{
  "margin_table": "| R | best VERIFIED full-collision rate (pair; trials) | best VERIFIED bias / distinguisher (statistic; z; trials) | method, status |\n|---|---|---|---|\n| 0 | 1, exactly, for every key: any difference confined to packet lanes 2,3 (bytes 16..31 of any block); 2^20/2^20 (32 B, 64 B), 65536/65536 for all 256 one-byte messages; z3 UNSAT with symbolic key+packet (exact and uninterpreted-multiplier models). Lane-1 near-certain pairs: byte 14 +1 / byte 8 -1 collides at (255/256)^4 = 0.9844 (measured 0.984445, 2^26); lane-1 bytes 10,11,13 +1 at (255/256)^3 = 0.98834 (measured 0.988336, 2^26). | output identical (bias undefined) | lane locality; PROVEN (Lemma 2 refereed + z3) |\n| 1 | 0.996 = 2^-0.006: lane 3 byte 0 +-1 / ^1 (m=b4a9f0039dfdf1097584bf1b16743255b343b39646ca5b5d8d52227d6c9bd270, m2=...8c52227d6c9bd270): 4277934604/2^32 (bias-R2), 267370397/2^28, 16710137/2^24; reproduced 16710592, 16710519, 16710506, 16710795, 16710399 per 2^24 (five independent codes). PROVEN >= 1-9*2^-8 = 0.9648 for every 32-byte m (Theorem 1); lane 2 += 2^32: 0.988 (proven >= 0.9727); lane 2 += 2^56: 0.992 (proven >= 0.9883). Sum-cancellation lane 3 += 0xFF00 (m1 = 0^25 01 0^6, m2 = 0^26 01 0^5): (255/256)^6 = 0.97679, measured 0.97678 (2^26), reproduced 0.976841/0.976755/0.976825/0.976751 (2^24); same at 31, 63, 64 B. q-cancellation (m1 byte 19 = 01, m2 byte 8 = 01): 2^-17.25 (108/2^24; reproduced 102, 97 per 2^24), single halves 0. Remainder path 48 B: 2^-9.86 (single lens). | saturated: every output bit of the 0.996 pair has z = -sqrt(N); R=1 output ignores v1[2],v1[3],mul0[2..3],mul1[2..3] (z3, all states; confirmed 0/2^18) | analytic + SMT + sampling; PROVEN bounds (Theorems 1,2 refereed) |\n| 2 | 2^-19.7 unconditional: lane 3 byte 0 +-1 / ^1 / ^3: 4998/2^32 (bias-R1, seed 2) and 5004/2^32 (bias-R2, seed 11; m=4bf545df50d991ba258f7195dc5b0d737b21e41a7b558d14f2539cf7a0733d13, m2=...f1539cf7a0733d13); 313/2^28, 298/2^28, 100/2^26, 89/2^26 (random base), 82/2^26 (29 B), 26/2^24 (63 B), 18/2^24 (61 B); reproduced 338/2^28, 331/2^28, 76/2^26, 86/2^26, 70/2^26, 17..25 per 2^24 in 12 independent runs (range 2^-19.4..2^-20.1). Conditional: hi32(key[3]) = 0x243f6a88 (density 2^-32): 2^-9.86 (289289/2^28; reproduced 18268/2^24); plus hi32(v0[1]) = 0 after the packet (density 2^-64): 0.9804 (16448663/2^24; reproduced 16447944/2^24), which contributes only 2^-64*0.98 unconditionally. | bit 63 of H(m)^H(m') set for 2^-12.2 of keys (z = -65509 = -sqrt(N) at 2^32; 39 of 64 bits |z| >= 6; reproduced z = -4094.3 at 2^24 everywhere); low-32-bit collisions 2^-10.05, low-16 2^-9.44; output bit 63 affine in lane-3 bits {0,1} for 99.98% of keys (2^24). w3^2^31 on base b4a9...d270: bit-63 eps = -2^-6.1 (z = -1884.5 at 2^32 and -1333 at 2^31, two lenses). | hill-climb, multi-key SMT, analytic (unique surviving pattern), weak-key sampling; MEASURED, mechanism identified, no proof of the rate |\n| 3 | none: 0 collisions in 2^34.5 keys for the byte-29 family and 2^33.5 for the byte-24 family (< 2^-33 at 95%); 0 in 2^28 (density 2^-32 class), 2^24 (2^-96 class). Partial: top-8 output bits agree at 2^-6.64 (2688110/2^28, ideal 2^-8, 2.57x; reproduced 168226/2^24 and 167666/2^24 at 64 B), top-16 at 2^-14.62 (2.6x), |H(m')-H(m)| < 2^48 at 2.61x (341895 vs 131072 at 2^32); scale-free 2.5-2.8x excess consistent with ~2.6 x 2^-64 full collisions (unmeasurable). | lane 3 byte 5 +-1 (message byte 29; m=5f72b7f79be87f36370ba115cf30f4ed47788868fb06fd6b4b7233a5ae16d392, m2=...ae17d392; also 6bfe...bbfc5821/bbfd5821 and the zero base with byte 29 = 01): P[bit 63 of H^H' set] = 0.421..0.424, z = -9927 (bias-R4), -10040 (bias-R1), -10345 (bias-R2) at 2^32, -5617 at 2^30.24, -2498/-2585/-2480 at 2^28; z63 = -0.15 sqrt(N); bits 57..62 halving; reproduced z = -646.6, -646.5, -627.0, -620.1, -631.6, -617.1 (2^24), -1248.3, -1238.6 (2^26). Mask A62^A63 of H(m')-H(m) even for 0.607 of keys (z = +7620 at 2^30.24; reproduced 0.60705, +877 at 2^24). 