Papers
Topics
Authors
Recent
Search
2000 character limit reached

Proofs of Quantumness: Certifying Quantum Behavior

Updated 14 July 2026
  • Proofs of Quantumness (PoQ) are protocols that enable a classical verifier to confirm that a device exhibits genuine quantum behavior beyond classical simulation.
  • They employ diverse methods such as trapdoor functions, contextuality tests, and memory bounds to distinguish quantum operations from classical imitation.
  • Different PoQ constructions balance verifier efficiency, soundness, and assumption strength, driving advancements in quantum certification and cryptographic applications.

Searching arXiv for recent and foundational papers on proofs of quantumness to ground the article. Proofs of quantumness (PoQ) are interactive or operational procedures through which a classical verifier, or more generally a classical analysis procedure, certifies that an observed device behavior cannot be reproduced by an efficient classical machine and therefore exhibits genuinely quantum capability. Across the literature, PoQ encompass several distinct settings: cryptographic challenge–response protocols with a classical verifier and a quantum prover; inefficient-verifier formulations that certify sampling-based and search-based quantum advantage; contextuality- and Bell-inspired tests adapted to single devices; and temporal or foundational schemes that derive an inequality-free contradiction with classical assumptions from time-separated measurements (Brakerski et al., 2020, Morimae et al., 2022, Morimae et al., 2023, Arora et al., 2024, Hiroka et al., 2024, Ali et al., 2022). The field is unified by a common objective—distinguishing quantum from classical behavior under explicit assumptions—but differs sharply in verifier power, device dependence, round complexity, robustness, and the hardness assumptions required to establish soundness.

1. Definitions and formal variants

In cryptographic formulations, a proof of quantumness is a protocol between a classical probabilistic polynomial-time verifier and a prover such that an honest quantum prover is accepted with high probability while any efficient classical prover succeeds only with smaller probability. One explicit formalization requires constants α,β\alpha,\beta with αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda), α\alpha-correctness for some quantum PPT prover, and β\beta-soundness against every classical PPT prover (Morimae et al., 2022). A closely related formulation used in two-message random-oracle protocols states that for any PPT classical prover A\mathcal{A}, verifier acceptance is negligible, whereas an honest quantum prover is accepted with probability at least 1negl(λ)1-\mathrm{negl}(\lambda) (Brakerski et al., 2020).

Later work broadened the concept along two different axes. First, inefficient-verifier proofs of quantumness (IV-PoQ) allow the interaction phase to be handled by a PPT verifier V1V_1 while a second-stage verifier V2V_2 is unbounded and decides acceptance from the transcript. Completeness and soundness are then defined with respect to the final offline decision, and IV-PoQ are presented as a generalization of standard PoQ that captures both sampling-based and search-based quantum advantage (Hiroka et al., 2024, Morimae et al., 2023). Second, proofs of quantum memory (PoQM) generalize PoQ by splitting the protocol into an initialization phase and an execution phase and requiring soundness against provers that preserve at most m2(λ)m_2(\lambda) qubits across the phase boundary. In that formulation, PoQ is recovered as the special case m2=0m_2=0 (Hhan et al., 5 Oct 2025).

A separate foundational line uses “proof of quantumness” in a non-cryptographic sense. “Certified quantumness in time” denotes a non-probabilistic certification obtained from one sequence of two time-separated measurements on a single spin-αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)0 system. There the certification is not device-independent and is derived from a contradiction between quantum predictions and three classical assumptions: classical realism or macrorealism, noninvasive measurability, and simultaneous value definiteness (Ali et al., 2022). This suggests that PoQ has both a cryptographic meaning, centered on efficient classical verification, and a foundational meaning, centered on excluding classical hidden-variable explanations.

2. Historical trajectories and conceptual sources

The literature surveyed here organizes PoQ around several pre-existing themes. One trajectory begins with classically checkable quantum computations such as factoring via Shor’s algorithm; such tasks give a “trivial” PoQ in the sense that the verifier samples an average-case problem easy for quantum computers and conjecturally hard for classical ones, then asks the prover to solve it (Brakerski et al., 2020, Tomer et al., 6 Oct 2025). A second trajectory derives PoQ from Bell non-locality or contextuality, either directly through nonlocal games or via cryptographic compilers that emulate spatial or temporal separation inside a single device (Arora et al., 2024). A third trajectory is cryptographic and trapdoor-based: the verifier uses trapdoor claw-free functions, trapdoor permutations, one-way puzzles, or related primitives to force a prover into creating or measuring specific superpositions (Brakerski et al., 2020, Morimae et al., 2022, Morimae et al., 2023, Arabadjieva et al., 2024).

