Pillar C · State as of 2026-08-28

Does IBM's doped Clifford claim survive the classical counterattack?

Neither refuted nor intact. On August 13, 2026 — day 14 of the claim — Manabe, Gu & Pan computed exact amplitudes for all 2,051 of IBM's published bitstring batches in 37.3 minutes on 256 GPUs, and instead of tearing the experiment down, independently confirmed its fidelity bound (log-XEB 0.35 vs. the certified ≥0.284). What weakened is the hardness half: the instance's quasi-1D geometry admits cheap amplitude computation, and the largest tensor came in 256× below IBM's estimate. The sampling task itself has not been reproduced classically. Status as of 2026-08-28: standing, narrower.
→ Leer en español
State as of: 2026-08-28

Status as of: August 28, 2026.

Neither refuted nor intact. On August 13 — day 14 of the claim — Manabe, Gu & Pan computed exact amplitudes for all 2,051 of IBM's published bitstring batches in 37.3 minutes on 256 GPUs, and instead of tearing the experiment down, they independently confirmed its fidelity bound: their log-XEB estimate of 0.35 sits above IBM's certified ≥0.284. What weakened is the other half of the claim — classical hardness: the instance's quasi-one-dimensional geometry admits cheap amplitude computation, and the largest tensor came in 256× below IBM's estimate. Nobody has classically reproduced the sampling task itself. The claim stands, narrower than published.

This is the follow-up our credibility-checklist post left open on August 25: the counterattack had landed, and the question was what it actually showed. Here is the answer at day 15 of the counterattack, component by component.

What exactly did IBM claim?

The paper (Martiel et al., arXiv:2607.25941, posted July 28; announced by IBM on July 30) reports sampling from "doped Clifford" circuits — a Clifford scaffolding doped with 468 T gates — encoded in an error-detecting code: 70 logical qubits on 97 physical qubits at depth 70, with roughly 10× gate-error suppression from the encoding. The structural point of the construction is that fidelity becomes certifiable from the circuit structure and measured code syndromes: the paper certifies a fidelity lower bound of 0.284 at 95% confidence.

Read as a claim, it has two halves. Half one: the experiment ran at verifiably high fidelity — the certified 0.284 was the strongest quantitative bound of the three July claims, which is why our checklist post scored it as the strongest answer to "is there a quantitative error bound?" in the field. Half two: the sampled distribution is beyond practical classical reach — the hardness half, resting on a classical cost estimate.

Keeping the halves separate is not pedantry. As of August 28, they have opposite trajectories.

ONE CLAIM, TWO HALVES VERIFICATION fidelity ≥ 0.284 (95%) certified via code syndromes the attack's own estimate: log-XEB 0.35 [0.30–0.40] above the bound INDEPENDENTLY CONFIRMED CLASSICAL HARDNESS "beyond practical reach" of classical simulation 2,051 batches → 37.3 min largest tensor: 256 GiB 256× below IBM's estimate NARROWED (SAMPLING UNTESTED) the same attack confirmed the measurement and cheapened the difficulty — both at once

What did the counterattack actually do?

Manabe, Gu & Pan (arXiv:2608.13110, August 13) built a deterministic transverse tensor-network contraction for quasi-1D brickwork circuits: for an n-qubit circuit of depth d, exact amplitudes at contraction width ⌈d/2⌉. Two structural facts do the work. The instance has open quasi-one-dimensional geometry, and its entangling gates have operator Schmidt rank 2 — which together admit a low-width contraction. And in their method, the number and placement of T gates does not change the cost at all: the "doping" that names the experiment is free for this attack.

The result: all 2,051 amplitude batches corresponding to IBM's published output bitstrings, computed exactly in 37.3 minutes on 32 nodes of 8 NVIDIA H100 GPUs each. The largest intermediate tensor needed 256 GiB — in their words, 256 times smaller than IBM's estimation. From those exact amplitudes they computed a log-XEB estimate of 0.35034, 95% CI [0.298, 0.403], which they call "numerically compatible with IBM's independently reported fidelity lower bound."

What they did not do matters just as much: they did not sample. Computing the probability of bitstrings a quantum device already produced is a different task from producing samples with matching fidelity — and for this circuit family, nobody has publicly done the second. Their own framing is explicit: the method is "a practical diagnostic for experimental outputs and a quantitative tool for designing future doped Clifford sampling experiments." That is not the language of a refutation, and we read it at face value.

Diagnosis or refutation? Run it through the tree

Our reader's checklist asks five questions in order; this episode is the fourth and fifth interacting in real time. The fourth question — is there a quantitative error bound? — was where IBM's claim was strongest, and the counterattack made it stronger: the best independent evidence to date that IBM's device did what IBM said it did is the classical attack on it. That sentence is strange, and it is the most citable fact of the episode.

