{"id":"5a872c64-3e6c-4dbb-a058-c296c409968b","arxiv_id":"2607.03983","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":4.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A modular composable framework for hardware-efficient, statistically secure verification of quantum computations reduces verifier and prover overheads and extends to multi-party and fault-tolerant regimes.","lead":"This HDR manuscript synthesizes a modular framework for statistically secure verification of delegated quantum computations, splitting it into remote state preparation, traps, and embedding. It shows how to cut hardware demands on the verifier and prover while scaling to multi-party and fault-tolerant settings.","discovery_kind":"review","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified beyond the reader's already-flagged FT assumption.","rationale":"The reader's weakest-assumption diagnosis is accurate and already isolates the only non-trivial modelling choice that is not fully discharged by prior peer-reviewed work. The rest of the manuscript is a clean, consistent re-assembly of published modules; no new formal claim is advanced that could fail independently of those sources. Consequently the CONDITIONAL verdict (valuable architectural guide once the FT modelling assumptions are accepted) stands without adjustment. The concrete test simply verifies that the deferred proofs exist and interface correctly—an elementary bibliographic check that, if passed, leaves the synthesis intact.","tokens_in":49625,"tokens_out":484,"duration_ms":5311,"concrete_test":"Confirm that each of the six cited source papers (LMKO21, KKL+24, KKL+25, KLMO24, GLMO24, KLMO25) contains a complete Abstract-Cryptography security proof for the corresponding module (RSP, dummyless traps, WCP BatchRSP, CRSP, SafeRec FT-RSP) and that the interface signatures match those used in Protocols 5–14 of the present manuscript; any mismatch would break the claimed composability.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The manuscript is an HDR synthesis that explicitly defers all formal security proofs to six earlier peer-reviewed works. Its central claim is architectural: that isolating RSP, trappification and embedding lets hardware requirements be relaxed while statistical security is preserved, and that the same modules extend to multi-party and fault-tolerant settings. Because the reductions are presented only at the resource-interface level and the concrete theorems (e.g., Theorems 5–17) are stated as consequences of the cited papers, there is no independent derivation inside this text that could contain a hidden inconsistency. The only load-bearing condition that is not already discharged by the published literature is precisely the one the reader identified: Chapter 10 grants the verifier logical single-qubit operations on a concatenated Reed-Muller code and models imperfections as independent stochastic compromise events of constant probability pc. That assumption is openly stated (Resource 9, Definitions 13–15, Theorem 15) and is not claimed to hold for a purely physical-qubit verifier. No further soft spot in the modular argument itself is visible.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"This manuscript is a conceptual synthesis (HDR-style) of the author’s prior peer-reviewed works on statistically secure verification of quantum computations. It partitions verification into three composable modules—remote state preparation (RSP), trap-based deviation detection via trappified schemes, and error-correcting embedding—then shows how the modules systematically relax hardware requirements of early VBQC protocols (zero space overhead via round-based repetition, dummyless XY-plane states, trusted rotations or multi-intensity weak coherent pulses) while preserving Abstract Cryptography security. The same modules are extended to asymmetric multi-party computation (via collective RSP) and to gate-level fault-tolerant delegation under a stochastic-compromise noise model.","tokens_in":49840,"tokens_out":904,"duration_ms":12950,"significance":"If the modular reductions hold as claimed, the work supplies a practical architectural blueprint that removes the security-versus-computation trade-off and lowers verifier-side quantum requirements to levels compatible with existing QKD hardware or trusted phase modulators. The explicit composability and the concrete extensions to multi-party and fault-tolerant settings are valuable for hardware vendors and cloud providers. The synthesis itself is useful as a guide; all technical security claims rest on six already-published papers, so the novelty is organizational rather than foundational.","major_comments":[{"comment":"Chapter 10 (Resource 9, Definitions 13–15, Theorems 15–17) grants the verifier the ability to prepare and operate on single logical qubits of a concatenated Reed–Muller code with transversal Z(θ) and models imperfections as independent stochastic compromise events of constant probability pc below a fixed threshold. The quadratic leakage suppression and the threshold theorem rely on these assumptions; if the verifier is restricted to physical single-qubit operations or if compromise events are correlated/adaptive, the side-channel argument fails. The limitation is stated but should be elevated to a clear caveat in the abstract and conclusions so that the claimed “gate-level” robustness