{"id":"3a0e4e88-8748-49b8-9d87-f2442d6672fc","arxiv_id":"2505.12974","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"Randomly varying SPAD gate voltage under pulsed detector blinding creates a large trigger-pulse energy gap that reveals eavesdropper fingerprints and enables estimation of compromised key bits.","lead":"This paper tests a defense against detector blinding attacks on quantum key distribution, where an attacker blinds the receiver's photon detectors and forces fake clicks. The authors show that under pulsed blinding, randomly varying the detector's gate voltage makes the attacker leave detectable double-click fingerprints, allowing the honest parties to estimate how many key bits were compromised.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Countermeasure collapses if Eve can infer Bob's gate voltage from optical back-reflection or blinding-light response; the paper assumes she only guesses, with no side-channel analysis.","rationale":"After reading the paper carefully, the central claim has two pillars: the measured energy gap satisfying 2Ehigh_always <= Elow_never, and the statistical conversion of double/error clicks into an estimate of Eve's controlled bits. The first pillar is supported by the experimental figures, though the abstract's 13 dB vs 25 dB discrepancy and missing error bars are worrying. The second pillar, however, only functions if Eve's gate-state guess can be wrong. The paper defines probabilities Phigh/Plow for Eve sending the two trigger energies but does not justify why Eve cannot determine the gate state. The manuscript itself cites Trojan-horse attacks, so an optical or electrical side channel revealing the gate is within the standard threat model. I agree with the reader that this is the weakest assumption. Because this concern can be settled empirically and does not contradict the measured physics, I do not recommend changing the conditional verdict: the paper should add a side-channel test and, if leakage exists, an optical isolation or randomization scheme or a revised threat model. The separate algebraic inconsistencies in Appendix A and Eq. (5) are real but less load-bearing: they bias the estimator, generally in a conservative direction, rather than invalidate the countermeasure, and a corrected derivation would not change the qualitative conclusion.","tokens_in":12329,"tokens_out":16115,"duration_ms":173254,"concrete_test":"Build the Fig. 3 setup with randomized gate voltages (default 3.95 V vs low 2.31 V) and 10 MHz pulsed blinding. Add an eavesdropper monitoring photodiode at the input to record the optical power back-reflected from Bob during each blinding pulse, plus a current probe on the blinding line, synchronized to the gate toggle. For 10^5 gate slots, train a simple threshold classifier on the reflected/current waveform to label high vs low gate and measure classification accuracy with the gate toggle disabled as a chance-level control. If accuracy is significantly above 50%, Eve can learn the gate in real time and choose matching trigger energies, nullifying condition (1). If the test shows no leakage above noise, the concern is settled.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The countermeasure depends entirely on Eve being forced to guess Bob's gate-voltage level. Section V states that 'Eve tries to guess not only the basis but also the gate level set by Bob,' and the leakage estimator in Eqs. (5)-(8) counts double/error clicks that occur only when Eve sends the low-gate trigger energy while Bob is actually at the high gate. The paper never examines whether the gate state is observable from Eve's side. Eve already injects bright blinding light into Bob; the APD photocurrent, the voltage drop across Rbias, and the optical back-reflection from Bob's input are all gate-dependent. If Eve can measure any of these during each blinding pulse (or via a probe pulse), she can choose Ealways for the actual gate, so condition (1) never produces a fingerprint. This is not an exotic assumption: the paper cites Trojan-horse attacks [2], and Huang et al. [29] showed that a similar 'breakable unrealistic assumption' defeats the CW version of random-detector-efficiency countermeasures. Without a leakage analysis or a measured bound on information about the gate state, the central claim that pulsed DBA leaves detectable fingerprints is conditional on an unverified physical assumption.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"Melkonian et al. present a countermeasure against the pulsed detector blinding attack (DBA) on QKD receivers, based on randomly switching the SPAD gate voltage between two levels. They experimentally measure a large gap, about 25 dB, between the trigger-pulse energies required to produce clicks under high and low gate voltages in the blinded state, satisfying condition (1). They then model the statistics of double- and error-click 'fingerprints' that arise when Eve guesses the wrong gate level, derive estimators for the fraction of key bits under Eve's control (Eqs. (5)-(8)), and simulate the resulting secure key fraction for one- and two-SPAD receivers.","tokens_in":12622,"tokens_out":13609,"duration_ms":126675,"significance":"The proposed countermeasure is attractive because it requires no extra optical components in Bob's receiver and, if the underlying assumptions hold, it not only detects DBA but also yields a quantitative estimate of the leaked key fraction. The paper provides