---
title: 'Pseudorandom Quantum States: Concepts & Constructions'
url: https://www.emergentmind.com/topics/pseudorandom-quantum-states-prs
type: topic
---

# Pseudorandom Quantum States: Concepts & Constructions

Searching arXiv for recent papers on pseudorandom quantum states and closely related notions.
Pseudorandom quantum states (PRS) are keyed families of efficiently generable pure quantum states that are computationally indistinguishable from Haar-random pure states even when a distinguisher receives polynomially many identical copies. Introduced by Ji, Liu, and Song and used throughout subsequent work, PRS occupy a central place in quantum cryptography as quantum analogues of classical pseudorandom generators, while exhibiting structural features with no direct classical counterpart. Recent work has broadened the theory in several directions: scalable constructions in which the security parameter is decoupled from output length [2004.01976], function-like and adaptive variants [2507.22535], mixed-state generalizations via pseudorandom density matrices [2407.11607], stronger scrambling notions acting on arbitrary inputs [2309.08941], and black-box separation results clarifying the limits of shrinking, stretching, and deriving classical pseudorandom generators from PRS [2402.13324], [2606.24736], [2510.20131].

## 1. Definition and basic model

The standard PRS notion used across the literature is a keyed family of \(n\)-qubit pure states \(\{|\phi_k\rangle\}_{k\in K}\) such that two conditions hold. First, there is an efficient quantum algorithm \(G\) that, on input the key \(k\), outputs \(|\phi_k\rangle\). Second, for any polynomial \(t\) and any quantum polynomial-time distinguisher \(A\), the ensembles \(\{|\phi_k\rangle^{\otimes t}\}\) and \(\{|\psi\rangle^{\otimes t}\}_{|\psi\rangle\sim \mu}\), where \(\mu\) is Haar measure on the relevant Hilbert space, are computationally indistinguishable [2309.08941], [2407.11607], [2510.20131], [2402.13324], [2110.11724].

A representative formal expression is
\[
\left|
\Pr_{k\gets K}[A(|\phi_k\rangle^{\otimes \ell})=1]
-
\Pr_{|\psi\rangle\gets \mu}[A(|\psi\rangle^{\otimes \ell})=1]
\right|
\le \mathrm{negl}(\lambda),
\]
with \(\ell(\lambda)\) polynomial in the security parameter \(\lambda\) [2309.08941]. Equivalent formulations appear with \(n\) rather than \(\lambda\) as the main asymptotic variable [2407.11607], [2402.13324].

This definition is intrinsically multi-copy. The distinguisher is allowed polynomially many identical copies because a single quantum state cannot, in general, be cloned. That feature sharply distinguishes PRS from classical pseudorandom generators: the quantum notion is explicitly parameterized by copy complexity rather than by a single output string [2402.13324], [2606.24736].

A weaker notion, single-copy pseudorandom states or \(1\)-PRS, requires security only for \(t=1\), together with an output-length stretch condition \(m(n)>n\) so that trivial encodings do not qualify [2606.24736]. Recent work shows that any \(1\)-PRS can be amplified to \(t\)-copy security for any polynomial \(t\) without additional assumptions, yielding generic number-of-copies amplification [2606.29325]. This suggests that polynomial-copy security is not, at the level of existence, strictly stronger than single-copy security, although black-box limits still arise for other transformations such as stretching output length [2606.24736].

## 2. Constructions and scalable pseudorandomness

A standard construction paradigm first proves a statistical statement relative to a truly random classical function and then replaces that function by a quantum-secure pseudorandom function. Earlier constructions randomized phases only, but scalable PRS required a different mechanism: randomizing amplitudes as well as phases [2004.01976].

