---
title: Quantum Local Differential Privacy Overview
url: https://www.emergentmind.com/topics/quantum-local-differential-privacy-qldp
type: topic
---

# Quantum Local Differential Privacy Overview

Quantum local differential privacy (QLDP) is the quantum analogue of classical local differential privacy, formulated for mechanisms that release quantum states or act as quantum channels and are required to make the released information difficult to distinguish across possible inputs under **every** allowed measurement. Across the literature, QLDP appears in several closely related forms: as a semidefinite-order condition on families of density operators, as a measurement-based channel inequality over all input pairs, and as an equivalent divergence constraint involving the quantum hockey-stick divergence or smooth max-relative entropy. A recurring theme is that QLDP reduces to classical LDP when the relevant output states commute, while genuinely nonclassical phenomena emerge once the protected alphabet or state family is sufficiently rich [2011.09960].

## 1. Formal definitions and equivalent formulations

One early formulation treats local privacy as a property of a family of outputs indexed by a classical input alphabet. For an \(n\)-tuple of probability vectors \((p_i)_{i=1}^n\), classical \(\varepsilon\)-DP is the entrywise condition
\[
p_i \le e^\varepsilon p_j \qquad \text{for all } i,j=1,\dots,n.
\]
Its classical-quantum extension replaces probability vectors by density matrices \((\rho_i)_{i=1}^n\) and requires
\[
\rho_i \le e^\varepsilon \rho_j \qquad \text{for all } i,j=1,\dots,n,
\]
equivalently \(e^\varepsilon \rho_j-\rho_i \succeq 0\). In this model, the input is classical and the released object is quantum, so privacy is enforced at the level of a classical-to-quantum mechanism [2011.09960].

A channel-based formulation, used widely in later work, defines a quantum channel \(\mathcal N\) to be \((\varepsilon,\delta)\)-locally differentially private if for every POVM \(\mathcal M=\{\mathcal M_x\}_{x\in\mathcal X}\), every pair of input states \(\rho,\sigma\), and every outcome \(x\),
\[
\operatorname{Tr}[\mathcal M_x \mathcal N(\rho)] \le e^\varepsilon \operatorname{Tr}[\mathcal M_x \mathcal N(\sigma)] + \delta.
\]
The pure case is \(\delta=0\). For POVMs themselves, the same condition yields the notion of \((\varepsilon,\delta)\)-trivial or near-trivial measurements. In this form, QLDP means that no downstream measurement can distinguish inputs beyond the prescribed multiplicative-additive bound [2203.03591].

Several papers replace the universal measurement quantifier by a state-based divergence criterion. Using the quantum hockey-stick divergence
\[
E_\gamma(\rho\|\sigma)=\operatorname{Tr}[(\rho-\gamma \sigma)^+],
\]
one has
\[
\mathcal N \text{ is }(\varepsilon,\delta)\text{-LDP}
\iff
\forall \rho,\sigma:\ E_{e^\varepsilon}(\mathcal N(\rho)\|\mathcal N(\sigma))\le \delta,
\]
and equivalently
\[
\forall \rho,\sigma:\ D_{\max}^{\delta}(\mathcal N(\rho)\|\mathcal N(\sigma))\le \varepsilon.
\]
This reformulation makes privacy a property of output states alone, without checking every POVM explicitly. The same framework also yields a quantum analogue of Rényi differential privacy and a hypothesis-testing interpretation of privacy regions [2202.10717].

The literature does not use a single neighboring relation. Some works take the supremum over **all** input-state pairs, which is the direct quantum counterpart of local DP. Others parameterize neighborhood structure more finely. A unifying framework introduces \((\Xi,\tau)\)-neighboring states via equality of suitable marginals together with a trace-distance bound, thereby subsuming both bounded-trace-distance and local-measurement-style notions [2307.04733]. This suggests that QLDP is best viewed as a family of closely related local privacy models rather than a single fixed definition.

