{"id":"511c1e9f-c85d-499b-8890-68ea5fe1b3a4","arxiv_id":"2504.13506","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A general algorithm computes Selmer groups for finite Galois modules using permutation-module resolutions and Hecke operators.","lead":"This paper gives a method to compute Selmer groups, key number theory objects, for any finite Galois module and any Selmer system. The method builds algebraic resolutions with Hecke operators and reduces the computation to S-units and class groups.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Proposition 3.7's proof of the unramified-local equality uses a false N-torsion exactness assertion; Theorem 3.8 is therefore not established as written.","rationale":"The reader's conditional verdict is on the right track, but the most precise failure is not the 'equal valuations imply equality' overstatement, which is repairable. The sharper gap is the asserted N-torsion exactness in Proposition 3.7: the proof dualizes a sequence involving P'_0/N and then reads off a statement about d0 on I0[N], even though d0 is dual to a map into P0, not P'_0. The trivial-module example shows the asserted intermediate equality is false in a case squarely inside the paper's framework. The dependence on [6] for Propositions 1.3 and 1.4 is a separate verification risk, but it is not a demonstrated error; the N-torsion step is a demonstrated error. Because Proposition 3.7 is essential to Theorem 3.8 and hence to Theorem A, the central claim is not proved as written. The underlying local statement is standard and likely can be repaired, so I do not see grounds to reject outright, but the paper should not be accepted without a corrected proof. This keeps the reader's CONDITIONAL verdict, hence UNCHANGED.","tokens_in":11235,"tokens_out":31821,"duration_ms":309180,"concrete_test":"Analytical check: instantiate Proposition 3.7's disputed step with M=Z/N (trivial action), v∤N. Use the resolution P1=Z --N--> P0=Z -> Z/N ->0, so locally I0=I1=(K^ur_v)^× and d0 is x↦x^N, d1=0. Compute Im(d0|I0[N])={1} and Ker(d1|I1[N])=μ_N, disproving the asserted equality 'Im(d0)=Ker(d1) for the N-th roots of unity.' Also inspect the dual of 0->P'_2/N -> P1/N -> P'_0/N ->0: it controls Hom(P'_0/N, μ_N), not Hom(P0/N, μ_N), so the proof conflates the two. This settles that the proof as written fails. Separately verify the proposition's actual conclusion via inflation-restriction in this example; if it holds, the statement is repairable, but the paper's argument must be replaced.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Proposition 3.7 is the load-bearing local statement behind Theorem 3.8. Its first-inclusion proof asserts that for the N-th roots of unity, Im(d0)=Ker(d1), and justifies this by reducing modulo N to the sequence 0 -> P'_2/N -> P1/N -> P'_0/N ->0 and 'taking the dual.' The dual used is Hom(-, μ_N); the exactness that would make this work is exactness on Z/N-modules, but d0 is expressed through Hom(P0/N, μ_N), not Hom(P'_0/N, μ_N), and these are conflated. The assertion is in fact false: for the trivial module M=Z/N, the resolution P1=Z --N--> P0=Z -> Z/N ->0 dualizes to 0->Z/N->K^× --x↦x^N--> K^× ->0, with d1=0. Then Im(d0|I0[N])={1}, while Ker(d1|I1[N])=μ_N. This invalid step is what makes the proof conclude that a local unit lies in B1_ram. A separate overstatement in the second inclusion, 'again by injectivity, d0(z)=x', is repairable because only a unit quotient is needed, but the first gap is not. Since Theorem 3.8 is the core of Theorem A, the paper's central claim is unproven as written.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper claims an algorithm (Theorem A) that, given a finite Galois module M over a number field K and a Selmer system L, computes the Selmer group Sel_L. The construction first builds a partial resolution of M by duals of permutation modules whose differentials are Hecke operators, then defines a group H^1_S from S-units of étale algebras. Theorem 3.8 asserts that if S contains the primes dividing |M| and spans Cl(L0), then H^1_S is exactly the Selmer group with no local conditions above S and unramified conditions outside S. Section 4 packages this into Algorithms 4.2 and 4.3 and states a conditional