Preprint
Article

This version is not peer-reviewed.

A Hybrid Quantum–Classical Algorithm for k-SAT via Grover-Enhanced Local Search

Submitted:

16 September 2026

Posted:

16 September 2026

You are already at the latest version

Abstract
The \(k\)-SAT problem is a canonical NP-complete problem for which no efficient algorithm is known. This paper proposes a hybrid quantum–classical algorithm that employs Grover's algorithm as the inner local search of a randomized outer loop. Each outer iteration measures a random assignment, prepares a problem-dependent superposition over the Hamming ball of radius \(r\) around it, and applies amplitude amplification to locate a satisfying assignment. Because the ball center is measured, the outer loop remains a classical repetition over independently sampled balls and contributes the inverse success probability rather than its square root; balancing this against the inner quadratic speedup shifts the optimal radius from \(n/(k+1)\) to \(n/(1+\sqrt{k})\) and yields the running time $(2-2/(1+\sqrt{k}))^{n}$, up to polynomial factors—\(1.268^{n}\) for \(k=3\), below the best known classical \(1.307^{n}\). The contribution is not an asymptotic record—the best known quantum exponents for \(k\)-SAT, obtained by amplifying stronger classical solvers as black boxes, remain smaller—but a fully explicit, gate-level construction: the problem-dependent state over the Hamming ball and the \(k\)-SAT oracle are decomposed into elementary quantum gates, and the polynomial gate and qubit overheads are accounted for in full.
Keywords: 
;  ;  ;  ;  ;  ;  

1. Introduction

The k-SAT problem ( k ≥ 3 ) is a canonical NP-complete problem [1], and no polynomial-time algorithm for it is known. Classical algorithms for k-SAT fall broadly into two categories: deterministic and probabilistic. Deterministic approaches typically rely on divide-and-conquer, exhaustive search, or backtracking, while probabilistic methods often employ local search heuristics. The worst-case time complexity of state-of-the-art algorithms in both categories is generally O ( α n ) , where n is the number of Boolean variables and α > 1 is a constant base. Since a smaller α implies lower computational complexity, much research [2,3,4] has focused on minimizing this exponential base.
On the probabilistic side, Paturi, Pudlák, and Zane [2] introduced the PPZ algorithm in 1997, achieving a randomized upper bound significantly below 2 n . Schöning [3] subsequently proposed a simple local search algorithm with expected running time ( 2 ( 1 − 1 / k ) ) n , yielding O ( ( 4 / 3 ) n ) , which improved upon the earlier PPZ bound of Ref. [2]. Hofmeister et al. [5] later refined Schöning’s approach, reducing the 3-SAT complexity to O ( 1 . 3302 n ) . Meanwhile, Paturi et al. [6] enhanced the original PPZ framework into the PPSZ algorithm, achieving O ( 1 . 308 n ) for unique 3-SAT (the variant with exactly one satisfying assignment). Hertli [7] subsequently extended this analysis, proving that the PPSZ bound under the uniqueness assumption applies equally to general 3-SAT. More recently, Hansen et al. [8] introduced a biased variant of PPSZ, further improving the unique 3-SAT bound to O ( 1 . 307 n ) .
Parallel to these randomized advances, significant effort has been devoted to derandomization and deterministic algorithm design. Dantsin et al. [9] showed how to simulate Schöning’s random walk deterministically, at the price of a mildly larger base: their Hamming-ball local search runs in time O ( ( 2 − 2 / ( k + 1 ) ) n ) , i.e., 1 . 5 n for k = 3 . For 3-SAT specifically, they introduced a tailored local search strategy that further reduced the bound to O ( ( 1.481 ) n ) . Moser and Scheder [10] later completed the full derandomization of Schöning’s algorithm using limited independence. Brueggemann and Kern [4] refined the local search strategy of Dantsin et al., reducing the 3-SAT complexity to O ( 1 . 473 n ) . Scheder [11] further improved this bound to O ( 1 . 465 n ) . To the best of our knowledge, the current best deterministic algorithm for 3-SAT remains that of Kutzkov and Scheder [12], achieving O ( 1 . 439 n ) . Despite over a decade of effort, no improvement has been found, highlighting the need for fundamentally new paradigms.
Quantum algorithms have demonstrated advantages over classical counterparts in several computational tasks, including integer factorization, unstructured search, and search on graphs [13,14,15], and they are by now a standard tool in application areas such as machine learning and combinatorial optimization [16,17,18]. Motivated by these developments, we investigate the application of quantum computation to the k-SAT problem. Prior quantum approaches to k-SAT largely accelerate an existing classical solver while keeping its structure inside a black-box oracle. Grover’s algorithm alone yields O ( 2 n / 2 ) = O ( 1 . 414 n ) [14]. Combining Grover search with the then best classical 3-SAT algorithm ( O ( 1 . 3302 n ) [5]) lowers the exponent to O ( 1 . 153 n ) [19], and applying amplitude amplification [20] to the PPSZ algorithm [6,7,8] gives O ( 1 . 143 n ) for 3-SAT. These are, to our knowledge, the strongest known exponents for worst-case k-SAT in the gate model. Inspired by the classical algorithm in [3], we propose a hybrid quantum-classical algorithm that employs Grover’s algorithm as a local search subroutine for solving k-SAT. The proposed algorithm is a hybrid quantum-classical procedure: its outer loop classically samples local search spaces, while its inner loop performs quantum search. It proceeds in t outer iterations. In each iteration, a problem-dependent superposition state is constructed over a local search space—specifically, a Hamming ball of radius r centered at a randomly generated assignment—by exploiting the problem structure. Grover’s algorithm is then applied to this state in its amplitude-amplification form—the number of solutions inside a ball is not known in advance, so the exponential-search variant is used—to search for a satisfying assignment. Because the outer loop is a classical repetition over independently sampled balls, the number of outer iterations is governed by the classical success probability, and the resulting running time is ( 2 − 2 / ( 1 + k ) ) n (with the optimal radius r = n / ( 1 + k ) ), which improves upon the classical local-search bounds for k-SAT [3,9] and, at k = 3 , upon the best known classical algorithm [8] ( 1 . 268 n versus 1 . 307 n ; see Section 3.6 for the general-k comparison). These gains are over classical solvers: black-box amplification of a stronger classical solver yields smaller quantum exponents [6,8,19,20].
The contributions of this work can be summarized as follows.
  • An explicit, gate-level construction. Both the problem-dependent superposition over the Hamming ball and the k-SAT oracle are decomposed into elementary gates, so that no black-box oracle is left in the complexity and the polynomial overhead is fixed at O ( n m k ) gates in total.
  • A hybrid framework with a re-optimized ball radius. Because the center of each ball is measured, the outer loop is a classical repetition over independently sampled balls and contributes the inverse success probability rather than its square root; balancing this factor against the quadratic speedup of the inner search shifts the optimal radius from the classical r = n / ( k + 1 ) to r = n / ( 1 + k ) , so that the classical repetition does not simply reproduce the classical Hamming-ball exponent.
  • A complete accounting and a numerical verification. The qubit and gate costs of the whole construction are counted, and the two bounds on which the exponent rests—the success probability of a ball and the marked amplitude of the constructed state—are checked numerically for k = 3 on small planted instances (Section 4).
The remainder of this paper is organized as follows. Section 2 introduces the k-SAT problem, defines quantum analogues of the three fundamental classical logic gates involved, and reviews Grover’s algorithm. Section 3 presents the proposed algorithm, beginning with an overview of the framework, followed by the construction of the problem-dependent state and the decomposition of the Grover oracle for k-SAT into elementary quantum gates. The section concludes with an analysis of the algorithm’s feasibility and time complexity and with a comparison against prior quantum algorithms. Section 4 reports the numerical verification of the two bounds entering the exponent; Section 5 offers concluding remarks, and the Appendix details the gate-level implementation of the conditional neighborhood expansion.

