{"id":"8ebc3678-9cb5-47ab-98a0-09b38ff714b5","arxiv_id":"2605.24166","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"Aligning DP noise to the dominant QFI eigenmode of a quantum embedding yields minimax-optimal privacy bounds with claimed large advantage over isotropic depolarizing and classical DP.","lead":"This paper argues that quantum differential privacy should add noise along the Quantum Fisher Information eigenmodes of a data embedding, not isotropically. If right, cloud quantum ML could get far tighter privacy at the same accuracy by exploiting embedding geometry and even hardware decoherence.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.5","headline":"Central optimality (Thm 3.1) rests on Lemma 2.4’s first-order F_eff contraction and the local max-divergence coefficient Δ²/2, neither of which is controlled beyond small-γ/small-Δ expansions.","rationale":"The reader correctly isolates the load-bearing soft spot: everything downstream of Thm 3.1 (advantage ratio, composition saturation, uncertainty relation, experimental ε claims) inherits the validity of Lemma 2.4 plus the local D_∞↔QFI conversion. My reading finds no deeper internal inconsistency that would overturn the geometric idea itself; the asymptotic mis-statement (Ω(d) written for ln d) is real but secondary once the local contraction is granted. The proposed numerical check is decisive, inexpensive on the paper’s own 4-qubit embedding, and directly falsifies or corroborates the two approximations. Because the concern is already the reader’s weakest_assumption and does not introduce a new fatal flaw, the CONDITIONAL verdict and MODERATE confidence remain appropriate; only the concrete validation (or a fully rigorous remainder-controlled proof of Lemma 2.4) would move the needle.","tokens_in":27145,"tokens_out":867,"duration_ms":32602,"concrete_test":"On the exact 4-qubit anisotropic circuit of Sec. 10.2 (α=[3.0,1.0,0.3,0.1]), compute the true quantum max-divergence D_∞(Φ_{γ,p*}(ρ_x), Φ_{γ,p*}(ρ_{x+Δ u_1})) by SDP (or by the closed-form pure-state formula after purification) for a grid of γ∈{0.01,0.05,0.1,0.2} and Δ up to the paper’s sensitivity; compare each value to the predicted (Δ²/2)λ_max(1−cγ) with the paper’s c. If the relative discrepancy exceeds 20 % for any point with γ≥0.1 or Δ≥0.1, the ε* formula and the optimality claim do not hold as stated.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The strongest claim (minimax concentration p*_1=1 yielding ε*=(Δ²/2)λ_max(1−cγ) and the stated advantage) is derived entirely from two linked approximations: (i) Lemma 2.4’s effective-QFI formula F_eff_ij = Σ_k λ_k(1−cγ p_k+O(γ²))⟨u_k|e_i⟩⟨e_j|u_k⟩ with a single calibration constant c∈(0,2], obtained by expanding the fidelity of the metric-adapted mixture to first order in γ after replacing the generators by infinitesimal shifts U_k≈I+iη_k G_k; and (ii) the local conversion D_∞≈(Δ²/2)λ_max of Sec. 2.4–2.5 (Eqs. 7–8), which begins from the pure-state fidelity expansion |⟨ψ|ψ+dx⟩|²=1−(1/4)dx^T F dx and then invokes an unspecified “refined calculation [27]” to replace the coefficient 1/4 by 1/2. Both steps are used without remainder bounds that would guarantee the max_k λ_k(1−cγ p_k) still dominates for finite, implementable η_k and for the Δ values appearing in the experiments. If either the O(γ²) terms or the higher-order Bures/max-divergence contributions re-order the effective eigenvalues, or if the concrete unitaries U_k fail to realize pure directional contraction, the minimax argument and the Ω(d/λ_max) (actually ∼ln d/λ_max) advantage collapse. The KKT derivation in A.2 is conditional on those two approximations and therefore inherits the same gap.