Pith. sign in

REVIEW 5 major objections 4 minor 1 cited by

Probability distributions over CSS codes: two-universality, QKD hashing, collision bounds, security

T0 review · 5 major / 4 minor · reviewed 2026-08-04 · deepseek-v4-flash

Pith's one-line read This paper claims that POVM-based probability distributions over CSS codes make parity-check functions efficiently computable, and that the resulting two-universal QKD hashing protocol is 2^{−k/2 + n h_2(r/n) + (5/2)(5−3/2) + log_2√C}-secur

desk verdict The central object is not a probability measure and the security bound contains an unspecified constant in the exponent, so the paper is not referee-ready. read the letter →

arxiv 2510.02402 v2 pith:AMJEDULL submitted 2025-10-01 quant-ph cs.ITmath.ITmath.PR

classification quant-phcs.ITmath.ITmath.PR MSC 81P9481P7094A60 PACS 03.67.Dd03.67.Pp
keywords CSScodestwo-universalhashingquantumkeydistributionparity-checkmatricesPOVM-basedprobabilitydistributionsrandomoverF2diamondnormcollisionbounds
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper attempts to define probability distributions over CSS codes by attaching POVM elements to random matrices over the two-element field, so that the two parity-check matrices of the hashing protocol arise as marginals. Using these distributions, it introduces real, simulator, and ideal isometries and shows that expectation values of the purified random-matrix state control the diamond distance between ideal and real hashing transformations. The central advertised result is an explicit security bound for a two-universal QKD hashing protocol: 2^{−k/2 + n h_2(r/n) + (5/2)(5−3/2) + log_2√C}-secure for a strictly positive constant C. A sympathetic reader would care because the paper is trying to show precisely how the ability to compute functions of parity-check matrices efficiently translates into a concrete, quantified loss of unconditional security relative to the earlier two-universal hashing bound.

What carries the argument

The load-bearing object is the purified random-matrix state |L⟩ = ∑_L √p_L |LL⟩ over 2×2 matrices with entries in the field F_2, together with Bell-basis decompositions of maximally entangled outer products. The argument is carried by three kinds of isometries — real (U_Real, V_Real), simulator (U_Simulator, V_Simulator), and ideal (U_Ideal, V_Ideal) — whose braket expectation values ⟨L| U†_Ideal U†_Simulator U_Real |L⟩ (and the V-analogues) are shown to be at least 2^{5−3/2}(1−2^{−k+nh(r/n)}) up to constants. These expectation values, through a diamond-norm estimate, produce the additive term (5/2)(5−3/2) + log_2√C in the security exponent. The probability measures P_L and P_{(L^{−1})^T} de

What would settle it

Compute the trace of the unnormalized operator ∑_U POVM_U = I on the relevant register and compare with the required normalization ∑_L p_L = 1 for the purified state |L⟩; if no assignment of positive scalars p_L satisfies both the POVM identity and the marginal equalities P1, P2, the probabilities in the security theorems are not defined. Alternatively, evaluate the diamond-distance bound for a small instance (e.g., n=2, r=1, k=1) numerically from the stated isometries and check whether it respects the claimed exponent.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is a family of probability measures over CSS codes: each random matrix L in Mat_{F_2^n}[2×2] is assigned a POVM element with ∑_U POVM_U = I, and the first- and second-column marginals of the resulting measure are exactly the parity-check matrices P1 and P2 used in the hashing protocol. Under these measures, the purified state |L⟩ = ∑_L √p_L |LL⟩ and a triple of real, simulator, and ideal isometries (U and V families) make it possible to compute the bit-flip and phase-flip functions g1 and g2 directly from parity-check data. The quantitative conclusion is that the ideal and real transformations are close in diamond norm, d_Diamond(E_Ideal, E_Rea

Load-bearing premise

The load-bearing premise is that the POVM-valued assignment in the definition of the probability distributions is a genuine probability distribution over CSS codes, with normalized weights p_L such that |L⟩ = ∑_L √p_L |LL⟩ is a valid state, and whose marginals recover precisely the parity-check matrices P1 and P2; as written, the definition assigns operator mass with ∑_U POVM_U = I, an operator identity rather than a probability normalization.

