{"id":"38c4d157-1fe5-48a1-9a8e-2c0ea53f7a1a","arxiv_id":"2504.18102","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":8,"one_line_summary":"An N-particle GHZ-based secure remote sensing protocol with Heisenberg-limited precision is extended by local quantum optimal control, which numerical three-qubit simulations show improves Fisher information under dephasing and depolarizing noise.","lead":"This paper presents a protocol for secure quantum remote sensing in which Alice estimates a parameter encoded by Bob over a shared multi-particle entangled state, reaching Heisenberg-limited precision in the ideal case. The authors add local quantum optimal control pulses to mitigate dephasing and depolarizing noise, and they report improved quantum and classical Fisher information in three-qubit simulations.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Parameter-integrity claim fails for attacks mounted after verification: pre-encoding Pauli checks cannot detect a bias β introduced during Bob's evolution, so the advertised security guarantee is not established.","rationale":"The HL scaling derivation (Eq. 16) is standard and not in question; the QOC numerics are under-documented but that is a reproducibility issue, not a demonstrated logical flaw. The security argument is the one place where the text makes a definite, checkable assertion that appears to be wrong. The paper's own sequencing—verification before encoding—makes it impossible for the stated checks to catch an attack on the encoding Hamiltonian, and the alternative reading (bias injected into the distributed state) yields only probabilistic detection. This directly affects the 'unconditional security' advertised in the abstract and conclusion, so it is load-bearing. I agree with the reader's weakest_assumption and recommend keeping the verdict CONDITIONAL: the metrology core can stand once the security claim is either removed, restricted to a defined threat model that excludes post-verification tampering, or supplemented with a proof (and a test) covering such attacks. The missing numerical reproducibility of Sec. IV should also be fixed, but it is secondary.","tokens_in":13604,"tokens_out":16783,"duration_ms":185705,"concrete_test":"Run a numerical simulation of the ideal C-QSRS protocol in which an adversary, after the verification round has passed, changes Bob's encoding Hamiltonian from Hω to H_{ω+β} in Eq. (13) for the ps sensing copies. Check whether the pre-encoding σx-parity (Eq. 12) and σz-equality outcomes still pass with probability 1 and whether Alice's maximum-likelihood estimate shifts by β. This settles whether the advertised 'tampering can be detected' claim covers the actual encoding step.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Sec. III ('Parameter integrity') claims that an adversary-induced bias β in the estimated parameter is detectable via the Pauli-X verification step. This is the load-bearing security argument behind 'unconditional security' in the Conclusion. The verification checks (σx parity S_N=∏m_xk and σz equality) are performed on pc states before the encoding step, as stated in Sec. III ('Controlled security check' and 'Controlled QM'). An adversary who biases the parameter after verification—for example, replacing Hω in Eq. (13) by H_{ω+β} during the evolution encoded on Bob's NS qubits—leaves every pre-encoding verification outcome unchanged while shifting the state in Eq. (14) to a relative phase (ω+β)N_S t_s/2. Alice's final estimate is then ω+β, with no detection event. Even under the more favorable interpretation that the bias is injected into the distributed GHZ state before verification, a single σx parity round rejects only with probability (1−cosβ)/2, so detection is probabilistic, not guaranteed. Since the paper's 'secure' claim depends on this argument, the protocol's advertised security guarantee is not established by the presented analysis.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript proposes a controlled quantum secure remote sensing (C-QSRS) protocol. In the ideal setting, Alice (or a trusted external source) distributes an N-partite GHZ state, verifies it with sigma_x parity and sigma_z equality checks, and Bob encodes an unknown parameter omega on his N_S qubits under H_omega = (omega/2) sum_j sigma_z^(j); Alice's final sigma_x measurement yields Heisenberg-limited scaling. For non-ideal dynamics, the paper introduces local quantum optimal control (QOC) pulses on Bob's qubits and reports, for a three-qubit system (N=3, N_A=1, N_S=2), numerical improvements in the quantum and classical Fisher information under generalized Pauli dephasing, parallel dephasing, and depolarizing noise, for both noiseless and noisy communication channels. The paper further claims that the