Locally Testable Codes and Cayley Graphs

We give two new characterizations of ($\F_2$-linear) locally testable error-correcting codes in terms of Cayley graphs over $\F_2^h$: \begin{enumerate} \item A locally testable code is equivalent to a Cayley graph over $\F_2^h$ whose set of generators is significantly larger than $h$ and has no short linear dependencies, but yields a shortest-path metric that embeds into $\ell_1$ with constant distortion. This extends and gives a converse to a result of Khot and Naor (2006), which showed that codes with large dual distance imply Cayley graphs that have no low-distortion embeddings into $\ell_1$. \item A locally testable code is equivalent to a Cayley graph over $\F_2^h$ that has significantly more than $h$ eigenvalues near 1, which have no short linear dependencies among them and which"explain"all of the large eigenvalues. This extends and gives a converse to a recent construction of Barak et al. (2012), which showed that locally testable codes imply Cayley graphs that are small-set expanders but have many large eigenvalues. \end{enumerate}


Introduction
In this work, we show that locally testable codes are equivalent to Cayley graphs with certain properties, thereby providing a new perspective from which to approach long-standing open problems about the achievable parameters of locally testable codes.
Before describing these results, we review the basics of both locally testable codes and Cayley graphs.

Locally Testable Codes
Informally, a locally testable code (LTC) is an error-correcting code in which one can distinguish received words that are in the code from those that are far from the code by a randomized test that probes only a few coordinates of the received word.Local testing algorithms for algebraic error-correcting codes (like the Hadamard code and the Reed-Muller code) were developed in the literature on program testing [BLR93,RS96], inspired the development of the field of property testing [GGR98], and played a key role in the constructions of multi-prover interactive proofs and the proof of the PCP Theorem [BFL91, FGL + 96, BFLS91, AS98, ALM + 98].Indeed, they are considered to be the "combinatorial core" of PCPs (cf., [GS06, BGH + 06]), and thus understanding what is possible and impossible with locally testable codes can point the way to a similarly improved understanding of PCPs.See the surveys [Tre04,Gol11,Ben10].We focus on the commonly studied case of linear codes over F 2 .Thus a code is specified by a linear subspace C ⊂ F n 2 .n is called the blocklength of the code, and k = dim(C) is its rate.The minimum distance is d = min A local tester for C is a randomized algorithm T that, when given oracle access to a received word r ∈ F n 2 , makes at most a small number q of queries to symbols of r and accepts or rejects.If r ∈ C, then T r should accept with high probability (completeness), and if r is "far" from C in Hamming distance, then T r should reject with high probability (soundness).It was shown in [BHR05] that any tester for a linear code can be converted into one with the following structure: the tester T randomly samples a string α ← D and accepts if α•r = 0, where D = D T is some distribution on the dual code C ⊥ = {α ∈ F n 2 : α•c = 0∀ c ∈ C}.In particular, such a tester has perfect completeness (accepts with probability 1 if r ∈ C).We say the tester (which is now specified solely by D) has soundness δ if for every r ∈ F n 2 , where d(r, C) = min c∈C d(r, c).This formulation of soundness is often referred to as strong soundness in the literature.Weaker formulations of soundness in the literature only require that the test reject with good probability when r is sufficiently far from the code.Typically, we want δ = Ω(1/d), where d is the minimum distance of the code, so that received words at distance Ω(d) from C are rejected with constant probability.If there are received words at distance ω(d) from C, then it is common to cap the rejection probability at a constant (e.g.require Pr α←D [α • r = 1] ≥ min{δ • d(r, C), 1/3}), but we ignore this issue in the introduction for simplicity.We are interested in two parameter regimes for LTCs: Asymptotically Good LTCs Here we seek rate k = Ω(n), minimum distance d = Ω(n), soundness δ = Ω(1/d) = Ω(1/n), and query complexity q = O(1).Unfortunately, we do not know whether such codes exist -this is the major open problem about LTCs first posed by [GS06] , and it is closely related to the long-standing open question about whether SAT has constant-query PCPs of linear length (which would enable proving that various approximation problems require time 2 Ω(n) under the exponential-time hypothesis).The closest we have is Dinur's construction [Din07], which has inverse-polylogarithmic (rather than constant) relative rate (i.e.n = k • polylog(k)).A recent result by Viderman additionally achieves strong soundness [Vid13].In terms of limitations of LTCs, there are a number of results shedding light on the structure of an LTC with good parameters (see the survey [Ben10]), but there are essentially no nontrivial upper-bounds on rate known for arbitrary F 2 -linear LTCs.