The paper “Scalable Pseudorandom Quantum States” shows that any quantum-secure one-way function implies scalable PRS [2004.01976]. Its central oracle-level construction produces asymptotically random states by sampling approximate complex Gaussian amplitudes, using the fact that a normalized complex Gaussian vector is Haar-distributed. The resulting trace-distance bound between \(t\) copies of the oracle construction and \(t\) copies of a Haar-random state is
\[
(t+8)e^{-\lambda} + \bigl(5\sqrt{t} + \lambda +1\bigr)2^{-\lambda} + 2\bigl(\tfrac{8}{10}\bigr)^\lambda,
\]
which is negligible in \(\lambda\) for polynomial \(t\) [2004.01976]. Replacing the random function with a quantum-secure PRF yields scalable computational PRS under post-quantum one-way functions [2004.01976].

A later construction gives a new isometric method for scalable PRS and, from it, the first scalable and quantum-accessible adaptive pseudorandom function-like quantum state generators (PRFS) under quantum-secure one-way functions [2507.22535]. The construction is notable for introducing no entanglement or correlations with the environment, which is especially useful for adaptive function-like variants.

Subset-state constructions show that relative phases are not necessary for state pseudorandomness. Two independent 2023 papers prove that random subset states—equal superpositions over randomly chosen subsets of computational basis states—are information-theoretically indistinguishable from Haar-random states in an intermediate regime of subset sizes [2312.15285], [2312.09206]. In one formulation, if \(d=2^n\), \(k=\mathrm{poly}(n)\), and the subset size \(s\) satisfies
\[
s=\omega(\mathrm{poly}(n))
\quad\text{and}\quad
s=\frac{2^n}{\omega(\mathrm{poly}(n))},
\]
then
\[
\left\|
\int \psi^{\otimes k} d\mu(\psi)
-
\mathbb{E}_{S:|S|=s}\phi_S^{\otimes k}
\right\|_1
\le
O\!\left(\frac{k^2}{d} + \frac{k}{\sqrt{s}} + \frac{s k}{d}\right),
\]
so the ensembles are statistically close for polynomially many copies [2312.15285]. With a quantum-secure pseudorandom permutation, this yields an efficiently generable PRS family [2312.15285]. This resolves a conjecture of Ji, Liu, and Song and shows that state pseudorandomness does not require random phases [2312.15285], [2312.09206].

## 3. Variants: scramblers, function-like generators, and mixed-state generalizations

A major strengthening of the original generator notion is the pseudorandom state scrambler (PRSS). Whereas a standard pseudorandom state generator maps a fixed initial state, usually \(|0^n\rangle\), to a pseudorandom output, a PRSS is a keyed family of isometries \(S_k\) such that for every fixed input pure state \(|\phi\rangle\), the outputs \(S_k|\phi\rangle\) are pseudorandom against polynomially many copies [2309.08941]. This remedies a limitation of earlier PRSG constructions, which can fail badly on inputs other than the designated initial state [2309.08941].

The information-theoretic core of PRSS is built from a parallel version of Kac’s walk. On a space of dimension \(N=2^n\), the parallel walk mixes in total variation in \(O(\log N)\) steps rather than the \(\Theta(N\log N)\) behavior of the standard walk, making polynomial-size implementations possible [2309.08941]. The resulting random scrambler also has a dispersing property: for every input, the set of outputs over keys forms a negligible-\(\epsilon\)-net of the sphere [2309.08941]. This is substantially stronger than what standard PRS generators guarantee.

The mixed-state extension is pseudorandom density matrices (PRDMs). A PRDM family \(\{\rho_{k,m}\}\) is efficiently generable and computationally indistinguishable from the \((n,m)\) generalized Hilbert–Schmidt ensemble
\[
\eta_{n,m}
=
\left\{\operatorname{Tr}_m(|\psi\rangle\langle\psi|)\right\}_{|\psi\rangle\sim \mu_{n+m}},
\]
obtained by tracing out \(m\) qubits from Haar-random \((n+m)\)-qubit pure states [2407.11607]. When \(m=0\), PRDMs reduce exactly to standard PRS [2407.11607]. For \(m=\omega(\log n)\), the GHSE is statistically indistinguishable from the maximally mixed state on polynomially many copies, since
\[
\operatorname{TD}\!\left(
\mathbb{E}_{\rho\leftarrow \eta_{n,m}}[\rho^{\otimes t}],
\;
(I_n/2^n)^{\otimes t}
\right)
=
O\!\left(\frac{t^2}{2^m}\right),
\]
and hence PRDMs in this regime are computationally indistinguishable from maximally mixed as well [2407.11607].