Editorial extensions

If this is right

  • If the derivation is correct, the modified two-universal QKD hashing protocol is 2^{−k/2 + n h_2(r/n) + (5/2)(5−3/2) + log_2√C}-secure, with the additive constant coming from the isometry construction.
  • The same argument yields a probabilistic collision bound for the simultaneous failure of the bit-flip and phase-flip functions, via a union bound over the error set.
  • The diamond-distance bound gives a direct operational handle on how far the efficient protocol is from the idealized hashing transformation.
  • Efficient computation of parity-check-matrix functions comes at a provable security cost: the additive exponent in the security bound is larger than in earlier two-universal hashing, so the security guarantee is weaker.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the POVM-based probability measures can be normalized properly, the same marginal formulation would apply to any family of POVMs indexed by random matrices, suggesting a general recipe for building CSS-code distributions from operator-valued measures.
  • A natural numerical test is to evaluate the purified-state expectation values for small n and r to see whether the constant C is near 1 or grows with n, which would determine the practical size of the security loss.
  • The framework suggests a trade-off curve: different choices of real/simulator isometries would change the additive constant in the exponent, so one could search for an isometry design that preserves efficient g1 and g2 computation while minimizing the security penalty.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 4 minor

Summary. The manuscript proposes a new class of probability distributions over CSS codes defined through POVMs, and uses them to analyze a two-universal QKD hashing protocol π′(n,k,r). The central result, Theorem 2, claims that this protocol is 2^{−k/2 + n h_2(r/n) + (5/2)(5−3/2) + log_2√C}-secure for a strictly positive constant C, i.e., a factor 2^{(5/2)(5−3/2)+log_2√C} less secure than Ostrev's bound [40]. The derivation introduces real, simulator, and ideal isometries, purified states |L⟩=∑_L√p_L|LL⟩ of random matrices, and reduced expressions for Eve's register. The paper also states a probabilistic collision bound (Theorem 1) and several propositions concerning outer-product decompositions and diamond-norm distances.

Significance. The question addressed — whether two-universal QKD hashing security can be understood through distributions over CSS codes and parity-check-matrix marginals — is a legitimate follow-up to Ostrev [40]. If the claimed security bound were proved with a concrete constant, it would quantify a trade-off between computational efficiency and security. The manuscript contains substantial raw computation and attempts explicit operator-level constructions. However, the central objects are not well-defined (see major comments), and the advertised bound contains an unspecified constant and an exponent that is not derived from the stated propositions. No machine-checked proofs or reproducible code are provided; the lengthy algebraic manipulations are not independently checkable because many terms are undefined. As a result, the significance of the claimed result cannot be assessed in its present form.

major comments (5)
  1. [§1.4, Definition 1] Definition 1 defines the 'probability measures' P_L(·) and P_M(·) by assigning mass equal to a POVM element, P_L(...) = POVM_U with ∑_U POVM_U = I. This is an operator identity, not a scalar probability normalization. A probability measure must assign numbers in [0,1] summing to 1; POVM elements are positive operators and ∑_U POVM_U = I has trace equal to the Hilbert-space dimension, not 1. Consequently every later probability expression, including Theorem 1 and Theorem 2, is not defined as written. This is not a missing constant or a presentation issue; the foundational object of the paper is absent.
  2. [§1.4, before Proposition 1] Before Proposition 1 the purified state |L⟩ = ∑_L √p_L |LL⟩ is introduced, with P_L ≡ {∀L>0:p_L>0}, and the text speaks of 'uniformly distributed random matrices'. The coefficients p_L are never specified and no normalization ∑_L p_L = 1 is stated. Without scalar probabilities p_L, the expectation values ⟨L|(⋯)|L⟩ in Propositions 2–5 and the security probability in Theorem 2 have no referent. The phrase 'uniformly distributed' does not rescue the definition, since the set of matrices and the probability weights are not defined.
  3. [§1.4, marginal definitions] It is asserted that the parity-check matrices are obtained as 'marginals' of P_L and P_M: P_L|first column ≡ P1, P_M|second column ≡ P2. A marginal of a distribution over 2×2 matrices is a distribution over columns, not a single matrix. Moreover P1 and P2 are subsequently used both as matrices acting on syndromes and as probability measures (e.g., Corollary 1 of [40] is invoked with P_L probabilities). This conflation makes the definitions of the real isometries U_Real, V_Real and the probability bounds ill-posed.
  4. [§1.4, Proposition 5 and Theorem 2] Proposition 5 concludes d_Diamond(E_Ideal,E_Real) ≲ sqrt(2^{−k + n h(r/n) + 5 − 3/2}) = 2^{−k/2 + n h(r/n)/2 + 7/4}. Theorem 2 instead asserts the protocol is 2^{−k/2 + n h_2(r/n) + (5/2)(5−3/2) + log_2√C}-secure = 2^{−k/2 + n h_2 + 35/4 + log√C}. The exponent in Theorem 2 has an h_2 term with coefficient n instead of n/2 and an extra 35/4 (plus log√C) that does not follow from Proposition 5. Since C is only asserted to be some strictly positive constant defined through a ratio in Proposition 5 and no bound on C is given, the security statement is not a concrete bound and cannot be compared with Ostrev's 2^{−k/2 + n h(r/n) + 5/2}.
  5. [§2.1, Definition 2 and Theorem 1] Definition 2 defines the collision bound Θ through POVM_U(...) = POVM_V(...) = P_L(...) ≤ Θ. Since POVM_U and POVM_V are operators, equality with the scalar P_L(...) and inequality to scalar Θ are not meaningful unless a trace or a specific state is taken. Theorem 1 then states a union bound with Θ|S|. This compounds the undefined probability space from Definition 1.
minor comments (4)
  1. [§1.4, Theorem 2] h_2 is never defined; Ostrev's h is the binary entropy. Please define h_2 and reconcile notation between h and h_2.
  2. [§1.4, Propositions 2 and 3] Powers such as 25−3/2 and 5−3/2 should be parenthesized (e.g., 2^{5−3/2}) to avoid ambiguity; as typeset they are easily misread.
  3. [§3.5–3.6, Proposition 4 and Corollary] The quantities T'_k in the Corollary are used before being defined; the proof of Proposition 4 relies on an unexplained 'anticommutation with respect to the ratio of projections'.
  4. [Throughout] There are numerous typos ('two-univrsal', 'isomteries', 'occurence'), and reference [48] shares the same arXiv identifier as [47]; several references are listed as 'submitted' without public identification.

