Skip to content

Network Verification

Quantum-network verification is the inference that a network delivered a declared quantum object or service with declared quality, under a declared trust model and finite-data error guarantee. The object may be an endpoint Bell pair, a multipartite graph state, a quantum channel, a remote operation, or a service transcript. The evidence may come from calibrated local measurements, state-verification tests, steering, Bell correlations, network-locality tests, challenge requests, or operational logs.

Verification is narrower than complete characterization and broader than measuring one fidelity. A useful certificate must say what was tested, which uses were eligible, what was trusted, which null model was rejected, how loss and postselection were handled, and what later use the result covers. A Bell pair measured for tomography no longer exists for an application. A certificate for retained pairs therefore needs a sampling argument connecting sacrificed test systems to unmeasured systems.

This page is the canonical home for the network-level verification contract: test-versus-use sampling, endpoint and multipartite state checks, source-independence tests, channel and heralding checks, service-level acceptance, route diagnosis, adversarial nodes, and continuous monitoring. Certification of Entanglement owns the general hierarchy of witnesses, steering, Bell tests, and self-testing. State Tomography and Process Tomography own reconstruction. Quantum Network Architectures owns services, layers, routing, inventory, and trust domains. Network Case Studies owns experiment-by-experiment evidence. Here those pieces are assembled into a decision about a delivered network service. Distributed Quantum Sensing owns the separate application-level question of whether a verified resource improves a calibrated weighted-field estimator under matched resources.

“The network works” has no mathematical complement and therefore no test. A verification task should begin with a record such as

V=(O,S,H0,H1,T,M,A,α,β).\mathcal V = \left( O,S,H_0,H_1,\mathsf T,\mathsf M,\mathsf A, \alpha,\beta \right).

Here:

  • OO is the delivered object and its endpoint identities;
  • SS is the sample frame: eligible requests, routes, times, and exclusions;
  • H0H_0 is the bad-service class to be controlled;
  • H1H_1 is the intended good-service class;
  • T\mathsf T is the device, source, node, and causal trust model;
  • M\mathsf M is the randomized measurement or challenge design;
  • A\mathsf A is the acceptance rule fixed before seeing outcomes;
  • α\alpha bounds false certification under H0H_0;
  • β\beta is a target bound on failing to certify a specified good alternative.

The two error probabilities answer different questions. A small α\alpha protects against declaring a bad service good. A small β\beta gives the test power to recognize a useful service. Neither is the posterior probability that the network is good.

A threshold claim might be

H0:FAB≤Fmin⁡versusH1:FAB≥Fmin⁡+Δ,H_0:F_{AB}\leq F_{\min} \qquad\text{versus}\qquad H_1:F_{AB}\geq F_{\min}+\Delta,

where Δ>0\Delta>0 is the indifference margin used for power planning. Omitting Δ\Delta can make the required sample size appear mysteriously large: no finite experiment reliably distinguishes parameters separated by an arbitrarily small amount.

Different observations support different conclusions.

ClaimTypical evidenceWhat it does not establish
component respondssource counts, detector tests, memory calibrationendpoint entanglement
elementary link delivers a stateendpoint correlations with a declared heraldmulti-hop performance
endpoint state is entangledwitness, steering, or Bell testtarget-state fidelity unless separately bounded
endpoint state is close to a targetfidelity test or state verificationarbitrary channel behavior
route implements a channelprocess test or entangled-input testsustained rate and availability
multipartite resource is presentstabilizer, witness, or network protocolhonesty of every party
source-independence model is violatedbilocal or network-locality statisticunique physical topology
service meets its contractjoint quality, rate, latency, identity, and failure testscryptographic secrecy without a security proof

A successful swap herald plus two bright detectors proves neither that the end memories are entangled nor that the application received the correct pair. A high reconstructed fidelity proves neither that requests are served on time nor that discarded attempts were independent of the settings. Conversely, a service can be useful for a restricted task without supporting complete state or process tomography.

Most network tests are destructive. Measuring X⊗XX\otimes X on a Bell pair consumes that pair. Verification therefore certifies a population, process, or future use only through a sampling theorem and its assumptions.

Eligible network deliveries are assigned at random to a destructive test pool or an application pool, with both branches tied to one authenticated audit ledger.

A certificate does not jump automatically from measured pairs to retained pairs. Random assignment, hidden test choices, authenticated identities, and a declared statistical or adversarial model provide that bridge. The audit ledger must include every eligible attempt, not only successful-looking records.

Suppose a batch contains NN eligible deliveries. A secret random subset T⊆{1,…,N}T\subseteq\{1,\ldots,N\} is assigned to testing and the complement UU to use. A valid statement about UU requires conditions such as exchangeability, random sampling without replacement, an independent-use model, or a protocol proved against correlated and adversarial preparations. Choosing TT after looking at heralds, routes, or preliminary outcomes can destroy the guarantee.

