REVIEW 2 major objections 4 minor 2 cited by
Efficient Verification of Pure Quantum States in the Adversarial Scenario
T0 review · 2 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read This paper establishes that a trivial-test hedging recipe verifies any pure state in the adversarial scenario with at most a factor of e times the nonadversarial test count, and at most 3 times when the infidelity and significance level…
desk verdict A compact letter with a simple, general recipe that likely solves adversarial state verification with constant-factor overhead, but all proofs are deferred to a companion paper, so the referee must read both. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the hedged verification operator $\Omega_p=p\mathbf{1}+(1-p)\Omega$, built by performing a trivial test—the identity operator, which every state passes—with probability $p$ and the original strategy $\Omega$ with probability $1-p$. Hedging makes $\Omega_p$ nonsingular and rebalances its extreme eigenvalues so that the factor $\tilde{\beta}\ln\tilde{\beta}^{-1}$ in the asymptotic $N\approx(\ln\delta)/(\epsilon\tilde{\beta}\ln\tilde{\beta}^{-1})$ is kept near its optimum. The paper shows that the choice $p=\nu/e$ is nearly optimal and requires no knowledge of the smallest eigenvalue $\tau$, because it lifts the second-largest eigenvalue toward the optimal plateau $\beta_p\approx e^{-1}$ without letting the smallest eigenvalue dominate; for homogeneous strategies $\Omega=|\Psi\rangle\langle\Psi|+\lambda(\mathbf{1}-|\Psi\rangle\langle\Psi|)$, the optimal nontrivial parameter is $\lambda=e^{-1}$. This mechanism is what converts an arbitrary nonadversarial verification protocol into an adversarial one at constant overhead.
What would settle it
For a qubit target, take the homogeneous strategy with $\lambda=e^{-1}$ and ask whether the claimed bound $N(\epsilon,\delta,\lambda=e^{-1})\approx e\,\epsilon^{-1}\ln\delta^{-1}$ survives an explicit adversary: construct a permutation-invariant ensemble that passes $N$ tests with probability at least $\delta$ but leaves the unmeasured system with fidelity below $1-\epsilon$, and evaluate Theorem 1's exact formula for $F(N,\delta,\lambda)$ at $\epsilon=\delta=0.1$. A state achieving such a violation would disprove the central overhead claim.
Extended reading notes
Core claim
Suppose a source is meant to emit $|\Psi\rangle$ but is controlled by an adversary who can prepare an arbitrary permutation-invariant state $\rho$ over $N+1$ systems. A verification strategy is a convex combination $\Omega=\sum_l \mu_l E_l$ of two-outcome tests, with $\Omega|\Psi\rangle=|\Psi\rangle$; its efficiency is governed by the spectral gap $\nu=1-\beta$, where $\beta$ is the second largest eigenvalue of $\Omega$. The paper defines $F(N,\delta,\Omega)$ as the minimal guaranteed fidelity of the unmeasured system conditional on $N$ randomly chosen test systems passing with probability at least $\delta$, and $N(\epsilon,\delta,\Omega)$ as the minimal $N$ for which that fidelity reaches $1-\epsilon$. It shows that for nonsingular $\Omega$ the high-precision cost is $N\approx (\ln \delta)/(\epsilon\,\tilde{\beta}\ln\tilde{\beta}^{-1})$, with $\tilde{\beta}$ fixed by the two extreme eigenvalues. The main discovery is that replacing $\Omega$ by the hedged operator $\Omega_p=p\mathbf{1}+(1-p)\Omega$ with $p=\nu/e$ yields $N(\epsilon,\delta,\Omega_p)< h(\nu/e,\nu,0)\ln((1-\epsilon)\delta)^{-1}/\epsilon \le \ln((1-\epsilon)\delta)^{-1}/\big((1-\nu+e^{-1}\nu^2)\nu\epsilon\big)$, giving optimal scaling in both $\epsilon$ and $\delta$; the corresponding overhead factor $\nu h(\nu/e,\nu,0)$ lies strictly between 1 and $e$, and is at most 3 when $\epsilon,\delta\le1/10$.