Constant-distance LTCs
Instead of bounding the query complexity of our LTCs, it is convenient for us to work with smooth LTCs, where we simply require that the tester does not query any one coordinate too often.Formally, a tester, specified by a distribution D on C ⊥ , is ε-smooth if for every i ∈ [n], Pr α←D [α i = 1] ≤ ε.This is analogous to the notion of smooth locally decodable codes (LDCs) defined by Katz and Trevisan [KT00].Like in the case of LDCs, bounding smoothness is almost equivalent to bounding query complexity, where query complexity q corresponds to smoothness Θ(q/n) (as would be the case for testers that make q uniformly distributed queries). 2In particular, we want the smoothness to be ε = O(1/n) in the asymptotically good regime, and ε = O(1/d) in the constant-distance regime.

Cayley Graphs
Cayley graphs are combinatorial structures associated with finite groups and are useful for applications ranging from pure group theory to reasoning about the mixing rates of Markov chains to explicit constructions of expander graphs [Big93,HLW06].In this paper, we focus on the case that the group is a finite-dimensional vector space V over F 2 .(So V ∼ = F h 2 for some h ∈ N.) Given a multiset S ⊆ V, the Cayley (multi)graph Cay(V, S) has vertex set V and edges (x, x + s) for every s ∈ S (with appropriate multiplicities if S is a multiset).Note that this is an |S|-regular undirected graph, since every element of V is its own additive inverse.If we take S to be a basis of V, then Cay(V, S) is simply the h-dimensional hypercube, where h = dim V. We will be interested in the properties of such graphs when |S| is larger than h.

LTCs and Metric Embeddings of Cayley Graphs
Our first result shows that locally testable codes are equivalent to Cayley graphs with low-distortion metric embeddings into ℓ 1 .We refer the reader to [Mat02, Chapter 15] for background on metric embeddings.
An embedding of a metric space (X 1 , d 1 ) into metric space (X 2 , d 2 ) with distortion c ≥ 1 is a function f : X 1 → X 2 such that for some α ∈ R + and every x, y ∈ X 1 , we have A commonly studied case is when (X 1 , d 1 ) is the shortest-path metric d G on a graph G, and (X 2 , d 2 ) is an ℓ p metric.Indeed, we will take (X 1 , d 1 ) to be the shortest-path metric on a Cayley graph, and (X 2 , d 2 ) to be an ℓ 1 metric.We will use the well-known characterization of ℓ 1 metrics as the cone of the "cut metrics": a finite metric space (X 2 , d 2 ) is an ℓ 1 metric if and only if there is a constant α ∈ R + and a distribution F on boolean functions on X 2 such that for all x, y ∈ X 2 , Note that the shortest-path metric on the hypercube Cay(F h 2 , {e 1 , . . ., e h }) is an ℓ 1 metric.Indeed, this metric is simply the Hamming distance d, and d(x, y) We show that the existence of locally testable codes is equivalent to being able to approximate this property (i.e. have low-distortion embeddings into ℓ 1 ) even when the number of generators is noticeably larger than h.To avoid trivial ways of increasing the number of generators (like duplicating generators, or taking small linear combinations), we will also require that the generators are d-wise linearly independent (i.e. have no linear dependency of length smaller than d).
1.If there is an F 2 -linear code of blocklength n, rate k, and distance d with an ε-smooth local tester of soundness δ, then there is a Cayley graph G = Cay(F h 2 , S) such that |S| = n, h = n−k, S is d-wise linearly independent, and the shortest path metric on G embeds into ℓ 1 with distortion at most ε/δ.