Circularity Check

3 steps flagged · score 8.0 of 10

The central probability object is defined into existence (P_L is a POVM, not a scalar probability measure), the collision bound Θ is defined as the inequality Theorem 1 restates, and the security constant C is defined from the same ratio used in Theorem 2; the main results reduce to their own definitions.

  1. self definitional [Definition 1, §1.4; used throughout Propositions 1–6 and Theorem 2]
    "The probability measures over Quantum CSS codes that will be considered in this work, P_L(·), P_{(L^{-1})^T}(·) ≡ P_M(·), assigns the mass P_L(There exists a CSS code such that the first parity check matrix, from the finite dimensional representation of L, which can be used for error correction) ≡ POVM_U, where, Σ_U POVM_U = I, and, for M=(L^{-1})^T, equal, P_M(...) ≡ POVM_V, where Σ_V POVM_V = I."

    A probability measure must assign scalar masses in [0,1] summing to 1; here the 'mass' is a POVM element and the normalization is the operator identity Σ POVM_U = I. The parity-check matrices P1 and P2 are then declared to be 'the marginal distributions' of this object, and every later security probability is an evaluation P_L(...). Theorem 2 therefore computes a number under a measure whose defining property is the same operator assignment; security is entailed by Definition 1 rather than derived from an external stochastic model.

  2. self definitional [Definition 2 (§2.1) and Theorem 1 (§1.4); proof in §3.9]
    "Definition2(suitable collision probability bounds from POVMs over isometries). Denote a family of hashing functions, H, where H:X→Y, for two finite sets X and Y. The two-universal collision probability bound, Θ>0, satisfies, POVM_U[H∈H:H(x)=H(x′)] = POVM_V[...] = P_L[H∈H:H(x)=H(x′)] ≤ Θ."

    Θ is introduced as a number satisfying exactly the collision inequality. Theorem 1 then states P({f_S≠g_{1,S}},{f_S≠g_{2,S}}) ≤ Θ|S|, and its proof says 'a straightforward application of a probabilistic union bound, along with Θ provided ... implies the desired result.' Up to the factor |S|, the theorem is the defining inequality of Θ; the 'bound' is assumed rather than proved.

1 more flagged steps
  1. self definitional [Proposition 5 (§1.4) and Theorem 2 (§1.4)]
    "Denote E_Ideal and E_Real as the ideal, and real, transformations, respectively, for preparing the purified state |L⟩, and a strictly positive constant C, for which, ⟨L|[Σ U†Ideal U†Simulator U′Real]|L⟩ / [2^{5−3/2}−2^{−k+nh(r/n)+5−3/2}] I_AB = ⟨L|[Σ V†Ideal V†Simulator V′Real]|L⟩ / [...] ≥ C ≡ C(z_A,z_B,x_A,x_B,L). ... d_Diamond(E_Ideal,E_Real) ≲ √(2^{−k+nh(r/n)+5−3/2}), implies, d_Diamond(E_Ideal,E_Real) ≤ √(C 2^{−k+nh(r/n)+5−3/2})."

    C is not an independently fixed constant; it is defined in Proposition 5 as a lower bound on a ratio of the very expectation values appearing in the proof. Theorem 2 then reports the security exponent as containing log_2√C, presenting the bookkeeping identity as a novel factor 'less secure'. Since the value of C is chosen after the fact from the same expressions, the final security bound is a rearrangement of the proof's own definitions, not a prediction.

full rationale

The paper's derivation chain is not circular through self-citation: the main external input, Ostrev [40], is cited for an independent result. The circularity is definitional and structural. Definition 1 creates the 'probability measure' P_L by setting its mass equal to POVM elements normalized by Σ POVM_U = I; because this is an operator identity rather than a scalar probability normalization, every later event probability P_L(...), including the acceptance probability in the proof of Theorem 2, is an evaluation of the object that was stipulated into existence. Definition 2 then defines the collision bound Θ as the very inequality Theorem 1 restates; the proof adds only a union-bound factor and 'Θ provided.' Finally, Proposition 5 introduces C as a lower bound on a ratio of the same expectation values used in the diamond-distance estimate, and Theorem 2 inserts log_2√C into the exponent. The stated security gap is therefore a rewriting of the proof's own definitions. Some algebraic work with isometries and outer-product decompositions is present, but it does not supply an independent probability model or an externally fixed constant; hence the central security claim reduces to its inputs. Score 8 rather than 10 because the algebra is not wholly empty, but the probabilistic content is stipulated.

