{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:UA3IMYCVT2Z5L3DQUONG4A5MHX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"47488b272a599ec7c13ee72bc7026a1cfa6eb61f5faabb9f3520426249913340","cross_cats_sorted":["cs.CR","math.NT","math.ST","quant-ph","stat.TH"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.DS","submitted_at":"2026-05-17T12:00:59Z","title_canon_sha256":"9e03b3f598e3a2b1c01046111eabe8ec452b074f6732dbdead26bdaed7b3bdd3"},"schema_version":"1.0","source":{"id":"2605.17404","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.17404","created_at":"2026-05-20T00:03:56Z"},{"alias_kind":"arxiv_version","alias_value":"2605.17404v1","created_at":"2026-05-20T00:03:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.17404","created_at":"2026-05-20T00:03:56Z"},{"alias_kind":"pith_short_12","alias_value":"UA3IMYCVT2Z5","created_at":"2026-05-20T00:03:56Z"},{"alias_kind":"pith_short_16","alias_value":"UA3IMYCVT2Z5L3DQ","created_at":"2026-05-20T00:03:56Z"},{"alias_kind":"pith_short_8","alias_value":"UA3IMYCV","created_at":"2026-05-20T00:03:56Z"}],"graph_snapshots":[{"event_id":"sha256:0c6acb965463816b86d61848b65bc0b37646ac34a88a38dcee3fb0eb6d916634","target":"graph","created_at":"2026-05-20T00:03:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"We prove that the L² CVP distance from a random short ring element to the log-unit lattice of Q(ζ_{2^k}) converges to π/(2√6) √n as n=2^{k-1}→∞. ... combined with Parts I and II, we reduce the CDPR factor for ML-KEM from exp(O(√n)) to a sub-polynomial value."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The model of a 'random short ring element' in the ring of integers of Q(ζ_{2^k}) is sufficiently representative that its embedding statistics match the sub-Gaussian coordinates used to derive the limit and the Voronoi cell membership (abstract, first sentence and L^∞ paragraph)."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"The L² CVP distance to the log-unit lattice converges to (π/(2√6))√n, enabling sub-polynomial approximation factors for the Short Generator Problem and reducing the CDPR factor for ML-KEM from exp(O(√n)) to sub-polynomial."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"The L² CVP distance from a random short ring element to the log-unit lattice converges to π/(2√6) √n as the dimension n tends to infinity."}],"snapshot_sha256":"47f9a0d15268ebbea77c9c72bfd65dfdc42708f5afb2b41a395a6e67866b9a01"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"b106c21ddf20bcb2aff7196ae4e3bf9af24e739c852527f71151a46ade2279fc"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T23:01:28.601020Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T23:01:19.643457Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T21:41:57.751424Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T21:33:23.694620Z","status":"skipped","version":"1.0.0"}],"endpoint":"/pith/2605.17404/integrity.json","findings":[],"snapshot_sha256":"38da1985aef45a716384c2ae966bf6b8edabdc3d7676213a69f4fe19ddc07410","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"We prove that the $L^2$ CVP distance from a random short ring element to the log-unit lattice of $\\Q(\\zeta_{2^k})$ converges to $\\frac{\\pi}{2\\sqrt{6}}\\sqrt{n}$ as $n=2^{k-1}\\to\\infty$. We then show that this target lies inside the Voronoi cell of the origin for $k\\ge 4$. For the $L^\\infty$ norm, the maximum over $n$ sub-Gaussian coordinates yields $O(\\sqrt{\\log n})$ which translates into a sub-polynomial approximation factor for the Short Generator Problem. We show a Coarse Lattice Theorem that Babai's algorithm returns zero for all structured targets, yet exactly recovers unit perturbations o","authors_text":"Ming-Xing Luo","cross_cats":["cs.CR","math.NT","math.ST","quant-ph","stat.TH"],"headline":"The L² CVP distance from a random short ring element to the log-unit lattice converges to π/(2√6) √n as the dimension n tends to infinity.