Reuse & Permissions

It is not necessary to obtain permission to reuse this article or its components as it is available under the terms of the Creative Commons Attribution 4.0 International license. This license permits unrestricted use, distribution, and reproduction in any medium, provided attribution to the author(s) and the published article's title, journal citation, and DOI are maintained. Please note that some figures may have been included with permission from other third parties. It is your responsibility to obtain the proper permission from the rights holder directly for these figures.

Export citation

Export citation

Choose format for download:

Download Citation
  • Open Access

Adaptively Secure Unitary Designs with Constant Non-Clifford Cost

Lennart Bittel1,*,† and Lorenzo Leone1,2,*,‡

  • *These authors contributed equally to this work.
  • †Contact author: l.bittel@fu-berlin.de
  • ‡Contact author: loleone@unisa.it

Phys. Rev. Lett. 136, 210802 – Published 28 May, 2026

DOI: https://doi.org/10.1103/9hcw-7fl6

Abstract

Randomness is a fundamental resource in quantum information, with crucial applications in cryptography, algorithms, and error correction. A central challenge is to construct unitary k designs that closely approximate Haar-random unitaries while minimizing the costly use of non-Clifford operations. In this Letter, we present a protocol able to generate unitary k designs on n qubits, secure against any adversarial quantum measurement, with a system-size-independent number of non-Clifford gates. Our construction applies a k design only to a subsystem of size Θ(k), independent of n. This “seed” design is then “diluted” across the entire n-qubit system by sandwiching it between two random Clifford operators. The resulting ensemble forms an ϵ-approximate unitary k design on n qubits. We prove that this construction achieves full quantum security against adaptive adversaries using only O˜(k2logϵ−1) non-Clifford gates. If one requires security only against polynomial-time adaptive adversaries, the non-Clifford cost decreases to O˜(k+log1+cϵ−1). This is optimal, since we show that at least Ω(k) non-Clifford gates are required in this setting. Compared to existing approaches, our method significantly reduces non-Clifford overhead while strengthening security guarantees to adaptive security as well as removing artificial assumptions between n and k. These results make high-order unitary designs practically attainable in near-term fault-tolerant quantum architectures.

View figure in article

Physics Subject Headings (PhySH)

Article Text

Supplemental Material

References (63)

