{"id":"12c4de16-1ca4-4a4e-88c7-08640814265b","arxiv_id":"2412.17931","paper_version":1,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"low","formal_verification":"none","parameter_count":1,"one_line_summary":"By running 1.34 billion loophole-free Bell trials with biased public inputs, the authors extracted 20,431,465 bits certified ε-random with ε=10^-12.","lead":"Using superconducting qubits 30 meters apart, this experiment purified imperfect random bits from a physical source into 20.4 million certified private random bits. It is the first demonstration of device-independent randomness amplification, removing an assumption that all earlier quantum cryptography experiments needed.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Uncertified SV-source assumption (SI V.4) is load-bearing: if the QRNGs' conditional bias exceeds 0.75% or Eve holds quantum side info, the ε=1e-12 guarantee for K does not follow.","rationale":"I agree with the reader that the weakest assumption is the SV-source condition with classical side information. It is load-bearing because every certificate in the chain—MDL violation, min-entropy bound, extractor security—presupposes it. The concern does not defeat the paper: the assumptions are listed in SI V, the security proof is chained to published theorems, and the experimental numbers (n=1.34e9, S_obs=2.271, S_μ,obs=0.00296, timing margin 3.1 ns) support the execution under those assumptions. But the 'guarantee' is conditional on an unverified property of a commercial device. A concrete empirical test of the QRNGs' conditional bias is feasible and would settle whether the condition plausibly holds. Since the paper states the condition explicitly and the reader already flagged it, I do not change the verdict.","tokens_in":23261,"tokens_out":16413,"duration_ms":167478,"concrete_test":"Ask the authors for the raw bit streams of the two QRNGs (data available on request) and compute the empirical maximum conditional bias: for histories h of length up to 10 and conditioning variables c including the other source's bits and timing indices, estimate p_max = max |Pr[b_i=1 | b_<i=h, c] − 1/2| with conservative confidence intervals. If any upper confidence bound exceeds 0.75%, the SV assumption is falsified for the implemented sources and the security guarantee does not follow. If all bounds lie below 0.75%, the concern is mitigated, though adversarial side information e remains untestable; an additional analytical check would be to re-prove Theorem 5 allowing quantum side information about the sources.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The headline guarantee depends on SI §V Assumption 4: the two QRNGs are (possibly correlated) Santha–Vazirani sources with μ ≤ 0.75% and Eve has only classical side information about them. This property is not experimentally certified. The manufacturer's stated 'excess predictability < 1e-5' (Ref. [43]) is an unconditional guessability figure, not the conditional bound Pr[b_i | b_<i, e] ∈ [1/2−μ, 1/2+μ] that the SV model and the MDL inequality (Eq. 4) require. Correlations between the two QRNGs, memory effects, or coupling to the experiment's clock/trigger signals could make the effective conditional bias exceed 0.75% without contradicting the datasheet. Because the security proof uses S_μ,obs only as a certificate of min-entropy when the inputs are μ-SV, a violation of Assumption 4 would void the bound H_min(AB|XYE) and hence the ε=1e-12 statement for K. The paper is transparent about this assumption, so the claim is conditional; however, the abstract's 'guaranteed' and 'demonstrate the amplification' soften that caveat.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an experimental realization of device-independent randomness amplification. Two commercial quantum random number generators serve as public Santha-Vazirani sources with bias μ = 0.75%; their bits set the measurement bases for a two-node superconducting circuit distributed over 30 m, which violates a measurement-dependent locality inequality. After n = 1.34×10^9 trials, with observed CHSH value S = 2.271 and MDL value S_μ,obs = 0.00296, the authors apply a two-source extractor seeded from one of the SV sources to produce a 20,431,465-bit output string K. The security claim, with ε = 10^-12, is based on a proof in the Supplementary Information that combines the entropy accumulation theorem with the MDL bound of Kessler and Arnon-Friedman and quantum-proof extractor results of Arnon-Friedman, Portmann, and Scholz. The experiment closes the locality, fair-sampling, and memory loopholes; the timing analysis leaves a 3.1 ns margin to the Bell bound.","tokens_in":23431,"tokens_out":14152,"duration_ms":130061,"significance":"If the security proof and experimental execution hold up, this is the first experimental demonstration of randomness amplification, a task that is impossible classically. The paper is notable for its transparency: it explicitly lists