If there is a Cayley graph G = Cay(F h
2 , S) such that |S| = n, S is d-wise linearly independent, and the shortest path metric on G embeds into ℓ 1 with distortion at most c, then there is an F 2 -linear code of blocklength n, rate k = n − h, and distance d with an ε-smooth local tester of soundness δ, for some δ and ε such that ε/δ ≤ c.
Note that the theorem provides an exact equivalence between locally testable codes and ℓ 1 embeddings of Cayley graphs, except that the equivalence only preserves the ratio ε/δ rather than the two quantities separately.It turns out that this ratio is the appropriate parameter to measure when considering strong soundness.(See Section 3.1.)For weaker notions of soundness, we obtain equivalences with weaker notions of low-distortion embeddings, such as "single-scale embeddings" (where we replace the requirement that d 2 (f (x), f (y)) ≥ αd 1 (x, y) with d 1 (x, y) ≥ D ⇒ d 2 (f (x), f (y)) ≥ αD, see [Lee05] and references therein).
The theorem specializes as follows for the two main parameter regimes of interest: Corollary 2. There is an asymptotically good smooth LTC with strong soundness To interpret the theorem, let's consider what the conditions on the Cayley graph G mean.The condition that |S| = n and the elements of S are d-wise independent means that locally, in balls of radius d, the graph G looks like the n-dimensional hypercube (which embeds into ℓ 1 with no distortion).However, it is squeezed into a hypercube of significantly lower dimension h (which may make even constant distortion impossible).
The canonical example of graphs that do not embed well into ℓ 1 are expanders.Specifically, an nregular expander on H = 2 h vertices with all nontrivial eigenvalues bounded away from 1 requires distortion Ω(h/ log n) to embed into ℓ 1 .Roughly speaking, the reason is that by Cheeger's Inequality (or the Expander Mixing Lemma), cuts cannot distinguish random neighbors in the graph from random and independent pairs of vertices in the graph, and random pairs of vertices are typically at distance Ω(h/ log n). 3hus, saying that a graph G embeds into ℓ 1 with constant distortion intuitively means that G is very far from being an expander.More precisely, to prove the nonexistence of an ℓ 1 embedding of distortion c amounts to exhibiting a distribution D close on edges of G and a distribution D far on pairs of vertices in G such that for every cut f : As discussed above, if G were an expander, we could take D close to be the uniform distribution on edges and D far to be the uniform distribution on pairs of vertices, and deduce a superconstant lower bound on c. Showing an impossibility result for LTCs amounts to finding such expander-like distributions D close and D far in an arbitrary Cayley graph with a large (size n) set of d-wise linearly independent generators S.
Our construction of a Cayley graph from an LTC in Item 1 of Theorem 1 is a "quotient of hypercube" construction previously analyzed by Khot and Naor [KN06].Specifically, they showed that if we start from a code C whose dual code C ⊥ has large minimum distance, then the resulting Cayley graph G requires large distortion to embed into ℓ 1 .Our contributions are to show that we can replace the hypothesis with the weaker condition that C is not locally testable, and to establish a tight converse by constructing LTCs from Cayley graphs with low-distortion embeddings.

LTCs and Spectral Properties of Cayley Graphs.
In our second result, we show that locally testable codes are equivalent to Cayley graphs with spectral properties similar to the "ε-noisy hypercube".We call such graphs derandomized hypercubes.
For Cayley graphs over F 2 vector spaces (and more generally abelian groups), the spectrum can be described quite precisely using Fourier analysis.Let M be the transition matrix for the random walk on Cay(V, S), i.e. the adjacency matrix divided by |S|.Then, regardless of the choice of S, the eigenvectors of M are exactly of the form χ b (x) = (−1) b(x) where b : V → F 2 ranges over all F 2 -linear functions.(If we pick a basis so that for λ bounded away from 1, then all the nontrivial eigenvalues have magnitude at most λ, and hence the graph Cay(V, S) is an expander.In contrast, for the case of the hypercube (S = {e 1 , . . ., e h } for a basis e 1 , . . ., e h of V), the eigenvalue associated with b = (b 1 , . . ., b h ) is 1 − 2|b|/h where |b| is the Hamming weight of b, so there are h i eigenvalues of value 1 − 2i/h.In this section, it will be useful to generalize the notion of Cayley graph from multisets to distributions over V.If S is a distribution over V, then Cay(V, S) is a weighted graph where we put weight Pr[S = s] on the edge (x, x + s) for every x, s ∈ F h 2 .Pr[S = s] is also the (x, x + s) entry of the transition matrix of the random walk on Cay(V, S).Now, the eigenvalues are λ Here a useful example is the ε-noisy hypercube, where V = F h 2 and S = (S 1 , . . ., S h ) has each coordinate independently set to 1 with probability ε, and hence the eigenvalues are λ Neither the hypercube nor the ε-noisy hypercube are very good expanders, as they have eigenvalues of 1 − 2/h and 1 − 2ε, respectively, corresponding to eigenvectors χ b with |b| = 1 (which in turn correspond to the "coordinate cuts," partitioning F h 2 into the sets {x : x i = 1} and {x : x i = 0}).However, their spectral properties do imply that small sets expand well.Indeed, Kahn, Kalai, and Linial [KKL88] showed that the indicator vectors of "small" sets in F h 2 are concentrated on the eigenvectors χ b where |b| is large, and hence small sets expand well in both the hypercube and ε-noisy hypercube (where "small" is |V| 1−Ω(1) in the case of the hypercube, and o(|V|) in the case of the ε-noisy hypercube).
Our spectral characterization of locally testable codes is as follows.
Theorem 4.There is an F 2 -linear code of blocklength n, rate k, and distance d with an ε-smooth local tester of soundness δ if and only if there is a Cayley graph