2-cube {lane-3 bit 0, bit 40}: XOR of four outputs has bit 63 = 0 for 0.685 of keys (z = 3029 at 2^26; reproduced 1513.7 at 2^24, 3026.8 at 2^26). Fixed key: 64/64 keys give z63 in [-166,-151] at 2^20 pairs (~2^11 pairs per key suffice). Weak-key: hi32(key[3]) = 0x243f6a88 (2^-32): P[differ] = 0.434 (z = -2169 at 2^28; reproduced -542 at 2^24); with two round-1 conditions (2^-96): 0.016 (z = -2805 at 2^23; reproduced -3967 at 2^24). Residual of the R=2 family: eps = -2^-13.6..-2^-14.0 on bit 63 (z = -10.5 at 2^32; reproduced -7.75, pooled -8.95 over 2^32.33); amplified to eps = 0.067 on the class hi32(key[3])^0x243f6a88 < 2^16 (density 2^-16; refuter's computation, z = -1100 over 2^26 pairs). | single-bit sweep + bias counters + additive-magnitude and mask statistics + cube derivative + weak-key sampling; MEASURED, no proof, no collision |\n| 4 | none: 0 in 2^34.5 keys (byte-29 family, < 2^-33) and 2^33.5 (byte-24 family); 0 in 6 x 2^26 + 2^25 + 2 x 2^24 hill-climb winners, 2 x 2^30 on the top two; 0 in 2^28 (2^-32 class), 2^24/2^23 (2^-64/2^-96 classes); every lo-k/hi-k (k = 4..32) and |A| < 2^k (k = 32..60) count at ideal (e.g. |A| < 2^48: 131285 vs 131072 at 2^32; hi-16 4131 vs 4096 at 2^28). | none: per-bit |z| <= 3.0 at 2^32 for the byte-29, byte-24, 64 B pairs (eps < 2^-14.4); 3.7 max over 1280 bit tests at 2^29 (P[null max >= 3.7] = 0.24); all 65535 top-16 masks of X and A |z| <= 4.8 vs null max 4.9 (eps < 2^-13.5); joint (top byte, top byte) and (low byte, low byte) independence |z| < 1.4; byte chi-square |z| <= 3.5; kdb per-key mean z^2 in [0.55, 1.62] (null 1 +- 0.18); cube restricted degree >= d-1 to d = 26, monomial density |z| <= 3; weak-key classes to 2^-96: max |z| 2.6; random control indistinguishable from every structured pair. | all six methods null; OPEN (neither broken nor proven) |",
  "strongest_verified_effects": [
    "R=0, rate 1 for every key: any difference confined to packet lanes 2,3 (bytes 16..31 of any block, e.g. m=b4a9...8d52227d6c9bd270 vs ...8c52227d6c9bd270); z3 UNSAT with symbolic key and packet; 2^20/2^20 and 65536/65536 measured; refereed as Lemma 2 (lane locality: H_0 depends only on k0, k1, |M| and message bytes 32q+j, j<16).",
    "R=1, lane 3 byte 0 +-1 (m=b4a9f0039dfdf1097584bf1b16743255b343b39646ca5b5d8d52227d6c9bd270, m2=...8c52227d6c9bd270): full collision for 0.996 of keys (4277934604/2^32; 267370397/2^28; five independent 2^24 reproductions at 16710399..16710795); PROVEN >= 1-9*2^-8 for every 32-byte message (Theorem 1). Companion proven classes: lane 2 += 2^32 (0.988, >= 0.9727) and lane 2 += 2^56 (0.992, >= 0.9883).",
    "R=1, sum cancellation lane 3 += 0xFF00 (m1 = 0^25 01 0^6, m2 = 0^26 01 0^5, and the same bytes 57/58 of a 64 B message): collision rate (255/256)^6 = 0.9768, measured 0.97678 (2^26) and reproduced 0.976841, 0.976755, 0.976825, 0.976751 (2^24); all collisions are v0[0] +2^32 against v1[0] -2^32 with both mul words equal; the six failure residuals are single byte carries at 2^26/256 each.",
    "R=1, q-cancellation (m1 byte 19 = 01, m2 byte 8 = 01, i.e. lane 1 byte 0 +1 with lane 2 byte 3 -1): 108/2^24 = 2^-17.25 (reproduced 102 and 97 per 2^24) while each single half gives 0/2^24: a difference in v1[0] cancelled by -swap32 of a difference in v0[2] before any multiply; variant (bytes 17/9): 254/2^24 = 2^-16.0 (reproduced 250).",
    "R=2, lane 3 byte 0 +-1 / ^1 / ^3: full collisions at 2^-19.7 (4998/2^32 and 5004/2^32 in two lenses; 298, 313, 338, 331 per 2^28; 12 independent reproductions at 2^24..2^28 in the range 2^-19.4..2^-20.1), length-independent (29, 32, 61, 63 B and the second packet of 64 B); bit 63 of H^H' set for only 2^-12.2 of keys (z = -sqrt(N)), 39 of 64 bits |z| >= 6, low-32 collisions 2^-10.05. Analytic: the unique last-packet pattern surviving the R=2 necessary conditions; delta = +-1 is the maximum of the channel (100, 52, 28, 27, 9, 4, 0, 0 collisions per 2^26 for delta = 1, 2, 3, 4, 8, 16, 128, 255).",
