---
title: Reed–Muller Distillation Factory
url: https://www.emergentmind.com/topics/reed-muller-distillation-factory
type: topic
---

# Reed–Muller Distillation Factory

A Reed–Muller distillation factory is a magic-state distillation construction whose coding-theoretic core is supplied by Reed–Muller codes, quantum Reed–Muller codes, or punctured/shortened Reed–Muller-derived CSS and triorthogonal codes. In the literature, the term encompasses at least three closely related objects: Reed–Muller code families that admit transversal non-Clifford action and therefore serve as candidate distillation ingredients; explicit distillation modules such as \(15\ket T\to\ket T\), \(64\ket T\to\ket{CCZ}\), and \(127\ket T\to\ket T\) routines; and architectural realizations in which the relevant stabilizer measurements are made geometrically local in 2D or 3D. The subject therefore sits at the intersection of algebraic coding theory, transversal-gate constructions, and factory-level resource optimization [2305.06423] [2605.06284] [2510.10852] [1205.3104].

## 1. Conceptual scope and factory model

In the code-theoretic sense, Reed–Muller constructions are relevant because transversal \(T\)-type operations act nontrivially on suitable Reed–Muller codes, so the codes can be used as distillation or checking gadgets for noisy \(T\) states, or for producing \(CCZ\) states [2605.06284]. In the stabilizer-code sense, a CSS-T code is a CSS code \(CSS(C_1,C_2)\) built from binary linear codes \(C_2\subseteq C_1\) such that the code space is preserved by transversal physical \(T\) and \(T^\dagger\), making it a natural ingredient for implementing logical non-Clifford resources [2305.06423].

In the protocol sense, a factory is a recursively concatenated family of triorthogonal-code modules. For a triorthogonal code with parameters \([[n,k,d]]_p\), the routine consumes \(n\) noisy input magic states and outputs \(k\) improved ones, with leading-order suppression
\[
\epsilon_{\rm out}=O(A_d \epsilon_{\rm in}^d),
\]
where \(A_d\) is the number of weight-\(d\) logical \(Z\)-type operators [2510.10852]. After \(z\) concatenation levels,
\[
\epsilon_{\rm out}=O\!\left(A_d^{\frac{d^z-1}{d-1}}\epsilon_{\rm in}^{d^z}\right)
\]
from
\[
\frac{n^z}{k^{z-1}}
\]
noisy magic states, and the asymptotic overhead scales as
\[
O\!\left(\log^\gamma\!\frac{1}{\epsilon_{\rm out}}\right), \qquad \gamma=\frac{\log(n/k)}{\log d}.
\]
This gives a precise operational meaning to “factory”: an iterated family of distillation blocks whose performance is governed by \(n\), \(k\), \(d\), \(A_d\), and postselection [2510.10852].

A common misconception is to identify every Reed–Muller transversal-\(T\) code with a complete factory protocol. That identification is too strong. Some works provide explicit distillation maps and leading-order error formulas, whereas others provide only the code-family input that such a factory would require. In particular, the CSS-T Reed–Muller analysis of [2305.06423] is explicitly coding-theoretic rather than protocol-theoretic.

## 2. Reed–Muller algebraic foundations

The binary Reed–Muller code used in the CSS-T setting is
\[
\RM(r,m)=\{ev(f)\mid f\in \mathbb F_2[x_1,\dots,x_m],\ \deg(f)\le r\},
\]
with parameters
\[
\RM(r,m)\text{ is }[2^m,\ \sum_{i=0}^r \binom{m}{i},\ 2^{m-r}],
\]
nesting
\[
\RM(r_2,m)\subseteq \RM(r_1,m)\qquad\text{if }r_2\le r_1,
\]
and duality
\[
\RM(r,m)^\perp=\RM(m-r-1,m)
\]
[2305.06423].