For every linear map b
Let's compare these properties with those of the ε-noisy hypercube.Recall that, in the ε-noisy hypercube, the coordinate cuts S = {e 1 , . . ., e h } are linearly independent and all give eigenvalues of 1 − 2ε.And for every b, λ(b) Like in our metric embedding result, the main difference here is that we are asking for the set S to be of size larger than h (while retaining d-wise independence among the generators), so we need to squeeze many large eigenvalues into a low-dimensional space.One reason that these spectral properties are interesting is that they imply that the graph G is a small-set expander for sets of size |V|/ exp(d)(see Lemma 18).
One direction of the above theorem (from LTCs to Cayley graphs) is extracted from the work of Barak et al. [BGH + 12], who used locally testable codes (in the constant distance regime) to construct small-set expanders that have a large number of large eigenvalues (as a function of the number H = 2 h of vertices).Such graphs provide barriers to improving the analysis of the Arora-Barak-Steurer algorithm for approximating small-set expansion and unique games [ABS10], and were also used by Barak et al. [BGH + 12] to construct improved integrality gap instances for semidefinite programming relaxations of the unique games problem.Our contribution is showing that the connection can be reversed, when formulated appropriately (in terms of spectral properties rather than small-set expansion).
We can specialize Theorem 4 to the two parameter regimes of interest to us (see Corollaries 16 and 17 in Section 4.4 for precise statements).The existence of asymptotically good smooth LTCs with strong soundness is equivalent to the existence of Cayley graphs whose eigenvalue spectrum resembles the ndimensional Boolean hypercube (for eigenevalues in the range [0.5, 1]) but where the number of vertices is 2 (1−Ω(1))n .In the constant d regime, the existence of [n, n − c d log n, d] 2 LTCs blocklength n with smoothness ε = O(1/d), and soundness δ = Ω(1/d) is equivalent to the existence of Cayley graphs whose eigenvalue spectrum resembles the n-dimensional Boolean hypercube (for eigenvalues in the range [0.5, 1]) but where the number of vertices is n c d .
Like our metric embedding result, Theorem 4 and its corollaries have analogues for weaker notions of soundness for the locally testable codes.Specifically, Item 4 changes in a way that is analogous to the soundness condition, for example only requiring that λ(b) is small when rank S (b) is large.

Perspective
For many of the problems about constructing codes or Cayley graphs studied in theoretical computer science, the main challenge is finding an explicit construction.Indeed, we know that a randomly chosen code has good rate and distance and that a randomly chosen set of generators yields a Cayley graph with high expansion, and much of the research on these topics is aimed at trying to match these parameters with efficient deterministic algorithms.
Locally testable codes (and the equivalent types of Cayley graphs that we formulate) are intriguing in that they combine properties of random objects (such as large distance) with very non-random properties (the existence of a local tester).Thus the major open questions (such as whether there are asymptotically good LTCs) are existential -do there even exist objects with the given parameters, regardless of the complexity of constructing them?
Our hope is that the alternative characterizations developed in this paper will be useful in approaching some of these existential questions, either positively (e.g. by using graph operations to construct Cayley graphs with the properties discussed above, analogously to Meir's construction of LTCs [Mei09]) or negatively (e.g. by reasoning about expander-like subgraphs of Cayley graphs, as discussed above in Section 1.3).
The connection between metric embeddings and local testability gives a new perspective on existing results in this area, for instance we use it to give a simple LTC-based proof of the non-embeddability result of Khot and Naor [KN06] (see Section 3.2).Similarly, the connection to derandomized hypercubes has been used by [BGH + 12, KM13] to construct improved integrality gap instances for semidefinite programming relaxations of combinatorial optimization problems.