    "R=2 conditional ladder for the same pair: hi32(key[3]) = 0x243f6a88 (density 2^-32) -> 2^-9.86 (289289/2^28; reproduced 2^-9.84); plus hi32(v0[1]) = 0 after the packet (density 2^-64) -> 0.9804 (16448663/2^24; reproduced 16447944/2^24). The class contributes 2^-64 * 0.98, so the unconditional 2^-19.7 is a byte-carry/confinement event, not a zero-co-operand event.",
    "R=3, lane 3 byte 5 +-1 (message byte 29; m=5f72b7f79be87f36370ba115cf30f4ed47788868fb06fd6b4b7233a5ae16d392, m2=...ae17d392; also 6bfe...bbfc5821/bbfd5821; also the zero base with byte 29 = 01; also byte 61 of a 64 B message): P[bit 63 of H^H' set] = 0.421..0.424 (z = -9927, -10040, -10345 at 2^32; eight independent reproductions), bits 57..62 biased with halving per bit; A62^A63 of H(m')-H(m) even for 0.607 of keys (z = +7620 at 2^30.24, reproduced); top-8 bits agree at 2^-6.64 (2.57x ideal), top-16 at 2^-14.62, |H(m')-H(m)| < 2^k at 2.5..2.8x ideal for k = 32..56 (reproduced); same sign for all 64 of 64 keys tested (fixed-key chosen-message distinguisher at ~2^11 pairs); the effect is monotone in |delta| (null beyond |delta| >= 64) and any second differing bit anywhere in the packet kills it (221 two-bit patterns at 2^20: |z| <= 3.5).",
    "R=3, chosen-message second derivative: 2-cube {lane-3 bit 0, lane-3 bit 40} on the zero base (bytes 24, 29 in {00,01}^2): XOR of the four R=3 outputs has bit 63 = 0 for 0.685 of keys (z = 3029 at 2^26 random bases; reproduced 1513.7 at 2^24 and 3026.8 at 2^26), more than double the first-derivative bias; 21 bits |z| >= 6.",
    "R=3 weak-key amplification of lane 3 +1 (m=b4a9f0039dfdf1097584bf1b16743255b343b39646ca5b5d8d52227d6c9bd270, m2=...8e52227d6c9bd270): under hi32(key[3]) = 0x243f6a88 (density 2^-32) P[bit 63 differs] = 0.434 (z = -2169 at 2^28; reproduced -542 at 2^24); under that plus hi32(v0[1]) = 0 and lo32(v0[2]+mul1[2]) = 0 after the packet (density 2^-96) P = 0.016 (z = -2805 at 2^23; reproduced -3967 at 2^24 with exact uniform sampling); 0 R=3 collisions in 2^28 and 2^24 conditional keys; R=4 in the same classes: max |z| 2.6.",
    "R=3 residual of the R=2 collision family (lane 3 bits 0,1; m=4bf5...f2539cf7a0733d13 / ...f1539cf7a0733d13): bit-63 eps = -2^-13.6..-2^-14.0 (z = -10.5 at 2^32; reproduced z = -7.75 at 2^32, pooled -8.95 over 2^32.33), invisible at 2^28; per key the bias exists with sign determined by hi32(v0[3]) (kdb mean z^2 = 3.42 vs null 1 +- 0.18), and on the class hi32(key[3])^0x243f6a88 < 2^16 (density 2^-16) it is eps = 0.067 (refuter: z = -1100 over 2^26 pairs).",
    "R=4 null, verified at scale: for the byte-29 pair 2^32 keys give 0 collisions, per-bit |z| <= 2.8/2.7 (eps < 2^-14.4), all 65535 top-16 masks |z| <= 4.63/4.50 (null max ~4.9), joint byte independence z +0.39/+0.28, |A| < 2^48 at 1.00x; identical null for the byte-24 pair (2^32, 2^31), the 64 B byte-61 pair (2^31), the complements and additive pairs (2^29..2^32), four hill-climb winners (2^30), cube degree profiles to d = 26, and the weak-key classes to density 2^-96.",
    "Known-key internal collision (referee's counterexample to Lemma 1): for EVERY key there is an explicit 96-byte pair (or 72 B with tail) differing in lane 0 of three consecutive packets whose 1024-bit states coincide after absorption, hence colliding in HighwayHash64/128/256 at every R (65536/65536 keys; e.g. kTestKey1: M=fea24c741343cab5...d0d162 vs M'=fea24d751343cab5...d0d162, both hash to 80a08f489ebe8a20). Not an attack in the random-key model (each such pair collides for 0/65536 fresh keys), but a computed fact that constrains how the paper states 'collisions are truncation collisions'."