The local-unfolding literature uses a quantum Reed–Muller notation
\[
QRM_m(q,r),
\]
defined on \(n=2^m\) physical qubits, with \(X\)-stabilizer group \(RM_m(q)\) and \(Z\)-stabilizer group \(RM_m(m-r-1)\). Equivalently, the \(X\) stabilizers are generated by subcubes of dimension \(m-q\), and the \(Z\) stabilizers by subcubes of dimension \(r+1\). A subset of vertices is represented by
\[
V_P=\{v\in \mathbb{F}_2^m\mid P(v)=1\},
\]
with associated Pauli operators
\[
Z(V)=\prod_{v\in \mathbb{F}_2^m}(Z_v)^{v\in V},\qquad X(V)=\prod_{v\in \mathbb{F}_2^m}(X_v)^{v\in V}
\]
[2605.06284].

For prime dimension \(p\), the classical Reed–Muller code generalizes to
\[
RM_p(r,m)=\{ f : \deg(f)\le r,\; f\in \mathbb F_p[x_1,\dots,x_m]/\langle \dots, x_i^p-x_i,\dots\rangle\},
\]
whose codewords are evaluations
\[
{\rm ev}(f)=(f(\vec v): \vec v\in \mathbb F_p^m)\in \mathbb F_p^{p^m}.
\]
Its dual is
\[
RM_p(r,m)^\perp = RM_p(\tilde r,m), \qquad \tilde r = m(p-1)-r-1
\]
[2510.10852].

A distinct odd-prime construction uses shortened first-order \(d\)-ary Reed–Muller codes to define a one-logical-qudit CSS code
\[
\mathcal{QRM}_d(m)
\]
on
\[
n=d^m-1
\]
physical qudits, with
\[
\mathcal{L}_X=\mathcal{RM}_d^*(1,m), \qquad \mathcal{L}_Z=[\mathrm{span}(\mathcal{L}_X,\mathbf{1})]^\perp
\]
[1205.3104]. This family underlies explicit qutrit and ququint distillation protocols rather than only asymptotic code families.

## 3. Transversal non-Clifford structure

For binary CSS-T codes, the defining conditions are that \(C_2\) is an even code and that for each codeword \(x\in C_2\), there exists a self-dual code in \(C_1^\perp\) supported on \(x\) [2305.06423]. A structural criterion used in the analysis is:

> An \([n,k]\) binary linear code \(C\) contains a self-dual code if and only if \(n\) is even and \(C^\perp\) is self-orthogonal, meaning that \(C^\perp\subseteq C\).

Combined with puncturing/shortening duality,
\[
short(C,I)^\perp=punct(C^\perp,I),
\]
this yields the equivalent support condition
\[
punct(C_1,\mathbb F_2^m\setminus \operatorname{supp}(x)) \subseteq short(C_1^\perp,\mathbb F_2^m\setminus \operatorname{supp}(x)) \qquad\forall x\in C_2
\]
[2305.06423].

The central Reed–Muller CSS-T characterization takes
\[
C_1=\RM\!\left(\frac{m-1}{2}-t,\ m\right),\qquad C_2=\RM(r_2,m),
\]
and proves that \(CSS(C_1,C_2)\) is a CSS-T code if and only if
\[
r_2\le 2t+1 \quad\text{for \(m\) even,}
\]
or
\[
r_2\le 2t \quad\text{for \(m\) odd.}
\]
The proof proceeds by translating the support condition into a puncturing/shortening inclusion and then using degree bounds for products of polynomials [2305.06423].

In the prime-dimensional triorthogonal setting, the exact algebraic criterion is
\[
RM_p(r,m)\ \text{is a classical triorthogonal space if}\ 3r < m(p-1).
\]
Given a triorthogonal generator matrix \(G\), one punctures \(k\) coordinates to obtain \(G'\), shortens on the same coordinates to obtain \(G_0\), and forms
\[
CSS(G_0\to X,\; G'{}^\perp\to Z).
\]
If the surviving submatrix has full rank, then the resulting CSS code has length \(n_0-k\), dimension \(k\), and in the nondegenerate case considered,
\[
d=\min(d(G_0^\perp), d(G'))=d(G_0^\perp)
\]
[2510.10852].

For odd prime dimension \(d\), the transversal structure is expressed in terms of a diagonal non-Clifford gate \(M\in\mathcal{M}_d^m\). An \(\mathcal{M}_d^m\)-distillation code satisfies
\[
M^{\otimes n}\Pi (M^{\otimes n})^\dagger = M_L^\dagger \Pi M_L,
\]
with logical operators
\[
X_L = X[\mathbf{1}],\qquad Z_L = Z[(d-1)\mathbf{1}]
\]
[1205.3104]. This transversality is the mechanism that turns a Reed–Muller code into a distillation primitive.

