{"id":"1e4729b8-0b8d-457d-9584-2636c4a2103d","arxiv_id":"1908.04526","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":6,"one_line_summary":"A rateless reconciliation protocol combining multidimensional reconciliation with Raptor codes achieves over 95% efficiency from -20 to 0 dB SNR in simulations and supports optimal modulation variance in CV-QKD.","lead":"This paper proposes using Raptor codes, a type of rateless error correction, for information reconciliation in continuous-variable quantum key distribution. The authors simulate the protocol and report reconciliation efficiency above 95% across a wide signal-to-noise range, which could simplify practical CV-QKD systems.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Security of the rateless protocol is not established: Eq. (9) covers a single mapping function, but the protocol publicly reveals the stopping time/feedback and check code r, which are not shown independent of c'.","rationale":"The reader's conditional verdict is sound: the central claim should not be accepted as stated until the protocol's adaptive/rateless behavior is shown to preserve security and the simulation claims are reproducible. I partially agree with the reader's weakest assumption. The reader focused on the SNR-dependent switch among degree distributions; my sharper concern is that the rateless operation itself adds public messages (ACK/stop signal, number of mapping functions, check code r) that are not covered by Eq. (9). Even if each M(y',c') is independent of c' by the Haar-measure argument, the stopping time and check bits could be correlated with c' in finite-length decoding, and no analysis bounds this. If such correlation exists, the key rate formula in Eq. (1) omits leakage, so the finite-size rates in Fig. 6 are not justified. The one-distribution wording is also internally contradicted by Table I and the adaptive switch, but that is a novelty/complexity overstatement rather than a direct security failure. A Monte Carlo test of I(c'; T, r) is a concrete way to settle whether the security concern lands. If it shows no leakage, the conditional acceptance can proceed on the efficiency claims; if it shows leakage, the paper needs a revised security analysis before the rates can be trusted.","tokens_in":14672,"tokens_out":17392,"duration_ms":204579,"concrete_test":"Run a Monte Carlo of the proposed rateless reconciliation at SNR = -20 dB and -12 dB with k = 9900 using the Table I distributions. For at least 10^4 random seeds u and channel realizations, record the ACK round T (number of mapping functions required before successful decoding) and the check bits r. Compute the empirical mutual information I(c'; T, r) (or a chi-square test of P(T, r | c')). If the mutual information is nonzero to within sampling error, the public feedback leaks key information and the rates in Fig. 6 are not security-justified.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section III argues that each mapping function M(y',c') is independent of c' via Eq. (9), and therefore the public messages do not leak. But the rateless protocol sends more than the individual M's: Alice transmits a stop/ACK signal once decoding succeeds, Bob may send additional check bits r, and the number of mapping functions n(γ) sent before success is itself public. None of these are analyzed. Decoding success time for a finite-length Raptor code can depend on the particular codeword c' and the noise realization; if the ACK time T has even a small correlation with c', Eq. (9)'s per-M independence does not bound Eve's information. The same gap applies to the additional check code r mentioned in Section III. The key rate formula (1) assumes reconciliation leakage is captured by βI(A:B); an unaccounted side channel from feedback would invalidate the finite-size rates in Fig. 6. Separately, the abstract's 'just one degree distribution' claim is contradicted by the four distributions in Table I and the adaptive switch described in Section IV, which weakens the stated novelty, but the security gap is the more load-bearing issue.