all assumptions in SI section V, provides a security proof in SI section VI as a chain of published theorems, and includes conservative timing verification with real-time monitoring. The result is a significant step toward device-independent cryptography without the assumption of perfect randomness, and the output length is already useful as input for device-independent QKD. The main limitation is that the SV-source property of the QRNGs is assumed, not certified; the authors state this assumption plainly, and it is inherent to the nature of the task.","major_comments":[],"minor_comments":[{"comment":"The main text attributes the extractor used in the experiment to Ref. [55], while the security proof in SI section VI is based on the construction from Ref. [63] (Theorem 2); please clarify whether these are the same construction and reconcile the citations, because the proof must cover the actually implemented function.","section":"Methods, 'Requirements for the randomness extractor'; SI section VI, Theorem 2"},{"comment":"The ε = 10^-12 guarantee for K is conditional on the two QRNGs being μ-SV sources with μ ≤ 0.75% and on Eve holding only classical side information about them; although this is stated in the text, the abstract and conclusion could more prominently emphasize that this source property is assumed rather than experimentally certified, since the manufacturer's 'excess predictability below 10^-5' is not the same as the conditional SV bound required by the proof.","section":"SI section V, Assumption 4; final summary paragraph"},{"comment":"The statement that the protocol starts from 5,368,709,120 low-quality random bits could be clarified: with n = 1,342,177,280 trials, this number equals 4n, corresponding to two input bits per trial (xi, yi) plus an additional 2n-bit seed for the extractor; please spell out this accounting.","section":"Main text, final summary paragraph"},{"comment":"The notation PABXY(abcd) is used without an explicit definition; please define it as Pr[A=a, B=b, X=c, Y=d] so that the MDL inequality is unambiguous.","section":"Methods, Eq. (4)"},{"comment":"In the expression for the output size m, the additive term '-6εs' appears outside the factor n/6; please verify the expression and comment on the origin of this term, as it is not immediately transparent from the preceding Theorem 4.","section":"SI section VI, Eq. (18)"}],"recommendation":"minor_revision","confidential_remarks":"This is a strong manuscript reporting the first experimental demonstration of device-independent randomness amplification. The uncertified SV-source assumption is a real limitation but is standard and transparently acknowledged; I encourage the editors to ensure the abstract does not overstate the guarantee. The extractor citation inconsistency should be fixed before publication."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"First, the headline: this is a genuine first experimental demonstration of device-independent randomness amplification, and it deserves a serious referee. The central claim is conditional, not absolute, and the paper is mostly honest about that.\n\nWhat is actually new: no prior experiment had the combination of Bell violation (S ≈ 2.27), trial count (~1.34 billion), and tolerated source bias (μ = 0.75%) needed to run the Kessler–Arnon-Friedman protocol. The engineering is impressive: 50 kHz repetition, 30 m separation, 3.1 ns timing margin, and multi-hour stability. The SI security proof is transparent — it chains published results (EAT, MDL bound, extractor) and lists assumptions explicitly. The output of 20.4 Mbit at ε = 10^-12 is a legitimate benchmark.\n\nThe soft spots, in proportion. The SV-source assumption (SI section V, Assumption 4) is load-bearing: the guarantee for K depends on the two QRNGs having conditional bias ≤ 0.75% with only classical side information. That property is not experimentally certified. The manufacturer's datasheet figure (< 10^-5) is an unconditional predictability number, not the conditional bound the proof needs; correlations or memory effects could in principle push the effective bias higher without contradicting the datasheet. The paper states this assumption openly, so it is not a hidden flaw. But the abstract's 'guaranteed' is a bit strong — the guarantee is conditional on that premise. Given that the whole point of the experiment is to relax input-randomness assumptions, this is the one place where a skeptic will press.\n\nAlso, data and code are not public; 'available upon reasonable request' is weak for a result of this consequence. That should be fixed in revision.\n\nThe statistical tests (NIST/Diehard) are sanity checks, not security evidence; the paper presents them that way, so no problem.\n\nThe self-citations to Renner's earlier work are appropriate; the proof really does rest on those results.