{"id":"dffe2a4e-2869-447b-88c5-0e5bb897e323","arxiv_id":"2504.16434","paper_version":2,"verdict":"REJECT","confidence":"MODERATE","novelty_score":2.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"The paper derives a sufficient condition for a positive Woodhead key-rate bound in BB84-like QKD, but the key inequality is false and the attack's induced error rate is never computed.","lead":"This paper claims to modify Woodhead's lower bound on secret key rates so a BB84-like quantum key distribution protocol always generates a key, and it applies the condition to two quantum cloning attacks. The central derivation relies on an inequality that appears to be false, so the claimed guarantee is not established.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The proof of the central bound uses log(delta_z) > delta_z^2 - 2.5*delta_z, which is false on (0,0.305); consequently Eqs. (21)-(23) and the claimed F, delta_z ranges are unsupported.","rationale":"The reader's weakest-assumption identification is correct and is the load-bearing point: without Eq. (21), there is no derivation of Eq. (22), and without Eq. (22) the paper's quantitative predictions are unsubstantiated. This is not a disagreement with consensus; it is an internal numerical falsehood. The paper contains no machine-checked proof or reproducible artifact that could rescue the step. I therefore see no reason to change the reader's rejection.","tokens_in":15843,"tokens_out":17152,"duration_ms":158493,"concrete_test":"Evaluate the displayed inequality log delta_z > delta_z^2 - 2.5 delta_z at delta_z = 0.2 (and at 0.01) to confirm it is false. Then recompute the allowed delta_z intervals from the exact positivity condition a + delta_z ln delta_z - delta_z > 0 for the F values listed in Tables I-III; if exact R_lb is negative for any value inside a claimed interval, or if the intervals differ from the paper's delta_z1, the central claim collapses.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section III defines R_lb = [log 2 + u log u + (1-u) log(1-u) + delta_z log delta_z - delta_z] / ln 2, with u = (1+F)/2, and then invokes log delta_z > delta_z^2 - 2.5 delta_z for delta_z in (0,0.305) to pass to Eq. (21) and the quadratic condition (22). This inequality is false throughout the stated interval: at delta_z = 0.2, ln 0.2 = -1.609 while 0.2^2 - 2.5*0.2 = -0.46, so the claimed lower-bound direction fails. Because this is the step that converts the entropy expression into the quadratic inequality, the advertised ranges F(rho_E,rho'_E) in (0.8281,0.9922) and delta_z in (0,delta_z1) with delta_z1 in (0,0.305) are not established. The central claim that the modified Woodhead bound 'always' gives positive key rate therefore rests on an unsound step. The later QCM sections also do not derive the actual delta_z induced by the cloners; for the WZ cloner the induced Z-basis error is 2 alpha^2(1-alpha^2), which for the advertised fidelity range lies well above the paper's own threshold delta_z1 <= 0.305.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper considers a BB84-like QKD protocol in which the key is distilled from Z-basis rounds, with an eavesdropper who intercepts Alice's qubit and applies a quantum cloning machine. The authors start from Woodhead's lower bound r ≥ 1 − h(u) − h(δz), u = (1 + F(ρE,ρ'E))/2 (Eq. (15)), rewrite it as an expression R in the fidelity F and the Z-basis error rate δz (Eq. (16)), and claim to derive a sufficient condition for positivity of R by applying elementary inequalities, culminating in the quadratic condition (22) and the claimed windows F ∈ (0.8281, 0.9922) and δz ∈ (0, δz1) with δz1 ∈ (0, 0.305). They then compute the fidelity induced by the Wootters–Zurek and a modified Buzek–Hillery cloner (Eqs. (33) and (42)), tabulate parameter ranges for which they claim key distillation succeeds (Tables I–III), and use Hilbert–Schmidt distance inequalities to bound the cloners' efficiency (Section V). The stated goal is a lower bound that guarantees the protocol never aborts.","tokens_in":16157,"tokens_out":43626,"duration_ms":333940,"significance":"If valid, the paper would provide a simple sufficient condition for positivity of a previously known lower bound and would show that two specific state-dependent cloning attacks