{"id":"79ded07e-da52-4a3f-b51a-4253effcfc1c","arxiv_id":"2502.01611","paper_version":3,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Optimized sandwiched Rényi conditional entropy is additive under tensor products of arbitrary quantum channels, yielding new chain rules and time-adaptive quantum cryptographic security proofs.","lead":"The paper proves a general additivity property for the optimized sandwiched Rényi entropy of quantum channels: the minimum output entropy splits additively under tensor products, even when the channels are different. It also derives new chain rules and applies them to security proofs for time-adaptive quantum key distribution.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Strong duality in Appendix B Eq. (17) is false: for Φ=id, N=id, τ=I/2, p=2, primal=1/√2 but dual≥1; Theorem 4.15's proof is unsound.","rationale":"The reader identified the compressed strong-duality step in Appendix B as the weakest assumption. Our stress test confirms this concern and sharpens it: Eq. (17) is not merely missing a stated Slater condition; it is false in a simple finite-dimensional instance with Φ=id, N=id, τ=I/2, and p=2. This is a concrete duality gap, exactly the scenario the reader feared. The gap is load-bearing because Theorem 4.15 is the sole route to the constrained additivity (Corollary 5.1) and the time-adaptive security theorem (Theorem 5.2). The paper's attempt to justify strong duality by exhibiting one strictly feasible dual point only proves weak duality; it does not rule out gaps like the one above. We are not asserting that Theorem 4.15 itself is false; the final inequality might hold in the counterexample (indeed it does for n=2), but the proof as written is invalid. The unconstrained multiplicativity (Theorem 4.10) and the chain rules do not depend on Eq. (17), so those results may stand independently. The correct verdict remains CONDITIONAL: the paper should be accepted only if the authors provide a correct proof of the constrained additivity, either by proving a valid strong-duality theorem under explicit constraint qualifications that exclude this counterexample, or by replacing the duality argument with a direct proof. This is a substantive technical flaw, not a matter of style or missing references.","tokens_in":35461,"tokens_out":41750,"duration_ms":364790,"concrete_test":"Evaluate Eq. (17) with Φ=id on ℂ², N=id, τ=I/2, p=2. The primal is ∥I/2∥₂=1/√2. The dual constraint forces Σ₀₀≥1 and Σ₁₁≥1 (from ρ=|0⟩⟨0| and ρ=|1⟩⟨1|), so Tr[Στ]=(Σ₀₀+Σ₁₁)/2≥1. This explicit evaluation shows the asserted strong duality fails, settling that the proof of Theorem 4.15 needs repair.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Theorem 4.15, the constrained multiplicativity result, is proved in Appendix B via the strong duality statement Eq. (17): sup_{ρ≥0,N(ρ)=τ} g^Φ_p(ρ) = inf_{Σ≥0} {Tr[Στ] : g^Φ_p(ρ) ≤ Tr[ΣN(ρ)] ∀ρ≥0}. This duality is false as written. Concrete counterexample: take Q=Q'=ℂ², Φ=id, N=id, τ=I/2, and p=2. The primal constraint N(ρ)=τ forces ρ=I/2, so the primal value is g^Φ_2(I/2)=∥I/2∥₂=1/√2. The dual requires Σ≥0 with ∥ρ∥₂≤Tr[Σρ] for all ρ≥0. Testing ρ=|0⟩⟨0| gives 1≤Σ₀₀; testing ρ=|1⟩⟨1| gives 1≤Σ₁₁. Hence Tr[Στ]=(Σ₀₀+Σ₁₁)/2≥1, so the dual value is at least 1, strictly larger than the primal value. The paper's verification of a strictly feasible dual point Σ=C1 establishes weak duality but cannot close this gap. Since Theorem 4.15, Corollary 5.1, and Theorem 5.2 rely directly on Eq. (17), their proofs are not valid without additional constraint qualifications or a different argument. The unconstrained Theorem 4.10 does not use Eq. (17) and may be correct, but the constrained additivity and the time-adaptive cryptographic rate claims are unsupported by the current proof.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper develops a theory of multi-index Schatten (Pisier) norms and uses it to prove multiplicativity theorems for completely bounded norms of completely positive maps. The main results are: Theorem 4.6 (ordered multiplicativity), Theorem 4.10 (multiplicativity of 1→(1,p) CB norms), chain rules for optimized Rényi conditional entropies (Corollaries 4.2, 4.5, 4.8), and Theorem 4.15, which extends multiplicativity to linearly constrained state spaces. The constrained result is used to prove Corollary 5.1, a reduction to independent attacks for f-weighted Rényi entropies, and Theorem 5.2, a time-adaptive asymptotic key rate for QRNG/QKD protocols. The unconstrained theorems are proved in the main text, while the constrained theorem is proved in Appendix B via a strong-duality argument.","tokens_in":35767,"tokens_out":16346,"duration_ms":139489,"significance":"The unconstrained multiplicativity results