  ],
  "proven_statements": [
    "[R=0, refereed CONFIRMED] Lane locality (proof-trails Lemma 2): lanes {0,1} after Update depend only on lanes {0,1} before it and packet lanes 0,1; Reset and the remainder step are lane-wise; H_0(k,M) is a function of k0, k1, |M| and the message bytes at positions 32q+j, 0 <= j < 16 only (tail: j < min(16, s&~3)). Hence any two same-length messages agreeing on those bytes collide at R=0 for every key: differences confined to lanes 2,3 of any packets, all 256 one-byte messages, the last s mod 4 bytes for 1 <= s <= 15. Referee sharpening of (iv): with the difference confined to lane-1 bytes 2,3,5 plus lanes 2,3, the lane-0 state is equal iff the carries into bit 32 and bit 48 at step A and into bit 32 at step E agree in both executions (0 violations in 8 x 2^17 keys); the same fact is z3 UNSAT with symbolic key and packet in both the exact and the uninterpreted-multiplier model.",
    "[R=1, refereed CONFIRMED, scope corrected] Closed form of the lane-0 output for messages of exactly 32 bytes (proof-attempt Lemma 1): with A_i, B_i, M0_i, M1_i, X0, X1, Z2, Z3, Y0, Y1, U0, W0, T, U1, W1, a, b, v as in the lemma and f0(x,y) = [x.b3, y.b4, x.b2, x.b5, y.b6, x.b1, y.b7, x.b0], f1(x,y) = [y.b3, x.b4, y.b2, y.b5, y.b1, x.b6, y.b0, x.b7], H_1(m) = a + v + [M0_0 ^ (lo32 U0 * hi32 X0)] + [M1_0 ^ (lo32 W0 * hi32 U0)]; the R=1 output ignores v1[2], v1[3], mul0[2..3], mul1[2..3], and lanes 2,3 enter only through Z2 = v0[2] (both lane-0 multiplies) and Z3 = v0[3] (byte shuffles and additions only). Verified 0 mismatches on 2^20 random + 580,608 structured cases; for lengths 1..31 the remainder-aware form (rot32_s on v1's halves, v0 += (s<<32)+s) is required and was verified for every s. Consistent with smt-R4's lastround_dep (z3 UNSAT over all 2^1024 states: one round + lane-0 sum ignores v1[2], v1[3], mul0[2], mul0[3], mul1[2], mul1[3]).",
    "[R=1, refereed CONFIRMED] Zero-multiply sector (proof-attempt Lemma 2): a difference confined to A3 bytes {0,1,2,3,5} or A2 bytes {4,6,7} changes Z3 but not Z2; then U0, X0, W0 and both lane-0 multiply terms are unchanged and H_1' - H_1 = (a'-a) + (v'-v) is a function of (A2, A3, B3, T, U0, W0, W1) and (A2', A3') only; freeing those seven words is a sound relaxation, so z3-UNSAT statements on it hold for every key and every 32-byte message (checked: Z2 changed 0 times and the formula held in 100% of 2^25.5 confined trials).",
    "[R=1, refereed CONFIRMED] Slice lemma: if for every fixing of the remaining key coordinates a byte quantity Q = phi(kappa) + e(kappa) mod 256 with phi a bijection of one key byte and e in {0..r}, then Pr[Q = v] <= (r+1)/256, exactly 1/256 when r = 0; all 16 applications used in Theorems 1 and 2 satisfy the hypothesis with the stated or smaller r (2^25 evaluations per application, 0 violations); the joint bound 9*2^-16 can be tightened to 3*2^-16.",
    "[R=1, refereed CONFIRMED] Theorem 1 (certain collisions): for every 32-byte m, Pr[H_1(m+e_3) = H_1(m)] >= 1-9*2^-8 = 0.9648; Pr[H_1(m+2^32 e_2) = H_1(m)] >= 1-7*2^-8 = 0.9727; Pr[H_1(m+2^56 e_2) = H_1(m)] >= 1-3*2^-8 = 0.9883 (the original decimals 0.965/0.973 were rounded up; measured 0.996, 0.988, 0.992 over 1450 messages; cond && !collision occurred 0 times in 34,226,176 samples per pair).",
    "[R=1, refereed CONFIRMED] Theorem 2 (upper bounds, zero active multiplies): for every 32-byte m, Pr[H_1(m+2^8 e_3) = H_1(m)] <= 2^-22; Pr[H_1(m+2^16 e_3) = H_1(m)] <= 2^-8; Pr[H_1(m+2^24 e_3) = H_1(m)] <= 3*2^-8; Pr[H_1(m+2^40 e_3) = H_1(m)] <= 2^-8 + 9*2^-16 (tightenable to 3*2^-16); Pr[H_1(m+2^48 e_2) = H_1(m)] <= 3*2^-8; measured 0, 0, 0, 0 in 2^26.3 keys and 2^-22.9 for the last class (which really collides: delta_b = 0xffff0001 skips byte 4).",
    "[any R, refereed CONFIRMED parts of Lemma 3] One-step separation: (a) after v1[i] += delta the low half differs iff lo32(delta) != 0, the high half iff hi32(delta) + carry != 0 mod 2^32; (b) since 32x32->64 products are exact integers, a'H - aH = (a'-a)H vanishes iff H = 0, so mul0[i] changes iff lo32(delta) != 0 and hi32(v0[i]) != 0, and mul1[i] changes iff the high half of v1[i] changes and lo32(v0[i] + mul1[i]) != 0; (c) for one-packet messages and a uniform key the co-operands H and L are independent uniform, P[H=0] = P[L=0] = 2^-32, P[H=L=0] = 2^-64, and for |M| = 32 P[carry] = lo32(delta)/2^32 exactly. The exact silencing subspaces hi32(key[i]) = hi32(init0[i]) and lo32(key[i]) = lo32(init0[i]) ^ (-lo32(init1[i])) hold ONLY for |M| = 32 (referee correction; on the remainder path the subspaces are hi32(v0[i]) = 0 resp. lo32(v0[i]) + lo32(init1[i]) = 0 with v0[i] = (init0[i]^key[i]) + (s<<32) + s).",
    "[any R, refereed CONFIRMED parts of Lemma 4] Silenced trails with the corrected k'_msg(delta) = #{i: lo32(delta_i) != 0} + #{i: hi32(delta_i) not in {0, 2^32-1}} + #{i: lo32(delta_i) = 0 and hi32(delta_i) = 2^32-1} >= 1: the message Update activates >= k'_msg multiplies with exactly one differing operand each, so for one-packet messages P[message Update silenced] <= 2^(-32 k'_msg) <= 2^-32 (checked: 0 silenced in 2^20 uniform keys, 65536/65536 in the density-2^-32 subspace); on a silenced trail round 1 activates >= 2 multiplies in two different lanes (measured minimum 3), every later round >= 1 (33,685,504 state-level round evaluations, minimum 1), so a fully silenced trail through R rounds activates >= R+2 multiplies. The 2^-32(R+2) figures are heuristic and NOT part of the proven statement.",
    "[any R, referee-corrected form of Lemma 1] Update_p, the finalization round rho and the remainder step are bijections of the 1024-bit state with the explicit inverse F^-1, E^-1, D^-1, C^-1, B^-1, A^-1 (65536/65536 checked by both sides); tau = v0[0]+v1[0]+mul0[0]+mul1[0] is a surjective homomorphism with fibres of exactly 2^960 states; for equal-length messages whose padded packet sequences differ in exactly one packet (the setting of this entire study) the final states differ for every key, so every such collision is a collision of tau on two distinct states. The original clause 'for every M != M' the final states differ' is REFUTED (known-key three-packet counterexample) and is not claimed.",
    "[any R, elementary, not refereed] Last-round truncation collision: for every entering state, mul1[0] ^= 2^63 leaves the output unchanged (2^20/2^20 states). Two-line argument re-derived here: step D's product reads lo32(v0[0]) and hi32(v1[0]), neither of which changes (v0[0] changes by exactly 2^63 after step C, v1[0] does not read mul1), so mul1[0] ends XORed by 2^63 = plus 2^63 mod 2^64 and v0[0] ends plus 2^63; ZipperMerge does not route byte 7 of v0[0] into v1[0]; the two 2^63 terms cancel in tau. Its unreachability from a message pair is argued, not proven."