a parameter-free relation between observed click anomalies and the attack parameters (alpha, beta), and the numerical simulation suggests that a substantial secure key rate can be maintained even under pulsed DBA. The main experimental quantity, the energy gap, is directly measured for a commercial SPAD. However, the security guarantee depends on the eavesdropper being unable to learn the instantaneous gate voltage, an assumption that is not analyzed.","major_comments":[{"comment":"The derivation of the double-click probability is algebraically inconsistent. Substituting the conditional probabilities (A1) into (A2) gives P_bld_double = alpha*beta/4, not alpha*beta/2 as claimed in (A3) and used in Eq. (5). The physical argument in Section V (that basis mismatch contributes a factor 1/2) accounts for the prefactor 1/2, so the additional 1/2 inside each term of (A2) is spurious. Because Eqs. (5)-(8) and the subsequent numerical simulations depend on this factor, the authors must correct the derivation and re-examine the resulting estimates.","section":"Appendix A, Eqs. (A1)-(A3) and Eq. (5)"},{"comment":"The countermeasure and the leakage estimator rely on the assumption that Eve can only guess Bob's gate-voltage setting (with probabilities alpha and beta) and cannot determine it in real time. However, Eve already sends bright light into Bob's receiver; optical back-reflection from Bob's input, the photocurrent through the SPAD, or the response to blinding pulses can be gate-voltage dependent and could reveal the applied level. The paper cites Trojan-horse attacks [2] and the breakable-unrealistic-assumption analysis of Huang et al. [29] but does not analyze this side channel. Without a quantitative bound on the information Eve can obtain about the gate level, the claim that DBA necessarily leaves fingerprints is not fully established. Please provide a side-channel analysis or explicitly state this assumption as a limitation.","section":"Section V, security model"},{"comment":"The central experimental claim is that (Elow_never - Ehigh_always)/Ehigh_always >= 500, i.e., about 25 dB, satisfying condition (1). However, the reported measurements lack error bars, the number of repetitions, and a specific detector model or part number. Given that the entire countermeasure hinges on this margin, the authors should provide uncertainty estimates and reproducibility details.","section":"Section IV, Figs. 4 and 5"}],"minor_comments":[{"comment":"The abstract states 'approximately 13 dB increase' while the introduction and conclusions state 'approximately 25 dB'. Please decide on the correct value and make it consistent throughout.","section":"Abstract vs. Introduction and Conclusions"},{"comment":"The formatting of Table I is garbled (e.g., 'Pdet * 10.1 6 .45 2 .35 6 .58 6 .45 6 .12'); please present the data in a standard table with clear column headers.","section":"Table I"},{"comment":"The symbols Phigh and Plow are used both as probabilities for sending trigger pulses and as labels for high- and low-energy pulses. Please disambiguate, for example by writing P(E_low_gate) for the probability of sending the low-gate-appropriate pulse.","section":"Section V, notation"},{"comment":"It would be helpful to state explicitly that the optimal alpha in (10) is obtained by maximizing (8) with Nexp_double and NAliceQEve treated as given, and to comment on the resulting beta at this optimum.","section":"Section V, Eq. (10)"},{"comment":"In the conclusion, the statement that 'Eve cannot steal more than approximately one third of the distributed key' for a 100 km two-SPAD system should specify the simulation parameters (alpha, beta, eta2) used to obtain that number.","section":"Section VI, numerical claim"}],"recommendation":"major_revision","confidential_remarks":"The most serious issue in my view is the side-channel concern about gate-voltage leakage: if Eve can learn the gate setting from the blinding-light response or back-reflection, the countermeasure collapses. Even if the authors cannot fully close this channel, they should state the assumption explicitly and discuss its plausibility. The algebraic error in Appendix A is also load-bearing and must be fixed before the estimator can be used."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear [Colleague],\n\nTwo things to know. First, the core experimental claim is worth taking seriously: under pulsed detector blinding, varying the gate voltage produces a much larger gap between the trigger energies that always fire a blinded detector at the high gate and those that never fire it at the low gate—roughly 25 dB, versus near-overlap under CW blinding. If that holds, it is a real hardware-only option for catching pulsed DBA that prior work (Huang et al.) had left for dead. Second, the paper as written is not yet a secure countermeasure. The entire leakage-estimation scheme assumes Eve only guesses Bob's gate level and cannot observe it. The authors do not analyze whether the gate state leaks via optical back-reflection, blinding-light response, or any other probe. Since Eve already controls the bright illumination, this is a load-bearing assumption, not a formality.\n\nWhat the paper does well: the measurement is new and directly addresses a known gap in the literature. The idea of using double-click or error-click statistics to estimate the number of attacked bits rather than discarding the entire key is practical and, as far as I know, not in the earlier random-detector-efficiency papers. The numerical simulation of key fraction is a reasonable first pass.