Faking entanglement with imperceptible measurement deviations
Source: arXiv:2606.20396 · Published 2026-06-18 · By Jaime Moreno, Elna Svegborn, Simon Morelli, Markus Hiekkamäaki, Lea Kopf, Robert Fickler et al.
TL;DR
This paper addresses a critical vulnerability in the verification of high-dimensional quantum entanglement. Standard entanglement witnessing approaches assume ideal measurement implementations, but the authors demonstrate both theoretically and experimentally that arbitrarily small, adversarially crafted deviations in measurement settings can cause false certification of high-dimensional entanglement from completely separable (product) states. This invalidates the commonly accepted fidelity-based assumptions and reveals a fundamental weakness in device-dependent entanglement tests. The authors construct explicit perturbations of measurement bases that, while remaining extremely close in average fidelity (errors as low as 0.23%), can fake entanglement dimensionalities as high as 26 in a 61-dimensional photonic system. The findings highlight increasing risk of false positives as system dimensionality grows, exposing a key security and reliability gap in current quantum verification and related quantum communication protocols.
Key findings
- Measurement deviations bounded by average fidelity error ε as small as 0.7% can falsely certify up to Schmidt number K = 47 entanglement in d = 61 dimensions (Fig. 1b).
- Experimentally, a product state encoded in spatial modes with ε = 0.7% measurement perturbations yields witness Wd = 1.36 ± 0.03, falsely certifying K = 11 dimensional entanglement at d = 31 (Fig. 3a).
- Experimentally verified false certifiable entanglement dimensionality reached K = 26 at d = 61 with the same perturbation level (Fig. 3b).
- Intrinsic experimental crosstalk ratios measured between 1:700 to 1:760, which, while reducing measured witness values, are still exceeded by the ε-perturbation attack.
- The perturbed measurement bases produce joint probability distributions nearly indistinguishable from those of a maximally entangled state.
- Three different fidelity error models (average, worst-case, and outcome-wise) all confirm the fundamental vulnerability of device-dependent entanglement witnesses to small perturbations.
- The attack saturates the known theoretical bounds making it effectively optimal for faking entanglement with minimal measurement deviations.
Threat model
The adversary is assumed capable of introducing small, adversarial deviations limited by fidelity error ε into the measurement devices used by the legitimate quantum parties (Alice and Bob). The adversary cannot modify the quantum state, which is prepared as a separable product state. The attacker aims to manipulate measurement bases to produce correlations that pass entanglement witness thresholds despite no real entanglement. The adversary cannot circumvent fundamental quantum measurement constraints or introduce large noise that would raise suspicion.
Methodology — deep read
Threat model and assumptions: The adversary is assumed to have control to introduce small adversarial deviations (perturbations) to the measurement apparatus, limited by an infidelity error parameter ε, but cannot alter the true quantum state, which is separable (product state). The analysis assumes device-dependent entanglement certification using fixed measurement bases, with no device independence assumptions. The adversary leverages small measurement imperfections systematically to fake entanglement.
Data and experimental setup: The experiments use classical photonic states generated from attenuated pulsed lasers at 780 nm, encoding product states into pairs of photons over spatial macro-pixel modes defining a d-dimensional Hilbert space (up to d=61). Measurement bases (computational and Fourier/MUB) are implemented with spatial light modulators (SLMs) and single-mode fibers (SMFs), detecting via single-photon avalanche diodes (SPADs). Crosstalk and other noise sources are characterized to quantify intrinsic imperfections.
Algorithm and attack construction: The authors explicitly construct perturbed measurement bases {|ϕ_k⟩} that differ from target computational bases by an ε-bounded average fidelity perturbation. These perturbations are carefully designed linear superpositions with coefficients (α, β, γ, δ) dependent on dimension and ε (detailed in Supplementary Information). The Fourier basis perturbations are derived as unitary transformations of these perturbed bases. When applied by Alice and Bob to a separable product state |ψ⟩⊗|ψ⟩, this yields elevated entanglement witness values W_d beyond ideal theoretical upper bounds for separable states, falsely certifying entanglement.
Training and measurement regime: While no machine learning training is involved, the experimental measurements are performed sequentially for each projector in the measurement basis using holographic modulation and optical detection. Measurement fidelity and crosstalk are experimentally quantified, and perturbations are implemented by altering the hologram patterns on the SLMs.
Evaluation protocol: The main metric is the entanglement witness W_d computed as the sum of correlations in the computational and Fourier bases, compared to theoretical separable thresholds 1 + K/d for various Schmidt numbers K. Benchmarks compare witness values from ideal measurements (ε=0), perturbed measurements, and intrinsic experimental noise. False positives occur when W_d exceeds separable bounds under perturbations.
Reproducibility: The authors provide detailed methods including mathematical constructions, experimental schematics, and supplementary information. While no public code or dataset release is mentioned, the experimental setup and perturbation models are described in sufficient technical detail for reproduction by quantum optics labs.
Example end-to-end (d=31): Start with a known separable product state in the macro-pixel basis. Implement the ideal and ε=0.7% perturbed measurement bases via SLM holograms. Perform sequential projections and detect coincidences with SPADs. Calculate W_d witness from measurement correlations. Observe W_d = 1.36 ± 0.03, which falsely certifies entanglement with Schmidt number K=11, despite separability of input state.
Technical innovations
- Explicit construction of ε-bounded perturbations to computational and Fourier measurement bases that optimally maximize entanglement witness values for product states.
- Demonstration that minimal measurement deviations (≈0.23% fidelity loss) suffice to fake high-dimensional entanglement up to maximal Schmidt number d.
- Systematic experimental realization using spatial mode encoding and SLM-based adaptive measurement to validate theoretical attacks across multiple dimensions up to 61.
- Extension and analysis across three distinct measurement error models (average, worst-case, and outcome-wise fidelity) confirming generality of the vulnerability.
- Incorporation of intrinsic experimental crosstalk into fidelity bounds and witness calculations, establishing realistic attack applicability.
Datasets
- Spatial macro-pixel photonic states — up to 61 dimensions — generated by attenuated pulsed laser and modulated with spatial light modulators (not publicly available)
Baselines vs proposed
- Ideal (ε=0) measurement: W_d = max allowed for separable states = 1 + 1/d vs attack with ε=0.7%: W_d up to match maximally entangled states (theoretical maximum of 2).
- Measured witness at d=31: ideal model W_d ~1.4 for ε=0.7% perturbation vs experimental W_d = 1.36 ± 0.03.
- Measured witness at d=61: ideal model W_d higher than experimental due to crosstalk; experimental W_d still exceeds separable threshold, falsely certifying K=26 dimensional entanglement.
Figures from the paper
Figures are reproduced from the source paper for academic discussion. Original copyright: the paper authors. See arXiv:2606.20396.

