---
title: Parallel-Query Pseudorandom Unitaries
url: https://www.emergentmind.com/topics/parallel-query-pseudorandom-unitaries
type: topic
---

# Parallel-Query Pseudorandom Unitaries

Parallel-query pseudorandom unitaries are ensembles of efficiently implementable unitaries that are intended to be indistinguishable from Haar-random unitaries to quantum distinguishers with oracle access, in regimes where access may be batched, entangled, and non-adaptive, or more generally where arbitrary polynomial-time oracle access is allowed. In the non-adaptive formulation, the distinguisher prepares an arbitrary joint input state and applies a single parallel call \(U^{\otimes t}\); in the full oracle formulation, it may interleave polynomially many calls to \(U\) with arbitrary quantum computation, and in the strong formulation it may also query \(U^\dagger\). The subject therefore sits at the intersection of unitary designs, quantum query complexity, and quantum cryptography, with the main conceptual divide being between parallel-only security and full adaptive security [2402.14803][2410.10116].

## 1. Oracle models and definitions

The standard oracle model for pseudorandom unitaries fixes an \(n\)-qubit oracle unitary \(\mathcal{O}\) acting on a query register \(\mathsf{A}\), together with an ancilla or workspace register \(\mathsf{B}\) of \(m=\mathrm{poly}(n)\) qubits. A forward-only \(t\)-query adversary is parameterized by inter-query unitaries \(A_1,\dots,A_t\) on \(\mathsf{A}\otimes\mathsf{B}\), and its final state is
\[
\ket{\mathrm{Adv}_t^{\mathcal O}}_{\mathsf{AB}}
=
\prod_{i=1}^t
\bigl(\mathcal O_{\mathsf A}\cdot A_{i,\mathsf{AB}}\bigr)\ket{0^{n+m}}_{\mathsf{AB}}.
\]
In the strong setting, the adversary may alternate between forward and inverse queries. Writing \(b_i\in\{0,1\}\), with \(b_i=0\) denoting \(\mathcal O\) and \(b_i=1\) denoting \(\mathcal O^\dagger\), the final state is
\[
\ket{\mathrm{Adv}_t^{\mathcal O}}_{\mathsf{AB}}
=
\prod_{i=1}^t
\Bigl(\bigl(1-b_i\bigr)\mathcal O_{\mathsf A}+b_i\mathcal O_{\mathsf A}^\dagger\Bigr)
A_{i,\mathsf{AB}}\ket{0^{n+m}}_{\mathsf{AB}}.
\]
A family \(\{\mathcal U_n\}_{n\in\mathbb N}\), with \(\mathcal U_n=\{U_k\}_{k\in\mathcal K_n}\), is a pseudorandom unitary family if it is efficiently computable and if no polynomial-time oracle adversary can distinguish \(U_k\) from Haar-random with more than negligible advantage; a strong PRU is secure even when the adversary can query both \(U\) and \(U^\dagger\) [2410.10116].

The non-adaptive, or parallel-query, formulation specializes this oracle model to a single batch query. The distinguisher prepares an arbitrary state \(\ket{\psi}_{A_1\cdots A_t B}\), applies \(U^{\otimes t}\) once on registers \(A_1,\dots,A_t\), and then performs an arbitrary measurement. Security is equivalently phrased as computational indistinguishability of
\[
\mathbb{E}_{k\sim\mathcal K}
\Bigl[(U_k^{\otimes t}\otimes \mathbf 1)\ket{\psi}\bra{\psi}(U_k^{\otimes t}\otimes \mathbf 1)^\dagger\Bigr]
\approx_c
\mathbb{E}_{U\sim\mathrm{Haar}}
\Bigl[(U^{\otimes t}\otimes \mathbf 1)\ket{\psi}\bra{\psi}(U^{\otimes t}\otimes \mathbf 1)^\dagger\Bigr].
\]
In this sense, “parallel-query PRU” originally meant indistinguishability under one use of \(U^{\otimes t}\), whereas later work uses the full oracle model and thereby strictly contains the parallel setting as a special case [2402.14803].

A recurring source of confusion is that the full oracle model already includes substantial parallelism. A single oracle call acts on the entire query register, so it automatically supports superpositions over all \(2^n\) basis inputs. What the formalism counts is the number of oracle uses \(t\), not a notion of rounds. This means that adaptivity, superposition queries, and arbitrary entanglement are unconstrained; only total oracle-gate complexity is polynomially bounded [2410.10116].

