{"id":"efab743d-c473-40b3-a673-fe306e849706","arxiv_id":"1909.01900","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Adding trivial 'always pass' tests lets any pure quantum state be verified against an adversarial device with at most a constant-factor overhead over nonadversarial verification.","lead":"This paper develops a general framework for verifying quantum states when the device is controlled by a malicious adversary, and proves that mixing in trivial 'always pass' tests makes verification nearly as efficient as in the trusted-device setting. It settles the resource cost of adversarial quantum state verification and gives a recipe that works for arbitrary pure states, including with local measurements.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"All central theorems are stated without proof and deferred to companion [26], so the advertised overhead bound in Theorem 6 cannot be checked from this letter; the central claim is conditional on an external document.","rationale":"The reader's weakest assumption is exactly the deferred proof, and my read agrees fully. I attempted to find a more technical weakness. One tempting counterexample uses a product state sigma_A tensor phi_perp_B to drive the conditional fidelity to zero, but this state is not permutation invariant, and because the protocol randomizes which system is tested, the reduction to symmetric rho disposes of it. A second concern was that for p=nu/e and tau close to beta, tau_p ln(1/tau_p) could drop below the tau=0 value, making h larger than h(nu/e,nu,0); this cannot happen because tau<=beta and beta_p=1-nu+nu^2/e is minimized at nu=1 with value 1/e, so the minimum of the two x ln(1/x) terms is never below the value used in Eq. (25). The internal logic is therefore consistent. The remaining issue is external support: Theorems 1-6 and Lemma 1 have no proofs in this text, and the companion paper [26] is the only warrant for the central bound. Since that companion exists and is published, the appropriate disposition is to keep the reader's conditional verdict pending verification of the deferred proofs. No change to the verdict is needed.","tokens_in":8761,"tokens_out":20629,"duration_ms":214679,"concrete_test":"Independently re-derive Theorem 6 from Eq. (17) with p=nu/e, and prove the pointwise inequalities h(nu/e,nu,0)<=1/((1-nu+nu^2/e)nu) and nu h(nu/e,nu,0)<=e for 0<nu<=1 using Eq. (22). If either inequality fails at any nu, the overhead-e bound in Eq. (25) is invalid; if both hold, the central quantitative claim is confirmed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper explicitly states that it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' Theorems 1-6 and Lemma 1 are therefore statements, not demonstrated results, in this text. The central claim is Theorem 6: with the hedging probability p=nu/e, N(epsilon,delta,Omega_p) < h(nu/e,nu,0) ln((F delta)^-1)/epsilon <= ln((F delta)^-1)/((1-nu+e^-1 nu^2) nu epsilon), giving a universal overhead factor at most e asymptotically and at most 3 for epsilon,delta<=0.1. Correctness of this theorem depends on the companion derivation, including the monotonicity of h(nu/e,nu,0) and nu h(nu/e,nu,0). I checked the internal logic and did not find a contradiction: apparent counterexamples vanish when permutation invariance is enforced, and the concern that tau_p near 1 could make h large is bounded because tau<=beta and beta_p=1-nu+nu^2/e>=1/e, so the worst case for the min is indeed tau=0. Nevertheless, none of the proofs are present, so a reader of the preprint cannot independently verify the central claim. This is a verifiability and support concern, not a discovered mathematical error.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper treats efficient verification of pure quantum states in the adversarial scenario, where the source is controlled by a potentially malicious adversary and may produce correlated or entangled states. It defines the figures of merit F(N,δ,Ω) and N(ε,δ,Ω), derives explicit formulas for homogeneous strategies (Theorems 1–3), general nonsingular verification operators (Lemma 1, Theorems 4–5), and proposes a hedging recipe in which a trivial test is performed with probability p (Eq. (19)). The central result, Theorem 6, states that for p=ν/e or p∈[p∗(ν,τ),p∗(ν)], the number of tests obeys N(ε,δ,Ω_p)<h(ν/e,ν,0) ln((Fδ)^{-1})/ε ≤ ln((Fδ)^{-1})/((1−ν+e^{-1}ν^2)νε), giving an asymptotic overhead factor at most e relative to the