{"id":"7aef87d4-1c43-47a5-83b6-fbfbae803cd0","arxiv_id":"2506.18684","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"Pulse correlations of arbitrary order in QKD can be upper bounded by an exponential decay derived from the step response of a linear time-invariant model, fitted to measurements of the modulation pulses.","lead":"This paper models pulse correlations in QKD transmitters as the response of a linear filter, and derives exponential upper bounds on their strength at any separation. The authors fit the filter to measured waveforms and use it to bound long-range correlations, a step needed for QKD security proofs with unbounded memory effects.","discovery_kind":"first_principles","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The exponential bound is fitted to one sequence, not validated as a true upper bound; if A or b underestimate the real tail, the arbitrary-order security claim fails.","rationale":"The reader's conditional verdict is appropriate. The mathematical derivation in Appendix D is internally consistent: given an LTI system with an exponential step-response error bound, Eqs. (14) and (15) follow, and the paper correctly connects them to the security analysis of [23]. The load-bearing weakness is the empirical validation of that premise. The fit to a single waveform does not demonstrate that the fitted A and b upper-bound the true step response for all inputs; the large gap between the model's predicted best-case ϵ_total and the directly measured value shows that the model leaves real imperfections unexplained. That gap does not by itself refute the method, because measured short-range correlations can include state-preparation flaws and noise that are not SCD correlations, and the paper explicitly distinguishes these. However, it does mean the claim 'upper bounds for arbitrary order from the step response' is conditional on a validation that the paper does not provide. The proposed test, comparing the predicted bound against all measured sequence pairs and against a direct step-response measurement, would settle whether the bound is actually conservative. If the bound holds for all measured pairs and for the direct step response, the central claim stands; if not, the method needs a certified bound with uncertainty margins before it can support QKD security. No code or raw data are shipped, which further limits independent verification. I therefore keep the reader's CONDITIONAL verdict unchanged.","tokens_in":24333,"tokens_out":12695,"duration_ms":127982,"concrete_test":"Apply the fitted filter to all 243 five-pulse sequences, not just the sequence used for the fit, and for each l = 1,...,4 and each t0 in the alignment interval compare the measured phase difference |φ_j|tilde_j - φ_j|j| against the bound A e^{-b t0}(1 + e^{-bT})e^{-bT(l-1)} from Eq. (D9). If any measured difference exceeds the bound, Eqs. (14)–(15) are not valid upper bounds for this device. In addition, acquire a direct step-response trace (a long run of one setting followed by a step to each other setting), fit A and b to that true step response, and repeat the check, including different step amplitudes to test linearity.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim requires Eq. (13), |g(t)| ≤ A e^{-bt}, to hold as a genuine upper bound on the step-response error of the real transmitter, not merely for the fitted three-pole filter on one measured waveform. The paper's own Section IV states that the method 'relies on the assumption' of an LTI system and that nonlinearities, if present, are 'still dominated by its linear behavior'; this is an assumption, not a demonstrated property. The experimental support is a single least-squares fit of V_AWG(t) in Fig. 7(a) to one five-pulse sequence, with Table I reporting A = 1.60 and b = 318.7 Mrad/s and no uncertainty or residual analysis. Because Eqs. (14)–(15) and hence l_e in Eq. (11) scale directly with A and with e^{-bT(l-1)}, any underestimation of A or b, or any unmodeled nonlinearity producing a slower tail, invalidates the claimed exponential bound for all l. This is not merely a formal gap: the model's best-case predicted ϵ_total is about 3.8e-10, while the directly measured ϵ_total is about 1.9e-3, so the fitted filter demonstrably does not capture all real imperfections. A security proof needs an upper bound, not a best fit, and the presented data do not establish that this bound is conservative.