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a rateless information reconciliation protocol for continuous-variable quantum key distribution (CV-QKD), combining multidimensional reconciliation with Raptor codes. The authors claim that the protocol achieves reconciliation efficiency above 95% over a SNR range from -20 dB to 0 dB, allows the modulation variance to remain at its optimal value, and yields finite-size secret key rates up to a distance of 132 km at a 5-MHz repetition rate. The protocol works by having Bob generate Raptor-encoded bits, map them onto binary spherical codes, send the corresponding orthogonal mapping functions to Alice, and then feed back a stop signal and additional check bits upon successful decoding. The paper reports simulation results for four Raptor degree distributions and an adaptive switching (\"DD-adaptive\") envelope that selects the best distribution at each SNR.","tokens_in":14910,"tokens_out":3181,"duration_ms":33883,"significance":"If the security and efficiency claims hold, this work would be a practical step forward: a single rateless reconciliation framework could replace multiple fixed-rate LDPC codes, simplify code optimization for variable channel conditions, and remove the need to sacrifice the optimal modulation variance. The paper builds on established multidimensional reconciliation (Ref. [40]) and Raptor-code design (Refs. [49-52]), provides concrete degree distribution polynomials in Table I, and compares finite-size key rates with published experiments and field tests in Fig. 6. However, the security argument is incomplete, the \"just one degree distribution\" claim is contradicted by the adaptive switching method in Section IV, and the simulation evidence is presented without error bars, trial counts, or code release. The central efficiency claim is therefore plausible but not fully established as stated.","major_comments":[{"comment":"The independence proof for the mapping function M(y',c') and the codeword c' applies only to a single M(y',c') under a random orthogonal transformation. The rateless protocol additionally transmits, over the authenticated public channel, the stop/ACK signal upon successful decoding, the number of mapping functions n(gamma) sent before success, and the additional check bits r (Fig. 2 and Section III). The paper does not analyze whether any of these public messages are independent of c'. If the stopping time T or the check bits r have even a small correlation with the particular codeword c', then Eq. (9)'s per-mapping independence does not bound Eve's total information about c', and the reconciliation leakage in Eq. (1) (captured only through beta I(A:B)) would be underestimated. This gap directly affects the validity of the finite-size secret key rates in Fig. 6, and it must be closed by an explicit security analysis of the feedback and check-bit messages, or by reference to a published proof covering rateless feedback in this setting.","section":"Section III, Eq. (9) and Fig. 2"},{"comment":"The abstract and the conclusion state that the protocol achieves high efficiency using \"just one degree distribution,\" but Section IV uses four distinct degree distributions Ω1(x) through Ω4(x) (Table I) with an adaptive switching method, and the reported >95% efficiency is the envelope over these four distributions. This is not a single-distribution result. The wording should be corrected, and if the authors wish to claim single-distribution performance, they must provide results for a single Ω(x) covering the full −20 to 0 dB range. As it stands, the efficiency envelope is the maximum over four separately optimized distributions, which weakens the stated reduction in optimization complexity.","section":"Abstract, Section IV, Fig. 3 and Table I"},{"comment":"The degree distributions are obtained by EXIT-chart optimization (Section III) for the very SNR range in which the protocol is then evaluated, and the final efficiency curve in Fig. 3 is the best of four fitted distributions. Consequently, the >95% values are partly the output of the optimization procedure rather than an independent predictive test. The simulation results also lack error bars, the number of Monte Carlo trials, and the exact decoding failure criteria, and no code or detailed simulation parameters are released. Finally, it is unclear whether the β values used in the finite-size points of Fig. 6 are obtained from actual Raptor encoding/decoding runs at each SNR or from the theoretical formulas in Eqs. (10)-(11) combined with the Fig. 3 envelope. Please clarify the simulation methodology and provide statistical uncertainty so that the efficiency claims can be independently assessed.","section":"Section III, EXIT-chart derivation, and Section IV, Fig. 3 and Fig. 6"}],"minor_comments":[{"comment":"The text says the −20 dB to 0 dB range corresponds to distances from 35 to 124 km, while the Fig. 4 caption says the enlargement is from 34 to 124 km; please make these values consistent.","section":"Section IV, Fig. 4 caption and text"},{"comment":"The sentence \"In order to satisfy the requirement that the secure key rate is greater than zero, a higher reconciliation efficiency is needed under the condition of low SNRs\" is somewhat vague; it would be clearer to state that βmin is determined by the condition K_finite(βmin)=0 and that nval is the corresponding maximum block length.","section":"Section III, after Eq. (13)"},{"comment":"Equation (6) writes Prob(ci=0)=Prob(ci=1)=1/2 as a single equality chain; this is correct only if the precoded bits are uniform and the degree selection is independent, so please add a brief note stating these conditions explicitly.","section":"Section III, Eq. (6)"},{"comment":"The figure caption says \"The blue solid line is the secret key rate for optimal modulation variance...