The sampling unit must also be explicit. It might be an optical attempt, a heralded memory pair, an accepted end-to-end pair, a remote gate, or a complete application transaction. Changing the unit changes both the denominator and the claim.

There is no universally strongest practical test. Reducing trust generally requires stronger correlations, more trials, tighter causal control, or a weaker conclusion.

ModelTrusted elementsTypical conclusion
calibrated-devicestate dimension, endpoint POVMs, labels, classical recordswitness value, fidelity, or reconstructed state
untrusted sourceendpoint measurements and randomnesstarget-state verification against a faulty or adversarial source
one-sided device-independentone endpoint laboratorysteering or fidelity guarantee with the other side uncharacterized
device-independentinput choices, outputs, laboratory isolation, causal orderentanglement or state/measurement equivalence from Bell correlations
network-device-independentthe preceding interface plus a source-independence or causal graph assumptionincompatibility with a network-local model, sometimes network-assisted self-testing

“Device-independent” never means assumption-free. Current inputs must be sufficiently private, every eligible trial needs a declared output, forbidden communication must be excluded during the trial, and the classical analysis must be trusted. A network-locality conclusion adds assumptions about which sources share common causes. If two nominally independent sources are pumped by one controller with hidden correlated state, a bilocal model is the wrong null.

Device-Independent QKD owns the stronger step from observed Bell data to composable secret key. A network Bell violation by itself is not a key-security proof.

For the target

∣Φ+⟩=∣00⟩+∣11⟩2,|\Phi^+\rangle = \frac{|00\rangle+|11\rangle}{\sqrt2},

the projector has the Pauli expansion

∣Φ+⟩⟨Φ+∣=14(I⊗I+X⊗X−Y⊗Y+Z⊗Z).|\Phi^+\rangle\langle\Phi^+| = \frac14 \left( I\otimes I +X\otimes X -Y\otimes Y +Z\otimes Z \right).

For any two-qubit state ρ\rho, not merely a Bell-diagonal state,

FΦ+=14(1+cX−cY+cZ),F_{\Phi^+} = \frac14 \left( 1+c_X-c_Y+c_Z \right),

where cP=Tr⁡[ρ(P⊗P)]c_P=\operatorname{Tr}[\rho(P\otimes P)]. If simultaneous one-sided confidence bounds give

cX≥ℓX,cY≤uY,cZ≥ℓZ,c_X\geq \ell_X, \qquad c_Y\leq u_Y, \qquad c_Z\geq \ell_Z,

then a conservative fidelity bound is

FΦ+≥FL=14(1+ℓX−uY+ℓZ).F_{\Phi^+} \geq F_L = \frac14 \left( 1+\ell_X-u_Y+\ell_Z \right).

Every separable two-qubit state has overlap at most 1/21/2 with a maximally entangled state. Thus FL>1/2F_L>1/2 certifies entanglement under the calibrated qubit-and-measurement model. A service requirement F≥0.90F\geq0.90 is stricter: an entanglement certificate can pass while the service-quality certificate fails.

Suppose the intervals are

cX≥0.88,cY≤−0.84,cZ≥0.86.c_X\geq0.88, \qquad c_Y\leq-0.84, \qquad c_Z\geq0.86.

Then

FL=1+0.88+0.84+0.864=0.895.F_L = \frac{1+0.88+0.84+0.86}{4} =0.895.

This certifies entanglement but does not certify a 0.900.90 minimum. Rounding the point estimate upward would reverse a scientifically meaningful decision.

The target also depends on a frame convention. If a herald identifies ∣Ψ−⟩|\Psi^-\rangle and software records a Pauli-frame update to ∣Φ+⟩|\Phi^+\rangle, the correlators must be interpreted using that exact record. Mixing uncorrected Bell labels can make individually good pairs look maximally mixed.

Full tomography estimates many parameters that a pass/fail decision does not need. Quantum-state verification instead chooses local tests that accept an ideal target ∣ψ⟩|\psi\rangle with certainty. Let setting ss be selected with probability μs\mu_s and let PsP_s be its pass operator. The verification operator is

Ω=∑sμsPs,Ω∣ψ⟩=∣ψ⟩.\Omega = \sum_s \mu_s P_s, \qquad \Omega|\psi\rangle=|\psi\rangle.

Write its two largest eigenvalues as

λ1(Ω)=1,λ2(Ω)=βΩ,\lambda_1(\Omega)=1, \qquad \lambda_2(\Omega)=\beta_\Omega,

and define the spectral gap

ν=1−βΩ.\nu=1-\beta_\Omega.

For any state satisfying

⟨ψ∣ρ∣ψ⟩≤1−ε,\langle\psi|\rho|\psi\rangle \leq1-\varepsilon,

the one-trial pass probability obeys

Tr⁡(Ωρ)≤1−νε.\operatorname{Tr}(\Omega\rho) \leq1-\nu\varepsilon.

