{"id":"eda2d7bd-b014-4434-9731-97863315047b","arxiv_id":"2412.09684","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":6,"one_line_summary":"The loss-tolerant QKD protocol remains secure under joint state preparation flaws and detection efficiency mismatch, with a computable asymptotic key rate bound.","lead":"This paper proves the security of a widely used quantum key distribution protocol when both the light source and the detectors are imperfect, and it measures the detection efficiency mismatch of two commercial detectors. The result makes it easier to certify real QKD installations without requiring perfectly matched detectors.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The virtual filter in Eq. (B20) requires invertible efficiency operators F0 and F1 (Assumption A5); real detectors with a zero-efficiency mode fall outside the theorem, so the claimed secure-key guarantee for actual implementations is conditional on an unverified spectral condition.","rationale":"The paper's goal is an asymptotic security proof for loss-tolerant QKD with both state preparation flaws and detection efficiency mismatch, plus a detector characterization. Read in good faith, the proof is detailed and appears internally consistent under Assumptions (A1)-(A6): the loss-tolerant inversion in Eq. (7), the virtual protocol, and the operator-inequality bounds in Appendix B all cohere. No formal verification, code, or raw data are supplied, and experimental uncertainties are not propagated, but those are completeness issues rather than flaws in the core argument.\n\nThe most load-bearing concern is the spectral requirement in Assumption (A5): the virtual filter G_BT in Eq. (B20) contains F0^{-1} and F1^{-1}, and the bounds in Eqs. (11), (15), and (17) rely on positive-definite efficiency operators. If a real detector has a mode with zero efficiency, the proof does not apply, and the paper does not prove that such cases cannot yield positive key. The experimental characterization measures only four polarization settings and does not certify positive-definiteness over all relevant modes. This matches the reader's weakest assumption, but I would sharpen it: a single efficiency-affecting mode T of arbitrary dimension already covers many multi-mode situations, so the real crux is factorization between the qubit B and T together with invertibility of F_s.\n\nThe concern is genuine but explicitly assumed, and the paper labels it as an assumption. Thus the appropriate verdict is the same conditional acceptance the reader gave: the result is a valid conditional theorem, with the open question being how broadly Assumption (A5) holds for deployed detectors. The proposed singular-efficiency test would settle whether the invertibility condition is merely technical or genuinely restricts the central claim.","tokens_in":30416,"tokens_out":11641,"duration_ms":128100,"concrete_test":"Analyze a minimal singular-efficiency example: take T as a qubit, F0 = diag(η0, 0), F1 = η1 1, and let Eve send every signal in the |1>_T mode. The protocol can in principle still generate key from D1 clicks, so compute the actual key rate by an independent direct method, then regularize as F0(ε) = F0 + ε 1, apply Eqs. (8)-(19) with F0(ε), and take ε → 0. If the bound tends to a positive value consistent with the independent rate, invertibility is a removable technical condition; if it tends to zero or becomes negative, or if the SDP becomes infeasible, then Assumption (A5) is load-bearing and the claimed applicability to real detectors requires a new argument beyond this paper.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central bound Eq. (12) is derived through the Procrustean virtual filter G_BT = |0Z><0Z|_B ⊗ C F0^{-1} + |1Z><1Z|_B ⊗ C F1^{-1} (Eq. B20). This operator is well defined only if the generalized efficiency operators F0 and F1 are invertible, and the operator inequalities Eq. (11) used to connect virtual to actual X statistics require finite λ±, which again needs the F_s to be positive definite. The paper assumes this in (A5) and cites Ref. [36] for the claim that no positive SKR is achievable otherwise, but no proof of that claim is given here. Real detection efficiency mismatch can include modes with vanishing detection probability, e.g., a polarization orthogonal to the detector's preferred axis or an arrival-time bin outside the detection window. For such modes the proof is silent: G_BT is undefined and the virtual POVM (B21) does not exist. The experimental section characterizes only four polarization states and reports up to 5% intensity fluctuations (Sec. V A); it does not establish positive-definiteness over the full mode space. Because every subsequent bound (Eqs. 15-17) depends on C and on λ± satisfying Eq. (11), a failure of invertibility removes the foundation of the claimed secure key rate for actual implementations, rather than merely loosening the rate.