- Open Access
Quantum-Secure Multiparty Deep Learning
Phys. Rev. X 15, 041056 – Published 24 December, 2025
DOI: https://doi.org/10.1103/k8wg-qmbh
Abstract
Secure multiparty computation enables the joint evaluation of multivariate functions across distributed users while ensuring the privacy of their local inputs. This field has become urgent due to the demand for computationally intensive deep learning inference. These computations are typically offloaded to cloud servers, leading to vulnerabilities. To solve this problem, we introduce a linear algebra engine that leverages the quantum nature of light for information-theoretically secure multiparty inference using telecommunication components. We apply this linear algebra engine to deep learning and derive rigorous upper bounds on the information leakage of both the deep neural network weights and the client’s data, enabling double-blind operations. Applied to the modified National Institute of Standards and Technology classification task, we obtain test accuracies exceeding 95% while guaranteeing leakage of less than 0.1 bits per weight and data element. This leakage is an order of magnitude below the minimum bit precision required for accurate deep learning using state-of-the-art quantization techniques. Our work lays the foundation for practical quantum-secure computation and unlocks secure cloud deep learning as a field.
Physics Subject Headings (PhySH)
- Analog computation
- Artificial intelligence
- Communication schemes
- Information & communication theory
- Neuromorphic computing
- Physics of computation
- Quantum algorithms & computation
- Quantum communication, protocols & technology
- Quantum information processing
- Quantum information theory
- Quantum optics
- Shannon entropy
Popular Summary
The demand for secure computing is becoming increasingly urgent as more data-intensive tasks, like deep learning, are outsourced to cloud servers. This poses serious privacy risks, particularly for sensitive information in fields such as finance, health care, and business. Our research addresses the crucial question: Can we use the power of artificial intelligence (AI) and big data without compromising privacy? We discover that the answer is yes, thanks to our new approach that combines AI with the security advantages of quantum mechanics.
In our work, we developed a quantum-secure computation protocol that allows multiple parties to collaborate on complex AI computations while ensuring that neither proprietary data nor machine learning models get exposed to the other parties. Our protocol is powered by the quantum properties of light and is readily implemented using present-day photonics. We derive analytical upper bounds for information leakage of the data and models and demonstrate the protocol performance on benchmark tasks. Our solution also directly addresses the severe scaling limitations of classical secure-computation approaches.
Looking ahead, this quantum-secure deep learning approach opens the door to safer AI technologies for sectors where privacy is paramount. Future research could perform joint optimization of model parameters and protocol steps to further improve the accuracy and security. Furthermore, artificial intelligence-based tools can provide tighter upper bounds for information leakage. Lastly, integrating our secure computation protocol with quantum resources may pave the way to quantum computational advantages.
Article Text
References (128)
- Y. LeCun, Y. Bengio, and G. Hinton, Deep learning, Nature (London) 521, 436 (2015).
- O. Vinyals, I. Babuschkin, W. M. Czarnecki, M. Mathieu, A. Dudzik, J. Chung, D. H. Choi, R. Powell, T. Ewalds, P. Georgiev et al., Grandmaster level in starcraft II using multi-agent reinforcement learning, Nature (London) 575, 350 (2019).
- T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell et al., Language models are few-shot learners, Adv. Neural Inf. Process. Syst. 33, 1877 (2020).
- P. Li, J. Li, Z. Huang, T. Li, C.-Z. Gao, S.-M. Yiu, and K. Chen, Multi-key privacy-preserving deep learning in cloud computing, Future Gener. Comput. Syst. 74, 76 (2017).
- M. Satyanarayanan, The emergence of edge computing, Computer 50, 30 (2017).
- U. A. Butt, M. Mehmood, S. B. H. Shah, R. Amin, M. W. Shaukat, S. M. Raza, D. Y. Suh, and M. J. Piran, A review of machine learning algorithms for cloud computing security, Electronics 9, 1379 (2020).
- V. Sze, Y.-H. Chen, T.-J. Yang, and J. S. Emer, Efficient processing of deep neural networks: A tutorial and survey, Proc. IEEE 105, 2295 (2017).
- T.-J. Yang, Y.-H. Chen, J. Emer, and V. Sze, A method to estimate the energy consumption of deep neural networks, in Proceedings of the 2017 51st Asilomar Conference on Signals, Systems, and Computers (IEEE, New York, 2017), pp. 1916–1920.