  ],
  "unproven_boundary": "Proof stops one multiply into the trail, already at R=1, and never recovers. Precisely: (1) At R=1 the zero-multiply sector (differences routed only into v0[3]) is fully decided (Theorems 1, 2). The first multiply-active branch, m' = m + 2^40 e_3 with the 2^-8 of keys where A3.b5 = ff, reduces (claimant's Proposition 3, z3-proved but NOT refereed) to Pr_key[(M ^ (P+h)) - (M ^ P) = 0xFEFF0000FFFFFFFF] with M = mul0[0] = init0[0] ^ (lo32(A0) * hi32(init0[0]^k0)) a key-dependent XOR mask, P = lo32(U0) * hi32(X0) a 32x32 product and h = hi32(X0). Carry analysis forces h odd, 25 bits of M and 24 bits of P; the M pattern was counted exhaustively for ONE m0 (196 of 2^32); nothing bounds it uniformly in m, the non-generic carry sub-cases (wraps in U0, U1, Z3, hi32(Z2)) are not enumerated, and nothing bounds the min-entropy of lo32(U0), i.e. of hi32(Z2) = hi32(B2 + f0(A2, A3)) over (k2, k3) where hi32(k2) enters both B2 and A2 (only 15 bits are certifiable). The certified bound for this pair is therefore 2^-8 + 3*2^-16 against a measured 0 in 2^26.3 keys: a gap of at least 2^18 on the very first active multiply. (2) From R=2 on, every trail crosses Permute and the round-1 multiplies of the differing lane have BOTH operands differing (Lemma 4(b), refereed), so even the exact identity a'H - aH = (a'-a)H is lost: a'H' - aH = (a'-a)H' + a(H'-H) carries no structure that bounds Pr[a'H' = aH], and the XOR masks are key-dependent. No statement about R >= 2 has a proof; the R=2 rate 2^-19.7 has an explanatory mechanism (six byte conditions predict 89 of 100 collisions) but no closed form. (3) The universality-style route fails for structural reasons: f(k) = H_R(k,m) - H_R(k,m') is not a polynomial over Z/2^64 (XOR with key-dependent words, lo/hi splits, byte permutations), Z/2^64 has no root bound even for polynomials (2^63 X vanishes on half the ring, (2^32 X)(2^32 Y) identically), the GF(2) degree of product bits reaches 32 so the Boolean degree bound is vacuous, and the assumption that would finish it, 'products along a trail are independent uniform words', is false (two products sharing an operand differ by exactly (a'-a)H, confined below bit 33 for 75% of keys for delta = 1; P[bit 63 of a product] = 0.153; operands are functions of the same key halves). (4) What the structural lemmas do give beyond R=1 is only a count: a fully silenced trail through R rounds needs >= R+2 zero co-operands (heuristically 2^-32(R+2)), but the observed R <= 2 collisions are NOT silenced trails (they are byte-carry/confinement events at ~2^-8 each), and the analytic lenses' claims that no designed trail exists at R >= 3 (sumcancel-R3/R4 taint pull-back: all 46 R=4 condition bytes polluted for every 1- and 2-byte pattern; weakkey-R3's multiply-free ZipperMerge route into q3[0] that no lane-1 route can cancel) are hand-derived over-approximations, consistent with every measurement, refereed by nobody, and not probability bounds. (5) Sampling cannot cross the boundary from the other side: 2^32..2^34 keys per pair bound per-pair collision rates at 2^-33 and per-bit biases at 2^-14.4 (2^-13.5 per linear mask), which is 30 binary orders above the ideal 2^-64; 2^40 keys would reach 2^-38 / 2^-18. So the truth about H_4 lies strictly between 'no proof beyond R=1' and 'no signal at 2^-33 / 2^-14', and no technique in this panel can narrow that interval.",
  "draft_latex": "% ---------------------------------------------------------------------------\n% Draft for the adversarial appendix: HighwayHash-64 under round reduction.\n% Every number was measured by two independent implementations (the lens that\n% found it and a reproduction written from the reference C with its own key\n% stream); every statement marked proven was refereed.  Code: the lens\n% amsmath, booktabs, cleveref).\n% ---------------------------------------------------------------------------\n\\section{HighwayHash-64 under round reduction}\n\\label{app:highway}\n\nHighwayHash-64~\\cite{highwayhash} keeps a $1024$-bit state\n$(v_0,v_1,m_0,m_1)$ of four $64$-bit lanes each.  One \\texttt{Update} with a\n$32$-byte packet $p$ does, per lane $i$,\n$v_{1,i}\\mathrel{+}=m_{0,i}+p_i$,\n$m_{0,i}\\mathrel{\\oplus}=\\mathrm{lo}_{32}(v_{1,i})\\cdot\\mathrm{hi}_{32}(v_{0,i})$,\n$v_{0,i}\\mathrel{+}=m_{1,i}$,\n$m_{1,i}\\mathrel{\\oplus}=\\mathrm{lo}_{32}(v_{0,i})\\cdot\\mathrm{hi}_{32}(v_{1,i})$,\nfollowed by two additions of a fixed byte permutation (\\emph{ZipperMerge})\nthat mixes lanes $\\{0,1\\}$ with each other and lanes $\\{2,3\\}$ with each\nother.  