REVIEW 2 major objections 7 minor 87 references
Verifiable blind probabilistic error cancellation
T0 review · 2 major / 7 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read This paper claims that probabilistic error cancellation, a standard quantum error mitigation technique, can be delegated to a fully malicious server with perfect blindness and verifiable, composably secure outputs.
desk verdict First composable-security protocol for PEC; the main theorem survives my checks, but practicality claims are untested and the proof is dense. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is the combination of the quantum one-time pad (QOTP) twirl, general trap patterns, and the inverse Walsh–Hadamard transform. The QOTP converts any server deviation into an effective stochastic Pauli channel whose $Z$ component alone flips measurement outcomes, so PEC's inverse channel can be realized entirely by classical bit flips on the client's decoded outcomes. Test rounds use random general trap patterns, and because $\mathbb{E}[(-1)^{\langle \mathrm{set}(P), S_i\rangle} \tilde{y}_i] = \tilde{p}_T(P)$, the signed average over $N_t$ traps gives an unbiased estimator of the server's Pauli-deviation probability. The client assembles these estimates into the statistic $\widetilde{\Delta} = D_\Lambda(\tilde{p}_T, \tilde{p}_{\mathrm{PEC}})$, a coarse-grained $\ell^1$ distance between the estimated and reference deviation distributions, and accepts iff $\widetilde{\Delta} \le \epsilon_t$. The proof then bounds three fluctuations---the PEC estimator, the trap-statistic estimator, and the computation/test round mismatch---using Hoeffding, McDiarmid, and Serfling inequalities.
What would settle it
Search numerically for an adversarial sequence of Pauli deviations across rounds that passes the test condition $\widetilde{\Delta} \le \epsilon_t$ while the PEC-corrected computation estimate satisfies $|\widetilde{o}_C - \mathrm{Tr}[\rho O]| > \epsilon$ with non-negligible probability. Theorem 2's security bound says this joint event has probability at most three exponentially small terms, so any concrete strategy beating that bound would refute the central claim.
Extended reading notes
Core claim
The central discovery, stated as Theorem 2, is that VBPEC $\delta$-constructs the SDPEC resource: for any accepted non-abort output, the probability that it deviates from the ideal expectation value $\mathrm{Tr}[\rho O]$ by more than $\epsilon$ is negligible in both $N_c$ and $N_t$, and under honest noise matching the reference model $E_{\mathrm{PEC}}$, the probability of accepting a correct mitigated estimate converges to one exponentially. The protocol achieves this by turning trap-based verification from deterministic pass/fail checks into a statistical benchmark of the server's effective Pauli deviation distribution, and by proving that the residual bias of the PEC estimator is controlled by the same statistic used for acceptance.
Load-bearing premise
The protocol assumes the client already has a correct-enough description of the server's noise as a stochastic Pauli channel with only polynomially many relevant terms, and that the server's true deviation, after the one-time-pad randomization, really is of that form; the protocol verifies consistency with this description but does not learn it from scratch.
Editorial extensions
If this is right
- A client with only single-qubit prepare-and-send capabilities can obtain error-mitigated expectation values from an untrusted quantum server while keeping the computation perfectly blind.
- PEC's cancellation operations reduce to classical bit flips in the client's post-processing, so no additional noisy quantum gates are inserted into the delegated circuit.
- Under honest noise that matches the reference model, the probability of accepting a within-$\epsilon$ estimate converges to one exponentially in $N_c$ and $N_t$; under moderate model mismatch it remains high as long as $D_{\mathrm{mis}} < \min(\epsilon/\|\vec q\|_1, \epsilon_t)$.
- Verification no longer rejects once noise exceeds a fixed threshold; noise consistent with the PEC model is actively cancelled, so the practical acceptance probability improves without changing the security guarantee.
Reading between the lines
- Beyond the paper: the same trap post-processing already reconstructs the server's effective Pauli distribution, so the test-round data could serve as a standalone noise-benchmarking primitive that certifies sparse Pauli noise models without a separate calibration step.
- Beyond the paper: the proof mechanism of estimator-valued tests plus concentration bounds should transfer to other QEM schemes whose correction is a classical function of the decoded outcomes, such as probabilistic error amplification, though the paper only sketches this direction.
