Research · Papers · The SHA-256 record and exact synthesis · ML-010

Affine rank of product-output functions and fixed-XOR optimization in the leader

OPT_fixed-XOR = 274

ML-010EXHAUSTEDEXHAUSTIVE CHECKNEGATIVE RESULTThe SHA-256 record and exact synthesis

Published 2026-08-29

For everyone

Plain summary

This paper tests two specific shortcuts for reducing the multiplication count in the leader circuit, which has 768 public inputs and 22,215 product rows. A free row is a multiplication step you can cut because its output is already produced by linear combinations of the inputs or earlier rows. Across 1,905 exact test cases, global scans of affine factors, and an exact optimization run over fixed XOR patterns (addition modulo 2), no reductions appeared. There are zero duplicate factor pairs. All 22,215 product-output functions stay linearly independent after removing the affine span of the 768 inputs. On the canonical 29,434-node round graph, selecting among all 9,722 recognized XOR patterns yields an exact optimum of 274, verified by an independent replay of a disjoint circuit at that count. These checks rule out existing-output affine deletions and fixed structural-XOR selections. They don't constrain refactors that change circuit topology. The register records no prior-art comparison.

Result

For the pinned leader, 1,905 exact runs and global scans prove zero reductions within the tested free-row classes. There are zero duplicate affine-factor pairs. Modulo the affine span of the 768 public inputs, all 22,215 actual product-output functions retain full rank.

On the canonical 29,434-node round AIG, exact global selection over all 9,722 recognized structural XOR patterns yields:

OPT_fixed-XOR = 274.

An explicit disjoint XAG with 274 product rows replayed independently. The six apparent overlaps in the fixed mapping cannot reach 273. Existing-output affine deletions and fixed structural-XOR selections are closed. Topology-changing refactors remain open.

Setting and definitions

The leader is the pinned 768-input Boolean network with 22,215 product rows. A product-output function is the Boolean function evaluated at one of those rows and routed downstream. The affine span of the public inputs comprises all constants, inputs, and their XOR combinations available as affine terms.

The audit evaluates two classes:

  1. Deleting an existing product output whose function is affine-dependent on the public inputs and available product outputs.
  2. Selecting among recognized structural XOR patterns while preserving the canonical round AIG topology.

A disjoint XAG is an XOR-AND graph where the chosen product rows have explicit, non-overlapping accounting under the fixed mapping.

Method

The linear-dependency audit combined 1,905 exact runs, a global affine-factor scan, and an exact functional-rank scan. The factor scan identified zero duplicate pairs. The rank scan verified that all 22,215 actual product-output functions have full rank modulo the affine span of the 768 public inputs, closing the affine-deletion route on the pinned implementation.

The structural selection audit formulated the fixed-AIG XOR-cover problem over all 9,722 recognized XOR patterns on the 29,434-node canonical round AIG. The exact integer model returned optimum 274. An explicit disjoint XAG at 274 was replayed independently, verifying row selection and the fixed mapping, and excluding 273 within this structural class.

The corresponding certificates and replay logs are provided in this paper's downloadable evidence pack.

Discussion

The scanned classes contain no free rows. Because existing product outputs show no affine redundancy over the 768 public inputs, direct output elimination yields no savings. Likewise, the fixed-AIG optimization proves the six candidate overlaps cannot compress the structure to 273 rows; the 274-row disjoint XAG achieves the exact minimum for this structural model.

These bounds apply strictly to the fixed mapping and existing outputs. They do not constrain topology-changing refactors, leaving the unrestricted minimum multiplicative complexity of the leader uncharacterized. Status is EXHAUSTED for the specified free-row classes. The register records no prior-art position.

For everyone — the takeaway

What this means

We can't trim multiplications from the leader using simple input-output combinations, and we can't squeeze the fixed structural XOR patterns past 274 down to 273. Any smaller circuit will require a real architectural refactor rather than local deletions.

Register references

  • ML-010
  • output_product_actual_affine_rank_certificate.json
  • output_product_actual_affine_rank_replay.json
  • xor_cover_exact_milp_result.json
  • xor_cover_full_replay_certificate.json
  • Prior art: the register does not record this.

Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.

Evidence pack

Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 0 of 0 receipt files bundled (1 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.

Download evidence.zip

Changelog

Last reviewed 2026-08-29

  • 2026-08-29Published on this site.

Related in this programme