Papers
Topics
Authors
Recent
Search
2000 character limit reached

Non-Local Search-to-Decision Reduction over F2

Published 19 Aug 2026 in quant-ph | (2608.19091v1)

Abstract: Non-local search-to-decision asks whether two noncommunicating parties, given the two shares of a bipartite encoding of a uniformly random string x∈F2<sup>nx\in \mathbb{F}_2<sup>n, can both predict the same random parity ⟨r,x⟩\langle r,x\rangle without there also being local measurements with which both parties recover xx. We prove that if their optimal probability of both recovering xx by local measurements is pp, then their probability of both answering a common parity challenge correctly is at most min⁡1,12+5p<sup>1/22\min{1,\frac{1}{2}+5p<sup>{1/22}}. The result is motivated by applications to unclonable encryption and quantum copy-protection. The proof is information-theoretic and does not provide an efficient extractor. The proof and the exposition were developed with assistance from ChatGPT using GPT-5.6 Sol Pro and Codex in the Ultra reasoning mode.

Authors (1)

Summary

  • The paper proves that any joint prediction advantage beyond the guessing baseline in non-local search scenarios implies a polynomially related probability of joint full-string recovery.
  • The theorem applies to arbitrary bipartite ensembles under a uniform prior, with unrestricted local quantum measurements and concerns a joint evolving event with identical challenges.
  • The findings are used for a common-challenge compiler to generate unclonable encryption schemes with information-theoretic search security.

The problem and the main result

The paper studies a non-local variant of the Goldreich–Levin search-to-decision reduction. A uniformly random string x∈F2nx \in \mathbb{F}_2^n is encoded by an arbitrary quantum channel Φ\Phi into a bipartite state ρx\rho_x, with one share given to Bob and one to Charlie, who cannot communicate. In the search experiment, both parties attempt to recover xx using local POVMs; let psrchp_{\mathrm{srch}} denote the optimal joint success probability, which lies in [2−n,1][2^{-n}, 1]. In the decision experiment, both parties receive the same challenge vector rr drawn uniformly from F2n\mathbb{F}_2^n and must each output ⟨r,x⟩\langle r, x\rangle; let ppredp_{\mathrm{pred}} be the probability that both are correct simultaneously. Since the shared challenge can be ignored (e.g., output the first coordinate of Φ\Phi0), the trivial baseline is exactly Φ\Phi1.

The main theorem (2608.19091) proves:

Φ\Phi2

Equivalently, any joint prediction advantage Φ\Phi3 over the guessing baseline forces local full-string extraction POVMs succeeding with probability at least Φ\Phi4. Consequently, negligible optimal local recovery probability implies negligible joint prediction advantage over Φ\Phi5. Two aspects of this statement deserve emphasis: it applies to arbitrary bipartite ensembles under the uniform prior, with unrestricted local quantum measurements; and it concerns the joint success event of both parties on an identical challenge, a setting in which prior non-local Goldreich–Levin results required independent challenges or imposed structural restrictions on the strategies.

The exponent Φ\Phi6 is weak but sufficient for asymptotic purposes, and the proof is entirely information-theoretic. This is also its principal limitation: the argument establishes existence of witness extraction POVMs but does not yield a uniform efficient procedure for constructing them from efficient prediction measurements. Hence the theorem transfers information-theoretic search security, not computational search security.

Position relative to prior work

Prior non-local simultaneous Goldreich–Levin results split along several axes: the field, the joint distribution of hidden strings and challenges, and whether acceptance is exact or relational. Ananth, Kaleoglu, and Liu proved a shared-secret Φ\Phi7 theorem with independent challenges and an efficient extractor [AKL23]; Kundu and Tan allowed arbitrary joint distributions over the two secrets, again with independent challenges [KT25]; Broadbent, Karvonen, and Lord applied the independent-challenge principle to uncloneable advice [BKL24]; Coladangelo and Gunn gave many-sample extensions [CG24]; and Ananth and Behera stated identical- and independent-sample conjectures over large prime fields, where only binary distinction tasks are treated [AB24]. Most relevantly, Coladangelo, Liu, and Xie analyzed an identical-challenge monogamy game but only for semi-classical strategies with an unentangled referee register, leaving general fully quantum strategies conjectural [CLX26].

The present result closes a specific gap: it handles a single challenge vector copied verbatim to both parties, against arbitrary entangled local quantum strategies. The author reserves the term "non-local search-to-decision" rather than "simultaneous Goldreich–Levin" precisely because no constructive efficient extraction procedure is provided—a deliberate terminological concession that mirrors the proof's actual content.

The main cryptographic corollary is a compiler for unclonable encryption: any one-time secret-key scheme for unclonable encryption of uniform messages with information-theoretic search security yields a one-bit-message scheme whose identical-challenge distinguishing advantage is negligible. This compiler structure appears in [AKL23] for independent challenges; the new theorem supplies the common-challenge analysis, building on the equivalence of Georgiou and Zhandry between unclonable encryption and selectively secure single-decryptor encryption [GZ20]. Because the compiler leaves the quantum part of the ciphertext untouched, the BB84 construction [BL20] and coset-state constructions retain their state structure, yielding an alternative information-theoretically secure plain-model construction for one-bit messages—though with weaker quantitative bounds than recent dedicated constructions [AS26], [Rag26], [BBC26].

