{"id":"faf5e79b-a23a-46a9-a409-ae056443c954","arxiv_id":"2505.23937","paper_version":1,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"Infinite explicit sequences of LCD, LCP, self-orthogonal, and self-dual AG codes over F_{q^2} attain the Tsfasman-Vladut-Zink bound.","lead":"This paper constructs explicit infinite families of error-correcting codes with a special cryptographic property, called LCD codes and LCPs, over the field F_{q^2}. The families reach the best known asymptotic performance limit and are the first explicit examples built from the Garcia-Stichtenoth tower of function fields.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Proposition 4.2 subtracts the place P∞ from a non-special degree-g_m divisor without verifying that the cited [3, Lemma 3] applies to this specific place; the LCD/LCP constructions depend on the resulting divisor being non-special.","rationale":"The reader's weakest assumption was Lemma 5.2, the imported different-divisor formula. My stress test instead focuses on Proposition 4.2's construction of the degree-(g_m-1) non-special divisor, specifically the subtraction of P∞ via [3, Lemma 3]. This is the divisor that must be used as gcd(G,H) in both the LCD and LCP theorems, so it is at least as load-bearing as Lemma 5.2. The concern is not that the result is false; it is that the proof contains an unverified reference to a lemma whose generality is doubtful without checking its statement. If [3, Lemma 3] is indeed exactly applicable, then the concern evaporates and the reader's ACCEPT stands. But because the authors do not state the lemma or verify its hypotheses for P∞, a conditional acceptance with a request to supply the verification is the honest recommendation. The paper is otherwise internally consistent: I spot-checked the degree computations, the gcd/lmd identities, and the limiting rate-distance calculations, and they match the stated TVZ bound.","tokens_in":20922,"tokens_out":35386,"duration_ms":354644,"concrete_test":"Read [3, Lemma 3] and check its exact hypotheses: does it conclude i(B-P)=0 from i(B)=0 and P∉Supp(B) for arbitrary P, or merely assert existence of some P, or require an additional non-Weierstrass-type condition? Independently, for q=4 and m=2,3,4, use MAGMA or Sage to construct the Garcia-Stichtenoth function fields from (3.1), form the divisor B-P∞ from (4.3), and compute its Riemann-Roch index i(B-P∞). If any of these indices is positive, Proposition 4.2 fails and the gcd divisor in Theorems 5.4 and 5.6 is special, invalidating the LCD/LCP conclusions.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The most load-bearing step is the unsupported subtraction in Proposition 4.2. After proving that B := Σ_{k=0}^{⌊(m-2)/2⌋} (q^{⌈m/2⌉}-1) A_k is non-special of degree g_m, the proof asserts that B - P∞ is non-special by invoking [3, Lemma 3]. Non-speciality of degree g is not preserved by subtracting an arbitrary rational place: for a non-special divisor A of degree g, the index i(A-P) can be positive, and for degree g-1 one has i(A-P)=ℓ(A-P), so this is exactly the condition that some effective divisor in |A| contains P. The paper does not verify any hypothesis on P∞ beyond P∞∉Supp(B), nor does it state the lemma's hypotheses. This matters because the divisor (4.4) is used verbatim as gcd(G(m),H(m)) in Theorem 5.4 and Theorem 5.6; Theorem 5.4 uses its non-speciality to conclude ℓ(gcd)=0 and hence the LCD property. If B-P∞ were special, the dimension and intersection arguments for both the LCD and LCP families would fail. This is a more direct gap than Lemma 5.2, which is at least imported from published ramification calculations.