## 2. Classical completeness, essential classicality, and genuine quantum separation

A central structural question is whether quantum locally private mechanisms are genuinely more expressive than classical ones, or merely classical mechanisms re-encoded by quantum channels. To formalize this, the set \(\mathrm{EC}_n(\varepsilon)\) of **essentially classical** mechanisms is defined inside \(\mathrm{CQ}_n(\varepsilon)\): a CQ-private tuple \((\rho_i)_{i=1}^n\) is essentially classical if there exist a classical \(\varepsilon\)-DP tuple \((p_i)_{i=1}^n\in \mathrm C_n(\varepsilon)\) and a CPTP map \(\Lambda\) such that
\[
\Lambda(\operatorname{diag}(p_i))=\rho_i \qquad \text{for all } i.
\]
Equivalently,
\[
\mathrm{EC}_n(\varepsilon)
=
\left\{
\left(\sum_k p_i(k)\sigma_k\right)_{i=1}^n
:
(p_i)_{i=1}^n\in \mathrm C_n(\varepsilon),\ \sigma_k \text{ density matrices}
\right\}.
\]
In this characterization, the privacy-relevant structure is already classical, and the quantum layer acts only as a re-encoding map [2011.09960].

The sharp separation result is dimension-free in the input alphabet size. For binary private data,
\[
\mathrm{EC}_2(\varepsilon)=\mathrm{CQ}_2(\varepsilon),
\]
so every CQ-private binary mechanism is essentially classical. For every \(n\ge 3\),
\[
\mathrm{EC}_n(\varepsilon)\neq \mathrm{CQ}_n(\varepsilon),
\]
showing that genuinely quantum locally private mechanisms exist as soon as the input alphabet has size at least three. The same work gives an operational witness of this strict inclusion using the objective
\[
\Phi(\rho_1,\dots,\rho_n)=\min_{i\ne j} J_\theta(\rho_i,\rho_j),
\]
where \(J_\theta\) is the RLD Fisher information for the pair \((\rho_i,\rho_j)\), and proves
\[
M_n^{EC}(;J_\theta)=M_n^C(;J_\theta)<M_n^{CQ}(;J_\theta)
\qquad \text{for all } n\ge 3.
\]
Thus, the gap is not only representational but also utility-relevant [2011.09960].

This binary-versus-\(n\)-ary dichotomy has become a recurrent organizing principle in QLDP. A plausible implication is that commutative structure is effectively exhaustive only in the smallest alphabet case, while noncommutativity becomes operationally visible once the local mechanism must protect three or more alternatives.

## 3. Optimal mechanisms and privacy-utility trade-offs

A substantial algorithmic line of work asks, for a fixed quantum mechanism \(\mathcal E\), what is the smallest privacy budget it satisfies. One formulation defines the optimal QLDP value by
\[
\epsilon^*(\mathcal E)=
\max_{0\le M\le I}
\ln
\frac{\lambda_{\max}[\mathcal E^\dagger(M)]}
{\lambda_{\min}[\mathcal E^\dagger(M)]},
\]
with a reduction to pure states,
\[
\epsilon^*(\mathcal E)=
\max_{|\psi\rangle}
\ln
\frac{\lambda_{\max}[\mathcal E^\dagger(\psi)]}
{\lambda_{\min}[\mathcal E^\dagger(\psi)]}.
\]
If \(\lambda_{\min}[\mathcal E^\dagger(\psi)]=0\) for some \(\psi\), then \(\epsilon^*(\mathcal E)=\infty\). Finite QLDP is characterized by strict positivity of the Choi matrix of the dual map or, equivalently, by the linear span of the adjoint Kraus operators covering the full matrix space [2407.13516].

Within the class of unital mechanisms, quantum depolarizing noise plays the role classically occupied by randomized response. For \(n\) qubits,
\[
\mathcal N_{\mathrm{Dep}}^n(\rho)=p\rho+(1-p)\frac{I}{2^n},\qquad 0\le p<1.
\]
It is identified as the optimal unital privatization mechanism, simultaneously optimizing fidelity utility and anti-trace-distance utility under a fixed QLDP level:
\[
F(\mathcal E)\le \frac{e^\epsilon}{e^\epsilon+2^n-1},
\qquad
\hat T(\mathcal E)\le \frac{e^\epsilon}{e^\epsilon+2^n-1},
\]
with equality achieved by a depolarizing-like family. The same work proves an additive composition theorem:
\[
\mathcal E_1\otimes \mathcal E_2 \text{ is }(\epsilon_1+\epsilon_2)\text{-QLDP},
\]
and more generally \(\bigotimes_k \mathcal E_k\) is \((\sum_k \epsilon_k)\)-QLDP, including distributed systems with entangled states [2407.13516].

