arXiv ScienceSearch

arXiv subjects

Craig Gidney

Publications and source records attributed to Craig Gidney.

At least 19 recordsLinked to original sources

Borrowed Identities: Malleable Distillation Factories and a Unified Numerical Search

Magic-state distillation is one of the leading overheads in fault-tolerant quantum computation. Existing methods for finding distillation factories require a transversal gate to act correctly on the entire codespace, a constraint that limits both generality and search efficiency. We introduce a strictly weaker borrowed-identity condition, requiring only that the distillation circuit act as the identity on a single input state. It applies uniformly across all levels of the Clifford hierarchy and unifies, within a single level, factories that distill different magic states -- for example, the $|T\rangle$, $|CS\rangle$, and $|CCZ\rangle$ factories. A brute-force search over borrowed-identity circuits with two-group symmetry recovers, within the search range, all distance-2 factories known from code-construction approaches, including entangled-output and multi-output factories previously outside the scope of any single numerical search. This unification yields parent circuits that encode multiple factories, so the output magic-state type can be chosen at compile time rather than fixed by a hard-coded design. The framework also extends beyond CSS codes, unifying constructions, including synthillation and non-CSS catalytic factories, previously obtained by disparate approaches.

quant-ph

Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations

This whitepaper seeks to elucidate implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem, the core of modern blockchain cryptography. We demonstrate that Shor's algorithm for this problem can execute with either <1200 logical qubits and <90 million Toffoli gates or <1450 logical qubits and <70 million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with 1e-3 physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between fast-clock (such as superconducting and photonic) and slow-clock (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable on-spend attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, Proof-of-Stake consensus, and Data Availability Sampling, as well as the enduring concern of abandoned assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of digital salvage to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to Post-Quantum Cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the ongoing migration to PQC without delay.

quant-ph

LUCI in the Surface Code with Dropouts

Recently, usage of detecting regions facilitated the discovery of new circuits for fault-tolerantly implementing the surface code. Building on these ideas, we present LUCI, a framework for constructing fault-tolerant circuits flexible enough to construct aperiodic and anisotropic circuits, making it a clear step towards quantum error correction beyond static codes. We show that LUCI can be used to adapt surface code circuits to lattices with imperfect qubit and coupler yield, a key challenge for fault-tolerant quantum computers using solid-state architectures. These circuits preserve spacelike distance for isolated broken couplers or isolated broken measure qubits in exchange for halving timelike distance, substantially reducing the penalty for dropout compared to the state of the art and creating opportunities in device architecture design. For qubit and coupler dropout rates of 1% and a patch diameter of 15, LUCI achieves an average spacelike distance of 13.1, compared to 9.1 for the best method in the literature. For a SI1000(0.001) circuit noise model, this translates to a 36x improvement in median logical error rate per round, a factor which increases with device performance. At these dropout and error rates, LUCI requires roughly 25% fewer physical qubits to reach algorithmically relevant one-in-a-trillion logical codeblock error rates.

quant-ph

Magic state cultivation on a superconducting quantum processor

Fault-tolerant quantum computing requires a universal gate set, but the necessary non-Clifford gates represent a significant resource cost for most quantum error correction architectures. Magic state cultivation offers an efficient alternative to resource-intensive distillation protocols; however, testing the proposal's assumptions represents a challenging departure from quantum memory experiments. We present an experimental study of magic state cultivation on a superconducting quantum processor. We implement cultivation, including code-switching into a surface code, and develop a fault-tolerant measurement protocol to bound the magic state fidelity. Cultivation reduces the error by a factor of 40, with a state fidelity of 0.9999(1) (retaining 8% of attempts). Our results experimentally establish magic state cultivation as a viable solution to one of quantum computing's most significant challenges.

quant-ph

Quantum-Classical Separation in Bounded-Resource Tasks Arising from Measurement Contextuality

The prevailing view is that quantum phenomena can be harnessed to tackle certain problems beyond the reach of classical approaches. Quantifying this capability as a quantum-classical separation and demonstrating it on current quantum processors has remained elusive. Using a superconducting qubit processor, we show that quantum contextuality enables certain tasks to be performed with success probabilities beyond classical limits. With a few qubits, we illustrate quantum contextuality with the magic square game, as well as quantify it through a Kochen--Specker--Bell inequality violation. To examine many-body contextuality, we implement the N-player GHZ game and separately solve a 2D hidden linear function problem, exceeding classical success rate in both. Our work proposes novel ways to benchmark quantum processors using contextuality-based algorithms.

