---
title: Complexity-Theoretic No-Cloning Theorem
url: https://www.emergentmind.com/topics/complexity-theoretic-no-cloning-theorem
type: topic
---

# Complexity-Theoretic No-Cloning Theorem

The Complexity-Theoretic No-Cloning Theorem denotes a family of results in which quantum unclonability is expressed as a computational hardness statement rather than as a purely linear-algebraic impossibility. In this regime, the cloner may receive auxiliary classical information such as a verifier circuit, a reflection oracle, or even a full state-preparation circuit, so the standard no-cloning theorem is not by itself the relevant obstruction. A central recent formulation develops a route from QMA witness cloning to representation-theoretic hardness: contingent on a white-box conjecture about cloning hidden maximally entangled states over hidden subspaces, any efficient uniform quantum algorithm that clones those witnesses would imply \( \mathrm{BQP} \supseteq \mathrm{NP} \), thereby tying witness cloning hardness to the positivity and multiplicity structure of Kronecker coefficients of the symmetric group [2411.11805].

## 1. Witness cloning as a computational problem

In the QMA setting, a language \(L\) is verified by a polynomial-time quantum circuit \(V\) acting on an \(n\)-qubit witness and \(m\) ancillas initialized to \(|0\rangle^{\otimes m}\). The corresponding Hermitian acceptance operator is
\[
H=(I^{\otimes n}\otimes \langle 0|^{\otimes m})\,V^\dagger\,(|1\rangle\langle 1|\otimes I^{\otimes n+m-1})\,V\,(I^{\otimes n}\otimes |0\rangle^{\otimes m}),
\]
and completeness \(c\) and soundness \(s\) mean that the spectrum of \(H\) avoids \((s,c)\). The accepting subspace \(L\) is the span of eigenvectors with eigenvalue at least \(c\). A QMA witness is any \(|\psi\rangle\) that causes \(V\) to accept with probability at least \(c\) [2411.11805].

The standard no-cloning theorem does not directly address this setting. In complexity-theoretic witness cloning, the input contains not only one copy of \(|\psi\rangle\) but also the classical description \(\langle V\rangle\). Information-theoretically, with unlimited computation one can derive a second copy from \(\langle V\rangle\); the obstacle, if any, must therefore be computational rather than merely linear-algebraic. This is the basic reason that a complexity-theoretic no-cloning theorem is conceptually distinct from the ordinary no-cloning principle [2411.11805].

The cloning task is formalized as follows. Given one copy of a QMA witness \(|\psi\rangle\) for \(V\) and the verifier description \(\langle V\rangle\), produce a \(2n\)-qubit state whose reduced marginals on the first and last \(n\) qubits are each accepted by \(V\) with probability at least \(c\). If the verifier has a unique witness, this coincides with implementing \(|\psi\rangle \mapsto |\psi\rangle\otimes |\psi\rangle\). The relevant resource bound is a polynomial-time uniform quantum algorithm with success probability bounded away from \(0\); the specific construction in the representation-theoretic approach uses strong completeness \(c=1\) and soundness \(s\le 8/9\) [2411.11805].

## 2. Hidden subspaces and hidden maximally entangled states

The representation-theoretic construction reduces witness cloning to cloning a special family of maximally entangled states associated with hidden subspaces. For a subspace \(H\subseteq \{0,1\}^n\), the uniform superposition over \(H\) is
\[
|H\rangle=\frac{1}{\sqrt{|H|}}\sum_{h\in H}|h\rangle,
\]
and the maximally entangled state over \(H\) is
\[
|\Phi_H\rangle=\frac{1}{\sqrt{|H|}}\sum_{h\in H}|h\rangle\otimes |h\rangle.
\]
In the more general complex formulation, if \(\Pi\subseteq \mathbb{C}^{d_2}\) is a \(d_1\)-dimensional subspace with orthonormal basis \(\{|b_i\rangle\}_{i=1}^{d_1}\), then
\[
|\Phi_\Pi\rangle=\frac{1}{\sqrt{d_1}}\sum_{i=1}^{d_1}|b_i\rangle\otimes |b_i^*\rangle,
\]
which is basis-independent [2411.11805].