\" but the body text refers to blue and orange lines in a way that could mislead readers about which curve corresponds to which strategy; please align the color descriptions in text and caption.","section":"Section IV, Fig. 5"},{"comment":"The claim that \"the rateless reconciliation protocol can achieve error-correction under lower SNRs (-25 or -30 dB)\" is not supported by the simulations in Section IV; if this is a conjecture, please state it as such and avoid presenting it as a demonstrated property.","section":"Section V, Discussion"}],"recommendation":"major_revision","confidential_remarks":"The manuscript addresses a relevant practical problem in CV-QKD and builds on legitimate prior art, but the security gap concerning the public feedback (stop signal, check bits, number of iterations) is load-bearing and needs a substantive fix, not a cosmetic revision. The efficiency claims would also benefit from a more transparent simulation methodology. I recommend major revision rather than rejection because the core idea is defensible and the missing analysis appears to be addable within the scope of a revised manuscript."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: first Raptor-code rateless reconciliation for CV-QKD, with useful simulations, but the security argument doesn't cover the feedback/stop messages, and the \"one degree distribution\" line oversells four adaptive distributions.\n\nWhat is new: the combination of multidimensional reconciliation with Raptor codes, an adaptive envelope over four degree distributions that keeps efficiency above 95% in simulation from -20 to 0 dB SNR, and operation at the optimal modulation variance. The comparisons with fixed-rate MET-LDPC and polar codes are fair and make the practical point. No code or data is released, but the protocol is described well enough to reimplement.\n\nSoft spots, in proportion. The load-bearing one is security. Eq. (9) is the standard independence result for a single random-orthogonal mapping M(y',c'). The protocol additionally reveals the stop/ACK time, the number of mappings sent, and a check code r; none of these are shown independent of c'. For finite-length Raptor codes, the decoding success time can depend on the particular codeword and noise realization, and if the ACK time is even slightly correlated with c', Eq. (9) does not bound Eve's information. The key-rate formula (1) assumes all reconciliation leakage is captured by beta I(A:B); an unaccounted feedback side channel would invalidate the finite-size rates. This needs either a proof that the feedback is independent of c' or a modified security analysis. It is not fatal to the idea, but it is fatal to the current claim.\n\nSecond, efficiency is simulation-only, with no error bars and no code release. The degree distributions are EXIT-optimized in the same SNR range where the >95% envelope is reported. That is mild circularity, typical for coding papers, but the abstract should say \"simulated\". Third, \"just one degree distribution\" is contradicted by Table I and Fig. 3; the adaptive switch is a sensible engineering choice, but the wording oversells it.\n\nCitation pattern looks fine: the Raptor-on-AWGN and CV-QKD reconciliation literature is properly cited, including the source of Eq. (9).\n\nThis paper is for people building CV-QKD postprocessing and for coding theorists interested in rateless codes with feedback. I would not cite the security claims as they stand, but I would cite it as a first rateless-reconciliation demonstration. It deserves peer review, not desk rejection; the referee should insist on a security analysis of the feedback channel and reproducible simulation details. Bottom line: promising protocol, currently over-claimed.","headline":"First Raptor-code rateless reconciliation for CV-QKD, with useful simulations, but the security argument doesn't cover the feedback/stop messages, and the 'one degree distribution' line oversells four adaptive distributions.","tokens_in":15475,"tokens_out":4390,"would_cite":true,"duration_ms":45716,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper claims that a Raptor-code-based rateless reconciliation protocol keeps CV-QKD reconciliation efficiency