- Beyond the paper: feeding the estimated $\tilde{p}_T$ back into an updated $E_{\mathrm{PEC}}$ over successive blocks could make the protocol noise-agnostic, replacing a priori model trust with statistical certification.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces Verifiable Blind Probabilistic Error Cancellation (VBPEC), a delegated quantum computation protocol that integrates probabilistic error cancellation (PEC) into the universal blind quantum computing framework. The authors formalize the ideal functionality as the Secure Delegated Probabilistic Error Cancellation (SDPEC) resource in the abstract cryptography framework, and prove that VBPEC constructs it with perfect blindness and an exponentially small security error. The protocol uses test rounds based on general trap patterns to estimate the server's effective Pauli deviation via a Walsh-Hadamard post-processing, and compares this estimate to the reference PEC noise model through a statistical test statistic. The main result, Theorem 2, claims that VBPEC delta-constructs the SDPEC resource with negligible delta in both the number of computation rounds and the number of test rounds, while also providing active error cancellation that improves acceptance probability under matched and moderately mismatched honest noise.
Significance. If the proof can be repaired, this is a substantial contribution to both quantum error mitigation and verified delegated computation. It provides the first composable cryptographic treatment of a QEM technique, formalizing PEC as an ideal resource and showing that it can be securely delegated to a fully malicious server. The extension of trap-based verification from deterministic pass/fail outcomes to statistical benchmarking via the Walsh-Hadamard transform is conceptually novel and technically useful. The protocol inherits the absence of quantum-space overhead from PEC and from recent verification protocols, with overhead only in additional repetitions. The concentration proofs are detailed and largely sound, and the noise-robustness analysis in Section V is a significant improvement over threshold-based verification, since correctly mitigated estimates are accepted with high probability under matched honest noise. The construction is not circular: the reference noise model E_PEC is an input, protocol parameters are fixed, and the security proof does not fit the data.
major comments (2)
- [Section IV.C, Eq. (38) and Eq. (47)] The McDiarmid bound in Eq. (47) is applied to the deviation |˜∆−Δ_T|, with Δ_T defined in Eq. (38) as E[˜∆|p_T]. However, the independence of the test-round variables required for the bounded-difference argument holds only conditionally on the actual test set S_T and the fixed Pauli sequence, so Eq. (47) controls |˜∆−E[˜∆|S_T, Pauli sequence]|, not |˜∆−E[˜∆|p_T]|. The gap between these two conditional means is not bounded, and E[˜∆|S_T, Pauli sequence] can depend on the detailed composition of S_T beyond the empirical distribution p_T, so this gap can be non-negligible. This breaks the chain leading from Eq. (42) to Eq. (43) and therefore the proof of Theorem 2 as written. The fix is local: redefine Δ_T := E[˜∆|S_T, Pauli sequence], use Jensen's inequality to obtain D_Λ(p_T, p_PEC) ≤ Δ_T in Lemma 6, and update Eq. (38) and the surrounding text accordingly.
- [Theorem 2 and Section IV.C, Eq. (53)] The security proof of Theorem 2 fixes the protocol parameter in Eq. (53) as ϵ_t = γ_t = γ_s = ϵ/(4∥q∥₁), whereas the theorem statement allows any 0 ≤ ϵ_t < ϵ/∥q∥₁. With the choices in Eq. (53), the proof only covers the single value ϵ_t = ϵ/(4∥q∥₁); for other admissible ϵ_t, the inequality γ_c + ∥q∥₁(ϵ_t + γ_t + γ_s) ≤ ϵ may fail. The statement and proof should be reconciled by either stating the theorem for this specific choice or by introducing the slack s = ϵ − ∥q∥₁ϵ_t > 0 and choosing γ_c = s/4, γ_t = γ_s = s/(4∥q∥₁), which preserves the exponential bounds. The lack of consistency is compounded by the correctness proof taking ϵ_t = ϵ/2 and the noise-robustness section taking ϵ_t = ϵ/4, without clarifying that these are illustrative choices for a protocol whose ϵ_t is a single fixed parameter.
minor comments (7)
- [Resource 1 and Resource 2] The description of the filtered server interface ('when e=0, the interface does not send any information nor take inputs') is easy to misread; please clarify that the server receives only the public information and otherwise has a null interface in the honest case.
- [Protocol 3] The set N_G^odd(S) and the variables d_v are used in Step 5 before being defined; add a pointer to Appendix D where the general trap construction is explained.
