Research · Papers · What rank-one constraints can express · ML-050

Impossibility of helper-free IsZero over finite fields with |F| ≥ 4

For |F| ≥ 4, no family of degree-at-most-two equations in (x,z) has solution relation Γ₀ = {(0,1)} ∪ {(x,0) : x ∈ F*}

ML-050PROVED DEADPAPER PROOFNEGATIVE RESULTWhat rank-one constraints can express

Published 2026-08-29

For everyone

Plain summary

An IsZero gadget outputs z = 1 when its input x is zero, and z = 0 otherwise. The most compact interface exposes only the pair (x,z) without extra helper variables. Over every finite field with four or more elements, no collection of quadratic equations—constraints multiplying at most two values—can isolate exactly the valid pairs (0,1) and (x,0). Adding more quadratic or rank-one rows cannot fix this as long as the interface exposes only x and z. The standard inverse helper u is therefore mandatory. F₃ is the sole exception: the single row x·x = 1−z computes IsZero, and the register records a two-row implementation of the full inverse-or-default target. The register records no prior art.

Result

Let F be a finite field with |F| ≥ 4, let F* = F \ {0}, and define

Γ₀ = {(0,1)} ∪ {(x,0) : x ∈ F*}.

No family of degree-at-most-two equations in the exposed pair (x,z) has solution relation Γ₀. Equivalently, helper-free IsZero with z = [x=0] cannot be represented by any number of quadratic or rank-one rows without auxiliary allocations; the inverse helper u is required. Over F₃, the obstruction fails: x·x = 1−z realizes IsZero, and the register records a two-row implementation of the full inverse-or-default target.

Setting and definitions

Let F be a finite field, F* its nonzero multiplicative group, and [x=0] the zero indicator. The exposed pair interface consists strictly of input x and output z. Helper-free means no additional variables (such as the inverse helper u) are allocated. A degree-at-most-two equation is quadratic in (x,z), corresponding to standard R1CS rank-one rows.

The target solution relation is

Γ₀ = {(0,1)} ∪ {(x,0) : x ∈ F*},

which enforces zero fibre {1} at x = 0 and nonzero fibre {0} for all x ∈ F*. The three-element field F₃ forms the unique exception.

Method

The certificate combines exact polynomial algebra with fibre replay across zero and nonzero inputs. The algebra establishes that for |F| ≥ 4, no degree-at-most-two system in (x,z) cuts out Γ₀. Fibre replay confirms that F₃ admits the single-row solution x·x = 1−z as well as a two-row inverse-or-default construction (the specific two-row equations are omitted from the register). The verification scripts, raw certificate data, and full derivations are provided in this paper's downloadable evidence pack. The entry cross-references MF-091.

Discussion

The impossibility bound applies to any number of quadratic or rank-one constraints over |F| ≥ 4, provided the system contains only x and z. It does not restrict gadgets that allocate an inverse helper u or other hidden signals. Because u is forced on the exposed interface, allocating an auxiliary witness is mathematically necessary.

The field size bound is sharp. F₃ collapses the obstruction, yielding a one-row IsZero and a two-row inverse-or-default gadget. Large cryptographic prime fields do not exhibit this collapse. This result characterizes the expressiveness of the helper-free exposed pair rather than establishing a lower bound on general R1CS IsZero gadgets with internal wires.

Curation records note Corrections: NONE, and the INDEX contains no corrections, retractions, or addenda for ML-050. The register records no prior art. Status is PROVED DEAD for helper-free designs, with the F₃ exception preserved.

For everyone — the takeaway

What this means

If you want a zero-check gadget with just an input wire x and an output wire z, you cannot build it out of quadratic constraints on fields with four or more elements. Stacking more rows won't help. You must add at least one hidden helper wire—usually the inverse helper u—to make the check work. Only F₃ dodges this rule, allowing a one-line formula for zero checks and a two-row version for combined inversion. No prior art is recorded.

Register references

ML-050

Receipt artifacts: 01-r1cs-gadget-theory/quadratic_relation_certificate.py; 01-r1cs-gadget-theory/quadratic_relation_certificate.json; REPORT.md §3.1

Register cross-reference: MF-091

Prior art: the register does not record this.

Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.

Evidence pack

Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 2 of 2 receipt files bundled (14 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.

Download evidence.zip

Changelog

Last reviewed 2026-08-29

  • 2026-08-29Published on this site.

Related in this programme