\n\nWho this is for: experimental quantum information and DI crypto researchers. It closes a conceptual gap and gives DI-QKD a path off perfect input randomness. My verdict: accept with revisions. The referee should push for a more careful statement of the source assumption and public data.","headline":"A genuine experimental first in DI randomness amplification; the headline guarantee is honestly conditional on an uncertified SV-source assumption that the paper states clearly.","tokens_in":24051,"tokens_out":2158,"would_cite":true,"duration_ms":21236,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper reports the first experimental demonstration of device-independent randomness amplification, converting 5,368,709,120 bits with up to 0.75% bias into 20,431,465 bits certified to be uniformly random to within 10^-12 error.","keywords":["device-independent randomness amplification","Santha-Vazirani source","measurement-dependent locality inequality","loophole-free Bell test","quantum random number generator","two-source extractor","superconducting qubits","min-entropy"],"falsifier":"Measure the predictability of each QRNG bit conditioned on all earlier bits and on classical environmental variables (temperature, supply voltage, laser current). If the best predictor succeeds with probability above 0.5075 for any bit, the Santha-Vazirani assumption with μ = 0.75% is violated, and the ε = $10^{-12}$ guarantee for K no longer follows. Alternatively, an independent timing audit that reconstructs t_protocol from the published segment durations and finds it exceeds 109.83 ns would open the locality loophole and invalidate the device-independent certification.","tokens_in":23005,"feed_emoji":"🎲","tokens_out":6676,"duration_ms":57282,"temperature":0.7,"pith_summary":"This paper reports the first experimental demonstration of randomness amplification: turning weakly random bits into almost perfect randomness in a device-independent way. Specifically, the authors used a loophole-free Bell test with two superconducting qubits 30 meters apart, driving the measurement choices with two commercial quantum random number generators treated as biased public sources. From 5,368,709,120 input bits with bias up to 0.75%, they produced 20,431,465 output bits certified to be uniformly random to within $10^{-12}$, assuming only that the input sources are Santha-Vazirani sources and that the adversary holds classical side information about them. The result closes a long-standing gap: prior device-independent protocols assumed perfect input randomness, while this one starts from imperfect sources. If correct, the method supplies a practical, certified randomness source for quantum cryptography and other tasks that need full-entropy randomness.","feed_headline":"20 million certified random bits from a biased source","feed_subtitle":"First experiment turns 5.37 billion weak bits into 20.4 million device-independent random bits at 10^-12 error.","key_machinery":"The central object is the measurement-dependent locality (MDL) inequality S_μ, a version of the CHSH/Eberhard Bell inequality that accounts for biased input distributions: for inputs from a μ-SV source, a violation S_μ > 0 certifies min-entropy in the outputs. The proof chain uses the entropy accumulation theorem to bound smooth min-entropy of the outputs AB given inputs XY and adversary side information E in terms of S_μ, and then a two-source extractor (constructed from non-cyclic shift matrices) that converts AB plus an additional public seed Z into a near-uniform private string K. The experiment closes the locality, fair-sampling, and memory loopholes via 30 m separation, all-trials inclusion, and a non-i.i.d. security proof.","core_discovery":"The paper claims that a two-node superconducting circuit apparatus can amplify the randomness of a public, imperfect source: running a loophole-free Bell test with measurement choices drawn from two possibly correlated Santha-Vazirani sources with bias μ = 0.75% yields a string K of length 20,431,465 bits that is ε-random with ε = $10^{-12}$, guaranteed by the violation of the measurement-dependent locality inequality S_μ. The guarantee is device-independent for the quantum device—the device is treated as an untrusted black box—and holds provided the input sources satisfy the SV condition and the adversary has only classical side information about them. The output passes the NIST and Diehard statistical test suites.","pith_inferences":["A natural extension, not explored in the paper, would be to allow the adversary quantum side information about the QRNGs; the current security proof only covers classical side information, so a malicious manufacturer who entangles the seed photons would break the stated guarantee.","The margin between the protocol duration (106.7 ns) and the Bell-distance budget (109.8 ns) is only 2.8% of the budget; tighter timing or longer distances would increase the robustness of the locality loophole closure.","The same setup, with better channel loss and faster repetition, could tolerate sources