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper constructs explicit infinite sequences of LCD codes and of linear complementary pairs (LCPs) over F_{q^2} obtained from the Garcia-Stichtenoth tower. For q>=4 (and q>2 for LCPs), the main theorems (Theorems 5.5 and 5.7) give divisors G(m), H(m) such that the associated AG codes have limit parameters satisfying R + delta >= 1 - 1/(q-1), hence attain the Tsfasman-Vladut-Zink bound. The key technical ingredients are explicit non-special divisors of degree g_m - 1 on each tower level (Proposition 4.2), a computation of the canonical divisor W(m) = (dt/t) (Lemma 5.3), and the application of LCP/LCD criteria from prior work (Theorem 2.8). Section 6 additionally constructs self-orthogonal sequences (q >= 7) and self-dual sequences (q even, q >= 8) from the same tower, also attaining the TVZ bound.","tokens_in":21067,"tokens_out":34965,"duration_ms":309168,"significance":"If correct, this is a valuable contribution: it provides fully explicit infinite families of LCD codes and LCPs that attain the TVZ bound, going beyond existential results by Carlet et al. and Jin-Xing. The construction is concrete, with closed-form divisors and transparent asymptotic computations. The paper also gives explicit self-orthogonal and self-dual sequences with the same asymptotic optimality. The main proofs are computational and checkable, and the reliance on published ramification and Weierstrass-semigroup results is clearly indicated, making the paper a useful reference for explicit good AG code families.","major_comments":[],"minor_comments":[{"comment":"The step 'from [3, Lemma 3]' is not self-contained. Subtracting an arbitrary rational place from a non-special divisor of degree g does not in general preserve non-speciality, and the paper only notes that P_infty is not in the support of B. The conclusion is nevertheless correct here because B = sum (q^{ceil(m/2)} - 1) A_k is effective and non-special of degree g_m, so ell(B)=1 and L(B)=F_q; hence ell(B - P_infty)=0, which is equivalent to B - P_infty being non-special. Please include this argument (or state the precise lemma from [3] and verify its hypotheses) to make the proof complete.","section":"Section 4, Proposition 4.2"},{"comment":"The proof verifies that gcd(G,H) and lmd(G,H) - D are non-special of degree g_m - 1, but it does not explicitly verify condition (ii) of Theorem 2.8, namely ell(G) + ell(H) = n_m. This condition follows from the non-speciality of G and H (via G,H >= gcd), the relation G+H = gcd + lmd, and deg(lmd) = n_m + g_m - 1, but the argument should be stated.","section":"Section 5, Theorem 5.6"},{"comment":"The condition Supp(G(m)) cap Supp(D(m)) = empty (and similarly for H(m)) is not explicitly verified. It is true by construction because D(m) is supported on places lying over F_{q^2} \\setminus Omega, while G(m) and H(m) are supported on places over Omega, on zeros of x_1, and on P_infty; please state this for completeness.","section":"Section 5, Theorems 5.5 and 5.7"},{"comment":"The claim that for sufficiently large q the constructed codes exceed the Gilbert-Varshamov bound is stated in the abstract but not proved or referenced in the main theorems. A brief sentence indicating the standard threshold (e.g., where the TVZ line lies above the GV curve for F_{q^2}) would help the reader.","section":"Abstract and Introduction"},{"comment":"In the display for delta_m, there is an unmatched closing parenthesis in the numerator (after 'q^{ceil(m/2)}'), and the limit expression '1 - 3q - 2/(q^2 - q)' should be typeset with parentheses around the numerator as (3q-2)/(q^2-q).","section":"Proof of Theorem 5.7"},{"comment":"The reference to Stichtenoth's remark appears as '[26, Remark 4.3.7, (c)]' in one place and '[26, Remark 4.4.7 (c)]' in another; please unify the citation.","section":"Lemma 5.3"}],"recommendation":"minor_revision","confidential_remarks":"The paper is a solid explicit construction and the main results are convincing. The only technical point that deserves attention is the use of [3, Lemma 3] in Proposition 4.2; the argument can be made elementary and self-contained, so I recommend the authors add a few sentences there. The paper fits well within the scope of the journal."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"This paper earns its place: it turns existential results for LCD and LCP codes meeting the TVZ bound into explicit families on the Garcia-Stichtenoth tower. The key technical work is the construction of non-special divisors of degree g_m−1 (Prop. 4.2) and the explicit canonical divisor computation (Lemma 5.3). I spot-checked the gcd/lmd identities in Theorems 5.5 and 5.7, the degree calculations, and the limiting rates; they are internally consistent. The asymptotic claims R+δ = 1−1/(q−1) for both families check out.