Pith. sign in

REVIEW 4 major objections 6 minor 52 references

Optimal Quantum Differential Privacy via Fisher Information Spectral Analysis

T0 review · 4 major / 6 minor · reviewed 2026-07-14 · grok-4.5

Pith's one-line read Quantum privacy is tightest when noise is aimed only at the single most leaky direction of a quantum embedding, not spread evenly.

desk verdict Solid geometric idea for quantum DP—noise on the dominant QFI mode, plus constructive dephasing and saturating composition—but the headline advantage scaling is wrong and the optimality proof sits on uncontrolled local expansions. read the letter →

arxiv 2605.24166 v2 pith:NSCSVYWI submitted 2026-05-22 quant-ph cs.CR

classification quant-phcs.CR
keywords quantumdifferentialprivacyFisherinformationmetric-adaptedchannelminimaxnoiseallocationdephasingamplificationQFIcompositionembeddings
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper treats the Quantum Fisher Information of a quantum data embedding as the privacy sensitivity map: directions with large QFI eigenvalues are easy for an adversary to distinguish, while low-QFI directions are already hard to tell apart. Instead of the usual isotropic depolarizing channel that adds the same noise in every Hilbert-space direction, the authors design a metric-adapted channel that spends the entire noise budget on the single largest QFI eigenmode. They prove this allocation is minimax-optimal for the worst-case privacy parameter, yields an advantage that grows with Hilbert-space dimension, and comes with a privacy–utility uncertainty relation, adaptive estimation, composition that saturates rather than growing with depth, and a constructive use of hardware dephasing when it is misaligned with the adversary’s measurement. Experiments on simulators and IBM hardware report equivalent utility at privacy parameters orders of magnitude smaller than classical DP baselines. The practical stake is that geometry-aware quantum DP can make private quantum machine learning feasible where isotropic noise would destroy utility or exhaust the privacy budget.

What carries the argument

The metric-adapted channel Φγ,p, which replaces isotropic depolarizing with a mixture of unitaries that shift the state along QFI eigenvectors, together with the first-order effective-QFI formula that contracts each mode by (1−cγ pk). Privacy is then controlled by max_k λk(1−cγ pk).

What would settle it

Implement the claimed metric-adapted generators on a device or high-fidelity simulator, measure the actual max-divergence between neighboring embeddings for a known anisotropic QFI spectrum, and check whether the observed ε matches (Δ²/2)·λmax·(1−cγ) rather than the isotropic formula or a weaker intermediate bound.

Watch

Extended reading notes

Core claim

For a quantum embedding whose QFI eigenvalues are ordered λ1 ≥ λ2 ≥ ⋯, the minimax-optimal DP mechanism concentrates the entire noise budget on the dominant eigenmode alone. The resulting privacy parameter is ε* = (Δ²/2)·λ1·(1−cγ), which improves on isotropic depolarizing by a factor that scales as Ω(d/λ1) and saturates under aligned multi-layer composition.

Load-bearing premise

The argument rests on a local, first-order model of how the metric-adapted channel contracts the QFI and on the claim that worst-case privacy after the channel is fully captured by that contracted maximum eigenvalue.

Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper proposes a geometry-aware quantum differential privacy framework that replaces isotropic depolarizing noise with a metric-adapted channel aligned to the Quantum Fisher Information (QFI) eigenstructure of a quantum embedding. It proves six main results: (1) minimax-optimal noise concentrates on the dominant QFI mode, giving ε* = (Δ²/2)λ_max(1−cγ) and a claimed advantage over isotropic depolarizing; (2) mixed-state SLD decomposition showing that aligned dephasing can increase accessible information while misaligned dephasing amplifies privacy; (3) a privacy–utility uncertainty relation; (4) adaptive EMA QFI estimation with O(1/√n) convergence; (5) QFI-aligned composition that saturates at O(1) when successive layers share eigenvectors; and (6) constructive use of hardware noise. Corollaries cover adversarial attacks, Wasserstein bounds, subspace projection, and a Merkle-tree ZK audit. Validation uses Qiskit Aer, IBM ibm_fez, and classical DP baselines on anisotropic embeddings.

