Skip to content

Fault-Tolerant Gates

A fault-tolerant logical gate is an encoded operation designed so that a small number of faults during the operation cannot spread into an uncorrectable error. Logical correctness in an ideal circuit is necessary but not sufficient. The implementation must also preserve the code’s ability to diagnose, track, or remove faults while the gate is running.

This requirement changes what a gate is. At the physical layer, CNOT may be one calibrated pulse sequence. At the logical layer, the same CNOT may be a transversal circuit, a sequence of joint parity measurements, a deformation of code boundaries, a teleportation gadget, or a conversion into another code followed by a native operation. Its output includes not only a quantum state, but also syndrome records, a decoder decision, and a known logical frame.

The central design question is therefore:

How can an encoded operation implement the intended logical channel while keeping every allowed collection of faults inside a correctable class?

Why Quantum Error Correction Is Possible owns the error-correction conditions. Stabilizer Formalism owns stabilizer codes, logical Pauli operators, syndrome algebra, and Clifford propagation. Syndrome Measurement owns signed check circuits, ordered single-fault ledgers, repeated records, and detector construction; this page retains general bounded-propagation criteria and code-dependent gadget-level containment. Universal Gate Sets owns exact and approximate universality and the distinction between physical, compiled, and logical gate alphabets. Topological Quantum Computation specializes those distinctions to a declared fusion-space encoding, its protected braid/fusion/measurement alphabet, induced projective logical operations, and any non-braid completion; the general correctability and fault-spread contract remains here. For oscillator encodings, Bosonic and Encoded Computation Models owns the induced logical-operation audit for a declared complete physical bosonic program, including leakage, rejection, recovery, frames, and resources; this page retains fault containment and gadget-level fault-tolerance criteria. Surface Code owns the surface-code lattice and patch geometry.

This page is the canonical home for the general fault-tolerant gate contract and for comparing the main ways of satisfying it: transversal gates, code deformation, lattice surgery, gauge fixing, pieceable fault tolerance, and teleportation-based gates. The later dedicated articles on Lattice Surgery and Magic State Distillation own their protocol catalogs, correction tables, and factory constructions. Decoders owns the general inference problem. The Threshold Theorem owns recursive suppression, noise hypotheses, and asymptotic overhead, while the Fault-Tolerant Quantum Computing Frontier owns dated experimental and architecture-level claims.

Quantum Error Correction and Fault Tolerance supplies the correctability, extraction, decoder, and architecture inputs and routes the resulting operation claim; this page retains bounded fault propagation, transversal and deformation mechanisms, surgery, gauge fixing, pieceable and teleported gadgets, frames, and universal completion.

Let an [[n,k,d]][[n,k,d]] code correct

t=⌊d−12⌋t = \left\lfloor \frac{d-1}{2} \right\rfloor

arbitrary physical-qubit errors. A fault is a failure at a circuit location: a preparation, gate, idle, measurement, reset, transport step, or classical-control action. An error is the resulting disturbance on data or ancillas. One fault can create several errors if the circuit lets it propagate.

Consider a logical unitary ULU_L and a physical gadget GU\mathfrak G_U. In a simplified local-fault model, give the input at most ss correctable errors per code block and place rr faults inside the gadget. A distance-dd gadget should satisfy the following implication whenever s+r≤ts+r\leq t:

input error in Es+r gadget faults⟹correct logical ULand a correctable residual error.\begin{aligned} &\text{input error in }\mathcal E_s \quad+\quad r\text{ gadget faults} \\ &\qquad\Longrightarrow \text{correct logical }U_L \quad\text{and a correctable residual error}. \end{aligned}

Here Es\mathcal E_s denotes the declared correctable set. For a nondegenerate Pauli code it may be all errors of weight at most ss. Degenerate codes, erasure models, biased-noise constructions, and bosonic codes can have a more informative correctable set than a weight cutoff.

An ideal decoder makes the logical requirement precise. Let Enc\mathsf{Enc} encode the logical state, let Ns\mathcal N_s represent an allowed input disturbance, and let GU(r)\mathfrak G_U^{(r)} denote a gadget with rr faults. If Dec\mathsf{Dec} includes an ideal final recovery and discards syndrome subsystems, then fault tolerance requires

Tr⁡syn ⁣[Dec∘GU(r)∘Ns∘Enc(ρ)]=ULρUL†\operatorname{Tr}_{\mathrm{syn}} \!\left[ \mathsf{Dec} \circ \mathfrak G_U^{(r)} \circ \mathcal N_s \circ \mathsf{Enc}(\rho) \right] = U_L\rho U_L^\dagger

for the allowed combinations of ss and rr. This is a specification, not a claim that a real decoder is ideal. It separates two questions:

  1. Does the gadget map allowed faults to a correctable logical class?
  2. Can the implemented syndrome extraction and decoder identify that class with acceptable latency and failure probability?

A useful circuit-level formulation separates correctness from spread.

  • With no internal faults, the gadget must implement ULU_L on every valid encoded input, including inputs carrying allowed errors.
  • With internal faults, the gadget must leave no more than the declared correctable damage in each output block, provided the combined input and gadget fault budget is at most tt.