- D. Patterson, J. Gonzalez, Q. Le, C. Liang, L.-M. Munguia, D. Rothchild, D. So, M. Texier, and J. Dean, Carbon emissions and large neural network training, arXiv:2104.10350.
- A. C. Yao, Protocols for secure computations, in Proceedings of the 23rd Annual Symposium on Foundations of Computer Science (sfcs 1982) (IEEE, New York, 1982), pp. 160–164.
- C. Gentry, Fully homomorphic encryption using ideal lattices, in Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing (Association for Computing Machinery, New York, 2009), pp. 169–178.
- J. H. Cheon, A. Kim, M. Kim, and Y. Song, Homomorphic encryption for arithmetic of approximate numbers, in Advances in Cryptology–ASIACRYPT 2017: Proceedings of the 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, 2017, Part I (Springer, New York, 2017), pp. 409–437.
- B. Li and D. Micciancio, On the security of homomorphic encryption on approximate numbers, in Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques (Springer, New York, 2021), pp. 648–677.
- C. Portmann and R. Renner, Security in quantum cryptography, Rev. Mod. Phys. 94, 025008 (2022).
- N. H. Y. Ng, S. K. Joshi, C. Chen Ming, C. Kurtsiefer, and S. Wehner, Experimental implementation of bit commitment in the noisy-storage model, Nat. Commun. 3, 1326 (2012).
- V. Vilasini, C. Portmann, and L. Del Rio, Composable security in relativistic quantum cryptography, New J. Phys. 21, 043057 (2019).
- A. Chailloux and I. Kerenidis, Optimal quantum strong coin flipping, in Proceedings of the 2009 50th Annual IEEE Symposium on Foundations of Computer Science (IEEE, New York, 2009), pp. 527–533.
- A. Pappa, P. Jouguet, T. Lawson, A. Chailloux, M. Legré, P. Trinkler, I. Kerenidis, and E. Diamanti, Experimental plug and play quantum coin flipping, Nat. Commun. 5, 3717 (2014).
- D. Unruh, Universally composable quantum multi-party computation, in Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques (Springer, New York, 2010), pp. 486–505.
- S. Wehner, C. Schaffner, and B. M. Terhal, Cryptography from noisy storage, Phys. Rev. Lett. 100, 220502 (2008).
- R. Konig, S. Wehner, and J. Wullschleger, Unconditional security from noisy quantum storage, IEEE Trans. Inf. Theory 58, 1962 (2012).
- C. Erven, N. Ng, N. Gigov, R. Laflamme, S. Wehner, and G. Weihs, An experimental implementation of oblivious transfer in the noisy storage model, Nat. Commun. 5, 3418 (2014).
- M. B. Santos, P. Mateus, and A. N. Pinto, Quantum oblivious transfer: A short review, Entropy 24, 945 (2022).
- C. Li, B. Li, O. Amer, R. Shaydulin, S. Chakrabarti, G. Wang, H. Xu, H. Tang, I. Schoch, N. Kumar et al., Blind quantum machine learning with quantum bipartite correlator, Phys. Rev. Lett. 133, 120602 (2024).
- C. Crépeau, D. Gottesman, and A. Smith, Secure multi-party quantum computation, in Proceedings of the Thirty-Fourth Annual ACM Symposium on Theory of Computing (Association for Computing Machinery, New York, 2002), pp. 643–652.
- M. Ben-Or, C. Crépeau, D. Gottesman, A. Hassidim, and A. Smith, Secure multiparty quantum computation with (only) a strict honest majority, in Proceedings of the 2006 47th Annual IEEE Symposium on Foundations of Computer Science (FOCS’06) (IEEE, New York, 2006), pp. 249–260.
- F. Dupuis, J. B. Nielsen, and L. Salvail, Actively secure two-party evaluation of any quantum operation, in Proceedings of the Annual Cryptology Conference (Springer, New York, 2012) pp. 794–811.
- Y. Dulek, A. B. Grilo, S. Jeffery, C. Majenz, and C. Schaffner, Secure multi-party quantum computation with a dishonest majority, in Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques (Springer, New York, 2020), pp. 729–758.
- V. Lipinska, J. Ribeiro, and S. Wehner, Secure multiparty quantum computation with few qubits, Phys. Rev. A 102, 022405 (2020).