Assumptions & free parameters 4 free parameters · 4 assumptions · 3 invented entities

The central claims rest on a chain of definitions and cited results: the security framework of [40], the probabilistic bound Corollary 1 of [40], the assumption that newly defined operators are isometries, and an unspecified constant C. The 'probability distributions' are normalized to the identity operator rather than to unit probability mass.

free parameters (4)
  • C
    Introduced in Proposition 5 as C(z_A,z_B,x_A,x_B,L), the ratio of the paper's two derived lower bounds; enters the Theorem 2 security exponent as log_2√C. No lower bound is given, so the security guarantee is vacuous.
  • p_L (weights of the random-matrix purification)
    The state |L⟩ = ∑_L √p_L |LL⟩ is used in all expectation-value computations; the text says L is drawn uniformly but the p_L are only specified by support P_L = {∀L>0: p_L>0}; normalization is asserted via the POVM identity rather than a probability measure.
  • k, n, r (protocol parameters)
    Inputs inherited from the protocol; r is the Hamming-ball radius used in h(r/n); the key-entropy/dimension conditions from [40] are assumed.
  • M = third column row of (M^{-1})^T
    An ad hoc object (the 'third column' of the inverse transpose) used to define the W isometry and Bob's key acceptance w_B + M^t; no uniqueness or independence argument is given.
assumptions (4)
  • domain assumption Security framework of [40]: Definitions 1–3 of ϵ-security, ϵ-correctness, and ϵ-closeness, plus Theorem 2 of [40] as benchmark
    Adopted wholesale in §2.1; the paper's protocol and security notion inherit these definitions without modification.
  • domain assumption Corollary 1 of [40]: error-probability bound 1 − 2^{−k+nh(r/n)} for the two-universal hashing distribution
    Invoked in Propositions 2 and 3 as the step that converts a sup over events into the final exponent; not proven or adapted to the new probability measures.
  • ad hoc to paper The newly defined operators U_Real, U_Simulator, U_Ideal, V_*, W are isometries with mutually consistent registers
    All trace and expectation-value manipulations in Props 1–6 presuppose this; no verification is given, and some displayed maps are rank-1 (e.g., (1/√2)(|z_B+z_A⟩⟨z_B|+|z_B+z_A⟩⟨z_A|)).
  • standard math Bell-basis completeness and the outer-product projection identities P(g,x) = 2^{−m}∏(I + (−1)^{x_j} g_j)
    Used in the proof of the Lemma and throughout; standard but unstated in detail; the Lemma's claimed decomposition is not derived.
invented entities (3)
  • Real, simulator, and ideal isometries (U_Real, U_Simulator, U_Ideal, V_Real, V_Simulator, V_Ideal) and W
    purpose: To compute functions g1, g2 of the parity-check matrices and to relate the purified random-matrix state to the protocol's security
    No falsifiable handle; their validity as isometries and their register labels are not established; labels change across occurrences.
  • Purified states of random matrices |L⟩_PL = ∑_L √p_L |LL⟩
    purpose: Vehicle for expectation values ⟨L|(Sim)†(Ideal)†Real|L⟩ used in the security proof
    Inherited from [40]; here the weights p_L are unspecified beyond support.
  • Third column of (L^{−1})^T (called M)
    purpose: Defines the W isometry and Bob's acceptance string w_B + M^t
    No independent justification; appears only in the construction.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Probability distributions over CSS codes: two-universality, QKD hashing, collision bounds, security." pith.science (2026). https://pith.science/paper/AMJEDULL

@misc{pith2026251002402,
  author       = {Pith},
  title        = {Pith review of: Probability distributions over CSS codes: two-universality, QKD hashing, collision bounds, security},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/AMJEDULL}},
  note         = {Machine review of arXiv:2510.02402}
}
abstract