The fifth question — how long does the claim survive contact with classical methods? — is where the damage landed, and it landed on the estimate, not the experiment. The hardness half rested on a classical cost projection that did not anticipate a transverse contraction exploiting the open geometry and rank-2 entanglers. That projection was off by 256× on tensor memory for this instance. This is the weak-baseline lesson in a new coat: the classical side of any advantage claim is a moving baseline, and the estimate you publish is a snapshot of the methods you knew.

None of this is an accusation. IBM's cost estimate was made against the methods known at publication, the bitstrings were published precisely so that others could attack them, and the attack's authors chose measured, non-triumphalist language. This is the system working as designed — in public, on artifacts, in 14 days.

The claim, component by component

Component IBM published (Jul 28) Counterattack showed (Aug 13) Status at Aug 28 Source
Fidelity lower bound 0.284 at 95%, certified via syndromes log-XEB 0.35 [0.30–0.40] from exact amplitudes — compatible, above the bound confirmed independently arXiv:2607.25941 · arXiv:2608.13110
Amplitude hardness large classical cost estimated width-⌈d/2⌉ contraction; 2,051 batches in 37.3 min; max tensor 256 GiB (256× below estimate) narrowed for this geometry arXiv:2608.13110
Sampling hardness the claimed task not attempted — amplitudes ≠ samples open, untested arXiv:2608.13110
Next instances fixed published instance simulatability map: periodic boundaries, rank-4 entanglers, more depth escape the method design space mapped arXiv:2608.13110 §6 · arXiv:2608.15963

What happens next?

31 DAYS OF A CLAIM JUL 28 arXiv v1: 70 logical / 97 physical qubits 468 T gates · certified bound 0.284 JUL 30 IBM announces: "trusted quantum advantage" — beyond classical reach AUG 13 day 14: exact amplitudes of all 2,051 batches — 37.3 min on 256 H100s log-XEB 0.35 → bound CONFIRMED AUG 16 design moves: Clifford obfuscation proposal (arXiv:2608.15963) AUG 28 day 15 of the counterattack: no IBM response found — still open turquoise = new measurement · gold = claim or silence

The counterattack's most constructive section is a classical-simulatability map: the features that would put a next-generation instance beyond the transverse contraction are concrete — periodic boundary conditions instead of open ones, entangling gates of operator Schmidt rank 4 instead of 2, more depth (their width scales with ⌈d/2⌉, so cost grows exponentially in depth). The next doped Clifford experiment can be designed outside the map, and the map's authors published it so that it would be.

The design conversation is already moving: on August 16, three days after the counterattack, a separate proposal (Yan, arXiv:2608.15963) suggested hiding the Clifford structure itself via obfuscation, injecting non-stabilizer resources against exactly the reverse-engineering and direct-simulation strategies this episode showcased.

From IBM: as of August 28 we found no v2 of the paper and no public response to the counterattack — 15 days after it posted. Absence of response is not concession, and 15 days is short; our checklist's own rule applies to both sides: "open" is a state, not a verdict. The whole episode, note, ran on published artifacts — IBM released the bitstrings that were attacked. That is radical reproducibility doing precisely its job, at day 14 instead of the months it took for earlier claims.

What we know / what we don't know

What we know, with sources: the fidelity bound is now independently confirmed by the attackers' exact amplitudes (arXiv:2608.13110 vs. arXiv:2607.25941); amplitudes of all published outputs are computable in 37.3 minutes on 256 H100s; IBM's tensor-memory estimate was 256× high for this instance's geometry; no classical samples of matching fidelity have been produced; and no IBM response had appeared by August 28.

What we don't know: whether the sampling task itself — not amplitude evaluation — is classically matchable for this circuit family, which is the technical question the debate now hangs on; whether the log-XEB-to-fidelity translation holds exactly, since it leans on Porter–Thomas and scrambled-noise assumptions both sides share; whether IBM answers with a rebuttal or with a next-generation instance built outside the simulatability map; and whether the Quantum Advantage Tracker formally adjudicates this episode — we found no adjudication either way at close. Our day counts are direct arithmetic on the cited posting dates; we have no measurements of our own in this problem class and claim none.

Rosetta Q publishes verdicts with raw, reproducible data. This is educational content, not a product claim.

Sources:
· Martiel et al., "Sampling hard circuits with verifiably high fidelity" (arXiv:2607.25941, Jul 28, 2026)
· IBM Quantum blog, "Quantum advantage through trusted quantum computation" (Jul 30, 2026)
· Manabe, Gu & Pan, "Classical Simulation and Design Frontiers for IBM's Doped Clifford Sampling Experiment" (arXiv:2608.13110, Aug 13, 2026)
· Yan, "Classical Verification of Quantum Advantage via Clifford Obfuscation" (arXiv:2608.15963, Aug 16, 2026)
· PostQuantum, "IBM's Three Quantum Advantage Claims, Fact-Checked" (Aug 1, 2026)
· IBM Quantum blog, "Quantum Advantage Tracker: the race to advantage" (Feb 23, 2026)
· Quantum Computing Report, "IBM and Ecosystem Partners Demonstrate 'Trusted Quantum Advantage'" (Jul 2026)