REVIEW 2 major objections 4 minor 49 references
Verification of Quantum Computations: Hardware-Efficient Security Proofs
T0 review · 2 major / 4 minor · reviewed 2026-07-11 · grok-4.5
Pith's one-line read A modular split of verification into remote state preparation, traps, and embedding lets limited users check untrusted quantum servers with far lighter hardware while keeping statistical security.
desk verdict Clean HDR synthesis of the author’s own modular VBQC stack; useful architectural map, no new theorems, FT chapter still needs logical ops on the verifier. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The three-module template (remote state preparation + trappified scheme + proper embedding) together with the abstract-cryptography compiler that converts local detection/insensitivity/correctness parameters into a composable security error for the secure delegated quantum computation resource.
What would settle it
Construct a concrete attack in which a prover, given only physical single-qubit operations from the verifier or correlated compromise events, extracts secret measurement angles or forces an undetected logical error while still passing the trap tests of the level-k protocol.
Extended reading notes
Core claim
Verification of quantum computations under information-theoretic security reduces to three composable modules—remote state preparation for blindness, trappified canvases for deviation detection, and proper embedding for amplification—whose local properties (detection, insensitivity, correctness) lift directly to global security bounds. Instantiating these modules yields concrete protocols that eliminate spatial overhead on the prover, restrict the verifier to equatorial-plane states or even trusted rotations and weak coherent pulses, and extend without reopening the security ledger to asymmetric multi-party computation and gate-level fault-tolerant delegation.
Load-bearing premise
In the fault-tolerant extension the verifier must be able to prepare and operate on single logical qubits of a concatenated code, and physical imperfections must behave as independent stochastic compromise events of constant probability below a fixed threshold.
Editorial extensions
If this is right
- Provers can run verified BQP computations with zero extra qubits per computation round, only sequential test rounds.
- Verifiers can replace cryogenic single-photon sources with phase modulators plus random bit flips, or with off-the-shelf attenuated lasers, while retaining statistical security.
- A classical secure multiparty computation among light clients plus one quantum server yields composable multi-party quantum computation for classical-input classical-output tasks.
- Once the verifier can handle single logical qubits, gate-level noise below a constant threshold no longer forces abort or leaks secrets, so verification scales with circuit size.
Reading between the lines
- Trap statistics collected during honest runs can double as real-time device characterisation, giving hardware vendors an immediate operational incentive to expose the required interfaces.
- The same modular split should translate almost unchanged into the circuit model, removing any dependence on measurement-based computation for superconducting platforms.
- If the remaining open question—statistical soundness with a fully classical client—can be solved inside the same modules, the hardware barrier for verification would drop to zero.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This manuscript is a conceptual synthesis (HDR-style) of the author’s prior peer-reviewed works on statistically secure verification of quantum computations. It partitions verification into three composable modules—remote state preparation (RSP), trap-based deviation detection via trappified schemes, and error-correcting embedding—then shows how the modules systematically relax hardware requirements of early VBQC protocols (zero space overhead via round-based repetition, dummyless XY-plane states, trusted rotations or multi-intensity weak coherent pulses) while preserving Abstract Cryptography security. The same modules are extended to asymmetric multi-party computation (via collective RSP) and to gate-level fault-tolerant delegation under a stochastic-compromise noise model.
Significance. If the modular reductions hold as claimed, the work supplies a practical architectural blueprint that removes the security-versus-computation trade-off and lowers verifier-side quantum requirements to levels compatible with existing QKD hardware or trusted phase modulators. The explicit composability and the concrete extensions to multi-party and fault-tolerant settings are valuable for hardware vendors and cloud providers. The synthesis itself is useful as a guide; all technical security claims rest on six already-published papers, so the novelty is organizational rather than foundational.
major comments (2)
- [Chapter 10 / Resource 9 / Theorem 15] Chapter 10 (Resource 9, Definitions 13–15, Theorems 15–17) grants the verifier the ability to prepare and operate on single logical qubits of a concatenated Reed–Muller code with transversal Z(θ) and models imperfections as independent stochastic compromise events of constant probability pc below a fixed threshold. The quadratic leakage suppression and the threshold theorem rely on these assumptions; if the verifier is restricted to physical single-qubit operations or if compromise events are correlated/adaptive, the side-channel argument fails. The limitation is stated but should be elevated to a clear caveat in the abstract and conclusions so that the claimed “gate-level” robustness is not over-read.