Significance. If the technical claims hold under controlled approximations, the work is significant: it cleanly exploits the metrology–privacy duality of QFI, gives a concrete minimax design principle (spend the budget on λ_max), and produces composition and hardware-noise results that are not available from isotropic quantum DP. Strengths include an explicit metric-adapted channel, full appendix proofs, adaptive tracking, a practical audit protocol, and hardware runs on ibm_fez plus classical baselines. The constructive dephasing result (misaligned hardware noise as a privacy resource) is of independent NISQ interest. These contributions would matter for private QML on cloud quantum services, provided the local expansions and advantage scalings are repaired and stated accurately.

major comments (4)
  1. Abstract and Theorem 3.1 (Eq. 13) claim an advantage R = ε_iso/ε* = Ω(d/λ_1) or O(d/λ_max). The isotropic baseline used is ε_iso = ln(1 + d/(γ(1−γ))) ∼ ln d, so the ratio scales as O((ln d)/λ_max), not Ω(d/λ_max). The proof text itself writes “R ∼ ln d/λ_1 = Ω(d/λ_1),” which is incorrect. This overstates the central quantitative claim in the abstract, introduction, and theorem statement and must be corrected throughout (including experimental extrapolations that invoke the same scaling).
  2. Lemma 2.4 and Sec. 2.4–2.5 are load-bearing for Theorem 3.1: optimality and ε* rest on F_eff with a single calibration constant c and on the local conversion D_∞ ≈ (Δ²/2)λ_max. Both are first-order small-γ / small-Δ expansions (fidelity of the metric-adapted mixture; pure-state fidelity expansion with a “refined” coefficient change from 1/4 to 1/2 citing Helstrom). There are no remainder bounds showing that max_k λ_k(1−cγ p_k) still dominates for finite implementable η_k and the Δ, γ used in experiments. If O(γ²) or higher-order Bures/max-divergence terms reorder effective eigenvalues, or if U_k fail to realize pure directional contraction, the minimax argument and advantage claims fail. Please supply controlled remainders or numerical verification of the effective spectrum for the concrete generators.
  3. Theorem 3.6 / Appendix A.3: the product bound derivation inserts a factor γ/d into ε·(1−F_min), then appeals to “lim γ o0 and optimal γ” to recover ε·(1−F_min) ≥ (Δ²/2) Tr(F)/d without that factor. As written this step is not justified (the lower bound vanishes as γ o0). Either fix the derivation with a γ-independent argument or weaken the claimed tight uncertainty relation and its abstract statement.
  4. Theorem 8.1’s O(1) saturation assumes successive layers share QFI eigenvectors (and the same λ_max contraction). The manuscript states this, but the abstract and contribution list present saturating composition as a general principal theorem. Please scope the claim to the aligned case, and either bound the misaligned interpolation (mentioned as open in Sec. 11.3) or mark composition advantage as conditional in the abstract/results summary.
minor comments (6)
  1. Sec. 2.4: the jump from D_∞ ≈ (1/4) dx^T F dx to coefficient Δ²/2 via “refined calculation [27]” should be spelled out or given a self-contained derivation; Helstrom is primarily estimation theory.
  2. Fig. 1 caption and circuit description are useful; ensure α = [3.0,1.0,0.3,0.1] and the reported λ spectrum are consistent across Sec. 10.2 (λ ≈ [9,9,0.09,0.09]) and later adversarial numbers (λ ≈ [11.2,…]).
  3. Classical DP comparison (Fig. 11, ε ≈ 0.001 vs ≈ 4800) should state explicitly that noise is applied to different objects (kernel entries vs QFI-aligned channel); otherwise the 10^6 imes claim can be misread as a like-for-like mechanism comparison.
  4. Notation: c ∈ (0,2] is free in Lemma 2.4 but often set to 1; state the experimental default and sensitivity of reported factors (1.92 imes, 9 imes, 308 imes) to c.
  5. Related work is thorough; a short explicit contrast with Hirche et al. Rényi quantum DP on composition tightness would help place Theorem 8.1.
  6. Typos/formatting: “Privacy− utility” spacing in abstract; Algorithm 1 is referenced as Fig. 2; ensure theorem numbering in figures (“Thm 10”, “Thm 11”) matches the body.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: main theorems are minimax/series derivations from a first-order effective-QFI model and standard local max-divergence, not fits or self-citation chains.