2. Preliminaries

2.1. Definition of the k-SAT Problem

The k-SAT problem in conjunctive normal form (CNF) is defined as follows. Let X = { x 1 , x 2 , … , x n } be a finite set of n Boolean variables, and let C = { c 1 , c 2 , … , c m } be a set of m clauses. Each clause is given by c i = l i , 1 ∨ l i , 2 ∨ … ∨ l i , k , where each l i , j ∈ { x p , ¬ x p ∣ 1 ≤ p ≤ n } is called a literal; for simplicity, the k literals of a clause are assumed to involve k distinct variables, so that no clause contains both x p and ¬ x p . This is the case considered throughout, and it is what makes the k branches generated by F c i [Equation (5)] distinct. The k-SAT problem asks whether there exists an assignment a = { a 1 , a 2 , … , a n } , such that the formula  F = c 1 ∧ c 2 ∧ … ∧ c m is satisfied. If F is satisfied by a, then a is called a satisfying assignment of F .
Note that for fixed n and m, each distinct set of clauses defines a unique instance of the k-SAT problem. Throughout, m is taken to be polynomially bounded in n, so that the clause count contributes only a polynomial factor to all running times reported below. In classical computation, a Boolean variable takes a binary value of either 0 (false) or 1 (true), and logical operations act on one or more such variables. By analogy, a quantum truth value can be defined as a superposition of the basis states 0 and 1. A quantum logical variable assumes such a quantum truth value and is naturally represented by a qubit, whose state encodes this value. Consequently, a quantum logical operation is defined as a quantum gate acting on one or more qubits, transforming their joint quantum state.
The k-SAT problem involves n Boolean variables, each taking a value in { 0 , 1 } . Consequently, there are 2 n possible assignments, which constitute the search space H n = { 0 , 1 } n . Each assignment a = { a 1 , a 2 , … , a n } can be encoded as a computational basis state a = a 1 a 2 … a n , where a i ∈ { 0 , 1 } . In the remainder of this paper, we identify each classical assignment with its corresponding computational basis state.

2.2. Quantum Realizations of Logic Gates: NOT, AND, and OR

As shown above, the k-SAT problem is built upon three basic logical operations: AND (∧), OR (∨), and NOT (¬). Their quantum analogues, denoted as QAND , QOR , and QNOT , are defined as follows.
The classical NOT operation maps 0 ↦ 1 and 1 ↦ 0 . Its quantum analogue, QNOT , is defined by its action on the computational basis:
QNOT x = ¬ x , x ∈ { 0 , 1 } .
This operator is equivalent to the single-qubit Pauli-X gate, which flips 0 ↔ 1 .
The classical AND gate ( x 1 ∧ x 2 ) embeds into a reversible three-qubit operator QAND :
QAND x 1 , x 2 , x 3 = x 1 , x 2 , x 3 ⊕ ( x 1 ∧ x 2 ) .
This is precisely the Toffoli gate, which applies a bit-flip to the third qubit if and only if the first two qubits are both 1.
The classical OR operation acts on two Boolean variables, yielding 0 if and only if both inputs are 0. Its reversible quantum analogue, QOR , is defined on three qubits as:
QOR x 1 , x 2 , x 3 = x 1 , x 2 , x 3 ⊕ ( x 1 ∨ x 2 ) ,
where ⊕ denotes addition modulo 2. This operation flips the target qubit x 3 conditioned on at least one of the control qubits x 1 or x 2 being 1. The QOR gate can be implemented via QNOT and QAND . Specifically, one applies QNOT to each of the first two qubits, then QAND to all three qubits, and finally QNOT to each of the three qubits.

2.3. Grover’s Algorithm

In Grover’s algorithm, the Grover iteration is applied O N / M times to the system state, where N = 2 n is the search space size (n being the number of qubits) and M is the number of solutions. The qubits are then measured in the computational basis, which returns a solution with probability Ω ( 1 ) ; repeating the whole procedure O ( log ( 1 / δ ) ) times raises the success probability to at least 1 − δ .
The Grover iteration consists of the following four steps:
  • Apply the oracle O: x ↦ ( − 1 ) f ( x ) x , where f ( x ) = 1 if x is a solution and f ( x ) = 0 otherwise. This marks the solution states by flipping their phases.
  • Apply the Hadamard transform H ⊗ n .
  • Apply the diffusion operator D 0 = 2 ⟩ ⟨ 0 0 − I , which reflects the state about |0⟩ (equivalently, flips the phase of all non-zero computational basis states).
  • Apply the Hadamard transform H ⊗ n .
Using the identity H ⊗ n ( 2 ⟩ ⟨ 0 0 − I ) H ⊗ n = 2 ψ ψ − I , where ψ = H ⊗ n 0 is the equal superposition state, the Grover iteration simplifies to
G = ( 2 ψ ψ − I ) O ,
where O is the oracle defined in Step 1.
If an oracle is available that marks the solution states of a given problem, Grover’s algorithm can solve it without exploiting additional problem-specific structure beyond the oracle itself. In particular, for the k-SAT problem, assuming such an oracle exists and the instance has a unique solution ( M = 1 ), Grover’s algorithm achieves a time complexity of O ( 2 n ) ≈ O ( 1 . 414 n ) . This provides a quadratic speedup over exhaustive classical search and outperforms the best known classical deterministic algorithms for k-SAT, though it remains slower than state-of-the-art probabilistic solvers. Nevertheless, incorporating problem structure into the quantum algorithm can further reduce the complexity, as demonstrated in the subsequent analysis.

3. The Proposed Algorithm

3.1. Algorithm Framework

The proposed algorithm is a hybrid quantum-classical procedure whose outer loop performs t classically repeated iterations, each consisting of the following three steps:
  • Random assignment generation. Prepare the uniform superposition state by applying H ⊗ n to n qubits initialized in 0 ⊗ n , then measure all qubits in the computational basis to obtain a random assignment a ∈ H n .
  • Subspace state preparation. Construct a problem-dependent quantum state ψ a starting from the randomly generated assignment a.
  • Grover search within subspace. Apply Grover’s algorithm to ψ a to search for a solution to the k-SAT instance.

