REVIEW 4 major objections 4 minor 37 references
Practically feasible robust quantum money with classical verification
T0 review · 4 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read A private quantum money scheme based on Sampling Matching claims unconditional security against forging while tolerating noise up to 21.4% with a fixed passive linear-optical verification circuit.
desk verdict Plausible SM-based money scheme with a clean single-photon correctness analysis, but the advertised coherent-state implementation has no security proof and the single-photon proof leans on imported, partly conjectural ingredients. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the Sampling Matching verification scheme: the noteholder's single-photon state is mixed mode-by-mode with a verifier-prepared equal-amplitude local state on 50/50 beam splitters, and the pattern of two-photon clicks—both in the same output family versus one photon in each family—yields the parity $x_k \oplus x_l$ for a sampled tuple $(k,l)\in T_n$. The quantitative engine is the conversion of forging into a fidelity-maximization SDP, whose bound $\bar F \le \frac12 + \frac1n$ directly lower-bounds the adversary's error probability; the fixed-hardware claim comes from the coherent-state version of Sampling Matching, where the whole interaction is a single beam splitter followed by two threshold detectors.
What would settle it
Send the verifier a single copy prepared as a two-photon state with one photon in mode $k$ and one in mode $l$ ($k\neq l$), then run the Sampling Matching test. It yields two single-photon clicks, so it passes the local two-click check; if such a two-photon state, or a mixture of two-photon states, can also make the Bank's parity comparison succeed often enough, the claimed unconditional security against all adversaries is false. This is directly checkable with the weak-coherent-state setup.
Extended reading notes
Core claim
The paper's central claim is that Sampling Matching can serve as the verification primitive for private quantum money in a way that is both equipment-light and unconditionally secure. The Bank encodes each secret string $x\in\{0,1\}^n$ as a single-photon state $|x\rangle = \frac{1}{\sqrt n}\sum_{k=1}^n (-1)^{x_k}\hat a_k^\dagger|0\rangle$; the verifier interferes this state mode-by-mode with his own equal-superposition state through 50/50 beam splitters. Two single-photon clicks in distinct output modes reveal the parity $x_k \oplus x_l$ of a sampled tuple, while two photons in one mode give no information. The security proof reduces any forging strategy to maximizing the average fidelity with the honest state, imports the bound $\bar F \le \frac12 + \frac1n$, and shows that the forger's success probability decays exponentially whenever the honest success rate exceeds the forger's by the noise tolerance $\frac14 - \frac{1}{2n}$; at $n=14$ that tolerance is 21.4%. In the weak-coherent-state implementation, the same verification uses a single 50/50 beam splitter and two single-photon threshold detectors, independent of the note size.
Load-bearing premise
The proof assumes that any forger must send exactly one photon distributed over the $n$ modes for each copy, because it only analyzes single-photon mixed states; the verifier's local test, however, does not reject states with two photons in two different modes, which also produce two single-photon clicks.
Editorial extensions
If this is right
- If the central claim is correct, a fixed passive linear-optical circuit—one 50/50 beam splitter and two threshold detectors in the coherent-state version—suffices to verify quantum money at any noise tolerance up to the threshold, whereas earlier matching-based schemes needed more optical elements as the tolerance grew.
- Because verification uses a single round of classical communication, the Bank does not need to keep an active memory of the interaction, so many local verifiers can authenticate notes concurrently.
- Each note can be reused for a number of verifications linear in its size, with the Bank capping the total number of attempts before the note is retired.
- The security guarantee is information-theoretic rather than computational, so it would survive an adversary with unbounded quantum computing power.
- If the fidelity bound $\bar F \le \frac12 + \frac1n$ holds for all $n$, the scheme's asymptotic noise tolerance reaches 25%, the conjectured ceiling for matching-based money schemes.
Reading between the lines
- Inference: Since the coherent-state Sampling Matching circuit has already been demonstrated with weak pulses, running the verification at $n=14$ and measuring the honest-holder error rate would turn the 21.4% tolerance from a theoretical number into a directly testable one.
- Inference: The same parity-sampling game could plausibly be reused for other linear-optics verification tasks—checking that a prover knows an encoded string while revealing only one parity at a time—so the fixed-circuit simplification may outlive this particular money scheme.