The same paper also introduces memoryless PRS, a restricted-adversary notion in which the distinguisher receives copies one at a time, may perform adaptive POVMs, but has no persistent quantum memory between copies [2407.11607]. Standard PRS imply memoryless PRS, but the converse fails: there exist single-copy PRS-like constructions that are not memoryless PRS because coherence tests can distinguish them without quantum memory [2407.11607]. This restricted model supports stronger noise robustness statements than the unrestricted pure-state notion.

## 4. Resource-theoretic structure and hidden resources

PRS have strong connections to quantum resource theory because Haar-random states typically exhibit near-maximal entanglement, coherence, and magic. A recurring question is whether pseudorandom families must share those resource profiles, or whether low-resource ensembles can computationally masquerade as high-resource ones.

Subset-state constructions demonstrate pseudoentanglement directly. Since a subset state \(|S\rangle\) has Schmidt rank at most \(|S|\) across any bipartition, its entanglement entropy across any cut is at most \(\log |S|\). Choosing \(|S|=2^{h(n)}\) with \(h(n)\) superlogarithmic but sublinear yields PRS families with entanglement entropy at most \(h(n)\) across every cut, yet still pseudorandom against polynomial-time distinguishers [2312.15285]. The same constructions also yield low-entanglement ensembles that are statistically close to Haar for polynomially many copies in the appropriate parameter regime [2312.09206], [2312.15285].

The paper “Pseudorandom unitaries are neither real nor sparse nor noise-robust” develops a broader “pseudoresource” framework [2306.11677]. For PRS, it establishes lower bounds on coherence and purity while showing that imaginarity behaves differently. PRS must have relative entropy of coherence \(\mathcal{C}=\omega(\log n)\), and sparse states with only \(\mathrm{poly}(n)\) support in the computational basis cannot be pseudorandom [2306.11677]. By contrast, imaginarity of pure states is hard to test efficiently, and therefore PRS can assume any value of imaginarity; there exist both real PRS and highly imaginary PRS [2306.11677].

This leads to pseudoimaginarity: a low-imaginarity ensemble, even an exactly real one, can masquerade as an ensemble with nearly maximal imaginarity [2306.11677]. The paper classifies purity, coherence, entanglement, magic, and imaginarity into distinct pseudoresource regimes, with purity admitting only an exponentially small gap while imaginarity admits an essentially maximal one [2306.11677].

PRDMs sharpen these observations for mixed states. The generalized Hilbert–Schmidt ensemble has near-maximal magic, coherence, and entanglement with overwhelming probability. Specifically, for \(\rho\leftarrow \eta_{n,m}\),
\[
\mathrm{LR}(\rho) \ge n-m-2\log(n+m)-1,
\qquad
C(\rho)\ge n-m-1,
\]
and logarithmic negativity across a bipartition is also \(\Theta(n)\) in the relevant regime [2407.11607]. Yet for \(m=\omega(\log n)\), the ensemble is statistically close to maximally mixed, which has zero entanglement, zero coherence, and zero magic. This produces a pseudoresource gap of \(\Theta(n)\) versus \(0\) for magic and coherence when PRDMs are instantiated via binary-phase PRS and partial trace [2407.11607]. A plausible implication is that mixed-state pseudorandomness creates stronger hidden-resource phenomena than the pure-state theory alone.