- A. Broadbent, J. Fitzsimons, and E. Kashefi, Universal blind quantum computation, in Proceedings of the 2009 50th Annual IEEE Symposium on Foundations of Computer Science (IEEE, New York, 2009), pp. 517–526.
- V. Dunjko, E. Kashefi, and A. Leverrier, Blind quantum computing with weak coherent pulses, Phys. Rev. Lett. 108, 200502 (2012).
- S. Barz, E. Kashefi, A. Broadbent, J. F. Fitzsimons, A. Zeilinger, and P. Walther, Demonstration of blind quantum computing, Science 335, 303 (2012).
- V. Giovannetti, L. Maccone, T. Morimae, and T. G. Rudolph, Efficient universal blind quantum computation, Phys. Rev. Lett. 111, 230501 (2013).
- J. F. Fitzsimons and E. Kashefi, Unconditionally verifiable blind quantum computation, Phys. Rev. A 96, 012303 (2017).
- J. Zeuner, I. Pitsios, S.-H. Tan, A. N. Sharma, J. F. Fitzsimons, R. Osellame, and P. Walther, Experimental quantum homomorphic encryption, npj Quantum Inf. 7, 25 (2021).
- S. Barz, J. F. Fitzsimons, E. Kashefi, and P. Walther, Experimental verification of quantum computation, Nat. Phys. 9, 727 (2013).
- H.-L. Huang, Q. Zhao, X. Ma, C. Liu, Z.-E. Su, X.-L. Wang, L. Li, N.-L. Liu, B. C. Sanders, C.-Y. Lu et al., Experimental blind quantum computing for a classical client, Phys. Rev. Lett. 119, 050503 (2017).
- S. Gupta, A. Agrawal, K. Gopalakrishnan, and P. Narayanan, Deep learning with limited numerical precision, in Proceedings of the International Conference on Machine Learning (PMLR, Brookline, MA, 2015), pp. 1737–1746.
- G. Wetzstein, A. Ozcan, S. Gigan, S. Fan, D. Englund, M. Soljačić, C. Denz, D. A. Miller, and D. Psaltis, Inference in artificial intelligence with deep optics and photonics, Nature (London) 588, 39 (2020).
- B. J. Shastri, A. N. Tait, T. Ferreira de Lima, W. H. Pernice, H. Bhaskaran, C. D. Wright, and P. R. Prucnal, Photonics for artificial intelligence and neuromorphic computing, Nat. Photonics 15, 102 (2021).
- P. L. McMahon, The physics of optical computing, Nat. Rev. Phys. 5, 717 (2023).
- Y. Shen, N. C. Harris, S. Skirlo, M. Prabhu, T. Baehr-Jones, M. Hochberg, X. Sun, S. Zhao, H. Larochelle, D. Englund et al., Deep learning with coherent nanophotonic circuits, Nat. Photonics 11, 441 (2017).
- A. N. Tait, T. F. De Lima, E. Zhou, A. X. Wu, M. A. Nahmias, B. J. Shastri, and P. R. Prucnal, Neuromorphic photonic networks using silicon photonic weight banks, Sci. Rep. 7, 7430 (2017).
- F. Ashtiani, A. J. Geers, and F. Aflatouni, An on-chip photonic deep neural network for image classification, Nature (London) 606, 501 (2022).
- J. Feldmann, N. Youngblood, C. D. Wright, H. Bhaskaran, and W. H. Pernice, All-optical spiking neurosynaptic networks with self-learning capabilities, Nature (London) 569, 208 (2019).
- J. Feldmann, N. Youngblood, M. Karpov, H. Gehring, X. Li, M. Stappers, M. Le Gallo, X. Fu, A. Lukashchuk, A. S. Raja et al., Parallel convolutional processing using an integrated photonic tensor core, Nature (London) 589, 52 (2021).
- Z. Chen, A. Sludds, R. Davis III, I. Christen, L. Bernstein, L. Ateshian, T. Heuser, N. Heermeier, J. A. Lott, S. Reitzenstein et al., Deep learning with coherent vcsel neural networks, Nat. Photonics 17, 723 (2023).
- S. Bandyopadhyay, A. Sludds, S. Krastanov, R. Hamerly, N. Harris, D. Bunandar, M. Streshinsky, M. Hochberg, and D. Englund, Single-chip photonic deep neural network with forward-only training, Nat. Photonics 18, 1335 (2024).