- [Eq. (12) and Protocol 4] The estimator ˜p_T(P) is defined twice, once in the text around Eq. (12) and again inside Protocol 4; unify the notation to avoid duplication and potential inconsistency.
- [Section IV.C, before Eq. (38)] There is a stray period after the definition of μ_C in the sentence introducing Eq. (38); this is a minor typographical error.
- [Appendix E, Lemma 6 proof] The equality D_Λ(p_T, p_PEC) = D_Λ(E[˜p_T|p_T], p_PEC) is used without comment; it follows from Lemma 5 and linearity of the conditional expectation, but this should be stated explicitly for clarity.
- [Section II.B] The crucial assumption that the client's preparation imperfections are independent of the secret QOTP parameters is stated in passing; it is load-bearing for the twirling argument and should be listed as an explicit assumption in Section II.B alongside the definition of E_PEC.
- [References] Several references are to unpublished or not-yet-indexed works (e.g., Refs. [24], [28], [59]); please provide arXiv identifiers or DOIs where available for reproducibility.
Circularity Check
No significant circularity: VBPEC's security proof is a concentration-based derivation from a fixed input noise model, not a fit or a self-citation chain.
full rationale
The claimed derivation chain is self-contained and does not reduce to its inputs. The reference model E_PEC (equivalently p_PEC and q) is an explicit protocol input and is never fitted to the server's trap data; the trap statistic p~_T is used only to test consistency with p_PEC. The central bound Lemma 6 derives |mu_C - Tr[rho O]| <= ||q||_1 D_Lambda(p_C,p_PEC) using the inversion identity q * p_PEC = e_0 and Young's inequality; this is a mathematical consequence of PEC, not a restatement of the acceptance test. The acceptance test supplies D_Lambda(p~_T,p_PEC) <= eps_t, and the proof separately controls fluctuations of the mitigated estimator, the test statistic, and the computation/test split by Hoeffding, McDiarmid, and Serfling inequalities; none of these bounds is calibrated to the data. Consequently, 'every accepted output is within eps' is a derived statistical guarantee rather than a definitional equivalence. The main self-citations (VBOE [29], general traps [27], UBQC composability [36]) are either independently established, used for comparison, or derived in the appendices; none imports an unverified uniqueness theorem or ansatz. The reviewer-noted conditioning concern around Eq. (47) is, even if valid, a proof-completeness issue about the conditioning in McDiarmid's inequality, not a circular reduction of the claim to its inputs, so it does not affect the circularity score.
Assumptions & free parameters
assumptions (7)
- domain assumption Reference E_PEC is a stochastic Pauli channel, invertible in Pauli transfer representation, with known support Lambda of polynomial size in |V|.
- domain assumption QOTP twirls any server-side deviation into an effective stochastic Pauli channel; X errors immediately before X-basis measurements are harmless, so PEC can be reduced to I/Z corrections.
- domain assumption General trap patterns from Kapourniotis et al. satisfy Lemma 4 and the Walsh-Hadamard relation, yielding unbiased estimators of Pauli deviation probabilities.
- domain assumption UBQC is perfectly blind and composably secure, and UBOE therefore perfectly constructs the BDOE resource.
- domain assumption Client preparation imperfections are modeled as a single deviation independent of secret parameters, absorbed into the server-side deviation.
- standard math Hoeffding, McDiarmid, and Serfling concentration inequalities.
- standard math Observable estimation problems reduce without loss of generality to binary +/-1 observables via Naimark dilation.