The key enters only $v_0,v_1$ at reset; $m_0,m_1$ start at public\nconstants.  Finalization applies $R=4$ rounds of\n$\\texttt{Update}(\\texttt{Permute}(v_0))$, where \\texttt{Permute} rotates the\nlanes by two and swaps the $32$-bit halves, and returns\n$v_{0,0}+v_{1,0}+m_{0,0}+m_{1,0}$.  We write $H_R$ for the variant with $R$\nrounds; $H_4$ is the published function.  The reference C (Apache-2.0) was\ncopied with one added round-count parameter and reproduces the published\nvectors (\\texttt{kExpected64} for all $65$ lengths and the $33$-byte\n\\texttt{kTestKey2} vector) at $R=4$ in every tool.\n\n\\paragraph{Model.}\nAs in \\Cref{app:adversarial}: the key is four uniformly random $64$-bit\nwords, hidden; the attacker fixes a pair of equal-length messages whose\ndifference lies in the last packet; the reported rate is the fraction of keys\nfor which the pair collides, or for which a given bit of\n$H_R(m)\\oplus H_R(m')$ (or of $H_R(m')-H_R(m)$) is set.  A random function\ngives $2^{-64}$ and $\\tfrac12$; $z$ denotes the deviation of a bit count from\n$N/2$ in units of $\\sqrt N/2$.  Messages are $32$ bytes unless stated; $29$-,\n$48$-, $61$-, $63$- and $64$-byte variants (remainder path, second packet)\nwere checked for every effect quoted.  Six methods were run at every $R$:\nevolutionary search over pairs, analytic cancellation in the lane-$0$ output\nsum, exact bit-vector models in z3 and boolector, sampling of the key\nsubspaces that zero a multiply operand, bias counters at $2^{28}$--$2^{32}$\nkeys (per bit, all $65535$ linear masks of the top $16$ bits, additive\nnear-collisions, joint byte tables), and cube/ANF testers.  Every rate below\nwas re-measured by a second implementation with its own key stream, and every\nproof was refereed; refereed statements are marked \\emph{proven}, everything\nelse is a measurement.\n\n\\begin{table}[t]\n\\centering\n\\small\n\\begin{tabular}{@{}cp{0.34\\linewidth}p{0.36\\linewidth}l@{}}\n\\toprule\n$R$ & best full-collision rate & best distinguisher & status \\\\\n\\midrule\n$0$ & $1$: any difference in packet lanes $2,3$ & output identical & proven, all keys \\\\\n$1$ & $0.996$: lane $3$ byte $0$ $\\pm1$ ($2^{32}$ keys) & saturated & proven $\\ge1-9\\cdot2^{-8}$, every $m$ \\\\\n$2$ & $2^{-19.7}$: same pair ($4998$, $5004$ in $2\\times2^{32}$) & bit $63$ of $H\\oplus H'$ set for $2^{-12.2}$ of keys & measured; mechanism known \\\\\n$3$ & $0$ in $2^{34.5}$ ($<2^{-33}$) & lane $3$ byte $5$ $\\pm1$: bit $63$ of $H\\oplus H'$ set for $0.421$ of keys ($z=-9927$ at $2^{32}$) & measured; no proof \\\\\n$4$ & $0$ in $2^{34.5}$ ($<2^{-33}$) & none: every bit $|\\varepsilon|<2^{-14.4}$, every top-$16$ mask $|\\varepsilon|<2^{-13.5}$ ($2^{32}$ keys) & open \\\\\n\\bottomrule\n\\end{tabular}\n\\caption{HighwayHash-64 with $R$ finalization rounds, difference in the last\npacket, uniform key.  Rates are per pair over keys; the zeros at $R=3,4$ are\n$95\\%$ upper bounds $3/N$ over the pairs tested at scale.}\n\\label{tab:highway:rounds}\n\\end{table}\n\n\\paragraph{$R=0$ and $R=1$ (proven).}\nWithout finalization the lane pairs never meet: $H_0$ is a function of\n$k_0$, $k_1$, the length and the message bytes at positions $32q+j$ with\n$j<16$ only, so any difference confined to bytes $16$--$31$ of any packet\ncollides for every key (z3: \\textsc{unsat} with symbolic key and packet,\nalso with an uninterpreted multiplier; measured $2^{20}/2^{20}$ and, for the\n$256$ one-byte messages, $65536/65536$ keys).  With one round, the lane-$0$\noutput of a $32$-byte message has a closed form in which lanes $2,3$ enter\nonly through $v_{0,2}$ (which feeds both lane-$0$ multiplies) and $v_{0,3}$\n(which feeds byte shuffles and additions only).  Differences routed into\n$v_{0,3}$ never touch a multiply, and there everything is decidable: for\n\\emph{every} $32$-byte $m$, with $e_i$ one unit in packet lane $i$,\n\\[\n\\Pr[H_1(m+e_3)=H_1(m)]\\ge1-9\\cdot2^{-8},\\quad\n\\Pr[H_1(m+2^{32}e_2)=H_1(m)]\\ge1-7\\cdot2^{-8},\\quad\n\\Pr[H_1(m+2^{56}e_2)=H_1(m)]\\ge1-3\\cdot2^{-8}\n\\]\n(measured $0.996$, $0.988$, $0.992$), and conversely\n$\\Pr[H_1(m+2^{8}e_3)=H_1(m)]\\le2^{-22}$,\n$\\Pr[H_1(m+2^{16}e_3)=H_1(m)]\\le2^{-8}$,\n$\\Pr[H_1(m+2^{40}e_3)=H_1(m)]\\le2^{-8}+3\\cdot2^{-16}$ (measured $0$ in\n$2^{26}$ keys each).  