- T. Wu, M. Menarini, Z. Gao, and L. Feng, Lithography-free reconfigurable integrated photonic processor, Nat. Photonics 17, 710 (2023).
- S. Pai, Z. Sun, T. W. Hughes, T. Park, B. Bartlett, I. A. Williamson, M. Minkov, M. Milanizadeh, N. Abebe, F. Morichetti et al., Experimentally realized in situ backpropagation for deep learning in photonic neural networks, Science 380, 398 (2023).
- J. R. Basani, M. Heuck, D. R. Englund, and S. Krastanov, All-photonic artificial-neural-network processor via nonlinear optics, Phys. Rev. Appl. 22, 014009 (2024).
- X. Lin, Y. Rivenson, N. T. Yardimci, M. Veli, Y. Luo, M. Jarrahi, and A. Ozcan, All-optical machine learning using diffractive deep neural networks, Science 361, 1004 (2018).
- T. Zhou, X. Lin, J. Wu, Y. Chen, H. Xie, Y. Li, J. Fan, H. Wu, L. Fang, and Q. Dai, Large-scale neuromorphic optoelectronic computing with a reconfigurable diffractive processing unit, Nat. Photonics 15, 367 (2021).
- L. G. Wright, T. Onodera, M. M. Stein, T. Wang, D. T. Schachter, Z. Hu, and P. L. McMahon, Deep physical neural networks trained with backpropagation, Nature (London) 601, 549 (2022).
- T. Wang, S.-Y. Ma, L. G. Wright, T. Onodera, B. C. Richard, and P. L. McMahon, An optical neural network using less than 1 photon per multiplication, Nat. Commun. 13, 123 (2022).
- L. Bernstein, A. Sludds, C. Panuski, S. Trajtenberg-Mills, R. Hamerly, and D. Englund, Single-shot optical neural network, Sci. Adv. 9, eadg7904 (2023).
- T. Wang, M. M. Sohoni, L. G. Wright, M. M. Stein, S.-Y. Ma, T. Onodera, M. G. Anderson, and P. L. McMahon, Image sensing with multilayer nonlinear optical neural networks, Nat. Photonics 17, 408 (2023).
- S.-Y. Ma, T. Wang, J. Laydevant, L. G. Wright, and P. L. McMahon, Quantum-limited stochastic optical neural networks operating at a few quanta per activation, Nat. Commun. 16, 359 (2025).
- S. Choi, Y. Salamin, C. Roques-Carmes, R. Dangovski, D. Luo, Z. Chen, M. Horodynski, J. Sloan, S. Z. Uddin, and M. Soljačić, Photonic probabilistic machine learning using quantum vacuum noise, Nat. Commun. 15, 1 (2024).
- X. Xu, M. Tan, B. Corcoran, J. Wu, A. Boes, T. G. Nguyen, S. T. Chu, B. E. Little, D. G. Hicks, R. Morandotti et al., 11 tops photonic convolutional accelerator for optical neural networks, Nature (London) 589, 44 (2021).
- R. Davis III, Z. Chen, R. Hamerly, and D. Englund, Rf-photonic deep learning processor with shannon-limited data movement, Sci. Adv. 11, eadt3558 (2025).
- R. Hamerly, L. Bernstein, A. Sludds, M. Soljačić, and D. Englund, Large-scale optical neural networks based on photoelectric multiplication, Phys. Rev. X 9, 021032 (2019).
- A. Sludds, S. Bandyopadhyay, Z. Chen, Z. Zhong, J. Cochrane, L. Bernstein, D. Bunandar, P. B. Dixon, S. A. Hamilton, M. Streshinsky et al., Delocalized photonic deep learning on the internet’s edge, Science 378, 270 (2022).
- A. S. Holevo, Bounds for the quantity of information transmitted by a quantum communication channel, Probl. Peredachi Inf. 9, 3 (1973). [Probl. Inf. Transm. 9, 177 (1973)].
- C. R. Rao, Information and the accuracy attainable in the estimation of statistical parameters, in Breakthroughs in Statistics: Foundations and Basic Theory (Springer, New York, 1992), pp. 235–247.
- T. C. Ralph, All-optical quantum teleportation, Opt. Lett. 24, 348 (1999).
- O. Oreshkov and T. A. Brun, Weak measurements are universal, Phys. Rev. Lett. 95, 110409 (2005).
