Conceptio › Archive › arXiv CS
arXiv CSopen access

Classical Verification of Quantum Computation with Quasilinear Resources, from Compiled Nonlocal Games

Finn Holler et al. · arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Classical Verification of Quantum Computation with Quasilinear Resources, from Compiled Nonlocal Games Finn Holler*

Anand Natarajan†

ETH Zurich

MIT

arXiv:2609.38060v1 [quant-ph] 29 Sep 2026

September 29, 2026

Abstract Computational self-testing gives a classical verifier command over the quantum register of a single computationally bounded prover. We use this framework to construct the first argument system for BQP with quasilinear total resource requirements in the circuit model. Our argument system is based on the learning with errors (LWE) assumption and requires total resources of O(poly(λ, log g) · g) for delegating a circuit with g gates, where λ is the LWE security parameter. This is achieved by constructing a new computational self-test for certifying the prover’s quantum state and using it to dequantize the efficient verification protocol of Broadbent (ToC 2018). Specifically, this self-test enables the verifiable, random remote state preparation √ of tensor product √ states of the single-qubit Clifford observables σX , σY , σZ , (σY − σX )/ 2 and (σY + σX )/ 2, with constant robustness: the verification error is independent of the number of prepared qubits. This approach was first proposed by Coladangelo et al. (ToC 2024) in the multi-prover setting. We replicate their result in the single-prover setting by applying the compiler proposed by Kalai et al. (STOC 2023)—which turns any nonlocal game into a single-prover argument system—to a modified version of their self-test.

* [email protected] † [email protected]

1

Contents 1

Introduction

3

2 Technical overview 2.1 Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.2 Rigidity result . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.3 BQP verification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.4 Technical contributions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.5 Open questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.6 Paper outline . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

5 5 7 11 12 13 14

3

Preliminaries 3.1 Notation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.2 Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.3 Quantum Fourier transform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.4 Bell states . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.5 Distance measures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.6 Nonlocal games . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.7 Cryptography . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.7.1 The KLVY transform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.7.2 Modeling prover strategies in a compiled game . . . . . . . . . . . . . . . 3.7.3 Security of the cryptography . . . . . . . . . . . . . . . . . . . . . . . . . . 3.7.4 QFHE Overhead . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.8 Approximate group representations . . . . . . . . . . . . . . . . . . . . . . . . . .

15 15 19 21 23 24 26 26 29 29 30 37 38

4

Rigidity 4.1 Protocols . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.1.1 Honest prover strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.2 Compiled prover switching . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3 Soundness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.1 Conjugation relation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.2 Mixed-versus-pure basis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.3 Small/large answer consistency . . . . . . . . . . . . . . . . . . . . . . . . 4.3.4 Commutation relation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.5 Product relation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.6 Clifford conjugation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.7 Clifford group relations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.3.8 Rounding to an exact representation . . . . . . . . . . . . . . . . . . . . . . 4.3.9 Clifford test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.4 State characterization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

41 41 46 47 55 55 60 63 64 66 68 70 72 81 94

5

BQP verification 106 5.1 Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106 5.2 Soundness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107 5.3 Sequential repetition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112

A Supplementary Material 115 A.1 Compiled (anti-)commutation tests . . . . . . . . . . . . . . . . . . . . . . . . . . . 115 A.2 Isometry circuit calculation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116 A.3 Parseval’s identity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118 A.4 Useful results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119

2

1

Introduction

Quantum computers are becoming more capable, with a centralized ‘quantum cloud’ being the dominant deployment model. In the near term, users are thus unlikely to own quantum hardware and they will have to access it remotely, on machines they can’t control. This makes trustless classical delegation of quantum computation an important primitive. Classically, this topic has been extensively studied and its practical relevance is clear from numerous applications in blockchain technology and cloud computing. Extending the idea to the quantum realm, we would like that a fully classical verifier could delegate an arbitrary quantum computation to a single untrusted prover, having a strong correctness guarantee for the purported outcome. How to achieve this functionality is far from obvious, and doing so efficiently with information-theoretic security is still a major open problem. In a breakthrough result Mahadev showed that classical verification of quantum computations (CVQC) is indeed possible under cryptographic assumptions, constructing the first singleprover, classical-verifier argument system for BQP [Mah18]. Her protocol has overall complexity of O( g3 ) to verify a circuit of g gates, placing high resource demands on the quantum prover. The overhead stems from a circuit-to-Hamiltonian reduction, which allows the verifier to check the computation by testing that there exists a Feynman-Kitaev history state with sufficiently low energy. Since the best-known circuit-to-Hamiltonian reductions [BC18] have an inversepolynomial promise gap—distinguishing good from bad computations—a polynomial overhead is inherent to all works taking a Hamiltonian approach1 . This situation is unsatisfactory, since CVQC acts as a primitive in other works, which inherit the cubic overhead. Zhang partially addressed this issue by proposing the first linear-time CVQC protocol for measurement-based computations in the quantum random-oracle model [Zha22]2 . Although the measurement-based and circuit models are equivalent, converting from the latter to the former for a fixed cluster state incurs a polynomial factor in the circuit size, due to locality restrictions stemming from the geometry of the cluster state. Constructing an efficient protocol in the circuit model was explicitly left open in [Zha22]; we resolve this by constructing the first CVQC protocol in the circuit model with quasilinear resource requirements and proving its soundness. Delegation through dequantisation. As inspiration for our construction, we turned to an older body of results in the nonlocal, information-theoretic model. Here a classical verifier interacts with multiple provers sharing entanglement, who are assumed to not communicate. These interactive protocols are called nonlocal games. In this model more efficient protocols have been constructed [CGJV24] using the powerful phenomenon of self-testing [MY04], in which nonlocal correlations can be used to certify specific quantum states and measurements. A direct application of self-testing can yield a test for an accepting history state, in the sense of the Mahadev protocol: this is done by the elegant nonlocal protocol of Grilo [Gri19]. But self-testing enables richer control over the prover’s system: Coladangelo et al. realized that it could be used to simulate protocols with quantum communication between the prover and verifier, which are known to have very low overhead. In particular, they were able to implement an efficient protocol due to Broadbent [Bro18] in the nonlocal setting, achieving quasi-linear total resources with a fully classical verifier. In the language of a more recent line of work [GV19, Zha22, GMP23, Zha25], the self-testing results they relied on can be viewed as a nonlocal form of verifiable, random remote state preparation (RSP) — a primitive that can be used to construct CVQC by ‘dequantising’ verification protocols requiring quantum communication. 1A positive resolution of the quantum PCP conjecture as formulated in [AAV13] would improve this situation. 2 The introduction of his paper provides a thorough overview of the protocol landscape.

3

Informally, verifiable RSP is a single-prover interactive protocol with classical messages, which realises the functionality of sending a quantum state, even in the presence of cheating provers. Single-prover protocols from nonlocal games. We obtain an efficient CVQC protocol by constructing a verifiable random RSP, informed by the self-test of [CGJV24]. Specifically, we employ the compiler of Kalai et al. [KLVY23], which serves as a bridge between the nonlocal and single-prover settings. Compilation here means taking any nonlocal game and converting it into a single-prover argument system using a fixed transformation. The approach of building argument systems through compilation of proof systems has a long and fruitful history in the classical cryptographic literature [KR09, KRR21, BC12]. The KLVY transform achieves this by enforcing the structural assumption of non-communication by cryptographic means, specifically by using quantum fully homomorphic encryption (QFHE) with classical ciphertexts; a strengthening of classical FHE to allow for homomorphic evaluation of quantum circuits. Earlier results have shown that these compiled nonlocal games are a powerful resource, enabling the combination of techniques from both the cryptography and nonlocal-games literature, while retaining the self-testing powers of their nonlocal counterparts [NZ23, MNZ24]. Unlike earlier works on computational self-testing, which had to exploit the specific structure of the underlying computational assumption and build bespoke cryptographic machinery [BCM+ 21, Mah18, MV21], an approach through compiled nonlocal games yields a more modular construction that can be instantiated from different cryptographic assumptions [GV24, BK25, BKM+ 25], with proofs that closely follow their nonlocal models, where the cryptography can largely be abstracted away. For the first time we use this paradigm to construct verifiable random remote state preparation à la [GV19, GMP23] from compiled nonlocal games. New rigidity results. Our main contribution is a novel computational rigidity result3 , which generalizes the Pauli braiding test [NV17] from the Heisenberg–Weyl group to what we call the extended Pauli group. This allows us to certify that an efficient prover holds a state that is computationally indistinguishable from a uniformly random element of S ⊗n , with n   o S = {|0⟩, |1⟩} ∪ |+θ ⟩ = √1 |0⟩ + eiθ |1⟩ : θ ∈ {0, π4 , . . . , 7π } , 4 2

⊗n

or its complex conjugate (S ), without the prover knowing which state he holds. This complex conjugate ambiguity (also called “complex conjugation attack”) is unavoidable, since the correlations tested by interactive protocols are invariant under complex conjugation. Still, it is important that the final state held by the prover is indistinguishable from a classical mixture and not a coherent superposition of the two conjugation branches. This strength of characterization wasn’t achieved by earlier works, such as [GV19], where a coherent mixture of the canonical and complex conjugate state can’t be excluded. The RSP guarantee above can be used to dequantise Broadbent’s efficient protocol for verifying BQP computations with constant completeness–soundness gap in the circuit model [Bro18], yielding our headline result: Informal Theorem 1.1 (Formally, Corollary 5.1). Under the assumption that LWE is sub-exponentially hard for non-uniform quantum adversaries, every language L ∈ BQP admits a single-prover, classicalverifier argument system with total resource requirement Õ(|Cx |), where Cx is the circuit deciding L on input x. The sub-exponential hardness assumption is used only to set λ = polylog(|Cx |) to obtain quasilinear resources; polynomial hardness of LWE still yields a correct argument system, with almost-linear resource requirements, i.e. O(|Cx |1+ε ) for all ε > 0. Here non-uniform adversaries do not include (potentially inefficiently computable) quantum advice. 3We believe that a straight-forward translation to the nonlocal setting should reproduce the rigidity guarantee

of [CGJV24], with slightly better resource requirements (no logarithmic factor).

4

A representation-theoretic perspective. Our protocol design and discussion can serve as an independent discussion of [CGJV24], who were the first to introduce the richer set of self-tests for operators beyond the Pauli group; we show that these tests can be extended to the singleprover setting. Along the way, we reformulate the analysis to use the framework of approximate group representation theory for self-testing, which was still nascent when [CGJV24] developed their protocol. Hopefully this new perspective can clarify some of the technical issues that were solved in a more ad-hoc way in their work. To the best of our knowledge, this is the first rigidity proof via approximate group representation theory for a group whose representation theory is richer than that of the Heisenberg–Weyl group; we hope that this will inform future constant-robustness rigidity results for larger classes of observables. Our construction also yields a slight performance improvement over the self-test from [CGJV24] (total resources of O(n) instead of O(n log n) for certifying n qubits) for circuits compiled in the gateset assumed by [Bro18], because we no longer require communicating a permutation on the qubits, as is done in their ‘ParBell’ subtest.

2

Technical overview

This section provides a high-level technical overview of the paper. We begin by recalling important prior results; we then introduce the idea behind our rigidity test and outline its soundness analysis, carried out in Section 4. Finally, we sketch how the rigidity result is used to construct an efficient CVQC protocol with quasilinear resources, referring to Section 5 for the full soundness argument.

2.1

Background

In this work we use compiled nonlocal games (schematically illustrated in Fig. 1) toward an efficient argument system for BQP.

Alice Verifier Bob

Figure 1: Schematic of a compiled nonlocal game. Lock denotes quantum fully homomorphic encryption. Both ‘Alice’ and ‘Bob’ are invocations of the same single prover and are only distinguished for illustrative purposes. Communication is sequential and flows from top to bottom. Proof and argument systems for BQP already exist in both the nonlocal and classical verification settings, and Table 1 summarizes the resource requirements of prior works4 . We note that the polylogarithmic overhead in the circuit size in our construction is often unavoidable: most protocols assume a fixed universal gate set, and converting between gate sets typically introduces a polylogarithmic factor in the circuit size, via the Solovay–Kitaev theorem. In our case this overhead becomes explicit, since both QFHE and the Broadbent protocol require distinct gate sets, so one conversion is already baked into the protocol. 4 These results are stated in different settings; for a fair comparison, we include any overhead from repetitions

needed to achieve a constant completeness–soundness gap.

5

Protocol

Type

Provers

Rounds

Total resources

Assumption Blind

[RUV13]

MB

2

poly(n)

IT

Yes

[GKW15]

MB

2

poly(n)

IT

Yes

[Gri19]

LH

2

1

IT

No

[CGJV24]

C

2

O(depth)/2

≥ g8192 ≥ g2048 Ω ( n g2 ) Θ( g log g)

IT

Yes/No

[Mah18]

LH

1

2

O(poly(λ) g3 )

LWE

No

[Zha22]

MB

1

O(depth)

O(poly(λ) g)

LWE + QROM

No

Here

C

1

O(depth)

O(poly(λ, log g) g)

LWE

No

Table 1: Resource overheads of classical-verifier BQP verification protocols. The [CGJV24] result presents two protocols, which are compactly described as a single entry in the table (first entry is the ‘Leash’ and second is the ‘Dog walker’ protocol). g is the number of gates in the delegated circuit, n the qubit count, and λ the security parameter. “Total resources” bundles prover time and gate complexity, EPR pairs, and classical communication; “depth” refers to the T-depth of the delegated circuit. Abbreviations: LH = local Hamiltonian, MB = MBQC, C = circuit, IT = information-theoretic, LWE = learning with errors, QROM = quantum random oracle model. The Broadbent protocol Since the Broadbent protocol plays an important role in our construction, we briefly discuss it here. At a high level, its soundness rests on the indistinguishability of two kinds of rounds, called test rounds and computation rounds. The test rounds function as trapdoors that constrain a cheating prover: any strategy that is accepted with high probability in test rounds must yield the correct circuit outcome in computation rounds. Round indistinguishability is achieved by encrypting the verifier’s input states with the quantum one-time pad (QOTP). For random classical bits a, b ∈ {0, 1}, the QOTP of a single-qubit state |ψ⟩ ∈ C2 is σXa σZb |ψ⟩. By the Pauli twirl, when ( a, b) is uniform the QOTP provides the same information-theoretic security as its classical analog: 1 1 ∑ σXa σZb |ψ⟩⟨ψ|σZb σXa = 2 , 4 a,b∈{ 0,1} which generalizes straightforwardly to multi-qubit states. A candidate approach, to make the different rounds indistinguishable, is for the verifier to encrypt the circuit input (assumed to be encoded in the computational basis) with the QOTP. Knowing the circuit specification, the verifier could ideally keep track of the updated QOTP keys by commuting each gate in the circuit past the tensor product of Pauli σX and σZ operators that implement the QOTP encryption. Unfortunately, for circuits over the universal gate set {σX , σZ , H, CNOT, T }, this commutation trick succeeds only for the Clifford gates σX , σZ , H, and CNOT—insufficient on its own, since any circuit using only Clifford gates can be efficiently simulated classically [AG04]. By incorporating T-gate gadgets, however, the approach can be made to work: in addition to the QOTP-encrypted input qubits, the verifier sends encrypted magic state qubits (one per T-gate in the circuit) that enable the application of a T-gate on QOTP encrypted qubits through re-keying and hence allow the verifier to classically track all key updates through the full circuit. For every gate in the circuit, the QOTP keys thus evolve 6

as ( a, b) 7→ ( a′ , b′ ) in a way that is known to the verifier, so at the end of the computation the verifier knows exactly how he can decrypt the encrypted outcome returned by the prover. We refer the reader to [Bro18] for a full description and security analysis. For our purposes, the crucial point is that the verifier needs only prepare states from the following set of ten:   o n } . S = {|0⟩, |1⟩} ∪ |+θ ⟩ = √1 |0⟩ + eiθ |1⟩ : θ ∈ {0, π4 , . . . , 7π 4 2

If we can design a remote state preparation protocol which certifies that the prover holds a random tensor product of these states—without knowing which one—through purely classical interaction, we can use it to replace the quantum communication at the start of the Broadbent protocol. The set of states S coincides with the states certified in a work by Gheorghiu and Vidick [GV19]; unfortunately, their protocol does not have constant rigidity and thus cannot directly be used for our purposes. They obtain a per-qubit rigidity error of ε (which quantifies the deviation of the obtained state from the target state) with a resource cost of O(1/ε3 ). To delegate a circuit of size g, the Broadbent protocol requires O( g) prepared qubits, so naively invoking this RSP g times already costs O( g/ε3 ). Moreover, to obtain constant overall rigidity error ε tot , the per-qubit error must scale as ε tot /g, driving the total cost up to O( g4 )—worse than the Mahadev protocol. Zhang [Zha22] gives an efficient parallel RSP protocol for states |+θ ⟩ with θ ∈ {0, 1, . . . , 7}, but this only covers part of S : the computational basis states are missing, which is why his construction applies only to verification in the MBQC model, through dequantizing the protocol of [FKD18].

2.2

Rigidity result

So-called rigidity results, which allow a verifier to characterize the internal quantum operations of an untrusted prover, are central to (computational) self-testing. A rigidity result for the simple fact that the prover is applying two anti-commuting observables—which is provided by the CHSH or Magic Square nonlocal games—is remarkably powerful and is sufficient for many applications [RUV13,BCM+ 21,Mah18,Gri19]. How this observation about the internal workings of an untrusted prover is obtained differs strongly between nonlocal and early cryptographic works. The KLVY compiler allows us to reconcile the different settings, by enabling the use of nonlocal techniques in the cryptographic setting, uncovering their fundamental relation and reusing existing techniques, such as the framework of approximate group representations. It has been even noted that the analysis can be completely performed in the nonlocal setting, by restricting to computationally nonlocal strategies as defined in [BK25], eliminating the need to deal with the specifics of the cryptography, but instead having to make sure that the quantum operations satisfy the definition of a computationally nonlocal strategy. Rigidity results such as those in [MY04,RUV13,WBMS16,NV17] are usually stated as guarantees on the observables which the provers implement and on the entangled state which they share. From such a guarantee it is typically straightforward to deduce that a specific state has been prepared, provided it is an eigenstate of the certified observables, since applying the certified measurements projects into one of its eigenstates. The states in S are, up to a global phase, eigenstates of the single-qubit Clifford observables σX ,

σY ,

σZ ,

σF = √1 (σY − σX ), 2

σG = √1 (σY + σX ). 2

Certifying preparation of states in S therefore reduces to certifying these observables. This is a stronger guarantee than that the prover is applying two anti-commuting observables, which has traditionally been extensively studied. Fortunately, the analysis of these types of rigidity results can be unified through the framework of approximate group representation

7

theory5 , which has become a standard technique in self-testing after the development of the Pauli braiding test [NV17], which can also be applied in the cryptographic setting thanks to the KLVY compiler. We develop the main ideas of this framework first in the nonlocal setting, through the Heisenberg–Weyl group and the CHSH game (the scenario of certifying two anticommuting observables), and then explain how the argument extends to the group of interest, which contains the five observables from above. The CHSH game, named after Clauser, Horne, Shimony and Holt [CHSH69], is a two-prover nonlocal game that distills the original Bell experiment. Beyond its role in ruling out local hidden-variable theories [HBD+ 15], it has become a central tool in self-testing, including the breakthrough of [RUV13]. The game proceeds as follows: • The verifier samples two random bits x, y ∈ {0, 1} and sends them to the provers. • The provers respond with one bit each, denoted a, b ∈ {0, 1}. • The verifier accepts if and only if a ⊕ b = x · y. The no-communication assumption is what makes this game nontrivial, since both provers don’t know which question the other received. Classical, unentangled provers can win with probability at most 3/4, for instance by always outputting the same pre-agreed bit (a = b). Sharing entanglement, they can exploit the nonlocal correlations it enables and achieve a winning probability of cos2 (π/8) ≈ 0.853, which Tsirelson showed to be optimal among all quantum strategies [Tsi87]. A winning probability above 3/4 therefore witnesses genuinely quantum behavior—the Bell-test, or proof-of-quantumness, aspect of CHSH. The specific CHSH nonlocal game has even more power: its optimal strategy is unique up to isometry. This implies that if the provers win with a probability equal to the quantum optimum ω ∗ = cos2 (π/8), the verifier can conclude that they are playing the optimal strategy. The optimal strategy for CHSH consists of the provers sharing an EPR pair and measuring anticommuting observables on it. Fortunately, this also holds robustly, i.e. if the provers succeed in the CHSH game with a probability close to the quantum optimum ω ∗ − ε, then the provers’ measurements approximately anti-commute in a suitable distance measure (defined in Section 3) and they share a state which is close to an EPR pair. A classical verifier can therefore infer that successful, non-communicating provers implement approximately anti-commuting observables; in many applications, however, one needs control over which observables are realized, not merely which algebraic relation they satisfy (anti-commutation in this case). Approximate group representation theory supplies a way to achieve this, by determining the group defined by the algebraic relations and using the irreducible representations of that group. We will illustrate this approach using the single-qubit Heisenberg–Weyl group as an example. This group is generated by elements ω, x, and z, satisfying relations

⟨ω 2 = x2 = z2 = 1, xz = ωzx, zω = ωz, xω = ωx ⟩. This single-qubit group exhibits several one-dimensional irreducible representations (with ω = 1 and various sign choices for x and z) and a unique two-dimensional irreducible representation,     0 1 1 0 ω = −1, x = = σX , z = = σZ , 1 0 0 −1 corresponding to the Pauli matrices σX and σZ . Imposing ω = −1 thus leaves the anticommutation relation {z, x } = 0 as the algebraic relation defining the group—precisely the relation certified by the CHSH game. Let A0 and A1 be the measurements implemented by 5 For a comprehensive and thorough introduction to the subject, we refer the reader to the excellent course notes

of [Vid21].

8

one of the provers on questions 0 and 1, respectively. Because A0 and A1 are unitary (as binary observables) and approximately satisfy anti-commutation for a sufficiently successful prover, they form an approximate unitary representation of the single-qubit Heisenberg–Weyl group. The Gowers–Hatami (GH) theorem [GH17] guarantees that any approximate unitary representation can be rounded to an exact one on a larger Hilbert space. Informally, this means that there exists an isometry V such that for any ε > 0, VA0 ≈ε (σZ ⊗ 1)V,

and

VA1 ≈ε (σX ⊗ 1)V,

in the same state-dependent norm as defined in Section 3.5. We used the single-qubit case for illustration, but GH is most useful in the multi-qubit setting, where it certifies many qubits with constant robustness: the approximation error ε does not grow with the number of certified qubits. Single-qubit self-testing was known before GH, via Jordan’s lemma, but that approach does not easily scale. For n qubits the Heisenberg–Weyl group has relations

⟨ω 2 = x ( a)2 = z( a)2 = 1, x ( a)z(b) = ω a·b z(b) x ( a), z( a)ω = ωz( a), x ( a)ω = ωx ( a), x ( a ⊕ b) = x ( a) x (b), z( a ⊕ b) = z( a)z(b)⟩, where a, b ∈ {0, 1}n . This group again admits many one-dimensional irreducible representations, corresponding to all possible sign assignments, but only one 2n -dimensional irreducible representation: ω = −1,

x ( a) =

O

σXai = σX ( a),

i ∈[n]

z( a) =

O

σZai = σZ ( a).

i ∈[n]

Assuming one can construct prover observables A0 ( a) and A1 ( a) that exactly satisfy Ai ( a) Ai (b) = Ai ( a ⊕ b) for i ∈ {0, 1} and approximately satisfy the characteristic relation A0 ( a) A1 (b) = (−1)a·b A1 (b) A0 ( a), GH provides an isometry V such that for any ε > 0, VA0 ( a) ≈ε (σZ ( a) ⊗ 1)V,

and

VA1 ( a) ≈ε (σX ( a) ⊗ 1)V,

with error ε independent of n. To our knowledge, the multi-qubit Heisenberg–Weyl group is the most complex group previously self-tested in this framework. The observables needed for S lie in a larger group, which we call the extended Pauli group. It is generated by ω, x ( a), z( a) and g( a) with relations

⟨ω 4 = x ( a)2 = z( a)2 = g( a)2 = 1, x ( a)z(b) = ω 2a·b z(b) x ( a), z( a)ω = ωz( a), x ( a)ω = ωx ( a), g( a)ω = ωg( a), g( a)z(b) = ω 2a·b z(b) g( a), g( a) x ( a) g( a) = ω |a| x ( a)z( a) x ( a ⊕ b) = x ( a) x (b), z( a ⊕ b) = z( a)z(b), g( a ⊕ b) = g( a) g(b)⟩. Because ω is a fourth root of unity, the representation theory is substantially richer. First, when ω 2 = 1, there are many 2k -dimensional “classical” irreducible representations (0 ≤ k ≤ n); intermediate dimensions arise because x and g can anti-commute even when ω 2 = 1. Second, when ω 2 = −1, there are 2n+1 distinct 2n -dimensional “quantum” irreducible representations which, √ up to sign choices and phase ambiguity, correspond to the matrices σX , σZ , and σG = 1/ 2(σX + σY ). These are far more irreps than the unique quantum one in the Heisenberg–Weyl case, owing to sign freedom on g induced by its conjugation relation to x and z. Finally, both ω = i1 and ω = −i1 are admissible; this is the algebraic origin of the complex-conjugation attack discussed in the introduction and in [CGJV24, Zha22]. To apply GH in this setting, we must self-test the full relation set, including a conjugation relation. The only prior self-test for such a relation that we are aware of is due to [CGJV24], which heavily influenced our construction; it is specified in protocol 4 and its soundness is analyzed in Section 4.3.1. 9

Even after the relations are certified and the approximate representation is rounded, a perqubit sign ambiguity on G ( a) remains (here G ( a) denotes the prover’s implementation of the abstract group element g( a) in the 2n -dimensional branch). In the Heisenberg–Weyl case one excludes one-dimensional representations by requiring −1 7→ −1 under the approximate representation, equivalently discarding the ω = 1 branch; approximate anti-commutation enforces this automatically, as scalars cannot anti-commute. An analogous argument removes the ω 2 = 1 branch of “classical” irreps. for the extended Pauli group, but aligning the sign of G ( a) across qubits still requires an additional test, whose guarantee goes beyond the algebraic relations that defined the group, as we now want to pick out specific irreducible representations among the many admissible ones. Our self-test again follows [CGJV24], who confronted the same issue. They certify the same group with a protocol structurally similar to ours; the main difference is methodological, as their analysis predates the systematic GH framework and relies on more ad hoc arguments. We adapt their ideas into a self-test with a simpler structure and a more direct group-theoretic analysis. The idea of forcing a consistent sign choice across all G observables, used in [BSCA18, CGJV24], is a beautiful one. The test proceeds as follows: • The verifier asks Alice to measure pairs of her qubits in the Bell basis. • The verifier asks Bob to measure all of his qubits separately in the G eigenbasis. • The verifier accepts if and only if the correlations between the different G outcomes reported by Bob match the ones expected based on the Bell basis outcome reported by Alice. Intuitively, the test performs entanglement swapping. Provers who pass the earlier subtests must share something that has the properties of perfect entanglement (up to efficient distinguishers); Alice’s Bell measurement then converts inter-prover entanglement into entanglement internal to Bob’s register. Bob does not know the post-measurement state on his side, so inconsistent per-qubit signs for G alter his measurement statistics in a way the verifier can detect. We refer to protocol 11 subtests 2 and 3 for the protocol specification and to Section 4.3.9 for the full soundness argument; here we only sketch the main idea, using the Pauli Y operator as an example. Suppose Alice’s Bell measurement projects two of her qubits onto an EPR pair |Φ+ ⟩. By entanglement swapping, the two paired qubits on Bob’s side are then |Φ+ ⟩ as well. A direct calculation gives ⟨Φ+ |σY ⊗ σY |Φ+ ⟩ = −1, so if Bob applies σY with the same sign on both qubits, his outcomes are perfectly anti-correlated; a single sign flip on one of the observables converts this to perfect correlation, which the verifier would detect. The argument extends to the σG observable and the other three Bell basis states. Since this test can only detect inconsistent pairwise signs, a global sign on G ( a) can survive; we remove it with a CHSH subtest, noting that σF and σG are optimal CHSH observables. Together, these components yield a self-test for specific 2n -dimensional irreducible representations of the n-qubit extended Pauli group: the prover’s measurements are certified, up to isometry and complex conjugation, with constant robustness. This is captured by the following informal theorem: Informal Theorem 2.1 (Formally, Theorem 4.1). For any efficient prover that passes the n-qubit compiled Clifford test from protocol 11 with probability ω ∗ − ε, there exists an isometry such that under uniform expectation over W̃ ∈ { X, Y, Z, F, G }n V W̃ ( a) ≈ε ((σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1)V, 10

where ω ∗ is the optimal winning probability of the test, W̃ ( a) is the prover’s observable on question W̃ and O a σW̃ ( a) := σW̃i . i ∈[n]

i

Here the direct sum structure is a consequence of the phase ambiguity, which was mentioned earlier. Using this characterization and a consistency test—the verifier asks both provers the same question and checks that the answers agree—we can also characterize the prover’s state. This is possible because the notation ≈ε relates to the state-dependent norm, which depends on the prover’s state. Explicitly using this state dependence, we arrive at the following result: Informal Theorem 2.2 (Formally, Theorem 4.2). For any efficient prover that passes the n-qubit compiled Clifford test from protocol 11 with probability ω ∗ − ε, there exists an isometry such that E

∑

W̃ v∈{0,1}n

Enc(W̃ )

|v, W̃ ⟩⟨v, W̃ |W ⊗ Vϕv

 c v v ⊗ ρ0 + τ W̃ ⊗ ρ1 , V † ≈√ε E |v, W̃ ⟩⟨v, W̃ |W ⊗ τW̃ v,W̃

Enc(W̃ )

where ω ∗ is the optimal winning probability of the test, the verifier holds the W register, ϕv is the prover’s state after receiving the encrypted question W̃ and answering with an encryption of v and v := τW̃

O 1 i ∈[n]

2

 1 + (−1)vi σW̃i , c

We have not yet introduced the notation, but ≈δ should be understood as computational indistinguishability with an advantage of δ. The state guarantee for imaginary observables, such as σY , σF , and σG , factors into two distinct blocks, because of the phase ambiguity. In general, there are also coherences between these two cases; it could be imaginable that the prover applies a coherent superposition of the canonical and complex conjugate observables. However, because the QFHE makes it impossible to consistently apply this superposition during both parts of the interaction, we can show that the coherences are cryptographically small (see Corollary 4.5 for the detailed statement), which achieves a stronger state characterization than prior results in our setting, such as [GV19], where these coherences are not generally excluded. In what follows, we will show how this state characterization can be used to run the Broadbent protocol with purely classical communication and thus achieve BQP verification between a classical verifier and a single computationally bounded prover.

2.3

BQP verification

As mentioned before, the idea is to run the Broadbent protocol with a classical verifier, by replacing the quantum communication with verifiable remote state preparation, obtained through our rigidity result. To start our protocol, the verifier chooses the bases to prepare his qubits in, as in a normal execution of the Broadbent protocol; this yields the basis assignment string W̃ ∈ { X, Y, Z, F, G }n . Next, instead of preparing the qubits in the eigenstates of these bases dictated by the QOTP keys, he encrypts the basis assignment string and sends it to the prover. The prover replies with an encrypted answer α, whose decryption (v = Dec(α) ∈ {0, 1}n ), in an honest execution, encodes the measurement outcomes of measuring n qubits in the basis specified by W̃. Recalling the previous section, we have a rigidity test, where a high passing probability forces this to be the case. Thus, by executing the rigidity test often enough to estimate this passing probability we can be sure that the prover holds the eigenstate of the tensor product of the n observables specified by W̃, corresponding to the per-observable eigenvalues v in his quantum register, after answering the first question. 11

Importantly, the prover only receives the encryption of W̃ and homomorphically evaluated the measurement; thus, by the semantic security of the QFHE scheme, he doesn’t know which bases his qubits are in. To actually perform the delegation, we need to sprinkle in executions of the Broadbent protocol. This is why there are two subtests in protocol 12, which are executed with different probabilities: the first is more likely to run and performs the rigidity protocol, while the second acts identical in the encrypted part of the interaction and then performs the classical part (all interactions after the verifier sent his quantum states to the prover) of the Broadbent verification protocol. By appropriately choosing the probability with which the verification game is played, we can ensure that the rigidity guarantee (specifically the state characterization) applies in this second case as well, which makes the soundness guarantees of the Broadbent protocol kick in and ensures that the overall verification protocol is sound.

2.4

Technical contributions

In the compiled setting, many of the guarantees rest on the IND-CPA security of the underlying cryptography, and as a consequence some routine operations from the nonlocal setting become more delicate. For example, when ‘prover switching’ observables corresponding to distinct questions, the analysis relies on the computational indistinguishability of the two state the prover holds after the QFHE encrypted part of the interaction. Because this indistinguishability holds only in computational distance, every operator that enters the argument—which often includes the Gowers–Hatami (GH) isometry—must be computationally efficient. An explicit GH isometry. Building on the previous point, we had to show that the GH isometry is computationally efficient. To do so, we slightly modified the dilation-based proof of GH in [MNZ24] to obtain an explicit expression for the isometry (see Theorem 3.1). To block-diagonalize the exact representation to which GH rounds, we computed an explicit circuit for the Fourier transform over our extended Pauli group and verified that this operation is efficient. This construction may be of independent interest. At a technical level, our modification of [MNZ24, Theorem 3.1 (Gowers–Hatami)] yields a tighter characterization of the error between the pre- and post-isometry rounded operators. In other self-testing works (including [MNZ24]), the quantity that is bounded is

∥ X − V † (σX ⊗ 1)V ∥ψ , which led to what they called the “VV † problem.” In our analysis, we instead bound quantities of the form ∥VX − (σX ⊗ 1)V ∥ψ . This seemingly small change makes it substantially easier to compose error bounds when studying how the isometry acts on products of operators. Interestingly, deriving these improved bounds required the explicit expression for V that our modified dilation-based proof of GH provides. Robust state preparation. We reproduce the result of [MV21], extended to a parallel self-test of multiple EPR pairs with constant robustness (protocol 11, subtest 2 and Lemma 4.22). This improves on [FWZ23], where a similar result is shown without constant robustness. Natarajan and Zhang [NZ23] asserted that compiled nonlocal games—specifically, their compiled Pauli braiding test—would suffice to certify EPR pairs, and our calculations confirm this intuition. Moreover, Theorem 4.2 extends the results of [GV19, GMP23] by yielding the first random verifiable RSP beyond BB84 states, with constant robustness. We are not the first to achieve 12

constant robustness computational self-testing [NZ23, MNZ24], but we extend previous results from operator to state self testing and from the Heisenberg–Weyl group to the extended Pauli group. We achieve random remote state preparation, because in obtaining constant robustness, we need to retain the expectation over the test distribution of the basis assignments. In [GMP23] closeness is shown for all basis choices separately, which is achieved by a hybrid computational indistinguishability argument. We could repeat this argument, but it will always introduce a dependence on the number of prepared qubits. Our weaker notion of random remote state preparation is sufficient for any downstream application where the winning probability is taken over random basis choices anyway, which is the case in the Broadbent protocol. The complex conjugation ambiguity. One of the main technical obstructions when working with imaginary observables (such as the Pauli Y) is the “complex-conjugate” attack (also called phase ambiguity). The nonlocal correlations tested during protocol execution are invariant under complex conjugation, so a prover may implement either the canonical strategy or its complex conjugate, or, in the worst case, even a coherent superposition of the two. This observation led McKague and Mosca [MM11] to propose a generalized self-testing framework called complex self-testing. Previous works [Zha22, CGJV24] have confronted the same issue; they are either in a different setting (nonlocal), or the states they certify are unitarily equivalent to their complex conjugates, which makes the complex conjugate attack harmless. The work closest to our setting [GV19] contains a bug in the proof of Lemma 3.5, which ignores the phase ambiguity. It is impossible to completely remove the phase ambiguity, but in this work we show that an efficient prover can’t apply a coherent superposition of the two strategies, which implies that the prepared state is computationally indistinguishable from a classical mixture of the canonical state and its complex conjugate. Entanglement between the simulated provers. The results mentioned above are strong state self-testing guarantees for the prover’s unencrypted part. Unfortunately, we have very little control over the state shared between the encrypted and unencrypted parts of the prover. To obtain a full analog of nonlocal games, we would like to show that these parts carry entanglement between them. We make partial progress toward this goal: we show that the state held by the prover after the QFHE encrypted part of the interaction, when marginalized over the encrypted responses, is computationally indistinguishable from the maximally mixed state (Lemma 4.32). Our resolution for the phase ambiguity coherences used consistency between the encrypted and unencrypted parts of the prover; in the nonlocal setting, [CGJV24] get rid of these coherences by certifying that the provers share EPR pairs.

2.5

Open questions

1. At present we have only limited ‘inter-prover’ state self-testing guarantees (e.g. Lemma 4.32), which hold up to computational indistinguishability. Is there a cheating strategy that passes our compiled n-qubit test while carrying far less entropy than the canonical honest strategy of preparing n EPR pairs—e.g. a form of computational “pseudo-entanglement”? Such strategies would bear directly on the quantum soundness of the KLVY compiler, since they would show that optimal compiled strategies can be far from any nonlocal strategy and would thereby constrain rounding-based approaches to quantum soundness. Merkulov and Arnon [MA25] prove entropy lower bounds for strategies with anti-commuting observables in the cryptographic setting; stronger results of this kind would clarify how far state self-testing can be pushed in the compiled model. 2. In the nonlocal setting, [CGJV24] construct a constant round protocol for QMA verification using the entanglement-based version of [Bro18]. We believe a similar extension should be

13

possible here. We have not yet carried it out as we faced obstructions in state certification, attempting a route through an entanglement-based formulation in the compiled setting. 3. Within the context of QMA verification, witness preservation is also of considerable interest. This question has been studied intensively in recent work of Kalai, Khurana, and Raizes [KKR26]. We hope that, because our protocol delegates a verification circuit gate-by-gate, it may be easier to obtain witness-preserving protocols by delegating the Marriott–Watrous amplified verification circuit. 4. Ultimately, the “pie in the sky” goal, as proposed by Justin Raizes [Rai26], is an interactive argument for QMA that is as good as, or better than, the direct proof system: it should use as few rounds as possible (ideally a constant number), the prover should need only one copy of the witness state, and completeness and soundness should be negligibly close to 1 and 0, respectively. One would also hope for succinctness. It remains far from clear how to achieve all of these properties simultaneously, but we hope the tools introduced in this work will prove useful. 5. Among more immediate protocol improvements, one straightforward route to nearperfect completeness would be to extend our current CHSH test (protocol 11, subtest 5) to a parallel version with multi-qubit observables, along the lines of [CGJV24]; we have not yet completed the corresponding calculation. We also believe that blindness can be added to our protocol by delegating a universal circuit, following the standard approach of [CGJV24], at the cost of an additional logarithmic factor in resource overhead and a potential sequential execution of the rigidity test. 6. For succinctness, one promising direction is the recently proposed black-box compiler of Bartusek, Liu, and Malavolta [BLM26]. Another is to apply the techniques of [MNZ24], based on the ideas of de la Salle [dlS25], to sparsify the group self-test. An important first step to achieving succinctness is to reduce the round complexity of our verification protocol.

2.6

Paper outline

The remainder of this paper is organized as follows. Section 3 introduces the background, concepts, and helpful tools needed for the analysis. We fix notation, introduce the extended Pauli group (Definition 3.1), and define the state-dependent distance measures used throughout (Definition 3.2). We also state the Gowers–Hatami theorem (Theorem 3.1) that underlies our self-testing arguments. Section 4 develops the core technical contribution. We specify the Clifford rigidity test (protocol 11) and the constituent subtests, introduce compiled prover switching as a tool for analyzing protocols in the cryptographic setting, and prove soundness of each subtest. The section concludes with a state characterization theorem (Theorem 4.2) that certifies remote preparation of the states required by the Broadbent protocol. Section 5 applies this rigidity result to obtain the headline result: an efficient CVQC protocol. The protocol specification is given in protocol 12 and its completeness and soundness for the BQP-complete promise problem Q-CIRCUIT (Definition 5.1) are proven in the subsequent lemmas, culminating in Theorem 5.1. A constant number of sequential repetitions then yields the standard completeness and soundness bounds of 2/3 and 1/3 (Lemma 5.3), and thus an argument system for every language in BQP (Corollary 5.1). Finally, the appendix (Section A) provides supplementary material, including an explicit efficient circuit for the Fourier transform over the extended Pauli group, which is needed to implement the Gowers–Hatami isometry efficiently and may be of independent interest. 14

Acknowledgments and AI statement AN was supported by NSF CAREER grant 2339948. We thank Thomas Vidick and Andru Gheorghiu for helpful conversations, and Tina Zhang and Tony Metger for sharing an unpublished note on self-testing the Pauli Y operator. The authors acknowledge the use of ChatGPT 5.5 for assistance in the initial analysis of the irreducible representations of the extended Pauli group and Claude 4.8 for suggestions regarding the explicit circuit for the quantum Fourier transform over that group. Anthropic’s Claude models provided the proof ideas for Lemmas 3.4, 3.7, and 5.3, and the statement and proof of Corollary 3.2. Claude was also used for generating Figure 4, for reviewing the paper, finding mistakes in the proofs and for minor writing improvements. The authors take responsibility for all content.

3

Preliminaries

3.1

Notation

Throughout this work we assume basic knowledge of quantum information theory and linear algebra, including familiarity with Dirac bra–ket notation. Table 3 collects the most frequently used symbols for quick reference; each entry is introduced and discussed in more detail in the following subsections. Sets and bitstrings For a positive integer n, we let

[n] := {1, 2, . . . , n}. We write {0, 1}n for the set of n-bit binary strings, whose coordinates we index by [n]. For x ∈ {0, 1}n , its Hamming weight | x | is the number of ones in x, i.e. | x | = ∑i∈[n] xi , and its elementwise complement is x ∈ {0, 1}n with xi = 1 ⊕ xi for all i ∈ [n]. For i ∈ [n] we write ei ∈ {0, 1}n for the string with a 1 in position i and zeros elsewhere, where the length n should be clear from the context. From an index set I ⊆ [n] and a bit-string x ∈ {0, 1}n , we can define the following two objects: • the restriction x | I ∈ {0, 1}| I | is the string obtained by keeping only the coordinates of x indexed by I; • the projection x ( I ) ∈ {0, 1}n is the n-bit string that agrees with x on I and is zero elsewhere. Equivalently, x ( I ) is the element-wise product of x and the indicator string 1nI ∈ {0, 1}n (the string with a 1 at every position in I and a 0 elsewhere). Hilbert spaces, states, and operators We work exclusively with finite-dimensional Hilbert spaces over C. A generic Hilbert space is denoted H; when a Hilbert space is associated with a physical system (or register) labeled A, we write H A . Pure quantum states are denoted by Dirac kets |ψ⟩ ∈ H, and the corresponding density matrix is denoted by the bare symbol ψ := |ψ⟩⟨ψ|. We will say states (on H) to denote the set of normalized density matrices

{ρ ∈ Pos(H) : Tr(ρ) = 1}, where Pos(H) denotes the positive semi-definite operators on H (see Table 2). 15

For an operator M on H, we denote by M† its Hermitian adjoint and by M its element-wise complex conjugate in the computational basis; the transpose in the computational basis is M T = M† . We write 1 for the identity operator on H (with a subscript indicating the Hilbert space whenever ambiguity may arise). The trace of an operator ρ is denoted Tr [ρ]. A more thorough discussion of operator and vector norms, including our default convention ∥·∥ = ∥·∥∞ , is deferred to Section 3.5. Our conventions for the most frequently used subsets of the bounded operators on H are summarized in Table 2. Symbol

Definition

L(H)

Linear operators A : H → H (endomorphisms of H)

GL(H)

Invertible linear operators A : H → H (automorphisms of H)

U (H)

Unitary operators A : H → H

Pos(H)

Positive semi-definite operators A : H → H

Herm(H)

Hermitian (self-adjoint) operators A : H → H

Obs(H)

Binary observables A : H → H

Cliff(H)

Clifford unitaries A : H → H

Table 2: Overview of operator sets on a finite-dimensional Hilbert space H. The following inclusions hold: Pos(H) ⊊ Herm(H),

U (H) ⊊ GL(H) ⊊ L(H),

Cliff(H) ⊊ U (H).

For A, B ∈ Pos(H) we write A ⪯ B when B − A ∈ Pos(H), the PSD order. Unless stated otherwise, all observables are binary; for brevity, “observable” will henceforth mean binary observable. Fourier transform For a function f : {0, 1}n → C, we denote its Fourier (or Walsh–Hadamard) transform over Z2n by g( x ) = fb( x ) := E (−1) x·a f ( a), a∈{0,1}n

where the expectation is taken uniformly over a ∈ {0, 1}n . The inverse transform is f ( a) =

∑ (−1)a·x g(x).

x ∈{0,1}n

Measurements and observable families Projectors corresponding to single-symbol questions in a protocol specification are denoted by the same symbol as the question, with a superscript denoting the n-bit measurement outcome (where n is the expected number of answer bits on that question). For example, if the verifier sends question Q, expecting n answer bits, we denote the PVM applied during the un-encrypted interaction with the prover as { Qv }v∈{0,1}n . If the question is not a single symbol but a tuple, for example ( Q, a), we denote the corresponding two-outcome projectors by { Q0a , Q1a }. For other tailored questions we don’t have a default convention; the corresponding projectors are always introduced explicitly. 16

To every such projective measurement we associate a family of observables parameterized by a ∈ {0, 1}n : W ( a) := ∑ (−1) a· x W x . x ∈{0,1}n

If the PVM has only two outcomes, we use the shorthand W = W (1) = W 0 − W 1 ; thus twooutcome measurements share the symbol with their corresponding single-symbol questions. The outcome projectors can be interpreted as the Fourier transform of the observable W ( a), i.e. b ( x ) = Ea∈{0,1}n (−1) x·a W ( a). Wx = W Expectations and probability distributions We denote the expectation value by E. If the subscript is a variable together with an indication of the set it belongs to (e.g. a ∈ S), the expectation is the uniform one over that set. If the set is omitted, the distribution should be clear from context. For non-uniform expectations, we are often explicit by writing both the variable and the distribution in the subscript, for example EW ∼µ . We write Un for the uniform probability distribution over a set of n elements, R

i.e. Un ( a) = 1/n. We write x ← S when x is uniformly sampled from a set S . The arrow may µ carry a distribution above it, for example x ← S , in which case x is sampled according to the distribution µ from the set S . For a predicate P, we write 1{ P} for the indicator taking value 1 if P holds and 0 otherwise.

