Submitted:
21 August 2026
Posted:
24 August 2026
You are already at the latest version
Abstract
Auditing a firewall as a black box means learning, from accept/deny answers alone, whether a device implements the intended policy. A companion paper showed this is inherently expensive classically: a hidden rule in a header space of size N = 2^104 forces N − 1 queries, while structured tree-rule and disjoint listed-rule policies are learned with Θ(m log W) queries (m rules, field width W). We ask what changes when the auditor is quantum. If the firewall records which rule it hit (a hit counter), every quantum advantage vanishes: the counter is a projective measurement of the query register. Quantum queries do not help on structure: localising a tree-rule or disjoint listed-rule policy still needs Ω(m log W) queries, by a direct-sum theorem for the adversary bound over m independent ordered searches. On overlapping listed-rule policies, a hidden-corner family shows that re-localising one rule whose corner lies on an antichain of width n, the other rules being known, costs Ω(n) classically and Θ(√n) quantumly against O(log W) for a tree boundary: in incremental audits, overlap can be exponentially more expensive than tree structure. Only unstructured tasks keep the Grover square root (Θ(√N) hidden rule, Θ(√(N/M)) witness, Θ(√m) certificate replay). Simulations with real policies compiled into quantum oracles confirm the constants.

Keywords:
firewall verification
; black-box testing
; quantum query complexity
; Grover search
; adversary method
; direct-sum theorem
; tree-rule firewall
; hit counter
; measurement
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.