<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Alex Bredariol Grilo | LIP6 - Équipe QI</title><link>https://qi.lip6.fr/fr/people/alex-bredariol-grilo/</link><atom:link href="https://qi.lip6.fr/fr/people/alex-bredariol-grilo/index.xml" rel="self" type="application/rss+xml"/><description>Alex Bredariol Grilo</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>fr</language><copyright>© 2022 LIP6 Quantum Information Team</copyright><lastBuildDate>Thu, 08 Jan 2026 00:00:00 +0000</lastBuildDate><image><url>https://qi.lip6.fr/fr/people/alex-bredariol-grilo/avatar_hu_1f98439db6522aa.jpg</url><title>Alex Bredariol Grilo</title><link>https://qi.lip6.fr/fr/people/alex-bredariol-grilo/</link></image><item><title>Quantum pseudoresources imply cryptography</title><link>https://qi.lip6.fr/fr/publication/5459407-quantum-pseudoresources-imply-cryptography/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/5459407-quantum-pseudoresources-imply-cryptography/</guid><description>&lt;p&gt;While one-way functions (OWFs) serve as the minimal assumption for computational cryptography in the classical setting, in quantum cryptography, we have even weaker cryptographic assumptions such as pseudo-random states, and EFI pairs, among others. Moreover, the minimal assumption for computational quantum cryptography remains an open question. Recently, it has been shown that pseudoentanglement is necessary for the existence of quantum cryptography (Goulão and Elkouss 2024), but no cryptographic construction has been built from it. In this work, we study the cryptographic usefulness of quantum pseudoresources—a pair of families of quantum states that exhibit a gap in their resource content yet remain computationally indistinguishable. We show that quantum pseudoresources imply a variant of EFI pairs, which we call EPFI pairs, and that these are equivalent to quantum commitments and thus EFI pairs. Our results suggest that, just as randomness is fundamental to classical cryptography, quantum resources may play a similarly crucial role in the quantum setting. Finally, we focus on the specific case of entanglement, analyzing different definitions of pseudoentanglement and their implications for constructing EPFI pairs. Moreover, we propose a new cryptographic functionality that is intrinsically dependent on entanglement as a resource.&lt;/p&gt;</description></item><item><title>StoqMA vs. MA: the power of error reduction</title><link>https://qi.lip6.fr/fr/publication/2968357-stoqma-vs-ma-the-power-of-error-reduction/</link><pubDate>Thu, 11 Sep 2025 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2968357-stoqma-vs-ma-the-power-of-error-reduction/</guid><description>&lt;p&gt;StoqMA characterizes the computational hardness of stoquastic local Hamiltonians, which is a family of Hamiltonians that does not suffer from the sign problem. Although error reduction is commonplace for many complexity classes, such as BPP, BQP, MA, QMA, etc.,this property remains open for StoqMA since Bravyi, Bessen and Terhal defined this class in 2006. In this note, we show that error reduction forStoqMA will imply that StoqMA = MA.&lt;/p&gt;</description></item><item><title>19th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2024)</title><link>https://qi.lip6.fr/fr/publication/4739775-19th-conference-on-the-theory-of-quantum-computation-communication-and-cryptography-tqc-2024/</link><pubDate>Mon, 26 Aug 2024 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4739775-19th-conference-on-the-theory-of-quantum-computation-communication-and-cryptography-tqc-2024/</guid><description/></item><item><title>The Round Complexity of Proofs in the Bounded Quantum Storage Model</title><link>https://qi.lip6.fr/fr/publication/4594661-the-round-complexity-of-proofs-in-the-bounded-quantum-storage-model/</link><pubDate>Thu, 30 May 2024 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4594661-the-round-complexity-of-proofs-in-the-bounded-quantum-storage-model/</guid><description>&lt;p&gt;The round complexity of interactive proof systems is a key question of practical and theoretical relevance in complexity theory and cryptography. Moreover, results such as QIP = QIP(3) (STOC'00) show that quantum resources significantly help in such a task. In this work, we initiate the study of round compression of protocols in the bounded quantum storage model (BQSM). In this model, the malicious parties have a bounded quantum memory and they cannot store the all the qubits that are transmitted in the protocol. Our main results in this setting are the following: 1. There is a non-interactive (statistical) witness indistinguishable proof for any language in NP (and even QMA) in BQSM in the plain model. We notice that in this protocol, only the memory of the verifier is bounded. 2. Any classical proof system can be compressed in a two-message quantum proof system in BQSM. Moreover, if the original proof system is zero-knowledge, the quantum protocol is zero-knowledge too. In this result, we assume that the prover has bounded memory. Finally, we give evidence towards the &amp;ldquo;tightness&amp;rdquo; of our results. First, we show that NIZK in the plain model against BQS adversaries is unlikely with standard techniques. Second, we prove that without the BQS model there is no 2-message zero-knowledge quantum interactive proof, even under computational assumptions.