are a substantive technical contribution. They generalize the Devetak–Junge–King–Ruskai multiplicativity theorem to arbitrary multi-index Schatten norms and yield chain rules for optimized Rényi entropies that avoid some limitations of earlier work, such as the need to optimize over purifications and a loss in the Rényi parameter. The proofs are explicit and largely self-contained. However, the paper's headline application to time-adaptive cryptography rests on Theorem 4.15, whose proof relies on a strong-duality statement (Eq. (17)) that is false as stated. The constrained additivity result and the derived cryptographic rate theorem are therefore not established by the arguments given; the unconstrained portion may stand independently.","major_comments":[{"comment":"The asserted strong duality is false as stated. Take Q = C^2, let Φ be the identity channel with R trivial (so the output multi-index norm is (\\tilde Q:1, S:p)), set N = id, τ = I/2, and p = 2. Then g^Φ_2(ρ) = ||ρ||_2, so the primal value is ||I/2||_2 = 1/√2. A dual feasible Σ must satisfy ||ρ||_2 ≤ Tr[Σρ] for all ρ ≥ 0; testing rank-one projectors gives Σ ≥ I, hence Tr[Στ] ≥ 1. Thus the dual value is at least 1 > 1/√2, contradicting Eq. (17). The proof in Appendix B only exhibits a dual feasible point Σ = C1, which establishes weak duality, not strong duality.","section":"Appendix B, Eq. (17)"},{"comment":"Because the proof of Theorem 4.15 invokes Eq. (17) to pass from dual-feasible Σ_i to the infimum over Σ_i and to identify that infimum with the product of the individual primal optima, the counterexample to Eq. (17) invalidates the proof of Theorem 4.15. No alternative argument is supplied. Corollary 5.1 is then derived by applying Theorem 4.15, and Theorem 5.2 relies on Corollary 5.1; therefore the claimed reduction to independent attacks and the time-adaptive asymptotic rate are unsupported by the current manuscript. The unconstrained Theorem 4.10, whose proof does not use Eq. (17), is not affected by this issue.","section":"Theorem 4.15 and Corollary 5.1"},{"comment":"The theorem is stated for arbitrary linear restrictions (N_i, τ_i), but the proof does not state or verify any constraint qualification for the primal problem. The exhibited dual feasible point Σ = C1 only proves weak duality. Since Eq. (17) fails even for the simple strictly feasible case N = id, τ = I/2, p = 2, the statement of Theorem 4.15 would need additional hypotheses, or a proof that the specific g^Φ_p and constraints arising in the cryptographic application satisfy a valid duality, before the result can be accepted.","section":"Section 4.3 / Theorem 4.15 statement"}],"minor_comments":[{"comment":"References [3] and [25] are listed as \"to appear\" without arXiv or journal identifiers; please update them.","section":"References"},{"comment":"The normalization in the linear constraint (13) should be stated more explicitly: since each N_t is trace preserving, the right-hand side ⊗_t τ_t fixes the trace of ρ_{Q^n} only if each τ_t has trace 1, which is true in the examples but should be said.","section":"Section 5.2, Eq. (13)"},{"comment":"The sentence \"The right-hand side becomes ...\" omits the infimum; the displayed quantity is the infimum over σ, and the wording should reflect that.","section":"Corollary 4.2 proof"},{"comment":"In Corollary 5.1, the substitution used to apply Theorem 4.15 (A_i → S_i, X_i → R_i) should be stated explicitly, as the notation otherwise switches between classical and quantum registers without comment.","section":"Section 5.1"}],"recommendation":"major_revision","confidential_remarks":"The constrained part of the paper is not ready for publication as it stands. I would advise the editor that acceptance should be conditional on a correct proof of Theorem 4.15, or on a revised theorem with explicit hypotheses under which the reduction to independent attacks holds. The unconstrained results are likely valuable on their own, but the paper's advertised time-adaptive key-rate claims should not be cited until the duality gap is resolved."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"You should look at this paper for its unconstrained results, not for its security proof. The main multiplicativity theorem (Thm 4.10) for 1→(1,p) CB norms of tensor products of different CP maps, and the derived chain rules (Cor 4.2, 4.8) that remove the α-loss and purification optimization from Metger et al., are genuine and likely correct. The proofs of these are explicit and do not touch Appendix B. That is a real contribution: additivity of optimized Rényi conditional entropy for arbitrary tensor products of channels (Eq. 2) generalizes both Devetak-Junge-King-Ruskai and Van Himbeeck-Brown.