{"id":"cf3d8ea8-ada8-4ad1-ba9d-179874d275c4","arxiv_id":"2412.03020","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A two-node network of silicon-vacancy spin qubits performs single- and two-qubit blind quantum gates and a Deutsch-Jozsa-type algorithm with hidden oracles.","lead":"Silicon-vacancy qubits in diamond cavities were used to demonstrate the first universal set of blind quantum gates on a distributed two-node network, hiding the client's circuit from the servers. The work is a step toward running private quantum computations on remote matter-based quantum computers.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Blindness evidence omits success/failure side channel; reported Holevo information may not bound real server leakage.","rationale":"The central claim is a universal blind gate set, so the 'blind' part depends entirely on the claim that the server learns nothing about the client's choices. The paper's leakage metric chi (Eq. S41) captures only information in the post-success reduced density matrix. But a server in a probabilistic, heralded protocol also knows whether and when success occurred. The supplement concedes the server knows success, and its own simulation section identifies success-rate asymmetry as a leakage source. Omitting this term means the measured chi is not an upper bound on the server's total information. This is more load-bearing than the lack of two-qubit process tomography, which affects characterization rather than blindness, and more central than the reliance on the unpublished ref. [13], which concerns theory context. The proposed check is directly implementable from the existing data and would settle whether the side channel is real. If success rates are independent of the client settings after appropriate blinding, the blindness claim survives; if not, the paper must either modify the protocol or weaken the claim. I agree with the reader's weakest_assumption; the concrete check would resolve it. The concern is not about author conduct but about an analytical gap in the security argument.","tokens_in":40445,"tokens_out":20868,"duration_ms":215933,"concrete_test":"From the raw time-tagged data, reconstruct for each client setting Phi (e.g., Rz(phi) for phi in {0, pi/2, pi, 3pi/2}, and distributed CZ vs I) the full sequence of trials: number of attempts until a heralded success, and the server matter-qubit state after each success. Compute the mutual information I(Phi; success/failure pattern) and compare it with the reported chi from Eq. S41. A direct check is to list the measured success probabilities per Phi before and after the Supplement IV D thresholds; if they differ across Phi by more than statistical error, the side channel is open and the blindness claim is not established. If the success rates are statistically equal and the post-success states show chi consistent with zero, the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is a universal blind gate set, and the paper's blindness evidence is the measured Holevo information chi of the server's post-gate matter states (Supplement IV A, Eq. S41). This quantity conditions on a successfully heralded gate and averages only over the client's measurement outcomes s. It does not include the classical fact, available to the server in any repeat-until-success implementation, that the gate succeeded or how many attempts it took. Supplement III states the server knows the gate succeeded, yet the success probability itself is not treated as a possible output. If the success rate or waiting-time distribution depends on the hidden parameter, for example because short and long TDIs have different losses or because contrast errors make detection rates angle-dependent (as the simulations in Section III note), then the server can infer the operation from timing alone, and chi as measured can be much smaller than the true leakage. The post-hoc threshold optimization of Supplement IV D worsens this: thresholds are chosen after seeing data to maximize fidelity, so the filtered set used for chi may discard the very runs that carry leakage. Therefore the experimental support for 'blind' is incomplete.