Locally Testable Codes revisited
In this section we reformulate the properties of Locally Testable Codes in terms of cosets, which makes our equivalences easier to show.
Recall that a local tester for an 2 .We say that an [n, k, d] 2 linear code is (ε, δ)-locally testable if it has a tester D which has smoothness ε and soundness δ.By considering received words at distance 1 from the code, we get δ ≤ Rej(e i , D) ≤ ε.The upper bound is an easy consequence of the smoothness.Ideally, we want δ = Ω(ε).
Given v ∈ V, let v ∈ V/C denote the coset of C containing it.Let Ē = {ē 1 , . . ., ēn } denote the coset representatives of the basis vectors {e 1 , . . ., e n }.The ēi s are not independent over F 2 , indeed we have Hence the shortest non-trivial linear dependence is of weight exactly d.
For v ∈ V/C, there could be several ways to write it as a linear combination over Ē.We have This lets us define Rej(v, D) = Rej(v, D) for any v ∈ v.
We can now rephrase smoothness and soundness in terms of coset representatives.
Pr α←D Thus D is ε-smooth if every ēi is rejected with probability at most ε.
We say a set S of vectors in an F 2 -linear space is d-wise independent if every T ⊆ S where |T | < d is linearly independent over F 2 .For a set of vectors S = {s 1 , . . ., s n } which span a space T , we use rank S (t) for t ∈ T to denote the smallest k such that t can be expressed as the sum of k vectors from S. With this notation, D has soundness We summarize these observations in the following lemma: Lemma 5. Let C be an [n, k] 2 code and let D be a tester for C.

Locally Testable Codes and Metric Embeddings
Let S = {s 1 , . . ., s n } ⊂ F h 2 be set of n ≥ h generators of F h 2 that are d-wise independent.Let G = Cay(F h 2 , S) be the Cayley graph whose edges correspond to the set S. The graph G can be naturally associated with a code C G which consists of all vectors c = (c 1 , . . ., c n ) such that i c i s i = 0.It is easy to see that C G is an [n, n − h, d] 2 linear code.
Similarly, one can start from an [n, k, d] 2 linear code C and construct a Cayley graph G C on F n−k

2
. We take the vertex set to be F n 2 /C.We add an edge (x, ȳ) if there exist x ∈ x and y ∈ ȳ such that d(x, y) = 1.It is easy to see that is equivalent to taking S = { ē1 , . . ., ēn }, and this set is d-wise independent by the distance property of C.
It is easy to see that this construction inverts the previous construction.Henceforth we will fix a code C and a graph G that can be derived from one another.The vertex set of G is given by V (G) = F n 2 /C and the edge set E(G) by {x, x + ēi } for x ∈ F n 2 /C and i ∈ [n].Lemma 6.Let d G denote the shortest path metric on G.We have An ℓ 1 -embedding of the shortest path metric d G on the graph G is a distribution D over Boolean functions f : V (G) = F n 2 /C → {±1}.The distance δ(x, ȳ) between a pair of vertices x and ȳ under this embedding is We define the stretch of an edge (x, ȳ) to be the ratio δ(x, ȳ)/d(x, ȳ).The distortion c D of the embedding D is the ratio of the maximum to the minimum stretch of any pair of vertices.It is given by It follows by the triangle inequality that the stretch is maximized by some edge.Hence we get The minimum c achieved over all ℓ 1 -embeddings of G is denoted c 1 (G).

Definition 7. An embedding
The space of linear functions on F n 2 /C is isomorphic to C ⊥ .In a linear embedding, we have Thus, the distance δ is invariant under shifting in linear embeddings, just like the shortest path distance d G .Indeed, the next lemma shows that we can replace any embedding by a linear embedding without increasing the distortion.
Lemma 8.There is a linear embedding D of G into ℓ 1 achieving distortion c 1 (G).
To prove this lemma, we set up some machinery.Let f : F n 2 /C → {±1} be a Boolean function on F n 2 /C.We can extend f to a function on all of F n 2 by setting f (x) = f (x).(We will henceforth switch freely between both notions).The resulting function is invariant under cosets of C, which implies that its Fourier spectrum is supported on C ⊥ .Hence we have Further, we have α∈C ⊥ f (α) 2 = 1.
We now proceed to the proof of Lemma 8.
Proof: Given an arbitrary distribution D on Boolean functions, we define a new distribution D ′ on functions where we sample a ∈ F n 2 uniformly at random, f ∈ D, and return the function Let a 1 and a 2 be the values of a that minimize and maximize δ(x + a, y + a) respectively.Then Hence we have since all the denominators are equal.But this implies that Next we show that there is a linear embedding D ′′ with distortion c D ′′ = c D ′ .The embedding is simple to describe: we first sample f ∈ D, we then sample χ α ∈ C ⊥ with probability f (α) 2 .We denote this distribution on C ⊥ by f 2 .Note that From this it follows that c ′′ D = c ′ D ≤ c D .The lemma follows by taking D to be the ℓ 1 embedding of G that minimizes distortion.
We now prove the main result of this section.

