C-4.2 Example
Suppose we have the following LWE setup:
Now, suppose we want modulus switching from
to
, which
gives:
Now, verify if the following LWE constraint holds:
We got this small difference of 1 due to the rounding drift error of
and
.
If we solve the LWE decryption formula:
,
which is correct.