Under the corresponding independent-product promise, the probability that NN bad systems all pass is at most

(1−νε)N≤e−Nνε.\left(1-\nu\varepsilon\right)^N \leq e^{-N\nu\varepsilon}.

It is therefore sufficient to choose

N≥ln⁡(1/δ)νεN \geq \frac{\ln(1/\delta)}{\nu\varepsilon}

to limit false acceptance to δ\delta. Larger gap means better sample efficiency. Locality, available bases, dishonest parties, and noisy honest devices constrain which PsP_s are implementable and change the gap.

The all-pass protocol is not appropriate when even an acceptable source has a nonzero fail probability. Then the protocol needs a threshold on the number of passes, an explicit good-state noise model, and finite-sample bounds for both errors. Correlated or adversarial batches require a theorem for that setting; blindly raising an IID binomial probability to the NNth power is not such a theorem.

Let a graph G=(V,E)G=(V,E) define the graph-state stabilizer generators

Kv=Xv∏u∈N(v)Zu,v∈V.K_v = X_v \prod_{u\in N(v)}Z_u, \qquad v\in V.

For the ideal graph state, Kv∣G⟩=∣G⟩K_v|G\rangle=|G\rangle. Define

Pv=I+Kv2.P_v=\frac{I+K_v}{2}.

Because the generators commute and uniquely specify the graph state,

∣G⟩⟨G∣=∏v∈VPv.|G\rangle\langle G| = \prod_{v\in V}P_v.

The operator inequality

I−∏vPv⪯∑v(I−Pv)I-\prod_vP_v \preceq \sum_v(I-P_v)

gives the directly useful lower bound

FG≥1−12∑v∈V(1−⟨Kv⟩).F_G \geq 1- \frac12 \sum_{v\in V} \left(1-\langle K_v\rangle\right).

This bound turns local Pauli correlators into a target-state guarantee. Graph coloring can group compatible stabilizer tests into fewer global settings. Specialized verification operators can have better sample complexity than this simple union bound.

A network adds a strategic problem absent from a trusted laboratory: some parties may lie about settings or outcomes, collude with the source, or exploit loss. Protocols for untrusted networks specify at least one honest verifier, private random challenges, authenticated classical communication, which parties may collude, and how untested copies are selected. Passing a trusted stabilizer test and passing an adversarial multipartite protocol are different claims even when both target the same ∣G⟩|G\rangle.

Ordinary Bell locality uses one shared hidden variable. An entanglement- swapping network has two nominally independent sources. In a three-node chain, a bilocal model factors as

p(a,b,c∣x,y,z)=∫dλ1 dλ2  q1(λ1)q2(λ2)×p(a∣x,λ1)p(b∣y,λ1,λ2)p(c∣z,λ2).\begin{aligned} p(a,b,c|x,y,z) ={}& \int d\lambda_1\,d\lambda_2\; q_1(\lambda_1)q_2(\lambda_2)\\ &\times p(a|x,\lambda_1) p(b|y,\lambda_1,\lambda_2) p(c|z,\lambda_2). \end{aligned}

The product q1q2q_1q_2 is the source-independence assumption. A general Bell-local model may replace it with a correlated q(λ1,λ2)q(\lambda_1,\lambda_2), so the bilocal set is smaller and generally nonconvex.

In one standard binary-setting formulation, the middle node returns two bits b0,b1b_0,b_1. Let Bj=(−1)bjB^j=(-1)^{b_j} and define

I=14∑x,z⟨AxB0Cz⟩,I = \frac14 \sum_{x,z} \langle A_xB^0C_z\rangle, J=14∑x,z(−1)x+z⟨AxB1Cz⟩.J = \frac14 \sum_{x,z} (-1)^{x+z} \langle A_xB^1C_z\rangle.

Bilocal correlations satisfy

∣I∣+∣J∣≤1.\sqrt{|I|}+\sqrt{|J|}\leq1.

A statistically valid violation rejects this bilocal null under the declared trial, independence, measurement-choice, communication, and loss assumptions. It does not by itself certify a particular Bell-state fidelity, identify which component is faulty, or prove that the sources are physically independent. Independence is an input to the null model, not an output conjured by the inequality.

Network nonlocality can reveal correlations that admit an ordinary Bell-local model but not a source-independent network-local model. That is a real and useful distinction, not a stronger synonym for every kind of nonclassicality.

Self-testing infers that every compatible realization contains a target state and measurements, up to local isometries and irrelevant auxiliary systems. A robust statement has the schematic form

observed score≥Smax⁡−η⟹D ⁣(Φ(ρ),∣ψ⟩⟨ψ∣⊗ρjunk)≤f(η),\text{observed score}\geq S_{\max}-\eta \quad\Longrightarrow\quad D\!\left( \Phi(\rho), |\psi\rangle\langle\psi|\otimes\rho_{\rm junk} \right) \leq f(\eta),

where DD is a chosen distance, Φ\Phi is a product of local extraction maps, and f(η)→0f(\eta)\to0 as η→0\eta\to0. The exact robustness function is protocol-specific. A statement of ideal self-testing without the finite-noise bound needed by the experiment is incomplete.