The contextuality lineage is older at the foundational level. Peres’s two-qubit proof uses commuting observables αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)1, αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)2, and αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)3, together with a noncontextual value assignment rule αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)4, to derive an inconsistency with quantum predictions in the singlet state (Ali et al., 2022). The temporal analogue replaces two particles at two locations by one spin-αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)5 measured at two times αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)6, yielding an inequality-free contradiction in time (Ali et al., 2022). More recent computational contextuality work adapts this spirit to efficient single-device tests: arbitrary contextuality games can be compiled into a four-message computational test of contextuality by using cryptography to enforce “temporal separation,” and those ideas also yield a two-round PoQ based on a single encrypted CNOT and very simple quantum operations (Arora et al., 2024).

The cryptographic line has evolved from stronger to weaker assumptions in some dimensions and from standard to generalized verification models in others. Two-message PoQ in the random oracle model eliminate the adaptive hard-core bit property from earlier trapdoor-claw-free-function protocols and thereby allow Ring Learning with Errors instantiations (Brakerski et al., 2020). Trapdoor permutations suffice for non-verifiable remote state preparation secure against classical adversaries and hence for PoQ against classical provers, showing that collision resistance and 2-to-1 structure are unnecessary in that restricted setting (Morimae et al., 2022). On a different front, IV-PoQ demonstrate that quantum advantage can be based on one-way functions and even on meta-complexity assumptions about GapK, though the verifier’s final decision becomes inefficient (Morimae et al., 2023, Hiroka et al., 2024).

3. Protocol architectures and representative constructions

A recurring architecture is remote state preparation. In one standard pattern, the verifier causes the prover to end with a superposition αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)7 while learning the pair αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)8 itself. The prover is then challenged to perform basis-dependent operations or measurements whose correct outputs depend on coherent access to that hidden pair. Earlier constructions realized this using 2-to-1 trapdoor collision-resistant hash functions; the 2022 trapdoor-permutation work instead uses a coherent execution of the Naor–Ostrovsky–Venkatesan–Yung interactive hashing protocol to generate exactly two consistent images αβ1/poly(λ)\alpha-\beta\ge 1/\mathrm{poly}(\lambda)9, whose unique preimages under a full-domain trapdoor permutation are α\alpha0 (Morimae et al., 2022). The resulting PoQ combines the remote-state-preparation stage with a computational Bell test. In the honest execution, the verifier accepts with probability α\alpha1, while any classical PPT prover is bounded by α\alpha2 (Morimae et al., 2022).

A second architecture uses trapdoor claw-free functions more directly. In the two-message random-oracle protocol, the verifier sends a trapdoor-claw-free key α\alpha3, the honest quantum prover produces tuples α\alpha4, and the verifier uses the trapdoor to recover α\alpha5 and check

α\alpha6

Acceptance occurs if at least α\alpha7 tuples pass (Brakerski et al., 2020). The honest prover is accepted with probability α\alpha8, whereas any classical PPT prover succeeds only with negligible probability in the random-oracle model (Brakerski et al., 2020). The paper presents this as a significant simplification relative to earlier trapdoor-based PoQ because it removes the adaptive hard-core bit property and reduces the interaction to a single challenge and a single response (Brakerski et al., 2020).

A third architecture compiles multi-round protocols into single-round ones using knowledge assumptions. Existing multi-round PoQ based on DDH or LWE are transformed into single-round protocols by introducing either a knowledge-of-exponent assumption or a knowledge-of-lattice-point assumption, respectively. The resulting schemes retain the same quantum resource requirements as the original multi-round counterparts while eliminating mid-circuit measurements. The DDH-based route uses an α\alpha9-NTCF framework and a three-test protocol with completeness β\beta0 and classical soundness at most β\beta1; the LWE-based β\beta2-NTCF route yields a two-test single-round protocol with completeness β\beta3 and soundness β\beta4, with β\beta5 in the explicit LWE instantiation (Arabadjieva et al., 2024). This suggests that removing interaction without using random oracles is possible, but at the cost of white-box knowledge assumptions.