We characterize novel probability distributions for CSS codes. Such classes of error correcting codes, originally introduced by Calderbank, Shor, and Steane, are of great significance in advancing the fidelity of Quantum computation, with implications for future near term applications. Within the context of Quantum key distribution, such codes, as examined by Ostrev in arXiv: 2109.06709 along with two-universal hashing protocols, have greatly simplified Quantum phases of computation for unconditional security. To further examine novel applications of two-universal hashing protocols, particularly through the structure of parity check matrices, we demonstrate how being able to efficiently compute functions of the parity check matrices relates to marginals of a suitably defined probability measure supported over random matrices. The security of the two-universal QKD hashing protocol will be shown to depend upon the computation of purified states of random matrices, which relates to probabilistic collision bounds between two hashing functions. Central to our approach are the introduction of novel real, simulator, and ideal, isometries, hence allowing for efficient computations of functions of the two parity check matrices. As a result of being able to perform such computations involving parity check matrices, the security of the two-universal hashing protocol is a factor of $2^{ \frac{5}{2} ( 5 - \frac{3}{2} ) + \mathrm{log}_2 \sqrt{C}}$ less secure, for some strictly positive constant $C$.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Malleability of transformations on the ciphertext in noisy Quantum public key encryption

    quant-ph 2026-07 reject novelty 2.0 of 10

    The claimed noisy generalization of QKD everlasting security reduces, in the paper's own text, to its definition of noisy everlasting security.

Reference graph

Works this paper leans on

54 extracted references · 19 canonical work pages · cited by 1 Pith paper

  1. [40]

    Quantum7, 894 (2023) https://doi.org/10.22331/q-2023-01-13-894

    Ostrev, D.: Qkd parameter estimation by two-universal hashing. Quantum7, 894 (2023) https://doi.org/10.22331/q-2023-01-13-894

  2. [1]

    classical two way communication in xor games

    Amr, A., Villanueva, I.: Quantum one way vs. classical two way communication in xor games. Quantum Information Processing20(79) (2021)

  3. [2]

    STACS12, 1–12 (2019) https://doi.org/10.4230/LIPIcs.STACS.2019.12

    Bannik, T., al.: Bounding quantum-classical separations for classes of nonlocal games. STACS12, 1–12 (2019) https://doi.org/10.4230/LIPIcs.STACS.2019.12

  4. [3]

    Briet, J., Buhrman, H., Toner, B.: A generalized grothendieck inequality and entanglement in xor games. Comm. Math. Phys.305, 827–843 (2011) https:// doi.org/10.1007/s00220-011-1280-3

  5. [4]

    Theoretical Computer Science358, 3–14 (2006) https://doi.org/10.1016/j.tcs.2005.08.035

    Broadbent, A., Methot, A.A.: On the power of non-local boxes. Theoretical Computer Science358, 3–14 (2006) https://doi.org/10.1016/j.tcs.2005.08.035

  6. [5]

    Brassard, G., Broadbent, A., Tapp, A.: Quantum pseudo-telepathy. Found. Phys. 35, 1877–1907 (2005) https://doi.org/https://philpapers.org/rec/BRAQP

  7. [6]

    Phys Rev Applied16(044057) (2021) https://doi.org/10.1103/PhysRevApplied.16.044057

    Benedetti, M., Coyle, B., Fiorentini, M., Lubasch, M., Rosenkranz, M.: Varia- tional Inference with a Quantum Computer. Phys Rev Applied16(044057) (2021) https://doi.org/10.1103/PhysRevApplied.16.044057

  8. [7]

    Phys- ical Review Letters127(120502) (2021) https://doi.org/10.1103/PhysRevLett

    Bittel, L., Kliesch, M.: Training variational quantum algorithms is np-hard. Phys- ical Review Letters127(120502) (2021) https://doi.org/10.1103/PhysRevLett. 127.120502

Show all 54 references
  1. [8]

    Catani, L., Faleiro, R., Emeriau, P.E., Mansfield, S., Pappa, A.: Connecting xor and xor* games. Phys. Rev. A109(012427) (2024) https://doi.org/10.1103/ PhysRevA.109.012427

  2. [9]

    Physical Review Research4(043119) (2022) https://doi

    Chen, H., Vives, M., Metcalf, M.: Parametric amplification of an optomechanical quantum interconnect. Physical Review Research4(043119) (2022) https://doi. org/10.1103/PhysRevResearch.4.043119

  3. [10]

    New Journal of Physics18(073011) (2016) https://doi.org/10

    Cong, I., Duan, L.: Quantum discriminant analysis for dimensionality reduction and classification. New Journal of Physics18(073011) (2016) https://doi.org/10. 1088/1367-2630/18/7/073011

  4. [11]

    19th IEEE Annual Conference on Computational Complexity Proceedings, 236–249 (2004) https://doi.org/10.1109/CCC.2004.1313847

    Cleve, R., Hoyer, P., Toner, B., Watrous, J.: Consequences and limits of non- local strategies. 19th IEEE Annual Conference on Computational Complexity Proceedings, 236–249 (2004) https://doi.org/10.1109/CCC.2004.1313847

  5. [12]

