{"id":"8bb340ab-e3da-4a14-b225-e44b329b2bf1","arxiv_id":"2607.20765","paper_version":1,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A Legendre pair of length 333 cannot be invariant under any common multiplier subgroup of order at least 9; only subgroups of order at most 6 remain possible.","lead":"This paper proves that no Legendre pair of length 333 can be fixed by a common multiplier group of order at least 9, cutting off a structured route toward a Hadamard matrix of order 668, the smallest unresolved order. The proof combines an orbit-restricted compression argument with verified SAT/DRAT certificates, leaving only multiplier groups of order at most 6 possible.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Computational exclusions rest on unexecuted DRAT/PB certificates and an unproved row-sum reachable set; analytic core is sound, so risk is trust-on-rerun only.","rationale":"The paper's in-text mathematics is solid: Proposition 1 and Proposition 2 correctly reduce to 668 as a sum of two squares; Lemma 4 and the value-set analysis check out; Theorem 2's one-big-one-small count and the bound -249+9<-74 are correct. The subgroup count is consistent (21 impossible, 9 open, 19 of order >=9 all impossible). The main theorem is stated conservatively and does not overclaim. The only genuine risk is the computational certificate chain and the unproved row-sum propagation; both are checkable and the archive provides the necessary artifacts. The reader's ACCEPT with MODERATE confidence is appropriate. Running the suggested verification would convert the trust-on-rerun into a confirmed check, but even without that run, the evidence (DRAT proofs, positive controls, hashes, independent generator) supports the verdict. No adjustment is needed.","tokens_in":9903,"tokens_out":17364,"duration_ms":147474,"concrete_test":"Execute the archived verification pipeline: (1) run drat-trim on the five DRAT traces and verify the SHA-256 manifest; (2) recompute the direct pseudo-Boolean upper bounds for IDs 11,15,19,23,28 at shift 111; (3) recompute the modulo-24 subset-sum reachable sets for IDs 16,17,18,24 from the archived orbit-size lists and confirm 1 and 23 are excluded. If all three pass, the computational exclusions are confirmed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central classification is correct in its analytic pieces: the mod-3 and mod-37 Fourier obstructions, the value-set 9-compression, and the H12 argument are rigorous. The load-bearing fragility is entirely in the computational exclusions. For 11 subgroups the impossibility is certified by DRAT traces or direct pseudo-Boolean upper bounds that this review did not execute; if a CNF-encoding bug or a mismatched certificate existed, those exclusions (IDs 13,14,20,21,22 and 11,15,19,23,28) would not be sound, despite Lemma 5 and the positive controls. A second, smaller gap is Proposition 3: the row-sum reachable set for IDs 16,17,18,24 is asserted without an in-text derivation or a machine-checked certificate; it is an exact subset-sum propagation whose output is only archived. If it failed for IDs 16,17, or 18, three order-12 subgroups would remain open and Theorem 1 would not follow. These are normal trust-on-rerun dependencies, not observed mathematical errors; the paper's SHA-256 manifests, independent generator, positive controls, and analytic proofs reduce but do not eliminate this residual.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies common-multiplier-invariant Legendre pairs of length 333, the length relevant to the open Hadamard order 668. It proves Theorem 1: if an H-invariant Legendre pair of length 333 exists, then H lies in the mod-3 kernel of (Z/333Z)^× and has order at most 6. After the mod-3 reduction there are exactly 30 subgroups of the kernel; the paper excludes 21 of them, including all 19 of order at least 9. The key analytic case is the order-9 subgroup H12 = ⟨10,46⟩, for which a 9-compression argument restricts entries to {±1,±17,±19,±35,±37}; the squared-norm equation forces exactly two entries of absolute value 17 in one compressed sequence, and a one-shift autocorrelation bound contradicts the required compressed correlation. The remaining exclusions use a mod-37 spectral obstruction, a row-sum congruence modulo 24, exact value-set enumeration, direct pseudo-Boolean coefficient bounds, and DRAT-certified SAT encodings. The unrestricted length-333 and order-668 existence problems remain open.","tokens_in":10093,"tokens_out":16793,"duration_ms":155739,"significance":"If the computational certificates and the two finite arithmetic claims are valid, this is a meaningful