Faster all-pairs shortest paths via circuit complexity

Ryan Williams

Introduction

Since the 1970s [Mun71, FM71, AHU74] it has been known that the search for faster algorithms for APSP is equivalent to the search for faster algorithms for the min-plus (or max-plus) matrix product (a.k.a. distance product or tropical matrix multiplication), defined as:

That is, min⁡\min plays the role of addition, and ++ plays the role of multiplication. A T(n)T(n)-time algorithm exists for this product if and only if there is an O(T(n))O(T(n))-time algorithm for APSP.Technically speaking, to reconstruct the shortest paths, we also need to compute the product (A⊙B)[i,j]=arg min⁡k(A[i,k]+B[k,j])(A\odot B)[i,j]=\operatorname*{arg\,min}_{k}(A[i,k]+B[k,j]), which returns (for all i,ji,j) some kk witnessing the minimum A[i,k]+B[k,j]A[i,k]+B[k,j]. However, all known distance product algorithms (including ours) have this property.

Perhaps inspired by the surprising n2.82n^{2.82} matrix multiplication algorithm of Strassen [Str69] over rings,As min⁡\min and max⁡\max do not have additive inverses, min-plus algebra and max-plus algebra are not rings, so fast matrix multiplication algorithms do not directly apply to them. Fredman [Fre75] initiated the development of o(n3)o(n^{3}) time algorithms for APSP. He discovered a non-uniform decision tree computing the n×nn\times n min-plus product with depth O(n2.5)O(n^{2.5}) (but with size 2Θ(n2.5)2^{\Theta(n^{2.5})}). Combining the decision tree with a lookup table technique, he obtained a uniform APSP algorithm running in about n3/log⁡1/3nn^{3}/\log^{1/3}n time. Since 1975, many subsequent improvements on Fredman’s algorithm have been reported (see Table 1).There have also been parallel developments in APSP algorithms on sparse graphs [Joh77, FT87, PR05, Pet04, Cha06] and graphs with small integer weights [Rom80, Pan81, Sei95, Tak95, AGM97, SZ99, Zwi02, GS13]. The small-weight algorithms are pseudopolynomial, running in time O(Mαnβ)O(M^{\alpha}n^{\beta}) for various α>0\alpha>0 and various β\beta greater than the (ring) matrix multiplication exponent. However, all these improvements have only saved log⁡cn\log^{c}n factors over Floyd-Warshall: most recently, Chan [Cha07] and Han and Takaoka [HT12] give time bounds of roughly n3/log⁡2nn^{3}/\log^{2}n.

The consensus appears to be that the known approaches to general APSP may never save more than small poly(log⁡n){\text{poly}}(\log n) factors in the running time. The methods (including Fredman’s) use substantial preprocessing, lookup tables, and (sometimes) bit tricks, offloading progressively more complex operations into tables such that these operations can then be executed in constant time, speeding up the algorithm. It is open whether such techniques could even lead to an n3/log⁡3nn^{3}/\log^{3}n time Boolean matrix multiplication (with logical OR as addition), a special case of max-plus product. V. Vassilevska Williams and the author [VW10] proved that a large collection of fundamental graph and matrix problems are subcubic equivalent to APSP: Either all these problems are solvable in n3−εn^{3-{\varepsilon}} time for some ε>0{\varepsilon}>0 (a.k.a. “truly subcubic time”), or none of them are. This theory of APSP-hardness has nurtured some pessimism that truly subcubic APSP is possible.

We counter these doubts with a new algorithm for APSP running faster than n3/log⁡knn^{3}/\log^{k}n time, for every kk.

A similar n2+o(1)log⁡Mn^{2+o(1)}\log M time factor would necessarily appear in a complete running time description of all previous algorithms when implemented on a machine that takes bit complexity into account, such as the word RAM—note the input itself requires Ω(n2log⁡M)\Omega(n^{2}\log M) bits to describe in the worst case. In the real RAM model, where additions and comparisons of real numbers given in the input are unit cost, but all other operations have typical cost, the algorithm runs in the “strongly polynomial” bound of n3/2Ω(log⁡n)1/2n^{3}/2^{\Omega(\log n)^{1/2}} time. Most prior algorithms for the general case of APSP also have implementations in the real RAM. (For an extended discussion, see Section 2 of Zwick [Zwi04].)

The new algorithm avoids an exponential blowup by exploiting the fact that min⁡\min and addition are simple operations from the point of view of Boolean circuit complexity. Namely, these operations are both in AC0{\sf AC}^{0}, i.e., they have circuits of constant-depth and polynomial-size over AND/OR/NOT gates of unbounded fan-in. It follows that min-plus inner products can be computed in AC0{\sf AC}^{0}, and the new algorithm manipulates such circuits at the bit-level. (This also means the approach is highly non-black-box, and not subject to lower bounds based on additions and comparisons alone; this is necessary, due to Kerr’s Ω(n3)\Omega(n^{3}) lower bound.) AC0{\sf AC}^{0} operations are very structured and have many known limitations (starting with [Ajt83, FSS81]). Circuit lower bound techniques often translate algorithmically into nice methods for manipulating circuits.

Minimum weight triangle: Given an nn-node graph with real edge weights, compute u,v,wu,v,w such that (u,v),(v,w),(w,u)(u,v),(v,w),(w,u) are edges and the sum of edge weights is minimized.

Minimum cycle: Given an nn-node graph with real positive edge weights, find a cycle of minimum total edge weight.

Second shortest paths: Given an nn-node directed graph with real positive edge weights and two nodes ss and tt, determine the second shortest simple path from ss to tt.

Replacement paths: Given an nn-node directed graph with real positive edge weights and a shortest path PP from node ss to node tt, determine for each edge e∈Pe\in P the shortest path from ss to tt in the graph with ee removed.

Faster algorithms for some sparse graph problems also follow from Theorem 1.1. An example is that of finding a minimum weight triangle in a sparse graph:

In other words, this is the usual discrete convolution of two vectors in (min⁡,+)(\min,+) algebra.

Is it possible that the approach of this paper can be extended to give a “truly subcubic” APSP algorithm, running in n3−εn^{3-{\varepsilon}} time for some ε>0{\varepsilon}>0? If so, we might require an even more efficient way of representing min-plus inner products as inner products over the integers. Very recently, the author discovered a way to efficiently evaluate large depth-two linear threshold circuits [Wil13] on many inputs. The method is general enough that, if min-plus inner product can be efficiently implemented with depth-two threshold circuits, then truly subcubic APSP follows. For instance:

To phrase it another way, the hypothesis that APSP is not in truly subcubic time implies interesting circuit lower bounds.