Fig 2: Illustrative schematic of the experimental setup employing the macro-pixel

Fig 1: Falsely verified Schmidt number K

Fig 3: Experimental results for the average fidelity model. a) scaling of the entan-

Fig 4 (page 6).

Fig 5 (page 6).

Fig 6 (page 6).

Fig 7 (page 6).

Fig 8 (page 34).
Limitations
- Experimental realization constrained to sequential projective measurements rather than full multi-outcome POVMs, potentially limiting perturbation complexity.
- Sampled perturbations and dimensions up to 61—scalability and practical feasibility beyond this remain untested experimentally.
- No adversarial or active quantum attacker tested beyond passive measurement deviations; real-world adversaries may have other capabilities.
- Assumes access to trusted quantum states (separable); does not address multipartite entanglement or more general quantum network scenarios.
- No publicly released code or datasets to verify the exact perturbation parameters and experimental control.
Open questions / follow-ons
- How can entanglement certification protocols be devised to remain robust against bounded yet adversarial measurement deviations, possibly leveraging device independence or self-testing approaches?
- Can similar adversarial attacks be constructed and defended against in multipartite or networked quantum entanglement scenarios?
- What are the implications of these vulnerabilities for security claims and threshold tolerances in quantum key distribution and related protocols?
- How can real-time device characterization or adaptive measurement calibration be integrated to mitigate adversarial basis perturbations?
Why it matters for bot defense
For bot-defense and CAPTCHA research practitioners concerned with robust verification under adversarial conditions, this work serves as a cautionary example of how small, imperceptible deviations in system components can fundamentally undermine trustworthiness of high-dimensional certification tests—in this case, entanglement verification. Analogously, bot detection systems relying on idealized or fixed measurement assumptions may be vulnerable to subtle manipulation that produces false positives or negatives. The paper highlights the importance of designing verification schemes that explicitly account for bounded but malicious deviations in measurement or observation processes, and the value of device-independent or error-robust certification techniques. Practitioners should consider incorporating adversarial robustness into their test designs, validation protocols, and anomaly detection thresholds to prevent attackers from exploiting small discrepancies that are otherwise considered negligible.
Cite
@article{arxiv2606_20396,
title={ Faking entanglement with imperceptible measurement deviations },
author={ Jaime Moreno and Elna Svegborn and Simon Morelli and Markus Hiekkamäaki and Lea Kopf and Robert Fickler and Armin Tavakoli },
journal={arXiv preprint arXiv:2606.20396},
year={ 2026 },
url={https://arxiv.org/abs/2606.20396}
}