Network constraints can enable certifications unavailable in the same ordinary Bell scenario. They can also test candidate causal structures. Given observed p(a∣x)p(\mathbf a|\mathbf x), one may ask whether any states and measurements arranged on a proposed source graph can reproduce the data. Inflation and related relaxations generate necessary constraints on that model. Violating one excludes the candidate structure within the assumptions.

This conclusion is usually an equivalence-class statement, not a photograph of cables. Two physical networks can produce the same observable statistics, and finite tests rarely identify one unique internal realization. The certificate must state which candidate models were excluded and which alternatives remain.

A network often promises a channel rather than a fixed state. For a trace-preserving map E\mathcal E on dimension dd, define the normalized Choi state

JE=(id⁡⊗E)(∣Φd⟩⟨Φd∣),J_{\mathcal E} = (\operatorname{id}\otimes\mathcal E) \left( |\Phi_d\rangle\langle\Phi_d| \right),

with

∣Φd⟩=1d∑j=0d−1∣j⟩∣j⟩.|\Phi_d\rangle = \frac1{\sqrt d} \sum_{j=0}^{d-1}|j\rangle|j\rangle.

Its entanglement fidelity relative to the identity is

Fe=⟨Φd∣JE∣Φd⟩.F_e = \langle\Phi_d|J_{\mathcal E}|\Phi_d\rangle.

For a trace-preserving channel, the Haar-average pure-state fidelity satisfies

Favg=dFe+1d+1.F_{\rm avg} = \frac{dF_e+1}{d+1}.

This relation does not license silent conditioning on loss. A heralded branch is a completely positive trace-nonincreasing map Eh\mathcal E_h. Its Choi operator is subnormalized:

Jh=(id⁡⊗Eh)(∣Φd⟩⟨Φd∣),J_h = (\operatorname{id}\otimes\mathcal E_h) \left( |\Phi_d\rangle\langle\Phi_d| \right), phmm=Tr⁡Jh,Fe∣h=⟨Φd∣Jh∣Φd⟩Tr⁡Jh.p_h^{\rm mm}=\operatorname{Tr}J_h, \qquad F_{e|h} = \frac{\langle\Phi_d|J_h|\Phi_d\rangle} {\operatorname{Tr}J_h}.

The superscript reminds us that phmmp_h^{\rm mm} is the success probability for the maximally mixed input represented by the Choi experiment. If success depends strongly on the input, one number does not certify uniform transmission. A complete link certificate reports success behavior and conditional quality together, and includes failed trials in the sampling frame.

Herald timing matters. For an event-ready Bell test, the event definition and herald must be fixed before the endpoint settings are chosen. Otherwise the herald can become outcome- or setting-dependent postselection.

An application consumes identified resources in time. A service claim can be written as the conjunction

Csvc={Fcond≥F∗,Rdel≥R∗,Pr⁡(L≤L∗)≥q∗,A≥A∗,pwrong id≤ϵid}.\mathcal C_{\rm svc} = \left\{ \begin{array}{l} F_{\rm cond}\geq F_*,\\ R_{\rm del}\geq R_*,\\ \Pr(L\leq L_*)\geq q_*,\\ A\geq A_*,\\ p_{\rm wrong\ id}\leq\epsilon_{\rm id} \end{array} \right\}.

Here RdelR_{\rm del} counts accepted resources per wall-clock time, LL is request-to-delivery latency, AA is availability over a declared observation schedule, and pwrong idp_{\rm wrong\ id} includes endpoint, memory-slot, route, or Pauli-frame mismatch. A high conditional fidelity with a vanishing delivery rate does not satisfy this contract.

If component tests have false-certification probabilities αj\alpha_j, a simple simultaneous guarantee follows from the union bound:

Pr⁡(any false component certificate)≤∑jαj.\Pr(\text{any false component certificate}) \leq \sum_j\alpha_j.

This bound can be conservative, but it forces the error budget to be visible. Reporting five separate “99% confidence” intervals does not automatically give a 99% joint certificate.

Request classes must not be pooled indiscriminately. Fidelity, rate, and latency can depend on endpoints, route, requested threshold, priority, memory age, time of day, and competing traffic. A weighted average can pass while a contractually important class fails.

End-to-end failure should be detected end to end. Component tests are then useful for localization. Testing only components can miss correlated phase errors, wrong Bell labels, timing mismatches, swap-feed-forward faults, and software identity errors that appear only after composition.

In a simplified additive model, route statistic yry_r depends on link parameters θe\theta_e through

yr=∑eAreθe+ϵr,y_r = \sum_e A_{re}\theta_e+\epsilon_r,

or in vector form

y=Aθ+ϵ.\mathbf y=A\boldsymbol\theta+\boldsymbol\epsilon.

