|q⟩ Bad Qubits

advanced · Physics · Bell Nonlocality & Device-Independence

Randomness from Nonlocality

If a Bell test certifies that your boxes contain genuine entanglement, it also certifies something operationally priceless: their outputs are unpredictable, even to an adversary who built the hardware. This lesson explains why a Bell violation lower-bounds the randomness of the outcomes, device-independently.

Why a violation implies randomness

Suppose, toward contradiction, that Alice's outcome aa were deterministic given the inputs — fixed in advance, perhaps by a hidden variable the manufacturer pre-loaded. Then the model is a local deterministic one, and we proved such models obey S2S\le 2. So observing S>2S>2 rules out determinism: the outcomes cannot be a pre-set function of the settings. Some genuine randomness must be generated at measurement time. The larger the violation, the more randomness is forced.

Quantifying it: the guessing probability

The right measure is the min-entropy. Let Pguess(ax)P_{\text{guess}}(a\mid x) be the maximum probability with which an adversary Eve — who may hold a quantum system correlated with the boxes — predicts the outcome aa for a fixed input xx. The certified randomness is

Hmin(ax)=log2Pguess(ax).H_{\min}(a\mid x) = -\log_2 P_{\text{guess}}(a\mid x).

The central DI result bounds PguessP_{\text{guess}} using only the observed CHSH value SS. For the CHSH scenario,

Pguess12(1+2S24),P_{\text{guess}} \le \frac{1}{2}\left(1 + \sqrt{2 - \frac{S^2}{4}}\right),

a function that decreases monotonically as SS grows from 22 to 222\sqrt2.

The two extremes

At the classical boundary S=2S=2, the bound gives Pguess1P_{\text{guess}}\le 1: no randomness is certified, consistent with a deterministic local model. At maximal violation S=22S=2\sqrt2, we have 2S2/4=22=02 - S^2/4 = 2 - 2 = 0, so

Pguess12,Hmin(ax)1 bit.P_{\text{guess}} \le \frac12, \qquad H_{\min}(a\mid x) \ge 1\ \text{bit}.

A single maximally-nonlocal round certifies a full bit of fresh, private randomness in Alice's outcome — the strongest possible for one binary output. Eve, despite having manufactured the devices and holding any correlated quantum side information, can do no better than a coin flip.

From one round to a protocol

A randomness-expansion protocol interleaves many rounds, uses a few random rounds to estimate SS, and feeds the rest through a classical randomness extractor to distil near-uniform bits. Security proofs against quantum adversaries accumulate the per-round min-entropy via the entropy accumulation theorem, yielding a net output rate set by the observed violation. This is how the 2010 experiment of Pironio et al. produced the first numbers "certified by Bell's theorem."

The takeaway

A Bell violation is incompatible with determinism, so it forces randomness. Quantitatively, PguessP_{\text{guess}} is bounded by a decreasing function of SS, hitting 1/21/2 — a full certified bit — at S=22S=2\sqrt2. Randomness becomes a measurable consequence of nonlocality, secure against an adversary who controls the devices.

Sign in on the full site to ask questions and join the discussion.