&lt;/p&gt;</description></item><item><title>The power of shallow-depth Toffoli and qudit quantum circuits</title><link>https://qi.lip6.fr/fr/publication/4564456-the-power-of-shallow-depth-toffoli-and-qudit-quantum-circuits/</link><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4564456-the-power-of-shallow-depth-toffoli-and-qudit-quantum-circuits/</guid><description>&lt;p&gt;The relevance of shallow-depth quantum circuits has recently increased, mainly due to their applicability to near-term devices. In this context, one of the main goals of quantum circuit complexity is to find problems that can be solved by quantum shallow circuits but require more computational resources classically. Our first contribution in this work is to prove new separations between classical and quantum constant-depth circuits. Firstly, we show a separation between constant-depth quantum circuits with quantum advice $\mathsf{QNC}^0/\mathsf{qpoly}$, and $\mathsf{AC}^0[p]$, which is the class of classical constant-depth circuits with unbounded-fan in and $\pmod{p}$ gates. In addition, we show a separation between $\mathsf{QAC}^0$, which additionally has Toffoli gates with unbounded control, and $\mathsf{AC}^0[p]$. This establishes the first such separation for a shallow-depth quantum class that does not involve quantum fan-out gates. Secondly, we consider $\mathsf{QNC}^0$ circuits with infinite-size gate sets. We show that these circuits, along with (classical or quantum) prime modular gates, can implement threshold gates, showing that $\mathsf{QNC}^0[p]=\mathsf{QTC}^0$. Finally, we also show that in the infinite-size gateset case, these quantum circuit classes for higher-dimensional Hilbert spaces do not offer any advantage to standard qubit implementations.&lt;/p&gt;</description></item><item><title>Towards the Impossibility of Quantum Public Key Encryption with Classical Keys from One-Way Functions</title><link>https://qi.lip6.fr/fr/publication/4540950-towards-the-impossibility-of-quantum-public-key-encryption-with-classical-keys-from-one-way-functions/</link><pubDate>Tue, 09 Apr 2024 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4540950-towards-the-impossibility-of-quantum-public-key-encryption-with-classical-keys-from-one-way-functions/</guid><description>&lt;p&gt;There has been a recent interest in proposing quantum protocols whose security relies on weaker computational assumptions than their classical counterparts. Importantly to our work, it has been recently shown that public-key encryption (PKE) from one-way functions (OWF) is possible if we consider quantum public keys. Notice that we do not expect classical PKE from OWF given the impossibility results of Impagliazzo and Rudich (STOC'89). However, the distribution of quantum public keys is a challenging task. Therefore, the main question that motivates our work is if quantum PKE from OWF is possible if we have classical public keys. Such protocols are impossible if ciphertexts are also classical, given the impossibility result of Austrin et al.(CRYPTO'22) of quantum enhanced key-agreement (KA) with classical communication. In this paper, we focus on black-box separation for PKE with classical public key and quantum ciphertext from OWF under the polynomial compatibility conjecture, first introduced in Austrin et al.. More precisely, we show the separation when the decryption algorithm of the PKE does not query the OWF. We prove our result by extending the techniques of Austrin et al. and we show an attack for KA in an extended classical communication model where the last message in the protocol can be a quantum state.&lt;/p&gt;</description></item><item><title>Trainability and Expressivity of Hamming-Weight Preserving Quantum Circuits for Machine Learning</title><link>https://qi.lip6.fr/fr/publication/4225039-trainability-and-expressivity-of-hamming-weight-preserving-quantum-circuits-for-machine-learning/</link><pubDate>Mon, 02 Oct 2023 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4225039-trainability-and-expressivity-of-hamming-weight-preserving-quantum-circuits-for-machine-learning/</guid><description>&lt;p&gt;Quantum machine learning has become a promising area for real world applications of quantum computers, but near-term methods and their scalability are still important research topics. In this context, we analyze the trainability and controllability of specific Hamming weight preserving quantum circuits. These circuits use gates that preserve subspaces of the Hilbert space, spanned by basis states with fixed Hamming weight $k$. They are good candidates for mimicking neural networks, by both loading classical data and performing trainable layers. In this work, we first design and prove the feasibility of new heuristic data loaders, performing quantum amplitude encoding of $\binom{n}{k}$-dimensional vectors by training a n-qubit quantum circuit. Then, we analyze more generally the trainability of Hamming weight preserving circuits, and show that the variance of their gradients is bounded according to the size of the preserved subspace. This proves the conditions of existence of Barren Plateaus for these circuits, and highlights a setting where a recent conjecture on the link between controllability and trainability of variational quantum circuits does not apply.