17

Symbol

Definition

Sets and bitstrings log( x )

The binary logarithm of x (logarithm base 2)

[n] {0, 1}n ei |x| x x| I x( I )

The set of integers {1, 2, . . . , n} The set of n-bit binary strings The n-bit string with a 1 at position i ∈ [n] and zeros elsewhere The Hamming weight of the binary string x ∈ {0, 1}n The element-wise complement of the binary string x ∈ {0, 1}n The restriction of x ∈ {0, 1}n to the coordinates indexed by I ⊆ [n] The projection of x ∈ {0, 1}n onto the coordinates indexed by I ⊆ [n]

Hilbert spaces, states, and operators

H, H A | ψ ⟩, ψ 1 M† M Tr ∥ M∥

A (finite-dimensional, complex) Hilbert space; subscript denotes the system A pure state and its density matrix ψ = |ψ⟩⟨ψ| The identity operator on a Hilbert space H The Hermitian adjoint of an operator M The complex conjugate of an operator M (in the computational basis) The trace of an operator The operator norm of M, equal to the largest singular value of M

Fourier transform, expectations, and distributions fb( a) The Fourier (Walsh–Hadamard) transform of f over Zn 2

The uniform distribution over a set of n elements, Un ( a) = 1/n

Un R

x←S

x is uniformly sampled from the set S

1{ P}

Indicator: 1 if predicate P holds, 0 otherwise

Extended Pauli group (three-tier notation; Definition 3.1) x ( a ), z ( a ), g ( a )

Abstract generators of Cn ; also y( a), f ( a) (derived)

xj

Single-qubit generator x (e j ) (likewise y j , z j , g j )

σW ( a)

Pauli/Clifford matrix

W ( a)

Prover observable for the question labelled W

N

ai i σW

Table 3: Overview of notational conventions used throughout this paper.

18

3.2

Groups

Pauli group The Pauli matrices are defined as,   0 1 σX := , 1 0

 σY :=

 0 −i , i 0

 σZ :=

 1 0 . 0 −1

Additionally, we define 1 1 σG := √ (σY + σX ) = √ 2 2



 0 1−i , 1+i 0

1 1 σF := √ (σY − σX ) = √ 2 2



 0 −i − 1 , i−1 0

with σ G = −σF , as well as  σS :=

 1 0 , 0 i

 σT :=

 1 0 . 0 eiπ/4

We write σX , σZ , . . . rather than X, Z, . . . in order to distinguish the “true” matrices from the untrusted operators that the prover applies; in the case of σS and σT , we will never need to make this distinction in our analysis so we will often use S and T as shorthand for these. We also note that some references, in particular [Bro18], use P instead of S. For a ∈ Z2n and W ∈ { X, Y, Z, F, G }, let σW ( a) :=

(σW ) ai ,

O i ∈[n]

in other words, σW ( a) is the 2n -dimensional matrix that is the tensor product of σW on all the qubits where ai = 1 and identity elsewhere. Furthermore, for W̃ ∈ { X, Y, Z, F, G }n , let O

σW̃ ( a) :=

(σW̃i ) ai ,

i ∈[n]

which is the mixed-basis extension of the above. We denote the corresponding projector as O a i

a := τW̃

i ∈[n]

τW̃ , i

where τW̃i is the single-qubit projector defined as ai := τW̃ i

1 (1 + (−1)ai σW̃i ). 2

Extended Pauli group Definition 3.1 (Extended Pauli group). We use Cn to denote the n-qubit extended Pauli group, which is a subgroup of the n-qubit Clifford group. It is generated by a central phase ω and single-qubit elements x j , z j , g j for j ∈ [n]. Writing x ( a) := ∏ j:a j =1 x j and likewise z( a), g( a), these satisfy the following relations for all a, b ∈ {0, 1}n : • Orders: ω 4 = x ( a)2 = z( a)2 = g( a)2 = 1. • Linearity: w( a ⊕ b) = w( a)w(b) for w ∈ { x, z, g}. • Centrality: w( a)ω = ωw( a) for w ∈ { x, z, g}. 19

• (Anti)commutation: w( a)z(b) = ω 2a·b z(b)w( a) for w ∈ { x, g}. • Conjugation: g( a) x (b) g( a) = ω |a∩b| x (b)z( a ∩ b). An element of Cn can be uniquely written in the normal form6 : ω p x ( a) g(b)z(c) for p ∈ {0, 1, 2, 3} and a, b, c ∈ {0, 1}n . This implies that the group has 23n+2 elements. When a label W ∈ { X, Y, Z, F, G } is used as a variable, we write w( a) for the corresponding abstract element of Cn . This includes the generators x ( a), z( a), g( a) from the definition, and the derived elements y( a) and f ( a), specified by the unique words y ( a ) = ω | a | x ( a ) z ( a ),

f ( a ) = ω | a | g ( a ) z ( a ).

Single-qubit generators are the special case x j = x (e j ), and likewise y j , z j , f j , g j . Lemma 3.1. The irreducible representations ρµ : Cn → U (Cdµ ) of the n-qubit extended Pauli group can be characterized by their action on the center of the group, i.e. ω 7→ iℓ 1 for ℓ ∈ {0, 1, 2, 3}. We can use this to distinguish two classes of irreps: • The ‘classical’ irreps (ℓ ∈ {0, 2}): 2k -dimensional representations (for 0 ≤ k ≤ n), which map ω 7→ (−1)ℓ/2 1. They can retain anti-commutation of x and g (if k ̸= 0) but always collapse to commuting x and z (and g and z), since they map ω 2 7→ 1. They are given by choosing K ⊂ [n], with |K | = k, and assigning:

∀ j ∈ K, x j 7→ σX (e j ), g j 7→ σZ (e j ), followed by choosing an assignment of either 1 or -1 for each of the generators xj , gj with j ̸∈ K and using that y j = g j x j g j and z j = ωy j x j . • The ‘quantum’ irreps (ℓ ∈ {1, 3}): 2n -dimensional representations, which map ω 7→ iℓ 1, where

∀ j ∈ [n], x j 7→ σX (e j ), 1 g j 7→ ± √ (σX (e j ) + i(ℓ−1) σY (e j )), 2 z j 7→ σZ (e j ); There is an additional freedom of sign choice on each g j , which means that there are 2n such irreducible representations for a fixed ℓ. The all-plus, ℓ = 1 member of this family is the defining representation, sending x ( a) 7→ σX ( a), z( a) 7→ σZ ( a), g( a) 7→ σG ( a), and likewise y( a) 7→ σY ( a), f ( a) 7→ σF ( a). This representation is injective, so the normal form of Definition 3.1 labels each group element uniquely. Proof. It can be verified by direct calculation that each one of these is a representation. It is also clear that all of them are mutually non-isomorphic. The defining representation is injective: a a

b

c

local factor σXj σGj σZj is scalar if and only if a j = b j = c j = 0, so ρ(ω p x ( a) g(b)z(c)) = 1 forces p = a = b = c = 0. 6 This is a bijection on C : the set of normal-form words is closed under right multiplication by the generators n

(surjectivity), and the defining representation of Lemma 3.1 is injective.

20

Recall that the sum of the squares of the degrees of the irreps of a group is equal to the order of the group. The order of Cn is 23n+2 . The number of 2k -dimensional ‘classical’ representations is N (2k ) = 2 · 4n−k · (nk). Summing over its product with the squared dimension yields: n

n

  n ∑ N (2 ) · (2 ) = 2 ∑ k 4n = 23n+1 k =0 k =0 k

k 2

the 2n -dimensional quantum representations (ℓ = 1), and their complex conjugates (ℓ = 3), also contribute 23n+1 , for a total of 23n+1 + 23n+1 = 23n+2 . Hence these are all of the irreps of Cn .

3.3

Quantum Fourier transform

We define the quantum Fourier transform (QFT) over our group as s  dµ  UQFT := ∑ ∑ ∑ ρµ ( g) i,j |µ⟩|i, j⟩µ ⟨ g|, |Cn | g∈Cn µ i,j∈[d ] µ

where µ is an index over all irreducible representations and ρµ is a specific irrep. indexed by µ, with dimension dµ . The subscript µ on the vector |i, j⟩µ indicates that it lives in a d2µ -dimensional space. We will explicitly show that UQFT is unitary † UQFT UQFT = ∑ ∑

dµ 

∑ |Cn | ρµ ( g′ ) i,j ρµ ( g) i,j | g′ ⟩⟨ g|  



g,g′ µ i,j∈[dµ ]

h i   1 ′ † d ρ ( g ) ρµ ( g) i,j | g′ ⟩⟨ g| µ µ ∑ ∑ ∑ |Cn | g,g′ µ i,j∈[d ] j,i µ h i 1 ′ † d Tr ρ ( g ) ρ ( g ) | g′ ⟩⟨ g| = µ µ µ ∑′ ∑ |Cn | g,g µ

=

=

1 ∑′ ∑ dµ χµ (( g′ )−1 g)| g′ ⟩⟨ g| |Cn | g,g µ

= ∑ δgg′ | g′ ⟩⟨ g| g,g′

= 1, where the first term uses orthogonality of the µ and potential i, j registers, the fourth line uses the exact group homomorphism property and the second-to-last line uses [Ser77, Proposition 1 and Corollary 2], where χµ is the character of the µ-th irrep defined as   χµ ( g) = Tr ρµ ( g) . Let HCn be a |Cn |-dimensional Hilbert space, whose basis vectors correspond to group elements. The left regular representation π : Cn → U (HCn ) is then defined as π ( g) = ∑ | gh⟩⟨h|. h∈Cn

We will now show that the quantum Fourier transform over Cn block-diagonalizes the left

21

regular representation † UQFT (π ( g))UQFT

q

=∑

∑

∑

=∑

∑

∑

=∑

∑

|Cn | q d µ d µ′ 

µ,µ′ i,j,k ∈[dµ ] l,m∈[dµ′ ]

|Cn |

µ,µ′ i,j,k ∈[dµ ] l,m∈[dµ′ ]



µ i,j,k ∈[dµ ]

= ∑ |µ⟩⟨µ| µ

=

M

d µ d µ′ 

orthogonality of irreps

}| {    ρµ ( g) i,k ∑ ρµ ( g′ ) k,j ρµ′ ( g′ ) l,m |µ⟩|i, j⟩µ ⟨µ′ |⟨l, m|µ′ 

z



g′

 |Cn | ρµ ( g) i,k δµµ′ δkl δjm |µ⟩|i, j⟩µ ⟨µ′ |⟨l, m|µ′ dµ



ρµ ( g) i,k |µ⟩|i, j⟩µ ⟨µ|⟨k, j|µ

∑



i,k ∈[dµ ]

 ρµ ( g) i,k |i ⟩⟨k |µ ⊗ 1dµ

ρ µ ( g ) ⊗ 1d µ ,

µ

where we used the orthogonality of irreducible representations [Ser77, Corollary 3]. Explicit QFT circuit To obtain an explicit circuitfor the quantum Fourier transform over our group, we need to find an explicit expression for ρµ ( g) i,j . Ideally, this would be a simple index-based expression, matching the specific irreps chosen in Lemma 3.1. We start by writing out this kind of compact expression for the ‘classical’ irreps (ℓ ∈ {0, 2}): h i h i (ℓ) (ℓ) ρC,µ ( g) = ρC,µ (ω p x ( a) g(b)z(c)) r,s r,s   

= i pℓ 

∏

j ∈ S ( µ ⊕1n )

|

(−1)a j r j +bj s j +c j ℓ/2   ∏ (−1)bj s j +(ℓ/2+1)c j δr j ,s j ⊕a j  . j∈S(µ)

{z

}|

1D contributions

{z

2D contributions

}

Here S(µ) := {i ∈ [n] : µi = 1}. This indeed yields the expected structure, for example if S(µ) = [n] and g = x (1n ) we obtain h i (ℓ) ρC,K ( x (1n )) = ∏ δr j ,s j ⊕1 = δr,s⊕1n = σX (1n ), r,s

j∈[n]

which is the defining matrix of this irrep on that group element. We can do the same thing for π the ‘quantum’ irreps (ℓ ∈ {1, 3}). Let ω (s) := ei 4 (1−2s) , then for r, s ∈ {0, 1} and ℓ = 1 we have the matrix entries of σG [σG ]r,s = ω (s)δr,s⊕1 , if ℓ = 3, this becomes

[σG ]r,s = ω (s)δr,s⊕1 . This observation lifted to the n-qubit case (where r, s ∈ {0, 1}n ) allows us to also write down a compact expression for the quantum irreps h i h i (ℓ) (ℓ) ρQ,µ ( g) = ρQ,µ (ω p x ( a) g(b)z(c)) r,s

=i

pℓ

∏ (−1)

b j µ j +c j s j

j∈[n]

22

r,s bj

ωℓ (s j ) δr j ,s j ⊕a j ⊕bj ,

Figure 2: Parallel gate notational convention.

Figure 3: Explicit circuit implementation of UQFT for Cn in chosen basis. Note that we are using a slightly ambiguous notational convention for parallel gates. where ωℓ (s) := 1{ℓ = 1}ω (s) + 1{ℓ = 3}ω (s). We can combine both classes into a single indexed set of irreps h i h i h i (ℓ) (ℓ) (ℓ) ρµ ( g) = 1{ℓ ≡ 0 (mod 2)} ρC,µ ( g) + 1{ℓ ≡ 1 (mod 2)} ρQ,µ ( g) . r,s

r,s

r,s

It remains to design an efficient quantum circuit that implements the following operation s dµ h (ℓ0 +2ℓ1 ) i ( g) |ℓ0 , ℓ1 , µ, r, s⟩, ρ | g⟩ = | p1 , p0 , a, b, c⟩ 7→ ∑ ∑ r,s |Cn | µ ℓ ,ℓ ∈{0,1} µ,r,s∈{0,1}n 0

1

where we represented a group element in bit notation where p0 , p1 ∈ {0, 1} and a, b, c ∈ {0, 1}n , by the observation that ω p x ( a) g(b)z(c) uniquely encodes a group element. An efficient circuit for the quantum Fourier transform over Cn is shown in Fig. 3, where any control or gate acting on a multi-qubit wire is interpreted as parallel operations (as visualized in Fig. 2). A correctness proof for this specific circuit can be found in the appendix (Section A).

3.4

Bell states

The four Bell states form an orthonormal basis for C2 ⊗ C2 consisting of maximally entangled states. They are the simultaneous eigenstates of the observables σX ⊗ σX and σZ ⊗ σZ . Explicitly, for a, b ∈ {0, 1} we define 1 |Φ ab ⟩ = √ ∑ (−1)a·s |s, s ⊕ b⟩, 2 s∈{0,1}

(3.1)

so that

(σX ⊗ σX )|Φ ab ⟩ = (−1) a |Φ ab ⟩,

(σZ ⊗ σZ )|Φ ab ⟩ = (−1)b |Φ ab ⟩.

In the traditional notation this gives

|Φ00 ⟩ = |Φ+ ⟩,

|Φ10 ⟩ = |Φ− ⟩,

|Φ01 ⟩ = |Ψ+ ⟩, 23

|Φ11 ⟩ = |Ψ− ⟩.

The Bell basis is related to the EPR state |Φ00 ⟩ = √1 (|00⟩ + |11⟩) by local Pauli corrections: 2

|Φ ab ⟩ = (σZa σXb ⊗ 1) |Φ00 ⟩. Equivalently, acting on the second register, |Φ ab ⟩ = (1 ⊗ σXb σZa ) |Φ00 ⟩. More generally, for any operator M acting on C2 the EPR state has the following transpose property

( M ⊗ 1)|Φ00 ⟩ = (1 ⊗ M T )|Φ00 ⟩,

(3.2)

where M T denotes the transpose in the computational basis. Because the Bell states form an ONB, they also resolve the identity

∑

|Φ ab ⟩⟨Φ ab | = 14 ,

a,b∈{0,1}

and satisfy the twirl identity: for any operator ρ on C2 ⊗ C2 , 1 (σZa σXb ⊗ 1) ρ (σXb σZa ⊗ 1) = ∑ ⟨Φ ab |ρ|Φ ab ⟩ |Φ ab ⟩⟨Φ ab |. 4∑ a,b a,b

(3.3)

That is, twirling by the single-qubit Pauli group dephases any two-qubit state into the Bell basis.

3.5

Distance measures

The Schatten-p norm of A ∈ L(H) is defined as h i1/p ∥ A∥ p := Tr ( A† A) p/2 . The Schatten norms satisfy Hölder’s inequality for p, q, r ∈ [1, ∞] such that 1r = 1p + 1q :

∥ AB∥r ≤ ∥ A∥ p ∥ B∥q . We use the shorthand notation ∥ A∥ = ∥ A∥∞ , i.e. our default operator norm is the Schatten-∞ norm, which can equivalently be defined as

∥ A∥ = sup ∥ A| x ⟩∥ = sup |⟨ x | A|y⟩|. ⟨ x | x ⟩≤1

⟨ x | x ⟩≤1 ⟨y|y⟩≤1

We use the Euclidean norm as our default vector norm. Definition 3.2 (State-dependent inner product and norm). Let H be a finite-dimensional Hilbert space and A, B ∈ L(H) be linear operators on H. Let ρ ∈ Pos(H). We define the state-dependent (semi) inner product of A and B w.r.t ρ as h i ⟨ A, B⟩ρ := Tr A† Bρ . This induces the state-dependent (semi) norm h i ∥ A∥2ρ := ⟨ A, A⟩ρ := Tr A† Aρ . Remark 3.1. The state-dependent norm can also be expressed as a Schatten-2 norm

∥ A∥ρ = ∥ Aρ1/2 ∥2 . For a pure state, the state-dependent norm of an operator reduces to the Euclidean norm of that operator acting on the pure state vector. 24

Lemma 3.2. For all ρ, ρ′ ∈ Pos(H) and linear operators A, B ∈ L(H) on some finite-dimensional Hilbert space H, the following identities hold: (i) ∥ A∥ BρB† = ∥ AB∥ρ . (ii) ∥ AB∥ρ ≤ ∥ A∥ · ∥ B∥ρ . (iii) ∀ U ∈ U (H) : ∥U A∥ρ = ∥ A∥ρ . (iv) ∥ A∥2ρ+ρ′ = ∥ A∥2ρ + ∥ A∥2ρ′ . (v) ∥∑ x∈X A x ∥2ρ ≤ |X | ∑ x∈X ∥ A x ∥2ρ . (vi) ∥Ex∈X A x ∥2ρ ≤ Ex∈X ∥ A x ∥2ρ . With our distance measure properly introduced, we can now define what it means for two operators to be close to each other. Definition 3.3 (δ-isometric and δ-equivalent). Let H and H′ be two finite-dimensional Hilbert spaces, δ > 0, R ∈ L(H) and S ∈ L(H ′ ) linear operators. We say that R and S are δ-isometric with respect to ρ ∈ Pos(H), and write R ≃δ S, if there exists an isometry V : H → H′ such that

∥VR − SV ∥2ρ = O(δ). If V is the identity (i.e. H = H′ ), then we further say that R and S are δ-equivalent, and write R ≈δ S for ∥ R − S∥2ρ = O(δ). With this we can equivalently write R ≃δ S as VR ≈δ SV, which clearly shows the asymmetry of this notation. Remark 3.2. If we are dealing with the δ-equivalence of a parameterized family of observables, i.e. A( a) ≈δ B( a), the notation is overloaded to also include an implicit uniform expectation over the parameter, if not specified otherwise, thus E ∥ A( a) − B( a)∥2ρ = O(δ), a

by the equivalence of A( a) ≃δ B( a) to VA( a) ≈δ B( a)V, this also holds for the δ-isometric notation. Remark 3.3. Our definition of δ-isometric differs from the one used in [CGJV24]. Our notion is strictly stronger, since by Lemma A.4 one can recover the one in [CGJV24] from ours without loss, but not the other way around incurs a square-root loss. The notations R ≃δ S and R ≈δ S are ambiguous since they neither specify the state ρ nor the isometry V. Both should always be obvious from the context and will be explicitly stated if not. The isometry relation is transitive, but not reflexive: the operator on the left acts on the state before the isometry, the operator on the right acts after the isometry. The notion of δ-equivalence is both transitive and reflexive; we will use it as our main notion of distance and its transitivity will be frequently used. We overload the notation a ≈δ b to mean | a − b| = δ for scalars a and b, which is consistent with the canonical definition in this setting. Remark 3.4. The previous definition extends to scalars if we take R and S to be scalar linear maps (R = a · 1 and S = b · 1). In this setting R ≈δ S would imply ( a − b)2 = O(δ), which gives a square root difference to the canonical definition for approximate equality between scalars.

25

3.6

Nonlocal games

Definition 3.4 (Nonlocal game). A two-player nonlocal game G is specified by two question and answer sets (Q A , Q B and A A , A B ), a distribution Q over pairs ( x, y) ∈ Q A × Q B , and a PPT verification predicate V ( x, y, a, b) ∈ {0, 1}, where a ∈ A A and b ∈ A B . Definition 3.5. A deterministic classical strategy Sc for a two-player nonlocal game G consists of two functions: f : Q A → A A and g : Q B → A B . The (classical) value or winning probability of Sc in G is ω ( G, Sc ) :=

E

∑ ∑ V (x, y, f (x), g(y)) .

( x,y)∼ Q a∈A b∈A A B

(3.4)

Definition 3.6 (Local value). The local value of a game G is ωc ( G ) := sup ω ( G, Sc ) ,

(3.5)

Sc

where the supremum is taken over all classical strategies Sc for G (as in Definition 3.5). Here it is sufficient to take the supremum over all deterministic classical strategies, because the ω ( G, Sc ) is linear and the set of classical strategies is the convex hull of the deterministic ones. Definition 3.7 (Quantum strategy). A quantum strategy S for a two-player nonlocal game G consists of: • a bipartite finite-dimensional quantum state |ψ⟩ ∈ H A ⊗ H B ; • for every x ∈ Q A , a projective measurement { A ax } a∈A A on H A (Alice’s measurements); y

• for every y ∈ Q B , a projective measurement { Bb }b∈AB on H B (Bob’s measurements). The (quantum) value or winning probability of S in G is ω ∗ ( G, S) :=

∑ ∑ V (x, y, a, b) · ⟨ψ| Aax ⊗ Bb |ψ⟩ . ( x,y)∼ Q y

E

(3.6)

a∈A A b∈A B

Definition 3.8 (Entangled value). The entangled value of a game G is ω ∗ ( G ) := sup ω ∗ ( G, S) ,

(3.7)

S

where the supremum is taken over all quantum strategies S for G (as in Definition 3.7).

3.7

Cryptography

Definition 3.9 (Quantum polynomial time). The class quantum polynomial time (QPT) consists of all procedures that can be implemented by a logspace-uniform family of quantum circuits with size polynomial in 1) the number of qubits n which they take as input, and 2) the security parameter λ. We denote by PPT the corresponding class of classical probabilistic polynomial-time procedures. Definition 3.10 (Non-uniform quantum polynomial time). The class non-uniform quantum polynomial time (nuQPT) consists of all procedures that can be implemented by a family of quantum circuits {Cλ }λ∈N with |Cλ | ≤ poly(λ). The circuit family {Cλ }λ need not be uniformly generated. Remark 3.5. Non-uniform QPT often includes access to quantum advice, which is not necessarily efficiently computable. To work under more conservative hardness assumptions, we exclude it here. The indistinguishability reductions of this section run the prover only once, so they would lift to quantum-advice distinguishers if the hardness assumption was upgraded; it might be useful to assume quantum auxiliary input to get desirable guarantees for composability and sequential repetition, we show that the latter does not require quantum advice in our setting. Even though we are considering non-uniform procedures, throughout this work we will often drop the indexing by λ for ease of exposition. 26

Definition 3.11 (Efficiency and distinguishing advantage). Throughout this work, what qualifies as ‘efficient’ and which distinguishing advantage is tolerated, will depend on a chosen hardness assumption. We will consider the following two hardness assumptions, which always include classical advice, which determine a class of efficient quantum algorithms and a class of cryptographically small functions η : N → [0, 1]: • Polynomial hardness: efficient means nuQPT and η ranges over negligible functions of λ. • Sub-exponential hardness: efficient means a non-uniform family of circuits {Cλ }λ∈N , with δ δ |Cλ | ≤ 2O(λ ) and η ranges over functions satisfying η (λ) = 2−Ω(λ ) . Here, δ ∈ (0, 1) is determined by the assumed hardness of the cryptographic scheme. Here, λ denotes the security parameter of the cryptographic scheme. We write η (λ) for a generic cryptographically small function arising from the cryptography, that may differ between statements. Remark 3.6 (Setting λ relative to the game size). Honest provers act on O(n) qubits, where n is the game size. Under polynomial hardness this requires λ = nΩ(1) , so that honest, poly(n, λ)-sized, provers lie in the nuQPT adversary class. Under sub-exponential hardness it suffices to take δ λ = (log n)Θ(1/δ) , since then poly(n, λ) = 2O(λ ) . Resource overheads of the form poly(λ) · n are therefore almost linear in n in the first instantiation (specifically O(n1+ε ) for every ε > 0) and quasilinear in the second. We keep all rigidity lemmas in terms of a generic cryptographically small η (λ) and instantiate λ according to one of the two hardness assumptions from Definition 3.11, only when stating concrete resource bounds (Theorem 5.1, Section 3.7.4). Remark 3.7 (Non-uniformity). Non-uniformity is primarily required for ease of exposition: From separate IND-CPA invocations we get multiple cryptographically small functions η p (λ). Hardwiring, for every security parameter, a worst-case parameter p∗ into the advice yields a single adversary, whose advantage ν(λ) must also be cryptographically small, with η p (λ) ≤ ν(λ) for all p. Since E p [η p ] ≤ max p η p , expectations over arbitrary distributions are then again cryptographically small (when considering non-uniform adversaries). We deliberately do not allow quantum advice as it is not needed for our argument and would be a strong assumption under sub-exponential hardness. Definition 3.12 (Computational indistinguishability). Let {ρλ }λ and {ρ′λ }λ be two families of states in Pos(H), indexed by the security parameter λ. We say that they are computationally indistinguishable if for every efficient two-outcome POVM (corresponding to the non-uniform family { Mλ , 1 − Mλ }λ ) on H, it holds that   Tr Mλ (ρλ − ρ′λ ) ≤ η (λ), with η (λ) cryptographically small. This is denoted by c

ρ ≈ ρ′ , where we suppress the dependence of the states on λ. If we write c

ρ ≈ε ρ′ , this means that every such distinguisher has an advantage of O(ε):   Tr Mλ (ρλ − ρ′λ ) ≤ O(ε). The following definition is taken from [KLVY23], with some minor modifications. For example, we make the evaluation key explicit as it will be considered separately in the resource accounting of Section 3.7.4.

27

Definition 3.13 (Quantum fully homomorphic encryption (QFHE)). A quantum fully homomorphic encryption scheme QFHE = (Gen, Enc, Eval, Dec) for a class of quantum circuits C is a tuple of algorithms with the following syntax: • Gen is a PPT algorithm that takes as input the security parameter 1λ and the number of levels 1 L of the circuit, and outputs a classical secret key sk ∈ {0, 1}poly(λ) and an evaluation key evk ∈ {0, 1}poly(λ,L) ; • Enc is a PPT algorithm that takes as input a secret key sk and a classical plaintext x, and outputs a ciphertext ct; • Eval is a QPT algorithm that takes as input a tuple (C, |Ψ⟩, ctin , evk), where C : H × (C2 )⊗n → (C2 )⊗m is a quantum circuit (with at most L levels), |Ψ⟩ ∈ H is a quantum state, ctin is a ciphertext encrypting an n-bit message and evk is an evaluation key. Eval runs a quantum circuit ⊗ poly(λ,n) EvalC (|Ψ⟩ ⊗ |0⟩ , ctin , evk) and outputs a ciphertext ctout . If C produces a classical output, then EvalC is required to produce a classical output as well. • Dec is a QPT algorithm that takes as input a secret key sk and a ciphertext ct, and outputs a quantum state |ϕ⟩. Moreover, if ct is a classical ciphertext, then decryption outputs a classical bit string y. We require the following properties from QFHE: • Correctness with auxiliary input: For every security parameter λ ∈ N, any quantum circuit C : H × (C2 )⊗n → (C2 )⊗m (with classical output and at most L levels), any quantum state R

|Ψ⟩ AB ∈ H A ⊗ H B , any message x ∈ {0, 1}n , any key pair (sk, evk) ← Gen(1λ , 1 L ) and any R ciphertext ct ← Encsk ( x ), the following states have cryptographically small trace distance: Game 1. Start from ( x, |Ψ⟩ AB ), evaluate C on classical input x and register A, obtaining a classical string y, and output y together with the contents of register B. Game 2. Start from |Ψ⟩ AB and ct. Homomorphically evaluate C on register A by running ⊗ poly(λ,n) ct′ ← EvalC (· ⊗ |0⟩ , ct, evk). Compute y′ = Decsk (ct′ ). Output y′ together with the contents of register B. • IND-CPA security against efficient quantum distinguishers: For any efficient adversary A (in the sense of Definition 3.11) and any two messages x0 , x1 ∈ {0, 1}n , there exists a cryptographically small function η (λ) such that, "

# R (sk, evk) ← Gen(1λ , 1 L ) Pr A (ct0 , evk) = 1 − R ct0 ← Encsk ( x0 ) " # R (sk, evk) ← Gen(1λ , 1 L ) Encsk (·) Pr A (ct1 , evk) = 1 ≤ η ( λ ). R ct1 ← Encsk ( x1 ) Encsk (·)

Here Encsk (·) denotes the encryption oracle instantiated with key sk. Remark 3.8 (Instantiation). We will use the leveled scheme due to Brakerski [Bra18] to instantiate QFHE in this work. The scheme has a hybrid structure, where ciphertexts consist of a QOTP encrypted state and a classical FHE encryption of the OTP keys. Once these classical encryptions are replaced by encryptions of a fixed unrelated value—such as zero—by a hybrid argument,the OTP hides the state information-theoretically, so any adversary against the IND-CPA security of the QFHE yields an adversary against the classical FHE. One can then apply a standard argument relating FHE security to that of LWE, with a polynomial loss [Bra18, Theorems 3.4 and 3.6]. Thus, the hardness assumption on LWE (against polynomial-time or sub-exponentialtime adversaries in our case) propagates cleanly, up to polynomial factors, to the semantic security of the QFHE scheme. 28

3.7.1

The KLVY transform

With any scheme satisfying Definition 3.13 we can instantiate the transformation from nonlocal games to single-prover arguments, proposed by [KLVY23]. Definition 3.14 presents the transform for a two-player nonlocal game, since this is the only setting which will be used in this paper. The general transform applies to nonlocal games with an arbitrary number of players and is described in [KLVY23, Section 3.2]. Definition 3.14 (Compiled nonlocal game). Fix a quantum homomorphic encryption scheme QFHE = (Gen, Enc, Eval, Dec). The KLVY transform of the two-prover nonlocal game G = (Q, V ) works as follows: R

R

R

1. The verifier samples ( x, y) ← Q, (sk, evk) ← Gen(1λ , 1 L ), and c ← Encsk ( x ). The verifier then sends c to the prover as its first message. (The evaluation key evk is used to evaluate the quantum circuit C, of depth L, on the ciphertext c and is assumed to be public knowledge to the prover.) 2. The prover replies with a message α. 3. The verifier sends y to the prover in the clear. 4. The prover replies with a message b. 5. Define a := Decsk (α). The verifier accepts if and only if V ( x, y, a, b) = 1. Remark 3.9 (Fixed-length encoding of Alice questions). IND-CPA security (Definition 3.13) is only guaranteed for pairs of messages x0 , x1 ∈ {0, 1}n of the same length n; every switching argument built on it in Section 3.7.3 (Lemmas 3.3 and 3.8 and Corollary 3.1 and their uses throughout this work) is therefore only meaningful once all elements of Alice’s question set Q A are encoded as bit strings of one common length before encryption. Throughout this work, we fix once and for all a canonical, efficiently invertible padding scheme and encode every Alice question—large-answer questions W ∈ Σn , small-answer questions (W, a), Bell pairings, magic-square rows and columns, CHSH questions, and the delegation-game question W̃ ∈ { X, Y, Z, F, G }m alike, across every test in protocols 11 and 12—as a bit string of the same length nQ A = poly(λ) before encryption, padding shorter encodings to nQ A . Under this convention ct0 , ct1 are always ciphertexts of equal-length plaintexts, so the ciphertext length carries no information about which type of question was sent, and every use of Lemma 3.3 or Corollary 3.1 to switch between Alice questions of different types is licensed by IND-CPA security in this sense. 3.7.2

Modeling prover strategies in a compiled game

The main benefit of compiled nonlocal games is the fact that you are only dealing with a single prover. Unfortunately, this also has some drawbacks. For example, a common technique in nonlocal games is to trace out one of the prover’s systems, since by assuming non-communication and finite-dimensional Hilbert spaces, the actions of different provers can be assumed to be local to their system; because of this locality, any action which Alice performs after her measurement won’t affect Bob’s outcome. In the single-prover setting these assumptions no longer hold. The prover now acts on the same quantum state in the first and second round of the interaction. We will now establish the most general way to model the prover’s actions in a compiled nonlocal game, using the same conventions as [NZ23, MNZ24] We start by introducing the initial prover state |ψ⟩, which is assumed to be efficiently prepareable and an implicit function of the cryptography’s evaluation key (evk) and security parameter (λ). All actions performed by the prover before receiving the first verifier message can be absorbed into this state. Without loss of generality, we can assume that |ψ⟩ is a pure state. 29

R

When the prover receives the first encrypted message (c ← Encsk ( x ) for x ∈ Q A ) from the verifier, he performs a general projective measurement { Pcα }α , where α goes over all possible encrypted responses to that question; again, there is an implicit dependence on evk and λ. The measurement is assumed to be projective, since we can always extend the prover’s space to obtain a projective measurement by Naimark’s dilation theorem. After this the prover is free to apply any unitary (Uαc ) which depends on the question and his output; we can absorb this operation into his projective measurement and define the non-unitary operator Acα := Uαc Pcα , where {( Acα )† Acα }α is a projector-valued measurement (PVM). Up to this point, we can identify all actions performed by the prover into the ‘Alice part’ of the nonlocal game. The sub-normalized ‘post-Alice’ state is defined as

|ψαc ⟩ = Acα |ψ⟩ = Uαc Pcα |ψ⟩, where Pr[α] = ⟨ψαc |ψαc ⟩ = ⟨ψ|( Acα )† Acα |ψ⟩, is the probability of the prover outputting α on the first question. Lastly, ψc = ∑ ψαc = ∑ |ψαc ⟩⟨ψαc |. α

α

After receiving the first response, the verifier sends the second message (b ∈ Q B ) in the clear and the prover’s actions can be modeled by a projective measurement { Byb }b , which will often be denoted by the corresponding question symbol. The prover is free to perform any unitary after this measurement, but we do not need to account for this in our model, since the interaction in a nonlocal game stops after receiving the second message from the prover. Throughout this work we will use the following compact notation: ψEnc(Q) = ∑ ψα

Enc( Q)

and

Enc( Q)

ψα

α

=

E

c←Enc( Q)

Acα |ψ⟩⟨ψ|( Acα )† ,

where the expectation over the secret key sk is implicit. Specifically, in any expression containing one or multiple secret key dependent objects, we have an implicit expectation over the secret key. I.e. ∥O(Dec(α))∥2ψEnc(Q) = E ∥O(Decsk (α))∥2ψEncsk (Q) , sk

where ψEncsk (Q) =

E

c←Encsk ( Q)

ψc .

This is very important, since the security guarantees of the cryptography (for example IND-CPA security) only hold under expectation over the secret key, as it is randomly generated by the key generation function. The same implicit expectation is assumed for the evaluation key. 3.7.3

Security of the cryptography

In this section we will introduce some useful lemmas from [NZ23] regarding the indistinguishability of different objects under the cryptography. We had to modify some of the statements, since we are working with parametrized observables implemented by Bob, which can be correlated with the Alice question. The following lemma uses the IND-CPA security of the QFHE scheme to argue that two of the prover’s states after the encrypted interaction—on two different questions—are computationally indistinguishable, even if the distinguishing measurement is allowed to depend on the prover’s first-round outcome α and one takes the expectation over different questions. Since this invokes properties of the QFHE scheme, it introduces a cryptographically small function η (λ), which 30

represents the prover’s distinguishing advantage and depends on the security parameter of the encryption. It also depends on the prover and on the distinguishing procedure (i.e. the distributions and the measurement family in the lemma below), each of which is understood as a λ-indexed family. This function will appear in most of our error bounds, and is always related to the security of the QFHE scheme. Convention (cryptographically small functions). Throughout this work, cryptographically small functions (in the sense of Definition 3.11) will appear. These always depend on the specific adversary. Thus when separately invoking the indistinguishability lemmas of this section, we are dealing with multiple different cryptographically small functions. When averaging multiple cryptographically small functions over a set whose size depends on λ, the result might not be cryptographically small. This is why the lemmas in this section construct a particular adversary, who samples the questions according to the desired distribution himself, such that a single cryptographically small function is obtained through a single invocation of the IND-CPA security. This is possible as long as the adversary can construct the question himself and its distribution is efficiently sampleable, which will always be the case in our work. However, explicitly carrying this average through calculations often unnecessarily complicates the notation. This is why we will often stick to point-wise bounds and resort to obtaining a bound on the expectation by leveraging the assumption of non-uniform adversaries (see Remark 3.7). Remark 3.10. The following lemma introduces an efficient family of POVMs {( M p , 1 − M p )} p that is uniform in p: for every λ ∈ N there is a single circuit Cλ , of size at most the bound in Definition 3.11, which takes p as classical input and implements the measurement ( M p , 1 − M p ). Our adversaries and their operations are thus non-uniform in the security parameter λ, but uniform in additional parameters, such as p; in particular, the size bound does not depend on p, which is what Remark 3.7 requires. Lemma 3.3. Let D be an efficiently sampleable distribution over triples ( x, z0 , z1 ), where x is any parameter and z0 , z1 are plaintext Alice questions. Then, for any efficient prover (modeled as in Section 3.7.2) and any efficient two-outcome POVM family { Mx,α , 1 − Mx,α } x,α (uniform in x and α), there exists a cryptographically small function η (λ) such that for all λ ∈ N, h  i Enc(z0 ) Enc(z1 ) Tr M ψ − ψ ≤ η ( λ ). x,α α α ∑

E

( x,z0 ,z1 )∼ D α

In particular, if D1 and D2 are efficiently sampleable distributions over pairs ( x, z) with identical marginals on x and efficiently sampleable conditionals Di (· | x ), the same bound holds with h

∑ Tr Mx,α ψα ( x,z)∼ D E

1

Enc(z)

i

−

h

∑ Tr Mx,α ψα ( x,z)∼ D E

2

α

Enc(z)

i

≤ η ( λ ).

α

Proof. This follows from a standard reduction to the IND-CPA security of the QFHE scheme. For a triple t = ( x, z0 , z1 ) and i ∈ {0, 1} let h i Enc(zi ) pi (t) := ∑ Tr Mx,α ψα , α

and write f (t) := p0 (t) − p1 (t). The quantity pi (t) is the acceptance probability of the efficient experiment E ( x, c): prepare |ψ⟩, apply the prover’s first-round measurement on ciphertext c, obtaining an outcome α, then measure { Mx,α , 1 − Mx,α }. Define a distinguisher A against the IND-CPA security of the scheme as follows:

31

• Sample t = ( x, z0 , z1 ) ∼ D and submit (z0 , z1 ) to the IND-CPA challenger; receive the R

R

challenge ciphertext c ← Enc(zb ), where b ← {0, 1} is chosen by the challenger. • Run E ( x, c) and output the outcome bit. The reduction is efficient in the sense of Definition 3.11: it samples from an efficient distribution, runs the efficient prover once, and implements a uniformly efficient measurement. Conditioned on the challenge bit b, the acceptance probability of A is Et∼ D pb (t). The distinguishing advantage is therefore Et∼ D f (t) , which is cryptographically small by IND-CPA security of the QFHE scheme. For the D1 , D2 form, sample x from the common marginal (e.g. sample ( x, z) ∼ D1 and discard z), then sample z0 ∼ D1 (· | x ) and z1 ∼ D2 (· | x ). This is an efficiently sampleable distribution over triples, and the first claim specialises to the second. The lemma above is a strengthening of [NZ23, Lemma 8], since it allows for a dependence on α and introduces an additional parameter x. Choosing Mx,α = Mx independent of α yields the corresponding statement for the marginal states ψEnc(z) . Lemma 3.4. Let D1 and D2 be two distributions over pairs ( x, z), where x is any parameter and z is a plaintext Alice question. Suppose D1 and D2 satisfy the following. • D1 and D2 are efficiently sampleable, with identical marginals on x. • For any x in the support of their common marginal, the conditional distributions D1 (·| x ) and D2 (·| x ) over z are also efficiently sampleable. Then, for any efficient prover, and for any efficient family of POVMs {{ Mβ,x,α } β } x,α (uniform in x and α) with outcomes | β| ≤ O(1), there exists a cryptographically small function η (λ) such that for all λ ∈ N, E

h i Enc(z) β Tr M ψ − β,x,α α ∑∑

( x,z)∼ D1 α

β

E

h i Enc(z) β Tr M ψ ≤ η ( λ ). β,x,α α ∑∑

( x,z)∼ D2 α

β

Proof. Let C ∈ N such that | β| ≤ C for all ( x, α), and define the rescaled outcomes as, β̃ =

β+C ∈ [0, 1]. 2C

Define the two-outcome POVM { Nx,α , 1 − Nx,α }, with Nx,α := ∑ β̃Mβ,x,α , β

intuitively this measurement can be implemented as follows: first perform the M measurement (efficient given the pair ( x, α)) and obtain an outcome β, then output 1 with probability β̃. Nx,α is indeed a valid POVM element, since Nx,α ⪰ 0 ( β̃ ≥ 0 and Mβ,x,α ⪰ 0) and Nx,α ⪯ ∑ 1 · Mβ,x,α = 1, β

it is also uniformly efficient in ( x, α), since {{ Mβ,x,α } β } x,α is. Applying Lemma 3.3 to Nx,α in the D1 , D2 form, there exists a cryptographically small function η (λ) such that E

h i Enc(z) Tr N ψ − x,α α ∑

( x,z)∼ D1 α

E

h i Enc(z) Tr N ψ ≤ η ( λ ), x,α α ∑

( x,z)∼ D2 α

32

inserting the definition of Nx,α and β̃, we get

∑ ( x,z)∼ D E

1 α,β



β+C 2C

 Tr

h

Enc(z) Mβ,x,α ψα

i

−

∑ ( x,z)∼ D E



2 α,β

β+C 2C



h i Enc(z) ≤ η ( λ ). Tr Mβ,x,α ψα

The shift of C contributes the same constant to both terms, since by completeness of the POVM h i h i 1 h Enc(z) i C 1 1 Enc(z) Enc(z) Tr ψ = Tr M ψ = Tr ψ = , α α β,x,α ∑ ∑ ∑ 2C 2 α 2 2 α β so it cancels, and the re-scaling of 2C can be absorbed in η (λ), which remains cryptographically small. This completes the proof. Definition 3.15. Let Hx ∈ Herm(H) be a Hermitian matrix parameterized by x. A uniformly efficient family of block encodings of { Hx } with scale factors {t x } and auxiliary dimension k is an efficient circuit, that given x implements a unitary matrix Ux ∈ U ((C2 )⊗k ⊗ H), such that

(⟨0k | ⊗ 1)Ux (|0k ⟩ ⊗ 1) = t x Hx , or graphically for the case of k = 1:  Ux =

 t x Hx ∗ . ∗ ∗

That is, the set {Ux } x is a efficient family of unitaries, uniform in x, with the additional block-encoding condition. Lemma 3.5. The set of unitaries { B( a)} a defined from an efficient PVM { B x } x∈{0,1}n , as B( a) =

∑ (−1)x·a Bx ,

x ∈{0,1}n

is a efficient family of unitaries, uniform in a. I.e. there exists an efficient procedure, that given a as input, implements B( a). Proof. Since the PVM is efficiently implementable, there exists an efficient unitary U (the measurement circuit) such that U |ψ⟩|0⟩ = ∑( B x |ψ⟩)| x ⟩, x

where the second register is an ancilla register, which records the measurement outcome. We have B( a)|ψ⟩|0⟩ = U † (1 ⊗ σZ ( a))U |ψ⟩|0⟩, which is also efficiently implementable given a as input. Definition 3.16 (Uniformly efficient family of linear combination of unitaries (LCU)). A set of operators { A x } x , indexed by a classical parameter x, is a uniformly efficient family of LCUs, if there exists a constant m ∈ N and: • uniformly efficient real coefficient γi,x ∈ [−1, 1], with ∑i |γi,x | ̸= 0 ∀ x. • a set of uniformly efficient families of unitaries {{Ui,x } x }i∈[m] , such that for all x

A x = ∑ γi,x Ui,x . i ∈[m]

33

Lemma 3.6. For every uniformly efficient family of LCUs ({ A x } x ), where all A x are Hermitian, there exists a uniformly efficient family of block encodings of { A x } with uniformly efficient scale factors t x = 1/νx , where νx = ∑i |γi,x |. In particular |t x | ≥ 1/m. Proof. The circuit will act on k = ⌈log(m)⌉ ancilla qubits, where m is the maximal number of terms in the LCUs. We first introduce the preparation unitary Px , which given x implements s |γi,x | | i − 1⟩, Px |0⟩ = ∑ νx i ∈[m] where νx = ∑i |γi,x | and |i − 1⟩ denotes the computational-basis encoding of the integer i − 1 on the ancilla register. This operation is efficient since there are only a constant number of terms in the sum. Next we define the controlled application of our unitaries, based on the ancilla register, let Sx := ∑ |i − 1⟩⟨i − 1| ⊗ si,x Ui,x i ∈[m]

γ where si,x = |γi,x | (and si,x = 1 if γi,x = 0). Again this unitary is uniformly efficient in x, because i,x

the family of unitaries are uniformly efficient in x and because there are only constantly many of them. The operation Ux = ( Px† ⊗ 1)Sx ( Px ⊗ 1) then satisfies

|γi,x | 1 si,x Ui,x = A x , νx νx i ∈[m]

(⟨0| ⊗ 1)Ux (|0⟩ ⊗ 1) = ∑

so Ux is a block encoding of A x with scale factor t x = 1/νx . Since γi,x ∈ [−1, 1] and there are only m terms, we have 0 < νx ≤ m, hence |t x | ≥ 1/m. Both Px and Sx are efficient procedures taking x as input and implementing a specific quantum circuit, so {Ux } x is a uniformly efficient family of unitaries, which completes the proof. Lemma 3.7. Suppose we have a uniformly efficient family of block encodings for a family of (not necessarily binary) observables { A x } x with uniformly efficient scale factors |t x | ≥ 1/c for some constant c independent of x. Then there exists a uniformly efficient POVM family { Mβ,x } β,x with outcomes β ∈ {−1/t x , 1/t x }, satisfying | β| ≤ c = O(1), such that for any state ρ,   ∑ β Tr Mβ,x ρ = Tr [ Ax ρ] . β

Proof. This is a generalization of [NZ23, Lemma 14] to uniformly efficient families of observables and measurements. Since { A x } are observables, they are Hermitian, and we can replace the canonical phase-estimation approach by the simpler Hadamard test, which yields the same result for Hermitian operators. By the lemma assumptions we know that there exists a uniformly efficient family of block encodings of { A x }, the elements of which we can denote by Ux . We then construct the binary measurement Mβ,x as follows: it performs the Hadamard test on ρ with a controlled Ux (and the block encoding ancillas initialized in |0⟩), denoting the control qubit measurement outcome as b, the associated POVM outcome is then defined as β = (−1)b /t x . This POVM family is uniformly efficient in x, since both t x and {Ux } are uniformly efficient and we only incur a multiplicative overhead when implementing the controlled operation. By the Hadamard test identity and the block-encoding relation (⟨0| ⊗ 1)Ux (|0⟩ ⊗ 1) = t x A x , we have Pr[b] =

  1 1 1 + (−1)b ℜ Tr [Ux (|0⟩⟨0| ⊗ ρ)] = 1 + (−1)b t x Tr [ A x ρ] , 2 2 34

where the last step uses that A x is Hermitian (so the trace is real) and that t x is real. The two outcomes are β ± = ±1/t x , and therefore 1

1

∑ β Tr Mβ,x ρ = tx Pr[b = 0] − tx Pr[b = 1] = Tr [ Ax ρ] . 