Proof architecture

The proof proceeds through six stages, organized around a purification Φ\Phi8 of each Φ\Phi9 and the operator

ρx\rho_x0

where ρx\rho_x1 and ρx\rho_x2 are the Fourier coefficients of Bob's and Charlie's difference observables at character ρx\rho_x3, and ρx\rho_x4 is the common-challenge correlation operator, so that ρx\rho_x5.

Spectral decomposition. For each ρx\rho_x6, Bob's space is split according to whether eigenvalues of ρx\rho_x7 have absolute value at least ρx\rho_x8, giving high/low projectors ρx\rho_x9; Charlie's analogously via xx0 with xx1. This induces four orthogonal sectors xx2 of the purification.

Pruning. Parseval's identity (xx3) shows that xx4: the xx5 component itself defines valid local sub-POVMs whose normalization is bounded by search security. The entire xx6 family plus any other sector of average weight below xx7 is deleted from the algebraic estimate; Cauchy–Schwarz bounds the resulting perturbation of xx8 by xx9 where psrchp_{\mathrm{srch}}0. If either one-high sector vanishes, a marginal bound immediately gives the target. The hard case has both psrchp_{\mathrm{srch}}1.

Schur complement. The slack operator psrchp_{\mathrm{srch}}2 has margin psrchp_{\mathrm{srch}}3 on any subspace where either party is low. Rather than bounding the psrchp_{\mathrm{srch}}4–psrchp_{\mathrm{srch}}5 and psrchp_{\mathrm{srch}}6–psrchp_{\mathrm{srch}}7 cross terms individually—which would discard positivity and would require controlling half-extraction paths that search security alone cannot bound—the proof completes the square in the psrchp_{\mathrm{srch}}8 component, equivalently taking the Schur complement of the positive psrchp_{\mathrm{srch}}9 block. This reduces everything to a single averaged scalar [2−n,1][2^{-n}, 1]0, combining the direct [2−n,1][2^{-n}, 1]1 path with an [2−n,1][2^{-n}, 1]2 mediated path:

[2−n,1][2^{-n}, 1]3

Neumann expansion. On the [2−n,1][2^{-n}, 1]4 subspace, writing [2−n,1][2^{-n}, 1]5 with [2−n,1][2^{-n}, 1]6 and [2−n,1][2^{-n}, 1]7, a resolvent identity controls the replacement of [2−n,1][2^{-n}, 1]8 by [2−n,1][2^{-n}, 1]9 with error at most rr0; the latter expands as a convergent Neumann series in rr1, decomposing rr2 into contributions rr3, each carrying rr4 copies of the common-challenge operator rr5.

Reduction to search. Each rr6, expanded over auxiliary challenge words rr7 fixed independently of rr8, factors into products rr9 whose normalized adjoint-products form local sub-POVMs indexed by candidate strings. The key normalizability estimate is a telescoping identity plus Minkowski's inequality:

F2n\mathbb{F}_2^n0

with the analogous Charlie-side bound costing nothing extra since his endpoint projector F2n\mathbb{F}_2^n1 already normalizes the contractions. Search security then gives F2n\mathbb{F}_2^n2, and summing the geometrically weighted series yields F2n\mathbb{F}_2^n3, comfortably below the required threshold F2n\mathbb{F}_2^n4. Choosing F2n\mathbb{F}_2^n5 completes the proof, with the numerical constants (e.g., F2n\mathbb{F}_2^n6) absorbing the deletion cost.

A notable feature of the architecture is that the low-weight test precedes the delicate block analysis, preserving the quantitative smallness of genuinely tiny sectors rather than replacing them by worst-case bounds; and that the square completion accounts exactly for the most unfavorable possible effect of the F2n\mathbb{F}_2^n7 interactions rather than bounding them term-by-term.

Limitations and open problems

Two limitations are explicit. First, the extraction POVMs produced by the proof are existential witnesses hardwired to fixed challenge words; there is no uniform polynomial-time construction from the prediction measurements, so computational search security cannot be transferred. A candidate efficient reduction targeting the weaker conclusion F2n\mathbb{F}_2^n8 was suggested during the work's development but remains unverified. Second, the result is specific to F2n\mathbb{F}_2^n9; an analogue over larger finite fields covering arbitrary ensembles and the full negligible-advantage regime remains open, though candidate arguments exist in restricted structured regimes. It should also be noted that the quantitative bound degrades rapidly in the advantage-to-recovery direction (⟨r,x⟩\langle r, x\rangle0), so the compiler's security loss is substantial even when applicable.

Conclusion

This paper resolves the shared-secret, identical-challenge, exact-output non-local search-to-decision problem over ⟨r,x⟩\langle r, x\rangle1 for unrestricted local quantum strategies, proving that joint prediction advantage over the ⟨r,x⟩\langle r, x\rangle2 baseline implies joint full-string recovery with polynomially related probability. The proof combines spectral sectoring, Schur-completion of the lowest sector, and a Neumann-series decomposition into finite-length common-challenge paths, each reducible to search security via Parseval-normalized witness measurements. The result supplies the missing analysis for the common-challenge case of unclonable-encryption compilers, while leaving open efficient extraction and extensions beyond ⟨r,x⟩\langle r, x\rangle3.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Tweets

Sign up for free to view the 1 tweet with 4 likes about this paper.