- [Part II / Theorems 3–5 and subsequent chapters] All formal security statements (Theorems 5–17) are deferred to the six cited papers; the present text supplies only resource definitions, informal sketches and takeaway claims. While this is appropriate for an HDR synthesis, a journal reader cannot independently verify the load-bearing reductions (detection/insensitivity/correctness → AC security, WCP batch statistics, split-compilation privacy) without consulting the external literature. A short self-contained appendix summarizing the key lemmas, or an explicit statement that the manuscript is not intended to stand alone, would strengthen the submission.
minor comments (4)
- [§2.1] Notation for the set of angles Θ and for the flow function f is introduced early but occasionally overloaded (e.g., ϕ′ versus δ). A single consolidated notation table would help.
- [Chapters 2 and 5] Figures 2.7–2.9 and 5.1 are helpful but lack captions that explicitly link the pictorial elements (primary/added vertices, trap/dummy/computation labels) to the formal definitions of trappified canvases.
- [Front matter] The Foreword and Acknowledgments contain personal and administrative remarks that are customary for an HDR but sit awkwardly in a journal article; they can be shortened or moved to a separate note.
- [Bibliography] Several citations appear only as arXiv identifiers or “in preparation”; final bibliographic details should be supplied where available.
Circularity Check
HDR synthesis defers all proofs to prior peer-reviewed works by the author; no self-definitional loops, fitted predictions, or forced uniqueness inside this text.
-
self citation load bearing
[Foreword + Chapter 4 (Framework) + Theorems 5, 6, 9, 11, 14, 15–17]
"this manuscript is synthesized from the following works: [LMKO21, KKL+24, KKL+25, KLMO24, GLMO24, KLMO25]. … Rather than duplicating the dense technical proofs of the underlying publications, our focus here is on the physical motivations, the structural connections … Theorem 5. Security and Noise-Robustness of Protocol 4, Theorem 13 from [KKL+24]"
Every concrete security bound and module property is justified solely by citation to the author’s own prior papers. In an HDR this is expected and does not create a definitional loop, but it does make the present text non-self-contained for the load-bearing claims.
full rationale
The manuscript is explicitly a conceptual synthesis (Foreword, Abstract) of six earlier publications [LMKO21, KKL+24, KKL+25, KLMO24, GLMO24, KLMO25]. Every security theorem (Theorems 1–17), resource definition, and protocol is stated as a consequence of those works; the present text supplies only modular interfaces, physical motivations, and architectural takeaways. No quantity is defined in terms of a later claim, no parameter is fitted to data and then re-presented as a prediction, and no uniqueness theorem is imported solely to forbid alternatives. Self-citation is load-bearing only in the ordinary sense that an HDR reviews the candidate’s own results; those results were independently published and peer-reviewed, so they constitute external evidence under the evaluation rules. The sole non-trivial modeling assumption (stochastic compromise events of constant pc for the FT extension) is openly declared (Resource 9, Definitions 13–15) rather than smuggled. Consequently the derivation chain contains no circular reduction.
Assumptions & free parameters
assumptions (5)
- domain assumption Abstract Cryptography (Maurer-Renner) composability: sequential and parallel composition of resources preserves security up to additive distinguishing advantage.
- domain assumption Any adversarial CPTP map on a UBQC-encrypted computation reduces, via Pauli twirling, to a convex combination of Pauli operators.
- standard math For classical-I/O MBQC there exists a non-trivial Pauli deviation (product of Z on odd-degree vertices) that leaves the output distribution invariant.