structural result for a well-known open construction: it eliminates every fixed common-multiplier group of order at least 9 and leaves exactly nine weak-symmetry subgroups. The analytic H12 argument is elegant and gives a new value-set compression principle. The computational part is unusually well documented for this area: equisatisfiable CNF encodings (Lemma 5), DRAT traces checked by an independent checker, SHA-256 manifests, positive controls, and a dependency-free verifier for the value-set enumeration are described and archived. These are genuine strengths. The theorem is narrow—it does not address multiplier-with-translation symmetry or the unrestricted problem—but the paper is honest about that limitation.","major_comments":[{"comment":"The row-sum obstruction is load-bearing for the main theorem, since IDs 16, 17, 18 are closed by Proposition 3 alone and ID 24 is also claimed there. However, the statement that 'exact subset-sum propagation modulo 24 gives the same reachable set' is not demonstrated in the text: no orbit-size multisets, no intermediate residues, and no certificate are shown for these four subgroups. This is not a typographical issue but a missing verification step for a claim on which Theorem 1 depends. Please include the orbit-size data and a short derivation (or reproduce the archived row-sum certificate in an appendix). For example, for ID 16 the orbit sizes are 9 singletons and 27 orbits of size 12, and the stated set follows from a quick parity argument; the analogous data for IDs 17, 18, 24 should be made explicit.","section":"§3.4, Proposition 3"},{"comment":"The 'direct pseudo-Boolean upper-bound' exclusions for IDs 11, 15, 19, 23, 28 (and, independently, ID 24) rest entirely on the assertion that at shift 111 the left side of Eq. (3) has maximum 222. This is a finite arithmetic claim about the orbit-intersection coefficients W_s(q,r), but the paper does not display these coefficients or provide the computation. Because these five exclusions have no other in-text proof vehicle, the relevant coefficient sums should be tabulated or the certificate format explicitly described. The claim is easy to verify once the orbit data are supplied, but as written the reader cannot check it from the text.","section":"§5.1, Eq. (3) and Table 3"}],"minor_comments":[{"comment":"Typo: 'Entrees of square 1225 or 1369' should be 'Entries of square 1225 or 1369'.","section":"§4.1"},{"comment":"The 'strongest certificate' column for ID 24 lists 'Row-sum obstruction modulo 24', while §5.1 and §6 also give a direct PB upper-bound certificate. Clarify which certificate is intended as the primary proof vehicle, or state that both are independent.","section":"Table A1, row 24"},{"comment":"The exact enumeration for Proposition 4 is described at a high level, and for ID 6 the CP-SAT check did not terminate. Since the exclusion rests on the bespoke enumerator, it would help to specify the multiset generation and PAF-profile matching more precisely, or to point to a machine-checkable artifact beyond the dependency-free verifier.","section":"§4.2"},{"comment":"In the proof of Lemma 5, the sentence about unit-split CNF could be clearer: splitting a unit clause with a fresh variable preserves equisatisfiability, but not logical equivalence. The current wording is acceptable, but the distinction is worth stating explicitly.","section":"§5.1"}],"recommendation":"major_revision","confidential_remarks":"This is a solid computational paper with a sound analytic core. My main concern is not the correctness of the arguments but the self-containedness of two finite, load-bearing arithmetic claims: Proposition 3's row-sum reachable set and the shift-111 coefficient maximum behind the direct PB bounds. Both are easily fixable by adding short computations or reproducing the archived certificates. Once those are made transparent, I would support acceptance. The DRAT/certificate infrastructure is a notable strength and should be preserved in the revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The main thing to know: this is a real result. It eliminates all fixed common-multiplier subgroups of order at least 9 for Legendre pairs of length 333, and the analytic proof for the last order-9 case is the genuinely new piece. The value-set 9-compression is what makes H12 work: restricting the compressed entries to the exact orbit-size-imposed set {±1, ±17, ±19, ±35, ±37} instead of treating them as arbitrary odd integers turns an infeasible-looking problem into a one-shift contradiction. The free-odd relaxation is feasible, which shows the restriction carries the load rather than being an artifact of the enumeration.