3.2. Construction of the Problem-Dependent State

The problem-dependent state ψ a is constructed by applying the following two procedures iteratively r times, starting from the randomly generated assignment a; throughout this section, ψ a denotes the state of the round being considered.
  • Clause evaluation (E). This procedure computes the quantum truth value of each clause in the k-SAT instance. For a clause c i = l i , 1 ∨ l i , 2 ∨ … ∨ l i , k , we introduce ( k − 1 ) auxiliary qubits α i , 1 , … , α i , k − 1 , all initialized to 0. Let l i , j denote the qubit corresponding to literal l i , j . The quantum OR operation ( QOR ) is applied sequentially: first to l i , 1 , l i , 2 , and α i , 1 ; then to l i , 3 , α i , 1 , and α i , 2 ; and so on, until finally to l i , k , α i , k − 2 , and α i , k − 1 . The final result is stored in α i , k − 1 . Across all m clauses, this requires m ( k − 1 ) auxiliary qubits, with the truth values of clauses c 1 , … , c m stored in α 1 , k − 1 , … , α m , k − 1 , respectively.
    The full clause-evaluation operator is defined as
    E = QOR c m QOR c m − 1 … QOR c 1 ,
    where QOR c i denotes the sequence of ( k − 1 ) QOR gates applied to clause c i , as described above. After applying E, the state of the current round becomes entangled with each clause register α i , k − 1 as
    ψ a , α i , k − 1 = ψ a c i , 0 , 0 + ψ a c i , 1 , 1 ,
    where ψ a c i , 0 and ψ a c i , 1 are the (unnormalized) components of that state supported on the subspaces in which clause c i evaluates to false and true, respectively.
  • Conditional neighborhood expansion (F). This procedure applies a conditional transformation to each computational basis state in the superposition ψ a , expanding the neighborhood of one unsatisfied clause. Let i ( a ) = min { i ∣ c i is false under a } be the index of the first clause that is false under a, and let C i ( · ) denote conditioning on the clause-register pattern in which clauses c 1 , … , c i − 1 are true and clause c i is false, i.e., the multiply-controlled unitary that acts as the identity unless the clause registers α 1 , k − 1 , … , α m , k − 1 hold that pattern and that applies the operation in its argument whenever they do. The conditional expansion operator is defined as the product of these controlled unitaries,
    F = ∏ i = 1 m C i F c i ,
    where F c i is the expansion operator associated with clause c i . The m control patterns are mutually exclusive—no assignment can have two first-false clauses—and the expansion F c i changes only the assignment and label registers, so the clause registers are left untouched while a factor acts and, on any computational basis state, at most one factor of Equation (3) differs from the identity; the factors therefore commute. Equivalently, on a basis state of the clause registers F reduces to the direct sum of the unitaries F c 1 , … , F c m , one summand for each sector in which clause c i is the first clause that is false, together with the identity on the sector in which all clauses are true: an individual summand is only a partial isometry, and it is the completeness of the mutually exclusive sectors that makes the operator F unitary. Each factor is a controlled unitary, and hence unitary, by construction, and so is their product. On a computational basis state whose clause registers hold the values ( η 1 , … , η m ) , exactly one sector is selected—the expansion of the first clause that is false, i.e., of clause c i ( a ) —whereas if a satisfies every clause no expansion takes place, in which case F acts as the identity on the assignment and label registers. Thus F performs a single k-way branching per round instead of a simultaneous expansion of all m clauses. This mirrors the branching step of a classical local search, in which a single unsatisfied clause is selected and each of its k literals is tried in turn; applying instead the expansion of every false clause—each F c i controlled by the single clause c i —would generate k m f branches in a single round for an assignment with m f false clauses and would not correspond to the classical search tree. The circuit implementation of F is illustrated in Figure 1.
    Each block F c i acts on the assignment register and on an auxiliary label register s of q = ⌈ log 2 k ⌉ qubits, initialized to 0 ⊗ q : a unitary W first prepares a uniform superposition over k basis states of s, which then controls a Pauli- X flip of the corresponding literal,
    F c i = ∑ j = 1 k X p ( i , j ) ⊗ j j s + 1 a ⊗ ∑ j = k + 1 2 q j j s W ,
    where W 0 ⊗ q = k − 1 / 2 ∑ j = 1 k j prepares the uniform superposition in s, the label values being understood cyclically, 2 q ≡ 0 ⊗ q , so that the 2 q basis states of s are indexed by j = 1 , … , 2 q ; the second sum then acts as the identity on the unused label values j > k , which for k = 2 q − 1 is the single all-zero label 0 ⊗ q (cf. Appendix A) and is empty when k = 2 q , so that it completes the first factor to a unitary on the whole register space. X p ( i , j ) flips the variable x p ( i , j ) to which the literal l i , j refers. Acting on an assignment a that falsifies c i , this block gives
    a 0 s → F c i 1 k ∑ j = 1 k g l i , j ( a ) j s ,
    where g l i , j ( a ) denotes the assignment obtained by flipping the bit corresponding to literal l i , j in a. Each g l i , j ( a ) differs from a in exactly one bit position and satisfies c i , so F c i maps a to a uniform, coherent superposition over its k Hamming-distance-1 neighbors that satisfy c i , with the chosen branch recorded in the label register s. This label is retained rather than uncomputed, and no unitary can do otherwise: the corresponding map on the assignment register alone, T bf a = k − 1 / 2 ∑ j = 1 k g l i , j ( a ) , is not an isometry—for k = 2 and { p ( i , 1 ) , p ( i , 2 ) } = { 1 , 2 } it gives T bf 00 = T bf 11 = ( 10 + 01 ) / 2 , and the obstruction persists for k ≥ 3 inside the sector where F c i is active: were the label reset, the falsifying input 000 would keep a component of amplitude 1 / k on 100 0 ⊗ q , the very state that the control leaves untouched for the orthogonal input 100—so no unitary that generates Equation (5) can also return s to 0 ⊗ q . Consequently each of the r rounds of the construction employs its own label register s 1 , … , s r (and, in the case k = 2 q − 1 , its own copy of the auxiliary register w of Appendix A), and each round keeps its own copy of the clause registers as well, since these cannot be uncomputed either (see the discussion of Equation (6)). We provide an implementation scheme of F c i using elementary quantum gates in Appendix A.
The full construction procedure can then be written as
C = F r E r … F 2 E 2 F 1 E 1 ,
where E i denotes the clause-evaluation operator [Equation (2)] acting on the i-th copy of the clause registers, which starts in 0 ⊗ m ( k − 1 ) , and F i the conditional neighborhood expansion [Equation (3)] controlled by those registers and acting on the label register s i of the i-th round. In each round the quantum truth values of all clauses are first computed by E i for the assignment currently held in the assignment register, and the conditional neighborhood expansion F i is then applied on the basis of these truth values. Unlike the oracle of Equation (9), the expansion changes the assignment register, so the clause registers of a round cannot be uncomputed by E i † : applying E i † after the expansion computes the clause values of the new assignment on top of those of the previous one, and the registers return to 0 only when the assignment register is left unchanged—which holds for the oracle but not here. Like the branch label of F [Equation (5)], they are therefore retained rather than uncomputed and reused. This iterative process leverages the clause structure of the k-SAT instance to transform the initial random assignment into a problem-dependent superposition. The resulting state is supported on basis states of the form x s 1 … s r , tensored with the retained clause registers, in which x lies in the Hamming ball B ( a , r ) and the labels record the k-way choices taken along the corresponding branch of the search tree, so that the state forms a local search subspace tailored to the problem instance.
Remark on unitarity. All the operators employed above are unitary: QNOT , QAND , QOR and CNOT act as permutations of the computational basis (and are self-inverse); the Hadamard transform H and D 0 = 2 | 0 ⟩ ⟨ 0 | − I are Hermitian and satisfy H 2 = D 0 2 = 1 ; W is a state-preparation unitary [Equation (4) and Appendix A]; E [Equation (2)], T [Equation (7)], F c i [Equation (4)] and F [Equation (3)] are products of multiply-controlled unitaries, each control condition being a computational-basis pattern on the clause registers (so that the operator reduces to a direct sum of unitaries over the mutually exclusive sectors), and the same holds for the construction C [Equation (6)], the oracle O [Equation (9)] and the Grover iteration G [Equation (1)]. Within the construction, the only non-unitary object in the analysis is the branch-and-forget map T bf introduced below Equation (5), which is not an executed operation but the shortcut of discarding the branch labels: its failure to be an isometry is precisely why the label registers—and, as explained above, the clause registers of each round—are retained and never discarded, so that every step of the construction is a unitary gate. Non-unitary operations occur only where the algorithm measures—in generating the random assignment in Step 1, in the intermediate checks performed by the exponential-search variant of amplitude amplification in Step 3, and in the final readout—and it is the measurement in Step 1 that keeps the outer loop over balls a classical repetition.

3.3. Oracle for the k-SAT Problem

In this subsection, we decompose the oracle O into elementary quantum operations. As previously described, the oracle O identifies solution states and flips their phases. To detect these states, we first apply the clause-evaluation operator E [Equation (2)] to compute the quantum truth values of all m clauses. Subsequently, the quantum AND operation ( QAND ) is applied sequentially ( m − 1 ) times to evaluate the entire formula F . This formula-evaluation procedure is defined as
T = QAND α m , k − 1 , β m − 2 , β m − 1 … QAND α 3 , k − 1 , β 1 , β 2 · QAND α 1 , k − 1 , α 2 , k − 1 , β 1 ,
where β 1 , … , β m − 1 are auxiliary qubits initialized to 0, and QAND x , y , z denotes the QAND gate acting on qubits x, y, and z. This step requires ( m − 1 ) auxiliary qubits in total, with the final truth value of F stored in β m − 1 .
Writing the collection of labels produced by the construction as l, the problem-dependent state ψ a can be decomposed into two orthogonal components based on the value of f ( x ) :
ψ a = ψ a 0 + ψ a 1 = ∑ x : f ( x ) = 0 ∑ l A x , l x l + ∑ x : f ( x ) = 1 ∑ l B x , l x l ,
where ψ a 0 and ψ a 1 are unnormalized and span the subspaces corresponding to unsatisfying and satisfying assignments, respectively (the label and clause registers of the construction are spectators: the oracle below acts as the identity on them and uses its own clause and formula registers, initialized to 0, so the marking condition depends only on the assignment). After applying the clause-evaluation operator E [Equation (2)] and the formula-evaluation operator T [Equation (7)], the system becomes entangled with the ancilla qubit β m − 1 :
ψ a , β m − 1 = ψ a 0 , 0 + ψ a 1 , 1 .
Finally, a controlled-NOT ( CNOT ) gate is applied to the ancilla qubits β m − 1 (control) and β m (target), where β m is initialized to − = ( 0 − 1 ) / 2 . This operation transforms the entangled state into
ψ a , β m − 1 , β m = ψ a 0 , 0 , − − ψ a 1 , 1 , − .
The complete oracle for the k-SAT problem is then given by
O = E † T † CNOT β m − 1 , β m T E ,
where E † and T † are the inverses of the clause-evaluation operator E [Equation (2)] and the formula-evaluation operator T [Equation (7)], respectively. These uncomputation steps restore the clause and formula registers to their initial states, ensuring that the oracle acts as a pure phase oracle on the computational basis; it is the identity on the label and clause registers of the construction.

