{"id":"e4844e1d-65f0-4d6f-a580-884301841ddd","arxiv_id":"2608.10880","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"For elliptic curves with surjective mod p Galois representations, the paper completely classifies the possible joint images and gives the density of primes witnessing noncongruence.","lead":"For two elliptic curves over the rational numbers with surjective mod p Galois representations, this paper lists all possible joint images of the two p-torsion representations and computes the density of primes that witness the curves are not congruent modulo p. That density gives a fast numerical way to identify which joint image a concrete pair of curves has, complementing the slower Sturm-bound search for congruences.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"p=3 classification and W(H_Q) rest on unverified computer enumeration; independent re-derivation needed for Theorem 4.1 completeness.","rationale":"The reader's weakest_assumption was surjectivity of both residual representations. That is an explicit hypothesis, not a gap in the proof. My reading of the p>=5 argument found no substantive flaw: Theorem 3.1 follows from Goursat's lemma, the normal-subgroup classification, and the determinant-preserving automorphism computation; the witness-ratio formulas in Theorem 3.16 match the table entries and small-p arithmetic. The genuinely exposed point is the p=3 classification and the value of W(H_Q). The paper states that these were determined by computer algebra, but it does not give a hand-verifiable derivation or a sufficiently pinned-down reproducible script (no commit hash, no transcript). This is a concrete, checkable gap that directly supports the reader's conditional verdict. I therefore recommend keeping the verdict as CONDITIONAL rather than elevating it to full acceptance, and the conditional should require the independent enumeration described above. My agreement with the reader is partial because I locate the load-bearing concern in the p=3 computational completeness rather than in the explicit surjectivity assumption.","tokens_in":21275,"tokens_out":41955,"duration_ms":367446,"concrete_test":"Independently enumerate in GAP or Magma all subgroups H of GL2(F3)×GL2(F3) that surject onto each factor and satisfy det(g1)=det(g2) for all (g1,g2)∈H. Up to conjugacy, verify the only non-diagonal possibilities are Γχ, H±, H_Q, Δ, with orders 48, 96, 384, 1152 respectively. For each such group, count the trace-different elements and recompute W(H_Q); check that W(H_Q)=35/64 and that the other ratios match Theorem 4.1. Also verify that the pair (11a2,352d1) satisfies the discriminant criterion of Theorem 4.2 and has product-image H_Q.","verdict_should_be":"UNCHANGED","load_bearing_attack":"For p>=5 the group-theoretic proof appears complete and internally sound: Goursat's lemma, the normal-subgroup dichotomy, the automorphism classification, and the witness-ratio computations all check out. The load-bearing weak spot is Theorem 4.1 for p=3. The text says 'As confirmed by our explicit computations, the extra subgroup Q8 gives rise to precisely one more admissible group' and the proof of Theorem 4.1 says the possible groups were determined by a computer algebra system. No hand proof is given that the normal subgroups of GL2(F3) relevant to Goursat's lemma are exactly {I}, {±I}, Q8, SL2(F3), G, nor that the admissible product images are only Γχ, H±, H_Q, Δ. It also does not exhibit the computation of W(H_Q)=35/64, only asserting it is 'straightforward'. The cited [Ade01, Figure 5.1] lists normal subgroups, but the deduction to the full admissible list and the witness ratio is not documented in the text. This matters because Theorem A for p=3 is part of the central claim: if the enumeration missed a subgroup, or if W(H_Q) were miscounted, the density conclusion for p=3 would fail. The surjectivity assumption is a limitation, but it is explicitly stated; the p=3 completeness is a verification gap inside the proof itself.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies the product of two residual mod p Galois representations attached to elliptic curves over Q, under the standing assumption that both representations are surjective. Using Goursat's lemma together with a classification of normal subgroups of GL2(Fp), it determines, for p >= 5, that the image of the product representation is conjugate to one of Gamma_id, Gamma_chi, H_plusminus, or Delta, and computes exact witness ratios W(H), which are interpreted via Chebotarev as densities of primes where the Frobenius traces of the two curves are incongruent modulo p. For p = 3 the paper adds one further group H_Q and computes its witness ratio. It also gives a characterization of the pairs of elliptic curves realizing each group in terms of quadratic twists, and discusses numerical examples and connections with the Sturm bound.","tokens_in":21476,"tokens_out":11522,"duration_ms":113045,"significance":"If the results are correct, the paper provides a complete and explicit description of all possible images of product representations of two surjective