
Lattices, Folding, & Symphony with Binyi Chen
Zero Knowledge
00:00
Explaining the SIS assumption
Binyi defines SIS (Shortest Integer Solution), its hardness, and why it's foundational to lattice cryptography's post-quantum promise.
Play episode from 32:19
Transcript
Transcript
Episode notes
In this episode Anna Rose and Nico Mohnblatt chat with Binyi Chen, researcher at Stanford University. They discuss his work on lattice-based folding schemes, revisit LatticeFold and LatticeFold+, and cover how lattices enable low-cost, post-quantum-secure folding by replacing Pedersen hashes with Ajtai commitments. They discuss the early folding work from 2023 and how it has evolved and explore the advantages of lattices over other approaches in the folding context while also highlighting their tradeoffs.
Binyi goes on to introduce Symphony, his new work that eliminates the need to implement Fiat-Shamir in the recursive verification circuit, and describes how that improves efficiency and removes the chances for a KRS-style attack.
Aztec is a privacy-first Layer 2 on Ethereum supporting smart contracts with both private and public state and execution. Details about Aztec’s technology, research, and community programmes are available at aztec.network.
Check out the latest jobs in ZK at the ZK Podcast Jobs Board.
**If you like what we do:** * Find all our links here! @ZeroKnowledge | Linktree * Subscribe to our podcast newsletter * Follow us on Twitter @zeroknowledgefm * Join us on Telegram * Catch us on YouTube **Support the show:** * Patreon * ETH - Donation address * BTC - Donation address * SOL - Donation address * ZEC - Donation address Read transcript
Related Links
- Binyi Chen’s Website
- LatticeFold: A Lattice-based Folding Scheme and its Applications to Succinct Proof Systems
- LatticeFold+: Faster, Simpler, Shorter Lattice-Based Folding for Succinct Proof Systems
- Symphony: Scalable SNARKs in the Random Oracle Model from Lattice-Based High-Arity Folding
- Protostar: Generic Efficient Accumulation/Folding for Special-sound Protocols
- ZK Whiteboard Sessions:SEASON 3 MODULE 3: Lattice-based SNARKs, w/ Vadim Lyubashevsky
- ZK Whiteboard Sessions:SEASON 3 MODULE 4: LatticeFold, w/ Binyi Chen
- Implementing LatticeFold with Matthew and Albert from Nethermind
- Lattice-based ZK Systems with Vadim Lyubashevsky
Further Reading
- Generating Hard Instances of Lattice Problems by M. Ajtai
- SWIFFT: A Modest Proposal for FFT Hashing
- Delegating Computation: Interactive Proofs for Muggles
- How to Prove False Statements: Practical Attacks on Fiat-Shamir
- BaseFold: Efficient Field-Agnostic Polynomial Commitment Schemes from Foldable Codes
- Blaze: Fast SNARKs from Interleaved RAA Codes
- Neo: Lattice-based folding scheme for CCS over small fields and pay-per-bit commitments
- LaBRADOR: Compact Proofs for R1CS from Module-SIS?
Aztec is a privacy-first Layer 2 on Ethereum supporting smart contracts with both private and public state and execution. Details about Aztec’s technology, research, and community programmes are available at aztec.network.
Check out the latest jobs in ZK at the ZK Podcast Jobs Board.
**If you like what we do:** * Find all our links here! @ZeroKnowledge | Linktree * Subscribe to our podcast newsletter * Follow us on Twitter @zeroknowledgefm * Join us on Telegram * Catch us on YouTube **Support the show:** * Patreon * ETH - Donation address * BTC - Donation address * SOL - Donation address * ZEC - Donation address Read transcript
The AI-powered Podcast Player
Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!