Contextuality-based constructions form a distinct protocol family. A four-message compiler transforms a size-2 contextuality game with quantum value β\beta6 and non-contextual value β\beta7 into a single-device computational test whose honest quantum success is at least β\beta8 and whose classical PPT soundness is at most β\beta9 (Arora et al., 2024). In addition, the same paper extracts a standalone two-round PoQ whose honest quantum success is A\mathcal{A}0 and whose classical soundness is A\mathcal{A}1 (Arora et al., 2024). The protocol uses an NTCF family whose key generation hides a bit A\mathcal{A}2 in the xor of claw preimages, and the prover’s first-round actions leave behind a single BB84 qubit known to the verifier but not to the prover (Arora et al., 2024).

A final class replaces computational assumptions by memory restrictions. In the first bounded-memory protocol, the verifier streams linear equations defining a 2-to-1 linear map A\mathcal{A}3, where the kernel encodes a hidden parity vector. The honest quantum prover uses a superposition over A\mathcal{A}4 and obtains a claw state A\mathcal{A}5, after which a CHSH-style measurement test is run. Completeness is A\mathcal{A}6, while any classical prover using fewer than A\mathcal{A}7 bits of memory has success probability at most A\mathcal{A}8 (Malavolta et al., 29 May 2025). A second bounded-storage protocol based on interactive hashing yields an exponential gap between honest and adversarial memory: honest parties use A\mathcal{A}9 memory, whereas classical cheating provers with memory below 1negl(λ)1-\mathrm{negl}(\lambda)0 are still bounded by 1negl(λ)1-\mathrm{negl}(\lambda)1 (Malavolta et al., 29 May 2025).

4. Soundness mechanisms and hardness assumptions

The literature supports several distinct soundness mechanisms. The most direct is average-case classical hardness of a BQP task. This yields what one 2025 paper calls “trivial” PoQ: the verifier samples an average-case hard problem for classical computers that is easy for quantum computers and asks the prover to solve it (Tomer et al., 6 Oct 2025). By contrast, “non-trivial” PoQ rely on assumptions hard even for quantum computers, such as LWE, DDH-based adaptive hard-core constructions, or quantum-secure falsifiable assumptions more generally (Tomer et al., 6 Oct 2025).

Trapdoor-based PoQ derive soundness from the impossibility of simultaneously satisfying challenge branches that are easy to answer only if the prover can create or exploit a superposition over two hidden preimages. In the random-oracle two-message PoQ, the soundness proof is organized around three experiments and reduces any successful classical prover to a claw finder against the underlying noisy trapdoor claw-free family (Brakerski et al., 2020). In the trapdoor-permutation-based remote-state-preparation protocol, security against classical adversaries is inherited from a theorem about the NOVY interaction showing that a classical PPT algorithm cannot output preimages of both of the two values singled out by the random linear equations (Morimae et al., 2022). In the single-round protocols from knowledge assumptions, soundness is reduced to adaptive hard-core bits together with extractability of weak-image or image-test branches (Arabadjieva et al., 2024).

The efficient-versus-inefficient verifier distinction leads to different minimal assumptions. IV-PoQ can be built from one-way functions via statistically hiding, computationally binding bit commitments (Morimae et al., 2023). Quantum advantage can also be based on meta-complexity: weakly-classical-average-hard GapK implies classical-average-hard QPE, which implies the QAS/OWF condition and therefore the existence of IV-PoQ (Hiroka et al., 2024). In that framework IV-PoQ are explicitly described as a generalization of standard PoQ, and they encompass both sampling-based and search-based quantum advantage (Hiroka et al., 2024). This suggests that allowing offline, inefficient verification substantially broadens the assumption base.