The proofs are z3 certificates on a relaxed model in\nwhich seven key-derived words are free (sound for statements that hold for\nevery key), combined with a counting lemma for single key bytes.  The\ntwo-byte pattern lane $3$ $+\\,\\texttt{0xFF00}$ collides at\n$(255/256)^6=0.9768$ (measured $0.97678$ at $2^{26}$ keys, $0.97684$ and\n$0.97676$ in two reproductions): the $+2^{32}$ it delivers to $v_{0,0}$\ncancels the $-2^{32}$ it delivers to $v_{1,0}$ while both $m$ words stay\nequal, and each of the six failure modes is one byte carry.\n\n\\paragraph{$R=2$ (collisions at $2^{-19.7}$).}\nThe difference $\\pm1$ in lane $3$ byte $0$ (message byte $24$) is the one\nlast-packet pattern that survives the necessary conditions for a cancellation\nin the lane-$0$ sum after two rounds.  It collides for $4998$ and $5004$ of\n$2^{32}$ keys in two independent runs ($2^{-19.7}$, i.e.\\ $2^{44}$ times the\nideal), for $298$, $313$, $338$, $331$ of $2^{28}$ across bases and seeds, and\nat the same rate through the remainder path ($29$, $61$, $63$ bytes) and in\nthe second packet of a $64$-byte message.  Bit $63$ of $H_2(m)\\oplus H_2(m')$\nis set for only $2^{-12.2}$ of keys, $39$ of the $64$ bits have $|z|\\ge6$, and\nthe low $32$ bits collide for $2^{-10.05}$ of keys.  The colliding keys are a\nchance coincidence: the two product differences that the $+1$ creates\n($\\delta\\cdot\\mathrm{hi}_{32}(v_{0,3})$ at the packet step and\n$\\delta\\cdot2^{16}\\,\\mathrm{hi}_{32}(v_{0,1})$ in round $1$) both stay out of\nthe bytes that reach lane $0$; six byte conditions after round $1$ account for\n$89$ of $100$ collisions.  Zeroing the first operand by the key condition\n$\\mathrm{hi}_{32}(k_3)=\\mathrm{hi}_{32}(\\mathrm{init}_{0,3})$ (density\n$2^{-32}$) raises the rate to $2^{-9.86}$ ($289289/2^{28}$); zeroing the\nsecond as well (density $2^{-64}$) raises it to $0.980$, so that class\ncontributes $2^{-64}\\cdot0.98$ and the unconditional $2^{-19.7}$ is a\ncarry-and-confinement event, not a weak-key event.  No proof of the rate\nexists.\n\n\\paragraph{$R=3$ (a distinguisher, no collisions).}\nEvery $R=3$ effect found lives in one channel: an additive $\\pm d$, $d$\nsmall, in lane $3$ byte $5$ (message byte $29$).  For $d=1$ the top bit of\n$H_3(m)\\oplus H_3(m')$ is set for $0.421$--$0.424$ of keys instead of\n$\\tfrac12$ ($z=-9927$, $-10040$, $-10345$ at $2^{32}$ keys in three lenses,\n$z_{63}\\approx-0.15\\sqrt N$; bits $57$--$62$ biased with the bias halving per\nbit); the parity of the top two bits of $H_3(m')-H_3(m)$ is even for $0.607$\nof keys; the top $8$ output bits agree for $2^{-6.64}$ of keys ($2.57\\times$\nideal; $2^{-14.62}$ for the top $16$, and the same $2.5$--$2.8\\times$ excess of\n$|H_3(m')-H_3(m)|<2^k$ for every $k$ from $32$ to $56$); the second derivative\non the two-bit cube $\\{\\text{lane-}3\\text{ bit }0,\\text{ bit }40\\}$ has top\nbit $0$ for $0.685$ of keys ($2^{26}$ keys).  The bias has the same sign for\nevery key ($64$ of $64$ keys, $z_{63}\\in[-166,-151]$ at $2^{20}$ pairs each),\nso about $2^{11}$ chosen message pairs distinguish $H_3$ from random under a\nfixed key, and about $2^{11}$ keys under a fixed pair.  Any second differing\nbit anywhere in the packet kills the effect ($|z|\\le3.5$ at $2^{20}$ keys for\n$221$ two-bit patterns).  The $R=2$ collision family keeps only a residue at\n$R=3$, $\\varepsilon\\approx-2^{-14}$ on bit $63$ ($z=-10.5$ and $-7.8$ in two\nruns of $2^{32}$).  Full collisions: $0$ in $2^{34.5}$ keys over the channel's\nvariants, i.e.\\ below $2^{-33}$.  Key subspaces that silence multiplies\nsharpen the bias but never produce an $R=3$ collision: with\n$\\mathrm{hi}_{32}(k_3)=\\mathrm{hi}_{32}(\\mathrm{init}_{0,3})$ (density\n$2^{-32}$) the lane-$3$ $+1$ pair has $\\Pr[\\text{bit }63\\text{ differs}]=0.434$,\nwith two further round-$1$ conditions (density $2^{-96}$) $0.016$, and $0$\ncollisions in $2^{28}$ and $2^{24}$ conditional keys.\n\n\\paragraph{$R=4$ (the published function).}\nNothing.  