β

The hypothesis |t x | ≥ 1/c gives | β| ≤ c = O(1), which completes the proof. Lemma 3.8. Let D1 and D2 be two distributions over pairs ( x, z), where x is any parameter and z is a plaintext Alice question. Suppose D1 and D2 satisfy the following. • D1 and D2 are efficiently sampleable, with identical marginals on x. • For any x in the support of their common marginal, the conditional distributions D1 (·| x ) and D2 (·| x ) over z are also efficiently sampleable. Then, for any efficient prover, and for any uniformly efficient family of LCUs { A x,α } x,α (with A x,α = A†x,α ), indexed by the pair ( x, α), there exists a cryptographically small function η (λ) such that for all λ ∈ N, h i h i Enc(z) Enc(z) E ∑ Tr A x,α ψα − E ∑ Tr A x,α ψα ≤ η ( λ ). (3.8) ( x,z)∼ D1 α

( x,z)∼ D2 α

Proof. Let { Mβ,x,α } be the uniformly efficient family of POVMs guaranteed by Lemma 3.7 applied to the uniformly efficient family of block encodings for { A x,α } given by Lemma 3.6, both instantiated with the classical index ( x, α). Lemma 3.6 yields scale factors t x,α = 1/νx,α with νx,α ≤ m, hence |t x,α | ≥ 1/m; the Hadamard-test outcomes therefore satisfy | β| = νx,α ≤ m = O(1) uniformly over ( x, α), as required by Lemma 3.4. By construction of the Hadamard test, the left-hand side of Eq. (3.8) equals h i Enc(z) β Tr M ψ − α β,x,α ∑∑

E

( x,z)∼ D1 α

β

i h Enc(z) β Tr M ψ , α β,x,α ∑∑

E

( x,z)∼ D2 α

β

which is cryptographically small by Lemma 3.4. Corollary 3.1. Let D1 and D2 be two distributions over pairs ( x, z), where x is any parameter and z is a plaintext Alice question. Suppose D1 and D2 satisfy the following. • D1 and D2 are efficiently sampleable, with identical marginals on x. • For any x in the support of their common marginal, the conditional distributions D1 (·| x ) and D2 (·| x ) over z are also efficiently sampleable. Then, for any efficient prover, and for any uniformly efficient family of LCUs { A x,α } x,α , there exists a cryptographically small function η (λ) such that for all λ ∈ N,

∑ ∥ Ax,α ∥2ψ ( ) − (x,zE)∼D ∑ ∥ Ax,α ∥2ψ ( ) ≤ η (λ).

E

Enc z α

( x,z)∼ D1 α

2

(3.9)

Enc z α

α

Proof. Equation (3.9) is equivalent to h

∑ Tr A†x,α Ax,α ψα ( x,z)∼ D E

1

α

Enc(z)

i

−

h

∑ Tr A†x,α Ax,α ψα ( x,z)∼ D E

2

35

α

Enc(z)

i

≤ η ( λ ).

If we can show that the set of all Cx,α = A†x,α A x,α is again a uniformly efficient family of LCUs (indexed by ( x, α)), we can apply Lemma 3.8 to {Cx,α } which completes the proof. We have Cx,α = A†x,α A x,α = ∑

† Uj,x,α , ∑ γi,x,α γj,x,α Ui,x,α

i ∈[m] j∈[m]

which is an LCU with m2 terms, indexed by pairs (i, j) ∈ [m] × [m]. Each coefficient γi,x,α γ j,x,α lies in [−1, 1], and since {{Ui,x,α } x,α }i∈[m] is a set of uniformly efficient families of unitaries, their pairwise products (cross-family for the same parameter) again form uniformly efficient families of unitaries. This shows that {Cx,α } is again a uniformly efficient family of LCUs, so the corollary conclusion immediately follows from Lemma 3.8 applied to {Cx,α }. Corollary 3.1 switches the state argument of an LCU A x,α ∈ L(H), an operator on H. Several of our arguments (e.g. Lemmas 4.31 and 4.33) instead need to switch the state argument of a norm ∥VUx,α − Nx,α V ∥2ψEnc(q) , where V : H → H′ is the (generally non-unitary) isometry of Definition 4.6 and Ux,α , Nx,α are unitaries on H, H′ respectively: here the object being switched is not literally an operator on H, so Corollary 3.1 does not apply directly. The following isometry version supplies the missing step. Corollary 3.2 (Isometry version of Corollary 3.1). Let V : H → H′ be a QPT-implementable isometry: there exist an efficiently-sized ancilla space anc, an efficient unitary dilation UV ∈ U (H ⊗ anc), and a fixed efficient embedding H′ ,→ H ⊗ anc, such that UV (|ψ⟩ ⊗ |0⟩anc ) = V |ψ⟩ for all |ψ⟩ ∈ H. (This holds for the isometry of Definition 4.6, by the same argument as in the proof of Corollary 3.3: the quantum Fourier transform of Section 3.3 and the controlled- f built from the prover’s operators are both efficient.) Let D1 , D2 be as in Corollary 3.1, let {Ux,α } x,α be a uniformly efficient family of unitaries on H, and let { Nx,α } x,α be a uniformly efficient family of unitaries on H′ . Then, for any efficient prover, there exists a cryptographically small function η (λ) such that for all λ ∈ N,

∥VUx,α − Nx,α V ∥2ψ ( ) − E ∑ ∥VUx,α − Nx,α V ∥2ψ ( ) ≤ η (λ). ∑ ( x,z)∼ D ( x,z)∼ D E

1

Enc z α

α

2

α

Enc z α

Proof. Write Bx,α := V † Nx,α V ∈ L(H). Since V † V = 1H and Ux,α , Nx,α are unitary, we can expand the squared norm to get h i Enc( x ) † † V † − V † Nx,α )(VUx,α − Nx,α V )ψα ∑ ∥VUx,α − Nx,α V ∥2ψαEnc(x) = ∑ Tr (Ux,α α α h i h  Enc(x) i Enc( x ) † † = 2 ∑ Tr ψα − ∑ Tr Ux,α Bx,α + Bx,α Ux,α ψα . (3.10) α

|

α

{z

=1

}

Our main task is to show that the second term in the last line corresponds to an efficient measurement of the state, such that we can apply Lemma 3.4 to relate its expectation value on the two distributions D1 , D2 . To do so, extend Nx,α to a unitary Ñx,α := Nx,α ⊕ 1 on H ⊗ anc, acting as the identity on the orthogonal complement of the fixed embedding H′ ,→ H ⊗ anc; since this embedding is fixed and efficient, { Ñx,α } is again uniformly efficient. Define † Ûx,α := (Ux,α ⊗ 1anc ) UV† Ñx,α UV ∈ U (H ⊗ anc),

which is efficient, since Ux,α , UV and Ñx,α are. Using UV (|ϕ⟩ ⊗ |0⟩anc ) = V |ϕ⟩ ∈ H ′ for all |ϕ⟩ ∈ H, and that Ñx,α restricted to H′ acts as Nx,α , a direct computation gives, for all |ϕ⟩, |χ⟩ ∈ H, † † (⟨ϕ| ⊗ ⟨0|anc ) Ûx,α (|χ⟩ ⊗ |0⟩anc ) = ⟨ϕ| Ux,α V † Nx,α V |χ⟩ = ⟨ϕ| Ux,α Bx,α |χ⟩,

36

† B so Ûx,α is an efficient, scale-1 block encoding of Ux,α x,α ∈ L (H), with ancilla register anc. By Lemma 3.7 (with c = 1), this yields a uniformly efficient family (β = ±1)    † of two-outcome  Bx,α ρ for every state ρ; since Hadamard-test POVMs { Mβ,x,α } with ∑ β β Tr Mβ,x,α ρ = Tr Ux,α the Hadamard test measures the real part of this (complex, in general) quantity, the same family also satisfies h    i † † 1 β Tr M ρ = Tr U B + B U β,x,α ∑ x,α x,α x,α x,α ρ . 2 β

Therefore, by Eq. (3.10), we have h i Enc(z) 2 VU − N V = 2 − β Tr M ψ . ∥ ∥ Enc(z) x,α x,α β,x,α α ∑ ∑∑ ψ α

α

α

β

The first term does not depend on z, so applying Lemma 3.4 to the uniformly efficient POVM family { Mβ,x,α } bounds the difference of the second term between D1 and D2 by a single cryptographically small function, which completes the proof. 3.7.4

QFHE Overhead

For our construction we will instantiate QFHE from Brakerski’s scheme [Bra18] (which improves the original proposal by Mahadev [Mah20]). We choose a specific scheme to be able to determine the overall resource requirements, which includes all QFHE encryptions, homomorphic evaluations, etc. We believe that our construction is still efficient if we replace the QFHE scheme with the one from [GV24] but we did not go through the resource estimation in detail for that protocol. Category

Resource

Asymptotic cost

Setting: classical input of c bits; security parameter λ; leveled scheme; Clifford + Toffoli circuit of size n with Toffoli depth L ≤ O(polylog(n)) and width q.

Communication

Prover

Verifier

Encrypted input (V → P)

O(c · poly(λ)) bits

Evaluation keys (V → P)

O( L · poly(λ)) bits

Encrypted output (P → V)

O(q · poly(λ)) bits

Total

 O (c + L + q) · poly(λ) bits

Quantum circuit size

O(n · poly(λ)) gates

Ancilla qubits per Toffoli (reusable)

poly(λ)

Time complexity

O(n · poly(λ))

Time complexity

O((c + q) · poly(λ))

Table 4: Resource requirements for Brakerski’s QFHE protocol [Bra18], leveled instantiation under LWE with polynomial modulus and no circular security assumption. Table 4 tells us that the QFHE encryption only introduces a multiplicative overhead of poly(λ) in all resources. Unfortunately, this specific scheme requires the circuit, which will be evaluated on the encrypted input, to be compiled in the Clifford + Toffoli gate set. The circuit in question is the honest Alice strategy, which consists of a circuit taking in the verifier’s question and Alice’s quantum state as inputs and performing a specific measurement on Alice’s state, depending on the question. In our rigidity test (protocol 11 and subtests), there are only a few different measurement types which the honest prover must implement. The most important ones are: 37

• Large-answer measurements: Every qubit with index i ∈ [n] gets measured in the basis W̃i , with W̃ ∈ { X, Y, Z, F, G }n . Pure-basis measurements are a special case of this where W̃ ∈ { X n , Y n , Z n , F n , G n }. This measurement type appears in protocols 5, 6, 8 and 11. • Small-answer measurements: The prover can be asked to perform up to three simultaneous (compatible) binary measurements. For example, in the commutation test, observables A and B are simultaneously measured. This measurement type appears in protocols 2, 3, 4, 6 and 8. • Bell-basis measurements: In the Clifford test (protocol 11) the prover is asked to measure all qubits in one of the two brick-wall pairings in the Bell basis. One can come up with a general encoding of the verifier question, which specifies the measurement type and some type-specific parameters (such as the basis or pairing choice). The honest prover strategy—acting on an encoded question and the prover’s state—is highly parallelizable (given O( g) ancillas) since we can ensure that different measurement blocks act on distinct qubits (i.e. qubits are separately handled), that there is only a constant depth of intersecting operations within one measurement block and that the rest of the operations is non-intersecting. When using the natural gate set (all the operations needed for the strategy are allowed), the circuit implementing Alice’s honest strategy has constant depth. To allow for homomorphic evaluation, the circuit needs to be compiled to the Clifford + Toffoli gate set. By the Solovay–Kitaev construction for approximating arbitrary unitaries, this will increase the depth by at most a factor of O(polylog( g)) (see [Kup23] for an efficient algorithm), since there are g gates in the circuit and approximating any gate up to precision ε introduces an overhead of polylog(1/ε). If we want to achieve a constant overall approximation precision, this ε will depend on g, which justifies the claimed blow-up. The exact circuit depth can be determined a priori and it is small (O(polylog( g)) which is O(poly(λ)) under both hardness assumptions), which allows us to use a leveled QFHE scheme, which does not require the circular security assumption, but where the verifier needs to send as many evaluation keys as there are levels (which are defined as a sequence of Cliffords followed by one layer of non-intersecting Toffolis) in the circuit. Not every gate in the honest strategy needs to be approximated, the only non-Clifford, nonToffoli gates that appear are CH, CP and CT, where the first two can be exactly implemented (see [BFGH08] for CH and use an ancilla with phase kick-back for CP) and only the latter needs to be approximated. If we insert a circuit size of O( g poly(log g)) (which also trivially bounds the width7 ) and classical input size of O( g) into Table 4, we see that the overall resource cost for the QFHE step is upper-bounded by O(poly(λ)polylog( g) g). Under polynomial hardness of LWE one must take λ = gΩ(1) to accommodate honest computations, so the overhead becomes O( g1+ε ) for every ε > 0. Under sub-exponential hardness, one can take λ = (log g)Θ(1/δ) and write the cost e ( g ). as O

3.8

Approximate group representations

A stability theorem is a result of the following form: if a collection of objects approximately satisfies a certain set of properties, then it can be “rounded” to another collection of objects that satisfy these properties exactly. We will be concerned with the stability of group representations, i.e. results that show that if a collection of operators approximately satisfies the relations of a group representation, then there exists another exact representation that is, in a suitable sense, 7 True width is O ( g ) + poly( λ ) since the Toffoli ancillas are reusable.

38

close to the approximate representation. Such stability results have been shown in generality by Gowers and Hatami [GH17] as well as de Chiffre et al. [DCOT18]. For our results, we need two modifications of these existing stability theorems: first, we show that group representations are stable even when averages are taken over arbitrary measures on the underlying group. This also provides a much simpler proof of a weaker version of the main result from [GH17] using only elementary facts from quantum information theory, as shown in Theorem 3.1. Second, we introduce an explicit expression for the isometry, which is defined in Definition 3.17. Definition 3.17 (GH Isometry). Let G be a finite group, UQFT be the quantum Fourier transform over that group and f : G → U (H). Then the Gowers–Hatami (GH) isometry is the isometry V : H → H′ defined as: 1 V := UQFT |t⟩ ⊗ f (ut−1 ) ⊗ |u⟩. | G | u,t∑ ∈G Theorem 3.1 (Strengthening of Theorem 3.1 in [MNZ24]). Let G be a finite group and f : G → U (H). Then for all g ∈ G and all ρ ∈ Pos(H), it holds that 1 ∥ f (h) f ( g) − f (hg)∥2ρ = ∥V f ( g) − π ( g)V ∥2ρ . | G | h∑ ∈G where V : H → H′ is the GH isometry from Definition 3.17 and π : G → U (H′ ) is the direct sum of all irreducible representations ρµ : G → U (Hµ ) of G π ( g) :=

M

ρµ ( g) ⊗ 1.

µ

Proof. This proof is in large part inspired by [MNZ24, Theorem 3.1], we made the modification of explicitly writing out an isometry to obtain a tighter anti-symmetric distance bound and simplify the proof. In this form the proof consists almost entirely of elementary facts from linear algebra. By embedding the function f inside the isometry, we are essentially just cleverly re-writing the expression to explicitly pull out an exact unitary representation of the group G. Let HG be a | G |-dimensional Hilbert space, where every basis vector is associated to a group element and define a representation π ′ : G → U (HG ) by π ′ ( g) = ∑ | gh⟩⟨h|.

(3.11)

h∈ G

It is clear that π ′ is a unitary representation of G (in fact, π ′ is the left regular representation, written in Dirac notation). Recall from Section 3.3 that the quantum Fourier transform blockdiagonalizes the left regular representation, and thus † UQFT π ′ ( g) UQFT =

M

ρ µ ( g ) ⊗ 1d µ ,

µ

where ρµ : G → U (Hµ ) is an irreducible representation of G with dimension dµ . As choice for the isometry, we will use the GH isometry from Definition 3.17. The specific form is based on an inspection of the proof of [MNZ24, Theorem 3.1]. Specifically, after determining the Kraus operators for the channel corresponding to ϕ in said proof, we guessed the simplified form of Definition 3.17 which yields a stronger bound and a shorter proof. Thus we have an isometry V : H → HG ⊗ H ⊗ HG given by V :=

1 UQFT |t⟩ ⊗ f (ut−1 ) ⊗ |u⟩, | G | u,t∑ ∈G 39

note that V is not necessarily efficient, since it requires computing the quantum Fourier transform of a general group, preparing the uniform superposition over all group element basis states and implementing the inverse and multiplication group operations. It is indeed an isometry since ! ! 1 † V†V = ⟨t′ |UQFT ⊗ f ( u ′ ( t ′ ) −1 ) † ⊗ ⟨ u ′ | ∑ UQFT |t⟩ ⊗ f (ut−1 ) ⊗ |u⟩ | G |2 u∑ ′ ,t′ u,t 1

}| { z 1 −1 † −1 = f ( ut ) f ( ut ) ∑ | G |2 u,t

= 1, where the last step follows from the unitarity of f . The following expression will be useful later † (UQFT π ′ ( g)UQFT ⊗ 1 ⊗ 1G )V =

1 UQFT π ′ ( g)|t⟩ ⊗ f (ut−1 ) ⊗ |u⟩ |G| ∑ u,t

=

1 UQFT | gt⟩ ⊗ f (ut−1 ) ⊗ |u⟩ |G| ∑ u,t

=

1 UQFT |t⟩ ⊗ f (ut−1 g) ⊗ |u⟩, |G| ∑ u,t

where we used the definition of π ′ ( g) in the second equality and relabeled tg 7→ t for the last equality. With this and an explicit expression for the isometry we can make the following observation, for arbitrary g ∈ G   2 † (UQFT π ′ ( g)UQFT ⊗ 1 ⊗ 1G )V − V f ( g ) | ψ ⟩

=

1 | G |2

∑ UQFT |t⟩ ⊗ ( f (ut−1 g) − f (ut−1 ) f ( g))|ψ⟩ ⊗ |u⟩

2

u,t

2 1 = ( f (ut−1 g) − f (ut−1 ) f ( g))|ψ⟩ ∑ 2 | G | u,t

=

1 ∥( f (hg) − f (h) f ( g))|ψ⟩∥2 , | G | h∑ ∈G

where we used left unitary invariance, the orthogonality of the group element basis and the following elementary fact for the last equality

∑ f (ut−1 ) = |G| ∑ f (h).

u,t∈ G

h∈ G

This fact follows from the closure of the group under the group operations and the fact that every group element has a unique inverse. Since any ρ ∈ Pos(H) is also Hermitian, it can be written in its orthonormal eigenbasis as ρ = ∑ λi |ψi ⟩⟨ψi |, i

with real eigenvalues λi . By the linearity in the state of the state-dependent (semi) norm and its equivalence to the Euclidean norm for pure states, we have

∥π ( g)V − V f ( g)∥2ρ = ∑ λi ∥π ( g)V − V f ( g)∥2ψi i

=∑ i

=

λi ∥ f (hg) − f (h) f ( g)∥2ψi | G | h∑ ∈G

1 ∥ f (hg) − f (h) f ( g)∥2ρ | G | h∑ ∈G 40

† with π : G → U (H′ ), π ( g) := UQFT π ′ ( g)UQFT ⊗ 1 ⊗ 1G , this shows the theorem claim and concludes the proof.

Remark 3.11. If f is exactly right-multiplicative over some µ, i.e. if f (h) f ( g) = f (hg) for all g ∈ supp(µ) and for all h ∈ G, then V f ( g) = π ( g)V for all g ∈ supp(µ). Corollary 3.3. Let G be a finite group and f : G → U (H). If the quantum Fourier transform over G, the group operations (including inversion) and a controlled- f are QPT-implementable in log | G | and λ, then there exists a finite-dimensional Hilbert space H′ such that the GH isometry V : H → H′ from Definition 3.17 is QPT-implementable, and it holds for all g ∈ G and all ρ ∈ Pos(H) that 1 ∥ f (h) f ( g) − f (hg)∥2ρ = ∥V f ( g) − π ( g)V ∥2ρ , | G | h∑ ∈G where π : G → U (H′ ) is the direct sum of all irreducible representations ρµ : G → U (Hµ ) of G π ( g) :=

M

ρµ ( g) ⊗ 1.

µ

Proof. This follows from Theorem 3.1, where the additional requirements ensure that the isometry V (from Definition 3.17) can be efficiently implemented.

4

Rigidity

4.1

Protocols

The Clifford test (protocol 11) is built hierarchically from a small set of reusable subtests. Figure 4 gives an overview of this structure: each box is a (sub)test, and an arrow points from a test to every subtest it invokes. The remainder of this section defines each of these protocols, working bottom-up from the primitive tests to the full Clifford test. Convention (automatic consistency test). The consistency test (protocol 1) never appears explicitly in the protocol boxes below. Instead, we wrap only named tests which themselves send questions to the provers, i.e. the leaf tests COM, AC, SLC, PREL, MBT and CONJ. Whenever such a leaf T is invoked as a subtest, it is executed as CON ( T ): with probability 1/2 the verifier plays T and with probability 1/2 it sends a question sampled from either the Alice-marginal or the Bobmarginal of T (each with equal probability) to both players and checks that the answers agree. Named tests that only dispatch to other named tests—CREL, CONJ - CLIFF and CLIFF - GROUP—are executed unwrapped, as are the top-level tests (the Clifford test (protocol 11) and the verification protocol (protocol 12)), the subtests specified inline within them, and the invocation of the Clifford test inside the verification protocol. This convention has two consequences that we use throughout. For completeness: the honest strategy (Table 5) passes every consistency check with probability 1, because Alice honestly measures the transposed observables on her halves of the shared EPR pairs, so her outcomes agree with Bob’s on identical questions; since moreover every wrapped leaf has perfect honest completeness, the wrapping leaves all quoted completeness values—in particular ω ∗ = 61 (5 + cos2 π8 ) for the Clifford test, whose only imperfect item (the inline CHSH subtest) is unwrapped—unchanged. For soundness: a prover that succeeds with probability 1 − ε in an invocation of a leaf test T (which, by the convention, is an invocation of CON ( T )) succeeds with probability 1 − 2ε in T itself and, by Lemma 4.1, every question distribution appearing in T is ε-self-consistent. Success 1 − ε in an unwrapped dispatcher is then success 1 − O(ε) in each of its constantly many wrapped leaves. All constant-factor bookkeeping arising from this is absorbed into the O(·) notation. Whenever a soundness lemma

41

below assumes success probability 1 − ε in a leaf test, it is to be read as success probability 1 − ε in its consistency-wrapped execution. CLIFF

Clifford test

CLIFF - GROUP

Clifford group test

Bell-basis test

CREL (×2)

PREL (×2)

CONJ - CLIFF

comm. relation

prod. relation

Cliff. conjugation

SLC

small/large

COM / AC

CONJ (×3)

SLC

conjugation

Sign con. test

CHSH test

MBT (×2)

mixed-vs-pure

MBT

COM / AC

Figure 4: Protocol structure of the Clifford test. An arrow points from each test to the subtests it invokes. Solid boxes are protocols defined in this section; the darkest is the top-level Clifford test (protocol 11), gray boxes are the primitive tests, and dashed boxes are subtests specified inline within protocol 11. Double outlines mark leaf tests that are executed as CON ( T ) (cf. the consistency convention above); named dispatchers (CLIFF - GROUP, CREL, CONJ - CLIFF) have a single outline and are unwrapped, as are the Clifford test itself and the inline subtests. A multiplicity “×k” indicates that the protocol is invoked k times (with different operator sets); e.g. CREL and PREL are each run for the Pauli and the Clifford generators. Protocol 1: Consistency test Notation: CON ( T ) Input: any two-player test T, with question set Q A × Q B and question distribution PT ( X, Y ) for ( X, Y ) ∈ Q A × Q B . Calculate PT,A (·) = ∑y∈QB PT (·, y) and PT,B (·) = ∑ x∈Q A PT ( x, ·), i.e. the Alice and Bob R

question marginals, and draw b, s ← {0, 1}. 1. If b = 0, execute the game T. 2. If b = 1, sample W ∼ PT,A if s = 0 and W ∼ PT,B if s = 1, and send this question to both players. Receive answers a, b ∈ {0, 1}n from both provers, respectively and accept if and only if a = b. Here n is equal to the number of answer bits expected for the label W in game T. Protocol 2: Commutation test Notation: COM ( A, B) Input: Two questions A and B, corresponding to some Bob observables.

42

1. Send W = ( A, B) to Alice and receive answer a = ( a1 , a2 ) ∈ {0, 1}2 . R

2. Draw b ← [2], send Wb to Bob and receive answer d ∈ {0, 1}. Accept if and only if ab = d, where W1 = A and W2 = B. Protocol 3: Anti-commutation test Notation: AC ( A, B) Input: Two questions A and B, corresponding to some Bob observables. In this protocol, the verifier plays a version of the Mermin–Peres Magic Square game [Mer90, Per90] with the provers, in which Alice is asked to measure three observables forming a row or column of the square, and Bob is asked to measure one observable from a single cell of the square. All labels except for cells 2 and 4 should not appear in any other game, thus if the input labels to the anti-commutation game are X and Y, the cells will have labels C IX , C IY , .... 2

1

Γ1AB

3

5

4

6

Γ5AB

B 7

8

Γ7AB

Γ3AB

A

Γ6AB 9

Γ8AB

Γ9AB

1. Choose a cell index j ∈ [9] uniformly at random; choose the row or the column which contains cell j uniformly at random, on the 3 × 3 grid. Denote the 3 cells in this row or column as (i1 , i2 , i3 ) (by construction one of these will be equal to j). 2. Send the triple of labels in the chosen row or column to Alice and receive three answer bits a = ( a1 , a2 , a3 ) ∈ {0, 1}3 . For example if (i1 , i2 , i3 ) = (1, 2, 3) then Alice receives (Γ1AB , A, Γ3AB ). 3. Send the label corresponding to the cell index j to Bob and receive one answer bit b ∈ {0, 1}. For example, if j = 3, Bob receives Γ3AB . 4. Accept if al = b for l s.t. il = j and ( a1 ⊕ a2 ⊕ a3 = 0 a1 ⊕ a2 ⊕ a3 = 1

If (i1 , i2 , i3 ) ̸= (3, 6, 9) If (i1 , i2 , i3 ) = (3, 6, 9)

Protocol 4: Conjugation test Notation: CONJ ( A, B, R) Input: Three questions A, B and R, corresponding to equally named Bob observables. Execute each of the following tests with equal probability (1/3 each). 1. (Anti)commutation test: With uniform probability (1/5 each), execute one of the following tests: COM ( XR , C AB ), AC ( XC , ZC ), COM ( A, XC ), COM ( B, XC ) or COM ( R, ZC ). 2. C AB characterization test: Ask Alice to measure A, B, C AB or ZC (with probability 1/4 each) returning answer a ∈ {0, 1}, and Bob to measure ( A, ZC ) or ( B, ZC ) (with probability 1/2 each), returning b = (b1 , b2 ) ∈ {0, 1}2 . Reject if either:

43

• Alice was asked C AB , Bob was asked ( A, ZC ), a ̸= b1 and b2 = 0; • Alice was asked C AB , Bob was asked ( B, ZC ), a ̸= b1 and b2 = 1; • Alice was asked A, Bob was asked ( A, ZC ) and a ̸= b1 ; • Alice was asked B, Bob was asked ( B, ZC ) and a ̸= b1 ; • Alice was asked ZC and a ̸= b2 . 3. XR characterization test: Ask Alice to measure R, XC or XR (with probability 1/3 each) returning answer a ∈ {0, 1} and Bob to measure ( R, XC ) returning b = (b1 , b2 ) ∈ {0, 1}2 . Reject if either: • Alice was asked R and a ̸= b1 ; • Alice was asked XC and a ̸= b2 ; • Alice was asked XR and a ̸= b1 ⊕ b2 . Protocol 5: Mixed-versus-pure basis test Notation: MBT (Σ, n, µ) Input: A question alphabet Σ, expected answer length n and a distribution µ over Σn . R

1. Sample W ← Σ, send it to Alice and receive answer a ∈ {0, 1}n . 2. Sample W̃ ← Σn , send it to Bob and receive answer b ∈ {0, 1}n . Accept if and only if ai = bi for all i : W̃i = W. µ

Protocol 6: Small/large answer consistency test Notation: SLC (Θ, n, µ) Input: A question set Θ, expected answer length n and bit-string distribution µ. R

1. Sample a ← {0, 1}n and W ← Θ. Send question (W, a) to Alice, receiving answer x ∈ {0, 1} and send question W to Bob, obtaining answer u ∈ {0, 1}n . Accept iff u · a = x. µ

Protocol 7: Commutation relation test Notation: CREL (Σ, n) Input: A question alphabet Σ and expected answer length n. R

R

R

Sample a, b ← {0, 1}n , W1 ← Σ and W2 ← Σ \ {W1 }. Execute each of the following tests with equal probability. 1. Small/large answer consistency test: Execute SLC (Σ, n, U2n ). 2. Small answer (anti)commutation test: (a) If a · b = 0: Execute COM ((W1 , a), (W2 , b)). (b) If a · b = 1: Execute AC ((W1 , a), (W2 , b)).

44

Protocol 8: Product relation test Notation: PREL ( Z, X, Y, n) Input: Three question symbols Z, X, Y and expected answer length n. R

R

Sample α ← {0, 1}n−1 , y ← [2] and compute the n-bit string a := α ∥ (α · α). Note that a always has even Hamming weight. Let W = ( Z, X ), so W1 = Z and W2 = X. Execute each of the following tests with equal probability. 1. Send question (( Z, a), ( X, a)) to Alice, receive outcome ( x1 , x2 ) ∈ {0, 1}2 , and send question Y to Bob, obtaining an answer u ∈ {0, 1}n . Accept if and only if u · a ⊕ | a|/2 = x1 ⊕ x2 (mod 2). 2. Send question (( Z, a), ( X, a)) to Alice, receive outcome ( x1 , x2 ) ∈ {0, 1}2 and send question Wy to Bob, obtaining an answer u ∈ {0, 1}n . Accept if and only if xy = u · a. Protocol 9: Clifford conjugation test Notation: CONJ - CLIFF ( X, Y, G, F, n) Input: Four question symbols X, Y, G, F and expected answer length n. R

Sample a, b ← {0, 1}n and let A be the unique element in { X, Y }n , that has X’s at the positions i ∈ [n] where ai = 0 and Y’s at the positions where ai = 1. Note its implicit dependence on a. Execute each of the following tests with equal probability. 1. Conjugation test: Execute each of the following tests with equal probability (a) CONJ (( G, a), ( F, a), (Y, a)). (b) CONJ (( X, a), (Y, a), ( G, a)). (c) CONJ (( X, b), ( A, b), ( G, a)). 2. Small/large answer consistency test: Execute SLC ({ A, X, Y, G, F }, n, U2n ). 3. Mixed-versus-pure basis test: Execute MBT ({ X, Y }, n, U2n ). Protocol 10: Clifford group test Notation: CLIFF - GROUP ( X, Y, Z, F, G, n) Input: Five large-answer question symbols, X, Y, Z, F and G and expected answer length n. Execute each of the following tests with equal probability. 1. Pauli (anti)commutation test: Execute CREL ({ X, Y, Z }, n). 2. Clifford (anti)commutation test: Execute CREL ({ Z, F, G }, n). 3. Pauli product relation test: Execute PREL ( X, Z, Y, n). 4. Clifford product relation test: Execute PREL ( G, Z, F, n). 5. Clifford conjugation test: Execute CONJ - CLIFF ( X, Y, G, F, n).

45

Protocol 11: Clifford test Notation: CLIFF ( X, Y, Z, F, G, n) Input: Observable symbols X, Y, Z, F, G and qubit count n. Let P0 , P1 be the brick-wall pairings on [n] (see Definition 4.7). Execute each of the following tests with equal probability. 1. Clifford group test: Execute CLIFF - GROUP ( X, Y, Z, F, G, n). R

2. Bell-basis test: Let W = ( X, Z ). Sample b, c ← {0, 1}. (a) Send Pb to Alice, receiving Bell-measurement outcomes v = (v0 , v1 ) ∈ {0, 1}| Pb | × {0, 1}| Pb | . (b) Send Wc to Bob, receiving outcome u ∈ {0, 1}n . (c) Accept iff for every ( j, k ) ∈ Pb : u j ⊕ uk = (vc )⌈ j/2⌉ , where ⌈ j/2⌉ indexes the pair ( j, k) in vc . R

3. Sign consistency test: Sample b, c ← {0, 1}. Let W = ( G, W1 ), where W1 ∈ { G, F }n is the string of alternating G and F symbols, starting with G. (a) Send Pb to Alice, receiving Bell-measurement outcomes v = (v0 , v1 ) ∈ {0, 1}| Pb | × {0, 1}| Pb | . (b) Send Wc to Bob, receiving outcome u ∈ {0, 1}n . (c) Reject if there is a pair ( j, k ) ∈ Pb with (v1 )⌈ j/2⌉ ̸= c and u j ⊕ uk = (v0 )⌈ j/2⌉ ⊕ (v1 )⌈ j/2⌉ . 4. Mixed-versus-pure basis test: Execute MBT ({ G, F }, n, µ), where µ is the point distribution on W1 ∈ { G, F }n , the string of alternating G and F symbols, starting with G. R

5. CHSH test: Let A := (Y, X ) and B := ( F, G ) and sample x, y ← {0, 1}. (a) Send A x to Alice and receive answer a ∈ {0, 1}n . (b) Send By to Bob and receive answer b ∈ {0, 1}n . (c) Accept if and only if a1 ⊕ b1 ≡ x · (1 − y)

(mod 2) .

6. Mixed-versus-pure basis test: Execute MBT ({ X, Y, Z, F, G }, n, U5n ). 4.1.1

Honest prover strategy

Most questions that a prover can receive in the Clifford test or any of its subtests are summarized in Table 5. A measurement in the basis indicated by W ∈ Σ means that the prover measures in σW , as introduced in Section 3.2. A large-answer question is a single symbol W ∈ Σ; a small-answer question is a pair (W, a) with W ∈ Σ and a binary string a ∈ {0, 1}n ; and a mixed-basis question is a length-n string W̃ ∈ Σn specifying one symbol per qubit. In addition, the conjugation test (protocol 4) internally introduces the auxiliary observable symbols C AB , XC , ZC and XR , which are either constant (XC and ZC ) or depend on the test inputs A, B and R. The honest prover responds to each question type as described below. By our consistency convention, Alice should perform the transpose of the specified operations. 46

Some questions, such as those internal to the anti-commutation test, are not listed here explicitly, since the magic-square test is standard in the self-testing literature, we refer the reader to [CHTW04] for more details. We do note that the prover also needs one additional EPR pair to pass the magic-square test (in addition to the control qubit required for the conjugation test). Question

Honest prover action

W∈Σ

Measure every qubit i ∈ [n] separately in the basis indicated by W and return the n-bit outcome x ∈ {0, 1}n .

(W, a) ∈ Σ × {0, 1}n

Simultaneously measure the qubits at positions i ∈ [n] where ai = 1 in the basis indicated by W and return the single-bit outcome x ∈ {0, 1}.

W̃ ∈ Σn

Measure each qubit i ∈ [n] separately in the basis specified by the symbol W̃i and return the n-bit outcome x ∈ {0, 1}n .

(W̃, a) ∈ Σn × {0, 1}n

Simultaneously measure the qubits at positions i ∈ [n] where ai = 1 in the basis indicated by W̃i and return the single-bit outcome x ∈ {0, 1}.

( Q1 , Q2 ) e.g. ( XC , ZC )

Jointly measure the two named small-answer observables and return the pair of bits ( x1 , x2 ) ∈ {0, 1}2 . Extended to three observables in the anti-commutation test.

P ∈ { P0 , P1 }

Perform a Bell-basis measurement on each qubit pair in P (indicating one of the two brick-wall pairings from Definition 4.7) and return the outcomes v ∈ {0, 1}| P| × {0, 1}| P| .

XR

Implement the observable XR as defined in Equation (4.4) and return the single-bit outcome x ∈ {0, 1}.

C AB

Implement the observable C AB as defined in Equation (4.4) and return the single-bit outcome x ∈ {0, 1}.

XC or ZC

Measure qubit n + 1 (the control) in the Hadamard or computational basis (depending on the question) and return the single-bit outcome x ∈ {0, 1}.

Table 5: Questions in the Clifford test and its subtests, with the honest prover action for each. Here Σ = { X, Y, Z, F, G }, n is the qubit count, and A, B, R are the conj. test inputs. Remark 4.1. We will use Q A to denote the set of all Alice questions in the Clifford test (protocol 11) and its subtests. Through the automatic consistency test, this includes every Bob question of a wrapped leaf; conversely, every Alice question of a wrapped leaf is also asked of Bob.

4.2

Compiled prover switching

Definition 4.1 (Question families). We define question families as the sets from which individual questions are sampled during protocol execution, for either player. The size of these sets can either depend on protocol parameters, such as the number of qubits or can be constant. All questions which get passed as input arguments to a game or which are fixed and not sampled from a set are also treated as individual question families. Definition 4.2 (Question distributions). A question distribution consists of a tuple ( Q, µ) where the first entry is a question family and the second is an efficiently sampleable probability distribution

47

over the elements of Q. The question distribution for single-element question families is the trivial point-distribution (U1 ). Definition 4.3 (ε-self-consistency). Any question distribution ( QW , µW ), over questions W ∈ QW , corresponding to PVMs, with efficient projectors {W v }v∈{0,1}n , which produce n-bit answers and satisfy the following expression h i E

∑ Tr W Dec(α) ψα

Enc(W )

W ∼ µW α

≥ 1 − O(ε)

is called ε-self-consistent. Here Dec(α) ∈ {0, 1}n and the sum over α goes over all valid encryptions of all n-bit strings. If µW is the uniform distribution we replace the expectation by EW ∈QW by our notational convention. Definition 4.4 (ε-cross-consistency). Any uniformly efficient family of PVMs {WV }V ∈QV , with projectors {WVv }v∈{0,1}n , which produce n-bit answers and satisfy the following expression E

h i Dec(α) Enc(V ) Tr W ψ ≥ 1 − O(ε) α ∑ V

V ∼ µV α

is called ε-cross-consistent with the question distribution ( QV , µV ). Here Dec(α) ∈ {0, 1}n and the sum over α goes over all valid encryptions of all n-bit strings. Lemma 4.1. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled consistency game CON ( T ), obtained from Protocol 1, it holds that the same strategy succeeds with probability 1 − 2ε in game T and that all question distributions in T are ε-self-consistent. Proof. The first claim of the lemma is immediate, since with probability 1/2 the verifier just plays game T and the averaged winning probability needs to be 1 − ε. For the second claim, winning the consistency game with probability 1 − ε requires h i Enc(W ) E E ∑ Tr W Dec(α) ψα ≥ 1 − 2ε, s∈{0,1} W ∼ PT,s α

where PT,0 = PT,A and PT,1 = PT,B are the Alice and Bob question marginals of T. Restricting to either value of s, each marginal therefore satisfies the same bound up to a constant factor. Each of these distributions can be decomposed into two separate distributions: one representing the probability of choosing a specific question family and the other representing the probability of choosing a specific question inside that family (according to the corresponding question distribution). Since there will always be only a constant number of question families within a game, on either side, we can disregard the expectation over this first distribution and conclude that for all question distributions ( QW , µW ) in game T it holds that h i Enc(W ) E ∑ Tr W Dec(α) ψα ≥ 1 − O ( ε ), W ∼ µW α

which completes the proof. Lemma 4.2. For any ε-self-consistent question distribution ( Q A , µ A ) over questions A ∈ Q A , corresponding to efficient PVMs with projectors { Av }v∈{0,1}m , and for every uniformly efficient family of PVMs { B A } A∈Q A , with projectors { BvA }v∈{0,1}n , which satisfies the following equation for any efficiently computable function f : {0, 1}m × {0, 1}n → {0, 1} and any efficiently sampleable set S ⊆ {0, 1}n (which can depend on A) h i Enc( A) E E ∑(−1) f (Dec(α),a) Tr B A ( a)ψα ≥ 1 − O ( δ ), A∼µ A a∈S α

48

where Dec(α) ∈ {0, 1}m , the following holds: for all q ∈ Q A there exists a cryptographically small function η (λ) such that 2

E

∑

E

A∼µ A a∈S

(−1)

f (v,a)

v

A − B A ( a)

v∈{0,1}m

≤ O ( ε + δ ) + η ( λ ). ψEnc(q)

Proof. We can rewrite the self-consistency of ( Q A , µ A ) as:

∑ ∥ ADec(α) − 1∥2 Enc(A) = 1 − E

E

A∼µ A α

h i Dec(α) Enc( A) Tr A ψ ≤ O ( ε ), α ∑

(4.1)

A∼µ A α

ψα

by the normalization property of the PVM (all projectors sum to the identity), we also know that h i a 2 a Enc( A) E ∥ A ∥ = E Tr A ψ ≤ O ( ε ). (4.2) α Enc ( A ) ∑ ∑ A∼µ A

a,α Dec(α)̸= a

A∼µ A

ψα

a,α Dec(α)̸= a

Then, A f ( a)

E

z

E

A∼µ A a∈S

∑

2 }| { f (v,a) v A − B A ( a) (−1)

v∈{0,1}m

ψEnc( A)

We can separate the term that aligns with Dec(α) from the remaining sum over v: 2

E ∑ (−1) f (Dec(α),a) ADec(α) − B A ( a) +

= E

A∼µ A a∈S α

∑

(−1) f (v,a) Av

v∈{0,1}m v̸=Dec(α)

Enc( A)

ψα

Applying the triangle inequality for the squared state-dependent norm (Lemma 3.2, point (v)):   2

 2  ≤ 2 E E ∑  (−1) f (Dec(α),a) ADec(α) − B A ( a) Enc( A) + A∼µ A a∈S α  ψα

∑

(−1)

f (v,a)

v∈{0,1}m v̸=Dec(α)

A

   

v Enc( A)

ψα

Applying a telescopic sum, the same triangle inequality, left unitary invariance and using the fact that { Av } is a PVM:

≤2 E

E ∑ 2

A∼µ A a∈S α

+

∑



ADec(α) − 1

2

+ (−1) f (Dec(α),a) 1 − B A ( a) Enc( A)

ψα

2

 Enc( A)

ψα

!

∥ Av ∥2ψEnc( A) α m

v∈{0,1} v̸=Dec(α)

≤ O ( ε + δ ), where the last line follows from (4.1), (4.2) and the lemma hypothesis (rewritten as a statedependent norm). Lastly, the argument of the state-dependent norm in the lemma conclusion is A f ( a) − B A ( a), where { A f ( a)} A,a is a uniformly efficient family of unitaries parameterized by A ∈ Q A and a ∈ {0, 1}n , since the prover projectors are efficiently measurable given the question and we can reuse the argument of Lemma 3.5, now with an efficient function in the 49

exponent. Similarly, { B A ( a)} A,a is a uniformly efficient family of unitaries (parameterized by A and a), by Lemma 3.5. Thus the argument of the norm is a uniformly efficient family of LCUs (which is also Hermitian) and we can apply Corollary 3.1, where the sampled parameter is the tuple ( a, A), with a uniformly from S, A ∼ µ A , and z = A deterministically for D1 . For D2 the distribution over the sampled parameter is identical (recall identical marginal constraint) and z = q deterministically. The point distribution on any fixed q ∈ Q A is efficiently sampleable, so the corollary yields, for every such q, a single cryptographically small function η (λ) such that 2

E

E

A∼µ A a∈S

∑

(−1)

f (v,a)

v

A − B A ( a)

v∈{0,1}m

≤ O ( ε + δ ) + η ( λ ), ψEnc(q)

which completes the proof. Corollary 4.1. For any ε-self-consistent question distribution ( Q A , µ A ) over questions A, corresponding to PVMs, with efficient projectors { A a } a∈{0,1}n and any uniformly efficient family of PVMs { B A } A∈Q A , with projectors { BbA }b∈{0,1}n , which is δ-cross-consistent with ( Q A , µ A ), for all q ∈ Q A there exists a cryptographically small function η (λ) such that E

A∼µ A

∑

v∈{0,1}n

∥ Av − BvA ∥2ψEnc(q) = E

A∼µ A

E

a∈{0,1}n

∥ A( a) − B A ( a)∥2ψEnc(q) ≤ O(ε + δ) + η (λ).