cannot prevent key distillation. The manuscript has some strengths: the circuit construction of Alice's state in Section II is explicit and algebraically consistent, the fidelity computations in Appendix A (Eqs. (33) and (42)) are correct for the commuting states under consideration, and the starting point in Woodhead's bound is properly attributed. However, the central derivation rests on a numerically false inequality, the attack analysis never verifies that the error rates induced by the cloners lie within the claimed success window, and the efficiency bound (50) is violated by the paper's own WZ example. The main claim and the QCM conclusions are therefore not established, and several of the specific numerical claims are inconsistent with the protocol model as defined. The paper provides no code, data, or machine-checked verification artifacts.","major_comments":[{"comment":"The transition from (20) to (21) invokes the inequality log δz > δz² − 2.5δz for δz ∈ (0, 0.305). This inequality is false in the stated direction on the entire interval; for example, at δz = 0.2 one has ln δz = −1.609 while δz² − 2.5δz = −0.46, and the reverse inequality holds throughout the interval. Since δz log δz enters (20) with a positive coefficient, substituting a quantity that is larger than log δz yields an upper bound on R_lb, not the lower bound asserted in (21). Consequently the quadratic positivity condition (22), the derived ranges F ∈ (0.8281, 0.9922) and δz ∈ (0, δz1) with δz1 ∈ (0, 0.305), and the central claim that the key rate is positive on these ranges are unsupported. Because this is the step that converts the entropy expression into an algebraic condition, the paper's main result fails as derived.","section":"Section III, Eqs. (20)–(22)"},{"comment":"The analysis of the cloning attacks treats δz as a free parameter and never computes the Z-basis error rate that the cloners actually induce. For the WZ cloner, Bob's reduced state after the attack is ρB = α²|0⟩⟨0| + β²|1⟩⟨1| (the B-mode marginal of (28)), so a Z-basis measurement by Bob yields δz = 2α²(1 − α²) = F/2. For the paper's advertised fidelity range F ∈ (0.8281, 0.9922), this gives δz ∈ (0.414, 0.496), entirely above the claimed threshold δz1 ≤ 0.305. For the modified BH cloner the induced error is δz = ξ + 2(1 − 2ξ)α²(1 − α²), which for the parameters of Table I lies in the range ≈ 0.39–0.50; the first row of Table I (ξ = 0.1, α² = 0.241) lists the window δz ∈ (0, 0.0003) while the induced error is ≈ 0.39. Thus the conclusion that Alice and Bob can distill a secret key in the presence of these specific attacks is not supported; under the paper's own model these attacks produce error rates above the success threshold.","section":"Section IV, Tables I–II"},{"comment":"The bound (50) is derived by imposing condition (49), DHS(ρE,ρid) ≤ DHS(ρE,ρ'E), which is not a consequence of the triangle inequality but an additional assumption, and it is violated by the paper's own WZ example: for α² = 0.293 one finds DHS(ρE,ρid) = 2α²(1 − α²) ≈ 0.414 while DHS(ρE,ρ'E) = 2(α² − (1 − α²))² ≈ 0.343, so (49) fails and the claimed consequence DHS(ρE,ρid) ≤ 2D(ρE,ρ'E)² also fails numerically (0.414 > 0.343). The efficiency bounds in Tables II–III therefore do not follow from the stated derivation.","section":"Section V.A, Eqs. (48)–(50)"}],"minor_comments":[{"comment":"The title inside the manuscript, 'Achieving the positivity of the secret key in a BB84 like quantum key distribution protocol', differs from the title under which the paper is posted on arXiv; the two should be reconciled.","section":"Title"},{"comment":"The base of the logarithm is used inconsistently: (15) is expressed with log2 through h(x), while (16) uses natural log with the conversion implicit in the prefactor 1/log 2; a sentence explicitly defining log as the natural logarithm would help.","section":"Section III, Eq. (16)"},{"comment":"The abstract and introduction say that the secret key is 'always generated', but the result is conditional on the fidelity and error-rate ranges derived in Section III; the wording should be qualified.","section":"Abstract and Introduction"},{"comment":"The question posed at the end of Section IV.A, whether there exists a cloner for which Alice may choose α² in (0,1), is answered in