Classical verifier checks quantum computations using quasilinear resources under LWE
This paper shows how a fully classical user can check a quantum computation while costing the quantum machine almost only a little more than the size of the quantum circuit. The scheme runs in quasilinear total resources: about O(poly(λ, log g) · g) work to delegate a circuit with g gates, where λ is the security parameter of the cryptographic assumption used. The protocol relies on standard cryptography rather than information‑theoretic guarantees.
The authors build a new kind of computational self-test. A self-test is a way for a classical verifier to force a remote quantum device to prepare certain quantum states and measurements. Here the test certifies that the prover holds many single‑qubit states drawn from a small set of Clifford‑type states and does so with constant robustness: the verifier’s error does not grow with the number of qubits prepared. The test is then used to implement verifiable, random remote state preparation (RSP), meaning the prover can be made to hold the desired states even though all messages are classical.
To turn this testing idea into a single‑prover protocol the paper uses a recent compiler that converts nonlocal games (interactions with multiple separated provers) into single‑prover argument systems. That compiler enforces a no‑communication assumption by cryptographic means, relying on quantum fully homomorphic encryption (QFHE) over classical ciphertexts. Combining the new self-test with this compiled nonlocal‑game approach lets the authors “dequantize” an existing low‑overhead verification protocol of Broadbent (2018). The result is a classical‑verifier argument system for BQP (efficient quantum computation) with quasilinear total resources under the stated assumptions.
Why this matters: earlier single‑prover classical verification protocols required polynomial or worse overheads because they used a circuit‑to‑Hamiltonian reduction. Those approaches force the quantum prover to do many more operations than the original circuit. The present work cuts that overhead down to near linear in the circuit size, making classical verification of remote quantum computations much more practical in principle. The construction is modular and follows ideas from recent nonlocal‑games literature, so it can be instantiated from different cryptographic assumptions in future work.