---
title: 'Proofs of Quantumness: Certifying Quantum Behavior'
url: https://www.emergentmind.com/topics/proofs-of-quantumness-poq
type: topic
---

# Proofs of Quantumness: Certifying Quantum Behavior

Searching arXiv for recent and foundational papers on proofs of quantumness to ground the article.
Proofs of quantumness (PoQ) are interactive or operational procedures through which a classical verifier, or more generally a classical analysis procedure, certifies that an observed device behavior cannot be reproduced by an efficient classical machine and therefore exhibits genuinely quantum capability. Across the literature, PoQ encompass several distinct settings: cryptographic challenge–response protocols with a classical verifier and a quantum prover; inefficient-verifier formulations that certify sampling-based and search-based quantum advantage; contextuality- and Bell-inspired tests adapted to single devices; and temporal or foundational schemes that derive an inequality-free contradiction with classical assumptions from time-separated measurements [2005.04826], [2208.12390], [2302.04749], [2405.06787], [2410.01369], [2206.02581]. The field is unified by a common objective—distinguishing quantum from classical behavior under explicit assumptions—but differs sharply in verifier power, device dependence, round complexity, robustness, and the hardness assumptions required to establish soundness.

## 1. Definitions and formal variants

In cryptographic formulations, a proof of quantumness is a protocol between a classical probabilistic polynomial-time verifier and a prover such that an honest quantum prover is accepted with high probability while any efficient classical prover succeeds only with smaller probability. One explicit formalization requires constants \(\alpha,\beta\) with \(\alpha-\beta\ge 1/\mathrm{poly}(\lambda)\), \(\alpha\)-correctness for some quantum PPT prover, and \(\beta\)-soundness against every classical PPT prover [2208.12390]. A closely related formulation used in two-message random-oracle protocols states that for any PPT classical prover \(\mathcal{A}\), verifier acceptance is negligible, whereas an honest quantum prover is accepted with probability at least \(1-\mathrm{negl}(\lambda)\) [2005.04826].

Later work broadened the concept along two different axes. First, inefficient-verifier proofs of quantumness (IV-PoQ) allow the interaction phase to be handled by a PPT verifier \(V_1\) while a second-stage verifier \(V_2\) is unbounded and decides acceptance from the transcript. Completeness and soundness are then defined with respect to the final offline decision, and IV-PoQ are presented as a generalization of standard PoQ that captures both sampling-based and search-based quantum advantage [2410.01369], [2302.04749]. Second, proofs of quantum memory (PoQM) generalize PoQ by splitting the protocol into an initialization phase and an execution phase and requiring soundness against provers that preserve at most \(m_2(\lambda)\) qubits across the phase boundary. In that formulation, PoQ is recovered as the special case \(m_2=0\) [2510.04159].

A separate foundational line uses “proof of quantumness” in a non-cryptographic sense. “Certified quantumness in time” denotes a non-probabilistic certification obtained from one sequence of two time-separated measurements on a single spin-\(1/2\) system. There the certification is not device-independent and is derived from a contradiction between quantum predictions and three classical assumptions: classical realism or macrorealism, noninvasive measurability, and simultaneous value definiteness [2206.02581]. This suggests that PoQ has both a cryptographic meaning, centered on efficient classical verification, and a foundational meaning, centered on excluding classical hidden-variable explanations.

## 2. Historical trajectories and conceptual sources

The literature surveyed here organizes PoQ around several pre-existing themes. One trajectory begins with classically checkable quantum computations such as factoring via Shor’s algorithm; such tasks give a “trivial” PoQ in the sense that the verifier samples an average-case problem easy for quantum computers and conjecturally hard for classical ones, then asks the prover to solve it [2005.04826], [2510.05082]. A second trajectory derives PoQ from Bell non-locality or contextuality, either directly through nonlocal games or via cryptographic compilers that emulate spatial or temporal separation inside a single device [2405.06787]. A third trajectory is cryptographic and trapdoor-based: the verifier uses trapdoor claw-free functions, trapdoor permutations, one-way puzzles, or related primitives to force a prover into creating or measuring specific superpositions [2005.04826], [2208.12390], [2302.04749], [2405.15736].