A hidden subspace in this context is a subspace for which deciding whether \(\Pi\neq 0\) is NP-hard under polynomial-time reductions. The intended verification problem is arranged so that the unique accepted state is precisely \( |\Phi_\Pi\rangle \), with completeness \(1\) and soundness at most \(8/9\). The corresponding cloning problem is then: given one copy of \( |\Phi_\Pi\rangle \) and the verifier description, produce \( |\Phi_\Pi\rangle^{\otimes 2} \), or more generally a state whose marginals certify acceptance in the two output registers, in uniform polynomial time and with success probability bounded away from \(0\) [2411.11805].

This formulation isolates a particularly rigid unclonability target. If deciding \(\Pi\neq 0\) is NP-hard, then efficiently constructing any \(|\phi\rangle\in \Pi\) would already imply \( \mathrm{BQP} \supseteq \mathrm{NP} \). The central conjectural step is that an efficient cloner for \( |\Phi_\Pi\rangle \) should “leak” enough structure to recover such a vector in \(\Pi\), transforming cloning hardness into generation hardness [2411.11805].

## 3. Representation theory and the verifier construction

The concrete hidden subspaces arise from weak Fourier sampling over finite groups, specialized to the symmetric group \(S_n\). For a finite group \(G\), a representation \(\sigma\) decomposes as
\[
\sigma \cong \bigoplus_{\lambda\in I_G} I_{m_{\sigma\lambda}}\otimes \rho^\lambda,
\]
and the associated weak Fourier sampling projectors are
\[
\Xi_\lambda=\frac{d_\lambda}{|G|}\sum_{g\in G}\chi^\lambda(g)^*\,\sigma(g).
\]
These projectors form a POVM and are efficiently implementable whenever controlled-\(\sigma\) and the quantum Fourier transform over \(G\) are efficient. For \(G=S_n\), irreducibles are indexed by partitions \(\lambda\vdash n\), and the relevant representation is \(\sigma=\rho^\mu\otimes \rho^\nu\) [2411.11805].

The multiplicities in this tensor product are the Kronecker coefficients:
\[
V_\mu\otimes V_\nu \cong \bigoplus_\lambda g(\lambda,\mu,\nu)\,V_\lambda,
\]
with the paper’s notation \(m_{\mu\nu\lambda}=g(\lambda,\mu,\nu)\). The projector \(\Xi_\lambda\) has dimension \(m_{\mu\nu\lambda}d_\lambda\), so \(\Xi_\lambda\neq 0\) if and only if \(m_{\mu\nu\lambda}>0\). This directly ties the existence of accepted states to the positivity problem for Kronecker coefficients, whose decision version is NP-hard, while computing the multiplicity is #P-hard in unary encoding [2411.11805].

The verifier is strengthened by an internal-state test on
\[
U=\sum_{k\in G}|k\rangle\langle k|\otimes \sigma(k)\otimes \sigma(k)^*.
\]
One-bit phase estimation accepts with probability
\[
p=\frac12+\frac12|\langle U\rangle|^2.
\]
Combined with weak Fourier sampling, this test forces any accepted state to be close to a maximally entangled form across multiplicity blocks. Conditioned on weak Fourier sampling outcome \(\lambda\), the internal test implies closeness to
\[
M_\lambda=\mathrm{span}\{|\Phi_{\Xi_{\lambda,j}}\rangle: j=1,\dots,m_{\sigma\lambda}\},
\]
and if a state passes both tests with probability \(1-\varepsilon\), then it is at most \(3\sqrt{2\varepsilon}\)-close to \(|a\rangle\otimes |\Phi_{\Xi_\lambda}\rangle\), where \(|a\rangle\) is an outer multiplicity register. In the unique-multiplicity case \(m_{\mu\nu\lambda}=1\), the unique accepting state is exactly the hidden maximally entangled state \( |\Phi_{\Xi_\lambda}\rangle \) up to global phase [2411.11805].