Section IV.B only for α² ∈ (0, 0.455); the text should explicitly state that the question is answered only partially.","section":"Section IV.B"},{"comment":"The fidelity formula (A1) is stated in terms of the eigenvalues of ρσ; this is valid for the commuting states used here, since ρE and ρ'E are co-diagonal, but the formula is not valid for general states, where the Uhlmann fidelity requires the trace of the square root of √ρ σ √ρ; the appendix should state this restriction.","section":"Appendix A, Eq. (A1)"},{"comment":"The inequality (46) is actually an equality for qubit states, DHS = 2D²; noting this would clarify why the bounds in Tables II–III are loose and would simplify the derivation.","section":"Section V.A, Eq. (46)"},{"comment":"In Fig. 2 the y-axis is labeled 'r' while the caption refers to the lower bound Rlb; the plotted quantity should be labeled explicitly.","section":"Figure 2"}],"recommendation":"reject","confidential_remarks":"For the editor: the paper's central contribution is largely a restatement of Woodhead's bound with an additional inequality manipulation, and that manipulation is numerically false. The cloning-machine sections do not connect the induced error rate to the assumed parameter window, and for the two cloners studied the induced δz actually lies above the derived threshold; this is an internal inconsistency rather than a question of interpretation. A resubmission would require re-deriving the positivity condition (the exact condition δz(1 − ln δz) < ln 2 (1 − h(u)) is readily analyzable) and recomputing the attack-induced error rates, which for the WZ and modified BH cloners considered here appear to fall outside the success window. As it stands, the manuscript's numerical claims are not consistent with the protocol model it defines."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe short version: the central claim is wrong. The inequality log δ_z > δ_z^2 − 2.5δ_z, stated for δ_z ∈ (0, 0.305), is numerically false throughout that interval. At δ_z = 0.2, ln δ_z ≈ −1.61 while δ_z^2 − 2.5δ_z = −0.46. Since this is the step that converts the entropy expression into the quadratic condition, Eqs. (21)–(23) and the ranges F ∈ (0.8281, 0.9922), δ_z ∈ (0, δ_z1) with δ_z1 ≤ 0.305 all collapse.\n\nTo its credit, the paper is clearly written and the fidelity computations for the Wootters–Zurek and modified Buzek–Hillery cloners in Appendix A appear correct. The question of when Woodhead's bound is positive is legitimate, and the authors present their steps transparently.\n\nBut the soft spots are load-bearing. The \"modified bound\" is an algebraic rearrangement of Woodhead's expression plus a hand-picked inequality; there is no new security analysis. Even setting the false inequality aside, the attack analysis never computes the actual δ_z induced by either cloner. For the WZ machine on these states, the Z-basis bit error is 2α²(1−α²), which for the claimed α² interval lies between roughly 0.41 and 0.50, far above the upper limit δ_z1 ≤ 0.305. So the cloner analysis does not connect to the positivity region in the advertised way.\n\nI do not think this paper deserves a serious referee. It is a modest restatement of a known bound, and the numerical error invalidates the main result. Desk reject is the right call. If the authors correct the inequality and rederive the ranges, the result would at best be a minor technical note; as submitted, it is not a sound contribution.\n\nI would not bring this to our reading group and would not cite it.\n\nBest,\n[Your name]","headline":"The paper's central claim that the modified Woodhead bound always guarantees a positive key rate collapses on a numerically false logarithmic inequality; the advertised fidelity and error-rate ranges are unsupported.","tokens_in":16678,"tokens_out":7263,"would_cite":false,"duration_ms":64487,"reading_group":"no","serious_thinker":"yes","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P45"],"pacs":["03.67.Dd","03.67.