Papers
Topics
Authors
Recent
Search
2000 character limit reached

Time-Space Tradeoffs for Distinguishing Distributions and Applications to Security of Goldreich's PRG

Published 17 Feb 2020 in cs.CC and cs.CR | (2002.07235v1)

Abstract: In this work, we establish lower-bounds against memory bounded algorithms for distinguishing between natural pairs of related distributions from samples that arrive in a streaming setting. In our first result, we show that any algorithm that distinguishes between uniform distribution on 0,1<sup>n{0,1}<sup>n and uniform distribution on an n/2n/2-dimensional linear subspace of 0,1<sup>n{0,1}<sup>n with non-negligible advantage needs 2<sup>Ω(n)2<sup>{\Omega(n)} samples or Ω(n<sup>2)\Omega(n<sup>2) memory. Our second result applies to distinguishing outputs of Goldreich's local pseudorandom generator from the uniform distribution on the output domain. Specifically, Goldreich's pseudorandom generator GG fixes a predicate P:0,1<sup>k</sup>→0,1P:{0,1}<sup>k</sup> \rightarrow {0,1} and a collection of subsets S1,S2,…,Sm⊆[n]S_1, S_2, \ldots, S_m \subseteq [n] of size kk. For any seed x∈0,1<sup>nx \in {0,1}<sup>n, it outputs P(xS1),P(xS2),…,P(xSm)P(x_{S_1}), P(x_{S_2}), \ldots, P(x_{S_m}) where xSix_{S_i} is the projection of xx to the coordinates in SiS_i. We prove that whenever PP is tt-resilient (all non-zero Fourier coefficients of (−1)<sup>P(-1)<sup>P are of degree tt or higher), then no algorithm, with $&lt;n<sup>\epsilon$ memory, can distinguish the output of GG from the uniform distribution on 0,1<sup>m{0,1}<sup>m with a large inverse polynomial advantage, for stretch m≤(nt)<sup>(1−ϵ)36⋅</sup>tm \le \left(\frac{n}{t}\right)<sup>{\frac{(1-\epsilon)}{36}\cdot</sup> t} (barring some restrictions on kk). The lower bound holds in the streaming model where at each time step ii, Si⊆[n]S_i\subseteq [n] is a randomly chosen (ordered) subset of size kk and the distinguisher sees either P(xSi)P(x_{S_i}) or a uniformly random bit along with SiS_i. Our proof builds on the recently developed machinery for proving time-space trade-offs (Raz 2016 and follow-ups) for search/learning problems.

Citations (7)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.