full rationale

The load-bearing chain for Theorem 3.1 is: (i) pure-state fidelity expansion giving local D_∞ ~ dx^T F dx (Sec. 2.4, with coefficient refined via Helstrom [27]); (ii) Lemma 2.4’s first-order contraction F_eff with factors (1−cγ p_k) for the metric-adapted channel; (iii) minimax over the simplex of max_k λ_k(1−cγ p_k), which forces p*_1=1. That is a conditional derivation under stated small-γ/small-Δ expansions, not a result forced by defining ε in terms of itself or by fitting the target. Calibration η_k ~ √(2ε_target/(Δ² λ_k)) is ordinary mechanism design (analogous to setting Laplace scale to Δ/ε), and c is left as a model constant, not reverse-engineered from the experimental 1.92× / 308× / 9× factors—those are measurements on constructed anisotropic embeddings. Composition (Thm 8.1) is a geometric series from successive application of the same contraction; mixed-state SLD split and Wasserstein lift are standard expansions. Related work cites external literature (Aaronson–Rothblum, Zhou–Ying, Zou et al., Helstrom, Braunstein–Caves, etc.); there is no load-bearing self-citation or uniqueness theorem imported from the present authors. Weak local approximations and possible unfair classical baselines are correctness/scope issues, not circularity. Score 0 with empty steps is the honest finding.

Assumptions & free parameters 4 free parameters · 5 assumptions · 2 invented entities

The central optimality claim rests on standard QFI/DP definitions plus a paper-specific metric-adapted channel and a first-order effective-QFI contraction with free calibration c. Experimental advantage numbers further depend on hand-chosen anisotropic embeddings and noise schedules. No new physical entity is postulated; the invented object is the mechanism and its effective-QFI calculus.

free parameters (4)
  • calibration constant c in effective QFI
    Lemma 2.4 introduces c∈(0,2] (claimed ≈1 when η_k is optimally calibrated). All ε* and composition formulas scale with c; it is not derived from first principles for general embeddings.
  • embedding rotation strengths α
    α=[3.0,1.0,0.3,0.1] is chosen by hand to create a 100:1 QFI condition number for experiments and adversarial ratios; not forced by data.
  • EMA decay β and noise budget γ schedules
    Adaptive tracking uses β (e.g. 0.9) and experimental γ values that set reported 1.92× and composition ratios; chosen for demonstration.
  • mixed-state mixture weight 0.6/0.4
    Sec. 4 experiment uses ρ=0.6|ψ⟩⟨ψ|+0.4σ to illustrate classical/quantum QFI reorganization; illustrative, not estimated from hardware tomography.
assumptions (5)
  • domain assumption Quantum (ε,0)-DP via max-divergence / POVM likelihood ratio (Def. 2.1), following Zhou–Ying / Zou et al.
    Privacy semantics are taken from prior quantum DP literature and used as the optimization target.
  • standard math Local fidelity expansion |⟨ψ(x)|ψ(x+dx)⟩|² = 1 − (1/4) dx^T F dx + O(∥dx∥³) converts QFI into ε
    Standard pure-state QFI/Bures geometry; paper upgrades coefficient to Δ²/2 without full main-text derivation.
  • ad hoc to paper Metric-adapted channel Φ_{γ,p} contracts each QFI mode as λ_k(1−cγ p_k)+O(γ²) (Lemma 2.4)
    Load-bearing effective-QFI model for the paper’s mechanism; depends on generator calibration and small-γ expansion.
  • ad hoc to paper Successive layers share QFI eigenvectors for saturating composition (Thm 8.1)
    Strong alignment assumption; paper notes misaligned case is open.
  • domain assumption QFI map is L-Lipschitz on the data domain for adaptive EMA rates (Thm 5.1)
    Needed for O(1/√n) convergence; not verified beyond the constructed embedding.
invented entities (2)
  • Metric-adapted (QFI-aligned) DP channel Φ_{γ,p}
    purpose: Replace isotropic depolarizing with direction-dependent random unitaries along QFI eigenmodes to achieve minimax ε.
    Defined in Def. 2.3; central engineered object. Independent evidence is only the paper’s simulations/hardware population statistics, not an external standard mechanism.
  • Zero-knowledge Merkle-tree DP audit sigma protocol for per-sample QFI/ε
    purpose: Cryptographic corollary so a prover can claim ε without revealing all data.
    Standard Merkle/Fiat–Shamir techniques applied to QFI logs; not a new physical entity, but a paper-specific protocol construction.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Optimal Quantum Differential Privacy via Fisher Information Spectral Analysis." pith.science (2026). https://pith.science/paper/NSCSVYWI

