Search arXiv⌕ Search

arXiv · 2609.37342

Collision Detection is Instance $\widetilde{O}$ptimal Under the Birthday Threshold

Abstract

Can structural knowledge about a hash function help accelerate the (black box) detection of collisions in it? This question is fundamental to cryptography theory given the importance of collision-resistant hash functions, and in this paper we tackle it from the angle of instance optimality, an ultimate notion of beyond worst case algorithm analysis that has gained significant traction in recent years. Instance optimality asks for a single algorithm that, on every input, performs nearly as well as the best correct algorithm that ``knows the structure'' of that specific input. Here we measure algorithms by the number of queries they make to the hash function $f\colon [n]\to [n]$, and we say that an algorithm ``knows the structure'' of the input if, in addition to query access to $f$, it has free access to an unlabeled copy $π^{-1}\circ f\circπ$ of $f$, for an unknown permutation $π$ on $[n]$. We prove the existence of an (almost) instance-optimal algorithm for collision detection in the regime most interesting from a cryptographic perspective: among functions where finding a collision takes significantly less than $\sqrt{n}$ queries. Specifically, we prove the existence of a single algorithm $A$ that, for any input $f$ in which a structure-aware algorithm can find a collision using $q\leq O(\sqrt{n/\log n})$ queries in expectation, $A$ can find a collision in at most $O(q\log n)$ queries. The $O(\log n)$ multiplicative overhead is tight, matching a lower bound of Ben-Eliezer, Grossman, and Naor [ICALP'25], and partially resolving their main open question. Our result implies, in particular, that it is impossible for a cryptographic designer to plant purely structural backdoors for collision finding (for this unlabeled notion of structure): whatever collisions the designer's secret knowledge finds, the public can find with a multiplicative overhead of $O(\log n)$.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Omri Ben-Eliezer, Tomer Grossman, Václav Rozhoň, Jakub Tětek. 2026-09-29. Collision Detection is Instance $\widetilde{O}$ptimal Under the Birthday Threshold. https://arxiv.org/abs/2609.37342

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Min-Sum Set Cover on Parallel Machines

We consider a generalization of the Min-Sum Set Cover to the setup with $m$ set-sequences, or in scheduling terminology, $m$ parallel machines. We call this problem Parallel Min-Sum Set Cover. To obtain approximation algorithms for its numerous variants we use a crucial sub-problem called Parallel Densest Subfamily. We prove that an $α$-approximation algorithm for this task gives a $4\cdotα$-approximation for the Parallel Min-Sum Set Cover, which yields $\frac{4\cdot e}{e-1}+ε$ and $4\cdot \frac{e}{e-1}^2+ε$-approximation ratios for identical and unrelated machines, respectively. To obtain the latter result we give a new $\frac{e}{e-1}^2+ε$-approximation algorithm for the Maximum Coverage Multiple Knapsacks problem which is of independent interest. If the sets are precedence-constrained, for unit cost sets we give an $\mathcal{O}(k^{2/3})$ approximation ($k$ is the number of sets). For the case of out-forest precedence constraints we improve this bound to $\mathcal{O}(\log k)$ via a reduction to the Group Steiner Orienteering problem, and show this is tight, unless $NP\subseteq ZTIME(n^{\mathcal{O}(\text{poly}(\log n))})$.

cs.DS↗

Learning Latent Algebraic Structure from Ambiguous Set Observations

We study when statistically learnable latent structure can also be recovered efficiently, and how membership queries change the answer. An unknown support $A\subseteq\mathbb F_2^n$ has small additive doubling and is observed through a fixed set $B$ satisfying $|A\triangle B|\leη|A|$. We seek one linear subspace $V$ such that every compatible support $A$ is covered by few $V$-cosets and satisfies $|V|\le|A|$. For every $η<1$, polynomially many uniform samples suffice statistically, with cost polynomial in the doubling constant and proportional to $(1-η)^{-1}$; this radius dependence is sharp. Under a specified hardness assumption for learning parities with noise (search-LPN), however, no polynomial-time sample-only learner achieves even constant covering cost, including when the latent support is unique. At fixed structural parameters and the same constant covering budget, adding exact membership queries to $B$ permits polynomial-time recovery. The general query learner constructs a short structural list and uses fresh samples to select one common output through a majority-coverage rule. Persistent structured cores make this candidate construction possible. At doubling one, a complementary distinction appears at $η=1/3$: coarse recovery remains polynomial time, while exact recovery requires exponentially many accesses in the worst case when latent cardinality is unknown.

cs.DS↗

Testing the Binary Rank with Polynomial Query Complexity

We design an adaptive two-sided error testing algorithm for the binary rank of a $0,1$ matrix $M$ with query complexity $O(d^3\log(d+1)/ε^2)$, where $d$ is the tested binary rank bound and $ε$ is the distance parameter. This answers an open question posed by Parnas, Ron and Shraibman~\cite{parnas2021property}, who asked if the binary rank can be tested with query complexity polynomial in $d$ and $1/ε$. Furthermore, our testing algorithm can be used to find an approximate binary decomposition of $M$ with an additional $d(n+m)$ queries. That is, under the promise that the binary rank of $M$ is at most $d$, we show how to find, with probability at least $5/6$, two $0,1$ matrices $A',B'$ such that $M' = A' \cdot B'$ is a $0,1$ matrix which differs from $M$ on at most an $O(ε)$ fraction of its entries. Our results also imply a testing algorithm with polynomial query complexity for the equivalent problem of testing if the edges of a bipartite graph can be partitioned into at most $d$ bicliques.

cs.DS↗