Paper 2025/1876

SoK: Lookup Table Arguments

Hossein Hafezi, New York University
Gaspard Anthoine, IMDEA Software
Matteo Campanelli, Offchain Labs
Dario Fiore, IMDEA Software
Abstract

Lookup arguments have become a central tool in proof systems, powering a range of practical applications. They enable the efficient enforcement of non-native operations, such as bit decomposition, range checks, comparisons, and floating-point arithmetic. They underpin zk-VMs by modelling instruction tables, provide set membership proofs in stateful computations, and strengthen extractors by ensuring witnesses belong to small domains. Despite these broad uses, existing lookup constructions vary widely in assumptions, efficiency, and composability. In this work, we systematize the design of lookup arguments and the cryptographic primitives they rely on. We introduce a unified and modular framework that covers standard, projective, indexed, vector, and decomposable lookups. We classify existing protocols by proof technique—multiset equality, Logup-based, accumulators, and subvector extraction (matrix–vector)—as well as by composition style. We survey and evaluate existing protocols along dimensions such as prover cost, dependence on table size, and compatibility with recursive proofs. From this analysis, we distill lessons and guidelines for choosing lookup constructions in practice and highlight the benefits and limitations of emerging directions in literature, such as preprocessing and decomposability.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Minor revision. Financial Cryptography 2026
Keywords
lookupssnarkssok
Contact author(s)
h hafezi @ nyu edu
gaspard anthoine @ imdea org
binarywhalesinternaryseas @ gmail com
dario fiore @ imdea org
History
2026-02-03: last of 3 revisions
2025-10-08: received
See all versions
Short URL
https://ia.cr/2025/1876
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1876,
      author = {Hossein Hafezi and Gaspard Anthoine and Matteo Campanelli and Dario Fiore},
      title = {{SoK}: Lookup Table Arguments},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1876},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1876}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.