- Inference: If the fidelity bound $\bar F \le \frac12 + \frac1n$ is ever proven for all $n$, the fixed circuit would achieve the conjectured matching-scheme ceiling of 25% noise tolerance without any increase in optical hardware.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript introduces a private quantum money mini-scheme whose verification is based on the Sampling Matching problem. The Bank prepares q copies of single-photon superposition states encoding random n-bit strings; a verifier interferes each selected copy with a local reference state through 50/50 beam splitters, checks the click statistics, and forwards parity outcomes to the Bank. The paper claims information-theoretic unforgeability with a noise tolerance of 21.4%, a fixed passive linear-optical verification circuit, and re-usability that grows linearly with note size. A practical implementation using weak coherent states, a single 50/50 beam splitter, and two threshold detectors is also described. Correctness is analyzed with Chernoff bounds; unforgeability is reduced to a fidelity bound imported from [AA17], with a short argument that coherent attacks reduce to collective attacks. Section 3.4 explicitly states that no full security proof is provided for the coherent-state scheme.
Significance. If the security proof were complete, the scheme would be a genuinely useful simplification of matching-based quantum money: a fixed passive linear-optical verification circuit, a single round of classical communication with the Bank, and a claimed noise tolerance comparable to or better than previous schemes. The correctness calculation is simple, and the circuit simplification for the coherent-state implementation is attractive. However, the advertised unconditional security is not established by the manuscript. The central adversary bound is imported from another paper and is only numerically verified and partly conjectured; the proof for the practical threshold-detector implementation explicitly disclaims a full analysis; and the reduction from coherent to collective attacks is asserted rather than proved. These are load-bearing gaps in the central claim, not presentation issues.
major comments (4)
- [Section 3.4 / Abstract] The abstract promises 'unconditional security' for a practically feasible scheme using weak coherent states, but Section 3.4 states: 'Here we are not providing full security proof of our quantum money scheme using coherent states.' The security analysis in Section 3.3 is formulated for single-photon states of the form Eq. (22) and does not analyze the vacuum or multi-photon components of the coherent states used in Eq. (43). Since the coherent-state implementation is exactly the one advertised as practical, the central practical claim is unsupported by the proof given in the manuscript.
- [Section 3.3.1, Eq. (33)] The main adversary bound, Eq. (33), is taken directly from [AA17] as a numerically verified inequality for n <= 14 and as a conjecture for larger n. The paper provides no proof or rigorous numerical certification of this SDP bound and no detailed demonstration that the SDP optimization for the Sampling Matching scheme is identical to the one solved in [AA17]. Since Eq. (33) is the step that converts the fidelity calculation into an upper bound on the forging probability, the claimed 'unconditional' security is conditional on an unproven external bound. This is a substantive gap for an information-theoretic security claim.
- [Section 3.3.1, before Eq. (21)] The proof restricts the adversary to single-photon states of the form Eq. (22), justified by the assertion that any other state fails the step 5 check of the Verification phase with certainty. This assertion is valid only for ideal photon-number-resolving detection. The practical implementation in Section 3.4 uses threshold detectors, which do not resolve photon number, so a multi-photon component distributed over distinct modes can in principle produce the required click pattern. The reduction to Eq. (22) therefore does not cover the threshold-detector implementation, and the manuscript needs either a security analysis of multi-photon adversarial states in that setting or an explicit statement that the proof applies only to the PNR implementation.
- [Section 3.3.2] The reduction from coherent attacks to collective attacks is handled in one paragraph asserting that the Croke-Kent teleportation argument applies because the setting is 'very similar.' No formal mapping between the money-forging game and the bit-commitment setting is given, and the role of two independent verifiers together with authenticated classical communication to the Bank is not addressed. Since this reduction is needed to rule out arbitrary joint operations across the q' copies, the proof of unconditional security is incomplete at this step as well.
minor comments (4)
- [Definition 2.2, Eq. (4)] Equation (4) writes the second verification event as VerB_H($1) = 1 twice; the second event should be VerB_H($2) = 1.
- [Section 4, Eq. (41)] In the measure-and-resend example for n = 4, the adversary state of Eq. (40) provides correct parity information only for the measured tuple. Since the verifier can obtain any of the six tuples, the error probability is 5/12, not 1/3 as stated in Eq. (41).
- [Section 3.4, Fig. 7] The text repeatedly refers to 'single-photon clicks' in the coherent-state implementation, but threshold detectors are not photon-number-resolving and produce only binary click/no-click outcomes. The wording should be adjusted to avoid implying number resolution.
- [Throughout] There are several typographical errors, including 'upto' in the abstract, 'mdoe' in Section 2.2.2, 'prarity' in Section 3.3.2, and some inconsistent pronoun use. A careful proofreading pass is needed.
