Computable oneway real functions

Hardness of inverting functions on the reals

George Barmpalias

Chinese Academy of Sciences

Joint work with M. Wang and X. Zhang

Tianyuan Workshop on Computability and Descriptive Set Theory, June 2025

Effective functions on the reals

This is a standard notion in computable analysis due to Turing (1936).

Computability of real functions is effective continuity:
  • computable real functions are continuous
  • every continuous real function is computable in some oracle

Overview (25 slides)

  1. Inversions of real functions
  2. Oneway real functions
  3. Nearly injective functions
  4. Collisions and hashing
  5. Weakly oneway
  6. Unresolved problems

Partial computable real functions

  • Continuous with $\Pi^0_2$ domain and $\Sigma^1_1$ range
  • if total then uniformly continuous with $\Pi^0_1$ range

Properties of interest include many-to-one versus one-to-one and

A partial computable function is positive iff it extends a random-preserving partial computable function.

Positive and random-preserving maps can be treated as one.

Complexity of inversion

There is no degree bound, even for total functions.

There is a total computable random-preserving surjection $f$ which has no continuous inversion.

Total computable injections have computable inverses.

If a total computable $f$ is injective on $R$ then $f:R\to 2^{\omega}$ is effectively invertible.

Inversion-hardness from non-injectivity and partiality (domain complexity).

Using domain complexity

The true sentences of arithmetic form a $\Pi^0_2$ singleton: ${\emptyset^{\omega}}\in \Pi^0_2$.

There are partial computable $f, h:\subseteq\twome\to\twome$ such that
  • $f$ is injective and no arithmetical $g$ can invert $f$ on any real
  • $\dom(h)$ is uncountable and no $g\in \Delta^1_1$ can invert $h$ on any real.

Many other examples using facts from computability:

for example $x\oplus z\mapsto x$ restricted to randoms.

Randomized computations

Randomized computations can occasionally be replaced by deterministic ones.

Probabilistic inversion

Given $f, g:\subseteq 2^{\omega}\to 2^{\omega}$ we say that $g$ is a

There is an effective positive $f$ which is probabilistically invertible but has no positive inversion $\leq_T 0'$.

Restrict $x\oplus z\mapsto z$ to a $\Pi^0_1(0')$ class of 2-randoms

The following are equivalent:
  • for positive many $r$ there is a positive inversion $g\leq_T r$ of $f$
  • there is a probabilistic inversion $g\leq_T\emptyset$ of $f$.

Examples

There is a partial computable $f:\subseteq\twome\to\twome$ which is
  • random-preserving and nowhere effectively invertible
  • a.e. probabilistically invertible.
If $f$ is a positive partial computable function then it has a positive inversion $g\leq_T 0''$. If $f$ is total then $g\leq_T 0'$. What is the complexity of probabilistic inversions of positive partial computable functions?

--

Oneway real functions

Oneway functions

In computational complexity they are finite maps between strings that are

easy to compute but hard to invert, even probabilistically

Levin (2023) extended them to real functions:

partial computable, positive, with no effective probabilistic inversion.

and asked if they exist. Last year (2024)

Properties of interest: total, surjective, injective, collision-resistant.

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

Shuffle maps on the reals

A shuffle $f:\twome\to\twome$ is given by a computable injection $(a_i)\in\omega^{\omega}$ and $$ f(x)(i):=x(a_i). $$

The $(a_i)$-shuffle has the following properties:
  • it is a total computable random-preserving surjection
  • it is strongly nowhere injective: $f^{-1}(y)$ is uncountable for each $y$
  • every probabilistic inversion of it computes $\sqbrad{a_i}{i\in\omega}$.

Letting $(a_i)$ be an injective enumeration of $0'$ we get:

There is a total computable random-preserving oneway surjection $f$ such that any probabilistic inversion of $f$ computes $0'$.

Why shuffles are oneway

Shuffles $f$ are nowhere injective so an inversion $g$ of $f$

  • makes choices on the unused bits
  • the set of unused bits is undecidable.

Therefore if $g$ attempts to effectively invert $f$:

  • input-bits determined by $g$ are later appended in the output
  • this makes the output predictable by $g$
  • almost all outputs are unpredictable (random)

So $g$ fails to invert $f$ almost everywhere.

Variations on shuffles

If $(a^z_i)$ is the $z$-computable enumeration of $z'$ and $h^z(x)$ is given by $$ h^z(x)(i):=x(a^z_i) $$ the relativized shuffle $f:\twome\to\twome$ is be given by $$f(x\oplus z):=h^z(x)\oplus z.$$

The relativized shuffle
  • is a total computable random-preserving surjection
  • is oneway and has no continuous inversion
  • has a positive inversion $g\leq_T 0'$

and is strongly nowhere injective: $f^{-1}(y)$ is uncountable for each $y$.