nonadversarial case and at most 3 for ε,δ≤1/10. The letter explicitly defers all proofs to the companion paper [26].","tokens_in":9045,"tokens_out":10138,"duration_ms":102336,"significance":"If the stated results are correct, the paper would settle a natural open question: adversarial pure-state verification is at most a constant factor more expensive than nonadversarial verification, for arbitrary pure states and with the same measurement settings. The analysis is parameter-free and the bounds are explicit and falsifiable, with concrete applications to bipartite pure states, stabilizer states, hypergraph states, weighted graph states, and Dicke states. The known limits in Eq. (8) and Eq. (3) are recovered correctly. The main caveat is that the advertised scaling and the factor-e/3 overhead are conditional on the companion paper, since none of the theorems are proved in this letter.","major_comments":[{"comment":"The letter states that it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' As a result, Theorems 1–6 and Lemma 1 are presented without proof, and the central claim in Theorem 6 and Eq. (25) cannot be verified from this manuscript. The monotonicity assertions in the paragraph after Eq. (26) — namely that h(ν/e,ν,0) decreases monotonically in ν and that νh(ν/e,ν,0) increases monotonically with νh≤e — are also load-bearing and are likewise deferred. This is a verifiability problem for the advertised universal overhead bound, not merely a presentation issue. Please include proofs or detailed derivations for the key statements in the letter itself or in a specifically accessible supplement, or otherwise identify precisely which results in [26] imply each theorem and provide the necessary ingredients.","section":"Introduction and Sections 'Homogeneous strategies', 'General verification strategies', 'Recipe to constructing…"},{"comment":"The displayed inequality in Eq. (23) appears to have a sign error as typeset. For 0<ε,δ<1, the right-hand side is written as νh(p,ν,τ)[ln(1−νǫ)]^{-1} ln(Fδ)/(νǫ lnδ), which is negative because ln(1−νǫ)<0 and ln(Fδ)/lnδ>0, while the left-hand side N(ε,δ,Ω_p)/N_NA(ε,δ,Ω) is positive. Please replace [ln(1−νǫ)]^{-1} with −ln(1−νǫ) (equivalently ln((1−νǫ)^{-1})) in the numerator and check the placement of ν in the prefactor. Since this equation underlies the overhead comparisons and Figure 2, it must be corrected and re-derived before the finite-precision claims are accepted.","section":"Recipe to constructing efficient protocols, Eq. (23)"}],"minor_comments":[{"comment":"In the second paragraph, 'the target state can alway pass the test' should read 'the target state can always pass the test'.","section":"Verification of a pure state"},{"comment":"The definition of Ñ(ǫ,δ,λ,k) in Eq. (10) is not legible in the current typeset: the exponents on kν and on λ are rendered ambiguously. Please ensure the equation is typeset with clear superscripts.","section":"Homogeneous strategies, Eq. (10)"},{"comment":"The symbol F is used both for the fidelity Fρ in Eq. (4) and for F=1−ǫ in Eqs. (10), (17), and (21). This is a potential source of confusion; please introduce a separate notation for one of the two quantities.","section":"General verification strategies and Recipe"},{"comment":"The caption refers to the approximate formula '(ln δ)/(λǫ ln λ)' without derivation; please add a reference to Eq. (13) or define the approximation in the caption.","section":"Figure 1 caption"}],"recommendation":"major_revision","confidential_remarks":"The main barrier is verifiability: all central theorems and the key monotonicity estimates are contained in the companion paper [26], so a reviewer of this letter cannot check the advertised result. If the companion paper is accessible to the reviewers, the Editor may wish to obtain it before final evaluation. I also recommend that the authors fix Eq. (23) and supply a proof appendix or explicit mapping to results in [26] during revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe paper is worth your time. It gives a clean, general recipe for adversarial quantum state verification: take any nonadversarial protocol with spectral gap ν, add the trivial test with probability p=ν/e, and the number of tests needed to achieve infidelity ǫ and significance δ is at most a constant factor e (and at most 3 for ǫ,δ≤1/10) over the nonadversarial case. That claim resolves the resource-cost question for arbitrary pure states, and the recipe is simple enough to use.