3.4. Reachability within Hamming Balls

Suppose a * ∈ B ( a , r ) is a satisfying assignment. We now show that after r iterations of the construction procedure [Equation (6)], the state ψ a has amplitude at least k − r / 2 on the marked subspace, i.e., on the components of Equation (8) whose assignment register holds a satisfying assignment. The Hamming distance between two assignments x and y, denoted d ( x , y ) , is the number of bit positions in which they differ. The set of all assignments within Hamming distance r from a center assignment a is called a Hamming ball, denoted B ( a , r ) = { x ∣ d ( x , a ) ≤ r } .
By construction [Equation (6)], each literal-flip operator g l i , j satisfies d ( a , g l i , j ( a ) ) = 1 . Consequently, all assignments reachable via the state-generation procedure lie within B ( a , r ) . For any clause c i = l i , 1 ∨ l i , 2 ∨ … ∨ l i , k that is unsatisfied by a, at least one literal l i , j in c i must evaluate to true under a * . Flipping the corresponding variable in a yields an assignment g l i , j ( a ) such that
d g l i , j ( a ) , a * = d ( a , a * ) − 1 .
Thus, after r rounds of the construction procedure [Equation (6)], the state ψ a necessarily contains a component whose assignment register holds a satisfying assignment: at every round the selected clause contains at least one literal that is true under a * (which satisfies every clause), so a distance-decreasing flip is always available, and the path that applies such a flip in each of the r rounds ends at a * unless it meets another satisfying assignment after d < r rounds, in which case no further expansion takes place and the path ends there. More quantitatively, every branch of the expansion carries the same amplitude k − 1 / 2 [Equation (5)], so the distance-decreasing path carries the amplitude k − r / 2 , or the larger amplitude k − d / 2 if it ends after d < r rounds. Distinct paths are recorded by distinct label configurations and are therefore mutually orthogonal, so their contributions add in quadrature, with no interference and hence no cancellation; the squared overlap, i.e., the probability, of ψ a with the marked subspace is thus at least k − r , since the distance-decreasing path alone has an amplitude of magnitude no less than k − r / 2 on that subspace. Moreover, once the assignment register reaches a satisfying assignment it is no longer modified: every clause is satisfied there, hence none of the control patterns of Equation (3) holds and F acts as the identity on the assignment and label registers, so the amplitude of the component that ends there is preserved. The amplitude of ψ a on the marked subspace is therefore at least k − r / 2 , so amplitude amplification locates a satisfying assignment within O ( k r / 2 ) iterations. Since the number of satisfying assignments inside the ball is not known in advance, we use the exponential-search variant of amplitude amplification [20], which preserves this scaling up to a constant factor.

3.5. Time Complexity

Throughout, running times are counted as the number of elementary gates; the depth of a single run is of the same order as its gate count, since the O ( k ρ n / 2 ) amplitude-amplification iterations are sequential, and the t classically repeated runs multiply both quantities by the same factor.
The size of the Hamming ball B ( a , r ) satisfies the following bounds [9]:
2 n h ( ρ ) 8 n ρ ( 1 − ρ ) ≤ | B ( a , r ) | ≤ 2 n h ( ρ ) ,
where ρ = r / n and h ( ρ ) = − ρ log 2 ρ − ( 1 − ρ ) log 2 ( 1 − ρ ) is the binary entropy function.
Assume the given k-SAT instance has at least one satisfying assignment, and fix one such assignment a * . The analysis below therefore does not require the instance to have a unique solution, and the unique-solution assumption made for plain Grover search in Section 2.3 is not needed here. Under the uniform distribution over all 2 n assignments, the probability that a fixed solution lies in B ( a , r ) is at least
p B = | B ( a , r ) | 2 n ≥ 2 n ( h ( ρ ) − 1 ) 8 n ρ ( 1 − ρ ) .
Since the initial random assignment is measured before the quantum search, different balls are sampled classically and independently, so the outer loop is a purely classical repetition. The probability that a single sampled ball contains a fixed satisfying assignment is p B [Equation (10)], so t = O ( 1 / p B ) = O 2 n ( 1 − h ( ρ ) ) repetitions are required to locate a ball containing a solution. Within such a ball, the constructed state is spread over the reachable branches of the search tree, at most k r of them, each recorded by its own label configuration; by the amplitude bound established in Section 3.4 its amplitude on the satisfying assignments is at least k − r / 2 ; applying amplitude amplification [20] therefore locates a satisfying assignment in O ( k r / 2 ) = O ( k ρ n / 2 ) iterations. Note also that the reflection is taken about the prepared state ψ a rather than about the equal superposition H ⊗ n 0 [cf. Equation (1)]: writing ψ a = C a 0 , where C a denotes the construction C [Equation (6)] preceded by the Pauli- X layer that prepares the measured assignment |a⟩, the diffusion operator is realized as C a ( 2 | 0 ⟩ ⟨ 0 | − I ) C a † = 2 ψ a ψ a − I . The total runtime (up to polynomial factors) is therefore
T tot = 2 n ( 1 − h ( ρ ) ) · k ρ n / 2 .
Minimizing this expression with respect to ρ (equivalently, minimizing ( 1 − h ( ρ ) ) + ρ 2 log 2 k ) and using h ′ ( ρ ) = log 2 ( 1 − ρ ) / ρ yields the optimal choice ρ * = 1 / ( 1 + k ) , i.e., r * = n / ( 1 + k ) , which gives
T tot = 2 k 1 + k n = 2 − 2 1 + k n .
For comparison, the corresponding classical template performs t · k r local-search steps, since the search tree of depth r has k r leaves, and the two factors are balanced at ρ = 1 / ( k + 1 ) ; the resulting exponent is ( 2 − 2 / ( k + 1 ) ) n , i.e., exactly the Hamming-ball local search of Dantsin et al. [9]. Replacing k r by the quadratic k r / 2 of amplitude amplification is what shifts the optimal radius to ρ * = 1 / ( 1 + k ) and yields Equation (11). In particular, when k = 3 , the time complexity is T tot ≈ 1 . 268 n .
Finally, we make the polynomial overhead explicit. Each QOR gate is implemented by a single QAND (Toffoli) gate together with a constant number of single-qubit QNOT gates, so the clause-evaluation operator E [Equation (2)] requires m ( k − 1 ) QOR gates and m ( k − 1 ) auxiliary qubits, while the formula-evaluation operator T [Equation (7)] requires m − 1 QAND gates and m − 1 auxiliary qubits. Since the oracle [Equation (9)] consists of E, T , their inverses, and a single CNOT , a single oracle call costs O ( m k ) elementary gates and uses m k auxiliary qubits of its own. Together with the r = ρ n rounds of state preparation [Equation (6)] and the O ( k ρ n / 2 ) Grover iterations performed for each of the t = O ( 2 n ( 1 − h ( ρ ) ) ) sampled balls, the total number of elementary gates over all runs is
O ( n m k ) 2 − 2 1 + k n ,
with O ( m k ) auxiliary qubits for the oracle’s own clause and formula registers, which are uncomputed by E † and T † and are therefore reused across all Grover iterations and t sampled balls. The registers of the construction, by contrast, cannot be uncomputed and are therefore retained: because both the branch label [Equation (5)] and the clause registers [Equation (6)] of a round are kept, each of the r = ρ n rounds uses its own label register of q = ⌈ log 2 k ⌉ qubits, plus L qubits in the case k = 2 q − 1 (see Appendix A), and its own m ( k − 1 ) clause ancillas, i.e., O ( r ( log k + L ) ) = O ( n log n ) and O ( r m k ) qubits in total, respectively. Both counts are polynomial in n for m = poly ( n ) and leave the exponential scaling of Equation (11) unchanged. In summary, the explicit construction fixes the polynomial overhead of the algorithm rather than leaving it inside an unaccounted-for oracle. Table 1 collects the resulting resources for k = 3 , 4 , 5 : the optimal radius ρ * = 1 / ( 1 + k ) , the number t = O 2 n ( 1 − h ( ρ * ) ) of classically repeated runs, the number O k ρ * n / 2 of amplitude-amplification iterations performed in each run, and the exponential base α of Equation (11). The two factors balance at ρ * , and their product reproduces α ; note that the classical factor alone, 2 n ( 1 − h ( ρ * ) ) , is much smaller than the total cost, so that the exponent is dominated by the inner quantum search. Single-run gate counts and qubit counts are those of Equations (12) and the accompanying text, namely O ( n m k ) elementary gates per run and O ( r m k + n log n + m k ) qubits in total, with r = ρ * n ; both are polynomial in n and m and multiply the base α n .

