{"id":"a6351564-97a2-4123-afd1-b4e59098cc12","arxiv_id":"2411.19874","paper_version":2,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A security proof for QKD with basis-dependent detection probabilities, using a tunable beam splitter to bound phase error without assuming basis-independent detection.","lead":"Quantum key distribution gets a security proof that works even when the receiver's two measurement bases have different detection efficiencies, a common hardware flaw attackers can exploit. The protocol uses a fast-switchable beam splitter to detect whether an eavesdropper is actually using the mismatch, instead of assuming the worst case forever.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The proof's central claim is conditional on the TBS being adversary-uninfluenceable and mode-independent; if Eve can tailor modes to which the TBS responds differently, the detector-decoy equations and the phase-error bound (42) break down.","rationale":"The paper is a technically substantial and internally consistent security proof. The main request is to drop the assumption that detection probability is basis-independent, and the authors do this by actively estimating the relevant quantities via TBS statistics and the detector-decoy technique. The derivation is detailed and the simulations support the claims. The weakest point is the TBS model: the proof requires the TBS to be mode-independent and not adversary-controlled. The reader correctly identified this as the weakest assumption, and the manuscript explicitly states it and lists relaxation as future work. This is a genuine boundary on the applicability of the central claim, but it is not a hidden flaw, circular step, or internal contradiction. The key rate expression (17) and the phase-error bound (42) are derived under that explicit assumption, and the attack simulations are consistent with the proof. Therefore, the reader's ACCEPT verdict with moderate confidence remains appropriate; no change to the verdict is needed. A concrete test of the mode-dependence assumption would clarify the practical scope of the claimed result, but it would not invalidate the proof within its stated model.","tokens_in":76588,"tokens_out":25554,"duration_ms":250594,"concrete_test":"Simulate the protocol for d=2 with a deliberately mode-dependent TBS, e.g., η_i(ω) = η_i + δ·(ω-ω0)/Δω inside Z, and let Eve send narrowband pulses at frequencies where η↓ differs from its nominal value. Generate the full protocol statistics under this model, compute the true phase error rate, and evaluate the upper bound (42) using those statistics. If the bound falls below the true phase error for any nonzero δ, the mode-independence assumption is necessary for security, confirming that the paper's central claim is strictly conditional on that assumption.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The security argument hinges on the tunable beam splitter (TBS) satisfying a very specific model: its transmittance inside the Z window is exactly η_i for every optical mode, and outside Z it is exactly η_l, with no adversarial influence. This assumption is stated in Sec. IIIB and is used throughout Appendix C4 to derive the detector-decoy equations, e.g., Eq. (C186) and the bounds on w>1_Z (B5), w0_Z, and w1_Z. These equations assume that the probability of a Z-basis click given α photons localized in Z is p✓|α = 1 - (1 - pZ_d) η↓^α (Eq. C181). If the TBS transmittance is mode-dependent, as is plausible for a wavelength-sensitive modulator in the time-frequency QKD setups the paper targets, then different optical modes inside Z experience different effective η↓, and the simple α-photon coefficient η↓^α is replaced by a product of per-mode transmittances. The detector-decoy bounds then no longer upper-bound the true weights of the received state in the (≤1)-photon subspace, and the phase-error bound (42) is not guaranteed to be valid. The paper explicitly acknowledges this assumption and lists relaxing it as future work, so this is a stated boundary of the central claim rather than an internal inconsistency; however, it is directly load-bearing because the claimed elimination of a priori characterization of detection-efficiency mismatch is contingent on this idealized TBS.