-a"],"model":"deepseek-v4-flash","headline":"A modified lower bound guarantees a positive secret key for BB84-like QKD within a specific fidelity-error window.","keywords":["BB84-like QKD","secret key rate","lower bound","quantum cloning machine","fidelity","collective attacks","HS distance","error rate"],"falsifier":"Evaluate the inequality at $\\delta_z=0.2$: $\\log(0.2)\\approx -1.609$, while $0.2^2-2.5(0.2)=-0.46$; since $-1.609$ is not greater than $-0.46$, the inequality fails at a point inside the claimed range, so the quadratic condition and the derived fidelity and error windows do not follow from this derivation.","tokens_in":15630,"feed_emoji":"🔐","tokens_out":15853,"duration_ms":126248,"temperature":0.7,"pith_summary":"The paper tries to establish that a BB84-like quantum key distribution protocol can be guaranteed to generate a secret key, rather than sometimes aborting, by replacing a known lower bound on the secret key rate with a modified positive lower bound. The modified bound is expressed in terms of the fidelity between the two states an eavesdropper produces when cloning the two possible secret states, together with the Z-basis error rate. The paper claims that for fidelities between 0.8281 and 0.9922 there is a window of error rates, with upper bound below 0.305, in which the modified bound is positive and the protocol succeeds. It then applies this to two symmetric quantum cloning machines and finds parameter ranges where Alice and Bob can still distill a key in the presence of an eavesdropper.","feed_headline":"Guaranteed secret key for BB84-like QKD over a fidelity window","feed_subtitle":"The modified lower bound keeps the protocol alive even when Eve clones the transmitted states.","key_machinery":"The carrying object is the modified lower bound $R_{lb}$. Starting from $R=1-h(u)-h(\\delta_z)$, where $h$ is the binary entropy function, $u=(1+F)/2$, and $F=F(\\rho_E,\\rho'_E)$ is the fidelity between the two states Eve obtains after cloning the two secret states, the paper uses $x/(1+x)\\le \\log(1+x)$ to replace $(1-\\delta_z)\\log(1-\\delta_z)$ by $-\\delta_z$, then uses a numerical bound for $\\log\\delta_z$ to produce the quadratic condition $\\delta_z^2-2.5\\delta_z+2.5a-1>0$ whose solution yields $F\\in(0.8281,0.9922)$ and $\\delta_z\\in(0,\\delta_{z1})$. The analysis of particular clones enters through the fidelity formulas $4\\alpha^2(1-\\alpha^2)$ for the state-dependent cloner and $4[\\alpha^2(1-\\alpha^2)(1-2\\xi)^2+\\xi(1-\\xi)]$ for the modified symmetric cloner, which link Eve's overlap to Alice's state parameter and the cloning-machine parameter.","core_discovery":"The central claim is that the secret-key-rate lower bound can be modified so that $R_{lb}>0$ whenever the fidelity $F(\\rho_E,\\rho'_E)$ lies between 0.8281 and 0.9922 and the error rate $\\delta_z$ lies in $(0,\\delta_{z1})$ with $\\delta_{z1}\\in(0,0.305)$. The derivation starts from the cloning-based bound $R=1-h(u)-h(\\delta_z)$ with $u=(1+F)/2$, applies elementary inequalities to the entropy terms, and reduces the positivity condition to a quadratic inequality in $\\delta_z$. Solving that inequality gives the claimed ranges. For the state-dependent cloner the allowed secret-state parameter is $\\alpha^2\\in(0.293,0.456)$, while for the modified symmetric cloner, for each machine parameter $\\xi\\in(0,0.455)$ there are values of $\\alpha^2\\in(0,0.455)$ that keep $R_{lb}>0$. The paper also bounds Eve's cloning efficiency by relating fidelity to trace distance and the HS distance, giving an upper efficiency bound beyond which the protocol would be aborted.","pith_inferences":["If the claimed parameter window is correct, the same entropy-bounding step could be applied to other prepare-and-measure QKD protocols whose security bounds take the form $1-h(\\cdot)-h(\\cdot)$, converting a continuous abort-or-not condition into explicit success windows.","A direct experimental test would be to implement the modified protocol with a controllable cloner, measure $F(\\rho_E,\\rho'_E)$ and $\\delta_z$, and check whether the measured key rate stays positive exactly where the quadratic condition predicts.","The paper leaves asymmetric cloning machines open; repeating the derivation with fidelity formulas that depend on two machine parameters would replace the one-dimensional success interval with a higher-dimensional success region, a testable extension of the same construction."],"forward_implications":["For each fidelity in $F\\in(0.8281,0.9922)$, the protocol succeeds for every Z-basis error rate below the computed upper bound, so