In Section 2, we try to provide a relatively succinct exposition of how to solve APSP in less than n3/log⁡knn^{3}/\log^{k}n time for all kk, in the case where the edge weights are not too large (e.g., at most poly(n){\text{poly}}(n)). In Section 3 we prove Theorem 1.1 in full, by expanding considerably on the arguments in Section 2. In Section 4 we illustrate one of the many applications, and consider the possibility of extending our approach to a truly subcubic algorithm for APSP. We conclude in Section 5.

A relatively short argument for faster APSP

We begin with a succinct exposition of a good algorithm for all-pairs shortest paths, at least in the case of reasonable-sized weights. This will illustrate most of the main ideas in the full algorithm.

There is a deterministic algorithm for APSP which, for some δ>0\delta>0, runs in time

To simplify the presentation, we will not be explicit in our choice of δ\delta here; that lovely torture will be postponed to the next section. Another mildly undesirable property of Theorem 2.1 is that the bound is only meaningful for M≤22ε(log⁡n)δM\leq 2^{2^{{\varepsilon}(\log n)^{\delta}}} for sufficiently small ε>0{\varepsilon}>0. So this is not the most general bound one could hope for, but it is effective when the edge weights are in the range {0,1,…,poly(n)}\{0,1,\ldots,{\text{poly}}(n)\}, which is already a difficult case for present algorithms. The (log⁡M)1+o(1)(\log M)^{1+o(1)} factor will be eliminated in the next section.

A min-plus matrix multiplication simply represents a collection of all-pairs min-plus inner products over a set of vectors.

Given u,v∈Wdu,v\in{\cal W}^{d} encoded as O(dlog⁡M)O(d\log M)-bit strings, (u⋆v)(u\star v) is computable with constant-depth AND/OR/NOT circuits of size (dlog⁡M)O(1)(d\log M)^{O(1)}. That is, the min-plus inner product function is computable in AC0{\sf AC}^{0} for every dd and MM.

The proof is relatively straightforward; it is given in Appendix A for completeness. Next, we show that a small AC0{\sf AC}^{0} circuit can be quickly evaluated on all pairs of inputs of one’s choice. The first step is to deterministically reduce AC0{\sf AC}^{0} circuits to depth-two circuits with a symmetric function (a multivariate Boolean function whose value only depends on the sum of the variables) computing the output gate and AND gates of inputs (or their negations) on the second layer. Such circuits are typically called SYM+{\sf SYM}^{+} circuits [BT94]. It is known that constant-depth circuits with AND, OR, NOT, and MODmm gates of size ss (a.k.a. ACC{\sf ACC} circuits) can be efficiently translated into SYM+{\sf SYM}^{+} circuits of size 2(log⁡s)c2^{(\log s)^{c}} for some constant cc depending on the depth of the circuit and the modulus mm:A MODmm gate outputs 11 if and only if the sum of its input bits is divisible by mm.

Moreover, given the number of ANDs in the circuit evaluating to 11, the symmetric function itself can be evaluated in (log⁡s)O(f(e,m))(\log s)^{O(f(e,m))} time.

The second step is to quickly evaluate these polynomials on many chosen inputs, using rectangular matrix multiplication. Specifically, we require the following:

For all sufficiently large NN, multiplication of an N×N.172N\times N^{.172} matrix with an N.172×NN^{.172}\times N matrix can be done in O(N2log⁡2N)O(N^{2}\log^{2}N) arithmetic operations.See Appendix C for a detailed exposition of this algorithm.

Let pp be a 2k2k-variate polynomial over the integers (in its monomial representation) with m≤n0.1m\leq n^{0.1} monomials, along with A,B⊆{0,1}kA,B\subseteq\{0,1\}^{k} such that ∣A∣=∣B∣=n|A|=|B|=n. The polynomial p(a1,…,ak,b1,…,bk)p(a_{1},\ldots,a_{k},b_{1},\ldots,b_{k}) can be evaluated over all points (a1,…,ak,b1,…,bk)∈A×B(a_{1},\ldots,a_{k},b_{1},\ldots,b_{k})\in A\times B in n2⋅poly(log⁡n)n^{2}\cdot{\text{poly}}(\log n) arithmetic operations.

Note that the obvious polynomial evaluation algorithm would require n2.1n^{2.1} arithmetic operations.

Putting the pieces together, we obtain our “warm-up” APSP algorithm:

But K≤n0.1K\leq n^{0.1} precisely when (log⁡(dlog⁡M))c≤0.1log⁡n(\log(d\log M))^{c}\leq 0.1\log n, i.e.,

Proof of The Main Theorem

First, we can assume without loss of generality that for all i,ji,j, there is a unique kk achieving the minimum A[i,k]+B[k,j]A[i,k]+B[k,j]. One way to enforce this is to change all initial A[i,j]A[i,j] entries at the beginning to A[i,j]⋅(n+1)+jA[i,j]\cdot(n+1)+j, and all B[i,j]B[i,j] entries to B[i,j]⋅(n+1)B[i,j]\cdot(n+1), prior to sorting. These changes can be made with only O(log⁡n)O(\log n) additions per entry; e.g., by adding A[i,j]A[i,j] to itself for O(log⁡n)O(\log n) times. Then, min⁡kA[i,k]+B[k,j]\min_{k}A[i,k]+B[k,j] becomes

where k⋆k^{\star} is the minimum integer achieving min⁡kA[i,k]+B[k,j]\min_{k}A[i,k]+B[k,j].

Next, we encode a trick of Fredman [Fre75] in the computation; his trick is simply that

This subtle trick has been applied in most prior work on faster APSP. It allows us to “prepare” AA and BB by taking many differences of entries, before making explicit comparisons between entries. Namely, we construct matrices A′A^{\prime} and B′B^{\prime} which are n×d2n\times d^{2} and d2×nd^{2}\times n. The columns of A′A^{\prime} and rows of B′B^{\prime} are indexed by pairs (k,k′)(k,k^{\prime}) from [d]2[d]^{2}. We define:

Observe that A′[i,(k,k′)]≤B′[(k,k′),j]A^{\prime}[i,(k,k^{\prime})]\leq B^{\prime}[(k,k^{\prime}),j] if and only if A[i,k]+B[k,j]≤A[i,k′]+B[k′,j]A[i,k]+B[k,j]\leq A[i,k^{\prime}]+B[k^{\prime},j].

