# Simon's problem

(Redirected from Simon's algorithm)

In computational complexity theory and quantum computing, Simon's problem is a computational problem conceived to showcase the efficiency increase a quantum algorithm could have over a classic one. Although the problem itself is of little practical value, it is interesting because it provides an exponential speedup over any classical algorithm (in a black box model).[1]

The problem deals with the model of decision tree complexity or query complexity and was conceived by Daniel Simon in 1994.[2] Simon exhibited a quantum algorithm, usually called Simon's algorithm, that solves the problem exponentially faster than any deterministic or probabilistic classical algorithm, requiring exponentially less computational power than the best classical probabilistic algorithm.

This problem yields an oracle separation between BPP and BQP, unlike the separation provided by the Deutsch-Jozsa algorithm, which separates P and EQP.

Simon's algorithm was also the inspiration for Shor's algorithm. Both problems are special cases of the abelian hidden subgroup problem, which is now known to have efficient quantum algorithms.

## Problem description and algorithm

The input to the problem is a function (implemented by a black box) ${\displaystyle f:\{0,1\}^{n}\rightarrow \{0,1\}^{n}}$, promised to satisfy the property that for some ${\displaystyle s\in \{0,1\}^{n}}$ we have for all ${\displaystyle y,z\in \{0,1\}^{n}}$, ${\displaystyle f(y)=f(z)}$ if and only if ${\displaystyle y=z}$ or ${\displaystyle y\oplus z=s}$. Note that the case of ${\displaystyle s=0^{n}}$ is allowed, and corresponds to ${\displaystyle f}$ being a permutation. The problem then is to find ${\displaystyle s}$.

The set of n-bit strings is a ${\displaystyle \mathbb {Z} _{2}}$ vector space under bitwise XOR. Given the promise, the preimage of f is either empty, or forms cosets with n-1 dimensions. Using quantum algorithms, we can, with arbitrarily high probability determine the basis vectors spanning this n-1 subspace since s is a vector orthogonal to all of the basis vectors.

Quantum subroutine in Simon's algorithm

Consider the Hilbert space consisting of the tensor product of the Hilbert space of input strings, and output strings. Using Hadamard operations, we can prepare the initial state

${\displaystyle \sum _{x}\left|x\right\rangle \left|0\right\rangle }$

and then call the oracle to transform this state to

${\displaystyle \sum _{x}\left|x\right\rangle \left|f(x)\right\rangle }$

Hadamard transforms convert this state to

${\displaystyle \sum _{y}\sum _{x}(-1)^{x.y}\left|y\right\rangle \left|f(x)\right\rangle }$

We perform a simultaneous measurement of both registers. If ${\displaystyle s\cdot y=1}$, we have destructive interference. So, only the subspace ${\displaystyle s\cdot y=0}$ is picked out. Given enough samples of y, we can figure out the n-1 basis vectors, and compute s.

## Complexity

Simon's algorithm requires ${\displaystyle O(n)}$ queries to the black box, whereas a classical algorithm would need at least ${\displaystyle \Omega (2^{n/2})}$ queries. It is also known that Simon's algorithm is optimal in the sense that any quantum algorithm to solve this problem requires ${\displaystyle \Omega (n)}$ queries.[3][4]