Pith. sign in

REVIEW 2 major objections 4 minor 2 cited by

Efficient Verification of Pure Quantum States in the Adversarial Scenario

T0 review · 2 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read This paper establishes that a trivial-test hedging recipe verifies any pure state in the adversarial scenario with at most a factor of e times the nonadversarial test count, and at most 3 times when the infidelity and significance level…

desk verdict A compact letter with a simple, general recipe that likely solves adversarial state verification with constant-factor overhead, but all proofs are deferred to a companion paper, so the referee must read both. read the letter →

arxiv 1909.01900 v2 pith:CJJRIPWU submitted 2019-09-04 quant-ph math-phmath.MP

classification quant-phmath-phmath.MP PACS 03.67.-a03.67.Lx
keywords quantumstateverificationadversarialscenariopurestatesspectralgaptrivialtesthedgingblindmeasurement-basedcomputationfidelityguarantee
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Verifying a pure quantum state is harder when the device producing it is adversarial: the output systems may be correlated or entangled, so guarantees that assume independent runs no longer apply. This paper builds a general framework for adversarial quantum state verification and derives formulas for the minimum number of tests needed to certify a given infidelity $\epsilon$ and significance level $\delta$. The central recipe is to take any nonadversarial verification strategy, with spectral gap $\nu$, and hedge it by performing a trivial test—one every state passes—with probability $p=\nu/e$. With this recipe every pure state can be verified in the adversarial scenario with the same asymptotic scaling in $\epsilon$ and $\delta$ as in the nonadversarial scenario, and the overhead is at most a factor $e$ (at most 3 when $\epsilon,\delta\le 1/10$). This matters because efficient adversarial verification is a bottleneck for applications such as blind measurement-based quantum computation and quantum networks.

What carries the argument

The central object is the hedged verification operator $\Omega_p=p\mathbf{1}+(1-p)\Omega$, built by performing a trivial test—the identity operator, which every state passes—with probability $p$ and the original strategy $\Omega$ with probability $1-p$. Hedging makes $\Omega_p$ nonsingular and rebalances its extreme eigenvalues so that the factor $\tilde{\beta}\ln\tilde{\beta}^{-1}$ in the asymptotic $N\approx(\ln\delta)/(\epsilon\tilde{\beta}\ln\tilde{\beta}^{-1})$ is kept near its optimum. The paper shows that the choice $p=\nu/e$ is nearly optimal and requires no knowledge of the smallest eigenvalue $\tau$, because it lifts the second-largest eigenvalue toward the optimal plateau $\beta_p\approx e^{-1}$ without letting the smallest eigenvalue dominate; for homogeneous strategies $\Omega=|\Psi\rangle\langle\Psi|+\lambda(\mathbf{1}-|\Psi\rangle\langle\Psi|)$, the optimal nontrivial parameter is $\lambda=e^{-1}$. This mechanism is what converts an arbitrary nonadversarial verification protocol into an adversarial one at constant overhead.

What would settle it

For a qubit target, take the homogeneous strategy with $\lambda=e^{-1}$ and ask whether the claimed bound $N(\epsilon,\delta,\lambda=e^{-1})\approx e\,\epsilon^{-1}\ln\delta^{-1}$ survives an explicit adversary: construct a permutation-invariant ensemble that passes $N$ tests with probability at least $\delta$ but leaves the unmeasured system with fidelity below $1-\epsilon$, and evaluate Theorem 1's exact formula for $F(N,\delta,\lambda)$ at $\epsilon=\delta=0.1$. A state achieving such a violation would disprove the central overhead claim.