&lt;/p&gt;</description></item><item><title>Quantum security of subset cover problems</title><link>https://qi.lip6.fr/fr/publication/3832954-quantum-security-of-subset-cover-problems/</link><pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3832954-quantum-security-of-subset-cover-problems/</guid><description>&lt;p&gt;The subset cover problem for $k \geq 1$ hash functions, which can be seen as an extension of the collision problem, was introduced in 2002 by Reyzin and Reyzin to analyse the security of their hash-function based signature scheme HORS. The security of many hash-based signature schemes relies on this problem or a variant of this problem (e.g. HORS, SPHINCS, SPHINCS+, \dots). Recently, Yuan, Tibouchi and Abe (2022) introduced a variant to the subset cover problem, called restricted subset cover, and proposed a quantum algorithm for this problem. In this work, we prove that any quantum algorithm needs to make $\Omega\left(k^{-\frac{2^{k-1}}{2^k-1}}\cdot N^{\frac{2^{k-1}-1}{2^k-1}}\right)$ queries to the underlying hash functions to solve the restricted subset cover problem, which essentially matches the query complexity of the algorithm proposed by Yuan, Tibouchi and Abe. We also analyze the security of the general $(r,k)$-subset cover problem, which is the underlying problem that implies the unforgeability of HORS under a $r$-chosen message attack (for $r \geq 1$). We prove that a generic quantum algorithm needs to make $\Omega\left(N^{k/5}\right)$ queries to the underlying hash functions to find a $(1,k)$-subset cover. We also propose a quantum algorithm that finds a $(r,k)$-subset cover making $O\left(N^{k/(2+2r)}\right)$ queries to the $k$ hash functions.&lt;/p&gt;</description></item><item><title>Encryption with Quantum Public Keys</title><link>https://qi.lip6.fr/fr/publication/4022634-encryption-with-quantum-public-keys/</link><pubDate>Fri, 10 Mar 2023 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4022634-encryption-with-quantum-public-keys/</guid><description>&lt;p&gt;It is an important question to find constructions of quantum cryptographic protocols which rely on weaker computational assumptions than classical protocols. Recently, it has been shown that oblivious transfer and multi-party computation can be constructed from one-way functions, whereas this is impossible in the classical setting in a black-box way. In this work, we study the question of building quantum public-key encryption schemes from one-way functions and even weaker assumptions. Firstly, we revisit the definition of IND-CPA security to this setting. Then, we propose three schemes for quantum public-key encryption from one-way functions, pseudorandom function-like states with proof of deletion and pseudorandom function-like states, respectively.&lt;/p&gt;</description></item><item><title>Post-Quantum Zero-Knowledge with Space-Bounded Simulation</title><link>https://qi.lip6.fr/fr/publication/3812841-post-quantum-zero-knowledge-with-space-bounded-simulation/</link><pubDate>Thu, 13 Oct 2022 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3812841-post-quantum-zero-knowledge-with-space-bounded-simulation/</guid><description>&lt;p&gt;The traditional definition of quantum zero-knowledge stipulates that the knowledge gained by any quantum polynomial-time verifier in an interactive protocol can be simulated by a quantum polynomial-time algorithm. One drawback of this definition is that it allows the simulator to consume significantly more computational resources than the verifier. We argue that this drawback renders the existing notion of quantum zero-knowledge not viable for certain settings, especially when dealing with near-term quantum devices. In this work, we initiate a fine-grained notion of post-quantum zero-knowledge that is more compatible with near-term quantum devices. We introduce the notion of $(s,f)$ space-bounded quantum zero-knowledge. In this new notion, we require that an $s$-qubit malicious verifier can be simulated by a quantum polynomial-time algorithm that uses at most $f(s)$-qubits, for some function $f(\cdot)$, and no restriction on the amount of the classical memory consumed by either the verifier or the simulator. We explore this notion and establish both positive and negative results: - For verifiers with logarithmic quantum space $s$ and (arbitrary) polynomial classical space, we show that $(s,f)$-space-bounded QZK, for $f(s)=2s$, can be achieved based on the existence of post-quantum one-way functions. Moreover, our protocol runs in constant rounds. - For verifiers with super-logarithmic quantum space $s$, assuming the existence of post-quantum secure one-way functions, we show that $(s,f)$-space-bounded QZK protocols, with fully black-box simulation (classical analogue of black-box simulation) can only be achieved for languages in BQP.