Load-bearing premise
The letter states all six theorems without proofs and defers every derivation to a separate companion paper, so the central overhead bound stands or falls with the correctness of that external document.
Editorial extensions
If this is right
- Any pure state with an efficient nonadversarial verification protocol inherits an adversarial protocol using the same measurement settings plus one trivial test, with overhead at most a factor $e$ (and at most 3 for $\epsilon,\delta\le1/10$).
- Bipartite pure states can be verified adversarially with local projective measurements using only $\lceil e\,\epsilon^{-1}\ln\delta^{-1}\rceil$ tests, matching the nonadversarial count up to $e$.
- Stabilizer states (including graph states) require about $3\,\epsilon^{-1}\ln\delta^{-1}$ tests, while hypergraph states, weighted graph states, and Dicke states require about $n\,\epsilon^{-1}\ln\delta^{-1}$ tests, where $n$ is the number of qubits.
- The adversarial test count scales optimally as $\epsilon^{-1}\ln\delta^{-1}$, the same dependence on precision and significance as the nonadversarial setting, so increasing the required confidence does not change the constant-factor overhead.
- Because the trivial-test probability $p=\nu/e$ depends only on the spectral gap, the recipe can be applied without computing the full spectrum of $\Omega$.
Reading between the lines
- Editorial inference: the recipe implies that future improvements to nonadversarial verification automatically improve adversarial verification, so research effort can focus on nonadversarial protocols without a separate adversarial analysis.
- Editorial inference: since the optimal hedging probability does not depend on the smallest eigenvalue $\tau$, the scheme should remain nearly optimal for imperfectly characterized verification operators, where only the spectral gap is known.
- Editorial inference: the same constant-factor argument likely extends to verification of other quantum resources (e.g., subspaces or channels) whenever the verification operator has a nonzero spectral gap, though the paper itself treats pure states.
- Editorial inference: a direct numerical check of Theorem 1's formula for small $N$ and $\lambda=e^{-1}$ against adversarial ensembles would test how tight the constant $e$ is outside the asymptotic regime.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper treats efficient verification of pure quantum states in the adversarial scenario, where the source is controlled by a potentially malicious adversary and may produce correlated or entangled states. It defines the figures of merit F(N,δ,Ω) and N(ε,δ,Ω), derives explicit formulas for homogeneous strategies (Theorems 1–3), general nonsingular verification operators (Lemma 1, Theorems 4–5), and proposes a hedging recipe in which a trivial test is performed with probability p (Eq. (19)). The central result, Theorem 6, states that for p=ν/e or p∈[p∗(ν,τ),p∗(ν)], the number of tests obeys N(ε,δ,Ω_p)<h(ν/e,ν,0) ln((Fδ)^{-1})/ε ≤ ln((Fδ)^{-1})/((1−ν+e^{-1}ν^2)νε), giving an asymptotic overhead factor at most e relative to the nonadversarial case and at most 3 for ε,δ≤1/10. The letter explicitly defers all proofs to the companion paper [26].
Significance. If the stated results are correct, the paper would settle a natural open question: adversarial pure-state verification is at most a constant factor more expensive than nonadversarial verification, for arbitrary pure states and with the same measurement settings. The analysis is parameter-free and the bounds are explicit and falsifiable, with concrete applications to bipartite pure states, stabilizer states, hypergraph states, weighted graph states, and Dicke states. The known limits in Eq. (8) and Eq. (3) are recovered correctly. The main caveat is that the advertised scaling and the factor-e/3 overhead are conditional on the companion paper, since none of the theorems are proved in this letter.
major comments (2)
- [Introduction and Sections 'Homogeneous strategies', 'General verification strategies', 'Recipe to constructing…] The letter states that it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' As a result, Theorems 1–6 and Lemma 1 are presented without proof, and the central claim in Theorem 6 and Eq. (25) cannot be verified from this manuscript. The monotonicity assertions in the paragraph after Eq. (26) — namely that h(ν/e,ν,0) decreases monotonically in ν and that νh(ν/e,ν,0) increases monotonically with νh≤e — are also load-bearing and are likewise deferred. This is a verifiability problem for the advertised universal overhead bound, not merely a presentation issue. Please include proofs or detailed derivations for the key statements in the letter itself or in a specifically accessible supplement, or otherwise identify precisely which results in [26] imply each theorem and provide the necessary ingredients.