\n\nWhat is actually new: the hedging construction, the definition of F(N,δ,Ω), the exact formulas for homogeneous strategies, and the lower-bound technique behind the resource count. The formulas match known limits: λ=0 recovers Eq. (8), and the nonadversarial case is recovered in the appropriate limit. The paper does not oversell—it is explicit that the proofs live in the companion PRA paper [26], which also contains the technical details. The internal logic I checked is consistent: the apparent counterexamples vanish when permutation invariance is imposed, and the τ→0 boundary is controlled by τ≤β and βp≥1/e.\n\nSoft spots, in proportion. The big one is that this letter states Theorems 1–6 without proof. A reader of the arXiv letter alone cannot verify Theorem 6; the derivation is in a separate publication by the same authors. That companion is published and checkable, so this is a verifiability issue rather than a discovered error, but a referee must read both documents. Some monotonicity claims (\"analysis shows\") are also deferred. The notation is dense, and the letter would be hard to use without the companion. None of this undermines the central argument as far as I can tell.\n\nWho this is for: anyone working on quantum state verification, blind MBQC, or quantum networks. The result is significant and likely correct. I would not desk-reject it; it deserves a serious referee, with the explicit instruction that the referee must check the proofs in [26] before accepting. If those proofs hold up, this is a solid contribution.","headline":"A compact letter with a simple, general recipe that likely solves adversarial state verification with constant-factor overhead, but all proofs are deferred to a companion paper, so the referee must read both.","tokens_in":9551,"tokens_out":2360,"would_cite":true,"duration_ms":22273,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.-a","03.67.Lx"],"model":"deepseek-v4-flash","headline":"This paper establishes that a trivial-test hedging recipe verifies any pure state in the adversarial scenario with at most a factor of e times the nonadversarial test count, and at most 3 times when the infidelity and significance level…","keywords":["quantum state verification","adversarial scenario","pure states","spectral gap","trivial test","hedging","blind measurement-based quantum computation","fidelity guarantee"],"falsifier":"For a qubit target, take the homogeneous strategy with $\\lambda=e^{-1}$ and ask whether the claimed bound $N(\\epsilon,\\delta,\\lambda=e^{-1})\\approx e\\,\\epsilon^{-1}\\ln\\delta^{-1}$ survives an explicit adversary: construct a permutation-invariant ensemble that passes $N$ tests with probability at least $\\delta$ but leaves the unmeasured system with fidelity below $1-\\epsilon$, and evaluate Theorem 1's exact formula for $F(N,\\delta,\\lambda)$ at $\\epsilon=\\delta=0.1$. A state achieving such a violation would disprove the central overhead claim.","tokens_in":8565,"feed_emoji":"⚛️","tokens_out":14205,"duration_ms":124323,"temperature":0.7,"pith_summary":"Verifying a pure quantum state is harder when the device producing it is adversarial: the output systems may be correlated or entangled, so guarantees that assume independent runs no longer apply. This paper builds a general framework for adversarial quantum state verification and derives formulas for the minimum number of tests needed to certify a given infidelity $\\epsilon$ and significance level $\\delta$. The central recipe is to take any nonadversarial verification strategy, with spectral gap $\\nu$, and hedge it by performing a trivial test—one every state passes—with probability $p=\\nu/e$. With this recipe every pure state can be verified in the adversarial scenario with the same asymptotic scaling in $\\epsilon$ and $\\delta$ as in the nonadversarial scenario, and the overhead is at most a factor $e$ (at most 3 when $\\epsilon,\\delta\\le 1/10$). This matters because efficient adversarial verification is a bottleneck for applications such as blind measurement-based quantum computation and quantum networks.","feed_headline":"Hedging with trivial tests caps adversarial verification overhead at e","feed_subtitle":"Mixing in a pass-all test restores near-optimal scaling against adversarial quantum state sources.","key_machinery":"The central object is the hedged verification operator $\\Omega_p=p\\mathbf{1}+(1-p)\\Omega$, built by performing a trivial test—the identity