above 95% from -20 dB to 0 dB SNR and yields a secret key rate of about $5\\times10^{-4}$ bits per pulse at 132 km.","keywords":["continuous-variable quantum key distribution","CV-QKD","rateless reconciliation","Raptor codes","multidimensional reconciliation","reconciliation efficiency","secret key rate","adaptive degree distribution"],"falsifier":"Run the proposed protocol at a mid-envelope SNR such as -10 dB with k=9900 and measure the realized Raptor rate $R(\\gamma)$: if $\\beta=R(\\gamma)/C(\\gamma)$ falls below 95% at any point in [-20, 0] dB, the efficiency claim fails. Alternatively, compute the mutual information $I(c';M(y',c'))$ across a degree-distribution switch; a nonzero value would break the security argument.","tokens_in":14460,"feed_emoji":"🔐","tokens_out":7189,"duration_ms":69646,"temperature":0.7,"pith_summary":"The paper proposes replacing the fixed-rate error-correcting codes used in continuous-variable quantum key distribution with a rateless Raptor code. Because a Raptor code can generate an unlimited number of coded symbols until the receiver decodes successfully, one code design, with an SNR-adaptive choice among four degree distributions, can hold reconciliation efficiency above 95% across the SNR range from -20 dB to 0 dB. This removes the need to redesign codes for each channel condition and lets the system keep the modulation variance at its optimal value, which fixed-rate schemes sacrifice. The simulated consequence is a finite-size secret key rate of about $5\\times10^{-4}$ bits per pulse at a maximum distance of 132 km, obtained with $N=10^{12}$ block data at a 5-MHz repetition rate.","feed_headline":"Rateless Raptor codes keep CV-QKD reconciliation above 95%","feed_subtitle":"One adaptive code covers -20 to 0 dB SNR and yields a 5e-4 bits/pulse key rate at 132 km.","key_machinery":"The load-bearing object is the Raptor code, a rateless fountain code in which an LT code generates unlimited output symbols from a message first protected by a high-rate LDPC precoder; its degree distribution $\\Omega(x)$ controls the probabilities of output-node degrees. The protocol feeds the Raptor output through multidimensional reconciliation: Bob maps each $d$-dimensional block of normalized Gaussian data to a binary spherical code via a random orthogonal transformation $M(y',c')$, converting the physical Gaussian channel into a virtual binary-input AWGN channel on which Raptor decoding runs. The rateless feedback loop, in which Bob sends more mapping functions and Alice decodes again until the LDPC check equations pass, is what makes one design cover a wide SNR range. The four degree distributions, each optimized for part of the SNR range by the EXIT-chart method, are combined into one adaptive envelope.","core_discovery":"The central claim is that multidimensional reconciliation and Raptor codes can be combined into a rateless reconciliation protocol for CV-QKD that keeps the reconciliation efficiency $\\beta = R(\\gamma)/C(\\gamma)$ above 95% for every SNR in [-20, 0] dB, reaching 98% at the lowest end. The protocol relies on Bob generating Raptor-coded spherical sequences $c'$, computing mapping functions $M(y',c')$ that rotate his normalized Gaussian data $y'$ into $c'$, and sending those mappings to Alice until her Raptor decoder succeeds; extra check bits guard against false success. Four optimized degree distributions, switched according to the SNR, form an efficiency envelope that behaves like a single rateless code. Because the realized code rate adapts to the channel, the modulation variance can stay at the value that maximizes the secret key rate, and the simulations report secret key rates of about 300 kbit/s at 32 km, 2.5 kbit/s at 130 km, and roughly $5\\times10^{-4}$ bits per pulse at 132 km, exceeding the fixed-rate results compared in the paper.","pith_inferences":["If the efficiency envelope persists at longer block lengths, a CV-QKD system could self-tune to unknown channel loss without storing many code-rate tables, a step toward unattended QKD networks that goes beyond this paper's offline simulations.","The no-leakage proof is given for a fixed encoding; an explicit test of the independence between $M(y',c')$ and $c'$ under the SNR-driven switch would close the gap between the rateless envelope and the security claim.","The eight-dimensional reconciliation map carries a capacity penalty that grows with SNR, so the same Raptor envelope should not be assumed to extend above 0 dB into short-distance, high-rate operation without further design."],"forward_implications":["A single rateless code with adaptive degree distribution can replace a bank of fixed-rate LDPC codes, so the reconciliation layer no