- The paper develops an exact semidefinite programming formulation for device-dependent guessing probability, replacing a nonconvex optimization over Naimark dilations and Eve’s measurements with a computationally tractable method.
- The SDP proves the depolarizing-noise bound is tight, identifies modestly overestimated min-entropy in a quantum-computing randomness scheme, and shows that untrusted measurements can sharply reduce certified randomness.
- The paper demonstrates that entanglement between preparation and measurement devices increases Eve’s predictive power, with a qubit example giving P_guess = 0.910376 versus at most 0.909672 under separability.
The device-dependent guessing probability quantifies how well an adversary, Eve, can predict the outcome of a measurement performed on a fully characterized quantum state, given quantum side information about both the state and the measurement apparatus. Although this quantity underlies security analyses of the simplest prepare-and-measure (PM) quantum random number generators (QRNGs), its definition involves a nonconvex optimization over Naimark dilations and Eve's measurements for which no general computational method was known. The paper by D'Avino, Mugnai, Navascués, Acín, and Senno (2606.12079) resolves this by showing that the device-dependent guessing probability admits an exact semidefinite programming (SDP) formulation, and then uses this tool to settle several previously open questions about certifiable randomness.
The scenario and the guessing probability
The setup is a PM experiment in which Alice prepares a known d-dimensional state ρS and applies a known k-outcome POVM {MSa}a. Following the framework of Senno et al., what Alice describes as her POVM is modeled as a projective measurement {ΠSMa}a acting on S plus an ancilla M — a generalized Naimark dilation. Since Alice only has tomographic access to S, she cannot distinguish among the infinitely many compatible dilations or detect correlations between S and M; the dilation is therefore chosen adversarially by Eve, who also holds a purification of the joint system-plus-ancilla state. The guessing probability is the maximum, over all such dilations and Eve's decoding measurements, of the probability that Eve correctly predicts Alice's outcome. The certifiable randomness is then given by the conditional min-entropy ρS0 (2606.12079).
This optimization is a noncommutative polynomial problem: both the dilation operators and Eve's states are variables coupled through bilinear terms. The reformulation in terms of subnormalized conditional states ρS1 makes the structure amenable to moment-matrix techniques but does not by itself convexify it.
The key observation is that any PVM dilation can be written in block form with respect to a basis of ρS2, with blocks ρS3 acting on the ancilla. Introducing generalized moment matrices ρS4 built from the operator set ρS5, the objective and all physical constraints — compatibility with ρS6, with the observed POVM elements and statistics, Hermiticity, completeness, and projectivity of the dilation — become linear constraints on the entries of the ρS7, together with positive-semidefiniteness (2606.12079).
The main technical result is a sufficiency theorem: every feasible solution of the SDP relaxation can be mapped back to an explicit feasible solution of the original nonconvex problem achieving the same objective value. The proof constructs, from a Gram decomposition of the moment matrices, explicit orthogonal subspaces whose projectors form a valid complete PVM on a Hilbert space of dimension ρS8. Consequently, the SDP is not merely a relaxation but an exact characterization: the device-dependent guessing probability is computable to arbitrary precision by standard convex optimization. This is the central contribution, and it converts randomness certification in characterized-but-untrusted PM setups from an intractable optimization into a routine numerical task.
Applications
Tightness of the depolarizing-noise bound. For a qubit state and measurement both affected by depolarizing noise of equal strength, Curran et al. derived an analytic lower bound on the guessing probability, ρS9. The SDP reproduces this value exactly across the noise range, establishing that the analytic bound is tight and that the previously known quantity was in fact the exact certifiable randomness (2606.12079).
Randomness generation on quantum computers. For the Berta–Brandão scheme targeting implementations on quantum hardware — a depolarized k0 state measured with an inefficient detector parametrized by k1 — the original analysis fixed one particular Naimark dilation rather than optimizing over all dilations. The SDP shows that this fixed-dilation analysis overestimates the min-entropy for broad regions of the k2 parameter space, though the discrepancy is small. The practical implication is that published min-entropy figures for this scheme should be recomputed with the exact formulation before being used in entropy accounting.
Source-device-independent schemes with untrusted measurements. Avesani et al. proposed equiangular k3-outcome POVMs on the k4 plane of the Bloch sphere which, if trusted, certify unbounded randomness (k5) from an uncharacterized qubit. The paper extends the SDP by promoting k6 to an optimization variable and allowing Eve to be correlated with the measurement. The result is stark: for k7 the certified min-entropy collapses relative to the trusted-measurement prediction. This is not surprising in hindsight — any qubit POVM with more than four outcomes (and, restricted to the k8 plane, more than three) fails to be extremal, so Eve can always couple to it — but the SDP makes the failure quantitative. Moreover, adding realistic depolarizing noise to the measurement shows that even for the extremal trine measurement (k9), the min-entropy vanishes already at a noise level of {MSa}a0, indicating extreme fragility of this scheme to measurement imperfections (2606.12079). The broader lesson is that "unbounded randomness from a qubit" claims rest entirely on the trusted-measurement assumption, which is precisely the assumption the device-dependent framework is designed to remove.
Entanglement assistance increases Eve's predictive power
A parallel framework by Dai et al. assumes that the system {MSa}a1 and the measurement ancilla {MSa}a2 are in a product state, i.e., that no entanglement exists between preparation and measurement devices. Whether this separability assumption has operational consequences was left open. The paper answers it affirmatively using a lemma showing that separability of {MSa}a3 implies positivity of the partial transpose of the summed moment matrix; imposing this PPT constraint yields upper bounds on the separable-case guessing probability.
For a concrete qubit example — a full-rank state and a binary POVM element with off-diagonal entries of modulus {MSa}a4 and phase {MSa}a5 — the authors find
{MSa}a6
The gap is numerically small but structurally significant: even in the simplest possible scenario of a single qubit and a binary measurement, entanglement between the preparation and measurement registers strictly increases Eve's predictive power. Any randomness certification protocol that assumes classical correlations between these devices therefore overestimates the generated min-entropy (2606.12079). To the authors' knowledge, this is the minimal example demonstrating the effect of entanglement assistance in PM randomness certification.
Limitations and open questions
Several caveats attach to these results. First, the SDP operates at the first level of the moment hierarchy; while the sufficiency theorem proves exactness here, the construction relies on the specific operator set {MSa}a7, and scaling to larger Hilbert-space dimensions or many-outcome measurements will strain the solver, since the moment matrix grows as {MSa}a8. Second, the entanglement-separation result is established via a single numerical instance with a small gap; whether the gap can be made large, or characterized analytically, remains open. Third, the source-device-independent analysis still fixes the measurement to lie in the {MSa}a9 plane; the behavior of non-extremal measurements in more general geometries under the exact formulation is not addressed. Finally, the framework certifies randomness per round for i.i.d. devices; extending the SDP-based accounting to finite-size, non-i.i.d. settings would require additional statistical machinery not developed here.
Conclusion
This work provides an exact SDP characterization of the device-dependent guessing probability, resolving the computational status of intrinsic randomness in characterized-but-untrusted PM setups. The applications demonstrate concrete payoffs: proving tightness of an existing analytic bound, correcting mildly optimistic min-entropy estimates in a quantum-computing randomness scheme, and quantifying the collapse of claimed unbounded randomness once the trusted-measurement assumption is dropped. The demonstration that entanglement between preparation and measurement strictly aids the adversary, even for a qubit with a binary measurement, establishes that separability assumptions in competing frameworks have genuine operational cost. The formulation supplies a general, implementable recipe — with public code — for certifying randomness in realistic, noisy device-dependent QRNGs.