Proof. If we set S = {0, 1}n , m = n and f ( a, b) = a · b in Lemma 4.2, the lemma hypothesis is equivalent to the displayed δ-cross-consistency requirement, since h i Enc( A) E E ∑(−1)Dec(α)·a Tr B A ( a)ψα A∼µ A a∈{0,1}n α

δv,Dec(α)

z

}| { h i Enc( A) (−1)(Dec(α)+v)·a Tr BvA ψα

= E

∑ ∑

= E

i h Dec(α) Enc( A) ψ Tr B α ∑ A

E

A∼µ A α a∈{0,1}n v∈{0,1}n

A∼µ A α

≥ 1 − O ( δ ). The hypothesis is thus satisfied by the cross-consistency and the conclusion holds. We again provide an equivalent form for the conclusion, which follows from Parseval’s identity (Corollary A.1), since Av − BvA is the Fourier transform of A( a) − B A ( a). Lemma 4.3 (Restatement of [MNZ24] Lemma 6.1). For any ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n , it holds that for all a ∈ {0, 1}n , 2

∑ B(a) − (−1)a·Dec(α) 1 ψ ( ) ≤ O(ε). B∼µ E

B

Enc B α

α

Proof. The condition that ( Q B , µ B ) is ε-self-consistent means that

∑ Tr[ BDec(α) ψα B∼µ E

B

∑ ∑ B∼µ w α

] ≥ 1 − O(ε)

Enc( B)

] ≤ O ( ε ),

α

E

B

Enc( B)

Tr[ Bw ψα

w̸=Dec(α)

50

where the second expression follows immediately from the fact that a PVM is normalized. Thus, for all a ∈ {0, 1}n

∑ ∥ B(a) − (−1)a·Dec(α) 1∥2ψ ( )

E

Enc B α

B∼µ B α

h

∑(−1)a·Dec(α) Tr B(a)ψα B∼µ

= 2−2 E

B

Enc( B)

i

α

≥0

h

∑ Tr BDec(α) ψα B∼µ

i

h

i

= 2−2 E

B

Enc( B)

∑ Tr BDec(α) ψα B∼µ

≤ 2−2 E

B

∑ ∑

−2 E

B∼µ B α w̸=Dec(α)

α

Enc( B)

h i Enc( B) Tr Bw ψα

∑ ∑ B∼µ

+2 E

B

α

z h }| i{ a·(w+Dec(α)) w Enc( B) Tr B ψα (−1)

α w̸=Dec(α)

≤ O ( ε ).

Lemma 4.4 (Restatement [MNZ24] Lemma 6.2). For any ε-self-consistent question distribution (QW , µW ) over questions W ∈ QW , which correspond to efficient PVMs {W v }v∈{0,1}n , for all a ∈ {0, 1}n it holds that E

∑ W (a)ψα

Enc(W )

W ∼ µW α

Enc(W )

− ψα

W ( a)

1

≤ O(ε1/2 ),

Proof. Consider the quantity we want to bound E

∑ W (a)ψα

≤



Enc(W )

W ∼ µW α

∑

E

Enc(W )

− ψα

W ( a)

1 Enc(W )

(W ( a) − (−1) a·Dec(α) 1)ψα

W ∼ µW α

Enc(W )

1

+ ψα

((−1)a·Dec(α) − W ( a)) Enc(W )

Since the Schatten-1 norm is invariant under Hermitian adjoint and both ψα Hermitian:

∑ (W (a) − (−1)a·Dec(α) 1)ψα W ∼µ

 1

and W ( a) are

Enc(W )

=2 E

W

1

α

Applying [MNZ24, Lemma 2.10], where the sums and the expectation are combined into one large sum: r 2 ≤2 E ∑ W ( a) − (−1) a·Dec(α) 1 ψEnc(W )

≤ O(ε

W ∼ µW α 1/2

α

),

the last line follows from Lemma 4.3 and the fact that the question distribution ( QW , µW ) is assumed to be ε-self-consistent. Lemma 4.5 (Compiled prover switching). For any efficient LCU A B ∈ L(H), with ∥ A B ∥ ≤ O(1) (for all B ∈ Q B ), and ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n , and for all q ∈ Q A and all a ∈ {0, 1}n there exists a cryptographically small function η (λ) such that 2

E ∥ A B B( a)∥ψEnc(q) ≤ 2 E ∥ A B ∥2ψEnc(q) + O(ε) + η (λ).

B∼µ B

B∼µ B

51

Proof. Because of the ε-self-consistency of ( Q B , µ B ), we can immediately apply Lemma 4.3, yielding (for all a ∈ {0, 1}n ) 2

∑ B(a) − (−1)a·Dec(α) 1 ψ ( ) ≤ O(ε). B∼µ E

B

Enc B α

α

Enc( B)

By the above, we can interpret ψα as an approximate eigenstate of B( a). Since B( a) is an observable, applying it on that state will only yield a factor of either −1 or 1, which is irrelevant if we just want to make use of an upper-bound on the norm of A B . This is the intuition behind the fact that we can completely disregard self-consistent operators on the right side of the state-dependent norm. By Corollary 3.1, where D1 is the point distribution on q and D2 = µb and the fact that A B B( a) is again an efficient LCU (since B( a) is an efficient observable): E ∥ A B B( a)∥2ψEnc(q) ≈η (λ) E ∥ A B B( a)∥2ψEnc(B) ,

B∼µ B

B∼µ B

so we can focus on bounding the latter quantity. To do so, we calculate: E ∥ A B B( a)∥2ψEnc(B)

B∼µ B

= E

∑ ∥ AB B(a)∥2ψ ( )

= E

∑ ∥ AB B(a) − (−1)a·Dec(α) AB + (−1)a·Dec(α) AB ∥2ψ ( )

Enc B α

B∼µ B α

Enc B α

B∼µ B α



∑ ∥(−1)

≤2 E

B∼µ B α

a·Dec(α)

A B ∥2 Enc(B) + ∥ A B ( B( a) − (−1) a·Dec(α) 1)∥2 Enc(B) ψα ψα

= 2 E ∥ A B ∥2ψEnc(B) + 2 E B∼µ B



∑ ∥ AB ( B(a) − (−1)a·Dec(α) 1)∥2ψ ( ) Enc B α

B∼µ B α

≤ 2 E ∥ A B ∥2ψEnc(B) + 2 E ∥ A B ∥2 ∑ ∥ B( a) − (−1) a·Dec(α) 1∥2 Enc(B) B∼µ B

B∼µ B

≤ 2 E ∥ A B ∥2ψEnc(B) + 2O(1) E B∼µ B

ψα

α

∑ ∥ B(a) − (−1)a·Dec(α) 1∥2ψ ( ) Enc B α

B∼µ B α

≤ 2 E ∥ A B ∥2ψEnc(B) + O(ε). B∼µ B

We can then use Corollary 3.1 again (and the fact that A B is an efficient LCU), which completes the proof. Corollary 4.2. For any efficient LCU A ∈ L(H) with ∥ A∥ ≤ O(1) and ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n , for all q ∈ Q A there exists a cryptographically small function η (λ) such that

∑

E

B∼µ B

v∈{0,1}n

∥ ABv ∥2ψEnc(q) ≤ 2∥ A∥2ψEnc(q) + O(ε) + η (λ).

Proof. The same argument as in Lemma 4.5, with the additional parameter a drawn uniformly from {0, 1}n included in the sampled index of Corollary 3.1, yields a single cryptographically small function η (λ) (for this q) such that E

E

B∼µ B a∈{0,1}n

∥ AB( a)∥2ψEnc(q) ≤ 2∥ A∥2ψEnc(q) + ∥ A∥2 O(ε) + η (λ).

c ( a), then gives Parseval’s identity (Corollary A.1), since ABv = AB E

B∼µ B

∑

v∈{0,1}n

∥ ABv ∥2ψEnc(q) = E

E

B∼µ B a∈{0,1}n

∥ AB( a)∥2ψEnc(q)

≤ 2∥ A∥2ψEnc(q) + ∥ A∥2 O(ε) + η (λ).

52

Corollary 4.3. For any ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n and efficient LCUs A, C ∈ L(H), with A ≈δ C and ∥ A − C ∥ ≤ O(1). For all a ∈ {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that AB( a) ≈δ+ε+η (λ) CB( a), on ψEnc(q) and under implicit expectation over B ∼ µ B . Proof. E ∥( A − C ) B( a)∥2ψEnc(q) ≤ 2∥ A − C ∥2ψEnc(q) + O(ε) + η (λ)

B∼µ B

≤ O(δ + ε + η (λ)), where the first inequality follows from Lemma 4.5 since A − C is again an efficient LCU and the fact that B( a) is constructed from an efficient PVM, the last inequality uses the hypothesis. Lemma 4.6. For any efficient LCU A ∈ L(H) with ∥ A∥ ≤ O(1) and ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n , for all q ∈ Q A and all a ∈ {0, 1}n there exists a cryptographically small function η (λ) such that

∥ A∥2ψEnc(q) ≤ 2 E ∥ AB( a)∥2ψEnc(q) + O(ε) + η (λ). B∼µ B

Proof. Because of the ε-self-consistency of ( Q B , µ B ), we can immediately apply Lemma 4.3, yielding (for all a ∈ {0, 1}n ) 2

∑ B(a) − (−1)a·Dec(α) 1 ψ ( ) ≤ O(ε). B∼µ E

B

Enc B α

α

By Corollary 3.1 and the fact that A is an efficient LCU:

∥ A∥2ψEnc(q) ≈η (λ) E ∥ A∥2ψEnc(B) , B∼µ B

so we can focus on bounding the latter quantity. To do so, we calculate: E ∥ A∥2ψEnc(B) = E

B∼µ B

∑ ∥ A∥2ψ ( )

B∼µ B α

Enc B α

  2 a·Dec(α) AB ( a ) − A B ( a ) − (− 1 ) 1 ∑ Enc( B) B∼µ B α ψα   2 a·Dec(α) 2 ≤ 2 E ∑ ∥ AB( a)∥ Enc(B) + ∥ A( B( a) − (−1) 1)∥ Enc(B)

= E

B∼µ B α

ψα

ψα

≤ 2 E ∥ AB( a)∥2ψEnc(B) + 2∥ A∥2 E B∼µ B

∑ ∥ B(a) − (−1)a·Dec(α) 1∥2ψ ( )

B∼µ B α

Enc B α

≤ 2 E ∥ AB( a)∥2ψEnc(B) + O(ε). B∼µ B

We can then use Corollary 3.1 (state switching) again since the product of an efficient LCU and an efficient observable is again an efficient LCU, which completes the proof. Remark 4.2. Lemma 4.5 and Lemma 4.6 allow us to both introduce and remove observables corresponding to ε-self-consistent question distributions on the right of the state-dependent norm. The bound in both directions is quite loose, but this gives the best ε dependence. For a tighter two-sided bound, refer to the following lemma, which has a square-root dependence on ε. 53

Lemma 4.7. Let { Mx , 1 − Mx } x be a uniformly efficient family of two-outcome POVMs indexed by a classical parameter x, let ν be an efficiently sampleable distribution over pairs ( x, q) with q ∈ Q A , and let ( Q B , µ B ) be an ε-self-consistent question distribution over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n . Then for all a ∈ {0, 1}n there exists a cryptographically small function η (λ) such that  h i h i E

E

( x,q)∼ν B∼µ B

Tr B( a) Mx B( a) ψEnc(q) − Tr Mx ψEnc(q)

≤ Cε1/2 + 2η (λ),

for some constant C ∈ N. Proof. Expanding through a telescoping sum and using linearity of the trace and the expectation,  h i h i E E Tr B( a) Mx B( a) ψEnc(q) − Tr Mx ψEnc(q) ( x,q)∼ν B∼µ B h  i = E E Tr B( a) Mx B( a) ψEnc(q) − ψEnc( B) ( x,q)∼ν B∼µ B  h i h i + E E Tr B( a) Mx B( a) ψEnc( B) − Tr Mx ψEnc( B) ( x,q)∼ν B∼µ B h  i + E E Tr Mx ψEnc( B) − ψEnc(q) . ( x,q)∼ν B∼µ B

For the middle term, the triangle inequality, the cyclicity of the trace, the tracial Hölder inequality [Bau11, Theorem 2], ∥ Mx B( a)∥ ≤ 1 and Lemma 4.4 give  h i h i E Tr B( a) Mx B( a) ψEnc( B) − Tr Mx ψEnc( B) ≤ E B( a)ψEnc( B) − ψEnc( B) B( a) B∼µ B

B∼µ B

1

≤ Cε1/2 , pointwise in x and a, hence also after taking E(x,q)∼ν . For the first and third terms, both { Mx } and { B( a) Mx B( a)}(x,B,a) are uniformly efficient two-outcome POVM families (conjugating an efficient POVM element by the efficient unitary B( a) from Lemma 3.5 preserves uniform efficiency), so two applications of Lemma 3.3—with D sampling ( x, q) ∼ ν and B ∼ µ B , and plaintext pair (z0 , z1 ) = (q, B)—bound their absolute values by η (λ) each. Combining the three bounds completes the proof. Lemma 4.8. For any efficient LCU A ∈ L(H) and ε-self-consistent question distribution ( Q B , µ B ) over questions B, corresponding to efficient PVMs { Bv }v∈{0,1}n , for all a ∈ {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that 2

E ∥ AB( a)∥ψEnc(q) ≈C∥ A∥2 ε1/2 +2η (λ) ∥ A∥2ψEnc(q) ,

B∼µ B

with some constant C ∈ N. Proof. By Definition 3.2, the cyclicity of the trace, and the fact that B( a) is an observable: h i E ∥ AB( a)∥2ψEnc(B) − ∥ A∥2ψEnc(B) ≤ E Tr B( a) A† A( B( a)ψEnc( B) − ψEnc( B) B( a)) B∼µ B

B∼µ B

now we apply the tracial Hölder’s inequality [Bau11, Theorem 2]:

≤ E ∥ A† AB( a)∥ · B( a)ψEnc( B) − ψEnc( B) B( a) B∼µ B

Using that B( a) is an observable and Lemma A.5:

≤ E ∥ A∥2 · ∥ B( a)ψEnc( B) − ψEnc( B) B( a)∥1 B∼µ B

≤ ∥ A∥2 O(ε1/2 ), 54

1

the last line uses the fact that ( Q B , µ B ) is a ε-self-consistent question distribution and Lemma 4.4 (with a triangle inequality and the definition of ψEnc( B) ). This tells us that for all a ∈ {0, 1}n E ∥ AB( a)∥2ψEnc(B) ≈C∥ A∥2 ε1/2 E ∥ A∥2ψEnc(B) ,

B∼µ B

B∼µ B

(4.3)

for some constant C ∈ N. This bound is stated for the state obtained on question B; we need the same estimate for an arbitrary initial Alice question. Since A is an efficient LCU and B( a) is an efficient observable, their product is an efficient LCU and we can use Corollary 3.1 to switch out the state in the state-dependent norm E ∥ AB( a)∥2ψEnc(q) ≈η (λ) E ∥ AB( a)∥2ψEnc(B)

B∼µ B

B∼µ B

≈C∥ A∥2 ε1/2 E ∥ A∥2ψEnc(B) B∼µ B

≈η (λ) ∥ A∥2ψEnc(q) , where the middle line uses (4.3) and the last line uses Corollary 3.1 again, combined with the fact that the operators are efficient.

4.3

Soundness

4.3.1

Conjugation relation

One way in which the extended Pauli group differs from the Heisenberg–Weyl group is in the group relations that define it. The F and G operators lie in the XY-plane and are related to the latter by a conjugation relation. To apply the GH theorem, we need to certify that the prover’s operators approximately satisfy all group relations, which means that we need a self-test for conjugation relations. Such a self-test is defined in protocol 4 and proven sound in Lemma 4.9. The idea (which was first proposed in [CGJV24]) is the following: we need to test that three binary observables A, B, R approximately satisfy the following relations RA ≈ε BR

and

AR ≈ε RB.

To this end, we introduce two new binary observables C AB and XR , which are certified to have the following form, in the basis spanned by an additional control qubit (defined by anti-commuting observables ZC and XC ):     A 0 0 R C AB = , and XR = . (4.4) 0 B R 0 It remains to show that C AB and XR approximately anti-commute, which yields the desired conjugation relations. An anti-commutation test is standard in the literature, so the main challenge is to ensure the correct form for the observables C AB and XR . Lemma 4.9. Let P∗ be any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled conjugation game CONJ ( A, B, R), obtained from Protocol 4. Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that on ψEnc(q) RA ≈ε+η (λ) BR

and

AR ≈ε+η (λ) RB.

Proof. The operators ZC and XC act exclusively as reference or “control” operators: they do not appear in any other test and are solely introduced to describe the basis in which C AB is block-diagonal and XR is anti-diagonal. By our convention on automatic consistency tests (see the beginning of Section 4.1), the leaf game CONJ ( A, B, R) is executed wrapped in the consistency test CON (·) from protocol 1. This 55

certifies that every question distribution which appears in CONJ ( A, B, R) is ε-self-consistent, by Lemma 4.1. ij

We start by analyzing Item 2 of protocol 4, to characterize the structure of C AB . Let {WAZ }i,j∈{0,1} ij

be the 4-outcome projector corresponding to the Bob question ( A, ZC ) and similarly for {WBZ }i,j∈{0,1} and ( B, ZC ). Introduce the following compact notation: WP := WP0 − WP1 ,

iz WPi := ∑ WPZ , z

WZ| P := WZ0 | P − WZ1 | P

and

WZi | P := ∑ WPZ , pi

p

for P ∈ { A, B}. Then a success probability of 1 − O(ε) in the cross-consistency test (Alice was asked A or B and Bob was asked (A, ZC ) or (B, ZC )), implies that: h i Dec(α) Enc( P) Tr W ψ ≥ 1 − O ( ε ), α ∑ P α h i (4.5) Dec(α) Enc( ZC ) Tr W ψ ≥ 1 − O ( ε ) , α ∑ Z|P α

with P ∈ { A, B} and by the protocol specification we can assume that α is the encryption of a single bit. Equation (4.5) tells us that WP is ε-cross-consistent with P and WZ| P is ε-crossconsistent with ({ ZC }, U1 ), for P ∈ { A, B}. Recall that the automatic self-consistency check guarantees ε-self-consistency of ({ A}, U1 ), ({ B}, U1 ) and ({ ZC }, U1 ). With that we can invoke Corollary 4.1 (both times the argument of the norm is an efficient LCU), to conclude that for P ∈ { A, B} and all q ∈ Q A we have

and

1 ∥WP − P∥2ψEnc(q) = ∑ ∥WPa − P a ∥2ψEnc(q) ≤ O(ε) + η (λ), 2 a∈{0,1}

(4.6)

1 2 WZ| P − ZC ψEnc(q) = ∑ ∥WZa | P − ZCa ∥2ψEnc(q) ≤ O(ε) + η (λ). 2 a∈{0,1}

(4.7)

az = W a W z z a We have WAZ A Z | A = WZ | A WA , which we use to show that A and ZC approximately commute.

AZC ≈ε+η (λ) WA ZC

≈ε+η (λ) WA WZ| A = WZ| A WA ≈ε+η (λ) WZ| A A ≈ε+η (λ) ZC A, where we used (4.6), (4.7), the ε-self-consistency of ({ A}, U1 ), the fact that all products are efficient unitaries and ({ ZC }, U1 ) and Lemma 4.5. Thus

[ A, ZC ] ≈ε+η (λ) 0. bz , we find that Repeating the same steps for WBZ

[ B, ZC ] ≈ε+η (λ) 0. Both expressions hold on the state ψEnc(q) for all q ∈ Q A . Success in the characterization tests, where Alice is asked to measure C AB , guarantees h  i Dec(α)0 Enc(C AB ) 1 Tr W + W ψ ≥ 1 − O ( ε ), α ∑ Z| A AZ α

56

and

∑ Tr

h

Dec(α)1

WBZ

 i Enc(C AB ) + WZ0 | B ψα ≥ 1 − O ( ε ),

α

ij

ij

or equivalently, by the normalization of the {WAZ } and {WBZ } PVMs and the factorization into marginals

∑

Dec(α) 0 WA WZ| A

∑

WB

α

Dec(α)

2 Enc(C AB )

= ∑ Tr





Enc(C AB )

= ∑ Tr

ψα 2

WZ1 | B

α

ψα

Dec(α) 0 WZ| A WA



Enc(C AB ) ψα



≤ O ( ε ),

α

Dec(α)

WB

  Enc(C AB ) ≤ O ( ε ), WZ1 | B ψα

α

here the equalities follow from the fact that the marginal projectors commute. An application of a telescoping sum and the triangle inequality, using Eq. (4.6) and Eq. (4.7) (already on ψEnc(CAB ) , since those bounds hold for all q ∈ Q A ) and the ε-self-consistency of ({ ZC }, U1 ) with Corollary 4.2, gives 2

∑ ADec(α) ZC0 ψ (

Enc C AB ) α

α

≤ O(ε) + η (λ)

2

∑ BDec(α) ZC1 ψ (

and

Enc C AB ) α

α

≤ O ( ε ) + η ( λ ).

By A0 + A1 = B0 + B1 = 1 it immediately follows that 2

∑ (1 − ADec(α) )ZC0 ψ (

Enc C AB ) α

α

2

∑ (1 − BDec(α) )ZC1 ψ (

Enc C AB ) α

α

≤ O ( ε ) + η ( λ ), ≤ O ( ε ) + η ( λ ).

These two observations are sufficient to conclude that 2

∑ AZC0 − (−1)Dec(α) ZC0 ψ (

Enc C AB ) α

α

and

2

∑ BZC1 − (−1)Dec(α) ZC1 ψ (

Enc C AB ) α

α

≤ O ( ε ) + η ( λ ),

(4.8)

≤ O ( ε ) + η ( λ ).

(4.9)

Combining Eq. (4.8) and Eq. (4.9) with the guarantee from Lemma 4.3 (since ({C AB }, U1 ) is ε-self-consistent) and an application of the triangle inequality gives AZC0 + BZC1 − C AB

2 ψEnc(C AB )

≤ O ( ε ) + η ( λ ).

(4.10)

Now we will analyze Item 3 of protocol 4, to characterize the structure of XR . Let the 4-outcome ij PVM, executed when Bob is asked to measure ( R, XC ), be denoted by {WRX }i,j∈{0,1} . Define WRi := ∑ WRX , ij

WR := WR0 − WR1 ,

j

WX := ∑ WRX j

ij

and

WX := WX0 − WX1 .

i

A success probability of 1 − O(ε) in the cross-consistency test (Alice measures R or XC ) implies h i Dec(α) Enc( R) ≥ 1 − O(ε) ∑ Tr WR ψα α h i Dec(α) Enc( XC ) Tr W ψ ≥ 1 − O(ε) α ∑ X α

57

The first equation tells us that {WRi }i is ε-cross-consistent with ({ R}, U1 ) and since the latter is ε-self-consistent, we can apply Corollary 4.1 to conclude that 2 1 ∥WR − R∥2ψEnc(q) = ∑ WRi − Ri Enc(q) ≤ O(ε) + η (λ). 2 ψ i ∈{0,1}

(4.11)

Analogously, from the second equation, ε-self-consistency of ({ XC }, U1 ) and Corollary 4.1 we conclude that 2 1 ∥WX − XC ∥2ψEnc(q) = ∑ WXi − XCi Enc(q) ≤ O(ε) + η (λ). 2 ψ i ∈{0,1} ij

j

(4.12)

j

Again we can use this and the observation that WRX = WRi WX = WX WRi to conclude that XC and R approximately commute XC R ≈ε+η (λ) WX R

≈ε+η (λ) WX WR = WR WX ≈ε+η (λ) WR XC ≈ε+η (λ) RXC , where we used (4.11), (4.12), the ε-self-consistency of R and XC and Corollary 4.3. Success in the characterization test, where Alice is asked to measure XR , implies Dec(α)

=WX

∑ Tr

"z 

# }|R { Enc( XR ) (1−Dec(α))1 Dec(α)0 ≥ 1 − O ( ε ). ψα + WRX WRX

α

Similarly, since {WXi R }i forms a PVM and ({ XR }, U1 ) is ε-self-consistent, we can conclude by Corollary 4.1 that

∑

WXi R − XRi

i ∈{0,1}

2 ψEnc(q)

≤ O ( ε ) + η ( λ ),

inserting the definition of WXi R , we get

∑

(1− i )

WRi WX0 + WR

WX1 − XRi

i ∈{0,1}

2 ψEnc(q)

≤ O ( ε ) + η ( λ ),

skipping some steps where we use (4.11), (4.12) and the ε-self-consistency of ({ XC }, U1 ), we obtain X̃ i

1 2 X̃R − XR ψEnc(q) = ∑ 2 i ∈{0,1}

z }|R { 2 i 0 (1− i ) 1 R XC + R XC − XRi Enc(q) ≤ O(ε + η (λ)), ψ

where XR = XR0 − XR1 , X̃R := X̃R0 − X̃R1 = RXC , and the left-hand side was obtained through Parseval’s identity (Corollary A.1). Since X̃R = RXC we can immediately conclude that for all q ∈ Q A , on ψEnc(q) we have XR ≈ε+η (λ) RXC . It remains to show the conjugation relation between A and B. Success with probability 1 − O(ε) in Item 1 of the protocol certifies, by Lemma A.1, that

[ XR , C AB ] ≈ε+η (λ) 0, [ A, XC ] ≈ε+η (λ) 0, [ B, XC ] ≈ε+η (λ) 0, [ R, ZC ] ≈ε+η (λ) 0, 58

and by Lemma A.2

{ XC , ZC } ≈ε+η (λ) 0, note that all of bounds above hold for distinct cryptographically small functions, but since there is only a constant number of them, we take the maximum and denote it by a single symbol. We can use the (anti)commutator relations, together with our characterizations of XR and C AB (see Eq. (4.10)) to obtain the desired conjugation relations. Concretely, expanding the commutator with XR ≈ RXC and C AB ≈ AZC0 + BZC1 , commuting XC past A and B, ZC past R, and using the exact relation XC ZC0 = ZC1 XC (which follows from { XC , ZC } = 0; in the approximate setting the anti-commutation bound is used instead), we obtain   [ XR , C AB ] ≈ ZC0 ( RB − AR) + ZC1 ( RA − BR) XC , and removing the unitary XC on the right via Lemma 4.5 (using the ε-self-consistency of ({ XC }, U1 )) yields ZC0 ( RB − AR) + ZC1 ( RA − BR)

2

≤ O(ε + η (λ)),

ψEnc(q)

since { ZCi }i is a PVM (we specifically need orthogonality and idempotence) this is equivalent to 2

ZC0 ( RB − AR) ψEnc(q) + ZC1 ( RA − BR)

2 ψEnc(q)

≤ O(ε + η (λ)),

(4.13)

since both terms are lower-bounded by 0, this gives us a separate upper bound for each of them. The two bounded blocks pair ZC0 with RB − AR and ZC1 with RA − BR; to bound the full relations we also need the two opposite pairings, which follow by inserting a factor of R. Now 2

2

ZC0 ( RA − BR) ψEnc(q) = RZC0 ( RA − BR) ψEnc(q) where the equality is exact, since R is a binary observable and hence R2 = 1. Using the fact that ZC and R approximately commute (as certified by Item 1 of the protocol), the ε-self-consistency of ({ A}, U1 ), ({ B}, U1 ) and ({ R}, U1 ), combined with repeated applications of Lemma 4.5: 2

≤ ZC0 R( RA − BR) ψEnc(q) + O(ε + η (λ)) 2

= ZC0 ( RB − AR) R ψEnc(q) + O(ε + η (λ)) where we used R( RA − BR) = A − RBR = −( RB − AR) R. Again using ε-self-consistency of ({ R}, U1 ) and Lemma 4.5: 2

≤ 2 ZC0 ( RB − AR) ψEnc(q) + O(ε + η (λ)) ≤ O(ε + η (λ)), the last line follows from (4.13). This finally allows us to bound the desired quantity, by using the above and (4.13)

∥ RA − BR∥2ψEnc(q) = ( ZC0 + ZC1 )( RA − BR) 2

2 ψEnc(q)

= ZC0 ( RA − BR) ψEnc(q) + ZC1 ( RA − BR) ≤ O(ε + η (λ)).

59

2 ψEnc(q)

To prove the second conjugation relation, one repeats the same R-insertion argument on the ZC1 block to find 2 ZC1 ( AR − RB) Enc(q) ≤ O(ε + η (λ)), ψ

which combines with ZC0 ( AR − RB)

2 = ψEnc(q)

2

ZC0 ( RB − AR) ψEnc(q) ≤ O(ε + η (λ)) from (4.13)

to give ∥ AR − RB∥2ψEnc(q) ≤ O(ε + η (λ)). This completes the proof.

4.3.2

Mixed-versus-pure basis

In much of the initial certification of the extended Pauli group, including the application of GH, we will be restricting the prover to applying pure-basis measurements, i.e. measuring all qubits in the same basis. Not only does this simplify the analysis, it allows us to add on the certification of mixed-basis measurements later on, in a modular way. This is achieved through the mixed-versus-pure basis test, defined in protocol 5 and proven sound in Lemma 4.10. The idea is the following: the verifier sends a pure-basis question to Alice and a mixed-basis question to Bob; it then accepts if and only if the answers are equal on the subset of qubits where the bases align. This simple consistency test allows us to generalize our pure-basis results to the mixed-basis case. The verifier can also choose which distribution of mixed-basis questions to use, which provides an easy route to certifying different mixed-basis distributions through a simple protocol modification—potentially useful for downstream applications. Lemma 4.10. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled mixed-versus-pure basis game MBT (Σ, n, µ) (where Σ is a constant size alphabet), obtained from Protocol 5, the following holds. For all q ∈ Q A , all W ∈ Σ and all distributions µ′ over {0, 1}n , there exists a cryptographically small function η (λ) such that E

E ′ W ( a( J ) ) − W̃ ( a( J ) )

W̃ ∼µ a∼µ

2 ψEnc(q)

≤ O ( ε ) + η ( λ ),

where J = { j ∈ [n] : W̃j = W }. Proof. Let k := | J |. We will use the following shorthand notation in this proof d := Dec(α)| J (the restriction of the decryption of α to the indices included in J), and Sd := { a ∈ {0, 1}n : a| J = d}, these notations will be convenient but they leave a lot of indirect dependencies implicit. For example, Sd depends on the set J, which in turn depends on both W and W̃. Winning in MBT (Σ, n, µ), means that for all W ∈ Σ (as long as the size of Σ is constant) h i Enc(W ) E ∑ ∑ Tr W̃ a ψα = E N (W̃, W ) ≥ 1 − O(ε), W̃ ∼µ α a∈S d

W̃ ∼µ

where we introduced h i h i Enc(W ) Enc(W ) N (W̃, W ) := ∑ ∑ Tr W̃ a ψα = ∑ Tr Pd ψα , α a ∈ Sd

α

for the left-hand side we pulled the sum over a ∈ Sd into the trace and defined P x := ∑ W̃ a , a∈Sx

60

(4.14)

for x ∈ {0, 1}k . Clearly, { P x } x∈{0,1}k again forms a PVM, since x 2

(P ) =

∑ W̃

! a

a∈Sx

∑ W̃

! b

= ∑ W̃ a = P x

∀ x ∈ {0, 1}k ,

a∈Sx

b∈Sx

which follows from the fact that {W̃ a } a is a PVM. Moreover,  !

∑ W̃ a

P x Py =

a∈Sx

 ∑ W̃ b  = 0

∀ x ̸= y ∈ {0, 1}k ,

b ∈ Sy

which follows from the fact that Sx ∩ Sy = ∅ for x ̸= y and the orthogonality of {W̃ a } a . Third, we have ∑ Px = ∑ ∑ W̃ a = 1, x ∈{0,1}k a∈Sx

x ∈{0,1}k

since x∈{0,1}k Sx = {0, 1}n and {W̃ a } a is normalized. Lastly, { P x } x is an efficient PVM, since {W̃ a } a is, J can be efficiently computed and the sum of these projectors can coherently be prepared. At this point it is important to note that P x depends on W and W̃, so we are assuming both to be fixed for now, i.e. P x will only appear inside a specific N (W̃, W ). S

By the convexity of O(ε), we can use Eq. (4.14) to obtain the following general pointwise lower bound for a fixed W and for all W̃ ∈ Σn h i d Enc(W ) Tr P ψ = N (W̃, W ) ≥ 1 − ε W̃ , α ∑ α

where ε W̃ ≥ 0 and EW̃ ε W̃ = O(ε). Define

∑ (−1)a·x Px ,

P( a) =

x ∈{0,1}k

if we then also choose f (Dec(α), a) := Dec(α)| J · a, we can equivalently write h

∑(−1) f (Dec(α),a) Tr P(a)ψα a∈{0,1} E

k

Enc(W )

i

α

h i Enc(W ) = ∑ Tr P Dec(α)| J ψα ≥ 1 − ε W̃ , α

this is now in the form of the hypothesis of Lemma 4.2 (since we also know that (Σ, U|Σ| ) is ε-self-consistent by the automatic consistency check, as this is the Alice-marginal of the leaf), S = {0, 1}k , the m in the lemma is equal to n here and the n in the lemma is equal to k here. Applying that lemma (without the final state switch) yields, for each W̃, 2

∑ (−1)

E

a∈{0,1}k

v| J · a

v

W − P( a)

v∈{0,1}n

≤ O(ε W̃ + ε). ψEnc(W )

Averaging over W̃ ∼ µ and using EW̃ ε W̃ = O(ε), 2

E

E

W̃ ∼µ a∈{0,1}k

∑ (−1)

v| J · a

v

W − P( a)

v∈{0,1}n

≤ O ( ε ). ψEnc(W )

The argument of the norm is a uniformly efficient family of LCUs parameterized by ( a, W̃ ). Applying Corollary 3.1 with this pair as the common marginal, D1 having z = W and D2 the

61

point distribution on the fixed q ∈ Q A , we obtain a single cryptographically small function η (λ) (depending on q) such that 2

E

∑ (−1) v| ·a W v − ∑

E

∑ (−1)x·a W̃ b

J

W̃ ∼µ a∈{0,1}| J |

≤ O ( ε ) + η ( λ ),

x ∈{0,1}| J | b∈{0,1}n b| J = x

v∈{0,1}n

(4.15)

ψEnc(q)

here we replaced Sx by its definition {b ∈ {0, 1}n : b| J = x }, since this makes the dependence on J explicit. These restriction sets form a partitioning of {0, 1}n and thus we can write the double sum on the left as a sum over v, obtaining 2

E

E

W̃ ∼µ a∈{0,1}| J |

∑ (−1)

v| J · a

v

W − W̃

v



v∈{0,1}n

≤ O ( ε ) + η ( λ ). ψEnc(q)

Lastly, we pass from a ∈ {0, 1}| J | to a ∈ {0, 1}n by observing that v · a( J ) = v| J · a| J , so averaging W ( a( J ) ) over n-bit a reproduces the previous average (each projection is repeated 2n−| J | times). This yields E

E

W̃ ∼µ a∈{0,1}n

W (a

( J)

( J)

) − W̃ ( a )

2 ψEnc(q)

2

= E

E

W̃ ∼µ a∈{0,1}n

∑ (−1)

v· a( J )

v∈{0,1}n

v

W − W̃

v

 ψEnc(q)

≤ O ( ε ) + η ( λ ).

(4.16)

Finally, we will use the linearity of the W ( a) and W̃ ( a) operators and their ε-self-consistency to extend this result to arbitrary distributions over a. This trick will be used in the Pauli basis test analysis as well. E

E ′ W ( a( J ) ) − W̃ ( a( J ) )

W̃ ∼µ a∼µ

2 ψEnc(q)

By the ε-self-consistency of (Σ, U|Σ| ) and Lemma 4.6 (where we dropped the expectation over Σ):

≤2 E

E′

E

W̃ ∼µ a∼µ b∈{0,1}n

W ( a( J ) + b( J ) ) − W̃ ( a( J ) )W (b( J ) )

2 ψEnc(q)

+ O(ε) + η (λ)

By the fact that a( J ) + b( J ) is uniformly distributed for uniform b and arbitrarily distributed a and Eq. (4.16):

≤4 E

E′

E

W̃ ∼µ a∼µ b∈{0,1}n

W̃ ( a( J ) + b( J ) ) − W̃ ( a( J ) )W (b( J ) )

By the linearity of W̃ ( a), left unitary invariance and Eq. (4.16):

≤ O(ε) + 7η (λ),

this concludes the proof.

62

2 ψEnc(q)

+ O(ε) + 3η (λ)

4.3.3

Small/large answer consistency

Since we are not trying to achieve succinctness at this point, we can tolerate a linear communication complexity, so we can use large-answer questions in much of our analysis. These are questions, on which the prover answers with n bits, which—in an honest setting—correspond to a measurement of all his qubits in the basis specified by the question. The benefit of these large-answer questions, is the fact that we can construct the corresponding observables in the analysis/on the verifier’s side (as the Fourier transform of the projectors) and get exact linearity for free, which simplifies much of the analysis. However, these large-answer questions don’t work in every setting, since in an honest execution they correspond to a separate measurement of every qubit. In some cases, such as the commutation test, we want to simultaneously measure different qubits and only obtain one outcome. Think for example of σX ⊗ σX , which commutes with σZ ⊗ σZ , only if the two qubits are measured simultaneously. Thus to achieve completeness, we will sometimes have to rely on small-answer questions. The small/large answer consistency test, defined in protocol 6 and proven sound in Lemma 4.11, allows us to relate the prover operators corresponding to both question types. The test has the same simple consistency check structure as the mixed-versus-pure basis test. In particular, the verifier sends a small-answer question to Alice and a large-answer question to Bob; it then accepts if and only if the XOR of the large answers (restricted to the qubits included in the small-answer question) is equal to the small answer. Lemma 4.11. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the small/large answer consistency test SLC (Θ, n, µ), obtained from Protocol 6, the prover’s efficient operators satisfy the following: for all q ∈ Q A there exists a cryptographically small function η (λ) such that E

E

W ∈Θ a∼µ

(Wa0 − Wa1 ) − W ( a)

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

(4.17)

Proof. Remember that we denote the small-answer projectors, corresponding to the question (W, a) as {Wav }v∈{0,1} . The large-answer projectors corresponding to question W (on which an n-bit response is expected) are denoted by {W v }v∈{0,1}n , which are combined to form W ( a). The winning condition can be rewritten as h i Enc((W,a)) E E ∑(−1)Dec(α) Tr W ( a)ψα ≥ 1 − O ( ε ), W ∈Θ a∼µ α

where Dec(α) ∈ {0, 1}. This corresponds to the hypothesis of Lemma 4.2, if we set m = 1, f ( a, b) = a and we let S be the set that only exactly the a that appears in the Alice question (W, a). By the automatic self-consistency check that is executed for this leaf test, every Alice question also exists on Bob’s side and a winning probability of 1 − ε implies ε-self-consistency of the question distribution ( Qs , µs ), over all small-answer questions (W, a) (corresponding to projectors {Wa0 , Wa1 }). Thus we can apply Lemma 4.2 and conclude that =E(W,a)∼µs

z }| { 2 E E Wa0 − Wa1 − W ( a) Enc(q) ≤ O(ε) + η (λ),

W ∈Θ a∼µ

ψ

where {Wa0 , Wa1 } are the projectors applied by Bob on question Q = (W, a), this completes the proof.

63

4.3.4

Commutation relation

Multi-qubit (anti-)commutation relations are an important part of the group relations of the extended Pauli group. Protocol 7 is designed to certify these and is proven sound in Lemma 4.12. The relation we want to test is the following: W ( a)W ′ (b) ≈ε (−1) a·b W ′ (b)W ( a)

for all a, b ∈ {0, 1}n and W ̸= W ′ ∈ { X, Y, Z }.

and the same for the observables in { Z, F, G }. The test is essentially a wrapper on the commutation and anti-commutation tests, which both act on the small-answer level. The test thus combines these two subtests with the small/large answer consistency test to obtain a guarantee on the large-answer level. Lemma 4.12. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the commutation relation test CREL (Σ, n), obtained from Protocol 7, the prover’s efficient operators satisfy the following: for all q ∈ Q A there exists a cryptographically small function η (λ) such that E′

E

W ̸=W ∈Σ a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

(4.18)

Proof. If a · b = 0, success in COM ((W, a), (W ′ , b)) tells us (by Lemma A.1) that for all q ∈ Q A , all a, b ∈ {0, 1}n with a · b = 0 and all W ̸= W ′ ∈ Σ there exists a cryptographically small function ηW,W ′ ,a,b (λ) such that 0

1

[Wa0 − Wa1 , Wb′ − Wb′ ]

2

≤ O(ε W,W ′ ,a,b ) + ηW,W ′ ,a,b (λ),

ψEnc(q)

where E

E

W ̸=W ′ ∈Σ a,b∈{0,1}n a · b =0

ε W,W ′ ,a,b = ε.

To apply the technique from Remark 3.7, we imagine an adversary against the commutation test, when averaging over W ̸= W ′ ∈ Σ and a, b ∈ {0, 1}n with a · b = 0. This adversary receives the values of W, W ′ , a and b which maximize ηW,W ′ ,a,b (λ) (per λ) as classical advice. Since the commutation test is uniform in W, W ′ , a and b, the advantage of this new adversary is also bounded by a cryptographically small function η (λ) such that E′

0

1

[Wa0 − Wa1 , Wb′ − Wb′ ]

E

W ̸=W ∈Σ a,b∈{0,1}n a · b =0

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

Similarly, if a · b = 1, success in AC ((W, a), (W ′ , b)) tells us (by Lemma A.2) that for all q ∈ Q A , all a, b ∈ {0, 1}n with a · b = 1 and all W ̸= W ′ ∈ Σ there exists a cryptographically small function ηW,W ′ ,a,b (λ) such that 0

1

{Wa0 − Wa1 , Wb′ − Wb′ }

2 ψEnc(q)

≤ O(ε W,W ′ ,a,b ) + ηW,W ′ ,a,b (λ),

where E

E

W ̸=W ′ ∈Σ a,b∈{0,1}n a · b =1

ε W,W ′ ,a,b = ε.

As with the commutation guarantee, we again apply the technique from Remark 3.7, to conclude that there exists a single negligible function η (λ) such that E′

E

W ̸=W ∈Σ a,b∈{0,1}n a · b =1

0

1

{Wa0 − Wa1 , Wb′ − Wb′ }

64

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

Together, we thus have E′

0

1

0

1

(Wa0 − Wa1 )(Wb′ − Wb′ ) − (−1) a·b (Wb′ − Wb′ )(Wa0 − Wa1 )

E

W ̸=W ∈Σ a,b∈{0,1}n

2 ψEnc(q)

≤ O ( ε ) + η ( λ ). Since the prover passes the small/large answer consistency test, we can invoke Lemma 4.11, and conclude that E

E

W ∈Σ a∈{0,1}n

2

W ( a) − (Wa0 − Wa1 )

ψEnc(q)

≤ O ( ε ) + η ( λ ),

which also implies for some W ∈ Σ: E

0

E

W ′ ∈(Σ\W ) a∈{0,1}n

1

W ′ ( a) − (Wa′ − Wa′ )

2 ψEnc(q)

≤

|Σ| (O(ε) + η (λ)) , |Σ| − 1

With this we can write out the following approximate equalities, under expectation over W ̸= W ′ ∈ Σ and a, b ∈ {0, 1}n W ( a)W ′ (b) ≈ε+η (λ) (Wa0 − Wa1 )W ′ (b) 0

1

≈ε+η (λ) (Wa0 − Wa1 )(Wb′ − Wb′ ) 0

1

0

1

≈ε+η (λ) (−1)ab (Wb′ − Wb′ )(Wa0 − Wa1 ) ≈ε+η (λ) (−1)ab (Wb′ − Wb′ )W ( a) ≈ε+η (λ) (−1)ab W ′ (b)W ( a), here the first and the last line use compiled prover-switching (Corollary 4.3), since (Σ, U|Σ| ) and (Σ \ W, U|Σ|−1 ) are ε-self-consistent question distributions, as certified by the wrapped SLC subtest and Lemma 4.1. The chain of inequalities tells us that for all q ∈ Q A we have E′

E

W ̸=W ∈Σ a,b∈{0,1}n

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

(4.19)

Now we will exploit the exact linearity of the observables and their ε-self-consistency to extend the result to arbitrary distributions. Consider the quantity that needs to be bounded E′

E

W ̸=W ∈Σ a∼µ,b∈{0,1}n

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

By the ε-self-consistency of (Σ, U|Σ| ) and Lemma 4.6:

≤2

E′

E

W ̸=W ∈Σ a∼µ,b,c∈{0,1}n

W ( a)W ′ (b)W (c) − (−1) a·b W ′ (b)W ( a + c)

2 ψEnc(q)

+ O(ε) + η (λ) ≤4

E′

E

W ̸=W ∈Σ a∼µ,b,c∈{0,1}n

+4

E′

E

W ( a)(W ′ (b)W (c) − (−1)c·b W (c)W ′ (b))

W ̸=W ∈Σ a∼µ,b,c∈{0,1}n

2 ψEnc(q)

W ( a + c)W ′ (b) − (−1)(a+c)·b W ′ (b)W ( a + c)

2 ψEnc(q)

+ O(ε) + η (λ) By left unitary invariance and since the distribution on a + c is uniform again, we can apply Eq. (4.19) and conclude:

≤ O(ε + η (λ)). 65

Repeating the same steps, starting from the expression above, one can show that for any µ and µ′ E′

E

W ̸=W ∈Σ a∼µ,b∼µ′

4.3.5

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

Product relation

Product relations of the type certified in protocol 8 are not directly part of the group relations, but they are crucial for pinning down the abstract group elements y and f, which are not generators themselves, but are defined as products of the generators. The test only acts on even numbers of qubits; this is due to the fact that in an honest execution Y and F are defined as Y = iXZ, and F = iGZ. Since we can’t associate a prover operator to the imaginary phase unit i, because it wouldn’t be an observable, it is not possible to test this product relation on the single-qubit level. Instead, if we pair an even number of qubits, the phase will factor out (since it is in the center of the group) and we obtain a relation that is directly testable. These relations are needed only in the multi-qubit setting: for n = 1 the test would not apply, but it would also be unnecessary, since the correct form of Y and F would then follow from the analysis directly. Lemma 4.13. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the product relation test PREL ( X, Z, Y, n), obtained from Protocol 8, the prover’s efficient operators satisfy the following: for all q ∈ Q A there exists a cryptographically small function η (λ) such that

(−1)|a|/2 X ( a) Z ( a) − Y ( a)

E

a∈{0,1}n

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

(4.20)

| a|≡0 (mod 2)

Proof. Let Q = (( Z, a), ( X, a)), its dependence on a is left implicit, but it is important to remember that the expectation over a is an expectation over the Alice question. Since the subtests ( a) and (b) are selected with uniform probability and the overall winning probability is 1 − ε, we have 1 − 2ε ≤ Pr[u · a + | a|/2 = x1 + x2 |subtest( a)] h i 1 1 Enc( Q) = + E n ∑(−1)Dec(α)1 +Dec(α)2 +|a|/2 Tr Y ( a)ψα , 2 2 a∈{0,1} α | a|≡0 (mod 2)

repeating the same reasoning for the other passing conditions yields h i Enc( Q) E n ∑(−1)Dec(α)1 +Dec(α)2 +|a|/2 Tr Y ( a)ψα ≥ 1 − 4ε a∈{0,1} α | a|≡0 (mod 2)

h

i

E

∑(−1)Dec(α) Tr Z(a)ψα

E

h i Enc( Q) Dec(α)2 (− 1 ) Tr X ( a ) ψ ≥ 1 − 8ε. α ∑

1

a∈{0,1}n α | a|≡0 (mod 2) a∈{0,1}n α | a|≡0 (mod 2)

66

Enc( Q)

≥ 1 − 8ε

From the above we can conclude that 2

∑ (−1)Dec(α) +Dec(α) +|a|/2Y (a) − 1 ψ ( )

E

2

1

Enc Q α

a∈{0,1}n α | a|≡0 (mod 2)

h

∑(−1)Dec(α) +Dec(α) +|a|/2 Tr Y (a)ψα

E

= 2−2

2

1

Enc( Q)

i

(4.21)

a∈{0,1}n α | a|≡0 (mod 2)

≤ 8ε and similarly we have 2

E

∑ (−1)Dec(α) Z(a) − 1 ψ ( ) ≤ 16ε

E

∑

1

Enc Q α

a∈{0,1}n α | a|≡0 (mod 2)

a∈{0,1}n α | a|≡0 (mod 2)

(−1)Dec(α)2 X ( a) − 1

2

(4.22)

≤ 16ε. Enc( Q)

ψα

Now we have all ingredients to bound the desired quantity under uniform distributions. For brevity, define sα := (−1)Dec(α)1 +Dec(α)2 ,

tα := (−1)Dec(α)1 ,

(−1)|a|/2 X ( a) Z ( a) − Y ( a)

E

a∈{0,1}n

uα := (−1)Dec(α)2 .

