Papers
Topics
Authors
Recent
Search
2000 character limit reached

Robust Quantum State Tomography

Updated 12 December 2025
  • The paper introduces a truncated mean estimator for robust shadow tomography, effectively mitigating adversarial corruption of quantum measurement data.
  • By leveraging coordinate-wise truncation and t-design measurements, the method achieves near-optimal error bounds and minimal sample complexity in high-dimensional regimes.
  • Robust shadow tomography serves as a subroutine for full state estimation, enabling recovery of low-rank quantum states despite worst-case disturbances.

Adversarially robust state tomography addresses the quantum learning problem of reconstructing properties of an unknown quantum state—or the state itself—in the presence of arbitrary, worst-case corruption of a fraction of measured data points. Its development is motivated by the need to guarantee state estimation accuracy even under strong non-stochastic disturbances, such as adversarial attacks on measurement outcomes, calibration drifts, or experimental tampering.

1. Adversarial Corruption Models in Quantum Tomography

The foundational adversarial corruption model posits that given nn copies of a dd-dimensional unknown quantum state ρ\rho and a non-adaptive measurement schedule—e.g. specified POVMs M1,…,MnM_1,\dots, M_n—an adversary who knows the chosen measurements a priori can arbitrarily corrupt up to γn\gamma n of the measurement outcomes. The observed data stream y=(y1,…,yn)y = (y_1, \dots, y_n) then differs from the ideal measurement outcome string x=(x1,…,xn)x = (x_1, \dots, x_n) in at most γn\gamma n entries but may have arbitrarily chosen corrupted values in these locations. The tomography algorithm must, from yy and the measurement schedule, reconstruct high-accuracy estimates EjE_j for dd0 target observables dd1, or reconstruct dd2 itself, with error and sample complexity guarantees quantified as a function of dd3, dd4, dd5, and (for low-rank settings) the state rank dd6 (Aliakbarpour et al., 5 Dec 2025).

The adversarial model generalizes to other noise patterns. In (Kalev et al., 2015), the measurement map is dd7, where dd8 is an arbitrary error vector with dd9 in some norm, modeling worst-case (adversarial) measurement deviations.

2. Failure of Standard Shadow Tomography Under Adversarial Corruption

The classical shadows algorithm of Huang–Kueng–Preskill (HKP20), based on median-of-means estimation, fails catastrophically under adversarial corruption. In the Haar-POVM scheme, the median-of-means estimator is highly sensitive to batch-level outliers, as an adversary can concentrate corrupted samples in a way that shifts batch means by ρ\rho0 per batch, resulting in an overall worst-case error ρ\rho1 for median-of-means, even for a single observable such as projective fidelity estimation [(Aliakbarpour et al., 5 Dec 2025), Theorem 2.4]. This breakdown is particularly severe as ρ\rho2 grows, rendering naive shadow tomography or direct per-observable estimation inadequate in the high-dimensional or large-ρ\rho3 setting.

3. Robust Shadow Tomography: Truncated Mean Estimation

To circumvent adversarial fragility, (Aliakbarpour et al., 5 Dec 2025) introduces a robust, coordinate-wise truncated mean estimator:

  1. For each copy ρ\rho4:
    • Sample a random unitary ρ\rho5 (from an approximate ρ\rho6-design with ρ\rho7),
    • Apply ρ\rho8 to the ρ\rho9th copy, measure in the computational basis to obtain M1,…,MnM_1,\dots, M_n0, set M1,…,MnM_1,\dots, M_n1,
    • Form the classical shadow M1,…,MnM_1,\dots, M_n2.
  2. For each target observable M1,…,MnM_1,\dots, M_n3:
    • Compute samples M1,…,MnM_1,\dots, M_n4 for M1,…,MnM_1,\dots, M_n5,
    • Apply the truncated mean: sort M1,…,MnM_1,\dots, M_n6, drop the top and bottom M1,…,MnM_1,\dots, M_n7 fraction, and average the remaining values to obtain the estimate M1,…,MnM_1,\dots, M_n8.

The truncation threshold is set to eliminate up to M1,…,MnM_1,\dots, M_n9 extreme outliers per observable coordinate, harnessing robust statistics to maintain concentration around the true mean even with adversarially chosen contaminated samples.

Theoretical analysis leverages uniform bounds on higher central moments of the shadow samples—specifically,

γn\gamma n0

for Hermitian γn\gamma n1, where γn\gamma n2 is the Hilbert–Schmidt norm [(Aliakbarpour et al., 5 Dec 2025), Thm 3.2]. Under these moment bounds, standard results imply that truncated mean estimation incurs an additive error γn\gamma n3 per observable, with logarithmic dependence absorbed in γn\gamma n4 notation. The required sample complexity to achieve this error for γn\gamma n5 observables is γn\gamma n6 (Aliakbarpour et al., 5 Dec 2025).

This estimator matches an information-theoretic lower bound: γn\gamma n7 for any non-adaptive algorithm [(Aliakbarpour et al., 5 Dec 2025), Thm 4.1]. Thus, the truncated-mean paradigm achieves optimal (up to logarithms) adversarial robustness in the high-dimensional, multi-observable regime.

