- The paper proves that any joint prediction advantage beyond the guessing baseline in non-local search scenarios implies a polynomially related probability of joint full-string recovery.
- The theorem applies to arbitrary bipartite ensembles under a uniform prior, with unrestricted local quantum measurements and concerns a joint evolving event with identical challenges.
- The findings are used for a common-challenge compiler to generate unclonable encryption schemes with information-theoretic search security.
The problem and the main result
The paper studies a non-local variant of the Goldreich–Levin search-to-decision reduction. A uniformly random string x∈F2n is encoded by an arbitrary quantum channel Φ into a bipartite state ρx, with one share given to Bob and one to Charlie, who cannot communicate. In the search experiment, both parties attempt to recover x using local POVMs; let psrch denote the optimal joint success probability, which lies in [2−n,1]. In the decision experiment, both parties receive the same challenge vector r drawn uniformly from F2n and must each output ⟨r,x⟩; let ppred be the probability that both are correct simultaneously. Since the shared challenge can be ignored (e.g., output the first coordinate of Φ0), the trivial baseline is exactly Φ1.
The main theorem (2608.19091) proves:
Φ2
Equivalently, any joint prediction advantage Φ3 over the guessing baseline forces local full-string extraction POVMs succeeding with probability at least Φ4. Consequently, negligible optimal local recovery probability implies negligible joint prediction advantage over Φ5. Two aspects of this statement deserve emphasis: it applies to arbitrary bipartite ensembles under the uniform prior, with unrestricted local quantum measurements; and it concerns the joint success event of both parties on an identical challenge, a setting in which prior non-local Goldreich–Levin results required independent challenges or imposed structural restrictions on the strategies.
The exponent Φ6 is weak but sufficient for asymptotic purposes, and the proof is entirely information-theoretic. This is also its principal limitation: the argument establishes existence of witness extraction POVMs but does not yield a uniform efficient procedure for constructing them from efficient prediction measurements. Hence the theorem transfers information-theoretic search security, not computational search security.
Position relative to prior work
Prior non-local simultaneous Goldreich–Levin results split along several axes: the field, the joint distribution of hidden strings and challenges, and whether acceptance is exact or relational. Ananth, Kaleoglu, and Liu proved a shared-secret Φ7 theorem with independent challenges and an efficient extractor [AKL23]; Kundu and Tan allowed arbitrary joint distributions over the two secrets, again with independent challenges [KT25]; Broadbent, Karvonen, and Lord applied the independent-challenge principle to uncloneable advice [BKL24]; Coladangelo and Gunn gave many-sample extensions [CG24]; and Ananth and Behera stated identical- and independent-sample conjectures over large prime fields, where only binary distinction tasks are treated [AB24]. Most relevantly, Coladangelo, Liu, and Xie analyzed an identical-challenge monogamy game but only for semi-classical strategies with an unentangled referee register, leaving general fully quantum strategies conjectural [CLX26].
The present result closes a specific gap: it handles a single challenge vector copied verbatim to both parties, against arbitrary entangled local quantum strategies. The author reserves the term "non-local search-to-decision" rather than "simultaneous Goldreich–Levin" precisely because no constructive efficient extraction procedure is provided—a deliberate terminological concession that mirrors the proof's actual content.
The main cryptographic corollary is a compiler for unclonable encryption: any one-time secret-key scheme for unclonable encryption of uniform messages with information-theoretic search security yields a one-bit-message scheme whose identical-challenge distinguishing advantage is negligible. This compiler structure appears in [AKL23] for independent challenges; the new theorem supplies the common-challenge analysis, building on the equivalence of Georgiou and Zhandry between unclonable encryption and selectively secure single-decryptor encryption [GZ20]. Because the compiler leaves the quantum part of the ciphertext untouched, the BB84 construction [BL20] and coset-state constructions retain their state structure, yielding an alternative information-theoretically secure plain-model construction for one-bit messages—though with weaker quantitative bounds than recent dedicated constructions [AS26], [Rag26], [BBC26].