All link parameters are identifiable only if the probe-route matrix has the required rank. If AA has a nontrivial null space, several internal fault patterns produce the same end-to-end data. More trials reduce statistical noise but do not cure structural nonidentifiability.

The additive model itself must be validated. Coherent errors can interfere, memory noise depends on stochastic waiting time, swapping can correlate branches, and purification changes both state quality and selection. Network tomography is therefore model-based diagnosis, not a substitute for direct service verification.

Finite Statistics, Drift, and Repeated Monitoring

Section titled “Finite Statistics, Drift, and Repeated Monitoring”

For independent bounded observations Xi∈[a,b]X_i\in[a,b], Hoeffding’s inequality gives

Pr⁡ ⁣(∣Xˉ−EX∣≥t)≤2exp⁡ ⁣[−2Nt2(b−a)2].\Pr\!\left( |\bar X-\mathbb E X|\geq t \right) \leq 2\exp\!\left[ -\frac{2Nt^2}{(b-a)^2} \right].

It is useful for planning simple correlator tests, but its independence and stationarity assumptions are physical assumptions. Network records often have bursts, shared calibration drift, queue correlations, memory effects, and adaptive route selection. Treating every click as an independent sample can underestimate uncertainty by orders of magnitude.

The acquisition hierarchy should be retained:

campaign⊃day or calibration epoch⊃route batch⊃request⊃attempt.\text{campaign} \supset \text{day or calibration epoch} \supset \text{route batch} \supset \text{request} \supset \text{attempt}.

Randomize test settings within relevant timescales, report between-epoch variation, and use block, hierarchical, martingale, or confidence-sequence methods when their assumptions match the protocol. If a dashboard is checked continuously, a fixed-horizon confidence interval recomputed after every event does not retain its nominal coverage. Time-uniform inference or a declared alpha-spending rule is needed.

Drift is also a property to test. A six-hour average above threshold can hide forty-minute outages. Report time-resolved bounds, change-point policy, data latency, and the recovery rule that returns a route to service.

A faulty network can bias verification without changing the quantum state. It can omit inconvenient trials, relabel endpoints, replay heralds, announce a route different from the one used, delay messages until settings are known, or select calibration corrections after viewing outcomes.

A defensible transcript includes:

  • a unique request and attempt identifier;
  • endpoint and memory-slot identifiers;
  • route and protocol versions;
  • timestamps from declared clock domains;
  • herald and swap outcomes in causal order;
  • setting-generation records and commitment points;
  • every no-click, timeout, abort, retry, and exclusion reason;
  • Pauli-frame, reference-frame, and calibration versions;
  • hashes or signatures that expose deletion and alteration;
  • the preregistered test rule and analysis code version.

Authentication protects record integrity, not record truth. Independent cross-checks at endpoints, challenge traffic, causal timing, and physical tests are still required. Likewise, encrypting the transcript does not make a weak statistical test strong.

When some parties are dishonest, state what honest subset is guaranteed a useful state after acceptance. “At least one verifier is honest” and “all honest parties simultaneously receive a good state” are different security statements.

Logical and Application-Level Verification

Section titled “Logical and Application-Level Verification”

A physical Bell-pair certificate does not automatically certify a logical Bell pair or remote logical gate. The logical object includes encoding, repeated syndrome extraction, decoder state, frame updates, leakage handling, accepted failure modes, and the time at which the application may safely consume it.

Distributed Quantum Computing owns teledata, telegates, partitioning, scheduling, and logical network-resource accounting. Network verification supplies testable acceptance conditions for the remote states or operations used there. A complete logical certificate should distinguish:

pphysical link,plogical operation,papplication failure.p_{\rm physical\ link}, \qquad p_{\rm logical\ operation}, \qquad p_{\rm application\ failure}.

These probabilities need not be equal, and postselection at one layer changes the denominator seen by the next.

Cryptographic, sensing, and computing applications can require properties not captured by fidelity. QKD needs a security proof and authenticated transcript; sensing may need phase-reference stability and simultaneous delivery; distributed computation may need coherence-bound feed-forward latency. Verify the metric that the application theorem actually uses.

  1. Name the service boundary. Identify endpoints, output system, success flag, deadline, and who controls each interface.
  2. Write the bad-service null. Include thresholds, dimensions, source graph, loss behavior, and allowed adversarial memory.
  3. Choose the least-trusting feasible protocol. Do not claim a stronger trust class than the implementation closes.
  4. Define all eligible trials before outcomes. Include no-clicks, timeouts, retries, and aborted transactions.
  5. Randomize test assignment and settings. Record when choices become knowable to sources, relays, and endpoints.
  6. Precompute power and error budgets. Include simultaneous metrics and planned subgroup analyses.
  7. Bind quantum and classical identities. Check route, slot, herald, correction, calibration, and clock records.
  8. Test end to end, then localize. Component certificates supplement but do not replace delivered-service tests.
  9. Stress the assumptions. Look for drift, source correlation, selective loss, setting leakage, and model nonidentifiability.
  10. Issue a scoped certificate. State the covered population, validity window, confidence, exclusions, and revocation triggers.