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an experimental implementation of blind quantum computing primitives using silicon-vacancy (SiV) centers in nanophotonic cavities as two distributed matter-qubit servers. The authors demonstrate a single-qubit blind gate based on three spin-photon gates with adaptive feedback, an intra-node two-qubit blind gate that can implement either an entangling or non-entangling operation, and a distributed two-qubit blind gate across two servers using a four-time-bin photonic qudit. They also implement a Deutsch-Jozsa-type algorithm with hidden oracles. The central claim is that these ingredients constitute the first matter-based universal blind gate set for distributed blind quantum computing, supported by measured gate fidelities and Holevo information values for the information leakage to the servers.","tokens_in":40689,"tokens_out":5741,"duration_ms":62813,"significance":"If the central claim holds, this is an important experimental step: it is the first matter-qubit realization of the universal blind gate set needed for measurement-based blind quantum computing, and the distributed two-node implementation demonstrates a scalable architecture that combines local matter-qubit control with photon-mediated remote gates. The supplement contains self-contained derivations of the blindness property for the ideal gates (Eqs. S4, S10, S17), and the paper reports measured single-qubit process tomography, state fidelities for the two-qubit gates, and Holevo information bounds. The explicit discussion of efficiency, error budgets, and paths toward deterministic operation via quantum memories is useful and grounded in the demonstrated hardware.","major_comments":[{"comment":"The reported Holevo information χ, defined in Eq. (S41), quantifies only the distinguishability of the server's post-gate matter-qubit density matrices, averaged over the client's secret measurement outcomes. Supplement §III states explicitly that the server is assumed to know when the gate has succeeded, and in a repeat-until-success implementation the success/failure history and the waiting time are observable classical side channels. If the successfully heralded detection rate or the timing distribution depends on the client's hidden choice (for example, through the short- versus long-TDI switching in Fig. 4D, or through angle-dependent contrast asymmetries discussed in §III C), the true information leakage can exceed the measured χ. The authors should either extend the leakage bound to include these side channels or provide an explicit argument that they are independent of the client's choice.","section":"Supplement §III and §IV A"},{"comment":"The data-analysis section states that thresholds for SiV contrast, π-pulse fidelity, initialization fidelity, and laser drift are optimized after seeing the data to maximize the client fidelity, and the reported χ values are computed only on the filtered set. Because the discarded runs are precisely those in which the server's observations may be most strongly correlated with the client's gate choice, the reported leakage bounds are not conservative. Please report the information leakage on the unfiltered data or under a pre-registered threshold-selection rule, and show explicitly that the filtering is independent of the client's choice.","section":"Supplement §IV D"},{"comment":"The universal gate-set claim is supported for single-qubit gates by process tomography (Supplement Fig. S19), but the two-qubit blind gates are characterized only by state fidelities on selected inputs (e.g., product/Bell fidelities of 0.85 for the intra-node gate and 0.76/0.75 for the distributed gate) and by truth tables. Supplement §III B acknowledges that full gate-set tomography was not performed experimentally and supplies simulated process fidelities instead. Since the central claim includes a universal two-qubit gate, the paper should provide an experimentally measured process fidelity or a clearly justified alternative metric that certifies the two-qubit gate operation beyond selected input states.","section":"Main text Figs. 3–4; Supplement §III B"}],"minor_comments":[{"comment":"The word 'realizaion' in the last sentence of the Discussion is a typo and should read 'realization'.","section":"Discussion"},{"comment":"The phrase 'post selectong' appears in the caption of Table S3 and should be corrected to 'post selecting'; elsewhere in the supplement, 'P hotonCount' should be 'PhotonCount' and 'sample principle' should be 'same principle'.","section":"Supplement §I F and Table S3"},{"comment":"The manuscript relies on Ref. [13], an unpublished 'manuscript in preparation', for the definition and decomposition of the universal blind cell and for the matter-photon BQC framework. Since these components are central to the claimed universality, the authors should either include the necessary definitions and proofs in the supplement or cite a published or otherwise publicly available version.","section":"Supplement §I A"},{"comment":"In the description of the qudit POVMs, the phases ϕ1, ϕ2, ϕ3 are used in the text but the corresponding elements in Fig. S10C,D are not labeled consistently; adding a short definition in the figure caption would improve