@misc{pith2026260524166,
  author       = {Pith},
  title        = {Pith review of: Optimal Quantum Differential Privacy via Fisher Information Spectral Analysis},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/NSCSVYWI}},
  note         = {Machine review of arXiv:2605.24166}
}
abstract

The Quantum Fisher Information (QFI) metric governs a fundamental duality: it quantifies both how precisely a parameter can be estimated (metrology) and how distinguishable two quantum states are (privacy). We exploit this duality to establish a geometry-aware framework for quantum differential privacy (DP) that replaces isotropic depolarizing noise with direction-dependent noise aligned to the QFI eigenstructure of the quantum embedding. We prove six principal theorems: (1) the minimax-optimal mechanism concentrates the noise budget in the dominant QFI eigenmode, achieving $\varepsilon = (\Delta^2/2)\lambda_{\max}(1-c\gamma)$ with $O(d/\lambda_{\max})$ advantage; (2) mixed-state QFI decomposition reveals that dephasing in the adversary's basis $\textit{increases}$ accessible information, while misaligned-basis dephasing provides constructive privacy amplification from hardware noise; (3) a tight privacy $-$ utility uncertainty relation $\varepsilon \cdot (1 - F) \ge \frac{\Delta^2}{2}\frac{\operatorname{Tr}(F)}{d}$; (4) adaptive QFI estimation converging at $O(1/\sqrt{n})$ yields $1.92\times$ tighter bounds; (5) QFI-aligned composition saturates at $O(1)$ versus $O(k)$ for standard composition; and (6) hardware noise can be harnessed for privacy amplification. Adversarial vulnerabilities, Wasserstein guarantees, subspace projection, and a zero-knowledge audit protocol follow as corollaries. Results are validated on Qiskit Aer GPU simulations, IBM Quantum hardware (ibm_fez, 156 qubits), and against classical DP baselines, achieving equivalent utility at $\varepsilon \approx 0.001$ versus $\varepsilon \approx 4800$ for classical DP.

Figures

Figures reproduced from arXiv: 2605.24166 by the authors.

