frobenius](a) kills the nilradical and forces every surviving coefficient to be one, so each entrywise sequence is the plain sum over a set of fewer than κ atoms. No bound on the global union is needed; synchronization later uses only constraint-local unions.
Lemma 
(Atomization). Let E have characteristic two and let ( u k ) k ≥ 0 be a sequence in E satisfying a monic linear recurrence with characteristic polynomial χ ∈ E [ T ] of degree ρ ≥ 1 , and suppose u 2 k = u k 2 for every k < ρ . Then there is a set Ξ of at most ρ distinct roots of χ in a splitting field with
u k = ∑ ξ ∈ Ξ ξ k ( k ≥ 0 ) .
Proof. 
Let E ¯ be a splitting field of χ and put B : = E ¯ [ T ] / ( χ ) . Define g : B → E ¯ by g ( T k mod χ ) : = u k . This is well defined, because the map E ¯ [ T ] → E ¯ sending T k to u k annihilates every multiple of χ , which is precisely the recurrence at every shift.
We first show g ( ψ 2 ) = g ( ψ ) 2 for every ψ ∈ B . Writing ψ = ∑ i = 0 ρ − 1 a i T i and using that squaring is additive in characteristic two, ψ 2 = ∑ i = 0 ρ − 1 a i 2 T 2 i , so
g ( ψ 2 ) = ∑ i = 0 ρ − 1 a i 2 u 2 i = ∑ i = 0 ρ − 1 a i 2 u i 2 = ( ∑ i = 0 ρ − 1 a i u i ) 2 = g ( ψ ) 2 ,
where the first step follows from the definition of g, the second step follows from the hypothesis u 2 i = u i 2 , available because i < ρ , the third step follows again from additivity of squaring, and the fourth step follows from the definition of g.
Next, g vanishes on the nilradical of B . Indeed, let ψ ∈ B be nilpotent. Some power ψ 2 a with a ≥ 0 vanishes, and iterating the previous paragraph gives g ( ψ ) 2 a = g ( ψ 2 a ) = 0 , so g ( ψ ) = 0 because E ¯ is a field.
Consequently g factors through B red : = B / nil ( B ) , where nil ( B ) denotes the ideal of nilpotent elements of B . By the Chinese remainder theorem, B red is a product of t copies of E ¯ , one for each of the t distinct roots ξ 1 , … , ξ t of χ , where t ≤ ρ . Let ε 1 , … , ε t be the primitive idempotents and c ν : = g ( ε ν ) for 1 ≤ ν ≤ t . From ε ν 2 = ε ν we get c ν 2 = c ν , and in a field this forces c ν ∈ { 0 , 1 } .
Finally, the image of T in B red is ∑ ν = 1 t ξ ν ε ν , so T k maps to ∑ ν = 1 t ξ ν k ε ν and u k = g ( T k ) = ∑ ν = 1 t c ν ξ ν k . Taking Ξ : = { ξ ν : c ν = 1 } completes the proof, and | Ξ | ≤ t ≤ ρ . □
When the polynomial moment matrix has rank ρ < κ , its entries satisfy algebraic dependencies of bounded order. The next lemma converts this rank deficiency into a short linear recurrence for each scalar moment sequence, providing the starting point for the atomization argument.
Lemma 
(Short recurrence). Suppose the table satisfies the index-fiber consistency family Definition 3.8-[item:folding](b) and ρ : = rank K ( X ) U ( X ) < κ . Then for every i , j there is a monic linear recurrence of order ρ i , j ≤ ρ (where order zero means that the sequence vanishes) satisfied by ( u i , j , k ) k at every index
ρ i , j ≤ k < ρ i , j + W iso .
Proof. 
All minors of U ( X ) of size ρ + 1 vanish identically, hence also after substituting X = ζ , so rank E U ( ζ ) ≤ ρ . By the folding hypothesis, fixing i and j and letting a < W iso and b < κ range gives the Hankel submatrix ( u i , j , a + b ) of U ( ζ ) , whose rank is therefore at most ρ . Hence its first ρ + 1 columns are linearly dependent. Let ρ i , j ≤ ρ be minimal such that its columns c 0 , … , c ρ i , j are linearly dependent; such an index exists because the rank is at most ρ < κ . By minimality c 0 , … , c ρ i , j − 1 are independent, so c ρ i , j is a combination of them, which is a monic recurrence of order ρ i , j holding at every row index a < W iso , that is, at every index k = a + ρ i , j with a < W iso . □
Because the recurrence of Lemma 5.2 is verified at every row index below W iso , the sequence it extends agrees with the true moments on the whole window 0 ≤ k < W iso , and Lemma 5.1 applies with ρ i , j ≤ ρ < κ ≤ W iso . This gives the following form of the moments. The atom sets are indexed entrywise, and no claim is made that one set serves all entries; the synchronization is carried out constraint by constraint in Section 6, where each constraint couples at most n + 1 entries.
Lemma 5.2 gives a short recurrence for each moment sequence, but a recurrence alone may still involve arbitrary coefficients and repeated roots. The Frobenius identity removes this ambiguity by forcing the sequence to be a sum of pure exponentials with distinct atoms and unit coefficients, as formalized next.
Lemma 
(Atomic moments). Suppose the table satisfies Definition 3.8-[item:folding](b) and Definition 3.10-[item:frobenius](a), and suppose ρ : = rank K ( X ) U ( X ) < κ . Then for every i , j there is a set Ξ i , j of at most ρ distinct elements of a fixed algebraic closure of E with
u i , j , k = ∑ ξ ∈ Ξ i , j ξ k ( 0 ≤ k < W iso ) .
Consequently, for any set F of at most n + 1 index pairs, the union Ξ F : = ⋃ ( i , j ) ∈ F Ξ i , j satisfies | Ξ F | ≤ ( n + 1 ) ρ < ( n + 1 ) κ ≤ W iso .
Proof. 