The contextuality lineage is older at the foundational level. Peres’s two-qubit proof uses commuting observables \(\sigma_x^{(1)}\sigma_x^{(2)}\), \(\sigma_y^{(1)}\sigma_y^{(2)}\), and \(\sigma_z^{(1)}\sigma_z^{(2)}\), together with a noncontextual value assignment rule \(v(AB)=v(A)v(B)\), to derive an inconsistency with quantum predictions in the singlet state [2206.02581]. The temporal analogue replaces two particles at two locations by one spin-\(1/2\) measured at two times \(t_1,t_2\), yielding an inequality-free contradiction in time [2206.02581]. More recent computational contextuality work adapts this spirit to efficient single-device tests: arbitrary contextuality games can be compiled into a four-message computational test of contextuality by using cryptography to enforce “temporal separation,” and those ideas also yield a two-round PoQ based on a single encrypted CNOT and very simple quantum operations [2405.06787].

The cryptographic line has evolved from stronger to weaker assumptions in some dimensions and from standard to generalized verification models in others. Two-message PoQ in the random oracle model eliminate the adaptive hard-core bit property from earlier trapdoor-claw-free-function protocols and thereby allow Ring Learning with Errors instantiations [2005.04826]. Trapdoor permutations suffice for non-verifiable remote state preparation secure against classical adversaries and hence for PoQ against classical provers, showing that collision resistance and 2-to-1 structure are unnecessary in that restricted setting [2208.12390]. On a different front, IV-PoQ demonstrate that quantum advantage can be based on one-way functions and even on meta-complexity assumptions about GapK, though the verifier’s final decision becomes inefficient [2302.04749], [2410.01369].

## 3. Protocol architectures and representative constructions

A recurring architecture is remote state preparation. In one standard pattern, the verifier causes the prover to end with a superposition \(|x_0\rangle+|x_1\rangle\) while learning the pair \(\{x_0,x_1\}\) itself. The prover is then challenged to perform basis-dependent operations or measurements whose correct outputs depend on coherent access to that hidden pair. Earlier constructions realized this using 2-to-1 trapdoor collision-resistant hash functions; the 2022 trapdoor-permutation work instead uses a coherent execution of the Naor–Ostrovsky–Venkatesan–Yung interactive hashing protocol to generate exactly two consistent images \(y_0,y_1\), whose unique preimages under a full-domain trapdoor permutation are \(x_0,x_1\) [2208.12390]. The resulting PoQ combines the remote-state-preparation stage with a computational Bell test. In the honest execution, the verifier accepts with probability \(\frac{1}{2}+\frac{1}{2}\cos^2\frac{\pi}{8}\approx 0.925\), while any classical PPT prover is bounded by \(\frac{7}{8}+\mathrm{negl}(\lambda)\) [2208.12390].

A second architecture uses trapdoor claw-free functions more directly. In the two-message random-oracle protocol, the verifier sends a trapdoor-claw-free key \(k\), the honest quantum prover produces tuples \((y_i,m_i,d_i)\), and the verifier uses the trapdoor to recover \(x_{i,0},x_{i,1}\) and check
\[
m_i = d_i^\top\big(\mathrm{BitDecomp}(x_{i,0})+\mathrm{BitDecomp}(x_{i,1})\big)+H(x_{i,0})+H(x_{i,1}) \pmod 2.
\]
Acceptance occurs if at least \(0.75\lambda\) tuples pass [2005.04826]. The honest prover is accepted with probability \(1-\mathrm{negl}(\lambda)\), whereas any classical PPT prover succeeds only with negligible probability in the random-oracle model [2005.04826]. The paper presents this as a significant simplification relative to earlier trapdoor-based PoQ because it removes the adaptive hard-core bit property and reduces the interaction to a single challenge and a single response [2005.04826].

A third architecture compiles multi-round protocols into single-round ones using knowledge assumptions. Existing multi-round PoQ based on DDH or LWE are transformed into single-round protocols by introducing either a knowledge-of-exponent assumption or a knowledge-of-lattice-point assumption, respectively. The resulting schemes retain the same quantum resource requirements as the original multi-round counterparts while eliminating mid-circuit measurements. The DDH-based route uses an \(e^3\)-NTCF framework and a three-test protocol with completeness \(\frac{2+\gamma}{3}-\mathrm{negl}(\lambda)\) and classical soundness at most \(5/6+\mathrm{negl}(\lambda)\); the LWE-based \(e^2\)-NTCF route yields a two-test single-round protocol with completeness \((1+\gamma)/2\) and soundness \(3/4+\mathrm{negl}(\lambda)\), with \(\gamma=1\) in the explicit LWE instantiation [2405.15736]. This suggests that removing interaction without using random oracles is possible, but at the cost of white-box knowledge assumptions.