the abort condition is avoided across an explicit parameter window.","For the state-dependent cloner, Alice's state parameter must stay in $\\alpha^2\\in(0.293,0.456)$; outside that window the modified lower bound can be negative and the protocol would fail.","For the modified symmetric cloner, a range of machine parameters $\\xi\\in(0,0.455)$ admits values of $\\alpha^2\\in(0,0.455)$ for which the key remains positive, so the eavesdropper can remain hidden while a key is still distilled.","The paper's efficiency analysis yields an upper bound on Eve's HS distance: a cloning machine that is too efficient would push the protocol into abort."],"supporting_citations":[{"why":"supplies the lower-bound formula and the cloning-based security setting that the paper modifies.","marker":"[20]"},{"why":"gives the base key-rate bound $1-h(\\delta_x)-h(\\delta_z)$ that the paper's bound tightens.","marker":"[24]"},{"why":"defines the first cloning transformation and yields the fidelity $4\\alpha^2(1-\\alpha^2)$.","marker":"[26]"},{"why":"defines the symmetric cloning transformation whose parameters are fixed to make the modified machine and yields the corresponding fidelity formula.","marker":"[28]"},{"why":"supplies the fidelity formula $(\\sum_i\\sqrt{\\lambda_i(\\rho\\sigma)})^2$ used to compute overlaps.","marker":"[27]"},{"why":"supplies the inequality between the HS distance and the trace distance used to bound cloning efficiency.","marker":"[36]"},{"why":"supplies the inequality between fidelity and trace distance used in the efficiency analysis.","marker":"[35]"}],"fun_headline_variants":["BB84-like QKD: secret key always generated within fidelity window","Modified lower bound guarantees secret key for BB84-like QKD","Fidelity window ensures secret key distillation despite cloning"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing assumption is that the natural logarithm of the error rate satisfies $\\log \\delta_z > \\delta_z^2 - 2.5\\delta_z$ for every $\\delta_z\\in(0,0.305)$; this numerical inequality is what turns the lower bound into the quadratic condition that produces all the claimed fidelity and error ranges.","fun_headline_variants_meta":{"raw":{"variants":["BB84-like QKD: secret key always generated within fidelity window","Modified lower bound guarantees secret key for BB84-like QKD","Fidelity window ensures secret key distillation despite cloning"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000471,"raw_usage":{"total_tokens":2387,"prompt_tokens":1031,"completion_tokens":1356,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":647,"completion_tokens_details":{"reasoning_tokens":1302}},"tokens_in":647,"tokens_out":1356,"duration_ms":9133,"temperature":1.0,"reasoning_tokens":1302,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T11:04:44.203622+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Evaluate the inequality at $\\delta_z=0.2$: $\\log(0.2)\\approx -1.609$, while $0.2^2-2.5(0.2)=-0.46$; since $-1.609$ is not greater than $-0.46$, the inequality fails at a point inside the claimed range, so the quadratic condition and the derived fidelity and error windows do not follow from this derivation.","supporting_citations":[{"cited_title":"Devetak and A","cited_arxiv_id":null,"evidence_quote":"supplies the lower-bound formula and the cloning-based security setting that the paper modifies."},{"cited_title":"Curty, T","cited_arxiv_id":null,"evidence_quote":"gives the base key-rate bound $1-h(\\delta_x)-h(\\delta_z)$ that the paper's bound tightens."},{"cited_title":"Dogra, K","cited_arxiv_id":null,"evidence_quote":"defines the symmetric cloning transformation whose parameters are fixed to make the modified machine and yields the corresponding fidelity formula."},{"cited_title":"Woodhead, Phys","cited_arxiv_id":null,"evidence_quote":"supplies the fidelity formula $(\\sum_i\\sqrt{\\lambda_i(\\rho\\sigma)})^2$ used to compute overlaps."},{"cited_title":"Dodonov, O.V","cited_arxiv_id":null,"evidence_quote":"supplies the inequality between the HS distance and the trace distance used to bound cloning efficiency."},{"cited_title":"Buˇ zek, and M","cited_arxiv_id":null,"evidence_quote":"supplies the inequality between fidelity and trace distance used in the efficiency analysis."}],"review_version":1}