For a multi-block operation, “in each block” is essential. A transversal two-block gate can turn one faulty physical interaction into one error in each block. That is acceptable for a code correcting one error per block, even though the total error has weight two across the machine.

These conditions must cover ancilla preparation, syndrome extraction, measurement faults, classical feedforward, and rejected runs. Proving only that the noiseless data circuit preserves the code space does not prove fault tolerance.

Concatenated-code threshold proofs package operations into gadgets:

  • a gate gadget implements an encoded preparation, gate, or measurement;
  • an error-correction gadget diagnoses and removes or tracks errors;
  • a rectangle combines a gate gadget with trailing error correction;
  • an extended rectangle, or exRec, adds the leading error correction that supplied the gate’s input.

The leading correction of one exRec overlaps the trailing correction of the previous one. That overlap matters when assigning a fault to neighboring logical locations. A standard proof strategy shows that every exRec containing at most tt faults is correct under an ideal-decoder test, and then handles overlapping bad exRecs consistently.

Under independent local stochastic noise with physical fault probability pp, a tt-fault-tolerant gadget cannot fail until at least t+1t+1 suitably placed faults occur. Its low-pp expansion therefore has the form

pL(U)≤At+1(U)pt+1+O ⁣(pt+2),p_{\mathrm L}^{(U)} \leq A_{t+1}^{(U)}p^{t+1} +O\!\left(p^{t+2}\right),

where At+1(U)A_{t+1}^{(U)} counts or bounds malignant fault sets: combinations that can produce logical failure. The coefficient depends on the circuit, noise model, decoder, and acceptance rule. Correlated faults whose joint probability is O(p)O(p) can invalidate the pt+1p^{t+1} suppression even when their support contains t+1t+1 locations.

The Pauli propagation rules for a physical CNOT with control cc and target qq are

Xc⟼XcXq,Zc⟼Zc,Xq⟼Xq,Zq⟼ZcZq.\begin{aligned} X_c &\longmapsto X_cX_q, & Z_c &\longmapsto Z_c, \\ X_q &\longmapsto X_q, & Z_q &\longmapsto Z_cZ_q. \end{aligned}

Suppose one ancilla controls CNOTs into several data qubits. An XX error on that ancilla before the sequence can copy an XX error into every later target. If the ancilla is instead the common target, a ZZ error can propagate back into every later control. A circuit that measures the correct stabilizer in the absence of noise may therefore turn one ancilla fault into a high-weight data error.

This is why fault-tolerant syndrome circuits use verified cat states, encoded ancillas, flag qubits, carefully chosen CNOT orderings, or other containment devices. It is also why the gate and its surrounding error correction must be analyzed together: a propagated error is harmless only if the available record identifies it before it becomes a logical operator.

Comparison of uncontrolled fanout with transversal, pieceable, and measurement-based fault-tolerant logical gate mechanisms

A fault-tolerant mechanism limits the within-block footprint of each allowed fault. Transversality prevents one physical interaction from touching two positions in the same block. Pieceable constructions interrupt controlled propagation with intermediate correction. Measurement-based constructions change checks or teleport the state while retaining a decodable spacetime record. None of the three is safe without its ancilla, measurement, and decoder assumptions.

Partition each of mm code blocks into physical positions j=1,…,nj=1,\ldots,n. A transversal operation has the form

U‾tr=⨂j=1nuj,\overline U_{\mathrm{tr}} = \bigotimes_{j=1}^{n}u_j,

where uju_j may couple position jj across different blocks but never couples two positions from the same block. A fault in uju_j can therefore damage position jj in each participating block, but it cannot spread directly to positions j′≠jj'\neq j within one block.

Transversality is a geometric condition on support. It does not by itself show that U‾tr\overline U_{\mathrm{tr}} preserves the code space or implements the desired logical operator. Those properties must be checked by conjugating the stabilizer and logical operators, or by verifying the action on a logical basis.

CSS Codes owns algebraic preservation of identical-block bitwise CNOT and the extra code structure required for bitwise Hadamard and phase gates. This page retains fault propagation, gadget correctness, the Eastin–Knill limitation, universal completion, and code switching.

Worked example: bitwise CNOT on a CSS code

Section titled “Worked example: bitwise CNOT on a CSS code”

Take two blocks of the same CSS code and apply

CNOT‾=∏j=1nCNOTcj→qj.\overline{\mathrm{CNOT}} = \prod_{j=1}^{n} \mathrm{CNOT}_{c_j\rightarrow q_j}.

The physical CNOT conjugation rules imply

X‾c⟼X‾cX‾q,Z‾c⟼Z‾c,X‾q⟼X‾q,Z‾q⟼Z‾cZ‾q.\begin{aligned} \overline X_c &\longmapsto \overline X_c\overline X_q, & \overline Z_c &\longmapsto \overline Z_c, \\ \overline X_q &\longmapsto \overline X_q, & \overline Z_q &\longmapsto \overline Z_c\overline Z_q. \end{aligned}

The same mapping carries every XX-type control stabilizer into the product of corresponding XX-type stabilizers on the two blocks, and carries every ZZ-type target stabilizer into the corresponding product on the two blocks. The stabilizer group is therefore preserved, and the logical Pauli action is that of a logical CNOT.