Figure 1
Figure 1. Quantum circuit transpiled for ibm_fez (156-qubit Eagle r3 processor) from IBM Quantum [PITH_FULL_IMAGE:figures/full_fig_p007_1.png] view at source ↗
Figure 3
Figure 3. Privacy–utility tradeoff. The optimal targeted channel (red dashed) achieves substantially lower [PITH_FULL_IMAGE:figures/full_fig_p013_3.png] view at source ↗
Figure 4
Figure 4. QFI eigenvalue spectra. Left: isotropic (degenerate, all [PITH_FULL_IMAGE:figures/full_fig_p014_4.png] view at source ↗
Figures from the paper (8 more)
Figure 5
Figure 5. Figure 5: Privacy–accuracy Pareto frontier. The green shaded region ( [PITH_FULL_IMAGE:figures/full_fig_p015_5.png]
Figure 6
Figure 6. Figure 6: Hardware noise impact on fidelity. Error bars [PITH_FULL_IMAGE:figures/full_fig_p015_6.png]
Figure 7
Figure 7. Figure 7: Composition advantage ratio R(k) = εseq/εqfi. At γ = 0.1 (red), the advantage exceeds 2× at k = 20 and 9× at k = 100. The saturation of εqfi as k → ∞ is the key geometric contribution. 11 Discussion 11.1 The QFI as a Universal Privacy Metric The QFI emerges from our an…
Figure 8
Figure 8. Figure 8: Left: QFI evasion—distinguishability D∞ by perturbation direction. Perturbing along the minimum-QFI eigenvector produces 308× less distinguishable state changes than perturbing along the maximum-QFI eigenvector. Right: Information leakage pie chart—76.0% of total mutua…
Figure 9
Figure 9. Figure 9: Adaptive QFI tracking. Per-batch λmax estimates (circles), EMA trajectory with β = 0.9 (red line), population mean (green dashed), and worst-case bound (gray dotted). The EMA stabilizes within 7 batches, providing 1.92× tighter ε than the worst-case analysis. eigenbase…
Figure 10
Figure 10. Figure 10: End-to-end QFI-DP pipeline architecture. Box colors: blue = classical, green = quantum, yellow = theory, [PITH_FULL_IMAGE:figures/full_fig_p019_10.png]
Figure 11
Figure 11. Figure 11: Privacy–utility tradeoff: QFI-optimal vs classical DP mechanisms. The QFI-optimal channel (red) achieves [PITH_FULL_IMAGE:figures/full_fig_p020_11.png]
Figure 12
Figure 12. Figure 12: Constructive dephasing privacy amplification. Left: Mutual information between feature [PITH_FULL_IMAGE:figures/full_fig_p021_12.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references

  1. [1]

    Marco Cerezo, Guillaume Verdon, Hsin-Yuan Huang, Lukasz Cincio, and Patrick J. Coles. Chal- lenges and opportunities in quantum machine learning.Nature Computational Science, 4:363–374, 2024

  2. [2]

    Iris Cong, Soonwon Choi, and Mikhail D. Lukin. Quantum convolutional neural networks.Nature Physics, 15:1273–1278, 2019

  3. [3]

    Córcoles, Kristan Temme, Aram W

    Vojtěch Havlíček, Antonio D. Córcoles, Kristan Temme, Aram W. Harrow, Abhinav Kandala, Jerry M. Chow, and Jay M. Gambetta. Supervised learning with quantum-enhanced feature spaces.Nature, 567:209–212, 2019

  4. [4]

    A rigorous and robust quantum speed-up in supervised machine learning.Nature Physics, 17:1013–1017, 2021

    Yunchao Liu, Srinivasan Arunachalam, and Kristan Temme. A rigorous and robust quantum speed-up in supervised machine learning.Nature Physics, 17:1013–1017, 2021

  5. [5]

    Hsin-Yuan Huang, Michael Broughton, Masoud Mohseni, Ryan Babbush, Sergio Boixo, Hartmut Neven, and Jarrod R. McClean. Power of data in quantum machine learning.Nature Communi- cations, 12:2631, 2021

  6. [6]

    Benjamin, Suguru Endo, Keisuke Fujii, Jarrod R

    Marco Cerezo, Andrew Arrasmith, Ryan Babbush, Simon C. Benjamin, Suguru Endo, Keisuke Fujii, Jarrod R. McClean, Kosuke Mitarai, Xiao Yuan, Lukasz Cincio, and Patrick J. Coles. Variational quantum algorithms.Nature Reviews Physics, 3:625–644, 2021

  7. [7]

    Kottmann, Tim Menke, Wai-Keong Mok, Sukin Sim, Leong-Chuan Kwek, and Alán Aspuru-Guzik

    Kishor Bharti, Alba Cervera-Lierta, Thi Ha Kyaw, Tobias Haug, Sumner Alperin-Lea, Abhinav Anand, Matthias Degroote, Hermanni Heimonen, Jakob S. Kottmann, Tim Menke, Wai-Keong Mok, Sukin Sim, Leong-Chuan Kwek, and Alán Aspuru-Guzik. Noisy intermediate-scale quantum algorithms.Reviews of Modern Physics, 94:015004, 2022