For each column (k,k′)(k,k^{\prime}) of A′A^{\prime} and corresponding row (k,k′)(k,k^{\prime}) of B′B^{\prime}, sort the 2n2n numbers in the set

and replace each A′[i,(k,k′)]A^{\prime}[i,(k,k^{\prime})] and B[(k,k′),j]B[(k,k^{\prime}),j] by their rank in the sorted order on S(k,k′)S_{(k,k^{\prime})}, breaking ties arbitrarily (giving AA entries precedence over BB entries). Call these new matrices A′′A^{\prime\prime} and B′′B^{\prime\prime}. The key properties of this replacement are:

All entries of A′′A^{\prime\prime} and B′′B^{\prime\prime} are from the set {1,…,2n}\{1,\ldots,2n\}.

A′′[i,(k,k′)]≤B′′[(k,k′),j]A^{\prime\prime}[i,(k,k^{\prime})]\leq B^{\prime\prime}[(k,k^{\prime}),j] if and only if A′[i,(k,k′)]≤B′[(k,k′),j]A^{\prime}[i,(k,k^{\prime})]\leq B^{\prime}[(k,k^{\prime}),j]. That is, the outcomes of all comparisons have been preserved.

For every i,ji,j, there is a unique kk such that A′′[i,(k,k′)]≤B′′[(k,k′),j]A^{\prime\prime}[i,(k,k^{\prime})]\leq B^{\prime\prime}[(k,k^{\prime}),j] for all k′k^{\prime}; this follows from the fact that there is a unique kk achieving the minimum A[i,k]+B[k,j]A[i,k]+B[k,j].

Here we are using the notation that, for a logical expression QQ, the expression [QQ] is either or 11, and it is 11 if and only if QQ is true.

In the expression PP, there are dd different ANDs over dd comparisons. In order to get a “short” polynomial, we need to reduce the fan-in of the ANDs. Razborov and Smolensky proposed the following construction: for an AND over dd variables y1,…,ydy_{1},\ldots,y_{d}, let e≥1e\geq 1 be an integer, choose independently and uniformly at random e⋅de\cdot d bits r1,1,…,r1,d,r2,1,…,r2,d, … ,re,1,…,re,d∈{0,1}r_{1,1},\ldots,r_{1,d},r_{2,1},\ldots,r_{2,d},~{}\ldots~{},r_{e,1},\ldots,r_{e,d}\in\{0,1\}, and consider the expression

where ++ corresponds to addition modulo 22. Note that when the ri,jr_{i,j} are fixed constants, EE is an AND of ee XORs of at most d+1d+1 variables yjy_{j} along with possibly the constant 11.

For every fixed (y1,...,yd)∈{0,1}d(y_{1},...,y_{d})\in\{0,1\}^{d},

For completeness, we give the simple proof. For a given point (y1,…,yd)(y_{1},\ldots,y_{d}), first consider the expression Fi=1+⊕j=1dri,j⋅(yj+1)F_{i}=1+\oplus_{j=1}^{d}r_{i,j}\cdot(y_{j}+1). If y1∧⋯∧yd=1y_{1}\wedge\cdots\wedge y_{d}=1, then (yj+1)(y_{j}+1) is modulo 22 for all jj, and hence Fi=1F_{i}=1 with probability 11. If y1∧⋯∧yd=0y_{1}\wedge\cdots\wedge y_{d}=0, then there is a subset SS of yjy_{j}’s which are , and hence a subset SS of (yj+1)(y_{j}+1)’s that are 11. The probability we choose ri,j=1r_{i,j}=1 for an odd number of the yjy_{j}’s in SS is at exactly 1/21/2. Hence the probability that Fi=0F_{i}=0 in this case is exactly 1/21/2.

Since E(y1,…,yd)=∧i=1eFiE(y_{1},\ldots,y_{d})=\wedge_{i=1}^{e}F_{i}, it follows that if y1∧⋯∧yd=1y_{1}\wedge\cdots\wedge y_{d}=1, then E=1E=1 with probability 11. Since the ri,jr_{i,j} are independent, if y1∧⋯∧yd=0y_{1}\wedge\cdots\wedge y_{d}=0, then the probability is only 1/2e1/2^{e} that for all ii we have ri,j=1r_{i,j}=1 for an odd number of yj=0y_{j}=0. Hence the probability is 1−1/2e1-1/2^{e} that some Fi(y1,…,yd)=0F_{i}(y_{1},\ldots,y_{d})=0, completing the proof.

Now set e=2+log⁡de=2+\log d, so that EE fails on a point yy with probability at most 1/(4d)1/(4d). Suppose we replace each of the dd ANDs in expression PP by the expression EE, yielding:

By the union bound, the probability that the (randomly generated) expression P′P^{\prime} differs from PP on a given row A′′[i,:]A^{\prime\prime}[i,:] and column B′′[:,j]B^{\prime\prime}[:,j] is at most 1/41/4.

Next, we open up the d2d^{2} comparisons in PP and simulate them with low-depth circuits. Think of the entries of A′′[i,(k,k′)]A^{\prime\prime}[i,(k,k^{\prime})] and B′′[(k,k′),j]B^{\prime\prime}[(k,k^{\prime}),j] as bit strings, each of length t=1+log⁡nt=1+\log n. To check whether a≤ba\leq b for two tt-bit strings a=a1,...,ata=a_{1},...,a_{t} and b=b1,...,btb=b_{1},...,b_{t} construed as positive integers in {1,…,2t}\{1,\ldots,2^{t}\}, we can compute (from Lemma 2.1)

where ++ again stands for addition modulo 22. (We can replace the outer ∨\vee with a ⊕\oplus, because at most one of the tt expressions inside of the ⊕\oplus can be true for any aa and bb.)

The LEQLEQ circuit is an XOR of t+1t+1 ANDs of fan-in ≤t\leq t of XORs of fan-in at most 3. Applying Claim 1, we replace the ANDs with a randomly chosen expression E′(e1,…,et)E^{\prime}(e_{1},\ldots,e_{t}), which is an AND of fan-in e′e^{\prime} (for some parameter e′e^{\prime} to be determined) of XORs of ≤t\leq t fan-in. The new expression LEQ′LEQ^{\prime} now has the form

that is, we have an XOR of t+1t+1 fan-in, of ANDs of fan-in e′e^{\prime}, of XORs of ≤t\leq t fan-in, of XORs of fan-in at most 3.

