EFI Pairs Without One-Way Puzzles: Oracle Separations from Communication Complexity Atul Mantri ∗
arXiv:2609.11901v1 [quant-ph] 10 Sep 2026
Department of Computer Science, Virginia Tech, USA 24061
Abstract EFI pairs (Brakerski, Canetti, and Qian, ITCS 2023) and one-way puzzles (Khurana and Tomer, STOC 2024) are the leading candidates for the minimal assumption of quantum cryptography. The first are efficiently preparable quantum states, statistically far yet computationally indistinguishable; the second are classical puzzles, easy to sample and hard to solve. One-way puzzles imply EFI pairs, and whether the converse holds is open. We construct a single classical oracle relative to which one-way puzzles do not exist, even with an unbounded verifier, while an EFI pair survives every distinguisher that queries the oracle classically throughout and holds advice about it, making its one superposition query at the end. The oracle answers every question about the output probabilities of quantum samplers, which removes the puzzles, and hides a Haar-random half-dimensional subspace. To prove security we reduce it to communication complexity. An adversary whose knowledge of the subspace arrives as classical query answers can be simulated inside a two-party protocol against the party holding it, so it does no better than the best classical protocol for Vectorin-Subspace (Klartag and Regev, STOC 2011), whatever the oracle computes. That argument does not cover the superposition query, which we bound instead using tools from random matrix theory. The same attack gives a classical simulation of any quantum party in a classical-message protocol with no entanglement shared in advance, so relative to the oracle there is no proof of quantumness either. Quantum polynomial time therefore offers no advantage on any task with classical inputs and outputs, while the two quantum states stay indistinguishable. We state conjectures on removing the restriction on superposition queries.
∗
1
Contents 1 Introduction 1.1 Main results . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.2 Technical overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.3 Comparison with Lombardi–Ma–Wright . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.4 The question of fully coherent access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.5 Related work . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
3 4 8 13 15 15
2 Preliminaries 17 2.1 Notation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 2.2 Operators and effects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 2.3 Haar-random subspaces and the half-subspace pair . . . . . . . . . . . . . . . . . . . . . . . . 19 2.4 The query model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 2.5 EFI pairs and one-way puzzles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20 2.6 Classical communication complexity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2.7 The Vector-in-Subspace problem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 3 Security from communication complexity
24
4 The oracle and the primitives it removes 27 4.1 The state source . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27 4.2 The counting oracle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 4.3 Nonexistence of one-way puzzles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30 4.4 Nonexistence of QEFID pairs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 4.5 Interactive protocols with classical messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 5 EFI security 38 5.1 Reference copies and the residual instance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 5.2 The security theorem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 5.3 The optimal advantage of a classical adversary . . . . . . . . . . . . . . . . . . . . . . . . . . 42 5.4 The one-way rate for VSPn . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44 6 Coherent queries 47 6.1 Concentration of measure on the classical compact groups . . . . . . . . . . . . . . . . . . . . 47 6.2 A variance bound for linear statistics of a Haar-conjugated observable . . . . . . . . . . . . . 49 6.3 The one-query bound . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 6.4 Quantum advice . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54 6.5 Classical queries followed by one coherent query . . . . . . . . . . . . . . . . . . . . . . . . . . 58 7 The separation relative to a single classical oracle 65 7.1 The oracle and the generator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65 7.2 The separation theorem . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 66 7.3 The black-box barrier . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70 8 Fully coherent access
70
9 Discussion and open problems
77
A The conditional-sampling attack
85
B The two rates
86
C Deferred proofs
94
D The sharp rate for the half-subspace pair
98
2
1
Introduction
Classical cryptography is organized around a single minimal primitive. One-way functions are necessary and sufficient for essentially all of Minicrypt, so that one assumption governs commitments, symmetric encryption, signatures, and zero knowledge. Quantum cryptography has no such primitive. Instead, a line of work beginning with Ji, Liu, and Song [JLS18] has shown that quantum commitments, and through them secure two-party and multiparty computation, follow from assumptions that are not known to imply one-way functions and are plausibly weaker [MY22; AQY22; KT24; BCQ23]. Out of that line two candidates for the minimal assumption have emerged. The first is the EFI pair of Brakerski, Canetti, and Qian [BCQ23]: a family of pairs of mixed states (ρ0,λ , ρ1,λ ) that are efficiently generatable, statistically f ar, and computationally indistinguishable. EFI pairs turn out to be equivalent to quantum bit commitments, and are therefore necessary and sufficient for oblivious transfer, for secure multiparty computation, and for quantum computational zero knowledge for all of QIP [BCQ23]. They are also equivalent, up to O(log λ) bits of non-uniformity, to single-copy pseudorandom states [Cav+25a]. The second candidate is the one-way puzzle of Khurana and Tomer [KT24]: a pair (Samp, Ver) in which the sampler Samp is an efficient quantum algorithm producing a classical key–puzzle pair (k, s), while the verifier Ver is computationally unbounded. Since challenge and solution are both classical, one-way puzzles are the natural notion of one-wayness for quantum computation with classical communication [CGG24]. They are implied by pseudorandom states, by one-way state generators, and by quantum money, and they in turn imply quantum commitments [KT24; CGG24]. Moreover, their classically-secure variant characterizes inefficient-verifier proofs of quantumness against uniform adversaries [MSY25]. One-way puzzles imply EFI pairs, and whether the converse holds is open. The two primitives ask for hardness of different kinds. A one-way puzzle asks for a classical search problem that is hard on average, whereas an EFI pair asks only that two quantum states be hard to tell apart. The question is whether the second kind of hardness always brings the first with it. Equivalently, it is the question of where the boundary lies between the two lowest worlds in the classification of [Gol+24]. One asymmetry is already known: one-way puzzles cannot exist if BQP = PP, so counting power removes them, whereas EFI pairs have no known attack from any fixed classical complexity oracle. The state of the art is due to Bostanci, Chen, and Nehoran [BCN25], who show that in the common Haar random state (CHRS) model, augmented by unitary oracles for large complexity classes, EFI pairs exist while one-way state generators and sample-efficient one-way puzzles do not. That last restriction is deliberate rather than technical, since one-way puzzles with an inefficient verifier are in fact constructed in the same augmented model. The reason is that a common Haar random state does not remove the difficulty of estimating the output probabilities of quantum samplers, and one-way puzzles exist precisely when that estimation problem is hard on average [Cav+25c; HM25]. The following question therefore remains. Is there an oracle relative to which EFI pairs exist but one-way puzzles, including the inefficiently verifiable notion, do not? In other words, we are asking whether the minimal assumption of quantum cryptography can be separated from classical average-case hardness. An affirmative answer would say that, relative to an oracle, commitments and everything built from them can rest on hardness that is not the hardness of any classical search problem, and hence that no relativizing argument derives a one-way puzzle from an EFI pair. 3
The characterization of [Cav+25c] suggests how to proceed. To remove one-way puzzles we should hand every oracle-aided sampler its own output probabilities, so that estimating them becomes easy. The difficulty is that those probabilities depend on the hidden object out of which the EFI pair is built, so the oracle that removes the puzzles also leaks information about the object on which the pair’s indistinguishability rests. The rest of the paper shows that the two can coexist.
1.1
Main results
We answer the question affirmatively for distinguishers with coherent-last access, a model made precise below. Definition 2.3 names the resulting notion of security, and Corollary 7.6 states the black-box barrier it yields. Throughout, n = n(λ) = 2λ and H ⊆ Rn is a Haar-random subspace of dimension n/2. The pair we hide consists of the maximally mixed states on H and on its orthogonal complement, 2PH 2PH ⊥ ρ0 = , ρ1 = . n n The two states have orthogonal supports, so a party who knows H tells them apart with certainty: it measures {PH , PH ⊥ }. A party who does not know H has no such measurement available. The question is how much of H an oracle-aided adversary can learn. We hide a subspace because of a property that Theorem C isolates. Deciding which of the two states one holds is a two-party problem that is easy for quantum communication and hard for classical communication, and the security proof turns that gap into a bound on the distinguisher’s advantage. The oracle itself is a pair O = (R, Count). The source R returns, on input (b, 1λ ), one fresh copy of ρb . The counting oracle Count is classical, and when asked about an oracle-aided quantum sampler C with classical output it returns bits of the exact output probability Pr[C O (1λ ) = x]. Such a sampler may of course query O in turn, so the definition as just stated would be circular. We break the circularity by giving each query a rank: a query of rank r may ask only about samplers whose own calls have rank below r. One thing has to be fixed before we can state the results. In an oracle model the access a distinguisher is granted is part of the security claim, so security must be stated against a named class of distinguishers. The class below grants every resource the EFI game requires, together with a full polynomial budget of classical queries, and restricts only where superposition queries may occur. Model 1.1 (Coherent-last access). A distinguisher has coherent-last access to an oracle if it may do the following, in this order: (o) receive advice depending arbitrarily on the oracle, either a classical string of polynomial length or a quantum state on ( 13 − ε)λ qubits for a fixed ε > 0 (Corollary 6.18; Corollary D.2 raises this to (1 − ε)λ); (i) obtain polynomially many reference copies of both outputs, from honest executions of the generator run by the challenger, which returns only the designated output register; (ii) make polynomially many adaptive classical queries of polynomial total length, interleaved with arbitrary quantum processing; and (iii) make one coherent query on polynomially many qubits, that is, of width M = 2poly(λ) , before measuring. Its computational power is otherwise unbounded. Equivalently, every oracle interaction but the last is classical. 4
Theorem A (EFI pairs without one-way puzzles; informal, Theorem 7.2) O′ :
There is a single deterministic Boolean oracle O′ on classical strings such that, relative to
(i) one-way puzzles do not exist, even with a computationally unbounded verifier, and the attack is a classical polynomial-time algorithm making classical queries, so classicallysecure puzzles and QEFID pairs are ruled out as well; and (ii) an approximation of the half-subspace pair, stored in the oracle, is efficiently generatable with TD ≥ 1 − 2−Ω(λ) , and every QPT distinguisher with coherent-last access (Model 1.1) has advantage 2−Ω(λ) against it. Part (i) holds for every fixing of the oracle’s randomness, and part (ii) with probability one. Part (i) carries no restriction on access: the attack is classical, so it applies verbatim to adversaries that query O′ in superposition. Part (ii) makes the pair a classical-advice EFI pair (Definition 2.3), secure in addition against quantum advice of linearly many qubits, and it yields a black-box barrier: no fully black-box construction of one-way puzzles from EFI pairs has a security reduction in the class of Model 1.1 (Corollary 7.6). Part (i) is elementary: because Count returns exact bits, the attack is a short conditionalsampling argument. All of the difficulty lies in part (ii), and there it is imported rather than manufactured: from the communication lower bound of Klartag and Regev for the classical queries, and from matrix concentration for the coherent one. We build and analyze the oracle in two stages. Section 4 through Section 6 work with an idealized source that returns a fresh sample on every call, since that is the form the concentration arguments require, and Section 7 then implements that source inside a Boolean function, so that the final oracle O′ is classical. Scope of the access model. Part (i) carries no restriction. The attack is a classical polynomialtime algorithm making classical queries, so it applies verbatim to adversaries with full coherent access to O′ . Only part (ii) is restricted. Two features define the class of Model 1.1 against which it is proved. The first is the placement of the coherent query. In the standard quantum oracle model an algorithm may query a classical oracle in superposition throughout, whereas here one such query comes last. Running the public generator oneself costs one coherent query per execution, so a distinguisher may do that once, and further executions are then supplied to it as reference copies run by the challenger. The second feature is the advice, which may be classical of any polynomial length, or quantum on O(λ) qubits (Corollary 6.18). Against quantum advice alone, by contrast, the pair is secure at every polynomial size (Corollary 6.10). Corollary 7.6 draws the black-box consequence: a reduction escapes the class only by making two or more adaptive coherent queries, or else one coherent query followed by classical ones. Comparison with known coherent-query bounds. The restriction to one coherent query is not special to our construction. We know of no ensemble for which a lower bound is available against more than one adaptive coherent query to an arbitrary Boolean function of the secret, at the width M = 2poly(λ) that this model forces. The state of the art is a single query together with polynomially many parallel ones for the phase-state ensemble [LMW24], explicit one-query separations for structured unitaries [DLM26], and a bound at “one and a half” for pseudorandom 5
states [Hua25], whose sharper form is conditional and whose unconditional form does not reach the width we need. To these we add two statements that reach past a single query (Proposition 8.5, Proposition 8.6), and coherent-last access grants in addition a full polynomial budget of adaptive classical queries, which none of those settings addresses (Table 1). Removing both features at once is what Conjecture 8.2 asks for. Resolving it affirmatively would also admit quantum advice of any polynomial size (Section 8), and Section 1.4 returns to the question. Part (i) is stronger than the nonexistence of one-way puzzles. The estimator behind it applies to any party in a protocol whose messages are classical, sent one outgoing bit at a time, and it collapses quantum polynomial time to classical throughout that setting. Theorem B (interactive collapse; informal, Theorem 4.14, Corollary 4.15) Relative to O′ , every quantum polynomial-time party in a protocol whose messages are classical, with no entanglement or other correlated setup shared in advance, is simulated by a classical polynomial-time party making classical queries to O′ , to within 2−λ in total variation on the whole transcript. The simulation is uniform in the counterparty, which may have unbounded computational power. Consequently, relative to O′ there is no proof of quantumness even against an unbounded verifier, and every quantum-samplable classical distribution is classically samplable. The proof of part (ii) is different in kind, and it uses nothing about Count beyond the fact that its answers are classical bits. Since hiding a subspace is only one way to apply it, we state it separately. Theorem C (security from communication complexity; informal, Theorem 3.2) Let X be a hidden random object, and let ΠX be the two-party problem in which Bob holds X, Alice holds a classical description of a sample from ρ0 (X) or from ρ1 (X), and Alice must say which one after classical communication. Write βΠ (ℓ) for the best advantage that a classical protocol for ΠX achieves with ℓ bits. Suppose that, apart from the challenge and declared classical side information, a distinguisher’s dependence on X runs through L bits of classical query-and-answer traffic with an oracle determined by X, together with a bits of classical advice. Then its average advantage is at most 2βΠ (L + a + 1). The oracle need only be deterministic; it may be arbitrarily powerful, and it need not be computable. Security thus reduces to a communication lower bound, and it does so no matter how powerful the oracle is. Notice what is being bounded here: not what the oracle can compute, but how much of X actually reaches the adversary. Adaptivity and the number of queries, in particular, cost nothing beyond what they contribute to the total length L, because a two-way protocol charges only the length of the conversation. Section 3 makes the comparison with a one-query coherent bound precise. Advice, by contrast, we charge directly. Advice about X is itself a message from Bob, so a bits of it degrade the budget from L to L + a + 1, and they do so even when the advice is chosen after the oracle has been fixed. Theorem C also constrains the construction, through two requirements. The pair must be usable, so the associated two-party problem has to be easy for quantum communication: the holder of the challenge sends her state to the holder of the secret, who measures it. The pair must also not leak, so the same problem has to be hard for classical communication. We need, then, a problem 6
whose quantum and classical communication complexities are far apart, and the size of that gap is the security we obtain. Of the two requirements, the classical one is built into the bound itself, which certifies nothing once ΠX admits a cheap classical protocol. The quantum one is automatic (Proposition 3.3): the holder of X can always perform the Helstrom measurement on a state that Alice sends in ⌈log2 d⌉ qubits. Any use of Theorem C rests on such a gap. The standard example of a problem with that gap is Vector-in-Subspace, VSPn , studied by Klartag and Regev [KR11]. Here Bob holds a half-dimensional subspace H ⊆ Rn , Alice holds a unit vector promised to lie either in H or in H ⊥ , and Alice must decide which. Quantumly the problem is easy. An O(log n)-qubit two-message protocol decides it with certainty: Alice sends the vector encoded in amplitudes, and Bob, who knows H, measures {PH , PH ⊥ } and returns the outcome. Classically it is hard. The randomized communication complexity is Ω(n1/3 ), even with two-way interaction and shared randomness. This is why the pair we hide is built from a halfdimensional subspace. Theorem D turns to coherent queries. A separation in the standard quantum oracle model has to handle them, and Theorem C provably cannot, since a coherent query behaves like quantum communication and VSP is exponentially easy in that model. Theorem D (coherent queries; informal, Theorem 6.6, Corollary 6.8, Corollary 6.10, Theorem 6.13, Proposition 8.5, Proposition 8.6) Let fH : [M ] → {±1} be an arbitrary Boolean function of H, accessed as a phase oracle, and assume nothing about the adversary’s computational power. Against (ρ0 , ρ1 ): (i) one coherent query has average bias O p bias O t log(2M )/n ;
log(2M )/n , and t parallel queries have average
p
√ (ii) m qubits of quantum advice give bias O( m + 1/n), so m = Θ(n2 ) is the exact threshold for constant bias; (iii) poly(λ) adaptive classical Count-queries followed by one coherent query, with reference copies and advice, classical or of linearly many qubits, give advantage negl(λ); (iv) advice of dimension n2−ε with one coherent query of any width, and two adaptive coherent queries whose first has width n2−ε however wide the second, give bias 2−Ω(λ) . Part (iii) is the full game of Theorem A(ii); the others take one challenge copy and no reference copies, and part (iv) is as far past one query as the argument reaches. Theorem E asks the opposite question: not how little the oracle reveals, but how much. Two rates come out of it. The first measures what a natural class of classical adversaries learns, and the second measures what a message is worth in the one-way model of the communication problem behind it. Theorem E (two rates; informal, Proposition 5.8, Proposition 5.10) (i) An adversary that measures its challenge copy with any H-independent POVM, takes no reference copies, and is then told the exact probability of every outcome, a relaxation √ of the bits Count supplies, has average advantage at most 2/ πn. Measuring in the
7
computational basis with O(λ) classical queries attains this to within a factor 1 − O(n−1 ), √ so the rate in this model is 2/ πn (1 + O(n−1 )): sharp to the leading constant, not an exact finite-n optimum. √ (ii) In the one-way model of VSPn an L-bit message yields advantage O(L/ n), while Ω(n−1/2 ) is available already at logarithmic length. This holds at every message length, on the exact promise and the rotation-invariant distribution; the constant-advantage endpoint it √ recovers, Θ( n) bits, is already known by a different route (Section 5.4). √ The upper and lower bounds of part (i) agree asymptotically, at the rate 2/ πn, and three consequences follow. First, the dimension must be superpolynomial rather than merely large, since negligible security forces n = λω(1) . Second, the security level is 2−Θ(λ) on both sides, so that the gap between the n−1/6 we prove and the n−1/2 an attack achieves is a gap in the exponent only. That gap comes from converting a constant-error communication bound into a small-advantage one, and not from the Ω(n1/3 ) bound itself (Section 5.3). Third, the same rate is the most that a single bit of information about H can ever be worth (Lemma 6.5), and each answer of the counting oracle is exactly one such bit. The scale n−1/2 √ then appears once more in Theorem D, as the value of one coherent query, tight there up to log M , and Corollary 6.7 shows that a one-query adversary attains it. Part (ii), finally, is a statement about VSPn alone, proved by a spectral argument that is independent of the rest of the paper. Section 5.4 relates it to the program aiming at the same bound for two-way protocols. Primitives removed along with one-way puzzles. One-way puzzles do not exist relative to O′ , and so neither does any primitive known to imply them: multi-copy pseudorandom states (PRS) and unitaries, pure-output one-way state generators, and quantum money mini-schemes with pure banknotes. Corollary 4.10 proves this for the source-model oracle of Section 4, and the argument applies verbatim to O′ , since Theorem 7.2(i) is the same attack, as is Theorem B. The qualifier “multi-copy” is necessary, for the following reason. By [Cav+25a], EFI pairs are equivalent to single-copy pseudorandom states, up to O(log λ) bits of non-uniformity in the state family. Suppose that equivalence relativizes to the access model of Theorem 7.2, preserving its advice convention and query budget. Then single-copy pseudorandomness survives O′ in that model, and O′ separates multi-copy from single-copy pseudorandomness, which is the separation studied in [CCS25]. Section 4.3 states precisely the condition on relativization that this inference depends on.
1.2
Technical overview
Theorem A combines two oracle layers whose requirements conflict. Removing one-way puzzles requires that every oracle-aided sampler be handed its own output probabilities, because by [Cav+25c; HM25] the average-case hardness of estimating those probabilities is exactly what a one-way puzzle provides. Those probabilities are, however, functions of the hidden subspace, so the layer that removes the puzzle bears directly on the pair that is supposed to remain indistinguishable. The two are compatible because the counting oracle is queried classically and answers in single bits, and because by the communication lower bound no polynomial number of classical bits about H suffices to distinguish the pair. 8
We sketch the argument here in the order in which the proof develops it; the formal treatment occupies Section 3 through Section 7. There are four parts. We first define the counting layer and show that it removes every form of classical-output hardness. We then ask what a bounded classical transcript about H is worth, which turns out to be a question of communication complexity, and this settles the classical part of the access model. Next we ask what one superposition query is worth; no communication argument can reach that question, so we treat it in query complexity instead, and then combine the two bounds. Finally we replace the state source by a Boolean function, so that the oracle becomes a single classical object, and we draw the black-box barrier. Along the way we collect two exact rates, which measure what the oracle does leak. The counting oracle. The samplers whose probabilities Count reports may themselves query Count, and without some restriction on this the definition is inconsistent. To see the difficulty, consider a sampler that requests the leading bit of its own probability of outputting 0 and then outputs that bit. No answer to that query is consistent with the sampler’s behavior (Example 4.2). We therefore assign each query a rank, much as the polynomial hierarchy is stratified by alternation depth, and permit a rank-r query to refer only to samplers whose own calls have rank below r. We can then define the whole family by an ordinary recursion on r, and we need no fixed-point theorem to do so (Lemma 4.5). Two features of the definition matter later, and both concern how it is stated rather than what it says. The first is that the rank condition is checked against the description the oracle is handed, and not against the behavior of the sampler that description defines. This is necessary, because a sampler may compute its rank at runtime, possibly in superposition, in which case there is no single behavior to inspect (Section 4.2). The second is that Count returns exact bits of the probability rather than an approximation. Consequently we never have to control an accumulation of approximation error across ranks, and the coherent form of the oracle remains an ordinary Boolean function (Definition 4.4). Removing classical-output hardness. Because the bits are exact, t classical queries pin an output probability down to additive error 2−t , so that error 2− poly(λ) is available at polynomial cost (Lemma 4.6). Given that, the attack on one-way puzzles is elementary. What the adversary would like, on being given a puzzle s, is to sample a key from the true conditional distribution of keys given s, since a key drawn that way is accepted by the honest verifier just as often as an honest key is. It can do exactly this, one bit at a time. Indeed, the conditional probability of the next key bit is a ratio of two output probabilities, namely those of the samplers “run Samp(1λ ) and output (s, k1 · · · ki )”, and both are available from Count. A hybrid argument over the m key bits then places the joint distribution of (s, A(s)) within 2−λ of the honest one (Lemma A.1), by separating the prefixes that carry little probability from those on which the estimates are relatively accurate. Both halves of that accounting – the local one and the threshold – are shared with the interactive simulation below, so we state them once (Lemma 4.7, Lemma 4.8). The unbounded verifier then accepts with probability 1 − negl(λ). Notice that the adversary never runs Ver, so we need no assumption on the verifier. Notice too that it is a classical algorithm making classical queries, so classically-secure puzzles are ruled out as well (Theorem 4.9). The same estimates settle the corresponding decision problem. With exact bits in hand the likelihood-ratio test between two classical-output samplers becomes computable, so relative to O no such pair is closer computationally than it is statistically (Proposition 4.11), and QEFID pairs do not exist either (Corollary 4.12). The estimator applies round by round to an interactive party as well. Simulating each outgoing 9
bit in turn replaces any QPTO party in a classical-message protocol by a classical one, and does so against every counterparty at once (Theorem 4.14), so that relative to O there is no proof of quantumness even with an unbounded verifier (Corollary 4.15). Taken together, these three statements say what can survive O. On any task with classical inputs and outputs, quantum polynomial time gains nothing over classical polynomial time. Whatever hardness survives O must be of a different kind altogether, namely the indistinguishability of two quantum states. Security from a classical transcript. Suppose that every route from the hidden object X to the adversary carries classical data. Then we may run the adversary inside a two-party game, with one player running it while a second player, who holds X and is computationally unbounded, answers its queries. Each query becomes a message and each answer a message in return, so the advantage is bounded by the length of that conversation and by nothing else, and in particular not by anything the oracle happens to be able to compute (Theorem 3.2). Adaptivity and the number of queries cost nothing here, since a two-way protocol charges only the total length of the conversation. Advice about X, on the other hand, is itself a message from the holder of X, so a bits of advice cost a + 1 bits of budget, and they do so even when the advice is chosen after the oracle has been fixed. One requirement shapes the definition. A communication protocol takes classical inputs, so the challenge must be handed over as a description rather than as a state. That makes the simulating player stronger rather than weaker, which is precisely why the reduction is sound. Unfortunately, the same requirement excludes quantum side information depending on X. That is why we treat the reference copies separately below, and why coherent access falls outside the scope of the theorem altogether, as Section 3 explains. The associated two-party problem. Theorem C placed two requirements on the construction, one quantum and one classical, and Vector-in-Subspace meets both of them (Proposition 3.3, Theorem 2.6). We use the classical bound through a small-advantage form, namely β(n, L) ≤ q
C (L + 1)/n1/3 , which we obtain by symmetrizing across and within the two promise cases and then amplifying (Lemma 2.7).
Reference copies. The generator is public, so a distinguisher can do more than hold its challenge: it can draw polynomially many fresh copies of both states besides. Those copies are quantum side information about H, and quantum side information is exactly what Theorem 3.2 does not cover. We therefore remove them, by handing the adversary something classical that is at least as useful in their place, namely the spans A ⊆ H and B ⊆ H ⊥ of the copies it would have drawn. Given a basis of A, the adversary can resample the copies for itself with the correct joint distribution, so it loses nothing by the exchange. Unlike the copies, the spans are classical, which is exactly what the reduction needs. Now condition on the spans. The challenge then splits into two branches. The first is supported on the subspace the adversary already knows, and there we concede the entire advantage; since that branch carries weight only 2q/n, conceding it is cheap. The second branch is a fresh Vector-in-Subspace instance, this time inside K = (A ⊕ B)⊥ , of dimension n − 2q, in which the residual subspace is once again Haar-random of half dimension (Lemma 5.1, Lemma 5.2). Reference copies cost us two things, then, and nothing more: an additive 2q/n, and a loss of dimension (Corollary 5.3). One step then remains, and it is routine. What we have bounded so far is an advantage averaged over the random subspaces, whereas an oracle separation needs a single sequence {Hλ } that defeats 10
every adversary at once. A discretization of the gate set, Markov’s inequality, and Borel–Cantelli together make that passage, and we isolate it as Lemma 5.4 because three later arguments need it. The one point to watch is that the maximization over advice strings has to sit inside the expectation; the reduction accommodates this without loss, since the holder of X can send the best advice (Section 5.2). The two rates. The bounds above say that the oracle leaks little. Two rates say how little, and we compute both directly rather than through the reduction. Consider first a distinguisher that measures its challenge with a fixed POVM {Ek } and is then told every outcome probability exactly. Its advantage is the likelihood-ratio quantity 1X Tr(Ek RH ) , n k and each term in that sum is governed by the law of ⟨v|PH |v⟩, which for a real half-dimensional √ subspace is Beta(n/4, n/4). The mean absolute deviation of that law gives the rate 2/ πn, and measuring in the computational basis attains it (Proposition 5.8).R For the one-way model of VSPn the picture is different. There the second-moment operator EH [( f dµH )2 ] is diagonalized exactly 1 by the spherical harmonics, with eigenvalue n−1 at degree two and rapid decay above it. A level-ℓ inequality then bounds what a single cell of the partition induced by Alice’s message can leak, and √ summing over cells gives O(L/ n) (Proposition 5.10). The one-query bound. The communication argument charges the adversary for the classical bits it exchanges with the oracle, and a superposition query is not a classical message, so that argument does not apply under coherent access. By Proposition 3.3 no communication bound can replace it, since the problem is easy for quantum communication. We turn to query complexity instead. Write the pre-query processing of a one-query adversary as an isometry with branches Ax , one branch for each label x the oracle can be asked about, and write its post-query measurement as an effect Π. The bias is then a quadratic form in the unknown truth table, ZH (f ) =
X
fx fy CH (x, y),
CH (x, y) = Tr(Πxy Ay ∆A†x ),
∆ = RnH ,
x,y
where RH = 2PH − I is the reflection in H. Three objects enter this form, each in a different way. The adversary contributes the fixed data (Ax , Πxy ). The randomness of H enters linearly, through ∆ alone. The truth table appears only through the rank-one sign pattern fx fy . What we have to bound is the maximum of |ZH (f )| over all 2M sign patterns, since f is an arbitrary function of H and we are given no control over it. The one general tool for bounding a quadratic form is the operator norm, and applying it directly costs a factor M that the completeness relation shows is spurious. Reweighting the labels by the 1/2 query mass τx = n1 Tr(A†x Ax ) removes it, because Dτ f is a unit vector for every sign pattern, so that the maximum over the 2M patterns collapses to a single operator norm ∥GH ∥op (Section 6.3 does this carefully). Neither the weighting nor the collapse is new: both are the query-label form of the argument of Lombardi, Ma, and Wright [LMW24], and Section 1.3 compares the two settings. What is left is to bound EH ∥GH ∥op , and here our setting differs from the earlier one. By the linearity in RH , each entry of GH is a linear statistic Tr(Bxy RH /n) of one Haar-conjugated reflection. The scalar case is easy, and it already shows the scale we are after: such a statistic is Lipschitz in the Haar unitary that p defines RH , hence subgaussian, so that a maximum over N suitably normalized statistics is O( log(2N )/n) (Lemma 6.1). An operator norm, however, is not 11
a maximum over finitely many scalars, and what we need is the matrix form of that statement. Had the entries been built from independent random signs, the classical matrix Khintchine inequality p would supply it, giving an operator norm of order σ log(2M ) for a variance parameter σ computed from the coefficient matrices. A single Haar reflection, though, offers no independence, so we take the matrix concentration from a curvature hypothesis instead and compute the variance proxy it asks for (Lemma 6.4), with the row and column normalizations playing the role of the variance parameter. The substitute for independence is curvature. Haar measure on SU(n) and SO(n) has Ricci curvature Ω(n), which is precisely why scalar Lipschitz functions on those groups concentrate at scale n−1/2 , and Huang and Tropp [HT21] show that the same hypothesis yields subgaussian concentration for matrix-valued functions as well. Their criterion asks for a bound on the sum of squared derivatives along an orthonormal frame, and here that computation is short: moving U in a direction K rotates RH by the commutator i[K, D], and ∥[K, D]∥2 ≤ 2 ∥D∥op ∥K∥2 . The p conclusion is that EH maxf |ZH (f )| ≤ C log(2M )/n (Theorem 6.6). This extends to parallel queries with no further argument (Corollary 6.8) and, applied through Rosenthal’s one-query state synthesis [Ros24], it also excludes quantum advice of polynomial size (Corollary 6.10). Combining classical and coherent queries. The two arguments above bound different resources by different methods, and Theorem 6.13 combines them into a single statement, covering polynomially many adaptive classical queries together with advice, followed by one coherent query. The combination preserves negligibility, though not the sharp constant of the pure one-query corner. We split the advantage into two parts: the part that an H-independent final query would produce, which the communication bound controls, and the increment that arises from making that query H-dependent, which the spectral bound controls. For the increment we would like to fix the classical transcript and then apply the one-query bound to whatever follows it. The problem is that the transcript is correlated with H, so conditioning on it changes the law of H, whereas the one-query bound is an average over that law. Two facts resolve it. The first makes the conditioning explicit: write the answers into a fixed operator Vπ , and leave the question of whether they are the true answers to an indicator χπ (H). The transcript’s HP dependence is then carried by a scalar, and the masses wπ = n1 Tr(Vπ† Vπ ) satisfy π χπ (H)wπ = 1 for every H (Lemma 6.14), so that what follows is a convex combination. The second fact is that the quantity being conditioned, namely the relaxed spectral norm of the previous paragraph, is a Lipschitz function of the Haar unitary defining RH , and so concentrates. Concentration is exactly what survives conditioning on a classical transcript, since such a transcript is a condition on that L+a+2 transcripts then costs only a same unitary. Removing the p conditioning over the at most 2 maximal-inequality term C (L + a)/n. Quantum advice is admitted on O(λ) qubits, by charging a net of advice states to the classical budget (Corollary 6.18). Beyond that size, however, the same argument marks the limit of what we can prove, since it requires a classical transcript between the state source and the coherent query. There are two ways to violate that requirement. A coherent query placed first can synthesize arbitrary quantum advice about H, by Corollary 6.10, and two coherent queries already contain advice together with a query. In the first case the adversary holds H-dependent quantum side information before any transcript exists, which the communication reduction cannot represent; in the second there is no transcript at all (Section 6.5, Section 8). Closing either case is the content of Conjecture 8.2.
12
Removing the state source. Section 4 through Section 6 work with the source R, which returns a fresh Haar sample on every call, because that is the form the concentration arguments require. The final oracle contains no such source. Instead we store samples inside a Boolean function, again through Rosenthal’s one-query synthesis: for each branch b and each index r we draw a vector ub,r from the appropriate sphere, and the oracle carries the Boolean function that synthesizes an approximation of the rounded state |ũb,r ⟩. The generator picks r with its own coins, runs the synthesis circuit with its one query addressed to that section, and then discards r. The construction works because r is discarded, and the order of the two steps in the proof is forced by that. Suppose we tried to apply the communication reduction to the stored experiment directly. The holder of the hidden object would receive the entire list from which the challenge was drawn, and the associated problem would collapse: Alice fingerprints her challenge vector in O(λ) bits, the other player finds the matching entry, and reads off its branch. So we must replace the stored samples by fresh ones before applying the reduction, which is what Lemma 7.3 does. Only then does the analysis of the earlier sections apply, and it applies with the enlarged hidden object in place of H (Lemma 7.4). Section 7 gives two further reasons why the replacement is a precondition rather than a convenience.
1.3
Comparison with Lombardi–Ma–Wright
The closest prior security proofs are those of Lombardi, Ma, and Wright [LMW24] and, concurrently with this manuscript, Huang [Hua25]. Since then, Dong, Lombardi, and Ma [DLM26] have proved explicit one-query lower bounds through oracle state search and Choi state games, together with a sharper separation between one-query synthesis and quantum programs. Their lower bounds concern one-query adversaries; moreover, some of their targets admit two-query constructions, and their quantum-program result concerns advice without queries. So our coherent-query bounds do not improve on any of these, and the two settings are better compared by scope than by strength. For unitary synthesis the classical half is the easy one, which is not what one might expect. Indeed, a classical algorithm making T queries reads only T bits of the oracle, so that once we fix its internal randomness the circuit can reach at most 2T states, no matter how adaptively it chose those queries. A counting argument then caps the fidelity it can achieve with a generic state at a constant (Proposition C.1). A single coherent query, by contrast, already suffices to synthesize an arbitrary state [Ros24], and Section 3 makes the comparison precise. We adopt the plan of their one-query proof rather than rediscover it. The deterministic querymass weighting that depends only on the isometry, which we call τ , is their weight vector |wtV ⟩ read on query labels instead of on workspace basis vectors [LMW24, §2.4.1]. Their DV,h is a different quantity, measuring the deviation of amplitudes from typical. The reduction of a maximum over truth tables to a single operator norm by means of that weighting is also due to them, and it works in both settings for the same reason, namely that a diagonal weighting commutes with the phase oracle. A concentration statement for the ensemble is likewise common to both proofs, in their case a Talagrand inequality on the Boolean cube, which is essential to their conclusion about pseudorandom states. What differs at this step is which concentration statement is available, and what has to be computed to use it. Their states are built from independent coordinates, so matrix concentration for independent sums applies to them directly. A single Haar-conjugated reflection provides no independence, so we take the matrix concentration from a curvature hypothesis instead — an inequality due to Huang and Tropp rather than to us (Proposition 6.2) — and what Lemma 6.4 supplies is the variance proxy that hypothesis asks for, for a matrix whose entries are linear statistics of one conjugation. 13
Work
Coherent
Classical
Ensemble / target
Result type
Prior work [LMW24]
one; poly parallel advice only
random oracle; single-copy PRS, commitments
one-query bound (not an EFI-versus-OWPuzz separation)
[Hua25]†
one, then one classical
random oracle; PRS
conditional bound (not a separation)
This work one; poly poly parallel; one adaptive (+ after the classical advice) phase; two at restricted width
single classical oracle; Haar half-subspace pair; classical-advice EFI vs. OWPuzz and QEFID
separation in the classical-query model, extended by one coherent query
Open
any
fully coherent access; Conjecture 8.2
poly adaptive
one (after)
Table 1: Positioning. All three share a single-coherent-query base, and none reaches polynomially many adaptive coherent queries, the row that fully coherent access to a classical oracle would need. Classical queries are the easy case (Proposition C.1), and the ensemble of [LMW24] is better suited to the complexity-independence conclusion. The third column is the resource their setting does not address and ours requires, since the counting oracle is queried classically. † Preprint; it gives an assumption-light route whose bound is not negligible at polynomial width, and a sharper route conditional on a block-orthogonality (sum-to-max) assumption that it states as such. The one structural difference lies in how the hidden object enters the bias. In [LMW24] the challenge state |ψRk ⟩ is itself random and oracle-dependent, so that the bias is a quadratic form in the same random vector, and decoupling is then required in order to separate its two occurrences. 1 In our setting the bias is ZH (f ) = n Tr Ef RH , which is linear in the hidden reflection, for every truth table f and every query count T . Consequently there is no decoupling step and no good p event on which to condition, although the width still enters through log(2M ). The one-query proof accordingly reduces to three steps: a weighted relaxation, a derivative computation, and an appeal to a matrix concentration inequality. This is the one respect in which our setting is simpler than theirs. Neither ensemble dominates the other, since the two are suited to different conclusions. The phase states of [LMW24] are efficiently preparable from a classical random oracle. A polynomialquery theorem in their setting would yield a classical oracle relative to which single-copy pseudorandomness survives while, as Lombardi, Ma, and Wright observe, quantum cryptography would not black-box imply any hard language, which is the question raised in [Kre+23]. Our states, by contrast, require Haar-random data, which Section 7 stores in a Boolean function rather than removes, so for that conclusion their ensemble is the better suited. A random oracle, on the other hand, does not eliminate one-way puzzles, whereas our counting oracle does, so for the purpose of proving a separation ours is the better suited. Table 1 sets out the comparison. Single-copy security in both conjectures. Conjecture 8.2 and the conjecture of [LMW24] are both single-copy statements, and there is a reason for that. Kretschmer [Kre21] breaks any multi-copy PRS with a single PP query, using O(λ) copies, and so no unitary-synthesis lower bound can proceed through multi-copy security. Single-copy security is therefore the only level at which the connection to synthesis remains available, and [LMW24] say so explicitly. Now, by [Cav+25a, Thm. 1.1], EFI pairs are equivalent to non-uniform single-copy pseudorandom states (1PRS) with 14
O(log λ) advice. An EFI pair therefore sits at exactly the level where that connection is available and where the counting attack does not apply. This is why the two conjectures take the same form: both are single-copy distinguishing questions against a secret-dependent classical oracle. The ensembles themselves, however, differ, and the relationship between the two conjectures is not a reduction. An equivalence between primitives does not transport an ensemble-level query lower bound from one to the other, and we know of no reduction between the two ensembles in either direction.
