---
title: Quantum Rejection Sampling (QRS)
url: https://www.emergentmind.com/topics/quantum-rejection-sampling-qrs
type: topic
---

# Quantum Rejection Sampling (QRS)

Searching arXiv for Quantum Rejection Sampling and closely related recent work.
Searching arXiv for the foundational 2011 QRS paper and recent applications in sampling, state preparation, and certification.
Quantum rejection sampling (QRS) denotes a family of quantum procedures that realize the logic of classical rejection sampling in coherent form. In its foundational formulation, the task is not merely to draw classical samples from a target distribution, but to transform a source superposition
\[
\lvert \pi^\xi\rangle=\sum_{k=1}^n \pi_k \lvert \xi_k\rangle \lvert k\rangle
\]
into
\[
\lvert \sigma^\xi\rangle=\sum_{k=1}^n \sigma_k \lvert \xi_k\rangle \lvert k\rangle,
\]
where the amplitudes \(\pi,\sigma\) are known, while the attached states \(\lvert \xi_k\rangle\) are normalized but unknown [1103.2774]. Subsequent literature has used the same name, or closely related descriptions, for several technically distinct primitives: amplitude-amplified conditional sampling on Bayesian networks [1402.7359], specialized spectral-distribution sampling via block-encoded acceptance tests [2304.09827], explicit state-preparation and block-encoding frameworks based on reference majorants [2405.11436], and lattice discrete Gaussian sampling with coherent proposal-to-target conversion [2605.20133]. The term therefore refers less to a single circuit template than to a recurring quantum principle: implement an accept/reject reweighting coherently and exploit amplitude amplification or related amplification methods to obtain a quadratic improvement in the relevant acceptance parameter.

## 1. Foundational formulation and oracle model

The canonical formulation of QRS was introduced as a coherent analogue of classical rejection sampling in the state-generation problem \( \mathrm{QSAMPLING}_{\pi\to\sigma}\) [1103.2774]. The input is a preparation oracle \(O\) satisfying
\[
O\lvert 0\rangle_{dn}=\lvert \pi^\xi\rangle,
\]
with access to both \(O\) and \(O^\dagger\), and the objective is to prepare the target state \(\lvert \sigma^\xi\rangle\) without learning or disturbing the hidden states \(\lvert \xi_k\rangle\). This setting is strictly more general than ordinary classical sampling, because the algorithm must preserve unknown side information coherently.

The paper formalizes success through an overlap criterion. For a general state-generation problem, the output state is required to have the form
\[
\lvert \psi_x\rangle = \sqrt p\,\lvert \sigma_x\rangle\lvert 0\rangle + \lvert \mathrm{error}_x\rangle,
\]
with \(\|\lvert \mathrm{error}_x\rangle\|\le \sqrt{1-p}\) [1103.2774]. Exact generation corresponds to \(p=1\), while \(p<1\) yields an approximate formulation. This distinguishes QRS from frameworks that define correctness solely by classical total variation distance after measurement.

The structural parameter controlling the query complexity is the “water-filling” profile
\[
\varepsilon_k(\gamma):=\min\{\pi_k,\gamma \sigma_k\},
\]
from which the paper defines the optimal filtered vector \(\varepsilon_{\pi\to\sigma}^{\,p}\) [1103.2774]. The main theorem states
\[
Q_{1-p}\!\left(\mathrm{QSAMPLING}_{\pi\to\sigma}\right)=\Theta\!\left(\frac{1}{\|\varepsilon_{\pi\to\sigma}^{\,p}\|_2}\right).
\]
At \(p=1\), this reduces to
\[
Q_0(\mathrm{QSAMPLING}_{\pi\to\sigma})=\Theta\!\left(\max_k \frac{\sigma_k}{\pi_k}\right),
\]
provided the target support lies within the source support [1103.2774]. This is the amplitude analogue of the classical rejection-sampling ratio bound.

The same work also defines a stronger state-conversion variant \( \mathrm{SQSAMPLING}_\tau\), where one is given a reflection oracle through the source state,
\[
O_{\xi,\tau}= \operatorname{ref}_{\lvert \pi^\xi\rangle} = I-2\lvert \pi^\xi\rangle\langle \pi^\xi\rvert,
\]
and only amplitude ratios via \(\tau\) [1103.2774]. This establishes QRS as a reusable abstraction for coherent amplitude reweighting rather than a single application-specific algorithm.