3.6. Comparison with Prior Quantum Algorithms

Table 2 collects the best known exponents for worst-case 3-SAT in the gate model together with the exponent obtained here. Table 3 lists the same comparison for general k with 3 ≤ k ≤ 10 , where Schöning’s bound ( 2 − 2 / k ) n and the deterministic Hamming-ball template ( 2 − 2 / ( k + 1 ) ) n are confronted with the exponent ( 2 − 2 / ( 1 + k ) ) n obtained here. The exponent of the present algorithm lies below both classical bounds for every k ≥ 3 , since the optimal fraction 1 / ( 1 + k ) exceeds both 1 / k and 1 / ( k + 1 ) ; the gap to the Hamming-ball template that it accelerates is substantial—at k = 3 the base falls from 1.500 to 1.268 , a reduction of about 15 % —and it persists over the whole range, the exponent obtained here being strictly smaller than both classical exponents.
A quantum algorithm that accelerates a classical solver as a black box achieves, up to polynomial factors, the square root of that solver’s exponent; the quality of the resulting bound is therefore determined by the quality of the underlying classical algorithm. Grover search alone gives O ( 1 . 414 n ) [14]; combining it with the best classical 3-SAT algorithm of its time ( O ( 1 . 3302 n ) [5]) gives O ( 1 . 153 n ) [19]; and applying amplitude amplification [20] to the PPSZ algorithm [6,7,8] gives O ( 1 . 143 n ) . The present construction, by contrast, accelerates a Hamming-ball (Dantsin-type) local search whose classical exponent is ( 2 − 2 / ( k + 1 ) ) n ( 1 . 5 n for k = 3 ; instance-specific refinements of this Hamming-ball search reach 1 . 481 n [9], 1 . 473 n [4], and 1 . 465 n [11], but they modify the local search itself rather than the ball-by-ball template accelerated here), and it does so only in its inner loop: because the random assignment of Step 1 is measured, the outer loop over balls remains classical, so the exponent is ( 2 − 2 / ( 1 + k ) ) n rather than the square root ( 2 − 2 / ( k + 1 ) ) n / 2 that a fully coherent variant would give. For general k, the classical reference points are Schöning’s local search ( 2 − 2 / k ) n [3], the deterministic Hamming-ball search ( 2 − 2 / ( k + 1 ) ) n [9], and the PPSZ-type bounds [6,8]; the exponent ( 2 − 2 / ( 1 + k ) ) n obtained here lies below Schöning’s ( 2 − 2 / k ) n for every k ≥ 3 (for instance 1.268 < 1.333 at k = 3 and 1.333 < 1.5 at k = 4 ; Table 3 extends the comparison up to k = 10 ), so the improvement claimed in the abstract refers to the classical local-search bounds, while for k = 3 it also applies to the best known classical algorithm, whose exponent is 1 . 307 n [8]. Consequently, the exponents obtained here do not compete with those listed above, and we make no claim of an improvement in the asymptotic exponent over previous quantum algorithms. The contribution of this work is instead an explicit, gate-level realization of a problem-structured quantum local search, in which the problem-dependent superposition over the Hamming ball and the k-SAT oracle are both decomposed into elementary quantum gates (Section 3.2 and Section 3.3). Extending this explicit construction so that its exponent becomes competitive—for example, by removing the measurement in Step 1 so that the outer loop can also be amplified—is an interesting direction for future work; for a recent study of quantum advantage for structured k-SAT that accounts for fault-tolerant overheads, see Ref. [21].

4. Numerical Verification

The exponent of Equation (11) rests on two worst-case bounds: the probability p B that a uniformly sampled ball contains a solution [Equation (10)], and the lower bound k − r / 2 on the amplitude of the constructed state on the marked subspace (Section 3.4). Both are checkable independently on small instances, and we do so here for k = 3 on planted random instances with m = ⌊ 4.26 n ⌉ clauses and n = 12 to 38. The probability p B is measured by Monte Carlo sampling of the ball center, with 2 × 10 6 centers per point, while the marked amplitude
γ = ∑ ℓ k − d ℓ 1 / 2
is obtained by exact enumeration of the branch tree of Equation (6); the sum runs over those leaves ℓ whose assignment satisfies every clause and d ℓ is the depth of ℓ. Equation (13) is precisely the amplitude of ψ a on the marked subspace: by Equation (5) such a leaf carries the amplitude k − d ℓ / 2 , and distinct leaves are recorded by distinct label configurations and are therefore mutually orthogonal, so that their amplitudes combine in quadrature. The enumeration also reproduces the structural statement of Section 3.4 directly: in every run reported below, a ball containing a solution produced a satisfying leaf of the enumerated tree.
Figure 2(a) confronts the measured p B with Equation (10). Because d ( a , a * ) is a sum of n independent fair bits, the probability that a uniformly random center lies within distance r of a fixed solution is exactly the binomial tail p B = 2 − n ∑ i ≤ r n i , which can be evaluated without sampling error; the figure shows both this exact value and the Monte Carlo estimate. The two agree at every point to within the statistical error of the sampler, which validates the sampling of the ball center on which the amplitude measurements rely, and every point lies inside the window of Equation (10). The plotted ratio tends toward the lower end of that window rather than toward unity: the entropy factor 2 n ( h ( ρ ) − 1 ) taken alone overestimates p B by a root-of-n factor, and at the optimal radius the ratio to the lower bound of Equation (10) lies between 1.8 and 2.3 for every n studied, so that the bound is tight up to its root-of-n correction. At the other radii the ratio to the lower bound runs from 1.3 at ρ = 0.20 to 4.6 at ρ = 0.50 , the increase being that of the factor 8 n ρ ( 1 − ρ ) of Equation (10).
Figure 2(b) shows the measured γ in units of the guaranteed bound k − r / 2 . Every point satisfies γ ≥ k − r / 2 , as required, but the bound is far from tight: at the optimal radius the ratio grows from 4.4 at ( n , r ) = ( 12 , 4 ) to 831 at ( 38 , 14 ) , in proportion to k r / 2 : the measured γ stays of order 0.1 to 0.5 rather than decaying, while the guaranteed bound k − r / 2 falls off exponentially. Two effects contribute. First, a leaf that satisfies the formula at depth d < r carries k − d / 2 rather than k − r / 2 , so every satisfying leaf reached before the last round raises γ above the bound. Second, and more importantly, the planted instances used here are not unique-solution instances: with m = ⌊ 4.26 n ⌉ clauses a random k-SAT instance has of order 2 n ( 1 − 2 − k ) m satisfying assignments in expectation, about 7 at n = 16 and about 110 at n = 38 , so a ball of radius r typically contains several solutions instead of the single one assumed in the worst case. The measured γ therefore probes the typical instance, whereas k − r / 2 is a guarantee that must hold for the least favorable placement of a single solution, which is the situation the analysis of Section 3.4 is designed for. The number of enumerated trees per point falls with r, from 40 at r ≤ 9 to 13–20 at r ≥ 10 , because each enumeration visits k r leaves. This is the main source of the residual scatter of the points at the largest n, and it also dominates the uncertainty of the last two entries of Table 4: repeating the measurement at ( 38 , 14 ) with a different number of trees moves γ from 0.22 to 0.38 , that is, the ratio to the bound from 476 to 831.
Table 4 collects the corresponding costs at ρ * , with t = 1 / p B balls and J = ( π / 4 ) / γ amplitude-amplification iterations per ball, and Figure 3 shows the total cost against n. The measured base ( t J ) 1 / n decreases from 1.19 at n = 12 to 1.09 at n = 38 , and a least-squares fit over n ≥ 20 gives 1.075 , below the asymptotic value 2 − 2 / ( 1 + 3 ) = 1.268 of Equation (11). This gap is not a claim of a better complexity. The measured quantities are averages over planted instances, whereas Equation (11) bounds every instance, and over the range of n accessible here the polynomial overhead alone, of order n m k elementary gates as in Equation (12), is already large enough to bridge the difference: the bound exceeds the measured cost by a factor growing from 2 at n = 12 to 290 at n = 38 , whereas a polynomial overhead of order n 1.5 in the total cost is 230 at the largest n studied and exceeds that difference at every smaller n; extrapolating a base from this window would therefore not be meaningful. What the numbers do establish is that both ingredients of the analysis are valid, and conservative in the typical case: p B obeys Equation (10) including the root-of-n correction, the amplitude bound γ ≥ k − r / 2 of Section 3.4 holds at every point, and the inner quantum search is far cheaper than the worst-case estimate J ≲ ( π / 4 ) k r / 2 on which Equation (11) is built.

