Tight Time-Space Lower Bounds for Collision Finding and Element Distinctness under Label Symmetry
quant-ph, cs.CC, cs.CR, cs.DS
Submitted: 2026-09-09
Updated: 2026-10-02
License: http://creativecommons.org/licenses/by/4.0/
The gist: How much memory is needed to retain the quantum speedup for collision finding? For a uniformly random function f:[N] to [N], the BHT algorithm finds a collision using O(N 1/3) queries and a quantumly
Terminology
Abstract
How much memory is needed to retain the quantum speedup for collision finding? For a uniformly random function f:[N] to [N], the BHT algorithm finds a collision using O(N 1/3) queries and a quantumly accessible classical table containing O(N 1/3) input-output pairs, whereas a logarithmic-space Grover search uses O(sqrt N) queries. Determining the optimal query-space tradeoff between these extremes remains a major open problem. We resolve this equation within the class of label-symmetric algorithms, which treat the function f 's output labels as interchangeable. We prove that such algorithm that makes T queries, uses S qubits, and finds a collision in a uniformly random function f:[M] to [N] with constant probability satisfies T=Ω(N 1/3) and T 2S=Ω(N N). For the setting where M=N, these bounds are matched by a space-efficient implementation of the BHT algorithm. As a consequence of our tradeoff, any label-symmetric algorithm for the search version of Element Distinctness on f: [n] to [n 2] must satisfy T=Ω(n 2/3) and T 2S=Ω(n squared n), matching Ambainis's quantum walk. Thus, both tradeoffs are optimal within the class of label-symmetric algorithms. To prove these results, we develop a space-sensitive version of the compressed oracle technique. The compressed oracle records the information learned by the algorithm in an evolving superposition of databases. Using label symmetry and representation theory, we show that an algorithm using S qubits can effectively retain information about only O(S/ N) collision-free database entries. Substituting this estimate into the compressed oracle technique yields the stated tradeoffs.
Sources
- Open Problems Related to Quantum Query Complexity
- The Spectra of Arrangement Graphs
- Quantum walk algorithm for element distinctness
- A new quantum lower bound method, with an application to strong direct product theorem for quantum search
- Symmetry-assisted adversaries for quantum state generation
- Quantum lower bounds for the collision and the element distinctness problems
- Quantum cryptography: Public key distribution and coin tossing
- Element Distinctness, Frequency Moments, and Sliding Windows
- Quantum Algorithm for the Collision Problem
- Quantum Time-Space Tradeoffs for Matrix Problems
- Translation-Invariant Quantum Algorithms for Ordered Search are Optimal
- Cyclic decomposition of k-permutations and eigenvalues of the arrangement graphs
- Truly Low-Space Element Distinctness and Subset Sum via Pseudorandom Hash Functions
- Invariant Quantum Algorithms for Insertion into an Ordered List
- Quantum random access memory
- A fast quantum mechanical algorithm for database search
- Quantum Time-Space Tradeoff for Finding Multiple Collision Pairs
- Quantum complexities of ordered searching, sorting, and element distinctness
- The Compressed Oracle is a Worthy (Multiplicative) Adversary
- Quantum and Classical Strong Direct Product Theorems and Optimal Time-Space Tradeoffs
Related papers
- Reconquering Bell sampling on qudits: stabilizer learning and testing, quantum pseudorandomness bounds, and more
- Encrypted clones can leak: Classification of informative subsets in Quantum Encrypted Cloning
- Polynomial-time classical and quantum simulation of quantum impurity models
- Theory of quantum-enhanced interferometry with general Markovian light sources
- A convergent hierarchy of spectral gap certificates for qubit Hamiltonians
- Universal Bound and Phase Transition in Many-Body Fermionic Non-Gaussianity