{"id":"da200f2b-19dd-4bb2-9136-01f4aa2bb0ef","arxiv_id":"2608.09727","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":6,"one_line_summary":"Codes over binary extension fields yield compact qubit magic state distillation protocols, including a 4-to-1 CS protocol at distance 2 on four logical qubits and a 24-to-4 CCZ protocol at distance 3.","lead":"Quantum computers that correct their own errors run on special disposable states called magic states, and making these states is typically the most expensive part of the machine. This paper builds new purification recipes from codes over larger number fields that produce magic states more cheaply, including a four-to-one recipe for CS states that uses only four logical qubits.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The 'outperform state-of-the-art' claim rests on an unvalidated cost model, especially the assumed 10^-6 |CS> cultivation; a sensitivity check of Appendix D would determine whether the Pareto-frontier conclusion is robust.","rationale":"The paper's strongest claim is not merely that the protocols exist, but that they outperform the state-of-the-art in almost every situation. That claim is underwritten by a specific PBC cost model in Appendix D, with self-imposed caps and hand-chosen time costs. The text itself flags the weakest point: cultivation of |CS> states to 10^-6 'has not been studied directly' but is assumed 'entirely reasonable'. This is an explicit admission of missing support for a load-bearing premise. The algebraic constructions and transversality conditions are checkable and largely independent of the benchmark, so I do not object to the existence or validity of the codes. The concern is concentrated in the cost-model layer: if the relative cost of |CS> injection or cultivation differs from the assumed values, the Pareto-frontier conclusion can fail even though every protocol in the catalogue is correct. The reader's conditional verdict already captures this, so I agree with the identified weakest assumption and see no reason to change the verdict. The proposed sensitivity check directly tests whether the headline outperformance claim survives alternative, equally plausible cost assignments.","tokens_in":68651,"tokens_out":3373,"duration_ms":26693,"concrete_test":"Recompute the Pareto frontiers of Figures 1 and 2 using the public SageMath notebooks, varying the cost model one parameter at a time: set the time cost of a |CS> injection to c ∈ {1,2,3} and replace the untested 10^-6 CS-cultivation assumption with a concrete cultivation cost (e.g., derived from [GSJ24] or measured by simulating the cultivation circuit). If a substantial fraction of frontier points switch from novel (red) to existing (blue) protocols, the headline outperformance claim is model-dependent.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section 1.3.2 and Appendix D benchmark concatenated protocols in a Pauli-based computation model with specific cost choices: one time unit per |T> injection, two time units per |CS> injection, concatenated distance capped at 8, spatial footprint capped at 75, and input error 10^-6 modeled by 'some small amount of cultivation'. The paper explicitly says cultivation of |CS> states 'has not been studied directly' (footnote 2) yet treats it as 'entirely reasonable'. The central headline claim—outperforming state-of-the-art in almost every situation—is therefore not an intrinsic property of the new codes but a statement about this cost model. If realistic architectures price |CS> injection differently, or if CS cultivation is significantly more expensive than assumed, the Pareto frontiers in Figures 1-2 shift and the outperformance claim can fail while all algebraic constructions remain valid. The protocols exist as quantum codes; the load-bearing weakness is the unvalidated benchmarking layer that supports the strongest practical claim.