Papers
Topics
Authors
Recent
Search
2000 character limit reached

A semi-definite programming formulation of the device-dependent guessing probability

Published 10 Jun 2026 in quant-ph | (2606.12079v1)

Abstract: In quantum mechanics, a measurement applied to a state in general produces some amount of intrinsic randomness. This is not only a fundamental feature of the theory, but is also at the basis of any quantum process to generate random numbers. The simplest of such processes consists of a single, fully charaterized, measurement acting on a single, fully characterized, state. Unfortunately, no general method to estimate the intrinsic randomness produced in such setups is known. In this work, we address this issue by presenting a semidefinite programming formulation of the maximum probability with which an adversary, Eve, can guess the outcomes of characterized but untrusted prepare-and-measure setups. We then present several applications of this construction. First, we apply our method to a variety of specific setups, allowing us both to benchmark the approach and, more importantly, to determine the exact amount of certifiable randomness in scenarios where only upper bounds were previously available. Then, we show that the presence of entanglement between the device preparing the state and the measurement strictly increases Eve's predictive power, already in the most elementary setup of a binary measurement acting on a qubit state.

Summary

  • The paper develops an exact semidefinite programming formulation for device-dependent guessing probability, replacing a nonconvex optimization over Naimark dilations and Eve’s measurements with a computationally tractable method.
  • The SDP proves the depolarizing-noise bound is tight, identifies modestly overestimated min-entropy in a quantum-computing randomness scheme, and shows that untrusted measurements can sharply reduce certified randomness.
  • The paper demonstrates that entanglement between preparation and measurement devices increases Eve’s predictive power, with a qubit example giving P_guess = 0.910376 versus at most 0.909672 under separability.

The device-dependent guessing probability quantifies how well an adversary, Eve, can predict the outcome of a measurement performed on a fully characterized quantum state, given quantum side information about both the state and the measurement apparatus. Although this quantity underlies security analyses of the simplest prepare-and-measure (PM) quantum random number generators (QRNGs), its definition involves a nonconvex optimization over Naimark dilations and Eve's measurements for which no general computational method was known. The paper by D'Avino, Mugnai, Navascués, Acín, and Senno (2606.12079) resolves this by showing that the device-dependent guessing probability admits an exact semidefinite programming (SDP) formulation, and then uses this tool to settle several previously open questions about certifiable randomness.

The scenario and the guessing probability

The setup is a PM experiment in which Alice prepares a known dd-dimensional state ρS\rho_S and applies a known kk-outcome POVM {MSa}a\{M_S^a\}_a. Following the framework of Senno et al., what Alice describes as her POVM is modeled as a projective measurement {ΠSMa}a\{\Pi_{SM}^a\}_a acting on SS plus an ancilla MM — a generalized Naimark dilation. Since Alice only has tomographic access to SS, she cannot distinguish among the infinitely many compatible dilations or detect correlations between SS and MM; the dilation is therefore chosen adversarially by Eve, who also holds a purification of the joint system-plus-ancilla state. The guessing probability is the maximum, over all such dilations and Eve's decoding measurements, of the probability that Eve correctly predicts Alice's outcome. The certifiable randomness is then given by the conditional min-entropy ρS\rho_S0 (2606.12079).

This optimization is a noncommutative polynomial problem: both the dilation operators and Eve's states are variables coupled through bilinear terms. The reformulation in terms of subnormalized conditional states ρS\rho_S1 makes the structure amenable to moment-matrix techniques but does not by itself convexify it.

The SDP formulation

The key observation is that any PVM dilation can be written in block form with respect to a basis of ρS\rho_S2, with blocks ρS\rho_S3 acting on the ancilla. Introducing generalized moment matrices ρS\rho_S4 built from the operator set ρS\rho_S5, the objective and all physical constraints — compatibility with ρS\rho_S6, with the observed POVM elements and statistics, Hermiticity, completeness, and projectivity of the dilation — become linear constraints on the entries of the ρS\rho_S7, together with positive-semidefiniteness (2606.12079).

The main technical result is a sufficiency theorem: every feasible solution of the SDP relaxation can be mapped back to an explicit feasible solution of the original nonconvex problem achieving the same objective value. The proof constructs, from a Gram decomposition of the moment matrices, explicit orthogonal subspaces whose projectors form a valid complete PVM on a Hilbert space of dimension ρS\rho_S8. Consequently, the SDP is not merely a relaxation but an exact characterization: the device-dependent guessing probability is computable to arbitrary precision by standard convex optimization. This is the central contribution, and it converts randomness certification in characterized-but-untrusted PM setups from an intractable optimization into a routine numerical task.