polynomial-time bound using oracles for S-units/class groups and fixed fields.","tokens_in":11535,"tokens_out":24915,"duration_ms":228070,"significance":"The proposed method is genuinely more general than existing Selmer-group algorithms for elliptic curves and, if correct, would be a valuable tool. The paper is clearly organized and the algorithmic idea is attractive; the complexity statement is explicit about which steps are not known to be polynomial. However, the proof of the central local statement (Proposition 3.7) contains a false exactness assertion, so Theorem 3.8 and hence Theorem A are not established in the present version.","major_comments":[{"comment":"The proof reduces to the assertion that \"for the N-th roots of unity, Im(d0) = Ker(d1)\", justified by dualizing 0 -> P'_2/N -> P1/N -> P'_0/N -> 0. This does not follow: d0 on N-torsion is the map Hom(P0/N, mu_N) -> Hom(P1/N, mu_N), whereas exactness of the displayed sequence only controls Hom(P'_0/N) -> Hom(P1/N) -> Hom(P'_2/N). The assertion is false in general: for M = Z/N with trivial G-action and the resolution P2 = 0, P1 = Z --N--> P0 = Z, the induced maps on N-torsion are d0 = 0 and d1 = 0, so Im(d0|I0[N]) = {1} while Ker(d1|I1[N]) = mu_N. Since this exactness is used to discard the root of unity zeta_N and conclude that a local unit lies in B1_ram, the inclusion H^1_units,v subset of Ker(Res) is not proved as written. This is load-bearing because Proposition 3.7 is the key input to Theorem 3.8.","section":"Proposition 3.7, first inclusion"},{"comment":"After deriving val(Res(d0(z)x^{-1})) = 0, the proof concludes \"so, again by injectivity, d0(z) = x\". Injectivity of d0 on the valuation lattice gives only equality of valuations, not equality of the elements in the multiplicative groups. The desired conclusion can likely be obtained by working modulo units, since val(Res(d0(z)x^{-1})) = 0 already says that x*d0(z)^{-1} is a unit, but the argument as written does not say this.","section":"Proposition 3.7, second inclusion"},{"comment":"Definition 3.1 and the proof of Proposition 3.2 rely on Propositions 1.3 and 1.4, which are imported from the author's preprint [6] without proof. Proposition 1.4 is essential for H^1_S to be well-defined, since Hecke operators must send S-units to S-units, and Proposition 1.3 is used in the proof of the injection H^1_S into H^1. The manuscript should either prove these facts or state explicitly and verify the hypotheses under which [6] applies; as it stands, a central part of the construction depends on an unverified source.","section":"Definition 3.1 and Proposition 3.2"}],"minor_comments":[{"comment":"The proof contains two evident typos: \"i composed with s = 0\" should be \"s composed with i = 0\", and \"f composed with i = 1\" should be \"f composed with i = 0\". The claim that i^* is surjective because i is injective also deserves a justification using divisibility of K^times; the lemma is true, but the proof as written is incomplete.","section":"Lemma 2.2"},{"comment":"The displayed definitions of Z^1_ram and B1_ram appear to interchange the indices of d0 and d1: Z^1_ram should be a kernel inside (L1 tensor K_v^ur)^times and B1_ram an image from (L0 tensor K_v^ur)^times, consistent with the usage in the proof of Proposition 3.7.","section":"Definition 3.3"},{"comment":"The proof has a variable-name inconsistency: \"Since x is in B1\" should refer to y. The saturation argument for Z^times_{S,L0} should also be spelled out explicitly.","section":"Proposition 3.2"},{"comment":"Definition 3.1 calls S a set of prime numbers, but S-units and the condition that S spans Cl(L0) require S to be a set of places or prime ideals; this should be clarified.","section":"Definition 3.1 / Proposition 3.6"},{"comment":"The proof that local adjustments can be patched globally is only a sketch: the reduction to fractional ideals and the use of the fact that S spans Cl(L0) should be written out as a weak-approximation or Chinese-remainder argument.","section":"Proposition 3.6"},{"comment":"The phrase \"the smallest set S\" may not be well-defined, since several sets can satisfy the listed conditions; the algorithm should say \"choose a finite set S satisfying the following conditions\".","section":"Algorithm 4.3"}],"recommendation":"major_revision","confidential_remarks":"The paper's main obstacle is the local statement Proposition 3.7; I recommend asking the author to supply a corrected proof of that statement before further consideration. The dependence on the author's own preprint [6] for Propositions 1.3 and 1.4 should also be clarified or eliminated."