## 2. Core mechanism and its relation to classical rejection sampling

The basic QRS construction closely parallels classical rejection sampling, but the accept/reject test is executed coherently. Starting from
\[
O\lvert 0\rangle_d\lvert 0\rangle_n\lvert 0\rangle = \sum_{k=1}^n \pi_k \lvert \xi_k\rangle \lvert k\rangle \lvert 0\rangle,
\]
one applies, controlled on \(k\), a one-qubit rotation \(R_\varepsilon(k)\) whose sine is \(\varepsilon_k/\pi_k\), yielding
\[
\lvert \Psi_\varepsilon\rangle = \sum_{k=1}^n \lvert \xi_k\rangle \lvert k\rangle \left( \sqrt{\pi_k^2-\varepsilon_k^2}\,\lvert 0\rangle + \varepsilon_k \lvert 1\rangle \right)
\]
[1103.2774]. If the ancilla were measured immediately, the accept probability would be
\[
q_\varepsilon=\|\varepsilon\|_2^2,
\]
and the postselected accept branch would have overlap
\[
p_\varepsilon = \left(\frac{\sigma\cdot \varepsilon}{\|\varepsilon\|_2}\right)^2
\]
with the desired target [1103.2774].

The quantum speedup arises because the procedure does not repeatedly measure and restart. Instead it defines reflections about the accept branch and about \(\lvert \Psi_\varepsilon\rangle\), then applies amplitude amplification. Choosing \(\varepsilon = r\,\varepsilon_{\pi\to\sigma}^{\,p}\) for a constant \(r\in[1/2,1]\), the target can be reached in
\[
O\!\left(\frac{1}{\|\varepsilon_{\pi\to\sigma}^{\,p}\|_2}\right)
\]
iterations [1103.2774]. This is the direct quantum counterpart of replacing classical repetition by coherent rotation in a two-dimensional invariant subspace.

A related but application-specific formulation appears in Bayesian-network inference. There, the full joint distribution is encoded as the q-sample
\[
\left|\psi_P\right>=\sum_{x_1,\dots,x_n}\sqrt{P(x_1,\dots,x_n)}\left|x_1\dots x_n\right>,
\]
which decomposes into evidence-consistent and evidence-inconsistent sectors with amplitude \(\sqrt{P(e)}\) on the desired evidence pattern [1402.7359]. Amplitude amplification with the Grover iterate
\[
\hat G=-\hat A \hat S_0\hat A^\dagger \hat S_e
\]
reduces the dependence on the evidence probability from \(P(e)^{-1}\) classically to \(P(e)^{-1/2}\) quantumly, giving per-sample complexity
\[
\mathcal O\!\left(n2^m P(e)^{-1/2}\right)
\]
for a Bayesian network with \(n\) nodes and maximum indegree \(m\) [1402.7359]. Although that paper presents the method as “quantum rejection sampling,” its operational content is again amplitude amplification of a coherently marked accept sector.

This suggests a common invariant across the literature: QRS is best viewed as coherent accept-branch engineering plus amplification, while the exact representation of the branch—coin qubit, evidence register, block-encoding ancilla, or selective-phase subspace—varies by application.

## 3. Variants of the QRS paradigm

The subsequent literature does not maintain a single canonical formalism. One line keeps the original state-conversion viewpoint, while others specialize the idea to different access models.

In quantum state preparation and matrix block-encoding, QRS is formulated through a reference majorant. For a target state
\[
|\psi_f\rangle=\frac{1}{\mathcal N_f}\sum_{x=1}^N f(x)\,|x\rangle
\]
and reference
\[
|\psi_g\rangle=\frac{1}{\mathcal N_g}\sum_{x=1}^N g(x)\,|x\rangle,
\qquad g(x)\ge |f(x)|,
\]
the algorithm introduces a sampling register of dimension \(M\), coherently flags whether \(m\,g(x)\le M|f(x)|\), and uses amplitude amplification to project onto the accepted branch [2405.11436]. The number of amplification rounds is
\[
R = \left\lceil \frac{\pi}{4\arcsin(\mathcal N_f/\mathcal N_g)} -\frac12 \right\rceil,
\]
so the usefulness of the method depends explicitly on constructing an efficiently preparable reference \(g\) with small \(\mathcal N_g/\mathcal N_f\) [2405.11436]. The same logic is lifted entrywise to matrices by introducing a reference matrix \(G\) satisfying \(G_{ij}\ge |A_{ij}|\), yielding block-encodings of \(A/\alpha\) from coherent acceptance tests on matrix entries [2405.11436].