- J. S. Lundeen and C. Bamber, Procedure for direct measurement of general quantum states using weak measurement, Phys. Rev. Lett. 108, 070402 (2012).
- Y.-S. Kim, J.-C. Lee, O. Kwon, and Y.-H. Kim, Protecting entanglement from decoherence using weak measurement and quantum measurement reversal, Nat. Phys. 8, 117 (2012).
- L. Zhang, A. Datta, and I. A. Walmsley, Precision metrology using weak measurements, Phys. Rev. Lett. 114, 210801 (2015).
- K. Sulimany, S. K. Vadlamani, R. Hamerly, P. Iyengar, and D. Englund, Quantum-secure multiparty deep learning, https://github.com/kfirsuli/Quantum-secure-multiparty-deep-learning (2024).
- V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus, and M. Peev, The security of practical quantum key distribution, Rev. Mod. Phys. 81, 1301 (2009).
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quantum key distribution with realistic devices, Rev. Mod. Phys. 92, 025002 (2020).
- F. Laudenbach, C. Pacher, C.-H. F. Fung, A. Poppe, M. Peev, B. Schrenk, M. Hentschel, P. Walther, and H. Hübel, Continuous-variable quantum key distribution with Gaussian modulation—The theory of practical implementations, Adv. Quantum Technol. 1, 1800011 (2018).
- S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani et al., Advances in quantum cryptography, Adv. Opt. Photonics 12, 1012 (2020).
- K. Sulimany, G. Pelc, R. Dudkiewicz, S. Korenblit, H. S. Eisenberg, Y. Bromberg, and M. Ben-Or, High-dimensional coherent one-way quantum key distribution, npj Quantum Inf. 11, 16 (2025).
- B. A. Bash, A. H. Gheorghe, M. Patel, J. L. Habif, D. Goeckel, D. Towsley, and S. Guha, Quantum-secure covert communication on bosonic channels, Nat. Commun. 6, 8626 (2015).
- E. Polino, M. Valeri, N. Spagnolo, and F. Sciarrino, Photonic quantum metrology, AVS Quantum Sci. 2, 024703 (2020).
- A. Gholami, S. Kim, Z. Dong, Z. Yao, M. W. Mahoney, and K. Keutzer, A survey of quantization methods for efficient neural network inference, in Low-Power Computer Vision (Chapman and Hall/CRC, Boca Raton, 2022), pp. 291–326.
- G. P. Agrawal, Fiber-Optic Communication Systems (John Wiley & Sons, New York, 2012).
- L. d. Moura and S. Ullrich, The Lean 4 theorem prover and programming language, in Automated Deduction–CADE 28: Proceedings of the 28th International Conference on Automated Deduction, Virtual Event, 2021 (Springer, New York, 2021), pp. 625–635.
- B. Breen, M. Del Tredici, J. McCarran, J. Aspuru Mijares, W. W. Yin, K. Sulimany, J. M. Taylor, F. H. L. Koppens, and D. Englund, AX-Prover: A deep reasoning agentic framework for theorem proving in mathematics and quantum physics, arXiv:2510.12787.
- K. Sulimany and Y. Bromberg, All-fiber source and sorter for multimode correlated photons, npj Quantum Inf. 8, 4 (2022).
- R. Nehra, R. Sekine, L. Ledezma, Q. Guo, R. M. Gray, A. Roy, and A. Marandi, Few-cycle vacuum squeezing in nanophotonics, Science 377, 1333 (2022).
- Y. Xia, W. Li, Q. Zhuang, and Z. Zhang, Quantum-enhanced data classification with a variational entangled sensor network, Phys. Rev. X 11, 021047 (2021).
- Q. Zhuang and Z. Zhang, Physical-layer supervised learning assisted by an entangled sensor network, Phys. Rev. X 9, 041023 (2019).
- Y. Bloom, Y. Ordan, T. Levin, K. Sulimany, E. G. Bowes, J. A. Hollingsworth, and R. Rapaport, Decoy-state and purification protocols for superior quantum key distribution with imperfect quantum-dot-based single-photon sources: Theory and experiment, PRX Quantum 6, 030332 (2025).
- A. W. Harrow, A. Hassidim, and S. Lloyd, Quantum algorithm for linear systems of equations, Phys. Rev. Lett. 103, 150502 (2009).
- P. Rebentrost, M. Mohseni, and S. Lloyd, Quantum support vector machine for big data classification, Phys. Rev. Lett. 113, 130503 (2014).
