Fault-tolerant quantum memories do not hide logical input from error logs
Execution-transcript privacy for fault-tolerant surface-code memories
Cryptography and Security
Summary
Quantum computers running error-correcting codes produce detailed logs about errors and corrections during computation. The authors show that even with fault tolerance, the recorded data (transcripts) can leak information about the logical input stored in the quantum memory. They prove this leakage decreases exponentially with the code distance under certain technical conditions, but not always. Their experiments on a real quantum device confirm that some error processes reveal significant input information to these transcripts. The work clarifies when fault tolerance can and cannot keep logical data private from these error records.
What this means in practice
- •For quantum hardware engineers: Assess and improve the privacy of logical qubits stored on surface-code memory devices by analyzing error logs for information leakage.
- •For quantum software developers: Develop error-correction protocols that consider which recorded syndromes could reveal logical input, enhancing secure operation of quantum memories.
Authors
Jiachen Shen, Hui Zhong
Abstract
A fault-tolerant quantum computer runs behind a telemetry stream logging syndromes, decoder actions, resets and timing separately from the answer. Can it reveal the logical input? For a distance-$d$ rotated surface-code memory on a fixed schedule of $T=Θ(d)$ rounds, under three stated hypotheses (sector-scalar honest backbone, transcript locality, Kotecky-Preiss smallness), the channel from logical qubit to transcript is $e^{-Θ(d)}$-close in diamond norm to one that ignores the input. A statement of this kind follows generically from correctability-privacy duality. Anisotropy does not. Each logical axis pays the distance of its own coset, so under amplitude damping the computational-basis label is governed by the code's $Z$-distance $d_Z\ge d_{\min}$ and not by the code distance. Two codes of quantum distance $1$ make the gap concrete. A phase-flip code's $X$-syndrome transcript is exactly input-independent under unobserved damping, while a repetition code leaks at first order. A matched converse identifies the records that do expose it, among them a lattice-surgery parity readout. On a 156-qubit superconducting processor our sufficient certificate misses by $21.5\times$, so the theorem cannot be invoked there. Measured directly, a $d_Z=1$ memory's record identifies its input with total variation $\ge 0.927$ under randomised, label-balanced acquisition. Holding the code fixed and varying the damping exposure reproduces the parameter-free law, with exponent $0.85\pm0.03$ against a predicted $0.86$. Randomized encoding returns the statistic to the floor at no two-qubit-gate cost. Fault tolerance does not grant transcript privacy. It relocates it, and only to the logical state, not to the circuit's identity.