{"id":"4e486cd6-2334-4c18-a092-597abd82e892","arxiv_id":"2607.27171","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"OQRAM hides coherent QRAM address states and encrypted data from an untrusted server via offline shuffle/encrypt plus online qPRP or qOTP address masking, with optional decoy checks.","lead":"The paper defines oblivious QRAM: a client can outsource coherent database lookups to a large quantum server without revealing the logical address superposition or plaintext data. It offers a lighter alternative to full blind quantum computing for the common case of private delegated memory access.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.5","headline":"qPRP address-hiding reduction does not justify the Feistel bound once the full permuted layout is in the server view","rationale":"The reader correctly located the load-bearing assumption in the strong-qPRP instantiation and the t < O(N^{1/12}) epoch cap. The sharper failure mode is not that Feistel might be false in the abstract, but that the paper’s own reduction (Lemma 8 + D.1 hybrid order) does not place the server’s real interface inside that abstract game with only t queries: the full C_π layout is π-dependent until encryption is idealized, and materializing it costs N inverse queries that destroy the Feistel bound. This is fixable in principle by hybrid reordering (dummy-encrypt first) or by treating the layout as an ideal random table after qIND-qCPA, after which Lemma 6-style averaging gives strong single-query hiding and Lemma 11 applies with q~t. Until that writeup gap is closed, multi-query amortization and concrete parameter guidance remain conditional—the same CONDITIONAL verdict the reader reached, with correctness_risk still medium. qOTP single-query and the UBQC communication comparison are on firmer ground and are not the primary soft spot. No formal verification or code alters this reading.","tokens_in":28336,"tokens_out":719,"duration_ms":92374,"concrete_test":"Reorder Appendix D.1 hybrids: apply the N-block qIND-qCPA dummy-encryption hybrid before the qPRP-vs-random step; re-run the Lemma 8 reduction on the resulting address-only view with at most q = O(t) bidirectional quantum queries. If the distinguishing advantage is then negligible under the paper’s O(q³/N^{1/4}) Feistel bound for t < O(N^{1/12}), the amortization stands; if the joint layout+address view still forces superpolynomial qPRP queries or non-negligible loss, Thm. 10 / Lemma 11 and the Table 1 refresh frequency need revision.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The central privacy+amortization claim (Thm. 10, Lemmas 8–11, Sec. 7.1) rests on replacing the keyed address qPRP by a uniform random permutation with loss ε_addr(q_addr,λ) from the seven-round Feistel bound O(q³/N^{1/4}), then capping the epoch at t < O(N^{1/12}). Lemma 8’s reduction only says a server distinguishing real vs random π “gives a qPRP distinguisher by using its oracle to generate the protected address registers.” In the actual experiments the server also holds the full layout C_π[j] = Enc(D[π^{-1}(j)]), which a black-box reduction must materialize consistently. Building that layout takes N inverse-permutation evaluations, so q ~ N and the cited Feistel advantage is vacuous. Appendix D.1 keeps the same hybrid order (replace π before dummy-encrypting the N blocks). Without a reordered hybrid (dummy/qIND-qCPA first, so the layout becomes π-independent and only t coherent address queries remain) or an explicit low-query simulation, the concrete multi-query refresh amortization and the computational half of single-query address hiding are not established from the stated assumptions.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The paper proposes Oblivious QRAM (OQRAM), a cryptographic abstraction for privacy-preserving delegated coherent QRAM queries. A lightweight client outsources an encrypted, secretly shuffled database layout and protects each online address state by coherent masking—either a qPRP plus Z-padding (multi-query epochs) or a fresh qOTP (single-query). The server runs ordinary bucket-brigade QRAM on the protected layout; the client unmasks and decrypts. Security is argued by hybrid reductions to strong qPRP and qIND-qCPA (or information-theoretic qOTP address hiding), with decoy query–unquery checks for cheat-sensitive malicious-server detection. Resource claims emphasize Θ(n+m+τ) online quantum communication versus Θ(N) for blinding a full QRAM under UBQC, modest client workspace, and amortized classical refresh when a qPRP layout is reused for t < O(N^{1/12}) queries.","tokens_in":28680,"tokens_out":1590,"duration_ms":44798,"significance":"If the security reductions