    IEEE 65th Annual Symposium on Foundations of Computer Science (FOCS), 920–929 (2024) https://doi.org/10.1109/FOCS61266.2024.00061

    Culf, E., Mousavi, H., Spirig, T.: Approximation algorithms for noncommuta- tive csps. IEEE 65th Annual Symposium on Foundations of Computer Science (FOCS), 920–929 (2024) https://doi.org/10.1109/FOCS61266.2024.00061

  6. [13]

    arXiv: 2402.17301 (2024)

    Cui, D., Malavolta, G., Mehta, A., Natarajan, A., Paddock, C., Schmidt, S., Walter, M., Zhang, T.: A computational tsireslson’s theorem for the value of 63 compiled xor games. arXiv: 2402.17301 (2024)

  7. [14]

    23rd Annual IEEE Conference on Computational Complexity8(2018)

    Doherty, A.C., Liang, Y.C., Toner, B., Wehner, S.: The quantum moment problem and bounds on entangled multi-prover games. 23rd Annual IEEE Conference on Computational Complexity8(2018)

  8. [15]

    Srinivas, Cabello, A., al.: Experimental quantum advantage in the odd- cycle game

    Drmota, P., Main, D., Ainley, E.M., Agrawal, A., Araneda, G., Nadlinger, R. Srinivas, Cabello, A., al.: Experimental quantum advantage in the odd- cycle game. Phys. Rev. Lett.134(070201) (2025) https://doi.org/10.1103/ PhysRevLett.134.070201

  9. [16]

    IEEE Transactions on Microwave Theory and Techniques70(5), 2517–2525 (2022) https://doi.org/10.1109/TMTT.2022

    Ewe, W.-B., Koh, D.E., Goh, S.T., Chu, H.-S., Png, C.E.: Variational quantum- based simulation of waveguide modes. IEEE Transactions on Microwave Theory and Techniques70(5), 2517–2525 (2022) https://doi.org/10.1109/TMTT.2022. 3151510

  10. [17]

    PRX Quantum3(020307) (2022) https://doi.org/ 10.1103/PRXQuantum.3.02030

    Pierre-Emmanuel Emeriau, P.-E., Howard, M., Mansfield, S.: Quantum advan- tage in information retrieval. PRX Quantum3(020307) (2022) https://doi.org/ 10.1103/PRXQuantum.3.02030

  11. [18]

    Quantum Inf Process19(229) (2020) https://doi.org/10.1007/s11128-020-02717-

    Faleiro, R.: Quantum strategies for simple 2-player xor games. Quantum Inf Process19(229) (2020) https://doi.org/10.1007/s11128-020-02717-

  12. [19]

    Advance in Neural Information Processing Systems32(2019)

    Garg, D., Ikbal, S., Srivastava, S.K., Vishwakarma, H., Karanam, H., Subrama- niam, L.V.: Quantum embedding of knowledge for reasoning. Advance in Neural Information Processing Systems32(2019)

  13. [20]

    Jour- nal of Physics A: Mathematical and Theoretical52(43) (2019) https://doi.org/ 10.1088/1751-8121/ab3fe0

    Genoni, M.G., Tufarelli, T.: Non-orthogonal bases for quantum metrology. Jour- nal of Physics A: Mathematical and Theoretical52(43) (2019) https://doi.org/ 10.1088/1751-8121/ab3fe0

  14. [21]

    Phys.Rev.A108(032409) (2023) https://doi.org/10.1103/ PhysRevA.108.032409

    Gidi, J.A., Candia, B., Munoz-Moller, A.D., Rojas, A., Pereira, L., Munoz, M., Zambrano, L., Delgado, A.: Stochastic optimization algorithms for quan- tum applications. Phys.Rev.A108(032409) (2023) https://doi.org/10.1103/ PhysRevA.108.032409

  15. [22]

    AIAA58(8) (2020)

    Givi, P., Daley, A.J., Mavriplis, D., Malik, M.: Quantum speedup for aeroscience and engineering. AIAA58(8) (2020)

  16. [23]

    Helton, J.W., Mousavi, H., Nezhadi, S.S., al.: Synchronous values of games. Ann. Henri Poincar´ e25, 4357–4397 (2024) https://doi.org/10.1007/ s00023-024-01426-1

  17. [24]

    IEEE Transactions on Information Theory70(3), 1876– 1896 (2024) https://doi.org/10.1109/TIT.2023.3324527 64

    Hadiashar, S.B., Nayak, A., Sinha, P.: Optimal lower bounds for quantum learning via information theory. IEEE Transactions on Information Theory70(3), 1876– 1896 (2024) https://doi.org/10.1109/TIT.2023.3324527 64

  18. [25]

    Quantum Machine Intelligence4(3) (2022) https://doi.org/ 10.1007/s42484-021-00061-x