- ad hoc to paper Physical imperfections on the verifier side are independent stochastic compromise events of constant probability pc below a fixed threshold.
- domain assumption The [[15,1,3]] Reed-Muller code admits transversal Z(θ) and two consecutive EC blocks erase syndrome dependence on secret angles unless both are compromised.
invented entities (3)
-
Trappified canvas / trappified scheme
-
Remote Rotation with Dephasing (RRD) resource
-
BatchRSP resource constructed from multi-intensity WCPGenerator
Cite this review
Pith. "Pith review of Verification of Quantum Computations: Hardware-Efficient Security Proofs." pith.science (2026). https://pith.science/paper/3BO3ZP3E
@misc{pith2026260703983,
author = {Pith},
title = {Pith review of: Verification of Quantum Computations: Hardware-Efficient Security Proofs},
year = {2026},
howpublished = {\url{https://pith.science/paper/3BO3ZP3E}},
note = {Machine review of arXiv:2607.03983}
}
read the original abstract
How can a user with limited quantum resources verify the output of an untrusted, fully quantum server? This manuscript provides a conceptual synthesis of some recent developments toward answering this question under statistical (information-theoretic) security. Rather than duplicating the dense technical proofs of the underlying publications, our focus here is on the physical motivations, the structural connections between different protocols, and the path toward hardware-efficient implementation. We begin by introducing a modular, composable framework that partitions verification into three distinct, independent primitives: remote state preparation, trap-based deviation detection, and error-correcting embedding. Using this framework, we show how the demanding hardware requirements of early protocols can be systematically relaxed. We review schemes that eliminate the spatial overhead, remove the need to prepare computational-basis dummy states, and replace single-photon sources with trusted local rotations or weak coherent pulses. Finally, we examine how these techniques scale, both to asymmetric multi-party settings and to the delegation of fully fault-tolerant computations in the presence of gate-level noise. This document is intended as a guide to the architectural principles of practical quantum verification.
Reference graph
Works this paper leans on
-
[1]
Interactive proofs for quantum computation
Dorit Aharonov, Michael Ben-Or, and Elad Eban. Interactive proofs for quantum computation. In Proceedings of Innovations of Computer Science (ICS 2010) , page 453–469, 2010
2010
-
[2]
Interactive proofs for quantum computations
Dorit Aharonov, Michael Ben-Or, Elad Eban, and Urmila Mahadev. Interactive proofs for quantum computations. arxiv:1704.04487 , 2017. Updated and corrected version of arxiv:0810.5375
arXiv 2017
-
[3]
Requirements for a processing-node quantum repeater on a real-world fiber grid
Guus Avis, Francisco Ferreira da Silva, Tim Coopmans, Axel Dahlberg, Hana Jirovská, David Maier, Julian Rabbie, Ariana Torres-Knoop, and Stephanie Wehner. Requirements for a processing-node quantum repeater on a real-world fiber grid. npj Quantum Information , 9(1), October 2023
2023
-
[4]
Quantum accuracy threshold for concatenated distance-3 codes
Panos Aliferis, Daniel Gottesman, and John Preskill. Quantum accuracy threshold for concatenated distance-3 codes. Quant. Inf. Comput. , 6:97--165, 2006
2006
-
[5]
Vazirani
Dorit Aharonov and Umesh V. Vazirani. Is Quantum Mechanics Falsifiable? A Computational Perspective on the Foundations of Quantum Mechanics , page 329–350. The MIT Press, June 2013
2013
-
[6]
Security Limitations of Classical-Client Delegated Quantum Computing , page 667–696
Christian Badertscher, Alexandru Cojocaru, Léo Colisson, Elham Kashefi, Dominik Leichtle, Atul Mantri, and Petros Wallden. Security Limitations of Classical-Client Delegated Quantum Computing , page 667–696. Springer International Publishing, 2020
2020
-
[7]
Universal blind quantum computation
Anne Broadbent, Joseph Fitzsimons, and Elham Kashefi. Universal blind quantum computation. In IEEE, editor, 50th Annual IEEE Symposium on Foundations of Computer Science , 2009
2009
-
[8]
Generalized flow and determinism in measurement-based quantum computation
Daniel E Browne, Elham Kashefi, Mehdi Mhalla, and Simon Perdrix. Generalized flow and determinism in measurement-based quantum computation. New Journal of Physics , 9(8):250, 2007
2007
Show all 49 references
-
[9]
Secure multiparty quantum computation with (only) a strict honest majority
Michael Ben-Or, Claude Crepeau, Daniel Gottesman, Avinatan Hassidim, and Adam Smith. Secure multiparty quantum computation with (only) a strict honest majority. In Proceedings of the 47th Annual IEEE Symposium on Foundations of Computer Science , FOCS '06, pages 249--260, Wash...