Fix i , j and let ρ i , j be the order supplied by Lemma 5.2. If ρ i , j = 0 , then the relation produced there reads u i , j , k = 0 for every k < W iso , and Ξ i , j : = ∅ satisfies Eq. (6) on the whole window, so we may assume ρ i , j ≥ 1 below. Its characteristic polynomial is called χ i , j , and the recurrence is valid at every index ρ i , j ≤ k < ρ i , j + W iso . Let ( u ˜ k ) k ≥ 0 be the sequence determined by the first ρ i , j moments and by that recurrence. By induction on k, u ˜ k = u i , j , k for every k < W iso + ρ i , j , and in particular on the window 0 ≤ k < W iso : the two agree below ρ i , j by construction, and for ρ i , j ≤ k < W iso + ρ i , j the recurrence expresses both in the same way from earlier terms.
Since ρ i , j ≤ κ − 1 and W syn ≥ 1 , W iso + ρ i , j − 1 ≤ ( W syn + 1 ) ( κ − 1 ) ≤ W ind . Moreover, whenever 0 ≤ k < ρ i , j , 2 k ≤ 2 ρ i , j − 2 ≤ 2 ( κ − 2 ) ≤ W ind .
For every 0 ≤ k < ρ i , j , both k and 2 k lie in the range on which u ˜ agrees with u i , j , · , and 2 k ≤ W ind . Hence the doubling-is-squaring condition gives
u ˜ 2 k = u i , j , 2 k = u i , j , k 2 = u ˜ k 2 .
Thus Lemma 5.1 applies to u ˜ and produces a set Ξ i , j of at most ρ i , j distinct roots of χ i , j with u ˜ k = ∑ ξ ∈ Ξ i , j ξ k for every k ≥ 0 , which is Eq. (6) on the window where u ˜ and u i , j , · agree.
The final bound is immediate: a union of at most n + 1 sets of size at most ρ has at most ( n + 1 ) ρ elements, and ( n + 1 ) κ ≤ W iso holds by the choice of W iso and the requirement κ ≥ n + 1 . □
Remark 5.4.
It is tempting to shorten the argument by writing the block Hankel matrix as U ( ζ ) = ∑ ξ ∈ Ξ 1 ξ ⊗ v ξ v ξ ⊤ with v ξ = ( ξ a ) a and concluding rank U ( ζ ) = ∑ ξ ∈ Ξ rank 1 ξ , which would bound the total number of atoms by ρ and make the synchronization immediate. The standard factorization proving that identity uses linear independence of the vectors v ξ . Without this hypothesis the identity need not hold. Over F 4 , take the atoms 0, 1, and p with p 2 + p + 1 = 0 , two moment coordinates v ξ = ( 1 , ξ ) ⊤ , and 1 ξ = [ 1 ] for each of the three atoms. Then ∑ ξ ∈ { 0 , 1 , p } rank 1 ξ = 3 , whereas
∑ ξ ∈ { 0 , 1 , p } v ξ v ξ ⊤ = 1 p 2 p 2 p
has determinant p + p 4 = 0 and hence rank one. This is why the argument above keeps the atom sets entrywise and pays for the union with the synchronization factor W syn .

6. Soundness Criterion

We now combine the two cases. If the table is light, rank charging forces the moment matrix to have rank below κ . Atomization then represents every matrix entry through its own set of fewer than κ atoms, and constraint-local Vandermonde isolation synchronizes precisely the entries in each linear-combination, symmetry, encoding, or anchor equation and recovers a satisfying assignment.
Lemma 
(Isolation). Let L be a field, let Ξ ⊆ L be finite with distinct elements, and let ( c ξ ) ξ ∈ Ξ ⊆ L satisfy ∑ ξ ∈ Ξ c ξ ξ k = 0 for every 0 ≤ k < | Ξ | . Then c ξ = 0 for every ξ.
Proof. 
The system has coefficient matrix ( ξ k ) ξ ∈ Ξ , 0 ≤ k < | Ξ | , which is a Vandermonde matrix on the distinct elements of Ξ and hence invertible. □
The preceding lemmas provide two complementary tools: rank charging rules out low-weight solutions in the high-rank case, while atomization and Vandermonde isolation decode a satisfying assignment in the low-rank case. The next lemma combines these two branches. It shows that every solution lighter than R 0 must arise from a satisfiable formula.
Lemma 
(Soundness criterion). Assume n ≥ 4 . Suppose a binary solution of H θ = b has weight less than R 0 = κ ( q − W deg ) . Then φ is satisfiable.
Proof. 
Because the binary vector solves H θ = b , it satisfies Definition 3.8-[item:degree](a). Lemma 4.3 in contrapositive form therefore gives ρ : = rank K ( X ) U ( X ) < κ . The solution also satisfies Definition 3.8-[item:folding](b) and Definition 3.10-[item:frobenius](a), so Lemma 5.3 gives entrywise atom sets Ξ i , j of size at most ρ with Eq. (6) valid for 0 ≤ k < W iso . We define
1 ξ ( i , j ) : = 1 if ξ ∈ Ξ i , j and 1 ξ ( i , j ) : = 0 otherwise ,
and we let Ξ : = ⋃ 0 ≤ i , j ≤ n Ξ i , j , so that u i , j , k = ∑ ξ ∈ Ξ 1 ξ ( i , j ) ξ k for 0 ≤ k < W iso . No bound on the total number of atoms is claimed. Each constraint below couples at most n + 1 entries, so by Lemma 5.3 the union Ξ F of the atom sets it involves has fewer than W iso elements, and Lemma 6.1 applies to it on the window 0 ≤ k < W iso .
Symmetry. By Definition 3.11-[item:symmetry](a), f i , j , p ( s ) = f j , i , p ( s ) for every p ∈ P and s ∈ S . Uniqueness of interpolation gives F i , j , p = F j , i , p , and Definition 3.9 hence gives u i , j , k = u j , i , k for every k < W iso . The two entries involve at most 2 ρ < W iso atoms, so Lemma 6.1 applied to the differences gives 1 ξ ( i , j ) = 1 ξ ( j , i ) for every ξ .