clarity.","section":"Supplement §II C and Fig. S10"}],"recommendation":"major_revision","confidential_remarks":"The theoretical blindness derivations in the supplement (Eqs. S4, S10, S17) are self-contained and appear sound, and the experimental platform is significant. My main concerns are the unaddressed classical side channels in the leakage analysis and the post-hoc threshold optimization, both of which directly affect the validity of the headline 'blind' claim. The lack of measured two-qubit process fidelities is also a barrier to the 'universal gate set' claim. These issues are fixable with additional analysis or targeted measurements, so I recommend major revision rather than rejection. I also note that Ref. [13] is a co-authored unpublished manuscript; the authors should make the reliance on it transparent and ideally self-contained."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Here is my read on arXiv:2412.03020. The actually new thing is that it is the first experimental universal blind gate set on matter qubits, running on a distributed two-node SiV network. The QUBE gate for the distributed 2QBG is a real innovation: the client switches entanglement on and off through the TDI choice, and the servers cannot tell which operation was applied. The hidden-oracle Deutsch-Jozsa-type algorithm is a nice addition, and the authors are honest that it gives no quantum advantage because the gates are probabilistic. The supplement is unusually thorough: self-contained blindness derivations, simulations that reproduce the experiment, a code link, and a concrete breakdown of error sources and efficiencies.\n\nThe main soft spot is the blindness evidence. The measured Holevo information chi conditions on successfully heralded gates and averages over the client's measurement outcomes. It does not include the success/failure side channel. The paper's own supplement III admits that if the server knows the gate succeeded, and if contrast errors or other imperfections make the success rate angle-dependent, timing alone can leak information. The measured chi therefore does not bound what a realistic server could extract. This is a real gap, not a fatal one: the ideal protocol is information-theoretically blind, and the authors could close the gap by measuring the success-rate dependence or arguing it is negligible under their operating conditions.\n\nTwo other concerns, both moderate. The two-qubit gates are characterized by state fidelities on selected inputs, not experimental process tomography; the full process matrices in the supplement are simulated. That is a reasonable resource constraint, but it means the universal gate set claim rests on a weaker benchmark than the title suggests. And the post-hoc threshold optimization in Supplement IV D — thresholds chosen after seeing data to maximize fidelity, then used to compute chi — can inflate performance and may discard runs that carry leakage. The 50% cap on filtering helps, but it is still a multiple-comparisons issue. The reliance on the unpublished co-authored ref [13] is minor because the supplement redefines the key definitions.\n\nWho is this for? Anyone working on distributed quantum computing, solid-state quantum networks, or delegated quantum computation. It is a solid proof-of-principle with new experimental building blocks, and it deserves a serious referee. I would send it to peer review, asking the authors to address the side-channel leakage analysis and to either provide experimental two-qubit process data or clearly label the simulated process fidelity as a prediction.","headline":"First matter-based universal blind gate set on a distributed two-node SiV network, but the blindness evidence omits the success/failure side channel and the two-qubit gates lack experimental process tomography.","tokens_in":41251,"tokens_out":3245,"would_cite":true,"duration_ms":34026,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper reports the first matter-qubit realization of a universal blind quantum gate set on a two-node silicon-vacancy network, with client-hidden single- and two-qubit operations and measured Holevo information far below one bit.","keywords":["blind quantum computing","silicon-vacancy centers","distributed quantum network","matter qubits","universal blind gate set","Holevo information","time-bin qudit","Deutsch-Jozsa algorithm"],"falsifier":"Re-analyze the recorded data with a server-side classifier that is allowed to condition on the client's TDI choice (short or long delay), the photon arrival time bin, and the sequence of lost versus detected photons; if the mutual information between those conditioned server states and the client's choice of $CZ$ versus