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague, here's my take on arXiv:2504.13506.\n\nThe paper proposes something genuinely new: a general algorithm to compute Selmer groups for arbitrary finite Galois modules and arbitrary Selmer systems, using resolutions whose morphisms are Hecke operators. The earlier algorithms (Bruin, Maistret-Shukla) were aimed at elliptic curves. The construction of H^1_S and the claim that it equals a Selmer group under mild hypotheses is a nice insight, and Algorithm 4.3 is clearly laid out. The author also states honestly that the implementation is future work and that two key propositions come from his own preprint [6].\n\nThe problems are in the proof of Proposition 3.7, which is load-bearing for Theorem 3.8. The stress-test note is correct: the argument that 'Im(d0)=Ker(d1) for the N-th roots of unity' comes from dualizing a short exact sequence modulo N, but the maps in the dual sequence do not line up with d0 and d1. The image of P1/N in P0/N is not the same as P'_0/N after reduction. For the trivial module Z/N, the resolution Z --N--> Z -> Z/N ->0 dualizes to 0->Z/N->K^× -^N-> K^× ->0, and on N-torsion Im(d0)=1 while Ker(d1)=μ_N. So the claimed equality is false. That invalidates the first inclusion H^1_units ⊆ Ker(Res), and with it Theorem 3.8. The second inclusion also has an overstatement ('again by injectivity, d0(z)=x' from equality of valuations), though that one is repairable if you work in the unit quotient.\n\nThere are smaller things. Lemma 2.2's proof contains a typo (f∘i=1 instead of 0) and the kernel-inclusion is backwards; the lemma itself is true for Hom(-, Kbar^×), so this is presentational. Proposition 3.2 has a step where k·x being an S-unit is used to conclude x is an S-unit; that only works if the prime divisors of k are in S, which is not stated. And the paper depends on [6] for two nontrivial properties of Hecke operators; that's a legitimate dependency, not circularity, but it makes the proof conditional on an unpublished preprint.\n\nBottom line: the central theorem is not established as written. The idea is good enough that I would send the paper to a careful referee, not desk reject. But the author needs to fix Prop 3.7 before this is citable. The right audience is people working on algorithmic Galois cohomology and arithmetic statistics; they will find the setup worth understanding, but they should not rely on Theorem A yet. I would not cite it in my own work in the next year.","headline":"Novel idea for computing Selmer groups via Hecke-operator resolutions, but the key local proposition has a genuine gap and Theorem 3.8 is not established as written.","tokens_in":12024,"tokens_out":19410,"would_cite":false,"duration_ms":167597,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["11R34","11R32","11Y40"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims an algorithm that computes the Selmer group of any finite Galois module from S-unit groups, using resolutions whose morphisms are Hecke operators.","keywords":["Selmer groups","Galois cohomology","Hecke operators","permutation modules","S-units","finite Galois modules","computational number theory","class groups"],"falsifier":"Take a finite Galois module whose algorithm-4.2 resolution has a nontrivial kernel for $d_0$, choose a place $v$ not dividing $|M|$, and seek $x$ in the local S-unit group with the same valuation as $d_0(z)$ but not equal to $d_0(z)$; finding such an $x$ would contradict the proof of Proposition 3.7 and therefore the identification of $H^1_S$ with the unramified Selmer group in Theorem 3.8.","tokens_in":11057,"feed_emoji":"🧮","tokens_out":7864,"duration_ms":74953,"temperature":0.7,"pith_summary":"The paper claims that Selmer groups, the Galois-cohomology objects behind descent and ranks of elliptic curves, can be computed by a uniform algorithm for any finite Galois