- [Recipe to constructing efficient protocols, Eq. (23)] The displayed inequality in Eq. (23) appears to have a sign error as typeset. For 0<ε,δ<1, the right-hand side is written as νh(p,ν,τ)[ln(1−νǫ)]^{-1} ln(Fδ)/(νǫ lnδ), which is negative because ln(1−νǫ)<0 and ln(Fδ)/lnδ>0, while the left-hand side N(ε,δ,Ω_p)/N_NA(ε,δ,Ω) is positive. Please replace [ln(1−νǫ)]^{-1} with −ln(1−νǫ) (equivalently ln((1−νǫ)^{-1})) in the numerator and check the placement of ν in the prefactor. Since this equation underlies the overhead comparisons and Figure 2, it must be corrected and re-derived before the finite-precision claims are accepted.
minor comments (4)
- [Verification of a pure state] In the second paragraph, 'the target state can alway pass the test' should read 'the target state can always pass the test'.
- [Homogeneous strategies, Eq. (10)] The definition of Ñ(ǫ,δ,λ,k) in Eq. (10) is not legible in the current typeset: the exponents on kν and on λ are rendered ambiguously. Please ensure the equation is typeset with clear superscripts.
- [General verification strategies and Recipe] The symbol F is used both for the fidelity Fρ in Eq. (4) and for F=1−ǫ in Eqs. (10), (17), and (21). This is a potential source of confusion; please introduce a separate notation for one of the two quantities.
- [Figure 1 caption] The caption refers to the approximate formula '(ln δ)/(λǫ ln λ)' without derivation; please add a reference to Eq. (13) or define the approximation in the caption.
Circularity Check
No circularity found: all central quantities are derived from first-principles optimization, and reliance on the companion paper is a proof-deferral issue, not a circular reduction.
full rationale
The paper's derivation chain is mathematical and parameter-free. The nonadversarial bound in Eq. (3) follows from the spectral-gap expression in Eq. (1) and a product probability bound, neither of which is fitted. The adversarial figure of merit F(N, δ, Ω) is defined in Eq. (4) as a minimization over adversarial states, and the required number of tests N(ε, δ, Ω) is then defined by Eq. (5); there is no hidden input that equals the target conclusion. Theorems 1–6 and Lemma 1 state closed-form formulas in terms of the eigenvalues β, τ, and ν of the verification operator; these are not empirical parameters. In particular, the hedging probability p = ν/e in Theorem 6 is a simple closed-form choice, and the general optimizer p* is itself derived from a minimization problem in Eq. (24). The letter explicitly says it 'extracts the key results in Ref. [26], which contains complete technical details and additional results, including the proofs of all statements presented here.' This is a deferral of proofs to the authors' companion paper, which is a completeness and verifiability concern, but not circularity: the companion is a parameter-free mathematical treatment with stated assumptions that do not include the target efficiency bound, and no claim here is equivalent by construction to an input assumption or to a fitted value. Accordingly, the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (4)
- domain assumption Quantum states are described by density operators on a Hilbert space, and measurements are two-outcome tests {E_l, 1 - E_l} with E_l|Psi> = |Psi> for the target state.
- domain assumption The adversary can produce an arbitrary, possibly entangled joint state on N+1 systems, and the verifier randomly chooses N systems to test.
- domain assumption In the nonadversarial analysis, the device's outputs are independent; in the adversarial case, no independence is assumed.
- standard math Standard inequalities (Jensen, logarithmic bounds) and eigenvalue optimization are used in the proofs of Theorems 1 through 6.