Circularity Check
No circularity: the security proof is derived from the paper's own Sampling Matching analysis plus the external AA17 SDP bound, and KKD19 self-citations are background/implementation support rather than load-bearing.
full rationale
The derivation chain is not circular. The unforgeability proof in Section 3.3 does not assume the theorem it is trying to prove: it computes the adversary's per-copy error probability directly from the Sampling Matching output operator in Section 2.2.2 (Eqs. (9)-(14), (24)-(31)), then imports only the numerical fidelity bound F-bar <= 1/2 + 1/n for n <= 14 from Amiri and Arrazola [AA17], an external source; the paper explicitly says 'Here we directly use the SDP result of [AA17]'. The 21.4% noise tolerance is a consequence of that external bound for n = 14, not a fitted parameter. Citations to the author's own KKD19 work supply the Sampling Matching primitive and the coherent-state implementation, but the paper restates the SM scheme in Section 2.2.2 and describes the coherent-state circuit in Section 3.4 with equations; KKD19 is an experimentally demonstrated, published result, so it counts as independent support under the review rules rather than a load-bearing self-citation. The verification thresholds (l_min and delta) are defined from honest-holder expectations and are standard correctness checks, not predictions of security. The only notable gaps: the absence of a full security proof for the coherent-state scheme (Section 3.4: 'Here we are not providing full security proof of our quantum money scheme using coherent states') and the proof's restriction to single-photon states of the form Eq. (22) are completeness and correctness limitations, not circular reductions. Therefore the circularity score is 0.
Assumptions & free parameters
free parameters (3)
- n (string length / note size) =
14 for the claimed 21.4% tolerance
- delta (Bank cutoff) =
(c - c_adv)/2
- epsilon (local test security factor) =
not specified numerically
assumptions (6)
- standard math Chernoff-Hoeffding bound
- standard math Quantum mechanics and no-cloning
- domain assumption Ben-David and Sattath reduction from mini-scheme to full scheme requires collision-resistant hash functions secure against quantum adversaries
- domain assumption The SDP bound Eq. (33): average fidelity <= 1/2 + 1/n, numerically verified for n<=14 and conjectured for all n
- domain assumption Croke and Kent proof that coherent attacks are no more powerful than collective attacks
- ad hoc to paper Adversarial states can be restricted to single-photon states
Cite this review
Pith. "Pith review of Practically feasible robust quantum money with classical verification." pith.science (2026). https://pith.science/paper/XVR472KX
@misc{pith2026190804114,
author = {Pith},
title = {Pith review of: Practically feasible robust quantum money with classical verification},
year = {2026},
howpublished = {\url{https://pith.science/paper/XVR472KX}},
note = {Machine review of arXiv:1908.04114}
}
read the original abstract
We introduce a private quantum money scheme with the note verification procedure based on Sampling Matching, a problem in the one-way communication complexity model introduced by Kumar et al.[Nature Communications 10, Article number: 4152]. Our scheme involves a Bank that produces and distributes quantum notes, noteholders who are untrusted and trusted local verifiers of the Bank to whom the holders send their notes in order to carry out transactions. The key aspects of our money scheme include: note verification procedure requiring a single round classical interaction between the local verifier and Bank; fixed verification circuit that uses only passive linear optical components; re-usability of each note in our scheme which grows linearly with the size of note, and an unconditional security against any adversary trying to forge the banknote while tolerating the noise of up to 21.4%. We further describe a practical implementation technique of our money scheme using weak coherent states of light and the verification circuit involving a single 50/50beam splitter and 2 single-photon threshold detectors. Previous best-known matching based money scheme proposal [AA17] involves a verification circuit where the number of optical components increase proportionally to the increase in desired noise tolerance (robustness). In contrast, we achieve any desired noise tolerance (up to a maximal threshold value) with only a fixed number of optical components. This considerable reduction of components in our scheme enables us to reach the robustness values that are not feasible for any existing money scheme with the current technology.