with bias above 0.75%, reducing the gap toward the theoretical 4% limit shown in the paper's parameter plot."],"forward_implications":["The output K, 20.4 Mbit with ε = 10^-12, is large enough to serve as a public certified randomness beacon or as input randomness for later device-independent protocols.","The demonstrated rate and statistics enter the regime required for device-independent quantum key distribution without assuming perfect randomness.","The protocol aborts when the MDL violation is not observed, so the same hardware can be reused in a fallback mode whenever the sources degrade.","The result shifts randomness amplification from a theoretical existence proof to an experimentally achievable task, establishing a benchmark for future implementations."],"supporting_citations":[{"why":"Introduces the concept of randomness amplification from weak sources.","marker":"[19]"},{"why":"Supplies the theoretical protocol and the MDL-based min-entropy bound used here.","marker":"[20]"},{"why":"Provides the loophole-free Bell test platform with superconducting circuits that this experiment builds on.","marker":"[21]"},{"why":"Describes the phase-diffusion QRNGs used as the imperfect public sources.","marker":"[43]"},{"why":"Defines the Santha-Vazirani source model for biased randomness.","marker":"[52]"},{"why":"Shows that classical two-source extractors remain secure against quantum side information, used in the proof.","marker":"[54]"},{"why":"Gives the efficient two-source extractor that the implementation uses.","marker":"[55]"},{"why":"Provides the non-cyclic shift matrix extractor construction (Lemma 4) used in the proof.","marker":"[63]"},{"why":"Is the entropy accumulation theorem used to bound the smooth min-entropy from the MDL violation.","marker":"[68]"}],"fun_headline_variants":["20M certified random bits from a biased source","Device-independent randomness amplification demonstrated","Weak source to certified randomness via loophole-free Bell test","From 5.37B weak bits to 20.4M provably random ones","Bell test amplifies imperfect randomness in superconducting circuit"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The result assumes, without direct experimental proof, that the two commercial QRNGs really are Santha-Vazirani sources with bias at most 0.75% against an adversary who holds only classical side information.","fun_headline_variants_meta":{"raw":{"variants":["20M certified random bits from a biased source","Device-independent randomness amplification demonstrated","Weak source to certified randomness via loophole-free Bell test","From 5.37B weak bits to 20.4M provably random ones","Bell test amplifies imperfect randomness in superconducting circuit"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000259,"raw_usage":{"total_tokens":1564,"prompt_tokens":899,"completion_tokens":665,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":515,"completion_tokens_details":{"reasoning_tokens":587}},"tokens_in":515,"tokens_out":665,"duration_ms":7081,"temperature":1.0,"reasoning_tokens":587,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T05:09:40.925999+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure the predictability of each QRNG bit conditioned on all earlier bits and on classical environmental variables (temperature, supply voltage, laser current). If the best predictor succeeds with probability above 0.5075 for any bit, the Santha-Vazirani assumption with μ = 0.75% is violated, and the ε = $10^{-12}$ guarantee for K no longer follows. Alternatively, an independent timing audit that reconstructs t_protocol from the published segment durations and finds it exceeds 109.83 ns would open the locality loophole and invalidate the device-independent certification.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the loophole-free Bell test platform with superconducting circuits that this experiment builds on."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Describes the phase-diffusion QRNGs used as the imperfect public sources."},{"cited_title":"Magnard, P","cited_arxiv_id":null,"evidence_quote":"Defines the Santha-Vazirani source model for biased randomness."},{"cited_title":"Kurpiers, P","cited_arxiv_id":null,"evidence_quote":"Shows that classical two-source extractors remain secure against quantum side information, used in the proof."},{"cited_title":"Walter, P","cited_arxiv_id":null,"evidence_quote":"Gives the efficient two-source extractor that the implementation uses."},{"cited_title":"Vazirani, in Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing , STOC ’87 (Association for Computing Machinery, New York, NY , USA, 1987) p","cited_arxiv_id":null,"evidence_quote":"Provides the non-cyclic shift matrix extractor construction (Lemma 4) used in the proof."},{"cited_title":"Dodis, S","cited_arxiv_id":null,"evidence_quote":"Is the entropy accumulation theorem used to bound the smooth min-entropy from the MDL violation."}],"review_version":1}