\n\nThe soft spot is exactly where the reader's report and the stress-test point: Appendix B, Eq. (17). The paper asserts strong duality for sup_{N(ρ)=τ} g(ρ) after exhibiting a strictly feasible dual point. That is not sufficient. The stress-test's counterexample checks out: take Φ=id, N=id, τ=I/2, p=2, with R trivial and S=Q. Then primal is ∥I/2∥_2=1/√2, but the dual constraint forces Σ≥I, giving dual value ≥1. So Eq. (17) is false as written. The dual feasible point only gives weak duality, and the subsequent proof of Theorem 4.15 collapses: the reduction to independent attacks (Cor 5.1) and the time-adaptive rate theorem (Thm 5.2) are unsupported.\n\nNote the paper explicitly cites [25] for this duality argument and says \"this follows by showing that there exists a dual feasible Σ\" — that is precisely the gap. In convex optimization, a strictly feasible dual point usually gives strong duality, but here the primal is a maximization of a convex function, not a standard convex minimization, so the usual Slater arguments do not apply without extra conditions. The stress-test shows the missing condition is not cosmetic.\n\nWho is this for? Anyone working on EAT-type chain rules or on QKD/QRNG security proofs will want to read the unconstrained part. The constrained part needs a real fix: either prove a correct duality with additional assumptions, or find another route to Theorem 4.15. As it stands, the paper should not be treated as having a valid security proof for time-adaptive protocols.\n\nRecommendation: send it to peer review. The unconstrained results are worth refereeing, and the flaw is specific and fixable. A serious referee should be asked to verify whether the constrained theorem can be rescued; if not, the authors should remove or clearly weaken the cryptographic claims.","headline":"Unconstrained additivity and chain rules look strong, but the constrained version relies on a false strong-duality claim that breaks the cryptographic applications.","tokens_in":36334,"tokens_out":9240,"would_cite":true,"duration_ms":78847,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["46L07","81P45","94A17"],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper proves that optimized sandwiched Rényi conditional entropy is additive over tensor products of arbitrary quantum channels, with chain rules and time-adaptive cryptographic applications.","keywords":["quantum entropies","Rényi conditional entropy","additivity","multi-index Schatten norms","Pisier norms","completely bounded norms","chain rules","time-adaptive quantum cryptography"],"falsifier":"Compute, for a small finite-dimensional channel $\\Phi$ and a linear constraint $(N,\\tau)$, the primal value $\\sup_{\\rho\\geq 0,\\,N(\\rho)=\\tau} \\|\\Phi(\\rho)\\|_{(R:1,S:p)}$ and its dual $\\inf_{\\Sigma\\geq 0,\\, g^\\Phi_p(\\rho)\\leq \\operatorname{Tr}[\\Sigma N(\\rho)]\\ \\forall\\rho} \\operatorname{Tr}[\\Sigma\\tau]$; any channel where the two values differ by more than numerical precision would break Eq. (17), and with it Theorem 4.15 and Corollary 5.1. A natural candidate is a qubit amplitude-damping channel with a constraint fixing the output Bloch component.","tokens_in":35237,"feed_emoji":"🔐","tokens_out":7524,"duration_ms":68404,"temperature":0.7,"pith_summary":"This paper establishes that the optimized sandwiched Rényi conditional entropy of a quantum channel is additive under tensor products: for any collection of completely positive maps, the best conditional entropy produced by the joint map equals the sum of the best entropies of the individual maps. The proof works by translating the entropy statement into a statement about completely bounded norms between multi-index Schatten spaces (Pisier norms), and proving that those norms are multiplicative under tensor products. The same machinery yields chain rules for Rényi conditional entropies that improve on earlier versions by having no loss in the parameter $\\alpha$ and no purification optimization on the right-hand side. Under linear constraints on the input states, the additivity extends and implies that minimizing the $f$-weighted Rényi entropy over $n$ rounds reduces to independent per-round optimizations. The cryptographic application is a security proof for time-adaptive quantum random number generation and key distribution that achieves the average of the per-round optimal rates, which is strictly higher than static proofs when channel noise varies.","feed_headline":"Entropy additivity proven for all tensor products of quantum channels","feed_subtitle":"Multi-index Schatten norms turn the proof into a norm-multiplicativity statement, unlocking time-adaptive key rates.","key_machinery":"Multi-index Schatten norms, defined by iterating Pisier's variational formula $\\|X\\|_{S_p[H,\\mathcal{X}]} = \\inf_{X=FYG} \\|F\\|_{2p}\\|Y\\|_{S_\\infty[H,\\mathcal{X}]}\\|G\\|_{2p}$, are the central object. A norm with $k$ indices, written $\\|X\\|_{(A_1:q_1,\\ldots,A_k:q_k)}$, records the order and Schatten exponent for each tensor factor. Theorems 3.2 and 3.4 provide variational characterizations of three-index norms that make them tractable. These norms carry the argument because sandwiched Rényi conditional entropy is the logarithm of a $(1,\\alpha)$-norm, so proving multiplicativity of completely bounded norms between such spaces is exactly proving additivity of conditional entropies. The proof also relies on the complete-contraction property of the swap map for ordered indices and on the identity-to-the-right lemma showing that attaching an identity operator space to the output of a completely positive map does not change its norm.","core_discovery":"The central discovery is that the completely bounded $1\\to(1,p)$ norm of a tensor product of completely positive maps factorizes: $\\|\\otimes_i \\Phi_i\\|_{cb,(Q^n:1)\\to(R^n:1,S^n:p)} = \\prod_i \\|\\Phi_i\\|_{cb,(Q_i:1)\\to(R_i:1,S_i:p)}$. Taking logarithms via the identity $H^\\uparrow_\\alpha(A|B)_\\rho = \\frac{\\alpha}{1-\\alpha}\\log \\|\\rho\\|_{(B:1,A:\\alpha)}$ gives the entropic additivity statement $\\inf_E \\inf_\\rho H^\\uparrow_\\alpha(S^n|R^nE)_{\\Phi^n(\\rho)} = \\sum_i \\inf_E \\inf_\\rho H^\\uparrow_\\alpha(S_i|R_iE)_{\\Phi_i(\\rho)}$. This holds for arbitrary completely positive maps with different input and output spaces, not only identical channels. The proof generalizes an earlier multiplicativity result [9] to arbitrary multi-index Schatten norms using variational formulas (Theorems 3.2 and 3.4) and an identity-to-the-right lemma (Theorem 4.1). A constrained version with linear input constraints (Theorem 4.15) is proven via strong duality and yields the reduction to independent attacks (Corollary 5.1) and a time-adaptive rate theorem (Theorem 5.2). The paper also proves chain rules for optimized Rényi conditional entropies (Corollaries 4.2 and 4.8).","pith_inferences":["A natural testable consequence is that the finite-size correction in the adaptive proof could be tightened by applying the new chain rule repeatedly rather than through the uniform-continuity lemma, which currently costs a factor of $(\\log \\eta)^2$ per round.","Because Theorem 4.10 does not require the channels to act on identical systems or to commute, the same proof should yield entropy-accumulation-style bounds for protocols with memoryless but non-identical channels from round to round, a setting not explicitly treated in the paper.","The multiplicativity of the $1\\to(1,p)$ completely bounded norm suggests that the optimized Rényi conditional entropy itself, not only its infimum, is nearly additive for product inputs; checking whether equality holds only at product minimizers would clarify which states saturate the bound.","For quantum key distribution, the time-adaptive framework could allow selecting measurements in each round based on previously observed statistics, since the per-round maps are arbitrary; the proof appears to allow such adaptivity as long as the linear constraint factors, though the paper does not state this."],"forward_implications":["Additivity extends from identical channels to arbitrary tensor products: the optimized conditional Rényi entropy of the joint channel is the sum of the per-channel values, for all $\\alpha \\geq 1$.","The chain rules bound the entropy loss when processing a state through a product channel in terms of one channel's minimum output entropy, with no loss in $\\alpha$ and no need to optimize over purifications on the right-hand side.","For states satisfying independent linear constraints, minimization of the $f$-weighted Rényi entropy over $n$ rounds reduces to independent round-by-round optimizations, so collective attacks are no stronger than independent attacks in this setting.","Time-adaptive quantum random number generation and key distribution protocols can be proven secure at the average of the per-round optimal rates; when the protocol is fixed but the noise varies, this exceeds the static-proof rate whenever the rate function is strictly convex.","The asymptotic rate of randomness extraction is $\\lim_{n\\to\\infty} \\frac{1}{n}\\sum_{t=1}^n h(M_t,N_t,\\tau_t,q^{\\mathrm{hon}}_{X_t})$, which also permits security proofs for protocols whose operations change from round to round."],"supporting_citations":[{"why":"Provides the base multiplicativity result for completely bounded $p$-norms and the relation between $(1,\\alpha)$-norms and conditional Rényi entropies that this paper generalizes.","marker":"[9]"},{"why":"Supplies Pisier's formula and the