Applications

Tightness of the depolarizing-noise bound. For a qubit state and measurement both affected by depolarizing noise of equal strength, Curran et al. derived an analytic lower bound on the guessing probability, ρS\rho_S9. The SDP reproduces this value exactly across the noise range, establishing that the analytic bound is tight and that the previously known quantity was in fact the exact certifiable randomness (2606.12079).

Randomness generation on quantum computers. For the Berta–Brandão scheme targeting implementations on quantum hardware — a depolarized kk0 state measured with an inefficient detector parametrized by kk1 — the original analysis fixed one particular Naimark dilation rather than optimizing over all dilations. The SDP shows that this fixed-dilation analysis overestimates the min-entropy for broad regions of the kk2 parameter space, though the discrepancy is small. The practical implication is that published min-entropy figures for this scheme should be recomputed with the exact formulation before being used in entropy accounting.

Source-device-independent schemes with untrusted measurements. Avesani et al. proposed equiangular kk3-outcome POVMs on the kk4 plane of the Bloch sphere which, if trusted, certify unbounded randomness (kk5) from an uncharacterized qubit. The paper extends the SDP by promoting kk6 to an optimization variable and allowing Eve to be correlated with the measurement. The result is stark: for kk7 the certified min-entropy collapses relative to the trusted-measurement prediction. This is not surprising in hindsight — any qubit POVM with more than four outcomes (and, restricted to the kk8 plane, more than three) fails to be extremal, so Eve can always couple to it — but the SDP makes the failure quantitative. Moreover, adding realistic depolarizing noise to the measurement shows that even for the extremal trine measurement (kk9), the min-entropy vanishes already at a noise level of {MSa}a\{M_S^a\}_a0, indicating extreme fragility of this scheme to measurement imperfections (2606.12079). The broader lesson is that "unbounded randomness from a qubit" claims rest entirely on the trusted-measurement assumption, which is precisely the assumption the device-dependent framework is designed to remove.

Entanglement assistance increases Eve's predictive power

A parallel framework by Dai et al. assumes that the system {MSa}a\{M_S^a\}_a1 and the measurement ancilla {MSa}a\{M_S^a\}_a2 are in a product state, i.e., that no entanglement exists between preparation and measurement devices. Whether this separability assumption has operational consequences was left open. The paper answers it affirmatively using a lemma showing that separability of {MSa}a\{M_S^a\}_a3 implies positivity of the partial transpose of the summed moment matrix; imposing this PPT constraint yields upper bounds on the separable-case guessing probability.

For a concrete qubit example — a full-rank state and a binary POVM element with off-diagonal entries of modulus {MSa}a\{M_S^a\}_a4 and phase {MSa}a\{M_S^a\}_a5 — the authors find

{MSa}a\{M_S^a\}_a6

The gap is numerically small but structurally significant: even in the simplest possible scenario of a single qubit and a binary measurement, entanglement between the preparation and measurement registers strictly increases Eve's predictive power. Any randomness certification protocol that assumes classical correlations between these devices therefore overestimates the generated min-entropy (2606.12079). To the authors' knowledge, this is the minimal example demonstrating the effect of entanglement assistance in PM randomness certification.

Limitations and open questions

Several caveats attach to these results. First, the SDP operates at the first level of the moment hierarchy; while the sufficiency theorem proves exactness here, the construction relies on the specific operator set {MSa}a\{M_S^a\}_a7, and scaling to larger Hilbert-space dimensions or many-outcome measurements will strain the solver, since the moment matrix grows as {MSa}a\{M_S^a\}_a8. Second, the entanglement-separation result is established via a single numerical instance with a small gap; whether the gap can be made large, or characterized analytically, remains open. Third, the source-device-independent analysis still fixes the measurement to lie in the {MSa}a\{M_S^a\}_a9 plane; the behavior of non-extremal measurements in more general geometries under the exact formulation is not addressed. Finally, the framework certifies randomness per round for i.i.d. devices; extending the SDP-based accounting to finite-size, non-i.i.d. settings would require additional statistical machinery not developed here.

Conclusion

This work provides an exact SDP characterization of the device-dependent guessing probability, resolving the computational status of intrinsic randomness in characterized-but-untrusted PM setups. The applications demonstrate concrete payoffs: proving tightness of an existing analytic bound, correcting mildly optimistic min-entropy estimates in a quantum-computing randomness scheme, and quantifying the collapse of claimed unbounded randomness once the trusted-measurement assumption is dropped. The demonstration that entanglement between preparation and measurement strictly aids the adversary, even for a qubit with a binary measurement, establishes that separability assumptions in competing frameworks have genuine operational cost. The formulation supplies a general, implementable recipe — with public code — for certifying randomness in realistic, noisy device-dependent QRNGs.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.