If one physical CNOT fails, it may place one error in the control block and one in the target block. A distance-three code can still correct one error in each block. By contrast, a circuit that connects one control qubit to several positions of the same target block loses this immediate containment argument.

The available transversal set is code dependent.

  • Self-dual CSS codes can admit bitwise Hadamard because HH exchanges XX and ZZ checks.
  • Suitable CSS codes admit bitwise CNOT between identical blocks.
  • Steane Code owns the code-specific proofs that H⊗7H^{\otimes7} and bitwise CNOT implement logical HH and logical CNOT and, with Y‾=iX‾Z‾\overline Y=i\overline X\overline Z, that S⊗7S^{\otimes7} implements logical S†S^\dagger; this page retains general transversality, fault spread, the Eastin–Knill limitation, universal completion, and code switching.
  • Fifteen-qubit Reed–Muller constructions admit a transversal non-Clifford phase gate but do not supply every Clifford operation by the same transversal mechanism.
  • Color Codes owns the colex construction and the precise two-dimensional-versus-higher-dimensional boundary for transversal gates in the Clifford hierarchy; this page retains fault propagation, gadget certification, Eastin–Knill, universal completion, and code switching.

A hardware schedule can weaken the abstract benefit. Long-range couplers, movement, spectator interactions, leakage, or a common control line can correlate several nominally separate factors uju_j. The physical fault model must justify treating those factors as independently contained locations.

The Eastin–Knill theorem states, under its exact finite-dimensional assumptions, that a nontrivial code detecting arbitrary errors on each physical subsystem cannot have a universal set of transversal encoded unitaries. The theorem blocks a universal gate set for one fixed exact code using transversality alone. It does not block:

  • a nonuniversal but useful transversal subset;
  • measurements, feedforward, or teleportation;
  • changing codes or gauge choices during the computation;
  • consuming specially prepared resource states;
  • pieceable nontransversal circuits;
  • approximate codes or settings outside the theorem’s assumptions.

There are also locality-sensitive restrictions. For sufficiently large two-dimensional topological stabilizer codes, a constant-depth geometrically local circuit can implement only a logical Clifford operation under the Bravyi–König assumptions. Higher spatial dimension permits higher levels of the Clifford hierarchy, but still imposes structure. These results explain why a protected architecture usually combines several gate mechanisms instead of searching for one static transversal alphabet.

The no-go theorem is not a claim that transversal gates are rare or unimportant. It says that their strongest error-containment property cannot, by itself, provide every operation needed for universal computation.

A code deformation changes the measured constraints gradually while transporting the logical information through the sequence. Let

S0, S1, …, SM\mathcal S_0,\, \mathcal S_1,\, \ldots,\, \mathcal S_M

denote the stabilizer groups active at successive stages. A transition can retire some checks, introduce new checks, move a boundary or defect, change a patch shape, or merge encoded regions. New measurement outcomes determine syndromes, gauge values, or logical-frame updates.

The operation is not certified by showing that the initial and final codes both have distance dd. Faults can form paths through spacetime while the checks are changing. A useful operation-level distance is

dop=min⁡Γ∈Lfail∣Γ∣,d_{\mathrm{op}} = \min_{\Gamma\in\mathcal L_{\mathrm{fail}}} |\Gamma|,

where Lfail\mathcal L_{\mathrm{fail}} is the set of circuit-level fault histories that produce an undetected logical failure for the complete schedule. The relevant object includes measurement rounds and temporal boundaries, not only a static lattice snapshot.

A deformation protocol must specify:

  1. which checks are stopped and started at each time;
  2. how anticommuting old and new checks are handled;
  3. which measurement outcomes set a logical or gauge frame;
  4. how many repeated rounds protect each transition;
  5. what decoder graph or detector model covers the changing geometry;
  6. the minimum operation distance against every relevant fault type.

Code deformation is broader than moving holes in a surface code. It is a general measurement-based change of encoding. A proposed path can be logically valid yet not fault tolerant if an intermediate boundary shortens a logical string, if new checks are measured with unsafe fanout, or if the decoder does not include the transition.

Lattice surgery performs logical operations by merging and splitting neighboring topological-code patches. Its basic primitive is a protected joint logical-Pauli measurement such as

Z‾AZ‾BorX‾AX‾B.\overline Z_A\overline Z_B \qquad\text{or}\qquad \overline X_A\overline X_B.

At a merge, new local checks span a shared boundary. Their product reveals the desired joint logical parity. Repeating the modified check schedule for enough rounds protects the parity against data and measurement faults. A split restores separate patches while preserving a known relation among their logical frames.

An encoded CNOT can be assembled from an ancilla patch, protected Z‾Z‾\overline Z\overline Z and X‾X‾\overline X\overline X parity measurements, an ancilla readout, and classically controlled Pauli-frame updates. The individual parity outcomes are random; their combination and feedforward realize a deterministic logical channel.