2006
-
[10]
How to verify a quantum computation
Anne Broadbent. How to verify a quantum computation. Theory of Computing , 14(11):1--37, 2018
2018
-
[11]
Secure multi-party quantum computation
Claude Cr \'e peau, Daniel Gottesman, and Adam Smith. Secure multi-party quantum computation. In Proceedings of the Thiry-fourth Annual ACM Symp. on Theory of Computing , STOC '02, page 643, New York, NY, USA, 2002. ACM
2002
-
[12]
Exact and approximate unitary 2-designs and their application to fidelity estimation
Christoph Dankert, Richard Cleve, Joseph Emerson, and Etera Livine. Exact and approximate unitary 2-designs and their application to fidelity estimation. Physical Review A , 80(1), July 2009
2009
-
[13]
Fitzsimons, Christopher Portmann, and Renato Renner
Vedran Dunjko, Joseph F. Fitzsimons, Christopher Portmann, and Renato Renner. Composable security of delegated quantum computation. In Palash Sarkar and Tetsu Iwata, editors, Advances in Cryptology -- ASIACRYPT 2014 , pages 406--425, Berlin, Heidelberg, 2014. Springer Berlin H...
2014
-
[14]
Grilo, Stacey Jeffery, Christian Majenz, and Christian Schaffner
Yfke Dulek, Alex B. Grilo, Stacey Jeffery, Christian Majenz, and Christian Schaffner. Secure multi-party quantum computation with a dishonest majority. In Anne Canteaut and Yuval Ishai, editors, Advances in Cryptology -- EUROCRYPT 2020 , pages 729--758, Cham, 2020. Springer In...
2020
-
[15]
Determinism in the one-way model
Vincent Danos and Elham Kashefi. Determinism in the one-way model. Phys. Rev. A , 74:052310, Nov 2006
2006
-
[16]
Universal blind quantum computing with weak coherent pulses
Vedran Dunjko, Elham Kashefi, and Anthony Leverrier. Universal blind quantum computing with weak coherent pulses. Phys. Rev. Lett. , 108(200502), 2012
2012
-
[17]
The measurement calculus
Vincent Danos, Elham Kashefi, and Prakash Panangaden. The measurement calculus. J. ACM , 54(2), April 2007
2007
-
[18]
Actively secure two-party evaluation of any quantum operation
Fr \'e d \'e ric Dupuis, Jesper Buus Nielsen, and Louis Salvail. Actively secure two-party evaluation of any quantum operation. In Advances in Cryptology--CRYPTO 2012 , pages 794--811. Springer, 2012
2012
-
[19]
Fitzsimons, Michal Hajdu s s ek, and Tomoyuki Morimae
Joseph F. Fitzsimons, Michal Hajdu s s ek, and Tomoyuki Morimae. Post hoc verification of quantum computation. Phys. Rev. Lett. , 120:040501, Jan 2018
2018
-
[20]
Fitzsimons and Elham Kashefi
Joseph F. Fitzsimons and Elham Kashefi. Unconditionally verifiable blind quantum computation. Phys. Rev. A , 96:012303, Jul 2017
2017
-
[21]
Reducing resources for verification of quantum computations
Samuele Ferracin, Theodoros Kapourniotis, and Animesh Datta. Reducing resources for verification of quantum computations. Physical Review A , 98(2):022323, 2018
2018
-
[22]
Accrediting outputs of noisy intermediate-scale quantum computing devices
Samuele Ferracin, Theodoros Kapourniotis, and Animesh Datta. Accrediting outputs of noisy intermediate-scale quantum computing devices. New Journal of Physics , 21(11):113038, nov 2019
2019
-
[23]
Robustness and device independence of verifiable blind quantum computing
Alexandru Gheorghiu, Elham Kashefi, and Petros Wallden. Robustness and device independence of verifiable blind quantum computing. New Journal of Physics , 17(8):083040, 2015
