{"id":"575d3f6e-9729-48d5-8015-a8c1b6352148","arxiv_id":"2507.09963","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":1,"one_line_summary":"A routed Bell test network gives a device-independent private quantum randomness beacon that certifies clients' randomness while moving the costly detector requirements to a shared server.","lead":"This paper proposes using a routed Bell test, where a server entangles photons with clients' devices via an optical switch, to generate randomness that is both device-independent and private. The intended value is a cheaper route to certified private random numbers, since only the server needs high-efficiency detectors and one server can serve many clients.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Eq. (3)'s min-tradeoff function omits the announced test register D_i, so Theorem 1's bound on H_min(C^n|D^n,E^n) does not follow; the >50% rate claim is unsupported until this is fixed.","rationale":"The reader's CONDITIONAL verdict is appropriate, but the most load-bearing part of the central claim is the entropy-estimation chain: if h* is overestimated, the >50% threshold may be wrong. The manuscript's Definition 2 and Theorem 1 have a mismatch over D_i: the virtual protocol announces D_i and thereby reduces conditional entropy, while the quoted GEAT theorem conditions on D^n; the min-tradeoff function must therefore lower-bound the D_i-conditional entropy, but the paper computes an unconditioned single-round entropy. This is an internal inconsistency rather than merely a missing numerical detail. The honest-but-curious server assumption flagged by the reader is a real limitation and is explicitly acknowledged, but it does not by itself make the protocol's mathematics wrong. The D_i issue, if it lands, does. I do not recommend REJECT because the authors may have intended the standard GEAT definition and simply omitted D_i in the write-up; the numerical analysis could still support the threshold after correction. Hence the verdict remains CONDITIONAL, with the condition made more specific: fix the min-tradeoff definition and provide corrected, normalized SDP numerics.","tokens_in":12228,"tokens_out":27294,"duration_ms":329427,"concrete_test":"Check Definition 2 against Corollary 4.6 of Ref. [29]: if the original min-tradeoff condition is f(q) ≤ H(C_i|D_i,E_i,\\tilde E_{i-1})_ν, recompute h* with D_i included for the ideal lossless SPDC model and compare the resulting rate per heralded event with Fig. 3. Also re-evaluate Eq. (9) with the X,Z distribution normalized to Z≠X; if either change moves the threshold by more than a few percent or makes the η=1 rate inconsistent with known CHSH-based bounds, the central quantitative claim is not established.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section V.B defines a min-tradeoff function in Definition 2 (Eq. 3) via f(q) ≤ H(C_i|E_i, \\tilde E_{i-1})_ν, but Theorem 1 (Eq. 5) concludes a bound on H_min(C^n|D^n,E^n). In the infrequent-sampling virtual protocol, D_i is the publicly announced test outcome and is a function of A_i,B_i,C_i,X_i,Y_i,Z_i,S_i in test rounds, so conditioning on D^n can only reduce the entropy. A function that lower-bounds only H(C_i|E_i,\\tilde E_{i-1}) is therefore not a valid min-tradeoff function for the stated theorem unless D_i is independent of C_i, which is not the case. The single-round analysis in Section V.C similarly computes Pg(C|...E) without D_i, so h* is potentially overestimated. A related normalization ambiguity appears in Eq. (9): the SDP objective is labelled Pg(C_i|Z_i≠X_i,S_i=1,A_iE) but uses unconditional probabilities Pr[X_i=x,Z_i=z|S_i=1]; if not normalized by Pr[Z_i≠X_i|S_i=1], Eq. (8) acquires an extra -log Pr[Z_i≠X_i] ≈ 0.5 bits, inflating the rate. Both issues bear directly on the claimed positive-rate threshold of η>50%.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper introduces DIPQRB, a protocol for generating private random numbers from untrusted devices using a routed Bell test between a server (Alice and Bob) and clients (Charlie). The server runs high-performance devices and routes one share of each entangled state to a client; the client measures and generats raw randomness. Security is analyzed via the generalised entropy accumulation theorem (GEAT) with testing, with single-round entropy bounds obtained from an NPA-hierarchy optimisation. The paper claims that in the semi-device-independent variant, the asymptotic randomness generation rate per heralded event is positive whenever the client detection efficiency exceeds 50%. It also discusses a fully device-independent mode and positions the scheme as a cost-effective randomness-as-a-service application.","tokens_in":12485,"tokens_out":22833,"duration_ms":266136,"significance":"If