Proof:
For linear embeddings, we can use shift invariance to simplify the expression for distortion.Since D is a distribution on C ⊥ , we can view it as a tester for C. Note that Rej(x, D) = δ(x, 0).Recall by Equation (3) We can use δ(x, ȳ) = δ(x + ȳ, 0) = Rej(x + ȳ, D) to rewrite this as Given a linear embedding specified by a distribution D that gives distortion c D , we view D as a tester.By definition, it has smoothness ε for and has soundness δ for since any such δ satisfies the condition Rej(x, D) ≥ δd(x, 0).
By taking ε, δ to satisfy Equations 5 and 6 with equality, we get δ = ε/c D .
In the other direction, assume we have a (ε, δ)-tester for C where δ ≥ ε/c.Note that ε, δ must satisfy Equations 5 and 6.Plugging these into Equation 4, we get

Boosting the soundness
Theorem 9 implies the existance of an (ε, δ)-tester for C, where While this is the best ratio possible between ε and δ, Theorem 9 does not seem to guarantee the right absolute values for them.In this section, we show that one can achieve this by repeating the tests.First, we identify the right absolute values.Let t denote the covering radius of C, and let x be a codeword at distance t from C. Since we get δ ≤ 1/t.Given this upper bound, we would like ε to be Θ(1/t) and δ to be Θ(1/(c 1 (G)t)).We show that this is possible, with a small loss in constants (which we do not attempt to optimize).
We defer the proof of this result to Appendix A. Note that if d = Ω(n), then d and t differ by a constant factor.However, when d = o(n), it could be that t = ω(d).In this case, we could relax the soundness requirement for words at distance ω(d) as follows: It is possible to get such a tester where ε = O(1/d), δ = Ω(1/(c 1 (G)d)) using the same argument as above, but replacing t with d.We omit the details.

Relation to previous work
This equivalence allows us to reformulate results about LTCs in the language of metric embeddings and vice versa.We present two examples where we feel such reformulations are particularly interesting.

Embedding lower bounds from dual distance:
Khot and Naor show the following lower bound for c 1 (G) in terms of its dual distance.
Theorem 11. [KN06,Theorem 3.4] Let C be an [n, n − h] 2 code and let G be the associated Cayley graph.Let d ⊥ denote its dual distance.Then In the setting where h/n = Ω(1) (which is necessary to have constant relative distance), this gives a lower bound of Ω(d ⊥ ).Thus their result can be seen as the embedding analogue of the result of BenSasson et al. [BHR05], who showed that the existence of low-weight dual codewords is a necessary condition for local testability.Our results allow for a simple alternative proof of Theorem 11.
Proof of Theorem 11.By Theorem 9, there exists a (ε, δ)-tester D so that c 1 (G) = ǫ/δ.We may assume without loss of generality that D is supported on non-zero code-words in C ⊥ , each of which is of weight at least d ⊥ , so we have ε ≥ d ⊥ /n.
As in Section 3.1, we have δ ≤ 1/t where t is the covering radius of C. We lower bound t by a standard volume argument: .

Lower bounds for basis testers
2 code, a basis tester for C yields an embedding into (n − k)-dimensional space.Hence their result implies that any linear embedding of F n 2 /C into (n − k)-dimensional space requires distortion Ω(kd/n) (even though F n 2 /C has dimension n − k as a vector space over F 2 ), and hence low-distortion embeddings must have larger support.Note that since our reduction from arbitrary embeddings to linear embeddings could blow up the support, this does not imply a similar bound for arbitrary embeddings.