1.4
The question of fully coherent access
Access to O′ in Theorem 7.2 is classical, followed by one coherent query. Since O′ is itself a Boolean function, the natural strengthening is the standard relativized quantum model, in which the distinguisher queries O′ in superposition throughout. That is Conjecture 8.2, stated in Section 8. Both possible answers are informative. If Conjecture 8.2 holds at polynomial parameters, then the reductions of Section 7 carry Theorem 7.2 over to fully coherent access, so the separation holds in the standard quantum oracle model and admits quantum advice of any polynomial size (Proposition 8.7(A)). If instead it fails, then coherent access to a classical function of the secret, with polynomial classical advice, achieves a bias above the ceiling O(poly(λ) · n−1/6 ) that Klartag–Regev imposes on every classical transcript of polynomial length together with advice about the same secret (Proposition 8.7(B)). That would separate coherent access from classical transcripts for a concrete ensemble, though it would not resolve the Unitary Synthesis Problem of Aaronson and Kuperberg [AK07]; Section 8 gives the three reasons. At small width the question is already settled, by a union bound: enumerating truth tables and advice strings settles Conjecture 8.2 at every query count once M + a ≤ n2−ε for a fixed ε > 0, with polynomial classical advice and no reference copies (Proposition 8.4). Two further bounds reach past a single query, and both of them restrict a width rather than a query count. The first admits quantum advice of dimension n2−ε together with one coherent query of any width (Proposition 8.5); the second admits two adaptive coherent queries whose first has width n2−ε (Proposition 8.6). What remains open is therefore T ≥ 2 at widths n2−o(1) and above. Security against every QPT adversary has to cover that regime, since such an adversary may ask about samplers of description length λk for any k.
1.5
Related work
Minimal primitives. EFI pairs are due to [BCQ23] and OWPuzzs to [KT24], while pure-output and inefficiently verifiable one-way state generators (OWSGs) sit above OWPuzzs and above EFI pairs respectively [BJ24]. These primitives are organized in [Gol+24] into three classes. QuantuMania consists of those building EV-OWPuzzs, CountCrypt of those building OWPuzzs but not EV-OWPuzzs, and NanoCrypt of those building EFI pairs but not OWPuzzs. In that language, ours is a separation of NanoCrypt from CountCrypt in the model of Model 1.1, that is, against adversaries whose queries to Count are classical but for one at the end. Meta-complexity. OWPuzzs are characterized by the average-case hardness of probability estimation [Cav+25c; HM25]. That is precisely the hardness our counting oracle removes, and our attack follows the conditional-sampling idea behind the forward direction of the characterization. There is a second characterization, by hardness of proper quantum distribution learning [HHM25], and since our oracle makes probability estimation easy it would make that task easy relative to O as 15
well, provided the characterization relativizes. The bare nonexistence of OWPuzzs under counting power is, we stress, not new: they cannot exist if BQP = PP [Gol+24], and an explicit PP-oracle attack is known [Cav+25b]. What is different here is that a bare PP oracle is a fixed language independent of H, whereas once a state source produces H-dependent states, a sampler may call it. Our route to eliminating OWPuzzs, through probability estimation, therefore forces an H-dependent counting oracle, and such an oracle can in principle leak H and break the very pair the construction has to hide. In the converse direction, OWPuzzs can be built from #P-hardness together with quantum advantage [KT25], and our oracle removes exactly the hardness those constructions rely on. EFI, single-copy pseudorandomness, and P versus PSPACE. There is a classical oracle relative to which P = NP and single-copy pseudorandom states exist, together with the explicit question of whether single-copy PRS existence implies P ̸= PSPACE [Kre+23]. Together with [Cav+25a] that is, up to O(log λ) advice, the EFI-versus-P = PSPACE frontier. The known PP-oracle attack [Kre21, Thm. 27] uses poly(λ) copies, in fact O(λ) in its proof, so it does not apply to single-copy security, and copy amplification [BZ26] does not close the gap. No implication from EFI to P ̸= PSPACE is currently known, and our result does not give one; Section 4.2 returns to this point. Oracle separations and their lifting. Pseudorandom states are separated from one-way functions in [Kre21; Kre+23]. The CHRS model was introduced in [CCS25], together with a separation of single-copy from multi-copy pseudorandomness. Both CHRS and a Haar random swap model are used in [BCN25]; we rely only on the CHRS results there, since the swap-model section carries an author’s note retracting its EFI-versus-OWSG separation after a bug was found. A unitary oracle with EFI and QEFID pairs but no OWSGs is given in [Beh+25], which is the opposite orientation to ours, since it retains OWPuzzs. OWPuzzs are separated from their efficiently verifiable variant in [CGG24]. Finally, the current framework for lifting CHRS separations to unitary ones is [GZ25]; our separation does not need it, since Theorem 7.2 already gives a single classical oracle. Communication complexity. Our security reduction is, to our knowledge, the first to route the security of a quantum-state pair relative to a classical-query oracle through a communication lower bound. The hard problem is VSP [KR11], and Kerenidis et al. [Ker+12] give a prior-free information-complexity bound for a discretized robust variant. On the upper-bound side, the √ O( n) one-way protocol is stated by Raz [Raz99], first published in [Mon19, App. A], and given a computationally efficient form in [GS19]. That last paper belongs to a line of work on compressed classical descriptions of quantum states, beginning with [Aar04], in which the description size is √ governed by the same one-way communication bounds. A matching Ω( n) lower bound for one-way protocols on gapped instances follows from the one-way complexity of Partial Matching [Gav+07], by a reduction recorded in [GS19]; Section 5.4 compares it with Proposition 5.10.
1.6
Organization
Section 1.2 describes the whole argument informally. Section 2 then fixes notation and collects the background we use, including the query model, the conventions of communication complexity, and the classical lower bound for VSP; the matrix concentration inequality is stated separately in Section 6.1, where it is first used. Section 3 proves the reduction to communication complexity, together with the quantum protocol that bounds its reach. Section 4 defines the oracle and proves that classical-output hardness, of the search, decision, and interactive kinds, does not survive it. Section 5 applies the reduction to our pair, proves EFI security, and states the two rates of 16
Section 3 Security from a bounded classical transcript (Theorem 3.2)
Section 4.2–4.3, Appendix A The ranked counting oracle; no oneway puzzles (Theorem 4.9)
Section 4.4–4.5: QEFID pairs and the interactive collapse (Theorem 4.14)
Section 5.1–5.2 Reference copies, then EFI security under classical access (Theorem 5.5)
Section 5.3–5.4, Appendix B: the two exact rates (Theorem E)
Section 6.2–6.3 The variance bound (Lemma 6.4); one coherent query (Theorem 6.6)
Section 6.4, Appendix C: what quantum advice and what reference copies are worth
Section 6.5 Classical transcript, then one coherent query (Theorem 6.13) Section 7 One deterministic classical oracle (Theorem 7.2); the black-box barrier (Corollary 7.6)
Section 8: what fully coherent access would need (Conjecture 8.2)
Figure 1: Dependency structure. Solid boxes are used in the proof of Theorem 7.2; dashed boxes are not. Theorem E, whose proofs are deferred. Section 6 proves the coherent-query, quantum-advice, and hybrid bounds. Section 7 replaces the state source by a Boolean function and gives the single deterministic classical oracle of Theorem A. Section 8 states the conjecture that would place the separation in the standard quantum oracle model, and Section 9 collects the open problems. Three appendices follow: Appendix A contains the conditional-sampling attack, Appendix B the proofs of the two rates, and Appendix C two results used only locally. Figure 1 shows which parts of the paper the proof of Theorem 7.2 uses.
2
Preliminaries
This section fixes notation and collects the background the paper uses. Three of its subsections gather material from the areas the proof draws on. Section 2.4 fixes the form in which we write a query algorithm, Section 2.6 recalls the conventions of classical communication complexity, and Section 2.7 states the communication lower bound we import. There is a fourth such import, the matrix concentration inequality, but we defer it to Section 6.1, the first subsection of Section 6, where it is first used. For EFI pairs we follow [BCQ23], and for one-way puzzles [KT24; CGG24; 17
Gol+24].
2.1
Notation
We write QPT for quantum polynomial time. A function is negligible, written negl(λ), if it decays faster than every inverse polynomial. The security parameter is λ, and the ambient dimension is n = n(λ) = 2λ , a computable power of two, so that Cn is exactly λ qubits. In fact the arguments use only that n is even and 2Θ(λ) , and they use the two halves of that bound for different purposes. Every security estimate uses the lower bound n ≥ 2Ω(λ) . The upper bound n ≤ 2O(λ) , on the other hand, makes the dimension addressable: a QPT algorithm has to write indices into [n], and so needs log2 n = poly(λ). It also lets us report a bound of the form n−Ω(1) as 2−Ω(λ) . Following [BCQ23] we reserve n for the dimension and use λ for the security parameter. Part of the OWPuzz literature writes n for the security parameter instead, which would collide with our usage. We write ln for the natural logarithm and log2 for the base-two logarithm. Inside a concentration bound the base of a logarithm affects only the universal constant in front, and there we write log. Finally, 1[·] denotes the indicator of an event, and TV denotes total variation distance between distributions over a discrete set.
2.2
Operators and effects
For an operator Y on a finite-dimensional Hilbert space we write ∥Y ∥1 , ∥Y ∥op and ∥Y ∥2 = q
Tr(Y † Y ) for the trace, operator and Hilbert–Schmidt norms. We use ∥Y ∥op ≤ ∥Y ∥2 ≤ ∥Y ∥1 q √ throughout, and for a positive semidefinite Y on Cd we also use ∥Y ∥2 ≤ ∥Y ∥op Tr Y ≤ Tr Y when ∥Y ∥op ≤ 1. We write A ⪯ B when B − A is positive semidefinite, Hermd for the d × d Hermitian matrices, and I for the identity. The trace distance is TD(ρ, σ) = 21 ∥ρ − σ∥1 . An effect is an operator E with 0 ⪯ E ⪯ I, equivalently a single element of a two-outcome POVM {E, I − E}. The acceptance probability of a two-outcome measurement on a state ρ is then Tr(Eρ), for the effect E associated with the accepting outcome. Effects are how a computationally unbounded distinguisher enters the analysis, and they capture it completely: any such distinguisher is a channel followed by a two-outcome measurement, and that composition is again a two-outcome measurement. When an operator Π acts on a tensor product CX ⊗ K, for a finite index set X and a finite-dimensional Hilbert space K, we write Πxy := (⟨x| ⊗ I) Π (|y⟩ ⊗ I) for its blocks, which are operators on K. If Π is Hermitian then Π†xy = Πyx . Three devices recur in Section 6, and we fix them here. The first is the Hermitian dilation of a rectangular or non-Hermitian matrix Y , Y :=
0 Y Y† 0
!
,
which is Hermitian and satisfies ∥Y∥op = ∥Y ∥op . It converts a statement about Hermitian matrices into one about arbitrary matrices, at the cost of doubling the dimension. The second device is purification. For a state ρ on Cd , a purification is a pure state on a space of dimension at most d2 whose reduced state is ρ, and handing a purification to a receiver in place of ρ only increases what that receiver can do. The third is a net, which we record as a lemma because three separate arguments below reduce an operator norm to a finite maximum in exactly this way.
18
Lemma 2.1 (A net captures the norm of a Hermitian operator). Let V be a complex Hilbert space of dimension K. Its unit sphere carries a 14 -net N with |N | ≤ 92K , and for every such net and every Hermitian Y on V, ∥Y ∥op ≤ 2 max ⟨γ|Y |γ⟩ . γ∈N
Proof. The unit sphere of V is the unit sphere of a real space of dimension 2K, which carries a δ-net of size at most (1 + 2/δ)2K by the standard volume comparison; at δ = 41 that is 92K . For the inequality, recall that ∥Y ∥op = sup∥x∥=1 |⟨x|Y |x⟩| when Y is Hermitian. Take x attaining that supremum and γ ∈ N with ∥x − γ∥ ≤ 14 . Writing the difference as ⟨x − γ|Y |x⟩ + ⟨γ|Y |x − γ⟩ gives ⟨x|Y |x⟩ − ⟨γ|Y |γ⟩ ≤ 2 ∥x − γ∥ ∥Y ∥op ≤ 21 ∥Y ∥op , so that ∥Y ∥op ≤ maxγ∈N |⟨γ|Y |γ⟩| + 12 ∥Y ∥op , which rearranges to the claim.
2.3
Haar-random subspaces and the half-subspace pair
We write U(n) and O(n) for the unitary and real orthogonal groups, and SU(n) and SO(n) for their subgroups of determinant one. Each of these carries a unique translation-invariant probability measure, its Haar measure. On the sphere S n−1 we write σ for the uniform probability measure, and νH for the uniform probability measure on the unit sphere of a subspace H. By a Haar-random subspace of dimension n/2 in Rn , or in Cn , we mean one drawn from the rotation-invariant probability measure on the Grassmannian of n/2-dimensional subspaces. Concretely, H = Q · span(e1 , . . . , en/2 ) for Q Haar on O(n), or on U(n) in the complex case. Rotation invariance means that gH has the same law as H for every fixed g ∈ O(n), and this is the only property of the measure that we use anywhere. For such an H we write PH for the orthogonal projector onto it, and RH := 2PH − I (1) 2 = I and Tr R = 0. Write for the associated reflection, which is a Hermitian involution with RH H D for the diagonal matrix with n/2 entries +1 followed by n/2 entries −1. Then RH = QDQ⊤ in the real case, and RH = U DU † with U Haar on U(n) in the complex one, so that the reflection is a Haar conjugate of one fixed traceless involution. This is the form in which every estimate in Section 6 uses it. The two half-subspace states are
ρ0,H =
2PH I + RH = , n n
ρ1,H =
2PH ⊥ I − RH = , n n
ρ0,H − ρ1,H =
2RH . n
(2)
They have orthogonal supports, so that TD(ρ0,H , ρ1,H ) = 1 and the measurement {PH , PH ⊥ } distinguishes them with certainty. The third identity in (2) is the reason the analysis stays linear in the hidden object. Indeed, for any effect E acting on a single copy, the difference of the acceptance probabilities on ρ0,H and ρ1,H is Tr E(ρ0,H − ρ1,H )
=
2 Tr(E RH ), n
(3)
and since Tr RH = 0 only the traceless part of E contributes. We call a quantity of the form Tr(ARH ), with A fixed, a linear statistic of the reflection. Our construction uses the real ensemble, since that is the setting of the communication lower bound in Section 2.7. The arguments of Section 6, on the other hand, are stated for the complex ensemble. They transfer to the real one with a change of universal constant, and Lemma 6.3 makes that precise. 19
2.4
The query model
Let X be a finite set of query labels, write M = |X | for the width, and let f : X → {±1} be a truth table, whose values we also write fx = f (x). The phase oracle for f is the unitary Df ⊗ I on P CX ⊗ K with Df = x fx |x⟩⟨x|, where K carries the rest of the algorithm’s workspace. A Boolean function g : X → {0, 1} is accessed instead in the bit-flip form |x⟩|c⟩ 7→ |x⟩|c ⊕ g(x)⟩. The two forms are interchangeable: preparing the answer qubit in |−⟩ turns a bit-flip query into a phase query, and conversely a phase query on the domain X × {0, 1} with truth table (−1)c g(x) implements a bit-flip query. The two models are equivalent up to a factor 2 in the width, and we work with phase oracles throughout. That conversion costs us nothing, since our bounds hold for every truth table f and depend on the width only through log(2M ). Every algorithm below holds one copy of the challenge state, which is either ρ0,H or ρ1,H , and queries an oracle whose truth table is an arbitrary function of the hidden subspace. We describe such an algorithm in two ways, one general and one specific to a single query. The general description comes first. An algorithm making any number of queries, of arbitrary computational power, is a channel followed by a two-outcome measurement. Its acceptance probability on a challenge ρ is Tr(Ef ρ) for an effect Ef on Cn that depends on the truth table f but not on the challenge, and we measure its success by the bias ZH (f ) :=
1 2 Tr
Ef (ρ0,H − ρ1,H )
=
1 Tr Ef RH , n
(4)
which by (3) is half the distinguishing advantage. Note that the dependence on the number of queries is hidden inside Ef , and that for each fixed f the bias is a linear statistic of RH . The second description is specific to one query, and it is the form that the proof of Theorem 6.6 needs. A one-query algorithm applies a unitary to the challenge together with fresh ancillas, queries the phase oracle once, applies a second unitary, and measures. Absorbing the final unitary into the measurement, the pre-query processing is an isometry W : Cn → CX ⊗ K,
W |ψ⟩ =
X
X
|x⟩ Ax |ψ⟩,
A†x Ax = I,
(5)
x
x∈X
where Ax is the branch on which the algorithm queries the label x. The completeness relation on the right is exactly the statement that W preserves norms. The post-query measurement is then an effect 0 ⪯ Π ⪯ I on CX ⊗ K with blocks Πxy , and in this notation the effect of (4) is Ef = W † (Df ⊗ I)Π(Df ⊗ I)W . Finally, we attach to the isometry the query mass τx :=
† 1 n Tr(Ax Ax )
= Tr A†x Ax · nI ,
(6)
which is the probability that the query lands on the label x when the challenge is maximally mixed. By the completeness relation τ is a probability vector on X , and it depends on the algorithm alone, not on H.
2.5
EFI pairs and one-way puzzles
Definition 2.2 (EFI pair, [BCQ23]). A family {(ρ0,λ , ρ1,λ )}λ of pairs of mixed states is an EFI pair if: (i) Efficient generation: a QPT algorithm G satisfies G(1λ , b) = ρb,λ for both b ∈ {0, 1}; (ii) Statistical farness: TD(ρ0,λ , ρ1,λ ) ≥ δ(λ) for some inverse polynomial δ; 20
(iii) Computational indistinguishability: every non-uniform QPT distinguisher D has advantage negl(λ) in distinguishing ρ0,λ from ρ1,λ . Here non-uniform is as in [BCQ23]: D receives an advice state of polynomial size, which may be quantum. Definition 2.3 (Classical-advice EFI pair). A classical-advice EFI pair satisfies (i) and (ii) of Definition 2.2 and, in place of (iii), computational indistinguishability against every QPT distinguisher receiving a classical advice string of polynomial length. What we construct is a classical-advice EFI pair, and in fact it is secure against rather more than that definition asks. It is secure against quantum advice of O(λ) qubits together with everything else the model grants (Corollary 6.18), and against quantum advice of any polynomial size on its own (Corollary 6.10). Only one combination lies beyond these, namely polynomial-size quantum advice together with classical queries, and that combination is what separates Definition 2.3 from Definition 2.2 here (Section 5.2). Note that the convention is local to EFI distinguishers. Definition 2.4 below keeps the standard notion, under which the attacker to be ruled out may carry quantum advice, and since our attacker is classical, nothing is lost there. Some later works, for instance [Cav+25a], require farness 1 − negl(λ) instead. The two requirements are equivalent up to standard polarization, and in any case our constructions achieve TD = 1 in the source model and 1 − 2−Ω(λ) relative to the single classical oracle of Section 7, so the distinction is immaterial here. One feature of the oracle setting needs care. There both G and D have oracle access, and the third condition becomes meaningful only once we fix the access granted to D: restricting D to classical queries and forbidding it queries altogether are different security notions. We therefore always name the class, and ours is Model 1.1. Moreover, since G is public, a security proof must in addition let D obtain polynomially many copies of both states, which we call reference copies. Beyond this we use an EFI pair only as a pair of states that is hard to distinguish. Definition 2.4 (One-way puzzle, [KT24; Cav+25c]). A one-way puzzle is a pair (Samp, Ver) where Samp is a uniform QPT algorithm outputting a classical key–puzzle pair (k, s), and Ver(k, s) ∈ {0, 1} may be computationally unbounded, such that: (i) Correctness: Pr(k,s)←Samp(1λ ) [Ver(k, s) = 1] ≥ 1 − negl(λ); (ii) Security: every non-uniform QPT adversary A satisfies Pr(k,s)←Samp(1λ ) [Ver(A(1λ , s), s) = 1] ≤ negl(λ). If Ver is efficient the primitive is an efficiently verifiable one-way puzzle (EV-OWPuzz). Inefficient verification is the default in [KT24], because an efficient verifier would be broken by a QCMA oracle. Our target throughout is accordingly the unrestricted, inefficiently verifiable notion. A QEFID pair, introduced in [CGG24, Def. 5] and stated in [Beh+25, Def. 2.1], is the classicaloutput analogue of an EFI pair: a pair of distributions over classical strings, samplable by a QPT algorithm, statistically far, and computationally indistinguishable. The two classical-output primitives express hardness of different kinds. A one-way puzzle expresses classical-output hardness of search, whereas a QEFID pair expresses classical-output hardness of decision. They are nevertheless equivalent up to non-uniformity, by [CGG24, Lem. 8, Lem. 9, Cor. 14].
21
2.6
Classical communication complexity
We recall the model in the form used in Section 3, since it is not the form most familiar to a reader coming from quantum cryptography. In a two-party problem, Alice holds an input u and Bob holds an input H, and the two exchange classical messages according to functions fixed in advance of the input, each message depending on the sender’s own input and on the messages so far. At the end one of them announces an output. The cost of the protocol is the maximum total length of the messages exchanged, and this is the only resource charged: local computation is unbounded on both sides, and neither party is required to be efficient, or even computable. That last point is what makes the model useful to us, since the party who will hold our hidden subspace has to be able to answer arbitrary queries about it. A protocol has shared randomness if both parties see a common random string, drawn independently of the inputs, before the protocol begins. Equivalently, such a protocol is a distribution over deterministic ones. A one-way protocol consists of a single message from Alice to Bob, after which Bob announces the output; here we follow the definition of [KNR99]. Finally, on a distribution over inputs together with a bit b to be decided, the advantage of a protocol is | Pr[correct] − 12 |, the average being taken over the inputs, the bit, and the randomness. One structural fact is used twice below. Fix a deterministic protocol and fix a full transcript π. Then the set of input pairs producing π is a rectangle, that is, a set of the form A × B with A a set of Alice’s inputs and B a set of Bob’s. The reason is that at each round the sender’s message depends only on its own input and on the transcript so far, so membership in the set of inputs consistent with π is decided separately on the two sides. A protocol of cost L thus partitions the input space into at most 2L+1 rectangles. For a one-way protocol the partition is finer on Alice’s side only: her message realizes a partition of her input space into at most 2L+1 cells, and Bob then answers optimally given the cell and his own input. We record last the convention relating the two notions of advantage that appear in the paper. The distinguishing advantage of an algorithm D between two states is Adv(D) := | Pr[D(ρ0 ) = 1] − Pr[D(ρ1 ) = 1]|, written Adv(D; X) when the states depend on a hidden object X. With a uniform challenge bit, a distinguisher of advantage ε gives a protocol of advantage exactly ε/2, and we carry that factor 2 explicitly rather than absorbing it.
2.7
The Vector-in-Subspace problem
Definition 2.5 (Vector in Subspace, [KR11]). In VSPn , Bob receives a subspace H ⊆ Rn of dimension n/2 and Alice a unit vector u ∈ S n−1 promised to lie in H or in H ⊥ . The associated distribution draws H from the rotation-invariant measure on the Grassmannian of n/2-dimensional subspaces of Rn , a uniform bit b, and u uniformly from the unit sphere of H (if b = 0) or of H ⊥ (if b = 1). The goal is to decide b by classical randomized communication. The quantum upper bound is immediate. Alice encodes u in the amplitudes of ⌈log2 n⌉ qubits and sends them, and Bob applies {PH , PH ⊥ } and decides with certainty [KR11]. It is the classical lower bound that we use. Theorem 2.6 (Klartag–Regev [KR11, Thm. 4.2]). There is a universal c > 0 such that every classical randomized, two-way, shared-randomness protocol whose messages are Borel functions of the inputs, and which decides VSPn with error at most 31 on every instance of the promise of Definition 2.5, communicates at least c n1/3 bits. Three features of [KR11] matter for the way we use it. First, the bound is for two-way interactive protocols with shared randomness, and not only for one-way ones. 22
Second, the exact promise, that u ∈ H or u ∈ H ⊥ , is the case that Klartag and Regev call VSP0 , and it is exactly the case we need. The Borel hypothesis in Theorem 2.6 is due to Klartag and Regev, and it is needed only because the exact promise is supported on a measure-zero subset of S n−1 × Gr, where Gr is the Grassmannian of n/2-dimensional subspaces, so that a protocol has to realize a measurable rectangle partition. Our reduction satisfies that hypothesis: for each fixing of the public randomness the protocol is a fixed algorithm acting on the classical descriptions of√u and H, and so its message functions are Borel. For the robust promise VSPθ with 0 < θ < 1/ 2 they remove the hypothesis entirely. Third, their argument is a corruption bound, and the only use it makes of correctness is that the errors under the two promise cases sum to at most 23 . What they prove is in fact the distributional statement over the balanced distribution of Definition 2.5, which is the form we use. This lower bound does not rest on a single method. The prior-free information complexity of the discretized robust problem is also Ω(n1/3 ), by combining the main theorem of [Ker+12] with the same rectangle estimate of [KR11]. That bound is prior-free, that is, a maximum over input distributions rather than a statement about the distribution of Definition 2.5, so we cite it as corroboration rather than as a component of the proof. We use Theorem 2.6 only through the following small-advantage form. Write β(n, L) for the supremum, over classical randomized two-way protocols of cost L with shared randomness and Borel message functions, of the advantage on the VSPn distribution of Definition 2.5. The complement, symmetrization and majority-vote constructions in the proof below all preserve Borel measurability. Lemma 2.7 (Small-advantage bound). There is a universal C > 0 such that β(n, L) ≤ q C (L + 1)/n1/3 for every even n and every L ≥ 0. Moreover β(n, 0) = 0.
Proof. We amplify a protocol of small advantage into one of error 13 and apply Theorem 2.6. Let P be an L-bit protocol of advantage ε; replacing P by its complement, we may assume Pr[correct] = 1 2 + ε. We will show that P can be replaced, at the same cost, by a protocol whose success probability is 12 +ε on every instance of the promise. Majority voting needs exactly that uniformity over inputs, and P guarantees only an average over the distribution. The obvious device, rotating an instance, equalizes success within each promise case but not across the two, so we symmetrize the two cases against each other first. If (u, H, b) ∼ VSPn then so is (u, H ⊥ , 1 ⊕ b). Let P ′ publicly flip a fair coin: on heads run P (u, H); on tails Bob substitutes H ⊥ and they output the complement of P (u, H ⊥ ). Then for each fixed b, Pr[P ′ correct | b] = 21 Pr[P correct | b] + 12 Pr[P correct | 1 ⊕ b] = 12 + ε, so the two conditional success probabilities are now equal. Now we equalize within each case. The VSP distribution is invariant under a common rotation, and O(n) acts transitively on pairs (u, H) with u ∈ H, and on those with u ∈ H ⊥ . Sampling a Haar Q from public randomness and running P ′ on (Qu, QH) gives a protocol P ′′ of the same cost whose success probability is 12 + ε on every instance in the promise, which is the uniformity we wanted. Majority voting now applies. Running P ′′ independently t = Θ(1/ε2 ) times and taking the majority gives worst-case error at most 31 , at cost tL. Theorem 2.6 forces that cost to be large, and the bound on ε follows: s
tL ≥ c n1/3 ,
so
ε ≤ C 23
L n1/3
(L ≥ 1).
That leaves L = 0. With no communication the output is a function of the announcing party’s own input and the public randomness. Bob’s input H is independent of b, and since H is uniform, Alice’s marginal vector u is sphere-uniform regardless of b; in either case the output is independent of b, so β(n, 0) = 0. Writing L + 1 in place of L absorbs this case at the cost of a constant, and that is the stated bound.
3
Security from communication complexity
Everything the oracle of Section 4 will tell an adversary is a string of classical bits. In this section we show that when that is so, security reduces to a communication lower bound, however powerful the oracle may be. We state the reduction for an arbitrary hidden object and an arbitrary oracle, since the proof uses nothing about either beyond the fact that the answers are classical. Suppose, then, that the security of a primitive amounts to the claim that two states ρ0 (X), ρ1 (X) built from a hidden object X are hard to distinguish, and suppose that every route by which X influences the adversary carries classical data. We may then place the adversary in a two-party game, with Alice running it and holding the challenge while Bob holds X and is computationally unbounded. Each query becomes a message to Bob and each answer a message in return, so the adversary’s power is bounded by the length of that conversation and by nothing else, and in particular not by any property of the oracle it queries. One requirement shapes the definition that follows. A communication protocol gives Alice a classical input, so the problem we associate to the pair has to hand her a classical description of the challenge, from which she prepares the state herself. Granting her that description increases her power rather than restricting it, which is what makes the reduction legitimate. The same requirement, however, forces care over quantum side information depending on X. The theorem below does not cover such information, and where it arises, namely for the reference copies of Section 5.1, we reduce it to classical data first. Definition 3.1 (The associated two-party problem). Let X be a random hidden object taking values in a standard Borel space, and let (ρ0 (X), ρ1 (X)) be a pair of states. The associated twoparty problem ΠX is the following. Bob receives X. Alice receives, for a uniform bit b, a classical description y drawn from a preparation kernel κb (X); here κb is a Borel map from X to distributions on a standard Borel space of descriptions, each description y determines a pure state |ψy ⟩⟨ψy | through a Borel map, and the mixture of those states under κb (X) is ρb (X). The kernels are part of the data of ΠX , and for the half-subspace pair they are the uniform distributions on the unit vectors of H and of H ⊥ . Alice also receives classical side information ω(X), a Borel function of X. The two then communicate classically, and Alice outputs a guess for b. Write βΠ (L) for the supremum of the advantage over L-bit classical randomized protocols for ΠX on this distribution, with Borel message functions. Theorem 3.2 (Security from a bounded classical transcript). Let AX : {0, 1}∗ → {0, 1} be any deterministic Boolean truth table whose bits are measurable functions of X, not assumed efficiently computable, or computable at all. Let D be a quantum algorithm of arbitrary computational power whose dependence on X enters only through: (i) one challenge drawn from ρ0 (X) or ρ1 (X) with a uniform bit b, and classical side information ω(X), both as in Definition 3.1; (ii) classical query strings to AX , in a self-delimiting encoding, with total query-plus-answer length at most L; 24
(iii) classical advice α of length at most a, which may depend on X through any Borel map; and whose instruments and message functions are Borel in the classical data it holds, and which may otherwise use arbitrary computation and arbitrary resources independent of X. Then EX Adv(D; X)
≤ 2 βΠ (L + a + 1).
Proof. We build a protocol for ΠX in which Alice plays D and Bob holds X. The advice is not a query, so it must be paid for separately, and Bob supplies it before the simulation begins. Bob holds X and is unbounded, so he can compute an advice string α∗ (X) that maximizes D’s advantage. We take the lexicographically first among the finitely many maximizers, which makes X 7→ α∗ (X) Borel. He also computes a sign bit σ(X) := 1 Pr[Dα∗ (ρ0 ) = 1] > Pr[Dα∗ (ρ1 ) = 1] ,
and sends the pair (α∗ , σ), at a cost of at most a + 1 bits. Alice now receives the classical description of the challenge and of ω(X), prepares the corresponding states, and runs Dα∗ . All of her quantum computation is local: unitaries, weak measurements, and coherent reuse of a post-measurement state are all operations on her own registers. The queries are the only traffic. Whenever D issues a classical query z to AX , Alice sends z to Bob; Bob evaluates the deterministic bit AX (z) and returns it. This exchange is the only place where we use the hypothesis that the answers are classical bits. Alice then resumes D, takes its output as her guess for b, and flips that guess if σ = 1. Finally, a quantum Alice exchanging classical messages is simulated by a classical one. From the classical description of her state and the history so far, an unbounded classical Alice computes the exact conditional distribution of D’s next query and samples from it. So the result is a classical randomized protocol, and we have only given Alice more power than she would otherwise have. It remains to check that the simulation is faithful, and to count the bits. Alice’s simulated view is identical in distribution to D’s real view, since the challenge is a genuine sample and every oracle answer matches the true truth table. Hence for every fixed X the protocol is correct with probability at least 12 + 12 Adv(D; X), the sign bit having converted the absolute value in Adv(D; X) into a one-sided quantity. The communication is the charged transcript plus the advice, at most L + a + 1 bits. Averaging over X and comparing with βΠ gives 1 EX [Adv(D; X)] ≤ βΠ (L + a + 1), 2 as claimed. The hypotheses of Theorem 3.2 deserve two comments, one on what they permit and one on what they exclude. Assumptions on the oracle. Theorem 3.2 makes no assumption on AX beyond its being a deterministic function of classical strings. It may be uncomputable, and it may encode X in full. What the theorem bounds is not the oracle but how much of it reaches the adversary, and it is for this reason that the counting oracle of Section 4 may be computationally very powerful without weakening security, as Section 4.2 discusses. The requirement is tight, in the sense that classical output alone would not suffice. To see this, consider an oracle that takes the unknown challenge as quantum input, measures {PH , PH ⊥ }, and returns one classical bit. Its output would be classical, and yet it would distinguish the pair with certainty. Coherent access, quantum advice depending on the oracle, and an oracle sharing entanglement with the adversary are likewise not classical transcripts; nor, without further work, are quantum reference copies that depend on X. 25
Adaptivity and the number of queries. Our bound depends only on the total transcript length. In a two-way protocol adaptivity is free, and q queries of ℓ bits amount to q(ℓ + 1) bits once the answers are counted. Handling polynomially many fully adaptive queries costs us no additional work: it follows from the form of the reduction alone. Set this beside a one-coherent-query bound such as [LMW24]. The comparison is not a question of one result being stronger than the other. The two resources are formally incomparable. A coherent query is depth one at unbounded width, whereas polynomially many adaptive classical queries are depth polynomial at width one, and each is stronger than the other on some task [AA15; Chu+21]. For the purposes of synthesis, classical queries are the easy case (Proposition C.1).
The quantum upper bound Theorem 3.2 converts a communication lower bound into security, and its bound 2βΠ certifies nothing once ΠX has a cheap classical protocol, so the method applies only to pairs whose associated problem is classically hard. The complementary requirement, that the holder of the hidden object be able to use the pair, is automatic. Proposition 3.3 (Quantum communication always suffices). Let X be a hidden random object, let (ρ0 (X), ρ1 (X)) be states on Cd , and let ΠX be the associated problem of Definition 3.1 with no side information. If EX TD(ρ0 (X), ρ1 (X)) ≥ δ, then ΠX has a protocol of advantage at least δ/2 in which Alice sends ⌈log2 d⌉ qubits and Bob returns one classical bit. Proof. Alice prepares from her classical description one sample of ρb (X) on ⌈log2 d⌉ qubits and sends it. Bob, who holds X and is unbounded, applies the Helstrom measurement for the pair (ρ0 (X), ρ1 (X)) and returns its outcome. Since the success probability is affine in the state received, the average over Alice’s sampling randomness is the success probability on ρb (X), namely 12 + 1 2 TD(ρ0 (X), ρ1 (X)); averaging over X gives advantage at least δ/2, as required. Together the two statements give a general criterion, which we state on its own since hiding a subspace is only one way to apply it. It mentions neither subspaces, nor the counting oracle, nor Vector-in-Subspace. Corollary 3.4 (A communication gap yields a pair secure against classical transcripts). Let X be a hidden random object and (ρ0 (X), ρ1 (X)) a pair of states on Cd with EX TD(ρ0 (X), ρ1 (X)) ≥ δ, and let ΠX be the associated problem of Definition 3.1. Suppose that βΠ (ℓ) ≤ γ(ℓ) for a function γ. Then for every deterministic oracle AX , however powerful, every distinguisher whose dependence on X runs through at most L bits of classical query traffic with AX and a bits of classical advice has average advantage at most 2γ(L + a + 1); while the pair itself is usable, in the sense that ΠX has a ⌈log2 d⌉-qubit quantum protocol of advantage δ/2. Proof. The first assertion is Theorem 3.2 with βΠ replaced by its upper bound γ; the second is Proposition 3.3. So any two-party problem that is expensive for classical communication at small advantage, and whose two cases are statistically far, gives a pair hidden from every classical-transcript adversary. The work in applying it is finding an X for which the classical bound is both strong and provable at small advantage, and Section 2.7 explains why VSP is the example we know.
26
Limitations of the reduction. Proposition 3.3 is the reason no communication argument can ever reach coherent queries, and it says more than the familiar observation that quantum communication is sometimes cheaper. For every statistically far pair, the associated problem is easy for quantum communication at logarithmic cost, with the holder of the hidden object performing the measurement. The gap we require is not, then, a fortunate accident of VSP. Rather, the classical side has to be hard while the quantum side, which is always easy, remains inaccessible. Section 8 explains why the easy quantum protocol is nevertheless not an attack, and Section 6 supplies the query-complexity bounds that replace the unavailable communication argument. The reduction is also one-directional. It hands Alice a classical description of her challenge, which the distinguisher it simulates does not have, and a classical protocol may exploit that description in ways no holder of a single copy can reproduce. Indeed, if the descriptions of the two branches differ, a zero-communication protocol reads b straight off its input, whereas a one-copy distinguisher is bounded by the trace distance. Classical hardness of ΠX is thus sufficient for security against classical transcripts, but it is not necessary, and the security of a pair can exceed what Theorem 3.2 certifies. For the half-subspace pair the two receivers provably differ, as Section 6 shows.
4
The oracle and the primitives it removes
The requirements on the oracle come from Theorem 3.2. We want an oracle that answers every probability-estimation question, so that one-way puzzles cannot survive it, and one that answers in classical bits, so that the theorem applies to it. This section builds such an oracle and proves the first of the two halves of our result: relative to it, classical-output hardness of search and of decision both disappear. Fix n = n(λ) = 2λ . For each λ, independently across λ, sample a Haar-random halfdimensional real subspace Hλ ⊆ Rn(λ) and set ρb,λ as in (2). The supports are orthogonal, so that TD(ρ0,λ , ρ1,λ ) = 1.
4.1
The state source
Model 4.1 (State source R). On input (b, 1λ ), R returns one fresh copy of ρb,λ : it samples a Haar-random unit vector from Hλ (if b = 0) or Hλ⊥ (if b = 1) and returns that pure state, with the sampling randomness traced out. The input registers are measured in the computational basis before the sample is drawn, so that R is the channel ξ 7−→
⟨b, 1λ |ξ|b, 1λ ⟩ · ρb,λ ,
X b,λ
a completely positive trace-preserving map on classical-input registers, extended to malformed inputs by returning a fixed state. We shall use two properties of Model 4.1 later. The first is that R is a legitimate channel even when its input register is entangled with the caller’s workspace, because the dephasing makes the index classical. A call with a superposed index is a call with a classical index drawn from the induced distribution. Precisely, on a joint state ΞW I of the caller’s workspace W and the input register I, X (idW ⊗ R)(ΞW I ) = ⟨i|I ΞW I |i⟩I ⊗ ρi , i
27
so the workspace stays correlated with the dephased index. There is consequently no ambiguity of Stinespring dilation to resolve, and no access mode for R beyond sample access. Note that after t adaptive calls the retained joint state need not be a mixture of products, since a later index may depend on an earlier outcome; the domination below does not assume that it is. The second property is that the output is a fixed state for each index, so that t calls at security parameter λ yield at most t copies of ρ0,λ and ρ1,λ in total. This is dominated by granting t independent copies of each in advance and then, after each dephased index, swapping in the next unused copy of the corresponding state, which reproduces the joint state exactly. That is the form in which Section 5.1 charges them. The source doubles as the public EFI generator: G(1λ , b) calls R(b, 1λ ). A distinguisher may make additional calls on both branches, and Section 5.1 is where we control them. Comparison with the CHRS model. Each call to R re-samples, so t calls yield the product ρ⊗t b . This differs from the CHRS model [CCS25; BCN25; MNY24], where a single pure |ϕ⟩ is fixed at initialization and returned on every call, giving the permutation-invariant and strongly correlated Eϕ [|ϕ⟩⟨ϕ|⊗t ]. A swap test tells the two apart already at t ≥ 2. The distinction does not affect the separation, since Section 7 replaces R by a Boolean function altogether.
