Research · Papers · The quadratic hull and its defects · MF-132

The Boolean ramification polytope common evaluation conjecture

MC(F) ≥ r+D-2-c(Q) survives, but unqualified polytope equality is undefined at V=0 and remains a CONJECTURE (GAP)

MF-132CONJECTUREOPEN QUESTIONThe quadratic hull and its defects

Published 2026-09-04

For everyone

Plain summary

Multiplicative complexity measures the minimum number of nonlinear AND gates needed to run a Boolean circuit when linear XOR gates are free. The Boolean ramification polytope was introduced as a geometric framework to calculate this cost across circuit families. The general equality formula fails at its boundary by omitting zero-variable cases. Because of this gap, the one-bit identity function lacks a valid geometric representation, leaving the zero-cost baseline undefined as written. Specific lower bounds and restricted evaluations on odd-length inverse permutations and adder circuits remain sound, but the universal formula remains an open conjecture requiring boundary repair.

Result

Let MC(F) denote the multiplicative complexity of a Boolean map F under the GF(2) XOR-free XAG cost model. The costed-postcomposition lower bound MC(F) ≥ r+D-2-c(Q) holds. Restricted evaluations survive for the inverse permutation χ on odd dimensions n ≥ 3 and for FullAdd cascades with Kn ≥ 2.

The unqualified program-level equality for the Boolean ramification polytope is undefined at V=0, because the one-bit identity map has no admissible triple to support the endpoint Θ=MC=0. The general common evaluation equality is therefore categorized as CONJECTURE (GAP).

Setting and definitions

  • Cost model: GF(2) XAG (XOR-free), where linear XOR operations cost zero and nonlinear multiplications cost one.
  • Target families: χ on odd dimension n ≥ 3, and FullAdd on Kn ≥ 2.
  • Polytope parameters: V denotes variable count, Θ denotes the common polytope evaluation value, and r, D, c(Q) represent ramification rank, degree, and postcomposition correction terms in the bound MC(F) ≥ r+D-2-c(Q).

Method

The bound and its boundary limitation were established through algebraic structural verification recorded in zkgolf-decomp/SURFACE-LANGLANDS.md and zkgolf-decomp/SURFACE-VERIFY.md. The verification state is supported by the independent receipt zkgolf-decomp/surface-verify-scratch/independent-surface.receipt.json (SHA-256 44fee010c465c25c5f7c41c4fb3978a825d87e65db09479eb9c8a76d588b8391). Boundary analysis of admissible triples confirmed the lack of coverage at V=0.

Discussion

The unqualified polytope equality cannot be banked as a theorem. Because admissible triples exclude V=0, the one-bit identity function is omitted, leaving the endpoint Θ=MC=0 undefined. Restoring formal validity requires restricting the domain to V > 0 or adding a dedicated zero-envelope repair.

The mathematical content verified by the register is limited to:

  1. The postcomposition lower bound inequality MC(F) ≥ r+D-2-c(Q).
  2. Scoped evaluations for χ on odd n ≥ 3 and FullAdd on Kn ≥ 2.

The register states no prior-art position.

For everyone — the takeaway

What this means

Multiplicative complexity measures the exact cost of running cryptographic algorithms and arithmetic circuits in zero-knowledge and privacy-preserving systems. The ramification polytope was intended as a geometric tool to compute these costs directly. While it gives verified lower bounds for adders and permutations, its universal formula breaks down on the simplest possible inputs. Until the definition accounts for zero-variable boundary cases, the general formula remains an unproven conjecture.

Register references

  • Entry ID: MF-132
  • Receipt: zkgolf-decomp/SURFACE-LANGLANDS.md
  • Receipt: zkgolf-decomp/SURFACE-VERIFY.md
  • Receipt: zkgolf-decomp/surface-verify-scratch/independent-surface.receipt.json (SHA-256 44fee010c465c25c5f7c41c4fb3978a825d87e65db09479eb9c8a76d588b8391)
  • Prior-art works: the register does not record this.

Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.

Evidence pack

Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 0 of 3 receipt files bundled (1 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.

Download evidence.zip

Changelog

Last reviewed 2026-09-04

  • 2026-09-04Published on this site.

Related in this programme