2015
-
[24]
Composably secure delegated quantum computation with weak coherent pulses
Maxime Garnier, Dominik Leichtle, Luka Music, and Harold Ollivier. Composably secure delegated quantum computation with weak coherent pulses. In 2024 International Conference on Quantum Communications, Networking, and Computing (QCNC) , page 221–225. IEEE, July 2024
2024
-
[25]
Multi-pulse protocol for securely preparing a single (qu)bit (in preparation), 2025
Maxime Garnier, Dominik Leichtle, Luka Music, and Harold Ollivier. Multi-pulse protocol for securely preparing a single (qu)bit (in preparation), 2025
2025
-
[26]
Direct certification of a class of quantum simulations
D Hangleiter, M Kliesch, M Schwarz, and J Eisert. Direct certification of a class of quantum simulations. Quantum Science and Technology , 2(1):015004, feb 2017
2017
-
[27]
Remote blind state preparation with weak coherent pulses in the field
Yang-Fan Jiang, Kejin Wei, Liang Huang, Ke Xu, Qi-Chao Sun, Yu-Zhe Zhang, Weijun Zhang, Hao Li, Lixing You, Zhen Wang, Hoi-Kwong Lo, Feihu Xu, Qiang Zhang, and Jian-Wei Pan. Remote blind state preparation with weak coherent pulses in the field. Physical Review Letters , 123(10...
2019
-
[28]
Efficient verification of universal and intermediate quantum computing
Theodoros Kapourniotis. Efficient verification of universal and intermediate quantum computing . PhD thesis, School of Informatics, University of Edinburgh, 2016
2016
-
[29]
On optimising quantum communication in verifiable quantum computing, 2015
Theodoros Kapourniotis, Vedran Dunjko, and Elham Kashefi. On optimising quantum communication in verifiable quantum computing, 2015. Presented at AQIS'15 conference; arXiv:1506.06943
2015 arXiv
-
[30]
Unifying quantum verification and error-detection: Theory and tools for optimisations
Theodoros Kapourniotis, Elham Kashefi, Dominik Leichtle, Luka Music, and Harold Ollivier. Unifying quantum verification and error-detection: Theory and tools for optimisations. Quantum Science and Technology , 9(3):035036, May 2024
2024
-
[31]
Asymmetric quantum secure multi-party computation with weak clients against dishonest majority
Theodoros Kapourniotis, Elham Kashefi, Dominik Leichtle, Luka Music, and Harold Ollivier. Asymmetric quantum secure multi-party computation with weak clients against dishonest majority. Quantum Science and Technology , 10(2):025015, 2025
2025
-
[32]
Verification of quantum computations without trusted preparations or measurements
Elham Kashefi, Dominik Leichtle, Luka Music, and Harold Ollivier. Verification of quantum computations without trusted preparations or measurements. CoRR , 2024
2024
-
[33]
Plugging leaks in fault-tolerant quantum computation and verification, 2025
Theodoros Kapourniotis, Dominik Leichtle, Luka Music, and Harold Ollivier. Plugging leaks in fault-tolerant quantum computation and verification, 2025
2025
-
[34]
Multiparty delegated quantum computing
Elham Kashefi and Anna Pappa. Multiparty delegated quantum computing. Cryptography , 1(2):1--20, 7 2017
2017
-
[35]
Optimised resource construction for verifiable quantum computation
Elham Kashefi and Petros Wallden. Optimised resource construction for verifiable quantum computation. Journal of Physics A: Mathematical and Theoretical; preprint arXiv:1510.07408 , 2017
2017 arXiv