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper develops a security proof for the loss-tolerant three-state prepare-and-measure QKD protocol in the asymptotic regime, allowing simultaneously for state preparation flaws (SPFs) and detection efficiency mismatch (DEM). Bob's measurement is modeled by POVMs of the form M_{sβ} = |sβ><sβ|_B ⊗ F_s†F_s on a qubit system B and an efficiency-affecting system T, and the authors introduce a virtual Procrustean filter (Eq. B20) that balances the detection efficiencies so that Koashi's complementarity argument can be applied. The main result is the lower bound R ≥ p_sift_Z [ r_virt^L_X (1 - h2(e_p^U)) - f h2(e_b) ] (Eq. 12), with r_virt^L_X and e_p^U computed from Eqs. (15)-(17) using experimentally estimated X-basis statistics and semidefinite or analytical bounds on the efficiency operators. The paper also reports an experimental characterization of two commercial SPADs and simulates the key rate for polarization-dependent DEM.","tokens_in":30766,"tokens_out":9744,"duration_ms":94975,"significance":"If correct, this is a useful step: it extends the loss-tolerant QKD framework to receivers that fail the basis-independent detection efficiency condition, with a coherent-attack proof and a concrete recipe (SDP or analytical bounds) for evaluating the key rate. The derivation in Appendix B is detailed and the operator inequalities (B47)-(B48) give an internally consistent way to translate measured X-basis statistics into bounds on the virtual-X quantities. The experimental characterization, while limited, demonstrates a plausible route to applying the method to real devices. The main caveat is that the validity of the proof is conditional on the invertibility (positive-definiteness) of the efficiency operators, Assumption (A5), and this condition is not certified by the reported experiment.","major_comments":[{"comment":"The central proof object, the virtual filter in Eq. (B20), contains F_0^{-1} and F_1^{-1}, and the operator bounds in Eq. (11) require finite λ±. Thus the derivation of Eqs. (15)-(17), and hence Eq. (12), is valid only if F_0 and F_1 are invertible in a positive-definite sense, with bounded inverses when T is infinite-dimensional. The paper handles this by Assumption (A5), citing Ref. [36] for the claim that no positive key rate is achievable otherwise, but it does not prove that claim or state the precise condition. Real detectors can have modes with vanishing detection probability (for example, polarization orthogonal to the detector's preferred axis, or arrival times outside the detection window), and the experiment in Sec. V A only probes four polarization states and reports up to 5% intensity fluctuations, so it does not certify positive-definiteness over the full mode space. For a mode with a zero eigenvalue of F_s, Eq. (B20) is undefined and the virtual POVM in Eq. (B21) does not exist; the failure is not merely a looser rate but the removal of the proof's foundation. I recommend that the authors either provide a proof (or a precise statement with conditions) of the asserted no-positive-key-rate result, restrict the theorem's statement to settings where positive-definiteness is explicitly verified, or extend the analysis to non-invertible efficiency operators, and adjust the abstract and conclusions accordingly.","section":"II (Assumption A5), Appendix B (Eqs. B20-B21, Eq. 11)"}],"minor_comments":[{"comment":"The quantity perr,U_X virt used in Eq. (17) is not defined independently; as written it appears to omit the factor pZA pZB that is present in the corresponding bound in Eq. (B49). Please define all quantities explicitly and explain the normalization, even if the ratio with pvirt,L_X in Eq. (15) makes the factor cancel.","section":"Eqs. (16)-(17) and Eq. (B49)"},{"comment":"The operator ρ_E defined in Eq. (C16) is a sum over rounds and is not normalized; calling it a \"quantum state\" in Eq. (B26) is misleading. Clarify that the traces in Eqs. (B26)-(B50) are taken with respect to an unnormalized operator whose trace grows with N.","section":"Appendix C, Eq. (C16) and Eq. (B26)"},{"comment":"There is a grammatical typo: \"Therefore, have that\" should be \"Therefore, we have that.\" Also, the coherent-state ket in Eq. (22) should be written with a matching bra so that the density operator is clearly defined.","section":"Sec. V A, before Eq. (24)"},{"comment":"No uncertainties are reported for the fitted efficiencies and dead times, despite the text stating that error bars are approximately 1% of the detected values; adding confidence intervals would make the quantitative claim in Sec. V more robust.","section":"Table I and Fig. 3"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Read this if you care about whether loss-tolerant QKD still works when Bob's detectors have different efficiencies. The main contribution is a security proof for the three-state LT protocol covering both state preparation flaws and detection efficiency mismatch, with explicit expressions for the phase-error bound and an SDP to pick the free parameters. I went through Appendix B and the operator inequalities (B47)-(B48) check out; Eqs. (15)-(17) do follow from the measured X-basis statistics via the LT inversion, and the reduction to the original LT result when the detectors are identical is a good sanity check.\n\nWhat's new is the combination: previous proofs treated source flaws or detector mismatch separately, and this one handles both together. The detector characterization is basic but real — two commercial SPADs, four polarizations — and the key-rate simulation shows a few percent mismatch costs little. The authors are explicit about the scope: asymptotic, single-photon source, known qubit states.