Questions tagged [gaussian-noise]

20 questions
6
votes
1 answer

Differential privacy guarantees of Gaussian noise, when each coordinate has different sensitivity

Suppose you have a function $f$ that takes a dataset $D$ as input and returns an output in $\mathbb{R}^d$. If this function has $L^2$-sensitivity $\Delta$, then the analytical Gaussian mechanism (Theorem 8 in this paper) says that if you add…
Ted
  • 1,028
  • 5
  • 21
5
votes
1 answer

Noise flooding in Lattices

I noticed that in the paper [HLL24], the authors used the noise flooding technique to choose parameters and complete the proof. But I am confused that why set $\sigma \ge 2^{\kappa+6}y$ to guarantee the statistical distance between…
3
votes
1 answer

How small can the error be in LWE?

For modulus $Q$ and stddev $\sigma$, [GHS12] suggests that, to achieve 128-bit security, just choose the dimension $N$: $$ N\geq(Q/\sigma)\cdot 33.1 $$ This seems to suggest flexibility to choose smaller $\sigma$ ("as long as it is not too tiny"),…
Weikeng Chen
  • 564
  • 3
  • 13
2
votes
1 answer

How is it legal to use a rounded Gaussian for LWE?

As far as I understood, in Regev's initial paper, the error distribution was first constructed as follows: Then rounded in the following way: Using this distribution, the reduction in the theorem below can be achieved: I don't understand how in…
C.S.
  • 515
  • 3
  • 10
2
votes
1 answer

Standard deviation of gaussian noise in FHEW scheme

I've got two questions regarding the paper FHEW: Bootstrapping Homomorphic Encryption in less than a second. First, the final error of a ciphertext after the refresh procedure is stated as following a gaussian of standard deviation: $\beta =…
2
votes
0 answers

Can a reduction sample from conditional discrete gaussian in polynomial time without the help of a trapdoor?

For a matrix $\mathbf{A} \in \mathbb{Z}_q^{n\times m}$ I will use $\mathbf{A}^{-1}_\sigma (\mathbf{v})$ to denote a vector $\mathbf{u}$ sampled from a discrete gaussian over $\mathbb{Z}^m$ with standard deviation $\sigma$ conditioned on…
vxek
  • 551
  • 3
  • 10
2
votes
1 answer

The sum of independent discrete Gaussians is a discrete Gaussian

I am currently learning about lattice-based cryptography and, reading from A Decade of Lattice Cryptography by Peikert, specifically section 2.3, it emerges that [...] if the parameter s is greater or equal than the smoothing parameter of a lattice,…
Jackmill
  • 23
  • 3
2
votes
1 answer

How to choose the large noise when using noise flooding technique in FHE?

In LWE based multi party FHE schemes, the parties should choose a much larger noise when perform joint decryption. In this paper, the author just said that using noise flooding technique to avoid the information leakage about the noise of the…
Bob
  • 519
  • 3
  • 8
1
vote
1 answer

Errors for $\mathsf{LWE}$

Why do we take Gaussian-like errors in $\mathsf{LWE}$? Why for example we don't take uniform errors?
1
vote
1 answer

A smaller modulus-to-noise ratio means more security in LWE

Let $\text{Adv}^{\text{DLWE}}_{n,m,q,\sigma}$ be the advantage of an attacker to distinguish LWE samples from uniform ones, where $m$ is the number of samples, $q$ the modulus and $\sigma$ the standard deviation of the error distribution. I can't…
C.S.
  • 515
  • 3
  • 10
1
vote
0 answers

Is the error distribution in Learning with Errors (LWE), the discrete Gaussian distribution?

In $\mathbb{Z}$, the discrete Gaussian distribution is defined as $D_{Z,s}(x) = \frac{\rho_s(x)}{\rho_s(\mathbb{Z})}, x\in \mathbb{Z}$. In LWE, $(\overrightarrow{a}, b = \langle \overrightarrow{a}, \overrightarrow{s}\rangle + e)\in…
Bob
  • 519
  • 3
  • 8
1
vote
1 answer

Is the discretization of the Guassian distribution on torus still a discrete Gaussian distribution?

Let $\rho_s(x) = e^{-\pi x^2/s^2}$ be the Gaussian measures, then the discrete Gaussian distribution on $\mathbb{Z}$ could be defined as $D_{\mathbb{Z},s}(x) = \rho_s(x)/\sum_{n\in \mathbb{Z}}\rho_s(n)$. In [Regev05], the distribution $\Psi_s(r)$ on…
Bob
  • 519
  • 3
  • 8
1
vote
1 answer

BFV bootstrapping vs leveled scheme

I am trying to understand how BFV leveled scheme is different from BGV leveled scheme? Is the difference in the noise management techniques? Do we have modulus chain for BFV as well? how do we do bootstrapping in BFV? Any pointers to these questions…
1
vote
1 answer

Conditional distribution of an integer error vector, taken from an appropriate discrete Gaussian, given its syndrome [GPV'STOC2008]

I'm reading lemma 5.2 of [GPV'STOC2008, page 18] about conditional distribution of an integer error vector $\mathbf{e}\in\mathbb{Z}^{m}$, taken from an appropriate discrete Gaussian $\mathbf{e}\sim D_{\mathbb{Z}^{m},s}$, given its syndrome…
user1035648
  • 673
  • 5
  • 14
1
vote
1 answer

Gaussian width in lattice setting

In the lattice setting (like LWE, RLWE) , the Gaussian function is often defined as $$ \rho_{\Sigma}(x) = e^{-\pi x^T\Sigma^{-1}x} $$ The discrete Gaussian distribution $\mathcal{D}_{\Lambda, \Sigma}$ on lattice $\Lambda$ of dimension $n$ with…
Robert
  • 11
  • 2
1
2