From bdbbdcca7cabec87f5aa9478122ccb5bc1d83cca Mon Sep 17 00:00:00 2001 From: Abe Wieland Date: Mon, 22 Nov 2021 17:16:36 -0500 Subject: [PATCH 1/2] Quantum part 1 typos --- lec_19_quantum.md | 46 +++++++++++++++++++++++----------------------- 1 file changed, 23 insertions(+), 23 deletions(-) diff --git a/lec_19_quantum.md b/lec_19_quantum.md index 2eb67f8..73d1f8e 100644 --- a/lec_19_quantum.md +++ b/lec_19_quantum.md @@ -40,8 +40,8 @@ If we now carve out an additional slit in the metal barrier then more balls woul So far this is pure common sense, and it is indeed (to my knowledge) an accurate description of what happens when we shoot baseballs at a plastic wall. However, this is not the same when we shoot _photons_. -Amazingly, if we shoot with a "photon gun" (i.e., a laser) at a wall equipped with photon detectors through some barrier, then (as shown in [doubleslitfig](){.ref}) in some positions of the wall we will see _fewer_ hits when the two slits are open than one only ones of them is!.^[A nice illustrated description of the double slit experiment appears in [this video](https://www.youtube.com/watch?v=DfPeprQ7oGc).] -In particular there are positions in the wall that are hit when the first slit is open, hit when the second gun is open, but are _not hit at all when both slits are open!_. +Amazingly, if we shoot with a "photon gun" (i.e., a laser) at a wall equipped with photon detectors through some barrier, then (as shown in [doubleslitfig](){.ref}) in some positions of the wall we will see _fewer_ hits when the two slits are open than one only ones of them is!^[A nice illustrated description of the double slit experiment appears in [this video](https://www.youtube.com/watch?v=DfPeprQ7oGc).] +In particular there are positions in the wall that are hit when the first slit is open, hit when the second slit is open, but are _not hit at all when both slits are open!_ @@ -90,7 +90,7 @@ Specifically, consider an event that can either occur or not (e.g. "detector num In classical probability, we model this by a probability distribution over the two outcomes: a pair of non-negative numbers $p$ and $q$ such that $p+q=1$, where $p$ corresponds to the probability that the event occurs and $q$ corresponds to the probability that the event does not occur. In quantum mechanics, we model this also by pair of numbers, which we call _amplitudes_. This is a pair of (potentially negative or even complex) numbers $\alpha$ and $\beta$ such that $|\alpha|^2 + |\beta|^2 =1$. The probability that the event occurs is $|\alpha|^2$ and the probability that it does not occur is $|\beta|^2$. -In isolation, these negative or complex numbers don't matter much, since we anyway square them to obtain probabilities. +In isolation, these negative or complex numbers don't matter much, since we square them anyway to obtain probabilities. But the interaction of positive and negative amplitudes can result in surprising _cancellations_ where somehow combining two scenarios where an event happens with positive probability results in a scenario where it never does. ::: { .pause } @@ -116,7 +116,7 @@ Thus at this point many scientists prefer to just ignore the question of what is Some of the counterintuitive properties that arise from amplitudes or "negative probabilities" include: * **Interference** - As we see here, probabilities can "cancel each other out". -* **Measurement** - The idea that probabilities are negative as long as "no one is looking" and "collapse" to positive probabilities when they are _measured_ is deeply disturbing. Indeed, people have shown that it can yield to various strange outcomes such as "spooky actions at a distance", where we can measure an object at one place and instantaneously (faster than the speed of light) cause a difference in the results of a measurements in a place far removed. Unfortunately (or fortunately?) these strange outcomes have been confirmed experimentally. +* **Measurement** - The idea that probabilities are negative as long as "no one is looking" and "collapse" to positive probabilities when they are _measured_ is deeply disturbing. Indeed, people have shown that it can yield to various strange outcomes such as "spooky actions at a distance," where we can measure an object at one place and instantaneously (faster than the speed of light) cause a difference in the results of a measurements in a place far removed. Unfortunately (or fortunately?) these strange outcomes have been confirmed experimentally. * **Entanglement** - The notion that two parts of the system could be connected in this weird way where measuring one will affect the other is known as _quantum entanglement_. Again, as counter-intuitive as these concepts are, they have been experimentally confirmed, so we just have to live with them. @@ -142,9 +142,9 @@ This is a huge headache for scientists that actually need to do these calculatio In the 1981, physicist Richard Feynman proposed to "turn this lemon to lemonade" by making the following almost tautological observation: ->_If a physical system cannot be simulated by a computer in $T$ steps, the system can be considered as performing a computation that would take more than $T$ steps_ +>_If a physical system cannot be simulated by a computer in $T$ steps, the system can be considered as performing a computation that would take more than $T$ steps._ -So, he asked whether one could design a quantum system such that its outcome $y$ based on the initial condition $x$ would be some function $y=f(x)$ such that **(a)** we don't know how to efficiently compute in any other way, and **(b)** is actually useful for something.[^Feynman] +So, he asked whether one could design a quantum system such that its outcome $y$ based on the initial condition $x$ would be some function $y=f(x)$ that **(a)** we don't know how to efficiently compute in any other way, and **(b)** is actually useful for something.[^Feynman] In 1985, David Deutsch formally suggested the notion of a quantum Turing machine, and the model has been since refined in works of Detusch and Josza and Bernstein and Vazirani. Such a system is now known as a _quantum computer_. @@ -153,7 +153,7 @@ Such a system is now known as a _quantum computer_. For a while these hypothetical quantum computers seemed useful for one of two things. First, to provide a general-purpose mechanism to simulate a variety of the real quantum systems that people care about. -Second, as a challenge to the theory of computation's approach to model efficient computation by Turing machines, though a challenge that has little bearing to practice, given that this theoretical "extra power" of quantum computer seemed to offer little advantage in the problems people actually want to solve such as combinatorial optimization, machine learning, data structures, etc.. +Second, as a challenge to the theory of computation's approach to model efficient computation by Turing machines, though a challenge that has little bearing to practice, given that this theoretical "extra power" of quantum computer seemed to offer little advantage in the problems people actually want to solve such as combinatorial optimization, machine learning, data structures, etc. To a significant extent, this is still true today. We have no real evidence that quantum computers, when built, will offer truly significant[^Grover] advantage in 99 percent of the applications of computing.[^overhead] However, there is one cryptography-sized exception: @@ -167,7 +167,7 @@ However, some quantum computers have been built that achieved tasks that are eit When and if such a computer is built that can break reasonable parameters of Diffie Hellman, RSA and elliptic curve cryptography is anybody's guess. It could also be a "self destroying prophecy" whereby the existence of a small-scale quantum computer would cause everyone to shift away to lattice-based crypto which in turn will diminish the motivation to invest the huge resources needed to build a large scale quantum computer.