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper introduces an LTI low-pass model for setting-choice-dependent (SCD) pulse correlations in QKD transmitters. It shows that if the step-response error satisfies |g(t)| ≤ A e^{-bt} (Eq. 13), then phase and intensity correlation strengths at any order l obey the exponential bounds (14) and (15), with parameters given in Eqs. (16)-(17). These bounds are of the form required by the security framework of Pereira et al. [23], allowing an effective maximum correlation length l_e (Eq. 11) to be computed. The authors measure short-range correlations up to fourth order for a 50-MHz intensity modulator driven by a 150-MHz AWG, fit a three-pole transfer function to one measured sequence (Fig. 7 and Table I), and use the fitted parameters to estimate l_e and to simulate secret-key rates for unbounded correlations (Fig. 9).","tokens_in":24553,"tokens_out":10948,"duration_ms":103973,"significance":"Conditional on Eq. (13), the paper provides a clean and useful analytical result: arbitrary-order correlation strengths can be bounded from a single step-response measurement, and the exponential decay rate is expressed through physically meaningful parameters. The derivation in Appendix D is internally consistent, and the bridge to the security analysis of [23] is clearly made. The experimental demonstration, including the characterization of all 243 five-pulse sequences and the distinction between correlations and state-preparation flaws, is valuable and clearly presented. However, the current experimental evidence does not certify that Eq. (13) is a true upper bound for the real device, and the intensity bounds are derived under a Dirac-delta pulse approximation that is not fully reconciled with the finite-width pulses used in the experiment. The significance of the paper would be substantially strengthened by a demonstration that the fitted parameters are conservative, e.g., via direct step-response measurement, uncertainty bounds, or validation on multiple sequences.","major_comments":[{"comment":"The central assumption that |g(t)| ≤ A e^{-bt} is a genuine upper bound for the real transmitter is not experimentally established. The parameters A=1.60 and b=318.7 Mrad/s come from a least-squares fit of a three-pole transfer function to a single five-pulse sequence (Fig. 7 and Table I); no uncertainty, residual analysis, or validation on independent sequences is provided. Because Eqs. (14)-(15) and the resulting l_e (Eq. 11) scale directly with A and e^{-bT(l-1)}, any underestimation of A or b, or any unmodeled nonlinearity, invalidates the claimed exponential bound for all l. The statement that nonlinearities are \"still dominated by its linear behavior\" is an assumption without supporting evidence. Please provide a certified upper bound on the true step response (via direct measurement, conservative fitting, or worst-case analysis) and validate it on multiple sequences.","section":"Section IV.B and Eq. (13)"},{"comment":"The intensity-correlation bound (15) is derived using the Dirac-delta pulse approximation leading to Eq. (D13). The experimental intensity characterization, however, uses Gaussian pulses of FWHM 1 ns (Eq. 9) integrated over Δt = 2 FWHM (Eq. 8). The paper does not show that Eq. (15) remains a valid upper bound for finite-width pulses, nor does it provide a finite-pulse correction. Since the experimental parameters, including the chosen t0 values, are defined for the finite-pulse case, this gap directly affects the applicability of the intensity-correlation results. Please provide a derivation for finite pulse shapes or demonstrate that the delta approximation is conservative for the measured pulse parameters.","section":"Section IV.A and Appendix D, Eq. (15)"},{"comment":"The model's best-case prediction ϵ_total = 3.83e-10 is orders of magnitude below the directly measured value 1.94e-3. The authors attribute this difference to SPFs and noise, but they do not provide a quantitative comparison of the model's predicted ϵ_l with the measured correlation strengths (Fig. 3 vs Fig. 8), nor do they demonstrate that the exponential bound (14) envelopes the measured short-range values. As written, the security claim rests on the unverified assumption that the model captures all SCD correlations. Please add a direct comparison of model predictions and experimental ϵ_l for l=1,...,4 and discuss explicitly whether the fitted bound is conservative with respect to those measured values.","section":"Section V, Fig. 9"}],"minor_comments":[{"comment":"The word \"dtermine\" should be \"determine\".","section":"Section IV.B"},{"comment":"The notation ϵϕ_l(t0) is used both for the actual measured correlation strength and for the upper bound (e.g., Eq. (14)); consider using a distinct symbol such as ϵ̄ϕ_l(t0) for the bound to avoid confusion.","section":"Section IV.A"},{"comment":"Report uncertainties for the fitted parameters A and b and propagate them to Cϕ and Cµ; the current values are given without error bars.","section":"Section IV.B and Table I"},{"comment":"The yellow lines in Fig. 9 assume ideal BB84 states with zero SPFs, but this is only stated in Appendix B; the main text should say so explicitly for clarity.","section":"Section V"},{"comment":"Clarify