A different variant appears in ground-state energy certification, where rejection sampling is not used to transform one known coherent distribution into another, but to sample from spectral-measure-induced continuous densities of the form
\[
(p\ast \nu)(x)=\sum_i p_i \nu(x-E_i),
\qquad
p(x)=\sum_i p_i\delta(x-E_i)
\]
[2304.09827]. A classical computer first samples \(x\sim \mu\), and a quantum computer accepts \(x\) by implementing a block-encoding \(U_x\) of \(h(H-xI)\) satisfying
\[
|h(H-x I)|^2=\frac{\nu(H-x I)}{|M|^2\mu(x)},\quad \|h(H-x I)\|\leq 1.
\]
The ancilla-success probability becomes
\[
\frac{(p\ast \nu)(x)}{|M|^2\mu(x)},
\]
so conditioned on acceptance, the retained \(x\) is distributed according to the target \(p\ast \nu\) [2304.09827]. The paper explicitly describes this as “a novel use of quantum computers to facilitate rejection sampling,” not as an invocation of the standard Ozols–Roetteler–Roland framework [2304.09827].

A further neighboring direction replaces literal rejection logic by spectral filtering plus fixed-point amplitude amplification. In reversible Markov-chain QSAMPLE preparation, the target state is
\[
\ket{\pi}=\sum_{x\in\Omega}\sqrt{\pi(x)}\ket{x},
\]
and the conversion \(\ket{\pi_i}\to\ket{\pi_{i+1}}\) is driven by adjacent overlap
\[
p_i:=|\langle \pi_i|\pi_{i+1}\rangle|^2
\]
rather than by an explicit pointwise acceptance ratio [2605.23442]. The method builds approximate selective phases on the stationary eigenspace of a qubitized Szegedy walk and embeds them in fixed-point amplitude amplification, achieving \(\widetilde{\mathcal O}\!\left( \ell/\sqrt{p_{\min}\Delta_{\min}} \right)\) query complexity with one additional qubit in the working register [2605.23442]. The paper is technically QRS-like rather than literal rejection sampling.

Another related route uses quantum signal processing rather than explicit accept/reject flags. In proportional sampling, the target distribution is proportional to a nonnegative oracle-defined weight function \(c(x)\), and the algorithm prepares amplitudes proportional to \(\sqrt{c(x)}\) by encoding \(\sqrt{c(x)}\) into an eigenphase and then applying phase extraction via QSP/QET [2303.11077]. The final normalization step again uses amplitude amplification with overhead \(O(1/\sqrt{\bar c})\), where \(\bar c = \frac1N\sum_x c(x)\) [2303.11077]. The paper does not call this QRS, but the task is manifestly QRS-adjacent.

## 4. Representative applications

The foundational QRS paper already framed the method as a reusable primitive rather than a standalone sampling trick. It identifies three applications: the Harrow–Hassidim–Lloyd linear-systems algorithm, the quantum Metropolis move, and the Boolean hidden shift problem [1103.2774]. In the HHL setting, the crucial transformation
\[
\sum_j b_j \lvert \psi_j\rangle \lvert \lambda_j\rangle
\;\longrightarrow\;
\sum_j b_j \lambda_j^{-1}\lvert \psi_j\rangle \lvert \lambda_j\rangle
\]
is treated as strong resampling; in the quantum Metropolis setting, QRS amplifies the branch weighted by the Metropolis factor \(\sqrt{f_{ij}}\); and in the hidden shift problem, the Fourier amplitudes \(\pi_w=|\hat f(w)|\) are converted toward the flat target \(\sigma_w=2^{-n/2}\) by the same water-filling analysis [1103.2774].

Approximate inference on Bayesian networks provides one of the earliest explicit algorithmic realizations of QRS in a structured probabilistic model. With a q-sample of the full joint distribution and bounded indegree \(m\), the preparation cost is
\[
Q_{\hat A_\mathcal B}=\mathcal O(n2^m),
\]
and amplitude amplification then yields one sample from \(P(\mathcal Q\mid \mathcal E=e)\) in time
\[
\mathcal O\!\left(n2^m P(e)^{-1/2}\right)
\]
rather than the classical
\[
\mathcal O\!\left(nm\,P(e)^{-1}\right)
\]
[1402.7359]. The speedup is specifically in the rejection dependence on the evidence probability.