\n\nI checked the analytic pieces. Proposition 1 and Proposition 2 are standard Fourier/compression arguments applied correctly. Theorem 2's counting is sound: the 4x+5y=8 equation forces exactly two ±17s, the row sums prevent splitting them between sequences, and the bound -249+9 < -74 closes the case. The paper is also careful about scope: nine low-order subgroups and the unrestricted existence question are explicitly left open.\n\nThe soft spots are where the stress-test note lands. The exclusions for 11 subgroups rest on CNF/DRAT/pseudo-Boolean certificates I did not execute. That is normal trust-on-rerun for proof-carrying computation, mitigated by SHA-256 manifests, positive controls, and an independent generator, but it is still external. The smaller issue is Proposition 3: the row-sum reachable set for IDs 16, 17, 18, 24 is asserted without an in-text derivation or a checked certificate. The set is small enough that a few lines of subset-sum reasoning would close it; as written it is an expositor gap, not an observed error. If it were wrong, three order-12 subgroups would remain open. I'd want that reachable set proven in the text or discharged by a machine-checked artifact before acceptance.\n\nOverall, the analytic core holds up, the computational evidence is as good as this field normally gets, and the value-set compression is transferable to other composite lengths. This deserves a serious referee. Send it to review, and ask the authors to either prove the Proposition 3 reachable set in the text or add a certificate for it.","headline":"Clean analytic core plus well-packaged computational exclusions; send to review, but require a proof or certificate for the row-sum reachable set.","tokens_in":10679,"tokens_out":2301,"would_cite":true,"duration_ms":21266,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["05B20","05B10","11B83"],"pacs":[],"model":"deepseek-v4-flash","headline":"Any Legendre pair of length 333 that is invariant under a fixed common multiplier subgroup H must have |H| ≤ 6, and H must lie in the kernel of reduction modulo 3.","keywords":["Legendre pairs","Hadamard matrices","multiplier subgroups","periodic autocorrelation","compression","proof certificates","supplementary difference sets","order 668"],"falsifier":"A concrete falsifier would be a single Legendre pair of length 333 whose two sequences are both fixed by a subgroup of order at least 9 — one object would disprove Theorem 1. In the absence of such a pair, the computational pillar could be tested by re-running the archived proof checker on every CNF instance and independently re-deriving the reachable row-sum set modulo 24 for the four subgroup cases; a failed certificate check or a missing residue ±1 in that set would undercut the proof.","tokens_in":9709,"feed_emoji":"🧮","tokens_out":6966,"duration_ms":58480,"temperature":0.7,"pith_summary":"The paper establishes that the most natural symmetry reduction for a Legendre pair of length 333 — requiring both ±1 sequences to be constant on the orbits of a common multiplicative subgroup H of (Z/333Z)^× — cannot succeed for any subgroup of order 9 or more. It shows that H must first lie in the kernel of reduction mod 3, and then, among the 30 subgroups inside that kernel, all 19 of order at least 9 are impossible, leaving only nine subgroups of order at most 6. This matters because a Legendre pair of length 333 would produce a Hadamard matrix of order 668, the smallest order for which the Hadamard existence question is still unresolved; the result removes strong multiplier symmetry as a route to that matrix. The proof combines modular compression, exact enumeration, and machine-checked certificates, with the last order-9 subgroup closed by a short analytic argument. The unrestricted existence of a length-333 Legendre pair remains open.","feed_headline":"All order-9 multiplier groups fail for Legendre pair length 333","feed_subtitle":"A Legendre pair of length 333 would give Hadamard order 668; fixed common-multiplier symmetry of order 9 or more is ruled out.","key_machinery":"The central mechanism is fixed-common-multiplier symmetry combined with compression. A subgroup H ≤ (Z/333Z)^× acts by coordinate multiplication; an H-invariant sequence is constant on the multiplication orbits, reducing 333 signs to r orbit signs. The mod-3 compression reduces the problem to the kernel U1 ≅ C3 × C36 and its 30 subgroups; the mod-37 compression converts a surjective image into a contradiction with 668 not being a sum of two squares. For subgroups trivial mod 9, the 9-compression with exact orbit-size column sums