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper presents an analytical security proof for prepare-and-measure QKD protocols that drops the usual assumption that the detection probability of a state is independent of the measurement basis. The receiver incorporates a high-speed tunable beam splitter (TBS) that is switched between seven settings per round, and the security proof combines the decoy-state method, an entropic uncertainty relation, and a detector-decoy technique to bound the phase error rate in terms of observed statistics. The asymptotic key rate is given in Eq. (17) and is shown to be a lower bound on the Devetak-Winter rate under collective attacks. Simulations on a four-dimensional time-bin QKD setup show that the protocol yields positive key rates for honest implementations and detects a tailored intercept-resend attack that induces a detection efficiency mismatch, whereas a standard BB84 key rate overestimates the secure key rate in that scenario. The proof is self-contained and the mathematical steps are detailed in the appendices.","tokens_in":76956,"tokens_out":4769,"duration_ms":45853,"significance":"If correct, this is a significant result for implementation security of QKD: it provides a provably secure protocol that is robust to detection efficiency mismatches, including adversary-induced mode-dependent mismatches, without requiring a prior worst-case characterization of the efficiency mismatch. The analytical derivation is detailed and the simulation study is informative, illustrating both the achievable positive key rates and the protocol's ability to reduce the key rate in proportion to an active attack. The main limitation is clearly stated: the security proof assumes that the TBS is mode-independent and cannot be influenced by the adversary; this is a reasonable trust assumption for Bob's apparatus and is identified as future work. The paper is a valuable contribution to the QKD security literature.","major_comments":[],"minor_comments":[{"comment":"The assumption that the TBS is mode-independent and adversary-uninfluenceable is crucial for the derivation of the detector-decoy equations, e.g., Eq. (C181) and the bound on w>1_Z in Eq. (B5). Since this is a load-bearing boundary of the central claim, it should be stated more prominently in the abstract and in Sec. VII, and the physical conditions under which it could be violated (e.g., a wavelength-dependent TBS in time-frequency QKD) should be discussed explicitly.","section":"Sec. IIIB"},{"comment":"The discussion correctly attributes the gap to the decoy-BB84 rate in Fig. 4 to the looseness of the bound on w>1_Z, Eq. (B5). It would be helpful to state this earlier, near Eq. (B5), and to comment on whether additional decoy intensities or a different estimator could tighten the bound and reduce the gap.","section":"Sec. VI"},{"comment":"The simulation sets the decoy intensities to µ2 = 2µ3 = 2·10^-6 and pµ1 = 1, which corresponds to an asymptotic regime. A brief comment on the experimental feasibility of these parameters, and on the finite-key behavior if these extremes are relaxed, would strengthen the practical relevance of the simulations.","section":"Sec. VA"},{"comment":"The colorbar/contour levels in Fig. 3 are not described in the caption; the reader cannot easily read off the tolerable loss values. Please add a short description of the color scale or use explicit contour labels.","section":"Fig. 3"},{"comment":"The notation ~e_X,1 (phase error rate) and e_X,1 (bit error rate) is used throughout; please ensure that the tilde is not accidentally dropped in any formula, and that Appendix B is fully consistent with the main text definitions.","section":"General"}],"recommendation":"minor_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The short version: this is a real step forward in QKD security proofs. It removes the long-standing basis-independent detection assumption by measuring the mismatch during the protocol with a tunable beam splitter and detector decoys, instead of characterizing the worst-case mismatch in advance. The proof chain from Devetak-Winter through the uncertainty relation to the phase-error bound is present, and the simulations show the rate adapting to an active attack rather than being penalized in honest runs. I checked the stress-test note against the paper and the main concern is accurate but not fatal: the security now leans on the TBS being adversary-uninfluenceable and mode-independent, stated in Sec. IIIB and used in the p_click|alpha formulas in Appendix C4. If Eve can craft modes with different TBS transmittance, the detector-decoy equations and the phase-error bound break. The authors flag this themselves and list it as future work, so it is a stated boundary rather than an internal contradiction. That said, it undercuts the advertising a bit: the proof still needs a strong component trust assumption, just a different one from previous work.\n\nWhat the paper does well: it is the first to estimate detection-efficiency mismatch in real time from TBS statistics; it handles multi-photon states and mode-dependent mismatches; the decoy-state and subspace-reduction steps are laid out in enough detail to be checked; and the honest-implementation gap traced to the loose w>1_Z bound is correctly diagnosed. No circularity in the key rate derivation. Self-citations are only to the authors' own experimental setups and do not carry the security proof.