Reporting Standards owns the general artifact and provenance contract. The network-specific addition is that quantum-resource identity and causal ordering must be joined to the service transcript.

Several layers are established. Trusted endpoint correlations and tomography are standard laboratory tools. Efficient local verification strategies are known for Bell, stabilizer, graph, and related states. Experiments have verified multipartite entanglement with untrusted sources or parties, and small networks have demonstrated service-layer entanglement delivery with state and latency measurements. Bilocal and larger network-locality violations have also been demonstrated under stated source-independence and sampling assumptions.

Other layers remain developing. Robust device-independent bounds can be experimentally demanding. Topology certification and network-assisted self-testing are active research areas. Continuous certification of a multiuser, rerouting, memory-bearing network under correlated faults and adversarial nodes is not yet a standardized solved problem. A simulation of such a monitor is evidence about a model; a small fixed-topology experiment is evidence about that implementation; neither alone establishes internet-scale operation.

Use Network Case Studies for detailed experimental ledgers and Claims, Hype, and Evidence Standards for classifying the resulting public claim.

  • Treating a herald as a certificate. A herald defines a candidate event; it does not establish the endpoint state.
  • Reporting conditional fidelity alone. The herald probability, delivered rate, and all exclusions belong beside it.
  • Using tested pairs as if they remain available. Destructive measurements require a sampling argument for retained systems.
  • Calling a witness value tomography. A targeted test supports a targeted claim, not a complete reconstructed state.
  • Calling tomography device-independent. Reconstruction inherits its state, measurement, dimension, and stationarity models.
  • Ignoring source independence. Network-locality inequalities have a causal model different from ordinary Bell inequalities.
  • Combining marginal confidence levels as a joint level. Allocate an error budget across all required service metrics.
  • Dropping no-clicks or timeouts after seeing them. Outcome-dependent filtering can open a detection or selection loophole.
  • Pooling routes and epochs. A passing average can conceal a failing route or outage window.
  • Inferring components from unidentifiable path data. More samples cannot remove a null space in the probe design.
  • Equating entanglement with usefulness. Target fidelity, latency, reference frames, logical error, and application security can impose stricter conditions.
  • Letting the certificate outlive the system state. Firmware, calibration, topology, and maintenance changes need explicit invalidation rules.
  1. N. Friis, G. Vitagliano, M. Malik, and M. Huber, “Entanglement certification from theory to experiment,” Nature Reviews Physics 1, 72–87 (2019), doi:10.1038/s42254-018-0003-5.
  2. S. Pallister, N. Linden, and A. Montanaro, “Optimal verification of entangled states with local measurements,” Physical Review Letters 120, 170502 (2018), doi:10.1103/PhysRevLett.120.170502.
  3. R. Blume-Kohout, J. O. S. Yin, and S. J. van Enk, “Entanglement verification with finite data,” Physical Review Letters 105, 170501 (2010), doi:10.1103/PhysRevLett.105.170501.
  4. B. Dirkse, M. Pompili, R. Hanson, M. Walter, and S. Wehner, “Witnessing entanglement in experiments with correlated noise,” Quantum Science and Technology 5, 035007 (2020), doi:10.1088/2058-9565/ab8d88.
  5. H. Zhu and M. Hayashi, “Optimal verification of stabilizer states,” Physical Review Research 2, 043323 (2020), doi:10.1103/PhysRevResearch.2.043323.
  6. H. Zhu and M. Hayashi, “Efficient verification of hypergraph states,” Physical Review Applied 12, 054047 (2019), doi:10.1103/PhysRevApplied.12.054047.
  7. A. Unnikrishnan and D. Markham, “Verification of graph states in an untrusted network,” Physical Review A 105, 052420 (2022), doi:10.1103/PhysRevA.105.052420.
  8. W. McCutcheon et al., “Experimental verification of multipartite entanglement in quantum networks,” Nature Communications 7, 13251 (2016), doi:10.1038/ncomms13251.
  9. Y.-G. Han et al., “Optimal verification of the Bell state and Greenberger–Horne–Zeilinger states in untrusted quantum networks,” npj Quantum Information 7, 164 (2021), doi:10.1038/s41534-021-00499-8.