Lattice surgery is attractive in a two-dimensional nearest-neighbor layout because it replaces a direct transversal interaction between distant blocks with local boundary measurements. It does not make logical gates instantaneous. A distance-dd merge or split generally consumes O(d)O(d) syndrome rounds and O(d2)O(d^2) active qubit area, with architecture-dependent constants, routing space, and parallelism.

The dedicated Lattice Surgery article owns detailed patch conventions, rough-versus-smooth merge rules, CNOT correction tables, multi-patch Pauli measurements, twist-based variants, and scheduling. Here the canonical point is that surgery is a fault-tolerant parity-measurement mechanism, not a geometric animation alone.

A subsystem code has a gauge group G\mathcal G whose center determines the stabilizer,

S=Z(G)∩G,\mathcal S = Z(\mathcal G)\cap\mathcal G,

up to phase conventions. Gauge degrees of freedom are not protected logical data. Dressed logical Paulis are represented by C(S)/GC(\mathcal S)/\mathcal G, where C(S)C(\mathcal S) is the Pauli centralizer of the stabilizer.

Gauge fixing measures a commuting set of gauge operators and promotes their outcomes to fixed constraints. Different choices can expose different transversal logical gates while preserving the same protected logical subsystem. A transition has three conceptual steps:

  1. stop enforcing constraints that distinguish the old gauge choice;
  2. fault tolerantly measure the new commuting gauge operators;
  3. use their outcomes to apply a correction or update a frame for the new code.

The measurement must not reveal protected logical information. Algebraically, the newly fixed operators must act only on gauge degrees of freedom relative to the shared logical subsystem. Operationally, the syndrome circuit and decoder must distinguish measurement faults from genuine gauge changes.

Gauge fixing unifies several constructions. Three-dimensional gauge color codes use it to combine complementary transversal gates. Related code-switching protocols between Steane and Reed–Muller descriptions can exchange which Clifford or non-Clifford operation is transversal. More generally, code deformation and lattice surgery can be formulated as gauge fixing in an enlarged subsystem code.

The unification is conceptual, not a promise of equal cost. Two gauge choices may require different check weights, connectivity, ancilla factories, decoder models, or numbers of repeated rounds.

A nontransversal circuit can sometimes be made fault tolerant by dividing it into pieces:

UL=VmVm−1⋯V1.U_L = V_mV_{m-1}\cdots V_1.

Intermediate error correction is inserted between selected pieces:

GU=ECmVm⋯EC2V2EC1V1.\mathfrak G_U = \mathrm{EC}_m V_m \cdots \mathrm{EC}_2 V_2 \mathrm{EC}_1 V_1.

The point is not that every VjV_j is independently transversal. A fault may create a contagious error, meaning an error that would spread to too many qubits under later pieces. The partition is chosen so that:

  • each piece creates only a bounded number of contagious errors from the allowed faults;
  • the intermediate syndrome contains enough information to identify or constrain those errors;
  • errors that are not corrected immediately cannot become uncorrectable before the next correction step;
  • the complete gadget passes the ideal-decoder fault test.

This construction can provide logical Toffoli or CCZ gates directly on small stabilizer codes. Its cost is extra correction rounds, specialized syndrome logic, and a proof tailored to the interaction graph. Arbitrarily slicing a nontransversal circuit and inserting a standard recovery is not sufficient: the intermediate recovery may encounter error patterns outside the code’s usual bounded-weight decoder assumptions.

Teleportation separates interaction with data from preparation of a resource. Define

∣Φ+⟩=∣00⟩+∣11⟩2,∣Φab⟩=(I⊗XaZb)∣Φ+⟩.|\Phi^+\rangle = \frac{|00\rangle+|11\rangle}{\sqrt2}, \qquad |\Phi_{ab}\rangle = \left(I\otimes X^aZ^b\right)|\Phi^+\rangle.

The teleportation identity is, up to irrelevant outcome-dependent phases,

∣ψ⟩1∣Φ+⟩23=12∑a,b=01∣Φab⟩12XaZb∣ψ⟩3.|\psi\rangle_1|\Phi^+\rangle_{23} = \frac12 \sum_{a,b=0}^{1} |\Phi_{ab}\rangle_{12} X^aZ^b|\psi\rangle_3.

A Bell measurement of systems 1 and 2 therefore transfers the state to system 3 with a known Pauli byproduct. At the logical level, the Bell pair, Bell measurement, and byproduct tracking must all be fault tolerant.

For gate teleportation, prepare

∣ΦU⟩=(I⊗U)∣Φ+⟩.|\Phi_U\rangle = \left(I\otimes U\right)|\Phi^+\rangle.

The output becomes

UXaZb∣ψ⟩=(UXaZbU†)U∣ψ⟩.UX^aZ^b|\psi\rangle = \left( UX^aZ^bU^\dagger \right) U|\psi\rangle.

If UU is Clifford, the byproduct remains Pauli and can usually be absorbed into a Pauli frame. For a non-Clifford UU, the correction can lie higher in the Clifford hierarchy and may require an adaptive operation, another resource state, or a selective teleportation pattern.