the security proof is correct, the proposal would be a genuinely useful application of routed Bell tests: it would relax the detector-efficiency requirements for device-independent randomness generation while giving the client privacy against the server, which existing DIQRNG implementations do not offer at low client cost. The paper uses established external tools (GEAT from Ref. [29], NPA hierarchy from Ref. [32]) and is transparent about the honest-but-curious-server assumption and the semi-device-independent fair-sampling assumption. The main value is the conceptual protocol and the claimed efficiency threshold; however, the proof as written has several load-bearing gaps that must be resolved before the central claim can be accepted.","major_comments":[{"comment":"The min-tradeoff function in Eq. (3) is defined via H(C_i|E_i, \\tilde E_{i-1}), but Theorem 1 in Eq. (5) bounds H^ε_min(C^n|D^n,E^n). In the infrequent-sampling virtual protocol, D_i is a function of C_i (among other registers) in test rounds, so conditioning on D^n can reduce the entropy; a simple counterexample with D_i=C_i and independent E_i would violate Eq. (5) if Eq. (3) were the only hypothesis. Either Definition 2 should condition on D_i, i.e. f(q) ≤ H(C_i|E_i,\\tilde E_{i-1},D_i)_ν, or Theorem 1 should not condition on D^n (and the reduction to the actual protocol must be restated). As written, the two statements are inconsistent, and the single-round analysis in Section V.C never accounts for D_i, so h* is potentially overestimated.","section":"Section V.B, Definition 2 (Eq. (3)) and Theorem 1 (Eq. (5))"},{"comment":"The left-hand side of Eq. (9) is written as the conditional guessing probability Pg(C_i|Z_i≠X_i,S_i=1,A_iE), but the right-hand side sums over all x,z with weights Pr[X_i=x,Z_i=z|S_i=1] without dividing by Pr[Z_i≠X_i|S_i=1]. Consequently the quantity computed is Pr[Z_i≠X_i|S_i=1] times the desired conditional guessing probability (assuming zero support on x=z in the relevant branch). Substituting this into Eq. (8) without normalization introduces an extra factor of about −log₂ Pr[Z_i≠X_i|S_i=1] ≈ 0.5 bits into the rate estimate, inflating the single-round entropy. Since the headline claim of a positive rate above η=50% depends on this rate, the normalization must be fixed and Fig. 3 recomputed.","section":"Section V.C, Eq. (9)"},{"comment":"The entropy chain as written is not a valid lower bound. The left side of Eq. (6) conditions on A_i,B_i,X_i,Y_i,S_i,E but not on Z_i, yet the right side introduces conditioning on Z_i≠X_i, so the first inequality cannot follow simply by discarding non-negative terms. If Z_i is inserted into the left side, then replacing H(C_i|A_i,B_i,X_i,Y_i,Z_i,S_i=1,E) by H(C_i|A_i,E,S_i=1,Z_i≠X_i) goes in the wrong direction: dropping conditioning on X_i (and Y_i,B_i) can only increase the entropy, so the inequality would need to be reversed or justified by an additional conditional-independence (non-signalling) argument. The SDP in Eq. (9) actually conditions on X_i and Z_i through the sum over x,z, so the correct object being bounded is closer to Pg(C_i|A_i,X_i,Z_i,S_i=1,Z_i≠X_i,E); the notation and the entropy chain must be corrected to match, and the rate must be re-derived from the corrected expression.","section":"Section V.C, Eqs. (6)–(8)"}],"minor_comments":[{"comment":"The abstract advertises generation from 'untrusted devices', but Assumption 3 requires the server to be honest-but-curious and to announce its inputs and outputs truthfully. This is a substantial trust assumption and should be stated prominently in the abstract and introduction.","section":"Abstract and Section V.A"},{"comment":"The optimisation problem does not explicitly state the normalisation condition on the adversary's POVM elements E_{c|axz} (e.g., ∑_c E_{c|axz} = I for each a,x,z), which is needed for the NPA hierarchy implementation.","section":"Section V.C, Eq. (9)"},{"comment":"The numerical claim behind Fig. 3 is not reproducible from the text: the paper does not report the optimised guessing probability value, the specific NPA level, or provide a verification script. Including these would materially strengthen the paper.","section":"Fig. 3 and Section III"},{"comment":"There is a grammatical error: 'it was recently showed it is possible' should be 'it was recently shown that it is possible'.","section":"Section I, paragraph 8"},{"comment":"Eq. (6) appears to omit Z_i from the conditioning set; the subsequent text discusses discarding terms with Z_i=X_i, so Z_i should be present in the displayed entropy expression.","section":"Eq. (6) and surrounding text"}],"recommendation":"major_revision","confidential_remarks":"The core idea is promising and the authors are transparent about their assumptions, but the proof has three connected technical gaps that directly affect the claimed >50% threshold. These are fixable in principle—correct the GEAT min-tradeoff definition, normalise the guessing-probability SDP, and repair the entropy-chain notation—but the numerical rate and Fig. 3 must be recomputed after the fixes. I recommend major revision rather than rejection, provided the authors supply the corrected derivation and reproducible numerical data."