{"id":"e348c5d2-5f21-433c-bb97-0df302138b57","arxiv_id":"2411.14817","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A continuous-variable source-independent QRNG security proof using finite-dimensional SDP is proposed and simulated for time-multiplexed photon detection.","lead":"This paper proposes a security proof for a quantum random number generator that uses a single phase-insensitive light detector while trusting only the detector, not the light source. A dimension-reduction technique turns the infinite-dimensional security calculation into a finite optimization that can be solved on a computer.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Eq. (13) is not a valid dual of Eq. (12): the always-feasible point λ=η=ξ=0 has objective 0, while the primal can be 0.9, so the certified-bound claim d*_N ≥ p* fails as written.","rationale":"The reader's weakest_assumption concerns single-mode sources and exact ⟨n⟩ estimation. My concern is more basic: even in the idealized single-mode, exactly-known-⟨n⟩ regime, the dual problem printed as Eq. (13) is not a valid upper bound on the primal Eq. (12). The zero dual point with objective 0 is always feasible, while the primal optimum is positive for any phase-insensitive POVM that has a nonzero outcome probability (e.g., the two-outcome detector above). Since Eq. (15) uses d*_N from Eq. (13), the central claim is unproved as written. The flaw is nevertheless fixable: a standard Lagrange-dual derivation gives an objective with an extra +1 and different sign arrangement, so the underlying dimension-reduction method may survive revision. Because the error is correctable and the reader already returned CONDITIONAL, I do not move the verdict; I only flag that the proof obstacle is located in the dual construction, not primarily in the physical assumptions. The concrete two-outcome test settles the issue immediately.","tokens_in":7597,"tokens_out":21469,"duration_ms":217572,"concrete_test":"Solve Eq. (12) and Eq. (13) for the POVM M_1=0.9 I, M_2=0.1 I, N=20, ⟨n⟩=0, vacuum statistics p_1=0.9, p_2=0.1. If the Eq. (13) optimum is not ≥0.9 (it is ≤0 because all zero dual variables are feasible), the claimed d*_N ≥ p* is false. Independently, re-derive the Lagrange dual of Eq. (12) with standard sign conventions and compare: the printed objective omits the +1 constant and has the wrong signs on the λ, η, and (λ−η) terms.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim (Eq. 15) uses d*_N from Eq. (13) as a certified upper bound on the guessing probability. As printed, Eq. (13) does not satisfy weak duality with Eq. (12). The point λ=η=ξ=0 is always feasible in Eq. (13), because the constraint becomes M_{k,N} − I ⪯ 0, which holds since M_{k,N} ≤ I; the objective is 0. But the primal Eq. (12) can have positive optimum. Concretely, take m=2, M_1=0.9 I, M_2=0.1 I, N=20, ⟨n⟩=0, and vacuum statistics p_1=0.9, p_2=0.1. Then Eq. (12) has value 0.9 (ρ_1=|0⟩⟨0|), so 0 is not an upper bound. A standard Lagrange dual of Eq. (12), with λ for the upper constraints and η for the lower constraints, is minimize 1 + Σ_j λ_j p_j − Σ_j η_j pL_j + ξ subject to M_{k,N} + Σ_j(η_j−λ_j)M_{j,N} − (ξ+1)I ⪯ 0; Eq. (13) has the opposite signs and misses the +1. Since d*_N is exactly the quantity certified in Eq. (15), this invalidates the security proof as written; the flaw is present even in the idealized single-mode, exactly-known-⟨n⟩ setting.","agreement_with_reader":"disagree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript proposes a continuous-variable source-independent quantum random number generator (CV-SI-QRNG) that uses a single phase-insensitive detector whose POVM elements are diagonal in the Fock basis. To avoid squashing models, the authors introduce a dimension-reduction technique: they project the infinite-dimensional optimization for the guessing probability onto the subspace of photon numbers below a cutoff N, bound the tail weight outside this subspace by the mean photon number divided by N, and formulate a finite-dimensional SDP (Eq. (12)) with constraints derived from the observed probabilities. They then give a claimed dual SDP (Eq. (13)) and assert that its optimal value d*_N provides a rigorous upper bound on the original infinite-dimensional guessing probability, leading to the min-entropy bound H_min >= -log2 d*_N (Eq. (15)). The protocol is simulated for a