Teleportation moves risk; it does not remove it. The entangled resource must be prepared, verified or distilled, stored, routed, and consumed. A bad resource can inject a logical error directly into the data. The advantage is that much of this preparation can occur offline, and rejected resources need not disturb the data if the interface is designed correctly.

The dedicated Magic State Distillation article owns noisy non-Clifford state purification, exact recurrence maps, and factory protocols. Quantum Teleportation owns the full state-transfer derivation.

No mechanism is uniformly best. The relevant comparison is between complete gadgets under the same physical and logical contract.

MechanismHow spread is controlledTypical logical useMain hidden burden
transversalno physical factor touches two positions in one blockcode-native Clifford or selected non-Clifford gatesconnectivity, common-mode faults, incomplete gate set
code deformationchecks change along a protected spacetime pathmovement, braiding, basis change, code conversiontransition distance and time-dependent decoding
lattice surgeryrepeated local checks measure joint logical parityCNOT, multi-patch Pauli measurements, routingpatch area, repeated rounds, boundary scheduling
gauge fixingmeasured gauge operators select a code or gauge sectorswitch between complementary transversal gatesextra checks, gauge decoder, conversion faults
pieceable circuitintermediate recovery interrupts contagious errorsdirect Toffoli, CCZ, or other nontransversal gatescorrection latency and circuit-specific proof
teleportationverified resource and Bell measurement replace direct data interactionClifford gates, injection, code transferresource preparation, feedforward, rejection, storage

Hybrid architectures are normal. A processor may use transversal Clifford gates inside a small code, teleport between code blocks, use gauge fixing for a non-Clifford operation, and perform surface-code parity measurements for routing. The compiler must know which mechanism implements each logical instruction and what classical dependencies it creates.

A useful architecture needs more than individually protected gates. It needs a fault-tolerant set that is computationally universal after all allowed preparations, measurements, ancillas, and feedforward are included.

The most common organization is:

  1. implement logical Clifford operations by a relatively inexpensive code-native mechanism;
  2. add a non-Clifford resource such as TT, Toffoli, or CCZ through teleportation, gauge fixing, code switching, or a pieceable circuit;
  3. compile the algorithm into that logical alphabet with a declared synthesis error;
  4. allocate logical failure probability across gates, memory, factories, routing, and classical control.

The error budget has at least two distinct contributions:

ϵtot≲ϵsynth+∑j=1NopϵL(j)+ϵcorr,\epsilon_{\mathrm{tot}} \lesssim \epsilon_{\mathrm{synth}} + \sum_{j=1}^{N_{\mathrm{op}}} \epsilon_{\mathrm L}^{(j)} + \epsilon_{\mathrm{corr}},

where ϵsynth\epsilon_{\mathrm{synth}} is approximation error, ϵL(j)\epsilon_{\mathrm L}^{(j)} is the logical failure contribution of operation jj, and ϵcorr\epsilon_{\mathrm{corr}} collects correlations or composition terms not represented by a naive sum. The bound is useful only after the metric and noise assumptions are specified.

Gate Decomposition owns synthesis algorithms and approximation costs. Resource Estimation Tools owns end-to-end accounting.

Many logical gates do not end with a physical correction. They end with a known Pauli frame

F∈PLF \in \mathcal P_L

that records how the represented logical state differs from a chosen reference frame. Under a logical Clifford CLC_L,

F⟼CLFCL†,F \longmapsto C_LFC_L^\dagger,

which remains Pauli and can be tracked classically. A later measurement basis or non-Clifford gadget must be adapted to that frame.

The syndrome decoder and the gate controller therefore share state. During deformation or surgery, detector definitions change with time. During teleportation, Bell outcomes create byproducts. During gauge fixing, measured gauge values select a correction. During a pieceable circuit, an intermediate recovery may determine whether the next segment is allowed to proceed.

A decoder that eventually returns the right answer can still be too late. The gate contract must distinguish:

  • throughput, the sustained rate of syndrome processing;
  • decision latency, the time before a dependent operation can be chosen;
  • frame latency, the time before an outcome must affect a basis or resource-selection decision;
  • terminal latency, the time needed to finalize an operation or readout.

Clifford frame updates can often be deferred. Non-Clifford branching, real-time reset, patch reuse, and final measurement can create hard deadlines. Decoders develops this classical inference and timing contract.

Weight-counting proofs are valuable, but a physical implementation must test their assumptions.

A shared laser pulse, microwave line, coupler, clock, or calibration error can affect many nominally transversal locations. Calling the circuit transversal does not make those physical faults independent.

A leaked qubit can interact incorrectly with several partners over time. A transversal layer followed by ordinary Pauli recovery may not contain it. Leakage-reduction units, reset, teleportation, erasure flags, or schedules that limit lifetime must be part of the gadget.

Small systematic overrotations can add coherently across repeated logical gates. A Pauli-stochastic simulation can underestimate the resulting logical channel unless randomization or a coherent-noise analysis is justified.

Surgery, deformation, and resource-state routing create waits. The memory locations occupied during a logical gate are part of the operation, not a separate free resource.

Measurement-based gates inherit assignment error, reset error, crosstalk, classical bit corruption, and delayed feedforward. Repetition protects only against the faults represented in the spacetime detector model.