In fact, an anonymous STOC referee pointed out that, by performing additional preprocessing on the matrices A′′A^{\prime\prime} and B′′B^{\prime\prime}, we can reduce the LEQ′LEQ^{\prime} expression further, to have the form

Recall in the expression P′P^{\prime}, there are d2d^{2} comparisons, and hence d2d^{2} copies of the LEQLEQ circuit are needed. Setting

we ensure that, for a given row ii, column jj, and tt for P′P^{\prime}, d2d^{2} copies of the LEQ′LEQ^{\prime} circuit give the same output as LEQLEQ with probability at least 3/43/4.

Further simplifying, this quantity is at most

Let m′′m^{\prime\prime} denote the quantity in (2). Provided m′′≤n0.1m^{\prime\prime}\leq n^{0.1}, we will be able to apply a rectangular matrix multiplication in the final step. This is equivalent to

Recall t=1+log⁡nt=1+\log n, and note that log⁡2(m′′)\log_{2}(m^{\prime\prime}) expands to a sum of various powers of logs. For d≥td\geq t, the dominant term in log⁡2(m′′)\log_{2}(m^{\prime\prime}) is 2(log⁡2d)(log⁡3)≤O((log⁡d)2)2(\log^{2}d)(\log 3)\leq O((\log d)^{2}). Choosing

for sufficiently small δ>0\delta>0, inequality (3) will be satisfied, and the number m′′m^{\prime\prime} will be less than n0.1n^{0.1}.

Recall that if we have independent random variables YiY_{i} that are -11 valued with 0<E[Yi]<10<E[Y_{i}]<1, the random variable Y:=∑i=1kYiY:=\sum_{i=1}^{k}Y_{i} satisfies the tail bound

(e.g., in Motwani and Raghavan [MR95], this is Theorem 4.2). Applying this bound,

Therefore for d=2δ(log⁡n)1/2d=2^{\delta(\log n)^{1/2}}, the algorithm outputs the min-plus product of an n×dn\times d and d×nd\times n matrix in n2⋅poly(log⁡n)+n⋅d2⋅(log⁡M)n^{2}\cdot{\text{poly}}(\log n)+n\cdot d^{2}\cdot(\log M) time, with probability at least 1−(log⁡n)/n21-(\log n)/n^{2}.

Applying this algorithm to n/dn/d different n×dn\times d and d×nd\times n min-plus products, the min-plus product of two n×nn\times n matrices is computable in time n3/2Ω(log⁡n)1/2n^{3}/2^{\Omega(\log n)^{1/2}} on the real RAM with probability at least 1−(log⁡n)/n1-(\log n)/n, by the union bound. (On the word RAM, there is an extra additive factor of n2+o(1)⋅log⁡Mn^{2+o(1)}\cdot\log M, for the initial application of Fredman’s trick.)

The APSP algorithm can be made deterministic with some loss in the running time, but still asymptotically better than n3/(log⁡n)kn^{3}/(\log n)^{k} for every kk. See Appendix B for the proof.

There is a δ>0\delta>0 and a deterministic algorithm for APSP running in n3/2(log⁡n)δn^{3}/2^{(\log n)^{\delta}} time on the real RAM.

Some Applications

All applications referred to the introduction follow straightforwardly from the literature, except for possibly:

We follow the high-degree/low-degree trick of Alon, Yuster, Zwick [AYZ97]. To find a minimum edge-weight triangle with mm edges, let Δ∈[1,m]\Delta\in[1,m] be a parameter and consider two possible scenarios:

The min-weight triangle contains a node of degree at most Δ\Delta. Here, O(m⋅Δ)O(m\cdot\Delta) time suffices to search for the triangle: try all possible edges {u,v}\{u,v\} with deg⁡(v)≤Δ\deg(v)\leq\Delta, and check if there is a neighbor of vv which forms a triangle with uu, recording the triangle encountered of smallest weight.

To minimize the overall running time, we want

It seems likely that the basic approach taken in this paper can be extended to discover even faster APSP algorithms. Here we outline one concrete direction to pursue.

It is an open frontier in circuit complexity to exhibit explicit functions which are not computable efficiently with SYM∘THR{\sf SYM}\circ{\sf THR} circuits. As far as we know, it could be that huge complexity classes like EXPNP{\sf EXP}^{\sf NP} have SYM∘THR{\sf SYM}\circ{\sf THR} circuits with only poly(n){\text{poly}}(n) gates. (Allowing exponential weights is crucial: there are lower bounds for depth-two threshold circuits with small weights [HMP+93].)

That is, efficient depth-two circuits for (min⁡,+)(\min,+) inner product would imply a truly subcubic time algorithm for APSP. The proof applies a recent algorithm of the author:

Given a SYM∘THR{\sf SYM}\circ{\sf THR} circuit CC with 2k2k inputs and at most n1/12n^{1/12} gates with threshold weights of absolute value at most WbW_{b}, and given two sets A,B⊆{0,1}kA,B\subseteq\{0,1\}^{k} where ∣A∣=∣B∣=n|A|=|B|=n, we can evaluate CC on all n2n^{2} points in A×BA\times B using n2⋅poly(log⁡n)+n1+1/12⋅poly(log⁡n,log⁡Wb)n^{2}\cdot{\text{poly}}(\log n)+n^{1+1/12}\cdot{\text{poly}}(\log n,\log W_{b}) time.

A similar theorem also holds for depth-two threshold circuits (THR∘THR{\sf THR}\circ{\sf THR}). Note the obvious algorithm for the above evaluation problem would take at least Ω(n2+1/12)\Omega(n^{2+1/12}) time.

To compute the (min⁡,+)(\min,+)-multiplication of two n×nn\times n matrices, we reduce it into n/dn/d multiplies of n×dn\times d and d×nd\times n (as in Theorems 2.1 and 1.1), resulting in an algorithm running in time O(n3−1/(12k)⋅(log⁡M)k)O(n^{3-1/(12k)}\cdot(\log M)^{k}).