quant-ph

Low Depth Color Code Circuits with CXSWAP gate

We present two new types of syndrome extraction circuits for the color code. Our first construction, which after [M. McEwen, D. Bacon, and C. Gidney, Quantum 7, 1172 (2023)] we call the semi-wiggling color code, promises to mitigate leakage errors by periodically interchanging the roles of bulk data and measurement qubits. The second construction reduces circuit depth relative to [C. Gidney and C. Jones, arXiv:2312.08813 (2023)] by employing the CXSWAP gate instead of CNOT. This optimization leads to $\sim 10\%$ improvement in teraquop footprint under the uniform error model with the physical error rate $p=0.1\%$.

quant-ph

Verifiable Quantum Advantage via Optimized DQI Circuits

Decoded Quantum Interferometry (DQI) provides a framework for superpolynomial quantum speedups by reducing certain optimization problems to reversible decoding tasks. We apply DQI to the Optimal Polynomial Intersection (OPI) problem, whose dual code is Reed-Solomon (RS). We establish that DQI for OPI is the first known candidate for verifiable quantum advantage with optimal asymptotic speedup: solving instances with classical hardness $O(2^N)$ requires only $\widetilde{O}(N)$ quantum gates, matching the theoretical lower bound. Realizing this speedup requires highly efficient reversible RS decoders. We introduce novel quantum circuits for the Extended Euclidean Algorithm, the decoder's bottleneck. Our techniques, including a new representation for implicit Bézout coefficient access, and optimized in-place architectures, reduce the leading-order space complexity to the theoretical minimum of $2nb$ qubits while significantly lowering gate counts. These improvements are broadly applicable, including to Shor's algorithm for the discrete logarithm. We analyze OPI over binary extension fields $GF(2^b)$, assess hardness against new classical attacks, and identify resilient instances. Our resource estimates show that classically intractable OPI instances (requiring $>10^{23}$ classical trials) can be solved with approximately 5.72 million Toffoli gates. This is substantially less than the count required for breaking RSA-2048, positioning DQI as a compelling candidate for practical, verifiable quantum advantage.

quant-ph

A Classical-Quantum Adder with Constant Workspace and Linear Gates

In 2004, Cuccaro et al found a quantum-quantum adder with $O(n)$ gate cost and $O(1)$ ancilla qubits. Since then, it's been an open question whether classical-quantum adders can achieve the same asymptotic complexity. These costs are particularly relevant to modular arithmetic circuits, which often offset by the classically known modulus. In this paper, I construct an adder that uses 3 clean ancillae and $4n \pm O(1)$ Toffoli gates to add a classical offset into a quantum register. I also present an adder with a Toffoli cost of $3n \pm O(1)$ that uses 2 clean ancillae and $n-2$ dirty ancillae. I further show that applying the presented adders conditioned on a control qubit requires no additional workspace or Toffolis.

quant-ph

Observation of disorder-free localization using a (2+1)D lattice gauge theory on a quantum processor

Disorder-induced phenomena in quantum many-body systems pose significant challenges for analytical methods and numerical simulations at relevant time and system scales. To reduce the cost of disorder-sampling, we investigate quantum circuits initialized in states tunable to superpositions over all disorder configurations. In a translationally-invariant lattice gauge theory (LGT), these states can be interpreted as a superposition over gauge sectors. We observe localization in this LGT in the absence of disorder in one and two dimensions: perturbations fail to diffuse despite fully disorder-free evolution and initial states. However, Rényi entropy measurements reveal that superposition-prepared states fundamentally differ from those obtained by direct disorder sampling. Leveraging superposition, we propose an algorithm with a polynomial speedup in sampling disorder configurations, a longstanding challenge in many-body localization studies.

quant-ph

Demonstrating dynamic surface codes

A remarkable characteristic of quantum computing is the potential for reliable computation despite faulty qubits. This can be achieved through quantum error correction, which is typically implemented by repeatedly applying static syndrome checks, permitting correction of logical information. Recently, the development of time-dynamic approaches to error correction has uncovered new codes and new code implementations. In this work, we experimentally demonstrate three time-dynamic implementations of the surface code, each offering a unique solution to hardware design challenges and introducing flexibility in surface code realization. First, we embed the surface code on a hexagonal lattice, reducing the necessary couplings per qubit from four to three. Second, we walk a surface code, swapping the role of data and measure qubits each round, achieving error correction with built-in removal of accumulated non-computational errors. Finally, we realize the surface code using iSWAP gates instead of the traditional CNOT, extending the set of viable gates for error correction without additional overhead. We measure the error suppression factor when scaling from distance-3 to distance-5 codes of $Λ_{35,\text{hex}} = 2.15(2)$, $Λ_{35,\text{walk}} = 1.69(6)$, and $Λ_{35,\text{iSWAP}} = 1.56(2)$, achieving state-of-the-art error suppression for each. With detailed error budgeting, we explore their performance trade-offs and implications for hardware design. This work demonstrates that dynamic circuit approaches satisfy the demands for fault-tolerance and opens new alternative avenues for scalable hardware design.

