- Open Access
Adaptively Secure Unitary Designs with Constant Non-Clifford Cost
Phys. Rev. Lett. 136, 210802 – Published 28 May, 2026
DOI: https://doi.org/10.1103/9hcw-7fl6
Abstract
Randomness is a fundamental resource in quantum information, with crucial applications in cryptography, algorithms, and error correction. A central challenge is to construct unitary designs that closely approximate Haar-random unitaries while minimizing the costly use of non-Clifford operations. In this Letter, we present a protocol able to generate unitary designs on qubits, secure against any adversarial quantum measurement, with a system-size-independent number of non-Clifford gates. Our construction applies a design only to a subsystem of size , independent of . This “seed” design is then “diluted” across the entire -qubit system by sandwiching it between two random Clifford operators. The resulting ensemble forms an -approximate unitary design on qubits. We prove that this construction achieves full quantum security against adaptive adversaries using only non-Clifford gates. If one requires security only against polynomial-time adaptive adversaries, the non-Clifford cost decreases to . This is optimal, since we show that at least non-Clifford gates are required in this setting. Compared to existing approaches, our method significantly reduces non-Clifford overhead while strengthening security guarantees to adaptive security as well as removing artificial assumptions between and . These results make high-order unitary designs practically attainable in near-term fault-tolerant quantum architectures.
Physics Subject Headings (PhySH)
Article Text
Supplemental Material
References (63)
- A. Ambainis and A. Smith, in Proceedings of RANDOM’04, Lecture Notes in Computer Science Vol. 3122 (Springer, New York, 2004), pp. 249–260.
- W. Kretschmer, in TQC 2021 (Leibniz International Proceeding in Informatics (LIPIcs), Latvia, 2021), Vol. 197, pp. 2:1–2:20.
- P. Sen, in 21st Annual IEEE Conference on Computational Complexity (CCC’06) (IEEE, Prague, 2006), pp. 14–287.
- F. G. S. L. Brandão and M. Horodecki, Quantum Inf. Comput. 13, 901 (2013).
- R. Kueng, H. Zhu, and D. Gross, arXiv:1609.08595.
- J. Eisert, D. Hangleiter, N. Walk, I. Roth, D. Markham, R. Parekh, U. Chabaud, and E. Kashefi, Nat. Rev. Phys. 2, 382 (2020).
- I. Devetak and A. Winter, Phys. Rev. Lett. 93, 080501 (2004).
- B. Groisman, S. Popescu, and A. Winter, Phys. Rev. A 72, 032317 (2005).
- S. Popescu, A. J. Short, and A. Winter, Nat. Phys. 2, 754 (2006).
- P. Hayden and J. Preskill, J. High Energy Phys. 09 (2007) 120.
- Y. Sekino and L. Susskind, J. High Energy Phys. 10 (2008) 065.
- A. Munson, N. B. T. Kothakonda, J. Haferkamp, N. Yunger Halpern, J. Eisert, and P. Faist, PRX Quantum 6, 010346 (2025).
- E. Knill, Approximation by quantum circuits, arXiv:quant-ph/9508006.
- J. Emerson, Y. S. Weinstein, M. Saraceno, S. Lloyd, and D. G. Cory, Science 302, 2098 (2003).
- D. Gross, K. Audenaert, and J. Eisert, J. Math. Phys. (N.Y.) 48, 052104 (2007).
- Z. Ji, Y.-K. Liu, and F. Song, Pseudorandom quantum states, in Advances in Cryptology—CRYPTO 2018 (Springer International Publishing, New York, 2018), pp. 126–152.
- T. Haug, K. Bharti, and D. E. Koh, Quantum 9, 1759 (2025).
- T. Metger, A. Poremba, M. Sinha, and H. Yuen, arXiv:2402.14803.
- T. Schuster, J. Haferkamp, and H.-Y. Huang, arXiv:2407.07754.
- F. Ma and H.-Y. Huang, arXiv:2410.10116.
- T. Haug, K. Bharti, and D. E. Koh, arXiv:2306.11677.
- N. LaRacuente and F. Leditzky, arXiv:2407.07876.
- B. Eastin and E. Knill, Phys. Rev. Lett. 102, 110502 (2009).
- D. Gottesman, Stabilizer codes and quantum error correction, Ph.D. thesis, California Institute of Technology, 1997.
- S. Bravyi and J. Haah, Phys. Rev. A 86, 052329 (2012).
- A. Krishna and J.-P. Tillich, Phys. Rev. Lett. 123, 070507 (2019).
- K. Fang and Z.-W. Liu, arXiv:2410.14547.