Variations on shuffles

For each c.e. $A$ there is a total computable function which
  • is random-preserving and surjective
  • has an $A$-computable inversion
  • is not probabilistically invertible on any random $y\not\geq_T A$
  • is oneway relative to any $w\not\geq_T A$.

Injective oneway functions require partiality:

Every total computable random-preserving oneway function is almost nowhere injective: $f^{-1}(f(x))$ is perfect for almost all $x$.

--

Nearly injective functions

We say that $f:\twome\to\twome$ is two-to-one if $\forall y,\ \abs{f\inv(y)}\leq 2$.

There is a total computable $f:\twome\to\twome$ such that:
  • $f$ is a two-to-one random-preserving surjection
  • $f$ is almost everywhere effectively invertible
  • every $g:\subseteq\twome\to\twome$ that inverts $f$ computes $0'$

and the latter holds for the restriction of $f$ in any cylinder $\dbra{\sigma}$.

The form is $f(x\oplus z):=h^z(x)\oplus z$ where
  • $h^z$ selects positions of $x$-bits used in (copied into) $h^z(x)$
  • all but at most one position $k^z$ are used in $h^z(x)$.

Blueprint for two-to-one functions

  • if $\lim_s k^z_s=\infty$ all $x$-positions are used in $h^z(x)$
  • if $\lim_s k^z_s=k^z$ all $x$-positions except $k^z$ are used in $h^z(x)$.
Given $E^z_s\in \Sigma^0_1$ we update the unused $k^z_s$ if
  • either $k^z_s\in \zj_s$ which we call a $\zj$-permission
  • or $E^z_s(k^z_s)$ which we call a $z$-permission

Goal: given inversion $g$, for each $n$ produce $z,s$ with $k^z_s=n$ and $\neg E^z_s(k^z_s)$.

There is a total computable $f:\twome\to\twome$ such that:
  • $f$ is a two-to-one random-preserving surjection
  • every $g:\subseteq\twome\to\twome$ that inverts $f$ computes $0'$

Let $f(x\oplus z):=h^z(x)\oplus z$ and

$$ k^z_{s+1}:=\begin{cases} s+1 & \textrm{if $k^z_{s}\in \zj_{s}$ or $z(\tuple{k^z_{s},s})=1$} \\ k^z_{s} & \textrm{otherwise.} \end{cases} $$

To select the next $x$-bit used in $f(x\oplus z)$ let $h^z(x; s):=x(p^z_s)$ where:

$$ p^z_s:=\begin{cases} s+1 & \textrm{if $k^z_{s+1}=k^z_{s}$} \\ k^z_{s} & \textrm{otherwise.} \end{cases} $$

Given inversion $g$, for each $n$ produce $z,s$ with $k^z_s=n$ and $\neg E^z_s(k^z_s)$.

Use $g(f(0^\omega\oplus z))$ to determine if $n\in \zj$.

There is a total computable $f:\twome\to\twome$ with:
  • $f$ is a two-to-one random-preserving surjection
  • for each partial $g\not\geq_T \zj$, with positive probability, $g$ fails to invert $f$

and the latter holds for the restriction of $f$ in any cylinder $\sigma$.

Let $z^n$ be the $n$th column of $z$ and $U$ a member of a universal test.

Given $z$ let $k^z_s$ be the non-decreasing counter with
$$ k^z_{s+1}:=\begin{cases} s+1 & \textrm{if $d^z_{s}\in \zj_{s}$ or $z^{d^z_{s}}\in U_s$} \\ \ \ k^z_{s} & \textrm{otherwise} \end{cases} $$ where $d^z_{s}:=\abs{\sqbrad{t<s}{k^z_{t+1}\neq k^z_{t}}}$ counts the updates of $k^z$ and $$ p^z_s:=\begin{cases} s+1 & \textrm{if $k^z_{s+1}=k^z_{s}$} \\ \ \ k^z_{s} & \textrm{otherwise} \end{cases} $$ Updates of $k^z$ coincide with those of $d^z$ and are due to one of:

There is a total computable $f:\twome\to\twome$ with:
  • $f$ is a two-to-one random-preserving surjection
  • for each partial $g\not\geq_T \zj$, with positive probability, $g$ fails to invert $f$

For each $r\not\geqT\zj$ there exist $y, w$ such that

Effectively in $y\oplus w$ and $n$ we can define $z$ and $s$ such that

Given a.e. inversion $g$, use $g(f(x\oplus z))$ to determine if $n\in \zj$.