\n\nThe stress-test worry about subtracting P∞ from B does not hold up. The proof shows B is linearly equivalent to a non-special divisor of degree g_m with ℓ=1, so B itself has ℓ(B)=1; hence |B| is exactly {B}. Since P∞ is not in Supp(B), B−P∞ is automatically non-special: the only possible effective divisor in |B−P∞| would be B−P∞, which is not effective. The paper could have spelled this out, but the step is valid.\n\nSoft spots are minor. First, the paper never explicitly verifies Supp(G)∩Supp(D)=∅ in Theorems 5.5 and 5.7. It is true: D is the zero divisor of t, whose support consists of completely split places, while G and H are supported on the ramified places (the Pα, P∞, and the A_k). Still, the authors should state it. Second, Lemma 5.2 imports the different-divisor formula from [15] and [1] without proof. This is acceptable—the cited computations are published—but the lemma is load-bearing, so a referee should confirm the citations are correct. Third, the presentation has a few typos and minor index issues, but nothing that obscures the argument.\n\nWho gets value: coding theorists interested in explicit asymptotically good structured codes, and people working on side-channel-resistance applications of LCD/LCP codes. It also extends the authors' earlier work on Kummer/hyperelliptic/elliptic fields to the optimal tower. I'd send this to a serious referee; it deserves a careful look, and I expect it to be accepted after minor revisions.","headline":"Explicit LCD/LCP/self-dual AG code families attaining the TVZ bound on the Garcia-Stichtenoth tower; the construction is sound, and the stress-test worry about Proposition 4.2 dissolves once you note ℓ(B)=1.","tokens_in":21754,"tokens_out":3834,"would_cite":true,"duration_ms":36021,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["14G50","11T71","94B27","14Q05"],"pacs":[],"model":"deepseek-v4-flash","headline":"Explicit infinite LCD and LCP code families over $F_{q^2}$, built from the Garcia–Stichtenoth tower, attain the Tsfasman–Vladut–Zink bound and beat the Gilbert–Varshamov bound for large $q$.","keywords":["LCD codes","LCP of codes","algebraic geometry codes","Garcia–Stichtenoth tower","Tsfasman–Vladut–Zink bound","self-dual codes","tower of function fields","Gilbert–Varshamov bound"],"falsifier":"Compute the first nontrivial case, say $q=4$, $m=2$, inside the tower: write $T_2$ as an Artin–Schreier extension of $F_{16}(x_1)$, form $D(2)$ as the zero divisor of $t = (x_1^{16} - x_1)/(x_1^4 + x_1)$, take $G(2)$ and $H(2)$ from Theorem 5.5, and check with a computer algebra system whether $C_L(D(2),G(2))^\\perp$ equals $C_L(D(2),H(2))$ and whether its dimension is $24$; a mismatch would disprove the claimed construction.","tokens_in":20564,"feed_emoji":"🔐","tokens_out":12140,"duration_ms":120134,"temperature":0.7,"pith_summary":"This paper constructs explicit infinite families of error-correcting codes with a structural extra property: each code is complementary to its dual (LCD), or comes in a complementary pair (LCP), two families used in cryptography against side-channel and fault attacks. Working over the field $F_{q^2}$ with $q \\geq 4$, the authors use each level of the Garcia–Stichtenoth tower of function fields to define a code from a suitably chosen divisor, and they describe the needed non-special divisors of small degree at every level. They prove these codes have rate $R$ and relative distance $\\delta$ whose limits satisfy $R + \\delta \\geq 1 - 1/(q-1)$, the Tsfasman–Vladut–Zink bound, so for large $q$ they beat the Gilbert–Varshamov bound constructively rather than by an existence argument. The same tower is also shown to produce asymptotically good self-orthogonal codes for $q \\geq 7$ and, when $q$ is even, self-dual codes for $q \\geq 8$.","feed_headline":"Explicit code sequences attain the TVZ bound","feed_subtitle":"LCD, LCP, self-orthogonal, and self-dual codes from one tower beat Gilbert–Varshamov for large q.","key_machinery":"The machinery