## 2. Non-adaptive and parallel-query constructions

The first explicit non-adaptive construction uses the composition
\[
U_k=P_{k_1}F_{k_2}C_{k_3},
\]
where \(C_{k_3}\) is a random Clifford unitary, \(F_{k_2}\) is a pseudorandom binary phase operator
\[
F_{k_2}:\ket{x}\mapsto (-1)^{f_{k_2}(x)}\ket{x},
\]
and \(P_{k_1}\) is a pseudorandom permutation operator
\[
P_{k_1}:\ket{x}\mapsto \ket{\pi_{k_1}(x)}.
\]
Assuming quantum-secure one-way functions, and hence quantum-secure PRFs and PRPs, this ensemble is secure against non-adaptive distinguishers, meaning that no efficient quantum query algorithm allowed a single application of \(U^{\otimes \mathrm{poly}(n)}\) can distinguish it from Haar randomness [2402.14803].

A closely related line of work introduced the \(PFC\) ensemble,
\[
U=PFC,
\]
with \(P\) a random computational-basis permutation, \(F\) a random binary phase operator, and \(C\) a random Clifford unitary. The key information-theoretic statement is that the \(PFC\) ensemble is a diamond \(\varepsilon\)-approximate \(t\)-design with
\[
\varepsilon = O\!\left(\frac{t}{\sqrt d}\right),
\qquad d=2^n.
\]
Because this error is negligible for polynomial \(t\), replacing the truly random classical pieces by pseudorandom function and permutation families yields non-adaptive PRUs. The same framework also gives adaptive pseudorandom isometries once the unitary model is relaxed to isometries from \(n\) to \(n+\omega(\log n)\) qubits [2404.12647].

A second construction lifts random permutations on \(S(N)\) to random unitaries on \(U(N)\), \(N=2^n\), by forming products of exponentials of sparse Hermitian matrices built from phased permutations. The resulting ensemble is shown to approximate Haar moments up to \(2^{\Omega(n)}\), and substituting \(\tilde O(k)\)-wise independent permutations gives efficient \(k\)-designs, while substituting quantum-secure PRPs gives a parallel-secure PRU. In that framework, the operational distinguishability of an ensemble \(\mathcal U\) under \(k\) parallel queries is captured by the diamond norm between the twirling channels
\[
\mathcal N_{2k,\mathcal U}[\rho]
=
\mathbb E_{U\sim\mathcal U}
\bigl[U^{\otimes k}\rho\,U^{\dagger\otimes k}\bigr]
\]
and the Haar twirl \(\mathcal N_{2k,\mathrm{Haar}}\) [2404.16751].

These works established a precise parallel-query notion but also exposed its limitation. The non-adaptive model captures a single global batch \(U^{\otimes t}\), whereas adaptive distinguishers may interleave arbitrary channels between oracle calls. The early papers therefore left open whether the same simple \(PFC\)-type constructions remain secure against fully adaptive distinguishers, and that gap became the main structural question for PRUs [2402.14803][2404.12647].

## 3. Full existence theorems for standard and strong PRUs

The general existence question was resolved by proving that pseudorandom unitaries exist assuming any quantum-secure one-way function exists. Two variants were established. For standard PRUs, secure against forward-only oracle adversaries, the construction is
\[
\mathcal O = P_\pi \cdot F_f \cdot C,
\]
where \(\pi\) is a random permutation of \([N]\), \(f\) is a random Boolean function on \([N]\), \(P_\pi=\sum_x \ket{\pi(x)}\!\bra{x}\), \(F_f=\sum_x (-1)^{f(x)}\ket{x}\!\bra{x}\), and \(C\) is drawn from an exact unitary 2-design such as the random Clifford group. For every \(t\)-query adversary,
\[
\mathrm{TD}\!\left(
\mathbb E_{\mathcal O\gets \mathsf{PF}(\mathfrak D)}
\ketbra{\mathrm{Adv}_t^{\mathcal O}},
\mathbb E_{\mathcal O\sim\mathrm{Haar}}
\ketbra{\mathrm{Adv}_t^{\mathcal O}}
\right)
\le
\frac{4t(t-1)}{N+1}.
\]
Replacing the truly random permutation, function, and 2-design pieces by pseudorandom counterparts under quantum-secure one-way functions yields a computational PRU [2410.10116].