Cite this review
Pith. "Pith review of Verifiable blind probabilistic error cancellation." pith.science (2026). https://pith.science/paper/J63KP3OL
@misc{pith2026260725704,
author = {Pith},
title = {Pith review of: Verifiable blind probabilistic error cancellation},
year = {2026},
howpublished = {\url{https://pith.science/paper/J63KP3OL}},
note = {Machine review of arXiv:2607.25704}
}
read the original abstract
Quantum error mitigation (QEM) is an essential tool for mitigating hardware noise without incurring space overhead. Yet, its reliability depends on modeling, calibration, and implementation, leaving end-to-end security on untrusted quantum hardware unresolved. We address this problem by introducing verifiable blind probabilistic error cancellation (VBPEC), the first secure verification protocol against a fully malicious adversary that integrates QEM. VBPEC brings probabilistic error cancellation (PEC), a widely studied QEM technique, within the scope of composable security by formalizing delegated mitigation as a cryptographic resource in the abstract cryptography framework. The protocol performs PEC with perfect blindness and an exponentially small security error. VBPEC retains the absence of quantum-space overhead from recent statistically-secure verified quantum computation protocols and from PEC. The only overhead takes the form of additional repetitions due to the QEM procedure. To achieve this, we extend trap-based verification from deterministic pass/fail checks to statistical tests that benefit from QEM and develop a new proof technique that integrates the corresponding additional deviation sources. Rather than merely tolerating honest noise below a fixed threshold, VBPEC actively cancels it, enabling correctly mitigated estimates to be accepted with high probability without compromising security. Our framework thus establishes an essential route towards secure, reliable, and practical delegated quantum computation on near-future quantum hardware: VBPEC fundamentally improves the practicality of verification.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[1]
The Simulator setse= 1
-
[2]
The Simulator prepares EPR pairs for each qubit that the Server is supposed to receive in Protocol 4
-
[3]
The Simulator sends all half-EPR pairs to the Server and instructs the Server to perform measure- ments at random angles, and retrieves the alleged measurement outcomes
-
[4]
The Simulator forwards the second half of the EPR pairs, the chosen angles, and the received bits to the SDPEC resource
-
[5]
The Simulator samples at random indices within [Nc +Nt] to define the sets S C, and S T
-
[6]
Client” and a potentially malicious “Server
The Simulator decides the trap patterns{S i}i∈ST associated with each test round in S T and passes this to the SDPEC resource. Following the security proof of UBQC, the information passed per round, together with the type of each round, is sufficient for the SDPEC resource to generate per-round measurement results following the same probability dis- tribu...
-
[7]
The Client also computes a prop v = M j∈NG(v) ainit j ∈{0,1}for allv∈V
The Client generates secret parameters: (a) (Xrandomization) The Client chooses a random bit a init v ∈{0,1}forv∈I and sets a init v = 0 forv∈V\I. The Client also computes a prop v = M j∈NG(v) ainit j ∈{0,1}for allv∈V. (b) (Zrandomization) The Client chooses a random bit r v∈{0,1}for allv∈V. (c) (randomization for blindness) The Client chooses a randomθ v...
-
[8]
Forv∈I, the Client sequentially sends each qubit in O v∈I Rzv(θv)X ainit v v ! [ρinit]
The Client prepares and sends to the Server all single qubits corresponding tov∈V. Forv∈I, the Client sequentially sends each qubit in O v∈I Rzv(θv)X ainit v v ! [ρinit]. Forv∈V\I, the Client sends|+ θv⟩
Show all 87 references
-
[9]
The Server applies the entangling operationG= Y (u,v)∈E CZu,v to prepare the resource state according to the graphG
-
[10]
Once the Client receives the mea- surement outcome bj∈{0,1}for allj∈S X,v∪SZ,v, whereS X,v =f −1 G (v),S Z,v ={j|v∈N G (fG (j))}, the Client computes the adaptive angle updateϕ ′ v
For eachv∈V, the Client and Server interactively perform the MBQC process. Once the Client receives the mea- surement outcome bj∈{0,1}for allj∈S X,v∪SZ,v, whereS X,v =f −1 G (v),S Z,v ={j|v∈N G (fG (j))}, the Client computes the adaptive angle updateϕ ′ v. The Client then comp...
-
[11]
Protocol 6Universal Blind Observable Estimation (UBOE) Public Information:Public information (C,G,f G,Nc)
The Client performs the remaining classical post-processing upon the measurement results of all qubitsv∈Vand returns ˜y∈{−1,1}. Protocol 6Universal Blind Observable Estimation (UBOE) Public Information:Public information (C,G,f G,Nc). Inputs from Client:The target computationC...
-
[12]
The Client chooses the total number of roundsN c
-
[13]
For every round indexed byi∈[N c], the Client delegates the target computation with the UBQC protocol (Protocol 5)
-
[14]
Blind Delegated Observable Es- timation (BDOE)
Upon receiving and decoding the result of the computation roundi∈[N c], the Client assigns the result to ˜y i. The Client then sets ˜o= 1 Nc X i∈[Nc] ˜yi and returns ˜oas the final result. Based on MBQC, the UBQC protocol is given as Pro- tocol 5. Based on UBQC, the UBOE proto...
