{"id":"23023c47-3877-43ff-98b8-adb4357a93a1","arxiv_id":"2506.05627","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"A single homodyne detection system extracts uniform, Gaussian, and raw Rayleigh random numbers from the same vacuum noise measurements, with secure rates of 42.66 and 14.01 Gbps for the first two.","lead":"A quantum random number generator built from vacuum noise can produce uniform, Gaussian, or Rayleigh distributed random numbers on demand at over 40 Gbps after extraction. This is a step toward making quantum randomness practical for different applications with one hardware box.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Shot-noise-limited operation is not certified: a linear variance-vs-LO-power fit (R=0.99) also holds for technical noise, so the min-entropy values and all secure rates rest on an unverified calibration.","rationale":"I focused on the shot-noise-limited assumption rather than the Gaussian-extractor proof gap because it is load-bearing for all outputs, including the 42.66 Gbps uniform rate that is otherwise the strongest part of the paper. The reader's weakest assumption is correct; I agree with it. The linear variance fit in Fig. 3a is necessary but not sufficient: LO-intensity noise and imperfect common-mode rejection are also linear in LO power. Without a calibrated shot-noise reference, the PSD and Hmin numbers cannot be audited. This concern is more consequential than the separate, self-admitted issues in Sec. V.B (the Gaussian extractor 'lacks theoretical proof of randomness preservation') and Sec. V.C (no Rayleigh extractor; raw Rayleigh bits fail the Chi-squared test, as stated in the abstract: 'only denoised Rayleigh raw bits are generated'). Those issues are real and justify keeping the verdict at CONDITIONAL, but they are localized to two output modes and the paper already flags them. The concrete test I propose is a single calibration experiment that would settle the foundational assumption. Since this is the same weakest assumption identified by the reader, the verdict should remain unchanged at CONDITIONAL.","tokens_in":9926,"tokens_out":11215,"duration_ms":115833,"concrete_test":"At the operating point (4.13 mW/diode), record the homodyne output PSD with LO on and with LO blocked over 0-1.6 GHz, and compute the theoretical shot-noise PSD from the DC photocurrent (2e I_LO R^2). If the on-state PSD exceeds the shot-noise floor by more than the excess-noise tolerance assumed in the Hmin calculation, or if the LO-blocked floor is within a few percent of the on-state PSD at any frequency used, the shot-noise-limited assumption fails. Also repeat the variance-versus-power scan and check that the fitted slope matches the calibrated shot-noise slope within a few percent. If the corrected Hmin lowers the secure rates below 42.66 Gbps or 14.01 Gbps, the central claim fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central security claim assumes both homodyne detectors are shot-noise-limited at the 4.13 mW/diode operating point, so the measured variance is dominated by vacuum noise with all classical noise correctly characterized as side information. The only direct evidence is Fig. 3a, a linear fit of variance versus LO power with R=0.99. That is not sufficient certification: laser relative-intensity noise, imperfect common-mode rejection, and other LO-correlated technical noise also scale linearly with LO power, so a linear fit cannot distinguish shot noise from such noise. Fig. 3b shows the excess-noise PSDs of the two arms differ by more than 4 dBm at 1.6 GHz, and the text gives no quantitative shot-noise-to-excess-noise ratio at the operating point. The min-entropy values Hmin=0.70/0.71 and the resulting 42.66 Gbps uniform and 14.01 Gbps Gaussian rates are computed via the effective-iid model of [22], which is valid only if this shot-noise dominance holds. If a non-negligible fraction of the measured variance is uncharacterized classical noise, the leftover-hash bound is optimistic and all headline rates are overestimated. Vendor optimization and a statement that the two quantum noises are close below 1378 MHz do not replace a calibration against a known shot-noise reference.