In the high-privacy regime \(\epsilon\to 0^+\), the optimization theory becomes asymptotic and strikingly universal. For a broad class of utilities whose quantum second-order expansion is governed by a normalized Petz monotone metric, the classical and quantum optima satisfy
\[
OPT_n(\epsilon;\Phi_C)
=
\phi(\mathbf 1_n)
+
\frac{\lfloor n/2\rfloor\lceil n/2\rceil}{n-1}\cdot \frac{\beta_0}{2}\,\epsilon^2
+
o(\epsilon^2),
\]
\[
OPT_n(\epsilon;\Phi_Q)
=
\phi(\mathbf 1_n)
+
\frac{\beta_0 n}{4}\,\epsilon^2
+
o(\epsilon^2).
\]
Hence,
\[
\lim_{\epsilon\to 0^+}\frac{Q}{C}
=
\frac{n(n-1)}{2\lfloor n/2\rfloor\lceil n/2\rceil}
\ge \frac{3}{2}
\qquad (n\ge 3).
\]
The classical optimum is achieved asymptotically by the **binary mechanism**, whereas the quantum optimum is achieved by an **isoclinic mechanism** built from an equi-isoclinic tight fusion frame. This same ratio appears for Holevo information, symmetric hypothesis-testing exponents, and asymmetric hypothesis-testing exponents [2605.27278].

Taken together, these results establish two complementary facts. First, depolarization is a canonical and often optimal privatization primitive in the unital setting. Second, in the high-privacy regime, optimal quantum mechanisms can outperform classical ones by a universal factor that depends only on the input alphabet size.

## 4. Contraction of distinguishability and private hypothesis testing

QLDP can be interpreted as a contraction principle: privacy forces channels to suppress distinguishability. One strong data-processing line proves that if \(\mathcal N\) is \(\varepsilon\)-LDP, then
\[
D(\mathcal N(\rho)\|\mathcal N(\sigma))
+
D(\mathcal N(\sigma)\|\mathcal N(\rho))
\le
2(1-e^{-\varepsilon})\|\rho-\sigma\|_1,
\]
and, for \(\varepsilon\)-LDP POVMs,
\[
D(\mathcal M(\rho)\|\mathcal M(\sigma))
+
D(\mathcal M(\sigma)\|\mathcal M(\rho))
\le
e^\varepsilon(1-e^{-\varepsilon})^2 \|\rho-\sigma\|_1^2.
\]
The same framework derives private analogues of Stein-type bounds for asymmetric hypothesis testing under restricted measurements, making the type-II error exponent explicitly privacy-limited [2203.03591].

A later treatment sharpens this contraction picture by characterizing the exact privatized contraction coefficient for trace distance. For \(\varepsilon\)-QLDP channels,
\[
\eta_T^\varepsilon
=
\frac{e^\varepsilon-1}{e^\varepsilon+1},
\]
and for \((\varepsilon,\delta)\)-QLDP,
\[
\eta_T^{\varepsilon,\delta}
=
\frac{e^\varepsilon-1+2\delta}{e^\varepsilon+1}.
\]
Using the hockey-stick divergence machinery, the same work obtains
\[
[d_B(\mathcal A(\rho),\mathcal A(\sigma))]^2
\le
2\,\frac{(e^{\varepsilon/2}-1)^2}{e^\varepsilon+1}\,T(\rho,\sigma),
\]
and
\[
D(\mathcal A(\rho)\|\mathcal A(\sigma))
\le
\varepsilon\left(\frac{e^\varepsilon-1}{e^\varepsilon+1}\right)T(\rho,\sigma).
\]
These bounds lead directly to sample-complexity estimates for private quantum hypothesis testing and show that, for orthogonal states in the high-privacy regime, private sample complexity scales as
\[
\Theta\!\left(\left(\frac{e^\varepsilon+1}{e^\varepsilon-1}\right)^2\right)
=
\Theta(1/\varepsilon^2)
\quad (\varepsilon<1).
\]
The same analysis also yields fairness bounds and a Holevo-information stability guarantee for learning systems driven by private quantum channels [2406.18651].