elliptic-curve mod p representations, together with exact densities for congruence-breaking primes. A notable strength is that the witness ratios are exact counts in explicitly defined finite groups: there are no fitted parameters and the p >= 5 formulas are closed and checkable. The paper also ships computational scripts and gives concrete examples that agree with the formulas in Table 1. The p >= 5 classification and witness-ratio computations appear internally sound and are a genuine contribution. The p = 3 part, however, is the main weak spot: its completeness and one of its witness ratios currently rest on undocumented computer enumeration.","major_comments":[{"comment":"The proof of Theorem 4.1 does not give a complete enumeration of the admissible subgroups for p = 3. It says that 'we originally used a computer algebra system to determine the possible groups' and, before Theorem 4.2, that 'as confirmed by our explicit computations, the extra subgroup Q8 gives rise to precisely one more admissible group,' but no hand proof or deterministic reproducible listing is provided for the full list {Gamma_chi, H_plusminus, H_Q, Delta}. Since Theorem A and its density conclusion for p = 3 depend on the completeness of this list, the omission is load-bearing. Please provide either a complete hand verification (using, for example, the normal-subgroup data in [Ade01, Figure 5.1] together with the Goursat correspondence) or a self-contained, deterministic enumeration script whose output is the admissible-group list.","section":"§4, Theorem 4.1"},{"comment":"The value W(H_Q) = 35/64 is asserted as 'straightforward' without displaying the computation. This ratio is one of the four witness ratios in Theorem A, so the paper should either exhibit the conjugacy-class sizes of H_Q or include a short reproducible script that returns 35/64. Without this, a reader cannot independently verify a central numerical claim of the p = 3 case.","section":"§4, Theorem 4.1 and W(H_Q)"},{"comment":"The proof contains the assertion that 'G has a unique index 2 subgroup, namely S.' This is false for p >= 5: |GL2(Fp) : SL2(Fp)| = p - 1, not 2. The unique index-2 subgroup is ker(chi composed with det), and the Goursat argument should be phrased in terms of that subgroup or of the unique nontrivial character of G. As written, the step 'if N1 = S then chi_d = chi_{p*}' is invalid. The statement of Theorem 3.21 is plausible and likely fixable, but the proof needs correction.","section":"§3.4, proof of Theorem 3.21"}],"minor_comments":[{"comment":"The statement 'Suppose N1 and N2 contain Z' should read 'are contained in Z' (that is, N_i ⊆ Z). Under the literal wording the lemma is false or vacuous for p >= 5, whereas the intended statement, with the proof given, is correct and is exactly what is used in Theorem 3.1.","section":"Lemma 3.6"},{"comment":"The condition 'Delta_E1 Delta_E2^{±1} in (Q^times)^3' should be spelled out as 'either Delta_E1 Delta_E2 or Delta_E1 Delta_E2^{-1} is a rational cube' to avoid ambiguity.","section":"Theorem 4.2"},{"comment":"The notation in the proof is occasionally dense, especially the count of Delta-conjugacy classes and the use of the symbols N_t and n_t; a short illustrative example for one value of p in the appendix would improve readability.","section":"Theorem 3.12 and Proposition 3.14"}],"recommendation":"major_revision","confidential_remarks":"The p >= 5 portion of the paper is mathematically sound and publishable in my view. The p = 3 completeness verification and the faulty statement in the proof of Theorem 3.21 should be addressed before publication; both are local and fixable, so I am not recommending rejection. The reliance on the authors' own GitHub code for the p = 3 enumeration is acceptable in principle, but the manuscript itself should contain enough detail for the claimed completeness and witness ratio to be verified without downloading external scripts."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Read this one. The paper classifies, for elliptic curves over Q with surjective mod p representations, all possible images of the product representation, and computes exact witness ratios. The p≥5 half is the core result and it is correct: Goursat's lemma plus the normal-subgroup structure of GL2(F_p) really does force the image to be one of Γ_id, Γ_χ, H_±, or Δ. The proof is clean, including the automorphism classification (Lemma 3.7) and the subtle conjugacy-class splitting inside Δ (Theorem 3.12). I checked the witness-ratio formulas against the explicit examples in Table 1 for p=5,7,11,13 and they agree. The realization theorem (3.21) — tying Γ_χ to p* twists and H_± to other quadratic twists — is useful and clearly argued.\n\nWhat is genuinely new is modest but real: the closed-form witness ratios, the extra p=3 group H_Q, and the discriminant criterion in Theorem 4.2. The witness idea itself is not new; [BPP+19] already uses witness primes. The added value here is turning that idea into exact densities for each possible image group.