2 ψEnc(Q)

| a|≡0 (mod 2) 2

E

=

a∈{0,1}n

| a|≡0 (mod 2)

=

∑ X (a)Z(a) − (−1)|a|/2Y (a) ψ ( ) Enc Q α

α

2

E

∑ X (a)Z(a) − sα 1 + sα 1 − (−1)|a|/2Y (a) ψ ( )

E

∑ ∥ X ( a ) Z ( a ) − t α X ( a ) + t α X ( a ) − s α 1∥ ψ ( )

Enc Q α

a∈{0,1}n α | a|≡0 (mod 2)

≤2

2

a∈{0,1}n

| a|≡0 (mod 2)

+2

α

2

∑ sα 1 − (−1)|a|/2Y (a) ψ ( )

E

Enc Q α

a∈{0,1}n α | a|≡0 (mod 2)

≤ 16ε + 4

Enc Q α

E

∑ ∥ Z ( a ) − t α 1∥ ψ ( ) + 4

a∈{0,1}n α | a|≡0 (mod 2)

2

Enc Q α

E

∑ ∥ X ( a ) − u α 1∥ ψ ( ) 2

a∈{0,1}n α | a|≡0 (mod 2)

Enc Q α

≤ 144ε, where the last two inequalities follow from (4.21) and (4.22), respectively. We can then use the fact that the argument of the norm is a uniformly efficient family of LCUs (parameterized by a) to apply Corollary 3.1. Specifically, the expectation over a is the common marginal (where a plays the role of x in the corollary), in the first case Q is fully determined by a and we switch to a setting where q is fixed and independent of a. The point distribution on any fixed q ∈ Q A is efficiently sampleable, so the corollary yields, for every such q, a cryptographically small function η (λ) such that E

a∈{0,1}n | a|≡0 (mod 2)

(−1)|a|/2 X ( a) Z ( a) − Y ( a)

which concludes the proof. 67

2 ψEnc(q)

≤ 144ε + η (λ),

4.3.6

Clifford conjugation

Lemma 4.14. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled Clifford conjugation test CONJ - CLIFF ( X, Y, G, F, n), obtained from Protocol 9, the prover’s efficient operators satisfy the following relationships: for all q ∈ Q A there exists a cryptographically small function η (λ) such that

∥Y ( a) X ( a) − F ( a) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)),

E

a∈{0,1}n

and E

a,b∈{0,1}n

∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

Proof. Since the prover passes the small/large answer consistency test with probability 1 − O(ε) we can apply Lemma 4.11 and conclude that for all W ∈ { A, X, Y, G, F } E

a∈{0,1}n

W ( a) − (Wa0 − Wa1 )

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

(4.23)

Meanwhile, Lemma 4.9 and the prover succeeding in the third conjugation test, tells us that for all a, b ∈ {0, 1}n there exists a cryptographically small function ηa,b (λ) such that

( Ga0 − Ga1 )( Xb0 − Xb1 ) − ( A0b − A1b )( Ga0 − Ga1 )

2 ψEnc(q)

≤ O(ε a,b ) + ηa,b (λ),

with Ea,b∈{0,1}n ε a,b = ε. To apply the technique from Remark 3.7, we can imagine an adversary against the averaged conjugation test, who, per λ, receives the values of a, b as classical advice, which maximize ηa,b (λ). Since the whole test is uniform in a and b, this adversaries advantage is also upper-bounded by a single negligible function η (λ) such that E

a,b∈{0,1}n

( Ga0 − Ga1 )( Xb0 − Xb1 ) − ( A0b − A1b )( Ga0 − Ga1 )

2 ψEnc(q)

≤ O ( ε ) + η ( λ ).

We can use Eq. (4.23) to obtain an expression in terms of the large-answer observables. Consider the following chain of approximate equalities, which holds under an implicit expectation over a, b ∈ {0, 1}n : G ( a) X (b) ≈ε+η (λ) ( Ga0 − Ga1 ) X (b)

≈ε+η (λ) ( Ga0 − Ga1 )( Xb0 − Xb1 ) ≈ε+η (λ) ( A0b − A1b )( Ga0 − Ga1 ) ≈ε+η (λ) ( A0b − A1b ) G ( a) ≈ ε + η ( λ ) A ( b ) G ( a ), here the first and last line used Lemma 4.5 and the ε-self-consistency of ({Y, A, G }, U3 ) (as certified by the automatic consistency check performed for SLC), which implies self-consistency of the separate observables. Thus, E

a,b∈{0,1}n

∥ G ( a) X (b) − A(b) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

(4.24)

Now we want to relate the mixed-basis large-answer observable A(b) to a product of purebasis large-answer observables. For this we will use the guarantee obtained from the pureversus-mixed basis test and the exact linearity of the large-answer observables. Success in MBT ({ X, Y }, n, U2n ) tells us that for all W ∈ { X, Y } and all distributions µ over {0, 1}n : E

E

A∈{ X,Y }n b∼µ

W (b( JW ) ) − A(b( JW ) ) 68

2 ψEnc(q)

≤ O ( ε ) + η ( λ ),

where JW := {i ∈ [n] : Ai = W }. By the way that A is defined from a (see protocol 9), we know that JX = { i ∈ [ n ] : a i = 0 }

and

JY = {i ∈ [n] : ai = 1},

stepping over to more convenient notation, this means that b ( JX ) = b \ a

and

b( JY ) = a ∩ b.

We can now bound the following quantity E

a,b∈{0,1}n

∥ A(b) − X (b \ a)Y ( a ∩ b)∥2ψEnc(q)

Using exact linearity of A:

=

E

a,b∈{0,1}n

∥ A(b \ a) A( a ∩ b) − X (b \ a)Y ( a ∩ b)∥2ψEnc(q)

By a telescopic sum and the triangle inequality:

≤2

E

a,b∈{0,1}n

+2

∥ A(b \ a) A( a ∩ b) − X (b \ a) A( a ∩ b)∥2ψEnc(q)

E

a,b∈{0,1}n

∥ X (b \ a) A( a ∩ b) − X (b \ a)Y ( a ∩ b)∥2ψEnc(q) + O(ε) + η (λ)

By left unitary invariance, the ε-self-consistency of ({ A, X, Y, G, F }, U5 ) and Lemma 4.5:

≤4

E

a,b∈{0,1}n

+2

∥ A(b \ a) − X (b \ a)∥2ψEnc(q)

E

a,b∈{0,1}n

∥ A( a ∩ b) − Y ( a ∩ b)∥2ψEnc(q) + O(ε) + 2η (λ)

By our earlier observations, these are exactly the guarantees we get out of the mixed-versus-pure basis test, which lets us conclude:

≤ O(ε + η (λ)).

(4.25)

Combining (4.24) with (4.25), using ε-self-consistency of G and Lemma 4.5, we obtain E

a,b∈{0,1}n

∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

Using the same combination of the conjugation test guarantee (Lemma 4.9) with the nonuniform adversary trick and the small-versus-large answer test (Lemma 4.11), that were used to obtain Eq. (4.24), we can conclude from the first and second conjugation test in protocol 9 that E

∥ X ( a) G ( a) − G ( a)Y ( a)∥2ψEnc(q) ≤ O(ε + η (λ)),

E

∥ G ( a)Y ( a) − Y ( a) F ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

a∈{0,1}n

and a∈{0,1}n

With this we can make the following observation, under an implicit uniform average over a ∈ {0, 1}n Y ( a) X ( a) = Y ( a) G ( a)( G ( a) X ( a))

≈ε+η (λ) Y ( a)( G ( a)Y ( a)) G ( a) ≈ ε + η ( λ ) Y ( a )2 F ( a ) G ( a ) = F ( a ) G ( a ), the third line uses the self-consistency of G and Lemma 4.5. This completes the proof. 69

4.3.7

Clifford group relations

Lemma 4.15. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 to 5 of the compiled Clifford group test, obtained from Protocol 10, the prover’s efficient observables satisfy the following relationships: for all distributions µ, µ′ on {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that 1. (Σ, U3 ) is ε-self-consistent for Σ = { X, Y, Z } and Σ = { Z, F, G }. 2. W ( a)W (b) = W ( a + b) for all a, b ∈ {0, 1}n and all W ∈ { X, Y, Z, F, G }. 3. For all W ̸= W ′ ∈ { X, Y, Z } and all W ̸= W ′ ∈ { Z, F, G }: E

a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

4. For W = ( X, Z, Y ) and W = ( G, Z, F ): E

a∼µ:| a|=0

(mod 2)

(−1)|a|/2 W1 ( a)W2 ( a) − W3 ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

5. Ea∈{0,1}n Eb∼µ ∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)). 6. Ea∼µ ∥Y ( a) X ( a) − F ( a) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)). Proof. We prove each item in turn. 1. This follows from the automatic execution of CON ( SLC ({ X, Y, Z }), n)), CON ( SLC ({ Z, F, G }), n )) and Lemma 4.1. 2. This follows directly from the definition of W ( a) and the projectivity of the Bob PVMs {W u }u∈{0,1}n . 3. Let Σ = { X, Y, Z }, then the first execution of CREL in protocol 10 ensures that for arbitrary distributions µ, µ′ over {0, 1}n : E′

E

W ̸=W ∈Σ a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

Since the size of Σ is small, we can drop the expectation over W and W ′ , for a constant blow-up of the error. The same argument works if we set Σ = { Z, F, G } by the second execution of CREL in protocol 10. 4. From Lemma 4.13, and the fact that PREL is executed for ( X, Z, Y ) and ( G, Z, F ) with constant probability, we can conclude that (for W = ( X, Z, Y ) and W = ( G, Z, F )): E

a∈{0,1}n | a|≡0 (mod 2)

(−1)|a|/2 W1 ( a)W2 ( a) − W3 ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

(4.26)

Using the commutation guarantees 1 to 3 and a shifting trick we can extend this result to arbitrary distributions. Using left unitary invariance we can introduce uniformly distributed observables. For brevity, let V (b) := (−1)|b|/2 W1 (b)W2 (b). 70

(−1)|a|/2 W1 ( a)W2 ( a) − W3 ( a)

E

a∼µ | a|≡0 (mod 2)

E

=

E

a∼µ b∈{0,1}n | a|≡0 (mod 2) |b|≡0 (mod 2)

2 ψEnc(q)

(−1)|a|/2 V (b)W1 ( a)W2 ( a) − V (b)W3 ( a)

2 ψEnc(q)

By a telescoping sum, the triangle inequality, left unitary invariance, ε-self-consistency of ({W1 , W2 , W3 }, U3 ) with Lemma 4.5 and the fact that a + b is uniformly distributed and | a + b| = | a| + |b| − 2a · b:

≤6

E

E

a∼µ b∈{0,1}n | a|≡0 (mod 2) |b|≡0 (mod 2)

E

+9

c∈{0,1}n

2

W2 (b)W1 ( a) − (−1) a·b W1 ( a)W2 (b)

ψEnc(q)

∥V (c) − W3 (c)∥2ψEnc(q)

|c|≡0 (mod 2)

≤ O(ε + η (λ)), here the last line follows from Item 3 and Eq. (4.26). 5. Success in the CONJ - CLIFF test and Lemma 4.14 guarantee that E

a,b∈{0,1}n

∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

(4.27)

It only remains to show that we can replace the uniform expectation over b ∈ {0, 1}n by one under an arbitrary distribution on T. Again, we will use the familiar “shifting trick” from earlier calculations, which exploits the exact linearity of the large-answer observables and their self-consistency. For any distribution µ over T, consider E ∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥2ψEnc(q)

E

a∈{0,1}n b∼µ

Using the self-consistency of ({ X, Y, Z }, U3 ) and Lemma 4.6 to insert the unitary X (c) on the right (note X (b) X (c) = X (b + c) exactly, by Item 2):

≤6

E ∥ G ( a) X (b + c) − X (b \ a)Y ( a ∩ b) G ( a) X (c)∥2ψEnc(q) + O(ε) + η (λ)

E

a,c∈{0,1}n b∼µ

By a telescoping sum and the triangle inequality:

≤ 12

2

E

E ∥ G ( a) X (b + c) − X ((b + c) \ a)Y ( a ∩ (b + c)) G ( a)∥ψEnc(q)

a,c∈{0,1}n b∼µ

+ 12

E

E ∥ X ((b + c) \ a)Y ( a ∩ (b + c)) G ( a) − X (b \ a)Y ( a ∩ b) G ( a) X (c)∥2ψEnc(q)

a,c∈{0,1}n b∼µ

+ O(ε) + η (λ) By exact linearity (e.g. Y ((b + c) \ a) = Y (b \ a)Y (c \ a)), left unitary invariance and the fact that b + c is uniformly distributed:

≤ 24

E

a,d∈{0,1}n

+ 12

E

∥ G ( a) X (d) − X (d \ a)Y ( a ∩ d) G ( a)∥2ψEnc(q) 2

E ∥ X (c \ a)Y ( a ∩ b)Y ( a ∩ c) G ( a) − Y ( a ∩ b) G ( a) X (c)∥ψEnc(q)

a,c∈{0,1}n b∼µ

+ O(ε) + η (λ)

71

Using Eq. (4.27), a telescoping sum and left unitary invariance:

≤ 24

E ∥( X (c \ a)Y ( a ∩ b) − Y ( a ∩ b) X (c \ a))Y ( a ∩ c) G ( a)∥2ψEnc(q)

E

a,c∈{0,1}n b∼µ

+ 24

E

a,c∈{0,1}n

∥ X (c \ a)Y ( a ∩ c) G ( a) − G ( a) X (c)∥2ψEnc(q)

+ O(ε + η (λ)) We can bound the second term using Eq. (4.27), the first term can be bounded by applying Lemma 4.5 twice (since X, Y and G are all ε-self-consistent), using Item 3 and the fact that (c \ a) · ( a ∩ b) = 0, which yields the final bound of:

≤ O(ε + η (λ)), 6. Again CONJ - CLIFF guarantees that E

a∈{0,1}n

∥Y ( a) X ( a) − F ( a) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)),

(4.28)

which we will extend to arbitrary distributions using Items 1 to 3. Consider the quantity which we want to bound 2

E ∥Y ( a) X ( a) − F ( a) G ( a)∥ψEnc(q)

a∼µ

= E

E

a∼µ b∈{0,1}n

∥Y (b) X (b)Y ( a) X ( a) − Y (b) X (b) F ( a) G ( a)∥2ψEnc(q)

Using self-consistency of X and G with Lemma 4.5, Item 2 and the fact that a + b is again uniformly distributed:

≤8 E

E

a∼µ b∈{0,1}n

+8 E

E

X (b)Y ( a) − (−1) a·b Y ( a) X (b)

a∼µ b∈{0,1}n

+

E

c∈{0,1}n

2 ψEnc(q)

G (b) F ( a) − (−1) a·b F ( a) G (b)

2 ψEnc(q)

∥Y (c) X (c) − F (c) G (c)∥2ψEnc(q) + O(ε + η (λ))

≤ O(ε + η (λ)), the last line follows from Item 3 and Eq. (4.28).

4.3.8

Rounding to an exact representation

We have now introduced all tests required to certify the group relations and proved their soundness. Thus, a successful prover in all of these tests (specifically protocol 10) must be applying operations which approximately satisfy these group relations. What remains is to introduce an explicit approximate representation in terms of the prover’s operators and use the certified relations to show that it indeed is an approximate unitary representation of the extended Pauli group. We can then round this approximate representation to an exact one using a stability theorem. This framework of approximate representation theory has become the standard approach for many recent self-testing proofs. To define an approximate representation of the group, we recall that we can represent any group element in terms of its generators as ω p x ( a) g(b)z(c), for p ∈ {0, 1, 2, 3} and a, b, c ∈ {0, 1}n . Intuitively, we want to define our approximate representation as f (ω p x ( a) g(b)z(c)) = (−1)s ∆r X ( a) G (b) Z (c), 72

with s := ⌊ p/2⌋ (mod 2) and r := p (mod 2). Here ∆ is a “phase operator” that is meant to represent the phase i and will be defined in terms of the prover’s observables (in particular the Y and F observables, which only enter into the approximate representation via ∆). As a first step, we construct this phase operator and show that it satisfies some useful properties, which we would expect from a scalar. Constructing the phase operator ˜ ( a) = F ( a) Z ( a) G ( a). Suppose that for all distriLemma 4.16. Let ∆( a) = Y ( a) Z ( a) X ( a) and ∆ ′ n butions µ, µ on {0, 1} and all q ∈ Q A there exists a cryptographically small function η (λ) such that: 1. (Σ, U3 ) is ε-self-consistent for Σ = { X, Y, Z } and Σ = { Z, F, G }. 2. W ( a)W (b) = W ( a + b) for all a, b ∈ {0, 1}n and all W ∈ { X, Y, Z, F, G }. 3. For all W ̸= W ′ ∈ { X, Y, Z } and all W ̸= W ′ ∈ { Z, F, G }: E

a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

4. Ea∼µ ∥Y ( a) X ( a) − F ( a) G ( a)∥2ψEnc(q) ≤ O(ε + η (λ)). Then for all W ∈ { X, Y, Z, F, G }, all distributions µ, µ′ on {0, 1}n and all q ∈ Q A , there exists a cryptographically small function η (λ) such that 1.

2

∆ a+b − (−1) a·b ∆ a⊕b ψEnc(q) ≤ O(ε + η (λ)) for a, b ∈ {0, 1}.

˜ ( a) 2 Enc(q) ≤ O(ε + η (λ)). 2. Ea∼µ ∆( a) − ∆ ψ 3. Ea∼µ,b∼µ′ ∥∆( a)W (b) − W (b)∆( a)∥2ψEnc(q) ≤ O(ε + η (λ)). Proof. To obtain the first conclusion, we first show that ∆ is approximately a root of unity: ∆2 = Y (e1 ) Z (e1 ) X (e1 )Y (e1 )( Z (e1 ) X (e1 ))

≈ε+η (λ) −Y (e1 ) Z (e1 ) X (e1 )(Y (e1 ) X (e1 )) Z (e1 ) ≈ε+η (λ) Y (e1 )( Z (e1 )Y (e1 )) Z (e1 ) ≈ ε + η ( λ ) −1 here we repeatedly used Item 1 with Lemma 4.5 and Item 3. With this we can conclude the following, for a, b ∈ {0, 1}: ∆ a+b − (−1) a·b ∆ a⊕b

2 ψEnc(q)

≤ O(ε + η (λ)).

For the third conclusion (its proof involves showing the second conclusion), suppose W = Y. We make the following observations, with an implicit expectation over a ∼ µ and b ∼ µ′ : W ( b ) ∆ ( a ) = Y ( b )Y ( a ) Z ( a ) X ( a ) By exact linearity (hypothesis 2):

= Y ( a)(Y (b) Z ( a)) X ( a) 73

By hypotheses 1 (self-consistency) and 3 (anti-commutation) and Corollary 4.3:

≈ε+η (λ) (−1)b·a Y ( a) Z ( a)(Y (b) X ( a)) ≈ε+η (λ) (−1)2(b·a) Y ( a) Z ( a) X ( a)Y (b) = ∆ ( a )W ( b ) . So we have W (b)∆( a) ≈ε+η (λ) ∆( a)W (b) in the case W = Y. The other cases W = X, Z are ˜ ( a), then analogous. For the cases where W = G, F, we will use Item 4 to show that ∆( a) ≈ ∆ ˜ we can perform the same steps as above with ∆( a) and switch it back out for ∆( a) in the final expression, using compiled prover switching. Consider the following chain of approximate inequalities under an implicit expectation over a ∼ µ: ∆( a) = Y ( a)( Z ( a) X ( a))

≈ε+η (λ) (−1)|a| (Y ( a) X ( a)) Z ( a) ≈ε+η (λ) (−1)|a| F ( a)( G ( a) Z ( a)) ≈ε+η (λ) (−1)2|a| F ( a) Z ( a) G ( a) = ∆˜ ( a), the second and third line use Item 3 and the third line uses Item 4 and Lemma 4.5 with the self-consistency of Z. This completes the proof. Defining an approximate representation Definition 4.5. For a prover with observables W ( a) (for W ∈ { X, Y, Z, F, G } and a ∈ {0, 1}n ), we define a function f : Cn → U (H) as follows (recalling from Definition 3.1 that we can represent an arbitrary group element as ω p x ( a) g(b)z(c) for p ∈ {0, 1, 2, 3} and a, b, c ∈ {0, 1}n ): f (ω p x ( a) g(b)z(c)) = (−1)s( p) ∆r( p) X ( a) G (b) Z (c) , where s( p) := ⌊ p/2⌋ (mod 2) and r ( p) := p (mod 2). Note that the definition of f depends on the Y-observables only through ∆ := ∆(e1 ) = Y (e1 ) Z (e1 ) X (e1 ), where e1 is as in Section 3.1. Lemma 4.17. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 5 of the compiled Clifford group test, obtained from protocol 10, it holds for the function f , from Definition 4.5, that for all q ∈ Q A and all distributions µ over {0, 1}n there exists a cryptographically small function η (λ) such that E ∥ f (y( a)) − Y ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

a∼µ

Proof. Recall that, by the group relations, we can alternatively represent y( a) as ω | a | x ( a ) z ( a ). Let s( a) := ⌊ a/2⌋ (mod 2) and r ( a) := a (mod 2), so E ∥ f (y( a)) − Y ( a)∥2ψEnc(q)

a∼µ

= E

a∼µ

(−1)s(|a|) ∆r(|a|) X ( a) Z ( a) − Y ( a)

74

2 ψEnc(q)

We can split the expectation over a ∈ {0, 1}n based on the Hamming weight parity: E

=

a∼µ | a|≡0 (mod 2)

+

E

(−1)|a|/2 X ( a) Z ( a) − Y ( a)

a∼µ | a|≡1 (mod 2)

2 ψEnc(q)

(−1)(|a|−1)/2 ∆X ( a) Z ( a) − Y ( a)

2 ψEnc(q)

≤ O(ε + η (λ)),

(4.29)

where we bounded both terms separately. The bound on the first term automatically follows from Lemma 4.15, Item 4. To bound the second term, we have to do a bit more work. Expanding ∆ and using left unitary invariance and the exact linearity of Y ( a) and X ( a): E

a∼µ | a|≡1 (mod 2)

(−1)(|a|−1)/2 ∆X ( a) Z ( a) − Y ( a) =

E

a∼µ | a|≡1 (mod 2)

2 ψEnc(q)

(−1)(|a|−1)/2 Z (e1 ) X ( a + e1 ) Z ( a) − Y ( a + e1 )

2 ψEnc(q)

Using compiled prover switching left unitary invariance and the triangle inequality, we obtain:

≤4

Z (e1 ) X ( a + e1 ) − (−1) a·e1 +1 X ( a + e1 ) Z (e1 )

E

a∼µ | a|≡1 (mod 2)

+2

E

a∼µ | a|≡1 (mod 2)

2 ψEnc(q)

(−1)(|a|+2a·e1 +1)/2 X ( a + e1 ) Z ( a + e1 ) − Y ( a + e1 )

2 ψEnc(q)

+ O(ε + η (λ)) The first term can be bounded using Lemma 4.15, Conclusion 3. The second term can be rewritten by introducing ã = a + e1 ; this string has even Hamming weight and | ã| ≡ | a| + 2a · e1 + 1 (mod 4):

≤2

E

ã∼µ | ã|≡0 (mod 2)

(−1)|ã|/2 X ( ã) Z ( ã) − Y ( ã)

2 ψEnc(q)

+ O(ε + η (λ))

The final bound is then obtained by applying Lemma 4.15, Item 4,

≤ O(ε + η (λ)).

Lemma 4.18. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 5 of the compiled Clifford group test, obtained from protocol 10, it holds for the function f , from Definition 4.5, that for all q ∈ Q A and all distributions µ over {0, 1}n there exists a cryptographically small function η (λ) such that E ∥ f (f ( a)) − F ( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

a∼µ

Proof. Plugging the guarantees from Lemma 4.15 into Lemma 4.16, we know that E

a∼µ

˜ ( a) 2 Enc(q) ≤ O(ε + η (λ)). ∆( a) − ∆ ψ

75

(4.30)

Recall that, by the group relations, we can alternatively represent f ( a) as ω | a | g ( a ) z ( a ). Let s( a) := ⌊ a/2⌋ (mod 2) and r ( a) := a (mod 2), so 2

E ∥ f (f ( a)) − F ( a)∥ψEnc(q)

a∼µ

= E

a∼µ

(−1)s(|a|) ∆r(|a|) G ( a) Z ( a) − F ( a)

2 ψEnc(q)

We can split the expectation over a ∈ {0, 1}n based on the Hamming weight parity:

=

(−1)|a|/2 G ( a) Z ( a) − F ( a)

E

a∼µ | a|≡0 (mod 2)

+

E

a∼µ | a|≡1 (mod 2)

2 ψEnc(q)

(−1)(|a|−1)/2 ∆G ( a) Z ( a) − F ( a)

2 ψEnc(q)

Using Lemma 4.15, Item 4 and Eq. (4.30) with compiled prover switching on G and Z:

≤

2

˜ ( a) Z ( a) − F ( a) (−1)(|a|−1)/2 ∆G

E

a∼µ | a|≡1 (mod 2)

+ O(ε + η (λ))

ψEnc(q)

≤ O(ε + η (λ)), here the second term can be bounded in exactly the same way as in the proof of Lemma 4.17, where F takes the role of Y and G takes the role of X. Lemma 4.19. Suppose that for all distributions µ, µ′ on {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that: 1. (Σ, U3 ) is ε-self-consistent for Σ = { X, Y, Z } and Σ = { Z, F, G }. 2. W ( a)W (b) = W ( a + b) for all a, b ∈ {0, 1}n and all W ∈ { X, Y, Z, F, G }. 3. For all W ̸= W ′ ∈ { X, Y, Z } and all W ̸= W ′ ∈ { Z, F, G }: E

a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

2 ψEnc(q)

≤ O(ε + η (λ)).

2

4. Ea∈{0,1}n Eb∼µ ∥ G ( a) X (b) − X (b \ a)Y ( a ∩ b) G ( a)∥ψEnc(q) ≤ O(ε + η (λ)). 5. For all W ∈ { X, Y, Z, F, G }: Ea∼µ,b∼µ′ ∥∆( a)W (b) − W (b)∆( a)∥2ψEnc(q) ≤ O(ε + η (λ)). 2

6. Ea∼µ ∥ f (y( a)) − Y ( a)∥ψEnc(q) ≤ O(ε + η (λ)). Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that 1. Ea∈{0,1}n Eb∼µ G ( a) X (b) − (−1) a·b+s(|a∩b|) ∆r(|a∩b|) X (b) G ( a) Z ( a ∩ b) 2. Ea∈{0,1}n Eb∼µ G ( a)Y (b) − (−1)s(|b\a|) ∆r(|b\a|) X (b) G ( a) Z (b \ a) where γ = O(ε + η (λ)), s( a) ≡ ⌊ a/2⌋ (mod 2) and r ( a) ≡ a (mod 2). 76

2 ψEnc(q)

2 ψEnc(q)

≤ γ.

≤ γ.

Proof. Towards proving the first conclusion, we show that under implicit expectation over a ∈ {0, 1}n and b ∼ µ, we have G ( a ) X ( b ) ≈ ε + η ( λ ) X ( b \ a )Y ( a ∩ b ) G ( a )

≈ε+η (λ) X (b \ a)(−1)s(|a∩b|) ∆r(|a∩b|) X ( a ∩ b) Z ( a ∩ b) G ( a) ≈ε+η (λ) (−1)s(|a∩b|) ∆r(|a∩b|) X (b) Z ( a ∩ b) G ( a) ≈ε+η (λ) (−1)a·b+s(|a∩b|) ∆r(|a∩b|) X (b) G ( a) Z ( a ∩ b), here the first line uses Item 4, the second line uses Item 6, the third one follows from Item 5 with Item 2 and the last one uses Item 3. For most of these steps we also need Item 1 with compiled prover switching (Lemma 4.5). This shows the first conclusion. Now, towards the second conclusion, we consider the following approximate equalities under an implicit expectation over a ∈ {0, 1}n and b ∼ µ: G ( a)Y (b) ≈ε+η (λ) G ( a)(−1)s(|b|) ∆r(|b|) X (b) Z (b)

≈ε+η (λ) (−1)s(|b|) ∆r(|b|) G ( a) X (b) Z (b) ≈ε+η (λ) (−1)a·b+s(|b|)+s(|a∩b|) ∆r(|b|)+r(|a∩b|) X (b) G ( a) Z (b \ a) ≈ε+η (λ) (−1)a·b+s(|b|)+s(|a∩b|)+r(|b|)r(|a∩b|) ∆r(|b|)⊕r(|a∩b|) X (b) G ( a) Z (b \ a) = (−1)s(|b\a|) ∆r(|b\a|) X (b) G ( a) Z (b \ a), the first approximate equality follows from Item 6, the second one uses Item 5, for the third line we used our previous observation about commuting X past G and Item 2. The second-to-last line uses Item 3 and the final equality follows from the definitions of s( a), r ( a) and the fact that |b| = | a ∩ b| + |b \ a| and the following identity for u, v ∈ N: s ( u + v ) = s ( u ) + s ( v ) + r ( u )r ( v ).

Lemma 4.20. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 5 of the compiled Clifford group test, obtained from protocol 10, it holds for the function f , from Definition 4.5, that for all q ∈ Q A , all W ∈ { X, Y, Z, F, G } and all distributions µ over {0, 1}n there exists a cryptographically small function η (λ) such that E

a∼µ,h∈Cn

∥ f (h) f (w( a)) − f (h · w( a))∥2ψEnc(q) ≤ O(ε + η (λ)) ,

(4.31)

Proof. We first apply Lemma 4.15, which guarantees that the following relations hold for all distributions µ, µ′ , µ′′ on {0, 1}n and all q ∈ Q A : 1. (Σ, U3 ) is ε-self-consistent for Σ = { X, Y, Z } and Σ = { Z, F, G }. 2. W ( a)W (b) = W ( a + b) for all a, b ∈ {0, 1}n and all W ∈ { X, Y, Z, F, G }. 3. For all W ̸= W ′ ∈ { X, Y, Z } and all W ̸= W ′ ∈ { Z, F, G }: E

a∼µ,b∼µ′

W ( a)W ′ (b) − (−1) a·b W ′ (b)W ( a)

77

2 ψEnc(q)

≤ O(ε + η (λ)).

Using the conclusions of Lemma 4.15 (conclusions 1, 2 and 3) and applying them to Lemma 4.16, we can also conclude that for all W ∈ { X, Y, Z, F, G }: E

a∼µ,b∼µ′

∥∆( a)W (b) − W (b)∆( a)∥2ψEnc(q) ≤ O(ε + η (λ)).

(4.32)

and for all a, b ∈ {0, 1} ∆ a+b − (−1) a·b ∆ a⊕b

2

≤ O(ε + η (λ)).

(4.33)

E ∥ f (y( a)) − Y ( a)∥ψEnc(q) ≤ O(ε + η (λ)),

2

(4.34)

2

(4.35)

ψEnc(q)

From Lemma 4.17 and Lemma 4.18 we know that a∼µ

and

E ∥ f (f ( a)) − F ( a)∥ψEnc(q) ≤ O(ε + η (λ)).

a∼µ

With all of the above, we can apply Lemma 4.19 and conclude that: E

E

G ( a) X (b) − (−1) a·b+s(|a∩b|) ∆r(|a∩b|) X (b) G ( a) Z ( a ∩ b)

E

E

a∈{0,1}n b∼µ

a∈{0,1}n b∼µ

G ( a)Y (b) − (−1)s(|b\a|) ∆r(|b\a|) X (b) G ( a) Z (b \ a)

2 ψEnc(q) 2 ψEnc(q)

≤ O(ε + η (λ)), ≤ O(ε + η (λ)), (4.36)

where s( a) ≡ ⌊ a/2⌋ (mod 2) and r ( a) ≡ a (mod 2). All of these guarantees together, which we obtained through the appropriate self-tests, give us enough information about the prover operators to show Eq. (4.31). Since ω is in the center of the group and the approximate representation (Definition 4.5) maps ω 2 to −1 we can assume, without loss of generality, that h = ω p x ( a) g(b)z(c), with p ∈ {0, 1} and a, b, c ∈ {0, 1}n . Right multiplication on the normal form is given by the following identities, which follow from the relations in Definition 3.1. Anticommutation yields z(c) x (d) = ω 2c·d x (d)z(c) and z(c) g(d) = ω 2c·d g(d)z(c). Conjugation together with g(b)2 = 1 and a further anticommutation to restore the xgz order yields g(b) x (d) = ω 3|b∩d| x (d) g(b)z(b ∩ d). Linearity of x, g and z then gives the claims for x (d), z(d) and g(d); the claims for y(d) and f (d) follow by substituting y(d) = ω |d| x (d)z(d) and f (d) = ω |d| g(d)z(d). For all d ∈ {0, 1}n and h ∈ Cn , h · x (d) = ω p+2c·d+3|b∩d| x ( a + d) g(b)z(c + b ∩ d), h · y(d) = ω p+|d|+2c·d+3|b∩d| x ( a + d) g(b)z(c + d \ b), h · z ( d ) = ω p x ( a ) g ( b ) z ( c + d ), h · g(d) = ω p+2c·d x ( a) g(b + d)z(c), h · f (d) = ω p+|d|+2c·d x ( a) g(b + d)z(c + d). Applying Definition 4.5, reducing the central phase via s(k + 2m) = s(k) + m, r (k + 2m) = r (k ) and using the fact that |d| = |b ∩ d| + |d \ b|, we obtain, for p ∈ {0, 1}, f (h · x (d)) = (−1)(b+c)·d+s( p+|b∩d|) ∆r( p+|b∩d|) X ( a + d) G (b) Z (c + b ∩ d), f (h · y(d)) = (−1)c·d+s( p+|d\b|) ∆r( p+|d\b|) X ( a + d) G (b) Z (c + d \ b), f (h · z(d)) = ∆ p X ( a) G (b) Z (c + d), f (h · g(d)) = (−1)c·d ∆ p X ( a) G (b + d) Z (c), f (h · f (d)) = (−1)c·d+s( p+|d|) ∆r( p+|d|) X ( a) G (b + d) Z (c + d). 78

It remains to show that f (h) f (w(d)) is close to the right-hand side in each case. We start with W = X and W = Y. Under uniform expectation over a, b, c ∈ {0, 1}n , p ∈ {0, 1} and d ∼ µ, ∆ p X ( a) G (b)( Z (c) X (d)) ≈ε+η (λ) (−1)c·d ∆ p X ( a) G (b) X (d) Z (c)

≈ε+η (λ) (−1)(b+c)·d+s(|b∩d|) ∆ p+r(|b∩d|) X ( a + d) G (b) Z (c + b ∩ d) ≈ε+η (λ) (−1)(b+c)·d+s(|b∩d|)+ pr(|b∩d|) ∆r( p+|b∩d|) X ( a + d) G (b) Z (c + b ∩ d) = (−1)(b+c)·d+s( p+|b∩d|) ∆r( p+|b∩d|) X ( a + d) G (b) Z (c + b ∩ d), ∆ p X ( a) G (b)( Z (c)Y (d)) ≈ε+η (λ) (−1)c·d ∆ p X ( a) G (b)Y (d) Z (c)

≈ε+η (λ) (−1)c·d+s(|d\b|) ∆ p+r(|d\b|) X ( a + d) G (b) Z (c + d \ b) ≈ε+η (λ) (−1)c·d+s(|d\b|)+ pr(|d\b|) ∆r( p+|d\b|) X ( a + d) G (b) Z (c + d \ b) = (−1)c·d+s( p+|d\b|) ∆r( p+|d\b|) X ( a + d) G (b) Z (c + d \ b) In both cases the first line follows from Item 3, the second line uses Eq. (4.36) with Eq. (4.32) and Item 2, the third line uses Eq. (4.33) and the last line follows from the definitions of s( a), r ( a) and the fact that s( p) = 0 for p ∈ {0, 1}. The right-hand sides are f (h · x (d)) and f (h · y(d)) as displayed above, which shows Eq. (4.31) for W = X, Y. For W = Z, exact linearity immediately gives the exact equality f (h) f (z(d)) = ∆ p X ( a) G (b) Z (c) Z (d) = ∆ p X ( a) G (b) Z (c + d) = f (h · z(d)). For W = G, under the same implicit expectation, ∆ p X ( a) G (b)( Z (c) G (d)) ≈ε+η (λ) (−1)c·d ∆ p X ( a) G (b) G (d) Z (c)

= (−1)c·d ∆ p X ( a) G (b + d) Z (c), where the first step uses Item 3 and the second uses Item 2; the right-hand side is f (h · g(d)). Thus it only remains to show Eq. (4.31) for W = F. Again we take an implicit expectation over a, b, c ∈ {0, 1}n , p ∈ {0, 1} and d ∼ µ: ∆ p X ( a) G (b) Z (c) F (d) ≈ε+η (λ) (−1)s(|d|) ∆ p+r(|d|) X ( a) G (b)( Z (c) G (d)) Z (d)

≈ε+η (λ) (−1)c·d+s(|d|) ∆ p+r(|d|) X ( a) G (b + d) Z (c + d) ≈ε+η (λ) (−1)c·d+s(|d|)+ pr(|d|) ∆r( p+|d|) X ( a) G (b + d) Z (c + d) = (−1)c·d+s( p+|d|) ∆r( p+|d|) X ( a) G (b + d) Z (c + d) Here the first line follows from Eq. (4.34), Eq. (4.35) and Eq. (4.32), the second line uses Item 3 and Item 2, the third line uses Eq. (4.33) and the last line follows from the definitions of s( a), r ( a) and the fact that s( p) = 0 for p ∈ {0, 1}. The right-hand side is f (h · f (d)), which shows Eq. (4.31) for W = F and completes the proof.

From approximate representation to rigidity Definition 4.6 (Clifford test isometry). Let Cn be the n-qubit extended Pauli group (Definition 3.1), UQFT be the quantum Fourier transform over that group (see Section 3.3) and f : Cn → U (H) be the approximate unitary representation built from the prover operators in Definition 4.5. Then the Clifford isometry is the isometry V : H → H′ defined as: V :=

1 UQFT |t⟩ ⊗ f (ut−1 ) ⊗ |u⟩. |Cn | u,t∑ ∈Cn 79

Lemma 4.21. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in the compiled Clifford group test CLIFF - GROUP ( X, Y, Z, F, G, n), obtained from protocol 10, there exists a complex Hilbert space H′ of finite dimension d′ = d|Cn |2 and an efficient isometry V : H → H′ (from Definition 4.6) such that for all W ∈ { X, Y, Z, G, F }, all distributions µ on {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ ΛW ( a))V ∥2ψEnc(q) ≤ O(ε + η (λ)),

a∼µ

where Λ X ( a) = ΛY ( a) = Λ Z ( a) = 1 and Λ F ( a) = ΛG ( a) = ∑k∈{0,1}n (−1) a·k |k⟩⟨k | ⊗ 1 for all a ∈ {0, 1}n . Proof. Consider any prover strategy that succeeds with probability 1 − ε and choose an arbitrary q ∈ Q A and distribution µ over {0, 1}n . Let f be as in Definition 4.5. From Lemma 4.20, we get that for any W ∈ { X, Y, Z, G, F }, E

a∼µ,h∈Cn

∥ f (h) f (w( a)) − f (h · w( a))∥2ψEnc(q) ≤ O(ε + η (λ)) .

Any element of Cn can be encoded in 3n + 2 qubits and group multiplication is efficient under this encoding. Moreover, f is constructed from prover operators with classical post-processing, which enables an efficient implementation of the controlled- f operation. As shown in Section 3.3 the quantum Fourier transform over Cn can be efficiently implemented and thus we can apply Corollary 3.3 and conclude that under the isometry V : H → H′ from Definition 4.6 it holds that E ∥V f (w( a)) − (π (w( a)) ⊗ 1)V ∥2ψEnc(q) ≤ O(ε + η (λ)) ,

a∼µ

where the identity tensor factor is d|Cn |-dimensional and π : Cn → U (H ′ ) is the direct sum of all irreducible representations ρµ : Cn → U (Hµ ) of Cn (with dimension dµ ), π ( g) =

M

ρ µ ( g ) ⊗ 1d µ .

µ

Furthermore, from the definition of f and the equivalence guaranteed by Corollary 3.3, we know that 0 = E ∥ f (h) f (−1) − f (−h)∥2ψEnc(q) h∈Cn

= ∥V f (−1) − (π (−1) ⊗ 1)V ∥2ψEnc(q)

(4.37)

= ∥1 + π (−1) ⊗ 1∥2VψEnc(q) V † . where V is the same isometry as before. Finally, to show that X ( a), Y ( a), Z ( a), G ( a) and F ( a) are actually close to the corresponding Clifford operators (up to potential choice of faithful representation) after isometry, we need to further characterize the unitary representation π. Specifically, we will show that there exists a π̂, such that π̂ is of the form stated in the lemma, and E ∥VW ( a) − (π̂ (w( a)) ⊗ 1)V ∥2ψEnc(q) ≤ O(ε + η (λ)).

a∼µ

(4.38)

To this end, recall that π is the block-diagonalization of the left regular representation of Cn . By the specific choice of ordering for the encoding basis (see Section 3.3), we enforce that the ‘classical’ representations occupy the top block, so we can write π ( g) = π+ ( g) ⊕ π− ( g), where π± ( g) are representations satisfying π± (− g) = ±π± ( g) for all g ∈ Cn . I.e.   π+ ( g) 0 π ( g) = . 0 π− ( g) 80

We will now round π ( g) to a representation that only maps the negative identity group-element to −1, since this is exactly the unique algebraic property that distinguishes the classical from the fundamental irreps. We know that every irreducible representation appears in the left regular representation with a multiplicity that is equal to its dimension. From Lemma 3.1 we thus know that dim(π+ ) = dim(π− ) = 23n+1 . As such, we define   π− ( g) 0 π̂ ( g) = = π− ( g) ⊗ 12 . 0 π− ( g) For all g ∈ Cn , 1 ∥(π ( g) − π̂ ( g)) ⊗ 1∥VψEnc(q) V † = ∥(π ( g) − π̂ ( g)) · (1 + π (−1)) ⊗ 1∥VψEnc(q) V † 2 1 ≤ ∥π ( g) − π̂ ( g)∥ · ∥(1 + π (−1)) ⊗ 1∥VψEnc(q) V † 2 1 ≤ (∥π ( g)∥ + ∥π̂ ( g)∥) · ∥(1 + π (−1)) ⊗ 1∥VψEnc(q) V † 2 = ∥(1 + π (−1)) ⊗ 1∥VψEnc(q) V † = 0, where the first equality exploits the exact structure of the rounding (since only the top left block of the difference is non-zero). The second line follows from Lemma 3.2 point (ii), the third line makes use of the triangle inequality for the Schatten-∞ norm, the last line follows from the fact that both π ( g) and π̂ ( g) are representations and thus unitaries and the last equality uses Eq. (4.37). Since the state-dependent norm is non-negative we can conclude that both representations are equivalent, when restricted to the post-isometry state and thus 2

E ∥V f (w( a)) − (π̂ (w( a)) ⊗ 1)V ∥ψEnc(q) ≤ O(ε + η (λ)) .

a∈µ

(4.39)

The unitary representation π̂ is constructed from a direct sum of copies of the 2n+1 ‘quantum’ irreducible representations of Cn . We know how these look and by the specific basis ordering chosen for the QFT, the canonical ones appear before the conjugate ones and we can write 2

E ∥V f (w( a)) − ((σW ( a) ⊕ σW ( a)) ⊗ ΛW ( a))V ∥ψEnc(q) ≤ O(ε + η (λ)) ,

a∈µ

where Λ X ( a) = ΛY ( a) = Λ Z ( a) = 1 and Λ F ( a) = ΛG ( a) = ∑k∈{0,1}n (−1) a·k |k ⟩⟨k | ⊗ 1 for all a ∈ {0, 1}n . It remains to show that f (w( a)) = W ( a) for all W ∈ { X, Y, Z } and a ∈ {0, 1}n . By Definition 4.5 it is immediately clear that f ( x ( a)) = X ( a), f (z( a)) = Z ( a) and f ( g( a)) = G ( a) for all a ∈ {0, 1}n , however, since the prover’s Y operator is hidden inside ∆, and similarly for F. Earlier we already proved the required relations (see Lemma 4.17 and Lemma 4.18), plugging this into Eq. (4.39) (with a triangle inequality), we can conclude that E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ ΛW ( a))V ∥2ψEnc(q) ≤ O(ε + η (λ)) ,

a∼µ

(4.40)

where the Λ operators are defined as above. This concludes the proof. 4.3.9

Clifford test

The guarantee of Lemma 4.21 doesn’t yet pin down the sign on the prover’s G and F observables, which requires a test that certifies an algebraic relation that is not one of the group relations. As sketched in Section 2.2, this test will use entanglement swapping to enforce correct pairwise correlations on the observables corresponding to the unencrypted interaction. 81

Bell-basis test The first step is to convert entanglement shared between Alice and Bob into entanglement internal to Bob’s register. To this end, Alice receives a specific question, which instructs her to measure a predefined pairing of her qubits in the Bell basis. The second subtest of protocol 11 ensures that Alice really performs the requested measurement, by using Bob to check her reported outcomes. Definition 4.7 (Brick-wall pairings). For n qubits, define the two brick-wall pairings:   P0 := (2i − 1, 2i ) i∈[⌊n/2⌋] , P1 := (2i, 2i + 1) i∈[⌊(n−1)/2⌋] . u := 1 (1 + Definition 4.8 (Pairwise Bell and Pauli projectors). For a single qubit, define τW 2 u (−1) σW ) for W ∈ { X, Z, G, F } and u ∈ {0, 1}; for multi-bit superscripts, we mean the natural extension to tensor products of projectors. For a pair of qubits ( j, k ), define the single-qubit Bell-basis projector as ! !     u,v l m l m Φ j,k := ∑ τX (τX )k · ∑ τZ (τZ )k = |Φuv ⟩⟨Φuv | j,k . j

l ⊕m=u

j

l ⊕m=v

(α,β)

For a pairing Pb and label strings α, β ∈ {0, 1}| Pb | , define Φb un-paired qubits.