\n\nSoft spots, in rough order of severity. The side-channel point above is the big one; without a quantitative bound on Eve's information about the gate state, condition (1) cannot be the basis of a security claim. Second, the algebra in Appendix A and Eq. (7) does not check out: plugging the stated conditional probabilities (A1) into (A2) gives αβ/4, not αβ/2, and Eq. (7) appears to compound the error. That does not necessarily sink the physics, but it means the estimator formulas are currently unsubstantiated. Third, the experimental reporting is thin: no error bars, no detector model, no raw data, and the abstract says 13 dB while the main text says 25 dB. Fourth, the countermeasure is tested on a single detector setup, not an end-to-end two-detector QKD system, so the fingerprint statistics are extrapolated rather than demonstrated.\n\nWho should read this: people actively working on detector-control attacks and countermeasures for SPAD-based QKD. It is a useful experimental data point and a plausible direction, but it is not yet a trustworthy security claim. I would send it to peer review, not desk reject, because the core measurement is likely reproducible and the question it addresses matters. The reviewers should push hard on the side-channel and the statistics.","headline":"A potentially useful experimental insight about pulsed detector blinding and gate-voltage randomization, undermined by an unexamined side-channel and sloppy statistics.","tokens_in":13151,"tokens_out":4762,"would_cite":false,"duration_ms":43254,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Randomly switching the gate voltage of Bob's single-photon detectors makes a pulsed detector-blinding attack leave double- and error-click fingerprints, and those fingerprints reveal the fraction of key bits Eve controlled.","keywords":["quantum key distribution","detector blinding attack","pulsed blinding attack","single-photon avalanche diode","gate voltage randomization","double-click statistics","error-click statistics","secret-key leakage estimation"],"falsifier":"Give Eve a tap on Bob's blinding-light back-reflection or gate-switching timing and test whether she can classify the gate-voltage level before each trigger pulse; if she then imposes clicks at the normal rate with no excess double or error clicks, the assumption behind Eqs. (5)-(8) is false.","tokens_in":12117,"feed_emoji":"🔐","tokens_out":14068,"duration_ms":138433,"temperature":0.7,"pith_summary":"The paper claims that randomly switching the gate voltage of Bob's single-photon avalanche diode (SPAD) detectors turns the pulsed detector-blinding attack into a detectable, countable intrusion. Under pulsed blinding light, the maximum trigger-pulse energy that never clicks a detector at low gate exceeds the minimum that always clicks at high gate by so much that the no-fingerprint condition $2E_{\\mathrm{high}}^{\\mathrm{always}} \\le E_{\\mathrm{low}}^{\\mathrm{never}}$ holds with a margin of at least 500; a pulse aimed at a low gate therefore double-clicks or error-clicks when the default gate is actually applied. The observed double- and error-click statistics feed closed-form estimators for the fraction of key bits Eve controlled, and numerical simulations suggest that over standard channel lengths Bob can keep most of the secret key rate even while under attack. The why-care is practical: this is a receiver-side, no-new-optics countermeasure for commercial SPAD-based QKD systems that does more than raise an alarm.","feed_headline":"Gate-voltage jumps expose Eve's blinding clicks in QKD","feed_subtitle":"Trigger pulses aimed at low gates double-click at high gates, so Bob can count Eve's stolen bits.","key_machinery":"The load-bearing object is the energy-gap condition $2E_{\\mathrm{high}}^{\\mathrm{always}} \\le E_{\\mathrm{low}}^{\\mathrm{never}}$, together with the gate-voltage mechanism that produces it. Here $E_{\\mathrm{high}}^{\\mathrm{always}}$ is the minimum trigger energy that always clicks at the higher gate and $E_{\\mathrm{low}}^{\\mathrm{never}}$ the maximum trigger energy that never clicks at the lower gate. Because the blinded APD operates in a linear multiplication regime and the gate voltage changes the SPAD supply voltage by the full $\\Delta V$ while a bias change is shunted by $R_{\\mathrm{bias}}$, a small gate change creates a large threshold shift under pulsed blinding. The condition makes Eve's failure to guess Bob's gate level visible as double or error clicks, and those click counts are the input to the leakage estimators in Eqs. (5)-(8).","core_discovery":"On its own terms, the discovery is that pulsed blinding leaves a physical handle that CW blinding removes. When the SPAD is blinded, the photocurrent reduces the voltage across the quenching resistor and pushes the avalanche multiplication factor into its linear regime; lowering the gate voltage then lowers the APD supply voltage by the full $\\Delta V$, whereas lowering the bias voltage mostly drops across $R_{\\mathrm{bias}}$ and hardly changes the voltage across the APD itself. Measured on a commercial InGaAs/InP SPAD, this asymmetry makes the threshold gap under pulsed DBA large enough that $2E_{\\mathrm{high}}^{\\mathrm{always}} \\le E_{\\mathrm{low}}^{\\mathrm{never}}$ holds. An Eve who sends a trigger pulse calibrated for the low gate inevitably