Contextuality-based constructions form a distinct protocol family. A four-message compiler transforms a size-2 contextuality game with quantum value \(\omega_{\mathrm{Qu}}\) and non-contextual value \(\omega_{\mathrm{NC}}\) into a single-device computational test whose honest quantum success is at least \(\frac{1}{2}(1+\omega_{\mathrm{Qu}})-\mathrm{negl}(\lambda)\) and whose classical PPT soundness is at most \(\frac{1}{2}(1+\omega_{\mathrm{NC}})+\mathrm{negl}(\lambda)\) [2405.06787]. In addition, the same paper extracts a standalone two-round PoQ whose honest quantum success is \(\cos^2(\pi/8)\) and whose classical soundness is \(3/4+\mathrm{negl}(\lambda)\) [2405.06787]. The protocol uses an NTCF family whose key generation hides a bit \(s\) in the xor of claw preimages, and the prover’s first-round actions leave behind a single BB84 qubit known to the verifier but not to the prover [2405.06787].

A final class replaces computational assumptions by memory restrictions. In the first bounded-memory protocol, the verifier streams linear equations defining a 2-to-1 linear map \(x\mapsto Ax\), where the kernel encodes a hidden parity vector. The honest quantum prover uses a superposition over \(x\) and obtains a claw state \((|x_0\rangle+|x_1\rangle)/\sqrt{2}\), after which a CHSH-style measurement test is run. Completeness is \(\cos^2(\pi/8)-O(2^{-n})\), while any classical prover using fewer than \(n^2/20\) bits of memory has success probability at most \(3/4+O(2^{-n})\) [2505.23978]. A second bounded-storage protocol based on interactive hashing yields an exponential gap between honest and adversarial memory: honest parties use \(O(\lambda\,\mathrm{polylog}\,m)\) memory, whereas classical cheating provers with memory below \(m(\lambda)\) are still bounded by \(3/4+2^{-\Omega(\lambda)}\) [2505.23978].

## 4. Soundness mechanisms and hardness assumptions

The literature supports several distinct soundness mechanisms. The most direct is average-case classical hardness of a BQP task. This yields what one 2025 paper calls “trivial” PoQ: the verifier samples an average-case hard problem for classical computers that is easy for quantum computers and asks the prover to solve it [2510.05082]. By contrast, “non-trivial” PoQ rely on assumptions hard even for quantum computers, such as LWE, DDH-based adaptive hard-core constructions, or quantum-secure falsifiable assumptions more generally [2510.05082].

Trapdoor-based PoQ derive soundness from the impossibility of simultaneously satisfying challenge branches that are easy to answer only if the prover can create or exploit a superposition over two hidden preimages. In the random-oracle two-message PoQ, the soundness proof is organized around three experiments and reduces any successful classical prover to a claw finder against the underlying noisy trapdoor claw-free family [2005.04826]. In the trapdoor-permutation-based remote-state-preparation protocol, security against classical adversaries is inherited from a theorem about the NOVY interaction showing that a classical PPT algorithm cannot output preimages of both of the two values singled out by the random linear equations [2208.12390]. In the single-round protocols from knowledge assumptions, soundness is reduced to adaptive hard-core bits together with extractability of weak-image or image-test branches [2405.15736].

The efficient-versus-inefficient verifier distinction leads to different minimal assumptions. IV-PoQ can be built from one-way functions via statistically hiding, computationally binding bit commitments [2302.04749]. Quantum advantage can also be based on meta-complexity: weakly-classical-average-hard GapK implies classical-average-hard QPE, which implies the QAS/OWF condition and therefore the existence of IV-PoQ [2410.01369]. In that framework IV-PoQ are explicitly described as a generalization of standard PoQ, and they encompass both sampling-based and search-based quantum advantage [2410.01369]. This suggests that allowing offline, inefficient verification substantially broadens the assumption base.