Linear combination. By Definition 3.10-[item:identifier](b), for every j and every 0 ≤ k < W iso − 1 ,
∑ ξ ∈ Ξ ( 1 ξ ( 0 , j ) ξ + ∑ i = 1 n y i 1 ξ ( i , j ) ) ξ k = 0 ,
where we used Eq. (6) on both sides of Definition 3.10-[item:identifier](b) and collected the coefficient of ξ k . This relation involves the n + 1 entries ( 0 , j ) and ( i , j ) for 1 ≤ i ≤ n , whose atom sets have union of size at most ( n + 1 ) ρ ≤ ( n + 1 ) ( κ − 1 ) ≤ W iso − 1 . Thus the W iso − 1 moments indexed by 0 ≤ k < W iso − 1 suffice, and Lemma 6.1 gives
1 ξ ( 0 , j ) ξ = ∑ i = 1 n y i 1 ξ ( i , j ) ( ξ ∈ Ξ , 0 ≤ j ≤ n ) .
Structure of the coefficient matrices. Fix ξ with 1 ξ ≠ 0 . If 1 ξ ( 0 , j ) = 0 , then Eq. (7) gives ∑ i = 1 n y i 1 ξ ( i , j ) = 0 , and the y i are independent over F 2 , so the whole column j vanishes. Hence there is some j with 1 ξ ( 0 , j ) = 1 , and for every such j Eq. (7) gives ξ = ∑ i = 1 n y i 1 ξ ( i , j ) = enc ( x ) with x i : = 1 ξ ( i , j ) . Since x ↦ enc ( x ) is injective, this vector is the same for all such j; call it x ξ and put z ξ : = ( 1 , x ξ ) . Every column of 1 ξ is therefore 1 ξ ( 0 , j ) z ξ , that is, 1 ξ = z ξ a ξ ⊤ with ( a ξ ) j : = 1 ξ ( 0 , j ) . Symmetry gives ( a ξ ) j = 1 ξ ( 0 , j ) = 1 ξ ( j , 0 ) = ( z ξ ) j ( a ξ ) 0 . If ( a ξ ) 0 = 0 then a ξ = 0 and 1 ξ = 0 , contrary to assumption, so ( a ξ ) 0 = 1 and
1 ξ = z ξ z ξ ⊤ , ξ = enc ( x ξ ) , 1 ξ ( 0 , 0 ) = 1 .
Encoding equations. By Definition 3.10-[item:source](c), for every encoding form h ( m ) and every 0 ≤ k < W iso , using that h ( m ) has at most five nonzero coefficients and hence involves at most five entries, ∑ ξ ∈ Ξ ( ∑ i = 0 n ∑ j = 0 n h i , j ( m ) 1 ξ ( i , j ) ) ξ k = 0 with at most 5 ρ < W iso atoms involved, so Lemma 6.1 gives ∑ i = 0 n ∑ j = 0 n h i , j ( m ) 1 ξ ( i , j ) = 0 for every ξ ∈ Ξ . Substituting Eq. (8) turns this into h ( m ) ( z ξ ) = 0 .
Nonemptiness. By Definition 3.11-[item:anchor](b), f 0 , 0 , 0 ( s ) = 1 for every s, so the interpolant of Definition 3.7 is the constant polynomial 1 and Definition 3.9 gives u 0 , 0 , 0 = 1 . By Eq. (6) and Eq. (8), u 0 , 0 , 0 = ∑ ξ ∈ Ξ 1 ξ ( 0 , 0 ) counts modulo two the atoms with 1 ξ ≠ 0 , so that number is odd and in particular nonzero.
Pick any ξ with 1 ξ ≠ 0 . Then z ξ = ( 1 , x ξ ) satisfies every encoding form, so φ is satisfiable by Lemma 3.2. □

7. Hardness of Binary Nearest Codeword and Syndrome Decoding

It remains to choose the parameters. The radix d controls both the moment threshold κ = d r and the degree budget W deg , but it enters them very differently: κ grows like d r , whereas W deg grows only linearly in d. Since the sample field is taken greater than 2 W deg , the gap κ can be made almost as large as q r , and the block length pays q r + 1 . The ratio of these two exponents is what produces r / ( r + 1 ) .
Theorem 
(Main result, formal version of Theorem 1.8). Fix an integer r ≥ 1 and a real 0 < ϵ < r / ( r + 1 ) . Then GapNCP M r r + 1 − ϵ and GapSD M r r + 1 − ϵ are NP-hard under deterministic polynomial-time many-one reductions, where M is the binary block length. Consequently, binary nearest codeword and binary syndrome decoding are NP-hard to approximate within M r r + 1 − ϵ . For every fixed 0 < ϵ < 1 , their corresponding gap problems are NP-hard with factor M 1 − ϵ , and the optimization problems are NP-hard to approximate within the same factor.
Proof. 
Because r and ϵ are fixed rather than part of the input, all constants depending on them are hardwired into the reduction. If ϵ is irrational, choose a rational 0 < ϵ ′ < ϵ ; hardness for the larger factor obtained with ϵ ′ implies the claimed factor by monotonicity.
Let φ have encoding length N, and let n and L be as in Lemma 3.2, so n , L = O ( N ) . Fix an integer B ≥ 3 , depending only on the fixed r and ϵ , as chosen below. All sufficiently-large-n thresholds below are therefore constants. By adjoining unused Boolean variables before fixing the remaining parameters, we may assume that n ≥ 8 and that n exceeds all these thresholds. This preserves satisfiability and the sparsity of the encoding forms, and still gives n = O ( N ) . Every parameter below is a function of n alone, and the exponent is measured against M, so no lower bound on n in terms of N is needed. We define d to be the least power of two with d ≥ n B , and
κ : = d r , q : = the least power of two with q ≥ 12 r d n 2 , c : = ⌈ n / log 2 q ⌉ .
Then d ≥ 2 and κ ≥ n + 1 , as Section 3 requires. We let E be the field with q c elements, which contains K = F q , we let ζ generate E over K , and we let y 1 , … , y n be the first n members of an F 2 -basis of E , which exist because [ E : F 2 ] = c log 2 q ≥ n .
The parameter inequalities. We first check q > 2 W deg . Indeed
W deg = 2 r W syn ( d − 1 ) ( c − 1 ) < 4 r d n 2 log 2 q ≤ q 3 log 2 q ≤ q 12 < q 4 ,
where the first step follows from Definition 3.5, together with W syn = n + 2 ≤ 2 n , d − 1 ≤ d , and c − 1 < n / log 2 q , the second step follows from q ≥ 12 r d n 2 , and the third step follows from log 2 q ≥ 4 . Hence q − W deg ≥ 3 q / 4 , and by Eq. (5)
R 0 = κ ( q − W deg ) ≥ 3 κ q 4 .
