REVIEW 3 major objections 4 minor 1 cited by
Universal distributed blind quantum computing with solid-state qubits
T0 review · 3 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read The paper reports the first matter-qubit realization of a universal blind quantum gate set on a two-node silicon-vacancy network, with client-hidden single- and two-qubit operations and measured Holevo information far below one bit.
desk verdict First matter-based universal blind gate set on a distributed two-node SiV network, but the blindness evidence omits the success/failure side channel and the two-qubit gates lack experimental process tomography. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the spin-photon gate (SPG), in which spin-dependent reflection of a time-bin photon from the SiV-cavity system creates a photon-electron Bell pair; the client's measurement of that photon in the basis $|0\rangle \pm e^{i\phi}|1\rangle$ secretly applies $R_z(\phi)$ to the electron. Three SPGs interleaved with Hadamard gates make the universal one-qubit blind gate, with the client's real-time adjustment of later phases absorbing Pauli feedback. For the distributed two-qubit gate, the paper introduces the QUBE gate, which entangles a four-time-bin photonic qudit with two electron spins and lets the client secretly choose between a short or long time-delay interferometer; the short setting interferes neighboring time bins and turns on $e_1$-$e_2$ entanglement, while the long setting interferes next-nearest bins and leaves the qubits unentangled, so the servers always observe the same dephasing channel $\mathcal{N}_2(\rho)$ regardless of whether the implemented operation is $CZ$ or identity.
What would settle it
Re-analyze the recorded data with a server-side classifier that is allowed to condition on the client's TDI choice (short or long delay), the photon arrival time bin, and the sequence of lost versus detected photons; if the mutual information between those conditioned server states and the client's choice of $CZ$ versus identity exceeds one bit, the demonstrated blindness bound no longer describes what a real server could learn.
Extended reading notes
Core claim
On its own terms, the paper establishes that matter qubits can implement the universal blind gate set required for blind quantum computing, not just blind rotations. Using two nodes, each a $^{29}$SiV center coupled to a nanophotonic cavity, it demonstrates a one-qubit blind gate built from three successive spin-photon gates (realizing $R_z(\phi_3)R_x(\phi_2)R_z(\phi_1)$), an intra-node two-qubit blind gate that produces either $S_{e1}S_{n1}CZ$ or identity depending on the client's measurement phase, and a distributed two-qubit blind gate (the QUBE gate) that hides whether $CZ$ or identity is applied across the two servers. In all cases the server's reduced density matrix is nearly independent of the client's choice: the measured Holevo information is $0.0045^{+0.018}_{-0.0045}$ bits for the blind rotation, $0.032^{+0.12}_{-0.032}$ bits for the intra-node gate, and $0.12 \pm 0.06$ bits for the distributed gate. The same components run a four-oracle Deutsch-Jozsa-type algorithm in which the client identifies constant versus balanced functions with average probability $0.85 \pm 0.03$, while the servers cannot distinguish the paired oracles (leakage $0.05^{+0.19}_{-0.05}$ and $0.07^{+0.14}_{-0.07}$ bits).
Load-bearing premise
The blindness proof assumes that after a successfully heralded gate the servers know only that the gate succeeded; if a real server could also learn the client's interferometer setting, the photon's arrival-time pattern, or the loss history, the measured Holevo information would not upper-bound the true information leakage.
Editorial extensions
If this is right
- A client who can prepare and measure single photons can in principle tile the demonstrated universal blind cell in the brickwork pattern to run arbitrary circuits on remote matter qubits.
- The two-qubit blind gate uses one photon instead of the five photons required in all-photonic blind implementations, reducing the dominant loss overhead by roughly the fifth power of the photon efficiency.
- The same gates plug into memory-based distributed architectures, where repeated entanglement attempts are stored in ancillary qubits; the authors estimate this changes algorithm running time from exponential in depth to linear in depth.
- The hidden-oracle Deutsch-Jozsa-type algorithm runs with the servers unable to distinguish constant from balanced oracles, although the current probabilistic QUBE gate and post-selection steps do not preserve the usual single-query quantum advantage.
Reading between the lines
- An adversarial model that gives the servers access to the client's time-delay-interferometer setting (short versus long), photon arrival times, or the pattern of lost photons would enlarge their information beyond the paper's assumed 'gate succeeded' flag; the reported Holevo bounds do not automatically cover those side channels.