4. From Robust Shadow Tomography to Full State Estimation

Robust shadow tomography serves as a generic subroutine for adversarially robust full state tomography. The reduction proceeds via an γn\gamma n8-net γn\gamma n9 over rank-y=(y1,…,yn)y = (y_1, \dots, y_n)0 density matrices in trace norm, and the construction of pairwise distinguishing observables—specifically, the Holevo–Helstrom POVM for each pair y=(y1,…,yn)y = (y_1, \dots, y_n)1, yielding observables y=(y1,…,yn)y = (y_1, \dots, y_n)2 with rank at most y=(y1,…,yn)y = (y_1, \dots, y_n)3 and y=(y1,…,yn)y = (y_1, \dots, y_n)4. Applying the robust shadow protocol to the set y=(y1,…,yn)y = (y_1, \dots, y_n)5, and selecting the net point y=(y1,…,yn)y = (y_1, \dots, y_n)6 minimizing y=(y1,…,yn)y = (y_1, \dots, y_n)7, returns an estimate y=(y1,…,yn)y = (y_1, \dots, y_n)8 satisfying trace norm error y=(y1,…,yn)y = (y_1, \dots, y_n)9 for rank-x=(x1,…,xn)x = (x_1, \dots, x_n)0 true states, with copy complexity x=(x1,…,xn)x = (x_1, \dots, x_n)1 (Aliakbarpour et al., 5 Dec 2025).

This closes the prior gap established in [ABCL25], where a minmax-optimal error x=(x1,…,xn)x = (x_1, \dots, x_n)2 was only achievable at the cost of pseudo-polynomial sample complexity in x=(x1,…,xn)x = (x_1, \dots, x_n)3. The robust shadow method achieves both optimal error and (nearly) information-theoretic minimal copy complexity.

5. Alternative and Complementary Paradigms

Parallel lines of work validate and extend adversarial robustness principles:

  • The strictly-complete POVM framework exploits positivity constraints to achieve robust estimation. Measuring a small set of random orthonormal bases, forming a strictly-complete POVM for rank-x=(x1,…,xn)x = (x_1, \dots, x_n)4 states, enables convex optimization recovery schemes x=(x1,…,xn)x = (x_1, \dots, x_n)5 subject to x=(x1,…,xn)x = (x_1, \dots, x_n)6, with worst-case error scaling x=(x1,…,xn)x = (x_1, \dots, x_n)7 in the adversarial model (Kalev et al., 2015).
  • Convex programs penalizing low rank and sparse error, such as x=(x1,…,xn)x = (x_1, \dots, x_n)8, jointly reconstruct the state and unstructured/sparse adversarial errors, extending classical corrupted sensing to the quantum domain (Ma et al., 2024, Li et al., 2014).
  • Agnostic tomography for structured state classes (e.g., product states, stabilizer product states) matches the adversarial (worst-case) model by reducing quantum tomography to robust classical learning tasks (such as robust mean estimation in product distributions), with copy and runtime complexity polynomial (or quasipolynomial) in natural parameters and approximation error (Arulandu et al., 9 Oct 2025, Grewal et al., 2024).

These paradigms are summarized in the table below:

Approach Measurement Model Error Guarantee Sample Complexity
Robust classical shadows (Aliakbarpour et al., 5 Dec 2025) Random local (t-design, non-adaptive) x=(x1,…,xn)x = (x_1, \dots, x_n)9 γn\gamma n0
Strictly-complete POVM (Kalev et al., 2015) Few random bases (projective), non-adaptive γn\gamma n1 (arbitrary noise norm) γn\gamma n2 (conjectured)
Robust convex program (Ma et al., 2024, Li et al., 2014) Pauli or general measurements γn\gamma n3, solves for γn\gamma n4 γn\gamma n5
Product state reduction (Arulandu et al., 9 Oct 2025) Single-qubit product; adaptive crucial γn\gamma n6 γn\gamma n7

6. Limitations and Outstanding Challenges

Despite theoretical optimality, significant open questions remain:

  • The net-search required for low-rank robust state tomography is exponential in γn\gamma n8; no known polynomial-time algorithm achieves the same minmax error and copy complexity in the general (approximate) setting (Aliakbarpour et al., 5 Dec 2025).
  • All main results are for non-adaptive, single-copy measurement protocols. Whether adaptivity or entangled measurements can improve the tradeoff curves—specifically, the scaling in γn\gamma n9, yy0, or yy1—is unresolved (Aliakbarpour et al., 5 Dec 2025).
  • Worst-case adversarial models used here are stringent; intermediate models (e.g., bounded adversarial memory, restricted attack patterns, partial stochasticity) may allow interpolation with error mitigation or classical robust statistics (Aliakbarpour et al., 5 Dec 2025).
  • The precise minimal measurement designs—such as explicit, deterministic rank-yy2 strictly-complete POVMs—and sharp constants in error bounds are known only up to conjectures or via numerics (Kalev et al., 2015).
  • In agnostic tomography for mixed state classes, adaptivity is proven to be information-theoretically required for product mixed state tomography with yy3 trace-norm error (Arulandu et al., 9 Oct 2025).

7. Practical Implementation and Performance

Robust algorithms described above are implementable with tractable per-sample and per-iteration computational cost:

  • Truncated mean robust shadow tomography involves only basic data sorting/truncation and is scalable; random yy4-design or Haar-uniform measurements are realizable as single-copy local unitaries (Aliakbarpour et al., 5 Dec 2025).
  • Convex programs (nuclear norm + yy5 penalty) can be solved efficiently using proximal or ADMM methods, with each iteration dominated by low-rank SVDs and soft-thresholding, compatible with moderate experimental data rates (Ma et al., 2024, Li et al., 2014).
  • Product state/correlated classical reductions are polynomial in yy6 for typical error targets, with robust mean estimation modules drawn from the mature classical literature (Arulandu et al., 9 Oct 2025).

Numerical studies confirm stability to adversarial corruption up to significant fractions (yy7) of the data, with accurate state recovery observed for moderate numbers of copies, basis settings, and measurement rates (Ma et al., 2024, Li et al., 2014, Kalev et al., 2015). These results indicate that adversarially robust state tomography is both theoretically optimal (up to logarithms, information-theoretic lower bounds) and practically realizable for near-term quantum devices.


References:

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Adversarially Robust State Tomography.