Abstract

We prove near-optimal lower bounds for preprocessing attacks on quantum cryptography in the random oracle model. Specifically, we show that a $T$-query adversary with $S$ qubits of non-uniform advice can recover a random key $k$ from the $n$-qubit binary phase state $|ψ_k\rangle \propto \sum_{x} R(k,x) |x\rangle$ with probability at most $O(\frac{T^2 + \sqrt{ST}}{N})$ for $N=2^n$. In contrast, the best known bound for post-quantum one-way functions is $O(\frac{T^2 + ST}{N})$, with a trivial attack at $S = N$. This demonstrates a new advantage of quantum cryptography over classical cryptography: $n$ qubits of communication suffice for security against preprocessing attacks with space up to $N^2$ rather than $N$. Our methodology is simple: express the optimal preprocessing attack as the operator norm of a random matrix, and bound this value in expectation over the random oracle via the trace-moment method. These trace moments have a natural interpretation using compressed oracles [Zhandry, Crypto 2019], which we then analyze. This can be viewed as a simplification and generalization of the approach of Liu [Eurocrypt 2023] for proving the security of post-quantum cryptography against preprocessing attacks. We also prove the following results: (1) We tighten Liu's analysis of post-quantum PRGs in QROM, achieving a distinguishing advantage bound of $O(\frac{T^2}N + \sqrt{\frac{ST}N})$. (2) For unitary synthesis, we extend the one-query lower bound of Lombardi-Ma-Wright [STOC 2024] to hold against adversaries that can make one arbitrary function query along with polynomially many (adaptive) queries to the random oracle, either before or after the function query. This also interprets the original LMW24 result in terms of compressed oracles. (3) Finally, we prove a tight $O(\frac{\sqrt{S}}N)$ bound for the pseudorandomness of random binary phase states against space $S$ distinguishers.

Keywords

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Dong, F., & Lombardi, A. (2026). Lower Bounds for Preprocessing Attacks on Quantum Cryptography. https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography

MLA 9

Dong, Fangqi, and Alex Lombardi. "Lower Bounds for Preprocessing Attacks on Quantum Cryptography." https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography.

Chicago (author–date)

Dong, Fangqi, and Alex Lombardi. 2026. "Lower Bounds for Preprocessing Attacks on Quantum Cryptography." https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography.

Harvard

Dong, F. and Lombardi, A. (2026) 'Lower Bounds for Preprocessing Attacks on Quantum Cryptography', Available at: https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography.

Vancouver

Dong F, Lombardi A. Lower Bounds for Preprocessing Attacks on Quantum Cryptography. https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography

IEEE

F. Dong, and A. Lombardi, "Lower Bounds for Preprocessing Attacks on Quantum Cryptography," https://omanscience.com/en/articles/lower-bounds-for-preprocessing-attacks-on-quantum-cryptography.