module over a number field. The route is to resolve the module by permutation modules whose differentials are Hecke operators, dualize, and then read off cohomology from S-unit groups of the fields fixed by the stabilizers appearing in the resolution. The load-bearing comparison is a new group $H^1_S(\\mathcal{G}, M)$, built from S-units, which the author proves is exactly the Selmer group with unramified conditions outside $S$ once $S$ contains all primes dividing $|M|$ and spans the class group of the field $L_0$. If the proof is right, every step except computing fixed fields and S-units/class groups is polynomial, so Selmer computation is reduced to arithmetic in S-unit groups.","feed_headline":"Algorithm computes Selmer groups from S-units via Hecke resolutions","feed_subtitle":"General method handles any finite Galois module; only fixed fields and S-unit/class-group computations stay non-polynomial.","key_machinery":"The central object is a partial resolution of the finite Galois module $M$ by duals of permutation modules, with differentials expressed as sums of Hecke operators. Hecke operators are the morphisms attached by a natural isomorphism to double cosets $H\\backslash G/J$ between fixed-point modules, and the paper uses two imported properties: every surjective map between permutation modules has a quasi-inverse $\\Psi$ with $\\Phi \\circ \\Psi = k \\cdot \\mathrm{id}$ for a positive integer $k$ dividing $|G|^2$, and Hecke maps send S-units to S-units. These properties make $H^1_S$ well-defined and allow equations to be lifted from value groups. A Tor-functor argument on $N$-torsion-free permutation modules identifies the ramified local cohomology, completing the proof that $H^1_S$ is the unramified Selmer group outside $S$.","core_discovery":"Theorem A states that there is an algorithm which, given a finite Galois module $M$, the finite image $G$ of the Galois action, and a Selmer system $\\mathcal{L}$, outputs the Selmer group $\\mathrm{Sel}_{\\mathcal{L}}$. The algorithm first constructs a partial resolution $P_2 \\to P_1 \\to P_0 \\to M^* \\to 0$ by permutation modules with morphisms given by Hecke operators. Dualizing gives an exact sequence $0 \\to M \\to I_0 \\to I_1 \\to I_2$, and the paper defines $H^1_S(\\mathcal{G}, M)$ as the kernel of the induced map on S-unit groups modulo the image of the previous S-unit map. Theorem 3.8 proves that $H^1_S$ is the Selmer group attached to the Selmer structure with unramified conditions outside $S$, provided $S$ contains all primes dividing $|M|$ and the primes above $S$ span the class group $\\mathrm{Cl}(L_0)$. Since every Selmer group with prescribed local conditions lies inside such an $H^1_S$, the algorithm recovers $\\mathrm{Sel}_{\\mathcal{L}}$ as a kernel inside $H^1_S$; the complexity statement is polynomial except for oracles that compute fixed fields, S-units, and class groups.","pith_inferences":["Not in the paper itself: if the Hecke-operator properties from reference [6] are supplied with complete proofs, the method likely gives a practical route to Selmer groups for Galois modules arising in modularity and deformation problems.","The author's closing remark suggests the same resolution machinery could compute Selmer-type subgroups of $H^2(\\mathcal{G}, M)$; a natural test is to formalize the $H^2$ analogue.","Because $H^1_S$ is defined entirely from S-units, the equality in Theorem 3.8 suggests a way to compare different Selmer structures by changing $S$, which may simplify the subgroup search in algorithm 4.3.","The fixed-field oracle is the true bottleneck; replacing it with known polynomial-time algorithms for special Galois groups would make the complexity statement unconditional in those cases."],"forward_implications":["Selmer computation for any finite Galois module reduces, modulo fixed-field and S-unit/class-group oracles, to linear algebra in S-unit groups.","The group $H^1_S(\\mathcal{G}, M)$ itself is a Selmer group, so unramified-outside-$S$ Selmer groups admit an explicit S-unit description.","The method covers arbitrary finite Galois modules, not only modules arising from elliptic curves.","As a corollary noted in the paper, every Selmer group lies in some finitely generated $H^1_S$, giving