and amortization hold, the work cleanly fills a gap between classical ORAM / private query and full blind quantum computation: a query-specific primitive that preserves coherent superposition access while keeping client quantum resources near the address and bus registers and cutting quantum communication exponentially relative to circuit-level blinding of QRAM. The protocol split (offline layout refresh vs online masking), the explicit leakage profiles LqPRP and LqOTP, the two-round query-use-unquery wrapper, and the comparison to UBQC are useful contributions for delegated quantum algorithm design. Strengths include standard hybrid structure with appendices spelling out state evolution and proof steps, and an honest scoping of decoys as cheat-sensitive rather than fully verifiable. The result is significant for cloud quantum architectures only insofar as the qPRP multi-query reduction and refresh bound are made rigorous under the server’s actual view (layout plus coherent queries).","major_comments":[{"comment":"Lemma 8, Theorem 10, Lemma 11, and Appendix D.1: the address-hiding hybrid replaces the keyed qPRP π by a uniform random permutation with loss ε_addr(q_addr,λ) drawn from the seven-round Feistel bound O(q³/N^{1/4}) (Thm. 2 / Sec. 2.2), then caps the epoch at t < O(N^{1/12}) (Sec. 7.1). The stated reduction only argues that a distinguisher yields a qPRP adversary “by using its oracle to generate the protected address registers.” In the real experiment the server also holds the full layout C_π[j]=Enc(D[π^{-1}(j)]). A black-box simulation that materializes a π-consistent layout needs N inverse evaluations, so q∼N and the cited Feistel advantage is vacuous. Appendix D.1 keeps this order (replace π in H1 before dummy-encrypting N blocks in H4). Reordering—qIND-qCPA/dummy layout first, so the stored blocks are π-independent and only t coherent address queries remain—or an explicit low-query si","section":"§6.3, Lemma 8, Thm. 10, Lem. 11, App. D.1, §7.1"},{"comment":"Theorem 10’s ideal leakage LqPRP includes the full dephased amplitude multiset {|α_x|² : x∈{0,1}^n}. The text notes that reconstructing this over N addresses needs ~Ω̃(N) copies and that t < N^{1/12} stays “far below the reconstruction regime,” but the theorem statement still treats the entire multiset as allowed leakage after one query. For a single protected query the server sees one diagonal sample in a hidden basis, not the multiset. The leakage profile and simulator in H3–H5 should be tightened to what is actually implied (e.g., one shuffled computational-basis sample, or an explicit multi-copy tomography bound), otherwise the “simulatable from L” claim overstates single-query leakage.","section":"§6.3.1 Theorem 10, Hybrid H3–H5"},{"comment":"Section 5.2 and Proposition 15 give only a generic cheat-sensitivity bound (1−pη)^T with η left as an assumption on the attack family. The inversion decoy tests O²_C★=I and is acknowledged not to certify plaintext correctness; known-answer decoys cover only basis addresses. For the malicious-server contribution to be load-bearing alongside the honest-but-curious theorems, the paper should either derive η for concrete deviation classes (wrong cell, partial measure-and-reprepare, entangling probe) under the protected interface, or clearly demote malicious robustness to a heuristic extension so the main claim rests on the honest-but-curious results alone.","section":"§5.2, §6.5 Proposition 15"}],"minor_comments":[{"comment":"Typographical errors: “single qery” in Theorems 10 and 13 titles; “V ARIANTS” in Section 5 heading; inconsistent C★ vs C_π/C_x notation in places.","section":"Thm. 10, Thm. 13, §5"},{"comment":"Figure 3 is helpful but dense; a short caption walk-through of one amplitude through mask → QRAM → unmask → decrypt would improve readability.","section":"Figure 3"},{"comment":"Table 1 lists client depth with d_A(log q_A)² factors from a reversible arithmetic model that allows multi-qubit Toffoli, fanout, and mid-circuit feedforward (App. E.1). Flag this as an accounting convention in the main-text table caption so readers do not treat the depths as standard two-qubit gate counts.","section":"Table 1, App. E.1"},{"comment":"Related-work placement of quantum PIR / quantum private query is adequate but could more sharply separate “classical record retrieval” from “coherent unitary QRAM” in one sentence of the introduction for non-cryptographers.","section":"§1"},{"comment":"Sec. 4.4 correctly warns that the randomness suffix |r_i⟩ is branch-dependent garbage; consider cross-referencing this limitation in the abstract’s “coherent query” claim so readers expect the two-round uncompute for clean oracles.","section":"§4.4, Abstract"}],"recommendation":"major_revision","confidential_remarks":"The skeptic’s point on hybrid order versus the Feistel query budget is the main correctness risk; it looks fixable by reordering hybrids and rewriting Lemma 8/App. D.1 without enlarging the paper’s scope. I would not reject on novelty grounds: the OQRAM framing and the QRAM-specific resource comparison to UBQC are a reasonable fit for a quant-ph / quantum-crypto venue. Self-citations are architectural and not used as privacy evidence."