## 5. Noise, robustness, and adversary restrictions

Noise robustness is a point of sharp divergence between pure-state PRS and mixed-state generalizations. Standard PRS are extremely fragile under depolarizing or other unital noise, because purity changes are efficiently detectable. The paper “Pseudorandom unitaries are neither real nor sparse nor noise-robust” proves that PRS and PRU can exist only if the probability that an error occurs is negligible, ruling out their generation on noisy intermediate-scale and early fault-tolerant quantum computers [2306.11677]. The key test is the SWAP test, whose acceptance probability on two copies is
\[
\Pr_{\mathrm{SWAP}}(\rho)
=
\frac12 + \frac12 \operatorname{tr}(\rho^2),
\]
so any non-negligible purity loss becomes efficiently visible [2306.11677].

The mixed-state theory changes this conclusion. A PRDM ensemble is called noise-robust to a channel \(\Gamma\) if \(\{\Gamma(\rho_k)\}\) remains a PRDM [2407.11607]. For non-negligible purity, such as \(m=O(\log n)\), PRDMs are not robust to unital noise because purity changes remain detectable. But for \(m=\omega(\log n)\), PRDMs are robust to any efficiently implementable unital channel [2407.11607]. The reason is structural: in this regime PRDMs are already computationally indistinguishable from the maximally mixed state, and unital channels fix the maximally mixed state.

The same paper shows that this regime resists a strong attack due to Kretschmer that combines classical shadows with a \(\mathsf{PostBQP}\) oracle. For large-\(m\) PRDMs, the purity \(\operatorname{tr}(\rho_k^2)\) is negligible, so estimating it requires a superpolynomial number of copies [2407.11607]. This separates mixed-state pseudorandomness from standard PRS even against nonphysical distinguishers.

Memoryless PRS provide a restricted pure-state route to noise robustness. In the no-quantum-memory model, distinguishing noisy PRS from Haar-random states under unital noise requires a superpolynomial number of copies [2407.11607]. This suggests that realistic limitations on adversarial quantum memory partially restore noise tolerance for pure-state pseudorandomness, though only in a restricted security model.

An experimental paper on “Generation of Pseudo-Random Quantum States on Actual Quantum Processors” uses a different, non-cryptographic notion of pseudorandomness, defined through agreement with Haar entanglement statistics rather than computational indistinguishability [2302.04101]. It reports that generating highly entangled Haar-like states on current hardware is strongly limited by connectivity and SPAM errors, with IonQ Harmony outperforming IBM ibm_lagos despite lower two-qubit gate fidelity because of all-to-all connectivity and better SPAM [2302.04101]. This empirical notion is distinct from cryptographic PRS, but it reinforces the broader point that actual hardware noise and architecture matter sharply for random-state generation.

## 6. Cryptographic applications and structural limitations

PRS support a growing collection of cryptographic primitives. They underlie quantum money, commitments, and related tasks in the Ji–Liu–Song framework, and scalable PRS broaden the usable parameter regime [2004.01976]. PRS are also linked to hardware assumptions: efficient PRS are sufficient to construct the challenge set for universally unforgeable quantum physical unclonable functions, improving earlier constructions that required Haar-random states [2110.11724]. The same work shows that practical unknownness or strong uniqueness assumptions on qPUFs imply pseudorandom unitaries, which in turn imply PRS via \(U_k|0\rangle\) [2110.11724].

PRSS yield further applications. Because they scramble arbitrary inputs rather than only a fixed initial state, they subsume standard PRSGs, scalable PRSGs, and PRF-like state generators [2309.08941]. They also give streamlined constructions of quantum encryption and succinct quantum state commitments in regimes where prior PRSG-based constructions required postselection or multiple copies [2309.08941].