Discussion

1. Subquadratic 3SUM. Along with APSP, the 3SUM problem is another notorious polynomial-time solvable problem: given a list of integers, are there three which sum to zero? For lists of nn numbers, an O(n2)O(n^{2}) time algorithm is well-known, and the conjecture that no n1.999n^{1.999} time algorithm exists is significant in computational geometry and data structures, with many intriguing consequences [GO95, BHP01, SEO03, Pat10, VW13]. Baran, Demaine, and Patrascu [BDP05] showed that 3SUM is in about n2/log⁡2nn^{2}/\log^{2}n time (omitting poly(log⁡log⁡n){\text{poly}}(\log\log n) factors). Can this be extended to n2/2(log⁡n)δn^{2}/2^{(\log n)^{\delta}} time for some δ>0\delta>0? It is natural to start with solving Convolution-3SUM, defined by Patrascu [Pat10] as: given an array AA of nn integers, are there ii and jj such that A[i]+A[j]=A[i+j(modn)]A[i]+A[j]=A[i+j\pmod{n}]? Although this problem looks superficially easier than 3SUM, Patrascu showed that if Convolution-3SUM is in n2/(f(n⋅f(n)))2n^{2}/(f(n\cdot f(n)))^{2} time then 3SUM is in n2/f(n)n^{2}/f(n) time. That is, minor improvements for Convolution-3SUM would yield similar improvements for 3SUM.

2. Subquadratic String Matching. There are many problems involving string matching and alignment which are solvable using dynamic programming in O(n2/log⁡n)O(n^{2}/\log n) time, on strings of length nn. A prominent example is computing the edit distance [MP80]. Can edit distance be computed in n2/2(log⁡n)δn^{2}/2^{(\log n)^{\delta}} time?

3. Practicality? There are two potential impediments to making the approach of this paper work in practice: (1) the translation from AC0{\sf AC}^{0} circuits to polynomials, and (2) Coppersmith’s matrix multiplication algorithm. For case (1), there are no large hidden constants inherent in the Razborov-Smolensky translation, however the expansion of the polynomial as an XOR of ANDs yields a quasi-polynomial blowup. A careful study of alternative translations into polynomials would likely improve this step for practice. For case (2), Coppersmith’s algorithm as described in Appendix C consists of a series of multiplications with Vandermonde and inverse Vandermonde matrices (which are very efficient), along with a recursive step on 2×32\times 3 and 3×23\times 2 matrices, analogous to Strassen’s famous algorithm. We see no theoretical reason why this algorithm (implemented properly) would perform poorly in practice, given that Strassen’s algorithm can be tuned for practical gains [GG96, CLPT02, DN09, BDLS12, BDH+12]. Nevertheless, it would likely be a substantial engineering challenge to turn the algorithms of this paper into high-performance software.

5. Truly Subcubic APSP? What other circuit classes can compute (min⁡,+)(\min,+) inner product and also permit a fast evaluation algorithm on many inputs? This question now appears to be central to the pursuit of truly subcubic (n3−εn^{3-{\varepsilon}} time) APSP. Although we observe in the paper that (min⁡,+)(\min,+) inner product is efficiently computable in AC0{\sf AC}^{0}, the usual algebraic (+,×)(+,\times) inner product is in fact not in AC0{\sf AC}^{0}. (Multiplication is not in AC0{\sf AC}^{0}, by a reduction from Parity [CSV84].) This raises the intriguing possibility that (min⁡,+)(\min,+) matrix product (and hence APSP) is not only in truly subcubic time, but could be easier than integer matrix multiplication. A prerequisite to this possibility would be to find new Boolean matrix multiplication algorithms which do not follow the Strassenesque approaches of the last 40+ years. Only minor progress on such algorithms has been recently made [BW09].

Many thanks to Virginia Vassilevska Williams; without her as a sounding board, I would have stopped thinking about APSP a long time ago. I’m also grateful to Uri Zwick, Farah Charab, and the STOC referees for helpful comments. Thanks also to Eric Allender for a discussion on references.

References

Appendix A Proof of Lemma 2.1

Before giving the circuit, let us briefly discuss the encoding of ∞\infty. In principle, all we need is that ∞\infty encodes an integer greater than 2M2M, and that addition of ∞\infty with any number equals ∞\infty again. With that in mind, we use the following convention: t=3+log⁡Mt=3+\log M bits are allocated to encode each number in {0,…,M}\{0,\ldots,M\} (with two leading zeroes), and ∞\infty is defined as the all-ones string of tt bits.

The addition of two tt-bit strings xx and yy is computable in tO(1)t^{O(1)} size and constant depth, using a “carry-lookahead” adder [SV84] (with an improved size bound in [CFL85]). Recall that a carry-lookahead adder determines in advance:

which bits of xx and yy will “generate” a 11 when added, by taking the AND of each matching pair of bits from xx and yy, and

which bits of xx and yy will “propagate” a 11 if given a 11 from the summation of lower bits, by taking the XOR of each matching pair of bits.

The “generate” and “propagate” bits can be generated in constant depth. Given them, in parallel we can determine (for all ii) which bits ii of the addition will generate a carry in constant depth, and hence determine the sum in constant depth. (To handle the case of ∞\infty, we simply add a side circuit which computes in parallel if one of the inputs is all-11s, in which case all output bits are forced to be 11.)

Chandra, Stockmeyer, and Vishkin [CSV84] show how to compute the minimum of a collection of numbers (given as bit strings) in AC0{\sf AC}^{0}. For completeness, we give a construction here. First, the comparison of two tt-bit strings xx and yy (construed as non-negative integers) is computable in AC0{\sf AC}^{0}. Define

where ++ stands for addition modulo 22. The first disjunct is true if and only if x=yx=y. For the second disjunct and given i=1,…,ti=1,\ldots,t, the inner expression is true if and only if the first i−1i-1 bits of xx and yy are equal, the iith bit of xx is , and the iith bit of yy is 1. Replacing each 1+a+b1+a+b with (¬a∨b)∧(a∨¬b)(\neg a\vee b)\wedge(a\vee\neg b), we obtain an AC0{\sf AC}^{0} circuit.

Appendix B Appendix: Derandomizing the APSP algorithm

Reminder of Theorem 3.1 There is a δ>0\delta>0 and a deterministic algorithm for APSP running in n3/2(log⁡n)δn^{3}/2^{(\log n)^{\delta}} time on the real RAM.

The proof combines the use of Fredman’s trick in Theorem 1.1 with the deterministic reduction from circuits to polynomials in Theorem 2.1.

Therefore we can reduce an n×dn\times d and d×nd\times n min-plus matrix product to a matrix product over the integers, by replacing each row uu of the first matrix by a corresponding u′u^{\prime} of length

We derive an upper bound on dd as follows:

hence d=2(0.1log⁡n)1/c/4d=2^{(0.1\log n)^{1/c}/4} suffices for sufficiently large nn.