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The useful takeaway is simple: they carve out a middle ground between classical ORAM/PIR and full blind QC for coherent QRAM queries, and they get online quantum communication down to Θ(n+m+τ) with a thin client. That gap is real, and the packaging (offline encrypted shuffle + coherent address mask, qPRP multi-query vs qOTP single-query, two-round uncompute, decoys) is the actual contribution.\n\nWhat they do well is the systems framing. Client/server asymmetry is explicit, leakage is stated rather than waved away, correctness tracks the layout invariant cleanly, and the honest-but-curious hybrids are the standard ones you expect (Z-dephasing, dummy-database qIND-qCPA, qPRP→random π). The qOTP single-query path is the cleanest piece: address hiding is information-theoretic and the leakage is just public metadata. Resource tables and the UBQC comparison are honest about what is not claimed (full blindness, full verifiability).\n\nSoft spot, in proportion: the stress-test on Lemma 8 / Thm. 10 lands. The reduction that swaps the keyed address qPRP for a random permutation while the server already holds C_π needs N consistent inverse evaluations if you build the layout from a black-box oracle, which blows the Feistel O(q³/N^{1/4}) bound. Their appendix keeps replace-π before dummy-encrypt. Reordering (dummy/qIND first so the layout is π-independent, then only t address queries hit the oracle) almost certainly repairs it and restores t < O(N^{1/12}), but as written the multi-query amortization and the computational half of address hiding are not fully established from the cited assumptions. Secondary limits are already flagged in the paper: multi-query leakage includes the dephased {|α_i|²}, malicious security is only cheat-sensitive decoys, and there are no concrete parameters or code.\n\nWho it is for: people building or analyzing quantum-cloud memory interfaces, not algorithm designers chasing a new speedup. Math and citations look like normal theory-crypto practice; self-cites are architecture context, not load-bearing privacy steps.\n\nI would send it to referees. Fix the hybrid order, keep leakage and epoch bounds explicit, and it is a publishable systems-crypto note. Worth engaging if you care about delegated QRAM privacy; skip if you only want full BQC or machine-checked proofs.","headline":"Solid protocol abstraction for private delegated QRAM, with a real but fixable gap in the qPRP hybrid reduction that undercuts the stated multi-query amortization bound.","tokens_in":29342,"tokens_out":619,"would_cite":true,"duration_ms":33505,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Delegated quantum memory queries can hide the client’s address state and data without full blind quantum computing.","keywords":["oblivious QRAM","delegated quantum query","qPRP","quantum one-time pad","qIND-qCPA","bucket-brigade QRAM","decoy checks","blind quantum computing"],"falsifier":"Exhibit a quantum polynomial-time attack that, within the paper’s allowed epoch length t < O(N^{1/12}), recovers logical address structure or plaintext beyond the stated leakage from the protected address registers and encrypted layout—or show the seven-round Feistel round-function instantiation fails as a strong qPRP under bidirectional quantum queries at those parameters.","tokens_in":29144,"feed_emoji":"🔐","tokens_out":1032,"duration_ms":19454,"temperature":0.7,"pith_summary":"Many quantum algorithms need coherent lookup into a large classical database. When that lookup is outsourced to a remote QRAM server, the server normally sees a quantum superposition of addresses that can leak the algorithm’s private state. This paper defines oblivious QRAM: the client encrypts and secretly reshuffles the database offline, then online masks each coherent address so the server only ever touches protected physical locations and ciphertexts. A qPRP-based mask lets one layout serve multiple queries before a refresh; a qOTP-based mask gives stronger single-query hiding at the cost of refreshing every time. Decy checks give probabilistic detection if the server tampers. The point for a sympathetic reader is practical: a