- The switchable-entanglement mechanism is platform-agnostic: any emitter platform with a matter-photon entangling gate and a client-controlled interferometer could test the same hidden $CZ$-versus-$I$ operation, including neutral atoms, trapped ions, or superconducting qubits with microwave-optical transduction.
- A near-term upgrade that would restore the Deutsch-Jozsa single-query advantage is to add a memory qubit so the ancilla post-selection and the one-photon-of-two-QUBEs post-selection are eliminated; the paper's proposed teleportation-to-memory procedure is the natural implementation.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper reports an experimental implementation of blind quantum computing primitives using silicon-vacancy (SiV) centers in nanophotonic cavities as two distributed matter-qubit servers. The authors demonstrate a single-qubit blind gate based on three spin-photon gates with adaptive feedback, an intra-node two-qubit blind gate that can implement either an entangling or non-entangling operation, and a distributed two-qubit blind gate across two servers using a four-time-bin photonic qudit. They also implement a Deutsch-Jozsa-type algorithm with hidden oracles. The central claim is that these ingredients constitute the first matter-based universal blind gate set for distributed blind quantum computing, supported by measured gate fidelities and Holevo information values for the information leakage to the servers.
Significance. If the central claim holds, this is an important experimental step: it is the first matter-qubit realization of the universal blind gate set needed for measurement-based blind quantum computing, and the distributed two-node implementation demonstrates a scalable architecture that combines local matter-qubit control with photon-mediated remote gates. The supplement contains self-contained derivations of the blindness property for the ideal gates (Eqs. S4, S10, S17), and the paper reports measured single-qubit process tomography, state fidelities for the two-qubit gates, and Holevo information bounds. The explicit discussion of efficiency, error budgets, and paths toward deterministic operation via quantum memories is useful and grounded in the demonstrated hardware.
major comments (3)
- [Supplement §III and §IV A] The reported Holevo information χ, defined in Eq. (S41), quantifies only the distinguishability of the server's post-gate matter-qubit density matrices, averaged over the client's secret measurement outcomes. Supplement §III states explicitly that the server is assumed to know when the gate has succeeded, and in a repeat-until-success implementation the success/failure history and the waiting time are observable classical side channels. If the successfully heralded detection rate or the timing distribution depends on the client's hidden choice (for example, through the short- versus long-TDI switching in Fig. 4D, or through angle-dependent contrast asymmetries discussed in §III C), the true information leakage can exceed the measured χ. The authors should either extend the leakage bound to include these side channels or provide an explicit argument that they are independent of the client's choice.
- [Supplement §IV D] The data-analysis section states that thresholds for SiV contrast, π-pulse fidelity, initialization fidelity, and laser drift are optimized after seeing the data to maximize the client fidelity, and the reported χ values are computed only on the filtered set. Because the discarded runs are precisely those in which the server's observations may be most strongly correlated with the client's gate choice, the reported leakage bounds are not conservative. Please report the information leakage on the unfiltered data or under a pre-registered threshold-selection rule, and show explicitly that the filtering is independent of the client's choice.
- [Main text Figs. 3–4; Supplement §III B] The universal gate-set claim is supported for single-qubit gates by process tomography (Supplement Fig. S19), but the two-qubit blind gates are characterized only by state fidelities on selected inputs (e.g., product/Bell fidelities of 0.85 for the intra-node gate and 0.76/0.75 for the distributed gate) and by truth tables. Supplement §III B acknowledges that full gate-set tomography was not performed experimentally and supplies simulated process fidelities instead. Since the central claim includes a universal two-qubit gate, the paper should provide an experimentally measured process fidelity or a clearly justified alternative metric that certifies the two-qubit gate operation beyond selected input states.
minor comments (4)
- [Discussion] The word 'realizaion' in the last sentence of the Discussion is a typo and should read 'realization'.
- [Supplement §I F and Table S3] The phrase 'post selectong' appears in the caption of Table S3 and should be corrected to 'post selecting'; elsewhere in the supplement, 'P hotonCount' should be 'PhotonCount' and 'sample principle' should be 'same principle'.
- [Supplement §I A] The manuscript relies on Ref. [13], an unpublished 'manuscript in preparation', for the definition and decomposition of the universal blind cell and for the matter-photon BQC framework. Since these components are central to the claimed universality, the authors should either include the necessary definitions and proofs in the supplement or cite a published or otherwise publicly available version.