:=

N

αi ,β i i ∈[| Pb |] Φ( Pb )i , with identity on all

Lemma 4.22. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 and 2 of the compiled Clifford test, obtained from Protocol 11, Alice’s post-measurement state (after the isometry from Definition 4.6) satisfies, for all b ∈ {0, 1}:

∑ α



Dec(α)

Φb

 2 ⊗1 −1 Enc( Pb ) † ≤ O ( ε + η ( λ )). Vψα

V

Proof. Let W = ( X, Z ) as in the protocol specification. Fix b ∈ {0, 1} and let f b : {0, 1}n → {0, 1}| Pb | map an outcome string to its pairwise parities according to the corresponding brickwall pairing, i.e. f b (u)i = u2i−1+b ⊕ u2i+b for i ∈ [| Pb |]. We also define hb : {0, 1}| Pb | → {0, 1}n for mapping into pair-consistent, n-bit strings as hb (s)2i−1+b = hb (s)2i+b = si for every (2i − 1 + b, 2i + b) ∈ Pb , and set all unpaired coordinates to zero. Notice that: s · f b (u) = hb (s) · u for all s ∈ {0, 1}| Pb | and u ∈ {0, 1}n . For v ∈ {0, 1}| Pb | and c ∈ {0, 1}, define the projectors v v u := ∑ Wcu := ∑ τW PW and τ̃W . c c ,b c ,b u∈{0,1}n f b (u)=v

u∈{0,1}n f b (u)=v

The left projector can be used to characterize the prover’s winning probability. For a prover to pass the Bell-basis test, the parities of Bob’s reported outcomes (u ∈ {0, 1}n ) need to match pair-wise measurement outcome string reported by Alice (vc = Dec(α)c ∈ {0, 1}| Pb | ). We want to transition from projectors to binary observables, so the following character identity will be useful: 1{ f b (u) = v} = E (−1)s·( f b (u)⊕v) . s∈{0,1}| Pb |

82

Using the above with s · f b (u) = hb (s) · u and the observable expressions Wc ( a) and σWc ( a), we obtain v PW =∑ c ,b

E

|P | u s∈{0,1} b

E

=

s∈{0,1}| Pb |

(−1)v·s ∑(−1)hb (s)·u Wcu u

v·s

E

=

(−1)s·( f b (u)⊕v) Wcu

s∈{0,1}| Pb |

(−1) Wc (hb (s)),

and similarly v τ̃W = c ,b

E

s∈{0,1}

| Pb |

(−1)v·s σWc (hb (s)).

The two Fourier expressions above (linking projectors to observables) give, for every α, Dec(α)c

VPWc ,b

Dec(α)c

− (τ̃Wc ,b

⊗ 1)V =

E

s∈{0,1}| Pb |

(−1)Dec(α)c ·s (VWc (hb (s)) − (σWc (hb (s)) ⊗ 1)V ) .

Applying Lemma 3.2(vi), followed by linearity in the state, we obtain

∑ VPW ,b

Dec(α)c c

Dec(α)c

− (τ̃Wc ,b

⊗ 1)V

α

s∈{0,1}

E

=

Enc( Pb )

ψα

∑ ∥VWc (hb (s)) − (σW (hb (s)) ⊗ 1)V ∥ψ ( ) 2

E

≤

2

s∈{0,1}

| Pb |

| Pb |

c

α

Enc Pb α

∥VWc (hb (s)) − (σWc (hb (s)) ⊗ 1)V ∥2ψEnc(Pb )

≤ O(ε + η (λ)), where the last inequality follows from Lemma 4.21 by taking q = Pb and choosing µ to be the distribution of hb (s) for uniform s ∈ {0, 1}| Pb | . This allows us to push the aggregated Bob projector through the isometry. Since the Bell-basis test succeeds with probability 1 − O(ε), we have for all c ∈ {0, 1}

∑ Tr PW ,b

 Dec(α)c c

Enc( Pb ) 

ψα

≥ 1 − O ( ε ).

(4.41)

α

v Since PW is a projector for every v, Eq. (4.41) implies c ,b

∑ PW ,b

Dec(α)c c

−1

α

2 Enc( Pb ) ψα

 Dec(α) Enc( Pb )  = 1 − ∑ Tr PWc ,b c ψα ≤ O ( ε ). α

Combining the previous two bounds with a triangle inequality and using that V is an isometry yields, for all c ∈ {0, 1},

∑ (τ̃W ,b

Dec(α)c c

⊗ 1) − 1

α

2 Enc( Pb )

Vψα

V†

≤ O(ε + η (λ)).

(4.42)

By the tensor product structure (everything factorizes into pairs) we can easily verify that Dec(α)0 Dec(α)1 Dec(α) τ̃Z,b = Φb .

τ̃X,b

83

(4.43)

Concretely, for each pair ( j, k ) ∈ Pb , one checks that !     u v l m τ̃X,b j τ̃Z,b k = ∑ τX (τX )k ·

∑

j

l ⊕m=u



τZl

!



l ⊕m=v

j

= Φu,v j,k ,

(τZm )k

(α,β)

α · τ̃ and thus the full tensor product of all pairs yields τ̃X,b , a multi-qubit Bell-basis Z,b = Φb projection with pairing Pb . We can now use the two cases of Eq. (4.42) with Eq. (4.43) to prove the lemma statement   2 Dec(α) ⊗1 −1 ∑ Φb Enc( Pb ) † β

Vψα

α

=∑



V

Dec(α)0 Dec(α)1 τ̃Z,b ⊗1



τ̃X,b

−1

α



≤ 2∑

Dec(α)0

τ̃X,b

⊗1

 

Dec(α)1

τ̃Z,b

2 Enc( Pb )

Vψα



⊗1 −1

α

+2∑



Dec(α)0

τ̃X,b

≤ 2 ∑ τ̃X,b

Dec(α)0

⊗1

α

+2∑



Dec(α)0

τ̃X,b

 2 Enc( Pb )

Vψα

V†

 2 ⊗1 −1 Enc( Pb ) † Vψα

α

V†

2



Dec(α)1

τ̃Z,b

∞



⊗1 −1

α

V

 2 ⊗1 −1 Enc( Pb ) † Vψα

V

2 Enc( Pb )

Vψα

V†

≤ O(ε + η (λ)).

Sign consistency test We will now analyze the sign consistency subtest (protocol 11 item 3), which ensures that Bob’s reported outcomes are consistent with the underlying entanglement on his side, which Alice generated by collapsing her qubits pairwise into one of four Bell states. Because the correlations either remain in the same observable (G) or cross observables (G and F), we have two consistency subtests. We will first analyze the single-observable case. For ease of analysis we define the following set Definition 4.9 (Accepted answer sets). For a decrypted Alice answer (u, v) (for the Bell measurement question) and pairing index b ∈ {0, 1}, we define ( a ∈ {0, 1}n : ∀( j, k ) ∈ Pb , v⌈ j/2⌉ = 1 =⇒ a j ⊕ ak = u⌈ j/2⌉ if v ̸= 0| Pb | , S(u,v),b := {0, 1}n if v = 0| Pb | . and ( R(u,v),b :=

a ∈ {0, 1}n : ∀( j, k ) ∈ Pb , v⌈ j/2⌉ = 0 =⇒ a j ⊕ ak ̸= u⌈ j/2⌉ {0, 1}n

if v ̸= 1| Pb | , if v = 1| Pb | .

Here v serves as mask, which indicates on which pairs of the chosen pairing (P0 or P1 , depending on b) a specific parity constraint is checked. The set contains only bit-strings which satisfy the parity constraints on all pairs that are checked and if the mask is trivial, the set contains all possible bit-strings. To justify this choice of sets we have to look at the behavior of our Clifford operators on the four Bell states (by Eq. (3.2)).

−σG ⊗ σF |Φ00 ⟩ = |Φ00 ⟩,

σG ⊗ σF |Φ10 ⟩ = |Φ10 ⟩,

σG ⊗ σG |Φ01 ⟩ = |Φ01 ⟩,

−σG ⊗ σG |Φ11 ⟩ = |Φ11 ⟩. 84

(4.44)

From there the pattern is clear: if the ZZ outcome (corresponding to v) is 1, we are in the single-observable case and the parity of the pair directly corresponds to the XX outcome. If the ZZ outcome is 0, we are in the mixed-observable case and the parity of the pair is opposite of the XX outcome. The S(u,v),b set encodes these constraints in the single-observable case and the R(u,v),b set does the same in the mixed-observable setting. Definition 4.10 (G and GF pair projectors). For a decrypted Alice answer (u, v) (for the Bell measurement question) and pairing index b ∈ {0, 1}, we define   (u,v) a⊕k a⊕k τ̃G,b = ∑ ∑ τG ⊕ τ G ⊗ |k⟩⟨k| ⊗ 1 a∈S(u,v),b k ∈{0,1}n

and (u,v)

τ̃GF,b = where



∑

∑

a∈ R(u,v),b k ∈{0,1}n

 a⊕k a⊕k ⊗ |k⟩⟨k| ⊗ 1 τGF ⊕ τ GF

 a  a τGF = ∏ τGai i · ∏ τF j i∈ I

j∈ J

j

with I = {2i − 1 | i ∈ [⌊(n + 1)/2⌋]} and J = {2i | i ∈ [⌊n/2⌋]}. Lemma 4.23. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 to 4 of the compiled Clifford test, obtained from Protocol 11, it holds that for all b ∈ {0, 1}:

∑ τ̃G,b

−1

∑ τ̃GF,b

−1

Dec(α)

α

and Dec(α)

α

2 Enc( Pb )

V†

Enc( Pb )

V†

Vψα 2 Vψα

≤ O(ε + η (λ)),

≤ O(ε + η (λ)),

where V is the isometry from Definition 4.6. Proof. Fix b ∈ {0, 1}. From success in the Clifford test and Lemma 4.21, taking q = Pb , we have for all distributions µ over {0, 1}n E ∥VG ( a) − (σG ( a) ⊕ σ G ( a)) ⊗ ΛG ( a))V ∥2ψEnc(Pb ) ≤ O(ε + η (λ)),

a∼µ

and similarly for F ( a), where Λ F ( a) = ΛG ( a) = ∑k (−1) a·k |k⟩⟨k | ⊗ 1. Define a⊕k τ̃Ga := ∑(τGa⊕k ⊕ τ G ) ⊗ |k⟩⟨k| ⊗ 1. k

By Parseval (Corollary A.1 with µ a uniform expectation over a ∈ {0, 1}n ):

∑ ∥VG a − τ̃Ga V ∥2ψ ( ) ≤ O(ε + η (λ)). a

(4.45)

Enc Pb

By success in the pure-vs-mixed basis test, we know from Lemma 4.10 that for any distribution µ on {0, 1}n E

a∼µ

W̃ ( a) − G ( a( I ) ) F ( a( J ) )

2 ψEnc( Pb )

≤ O ( ε ) + η ( λ ),

where I ⊂ [n] is the set of odd indices, J ⊂ [n] is the set of even indices and we define W̃ ∈ { G, F }n as the string of alternating G and F symbols, starting with G. Chaining this with the Clifford test guarantee and the automatic self-consistency of F, a routine calculation yields E

a∼µ

V W̃ ( a) − ((σG ( a( I ) )σF ( a( J ) ) ⊕ σ G ( a( I ) )σ F ( a( J ) )) ⊗ ΛG ( a))V 85

2 ψEnc( Pb )

≤ O(ε + η (λ)).

a

ai · ∏ j∈ J τF,jj and define Let P a = ∏i∈ I τG,i a := ∑( P a⊕k ⊕ P τ̃GF

a⊕k

) ⊗ |k⟩⟨k| ⊗ 1.

k

Applying Parseval again gives a V ψ ( ) ≤ O(ε + η (λ)). ∑ V W̃ a − τ̃GF 2

(4.46)

Enc Pb

a

a } The families {τ̃Ga } a∈{0,1}n and {τ̃GF a∈{0,1}n are PVMs. For the first family this follows from the a fact that {τG } a is a PVM. For the second family, it follows from the fact that { P a } a is a PVM (the G and F projectors act on disjoint qubits).

Since the sign consistency test succeeds with probability 1 − O(ε), we have

∑ ∑

 Enc( Pb )  Tr G a ψα ≥ 1 − O ( ε ),

∑

and

∑

 Enc( Pb )  Tr W̃ a ψα ≥ 1 − O(ε), (4.47)

α a∈ RDec(α),b

α a∈SDec(α),b

where S(u,v),b and R(u,v),b are defined as in Definition 4.9. We will now transition to bounding the support of the state on the complementary, rejected, outcomes instead of summing the distance to the identity over all accepted outcomes. By Definition 4.10, Dec(α) τ̃G,b = ∑ τ̃Ga . a∈SDec(α),b

Since {τ̃Ga } a is a PVM, orthogonality and completeness give

∑ τ̃G,b

Dec(α)

α

−1

2 Enc( Pb )

Vψα

V†

=∑

∑

∥τ̃Ga V ∥2 Enc(Pb )

≤ 2∑

∑

∥τ̃Ga V − VG a ∥2 Enc(Pb ) + 2 ∑

ψα

α a/ ∈SDec(α),b

α a/ ∈SDec(α),b

ψα

∑

α a/ ∈SDec(α),b

∥VG a ∥2 Enc(Pb ) ψα

≤ 2 ∑ ∥τ̃Ga V − VG a ∥2ψEnc(Pb ) a    a Enc( Pb )   + 2 1 − ∑ ∑ Tr G ψα α a∈SDec(α),b

≤ O(ε + η (λ)). Here the second-to-last inequality uses linearity in the state, V † V = 1, and the fact that the summands are nonnegative; the final inequality follows from Eqs. (4.45) and (4.47). This proves the first claim. For the mixed-observable case, we analogously have by Definition 4.10 Dec(α)

τ̃GF,b

∑

=

a∈ RDec(α),b

86

a τ̃GF .

a } gives Using the complementary outcomes of the PVM {τ̃GF a

∑ τ̃GF,b

Dec(α)

α

−1

2 Enc( Pb )

Vψα

V†

=∑

∑

≤ 2∑

∑

a V ∥2 Enc(Pb ) ∥τ̃GF ψα

α a/ ∈ RDec(α),b

a τ̃GF V − V W̃ a ψEnc(Pb ) + 2 ∑ 2

α a/ ∈ RDec(α),b

α

∑

α a/ ∈ RDec(α),b

2

V W̃ a ψEnc(Pb ) α

a ≤ 2 ∑ τ̃GF V − V W̃ a ψEnc(Pb ) a    a Enc( Pb )   + 2 1 − ∑ ∑ Tr W̃ ψα 2

α a∈ RDec(α),b

≤ O(ε + η (λ)), where the last line follows from Eqs. (4.47) and (4.46). This proves the second claim. Sign ambiguity characterization It remains to fix the remaining global sign choice on the F and G observables to +, which is the whole reason for having the correlation test. The design was informed by the following observation: by performing Bell basis measurements on her qubits, Alice performs entanglement swapping, transforming the inter-prover entanglement into intra-prover entanglement on Bob’s side, if we consider the nonlocal view for a moment. From Alice’s reported measurement outcomes, the verifier knows which Bell state every pair on Bob’s side collapsed into. This information is crucial, because by Eq. (4.44) the verifier knows exactly which correlations should be present if Bob, for example, performs a G measurement on every qubit separately. If within a checked pair Bob would be using −σG and σG , the verifier could detect this through a correlation mismatch. This is also why we need to use the brick-wall pairings, since with one type of pairing alone, Bob could still use inconsistent sign choices across distinct pairs, testing these staggered pairings allows the verifier to force Bob to use a consistent sign choice for all of its G observables, either all + or all −. The two lemmas above are critical in concluding that the prover has to be consistent in his sign choice. The first tells us that Alice’s post-measurement state is really projected into a Bell basis eigenstate; the second identifies which operations Bob implements when asked to perform an all G or a mixed G and F measurement, and that he passes the verifier’s consistency checks. Combining these facts, we can use Equation (4.44) to extract information about the sign choice of the prover. Lemma 4.24. For any b ∈ {0, 1} and (u, v) ∈ {0, 1}| Pb | × {0, 1}| Pb | , !   (u,v) (u,v) (u,v) τ̃G,b Φb ⊗1 = ∑ 1 ⊗ |k⟩⟨k| ⊗ 1 Φb ⊗ 1 , k ∈Kv,b

 where Kv,b := a ∈ {0, 1}n : a j = ak ∀ ( j, k ) ∈ Pb where v⌈ j/2⌉ = 1 . (u,v)

Proof. Since everything factors into tensor products of pairs, we can analyze the action of τ̃G,b pair by pair. Fix a pair ( j, l ) ∈ Pb and let s = u⌈ j/2⌉ , t = v⌈ j/2⌉ . On positions where v vanishes, the strings in S(u,v),b are unconstrained (because the qubits got projected into a Bell state which requires mixed-observable measurement) and the sum over that set makes projectors sum to identity; we are thus only interested in the case t ̸= 0 (there is a parity constraint on this pair). Let a ∈ S(u,v),b be any bit-string which we are summing over, for which we can define c = a j ⊕ k j

87

and d = al ⊕ k l . Using Eq. (4.44), we compute:  1 (1 + (−1)c+d+s )1 ⊗ 1 + ((−1)c + (−1)d+s )σG,j ⊗ 1 |Φs1 ⟩⟨Φs1 | 4 c = 1{c ⊕ d ⊕ s = 0} (τG,j ⊗ 1) |Φs1 ⟩⟨Φs1 |

c d (τG,j ⊗ τG,l )|Φs1 ⟩⟨Φs1 | =

c = 1{k j ⊕ k l = 0} (τG,j ⊗ 1) |Φs1 ⟩⟨Φs1 |.

where the last line follows from the fact that membership in S(u,v),b guarantees that a j ⊕ al = s. The remaining G projector on qubit j vanishes once we sum over all valid a, since only the parity of the pair is constrained, which leaves two options for the value of c, so the projectors sum to the identity. The same guarantee holds for the complex conjugate block and in both cases, every pair yields an indicator for the parity constraint on k. Tensoring over all pairs in Pb and recalling that σ G = −σF , we can conclude:   a⊕k (u,v) a⊕k ⊕1 (u,v) τ Φ ⊕ τ Φ ⊗ |k⟩⟨k| ⊗ 1 ∑ ∑ F G b b a∈S(u,v),b k ∈{0,1}n

=

∑

∏ 1 { k j ⊕ k l = 0} Φ b

(u,v)

⊗ |k⟩⟨k| ⊗ 1,

k ∈{0,1}n ( j,l )∈ Pb : v⌈ j/2⌉ =1

  (u,v) which is equal to ∑k∈Kv,b 1 ⊗ |k ⟩⟨k | ⊗ 1 Φb ⊗ 1 and thus completes the proof. The identical computation with σF replacing σG (and conjugated Bell states |Φu0 ⟩ replaced by |Φ̃u0 ⟩) yields: Lemma 4.25. For any b ∈ {0, 1} and (u, v) ∈ {0, 1}| Pb | × {0, 1}| Pb | , !   (u,v) (u,v) (u,v) τ̃GF,b Φb ⊗1 = ∑ 1 ⊗ |k⟩⟨k| ⊗ 1 Φb ⊗ 1 , k ∈Kv,b

 where Kv,b := a ∈ {0, 1}n : a j = ak ∀ ( j, k ) ∈ Pb where v⌈ j/2⌉ = 1 . Proof. The argument is identical to Lemma 4.24, except that we now consider a tensor product of two different observables per pair. Here we use R(u,v),b , and unconstrained pairs are indicated by a vanishing entry in v, which explains the appearance of v. Lemma 4.26. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 to 4 of the compiled Clifford test, obtained from Protocol 11, it holds that for all b ∈ {0, 1}: 2 ∑ ∑ ∥1 ⊗ |k⟩⟨k| ⊗ 1∥ Enc(Pb ) † ≤ O(ε + η (λ)), Vψα

α k∈ / KDec(α) ,b

V

1

and

∑

∑

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † ≤ O(ε + η (λ)), Vψα

α k∈ / KDec(α) ,b

V

1

 where Kv,b := a ∈ {0, 1}n : a j = ak ∀ ( j, k ) ∈ Pb where v⌈ j/2⌉ = 1 and V is the isometry from Definition 4.6. Proof. We recall our previous results   2 Dec(α) 1. ∑α Φb ⊗1 −1 Enc( Pb ) † ≤ O ( ε + η ( λ )) (by Lemma 4.22). Vψα

Dec(α)

2. ∑α τ̃G,b

−1

2 Enc( Pb )

Vψα

V†

V

≤ O(ε + η (λ)) (by Lemma 4.23). 88

Dec(α)

3. ∑α τ̃GF,b

−1

2 Enc( Pb )

Vψα

V†

≤ O(ε + η (λ)) (by Lemma 4.23). (u,v)

(u,v)

For W ∈ { G, GF }, we know that τ̃W,b is a projector, thus τ̃W,b

∞

inequality:

∑ (τ̃W,b

Dec(α)

Dec(α)

− 1)(Φb

⊗ 1)

α

α ≤ 2 ∑ τ̃W,b − 1 ∞ Φb 2

≤ 1, and by a triangle

2 Enc( Pb )

Vψα

Dec(α)

V†

⊗1−1

α

2

α + 2 ∑ τ̃W,b − 1 VψEnc(Pb ) V † 2

Enc( Pb )

Vψα

V†

α

α

≤ O(ε + η (λ)). Where we used Item 1 and Item 2 or 3. From Lemma 4.24 and the above:   2   Dec(α) ⊗1 ∑  ∑ 1 ⊗ |k⟩⟨k| ⊗ 1 Φb k∈ / KDec(α) ,b

α

Enc( Pb )

Vψα

V†

Dec(α)



1

=∑  α

2

 

∑

k ∈KDec(α) ,b

1 ⊗ |k ⟩⟨k| ⊗ 1 − 1 Φb

⊗1

Enc( Pb )

1

= ∑ (τ̃G,b

Dec(α)

Vψα Dec(α)

− 1)(Φb

⊗ 1)

α

V†

2 Enc( Pb )

Vψα

V†

≤ O(ε + η (λ)). Using Lemma 4.25 we similarly obtain: 

∑  α

2

 

∑

k∈ / KDec(α) ,b

Dec(α)

1 ⊗ |k ⟩⟨k| ⊗ 1 Φb

⊗1



≤ O(ε + η (λ)) Enc( Pb )

1

Vψα

V†

Now we just need to drop the Bell projector again, which we can do using Item 1 and the same triangle inequality based argument that we used to introduce it (again the pre-factor is a projector with bounded operator norm). The orthogonality of the projectors then immediately completes the proof. Lemma 4.27 (Mismatch set characterization). Let Mb ( a) := {( j, k ) ∈ Pb : a j ̸= ak } denote the set of pairs in Pb on which a has mismatching bits. For any v ∈ {0, 1}| Pb | we have

{ a ∈ {0, 1}n : Mb ( a) ̸= ∅} ⊆ { a ∈ {0, 1}n : a ∈ / Kv,b } ∪ { a ∈ {0, 1}n : a ∈ / Kv,b }. Proof. Take any a ∈ {0, 1}n with Mb ( a) ̸= ∅, then there exists a pair ( j, k ) ∈ Pb for which a j ̸= ak and thus a is either included in { a ∈ / Kv,b } or in { a ∈ / Kv,b }, since v ⊕ v = 1| Pb | , thus every pair is checked in one of the two sets. Lemma 4.28. Let P∗ be any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 to 4 of the compiled Clifford test, obtained from Protocol 11. Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that

∑

k ∈{0,1}n \{0n ,1n }

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(q) V † ≤ O(ε + η (λ)),

where V is the isometry from Definition 4.6. 89

Proof. Fix b ∈ {0, 1}. By Lemma 4.27, we can set v = Dec(α)1 and conclude that

∑

k: Mb (k )̸=∅

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † Vψα

∑

≤

V

∑

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † + Vψα

k∈ / KDec(α) ,b

V

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † . Vψα

k∈ / KDec(α) ,b

1

V

1

This holds for every valid α separately, so we can sum both sides over all α:

∑

∑

α k: Mb (k )̸=∅

≤∑

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † Vψα

∑

α k∈ / KDec(α) ,b

V

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † + ∑ Vψα

V

∑

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2 Enc(Pb ) † Vψα

α k∈ / KDec(α) ,b

1

V

1

≤ O(ε + η (λ)), where the last line follows from the two bounds in Lemma 4.26. The set {k : Mb (k ) ̸= ∅} does not depend on α, and the state-dependent norm is linear in the state, so the left-hand side equals

∑

∑ ∥1 ⊗ |k⟩⟨k| ⊗ 1∥Vψ ( ) V = 2

k: Mb (k )̸=∅ α

Enc Pb α

†

∑

k: Mb (k )̸=∅

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(Pb ) V †

= ∥1 ⊗ Πb ⊗ 1∥2VψEnc(Pb ) V † , with Πb :=

∑

|k⟩⟨k|.

k: Mb (k )̸=∅

Expanding out the state-dependent norm, defining the POVM element Mb := V † Πb V and then swapping out the state by Lemma 3.4, we obtain:

∥1 ⊗ Πb ⊗ 1∥2VψEnc(q) V † ≤ O(ε + η (λ)),

∀ b ∈ {0, 1}.

The only k ∈ {0, 1}n for which both M0 (k ) = ∅ and M1 (k ) = ∅ are 0n and 1n , thus {k : M0 (k ) ̸= ∅} ∪ {k : M1 (k ) ̸= ∅} = {0, 1}n \ {0n , 1n }, and we can conclude:

∑

k ∈{0,1}n \{0n ,1n }

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(q) V † ≤

∑

k: M0 (k )̸=∅

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(q) V † +

∑

k: M1 (k )̸=∅

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(q) V †

≤ O(ε + η (λ)). Corollary 4.4. Let P∗ be any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in Items 1 to 4 of the compiled Clifford test, obtained from Protocol 11. Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that:

∥1 ⊗ (ΛG ( a) − ∆G ( a))∥2VψEnc(q) V † ≤ O(ε + η (λ)). | a|

where ΛG ( a) = ∑k∈{0,1}n (−1) a·k |k⟩⟨k | ⊗ 1 and ∆G ( a) = σZ ⊗ 1, here the Pauli Z operator acts only on the first qubit of the k register and V is the isometry from Definition 4.6. Proof. In the PSD order we have 1 ⊗ (ΛG ( a) − ∆G ( a))2 ⪯ 4

∑

k ∈{0,1}n \{0n ,1n }

90

1 ⊗ |k ⟩⟨k| ⊗ 1,

which immediately allows us to conclude that

∥1 ⊗ (ΛG ( a) − ∆G ( a))∥2VψEnc(q) V † ≤ 4

∑

k ∈{0,1}n \{0n ,1n }

∥1 ⊗ |k⟩⟨k| ⊗ 1∥2VψEnc(q) V † .

Using Lemma 4.28 we obtain the desired bound. Using Corollary 4.4 and the fact that the prover passes the Clifford subtest, we can conclude the following Lemma 4.29. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 4 of the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exists a complex Hilbert space H′ of finite dimension d′ = d|Cn |2 and an efficient isometry V : H → H′ (from Definition 4.6) such that for all W ∈ { X, Y, Z, G, F }, all distributions µ on {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that 2

E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ ∆W ( a))V ∥ψEnc(q) ≤ O(ε + η (λ)),

a∼µ

| a|

where ∆ X ( a) = ∆Y ( a) = ∆ Z ( a) = 1 and ∆ F ( a) = ∆G ( a) = σZ ⊗ 1 for all a ∈ {0, 1}n . Proof. Combining Lemma 4.21 and Corollary 4.4 by a triangle inequality. Now that the prover’s freedom to choose a sign has been reduced to a global sign, we can execute a CHSH game, which by the form of the F and G observables in terms of the X and Y observables, is ideally suited to distinguish between a positive or negative global sign choice. Lemma 4.30. For any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability ω ∗ − ε in Items 1 to 5 of the compiled Clifford test, obtained from Protocol 11, it holds under the isometry from Definition 4.6 that for all q ∈ Q A , all W ∈ { X, Y, Z, F, G } and all distributions µ over {0, 1}n there exists a cryptographically small function η (λ) such that: E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ 1)V ∥2ψEnc(q) ≤ O(ε + η (λ)).

a∼µ

Here ω ∗ = 15 (4 + cos2 ( π8 )) is the optimal winning probability of Items 1 to 58 : an honest prover achieves it up to a cryptographically small loss, and no efficient prover can exceed it by more than η (λ) (cf. Eq. (4.49)). Remark 4.3. The CHSH test of protocol 11 is designed under the assumption that Alice applies the transpose (in the computational basis) of the operators that she is asked to measure. This indeed has to be the case, by the answer equality between Alice and Bob, enforced by the consistency test (i.e. we enforce Y ⊗ Y |ψ⟩ = |ψ⟩ instead of the natural Y ⊗ Y |ψ⟩ = −|ψ⟩). Proof. We begin with the completeness of the CHSH game (protocol 11 subtest 5). A simple calculation confirms that if both parties share n EPR pairs, Alice measures −σY and σX , and Bob measures σF and σG , the Tsirelson bound is achieved, i.e. ideal provers win with probability cos2 ( π8 ) in subtest 5. Since all other subtests have perfect completeness, honest provers win with probability ω ∗ = 15 (4 + cos2 ( π8 )), up to a cryptographically small correctness loss of the QFHE scheme; conversely, Eq. (4.49) below shows that no efficient prover can win with probability greater than ω ∗ + η (λ). We next give a short sum-of-squares proof that the quantum value of the CHSH game is preserved under compilation with KLVY. This proof is inspired by [NZ23], however, it follows 8 It should be possible to bring completeness exponentially close to 1 by exploiting the fact that we are effectively

running n CHSH tests in parallel with the large-answer measurements.

91

a simplified approach, without pseudo-expectations. The argument applies to any flavor of CHSH game (different game polynomial); we carry it out for our choice of game polynomial, since this version of the game certifies the operators that we are interested in. Throughout, we use the convention that Alice implements the transpose of the operation on Bob’s side, as this is the only way to achieve completeness in the consistency test. The probability that the verification predicate is satisfied at any position i ∈ [n], is given by  h i h i 1 1 Enc(Y ) Enc( X ) Dec(α)1 Pr[win] = + ∑(−1) Tr ( G (e1 ) + F (e1 ))ψα + Tr ( G (e1 ) − F (e1 ))ψα . 2 8 α (4.48) A direct calculation gives 2 1 p2 = ∑ √ ( G (e1 ) + F (e1 )) − (−1)Dec(α)1 1 Enc(Y ) 2 α ψα h i 1 h i √ Enc(Y ) Enc(Y ) + ∑ Tr { G (e1 ), F (e1 )}ψα , = 2 − 2 ∑(−1)Dec(α)1 Tr ( G (e1 ) + F (e1 ))ψα 2 α α

and 2 1 q2 = ∑ √ ( G (e1 ) − F (e1 )) − (−1)Dec(α)1 1 Enc( X ) 2 α ψα i 1 h i h √ Enc( X ) Enc( X ) − ∑ Tr { G (e1 ), F (e1 )}ψα , = 2 − 2 ∑(−1)Dec(α)1 Tr ( G (e1 ) − F (e1 ))ψα 2 α α

thus, plugging in Eq. (4.48) p2 + q2 = 4(1 +

√

 i √ 1 h 2) − 8 2 Pr[win] + Tr { G (e1 ), F (e1 )} ψEnc(Y ) − ψEnc(X ) , 2

we note that the operator M = 12 { G (e1 ), F (e1 )} is a Hermitian LCU and has bounded eigenvalues. Hence, we can use it as POVM in Lemma 3.8 and let D1 , D2 be the appropriate point distributions. The lemma then guarantees that h  i h  i 1 ≤ η ( λ ). Tr M ψEnc(Y ) − ψEnc(X ) = Tr { G (e1 ), F (e1 )} ψEnc(Y) − ψEnc(X ) 4 Plugging this into the expression and rearranging, we get √ π √ 1 1 2 1 2 2 Pr[win] = √ (1 + 2) − √ ( p + q ) + η (λ) ≤ + + η (λ) = cos2 + η (λ), (4.49) 2 4 8 2 2 8 2 thus the quantum value of the compiled game respects the Tsirelson bound, up to cryptographically small advantage. By the Lemma 4.29 we know that for all W ∈ { X, Y, Z, F, G }, all q ∈ Q A and all distributions µ over {0, 1}n : E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ ∆W ( a))V ∥2ψEnc(q) ≤ O(ε + η (λ)),

a∼µ

(4.50)

| a|

where ∆ X ( a) = ∆Y ( a) = ∆ Z ( a) = 1 and ∆ F ( a) = ∆G ( a) = σZ ⊗ 1. Using the ε-self-consistency of ({ X, Y, Z }, U3 ) as certified by Item 1 (specifically the SLC within its first CREL subtest) of protocol 11, Lemma 4.3 gives 2

∑ X (e1 ) − (−1)Dec(α) ψ ( ) ≤ O(ε). 1

Enc X α

α

92

(4.51)

From the lemma assumption, we know that the prover succeeds in the CHSH subtest with probability at least cos2 ( π8 ) − O(ε). Hence, we can conclude that q =∑ 2

α

2 1 Dec(α)1 √ ( G (e1 ) − F (e1 )) − (−1) 1 ≤ O(ε + η (λ)). Enc( X ) 2 ψα

Combining this with Eq. (4.51) through a triangle inequality, we get 2 1 √ ( G (e1 ) − F (e1 )) − X (e1 ) ≤ O(ε + η (λ)). 2 ψEnc(X )

Since the norm argument is a LCU, we can apply Corollary 3.1 to switch out the state for any ψEnc(q) . Pushing this through the isometry using Eq. (4.50), we get

∥1 ⊗ (σZ − 1) ⊗ 1∥2VψEnc(q) V † ≤ O(ε + η (λ)), where the first identity has the dimension of twice the qubit register (i.e. acting on (C2 )⊗n ⊕ (C2 )⊗n ). Combining this with Eq. (4.50) completes the proof. What remains is to extend our characterization from pure-basis to mixed-basis observables. This can be achieved in a very modular way by invoking the mixed-versus-pure basis test (protocol 5), which yields the following theorem: Theorem 4.1. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability ω ∗ − ε in the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exists a complex Hilbert space H′ of finite dimension d′ = d|Cn |2 and an efficient isometry V : H → H′ (from Definition 4.6) such that for all distributions µ on {0, 1}n and all q ∈ Q A there exists a cryptographically small function η (λ) such that E

E

W̃ ∈{ X,Y,Z,F,G }n a∼µ

2

V W̃ ( a) − ((σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1)V ψEnc(q) ≤ O(ε + η (λ)).

Here ω ∗ = 16 (5 + cos2 ( π8 )) is the optimal winning probability of the Clifford test (an honest prover achieves it up to a cryptographically small loss, and no efficient prover can exceed it by more than η (λ)). Proof. An overall winning probability of ω ∗ − ε = 61 (5 + cos2 ( π8 )) − ε in the six equally weighted items of protocol 11 guarantees (using the trivial bound of 1 on the CHSH item) that the prover wins Items 1 to 5 with probability at least 15 (4 + cos2 ( π8 )) − O(ε), and each of the perfectcompleteness items (in particular Item 6, the mixed-versus-pure basis test) with probability 1 − O(ε + η (λ)), where the η (λ) term comes from bounding the CHSH item by the compiled Tsirelson bound cos2 ( π8 ) + η (λ) of Eq. (4.49). Hence we can invoke Lemma 4.30 and conclude that for all W ∈ { X, Y, Z, F, G }, any distribution µ over {0, 1}n and all q ∈ Q A E ∥VW ( a) − ((σW ( a) ⊕ σW ( a)) ⊗ 1)V ∥2ψEnc(q) ≤ O(ε + η (λ)) ,

a∼µ

(4.52)

We introduce the following notation JW := {i ∈ [n] : W̃i = W }, where we leave the W̃-dependence implicit. The following chain of approximate equalities holds under implicit expectation over a ∼ µ and over W̃ ∈ { X, Y, Z, F, G }n (uniform): VX ( a( JX ) ) Z ( a( JZ ) )Y ( a( JY ) ) F ( a( JF ) ) G ( a( JG ) )

≈ε̃ (σX ( a( JX ) ) ⊗ 1)VZ ( a( JZ ) )Y ( a( JY ) ) F ( a( JF ) ) G ( a( JG ) ) ≈ε̃ (σX ( a( JX ) )σZ ( a( JZ ) ) ⊗ 1)VY ( a( JY ) ) F ( a( JF ) ) G ( a( JG ) ) ≈ε̃ (σX ( a( JX ) )σZ ( a( JZ ) )(σY ( a( JY ) ) ⊕ σY ( a( JY ) )) ⊗ 1)VF ( a( JF ) ) G ( a( JG ) ) ≈ε̃ (σX ( a( JX ) )σZ ( a( JZ ) )(σY ( a( JY ) )σF ( a( JF ) ) ⊕ σY ( a( JY ) )σF ( a( JF ) )) ⊗ 1)VG ( a( JG ) ) ≈ε̃ (σX ( a( JX ) )σZ ( a( JZ ) )(σY ( a( JY ) )σF ( a( JF ) )σG ( a( JG ) ) ⊕ σY ( a( JY ) )σF ( a( JF ) )σG ( a( JG ) )) ⊗ 1)V, 93

where ε̃ = ε + η (λ) and every line follows by Eq. (4.52), where we explicitly need the fact that this holds for arbitrary distributions for a. We also used left unitary invariance and ε-selfconsistency of ({W }, U1 ) for W ∈ { X, Y, Z, F, G }, combined with Corollary 4.3. From this we can conclude that for all q ∈ Q A and under expectation over a ∼ µ and W̃ ∈ { X, Y, Z, F, G }

∏

W ( a( JW ) ) ≃ε+η (λ) (σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1.

(4.53)

W ∈{ X,Y,Z,F,G }n

It remains to bound the following term E

E

W̃ ∈{ X,Y,Z,F,G }n a∼µ

! 2

∏

V W̃ ( a) − V

W (a

( JW )

)

W ∈{ X,Y,Z,F,G }

ψEnc(q)

By left unitary invariance, because W̃ ( a) is linear and because

=

∏

E

E

W̃ ∈{ X,Y,Z,F,G }n a∼µ

! W̃ ( a( JW ) )

−

W ∈{ X,Y,Z,F,G }

S

W ∈{ X,Y,Z,F,G } JW = [ n ]:

∏

! 2 W ( a( JW ) )

W ∈{ X,Y,Z,F,G }

ψEnc(q)

≤ O(ε + η (λ)),

(4.54)

here the final upper bound is obtained by repeatedly using Lemma 4.10, since the prover succeeds in MBT ({ X, Y, Z, F, G }, n, U5n ). Furthermore we used left unitary invariance and compiled prover switching (Lemma 4.5), since the wrapped SLC subtests of CREL guarantee ε-self-consistency of ({W }, U1 ) for W ∈ { X, Y, Z, F, G }, by Lemma 4.1. Combining Eq. (4.53) and Eq. (4.54), yields E

E

W̃ ∈{ X,Y,Z,F,G }n a∼µ

2

V W̃ ( a) − ((σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1)V ψEnc(q) ≤ O(ε + η (λ)),

which completes the proof.

4.4

State characterization

We want to show that during both parts of the interaction (encrypted and unencrypted), the prover must be consistently using the canonical or complex conjugated irreducible representation of the extended Pauli group. The following lemma plays an important part in this as it shows shows that coherences in the flag register are computationally indetectable. Lemma 4.31. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 4 of the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exist complex Hilbert spaces H′ , Ĥ of finite dimension and an efficient isometry V : H → H′ ∼ = (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6) such that for every uniformly efficient family of two-outcome POVMs { Mq , 1 − Mq }q∈Q A in L(H′ ), indexed by the Alice question, and every efficiently sampleable distribution ν over Q A , there exists a cryptographically small function η (λ) such that h  i E Tr Mq (1 ⊗ σZ ⊗ 1)VψEnc(q) V † (1 ⊗ σZ ⊗ 1) − VψEnc(q) V † ≤ O((ε + η (λ))1/2 ).

q∼ν

Proof. Throughout the proof write Z̃ := 1 ⊗ σZ ⊗ 1 and fix a specific a ∈ {0, 1}n with | a| = 1. From Lemma 4.29 we know that there exists an efficient isometry V : H → H ′ ∼ = ( C2 ) n ⊗ C2 ⊗ Ĥ, such that for all W ∈ { X, Y, Z } and all q ∈ Q A there exists a cryptographically small function η (λ) with | a|

VW ( a) − (σW ( a) ⊗ ΣW ⊗ 1)V 94

2 ψEnc(q)

≤ O(ε + η (λ)),

with Σ X = Σ Z = 1 and ΣY = σZ . Here we used the identification A ⊕ A ∼ = A ⊗ C2 and the fact that for W ∈ { X, Y, Z } the complex conjugate becomes a scalar factor on the second system. | a| 2 The norm is of the isometry form ∥VW ( a) − NV ∥ψEnc(q) with W ( a) and N := σW ( a) ⊗ ΣW ⊗ 1 uniformly efficient unitaries (independent of the Alice question) on H and H′ respectively, so Corollary 3.2 applied with D1 a point distribution on an arbitrary fixed question and D2 sampling q ∼ ν upgrades the bound to an expectation over ν, with a single cryptographically small function depending on ν: E

q∼ν

| a|

VW ( a) − (σW ( a) ⊗ ΣW ⊗ 1)V

2 ψEnc(q)

≤ O(ε + η (λ)).

(4.55)

By Cauchy–Schwarz, for every family of operators { Nq } with Nq ≤ 1 and every W ∈ { X, Y, Z }, h  i | a| | a| Tr Nq VW ( a)ψEnc(q) W ( a)V † − (σW ( a) ⊗ ΣW ⊗ 1)VψEnc(q) V † (σW ( a) ⊗ ΣW ⊗ 1) | a|

≤ 2 VW ( a) − (σW ( a) ⊗ ΣW ⊗ 1)V

ψEnc(q)

.

Taking the expectation over q ∼ ν and using E f ≤ E | f | together with Jensen’s inequality, q Eν ∥·∥ψEnc(q) ≤ Eν ∥·∥2ψEnc(q) , we obtain with Eq. (4.55) that i h  | a| | a| E Tr Nq VW ( a)ψEnc(q) W ( a)V † − (σW ( a) ⊗ ΣW ⊗ 1)VψEnc(q) V † (σW ( a) ⊗ ΣW ⊗ 1)

q∼ν

≤ O((ε + η (λ))1/2 ).

(4.56)

Furthermore, for every uniformly efficient family of POVM elements { Nq }q in L(H′ ) the family {V † Nq V }q is a uniformly efficient family of POVM elements in L(H) (V is an efficient isometry and 0 ⪯ V † Nq V ⪯ V † V = 1), so Lemma 4.7 (with the ε-self-consistent question distributions certified by the consistency test, Lemma 4.1) lets us insert or remove the observables X ( a), Z ( a) and Y ( a) around ψEnc(q) at cost O(ε1/2 + η (λ)) in the signed average over q ∼ ν. With this we can make the following observation: h i E Tr Mq Z̃VψEnc(q) V † Z̃ q∼ν h i ≈√ε+η (λ) E Tr Mq Z̃VX ( a)ψEnc(q) X ( a)V † Z̃ by Lemma 4.7 q∼ν h i ≈(ε+η (λ))1/2 E Tr (σX ( a) ⊗ σZ ⊗ 1)† Mq (σX ( a) ⊗ σZ ⊗ 1)VψEnc(q) V † by Eq. (4.56) q∼ν h i ≈√ε+η (λ) E Tr (σX ( a) ⊗ σZ ⊗ 1)† Mq (σX ( a) ⊗ σZ ⊗ 1)VZ ( a)ψEnc(q) Z ( a)V † by Lemma 4.7 q∼ν h i ≈(ε+η (λ))1/2 E Tr (σY ( a) ⊗ σZ ⊗ 1)† Mq (σY ( a) ⊗ σZ ⊗ 1)VψEnc(q) V † by Eq. (4.56) q∼ν h i ≈(ε+η (λ))1/2 E Tr Mq VY ( a)ψEnc(q) Y ( a)V † by Eq. (4.56) q∼ν h i ≈√ε+η (λ) E Tr Mq VψEnc(q) V † . by Lemma 4.7 q∼ν

In the second-to-last step σY ( a) = iσX ( a)σZ ( a) is used and Eq. (4.56) is applied with W = Y: since | a| = 1, the post-isometry action of Y ( a) is exactly σY ( a) ⊗ ΣY ⊗ 1 = σY ( a) ⊗ σZ ⊗ 1. All families of POVM elements appearing on the left of the traces are uniformly efficient in q, since Mq is and all conjugating unitaries are fixed efficient operators. Combining the six steps yields h i h i Enc(q) † Enc(q) † E Tr Mq Z̃Vψ V Z̃ − E Tr Mq Vψ V ≤ O((ε + η (λ))1/2 ), q∼ν

q∼ν

which completes the proof. 95

The encryption forbids the prover from centrally keeping track of his sign choice. The consistency can thus only be achieved by something similar to an entangled pair, which keeps track of the choice, and is allowed by the encryption as it is ‘transparent’ to entanglement (cf. the correctness with auxiliary input property in [KLVY23]). Since Bob only has partial information about this shared system, this effectively (under computational assumptions) dephases the ‘flag’ register, which allows us to conclude that the prover can’t be applying a coherent superposition of the canonical and the complex conjugate of the Pauli Y observable. Corollary 4.5. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in Items 1 to 4 of the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exist complex Hilbert spaces H′ , Ĥ of finite dimension and an efficient isometry V : H → H′ ∼ = (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6) such that for every uniformly efficient family of two-outcome POVMs { Mq , 1 − Mq }q∈Q A in L(H′ ) and every efficiently sampleable distribution ν over Q A , there exists a cryptographically small function η (λ) such that h  i E Tr Mq D Z (VψEnc(q) V † ) − VψEnc(q) V † ≤ O((ε + η (λ))1/2 ),

q∼ν

where D Z is the dephasing operation on the phase ambiguity flag register, i.e.