protocol achieves unconditional security, including detection of an adversary-induced parameter bias beta.","tokens_in":13928,"tokens_out":5731,"duration_ms":66536,"significance":"The ideal-case protocol is a straightforward GHZ-based remote sensing scheme, and the reported Heisenberg-limited variance scaling of Eq. (16) appears correct. The more novel contribution is the numerical study of local QOC as a noise-mitigation tool for secure remote sensing; if the reported gains are reproducible, the idea is of interest to the quantum sensing and quantum communication communities. I also note that the metric comparison is not circular: the uncontrolled baseline is computed independently of the QOC optimization, and the noise rates are fixed model parameters rather than fitted to the target results. However, the security claim is not established by the presented verification argument, and the numerical results are not reproducible from the manuscript as written, so the advertised conclusions currently outrun the evidence.","major_comments":[{"comment":"The claim that an induced bias beta is detected by the sigma_x parity verification is not supported. The parity and equality checks are performed on the distributed GHZ states before the encoding step, as stated in Sec. III ('Controlled security check'). An adversary who replaces H_omega in Eq. (13) by H_{omega+beta} during Bob's evolution leaves every pre-encoding verification outcome unchanged while shifting the phase in Eq. (14) to N_S(omega+beta)t_s/2; Alice then silently estimates omega+beta with no detection event. Even under the more favorable interpretation that the bias is inserted into the distributed state before verification, a single sigma_x parity round rejects only with probability (1-cos(beta))/2, so detection is probabilistic rather than guaranteed. The Conclusion's 'unconditional security' therefore requires either a formal attack model that includes post-verification parameter tampering, or a substantially weakened security claim.","section":"Sec. III, 'Parameter integrity'"},{"comment":"The central quantitative claim that local QOC improves the QFI and CFI rests entirely on numerical simulations whose details are not reported. The paper specifies the control Hamiltonian in Eq. (19) and names GRAPE and differential evolution as optimizers, but it does not give the time discretization, number of control intervals, amplitude bounds, convergence tolerances, number of independent optimization runs, or the resulting optimal control pulses. Figures 4 and 5 contain no error bars or convergence data, and the data availability statement only offers code 'upon reasonable request.' Under standard reproducibility expectations, the reported C-QFI and C-CFI values cannot be verified from the manuscript; the authors should provide code and data, or at minimum a detailed optimization appendix with all hyperparameters.","section":"Sec. IV, Figs. 4-5"},{"comment":"For the noisy mixed states, the paper never states how the QFI is computed numerically. Equation (5) gives the SLD expression in the eigenbasis of rho, but the manuscript does not specify how F_Q(rho_omega) is evaluated for the Lindblad-evolved density matrices used in Secs. IV.C.1-IV.C.3, nor how the derivative partial_omega rho is obtained. Since the QFI is the primary metric in Figures 4 and 5, the numerical method (e.g., spectral decomposition with finite-difference derivatives, or an exact SLD formula) must be described to make the results checkable.","section":"Sec. IV, QFI computation"},{"comment":"The protocol does not quantify the number of verification rounds p_c needed for any claimed security level. The text states that p_c states are randomly chosen for sigma_x and sigma_z tests, but no relation is derived among p_c, the detection probability for a malicious modification, and an adversary's success probability. With finite p_c the guarantee is statistical, not 'unconditional,' and the Conclusion's use of 'unconditional security' is therefore too strong. A finite-resource security statement, or a clearly delimited asymptotic claim, is needed.","section":"Sec. III, 'Controlled security check' and Conclusion"}],"minor_comments":[{"comment":"The notation in Eq. (16) is inconsistent: the first expression uses sin^2(N_S omega t_s), while the denominator uses sin(N_S omega t), and the final identity should read 1/(p_s N_S^2 t_s^2). The variable t_s should be used consistently throughout the equation.","section":"Eq. (16)"},{"comment":"The statement that the scheme achieves Heisenberg-limited scaling should be qualified: the variance in Eq. (16) scales as (N_S t_s)^-2, not (N t_s)^-2, because the N_A ancilla qubits held by Alice do not enter the encoded phase. This is asymptotically equivalent to HL