5. Conclusions

The k-SAT problem is NP-complete and admits no known efficient classical solution. The best known classical algorithms for 3-SAT run in time O ( 1 . 307 n ) [6,7,8]. In this paper, we propose a hybrid quantum-classical algorithm that integrates Grover’s search as a local subroutine within a randomized framework.
Assuming the given k-SAT instance is satisfiable, the proposed hybrid algorithm requires O 2 n ( 1 − h ( ρ ) ) log ( 1 / δ ) classically repeated iterations of the outer loop (up to polynomial factors) to find a satisfying assignment with probability at least 1 − δ , for any constant δ > 0 . Each round uses its own clause registers of O ( m k ) qubits together with a label register of O ( log k + L ) qubits; these are retained rather than uncomputed and therefore accumulate over the r rounds, whereas the oracle uses its own clause and formula registers, which are uncomputed and reused. Both counts are polynomial in n and immaterial for the exponential scaling. In each iteration, Grover’s algorithm searches within a Hamming ball of radius r = n / ( 1 + k ) centered at a uniformly random assignment. As detailed in Section 3.2, we construct a problem-dependent superposition state that encodes all candidate solutions within this Hamming ball based on the clause structure. Subsequently, Section 3.3 presents an explicit, gate-level implementation of the oracle that identifies solution states within this superposition, built from the elementary gates QNOT , QAND , QOR , and CNOT .
The overall runtime of our algorithm is 2 − 2 1 + k n , which improves upon the classical local-search bounds for k-SAT and, at k = 3 , upon the best known classical algorithm ( 1 . 307 n ). The gain over the classical Hamming-ball template comes from the inner quantum search alone: because the center of each ball is measured, the outer sampling of balls remains a classical repetition and contributes the factor 2 n ( 1 − h ( ρ ) ) rather than its square root, and balancing this factor against the k ρ n / 2 cost of amplitude amplification shifts the optimal radius from ρ = 1 / ( k + 1 ) to ρ * = 1 / ( 1 + k ) (Table 1), the resulting base ( 2 − 2 / ( 1 + k ) ) n lying below both classical local-search bounds for every k ≥ 3 (Table 3). The explicit constructions of Section 3.2 and Section 3.3 fix the polynomial overhead at O ( n m k ) elementary gates in total, so that the total cost is that of Equations (11) and (12) and no unaccounted-for oracle is left in the complexity. Both bounds entering this exponent were verified numerically on small planted instances (Section 4). This exponent does not improve upon the best known quantum algorithms, which are obtained by accelerating stronger classical solvers [6,8,19,20] (Table 2). The main contribution of this work is therefore an explicit, gate-level realization of a problem-structured quantum local search rather than a new asymptotic record; eliminating the measurement in Step 1 so that the outer loop can also be amplified is a promising direction for future work.

Supplementary Materials

The following supporting information can be downloaded at: Preprints.org; Script S1: Python scripts used for the numerical verification of Section 4, together with the data underlying Figure 2 and Figure 3 and Table 4.

Author Contributions

Conceptualization, methodology, software, validation, formal analysis, investigation, writing—original draft preparation, writing—review and editing, visualization: the author. The author has read and agreed to the published version of the manuscript.

Funding

This research was funded by the Hainan Natural Science Foundation of China, grant numbers 621RC741 and 622RC668.

Institutional Review Board Statement

Not applicable.

Data Availability Statement

The Python scripts and the numerical data reported in Section 4, which also underlie Figure 2 and Figure 3 and Table 4, are provided as Supplementary Material (Script S1). All remaining data are contained within the article.

Conflicts of Interest

The author declares no conflicts of interest.

Appendix A. Implementation of F c i

The implementation of F c i can be divided into two steps. The first step prepares the state W 0 ⊗ q , i.e., a uniform superposition over k computational basis states in the label register s, which is initialized to 0 ⊗ q . The second step conditionally flips each qubit of a controlled by the corresponding component of s [Equation (4)]; the register s then records which branch was taken and is retained rather than uncomputed [Equation (5)]. Three cases must be considered based on the value of k: (1) k = 2 q , (2) k = 2 q − 1 , and (3) 2 q − 1 < k < 2 q − 1 , where q denotes the number of qubits in s.
In the first case ( k = 2 q ), the uniform superposition over all k basis states of s is prepared by applying Hadamard gates to all q qubits, i.e., W = H ⊗ q in Equation (4). The second step of F c i then employs Pauli-X gates conditioned on s via multi-controlled X gates; for q = 1 , 2 these are QNOT and QAND (Toffoli) gates, while for q ≥ 3 each of them decomposes into O ( q ) Toffoli gates together with O ( q ) ancillas, which leaves the polynomial overhead of Section 3.5 unchanged. Taking k = 4 as an example, suppose for illustration that a is in the basis state 0000 (in the algorithm a holds the assignment being expanded). Hadamard gates are first applied to the two auxiliary qubits to generate the uniform superposition state:
s = 1 2 00 + 01 + 10 + 11 .
Subsequently, each of the four qubits in a is flipped conditioned on the corresponding basis state of s. The quantum circuit for these controlled-flip operations is depicted in Figure A1. After these operations, s and a become entangled as follows:
s a = 1 2 ( | 00 ⟩ | 1000 ⟩ + | 01 ⟩ | 0100 ⟩ + | 10 ⟩ | 0010 ⟩ + | 11 ⟩ | 0001 ⟩ ) .
In the second case, a uniform superposition over exactly k computational basis states of s cannot be prepared by directly applying Hadamard gates. However, this state can be approximately obtained through an iterative procedure: Hadamard gates are repeatedly applied to the all-zero component of s, controlled by an additional auxiliary qubit register w initialized to 0 ⊗ L , where L denotes the number of iterations of the procedure.
Taking k = 3 as an example, s requires q = 2 qubits to encode k computational basis states. We first prepare the full uniform superposition over all computational basis states of s by applying Hadamard gates to every qubit. The resulting state s can be decomposed as:
s = ϕ 0 + ϕ ˜ 0 = 1 2 01 + 10 + 11 + 1 2 00 ,
where ϕ 0 spans the desired subspace and ϕ ˜ 0 corresponds to the unwanted all-zero component. Applying the operation depicted in Figure A2 to s and w affects only the ϕ ˜ 0 component, transforming it into ϕ 1 + ϕ ˜ 1 , where
ϕ 1 = 1 2 ϕ 0 10 … 0 , ϕ ˜ 1 = 1 2 ϕ ˜ 0 10 … 0 .
In general, the i-th application of the operation on s and w affects only ϕ ˜ i − 1 , transforming it into ϕ i + ϕ ˜ i , where
ϕ i = 2 − i ϕ 0 1 i 0 L − i , ϕ ˜ i = 2 − i ϕ ˜ 0 1 i 0 L − i ,
and the first i qubits of w are in the state 1. After L applications of this operation, the joint state of s and w can be expressed as:
s , w = ∑ i = 0 L ϕ i + ϕ ˜ L .
The amplitude of ϕ ˜ L is 2 − ( L + 1 ) , so the residual weight of the unwanted all-zero component is 4 − ( L + 1 ) , i.e., exponentially small in L. Within each branch i, the k desired basis states carry equal amplitudes 2 − i − q / 2 (i.e., 2 − i / 2 for the present case k = 3 , q = 2 ), so the marginal distribution over the desired basis states { 01 , 10 , 11 } is uniform up to the residual weight 4 − ( L + 1 ) that the state places on the unwanted component. Each application of the operation to the all-zero component of s requires one additional auxiliary qubit w i initialized to 0, so the register w comprises L qubits. Like s, the register w is retained as part of the branch label of its round [Equations (4) and (5)] and does not return to 0 ⊗ L , so that each of the r rounds uses its own copy; choosing L = ( 1 2 + ε ) log 2 n for a fixed ε > 0 keeps the residual weight 4 − ( L + 1 ) of the unwanted all-zero component small enough that the total error accumulated over the r = ρ n rounds, of order O ( r 4 − ( L + 1 ) ) = O ( n − 2 ε ) , is o ( 1 ) .
The third case ( 2 q − 1 < k < 2 q − 1 ) requires a uniform superposition over a specified subset S of k of the 2 q computational basis states, which can be prepared exactly by standard state-preparation techniques. Starting from the equal superposition H ⊗ q 0 = 2 − q / 2 ∑ z z , the indicator function of S is computed into an auxiliary qubit and one step of amplitude amplification [20] rotates the marked component into the target state S = k − 1 / 2 ∑ z ∈ S z . Since the subset occupies a fraction k / 2 q > 1 / 2 of the search space, O ( 1 ) amplification iterations suffice, and the indicator of S is evaluated with O ( q + k ) elementary gates from its classical description; alternatively, the uniform superposition over { 0 , … , k − 1 } can be prepared directly by the recursive construction of Ref. [22] and mapped onto S by a classically controlled permutation. In both cases the prepared state deviates from the exact uniform superposition by at most ε at a cost of poly ( q , log ( 1 / ε ) ) gates, which leaves the exponential scaling of Equation (11) unaffected.
Conditional structure. The selection that defines each factor of Equation (3)—clauses c 1 , … , c i − 1 true and clause c i false—is a computational-basis condition on the clause registers α j , k − 1 , and is therefore realized by a multiply-controlled gate: the m control patterns are computed simultaneously into a flag register by a reversible cascade of O ( m ) QAND gates with O ( m ) work ancillas, F c i is then applied controlled on the i-th flag, and the flags are uncomputed; if no flag is set, i.e., if every clause is satisfied, no expansion is applied. Because F c i changes only the assignment and label registers, the clause registers are untouched while the expansion acts, so the flags remain valid and their uncomputation is exact, returning all work ancillas to 0 for reuse in the next round. The conditional structure thus adds O ( m ) gates per round to the O ( m k ) gates of the clause evaluation, which leaves the polynomial overhead of Section 3.5 unchanged.
Figure A1. Entanglement between computational basis components of s and a via four Toffoli gates. The first gate entangles the 11 component of s with the 0001 component of a; the second, third, and fourth gates analogously entangle 10, 00, and 01 of s with 0010, 1000, and 0100 of a, respectively.
Figure A1. Entanglement between computational basis components of s and a via four Toffoli gates. The first gate entangles the 11 component of s with the 0001 component of a; the second, third, and fourth gates analogously entangle 10, 00, and 01 of s with 0010, 1000, and 0100 of a, respectively.
Preprints 233611 g0a1
Figure A2. Circuit decomposition of the expansion operation on the all-zero component of s using an ancilla qubit w i .
Figure A2. Circuit decomposition of the expansion operation on the all-zero component of s using an ancilla qubit w i .
Preprints 233611 g0a2

