---
title: Tolerant Quantum State Certification
url: https://www.emergentmind.com/topics/tolerant-quantum-state-certification
type: topic
---

# Tolerant Quantum State Certification

Tolerant quantum state certification is the family of tasks in which one certifies that a prepared quantum state is *sufficiently close* to a target, rather than requiring exact equality. In the most standard formulation, one distinguishes whether an unknown state \(\rho\) satisfies \( \mathrm{F}(\rho,\sigma)\ge 1-\varepsilon_1 \) or \( \mathrm{F}(\rho,\sigma)\le 1-\varepsilon_2 \) for a known reference state \(\sigma\), with \(\varepsilon_2>\varepsilon_1\) [2606.26034]. Contemporary work extends this basic promise-gap view in several directions: finite-batch certification of an unmeasured remainder, device-independent certification in terms of extractability, witness-based lower bounds from local measurements, restricted-measurement and gentle-measurement models, and task-adapted notions of fidelity for photonic and logical-computational settings [2407.13913].

## 1. Formal definitions and canonical promise-gap formulations

A standard modern definition of tolerant certification is the fidelity-gap decision problem
\[
\mathrm{F}(\rho,\sigma)\ge 1-\varepsilon_1
\quad\text{or}\quad
\mathrm{F}(\rho,\sigma)\le 1-\varepsilon_2,
\qquad \varepsilon_2>\varepsilon_1,
\]
where \(\sigma\) is known and \(\rho\) is accessed through identical copies [2606.26034]. In that work, fidelity is
\[
\mathrm{F}(\rho,\sigma)=\|\sqrt{\rho}\sqrt{\sigma}\|_1
=\tr\!\left(\sqrt{\sqrt{\sigma}\rho\sqrt{\sigma}}\right),
\]
and the Bures distance is
\[
\mathrm{D}_\mathrm{B}(\rho,\sigma)=\sqrt{2(1-\mathrm{F}(\rho,\sigma))}.
\]
The paper also emphasizes that fidelity is local to \(\supp(\sigma)\), so if \(\Pi\) projects onto \(\supp(\sigma)\), then
\[
\mathrm{F}(\rho,\sigma)=\mathrm{F}(\Pi\rho\Pi,\sigma).
\]

This support-locality yields a direct tolerant-certification corollary. If the known reference state \(\sigma\) has rank \(r\), then \(\mathrm{F}(\rho,\sigma)\) can be estimated to additive error \(\varepsilon\) using
\[
O\!\left(\frac{r^2}{\varepsilon^2}\right)
\]
copies of \(\rho\), with lower bound
\[
\Omega\!\left(\frac{r}{\varepsilon^2}\right).
\]
Consequently, the tolerant decision problem above can be solved with
\[
O\!\left(\frac{r^2}{(\varepsilon_2-\varepsilon_1)^2}\right)
\]
copies [2606.26034]. The same paper presents a second regime, where \(\rho\) has rank at most \(r\) but \(\sigma\) is arbitrary, with fidelity-estimation complexity
\[
O\!\left(\frac{r^2}{\varepsilon^4}\right).
\]

An earlier mixed-state certification line already contained robust, non-asymptotic gap statements, though expressed through Bures distance, Hilbert–Schmidt distance, and trace distance rather than the explicit \((\varepsilon_1,\varepsilon_2)\) promise above [1708.06002]. For a known \(d\)-dimensional mixed target \(\sigma\), that work gives a fidelity-oriented certification procedure using
\[
n=O(d/\epsilon)
\]
copies and a trace-distance-oriented procedure using
\[
n=O(d/\epsilon^2)
\]
copies. Its robust Bures-distance statement distinguishes
\[
D_{\mathrm B}^2(\rho,\sigma)\le 0.49\,\epsilon
\quad\text{from}\quad
D_{\mathrm B}^2(\rho,\sigma)> 0.5\,\epsilon,
\]
while the two-sample Hilbert–Schmidt tester distinguishes
\[
D_{\mathrm{HS}}^2(\rho,\sigma)\le 0.99\,\epsilon
\quad\text{from}\quad
D_{\mathrm{HS}}^2(\rho,\sigma)>\epsilon
\]
with \(O(1/\epsilon^2)\) copies of each state. In this sense, tolerant certification entered the literature both as an explicit fidelity-gap decision problem and as a robust weak-membership problem for state neighborhoods.

Taken together, these formulations suggest that the core invariant across the literature is not a single preferred metric, but the presence of a nontrivial acceptance region around the target together with explicit finite-copy guarantees.

