arXiv:cs.LG· Owen Friedewald, Ali Shiri Sichani, Chi-Ren Shyu·· 3 小时前AI 评分29
量子傅里叶采样为何止步:面向延迟 PUF 安全模型的三门审计协议
Where Quantum Fourier Sampling Stops Short: A Three-Gate Audit Protocol for Delay-PUF Security Models
AI 导读
研究提出 Three-Gate Quantum Audit Protocol,用于区分延迟 PUF 的量子理想查询优势与可实现安全收益。
正文
Abstract:Quantum Fourier sampling may help audit the spectral learnability of delay-based physical unclonable functions (PUFs). We ask whether that promise survives access matching, a strong classical comparator, and oracle synthesis. Three gates structure the evaluation. Structure: low degree is not small support at reachable challenge lengths; for 4-XOR at $n=14$, degree $\le d_f(0.1)$ admits $91\%$ of all $2^n$ characters and the median $90\%$-mass set spans a third of the spectrum. Algorithmics: constructing the phase oracle logically implies classical membership access, making Kushilevitz--Mansour the correct baseline; across 45 tasks it exhausts each finite domain, and no 4-XOR ideal-sampling case reaches $90\%$ mass within $2^n$ calls. A quantum-kernel diagnostic appears more favorable, with geometric difference rising to $2.151$ at $N=512$ challenges, but it correlates $0.991$ with $1/\sqrt{\lambda_{\min}(K_C)}$ for the classical Gram matrix $K_C$, and the 4-XOR label-complexity ratio does not exceed a balance-preserving permutation null ($p=0.930$). Trace-normalized geometric difference can therefore grow through classical ill-conditioning alone, without task-label alignment. Implementation: a simulator-validated fixed-point phase oracle based on the quantum Fourier transform admits an $18.9\%$ routed-depth reduction, yet the least certified precisions have estimated durations of $1.18$--$1.55\times$ the median dephasing time $T_2$ of the mapped qubits on a static backend snapshot, without hardware execution. We find no end-to-end advantage in the evaluated regime, although ideal sampling does use fewer coherent calls on the thresholded task. The contribution is the Three-Gate Quantum Audit Protocol: a reproducible procedure separating an ideal query advantage from a realizable security benefit. This is not a claim about deployed silicon and not an impossibility result.
| Comments: | Accepted for presentation as a long oral at the NeurIPS 2026 SaTQuML Workshop, December 12-13, 2026, Atlanta, GA. arXiv version includes minor formatting revisions to meet submission requirements |
| Subjects: | Quantum Physics (quant-ph); Cryptography and Security (cs.CR); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.02636 [quant-ph] |
| (or arXiv:2610.02636v1 [quant-ph] for this version) | |
| https://doi.org/10.48550/arXiv.2610.02636 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Owen Friedewald [view email]
[v1]
Fri, 2 Oct 2026 00:53:09 UTC (182 KB)
来源:arXiv:cs.LG · arxiv.org