The 3D local “rubik’s code” \(QRM_6(1,2)\) makes this logical action particularly explicit. It encodes 15 logical qubits indexed by 2-element subsets of \(\{1,\dots,6\}\), and a transversal \(T\) or \(\widetilde T\) on all 64 qubits acts logically as the product of all \(CCZ\) gates on triples of logical qubits that partition \(\{1,\dots,6\}\):
\[
\widetilde T_A \equiv \prod_{\{I,J,K\}\text{ partition }\{1,\dots,6\}} CCZ_{I,J,K}
\]
[2605.06284].

## 4. Distillation modules and representative constructions

The Reed–Muller factory literature contains both one-output and multi-output modules. In odd prime dimension, one round of the protocol takes \(n\) copies of a noisy single-qudit state, twirls each under the Clifford \(C_M\), measures the \(Z\)-type stabilizers, applies a Clifford correction conditioned on those outcomes, measures the \(X\)-type stabilizers and postselects on the trivial syndrome, then decodes to one qudit [1205.3104]. In the punctured-triorthogonal setting, the design recipe is: choose a triorthogonal \(RM_p(r,m)\), puncture a set \(S\subset \mathbb F_p^m\), shorten on the same coordinates, form the CSS code, and use its transversal \(T\) to distill \(k\) magic states from \(n\) noisy ones [2510.10852].

| Module | Map or parameters | Reported leading performance |
|---|---|---|
| Punctured \(QRM_4(1,1)\) | \([[15,1,3]]\)-type Reed–Muller \(T\)-state factory | \(35p^3\) |
| \(QRM_6(1,2)\) | \(64\ket T \to 15\ket{CCZ}\) | \(10416\,p^4\) |
| Big unfolded code | \(64\ket T \to \ket{CCZ}\) | \(8256\,p^4\) |
| Punctured \(QRM_7(2,2)\) | \(127\ket T \to \ket T\) | \(11811\,p^7\) |
| \(\mathcal{QRM}_3(2)\) | \(n=3^2-1=8\) qutrit code | \(\epsilon' \le K\epsilon^2\) |
| \(\mathcal{QRM}_5(1)\) | \(n=5^1-1=4\) ququint code | \(\epsilon' \sim \frac{3}{2}\epsilon^2+\frac{7}{2}\epsilon^3+O(\epsilon^4)\) |

For the local binary factories, the leading-order rule is
\[
p_{\text{out}} = m\, p_{\text{in}}^{d_Z},
\]
where \(d_Z\) is the \(Z\)-distance and \(m\) is the number of minimum-weight nontrivial \(Z\) logical operators [2605.06284]. Specific values reported are: punctured \(QRM_4(1,1)\), \(d_Z=3\), \(m=35\); \(QRM_6(1,2)\), \(d_Z=4\), \(m=10416\); the big unfolded code, \(d_Z=4\), \(m=8256\); and punctured \(QRM_7(2,2)\), \(d_Z=7\), \(m=11811\) [2605.06284].

For odd-prime protocols, the qutrit code \(\mathcal{QRM}_3(2)\) has threshold
\[
\epsilon^*=0.20015
\]
for all noise types and
\[
\epsilon_{\mathrm{dep}}^*=0.211001
\]
for depolarizing noise, while the ququint code \(\mathcal{QRM}_5(1)\) has
\[
\epsilon^*=0.31195
\]
for generic noise and
\[
\epsilon_{\mathrm{dep}}^*=0.3631226
\]
for depolarizing noise [1205.3104]. The ququint update under depolarizing noise is given exactly by
\[
\epsilon' = \frac{\epsilon^2(96-160\epsilon+75\epsilon^2)} {64-256\epsilon+480\epsilon^2-400\epsilon^3+125\epsilon^4}.
\]

The prime-\(p\) punctured Reed–Muller program emphasizes multi-output modules and asymptotic overhead rather than only one-output routines. Its most practically striking searched example is the ququint code
\[
[[519,106,5]]_5
\]
with
\[
\gamma=0.99.
\]
The same table gives
\[
A_d = 2180,
\]
and with \(\delta_{\rm in}=10^{-3}\), one round gives
\[
\delta_{\rm out}\approx 8\times 10^{-18},
\]
with distillation cost
\[
C=\frac{n}{\bar n_T}\approx 7.4
\]
[2510.10852]. This suggests that search-optimized puncturing can materially outperform analytically convenient puncturing rules at finite size.