is not over-read.","section":"Chapter 10 / Resource 9 / Theorem 15"},{"comment":"All formal security statements (Theorems 5–17) are deferred to the six cited papers; the present text supplies only resource definitions, informal sketches and takeaway claims. While this is appropriate for an HDR synthesis, a journal reader cannot independently verify the load-bearing reductions (detection/insensitivity/correctness → AC security, WCP batch statistics, split-compilation privacy) without consulting the external literature. A short self-contained appendix summarizing the key lemmas, or an explicit statement that the manuscript is not intended to stand alone, would strengthen the submission.","section":"Part II / Theorems 3–5 and subsequent chapters"}],"minor_comments":[{"comment":"Notation for the set of angles Θ and for the flow function f is introduced early but occasionally overloaded (e.g., ϕ′ versus δ). A single consolidated notation table would help.","section":"§2.1"},{"comment":"Figures 2.7–2.9 and 5.1 are helpful but lack captions that explicitly link the pictorial elements (primary/added vertices, trap/dummy/computation labels) to the formal definitions of trappified canvases.","section":"Chapters 2 and 5"},{"comment":"The Foreword and Acknowledgments contain personal and administrative remarks that are customary for an HDR but sit awkwardly in a journal article; they can be shortened or moved to a separate note.","section":"Front matter"},{"comment":"Several citations appear only as arXiv identifiers or “in preparation”; final bibliographic details should be supplied where available.","section":"Bibliography"}],"recommendation":"minor_revision","confidential_remarks":"The manuscript is an HDR synthesis that reorganizes six of the author’s own papers. Its value is pedagogical and architectural rather than the presentation of new theorems. Journals that publish high-level reviews or “perspectives” pieces will find it suitable after the minor revisions above; pure research journals may prefer the original technical papers. The FT assumption is the only substantive caveat and is already openly stated."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is an HDR synthesis, not a primary paper. Ollivier says so up front: every technical claim is taken from the six earlier works (LMKO21, KKL+24, etc.). What is new is the packaging—a single modular story that isolates remote state preparation, trappification, and embedding, then shows how each can be swapped to cut hardware cost while keeping statistical security.\n\nThat packaging works. The three-module split is clean, the resource definitions are consistent with Abstract Cryptography, and the progressive relaxations (zero space overhead via round separation, dummyless XY traps, trusted rotations or multi-intensity WCPs, collective RSP for multi-party, split-compilation for FT) form a coherent narrative. For anyone who has not read the full series, this is the best single entry point. The takeaways at the end of each chapter are honest about remaining caveats.\n\nSoft spots are modest and already flagged by the author. All formal proofs live elsewhere, so this text cannot be checked for hidden inconsistencies on its own; you have to trust the cited papers. The only load-bearing assumption that is not already discharged is in Chapter 10: the verifier is granted single logical-qubit operations on a concatenated Reed-Muller code, and imperfections are independent stochastic compromise events of constant pc. If the verifier is restricted to physical qubits or if compromise is adaptive/correlated, the side-channel argument fails. That limitation is stated openly; it is not smuggled in.\n\nWho it is for: people building or reviewing practical verification stacks, hardware groups deciding whether to expose RSP interfaces, and students who need the architectural picture before diving into the technical papers. It is not a source of new security theorems.\n\nI would send it to a serious referee as an invited survey/synthesis piece. It is not a research article that needs to invent new results, but it is a useful, carefully written guide that the community can use.","headline":"Clean HDR synthesis of the author’s own modular VBQC stack; useful architectural map, no new theorems, FT chapter still needs logical ops on the verifier.","tokens_in":50449,"tokens_out":485,"would_cite":true,"duration_ms":6664,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Lx","03.67.Dd","03.67.Hk"],"model":"grok-4.5","headline":"A modular split of verification into remote state preparation, traps, and embedding lets limited users check untrusted quantum servers with far lighter hardware while keeping statistical security.","keywords":["quantum verification","blind quantum computation","remote state preparation","composability","fault-tolerant delegation","weak coherent pulses","secure multiparty quantum computation","measurement-based quantum computation"],"falsifier":"Construct a concrete attack in which a prover, given only physical single-qubit operations from the verifier or correlated compromise events, extracts secret measurement angles or forces an undetected logical error while still passing the trap tests of the level-k protocol.","tokens_in":50472,"feed_emoji":"🔐","tokens_out":914,"duration_ms":11005,"temperature":0.7,"pith_summary":"A user with only limited quantum resources needs a way