---
title: Average Guessing Probability
url: https://www.emergentmind.com/topics/average-guessing-probability
type: topic
---

# Average Guessing Probability

Average guessing probability denotes an operational success measure for inference under uncertainty. Across sequential card guessing, quantum cryptography, privacy theory, and hat-guessing games, it is defined by averaging a correctness event over turns, inputs, outcomes, or realizations. In a shuffled multiset deck it is the per-turn quantity \(\mathbb{E}[S]/N\) derived from the expected number of correct guesses [2108.07355]; in Bell and prepare-and-measure quantum settings it is the optimal probability that an adversary guesses an outcome, possibly averaged over inputs [2212.08500, 2606.12079]; in quantum key distribution it is the success probability for guessing sifted bits or the final key [2112.11783, 1904.12075]; in infinite hat guessing it becomes the asymptotic density of correct guesses [2508.02828]; and in privacy-utility analyses it appears as the posterior probability of correctly inferring a sensitive variable under explicit constraints [1911.12777, 1704.03606]. This suggests that the term does not denote a single universal scalar, but a family of average success criteria adapted to the observation model and the admissible guessing strategy.

## 1. Core formulations and averaging regimes

A common template is a hidden variable, a side-information channel, a guessing rule, and an average of an indicator of correct reconstruction. Representative formulations are summarized below [2108.07355, 2212.08500, 2112.11783, 2508.02828, 1704.03606].

| Setting | Quantity | Averaging regime |
|---|---|---|
| Sequential card guessing | \(p_{\boldsymbol m}^{\pm}=\mathbb{E}[S_{\boldsymbol m}^{\pm}]/N\) | Deck randomness and turns |
| Bell / device-independent randomness | \(\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)P_{\mathrm{guess}}(A_x|E)\) | Outcomes, optionally inputs |
| QKD | \(p_{\mathrm{guess}}(\mathbf K|E)\), \(P_B\), \(P_E^\star\) | Keys, basis choices, protocol randomness |
| Infinite hat guessing | \(\overline Z_k=\frac1k\sum_{i=1}^k Z_i\), \(L\), \(U\) | Players and asymptotic density |
| Privacy-utility tradeoff | \(\mathcal P(U|V)=\max_g \Pr(U=g(V))\) | Source distribution and disclosed observation |

In the privacy-aware setting, the probability of correctly guessing a discrete random variable \(U\) given \(V\) is
\[
\mathcal{P}(U|V)=\max_g \Pr(U=g(V))=\sum_{v\in\mathcal V}\max_{u\in\mathcal U} P_{UV}(u,v),
\]
where the maximum is over deterministic decision rules \(g\) [1704.03606]. In Bell scenarios, the corresponding input-averaged quantity is
\[
\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)\,P_{\mathrm{guess}}(A_x|E),
\]
with \(q(x)\) the input distribution [2212.08500]. In infinite hat guessing, the average success over the first \(k\) players is
\[
\overline{Z}_k=\frac{1}{k}\sum_{i=1}^k \mathbf 1_{\{X_i=\xi_i\}},
\]
and the long-run lower and upper densities are
\[
L=\liminf_{k\to\infty}\overline Z_k,\qquad U=\limsup_{k\to\infty}\overline Z_k
\]
[2508.02828].

The main conceptual distinction is therefore not between “probability” and “average,” but between different averaging operations. Some works average over draws from a randomized experiment, some over channel inputs, some over sequential turns, and some over entire populations or blocklengths. This suggests that the correct normalization is model-specific.

## 2. Sequential card guessing and per-turn success

In complete-feedback card guessing on a uniformly random permutation of a multiset deck \(\boldsymbol m=(m_1,\dots,m_n)\), with total size \(N=\sum_i m_i\), the total number of correct guesses is
\[
S=\sum_{t=1}^N X_t,
\]
and the paper defines
\[
p_{\boldsymbol m}^{+}:=\frac{\mathbb E[S_{\boldsymbol m}^{+}]}{N},\qquad
p_{\boldsymbol m}^{-}:=\frac{\mathbb E[S_{\boldsymbol m}^{-}]}{N},
\]
for best and worst complete-feedback strategies, respectively [2108.07355]. The best strategy is the greedy max rule—guess a type among those currently most frequent among the remaining cards—while the worst strategy is the greedy min rule—guess a type among those currently least frequent among the remaining cards. For balanced even decks \(\boldsymbol m=m\mathbf 1_n\), the best-strategy asymptotic is
\[
\mathbb E[S_{\boldsymbol m}^{+}]
=
H_mH_n+\sum_{j=1}^{m}\ln \gamma_j
+O\!\left(\ln n\left(\frac{\ln n}{n}\right)^{1/m}\right),
\]
hence
\[
p_{n,m}^{+}\sim \frac{H_m}{m}\frac{\ln n}{n}.
\]
For the worst strategy on even decks,
\[
\mathbb E[S^-_{m\mathbf 1_n}]
\sim
\Gamma\!\left(\frac{m+1}{m}\right)n^{-1/m},
\qquad
p_{n,m}^{-}\sim
\Gamma\!\left(\frac{m+1}{m}\right)m^{-1}n^{-(1+1/m)}.
\]
Thus the optimal average success probability per turn decays like \(\Theta((\ln n)/n)\), whereas the pessimal average success probability decays like \(\Theta(n^{-(1+1/m)})\) [2108.07355].