  8. [8]

    Olson, and Alán Aspuru-Guzik

    Jonathan Romero, Jonathan P. Olson, and Alán Aspuru-Guzik. Quantum autoencoders for effi- cient compression of quantum data.Quantum Science and Technology, 2:045001, 2017

Show all 52 references
  1. [9]

    Quantumgenerativeadversarialnetworks.Phys- ical Review A, 98:012324, 2018

    Pierre-LucDallaire-DemersandNathanKilloran. Quantumgenerativeadversarialnetworks.Phys- ical Review A, 98:012324, 2018

  2. [10]

    Quantum generative adversarial learning.Physical Review Letters, 121:040502, 2018

    Seth Lloyd and Christian Weedbrook. Quantum generative adversarial learning.Physical Review Letters, 121:040502, 2018. 24

  3. [11]

    Harrow, Avinatan Hassidim, and Seth Lloyd

    Aram W. Harrow, Avinatan Hassidim, and Seth Lloyd. Quantum algorithm for linear systems of equations.Physical Review Letters, 103:150502, 2009

  4. [12]

    Quantum computing in the NISQ era and beyond.Quantum, 2:79, 2018

    John Preskill. Quantum computing in the NISQ era and beyond.Quantum, 2:79, 2018

  5. [13]

    Quantum differential privacy: An information theory perspective.IEEE Transactions on Information Theory, 69:2483–2504, 2023

    Yuxuan Du, Min-Hsiu Hsieh, Tongliang Liu, and Dacheng Tao. Quantum differential privacy: An information theory perspective.IEEE Transactions on Information Theory, 69:2483–2504, 2023

  6. [14]

    Quantum machine learning with differential privacy.Scientific Reports, 13:2453, 2023

    William Watkins, Samuel Yen-Chi Chen, and Shinjae Yoo. Quantum machine learning with differential privacy.Scientific Reports, 13:2453, 2023

  7. [15]

    Enhancing quantum machine learning with differential privacy.Quantum Science and Technology, 9:025011, 2024

    Weikang Gong, Dong Yuan, Weihua Li, and Mile Gu. Enhancing quantum machine learning with differential privacy.Quantum Science and Technology, 9:025011, 2024

  8. [16]

    Calibrating noise to sensitivity in private data analysis.Journal of Privacy and Confidentiality, 7(3):17–51, 2016

    Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. Calibrating noise to sensitivity in private data analysis.Journal of Privacy and Confidentiality, 7(3):17–51, 2016

  9. [17]

    The algorithmic foundations of differential privacy.Foundations and Trends in Theoretical Computer Science, 9(3–4):211–407, 2014

    Cynthia Dwork and Aaron Roth. The algorithmic foundations of differential privacy.Foundations and Trends in Theoretical Computer Science, 9(3–4):211–407, 2014

  10. [18]

    Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang

    Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. Deep learning with differential privacy. InProceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 308–318, 2016

  11. [19]

    RAPPOR: Randomized aggregatable privacy-preserving ordinal response

    Úlfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. RAPPOR: Randomized aggregatable privacy-preserving ordinal response. InProceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 1054–1067, 2014

  12. [20]

    Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang

    H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. Learning differentially pri- vate recurrent language models. InInternational Conference on Learning Representations (ICLR), 2018

  13. [21]

    Rothblum, and Salil Vadhan

    Cynthia Dwork, Guy N. Rothblum, and Salil Vadhan. Boosting and differential privacy. In Proceedings of the 51st Annual IEEE Symposium on Foundations of Computer Science (FOCS), pages 51–60, 2010

  14. [22]

    Rothblum

    Scott Aaronson and Guy N. Rothblum. Gentle measurement of quantum states and differential privacy. InProceedings of the 51st Annual ACM Symposium on Theory of Computing (STOC), pages 322–333, 2019

  15. [23]

    Differential privacy in quantum computation

    Li Zhou and Mingsheng Ying. Differential privacy in quantum computation. InProceedings of the IEEE Computer Security Foundations Symposium (CSF), pages 249–262, 2017

  16. [24]