[^legacy] -[^legacy]: Of course, given that "export grade" cryptography that was supposed to disappear with 1990's [took a long time to die](http://blog.cryptographyengineering.com/2016/03/attack-of-week-drown.html), I imagine that we'll still have products running 1024 bit RSA when everyone has a quantum laptop. +[^legacy]: Of course, given that "export grade" cryptography that was supposed to disappear with the 1990's [took a long time to die](http://blog.cryptographyengineering.com/2016/03/attack-of-week-drown.html), I imagine that we'll still have products running 1024 bit RSA when everyone has a quantum laptop. [^overhead]: This "99 percent" is a figure of speech, but not completely so. It seems that for many web servers, the TLS protocol (which based on the current non-lattice based systems would be completely broken by quantum computing) is responsible [for about 1 percent of the CPU usage](https://goo.gl/Gekjrc). @@ -196,7 +196,7 @@ Thus we can describe the _state_ of the system by the $2^n$-dimensional vector $ If we _measure_ the system and see what the coins came out, we will get the value $x$ with probability $v_x$. Naturally, if we measure the system twice we will get the same result. Thus, after we see that the coin is $x$, the new state of the system _collapses_ to a vector $v$ such that $v_y = 1$ if $y=x$ and $v_y=0$ if $y\neq x$. -In a quantum state, we do the same thing: if we _measure_ a vector $v$ corresponds to turning it with probability $|v_x|^2$ into a vector that has $1$ on coordinate $x$ and zero on all the other coordinates. +In a quantum state, we do the same thing: _measuring_ a vector $v$ corresponds to turning it with probability $|v_x|^2$ into a vector that has $1$ on coordinate $x$ and zero on all the other coordinates. __Operations:__ In the classical probabilistic setting, if we have a system in state $v$ and we apply some function $f:\{0,1\}^n\rightarrow\{0,1\}^n$ then this transforms $v$ to the state $w$ such that $w_y = \sum_{x:f(x)=y} v_x$. @@ -210,10 +210,10 @@ That is, $M$ is obtained by "lifting" some $8\times 8$ matrix $M'$ that operate Formally, given an $8\times 8$ matrix $M'$ (indexed by strings in $\{0,1\}^3$) and three distinct indices $i # {.remark title="Quantum vs probabilistic strategies" #quantumprob} -It is instructive to understand what is it about quantum mechanics that enabled this gain in Bell's Inequality. For this, consider the following analogous probabilistic strategy for Alice and Bob. They agree that each one of them output $0$ if he or she get $0$ as input and outputs $1$ with probability $p$ if they get $1$ as input. In this case one can see that their success probability would be $\tfrac{1}{4}\cdot 1 + \tfrac{1}{2}(1-p)+\tfrac{1}{4}[2p(1-p)]=0.75 -0.5p^2 \leq 0.75$. The quantum strategy we described above can be thought of as a variant of the probabilistic strategy for parameter $p$ set to $\sin^2 (\pi/8)=0.15$. But in the case $x=y=1$, instead of disagreeing only with probability $2p(1-p)=1/4$, because we can use these negative probabilities in the quantum world and rotate the state in opposite directions, and hence the probability of disagreement ends up being $\sin^2 (\pi/4)=0.5$. +It is instructive to understand what is it about quantum mechanics that enabled this gain in Bell's Inequality. For this, consider the following analogous probabilistic strategy for Alice and Bob. They agree that each one of them output $0$ if he or she get $0$ as input and outputs $1$ with probability $p$ if they get $1$ as input. In this case one can see that their success probability would be $\tfrac{1}{4}\cdot 1 + \tfrac{1}{2}(1-p)+\tfrac{1}{4}[2p(1-p)]=0.75 -0.5p^2 \leq 0.75$. The quantum strategy we described above can be thought of as a variant of the probabilistic strategy for parameter $p$ set to $\sin^2 (\pi/8)=0.15$. But in the case $x=y=1$, instead of disagreeing only with probability $2p(1-p)=1/4$, because we can use these negative probabilities in the quantum world and rotate the state in opposite directions, the probability of disagreement ends up being $\sin^2 (\pi/4)=0.5$. @@ -435,7 +435,7 @@ It is instructive to understand what is it about quantum mechanics that enabled ## Grover's Algorithm Shor's Algorithm, which we'll see in the next