-
[15]
The interface is filtered so that whene= 0, the interface does not send any information nor take inputs
-
[16]
Processing by the Resource:
Fore= 1, the Resource receives a quantum stateσandF, a list of instructions so that the resource producess∈R. Processing by the Resource:
-
[17]
Ife= 0, it setso= 1 Nc NcX i=1 yi withy i = 2Yi−1 whereY i∼B(p), sampled from a Bernoulli distributionB(p) with p= Tr [ρ|+O⟩⟨+O|]
-
[18]
Ife= 1, it computesousing the transmitted stateσandF
-
[19]
perfectly constructs the BDOE resource, leaking only pub- lic information(C,G,f G,Nc)
It forwardsoto the Client. perfectly constructs the BDOE resource, leaking only pub- lic information(C,G,f G,Nc). Appendix D: General trap patterns In the test rounds of VBPEC, we use general trap pat- terns introduced in [27], which can be seen as stabilizer tests. We review ...
-
[20]
Since VBOE is a special case of VBPEC that omits PEC, its test statistic can also be described as the identity-reference special case of ˜∆ in Eq
Noise-robustness of VBOE under honest noise We now analyze the noise robustness of VBOE in the honest-noise setting. Since VBOE is a special case of VBPEC that omits PEC, its test statistic can also be described as the identity-reference special case of ˜∆ in Eq. (12), by repl...
-
[21]
We assume that each round is independently affected by the same stochas- tic Pauli channel with deviation distribution⃗ p∈R|ΩV| ≥0
Noise-robustness of VBPEC under honest noise mismatch We now analyze the noise-robustness of VBPEC when the Server is honest, but the actual noise does not exactly match the noise model used for PEC. We assume that each round is independently affected by the same stochas- tic ...
-
[22]
Applying PEC locally to the first qubit in a two-qubit system Let us first consider a two-qubit system and take the noise modelE PEC = (1−p 1)II+p 1ZIas an illustrative example. The probability distributions ofE PEC andE−1 PEC can be expressed in vector form, respectively, as ...
-
[23]
Applying PEC for global dephasing in a two-qubit system Next, we consider the global two-qubit dephasing noise model EPEC = 1− 3p 4 II+ p 4 (ZI+IZ+ZZ).(G7) Here, 0< p <1, where the upper bound ensures that the inverse map exists. The probability distributions of 26 EPEC andE −...
-
[24]
Letd:= 2 |V| , and identify each u∈{0,1} |V| with the Pauli operation Zu := |V|O i=1 Zui
Applying PEC for global dephasing in a |V|-qubit system We now generalize the global dephasing model above to a|V|-qubit system. Letd:= 2 |V| , and identify each u∈{0,1} |V| with the Pauli operation Zu := |V|O i=1 Zui. (G15) SinceXcomponents are harmless in MBQC, grouping the ...
-
[25]
S. Endo, Z. Cai, S. C. Benjamin, and X. Yuan, Hybrid quantum-classical algorithms and quantum error mitiga- tion, Journal of the Physical Society of Japan90, 032001 (2021)
2021
-
[26]
Z. Cai, R. Babbush, S. C. Benjamin, S. Endo, W. J. Hug- gins, Y. Li, J. R. McClean, and T. E. O’Brien, Quantum error mitigation, Rev. Mod. Phys.95, 045005 (2023)
2023
-
[27]
Li and S
Y. Li and S. C. Benjamin, Efficient variational quantum simulator incorporating active error minimization, Phys. Rev. X7, 021050 (2017)
2017
-
[28]
Temme, S
K. Temme, S. Bravyi, and J. M. Gambetta, Error miti- gation for short-depth quantum circuits, Physical review letters119, 180509 (2017)
2017
-
[29]
S. Endo, S. C. Benjamin, and Y. Li, Practical quantum error mitigation for near-future applications, Phys. Rev. X8, 031027 (2018)
2018
-
[30]
Koczor, Exponential error suppression for near-term quantum devices, Phys
B. Koczor, Exponential error suppression for near-term quantum devices, Phys. Rev. X11, 031057 (2021)