- A. Skolik, J. R. McClean, M. Mohseni, P. Van Der Smagt, and M. Leib, Layerwise learning for quantum neural networks, Quantum Mach. Intell. 3, 1 (2021).
- J. Biamonte, P. Wittek, N. Pancotti, P. Rebentrost, N. Wiebe, and S. Lloyd, Quantum machine learning, Nature (London) 549, 195 (2017).
- I. Cong, S. Choi, and M. D. Lukin, Quantum convolutional neural networks, Nat. Phys. 15, 1273 (2019).
- J. Lin, T. Upadhyaya, and N. Lütkenhaus, Asymptotic security analysis of discrete-modulated continuous-variable quantum key distribution, Phys. Rev. X 9, 041064 (2019).
- F. Kanitschar, I. George, J. Lin, T. Upadhyaya, and N. Lütkenhaus, Finite-size security for discrete-modulated continuous-variable quantum key distribution protocols, PRX Quantum 4, 040306 (2023).
- S. Ghorai, P. Grangier, E. Diamanti, and A. Leverrier, Asymptotic security of continuous-variable quantum key distribution with a discrete modulation, Phys. Rev. X 9, 021059 (2019).
- W. Bogaerts, D. Pérez, J. Capmany, D. A. Miller, J. Poon, D. Englund, F. Morichetti, and A. Melloni, Programmable photonic circuits, Nature (London) 586, 207 (2020).
- E. Polino, M. Riva, M. Valeri, R. Silvestri, G. Corrielli, A. Crespi, N. Spagnolo, R. Osellame, and F. Sciarrino, Experimental multiphase estimation on a chip, Optica 6, 288 (2019).
- V. Saggio, B. E. Asenbeck, A. Hamann, T. Strömberg, P. Schiansky, V. Dunjko, N. Friis, N. C. Harris, M. Hochberg, D. Englund et al., Experimental quantum speed-up in reinforcement learning agents, Nature (London) 591, 229 (2021).
- I. Agresti, N. Viggianiello, F. Flamini, N. Spagnolo, A. Crespi, R. Osellame, N. Wiebe, and F. Sciarrino, Pattern recognition techniques for boson sampling validation, Phys. Rev. X 9, 011013 (2019).
- D. Marpaung, J. Yao, and J. Capmany, Integrated microwave photonics, Nat. Photonics 13, 80 (2019).
- P. Jouguet, S. Kunz-Jacques, A. Leverrier, P. Grangier, and E. Diamanti, Experimental demonstration of long-distance continuous-variable quantum key distribution, Nat. Photonics 7, 378 (2013).
- N. Jain, H.-M. Chin, H. Mani, C. Lupo, D. S. Nikolic, A. Kordts, S. Pirandola, T. B. Pedersen, M. Kolb, B. Ömer et al., Practical continuous-variable quantum key distribution with composable security, Nat. Commun. 13, 4740 (2022).
- Y. Zhang, Z. Chen, S. Pirandola, X. Wang, C. Zhou, B. Chu, Y. Zhao, B. Xu, S. Yu, and H. Guo, Long-distance continuous-variable quantum key distribution over 202.81 km of fiber, Phys. Rev. Lett. 125, 010502 (2020).
- K. R. Motes, A. Gilchrist, J. P. Dowling, and P. P. Rohde, Scalable boson sampling with time-bin encoding using a loop-based architecture, Phys. Rev. Lett. 113, 120501 (2014).
- M. Reck, A. Zeilinger, H. J. Bernstein, and P. Bertani, Experimental realization of any discrete unitary operator, Phys. Rev. Lett. 73, 58 (1994).
- N. K. Fontaine, R. Ryf, H. Chen, D. T. Neilson, K. Kim, and J. Carpenter, Laguerre-gaussian mode sorter, Nat. Commun. 10, 1865 (2019).
- O. Lib, K. Sulimany, and Y. Bromberg, Processing entangled photons in high dimensions with a programmable light converter, Phys. Rev. Appl. 18, 014063 (2022).
- O. Lib, K. Sulimany, M. Araújo, M. Ben-Or, and Y. Bromberg, High-dimensional quantum key distribution using a multi-plane light converter, Opt. Quantum 3, 182 (2025).