Watch

Extended reading notes

Core claim

Suppose a source is meant to emit $|\Psi\rangle$ but is controlled by an adversary who can prepare an arbitrary permutation-invariant state $\rho$ over $N+1$ systems. A verification strategy is a convex combination $\Omega=\sum_l \mu_l E_l$ of two-outcome tests, with $\Omega|\Psi\rangle=|\Psi\rangle$; its efficiency is governed by the spectral gap $\nu=1-\beta$, where $\beta$ is the second largest eigenvalue of $\Omega$. The paper defines $F(N,\delta,\Omega)$ as the minimal guaranteed fidelity of the unmeasured system conditional on $N$ randomly chosen test systems passing with probability at least $\delta$, and $N(\epsilon,\delta,\Omega)$ as the minimal $N$ for which that fidelity reaches $1-\epsilon$. It shows that for nonsingular $\Omega$ the high-precision cost is $N\approx (\ln \delta)/(\epsilon\,\tilde{\beta}\ln\tilde{\beta}^{-1})$, with $\tilde{\beta}$ fixed by the two extreme eigenvalues. The main discovery is that replacing $\Omega$ by the hedged operator $\Omega_p=p\mathbf{1}+(1-p)\Omega$ with $p=\nu/e$ yields $N(\epsilon,\delta,\Omega_p)< h(\nu/e,\nu,0)\ln((1-\epsilon)\delta)^{-1}/\epsilon \le \ln((1-\epsilon)\delta)^{-1}/\big((1-\nu+e^{-1}\nu^2)\nu\epsilon\big)$, giving optimal scaling in both $\epsilon$ and $\delta$; the corresponding overhead factor $\nu h(\nu/e,\nu,0)$ lies strictly between 1 and $e$, and is at most 3 when $\epsilon,\delta\le1/10$.

Load-bearing premise

The letter states all six theorems without proofs and defers every derivation to a separate companion paper, so the central overhead bound stands or falls with the correctness of that external document.

Editorial extensions

If this is right

  • Any pure state with an efficient nonadversarial verification protocol inherits an adversarial protocol using the same measurement settings plus one trivial test, with overhead at most a factor $e$ (and at most 3 for $\epsilon,\delta\le1/10$).
  • Bipartite pure states can be verified adversarially with local projective measurements using only $\lceil e\,\epsilon^{-1}\ln\delta^{-1}\rceil$ tests, matching the nonadversarial count up to $e$.
  • Stabilizer states (including graph states) require about $3\,\epsilon^{-1}\ln\delta^{-1}$ tests, while hypergraph states, weighted graph states, and Dicke states require about $n\,\epsilon^{-1}\ln\delta^{-1}$ tests, where $n$ is the number of qubits.
  • The adversarial test count scales optimally as $\epsilon^{-1}\ln\delta^{-1}$, the same dependence on precision and significance as the nonadversarial setting, so increasing the required confidence does not change the constant-factor overhead.
  • Because the trivial-test probability $p=\nu/e$ depends only on the spectral gap, the recipe can be applied without computing the full spectrum of $\Omega$.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: the recipe implies that future improvements to nonadversarial verification automatically improve adversarial verification, so research effort can focus on nonadversarial protocols without a separate adversarial analysis.
  • Editorial inference: since the optimal hedging probability does not depend on the smallest eigenvalue $\tau$, the scheme should remain nearly optimal for imperfectly characterized verification operators, where only the spectral gap is known.
  • Editorial inference: the same constant-factor argument likely extends to verification of other quantum resources (e.g., subspaces or channels) whenever the verification operator has a nonzero spectral gap, though the paper itself treats pure states.
  • Editorial inference: a direct numerical check of Theorem 1's formula for small $N$ and $\lambda=e^{-1}$ against adversarial ensembles would test how tight the constant $e$ is outside the asymptotic regime.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The paper treats efficient verification of pure quantum states in the adversarial scenario, where the source is controlled by a potentially malicious adversary and may produce correlated or entangled states. It defines the figures of merit F(N,δ,Ω) and N(ε,δ,Ω), derives explicit formulas for homogeneous strategies (Theorems 1–3), general nonsingular verification operators (Lemma 1, Theorems 4–5), and proposes a hedging recipe in which a trivial test is performed with probability p (Eq. (19)). The central result, Theorem 6, states that for p=ν/e or p∈[p∗(ν,τ),p∗(ν)], the number of tests obeys N(ε,δ,Ω_p)<h(ν/e,ν,0) ln((Fδ)^{-1})/ε ≤ ln((Fδ)^{-1})/((1−ν+e^{-1}ν^2)νε), giving an asymptotic overhead factor at most e relative to the nonadversarial case and at most 3 for ε,δ≤1/10. The letter explicitly defers all proofs to the companion paper [26].