when N_S is proportional to N, but for finite N the precise statement differs from 'N-particle HL scaling.'","section":"Sec. III, 'Secure parameter teleportation'"},{"comment":"The paper reports in Sec. IV.C.1 and IV.C.3 that QOC does not improve tripartite negativity, while Figures 4 and 5 show substantial QOC gains in Fisher information. This apparent tension is never addressed; a brief explanation (e.g., that local controls can protect parameter-sensitive coherences without increasing genuine tripartite entanglement) would improve the reader's understanding.","section":"Sec. IV.C, tripartite negativity"},{"comment":"The density-matrix elements in Eq. (21) contain absolute values such as |(4-3Gamma)Gamma|, which is unusual for a valid physical state. Clarify whether these expressions assume Gamma in a particular range or whether the absolute values are part of the state definition; as written, the positivity and smoothness of the state as a function of Gamma are unclear.","section":"Sec. IV.B.2.b, Eq. (21)"}],"recommendation":"major_revision","confidential_remarks":"The paper's central security claim is currently not supported, and the numerical evidence for the QOC enhancement is not reproducible from the manuscript. Both issues are fixable in revision: the authors can either prove a precise security statement for the attack model they intend, or remove 'unconditional security' and clearly scope the claim; and they can supply code, data, and complete optimization parameters. The ideal-case Fisher-information calculation is sound, so I do not see grounds for rejection if these concerns are addressed. I would also ask the editor to consider whether a dedicated reproducibility/data-availability policy applies, given the manuscript's reliance on numerical simulation."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe paper does two things: it re-derives the standard Heisenberg-limited sensitivity for an N-party GHZ remote sensing protocol, and it adds local quantum optimal control (QOC) to fight decoherence in a three-qubit example. The first part is textbook; the second is the actual new bit, and it is plausible but not fully supported.\n\nWhat is good: the ideal-case QFI/CFI calculation is correct. The protocol—Alice distributes a GHZ state, Bob encodes ω via σz on his qubits, Alice measures σx—is clean, and the claim that Bob learns nothing about ω after tracing out Alice's subsystem is right. The noise analysis covers reasonable models (GPD, PPD, depolarizing, with and without a noisy channel), and the plots consistently show QOC improving both QFI and CFI.\n\nThe soft spots are real. First, the security argument. The 'parameter integrity' paragraph says an induced bias β is detected by the Pauli-X verification check. But that check is performed on pc copies before the sensing copies run. An adversary who tampers with Bob's Hamiltonian after verification—say, by adding β during the encoding evolution—leaves every verification outcome unchanged and shifts Alice's estimate by β. The paper never addresses this. Even if the bias were injected into the distributed state before verification, a single parity round only detects it with probability (1−cosβ)/2. So the 'unconditional security' claim in the conclusion is not established. The protocol may be secure against some attacks, but the adversary model is unspecified and the proof is missing.\n\nSecond, the QOC results are purely numerical: no code, no data, no error bars, and incomplete optimization details (number of GRAPE iterations, DE population, whether curves are best-run or averaged). The noise rates are hand-picked, which is fine, but without reproducibility the central noisy-case claim is hard to verify. This is common in optimal control papers, but it matters because the entire contribution rests on those numbers.\n\nThird, the ideal N-partite protocol overlaps with the authors' own Ref. [14] and earlier GHZ remote sensing work; the novelty is the QOC layer, and that is modest.\n\nNet: the metrology is fine, the QOC idea is reasonable, but the security headline fails as stated. I would not cite this in its current form, but it deserves a serious referee to sort out the adversary model and the numerical reproducibility. Send it to review, expect major revision.","headline":"The ideal GHZ sensing calculation is standard and sound, but the paper's 'unconditional security' claim depends on a verification step that runs before the parameter is encoded, so the advertised guarantee is not established.","tokens_in":14369,"tokens_out":2596,"would_cite":false,"duration_ms":26854,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"An N-party GHZ-based remote sensing protocol reaches Heisenberg-limited precision under ideal conditions, and local quantum