time-multiplexed single-photon detector with weak coherent states and parameters N=20, m=10, Nmode=2^5, yielding min-entropy lower bounds above 10^-2 bits per sample for mean photon numbers below 1. The central claim is that the finite-dimensional SDP and its dual certify security against arbitrary source states compatible with the observed statistics and mean photon number.","tokens_in":7939,"tokens_out":16662,"duration_ms":164467,"significance":"If the proof can be corrected, the result would be a useful step: it would extend numerical security analysis to infinite-dimensional CV-SI-QRNGs without restrictive squashing assumptions, for a broad class of phase-insensitive detectors, using only standard SDP duality and no fitted parameters. The proposed implementation with a single time-multiplexed detector is experimentally simple, and the simulation gives a concrete, falsifiable prediction of the achievable min-entropy rate. However, the manuscript as printed contains load-bearing mathematical errors in Eqs. (8), (11), and (13), so the security claim is not currently established; the significance is therefore conditional on a successful correction.","major_comments":[{"comment":"Eq. (13) is not a valid dual of Eq. (12). The point λ=η=ξ=0 is always feasible in Eq. (13) because its constraint reduces to M_{k,N} − I ⪯ 0, and the objective at that point is 0. However, the primal Eq. (12) can have positive optimal value; for example, with m=2, M_1=0.9 I, M_2=0.1 I, N=20, ⟨n⟩=0, and p=(0.9,0.1), the feasible choice ρ_1=|0⟩⟨0|, ρ_2=0 gives objective 0.9. Hence the claimed inequality d*_N ≥ p* cannot be true, and Eq. (15) is unsupported as printed. The Lagrange derivation in Appendix A contains algebraic errors: starting from Eq. (A1), the constant term and the signs in the coefficient of ρ_{k,N} lead to a different dual, namely min_{λ,η,ξ≥0} 1 + Σ_j λ_j p_j − Σ_j η_j p^L_j + ξ subject to M_{k,N} + Σ_j(η_j − λ_j)M_{j,N} − (1 + ξ)I ⪯ 0 (with λ for the upper constraints and η for the lower constraints). The printed Eqs. (A4), (A5), and (13) have the wrong signs on the probability terms and are missing the constant 1.","section":"IV, Eq. (13) and Appendix A"},{"comment":"The second equality in Eq. (8) is not generally valid. It asserts Σ_k tr(ρ*_{k,bar N} M_{k,bar N}) = 1 − Σ_k tr(ρ*_{k,N}), which would require each M_{k,bar N} to be the identity on the tail subspace. In general only the inequality Σ_k tr(ρ*_{k,bar N} M_{k,bar N}) ≤ Σ_k tr(ρ*_{k,bar N}) = 1 − Σ_k tr(ρ*_{k,N}) holds, since Σ_k M_{k,bar N} = I_{bar N} and each M_{k,bar N} ⪯ I_{bar N}. The desired upper bound can be repaired by replacing the equality with this inequality, but as written the derivation is mathematically incorrect.","section":"IV, Eq. (8)"},{"comment":"The dual problem stated in Eq. (11) has the wrong objective sign. For the maximization max tr(ρ bar P) subject to tr(ρ a†a) = ⟨n⟩ and trρ = 1, the standard Lagrange dual is min_{x,y∈R} x + y⟨n⟩ subject to bar P − xI − y a†a ⪯ 0. The feasible point x=0, y=1/N then gives the upper bound ⟨n⟩/N on the tail weight, as used in the text. With the printed objective −x−y⟨n⟩, the same feasible point gives −⟨n⟩/N, so the claimed tail bound does not follow from the displayed dual.","section":"IV, Eqs. (10)-(11)"},{"comment":"The tail bound relies on an exact value of the mean photon number ⟨n⟩. The protocol (step 3) only says that ⟨n⟩ is \"well estimated\" by a phase-insensitive detector. If ⟨n⟩ is merely estimated from data, an underestimation makes the constraint p^L_j too large, so the finite SDP Eq. (12) need not contain the projection of the true feasible set and d*_N can fail to be an upper bound. The manuscript should either state explicitly that ⟨n⟩ is a known a priori upper bound on the source's mean photon number, or incorporate finite-sample or uncertainty bounds on ⟨n⟩ into p^L_j. This assumption is load-bearing, not merely a practical detail.","section":"IV, Eq. (12) and protocol step 3"},{"comment":"The optimization in Eq. (10) and the POVM model in Eq. (6) assume the source is a single bosonic mode. The security claim in Eq. (15) is phrased for \"any source state compatible with observed statistics\"; if the physical source emits light in several modes and the detector collects all of them, the operator a†a in Eq. (10) must be replaced by the total photon-number operator of the relevant modes and the