is the Garcia–Stichtenoth tower $T_m$ over $F_{q^2}$ together with explicit non-special divisors of degree $g_m - 1$ on every level. The tower supplies many rational places, with limit $\\lambda(T) = q-1$, and a fully described ramification divisor; the key identity is the description of the canonical divisor $W(m) = (dt/t)$ in Lemma 5.3, which lets the authors write the dual of $C_L(D(m),G(m))$ as $C_L(D(m), D(m) - G(m) + W(m))$. Choosing $G(m)$ and $H(m)$ with prescribed gcd and sum (or least common multiple) then forces the LCD and LCP conditions, and the explicit degrees of these divisors give the limiting rate and distance.","core_discovery":"The authors claim that for every $q \\geq 4$ there are explicit infinite sequences of LCD codes over $F_{q^2}$, and explicit infinite sequences of LCP pairs, both obtained from the Garcia–Stichtenoth tower and both attaining the TVZ bound $R + \\delta \\geq 1 - 1/(q-1)$. The construction attaches to each level $T_m$ the divisor $D(m)$ equal to the zero divisor of $t = (x_1^{q^2} - x_1)/(x_1^q + x_1)$, then chooses divisors $G(m)$ and $H(m)$ whose gcd is a non-special divisor of degree $g_m - 1$ and whose sum (or least common multiple) is controlled by the canonical divisor $W(m) = (dt/t)$. Under those divisor conditions, Theorem 5.4 makes $C_L(D(m),G(m))$ an LCD code with dual $C_L(D(m),H(m))$, while Theorem 5.6 makes the pair an LCP; Theorem 5.5 and Theorem 5.7 compute the resulting lengths, dimensions, and distance lower bounds, and pass to the limit to reach the TVZ bound. The paper further derives self-orthogonal and, for even $q$, self-dual sequences from the same tower.","pith_inferences":["The divisor recipe is portable: any tower with the same quality of ramification data, namely many rational places and an explicit different divisor, should yield analogous LCD and LCP families; the missing ingredient is usually writing explicit non-special divisors of degree $g-1$ at every level.","The proof gives explicit limiting rates and distances, so one could compute the smallest $q$ at which these families exceed the Gilbert–Varshamov bound; the paper states that this happens for sufficiently large $q$ but does not identify the threshold.","Because the codes are given by explicit divisors on an optimal tower, the construction could be turned into concrete code tables for modest $q$ and $m$, for instance as test cases for cryptographic countermeasures, though the paper does not address implementation."],"forward_implications":["For every $q \\geq 4$ there is an infinite sequence of LCD codes over $F_{q^2}$ whose asymptotic parameters satisfy $R + \\delta \\geq 1 - 1/(q-1)$; for large $q$ this is beyond the Gilbert–Varshamov curve.","The same tower gives infinite sequences of LCP pairs $(C_L(D(m),G(m)), C_L(D(m),H(m)))$ in which both component codes individually attain the TVZ bound.","The tower also yields self-orthogonal code sequences meeting the TVZ bound for $q \\geq 7$, and for even $q \\geq 8$ self-dual sequences with rate $1/2$ that exceed the Gilbert–Varshamov bound.","All constructions are explicit: each code is given by divisors written down on the $m$-th level of the tower, so the families are effective rather than existential."],"supporting_citations":[{"why":"Defines the Garcia–Stichtenoth tower, its genus formula, the totally ramified and completely split places, and the Drinfeld–Vladut optimality used throughout.","marker":"[15]"},{"why":"Gives the Weierstrass semigroup and the divisor properties of the functions $\\pi_j$, used in Proposition 4.2 to exhibit non-special divisors of degree $g_m - 1$.","marker":"[21]"},{"why":"Supplies the standard AG-code parameter formulas, Riemann–Roch dimension statements, and the dual-code formula $C_L(D,G)^\\perp = C_L(D, D-G+W)$ used in Theorem 5.4.","marker":"[26]"},{"why":"Provides the divisor conditions under which two AG codes form an LCP, which Theorems 5.4 and 5.6 verify.","marker":"[6]"},{"why":"Used in Lemma 5.2 for the different exponents of the ramified places in the tower, which determines the canonical divisor $W(m)$.","marker":"[1]"},{"why":"Gives the residue criteria for AG codes to be