arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

陷阱门 Clifford 算子及其应用

Trapdoored Clifford Operators and Applications

Minki Hhan, Hojune Lee

arXiv 2610.01848首次发表:更新:

发表机构

KAIST(韩国科学技术院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出陷阱门 Clifford 算子分布,在 LPN 变体假设下实现近线性采样与实现,用于加速量子协议并证明批量 Clifford 电路合成的困难性。

AI 中文摘要

随机 Clifford 算子在量子计算中有众多应用,包括随机基准测试、经典阴影和量子认证。然而,由于 Clifford 群的大小,采样和实现均匀随机的 $n$ 比特 Clifford 算子会带来近二次方的复杂度。我们引入了一种密码学方法来克服这些障碍:陷阱门 Clifford 算子分布,其样本在计算上与均匀随机的 Clifford 算子不可区分,但在给定陷阱门的情况下,实现它们可以快得多。我们构造了一个陷阱门 Clifford 算子的分布,其元素可以在学习奇偶校验噪声假设的一个变体下,以近线性时间进行采样和实现。我们的构造允许对 Pauli 标签进行快速表格作用以进行经典模拟,并且还可以优化以实现多对数深度实现。在此过程中,我们在有限域上构造了陷阱门矩阵,支持矩阵及其逆矩阵的高效乘法,解决了 Vaikuntanathan 和 Zamir [SODA'26] 留下的一个开放问题。我们利用这些构造来获得基于随机 Clifford 算子的更快协议。我们还探索了它们在矩阵和 Clifford 问题的最坏情况到平均情况归约中的应用,包括迭代矩阵乘法和 Clifford 电路合成。特别地,我们展示了批量处理 Clifford 电路的困难性:合成将相同 Clifford 算子应用于多个寄存器的电路,至少与最坏情况矩阵乘法一样困难,即使合成仅在随机 Clifford 算子的一个小的恒定分数上成功。这扩展到一般量子电路的近似实现。

英文摘要

Random Clifford operators have numerous applications in quantum computing, including randomized benchmarking, classical shadows, and quantum authentication. However, sampling and implementing uniformly random $n$-qubit Clifford incur near-quadratic complexity due to the size of Clifford group. We introduce a cryptographic way to overcome these barriers: trapdoored Clifford operator distributions whose samples are computationally indistinguishable from uniformly random Cliffords, yet implementing them can be much faster given the trapdoor. We construct a distribution of trapdoored Clifford operators whose elements can be sampled and implemented in near-linear time under a variant of the learning parity with noise assumption. Our constructions allow fast tableau action on Pauli labels for classical simulation, and also can be optimized to admit polylogarithmic-depth implementation. Along the way, we construct trapdoored matrices over finite fields that support efficient multiplication by both a matrix and its inverse, resolving an open question left by Vaikuntanathan and Zamir [SODA'26]. We use these constructions to obtain faster protocols based on random Cliffords. We also explore their applications to the worst-case to average-case reductions for matrix and Clifford problems including the iterated matrix multiplication and Clifford circuit synthesis. In particular, we show the hardness of batching Clifford circuits: synthesizing circuits that apply the same Clifford to multiple registers is at least as hard as worst-case matrix multiplication, even when synthesis succeeds on a small constant fraction of random Cliffords. This extends to approximate implementations by general quantum circuits.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