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports a dual-quadrature homodyne vacuum-noise QRNG that generates uniform, Gaussian, and Rayleigh distributed random numbers on demand from the same hardware. It claims a secure uniform bit rate of 42.66 Gbps using a Toeplitz extractor, a Gaussian bit rate of 14.01 Gbps using a modified Wallace method, and raw Rayleigh bits after denoising. The min-entropy estimation follows Gehring et al. and Bruynsteen et al., and the experimental verification relies on variance-vs-LO-power linearity and PSD measurements.","tokens_in":10185,"tokens_out":6282,"duration_ms":55473,"significance":"If fully substantiated, the dual-quadrature approach is a useful step toward multi-distribution QRNGs, and the 42 Gbps uniform rate is competitive with state-of-the-art. However, the security claims for the Gaussian stream are explicitly unproven, the Rayleigh output is not extracted randomness, and the shot-noise certification is not sufficient to support the claimed min-entropy values. The paper also omits key parameters of the entropy calculation, making the rates not independently verifiable.","major_comments":[{"comment":"The linear dependence of the measured variance on LO power (R=0.99) is not sufficient to certify shot-noise-limited operation, because LO-correlated technical noise (e.g., relative intensity noise and imperfect common-mode rejection) also scales linearly with LO power. The authors should provide a quantitative shot-noise-to-excess-noise ratio at the 4.13 mW operating point, for example by comparing the measured PSD to the calculated shot-noise level from the photocurrent, or by an independent calibration measurement. Without this, the min-entropy values Hmin=0.70/0.71 and the resulting rates are not supported.","section":"Section III, Fig. 3a"},{"comment":"The min-entropy derivation is not reproducible because the paper does not report sigma_M^2, sigma_Q,c^2, the effective photon number n, the ADC parameters R and N, or the nonlinearity term DNL_max that enter Eqs. (2)-(4). It also does not state the security parameter epsilon used in Eq. (1) or explain how the block sizes in the Toeplitz extractor (1536 input bits to 1024 output bits) relate to the claimed 2 GHz effective sampling rate and the 42.66 Gbps secure rate. Please provide the full set of measured parameters and a sample calculation, or include a supplementary document.","section":"Section IV and V.A"},{"comment":"The Gaussian extractor is explicitly stated to 'lack theoretical proof of randomness preservation' and to be 'not entirely reliable' and 'may introduce subtle correlations.' Therefore the abstract's claim of 'over 14 Gbps secure bit rate for Gaussian random number' is not supported. Please rephrase to 'statistically Gaussian' or provide a security proof for the modified Wallace method; otherwise remove 'secure' from the abstract.","section":"Section V.B and Abstract"},{"comment":"The Rayleigh output consists of raw bits that, after applying a Savitzky-Golay filter, still fail the chi-squared goodness-of-fit test (p=0). Since no randomness extraction is performed for the Rayleigh distribution, the paper does not actually demonstrate a third secure random number type. The title '40Gbps Tri-type' and the abstract's characterization of generating 'three distribution types of random numbers at over 60 Gbits/s raw bits' should be qualified to clarify that only uniform and (statistically) Gaussian outputs are extracted, while Rayleigh is a raw-data-only demonstration.","section":"Section V.C, Title, and Abstract"}],"minor_comments":[{"comment":"The term 'Raleigh' is a misspelling of 'Rayleigh' throughout this section.","section":"Section V.C"},{"comment":"The symbol K is introduced as the group size in the Wallace method but later k is used; please use consistent notation.","section":"Section V.B"},{"comment":"The sentence 'To generate the n−m+ 1-bit seed required' appears to be a typo; the Toeplitz seed length is n+m−1.","section":"Section V.A"},{"comment":"Eqs. (2) and (4) use 'erf' while the subsequent definition uses 'erfc'; please check the consistency of the expressions and clarify the relationship.","section":"Section IV"},{"comment":"The caption says 'quantum vacuum noise of both quadratures' but the text refers to 'conditional quantum variance sigma_Q^2'; please label the plotted quantity explicitly on the axis and define it precisely in the caption.","section":"Fig. 3c"},{"comment":"The paper would benefit from a table listing all parameters used in the entropy calculation, including the ADC range, resolution, DNL_max, sigma_M^2, sigma_Q,c^2, and the resulting effective n for each channel.","section":"General"}],"recommendation":"major_revision","confidential_remarks":"The manuscript's own text admits that the Gaussian extractor lacks a security proof and that the Rayleigh output fails statistical testing; these admissions are accurately reflected in my major comments. The editor may wish to consider whether the title and abstract need to be revised to match the demonstrated capabilities before acceptance."