For two card types, the refined decomposition
\[
C_{m_1,m_2}=T_{m_1,m_2}+L_{m_1,m_2}+P_{m_1,m_2}
\]
separates certified guesses, more-likely guesses, and pure-luck guesses [2303.04609]. Under the majority-color strategy,
\[
C_{m_1,m_2}\stackrel{\mathcal L}=m_1+B\!\left(W_{m_1,m_2},\tfrac12\right),
\]
so
\[
\mathbb E[C_{m_1,m_2}]=m_1+\frac12\,\mathbb E[W_{m_1,m_2}],
\qquad
\frac{\mathbb E[C_{m_1,m_2}]}{M}
=
\frac{m_1}{m_1+m_2}
+
\frac{1}{2(m_1+m_2)}\,\mathbb E[W_{m_1,m_2}].
\]
In the symmetric case \(m_1=m_2=m\),
\[
\mathbb E[C_{m,m}]
=
m+\frac{\sqrt{\pi}}{2}\sqrt m+o(\sqrt m),
\qquad
\frac{\mathbb E[C_{m,m}]}{2m}
=
\frac12+\frac{\sqrt\pi}{4}\frac{1}{\sqrt m}+o(m^{-1/2}),
\]
so the average success probability exceeds \(1/2\) by a \(m^{-1/2}\) correction [2303.04609].

These card-guessing models make the normalization explicit: average guessing probability is the expected number of correct guesses divided by the number of turns. In that sense it is a mean success frequency, not a one-shot posterior success probability.

## 3. Guesswork, stopping times, and search complexity

A closely related quantity is guesswork, or expected guessing time. In the unreliable-oracle model, a guessing strategy is a bijection \(g:\mathcal X\to\{1,\dots,N\}\), the stopping time is \(T_g=g(X)\), and the minimal expected guessing time is
\[
G(X)=\min_g \mathbb E[g(X)]=\sum_{i=1}^N i\,p_i
\]
under descending-probability ordering [1703.01672]. With side information \(Y\), the conditional analogue is
\[
G(X|Y)=\min_g \mathbb E[g(X,Y)].
\]
Since
\[
\Pr(T_g\le t)=\sum_{x:g(x)\le t}P_X(x),
\]
minimizing \(\mathbb E[T_g]\) front-loads success probability onto early guesses. After one noisy binary oracle answer \(Y_A=1(X\in A)\oplus V\), the exact identity
\[
G_A(X)=G(X)-CUT_A(\mathcal G_X)
\]
reduces the design of the best question \(A\) to a weighted max-cut problem, and the zigzag partition satisfies
\[
G_{ZZ}(X)\le G_{\mathrm{opt}}(X)+\frac{|1-2p|}{4}
\]
[1703.01672].

For word guessing in decreasing probability order, the expected number of successive attempts is the central object. In first-order and second-order language models, exact computation is combinatorially expensive, so the distribution of log-probability products is approximated numerically and, in many cases, by a normal law. For the normal regime the leading asymptotic term has the form
\[
G_1(X_1,\dots,X_m)\sim n^m A B^m m^{-1/2},
\]
and the proportion of guesses needed on average compared to the total number decreases almost exponentially with the word length [1405.2418]. The same source also shows that entropy-based expressions can overestimate or underestimate true guesswork; for English, the entropy ansatz underestimates by about a factor of \(10\) in first order and about \(100\) in second order at \(m=30\) [1405.2418].

The quantum extension replaces a single guess by a measurement followed by sequential label queries. For an ensemble \(\boldsymbol{\rho}\) and numbering-valued POVM \(\boldsymbol{\pi}\), the guesswork is
\[
G(\boldsymbol{\rho},\boldsymbol{\pi})
=
\sum_{t=1}^{|\mathcal M|} t\,q_{\boldsymbol{\rho},\boldsymbol{\pi}}(t),
\]
where \(q_{\boldsymbol{\rho},\boldsymbol{\pi}}(t)\) is the probability that the \(t\)-th query is correct; the minimum is
\[
G_{\min}(\boldsymbol{\rho})=\min_{\boldsymbol{\pi}}G(\boldsymbol{\rho},\boldsymbol{\pi})
\]
[2012.09350]. In this model eventual success probability is \(1\); the relevant average quantity is the distribution of success over guess indices, compressed into \(\mathbb E[T]\). For any qubit ensemble with uniform prior, the paper gives an analytical solution for \(G_{\min}\), and it computes explicit values for regular polygonal and polyhedral ensembles [2012.09350].

