Papers
Topics
Authors
Recent
Search
2000 character limit reached

Average Guessing Probability

Updated 10 July 2026
  • Average guessing probability is defined as the mean fraction of correct guesses across trials, serving as a measure of inference success under uncertainty.
  • It applies to a variety of fields—from sequential card games and quantum cryptography to privacy theory and infinite hat guessing—each with its own averaging regime.
  • Practical applications include assessing adversary success in QKD, optimizing guessing strategies in information theory, and quantifying privacy leakage in statistical models.

Average guessing probability denotes an operational success measure for inference under uncertainty. Across sequential card guessing, quantum cryptography, privacy theory, and hat-guessing games, it is defined by averaging a correctness event over turns, inputs, outcomes, or realizations. In a shuffled multiset deck it is the per-turn quantity E[S]/N\mathbb{E}[S]/N derived from the expected number of correct guesses (He et al., 2021); in Bell and prepare-and-measure quantum settings it is the optimal probability that an adversary guesses an outcome, possibly averaged over inputs (Datta et al., 2022, D'Avino et al., 10 Jun 2026); in quantum key distribution it is the success probability for guessing sifted bits or the final key (Su, 2021, Wang et al., 2019); in infinite hat guessing it becomes the asymptotic density of correct guesses (Eldredge, 4 Aug 2025); and in privacy-utility analyses it appears as the posterior probability of correctly inferring a sensitive variable under explicit constraints (Laud et al., 2019, Asoodeh et al., 2017). This suggests that the term does not denote a single universal scalar, but a family of average success criteria adapted to the observation model and the admissible guessing strategy.

1. Core formulations and averaging regimes

A common template is a hidden variable, a side-information channel, a guessing rule, and an average of an indicator of correct reconstruction. Representative formulations are summarized below (He et al., 2021, Datta et al., 2022, Su, 2021, Eldredge, 4 Aug 2025, Asoodeh et al., 2017).

Setting Quantity Averaging regime
Sequential card guessing pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N Deck randomness and turns
Bell / device-independent randomness Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E) Outcomes, optionally inputs
QKD pguess(KE)p_{\mathrm{guess}}(\mathbf K|E), PBP_B, PEP_E^\star Keys, basis choices, protocol randomness
Infinite hat guessing Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i, LL, UU Players and asymptotic density
Privacy-utility tradeoff P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V)) Source distribution and disclosed observation

In the privacy-aware setting, the probability of correctly guessing a discrete random variable pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N0 given pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N1 is

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N2

where the maximum is over deterministic decision rules pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N3 (Asoodeh et al., 2017). In Bell scenarios, the corresponding input-averaged quantity is

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N4

with pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N5 the input distribution (Datta et al., 2022). In infinite hat guessing, the average success over the first pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N6 players is

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N7

and the long-run lower and upper densities are

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N8

(Eldredge, 4 Aug 2025).

The main conceptual distinction is therefore not between “probability” and “average,” but between different averaging operations. Some works average over draws from a randomized experiment, some over channel inputs, some over sequential turns, and some over entire populations or blocklengths. This suggests that the correct normalization is model-specific.

2. Sequential card guessing and per-turn success

In complete-feedback card guessing on a uniformly random permutation of a multiset deck pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N9, with total size Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)0, the total number of correct guesses is

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)1

and the paper defines

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)2

for best and worst complete-feedback strategies, respectively (He et al., 2021). The best strategy is the greedy max rule—guess a type among those currently most frequent among the remaining cards—while the worst strategy is the greedy min rule—guess a type among those currently least frequent among the remaining cards. For balanced even decks Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)3, the best-strategy asymptotic is

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)4

hence

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)5

For the worst strategy on even decks,

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)6

Thus the optimal average success probability per turn decays like Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)7, whereas the pessimal average success probability decays like Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)8 (He et al., 2021).

For two card types, the refined decomposition

Pguess(AE)=xq(x)Pguess(AxE)\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)9

separates certified guesses, more-likely guesses, and pure-luck guesses (Kuba et al., 2023). Under the majority-color strategy,

pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)0

so

pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)1

In the symmetric case pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)2,

pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)3

so the average success probability exceeds pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)4 by a pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)5 correction (Kuba et al., 2023).