optimal control restores much of that precision under dephasing and depolarizing noise.","keywords":["secure quantum sensing","quantum metrology","GHZ states","Heisenberg limit","quantum Fisher information","quantum optimal control","dephasing noise","depolarizing noise"],"falsifier":"After the $\\sigma_x$-parity and $\\sigma_z$-equality checks pass, insert an unknown bias $\\beta$ into the Hamiltonian Bob applies; if the checks still pass and Alice's estimate becomes $\\omega+\\beta$ with unchanged verification statistics, the parameter-integrity claim fails. A numerical version of the same attack in the three-qubit model would settle it without an experiment.","tokens_in":13420,"feed_emoji":"⚛️","tokens_out":12065,"duration_ms":101954,"temperature":0.7,"pith_summary":"The paper proposes a general N-particle protocol, C-QSRS, in which Alice estimates a single unknown parameter at a remote site by sharing a multiparticle Greenberger-Horne-Zeilinger (GHZ) state with Bob, a semi-trusted sensor who cannot prepare quantum states and is intended to learn nothing about the parameter. In an ideal channel and encoding, the protocol reaches Heisenberg-limited scaling, with the quantum Cramér-Rao bound falling as $1/(p_s N_S^2 t_s^2)$. For non-ideal dynamics, the scheme adds local quantum optimal control (QOC) pulses on Bob's qubits, and a three-qubit numerical analysis shows that the controlled protocol raises both the quantum and classical Fisher information under generalized Pauli dephasing, parallel dephasing, and depolarizing noise. The security mechanism is a pre-encoding verification of the shared GHZ state using $\\sigma_x$-parity and $\\sigma_z$-equality checks, plus the fact that Bob's reduced state contains no parameter information.","feed_headline":"Remote sensing hits the Heisenberg limit; control tames noise.","feed_subtitle":"N-party GHZ protocol hits the quantum precision bound; control pulses keep Fisher information high under noise.","key_machinery":"The load-bearing object is the multiparticle GHZ state $|\\Psi_N\\rangle = (|0\\rangle^{\\otimes N}+|1\\rangle^{\\otimes N})/\\sqrt{2}$, split into $N_A$ qubits kept by Alice and $N_S$ qubits sent to Bob, together with the encoding Hamiltonian $H_\\omega = (\\omega/2)\\sum_{j=1}^{N_S}\\sigma_z^{(j)}$, which turns the parameter into a relative phase between the two GHZ branches. The security machinery is the two-basis verification: $\\sigma_x$ measurements whose outcome product must be $+1$, and $\\sigma_z$ measurements whose outcomes must all agree. The noisy-case machinery is the local control Hamiltonian $H_c(t) = \\sum_i u_i(t)\\sigma_i^{(2)} + \\sum_j v_j(t)\\sigma_j^{(3)}$ acting only on Bob's qubits, with amplitudes optimized to maximize the quantum or classical Fisher information; tripartite negativity sets the practical evolution time before entanglement is lost.","core_discovery":"The paper's central claim is that entanglement alone can secure remote sensing: an N-qubit GHZ state distributed between Alice and Bob, verified by $\\sigma_x$-parity and $\\sigma_z$-equality checks, lets Alice estimate a parameter encoded by Bob's evolution under $H_\\omega = (\\omega/2)\\sum_{j=1}^{N_S}\\sigma_z^{(j)}$ with Heisenberg-limited precision, while Bob's share never carries the parameter. The noisy extension claims that local time-dependent controls on Bob's qubits, optimized with GRAPE for dephasing and differential evolution for depolarizing noise, increase the achievable quantum and classical Fisher information; in the three-qubit examples the controlled classical Fisher information can even exceed the uncontrolled quantum Fisher information.","pith_inferences":["Not tested in the paper: since QOC raises Fisher information in generalized Pauli dephasing and depolarizing cases even though tripartite negativity is essentially unchanged, the mechanism is likely protection of specific two-qubit correlations rather than preservation of genuine tripartite entanglement; a bipartite negativity or subsystem QFI diagnostic would test this.","Not tested in the paper: the verification checks occur before encoding, so an adversary who can alter Bob's encoding Hamiltonian after the checks pass could inject an unknown bias into the estimate without tripping the $\\sigma_x$-parity or $\\sigma_z$-equality tests; a post-encoding check or authenticated encoding Hamiltonian would close that gap.","Not tested in the paper: the ideal Heisenberg scaling is directly testable in current photonic experiments by preparing GHZ states of increasing size and comparing the slope of $\\log F_Q$ versus $\\log N_S$ with the predicted value of $2$."],"forward_implications":["Under ideal conditions the estimation error obeys $(\\Delta\\tilde{\\omega})^2 \\approx 1/(p_s N_S^2 t_s^2)$, the