Examining the proof of Theorem 2.2 shows that we can estimate c=2Θ(d′)c=2^{\Theta(d^{\prime})}, where d′d^{\prime} is the depth of the original AC0{\sf AC}^{0} circuit. However, as Beigel and Tarui’s proof also works for the much more expressive class ACC{\sf ACC} (and not just AC0{\sf AC}^{0}), we are confident that better estimates on cc are possible with a different argument, and hence refrain from calculating an explicit bound here.

Appendix C Appendix: An exposition of Coppersmith’s algorithm

In 1982, Don Coppersmith proved that the rank (that is, the number of essential multiplications) of N×N0.1N\times N^{0.1} and N0.1×NN^{0.1}\times N matrix multiplication is at most O(Nlog⁡2N)O(N\log^{2}N). Prior work has observed that his algorithm can also be used to show that the total number of arithmetic operations for the same matrix multiply is N⋅poly(log⁡N)N\cdot{\text{poly}}(\log N). However, the implication is not immediate, and uses specific properties of Coppersmith’s algorithm. Because this result is so essential to this work and another recent circuit lower bound [Wil13], we give a self-contained exposition here.

For all sufficiently large NN, the rank of N×N.1××NN\times N^{.1}\times\times N matrix multiplication is at most O(N2log⁡2N)O(N^{2}\log^{2}N).

We wish to derive the following consequence of Coppersmith’s construction, which has been mentioned in the literature before [SM83, ACPS09, Wil11]:

For all sufficiently large NN, and α≤.172\alpha\leq.172, multiplication of an N×NαN\times N^{\alpha} matrix with an Nα×NN^{\alpha}\times N matrix can be done in N2⋅poly(log⁡N)N^{2}\cdot{\text{poly}}(\log N) arithmetic operations, over any field with O(2poly(log⁡N))O(2^{{\text{poly}}(\log N)}) elements.

Note Lemma C.1 has been “improved” in the sense that the upper bound on α\alpha has been increased mildly over the years [Cop97, HP98, KZHP08, Gal12]. However, these later developments only run in N2+o(1)N^{2+o(1)} time, not N2⋅poly(log⁡N)N^{2}\cdot{\text{poly}}(\log N) time (which we require). Our exposition will expand on the informal description given in recent work [Wil11].

First, observe that the implication from Theorem C.1 to Lemma C.1 is not immediate. For example, it could be that Coppersmith’s algorithm is non-uniform, making it difficult to apply. As far as we know, one cannot simply take “constant size” arithmetic circuits implementing the algorithm of Theorem C.1 and recursively apply them. In that case, the poly(log⁡N){\text{poly}}(\log N) factor in the running time would then become NεN^{{\varepsilon}} for some constant ε>0{\varepsilon}>0 (depending on the size of the constant-size circuit). To keep the overhead polylogarithmic, we have to unpack the algorithm and analyze it directly.

Coppersmith’s algorithm builds on many other tools from prior matrix multiplication algorithms, many of which can be found in the highly readable book of Pan [Pan84]. Here we will give a very brief tutorial of some of the aspects.

Essentially all methods for matrix multiplication are bilinear (and if not, they can be converted into such algorithms), meaning that they can be expressed in the so-called trilinear form

where αij\alpha_{ij}, βij\beta_{ij}, and γij\gamma_{ij} are constant-degree polynomials in xx over the field, and p(x)p(x) is a polynomial with constant coefficient . Such an algorithm can be converted into one with no polynomials and minimal extra overhead (as described in Coppersmith’s paper). Typically one thinks of AikA_{ik} and BkjB_{kj} as entries in the input matrices, and CjiC_{ji} as indeterminates, so the LHS of (4) corresponds to a polynomial whose CjiC_{ji} coefficient is the ijij entry of the matrix product. Note the transpose of the third matrix CC corresponds to the final matrix product.

To give an explicit example, we assume the reader is familiar with Strassen’s famous method for 2×2×22\times 2\times 2 matrix multiply. Strassen’s algorithm can be expressed in the form of (4) as follows:

The LHS of (4) and (C.1) represents the trace of the product of three matrices AA, BB, and CC (where the ijij entry of matrix XX is XijX_{ij}). It is well known that every bilinear algorithm naturally expresses multiple algorithms through this trace representation. Since

if we think of AA as a symbolic matrix and consider (4), we obtain a new algorithm for computing a matrix AA when given BB and CC. Similarly, we get an algorithm for computing a BB when given AA and CC, and analogous statements hold for computing ATA^{T}, BTB^{T}, and CTC^{T}. So the aforementioned algorithm for multiplying a sparse 2×32\times 3 and sparse 3×23\times 2 yields several other algorithms.

Schönhage’s decomposition paradigm.

Coppersmith’s algorithm follows a specific paradigm introduced by Schönhage [Sch81] which reduces arbitrary matrix products to slightly larger matrix products with “structured nonzeroes.” The general paradigm has the following form. Suppose we wish to multiply two matrices A′′A^{\prime\prime} and B′′B^{\prime\prime}.

First we preprocess A′′A^{\prime\prime} and B′′B^{\prime\prime} in some efficient way, decomposing A′′A^{\prime\prime} and B′′B^{\prime\prime} into structured matrices A,A′,B,B′A,A^{\prime},B,B^{\prime} so that A′′⋅B′′=A′⋅A⋅B⋅B′A^{\prime\prime}\cdot B^{\prime\prime}=A^{\prime}\cdot A\cdot B\cdot B^{\prime}. (Note, the dimensions of A′⋅AA^{\prime}\cdot A may differ from A′′A^{\prime\prime}, and similarly for B′⋅BB^{\prime}\cdot B and B′′B^{\prime\prime}.) The matrices AA and BB are sparse “partial” matrices directly based on A′′A^{\prime\prime} and B′′B^{\prime\prime}, but they have larger dimensions, and only contain nonzeroes in certain structured parts. The matrices A′A^{\prime} and B′B^{\prime} are very simple and explicit matrices of scalar constants, chosen independently of A′′A^{\prime\prime} and B′′B^{\prime\prime}. (In particular, A′A^{\prime} and B′B^{\prime} are Vandermonde-style matrices.)