4.2
The counting oracle
The second layer answers the probability-estimation questions that, by [Cav+25c; HM25], characterize OWPuzzs. It is an exact probability-bit oracle: it returns individual binary digits of an output probability, so that a polynomial number of requests yields an inverse-exponentially accurate estimate. This is considerably stronger than the approximate counting of Stockmeyer [Sto83], which it subsumes, and the strength is deliberate, since Theorem 3.2 is indifferent to it. There is one obstacle to defining such an oracle, and it is not a technicality. The samplers whose probabilities we estimate are themselves oracle-aided, and so may call the very oracle we are defining. The following example shows that unrestricted self-reference has no consistent solution at all. Example 4.2 (Self-reference is inconsistent). Suppose a single oracle Count answered outputprobability bits of all oracle-aided samplers, including those querying Count. Consider the sampler C that queries Count for the leading bit of Pr[C(1λ ) = 0] and outputs 1 if that bit is 1, else 0. If Count reports 1 (a value ≥ 21 ), then C outputs 1 deterministically, so the true probability of output 0 is 0, whose leading bit is 0, a contradiction. If Count reports 0, then C outputs 0 deterministically, so the probability of output 0 is 1, whose leading bit is 1, again a contradiction. Two other remedies suggest themselves, and we take neither. One is to look for a fixed point rather than to forbid the self-reference, in the manner of Kleene’s recursion theorem; Example 4.2 rules that out, since the obstruction is not a matter of finding the right construction but of there being no consistent assignment. The other is to weaken the oracle to approximate counting, which is consistent because an approximate answer need not be the exact one it perturbs. That works, but at the cost of an error parameter, which would then have to be tracked across the levels of the recursion and through every downstream estimate. We prefer the bookkeeping of ranks and exact answers. The remedy we take is a well-founded rank, much as the polynomial hierarchy is stratified by alternation depth. Each counting query carries a rank r ∈ N, and a rank-r query may ask only about samplers whose own oracle calls have rank strictly below r. We can then define the family by ordinary recursion on r, and no fixed-point theorem is needed, because the relation “query p may 28
refer to query q” requires rank(q) < rank(p) and so admits no cycles and no infinite descending chains. One point about the rank condition needs care, and it determines how we state the condition. The oracle has to be able to decide whether a query is admissible, and it has to do so even when the sampler it is asked about computes its own ranks while running, possibly in superposition, in which case there is no single behavior to inspect. We therefore impose the condition on the description the oracle is handed, rather than on the behavior of the sampler that description defines. Concretely, a sampler is admissible as the argument of a rank-r query when every counting gate in its description takes one of two forms, each of which can be recognized by reading the code. The first form carries a rank s < r written into the description, and admissibility is then decided by reading it. A sampler uses the second form when it has to choose a layer at runtime. That form carries a bound J < r, also written into the description, and it receives the rank itself as runtime data, which the computation may have produced adaptively or coherently. Such a gate forwards the query to Counts when the rank s it receives at runtime is well formed with s ≤ J, and returns 0 otherwise. Since the bound is fixed in the description while the rank is not, a gate of the second form accesses only O<r whatever the computation does, and this too can be decided by inspecting the code. A sampler that computes an index i and needs the answer of the i-th layer is accordingly given a gate of the second form rather than unrestricted access, and queries whose rank exceeds J return 0. Choosing J above every rank the sampler can write costs it nothing, and that is the situation in every use below. Throughout, samplers are clocked: a description carries an explicit polynomial step bound after which the computation halts, so the description alone bounds every rank its sampler can write. Write NormJ for the compiler that replaces each call to the joined oracle by a gate of the second form with bound J. When J is at least every well-formed rank that the original clocked computation can write, NormJ preserves its induced channel exactly, including for adaptive and coherent calls, and with only polynomial overhead. The reason is that the two gates agree as maps on every basis state the computation can produce: a well-formed rank at most J is forwarded unchanged, and by the choice of J no other rank ever occurs, so the substitution changes no amplitude. The overhead is the comparison against J. One further design choice remains. We make the oracle bit-valued, returning bits of the exact output probability rather than an approximation. This has three consequences: it removes a parameter; it removes any need to argue that approximation errors compound across ranks, since exact bits feed into exact bits; and, as Section 6 explains, it keeps the coherent version of the oracle an ordinary Boolean oracle. Definition 4.3 (Bit convention). For p ∈ [0, 1) let p = k≥1 bitk (p)2−k be the binary expansion P not ending in all 1s; for p = 1 set bitk (1) = 1 for all k. Then pet = k≤t bitk (p)2−k satisfies 0 ≤ p − pet ≤ 2−t for every p ∈ [0, 1], and bit1 (p) = 1 iff p ≥ 21 . P
Definition 4.4 (The oracle O = (R, Count)). Let O<r := R ∪ 0≤r′ <r Countr′ , so that O<0 = R. For r ≥ 0, on input (⟨C⟩, 1λ , x, k) where C is a clocked QPT sampler with classical output whose oracle access is to O<r only in the sense above, S
Countr ⟨C⟩, 1λ , x, k
= bitk Pr C O<r (1λ ) = x .
The index k is written in unary, so a query of polynomial length requests polynomially many bits. The full oracle is O = (R, Count) with Count(⟨1r , q⟩) := Countr (q), the unary-tagged Boolean join. Malformed tags, unclocked descriptions, and descriptions violating the rank condition receive 29
answer 0, so Count is a total Boolean oracle on classical strings, and all unary tags are charged to the query cost. Lemma 4.5 (Well-definedness). Definition 4.4 determines a unique oracle, and every bit of Count is a Borel function of the full sequence H = {Hλ }, and of {(Hλ , Sλ )} in Model 7.1, a sampler at one security parameter being permitted to query another. Proof. Read without the rank condition, Definition 4.4 would ask for a fixed point, and Example 4.2 shows that unrestricted self-reference admits no such assignment. With the rank in place there is no fixed point to find, only an ordinary recursion, and we run it. We argue by strong induction on r. The base O<0 = R is given. Suppose, then, that Countr′ is defined for all r′ < r. Then O<r is determined, and for any admissible C the quantity Pr[C O<r (1λ ) = x] is the output probability of a fixed algorithm with a fixed, already-defined oracle. It is a well-defined real, and so are its bits. Invalid inputs have the specified answer 0. Crucially, no reference to rank ≥ r occurs in the clause defining Countr , so the recursion never reaches back into the layer it is defining. Every layer, and hence the whole family, is determined uniquely. That leaves measurability, which follows by the same induction, in three steps. At the base, a call to R returns the fixed state ρb,λ = 2PH /n or its complement, so the output probability of a fixed clocked circuit with sample access alone is a polynomial in the entries of PH , and hence continuous in H. At rank r, suppose the oracle bits the circuit reads below r are Borel in H. Its output probability is then a finite sum of products of those bits, with coefficients that are themselves continuous in H, and hence Borel; and bitk of a Borel function is again Borel. For Model 7.1, finally, the base layer is Borel in (H, S) because the rounding map is constant on the cells of a finite measurable partition, and the same induction applies. The computational power of Count. The security proof does not require that Count be weak, and the ranked join is in fact strong. Because ranks are unary and uniformly addressable, a decreasing rank can serve as the recursion counter of an alternating computation, and we expect that for every fixing of the hidden subspaces the tagged Boolean join satisfies PCount = PSPACECount , whence every classical-input class in between collapses to it. With binary tags the same argument would reach EXPTIME, which shows that this is a property of the encoding. We do not use the claim anywhere, and so do not prove it. None of this matters for security. Theorem 3.2 already covers an arbitrary, even uncomputable truth table, so the computational power of Count is irrelevant to EFI security by construction. What is scarce is not the power of the oracle, but the amount and the type of information about H that reaches the adversary. We should stress what this does not show. It is no evidence that EFI pairs can coexist with the unrelativized equality P = PSPACE, nor with a single classical oracle: efficient generation still uses the state source R, and Theorem 5.5 permits only classical access to Count. The question of [Kre+23; Cav+25a] remains open, and our techniques do not address it, since replacing the Haar source by a short classical description of H would invalidate the proof outright, the holder of H being free to send that description.
4.3
Nonexistence of one-way puzzles
Lemma 4.6 (Probability estimation is easy relative to O). Every QPTO -samplable classical distribution admits efficient probability estimation relative to O, using one integer, a bound on the 30
ranks the sampler can write, that is read off its explicit step bound. The estimate is 2−t -additively accurate for any t = poly(λ), with success probability 1, using t classical queries. Proof. Fix an oracle-aided sampler C O with classical output. The only obstacle is that C is not, by itself, an admissible argument to any single layer of Count, and the proof consists in making it one. On inputs of length λ the sampler makes polynomially many oracle calls, each carrying a unary rank; let JC (λ) bound all ranks it can write at input length λ. That integer is at most the sampler’s step bound, since a rank is written in unary during the computation, so we can read it off the clocked description. Let Cλ be the clocked specialization running C O (1λ ) and Cbλ := NormJC (λ) (Cλ ). We will show that Cbλ is an admissible argument to CountJC (λ)+1 whose output distribution is exactly that of C O (1λ ), after which the estimate can be read off the oracle one bit at a time. Admissibility is by inspection: Cbλ has polynomial description length, and its code certifies that it accesses only O<JC (λ)+1 . The output distribution is unchanged for a different reason: JC (λ) bounds every rank C can write, so the normalization preserves the induced channel, by the property of NormJ recorded in Section 4.2. Now we run the estimator. On input x it constructs ⟨Cbλ ⟩ and queries CountJC (λ)+1 ⟨Cbλ ⟩, 1λ , x, k ,
k = 1, . . . , t,
outputting the truncation pet . By Definition 4.3, |pet − Pr[C O (1λ ) = x]| ≤ 2−t for every value, including 0 and 1, which is what the lemma asserts. The strength of Lemma 4.6 is that t classical queries give additive error 2−t , so exponentially small error is available at polynomial cost. So the next theorem admits a direct and elementary attack, and we need not assume that the characterization of [Cav+25c] relativizes. Two arguments below replace a quantum party by a classical one that samples from these estimates, one bit at a time: the puzzle attack of Appendix A and the interactive simulation of Section 4.5. Both pay for the estimator in the same way, and we isolate that accounting here, in two steps, so that neither has to repeat it. The first step is local. A simulator that must produce the next bit knows two truncated probabilities and samples from their ratio, and the question is how far that is from the true conditional law. Lemma 4.7 (Sampling from a truncated ratio). Let p0 , p1 ≥ 0 with p := p0 + p1 ≤ 1, and let η = 2−t > 0. Suppose 0 ≤ p̃y ≤ py and py − p̃y ≤ η for y ∈ {0, 1}, write S̃ := p̃0 + p̃1 , and let π̃ be the law on {0, 1} that gives y probability p̃y /S̃ when S̃ > 0, rounded to a multiple of 2−2t . If p ≥ 4η then S̃ > 0, the true conditional law π(y) := py /p is defined, and TV(π, π̃) ≤
4η . p
Proof. Both laws live on two points, so their total variation distance is the deviation at y = 0. Put ey := py − p̃y ∈ [0, η]. Before the rounding, a direct computation gives p0 p̃0 − p S̃
=
e0 p1 − e 1 p0 p S̃
≤
η , S̃
the numerator being at most η max{p0 , p1 } ≤ ηp. The rounding adds at most 2−2t , and 2−2t ≤ η/S̃ because S̃ ≤ 1, so TV(π, π̃) ≤ 2η/S̃. The denominator is itself close to p, since S̃ ≥ p − 2η. So p ≥ 4η gives S̃ ≥ p/2 > 0, and the displayed bound follows. 31
The second step is global. A history of small probability is cheap because it is rare; a history of large probability is cheap because Lemma 4.7 is accurate on it; and one threshold separates the two. Lemma 4.8 (Threshold accounting). Let H be a set of at most K elements, and let P, V : H → [0, 1] P satisfy h∈H V (h)P (h) = 1. Let η > 0 with K −1 ≥ 4η, and let τ : H → [0, 1] satisfy 4η P (h)
τ (h) ≤
whenever P (h) ≥ 4η.
Then X
V (h) P (h) τ (h) ≤ 2 4ηK. p
h∈H
Proof. Put θ := 4η/K. Then θ ≥ 4η, since θ2 = 4η/K ≥ 16η 2 by hypothesis. Split the sum at θ. A light h, one with P (h) < θ, contributes at most V (h)P (h)τ (h) ≤ P (h) < θ, using only V, τ ≤ 1. There are at most K elements in all, so the light ones contribute at most Kθ together. A heavy h, one with P (h) ≥ θ, has P (h) ≥ 4η, so the hypothesis applies to it, and the heavy ones contribute p
X h heavy
V (h)P (h) ·
X 4η 4η X 4η = 4η V (h) ≤ V (h)P (h) ≤ . P (h) θ h heavy θ h heavy
The choice of θ makes the two ranges equal, each being
√
4ηK, and adding them gives the bound.
Theorem 4.9 (No one-way puzzles relative to O). Fix any choice of {Hλ }. For every candidate one-way puzzle (SampO , Ver) satisfying correctness there is a polynomial-time adversary A (a classical algorithm making classical queries to Count) such that Pr
(k,s)←Samp(1λ )
Ver A(1λ , s), s = 1
≥ 1 − negl(λ).
In particular OWPuzzs do not exist relative to O, including inefficiently verifiable ones, for every fixing of the oracle’s randomness. Appendix A gives the proof. The adversary samples the key bit by bit, from an estimate of the true conditional distribution of keys given the puzzle, using Lemma 4.6 on the prefix samplers “run Samp and output (s, k1 · · · ki )”. Because the estimates are exponentially accurate, the joint distribution of (s, A(s)) lies within 2−λ of the honest one, and so the unbounded verifier accepts with probability 1 − negl(λ). Notice that the attack never runs Ver; that is why we need no assumption on the verifier. Corollary 4.10 (Consequences for other primitives). Relative to O, the following do not exist: multi-copy pseudorandom states and pseudorandom unitaries, pure-output one-way state generators, and quantum money mini-schemes with pure banknotes (each implies OWPuzzs [KT24; BJ24; KT25; MY22]). Moreover, since the adversary of Theorem 4.9 is a classical polynomial-time algorithm making classical queries, even classically-secure OWPuzzs do not exist relative to O.
32
The scope of these inferences. The word “multi-copy” in Corollary 4.10 is essential, for the following reason. By [Cav+25a, Thm. 1.1], EFI pairs exist if and only if non-uniform 1PRS with advice size O(log λ) exist. Since Theorem 5.6 keeps an EFI pair in its access model, non-uniform 1PRS with O(log λ) advice must survive relative to O in that same model. This is consistent, because multi-copy PRS imply OWPuzzs and are removed for that reason, whereas single-copy pseudorandomness is not known to imply them, and here does not. It follows that O separates multi-copy from non-uniform single-copy pseudorandomness, which is the separation of [CCS25], in the classical-query model of Model 1.1. That inference is conditional on the equivalence of [Cav+25a] relativizing to this access model, in which the 1PRS it yields is secure. The other half, by contrast, is robust. The nonexistence of multi-copy PRS survives the model restriction, since the chain PRS ⇒ pure OWSG ⇒ OWPuzz turns our classical-query OWPuzz attacker into a classical-query PRS attacker, while the candidate generator remains free to query Count coherently, which Definition 4.4 permits. Two further consequences carry conditions of the same kind. Quantum lightning does not survive O for the standard notion, since lightning yields a quantum money mini-scheme [Zha19, §3.2] and mini-schemes imply OWPuzzs [KT25, Cor. 1.1], and both links relativize. The minischeme of [KT25] has a pure banknote, however, so the mixed-banknote notion of [AC12] is not covered, and Section 9 returns to that gap. Unconditional, on the other hand, is the statement that O admits an EFI pair and no classical-output quantum advantage, by Theorem 5.5 together with Corollary 4.15; Section 4.5 compares it with the route through [MSY25, Thm. 1.1].
4.4
Nonexistence of QEFID pairs
The attack of Theorem 4.9 removes the classical-output one-wayness in the OWPuzz definition, and the same oracle removes classical-output indistinguishability as well. The qualitative conclusion here is not new, so we first state the result that already implies it. By [CGG24, Lem. 8], restated as [Beh+25, Thm. 6.3], QEFID pairs imply OWPuzzs in a black-box manner, so Theorem 4.9 already rules out QEFID pairs relative to O through that implication. What the direct argument below adds is quantitative. Its distinguisher is classical polynomial time with classical queries; its advantage is the full statistical distance up to 2−λ , rather than merely non-negligible; the conclusion holds for every fixing of {Hλ }; and no appeal to the relativization of [CGG24] is needed. The proposition says that relative to O the computational and the statistical theories of quantum-samplable classical distributions coincide. Proposition 4.11 (Statistical and computational indistinguishability coincide for classical-output samplers). Fix any choice of {Hλ }. Let S0 , S1 be QPT oracle samplers with classical outputs of length ℓ = ℓ(λ) = poly(λ), and write Db for the distribution of SbO (1λ ), suppressing λ. There is a classical polynomial-time adversary D, making O(ℓ + λ) classical queries to Count, whose distinguishing advantage between D0 and D1 satisfies, for all sufficiently large λ, Adv(D) ≥ TV D0 , D1 − 2−λ .
Proof. An adversary that knew the two output probabilities exactly would apply the likelihoodratio test and would achieve the full statistical distance. Our adversary knows them only to inverse-exponential accuracy, and the proof shows that this costs it almost nothing. Write pb (x) := Pr SbO (1λ ) = x ,
b ∈ {0, 1}, x ∈ {0, 1}ℓ ,
for those probabilities. The exact test outputs 1 precisely when p1 (x) > p0 (x), and its advantage is X
max p1 (x) − p0 (x), 0
x
33
= TV D0 , D1 ,
(7)
which no function of x improves on. Now fix the precision t := ℓ + λ + 2 and write η := 2−t . On input x the adversary applies Lemma 4.6 to each of S0 and S1 , obtaining truncations pe0 (x) and pe1 (x) that satisfy 0 ≤ pb (x) − peb (x) ≤ η and it outputs
(b = 0, 1),
g(x) := 1 pe1 (x) > pe0 (x) + η .
The margin η in the comparison is there to absorb the truncation error. Computing the two truncations takes 2t = O(ℓ + λ) classical queries, and we read the single integer bounding the ranks of both samplers off their clocked descriptions, exactly as in Lemma 4.6. We will show that g and the exact rule g ∗ (x) := 1[p1 (x) > p0 (x)] can disagree only when the two probabilities lie within 2η of each other. Suppose first that p1 (x) > p0 (x) + 2η. Then pe1 (x) ≥ p1 (x) − η > p0 (x) + η ≥ pe0 (x) + η, so g(x) = 1 = g ∗ (x). Suppose instead that p1 (x) ≤ p0 (x). Then pe1 (x) ≤ p1 (x) ≤ p0 (x) ≤ pe0 (x) + η, so g(x) = 0 = g ∗ (x). The two rules agree, then, outside the set B :=
x : 0 < p1 (x) − p0 (x) ≤ 2η ,
as claimed. That leaves B. Each x ∈ B costs at most |p1 (x) − p0 (x)| ≤ 2η of advantage relative to the exact rule, and B contains at most 2ℓ points. Subtracting this loss from (7), Adv(D) ≥ TV D0 , D1
− 2ℓ · 2η = TV D0 , D1 − 2ℓ+1−t = TV D0 , D1 − 2−λ−1 ,
which is the stated bound. Corollary 4.12 (Nonexistence of QEFID pairs and of classical-output EFI pairs). Relative to O, and for every fixing of {Hλ }, the following hold. (i) QEFID pairs do not exist, and the attacker is a classical polynomial-time algorithm making classical queries, so classically-secure QEFID pairs do not exist either. (ii) No EFI pair relative to O has both states diagonal in a common basis reachable by a QPT isometry whose Count-queries are made on registers in computational-basis states and which retains all its registers, so that it preserves trace distance. In particular the pair of Theorem 5.5 cannot be replaced by any classical ensemble. Proof. (i) Suppose (D0 , D1 ) is a QEFID pair with samplers S0 , S1 and farness TV(D0 , D1 ) ≥ δ(λ) for an inverse polynomial δ. Then Proposition 4.11 gives a distinguisher of advantage δ(λ) − 2−λ , which is not negligible. That distinguisher is a classical polynomial-time algorithm making classical queries, so classically-secure pairs are excluded by the same computation. (Alternatively, and without the quantitative conclusion, combine [CGG24, Lem. 8] with Theorem 4.9.) (ii) Suppose (ρ0,λ , ρ1,λ ) is an EFI pair relative to O, and let Vλ be a QPT isometry that diagonalizes both branches, in the sense that Vλ ρb,λ Vλ† is diagonal in the computational basis for 34
both b. We ask of Vλ only that it query Count on registers in computational-basis states, and that it retain all of its registers. Let Sb run the EFI generator on branch b, apply Vλ , and measure. Then S0 , S1 are QPTO samplers with classical output. A measurement in a basis that diagonalizes both states preserves trace distance, so TV(D0 , D1 ) = TD(ρ0,λ , ρ1,λ ) ≥ δ(λ), so part (i) applies. The distinguisher that applies Vλ , measures, and then runs the adversary of Proposition 4.11 makes only classical queries, so it lies in the class of Model 1.1 against which the pair is secure, and its advantage is not negligible. The second assertion of (ii) is the case Vλ = I. A classical ensemble that was an EFI pair relative to O would be a pair of QPTO -samplable classical distributions, statistically far apart and yet indistinguishable by every distinguisher of Model 1.1 – a class that contains the attacker of part (i).
4.5
Interactive protocols with classical messages
Theorem 4.9 and Proposition 4.11 remove classical-output hardness from two fixed experiments, one of search type and one of decision type. The same estimator, however, removes it from every experiment of that kind at once, interactive ones included, and that is what we prove here. Relative to O, a quantum polynomial-time party has no advantage over a classical one, provided that everything the party sends and receives is classical. Model 4.13 (Interactive party with classical messages). A quantum party Q is a QPTO algorithm carrying an internal quantum state across R = poly(λ) rounds. In round j it receives a classical message cj , applies a QPTO channel to its state together with that message, and measures a designated register to produce the classical message dj , which it sends. Its oracle calls inside a round may be coherent. A counterparty V is any process, of unbounded computational power and with an internal state of any kind, whose messages are classical and whose cj is produced from c1 , d1 , . . . , cj−1 , dj−1 together with its own private randomness. The two parties share no initial entanglement and no correlated setup, and V may itself query O. Truncating each incoming message to the prefix that Q reads leaves Q’s behavior unchanged, so we take all messages to have fixed polynomial lengths. We write A for the total number of incoming bits Q reads; its clock bounds that number, which depends on Q alone. We write N for the total length of Q’s messages. We write T (Q, V) for the distribution of the full transcript (c1 , d1 , . . . , cR , dR ). Theorem 4.14 (Interactive collapse). Fix any choice of {Hλ }. For every quantum party Q of b making poly(λ) classical Model 4.13 there is a classical probabilistic polynomial-time party Q, queries to Count, such that for every counterparty V and all sufficiently large λ, b V), T (Q, V) TV T (Q,
≤ 2−λ .
The bound is uniform in V: neither a bound on its complexity nor access to its description is used anywhere. Proof. The simulator draws each of Q’s outgoing bits from an estimate of the conditional law that Q itself uses, and the work lies in showing that these laws are visible to Count and that the estimation error does not accumulate over the N bits. First, each conditional is a ratio of two output probabilities of admissible samplers, and so is available from Count. Second, the truncated ratio we can sample from at polynomial cost. Third, a hybrid over the outgoing bits, with a threshold separating the histories of small probability from those on which the estimates are relatively accurate, keeps the accumulated error below 2−λ . 35
Step 1: the conditional law of each outgoing bit is a ratio of two output probabilities that Count reports. Regard the concatenation of Q’s messages as a single string of N bits, and for a bit index i let j(i) be the round it belongs to. For an incoming sequence c = (c1 , . . . , cj(i) ) let Cc,i be the sampler that runs Q(1λ ), feeds it c1 , . . . , cj(i) as the incoming messages, and outputs the first i bits that Q sends. Feeding fixed messages irrespective of what Q replies is legitimate, since the result is again a fixed clocked QPTO algorithm with classical output, of polynomial description length because |c| ≤ A = poly(λ). So, with J bounding the ranks Q can write, NormJ (Cc,i ) is an admissible argument to CountJ+1 by the reasoning of Lemma 4.6, and we read J +1 off Q’s clocked description. O (1λ ) = y]. Notice that these are consistent: Write Pc (y) := Pr[Cc,|y| Pc (y) = Pc (y0) + Pc (y1). When y0 and y1 lie in the same round as y, this is the marginal of a single sampler. When they open a new round it holds for a different reason: the first |y| bits are sent before cj(|y|+1) arrives, and so cannot depend on it. Consequently, for a history whose incoming part is c and whose outgoing part is y, the true conditional law of the next outgoing bit is πc,y (β) =
Pc (yβ) Pc (y)
whenever Pc (y) > 0.
This last identity is where we use the absence of a correlated setup. By induction on the rounds, on every fixed transcript branch the joint state is a product of Q’s and V’s sub-normalized branch states, each party acting on its own registers and learning of the other only through classical messages. The probability of a history thus factorizes as Pr[c, y] = V (c, y) Pc (y), where V (c, y) is the product of V’s conditional probabilities of its own messages, and likewise Pr[c, yβ] = V (c, y) Pc (yβ). The conditional law of the next outgoing bit is the ratio of the two, and the counterparty’s factor cancels. After Step 1 every number the simulator needs is the answer to a query about a single admissible sampler, and it can be obtained to any polynomial precision. Step 2: the simulator sends every outgoing bit drawn from the truncated ratio, at polynomial b keeps the history in the cost. Fix the precision t := A + N + 3λ and put η := 2−t . The party Q clear. To produce its i-th outgoing bit, with incoming messages c and own prefix y, it does the following. • It queries Count for the first t bits of Pc (y0) and of Pc (y1), obtaining truncations with 0 ≤ Pc (yβ) − Pec (yβ) ≤ η. • If both truncations vanish, it sends 0. • Otherwise it sends β with probability Pec (yβ)/(Pec (y0) + Pec (y1)), rounded to a multiple of 2−2t so that 2t fair coins realize it exactly. ec,y . The rounding costs 2−2t in total variation, which Lemma 4.7 already absorbs Call that rule π into its constant. The whole interaction costs 2N t = poly(λ) classical queries. b is a classical probabilistic polynomial-time party of the kind the So far we have shown that Q statement asks for, and it remains to compare the transcript it produces with the real one. Step 3: the hybrid over the N outgoing bits loses at most 2−λ in all. The rule of Step 2 is the one Lemma 4.7 analyses, at pβ = Pc (yβ), so whenever Pc (y) ≥ 4η, ec,y TV πc,y , π
36
≤
4η , Pc (y)
and trivially TV ≤ 1 elsewhere. For 0 ≤ i ≤ N let Di be the interaction in which Q’s first e , with V i outgoing bits are drawn from the true conditionals and the remaining ones from π b V). Adjacent hybrids use the same unchanged throughout, so that DN = T (Q, V) and D0 = T (Q, rule at every bit except the (i + 1)-st, and the history before that bit is distributed as in the real interaction, so ec,y ) , TV(Di , Di+1 ) ≤ E(c,y) TV(πc,y , π the expectation being over the real law of the history (c, y) before bit i + 1. That expectation is exactly what Lemma 4.8 bounds, and the chain rule supplies its hypotheses. Write Pr[c, y] = V (c, y) Pc (y), where V (c, y) collects V’s conditional probabilities of the messages in c. Then V (c, y) ≤ 1, and P c,y V (c, y)Pc (y) = 1 because the histories at a fixed step partition the probability space. There −1 ≥ 4η holds comfortably, since are at most 2A+N histories, so we take K = 2A+N ; and pK η = 2−(A+N +3λ) . The lemma therefore gives E(c,y) [TV] ≤ 2 4η 2A+N . Summing over the N steps, b V), T (Q, V) TV T (Q,
≤ 2N
q
4η 2A+N = 4N 2−3λ/2 ≤ 2−λ
for all large λ, since N = poly(λ). Notice that the only properties of V used anywhere are V (c, y) ≤ 1 and the normalization above, so the bound holds for every counterparty, which is what the theorem asserts. Everything V computes is a function of the transcript and of its own randomness, so the conclusion transfers to any quantity read off at the end of the interaction. We state the two cases we use. Corollary 4.15 (No quantum advantage over classical communication). Relative to O, and for every fixing of {Hλ }: (i) every classical distribution samplable in QPTO is samplable to within 2−λ in total variation by a classical probabilistic polynomial-time algorithm making classical queries to Count; and (ii) there is no inefficient-verifier proof of quantumness. For every QPTO prover and every verifier of unbounded computational power exchanging classical messages with it, there is a classical probabilistic polynomial-time prover, making classical queries to Count, whom that verifier accepts with probability differing by at most 2−λ . Proof. (i) Apply Theorem 4.14 with no incoming messages, so that A = 0 and the transcript is the sampler’s own output. (ii) Apply Theorem 4.14 with V the verifier. Write a(π) ∈ [0, 1] for its acceptance probability conditional on a transcript π. That is the same function in the real and in the simulated experiment, since the verifier’s own process, given the messages it sends and receives, is identical in both. So the two acceptance probabilities are X
Prreal [π] a(π)
and
π
X
Prsim [π] a(π).
π
Since 0 ≤ a ≤ 1, their difference is at most sup0≤f ≤1 |Ereal f − Esim f |, which is the total variation distance between the two transcript laws, and the theorem bounds that by 2−λ .
37
Part (ii) is stated in general form because a proof of quantumness is only the simplest instance. The simulation is uniform in the counterparty, so it applies to any interactive protocol whose messages are classical. Relative to O, then, an efficient quantum prover confers no advantage over an efficient classical one in such a protocol: whatever an unbounded verifier can be convinced of by a QPTO prover exchanging classical messages, it can be convinced of by a classical polynomialtime prover making classical queries, with acceptance probabilities differing by at most 2−λ . The classical-message restriction is essential: a prover sending quantum messages is outside the scope of Theorem 4.14, as is a prover sharing entanglement with the verifier in advance. Scope of the collapse. Corollary 4.15(i) contains the sampling half of Section 4.3 and Section 4.4, and in its own case Proposition 4.11 sharpens it, since that proposition achieves the full statistical distance rather than a simulation. Theorem 4.9 is not an instance, however. The attack there has to sample a key conditioned on a puzzle that the honest sampler itself produced, which is the same estimator applied to conditional rather than to joint distributions. What Theorem 4.14 adds beyond both is the interactive case, and with it part (ii), which no single-message statement reaches. Part (ii) can also be obtained along a second route, by combining the characterization of inefficient-verifier proofs of quantumness by classically-secure OWPuzzs [MSY25, Thm. 1.1] with Corollary 4.10. We prefer the direct route here because it assumes nothing about relativization, holds for every fixing of {Hλ }, and is not restricted to uniform adversaries. Theorem 4.9, Corollary 4.12 and Theorem 4.14 are three faces of a single statement. A OWPuzz is classical-output hardness of search, a QEFID pair is classical-output hardness of decision, and a proof of quantumness is classical-output hardness of interaction. What we have shown is that Count removes all three, for every fixing of the hidden subspaces and against unbounded verifiers. What remains available relative to O is hardness of a different kind, the indistinguishability of two quantum states, and Theorem 5.5 shows that this remainder is not empty. The two layers therefore fit together rather than merely coexist: the counting oracle trivializes the classical-output theory, and the state source supplies what is left, a pair of states whose distinguishing measurement is itself the secret. Nor are the two halves independent facts about O. By the equivalence recalled in Section 2.5, classical-output search hardness and classical-output decision hardness cannot be separated, so an oracle removing one necessarily removes the other. What our two proofs add is that both fail directly, by a classical polynomial-time attack, for every fixing of the hidden subspaces, with no implication needed in between. One further consequence follows. Since QEFID pairs trivially yield EFI pairs, by regarding the distributions as diagonal density operators, O also separates EFI pairs from QEFID pairs, in the classical-query model of Model 1.1 for the EFI direction and unconditionally for the QEFID direction. By that same equivalence this is a restatement of Theorem 5.6 rather than a new separation. It is, finally, the opposite orientation to [Beh+25], who give a unitary oracle with QEFID pairs but no OWSGs and hence retain the classical-output primitive.
5
EFI security
We now apply Theorem 3.2 to the half-subspace pair. One obstacle remains. Since the generator is public, a distinguisher may obtain reference copies, and those copies are quantum side information depending on H, which is exactly what the hypotheses of Theorem 3.2 do not cover. Section 5.1 reduces them to classical side information first. After that the associated problem is VSP, and the theorem applies. 38
5.1
Reference copies and the residual instance
The idea is to give the adversary something classical that is at least as useful as the copies themselves. A basis of the span of q Haar vectors in H determines their joint law, so the copies can be resampled from the span alone. In other words, the span is at least as good to the adversary as the copies were, and unlike them it is a classical object. Having replaced the copies by the two spans, we then condition on those spans. What is left is a Vector-in-Subspace instance in the orthogonal complement, of dimension n − 2q, together with one branch of weight 2q/n on which we concede everything. Reference copies cost us that branch and a loss of dimension, and nothing else. Fix q < n/4 and sample independent uniformly random q-dimensional A ⊆ H and B ⊆ H ⊥ . Set K = (A ⊕ B)⊥ , dim K = n − 2q, HA = H ∩ A⊥ , HB = H ⊥ ∩ B ⊥ . Lemma 5.1 (Geometry of the residual). The decompositions H = A ⊕ HA and H ⊥ = B ⊕ HB are orthogonal, both HA and HB lie inside K and have dimension (n − 2q)/2, and within K they are orthogonal complements of each other. Moreover, conditioned on (A, B), the subspace HA is Haar-random of dimension (n − 2q)/2 inside K. Proof. Since A ⊆ H, the orthogonal complement of A inside H is H ∩A⊥ = HA , so that H = A⊕HA with dim HA = n/2 − q. The same argument applied to B ⊆ H ⊥ gives H ⊥ = B ⊕ HB . Next, both residual subspaces lie in K. Indeed HA ⊆ A⊥ by definition, while B ⊆ H ⊥ gives B ⊥ ⊇ H ⊇ HA , so that HA ⊆ A⊥ ∩ B ⊥ = K, and symmetrically HB ⊆ K. Since HA ⊆ H and HB ⊆ H ⊥ , the two are orthogonal to each other, and dim HA + dim HB = n − 2q = dim K, so they are orthogonal complements inside K. What is left is to identify the conditional law of HA given (A, B), and this is the only place where we use the joint O(n)-invariance of (H, A, B). Given h ∈ O(K), extend it to g ∈ O(n) acting as the identity on A and on B and as h on K. Then g stabilizes (A, B) setwise, so (gH, A, B) has the same conditional law as (H, A, B) given (A, B). Since g preserves A⊥ and HA ⊆ K, we have gHA = gH ∩ A⊥ = h(HA ). The conditional law of HA is thus O(K)-invariant, and hence Haar. Lemma 5.2 (Reference-copy reduction). Let an adversary be given the classical descriptions of A and B, and then one challenge from ρ0 or ρ1 with a uniform bit. Consider any strategy with Borel message functions whose remaining classical communication with the holder of H is at most L bits. Its distinguishing advantage, averaged over H and over (A, B), is at most 2q n + 2β(n − 2q, L + 1). The additional bit here is the orientation of the gap, which the holder of H sends. Proof. If q = 0 there is nothing to condition on: the challenge is the residual branch itself, and the argument given below for that branch yields 2β(n, L + 1) directly. We may therefore assume q ≥ 1. Consider first why handing the adversary the spans concedes at least as much as handing it the copies. The span of q i.i.d. Haar vectors in H is almost surely a uniformly random q-dimensional subspace A ⊆ H. By O(n)-invariance, the conditional law of the vectors given their span depends on nothing but A: it is a fixed distribution on spanning q-tuples, rotated into A. So an adversary holding a basis of A can resample the reference copies locally with the correct joint distribution, adaptively and one at a time if they were requested that way. Now condition on (A, B). By Lemma 5.1 and PH = PA + PHA , 2q PA 2q PH A 2PH = · + 1− · , n n q n (n − 2q)/2 39
and symmetrically for ρ1 with (B, HB ). On each branch the challenge is a mixture: with probability 2q/n the maximally mixed state on the known subspace, and with probability 1 − 2q/n the maximally mixed state on the residual. The advantage splits along that mixture, because for a fixed strategy and fixed randomness the acceptance probability is affine in the input density operator, being a composition of fixed channels, of measurements, and of the holder’s fixed responses. On the known branch we bound the advantage by 1, paying 2q/n. ⊥, Now for the residual branch. There the challenge is maximally mixed on HA or on HB = K∩HA inside K of dimension n − 2q, with HA Haar of half dimension. A pure version of that state is a uniform unit vector in HA or in its complement within K, so deciding which of the two, using L bits of interaction with the holder of H, is an L-bit protocol for VSPn−2q . One bit separates that from β, namely the orientation: the distinguishing advantage is the absolute gap between the two branches, whereas β is one-sided. As in the proof of Theorem 3.2, we let the holder of H send one further bit recording the sign of that gap. The strategy then becomes an (L + 1)-bit protocol whose advantage is half the residual-branch distinguishing advantage, by the conventions of Section 2.6. So this branch contributes at most 2β(n − 2q, L + 1), which together with the 2q/n already paid is what the lemma asserts. Corollary 5.3 (The associated problem for the EFI game). For q < n/4 there is a universal C > 0 such that every strategy with at most q reference copies per side and at most L bits of classical interaction with the holder of H has average distinguishing advantage at most 2q +C n
s
L+2 . (n − 2q)1/3
Proof. Give the adversary the spans, which only increases its power and replaces the quantum reference copies by classical side information. Lemma 5.2 then bounds the average advantage by 2q n + 2β(n − 2q, L + 1), and Lemma 2.7 bounds the second term, applied with n − 2q > n/2. We make that application for each fixed (A, B) separately, with (A, B) hard-wired into the protocol, and averaging over (A, B) then preserves the bound. Absorbing the factor 2 into C gives the stated estimate.
5.2
The security theorem
Everything above bounds an advantage averaged over the random subspaces, whereas an oracle separation needs a single sequence {Hλ } that defeats every adversary at once. The passage from one to the other is the same in all three places where we make it, here and in Corollary 6.16 and Theorem 7.2, so we record it once. It has two ingredients: the adversaries must form a countable family, and the maximization over advice must sit inside the expectation. Lemma 5.4 (From average security to a fixed object). Let X = {Xλ } be a sequence of random objects and {Ni }i∈N a countable family of machines. Write Adv∗Ni (λ; X) for the advantage of Ni at security parameter λ, maximized over its advice strings, and suppose that for every i, µi (λ) := EX Adv∗Ni (λ)
= negl(λ).