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.DS","submitted_at":"2026-05-17T12:00:59Z","title":"Module Lattice Security (Part III): Structured CVP Distance on the Log-Unit Lattice"},"references":{"count":41,"internal_anchors":0,"resolved_work":41,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Recovering short generators of principal ideals in cyclotomic rings","work_id":"f8a67ee8-940e-4fc8-b850-3754f36035bc","year":2016},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Short stickelberger class relations and application to Ideal-SVP","work_id":"8a24f4f0-6150-40bc-b7fe-b3864cfa28e5","year":2017},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Mildly short vectors in cyclotomic ideal lattices in quantum polynomial time.Journal of the ACM, 68: 1-26, 2021","work_id":"7d47c40f-a511-48fe-9995-e4be8aad939c","year":2021},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Efficient quantum algorithms for computing class groups and solving the principal ideal problem in arbitrary degree number fields","work_id":"a5d1f997-8559-494f-b2af-d694caf9f1c0","year":2016},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Approx-SVP in ideal lattices with pre-processing","work_id":"372a343f-bdbc-4da6-bca5-a70a3d895616","year":2019}],"snapshot_sha256":"91938825853761620a6b814092cac122560ad183a760b7d346dd876767ef5b14"},"source":{"id":"2605.17404","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-19T22:55:40.783553Z","id":"7d58a4e3-2cfa-43c3-9ea2-e01292498349","model_set":{"reader":"grok-4.3"},"one_line_summary":"The L² CVP distance to the log-unit lattice converges to (π/(2√6))√n, enabling sub-polynomial approximation factors for the Short Generator Problem and reducing the CDPR factor for ML-KEM from exp(O(√n)) to sub-polynomial.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"The L² CVP distance from a random short ring element to the log-unit lattice converges to π/(2√6) √n as the dimension n tends to infinity.","strongest_claim":"We prove that the L² CVP distance from a random short ring element to the log-unit lattice of Q(ζ_{2^k}) converges to π/(2√6) √n as n=2^{k-1}→∞. ... combined with Parts I and II, we reduce the CDPR factor for ML-KEM from exp(O(√n)) to a sub-polynomial value.","weakest_assumption":"The model of a 'random short ring element' in the ring of integers of Q(ζ_{2^k}) is sufficiently representative that its embedding statistics match the sub-Gaussian coordinates used to derive the limit and the Voronoi cell membership (abstract, first sentence and L^∞ paragraph)."}},"verdict_id":"7d58a4e3-2cfa-43c3-9ea2-e01292498349"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fbeeb5ec9fd7ee4f749eb8f35ee7b6fa44d12859a0eed5191cacabdabd3f5d82","target":"record","created_at":"2026-05-20T00:03:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"47488b272a599ec7c13ee72bc7026a1cfa6eb61f5faabb9f3520426249913340","cross_cats_sorted":["cs.CR","math.NT","math.ST","quant-ph","stat.TH"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.DS","submitted_at":"2026-05-17T12:00:59Z","title_canon_sha256":"9e03b3f598e3a2b1c01046111eabe8ec452b074f6732dbdead26bdaed7b3bdd3"},"schema_version":"1.0","source":{"id":"2605.17404","kind":"arxiv","version":1}},"canonical_sha256":"a0368660559eb3d5ec70a39a6e03ac3de095de1e3f714c838464f0040db94157","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a0368660559eb3d5ec70a39a6e03ac3de095de1e3f714c838464f0040db94157","first_computed_at":"2026-05-20T00:03:56.737198Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:03:56.737198Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"MY+NlFa96BCjoP3E5HLbbCo3U3WLZUDTwD7lsUj7LmC/fVc2VFzLuDQ1r1OQ5ayk4lR4mDywpUkHzh5k8dwuAw==","signature_status":"signed_v1","signed_at":"2026-05-20T00:03:56.738183Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.17404","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fbeeb5ec9fd7ee4f749eb8f35ee7b6fa44d12859a0eed5191cacabdabd3f5d82","sha256:0c6acb965463816b86d61848b65bc0b37646ac34a88a38dcee3fb0eb6d916634"],"state_sha256":"cc32fec7fc336905494fc425016593b2aa2c797c3c4a628c7ae691aee2a56592"}