Lower-bound work sharpens the picture by identifying cryptographic hardness that must underlie various PoQ variants. Arbitrary-round IV-PoQ with black-box reduction to a quantum-secure falsifiable assumption imply quantum-secure one-way puzzles [2510.05082]. Constant-round efficiently verifiable PoQ either collapse to “trivial” two-round PoQ or imply quantum-secure one-way functions or weak unclonability primitives such as weak minischemes or signature-token analogues [2510.05082]. Three-message IV-PoQ whose soundness is proved by a black-box reduction to a quantum-secure falsifiable assumption are ruled out [2510.05082]. For public-coin constant-round PoQ, the same work argues that they imply weak forms of quantum money or quantum lightning, providing an explanation for the difficulty of building publicly verifiable PoQ and related protocols from lattices [2510.05082].

The bounded-memory papers replace computational hardness entirely by time-space or storage lower bounds. The first memory-bounded PoQ uses Raz’s lower bound for parity learning in small space to show that any classical adversary with memory below \(n^2/20\) cannot recover the hidden parity vector and therefore cannot emulate the prover’s CHSH-style correlations [2505.23978]. The second uses interactive hashing and bounded-storage arguments, together with a plug-in lemma for quantum memory, to show that a limited-memory adversary retains insufficient information about many streamed bits to reconstruct both “claw” values [2505.23978]. In an even more restrictive regime, unconditional PoQ between classical and quantum small-space machines are obtained by using sub-\(\log\log n\) space lower bounds of Dwork–Stockmeyer and Freivalds–Karpinski together with constant-space quantum algorithms for padded separation problems [2412.02662].

## 5. Qubit certification, contextuality, and temporal formulations

An important development is that some PoQ protocols certify more than “non-classicality.” A broad class of simple two-challenge PoQ protocols can be abstracted into a template where the verifier’s final check is determined by a transcript \(T\), private randomness \(R_V\), a one-bit challenge \(m\), and two projectors \(Q_0,Q_1\). The paper then defines observables \(S_0=2Q_0-I\) and \(S_1=2Q_1-I\) and shows that near-optimal quantum success forces approximate anti-commutation:
\[
\langle\psi_T|\{S_0,S_1\}^2|\psi_T\rangle = O(\varepsilon+\sqrt{s(\lambda,\kappa)}).
\]
Hence protocols of this kind certify that the prover holds a qubit and performs approximately Pauli \(Z\) and \(X\) measurements on it [2303.01293]. This result applies to recent “simple” PoQ proposals such as Kahanamoku-Meyer et al. and Kalai et al., and it proves a tight quantum soundness upper bound of \(\cos^2(\pi/8)\), where earlier works only gave lower bounds for honest quantum strategies and upper bounds for classical ones [2303.01293].

Contextuality is the natural conceptual bridge between Bell-type PoQ and single-device tests. The 2024 contextuality paper defines a contextuality game via a question set \(Q\), answer alphabet \(A\), a family of compatible contexts \(\mathbf{C}^{\mathrm{all}}\), a distribution over contexts, and a predicate \(\mathrm{pred}\). Non-contextual strategies correspond to a joint distribution over fixed answers \(a_q\) to all questions, while quantum strategies are determined by commuting observables \(\mathbf{O}[q]\) measured on a state \(|\psi\rangle\) [2405.06787]. By encrypting one question under QFHE and later revealing a combined Pauli key through an oblivious Pauli pad, the compiler forces “temporal separation” between the first and second measurements and obtains a computational contextuality test for a single device [2405.06787]. This suggests that cryptography can replace spatial separation in Bell tests and compatibility assumptions in contextuality tests by computational restrictions on information flow.

Temporal PoQ appear in an even more foundational sense in the single-shot temporal-measurement paper. There the system is a single qubit with Hamiltonian
\[
H=\frac{\hbar\omega}{2}\sigma_z,
\]
and Heisenberg evolution
\[
\sigma_x(t)=\sigma_x\cos(\omega t)-\sigma_y\sin(\omega t),\quad
\sigma_y(t)=\sigma_y\cos(\omega t)+\sigma_x\sin(\omega t),\quad
\sigma_z(t)=\sigma_z.
\]
For \(\omega t_1=0\) and \(\omega t_2=\pi/2\), the composite temporal observables
\[
O_1=\sigma_x(t_2)\sigma_y(t_1),\quad
O_2=\sigma_y(t_2)\sigma_x(t_1),\quad
O_3=\sigma_z(t_2)\sigma_z(t_1)
\]
satisfy the state-independent eigenvalue relations
\[
O_1|\phi\rangle=-|\phi\rangle,\quad O_2|\phi\rangle=+|\phi\rangle,\quad O_3|\phi\rangle=+|\phi\rangle
\]
for any state \(|\phi\rangle\) [2206.02581]. Under predetermined values \(m_x^{(1)},m_y^{(1)},m_x^{(2)},m_y^{(2)}\in\{\pm 1\}\), the corresponding hidden-variable equations
\[
m_x^{(2)}m_y^{(1)}=-1,\quad
m_y^{(2)}m_x^{(1)}=+1,\quad
m_x^{(2)}m_y^{(2)}m_y^{(1)}m_x^{(1)}=+1
\]
multiply to a contradiction because the left-hand side product is \(+1\) while the quantum right-hand sides multiply to \(-1\) [2206.02581]. The protocol is therefore a single-shot, inequality-free proof of certified quantumness in time, though strongly device-dependent [2206.02581].