Derandomized Hypercubes
We consider Cayley graphs over groups of characteristic 2. Let A = F h 2 for some h > 0. A distribution D over A gives rise to a weighted graph Cay(A, D) where the weight of edge (α, β) equals D(α + β).
The symmetry of Cayley graphs makes it easy to compute their eigenvectors and eigenvalues explicitly.Let A * denote the space of all linear functions b : A → F 2 .The characters of the group A are in 1-1 correspondence with linear functions: b ∈ A * corresponds to a character χ b : A → {±1} given by χ b (α) = (−1) b(α) .The eigenvectors of Cay(A, D) are precisely the characters {χ b } b∈A * .The corresponding eigenvalues are given by λ As mentioned earlier, the Cayley graphs we are interested in can be viewed as derandomizations of the ε-noisy hypercube, which retain many of the nice spectral properties of the Boolean hypercube.Before defining them formally, we list these properties that we would like preserved (at least approximately).
2. Linear Independence.The linear functions {e 1 , . . ., e h } corresponding to the top eigenvectors are linearly independent over F 2 .
We are interested in Cayley graphs whose threshold rank n is possibly (much) larger than h.But this means that the corresponding dual vectors which lie in the space A * of dimension h < n can no longer be linearly independent.So we relax the Linear Independence condition, and only ask that there should be no short linear dependencies between these vectors.The Spectral Decay condition will stay the same, except that we need to modify the notion of rank to account for linear dependencies.Note that any set of generators B * for A * gives us some values of n, d, µ and ν.We would like n, d to be large.Also, applying the Spectral decay condition to b ∈ B * , we see that Ideally, we would like them to be within a constant factor of each other.
We refer to such graphs as "derandomized hypercubes".The reason is that if there is a generating set of size n which is significantly larger than the dimension h, then the resulting graph has spectral properties that resemble the n dimensional hypercube, although it has only 2 h ≪ 2 n vertices.Every Cayley graph Cay(A, D) together with a generating set B * gives us a derandomized hypercube, the parameters n, d, µ, ν tell us how good the derandomization is (just like any code C and dual distribution D gives us local tester, whose quality is governed by the parameters it achieves).Theorem 14.Let C be an [n, k, d] 2 linear code for d ≥ 3, and let D be an (ε, δ)-tester for C.There exists a d-wise independent set Ē of size n which is a (2ε, 2δ)-spectrum generator for Cay(C ⊥ , D).
Proof.Observe that (C ⊥ ) * ∼ = V/C.This is because each v ∈ V defines a linear function on C ⊥ given by v(α) = α(v), and v, v ′ define the same function iff the lie in the same coset of C.
We take Ē = {ē 1 , . . ., ēn } to be the cosets corresponding to the received words e 1 , . . ., e n .By Lemma 5, since C has distance d, the set Ē is d-wise independence.We will show that it is a (2ε, 2δ)-spectrum generator for Cay(C ⊥ , D).
We bound the eigenvalues using the correspondence between the spectrum of Cay(C ⊥ , D) and the soundness of the tester D established by Barak et al..For v ∈ V/C, let χ v and λ(v) denote the corresponding eigenvalue.[BGH + 12, Lemma 4.5] says that • Smoothness implies Large Eigenvalues.By Lemma 5 the smoothness of D implies Rej(ē i , D) ≤ ε.By Equation 7, • Soundness implies Spectral decay.Fix v ∈ V/C so that rank B * (v) ≥ d ′ .By Lemma 5, the soundness of D implies Rej(v, D) ≥ δd ′ .By Equation 7,

Locally Testable Codes from Derandomized Hypercubes
We show how to start from a Cayley graph on A = F h 2 and a set of generators for A * and get a locally testable code from it.Our construction takes a Cayley graph Cay(A, D ′ ) and a (d, µ, ν)-spectrum generator B * .
We define the locally testable code C by specifying the dual code C ⊥ and the tester D. We view elements α ∈ A as messages, and embed them into F n 2 using the map Since B * generates A * , the mapping f is injective.Its image is a h-dimensional subspace of F n 2 which we denote by C ⊥ .The LTC will be C, which is the dual of C ⊥ .The distribution D ′ on A induces a distribution D = f (α) α∈D ′ on C ⊥ , which is the tester for C.
We observe that g(b Since B * is d-wise independent, so is Ē, which by Lemma 5 implies that C has distance d.This also implies that for any a ∈ A * , • Large Eigenvalues Imply Smoothness.In order to bound the smoothness of D we need to bound We have • Spectral decay implies soundness. for a ∈ A * , so that rank B * (g(a)) ≥ d ′ .From the spectral decay property of B * , The soundness of the tester follows by noting that

