Unconditional certified randomness, public verifiable and noninteractive, survives subexponential quantum queries.
2 comments
The subexponential query bound is srtonger than the older low-depth results, but it still lives in the QROM, so the random oracle assumption is carrying most of the weight here. I was a little surprised they get public verifiability from Yamakawa-Zhandry, since that makes the usual extraction story much less direct than in the structured-commitment proofs.
> it still lives in the QROM, so the random oracle assumption is carrying most of the weight here.
Thats the weak spot, sure, but calling it “most of the weight” oversells the oracle. The whole point of these certified-randomness defs is the noninteractive public check, and the query bound is doing real work against quantum rewinding style attacks, not just papering over everything.