Source-linked AI summary
Experimental Demonstration of Blind Quantum Computing
Stefanie Barz, Elham Kashefi, Anne Broadbent, Joseph F. Fitzsimons, Anton Zeilinger, Philip Walther
TL;DR
The paper addresses whether quantum computation can be delegated to a remote server while keeping the client’s input, computation, and output hidden. It uses measurement-based blind quantum computing with photonic qubits and experimentally demonstrates blind gates and algorithms, while identifying technical challenges before full implementation.
Problem
Remote quantum computation requires a way to keep client data private from centralized quantum servers, with unconditional security remaining a key challenge.
Method
The experiment uses optimized photonic blind cluster states so a client prepares and transmits individual qubits while a quantum server performs the computation.
Results
The experiment demonstrates blind single- and two-qubit gates, Deutsch’s and Grover’s algorithms, and blind computation with the client’s input, computation, and output hidden.
Takeaways & Limitations
The demonstration is a first step toward unconditionally secure quantum computing in client-server environments and future privacy-preserving quantum networks or clouds.
Takeaways & Limitations
Photon losses, post-selection, unwanted emitted photons, and non-ideal human-selected angles and prepared measurement settings remain technical challenges for full implementation.
Abstract
from arXiv · showhide
Quantum computers, besides offering substantial computational speedups, are also expected to provide the possibility of preserving the privacy of a computation. Here we show the first such experimental demonstration of blind quantum computation where the input, computation, and output all remain unknown to the computer. We exploit the conceptual framework of measurement-based quantum computation that enables a client to delegate a computation to a quantum server. We demonstrate various blind delegated computations, including one- and two-qubit gates and the Deutsch and Grover algorithms. Remarkably, the client only needs to be able to prepare and transmit individual photonic qubits. Our demonstration is crucial for future unconditionally secure quantum cloud computing and might become a key ingredient for real-life applications, especially when considering the challenges of making powerful quantum computers widely available.
Experimental Demonstration of Blind Quantum Computing
The paper experimentally demonstrates blind quantum computing, allowing a client to delegate computation while keeping data and computation hidden from an untrusted quantum server. It combines measurement-based computation with blind cluster states and requires only client-side preparation of individual photonic qubits.
- Motivation and protocol: The demonstrated framework addresses the challenge of performing remote quantum computation while preserving client privacy against a centralized quantum server.The motivation is the prospect that only a few powerful quantum computers may initially be available at specialized facilities.
- Motivation and protocol: Blind quantum computing enables delegation to an untrusted quantum server while keeping the client’s data and computation private.The protocol combines quantum cryptography with measurement-based quantum computation.
- Motivation and protocol: Blind cluster states are entangled resource states whose hidden preparation angles conceal the computation implemented by adaptive single-qubit measurements.The client prepares randomly rotated qubits and the server applies CPhase gates before carrying out measurements in instructed bases.
- Experimental implementation: The protocol requires the client only to prepare and transmit individual qubits; thereafter, the client communicates measurement instructions classically.The server performs the entangling gates and adaptive measurements needed for universal quantum computation.
- Experimental implementation: The experiment presents an optimized photonic implementation in which four-qubit blind cluster states are combined through optical gates to form a universal resource.Photons serve as the client’s quantum information carriers and support the server’s quantum processing.
Optimised blind quantum computing
The experiment optimizes blindness by varying only selected qubit rotations in four-qubit cluster states while fixing other angles, reducing the client’s preparation requirements. It demonstrates state preparation and extensive measurement implementations using photonic polarization qubits.
- Optimised blind quantum computing: Perfect security can hold for selected computations even when the server knows some qubit states.For four-qubit blind clusters, preparing only one or two qubits in arbitrary states supports various one- and two-qubit circuits and algorithms.
- Optimised blind quantum computing: The experiment fixes θ1 and θ4 to zero while varying θ2 and θ3 to construct four-qubit linear blind cluster states.The corresponding measurement patterns retain blindness for θ2 and θ3.
- Experimental implementation: Four photons emitted by a type-II SPDC source produce highly entangled states equivalent to the target blind cluster under H ⊗ I ⊗ I ⊗ H.Photon polarization encodes the physical qubits, with horizontal and vertical polarization representing |0⟩ and |1⟩.
- Experimental demonstration: 1962 different four-qubit measurements with 31392 measured outcomes demonstrate preparation and measurement of multiple blind cluster-state configurations.Collecting all outcomes represents the possible computational branches and implicitly incorporates the client’s random values rj.