Then, with probability one over X, every i has a threshold beyond which Adv∗Ni (λ) ≤ λ2 µi (λ), which is again negligible, and which is 2−Ω(λ) whenever µi is. For such a fixed X, every nonuniform adversary whose machine lies in the family has negligible advantage, however its advice depends on X. 40
Proof. Markov’s inequality at the threshold λ2 µi (λ) gives PrX Adv∗Ni (λ) > λ2 µi (λ) ≤ λ−2 ,
which is summable in λ. The first Borel–Cantelli lemma does not require independence, so almost surely only finitely many λ violate the threshold. Intersecting these probability-one events over the countably many i leaves an event of probability one on which every Ni obeys it. The last sentence follows because the maximization over advice sits inside µi . A non-uniform adversary is a pair (machine, advice sequence) whose machine is some Ni , and its advantage at every λ is at most Adv∗Ni (λ), whatever advice it uses and however that advice was chosen once X was fixed. The polynomial threshold is not essential. Any g(λ)µi (λ) with λ g(λ)−1 < ∞ would serve. −1/2 We take g polynomial rather than, say, g = µi , because a polynomial factor leaves the exponent of the expected advantage intact, and that is the exponent Section 5.3 compares with the attack. Countability is the other ingredient, and it is the reason we enumerate machines rather than (machine, advice-sequence) pairs, of which there are uncountably many. That enumeration suffices only because maxα sits inside EX , and the reduction of Theorem 3.2 accommodates this at no charge: the holder of the hidden object sends the best advice, together with a sign bit. P
Theorem 5.5 (EFI security). With probability one over {Hλ }, the ensembles {ρ0,λ }, {ρ1,λ } form an EFI pair relative to O. They are secure against every QPT distinguisher that has the public source R, adaptive classical access to Count, and classical advice of any polynomial length depending arbitrarily on the fixed oracle. Proof. Efficient generation and farness are immediate: G(1λ , b) calls R(b, 1λ ), and ρ0,λ ρ1,λ = 0 gives TD = 1. For indistinguishability there is one point to arrange. Corollary 5.3 bounds an expected advantage over the random subspaces, whereas Lemma 5.4 needs that expectation for each member of a countable family. Producing such a family, and bounding its expectations, is all that is left to do. To begin, fix a finite universal gate set and replace each machine’s gates by approximations over it, which by the Solovay–Kitaev theorem costs only polynomial overhead. Up to a negligible change in advantage, every QPT machine is then captured by a countable family {Ni } of oracle machines with explicit polynomial bounds ti (λ) on running time, advice length, sample calls, and transcript length. Fix such a machine Ni and let Adv∗Ni (λ; H) denote the best-advice advantage, the maximum over advice strings of length ≤ ti (λ). We will show that its expectation over H is 2−Ω(λ) . Place Ni in the two-party game of Theorem 3.2 at security parameter λ, with Alice running the machine and Bob holding Hλ , and write L for the length of the resulting transcript of classical Count queries and answers. Subspaces at other security parameters are independent of the challenge, so Alice and Bob sample those from shared public randomness at no cost, which makes every Hλ independent resource public. Bob then sends the maximizing advice string, at a cost of a ≤ ti (λ) bits; the sign bit that converts the two-sided advantage into a one-sided one is the orientation bit already charged inside Lemma 5.2. What results is a strategy of the kind Corollary 5.3 bounds, with q ≤ ti (λ) reference copies per side and L + a ≤ 2ti (λ) bits of interaction, so that its budget there is L + a + 1 ≤ 2ti (λ) + 1. Hence, with n = 2Ω(λ) , 2ti µi (λ) := EH Adv∗Ni (λ) ≤ +C n
41
s
2ti + 2 = 2−Ω(λ) . (n − 2ti )1/3
That is the hypothesis of Lemma 5.4, with X = H, and the lemma supplies the rest: a probabilityone set of sequences {Hλ } on which every Ni , with whatever advice, has negligible advantage. Theorem 5.6 (The separation in the source model). There is an oracle O = (R, Count), consisting of a sample-access state source and a Boolean counting oracle, such that (i) one-way puzzles, including inefficiently verifiable and classically-secure ones, do not exist relative to O, and neither do QEFID pairs; and (ii) the half-subspace pair (ρ0,λ , ρ1,λ ) is a secure EFI pair relative to O against every non-uniform QPT distinguisher that calls R polynomially many times, makes poly(λ) adaptive classical queries to Count, then makes one coherent query to Count of width 2poly(λ) , and receives poly(λ) bits of classical advice depending arbitrarily on the fixed oracle. Proof. (i) OWPuzzs fail for every fixing by Theorem 4.9, as do QEFID pairs by Corollary 4.12. (ii) EFI security in the stated access model holds on a probability-one set of fixings. Without the final coherent query this is Theorem 5.5, which we proved above. With that query it is Corollary 6.16, whose proof we defer to Section 6.5, since it needs the one-query bounds of Section 6. Choosing a fixing in the intersection, which again has probability one, gives an oracle for which both parts hold. Part (ii) permits at most one coherent query to Count, so this is a separation in the classicalquery model (Model 1.1) extended by a single coherent query, and the fully coherent case is Conjecture 8.2. Theorem 5.6 is an intermediate statement rather than the final one: its oracle still contains the state source R. Section 7 replaces R by a Boolean function, leaving the access model unchanged, and the resulting Theorem 7.2 is the main separation of the paper and the formal form of Theorem A. Quantum advice. Theorem 3.2 charges classical advice to the transcript. Quantum advice has no counterpart there, since it corresponds to a one-way quantum message from the holder of H, so two separate theorems cover it instead. Corollary 6.10 rules out poly(λ) qubits of arbitrarily Hdependent advice against a holder of one challenge copy; it does so by converting the advice into a single Boolean phase query, through Rosenthal’s synthesis [Ros24], and then applying Theorem 6.6. Corollary 6.18, meanwhile, admits O(λ) qubits alongside the full classical budget of Model 6.12, by charging a net of advice states to that budget. What is left over is polynomial-size quantum advice together with classical queries, and under the same conversion that becomes a coherent query placed before the classical ones, which is precisely the ordering Section 6.5 identifies as the limit of the method. The natural limit of the question is one-way quantum communication for VSP from the holder of H to a holder of the classical u, and that is settled at Θ(n) by Proposition 6.11. It is a different model from the one our advice statements need, and much stronger than anything we use here.
5.3
The optimal advantage of a classical adversary
Theorem 5.5 gives advantage 2−Ω(λ) , and it is natural to ask whether the pair is in fact perfectly hidden from Count. It is not, and for the natural class of classical attacks we can determine the rate exactly. The following fixes it at n−1/2 from both sides. Model 5.7 (Measure-then-count adversary). The adversary fixes a finite POVM {Ek }k∈K on Cn , of any size and not depending on H, measures its single challenge copy with it, and outputs a 42
bit computed from the outcome k together with the exact values {Tr(Ek′ PH )}k′ ∈K . No reference copies are used, and no bound is placed on the post-processing. The values in Model 5.7 are a relaxation of what Count provides: for an efficiently implementable POVM, the sampler that calls R(0, 1λ ), measures, and outputs the label k has output probability 2 n Tr(Ek PH ), so Lemma 4.6 returns its bits. Proposition 5.8 (The exact advantage of a measure-then-count adversary). Let H ⊆ Rn be Haarrandom of dimension n/2, with n ≥ 4. √ (i) (Upper bound, every POVM.) Every measure-then-count adversary has EH [Adv] ≤ 2/ πn. (ii) (Lower bound, one basis and poly(λ) queries.) Put t = 2⌈log2 n⌉ + λ. There is an adversary achieving q EH [Adv] ≥ 2(πn)−1/2 1 − 2/n − 4n−1 2−λ , namely the one that measures its challenge in the computational basis to obtain j, queries Count for the first t bits of Pr[R(0, 1λ ) measured in the computational basis = j], and outputs 1 if that truncation is below n1 − 2−t . Apart from the single computational-basis measurement of its challenge it is classical polynomial time, and it makes t = poly(λ) classical queries, since log2 n = poly(λ) for any source a QPT algorithm can call. In particular the two bounds coincide asymptotically: the exact rate is 2(πn)−1/2 1 +p O(n−1 ) , attained by the computational basis. Of the two deficits in the lower bound, the factor 1 − 2/n contributes O(n−1 ) relatively and the finite precision contributes O(2−λ n−1/2 ), which at n = 2λ is O(n−3/2 ), so the first of them is what the rate records.
Both parts rest on one computation, the mean absolute deviation of a single diagonal entry of PH about its mean 21 : the upper bound sums it over the eigenvectors of an arbitrary POVM, and the lower bound realizes it in the computational basis. That computation is a Beta-integral, and it and the finite-precision accounting are the whole of the proof; both are in Appendix B.1. Corollary 5.9 (A protocol of logarithmic length). For even n ≥ 4, β n, ⌈log2 n⌉ + 1 ≥ (2πn)−1/2 : Alice sends the index j drawn with probability u2j , and Bob replies with 1[(PH )jj < 21 ].
Proof. Alice’s sampling step is exactly the computational-basis measurement of the challenge, carried out on her classical description of it. Indeed, for u uniform on the unit sphere of H, E[u2j ] =
2(PH )jj , n
and symmetrically in H ⊥ . So the index j she sends has the law of the outcome in Proposition 5.8(ii). Bob, holding H, then applies the exact rule 1[(PH )jj < 12 ] rather than a truncation of it, and the protocol reproduces that distinguisher with no loss to finite precision. One factor of two separates the two statements. Part (ii) computes the distinguishing advantage of the exact rule as 2 EH |ξe1 |, whereas the advantage of a protocol is half of that: the former measures the gap between the two branches, the latter the excess of the success probability over 12 . The advantage here is thus EH |ξe1 |, which is at least (2πn)−1/2 by Lemma B.1(a). Alice sends an index in [n] and Bob a single bit, so the transcript carries ⌈log2 n⌉ + 1 bits, as claimed.
43
Three consequences follow, on the dimension, on the security level, and on how much the oracle is worth. First, the dimension must be superpolynomial. By Proposition 5.8(ii) a classical adversary making O(λ) queries already distinguishes the pair with advantage Ω(n−1/2 ), so negligible security forces n−1/2 = negl(λ), that is, n = λω(1) . Our choice n = 2Θ(λ) is one convenient point in that range, and the proofs use nothing else about it. Indeed, every bound in this paper is negligible as soon as n is superpolynomial. Second, the security level is 2−Θ(λ) , and the exponent is the quantity at stake. Theorem 5.5 proves O(poly(λ) · n−1/6 ), the polynomial collecting the adversary’s own parameters together with the factor its Markov step charges for passing from the expectation to the fixed oracle, and Proposition 5.8 exhibits Ω(n−1/2 ). Both are 2−Θ(λ) , so the separation itself is unaffected. The residual gap does not come from the imported bound. A worst-case communication bound of Ω(nα ) enters Theorem 5.5 only through Lemma 2.7, whose amplification step costs a square root and returns √ O( L n−α/2 ). Matching Proposition 5.8 would require α = 1, and that is impossible, since Raz’s √ √ protocol decides VSPn with O( n) bits [Raz99; Mon19]. Even the optimal worst-case bound Θ( n) would give only n−1/4 . The gap is thus a feature of the route rather than of the pair, and it can be closed by leaving the route: Appendix D bounds the same adversaries by poly(λ) · n−1/2 , using the linearity of ρ0 − ρ1 in RH in place of any communication bound. What would close it within the communication route is a direct estimate of β(n, L) in the small-advantage regime. Proposition 5.10 supplies such an estimate for one-way protocols, linear in the message length, and Corollary 5.11 handles the two-way case for very short transcripts. The general two-way question remains open, and Section 9 returns to it as a question about VSP rather than as one this construction needs. Third, the counting oracle is worth a single bit of information about H. Lemma 6.5 shows that a single [−1, 1]-valued function of H correlates with RH at scale n−1/2 , and Proposition 5.8(i) shows that granting the adversary the exact value of every outcome probability of an arbitrary measurement does not exceed that scale. The same n−1/2 recurs in Section 6 as the value of one coherent query, and it is attained there as well: Corollary 6.7 turns the attack of part (ii) into a √ one-query adversary meeting Theorem 6.6 to within log n.
5.4
The one-way rate for VSPn
√ Proposition 5.8 bounds every measure-then-count adversary by 2/ πn with no bound on what it is told, but its adversary holds one quantum copy of the challenge, whereas Alice in Definition 2.5 holds u as classical data and is strictly stronger (Section 6.4); at unbounded message length she can send u itself and decide with certainty. The next proposition bounds the one-way rate for the classical-input sender. Proposition 5.10 (The one-way rate for VSPn ). Let βow (n, L) be the maximum advantage on the VSPn distribution over one-way protocols with shared randomness [KNR99], in which Alice, holding the classical description of u, sends a single message of at most L bits and Bob, holding H, announces the guess. Then, for even n ≥ 4, there is a universal C with √
1 ≤ βow n, ⌈log2 n⌉ + 1 , 2πn
L+1 βow (n, L) ≤ C √ n
for all L ≥ 0.
Consequently the one-way randomized communication complexity of VSPn at constant advantage is √ √ Θ( n): the bounds above give Ω( n), and the upper bound is Raz’s one-way protocol [Raz99], whose first published proof is [Mon19, App. A] and for which Gosset and Smolin give a computationally efficient alternative [GS19]. The constant-advantage threshold is not new; see Section 5.4. What 44
the display adds is an upper bound at every message length, linear in L, on the exact promise and the Haar distribution. The lower bound is Corollary 5.9, whose protocol is one-way. We prove the upper bound in Appendix B, which also collects the harmonic analysis on the sphere that it uses. Here we describe only the mechanism, deferring the two estimates that carry it. Fix the shared randomness, so that the protocol is deterministic and Alice’s message realizes a partition {Am } of the sphere S n−1 into at most 2L+1 cells. Write µH := νH − νH ⊥ for the difference of the uniform probability measures on the unit spheres of H and H ⊥ . Since the two challenge distributions have the same marginal on H and differ only in which of νH , νH ⊥ produces u, Bob’s optimal decision given the cell Am has advantage governed by |µH (Am )|, and the whole quantity to P bound is EH m |µH (Am )|. So the question is how much a single cell of the sphere can distinguish the two spheres, and how those contributions add up over a partition. For one cell the answer comes from a second-moment computation. The operator behind R EH [( f dµH )2 ] is diagonalized exactly in Lemma B.2 by the spherical harmonics, and its eigen1 value at degree two is n−1 , with the higher degrees decaying rapidly. An indicator of measure α has 2 2 weight O α ln (e/α) at degree two, by a level-ℓ inequality on the sphere of Lemma B.3, proved there in the style of the Boolean-cube inequalities of harmonic analysis, so a single cell of measure √ α contributes O(α ln(e/α)/ n). Summing over cells is then an entropy bound. The measures αm of the cells sum to 1, so P L+1 parts. The depenm αm ln(e/αm ) is an entropy and is at most O(L) for a partition into 2 dence on the message length is linear for this reason. What we have to control in addition is the contribution of the higher degrees. That is a tail, and for small cells it must be suppressed; Lemma B.4 does this, and Appendix B.5 combines the two ranges of cell size. For two-way protocols the same second-moment computation gives a bound that is strong only for very short transcripts. Corollary 5.11 (Two-way protocols with very short transcripts). For even n ≥ 4 there is a √ universal C > 0 with β(n, L) ≤ C 2L/2 / n for every L ≥ 0. Proof. Write γ for the law of H, the rotation-invariant measure on the Grassmannian Gr. Fix the shared randomness, so that the protocol is deterministic, and let {At × Bt } be the rectangles into which its transcripts partition S n−1 × Gr, of which there are K ≤ 2L+1 (Section 2.6). On each transcript the output is a fixed bit, and the two challenge branches contribute masses 1 1 2 EH [1Bt (H)νH (At )] and 2 EH [1Bt (H)νH ⊥ (At )] to it, so answering optimally on each transcript gives X β ≤ 14 EH 1Bt (H) µH (At ) . (8) t
Consider a single rectangle first. Lemma B.2 with Parseval and ω2j ≤ ω2 = EH [µH (A)2 ] ≤ 4ω2 σ(A), so Cauchy–Schwarz in H gives EH 1Bt (H) µH (At )
≤
q
γ(Bt )
q
EH µH (At )2
≤ √
1 n−1
gives
q 2 γ(Bt ) σ(At ). n−1
p √ Discarding γ(Bt )σ(At ) ≤ 1 and summing over the K transcripts already gives β ≤ 2L / n − 1, but the factor 2L is spurious. It would be paid only if every rectangle were as large as the whole P space, whereas the At × Bt partition that space and so t σ(At )γ(Bt ) = 1. Our remedy is to keep the two measures instead of discarding them.
45
Cauchy–Schwarz over the K transcripts then gives t γ(Bt )σ(At ) ≤ this and the previous display into (8), √ K 2(L+1)/2 β ≤ √ ≤ √ , 2 n−1 2 n−1 P p
√
K, and substituting
as claimed. The two bounds available for two-way protocols are complementary. The second-moment bound of Corollary 5.11 is the stronger for L ≤ 23 log2 n, and the corruption bound of Lemma 2.7 beyond that. √ Prior work on the constant-advantage bound. An Ω( n) lower bound for one-way protocols at constant advantage is already known, by a reduction that Gosset and Smolin record and attribute to Kothari [GS19, §1]. The 14 -Partial Matching problem, a variant of the Hidden Matching problem √ introduced in [BJK04], has one-way classical complexity Θ( n) [Gav+07], and its instances embed P into VSPn as a state |ψ⟩ = n−1/2 i (−1)xi |i⟩ together with a projector Π built from Bob’s matching, for which ⟨ψ|Π|ψ⟩ takes the two values 41 and 34 . That reduction differs in two ways from what Proposition 5.10 proves. First, its instances are gapped, with ⟨ψ|Π|ψ⟩ bounded away from 0 and from 1, so the bound is for a promise strictly weaker than the exact one of Definition 2.5. Since exact instances satisfy any gapped promise, a lower bound on the exact problem is the stronger of the two. Second, the hard instances are the structured ones inherited from Partial Matching, and not the rotation-invariant distribution of Definition 2.5, which is the distribution the security proof requires. What Proposition 5.10 contributes is the √ rate O((L + 1)/ n) at every message length, for the exact promise and on the Haar distribution. The reduction above gives the constant-advantage endpoint for the gapped promise; since exact instances satisfy that promise, it does not by itself give the endpoint for Definition 2.5. √ √ Relation to the Ω( n) program for VSP. That VSPn should require Ω( n) bits, matching √ 1/3 n −c in place of e−cn , in Raz, is an established target. Klartag and Regev suggest the rate e a form using the arithmetic mean of νH (A) and p νH ⊥ (A), and Grupel [Gru17, §1] sharpens this to a conjecture√ in which the geometric mean νH (A)ν H ⊥ (A) is at least 0.9 σ(A) except with ′√ probability e−c n , for every A of measure at least e−c n . The geometric mean is the essential change here. The spherical cap that makes the Klartag–Regev rate tight satisfies the geometric √ form, so the conjecture escapes the very example behind their assessment that Ω( n) is “probably √ impossible using the rectangle bound”. Grupel proves the conjecture for sets depending on O( n) √ √ coordinates, and deduces Ω( n) for two-way protocols of total rank O( n), the rank counting the linear functionals of Alice’s input that the protocol evaluates; a variant of Raz’s protocol lies in that class [Gru17, Thm. 1.2, Cor. 1.3]. The conjecture itself remains open. Proposition 5.10 is incomparable to that result, and it does not require the conjecture. It places no rank restriction on Alice, whose message induces an arbitrary measurable partition, so the total rank of an L-bit one-way protocol may be as large as Ln. What replaces the conjecture is a weaker demand on the concentration statement. The rectangle method needs each cell to be atypical with probability below 2−L , which forces a high-probability statement. A one-way protocol, by contrast, P is charged m EH |µH (Am )|, a first moment over cells, and for that a second-moment computation suffices; Lemma B.2 performs it exactly. High-probability concentration is an artifact of interaction rather than of the geometry, and the same observation places Corollary 5.11 at the limit of what a per-rectangle second moment yields. Neither Klartag and Regev [KR11] nor Grupel [Gru17] treats the small-advantage regime, which is the one the security proof uses. 46
6
Coherent queries
The main theorem queries Count classically, which is what makes the communication argument available: that argument charges the adversary for the classical bits it exchanges with the oracle, and a superposition query is not a classical message. We now ask how much survives under coherent access. Throughout this section H ⊆ Cn is Haar-random of dimension n/2, and we write P = PH , R = 2P − I and ∆ = R/n. In the representation R = U DU † we take the conjugating unitary Haar on SU(n) rather than on U(n), which changes nothing, as Lemma 6.3 below records, and which is what the concentration inequality of Section 6.1 requires. The arguments transfer to the real ensemble of the main construction with a change of universal constant, with SO(n) in place of SU(n), since the bounds below use only that R = U DU † for U Haar on a group of curvature Ω(n) and D a fixed traceless involution. Advantage is measured as the bias (4), half the distinguishing advantage. The adversary of Section 6.3 holds one challenge copy and no reference copies, and we treat the full EFI game in Section 6.5. One point about the model has to be settled before the estimates begin. An oracle returning an exact real value in superposition is unsafe. Write vx (P ) for the real number such an oracle returns at the query label x when the hidden projector is P , and suppose, as the counting oracle would, that these values include the matrix entries of P . Querying the uniform superposition of labels P produces the state |ΦP ⟩ = M −1/2 x |x⟩|vx (P )⟩, and for two distinct projectors drawn from the ensemble the values differ at every label almost surely, so the corresponding states are orthogonal. One coherent query would then write an exact record of the hidden subspace. Of course that model is an idealization: a register holding an exact real, with orthogonal states for distinct values, spans a non-separable Hilbert space. Rounding to any finite precision returns a Boolean oracle of width 2poly(λ) , and Theorem 6.6 covers that, since it holds for every Boolean function of H.
6.1
Concentration of measure on the classical compact groups
This subsection collects the probabilistic input, in the order in which the proof needs it: first the elementary scalar fact, which already settles a special case and fixes the scale of every estimate below, then the matrix statement, which the maximum over truth tables requires. Both rest on the same classical fact, that Lipschitz functions on a compact group of large curvature concentrate. In the Hilbert–Schmidt metric, [Mec19, Thm. 5.17] gives, uniformly for SO(n), SU(n), U(n) and Sp(2n), 2
2
Pr F ≥ EF + t ≤ e−(n−2)t /(24 Lip(F ) )
(9)
for every Lipschitz F ; applying this to F and to −F , which has the same Lipschitz constant, yields 2 2 the two-sided bound Pr[|F − EF | ≥ t] ≤ 2e−(n−2)t /(24 Lip(F ) ) that we quote below. The scale n−1/2 in (9) is the source of every n−1/2 in this section. Lemma 6.1 (A single linear statistic). Let R = U DU † with U Haar on SU(n) or SO(n) and D a fixed Hermitian involution with Tr D = 0. For a fixed Hermitian matrix A write XA := n1 Tr(AR). Then EXA = 0, the map U 7→ XA is Lipschitz with constant 2 ∥A∥2 /n in the Hilbert–Schmidt metric, and XA is subgaussian with variance proxy O(∥A∥22 /n3 ). Consequently, for any family of √ at most N fixed matrices A with ∥A∥2 ≤ n, E max |XA | = O A
47
plog(2N )
n
.
Proof. First, EXA = 0. Indeed, Haar measure is invariant under translation, so ER is unchanged by conjugation by any element of the group. The standard representation of SU(n) on Cn , and of SO(n) on Rn , is irreducible, so ER must be a multiple of the identity; and its trace is Tr D = 0, whence ER = 0. Next we bound the Lipschitz constant, from which the variance proxy will follow. Cauchy– Schwarz in the Hilbert–Schmidt inner product, and then ∥D∥op ≤ 1, give |XA (U ) − XA (U ′ )| ≤
1 n ∥A∥2
U DU † − U ′ DU ′†
2
≤
2 n ∥A∥2
U − U′ 2 ,
the last step by writing U DU † − U ′ DU ′† = (U − U ′ )DU † + U ′ D(U − U ′ )† . Substituting this into (9) gives the stated variance proxy, the factor n − 2 in the exponent there supplying the third power of n. √ Finally, we take the maximum over the family. Under the hypothesis ∥A∥2 ≤ n every member has variance proxy O(n−2 ), so the maximal inequality for subgaussian variables, applied to these at most N variables, gives the last display. Lemma 6.1 already handles one regime completely. By (4) the bias ofpany adversary, at any √ number of queries, is n1 | Tr(Ef R)| for an effect Ef on Cn , and ∥Ef ∥2 ≤ Tr Ef ≤ n. Taking √ N = 2M in the lemma bounds the maximum over all 2M truth tables by O( M /n), which is negligible whenever M = O(n2−ε ). The difficulty lies at large width, a point to which Section 8 returns. At the widths our model forces, M is far larger than n2 and this estimate is useless, so the maximum over truth tables must be taken by a means other than a union bound. The standard means is an operator norm: a maximum of 2M quadratic forms sharing one coefficient matrix costs only the norm of that matrix. What we then need is a bound on the expected operator norm of a random matrix whose entries are linear statistics of R. In the classical setting, where the randomness consists of independent signs, this is matrix Khintchine: for fixed Hermitian d × d matrices A1 , . . . , Ak and independent Rademacher εi , E∥
q
i εi Ai ∥op ≤ Cσ log(2d),
P
σ2 =
2 i Ai op ,
P
(10)
√ √ so the operator norm costs only a log factor over the variance parameter, rather than the k that a union bound over sign patterns would give. Our randomness is a single Haar-conjugated reflection and provides no independence, so (10) does not apply and we prove the analogue we need in Section 6.2. What replaces independence is curvature. The reason (9) holds is that the special groups SO(n) and SU(n) have Ricci curvature of order n, and U(n) inherits the inequality from SU(n) by Lemma 6.3, so that Haar measure satisfies a logarithmic Sobolev inequality by the Bakry–Émery criterion. Huang and Tropp [HT21] show that the same hypothesis yields concentration for matrixvalued functions, with the variance parameter of (10) replaced by a sum of squared derivatives along an orthonormal frame. Proposition 6.2 (Matrix concentration under a curvature lower bound; Huang–Tropp [HT21, Thm. 1.1 of the arXiv version]). Let M be a compact Riemannian submanifold of Euclidean space whose Ricci curvature is bounded below by ρ > 0, let µ be the uniform measure on M, let {∂i } be an orthonormal frame, and let F : M → Hermd be differentiable with Eµ F = 0. Put vF = P 2 supx∈M i (∂i F (x)) op . Then, for a universal constant C > 0, (i) Prµ ∥F ∥op ≥ t
2
≤ 2d e−ρt /(2vF ) for every t ≥ 0; and consequently 48
s
(ii) Eµ ∥F ∥op ≤ C
vF log(2d) . ρ
Part (ii) is the p standard conversion of a subgaussian tail into a moment bound: integrate (i) and cut at t0 = 2vpF log(2d)/ρ, where the exponential factor absorbs the dimension 2d, leaving a remainder of order vF /ρ that t0 dominates. By [Mec19, Prop. 5.13], in the Hilbert–Schmidt metric the Ricci curvature is exactly n−2 4 on SO(n) and n2 on SU(n), so in both cases ρ = Ω(n) and Proposition 6.2 reads s
E ∥F ∥op ≤ C
vF log(2d) , n
vF = sup
2 i (∂i F (x)) op
P
x∈M
as in Proposition 6.2.
(11)
Applying Proposition 6.2 to our ensemble requires care on two points, and the structure of the hidden reflection resolves both. Lemma 6.3 (Reduction to SU(n) and SO(n)). Let D be a fixed diagonal ±1 matrix with Tr D = 0. Then U DU † has the same law when U is Haar on U(n) as when U is Haar on SU(n). Likewise QDQ⊤ has the same law when Q is Haar on O(n) as when Q is Haar on SO(n). Proof. Consider first the unitary case. Every U ∈ U(n) is eiθ V with V ∈ SU(n), and the central phase cancels in the conjugation, so the law of U DU † is a conjugation-invariant probability measure on the orbit {V DV † : V ∈ SU(n)}. Since SU(n) acts transitively on that orbit, such a measure is unique, and both Haar measures induce it. Consider next the orthogonal case. Here O(n) is the disjoint union of SO(n) and SO(n)J, where J = diag(−1, 1, . . . , 1); as D is diagonal it commutes with J, so (Q′ J)D(Q′ J)⊤ = Q′ DQ′⊤ . The two components induce the same law, as claimed. We need the reduction for two reasons. First, U(n) has a one-dimensional center, along which the Ricci curvature vanishes, so that Proposition 6.2 does not apply to U(n) directly. Second, and more awkwardly, O(n) is disconnected, so it is not a connected Riemannian manifold. Lemma 6.3 transfers both questions to SU(n) and SO(n), where the curvature hypothesis holds. For the scalar statements we need no such reduction, since (9) covers all four families uniformly. The second point concerns the choice of frame. Its index is written a throughout this section and the next, where it is the only meaning that letter carries; the advice length of Model 6.12, d also written a, appears in neither. On SU(n) an orthonormal frame is ∂a F (U ) = dt F (U eitKa )|t=0 2 −1 for {Ka }na=1 an orthonormal basis of traceless Hermitian matrices, and on SO(n) it is ∂a F (Q) = d tX a )| F (Qe t=0 for {Xa } an orthonormal basis of real antisymmetric matrices. In both cases the dt only property we use is the derivative bound (12) below, and its proof is insensitive to which of the √ two frames is used. On SU(n) the direction omitted relative to a full basis of Hermn is K = I/ n, which contributes nothing since [I, D] = 0, and on SO(n) Parseval over the antisymmetric subspace only decreases the sum. So we write the argument once, on SU(n).
6.2
A variance bound for linear statistics of a Haar-conjugated observable
Lemma 6.4 (Matrix concentration for linear statistics of R). Let R = U DU † with U Haar on SU(n), D = D† diagonal, Tr D = 0, ∥D∥op ≤ 1. Let Bxy ∈ Cn×n , x, y ∈ [M ], satisfy sup
∥α∥2 =1
sup
∥β∥2 =1
X X x
y
X X y
2
αy Bxy
2 2
βx Bxy
x
49
2
≤ b2 ,
(Row)
≤ b2 .
(Col)
Define the M × M random matrix Yxy = Tr(Bxy R/n). Then E ∥Y ∥op ≤ C b n−3/2 log(2M ) for a universal C. p
The two hypotheses are the analogue of the variance parameter σ 2 in (10): they say that the coefficient matrices, viewed as a map on the index set, do not amplify a unit vector by more than b in Hilbert–Schmidt norm, in either of the two directions. The conclusion has the same shape as (10), with b n−3/2 in the role of σ; the factor n−3/2 is the one already visible in Lemma 6.1, and the content of the lemma is that p passing from a single linear statistic to the operator norm of a whole matrix of them costs only log(2M ). We should be precise about the attribution here. The concentration is entirely Huang–Tropp’s: Proposition 6.2 is a matrix inequality that already dispenses with independence, asking curvature of it instead, and [HT21, Ex. 3.11 of the arXiv version] already instantiates it for a Haar-conjugated fixed symmetric matrix on SO(d), computing the variance proxy through the carré du champ. The Hermitian dilation we use to reach a non-Hermitian Y is also due to them. What Lemma 6.4 adds is the variance proxy in the shape the relaxation of Section 6.3 consumes. Their example is a d × d function of d × d data; ours is an M × M matrix, with M as large as P 2 2poly(λ) , whose entries are linear statistics of one n × n conjugation. Bounding a (∂a Y) op for that object is what the row and column hypotheses (Row)pand (Col) are for, and it is the step that lets a maximum over 2M truth tables be paid for at rate log(2M ). Two features of the statement matter later, and the half-subspace ensemble plays no part in either. It does not need D to be a reflection: the hypotheses ask only that D be Hermitian and traceless with ∥D∥op ≤ 1, so the bound applies verbatim to a Haar-conjugated projector. It also transfers to SO(n), by the reduction recorded at the start of Section 6. Proof. Everything here rests on one elementary fact: the map K 7→ i[K, D] has Hilbert–Schmidt operator norm at most 2 ∥D∥op . The rest of the argument carries that fact through the dilation and through the row and column sums. To begin, we put Y into the form Proposition 6.2 accepts. That proposition applies to Hermitian-matrix-valued functions of mean zero, and Y is neither, so we pass to its Hermitian dilation ! 0 Y Y := , Y† 0 which satisfies ∥Y∥op = ∥Y ∥op and lives in dimension 2M . Its mean vanishes, because ER = 0 as in Lemma 6.1, and hence EY = 0. 2 −1 Now we differentiate along the frame. Let {Ka }na=1 be the orthonormal basis of traceless Hermitian matrices fixed in Section 6.1. Differentiating R = U eitKa De−itKa U † at t = 0 gives ∂a R = U i[Ka , D] U † , so (∂a Y )xy = n1 Tr(Bxy U i[Ka , D] U † ). We will show that for any A ∈ Cn×n , X
Tr(A i[Ka , D])
2
≤ 4 ∥D∥2op ∥A∥22 ≤ 4 ∥A∥22 ,
(12)
a
which is the elementary fact above, in the form the frame delivers it. To see (12), note first that Tr(A i[Ka , D]) = Tr(Ka i[D, A]) by cyclicity. Write i[D, A] = S + iT with S and T Hermitian, √ and complete {Ka } to an orthonormal basis of Hermn by adjoining I/ n; that extra direction contributes nothing, since [I, D] = 0. Parseval in this basis then gives X
| Tr(Ka i[D, A])|2 = ∥S∥22 + ∥T ∥22 = ∥[D, A]∥22 ≤ (2 ∥D∥op ∥A∥2 )2 ,
a
which is (12). 50
That leaves the variance parameter. Bounding
a (∂a Y)
P 2 a (∂a Y) z⟩ op means bounding ⟨z, over unit vectors z of the doubled space, and we write such a z as a pair (u, v) with ∥u∥22 +∥v∥22 = 1. P
2
By the block form of the dilation,
⟨z, (∂a Y)2 z⟩ = ∥(∂a Y )v∥22 + (∂a Y )† u
2 2
,
so it suffices to bound a ∥(∂a Y )v∥22 by 4b2 n−2 ∥v∥22 . The calculation for the second summand is P identical, with (Col) in place of (Row), and we omit it. So fix v and set Gx := y vy Bxy . Then, by cyclicity of the trace, (∂a Y )v x = n1 Tr U † Gx U i[Ka , D] . P
Applying (12) with A = U † Gx U , and noting U † Gx U X
∥(∂a Y )v∥22 ≤
a
2
= ∥Gx ∥2 ,
2 4 X 4b2 4 X X 2 ≤ = ∥G ∥ v B ∥v∥22 x 2 y xy 2 n2 x n2 x n 2 y
2
by (Row). Hence a (∂a Y)2 ⪯ 4b I , so (11) with d = 2M and vY ≤ 4b2 /n2 gives the claim, the n2 2M log(4M ) that appears at d = 2M being at most 2 log(2M ). P
6.3
The one-query bound
First, the baseline against which the bound should be read. A single [−1, 1]-valued function of the hidden subspace, a single bounded statistic of H, already correlates with R at scale n−1/2 , and no more. Lemma 6.5 (Local correlation with the hidden reflection). For H ⊆ Cn Haar of dimension n/2 and any random variable s(H) ∈ [−1, 1], ∥EH [s(H)R]∥op ≤ (n + 1)−1/2 . Proof. Reduce the operator norm to a scalar second moment. The operator EH [s(H)R] is Hermitian, so its operator norm is attained on unit vectors: ∥EH [s(H)R]∥op = sup EH s(H) ⟨v|R|v⟩ .
∥v∥=1
So it is enough to bound the right-hand side at a single fixed v. Fix such a v. Since |s| ≤ 1, and then by Cauchy–Schwarz,
EH s(H) ⟨v|R|v⟩
≤ EH ⟨v|R|v⟩ ≤
q
2
EH ⟨v|R|v⟩ .
The weight s has now disappeared, and only the fluctuation of a single diagonal entry is left. Now we compute that second moment. By rotation invariance X := ⟨v|P |v⟩ is distributed as Beta(n/2, n/2), so ⟨v|R|v⟩ = 2X − 1 has mean 0 and variance 1/(n + 1), which gives the claim. We use the one-query normal form fixed in Section 2.4: an isometry W with branches Ax , a P phase query, and an effect Π with blocks Πxy . Expanding W ∆W † = x,y |x⟩⟨y| ⊗ Ax ∆A†y , the two copies of Df contribute fx fy , and tracing against Π picks out a block, so the bias (4) is ZH (f ) =
X
CH (x, y) = Tr Πxy Ay ∆A†x .
fx fy CH (x, y),
(13)
x,y
Each object enters in a different way: the adversary contributes the fixed data (Ax , Πxy ), the randomness of H enters ∆ linearly, and the unknown truth table appears only in the rank-one sign pattern fx fy . 51
Theorem 6.6 (One-query bound). There is a universal C > 0 such that for every isometry W and every effect 0 ⪯ Π ⪯ I, with M = |X | the width of the oracle, s
EH
max |ZH (f )| ≤ C
f ∈{±1}X
log(2M ) . n
Proof. Step 1: the bias is a quadratic form in the sign pattern whose coefficients are linear in R. This is the identity (13), established above together with the account of how each object enters it. We use nothing else about the algorithm below. Step 2: the maximum over the 2M sign patterns collapses to a single operator norm. The one general tool for a quadratic form is the operator norm, and applying it directly to (13) gives |f ⊤ CH f | ≤ ∥f ∥22 ∥CH ∥op = M ∥CH ∥op . The factor M is spurious. It would be paid only by an adversary able to place unit query weight on every label at once, whereas the completeness relation in (5) says that the total weight is 1. Our remedy is to change the normalization so that the sign vector becomes a unit vector. Recall from (6) the query mass τx = n1 Tr(A†x Ax ), a probability vector on X that depends on the adversary and not on H. Labels with τx = 0 have Ax = 0, and we discard them. Define the weighted coefficient matrix CH (x, y) GH (x, y) := √ , (14) τx τy 1/2
and rewrite (13) through the vector Dτ f , where Dτ = diag(τ ). That vector has norm exactly 1, since X X 2 Dτ1/2 f = τx fx2 = τx = 1, 2
x
x
which holds for every sign pattern f , because fx2 = 1. Hence for every H and every f , |ZH (f )| = (Dτ1/2 f )⊤ GH (Dτ1/2 f ) ≤ ∥GH ∥op ,
so
max |ZH (f )| ≤ ∥GH ∥op . f
We have therefore traded a maximum over 2M sign vectors for a single operator norm, of a matrix whose rows and columns are normalized by the adversary’s own query distribution. Neither the weighting nor the trade is new: both are due to Lombardi, Ma, and Wright, the weighting read here on query labels rather than on workspace basis vectors, and Section 1.3 makes the comparison precise. What Step 3 supplies is the variance computation that the concentration input of Proposition 6.2 asks for, in the shape this relaxation produces. Notice that after Step 2 the truth table has left the problem altogether, and all that remains is the expected operator norm of a single random matrix. p Step 3: that operator norm has expectation at most C log(2M )/n. By cyclicity the entries of GH are linear statistics of R:
GH (x, y) = Tr Bxy
R , n
Bxy :=
A†x Πxy Ay . √ τx τy
We verify (Row) with b = n; the verification of (Col) is identical, using Π†xy = Πyx , and is omitted. Three facts drive it: the masses normalize each branch, Tr(A†y Ay ) = nτy ; the measurement is a contraction, 0 ⪯ Π ⪯ I; and each branch has small operator norm relative to its mass, A†x
2 op
= A†x Ax
op
≤ Tr(A†x Ax ) = nτx ,
52
since A†x Ax ⪰ 0. α Fix α with ∥α∥2 = 1 and put Fy := √τyy Ay . Stack these into the single operator F :=
X
|y⟩ ⊗ Fy : Cn −→ CX ⊗ K,
so that
∥F ∥22 =
X
∥Fy ∥22 ,
y
y
the two norms agreeing because the |y⟩ are orthonormal. Multiplication by Π acts on F blockwise, P P ΠF = x |x⟩ ⊗ Γx with Γx := y Πxy Fy , and since ∥Π∥op ≤ 1 it does not increase the Hilbert– Schmidt norm. Hence X
∥Γx ∥22 = ∥ΠF ∥22 ≤ ∥F ∥22 =
X |αy |2 y
x
τy
Tr(A†y Ay ) =
X
|αy |2 n = n.