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper constructs magic-state distillation protocols for qubits from CSS codes over the binary extension fields F_{2^s}. It packages multi-qubit gates (CS, CCZ, TOF#) as single-Galois-qudit gates, derives algebraic orthogonality conditions for transversality, and constructs finite-length protocols from Reed-Solomon, one-point, Hermitian, elliptic, and Klein-quartic codes. The marquee results are a 4CS→1CS distance-2 protocol, a 24CCZ→4CCZ distance-3 protocol from the F8 Klein quartic, a 64T→2CCZ distance-4 protocol with leading error 2720p^4, and a family of (2k+2)CS→kCS protocols. The final sections benchmark concatenations of these protocols in a Pauli-based computation model and claim effectiveness in almost every considered regime.","tokens_in":68817,"tokens_out":13140,"duration_ms":92750,"significance":"The algebraic constructions are the core contribution, and they appear sound: Lemma 4.2 and Appendix A give explicit, hand-checkable transversality arguments, and the marquee protocols are stated as explicit matrices whose orthogonality can be verified directly. The 4→1 CS and 24→4 CCZ protocols, if correct, are the smallest known factories at these distances, and the trace-code 64T→2CCZ construction improves the leading error coefficient over Haah-Hastings. The linked SageMath notebooks and explicit matrices are reproducibility strengths. The headline benchmarking claims, however, are model-dependent and should not be presented as intrinsic properties of the codes.","major_comments":[{"comment":"The p=10^-6 benchmark relies on the assumption that |CS> states can be cultivated to error ~10^-6 at modest cost, a statement the authors explicitly say has not been studied directly. Because the 'outperform state-of-the-art' conclusion for all 10^-6 cases in Figure 2 rests on this premise, this is a load-bearing unsupported assumption. The authors should either provide a concrete cultivation construction or resource estimate, or explicitly rephrase the claim as conditional on that assumption.","section":"Section 1.3.2 and footnote 2"},{"comment":"The claimed optimality in 'almost every situation' is computed under fixed cost choices: one time unit per |T> injection, two time units per |CS> injection, concatenated distance capped at 8, and footprint capped at 75 logical qubits. These choices are reasonable but not derived from any architecture. A sensitivity analysis varying these parameters is needed; without it, Figures 1 and 2 establish optimality only within this particular cost model, not as an intrinsic property of the new codes.","section":"Section 1.3.2 and Appendix D"}],"minor_comments":[{"comment":"The sentence 'A subset of fields are integral domains, which are integral domains' contains a duplicated phrase and should read 'A subset of fields are integral domains.'","section":"Section 2.2"},{"comment":"The word 'purvue' should be 'purview' in 'although our protocols lie outside the purvue of all of these.'","section":"Section 1.2"},{"comment":"The phrase 'using only 4 logical qubits' for the 4CS→1CS protocol should be cross-referenced to the footprint definition in Section 1.3.2, since the binarized code itself has eight physical qubits and the reported number counts the rows of the generator matrix under the Pauli-based computation model.","section":"Section 1.1 and Table 1"},{"comment":"The index ranges for a, b, c in the twisted three-orthogonality condition should be stated explicitly: the condition is imposed over all rows of the generator matrix, with the nonzero diagonal value allowed only when all three indices coincide and lie among the first k logical rows.","section":"Equation (42)"},{"comment":"The paper states that upper bounds on distances are found by QDistRnd and that upper bounds are brute-force certified when they exceed lower bounds, but the text does not list which table entries were certified in this way. Including the exact verification scripts or certificates in the repository would make the catalogued parameters fully reproducible.","section":"Section 5, Table 3"}],"recommendation":"major_revision","confidential_remarks":"The algebraic contribution is strong and the marquee constructions are checkable by hand, so the main obstacle to acceptance is the cost-model dependence of the headline practical claims. I would advise requesting a sensitivity analysis or a modest rewording of the 'outperform state-of-the-art' claim, rather than rejecting on the basis of the constructions themselves."