## 4. The white-box conjecture and the hardness theorem

The main conjecture states that if \(\Pi\subseteq \mathbb{C}^{d_2}\) is a hidden subspace and \( |\Phi_\Pi\rangle \) is the unique state accepted by a verification circuit \(V\) with completeness \(1\) and soundness at most \(8/9\), then any uniform polynomial-time quantum algorithm \(C\) that maps
\[
|\Phi_\Pi\rangle\otimes |0\cdots 0\rangle \mapsto |\Phi_\Pi\rangle^{\otimes 2}
\]
with success probability bounded away from \(0\) yields a uniform polynomial-time quantum algorithm \(G\) that, given \(\langle V\rangle\), constructs some \(|\phi\rangle\in \Pi\) with non-negligible success probability. The conjecture is explicitly white-box: the circuit structure of the cloner must be exploitable. A black-box version is false in general because known oracle separations show that cloning verifiable states can be easy while generation remains hard [2411.11805].

On the unconditional side, the note proves hardness of state generation under \( \mathrm{BQP}\not\supseteq \mathrm{NP} \). For inputs \((\mu,\nu,\lambda)\), there is no uniform polynomial-time quantum algorithm that produces a state accepted by the \((\sigma=\rho^\mu\otimes \rho^\nu,\lambda)\)-verification algorithm whenever one exists, unless \( \mathrm{BQP}\supseteq \mathrm{NP} \). The proof uses the equivalence between existence of an accepted state and positivity of \(m_{\mu\nu\lambda}\). The result remains true even in the unique-witness regime \(m_{\mu\nu\lambda}\in\{0,1\}\), via the Valiant–Vazirani reduction from NP to UNIQUE-NP [2411.11805].

Conditioned on the conjecture, the same framework yields a witness-cloning hardness theorem. For instances with \(m_{\mu\nu\lambda}=1\), if there exists an efficient uniform algorithm that clones witnesses accepted by the \((\sigma,\lambda)\)-verification circuit, equivalently maps
\[
|\Phi_{\Xi_\lambda}\rangle \to |\Phi_{\Xi_\lambda}\rangle^{\otimes 2},
\]
then \( \mathrm{BQP}\supseteq \mathrm{NP} \). The reduction is direct: uniqueness identifies the accepted state with a hidden maximally entangled state over \(\Pi=\mathrm{image}(\Xi_\lambda)\); the cloner yields, by conjecture, a generator for some \(|\phi\rangle\in\Pi\); weak Fourier sampling then verifies membership and therefore witnesses \(\Pi\neq 0\); finally, Valiant–Vazirani lifts the resulting UNIQUE-NP algorithm to NP [2411.11805].

## 5. Relation to earlier complexity-theoretic no-cloning results

Earlier complexity-theoretic no-cloning statements are typically black-box or oracle-based. A canonical formulation gives an algorithm \(m\) initial copies of an unknown \(n\)-qubit pure state \(|\psi\rangle\) together with oracle access to a reflection \(U_\psi=I-2|\psi\rangle\langle\psi|\) or a verifier/projector for \(|\psi\rangle\), and shows that producing \(m+1\) output registers whose marginals each have fidelity at least \(1-\varepsilon\) with \(|\psi\rangle\) requires a superpolynomial, typically exponential, number of oracle queries. This is the standard CTNCT paradigm in quantum money and copy-protection, but it is a query-complexity lower bound rather than a white-box circuit lower bound [2302.01858].

Subsequent work sharpens the limits of what black-box arguments can prove. Aaronson–Christiano constructed an oracle under which cloning subset states requires exponentially many queries. Zhandry’s quantum money and lightning constructions obtain average-case hardness of cloning under cryptographic assumptions or in generic group-action models. Nehoran–Zhandry exhibited a quantum oracle model in which cloning verifiable states is easy while constructing them remains hard, showing that black-box proofs of “cloning implies generation” are impossible in general. The representation-theoretic program therefore departs from the black-box CTNCT by making a non-relativizing white-box conjecture the pivotal step [2411.11805].

A complementary oracle separation concerns no-telegraphing. There exists a quantum oracle and a family of states that are efficiently clonable relative to that oracle but not efficiently telegraphable, even when the sender may be inefficient and only the receiver is required to be efficient. In the same work, the class \(\mathrm{clonableQMA}\) is introduced, and a quantum-oracle separation between \(\mathrm{clonableQMA}\) and \(\mathrm{QCMA}\) is obtained. These results show that computational cloning and computational telegraphing, which are equivalent information-theoretically, separate under efficiency constraints [2302.01858].