\n\nSoft spots in proportion: the TBS assumption is load-bearing, so it deserves a named threat model rather than a brief paragraph. The w>1_Z bound is loose and produces an unexplained rate penalty in honest runs; the paper says a tighter bound would close the gap, so this is about efficiency, not validity. The proof is asymptotic and collective-attack only; the authors note that de Finetti-type reductions do not obviously apply given the infinite-dimensional mode structure, which limits practical use until finite-key analysis appears. The appendix algebra is dense and I did not rederive all of it, so a thorough referee should spend real time on Appendix C.\n\nWho should read this: QKD security theorists, and experimentalists working on time-bin or time-frequency setups. It deserves a serious, detailed referee, not a desk reject. I would want the TBS assumption handled more carefully in revision either a clear hardware-enforced model or an explicit attack if the mode-independence is violated.\n\nRecommendation: send to peer review with a demanding referee.","headline":"The proof genuinely drops basis-independent detection by estimating mismatches in real time, and it holds at the level of its stated assumptions, but the security now rests on a TBS trust assumption that is acknowledged and unresolved.","tokens_in":77501,"tokens_out":2619,"would_cite":true,"duration_ms":25773,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper proves security of prepare-and-measure QKD when detection probability depends on the measurement basis, using a tunable beam splitter to estimate the phase error rate from observed statistics instead of assuming the worst case.","keywords":["quantum key distribution","basis-dependent detection probability","phase error rate","tunable beam splitter","decoy-state method","detector decoy technique","collective attacks","time-bin QKD"],"falsifier":"An experiment in which Eve can modulate the tunable beam splitter's transmittance as a function of the incoming optical mode would test the proof's boundary: if that control kept the apparent key rate positive while Eve could predict the key, the security claim would be false.","tokens_in":76415,"feed_emoji":"🔑","tokens_out":8749,"duration_ms":76666,"temperature":0.7,"pith_summary":"Quantum key distribution proofs usually assume that Bob's chance of detecting a given incoming state does not depend on which measurement basis he uses. The authors drop that assumption. They prove that a prepare-and-measure protocol with two measurement bases remains secure under collective attacks even when an adversary induces basis-dependent detection efficiencies, provided Bob adds a fast tunable beam splitter and uses its statistics to estimate the phase error rate in real time. The asymptotic key rate they derive is a lower bound on the standard secret-key rate for collective attacks, and their simulations show positive rates for honest time-bin setups that previous worst-case proofs would penalize. The point is that the protocol monitors whether an eavesdropper is actively exploiting the efficiency mismatch instead of assuming the worst case.","feed_headline":"QKD stays secure when detection favors one basis","feed_subtitle":"A tunable beam splitter measures, not assumes, detector-efficiency mismatch, keeping positive key rates for honest systems.","key_machinery":"The load-bearing object is the tunable beam splitter (TBS), a beam splitter whose transmittance $(\\eta_i,\\eta_l)$ can be switched inside and outside the key-detection window $Z$ within a single round. It turns the $Z$-basis detector's click POVM into the diagonal operator $Z_{\\checkmark}=\\sum_{\\alpha\\ge0}p_{\\checkmark|\\alpha}\\Pi^\\alpha_Z$ with $p_{\\checkmark|\\alpha}=1-(1-p_Z^d)\\eta_\\downarrow^\\alpha$, so the seven TBS settings act as detector decoys that reveal how much of Bob's received state lies in the zero-, one-, and multi-photon sectors of $Z$. The proof reduces the phase error rate to the at-most-one-photon subspace, bounds the leftover weight $w_{>1}^Z$ via a linear system, and expresses the phase-error bound (42) in terms of observed gains and QBERs; an uncertainty relation with the compatibility coefficient $c=\\max_{j,k}|\\langle 1_{Z_j}|S^{-1}|1_{X_k}\\rangle|^2$ then converts this into Eve's conditional entropy.","core_discovery":"This paper's central claim is that the usual assumption $Z_{\\checkmark}=X_{\\checkmark}$, that a click is equally likely in either measurement basis for every input state, can be dropped without losing security. For phase-randomized coherent states with three intensities and $d$-outcome bases satisfying the single-photon basis-independence condition (7), the authors construct a protocol in which Bob routes each received signal through a tunable beam splitter whose transmittance differs inside and outside the key-detection window. From the gains and error rates of the seven TBS settings, together with the decoy-state method, they upper-bound the phase error rate $\\tilde e_{X,1}$ and prove that the key rate (17) is a lower bound on the asymptotic secret-key rate under collective attacks. The proof needs no a priori characterization of mode-dependent detection efficiencies; instead it estimates the weight of Eve's states outside