another proof that Selmer groups are finitely generated.","With oracles for fixed fields, S-units, and class groups, the whole algorithm runs in time polynomial in the size of the input and in $|M|$."],"supporting_citations":[{"why":"Supplies the two Hecke-operator properties on which the construction rests: the splitting quasi-inverse with constant $k$ dividing $|G|^2$, and the statement that Hecke operators send S-units to S-units.","marker":"[6]"},{"why":"Gives that $I_i^G = \\bigoplus_j L_{i,j}^\\times$, so the cohomology of the dual resolution is computed in S-unit groups.","marker":"[13]"},{"why":"Provides the Tor-functor short exact sequence used in Proposition 3.7 to prove equality on $N$-torsion.","marker":"[4]"},{"why":"Supplies the algorithm to compute fixed fields $L_{i,j} = \\overline{K}^{H_{i,j}}$, one of the two non-polynomial steps.","marker":"[7]"},{"why":"Provides the methods for stabilizers, module representations, and computations in permutation groups used in algorithms 4.1 and 4.2.","marker":"[8]"},{"why":"Defines Hecke operators on permutation modules as the morphisms attached to cosets $H\\backslash G/J$, the basic object of the resolutions.","marker":"[15]"}],"fun_headline_variants":["Hecke operators unlock Selmer group computation","General Selmer group algorithm uses S-units and Hecke","Permutation resolutions compute Selmer groups","New algorithm: Selmer groups via Hecke morphisms","Method computes Selmer groups with Hecke operators"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The construction rests on two statements imported without proof from the author's earlier preprint—that surjective Hecke-operator maps admit splitting quasi-inverses with constant $k$ dividing $|G|^2$, and that Hecke operators preserve S-units—and, in Proposition 3.7, on treating equal valuations as equality, which needs the finite kernel of $d_0$ to vanish.","fun_headline_variants_meta":{"raw":{"variants":["Hecke operators unlock Selmer group computation","General Selmer group algorithm uses S-units and Hecke","Permutation resolutions compute Selmer groups","New algorithm: Selmer groups via Hecke morphisms","Method computes Selmer groups with Hecke operators"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000359,"raw_usage":{"total_tokens":1944,"prompt_tokens":946,"completion_tokens":998,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":562,"completion_tokens_details":{"reasoning_tokens":925}},"tokens_in":562,"tokens_out":998,"duration_ms":9436,"temperature":1.0,"reasoning_tokens":925,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T12:06:56.607588+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a finite Galois module whose algorithm-4.2 resolution has a nontrivial kernel for $d_0$, choose a place $v$ not dividing $|M|$, and seek $x$ in the local S-unit group with the same valuation as $d_0(z)$ but not equal to $d_0(z)$; finding such an $x$ would contradict the proof of Proposition 3.7 and therefore the identification of $H^1_S$ with the unramified Selmer group in Theorem 3.8.","supporting_citations":[{"cited_title":"Computing class groups by induction with generalised norm relations","cited_arxiv_id":"2411.13124","evidence_quote":"Supplies the two Hecke-operator properties on which the construction rests: the splitting quasi-inverse with constant $k$ dividing $|G|^2$, and the statement that Hecke operators send S-units to S-units."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives that $I_i^G = \\bigoplus_j L_{i,j}^\\times$, so the cohomology of the dual resolution is computed in S-unit groups."},{"cited_title":"Homological algebra","cited_arxiv_id":null,"evidence_quote":"Provides the Tor-functor short exact sequence used in Proposition 3.7 to prove equality on $N$-torsion."},{"cited_title":"Constructions using Galois Theory","cited_arxiv_id":"2010.01281","evidence_quote":"Supplies the algorithm to compute fixed fields $L_{i,j} = \\overline{K}^{H_{i,j}}$, one of the two non-polynomial steps."},{"cited_title":"Holt, Bettina Eick, and Eamonn A","cited_arxiv_id":null,"evidence_quote":"Provides the methods for stabilizers, module representations, and computations in permutation groups used in algorithms 4.1 and 4.2."}],"review_version":1}