&lt;/p&gt;</description></item><item><title>QMA-Hardness of Consistency of Local Density Matrices with Applications to Quantum Zero-Knowledge</title><link>https://qi.lip6.fr/fr/publication/3773541-qma-hardness-of-consistency-of-local-density-matrices-with-applications-to-quantum-zero-knowledge/</link><pubDate>Mon, 01 Aug 2022 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3773541-qma-hardness-of-consistency-of-local-density-matrices-with-applications-to-quantum-zero-knowledge/</guid><description/></item><item><title>Quantum learning algorithms imply circuit lower bounds</title><link>https://qi.lip6.fr/fr/publication/3836332-quantum-learning-algorithms-imply-circuit-lower-bounds/</link><pubDate>Mon, 07 Feb 2022 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3836332-quantum-learning-algorithms-imply-circuit-lower-bounds/</guid><description/></item><item><title>Tight adaptive reprogramming in the QROM</title><link>https://qi.lip6.fr/fr/publication/2997744-tight-adaptive-reprogramming-in-the-qrom/</link><pubDate>Mon, 06 Dec 2021 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2997744-tight-adaptive-reprogramming-in-the-qrom/</guid><description>&lt;p&gt;The random oracle model (ROM) enjoys widespread popularity, mostly because it tends to allow for tight and conceptually simple proofs where provable security in the standard model is elusive or costly. While being the adequate replacement of the ROM in the post-quantum security setting, the quantum-accessible random oracle model (QROM) has thus far failed to provide these advantages in many settings. In this work, we focus on adaptive reprogrammability, a feature of the ROM enabling tight and simple proofs in many settings. We show that the straightforward quantum-accessible generalization of adaptive reprogramming is feasible by proving a bound on the adversarial advantage in distinguishing whether a random oracle has been reprogrammed or not. We show that our bound is tight by providing a matching attack. We go on to demonstrate that our technique recovers the mentioned advantages of the ROM in three QROM applications: 1) We give a tighter proof of security of the message compression routine as used by XMSS. 2) We show that the standard ROM proof of chosen-message security for Fiat-Shamir signatures can be lifted to the QROM, straightforwardly, achieving a tighter reduction than previously known. 3) We give the first QROM proof of security against fault injection and nonce attacks for the hedged Fiat-Shamir transform.&lt;/p&gt;</description></item><item><title>Oblivious Transfer is in MiniQCrypt</title><link>https://qi.lip6.fr/fr/publication/3033900-oblivious-transfer-is-in-miniqcrypt/</link><pubDate>Sun, 17 Oct 2021 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3033900-oblivious-transfer-is-in-miniqcrypt/</guid><description>&lt;p&gt;MiniQCrypt is a world where quantum-secure one-way functions exist, and quantum communication is possible. We construct an oblivious transfer (OT) protocol in MiniQCrypt that achieves simulation-security in the plain model against malicious quantum polynomial-time adversaries, building on the foundational work of Bennett, Brassard, Cr'epeau and Skubiszewska (CRYPTO 1991). Combining the OT protocol with prior works, we obtain secure two-party and multi-party computation protocols also in MiniQCrypt. This is in contrast to the classical world, where it is widely believed that one-way functions alone do not give us OT. In the common random string model, we achieve a constant-round universally composable (UC) OT protocol.&lt;/p&gt;</description></item><item><title>QMA-Hardness of Consistency of Local Density Matrices with Applications to Quantum Zero-Knowledge</title><link>https://qi.lip6.fr/fr/publication/3123358-qma-hardness-of-consistency-of-local-density-matrices-with-applications-to-quantum-zero-knowledge/</link><pubDate>Mon, 16 Nov 2020 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3123358-qma-hardness-of-consistency-of-local-density-matrices-with-applications-to-quantum-zero-knowledge/</guid><description>&lt;p&gt;We provide several advances to the understanding of the class of Quantum Merlin-Arthur proof systems (QMA), the quantum analogue of NP. First, we answer a longstanding open question by showing that the Consistency of Local Density Matrices problem is QMA-complete under Karp reductions. We also show for the first time a commit-and-open computational zero-knowledge proof system for all of QMA as a quantum analogue of a &amp;ldquo;sigma&amp;rdquo; protocol. We then define a Proof of Quantum Knowledge, which guarantees that a prover is effectively in possession of a quantum witness in an interactive proof, and show that our zero-knowledge proof system satisfies this definition. Finally, we show that our proof system can be used to establish that QMA has a quantum non-interactive zero-knowledge proof system in the secret parameters setting. Our main technique consists in developing locally simulatable proofs for all of QMA: this is an encoding of a QMA witness such that it can be efficiently verified by probing only five qubits and, furthermore, the reduced density matrix of any five-qubit subsystem can be computed in polynomial time and is independent of the witness. This construction follows the techniques of Grilo, Slofstra, and Yuen [FOCS 2019].&lt;/p&gt;</description></item></channel></rss>