PRDMs support additional primitives not available from pure-state pseudorandomness alone. They yield EFI pairs, a fundamental cryptographic primitive, in a form robust to mixed-unitary noise, including local depolarizing noise with substantial strength [2407.11607]. They also provide noise-robust quantum money in the sense that the Ji–Liu–Song private-key scheme remains secure when honest banknotes undergo a noise channel \(\Gamma\) satisfying
\[
\operatorname{Tr}(\rho_k \Gamma(\rho_k)) > 1-\epsilon
\quad\text{for all }k,
\]
with \(\epsilon\le 1/3\) [2407.11607].

At the same time, several black-box limitations have become clear. PRS cannot be shrunk from polynomial output length to logarithmic output length in a black-box way: relative to Kretschmer’s oracle, long PRS exist but short PRS do not [2402.13324]. Conversely, recent work on stretching shows the first black-box separation between short-stretch and longer-stretch \(1\)-PRS: relative to a quantum oracle, \(1\)-PRS with output length \(1.1n\) exist, but \(1\)-PRS with output length \(\Omega(n^{2+\varepsilon})\) do not [2606.24736]. Another 2025 result establishes a black-box separation between quantum-evaluable pseudorandom generators and both logarithmic and linear PRS, ruling out black-box derivations of PRGs from PRS in a unitary-oracle model with inverse access [2510.20131]. Taken together, these results indicate that output length, copy security, and relation to classical pseudorandomness are all structurally nontrivial for PRS.

## 7. Conceptual distinctions and current picture

Several distinctions have emerged as central. First, PRS, PRSS, and PRU are genuinely different notions. PRU imply PRSS, and PRSS imply standard PRSG behavior on fixed input, but the converses fail. In particular, real-valued PRSS exist, while PRU require imaginarity and cannot be real [2309.08941], [2306.11677].

Second, state pseudorandomness and unitary pseudorandomness impose different resource requirements. The paper on resource constraints proves that PRU require near-maximal imaginarity, while PRS do not have that restriction [2306.11677]. This establishes a qualitative gap: complex-valued formalism is operationally necessary for pseudorandom unitaries but not for pseudorandom states.

Third, mixed-state pseudorandomness appears to be the appropriate notion for robustness under strong noise. Standard PRS are too brittle under unital noise, whereas PRDMs with \(m=\omega(\log n)\) remain pseudorandom under arbitrary efficiently implementable unital channels and can even be computationally indistinguishable from the maximally mixed state while hiding extensive entanglement, magic, and coherence [2407.11607].

Fourth, resource-theoretic hardness results show that arbitrary mixed-state resource testing is severely limited. For \(Q\in\{E,\mathrm{LR},C\}\), any tester distinguishing \(Q(\rho)=0\) from \(Q(\rho)=\Theta(n)\) requires superpolynomially many copies in the negligible-purity regime [2407.11607]. Black-box resource distillation under the same conditions also requires superpolynomially many copies [2407.11607]. This suggests that pseudorandom mixed states are not merely cryptographic objects; they expose fundamental bounds on what quantum resources can be efficiently certified or distilled from unknown inputs.

A plausible synthesis is that PRS now sit within a broader hierarchy of quantum pseudorandom objects: fixed-input state generators, arbitrary-input scramblers, function-like state generators, mixed-state ensembles, and pseudorandom unitaries. The recent literature has clarified that these notions differ in adversary model, noise tolerance, resource requirements, and black-box power, rather than forming a single monotone ladder.

As of the current state of the literature, PRS are best understood not as a single primitive but as a family of closely related notions whose behavior depends critically on output length, copy security, adversary memory, whether the object is state-like or channel-like, and whether one allows mixed states. That perspective unifies the central developments: scalable constructions [2004.01976], arbitrary-input scrambling [2309.08941], mixed-state generalization [2407.11607], subset-state and pseudoresource phenomena [2312.15285], [2312.09206], and the recent separation results delimiting what PRS can and cannot generically do [2402.13324], [2606.24736], [2510.20131].

Source: https://www.emergentmind.com/topics/pseudorandom-quantum-states-prs