self-orthogonal or self-dual, used in Section 6.","marker":"[24]"},{"why":"Justifies subtracting one rational place from a non-special divisor of degree $g_m$ while keeping it non-special, used in Proposition 4.2.","marker":"[3]"},{"why":"Earlier constructions of LCD and LCP AG codes from Kummer, hyperelliptic, and elliptic function fields whose divisor strategy this paper adapts to the tower.","marker":"[10]"}],"fun_headline_variants":["Explicit LCD and LCP codes attain TVZ bound","One tower yields LCD, LCP, self-dual codes at TVZ","Self-orthogonal and self-dual codes meet TVZ bound","Codes from Garcia-Stichtenoth tower beat classic bound for large q","Garcia-Stichtenoth codes exceed Gilbert-Varshamov bound"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The construction rests on the claimed formula for how the places of the tower split and ramify at each level (Lemma 5.2); if that ramification formula were wrong, the canonical divisor used to form duals would be wrong and the LCD and LCP divisor conditions would no longer hold.","fun_headline_variants_meta":{"raw":{"variants":["Explicit LCD and LCP codes attain TVZ bound","One tower yields LCD, LCP, self-dual codes at TVZ","Self-orthogonal and self-dual codes meet TVZ bound","Codes from Garcia-Stichtenoth tower beat classic bound for large q","Garcia-Stichtenoth codes exceed Gilbert-Varshamov bound"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001099,"raw_usage":{"total_tokens":4631,"prompt_tokens":1034,"completion_tokens":3597,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":650,"completion_tokens_details":{"reasoning_tokens":3506}},"tokens_in":650,"tokens_out":3597,"duration_ms":24315,"temperature":1.0,"reasoning_tokens":3506,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T12:39:13.840140+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the first nontrivial case, say $q=4$, $m=2$, inside the tower: write $T_2$ as an Artin–Schreier extension of $F_{16}(x_1)$, form $D(2)$ as the zero divisor of $t = (x_1^{16} - x_1)/(x_1^4 + x_1)$, take $G(2)$ and $H(2)$ from Theorem 5.5, and check with a computer algebra system whether $C_L(D(2),G(2))^\\perp$ equals $C_L(D(2),H(2))$ and whether its dimension is $24$; a mismatch would disprove the claimed construction.","supporting_citations":[{"cited_title":"Garcia and H","cited_arxiv_id":null,"evidence_quote":"Defines the Garcia–Stichtenoth tower, its genus formula, the totally ramified and completely split places, and the Drinfeld–Vladut optimality used throughout."},{"cited_title":"Pellikaan, H","cited_arxiv_id":null,"evidence_quote":"Gives the Weierstrass semigroup and the divisor properties of the functions $\\pi_j$, used in Proposition 4.2 to exhibit non-special divisors of degree $g_m - 1$."},{"cited_title":"Stichtenoth , Algebraic Function Fields and Codes , Graduate Texts in Mathematics, Springer Berlin Heidel- berg, 2008","cited_arxiv_id":null,"evidence_quote":"Supplies the standard AG-code parameter formulas, Riemann–Roch dimension statements, and the dual-code formula $C_L(D,G)^\\perp = C_L(D, D-G+W)$ used in Theorem 5.4."},{"cited_title":"Bhowmick, D","cited_arxiv_id":null,"evidence_quote":"Provides the divisor conditions under which two AG codes form an LCP, which Theorems 5.4 and 5.6 verify."},{"cited_title":"Aleshnikov, V","cited_arxiv_id":null,"evidence_quote":"Used in Lemma 5.2 for the different exponents of the ramified places in the tower, which determines the canonical divisor $W(m)$."},{"cited_title":"Stichtenoth , Self-dual Goppa codes , Journal of Pure and Applied Algebra, 55 (1988), pp","cited_arxiv_id":null,"evidence_quote":"Gives the residue criteria for AG codes to be self-orthogonal or self-dual, used in Section 6."},{"cited_title":"Ballet and D","cited_arxiv_id":null,"evidence_quote":"Justifies subtracting one rational place from a non-special divisor of degree $g_m$ while keeping it non-special, used in Proposition 4.2."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Earlier constructions of LCD and LCP AG codes from Kummer, hyperelliptic, and elliptic function fields whose divisor strategy this paper adapts to the tower."}],"review_version":1}