The gap. By Eq. (2) and Eq. (3),
M = ( n + 1 ) 2 q r + 1 , R 1 = q ( n + 1 ) 2 , R 0 R 1 ≥ 3 κ 4 ( n + 1 ) 2 .
Since d = Θ ( n B ) and q = Θ ( r d n 2 ) up to one factor of two, taking logarithms base n gives
log n M = ( r + 1 ) ( B + 2 ) + 2 + o ( 1 ) , log n R 0 R 1 = B r − 2 + o ( 1 ) ,
where r and B are constants and the o ( 1 ) terms tend to zero as n grows. We define the fixed exponent
δ r , B : = B r − 2 B ( r + 1 ) + 2 r + 4 ,
which is the ratio of the two displayed quantities in the limit. As B tends to infinity δ r , B tends to r / ( r + 1 ) , so we may fix B with δ r , B > r / ( r + 1 ) − ϵ / 2 . Writing δ : = r / ( r + 1 ) − ϵ for the target exponent, the strict inequality δ < δ r , B leaves positive slack, so
R 0 R 1 ≥ 2 M δ
once n exceeds a fixed threshold. By the preceding padding, every instance entering the construction satisfies this threshold.
Completeness and soundness. Lemma 3.13 gives a solution of weight at most R 1 whenever φ is satisfiable, and Lemma 6.2 gives, in contrapositive form, that if φ is unsatisfiable then every solution has weight at least R 0 . Writing W ( H , b ) : = min { wt ( θ ) : H θ = b } for a consistent system,
φ satisfiable ⇒ W ( H , b ) ≤ R 1 , φ unsatisfiable and H θ = b consistent ⇒ W ( H , b ) ≥ 2 M δ R 1 > M δ R 1 .
Conversion. Gaussian elimination computes a solution ℓ of H ℓ = b and a generator matrix of the binary linear code C : = ker F 2 H . The solution set of H θ = b is the coset ℓ + C , so
dist H ( ℓ , C ) = min c ∈ C wt ( ℓ + c ) = min { wt ( θ ) : H θ = b } = W ( H , b ) ,
where the first step follows from the definition of Hamming distance together with ℓ − c = ℓ + c over F 2 , the second step follows because the solution set is ℓ + C , and the third step follows from the definition of W ( H , b ) . Output C , the target ℓ, and the radius R 1 ; its block length is M. For syndrome decoding, output H, the syndrome b, and the radius R 1 , whose optimum is W ( H , b ) and whose block length is again M.
Exceptional branches. If preprocessing finds an empty clause, or if H θ = b is inconsistent, then φ is unsatisfiable, the second case because a satisfiable formula produces a solution by Lemma 3.13. For nearest codeword output the fixed code { 00 } , the target 11, and the radius 1, whose distance is 2; for syndrome decoding output H : = I 2 , the syndrome b : = 11 , and the radius 1, whose optimum is also 2. If no clauses remain, then φ is satisfiable; output the code { 00 } with target 00 and radius 1, or the syndrome instance H : = I 2 with b : = 00 and radius 1, both of optimum zero.
Running time. For fixed r and B we have d , q = n O ( 1 ) and c = O ( n ) , so M = ( n + 1 ) 2 q r + 1 = n O ( 1 ) , which is N O ( 1 ) because n = O ( N ) . Write q = 2 m . By Shoup’s deterministic construction [28], first over F 2 in degree m and then over the resulting representation of F q in degree c, we can construct F q and a monic irreducible polynomial h ∈ F q [ T ] of degree c in time polynomial in log q and c; the small-characteristic guarantee applies because the characteristic is two. Any polynomial-factorization steps over the fixed prime field F 2 are deterministic and polynomial-time, so this construction introduces no randomized subroutine. Set E : = F q [ T ] / ( h ) and ζ : = T mod h . The product of the standard bases of F q over F 2 and of E over F q gives the explicit F 2 -basis from which y 1 , … , y n are selected, and elements of E are stored as c-tuples over F q . The interpolation matrix on S = K and its inverse are computed over K , so all coefficients F ^ i , j , p , a are explicit linear forms. We impose F ^ i , j , p , a = 0 for a > W deg . There are O ( ( n + 1 ) 2 | P | q ) coefficient conditions, O ( ( n + 1 ) 2 | P | 2 ) equal-exponent conditions, O ( ( n + 1 ) 2 W ind ) Frobenius conditions, O ( n W ind ) linear-combination conditions, O ( L W ind ) encoding conditions, and O ( M ) direct table conditions. A K -valued condition expands into log 2 q binary equations, and an E -valued condition expands into c log 2 q binary equations. Since L = O ( N ) and | P | , q , W ind , M = N O ( 1 ) , all conditions can be enumerated in polynomial time. Gaussian elimination is polynomial. Hence the whole mapping is deterministic polynomial time.
Conclusion. An M δ -approximation algorithm for either problem would compare its returned cost with M δ R 1 and thereby distinguish the two cases, so no such algorithm exists unless P = NP . Since δ = r / ( r + 1 ) − ϵ , this proves the first claim. For the second, given 0 < ϵ < 1 choose r ≥ 2 / ϵ and apply the first claim with ϵ / 2 . Then r r + 1 − ϵ 2 = 1 − 1 r + 1 − ϵ 2 ≥ 1 − ϵ . Therefore an M 1 − ϵ -approximation would also be an M r / ( r + 1 ) − ϵ / 2 -approximation, contradicting the first claim. □

8. Hardness of Euclidean GapCVP

The preceding section produces a gap in the minimum Hamming weight of a binary affine system. To obtain a Euclidean closest-vector instance, we realize the kernel code as the residue modulo two of a full-rank integer lattice and use a representative of the affine coset as the target. The minimum squared Euclidean distance to this lattice is exactly the minimum Hamming weight in the coset: odd coordinates cost at least one, and a minimum-weight binary representative attains equality. Consequently, a Hamming gap of M δ becomes a Euclidean-distance gap of M δ / 2 , which explains the exponent in this section.
