Search arXivSearch

arXiv · 2606.27231

A hardware-safety-gated system for LLM-written native ARTIQ control code on a trapped-ion platform

Abstract

Large-language-model (LLM) agents can write and run experimental control code. This allows laboratory work to be conducted autonomously. However, this autonomy raises a safety problem that prior work has not addressed. Unchecked code can damage the apparatus, and there is no formal, per-operation boundary between human authorization/supervision, and agent decisions. We present a control system that places an LLM agent in the loop of a trapped-ion experiment while enforcing such a boundary. The agent controls the existing Advanced Real-Time Infrastructure for Quantum physics (ARTIQ) stack through tools provided by a Model Context Protocol (MCP) server. No tool call reaches the hardware unless it carries an authorization token bound to its exact contents. Tokens are issued in one of two ways: automatically, by running the agent's proposed script in an isolated hardware simulation (dax.sim) and checking every operation against preset per-device bounds, or manually by a human operator for sensitive actions. Within this boundary the agent develops its own experiments, rather than only calling pre-built routines. We deploy the system on a co-trapped $^{40}$Ca$^{+}$/$^{40}$CaOH$^{+}$ crystal, where the agent autonomously builds a full calibration stack and, with targeted operator guidance, closes a cross-instrument magnetic-field-stabilization loop. On a separate, independent $^{171}$Yb$^{+}$ platform, we confirm interface-level portability. We systematically test token-authorization mechanism with adversarial scripts that attempt to bypass it, mapping the precise boundary of its protection and prioritizing where to strengthen it next. Analyzing where the agent still requires human guidance, we find that its limits lie in metacognitive control, namely recognizing when a problem must be re-framed, rather than in domain knowledge.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Duanyang Wang, Lu Qi, Yuanheng Xie, Norbert M. Linke, Kenneth R. Brown. 2026-06-25. A hardware-safety-gated system for LLM-written native ARTIQ control code on a trapped-ion platform. https://arxiv.org/abs/2606.27231

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Quantum Authenticated Key Expansion with Key Recycling

Data privacy and authentication are two main security requirements for remote access and cloud services. While QKD has been explored to address data privacy concerns, oftentimes its use is separate from the client authentication protocol despite implicitly providing authentication. Here, we present a quantum authentication key expansion (QAKE) protocol that (1) integrates both authentication and key expansion within a single protocol, and (2) provides key recycling property - allowing all authentication keys to be reused. We analyse the security of the protocol in a QAKE framework adapted from a classical authentication key exchange (AKE) framework, providing separate security conditions for authentication and data privacy. We experimentally implemented the protocol with appropriate post-selection. Additional results on the security of pseudorandom basis generation in QAKE and decoy state BB84 are provided.

quant-ph

Entanglement as Difference: Reduction-induced Minimal Partial Entropy Difference

Bipartite mixed-state quantum entanglement (QE) and its measures play a crucial role in both theoretical research and practical quantum applications. Its internal structure is far more complex and less well understood compared with bipartite pure-state QE. Some existing measures involve inherently intractable global optimizations, while others are only applicable to highly limited-dimensional quantum systems. Here based on the inherent feature that bipartite QE systems nonseparable necessarily implies that local reduced density matrix differs from its \textquotedblleft native\textquotedblright density matrix, we propose a more physical and intuitive measure termed Reduction-induced Minimal Partial Entropy Difference to quantify arbitrary bipartite mixed-state QE. Partial Von Neumann Entropy is only a pure-state special case of this method. This measure offers intrinsic structural %perspective insights into bipartite QE characterization, thereby establishing itself as a valuable complementary measure. Its intuitive and clear physical picture, combined with relatively low computational complexity and wide applicability, facilitates exploring its potential quantum information applications, hence its conceptual framework and line of thought deserve to be further developed to describe and quantify multipartite QE in the future.

quant-ph

Non-local mass superpositions and optical clock interferometry in atomic ensemble quantum networks

Quantum networks are emerging as powerful platforms for sensing, communication, and fundamental tests of physics. We propose a programmable quantum sensing network based on entangled atomic ensembles, where optical clock qubits realize mass superpositions arising via mass-energy equivalence, as in atom and atom-clock interferometry. Our approach uniquely combines scalability to large atom numbers with minimal control requirements, relying only on collective addressing of internal atomic states. This enables the creation of both non-local and local superpositions with spatial separations beyond those achievable in conventional matter-wave interferometry with single atoms. Starting from Bell-type seed states distributed via photonic channels, collective operations within atomic ensembles coherently build many-body mass superpositions sensitive to gravitational redshift. The resulting architecture implements a non-local Ramsey interferometer, where gravitationally induced phase shifts are imprinted on non-local entangled states and are read out through local measurements at the network nodes. Beyond extending the spatial reach of mass superpositions, our scheme establishes a scalable, programmable platform to probe the interface of quantum mechanics and gravity, and offers a new experimental pathway to test atom and atom-clock interferometer proposals, e.g. for probing gravitational dephasing, in a network-based quantum laboratory.

quant-ph