Cite this review
Pith. "Pith review of Efficient Verification of Pure Quantum States in the Adversarial Scenario." pith.science (2026). https://pith.science/paper/CJJRIPWU
@misc{pith2026190901900,
author = {Pith},
title = {Pith review of: Efficient Verification of Pure Quantum States in the Adversarial Scenario},
year = {2026},
howpublished = {\url{https://pith.science/paper/CJJRIPWU}},
note = {Machine review of arXiv:1909.01900}
}
read the original abstract
Efficient verification of pure quantum states in the adversarial scenario is crucial to many applications in quantum information processing, such as blind measurement-based quantum computation and quantum networks. However, little is known about this topic so far. Here we establish a general framework for verifying pure quantum states in the adversarial scenario and clarify the resource cost. Moreover, we propose a simple and general recipe to constructing efficient verification protocols for the adversarial scenario from protocols for the nonadversarial scenario. With this recipe, arbitrary pure states can be verified in the adversarial scenario with almost the same efficiency as in the nonadversarial scenario. Many important quantum states can be verified in the adversarial scenario using local projective measurements with unprecedented high efficiencies.
Figures
Forward citations
Cited by 2 Pith papers
-
Device-Independent Self-Testing of the Three-Qubit CCZ Hypergraph State
The CCZ hypergraph state and its Pauli measurements can be device-independently self-tested from twenty correlators, and also from maximal violation of a specially constructed Bell inequality.
-
Efficient certification of intractable quantum states with few Pauli measurements
The paper claims Clifford-enhanced product states can be certified with O(n^2/epsilon^2) Pauli measurements in the i.i.d. setting and polynomially many in the adversarial setting, but the central estimator is derived ...
Reference graph
Works this paper leans on
-
[26]
General framework for verifying pure quantum states in the adversarial scenario,
H. Zhu and M. Hayashi, “General framework for verifying pure quantum states in the adversarial scenario,” Phys. Rev. A 100, 062335 (2019)
work page 2019
-
[1]
R. Horodecki, P. Horodecki, M. Horodecki, and K. Horodecki, “Quantum entanglement,” Rev. Mod. Phys. 81, 865 (2009)
work page 2009
-
[2]
O. Gühne and G. Tóth, “Entanglement detection,” Phys. Rep. 474, 1 (2009)
work page 2009
-
[3]
Quantum state tomography via compressed sensing,
D. Gross, Y.-K. Liu, S. T. Flammia, S. Becker, and J. Eisert, “Quantum state tomography via compressed sensing,” Phys. Rev. Lett. 105, 150401 (2010)
work page 2010
-
[4]
Direct fidelity estimation from few Pauli measurements,
S. T. Flammia and Y.-K. Liu, “Direct fidelity estimation from few Pauli measurements,” Phys. Rev. Lett. 106, 230501 (2011)
work page 2011
-
[5]
A study of LOCC-detection of a maximally entangled state using hypothesis testing,
M. Hayashi, K. Matsumoto, and Y. Tsuda, “A study of LOCC-detection of a maximally entangled state using hypothesis testing,” J. Phys. A: Math. Gen. 39, 14427 (2006)
work page 2006
-
[6]
Group theoretical study of LOCC-detection of maximally entangled states using hypothesis testing,
M. Hayashi, “Group theoretical study of LOCC-detection of maximally entangled states using hypothesis testing,” New J. Phys. 11, 043028 (2009)
work page 2009
-
[7]
Optimal verification of entangled states with local measurements,
S. Pallister, N. Linden, and A. Montanaro, “Optimal verification of entangled states with local measurements,” Phys. Rev. Lett. 120, 170502 (2018)
work page 2018
Show all 26 references
-
[8]
Optimal verification and fidelity estimation of maximally entangled states,
