Why Pseudorandom Isn't Random: The Math of Reversible, Finite-State Generative Art

I used to do everything with Math.random() and a seeded PRNG, the same way every generative art platform does. Art Blocks, fxhash, most custom pipelines — they all start from a pseudorandom number generator. And whenever the question of "true" randomness came up, the answer was always the same: "It passes statistical tests. It's random enough for art."
For aesthetics, that's true.
For uniqueness, it's false — and that's the part that matters when you're promising someone a one-of-one. "Random enough" is a category error, and I want to show you the math, because in this post I'll make the full argument: every PRNG is deterministic, every PRNG is reversible, and every PRNG has a finite state space. Then I'll show where a quantum measurement breaks each of those limits.
First, the claim everyone makes
The stock defense of a PRNG is that its output is computationally indistinguishable from random — no efficient algorithm can tell the output apart from true random without knowing the seed. That's true. It's also irrelevant to the uniqueness argument, because distinguishable-or-not is a weaker property than actually-being-random.
Here's the thing: given state_0 (the seed), the entire output sequence is predetermined. There is no randomness in a PRNG. There is only computational indistinguishability from random.
What a PRNG actually is
A PRNG is a deterministic function:
state_{n+1} = f(state_n)
output_n = g(state_n)
That's the whole machine. The generators you actually meet in generative art:
- xorshift / xoshiro — 64 to 256-bit state, period 2⁶⁴ to 2²⁵⁶
- PCG (Permuted Congruential Generator) — 64 to 128-bit state
- ChaCha20 / AES-CTR (CSPRNGs) — 256-bit state, cryptographic security
- JS
Math.random()— typically xorshift128+, 128-bit state
The reversibility problem
Every PRNG is reversible. Given enough consecutive outputs, you can reconstruct the internal state:
- xorshift128+ (V8/Node.js
Math.random()): 2 consecutive 64-bit outputs reconstruct the full 128-bit state. - PCG: ~3–4 outputs.
- ChaCha20: computationally infeasible — but only because of the 256-bit key, not because of any law of physics.
Once you have the state you can predict every future output, run the generator backward to reconstruct every past output, and — if the seed space is small enough — recover the seed itself. This isn't theoretical. Tools like xorshift-reverse, pcg-reverse, and js-random-reverse exist and work. Take 2–3 outputs from a seeded collection and you can often regenerate the entire series.
State space vs. output space
A PRNG's output space cannot exceed its state space. There are only so many distinct sequences a 128-bit state can produce, and a 256-bit state can produce only 2²⁵⁶ of them:
| PRNG | State bits | Max unique sequences |
|---|---|---|
| xorshift128+ | 128 | 2¹²⁸ ≈ 3.4×10³⁸ |
| PCG64 | 128 | 2¹²⁸ |
| ChaCha20 (CSPRNG) | 256 | 2²⁵⁶ |
| Quantum (12 qubits, 4096 shots) | Effective ∞ | Physics-limited, not state-limited |
Even a CSPRNG with a 256-bit state has a finite, enumerable state space. It's not physics that protects it; it's the absence of sufficient compute. It's very practical protection, but it's protection, not impossibility.
Quantum randomness has no state. Its outcome is not generated by a function, there's no internal state to reverse, and the Born rule is a law of physics rather than an algorithm.
Quantum randomness: the Born rule
Measure a qubit in superposition α|0⟩ + β|1⟩ and the probability of outcome |0⟩ is |α|², of |1⟩ is |β|². That's the Born rule, one of the most intensely verified laws in physics. The relevant properties for our purposes:
- No hidden variables. Bell's theorem and the experimental violations of Bell inequalities rule out any local hidden-variable model explaining these correlations.
- No algorithm. The outcome isn't computed anywhere; it's a fundamental physical event.
- Irreproducible. Measurement collapses the wavefunction; the pre-measurement state is gone. No amount of compute can rewind it.
- Min-entropy of 1 bit per qubit per shot. For a perfectly prepared
|+⟩state, every measurement yields one full bit of true min-entropy. No algorithm can compress that further.
Putting numbers on "rare": the min-entropy comparison
Min-entropy, defined as H∞(X) = -log₂(maxₓ P[X=x]), measures the worst-case unpredictability of a source. Worst case, not average case — which is exactly what you want to reason about rare outcomes.
For a PRNG with an S-bit state: the output is deterministic given the seed, so H∞(output) ≤ H∞(state) ≤ S. An S-bit state caps its own entropy — and the seed usually isn't even a full S bits; it's frequently a timestamp plus a PID.
For a quantum measurement of a |+⟩ qubit: P[0] = P[1] = 0.5, so H∞ = -log₂(0.5) = 1 bit per shot. For N independent shots, min-entropy is N bits. No algorithm reduces this; it's the floor set by physics.
For Quantum Genesis (12-qubit circuit, 4096 shots per piece): each shot measures 12 qubits → 12 bits of true min-entropy per shot. Over 4096 shots that's 49,152 bits of true min-entropy in the measurement distribution. The SHA-256 seed derivation (detailed in my post on turning quantum noise into deterministic seeds) compresses this to 256 bits — and those bits inherit the full min-entropy of the source.
No PRNG can match this. A PRNG with a 256-bit state carries at most 256 bits of min-entropy, and only if its seed was itself truly random. Quantum Genesis seeds start from 49,152 bits of physics-guaranteed min-entropy, compressed to 256. That's why the whole seed space is larger than the number of atoms in the observable universe — and why every one of those seeds is physics-guaranteed. (If you want the intuition behind why quantum randomness and math-random look so different when it's actually running, this post has the visual comparison.)
The side-by-side
| Property | Classical generator (PRNG) | Quantum Genesis |
|---|---|---|
| Seed reversibility | Yes — 2 to 4 outputs | No — physics |
| Seed predictability | Yes — state reconstruction | No — Born rule |
| State-space limit | Finite (2¹²⁸–2²⁵⁶) | Physics-limited |
| Collision possibility | Non-zero (birthday bound) | Zero |
| Provenance type | Social / algorithmic | Physics-backed |
| Verifiable by | Code audit + seed | Physics + code + chain |
The honest caveat: for making something look nice, any competent PRNG is fine, and I'd never claim otherwise. The difference shows up at the boundary where uniqueness is the promise. If the whole value proposition is that a piece exists exactly once, the entropy at the source is the thing worth auditing.
I realize I've been talking about these two machines abstractly — in the next post I'll walk through the concrete hardware comparison from actually running 100 production jobs across Origin Quantum and IBM Quantum, SDK pain and all.
Comments
Post a Comment