- Y. He, X. Ding, Z.-E. Su, H.-L. Huang, J. Qin, C. Wang, S. Unsleber, C. Chen, H. Wang, Y.-M. He et al., Time-bin-encoded boson sampling with a single-photon device, Phys. Rev. Lett. 118, 190501 (2017).
- J. M. Arrazola, V. Bergholm, K. Brádler, T. R. Bromley, M. J. Collins, I. Dhand, A. Fumagalli, T. Gerrits, A. Goussev, L. G. Helt et al., Quantum circuits with many photons on a programmable nanophotonic chip, Nature (London) 591, 54 (2021).
- K. Yonezu, Y. Enomoto, T. Yoshida, and S. Takeda, Time-domain universal linear-optical operations for universal quantum information processing, Phys. Rev. Lett. 131, 040601 (2023).
- C. Cui, J. Postlewaite, B. N. Saif, L. Fan, and S. Guha, Superadditive communication with the green machine as a practical demonstration of nonlocality without entanglement, Nat. Commun. 16, 3760 (2025).
- C. Cui, J. R. Basani, J. Postlewaite, B. N. Saif, L. Fan, E. Waks, and S. Guha, Arbitrary unitary transformation over time-binned optical modes and the demonstration of superadditive communication, in Quantum Computing, Communication, and Simulation V (SPIE, Bellingham, WA, 2025), Vol. 13391, pp. 11–17.
- M. O. Scully and M. S. Zubairy, Quantum Optics (Cambridge University Press, Cambridge, England, 1997).
- M. G. Bacvanski, S. K. Vadlamani, K. Sulimany, and D. R. Englund, Qamnet: Fast and efficient optical QAM neural networks, arXiv:2409.12305.
- A. Leverrier and P. Grangier, Unconditional security proof of long-distance continuous-variable quantum key distribution with discrete modulation, Phys. Rev. Lett. 102, 180504 (2009).
- R. García-Patrón and N. J. Cerf, Unconditional optimality of Gaussian attacks against continuous-variable format quantum key distribution, Phys. Rev. Lett. 97, 190503 (2006).
- M. M. Wolf, G. Giedke, and J. I. Cirac, Extremality of Gaussian quantum states, Phys. Rev. Lett. 96, 080502 (2006).
- C. Lyle, M. van der Wilk, M. Kwiatkowska, Y. Gal, and B. Bloem-Reddy, On the benefits of invariance in neural networks, arXiv:2005.00178.
- E. Kauderer-Abrams, Quantifying translation-invariance in convolutional neural networks, arXiv:1801.01450.
- B. Neyshabur, S. Bhojanapalli, D. Mcallester, and N. Srebro, Exploring generalization in deep learning, in Advances in Neural Information Processing Systems, edited by I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Curran Associates, Inc., Red Hook, NY, 2017), Vol. 30.
- B. Neyshabur, R. R. Salakhutdinov, and N. Srebro, Path-sgd: Path-normalized optimization in deep neural networks, in Advances in Neural Information Processing Systems, Vol. 28, edited by C. Cortes, N. Lawrence, D. Lee, M. Sugiyama, and R. Garnett (Curran Associates, Inc., 2015).
- C. Orlandi, A. Piva, and M. Barni, Oblivious neural network computing via homomorphic encryption, EURASIP J. Inf. Secur. 2007, 1 (2007).
- A. Pananjady, M. J. Wainwright, and T. A. Courtade, Linear regression with shuffled data: Statistical and computational limits of permutation recovery, IEEE Trans. Inf. Theory 64, 3286 (2017).
- Ú. Erlingsson, V. Feldman, I. Mironov, A. Raghunathan, K. Talwar, and A. Thakurta, Amplification by shuffling: From local to central differential privacy via anonymity, in Proceedings of the Thirtieth Annual ACM-SIAM Symposium on Discrete Algorithms (SIAM, Philadelphia, 2019), pp. 2468–2479.
- V. Feldman, A. McMillan, and K. Talwar, Hiding among the clones: A simple and nearly optimal analysis of privacy amplification by shuffling, in 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS) (IEEE, New York, 2022), pp. 954–964.
- V. Feldman, A. McMillan, and K. Talwar, Stronger privacy amplification by shuffling for rényi and approximate differential privacy, in Proceedings of the 2023 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA) (SIAM, Philadelphia, 2023), pp. 4966–4981.
- A. Van der Vaart, 10.2 Bernstein–von Mises theorem, Asymptotic Statistics (1998).