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Bottom line: this is a substantive construction paper, and the flagship protocols are real. The packaging of multi-qubit CS, CCZ, and TOF# gates into single Galois qudit gates, the F4 and F8 transversality conditions, and the explicit matrices for 4 CS to 1 CS, 24 CCZ to 4 CCZ, 8 CS to 1 TOF#, and 64 T to 2 CCZ are new and checkable. The algebraic core is honest: the constructions come from orthogonality conditions verified directly, and the benchmarks compare against independent prior protocols rather than the paper's own outputs. The citation pattern is fair and the related work is placed accurately.\n\nThe soft spot is exactly where the stress-test note points. The 'outperform state-of-the-art in almost every situation' claim is a statement about the Appendix D cost model, not about the codes. The model's choices—one T injection per time unit, two per CS injection, distance cap 8, footprint cap 75, and especially 10^-6 input errors modeled by assuming CS cultivation is 'entirely reasonable' while admitting it 'has not been studied directly'—are reasonable guesses but not validated. If CS cultivation is significantly more expensive, or if architectures price CS injections differently, the Pareto frontiers in Figures 1 and 2 can shift while every construction in the paper remains correct. The paper would be stronger if it said this more plainly in the abstract and ran sensitivity checks on those assumptions. This is an addressable issue, not a fatal flaw.\n\nThere is a smaller reproducibility caveat. Several Table 3 distances and the MIS-selected logicals come from computational searches, and the linked SageMath notebooks are not commit-hash-pinned or independently re-run. That matters for the distance table, less for the small explicit protocols whose matrices can be checked by hand. The appendices containing the detailed error and footprint derivations were only partially available in the text I saw, so I could not verify all benchmark numbers end to end.\n\nWho this is for: anyone working on magic-state factories or transversal non-Clifford gates. The protocol catalogue alone is worth refereeing, and the algebraic framework will likely be reused. It deserves a serious referee; I would send it to peer review and ask for the benchmarking claims to be separated from the code constructions.","headline":"A substantial construction paper with explicit, checkable protocols; the headline performance claim is real only within an unvalidated cost model and should be softened.","tokens_in":69445,"tokens_out":1821,"would_cite":true,"duration_ms":19285,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P68","94B27","11T71","14G50"],"pacs":["03.67.Pp","03.67.Lx"],"model":"deepseek-v4-flash","headline":"Four noisy CS states produce one clean CS state at distance 2","keywords":["magic state distillation","Galois qudits","binary extension fields","algebraic geometry codes","transversal non-Clifford gates","three-orthogonality","CS and CCZ states","quantum error correction"],"falsifier":"Run the proposed 4$|\\mathrm{CS}\\rangle \\to 1|\\mathrm{CS}\\rangle$ protocol with independent errors on the four inputs and measure output error as a function of input error $p$: distance 2 predicts leading behavior $\\propto p^2$, so any undetectable failure caused by a weight-two input error pattern, or a suppression exponent of one, refutes the claim. For the cost-frontier claim, an independent implementation of the time and space model with an explicitly costed CS-cultivation step that reverses the reported ordering would refute it.","tokens_in":2489,"feed_emoji":"⚛️","tokens_out":6097,"duration_ms":107922,"temperature":0.7,"pith_summary":"This paper claims that distilling the multi-qubit magic states $|\\mathrm{CS}\\rangle$ and $|\\mathrm{CCZ}\\rangle$ becomes much cheaper when the underlying quantum codes are defined over binary extension fields $\\mathbb{F}_{2^s}$ rather than directly over qubits. Multi-qubit gates such as CS and CCZ can be repackaged as simple single-qudit gates over those fields, and a short algebraic condition---three-orthogonality of the code's generator rows---guarantees the gate is transversal, turning the code into a distillation protocol. The headline examples are a protocol that distills 4 $|\\mathrm{CS}\\rangle$ states into 1 $|\\mathrm{CS}\\rangle$ state at distance 2 using only 4 logical qubits, and one that distills 24 $|\\mathrm{CCZ}\\rangle$ states into 4 $|\\mathrm{CCZ}\\rangle$ states at distance 3 using the Klein quartic over $\\mathbb{F}_8$. In a