Figures
Figures from the paper (5 more)
Reference graph
Works this paper leans on
-
[1]
Quantum money with nearly optimal error tolerance
Ryan Amiri and Juan Miguel Arrazola. Quantum money with nearly optimal error tolerance. Physical Review A , 95(6):062334, 2017
work page 2017
-
[2]
Quantum money from hidden subspaces
Scott Aaronson and Paul Christiano. Quantum money from hidden subspaces. In Proceedings of the forty-fourth annual ACM symposium on Theory of computing , pages 41--60. ACM, 2012
work page 2012
-
[3]
Quantum superiority for verifying np-complete problems with linear optics
Juan Miguel Arrazola, Eleni Diamanti, and Iordanis Kerenidis. Quantum superiority for verifying np-complete problems with linear optics. npj Quantum Information , 4(1):56, 2018
work page 2018
-
[4]
Practical quantum retrieval games
Juan Miguel Arrazola, Markos Karasamanis, and Norbert L \"u tkenhaus. Practical quantum retrieval games. Physical Review A , 93(6):062311, 2016
work page 2016
-
[5]
A new protocol and lower bounds for quantum coin flipping
Andris Ambainis. A new protocol and lower bounds for quantum coin flipping. Journal of Computer and System Sciences , 68(2):398--416, 2004
work page 2004
-
[6]
Quantum cryptography: public key distribution and coin tossing
Charles H Bennett and Gilles Brassard. Quantum cryptography: public key distribution and coin tossing. Theor. Comput. Sci. , 560(12):7--11, 2014
work page 2014
-
[7]
Quantum tokens for digital signatures
Shalev Ben-David and Or Sattath. Quantum tokens for digital signatures. arXiv preprint arXiv:1609.09047 , 2016
arXiv 2016
-
[8]
Universal blind quantum computation
Anne Broadbent, Joseph Fitzsimons, and Elham Kashefi. Universal blind quantum computation. In 2009 50th Annual IEEE Symposium on Foundations of Computer Science , pages 517--526. IEEE, 2009
work page 2009
Show all 37 references
-
[9]
An adaptive attack on wiesner's quantum money
Aharon Brodutch, Daniel Nagaj, Or Sattath, and Dominique Unruh. An adaptive attack on wiesner's quantum money. arXiv preprint arXiv:1404.1507 , 2014
2014 arXiv
-
[10]
Experimental investigation of practical unforgeable quantum money
Mathieu Bozzio, Adeline Orieux, Luis Trigo Vidarte, Isabelle Zaquine, Iordanis Kerenidis, and Eleni Diamanti. Experimental investigation of practical unforgeable quantum money. npj Quantum Information , 4(1):5, 2018
2018
-
[11]
Quantum cryptography beyond quantum key distribution
Anne Broadbent and Christian Schaffner. Quantum cryptography beyond quantum key distribution. Designs, Codes and Cryptography , 78(1):351--382, 2016
2016
-
[12]
Exponential separation of quantum and classical one-way communication complexity
Ziv Bar-Yossef, Thathachar S Jayram, and Iordanis Kerenidis. Exponential separation of quantum and classical one-way communication complexity. In Proceedings of the thirty-sixth annual ACM symposium on Theory of computing , pages 128--137. ACM, 2004
2004
-
[13]
Secure multi-party quantum computation
Claude Cr \'e peau, Daniel Gottesman, and Adam Smith. Secure multi-party quantum computation. In Proceedings of the thiry-fourth annual ACM symposium on Theory of computing , pages 643--652. ACM, 2002
2002
-
[14]
Security details for bit commitment by transmitting measurement outcomes
Sarah Croke and Adrian Kent. Security details for bit commitment by transmitting measurement outcomes. Physical Review A , 86(5):052309, 2012
2012
-
[15]
Quantum money from knots
Edward Farhi, David Gosset, Avinatan Hassidim, Andrew Lutomirski, and Peter Shor. Quantum money from knots. In Proceedings of the 3rd Innovations in Theoretical Computer Science Conference , pages 276--289. ACM, 2012
2012
-
[16]
Quantum memory for photons: Dark-state polaritons
Michael Fleischhauer and Mikhail D Lukin. Quantum memory for photons: Dark-state polaritons. Physical Review A , 65(2):022314, 2002
2002
-
[17]
Experimental preparation and verification of quantum money
Jian-Yu Guan, Juan Miguel Arrazola, Ryan Amiri, Weijun Zhang, Hao Li, Lixing You, Zhen Wang, Qiang Zhang, and Jian-Wei Pan. Experimental preparation and verification of quantum money. Physical Review A , 97(3):032338, 2018
2018
-
[18]
Quantum money with classical verification
Dmitry Gavinsky. Quantum money with classical verification. In Computational Complexity (CCC), 2012 IEEE 27th Annual Conference on , pages 42--52. IEEE, 2012
2012
-
[19]
Quantum digital signatures
Daniel Gottesman and Isaac Chuang. Quantum digital signatures. arXiv preprint quant-ph/0105032 , 2001
2001 arXiv
-
[20]
New constructions for quantum money
Marios Georgiou and Iordanis Kerenidis. New constructions for quantum money. In LIPIcs-Leibniz International Proceedings in Informatics , volume 44. Schloss Dagstuhl-Leibniz-Zentrum fuer Informatik, 2015
2015
-
[21]
Exponential separations for one-way quantum communication complexity, with applications to cryptography
Dmitry Gavinsky, Julia Kempe, Iordanis Kerenidis, Ran Raz, and Ronald De Wolf. Exponential separations for one-way quantum communication complexity, with applications to cryptography. In Proceedings of the thirty-ninth annual ACM symposium on Theory of computing , pages 516--5...