(15)
y
This is the only place where we use the contraction property ∥Π∥op ≤ 1. For each x we have P † √1 y αy Bxy = τx Ax Γx , so
X y
2
αy Bxy
2
=
2 1 A†x Γx ≤ 2 τx
Summing over x and applying (15) gives then gives the bound of the theorem,
x∥
P
EH ∥GH ∥op ≤ C
A†x τx
2 op
∥Γx ∥22 ≤ n ∥Γx ∥22 .
2 2 y αy Bxy ∥2 ≤ n , i.e. (Row) with b = n. Lemma 6.4
P
n q n3/2
s
log(2M ) = C
log(2M ) . n
We make two observations about the bound. First, n−1/2 is the right scale. A single Boolean bit of information about H correlates with R at scalepat most n−1/2 (Lemma 6.5), and the theorem says that a coherent query of width M loses only log(2M ) over that single-bit baseline. The quantity the proof bounds is genuinely of the size the theorem reports, although the relaxation of Step 2 need not be tight: at Π = I, K = C, Ax = ⟨ex | we have ∥GH ∥op = maxx |Rxx |, and each diagonal entry has mean absolute deviation of order n−1/2 by Lemma B.1. A union bound p over the n of them gives EH ∥GH ∥op = O( log n/n), while retaining the single term x = 1 gives EH ∥GH ∥op ≥ EH |R11 | = Ω(n−1/2 ), so EH ∥GH ∥op is of that size up to the logarithm. At Π = I, however, ZH (f ) = 0 for every f , so the norm can exceed the bias. The conclusion is tight too, and by an explicit attack rather than an extremal example, as Corollary 6.7 shows. Second, the adversary enters only through the normalizations in (Row) and (Col); we use no property of the branch operators beyond completeness. That is why the bound holds for the maximum over all truth tables, and why it composes over parallel queries at no cost. √ Corollary 6.7 (Theorem 6.6 is tight up to log n). Let n ≥ 4 be even. Then there are a Boolean function fH of width M = 2n and a one-query adversary, holding apsingle challenge copy, whose average bias is at least (4πn)−1/2 . Set this against the upper bound C log(4n)/n that Theorem 6.6 gives at that width. The statement holds both in the complex ensemble of this section and in the real ensemble of the main construction. Proof. Take fH (j) = 1[(PH )jj < 12 ] for j ∈ [n], a Boolean function of H and hence one of the truth tables Theorem 6.6 quantifies over. The adversary measures its challenge in the computational basis, obtaining j, queries fH at j, and outputs the answer. 53
This is the exact rule analyzed in Proposition 5.8(ii), whose average distinguishing advantage is 2 EH |ξe1 | and whose bias is therefore EH |ξe1 |, computed in whichever ensemble is in force. In the real ensemble Lemma B.1 bounds that quantity below by (2πn)−1/2 , through the left-hand inequality of (17); this is the one place where we use the hypothesis n ≥ 4. In the complex ensemble, EH |ξe1 | ≥
q
1 − 1/n (2πn)−1/2 ≥ (4πn)−1/2
for n ≥ 2. In both ensembles the bias is at least (4πn)−1/2 . The last thing to check is that the attack costs a single query in the model of Theorem 6.6. The adversary makes one bit-flip query, which is one phase query on a domain of size 2n by the conversion of Section 2.4. With the answer register prepared in |−⟩, the phase oracle for the truth table g(j,c) = (−1)c fH (j) on [n] × {0, 1} implements that query. The two Hadamard gates of the conversion do not depend on H, so we absorb them into W and Π. The width is M = 2n, as the statement says. So the n−1/2 scale in √ Theorem 6.6 is exactly right, and the only question is the log(2M ) factor, which at M = Θ(n) is log n. Corollary 6.7 also bears on the model. The extremal one-query adversary is elementary; it measures in the computational basis and asks one classical question, which is why Proposition 5.8 and Theorem 6.6 give the same rate. p
Corollary 6.8 (Parallel coherent queries). Consider an adversary that prepares a state from its challenge copy by an H-independent isometry, applies Df⊗t once for a truth table f of H, and then p measures. Every such adversary has average bias at most C (t log(2M ) + 1)/n. Consequently, for n = 2Ω(λ) , polynomially many parallel coherent queries of width 2poly(λ) give negligible bias. Proof. A t-fold parallel query is a single query to a wider oracle. Indeed, Df⊗t is the phase oracle on t
′ CX with truth table f(x = i fxi , another Boolean function of H, on a domain of size M t . A 1 ,...,xt ) t-parallel adversary is a one-query adversary against that oracle, so Theorem 6.6 applies with M t in place of M , and log(2M t ) ≤ t log(2M ) + 1, which is the stated bound. For polynomially many queries of polynomial width the quantity under the root has numerator poly(λ), while n = 2Ω(λ) , so the bound is negl(λ), which is the second assertion.
6.4
Q
Quantum advice
This subsection settles the question of quantum advice that Section 5.2 raised. We give two arguments, which serve different p purposes. The first is direct and sharp: it charges m qubits of advice √ at rate m/n rather than m/n, and so reaches m = n2−Ω(1) , which is optimal. The second routes the advice through Rosenthal’s one-query state synthesis [Ros24]; it is quantitatively weaker, but it is the statement that identifies advice with a query, as Section 8 requires. √ Proposition 6.9 (Advice is charged at rate m/n). Let V be a Hilbert space of dimension dA and let 0 ⪯ Π ⪯ I be any fixed, H-independent effect on V ⊗ Cn . Then 1 EH sup Tr Π (|σ⟩⟨σ| ⊗ R) ≤ C |σ⟩∈V, ∥σ∥=1 n
p
log(2dA ) n
for the universal constant C of Lemma 6.4. Consequently, a distinguisher of unbounded computational power that receives m qubits of advice depending arbitrarily √ on H, together with one challenge copy, and makes no oracle queries, has average bias at most C ′ m + 1/n. This is negl(λ) for every m = n2−Ω(1) . 54
Notice the order of the quantifiers: the supremum is over the entire unit sphere of V, so the bound holds for an arbitrary advice family {|σH ⟩} with no measurability or computability hypothesis, and no maximization is left to exchange with the expectation. Proof. Fix an orthonormal basis {|i⟩}K i=1 of V and write Πji := (⟨j| ⊗ I) Π (|i⟩ ⊗ I) for the blocks of Π, which are operators on Cn ; since Π is Hermitian, Π†ji = Πij . Writing |σ⟩ = P i ci |i⟩ and expanding the trace, Tr Π(|σ⟩⟨σ| ⊗ R) =
X
ci c̄j Tr(Πji R)
and so
1 n Tr
Π(|σ⟩⟨σ| ⊗ R) = ⟨c|Y |c⟩,
i,j
where Y is the K × K matrix with entries Yji := n1 Tr(Πji R). Two features of Y are what decide the proposition. First, it is Hermitian, because Tr(Πij R) = Tr(R† Π†ij ) = Tr(Πji R). Second, it does not depend on |σ⟩. The supremum over unit |σ⟩ is exactly ∥Y ∥op , and this identity holds pointwise in H, so that no maximization is left to exchange with the expectation. Contrast this with the alternative route, which would fix an advice family {|σH ⟩} and run a net over such families: that route needs a measurability hypothesis on the family, and it pays for the net. Here neither is required, and it remains only to bound EH ∥Y ∥op . Apply Lemma 6.4 with Bji = Πji on an index set of size K. Both of its hypotheses hold √ P with b = n. For (Row), fix α with ∥α∥2 = 1 and notice that i αi Πji = (⟨j| ⊗ I)Π(|α⟩ ⊗ I). Hilbert–Schmidt norms add over blocks, so X X j
i
αi Πji
2 2
= ∥Π(|α⟩ ⊗ I)∥22 =
∥Π(|α⟩ ⊗ |el ⟩)∥2 ≤
l=1
with equality at Π = I. For (Col), put |w⟩ = then X
n X
∥|α⟩ ⊗ |el ⟩∥2 = n,
l=1
j βj |j⟩, so that
P
2
n X
P
j βj Πji = (⟨w| ⊗ I)Π(|i⟩ ⊗ I), and
(⟨w| ⊗ I)Π(|i⟩ ⊗ I) 2 = ∥(⟨w| ⊗ I)Π∥22 = Tr (⟨w| ⊗ I)Π2 (|w⟩ ⊗ I) ≤ Tr In = n,
i
√ √ using Π2 ⪯ Π ⪯ I. With b = n on both sides, Lemma 6.4 gives EH ∥Y ∥op ≤ C n · p n−3/2 log(2dA ), which is the bound displayed in the statement. Now we charge m qubits of advice. A mixed m-qubit advice state has a purification on 2m qubits, and handing the receiver the purification only increases its power, so we may take V of p √ √ 2m dimension dA ≤ 2 and log(2dA ) = O( m + 1). Finally m/n = negl(λ) whenever m = n2−Ω(1) , since n = 2Ω(λ) . Tightness of the rate, and comparison with a coherent query. Both ends of Proposition 6.9 are attained. At m = 0 the bias of a fixed effect is O(n−1 ) by Lemma 6.1, which matches the bound. At the other end, m = Θ(n2 ), the advice can carry the index of the nearest point of a constantaccuracy net of the Grassmannian. Such a net has exp(O(n2 )) points, since the Grassmannian has P real dimension Θ(n2 ), and the effect Π = p |p⟩⟨p| ⊗ PHp then achieves bias at least 21 − δ for a net of constant accuracy δ. So m = O(n2 ) qubits suffice for constant bias, and Proposition 6.9 shows that this order is also necessary. Comparing with Theorem 6.6 explains the difference between the two rates. A coherent query p √ of width M is charged log(2M )/n, which is a factor n worse per bit of index than advice. The 55
whole difference sits in the row constant. Theorem 6.6 must pay A†x
2 op
≤ nτx , because a query
branch may concentrate the entire challenge on a single label, whereas an orthonormal advice basis admits no such concentration and pays only ∥Π∥op ≤ 1. In this sense a coherent query of width M is comparable to Θ(n log(2M )) qubits of advice: the two upper bounds coincide there, with a ratio √ of n between the row constants. That is why Corollary 6.10 below, which is obtained by turning advice into a query, is the weaker of the two statements. The identification of advice with a query is nevertheless needed in Section 8, so we state it. Corollary 6.10 (Security against quantum advice, via one-query synthesis). Let {σH } be an arbitrary family of poly(λ)-qubit states depending arbitrarily on H. Every distinguisher ( of unbounded computational power) that receives σH together with one challenge copy, and makes no oracle queries, has average bias negl(λ). Equivalently: VSPn resists polylog(n)-qubit one-way quantum advice from the holder of H to the holder of one copy of the challenge state, even against an unbounded receiver. Section 6.4 explains why that is not the same as the receiver of Definition 2.5. Proof. The idea is to trade the advice for a query. Rosenthal’s one-query state synthesis turns the advice state into one query to a Boolean function of H, after which the entire advice adversary sits in the normal form of Section 2.4. Theorem 6.6 then applies. It applies because that theorem maximizes over all truth tables and constrains the adversary only to be an isometry followed by an effect, so we need know nothing about how the truth table was produced. The synthesis is exact only up to an exp(− poly(λ)) error, and we charge that at the end. We may take σH pure: purifying can only increase the receiver’s power, and a purification of a poly(λ)-qubit state lives on poly(λ) qubits. Write |ψH ⟩ for it, on m = poly(λ) qubits. Step 1: the advice state is prepared by a fixed circuit making one query to a Boolean function of H. Pad the advice register with |0⟩ qubits so that m ≥ λ, which changes neither the state nor the receiver’s power, and fix the target error ε(m) = exp(−m) ≤ exp(−λ). By [Ros24, Thm. 4.1] there is a uniform sequence of poly(m)-qubit circuits (Cm ), each making one query to a classical oracle, with the following property: for every m-qubit state |ψ⟩ there is an oracle f|ψ⟩ such that f
the reduced state on the first m qubits of Cm|ψ⟩ |0 · · · 0⟩ is within ε(m) trace distance of ψ. The query register here holds poly(m) qubits, so the truth table queried has 2poly(m) entries, and it can carry far more information than the m qubits being prepared. The content of the theorem is that a single fixed circuit decodes it. We use four features of that statement, all of them explicit in [Ros24]. • The circuit Cm depends on ε, which we have fixed in advance, but not on |ψ⟩; only the oracle does. • The oracle may be taken to have a single output bit, queried as the phase oracle which is precisely our Df .
f (x) |x⟩⟨x|, x (−1)
P
• The guarantee is on the reduced state, so no condition is needed on the other registers. • The query register holds poly(m) qubits, so the domain has size M = 2poly(m) = 2poly(λ) . Apply this with |ψ⟩ = |ψH ⟩ and set fH := f|ψH ⟩ , a Boolean function of H, arbitrary, which is all Theorem 6.6 ever asks of it. After Step 1 the whole dependence on H has been moved into the truth table fH , and the circuit that prepares the advice is fixed. We still have to assemble that circuit and the distinguisher into a single adversary of the required shape.
56
Step 2: the advice distinguisher becomes a one-query adversary in the normal form of Section 2.4. Let B be the advice distinguisher, whose two-outcome measurement on the advice register together with the challenge may be arbitrary and even unbounded. Assemble it with Cm as follows. The pre-query isometry is W :=
pre-query part of Cm ⊗ Ichallenge ,
acting on fresh ancillas and leaving the challenge untouched. This is a legitimate isometry Cn → CX ⊗ K, with K holding the challenge together with Rosenthal’s ancillas, and its completeness relation is immediate, the challenge register being carried along unchanged. The single query is to DfH , and the final effect Π is the post-query part of Cm followed by B’s own measurement. Step 3: the bias is negligible, and the synthesis error costs only exp(− poly(λ)). The adversary just built has truth table fH and query width M , so by Theorem 6.6 its bias is at most s
C
log(2M ) = C n
s
poly(λ) = negl(λ), n
since n = 2Ω(λ) . By Step 1 the state it hands B is within exp(− poly(λ)) of σH in trace distance, so B’s own bias differs from that display by at most 2 exp(− poly(λ)), and is negligible as well. The VSP restatement is the same statement read through Definition 2.5. A one-way m-qubit message from the holder of H is such an advice state, and m = poly(λ) = polylog(n), which is the claim. The obvious protocol is consistent with the corollary. The holder of H sending t copies of ρ0 = 2PH /n uses t log n qubits, and a swap test of one of them against the challenge has signal 1/n, since Tr ρ20 = 2/n and Tr ρ0 ρ1 = 0. The receiver holds only one challenge copy, so it cannot √ e t)/n rather than t/n run t such tests independently, and the t copies together are worth Θ( (Proposition C.2); either way the bias is negligible for t = poly(λ). Advice against a challenge copy. Proposition 6.9 and Corollary 6.10 bound a receiver holding one quantum copy of ρb . In Definition 2.5, by contrast, Alice holds a classical description of u, from which she may prepare as many copies of |u⟩ as she likes and compute with u directly. That is the one-directionality noted in Section 3, and here it is strict: the two models separate, so neither statement bears on the classical-input model of Definition 2.5. To see the separation, let Bob send a description of one unit vector w ∈ H accurate to 1/n, at a cost of m = O(n log n) bits, and let Alice threshold |⟨u|w̃⟩| at n−3/4 . Suppose first that b = 1. Then u ∈ H ⊥ , so ⟨u|w⟩ = 0 exactly and |⟨u|w̃⟩| ≤ 1/n. Suppose instead that b = 0. Then u is uniform on the spherepof H, so ⟨u|w⟩ has the law of a coordinate of a uniform vector on S n/2−1 , of standard deviation 2/n; hence |⟨u|w⟩| ≥ 2n−3/4 except with probability O(n−1/4 ), and in that case |⟨u|w̃⟩| ≥ 2n−3/4 − 1/n > n−3/4 . Alice succeeds with probability 1√− o(1). At the same m, meanwhile, Proposition 6.9 caps a receiver holding one copy of ρb at pC n log n/n = o(1). So at m = O(n log n) the classical-input receiver is stronger by a factor Ω( n/ log n). The reverse direction is in fact settled, and at a much larger scale than a net argument gives. Proposition 6.11 (Reverse one-way communication for VSP is linear). Let n be even. Suppose Bob, holding a Haar-random half-dimensional H ⊆ Rn , sends Alice an m-qubit message, after which Alice, holding u and computationally unbounded, decides VSPn with advantage 31 on the distribution of Definition 2.5. Then m ≥ n2 1 − h2 ( 16 ) = Ω(n), where h2 is the binary entropy. Conversely O(n) classical bits suffice for constant advantage, so the complexity is Θ(n). 57
Proof. Worst case first. Advantage 13 means success 56 on average over Definition 2.5. Sample a Haar Q ∈ O(n) and a uniform bit c from public randomness, run the protocol on (Qu, QH) when c = 0 and on (Qu, QH ⊥ ) when c = 1, complementing the output in the second case. Bob can form QH or QH ⊥ from H and Q, and Alice can form Qu, so this is again a one-way protocol from Bob to Alice of the same length. Fix any promised pair (u, H) with u ∈ H. When c = 0 the pair (Qu, QH) has the law of Definition 2.5 conditioned on b = 0, since QH is Haar and, given it, Qu is uniform on its unit sphere; when c = 1 the pair (Qu, QH ⊥ ) has that law conditioned on b = 1. Averaging the two coins, the transformed protocol succeeds with probability exactly 65 on every promised input, and symmetrically for u ∈ H ⊥ . This is the symmetrization of Lemma 2.7, read in the present model. Then embed the index problem. Put d = n/2 and, for x ∈ {0, 1}d , let Hx = span{e2j−1+xj : j ∈ [d]}, a subspace of dimension d. For i ∈ [d] take ui = e2i−1 . Then ui ∈ Hx if xi = 0, and ui ∈ Hx⊥ if xi = 1, so each (ui , Hx ) is a promised input. Bob’s message on Hx therefore lets Alice recover any single bit xi of her choosing with probability at least 56 : it is a quantum random access encoding of d bits into m qubits. Then count. Let X be uniform on {0, 1}d , let C be the public randomness, independent of X, and let M be Bob’s message register. Holevo gives I(X : M | C) ≤ m. Since the Xi are P independent, the chain rule gives I(X : M | C) ≥ i I(Xi : M | C), and Fano bounds each term below by 1 − h2 ( 16 ). Hence m ≥ d (1 − h2 ( 16 )), which is the claim; the bound allows mixed encodings and arbitrary decoding measurements [Nay99]. The upper bound. Bob rounds a unit vector w ∈ H to a δ-net of the sphere at a fixed constant accuracy and sends its index, which is O(n) bits since such a net has eO(n) points. Alice accepts √ when |⟨u|w̃⟩| ≥ a/ n. If u ∈ H ⊥ then ⟨u|w⟩ = 0, so E|⟨u|w̃⟩|2 ≤ 2δ 2 /n and the false-positive probability is at most 2δ 2 /a2 by Chebyshev. If u ∈ H then ∥PH w̃∥ ≥ 1 − δ, and the smallball estimate for a uniform vector on the sphere of H bounds the false-negative probability by O(a/(1 − δ)). Choosing δ ≪ a ≪ 1 makes both errors small. So the reverse one-way question is not an obstacle. What our advice statements need is the one-copy model, and Proposition 6.9 settles that at m = Θ(n2 ); the two thresholds differ by the factor n that the separation above exhibits. One resource remains to be measured, and the security proof does not need it, since Lemma 5.2 charges the adversary the classical spans of its copies rather than the copies themselves. The most natural advice about H is a supply of fresh samples of the b = 0 state, and those accumulate as a random walk: each copy couples to the challenge only through a swap, and each swap shifts the e √q)/n rather than q/n, mean by 2/n against a fluctuation of unit size. So q of them are worth Θ( both as an attack and as an upper bound (Proposition C.2, stated and proved in Appendix C.2). Two things follow. A classical description of the span of the same q vectors achieves 2q/n for q ≤ n/2, so classical knowledge of the reference states is quadratically stronger than the states themselves; that measures how much the passage to spans in Lemma 5.2 concedes. At m = q⌈log2 n⌉ √ advice qubits the walk attains the m rate of Proposition 6.9 up to logarithms, by the most elementary advice available, so that rate is tight in the interior of its range as well as at its endpoints.
6.5
Classical queries followed by one coherent query
Theorem 5.5 and Theorem 6.6 bound two incomparable access modes by different methods. We combine them into a single statement containing both: security against an adversary that makes its full adaptive-classical budget of Count-queries and then, as its final oracle interaction, one coherent 58
query. This also closes a gap in the scope of Theorem 6.6, which assumed no reference copies while the EFI game always provides them. The composition works because the relaxed one-query norm of Theorem 6.6 is a Lipschitz function of the Haar unitary defining R, and hence concentrated. The classical transcript conditions on that same unitary, and concentration is exactly what survives such conditioning. The feature is not peculiar to our ensemble, since Lombardi, Ma, and Wright [LMW24] prove an analogous concentration for theirs; what the composition requires is the pairing of the concentration with the transcript. Model 6.12 (Hybrid adversary with a final coherent query). This is Model 1.1 in the source model, with every parameter named. The adversary holds a challenge ρb with b uniform, and it may, in this order: (o) receive a classical advice string α of length at most a, depending arbitrarily on H; (i) call R for up to q reference copies per side; (ii) make up to L bits of adaptive classical Count-queries, interleaved with arbitrary quantum processing; and then ⊗t (iii) apply one coherent phase query OH of width M , or equivalently one parallel batch OH , in which case M is the width of the batch, and measure.
Its computational power is otherwise unbounded. All parameters are poly(λ), the width entering only through log M . Theorem 6.13 (Hybrid security against classical queries, advice, and one coherent query). There is a universal C > 0 such that for all q < n/4, all L, a ≥ 0 and all M ≥ 1, every hybrid adversary of Model 6.12 satisfies h
EH
max
α∈{0,1}≤a
Adv
i
6q ≤ + 2β n − 2q, L + a + 1 + C n
s
log(2M ) + L + a , n − 2q
q
with β as in Lemma 2.7; by that lemma the middle term is at most C (L + a + 2)/(n − 2q)1/3 . For n = 2Ω(λ) and all parameters poly(λ) the bound is 2−Ω(λ) . Setting M = 1 recovers Corollary 5.3 up to the enumeration term and the constant in the copy term, the generic split paying 6q/n where a direct argument pays 2q/n. At L = a = q = 0 the third term is the bound of Theorem 6.6, up to the factor two between bias and advantage, while the middle term 2β(n, 1) is what the two-part split costs for a single sign bit. Theorem 6.6 is the sharp statement in that corner, and it is not superseded here. The obvious move is not available. One would like to fix the classical transcript and then apply Theorem 6.6 to whatever follows it. The instrument the classical phase realizes depends on H — the answers it receives are Count’s, and those are functions of the secret — so conditioning on a transcript reweights the law of H itself, while Theorem 6.6 is an average over the unconditioned law. Nothing forbids that reweighting from concentrating on exactly the subspaces where the coherent query does well. Lemma 6.14 is what removes the difficulty, and it does so by relocating the H-dependence rather than by controlling it. The operators are made H-independent by hard-wiring the answers into them, and the question of whether those answers are the true ones is pushed into a scalar indicator. What is then left is a convex combination, because the masses of the consistent records sum to one at every H separately, and a convex combination of bounds is a bound. 59
Both lemmas are proved first. A record here is a classical query-and-answer string, unrelated to the recorded databases of the compressed-oracle technique. Throughout, a record is the string π = (x1 , a1 , . . . ) of query strings and answer bits produced by the classical phase; it has length at most L, so there are at most 2L+1 records. Lemma 6.14 (Record instrument). Fix the classical phase of the adversary, and defer all measurements except the query read-outs. There is, for each record π, a fixed operator Vπ on the workspace Q (independent of H and of the challenge bit), and an indicator χπ (H) = i 1[Count(xi , H) = ai ] such that the sub-normalized post-classical state on record π is χπ (H)Vπ ρVπ† . Writing wπ = n1 Tr(Vπ† Vπ ), X
χπ (H)Vπ† Vπ = I for every H,
X
hence
π
χπ (H)wπ = 1 for every H.
π
Proof. The construction hard-wires the answers into the operator and puts the truth into the indicator, so that the operator carries no H-dependence and, for the true H, the surviving records are exactly the consistent ones. Model each classical query as a measurement of the query register, with outcome xi , followed by the oracle writing the forced answer ai into the workspace, and then a fixed unitary. All other operations are purified: every ancilla is retained in the workspace, and every discard is deferred to the final effect, which acts as the identity on the discarded registers. Let Vπ be the product of these fixed unitaries with the outcome projectors and the answer-writes for the hard-wired string (xi , ai ). It carries no H-dependence, precisely because the answers are hard-wired, and χπ (H) is what records whether those answers match the truth. Now fix the true H. Only consistent records occur, so ρ 7−→
X
Vπ ρVπ†
π : χπ (H)=1
is exactly the trace-preserving instrument realized by the classical phase. Iterating xi |xi ⟩⟨xi | = I P over the queries then gives π χπ (H)Vπ† Vπ = I, and taking normalized traces gives the mass identity. P
Lemma 6.15 (Sub-normalized one-query norm, with concentration). Let V : Cn → CX ⊗ K be any nonzero linear map and let 0 ⪯ Π ⪯ I; the case V = 0 is trivial, with ϕ := 0. Define ZH (f ) from (V, Π) by (13), put w = n1 Tr(V † V ), and let ϕ(H) := ∥GH ∥op with GH the weighted coefficient matrix (14) formed from (V, Π). Then maxf |ZH (f )| ≤ w ϕ(H). Moreover ϕ is a nonnegative function of the Haar unitary U defining R, it is Lipschitz with constant 2 along geodesics, and it satisfies s log(2M ) 2 EH ϕ ≤ C , PrH ϕ ≥ EH ϕ + t ≤ 2e−cnt (t ≥ 0). n Proof. Set Ax := (⟨x| ⊗ I)V and let τx be the query mass (6) attached to the branch Ax , so that X
A†x Ax = V † V,
x
X
τx = w.
x 1/2
1/2
The computation of Theorem 6.6 goes through verbatim and gives ZH (f ) = (Dτ f )⊤ GH (Dτ f ), 1/2
2
the only change being that Dτ f = w rather than 1; hence maxf |ZH (f )| ≤ w ∥GH ∥op . 2 The hypotheses (Row) and (Col) still hold with row and column constant b = n, since their verification used only A†x
2
op
≤ Tr(A†x Ax ) = nτx , valid for any Ax , together with the contraction 60
0 ⪯ Π ⪯ I and ∥α∥2 = 1. Neither x τx = 1 nor V † V ⪯ I enters at any point, which is why the present lemma covers a map whose V † V has operator norm as large as n. Lemma 6.4 now gives the stated bound on EH ϕ. What is left is the tail, and we prove it in three steps: a derivative bound, a conversion between the geodesic and the Hilbert–Schmidt metric, and an appeal to Haar concentration. The derivative bound. Write Y for the Hermitian dilation of the proof of Lemma 6.4, so that P 2 ∥Y(U )∥op = ϕ. There the derivative bound reads a (∂a Y)2 ⪯ 4b I = 4I, and this already makes n2 U 7→ ϕ Lipschitz with constant 2 along geodesics. Indeed, each ∂a Y is Hermitian, so for ∥c∥2 = 1, by Cauchy–Schwarz in the index a, P
X
ca ∂a Y z ≤
a
X
|ca | ∥(∂a Y)z∥ ≤
q
z,
2 a (∂a Y) z
P
≤ 2 ∥z∥ ,
a
and the operator norm is in turn 1-Lipschitz in its argument. From geodesic to Hilbert–Schmidt distance. Since ϕ depends on U only through U DU † , it is invariant under central phases, and so extends unchanged to U(n), where the derivative bound holds trivially along the additional central direction. On U(n), as on SO(n), the geodesic distance is at most π/2 times the Hilbert–Schmidt distance; this follows from the eigenphase bound sin(θ/2) ≥ θ/π, valid for 0 ≤ θ ≤ π. Hence ϕ is Lipschitz with constant at most π in the Hilbert–Schmidt metric. Restricting back to SU(n) keeps that constant, the chord metric there being the restriction of the one on U(n), and we absorb the constant into c. Concentration. Haar concentration at scale n−1/2 , which is (9), now gives the subgaussian tail, which is the last of the three assertions. Proof of Theorem 6.13. We write the advantage as two pieces: the value that an H-independent final query would produce, plus the increment caused by the query’s dependence on H. The first piece is a classical-transcript quantity, so the communication argument bounds it. The increment carries the entire cost of the coherent query, and it is the two lemmas above that bound it. The increment is handled in four moves. First, conditioning on the spans replaces the increment by a half-subspace instance in the orthogonal complement, of dimension n − 2q. Second, the record decomposition of Lemma 6.14 survives that restriction, with its masses still summing to 1. Third, Lemma 6.15 then applies record by record. Fourth, concentration removes the conditioning on the record, at a cost only logarithmic in the number of records. One convention holds throughout. We fix an advice length budget a, and every object below depends implicitly on the advice string α. We keep maxα outside all the inequalities, which is legitimate because each step holds for every fixed α. Step 1: the advantage splits into a term with an H-independent effect and an increment. Let FH be the accept effect of step (iii) and F⋆ the accept effect obtained with the trivial oracle, all of whose signs are +1. Both are effects, so Γ(H) := FH − F⋆ satisfies ∥Γ(H)∥op ≤ 1. With EH the classical-phase channel, the signed advantage ∆adv (H) splits as ∆adv (H) = Tr[F⋆ EH (ρ0 − ρ1 )] + Tr[Γ(H) EH (ρ0 − ρ1 )] . |
{z
}
(I)
|
{z
(II)
}
Step 2: the term (I) contributes at most 2q n + 2β(n − 2q, L + a + 1) on average. For each fixed α the final query is a fixed, H-independent operation. Hence (I) is the advantage of an adversary with q reference copies per side, an L-bit classical transcript, a bits of advice, and otherwise Hindependent processing. That is an adversary of the kind Lemma 5.2 bounds, once we charge the advice to the transcript. We charge it as in the proof of Theorem 3.2, by having the holder of H send the maximizing advice; 61
the sign bit needed there is the orientation bit already charged inside Lemma 5.2. Applying that lemma with L + a bits of interaction bounds EH maxα |(I)| by 2q n + 2β(n − 2q, L + a + 1). Nothing so far has charged the coherent query, since F⋆ carries no dependence on H. The four remaining steps bound (II), where that query is paid for. Step 3: conditioning on the spans reduces the increment to a half-subspace instance of dimension n − 2q, at a cost of 4q n . Condition on the spans (A, B) of Lemma 5.1, which only increases the adversary’s power. The challenge then splits into two branches, and we treat them differently. On the known branch we concede everything. There the channel EH is trace preserving and ∥Γ(H)∥op ≤ 1, so |(II)| ≤ ∥EH (ϱ0 − ϱ1 )∥1 ≤ 2. Since that branch has weight 2q/n, it contributes 4q at most 2 · 2q n = n in total. On the residual branch the challenge is a half-subspace instance inside K = (A ⊕ B)⊥ , of dimension n′ := n − 2q and with reflection R′ . Note that, given (A, B), the truth table of the final coherent query is a Boolean function of the residual subspace alone, which is all the spectral bound requires. From here until the end of Step 6 we work inside K, writing n for n′ and R for R′ ; only the term 4q n already paid refers to the original n. Step 4: the record masses still form a probability vector after the restriction to K. We shall apply Lemma 6.15 to operators supported on K, so it remains to check that the record decomposition of Lemma 6.14 survives the restriction. It does. Put wπ := n1 Tr PK Vπ† Vπ PK . Conjugating the P identity π χπ (H)Vπ† Vπ = I by PK , and then taking normalized traces inside K, gives X
χπ (H) wπ = 1
for every H.
π
So the masses of the restricted instrument again form a probability vector at each fixed H, and that is the only property of them used below. P Step 5: record by record, the increment is at most 4 π χπ (H)wπ ϕπ (H). By Lemma 6.14 and ρ0 − ρ1 = 2R/n, 2X (II) = χπ (H) Tr Γ(H) Vπ RVπ† . n π Fix a record π, and let Wπ be the isometry of step (iii)’s pre-query processing. Then Wπ Vπ satisfies (Wπ Vπ )† (Wπ Vπ ) = Vπ† Vπ ⪯ I and has normalized trace wπ , so Lemma 6.15 applies to it. Now each of the two effects making up Γ(H) = FH − F⋆ contributes a quantity of the form Tr[F Vπ RVπ† ] = n ZH (f ), taken at f = s(H) for FH and at f ≡ 1 for F⋆ ; the factor n appears because ZH is defined through ∆ = R/n. Hence Tr[Γ(H)Vπ RVπ† ] ≤ 2n max |ZH (f )| ≤ 2n wπ ϕπ (H), f
and therefore |(II)| ≤ 4 π χπ (H) wπ ϕπ (H) pointwise in H. That estimate holds at every H, but the record still depends on H through χπ and each ϕπ is itself random. We still have to replace the ϕπ by their means uniformly over records and advice strings. p p Step 6: passing to the means costs C (log(2M ) + L + a)/n. Let mπ = EH ϕπ ≤ C log(2M )/n, and recall that each ϕπ is 2-Lipschitz and hence subgaussian with variance proxy σ 2 ≤ C ′ /n. By Step 4 the numbers wπ χπ (H) form a probability vector at each fixed H and each fixed advice P string. The quantity π wπ χπ (H)ϕπ is a convex combination of the ϕπ , and so is at most maxπ ϕπ . Splitting each term as ϕπ ≤ mπ + |ϕπ − mπ | now gives P
max α
X π
wπ χπ (H)ϕπ ≤ max mπ + max |ϕπ − mπ |. α,π
62
α,π
The first term is at most C log(2M )/n. The second is a maximum of at most 2a+1 · 2L+1 centered subgaussians of variance proxy σ 2 ≤ C ′ /n, so the standard maximal inequality gives p
s q
EH max ϕπ − mπ ≤ σ 2 ln 2a+L+3 α,π
≤ C
a+L+3 . n
Notice that dependence among the ϕπ is irrelevant here, since that inequality follows from a union bound on subgaussian tails alone. Putting the two terms together, 4q EH max (II) ≤ +C α n
s
log(2M ) + L + a . n
Adding the bounds of Steps 2 and 6, and restoring n − 2q for n in the residual estimates, gives 4q 6q the theorem with 2q n + n = n. Corollary 6.16 (A fixed oracle for the hybrid access model). With probability one over {Hλ }, the pair (ρ0,λ , ρ1,λ ) is an EFI pair relative to O against every non-uniform QPT distinguisher that (i) receives poly(λ) bits of classical advice, depending arbitrarily on the fixed oracle; (ii) calls R polynomially many times; (iii) makes poly(λ) adaptive classical Count-queries; and then (iv) makes one coherent Count-query of width 2poly(λ) . This is the access model of Theorem 5.6(ii). Proof. This is Theorem 5.5 with Theorem 6.13 in place of Corollary 5.3. Discretizing the gate set leaves countably many machines Ni , now with polynomial bounds ti (λ) on running time, advice length, sample calls, transcript length, and the logarithm of the width M of the final coherent query. For each i, Theorem 6.13 bounds EH [maxα AdvNi (λ)] by 2−Ω(λ) , with the maximum over advice strings already inside the expectation, which is what Lemma 5.4 asks for. That lemma then fixes a single sequence {Hλ }. The one thing left to check is that the query the corollary allows is one the theorem covers. That query is to some Boolean function of H, which is all Theorem 6.13 assumes of it, so the coherent form of Count at any rank and any precision (Model 8.1) falls under the bound. Polynomially many challenge copies are covered as well, and for a reason particular to the EFI game: the model supplies reference copies of both states, which is exactly what a hybrid over the copies needs. Corollary 6.17 (Many challenge copies). Fix the oracle and let D be a distinguisher of Model 6.12 that receives k copies of the challenge instead of one, with all other resources as there. Then there is a single-challenge distinguisher D′ of Model 6.12, with the same query budget, ordering and advice, and with k − 1 further reference copies, such that Adv(D′ ) = Adv(D)/k. Consequently the bounds of Theorem 6.13 and Corollary 6.16 hold for k challenge copies after multiplication by k, and remain negligible for every k = poly(λ). ⊗(k−j) Proof. Write Ωj := ρ⊗j and pj := Pr[D(Ωj ) = 1], so that pk −p0 is the signed advantage of 0 ⊗ρ1 ′ D. Let D draw j uniformly from [k], place its own challenge in position j, fill positions 1, . . . , j − 1 with reference copies of ρ0 and positions j + 1, . . . , k with reference copies of ρ1 , and run D. On P challenge ρ0 the input is Ωj and on ρ1 it is Ωj−1 , so the signed gap of D′ is k1 kj=1 (pj − pj−1 ) = (pk − p0 )/k. The reduction makes no oracle queries of its own and inserts the copies before the classical phase, so D′ lies in Model 6.12 with q + k − 1 reference copies per side. Everything here is pointwise in the oracle, so it applies to the stored pair of Section 7 as well as to the ideal one.
63
The step that makes this work is the availability of both ρ0 and ρ1 as reference copies. It is not the generic copy amplification of a pseudorandom state, where only one state is available and the joint law across copies is different. The advice in Model 6.12 is classical. Quantum advice of moderate size is covered by the same theorem, through a device that costs nothing beyond a longer classical string. Corollary 6.18 (Quantum advice in the hybrid). Let the adversary of Model 6.12 receive, in addition to its classical advice, a quantum advice register A of dimension dA in a state σH that depends arbitrarily on H. Then, with a′ := a + ⌈2dA log2 9⌉ and C the constant of Theorem 6.13, h
EH sup σH
max
α∈{0,1}≤a
Adv
i
h 6q
≤ 2
n
s
+ 2β n − 2q, L + a′ + 1 + C
log(2M ) + L + a′ i . n − 2q
Suppose now that n = 2λ , that q, L, a and log M are all polynomial in λ, and that dA ≤ n1/3−ε for a fixed ε > 0. Then the bound is 2−Ω(λ) . In other words, quantum advice of up to ( 13 − ε)λ qubits is admissible. Proof. The device is to spend classical bits on a net of advice states, so that the quantum advice becomes part of the adversary’s own workspace and Theorem 6.13 applies unchanged. Fix the adversary and a classical advice string α. Everything it does after receiving its advice is a quantum instrument applied to σ ⊗ ρb ⊗ (reference copies), and the acceptance probability is linear in the input state. So there is a Hermitian operator Zα (H) on A with Adv(σ, α; H) =
Tr σZα (H) .