For strong PRUs, secure against adversaries that can query both \(U\) and \(U^\dagger\), the construction becomes
\[
\mathcal O = D\cdot P_\pi \cdot F_f \cdot C,
\]
where \(f:[N]\to\{0,1,2\}\) is now ternary, \(F_f=\sum_x \omega_3^{f(x)}\ket{x}\!\bra{x}\) with \(\omega_3=e^{2\pi i/3}\), and both \(C\) and \(D\) come from a unitary 2-design. The statistical bound for every \(t\)-query forward-and-inverse adversary is
\[
\mathrm{TD}\!\left(
\mathbb E_{\mathcal O\gets \mathsf{sPRU}(\mathfrak D)}
\ketbra{\mathrm{Adv}_t^{\mathcal O}},
\mathbb E_{\mathcal O\sim\mathrm{Haar}}
\ketbra{\mathrm{Adv}_t^{\mathcal O}}
\right)
\le
\frac{18t(t+1)}{N^{1/8}}.
\]
This gives strong computational PRUs under the same quantum-secure one-way-function assumption [2410.10116].

These theorems are stronger than the earlier parallel-only results in two ways. First, the security definition is not restricted to a single batch call \(U^{\otimes t}\), but quantifies over arbitrary polynomial-time oracle circuits. Second, the strong notion explicitly allows inverse access. A non-adaptive parallel distinguisher is therefore just one special case of the general theorem. This suggests that the conceptual distinction is not “parallel versus non-parallel” in isolation, but rather “single-batch non-adaptive access versus unrestricted oracle access” [2410.10116].

## 4. Path-recording simulation of Haar queries

The conceptual core of the adaptive theory is the path-recording oracle. In the forward-only case, for an \(n\)-qubit Haar-random unitary \(U\), one defines an efficiently implementable linear map \(V\) acting on the query register together with a relation register \(\mathsf R\) that stores pairs \((x,y)\). In simplified form,
\[
V:\ket{x}_{\mathsf A}\ket{R}_{\mathsf R}
\mapsto
\frac{1}{\sqrt{N-|R|}}
\sum_{y\notin \mathrm{Im}(R)}
\ket{y}_{\mathsf A}\ket{R\cup\{(x,y)\}}_{\mathsf R}.
\]
It maps an input \(x\) to a uniform superposition over currently unused outputs \(y\), while recording the pair in \(\mathsf R\). For every \(t\)-query algorithm,
\[
\mathrm{TD}\!\left(
\mathbb E_U\ketbra{\mathrm{Adv}_t^U},
\mathrm{Tr}_{\mathsf R}\bigl(\ketbra{\mathrm{Adv}_t^V}\bigr)
\right)
\le
O\!\left(\frac{t^2}{N}\right).
\]
Thus any algorithm making up to \(t\) queries to a Haar-random unitary can be simulated by an explicit efficient quantum circuit up to trace distance \(O(t^2/2^n)\) [2410.10116].

When inverse queries are allowed, the bookkeeping is richer. The strong-security analysis introduces forward and inverse relation registers, partial path-recording isometries, and a symmetrized fully defined oracle \(V\) that reproduces the purified dynamics of the ternary permutation-function construction. The corresponding simulation theorem states that for any \(t\)-query forward-and-inverse algorithm,
\[
\mathrm{TD}\!\left(
\mathbb E_{U\sim\mathrm{Haar}}\ketbra{\mathrm{Adv}_t^U},
\mathrm{Tr}_{\mathsf L\mathsf R}\bigl(\ketbra{\mathrm{Adv}_t^V}\bigr)
\right)
\le
O\!\bigl(t^2/N^{1/8}\bigr).
\]
The paper’s abstract summarizes the upshot more broadly: any algorithm that makes queries to a Haar-random unitary can be efficiently simulated on a quantum computer, up to inverse-exponential trace distance [2410.10116].

The importance for parallel-query security is that these simulation bounds depend only on \(t\) and \(N\), not on the temporal organization of queries. The proofs reason about the full joint adversary state after \(t\) oracle uses, together with projectors onto “distinct” subspaces and variable-length relation registers encoding full coherent histories. This removes any need for a sequential Markovian interpretation of the oracle interaction [2410.10116].

## 5. How parallel access fits into the modern theory

In the single-oracle setting, the standard quantum oracle model already subsumes parallel-query strategies. A single call \(\mathcal O_{\mathsf A}\) acts on the full \(2^n\)-dimensional query register and therefore supports superpositions over all classical inputs. A non-adaptive batch adversary that applies \(U^{\otimes t}\) once is just a special case of a more general oracle algorithm, and the full PRU and strong-PRU definitions strictly contain such models [2410.10116].