quant-ph

Constructive interference at the edge of quantum ergodic dynamics

Quantum observables in the form of few-point correlators are the key to characterizing the dynamics of quantum many-body systems. In dynamics with fast entanglement generation, quantum observables generally become insensitive to the details of the underlying dynamics at long times due to the effects of scrambling. In experimental systems, repeated time-reversal protocols have been successfully implemented to restore sensitivities of quantum observables. Using a 103-qubit superconducting quantum processor, we characterize ergodic dynamics using the second-order out-of-time-order correlators, OTOC$^{(2)}$. In contrast to dynamics without time reversal, OTOC$^{(2)}$ are observed to remain sensitive to the underlying dynamics at long time scales. Furthermore, by inserting Pauli operators during quantum evolution and randomizing the phases of Pauli strings in the Heisenberg picture, we observe substantial changes in OTOC$^{(2)}$ values. This indicates that OTOC$^{(2)}$ is dominated by constructive interference between Pauli strings that form large loops in configuration space. The observed interference mechanism endows OTOC$^{(2)}$ with a high degree of classical simulation complexity, which culminates in a set of large-scale OTOC$^{(2)}$ measurements exceeding the simulation capacity of known classical algorithms. Further supported by an example of Hamiltonian learning through OTOC$^{(2)}$, our results indicate a viable path to practical quantum advantage.

quant-ph

How to factor 2048 bit RSA integers with less than a million noisy qubits

Planning the transition to quantum-safe cryptosystems requires understanding the cost of quantum attacks on vulnerable cryptosystems. In Gidney+Ekerå 2019, I co-published an estimate stating that 2048 bit RSA integers could be factored in eight hours by a quantum computer with 20 million noisy qubits. In this paper, I substantially reduce the number of qubits required. I estimate that a 2048 bit RSA integer could be factored in less than a week by a quantum computer with less than a million noisy qubits. I make the same assumptions as in 2019: a square grid of qubits with nearest neighbor connections, a uniform gate error rate of $0.1\%$, a surface code cycle time of 1 microsecond, and a control system reaction time of $10$ microseconds. The qubit count reduction comes mainly from using approximate residue arithmetic (Chevignard+Fouque+Schrottenloher 2024), from storing idle logical qubits with yoked surface codes (Gidney+Newman+Brooks+Jones 2023), and from allocating less space to magic state distillation by using magic state cultivation (Gidney+Shutty+Jones 2024). The longer runtime is mainly due to performing more Toffoli gates and using fewer magic state factories compared to Gidney+Ekerå 2019. That said, I reduce the Toffoli count by over 100x compared to Chevignard+Fouque+Schrottenloher 2024.

quant-ph

Rise of conditionally clean ancillae for efficient quantum circuit constructions

We introduce conditionally clean ancilla qubits, a new quantum resource, recently explored by [NZS24], that bridges the gap between traditional clean and dirty ancillae. Like dirty ancillae, they begin and end in an unknown state and can be borrowed from existing system qubits, avoiding the space overhead of explicit qubit allocation. Like clean ancillae, they can be treated as initialized in a known state within specific computations, thus avoiding the overhead of toggle detection required for dirty ancillae. We present new circuit constructions leveraging conditionally clean ancillae to achieve lower gate counts and depths, particularly with limited ancilla availability. Specifically, we provide constructions for: (a) $n$-controlled NOT using $2n$ Toffolis and $O(\log{n})$ depth given 2 clean ancillae. (b) $n$-qubit incrementer using $3n$ Toffolis given $\log_2^*{n}$ clean ancillae. (c) $n$-qubit quantum-classical comparator using $3n$ Toffolis given $\log_2^*{n}$ clean ancillae. (d) unary iteration over $[0,N)$ using $2.5N$ Toffolis given $\log_2^*{n}$ clean ancillae. (e) unary iteration via skew tree over $[0, N)$ using $1.25N$ Toffolis given $n$ dirty ancillae. We also introduce laddered toggle detection, a technique to replace clean ancillae with dirty ancillae in all our constructions, incurring a 2x Toffoli gate overhead. Our results demonstrate that conditionally clean ancillae are a valuable tool for quantum circuit design, especially in the resource-constrained early fault-tolerant era.