A gadget optimized for independent depolarizing noise may perform poorly under biased, erasure-dominated, temporally correlated, or nonstationary noise. Fault tolerance is always relative to a declared fault set or probabilistic model.

A complete claim reports the operation as a system:

Contract itemQuestions to answer
codeWhich code, distance, gauge, boundaries, and logical basis are active?
gadgetWhich physical locations, ancillas, checks, and feedforward implement the operation?
noiseWhich stochastic, coherent, correlated, leakage, loss, and drift mechanisms are included?
decoderWhich records and priors are used, and when must each decision arrive?
outputIs the result a corrected state, frame update, parity, herald, or postselected sample?
costWhat qubit area, duration, syndrome volume, resource-state consumption, and energy are counted?
metricIs failure a wrong logical Pauli, channel distance, conditional infidelity, or algorithmic error?
evidenceIs the result a proof, circuit-level simulation, hardware experiment, or extrapolation?

Benchmark preparation, leading and trailing correction, the gate body, ancilla verification, measurements, decoder decisions, feedforward, and rejection. A high-fidelity encoded state after postselection does not give the unconditional failure rate unless acceptance probability and retry cost are included.

A fault-tolerant gate may be compared with:

  • the same logical operation at lower code distance;
  • an unencoded implementation using comparable elapsed time and hardware;
  • an encoded but non-fault-tolerant circuit;
  • a memory experiment lasting as long as the gate;
  • the architecture’s allocated logical error budget.

Each comparison answers a different question. A gate can beat an unencoded baseline yet fail to improve with distance. It can improve with distance yet remain too slow for an algorithm. It can have low conditional infidelity but unacceptable rejection overhead.

Repeated and interleaved logical sequences can reveal coherent accumulation, frame bugs, decoder backlog, leakage persistence, and crosstalk that one state-transfer experiment misses. Process metrics should be accompanied by syndrome statistics and leakage or erasure records when those channels are relevant. Reporting Standards provides the broader evidence checklist.

  1. Specify the logical channel. Fix the code, logical basis, accepted outputs, approximation tolerance, and whether measurements or postselection are allowed.
  2. Declare the fault model. Include circuit locations, correlations, leakage, loss, idle periods, and classical-control failures.
  3. Trace propagation. Conjugate a basis of errors through every segment and identify faults that can become logical.
  4. Add containment. Choose transversality, flags, verified ancillas, intermediate correction, changing checks, teleportation, or a hybrid.
  5. Prove the gadget criterion. Show that every allowed fault set leaves the ideal logical action and a correctable residual class.
  6. Compile the detector model. Include temporal boundaries, deformation, gauge outcomes, and frame updates in the decoder input.
  7. Estimate complete cost. Count time, area, ancillas, retries, routing, decoding, and factory throughput.
  8. Validate scaling. Use circuit-level simulation and hardware data over enough sizes, depths, and operating points to test the intended suppression law.

An operation can preserve the code space in a noiseless calculation while one internal fault spreads to a logical error. Encoding alone does not prove containment.

Calling every bitwise operation a logical gate

Section titled “Calling every bitwise operation a logical gate”

A tensor product of physical gates is transversal by support, but it may not normalize the stabilizer or may implement the wrong logical operator.

Clifford operations alone are not universal, and Eastin–Knill forbids a universal transversal unitary set under its assumptions. The missing non-Clifford mechanism must be stated.

A deformation can begin and end with distance dd while a short spacetime fault path exists during the transition.

Treating parity measurement as instantaneous

Section titled “Treating parity measurement as instantaneous”

Lattice surgery requires repeated checks, decoding, ancilla space, and feedforward. The joint logical observable is the protocol’s result, not the first noisy boundary-check bit.

Teleportation transfers both state and dependence on a resource. Unverified entanglement, faulty Bell measurement, or wrong frame updates can inject a logical error.

Postselection can lower conditional error while making expected time or resource use diverge near a poor operating point.

Using physical-gate fidelity as logical-gate fidelity

Section titled “Using physical-gate fidelity as logical-gate fidelity”

Logical failure depends on correlated fault paths, syndrome extraction, decoder behavior, and composition. An average physical fidelity is not a logical operation certificate.

An ancilla is the control of CNOTs into data qubits q1,…,qwq_1,\ldots,q_w. An XX error occurs on the ancilla immediately before the first CNOT. Find the error after all ww gates. Repeat for a ZZ error when the ancilla is the common target.

Solution

For each CNOT, XX on the control propagates to XX on both control and target. The ancilla error remains and deposits one XX on every target:

Xa⟼Xa∏j=1wXqj.X_a \longmapsto X_a \prod_{j=1}^{w}X_{q_j}.

When the ancilla is the common target, ZZ on the target propagates backward to the control at each gate:

Za⟼Za∏j=1wZqj.Z_a \longmapsto Z_a \prod_{j=1}^{w}Z_{q_j}.

Thus one ancilla fault can create a weight-ww data error. The noiseless parity-measurement identity does not reveal this failure mode.

For two blocks of the same CSS code, use physical Pauli propagation to show that bitwise CNOT maps logical Paulis as a logical CNOT and preserves the stabilizer group.