- Experimental implementation: Maximum-likelihood tomography reconstructs each four-qubit density matrix, with uncertainties estimated by a Monte Carlo routine assuming Poissonian errors.The reconstructed states are used to evaluate the experimentally prepared blind cluster states.
Blind single- and two-qubit unitaries
Blind cluster states implement arbitrary single-qubit rotations and universal two-qubit gates while hiding the client’s choices and computation from the server.
- Single-qubit unitaries: Measuring a four-qubit linear blind cluster implements an arbitrary single-qubit unitary through adaptive measurements.The output is |Ψout⟩ = Rx(−φ3)Rz(−φ2)|Ψin⟩, with rotations determined by measurements on qubits 2 and 3.
- Single-qubit unitaries: χ = 0.169 ± 0.074, far below three bits, quantifies near-perfect blindness for the demonstrated single-qubit rotations.χ rises only to 0.185 ± 0.087 when maximized over all prior state distributions.
- Single-qubit unitaries: χ = 0.185 ± 0.087 after maximizing over prior distributions shows that the blindness measure changes only slightly under this worst-case choice.
- Two-qubit unitaries: Blind horseshoe clusters implement two-qubit gates, with measurements on qubits 2 and 3 transforming logical inputs and measurements on qubits 1 and 4 reading outputs.A four-state selection hides the choice among rotations Rz(π/2 ± π) ⊗ Rz(π/2 ± π).
- Two-qubit unitaries: The two-qubit output averaged over blind states is nearly totally mixed, with linear entropy 0.955 ± 0.011.
- Algorithmic extension: Blind staircase and triangle clusters extend the demonstrated computations to Deutsch’s and Grover’s algorithms.
Blind algorithms
The experiment implements blind Grover and Deutsch algorithms on photonic cluster states and tests whether the server exhibits quantum behavior. Grover search identifies the tagged item with high probability, while Deutsch’s algorithm produces correct constant-versus-balanced results.
- Grover’s algorithm: Grover search for n = 2 is embedded in a blind triangle cluster, hiding the tagged element and the computation from the server.
- Grover’s algorithm: 0.850 ± 0.039 is the highest probability of identifying the tagged state, with an average of 0.720 ± 0.015 across blind states.The reported unwanted-state outcomes arise from experimental noise.
- Deutsch’s algorithm: The blind Deutsch implementation uses a staircase cluster whose qubit measurements distinguish constant and balanced oracles without revealing which scenario is executed.
- Deutsch’s algorithm: 0.930 ± 0.025 and 0.887 ± 0.033 are the output fidelities for constant and balanced oracles, respectively.
- Server testing: Fixed measurement settings produce blind-state-dependent distributions that can distinguish the experimental quantum server from a classical server guessing each outcome with probability 1/16.The experiment is presented as an initial step toward verification schemes for quantum technology.
- Deutsch’s algorithm: 0.899 ± 0.006 and 0.895 ± 0.022 are the correct-result probabilities for constant and balanced oracles, respectively.
Towards verifying the quantumness
The experiment introduces a heuristic test for whether an untrusted server possesses quantum technology, using blindness to conceal the client’s prepared states. Comparing multi-round outcome statistics with theoretical predictions provides evidence of the server’s quantum nature.
- Blindness hides the client’s initial states, preventing a classical server from knowing which measurement outcomes are expected.For the chosen setting, a classical device guesses incorrectly with probability at least 1/8.
- The client tests the server by comparing observed outcome statistics with the known theoretical distribution.The procedure uses several outcomes and different measurement instructions.
- The experimental outcomes agree with theoretical predictions, confirming the quantum nature of the server.
- The demonstration is an initial step toward efficient verification schemes and benchmarks for future fault-tolerant protocols.With more qubits, such protocols are expected to detect a cheating server with probability exponentially close to one.
Discussion
The authors experimentally demonstrate blind quantum computing with photonic four-qubit cluster states and several quantum algorithms. They identify technical and randomness-generation challenges that must be addressed before full implementations, while positioning the work as an initial step toward private quantum-cloud computing.
- Discussion: Four-qubit blind cluster states implement universal single-qubit and non-trivial two-qubit gates, Deutsch’s algorithm, and Grover’s algorithm.
- Discussion: Photons let the client prepare qubits remotely for processing by a locally separated quantum server.The authors identify photon mobility as an intrinsic advantage of this physical system.