Significance. If the stated results are correct, the paper would settle a natural open question: adversarial pure-state verification is at most a constant factor more expensive than nonadversarial verification, for arbitrary pure states and with the same measurement settings. The analysis is parameter-free and the bounds are explicit and falsifiable, with concrete applications to bipartite pure states, stabilizer states, hypergraph states, weighted graph states, and Dicke states. The known limits in Eq. (8) and Eq. (3) are recovered correctly. The main caveat is that the advertised scaling and the factor-e/3 overhead are conditional on the companion paper, since none of the theorems are proved in this letter.

major comments (2)
  1. [Introduction and Sections 'Homogeneous strategies', 'General verification strategies', 'Recipe to constructing…] The letter states that it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' As a result, Theorems 1–6 and Lemma 1 are presented without proof, and the central claim in Theorem 6 and Eq. (25) cannot be verified from this manuscript. The monotonicity assertions in the paragraph after Eq. (26) — namely that h(ν/e,ν,0) decreases monotonically in ν and that νh(ν/e,ν,0) increases monotonically with νh≤e — are also load-bearing and are likewise deferred. This is a verifiability problem for the advertised universal overhead bound, not merely a presentation issue. Please include proofs or detailed derivations for the key statements in the letter itself or in a specifically accessible supplement, or otherwise identify precisely which results in [26] imply each theorem and provide the necessary ingredients.
  2. [Recipe to constructing efficient protocols, Eq. (23)] The displayed inequality in Eq. (23) appears to have a sign error as typeset. For 0<ε,δ<1, the right-hand side is written as νh(p,ν,τ)[ln(1−νǫ)]^{-1} ln(Fδ)/(νǫ lnδ), which is negative because ln(1−νǫ)<0 and ln(Fδ)/lnδ>0, while the left-hand side N(ε,δ,Ω_p)/N_NA(ε,δ,Ω) is positive. Please replace [ln(1−νǫ)]^{-1} with −ln(1−νǫ) (equivalently ln((1−νǫ)^{-1})) in the numerator and check the placement of ν in the prefactor. Since this equation underlies the overhead comparisons and Figure 2, it must be corrected and re-derived before the finite-precision claims are accepted.
minor comments (4)
  1. [Verification of a pure state] In the second paragraph, 'the target state can alway pass the test' should read 'the target state can always pass the test'.
  2. [Homogeneous strategies, Eq. (10)] The definition of Ñ(ǫ,δ,λ,k) in Eq. (10) is not legible in the current typeset: the exponents on kν and on λ are rendered ambiguously. Please ensure the equation is typeset with clear superscripts.
  3. [General verification strategies and Recipe] The symbol F is used both for the fidelity Fρ in Eq. (4) and for F=1−ǫ in Eqs. (10), (17), and (21). This is a potential source of confusion; please introduce a separate notation for one of the two quantities.
  4. [Figure 1 caption] The caption refers to the approximate formula '(ln δ)/(λǫ ln λ)' without derivation; please add a reference to Eq. (13) or define the approximation in the caption.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity found: all central quantities are derived from first-principles optimization, and reliance on the companion paper is a proof-deferral issue, not a circular reduction.

full rationale

The paper's derivation chain is mathematical and parameter-free. The nonadversarial bound in Eq. (3) follows from the spectral-gap expression in Eq. (1) and a product probability bound, neither of which is fitted. The adversarial figure of merit F(N, δ, Ω) is defined in Eq. (4) as a minimization over adversarial states, and the required number of tests N(ε, δ, Ω) is then defined by Eq. (5); there is no hidden input that equals the target conclusion. Theorems 1–6 and Lemma 1 state closed-form formulas in terms of the eigenvalues β, τ, and ν of the verification operator; these are not empirical parameters. In particular, the hedging probability p = ν/e in Theorem 6 is a simple closed-form choice, and the general optimizer p* is itself derived from a minimization problem in Eq. (24). The letter explicitly says it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' This is a deferral of proofs to the authors' companion paper, which is a completeness and verifiability concern, but not circularity: the companion is a parameter-free mathematical treatment with stated assumptions that do not include the target efficiency bound, and no claim here is equivalent by construction to an input assumption or to a fitted value. Accordingly, the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

No free parameters are fitted to data; the probability p in the hedging recipe is a derived choice (p = nu/e) and the overhead bounds are exact functions of the protocol's eigenvalues. The central claims rest on standard quantum mechanics and the deferred proofs in the companion paper [26].

assumptions (4)
  • domain assumption Quantum states are described by density operators on a Hilbert space, and measurements are two-outcome tests {E_l, 1 - E_l} with E_l|Psi> = |Psi> for the target state.
    Standard quantum mechanics; used to define the verification operator Omega and the pass probability.
  • domain assumption The adversary can produce an arbitrary, possibly entangled joint state on N+1 systems, and the verifier randomly chooses N systems to test.
    Defines the adversarial scenario; permutation invariance of the joint state follows from random selection and is used throughout the analysis.
  • domain assumption In the nonadversarial analysis, the device's outputs are independent; in the adversarial case, no independence is assumed.
    The nonadversarial bound in Eq. (2) assumes independent runs, while the adversarial framework drops this assumption, which is the key difference.
  • standard math Standard inequalities (Jensen, logarithmic bounds) and eigenvalue optimization are used in the proofs of Theorems 1 through 6.
    The theorems rely on these; the actual proofs are placed in the companion paper [26], but the letter states the results.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Efficient Verification of Pure Quantum States in the Adversarial Scenario." pith.science (2026). https://pith.science/paper/CJJRIPWU