The supremum over states σ is ∥Zα (H)∥op , and by Lemma 2.1 there is a 41 -net N of the unit sphere of A, of cardinality at most 92dA , on which that norm is at most 2 maxγ∈N |⟨γ|Zα (H)|γ⟩|. For a fixed γ ∈ N the state |γ⟩ does not depend on H, so the adversary with advice state |γ⟩⟨γ| is an adversary of Model 6.12: it prepares |γ⟩ as part of its own initial workspace, and its only H-dependent advice is α. Let D∗ be the adversary that reads a classical advice string of length a′ as a pair (α, j) with j an index into N , prepares |γj ⟩, and runs the original adversary with advice α. Then D∗ is again an adversary of Model 6.12, with a′ in place of a, and for every H max Adv(D∗ ; H) = max max ⟨γ|Zα (H)|γ⟩ ≥ (α,j)
α
γ∈N
1 Adv(σ, α; H). 2 sup max α σ
Taking expectations and applying Theorem 6.13 to D∗ q gives the display. The final claim is arith′ metic: a = O(K), and the middle term is at most C (L + a′ + 2)/(n − 2q)1/3 by Lemma 2.7, which is 2−Ω(λ) once dA ≤ n1/3−ε , while the other two terms are 2−Ω(λ) as well. The reduction is oblivious to what the hidden object is, so the corollary applies wherever Theorem 6.13 does, in particular to the enlarged object X = (H, S) of Section 7. The limit of the method. The proof needs a classical transcript between the state source and the coherent query. The reason is that the decorrelation step is a conditioning on H through the records, and it requires the information separating the two oracle interactions to be classical. Two coherent queries leave no transcript to condition on. A coherent query placed before the classical ones would be worse still, since it would put the H-dependence on the effect side of the relaxation, where there is no mass normalization. The method reaches a hybrid whose coherent query comes 64
last, and no further. Full interleaving would require a two-sided-normalized relaxation, and two full-width coherent queries would require Conjecture 8.2. Both of the excluded orderings have a concrete meaning, which Corollary 6.10 supplies: a coherent query placed first can synthesize arbitrary quantum advice about H, and so already contains that case. “Coherent-first, then classical” is thus the quantum-advice version of this theorem (Section 5.2), and “coherent, then coherent” is quantum advice together with one coherent query (Section 8). In neither case is there a record left to condition on.
7
The separation relative to a single classical oracle
This section proves the main separation. Our oracle here is one deterministic Boolean function on classical strings: a single function that answers every probability-estimation question and, at the same time, carries the two states of the pair. Relative to it, one-way puzzles do not exist, including the inefficiently verifiable ones, and the half-subspace pair is nevertheless an EFI pair in the access model of Model 1.1. We store samples of the pair inside the oracle, through Rosenthal’s one-query synthesis, so that the source R of Model 4.1 disappears from the statement. That source was always the analysis model rather than a part of the result: Section 4 through Section 6 work with fresh samples from a hidden H, because that is the form the concentration arguments require. Bridging the two costs us one elementary step, which replaces the stored challenge by a fresh one, and Section 7.2 explains why we cannot omit it.
7.1
The oracle and the generator
Rosenthal’s theorem, in the form quoted in the proof of Corollary 6.10, provides for every m-qubit state |ψ⟩ and every error ε ≥ exp(− poly(m)) a Boolean function f|ψ⟩ and a single uniform circuit f
Cm = Cm,ε , making one query, such that the reduced state on the first m qubits of Cm|ψ⟩ |0 · · · 0⟩ is within trace distance ε of ψ. We apply that theorem not to the sampled vectors themselves but to their roundings to a fixed finite set of states. Our reason is measurability. The expectations over S taken below, and the Borel hypothesis of Theorem 2.6, both require the oracle to be a measurable function of the hidden object, and ψ 7→ f|ψ⟩ is a selection made inside the proof of [Ros24], about which we prefer to assume nothing. Restricted to a finite set of states the assignment is a function on a finite set, hence measurable for that reason alone, and rounding costs one further δ in trace distance, both ε and δ being fixed in Model 7.1. We therefore fix, for each λ, a finite δ-net Nλ of the unit sphere of Rn , together with the rule sending each u to the nearest point of Nλ , least in a fixed enumeration if several are nearest. That rule is constant on the cells of a fixed finite measurable partition and so is Borel, and the rounded vector ũ satisfies TD(|ũ⟩⟨ũ|, |u⟩⟨u|) ≤ δ, since ∥u − ũ∥ ≤ δ gives |⟨u|ũ⟩| ≥ 1 − δ 2 /2. Model 7.1 (The oracle O′ ). Fix m := log2 n = λ, κ := m + 4λ, and ε := δ := 2−3λ . For each λ, independently across λ and in addition to the subspace H = Hλ , draw a family S = {ub,r }b∈{0,1}, r∈{0,1}κ of independent vectors. Here u0,r is uniform on the unit sphere of H, and u1,r on the unit sphere of H ⊥ . Write ũb,r for the rounding of ub,r to Nλ , and set G 1λ , b, r, x
:= f|ũb,r ⟩ (x),
the Rosenthal function of the rounded (b, r)-th sample at error ε. On inputs not of this form we set G := 0, so that G is a total Boolean function. 65
The oracle is then the tagged Boolean join O′ := (G, Count), where Count is the oracle of Definition 4.4 with base layer G in place of R. That is, a rank-j query may reference clocked samplers whose oracle access is to G and to ranks strictly below j; we write the rank as j here because r already indexes the stored samples. Thus O′ is one deterministic Boolean function on classical strings. The generator G′ (1λ , b) samples r ∈ {0, 1}κ uniformly with its own coins, runs Cm with the one query addressed to G(1λ , b, r, ·), outputs the designated m-qubit register, and discards the rest, P including r. Writing ρ̃b,r for the output at index r, the output of G′ on branch b is ρ̃b := 2−κ r ρ̃b,r , and by construction, through the rounded vector, TD(ρ̃b,r , |ub,r ⟩⟨ub,r |) ≤ ε + δ. Since the vectors u0,r lie in H and the vectors u1,r in H ⊥ , we get TD(ρ̃0 , ρ̃1 ) ≥ 1 − 2(ε + δ) = 1 − 2−3λ+2 . The generator queries its one G-section coherently. A distinguisher with coherent-last access (Model 1.1) is granted a coherent query as well, so it may run G′ itself, and its reference copies are supplied at no cost. That same access restriction applies to generator and distinguisher alike. Well-definedness of Count is Lemma 4.5 verbatim. For every fixing of (H, S) the base layer G is a fixed total Boolean function, so the recursion on ranks closes exactly as before, and the present case is in fact simpler, no channel semantics being needed for the base layer.
7.2
The separation theorem
Theorem 7.2 (Main separation). With probability one over (H, S) = {(Hλ , Sλ )}λ , the oracle O′ of Model 7.1 satisfies both of the following. (i) One-way puzzles, including inefficiently verifiable and classically-secure ones, do not exist relative to O′ , and neither do QEFID pairs; both statements hold for every fixing of (H, S). (ii) The pair (ρ̃0,λ , ρ̃1,λ ) generated by G′ is efficiently generatable relative to O′ , is statistically far, with TD ≥ 1 − 2−3λ+2 , and is computationally indistinguishable, with advantage 2−Ω(λ) , to every QPT distinguisher with coherent-last access to O′ (Model 1.1). It is therefore a classical-advice EFI pair (Definition 2.3), and Corollary 7.6 draws the black-box consequence. Part (i) is the attack of Appendix A unchanged. The adversary of Theorem 4.9 queries Count on the candidate sampler and its prefix specializations, all of which are admissible arguments by the reasoning of Lemma 4.6 with G in place of R, and it never queries G itself; the same applies to Proposition 4.11 and to Theorem 4.14. Nothing in that reasoning used the base layer being a state source: what it used is that base-layer calls carry no rank, so that NormJ leaves them untouched exactly as it left the calls to R, and that the base layer is a fixed object once (H, S) is fixed. Both hold for G, and the sampler may query it coherently. Part (ii) rests on the following lemma, and the order of the two steps below is forced. Applied directly to the stored samples, the communication reduction would hand Bob the list from which Alice’s challenge was drawn, and the associated problem would then be trivial, so the samples must be replaced before the reduction rather than after, and Section 7.2 gives the argument. Lemma 7.3 (Listed samples may be replaced by fresh ones). Fix λ and a distinguisher D in the access model of Theorem 7.2(ii), with q reference copies per side, transcript length L, advice length a, and coherent width M , all finite. Write Adv(D; H, S) for its advantage, maximized over advice strings. Write Adv◦ (D; H, S) for the same quantity in the modified experiment. In that experiment the 2q reference copies and the challenge are replaced by fresh samples: copies of ρ0 (H) and ρ1 (H), and a challenge drawn from ρb (H), all independent of S. Then for every H and every λ ≥ 2,
ES Adv(D; H, S) − Adv◦ (D; H, S) ≤ 2(2q + 1) 2(ε + δ) + 66
q
n2−κ /2
≤ 2(2q + 1) · 2−2λ+1 .
Proof. Everything the distinguisher does collapses into a single effect, and the two experiments then differ only in the states loaded into its 2q + 1 input registers. First, averaging over the indices that the honest executions of G′ discard makes the joint input state an exact tensor product, so that effect is applied to a product. Second, replacing the registers one at a time bounds the change in acceptance probability by the trace norms of the individual discrepancies. Third, p each of those discrepancies is small, the rounding contributing 2(ε + δ) and the sampling error n2−κ /2. Step 1: the acceptance probability is one fixed effect applied to a state that factorizes across the input registers. Fix (H, S) and an advice string α. Deferring all measurements, the distinguisher is a fixed oracle algorithm, and for a fixed oracle its interaction is a fixed quantum channel followed by a two-outcome measurement. Its acceptance probability on challenge branch b is therefore Tr[E ωb ] for a single effect E = E(H, S, α) on the 2q + 1 input registers, with ωb their joint state. Notice that E does not depend on the indices drawn by the honest executions of G′ . Those indices are internal coins of the generator and are discarded, so they reach the distinguisher only through the states themselves. This is exactly why the generator discards r. The indices of the 2q + 1 honest executions are independent and uniform on {0, 1}κ . Averaging over them, the joint input state factorizes exactly: ⊗q ωb = ρ̃⊗q 0 ⊗ ρ̃1 ⊗ ρ̃b .
The independence of the indices is what makes the average of a tensor product equal the tensor product of the averages. This includes the terms in which two indices coincide, since a repeated ⊗q index still contributes a product. In the modified experiment ωb◦ = ρ⊗q 0 ⊗ ρ 1 ⊗ ρb . Both experiments are now one effect applied to a product state, and no further property of D enters below. Step 2: passing from one product state to the other costs 2q + 1 single-register trace norms. Replacing the registers one at a time, and using | Tr[EX]| ≤ ∥X∥1 together with ∥A ⊗ τ ∥1 = ∥A∥1 for a state τ , each replaced register contributes the trace norm of its own discrepancy. Branch b = 0 carries q + 1 registers of type 0 and q of type 1, and branch b = 1 the reverse, so Tr[E ω0 ] − Tr[E ω0◦ ] ≤ (q + 1) ∥ρ̃0 − ρ0 ∥1 + q ∥ρ̃1 − ρ1 ∥1 , with the two coefficients exchanged for b = 1. The advantage is the difference of the two challenge branches, so adding the two displays gives Adv(D; H, S) − Adv◦ (D; H, S) ≤ (2q + 1) ∥ρ̃0 − ρ0 ∥1 + ∥ρ̃1 − ρ1 ∥1 ,
the maximum over advice passing through since the bound is uniform in α. So far we have shown that the entire discrepancy is carried by the two single-register distances, and it remains to bound them. p Step 3: each stored mixture is within 2(ε + δ) + n2−κ /2 of the true state in expectation over S. We bound ∥ρ̃b′ − ρb′ ∥1 by splitting off the exact empirical mixture, namely P σb′ := 2−κ r |ub′ ,r ⟩⟨ub′ ,r |, formed from the unrounded vectors, which are the ones actually lying in H and H ⊥ : ρ̃b′ − ρb′ = ρ̃b′ − σb′ + σb′ − ρb′ . |
{z
rounding
}
|
{z
sampling
}
The rounding term has trace norm at most 2(ε + δ), since TD(ρ̃b′ ,r , |ub′ ,r ⟩⟨ub′ ,r |) ≤ ε + δ for every r and the trace norm is convex.
67
The sampling term is where the number of stored vectors enters. It is supported on the p (n/2)dimensional subspace carrying ρb′ , so we may pass to the Hilbert–Schmidt norm at a cost of n/2. 2 The summands |ub′ ,r ⟩⟨ub′ ,r | are i.i.d. with mean ρb′ and E |ub′ ,r ⟩⟨ub′ ,r | − ρb′ 2 = 1 − n2 , so
ES ∥σb′ − ρb′ ∥22 = 2−κ 1 −
2 , n
and hence
ES ∥σb′ − ρb′ ∥1 ≤
q
n2−κ /2
by Jensen. Taking ES and summing the two terms gives the first bound. p The second bound is arithmetic. Here 2(ε + δ) = 2−3λ+2 and n2−κ /2 ≤ 2−2λ , the latter because κ = m + 4λ and 2m ≥ n; the first of these is below the second for λ ≥ 2, so their sum is at most 2−2λ+1 , as stated. The fresh experiment is one to which the theorems of Section 6 already apply, with the enlarged hidden object X = (H, S) playing the role of H. Lemma 7.4 (The fresh experiment is governed by H alone). Fix λ, and let D be any distinguisher of Theorem 7.2(ii), with q reference copies per side, transcript length L, advice length a, and coherent width M . Then EH,S Adv◦ (D; H, S)
6q ≤ + 2β n − 2q, L + a + 1 + C n
s
log(2M ) + L + a , n − 2q
where C is the universal constant of Theorem 6.13 and β is as in Lemma 2.7. The right-hand side is exactly the bound Theorem 6.13 gives for the hidden object H. Proof. In the fresh experiment the challenge and the 2q reference copies are drawn from ρ0 (H), ρ1 (H) independently of S, while the oracle O′ = (G, Count) is a deterministic Boolean function of X = (H, S). This is exactly the setting of Theorem 3.2 and Theorem 6.13 with X in place of H, since those theorems ask only that the truth table be an arbitrary Boolean function of the hidden object. What is left is to reduce X to H, and we do so one term at a time. First, S does not enter the spectral term. The weighted norm ϕπ (H) of Lemma 6.15 is built from the adversary’s fixed operators and the reflection RH , so it depends on H but not on S. As for the truth table s(X), it enters Theorem 6.13 only through the maximum over all Boolean functions, and that maximum already covers any function of (H, S). The conditioning behaves in the same way. The record identity of Lemma 6.14 holds pointwise in (H, S), and the decorrelation step of Theorem 6.13 bounds a maximum over record strings whose summands are functions of H alone, so its expectation is over H. Second, handing Bob the extra S does not raise the communication term. In the associated problem Bob holds X = (H, S) and Alice a fresh challenge drawn from ρb (H), independent of S given H. The conditional law of S given H is explicit here: it is 2κ+1 independent uniform vectors on the spheres of H and H ⊥ . So from H and private randomness Bob draws S ′ with that law and runs the protocol with S ′ in place of S. Since the challenge is independent of S given H, the joint law of the transcript and of Alice’s output is unchanged, and any L-bit protocol for the (H, S)-problem yields an L-bit protocol for the H-problem of the same advantage. The same substitution is needed after conditioning on the spans, which is the form in which Theorem 6.13 uses it. There Bob holds (HA , S) with (A, B) known to both. Since H = A ⊕ HA he can still sample S ′ from the conditional law, and the residual challenge is independent of S given (HA , A, B). Hence β for the associated problem is the β of Lemma 2.7, and Corollary 5.3 applies with hidden object H. The spectral term and the communication term are the ones Theorem 6.13 supplies for H, which is the stated bound. 68
Proof of Theorem 7.2(ii). Efficient generation from O′ and farness TD ≥ 1 − 2(ε + δ) were shown after Model 7.1, so it remains to prove indistinguishability. Discretize the gate set as in the proof of Theorem 5.5, giving a countable family of machines {Ni } with the same polynomial bounds ti (λ) on their parameters. Fix i. By Lemma 7.3, which replaces the stored samples by fresh ones, and then Lemma 7.4, which returns the fresh experiment to the hidden object H, EH,S AdvNi
≤ EH,S Adv◦Ni + 2(2ti + 1) · 2−2λ+1 ≤ 2−Ω(λ) ,
the last step because the Theorem 6.13 bound is 2−Ω(λ) for n = 2Ω(λ) and all parameters poly(λ). The quantum-advice clause is the same argument with Corollary 6.18 in place of Theorem 6.13. Its bound is 2−Ω(λ) under the stated size restriction, and the supremum over advice states lies inside the expectation, which is what Lemma 5.4 requires. Throughout, the base objects (Hµ , Sµ ) at security parameters µ ̸= λ are independent of (Hλ , Sλ ), and we fix them as shared public randomness, exactly as the proof of Theorem 5.5 fixes the subspaces at other parameters. Every bit of O′ is then a Borel function of X = (Hλ , Sλ ) alone, by the rank induction of Lemma 4.5. This holds for every section and every rank, and it holds even for a Count bit about a sampler at another input length that calls G at level λ. Now let i range. Lemma 5.4, applied with X = (H, S), fixes a set of (H, S) of probability one on which every Ni has negligible advantage. Since part (i) holds for every fixing of (H, S), that same set witnesses both parts, which gives the theorem. The order of the replacement. Lemma 7.3 is a precondition for the communication argument, not a convenience. Applied directly to the real experiment, Theorem 3.2 would hand Bob the whole object X = (H, S), and S contains the description ub∗ ,r∗ of the very challenge Alice prepares, which makes the associated problem trivial: Alice fingerprints her challenge vector in O(κ) = O(λ) bits, and Bob, holding S, finds the matching entry and reads off its branch. Applying Lemma 7.3 first removes the challenge from S and restores the Ω(n1/3 ) bound. The generator of Model 7.1 discards its index r for the same reason, and in the source model the same consideration is why R traces out its sampling randomness (Model 4.1). Two further reasons bind harder still, since they apply to the coherent half of the access model, where no communication argument is in play. The first concerns the spectral bounds. Those of Section 6 rest on ρ0 − ρ1 = 2RH /n, a linear statistic of a Haar-conjugated reflection with ERH = 0, whereas the stored pair has difference ρ̃0 − ρ̃1 , an empirical average over the list, to which Lemma 6.4 does not apply. The second concerns the reference copies. Lemma 5.2 replaces them by their spans, using the rotation-invariant conditional law of q independent Haar vectors given their span; the stored copies, however, are drawn with replacement from a finite list, so resampling from the span does not reproduce their joint law. Both objections disappear once the samples are fresh. The two demands come apart, even at the most permissive end of the OWPuzz definition: an EFI pair asks that two quantum states be hard to distinguish, a one-way puzzle that a classical search problem be hard. A single Boolean function collapses the meta-complexity hardness that characterizes OWPuzzs [Cav+25c; HM25; HHM25], removing them entirely. The half-subspace pair survives it, because distinguishing that pair requires implementing the hidden measurement {PH , PH ⊥ }, and neither a polynomial-length classical transcript [KR11] nor a single coherent query (Theorem 6.6) conveys enough information about H to do so.
69
7.3
The black-box barrier
Theorem 7.2 has a consequence for constructions. We state it in the fully black-box framework, the setting for black-box separations since Impagliazzo and Rudich [IR89], restricted to reductions whose oracle access lies in the class the theorem covers. Definition 7.5 (Fully black-box construction; C-bounded reduction). Let C be a class of oracle distinguishers. A fully black-box construction of one-way puzzles from EFI pairs is a pair (Con, Red) of oracle algorithms with the following property, required relative to every oracle O and for every QPTO generator G of a statistically far pair. First, ConG,O is the sampler of a one-way puzzle relative to O, for some verifier. Second, for every adversary A that inverts ConG,O with nonnegligible probability, RedG,A,O distinguishes the pair of G with non-negligible advantage. We call the construction C-bounded if the following holds whenever A is a classical polynomialtime algorithm making classical queries to O. The distinguisher RedA,O , with its reference copies of G’s outputs supplied as in Model 1.1(i), belongs to C. The boundedness condition says that the reduction, run together with the puzzle attacker, is itself a distinguisher of the class. For the class of Model 1.1 it means that the reduction obtains the generator’s outputs as reference copies and makes its own coherent query last. Corollary 7.6 (No coherent-last black-box construction). Let C be the class of QPT distinguishers with classical advice and coherent-last access (Model 1.1). There is no C-bounded fully black-box construction of one-way puzzles from EFI pairs. Proof. Suppose (Con, Red) were one. Fix (H, S) in the probability-one event of Theorem 7.2 and take O = O′ , G = G′ . The construction is then fed a genuine EFI pair: by Theorem 7.2(ii) the ′ ′ pair is statistically far, so ConG ,O is a one-way puzzle sampler relative to O′ . But puzzles do not survive O′ . By Theorem 7.2(i) there is a classical polynomial-time A making classical queries that inverts that sampler with probability 1 − negl(λ). Feed it to the reduction. By ′ C-boundedness, RedA,O with challenger-supplied reference copies is a distinguisher of Model 1.1, and it has non-negligible advantage against the pair of G′ . That contradicts Theorem 7.2(ii).
8
Fully coherent access
Theorem 7.2 places the separation in the classical-query model for O′ , extended by a single coherent query. In this section we ask what survives when O′ may instead be queried in superposition throughout, which for a deterministic Boolean oracle is the standard relativized model. The hidden object is now X = (H, S) of Model 7.1, and we read every statement below with an arbitrary Boolean function of X where it had one of H. Nothing depends on which of the two it is, since each bound quantifies over all Boolean functions of the hidden object. That quantification makes the conjecture below stronger than coherent security of O′ itself: it implies that security, but its failure for some function of X would not by itself yield an attack on O′ . Model 8.1 (Coherent access to O′ ). Since O′ is a single deterministic Boolean function on classical strings, coherent access to it is the ordinary relativized query UX |z⟩|c⟩ = |z⟩|c ⊕ O′ (z)⟩, with X = (H, S) the hidden object. Here z ranges over the query strings of Model 7.1, padded to a fixed length ℓ(λ) = poly(λ), so that the query domain at security parameter λ is {0, 1}ℓ(λ) . A query addressed to the counting layer carries a sampler description, an output string, and a bit index k, and it returns the k-th bit of the corresponding output probability. We call the largest index k an adversary uses its precision. A query addressed to the base layer G returns a bit of a 70
stored sample instead. No statement below depends on which layer a query addresses, since every bound quantifies over all Boolean functions of X. Conjecture 8.2 (Coherent multi-query security). There are c > 0 and d < ∞ such that the following holds for every sufficiently large even n, with λ := ⌈log2 n⌉. Let X be either H alone, Haar of dimension n/2 in Rn , or else (H, S) drawn as in Model 7.1. Let A be a fixed circuit whose operations, apart from its oracle queries, do not depend on X. Suppose A receives: (i) one challenge copy drawn from ρ0 (H) or ρ1 (H), the maximally mixed states on H and on H ⊥ , with a uniform bit; (ii) at most q̄ fresh reference copies of each of ρ0 (H) and ρ1 (H); and (iii) a bits of classical advice α(X). Suppose further that A makes T adaptive coherent queries to UfX , for a Boolean function fX of X, each query of width at most M . The maps X 7→ fX and X 7→ α(X) are assumed Borel. Write biasA (X) :=
1 2
Pr[A accepts | ρ0 ] − Pr[A accepts | ρ1 ]
for its signed bias at a fixed X. Then EX biasA (X) ≤
1 + T + q̄ + a + log M
d
· n−c .
Since λ = ⌈log2 n⌉, this is negl(λ) for all T, q̄, a and log M polynomial in λ. Note that a Count query carries its precision inside the query string, so precision is charged here through log M . The conjecture and the advice restriction. Conjecture 8.2 grants its adversary only classical advice. Resolving it affirmatively nevertheless removes the quantum-advice restriction as well, so that the two features delimiting Model 1.1 have a single resolution. Let an adversary hold m = poly(λ) qubits of quantum advice σX and make T classical Count queries, and fix a finite net of m-qubit states. For each net point the bias is a Borel function of X, so a lexicographically first pointwise maximizer over the net is Borel, as in the proof of Theorem 3.2, and it lies within exp(− poly(λ)) in trace distance of the best advice. Rosenthal’s one-query synthesis then supplies a Boolean function gX , together with a fixed circuit that prepares a purification of the rounded state with one query to gX , exactly as in Corollary 6.10. Tagging gX together with the counting layer gives a single Boolean function FX of X. Under FX the adversary is a fixed circuit making T + 1 adaptive coherent queries to UFX and carrying no quantum advice, which is exactly the form Conjecture 8.2 bounds. What makes this work is the quantification over every Boolean function of X: a statement about the counting truth table alone would not cover gX . We call the weaker statement that every such circuit with T, q̄, a and log M polynomial in λ has EX |biasA (X)| = negl(λ) the polynomial form of the conjecture. The displayed bound implies it, and it is the polynomial form that we use in Proposition 8.7. The single-challenge restriction costs us nothing, EFI security being a single-copy statement, ⊗s and we do need it for the analysis, since ρ⊗s 0 − ρ1 is not linear in R for s > 1. The reference copies are inessential, by the following lemma, so it suffices to prove or refute the conjecture at q̄ = 0; this is why the conjecture is stated for every even n rather than for n = n(λ), since Lemma 8.3 moves the instance to dimension n − 2q̄. The case T = 1 with no advice and no reference copies is Theorem 6.6; with advice and copies it is Theorem 6.13 at L = 0, and the parallel case is Corollary 6.8. 71
Lemma 8.3 (Reference copies cost only a dimension loss under coherent access). Let A be an adversary that receives one challenge copy, q̄ < n/4 reference copies of each of ρ0 and ρ1 , and a bits of classical advice given by a Borel map H 7→ αH . Grant it arbitrary coherent access to an arbitrary Boolean function of H, and suppose it achieves average bias η. Then there is an adversary A′ with one challenge copy, no reference copies, a bits of advice, and coherent access to an arbitrary Boolean function of a Haar-random half-dimensional subspace of a space of dimension n′ = n − 2q̄. It has the same query count and width as A, and its average bias is at least η − 2q̄/n. Proof. Give A the classical spans (A, B) of the copies it would have drawn. This only increases its power: from a basis of the spans it can resample the copies with the correct joint law, by the argument that opens the proof of Lemma 5.2. Now condition on (A, B). By Lemma 5.1 the challenge becomes a mixture of two branches, of weights 2q̄ and 1 − 2q̄ n n . |{z}
known subspace
| {z } residual
The first is the maximally mixed state on the subspace the adversary already knows. The second ⊥ , inside K; here dim K = n′ and H is is the maximally mixed state on HA , or on HB = K ∩ HA A Haar-random of dimension n′ /2 in K. The known branch can be discarded. The bias is affine in the challenge, and is at most 1 on that branch, so the residual branch carries bias at least η − 2q̄/n on average. All that is left is to see that the residual branch is already an instance with no reference copies. Given (A, B), the truth table is a Boolean function of HA alone. Hard-wiring (A, B) and the resampled copies into A leaves an adversary A′ that holds one challenge copy and nothing else, and that queries a Boolean function of a Haar-random half-dimensional subspace of K, at the same query count and width. Its average bias is at least η − 2q̄/n, which is the claim. One general statement is available, and it locates the regime in which the question lives. Proposition 8.4 (Small width is settled at every query count). Consider an adversary that holds one challenge copy, makes any number of coherent queries to any Boolean function of H of width M , receives a bits of classical advice, and uses no reference copies. There is a universal C such that every such adversary satisfies √ M +a EH max |ZH (f, α)| ≤ C . (16) n f ∈{±1}X , α Here X , of size M , is the set of query labels, and ZH (f, α) is the bias (4) of the adversary with truth table f and advice string α. In particular, for each fixed ε > 0 the conclusion of Conjecture 8.2 holds unconditionally with c = ε/2, at every query count, whenever M + a ≤ n2−ε . Proof. Whatever the number of queries, the algorithm ends in a single acceptance effect Ef,α on the challenge register, one such effect for each truth table f and advice string α. By (4) its bias is n1 | Tr(Ef,α R)|, which is a linear statistic of R with a fixed coefficient matrix. Those coefficient matrices are bounded uniformly in Hilbert–Schmidt norm, q √ ∥Ef,α ∥2 ≤ Tr Ef,α ≤ n, the last step because 0 ⪯ Ef,α ⪯ I on Cn . That is exactly the normalization Lemma 6.1 asks for. So apply that lemma to the family {Ef,α : f, α}, one effect per truth√table and advice string. The family has cardinality at most 2M +a , so its logarithmic factor is O( M + a), and the bound the lemma returns is (16). 72
Two statements are available beyond a single query, and each restricts a width rather than a query count. The first admits arbitrary quantum advice. Proposition 8.5 (Quantum advice with one coherent query). There is a universal C > 0 such that the following holds. Let A be an advice register of dimension K, let W : A ⊗ Cn → CX ⊗ K be an isometry that does not depend on H, let 0 ⪯ Π ⪯ I, and write TrCn for the partial trace over the challenge register. For a truth table f : X → {±1} put YH (f ) :=
1 n n TrC
(IA ⊗ RH ) W † Df ΠDf W ,
an operator on A. Then EH
max ∥YH (f )∥op ≤ C
q
f ∈{±1}X
log(2M ) + n
√
K n
.
Consequently, consider an adversary that holds one challenge copy together with quantum advice of m qubits depending arbitrarily on H, and that then makes one coherent query of any width. Its average bias is 2−Ω(λ) whenever log M = poly(λ) and m ≤ (2 − ε)λ for a fixed ε > 0. Proof. The advice σH enters only through | Tr(σH YH (f ))| ≤ ∥YH (f )∥op , so the consequence follows from the displayed bound, and it remains to prove that. There are three steps. We bound the quadratic form at a single fixed advice direction; we show that what results concentrates at scale n−1 ; and we then pass from the quadratic form to the operator norm by a net. Step 1: at a fixed direction the advice disappears, and the old bound applies. Fix a unit vector α ∈ A and set Wα := W (|α⟩ ⊗ I). Since W † W = I on A ⊗ Cn , Wα† Wα = (⟨α| ⊗ I) I (|α⟩ ⊗ I) = I
on Cn ,
so Wα is an isometry of the challenge register alone, and its query masses ⟨α|Qx |α⟩ sum to 1. In other words (Wα , Π) is an ordinary one-query strategy, and its bias is ⟨α|YH (f )|α⟩. Theorem 6.6 therefore applies to it unchanged: s
EH max ⟨α|YH (f )|α⟩ ≤ C f
log(2M ) . n
Step 2: that quantity fluctuates at scale n−1 . Put Xf,α := (⟨α| ⊗ I) W † Df ΠDf W (|α⟩ ⊗ I), an effect on Cn , so that ⟨α|YH (f )|α⟩ = n1 Tr(RH Xf,α ). Being an effect, Xf,α satisfies ∥Xf,α ∥22 ≤ Tr Xf,α ≤ n, and Cauchy–Schwarz then makes that quantity n−1/2 -Lipschitz in R in the Hilbert– Schmidt metric. A maximum of n−1/2 -Lipschitz functions is again n−1/2 -Lipschitz, and U 7→ R is 2-Lipschitz by the commutator estimate of Lemma 6.4. Hence Fα := max ⟨α|YH (f )|α⟩ f
is 2n−1/2 -Lipschitz in U , and (9) makes it subgaussian at scale n−1 . Step 3: a net converts the quadratic form into the operator norm. Each YH (f ) is Hermitian, so Lemma 2.1 applies to it. Fix the net N it provides, of cardinality at most 92dA ; then ∥YH (f )∥op ≤ 2 max ⟨α|YH (f )|α⟩ ,
so
α∈N
73
max ∥YH (f )∥op ≤ 2 max Fα . f
α∈N
Now combine the two estimates. Step 1 bounds each Fα in expectation, Step 2 makes it subgaussian, and a maximal inequality over N then gives s
EH max Fα ≤ C α∈N
log(2M ) C log |N | + . n n p
Since log |N | = O(K), this is the bound we wanted. The second statement allows two genuine queries, at the cost of a width restriction on the first. Proposition 8.6 (Two coherent queries with a narrow first query). Consider an adversary that holds one challenge copy and makes two adaptive coherent queries, the first of width M1 and the second of width M2 . Their truth tables f and g are independent, and each may depend arbitrarily on H. There is a universal C > 0 such that every such adversary satisfies EH max |ZH (f, g)| ≤ C f,g
q
log(2M2 ) + n
√
M1 n
.
In particular the bias is 2−Ω(λ) whenever M1 ≤ n2−ε for a fixed ε > 0 and log M2 = poly(λ), however large M2 may be. Proof. The two queries are handled by different means: the second by Theorem 6.6, the first by a union bound, which is affordable only because its width is restricted. The second query, at f fixed. Everything the adversary does before its second query is a composition of H-independent isometries with the fixed unitary Df , and so is itself an H-independent isometry. That isometry, together with the final effect, is an ordinary one-query strategy for the second query, so Theorem 6.6 applies to it and gives s
EH max ZH (f, g) ≤ C g
log(2M2 ) . n
The maximum over f . Write ZH (f, g) = n1 Tr RH Ef,g as in (4), where Ef,g is the acceptance effect on the challenge register. As in the proof of Proposition 8.5 this is n−1/2 -Lipschitz in R; the maximum over g preserves that constant; and so maxg |ZH (f, g)| is subgaussian at scale n−1 . A maximal inequality over the 2M1 first truth tables then costs √ M1 , C n
which is where the restriction on M1 is spent. Adding the two estimates gives the bound. What remains open is M = n2−o(1) , a regime the model forces, since QPT quantifies over all polynomials and an adversary may ask about samplers of description length λk for any k, giving k M = 2λ ≫ n2 . At T ≥ 2 no nontrivial bound is available once both widths exceed n2 , which is what Proposition 8.6 leaves open. The first open case. The first open case of Conjecture 8.2 is more structured than the general statement suggests, and Corollary 6.10 is what exhibits the structure. By Rosenthal’s one-query synthesis, a single coherent query to a suitable Boolean function of H prepares an arbitrary poly(λ)-qubit state σH . Splitting the query domain in two costs nothing
74
here, since the truth table is arbitrary and M = 2poly(λ) . Two adaptive coherent queries subsume arbitrary poly(λ)-qubit quantum advice about H, together with one coherent query. That special case is already settled up to advice of dimension n2−ε , by Proposition 8.5, and the complementary ordering – advice followed by classical queries – is settled on O(λ) qubits by Corollary 6.18. What remains in both is advice on more than linearly many qubits, and the reason is the one Section 6.5 identifies: the decorrelation step of Theorem 6.13 conditions on a classical record, quantum advice is not a record, and two coherent queries leave nothing to condition on. Note that the case is narrower than T = 2, since a first query may act on the challenge register jointly with the workspace, which no advice state models. For unitary synthesis, Dong, Lombardi, and Ma [DLM26] compare one-query synthesis with quantum programs, that is, with synthesis from quantum advice, for phase unitaries. Both answers to the conjecture are informative, and we record what each implies. Proposition 8.7 (Consequences of each answer; informal). Both of the following hold. • (A) Suppose Conjecture 8.2 holds in its polynomial form: every adversary with T, q̄, a, log M = poly(λ) has EX |biasA (X)| = negl(λ). Then Theorem 7.2 holds with fully coherent access, so the separation carries no restriction on the access mode, and by Section 8 none on the advice either. (The no-OWPuzz direction is immediate: the attack of Appendix A is classical, a special case of coherent access.) • (B) Suppose instead the polynomial form of Conjecture 8.2 fails. Then for every c > 0 there are, for infinitely many λ, a query count T = poly(λ), a width M with log M = poly(λ), an advice length a = poly(λ), and a family of Boolean functions {fH : [M ] → {±1}} with advice strings {αH }, admitting a T -query circuit with acceptance effect EfH ,αH such that h
EH n1 Tr EfH ,αH RH
i
> n−c ,
for a Haar-random half-dimensional H in dimension n = 2Θ(λ) , with no reference copies. Taking any c < 1/6, coherent access to a classical q function of H, with polynomial classical
advice, then achieves a bias exceeding the ceiling C (L + a + 2)/n1/3 = O(poly(λ) · n−1/6 ) that Lemma 2.7 imposes on every classical transcript of length L = poly(λ) together with a bits of advice about the same secret.