lecture, is an amazing achievement, but it only applies to very particular problems. -It does not seem to be relevant to breaking AES, lattice based cryptography, or problems not related to quantum computing at all such as scheduling, constraint satisfaction, traveling salesperson etc.. etc.. +It does not seem to be relevant to breaking AES, lattice based cryptography, or problems not related to quantum computing at all such as scheduling, constraint satisfaction, traveling salesperson etc. Indeed, for the most general form of these search problems, classically we don't how to do anything much better than brute force search, which takes $2^n$ time over an $n$-bit domain. Lev Grover showed that quantum computers can obtain a quadratic improvement over this brute force search, solving SAT in $2^{n/2}$ time. The effect of Grover's algorithm on cryptography is fairly mild: one essentially needs to double the key lengths of symmetric primitives. But beyond cryptography, if large scale quantum computers end up being built, Grover search and its variants might end up being some of the most useful computational problems they will tackle. From 4c6d2e5bf00101d3dc960b512a2c6cbcbc797b57 Mon Sep 17 00:00:00 2001 From: Abe Wieland Date: Wed, 1 Dec 2021 11:31:55 -0500 Subject: [PATCH 2/2] Quantum part II typos --- lec_20_quantum_part2.md | 38 +++++++++++++++++++------------------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/lec_20_quantum_part2.md b/lec_20_quantum_part2.md index 1b5e7fa..cc3634d 100644 --- a/lec_20_quantum_part2.md +++ b/lec_20_quantum_part2.md @@ -19,7 +19,7 @@ In 1994 Peter Shor showed that one would be wrong: The map that takes an integer $m$ into its prime factorization is efficiently quantumly computable. Specifically, it can be computed using $O(\log^3 m)$ quantum gates. -This is an exponential improvement over the best known classical algorithms, which as we mentioned before, take roughly $2^{\tilde{O(\log^{1/3}m)}}$ time. +This is an exponential improvement over the best known classical algorithms, which as we mentioned before, take roughly $\sim 2^{O(\log^{1/3}m)}$ time. We will now sketch the ideas behind Shor's algorithm. In fact, Shor proved the following more general theorem: @@ -57,7 +57,7 @@ Similarly, the main idea behind Shor's algorithm is to use a tool known as the _ Hence when we measure this state, we get a group element $h$ with probability proportional to the square of the corresponding Fourier coefficient. One can show that if $f$ is $h^*$-periodic then we can recover $h^*$ from this distribution. -Shor carried out this approach for the group $\mathbb{H}=\Z^*_q$ for some $q$, but we will start be seeing this for the group $\mathbb{H} = \{0,1\}^n$ with the XOR operation. +Shor carried out this approach for the group $\mathbb{H}=\Z^*_q$ for some $q$, but we will start by seeing this for the group $\mathbb{H} = \{0,1\}^n$ with the XOR operation. This case is known as _Simon's algorithm_ (given by Dan Simon in 1994) and actually preceded (and inspired) Shor's algorithm: @@ -71,17 +71,17 @@ Note that given $O(n)$ such samples, we can recover $h^*$ with high probability > # {.proof data-ref="simonsthm"} Let $HAD$ be the $2\times 2$ unitary matrix corresponding to the one qubit operation $|0\rangle \mapsto \tfrac{1}{\sqrt{2}}(|0\rangle+|1\rangle)$ and $|1\rangle \mapsto \tfrac{1}{\sqrt{2}}(|0\rangle-|1\rangle)$ or $|a\rangle\mapsto \tfrac{1}{\sqrt{2}}(|0\rangle+(-1)^a|1\rangle)$. -Given the state $|0^{n+m\rangle}$ we can apply this map to each one of the first $n$ qubits to get the state -$2^{-n/2}\sum_{x\in\{0,1\}^n}|x\rangle|0^m\rangle$ +Given the state $|0^{n+m}\rangle$. we can apply this map to each one of the first $n$ qubits to get the state +$2^{-n/2}\sum_{x\in\{0,1\}^n}|x\rangle|0^m\rangle$, and then we can apply the gates of $f$ to map this to the state -$2^{-n/2}\sum_{x\in\{0,1\}^n}|x\rangle|f(x)\rangle$ -now suppose that we apply this operation again to the first $n$ qubits then we get the state +$2^{-n/2}\sum_{x\in\{0,1\}^n}|x\rangle|f(x)\rangle$. +Now suppose that we apply this operation again