Lower-bound work sharpens the picture by identifying cryptographic hardness that must underlie various PoQ variants. Arbitrary-round IV-PoQ with black-box reduction to a quantum-secure falsifiable assumption imply quantum-secure one-way puzzles (Tomer et al., 6 Oct 2025). Constant-round efficiently verifiable PoQ either collapse to “trivial” two-round PoQ or imply quantum-secure one-way functions or weak unclonability primitives such as weak minischemes or signature-token analogues (Tomer et al., 6 Oct 2025). Three-message IV-PoQ whose soundness is proved by a black-box reduction to a quantum-secure falsifiable assumption are ruled out (Tomer et al., 6 Oct 2025). For public-coin constant-round PoQ, the same work argues that they imply weak forms of quantum money or quantum lightning, providing an explanation for the difficulty of building publicly verifiable PoQ and related protocols from lattices (Tomer et al., 6 Oct 2025).

The bounded-memory papers replace computational hardness entirely by time-space or storage lower bounds. The first memory-bounded PoQ uses Raz’s lower bound for parity learning in small space to show that any classical adversary with memory below 1negl(λ)1-\mathrm{negl}(\lambda)2 cannot recover the hidden parity vector and therefore cannot emulate the prover’s CHSH-style correlations (Malavolta et al., 29 May 2025). The second uses interactive hashing and bounded-storage arguments, together with a plug-in lemma for quantum memory, to show that a limited-memory adversary retains insufficient information about many streamed bits to reconstruct both “claw” values (Malavolta et al., 29 May 2025). In an even more restrictive regime, unconditional PoQ between classical and quantum small-space machines are obtained by using sub-1negl(λ)1-\mathrm{negl}(\lambda)3 space lower bounds of Dwork–Stockmeyer and Freivalds–Karpinski together with constant-space quantum algorithms for padded separation problems (Say et al., 2024).

5. Qubit certification, contextuality, and temporal formulations

An important development is that some PoQ protocols certify more than “non-classicality.” A broad class of simple two-challenge PoQ protocols can be abstracted into a template where the verifier’s final check is determined by a transcript 1negl(λ)1-\mathrm{negl}(\lambda)4, private randomness 1negl(λ)1-\mathrm{negl}(\lambda)5, a one-bit challenge 1negl(λ)1-\mathrm{negl}(\lambda)6, and two projectors 1negl(λ)1-\mathrm{negl}(\lambda)7. The paper then defines observables 1negl(λ)1-\mathrm{negl}(\lambda)8 and 1negl(λ)1-\mathrm{negl}(\lambda)9 and shows that near-optimal quantum success forces approximate anti-commutation: V1V_10 Hence protocols of this kind certify that the prover holds a qubit and performs approximately Pauli V1V_11 and V1V_12 measurements on it (Brakerski et al., 2023). This result applies to recent “simple” PoQ proposals such as Kahanamoku-Meyer et al. and Kalai et al., and it proves a tight quantum soundness upper bound of V1V_13, where earlier works only gave lower bounds for honest quantum strategies and upper bounds for classical ones (Brakerski et al., 2023).

Contextuality is the natural conceptual bridge between Bell-type PoQ and single-device tests. The 2024 contextuality paper defines a contextuality game via a question set V1V_14, answer alphabet V1V_15, a family of compatible contexts V1V_16, a distribution over contexts, and a predicate V1V_17. Non-contextual strategies correspond to a joint distribution over fixed answers V1V_18 to all questions, while quantum strategies are determined by commuting observables V1V_19 measured on a state V2V_20 (Arora et al., 2024). By encrypting one question under QFHE and later revealing a combined Pauli key through an oblivious Pauli pad, the compiler forces “temporal separation” between the first and second measurements and obtains a computational contextuality test for a single device (Arora et al., 2024). This suggests that cryptography can replace spatial separation in Bell tests and compatibility assumptions in contextuality tests by computational restrictions on information flow.

Temporal PoQ appear in an even more foundational sense in the single-shot temporal-measurement paper. There the system is a single qubit with Hamiltonian

V2V_21

and Heisenberg evolution

V2V_22

For V2V_23 and V2V_24, the composite temporal observables

V2V_25

satisfy the state-independent eigenvalue relations

V2V_26

for any state V2V_27 (Ali et al., 2022). Under predetermined values V2V_28, the corresponding hidden-variable equations

V2V_29

multiply to a contradiction because the left-hand side product is m2(λ)m_2(\lambda)0 while the quantum right-hand sides multiply to m2(λ)m_2(\lambda)1 (Ali et al., 2022). The protocol is therefore a single-shot, inequality-free proof of certified quantumness in time, though strongly device-dependent (Ali et al., 2022).