    Hur, T., Kim, L., Park, D.K.: Quantum convolutional neural network for classical data classification. Quantum Machine Intelligence4(3) (2022) https://doi.org/ 10.1007/s42484-021-00061-x

  19. [26]

    Holmes, Z., Coble, N.J., Sornborger, A.T., Subasi, Y.: On nonlinear transfor- mations in quantum computation. Phys. Rev. Research5(013105) (2023) https: //doi.org/10.1103/PhysRevResearch.5.013105

  20. [27]

    arXiv: 2204.00738 (2022) https: //doi.org/10.48550/arXiv.2204.00738

    Jing, H., Wang, Y., Li, Y.: Data-driven quantum approximate optimization algorithm for cyber-physical power systems. arXiv: 2204.00738 (2022) https: //doi.org/10.48550/arXiv.2204.00738

  21. [28]

    Journal of the London Mathematical Society110(5) (2024)

    Junge, M., Palazuelos, C.: On the power of quantum entanglement in multipartite quantum xor games. Journal of the London Mathematical Society110(5) (2024)

  22. [29]

    Physical Review A103(052425) (2021) https://doi.org/10.1103/PhysRevA.103.052425

    Kubo, K., Nakagawa, Y.O., Endo, S., Nagayama, S.: Variational quantum simula- tions of stochastic differential equations. Physical Review A103(052425) (2021) https://doi.org/10.1103/PhysRevA.103.052425

  23. [30]

    Linear Algebra and its Applications400, 147–167 (2005) https://doi.org/10.48550/arXiv.math/ 0404553

    Kribs, D.W.: A quantum computing primer for operator theorists. Linear Algebra and its Applications400, 147–167 (2005) https://doi.org/10.48550/arXiv.math/ 0404553

  24. [31]

    npj Quantum Information4(14) (2008) https://doi.org/10.1038/s41534-018-0060-8

    Li, R.Y., Di Felice, R., Rohs, R., Lidar, D.A.: Quantum annealing versus classi- cal machine learning applied to a simplied computational biology problem. npj Quantum Information4(14) (2008) https://doi.org/10.1038/s41534-018-0060-8

  25. [32]

    Quantum Information Processing20(393) (2021) https://doi.org/10.1007/s11128-021-03331-6

    Mahdian, M., Yeganeh, H.D.: Toward a quantum computing algorithm to quan- tify classical and quantum correlation of system states. Quantum Information Processing20(393) (2021) https://doi.org/10.1007/s11128-021-03331-6

  26. [33]

    Scientific Reports12(6379) (2022) https://doi.org/10.1038/s41598-022-10339-0

    Maldonado, T.J., Flick, J., Krastanov, S., Galda, A.: Error rate reduction of single-qubit gates via noise-aware decomposition into native gates. Scientific Reports12(6379) (2022) https://doi.org/10.1038/s41598-022-10339-0

  27. [34]

    Journal of Chemical Theory and Computation8(8), 2564–2568 (2012) https://doi.org/10.1021/ct300544e

    Manby, F.R., Stella, M., Goodpaster, J.D., Miller, T.F.: A simple, exact density-functional-theory embedding scheme. Journal of Chemical Theory and Computation8(8), 2564–2568 (2012) https://doi.org/10.1021/ct300544e

  28. [35]

    Maurer, U.: Perfect cryptographic security from partially independent channels. Proc. 23rd ACM Symposium on Theory of Computing — STOC, 561–572 (1991) https://doi.org/https://crypto.ethz.ch/publications/Maurer91b.html

  29. [36]

    Mensa, S., Sahin, E., Tacchino, F., Barkoutsos, P.K., Tavernelli, I.: Quantum machine learning framework for virtual screening in drug discovery: a prospective quantum advantage. Mach. Learn.: Sci. Technol.4(015023) (2023) https://doi. org/10.1088/2632-2153/acb900 65

  30. [37]

    Nan Sheng, H.M., Govono, M., Galli, G.: Quantum embedding theory for strongly-correlated states in materials. J. Chem. Theory Comput.17(4), 2116– 2125 (2021) https://doi.org/10.1021/acs.jctc.0c01258

  31. [38]

    Quantum Information and Computation16(13-14), 1191–1211 (2016) https://doi.org/10.26421/QIC16.13-14-6

    Ostrev, D.: The structure of nearly-optimal quantum strategies for the non-local xor games. Quantum Information and Computation16(13-14), 1191–1211 (2016) https://doi.org/10.26421/QIC16.13-14-6

  32. [39]

    IEEE International Symposium on Information Theory10(1109), 622–626 (2019) https://doi.org/10.1109/ISIT.2019.8849510

    Ostrev, D.: Composable, unconditionally secure message authentication without any secret key. IEEE International Symposium on Information Theory10(1109), 622–626 (2019) https://doi.org/10.1109/ISIT.2019.8849510

  33. [41]