longer needs to be re-optimized for each channel SNR.","Keeping the modulation variance at its optimum removes the key-rate penalty that fixed-rate systems pay when they tune variance to a code threshold.","The simulation predicts finite-size secret key rates of about 300 kbit/s at 32 km and 2.5 kbit/s at 130 km at 5 MHz repetition, with about $5\\times10^{-4}$ bits per pulse at 132 km.","The same protocol is expected in theory to work at even lower SNRs (-25 to -30 dB), extending reach, and to support free-space links and one-to-many QKD networks where SNR varies quickly."],"supporting_citations":[{"why":"Introduces Raptor codes, the rateless code family the protocol is built on.","marker":"[48]"},{"why":"Supplies the multidimensional reconciliation method that turns the Gaussian channel into a virtual binary-input AWGN channel and gives the no-leakage condition for the mapping function.","marker":"[40]"},{"why":"Provides the EXIT-chart design method for Raptor degree distributions on binary-input Gaussian channels, used to optimize the code.","marker":"[50]"},{"why":"Gives low-SNR Raptor-code design techniques that support the low-rate distributions used here.","marker":"[52]"},{"why":"Provides a fixed-rate quasi-cyclic MET-LDPC baseline whose efficiency drop motivates the rateless approach.","marker":"[36]"},{"why":"Provides a fixed-rate MET-LDPC long-distance baseline used for comparison of reconciliation efficiency.","marker":"[38]"},{"why":"Supplies the finite-size secret key rate formula used to compute the reported key rates.","marker":"[41]"},{"why":"Shows how to use all raw data for both parameter estimation and key extraction, the postprocessing choice that doubles the simulated key rate.","marker":"[37]"},{"why":"Gives experimental long-distance CV-QKD results used as a comparison point for the simulated secret key rate.","marker":"[13]"}],"fun_headline_variants":["One rateless code adapts CV-QKD to any SNR","Raptor codes lift CV-QKD reconciliation to 98% at low SNR","CV-QKD goes rateless: >95% efficiency across -20 to 0 dB","Rateless reconciliation pushes CV-QKD to 132 km","Adaptive Raptor protocol boosts CV-QKD key rate at all distances"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The entire scheme rests on the assumption that SNR-driven switching among four degree distributions leaves Bob's code word uniformly distributed and independent of the public mapping function $M(y',c')$, the condition under which the no-leakage step of the proof holds; the switching behavior itself is not analyzed.","fun_headline_variants_meta":{"raw":{"variants":["One rateless code adapts CV-QKD to any SNR","Raptor codes lift CV-QKD reconciliation to 98% at low SNR","CV-QKD goes rateless: >95% efficiency across -20 to 0 dB","Rateless reconciliation pushes CV-QKD to 132 km","Adaptive Raptor protocol boosts CV-QKD key rate at all distances"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00063,"raw_usage":{"total_tokens":2948,"prompt_tokens":1020,"completion_tokens":1928,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":636,"completion_tokens_details":{"reasoning_tokens":1830}},"tokens_in":636,"tokens_out":1928,"duration_ms":14251,"temperature":1.0,"reasoning_tokens":1830,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T13:40:20.368425+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the proposed protocol at a mid-envelope SNR such as -10 dB with k=9900 and measure the realized Raptor rate $R(\\gamma)$: if $\\beta=R(\\gamma)/C(\\gamma)$ falls below 95% at any point in [-20, 0] dB, the efficiency claim fails. Alternatively, compute the mutual information $I(c';M(y',c'))$ across a degree-distribution switch; a nonzero value would break the security argument.","supporting_citations":[{"cited_title":"Chung, G","cited_arxiv_id":null,"evidence_quote":"Introduces Raptor codes, the rateless code family the protocol is built on."},{"cited_title":"Zhang, Z","cited_arxiv_id":null,"evidence_quote":"Supplies the multidimensional reconciliation method that turns the Gaussian channel into a virtual binary-input AWGN channel and gives the no-leakage condition for the mapping function."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the EXIT-chart design method for Raptor degree distributions on binary-input Gaussian channels, used to optimize the code."},{"cited_title":"Zhang, J","cited_arxiv_id":null,"evidence_quote":"Supplies the finite-size secret key rate formula used to compute the reported key rates."},{"cited_title":"Pirandola, R","cited_arxiv_id":null,"evidence_quote":"Shows how to use all raw data for both parameter estimation and key extraction, the postprocessing choice that doubles the simulated key rate."}],"review_version":1}