to confirm that an untrusted, fully quantum server correctly executed a computation and did not secretly alter the result. This work shows that the task can be cleanly partitioned into three independent primitives—remote state preparation that hides the client’s secrets, trap-based tests that detect harmful deviations, and an embedding that amplifies detection by spreading the real computation across redundant structure. Once the pieces are separate, each can be improved in isolation: the server no longer needs extra qubits per run, the client need never prepare computational-basis dummy states, and single-photon sources can be replaced by trusted rotations or ordinary weak coherent pulses. The same modules also lift to multi-party settings with a single powerful server and to the full fault-tolerant regime under gate-level noise. The result is a practical architectural guide rather than another monolithic protocol.","feed_headline":"Light hardware can verify untrusted quantum servers","feed_subtitle":"Three modules cut prover qubits to zero overhead and replace single-photon sources with lasers or rotations","key_machinery":"The three-module template (remote state preparation + trappified scheme + proper embedding) together with the abstract-cryptography compiler that converts local detection/insensitivity/correctness parameters into a composable security error for the secure delegated quantum computation resource.","core_discovery":"Verification of quantum computations under information-theoretic security reduces to three composable modules—remote state preparation for blindness, trappified canvases for deviation detection, and proper embedding for amplification—whose local properties (detection, insensitivity, correctness) lift directly to global security bounds. Instantiating these modules yields concrete protocols that eliminate spatial overhead on the prover, restrict the verifier to equatorial-plane states or even trusted rotations and weak coherent pulses, and extend without reopening the security ledger to asymmetric multi-party computation and gate-level fault-tolerant delegation.","pith_inferences":["Trap statistics collected during honest runs can double as real-time device characterisation, giving hardware vendors an immediate operational incentive to expose the required interfaces.","The same modular split should translate almost unchanged into the circuit model, removing any dependence on measurement-based computation for superconducting platforms.","If the remaining open question—statistical soundness with a fully classical client—can be solved inside the same modules, the hardware barrier for verification would drop to zero."],"forward_implications":["Provers can run verified BQP computations with zero extra qubits per computation round, only sequential test rounds.","Verifiers can replace cryogenic single-photon sources with phase modulators plus random bit flips, or with off-the-shelf attenuated lasers, while retaining statistical security.","A classical secure multiparty computation among light clients plus one quantum server yields composable multi-party quantum computation for classical-input classical-output tasks.","Once the verifier can handle single logical qubits, gate-level noise below a constant threshold no longer forces abort or leaks secrets, so verification scales with circuit size."],"fun_headline_variants":["Three modules verify untrusted quantum servers with light hardware","Modular primitives cut quantum verification to zero prover overhead","Remote states, traps and embedding enable efficient quantum checks","Trusted rotations replace single photons for quantum server verification","Composable modules scale quantum verification to noisy fault-tolerant cases"],"cache_read_input_tokens":32896,"weakest_assumption_plain":"In the fault-tolerant extension the verifier must be able to prepare and operate on single logical qubits of a concatenated code, and physical imperfections must behave as independent stochastic compromise events of constant probability below a fixed threshold.","fun_headline_variants_meta":{"raw":{"variants":["Three modules verify untrusted quantum servers with light hardware","Modular primitives cut quantum verification to zero prover overhead","Remote states, traps and embedding enable efficient quantum checks","Trusted rotations replace single photons for quantum server verification","Composable modules scale quantum verification to noisy fault-tolerant cases"]},"model":"grok-4.5","effort":"low","cost_usd":0.003722,"raw_usage":{"total_tokens":1137,"prompt_tokens":775,"num_sources_used":0,"completion_tokens":77,"cost_in_usd_ticks":37220000,"prompt_tokens_details":{"text_tokens":775,"audio_tokens":0,"image_tokens":0,"cached_tokens":0},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":285,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":775,"tokens_out":77,"duration_ms":3071,"temperature":1.0,"reasoning_tokens":285,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-11T22:32:12.039079+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Construct a concrete attack in which a prover, given only physical single-qubit operations from the verifier or correlated compromise events, extracts secret measurement angles or forces an undetected logical error while still passing the trap tests of the level-k protocol.","supporting_citations":[],"review_version":1}