A different extension studies uncloneable quantum advice. Using “ingenerable sequences,” one can derandomize random-instance no-cloning games to fixed advice states, obtaining unconditional promise problems with uncloneable advice and, assuming copy-protected pseudorandom functions with super-logarithmic output lengths, languages with uncloneable advice. This shifts the focus from fidelity to operational success of two separated evaluators on fresh inputs, broadening the CTNCT landscape beyond oracle access to \(|\psi\rangle\) [2309.05155].

## 6. Scope, limitations, and later generalizations

The representation-theoretic witness-cloning program establishes several points unconditionally: an explicit efficiently verifiable family of witness states whose existence is NP-hard to decide via positivity of Kronecker coefficients; a structural theorem showing that accepted states must be close to maximally entangled states across multiplicity blocks; and hardness of generating accepted states under \( \mathrm{BQP}\not\supseteq \mathrm{NP} \), including the unique-witness case. What remains conditional is the actual cloning hardness theorem, whose proof depends on the unresolved white-box conjecture that an efficient cloner for \( |\Phi_\Pi\rangle \) can be converted into a generator for a vector in \(\Pi\) [2411.11805].

This limitation is substantive rather than cosmetic. The conjecture requires non-relativizing techniques, because the corresponding black-box implication is known to fail. The note therefore identifies several open directions: prove or refute the conjecture; tighten the complexity classification of Kronecker coefficients; extend the framework to other state families such as hidden subgroup states, stabilizer subspaces, or other representation-theoretic multiplicity spaces; and develop rigorous methods for extracting generators or circuit descriptions from cloners [2411.11805].

A later extension pushes the CTNCT perspective from single witnesses to quantum ensembles. For a purification
\[
|\psi\rangle_{AB}=\sum_i \sqrt{p_i}\,|\psi_i\rangle_A\otimes |i\rangle_B,
\]
the fine-grained cloning target is
\[
\sigma^{(2)}_\psi=\sum_i p_i\,\psi_i^{\otimes 2}\otimes |i\rangle\langle i|_B.
\]
For Haar-random ensembles on an \(A\mid B\) bipartition, any CPTP map given \(t\) copies of the purification obeys an average-case trace-distance lower bound implying that achieving small constant error requires \(t=\Omega(2^{n_B/2})\) copies. For nonlinear two-copy estimation, any algorithm that succeeds with constant accuracy and success probability greater than \(0.99\) requires \(t=\Omega(2^{n_B/4})\). These results formalize an information-theoretic barrier caused by measurement-induced branching and the requirement to clone the same post-selected trajectory [2606.27756].

The same ensemble work also establishes a computational barrier even when the preparation circuit is known. Under QPRF and QPRP assumptions, estimating a simple two-copy nonlinear observable from copies of an efficiently preparable purification requires super-polynomial time; under standard LWE hardness, the same remains true even when the full polynomial-size circuit \(C\) preparing \(|\psi\rangle=C|0\rangle^{\otimes n}\) is given explicitly. At the same time, bounded-gate-complexity tomography yields a partial circumvention for finite-time evolutions: with
\[
N=\widetilde{\Theta}\!\left(\frac{k^2 G}{\varepsilon^2}\right)
\]
copies of a state prepared by a circuit with \(G\) two-qubit gates, one can learn a classical description approximating the \(k\)-th moment state to trace distance \(\varepsilon\). This establishes a three-way trade-off among sample complexity, computational complexity, and measurement resources rather than a single universal unclonability mechanism [2606.27756].

Taken together, these developments define the modern complexity-theoretic no-cloning agenda. Oracle-based CTNCT results show black-box hardness of producing extra copies; representation-theoretic constructions relate witness cloning to NP-hard positivity questions for Kronecker coefficients; white-box formulations seek non-relativizing lower bounds for QMA witness cloning; and ensemble formulations show that even with full circuit knowledge, fine-grained cloning and nonlinear multi-copy estimation can remain computationally intractable. The unifying theme is that once auxiliary classical structure is made available, quantum unclonability survives only as a statement about efficient computation, not about linearity alone [2411.11805].

Source: https://www.emergentmind.com/topics/complexity-theoretic-no-cloning-theorem