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Honestly, the paper is a capable engineering demo. The real contribution is the single integrated dual-quadrature homodyne system that can switch among uniform, Gaussian, and Rayleigh outputs on demand in postprocessing, at rates that are competitive with current vacuum-noise QRNGs. The uniform output at 42.66 Gbps secure is a solid number, and the 14.01 Gbps Gaussian output is useful even if the extractor is not proven secure. The authors are honest about the Gaussian extractor's lack of a security proof and the absence of a Rayleigh extractor, which is more than many papers in this area do.\n\nThe soft spots are in the security claims. The shot-noise-limited regime is asserted but not convincingly certified. A linear variance-versus-LO-power fit (R=0.99) is exactly what you'd get for laser RIN or other LO-correlated technical noise, so it doesn't discriminate. The excess noise PSDs show a >4 dBm difference between the two detectors at 1.6 GHz, and the text never gives the shot-noise-to-excess-noise ratio at the operating point. The min-entropy values (Hmin=0.70/0.71) and the resulting secure rates rest on the model from Bruynsteen et al., which assumes the excess noise is actually quantum side information. Without a quantitative shot-noise calibration against a known reference, the rates could be optimistic. This is the main thing a referee should push on.\n\nThe other issue is that the abstract and conclusion call the Gaussian rate 'secure', while the text says the modified Wallace method lacks a proof of randomness preservation and is not suitable for cryptographic contexts. That's a direct contradiction, and it needs to be fixed. Similarly, the 'tri-type' label is generous when only uniform is fully secure; Rayleigh is raw bits only.\n\nMinor: no code or data for the analysis, and the entropy calculation details (sigma_M, sigma_Q, ADC model) are thin.\n\nFor a reader: this is for applied QRNG people who care about multi-distribution generation and FPGA postprocessing. It deserves a serious referee, but the referee should require the shot-noise calibration and the toned-down claims. If those are addressed, it's a worthwhile paper. I'd accept it conditional on revision.","headline":"A capable dual-quadrature QRNG with on-demand output types, but the secure-rate claims outrun the shot-noise calibration and the Gaussian extractor's proof status.","tokens_in":1,"tokens_out":3991,"would_cite":true,"duration_ms":77581,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A single optical detector can output uniform, Gaussian, and Rayleigh quantum random numbers on demand at secure rates above 40 Gbps.","keywords":["quantum random number generation","homodyne detection","quantum vacuum noise","dual-quadrature measurement","Gaussian distribution","Rayleigh distribution","min-entropy","FPGA randomness extraction"],"falsifier":"Record the homodyne voltage variance while sweeping local-oscillator power in fine steps near 4.13 mW per diode; if the variance-versus-power curve shows curvature or an intercept comparable to the shot-noise slope, or if a classical monitor of laser intensity and phase can predict post-extraction bits at a rate above the claimed min-entropy bound, the shot-noise-limited security assumption is refuted.","tokens_in":9715,"feed_emoji":"🎲","tokens_out":8353,"duration_ms":81090,"temperature":0.7,"pith_summary":"The paper claims one hardware setup can serve as a multi-format quantum random number generator: by measuring both quadratures of the quantum vacuum field with homodyne detection, it produces Gaussian samples from each quadrature and derives uniform and Rayleigh samples from the polar coordinates of the same measurements. This matters because different applications want different distributions, and existing solutions either need multiple machines or convert one distribution into another at a large cost in secure bits. The demonstrated device extracts over 42 Gbps of secure uniform bits and over 14 Gbps of secure Gaussian bits, with switching between distributions done in FPGA electronics at no throughput cost. Rayleigh bits are generated as denoised raw samples only, because no secure Rayleigh extractor exists yet. If