Solution

Every XX operator on the control block is copied to the corresponding position of the target, while every ZZ operator on the target is copied to the control. Therefore

X‾c↦X‾cX‾q,Z‾c↦Z‾c,X‾q↦X‾q,Z‾q↦Z‾cZ‾q.\begin{aligned} \overline X_c&\mapsto\overline X_c\overline X_q, & \overline Z_c&\mapsto\overline Z_c, \\ \overline X_q&\mapsto\overline X_q, & \overline Z_q&\mapsto\overline Z_c\overline Z_q. \end{aligned}

The same statements hold for the XX- and ZZ-type stabilizer generators. Their products remain stabilizers of the two-block code. The induced normalizer action is exactly the logical CNOT action.

A distance-three exRec has NN physical locations and fails only when a pair from a set of A2A_2 malignant pairs is faulty, up to events with three or more faults. Bound its logical failure probability for independent faults of probability pp. Why can a correlated pair mechanism spoil the result?

Solution

The union bound gives

pL≤A2p2+∑j=3N(Nj)pj(1−p)N−j.p_{\mathrm L} \leq A_2p^2 + \sum_{j=3}^{N} \binom Nj p^j(1-p)^{N-j}.

At low pp this is

pL≤A2p2+O(p3).p_{\mathrm L} \leq A_2p^2+O(p^3).

If one physical mechanism produces both faults together with probability O(p)O(p), that malignant pair contributes at first order rather than second order. The quadratic suppression relied on the local stochastic assumption, not on code distance alone.

Write two consecutive logical gate rectangles and identify which error-correction gadget belongs to both extended rectangles. Explain why a threshold proof cannot count its faults independently twice.

Solution

Let the sequence be

EC0  G1  EC1  G2  EC2.\mathrm{EC}_0 \;G_1\; \mathrm{EC}_1 \;G_2\; \mathrm{EC}_2.

The first exRec is EC0G1EC1\mathrm{EC}_0G_1\mathrm{EC}_1, and the second is EC1G2EC2\mathrm{EC}_1G_2\mathrm{EC}_2. Thus EC1\mathrm{EC}_1 is shared. A fault there can affect the output of the first rectangle and the input of the second. Independent double counting would assign incompatible explanations to the same physical event. Rigorous constructions truncate or otherwise classify overlapping bad exRecs consistently.

5. Derive the gate-teleportation byproduct

Section titled “5. Derive the gate-teleportation byproduct”

Starting from the teleportation identity, replace the Bell resource by ∣ΦU⟩=(I⊗U)∣Φ+⟩|\Phi_U\rangle=(I\otimes U)|\Phi^+\rangle. Show the output associated with Bell outcome (a,b)(a,b) and identify the correction.

Solution

Applying UU to the output half of the ordinary resource gives

∣ψ⟩∣ΦU⟩=12∑a,b∣Φab⟩UXaZb∣ψ⟩.|\psi\rangle|\Phi_U\rangle = \frac12 \sum_{a,b} |\Phi_{ab}\rangle UX^aZ^b|\psi\rangle.

The output can be written as

UXaZb∣ψ⟩=(UXaZbU†)U∣ψ⟩.UX^aZ^b|\psi\rangle = \left(UX^aZ^bU^\dagger\right)U|\psi\rangle.

Thus the known byproduct is UXaZbU†UX^aZ^bU^\dagger, up to phase, and its inverse is the required correction. For Clifford UU it is Pauli and can be tracked in a Pauli frame. For non-Clifford UU, the correction may require adaptive protected logic.

A proposed gauge-fixing measurement anticommutes with a protected logical Z‾\overline Z but is claimed to act only on a gauge subsystem. Diagnose the claim.

Solution

An operator acting only on the gauge subsystem must commute with the protected logical algebra. If the measured operator anticommutes with Z‾\overline Z, its outcome distinguishes or disturbs the conjugate logical information. It cannot be treated as a harmless gauge measurement under that logical identification. Either the logical representatives have been misidentified, the transition intentionally performs a logical measurement, or the proposed gauge fixing is invalid.

7. Why arbitrary circuit slicing is insufficient

Section titled “7. Why arbitrary circuit slicing is insufficient”

Suppose each segment of a nontransversal circuit can double the support of one particular error. Compare the worst-case support after mm segments with no intermediate correction and with a correction after every segment. What additional fact is needed for the second construction to be fault tolerant?

Solution

Without correction, one error can reach support as large as 2m2^m. If each intermediate correction truly removes the contagious component, the support can be returned to the code’s correctable set after every segment instead of growing exponentially.

The missing fact is that the intermediate syndrome procedure can reliably identify the error patterns produced by that segment, including faults in the correction itself. Standard recovery guarantees for arbitrary bounded-weight input errors may not cover correlated patterns created by the partial gate. A pieceable proof must establish this segment-specific diagnosability.

8. Choose a mechanism under architectural constraints

Section titled “8. Choose a mechanism under architectural constraints”

An architecture has a two-dimensional nearest-neighbor data plane, fast local measurement, slow long-range movement, and an abundant supply of verified Clifford ancillas. Compare a transversal inter-block CNOT, lattice surgery, and teleportation for a logical CNOT. Which information is still needed before choosing?