quant-ph

A log-depth in-place quantum Fourier transform that rarely needs ancillas

When designing quantum circuits for a given unitary, it can be much cheaper to achieve a good approximation on most inputs than on all inputs. In this work we formalize this idea, and propose that such "optimistic quantum circuits" are often sufficient in the context of larger quantum algorithms. For the rare algorithm in which a subroutine needs to be a good approximation on all inputs, we provide a reduction which transforms optimistic circuits into general ones. Applying these ideas, we build an optimistic circuit for the in-place quantum Fourier transform (QFT). Our circuit has depth $O(\log (n / \epsilon))$ for tunable error parameter $\epsilon$, uses $n$ total qubits, i.e. no ancillas, is local for input qubits arranged in 1D, and is measurement-free. The circuit's error is bounded by $\epsilon$ on all input states except an $O(\epsilon)$-sized fraction of the Hilbert space. The circuit is also rather simple and thus may be practically useful. Combined with recent QFT-based fast arithmetic constructions [arXiv:2403.18006], the optimistic QFT yields factoring circuits of nearly linear depth using only $2n + O(n/\log n)$ total qubits. Additionally, we apply our reduction technique to yield an approximate QFT with well-controlled error on all inputs; it is the first to achieve the asymptotically optimal depth of $O(\log (n/\epsilon))$ with a sublinear number of ancilla qubits. The reduction uses long-range gates but no measurements.

quant-ph

A Constant Rate Quantum Computer on a Line

We prove by construction that the Bravyi-Poulin-Terhal bound on the spatial density of stabilizer codes does not generalize to stabilizer circuits. To do so, we construct a fault tolerant quantum computer with a coding rate above 5% and quasi-polylog time overhead, out of a line of qubits with nearest-neighbor connectivity, and prove it has a threshold. The construction is based on modifications to the tower of Hamming codes of Yamasaki and Koashi (Nature Physics, 2024), with operators measured using a variant of Shor's measurement gadget.

quant-ph

Sparse Blossom: correcting a million errors per core second with minimum-weight matching

In this work, we introduce a fast implementation of the minimum-weight perfect matching (MWPM) decoder, the most widely used decoder for several important families of quantum error correcting codes, including surface codes. Our algorithm, which we call sparse blossom, is a variant of the blossom algorithm which directly solves the decoding problem relevant to quantum error correction. Sparse blossom avoids the need for all-to-all Dijkstra searches, common amongst MWPM decoder implementations. For 0.1% circuit-level depolarising noise, sparse blossom processes syndrome data in both $X$ and $Z$ bases of distance-17 surface code circuits in less than one microsecond per round of syndrome extraction on a single core, which matches the rate at which syndrome data is generated by superconducting quantum computers. Our implementation is open-source, and has been released in version 2 of the PyMatching library.

quant-ph

Magic state cultivation: growing T states as cheap as CNOT gates

We refine ideas from Knill 1996, Jones 2016, Chamberland 2020, Gidney 2023+2024, Bombin 2024, and Hirano 2024 to efficiently prepare good $|T\rangle$ states. We call our construction "magic state cultivation" because it gradually grows the size and reliability of one state. Cultivation fits inside a surface code patch and uses roughly the same number of physical gates as a lattice surgery CNOT gate of equivalent reliability. We estimate the infidelity of cultivation (from injection to idling at distance 15) using a mix of state vector simulation, stabilizer simulation, error enumeration, and Monte Carlo sampling. Compared to prior work, cultivation uses an order of magnitude fewer qubit-rounds to reach logical error rates as low as $2 \cdot 10^{-9}$ when subjected to $10^{-3}$ uniform depolarizing circuit noise. Halving the circuit noise to $5 \cdot 10^{-4}$ improves the achievable logical error rate to $4 \cdot 10^{-11}$. Cultivation's efficiency and strong response to improvements in physical noise suggest that further magic state distillation may never be needed in practice.

quant-ph

A SAT Scalpel for Lattice Surgery: Representation and Synthesis of Subroutines for Surface-Code Fault-Tolerant Quantum Computing

Quantum error correction is necessary for large-scale quantum computing. A promising quantum error correcting code is the surface code. For this code, fault-tolerant quantum computing (FTQC) can be performed via lattice surgery, i.e., splitting and merging patches of code. Given the frequent use of certain lattice-surgery subroutines (LaS), it becomes crucial to optimize their design in order to minimize the overall spacetime volume of FTQC. In this study, we define the variables to represent LaS and the constraints on these variables. Leveraging this formulation, we develop a synthesizer for LaS, LaSsynth, that encodes a LaS construction problem into a SAT instance, subsequently querying SAT solvers for a solution. Starting from a baseline design, we can gradually invoke the solver with shrinking spacetime volume to derive more compact designs. Due to our foundational formulation and the use of SAT solvers, LaSsynth can exhaustively explore the design space, yielding optimal designs in volume. For example, it achieves 8% and 18% volume reduction respectively over two states-of-the-art human designs for the 15-to-1 T-factory, a bottleneck in FTQC.

quant-ph