    Quantumdifferentialprivacywithdepolarizing channels.Quantum, 5:578, 2021

    JenniferZou, MaxArrasmith, andPatrickJ.Coles. Quantumdifferentialprivacywithdepolarizing channels.Quantum, 5:578, 2021

  17. [25]

    Braunstein and Carlton M

    Samuel L. Braunstein and Carlton M. Caves. Statistical distance and the geometry of quantum states.Physical Review Letters, 72:3439–3443, 1994

  18. [26]

    Monotone metrics on matrix spaces.Linear Algebra and Its Applications, 244:81–96, 1996

    Dénes Petz. Monotone metrics on matrix spaces.Linear Algebra and Its Applications, 244:81–96, 1996

  19. [27]

    Helstrom.Quantum Detection and Estimation Theory

    Carl W. Helstrom.Quantum Detection and Estimation Theory. Academic Press, 1976

  20. [28]

    Holevo.Probabilistic and Statistical Aspects of Quantum Theory

    Alexander S. Holevo.Probabilistic and Statistical Aspects of Quantum Theory. Edizioni della Normale, 2011

  21. [29]

    Quantum metrology.Physical Review Letters, 96:010401, 2006

    Vittorio Giovannetti, Seth Lloyd, and Lorenzo Maccone. Quantum metrology.Physical Review Letters, 96:010401, 2006

  22. [30]

    Multi-parameter estimation beyond quantum Fisher information.Journal of Physics A: Mathematical and Theoretical, 53: 363001, 2020

    Rafał Demkowicz-Dobrzański, Wojciech Górecki, and Mădălin Guţă. Multi-parameter estimation beyond quantum Fisher information.Journal of Physics A: Mathematical and Theoretical, 53: 363001, 2020

  23. [31]

    Quantum Fisher information matrix and multiparameter estimation.Journal of Physics A: Mathematical and Theoretical, 53: 023001, 2020

    Jing Liu, Haidong Yuan, Xiao-Ming Lu, and Xiaoguang Wang. Quantum Fisher information matrix and multiparameter estimation.Journal of Physics A: Mathematical and Theoretical, 53: 023001, 2020

  24. [32]

    Quantum Fisher information and its dynamical nature.PRX Quantum, 5:020322, 2024

    Johannes Jakob Meyer, Sebastian Gribben, Joseph Bowles, and Jens Eisert. Quantum Fisher information and its dynamical nature.PRX Quantum, 5:020322, 2024

  25. [33]

    Quantum natural gradient

    James Stokes, Josh Izaac, Nathan Killoran, and Giuseppe Carleo. Quantum natural gradient. Quantum, 4:269, 2020. 25

  26. [34]

    Fisher information in noisy intermediate-scale quantum applications

    Johannes Jakob Meyer. Fisher information in noisy intermediate-scale quantum applications. Quantum, 5:539, 2021

  27. [35]

    Quantum differential privacy: An information-theoretic perspective.IEEE Transactions on Information Theory, 69(9):5771–5787, 2023

    Christoph Hirche, Cambyse Rouzé, and Daniel Stilck França. Quantum differential privacy: An information-theoretic perspective.IEEE Transactions on Information Theory, 69(9):5771–5787, 2023

  28. [36]

    An equivalence between private learning and online learning in the quantum setting

    Mark Bun, Roi Livni, and Shay Moran. An equivalence between private learning and online learning in the quantum setting. InProceedings of the Conference on Learning Theory (COLT), pages 897–921, 2024

  29. [37]

    Adaptive quantum differential privacy

    Yonglong Li, Yifan Zhou, Yikang Zhang, and Tongyang Li. Adaptive quantum differential privacy. Quantum, 8:1297, 2024

  30. [38]

    Quantum privacy-preserving ma- chine learning via shadow tomography.npj Quantum Information, 10:42, 2024

    Shuaining Zhang, Xusheng Xu, Chengran Yang, and Mile Gu. Quantum privacy-preserving ma- chine learning via shadow tomography.npj Quantum Information, 10:42, 2024

  31. [39]