Proof. The two cases run in opposite directions. In case (A) we push the conjecture forward through the reductions of Section 7; in case (B) we pull a hypothetical attack backwards through them, into the standard position the statement describes. Suppose first that the polynomial form of Conjecture 8.2 holds. Then the indistinguishability half of Theorem 7.2 under fully coherent access follows by the reductions of Section 7, none of which depends on the access mode. There are three of them. (1) Lemma 7.3 collapses any interaction with a fixed oracle into one effect, and replaces the stored samples by fresh ones at the stated cost. (2) The resulting experiment is exactly the one the conjecture bounds: fresh copies and challenge, the oracle O′ as the Boolean function of X = (H, S), and the distinguisher’s advice as the advice parameter. The pointwise maximizing advice is Borel here, because the advice set is finite and each fixed-advice bias is Borel, so the lexicographically first maximizer is a Borel map. (3) Lemma 5.4, over the same countable family of machines as in Corollary 6.16, fixes one oracle. 75
The no-OWPuzz half needs nothing further, since the attack of Appendix A is classical and hence a special case of coherent access. That is case (A). Suppose instead that the polynomial form fails. Then some adversary with polynomially bounded T, q̄, a, log M has bias exceeding λ−k for some k and infinitely many λ. Since n = 2Θ(λ) , an inverse polynomial in λ is larger than n−c for every c > 0, so that bias exceeds n−c for every c > 0 as well. Three reductions now bring the adversary to the displayed form, and their order matters. (1) The hidden object is reduced to H. The stored samples are generated from H together with auxiliary randomness ω independent of H, as S = S(H, ω). Since the bias averaged over ω exceeds the threshold, some fixed ω does at least as well. Fixing it makes the truth table f(H,S(H,ω)) and the advice α(H,S(H,ω)) Borel functions of H alone, which is the hypothesis Lemma 8.3 requires. (2) The reference copies are removed. Lemma 8.3 removes them and retains the advice map while doing so, at a cost of 2q̄/n. That cost is at most 21 n−c for every c < 1 and all large λ, since q̄ = poly(λ) while n = 2Ω(λ) . The residual dimension is n′ = n − 2q̄ ≥ n/2, so the bias ′ is at least (n′ )−c for any c′ > c; and as c was arbitrary, the stated conclusion follows after renaming. (3) The residual instance is put in standard position. The spans that Lemma 8.3 conditions on ′ are fixed by the same averaging, and the residual space K is identified with Rn by a fixed isometry, under which HA remains Haar of half dimension. The advice survives as the strings αH of the statement. That leaves putting the surviving adversary into the displayed form. Holding one challenge copy, its bias is n1 | Tr(EfH ,αH RH )| by (4), which is the quantity displayed in case (B), and the comparison with the classical ceiling is then Lemma 2.7 read at L = poly(λ). Case (A) is the separation we are after. Case (B) would not by itself break O′ , whose coherent security would remain open. It would, however, contrast sharply with Klartag–Regev: with the same secret and the same holder of H available, the passage from classical to coherent access would turn a provable impossibility into an attack. It would not resolve the Unitary Synthesis Problem of Aaronson and Kuperberg [AK07] positively, and we see three reasons why. It gives inversepolynomial bias where synthesis asks for inverse-exponential diamond error; it concerns a single ensemble where the problem quantifies over all unitaries; and it is query-efficient where the problem asks for circuit efficiency. It would instead refute a non-synthesis statement for measurement synthesis on the half-subspace ensemble, which [LMW24] single out as the hard core of unitary synthesis. The quantum protocol for VSP. The O(log n)-qubit quantum protocol for VSP does not break the pair under coherent access. The power of that protocol lies in the measurement rather than in the message: Alice sends |u⟩, and it is Bob, who holds H, who applies {PH , PH ⊥ }. Neither of our oracles performs that measurement on the challenge, since R only emits states and Count returns classical bits. The adversary, who plays the part of Alice, cannot make the oracle act as the measuring Bob. The difference is one of direction. Our correspondence sends a query to a message, and that is the direction the lower bound uses. The reverse direction, from a cheap quantum protocol to an attack, would require a reflection oracle, a quantum-input channel, or some other means of letting the holder of H act on the challenge; neither G nor Count is such a means, and neither was R in the 76
analysis model. A cheap quantum protocol rules out a communication-based security proof under coherent access, which is the reason for the query-complexity method of Section 6, but it yields no attack by itself. If we grant the reflection oracle named there, the pair breaks at once, which makes the distinction just drawn a substantive one. Suppose an adversary can apply the controlled unitary RH using O(1) oracle queries. Since PH2 = PH and PH PH ⊥ = 0 give RH ρ0 = ρ0 and RH ρ1 = −ρ1 , the challenge ρb lies entirely in the (−1)b -eigenspace of RH . Applying RH alone is useless, since it multiplies ρb by a global sign; the control is what converts that sign into an observable bit. Prepare an ancilla in |+⟩, apply controlled-RH to the challenge, Hadamard the ancilla and measure it: the outcome is deterministic and equals b. Two oracles supply the controlled reflection. The subspace reflection I − 2PH = −RH , given in controlled form, supplies it in one query, the extra Z on the control merely flipping the outcome label. Oracle access to the defining representation Q of O(n) together with Q⊤ supplies it in two, since RH = QDQ⊤ with D public: apply Q⊤ , then the controlled public D, then Q, and note that QQ⊤ = I on the control-zero branch. Neither oracle is a Boolean function of H answering in classical bits, which is the only kind Conjecture 8.2 concerns.
9
Discussion and open problems
Every classical resource we have granted the distinguisher has a communication counterpart, and security against that resource is the hardness of VSP against its counterpart. Adaptive classical Count queries are interactive classical communication, and oracle-dependent classical advice is a one-way message from the holder of H. Both lie below the classical VSP threshold, and both are provably useless. Not perfectly useless, however, since the oracle does leak: at the rate Θ(n−1/2 ) for the measure-then-count adversaries of Proposition 5.8, and at most poly(λ) n−1/6 in general. Quantum advice, finally, is a one-way quantum message to the holder of one challenge copy, and there the threshold is m = Θ(n2 ) qubits, which is both necessary and sufficient (Proposition 6.9, Section 6.4). Coherent queries, by contrast, have no useful communication counterpart. Of course, one can simulate such a query by sending the query register to the holder of H and back, but that is quantum communication, and for quantum communication VSP is exponentially easy. No reduction of our kind reaches them, and Section 6 argues in query complexity instead. Just one resource crosses the two regimes, namely a polynomial classical transcript followed by a single coherent query, and that is the access model of Theorem 7.2. We conclude with four open problems. First, fully coherent access. Conjecture 8.2 asks whether the pair survives polynomially many adaptive coherent queries. An affirmative answer would place the separation of Theorem 7.2 in the standard quantum oracle model, with no restriction on where the distinguisher’s queries fall, and none on its advice either (Section 8). Two facts delimit an attempt. The first is that the question lives at T ≥ 2 with every width at n2−o(1) and above, by Proposition 8.4 read at each fixed ε and by Proposition 8.6. That is also the regime the model forces, so a union bound over truth tables is unavailable, and the maximum over them must instead be taken by an operator norm, as it is at T = 1. The second fact is that the first open case is concrete. Two coherent queries contain quantum advice together with one coherent query (Section 8), which is Theorem 6.13 with its classical record replaced by advice. The advice on its own is already handled (Corollary 6.10), and Proposition 8.5 settles the pair of them for advice of dimension n2−Ω(1) . What remains open is advice of larger dimension together with a query. What limits the argument there is the conditioning step rather 77
than the construction. Theorem 6.13 conditions on a classical record and averages against the masses wπ of the consistent records, which sum to one for every H (Lemma 6.14). Quantum advice supplies no record, and two coherent queries supply none either, so the convex combination that makes the conditioning harmless has no counterpart. Second, the classical communication complexity of VSP itself. Our proof uses only VSPn ∈ √ Ω(n1/3 ), while the known window is [n1/3 , n] with Raz’s protocol at the top [Raz99; Mon19]. Both endpoints are 2Ω(λ) , so the separation is unaffected, but the true threshold would locate the exact exponential rate at which classical counting begins to compromise quantum state hiding. Klartag and Regev show that their sampling theorem is tight, a spherical cap of measure exp(−n1/3 ) √ deviating with probability exp(−n1/3 ), and conclude that reaching Ω( n) “is probably impossible using the rectangle bound” [KR11]. That assessment is a heuristic drawn from the example rather than a proved barrier, and the example is circumvented by the geometric-mean form of the statement, which the same cap satisfies (Section 5.4). A second and related gap is √quantitative. The security proof lives in the small-advantage regime, where Lemma 2.7 gives O( L + 1 n−1/6 ) and Corollary 5.11 gives O(2L/2 n−1/2 ), and where by Proposition 5.8 no bound can improve on n−1/2 at L = poly(λ). A two-way analogue of Proposition 5.10, linear in L at rate O((L + 1)n−1/2 ), √ would sharpen Theorem 5.5 to its exact exponent and would in particular give Ω( n) at constant advantage, matching Raz. Whether a spectral argument of that kind survives interaction is open. It is not a rectangle bound, so the obstruction identified above does not immediately apply to it. Third, the classical communication complexity of k-VSPn , in which Alice receives k unit vectors drawn independently from the sphere of H or from that of H ⊥ . This is no longer a question the construction needs: security of the pair against k challenge copies follows from the single-copy statement by the hybrid of Corollary 6.17, at a factor k, because the access model supplies reference copies of both states. As a communication question it remains open. The obvious reduction runs in the unhelpful direction: from k vectors Alice can produce one uniform vector of the same law, by taking a uniformly random unit vector in their span, so k-VSP is at least as easy as VSP and hardness does not transfer. We are not aware of a lower bound for any k ≥ 2. The gap between the two statements is the one-directionality of Section 3: Alice holds classical descriptions, and a receiver of k quantum copies does not. Fourth, quantum advice. Linearly many qubits are admitted alongside the full classical budget (Corollary 6.18), and polynomial size is admitted when the advice stands alone (Corollary 6.10); what is open is polynomial size together with classical Count queries. What limits the argument is the ordering restriction in Theorem 6.13 rather than a missing communication bound (Section 5.2), and Section 8 gives the one route that closes the case. The nearest communication question, a one-way quantum message from the holder of H to a holder of the classical u, is settled: Proposition 6.11 puts it at Θ(n), by a reduction to random access coding. What our advice statements need is the other model, in which the receiver holds one quantum copy of the challenge rather than a classical description, and there Proposition 6.9 gives the threshold m = Θ(n2 ). The two models separate by the factor n between these answers (Section 6.4). What remains open is neither of them, but the mixed resource: quantum advice together with adaptive classical Count queries, which corresponds to an initial quantum message followed by two-way classical interaction. Two further questions we leave aside. Whether public-key quantum money with mixed banknotes survives the oracle is open, since the reduction of [KT25] produces a mini-scheme with a pure banknote and the mixed notion of [AC12] is not covered (Section 4.3). Whether the counting oracle can be made uniform, rather than defined by a recursion on ranks, we have not pursued; nothing in the security proof would change, since Theorem 3.2 is indifferent to how the truth table is specified. 78
Acknowledgements We thank Keshav Bhateja and Ezekiel Cochran for useful discussions on one-way puzzles and EFI pairs. Large language models were used in preparing this paper: Claude Opus 4.8 and ChatGPT 5 throughout, and Claude Opus 5 in the later stages of writing and to check proofs and computations. Their role was most substantial in the proofs of Section 6 and Appendix B, in particular in adapting the concentration inequality of Huang and Tropp to our ensemble and in the harmonic analysis on the sphere. We verified every argument line by line, checked the originality of the results and every reference against its source, and take full responsibility for all content. This work is supported by the author’s faculty startup grant from Virginia Tech.
References [AA15]
S. Aaronson and A. Ambainis. “Forrelation: A Problem that Optimally Separates Quantum from Classical Computing”. In: Proceedings of the 47th Annual ACM Symposium on Theory of Computing (STOC 2015). Association for Computing Machinery, 2015, pp. 307–316. doi: 10.1145/2746539.2746547. arXiv: 1411.5729 [quant-ph]. url: https://arxiv.org/abs/1411.5729.
[Aar04]
S. Aaronson. “Limitations of Quantum Advice and One-Way Communication”. In: Proceedings of the 19th Annual IEEE Conference on Computational Complexity (CCC 2004). IEEE, 2004, pp. 320–332.
[AC12]
S. Aaronson and P. Christiano. “Quantum Money from Hidden Subspaces”. In: Proceedings of the 44th Annual ACM Symposium on Theory of Computing (STOC 2012). Association for Computing Machinery, 2012, pp. 41–60. doi: 10 . 1145 / 2213977 . 2213983. arXiv: 1203.4740 [quant-ph]. url: https://arxiv.org/abs/1203.4740.
[AK07]
S. Aaronson and G. Kuperberg. “Quantum versus Classical Proofs and Advice”. In: Theory of Computing 3.7 (2007), pp. 129–157. doi: 10.4086/toc.2007.v003a007.
[AQY22]
P. Ananth, L. Qian, and H. Yuen. “Cryptography from Pseudorandom Quantum States”. In: Advances in Cryptology – CRYPTO 2022. Vol. 13507. Lecture Notes in Computer Science. Cham: Springer, 2022, pp. 208–236. doi: 10.1007/978- 3- 03115802-5_8. arXiv: 2112.10020 [quant-ph]. url: https://arxiv.org/abs/2112. 10020.
[BCN25]
J. Bostanci, B. Chen, and B. Nehoran. “Oracle Separation Between Quantum Commitments and Quantum One-Wayness”. In: Advances in Cryptology – EUROCRYPT 2025. Vol. 15607. Lecture Notes in Computer Science. Also Cryptology ePrint Archive, Paper 2024/1568. Cham: Springer, 2025, pp. 3–22. doi: 10.1007/978-3-031-910982_1. arXiv: 2410.03358 [quant-ph]. url: https://arxiv.org/abs/2410.03358.
[BCQ23]
Z. Brakerski, R. Canetti, and L. Qian. “On the Computational Hardness Needed for Quantum Cryptography”. In: 14th Innovations in Theoretical Computer Science Conference (ITCS 2023). Vol. 251. Leibniz International Proceedings in Informatics (LIPIcs). Dagstuhl, Germany: Schloss Dagstuhl–Leibniz-Zentrum für Informatik, 2023, 24:1–24:21. doi: 10.4230/LIPIcs.ITCS.2023.24. arXiv: 2209.04101 [quant-ph]. url: https://arxiv.org/abs/2209.04101.
79
[Beh+25]
A. Behera, G. Malavolta, T. Morimae, T. Mour, and T. Yamakawa. “A New World in the Depths of Microcrypt: Separating OWSGs and Quantum Money from QEFID”. In: Advances in Cryptology – EUROCRYPT 2025. Vol. 15607. Lecture Notes in Computer Science. Cham: Springer, 2025, pp. 23–52. doi: 10.1007/978- 3- 031- 91098- 2_2. arXiv: 2410.03453 [quant-ph]. url: https://arxiv.org/abs/2410.03453.
[BJ24]
R. Batra and R. Jain. “Commitments are Equivalent to Statistically-Verifiable OneWay State Generators”. In: Proceedings of the 65th IEEE Annual Symposium on Foundations of Computer Science (FOCS 2024). IEEE Computer Society, 2024, pp. 1178– 1192. doi: 10.1109/FOCS61266.2024.00077. arXiv: 2404.03220 [quant-ph]. url: https://arxiv.org/abs/2404.03220.
[BJK04]
Z. Bar-Yossef, T. S. Jayram, and I. Kerenidis. “Exponential Separation of Quantum and Classical One-Way Communication Complexity”. In: Proceedings of the 36th Annual ACM Symposium on Theory of Computing (STOC 2004). ACM, 2004, pp. 128– 137.
[BZ26]
Z. Brakerski and M. Zenilman. Generic Number-of-Copies Amplification for Pseudorandom States. 2026. arXiv: 2606.29325 [quant-ph]. url: https://arxiv.org/ abs/2606.29325.
[Cav+25a]
B. Cavalar, B. Chen, A. Coladangelo, M. Gray, Z. Hu, Z. Ji, and X. Li. A MetaComplexity Characterization of Minimal Quantum Cryptography. 2025. arXiv: 2510. 07859 [quant-ph]. url: https://arxiv.org/abs/2510.07859.
[Cav+25b]
B. Cavalar, E. Goldin, M. Gray, P. Hall, Y. Liu, and A. Pelecanos. “On the Computational Hardness of Quantum One-Wayness”. In: Quantum 9 (2025), p. 1679. doi: 10 . 22331 / q - 2025 - 03 - 27 - 1679. arXiv: 2312 . 08363 [quant-ph]. url: https : //arxiv.org/abs/2312.08363.
[Cav+25c]
B. P. Cavalar, E. Goldin, M. Gray, and P. Hall. “A Meta-Complexity Characterization of Quantum Cryptography”. In: Advances in Cryptology – EUROCRYPT 2025. Vol. 15607. Lecture Notes in Computer Science. Cham: Springer, 2025, pp. 82–107. doi: 10.1007/978-3-031-91098-2_4. arXiv: 2410.04984 [quant-ph]. url: https: //arxiv.org/abs/2410.04984.
[CCS25]
B. Chen, A. Coladangelo, and O. Sattath. “The Power of a Single Haar Random State: Constructing and Separating Quantum Pseudorandomness”. In: Advances in Cryptology – EUROCRYPT 2025. Vol. 15607. Lecture Notes in Computer Science. Cham: Springer, 2025, pp. 108–137. doi: 10.1007/978- 3- 031- 91098- 2_5. arXiv: 2404.03295 [quant-ph]. url: https://arxiv.org/abs/2404.03295.
[CGG24]
K.-M. Chung, E. Goldin, and M. Gray. “On Central Primitives for Quantum Cryptography with Classical Communication”. In: Advances in Cryptology – CRYPTO 2024. Vol. 14926. Lecture Notes in Computer Science. Also Cryptology ePrint Archive, Paper 2024/356. Cham: Springer, 2024, pp. 215–248. doi: 10.1007/978-3-031-68394-7_8. arXiv: 2402.17715 [quant-ph]. url: https://arxiv.org/abs/2402.17715.
[Chu+21]
K.-M. Chung, S. Fehr, Y.-H. Huang, and T.-N. Liao. “On the Compressed-Oracle Technique, and Post-Quantum Security of Proofs of Sequential Work”. In: Advances in Cryptology – EUROCRYPT 2021. Vol. 12697. Lecture Notes in Computer Science. Cham: Springer, 2021, pp. 598–629. doi: 10.1007/978-3-030-77886-6_21. arXiv: 2010.11658 [quant-ph]. url: https://arxiv.org/abs/2010.11658.
80
[DLM26]
F. Dong, A. Lombardi, and F. Ma. Explicit Separations for One-Query Unitary Synthesis. Preprint. 2026. arXiv: 2607.26478 [quant-ph].
[Gav+07]
D. Gavinsky, J. Kempe, I. Kerenidis, R. Raz, and R. de Wolf. “Exponential Separations for One-Way Quantum Communication Complexity, with Applications to Cryptography”. In: Proceedings of the 39th Annual ACM Symposium on Theory of Computing (STOC 2007). ACM, 2007, pp. 516–525.
[Gol+24]
E. Goldin, T. Morimae, S. Mutreja, and T. Yamakawa. CountCrypt: Quantum Cryptography Between QCMA and PP. Also Cryptology ePrint Archive, Paper 2024/1707. 2024. doi: 10 . 48550 / arXiv . 2410 . 14792. arXiv: 2410 . 14792 [quant-ph]. url: https://arxiv.org/abs/2410.14792.
[Gru17]
U. Grupel. “Sampling on the Sphere by Mutually Orthogonal Subspaces”. In: Proceedings of the Twenty-Eighth Annual ACM-SIAM Symposium on Discrete Algorithms (SODA 2017). 2017, pp. 973–983. arXiv: 1607.03714 [math.PR].
[GS19]
D. Gosset and J. Smolin. “A Compressed Classical Description of Quantum States”. In: 14th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2019). Vol. 135. LIPIcs. 2019, 8:1–8:9. arXiv: 1801.05721 [quant-ph].
[GZ25]
E. Goldin and M. Zhandry. “Translating Between the Common Haar Random State Model and the Unitary Model”. In: Advances in Cryptology – CRYPTO 2025. Vol. 16001. Lecture Notes in Computer Science. Also Cryptology ePrint Archive, Paper 2025/489. Cham: Springer, 2025, pp. 269–300. doi: 10.1007/978-3-032-01878-6_9. arXiv: 2503.11634 [quant-ph]. url: https://arxiv.org/abs/2503.11634.
[Hel00]
S. Helgason. Groups and Geometric Analysis: Integral Geometry, Invariant Differential Operators, and Spherical Functions. Vol. 83. Mathematical Surveys and Monographs. Providence, RI: American Mathematical Society, 2000. isbn: 978-0-8218-2673-7. doi: 10.1090/surv/083.
[HHM25]
T. Hiroka, M.-H. Hsieh, and T. Morimae. Hardness of Quantum Distribution Learning and Quantum Cryptography. 2025. arXiv: 2507.01292 [quant-ph]. url: https:// arxiv.org/abs/2507.01292.
[HM25]
T. Hiroka and T. Morimae. “Quantum Cryptography and Meta-Complexity”. In: Advances in Cryptology – CRYPTO 2025. Vol. 16001. Lecture Notes in Computer Science. Cham: Springer, 2025, pp. 545–574. doi: 10.1007/978-3-032-01878-6_18. arXiv: 2410.01369 [quant-ph]. url: https://arxiv.org/abs/2410.01369.
[HT21]
D. Huang and J. A. Tropp. “Nonlinear Matrix Concentration via Semigroup Methods”. In: Electronic Journal of Probability 26 (2021), pp. 1–31. doi: 10.1214/20-EJP578. arXiv: 2006.16562 [math.PR]. url: https://arxiv.org/abs/2006.16562.
[Hua25]
E. Huang. A 1.5-Query Lower Bound for the Unitary Synthesis Problem. Preprint; the arXiv listing gives the author as Eric Huang, the title page as Ting Jia Huang. 2025. arXiv: 2508.13215 [quant-ph]. url: https://arxiv.org/abs/2508.13215.
[IR89]
R. Impagliazzo and S. Rudich. “Limits on the Provable Consequences of One-Way Permutations”. In: Proceedings of the 21st Annual ACM Symposium on Theory of Computing (STOC 1989). Association for Computing Machinery, 1989, pp. 44–61. doi: 10.1145/73007.73012.
81
[JLS18]
Z. Ji, Y.-K. Liu, and F. Song. “Pseudorandom Quantum States”. In: Advances in Cryptology – CRYPTO 2018. Lecture Notes in Computer Science. Cham: Springer, 2018, pp. 126–152. doi: 10 . 1007 / 978 - 3 - 319 - 96878 - 0 _ 5. arXiv: 1711 . 00385 [quant-ph]. url: https://arxiv.org/abs/1711.00385.
[Juc74]
A.-A. A. Jucys. “Symmetric Polynomials and the Center of the Symmetric Group Ring”. In: Reports on Mathematical Physics 5.1 (1974), pp. 107–112. doi: 10.1016/ 0034-4877(74)90019-6.
[Ker+12]
I. Kerenidis, S. Laplante, V. Lerays, J. Roland, and D. Xiao. “Lower Bounds on Information Complexity via Zero-Communication Protocols and Applications”. In: Proceedings of the 53rd Annual IEEE Symposium on Foundations of Computer Science (FOCS 2012). Contains the information-complexity lower bound for the Vector-in-Subspace Problem. IEEE Computer Society, 2012, pp. 500–509. doi: 10.1109/FOCS.2012.68. arXiv: 1204.1505 [cs.CC]. url: https://arxiv.org/abs/1204.1505.
[KNR99]
I. Kremer, N. Nisan, and D. Ron. “On Randomized One-Round Communication Complexity”. In: Computational Complexity 8.1 (1999), pp. 21–49.
[KR11]
B. Klartag and O. Regev. “Quantum One-Way Communication Can Be Exponentially Stronger Than Classical Communication”. In: Proceedings of the 43rd Annual ACM Symposium on Theory of Computing (STOC 2011). Association for Computing Machinery, 2011, pp. 31–40. doi: 10.1145/1993636.1993642. arXiv: 1009.3640 [quant-ph]. url: https://arxiv.org/abs/1009.3640.
[Kre+23]
W. Kretschmer, L. Qian, M. Sinha, and A. Tal. “Quantum Cryptography in Algorithmica”. In: Proceedings of the 55th Annual ACM Symposium on Theory of Computing (STOC 2023). Association for Computing Machinery, 2023, pp. 1589–1602. doi: 10 . 1145 / 3564246 . 3585225. arXiv: 2212 . 00879 [quant-ph]. url: https : //arxiv.org/abs/2212.00879.
[Kre21]
W. Kretschmer. “Quantum Pseudorandomness and Classical Complexity”. In: 16th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2021). Vol. 197. Leibniz International Proceedings in Informatics (LIPIcs). Dagstuhl, Germany: Schloss Dagstuhl–Leibniz-Zentrum für Informatik, 2021, 2:1–2:20. doi: 10.4230/LIPIcs.TQC.2021.2. arXiv: 2103.09320 [quant-ph]. url: https: //arxiv.org/abs/2103.09320.
[KT24]
D. Khurana and K. Tomer. “Commitments from Quantum One-Wayness”. In: Proceedings of the 56th Annual ACM Symposium on Theory of Computing (STOC 2024). Association for Computing Machinery, 2024, pp. 968–978. doi: 10.1145/3618260. 3649654. arXiv: 2310 . 11526 [quant-ph]. url: https : / / arxiv . org / abs / 2310 . 11526.
[KT25]
D. Khurana and K. Tomer. “Founding Quantum Cryptography on Quantum Advantage, or, Towards Cryptography from #P-Hardness”. In: Proceedings of the 57th Annual ACM Symposium on Theory of Computing (STOC 2025). Also Cryptology ePrint Archive, Paper 2024/1490. Association for Computing Machinery, 2025. doi: 10.1145/3717823.3718145. arXiv: 2409.15248 [quant-ph]. url: https://arxiv. org/abs/2409.15248.
[Led01]
M. Ledoux. The Concentration of Measure Phenomenon. Vol. 89. Mathematical Surveys and Monographs. American Mathematical Society, 2001. isbn: 978-0-8218-3792-4. doi: 10.1090/surv/089. 82
[LMW24]
A. Lombardi, F. Ma, and J. Wright. “A One-Query Lower Bound for Unitary Synthesis and Breaking Quantum Cryptography”. In: Proceedings of the 56th Annual ACM Symposium on Theory of Computing (STOC 2024). Association for Computing Machinery, 2024, pp. 979–990. doi: 10 . 1145 / 3618260 . 3649650. arXiv: 2310 . 08870 [quant-ph]. url: https://arxiv.org/abs/2310.08870.
[Mec19]
E. S. Meckes. The Random Matrix Theory of the Classical Compact Groups. Vol. 218. Cambridge Tracts in Mathematics. Cambridge University Press, 2019. isbn: 978-1108-41952-9. doi: 10.1017/9781108303453.
[MNY24]
T. Morimae, B. Nehoran, and T. Yamakawa. “Unconditionally Secure Commitments with Quantum Auxiliary Inputs”. In: Advances in Cryptology – CRYPTO 2024. Vol. 14926. Lecture Notes in Computer Science. Also Cryptology ePrint Archive, Paper 2023/1844. Cham: Springer, 2024. doi: 10 . 1007 / 978 - 3 - 031 - 68394 - 7 _ 3. arXiv: 2311.18566 [quant-ph]. url: https://arxiv.org/abs/2311.18566.
[Mon19]
A. Montanaro. “Quantum States Cannot Be Transmitted Efficiently Classically”. In: Quantum 3 (2019), p. 154. doi: 10.22331/q-2019-06-03-154. arXiv: 1612.06546 [quant-ph]. url: https://arxiv.org/abs/1612.06546.
[MSY25]
T. Morimae, Y. Shirakawa, and T. Yamakawa. “Cryptographic Characterization of Quantum Advantage”. In: Proceedings of the 57th Annual ACM Symposium on Theory of Computing (STOC 2025). Association for Computing Machinery, 2025. doi: 10. 1145/3717823.3718133. arXiv: 2410.00499 [quant-ph]. url: https://arxiv.org/ abs/2410.00499.
[Mur81]
G. E. Murphy. “A New Construction of Young’s Seminormal Representation of the Symmetric Groups”. In: Journal of Algebra 69.2 (1981), pp. 287–297. doi: 10.1016/ 0021-8693(81)90205-2.
[MW82]
C. E. Mueller and F. B. Weissler. “Hypercontractivity for the Heat Semigroup for Ultraspherical Polynomials and on the n-Sphere”. In: Journal of Functional Analysis 48.2 (1982), pp. 252–283. doi: 10.1016/0022-1236(82)90069-6.
[MY22]
T. Morimae and T. Yamakawa. “Quantum Commitments and Signatures Without One-Way Functions”. In: Advances in Cryptology – CRYPTO 2022. Vol. 13507. Lecture Notes in Computer Science. Cham: Springer, 2022, pp. 269–295. doi: 10.1007/9783-031-15802-5_10. arXiv: 2112.06369 [quant-ph]. url: https://arxiv.org/abs/ 2112.06369.
[Nay99]
A. Nayak. “Optimal Lower Bounds for Quantum Automata and Random Access Codes”. In: 40th Annual Symposium on Foundations of Computer Science (FOCS 1999). IEEE Computer Society, 1999, pp. 369–376. doi: 10 . 1109 / SFFCS . 1999 . 814608. arXiv: quant - ph / 9904093 [quant-ph]. url: https : / / arxiv . org / abs / quant-ph/9904093.
[Raz99]
R. Raz. “Exponential Separation of Quantum and Classical Communication Complexity”. In: Proceedings of the 31st Annual ACM Symposium on Theory of Computing (STOC 1999). Association for Computing Machinery, 1999, pp. 358–367. doi: 10.1145/301250.301343.
[Ros24]
G. Rosenthal. “Efficient Quantum State Synthesis with One Query”. In: Proceedings of the 2024 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA 2024). 2024, pp. 2508–2534. doi: 10.1137/1.9781611977912.89. arXiv: 2306.01723 [quant-ph]. 83
[Sto83]
L. Stockmeyer. “The Complexity of Approximate Counting”. In: Proceedings of the 15th Annual ACM Symposium on Theory of Computing (STOC 1983). Association for Computing Machinery, 1983, pp. 118–126. doi: 10.1145/800061.808740.
[Zha19]
M. Zhandry. “Quantum Lightning Never Strikes the Same State Twice”. In: Advances in Cryptology – EUROCRYPT 2019. Vol. 11478. Lecture Notes in Computer Science. Cham: Springer, 2019, pp. 408–438. doi: 10.1007/978-3-030-17659-4_14. arXiv: 1711.02276 [quant-ph]. url: https://arxiv.org/abs/1711.02276.
84
A
The conditional-sampling attack
This appendix proves Theorem 4.9. We use the conditional-sampling attack that underlies the forward direction of the characterization of [Cav+25c]: given a puzzle s, sample a key from the true conditional distribution of keys given s, one bit at a time, computing each conditional probability from output-probability estimates. In the general setting that estimator is weak and the bookkeeping is delicate. Here, by contrast, the counting oracle provides exact bits, so additive error 2−t costs t queries and our analysis stays elementary. Let (Samp, Ver) be a candidate one-way puzzle relative to O with correctness. We may assume without loss of generality that the key has fixed length m = m(λ) and the puzzle length ℓ = ℓ(λ), both polynomial. Since Samp is a fixed polynomial-time machine, the ranks of its Count queries are bounded by an integer J = J(λ), and it accesses O<J+1 only. We read the integer J + 1 off its clocked description. For 0 ≤ i ≤ m let Ci,λ be the clocked specialization that runs Samp(1λ ) to get (k, s) and outputs (s, k1 · · · ki ), and put Cbi,λ := NormJ (Ci,λ ). Each of these is an admissible O (1λ ) = w] argument to CountJ+1 , by the reasoning of Lemma 4.6. Finally, we write P (w) := Pr[Cbi,λ i for w = (s, y) with y ∈ {0, 1} , so that P (w) = P (w0) + P (w1). The adversary is the following. Fix the precision t := m + ℓ + 3λ and put η := 2−t . On input (1λ , s) it produces the key one bit at a time. Having built the prefix w = (s, k1 · · · ki−1 ), it determines the next bit ki as follows. • It queries CountJ+1 for the first t bits of P (wy) for y ∈ {0, 1}, obtaining truncations with 0 ≤ P (wy) − Pe (wy) ≤ η. • If Pe (w0) + Pe (w1) = 0, it sets ki := 0. • Otherwise it sets ki := y with probability Pe (wy)/(Pe (w0) + Pe (w1)), rounded to a multiple of 2−2t so that 2t fair coins realize it exactly. After m rounds it outputs k. This is a classical randomized algorithm making 2mt = poly(λ) classical queries. Lemma A.1 (The attacker’s key distribution is close to the honest one). Let Dreal be the law of (s, k) ← Samp(1λ ) and DA the law of (s, A(1λ , s)) with s from the puzzle marginal, where p A is the adversary above with parameters t = m + ℓ + 3λ and η = 2−t . Then TV(DA , Dreal ) ≤ 4m η 2ℓ+m ≤ 2−λ for all large λ. Proof. Fix a prefix w, write πw (y) = P (wy)/P (w) for the true conditional law of the next key bit, ew for the adversary’s rule. These are the two laws of Lemma 4.7, at py = P (wy) and and write π e p̃y = P (wy), so on prefixes carrying mass P (w) ≥ 4η that lemma gives ew ) ≤ TV(πw , π
4η . P (w)
Elsewhere we use only the trivial bound TV ≤ 1. Now replace the adversary’s rule by the true conditional law, one bit at a time. For 0 ≤ j ≤ m let Dj draw (s, k1 · · · kj ) from the real process and the remaining bits by A’s rule, so that Dm = Dreal and D0 = DA . Adjacent hybrids differ only in the (j + 1)-st bit, conditioned on a prefix distributed as in the real process, so TV(Dj , Dj+1 ) ≤
X w
where w ranges over at most 2ℓ+j prefixes. 85
ew ), P (w) TV(πw , π
That sum is what Lemma 4.8 bounds, at K = 2ℓ+j and with V ≡ 1. Its two hypotheses P −1 ≥ 4η hold: w P (w) = 1, and the displayed per-prefix estimate is the required one, while K −(m+ℓ+3λ) comfortably, since η = 2 . Hence q
q
TV(Dj , Dj+1 ) ≤ 2 4η 2ℓ+j ≤ 4 η 2ℓ+m . Summing over the m steps, q
TV(DA , Dreal ) ≤ 4m η 2ℓ+m = 4m 2−3λ/2 ≤ 2−λ for all large λ, as claimed. Proof of Theorem 4.9. The event “Ver accepts” is a fixed measurable, possibly uncomputable, function of (k, s), and A never runs Ver, so no assumption on the verifier enters anywhere. Under Dreal that event has probability at least 1 − negl(λ) by correctness, hence at least 1 − negl(λ) − 2−λ under DA by Lemma A.1. Two further properties of the argument are used by later statements. First, it holds for every fixing of {Hλ }, because Lemma 4.6 does. Second, A is classical and makes classical queries, which is what gives Corollary 4.10. To summarize, a classical randomized polynomial-time adversary making poly(λ) classical queries produces, from the puzzle alone, a key that Ver accepts with probability 1 − negl(λ). That contradicts security.
B
The two rates
This appendix proves Proposition 5.8 and the upper bound of Proposition 5.10, the two statements of Theorem E. Neither is needed for the separation, and the two arguments are independent of one another.
B.1
The exact rate against a measure-then-count adversary
We isolate the Beta computation first, in the three ensembles the paper needs it in, and then read both halves of Proposition 5.8 off it. Lemma B.1 (Mean absolute deviation of a diagonal entry). For a unit vector v put ξv := ⟨v|PH |v⟩− 1 2 , so that ⟨v|RH |v⟩ = 2ξv . (a) If H ⊆ Rn is Haar of dimension n/2 and v ∈ Rn , then ⟨v|PH |v⟩ ∼ Beta(a, a) with a = n/4, and for n ≥ 4 1 1 q 1 √ ≤ √ 1 − n2 ≤ EH |ξv | ≤ √ . (17) πn πn 2πn 1 The middle bound is the sharp one: EH |ξv | = (πn)−1/2 1 − 2n + O(n−2 ) , so the two outer √ bounds of (17) differ by a factor 2 while the true value lies at the top of the interval.
(b) p If H ⊆ Cn is Haar of dimension n/2 and v ∈ Cn , the same holds with a = n/2, giving 1 − 1/n (2πn)−1/2 ≤ EH |ξv | ≤ (2πn)−1/2 . (c) In the real ensemble the upper bound of (17) holds for every complex unit vector v ∈ Cn as well. 86
Proof. Each part is the mean absolute deviation of a symmetric Beta variable about its mean, read at a different parameter, so we compute that deviation once. Throughout this subsection a denotes that Beta parameter and nothing else. Let X be Beta distributed with both parameters equal to a, so that its density on [0, 1] is proportional to xa−1 (1 − x)a−1 and its law is symmetric about 12 . 2 a−1 on [−1, 1], with normalizing Substitute x = 1+u 2 . The density becomes proportional to (1 − u ) |u| constant 2 · 4a−1 B(a, a), and |X − 21 | = 2 , so E X − 12
1 = a 4 B(a, a)
Z 1 −1
|u| (1 − u2 )a−1 du =
1 , a 4a B(a, a)
the last step because w = u2 turns the integral into 01 (1 − w)a−1 dw = a1 . Now clear the Beta function. Legendre duplication, Γ(2a) = 22a−1 π −1/2 Γ(a)Γ(a + 21 ), turns R
Γ(a)2 B(a, a) = Γ(2a)
√ into
B(a, a) =
and substituting that gives E X − 21
=
π Γ(a)
22a−1 Γ(a + 21 )
,
Γ(a + 12 ) √ . 2a π Γ(a)
(18)
At a = 1 this returns 14 , the value for the uniform law on [0, 1], which is a useful check. One tool controls the Gamma ratio in (18) from both sides, namely log-convexity of Γ: Γ x + 21
2
(x > 0). √ Read it at x = a and it gives the upper bound at once, Γ(a + 12 )/Γ(a) ≤ a. Read it instead at x = a + 12 and it gives Γ(a + 1)2 ≤
≤ Γ(x) Γ(x + 1) = x Γ(x)2
2
a + 21 Γ a + 12 ,
that is
q Γ(a + 21 ) a ≥ q ≥ a − 21 , 1 Γ(a) a+ 2
the last step because a2 ≥ (a − 12 )(a + 12 ). The two readings sandwich the ratio between √ and a, and hence p a − 1/2 1 √ ≤ E X − 12 ≤ √ . 2a π 2 πa
q
a − 12 (19)
It remains to identify the Beta parameter in each of the three ensembles. (a) By rotation invariance we may instead fix H and take v uniform on the sphere. Then P ⟨v|PH |v⟩ = i≤n/2 vi2 has the form U/(U +V ), where U and V are independent chi-square variables with n/2 degrees of freedom each; hence ⟨v|PH |v⟩ ∼ Beta(n/4, n/4). Setting a = n/4 in (19), the √ upper bound is exactly 1/ πn and the lower bound is r √ n−2 1 2 √ = √ 1− , n π πn n √ which is at least 1/ 2πn precisely when n ≥ 4; this is (17). For the asymptotic statement we go back to the exact value (18), the two-sided bounds (19) being too coarse. The standard expansion of the Gamma ratio, √ Γ(a + 12 ) 1 = a 1− + O(a−2 ) , Γ(a) 8a 87
1 1 + O(a−2 ) , which at a = n/4 reads (πn)−1/2 1 − 2n + turns (18) into E|X − 12 | = 21 (πa)−1/2 1 − 8a −2 O(n ) . (b) The complex ensemble is the same computation with the degrees of freedom doubled. The numerator now has n real degrees of freedom out of 2n rather than n/2 out of n, so the Beta parameter is a = n/2, and the stated bounds follow from (19) exactly as in part (a). (c) A complex vector tested against a real subspace has no Beta law of the kind used in part (a), and convexity replaces it. Write v = x + iy with x, y ∈ Rn and ∥x∥2 + ∥y∥2 = 1. Since PH is real symmetric the cross terms cancel, so that
⟨v|PH |v⟩ = x⊤ PH x + y ⊤ PH y,
ξv = ∥x∥2 ξx̂ + ∥y∥2 ξŷ
and hence
for the unit vectors x̂ = x/ ∥x∥ and ŷ = y/ ∥y∥, where we omit any term of weight zero. Thus ξv is a convex combination of two instances of the real case, and the triangle inequality together with rotation invariance gives E|ξv | ≤ ∥x∥2 E|ξx̂ | + ∥y∥2 E|ξŷ | = E|ξe1 |, √ which part (a) bounds by 1/ πn, the upper bound of (17). Only that bound survives the convexity step, and it is all that Proposition 5.8(i) uses. Proof of Proposition 5.8. (i) Fix a POVM {Ek }. The adversary sees the outcome k together with every value Tr(Ek′ PH ), so its optimal rule is the likelihood-ratio test between the two outcome distributions, whose probabilities are n2 Tr(Ek PH ) on branch b = 0 and n2 Tr(Ek PH ⊥ ) on branch b = 1. The advantage of that test is the total variation distance between them, which by RH = PH − PH ⊥ equals 1X 1X Tr(Ek PH ) − Tr(Ek PH ⊥ ) = Tr(Ek RH ) . n k n k We bound each summand separately, using nothing about the POVM beyond its trace. DiP agonalize the effect as Ek = i wk,i |vk,i ⟩⟨vk,i | with wk,i ≥ 0, noting that the eigenvectors may be complex, since nothing constrains the POVM to be real. Expanding the trace and applying the triangle inequality, Tr(Ek RH ) =
X
wk,i ⟨vk,i |RH |vk,i ⟩ ≤
X
wk,i ⟨vk,i |RH |vk,i ⟩ .
i
i
Part (c) of Lemma B.1 covers those complex eigenvectors, and this is the only place where we √ use it. Since ⟨v|RH |v⟩ = 2ξv , it gives EH |⟨v|RH |v⟩| ≤ 2/ πn for every unit vector v. Using P P i wk,i = Tr Ek and k Tr Ek = Tr I = n, EH
h1 X
n
k
Tr(Ek RH )
i
≤
1 2 X 2 ·√ Tr Ek = √ , n πn k πn
which is the bound of (i). (ii) Write dj := ⟨ej |PH |ej ⟩ and ξj := dj − 12 . Measuring ρb in the computational basis returns the outcome j with probability 2dj /n if b = 0 and 2(1 − dj )/n if b = 1. Suppose for the moment that the adversary could apply the exact rule 1[dj < 21 ]. Its advantage would then be 2X 4X (1 − dj ) − dj 1[ξj < 0] = |ξj | 1[ξj < 0]. n j n j
88
(20)
Three facts evaluate the expectation of the right-hand side: there are n indices; each ξj has the and that law is symmetric about 0, because Beta(a, a) is same law as ξe1 , by rotation invariance; symmetric about 12 , so that E |ξj | 1[ξj < 0] = 12 E|ξj |. Together they give EH
h4 X
n
i
|ξj | 1[ξj < 0]
j
=
2 q 4 1 · n · E|ξe1 | = 2 E|ξe1 | ≥ √ 1 − n2 n 2 πn
by Lemma B.1(a). The same lemma gives E|ξe1 | = (πn)−1/2 1 − O(n−1 ) , while part (i) is 2 supv E|ξv | up to the POVM normalization; so the exact rule attains the upper bound of (i) to within a factor 1 − O(n−1 ). That is the asymptotic claim, once we check that the truncation below costs less. Now we pay for the finite precision, since the adversary in the statement runs a truncated rule rather than the exact one. It does not learn pj := 2dj /n exactly, but only its truncation pej to t bits, and with η := 2−t that truncation satisfies pej ∈ [pj − η, pj ]. The rule in the statement outputs 1 exactly when pej < n1 − η. The two rules agree outside a narrow window. Indeed, if pj < n1 − 2η then pej ≤ pj < n1 − η, so the truncated rule outputs 1; and if pj ≥ n1 then pej ≥ pj − η ≥ n1 − η, so it outputs 0. They can differ only in between, at the indices with
1 n − 2η
≤ pj <
that is
1 n,
|ξj | ≤ nη.