Solution

A direct transversal CNOT may require nn long-range pairings and conflict with the connectivity constraint. Lattice surgery uses local joint checks but occupies boundary space and repeated syndrome rounds. Teleportation can move the interaction into an offline Bell resource, but then resource routing, Bell measurement, feedforward, and rejected-resource cost matter.

No unique choice follows from the qualitative description. One still needs code distance, patch layout, physical error channels, operation durations, ancilla preparation error and throughput, decoder latency, available parallelism, and the target logical error per CNOT. The comparison must use complete spacetime cost and logical failure, not gate count alone.

  1. P. W. Shor, “Fault-tolerant quantum computation,” in Proceedings of the 37th Annual Symposium on Foundations of Computer Science, 56–65 (1996), arXiv:quant-ph/9605011.
  2. D. Gottesman, “A theory of fault-tolerant quantum computation,” PhD thesis, California Institute of Technology (1997), arXiv:quant-ph/9702029.
  3. A. M. Steane, “Active stabilization, quantum computation, and quantum state synthesis,” Physical Review Letters 78, 2252–2255 (1997), doi:10.1103/PhysRevLett.78.2252.
  4. P. Aliferis, D. Gottesman, and J. Preskill, “Quantum accuracy threshold for concatenated distance-3 codes,” Quantum Information and Computation 6, 97–165 (2006), arXiv:quant-ph/0504218.
  5. B. M. Terhal, “Quantum error correction for quantum memories,” Reviews of Modern Physics 87, 307–346 (2015), doi:10.1103/RevModPhys.87.307.
  6. B. Eastin and E. Knill, “Restrictions on transversal encoded quantum gate sets,” Physical Review Letters 102, 110502 (2009), doi:10.1103/PhysRevLett.102.110502.
  7. S. Bravyi and R. König, “Classification of topologically protected gates for local stabilizer codes,” Physical Review Letters 110, 170503 (2013), doi:10.1103/PhysRevLett.110.170503.
  8. H. Bombin and M. A. Martin-Delgado, “Quantum measurements and gates by code deformation,” Journal of Physics A 42, 095302 (2009), doi:10.1088/1751-8113/42/9/095302.
  9. C. Horsman, A. G. Fowler, S. Devitt, and R. Van Meter, “Surface code quantum computing by lattice surgery,” New Journal of Physics 14, 123011 (2012), doi:10.1088/1367-2630/14/12/123011.
  10. H. Bombin, “Gauge color codes: optimal transversal gates and gauge fixing in topological stabilizer codes,” New Journal of Physics 17, 083002 (2015), doi:10.1088/1367-2630/17/8/083002.
  11. A. Paetznick and B. W. Reichardt, “Universal fault-tolerant quantum computation with only transversal gates and error correction,” Physical Review Letters 111, 090505 (2013), doi:10.1103/PhysRevLett.111.090505.
  12. J. T. Anderson, G. Duclos-Cianci, and D. Poulin, “Fault-tolerant conversion between the Steane and Reed–Muller quantum codes,” Physical Review Letters 113, 080501 (2014), doi:10.1103/PhysRevLett.113.080501.
  13. C. Vuillot, L. Lao, B. Criger, C. García Almudéver, K. Bertels, and B. M. Terhal, “Code deformation and lattice surgery are gauge fixing,” New Journal of Physics 21, 033028 (2019), doi:10.1088/1367-2630/ab0199.
  14. T. J. Yoder, R. Takagi, and I. L. Chuang, “Universal fault-tolerant gates on concatenated stabilizer codes,” Physical Review X 6, 031039 (2016), doi:10.1103/PhysRevX.6.031039.
  15. D. Gottesman and I. L. Chuang, “Demonstrating the viability of universal quantum computation using teleportation and single-qubit operations,” Nature 402, 390–393 (1999), doi:10.1038/46503.
  16. E. Knill, “Quantum computing with realistically noisy devices,” Nature 434, 39–44 (2005), doi:10.1038/nature03350.
  17. S. Bravyi and A. Kitaev, “Universal quantum computation with ideal Clifford gates and noisy ancillas,” Physical Review A 71, 022316 (2005), doi:10.1103/PhysRevA.71.022316.
  18. A. G. Fowler, M. Mariantoni, J. M. Martinis, and A. N. Cleland, “Surface codes: Towards practical large-scale quantum computation,” Physical Review A 86, 032324 (2012), doi:10.1103/PhysRevA.86.032324.
  19. C. Chamberland and M. E. Beverland, “Flag fault-tolerant error correction with arbitrary distance codes,” Quantum 2, 53 (2018), doi:10.22331/q-2018-02-08-53.
  20. D. Litinski, “A game of surface codes: Large-scale quantum computing with lattice surgery,” Quantum 3, 128 (2019), doi:10.22331/q-2019-03-05-128.
  21. D. A. Lidar and T. A. Brun, eds., Quantum Error Correction, Cambridge University Press (2013), doi:10.1017/CBO9781139034807.