to the first $n$ qubits then we get the state $2^{-n}\sum_{x\in\{0,1\}^n}\prod_{i=1}^n(|0\rangle+(-1)^{x_i}|1\rangle)|f(x)\rangle$ which if we open up each one of these product and look at all $2^n$ choices $y\in\{0,1\}^n$ (with $y_i=0$ corresponding to picking $|0\rangle$ and $y_i=1$ corresponding to picking $|1\rangle$ in the $i^{th}$ product) we get $2^{-n}\sum_{x\in\{0,1\}^n}\sum_{y\in\{0,1\}^n}(-1)^{\langle x,y \rangle}|y\rangle|f(x)\rangle$. -Now under our assumptions for every particular $z$ in the image of $f$, there exist exactly two preimages $x$ and $x\oplus h^*$ such that $f(x)=f(x+h^*)=z$. -So, if $\langle y,h^* \rangle=0 \pmod{2}$, we get that $(-1)^{\langle x,y \rangle}+(-1)^{\langle x,y+h^* \rangle}=2$ and otherwise we get $(-1)^{\langle x,y \rangle}+(-1)^{\langle x,y+h^* \rangle}=0$. -Therefore, if measure the state we will get a pair $(y,z)$ such that $\langle y,h^* \rangle=0 \pmod{2}$. QED +By the problem assumptions, for every particular $z$ in the image of $f$, there exist exactly two preimages, $x$ and $x\oplus h^*$, such that $f(x)=f(x\oplus h^*)=z$. +So, if $\langle y,h^* \rangle=0 \pmod{2}$, then $(-1)^{\langle x,y \rangle}+(-1)^{\langle x+h^*,y\rangle}=2\cdot(-1)^{\langle x, y\rangle}$ and otherwise $(-1)^{\langle x,y \rangle}+(-1)^{\langle x+h^*,y\rangle}=0$. +Therefore, if measure the state we will get a pair $(y,z)$ such that $\langle y,h^* \rangle=0 \pmod{2}$. Simon's algorithm seems to really use the special bit-wise structure of the group $\{0,1\}^n$, so one could wonder if it has any relevance for the group $\Z^*_m$ for some exponentially large $m$. It turns out that the same insights that underlie the well known Fast Fourier Transform (FFT) algorithm can be used to essentially follow the same strategy for this group as well. @@ -100,7 +100,7 @@ For every $\ell$ and $a\in\Z^*_\ell$, there is a quantum $poly(log \ell)$ algori -The idea is similar to Simon's algorithm. We consider the map $x \mapsto a^x (\mod \ell)$ which is a periodic map over $\Z_m$ where $m=|\Z^*_\ell|$ with period being the order of $a$. +The idea is similar to Simon's algorithm. We consider the map $x \mapsto a^x \pmod{\ell}$ which is a periodic map over $\Z_m$ where $m=|\Z^*_\ell|$ with period being the order of $a$. To find the period of this map we will now need to perform a _Quantum Fourier Transform (QFT)_ over the group $\Z_m$ instead of $\{0,1\}^n$. This is a quantum algorithm that takes a register from some arbitrary state $f \in \mathbb{C}^{m}$ into a state whose vector is the Fourier transform @@ -129,13 +129,13 @@ where $\omega = e^{2\pi i/m}$. The Fourier transform is simply a representation of $f$ in the *Fourier basis* $\{ \chi_x \}_{x \in \Z_m}$, where $\chi_x$ is the vector/function whose $y^{th}$ coordinate is -$\tfrac{1}{\sqrt{m}\omega^{xy}}$. Now the inner product of any two vectors +$\tfrac{1}{\sqrt{m}}\omega^{xy}$. Now the inner product of any two vectors $\chi_x,\chi_z$ in this basis is equal to $$\langle \chi_x,\chi_z \rangle = \tfrac{1}{m}\sum_{y\in\Z_m} \omega^{xy} \overline{\omega^{zy}} = \tfrac{1}{m}\sum_{y\in\Z_m} \omega^{(x-z)y} \;.$$ But if $x=z$ then $\omega^{(x-z)}=1$ and hence this sum is equal to $1$. On the other hand, if $x \neq z$, then this sum is equal to -$\tfrac{1}{m} \tfrac{1 -\omega^{(x-y)m}}{1-\omega^{x-y}}= -\tfrac{1}{m}\tfrac{1-1}{1-\omega^{x-y}}=0$ using the formula for the sum of +$\tfrac{1}{m} \tfrac{1 -\omega^{(x-z)m}}{1-\omega^{x-z}}= +\tfrac{1}{m}\tfrac{1-1}{1-\omega^{x-z}}=0$ using the formula for the sum of a geometric series. In other words, this is an *orthonormal* basis which means that the Fourier transform map $f \mapsto \hat{f}$ is a *unitary* operation. @@ -146,7 +146,7 @@ it’s easy to see that every function $\chi$ in the Fourier basis is a *homomorphism* from $\Z_m$ to $\mathbb{C}$ in the sense that $\chi(y+z)= \chi(y)\chi(z)$ for every $y,z \in \Z_m$. Also, every function $\chi$ is *periodic* in the sense that there -exists $r\in \Z_m$ such that $\chi(y+r)=\chi(z)$ for every $y\in \Z_m$ +exists $r\in \Z_m$ such that $\chi(y+r)=\chi(y)$ for every $y\in \Z_m$ (indeed if $\chi(y) = \omega^{xy}$ then we can take $r$ to be $\ell/x$ where $\ell$ is the least common multiple of $x$ and $m$). Thus, intuitively, if a function @@ -169,9 +169,9 @@ the same idea is used in the *quantum* Fourier transform algorithm. Note that -$\hat{f}(x) = \tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m} f(y)\omega^{xy} =$ +$\hat{f}(x) = \tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m} f(x)\omega^{xy} =$ -$\tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m,y \;even} f(y)\omega^{-2x(y/2)} + \omega^x\tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m,y \;odd} f(y)\omega^{2x(y-1)/2} \;.$ +$\tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m,y \;even} f(x)\omega^{2x(y/2)} + \omega^x\tfrac{1}{\sqrt{m}}\sum_{y\in\Z_m,y \;odd} f(x)\omega^{2x(y-1)/2} \;.$ Now since $\omega^2$ is an $m/2$th root of unity and $\omega^{m/2}=-1$, letting $W$ be the $m/2 \times m/2$ diagonal matrix with diagonal entries @@ -188,8 +188,8 @@ $1$) and by $\vec{v}_{low}$ (resp. $\vec{v}_{high}$) the restriction of $\vec{v}$ to coordinates with most significant bit $0$ (resp. $1$). The equations above are the crux -of the divide-and-conquer idea of the FFT algorithm, since they allow to -replace a size-$m$ problem with two size-$m/2$ subproblems, leading to a +of the divide-and-conquer idea of the FFT algorithm, since they allow +replacing a size-$m$ problem with two size-$m/2$ subproblems, leading to a recursive time bound of the form $T(m) = 2T(m/2) + O(m)$ which solves to $T(m)=O(m\log m)$. @@ -506,7 +506,7 @@ computed in $polylog(q_n)$ time. ### Quantum cryptography -There is another way in which quantum mechanics interacts with cryptography. These "spooky actions at a distance" have been suggested by Weisner and Bennet-Brassard as a way in which parties can create a secret shared key over an insecure channel. On one hand, this concept does not require as much control as general-purpose quantum computing, and so it has in fact been [demonstrated physically](https://en.wikipedia.org/wiki/Quantum_key_distribution#Quantum_Key_Distribution_Networks). On the other hand, unlike transmitting standard digital information, this "insecure channel" cannot be an arbitrary media such as wifi etc.. but rather one needs fiber optics, lasers, etc.. Unlike quantum computers, where we only need one of those to break RSA, to actually use key exchange at scale we need to setup these type of networks, and so it is unclear if this approach will ever dominate the solution of Alice sending to Bob a Brink's truck with the shared secret key. People have proposed some other ways to use the interesting properties of quantum mechanics for cryptographic purposes including [quantum money](https://en.wikipedia.org/wiki/Quantum_money) and [quantum software protection](http://www.scottaaronson.com/papers/noclone-ccc.pdf). +There is another way in which quantum mechanics interacts with cryptography. These "spooky actions at a distance" have been suggested by Weisner and Bennet-Brassard as a way in which parties can create a secret shared key over an insecure channel. On one hand, this concept does not require as much control as general-purpose quantum computing, and so it has in fact been [demonstrated physically](https://en.wikipedia.org/wiki/Quantum_key_distribution#Quantum_Key_Distribution_Networks). On the other hand, unlike transmitting standard digital information, this "insecure channel" cannot be an arbitrary media such as wifi, but rather one needs fiber optics, lasers, etc. Unlike quantum computers, where we only need one of those to break RSA, to actually use key exchange at scale we need to setup these type of networks, and so it is unclear if this approach will ever dominate the solution of Alice sending to Bob a Brink's truck with the shared secret key. People have proposed some other ways to use the interesting properties of quantum mechanics for cryptographic purposes including [quantum money](https://en.wikipedia.org/wiki/Quantum_money) and [quantum software protection](http://www.scottaaronson.com/papers/noclone-ccc.pdf).