non-malleable extractors
DESCRIPTION
Non-Malleable Extractors. Gil Cohen Weizmann Institute Joint work with Ran Raz and Gil Segev. Seeded Extractors. 0. 1. Seeded Extractor. Seeded Extractors. 11. 00. 10. 01. 01. 00. 10. 11. Seeded Extractor. Strong Seeded Extractor. Seeded Extractors. 11. 10. 101. 100. - PowerPoint PPT PresentationTRANSCRIPT
Seeded Extractors
2๐
2๐
000111 10 2๐
Seeded Extractor
2๐
Strong SeededExtractor
2๐00
0110
11
Seeded Extractors
2๐
2๐
000111
2๐
Seeded Extractor
2๐
000
101
100
111
โฆโฆ No limitation
Small-Bias Set
10
Non-Malleable Extractors [DodisWichs09]
Seeded Extractor Strong SeededExtractor
2๐
2๐
Non-MalleableExtractor
0
1
0
0
1
๐ด (๐ ) ๐
Proof Idea
๐
๐ ๐ด (๐ )
๐ธ๐ฅ๐ก (๐ ;๐ )๐ธ๐ฅ๐ก (๐ ; ๐ด (๐ ) )
is typically biased (say towards 0).
Proof Idea
๐
๐ ๐ด (๐ )
๐ธ๐ฅ๐ก (๐ ;๐ )๐ธ๐ฅ๐ก (๐ ; ๐ด (๐ ) )
is typically biased (say towards 0).
Proof Idea
๐ ๐ด (๐ )
๐ ๐ด (๐ )
๐๐๐๐ (๐๐ )Acyclic
Many verticesAverage edge weight is large
Proof Idea
๐ ๐ด (๐ )
๐ ๐ด (๐ )
๐๐๐๐ (๐๐ )Acyclic
Many verticesAverage edge weight is large
Proof Idea
โฏ ๐ ๐ โ ๐๐ด (๐ )โฏ
Small-Bias Set
[Raz05] implies that this is also an
extractor๐
stands in contradiction!
๐ ๐ =E ๐ฅ๐ก (๐ ; ๐ )โ๐ธ๐ฅ๐ก (๐ ; ๐ด (๐ ) )
? Construct a non-malleable extractor for smaller min-entropies, or prove this is hard.
? Waiting for applications to complexity (as apposed to cryptography).
Open Questions