that the bounds plotted in Fig. 7 are computed from the fitted transfer function, not directly from the measured waveform; a data-derived envelope would provide stronger evidence for Eq. (13).","section":"Appendix E, Eq. (E9)"},{"comment":"It should be stated whether the measured V_AWG(t) includes the oscilloscope's 4-GHz bandwidth response, which could affect the fitted filter parameters.","section":"Section III, experimental setup"}],"recommendation":"major_revision","confidential_remarks":"The paper addresses an important practical problem and the analytical framework is elegant. The main concern is whether the experimental validation certifies the central bound |g(t)| ≤ A e^{-bt} as a conservative upper bound for the real system. I would encourage the editors to seek a revision that either directly measures the step response or provides a conservative fitting procedure with validation on multiple sequences, and that reconciles the intensity bound with the finite-width pulse profile used in the experiment."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Two things to know. The paper's core move is genuinely new and useful. If the transmitter's memory acts as an LTI low-pass system whose step-response error obeys |g(t)| ≤ A e^{-bt}, the correlation strengths in the Pereira–Curty unbounded-correlations framework are exponentially bounded, with decay rates C = 2bT for phase correlations and C = bT for intensity correlations. The derivation in Appendix D is clean: linearity gives the phase difference, the triangle inequality gives the bound, and the fidelity steps are standard. This replaces an impractical characterization task — enumerating exponentially many long pulse trains — with a step-response measurement, which is exactly the experimental input that the [23] security proof was missing. The demonstration that the decay is set by bandwidth-to-repetition-rate ratio is a nice, confirmable intuition. I think this part holds up.\n\nThe soft spot is the experimental certification of the bound, and it is the load-bearing one. A and b come from a least-squares fit to one five-pulse sequence, with no uncertainty quantification and no demonstration that the fitted envelope is conservative across runs. The paper states plainly that LTI is an assumption and that any nonlinearities are assumed dominated by linear behavior; stating an assumption is not the same as testing it. For a security claim you need an upper bound on the real step-response error, not a best fit. The numbers make the gap visible: the model's best-case predicted total correlation is around 1e-10 while the directly measured value is around 1e-3 for the same quantity. The SPF-vs-correlation distinction explains part of that, and the paper argues it well, but it also implies the fitted filter does not capture all setting-dependent imperfection in the real device. The specific epsilon_1 and l_e values should not yet be used as security-grade bounds.\n\nThe short-range characterization (all 243 five-pulse sequences) and the distinction between correlations and state preparation flaws are solid and worth keeping. No code or raw data shipped — minor, but it would help reproducibility.\n\nWho this is for: anyone working on implementation security of high-speed QKD, and the groups doing source-side security proofs. The math is sound and the method is practical; the validation gap is real but fixable. I would send it to peer review and ask for a certified step-response bound — direct measurement, several trials, a conservative envelope with margin — before the numbers are used in a security argument.","headline":"Clean LTI-step-response derivation of exponential pulse-correlation bounds, with a real gap between the fitted model and a certified security bound — worth serious review.","tokens_in":25188,"tokens_out":6680,"would_cite":true,"duration_ms":66616,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A step-response measurement bounds all QKD pulse correlations.","keywords":["quantum key distribution","pulse correlations","patterning effect","linear time-invariant model","step response","unbounded correlations","decoy-state protocol","BB84"],"falsifier":"Generate long random setting sequences and directly measure, for many large separations $l$, how much flipping the $(N-l)$-th setting changes the phase or intensity of pulse $N$; if any measured strength exceeds the corresponding exponential bound from Eq. (14) or Eq. (15), the model is falsified. A cheaper check is to record the actual step response over many time constants and test whether $|g(t)|\\le A e^{-bt}$ holds everywhere, since the fitted envelope in the paper is only compared with one five-pulse sequence.","tokens_in":24088,"feed_emoji":"🔐","tokens_out":10099,"duration_ms":86716,"temperature":0.7,"pith_summary":"This paper addresses a gap in quantum