Next, we apply a specialized constant-sized matrix multiplication algorithm in a recursive manner, to multiply the structured AA and BB essentially optimally. Recall that Strassen’s famous matrix multiplication algorithm has an analogous form: it starts with a seven-multiplication product for 2×2×22\times 2\times 2 matrix multiplication, and recursively applies this to obtain a general algorithm for 2M×2M×2M2^{M}\times 2^{M}\times 2^{M} matrix multiplication. Here, we will use an optimal algorithm for multiplying constant-sized matrices with zeroes in some of the entries; when this algorithm is recursively applied, it can multiply sparse AA and BB with nonzeroes in certain structured locations.

Finally, we postprocess the resulting product CC to obtain our desired product A′′⋅B′′A^{\prime\prime}\cdot B^{\prime\prime}, by computing A′⋅C⋅B′A^{\prime}\cdot C\cdot B^{\prime}. Using the simple structure of A′A^{\prime} and B′B^{\prime}, the matrix products D:=A′⋅CD:=A^{\prime}\cdot C and D⋅B′D\cdot B^{\prime} can be performed very efficiently. Our aim is to verify that each step of this process can be efficiently computed, for Coppersmith’s full matrix multiplication algorithm.

C.2 The algorithm

The construction of Coppersmith begins by taking input matrices A′′A^{\prime\prime} of dimensions 24M/5×(M4M/5)24M/52^{4M/5}\times{M\choose 4M/5}2^{4M/5} and B′′B^{\prime\prime} of dimensions (M4M/5)24M/5×2M/5{M\choose 4M/5}2^{4M/5}\times 2^{M/5} where M≈log⁡NM\approx\log N, and obtains an O(5Mpoly(M))O(5^{M}{\text{poly}}(M)) algorithm for their multiplication. Later, he symmetrizes the construction to get an N×N×NαN\times N\times N^{\alpha} matrix multiply. We will give this starting construction and show how standard techniques can be used to obtain an N×Nα×NN\times N^{\alpha}\times N matrix multiply from his basic construction.

The multiplication of A′′A^{\prime\prime} and B′′B^{\prime\prime} will be derived from an algorithm which computes the product of 2×32\times 3 and 3×23\times 2 matrices with zeroes in some entries. In particular the matrices have the form:

and the algorithm is given by the trilinear form

When the algorithm given by (6) is applied recursively to 2M×3M2^{M}\times 3^{M} and 3M×2M3^{M}\times 2^{M} matrices (analogously to how Strassen’s algorithm is applied to do 2M×2M×2M2^{M}\times 2^{M}\times 2^{M} matrix multiply), we obtain an algorithm that can multiply matrices AA and BB with dimensions 2M×3M2^{M}\times 3^{M} and 3M×2M3^{M}\times 2^{M}, respectively, where AA has O(5M)O(5^{M}) nonzeroes, BB has O(4M)O(4^{M}) nonzeroes, and these nonzeroes appear in a highly regular pattern (which can be easily deduced). This recursive application of (6) will result in polynomials in xx of degree O(M)O(M), and additions and multiplications on such polynomials increase the overall time by an M⋅poly(log⁡M)M\cdot{\text{poly}}(\log M) factor. Therefore we can multiply these AA and BB with structured nonzeroes in O(5M⋅poly(M))O(5^{M}\cdot{\text{poly}}(M)) field operations.

The decomposition of A′′A^{\prime\prime} and B′′B^{\prime\prime} is performed as follows. We choose A′A^{\prime} and B′B^{\prime} to have dimensions 24M/5×2M2^{4M/5}\times 2^{M} and 2M×2M/52^{M}\times 2^{M/5}, respectively, and such that all 24M/5×24M/52^{4M/5}\times 2^{4M/5} submatrices of A′A^{\prime} and 2M/5×2M/52^{M/5}\times 2^{M/5} submatrices of B′B^{\prime} are non-singular. Following Schönhage, we pick A′A^{\prime} and B′B^{\prime} to be rectangular Vandermonde matrices: the i,ji,j entry of A′A^{\prime} is (αj)i−1(\alpha_{j})^{i-1}, where α1,α2,…\alpha_{1},\alpha_{2},\ldots are distinct elements of the field; B′B^{\prime} is defined analogously. Such matrices have three major advantages: (1) they can be succinctly described (with O(2M)O(2^{M}) field elements), (2) multiplying these matrices with arbitrary vectors can be done extremely efficiently, and (3) inverting an arbitrary square submatrix can be done extremely efficiently. More precisely, n×nn\times n Vandermonde matrices can be multiplied with arbitrary nn-vectors in O(n⋅poly(log⁡n))O(n\cdot{\text{poly}}(\log n)) operations, and computing the inverse of an n×nn\times n Vandermonde matrix can be done in O(n⋅poly(log⁡n))O(n\cdot{\text{poly}}(\log n)) operations (for references, see [CKY89, BP94]). In general, operations on Vandermonde matrices, their transposes, their inverses, and the transposes of inverses can be reduced to fast multipoint computations on univariate polynomials. For example, multiplying an n×nn\times n Vandermonde matrix with a vector is equivalent to evaluating a polynomial (with coefficients given by the vector) on the nn elements that comprise the Vandermonde matrix, which takes O(nlog⁡n)O(n\log n) operations. This translates to O(n⋅poly(log⁡n))O(n\cdot{\text{poly}}(\log n)) arithmetic operations.

The matrices AA and BB have dimensions 2M×3M2^{M}\times 3^{M} and 3M×2M3^{M}\times 2^{M}, respectively, where AA has only O(5M)O(5^{M}) nonzeroes, BB has only O(4M)O(4^{M}) nonzeroes, and there is an optimal algorithm for multiplying 2×32\times 3 (with 5 nonzeroes) and 3×23\times 2 matrices (with 4 nonzeroes) that can be recursively applied to multiply AA and BB optimally, in O(5M⋅poly(M))O(5^{M}\cdot{\text{poly}}(M)) operations. Matrices AA and BB are constructed as follows: take any one-to-one mapping between the (M4M/5)2M/5{M\choose 4M/5}2^{M/5} columns of the input A′′A^{\prime\prime} and columns of the sparse AA with exactly 24M/52^{4M/5} nonzeroes. For these columns qq of AA with 24M/52^{4M/5} nonzeroes, we compute the inverse Aq−1A_{q}^{-1} of the 24M/5×24M/52^{4M/5}\times 2^{4M/5} minor AqA_{q} of A′A^{\prime} with rows corresponding to the nonzeroes in the column, and multiply Aq−1A_{q}^{-1} with column qq (in 24M/5⋅poly(M)2^{4M/5}\cdot{\text{poly}}(M) time). After these columns are processed, the rest of AA is zeroed out. Then, there is a one-to-one correspondence between columns of A′′A^{\prime\prime} and nonzero columns of A′⋅AA^{\prime}\cdot A. Performing a symmetric procedure for B′′B^{\prime\prime} (with the same mapping on rows instead of columns), we can decompose it into BB and B′B^{\prime} such that there is a one-to-one correspondence between rows of B′′B^{\prime\prime} and nonzero rows of B⋅B′B\cdot B^{\prime}. It follows that this decomposition takes only O((M4M/5)24M/5⋅24M/5⋅poly(M))O({M\choose 4M/5}2^{4M/5}\cdot 2^{4M/5}\cdot{\text{poly}}(M)) time. Since 5M≈(M4M/5)44M/55^{M}\approx{M\choose 4M/5}4^{4M/5} (within poly(M){\text{poly}}(M) factors), this quantity is upper bounded by 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M).

