arXiv ScienceSearch

arXiv subjects

Jiachen Shen

Publications and source records attributed to Jiachen Shen.

4 recordsLinked to original sources

Execution-transcript privacy for fault-tolerant surface-code memories

A fault-tolerant quantum computer runs behind a telemetry stream logging syndromes, decoder actions, resets and timing separately from the answer. Can it reveal the logical input? For a distance-$d$ rotated surface-code memory on a fixed schedule of $T=Θ(d)$ rounds, under three stated hypotheses (sector-scalar honest backbone, transcript locality, Kotecky-Preiss smallness), the channel from logical qubit to transcript is $e^{-Θ(d)}$-close in diamond norm to one that ignores the input. A statement of this kind follows generically from correctability-privacy duality. Anisotropy does not. Each logical axis pays the distance of its own coset, so under amplitude damping the computational-basis label is governed by the code's $Z$-distance $d_Z\ge d_{\min}$ and not by the code distance. Two codes of quantum distance $1$ make the gap concrete. A phase-flip code's $X$-syndrome transcript is exactly input-independent under unobserved damping, while a repetition code leaks at first order. A matched converse identifies the records that do expose it, among them a lattice-surgery parity readout. On a 156-qubit superconducting processor our sufficient certificate misses by $21.5\times$, so the theorem cannot be invoked there. Measured directly, a $d_Z=1$ memory's record identifies its input with total variation $\ge 0.927$ under randomised, label-balanced acquisition. Holding the code fixed and varying the damping exposure reproduces the parameter-free law, with exponent $0.85\pm0.03$ against a predicted $0.86$. Randomized encoding returns the statistic to the floor at no two-qubit-gate cost. Fault tolerance does not grant transcript privacy. It relocates it, and only to the logical state, not to the circuit's identity.

quant-ph

Capability-Gated Conformance Testing of Quantum Error-Correction Decoder Libraries

A quantum error correction decoder is a library other people's results depend on, judged in one dominant way. Sample errors, decode, and count wrong logical observables. We ask what else can be checked there. Our conformance contract needs no oracle. One check asks that a returned correction explain the syndrome in the caller's index space. The other hands a decoder one instance under two presentations differing only in bookkeeping, where two feasible corrections of different weight prove the heavier is not minimum-weight. Verdicts are gated on what each library declares, so a firing contradicts a published guarantee. Nine configurations from five public libraries give three results. Documentation answers 4 of 54 capability questions. Bounded-distance correctness, the property callers most depend on, has a direct declaration yield of 0.0%, though its hypotheses hold in 62.1% of cases. Presentation sensitivity is real but shallow. One solver moved to a 26% heavier correction under a different numbering, which reaches the logical class at most once in twenty thousand shots. Established evaluation misses corruptions that preserve logical parity, while one summation over the caller's weights catches every one we injected. All 639 certificates ship as bundles a standalone verifier re-derives from first principles.

quant-ph

RedVLA: Physical Red Teaming for Vision-Language-Action Models

The real-world deployment of Vision-Language-Action (VLA) models remains limited by the risk of unpredictable and irreversible physical harm. However, we currently lack effective mechanisms to proactively detect these physical safety risks before deployment. To address this gap, we propose \textbf{RedVLA}, the first red teaming framework for physical safety in VLA models. We systematically uncover unsafe behaviors through a two-stage process: (I) \textbf{Risk Scenario Synthesis} constructs a valid and task-feasible initial risk scene. Specifically, it identifies critical interaction regions from benign trajectories and positions the risk factor within these regions, aiming to entangle it with the VLA's execution flow and elicit a target unsafe behavior. (II) \textbf{Risk Amplification} ensures stable elicitation across heterogeneous models. It iteratively refines the risk factor state through gradient-free optimization guided by trajectory features. Experiments on six representative VLA models show that RedVLA uncovers diverse unsafe behaviors and achieves the ASR up to 95.5\% within 10 optimization iterations. To mitigate these risks, we further propose SimpleVLA-Guard, a lightweight safety guard built from RedVLA-generated data. Our data, assets, and code are available \href{https://redvla.github.io}{here}.

cs.RO

Explicit Separators for Consecutive Levels of Parrilo's Sum-of-Squares Hierarchy over the Copositive Cone

Parrilo's cones $\Kc{n}{r}$ form a nested sequence of semidefinite-representable inner approximations of the copositive cone $\COP_n$. For $n=5$ their union is all of $\COP_5$, yet no single level attains it, and whether consecutive levels actually differ had remained open beyond the classical first step. No explicit matrix in $\Kc{n}{t}\setminus\Kc{n}{t-1}$ had, to our knowledge, been published for any $t\ge2$ and $n\ge5$. We settle the first three cases. Explicit rational matrices, obtained from diagonal scalings of the Horn matrix shifted along a positive interior direction, lie in $\Kc{5}{2}\setminus\Kc{5}{1}$, in $\Kc{5}{3}\setminus\Kc{5}{2}$, and in $\Kc{5}{4}\setminus\Kc{5}{3}$, giving three consecutive strict inclusions $\Kc{5}{1}\subsetneq\Kc{5}{2}\subsetneq\Kc{5}{3}\subsetneq\Kc{5}{4}$. Each is certified by an exact rational Gram matrix and an exact rational dual moment functional, re-verified by a standalone program in integer arithmetic. The separations are robust. One fixed certificate pair covers an interval of shifts of width exceeding $3\cdot10^{-3}$, and $\Kc{5}{2}\setminus\Kc{5}{1}$ has nonempty interior. Combining a scaling theorem of Dickinson, Dür, Gijben and Hildebrand with the completeness theorem of Schweighofer and Vargas shows further that strict adjacent inclusions recur at arbitrarily large levels. All separators were located by one threshold device: the least shift $\eps_r(M)$ carrying $M$ into $\Kc{5}{r}$ along an interior direction is nonincreasing in $r$, and each strict drop between levels marks a window of separators.

eess.SY