- [Supplement §II C and Fig. S10] In the description of the qudit POVMs, the phases ϕ1, ϕ2, ϕ3 are used in the text but the corresponding elements in Fig. S10C,D are not labeled consistently; adding a short definition in the figure caption would improve clarity.
Circularity Check
No significant circularity; the blindness and gate-set derivations are self-contained in the supplement.
full rationale
The paper's central claim is the experimental demonstration of a universal blind gate set on matter qubits. The blindness proofs in the supplementary material are algebraic and self-contained: Eq. S4 computes the server-reduced state for the 1QBG as an average over the client's secret outcomes and obtains the parameter-independent channel 1/2 I; Eq. S9–S10 does the same for the intra-node 2QBG, showing the server channel P0ρP0 + P1ρP1 is independent of the rotation angle φ; Eq. S16–S17 shows the distributed 2QBG server channel is independent of whether CZ or I is applied. These derivations use the definition of the gates and the assumption that the client's measurement outcome is unknown to the servers, which is the standard UBQC security model, not a circular assumption. The measured Holevo information is obtained directly from tomographic expectation values (Supplement IV.A), not from fitting a model to the blindness claim, so the experimental leakage numbers are not forced by construction. The only co-authored unpublished citation, ref. [13], is used for protocol definitions and fault-tolerant context, but the same definitions and derivations appear in the paper's own supplementary section I, so the citation is not load-bearing for the demonstration. The manuscript explicitly acknowledges the assumption that the server knows the gate succeeded (Supplement III), and the leakage calculation conditions on a heralded success; this is a modeling limitation regarding possible timing/success side-channels, which is a correctness/security concern rather than a circularity. The threshold optimization in Supplement IV.D selects data for fidelity and then computes leakage on the filtered set; while this could affect the robustness of the reported leakage, it is not equivalent to fitting a parameter and renaming it as a prediction. Overall, no step in the derivation reduces to its own inputs or to a self-citation that carries the argument.
Assumptions & free parameters
free parameters (4)
- Residual reflectivity threshold =
0.1 (Rz); 0.13 (1QBG)
- Pi-pulse fidelity threshold =
0.95 (Rz); 0.70 (1QBG)
- Initialization fidelity threshold =
0.94 (Rz); 0.91 (1QBG)
- Laser drift threshold =
0.3
assumptions (4)
- domain assumption Blindness of a gate can be certified by Holevo information of the server's reduced density matrix, conditioned on the server knowing the gate succeeded.
- standard math The brickwork-state universal blind cell construction from Broadbent et al. and Fitzsimons-Kashefi is valid and can be decomposed into 1QBG and 2QBG.
- domain assumption The cavity reflection model Eq. S33 accurately describes spin-dependent reflection with the fitted cavity-QED parameters.
- ad hoc to paper Data excluded by the fidelity-optimized thresholds are due to drift or error and are not correlated with the client's choice.
Cite this review
Pith. "Pith review of Universal distributed blind quantum computing with solid-state qubits." pith.science (2026). https://pith.science/paper/URY42GND
@misc{pith2026241203020,
author = {Pith},
title = {Pith review of: Universal distributed blind quantum computing with solid-state qubits},
year = {2026},
howpublished = {\url{https://pith.science/paper/URY42GND}},
note = {Machine review of arXiv:2412.03020}
}
read the original abstract
Blind quantum computing (BQC) is a promising application of distributed quantum systems, where a client can perform computations on a remote server without revealing any details of the applied circuit. While the most promising realizations of quantum computers are based on various matter qubit platforms, implementing BQC on matter qubits remains an outstanding challenge. Using silicon-vacancy (SiV) centers in nanophotonic diamond cavities with an efficient optical interface, we experimentally demonstrate a universal quantum gate set consisting of single- and two-qubit blind gates over a distributed two-node network. Using these ingredients, we perform a distributed algorithm with blind operations across our two-node network, paving the way towards blind quantum computation with matter qubits in distributed, modular architectures.
Figures
Forward citations
Cited by 1 Pith paper
-
Designing Fault-Tolerant Blind Quantum Computation
A hybrid matter-photon architecture for blind quantum computing offloads error correction to the server and is claimed to raise the communication error threshold to up to 10% with linear photonic overhead.
Reference graph
Works this paper leans on
-
[13]
Distributed 2QBG Similar to the intra-node 2QBG, we start by applying a distributed 2QBG to ancilla qubits and then teleport onto the memory qubits, as shown in Figs. S7E,F. The operation after the teleportation is summarized at the bottom of Fig. S7F. The feedback operator Z s1 1 Z s2 2 and the operation {I/CZ } remain the same after teleportation, prese...