-
[36]
Verifying BQP computations on noisy devices with minimal overhead
Dominik Leichtle, Luka Music, Elham Kashefi, and Harold Ollivier. Verifying BQP computations on noisy devices with minimal overhead. PRX Quantum , 2:040302, Oct 2021
2021
-
[37]
Classical-communication cost in distributed quantum-information processing: A generalization of quantum-communication complexity
Hoi-Kwong Lo. Classical-communication cost in distributed quantum-information processing: A generalization of quantum-communication complexity. Physical Review A , 62(1), June 2000
2000
-
[38]
Leung and Peter W
Debbie W. Leung and Peter W. Shor. Oblivious remote state preparation. Physical Review Letters , 90(12), March 2003
2003
-
[39]
Classical verification of quantum computations
Urmila Mahadev. Classical verification of quantum computations. In Mikkel Thorup, editor, 59th IEEE Annual Symposium on Foundations of Computer Science, FOCS 2018, Paris, France, October 7-9, 2018 , pages 259--267. IEEE Computer Society, 2018
2018
-
[40]
Constructive cryptography -- a new paradigm for security definitions and proofs
Ueli Maurer. Constructive cryptography -- a new paradigm for security definitions and proofs. In Sebastian M \"o dersheim and Catuscia Palamidessi, editors, Theory of Security and Applications , pages 33--56, Berlin, Heidelberg, 2012. Springer Berlin Heidelberg
2012
-
[41]
Fitzsimons
Tomoyuki Morimae and Joseph F. Fitzsimons. Post hoc verification with a single prover. CoRR , 2016
2016
-
[42]
QEnclave -- a practical solution for secure quantum cloud computing
Yao Ma, Elham Kashefi, Myrto Arapinis, Kaushik Chakraborty, and Marc Kaplan. QEnclave -- a practical solution for secure quantum cloud computing. npj Quantum Information , 8(1):128, 2022
2022
-
[43]
Shadow pauli flow: Characterising determinism in mbqcs involving pauli measurements
Mehdi Mhalla, Simon Perdrix, and Luc Sanselme. Shadow pauli flow: Characterising determinism in mbqcs involving pauli measurements. CoRR , 2022
2022
-
[44]
Abstract cryptography
Ueli Maurer and Renato Renner. Abstract cryptography. In Innovations in Computer Science , pages 1 -- 21. Tsinghua University Press, jan 2011
2011
-
[45]
A quantum linearity test for robustly verifying entanglement
Anand Natarajan and Thomas Vidick. A quantum linearity test for robustly verifying entanglement. In Proceedings of the 49th Annual ACM SIGACT Symposium on Theory of Computing , STOC ’17. ACM, June 2017
2017
-
[46]
Multi-client distributed blind quantum computation with the qline architecture, 2023
Beatrice Polacchi, Dominik Leichtle, Leonardo Limongi, Gonzalo Carvacho, Giorgio Milani, Nicolò Spagnolo, Marc Kaplan, Fabio Sciarrino, and Elham Kashefi. Multi-client distributed blind quantum computation with the qline architecture, 2023
2023
-
[47]
Robert Raussendorf and Hans J. Briegel. A one-way quantum computer. Phys. Rev. Lett. , 86:5188--5191, May 2001
2001
-
[48]
Reichardt, Reichardt Falk Unger, and Umesh Vazirani
Ben W. Reichardt, Reichardt Falk Unger, and Umesh Vazirani. Classical command of quantum systems. Nature , 496:456--460, 2013
2013
-
[49]
Relating measurement patterns to circuits via pauli flow
Will Simmons. Relating measurement patterns to circuits via pauli flow. CoRR , 2021
2021
Reviewed July 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.