Pauli-based-computation cost model, concatenating these protocols outperforms all published alternatives for almost every distillation task at input error rates $10^{-3}$ and $10^{-6}$. If correct, these are the smallest known factories at their distances and shift the resource-cost frontier for fault-tolerant magic state production.","feed_headline":"Four noisy CS states produce one clean CS state at distance 2","feed_subtitle":"Codes over binary extension fields shrink CCZ factories as well, distilling 24 states to 4 at distance 3.","key_machinery":"The machinery is the X-generator matrix $G \\in \\mathbb{F}_{2^s}^{m \\times n}$ whose first $k$ rows are logical operators and whose remaining rows are stabilizer generators, together with the generalized three-orthogonality identity $\\sum_i g_{a,i}g_{b,i}g_{c,i} = \\delta_{a=b=c}$ (and its twisted variant $\\sum_i g_{a,i}^4 g_{b,i}^2 g_{c,i} = \\delta_{a=b=c}$ for $U_7$). These identities are exactly what make the corresponding single-qudit diagonal gate transversal on the CSS code, so that applying the noisy gate transversally and measuring the syndrome gives a distillation protocol. Codes are built by evaluating monomials on points of low-genus maximal curves over $\\mathbb{F}_4, \\mathbb{F}_8, \\mathbb{F}_{16}, \\mathbb{F}_{32}, \\mathbb{F}_{64}$ (projective line, elliptic curves, Hermitian curves, the Klein quartic), then puncturing selected columns to create logical rows, and finally binarizing through a self-dual basis to obtain qubit codes. The distance of the resulting protocol is the minimum number of input magic states whose failure can cause an undetectable logical error.","core_discovery":"The central discovery is that codes over $\\mathbb{F}_{2^s}$, viewed as Galois qudit codes, reduce the transversality conditions for practically relevant multi-qubit gates to simple identities, and the resulting qubit protocols are unusually compact. The paper shows that the two-qubit CS gate is, in a self-dual basis of $\\mathbb{F}_4$, the single-qudit phase gate $|\\gamma\\rangle \\mapsto i^{\\gamma^3-\\mathrm{tr}(\\gamma)}|\\gamma\\rangle$, and that the three-qubit CCZ gate appears as the three-qudit gate $|x\\rangle|y\\rangle|z\\rangle \\mapsto (-1)^{\\mathrm{tr}(xyz)}|x\\rangle|y\\rangle|z\\rangle$; the $U_7$ gate over $\\mathbb{F}_8$ is a single CCZ. For each such gate the paper derives a linear-algebra condition on the X-generator matrix (three-orthogonality for CS and CCZ, twisted three-orthogonality for $U_7$) that makes the transversal physical gate induce the desired logical gate, and then constructs codes satisfying these conditions from Reed-Solomon codes, affine and projective monomial codes, and algebraic-geometry one-point codes, including punctured codes from maximal curves such as the Hermitian curve and the Klein quartic. Because distance is measured in input magic states, the framework handles the correlated errors present on multi-qubit states by construction.","pith_inferences":["The same Galois-qudit packaging argument suggests a systematic search for compact distillation protocols for any diagonal real-phase multi-qubit gate, using the paper's classification of such gates in the Galois qudit Clifford hierarchy.","If CS cultivation turns out to be cheap in a real architecture, the $10^{-6}$ frontier may shift even further toward the new CS-input protocols; if cultivation is expensive, the T-input protocols remain a robust fallback.","The forbidden-hypergraph maximum-independent-set construction used for the U7 and Klein quartic logicals is an explicit recipe that becomes NP-hard to scale, pointing to SAT-based or symmetry-based searches as the natural next step for finding even smaller factories at larger distances.","Because distance is measured in input magic states rather than qubit codeword weight, a fair architectural comparison with surface-code or qLDPC implementations of the same logic is an open question beyond the paper's Pauli-based-computation model."],"forward_implications":["The $(2k+2)|\\mathrm{CS}\\rangle \\to k|\\mathrm{CS}\\rangle$ family achieves asymptotic overhead 2 at distance 2, and Appendix A.4 proves this overhead is optimal for distance-2 CS distillation from $\\mathbb{F}_4$-linear triorthogonal codes.","The Klein quartic yields a 24-to-4 CCZ protocol at distance 3, reaching rate $1/6$ at distance 3 at small sizes---a regime for which the paper says no previous method is known.","Concatenations of the new protocols sit on the optimal Pareto frontier for almost every CS/CCZ distillation task at input error rates $10^{-3}$ and $10^{-6}$, for both time rate and spacetime volume, under the paper's cost model.","New protocols output exotic states such as TOF# directly (8 CS to 1 TOF# at distance 2, 16 CS to 1 TOF# at distance 3), which can be cheaper than distilling T states and then synthesizing the gate."],"supporting_citations":[{"why":"Supplies the gate-teleportation and twirling template on which all magic state distillation protocols in the paper are built.","marker":"[BK05]"},{"why":"Gives the CSS-code distillation framework and the $(3k+8)T \\to kT$ distance-2 family used as baselines and in concatenations.","marker":"[BH12]"},{"why":"Provides the generalized triorthogonality framework and the synthillation protocols $(7k+4)T \\to k\\mathrm{CS}$ and $(6k+2)T \\to k\\mathrm{CCZ}$ that are the main comparisons in the cost frontier.","marker":"[CH17]"},{"why":"The known 64 T to 2 CCZ distance-4 protocol whose leading error coefficient the new trace-code protocol improves.","marker":"[HH18a]"},{"why":"Introduces the $U_7$ gate and the twisted three-orthogonality condition that this paper generalizes and exploits for CCZ and norm-gate distillation.","marker":"[WHY25]"},{"why":"Establishes the Galois-qudit to qubit mapping for states, CSS codes, and the Clifford hierarchy, which turns the qudit constructions into qubit protocols.","marker":"[Wil26]"},{"why":"Shows that codes over binary extension fields give asymptotically good qubit codes with transversal CCZ, motivating the finite-size practical protocols presented here.","marker":"[Ngu25]"},{"why":"Provides the asymptotic constant-rate distillation results over binary extension fields that the paper builds on for its practical protocols.","marker":"[GG25a]"},{"why":"Supplies the theory of algebraic function fields and one-point codes used to construct and bound the distance of the algebraic-geometry code protocols.","marker":"[Sti08]"},{"why":"Provides the table of defect-zero curves over small binary fields from which the one-point code constructions select their curves.","marker":"[VV00]"}],"fun_headline_variants":["Galois qudit codes shrink magic state factories","CS and CCZ distillation from one code family","Binary field codes beat state-of-the-art magic state distillation","Distance-2 CS distillation from 4 noisy inputs"],"cache_read_input_tokens":71424,"weakest_assumption_plain":"The claim that these protocols beat the state of the art rests on a specific cost accounting---one time unit per T-state injection, two per CS injection, capped concatenation depth of eight, a 75-logical-qubit space limit, and the untested assumption that CS states can be pre-cultivated to $10^{-6}$ error---so if a real architecture prices these operations differently the protocols still work but the frontier claim may not.","fun_headline_variants_meta":{"raw":{"variants":["Galois qudit codes shrink magic state factories","CS and CCZ distillation from one code family","Binary field codes beat state-of-the-art magic state distillation","Distance-2 CS distillation from 4 noisy inputs"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000149,"raw_usage":{"total_tokens":1287,"prompt_tokens":1135,"completion_tokens":152,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":751,"completion_tokens_details":{"reasoning_tokens":90}},"tokens_in":751,"tokens_out":152,"duration_ms":1993,"temperature":1.0,"reasoning_tokens":90,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T11:54:30.245409+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the proposed 4$|\\mathrm{CS}\\rangle \\to 1|\\mathrm{CS}\\rangle$ protocol with independent errors on the four inputs and measure output error as a function of input error $p$: distance 2 predicts leading behavior $\\propto p^2$, so any undetectable failure caused by a weight-two input error pattern, or a suppression exponent of one, refutes the claim. For the cost-frontier claim, an independent implementation of the time and space model with an explicitly costed CS-cultivation step that reverses the reported ordering would refute it.","supporting_citations":[],"review_version":1}