identity exceeds one bit, the demonstrated blindness bound no longer describes what a real server could learn.","tokens_in":40285,"feed_emoji":"⚛️","tokens_out":8086,"duration_ms":73343,"temperature":0.7,"pith_summary":"Blind quantum computing lets a client run a computation on remote servers without revealing the circuit. This paper claims to supply the missing matter-based ingredients: a universal one-qubit blind gate, a two-qubit blind gate inside one node, and a two-qubit blind gate spread across two nodes, all built from silicon-vacancy (SiV) centers in nanophotonic diamond cavities. The client's gate choices are hidden because the servers see the same quantum channel regardless of which gate is applied; the measured leakage, quantified by Holevo information, is below one bit in every demonstrated gate. The work closes with a Deutsch-Jozsa-type algorithm whose oracles are hidden from the servers, showing that the distributed blind building blocks can run an actual delegated task.","feed_headline":"Solid-state qubits run blind gates on a two-node network","feed_subtitle":"Silicon-vacancy centers hide the client's gate choices from servers; measured leakage stays far below one bit.","key_machinery":"The load-bearing object is the spin-photon gate (SPG), in which spin-dependent reflection of a time-bin photon from the SiV-cavity system creates a photon-electron Bell pair; the client's measurement of that photon in the basis $|0\\rangle \\pm e^{i\\phi}|1\\rangle$ secretly applies $R_z(\\phi)$ to the electron. Three SPGs interleaved with Hadamard gates make the universal one-qubit blind gate, with the client's real-time adjustment of later phases absorbing Pauli feedback. For the distributed two-qubit gate, the paper introduces the QUBE gate, which entangles a four-time-bin photonic qudit with two electron spins and lets the client secretly choose between a short or long time-delay interferometer; the short setting interferes neighboring time bins and turns on $e_1$-$e_2$ entanglement, while the long setting interferes next-nearest bins and leaves the qubits unentangled, so the servers always observe the same dephasing channel $\\mathcal{N}_2(\\rho)$ regardless of whether the implemented operation is $CZ$ or identity.","core_discovery":"On its own terms, the paper establishes that matter qubits can implement the universal blind gate set required for blind quantum computing, not just blind rotations. Using two nodes, each a $^{29}$SiV center coupled to a nanophotonic cavity, it demonstrates a one-qubit blind gate built from three successive spin-photon gates (realizing $R_z(\\phi_3)R_x(\\phi_2)R_z(\\phi_1)$), an intra-node two-qubit blind gate that produces either $S_{e1}S_{n1}CZ$ or identity depending on the client's measurement phase, and a distributed two-qubit blind gate (the QUBE gate) that hides whether $CZ$ or identity is applied across the two servers. In all cases the server's reduced density matrix is nearly independent of the client's choice: the measured Holevo information is $0.0045^{+0.018}_{-0.0045}$ bits for the blind rotation, $0.032^{+0.12}_{-0.032}$ bits for the intra-node gate, and $0.12 \\pm 0.06$ bits for the distributed gate. The same components run a four-oracle Deutsch-Jozsa-type algorithm in which the client identifies constant versus balanced functions with average probability $0.85 \\pm 0.03$, while the servers cannot distinguish the paired oracles (leakage $0.05^{+0.19}_{-0.05}$ and $0.07^{+0.14}_{-0.07}$ bits).","pith_inferences":["An adversarial model that gives the servers access to the client's time-delay-interferometer setting (short versus long), photon arrival times, or the pattern of lost photons would enlarge their information beyond the paper's assumed 'gate succeeded' flag; the reported Holevo bounds do not automatically cover those side channels.","The switchable-entanglement mechanism is platform-agnostic: any emitter platform with a matter-photon entangling gate and a client-controlled interferometer could test the same hidden $CZ$-versus-$I$ operation, including neutral atoms, trapped ions, or superconducting qubits with microwave-optical transduction.","A near-term upgrade that would restore the Deutsch-Jozsa single-query advantage is to add a memory qubit so the ancilla post-selection and the one-photon-of-two-QUBEs post-selection are eliminated; the paper's proposed teleportation-to-memory procedure is the natural implementation."],"forward_implications":["A client who can prepare and measure single photons can in principle tile the demonstrated universal blind cell in the brickwork pattern to run arbitrary circuits on remote matter qubits.","The two-qubit blind gate uses one photon instead