Theorem 
(Euclidean closest vector, formal version of Theorem 1.3). Fix a real 0 < ϵ < 1 / 2 . There is a deterministic polynomial-time mapping that assigns to each 3SAT formula φ a nonsingular matrix B ∈ Z n × n , a target t ∈ Z n , and a radius r ∈ Q > 0 such that
φ satisfiable ⇒ dist 2 ( t , L ( B ) ) ≤ r , φ unsatisfiable ⇒ dist 2 ( t , L ( B ) ) > n 1 / 2 − ϵ r .
Consequently, GapCVP n 1 / 2 − ϵ ( 2 ) is NP-hard under deterministic polynomial-time many-one reductions.
Proof. 
Fix the theorem’s ϵ . The squared-distance identity below halves a binary gap exponent. We apply Theorem 7.1 with
δ : = 1 − ϵ ,
which that theorem supplies for every fixed 0 < ϵ < 1 . The target exponent 1 / 2 − ϵ is weaker than δ / 2 = 1 / 2 − ϵ / 2 , leaving the slack needed to absorb the rounding of the radius. We use the binary affine system constructed in the proof of Theorem 7.1. Before its conversion to nearest codeword, that proof deterministically produces a binary matrix H ∈ F 2 ρ × M , a syndrome b ∈ F 2 ρ , and an integer R 1 ≥ 1 , where ρ is the number of binary constraints. For a consistent system, write
W ( H , b ) : = min { wt ( x ) : x ∈ F 2 M , H x = b } .
We use the unused-variable padding in that proof with one additional fixed threshold, depending only on ϵ , so that M > 4 1 / ϵ . This preserves satisfiability and polynomial output size, and ensures 4 M − ϵ < 1 . Lemma 3.13 supplies the completeness guarantee. For soundness, we apply Lemma 6.2 and reuse the parameter verification from the proof of Theorem 7.1. These completeness and soundness conclusions are
φ satisfiable ⇒ H x = b is consistent and W ( H , b ) ≤ R 1 , φ unsatisfiable and H x = b consistent ⇒ W ( H , b ) ≥ M δ R 1 .
We convert every consistent affine system to a full-rank integer lattice without changing the dimension.
Let C : = ker F 2 H and compute a solution u ∈ F 2 M of H u = b . Gaussian elimination computes u and a basis for C. We define h : = dim C . Choose h linearly independent coordinate columns of a generator matrix, move them to the first h positions, and use invertible row operations to put the generator into systematic form [ I h A ] for some A ∈ F 2 h × ( M − h ) . The row operations only change the chosen basis of C, while the coordinate permutation preserves Hamming weight. The permuted code is therefore
C ′ : = { ( y , A ⊤ y ) : y ∈ F 2 h } .
All entries of A are henceforth represented by their lifts in { 0 , 1 } . The block form of B is chosen so that reduction modulo two remembers exactly the code C ′ , while the factor 2 I M − h makes the lattice full rank and ensures that it contains 2 Z M . Consequently, parity records the Hamming support of a coset representative, and the squared Euclidean norm charges at least one for each nonzero binary coordinate.
Define
B : = I h 0 A ⊤ 2 I M − h ∈ Z M × M .
We use the usual block-matrix conventions when h = 0 or h = M . The determinant of B is 2 M − h , so B is nonsingular.
We next identify its lattice. The first h columns of B, reduced modulo 2, generate C ′ , and the remaining columns reduce to zero. Moreover, 2 e j is a column of B for h < j ≤ M . If 1 ≤ i ≤ h and g i is the i-th column of B, then
2 e i = 2 g i − ∑ j = 1 M − h A i , j ( 2 e h + j ) .
Hence 2 Z M ⊆ L ( B ) . Every column of B reduces modulo 2 to an element of C ′ , so L ( B ) ⊆ { z ∈ Z M : z mod 2 ∈ C ′ } . For the reverse containment, let z ∈ Z M satisfy z mod 2 ∈ C ′ . The first h columns reduce to a basis of C ′ , so there is λ 0 ∈ L ( B ) with λ 0 mod 2 = z mod 2 . Then z − λ 0 ∈ 2 Z M ⊆ L ( B ) , and hence z ∈ L ( B ) . Therefore
L ( B ) = { z ∈ Z M : z mod 2 ∈ C ′ } .
Let t ∈ { 0 , 1 } M be the integer vector obtained by applying the same coordinate permutation to u. The affine coset t + C ′ is the permuted solution set of H x = b .
For any λ ∈ L ( B ) , we define x ′ : = ( t − λ ) mod 2 . Then x ′ ∈ t + C ′ , so x ′ is the coordinate permutation of a solution to H x = b . Since the permutation preserves Hamming weight, wt ( x ′ ) ≥ W ( H , b ) . Every nonzero coordinate of x ′ comes from an odd integer coordinate of t − λ , whose absolute value is at least one. Therefore
∥ t − λ ∥ 2 2 ≥ wt ( x ′ ) ≥ W ( H , b ) ,
where the first step follows because every coordinate on which x ′ is nonzero corresponds to an odd integer coordinate of t − λ , and the second step follows because x ′ represents a solution of H x = b . Conversely, let x attain W ( H , b ) and let x ′ be its coordinate permutation. Write x ′ = t + c for some c ∈ C ′ . We define λ : = t − x ′ . Then λ mod 2 = c ∈ C ′ , so the lattice characterization above gives λ ∈ L ( B ) . Moreover, we can show
∥ t − λ ∥ 2 2 = ∥ x ′ ∥ 2 2 = wt ( x ′ ) = wt ( x ) = W ( H , b ) ,
where the first step follows from t − λ = x ′ , the second step follows because x ′ is binary, the third step follows because the coordinate permutation preserves Hamming weight, and the fourth step follows from the choice of x as a minimum-weight solution. We have proved the exact identity
dist 2 ( t , L ( B ) ) 2 = W ( H , b ) .
The natural completeness radius is R 1 , which need not be rational. We round it up to the integer r so that the reduction has a valid rational output. This loses at most a factor two in distance, or a factor four after squaring. The padding condition 4 M − ϵ < 1 above ensures that the unused exponent slack absorbs this factor.