D Z (ρ) =

1 (ρ + (1 ⊗ σZ ⊗ 1)ρ(1 ⊗ σZ ⊗ 1)) . 2

Proof. Inserting the definition of D Z , h  i E Tr Mq D Z (VψEnc(q) V † ) − VψEnc(q) V †

q∼ν

=

h  i 1 E Tr Mq (1 ⊗ σZ ⊗ 1)VψEnc(q) V † (1 ⊗ σZ ⊗ 1) − VψEnc(q) V † , 2 q∼ν

so the claim follows directly from Lemma 4.31 (absorbing the factor 12 into the asymptotic notation). The next lemma is an important tool for our later analysis, as it allows us to decouple the qubit register from the verifier’s encrypted question and the prover’s encrypted answer. It shows that, up to efficient distinguishers, the post-Alice state satisfies an important property, which would be expected from EPR pairs being shared between the two parts of the prover. It is the closest we come to some kind of replacement for certifying EPR pairs (inter-prover), as can be achieved in the nonlocal setting. Lemma 4.32. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability 1 − ε in the compiled Clifford group test CLIFF - GROUP ( X, Y, Z, F, G, n), obtained from protocol 10, there exists a complex Hilbert space H′ of finite dimension and an efficient isometry V : H → (C2 )n ⊗ H ′ (from Definition 4.6) such that for all uniformly efficient POVM families { Mα , 1 − Mα }α and all q ∈ Q A , there exists a cryptographically small function η (λ) such that 

∑ Tr Mα α



1 Enc(q) † Vψα V − n ⊗ Tr1 2

h

Enc(q) † Vψα V

i

≤ O((ε + η (λ))1/2 ),

where Tr1 [·] denotes the partial trace over the (C2 )n register. In words, the post-isometry post-Alice state is computationally indistinguishable (with some advantage) from being fully mixed on the qubit register. Proof. Let q ∈ Q A and the uniformly efficient POVM family { Mα , 1 − Mα }α with 0 ⪯ Mα ⪯ 1 be arbitrary. By Lemma 4.21, for W ∈ { X, Z } and all a ∈ {0, 1}n ,

∥VW ( a) − (σW ( a) ⊗ 1)V ∥2ψEnc(q) ≤ O(ε + η (λ)) 96

By Cauchy–Schwarz, the triangle inequality, and the above we have for any Mα with ∥ Mα ∥∞ ≤ 1, W ∈ { X, Z } and any a ∈ {0, 1}n h  i Enc(q) Enc(q) ∑ Tr Mα VW (a)ψα W (a)V † − (σW (a) ⊗ 1)Vψα V † (σW (a) ⊗ 1) α

∑ ∥VW (a) − (σW (a) ⊗ 1)V ∥ψ ( ) 2

≤2

α

!1/2

Enc q α

2

∑ Mα† VW (a) ψ ( )

!1/2

Enc q α

α

≤ O((ε + η (λ))1/2 ).

(4.57)

With this we can make the following observation h i Enc(q) † E ∑ Tr Mα Vψα V a,b α h i Enc( X ) † ≈η (λ) E ∑ Tr Mα Vψα V a,b α h i Enc( X ) X ( a )V † ≈√ε E ∑ Tr Mα VX ( a)ψα a,b α h i Enc( X ) † ≈√ε+η (λ) E ∑ Tr Mα (σX ( a) ⊗ 1)Vψα V (σX ( a) ⊗ 1) a,b α

by Lemma 3.3 by Lemma 4.4 by Eq. (4.57)

Na,α

i hz }| { Enc( Z ) † V ≈η (λ) E ∑ Tr (σX ( a) ⊗ 1) Mα (σX ( a) ⊗ 1) Vψα a,b α h i Enc( Z ) ≈√ε E ∑ Tr Na,α VZ (b)ψα Z ( b )V † a,b α i h Enc( Z ) † V (σZ (b) ⊗ 1) ≈√ε+η (λ) E ∑ Tr Na,α (σZ (b) ⊗ 1)Vψα a,b α h i Enc(q) † V ≈η (λ) E ∑ Tr M(′ a,b),α Vψα a,b α

by Lemma 3.3 by Lemma 4.4 by Eq. (4.57) by Lemma 3.3

where M(′ a,b),α := (σZ (b)σX ( a) ⊗ 1) Mα (σX ( a)σZ (b) ⊗ 1). Evaluating the uniform expectation over a, b ∈ {0, 1}n and noticing that only M(′ a,b),α depends on a, b, we obtain

∑ Tr

h

Enc(q) † Mα Vψα V

i

≈√

α

ε+η (λ)

∑ Tr



α

  1 Enc(q) † ⊗ Tr1 [ Mα ] Vψα V , 2n

(4.58)

by the Pauli twirl identity: E

a,b∈{0,1}n

(σZ (b)σX ( a) ⊗ 1) Mα (σX ( a)σZ (b) ⊗ 1) =

1 ⊗ Tr1 [ Mα ]. 2n

Finally, we can use Eq. (4.58) to conclude that

∑ Tr

h

Enc(q) † Mα Vψα V

α

i

≈√



ε+η (λ)

∑ Tr Mα α



h i 1 Enc(q) † ⊗ Tr Vψ V 1 α 2n

which follows from the following property of the partial trace Tr [(1 ⊗ Tr1 [ A]) B] = Tr [ A (1 ⊗ Tr1 [ B])] , completing the proof.

97

 ,

An important part of obtaining a remote state preparation guarantee in our setting is characterizing the post-Alice state. From the different rigidity tests we already obtained characterizations of the Bob observables in the previous section. Now we will relate these observable characterizations to a state characterization, which we can do through the state-dependence of the norm we are using (Definition 3.2). Lemma 4.33. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability ω ∗ − ε in the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exists a complex Hilbert space Ĥ of finite dimension, an efficient isometry V : H → (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6), and a cryptographically small function η (λ) such that E ∑ PW̃

Dec(α)

W̃ α

Enc(W̃ )

Vψα

Dec(α)

V † PW̃

Enc(W̃ )

− Vψα

V†

1

≤ O((ε + η (λ))1/2 ),

where ω ∗ = 16 (5 + cos2 ( π8 )) is the optimal winning probability of the Clifford test (an honest prover achieves it up to a cryptographically small loss, and no efficient prover can exceed it by more than η (λ), cf. Lemma 4.30) and a a PW̃ = ∑ τW̃,k ⊗ |k⟩⟨k| ⊗ 1, k ∈{0,1}

a a a , τa with τW̃,0 = τW̃ = τ W̃ . In words, the post-isometry post Alice measurement state is information W̃,1

theoretically close to fully lying inside the image of the Bob projectors corresponding to the reported outcome of the requested measurement. Proof. From Theorem 4.1 we know that there exists an isometry V : H → ((C2 )n ⊗ H ′ )⊕2 , such that for all q ∈ Q A there exists a cryptographically small function η (λ) with E

2

E

V W̃ ( a) − ((σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1)V ψEnc(q) ≤ O(ε + η (λ)),

W̃ ∈{ X,Y,Z,F,G }n a∈{0,1}n

2

choosing some fixed q ∈ Q A . This is of the isometry form V W̃ ( a) − NV ψEnc(q) with W̃ ( a) and N := (σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1 a uniformly efficient family of unitaries, parameterized by a and W̃, so Corollary 3.2 lets us switch out the state and conclude that E

2

E

V W̃ ( a) − ((σW̃ ( a) ⊕ σW̃ ( a)) ⊗ 1)V ψEnc(W̃ ) ≤ O(ε + η (λ)),

W̃ ∈{ X,Y,Z,F,G }n a∈{0,1}n

applying Corollary A.1 (Parseval’s identity) yields

∑ V W̃ a − ((τW̃a ⊕ τW̃a ) ⊗ 1)V ψ ( ) ≤ O(ε + η (λ)), W̃ ∈{ X,Y,Z,F,G } 2

E

n

Enc W̃

a

where a := τW̃

O a i i ∈[n]

τW̃ . i

Interpreting the isometry co-domain as (C2 )n ⊗ C2 ⊗ Ĥ (under the canonical isomorphism between A ⊕ A and A ⊗ C2 ) we can rewrite this as a PW̃

z E

∑ V W̃ − a

W̃ ∈{ X,Y,Z,F,G }n a

}|

∑

k ∈{0,1}

!{

a τW̃,k ⊗ |k⟩⟨k| ⊗ 1

2

≤ O(ε + η (λ)),

V ψEnc(W̃ )

a a a and τ a where τW̃,0 = τW̃ = τ W̃ . By the ε-self-consistency of ({ X, Y, Z, F, G }n , U5n ), W̃,1

E ∑ W̃ Dec(α) − 1 W̃ α

98

2 Enc(W̃ )

ψα

≤ O ( ε ).

Enc(W̃ )

Chaining these two observations (using the fact that ψEnc(W̃ ) = ∑α ψα E ∑ PW̃

Dec(α)

W̃ α

−1

2 Enc(W̃ )

Vψα

V†

), we obtain

≤ O(ε + η (λ)),

(4.59)

Using (4.59) and [MNZ24, Lemma 2.10], we can bound the following trace norm s E ∑ ( PW̃

Dec(α)

W̃ α

Enc(W̃ )

− 1)Vψα

V†

1

E ∑ PW̃

Dec(α)

≤

W̃ α

−1

2

Enc(W̃ )

Vψα

V†

≤ O((ε + η (λ))1/2 ).

(4.60)

For any projector P and Hermitian operator ρ, it holds by the triangle inequality, Hölder’s inequality and invariance of the trace norm under Hermitian adjoint, that

∥ PρP − ρ∥1 ≤ ∥ Pρ( P − 1)∥1 + ∥( P − 1)ρ∥1 ≤ 2 ∥( P − 1)ρ∥1 a , we can use (4.60) to conclude that: applying the above to PW̃

E ∑ PW̃

Dec(α)

W̃ α

Enc(W̃ )

Vψα

Dec(α)

V † PW̃

Enc(W̃ )

− Vψα

V†

1

≤ O((ε + η (λ))1/2 ),

which completes the proof. Instead of having a characterization in terms of encrypted prover answers, we want to relate the post-Alice state directly to the decrypted answer from the first interaction round. Even though decryption is an inefficient operation (without knowledge of the secret key), this can be achieved because, at the current phase of the argument, all guarantees are information theoretic. Corollary 4.6. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability ω ∗ − ε in the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exists a complex Hilbert space Ĥ of finite dimension, an efficient isometry V : H → (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6), and a cryptographically small function η (λ) such that E

∑

Enc(W̃ )

W̃ v∈{0,1}n

v v PW̃ VψEnc(W̃ ) V † PW̃ − Vϕv

V†

1

≤ O((ε + η (λ))1/2 ),

where ω ∗ = 16 (5 + cos2 ( π8 )) is the optimal winning probability of the Clifford test (an honest prover achieves it up to a cryptographically small loss, and no efficient prover can exceed it by more than η (λ), cf. Lemma 4.30) and a PW̃ =

a ⊗ |k⟩⟨k| ⊗ 1 ∑ τW̃,k

Enc(W̃ )

and

ϕv

=

k ∈{0,1}

∑

Enc(W̃ )

ψα

,

α:Dec(α)=v

a a a , τa with τW̃,0 = τW̃ = τ W̃ . In words, the post-isometry post Alice measurement state (grouped per W̃,1 decrypted outcome) is information theoretically close to the fully marginalized state, projected into the image space of the projector corresponding to the reported outcome of the requested measurement.

Proof. By Lemma 4.33, there exists an isometry V : H → (C2 )n ⊗ C2 ⊗ Ĥ such that E ∑ PW̃

Dec(α)

W̃ α

Enc(W̃ )

Vψα

Dec(α)

V † PW̃

where v PW̃ =

Enc(W̃ )

− Vψα

V†

1

v ⊗ |k⟩⟨k| ⊗ 1. ∑ τW̃,k

k ∈{0,1}

99

≤ O((ε + η (λ))1/2 ),

By the triangle inequality, this implies E

∑

Enc(W̃ )

v Vϕv PW̃

W̃ v∈{0,1}n

Enc(W̃ )

v − Vϕv V † PW̃

V†

≤ O((ε + η (λ))1/2 ).

1

(4.61)

note that for a set of orthogonal projectors { Pv }v , and arbitrary operator A, by the pinching inequality it holds that ∑ ∥ Pv APv ∥1 ≤ ∥ A∥1 . v

With this we can write E

∑

v v v PW̃ VψEnc(W̃ ) V † PW̃ − PW̃ Vϕv

=E



Enc(W̃ )

W̃ v∈{0,1}n

∑

W̃ v∈{0,1}n



∑′ Vϕv′

v PW̃

v

∑′ Vϕv′ W̃

≤E

Enc(W̃ )

v

≤ E∑ W̃ v′

Enc(W̃ )

v V † PW̃

v′

1

Enc(W̃ )

V † − PW̃ Vϕv′

v′

V † PW̃



! v PW̃ 1

′

Enc(W̃ )

v V † − PW̃ Vϕv′

 ′

v V † PW̃

1

Enc(W̃ ) † Enc(W̃ ) † v′ v′ Vϕv′ V − PW̃ Vϕv′ V PW̃ 1

≤ O((ε + η (λ))1/2 ), where the last inequality follows from Eq. (4.61). Combining the above with Eq. (4.61), through the triangle inequality, we obtain E

∑

W̃ v∈{0,1}n

Enc(W̃ )

v v PW̃ VψEnc(W̃ ) V † PW̃ − Vϕv

V†

1

≤ O((ε + η (λ))1/2 ),

which completes the proof. We also want to apply the dephasing observation from Corollary 4.5 to the decrypted-outcome post-Alice state. This is a bit delicate, because generally we can’t apply the inefficient grouping per decrypted outcome to a computational statement. However, we can use the tools established in the lemmas above to combine computational and information-theoretic guarantees such that the desired statement follows. Lemma 4.34. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability ω ∗ − ε in the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exist complex Hilbert spaces H′ , Ĥ of finite dimension and an efficient isometry V : H → H′ ∼ = (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6) such that for all uniformly efficient (in v and W̃) POVMs { Mv,W̃ , 1 − Mv,W̃ }v,W̃ ∈ L(H′ ), there exists a cryptographically small function η (λ) such that E

∑

W̃ ∈{ X,Y,Z,F,G }n v∈{0,1}n

h  i Enc(W̃ ) † Enc(W̃ ) † Tr Mv,W̃ D Z (Vϕv V ) − Vϕv V ≤ O((ε + η (λ))1/2 )

where

Enc(W̃ )

ϕv

:=

∑

Enc(W̃ )

ψα

,

α:Dec(α)=v

D Z is the dephasing operation on the phase ambiguity flag register, i.e. D Z (ρ) =

1 (ρ + (1 ⊗ σZ ⊗ 1)ρ(1 ⊗ σZ ⊗ 1)) . 2

Here ω ∗ = 16 (5 + cos2 ( π8 )) is the optimal winning probability of the Clifford test. 100

Proof. Let Mv,W̃ be any uniformly efficient family of POVM elements in v ∈ {0, 1}n and W̃ ∈ { X, Y, Z, F, G }n . The lemma’s hypothesis (success probability of ω ∗ − ε on the full Clifford test) combined with the Tsirelson bound on the CHSH subtest and the equal weighting of the six items implies that the prover wins each non-CHSH subtest, and items 1 to 4 in particular, with probability 1 − O(ε + η (λ)). Hence both Corollary 4.6 and Corollary 4.5 apply, and make use of the same isometry V (from Definition 4.6). The proof idea is to replace the outcome-dependent state by a projection of the marginal, which is given by ! v v v PW̃ VψEnc(W̃ ) V † PW̃ = PW̃ V

∑′ ϕv′

Enc(W̃ )

v V † PW̃ .

v

From Corollary 4.6, we know that both states are close in trace norm E ∑ Vϕv

Enc(W̃ )

W̃ v

v v V † − PW̃ VψEnc(W̃ ) V † PW̃

1

≤ δ,

(4.62)

with δ = O((ε + η (λ))1/2 ). Using ∥ Mv,W̃ ∥ ≤ 1, the tracial Hölder inequality [Bau11, Theorem 2] and the cyclicity of the trace, we have for each W̃ and v   v  Enc(W̃ ) †  v Tr Mv,W̃ Vϕv V − Tr PW̃ Mv,W̃ PW̃ VψEnc(W̃ ) V †   Enc(W̃ ) † v v = Tr Mv,W̃ Vϕv V − PW̃ VψEnc(W̃ ) V † PW̃ Enc(W̃ )

≤ Vϕv

v v V † − PW̃ VψEnc(W̃ ) V † PW̃

1

.

(4.63)

v = v ⊗ | k ⟩⟨ k | ⊗ 1 commutes with 1 ⊗ σ ⊗ 1 and thus with the channel The projector PW̃ ∑k τW̃,k Z DZ : v v v v D Z ( PW̃ ρPW̃ ) = PW̃ D Z (ρ) PW̃ ∀ρ.

Combining this commutation relation with the trace-norm contractivity of D Z gives   v  Enc(W̃ ) †  v Mv,W̃ PW̃ D Z (VψEnc(W̃ ) V † ) Tr Mv,W̃ D Z (Vϕv V ) − Tr PW̃   Enc(W̃ ) † v v = Tr Mv,W̃ D Z Vϕv V − PW̃ VψEnc(W̃ ) V † PW̃ Enc(W̃ )

≤ Vϕv

v v V † − PW̃ VψEnc(W̃ ) V † PW̃

1

.

(4.64)

Combining Eq. (4.63) and Eq. (4.64) via the triangle inequality, summing over v, taking the expectation over W̃, and applying Eq. (4.62) yields

∑ Tr Mv,W̃ DZ (Vϕv W̃

E



Enc(W̃ )

Enc(W̃ )

V † ) − Vϕv

V†



v

 v  v − ∑ Tr PW̃ Mv,W̃ PW̃ D Z (VψEnc(W̃ ) V † ) − VψEnc(W̃ ) V † ≤ 2δ.

(4.65)

v

Write A and B for the two summed traces inside Eq. (4.65), so EW̃ | A − B| ≤ 2δ. It remains to bound the signed average of B. Since D Z (VψEnc(W̃ ) V † ) − VψEnc(W̃ ) V † does not depend on v, we can pull the sum over v inside the trace and define: v v MW̃ := ∑ PW̃ Mv,W̃ PW̃ . v

We claim that { MW̃ , 1 − MW̃ } is a binary POVM and that MW̃ is uniformly efficient given W̃.

101

v } is a complete set of orthogonal projectors: The family { PW̃ v

∑ PW̃v = 1 ⊗ (|0⟩⟨0| + |1⟩⟨1|) ⊗ 1 = 1.

′

v v v PW̃ PW̃ = δvv′ PW̃ ,

v

v v v v M Combined with 0 ⪯ Mv,W̃ ⪯ 1 this gives 0 ⪯ PW̃ v,W̃ PW̃ ⪯ PW̃ , hence 0 ⪯ MW̃ ⪯ ∑v PW̃ = 1.

Given W̃, the binary POVM { MW̃ , 1 − MW̃ } can be implemented sequentially: first projectively v } to obtain an outcome v ∈ {0, 1}n . Then apply { M measure { PW̃ v v,W̃ , 1 − Mv,W̃ }, which is uniformly efficient given v and W̃. With this identification, Corollary 4.5 applied with the question-indexed family { MW̃ }W̃ (uniformly efficient by the sequential implementation above) and ν the uniform distribution over W̃ ∈ { X, Y, Z, F, G }n gives   E Tr MW̃ D Z (VψEnc(W̃ ) V † ) − VψEnc(W̃ ) V † ≤ O((ε + η (λ))1/2 ). W̃

(4.66)

The triangle inequality EW̃ A ≤ EW̃ | A − B| + EW̃ B together with Eq. (4.65) and Eq. (4.66) yields the claim. With the above we have all required tools in place to show our random remote state preparation guarantee. We will use Lemma 4.33 to project the post-Alice state into the eigenspace of the outcome projectors corresponding to the certified observables. Then we will use Lemma 4.34 to get rid of potential coherences in the flag register. Along the way we will need to argue that different junk states on the auxiliary system, are computationally indistinguishable, making sure that they can’t leak information about the state to the prover; this can be achieved by a reduction to IND-CPA security of the QFHE, through Lemma 4.32. Theorem 4.2. For any computationally efficient prover modeled as in Section 3.7.2 that wins with probability ω ∗ − ε in the compiled Clifford test CLIFF ( X, Y, Z, F, G, n), obtained from protocol 11, there exists a complex Hilbert space Ĥ of finite dimension, an efficient isometry V : H → (C2 )n ⊗ C2 ⊗ Ĥ (from Definition 4.6), and a cryptographically small function η (λ) such that E

∑

 c v v V † ≈γ E |v, W̃ ⟩⟨v, W̃ |W ⊗ τW̃ ⊗ ρ0 + τ W̃ ⊗ ρ1 ,

Enc(W̃ )

W̃ v∈{0,1}n

|v, W̃ ⟩⟨v, W̃ |W ⊗ Vϕv

v,W̃

where γ = O((ε + η (λ))1/2 ), the expectation on W̃ is uniform over { X, Y, Z, F, G }n and that on v is uniform over {0, 1}n . The verifier holds the W register, let Enc(W̃ )

:=

ϕv

∑

Enc(W̃ )

ψα

,

α:Dec(α)=v

and ρ0 and ρ1 are sub-normalized states with orthogonal support, such that Tr [ρ0 + ρ1 ] = 1. Here ω ∗ = 61 (5 + cos2 ( π8 )) is the optimal winning probability of the Clifford test. Proof. Applying Lemma 4.33 yields an isometry V : H → (C2 )n ⊗ C2 ⊗ Ĥ such that E ∑ PW̃

Dec(α)

W̃ α

Enc(W̃ )

Vψα

Dec(α)

V † PW̃

where a PW̃ =

Enc(W̃ )

− Vψα

V†

1

≤ O((ε + η (λ))1/2 ),

a ⊗ |k⟩⟨k| ⊗ 1, ∑ τW̃,k

k ∈{0,1}

next we can combine this with Lemma 4.34 to obtain that for all uniformly efficient families of POVMs { Mv,W̃ , 1 − Mv,W̃ }v,W̃ ∈ L((C2 )n ⊗ C2 ⊗ Ĥ), h   i Enc(W̃ ) v Enc(W̃ ) v E ∑ Tr Mv,W̃ θv − D Z PW̃ θv PW̃ ≤ O((ε + η (λ))1/2 ), W̃ v

102

(4.67)

where

Enc(W̃ )

θv

:=

∑

Enc(W̃ )

Vψα

V†.

α:Dec(α)=v

We will start by expanding the right term:  Enc(W̃ ) i v τW̃ ⊗ |0⟩⟨0| ⊗ 1 θv h  Enc(W̃ ) i v v + τ W̃ ⊗ |1⟩⟨1| ⊗ Tr1,2 τ W̃ ⊗ |1⟩⟨1| ⊗ 1 θv h  Enc(W̃ ) i v v v v | ⊗ |1⟩⟨0| ⊗ Tr1,2 |τW̃ ⟩⟨τ W̃ ⟩⟨τW̃ | ⊗ |0⟩⟨1| ⊗ 1 θv + |τ W̃

Enc(W̃ ) v v PW̃ = τW̃ ⊗ |0⟩⟨0| ⊗ Tr1,2

v PW̃ θv

h

+ h.c. v = | τ v ⟩⟨ τ v | and τ v = | τ v ⟩⟨ τ v |. The notation where h.c. denotes the Hermitian conjugate, τW̃ W̃ W̃ W̃ W̃ W̃ Tr1,2 denotes the partial trace over the first ((C2 )n ) and second (C2 ) register. Applying the dephasing channel removes the coherences and we obtain   h  Enc(W̃ ) i v Enc(W̃ ) v v v D Z PW̃ θv PW̃ = τW̃ ⊗ |0⟩⟨0| ⊗ Tr1,2 τW̃ ⊗ |0⟩⟨0| ⊗ 1 θv h  Enc(W̃ ) i v v + τ W̃ ⊗ |1⟩⟨1| ⊗ Tr1,2 τ W̃ ⊗ |1⟩⟨1| ⊗ 1 θv v and the fact that it commutes with computational basis projectors, Using the definition of PW̃ we obtain h i v Enc(W̃ ) v v = τW̃ ⊗ |0⟩⟨0| ⊗ Tr1,2 (1 ⊗ |0⟩⟨0| ⊗ 1) PW̃ θv PW̃ h i v v Enc(W̃ ) v + τ W̃ ⊗ |1⟩⟨1| ⊗ Tr1,2 (1 ⊗ |1⟩⟨1| ⊗ 1) PW̃ PW̃ . θv

Applying Lemma 4.33 (using the data-processing of the trace norm) we can conclude that     Enc(W̃ ) Enc(W̃ ) v v Enc(W̃ ) v v E ∑ D Z PW̃ ⊗ θv,1 ≤ O((ε + η (λ))1/2 ), θv PW̃ − τW̃ ⊗ θv,0 + τ W̃ 1

W̃ v

where Enc(W̃ )

ρv,k

z }| h i{ Enc(W̃ ) Enc(W̃ ) := |k⟩⟨k | ⊗ Tr1,2 (1 ⊗ |k ⟩⟨k| ⊗ 1) θv θv,k for k ∈ {0, 1}. Combining this trace-norm bound with Eq. (4.67) via the triangle inequality for signed averages, we obtain h   i Enc(W̃ ) Enc(W̃ ) Enc(W̃ ) v v E ∑ Tr Mv,W̃ θv − τW̃ ⊗ θv,0 + τ W̃ ⊗ θv,1 ≤ δ, W̃ v

(4.68)

where δ ≤ O((ε + η (λ))1/2 ). What remains is to show that the auxiliary states are computationally indistinguishable from a W̃- and v-independent reference; i.e. no computationally bounded prover can learn any information about the basis choice or measurement outcomes from the auxiliary state. Choose any fixed q ∈ Q A and define the reference auxiliary states on C2 ⊗ Ĥ h i Enc(q) Enc(q) Enc(q) := Tr1,2 (1 ⊗ |k ⟩⟨k| ⊗ 1) VψEnc(q) V † , θk := θk = |k⟩⟨k| ⊗ ρk , ρk for k ∈ {0, 1}. Note that θ0 and θ1 have orthogonal supports on the flag register and that h i h i Enc(q) Enc(q) Tr [θ0 + θ1 ] = Tr ρ0 + ρ1 = Tr VψEnc(q) V † = 1. 103

Since the compiled Clifford group test is a subtest of the compiled Clifford test (and the lemma hypothesis ensures a winning probability of 1 − O(ε + η (λ)) in that subtest) we can apply a weakened version of Lemma 4.32 (ignoring the possible α dependence of the POVM) and conclude that for the same isometry V and any efficient POVM { M, 1 − M} ∈ L((C2 )n ⊗ C2 ⊗ Ĥ),    1 ≤ ξ, (4.69) Tr M VψEnc(q) V † − n ⊗ ρEnc(q) 2 h i where ρEnc(q) := Tr1 VψEnc(q) V † is the post-isometry qubit-marginal on C2 ⊗ Ĥ, and ξ ≤ O((ε + η (λ))1/2 ). Recalling that Tr2 denotes the partial trace over the flag register, note that h i Enc(q) Enc(q) Tr2 (|k⟩⟨k | ⊗ 1) ρ = ρk . The next steps are inspired by the proof of Proposition 4.32 in [GMP23], but we give a direct argument instead of a proof by contradiction. We will show that for any uniformly efficient family of two-outcome POVMs {Λv,W̃ , 1 − Λv,W̃ }v,W̃ ∈ L((C2 )n ⊗ C2 ⊗ Ĥ), h     i Enc(W̃ ) Enc(W̃ ) v v E ∑ Tr Λv,W̃ τW̃ ⊗ θv,0 − 21n θ0 + τ W̃ − 21n θ1 ≤ δ + ξ + η ( λ ). ⊗ θv,1 W̃ v

(4.70)

Define the mutually orthogonal projectors v v := τW̃ PW̃,0 ⊗ |0⟩⟨0| ⊗ 1,

v v := τ W̃ PW̃,1 ⊗ |1⟩⟨1| ⊗ 1.

The operator against which Λv,W̃ is traced is block diagonal and supported on these two projectors. Therefore, replacing Λv,W̃ by its pinching Λv,W̃ 7−→

v v Λv,W̃ PW̃,k ∑ PW̃,k

k ∈{0,1}

leaves the quantity in Eq. (4.70) unchanged. This replacement preserves uniform efficiency, since the projectors are efficiently measurable given v and W̃. Consequently, without loss of generality, v v Λv,W̃ = τW̃ ⊗ |0⟩⟨0| ⊗ Λv,W̃,0 + τ W̃ ⊗ |1⟩⟨1| ⊗ Λv,W̃,1 , (4.71) with 0 ⪯ Λv,W̃,k ⪯ 1 for all v ∈ {0, 1}n , k ∈ {0, 1}, and the family {Λv,W̃,k }v,W̃ uniformly efficient given W̃. Using Eq. (4.71) we can derive the following identity: h  i   v v Tr Λv,W̃ 21n ⊗ ρEnc(q) = Tr Λv,W̃ τW̃ ⊗ 21n θ0 + τ W̃ ⊗ 21n θ1 (4.72) We will now expand the summand of Eq. (4.70) using a telescoping sum: h     i Enc(W̃ ) Enc(W̃ ) ∑ Tr Λv,W̃ τW̃v ⊗ θv,0 − 21n θ0 + τW̃v ⊗ θv,1 − 21n θ1 v

Enc(W̃ )

Telescoping over ∑v θv and introducing a second sum on the first term, using the exact structure of Λv,W̃ given in Eq. (4.71) (specifically orthogonality), we obtain:

= ∑ Tr v

"



∑′ Λv′ ,W̃ v



Enc(W̃ )

v τW̃ ⊗ θv,0

104

Enc(W̃ ) 

v ⊗ θv,1 + τ W̃

Enc(W̃ )

− θv



#

Enc(W̃ )

Using ∑v θv

= VψEnc(W̃ ) V † and telescoping over VψEnc(q) V † : " #    Enc(W̃ ) † Enc(q) † + Tr ∑ Λv′ ,W̃ Vψ V − Vψ V v′

Correcting for VψEnc(q) V † and using Eq. (4.72) for the last term: # "    1 + Tr ∑ Λv′ ,W̃ VψEnc(q) V † − n ⊗ ρEnc(q) . 2 v′ Let

MW̃

ΓW̃ := V

†

z 

}| { ∑ Λv,W̃ V ∈ L(H). v

By the form of Eq. (4.71) (orthogonal projectors on first two systems), {ΓW̃ , 1 − ΓW̃ } is indeed a POVM and it’s efficient given W̃, since one can apply the efficient isometry V, measure the second register in the computational basis (obtaining outcome k), then measure the first register in the bases specified by W̃ (or their complex conjugate depending on the flag outcome k) and then apply Λv,W̃,k which is efficient given both outcomes and W̃. With this, the telescoping sum (taking the expectation over W̃) and the triangle inequality, we have  i  h   Enc(W̃ ) Enc(W̃ ) v v − 21n θ1 ⊗ θv,1 E ∑ Tr Λv,W̃ τW̃ ⊗ θv,0 − 21n θ0 + τ W̃ W̃ v

i h  Enc(W̃ ) Enc(W̃ )  Enc(W̃ ) v v − θv ≤ E ∑ Tr MW̃ τW̃ ⊗ θv,1 ⊗ θv,0 + τ W̃ W̃ v

h  i + E Tr ΓW̃ ψEnc(W̃ ) − ψEnc(q) W̃

+ Tr



E MW̃



VψEnc(q) V † −

W̃

 1 Enc(q) ⊗ ρ 2n



≤ δ + ξ + η ( λ ), where the last inequality follows from Eq. (4.68), Eq. (4.69) (since EW̃ MW̃ is an efficient POVM) and Lemma 3.3 applied with D sampling W̃ uniformly and (z0 , z1 ) = (W̃, q), with the family {ΓW̃ }W̃ uniformly efficient in W̃. This shows Eq. (4.70). Combining (4.70) with (4.68) via the triangle inequality for signed averages, we obtain h  i Enc(W̃ ) v v ≤ O((ε + η (λ))1/2 ), E ∑ Tr Mv,W̃ θv − 21n τW̃ ⊗ θ0 + τ W̃ ⊗ θ1 W̃ v

Enc(W̃ )

Enc(W̃ )

(4.73)

Identifying θv = Vϕv V † and ρk = θk for k ∈ {0, 1} in the theorem statement concludes the proof, since the W register in the theorem statement is classical, so without loss of generality the efficient POVM (implicit in the computational indistinguishability notation) can be written as M = ∑ |v, W̃ ⟩⟨v, W̃ | ⊗ Mv,W̃ . v∈{0,1}n

105

5

BQP verification

5.1

Protocol

Protocol 12: Verification protocol Notation: VERIFY (C, m, p) Input: An n-qubit circuit C compiled in the universal gate set {σX , σZ , T, H, CNOT }, where every H-gate is replaced by H ( TTH )3 (i.e. HPHPHPH), and a subtest probability 0 < p < 1. Let t be the number of T gates in C after this replacement (t0 of which have even parity, meaning an even number of Hadamard gates precede them in the compiled circuit). The argument m = Θ(n + t) should be such that every symbol appears at least n + t times in a uniformly random W̃ ∈ { X, Y, Z, F, G }m with probability 1 − e−O(m) . Execute the following tests with probability p and 1 − p, respectively. 1. State test: Execute CLIFF ( X, Y, Z, F, G, m). R

2. Delegation game: Sample W̃ ← { X, Y, Z, F, G }m and send it to Alice, receiving answer v ∈ {0, 1}m . If W̃ does not contain every symbol at least n + t times, reject. Otherwise, execute each of the following subtests with equal probability (1/3 each). In each subtest the index sets N, T0 , T1 are sampled uniformly among all tuples of disjoint subsets of the stated sizes whose positions carry the required symbols. We write PS := {i : W̃i ∈ S} for S ⊆ { X, Y, Z, F, G } to denote the different symbol classes. (a) Computation run: Choose N uniformly among all n-subsets of P{Z} . Sample T0 and T1 uniformly among disjoint subsets of P{G,F} of sizes t0 and t − t0 , respectively. R

Let a = v| N , b = 0n , d ← {0, 1}t , and let y′ ∈ {0, 1}t with yi′ = 0 if ( W̃ T ∪T )i = G 0 1 and yi′ = 1 otherwise; then y = y′ ⊕ d and e = v| T0 ∪T1 ⊕ d. Send (C, N, T0 , T1 ) to Bob and execute Interactive Proof System 1 from [Bro18] starting at step A.3 with keys ( a, b, d, e, y) on the qubits in N, T0 and T1 . (b) X-test run: Choose N and T0 uniformly among disjoint subsets of P{Z} of sizes n and t0 , respectively. Sample T1 uniformly among all (t − t0 )-subsets of P{X,Y } . Let a = v| N , b = 0n , d0 = v| T0 , d1 = v| T1 and let y ∈ {0, 1}t−t0 with yi = 0 if ( W̃ T )i = X and yi = 1 otherwise. 1

Send (C, N, T0 , T1 ) to Bob and execute Interactive Proof System 1 from [Bro18] starting at step B.3 with keys ( a, b, d0 , d1 , y) on the qubits in N, T0 and T1 . (c) Z-test run: Choose T0 uniformly among all t0 -subsets of P{X,Y } first. Then sample N uniformly among all n-subsets of P{X } \ T0 and T1 uniformly among all (t − t0 )-subsets of P{Z} . Let a = 0n , b = v| N , d0 = v| T0 , d1 = v| T1 and let y ∈ {0, 1}t0 with yi = 0 if ( W̃ T )i = X and yi = 1 otherwise. 0

Send (C, N, T0 , T1 ) to Bob and execute Interactive Proof System 1 from [Bro18] starting at step C.3 with keys ( a, b, d0 , d1 , y) on the qubits in N, T0 and T1 .

106

5.2

Soundness

Lemma 5.1 (Soundness against malicious ‘Bob’). Suppose the verifier executes the compiled Verification protocol VERIFY (C, m, p), obtained from protocol 12, where9 ∥Π0 C |0n ⟩∥2 ≤ 1/3, with a prover P∗ (not necessarily efficient) such that the shared state after the encrypted interaction is  v v ⊗ ρ1 , E E |v, W̃ ⟩⟨v, W̃ |W ⊗ τW̃ ⊗ ρ0 + τ W̃ v∈{0,1}m W̃ ∈{ X,Y,Z,F,G }m

where the verifier holds the W register and ρ0 and ρ1 are sub-normalized states with orthogonal support, such that Tr [ρ0 + ρ1 ] = 1. Then the verifier accepts in the delegation game with probability at most 7/9. v for the Proof. The proof follows from the soundness of the Broadbent protocol. Write σW̃ v v restriction of τW̃ to the qubits in N, T0 and T1 . Since τW̃ is a product state and v is uniform, the unused qubits are independent of the keys derived from v| N ∪T0 ∪T1 and may be absorbed into the prover’s private space. Thus, on the support of ρ0 , the prover holds (up to this private space) the prepare-and-send state of Interactive Proof System 1 from [Bro18] with the keys of protocol 12; on the support of ρ1 he holds the complex conjugate of that state in the computational basis. The expectations over W̃ and v supply the uniformly random keys required by Broadbent’s analysis. If W̃ lacks sufficiently many of each symbol the verifier rejects, which can only decrease the acceptance probability, so we may condition on the index sets being well-defined.

The remaining interaction is a (possibly adaptive) measurement of this cq-state, so by linearity the acceptance probability is a convex combination of the two branches. On the ρ0 branch the instance is a genuine execution of the Broadbent protocol. On the ρ1 branch, let Pe be the complex conjugate of P∗ ’s operations in the unencrypted interaction, i.e. the strategy obtained by conjugating every Kraus operator in the computational basis (again a valid strategy, since conjugation preserves ∑ j K †j K j = 1, though not necessarily efficiency). Since the prover’s answers are outcomes of computational-basis measurements, whose projectors are real, and the verifier’s messages and acceptance predicate are classical v ⊗ ρ induces the same transcript distribution as P∗ on functions of the transcript, Pe on σW̃ 1 v ⊗ ρ , by the following identity: σW̃ 1     v v ⊗ ρ1 = Tr M σW̃ ⊗ ρ1 , Tr M σW̃ Hence Pe is a (possibly inefficient) Broadbent prover on the correct plaintext states. Broadbent’s soundness is information-theoretic and gives acceptance at most 7/9 on a no-instance for Interactive Proof System 1, where the different run types are indistinguishable [Bro18, Section 7.6], which is the case in protocol 12 since the prior interaction is encrypted and the extra message which Bob receives (C, N, T0 , T1 ) is equally distributed in all three run types. Indeed, the sampling procedure of protocol 12 is invariant under any permutation of [m] that fixes the symbol classes PS setwise, since N, T0 , T1 are each chosen uniformly among subsets of a fixed size within fixed symbol classes; hence, conditioned on W̃ containing enough of each symbol, ( N, T0 , T1 ) is uniformly distributed over all admissible triples of disjoint subsets of [m] of the required sizes and symbol classes. The rejection event depends only on the symbol counts of W̃, not on which positions realize them, so it is independent of ( N, T0 , T1 ) given those counts; thus the law of ( N, T0 , T1 ), conditioned on non-rejection, is uniform over admissible triples independently of the run type, and so is the law of (C, N, T0 , T1 ). The winning probability of both branches is thus bounded by 7/9, and so is P∗ . Lemma 5.2. Suppose the verifier executes the compiled Verification protocol VERIFY (C, m, p), obtained from protocol 12, where ∥Π0 C |0n ⟩∥2 ≤ 1/3, with a computationally efficient prover P∗ , such that 9Π

0 denotes the projector onto the |0⟩ state of the first output qubit of the circuit, this indicates acceptance.

107

the prover is accepted with probability at least ω ∗ − ε, for some ε > 0, in the state test. Here ω ∗ = 1 2 π ∗ 6 (5 + cos ( 8 )) is the optimal winning probability of the Clifford test. Then the verifier accepts P in 7 1/2 the delegation game with probability at most 9 + γ, where γ = O((ε + η (λ)) ). Proof. By Theorem 4.2 (applied with qubit count m, since the state test is CLIFF ( X, Y, Z, F, G, m)), success of at least ω ∗ − ε in the state test implies the existence of a complex Hilbert space H̃ of finite dimension, an efficient isometry V : H → (C2 )m ⊗ H̃ and a cryptographically small function η (λ) such that Θ

z E

∑

W̃ v∈{0,1}m

Ω }| { }| z { c Enc(W̃ ) † v v ⊗ ρ0 + τ W̃ ⊗ ρ1 , |v, W̃ ⟩⟨v, W̃ |W ⊗ Vϕv V ≈γ E |v, W̃ ⟩⟨v, W̃ |W ⊗ τW̃ v,W̃

Enc(W̃ )

where γ = O((ε + η (λ))1/2 ) and ϕv ized per decrypted outcome).

(5.1)

is P∗ ’s state after the encrypted interaction (marginal-

After the encrypted round the remaining interaction consists of poly(m) rounds of cleartext messages: the verifier samples the run type and the data ( N, T0 , T1 , d, . . . ) as a function of the register W and his own randomness, the prover replies, and the verifier applies a classical acceptance predicate to the transcript. The accepting contribution of P∗ ’s continuation, averaged over the verifier’s randomness, can be written as a family of two-outcome POVMs { Dv,W̃ , 1 − Dv,W̃ } on H with  Enc(W̃ )  paccept = E ∑ Tr Dv,W̃ ϕv . W̃ v∈{0,1}m

The family depends on (v, W̃ ) because the verifier’s unencrypted messages are computed from v = Dec(α), which the prover cannot compute himself; it is uniformly efficient in (v, W̃ ), since the verifier is classical polynomial time, P∗ ’s continuation is efficient by assumption, and there are only poly(m) rounds. Let D := ∑ |v, W̃ ⟩⟨v, W̃ |W ⊗ Dv,W̃ ,

M := (1W ⊗ V ) D (1W ⊗ V † ).

v,W̃

Since V is an isometry we have 0 ⪯ M ⪯ (1W ⊗ VV † ) ⪯ 1, so { M, 1 − M } is a POVM, and it is uniformly efficient because D and V are. Enc(W̃ )

By V † V = 1 and cyclicity of the trace, Tr[VDv,W̃ V † Vϕv

Enc(W̃ )

V † ] = Tr[ Dv,W̃ ϕv

Tr[ MΘ] = paccept .

], hence (5.2)

Since M is a uniformly efficient POVM element, Eq. (5.1) gives Tr[ MΘ] − Tr[ MΩ] ≤ γ.

(5.3)

We claim that Tr[ MΩ] lower-bounds the acceptance probability of some prover holding the ideal state, i.e. the state on the right-hand side of Eq. (5.1). Recall that M was derived from the particular interaction between the verifier and P∗ , mapped into the dilated space of the isometry V. It remains to show that there exists a prover strategy, which acts on the ideal state (that lives in the dilated space), whose transcript distribution is identical to that of P∗ (on the parts of the ideal state that live inside the image of V). To this end define U as the efficient unitary extension of V, such that V |ψ⟩ = U (|ψ⟩ ⊗ |0⟩)

108

for all |ψ⟩ ∈ H. Then we can define P′ as applying U † , measuring the ancilla qubits in the computational basis, aborting if the outcome isn’t zero and otherwise applying P∗ ’s continuation on H. The element of the verifier’s interaction with P′ is then A = M + Aabort , where Aabort is PSD, such that 7 Tr[ MΩ] ≤ Tr[ AΩ] ≤ . 9 ′ Here the last inequality follows from Lemma 5.1, since P holds the ideal state. Combining with Eq. (5.2) and Eq. (5.3) yields, 7 paccept ≤ + γ, 9 which completes the proof. Definition 5.1 (Q-CIRCUIT). The input to the promise problem Q-CIRCUIT consists of a quantum circuit C = CT · · · C1 acting on n qubits, given in the universal gateset {σX , σZ , H, CNOT, T } (as in protocol 12, every H gate is replaced by H ( TTH )3 ). Let Π0 denote the projector onto |0⟩ of the first output qubit, and let p(C ) := ∥Π0 C |0n ⟩∥2 be the probability of observing 0 as a result of a computational-basis measurement of that qubit after evaluating C on |0n ⟩. Then define Q-CIRCUIT = {Q-CIRCUITYES , Q-CIRCUITNO } with Q-CIRCUITYES := {C : p(C ) ≥ 2/3} ,

Q-CIRCUITNO := {C : p(C ) ≤ 1/3} .

Theorem 5.1. Assuming LWE is hard for non-uniform quantum adversaries, in sense of Definition 3.11, there exist constants 0 < p < 1 and ∆ > 0, δSK > 0 and thresholds λ0 , m0 such that the following holds. For every instance C of Q-CIRCUIT (Definition 5.1) with m = Θ(|C |) ≥ m0 and with security parameter λ ≥ λ0 instantiated from m as in Remark 3.6, the compiled10 protocol VERIFY (C, m, p) of protocol 12 satisfies: 1. (Completeness:) If C ∈ Q-CIRCUITYES , then there is a strategy for the prover, consuming O(poly(λ, log |C |)|C |) total resources, that is accepted with probability at least    1 8 2 π pc = p 5 + cos ( ) + (1 − p) − e−O(m) − η (λ) − δSK , 6 8 9 where the cryptographically small term η (λ) accounts for the correctness error of the QFHE evaluation, while δSK accounts for gate-synthesis error. 2. (Soundness:) If C ∈ Q-CIRCUITNO , then any efficient prover strategy is accepted with probability at most ps = pc − ∆. Remark 5.1 (On the constants λ0 , m0 , ∆). The functions γ and η appearing in the proof below are, individually, only guaranteed to be cryptographically small for the specific prover under consideration; a priori this could make the threshold beyond which η (λ) < ε∗ prover-dependent, which would make λ0 (and hence ∆) depend on the prover as well. This is not the case: by Remark 3.7, for every λ we may hardwire, as classical advice, the choice of prover (among the non-uniform class fixed by Definition 3.11 for the assumed hardness of LWE) that maximizes η (λ), obtaining a single cryptographically small function that dominates η (λ) for every efficient prover simultaneously. It is this dominating function that is used to fix ε∗ , and hence λ0 and ∆, below; both are therefore genuine constants, valid uniformly over the entire class of efficient provers, not merely for a single fixed one. 10 Since the test has multiple rounds of interaction with Bob, compiled here means that the first interaction with

Alice is encrypted and all interactions with Bob happen in the clear.