@misc{pith2026190901900,
  author       = {Pith},
  title        = {Pith review of: Efficient Verification of Pure Quantum States in the Adversarial Scenario},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/CJJRIPWU}},
  note         = {Machine review of arXiv:1909.01900}
}
read the original abstract

Efficient verification of pure quantum states in the adversarial scenario is crucial to many applications in quantum information processing, such as blind measurement-based quantum computation and quantum networks. However, little is known about this topic so far. Here we establish a general framework for verifying pure quantum states in the adversarial scenario and clarify the resource cost. Moreover, we propose a simple and general recipe to constructing efficient verification protocols for the adversarial scenario from protocols for the nonadversarial scenario. With this recipe, arbitrary pure states can be verified in the adversarial scenario with almost the same efficiency as in the nonadversarial scenario. Many important quantum states can be verified in the adversarial scenario using local projective measurements with unprecedented high efficiencies.

Figures

Figures reproduced from arXiv: 1909.01900 by the authors.

Figure 1
Figure 1. FIG. 1. (color online) Number of tests [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. (color online) Overhead of QSV in the ad [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Device-Independent Self-Testing of the Three-Qubit CCZ Hypergraph State

    quant-ph 2026-07 accept novelty 6.0 of 10

    The CCZ hypergraph state and its Pauli measurements can be device-independently self-tested from twenty correlators, and also from maximal violation of a specially constructed Bell inequality.

  2. Efficient certification of intractable quantum states with few Pauli measurements

    quant-ph 2025-11 reject novelty 6.0 of 10

    The paper claims Clifford-enhanced product states can be certified with O(n^2/epsilon^2) Pauli measurements in the i.i.d. setting and polynomially many in the adversarial setting, but the central estimator is derived ...

Reference graph

Works this paper leans on

26 extracted references · 25 canonical work pages · cited by 2 Pith papers

  1. [26]

    General framework for verifying pure quantum states in the adversarial scenario,

    H. Zhu and M. Hayashi, “General framework for verifying pure quantum states in the adversarial scenario,” Phys. Rev. A 100, 062335 (2019)

  2. [1]

    Quantum entanglement,

    R. Horodecki, P. Horodecki, M. Horodecki, and K. Horodecki, “Quantum entanglement,” Rev. Mod. Phys. 81, 865 (2009)

  3. [2]

    Entanglement detection,

    O. Gühne and G. Tóth, “Entanglement detection,” Phys. Rep. 474, 1 (2009)

  4. [3]

    Quantum state tomography via compressed sensing,

    D. Gross, Y.-K. Liu, S. T. Flammia, S. Becker, and J. Eisert, “Quantum state tomography via compressed sensing,” Phys. Rev. Lett. 105, 150401 (2010)

  5. [4]

    Direct fidelity estimation from few Pauli measurements,

    S. T. Flammia and Y.-K. Liu, “Direct fidelity estimation from few Pauli measurements,” Phys. Rev. Lett. 106, 230501 (2011)

  6. [5]

    A study of LOCC-detection of a maximally entangled state using hypothesis testing,

    M. Hayashi, K. Matsumoto, and Y. Tsuda, “A study of LOCC-detection of a maximally entangled state using hypothesis testing,” J. Phys. A: Math. Gen. 39, 14427 (2006)

  7. [6]

    Group theoretical study of LOCC-detection of maximally entangled states using hypothesis testing,

    M. Hayashi, “Group theoretical study of LOCC-detection of maximally entangled states using hypothesis testing,” New J. Phys. 11, 043028 (2009)

  8. [7]

    Optimal verification of entangled states with local measurements,

    S. Pallister, N. Linden, and A. Montanaro, “Optimal verification of entangled states with local measurements,” Phys. Rev. Lett. 120, 170502 (2018)

Show all 26 references
  1. [8]

    Optimal verification and fidelity estimation of maximally entangled states,

    H. Zhu and M. Hayashi, “Optimal verification and fidelity estimation of maximally entangled states,” Phys. Rev. A 99, 052346 (2019)