This body of work places QLDP in the same conceptual family as channel contraction, SDPI, and testing under restricted measurements. Privacy is not merely an additive perturbation constraint; it is an explicit upper bound on how much any admissible channel can preserve operational distinguishability.

## 5. Learning-theoretic consequences and the quantum statistical query model

QLDP has a direct learning-theoretic interpretation through the quantum statistical query (QSQ) model. A QSQ oracle \(\mathsf{QStat}_\rho\) receives an operator \(M\) with \(\|M\|\le 1\) and tolerance \(\tau\), and returns a value in
\[
[\operatorname{Tr}(M\rho)-\tau,\ \operatorname{Tr}(M\rho)+\tau].
\]
A central equivalence theorem shows that learning with QLDP measurements and learning with QSQ access simulate one another up to parameter transformations. In one direction, any QSQ query can be simulated using Laplace-noised local measurements with
\[
m=O\!\left(\frac{\log(1/\beta)\,k^2}{\varepsilon^2\tau^2}\right)
\]
copies while each measurement remains \(\varepsilon\)-LDP. In the reverse direction, any \(\varepsilon\)-LDP measurement can be simulated using the QSQ oracle with expected query complexity \(O(e^\varepsilon)\), accuracy \(\tau=\Theta(\beta/e^{2\varepsilon})\), and total variation error at most \(\beta\). This is the quantum extension of the classical equivalence between LDP learning and SQ learning [2203.03591].

The same work uses QLDP to show that privacy constraints do not eliminate all quantum speedups. In a multi-party setting with quantum examples of a parity function
\[
c(x)=(-1)^{s\cdot x},
\]
each party applies an \(\varepsilon\)-LDP measurement and communicates classically. Because there exists an efficiently implementable quantum measurement \(M_j\) satisfying
\[
\langle \psi|M_j|\psi\rangle=\mathrm{Inf}_j(c),
\]
the support of the hidden parity string can be recovered from private measurements. The result states that with
\[
k \ge c\, n^{-2}\log(1/\beta)
\]
parties or copies, there is an efficient algorithm that learns \(s\) with probability at least \(1-\beta\), using only \(\varepsilon\)-LDP measurements, classical communication, and classical post-processing. The corresponding classical local-DP task requires exponentially many samples [2203.03591].

This learning perspective shows that QLDP is not only a privacy notion for state release. It is also a structural constraint on admissible observation models, with direct implications for sample complexity, oracle access, and separations between classical and quantum learnability.

## 6. Locality, amplification, and entanglement geometry

A generalized privacy framework for quantum algorithms introduces \((\Xi,\tau)\)-neighboring states:
\[
\rho \overset{(\Xi,\tau)}{\sim} \sigma
\quad\Longleftrightarrow\quad
\exists \mathcal I\in \Xi:\;
\operatorname{Tr}_{\mathcal I}\rho=\operatorname{Tr}_{\mathcal I}\sigma
\ \wedge\
\frac12\|\rho-\sigma\|_1\le \tau.
\]
This formalism captures both bounded-trace-distance and local-measurement-inspired neighbor relations. For local noisy channels of the form
\[
\mathcal N_p(\cdot)=p\frac{\mathbb 1}{2}+(1-p)\mathcal M(\cdot),
\]
applied productwise, privacy bounds depend on
\[
k=\max_{\mathcal I\in\Xi}|\mathcal I|
\]
rather than the full system size \(n\), yielding exponentially tighter guarantees when \(k\ll n\). The same framework also handles multi-copy private estimation by combining concentration of measure with classical noise addition and proves an advanced joint convexity property of the quantum hockey-stick divergence [2307.04733].

Privacy amplification also appears in a channel-contraction language. For a classical dataset encoded into quantum states \(\rho(x)=|\phi(x)\rangle\langle\phi(x)|\), the minimum adjacent kernel
\[
\hat\kappa_\phi=\min_{x\sim x'} |\langle \phi(x)\mid \phi(x')\rangle|^2
\]
controls privacy amplification from quantum encoding. Quantum-inspired subsampling yields
\[
(\varepsilon,\delta)\mapsto
\left(
\log(1+(e^\varepsilon-1)\Gamma(x)m),\ \delta\,\Gamma(x)m
\right),
\qquad
\Gamma(x)=\max_j |x_j|^2.
\]
For channels, if \(\mathcal E\) is \(\gamma\)-Dobrushin and \(\mathcal S\) is QDP at trace-distance scale \(\tau\), then \(\mathcal S\circ \mathcal E\) is QDP at the reduced scale \(\gamma\tau\). This provides a direct quantum-channel analogue of privacy amplification by mixing or diffusion [2203.03604].