Set r : = ⌈ R 1 ⌉ . This is a positive integer and can be computed by deterministic integer binary search. We can show
R 1 ≤ r ≤ R 1 + 1 ≤ 2 R 1 ,
where the first step follows from r = ⌈ R 1 ⌉ , the second step follows from the defining property of the ceiling function, the third step follows from R 1 ≥ 1 .
If φ is satisfiable, we have
dist 2 ( t , L ( B ) ) = W ( H , b ) ≤ R 1 ≤ r ,
where the first step follows from Eq. (10), the second step follows from completeness, and the third step follows from the definition of r.
Suppose that φ is unsatisfiable and H x = b is consistent. If
dist 2 ( t , L ( B ) ) ≤ M 1 / 2 − ϵ r ,
then we can show
W ( H , b ) ≤ M 1 − 2 ϵ r 2 ≤ 4 M 1 − 2 ϵ R 1 < M δ R 1 ,
where the first step follows from the assumed upper bound on the Euclidean distance and Eq. (10), the second step follows from r 2 ≤ 4 R 1 (Eq. (11)), and the third step follows from δ = 1 − ϵ and the padding guarantee 4 M − ϵ < 1 .
This contradicts soundness. Thus
dist 2 ( t , L ( B ) ) > M 1 / 2 − ϵ r .
The lattice rank is M, which is denoted by n in the theorem statement, so this is precisely the claimed NO threshold.
It remains to specify the exceptional branches. If preprocessing finds an empty clause, or if H x = b is inconsistent, output
B = ( 2 ) , t = ( 1 ) , r = 1 2 .
This is a one-dimensional NO instance: its rank is n = 1 , so n 1 / 2 − ϵ r = 1 / 2 , whereas dist 2 ( 1 , 2 Z ) = 1 . A satisfiable formula never reaches the inconsistent branch by completeness. If no clauses remain after preprocessing, output
B = ( 2 ) , t = ( 0 ) , r = 1 2 ,
which is a YES instance.
For fixed ϵ , Theorem 7.1 constructs H, b, and R 1 in deterministic polynomial time. Gaussian elimination, the coordinate permutation, construction of B, and integer square-root computation are also deterministic polynomial-time operations. The basis has dimension exactly M and entries in { 0 , 1 , 2 } , while t is binary. Equations (3) and (2) give R 1 ≤ M , and hence the bit length of r is O ( log ( r + 1 ) ) = O ( log ( R 1 + 1 ) ) = O ( log ( M + 1 ) ) . Hence the complete mapping has polynomial output size. A polynomial-time algorithm for GapCVP n 1 / 2 − ϵ ( 2 ) composed with this mapping would decide 3SAT in polynomial time, proving the stated NP-hardness. □

Acknowledgments

The AI tool used in preparing this paper is Codex 5.6 Sol. The author first provided the model with the OpenAI paper [Ope26], from which it derived a finite-k inapproximability exponent of k − 1 10 k + 5 for the binary nearest codeword problem, tending to 1 / 10 as k → ∞ . With further efforts, the author figured out the bound can be improved to k − 1 6 k + 5 , whose limit is 1 / 6 . After another level of deep discussion, the author and the AI together improved the bound to 1 / 4 . After using a different multi-axis construction and lifting, the author figures out how to obtain the present exponent 1 − ϵ for every fixed 0 < ϵ < 1 . All proofs in this paper have been carefully verified by the author. This paper has been substantially revised by the author in response to comments and feedback from Johan Håstad and Omri Weinstein. The author would like to thank Josh Alman and Omri Weinstein for helpful discussions. The author would like to thank Johan Håstad for providing several useful writing suggestions.

References

  1. Arora, Sanjeev, László Babai, Jacques Stern, and Z. Sweedyk. 1997. The hardness of approximate optima in lattices, codes, and systems of linear equations. J. Comput. Syst. Sci. 54, 2: 317–331. [Google Scholar] [CrossRef]
  2. Aggarwal, Divesh, Rishav Gupta, Aditya Morolia, and Chuanqi Zhang. 2026. Mind the gap? not for SVP hardness under ETH! 53rd Int. Colloq. Autom. Lang. Program. volume 374: 8:1–8:24. [Google Scholar]
  3. Alekhnovich, Mikhail, Subhash A. Khot, Guy Kindler, and Nisheeth K. Vishnoi. Hardness of approximating the closest vector problem with pre-processing. Proceedings of the 46th Annual IEEE Symposium on Foundations of Computer Science, 2005; pp. pages 216–225. [Google Scholar]
  4. Ajtai, Miklós, Ravi Kumar, and D. Sivakumar. A sieve algorithm for the shortest lattice vector problem. Proceedings of the 33rd Annual ACM Symposium on Theory of Computing, 2001; pp. pages 266–275. [Google Scholar]
  5. Alon, Noga, Rina Panigrahy, and Sergey Yekhanin. 2010. Deterministic approximation algorithms for the nearest codeword problem. Algebr. Methods Comput. Complex. volume 9421: 1–13. [Google Scholar]
  6. Aharonov, Dorit, and Oded Regev. 2005. Lattice problems in NP ∩ coNP. J. ACM 52, 5: 749–765. [Google Scholar] [CrossRef]
  7. Arora, Sanjeev. 1994. Probabilistic Checking of Proofs and Hardness of Approximation Problems . Princeton technical report CS-TR-476-94. PhD thesis. Revised version available as. Berkeley: University of California. [Google Scholar]
  8. Babai, László. 1986. On Lovász’ lattice reduction and the nearest lattice point problem. Combinatorica 6, 1: 1–13. [Google Scholar] [CrossRef]
  9. Bhattiprolu, Vijay, Venkatesan Guruswami, Euiwoong Lee, and Xuandi Ren. Inapproximability of finding sparse vectors in codes, subspaces, and lattices. Proceedings of the 66th Annual IEEE Symposium on Foundations of Computer Science, 2025; pp. pages 1295–1303. [Google Scholar]