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The paper proposes a geometry-aware quantum differential privacy framework that replaces isotropic depolarizing noise with a metric-adapted channel aligned to the Quantum Fisher Information (QFI) eigenstructure of a quantum embedding. It proves six main results: (1) minimax-optimal noise concentrates on the dominant QFI mode, giving ε* = (Δ²/2)λ_max(1−cγ) and a claimed advantage over isotropic depolarizing; (2) mixed-state SLD decomposition showing that aligned dephasing can increase accessible information while misaligned dephasing amplifies privacy; (3) a privacy–utility uncertainty relation; (4) adaptive EMA QFI estimation with O(1/√n) convergence; (5) QFI-aligned composition that saturates at O(1) when successive layers share eigenvectors; and (6) constructive use of hardware noise. Corollaries cover adversarial attacks, Wasserstein bounds, subspace projection, and a Merkle-tree ZK audit. Validation uses Qiskit Aer, IBM ibm_fez, and classical DP baselines on anisotropic embeddings.","tokens_in":27693,"tokens_out":1795,"duration_ms":30491,"significance":"If the technical claims hold under controlled approximations, the work is significant: it cleanly exploits the metrology–privacy duality of QFI, gives a concrete minimax design principle (spend the budget on λ_max), and produces composition and hardware-noise results that are not available from isotropic quantum DP. Strengths include an explicit metric-adapted channel, full appendix proofs, adaptive tracking, a practical audit protocol, and hardware runs on ibm_fez plus classical baselines. The constructive dephasing result (misaligned hardware noise as a privacy resource) is of independent NISQ interest. These contributions would matter for private QML on cloud quantum services, provided the local expansions and advantage scalings are repaired and stated accurately.","major_comments":[{"comment":"Abstract and Theorem 3.1 (Eq. 13) claim an advantage R = ε_iso/ε* = Ω(d/λ_1) or O(d/λ_max). The isotropic baseline used is ε_iso = ln(1 + d/(γ(1−γ))) ∼ ln d, so the ratio scales as O((ln d)/λ_max), not Ω(d/λ_max). The proof text itself writes “R ∼ ln d/λ_1 = Ω(d/λ_1),” which is incorrect. This overstates the central quantitative claim in the abstract, introduction, and theorem statement and must be corrected throughout (including experimental extrapolations that invoke the same scaling).","section":null},{"comment":"Lemma 2.4 and Sec. 2.4–2.5 are load-bearing for Theorem 3.1: optimality and ε* rest on F_eff with a single calibration constant c and on the local conversion D_∞ ≈ (Δ²/2)λ_max. Both are first-order small-γ / small-Δ expansions (fidelity of the metric-adapted mixture; pure-state fidelity expansion with a “refined” coefficient change from 1/4 to 1/2 citing Helstrom). There are no remainder bounds showing that max_k λ_k(1−cγ p_k) still dominates for finite implementable η_k and the Δ, γ used in experiments. If O(γ²) or higher-order Bures/max-divergence terms reorder effective eigenvalues, or if U_k fail to realize pure directional contraction, the minimax argument and advantage claims fail. Please supply controlled remainders or numerical verification of the effective spectrum for the concrete generators.","section":null},{"comment":"Theorem 3.6 / Appendix A.3: the product bound derivation inserts a factor γ/d into ε·(1−F_min), then appeals to “lim γ\to0 and optimal γ” to recover ε·(1−F_min) ≥ (Δ²/2) Tr(F)/d without that factor. As written this step is not justified (the lower bound vanishes as γ\to0). Either fix the derivation with a γ-independent argument or weaken the claimed tight uncertainty relation and its abstract statement.","section":null},{"comment":"Theorem 8.1’s O(1) saturation assumes successive layers share QFI eigenvectors (and the same λ_max contraction). The manuscript states this, but the abstract and contribution list present saturating composition as a general principal theorem. Please scope the claim to the aligned case, and either bound the misaligned interpolation (mentioned as open in Sec. 11.3) or mark composition advantage as conditional in the abstract/results summary.","section":null}],"minor_comments":[{"comment":"Sec. 2.4: the jump from D_∞ ≈ (1/4) dx^T F dx to coefficient Δ²/2 via “refined calculation [27]” should be spelled out or given a self-contained derivation; Helstrom is primarily estimation theory.","section":null},{"comment":"Fig. 1 caption and circuit description are useful; ensure α = [3.0,1.0,0.3,0.1] and the reported λ spectrum are consistent across Sec. 10.2 (λ ≈ [9,9,0.09,0.09]) and later adversarial numbers (λ ≈ [11.2,…]).","section":null},{"comment":"Classical DP comparison (Fig. 11, ε ≈ 0.001 vs ≈ 4800) should state explicitly that noise is applied to different objects (kernel entries vs QFI-aligned channel); otherwise the 