tail bound may no longer scale as ⟨n⟩/N. The single-mode assumption should be stated as an explicit protocol assumption, and the multi-mode case should be either analyzed or explicitly excluded.","section":"IV, Eq. (10)"}],"minor_comments":[{"comment":"In the first constraint, the summation index j is reused for the measurement outcome j; it should be Σ_k ρ_k rather than Σ_j ρ_j.","section":"II.B, Eq. (5)"},{"comment":"The non-projective condition is stated as \"the spectrum norm of an arbitrary POVM element M_j should be less than 1\"; since the M_j are positive, this should be written as ||M_j||∞ < 1, and the completeness relation Σ_j M_j = I should be stated explicitly.","section":"III, Eq. (6)"},{"comment":"The symbols ρ*_{k,N}, M_{k,N}, and bar N are used in Eq. (8) before their definition in the following sentence; the notation should be introduced before the equation. The word \"POP\" in the explanation after Eq. (8) appears to be a typo.","section":"IV, Eq. (8)"},{"comment":"The figure reports only a single curve; no solver, SDP tolerance, or verification of the dual bound is given, and the label \"lg(R)\" should state the base of the logarithm and clarify that the quantity is the min-entropy per sample.","section":"V, Fig. 2"},{"comment":"There are several typographical errors, including \"N umber\" in the title, \"aﬀact\" in Section III, and \"Arbitraty\" in Section III; these should be corrected.","section":"Title and throughout"}],"recommendation":"major_revision","confidential_remarks":"The paper's core idea is promising and the errors appear localized and correctable, so I am not recommending rejection. However, the counterexample to Eq. (13) is decisive as printed: the displayed dual does not even satisfy weak duality with the primal. The authors should re-derive the Lagrange dual, fix the sign and constant errors, and re-verify the chain of inequalities in Eqs. (8)-(12) before the security claim can be taken seriously. I would also ask the authors to state the single-mode and exact-mean-photon-number assumptions explicitly in the protocol definition."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The core idea here is sensible and worth pursuing: combine the dimension-reduction trick from Upadhyaya et al. with a single phase-insensitive detector to get a CV-SI-QRNG that avoids squashing models. The identification of diagonal-Fock POVMs as the compatible class is a genuine, practically useful observation, and the time-multiplexed detector simulation is a reasonable illustration of the framework. That part I like.\n\nThe problem is that the security proof, as printed, does not work. The reader's stress-test is correct: Eq. (13) is not a valid dual of Eq. (12). Take m=2, M1=0.9I, M2=0.1I, N=20, nbar=0, and vacuum statistics p1=0.9, p2=0.1. The primal has value 0.9 (rho1=|0><0|), but lambda=eta=xi=0 is feasible in Eq. (13) with objective 0. So the claimed certified bound d*_N >= p* fails even in the idealized single-mode, exactly-estimated-nbar setting. The sign errors in the Lagrange derivation in Appendix A are the source; Eq. (A3) has both the eta-lambda sign and the xi term wrong. This is a load-bearing flaw, not a typo, because Eq. (15) uses d*_N as the min-entropy bound.\n\nThere are also two smaller proof issues that point the same direction. Eq. (8) states an equality between the tail contribution and 1 - sum tr(rho*_{k,N}), but the correct relation is an inequality (each M_{k,Nbar} <= I). And Eq. (11) has a sign error in the dual objective: the correct dual is min x + y<n>, not -x - y<n>. The feasible point x=0, y=1/N still gives the intended n/N bound, so that one is cosmetic. Eq. (8) is more serious but fixable by changing the equality to <= and adjusting the subsequent optimization accordingly.\n\nThe good news is that the high-level approach is sound. The dimension reduction for diagonal POVMs is the right tool, and the errors are localized enough that a careful rewrite of Section IV could repair the proof. The novelty claim is a bit inflated—the technique itself is from [20]—but the specific assembly with a phase-insensitive detector is new.