Spectral-distribution sampling for early fault-tolerant ground-state energy certification constitutes a different application class. There the target is a Gaussian-smoothed spectral measure,
\[
(p\ast n_\sigma)(x)=\sum_i p_i\, n_\sigma(x-E_i),
\]
and rejection sampling is used to obtain samples from conditioned truncations of this density around a candidate \(\hat E_0\) [2304.09827]. The generic theorem gives an expected number \(|M|^2\) of block-encoding uses per accepted sample, while the Gaussian implementation produces circuits of depth \(\tilde{\mathcal O}(\sigma^{-1})\) [2304.09827]. The application is not merely sampling; it supports a certification test that checks peakedness and conditional variance near the putative ground-state energy.

Lattice-based cryptography has recently produced several explicit QRS instantiations. In discrete Gaussian sampling over lattices, the proposal is the coherent truncated Klein distribution \(q\), the target is the truncated lattice Gaussian \(D_{\Omega,\sigma}\), and the amplitude-transduction theorem produces
\[
|D_2\pm 2^{-\nu+1}\rangle
\]
after an average of \(O(\sqrt w)\) calls to the proposal and ratio-computing subroutines, where
\[
w := \max_{\vec x\in \Omega}\frac{D_2(\vec x)}{D_1(\vec x)}
\]
[2605.20133]. The final performance theorem yields gate count
\[
\sqrt{ \frac{ C^m\prod_{i=1}^{m}\rho_{\sigma_i}(\llbracket -2^M,2^M\rrbracket) }{ \rho_\sigma(\Omega) } } \times O\!\left(mM(\nu+mM+m^2r)^2\right)
\]
and total variation error at most \(2^{-\nu}\) relative to the infinite-support discrete Gaussian [2605.20133]. Closely related work reinterprets Wang–Ling’s lower bound on Klein’s proposal as precisely the domination condition needed for QRS, leading to \(\mathcal O(1/\sqrt{\Delta_{\mathcal R}})\) query complexity for truncated lattice Gaussian preparation and concrete attack-cost reductions of \(9\), \(4\), and \(13\) bits for Kyber-512, Kyber-768, and Kyber-1024, respectively [2605.24798].

## 5. Complexity measures and performance regimes

Across the QRS literature, the quadratic improvement appears in different parameters depending on the access model. In the original state-generation problem, the complexity is \(\Theta(1/\|\varepsilon_{\pi\to\sigma}^{\,p}\|_2)\), and in the exact-support case this becomes \(\Theta(\max_k \sigma_k/\pi_k)\) [1103.2774]. In Bayesian-network inference, the improvement is
\[
P(e)^{-1}\longrightarrow P(e)^{-1/2}
\]
[1402.7359]. In spectral-measure rejection sampling, the expected number of quantum accept/reject trials is
\[
\mathbb E[\text{\# uses of }U_x]=|M|^2
\]
for exact block-encodings, while the Gaussian filtering subroutine itself costs
\[
O\!\left(\sigma^{-1}\sqrt{\log(1/\epsilon)}\right)
\]
controlled evolution time [2304.09827]. In lattice Gaussian sampling, the classical dependence \(1/\Delta\) becomes \(1/\sqrt{\Delta}\) up to polynomial overheads [2605.20133, 2605.24798].

State-preparation QRS makes especially explicit that the amplification cost is governed by the norm ratio of target to reference. Direct postselection succeeds with probability
\[
P_{\mathrm{succ}}=\left(\frac{\mathcal N_f}{\mathcal N_g}\right)^2,
\]
so a good reference state can reduce the number of amplitude-amplification rounds to a constant [2405.11436]. The paper works out this regime for several structured amplitude families. For power-law amplitudes, the dyadic “ziggurat” majorant gives constant success probability depending only on \(\beta\), with \(R=1\) for the case \(\beta=1\) [2405.11436]. For Gaussian amplitudes, a flat-core plus exponential-tail reference yields
\[
P_{\mathrm{succ}\approx 0.529,
\]
hence again \(R=1\) in the regime \(\delta \ll \sigma \ll \delta N =1\) [2405.11436]. For hyperbolic tangent amplitudes, the constant reference \(g(x)=1/2\) gives
\[
P_{\mathrm{succ}\approx 0.704,
\]
so \(R=1\) as well [2405.11436].