\n\nThe soft spot is Assumption (A5): Bob's POVM must factorize as a perfect qubit projection times an efficiency operator, and F0 and F1 must be invertible. The virtual filter in Eq. (B20) uses F0^{-1} and F1^{-1}; if a real detector has a mode with zero detection probability, the proof is silent. The paper cites Ref. [36] for the claim that no positive key rate is possible otherwise, which is fair but not proven here, and the experiment only samples four polarization states, so it does not establish positive-definiteness over all modes. This is a stated assumption, not a hidden one, so I would not call it fatal; but the abstract's 'guaranteeing the security of actual implementations' overreaches if read without that caveat. Also, experimental uncertainties are not propagated into the rate bounds — minor for an illustrative section.\n\nNet: the central argument holds under the assumptions. This is a meaningful, incremental contribution to QKD security proofs, not a breakthrough. It deserves a serious referee; after tightening the invertibility caveat and adding uncertainty propagation, it should be acceptable. I would cite it if I were working on detector-mismatch security.","headline":"Extends loss-tolerant QKD to detector efficiency mismatch with a sound but assumption-laden proof and a small real-detector measurement; worth refereeing.","tokens_in":31279,"tokens_out":3342,"would_cite":true,"duration_ms":31530,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A security proof now covers QKD receivers whose two detectors click with different efficiencies.","keywords":["quantum key distribution","loss-tolerant protocol","detection efficiency mismatch","state preparation flaws","coherent attacks","phase-error rate","secret key rate","security proof"],"falsifier":"Measure, with full mode-resolved tomography, a pair of single-photon detectors whose efficiency operators either are not invertible or cannot be written as one factor $\\hat F_s^\\dagger\\hat F_s$ acting on a single mode $T$; for such a receiver the construction of $\\hat G_{BT}$ in Eq. (B20) is undefined, so any positive key rate predicted by Eq. (12) for that hardware would contradict the security claim.","tokens_in":30241,"feed_emoji":"🔐","tokens_out":9036,"duration_ms":77849,"temperature":0.7,"pith_summary":"Quantum key distribution's promise of verifiable secrecy is threatened when a real receiver's two single-photon detectors have different efficiencies, because an eavesdropper can bias which bit Bob registers. This paper extends the loss-tolerant security proof for the three-state prepare-and-measure QKD protocol to exactly that situation, while also allowing Alice's emitted states to deviate from the ideal ones. It establishes an asymptotic secret key rate lower bound, Eq. (12), valid against arbitrary attacks coordinated across all rounds, and gives both a semidefinite-program recipe and closed-form bounds for the quantities entering it. The authors also measure the polarisation-dependent efficiency mismatch of two commercial single-photon detectors and show that a few-percent mismatch costs little key rate, so the bound is usable in practice.","feed_headline":"QKD security proof now tolerates mismatched detector efficiencies","feed_subtitle":"New bound covers flawed state sources and unequal detectors together; measured 5% mismatch barely cuts the key rate.","key_machinery":"The load-bearing object is the virtual Procrustean filter $\\hat G_{BT}$ of Eq. (B20), built from the Gram-matrix diagonalisation $\\hat F_0(\\hat F_1^\\dagger\\hat F_1)^{-1}\\hat F_0^\\dagger = \\hat U \\hat D \\hat U^\\dagger$ and the matrix $\\hat C$ that balances the two efficiency operators. Composed with Bob's Z-basis filter, it turns his actual X-basis measurement into a virtual X-basis measurement whose success probability and error rate can be bounded by the observed X-basis statistics through the operator inequalities $\\lambda_s^- \\hat F_s^\\dagger\\hat F_s \\le \\hat C^\\dagger\\hat C \\le \\lambda_s^+ \\hat F_s^\\dagger\\hat F_s$ for $s=0,1$. Choosing the four parameters $\\lambda_s^\\pm$ by semidefinite programming, or by the closed-form bounds of Eq. (19), supplies the phase-error bound that enters the key rate formula.","core_discovery":"The central result is a lower bound on the asymptotic secret key rate per channel use, $R \\ge p_{\\mathrm{sift}}^Z [ r_{\\mathrm{virt}}^{L,X}(1-h_2(e_p^U)) - f h_2(e_b)]$ (Eq. 12), for the loss-tolerant three-state prepare-and-measure protocol when Alice's prepared qubit states are flawed and Bob's two detectors have unequal, mode-dependent efficiencies. The proof treats the detection efficiency mismatch through a virtual Procrustean filter that restores basis-independent behaviour in a virtual protocol, and it relates the filtered statistics to the experimentally observed X-basis data through operator inequalities. When the detectors are identical the bound reduces to the original loss-tolerant result. An experimental characterisation of two commercial single-photon avalanche