  10. Bhattiprolu, Vijay, Venkatesan Guruswami, and Xuandi Ren. 2025. PCP-free APX-hardness of nearest codeword and minimum distance. Electron. Colloq. Comput. Complex. TR25-029. [Google Scholar]
  11. Bitansky, Nir, Prahladh Harsha, Yuval Ishai, Ron D. Rothblum, and David J. Wu. Dot-product proofs and their applications. Proceedings of the 65th Annual IEEE Symposium on Foundations of Computer Science, 2024; pp. pages 806–825. [Google Scholar]
  12. Berman, Piotr, and Marek Karpinski. Approximating minimum unsatisfiability of linear equations. Proceedings of the Thirteenth Annual ACM-SIAM Symposium on Discrete Algorithms, 2002; Society for Industrial and Applied Mathematics, pp. pages 514–516. [Google Scholar]
  13. Berlekamp, Elwyn R., Robert J. McEliece, and Henk C. A. van Tilborg. 1978. On the inherent intractability of certain coding problems. IEEE Trans. Inf. Theory 24, 3: 384–386. [Google Scholar] [CrossRef]
  14. Bennett, Huck, and Chris Peikert. 2023. Hardness of the (approximate) shortest vector problem: A simple proof via Reed–Solomon codes. Approx. Randomization Comb. Optim. Algorithms Tech. volume 275: 37:1–37:20. [Google Scholar]
  15. Dinur, Irit, Guy Kindler, Ran Raz, and Shmuel Safra. 2003. Approximating CVP to within almost-polynomial factors is NP-hard. Combinatorica 23, 2: 205–243. [Google Scholar] [CrossRef]
  16. Dinur, Irit, Guy Kindler, and Shmuel Safra. Approximating CVP to within almost-polynomial factors is NP-hard. Proceedings of the 39th Annual IEEE Symposium on Foundations of Computer Science, 1998; pp. pages 99–111. [Google Scholar]
  17. Goldreich, Oded, and Shafi Goldwasser. 2000. On the limits of nonapproximability of lattice problems. J. Comput. Syst. Sci. 60, 3: 540–563. [Google Scholar] [CrossRef]
  18. Huang, Jeremy Ahrens, Young Kun Ko, and Chunhao Wang. 2026. On the (classical and quantum) fine-grained complexity of approximate CVP and Max-Cut. 53rd Int. Colloq. Autom. Lang. Program. volume 374: 111:1–111:17. [Google Scholar]
  19. Impagliazzo, Russell, and Ramamohan Paturi. 2001. On the complexity of k-SAT. J. Comput. Syst. Sci. 62, 2: 367–375. [Google Scholar] [CrossRef]
  20. Khot, Subhash A., Preyas Popat, and Nisheeth K. Vishnoi. 2014. Almost polynomial factor hardness for closest vector problem with preprocessing. SIAM J. Comput. 43, 3: 1184–1205. [Google Scholar] [CrossRef]
  21. Micciancio, Daniele, and Shafi Goldwasser. 2002. Complexity of Lattice Problems: A Cryptographic Perspective. Springer: volume 671. [Google Scholar]
  22. Moshkovitz, Dana. 2015. The projection games conjecture and the NP-hardness of lnn-approximating set-cover. Theory Comput. 11, 7: 221–235. [Google Scholar]
  23. Mukhopadhyay, Partha. 2022. The projection games conjecture and the hardness of approximation of Super-SAT and related problems. J. Comput. Syst. Sci. 123: 186–201. [Google Scholar] [CrossRef]
  24. Micciancio, Daniele, and Panagiotis Voulgaris. 2013. A deterministic single exponential time algorithm for most lattice problems based on voronoi cell computations. SIAM J. Comput. 42, 3: 1364–1391. [Google Scholar] [CrossRef]
  25. OpenAI. Ten advances in mathematics and theoretical computer science. Technical report, 2026. [Google Scholar]
  26. Reed, Irving S., and Gustave Solomon. 1960. Polynomial codes over certain finite fields. J. Soc. Ind. Appl. Math. 8, 2: 300–304. [Google Scholar] [CrossRef]
  27. Schnorr, Claus-Peter. 1987. A hierarchy of polynomial time lattice basis reduction algorithms. Theor. Comput. Sci. 53, 2–3: 201–224. [Google Scholar] [CrossRef]
  28. Shoup, Victor. 1990. New algorithms for finding irreducible polynomials over finite fields. Math. Comput. 54, 189: 435–447. [Google Scholar] [CrossRef]
  29. Boas, Peter van Emde. 1981. Technical Report MI-UvA-81-04. Another NP-complete partition problem and the complexity of computing short vectors in a lattice. Mathematisch Instituut, University of Amsterdam.
Figure 1. The soundness pipeline.
Figure 1. The soundness pipeline.
Preprints 230207 g001
Figure 2. A comparison of the bounded lift under two bases. With the same scalar a = 129 , lift bound J = 3 , and length r = 3 , base d = 4 gives lift 3 ( 4 ) ( 129 ) = ( 1 , 0 , 8 ) and ind 4 ( 1 , 0 , 8 ) = 129 , whereas base d = 8 gives lift 3 ( 8 ) ( 129 ) = ( 1 , 0 , 2 ) and ind 8 ( 1 , 0 , 2 ) = 129 . The superscripts and subscripts record the base only for this comparison; in the construction, d is fixed and therefore suppressed from the notation.
Figure 2. A comparison of the bounded lift under two bases. With the same scalar a = 129 , lift bound J = 3 , and length r = 3 , base d = 4 gives lift 3 ( 4 ) ( 129 ) = ( 1 , 0 , 8 ) and ind 4 ( 1 , 0 , 8 ) = 129 , whereas base d = 8 gives lift 3 ( 8 ) ( 129 ) = ( 1 , 0 , 2 ) and ind 8 ( 1 , 0 , 2 ) = 129 . The superscripts and subscripts record the base only for this comparison; in the construction, d is fixed and therefore suppressed from the notation.
Preprints 230207 g002
Figure 3. Rank charging. The same deficit δ s appears both as rank lost in the local weight bound and as the multiplicity of the zero of Δ at s. The degree of Δ therefore controls the total loss over all sample points.
Figure 3. Rank charging. The same deficit δ s appears both as rank lost in the local weight bound and as the multiplicity of the zero of Δ at s. The degree of Δ therefore controls the total loss over all sample points.