Some consequences of this equivalence
This equivalence lets us reformulate questions regarding LTCs as questions regarding the existence of certain families of derandomized hypercubes.
Corollary 16.There exists an asymptotically good family of codes {C n } where C n has blocklength n and is (O(1/n), Ω(1/n))-locally testable iff for infintitely many h there exists a Cayley graph G h = Cay(F h 2 , D) and a set B * of generators for (F h 2 ) * such that • the elements of B * are (ρ 0 h)-wise independent for ρ 0 > 0, • |B * | ≥ ρ 1 h for ρ 1 > 1, • B * is an (O(1/h), Ω(1/h))-spectrum generator for G h .Next we show that derandomized hypercubes are small-set expanders.We say that a regular graph G with n vertices is a (τ, φ)-expander if for every set S of at most τ n vertices, at least a fraction φ of the edges incident to S leave S (i.e. are on the boundary between S and S).
The following lemma says that if a graph has a (µ, ν) spectrum generator, then it is a (τ, φ)-expander for appropriately chosen τ and φ.The lemma is proved in [BGH + 12].Since our terminology and notation is different, we present a proof of the Lemma in Appendix B.
To interpret the expansion bound, think of νd/4 = Ω(1) (we can assume that the graphs obtained from LTCs have this property, since this is analogous to saying that words at distance d/4 are rejected with constant probability).So if we take τ = exp(−d), then φ τ = Ω(1).A particularly interesting instantiation of this bound is obtained by combining Corollary 17 and Lemma 18: In contrast, Arora et al. [ABS10] showed that if G is an (τ, Ω(1))-expander, then there are at most n O(ǫ) /τ eigenvalues greater than 1 − ǫ.

B Proof of Lemma 18
We first show the follow hypercontractive inequality: We now proceed to prove Lemma 18.
Proof of Lemma 18.For any two functions f, g : F h 2 → R, define their inner-product as and the p-norm of f to be For every function f : F h 2 → R with Fourier expansion x =y∈C d(x, y) = min x∈C−{0,} |x|, where d(•, •) denotes Hamming distance and | • | denotes Hamming weight.
wise linearly independent and the shortest path metric on G embeds into ℓ 1 with distortion O(1).Corollary 3.For a constant d, there is a distance d LTC of blocklength n with rate k = n − c d log n and ε/δ = O(1) iff there is a Cayley graph G = Cay(F h 2 , S) with |S| = 2 h/c d such that S is d-wise linearly independent and the shortest path metric on G embeds into ℓ 1 with distortion O(1).

:
A basis tester for a code C is a tester D which is supported on a basis for C. Ben-Sasson et al. showed a strong lower bound for such testers [BSGK + 10].Their main result when restated in our notation says: Theorem 12. [BSGK + 10, Theorem 5] Let C be an [n, k, d] 2 code with an (ε, δ)-basis tester.Then

Theorem 15 .
Let Cay(A = F h 2 , D ′ ) be a Cayley graph and let B * = {b 1 , . . ., b n } be a d-wise independent (µ, ν)-spectrum generator for it.Let C be the dual of the code specified by Equation 8. Then C is an [n, n − h, d] 2 linear code and D is a (µ/2, ν/2)-tester for C.
⇐⇒ g(a) = i∈S ēi Hence by Lemma 5, we have d(g(a), C) = rank B * (a).We can now deduce the local testability of C from the spectral properties of B * .

Corollary 17 .
Let d ≥ 3.There exists an asymptotic family of codes {C n } where C n has parameters [n, n − c d log n, d] 2 and is (ε, Ω(ε))-locally testable iff for infinitely many h there exists a Cayley graph G h = Cay(F h 2 , D) and a set B * of generators for (F h 2 ) * such that • the elements of B * are d-wise independent,•|B * | ≥ 2 h/c d ,• B * is an (ε, Ω(ε))-spectrum generator for G h .

Corollary 19 .
For d ≥ 3, suppose there exists an asymptotic family of codes {C n } where C n has parameters [n, n − c d log n, d] 2 and is (O(1/d), Ω(1/d))-locally testable.There for infinitely many h there exists a Cayley graph G h = Cay(F h 2 , D) such that G h is (O(9 −d ), Ω(1))-expander and has 2 h/c d eigenvalues greater than 1 − O(1/d).
Their bound implies that the graph G h obtained in Corollary 19 can have at most 2 O(h/d) eigenvalues greater than 1 − O(1/d).If there exist LTCs where c d = O(d), the resulting graphs G h would meet the ABS bound.The only lower bound we know of for c d is c d ≥ d/2 by the Hamming bound.
Here we are interested in codes where the minimum distance d is a fixed constant, and the traditional coding question is how large the rate k can be as n → ∞.BCH codes have (optimal) rate k = n − (d/2) • log n, but do not have any local testability properties.Reed-Muller codes yield the best known locally testable codes in this regime, with rate k = n − O((log n) log d ) and query complexity q = O(n/d) to achieve soundness δ = Ω(1/d) [BKS + 10]. 1 (This query complexity is optimal, as Ω(n/d) queries is needed to detect d/2 random corruptions to a codeword with constant probability.)An open problem is whether rate k = n − c d • log n is possible, for some constant c d depending only on d (but not on n).