- Discussion: Emitted photons, post-selection, and photon losses can reveal blind phases or reduce protocol efficiency.The authors identify on-demand single-qubit states and heralded blind-cluster generation as important technical targets.
- Discussion: The experiment used human-selected blind angles and measurement settings drawn from a prepared list rather than full shot-by-shot randomization.The source of randomness must be scrutinized for correlations with the server; full randomization remains challenging at the demonstrated photon rates.
- Discussion: The work is presented as a first step toward unconditionally secure client-server quantum computing with hidden computations.The authors anticipate applications in future quantum-computing networks or clouds.
Proof of blindness for optimised BQC
The optimized protocol achieves full blindness even when only some qubits carry secret initial rotations. For Deutsch’s and Grover’s algorithms, later Clifford-group measurements preserve this blindness by making the server’s received states and instructions independent of the client’s angles.
- Proof of blindness for optimised BQC: Full blindness can be achieved even when not every qubit has an initial secret rotation.
- Proof of blindness for optimised BQC: The construction applies when measurements following blind-qubit measurements use Clifford angles that are integer multiples of π/2.The authors state that Deutsch’s and Grover’s algorithms satisfy this condition.
- Proof of blindness for optimised BQC: The server receives measurement instructions δ2 = φ2 + θ2 + πr2 and δ3 = φ3 + θ3 + πr3 for qubits 2 and 3.Random bits r2 and r3 mask the client’s measurement choices.
- Proof of blindness for optimised BQC: Because r2 and r3 are random, the corresponding server-held density matrices are completely mixed and independent of the client’s measurement angles.
- Proof of blindness for optimised BQC: The classical instructions δ2 and δ3 are uniformly random and independent of φ2 and φ3, so the server learns nothing about those choices.
Leakage of information in experimental blind
The leakage analysis models the server’s information as the initial quantum state and the classical angles received during the protocol. Experimental imperfections are assessed through the Holevo information of the server’s received state.
- Leakage of information in experimental blind: The leakage model assumes that the server receives the client-supplied initial quantum state and the classical angles δi sent during the protocol.
- Leakage of information in experimental blind: The experimentally produced state is fixed for each ideal client input, while the client’s choices are treated as uniformly random.
- Leakage of information in experimental blind: Information leakage is bounded by the Holevo information of the quantum state received by the server.
Experimental setup
The experiment generates entangled photon pairs through non-collinear type-II SPDC, using a pulsed Ti:Sa laser whose frequency-doubled output provides the ultraviolet pump.
- Experimental setup: Entangled photon pairs are produced using emissions from a non-collinear type-II SPDC process.The source is pumped by a modelocked Mira HP Ti:Sa oscillator driven by a Coherent Verdi V-10 laser.
- Experimental setup: The laser output has τ = 200 fs, λ = 789 nm, and a repetition rate of 76 MHz before frequency doubling.A 2 mm-thick LBO crystal frequency-doubles the pulsed output.
- Experimental setup: Frequency doubling produces ultraviolet pulses with 0.8 W cw average power.The LBO crystal is translated to avoid optical damage and maintain a stable UV-pulse source.
Experimental preparation of blind cluster states
The blind cluster state is prepared from coherent four-photon emission pathways, whose polarization terms are combined at polarizing beam splitters and selected through fourfold detection. Source visibility, interference, phase drift, and polarization drift limit fidelity relative to the ideal state.
- State construction: The blind cluster state comprises four terms corresponding to distinct emissions of four photons.These arise from two entangled pairs emitted in forward and backward modes or from double-pair emissions in one mode.
- State construction: Coherent superposition of the four-pair contributions, together with PBS properties and post-selection, produces the appropriate cluster state.The preparation uses polarizing beam splitters and successful detection of the selected output events.
- Emission terms: Single-pair emissions in forward and backward directions generate |H⟩1|H⟩2|H⟩3|H⟩4 and −ei(θ2+θ3)|V⟩1|V⟩2|V⟩3|V⟩4 terms.Double-pair emissions add fourfold-coincidence terms with phase factors θ2 and θ3.
- Experimental limitations: About 0.9 Bell-pair visibility and 0.85 average PBS-interference visibility contribute to reduced blind-cluster fidelity.Phase drifts during measurements and smaller polarization drifts add further errors.
- Delegated preparation: The client prepares encoded phases such as θ2 and θ3 locally, while the server superimposes the photons on two PBSs and post-selects fourfold coincidences.Computation settings are then set by phase retarders in the output modes.