## 6. Applications, generalizations, and limitations

PoQ serve as entry points to stronger verification and cryptographic tasks. The “Simple Tests of Quantumness Also Certify Qubits” result explicitly positions qubit certification as a building block for certifiable randomness and classical delegation of quantum computation [2303.01293]. The contextuality compiler is presented as a route from any contextuality game with \(\omega_{\mathrm{Qu}}>\omega_{\mathrm{NC}}\) to a single-device computational test, and the authors note that the same ideas might extend to generalized contextuality or other quantum resources [2405.06787]. The multi-prover quantum-knowledge protocol goes further still: in a classical-verifier, two-prover setting for XZ-local Hamiltonian, successful play not only proves “quantumness” but allows an extractor, with oracle access to the provers’ observables, to reconstruct a low-energy witness state, thereby yielding a new level of verification for a proof of quantumness [2503.13699].

PoQM enlarge the scope from one-shot quantum capability to persistent quantum storage. One construction uses 1-of-\(2^k\) puzzles to obtain a four-round \((1-\mathrm{negl},\mathrm{negl},m_1,m_2)\)-PoQM under subexponential hardness of LWE for any polynomially bounded \(m_2\) [2510.04159]. Another uses verifiable remote state preparation of BB84 states to produce polynomial-round \((1-\mathrm{negl},1/p,\lfloor 9.1\,m_2\rfloor,m_2)\)-PoQM under polynomial LWE hardness [2510.04159]. Those constructions imply one-way puzzles, and an extractable version implies QCCC key exchange [2510.04159]. A plausible implication is that certifying persistent memory reveals stronger cryptographic structure than standard PoQ.

Several limitations recur. Many cryptographic PoQ are only sound against classical PPT provers, not malicious quantum adversaries [2208.12390], [2405.15736], [2405.06787]. Random-oracle protocols simplify interaction but move security out of the plain model [2005.04826], [2405.06787]. Device-independent security is usually absent; the temporal single-shot protocol is explicitly “strongly device-dependent” and assumes the correct Hilbert space, Hamiltonian, observables, and projective measurement model [2206.02581]. Robustness is often underdeveloped: the temporal proof has no quantitative noise threshold [2206.02581], and even some elegant memory-bounded protocols are mainly asymptotic [2505.23978]. Constant-round and public-coin variants appear to require stronger primitives such as weak money-like unclonability [2510.05082]. Finally, the existence of efficient-verifier PoQ from the weakest standard assumptions remains open, while 3-message IV-PoQ with black-box reduction to quantum-secure falsifiable assumptions are ruled out [2510.05082].

Taken together, these works show that “proofs of quantumness” is no longer a single protocol paradigm but a hierarchy of verification notions. At one end are foundational, inequality-free temporal contradictions [2206.02581]; at another are cryptographic challenge–response protocols grounded in trapdoor or commitment primitives [2005.04826], [2208.12390], [2405.15736]; alongside them sit contextuality compilers [2405.06787], inefficient-verifier formulations tied to one-way functions or meta-complexity [2302.04749], [2410.01369], memory-certification protocols [2510.04159], and unconditional bounded-memory or tiny-space protocols [2505.23978], [2412.02662]. The common theme is the same: extracting operational evidence of quantum capability from a classical interface. The main divergences concern what exactly is certified—mere non-classicality, a qubit, a witness state, persistent memory, contextuality, or temporal nonclassicality—and what hardness, trust, or resource assumptions are required to make that certification rigorous.

Source: https://www.emergentmind.com/topics/proofs-of-quantumness-poq