These card-guessing models make the normalization explicit: average guessing probability is the expected number of correct guesses divided by the number of turns. In that sense it is a mean success frequency, not a one-shot posterior success probability.

3. Guesswork, stopping times, and search complexity

A closely related quantity is guesswork, or expected guessing time. In the unreliable-oracle model, a guessing strategy is a bijection pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)6, the stopping time is pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)7, and the minimal expected guessing time is

pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)8

under descending-probability ordering (Burin et al., 2017). With side information pguess(KE)p_{\mathrm{guess}}(\mathbf K|E)9, the conditional analogue is

PBP_B0

Since

PBP_B1

minimizing PBP_B2 front-loads success probability onto early guesses. After one noisy binary oracle answer PBP_B3, the exact identity

PBP_B4

reduces the design of the best question PBP_B5 to a weighted max-cut problem, and the zigzag partition satisfies

PBP_B6

(Burin et al., 2017).

For word guessing in decreasing probability order, the expected number of successive attempts is the central object. In first-order and second-order LLMs, exact computation is combinatorially expensive, so the distribution of log-probability products is approximated numerically and, in many cases, by a normal law. For the normal regime the leading asymptotic term has the form

PBP_B7

and the proportion of guesses needed on average compared to the total number decreases almost exponentially with the word length (Andersson, 2014). The same source also shows that entropy-based expressions can overestimate or underestimate true guesswork; for English, the entropy ansatz underestimates by about a factor of PBP_B8 in first order and about PBP_B9 in second order at PEP_E^\star0 (Andersson, 2014).

The quantum extension replaces a single guess by a measurement followed by sequential label queries. For an ensemble PEP_E^\star1 and numbering-valued POVM PEP_E^\star2, the guesswork is

PEP_E^\star3

where PEP_E^\star4 is the probability that the PEP_E^\star5-th query is correct; the minimum is

PEP_E^\star6

(Dall'Arno et al., 2020). In this model eventual success probability is PEP_E^\star7; the relevant average quantity is the distribution of success over guess indices, compressed into PEP_E^\star8. For any qubit ensemble with uniform prior, the paper gives an analytical solution for PEP_E^\star9, and it computes explicit values for regular polygonal and polyhedral ensembles (Dall'Arno et al., 2020).

4. Quantum randomness, Bell scenarios, and characterized measurements

In device-independent Bell scenarios, the single-setting guessing probability is the optimal probability that Eve correctly guesses Alice’s outcome for a fixed input Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i0, denoted Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i1 (Datta et al., 2022). The natural input-averaged version is

Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i2

and for uniform inputs it becomes

Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i3

The paper studies SDP-based upper bounds and machine-learning approximations to these per-setting quantities in Bell scenarios Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i4, emphasizing that the SDP output is a certified upper bound whereas the neural network provides only an estimation of the upper bound and “will not provide a certification” (Datta et al., 2022).

In fully characterized prepare-and-measure setups, the device-dependent guessing probability is already an average over the outcome distribution: Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i5 with optimization over dilations, purifications, and Eve’s measurement, under constraints reproducing the characterized state Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i6, the POVM Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i7, and the observed statistics Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i8 (D'Avino et al., 10 Jun 2026). Its min-entropy is

Zk=1ki=1kZi\overline Z_k=\frac1k\sum_{i=1}^k Z_i9

A central technical point is that the paper gives an exact semidefinite program rather than a relaxation; the SDP computes the true maximum average guessing probability in the device-dependent model (D'Avino et al., 10 Jun 2026).

These two quantum formulations share the same operational meaning—optimal average success of an adversary—but differ in what is averaged and in what is trusted. Device-independent work averages over measurement outcomes and, if desired, over inputs; device-dependent work fixes the apparatus description and optimizes over all compatible dilations. The min-entropy conversion LL0 makes average guessing probability directly convertible into certifiable randomness (D'Avino et al., 10 Jun 2026).