Entanglement introduces a further geometric layer. In a bipartite system with product mechanism \(E=E_A\otimes E_B\) and local measurements \(M=M_A\otimes M_B\), one can restrict attention to pure input states with entanglement entropy at least \(s\):
\[
H_s=\{\,|\psi\rangle: E(\psi)\ge s\,\}.
\]
The corresponding entanglement-constrained local-measurement notion, ECLM-\(\varepsilon\)-QLDP, leads to an optimal leakage level
\[
\varepsilon^*(s)
=
\log
\max_{|\phi_a\rangle,|\phi_b\rangle}
\frac{J_{\max}(K_\phi,s)}{J_{\min}(K_\phi,s)}.
\]
There is a sharp phase transition: if \(s\le \log d_{\max}\), then the maximal privacy energy remains the unconstrained spectral maximum; if \(s>\log d_{\max}\), the optimizer acquires Gibbs-form Schmidt weights and the maximal privacy energy decreases strictly with \(s\). For sufficiently large \(s\), the leakage satisfies
\[
\varepsilon^*(s)<\varepsilon^*(0),
\]
and some mechanisms with \(\varepsilon^*(0)=+\infty\) become private once entanglement is large enough. The analysis is formulated as smooth optimization on a product manifold and attributes the phase transition to the non-convex geometry of the entanglement-constrained state set [2601.19126].

These results show that locality in QLDP is multifaceted: it can refer to user-side privatization, neighborhood structure, product measurements, contraction under local channels, or geometric restrictions on admissible entangled inputs.

## 7. Measurement-induced privacy and adjacent application domains

Some application-oriented work studies privacy mechanisms that resemble QLDP without always adopting the formal channel-based definition. One example analyzes projection-valued measurements with finite shot counts. If a circuit is measured \(n\) times under a projector \(M_m\), then the empirical outcomes are approximated by Gaussians
\[
\mathcal N\!\left(\mu_0,\frac{\mu_0(1-\mu_0)}{n}\right),
\qquad
\mathcal N\!\left(\mu_1,\frac{\mu_1(1-\mu_1)}{n}\right),
\]
with \(\mu_0=\operatorname{Tr}(\rho' M_m)\) and \(\mu_1=\operatorname{Tr}(\sigma' M_m)\). In that framework, shot noise itself acts as a privacy source, and depolarizing noise
\[
\mathcal E_{\mathrm{Dep}}(\rho)=(1-p)\rho+\frac{p}{D}I
\]
further reduces distinguishability through bounds such as
\[
\mu_0-\mu_1\le \frac{1-p}{p}\,\mu_1\, dD.
\]
This is best characterized as measurement-level or per-query quantum privacy rather than standard distributed local randomization [2312.08210].

A separate federated-learning line applies client-side Gaussian perturbation to updates of local quantum models. Its privacy guarantee is explicitly classical \((\epsilon,\delta)\)-DP, with client-level protection for the entire local dataset of a participant, and the local noise variance is calibrated by
\[
\sigma^2 = \frac{8T(2L+b)^2 \log(1/\delta)}{K^2 \epsilon^2}.
\]
An adaptive schedule
\[
\sigma_t^2=\sigma_0^2\cdot \frac{1}{1+\alpha t}
\]
is used to balance privacy with barren-plateau mitigation and convergence. The source explicitly states that this is **not** formal quantum DP in the channel/output-state sense, but a local DP-style mechanism applied to quantum clients. It is therefore adjacent to QLDP rather than an instance of the core formalism [2509.05377].

These neighboring literatures underscore a broader point. QLDP, strictly construed, is a measurement-universal privacy property of quantum mechanisms or channels. Around that core notion lies a growing ecosystem of measurement-induced, encoding-based, and client-side perturbative methods that borrow its local-privacy logic while adapting to specific quantum computing and quantum learning architectures.

Source: https://www.emergentmind.com/topics/quantum-local-differential-privacy-qldp