operator, which every state passes—with probability $p$ and the original strategy $\\Omega$ with probability $1-p$. Hedging makes $\\Omega_p$ nonsingular and rebalances its extreme eigenvalues so that the factor $\\tilde{\\beta}\\ln\\tilde{\\beta}^{-1}$ in the asymptotic $N\\approx(\\ln\\delta)/(\\epsilon\\tilde{\\beta}\\ln\\tilde{\\beta}^{-1})$ is kept near its optimum. The paper shows that the choice $p=\\nu/e$ is nearly optimal and requires no knowledge of the smallest eigenvalue $\\tau$, because it lifts the second-largest eigenvalue toward the optimal plateau $\\beta_p\\approx e^{-1}$ without letting the smallest eigenvalue dominate; for homogeneous strategies $\\Omega=|\\Psi\\rangle\\langle\\Psi|+\\lambda(\\mathbf{1}-|\\Psi\\rangle\\langle\\Psi|)$, the optimal nontrivial parameter is $\\lambda=e^{-1}$. This mechanism is what converts an arbitrary nonadversarial verification protocol into an adversarial one at constant overhead.","core_discovery":"Suppose a source is meant to emit $|\\Psi\\rangle$ but is controlled by an adversary who can prepare an arbitrary permutation-invariant state $\\rho$ over $N+1$ systems. A verification strategy is a convex combination $\\Omega=\\sum_l \\mu_l E_l$ of two-outcome tests, with $\\Omega|\\Psi\\rangle=|\\Psi\\rangle$; its efficiency is governed by the spectral gap $\\nu=1-\\beta$, where $\\beta$ is the second largest eigenvalue of $\\Omega$. The paper defines $F(N,\\delta,\\Omega)$ as the minimal guaranteed fidelity of the unmeasured system conditional on $N$ randomly chosen test systems passing with probability at least $\\delta$, and $N(\\epsilon,\\delta,\\Omega)$ as the minimal $N$ for which that fidelity reaches $1-\\epsilon$. It shows that for nonsingular $\\Omega$ the high-precision cost is $N\\approx (\\ln \\delta)/(\\epsilon\\,\\tilde{\\beta}\\ln\\tilde{\\beta}^{-1})$, with $\\tilde{\\beta}$ fixed by the two extreme eigenvalues. The main discovery is that replacing $\\Omega$ by the hedged operator $\\Omega_p=p\\mathbf{1}+(1-p)\\Omega$ with $p=\\nu/e$ yields $N(\\epsilon,\\delta,\\Omega_p)< h(\\nu/e,\\nu,0)\\ln((1-\\epsilon)\\delta)^{-1}/\\epsilon \\le \\ln((1-\\epsilon)\\delta)^{-1}/\\big((1-\\nu+e^{-1}\\nu^2)\\nu\\epsilon\\big)$, giving optimal scaling in both $\\epsilon$ and $\\delta$; the corresponding overhead factor $\\nu h(\\nu/e,\\nu,0)$ lies strictly between 1 and $e$, and is at most 3 when $\\epsilon,\\delta\\le1/10$.","pith_inferences":["Editorial inference: the recipe implies that future improvements to nonadversarial verification automatically improve adversarial verification, so research effort can focus on nonadversarial protocols without a separate adversarial analysis.","Editorial inference: since the optimal hedging probability does not depend on the smallest eigenvalue $\\tau$, the scheme should remain nearly optimal for imperfectly characterized verification operators, where only the spectral gap is known.","Editorial inference: the same constant-factor argument likely extends to verification of other quantum resources (e.g., subspaces or channels) whenever the verification operator has a nonzero spectral gap, though the paper itself treats pure states.","Editorial inference: a direct numerical check of Theorem 1's formula for small $N$ and $\\lambda=e^{-1}$ against adversarial ensembles would test how tight the constant $e$ is outside the asymptotic regime."],"forward_implications":["Any pure state with an efficient nonadversarial verification protocol inherits an adversarial protocol using the same measurement settings plus one trivial test, with overhead at most a factor $e$ (and at most 3 for $\\epsilon,\\delta\\le1/10$).","Bipartite pure states can be verified adversarially with local projective measurements using only $\\lceil e\\,\\epsilon^{-1}\\ln\\delta^{-1}\\rceil$ tests, matching the nonadversarial count up to $e$.","Stabilizer states (including graph states) require about $3\\,\\epsilon^{-1}\\ln\\delta^{-1}$ tests, while hypergraph states, weighted graph states, and Dicke states require about $n\\,\\epsilon^{-1}\\ln\\delta^{-1}$ tests, where $n$ is the number of qubits.","The adversarial test count scales optimally as $\\epsilon^{-1}\\ln\\delta^{-1}$, the same dependence on precision and significance as the nonadversarial setting, so increasing the required confidence does not change the constant-factor overhead.","Because the trivial-test probability $p=\\nu/e$ depends only on the spectral gap, the recipe can be applied