10^6\times claim can be misread as a like-for-like mechanism comparison.","section":null},{"comment":"Notation: c ∈ (0,2] is free in Lemma 2.4 but often set to 1; state the experimental default and sensitivity of reported factors (1.92\times, 9\times, 308\times) to c.","section":null},{"comment":"Related work is thorough; a short explicit contrast with Hirche et al. Rényi quantum DP on composition tightness would help place Theorem 8.1.","section":null},{"comment":"Typos/formatting: “Privacy− utility” spacing in abstract; Algorithm 1 is referenced as Fig. 2; ensure theorem numbering in figures (“Thm 10”, “Thm 11”) matches the body.","section":null}],"recommendation":"major_revision","confidential_remarks":"The geometric idea and hardware angle are publishable after correction; the main risk is overclaiming (advantage Ω(d/λ), “tight” uncertainty relation, unconditional composition). I would not reject on novelty grounds—the QFI-to-DP mechanism design link is real—but the abstract should not go out with the d vs ln d error. Fit for a solid quant-ph / QML venue after major revision."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The useful core is clear: treat the QFI spectrum of a quantum embedding as the privacy sensitivity metric, put the whole noise budget on the largest eigenmode, and get a tighter local ε than isotropic depolarizing. That minimax allocation (p*_1=1), the mixed-state dephasing paradox with constructive misalignment, and the saturating QFI-aligned composition are the pieces that look new relative to Aaronson–Rothblum, Zhou–Ying, Zou et al., and the Rényi quantum-DP line. The duality framing (metrology vs privacy) is clean, the related-work section is honest, and the experiments on anisotropic 4-qubit embeddings plus ibm_fez Hellinger checks are at least directionally consistent with the story.\n\nWhat the paper does well is keep the geometry front and center and derive several corollaries (subspace projection, adaptive EMA, ZK Merkle audit) from the same object. The composition saturation to O(1) when eigenbases align is the result I would actually want to use for deep variational circuits if the assumptions hold.\n\nSoft spots, in proportion. The abstract and Theorem 3.1 claim O(d/λ_max) advantage while the proof itself only gets ~ln d / λ_max; writing R∼ln d/λ_1=Ω(d/λ_1) is simply incorrect and should be fixed. More load-bearing: Lemma 2.4’s first-order F_eff contraction with a free c∈(0,2] and the local D_∞≈(Δ²/2)λ_max conversion (the 1/4→1/2 jump is waved at Helstrom) have no remainder control. The KKT argument inherits that gap; if higher-order terms reorder the effective eigenvalues for implementable unitaries, the optimality claim weakens. The privacy–utility uncertainty proof is sketchy, and the classical Gaussian/Laplace comparison (ε≈0.001 vs 4800) is not threat-model matched. IBM results only give computational-basis Hellinger lower bounds, not full fidelity. None of this kills the idea; it means the strongest asymptotic and optimality statements need tightening before they can be trusted at face value.\n\nWho it is for: people building private QML on cloud QPUs who already think in QFI/natural-gradient language. A serious referee should see it—novelty and potential impact inside quantum DP are real enough—but expect revision on the scaling claim, remainder bounds, and matched baselines. I would engage after those fixes; I would not cite the current advantage formula as written.","headline":"Solid geometric idea for quantum DP—noise on the dominant QFI mode, plus constructive dephasing and saturating composition—but the headline advantage scaling is wrong and the optimality proof sits on uncontrolled local expansions.","tokens_in":28332,"tokens_out":631,"would_cite":true,"duration_ms":7877,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Quantum privacy is tightest when noise is aimed only at the single most leaky direction of a quantum embedding, not spread evenly.","keywords":["quantum differential privacy","quantum Fisher information","metric-adapted channel","minimax noise allocation","dephasing privacy amplification","QFI composition","quantum embeddings"],"falsifier":"Implement the claimed metric-adapted generators on a device or high-fidelity simulator, measure the