of the five photons required in all-photonic blind implementations, reducing the dominant loss overhead by roughly the fifth power of the photon efficiency.","The same gates plug into memory-based distributed architectures, where repeated entanglement attempts are stored in ancillary qubits; the authors estimate this changes algorithm running time from exponential in depth to linear in depth.","The hidden-oracle Deutsch-Jozsa-type algorithm runs with the servers unable to distinguish constant from balanced oracles, although the current probabilistic QUBE gate and post-selection steps do not preserve the usual single-query quantum advantage."],"supporting_citations":[{"why":"Supplies the two-node SiV nanophotonic-cavity network and the photon-mediated remote entanglement on which all distributed gates run.","marker":"[33]"},{"why":"Provides the spin-photon entanglement mechanism and the electron/nuclear spin control used in every spin-photon gate.","marker":"[34]"},{"why":"Defines the universal blind cell and brickwork construction that the demonstrated 1QBG/2QBG decomposition implements.","marker":"[6]"},{"why":"Supplies the blind-quantum-computing framework and verification context for hiding the circuit from the servers.","marker":"[8]"},{"why":"Introduces the matter-photon hybrid BQC theory, including the 1QBG and 2QBG definitions realized in this experiment.","marker":"[13]"},{"why":"Demonstrates blind rotations on matter qubits, the closest prior experimental step that this work extends to a universal gate set.","marker":"[14]"},{"why":"Contains the protocol derivations, error budgets, data analysis, and efficiency tables that support the reported fidelities and leakage values.","marker":"[37]"},{"why":"Gives the Deutsch-Jozsa algorithm whose oracle-query structure underlies the hidden-oracle demonstration.","marker":"[38]"}],"fun_headline_variants":["Blind quantum computing goes solid-state on a two-node net","Solid-state blind gates hide client choices from servers","Two-node quantum network achieves blind computing on matter qubits","Matter qubits perform blind quantum gates without leaking the circuit","Distribution of blind quantum gates now possible with solid-state qubits"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The blindness proof assumes that after a successfully heralded gate the servers know only that the gate succeeded; if a real server could also learn the client's interferometer setting, the photon's arrival-time pattern, or the loss history, the measured Holevo information would not upper-bound the true information leakage.","fun_headline_variants_meta":{"raw":{"variants":["Blind quantum computing goes solid-state on a two-node net","Solid-state blind gates hide client choices from servers","Two-node quantum network achieves blind computing on matter qubits","Matter qubits perform blind quantum gates without leaking the circuit","Distribution of blind quantum gates now possible with solid-state qubits"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001029,"raw_usage":{"total_tokens":4354,"prompt_tokens":979,"completion_tokens":3375,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":595,"completion_tokens_details":{"reasoning_tokens":3293}},"tokens_in":595,"tokens_out":3375,"duration_ms":22152,"temperature":1.0,"reasoning_tokens":3293,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T22:51:36.654379+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Re-analyze the recorded data with a server-side classifier that is allowed to condition on the client's TDI choice (short or long delay), the photon arrival time bin, and the sequence of lost versus detected photons; if the mutual information between those conditioned server states and the client's choice of $CZ$ versus identity exceeds one bit, the demonstrated blindness bound no longer describes what a real server could learn.","supporting_citations":[{"cited_title":"In our proposed method, this can be followed by a teleportation to map the operation back to the quantum memory","cited_arxiv_id":null,"evidence_quote":"Defines the universal blind cell and brickwork construction that the demonstrated 1QBG/2QBG decomposition implements."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the blind-quantum-computing framework and verification context for hiding the circuit from the servers."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduces the matter-photon hybrid BQC theory, including the 1QBG and 2QBG definitions realized in this experiment."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates blind rotations on matter qubits, the closest prior experimental step that this work extends to a universal gate set."}],"review_version":1}