Hardness of LWE on General Entropic Distributions
Zvika Brakerski, Nico Döttling
Abstract
The hardness of the Learning with Errors (LWE) problem is by now a cornerstone of the cryptographic landscape. In many of its applications the so called “LWE secret” is not sampled uniformly, but comes from a distribution with some min-entropy. This variant, known as “Entropic LWE”, has been studied in a number of works, starting with Goldwasser et al. (ICS 2010). However, so far it was only known how to prove the hardness of Entropic LWE for secret distributions supported inside a ball of small radius. In this work we resolve the hardness of Entropic LWE with arbitrary long secrets, in the following sense. We show an entropy bound that guarantees the security of arbitrary Entropic LWE. This bound is higher than what is required in the ball-bounded setting, but we show that this is essentially tight. Tightness is shown unconditionally for highly-composite moduli, and using black-box impossibility for arbitrary moduli. Technically, we show that the entropic hardness of LWE relies on a simple to describe lossiness property of the distribution of secrets itself. This is simply the probability of recovering a random sample from this distribution s, given minimal amsmath wasysym amsfonts amssymb amsbsy mathrsfs upgreek -69pt document documents+e, where e is Gaussian noise (i.e. the quality of the distribution of secrets as an error correcting code for Gaussian noise). We hope that this characterization will make it easier to derive entropic LWE results more easily in the future. We also use our techniques to show new results for the ball-bounded setting, essentially showing that under a strong enough assumption even polylogarithmic entropy suffices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 657f83e2-1f88-40bd-af0f-9cb9c1561028Cited by top-tier papers4
- Continuous LWE is as Hard as LWE & Applications to Learning Gaussian MixturesAparna Gupte, Neekon Vafa, Vinod VaikuntanathanFOCS 2022 · 15 citations
- Quantum Oblivious LWE Sampling and Insecurity of Standard Model Lattice-Based SNARKsThomas Debris-Alazard, Pouria Fallahpour, Damien StehléSTOC 2024 · 8 citations
- Leftover Hash Lemma(s) Over Cyclotomic RingsKatharina Boudgoust, Oleksandra LapihaEUROCRYPT 2026 · 3 citations
- Near-Optimal Time-Sparsity Trade-Offs for Solving Noisy Linear EquationsKiril Bangachev, Guy Bresler, Stefan Tiegel, Vinod VaikuntanathanSTOC 2025 · 1 citation
Related papers
- A Lower Bound for Proving Hardness of Learning with Rounding with Polynomial ModulusParker Newton, Silas RichelsonCRYPTO 2023 · 5 citations
- Continuous LWEJoan Bruna, Oded Regev, Min Jae Song, Yi TangSTOC 2021 · 18 citations
- Rethinking Information-theoretic Generalization: Loss Entropy Induced PAC BoundsYuxin Dong, Tieliang Gong, Hong Chen, Shujian Yu et al.ICLR 2024 · 8 citations
- Improved Condensers for Chor-Goldreich SourcesJesse Goodman, Xin Li, David ZuckermanFOCS 2024 · 1 citation
- A Gaussian Leftover Hash Lemma for Modules over Number FieldsMartin R. Albrecht, Joël Felderhoff, Russell W. F. Lai, Oleksandra Lapiha et al.EUROCRYPT 2026