Earlier non-adaptive papers made this distinction explicit. In the non-adaptive model, the relevant object is one global twirl channel on \(t\) copies, and the proof strategy reduces everything to the comparison of
\[
\mathbb E_{P,F,C}(PFC)^{\otimes t}(\cdot)(PFC)^{\otimes t,\dagger}
\quad\text{and}\quad
\mathbb E_{U\sim\mathrm{Haar}}U^{\otimes t}(\cdot)U^{\otimes t,\dagger}.
\]
That analysis is sufficient for batch security but does not automatically address arbitrary adaptive compositions
\[
\mathcal E_\ell\circ \mathcal T\circ \mathcal E_{\ell-1}\circ \mathcal T\circ \cdots \circ \mathcal E_1\circ \mathcal T,
\]
which explains why adaptive security remained open in the unitary case even after non-adaptive PRUs had been constructed [2402.14803].

A second misconception concerns “many independent parallel oracle instances.” The single-oracle theory does not explicitly formalize a multi-instance model in which the adversary receives independent oracles \(U_1,\dots,U_w\) and can query them all in parallel. The full adaptive PRU proofs are stated for repeated uses of one oracle instance. The paper notes that if one wants \(w\) independent parallel queries to an \(n\)-qubit unitary, that corresponds to a different oracle model, and it is not explicitly treated. A plausible implication is that many applications can still be reduced to a larger single-instance Hilbert space, but this extension is not part of the formal theorem [2410.10116].

The gluing perspective reinforces the same point. Low-depth constructions built from overlapping local Haar blocks are analyzed through the adversary’s joint state and overall query count rather than any syntactic notion of rounds, which is why the resulting indistinguishability statements are naturally compatible with wide, low-depth, highly parallel oracle use [2410.10116][2404.12647].

## 6. Stronger oracle models, idealized variants, and later extensions

The inverseless Haar random oracle model provides an idealized benchmark for parallel-query pseudorandomness. In that model, all parties share access to a common Haar-random unitary \(U\), but not to \(U^{-1}\). It was shown that unbounded-query secure PRUs exist with a construction that makes two calls to the Haar oracle, while any construction making only a single call to the Haar oracle cannot achieve unbounded-query security. The single-call regime nevertheless admits bounded-query secure PRUs, with a threshold around \(\lambda/\log \lambda\) queries in the parallel or non-adaptive setting [2410.19320].

A distinct idealized model, the invertible quantum Haar random oracle model, gives all parties access to a common Haar-random unitary and its inverse. In that setting, classically-accessible adaptive secure pseudorandom function-like state generators were constructed, but simple keyed-unitary templates such as
\[
V_k = X_{k_1}UX_{k_0}
\]
were shown not to be quantum-accessible PRFSGs and in particular not to be PRUs. The attack uses a Simon-type quantum procedure and exploits coherent access to both the public Haar unitary and the keyed construction. This demonstrates that not every apparently natural “mask a Haar unitary by simple conjugation” template survives quantum parallel access [2411.03201].

The strongest post-2024 extension enlarges the oracle model beyond \(U\) and \(U^\dagger\) to include \(U^*\) and \(U^T\). This work introduces strong unitary designs and strong PRUs that remain robust under all such queries, including parallel and adaptive access patterns, and proves constructions of depth \(O(\log n)\) for strong designs and \(\mathrm{poly}(\log n)\) for ancilla-free strong PRUs. Its motivation is that butterfly-effect experiments, Hayden–Preskill decoding, and related scrambling diagnostics use precisely these richer oracle interfaces, which conventional designs and strong PRUs do not cover [2509.26310].

Taken together, these results give a layered picture of parallel-query pseudorandomness. Non-adaptive PRUs address one batch \(U^{\otimes t}\); standard and strong PRUs address arbitrary polynomial-time oracle use of \(U\) and possibly \(U^\dagger\); and later strong-design notions extend further to \(U^*\) and \(U^T\). This suggests that “parallel-query pseudorandom unitary” is best understood not as one single definition, but as a family of oracle indistinguishability notions ordered by the richness of the allowed query interface and the extent of adaptivity they permit.

Source: https://www.emergentmind.com/topics/parallel-query-pseudorandom-unitaries