5. Quantum key distribution and key-guessing interpretations

In QKD, average guessing probability appears both at the sifted-bit level and at the final-key level. For sifted bits, Bob’s and Eve’s average guessing probabilities are

LL1

with Eve’s relevant figure of merit

LL2

(Su, 2021). In BB84 and six-state protocols with common QBER LL3, one has

LL4

For BB84,

LL5

and for the six-state protocol,

LL6

(Su, 2021). The criterion LL7 yields tolerable QBER regions close to those obtained from the usual entropic key-rate conditions; the paper reports LL8 for BB84 and LL9 for the six-state protocol, compared with entropic thresholds of about UU0 and UU1, respectively (Su, 2021).

At the final-key level, the guessing probability is the success probability that Eve correctly guesses the entire key: UU2 A standard trace-distance argument yields

UU3

but the paper shows that this can be tightened by mapping the actual key UU4 to a shorter key UU5 with

UU6

Choosing UU7 so that UU8 gives

UU9

(Wang et al., 2019). The numerical example in the abstract states that a P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))0-secure key can admit an upper bound P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))1, more than P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))2 orders of magnitude smaller than P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))3 (Wang et al., 2019). This corrects a common misconception: the trace-distance security parameter is not itself the sharpest available estimate of final-key guessing probability.

6. Privacy, posterior success, and constrained average inference

In privacy-aware inference, average guessing probability becomes a utility-privacy tradeoff. For discrete P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))4 and P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))5,

P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))6

and the central constrained quantity is

P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))7

The map P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))8 is strictly increasing, concave, and piecewise linear, and the paper derives closed-form expressions for binary-input binary-output channels and asymptotic formulas for i.i.d. binary vectors (Asoodeh et al., 2017). Here P(UV)=maxgPr(U=g(V))\mathcal P(U|V)=\max_g \Pr(U=g(V))9 is itself a bound on the adversary’s average probability of correctly guessing the private variable pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N00, while pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N01 is the best achievable average probability of correctly guessing the non-private variable pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N02.

Differential privacy rephrases the same idea in posterior form. Let pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N03 be an event corresponding to “sufficiently correct guesses,” such as a ball of radius pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N04 around the true sensitive value. Under pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N05-DP and a distance bound pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N06, the posterior success probability after observing the mechanism output satisfies

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N07

so the additive increase in guessing probability is explicitly controlled by pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N08 (Laud et al., 2019). The paper defines pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N09 as the adversary’s advantage, namely the difference between posterior and prior success probabilities. Thus pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N10 can be interpreted as a parameter governing how much the average chance of correctly guessing a sensitive property may increase after disclosure (Laud et al., 2019).

These privacy formulations emphasize a different normalization from the card or QKD settings. The quantity being averaged is neither the fraction of correct turns nor the probability of a specific key guess, but the success probability of an optimal estimator before and after a privacy filter or DP mechanism. The shared structure is still operational: average guessing probability remains the mean success rate of a specified inference task.

7. Asymptotic density and collective guessing in infinite hat games

In the infinite hat-guessing game with two colors and countably many players, each player’s correctness indicator is

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N11

and the empirical average success over the first pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N12 players is

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N13

The lower and upper asymptotic densities of correct guesses are

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N14

(Eldredge, 4 Aug 2025). Under any measurable strategy, each player’s guess is independent of their own hat and

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N15

The main theorem sharpens this expectation-level fact to an almost-sure statement: pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N16 so measurable strategies cannot push the long-run lower density of correct guesses above pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N17 (Eldredge, 4 Aug 2025).

The same paper contrasts this with non-measurable strategies obtained from the axiom of choice. The Gabay–O’Connor construction gives, for every hat assignment,

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N18

so only finitely many players are wrong. The Lenstra construction gives, for every assignment, either

pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N19

meaning either everyone is correct or everyone is wrong (Eldredge, 4 Aug 2025). This is a sharp controversy in the subject: average guessing probability in the long-run density sense is forced to obey pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N20 under measurability, but can become asymptotically pm±=E[Sm±]/Np_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N21 under full choice.

The hat-game literature therefore shows that “average guessing probability” can also be an almost-sure asymptotic density rather than an expected one-shot success probability. The underlying theme remains the same: a correctness indicator is averaged, but the averaging now runs over an infinite population and is constrained by measurability rather than by decoding or feedback rules.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Average Guessing Probability.