2021
-
[31]
W. J. Huggins, S. McArdle, T. E. O’Brien, J. Lee, N. C. Rubin, S. Boixo, K. B. Whaley, R. Babbush, and J. R. McClean, Virtual distillation for quantum error mitiga- tion, Phys. Rev. X11, 041036 (2021)
2021
-
[32]
Bravyi, S
S. Bravyi, S. Sheldon, A. Kandala, D. C. Mckay, and J. M. Gambetta, Mitigating measurement errors in mul- tiqubit experiments, Phys. Rev. A103, 042605 (2021)
2021
-
[33]
Yoshioka, H
N. Yoshioka, H. Hakoshima, Y. Matsuzaki, Y. Tokunaga, Y. Suzuki, and S. Endo, Generalized quantum subspace expansion, Phys. Rev. Lett.129, 020502 (2022)
2022
-
[34]
B. Yang, R. Raymond, and S. Uno, Efficient quantum readout-error mitigation for sparse measurement out- comes of near-term quantum devices, Phys. Rev. A106, 012423 (2022)
2022
-
[35]
Kandala, K
A. Kandala, K. Temme, A. D. C´ orcoles, A. Mezzacapo, J. M. Chow, and J. M. Gambetta, Error mitigation ex- tends the computational reach of a noisy quantum pro- cessor, Nature567, 491 (2019)
2019
-
[36]
Y. Kim, A. Eddins, S. Anand, K. X. Wei, E. van den Berg, S. Rosenblatt, H. Nayfeh, Y. Wu, M. Zaletel, K. Temme, and A. Kandala, Evidence for the utility of quantum computing before fault tolerance, Nature618, 500–505 (2023)
2023
-
[37]
Yoshioka, M
N. Yoshioka, M. Amico, W. Kirby, P. Jurcevic, A. Dutt, B. Fuller, S. Garion, H. Haas, I. Hamamura, A. Ivrii, R. Majumdar, Z. Minev, M. Motta, B. Pokharel, P. Rivero, K. Sharma, C. J. Wood, A. Javadi-Abhari, and A. Mezzacapo, Krylov diagonalization of large many- body hamiltoni...
2025 doi
-
[38]
D. A. Abanin, R. Acharya, L. Aghababaie-Beni, G. Aigeldinger, A. Ajoy, R. Alcaraz, I. Aleiner, T. I. Andersen, M. Ansmann, F. Arute, K. Arya, A. As- faw, N. Astrakhantsev, J. Atalaya, R. Babbush, D. Ba- con, B. Ballard, J. C. Bardin, C. Bengs, A. Bengtsson, A. Bilmes, S. Boixo...
2025
-
[39]
Piveteau, D
C. Piveteau, D. Sutter, S. Bravyi, J. M. Gambetta, and K. Temme, Error mitigation for universal gates on en- coded qubits, Physical review letters127, 200505 (2021)
2021
-
[40]
Suzuki, S
Y. Suzuki, S. Endo, K. Fujii, and Y. Tokunaga, Quantum error mitigation as a universal error reduction technique: Applications from the nisq to the fault-tolerant quantum computing eras, PRX Quantum3, 010345 (2022)
2022
-
[41]
A. Mari, N. Shammah, and W. J. Zeng, Extending quantum probabilistic error cancellation by noise scaling, Phys. Rev. A104, 052607 (2021)
2021
-
[42]
van den Berg, Z
E. van den Berg, Z. K. Minev, A. Kandala, and K. Temme, Probabilistic error cancellation with sparse pauli–lindblad models on noisy quantum processors, Na- ture Physics19, 1116–1121 (2023)
2023
-
[43]
van den Berg and P
E. van den Berg and P. Wocjan, Techniques for learning sparse Pauli-Lindblad noise models, Quantum8, 1556 (2024)
2024
-
[44]
R. S. Gupta, E. v. d. Berg, M. Takita, D. Riste, K. Temme, and A. Kandala, Probabilistic error cancella- tion for dynamic quantum circuits (2023)
2023
-
[45]
Govia, S
L. Govia, S. Majumder, S. Barron, B. Mitchell, A. Seif, Y. Kim, C. Wood, E. Pritchett, S. Merkel, and D. McKay, Bounding the systematic error in quantum error mitiga- tion due to model violation, PRX Quantum6, 010354 (2025)
2025
-
[46]
E. H. Chen, S. Chen, L. E. Fischer, A. Eddins, L. C. G. Govia, B. Mitchell, A. He, Y. Kim, L. Jiang, and A. Seif, Disambiguating pauli noise in quantum comput- ers (2025)
2025
-
[47]
Y. Kim, L. C. G. Govia, A. Dane, E. van den Berg, D. M. Zajac, B. Mitchell, Y. Liu, K. Balakrishnan, G. Keefe, A. Stabile, E. Pritchett, J. Stehlik, and A. Kandala, Error mitigation with stabilized noise in superconduct- ing quantum processors, Nature Communications16, 10.1038...