Heisenberg limit, so each additional sensing particle improves precision quadratically rather than linearly.","Because tracing out Alice's share leaves Bob with the parameter-independent state $\\frac12(|0\\rangle\\langle0|^{\\otimes N_S}+|1\\rangle\\langle1|^{\\otimes N_S})$, Bob cannot learn the parameter from his subsystem alone.","In all considered noise models, including combinations with depolarizing communication noise, the QOC-controlled protocol yields higher quantum and classical Fisher information than the uncontrolled protocol.","The controlled classical Fisher information can surpass the uncontrolled quantum Fisher information, meaning the optimized local measurement extracts more from the noisy state than the best uncontrolled strategy does.","The framework is designed to extend to arbitrary $N$, tunable encoding schemes, and other measurement or LOCC strategies, with the three-qubit cases serving as the numerical demonstration."],"supporting_citations":[{"why":"Defines the Heisenberg limit that the protocol claims to achieve.","marker":"[1]"},{"why":"Introduces the secure quantum parameter transmission setting that C-QSRS generalizes.","marker":"[10]"},{"why":"Demonstrates entanglement-based secure remote sensing with LOCC verification, the security model the protocol adopts.","marker":"[11]"},{"why":"Provides earlier secure quantum sensing work that this paper extends to an N-party scheme with quantum optimal control.","marker":"[14]"},{"why":"Supplies the GRAPE algorithm used to optimize local control pulses for dephasing noise.","marker":"[26]"},{"why":"Supplies the differential evolution optimizer used for the depolarizing noise cases.","marker":"[29]"},{"why":"Defines bipartite negativity, which the paper uses to build the tripartite entanglement benchmark.","marker":"[30]"},{"why":"Defines the geometric-mean tripartite negativity used to fix the maximum evolution time before entanglement vanishes.","marker":"[31]"}],"fun_headline_variants":["Remote sensing reaches quantum limit with control-assisted GHZ","Secure quantum sensing hits Heisenberg bound under noise","Control pulses boost Fisher info in noisy quantum remote sensing","GHZ states and optimal control achieve quantum-limited sensing","Noise-tamed quantum remote sensing at Heisenberg precision"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security claim assumes that the pre-encoding GHZ verification checks ($\\sigma_x$ parity and $\\sigma_z$ equality) catch any tampering with the parameter, including an induced bias that an adversary could insert into Bob's encoding after the checks are done.","fun_headline_variants_meta":{"raw":{"variants":["Remote sensing reaches quantum limit with control-assisted GHZ","Secure quantum sensing hits Heisenberg bound under noise","Control pulses boost Fisher info in noisy quantum remote sensing","GHZ states and optimal control achieve quantum-limited sensing","Noise-tamed quantum remote sensing at Heisenberg precision"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000194,"raw_usage":{"total_tokens":1315,"prompt_tokens":866,"completion_tokens":449,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":482,"completion_tokens_details":{"reasoning_tokens":373}},"tokens_in":482,"tokens_out":449,"duration_ms":4975,"temperature":1.0,"reasoning_tokens":373,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T10:24:47.990946+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"After the $\\sigma_x$-parity and $\\sigma_z$-equality checks pass, insert an unknown bias $\\beta$ into the Hamiltonian Bob applies; if the checks still pass and Alice's estimate becomes $\\omega+\\beta$ with unchanged verification statistics, the parameter-integrity claim fails. A numerical version of the same attack in the three-qubit model would settle it without an experiment.","supporting_citations":[{"cited_title":"A trusted exter- nal source generates and distributes entanglement between Alice and Bob","cited_arxiv_id":null,"evidence_quote":"Defines the Heisenberg limit that the protocol claims to achieve."},{"cited_title":"Demkowicz-Dobrzański and L","cited_arxiv_id":null,"evidence_quote":"Provides earlier secure quantum sensing work that this paper extends to an N-party scheme with quantum optimal control."},{"cited_title":"Hassani, S","cited_arxiv_id":null,"evidence_quote":"Supplies the GRAPE algorithm used to optimize local control pulses for dephasing noise."},{"cited_title":"Huang, C","cited_arxiv_id":null,"evidence_quote":"Defines bipartite negativity, which the paper uses to build the tripartite entanglement benchmark."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the geometric-mean tripartite negativity used to fix the maximum evolution time before entanglement vanishes."}],"review_version":1}