## 2. Finite-sample certification of leftover states and device-independent extractability

A major development is the shift from certifying a measured sample to certifying a *surviving ensemble*. In the finite-batch protocol of “Efficient and Device-Independent Active Quantum State Certification” [2407.13913], a source emits a finite sequence
\[
S=\{\sigma_1,\sigma_2,\dots,\sigma_N\},
\]
assumed **independent but not necessarily identical**. A verifier randomly extracts a subset of size \(\mu N\), measures only that subset, and certifies the average fidelity of the untouched remainder \((1-\mu)N\). The tolerated infidelity is
\[
\eta=1-F,
\]
and the task is explicitly to certify that the average quality of the unmeasured remainder exceeds \(1-\eta\), rather than to verify exact target-state preparation.

In the device-independent formulation, the relevant figure of merit is **extractability** \(\Xi\), equivalent to fidelity up to local isometries. The protocol converts a Bell inequality into a nonlocal game and uses a robust self-testing relation of the form
\[
P_\eta = P_{\mathrm{QM}} - c\eta,
\]
where \(P_{\mathrm{QM}}\) is the optimal quantum winning probability and \(c\) depends on the Bell game. If the measured subset attains empirical winning probability \(P_{\mathrm{exp}}\), then the false-certification probability is bounded by
\[
\delta \le e^{-D(P_{\mathrm{exp}\parallel P_\eta)\mu N},
\]
with
\[
D(x\parallel y)=x\log(x/y)+(1-x)\log\!\left(\frac{1-x}{1-y}\right),
\]
leading to the main finite-statistics guarantee
\[
C \ge 1-\delta = 1-e^{-D(P_{\mathrm{exp}\parallel P_\eta)\mu N}.
\]
This is a one-sided lower-confidence statement for the **unmeasured residual ensemble**. The same paper gives a sample-size formula
\[
N \ge \frac{\ln \delta}{\ln\!\bigl(1-\mu+\mu e^{D(P_{\mathrm{exp}\parallel P_\eta)}\bigr)}.
\]

The scaling depends on whether the nonlocal game has \(P_{\mathrm{QM}}=1\). If \(P_{\mathrm{QM}}<1\), as for CHSH with
\[
P_{\mathrm{QM}}=\frac{2+\sqrt{2}}{4}\approx 0.85,
\]
the certifiable infidelity scales only as \(N^{-1/2}\)-type. If \(P_{\mathrm{QM}}=1\), as in the GHZ/Mermin construction, one obtains near-\(N^{-1}\) scaling [2407.13913]. Experimentally, the paper reports that certifying Bell-state thresholds \(\eta=\{0.2,0.15,0.1,0.08\}\) at \(99\%\) confidence required verifier sample counts \(\{1420,3106,10019,20982\}\), while GHZ-state thresholds \(\eta=\{0.2,0.15,0.13,0.12\}\) required \(\{433,919,1562,2111\}\).

A closely related but stronger non-IID formulation appears in “Experimental Sample-Efficient and Device-Independent GHZ State Certification” [2407.13529]. There the source may produce an arbitrary joint \(N\)-copy state \(\sigma^N\), potentially correlated across rounds, and the goal is to certify the **conditional state**
\[
\tilde{\sigma}_c
\]
of a randomly retained unmeasured copy after all other outcomes are fixed. The certified quantity is the extractability
\[
\Xi(\tilde{\sigma}_c,\ket{GHZ}) = \max_{\Phi}\mathscr{F}(\Phi[\tilde{\sigma}_c],\ket{GHZ}) \ge 1-\eta.
\]
Using a four-party Mermin operator with
\[
\beta_Q=\beta_{\rm algebraic}=8,\qquad p_{QM}=1,
\]
and affine robust self-testing bound
\[
\Xi(\sigma,\ket{GHZ}) \ge 0.1875\,\beta - 0.5,
\]
the paper derives the finite-sample confidence formula
\[
\delta \leq \left(\frac{1}{N} + \frac{N-1}{N}e^{D(p_1\|p_2)}\right)^N.
\]
Its headline experiment certifies
\[
\Xi(\tilde{\sigma}_c,\ket{GHZ}) \ge 0.896
\]
from
\[
N=4643
\]
verified samples at confidence level
\[
1-\delta=0.99,
\]
with observed pass probability
\[
P=0.973.
\]

A common source of confusion is that these device-independent protocols do not certify raw Hilbert-space fidelity in a fixed representation. They certify **extractability up to local isometries**, and in the leftover-copy setting they certify either an average over an unmeasured remainder or the conditional state of a retained copy.