operator-valued Schatten space framework from which the variational machinery is built.","marker":"[20]"},{"why":"Gives the identical-channel IID reduction and the strong-duality reduction argument for linear constraints that Appendix B adapts to arbitrary tensor products.","marker":"[25]"},{"why":"Provides the earlier generalized entropy accumulation chain rules to which the paper's new chain rules are compared and improved.","marker":"[16]"},{"why":"Supplies the additivity of Rényi entropy under tensor products of states used to obtain equality in Corollary 5.1.","marker":"[24]"},{"why":"Establishes the operator-valued Schatten space formulation of quantum entropies and the $H^\\uparrow_\\alpha = \\frac{\\alpha}{1-\\alpha}\\log\\|\\cdot\\|$ correspondence used throughout.","marker":"[5]"},{"why":"Provides the static security proof and asymptotic rate baseline against which the time-adaptive rate improvement is measured.","marker":"[23]"},{"why":"Supplies the convexity of the rate function $h$ used in the supporting-hyperplane construction for the post-processing functions.","marker":"[28]"}],"fun_headline_variants":["Multi-index Schatten norms prove channel entropy additivity","Channel entropy additivity proven via multi-index norms","Quantum entropy additivity for all tensor products","New proof of entropy additivity for quantum channels"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The constrained additivity result assumes that for every channel and linear constraint used, the convex optimization over input states can be exchanged with its Lagrangian dual with no gap; if any such channel has a duality gap, the product bound and the time-adaptive security theorem do not follow.","fun_headline_variants_meta":{"raw":{"variants":["Multi-index Schatten norms prove channel entropy additivity","Channel entropy additivity proven via multi-index norms","Quantum entropy additivity for all tensor products","New proof of entropy additivity for quantum channels"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000253,"raw_usage":{"total_tokens":1623,"prompt_tokens":1065,"completion_tokens":558,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":681,"completion_tokens_details":{"reasoning_tokens":499}},"tokens_in":681,"tokens_out":558,"duration_ms":5604,"temperature":1.0,"reasoning_tokens":499,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-09T14:51:00.306695+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute, for a small finite-dimensional channel $\\Phi$ and a linear constraint $(N,\\tau)$, the primal value $\\sup_{\\rho\\geq 0,\\,N(\\rho)=\\tau} \\|\\Phi(\\rho)\\|_{(R:1,S:p)}$ and its dual $\\inf_{\\Sigma\\geq 0,\\, g^\\Phi_p(\\rho)\\leq \\operatorname{Tr}[\\Sigma N(\\rho)]\\ \\forall\\rho} \\operatorname{Tr}[\\Sigma\\tau]$; any channel where the two values differ by more than numerical precision would break Eq. (17), and with it Theorem 4.15 and Corollary 5.1. A natural candidate is a qubit amplitude-damping channel with a constraint fixing the output Bloch component.","supporting_citations":[{"cited_title":"Devetak, M","cited_arxiv_id":null,"evidence_quote":"Provides the base multiplicativity result for completely bounded $p$-norms and the relation between $(1,\\alpha)$-norms and conditional Rényi entropies that this paper generalizes."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies Pisier's formula and the operator-valued Schatten space framework from which the variational machinery is built."},{"cited_title":"Van Himbeeck and P","cited_arxiv_id":null,"evidence_quote":"Gives the identical-channel IID reduction and the strong-duality reduction argument for linear constraints that Appendix B adapts to arbitrary tensor products."},{"cited_title":"Metger, O","cited_arxiv_id":null,"evidence_quote":"Provides the earlier generalized entropy accumulation chain rules to which the paper's new chain rules are compared and improved."},{"cited_title":"Tomamichel","cited_arxiv_id":null,"evidence_quote":"Supplies the additivity of Rényi entropy under tensor products of states used to obtain equality in Corollary 5.1."},{"cited_title":"Beigi and M","cited_arxiv_id":null,"evidence_quote":"Establishes the operator-valued Schatten space formulation of quantum entropies and the $H^\\uparrow_\\alpha = \\frac{\\alpha}{1-\\alpha}\\log\\|\\cdot\\|$ correspondence used throughout."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the static security proof and asymptotic rate baseline against which the time-adaptive rate improvement is measured."},{"cited_title":"Winick, N","cited_arxiv_id":null,"evidence_quote":"Supplies the convexity of the rate function $h$ used in the supporting-hyperplane construction for the post-processing functions."}],"review_version":1}