2025 doi
-
[48]
H. Xie, N. Yoshioka, K. Tsubouchi, and Y. Li, Noise- agnostic unbiased quantum error mitigation for logical qubits, Phys. Rev. Lett.136, 010603 (2026)
2026
-
[49]
J. F. Fitzsimons and E. Kashefi, Unconditionally verifi- able blind quantum computation, Physical Review A96, 012303 (2017)
2017
-
[50]
Leichtle, L
D. Leichtle, L. Music, E. Kashefi, and H. Ollivier, Ver- ifying bqp computations on noisy devices with minimal overhead, PRX Quantum2, 040302 (2021)
2021
-
[51]
Kapourniotis, E
T. Kapourniotis, E. Kashefi, D. Leichtle, L. Music, and H. Ollivier, Unifying quantum verification and error- detection: theory and tools for optimisations, Quantum Science and Technology9, 035036 (2024)
2024
-
[52]
Kapourniotis, D
T. Kapourniotis, D. Leichtle, L. Music, and H. Ollivier, Plugging leaks in fault-tolerant quantum computation and verification (2025)
2025
-
[53]
B. Yang, E. Kashefi, and H. Ollivier, Verifiable blind ob- servable estimation (2025)
2025
-
[54]
Gottesman and I
D. Gottesman and I. L. Chuang, Demonstrating the vi- ability of universal quantum computation using telepor- tation and single-qubit operations, Nature402, 390–393 (1999)
1999
-
[55]
Raussendorf and H
R. Raussendorf and H. J. Briegel, A one-way quantum computer, Phys. Rev. Lett.86, 5188 (2001)
2001
-
[56]
Knill, R
E. Knill, R. Laflamme, and G. J. Milburn, A scheme for efficient quantum computation with linear optics, Nature 409, 46–52 (2001)
2001
-
[57]
Danos, E
V. Danos, E. Kashefi, and P. Panangaden, The measure- ment calculus, J. ACM54, 8–es (2007)
2007
-
[58]
H. J. Briegel, D. E. Browne, W. D¨ ur, R. Raussendorf, and M. Van den Nest, Measurement-based quantum compu- tation, Nature Physics5, 19–26 (2009)
2009
-
[59]
Maurer and R
U. Maurer and R. Renner, Abstract cryptography, inThe Second Symposium on Innovations in Computer Science, ICS 2011, edited by B. Chazelle (Tsinghua University Press, 2011) pp. 1–21
2011
-
[60]
Dunjko, J
V. Dunjko, J. F. Fitzsimons, C. Portmann, and R. Ren- ner, Composable security of delegated quantum compu- tation (2014)
2014
-
[61]
Knill, Fault-tolerant postselected quantum computa- tion: Threshold analysis (2004)
E. Knill, Fault-tolerant postselected quantum computa- tion: Threshold analysis (2004)
2004
-
[62]
O. Kern, G. Alber, and D. L. Shepelyansky, Quantum error correction of coherent errors by randomization, The European Physical Journal D32, 153–156 (2005)
2005
-
[63]
Dankert, R
C. Dankert, R. Cleve, J. Emerson, and E. Livine, Exact and approximate unitary 2-designs and their application to fidelity estimation, Phys. Rev. A80, 012304 (2009)
2009
-
[64]
M. R. Geller and Z. Zhou, Efficient error models for fault- tolerant architectures and the pauli twirling approxima- tion, Phys. Rev. A88, 012314 (2013)
2013
-
[65]
J. J. Wallman and J. Emerson, Noise tailoring for scalable quantum computation via randomized compiling, Phys. Rev. A94, 052325 (2016)
2016
-
[66]
Broadbent, J
A. Broadbent, J. Fitzsimons, and E. Kashefi, Universal blind quantum computation, in2009 50th Annual IEEE Symposium on Foundations of Computer Science(IEEE, 2009)
2009
-
[67]
A. G. Fowler, M. Mariantoni, J. M. Martinis, and A. N. Cleland, Surface codes: Towards practical large-scale 29 quantum computation, Physical Review A86, 032324 (2012)
2012
-
[68]
Scheiber, P
T. Scheiber, P. Haubenwallner, and M. Heller, Reduced Sampling Overhead for Probabilistic Error Cancellation by Pauli Error Propagation, Quantum9, 1840 (2025)