produces double clicks on a two-SPAD receiver or error clicks on a one-SPAD receiver whenever Bob's actual gate is the high one; the fingerprint probability is $\\alpha\\beta/2$ and the successful-imposition probability is $(\\alpha+\\beta-\\alpha\\beta)/2$. From the observed double- and error-click counts, the legitimate users can therefore estimate, and then remove, the fraction of key bits Eve controlled.","pith_inferences":["A natural extension the paper leaves implicit is to use the same energy-gap measurement as a pre-deployment vulnerability check: if a detector's $E_{\\mathrm{high}}^{\\mathrm{always}}$ and $E_{\\mathrm{low}}^{\\mathrm{never}}$ do not satisfy the condition, the receiver is known to be open to pulsed DBA before any attack occurs.","The estimator treats every double or error click as Eve's fingerprint, which is conservative; on noisy channels, an adaptive baseline of ordinary double-click and error rates could raise the usable key rate with little added risk.","Because the gap shrinks as average blinding power rises, a plausible Eve could try to raise the blinding power to compress the gap; the paper's margin should therefore be checked at the maximum blinding power the SPAD can tolerate before permanent damage."],"forward_implications":["Pulsed detector blinding no longer forces a full key abort: the legitimate users can estimate the fraction of bits Eve imposed and remove exactly those bits in privacy amplification.","The countermeasure requires no new optical components inside Bob; it uses gate-voltage randomization and the double- and error-click statistics already collected during the session.","For a typical two-SPAD receiver, the numerical simulation says Eve cannot take more than about a third of the key on a 100 km channel without the double-click statistics revealing her.","Continuous-wave blinding remains concealed from this method, so the scheme must operate alongside basic detector current monitoring.","One-SPAD receivers can apply the same error-click estimator, but they need much lower dark-count rates and better optical alignment to keep a comparable secure-key fraction."],"supporting_citations":[{"why":"Shows the random-detector-efficiency countermeasure is breakable under CW blinding; the pulsed-DBA result must beat this baseline.","marker":"[29]"},{"why":"Supplies the original random detector-efficiency countermeasure and its patent, which the paper extends from detection to leakage estimation.","marker":"[27, 28]"},{"why":"Provides the avalanche multiplication factor versus supply-voltage description behind the gate-voltage threshold-shift mechanism.","marker":"[34]"},{"why":"Defines the detector-blinding attack on commercial QKD detectors that the proposed countermeasure targets.","marker":"[5]"},{"why":"Demonstrates SPAD current monitoring against bright illumination and supplies the auxiliary defense still needed for CW blinding.","marker":"[21]"},{"why":"Gives the decoy-state gain formula used to bound the maximum number of fake states Eve can send in the leakage estimator.","marker":"[35]"}],"fun_headline_variants":["Pulsed blinding leaves a handle: gate voltage reveals Eve's key bits","SPAD gate trick counts Eve's stolen bits under pulsed blinding","Gate-voltage asymmetry counts stolen QKD bits from pulsed DBA","Lower gate voltage fingerprints Eve's pulsed blinding attacks","New countermeasure estimates key leakage from pulsed blinding"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The leakage estimate assumes Eve never learns, in real time, which gate voltage Bob has set; if she can infer the gate level from optical back-reflection, timing, or blinding-light response, she can send matching trigger pulses and leave no fingerprints.","fun_headline_variants_meta":{"raw":{"variants":["Pulsed blinding leaves a handle: gate voltage reveals Eve's key bits","SPAD gate trick counts Eve's stolen bits under pulsed blinding","Gate-voltage asymmetry counts stolen QKD bits from pulsed DBA","Lower gate voltage fingerprints Eve's pulsed blinding attacks","New countermeasure estimates key leakage from pulsed blinding"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000704,"raw_usage":{"total_tokens":3158,"prompt_tokens":914,"completion_tokens":2244,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":530,"completion_tokens_details":{"reasoning_tokens":2162}},"tokens_in":530,"tokens_out":2244,"duration_ms":15722,"temperature":1.0,"reasoning_tokens":2162,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T20:23:05.309670+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Give Eve a tap on Bob's blinding-light back-reflection or gate-switching timing and test whether she can classify the gate-voltage level before each trigger pulse; if she then imposes clicks at the normal rate with no excess double or error clicks, the assumption behind Eqs. (5)-(8) is false.","supporting_citations":[{"cited_title":"Huang, S","cited_arxiv_id":null,"evidence_quote":"Shows the random-detector-efficiency countermeasure is breakable under CW blinding; the pulsed-DBA result must beat this baseline."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the avalanche multiplication factor versus supply-voltage description behind the gate-voltage threshold-shift mechanism."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates SPAD current monitoring against bright illumination and supplies the auxiliary defense still needed for CW blinding."}],"review_version":1}