- Q. T. Nguyen, in Proceedings of the 57th Annual ACM Symposium on Theory of Computing (Association for Computing Machinery, New York, 2025), pp. 697–706.
- L. Golowich and V. Guruswami, in Proceedings of the 57th Annual ACM Symposium on Theory of Computing (2025), pp. 707–717.
- A. Wills, M.-H. Hsieh, and H. Yamasaki, Nat. Phys. 21, 1842 (2025).
- See Supplemental Material at http://link.aps.org/supplemental/10.1103/9hcw-7fl6 for details of the proofs, which includes Refs. [9,14,19,32–55].
- J. Haferkamp, F. Montealegre-Mora, M. Heinrich, J. Eisert, D. Gross, and I. Roth, Commun. Math. Phys. 397, 995 (2023).
- L. Leone, S. F. E. Oliviero, A. Hamma, J. Eisert, and L. Bittel, arXiv:2505.10110.
- Y. Zhang, S. Vijay, Y. Gu, and Y. Bao, PRX Quantum 7, 010344 (2026).
- F. G. S. L. Brandão, A. W. Harrow, and M. Horodecki, Commun. Math. Phys. 346, 397 (2016).
- F. Ma and H.-Y. Huang, arXiv:2410.10116.
- L. Bittel, J. Eisert, L. Leone, A. A. Mele, and S. F. E. Oliviero, arXiv:2504.12263.
- L. Bittel and L. Leone, Quantum 10, 2069 (2026).
- L. Cui, T. Schuster, F. Brandao, and H.-Y. Huang, arXiv:2507.06216.
- C. Moore and M. Nilsson, arXiv:quant-ph/9808027.
- J. Jiang, X. Sun, S.-H. Teng, B. Wu, K. Wu, and J. Zhang, arXiv:1907.05087.
- L. Grevink, J. Haferkamp, M. Heinrich, J. Helsen, M. Hinsche, T. Schuster, and Z. Zimborás, arXiv:2506.23925.
- J. Emerson, R. Alicki, and K. Życzkowski, J. Opt. B 7, S347 (2005).
- A. W. Harrow and R. A. Low, Commun. Math. Phys. 291, 257 (2009).
- J. Haferkamp, arXiv:2203.16571.
- D. Gross, K. Audenaert, and J. Eisert, J. Math. Phys. (N.Y.) 48, 052104 (2007).
- B. Magni, A. Christopoulos, A. De Luca, and X. Turkeshi, Phys. Rev. X 15, 031071 (2025).
- D. Weingarten, J. Math. Phys. (N.Y.) 19, 999 (1978).
- A. F. Mello, A. Santini, G. Lami, J. De Nardis, and M. Collura, Phys. Rev. Lett. 134, 150403 (2025).
- R. A. Low, Phys. Rev. A 80, 052314 (2009).
- D. E. Knuth et al., The Art of Computer Programming (Pearson Education India, Upper Saddle River, 1997), Vol. 1, 3/E.
- S. Aaronson and D. Gottesman, Phys. Rev. A 70, 052328 (2004).
- A. Gu, L. Leone, K. Goodenough, and S. Khatri, arXiv:2502.09483.
- L. Leone, S. F. E. Oliviero, S. Lloyd, and A. Hamma, Phys. Rev. A 109, 022429 (2024).
- S. F. E. Oliviero, L. Leone, S. Lloyd, and A. Hamma, Phys. Rev. Lett. 132, 080402 (2024).
The notation denotes , i.e. the usual big- (or Landau) notation up to poly-logarithmic factors.
- A. W. Harrow and R. A. Low, Commun. Math. Phys. 291, 302 (2009).
A very recent work [39] introduced the notion of quantum-secure designs (referred to as measurable-error designs), with the primary goal of minimizing circuit depth. However, with respect to gate count, their results offer no asymptotic improvement over relative-error designs, as both require gates. In sharp contrast, our results show that when it comes to non-Clifford cost, relative-error designs impose an unnecessary burden: they require non-Clifford gates, whereas the practically motivated quantum-secure designs of Definition t1 need only .
- Z. Ji, Y.-K. Liu, and F. Song, in Advances in Cryptology—CRYPTO 2018, Lecture Notes in Computer Science, edited by H. Shacham and A. Boldyreva (Springer International Publishing, Cham, 2018), pp. 126–152.
- Z. Webb, Quantum Inf. Comput. 16, 1379 (2016).
- H. Zhu, Phys. Rev. A 96, 062336 (2017).
The dependence on the resolution error can be improved to by using extra qubits, using the construction of Ref. [39]; see Supplemental Material [31] for details.
- L. Leone, S. F. E. Oliviero, and A. Hamma, Quantum 8, 1361 (2024).