H. Zhu and M. Hayashi, “Optimal verification and fidelity estimation of maximally entangled states,” Phys. Rev. A 99, 052346 (2019)
2019
-
[9]
Efficient verification of bipartite pure states,
Z. Li, Y.-G. Han, and H. Zhu, “Efficient verification of bipartite pure states,” Phys. Rev. A 100, 032316 (2019)
2019
-
[10]
Optimal verification of two- qubit pure states,
K. Wang and M. Hayashi, “Optimal verification of two- qubit pure states,” Phys. Rev. A 100, 032315 (2019)
2019
-
[11]
Optimal verification of general bipartite pure states,
X.-D. Yu, J. Shang, and O. Gühne, “Optimal verification of general bipartite pure states,” npj Quantum Inf. 5, 112 (2019)
2019
-
[12]
Verifiable measurement- only blind quantum computing with stabilizer testing,
M. Hayashi and T. Morimae, “Verifiable measurement- only blind quantum computing with stabilizer testing,” Phys. Rev. Lett. 115, 220502 (2015)
2015
-
[13]
Verifiable fault tolerance in measurement-based quantum computation,
K. Fujii and M. Hayashi, “Verifiable fault tolerance in measurement-based quantum computation,” Phys. Rev. A 96, 030301(R) (2017)
2017
-
[14]
Self-guaranteed measurement-based quantum computation,
M. Hayashi and M. Hajdušek, “Self-guaranteed measurement-based quantum computation,” Phys. Rev. A 97, 052308 (2018)
2018
-
[15]
A simple protocol for cer- tifying graph states and applications in quantum net- works,
D. Markham and A. Krause, “A simple protocol for cer- tifying graph states and applications in quantum net- works,” (2018), arXiv:1801.05057
2018 arXiv
-
[16]
Efficient verification of hyper- graph states,
H. Zhu and M. Hayashi, “Efficient verification of hyper- graph states,” Phys. Rev. Applied 12, 054047 (2019)
2019
-
[17]
Verifying commut- ing quantum computations via fidelity estimation of weighted graph states,
M. Hayashi and Y. Takeuchi, “Verifying commut- ing quantum computations via fidelity estimation of weighted graph states,” New J. Phys. 21, 093060 (2019)
2019
-
[18]
Efficient verification of Dicke states,
Y.-C. Liu, X.-D. Yu, J. Shang, H. Zhu, and X. Zhang, “Efficient verification of Dicke states,” Phys. Rev. Ap- plied 12, 044020 (2019)
2019
-
[19]
Blind quantum computation protocol in which Alice only makes measurements,
T. Morimae and K. Fujii, “Blind quantum computation protocol in which Alice only makes measurements,” Phys. Rev. A 87, 050301(R) (2013)
2013
-
[20]
Quantum computational universality of hypergraph states with Pauli-X and Z basis measurements,
Y. Takeuchi, T. Morimae, and M. Hayashi, “Quantum computational universality of hypergraph states with Pauli-X and Z basis measurements,” Sci. Rep. 9, 13585 (2019)
2019
-
[21]
Distribution of entanglement in large-scale quantum networks,
S. Perseguers, G. J. Lapeyre Jr, D. Cavalcanti, M. Lewen - stein, and A. Acín, “Distribution of entanglement in large-scale quantum networks,” Rep. Prog. Phys. 76, 096001 (2013)
2013
-
[22]
Ex- perimental verification of multipartite entanglement in quantum networks,
W. McCutcheon, A. Pappa, B. A. Bell, A. McMillan, A. Chailloux, T. Lawson, M. Mafu, D. Markham, E. Dia- manti, I. Kerenidis, J. G. Rarity, and M. S. Tame, “Ex- perimental verification of multipartite entanglement in quantum networks,” Nat. Commun. 7, 13251 (2016)
2016
-
[23]
Verification of hypergraph states,
T. Morimae, Y. Takeuchi, and M. Hayashi, “Verification of hypergraph states,” Phys. Rev. A 96, 062321 (2017)
2017
-
[24]
Verification of many-qubit states,
Y. Takeuchi and T. Morimae, “Verification of many-qubit states,” Phys. Rev. X 8, 021060 (2018)
2018
-
[25]
Resource-efficient verification of quan- tum computing using Serfling’s bound,
Y. Takeuchi, A. Mantri, T. Morimae, A. Mizutani, and J. F. Fitzsimons, “Resource-efficient verification of quan- tum computing using Serfling’s bound,” npj Quantum Inf. 5, 27 (2019)
2019
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.