\n\nSoft spots, in proportion. Lemma 3.6 says 'contain Z' but means 'contained in Z' — a wording slip, not a math error. The real gap is the p=3 case. Theorem 4.1 relies on a computer algebra system to enumerate the admissible groups; the normal-subgroup list for GL2(F_3) is cited from [Ade01] but not proved, and W(H_Q)=35/64 is asserted rather than demonstrated. This is a verification gap, not a fatal one: the generators are explicit, the code is on GitHub, and the result is very likely right. The authors should pin it down — a commit hash plus a short script, or a hand-checkable normal-subgroup list — but a referee shouldn't block on it. The surjectivity assumption is a real limitation, but it is stated clearly in Section 2 and is the natural starting point.\n\nBottom line: a solid, honest subfield paper. I would send it to a serious referee. The referee should ask for the p=3 computational details to be made reproducible, and a clean-up of Lemma 3.6. Nothing here is a deal-breaker.","headline":"The p≥5 classification and witness-ratio formulas are rigorous and correct; the p=3 case is computer-assisted with a minor verification gap that should be patched, but the paper deserves a serious referee.","tokens_in":22055,"tokens_out":4817,"would_cite":true,"duration_ms":43120,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["14H52","11F80"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper proves that, for elliptic curves over Q with surjective mod p Galois representations, the image of their product representation is always conjugate to one of an explicit short list of finite groups, and it computes the exact…","keywords":["elliptic curves","Galois representations","mod p representations","Goursat's lemma","witness ratio","division fields","Chebotarev density theorem","quadratic twists"],"falsifier":"Take any pair of elliptic curves over Q with surjective mod p representations at a small prime p≥5, compute the image of the product representation directly from the division fields or from the Goursat data, and check that it is conjugate to Γ_id, Γ_χ, H_±, or Δ; the first pair that is not would falsify Theorem 3.18.","tokens_in":21038,"feed_emoji":"🔢","tokens_out":11176,"duration_ms":97777,"temperature":0.7,"pith_summary":"This paper asks how and how quickly one can tell two elliptic curves over the rationals apart modulo a prime p. The authors prove that if both mod p Galois representations are surjective, then the image of their product representation is one of an explicit finite list: the diagonal subgroup when the representations are isomorphic, and otherwise three non-diagonal groups for p≥5, plus one extra group when p=3. They define a witness ratio for each image group, the fraction of pairs (g,h) in the group with different traces, and show via the Chebotarev density theorem that this ratio equals the asymptotic density of good primes ℓ where a_ℓ(E1) and a_ℓ(E2) differ modulo p. This yields a practical numerical way to distinguish non-isomorphic representations and identifies the precise amount of computation needed to witness non-congruence.","feed_headline":"Four groups pin down mod p differences of elliptic curves","feed_subtitle":"The fraction of primes where the curves differ equals one of four explicit witness ratios.","key_machinery":"The central machinery is Goursat's lemma for subgroups of a product of two groups, applied to H = Im(rho_E1,p × rho_E2,p). Because both projections onto GL2(Fp) are surjective, H is determined by a pair of normal subgroups N1, N2 of GL2(Fp) together with an isomorphism GL2(Fp)/N1 ≅ GL2(Fp)/N2; for p≥5 the normal subgroups of GL2(Fp) are either contained in the scalars or contain SL2(Fp), which leaves exactly four admissible groups up to conjugation. The witness ratio W(H) = #{ (g,h) ∈ H : tr(g) ≠ tr(h) } / |H| is the invariant that converts this group structure into the density of witness primes through the Chebotarev density theorem.","core_discovery":"The paper establishes that, under the assumption that both residual representations are surjective, the image H of rho_E1,p × rho_E2,p is always conjugate to one of a short explicit list of subgroups of GL2(Fp) × GL2(Fp): the diagonal subgroup Γ_id, the quadratic-twisted diagonal Γ_χ, the sign-twisted diagonal H_±, and the full determinant-equal subgroup Δ, with a fifth group H_Q appearing only at p=3. For each admissible group it computes W(H), the fraction of elements in H whose two traces differ, and proves that W(H) is exactly the density of good primes ℓ for which a_ℓ(E1) is not congruent to a_ℓ(E2) modulo p. It further characterizes which pairs of elliptic curves realize each group: Γ_id corresponds to isomorphic representations, Γ_χ to representations differing by the quadratic character of conductor p*, H_± to quadratic twists by other squarefree integers, and Δ to every other case, while H_Q at p=3 occurs when the two curves have equal Q8-fixed subfields of their 3-division fields, equivalently when their discriminants generate the same class in Q*/(Q*)³.","pith_inferences":["The paper leaves open the non-surjective case; the same Goursat-based enumeration would produce a longer but still