6. Applications, generalizations, and limitations

PoQ serve as entry points to stronger verification and cryptographic tasks. The “Simple Tests of Quantumness Also Certify Qubits” result explicitly positions qubit certification as a building block for certifiable randomness and classical delegation of quantum computation (Brakerski et al., 2023). The contextuality compiler is presented as a route from any contextuality game with m2(λ)m_2(\lambda)2 to a single-device computational test, and the authors note that the same ideas might extend to generalized contextuality or other quantum resources (Arora et al., 2024). The multi-prover quantum-knowledge protocol goes further still: in a classical-verifier, two-prover setting for XZ-local Hamiltonian, successful play not only proves “quantumness” but allows an extractor, with oracle access to the provers’ observables, to reconstruct a low-energy witness state, thereby yielding a new level of verification for a proof of quantumness (Broadbent et al., 17 Mar 2025).

PoQM enlarge the scope from one-shot quantum capability to persistent quantum storage. One construction uses 1-of-m2(λ)m_2(\lambda)3 puzzles to obtain a four-round m2(λ)m_2(\lambda)4-PoQM under subexponential hardness of LWE for any polynomially bounded m2(λ)m_2(\lambda)5 (Hhan et al., 5 Oct 2025). Another uses verifiable remote state preparation of BB84 states to produce polynomial-round m2(λ)m_2(\lambda)6-PoQM under polynomial LWE hardness (Hhan et al., 5 Oct 2025). Those constructions imply one-way puzzles, and an extractable version implies QCCC key exchange (Hhan et al., 5 Oct 2025). A plausible implication is that certifying persistent memory reveals stronger cryptographic structure than standard PoQ.

Several limitations recur. Many cryptographic PoQ are only sound against classical PPT provers, not malicious quantum adversaries (Morimae et al., 2022, Arabadjieva et al., 2024, Arora et al., 2024). Random-oracle protocols simplify interaction but move security out of the plain model (Brakerski et al., 2020, Arora et al., 2024). Device-independent security is usually absent; the temporal single-shot protocol is explicitly “strongly device-dependent” and assumes the correct Hilbert space, Hamiltonian, observables, and projective measurement model (Ali et al., 2022). Robustness is often underdeveloped: the temporal proof has no quantitative noise threshold (Ali et al., 2022), and even some elegant memory-bounded protocols are mainly asymptotic (Malavolta et al., 29 May 2025). Constant-round and public-coin variants appear to require stronger primitives such as weak money-like unclonability (Tomer et al., 6 Oct 2025). Finally, the existence of efficient-verifier PoQ from the weakest standard assumptions remains open, while 3-message IV-PoQ with black-box reduction to quantum-secure falsifiable assumptions are ruled out (Tomer et al., 6 Oct 2025).

Taken together, these works show that “proofs of quantumness” is no longer a single protocol paradigm but a hierarchy of verification notions. At one end are foundational, inequality-free temporal contradictions (Ali et al., 2022); at another are cryptographic challenge–response protocols grounded in trapdoor or commitment primitives (Brakerski et al., 2020, Morimae et al., 2022, Arabadjieva et al., 2024); alongside them sit contextuality compilers (Arora et al., 2024), inefficient-verifier formulations tied to one-way functions or meta-complexity (Morimae et al., 2023, Hiroka et al., 2024), memory-certification protocols (Hhan et al., 5 Oct 2025), and unconditional bounded-memory or tiny-space protocols (Malavolta et al., 29 May 2025, Say et al., 2024). The common theme is the same: extracting operational evidence of quantum capability from a classical interface. The main divergences concern what exactly is certified—mere non-classicality, a qubit, a witness state, persistent memory, contextuality, or temporal nonclassicality—and what hardness, trust, or resource assumptions are required to make that certification rigorous.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Proofs of Quantumness (PoQ).