-
[1]
S3D) − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − →
Servers apply QUBE1, local 2-qubit gate, QUBE2 (see Fig. S3D) − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − →
-
[2]
Based on the targeted oracle, Client chooses the photon measurement basis in Table S2 − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − − →
-
[3]
Server post selecting on |−⟩a − − − − − − − − − − − − − − − − − − − − →(−1)f (x)|x⟩c (S26) (check Table S2). This implements an oracle based on a specific function, with the output of the function imprinted on the phase of the computational qubits (see Eq. S26 and Fig. S4B). By choosing the initial state of computational qubits to be a superposition state...
-
[4]
First, our quantum network photonic link has an efficiency of ∼ 10−5 efficiency
Post selection There are several post selection components in our experiment, which makes our success probability much less than 50% and therefore cancels the quantum speedup associated with the standard Deutsch-Jozsa algorithm. First, our quantum network photonic link has an efficiency of ∼ 10−5 efficiency. This can in principle be solved by having a det...
-
[5]
Experimental data To characterize our gate performance, we first check the parity of the three spin qubits after applying our protocol. After applying our gate sequence to the qubit initialized in |e2, e1, n1⟩ = |+ + +⟩, we get |Oi⟩ = 1 2n/2+1 X x={0,1}n |x⟩c |+⟩a + (−1)f (x) |x⟩c |−⟩a (S28) . Here n = 2 means the number of computational qubits. Post sele...
-
[6]
Blind rotation A deterministic blind z rotation, as already demonstrated in [14], can be achieved by first implementing the Rz(ϕ) blind rotation on the ancilla qubits (initialized at |+⟩) as we described in the main text. In our proposed method, this can be followed by a teleportation to map the operation back to the quantum memory. The entire process is ...
-
[7]
While success ̸= 1 (Step1: SPG) P hotonCount← 0 While P hotonCount̸= 1: Initialize the ancilla Execute Intra-node 2QBG with angle ϕ′ and get the photon count (Step2: Teleportation) Server executes teleportation and the announces the measurement results m if m = 0: success ← 1 else: ϕ′ ← 2ϕ′
Show all 27 references
-
[8]
Client applies feedback based on s by changing the subsequent blind operation A deterministic 1QBG can straightforwardly be implemented by concatenating three deterministic blind Rz(ϕ) rotations interleaved with Hadamard gate on the quantum memory qubit
-
[9]
Intra-node 2QBG For a deterministic intra-node 2QBG, we similarly first try to establish entanglement between two ancilla qubits (a1, a2) and the photon ( γ), as shown in the first step of Fig. S7D. Each time we initialize the ancilla qubits in the state |+i, +i⟩a1,a2 , follow...
-
[10]
WhileP hotonCount̸= 1: Initialize 2 ancilla qubits |+i, +i⟩a1,a2 Execute Intra-node 2QBG with rotation basis ϕ, get the photon count (Step2: Teleportation)
-
[12]
NI-2QBG ∼ 1/η (S31)
Client applies feedback based on s, m1, m2 by changing the subsequent blind operation The required reset clock cycles ( NI-2QBG) are determined by the probability of successful intra-node 2QBG events using ancilla qubits η. NI-2QBG ∼ 1/η (S31)
-
[14]
While P hotonCount̸= 1 Initialize 3 ancilla qubits |+, +, +⟩a1,a2,a′ 2 Execute distributed 2QBG and get the photon count and outcome s1, s2 (Step2: Teleportation)
-
[15]
Server executes teleportation and the server announces the measurement results m1, m2
-
[16]
Client applies feedback based on s1, s2, m1, m2 by changing the subsequent blind operation The required reset clock cycles ( ND-2QBG) are determined by the probability of successful distributed 2QBG events ηD. ND-2QBG ∼ 1/ηD (S32) Similarly, the client’s choice of implementing...
-
[17]
( C) photonic qudit measurement outcomes depending on the photon arrival time at the SNSPDs and whether the click is recorded on SNSPD1 or 2 for a TDI with delay length ∆ = τ
while sweeping the measurement phase ϕ applied by the AOM for different input states |ψi⟩. ( C) photonic qudit measurement outcomes depending on the photon arrival time at the SNSPDs and whether the click is recorded on SNSPD1 or 2 for a TDI with delay length ∆ = τ . ( D) Same...