    Physical Review A107(032428) (2023) https://doi.org/10

    Paine, A.E., Elfving, V.E., Kyriienko, O.: Quantum kernel methods for solving differential equations. Physical Review A107(032428) (2023) https://doi.org/10. 1103/PhysRevA.107.032428

  34. [42]

    Paudel, H.P., Syamlal, M., Crawford, S.E., Lee, Y.-L., Shugayev, R.A., Lu, P., Ohodnicki, P.R., Mollot, D., Duan, Y.: Quantum computing and simulations for energy applications: Review and perspective. ACS Eng. Au3, 151–196 (2022) https://doi.org/10.1021/acsengineeringau.1c00033

  35. [43]

    Journal of Physics A: Mathematical and Theoretical55(085301) (2022) https://doi.org/10.1088/1751-8121/ac4b15

    Przhiyalkovskiy, Y.V.: Quantum process in probability representation of quan- tum mechanics. Journal of Physics A: Mathematical and Theoretical55(085301) (2022) https://doi.org/10.1088/1751-8121/ac4b15

  36. [44]

    Physics Reports687, 1– 51 (2017) https://doi.org/https://papers.ssrn.com/sol3/papers.cfm?abstract id= 2972841

    Perc, M.: Statistical physics of human cooperation. Physics Reports687, 1– 51 (2017) https://doi.org/https://papers.ssrn.com/sol3/papers.cfm?abstract id= 2972841

  37. [45]

    Ravishankar Ramanathan, R., Augusiak, R., Murta, G.: Generalized xor games withdoutcomes and the task of nonlocal computation. Phys. Rev. A93(022333) (2016) https://doi.org/10.1103/PhysRevA.93.022333

  38. [46]

    arXiv: 2311.12887 (submitted) (2023)

    Rigas, P.: Optimal, and approximately optimal, quantum strategies for XOR ∗ and FFL games. arXiv: 2311.12887 (submitted) (2023)

  39. [48]

    arXiv: 2209.07714 (submitted) (2025) https://doi.org/10.48550/arXiv

    Rigas, P.: Quantum error bounds, optimality, and duality gaps for multiplayer xor, xor*, compiled xor, xor*, and strong parallel repetition of xor, xor*, and 66 ffl games. arXiv: 2209.07714 (submitted) (2025) https://doi.org/10.48550/arXiv. 2209.07714

  40. [49]

    arXiv: 2507.03035 (submitted) (2025) https://doi.org/10

    Rigas, P.: Error correction, authentication, and false acceptance, probabilities for communication over noisy quantum channels: converse upper bounds on the bit transmission rate. arXiv: 2507.03035 (submitted) (2025) https://doi.org/10. 48550/arXiv.2507.03035

  41. [50]

    arXiv: 2508.09380 (submitted) (2025) https://doi.org/10

    Rigas, P.: Parallel repetition of expanded, and multiplayer, quantum games: anchoring, optimal values, generalized error bounds, dependency-breaking as symmetry-breaking. arXiv: 2508.09380 (submitted) (2025) https://doi.org/10. 48550/arXiv.2508.09380

  42. [51]

    Journal of Phys A: Math

    Roscika, M., Mazurek, P., Grudka, A., Horodecki, M.: Generalized xor non- locality games with graph description on a square lattice. Journal of Phys A: Math. Theor.53(265302) (2020) https://doi.org/10.1088/1751-8121/ab8f3e

  43. [52]

    Journal of Mathematical Physics52(10), 102202 (2011) https://doi.org/ 10.1063/1.3652924

    Slofstra, W.: Lower bounds on the entanglement needed to play xor non-local games. Journal of Mathematical Physics52(10), 102202 (2011) https://doi.org/ 10.1063/1.3652924

  44. [53]

    Diversities in Quantum Computation and Quantum Information, 79–105 (2012) https://doi.org/10.1142/9789814425988 0003

    Dam, W., Sasaki, Y.: Quantum algorithms for problems in number theory, alge- braic geometry, and group theory. Diversities in Quantum Computation and Quantum Information, 79–105 (2012) https://doi.org/10.1142/9789814425988 0003

  45. [54]

    Wang, Y., Krstic, P.S.: Multistate transition dynamics by strong time-dependent perturbation in nisq era. J. Phys. Commun.7(075004) (2023) https://doi.org/10. 1088/2399-6528/ace67a

  46. [55]

    Quantum Machine Intelligence3(21) (2021) https://doi.org/10.1007/s42484-021-00048-8 67

    Zhao, L., Zhao, Z., Rebentrost, P., Fitzsimons, J.: Compiling basic linear algebra subroutines for quantum computers. Quantum Machine Intelligence3(21) (2021) https://doi.org/10.1007/s42484-021-00048-8 67

Pith tools

Reviewed August 4, 2026 · model on record in the stance chip above.