## 5. Geometric locality and unfolding

A major recent development is the conversion of Reed–Muller distillation constructions into geometrically local factories by “unfolding” the hypercube description of the code into 2D or 3D layouts in which a basis of the \(Z\)-stabilizer group becomes local [2605.06284]. The underlying algebraic mechanism is a product decomposition of polynomial subspaces associated with subcube types, rather than an ad hoc layout search.

For \(QRM_4(1,1)\), two cube coordinates are grouped into one planar axis and the other two into the second planar axis. For \(QRM_6(1,1)\), the coordinates are split as \(\{1,2,3\}\) and \(\{4,5,6\}\), producing a planar \(7\times 7\) structure; 49 local square checks are obtained from the product grid, and 8 more checks are appended to span the full 57-dimensional \(Z\)-stabilizer group [2605.06284]. The Gray-code basis used for \((\mathbb{F}_2[X,Y,Z])_{\le 2}\) is
\[
\big((Y+1)(Z+1),\; X(Z+1),\; Y(Z+1),\; (X+1)Y,\; (Y+1)Z,\; XZ,\; YZ\big).
\]

For the 64-qubit “rubik’s code” \(QRM_6(1,2)\), the coordinates are grouped as
\[
x\leftrightarrow \{1,2\},\qquad y\leftrightarrow \{3,4\},\qquad z\leftrightarrow \{5,6\}.
\]
The 27 bulk cubes correspond to the little cubes of a Rubik’s cube, and 15 more local cubes are placed on the boundary faces, giving 42 \(Z\)-stabilizer generators in total, matching
\[
\binom66+\binom65+\binom64+\binom63=42.
\]
According to the introduction, the 3D layout uses **64 data qubits plus 42 additional qubits** [2605.06284].

The “big unfolded code” interpolates between \(QRM_6(1,2)\) and \(QRM_6(1,1)\): it has the same \(X\)-stabilizer group as \(QRM_6(1,2)\), but its \(Z\)-stabilizer generators are chosen as a subset of the square checks from \(QRM_6(1,1)\). Three omitted \(Z\)-stabilizer generators become three logical \(Z\)’s, corresponding to logical qubits of types \(\{1,2\},\{3,4\},\{5,6\}\), and the resulting logical action is
\[
\widetilde T_{\langle \{1,2,3,4,5,6\}\rangle} \equiv CCZ_{\{\{1,2\},\{3,4\},\{5,6\}\}}.
\]
This yields a \(64\ket T\to\ket{CCZ}\) distillation factory [2605.06284].

For \(QRM_7(2,2)\), the coordinates are grouped as
\[
x\leftrightarrow \{1,2,3\},\qquad y\leftrightarrow \{4,5,6\},\qquad z\leftrightarrow \{7\},
\]
and the construction yields 99 generators total, matching
\[
\binom77+\binom76+\binom75+\binom74+\binom73=99.
\]
The 3D local implementation uses **127 data qubits plus 152 additional qubits** [2605.06284].

A common misunderstanding is that unfolding makes the entire stabilizer structure local in a symmetric way. The paper is explicit that locality is achieved for a **basis of the \(Z\)-stabilizer group**, while nonlocal \(X\)-stabilizers may remain acceptable, especially for biased-noise hardware such as cat qubits [2605.06284].