References

  1. Karp, R.M. Reducibility Among Combinatorial Problems. In 50 Years of Integer Programming 1958-2008: From the Early Years to the State-of-the-Art; Jünger, M., Liebling, T.M., Naddef, D., Nemhauser, G.L., Pulleyblank, W.R., Reinelt, G., Rinaldi, G., Wolsey, L.A., Eds.; Springer Berlin Heidelberg: Berlin, Heidelberg, 2010; pp. 219–241. [Google Scholar] [CrossRef]
  2. Paturi, R.; Pudlák, P.; Zane, F. Satisfiability Coding Lemma. In Proceedings of the Proceedings of the 38th Annual IEEE Symposium on Foundations of Computer Science (FOCS ’97), 1997; pp. 566–574. [Google Scholar] [CrossRef]
  3. Schöning, U. A probabilistic algorithm for k-SAT and constraint satisfaction problems. In Proceedings of the Proceedings of the 40th Annual IEEE Symposium on Foundations of Computer Science (FOCS ’99), 1999; pp. 410–414. [Google Scholar] [CrossRef]
  4. Brueggemann, T.; Kern, W. An improved deterministic local search algorithm for 3-SAT. Theor. Comput. Sci. 2004, 329, 303–313. [Google Scholar] [CrossRef]
  5. Hofmeister, T.; Schöning, U.; Schuler, R.; Watanabe, O. A Probabilistic 3-SAT Algorithm Further Improved. In Proceedings of the Proceedings of the 19th Annual Symposium on Theoretical Aspects of Computer Science, Berlin, Heidelberg, 2002; STACS ’02, pp. 192–202. [Google Scholar]
  6. Paturi, R.; Pudlák, P.; Saks, M.E.; Zane, F. An improved exponential-time algorithm for k-SAT. J. ACM 2005, 52, 337–364. [Google Scholar] [CrossRef]
  7. Hertli, T. 3-SAT Faster and Simpler—Unique-SAT Bounds for PPSZ Hold in General. SIAM J. Comput. 2014, 43, 718–729. [Google Scholar] [CrossRef]
  8. Hansen, T.D.; Kaplan, H.; Zamir, O.; Zwick, U. Faster k-SAT algorithms using biased-PPSZ. In Proceedings of the Proceedings of the 51st Annual ACM SIGACT Symposium on Theory of Computing (STOC ’19), 2019; pp. 578–589. [Google Scholar] [CrossRef]
  9. Dantsin, E.; Goerdt, A.; Hirsch, E.A.; Kannan, R.; Kleinberg, J.; Papadimitriou, C.; Raghavan, P.; Schöning, U. A deterministic (2-2/(k+1))n algorithm for k-SAT based on local search. Theor. Comput. Sci. 2002, 289, 69–83. [Google Scholar] [CrossRef]
  10. Moser, R.A.; Scheder, D. A Full Derandomization of Schöning’s k-SAT Algorithm. In Proceedings of the Proceedings of the 43rd Annual ACM Symposium on Theory of Computing (STOC ’11), 2011; pp. 245–252. [Google Scholar]
  11. Scheder, D. Guided Search and a Faster Deterministic Algorithm for 3-SAT. In Proceedings of the LATIN 2008: Theoretical Informatics; Laber, E.S., Bornstein, C., Nogueira, L.T., Faria, L., Eds.; Berlin, Heidelberg, 2008; pp. 60–71. [Google Scholar]
  12. Kutzkov, K.; Scheder, D. Using CSP To Improve Deterministic 3-SAT. arXiv 2010, arXiv:1007.1166. [Google Scholar]
  13. Shor, P.W. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM J. Comput. 1997, 26, 1484–1509. [Google Scholar] [CrossRef]
  14. Grover, L.K. Quantum Mechanics Helps in Searching for a Needle in a Haystack. Phys. Rev. Lett. 1997, 79, 325–328. [Google Scholar] [CrossRef]
  15. Shenvi, N.; Kempe, J.; Whaley, K.B. Quantum random-walk search algorithm. Phys. Rev. A 2003, 67, 052307. [Google Scholar] [CrossRef]
  16. Schuld, M.; Sinayskiy, I.; Petruccione, F. An introduction to quantum machine learning. Contemp. Phys. 2015, 56, 172–185. [Google Scholar] [CrossRef]
  17. Biamonte, J.; Wittek, P.; Pancotti, N.; Rebentrost, P.; Wiebe, N.; Lloyd, S. Quantum machine learning. Nature 2017, 549, 195–202. [Google Scholar] [CrossRef] [PubMed]
  18. Gemeinhardt, F.; Garmendia, A.; Wimmer, M.; Weder, B.; Leymann, F. Quantum Combinatorial Optimization in the NISQ Era: A Systematic Mapping Study. ACM Comput. Surv. 2024, 56, 36. [Google Scholar] [CrossRef]
  19. Ambainis, A. Quantum search algorithms. ACM SIGACT News 2004, 35, 22–35. [Google Scholar] [CrossRef]
  20. Brassard, G.; Høyer, P.; Mosca, M.; Tapp, A. Quantum amplitude amplification and estimation. Contemp. Math. 2002, arXiv:quant305, 53–74. [Google Scholar] [CrossRef]
  21. Brehm, M.; Weggemans, J. Assessing fault-tolerant quantum advantage for k-SAT with structure. Quantum 2026 1975, arXiv:2412.1327410. [Google Scholar] [CrossRef]
  22. Grover, L.; Rudolph, T. Creating superpositions that correspond to efficiently integrable probability distributions. arXiv 2002. [Google Scholar]
Figure 1. Quantum circuit implementing procedure F. The qubit α i , k − 1 encodes the quantum truth value of the i-th clause; the block F c i is activated only when α i , k − 1 = 0 (open circle, i.e., clause c i is false) while all preceding clauses are true (filled circles), so that at most one block acts on each computational basis state, and no block acts when every clause is satisfied (the filled control drawn on the row of dots belongs to the control line coming from the preceding clause qubits and passes through the omitted rows); s denotes the label register of the round, shared by its blocks F c i , prepared in a uniform superposition of k basis states and retained as the branch label [Equations (4) and (5)] (each round uses its own copies of the clause registers and its own register s i ); and ψ a denotes the state of the round being expanded, i.e., the problem-dependent superposition constructed so far.
Figure 1. Quantum circuit implementing procedure F. The qubit α i , k − 1 encodes the quantum truth value of the i-th clause; the block F c i is activated only when α i , k − 1 = 0 (open circle, i.e., clause c i is false) while all preceding clauses are true (filled circles), so that at most one block acts on each computational basis state, and no block acts when every clause is satisfied (the filled control drawn on the row of dots belongs to the control line coming from the preceding clause qubits and passes through the omitted rows); s denotes the label register of the round, shared by its blocks F c i , prepared in a uniform superposition of k basis states and retained as the branch label [Equations (4) and (5)] (each round uses its own copies of the clause registers and its own register s i ); and ψ a denotes the state of the round being expanded, i.e., the problem-dependent superposition constructed so far.
Preprints 233611 g001