For the byte-$29$ pair at $2^{32}$ keys: $0$ collisions; every bit\nof $H_4(m)\\oplus H_4(m')$ and of $H_4(m')-H_4(m)$ has $|z|\\le3.0$\n($|\\varepsilon|<2^{-14.4}$); all $65535$ linear masks of the top $16$ bits of\neither difference have $|z|\\le4.8$ against a null maximum of $4.9$\n($|\\varepsilon|<2^{-13.5}$); the joint distributions of the top bytes and of\nthe low bytes of the two outputs are independent ($|z|<1.4$); the counts of\n$|H_4(m')-H_4(m)|<2^k$ are at $1.00\\times$ ideal for $k=40,\\dots,60$.  The same\nholds for the $R=2$ collision pair, for the complement pairs $\\bar w_3$ and\n$\\bar w_2\\bar w_3$, for $w_0+2^{32}$, $w_3\\oplus2^{31}$, $w_0\\oplus2^{63}$ and\na random control at $2^{29}$--$2^{32}$ keys, for every winner of four $R=4$\nhill-climbs ($577{,}004$ pairs evaluated, $2^{30}$ keys on the top two), for\ncube dimensions up to $26$ in message and key bits (every restricted degree\n$\\ge d-1$, monomial density at random), and inside the weak-key classes of\ndensity $2^{-32}$ ($2^{28}$ keys), $2^{-64}$ and $2^{-96}$\n($2^{23}$--$2^{24}$).  With $0$ collisions in $2^{34.5}$ keys for the byte-$29$\nfamily and $2^{33.5}$ for the byte-$24$ family their rates are below\n$2^{-33}$; the ideal $2^{-64}$ is thirty binary orders further down.  Against\neverything tried here the published design keeps one round of margin against\ndistinguishers and two against collisions.\n\n\\paragraph{Where the proof stops.}\nA collision is a zero of $f(k)=H_R(k,m)-H_R(k,m')$ over $\\mathbb Z/2^{64}$,\nand $f$ is not a polynomial: XOR with key-dependent words, $32$-bit splits\nand byte permutations sit between the products, and $\\mathbb Z/2^{64}$ has\nno root bound anyway ($2^{63}X$ vanishes on half the ring).  The first\nobstruction appears at $R=1$, one multiply into the trail: for\n$m'=m+2^{40}e_3$ and the $2^{-8}$ of keys with a carry into the multiplied\nhalf, the collision condition is\n$(M\\oplus(P+h))-(M\\oplus P)=\\texttt{FEFF0000FFFFFFFF}$ with $M=m_{0,0}$ a\nkey-dependent XOR mask, $P=L\\cdot h$ a $32\\times32$ product and $h$ its\nkey-dependent operand.  Carry analysis pins $25$ bits of $M$ and $24$ of $P$\n(an exhaustive count gives $196$ admissible $\\mathrm{hi}_{32}(k_0)$ of\n$2^{32}$ for one $m_0$), but the count depends on $m$, the remaining\nsub-cases are not enumerated, and nothing bounds the entropy of $L$ over\n$(k_2,k_3)$; the certified bound for this pair is $2^{-8}+3\\cdot2^{-16}$\nagainst a measured $0$ in $2^{26}$.  From $R=2$ on every trail crosses\n\\texttt{Permute} and meets multiplies with \\emph{both} operands differing,\nwhere even the identity $a'H-aH=(a'-a)H$ is lost.  What survives as a theorem\nis structural: \\texttt{Update}, the round and the remainder step are\npermutations of the state with explicit inverses, so a collision of two\nmessages differing in one packet is a collision of the $64$-bit truncation on\ntwo distinct states; a multiply operand that carries a difference is silenced\nonly by a zero co-operand ($2^{-32}$ per multiply for one-packet messages);\nand a trail through $R$ rounds on which every product is silenced activates\nat least $R+2$ multiplies.  The observed $R\\le2$ collisions are not of that\nkind: they are byte-carry and byte-confinement events at about $2^{-8}$ each,\nand no accounting of them beyond $R=2$ has been made exact.  The assumption\nthat would close the gap, that the products along a trail are independent\nuniform words, is false: two products sharing an operand differ by exactly\n$(a'-a)H$ (confined below bit $33+\\log_2|a'-a|$ for three quarters of the\nkeys), and the top bit of a product of uniform $32$-bit halves is set with\nprobability $\\tfrac12-\\tfrac12\\ln2=0.153$, which is the mechanism behind the\n$R=3$ bias.\n\n\\paragraph{Caveat.}\nThe differences were confined to the last packet (plus a second packet for\nthe two families tested at $64$ bytes); two-packet trails in which the second\npacket cancels the first were not searched.  Sampling decides rates down to\nabout $2^{-33}$ per pair and biases down to $2^{-14}$ per bit; $H_4$ is\nneither broken nor proven at any finer scale.  For a \\emph{known} key the\ninternal state is not collision resistant at any $R$: since the packet enters\n$v_1$ additively and every step is a bijection, one can choose, for any given\nkey, a $96$-byte pair differing in lane $0$ of three consecutive packets that\nreaches the identical $1024$-bit state (verified for $65536/65536$ keys; each\nsuch pair collides for $0/65536$ other keys).  This is why the statements\nabove are over random keys and single-packet differences."
}
