← Back to Chapter 10, Noise budget and symmetric representatives
Regev noise budget on Zq
An honest Regev ciphertext is guaranteed to decode correctly while the parameters keep its noise inside the budget. Slide the error bound B and sample count m, scrub the noise inner product e⊤r, and toggle the modulus. The decoded points move along Zq. While the chapter budget 2mB < ⌊q/2⌋ holds, no honest ciphertext can decode wrongly. Once it is violated the guarantee is gone, and a large enough realized e⊤r flips the bit, which the scrubber lets you find.
modulus q
error bound B = 1
sample count m = 8
noise e⊤r = 8
of ±8
bit-0 decoding region
bit-1 decoding region
honest ciphertext