In computational complexity theory, P/poly is a complexity class representing problems that can be solved by small circuits. More precisely, it is the set of formal languages that have polynomial-size circuit families. It can also be defined equivalently in terms of Turing machines with advice, extra information supplied to the Turing machine along with its input, that may depend on the input length but not on the input itself. In this formulation, P/poly is the class of decision problems that can be solved by a polynomial-time Turing machine with advice strings of length polynomial in the input size. These two different definitions make P/poly central to circuit complexity and non-uniform complexity.
For example, the popular Miller–Rabin primality test can be formulated as a P/poly algorithm: the "advice" is a list of candidate values to test. It is possible to precompute a list of
O(n)
a\in\{2,7,61\}
BPP\subsetP/poly
P/poly, unlike other polynomial-time classes such as P or BPP, is not generally considered a practical class for computing. Indeed, it contains every undecidable unary language, none of which can be solved in general by real computers. On the other hand, if the input length is bounded by a relatively small number and the advice strings are short, it can be used to model practical algorithms with a separate expensive preprocessing phase and a fast processing phase, as in the Miller–Rabin example.
The complexity class P/poly can be defined in terms of SIZE as follows:
P/poly=cupc\inNSIZE(nc),
where
SIZE(nc)
nc
Alternatively,
P/poly
\alphan
Let
T,a:N → N
a(n)
DTIME(T(n))/a(n)
\{\alphan\}n
\alphan\in\{0,1\}a(n)
M(x,\alphan)=1\Leftrightarrowx\inL
for every
x\in\{0,1\}n
(x,\alphan)
O(T(n))
P/poly is an important class for several reasons. For theoretical computer science, there are several important properties that depend on P/poly:
P | |
\Sigma | |
2 |
PSPACE=
P | |
\Sigma | |
2 |
\cap
P | |
\Pi | |
2 |
Proof: Consider a language L from PSPACE. It is known that there exists an interactive proof system for L, where actions of the prover can be carried out by a PSPACE machine. By assumption, the prover can be replaced by a polynomial-size circuit. Therefore, L has a MA protocol: Merlin sends the circuit as proof, and Arthur can simulate the IP protocol himself without any additional help.
EXPTIME
P | |
=\Sigma | |
2 |
\cap
P | |
\Pi | |
2 |
EXPNP |
=
P | |
\Sigma | |
2 |
\cap
P | |
\Pi | |
2 |
Proof: If MAEXP ⊆ P/poly then PSPACE = MA (see above). By padding, EXPSPACE = MAEXP, therefore EXPSPACE ⊆ P/poly but this can be proven false with diagonalization.
One of the most interesting reasons that P/poly is important is the property that if NP is not a subset of P/poly, then P ≠ NP. This observation was the center of many attempts to prove P ≠ NP. It is known that for a random oracle A, NPA is not a subset of PA/poly with probability 1.
P/poly is also used in the field of cryptography. Security is often defined 'against' P/poly adversaries. Besides including most practical models of computation like BPP, this also admits the possibility that adversaries can do heavy precomputation for inputs up to a certain length, as in the construction of rainbow tables.
Although not all languages in P/poly are sparse languages, there is a polynomial-time Turing reduction from any language in P/poly to a sparse language.[3]
Adleman's theorem states that BPP ⊆ P/poly, where BPP is the set of problems solvable with randomized algorithms with two-sided error in polynomial time. A weaker result was initially proven by Leonard Adleman, namely, that RP ⊆ P/poly; and this result was generalized to BPP ⊆ P/poly by Bennett and Gill.[4] Variants of the theorem show that BPL is contained in L/poly and AM is contained in NP/poly.
Let L be a language in BPP, and let M(x,r) be a polynomial-time algorithm that decides L with error ≤ 1/3 (where x is the input string and r is a set of random bits).
Construct a new machine M(x,R), which runs M 48n times and takes a majority vote of the results (where n is the input length and R is a sequence of 48n independently random rs). Thus, M is also polynomial-time, and has an error probability ≤ 1/en by the Chernoff bound (see BPP). If we can fix R then we obtain an algorithm that is deterministic.
If
Bad(x)
\{R:M{{'}}(x,R)isincorrect\}
\forallxProbR[R\inBad(x)]\leq
1 | |
en |
.
The input size is n, so there are 2n possible inputs. Thus, by the union bound, the probability that a random R is bad for at least one input x is
ProbR[\existsxR\inBad(x)]\leq
2n | |
en |
<1.
In words, the probability that R is bad for some x is less than 1, therefore there must be an R that is good for all x. Take such an R to be the advice string in our P/poly algorithm.