restricts entries to a small value set V_h; the order-9 case leaves only one square multiset, forcing a +17/−17 pair, and a one-shift PAF bound finishes it. For the","core_discovery":"On its own terms, the paper proves Theorem 1: if an H-invariant Legendre pair of length 333 exists, then H is a subgroup of the kernel of the reduction (Z/333Z)^× → (Z/3Z)^× and |H| ≤ 6. Equivalently, inside the order-108 kernel there are exactly 30 subgroups; 21 are proved impossible, including every subgroup of order at least 9. The decisive analytic step treats the final order-9 subgroup H12 = ⟨10,46⟩: because its mod-37 image has order 9, each column sum of the 9-compression lies in {±1, ±17, ±19, ±35, ±37}, the total squared norm 594 forces exactly two entries of magnitude 17, and then a single-shift autocorrelation bound contradicts the required compressed correlation −74. The paper al","pith_inferences":["Inference: The nine open subgroups of orders 1, 2, 3, and 6 are finite and small enough that exhaustive search over each symmetry class may settle the length-333 Legendre-pair problem directly, or produce an explicit pair; a reader could test the orbit equations for those nine groups.","Inference: The value-set compression idea likely transfers to other composite lengths where a multiplier image has few nonzero orbit sizes; the same type of column-sum restriction could yield analytic obstructions at lengths such as 3^a times other primes.","Inference: If a Legendre pair with a fixed multiplier of order 6 is eventually found, it would immediately supply a Hadamard matrix of order 668, making the low-order cases not just residual but the main open computational target."],"forward_implications":["If the theorem is right, any length-333 Legendre pair found with fixed common-multiplier symmetry will have multiplier group of order 1, 2, 3, or 6 inside the mod-3 kernel; no order-9+ class can host one.","Any successful fixed-multiplier route to a Hadamard matrix of order 668 must be sought among the nine undecided low-order subgroups, or outside fixed-multiplier symmetry entirely.","The analytic order-9 exclusion demonstrates that exact orbit-size value sets can turn a feasible compressed relaxation into a contradiction; the paper states this as a general compression principle.","The computational exclusions are backed by independently checkable unsatisfiability certificates, not by solver status alone, so the nonexistence claims can be machine-verified.","The unrestricted length-333 existence problem and the order-668 Hadamard existence question are untouched by this result."],"fun_headline_variants":["No multiplier groups of order >=9 for Legendre pair length 333","Legendre pair 333: multiplier groups above order 6 impossible","Hadamard order 668 gap: order-9 multiplier groups ruled out","Only multiplier groups of size <=6 survive in Legendre pair 333"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The theorem rests on the reliability of the computational certificates: the archived CNF instances must exactly encode H-invariant Legendre pairs (the paper proves this equivalence), and the checked unsatisfiability and arithmetic certificates must be sound; the certificate chain was not re-run in the review, and the row-sum reachable set for four subgroups is stated in the text without derivation.","fun_headline_variants_meta":{"raw":{"variants":["No multiplier groups of order >=9 for Legendre pair length 333","Legendre pair 333: multiplier groups above order 6 impossible","Hadamard order 668 gap: order-9 multiplier groups ruled out","Only multiplier groups of size <=6 survive in Legendre pair 333"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000841,"raw_usage":{"total_tokens":3541,"prompt_tokens":826,"completion_tokens":2715,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":570,"completion_tokens_details":{"reasoning_tokens":2645}},"tokens_in":570,"tokens_out":2715,"duration_ms":17640,"temperature":1.0,"reasoning_tokens":2645,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-01T09:27:23.466899+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete falsifier would be a single Legendre pair of length 333 whose two sequences are both fixed by a subgroup of order at least 9 — one object would disprove Theorem 1. In the absence of such a pair, the computational pillar could be tested by re-running the archived proof checker on every CNF instance and independently re-deriving the reachable row-sum set modulo 24 for the four subgroup cases; a failed certificate check or a missing residue ±1 in that set would undercut the proof.","supporting_citations":[],"review_version":1}