## 3. Witnesses, parent Hamiltonians, and confidence regions from incomplete data

Another major branch of tolerant certification is witness-based and Hamiltonian-based. In “Quantum State Certification via Effective Parent Hamiltonians from Local Measurement Data” [2603.04499], the target is a known pure state \(\ket{\psi}\), together with a positive semidefinite Hamiltonian \(H\) satisfying \(H\succeq 0\), \(\ker H=\Span\{\ket{\psi}\}\), and spectral gap \(\Delta\ge 1\). The key certification inequality is
\[
\bra{\psi}\rho\ket{\psi} \;\ge\; 1 - \frac{\Tr(H\rho)}{\Delta}.
\]
For Dicke states
\[
\ket{D_n^{(k)} = \binom{n}{k}^{-1/2}\sum_{|x|=k}\ket{x},
\]
the engineered parent Hamiltonian is
\[
H_n^{(k)} = \frac{1}{n} \sum_{j<\ell} (1 - S_{j\ell}) + (P - k \cdot 1)^2,
\]
with
\[
P = \sum_{j=1}^n \ket{1}_j\!\bra{1}.
\]
For \(W_n=\ket{D_n^{(1)}\), this yields a tomography-free three-setting protocol using global \(X\), \(Y\), and \(Z\) measurements, with certified lower bound
\[
F_n^{\mathrm{lb}=\max\{0,1-\langle H_n\rangle\}.
\]
Experimentally, the paper reports genuine multipartite entanglement certification for \(W_n\) up to six qubits and positive lower bounds on \(W_n\) fidelity up to thirteen qubits.

A more general finite-confidence framework from partial information appears in “Certification of quantum state functions under partial information” [2311.06094]. There the object of certification is a function \(\mathcal F(\omega)\) of an unknown state \(\omega\), such as a linear witness, Bell functional, or von Neumann entropy. Two confidence-region constructions are given. The individual-constraint method uses
\[
\bigl|\operatorname{tr}(O_i\rho)-o_i\bigr|\leq \epsilon_i
\]
for measured observables \(O_i\), while the joint-constraint method uses
\[
\sum_{i=1}^m \left| \operatorname{tr} (E_i \rho) - q_i \right| \leq \epsilon
\]
for POVM outcome frequencies. In both cases, optimization over the resulting confidence region gives finite-sample lower and upper bounds
\[
\mathcal F_{\rm LB}\le \mathcal F(\omega)\le \mathcal F_{\rm UB}
\]
with probability at least \(1-\delta\). This is tolerant certification in the sense of finite-confidence intervals for state properties rather than full-state identity.

A different notion of tolerance, focused on noise-induced distinguishability loss, was introduced much earlier in “Certifiability criterion for large-scale quantum systems” [1306.0370]. There the certifiability of a pure state \(|\psi\rangle\) under noise channel \(\mathcal E\) is
\[
C(|\psi\rangle, {\cal E}) := \min_{\left| \phi \right\rangle : \langle \psi | \phi\rangle  =0} D \left[ \mathcal{E}( \psi), \mathcal{E}( \phi  ) \right],
\]
with \(D(\rho,\sigma)=\lVert \rho-\sigma \rVert_{1}/2\). Under local white noise, GHZ states satisfy
\[
C(\mathrm{GHZ}) \le p^N,
\]
hence are asymptotically incertifiable, while unique ground states of local gapped Hamiltonians are asymptotically certifiable, with
\[
C(\psi)\geq p^k \Delta/2.
\]
This criterion is not a finite-sample certification protocol, but it sharply separates state families whose coherence remains certifiable under realistic noise from those whose coherence becomes experimentally indistinguishable from an incoherent mixture.

## 4. Photonic, bosonic, and linear-optical variants of tolerance

In photonic continuous-variable platforms, tolerant certification is often expressed through fidelity witnesses or code-space witnesses tailored to the measurement model. “Reliable quantum certification for photonic quantum technologies” [1407.4817] treats pure Gaussian states, pure linear-optical states generated from Fock inputs, and their locally post-selected variants. The certifier estimates a fidelity lower bound \(F^{(n)}\) and accepts iff
\[
F^{(n)*}\ge F_T+\varepsilon.
\]
The resulting test is explicitly **robust**: it rejects all states with fidelity \(F<F_T\) and accepts all states with
\[
F\ge F_T+\Delta,
\]
where
\[
\Delta\coloneqq\max\left\{\frac{2\varepsilon+(1-F_T)(\tilde n^\perp-1)}{\tilde n^\perp},\,2\varepsilon\right\}.
\]
For Gaussian targets the extremality-based lower bound is
\[
F\ge F^{(0)}\coloneqq 1-\langle \hat n\rangle_{\tilde\varrho_{\mathrm p}},
\]
and for linear-optical \(n\)-photon targets
\[
F\ge F^{(n)}\coloneqq 1-\left\langle (\hat n-n)\prod_{j=1}^n \hat n_j\right\rangle_{\tilde\varrho_{\mathrm p}}.
\]
The protocol uses only single-mode homodyne detection, is efficient in the number of modes \(m\) for Gaussian targets, and remains efficient for linear-optical targets at constant input photon number \(n\).