2007
-
[22]
The foundations of cryptography, volume 2, chapter encryption schemes, 2004
Oded Goldreich. The foundations of cryptography, volume 2, chapter encryption schemes, 2004
2004
-
[23]
Information-theoretical aspects of quantum measurement
Alexander Semenovich Holevo. Information-theoretical aspects of quantum measurement. Problemy Peredachi Informatsii , 9(2):31--42, 1973
1973
-
[24]
Linear transformations which preserve trace and positive semidefiniteness of operators
Andrzej Jamio kowski. Linear transformations which preserve trace and positive semidefiniteness of operators. Reports on Mathematical Physics , 3(4):275--278, 1972
1972
-
[25]
Experimental demonstration of quantum memory for light
Brian Julsgaard, Jacob Sherson, J Ignacio Cirac, Jarom \' r Fiur \'a s ek, and Eugene S Polzik. Experimental demonstration of quantum memory for light. Nature , 432(7016):482, 2004
2004
-
[26]
Experimental demonstration of quantum advantage for one-way communication complexity surpassing best-known classical protocol
Niraj Kumar, Iordanis Kerenidis, and Eleni Diamanti. Experimental demonstration of quantum advantage for one-way communication complexity surpassing best-known classical protocol. Nature communications , 10(1):1--10, 2019
2019
-
[27]
Quantum memory for light
AE Kozhekin, Klaus M lmer, and E Polzik. Quantum memory for light. Physical Review A , 62(3):033809, 2000
2000
-
[28]
Optical quantum memory
Alexander I Lvovsky, Barry C Sanders, and Wolfgang Tittel. Optical quantum memory. Nature photonics , 3(12):706, 2009
2009
-
[29]
An online attack against wiesner's quantum money
Andrew Lutomirski. An online attack against wiesner's quantum money. arXiv preprint arXiv:1010.0256 , 2010
2010 arXiv
-
[30]
Quantum cheques
Subhayan Roy Moulick and Prasanta K Panigrahi. Quantum cheques. Quantum Information Processing , 15(6):2475--2486, 2016
2016
-
[31]
Optimal counterfeiting attacks and generalizations for wiesner’s quantum money
Abel Molina, Thomas Vidick, and John Watrous. Optimal counterfeiting attacks and generalizations for wiesner’s quantum money. In Conference on Quantum Computation, Communication, and Cryptography , pages 45--64. Springer, 2012
2012
-
[32]
Unforgeable noise-tolerant quantum tokens
Fernando Pastawski, Norman Y Yao, Liang Jiang, Mikhail D Lukin, and J Ignacio Cirac. Unforgeable noise-tolerant quantum tokens. Proceedings of the National Academy of Sciences , 109(40):16079--16082, 2012
2012
-
[33]
Semi-quantum money
Roy Radian and Or Sattath. Semi-quantum money. arXiv preprint arXiv:1908.08889 , 2019
1908 arXiv
-
[34]
Probability and computing: Randomized algorithms and probabilistic analysis, 2005
E Upfal and M Mitzenmacher. Probability and computing: Randomized algorithms and probabilistic analysis, 2005
2005
-
[35]
Stephen Wiesner. S. wiesner, sigact news 15, 78 (1983). Sigact News , 15:78, 1983
1983
-
[36]
A single quantum cannot be cloned
William K Wootters and Wojciech H Zurek. A single quantum cannot be cloned. Nature , 299(5886):802--803, 1982
1982
-
[37]
Lower bounds by probabilistic arguments
Andrew C Yao. Lower bounds by probabilistic arguments. In Foundations of Computer Science, 1983., 24th Annual Symposium on , pages 420--428. IEEE, 1983
1983
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.