  1. A. Ambainis and A. Smith, in Proceedings of RANDOM’04, Lecture Notes in Computer Science Vol. 3122 (Springer, New York, 2004), pp. 249–260.
  2. W. Kretschmer, in TQC 2021 (Leibniz International Proceeding in Informatics (LIPIcs), Latvia, 2021), Vol. 197, pp. 2:1–2:20.
  3. P. Sen, in 21st Annual IEEE Conference on Computational Complexity (CCC’06) (IEEE, Prague, 2006), pp. 14–287.
  4. F. G. S. L. Brandão and M. Horodecki, Quantum Inf. Comput. 13, 901 (2013).
  5. R. Kueng, H. Zhu, and D. Gross, arXiv:1609.08595.
  6. J. Eisert, D. Hangleiter, N. Walk, I. Roth, D. Markham, R. Parekh, U. Chabaud, and E. Kashefi, Nat. Rev. Phys. 2, 382 (2020).
  7. I. Devetak and A. Winter, Phys. Rev. Lett. 93, 080501 (2004).
  8. B. Groisman, S. Popescu, and A. Winter, Phys. Rev. A 72, 032317 (2005).
  9. S. Popescu, A. J. Short, and A. Winter, Nat. Phys. 2, 754 (2006).
  10. P. Hayden and J. Preskill, J. High Energy Phys. 09 (2007) 120.
  11. Y. Sekino and L. Susskind, J. High Energy Phys. 10 (2008) 065.
  12. A. Munson, N. B. T. Kothakonda, J. Haferkamp, N. Yunger Halpern, J. Eisert, and P. Faist, PRX Quantum 6, 010346 (2025).
  13. E. Knill, Approximation by quantum circuits, arXiv:quant-ph/9508006.
  14. J. Emerson, Y. S. Weinstein, M. Saraceno, S. Lloyd, and D. G. Cory, Science 302, 2098 (2003).
  15. D. Gross, K. Audenaert, and J. Eisert, J. Math. Phys. (N.Y.) 48, 052104 (2007).
  16. Z. Ji, Y.-K. Liu, and F. Song, Pseudorandom quantum states, in Advances in Cryptology—CRYPTO 2018 (Springer International Publishing, New York, 2018), pp. 126–152.
  17. T. Haug, K. Bharti, and D. E. Koh, Quantum 9, 1759 (2025).
  18. T. Metger, A. Poremba, M. Sinha, and H. Yuen, arXiv:2402.14803.
  19. T. Schuster, J. Haferkamp, and H.-Y. Huang, arXiv:2407.07754.
  20. F. Ma and H.-Y. Huang, arXiv:2410.10116.
  21. T. Haug, K. Bharti, and D. E. Koh, arXiv:2306.11677.
  22. N. LaRacuente and F. Leditzky, arXiv:2407.07876.
  23. B. Eastin and E. Knill, Phys. Rev. Lett. 102, 110502 (2009).
  24. D. Gottesman, Stabilizer codes and quantum error correction, Ph.D. thesis, California Institute of Technology, 1997.
  25. S. Bravyi and J. Haah, Phys. Rev. A 86, 052329 (2012).
  26. A. Krishna and J.-P. Tillich, Phys. Rev. Lett. 123, 070507 (2019).
  27. K. Fang and Z.-W. Liu, arXiv:2410.14547.
  28. Q. T. Nguyen, in Proceedings of the 57th Annual ACM Symposium on Theory of Computing (Association for Computing Machinery, New York, 2025), pp. 697–706.
  29. L. Golowich and V. Guruswami, in Proceedings of the 57th Annual ACM Symposium on Theory of Computing (2025), pp. 707–717.
  30. A. Wills, M.-H. Hsieh, and H. Yamasaki, Nat. Phys. 21, 1842 (2025).
  31. See Supplemental Material at http://link.aps.org/supplemental/10.1103/9hcw-7fl6 for details of the proofs, which includes Refs. [9,14,19,32–55].
  32. J. Haferkamp, F. Montealegre-Mora, M. Heinrich, J. Eisert, D. Gross, and I. Roth, Commun. Math. Phys. 397, 995 (2023).
  33. L. Leone, S. F. E. Oliviero, A. Hamma, J. Eisert, and L. Bittel, arXiv:2505.10110.
  34. Y. Zhang, S. Vijay, Y. Gu, and Y. Bao, PRX Quantum 7, 010344 (2026).
  35. F. G. S. L. Brandão, A. W. Harrow, and M. Horodecki, Commun. Math. Phys. 346, 397 (2016).
  36. F. Ma and H.-Y. Huang, arXiv:2410.10116.
  37. L. Bittel, J. Eisert, L. Leone, A. A. Mele, and S. F. E. Oliviero, arXiv:2504.12263.
  38. L. Bittel and L. Leone, Quantum 10, 2069 (2026).
  39. L. Cui, T. Schuster, F. Brandao, and H.-Y. Huang, arXiv:2507.06216.
  40. C. Moore and M. Nilsson, arXiv:quant-ph/9808027.
  41. J. Jiang, X. Sun, S.-H. Teng, B. Wu, K. Wu, and J. Zhang, arXiv:1907.05087.
  42. L. Grevink, J. Haferkamp, M. Heinrich, J. Helsen, M. Hinsche, T. Schuster, and Z. Zimborás, arXiv:2506.23925.
  43. J. Emerson, R. Alicki, and K. Życzkowski, J. Opt. B 7, S347 (2005).
  44. A. W. Harrow and R. A. Low, Commun. Math. Phys. 291, 257 (2009).
  45. J. Haferkamp, arXiv:2203.16571.
  46. D. Gross, K. Audenaert, and J. Eisert, J. Math. Phys. (N.Y.) 48, 052104 (2007).
  47. B. Magni, A. Christopoulos, A. De Luca, and X. Turkeshi, Phys. Rev. X 15, 031071 (2025).
  48. D. Weingarten, J. Math. Phys. (N.Y.) 19, 999 (1978).
  49. A. F. Mello, A. Santini, G. Lami, J. De Nardis, and M. Collura, Phys. Rev. Lett. 134, 150403 (2025).
  50. R. A. Low, Phys. Rev. A 80, 052314 (2009).
  51. D. E. Knuth et al., The Art of Computer Programming (Pearson Education India, Upper Saddle River, 1997), Vol. 1, 3/E.
  52. S. Aaronson and D. Gottesman, Phys. Rev. A 70, 052328 (2004).
  53. A. Gu, L. Leone, K. Goodenough, and S. Khatri, arXiv:2502.09483.
  54. L. Leone, S. F. E. Oliviero, S. Lloyd, and A. Hamma, Phys. Rev. A 109, 022429 (2024).
  55. S. F. E. Oliviero, L. Leone, S. Lloyd, and A. Hamma, Phys. Rev. Lett. 132, 080402 (2024).
  56. The notation O˜ denotes O˜(f(n))=O(f(n)polylogf(n)), i.e. the usual big-O (or Landau) notation up to poly-logarithmic factors.

  57. A. W. Harrow and R. A. Low, Commun. Math. Phys. 291, 302 (2009).
  58. A very recent work [39] introduced the notion of quantum-secure designs (referred to as measurable-error designs), with the primary goal of minimizing circuit depth. However, with respect to gate count, their results offer no asymptotic improvement over relative-error designs, as both require Θ(nk) gates. In sharp contrast, our results show that when it comes to non-Clifford cost, relative-error designs impose an unnecessary burden: they require Ω(n) non-Clifford gates, whereas the practically motivated quantum-secure designs of Definition t1 need only O(1).

  59. Z. Ji, Y.-K. Liu, and F. Song, in Advances in Cryptology—CRYPTO 2018, Lecture Notes in Computer Science, edited by H. Shacham and A. Boldyreva (Springer International Publishing, Cham, 2018), pp. 126–152.
  60. Z. Webb, Quantum Inf. Comput. 16, 1379 (2016).
  61. H. Zhu, Phys. Rev. A 96, 062336 (2017).
  62. The dependence on the resolution error ϵ can be improved to O˜(k2logϵ−1) by using O˜(k2) extra qubits, using the construction of Ref. [39]; see Supplemental Material [31] for details.

  63. L. Leone, S. F. E. Oliviero, and A. Hamma, Quantum 8, 1361 (2024).

Outline

Information

Sign In to Your Journals Account

Filter

Filter

Article Lookup

Enter a citation