“Reliable Quantum Certification of Bosonic Code Preparations” [2211.16777] constructs analogous witnesses for bosonic codes. For the two-component cat code, the witness is
\[
W_{tCat} = \mathds{1} -\frac{(\hat a^{\dagger 2}-\alpha^{*2})(\hat a^2-\alpha^2)}{2},
\]
with
\[
W_{tCat}\le P_{\bar{\mathcal H}_{tCat}},
\qquad
\operatorname{Tr}(P_{\bar{\mathcal H}_{tCat}}\rho)\ge \langle W_{tCat}\rangle_\rho.
\]
Thus \(\langle W_{tCat}\rangle_\rho\) lower-bounds code-space overlap. The paper extends the same strategy to four-component cat states, squeezed cat states, and realistic GKP states with finite squeezing and finite phase-space truncation, all estimated from Gaussian measurements or, in some cases, parity measurement plus Gaussian measurements. Here tolerance is built into the target model itself: certification addresses realistic finite-energy code states rather than exact idealized codewords.

A distinct photonic notion appears in “Certification of linear optical quantum state preparation” [2602.12269]. In LOQC, the relevant target is not a single fixed state but an LOQC equivalence class determined by indistinguishability data. Accordingly, the paper defines
\[
F_\mathrm{LO}(\rho,\rho_t) = \max_{\tau\sim\rho_t} F(\rho,\tau),
\]
and
\[
D_\mathrm{LO}(\rho,\rho_t) = \min_{\tau\sim\rho_t} D(\rho,\tau).
\]
This is tolerant certification in a stronger operational sense: the protocol certifies closeness to the nearest state in the LOQC-equivalence class, not to one arbitrarily chosen microscopic representative. This suggests that in photonic many-body platforms, the correct notion of “distance to target” can itself be task-dependent.

## 5. Restricted-measurement and gentle-measurement regimes

Several recent works ask how much tolerance survives under severe measurement restrictions. “Few Single-Qubit Measurements Suffice to Certify Any Quantum State” [2506.11355] proves that every pure \(n\)-qubit target can be certified using only adaptive single-qubit measurements, with
\[
O\!\left(n\varepsilon^{-1}\ln(1/\delta)\right)
\]
copies and
\[
O\!\left(n^2\varepsilon^{-1}\ln(1/\delta)\right)
\]
single-qubit measurements. The guarantee, however, is only
\[
\bra{\psi_{\mathrm{tar}}}\rho_{\mathrm{lab}}\ket{\psi_{\mathrm{tar}} \ge 1-\frac{\varepsilon}{2n}
\quad\text{vs.}\quad
\bra{\psi_{\mathrm{tar}}}\rho_{\mathrm{lab}}\ket{\psi_{\mathrm{tar}} \le 1-\varepsilon,
\]
so the test is explicitly only \(1/n\)-tolerant. The paper identifies improving this \(1/n\) loss as an open problem.

That open problem is partially resolved, for almost all pure target states, in “The Power of Two Bases: Robust and copy-optimal certification of nearly all quantum states with few-qubit measurements” [2602.11616]. Its first protocol uses one \(O(\log n)\)-qubit measurement together with single-qubit \(Z\)- or \(X\)-basis measurements on the other qubits. For all but an \(O(2^{-n})\)-fraction of pure target states, if a state \(\rho\) passes with probability \(1-\epsilon\), then
\[
\bra{\psi}\rho\ket{\psi}\ge 1-(2+o(1))\epsilon.
\]
After repetition, the copy complexity becomes
\[
O\!\left(\epsilon^{-2}\log(1/\delta)\right),
\]
which the paper identifies as copy-optimal. Its second protocol uses exclusively single-qubit measurements and achieves nearly robust behavior:
\[
\Pr[\mathrm{reject}] \ge \frac{1-\bra{\psi}\rho\ket{\psi}}{(2+o(1))\log n},
\]
so the positive-certification radius improves from \(O(1/n)\) to \(\Omega(1/\log n)\). The technical basis is a new uncertainty principle for conditional fidelities across the computational and Hadamard bases.