actual max-divergence between neighboring embeddings for a known anisotropic QFI spectrum, and check whether the observed ε matches (Δ²/2)·λmax·(1−cγ) rather than the isotropic formula or a weaker intermediate bound.","tokens_in":27990,"feed_emoji":"🔒","tokens_out":686,"duration_ms":6832,"temperature":0.7,"pith_summary":"This paper treats the Quantum Fisher Information of a quantum data embedding as the privacy sensitivity map: directions with large QFI eigenvalues are easy for an adversary to distinguish, while low-QFI directions are already hard to tell apart. Instead of the usual isotropic depolarizing channel that adds the same noise in every Hilbert-space direction, the authors design a metric-adapted channel that spends the entire noise budget on the single largest QFI eigenmode. They prove this allocation is minimax-optimal for the worst-case privacy parameter, yields an advantage that grows with Hilbert-space dimension, and comes with a privacy–utility uncertainty relation, adaptive estimation, composition that saturates rather than growing with depth, and a constructive use of hardware dephasing when it is misaligned with the adversary’s measurement. Experiments on simulators and IBM hardware report equivalent utility at privacy parameters orders of magnitude smaller than classical DP baselines. The practical stake is that geometry-aware quantum DP can make private quantum machine learning feasible where isotropic noise would destroy utility or exhaust the privacy budget.","feed_headline":"Aim noise at one quantum direction for far tighter privacy","feed_subtitle":"Geometry-aware DP beats isotropic noise by a factor that grows with Hilbert-space size","key_machinery":"The metric-adapted channel Φγ,p, which replaces isotropic depolarizing with a mixture of unitaries that shift the state along QFI eigenvectors, together with the first-order effective-QFI formula that contracts each mode by (1−cγ pk). Privacy is then controlled by max_k λk(1−cγ pk).","core_discovery":"For a quantum embedding whose QFI eigenvalues are ordered λ1 ≥ λ2 ≥ ⋯, the minimax-optimal DP mechanism concentrates the entire noise budget on the dominant eigenmode alone. The resulting privacy parameter is ε* = (Δ²/2)·λ1·(1−cγ), which improves on isotropic depolarizing by a factor that scales as Ω(d/λ1) and saturates under aligned multi-layer composition.","pith_inferences":[],"forward_implications":[],"fun_headline_variants":["Concentrate DP noise on dominant QFI eigenmode alone","QFI-aligned noise yields minimax-optimal quantum privacy","Dump full noise budget into top Fisher mode for tighter ε","Spectral QFI geometry beats isotropic depolarizing DP","Optimal quantum DP via single-eigenmode noise focus"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"The argument rests on a local, first-order model of how the metric-adapted channel contracts the QFI and on the claim that worst-case privacy after the channel is fully captured by that contracted maximum eigenvalue.","fun_headline_variants_meta":{"raw":{"variants":["Concentrate DP noise on dominant QFI eigenmode alone","QFI-aligned noise yields minimax-optimal quantum privacy","Dump full noise budget into top Fisher mode for tighter ε","Spectral QFI geometry beats isotropic depolarizing DP","Optimal quantum DP via single-eigenmode noise focus"]},"model":"grok-4.5","effort":"low","cost_usd":0.005024,"raw_usage":{"total_tokens":1442,"prompt_tokens":907,"num_sources_used":0,"completion_tokens":81,"cost_in_usd_ticks":50240000,"prompt_tokens_details":{"text_tokens":907,"audio_tokens":0,"image_tokens":0,"cached_tokens":0},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":454,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":907,"tokens_out":81,"duration_ms":4104,"temperature":1.0,"reasoning_tokens":454,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-14T18:45:52.660158+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Implement the claimed metric-adapted generators on a device or high-fidelity simulator, measure the actual max-divergence between neighboring embeddings for a known anisotropic QFI spectrum, and check whether the observed ε matches (Δ²/2)·λmax·(1−cγ) rather than the isotropic formula or a weaker intermediate bound.","supporting_citations":[],"review_version":2}