    Makhamisa Senekane, Mhlambululi Mafu, and Bentwell M. Taele. Privacy-preserving quantum machine learning through differential privacy.Quantum Information Processing, 20:244, 2021

  32. [40]

    Quantum computing for differential privacy.Quantum Science and Technology, 9: 045001, 2024

    ChrisCade, MartenFolkertsma, SevagGharibian, RyuHayakawa, FrançoisLeGall, andTomoyuki Morimae. Quantum computing for differential privacy.Quantum Science and Technology, 9: 045001, 2024

  33. [41]

    Genoni, and Ilaria Gianani

    Francesco Albarelli, Marco Barbieri, Marco G. Genoni, and Ilaria Gianani. A perspective on multiparameterquantummetrology: Fromtheoreticaltoolstoapplicationsinimagingandsensing. Applied Physics Letters, 123:140501, 2023

  34. [42]

    Quantum metrology in the presence of strongly correlated noise.Physical Review Letters, 133:090801, 2024

    Sisi Zhou, Michalis Skotiniotis, Jing Liu, Weiping Zhang, and Jianming Cai. Quantum metrology in the presence of strongly correlated noise.Physical Review Letters, 133:090801, 2024

  35. [43]

    Quantum adversarial machine learning.Physical Review Research, 2:033212, 2020

    Sirui Lu, Lu-Ming Duan, and Dong-Ling Deng. Quantum adversarial machine learning.Physical Review Research, 2:033212, 2020

  36. [44]

    Huggins, and K

    Haonan Liao, Ian Convy, William J. Huggins, and K. Birgitta Whaley. Machine learning in the quantum regime: Fundamental differences and their consequences.Quantum, 5:596, 2021

  37. [45]

    Quantum adversarial learn- ing and the role of entanglement.Nature Communications, 14:7621, 2023

    Nana Liu, Samuel Yen-Chi Chen, Chenghao Zhang, and Shinjae Yoo. Quantum adversarial learn- ing and the role of entanglement.Nature Communications, 14:7621, 2023

  38. [46]

    Verifying fairness in quantum machine learning

    Ji Guan, Wang Fang, and Mingsheng Ying. Verifying fairness in quantum machine learning. In Proceedings of the International Conference on Computer Aided Verification (CAV), pages 314– 336, 2024

  39. [47]

    The composition theorem for differential privacy.IEEE Transactions on Information Theory, 63(6):4037–4049, 2017

    Peter Kairouz, Sewoong Oh, and Pramod Viswanath. The composition theorem for differential privacy.IEEE Transactions on Information Theory, 63(6):4037–4049, 2017

  40. [48]

    Universal blind quantum computation

    Anne Broadbent, Joseph Fitzsimons, and Elham Kashefi. Universal blind quantum computation. InProceedings of the 50th Annual IEEE Symposium on Foundations of Computer Science (FOCS), pages 517–526, 2009

  41. [49]

    Classical verification of quantum computations

    Urmila Mahadev. Classical verification of quantum computations. InProceedings of the 59th Annual IEEE Symposium on Foundations of Computer Science (FOCS), pages 259–267, 2018

  42. [50]

    Computational security of quantum encryption

    GorjanAlagic, AmitBehera, ZvikaBrakerski, NicoDöttling, StaceyJeffery, andChristianMajenz. Computational security of quantum encryption. InProceedings of the Theory of Cryptography Conference (TCC), pages 1–31, 2024

  43. [51]

    Obfuscation of quan- tum computation

    James Bartusek, Andrea Coladangelo, Dakshita Khurana, and Fermi Ma. Obfuscation of quan- tum computation. InProceedings of the 56th Annual ACM Symposium on Theory of Computing (STOC), pages 1122–1132, 2024

  44. [52]

    Privacy amplification by iteration

    Vitaly Feldman, Ilya Mironov, Kunal Talwar, and Abhradeep Thakurta. Privacy amplification by iteration. InProceedings of the 59th Annual IEEE Symposium on Foundations of Computer Science (FOCS), pages 521–532, 2018. 26

Pith tools

Reviewed July 14, 2026 · model on record in the stance chip above.