Proof architecture
The proof proceeds through six stages, organized around a purification Φ8 of each Φ9 and the operator
ρx0
where ρx1 and ρx2 are the Fourier coefficients of Bob's and Charlie's difference observables at character ρx3, and ρx4 is the common-challenge correlation operator, so that ρx5.
Spectral decomposition. For each ρx6, Bob's space is split according to whether eigenvalues of ρx7 have absolute value at least ρx8, giving high/low projectors ρx9; Charlie's analogously via x0 with x1. This induces four orthogonal sectors x2 of the purification.
Pruning. Parseval's identity (x3) shows that x4: the x5 component itself defines valid local sub-POVMs whose normalization is bounded by search security. The entire x6 family plus any other sector of average weight below x7 is deleted from the algebraic estimate; Cauchy–Schwarz bounds the resulting perturbation of x8 by x9 where psrch0. If either one-high sector vanishes, a marginal bound immediately gives the target. The hard case has both psrch1.
Schur complement. The slack operator psrch2 has margin psrch3 on any subspace where either party is low. Rather than bounding the psrch4–psrch5 and psrch6–psrch7 cross terms individually—which would discard positivity and would require controlling half-extraction paths that search security alone cannot bound—the proof completes the square in the psrch8 component, equivalently taking the Schur complement of the positive psrch9 block. This reduces everything to a single averaged scalar [2−n,1]0, combining the direct [2−n,1]1 path with an [2−n,1]2 mediated path:
[2−n,1]3
Neumann expansion. On the [2−n,1]4 subspace, writing [2−n,1]5 with [2−n,1]6 and [2−n,1]7, a resolvent identity controls the replacement of [2−n,1]8 by [2−n,1]9 with error at most r0; the latter expands as a convergent Neumann series in r1, decomposing r2 into contributions r3, each carrying r4 copies of the common-challenge operator r5.
Reduction to search. Each r6, expanded over auxiliary challenge words r7 fixed independently of r8, factors into products r9 whose normalized adjoint-products form local sub-POVMs indexed by candidate strings. The key normalizability estimate is a telescoping identity plus Minkowski's inequality:
F2n0
with the analogous Charlie-side bound costing nothing extra since his endpoint projector F2n1 already normalizes the contractions. Search security then gives F2n2, and summing the geometrically weighted series yields F2n3, comfortably below the required threshold F2n4. Choosing F2n5 completes the proof, with the numerical constants (e.g., F2n6) absorbing the deletion cost.
A notable feature of the architecture is that the low-weight test precedes the delicate block analysis, preserving the quantitative smallness of genuinely tiny sectors rather than replacing them by worst-case bounds; and that the square completion accounts exactly for the most unfavorable possible effect of the F2n7 interactions rather than bounding them term-by-term.
Limitations and open problems
Two limitations are explicit. First, the extraction POVMs produced by the proof are existential witnesses hardwired to fixed challenge words; there is no uniform polynomial-time construction from the prediction measurements, so computational search security cannot be transferred. A candidate efficient reduction targeting the weaker conclusion F2n8 was suggested during the work's development but remains unverified. Second, the result is specific to F2n9; an analogue over larger finite fields covering arbitrary ensembles and the full negligible-advantage regime remains open, though candidate arguments exist in restricted structured regimes. It should also be noted that the quantitative bound degrades rapidly in the advantage-to-recovery direction (⟨r,x⟩0), so the compiler's security loss is substantial even when applicable.
Conclusion
This paper resolves the shared-secret, identical-challenge, exact-output non-local search-to-decision problem over ⟨r,x⟩1 for unrestricted local quantum strategies, proving that joint prediction advantage over the ⟨r,x⟩2 baseline implies joint full-string recovery with polynomially related probability. The proof combines spectral sectoring, Schur-completion of the lowest sector, and a Neumann-series decomposition into finite-length common-challenge paths, each reducible to search security via Parseval-normalized witness measurements. The result supplies the missing analysis for the common-challenge case of unclonable-encryption compilers, while leaving open efficient extraction and extensions beyond ⟨r,x⟩3.