-
[18]
Several steps can be taken to improve the overall efficiencies
All the efficiencies for the 1QBG are cubed because the gate requires 3 successful photon events in a row. Several steps can be taken to improve the overall efficiencies. The WCS can be replaced with a single photon source for an in principle arbitrarily high efficiency, altho...
2000
-
[19]
photon events
µ errors - the infidelity which occurs due to the occurrence of n = 2, 3, ... photon events. Since our photonic qubit is created using weak coherent sources for µ <1, there is a ≈ µ2 2 chance of getting two photons in the same mode. When two-photon events occur, there is a cha...
-
[20]
This deviation from Ref (↑) Ref (↓) → ∞can come from non-ideal cavity-QED parameters, the spectral diffusion of the SiV and also due to stray reflections on the path
the contrast errors- the infidelity that comes from residual reflectivity of the cavity when the electric is in a non-reflective state. This deviation from Ref (↑) Ref (↓) → ∞can come from non-ideal cavity-QED parameters, the spectral diffusion of the SiV and also due to stray...
-
[21]
We include the infidelities as a coherent under- or over-rotation of the electron or nuclear spins in each experimental shot between beam splitter operations
microwave gate errors- the infidelity that comes from imperfect single qubit rotations driven by microwave or RF signals. We include the infidelities as a coherent under- or over-rotation of the electron or nuclear spins in each experimental shot between beam splitter operatio...
-
[22]
TDI errors - the infidelity that comes from imperfect interference of the photonic modes in the time delay interferometer. We simulate the phase offset of the interference operator due to imperfect locking of the TDI, which results in the deviation of the basis ϕ chosen by the...
-
[23]
We sweep Φ i over 4 values: Υ = {0, π 4 , π 2 , 3π 4 }, so that the information leakage can be calculated with equation S43 and NΦ = 4
Single qubit blind rotation The single qubit blind rotation about z axis ( Rz) is characterized by a single parameter Φ i = ϕi where ϕi is the rotation angle of the applied gate Rz(ϕi). We sweep Φ i over 4 values: Υ = {0, π 4 , π 2 , 3π 4 }, so that the information leakage can...
-
[24]
We choose three different values of Φ i: Υ = {(0, 0, 0), ( π 2 , π 2 , π 2 ), ( π 4 , π 2 , π 4 )}, corresponding to the Identity, Hadamard, and T √ XT gates, respectively
One-qubit blind gate (1QBG) The 1QBG consists of three consecutive blind rotations and is characterized by three parameters Φ i = (ϕ(0) i , ϕ(1) i , ϕ(2) i ) defining the applied gate Rz(ϕ(2) i )Rx(ϕ(1) i )Rz(ϕ(0) i ). We choose three different values of Φ i: Υ = {(0, 0, 0), (...
-
[25]
We sweep Φ i over 4 values: Υ = {0, π 4 , π 2 , 3π 4 } (NΦ = 4)
Intra-node two-qubit blind gate The intra-node 2QBG, as with the single qubit blind rotation, is characterized by a single parameter Φ i = ϕi, but here ϕi is the rotation angle of the SPG in the intra-node 2QBG sequence (Fig.S3B) . We sweep Φ i over 4 values: Υ = {0, π 4 , π 2...
-
[26]
Inter-node two-qubit blind gate For the application of the inter-node 2QBG, the client can choose the three phases of the 4D qudit phase gate (equation S35), as well as the use of the short TDI (to measure in the {|0⟩ ± |1⟩ , |2⟩ ± |3⟩} basis for an entangling gate) or the lon...
-
[27]
We compute the fidelity for each phase ϕ, average over all phases, and select the parameter set yielding the highest fidelity to calculate the information leakage
Blind rotation (Rz) For each combination of thresholds, phase ϕ, initial state, and measurement basis, we calculate the total number of shots before and after filtering, as well as the parity values for both the client and server. We compute the fidelity for each phase ϕ, aver...
-
[28]
For each set of thresholds, gates, and measurement bases, we calculate the total number of shots before and after filtering, as well as the parity for both client and server
One-qubit blind gate (1QBG) For the 1QBG), which is composed of three spin-photon gates, data are analyzed for each gate type{T X1/2T, I, H}, initial state |+i⟩, and measurement bases {X, Y, Z}. For each set of thresholds, gates, and measurement bases, we calculate the total n...
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.