After AA and BB are constructed, the constant-sized algorithm for 2×32\times 3 and 3×23\times 2 mentioned above can be applied in the usual recursive way to multiply the sparse AA and BB in O(5M⋅poly(M))O(5^{M}\cdot{\text{poly}}(M)) operations; call this matrix ZZ. Because A′A^{\prime} and B′B^{\prime} are Vandermonde, the product A′⋅Z⋅B′A^{\prime}\cdot Z\cdot B^{\prime} can be computed in O(5M⋅poly(M))O(5^{M}\cdot{\text{poly}}(M)) operations. Hence we have an algorithm for multiplying matrices of dimensions 24M/5×(M4M/5)24M/52^{4M/5}\times{M\choose 4M/5}2^{4M/5} and (M4M/5)24M/5×2M/5{M\choose 4M/5}2^{4M/5}\times 2^{M/5} that is explicit and takes 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M) operations.

Call the above algorithm Algorithm 1. Observe Algorithm 1 also works when the entries of A′′A^{\prime\prime} and B′′B^{\prime\prime} are themselves matrices over the field. (The running time will surely increase in proportion to the sizes of the underlying matrices, but the bound on the number of operations on the entries remains the same.)

Up to this point, we have simulated Coppersmith’s construction completely, and have simply highlighted its efficiency. By exploiting the symmetries of matrix multiplication algorithms in a standard way, we can extract more algorithms from the construction. The trace identity tells us that

implying that the expression (6) can also be used to partially multiply a 3M×2M3^{M}\times 2^{M} matrix BB with at most 4M4^{M} structured nonzeroes and “full” 2M×2M2^{M}\times 2^{M} matrix CC in 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M) operations, obtaining a 3M×2M3^{M}\times 2^{M} matrix ATA^{T} with at most 5M5^{M} nonzeroes. In our Algorithm 1, we have a decomposition of AA and BB; in terms of the trace, we can derive:

This can be applied to obtain an algorithm for (M4M/5)24M/5×2M/5×24M/5{M\choose 4M/5}2^{4M/5}\times 2^{M/5}\times 2^{4M/5} matrix multiplication, as follows. Given input matrices B′′B^{\prime\prime} and C′′C^{\prime\prime} of the respective dimensions, we decompose B′′B^{\prime\prime} into a 3M×2M3^{M}\times 2^{M} BB with O(4M)O(4^{M}) nonzeroes and 2M×2M/52^{M}\times 2^{M/5} Vandermonde B′B^{\prime}, as described above. Letting A′A^{\prime} be a Vandermonde 24M/5×2M2^{4M/5}\times 2^{M} matrix, we compute the matrix C:=B′⋅C′′⋅A′C:=B^{\prime}\cdot C^{\prime\prime}\cdot A^{\prime} in at most 4M⋅poly(M)4^{M}\cdot{\text{poly}}(M) operations. Noting that CC is 2M×2M2^{M}\times 2^{M}, we can then multiply BB and CC in 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M) operations. This results in a 3M×2M3^{M}\times 2^{M} matrix ATA^{T} with at most 5M5^{M} nonzeroes. The final output A′′A^{\prime\prime} is obtained by using the one-to-one mapping to extract the appropriate (M4M/5)24M/5{M\choose 4M/5}2^{4M/5} rows from ATA^{T}, and multiplying each such row by the appropriate inverse minor of A′A^{\prime} (corresponding to the nonzeroes of that row). This takes at most (M4M/5)24M/5⋅2M⋅poly(M)≤5M⋅poly(M){M\choose 4M/5}2^{4M/5}\cdot 2^{M}\cdot{\text{poly}}(M)\leq 5^{M}\cdot{\text{poly}}(M) operations. Call this Algorithm 2.

From Algorithm 2 we immediately obtain an algorithm for 24M/5×2M/5×(M4M/5)24M/52^{4M/5}\times 2^{M/5}\times{M\choose 4M/5}2^{4M/5} matrix multiplication as well: given input matrices (C′′)T(C^{\prime\prime})^{T} and (B′′)T(B^{\prime\prime})^{T} of te respective dimensions, simply compute B′′⋅C′′B^{\prime\prime}\cdot C^{\prime\prime} using Algorithm 2, and output the transpose of the answer. Call this Algorithm 3.

Finally, by “tensoring” Algorithm 2 with Algorithm 3, we derive an algorithm for matrix multiplication with dimensions

That is, we divide the two input matrices of large dimensions into blocks of 24M/5×2M/52^{4M/5}\times 2^{M/5} and 2M/5×(M4M/5)24M/52^{M/5}\times{M\choose 4M/5}2^{4M/5} dimensions, respectively. We execute Algorithm 2 on the blocks, and call Algorithm 3 when the product of two blocks is needed.

As both Algorithm 2 and Algorithm 3 are explicit and efficient, their “tensorization” inherits these properties. Algorithm 2 uses 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M) operations, and each operation can take up to 5M⋅poly(M)5^{M}\cdot{\text{poly}}(M) time (due to calls to Algorithm 3). Therefore, we can perform a 5M×42M/5×5M5^{M}\times 4^{2M/5}\times 5^{M} matrix multiply over fields with 2poly(M)2^{{\text{poly}}(M)} elements, in 52M⋅poly(M)5^{2M}\cdot{\text{poly}}(M) time. Setting n=log⁡(M)/log⁡(5)n=\log(M)/\log(5), the algorithm runs in n2⋅poly(log⁡n)n^{2}\cdot{\text{poly}}(\log n) time for fields with 2poly(log⁡n)2^{{\text{poly}}(\log n)} elements.