lightweight client keeps only about as many qubits as the query itself, quantum communication stays linear in the address and bus size rather than the whole memory, and privacy for the query interface does not require blinding an entire delegated computation.","feed_headline":"Private quantum memory queries without full blind computing","feed_subtitle":"Masked addresses and shuffled ciphertexts cut quantum communication from whole-memory size to the query registers","key_machinery":"Encrypted shuffled layout plus coherent address masking: offline the client places qIND-qCPA ciphertexts at secret physical addresses (qPRP permutation or qOTP XOR shift); online the client applies U_π Z_z (or X_x Z_z), the server runs ordinary QRAM on the protected layout, and the client unmasks and decrypts. A two-round query-use-unquery cleans an arbitrary bus; decoys test O²=I or known answers against malice.","core_discovery":"Oblivious QRAM realizes the ideal coherent QRAM lookup while an honest-but-curious server’s view is simulatable from small public leakage—database size, ciphertext length, that a lookup occurred, and (for multi-query qPRP epochs) only the unlabeled dephased address weights—under strong qPRP and qIND-qCPA assumptions, or with information-theoretic address hiding via fresh qOTP and per-query refresh. Online quantum communication is Θ(n+m+τ), not Θ(N) as when blinding a full QRAM circuit.","pith_inferences":["Algorithm designers who already express work in the query model could treat OQRAM as a drop-in private oracle if refresh schedules match their query volume.","Sparse database updates inside a live qPRP epoch may fit classical ORAM-style patches better than full rebuild, which the deployment section only sketches.","If strong qPRP instantiations remain expensive in coherent depth, practical deployments may default to qOTP single-query mode until better quantum-friendly permutations exist.","End-to-end privacy for a larger algorithm still needs composition arguments the paper does not supply beyond the QRAM interface."],"forward_implications":["Private delegated QRAM becomes a stand-alone cloud primitive instead of requiring full blind quantum computation for every memory access.","Client online quantum workspace stays O(n+m+ancilla) while the server keeps standard Θ(N) bucket-brigade QRAM scaling.","Quantum communication per query drops exponentially versus blinding the whole QRAM (Θ(n+m+τ) vs Θ(N)).","qPRP epochs amortize classical layout upload over multiple queries; qOTP trades that for information-theoretic single-query address hiding.","Decoy rounds give cheat-sensitive detection of invasive probing, wrong lookup, or coherence breaking, not full verifiability."],"fun_headline_variants":["Oblivious QRAM hides delegated quantum queries from the server","Masked addresses enable private remote QRAM lookups","OQRAM shrinks quantum comms from full memory to query size","Shuffled ciphertexts protect coherent QRAM without full blinding","Delegated quantum queries stay private with address masking"],"cache_read_input_tokens":26240,"weakest_assumption_plain":"Multi-query reuse and the claimed refresh savings rest on treating a concrete seven-round Feistel construction as a strong quantum-secure pseudorandom permutation against a server that sees coherent queries, with epochs short enough that the distinguishing bound still holds.","fun_headline_variants_meta":{"raw":{"variants":["Oblivious QRAM hides delegated quantum queries from the server","Masked addresses enable private remote QRAM lookups","OQRAM shrinks quantum comms from full memory to query size","Shuffled ciphertexts protect coherent QRAM without full blinding","Delegated quantum queries stay private with address masking"]},"model":"grok-4.5","effort":"low","cost_usd":0.004145,"raw_usage":{"total_tokens":1314,"prompt_tokens":826,"num_sources_used":0,"completion_tokens":82,"cost_in_usd_ticks":41448000,"prompt_tokens_details":{"text_tokens":826,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":406,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":826,"tokens_out":82,"duration_ms":8218,"temperature":1.0,"reasoning_tokens":406,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-30T11:12:09.988261+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Exhibit a quantum polynomial-time attack that, within the paper’s allowed epoch length t < O(N^{1/12}), recovers logical address structure or plaintext beyond the stated leakage from the protected address registers and encrypted layout—or show the seven-round Feistel round-function instantiation fails as a strong qPRP under bidirectional quantum queries at those parameters.","supporting_citations":[],"review_version":2}