the security bound holds, a single compact unit could replace several single-purpose quantum random number generators and supply random numbers on demand through a network service.","feed_headline":"One detector yields three random distributions at 40+ Gbps","feed_subtitle":"Vacuum-noise measurement plus FPGA switching gives >42 Gbps secure uniform and >14 Gbps Gaussian bits.","key_machinery":"The carrier of the argument is dual-quadrature homodyne detection of the vacuum field: a balanced receiver measures one quadrature I while a second receiver measures the conjugate quadrature Q with a $\\pi/2$ phase-shifted local oscillator, and the two Gaussian-distributed voltages constitute the raw entropy. The distribution switch is the polar-coordinate identity $\\theta = \\arctan(Q/I)$, $r = \\sqrt{I^2+Q^2}$: $\\theta$ is uniform and $r$ is Rayleigh whenever I and Q are independent Gaussians. Security is carried by a min-entropy bound against quantum side information computed from the measured signal variance and the conditional quantum variance, together with Toeplitz hashing for uniform extraction and a recursive sum-of-squares-preserving transform for Gaussian extraction. The same electronics therefore select among three output types without any optical reconfiguration.","core_discovery":"Starting from the vacuum state, the two conjugate quadratures I and Q measured by balanced homodyne detection are independent Gaussian random variables. The same pair of measurements, converted to polar form, yields a phase angle $\\theta = \\arctan(Q/I)$ that is uniformly distributed and a radius $r = \\sqrt{I^2+Q^2}$ that is Rayleigh distributed, all from the same optical setup. The authors build a 1550 nm dual-quadrature homodyne system with two 1.6 GHz detectors, sample at 2 GHz, and postprocess on an FPGA: Toeplitz hashing extracts uniform bits at 42.66 Gbps total with a quantum-side-information min-entropy bound; a modified recursive matrix method extracts Gaussian bits at 14.01 Gbps; and Savitzky-Golay-filtered radial samples approximate Rayleigh statistics but do not yet pass goodness-of-fit tests after extraction. The central claim is that distribution type becomes a software choice, not a hardware property, and that this choice costs nothing in generation rate.","pith_inferences":["Because every homodyne setup that already records both I and Q obtains $\\theta$ and $r$ for free, the tri-type result transfers to any dual-quadrature QRNG design; the only missing ingredient for Rayleigh output is a conditional min-entropy bound for the radial distribution.","If a Rayleigh extractor is developed, the same device could potentially add a third secure stream on top of the I and Q channels, so total secure throughput might exceed the reported 42.66 Gbps rather than merely swapping distributions.","The FPGA switching architecture suggests a multiplexed network service where different clients receive different distributions simultaneously, which the paper's cloud deployment hints at but does not characterize.","A natural test of the 'switching costs nothing' claim is to benchmark bit rate and statistical-test results under rapid alternating distribution requests; the paper demonstrates the mechanism but does not report a switching-stress test."],"forward_implications":["A service can offer uniform, Gaussian, and Rayleigh random numbers from one continuously running device, so the user's choice of distribution no longer requires provisioning separate quantum hardware.","Switching distribution type in FPGA logic means throughput stays at the full detector-limited rate even when the requested distribution changes between requests.","The uniform output at 42.66 Gbps secure and Gaussian output at 14.01 Gbps secure are high enough for real-time cryptographic key generation and Monte Carlo simulation workloads.","Replacing the anti-aliasing filter with a high-speed low-noise version is projected to raise the uniform rate to about 68 Gbps and the Gaussian rate to about 22 Gbps on the same hardware.","A rigorous Rayleigh extractor remains the missing piece; until it exists, Rayleigh output is statistical raw material rather than a secure random stream."],"supporting_citations":[{"why":"Supplies the min-entropy bound against quantum side information that justifies the uniform secure rate.","marker":"[21]"},{"why":"Provides the effective iid model and conditional-variance method used to handle finite detector bandwidth, and the 100 Gbps integrated QRNG benchmark this work