Questions tagged [interactive-proof-systems]
62 questions
13
votes
2 answers
Interactive Proofs for coNP
I am trying to understand interactive proof systems and tried the following problem as an exercise. We know that $PH \subseteq PSPACE$ and $IP=PSPACE$, so come up with (easy to understand) interactive proof systems for $PH$?
An interactive proof…
Shitikanth
- 696
- 1
- 4
- 13
12
votes
1 answer
Are there any known AM-complete problems/is AM-complete well defined?
I'm curious about whether there are any complete problems in the Arthur-Merlin complexity class. Graph Non-Isomorphism (GNI) seems to be the canonical example of a problem in AM, but it's probably not a complete one.
I suppose I'm also wondering if…
Linear
- 223
- 1
- 6
10
votes
0 answers
"Essential" problem for MA
I am trying to understand different interactive proof systems, in particular AM and MA.
Is there a typical problem for the complexity class MA
as Graph-NonIsomorphism problem is for AM?
Is there a problem in MA that is not known to be in NP or…
Shitikanth
- 696
- 1
- 4
- 13
7
votes
1 answer
What is the difference between AM and IP
Intro
I am trying to understand how those two models of interactive proof are different. I understand that
$\text{AM}$ relies on public coins (the prover knows the random bits used by the verifier)
$\text{IP}$ relies on private coins (the prover…
Winks
- 215
- 2
- 9
6
votes
1 answer
How similar is the Goldwasser-Sipser Set Lower Bound Protocol to the Hashcash/Bitcoin Proof-of-Work?
Given a hash function $H:\{0,1\}^*\rightarrow\{0,1\}^n$, a difficulty $d\in\mathbb{N}$, and data $D\in\{0,1\}^*$, the framework of the Hashcash/Bitcoin Proof-of-Work entails finding a nonce $c$ such that $H(c\Vert D)$ starts with $d$ zero’s. That…
Mark S
- 263
- 1
- 7
5
votes
1 answer
Symmetry of IP complexity class
Wikipedia defines the IP complexity class as follows:
A language $L$ belongs to IP if there exists $V,P$ such that for all
$Q$, $w$,
$$w\in L\Rightarrow Pr[V\leftrightarrow P\text{ accepts }w]\geq2/3$$
$$w\notin L\Rightarrow…
stewbasic
- 268
- 1
- 5
5
votes
1 answer
Relation between interactive proof systems (IP), NP, coNP, PSPACE
I would like to ask you some clarification on the following question:
know that ${\sf NP}$ is a subset of ${\sf IP}$
and also ${\sf coNP}$ it is a subset of ${\sf IP}$.
So ${\sf IP}$ is a biggest class, but how much it is big?
May i say that ${\sf…
LMG
- 265
- 3
- 8
5
votes
1 answer
Why is the complement of SAT in IP?
It is mentioned in Sipser's text that the complement of SAT is in $IP$, before $IP$ is formally introduced. After looking at the definition and some of the results, I still don't see why this is the case.
Is this supposed to be seen directly? Or is…
theQman
- 597
- 3
- 8
5
votes
0 answers
Interactive proofs for coNP languages proof clarification
I was reading a paper by Lance Fortnow and Michael Sipser. "Are there interactive protocols for co-NP languages?" Information Processing Letters 28 v5 (1988), pp. 249-251. An online version of the paper can be found at…
Markandeya
- 71
- 3
5
votes
2 answers
Basic question about parallel repetition in IP protocol
The book Arora and Barak defines class IP (interactive protocol) by making the verifier have private coins. Before proceeding to public coin proofs and showing they are the "same," the book mentions the following:
The probabilities of correctly…
advocateofnone
- 3,179
- 1
- 27
- 44
5
votes
1 answer
Easy proof of IP ⊆ PSPACE for private coins
There is an extremely standard proof that IP⊆PSPACE, used for instance here, here, or here, by the argument that the full protocol is max-avg game tree that can be evaluated in polynomial space. It's really clean and, dare I say, obvious as a first…
Alex Meiburg
- 955
- 4
- 18
5
votes
0 answers
Interactive proof for PSPACE-hard problems different from QBF
The celebrated proof that IP = PSPACE relies on an interactive proof for the QBF problem.
Is there any other "natural" interactive proof for a PSPACE-hard problem other than QBF?
(of course, since QBF is PSPACE-complete, such a proof exists via a…
Charles Bouillaguet
- 283
- 1
- 8
5
votes
2 answers
Is there a Zero-Knowledge proof for SAT?
I know that SAT can be reduced to (3 vertex) Graph colouring, and there is a Zero-knowlegde protocol (ZKP) for graph colouring. However, I am interested in a ZKP that can be performed directly on a SAT instance, without graph colouring.
Is there a…
StackMachine
- 93
- 7
4
votes
4 answers
Are there deterministic and/or non-interactive zero-knowledge proofs?
The Wikipedia page on zero-knowledge proof says
Zero-knowledge proofs are not proofs in the mathematical sense of the term because there is some small probability, the soundness error, that a cheating prover will be able to convince the verifier of…
tparker
- 1,174
- 7
- 16
4
votes
1 answer
Sketch an IP proof for minSAT
I have to sketch an IP proof for the minSAT problem. The minSAT problem is define in this way:
For a given formulae find a satisfying assignment with a min subset of variables assigned to True;
My sketched IP protocol is:
Prover and Verifier…
Francesco Asnicar
- 43
- 2