the at-most-one-photon-in-$Z$ subspace and solves linear systems that isolate the TBS's effect on zero- and one-photon components. Simulations on a four-dimensional time-bin setup show positive key rates up to 30 dB loss for honest implementations, while an intercept-resend attack that steers clicks into one basis lowers the proved rate proportionately.","pith_inferences":["Inference: the same real-time-monitoring strategy could be adapted to other implementation flaws, such as basis-dependent source leakage, by inserting a fast switchable element and estimating the leakage parameter from the augmented statistics rather than bounding it a priori.","Inference: the paper's observation that the honest-implementation gap comes from the $w_{>1}^Z$ bound suggests a concrete test: increasing the number of decoy intensities should tighten the gap to decoy-BB84, which could be verified in simulation without new hardware.","Inference: because the proof does not restrict Bob's received states to a finite dimension, standard reductions to finite-dimensional symmetries are not available; a plausible path to coherent-attack security is an entropic uncertainty-relation argument, which the authors leave open."],"forward_implications":["Real QKD devices with unequal nominal detector efficiencies or dark-count rates no longer need their efficiency mismatch fully characterized before a secure key can be certified.","In honest implementations the new proof returns key rates close to the standard decoy-BB84 rate; the gap seen in simulations is attributed to a non-tight bound on the multi-photon weight $w_{>1}^Z$ rather than to the protocol itself.","Against an intercept-resend attack that steers which basis clicks, the proved key rate tracks the true extractable key, while the BB84 rate can overestimate it by more than ten percentage points.","The protocol applies to any two-basis setup in which one basis is a time-of-arrival measurement and the TBS can be tuned along the measured degree of freedom, including time-bin and time-frequency QKD."],"supporting_citations":[{"why":"Supplies the entropic uncertainty relation with quantum memory and the compatibility-coefficient reduction that lower-bounds Eve's conditional entropy in the single-photon rounds.","marker":"[8]"},{"why":"Detector decoy technique used to estimate the photon-number weights of the states Bob receives from the Z-basis detection statistics at different TBS settings.","marker":"[28]"},{"why":"Decoy-state method used to turn the three-intensity gains and QBERs into bounds on one-photon yields and error rates.","marker":"[37-39]"},{"why":"Defines the asymptotic secret-key-rate expression under collective attacks that the protocol's key rate is proven to lower-bound.","marker":"[46]"},{"why":"Earlier security proofs for detection-efficiency mismatch that require a priori characterization of the mismatch and therefore give pessimistic rates; the comparison baseline the paper improves on.","marker":"[33-36]"},{"why":"The experimental four-dimensional time-bin QKD setup whose parameters are used in the simulations of honest and attacked implementations.","marker":"[29, 30]"}],"fun_headline_variants":["Dropping basis-independence assumption keeps QKD secure","Tunable beam splitter neutralizes detector-bias loophole in QKD","Basis-dependent detection no longer breaks QKD key rate","Security proof for QKD with biased detector efficiencies"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the receiver's tunable beam splitter is outside the adversary's control and treats every optical mode the same way; if Eve could influence or mode-dependently alter its transmittance, the estimated phase-error bound could be biased.","fun_headline_variants_meta":{"raw":{"variants":["Dropping basis-independence assumption keeps QKD secure","Tunable beam splitter neutralizes detector-bias loophole in QKD","Basis-dependent detection no longer breaks QKD key rate","Security proof for QKD with biased detector efficiencies"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001046,"raw_usage":{"total_tokens":4404,"prompt_tokens":961,"completion_tokens":3443,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":577,"completion_tokens_details":{"reasoning_tokens":3373}},"tokens_in":577,"tokens_out":3443,"duration_ms":19992,"temperature":1.0,"reasoning_tokens":3373,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T05:43:16.947549+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"An experiment in which Eve can modulate the tunable beam splitter's transmittance as a function of the incoming optical mode would test the proof's boundary: if that control kept the apparent key rate positive while Eve could predict the key, the security claim would be false.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the entropic uncertainty relation with quantum memory and the compatibility-coefficient reduction that lower-bounds Eve's conditional entropy in the single-photon rounds."}],"review_version":1}