  10. J. S. Bell, “On the Einstein Podolsky Rosen paradox,” Physics Physique Fizika 1, 195–200 (1964), doi:10.1103/PhysicsPhysiqueFizika.1.195.
  11. J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt, “Proposed experiment to test local hidden-variable theories,” Physical Review Letters 23, 880–884 (1969), doi:10.1103/PhysRevLett.23.880.
  12. B. Hensen et al., “Loophole-free Bell inequality violation using electron spins separated by 1.3 kilometres,” Nature 526, 682–686 (2015), doi:10.1038/nature15759.
  13. C. Branciard, N. Gisin, and S. Pironio, “Characterizing the nonlocal correlations created via entanglement swapping,” Physical Review Letters 104, 170401 (2010), doi:10.1103/PhysRevLett.104.170401.
  14. C. Branciard, D. Rosset, N. Gisin, and S. Pironio, “Bilocal versus nonbilocal correlations in entanglement-swapping experiments,” Physical Review A 85, 032119 (2012), doi:10.1103/PhysRevA.85.032119.
  15. A. Tavakoli, A. Pozas-Kerstjens, M.-X. Luo, and M.-O. Renou, “Bell nonlocality in networks,” Reports on Progress in Physics 85, 056001 (2022), doi:10.1088/1361-6633/ac41bb.
  16. G. Carvacho et al., “Experimental violation of local causality in a quantum network,” Nature Communications 8, 14775 (2017), doi:10.1038/ncomms14775.
  17. D. J. Saunders, A. J. Bennet, C. Branciard, and G. J. Pryde, “Experimental demonstration of nonbilocal quantum correlations,” Science Advances 3, e1602743 (2017), doi:10.1126/sciadv.1602743.
  18. I. Šupić and J. Bowles, “Self-testing of quantum systems: a review,” Quantum 4, 337 (2020), doi:10.22331/q-2020-09-30-337.
  19. I. Šupić, J.-D. Bancal, Y. Cai, and N. Brunner, “Genuine network quantum nonlocality and self-testing,” Physical Review A 105, 022206 (2022), doi:10.1103/PhysRevA.105.022206.
  20. I. Šupić et al., “Quantum networks self-test all entangled states,” Nature Physics 19, 670–675 (2023), doi:10.1038/s41567-023-01945-4.
  21. M.-O. Renou et al., “Genuine quantum nonlocality in the triangle network,” Physical Review Letters 123, 140401 (2019), doi:10.1103/PhysRevLett.123.140401.
  22. Y.-L. Mao et al., “Certifying network topologies and nonlocalities of triangle quantum networks,” Physical Review Letters 132, 240801 (2024), doi:10.1103/PhysRevLett.132.240801.
  23. A. Ulibarrena et al., “Guarantees on the structure of experimental quantum networks,” npj Quantum Information 10, 117 (2024), doi:10.1038/s41534-024-00911-z.
  24. S. Neves et al., “Experimentally certified transmission of a quantum message through an untrusted and lossy quantum channel via Bell’s theorem,” PRX Quantum 6, 030312 (2025), doi:10.1103/PRXQuantum.6.030312.
  25. M. Pompili et al., “Experimental demonstration of entanglement delivery using a quantum network stack,” npj Quantum Information 8, 121 (2022), doi:10.1038/s41534-022-00631-2.
  26. M. A. Nielsen, “A simple formula for the average gate fidelity of a quantum dynamical operation,” Physics Letters A 303, 249–252 (2002), doi:10.1016/S0375-9601(02)01272-0.
  27. W. Hoeffding, “Probability inequalities for sums of bounded random variables,” Journal of the American Statistical Association 58, 13–30 (1963), doi:10.1080/01621459.1963.10500830.
  28. R. J. Serfling, “Probability inequalities for the sum in sampling without replacement,” The Annals of Statistics 2, 39–48 (1974), doi:10.1214/aos/1176342611.
  29. S. R. Howard, A. Ramdas, J. McAuliffe, and J. Sekhon, “Time-uniform, nonparametric, nonasymptotic confidence sequences,” The Annals of Statistics 49, 1055–1080 (2021), doi:10.1214/20-AOS1991.
  30. M. Guedes de Andrade et al., “Quantum network tomography with multiparty state distribution,” arXiv:2206.02920 (2022), doi:10.48550/arXiv.2206.02920.

Simultaneous confidence intervals give

cX∈[0.84,0.90],cY∈[−0.88,−0.82],cZ∈[0.86,0.92].c_X\in[0.84,0.90], \qquad c_Y\in[-0.88,-0.82], \qquad c_Z\in[0.86,0.92].

Find a lower bound on FΦ+F_{\Phi^+}. Does it certify entanglement? Does it certify a service threshold Fmin⁡=0.90F_{\min}=0.90?

Solution

Use the lower bounds for the positive terms and the upper bound for cYc_Y, because it enters with a minus sign:

FL=1+0.84−(−0.82)+0.864=0.88.F_L = \frac{1+0.84-(-0.82)+0.86}{4} =0.88.

Since 0.88>1/20.88>1/2, the result certifies entanglement under the trusted two-qubit measurement model. It does not certify F≥0.90F\geq0.90.