2025
-
[69]
By construction Λ is polynomial in|V|so that the eval- uation can be performed efficiently in spite of the expo- nential length of⃗ p
-
[70]
Hartung, S
T. Hartung, S. Schuster, J. von Zanthier, and K. Jansen, Real-time measurement error mitigation for one-way quantum computation (2024)
2024
-
[71]
J. M. Koh, D. E. Koh, and J. Thompson, Readout er- ror mitigation for mid-circuit measurements and feedfor- ward, PRX Quantum7, 010317 (2026)
2026
-
[72]
Gustiani, D
C. Gustiani, D. Leichtle, J. Miller, R. Grassie, D. Mills, and E. Kashefi, On-chip verified quantum computation with an ion-trap quantum processing unit, Phys. Rev. Lett. , (2025)
2025
-
[73]
Polacchi, D
B. Polacchi, D. Leichtle, G. Carvacho, G. Milani, N. Spagnolo, M. Kaplan, E. Kashefi, and F. Sciarrino, Experimental verifiable multiclient blind quantum com- puting on a qline architecture, Phys. Rev. Lett.134, 200603 (2025)
2025
-
[74]
Drmota, D
P. Drmota, D. Nadlinger, D. Main, B. Nichol, E. Ain- ley, D. Leichtle, A. Mantri, E. Kashefi, R. Srinivas, G. Araneda,et al., Verifiable blind quantum computing with trapped ions and single photons, Physical Review Letters132, 150604 (2024)
2024
-
[75]
Observation of con- structive interference at the edge of quantum ergodicity
X. Mi and K. Kechedzhi, A verifiable quan- tum advantage,https://research.google/blog/ a-verifiable-quantum-advantage/(2025), google Quantum AI blog post related to “Observation of con- structive interference at the edge of quantum ergodicity”, Nature 646, 825–830 (2025)
2025
-
[76]
Czarnik, A
P. Czarnik, A. Arrasmith, P. J. Coles, and L. Cincio, Er- ror mitigation with Clifford quantum-circuit data, Quan- tum5, 592 (2021)
2021
- [77]
- [78]
-
[79]
T. Peng, A. W. Harrow, M. Ozols, and X. Wu, Simulating large quantum circuits on a small quantum computer, Physical review letters125, 150504 (2020)
2020
-
[80]
X. Yuan, J. Sun, J. Liu, Q. Zhao, and Y. Zhou, Quantum simulation with hybrid tensor networks, Phys. Rev. Lett. 127, 040501 (2021)
2021
-
[81]
Harada, Y
H. Harada, Y. Suzuki, B. Yang, Y. Tokunaga, and S. Endo, Density matrix representation of hybrid tensor networks for noisy quantum devices, Quantum9, 1823 (2025)
2025
-
[82]
B. Yang, N. Yoshioka, H. Harada, S. Hakkaku, Y. Toku- naga, H. Hakoshima, K. Yamamoto, and S. Endo, Resource-efficient generalized quantum subspace expan- sion, Phys. Rev. Appl.23, 054021 (2025)
2025
-
[83]
S. A. Sater and H. Ollivier, Composable verification in the circuit-model via magic-blindness (2026)
2026
-
[84]
Huang, R
H.-Y. Huang, R. Kueng, and J. Preskill, Predicting many properties of a quantum system from very few measure- ments, Nature Physics16, 1050–1057 (2020)
2020
-
[85]
Seif, Z.-P
A. Seif, Z.-P. Cian, S. Zhou, S. Chen, and L. Jiang, Shadow distillation: Quantum error mitigation with clas- sical shadows for near-term quantum processors, PRX Quantum4, 010303 (2023)
2023
-
[86]
Jnane, J
H. Jnane, J. Steinberg, Z. Cai, H. C. Nguyen, and B. Koc- zor, Quantum error mitigated classical shadows, PRX Quantum5, 010324 (2024)
2024
-
[87]
McDiarmid, On the method of bounded differences, in Surveys in Combinatorics, 1989(Cambridge University Press, 1989) p
C. McDiarmid, On the method of bounded differences, in Surveys in Combinatorics, 1989(Cambridge University Press, 1989) p. 148–188
1989
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.