## 6. Asymptotic behavior, overhead tradeoffs, and limitations

The asymptotic behavior of Reed–Muller factory families depends strongly on which Reed–Muller formalism is used. For the binary CSS-T construction, the exact CSS dimension is
\[
k= \sum_{i=0}^{\frac{m-1}{2}-t}\binom{m}{i} - \sum_{i=0}^{r_2}\binom{m}{i},
\]
the block length is
\[
n=2^m,
\]
and the CSS lower bound on distance simplifies to
\[
d\ge 2^{r_2+1}
\]
[2305.06423]. The asymptotic Reed–Muller rate satisfies
\[
\lim_{m\to\infty} R(\RM(r(m),m)) = \Phi\!\left( \lim_{m\to\infty}\frac{2r(m)-m}{\sqrt m} \right),
\]
and for
\[
r_1(m)=\frac{m-1}{2}-t(m)
\]
the CSS-T family rate tends to
\[
\Phi(-2c), \qquad c=\lim_{m\to\infty}\frac{t(m)}{\sqrt m},
\]
with
\[
\Phi(-2c)\le \frac12.
\]
The maximum rate of a CSS-T code defined by Reed–Muller codes is therefore
\[
\frac12
\]
[2305.06423].

This same work proves an important limitation: a family of classical Reed–Muller codes cannot have both nonvanishing rate and nonvanishing relative distance, and CSS codes built only from nested Reed–Muller codes therefore have vanishing quantum relative distance [2305.06423]. For distillation-factory interpretation, that limitation does not eliminate usefulness, because the minimum distance can still diverge. If \(t(m)=\Theta(\sqrt m)\), then the asymptotic rate remains nonzero and \(r_2(m)\) can scale like \(O(\sqrt m)\), yielding a diverging distance lower bound while \(k/n\) stays bounded away from zero [2305.06423]. A plausible implication is that these families are best viewed as candidates for constant-overhead magic-state distillation rather than asymptotically good quantum memories.

For punctured prime-dimensional Reed–Muller factories, the central yield parameter is
\[
\gamma = \frac{\log(n/k)}{\log d},
\]
and the paper derives sublogarithmic magic-state cost
\[
O\!\left(\log^\gamma(\epsilon^{-1})\right)
\]
for all prime dimensions \(p\) [2510.10852]. In the analytically tractable Manhattan-weight puncturing family,
\[
n=\binom{m}{>w}_p,\qquad k=\binom{m}{\le w}_p,\qquad d=\Delta_p(m,\tilde r,w),
\]
with
\[
\tilde r = m(p-1)-r-1,\qquad 3r<m(p-1),\qquad w<m(p-1)-r
\]
[2510.10852]. The optimized asymptotic values reported include
\[
p=2:\ \gamma_0=0.67799,\quad
p=3:\ \gamma_0=0.63215,\quad
p=5:\ \gamma_0=0.55914,\quad
p=7:\ \gamma_0=0.50786,
\]
\[
p=11:\ \gamma_0=0.44108,\quad
p=23:\ \gamma_0=0.34663,
\]
and the large-\(p\) summary is
\[
\gamma \to \frac{1}{\ln p} \quad\text{as } p\to\infty
\]
[2510.10852].

Several limitations recur across the literature. The CSS-T Reed–Muller paper does not give a full \(T\)-state factory protocol, explicit MSD thresholds, acceptance probabilities, or routing architecture [2305.06423]. The local-unfolding work does not provide a full circuit-level resource table for the new factories and states that detailed protocol verification and numerical simulation beyond the earlier small-factory case are left to future work [2605.06284]. The Manhattan-weight puncturing scheme is explicitly not optimal and is chosen because it makes the distance analytically computable [2510.10852]. The odd-prime Reed–Muller distillation protocols assume protected stabilizer operations and do not include layout, routing, ancilla scheduling, or a complete architecture-level threshold for a higher-dimensional fault-tolerant stack [1205.3104].

Taken together, these results define the modern Reed–Muller distillation factory as a family of non-Clifford magic-state distillation architectures whose core resource is the algebraic structure of Reed–Muller codes: binary CSS-T families with nonvanishing asymptotic rate up to \(1/2\), explicit local qubit factories such as \(64\ket T\to\ket{CCZ}\) and \(127\ket T\to\ket T\), odd-prime one-output protocols such as the 8-qutrit and 4-ququint schemes, and prime-\(p\) punctured-triorthogonal families with sublogarithmic asymptotic overhead [2305.06423] [2605.06284] [2510.10852] [1205.3104].

Source: https://www.emergentmind.com/topics/reed-muller-distillation-factory