extends.","marker":"[22]"},{"why":"Introduces the vacuum-shot-noise Gaussian QRNG and the modified recursive Gaussian extraction approach adopted here.","marker":"[20]"},{"why":"Establishes vacuum-state homodyne measurement as a source of true quantum randomness.","marker":"[16]"},{"why":"Shows heterodyne dual-quadrature detection of vacuum noise at 17 Gbps, the direct procedural predecessor for measuring both quadratures.","marker":"[17]"},{"why":"Demonstrates real-time vacuum-fluctuation QRNG with FPGA postprocessing, the architecture used for the present device.","marker":"[18]"},{"why":"Gives the entropy-evaluation and Toeplitz-extraction postprocessing framework for QRNG.","marker":"[39]"},{"why":"States the leftover hash lemma against quantum side information that fixes the extractable output length.","marker":"[37]"},{"why":"Original recursive method whose statistical limitations motivate the modified Gaussian extractor.","marker":"[43]"}],"fun_headline_variants":["Tri-type randomness from a single detector at 40+ Gbps","Software-selectable random distributions at 40+ Gbps","One detector, three distribution types, 40+ Gbps","Uniform, Gaussian, Rayleigh: all from one setup at 40+ Gbps","Software switch for random distribution at 40+ Gbps"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security bounds assume the two homodyne detectors are shot-noise-limited at 4.13 mW per diode, so the measured variance is dominated by quantum vacuum fluctuations rather than classical electronic or laser noise.","fun_headline_variants_meta":{"raw":{"variants":["Tri-type randomness from a single detector at 40+ Gbps","Software-selectable random distributions at 40+ Gbps","One detector, three distribution types, 40+ Gbps","Uniform, Gaussian, Rayleigh: all from one setup at 40+ Gbps","Software switch for random distribution at 40+ Gbps"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001457,"raw_usage":{"total_tokens":5866,"prompt_tokens":949,"completion_tokens":4917,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":565,"completion_tokens_details":{"reasoning_tokens":4828}},"tokens_in":565,"tokens_out":4917,"duration_ms":32045,"temperature":1.0,"reasoning_tokens":4828,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T10:11:53.421355+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Record the homodyne voltage variance while sweeping local-oscillator power in fine steps near 4.13 mW per diode; if the variance-versus-power curve shows curvature or an intercept comparable to the shot-noise slope, or if a classical monitor of laser intensity and phase can predict post-extraction bits at a rate above the claimed min-entropy bound, the shot-noise-limited security assumption is refuted.","supporting_citations":[{"cited_title":"Parallel and real-time post-processing for quantum random number generators","cited_arxiv_id":"2403.19479","evidence_quote":"Original recursive method whose statistical limitations motivate the modified Gaussian extractor."},{"cited_title":"Gehring, C","cited_arxiv_id":null,"evidence_quote":"Supplies the min-entropy bound against quantum side information that justifies the uniform secure rate."},{"cited_title":"In this section, we have described a method to lower bound the min-entropy","cited_arxiv_id":null,"evidence_quote":"Provides the effective iid model and conditional-variance method used to handle finite detector bandwidth, and the 100 Gbps integrated QRNG benchmark this work extends."},{"cited_title":"Huang, Z","cited_arxiv_id":null,"evidence_quote":"Introduces the vacuum-shot-noise Gaussian QRNG and the modified recursive Gaussian extraction approach adopted here."},{"cited_title":"Gabriel, C","cited_arxiv_id":null,"evidence_quote":"Establishes vacuum-state homodyne measurement as a source of true quantum randomness."},{"cited_title":"Avesani, D","cited_arxiv_id":null,"evidence_quote":"Shows heterodyne dual-quadrature detection of vacuum noise at 17 Gbps, the direct procedural predecessor for measuring both quadratures."},{"cited_title":"Zheng, Y","cited_arxiv_id":null,"evidence_quote":"Demonstrates real-time vacuum-fluctuation QRNG with FPGA postprocessing, the architecture used for the present device."},{"cited_title":"Dodis, A","cited_arxiv_id":null,"evidence_quote":"Gives the entropy-evaluation and Toeplitz-extraction postprocessing framework for QRNG."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"States the leftover hash lemma against quantum side information that fixes the extractable output length."}],"review_version":1}