Repository navigation
feat: add initial OOD sampling to BitZ commitments - #76
Conversation
zkfriendly
left a comment
There was a problem hiding this comment.
Thanks for the PR, I checked OOD algebra, batching, transcript order, and circuit integration, and all looked good. Left some comments.
| for (chunk, &scale) in basis.chunks_exact_mut(block).zip(&head) { | ||
| for (basis, &weight) in chunk.iter_mut().zip(&tail) { | ||
| *basis += as_flock_f128(coefficient * scale * weight); | ||
| } | ||
| } |
There was a problem hiding this comment.
We can parallelize this for larger inputs, it can be improve by ~7x, based on some experiments:
| Packed elements | Current | Eight threads |
|---|---|---|
| 2^22 | 2.964 ms | 0.442 ms |
| 2^24 | 11.911 ms | 1.656 ms |
|
|
||
| let started = std::time::Instant::now(); | ||
| let mut transcript = prover_transcript(); | ||
| let (_, data) = instance |
There was a problem hiding this comment.
The prove timer now includes commitment creation but before it was not included.
|
|
||
| fn prove(instance: &Instance) -> Proof { | ||
| let mut transcript = prover_transcript(); | ||
| let (_, data) = instance |
There was a problem hiding this comment.
The fixture already commits in benchmark/crates/tests/src/lib.rs line 83. This duplicate commitment can be removed; similar to how CircuitProofSystem already does, we can create one OOD commitment and retain the its transcript. This can free ~80mb during proving.
| /// | ||
| /// Call before witness-dependent challenges and continue with the same transcript. | ||
| /// Profiles without initial OOD sampling omit that round. | ||
| fn commit_with_ood( |
There was a problem hiding this comment.
Do we need both commit and commit_with_ood, and both verification methods, in the public API? Could the normal methods handle OOD automatically based on the selected security profile?
This would give callers one standard way to create and verify proofs. We would still keep receive_commitment separate, because circuits need the OOD claim before Spartan starts.
Is there a use case that requires both paths? If so, could we document it? Otherwise, I suggest keeping one main interface to make it easier for callers to use correctly.
There was a problem hiding this comment.
I agree with exposing the developer with the option to choose the security profile than OOD sampling, and we can consolidate the APIs. Thanks for flagging this!
|
The newly added |
I'll use a shared |
e997628 to
4f831e6
Compare
Add an initial out-of-domain (OOD) evaluation of the committed packed witness before the Spartan and BitZ challenges. Batch that claim into the existing Ligerito opening.
CommitSchemewith transcript-aware commitment and verification methods. Retain the same OOD claim for dense and succinct openings.CommittedWitnessfrom circuit commitment and consume it during proving, preserving the transcript that sampled the OOD point. Verification receives the claim before replaying circuit proof challenges.This changes the BitZ and circuit proof transcripts and the circuit commitment API. Raw
Pcs::commitremains available without OOD; callers using the OOD path must continue the commitment transcript through opening.Regression tests cover altered, missing, and truncated OOD values, invalid grinding nonces, and dense/succinct round trips. Focused PCS, BitZ, and circuit tests, Clippy, formatting, and Rustdoc checks passed locally; the all-shapes test reaching m28 was not completed. Byte-for-byte transcript equivalence with BitZ-PoC remains unverified.