\n\nThis paper deserves a serious referee. The idea is good, the field would benefit from a correct version, and the current flaws are identifiable and correctable. I would not cite the current version or trust its bounds, but I would send it to review with a clear request to fix the dual formulation and the inequality in Eq. (8).","headline":"Promising protocol and the right dimension-reduction idea, but the central security proof as printed is not valid: the dual in Eq. (13) does not bound the primal, and Eq. (8) states an equality that is only an inequality.","tokens_in":8471,"tokens_out":4013,"would_cite":false,"duration_ms":39577,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A single phase-insensitive detector can certify randomness from an untrusted source.","keywords":["source-independent quantum random number generator","continuous-variable quantum cryptography","semi-definite programming","phase-insensitive detector","dimension reduction","min-entropy","Fock basis","time-multiplexed detector"],"falsifier":"Use a two-mode source engineered to give the same single-mode click probabilities and mean photon number while placing more than $\\langle n\\rangle/N$ weight above the cutoff; if its true guessing probability exceeds $d^*_N$, the finite-dimensional constraints have missed part of the feasible set.","tokens_in":1494,"feed_emoji":"🎲","tokens_out":4348,"duration_ms":108297,"temperature":0.7,"pith_summary":"This paper proposes a source-independent quantum random number generator that uses only a single phase-insensitive optical detector, such as a single-photon detector, and proves its security with semidefinite programming. The technical core is a dimension-reduction argument: because the detector's POVM is diagonal in the Fock basis, the infinite-dimensional guessing-probability optimization can be rigorously bounded by a finite-dimensional SDP whose optimum gives a guaranteed lower bound on the min-entropy. The bound holds for any source state compatible with the observed detection statistics and with the estimated mean photon number. Simulated time-multiplexed single-photon detection shows extraction rates above $10^{-2}$ bits per sample for typical weak coherent states. The scheme matters because it removes the need for conjugate measurements or a squashing model and simplifies practical implementation.","feed_headline":"One detector turns untrusted light into provable random numbers","feed_subtitle":"A finite SDP bound reduces the infinite-dimensional security problem, certifying min-entropy from phase-insensitive clicks.","key_machinery":"The load-bearing object is a dimension-reduction bound on the probability weight of a source state living above $N$ photons. For a POVM diagonal in the Fock basis, the projection onto $N$ photons commutes with each $M_j$; Hölder's inequality gives $\\operatorname{tr}(M_j \\bar P \\rho \\bar P) \\le \\|\\rho_{\\bar N}\\|_1 \\|M_{j,\\bar N}\\|_\\infty$, and the tail weight $\\|\\rho_{\\bar N}\\|_1$ is bounded by $\\langle n\\rangle/N$ via the dual program Eq. (11) with feasible point $x=0$, $y=1/N$. These two inequalities turn the infinite-dimensional SDP (5) into the finite-dimensional SDP (12), whose dual (13) is solved to obtain $d^*_N$.","core_discovery":"The central claim is that for any single-mode source state whose photon-number statistics match the observed outcomes and whose mean photon number is $\\langle n\\rangle$, the optimal value $d^*_N$ of the finite-dimensional SDP in Eq. (12), and its dual in Eq. (13), is an upper bound on the guessing probability of the infinite-dimensional problem, so $H_{\\min}(A|E) \\ge -\\log_2 d^*_N$. The argument splits each optimal sub-state into an $N$-photon part and a tail; the tail contributes at most $\\langle n\\rangle/N$ through the feasible point $x=0$, $y=1/N$ of the dual tail-weight program, and that slack is folded into loosened constraints. The bound is therefore valid even though the optimization is truncated to photon numbers below $N$.","pith_inferences":["A possible extension is to replace the single-mode tail bound with a multi-mode bound, tracking the photon-number operator per mode; the single-mode assumption is load-bearing in the present proof.","The asymptotic argument could be turned into a finite-size bound by estimating the mean photon number and outcome probabilities from a finite block and propagating confidence intervals through the loosened constraint, which the paper does not carry out.","The same projection-and-tail idea may extend to POVMs that are not Fock-diagonal if off-diagonal terms are bounded separately, which would