Markov-chain QSAMPLE preparation introduces a different performance metric, based on adjacent overlap \(p_{\min}\), minimum phase gap \(\Delta_{\min}\), and target trace distance \(\varepsilon\). The end-to-end theorem gives
\[
D_{\mathrm{tr}(\ket{\widetilde{\pi}_\ell}, \ket{\pi_\ell}) \le \varepsilon
\]
using
\[
\mathcal{O}\!\left( \frac{\ell}{\sqrt{p_{\min}\,\Delta_{\min}}}\log\frac{\ell}{\varepsilon}\log\!\left( \frac{\ell}{\varepsilon\sqrt{p_{\min}\log\frac{\ell}{\varepsilon}}} \right)\right)
\]
queries and one additional qubit in the working register [2605.23442]. The paper explicitly compares this with Wocjan and Abeyesinghe, improving the overlap dependence from \(1/p_{\min}\) to \(1/\sqrt{p_{\min}}\) and reducing the working-register ancilla cost to one [2605.23442].

These varied complexity statements indicate that the “quadratic speedup” slogan is precise only relative to a specified bottleneck: evidence probability, domination constant, overlap, or rejection ratio. QRS is therefore not defined by one asymptotic formula, but by a recurring square-root improvement in the acceptance or overlap parameter native to the application.

## 6. Terminological scope, misconceptions, and contemporary directions

A common misconception is that “quantum rejection sampling” names a single universally accepted primitive. The literature instead shows several partially overlapping uses. The Ozols–Roetteler–Roland paper defines QRS as coherent amplitude reweighting with tight query complexity in an oracle model containing unknown attached states [1103.2774]. The Bayesian-network paper uses the same term for amplitude-amplified conditional sampling from q-samples and emphasizes that the result is “unrelativized,” since it counts primitive gate operations rather than black-box state-preparation queries [1402.7359]. The ground-state certification paper does not adopt the formal label QRS at all, instead proposing “a novel use of quantum computers to facilitate rejection sampling” for spectral distributions [2304.09827]. The Markov-chain QSAMPLE paper is even further from literal rejection logic, though technically close in its use of overlap-driven state conversion and amplification [2605.23442].

A second misconception is that QRS is always a method for producing classical samples. The foundational formulation targets coherent state generation [1103.2774], and several later applications rely critically on preserving the coherent output. The discrete Gaussian sampler “outputs a quantum state which can either be measured to get the desired distribution or be used directly as such in other quantum algorithms” [2605.20133]. The same is true of QSAMPLE preparation for Markov chains and of QSP-based proportional sampling, where the state itself is the intended primitive [2605.23442, 2303.11077].

A third misconception is that QRS automatically yields practical advantage whenever a rejection step exists classically. The papers are more cautious. Bayesian-network QRS is efficient only for bounded indegree \(m\) [1402.7359]. State-preparation QRS requires an efficiently preparable reference majorant and efficient coherent arithmetic for the acceptance test [2405.11436]. Spectral-measure rejection sampling in ground-state certification has scaling “less favorable than that of the GSEE algorithm,” and the certification routine has
\[
\tilde{\mathcal O}(\eta^{-3}\epsilon^{-4}\log(\delta^{-1}))
\]
expected block-encodings, which is substantially worse than the corresponding estimation algorithm [2304.09827]. Lattice QRS papers often work in an oracle model assuming coherent access to truncated Klein proposals and ratio computations, so their strongest statements are complexity-theoretic rather than low-level gate-synthesis results [2605.24798].

Contemporary directions suggest both specialization and unification. Specialization appears in lattice sampling, spectral-measure sampling, and Markov-chain coherent sampling, where application structure determines the accept subspace and the complexity parameter [2605.20133, 2304.09827, 2605.23442]. Unification appears in the attempt to treat state preparation and matrix block-encoding under one reference-design framework, where previous methods are interpreted as special cases of QRS with different choices of \(g\) or \(G\) [2405.11436]. A plausible implication is that the most productive future uses of QRS may arise not from a single abstract formalism, but from systematically identifying hidden domination or overlap structures in domain-specific algorithms and then turning those structures into coherent accept branches amenable to amplification.

Source: https://www.emergentmind.com/topics/quantum-rejection-sampling-qrs