diodes finds roughly a 5% polarisation-dependent efficiency difference, and the simulated key rates show that this mismatch does not greatly reduce performance; for the studied parameters the semidefinite and analytical estimates of the auxiliary parameters coincide.","pith_inferences":["Because the proof assumes a single efficiency-affecting mode with invertible efficiency operators, hardware whose efficiency depends jointly on several coupled modes would need a multi-mode generalisation before this bound can be applied; the paper sketches such a generalisation but does not prove it.","The use of a concentration inequality to sum round-conditional probabilities indicates that a finite-size version of the same bound is a natural next step, and Eq. (12) already has the structure a finite-key analysis would start from.","An analogous characterisation of superconducting nanowire detectors, whose polarisation-dependent mismatch is typically larger, would be a direct stress test of how much this bound costs under realistic worst-case detector parameters."],"forward_implications":["QKD receivers no longer need identical detectors: a known, characterised efficiency difference is incorporated into the phase-error estimate instead of being left as an unmodelled loophole.","The loss-tolerant inversion handles flaws in the two key states, while the third trial state may deviate arbitrarily from ideal as long as it is fully characterised by Alice.","The result is compatible with the decoy-state method, so multi-photon source emissions can be treated separately without re-opening the detector-mismatch gap.","For the measured detectors, a polarisation-induced mismatch of roughly 5% costs little simulated secret key rate, and the analytical and semidefinite parameter choices coincide in this regime."],"supporting_citations":[{"why":"Supplies the complementarity argument that reduces security to bounding the phase-error rate of the virtual protocol.","marker":"[58]"},{"why":"Introduces the efficiency-operator model and the Procrustean virtual filter that this work generalises and simplifies to the loss-tolerant setting.","marker":"[36]"},{"why":"Original loss-tolerant three-state security proof, recovered by this analysis when the two detectors are identical.","marker":"[47]"},{"why":"Provides the concentration inequality used to pass from conditional round probabilities to observed counts in the asymptotic proof.","marker":"[66]"},{"why":"Gives the Procrustean filtering method on which the virtual filter construction is based.","marker":"[61]"}],"fun_headline_variants":["QKD proof now covers flawed sources and detector mismatch","New security bound tolerates QKD detector efficiency mismatch","QKD key rate preserved despite imperfect sources and detectors","Security proof relaxes QKD detector basis independence condition"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof stands on the assumption that Bob's whole detection setup acts as a perfect qubit measurement on the signal followed by a single efficiency-affecting mode whose effect on each detector is an invertible operator; if real detectors couple several such modes or can have zero efficiency for some mode, the virtual filter used in the proof is not guaranteed to exist.","fun_headline_variants_meta":{"raw":{"variants":["QKD proof now covers flawed sources and detector mismatch","New security bound tolerates QKD detector efficiency mismatch","QKD key rate preserved despite imperfect sources and detectors","Security proof relaxes QKD detector basis independence condition"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000229,"raw_usage":{"total_tokens":1463,"prompt_tokens":912,"completion_tokens":551,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":528,"completion_tokens_details":{"reasoning_tokens":488}},"tokens_in":528,"tokens_out":551,"duration_ms":5858,"temperature":1.0,"reasoning_tokens":488,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T16:51:46.309887+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure, with full mode-resolved tomography, a pair of single-photon detectors whose efficiency operators either are not invertible or cannot be written as one factor $\\hat F_s^\\dagger\\hat F_s$ acting on a single mode $T$; for such a receiver the construction of $\\hat G_{BT}$ in Eq. (B20) is undefined, so any positive key rate predicted by Eq. (12) for that hardware would contradict the security claim.","supporting_citations":[{"cited_title":"Tan, W.-Y","cited_arxiv_id":null,"evidence_quote":"Introduces the efficiency-operator model and the Procrustean virtual filter that this work generalises and simplifies to the loss-tolerant setting."},{"cited_title":"Sajeed, P","cited_arxiv_id":null,"evidence_quote":"Original loss-tolerant three-state security proof, recovered by this analysis when the two detectors are identical."},{"cited_title":"Curr´ as-Lorenzo, S","cited_arxiv_id":null,"evidence_quote":"Provides the concentration inequality used to pass from conditional round probabilities to observed counts in the asymptotic proof."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the Procrustean filtering method on which the virtual filter construction is based."}],"review_version":1}