without computing the full spectrum of $\\Omega$."],"supporting_citations":[{"why":"Supplies the nonadversarial verification sample-complexity formula against which the adversarial overhead bound is measured.","marker":"[7]"},{"why":"Contains the proofs of all theorems stated in this letter, including Theorem 6; the central bound depends on its derivations.","marker":"[26]"},{"why":"Represents the previous many-qubit verification approach with much larger test counts, used as the baseline that Theorem 4 improves on.","marker":"[24]"},{"why":"Provides the earlier hypergraph-state verification method whose large test counts motivate the new recipe.","marker":"[23]"},{"why":"The efficient bipartite-state verification protocol that, combined with the recipe, yields the claimed optimal adversarial protocols.","marker":"[9]"},{"why":"The nonadversarial hypergraph-state verification protocol used to demonstrate the recipe's application to hypergraph states.","marker":"[16]"}],"fun_headline_variants":["Adversarial state verification made near-optimal with a trivial test","Hedging with a pass-all test limits adversarial overhead to e","Trivial tests restore efficient verification against adversarial sources","Efficient adversarial verification: one tweak, overhead at most e","Near-optimal adversarial verification via a trivial test mix"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The letter states all six theorems without proofs and defers every derivation to a separate companion paper, so the central overhead bound stands or falls with the correctness of that external document.","fun_headline_variants_meta":{"raw":{"variants":["Adversarial state verification made near-optimal with a trivial test","Hedging with a pass-all test limits adversarial overhead to e","Trivial tests restore efficient verification against adversarial sources","Efficient adversarial verification: one tweak, overhead at most e","Near-optimal adversarial verification via a trivial test mix"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000362,"raw_usage":{"total_tokens":1989,"prompt_tokens":1018,"completion_tokens":971,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":634,"completion_tokens_details":{"reasoning_tokens":887}},"tokens_in":634,"tokens_out":971,"duration_ms":9656,"temperature":1.0,"reasoning_tokens":887,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T05:04:47.733598+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"For a qubit target, take the homogeneous strategy with $\\lambda=e^{-1}$ and ask whether the claimed bound $N(\\epsilon,\\delta,\\lambda=e^{-1})\\approx e\\,\\epsilon^{-1}\\ln\\delta^{-1}$ survives an explicit adversary: construct a permutation-invariant ensemble that passes $N$ tests with probability at least $\\delta$ but leaves the unmeasured system with fidelity below $1-\\epsilon$, and evaluate Theorem 1's exact formula for $F(N,\\delta,\\lambda)$ at $\\epsilon=\\delta=0.1$. A state achieving such a violation would disprove the central overhead claim.","supporting_citations":[{"cited_title":"Optimal veriﬁcation of entangled states with local measurements,","cited_arxiv_id":null,"evidence_quote":"Supplies the nonadversarial verification sample-complexity formula against which the adversarial overhead bound is measured."},{"cited_title":"General framework for verifying pure quantum states in the adversarial scenario,","cited_arxiv_id":null,"evidence_quote":"Contains the proofs of all theorems stated in this letter, including Theorem 6; the central bound depends on its derivations."},{"cited_title":"Veriﬁcation of many-qubit states,","cited_arxiv_id":null,"evidence_quote":"Represents the previous many-qubit verification approach with much larger test counts, used as the baseline that Theorem 4 improves on."},{"cited_title":"Veriﬁcation of hypergraph states,","cited_arxiv_id":null,"evidence_quote":"Provides the earlier hypergraph-state verification method whose large test counts motivate the new recipe."},{"cited_title":"Eﬃcient veriﬁcation of bipartite pure states,","cited_arxiv_id":null,"evidence_quote":"The efficient bipartite-state verification protocol that, combined with the recipe, yields the claimed optimal adversarial protocols."},{"cited_title":"Eﬃcient veriﬁcation of hyper- graph states,","cited_arxiv_id":null,"evidence_quote":"The nonadversarial hypergraph-state verification protocol used to demonstrate the recipe's application to hypergraph states."}],"review_version":1}