key distribution: memory effects in modulators make emitted pulse states depend on settings chosen many rounds earlier, and no existing method could characterize those correlations beyond a few orders. The authors propose modeling the bandwidth-limited devices in the transmitter as a single linear time-invariant low-pass system, so that the entire correlation structure follows from the system's step response. Under the assumption that the step-response error is bounded by a single exponential, they derive closed-form exponential upper bounds on the correlation strength of every order, for both phase and intensity encoding. This supplies the experimentally missing parameters needed by existing security proofs that handle unbounded correlations, converting an apparently impossible characterization problem into one waveform measurement.","feed_headline":"A step-response measurement bounds all QKD pulse correlations","feed_subtitle":"A linear low-pass model converts one measured waveform into exponential bounds on arbitrary-order memory leakage in QKD.","key_machinery":"The load-bearing object is the step-response error function $g(t)$, defined by writing the LTI system's step response as $\\vartheta(t)=G_0[1+g(t)]\\theta(t)$. For a low-pass system, $g(t)$ is a sum of damped oscillations, and the key technical step is replacing it by the global exponential envelope $|g(t)|\\le A e^{-bt}$. Because the output is a superposition of shifted step responses, the phase difference between two $N$-pulse sequences that differ only in round $N-l$ collapses to $\\Delta_{N-l}[g(t_0+lT)-g(t_0+(l-1)T)]$, which the envelope bounds term by term; the fidelity bounds for qubit phases and Poissonian intensity distributions then convert that into the exponential correlation bounds. This machinery is what reduces an exponential-in-$l$ characterization problem to two fitted parameters, $A$ and $b$.","core_discovery":"The central claim is that for a transmitter whose memory is captured by an LTI low-pass system with step-response error satisfying $|g(t)| \\le A e^{-bt}$, the setting-choice-dependent pulse correlations are bounded by $\\epsilon_l^\\phi(t_0) = \\frac{1}{4} A^2 \\Delta_{\\max}^2 e^{-2bt_0}(1+e^{-bT})^2 e^{-2bT(l-1)}$ for phase encoding and $\\epsilon_l^\\mu(t_0) = \\frac{\\mu_0}{2} A \\Delta_{\\max} e^{-bt_0}(1+e^{-bT}) e^{-bT(l-1)}$ for intensity encoding. These are exactly the exponential form $\\epsilon_l \\le \\epsilon_1 e^{-C(l-1)}$ that the unbounded-correlation security analysis of [23] requires, with $C^\\phi=2bT$ and $C^\\mu=bT$. Therefore a single step-response measurement---or, as done experimentally, the same data already acquired for short-range characterization---determines the effective maximum correlation length $l_e$, and existing finite-length proofs can be applied as if correlations beyond $l_e$ were zero, paying only a small security-parameter increase. The paper validates the model by fitting one measured five-pulse sequence from a 50 MHz transmitter and using the fitted filter to estimate $l_e^\\phi=6$ and $l_e^\\mu=11$ for $N=10^{12}$ emitted signals.","pith_inferences":["A natural testable prediction of the model is parameter transferability: the same fitted filter should predict correlations at other repetition rates, since $T$ enters the exponents explicitly, so re-running the characterization at 25 MHz and 100 MHz would check the model directly.","If finite-key security proofs for intensity correlations become available, the same $A$ and $b$ parameters would immediately yield $l_e^\\mu$ and unlock finite-key decoy-state rates under unbounded intensity correlations; the paper stops short of this because current intensity-correlation proofs are asymptotic.","One could use the exponential envelope as a design tool before building a link: a single step-response measurement of candidate modulators would predict whether a chosen repetition rate is safely below the memory-dominated regime, guiding the bandwidth-versus-rate trade-off.","The same LTI-envelope reasoning should transfer to other encoding degrees of freedom, such as polarization modulation through a birefringent phase modulator, because the underlying phase modulation is still a linear response to the applied field."],"forward_implications":["The characterization burden for arbitrary-order pulse correlations drops from generating and processing exponentially many setting sequences to measuring one step response and fitting two parameters.","For the experimental 50 MHz transmitter with $N=10^{12}$, the effective correlation length is $l_e^\\phi=6$ for phase correlations and $l_e^\\mu=11$ for intensity correlations, so existing security proofs for finite $l_c$ apply with those values and a small security-parameter penalty.","The correlation decay rate is set by the ratio of system bandwidth to repetition rate: $C^\\phi=2bT$ and $C^\\mu=bT$, so correlations grow when the protocol is run faster relative to the device bandwidth.","Secret-key-rate simulations for BB84 with unbounded phase correlations show that using the LTI-model bounds, rather than raw experimental short-range strengths, preserves higher rates because state-preparation flaws are not counted as correlations."],"supporting_citations":[{"why":"Supplies the security analysis for unbounded pulse correlations: the exponential-decay condition of Eq. (10) and the effective maximum correlation length formula of Eq. (11) that the paper's bounds plug into.","marker":"[23]"},{"why":"Provides the finite-size security proof for imperfect sources used in the secret-key-rate simulations, along with the definitions of the qubit and correlation epsilon parameters.","marker":"[19]"},{"why":"Establishes the earlier security framework for QKD with correlated sources that motivates quantifying correlation strength by fidelity lower bounds.","marker":"[18]"},{"why":"First experimental report of intensity correlations in QKD and an efficient countermeasure, defining the side-channel this paper characterizes.","marker":"[12]"},{"why":"Measured intensity correlations up to sixth order and showed higher-order correlations can exceed nearest-neighbor ones, motivating the need for arbitrary-order bounds.","marker":"[24]"},{"why":"Reported nearest-neighbor bit, basis and intensity correlations in a fast polarization-based QKD system; the paper adopts its operating parameters such as a signal mean photon number of 0.3.","marker":"[9]"},{"why":"Provides the security analysis for QKD with intensity correlations that the paper's intensity-correlation bounds are meant to feed.","marker":"[16]"},{"why":"Extends decoy-state security to correlated intensity fluctuations, another target application of the bounded intensity correlations.","marker":"[17]"}],"fun_headline_variants":["Step-response test caps QKD memory leakage","One waveform bounds all QKD pulse correlations","Bounding unbounded QKD correlations with a step response","Step response tames arbitrary-order QKD leakage","A single measurement bounds QKD pulse memory"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole chain depends on the transmitter's memory being representable by a single linear low-pass system whose step-response error stays inside one exponential envelope $|g(t)|\\le A e^{-bt}$ for all times; if the real device has nonlinear behavior that is not dominated by this linear response, or if the fitted $A$ and $b$ underestimate the true tail of $g(t)$, the exponential bounds on correlations are not guaranteed.","fun_headline_variants_meta":{"raw":{"variants":["Step-response test caps QKD memory leakage","One waveform bounds all QKD pulse correlations","Bounding unbounded QKD correlations with a step response","Step response tames arbitrary-order QKD leakage","A single measurement bounds QKD pulse memory"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000232,"raw_usage":{"total_tokens":1517,"prompt_tokens":1000,"completion_tokens":517,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":616,"completion_tokens_details":{"reasoning_tokens":447}},"tokens_in":616,"tokens_out":517,"duration_ms":5197,"temperature":1.0,"reasoning_tokens":447,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T18:45:13.227165+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Generate long random setting sequences and directly measure, for many large separations $l$, how much flipping the $(N-l)$-th setting changes the phase or intensity of pulse $N$; if any measured strength exceeds the corresponding exponential bound from Eq. (14) or Eq. (15), the model is falsified. A cheaper check is to record the actual step response over many time constants and test whether $|g(t)|\\le A e^{-bt}$ holds everywhere, since the fitted envelope in the paper is only compared with one five-pulse sequence.","supporting_citations":[{"cited_title":"Kang, F.-Y","cited_arxiv_id":null,"evidence_quote":"Provides the finite-size security proof for imperfect sources used in the secret-key-rate simulations, along with the definitions of the qubit and correlation epsilon parameters."},{"cited_title":"Gottesman, H.-K","cited_arxiv_id":null,"evidence_quote":"First experimental report of intensity correlations in QKD and an efficient countermeasure, defining the side-channel this paper characterizes."},{"cited_title":"Gr¨ unenfelder, A","cited_arxiv_id":null,"evidence_quote":"Provides the security analysis for QKD with intensity correlations that the paper's intensity-correlation bounds are meant to feed."},{"cited_title":"Yoshino, M","cited_arxiv_id":null,"evidence_quote":"Extends decoy-state security to correlated intensity fluctuations, another target application of the bounded intensity correlations."}],"review_version":2}