--

Weakly oneway functions

Left and right oneway functions (Gacs)

A partial computable $f$ is left-oneway if it has positive domain and $$\mu(\sqbrad{x\oplus r}{f(g(f(x), r))=f(x)})=0$$ for each partial computable $g$. It is right-oneway if $$\mu(\{y\oplus r:f(g(y\oplus r))=y\})=0$$ for each partial computable $g$ and it has positive range.

These notions are considerably weaker than oneway functions.

Gacs (2024) showed that there is a left-oneway partial computable $f$.

Another way...

By Kurtz every 2-random $x$ is CEA (it is $y$-c.e. for some $y \leT x$).

  • if $x\leq_T r \oplus y$ and $x$ is $y$-c.e. then r is not y'-random
  • there are only countably many y-c.e. sets

so the functional $\Phi(x)=y$ of Kurtz is left-oneway.

Can the above be injective?

Is there a partial computable injection that maps to 1-generics with positive probability?

Oneway injections

Is there an injective oneway real function?

All constructions of oneway real functions rely on non-injectivity.

We know that oneway injections are:

  • partial: their domain does not contain any positive $\pz$ class
  • not oneway relative to any almost everywhere dominating oracle.

By a direct measure-type priority construction we show:

There is a left-oneway partial computable injection.

Collisions and hashing

Collision resistance

$\CC\subseteq\twome$ is negligible if the set of oracles that compute a member of $\CC$ is null.

We say that $f:\subseteq \twome\to\twome$ is collision-resistant if $$S_f:=\sqbrad{(x,z)}{x\neq z\wedge f(x)=f(z)}$$ is negligible. The members of $S_f$ are called $f$-siblings.

Levin (2024) noticed that shuffles

and asked for a collision-resistant computable oneway real function.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

A hash-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes \texttt{noise}(i) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

A hash-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes \texttt{noise}(i) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

A hash-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes \texttt{noise}(i) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

A hash-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes \texttt{noise}(i) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

A hash-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes \texttt{noise}(i) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hashing the shuffles

The idea is to XOR the shuffle output with "random" bits.

If $A\subseteq\Nat$ is an infinite c.e. set a computable $$h: \sqbrad{\sigma}{|\sigma|\in A}\to \{0,1\}$$ is called an $A$-hash or simply a hash.

Let $\otimes$ denote XOR. We define hash-shuffles.

The $(h,A)$-shuffle $f:\twome\to\twome$ is given by $$ f(x)(i):=x(a_i)\otimes h(x\restr_{a_i}) $$ where $(a_i)$ is a computable enumeration of $A$ without repetitions.

Hash-shuffles

Let $A$ be a c.e. set and $h$ be an $A$-hash.

The $(h,A)$-shuffle is total computable and
  • random-preserving and surjective
  • nowhere injective: $f^{-1}(y)$ is uncountable for each $y$.
  • oneway relative to all $w\not\geq_T A$.

But how should we choose $h$ to make $f$ collision-resistant?

Let $h$ be the universal partial computable binary predicate $\varphi_i(i)$.

Universal hashing

Let $A:=\sqbrad{\tuple{\sigma_i, n_i}}{i\in\Nat}$ where

and define the $A$-hash:

$$ h(\tau):= \begin{cases} \varphi_{n_i}(n_i)&\textrm{if $\sigma_i\prec \tau\wedge \tau\in 2^{\tuple{\sigma_i, n_i}}$}\\ \ \ \ 0 &\textrm{if $\sigma_i\not\prec \tau\wedge \tau\in 2^{\tuple{\sigma_i, n_i}}$} \end{cases} $$

so the $h$-shuffle is given by $f(x)(i)=:h(x\restr_{\tuple{\sigma_i, n_i}})\otimes x(\tuple{\sigma_i, n_i})$.

There is a total computable function which is
  • random-preserving and surjective
  • oneway and collision-resistant.

--

Unresolved problems

Oracles for inversion

We know that $\mathbf{0}'$ characterizes the strength of total oneway functions.

Which oracles $x$ can probabilistically invert every
  1. random-preserving partial computable function $f$?
  2. random-preserving partial computable injection $f$?
Is there a partial computable oneway injection?

Making positive maps injective

Which oracles $x$ can compute an injective restriction for each random-preserving partial computable function?

We know that $\mathbf{0'}$ suffices.

If $f$ is partial computable and random-preserving there is $h$ which
  • is an injective restriction of $f$ and $h\leq_T \mathbf{0}'$
  • has $\Pi^0_1(\emptyset'')$ domain and positive $\Pi^0_1(\emptyset'')$ range.

--

Thank you for your attention!

Thanks to Leonid Levin and Yu Liang and his students

References