  2. [9]

    Efficient verification of bipartite pure states,

    Z. Li, Y.-G. Han, and H. Zhu, “Efficient verification of bipartite pure states,” Phys. Rev. A 100, 032316 (2019)

  3. [10]

    Optimal verification of two- qubit pure states,

    K. Wang and M. Hayashi, “Optimal verification of two- qubit pure states,” Phys. Rev. A 100, 032315 (2019)

  4. [11]

    Optimal verification of general bipartite pure states,

    X.-D. Yu, J. Shang, and O. Gühne, “Optimal verification of general bipartite pure states,” npj Quantum Inf. 5, 112 (2019)

  5. [12]

    Verifiable measurement- only blind quantum computing with stabilizer testing,

    M. Hayashi and T. Morimae, “Verifiable measurement- only blind quantum computing with stabilizer testing,” Phys. Rev. Lett. 115, 220502 (2015)

  6. [13]

    Verifiable fault tolerance in measurement-based quantum computation,

    K. Fujii and M. Hayashi, “Verifiable fault tolerance in measurement-based quantum computation,” Phys. Rev. A 96, 030301(R) (2017)

  7. [14]

    Self-guaranteed measurement-based quantum computation,

    M. Hayashi and M. Hajdušek, “Self-guaranteed measurement-based quantum computation,” Phys. Rev. A 97, 052308 (2018)

  8. [15]

    A simple protocol for cer- tifying graph states and applications in quantum net- works,

    D. Markham and A. Krause, “A simple protocol for cer- tifying graph states and applications in quantum net- works,” (2018), arXiv:1801.05057

  9. [16]

    Efficient verification of hyper- graph states,

    H. Zhu and M. Hayashi, “Efficient verification of hyper- graph states,” Phys. Rev. Applied 12, 054047 (2019)

  10. [17]

    Verifying commut- ing quantum computations via fidelity estimation of weighted graph states,

    M. Hayashi and Y. Takeuchi, “Verifying commut- ing quantum computations via fidelity estimation of weighted graph states,” New J. Phys. 21, 093060 (2019)

  11. [18]

    Efficient verification of Dicke states,

    Y.-C. Liu, X.-D. Yu, J. Shang, H. Zhu, and X. Zhang, “Efficient verification of Dicke states,” Phys. Rev. Ap- plied 12, 044020 (2019)

  12. [19]

    Blind quantum computation protocol in which Alice only makes measurements,

    T. Morimae and K. Fujii, “Blind quantum computation protocol in which Alice only makes measurements,” Phys. Rev. A 87, 050301(R) (2013)

  13. [20]

    Quantum computational universality of hypergraph states with Pauli-X and Z basis measurements,

    Y. Takeuchi, T. Morimae, and M. Hayashi, “Quantum computational universality of hypergraph states with Pauli-X and Z basis measurements,” Sci. Rep. 9, 13585 (2019)

  14. [21]

    Distribution of entanglement in large-scale quantum networks,

    S. Perseguers, G. J. Lapeyre Jr, D. Cavalcanti, M. Lewen - stein, and A. Acín, “Distribution of entanglement in large-scale quantum networks,” Rep. Prog. Phys. 76, 096001 (2013)

  15. [22]

    Ex- perimental verification of multipartite entanglement in quantum networks,

    W. McCutcheon, A. Pappa, B. A. Bell, A. McMillan, A. Chailloux, T. Lawson, M. Mafu, D. Markham, E. Dia- manti, I. Kerenidis, J. G. Rarity, and M. S. Tame, “Ex- perimental verification of multipartite entanglement in quantum networks,” Nat. Commun. 7, 13251 (2016)

  16. [23]

    Verification of hypergraph states,

    T. Morimae, Y. Takeuchi, and M. Hayashi, “Verification of hypergraph states,” Phys. Rev. A 96, 062321 (2017)

  17. [24]

    Verification of many-qubit states,

    Y. Takeuchi and T. Morimae, “Verification of many-qubit states,” Phys. Rev. X 8, 021060 (2018)

  18. [25]

    Resource-efficient verification of quan- tum computing using Serfling’s bound,

    Y. Takeuchi, A. Mantri, T. Morimae, A. Mizutani, and J. F. Fitzsimons, “Resource-efficient verification of quan- tum computing using Serfling’s bound,” npj Quantum Inf. 5, 27 (2019)

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.