Figure 2. Verification of the two bounds entering the exponent, for k = 3 . (a) The measured p B in units of the entropy factor 2 n ( h ( ρ ) − 1 ) , for ρ = 0.20 , 0.25 , 0.30 , ρ * = 0.366 , 0.42 and 0.50 . Solid lines are the exact binomial tail 2 − n ∑ i ≤ r n i with r the integer nearest ρ n , open symbols the Monte Carlo estimate at the same points, dotted lines the lower bound of Equation (10) and the dashed line its upper bound; every value lies inside the window. (b) The measured marked amplitude γ in units of the guaranteed bound k − r / 2 , drawn as the dashed line at unity, for the radii of panel (a) and for the optimal radius ρ * up to n = 38 . The bound holds everywhere and is increasingly conservative as r grows.
Figure 2. Verification of the two bounds entering the exponent, for k = 3 . (a) The measured p B in units of the entropy factor 2 n ( h ( ρ ) − 1 ) , for ρ = 0.20 , 0.25 , 0.30 , ρ * = 0.366 , 0.42 and 0.50 . Solid lines are the exact binomial tail 2 − n ∑ i ≤ r n i with r the integer nearest ρ n , open symbols the Monte Carlo estimate at the same points, dotted lines the lower bound of Equation (10) and the dashed line its upper bound; every value lies inside the window. (b) The measured marked amplitude γ in units of the guaranteed bound k − r / 2 , drawn as the dashed line at unity, for the radii of panel (a) and for the optimal radius ρ * up to n = 38 . The bound holds everywhere and is increasingly conservative as r grows.
Preprints 233611 g002
Figure 3. Total cost t J at the optimal radius ρ * against n, for k = 3 . Symbols are the measured values of Table 4, the solid line a least-squares fit over n ≥ 20 and the dashed line the asymptotic bound 1 . 268 n of Equation (11). The measured base lies below the bound because the bound uses the worst-case amplitude k − r / 2 , and over this range of n the polynomial overheads that Equation (11) discards are of the same order as the difference.
Figure 3. Total cost t J at the optimal radius ρ * against n, for k = 3 . Symbols are the measured values of Table 4, the solid line a least-squares fit over n ≥ 20 and the dashed line the asymptotic bound 1 . 268 n of Equation (11). The measured base lies below the bound because the bound uses the worst-case amplitude k − r / 2 , and over this range of n the polynomial overheads that Equation (11) discards are of the same order as the difference.
Preprints 233611 g003
Table 1. Resources of the proposed algorithm at the optimal radius ρ * = 1 / ( 1 + k ) , for k = 3 , 4 , 5 . Classically repeated runs: t = O 2 n ( 1 − h ( ρ * ) ) , with h the binary entropy function. Amplitude-amplification iterations per run: O k ρ * n / 2 . Exponential base of Equations (11) and (12): α = 2 1 − h ( ρ * ) k ρ * / 2 = 2 − 2 / ( 1 + k ) , so that t · k ρ * n / 2 = α n up to polynomial factors.
Table 1. Resources of the proposed algorithm at the optimal radius ρ * = 1 / ( 1 + k ) , for k = 3 , 4 , 5 . Classically repeated runs: t = O 2 n ( 1 − h ( ρ * ) ) , with h the binary entropy function. Amplitude-amplification iterations per run: O k ρ * n / 2 . Exponential base of Equations (11) and (12): α = 2 1 − h ( ρ * ) k ρ * / 2 = 2 − 2 / ( 1 + k ) , so that t · k ρ * n / 2 = α n up to polynomial factors.
k ρ * t Iterations α
3 0.366 1 . 037 n 1 . 223 n 1.268
4 0.333 1 . 058 n 1 . 260 n 1.333
5 0.309 1 . 078 n 1 . 282 n 1.382
Table 2. Exponential base α in the gate-model running time O ( α n ) for worst-case 3-SAT. The first two rows are classical reference points included for comparison; the remaining rows are quantum gate-model algorithms.
Table 2. Exponential base α in the gate-model running time O ( α n ) for worst-case 3-SAT. The first two rows are classical reference points included for comparison; the remaining rows are quantum gate-model algorithms.
Algorithm Base α
Classical: Schöning’s local search [3] 1.333
Classical: best known (PPSZ-type) [6,7,8] 1.307
Grover search (oracle only) [14] 1.414
Grover search + Hofmeister et al. [5,19] 1.153
Amplitude amplification + PPSZ [6,8,20] 1.143
This work (Grover within a Hamming ball, hybrid) 1.268
Table 3. Exponential bases α in the running time O ( α n ) for general k: Schöning’s local search ( 2 − 2 / k ) n [3], the deterministic Hamming-ball template ( 2 − 2 / ( k + 1 ) ) n [9], and the exponent ( 2 − 2 / ( 1 + k ) ) n obtained here. The present exponent lies below both classical bounds for every k ≥ 3 .
Table 3. Exponential bases α in the running time O ( α n ) for general k: Schöning’s local search ( 2 − 2 / k ) n [3], the deterministic Hamming-ball template ( 2 − 2 / ( k + 1 ) ) n [9], and the exponent ( 2 − 2 / ( 1 + k ) ) n obtained here. The present exponent lies below both classical bounds for every k ≥ 3 .
k Schöning Hamming ball This work
3 1.333 1.500 1.268
4 1.500 1.600 1.333
5 1.600 1.667 1.382
6 1.667 1.714 1.420
7 1.714 1.750 1.451
8 1.750 1.778 1.478
9 1.778 1.800 1.500
10 1.800 1.818 1.519
Table 4. Numerical verification at the optimal radius ρ * = 1 / ( 1 + k ) for k = 3 . p B is the exact binomial tail | B ( a , r ) | / 2 n ; γ is the marked amplitude of Equation (13) measured by exact enumeration of the branch tree; and ( t J ) 1 / n is the base of the total cost t J , with t = 1 / p B classically repeated balls of J = ( π / 4 ) / γ amplitude-amplification iterations each, to be compared with 2 − 2 / ( 1 + 3 ) = 1.268 of Equation (11). The guaranteed lower bound is γ min = k − r / 2 .
Table 4. Numerical verification at the optimal radius ρ * = 1 / ( 1 + k ) for k = 3 . p B is the exact binomial tail | B ( a , r ) | / 2 n ; γ is the marked amplitude of Equation (13) measured by exact enumeration of the branch tree; and ( t J ) 1 / n is the base of the total cost t J , with t = 1 / p B classically repeated balls of J = ( π / 4 ) / γ amplitude-amplification iterations each, to be compared with 2 − 2 / ( 1 + 3 ) = 1.268 of Equation (11). The guaranteed lower bound is γ min = k − r / 2 .
n r p B γ γ / γ min ( t J ) 1 / n
12 4 0.194 0.493 4.4 1.192
16 6 0.227 0.434 11.7 1.139
20 7 0.132 0.410 19.2 1.143
24 9 0.154 0.316 44.4 1.123
28 10 0.0925 0.390 94.7 1.116
32 12 0.108 0.208 152 1.118
36 13 0.0662 0.142 179 1.131
38 14 0.0717 0.380 831 1.093
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.