finite list of admissible images indexed by the possible subgroups of GL2(Fp) that can occur as mod p images, and the witness-ratio formulas would have to be recomputed for those smaller groups.","The witness-ratio approach suggests a probabilistic substitute for the Sturm bound: instead of checking all primes up to an O(N) bound, one can sample primes and stop once the empirical witness proportion is close to one of the admissible ratios; the explicit Chebotarev error terms cited in the paper give a principled stopping rule under the generalized Riemann hypothesis.","Because the witness ratios for Γ_χ and H_± differ by O(p^{-2}), numerical ratio comparison alone becomes impractical for large p; a cheaper distinguishing test, suggested by the paper's Remark 3.19, is to check whether a_ℓ(E2) always equals the Legendre symbol (ℓ/p) times a_ℓ(E1), which in the Γ_χ case holds for all good primes.","The p=3 discriminant criterion for H_Q provides a direct search strategy: look for surjective mod 3 curve pairs that are not quadratic twists but whose discriminants generate the same class in Q*/(Q*)³; the paper's Table 1 already contains one such pair."],"forward_implications":["For p≥5, two elliptic curves with surjective mod p representations that are not isomorphic have product image conjugate to exactly one of Γ_χ, H_±, or Δ, so the density of primes where a_ℓ(E1) differs from a_ℓ(E2) modulo p is one of the three closed-form witness ratios in Theorem 3.18.","For p=3 the worst-case witness density is 1/4, so the number of witness primes below X is asymptotically (1/4 + o(1)) Li(X) regardless of which non-diagonal image group occurs.","Which image group occurs is determined by representation-theoretic data: isomorphic representations give Γ_id, a twist by the Legendre-symbol character gives Γ_χ, any other quadratic twist gives H_±, and all other pairs give Δ; at p=3, H_Q occurs exactly when the two 3-division fields have equal Q8-fixed fields, equivalently when the normalized discriminants differ by a rational cube.","The witness ratios of all admissible groups are pairwise distinct, so a sufficiently large sample of good primes can identify, numerically, which of the finitely many image groups a concrete pair of elliptic curves realizes."],"supporting_citations":[{"why":"Source for the surjectivity assumption on mod p Galois representations and for the classification of possible subgroups of GL2(Fp) that underlies the admissible-group list.","marker":"[Ser72]"},{"why":"Provides the Sturm bound that the paper compares against and that motivates a density-based approach to finding witness primes.","marker":"[Ste07]"},{"why":"Supplies the division-field facts used to characterize Γ_χ, H_±, and the p=3 group H_Q in terms of quadratic twists and discriminants.","marker":"[Ade01]"},{"why":"The companion computational scripts that enumerate admissible groups, compute witness ratios for small primes, and produce the explicit examples in Table 1.","marker":"[BHK+]"},{"why":"The effective Chebotarev density theorem used to state the asymptotic count of witness primes in Corollary 1.2.","marker":"[DKN25]"},{"why":"Gives the GRH-conditional explicit error bounds used in Remark 1.3 to quantify how quickly witnesses are found.","marker":"[GM19]"}],"fun_headline_variants":["Four witness ratios pin down mod p differences of curves","Explicit images of product Galois reps for elliptic curves","Witness ratio equals density of primes with distinct traces","Elliptic curves: product representations have explicit images","Short list of groups determines mod p congruence of curves"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The entire classification and the witness-ratio formulas rely on both mod p representations being surjective onto GL2(Fp); if either representation has a smaller image, such as a Borel or Cartan subgroup, the four-group list and the density formulas can fail.","fun_headline_variants_meta":{"raw":{"variants":["Four witness ratios pin down mod p differences of curves","Explicit images of product Galois reps for elliptic curves","Witness ratio equals density of primes with distinct traces","Elliptic curves: product representations have explicit images","Short list of groups determines mod p congruence of curves"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000206,"raw_usage":{"total_tokens":1352,"prompt_tokens":853,"completion_tokens":499,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":469,"completion_tokens_details":{"reasoning_tokens":423}},"tokens_in":469,"tokens_out":499,"duration_ms":5530,"temperature":1.0,"reasoning_tokens":423,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T15:10:03.684583+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take any pair of elliptic curves over Q with surjective mod p representations at a small prime p≥5, compute the image of the product representation directly from the division fields or from the Goursat data, and check that it is conjugate to Γ_id, Γ_χ, H_±, or Δ; the first pair that is not would falsify Theorem 3.18.","supporting_citations":[],"review_version":1}