A verification operator has gap ν=2/3\nu=2/3. How many all-pass trials are sufficient, using the exponential bound, to reject states with infidelity at least ε=0.02\varepsilon=0.02 at false-acceptance probability δ=0.01\delta=0.01?

Solution

The sufficient bound is

N≥ln⁡(1/δ)νε=ln⁡100(2/3)(0.02)≈345.39.N \geq \frac{\ln(1/\delta)}{\nu\varepsilon} = \frac{\ln100}{(2/3)(0.02)} \approx345.39.

Thus N=346N=346 trials suffice. This calculation assumes the all-pass protocol and the product or conditional bad-state promise used in its proof.

A link makes 6,0006{,}000 attempts in one hour, heralds 120120 pairs, and estimates conditional Bell-state fidelity 0.940.94. State the delivery probability and explain why the fidelity alone does not certify an application requiring at least one pair per ten seconds.

Solution

The empirical herald probability is

p^h=1206000=0.02.\widehat p_h = \frac{120}{6000} =0.02.

The delivered rate is 120/3600=1/30 s−1120/3600=1/30\ \mathrm{s}^{-1}, before any additional application rejection. The average rate is therefore below one pair per ten seconds. The conditional fidelity concerns states given a herald; it does not guarantee rate, latency quantiles, or availability.

Show how a bilocal model becomes an ordinary Bell-local model if the two hidden variables are allowed a joint distribution q(λ1,λ2)q(\lambda_1,\lambda_2). Why can a bilocality violation coexist with an ordinary Bell-local explanation?

Solution

Replace q1(λ1)q2(λ2)q_1(\lambda_1)q_2(\lambda_2) by an arbitrary joint distribution and define one shared hidden variable λ=(λ1,λ2)\lambda=(\lambda_1,\lambda_2). Then

p(a,b,c∣x,y,z)=∫dλ q(λ)p(a∣x,λ)p(b∣y,λ)p(c∣z,λ),p(a,b,c|x,y,z) = \int d\lambda\,q(\lambda) p(a|x,\lambda) p(b|y,\lambda) p(c|z,\lambda),

after allowing each response to ignore whichever component it does not need. The ordinary local set therefore permits source correlations forbidden by the bilocal model. Data can lie outside the smaller bilocal set while remaining inside the ordinary Bell-local set.

Four stabilizer generators have measured expectations

0.96,0.94,0.97,0.95.0.96, \qquad 0.94, \qquad 0.97, \qquad 0.95.

Use the generator union bound to lower-bound the graph-state fidelity.

Solution

The total generator failure bound is

12(0.04+0.06+0.03+0.05)=0.09.\frac12 \left( 0.04+0.06+0.03+0.05 \right) =0.09.

Therefore

FG≥1−0.09=0.91.F_G\geq1-0.09=0.91.

This is a conservative target-state bound under the trusted stabilizer measurement model, not a device-independent statement.

Three unknown link-error parameters are θ1,θ2,θ3\theta_1,\theta_2,\theta_3. Two route probes give

y1=θ1+θ2,y2=θ2+θ3.y_1=\theta_1+\theta_2, \qquad y_2=\theta_2+\theta_3.

Are all links identifiable? What additional route makes the linear system identifiable?

Solution

The first probe matrix is

A=(110011),A = \begin{pmatrix} 1&1&0\\ 0&1&1 \end{pmatrix},

which has rank 2<32<3. The vector (1,−1,1)T(1,-1,1)^{\mathsf T} lies in its null space, so the three errors are not identifiable. Adding

y3=θ1+θ3y_3=\theta_1+\theta_3

gives

A′=(110011101),A' = \begin{pmatrix} 1&1&0\\ 0&1&1\\ 1&0&1 \end{pmatrix},

whose determinant is 22, so the linearized parameters are identifiable.

A service certificate requires fidelity, delivered rate, latency, and identity tests to pass. Give a simple allocation that guarantees total false certification probability at most 0.010.01.

Solution

Assign each of the four component tests

αj=0.0025.\alpha_j=0.0025.

Then the union bound gives

Pr⁡(any false component certificate)≤4(0.0025)=0.01.\Pr(\text{any false component certificate}) \leq 4(0.0025) =0.01.

Other allocations are valid and may give more power by assigning more error budget to the hardest metric, but they should be fixed before inspecting the data.

A three-node network alternates between two routes and recalibrates every hour. Sketch a verification design that can certify a daily fidelity threshold without hiding a forty-minute failure.

Solution

A defensible design would stratify by route and calibration epoch, randomly interleave destructive test requests with application requests inside each stratum, and retain attempt-level timestamps, heralds, no-clicks, frame data, and exclusions. It would set both a daily aggregate threshold and a shorter window or change-point rule, with a simultaneous error budget. A route is removed from service when its time-uniform lower bound crosses the failure threshold and is reinstated only after a preregistered recovery test. This design can identify a forty-minute failure instead of averaging it into the rest of the day.