Summary: Extractors for LowWeight A#ne Sources
Anup Rao #
Institute for Advanced Study
November 19, 2007
We give polynomial time computable extractors for lowweight a#nce sources. A distribution
is a#ne if it samples a random points from some unknown low dimensional subspace of F n
2 . A
distribution is low weight a#ne if the corresponding linear space has a basis of lowweight vectors.
Lowweight a#ne sources are thus a generalization of the well studied models of bitfixing sources
(which are just weight 1 a#ne sources).
For universal constants c, #, our extractors can extract almost all the entropy from weight k #
a#ne sources of dimension k, as long as k > log c
n, with error 2
-k##3# . This gives new extractors
for low entropy bitfixing sources with exponentially small error, a parameter that is important for
the application of these extractors to cryptography.
Our techniques involve constructing new condensers for a#ne somewhere random sources.
Keywords: Extractors, A#ne Sources, Exposure Resilient Cryptography