Each such index changes the sum in (20) by at most n4 · nη = 4η, and there are at most n indices altogether, so the total loss is at most 4nη ≤ 4n · n−2 2−λ =
4 −λ 2 . n
Subtracting that loss from the advantage of the exact rule gives the bound of (ii). Relative to the √ 2(πn)−1/2 of part (i) this loss is 2 π 2−λ n−1/2 , which at n = 2λ is O(n−3/2 ) and so is dominated by the O(n−1 ) of the previous paragraph; that is the asymptotic claim in full.
B.2
The one-way rate: harmonic analysis on the sphere
The space L2 (S n−1 , σ) decomposes as an orthogonal direct sum ℓ≥0 Hℓ of spaces of spherical harmonics of degree ℓ, the restrictions to the sphere of harmonic polynomials homogeneous of degree ℓ. Each Hℓ is invariant and irreducible under the action of O(n) by rotation. We write Pℓ for the orthogonal projection onto Hℓ and L
Wℓ (f ) := ∥Pℓ f ∥22 for the mass of f at degree ℓ, so that Parseval reads ℓ Wℓ (f ) = ∥f ∥22 . For an indicator 1A that mass is σ(A). Two standard facts are used. The first is the Funk–Hecke theorem [Hel00]. If an operator on L2 (S n−1 ) commutes with all rotations, then by Schur’s lemma it acts on each Hℓ as a scalar. When the operator has the form f 7→ E[f (u′ )] for u′ drawn from a law depending on u only through the inner product t = ⟨u|u′ ⟩, that scalar is E[Gℓ (t)], where P
Gℓ := Cℓζ /Cℓζ (1),
ζ = n−2 2 ,
is the normalized Gegenbauer (ultraspherical) polynomial of degree ℓ. We write the index ζ rather than the customary λ, which in this paper is the security parameter. We use the classical values 89
ζ ζ C2j (0) = (−1)j ζ+j−1 and C2j (1) = 2ζ+2j−1 , the binomial coefficients being the generalized ones j 2j since ζ need not be an integer, together with the expansion
ζ C2j (t) =
j X
(−1)j−k
k=0
Γ(ζ + j + k) (2t)2k . Γ(ζ) (j − k)! (2k)!
Throughout, (a)k := a(a + 1) · · · (a + k − 1) denotes the rising factorial and 2 F1 the Gauss hypergeometric function. The second is the heat semigroup et∆ generated by the Laplace–Beltrami operator, which acts on Hℓ as multiplication by e−tℓ(ℓ+n−2) . The round sphere has Ricci curvature n − 2 in every direction, so by the Bakry–Émery criterion σ satisfies a logarithmic Sobolev inequality with constant n − 2, and Gross’s theorem makes the semigroup hypercontractive [Led01; MW82]: et∆ f
B.3
2
p = 1 + e−2(n−2)t .
≤ ∥f ∥p ,
The second-moment operator
Throughout, µH := νH − νH ⊥ denotes the difference of the uniform probability measures on the unit spheres of H and H ⊥ . Lemma B.2 (Spectral form of the second-moment operator). Let n ≥ 4 be even and let H ⊆ Rn be Haar of dimension n/2. Then for every real-valued f ∈ L2 (S n−1 ), h Z
EH
f dµH
2 i
= 4
X
ω2j W2j (f ),
j odd
ω2j :=
j Y
2i − 1 , n − 3 + 2i i=1
1 and the degrees ℓ ̸≡ 2 (mod 4) contribute nothing. In particular ω2 = n−1 , the ω2j are strictly
decreasing in j, and ω2j ≤
2j j n−1 .
Proof. Expand the square and average over H, so that the whole expectation becomes a quadratic form in two rotation-invariant two-point operators. The argument then has three steps: Funk–Hecke diagonalizes both operators, the Chu–Vandermonde identity evaluates the resulting Gegenbauer scalars, and at half dimension the two scalars cancel at every degree ℓ ≡ 0 (mod 4).R One preliminary. For bounded Borel f the averaged quadratic forms f 7→ EH [( f dνH )2 ] and R f 7→ EH [( f dνH ⊥ )2 ] are at most ∥f ∥22 by Jensen, so both sides of the claimed identity extend to L2 . Now expand. The two square terms agree by the symmetry H ↔ H ⊥ , so that h Z
EH
f dµH
2 i
= 2 ⟨f, (Qs − Qo )f ⟩.
Here Qs is the two-point operator of a common subspace: Qs f (u) = E[f (u′ )], for u′ drawn uniformly from the sphere of a Haar H conditioned on u ∈ H, and Qo is the two-point operator of opposite subspaces, defined in the same way but with u′ drawn from the sphere of H ⊥ . Both are self-adjoint and commute with rotations, so by Funk–Hecke each acts on Hℓ as the scalar E[Gℓ (t)], where t = ⟨u|u′ ⟩. What is left is to evaluate those two scalars. Consider first Qo , where u′ ⊥ u exactly and, given u, the vector u′ is uniform on the equator sphere S n−1 ∩ u⊥ . Its scalar is Gℓ (0), which vanishes for odd ℓ and equals (−1)j ω2j for ℓ = 2j, by the Gegenbauer values recorded in Appendix B.2 together with the product form of ω2j derived at the end of this proof. 90
√ Consider next Qs . Given u the conditional law of u′ is that of tu + 1 − t2 w with w uniform on the equator of u and, independently, t distributed as the first coordinate of a Haar unit vector in dimension m = n/2, whose density is proportional to (1−t2 )(m−3)/2 . So the scalar is E[Gℓ (t)], again (1/2)k ζ . 0 for odd ℓ. For ℓ = 2j we insert the expansion of C2j together with the moments E[t2k ] = (m/2) k k k Using (2k)! = 4 k! (1/2)k and (−j)k = (−1) j!/(j − k)!, this gives ζ E C2j (t) =
− ζ − j)j (−1)j Γ(ζ + j) m (−1)j Γ(ζ + j) ( m , ; 1 = · 2 m 2 F1 − j, ζ + j; Γ(ζ) j! 2 Γ(ζ) j! ( 2 )j
by the Chu–Vandermonde identity, which evaluates 2 F1 at argument 1 when its first parameter is a negative integer. The half-dimension now enters, and the result rests on the cancellation it produces. At m = n/2 n m j n j m j we have m 2 − ζ − j = 1 − 4 − j, so ( 2 − ζ − j)j = (−1) ( 4 )j = (−1) ( 2 )j , the 2 F1 equals (−1) exactly, and Γ(ζ + j) = G2j (0) = ω2j . E G2j (t) = ζ (1) Γ(ζ) j! C2j The scalar of Qs − Qo at degree 2j is ω2j − (−1)j ω2j , which is zero for even j and 2ω2j for odd j, and Parseval gives the stated identity. Now for the product form. Legendre duplication turns the two binomial coefficients into (2ζ)2j = 4j (ζ)j (ζ + 12 )j and (2j)! = 4j j! ( 12 )j , so that the ratio collapses to j
ω2j =
j
Y i− 1 Y 2i − 1 ( 12 )j 2 , = = n − 3 + 2i (ζ + 12 )j ζ + i − 21 i=1 i=1
2j using ζ = n−2 2 . Each factor is less than 1 and at most n−1 , which gives the monotonicity and the last bound, as claimed.
Two elementary checks on Lemma B.2. Only two features of Lemma B.2 are used down1 stream. The first is the value ω2 = n−1 at degree two, which dominates every estimate below. The second is the vanishing at degrees ℓ ≡ 0 (mod 4), which is where the half dimension enters. We can confirm both directly, without any harmonic analysis. For degree two take f (x) = x21 − x22 . For u uniform on the unit sphere of an m-dimensional subspace with projector P we have E[uu⊤ ] = P/m, so with m = n/2, Z
f dµH =
4 (P11 − P22 ) , n
1 Now P11 ∼ Beta(n/4, n/4) has variance 2n+4 , and n 2 so that E[(P11 − P22 ) ] = (n−1)(n+2) and
h Z
EH
f dµH
2 i
=
∥f ∥22 = P
4 . n(n + 2)
n 1 1 i Pii = 2 forces E[P11 P22 ] = 4 − (n−1)(2n+4) ,
16 = 4 ω2 ∥f ∥22 (n − 1) n (n + 2)
1 at ω2 = n−1 .
6 For degree four take the harmonic part of x41 , which on the sphere is h(x) = x41 − n+4 x21 + 2 3 ⊤ ], together with E[u4 ] = 3P11 , gives for d := P − 1 . The same identity for E[uu 11 1 2 (n+2)(n+4) m(m+2)
Z
h dµH =
6d 1 2 − , m m+2 n+4 91
h dµH = 0 for and at m = n/2 the bracket vanishes identically, since then m + 2 = n+4 2 . So every H, not merely in expectation, whereas the bracket is nonzero at every other dimension. The vanishing at degrees ℓ ≡ 0 (mod 4) is not an artifact of the Gegenbauer bookkeeping. It is the same cancellation that the proof above locates in the Chu–Vandermonde step. R
B.4
A level-ℓ inequality, and the leakage of one cell
Lemma B.3 (Level-ℓ inequality on the sphere). There are universal C0 , c′0 > 0 such that for every measurable A ⊆ S n−1 with α = σ(A) ≤ 21 and every 1 ≤ ℓ ≤ 2 ln(e/α) with ℓ ln 2 ln(e/α) ≤ c′0 n, Wℓ (1A ) ≤ α2
C ln(e/α) ℓ 0
ℓ
.
Proof. The argument is hypercontractivity of the heat semigroup, optimized over the diffusion time. The semigroup acts on degree-ℓ harmonics as multiplication by e−tℓ(ℓ+n−2) , so for f = 1A we may undo that damping at level ℓ and then apply the hypercontractive estimate of Appendix B.2, Wℓ (1A ) ≤ e2tℓ(ℓ+n−2) et∆ 1A
2 2
(21)
≤ e2tℓ(ℓ+n−2) α2/p .
This holds at every diffusion time, and it remains to choose one. Reparameterize by ε := e−2(n−2)t ∈ (0, 1], so that p = 1 + ε, the prefactor becomes e2tℓ(ℓ+n−2) = ℓ −ℓ(1+ n−2 ) ε , and α2/p ≤ α2 e2ε ln(1/α) . Take ε :=
ℓ ≤ 1, 2 ln(e/α)
which is admissible by the hypothesis ℓ ≤ 2 ln(e/α). Two error factors must then be controlled. The first is e2ε ln(1/α) ≤ eℓ , immediate from the ℓ choice of ε. The second is the excess produced by the term n−2 in the exponent of the prefactor, 2
ε−ℓ /(n−2) = exp
ℓ2
n−2
ln
2 ln(e/α) ≤ eℓ , ℓ
the last inequality holding by the second hypothesis ℓ ln 2 ln(e/α) ≤ c′0 n. Substituting both into (21) and absorbing the resulting factor e2ℓ into C0ℓ gives the claim.
Lemma B.4 (The leakage of a single cell). Let n ≥ 4 be even, let H ⊆ Rn be Haar of dimension n/2, let A ⊆ S n−1 be measurable, and put α := σ(A) and s := ln(e/α). Then EH µH (A) ≤ 2α √ for every A, and there are universal C, c0 > 0 such that if α ≤ 21 and s ≤ c0 n then also √ αs EH µH (A) ≤ C √ + 2 α θ(s), n
θ(s) :=
4s ⌈s⌉/2
n−1
.
(22)
Proof. The first bound needs no spectral information. By rotation invariance EH νH (A) and EH νH ⊥ (A) both equal σ(A) = α, so the triangle inequality gives EH |µH (A)| ≤ EH νH (A) + EH νH ⊥ (A) = 2α. For the second bound, start from Cauchy–Schwarz and the identity of Lemma B.2, EH µH (A) ≤
EH µH (A)2
1/2
= 2
X j odd
92
1/2
ω2j W2j (1A )
,
and split the sum at j ∗ := ⌈s⌉, which is at least 2 because α ≤ 12 forces s > 1. The two ranges are controlled by different means, the level-ℓ inequality below j ∗ and the decay of ω above it. Consider first the terms with j < j ∗ . There 2j < 2s, so Lemma B.3 applies at ℓ = 2j. Its second hypothesis reads 2j ln(2s) ≤ c′0 n, where c′0 is the constant of Lemma B.3, and this holds √ 2j j since j < s ≤ c0 n once c0 is small in terms of c′0 . Inserting it together with ω2j ≤ ( n−1 ) , ω2j W2j (1A ) ≤ α2
2j j C s 2j 0
n−1
2j
= α2
C1 s 2 j , j (n − 1)
C2
C1 := 20 ,
and summing over j ≥ 1 gives at most twice the first term, namely 2C1 α2 s2 /(n − 1), because the ratio of consecutive terms is at most C1 s2 /(n − 1) ≤ 21 once c0 is small. Consider next the terms with j ≥ j ∗ , where monotonicity of ω and Parseval give X
ω2j W2j (1A ) ≤ ω2j ∗ α ≤ α θ(s)2 ,
j≥j ∗
the last step because ⌈s⌉ ≤ 2s for s ≥ 1. Adding the two ranges, taking square roots and using √ √ √ x + y ≤ x + y gives (22).
B.5
Proof of the one-way rate
Proof of the upper bound in Proposition 5.10. Fix the shared randomness, so that the protocol is deterministic. Alice’s message then realizes a measurable partition {Am } of S n−1 into at most 2L+1 cells (Section 2.6), and Bob, knowing H and m, answers optimally. Write αm := σ(Am ) and sm := ln(e/αm ) for the parameters of Lemma B.4 at the cell Am . Since the two challenge distributions on (m, H) have the same H-marginal and conditional laws νH (Am ) and νH ⊥ (Am ), the advantage satisfies X βow ≤ 14 EH µH (Am ) . m
Three reductions dispose of the degenerate ranges. Set c := c0 /(4 ln 2). √ (1) Long messages. For L ≥ c n the right-hand side of the proposition exceeds 21 once its constant √ C is large enough, while βow ≤ 21 always. The bound holds there, so we may assume L ≤ c n. (2) Small n. We may assume n ≥ n0 for a universal n0 fixed at the end of the proof, since for n < n0 the proposition holds by enlarging its constant. (3) Large cells. Because µH (S n−1 ) = 0 we may replace any cell of measure above 12 by its complement, and since at most one cell has such a measure this costs one further application of the bounds below. What is left is to sum Lemma B.4 over the cells, which we do in two ranges of cell size, the very small cells being disposed of by the cruder of its two bounds. √ Consider first the cells√ with sm > c0 n, for which the first bound of Lemma B.4 suffices. Each 1−c0 n , and there are at most 2L+1 of them, so their total contribution is at such cell has αm √< e √ most 2L+2 e1−c0 n ≤ n−1/2 , the last step because L ≤ c0 n/(4 ln 2) and n ≥ n0 . √ Consider next the cells with sm ≤ c0 n, where (22) applies and its two terms are summed separately. The first term sums by the entropy bound, with C the constant of Lemma B.4, since P L+1 cells, m αm ≤ 1 and there are at most 2 C 1 + (L + 1) ln 2 C X e √ √ αm ln ≤ . n m αm n
93
The second term sums by counting cells at each scale. Fewer than ek cells have sm ∈ [k, k + 1), k/2 , the base being at most since each of those has αm > e−k , and for such a cell θ(sm ) ≤ ( 4(k+1) n−1 ) √ √ one for n ≥ n0 . The cells in this range have sm ≤ c0 n, so only the scales 1 ≤ k ≤ kmax := ⌈c0 n⌉ occur, and X √
kX max
m
k=1
2 αm θ(sm ) ≤ 2
ek
4(k + 1) k/2
n−1
= 2
kX max k=1
4e2 (k + 1) k/2 . n−1
Over k ≤ kmax the base is at most ϑ :=
c 4e2 (kmax + 1) 0 = O √ , n−1 n
so there is a universal n0 beyond which ϑ ≤ 14 . We take n0 large enough that the two earlier steps that assumed it hold as well. Separating the first scale from the rest and bounding every base by ϑ, 2
kX max k=1
8e2 1/2 8e2 1/2 X 4e2 (k + 1) k/2 C′ 2ϑ √ ≤ √ , ≤ 2 +2 ϑk/2 ≤ 2 + n−1 n−1 n−1 n 1− ϑ k≥2
both terms being O(n−1/2 ). √ Putting everything together, the three contributions just bounded are each O (L + 1)/ n , so adding them and dividing by 4 gives the claim.
C
Deferred proofs
This appendix collects two statements that we use only locally: the counting argument behind the comparison drawn in Section 3, and the side result on reference copies quoted in Section 6.4.
C.1
Classical queries do not synthesize
The following counting argument is folklore. It is the argument that Section 1.3 and Section 3 appeal to when they call classical queries the easy case, and it should be contrasted with [Ros24, Thm. 4.1], where a single coherent query to a classical oracle synthesizes an arbitrary state. Proposition C.1 (Classical queries do not synthesize). Fix m, and fix a circuit on m output qubits and any number of ancillas that makes T classical queries to an oracle g : {0, 1}∗ → {0, 1}, each query string being computed from an oracle-independent random seed s and from the previous answers. Write ρg for the reduced state of its output on the m output qubits. If T ≤ 2m − m − 3, there is an m-qubit pure state |ψ⟩ such that ⟨ψ|ρg |ψ⟩ ≤ 43 , and hence TD(ρg , |ψ⟩⟨ψ|) ≥ 14 , for every g. In particular this holds for every T = poly(m). Proof. Fix the seed s. The first query string is then fixed, and by induction, once the first i answers are fixed so is the (i + 1)-st query string. Hence the transcript is a function of the answer vector (a1 , . . . , aT ) ∈ {0, 1}T , and the conditional output ρg,s ranges, as g varies, over a set Fs of at most 2T states that does not depend on g. For any pure |ψ⟩, ⟨ψ|ρg |ψ⟩ = Es ⟨ψ|ρg,s |ψ⟩ ≤ Es ms (ψ),
94
ms (ψ) := max⟨ψ|σ|ψ⟩. σ∈Fs
So it is enough to exhibit a single |ψ⟩ whose overlap with Fs is small on average over s. A Haarrandom |ψ⟩ will do, and the rest of the proof verifies this. Put N = 2m and draw |ψ⟩ Haar-random in CN . Against a fixed unit vector |ϕ⟩, Pr |⟨ϕ|ψ⟩|2 ≥ 12
ψ
= 2−(N −1) .
A state σ overlaps |ψ⟩ by at most its largest overlap with one of its N eigenvectors, so the same estimate survives a factor N : Pr ⟨ψ|σ|ψ⟩ ≥ 21
ψ
≤ N 2−(N −1) .
Now union bound over the at most 2T members of Fs . Since T ≤ 2m − m − 3, the exponent is at most −2, and so for each fixed seed s, Pr ms (ψ) ≥ 12
ψ
≤ N 2 T −N +1 ≤
1 4.
Split the expectation of ms on that event. Off it ms < 21 , and on it ms ≤ 1 while the event itself has probability at most 14 , so Eψ Es ms (ψ) ≤ 12 + 41 . Some fixed |ψ⟩ must then have Es ms (ψ) ≤ 34 , and for that |ψ⟩ the first display gives ⟨ψ|ρg |ψ⟩ ≤ 34 for every g. Testing with the effect |ψ⟩⟨ψ| converts an overlap into a trace distance: TD(ρ, |ψ⟩⟨ψ|) ≥ 1 − ⟨ψ|ρ|ψ⟩ for every ρ. That is the claim.
C.2
Reference copies accumulate as a random walk
This subsection states and proves the side result quoted in Section 6.4: q reference copies of one of √ the two states are worth q rather than q, up to a logarithm, both as an attack and as an upper bound. Nothing in the separation depends on it. Proposition C.2 (Reference copies accumulate as a random walk). Let n ≥ 4 be even and 1 ≤ n ⊗(q+1) : a distinguisher holding q reference q ≤ n2 , and for b ∈ {0, 1} put µb := ρ⊗q 0 ⊗ ρb on (C ) copies of the b = 0 state alongside its challenge. Then: (i) (Attack, pointwise in H.) There is a single effect Πq on (Cn )⊗(q+1) , depending only on n and q, such that for every half-dimensional subspace H, √ q 1 p Tr(Πq µ0 ) − Tr(Πq µ1 ) ≥ , 40 n log2 (4n) 1 so the bias of the corresponding distinguisher is at least 80
p
q/ log2 (4n) / n.
(ii) (Matching upper bound, on average.) Every distinguisher measuring µb with an Hp independent effect has average bias EH [bias] ≤ C 2q log(2n) / n, with C the constant of Proposition 6.9. Part (i) holds for every fixed half-dimensional H, real or complex; part (ii) holds in either ensemble, with C the corresponding constant of Lemma 6.4. The proof rests on an elementary counting bound, which we state on its own because it is the only combinatorial input and is independent of everything quantum. Throughout, the copies occupy registers 1, . . . , q and the challenge occupies register q + 1. For π ∈ Sq+1 we write |π| := (q + 1) − #cycles(π) for the minimal number of transpositions expressing π. 95
Lemma C.3 (Walk counting for the swap sum). For a word w = (i1 , . . . , i2k ) ∈ [q]2k put πw := (i1 q+1) (i2 q+1) · · · (i2k q+1) ∈ Sq+1 . Then for every integer k ≥ 2 and every x ∈ (0, 1] with x2 q ≤ 2k, x |πw | ≤ (24 kq)k .
X w∈[q]2k
Proof. Suppose first that q ≤ 2k. Then |πw | ≥ 0 and x ≤ 1 give X
x|πw | ≤ q 2k = (q 2 )k ≤ (2kq)k ,
w
which suffices. Suppose instead that q > 2k. Only a repeated index can move the walk back toward the identity. Each fresh index pushes πw one step further from it, so a word using many distinct indices carries a small weight x|πw | , while a word using few of them has few realizations, and the whole estimate is a trade between these two effects. Call step ℓ fresh if iℓ ∈ / {i1 , . . . , iℓ−1 } and old otherwise, and let f be the number of fresh steps. Multiplying by a transposition changes | · | by exactly ±1, and a fresh step always contributes +1. To see the latter, note that the support of the permutation built so far lies in the challenge slot together with the indices already used, so a fresh iℓ is a fixed point of it; joining its cycle to the cycle of the challenge increases the length. Since the remaining 2k − f steps contribute at least −1 each, |πw | ≥ max(0, 2f − 2k). It remains to count the words at each value of f . Those with exactly f fresh steps number at f 2k−f most 2k q f ≤ 4k q f (2k)2k−f , by choosing the positions of the fresh steps, then their values, f and then the old values from among the at most f indices already used. Splitting the sum at f = k gives " # X w
x|πw | ≤ 4k
X
q f (2k)2k−f +
f ≤k
k X
q k+g (2k)k−g x2g .
g=1
Each sum is now a geometric comparison against the single quantity (2kq)k . In the first, q f (2k)2k−f = (2kq)k
2k k−f
q
≤ (2kq)k ,
since 2k ≤ q and f ≤ k, and there are at most k + 1 terms. In the second, write f = k + g; then q k+g (2k)k−g x2g = (2kq)k
x 2 q g
2k
≤ (2kq)k
by the hypothesis x2 q ≤ 2k, and there are k terms. The whole sum is thus at most 4k (2k + 1)(2kq)k ≤ 4k 3k (2kq)k = (24 kq)k , using 2k + 1 ≤ 3k , and the lemma follows.
96
Proof of Proposition C.2. The mechanism is a random walk. Each copy couples to the challenge P only through a swap, and the q swaps sum to X = qi=1 SWAPi, q+1 . Against µb every permutation observable evaluates exactly, with no dependence on H, so that ⟨X⟩µ0 − ⟨X⟩µ1 = 2q/n exactly. √ Meanwhile X fluctuates at scale q under both states, and truncating X at that scale and thresholding gives (i). Part (ii) is Proposition 6.9 applied to a purification of the copies. Throughout we use the notation fixed above, writing Pπ for the operator permuting the tensor factors. (i). Start from an exact trace identity. For operators σ1 , . . . , σq+1 on Cn , Tr Pπ (σ1 ⊗ · · · ⊗ σq+1 ) =
Tr
Y
Y
cycles c of π
σj ,
j∈c
where the product inside each trace is taken along the cycle. The order is immaterial here, because all our factors are polynomials in the single operator PH and hence commute. Now take σj = ρ0 for j ≤ q and σq+1 = ρb . Since ρ0 = 2PH /n has rank n/2 with all nonzero eigenvalues 2/n, Tr(ρ0ℓ ) = (2/n)ℓ−1 ,
Tr(ρ0ℓ−1 ρ1 ) = 0 (ℓ ≥ 2),
Tr(ρ1 ) = 1,
the middle identity holding because ρ0 ρ1 = n42 PH PH ⊥ = 0. Read cycle by cycle, this says the following. A cycle of length ℓ that avoids the challenge slot contributes (2/n)ℓ−1 . A cycle through the challenge contributes (2/n)ℓ−1 when b = 0; when b = 1 it contributes 0, unless ℓ = 1. Multiplying over cycles, Pπ µ0 =
2 |π|
n
2 |π|
Pπ µ1 = 1 π(q+1) = q+1 ·
,
n
,
(23)
for every fixed H, and in both the real and the complex ensemble; the dimension n/2 is the only feature of H that enters anywhere. Note that every quantity below is a linear combination of the values (23), so the entire argument is pointwise in H. We state the content of (23) separately, since it is the reason the rest of the argument stays elementary. The maximally mixed state on (Cd )⊗(q+1) with d = n/2 also has ⟨Pπ ⟩ = d−|π| , since Tr(Pπ ) = d#cycles(π) . So on permutation observables µ0 is indistinguishable from that state, and µ1 never exceeds it. In other words, the moment bound and the truncation below are statements about the maximally mixed state on q + 1 registers of dimension d, with no hidden subspace in them. The two means are immediate. Put X :=
q X
SWAPi, q+1 =
i=1
q X
P(i q+1) .
i=1
Each transposition has |π| = 1 and moves the challenge slot, so (23) gives 2 , n
⟨X⟩µ0 = q ·
⟨X⟩µ1 = 0.
Next we bound the even moments of X, and this is the only place where the walk counting is used. We claim that for every integer k ≥ 2 and both b, X 2k µ
b
≤ (24 kq)k .
(24)
Expanding X 2k = w Pπw over words w ∈ [q]2k , every term is nonnegative and at most (2/n)|πw | by (23), so the claim is exactly Lemma C.3 applied with x = 2/n. Its hypotheses hold, since x ≤ 1 for n ≥ 2, and x2 q = 4q/n2 ≤ 4 ≤ 2k because q ≤ n2 and k ≥ 2. P
97
Finally, truncate. Set k := ⌈log2 (4n)⌉ (≥ 4),
Λ := e 24 kq, p
A := X · 1 |X| ≤ Λ .
Then A is Hermitian with ∥A∥op ≤ Λ, so Πq := 12 (I + A/Λ) is an effect. What the truncation discards is controlled by the moment bound. Indeed |x| 1[|x| > Λ] ≤ x2k /Λ2k−1 for every real x, and e2k ≥ e2 ln(4n) = 16n2 , so (24) gives, for both b, √ (24kq)k e 24kq q −2k = Λe ≤ ≤ ⟨X 1[|X| > Λ]⟩µb ≤ , 2k−1 2 Λ 16n 2n √ the last step because e 24k ≤ 8n for n ≥ 4 and q ≥ 1. So truncation costs at most half of the gap 2q/n between the two means, and what is left is still of that order: √ q 2q q q q √ Tr A(µ0 − µ1 ) ≥ −2· = , so Tr Πq (µ0 − µ1 ) ≥ = , n 2n n 2Λn 2e 24k n √ √ where uses Λ = e 24kq. Since k ≤ 2 log2 (4n) we have 2e 24k ≤ p the second equality p 2e 48 log2 (4n) ≤ 40 log2 (4n), and together these give (i), for every H. (ii). Fix an effect Π on the q + 1 registers, and purify the copies, writing ρ⊗q 0 = TrE |ΨH ⟩⟨ΨH | with |ΨH ⟩ ∈ V ⊗ E for V = (Cn )⊗q and an environment E of dimension nq . Then bias(Π) = 21 Tr Π(µ0 − µ1 )
= n1 Tr (Π ⊗ IE ) |ΨH ⟩⟨ΨH | ⊗ R
,
after reordering the registers so that the copies and E together form the advice space, of dimension K = n2q . This is exactly the quantity of Proposition 6.9, whose bound is uniform over effects. Hence p p C log(2n2q ) C 2q log(2n) EH [bias] ≤ ≤ , n n which is (ii). √ The origin of the q rate. The operator being controlled is the Jucys–Murphy element Xq+1 of C[Sq+1 ] [Juc74; Mur81], whose spectrum consists of the integer contents of Young-diagram boxes. Lemma C.3 is an elementary substitute for that spectral information. At q = 1 the value is exactly 1/n, attained for every H by the symmetric-subspace effect 12 (I + SWAP). The proposition completes an account of what each resource about H is worth against the pair. e √q)/n for q of them. A classical description Fresh samples of the secret’s own output are worth Θ( of their span p is worth Θ(q/n). One coherent query, of any width M = 2poly(λ) , is worth n−1/2 up to the factor log(2M ) (Theorem 6.6, Corollary 6.7). The pair survives relative to O because the oracle provides only the weakest of these resources: fresh samples from R, and classical bits from Count that the communication bound already accounts for.
D
The sharp rate for the half-subspace pair
The bounds of Section 5 and Section 6.5 pass through Theorem 3.2, and a worst-case communication bound enters them through Lemma 2.7, whose amplification step costs a square root; the rate they return is poly(λ) · n−1/6 . This appendix proves the same statements at poly(λ) · n−1/2 , which is optimal up to the polynomial by Proposition 5.8. The argument uses no communication bound. In place of one it uses the linearity of ρ0 − ρ1 = 2RH /n in the reflection, and so, unlike Theorem 3.2, it does not extend to an arbitrary hidden object. 98
Theorem D.1 (Sharp hybrid security for the half-subspace pair). There is a universal C > 0 such that for all q < n/4, all L, a ≥ 0 and all M ≥ 1, every hybrid adversary of Model 6.12 satisfies h
EH
max
α∈{0,1}≤a
Adv
i
2q ≤ + C n
s
log(2M ) + L + a . n − 2q
For n = 2Ω(λ) and all parameters poly(λ) the bound is poly(λ) · n−1/2 . At M = 1 the final query is trivial, and the statement bounds an adversary with q reference copies per p side, L bits of adaptive 2q classical queries and a bits of advice, with no coherent query, by n + C (L + a + 1)/(n − 2q). At L = a = q = 0 it is Theorem 6.6, up to the factor two between bias and advantage. Proof. The argument is Steps 3–6 of the proof of Theorem 6.13, applied to the whole signed advantage rather than to its increment. The split of Step 1 there, and the communication bound of Step 2, are not needed: Lemma 6.15 bounds maxf |ZH (f )| over all truth tables, so it bounds the contribution of an H-independent effect exactly as it bounds that of FH , and the record identity of Lemma 6.14 turns the whole advantage into a convex combination of such terms. Fix the adversary. Every object below depends implicitly on the advice string α, and we keep maxα outside all inequalities, each of which holds for every fixed α. Step 1: reference copies cost 2q n and a loss of dimension. Give the adversary the classical spans (A, B) of its reference copies. This only increases its power, since from a basis of the spans it resamples the copies with the correct joint law, by the argument that opens the proof of Lemma 5.2. Condition on (A, B). By Lemma 5.1 each challenge branch is a mixture, with weight 2q n on the 2q maximally mixed state of the known subspace, A or B, and weight 1 − n on the maximally mixed state of the residual, HA or HB , inside K = (A ⊕ B)⊥ of dimension n′ := n − 2q. For a fixed strategy the acceptance probability is affine in the challenge, so the signed advantage splits along the mixture. On the known branch it is a difference of two probabilities, hence at most 1 in absolute value, and that branch contributes at most 2q n . This is where the present argument is cheaper than Step 3 of Theorem 6.13, which bounds a difference of effects and pays 4q n. On the residual branch the adversary faces the half-subspace pair of HA inside K, with HA Haar of dimension n′ /2 in K by Lemma 5.1. Given (A, B), the Count answers and the truth table of the final query are Boolean functions of HA alone, since H = A ⊕ HA , and the resampled copies are functions of (A, B) and private randomness. Hard-wiring these leaves a hybrid adversary with no reference copies against a half-subspace pair in dimension n′ . It remains to bound its advantage uniformly in (A, B). From here on we write n for n′ , R for the reflection 2PHA − PK on K, and ρb for the residual pair, so that ρ0 − ρ1 = 2R/n. Step 2: the whole advantage is a convex combination of one-query expressions. Let FH be the accept effect of step (iii): FH = W † (Ds(H) ⊗ I) Π (Ds(H) ⊗ I)W for the pre-query isometry W , the truth table s(H) and the final effect Π. By Lemma 6.14, with the operators Vπ of the classical phase and the masses wπ := n1 Tr(PK Vπ† Vπ PK ) of the instrument restricted to K, ∆(H) := Tr FH EH (ρ0 − ρ1 ) =
2X χπ (H) Tr FH Vπ RVπ† , n π
and the masses satisfy π χπ (H) wπ = 1 for every H, the identity surviving the restriction to K exactly as in Step 4 of the proof of Theorem 6.13. Fix a record π. Then Tr[FH Vπ RVπ† ] = n ZH (s(H)) for the quadratic form (13) built from the pair (W Vπ , Π), and W Vπ has normalized trace wπ because W is an isometry. Lemma 6.15 applies to that pair and gives, for the weighted norm ϕπ (H) it defines, P
Tr[FH Vπ RVπ† ] ≤ n max |ZH (f )| ≤ n wπ ϕπ (H). f
99
Hence, pointwise in H and for every fixed α, |∆(H)| ≤ 2
X
χπ (H) wπ ϕπ (H) ≤ 2 max ϕπ (H), π
π
the last step because the numbers χπ (H)wπ form a probability vector and each ϕπ ≥ 0. Step 3: ppassing to the means. This is Step 6 of the proof of Theorem 6.13. Write mπ = EH ϕπ ≤ C log(2M )/n. Each ϕπ is 2-Lipschitz along geodesics in the Haar unitary defining R, hence subgaussian with variance proxy σ 2 ≤ C ′ /n, and there are at most 2a+1 · 2L+1 pairs (α, π). The maximal inequality for subgaussian variables, which uses only a union bound on their tails, gives s log(2M ) + L + a EH max |∆(H)| ≤ 2 max mπ + 2 EH max |ϕπ − mπ | ≤ C , α α,π α,π n q
the first term being at most 2C log(2M )/n and the second at most 2σ 2 ln(2a+L+3 ) ≤ p C (L + a + 3)/n; the constants are absorbed, since log(2M ) ≥ log 2. Step 4: reassembling. The bound of Step 3 holds for every (A, B), so averaging over (A, B) preserves it. Adding the 2q n of Step 1 and restoring n − 2q for n gives the theorem. p
The net argument of Corollary 6.18 is unchanged by the substitution, and it improves with the bound it is fed. Corollary D.2 (Quantum advice at the sharp rate). In the setting of Corollary 6.18, with a′ := a + ⌈2dA log2 9⌉ and C the constant of Theorem D.1, h
EH sup σH
max
α∈{0,1}≤a
Adv
i
h 2q
≤ 2
n
s
+C
log(2M ) + L + a′ i . n − 2q
For n = 2λ , all of q, L, a, log M polynomial in λ, and dA ≤ n1−ε with ε > 0 fixed, the bound is 2−Ω(λ) : quantum advice of up to (1 − ε)λ qubits is admissible, against ( 13 − ε)λ from Corollary 6.18. Proof. The net argument of Corollary 6.18 is unchanged: an index into a 41 -net of the unit sphere of A costs ⌈2dA log2 9⌉ classical bits and loses a factor two. Applying Theorem D.1 to the resulting adversary gives the display. For the final claim, a′ = O(K) ≤ O(n1−ε ), so the square root is −Ω(λ) as well. O(n−ε/2 ) = 2−Ω(λ) , and 2q n is 2 Remark D.3 (The enlarged hidden object of Section 7). Theorem D.1 uses three properties of the hidden object: the record identity of Lemma 6.14 holds pointwise; the weighted norms ϕπ depend on the object only through the reflection R; and the truth tables queried are covered by the maximum over all Boolean functions. All three hold for X = (H, S) of Model 7.1 in the fresh experiment of Lemma 7.3. The first is an identity about the instrument realized by any fixed oracle. For the second, ϕπ is built from the adversary’s fixed operators and RHA , so S does not enter it, and the expectation of Step 3 is over HA given (A, B), which is Haar in K by Lemma 5.1, the fresh reference copies being drawn from ρb (H) independently of S. The third holds by construction. So Theorem 7.2 holds with poly(λ) · n−1/2 in place of poly(λ) · n−1/6 , and the clause of Lemma 7.4 that transfers the communication term is not needed on this route.
100