broaden the detector classes beyond phase-insensitive ones."],"forward_implications":["Any source state compatible with the measured outcome probabilities and mean photon number is covered by the same bound, so the security statement is not tied to the coherent-state simulation.","Detectors whose POVM elements are diagonal in the Fock basis, including common single-photon detectors, can serve as the measurement, so no squashing model is needed.","The randomness yield per sample is at least $-\\log_2 d^*_N$ in the asymptotic limit, and solving the dual problem avoids relying on the exact optimum of the truncated primal under finite precision.","The simulation indicates that with a time-multiplexed detector and weak coherent states the lower bound exceeds $10^{-2}$ bits per sample, pointing to practical rates."],"supporting_citations":[{"why":"Supplies the dimension-reduction technique used to replace the infinite-dimensional SDP with a finite-dimensional one.","marker":"[20]"},{"why":"Establishes the SDP-based numerical framework for SI-QRNG security analysis that this work adapts to continuous variables.","marker":"[17]"},{"why":"Shows general non-projective POVMs can certify source-independent randomness, the starting point for using phase-insensitive detectors.","marker":"[14]"},{"why":"Introduces the source-independent QRNG paradigm with conjugate measurements that the phase-insensitive protocol generalizes.","marker":"[8]"},{"why":"Supplies the time-multiplexed detector photon-counting model, including Stirling-number statistics, used in the simulations.","marker":"[21]"}],"fun_headline_variants":["Single detector, provable randomness from untrusted sources","One detector suffices for source-independent quantum randomness","Finite SDP bound secures randomness with one detector","Provable random numbers from a single phase-insensitive detector","Untrusted light, one detector, certified min-entropy"],"cache_read_input_tokens":10496,"weakest_assumption_plain":"The proof assumes the source is a single optical mode and that the mean photon number is known exactly, because the tail-weight bound $\\langle n\\rangle/N$ relies on that dual feasible point.","fun_headline_variants_meta":{"raw":{"variants":["Single detector, provable randomness from untrusted sources","One detector suffices for source-independent quantum randomness","Finite SDP bound secures randomness with one detector","Provable random numbers from a single phase-insensitive detector","Untrusted light, one detector, certified min-entropy"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000201,"raw_usage":{"total_tokens":1354,"prompt_tokens":896,"completion_tokens":458,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":512,"completion_tokens_details":{"reasoning_tokens":380}},"tokens_in":512,"tokens_out":458,"duration_ms":4208,"temperature":1.0,"reasoning_tokens":380,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T14:51:48.432692+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Use a two-mode source engineered to give the same single-mode click probabilities and mean photon number while placing more than $\\langle n\\rangle/N$ weight above the cutoff; if its true guessing probability exceeds $d^*_N$, the finite-dimensional constraints have missed part of the feasible set.","supporting_citations":[{"cited_title":"ˇSupi´ c, P","cited_arxiv_id":null,"evidence_quote":"Supplies the dimension-reduction technique used to replace the infinite-dimensional SDP with a finite-dimensional one."},{"cited_title":"Nie, J.-Y","cited_arxiv_id":null,"evidence_quote":"Establishes the SDP-based numerical framework for SI-QRNG security analysis that this work adapts to continuous variables."},{"cited_title":"Chaturvedi and M","cited_arxiv_id":null,"evidence_quote":"Shows general non-projective POVMs can certify source-independent randomness, the starting point for using phase-insensitive detectors."},{"cited_title":"( 8), which means the asymptotic randomness per sample has a lower bound Hmin(A|E) ≥ − log2d∗ N","cited_arxiv_id":null,"evidence_quote":"Introduces the source-independent QRNG paradigm with conjugate measurements that the phase-insensitive protocol generalizes."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the time-multiplexed detector photon-counting model, including Stirling-number statistics, used in the simulations."}],"review_version":1}