109

Proof. Completeness. Completeness is straightforward to show; for more details about the honest prover strategy see Table 5 and Section 4.1. The Clifford subtest (CLIFF) has completeness 1 2 π 6 (5 + cos ( 8 )), which is achieved by the prover holding m + 2 EPR pairs and performing the honest measurements. By our consistency convention, the honest Alice measurements are actually the transposes of the requested operators. The delegation subtest corresponds to an execution of the prepare-and-send version of the Broadbent protocol, which has perfect completeness in the test rounds and completeness at least 23 in the computation rounds (cf. [Bro18, Section 6]), which yields overall completeness of at least 89 since all three rounds are executed with equal probability. The correction term e−O(m) is due to the fact that a uniformly random W̃ ∈ { X, Y, Z, F, G }m does not always contain every symbol sufficiently often, and the cryptographically small term η (λ) accounts for the correctness error of the homomorphic evaluation performed by the honest prover in the encrypted round. Lastly, there is also an error term stemming from the synthesis of the honest Alice circuit into the gate set supported by QFHE. Let GSK be the number of gates in that circuit that require approximation (in our construction, only controlled-T gates). Synthesize each such gate to operator-norm error at most δSK /(2GSK ). It is then possible to bound the diamond-norm distance between the ideal and synthesized Alice channels by δSK , which only changes the prover’s acceptance probability by at most δSK . δSK is an independent and constant error term. Solovay–Kitaev gives a per-gate synthesis overhead of polylog( GSK /δSK ), which was already accounted for. We will now show that the basis choices mandated by the protocol correspond to the key assignments in the Broadbent protocol, taking the computation runs as example. On the qubits in N we have W̃i = Z, so the prover holds the σZ -eigenstate |vi ⟩ = σXvi |0⟩; this is the one-timepadded all-zero input of [Bro18], with X-key a = v| N and trivial Z-key b = 0n . On the qubits √ in T0 ∪ T1 we have W̃i ∈ { G, F }, uniformly. Writing |+θ ⟩ = (|0⟩ + eiθ |1⟩)/ 2, the eigenstates of σG with outcomes vi = 0, 1 are |+π/4 ⟩ and |+5π/4 ⟩, and those of σF are |+3π/4 ⟩ and |+7π/4 ⟩, respectively. In our gate notation, y

|+θ ⟩ = σXdi σZei σS i σT |+⟩ up to global phase, with θ = π/4 + (yi ⊕ di )π/2 + (ei ⊕ di )π for any i ∈ [t]. Substituting R

the keys d ← {0, 1}t , y = y′ ⊕ d and e = v| T0 ∪T1 ⊕ d of protocol 12 recovers exactly the four eigenstates above, so the physical state is consistent with Broadbent’s T-gadget auxiliaries. The X- and Z-test runs follow the same pattern; Table 6 summarizes the correspondence for all three run types. For the X-test, the σX /σY -eigenstates on T1 with outcome (d1 )i are exactly Run Computation

X-test

Z-test

W̃ symbol

Broadbent aux state

Keys

N

Z

a = v | N , b = 0n

T0 ∪ T1

G, F

σXvi |0⟩ y σXdi σZei σS i σT |+⟩

d, y = y′ ⊕ d, e = v| T0 ∪T1 ⊕ d

N, T0

Z

σXvi |0⟩

a = v| N , b = 0n , d0 = v| T0

T1

X, Y

σS i σZ 1 i |+⟩

y

d1 = v| T1 , yi = 0 ⇔ W̃i = X

N

X

σZvi |+⟩

b = v | N , a = 0n

T0

X, Y

σS i σZ 0 i |+⟩

d0 = v| T0 , yi = 0 ⇔ W̃i = X

Z

(d ) σX 1 i |0⟩

d1 = v| T1

Positions

T1

y

(d )

(d )

Table 6: Correspondence between the position classes sampled by protocol 12 and the auxiliary states and keys of [Bro18]’s Interactive Proof System 1, for all three run types.

110

(d )

(d )

σZ 1 i |+⟩ (for W̃i = X, yi = 0) and σS σZ 1 i |+⟩ (for W̃i = Y, yi = 1), matching the definition of y in protocol 12; the Z-test entries follow by the same computation with the roles of ( N, a, b) and of the two test-position classes exchanged. This shows that the physical state prepared on every position class, in every run type, is exactly the Broadbent auxiliary state with the keys assigned by protocol 12. The joint law of ( N, T0 , T1 ), and hence of the keys, does not depend on the run type, and the unused positions are maximally mixed and independent of the keys, by the argument given in the proof of Lemma 5.1. Finally, in every run type the interaction with Bob continues past the step named in protocol 12: steps A.4–A.5 (resp. B.4–B.5, C.4–C.5) of [Bro18]—the output measurement, decryption, and accept predicate—are executed as well, exactly as in the Broadbent protocol. Together with the Clifford-test completeness above, this shows that completeness of our protocol indeed follows from the completeness of the Clifford test and the Broadbent protocol. Soundness. It remains to show that any efficient prover will be accepted with probability at most pc − ∆, in an execution of VERIFY (C, m, p), where C ∈ Q-CIRCUITNO . We can make the following case distinction, where ε∗ is a constant parameter we will set at the end of the proof: Good prover: The prover is accepted in the state test with probability at least ω ∗ − ε∗ . Bad prover: The prover is accepted in the state test with probability at most ω ∗ − ε∗ . In the case of a good prover, we invoke Lemma 5.2 to conclude that P∗ succeeds with probability at most 79 + γ(ε∗ + η (λ)). Since no efficient prover can win the state test with probability exceeding ω ∗ + η (λ) (cf. Theorem 4.1), the upper bound on the winning probability of a good prover is pgood ≤ p(ω ∗ + η (λ)) + (1 − p) 79 + γ(ε∗ + η (λ)) . In the case of a bad prover, we can’t use the rigidity test, nor the soundness guarantee of the Broadbent protocol (because we can’t round the state). The upper bound on the winning probability of a bad prover is pbad ≤ p(ω ∗ − ε∗ ) + (1 − p), since his winning probability in the state test is at most ω ∗ − ε∗ . Since one of the two cases must hold, in general the winning probability of any prover on a no-instance is     7 ∗ ∗ ∗ ∗ max p(ω + η (λ)) + (1 − p) + γ(ε + η (λ)) , p(ω − ε ) + (1 − p) . 9 By choosing the protocol constant p sufficiently close to 1, specifically 2 − γ(ε∗ ) p = p∗ (ε∗ ) := 2 9 ∗ ∗ 9 − γ(ε ) + ε

the first argument (corresponding to the good prover case) can be made to always dominate the  maximum (the first argument dominates whenever p(ε∗ + η (λ)) ≥ (1 − p) 29 − γ(ε∗ + η (λ)) , and p∗ (ε∗ ) satisfies this already for η (λ) = 0). Then the highest possible winning probability on a no-instance is   7 ∗ ∗ ∗ ∗ ∗ ∗ ps = p (ε )(ω + η (λ)) + (1 − p (ε )) + γ(ε + η (λ)) . 9 Recalling the completeness probability    1 8 ∗ ∗ 2 π pc = p (ε ) 5 + cos ( ) + (1 − p∗ (ε∗ )) − e−O(m) − η (λ) − δSK , 6 8 9

111

the completeness–soundness gap becomes   1 ∗ ∗ ∗ − γ(ε + η (λ)) − O(η (λ)) − e−O(m) − δSK . ∆ = pc − ps = (1 − p (ε )) 9 We are now in a position to set ε∗ : if we choose it such that γ(2ε∗ ) < 1/9, then for all sufficiently large λ, η (λ) < ε∗ , so we have γ(ε∗ + η (λ)) < 1/9. This means there is some positive constant K such that ∆ ≥ K − O(η (λ)) − e−O(m) − δSK . We then choose the constant δSK smaller than, for example, K/2. If m and λ are also sufficiently large, the terms e−O(m) and O(η (λ)) do not change the sign of the gap, so ∆ remains a positive constant. The more prover errors we wish to tolerate, the smaller the gap becomes and the closer to 1 the probability of selecting a state test round (p) has to be. The only relevant regime is the one where γ(ε∗ + η (λ)) < 19 . In this work the analysis was performed without keeping exact count of the constants and the large constant for the fundamental anti-commutation test (see Lemma A.2) propagates through the analysis, requiring a very small ε∗ , and yielding a small but constant gap. The protocol is thus far from practical in its current state, although we believe that the constants can be reduced by a tighter analysis. Regarding resource requirements, an honest prover needs O(poly(λ) poly(log m)m) qubits (including EPR pairs) to pass the rigidity test, see Section 3.7.4 for more details regarding the overhead of the QFHE scheme. Similarly, the communication is of order O(poly(λ)m) bits. Completeness and soundness hold for a generic cryptographically small η (λ) against efficient provers, in the sense of Definition 3.11. Instantiating QFHE under polynomial hardness of LWE requires λ = mΩ(1) (Remark 3.6) and yields almost-linear overhead O(m1+ε ) for every ε > 0. Instantiating under sub-exponential hardness of LWE, with λ = (log m)Θ(1/δ) for some e (m). When using our rigidity test in the nonlocal δ ∈ (0, 1), yields resource requirements of O setting the honest prover resource requirements are only O(m), since we manage to avoid the sampling overhead of the extended Pauli braiding test in [CGJV24] and do not consider blindness at this point.

5.3

Sequential repetition

The gap ∆ provided by Theorem 5.1 is a positive but small constant, so the completeness and soundness bounds sit near the Clifford test value ω ∗ . The next lemma shows that the standard, sequential, threshold-based gap amplification works for our construction (allowing only classical advice), by performing a constant number of repetitions, with independent keys. The reduction only requires classical advice: leftover states are sampled by restarting the prover, rather than hardwired as quantum advice. Lemma 5.3 (Sequential repetition). Let p, ∆, pc and ps = pc − ∆ be as in Theorem 5.1, and assume λ and m are large enough for that theorem to apply. There exist constants k ∈ N and t ∈ [k ], independent of λ and |C |, such that the following hold for the k-fold sequential repetition of the compiled Verification protocol VERIFY (C, m, p), obtained from protocol 12, in which each execution uses independently sampled keys and questions, and the verifier accepts if and only if at least t executions accept. 1. (Completeness:) If C ∈ Q-CIRCUITYES , then there is a strategy for the prover, consuming O(poly(λ, log |C |)|C |) total resources, that is accepted with probability at least 2/3. 2. (Soundness:) If C ∈ Q-CIRCUITNO , then any efficient prover strategy is accepted with probability at most 1/3. Proof. For all sufficiently large λ, pc ≥ α is bounded from below and ps ≤ β from above by constants separated by a positive gap ∆ := α − β. Let τ := (α + β)/2 = α − ∆/2 denote the midpoint of the gap which is constant, and set t := ⌈kτ ⌉ for a constant k to be chosen below. 112

Completeness. By the independence of the sequential runs, completeness follows from a concentration bound and choosing an appropriate number of repetitions. On a yes-instance the honest prover of Theorem 5.1 is accepted with probability at least pc ≥ α in a single execution. Repeating that strategy independently—preparing a fresh state at the start of each execution— yields k independent Bernoulli random variables Y1 , . . . , Yk (indicating acceptance) with mean at least pc and Hoeffding’s inequality gives for all a > 0 h k i  Pr ∑ Yi ≤ kα − a ≤ exp −2a2 /k , i =1

where we used that

h k i E ∑ Yi ≥ kα . i =1

The sequential verifier accepts iff ∑ik=1 Yi ≥ t. Setting a = kα − t yields the following bound on the verifier’s rejection probability h k i  Pr ∑ Yi < t ≤ exp −2(kα − t)2 /k . i =1

From t ≤ kτ + 1 and τ = α − ∆/2 we have kα − t ≥ k∆/2 − 1. For k ≥ 8/∆ this is at least k∆/4, hence   exp −2(kα − t)2 /k ≤ exp −2(k∆/4)2 /k = exp(−k∆2 /8). Choosing k ≥ (8/∆2 ) ln 3 > 8/∆ (since ∆ < 1) makes the rejection probability at most 1/3. The k executions contribute only a constant factor to the resource bound of Theorem 5.1. Soundness. Let B be an efficient sequential prover, with only classical advice, and write X = ( X1 , . . . , Xk ) ∈ {0, 1}k for the accept/reject bits of k executions. For i ∈ [k] and u ∈ {0, 1}i−1 write pi (u) := Pr[ X<i = u] and ri (u) := Pr[ Xi = 1 | X<i = u], taking ri (u) = 0 if pi (u) = 0. Fix a threshold constant γ := 2−k /6. A prefix u is common if pi (u) ≥ γ and rare otherwise. Choose any i ∈ [k]. We first claim that ri (u) ≤ ps + η (λ) for every common prefix u ∈ {0, 1}i−1 . Define a single-shot prover Ai,u against VERIFY (C, m, p) as follows: the pair (i, u) is classical advice. The adversary Ai,u repeats the following procedure at most ν := ⌈λ/γ⌉ times: prepare the starting state of B (which is efficient in our adversary model), internally simulate verifiers 1, . . . , i − 1 by sampling their keys and questions independently, perform the interaction and check whether the resulting verdict string equals u. If they match, Ai,u relays B’s i-th execution to the external verifier; if no match is found, in ν iterations, Ai,u aborts and is rejected. Each trial succeeds with probability pi (u) ≥ γ, so the probability that all ν trials fail is at most (1 − pi (u))ν ≤ (1 − γ)ν ≤ e−λ , which is cryptographically small. The state of B on success is distributed exactly as B’s leftover state conditioned on X<i = u, hence   Pr[ Ai,u is accepted] = ri (u) 1 − (1 − pi (u))ν ≥ ri (u) 1 − e−λ . The adversary Ai,u is efficient in the sense of Definition 3.11: k is a constant, so ν = O(λ) and Ai,u incurs only a linear overhead in λ over B, in both the polynomial and the sub-exponential instantiations. Theorem 5.1 therefore bounds its acceptance probability by ps , which rearranges to ri (u) ≤ ps + η (λ). Since we don’t allow quantum auxiliary inputs in our model, the leftover state after i executions, conditioned on a specific verdict, needs to be efficiently preparable. Based on the transcripts alone this is not the case, since it requires post-selecting on the prover’s outgoing messages. However, splitting verdict prefixes into common and rare, the argument above shows that

113

preparing the leftover state in the common case is efficient, by restarting B from its classical advice until the verdict string matches. Let R be the event that there exists an i ∈ [k ] such that the prefix X<i of X is rare. There are at most 2i−1 prefixes of length i − 1, each rare one having probability mass less than γ, so k

Pr[ R] ≤ ∑ 2i−1 γ < 2k γ = i =1

1 . 6

On the complementary event (¬ R) every prefix X<i is common, hence every successive conditional satisfies r ( X<i ) ≤ ps + η (λ). Coupling the verdict bits to independent Bernoulli random variables Z1 , . . . , Zk of mean ps + η (λ) in the usual way (draw Ui uniformly from [0, 1] and set Xi = 1{Ui < r ( X<i )}, Zi = 1{Ui < ps + η (λ)}) yields Xi ≤ Zi on ¬ R, and therefore h k i 1 Pr ∑ Xi ≥ t ≤ Pr[ R] + Pr ∑ Zi ≥ t ≤ + Pr ∑ Zi ≥ t . 6 i =1 i =1 i =1 h k

h k

i

i

(5.4)

The random variables Z1 , . . . , Zk are independent Bernoulli with mean ps + η (λ). Hoeffding’s inequality gives, for all a > 0, h k i  Pr ∑ Zi ≥ k (τ − ∆/4) + a ≤ exp −2a2 /k , i =1

where we used that for all sufficiently large λ one has ps + η (λ) ≤ τ − ∆/4, and thus h k i E ∑ Zi ≤ k (τ − ∆/4) , i =1

Setting a = t − k (τ − ∆/4) (which is positive, since t = ⌈kτ ⌉ ≥ kτ) yields h k i 2  Pr ∑ Zi ≥ t ≤ exp −2 t − k(τ − ∆/4) /k . i =1

From t ≥ kτ we have t − k (τ − ∆/4) ≥ k∆/4, hence 2   exp −2 t − k(τ − ∆/4) /k ≤ exp −2(k∆/4)2 /k = exp(−k∆2 /8). Choosing k ≥ (8/∆2 ) ln 6 > 8/∆ (since ∆ < 1) upper bounds the quantity by 1/6, and the sequential verifier accepts B with probability at most 1/3, by the above and Eq. (5.4). Corollary 5.1. Assuming LWE is hard for non-uniform quantum adversaries in the sense of Definition 3.11, every language L ∈ BQP admits a single-prover, classical-verifier argument with completeness 2/3, soundness 1/3 and total resource requirements O(poly(λ, log |Cx |)|Cx |), where Cx is a circuit deciding L on input x and λ is the LWE security parameter. Instantiating the security parameter as in Remark 3.6 yields almost-linear overhead O(|Cx |1+ε ) for every ε > 0 under e (|Cx |) under sub-exponential hardness. polynomial hardness of LWE, and quasilinear overhead O Proof. The promise problem Q-CIRCUIT is BQP-complete: for every language L ∈ BQP there exists a classical polynomial-time reduction which, on input x, outputs a circuit Cx in the gateset of Definition 5.1, of size poly(| x |), such that Cx ∈ Q-CIRCUITYES if x ∈ L and Cx ∈ Q-CIRCUITNO if x ∈ / L. An argument system for all L ∈ BQP then immediately follows from Lemma 5.3: on input x, the verifier constructs Cx and runs the k-fold sequential repetition of VERIFY (Cx , m, p), with m = Θ(|Cx |). 114

A

Supplementary Material

A.1

Compiled (anti-)commutation tests

Lemma A.1. Let P∗ be any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled commutation game COM ( A, B), obtained from Protocol 2. Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that

∥[ A, B]∥2ψEnc(q) ≤ O(ε) + η (λ), with A, B ∈ Obs(H), P∗ ’s observables that correspond to single-bit answer question labels. Proof. Let W = ( A, B), then W1 = A and W2 = B. By a slight abuse of notation, these are simultaneously the labels for the questions sent by the verifier as well as the observables that the prover applies in the unencrypted part of the interaction. We know from the protocol specification that α is checked to be the encryption of a tuple, since the prover immediately loses if this is not the case, we can assume Dec(α) ∈ {0, 1}2 . The winning probability is then given by ! h i 1 Enc(W ) Dec(α)b ≥ 1 − ε, pwin = 1 + E ∑(−1) Tr Wb ψα 2 b α where we inserted the assumed winning probability from the lemma statement. Rearranging, we obtain γ z }| h i{ Enc(W ) Dec(α)b E ∑(−1) ≥ 1 − 2ε. Tr Wb ψα b

α

Since γ ≤ 1 and b is uniformly distributed over two options (see specification of protocol 2), the following must hold h i γ = ∑(−1)Dec(α)b Tr Wb ψα

Enc(W )

≥ 1 − 4ε.

α

We have h

∑ ∥Wb − (−1)Dec(α) 1∥2ψ ( ) = 2 − 2 ∑(−1)Dec(α) Tr Wb ψα b

b

Enc W α

α

Enc(W )

i

≤ 8ε,

α

for any b ∈ [2]. Since the upper-bound holds for a convex combination of sums of non-negative terms, we know that ∥Wb − (−1)Dec(α)b 1∥2 Enc(W ) ≤ ε α , ψα

with ∑α ε α = 8ε. Since the identity matrix always commutes, we can use the fact that W1 = A and W2 = B approximately act as plus or minus the identity on Alice’s post-measurement state to conclude that they must also approximately commute. For fixed α, we have W1 W2 ≈ε α W1 (−1)Dec(α)2 1 = (−1)Dec(α)2 W1

(−1)Dec(α)2 W1 ≈ε α (−1)Dec(α)2 (−1)Dec(α)1 = (−1)Dec(α)1 (−1)Dec(α)2 (−1)Dec(α)1 (−1)Dec(α)2 ≈ε α (−1)Dec(α)1 W2 = W2 (−1)Dec(α)1 W2 (−1)Dec(α)1 ≈ε α W2 W1 . Chaining these approximate equalities together, we obtain

∥[W1 , W2 ]∥2 Enc(W ) = ∥W1 W2 − W2 W1 ∥2 Enc(W ) ≤ O(ε α ). ψα

ψα

115

Reintroducing the sum over the Alice answer α, this becomes

∥[W1 , W2 ]∥2ψEnc(W ) = ∑ ∥[W1 , W2 ]∥2 Enc(W ) ≤ O(ε). ψα

α

Since the commutator is an efficient LCU, we can switch out the state by Corollary 3.1 (choosing a point distribution on q) and obtain

∥[W1 , W2 ]∥2ψEnc(q) ≤ O(ε) + η (λ), which completes the proof by the definition of W1 and W2 as A and B, respectively. Lemma A.2. Let P∗ be any computationally efficient prover modeled as in Section 3.7.2 that succeeds with probability 1 − ε in the compiled anti-commutation game AC ( A, B), obtained from Protocol 3. Then for all q ∈ Q A there exists a cryptographically small function η (λ) such that

∥{ A, B}∥2ψEnc(q) ≤ O(ε) + η (λ), with A, B ∈ Obs(H), P∗ ’s observables that correspond to single-bit answer question labels. Proof. In [CMM+ 26, Theorem 6.7] it is shown that ∃ η ′ (λ), s.t. ∀ q ∈ Q MS (the questions used in the magic-square test) E

∑ ∥{ B2 , B4 } |ψαc ⟩∥2 ≤ 17280ε + 52η ′ (λ),

sk←Gen(1λ ) α c←Encsk (q)

where η ′ (λ) is a negligible function. In our setting B2 = A (represented by question A), B4 = B (represented by question B), observing |ψαc ⟩ = |ψαc ⟩. Since the anti-commutator is an efficient LCU, we can extend the statement to hold for any q ∈ Q A by Corollary 3.1. Their result also holds in the setting of sub-exponential security of LWE (where nuQPT/negligible are replaced by the second two classes of Definition 3.11), as their protocol can be instantiated from the same QFHE scheme as ours and their analysis only performs the same same type of IND-CPA invocations as our work. The function η (λ) := 52η ′ (λ) is thus cryptographically small in general.

A.2

Isometry circuit calculation

Using the expressions from the previous section, we constructed an explicit quantum circuit, where the choice of gates was informed by replicating the required phases and cross-register correlations (represented by the delta functions). We will explicitly verify that the circuit in Fig. 3 implements the correct operations. The boxed operation on the first two qubits yields

| p1 , p0 , a, b, c⟩ 7→

1 i(2p1 + p0 )(2ℓ1 +ℓ0 ) |ℓ0 , ℓ1 , a, b, c⟩. 2 ℓ ,ℓ ∑ ∈{0,1} 0

1

This step already ensures that the factor shared between the classical and quantum irreps appears. We will first analyze the first half of the circuit, where every operation is controlled on the fact that ℓ0 = 0, after the first two gates, we have r 1 |0, ℓ1 , a, b, c⟩ 7→ (−1)ℓ1 c j +µ j c j |0, ℓ1 , a, b, µ⟩ ∏ 2n µ∈{∑ 0,1}n j∈[n]

116

The doubly controlled Hadamard gate then yields    s | µ | 2  ∏ (−1) a j r j   ∏ δr j ,a j  |0, ℓ1 , r, b, µ⟩. |0, ℓ1 , a, b, µ⟩ 7→ 2n r∈{∑ j∈S(µ) 0,1}n j ∈ S ( µ ⊕1n ) Combining the two we obtain

|0, ℓ1 , a, b, c⟩ 7→

s

1 2n/2

∑

µ,r ∈{0,1}n

2| µ |

2n

∏

(−1)ℓ1 c j +a j r j 

j ∈ S ( µ ⊕1n )

 ∏ (−1)(ℓ1 +1)c j δr j ,a j  |0, ℓ1 , r, b, µ⟩. j∈S(µ)

Applying the Hadamard on b we get   s | µ | 1 2  |0, ℓ1 , a, b, c⟩ 7→ n ∑ ∏ n (−1)ℓ1 cj +aj rj +bj sj  2 µ,r,s∈{0,1}n 2n j ∈ S ( µ ⊕1 )    ∏ (−1)(ℓ1 +1)c j +bj s j δr j ,a j  |0, ℓ1 , r, s, µ⟩. j∈S(µ)

The last step consists of a Toffoli and two swap gates, which yield   s | µ | 1 2  |0, ℓ1 , a, b, c⟩ 7→ n ∑ ∏ n (−1)ℓ1 cj +aj rj +bj sj  2 µ,r,s∈{0,1}n 2n j ∈ S ( µ ⊕1 )    ∏ (−1)(ℓ1 +1)c j +bj s j δr j ,a j  |0, ℓ1 , µ, r ⊕ (s · µ), s⟩. j∈S(µ)

Relabeling r ⊕ (s · µ) 7→ r, we obtain   s 2| µ |  1 |0, ℓ1 , a, b, c⟩ 7→ n ∑ n 2n ∏ n (−1)ℓ1 cj +aj rj +bj sj  2 µ,r,s∈{ 0,1} j ∈ S ( µ ⊕1 ) 

 ∏ (−1)(ℓ1 +1)c j +bj s j δr j ⊕s j ,a j  |0, ℓ1 , µ, r, s⟩. j∈S(µ)

Putting everything together, the first part of the circuit implements the following operation: s i 2|µ| h (2ℓ1 ) 2p1 + p0 | p1 , p0 , a, b, c⟩ 7→ ∑ ρ ( i x ( a ) g ( b ) z ( c )) |0, ℓ1 , µ, r, s⟩ ∑ 23n+2 C,µ r,s ℓ ∈{0,1} µ,r,s∈{0,1}n 1

+

1 ∑ i(2p1 + p0 )(2ℓ1 +1) |1, ℓ1 , a, b, c⟩. 2 ℓ ∈{ 0,1} 1

It remains to explicitly write out the operations that are controlled on ℓ0 = 1, after the Hadamard, T, S and CZ gates, we obtain b

=ω2+ℓ (s j ) j

|1, ℓ1 , a, b, c⟩ 7→

∑

s∈{0,1}n

r

z }|1 { π π 1 c j s j i 4 b j −i 2 s j b j −i π2 ℓ1 b j +iπs j b j ℓ1 (−1) e 2n j∏ ∈[n]

|1, ℓ1 , a, b, s⟩, 117

where we recall that ωℓ (s) = 1{ℓ = 1}ω (s) + 1{ℓ = 3}ω (s), with ω (s) = ei 4 (1−2s) . Next, we have two CNOT and a Hadamard gate π

|1, ℓ1 , a, b, c⟩ 7→

1 (−1)c j s j +a j µ j ω2+ℓ1 (s j )bj |1, ℓ1 , µ, b ⊕ a ⊕ s, s⟩, n ∏ 2 µ,s∈{0,1}n j∈[n]

∑

the final operations are two CZ gates, which yield

|1, ℓ1 , a, b, c⟩ 7→

1 (−1)c j s j +a j µ j +(a j +bj +s j )µ j +s j µ j ω2+ℓ1 (s j )bj n ∏ 2 j∈[n] µ,s∈{0,1}n

∑

|1, ℓ1 , µ, b ⊕ a ⊕ s, s⟩, simplifying the expression we obtain

|1, ℓ1 , a, b, c⟩ 7→

1 (−1)c j s j +bj µ j ω2+ℓ1 (s j )bj δr j ,s j ⊕a j ⊕bj n ∏ 2 µ,r,s∈{0,1}n j∈[n]

∑

|1, ℓ1 , µ, r, s⟩. Combining this with the analysis of the first half of the circuit, we see that our circuit indeed implements the desired operation, which maps r i dµ h (ℓ +2ℓ ) | p1 , p0 , a, b, c⟩ 7→ ∑ ∑ n 23n+2 ρµ 0 1 (i2p1 + p0 x(a) g(b)z(c)) r,s ℓ ,ℓ ∈{0,1} µ,r,s∈{0,1} 0

1

|ℓ0 , ℓ1 , µ, r, s⟩. Since our circuit only uses a constant number of gates per qubit, it implements UQFT in O(n), which is efficient in both senses of Definition 3.11, under the corresponding relation between n and λ.

A.3

Parseval’s identity

Lemma A.3 (Parseval’s identity). Let g : Z2n → L(H) and gb : Z2n → L(H) be its Fourier transform, defined as gb( x ) = E(−1) x·a g( a). a

Then

E g( a)† g( a) = ∑ gb( x )† gb( x ). a

x

Proof. =0 if a̸=b, else 2n

z }|    { † ax † bx ( a+b) x E ∑(−1) g( a)† g(b) ∑ gb(x) gb(x) = ∑ Ea (−1) g(a) · Eb (−1) g(b) = a,b x x x   =2n z }| {     1  0· x † ( a+b) x = 2n  (− 1 ) g ( a ) g ( a ) + (− 1 ) g( a)† g(b) ∑ ∑ ∑ ∑   2 

a

x

a,b a̸=b

= E g( a)† g( a) a

118

x

Corollary A.1. Let g : Z2n → L(H) and gb : Z2n → L(H) be its Fourier transform, defined as gb( x ) = E(−1) x·a g( a). a

Then for all ρ ∈ Pos(H),

E ∥ g( a)∥2ρ = ∑ ∥ gb( x )∥2ρ . a

x

Proof. Apply Lemma A.3 and the definition of the state-dependent norm, with the linearity of the trace.

A.4

Useful results

Lemma A.4. Let |ψ⟩ ∈ H with ⟨ψ|ψ⟩ = α, R ∈ U (H), S ∈ U (H′ ) and V : H → H′ an isometry. Then √ ∥( R − V † SV )|ψ⟩∥2 ≤ ε =⇒ ∥(VR − SV )|ψ⟩∥2 ≤ 4 αε, and

∥(VR − SV )|ψ⟩∥2 ≤ ε

=⇒

∥( R − V † SV )|ψ⟩∥2 ≤ ε.

Proof. We start by showing the first implication. By the assumption of the lemma and the fact that V is an isometry, we have:

∥(VR − VV † SV )|ψ⟩∥2 = ∥( R − V † SV )|ψ⟩∥2 ≤ ε.

(A.1)

Let α := ⟨ψ|ψ⟩, be the squared norm of |ψ⟩. The proof idea is to show that by the assumption of the first implication, the projection onto the image space of the isometry of the vector SV |ψ⟩ is close to the vector VR|ψ⟩. Specifically this can be shown using that R is a unitary and using the triangle inequality   √ α = ∥VR|ψ⟩∥ = ∥ VV † SV + VR − VV † SV |ψ⟩∥   ≤ ∥VV † SV |ψ⟩∥ + ∥ VR − VV † SV |ψ⟩∥ √ √ √ 2 √ ⇔ ∥ΠV SV |ψ⟩ ∥ ≥ α − ε =⇒ ⟨ ϕ | ΠV | ϕ ⟩ ≥ α− ε , | {z } |ϕ⟩

with ΠV := VV † , |ϕ⟩ := SV |ψ⟩, and ⟨ϕ|ϕ⟩ = α, since S is unitary. Since this lower-bound is close to the norm of |ϕ⟩ itself, we can conclude that the projection does not have a large effect and |ϕ⟩ primarily lies in the image space of the isometry, i.e. the unitary S roughly preserves this space. Quantitatively this is expressed by the following upper-bound on the difference between |ϕ⟩ and ΠV |ϕ⟩: √ ∥(VV † SV − SV )|ψ⟩∥2 = ∥(ΠV − 1)|ϕ⟩∥2 = α − ⟨ϕ|ΠV |ϕ⟩ ≤ 2 αε − ε. (A.2) By combining both observations in a transitive manner, we arrive at the following expression:

∥(VR − SV )|ψ⟩∥2 = ∥(VR − VV † SV + VV † SV − SV )|ψ⟩∥2 √ √  ≤ 2ε + 2 2 αε − ε = 4 αε where the inequality follows from (A.1) and (A.2) and the triangle inequality. This shows the first implication.

119

For the reverse implication, |ϕ′ ⟩

z }| { ∥( R − V † SV )|ψ⟩∥2 = ∥V † (VR − SV )|ψ⟩ ∥2

= ⟨ϕ′ |ΠV |ϕ′ ⟩ ≤ ⟨ϕ′ |ϕ′ ⟩ ≤ ε, with |ϕ′ ⟩ := (VR − SV )|ψ⟩ and where the second-to-last inequality follows from the Cauchy– Schwarz inequality. The last inequality follows from the lemma assumption and concludes the proof of the second implication. Lemma A.5. Let A ∈ L(H). Then ∥ A† A∥ = ∥ A∥2 . Proof. For the forward bound,

∥ A ∥2 =



sup ∥ A|v⟩∥

2

⟨v|v⟩≤1

= sup ∥ A|v⟩∥2 = sup ⟨v| A† A|v⟩ ⟨v|v⟩≤1

⟨v|v⟩≤1

†

†

≤ sup ∥|v⟩∥ · ∥ A A|v⟩∥ ≤ sup ∥ A A|v⟩∥ = ∥ A† A∥, ⟨v|v⟩≤1

⟨v|v⟩≤1

where we used a well-known identity for the squared supremum over a set of non-negative reals and the Cauchy–Schwarz inequality. For the reverse bound,

∥ A† A∥ =

sup

|⟨u| A† A|v⟩| ≤ sup ∥ A|v⟩∥2 = ∥ A∥2 ,

⟨u|u⟩,⟨v|v⟩≤1

⟨v|v⟩≤1

where we used the variational definition of the operator norm (in terms of optimizing over two states) and the Cauchy–Schwarz inequality.

References [AAV13]

Dorit Aharonov, Itai Arad, and Thomas Vidick. Guest column: the quantum pcp conjecture. ACM SIGACT News, 44(2):47–79, June 2013, doi:10.1145/2491533.2491549, arXiv:1309.7495.

[AG04]

Scott Aaronson and Daniel Gottesman. Improved simulation of stabilizer circuits. Physical Review A, 70(5), November 2004, doi:10.1103/physreva.70.052328, arXiv:quant-ph/0406196.

[Bau11]

Bernhard Baumgartner. An inequality for the trace of matrix products, using absolute values, 2011, doi:10.48550/ARXIV.1106.6189, arXiv:1106.6189.

[BC12]

Nir Bitansky and Alessandro Chiesa. Succinct Arguments from Multi-prover Interactive Proofs and Their Efficiency Benefits, pages 255–272. Springer Berlin Heidelberg, 2012, doi:10.1007/978-3-642-32009-5 16, IACR ePrint:2012/461.

[BC18]

Johannes Bausch and Elizabeth Crosson. Analysis and limitations of modified circuit-to-hamiltonian constructions. Quantum, 2:94, September 2018, doi:10.22331/q-2018-09-19-94, arXiv:1609.08571.

[BCM+ 21] Zvika Brakerski, Paul Christiano, Urmila Mahadev, Umesh Vazirani, and Thomas Vidick. A cryptographic test of quantumness and certifiable randomness from a single quantum device. Journal of the ACM, 68(5):1–47, August 2021, doi:10.1145/3441309, arXiv:1804.00640.

120

[BFGH08] Debajyoti Bera, Stephen Fenner, Frederic Green, and Steve Homer. Universal quantum circuits, 2008, doi:10.48550/ARXIV.0804.2429, arXiv:0804.2429. [BK25]

James Bartusek and Dakshita Khurana. On the power of oblivious state preparation. In Yael Tauman Kalai and Seny F. Kamara, editors, Advances in Cryptology – CRYPTO 2025, pages 575–607, Cham, 2025. Springer Nature Switzerland, doi:10.1007/978-3032-01878-6 19, arXiv:2411.04234v1.

[BKM+ 25] Kaniuar Bacho, Alexander Kulpe, Giulio Malavolta, Simon Schmidt, and Michael Walter. Compiled nonlocal games from any trapdoor claw-free function. In Advances in Cryptology – CRYPTO 2025, pages 642–673. Springer Nature Switzerland, 2025, doi:10.1007/978-3-032-01878-6 21, IACR ePrint:2024/1829. [BLM26]

James Bartusek, Jiahui Liu, and Giulio Malavolta. A modular approach to succinct arguments for qma. In Advances in Cryptology – EUROCRYPT 2026, pages 446– 474. Springer Nature Switzerland, 2026, doi:10.1007/978-3-032-25336-1 16, IACR ePrint:2026/371.

[Bra18]

Zvika Brakerski. Quantum fhe (almost) as secure as classical. In Advances in Cryptology – CRYPTO 2018, pages 67–95. Springer International Publishing, 2018, doi:10.1007/978-3-319-96878-0 3, IACR ePrint:2018/338.

[Bro18]

Anne Broadbent. How to verify a quantum computation. Theory of Computing, 14(1):1–37, 2018, doi:10.4086/toc.2018.v014a011, arXiv:1509.09180.

[BSCA18]

Joseph Bowles, Ivan Supić, Daniel Cavalcanti, and Antonio Acı́n. Self-testing of Pauli observables for device-independent entanglement certification. Physical Review A, 98(4), October 2018, doi:10.1103/physreva.98.042336, arXiv:1801.10446.

[CGJV24]

Andrea Coladangelo, Alex B. Grilo, Stacey Jeffery, and Thomas Vidick. Verifier-ona-leash: New schemes for verifiable delegated quantum computation, with quasilinear resources. Theory of Computing, 20(1):1–87, 2024, doi:10.4086/toc.2024.v020a003, arXiv:1708.07359.

[CHSH69] John F. Clauser, Michael A. Horne, Abner Shimony, and Richard A. Holt. Proposed experiment to test local hidden-variable theories. Physical Review Letters, 23(15):880– 884, October 1969, doi:10.1103/physrevlett.23.880. [CHTW04] Richard Cleve, Peter Hoyer, Ben Toner, and John Watrous. Consequences and limits of nonlocal strategies. In Proceedings. 19th IEEE Annual Conference on Computational Complexity, 2004., pages 236–249. IEEE, 2004, doi:10.1109/ccc.2004.1313847, arXiv:quant-ph/0404076. [CMM+ 26] David Cui, Giulio Malavolta, Arthur Mehta, Anand Natarajan, Connor Paddock, Simon Schmidt, Michael Walter, and Tina Zhang. A computational Tsirelson’s theorem for the value of compiled XOR games. Quantum, 10:1987, January 2026, doi:10.22331/q-2026-01-27-1987, arXiv:2402.17301v3. [DCOT18] Marcus De Chiffre, Narutaka Ozawa, and Andreas Thom. Operator algebraic approach to inverse and stability theorems for amenable groups. Mathematika, 65(1):98–118, August 2018, doi:10.1112/s0025579318000335, arXiv:1706.04544. [dlS25]

Mikael de la Salle. Spectral gap and stability for groups and non-local games. Journal de l’École polytechnique — Mathématiques, 12:1417–1444, September 2025, doi:10.5802/jep.314, arXiv:2204.07084.

121

[FKD18]

Samuele Ferracin, Theodoros Kapourniotis, and Animesh Datta. Reducing resources for verification of quantum computations. Physical Review A, 98(2), August 2018, doi:10.1103/physreva.98.022323, arXiv:1709.10050.

[FWZ23]

Honghao Fu, Daochen Wang, and Qi Zhao. Parallel self-testing of epr pairs under computational assumptions. In 50th International Colloquium on Automata, Languages, and Programming (ICALP 2023), volume 261, pages 64:1–64:19. Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2023, doi:10.4230/LIPICS.ICALP.2023.64, arXiv:2201.13430.

[GH17]

W Timothy Gowers and Omid Hatami. Inverse and stability theorems for approximate representations of finite groups. Sbornik: Mathematics, 208(12):1784–1817, December 2017, doi:10.1070/sm8872, arXiv:1510.04085.

[GKW15]

Alexandru Gheorghiu, Elham Kashefi, and Petros Wallden. Robustness and device independence of verifiable blind quantum computing. New Journal of Physics, 17(8):083040, August 2015, doi:10.1088/1367-2630/17/8/083040, arXiv:1502.02571.

[GMP23]

Alexandru Gheorghiu, Tony Metger, and Alexander Poremba. Quantum cryptography with classical communication: Parallel remote state preparation for copy-protection, verification, and more. In 50th International Colloquium on Automata, Languages, and Programming (ICALP 2023), volume 261, pages 67:1–67:17. Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2023, doi:10.4230/LIPICS.ICALP.2023.67, arXiv:2201.13445.

[Gri19]

Alex B. Grilo. A simple protocol for verifiable delegation of quantum computation in one round. In 46th International Colloquium on Automata, Languages, and Programming (ICALP 2019), volume 132, pages 28:1–28:13. Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2019, doi:10.4230/LIPICS.ICALP.2019.28, arXiv:1711.09585.

[GV19]

Alexandru Gheorghiu and Thomas Vidick. Computationally-secure and composable remote state preparation. In 2019 IEEE 60th Annual Symposium on Foundations of Computer Science (FOCS), pages 1024–1033. IEEE, November 2019, doi:10.1109/focs.2019.00066, arXiv:1904.06320v1.

[GV24]

Aparna Gupte and Vinod Vaikuntanathan. How to construct quantum fhe, generically. In Advances in Cryptology – CRYPTO 2024, pages 246–279. Springer Nature Switzerland, 2024, doi:10.1007/978-3-031-68382-4 8, arXiv:2406.03379.

[HBD+ 15] B. Hensen, H. Bernien, A. E. Dréau, A. Reiserer, N. Kalb, M. S. Blok, J. Ruitenberg, R. F. L. Vermeulen, R. N. Schouten, C. Abellán, W. Amaya, V. Pruneri, M. W. Mitchell, M. Markham, D. J. Twitchen, D. Elkouss, S. Wehner, T. H. Taminiau, and R. Hanson. Loophole-free Bell inequality violation using electron spins separated by 1.3 kilometres. Nature, 526(7575):682–686, October 2015, doi:10.1038/nature15759, arXiv:1508.05949. [KKR26]

Yael Tauman Kalai, Dakshita Khurana, and Justin Raizes. How to classically verify a quantum cat without killing it, 2026, doi:10.48550/ARXIV.2602.09282, arXiv:2602.09282.

[KLVY23]

Yael Kalai, Alex Lombardi, Vinod Vaikuntanathan, and Lisa Yang. Quantum advantage from any non-local game. In Proceedings of the 55th Annual ACM Symposium on Theory of Computing, STOC ’23, pages 1617–1628. ACM, June 2023, doi:10.1145/3564246.3585164, arXiv:2203.15877. 122

[KR09]

Yael Tauman Kalai and Ran Raz. Probabilistically Checkable Arguments, pages 143–159. Springer Berlin Heidelberg, 2009, doi:10.1007/978-3-642-03356-8 9.

[KRR21]

Yael Tauman Kalai, Ran Raz, and Ron D. Rothblum. How to delegate computations: The power of no-signaling proofs. Journal of the ACM, 69(1):1–82, November 2021, doi:10.1145/3456867, IACR ePrint:2013/862.

[Kup23]

Greg Kuperberg. Breaking the cubic barrier in the solovay-kitaev algorithm, 2023, doi:10.48550/ARXIV.2306.13158, arXiv:2306.13158.

[MA25]

Ilya Merkulov and Rotem Arnon. Entropy accumulation under post-quantum cryptographic assumptions. Entropy, 27(8):772, July 2025, doi:10.3390/e27080772, arXiv:2307.00559.

[Mah18]

Urmila Mahadev. Classical verification of quantum computations. In 2018 IEEE 59th Annual Symposium on Foundations of Computer Science (FOCS), pages 259–267. IEEE, October 2018, doi:10.1109/focs.2018.00033, arXiv:1804.01082.

[Mah20]

Urmila Mahadev. Classical homomorphic encryption for quantum circuits. SIAM Journal on Computing, 52(6):FOCS18–189–FOCS18–215, December 2020, doi:10.1137/18m1231055.

[Mer90]

N. David Mermin. Simple unified form for the major no-hiddenvariables theorems. Physical Review Letters, 65(27):3373–3376, December 1990, doi:10.1103/physrevlett.65.3373.

[MM11]

Matthew McKague and Michele Mosca. Generalized Self-testing and the Security of the 6-State Protocol, pages 113–130. Springer Berlin Heidelberg, 2011, doi:10.1007/9783-642-18073-6 10, arXiv:1006.0150.

[MNZ24]

Tony Metger, Anand Natarajan, and Tina Zhang. Succinct arguments for QMA from standard assumptions via compiled nonlocal games. In 2024 IEEE 65th Annual Symposium on Foundations of Computer Science (FOCS), pages 1193–1201. IEEE, October 2024, doi:10.1109/focs61266.2024.00078, arXiv:2404.19754.

[MV21]

Tony Metger and Thomas Vidick. Self-testing of a single quantum device under computational assumptions. Quantum, 5:544, September 2021, doi:10.22331/q-202109-16-544, arXiv:2001.09161.

[MY04]

Dominic Mayers and Andrew Yao. Self testing quantum apparatus. Quantum Information & Computation, 4(4):273–286, July 2004, arXiv:quant-ph/0307205.

[NV17]

Anand Natarajan and Thomas Vidick. A quantum linearity test for robustly verifying entanglement. In Proceedings of the 49th Annual ACM SIGACT Symposium on Theory of Computing, STOC ’17, pages 1003–1015. ACM, June 2017, doi:10.1145/3055399.3055468, arXiv:1610.03574.

[NZ23]

Anand Natarajan and Tina Zhang. Bounding the quantum value of compiled nonlocal games: From CHSH to BQP verification. In 2023 IEEE 64th Annual Symposium on Foundations of Computer Science (FOCS), pages 1342–1348. IEEE, November 2023, doi:10.1109/focs57990.2023.00081, arXiv:2303.01545.

[Per90]

Asher Peres. Incompatible results of quantum measurements. Physics Letters A, 151(3–4):107–108, December 1990, doi:10.1016/0375-9601(90)90172-k.

[Rai26]

Justin Raizes. How to classically verify a quantum cat without killing it. CIS Seminar, EECS Department, MIT, April 2026. Invited talk. 123

[RUV13]

Ben W. Reichardt, Falk Unger, and Umesh Vazirani. Classical command of quantum systems. Nature, 496(7446):456–460, April 2013, doi:10.1038/nature12035, arXiv:1209.0449.

[Ser77]

Jean-Pierre Serre. Linear Representations of Finite Groups. Springer New York, 1977, doi:10.1007/978-1-4684-9458-7.

[Tsi87]

B. S. Tsirel’son. Quantum analogues of the Bell inequalities. the case of two spatially separated domains. Journal of Soviet Mathematics, 36(4):557–570, February 1987, doi:10.1007/bf01663472.

[Vid21]

Thomas Vidick. Course FSMP, fall’20: Interactions with quantum devices. https: //www.epfl.ch/labs/qcc/wp-content/uploads/2026/01/fsmp.pdf, 2021. [Accessed 15.05.2026].

[WBMS16] Xingyao Wu, Jean-Daniel Bancal, Matthew McKague, and Valerio Scarani. Deviceindependent parallel self-testing of two singlets. Physical Review A, 93(6), June 2016, doi:10.1103/physreva.93.062121, arXiv:1512.02074. [Zha22]

Jiayu Zhang. Classical verification of quantum computations in linear time. In 2022 IEEE 63rd Annual Symposium on Foundations of Computer Science (FOCS), pages 46–57. IEEE, October 2022, doi:10.1109/focs54457.2022.00012, arXiv:2202.13997.

[Zha25]

Jiayu Zhang. Formulations and constructions of remote state preparation with verifiability, with applications. In 16th Innovations in Theoretical Computer Science Conference (ITCS 2025), volume 325, pages 96:1–96:19. Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2025, doi:10.4230/LIPICS.ITCS.2025.96, arXiv:2310.05246.

124

Record · ID 1122185 · SHA-256 a2bda9fe8d0e73f1
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.