Preprints 230207 g003
Figure 4. Short-recurrence atomization for a fixed matrix entry. Low Hankel rank gives a short recurrence and candidate atoms. The doubling-is-squaring identity makes g vanish on nilpotents and forces every surviving coefficient to equal one, producing the entrywise set Ξ i , j .
Figure 4. Short-recurrence atomization for a fixed matrix entry. Low Hankel rank gives a short recurrence and candidate atoms. The doubling-is-squaring identity makes g vanish on nilpotents and forces every surviving coefficient to equal one, producing the entrywise set Ξ i , j .
Preprints 230207 g004
Figure 5. Constraint-local synchronization. No bound is imposed on the global union of the entrywise atom sets. Instead, each constraint uses fewer than W iso atoms, so Vandermonde isolation converts its moment identity into atomwise symmetry, linear-combination, encoding, or anchor conditions.
Figure 5. Constraint-local synchronization. No bound is imposed on the global union of the entrywise atom sets. Instead, each constraint uses fewer than W iso atoms, so Vandermonde isolation converts its moment identity into atomwise symmetry, linear-combination, encoding, or anchor conditions.
Preprints 230207 g005
Table 1. Historical hardness lower bounds and algorithmic upper bounds for Euclidean closest vector, measured as a function of the lattice rank n. In the second panel, D and R denote deterministic and randomized algorithms, respectively, and poly abbreviates polynomial time. In the 1997 row, the constant-factor hardness is unconditional, whereas the 2 ( log n ) 1 − ϵ factor assumes NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) . In the 2003 row, a > 0 is an absolute constant. The final hardness row holds for every fixed 0 < ϵ < 1 / 2 .
Table 1. Historical hardness lower bounds and algorithmic upper bounds for Euclidean closest vector, measured as a function of the lattice rank n. In the second panel, D and R denote deterministic and randomized algorithms, respectively, and poly abbreviates polynomial time. In the 1997 row, the constant-factor hardness is unconditional, whereas the 2 ( log n ) 1 − ϵ factor assumes NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) . In the 2003 row, a > 0 is an absolute constant. The final hardness row holds for every fixed 0 < ϵ < 1 / 2 .
Year Authors Reference Ratio
1997 Arora, Babai, Stern, and Sweedyk [ABSS97] Every constant; 2 ( log n ) 1 − ϵ
2003 Dinur, Kindler, Raz, and Safra [DKRS03] n a / log log n
2026 OpenAI [Ope26] n 1 / 400
2026 This paper Theorem 1.3 n 1 / 2 − ϵ
Year Authors Reference R/D Time Ratio
1986 Babai [8] D poly 2 n / 2
1987 Schnorr [27] D poly 2 O ( n ( log log n ) 2 / log n )
2001 Ajtai, Kumar, and Sivakumar [4] R poly 2 O ( n log log n / log n )
2013 Micciancio and Voulgaris [24] D poly 2 O ( n log log n / log n )
Table 2. Historical hardness lower bounds and algorithmic upper bounds for binary nearest codeword. In the first panel, the 2005 and 2014 rows concern nearest codeword with preprocessing; all other rows concern ordinary nearest codeword or the equivalent syndrome-decoding formulation. The constant-factor statements in the 1997 and 2025 rows are unconditional. The 2 ( log n ) 1 − ϵ statements in those rows, as well as the 2005 row, assume NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) ; the 2014 row assumes NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 / ϵ ) ) . Both 2026 hardness results are unconditional, and the final row holds for every fixed 0 < ϵ < 1 . In the second panel, n denotes the binary block length, k denotes the code dimension, and R and D denote randomized and deterministic algorithms, respectively. The randomized 2002 row records the sharper O ( k / log n ) guarantee that Alon, Panigrahy, and Yekhanin observed from Berman and Karpinski’s analysis; Berman and Karpinski themselves stated O ( k / log k ) . In the first row of the second panel, c > 0 is an arbitrary fixed constant. The parameter s is a fixed positive integer, and log ( s ) n denotes the s-fold iterated logarithm.
Table 2. Historical hardness lower bounds and algorithmic upper bounds for binary nearest codeword. In the first panel, the 2005 and 2014 rows concern nearest codeword with preprocessing; all other rows concern ordinary nearest codeword or the equivalent syndrome-decoding formulation. The constant-factor statements in the 1997 and 2025 rows are unconditional. The 2 ( log n ) 1 − ϵ statements in those rows, as well as the 2005 row, assume NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 ) ) ; the 2014 row assumes NP ¬ ⊆ DTIME ( 2 ( log n ) O ( 1 / ϵ ) ) . Both 2026 hardness results are unconditional, and the final row holds for every fixed 0 < ϵ < 1 . In the second panel, n denotes the binary block length, k denotes the code dimension, and R and D denote randomized and deterministic algorithms, respectively. The randomized 2002 row records the sharper O ( k / log n ) guarantee that Alon, Panigrahy, and Yekhanin observed from Berman and Karpinski’s analysis; Berman and Karpinski themselves stated O ( k / log k ) . In the first row of the second panel, c > 0 is an arbitrary fixed constant. The parameter s is a fixed positive integer, and log ( s ) n denotes the s-fold iterated logarithm.
Year Authors Reference Ratio
1997 Arora, Babai, Stern, and Sweedyk [ABSS97] Every constant; 2 ( log n ) 1 − ϵ
2005 Alekhnovich, Khot, Kindler, and Vishnoi [3] ( log n ) 1 − ϵ
2014 Khot, Popat, and Vishnoi [KPV14] 2 ( log n ) 1 − ϵ
2025 Bhattiprolu, Guruswami, and Ren [BGR25] Every constant; 2 ( log n ) 1 − ϵ
2026 OpenAI [Ope26] n 1 / 200
2026 This paper Theorem 1.8 n 1 − ϵ
Year Authors Reference R/D Time Ratio
2002 Berman and Karpinski [BK02] D poly O ( k / c )
2002 Berman and Karpinski [APY10,BK02] R poly O ( k / log n )
2010 Alon, Panigrahy, and Yekhanin [APY10] D poly O ( n / log n )
2010 Alon, Panigrahy, and Yekhanin [APY10] D n O ( s ) O ( k log ( s ) n / log n )
2010 Alon, Panigrahy, and Yekhanin [APY10] D n O ( log * n ) O ( k / log n )
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.