## 4. Quantum randomness, Bell scenarios, and characterized measurements

In device-independent Bell scenarios, the single-setting guessing probability is the optimal probability that Eve correctly guesses Alice’s outcome for a fixed input \(x\), denoted \(P_g(a|x,E)\) [2212.08500]. The natural input-averaged version is
\[
\overline{P}_{\mathrm{guess}}(A|E)=\sum_x q(x)\,P_{\mathrm{guess}}(A_x|E),
\]
and for uniform inputs it becomes
\[
\overline{P}_{\mathrm{guess}}(A|E)=\frac1m\sum_{x=1}^m P_{\mathrm{guess}}(A_x|E).
\]
The paper studies SDP-based upper bounds and machine-learning approximations to these per-setting quantities in Bell scenarios \([m,k]\), emphasizing that the SDP output is a certified upper bound whereas the neural network provides only an estimation of the upper bound and “will not provide a certification” [2212.08500].

In fully characterized prepare-and-measure setups, the device-dependent guessing probability is already an average over the outcome distribution:
\[
P_{\mathrm{guess}}(A|E,\rho_S,\{M_S^a\}_a)
=
\max
\sum_a
\langle\psi|\Pi_{SM}^a\otimes M_E^a|\psi\rangle,
\]
with optimization over dilations, purifications, and Eve’s measurement, under constraints reproducing the characterized state \(\rho_S\), the POVM \(\{M_S^a\}\), and the observed statistics \(\operatorname{Tr}[M_S^a\rho_S]\) [2606.12079]. Its min-entropy is
\[
H_{\min}(A|E,\rho_S,\{M_S^a\}_a)
=
-\log_2 P_{\mathrm{guess}}(A|E,\rho_S,\{M_S^a\}_a).
\]
A central technical point is that the paper gives an exact semidefinite program rather than a relaxation; the SDP computes the true maximum average guessing probability in the device-dependent model [2606.12079].

These two quantum formulations share the same operational meaning—optimal average success of an adversary—but differ in what is averaged and in what is trusted. Device-independent work averages over measurement outcomes and, if desired, over inputs; device-dependent work fixes the apparatus description and optimizes over all compatible dilations. The min-entropy conversion \(H_{\min}=-\log_2 P_{\mathrm{guess}}\) makes average guessing probability directly convertible into certifiable randomness [2606.12079].

## 5. Quantum key distribution and key-guessing interpretations

In QKD, average guessing probability appears both at the sifted-bit level and at the final-key level. For sifted bits, Bob’s and Eve’s average guessing probabilities are
\[
P_B=\sum_{i=0}^{t-1}\wp_i\,P(a_i=b_i),
\qquad
P_E=\sum_{i=0}^{t-1}P(e=a_i+id),
\]
with Eve’s relevant figure of merit
\[
P_E^\star=\max_{V\in SU(td)} P_E
\]
[2112.11783]. In BB84 and six-state protocols with common QBER \(\varepsilon\), one has
\[
P_B=1-\varepsilon.
\]
For BB84,
\[
P_E^\star=\frac12+\sqrt{2\varepsilon(1-2\varepsilon)},
\]
and for the six-state protocol,
\[
P_E^\star=\frac12+\sqrt{\frac34\,\varepsilon(2-3\varepsilon)}
\]
[2112.11783]. The criterion \(P_B>P_E^\star\) yields tolerable QBER regions close to those obtained from the usual entropic key-rate conditions; the paper reports \(\varepsilon_{\rm cr}\approx 10\%\) for BB84 and \(\varepsilon_{\rm cr}'\approx 11.8\%\) for the six-state protocol, compared with entropic thresholds of about \(11\%\) and \(12.6\%\), respectively [2112.11783].

At the final-key level, the guessing probability is the success probability that Eve correctly guesses the entire key:
\[
p(\mathbf k)=p_{\mathrm{guess}}(\mathbf K|E)
=
\max_{\{\Lambda_{\mathbf k}\}}
\sum_{\mathbf k} p_{\mathbf K}(\mathbf k)\,
\operatorname{Tr}\!\bigl(\Lambda_{\mathbf k}\rho_E^{\mathbf k}\bigr).
\]
A standard trace-distance argument yields
\[
p(\mathbf k)\le 2^{-n_1}+\varepsilon_{\mathbf k},
\]
but the paper shows that this can be tightened by mapping the actual key \(\mathbf k\) to a shorter key \(\mathbf k'\) with
\[
p(\mathbf k)\le p(\mathbf k')\le 2^{-n_2}+\varepsilon_{\mathbf k'}.
\]
Choosing \(n_2\) so that \(2^{-n_2}=\varepsilon_{\mathbf k'}(n_2)\) gives
\[
p(\mathbf k)\le 2^{-(n_2-1)}
\]
[1904.12075]. The numerical example in the abstract states that a \(10^{-9}\)-secure key can admit an upper bound \(2\times 10^{-3277}\), more than \(3000\) orders of magnitude smaller than \(10^{-9}\) [1904.12075]. This corrects a common misconception: the trace-distance security parameter is not itself the sharpest available estimate of final-key guessing probability.