A different measurement constraint is analyzed in “Locally Gentle State Certification for High Dimensional Quantum Systems” [2602.04550]. There the standard identity-testing task
\[
H_0:\rho=\rho_0
\qquad\text{vs.}\qquad
H_1:\|\rho-\rho_0\|_{\mathrm{tr}}>\varepsilon
\]
is studied under the requirement that each local measurement be \(\alpha\)-gentle, meaning that for every outcome \(y\),
\[
\|\rho-\rho_{M\to y}\|_{\mathrm{tr}}\le \alpha.
\]
For the maximally mixed reference \(\rho_0=I/d\), fixed unentangled locally-\(\alpha\)-gentle measurements have minimax sample complexity
\[
n=\Theta\!\left(\frac{d^3}{\varepsilon^2\alpha^2}\right).
\]
The paper also proves a close relation between local gentleness and local quantum differential privacy, including
\[
\alpha=\tanh(\delta/4)
\]
for the implication from local-\(\delta\)-qDP to an \(\alpha\)-gentle implementation. This is not tolerant certification in the usual promise-gap sense; it is tolerance with respect to **measurement-induced disturbance**.

## 6. Device models, computational outputs, and conceptual boundaries

The literature also differs sharply in device model. “Certifying bipartite pure quantum states efficiently using untrusted devices” [2306.07755] assumes the local dimension \(d\) is known and shows that arbitrary \(d\times d\) bipartite pure states can be certified from a single local measurement setting per party, with untrusted measurements and robustness
\[
F(\rho,\Phi_d)\ge 1-O(d^{4}\epsilon^{1/8})
\]
for the maximally entangled-state protocol. This is semi-device-independent rather than fully device-independent, and the equivalence notion is up to local unitaries rather than general local isometries.

“Local certification of programmable quantum devices of arbitrary high dimensionality” [1911.09448] treats a single programmable black box in a contextuality scenario. Its guarantee is a robust self-testing statement:
\[
\left\| V|u_i\rangle\!\langle u_i|V^\dagger - |u_i'\rangle\!\langle u_i'| \right\| \le \mathcal O(\sqrt{\epsilon}),
\]
for near-optimal contextuality witness value. This is tolerant in the robust-self-testing sense, but it does not provide a finite-sample accept/reject theorem. Likewise, “Device-independent certification of tensor products of quantum states using single-copy self-testing protocols” [1909.12759] shows how to transform single-copy self-tests into tensor-product certification with constant measurement choices, but its main theorems are exact and its robustness analysis is limited.

A further expansion of scope appears when certification is attached to a computational process rather than a static preparation. “Logical accreditation: a framework for efficient certification of fault-tolerant computations” [2508.05523] certifies logical output distributions of fault-tolerant circuits and then derives a state-quality consequence:
\[
1 - F(\rho_{out,id}, \rho_{out}) \leq \gamma.
\]
The accreditation bound \(\gamma\) is estimated from trap circuits, with trap number requirement
\[
M>\frac{2}{\epsilon^2}\log\!\left(\frac{4}{1-\alpha}\right).
\]
This is not direct state verification of an arbitrary logical state, but it is a rigorous tolerant state certificate for logical circuit outputs when the ideal output state is pure.

Finally, “Certifying localizable quantum properties with constant sample complexity” [2509.17580] argues that many global properties are preserved in projected ensembles on small subsystems. Its witness gap is the localizable-quantumness quantity
\[
\mathrm{LQ}_{\mathsf P}(\psi) = \sum_{\bm z} p_\psi(\bm z)\bigl[1-\mathrm{Fid}_{\mathsf P}(\psi_{\bm z})\bigr].
\]
If \(\mathrm{LQ}_{\mathsf P}(\psi)=\Omega(1)\) and the retained subsystem size \(n_A=O(1)\), then the framework gives constant sample complexity and constant trace-distance tolerance for certifying properties such as entanglement, circuit complexity, or magic. Its random-basis fidelity variant proves positivity of a spectral gap \(\Delta(O_\psi)\) for Haar-random states, while constant-\(\Delta\) behavior for generic states is supported numerically rather than proved.

Taken together, these developments suggest that “tolerant quantum state certification” has become an umbrella term for several distinct but related tasks: promise-gap fidelity testing relative to a known reference, finite-confidence lower bounds on an unmeasured remainder, device-independent extractability certification up to local isometries, witness-based certification of structured states or state functions, certification under restricted or gentle measurements, and computational accreditation that induces certified output-state infidelity bounds. The main conceptual boundary is therefore not between tolerant and non-tolerant methods alone, but between incompatible operational targets: full-state identity, equivalence-class certification, code-space membership, property certification, and certification of a leftover or computational output.

Source: https://www.emergentmind.com/topics/tolerant-quantum-state-certification