## 6. Privacy, posterior success, and constrained average inference

In privacy-aware inference, average guessing probability becomes a utility-privacy tradeoff. For discrete \(U\) and \(V\),
\[
\mathcal P(U|V)=\max_g \Pr(U=g(V))=\sum_v \max_u P_{UV}(u,v),
\]
and the central constrained quantity is
\[
\mathcalboondox{h}(P_{XY},\epsilon)
=
\sup_{P_{Z|Y}: X\markov Y\markov Z,\ \mathcal P(X|Z)\le \epsilon}
\mathcal P(Y|Z).
\]
The map \(\epsilon\mapsto \mathcalboondox{h}(P_{XY},\epsilon)\) is strictly increasing, concave, and piecewise linear, and the paper derives closed-form expressions for binary-input binary-output channels and asymptotic formulas for i.i.d. binary vectors [1704.03606]. Here \(\epsilon\) is itself a bound on the adversary’s average probability of correctly guessing the private variable \(X\), while \(\mathcalboondox{h}(P_{XY},\epsilon)\) is the best achievable average probability of correctly guessing the non-private variable \(Y\).

Differential privacy rephrases the same idea in posterior form. Let \(X'\) be an event corresponding to “sufficiently correct guesses,” such as a ball of radius \(r\) around the true sensitive value. Under \(\epsilon\)-DP and a distance bound \(R\), the posterior success probability after observing the mechanism output satisfies
\[
\Pr[X'\mid M_q(X)=y]
\le
\frac{1}{1+e^{-\epsilon R}\cdot \frac{\Pr[X\setminus X']}{\Pr[X']}},
\]
so the additive increase in guessing probability is explicitly controlled by \(\epsilon\) [1911.12777]. The paper defines \(\delta\) as the adversary’s advantage, namely the difference between posterior and prior success probabilities. Thus \(\epsilon\) can be interpreted as a parameter governing how much the average chance of correctly guessing a sensitive property may increase after disclosure [1911.12777].

These privacy formulations emphasize a different normalization from the card or QKD settings. The quantity being averaged is neither the fraction of correct turns nor the probability of a specific key guess, but the success probability of an optimal estimator before and after a privacy filter or DP mechanism. The shared structure is still operational: average guessing probability remains the mean success rate of a specified inference task.

## 7. Asymptotic density and collective guessing in infinite hat games

In the infinite hat-guessing game with two colors and countably many players, each player’s correctness indicator is
\[
Z_i=\mathbf 1_{\{X_i=\xi_i\}},
\]
and the empirical average success over the first \(k\) players is
\[
\overline Z_k=\frac1k\sum_{i=1}^k Z_i.
\]
The lower and upper asymptotic densities of correct guesses are
\[
L=\liminf_{k\to\infty}\overline Z_k,\qquad
U=\limsup_{k\to\infty}\overline Z_k
\]
[2508.02828]. Under any measurable strategy, each player’s guess is independent of their own hat and
\[
\mathbb P(X_i=\xi_i)=\frac12,\qquad
\mathbb E[\overline Z_k]=\frac12.
\]
The main theorem sharpens this expectation-level fact to an almost-sure statement:
\[
\mathbb P\!\left(L\le \frac12 \le U\right)=1,
\]
so measurable strategies cannot push the long-run lower density of correct guesses above \(1/2\) [2508.02828].

The same paper contrasts this with non-measurable strategies obtained from the axiom of choice. The Gabay–O’Connor construction gives, for every hat assignment,
\[
L=U=1,
\]
so only finitely many players are wrong. The Lenstra construction gives, for every assignment, either
\[
L=U=1\qquad\text{or}\qquad L=U=0,
\]
meaning either everyone is correct or everyone is wrong [2508.02828]. This is a sharp controversy in the subject: average guessing probability in the long-run density sense is forced to obey \(L\le \tfrac12\le U\) under measurability, but can become asymptotically \(1\) under full choice.

The hat-game literature therefore shows that “average guessing probability” can also be an almost-sure asymptotic density rather than an expected one-shot success probability. The underlying theme remains the same: a correctness indicator is averaged, but the averaging now runs over an infinite population and is constrained by measurability rather than by decoding or feedback rules.

Source: https://www.emergentmind.com/topics/average-guessing-probability