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: DIPQRB is a genuinely new combination — routed Bell tests used to give clients private, device-independent randomness on cheap hardware, with an honest-but-curious server. The security analysis uses a careful GEAT channel construction, and the SPDC simulation is a real step toward practical numbers. If the >50% client-efficiency threshold holds up, it would be the first protocol to hit all three properties at once. That's worth taking seriously.\n\nThe GEAT construction is the paper's strongest piece. They are explicit about the non-signalling conditions needed for the routed Bell test, and they acknowledge that the server must be honest in preparing the registers and announcing inputs/outputs. The virtual protocol with test rounds is standard, and the reduction to a single-round entropy bound is the right high-level approach.\n\nNow the soft spots. First, the quantitative claim is not reproducible from the manuscript. The SDP in Eq. (9) is not fully specified — no NPA level, no numerical results, no closed form for the min-tradeoff function. The figure with the 50% threshold is simply asserted. For a protocol paper that is supposed to convince you of a practical advantage, this is the key missing piece.\n\nSecond, there is a specific normalization concern in Eq. (9). It labels the objective as the guessing probability conditioned on Z_i≠X_i, but the sum uses unconditional input probabilities Pr[X_i=x, Z_i=z|S_i=1] and does not divide by Pr[Z_i≠X_i|S_i=1]. If the sum is over all x,z, this is not the conditional quantity. If the sum should be restricted to x≠z, the missing normalization factor shifts the entropy bound by about half a bit. Either way, the equation needs to be corrected and the numerics rechecked. This is fixable, but it is load-bearing for the threshold.\n\nOne concern from the stress-test that I don't think lands is the worry that the min-tradeoff function in Definition 2 omits D_i. That is standard EAT: the test register D_i is handled by the event and by the final conditioning on D^n in Theorem 1. No issue there.\n\nThe honest-but-curious server is a real assumption, and it means the 'device-independence' is one-sided. The client's device is untrusted, but the server must be honest in its announcements. The paper states this clearly, so it is not a hidden flaw, but it limits the 'untrusted devices' framing. For a commercial beacon service, that trust model is reasonable.\n\nBottom line: This is a promising proposal with a sound high-level architecture and an honest statement of assumptions. It deserves a serious referee. The referee should ask for the missing numerical details and a corrected Eq. (9). If those come out clean, the >50% threshold will be a solid result.","headline":"A genuinely new architecture for private device-independent randomness via routed Bell tests, but the headline >50% efficiency claim is not yet reproducible and Eq. (9) has a normalization issue that needs fixing.","tokens_in":13046,"tokens_out":11922,"would_cite":true,"duration_ms":124826,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Client detectors above 50% suffice for certified private randomness","keywords":["device-independent quantum random number generation","routed Bell test","private randomness","entropy accumulation","quantum networks","randomness beacon","Bell nonlocality","detection efficiency"],"falsifier":"Run the semi-device-independent protocol with the client's detection efficiency swept from below to above 50% and measure the certified randomness rate per heralded event; the paper predicts the rate drops to zero at the 50% threshold, so a positive rate below that efficiency would falsify the central quantitative claim.","tokens_in":11990,"feed_emoji":"🎲","tokens_out":12043,"duration_ms":128352,"temperature":0.7,"pith_summary":"Device-independent random number generation normally demands expensive, high-efficiency detectors on every user's side. The paper claims that a routed Bell test can shift almost all of that burden onto a central server while still certifying the client's output without trusting the internal workings of the client's device, and while keeping that output private from the server. In the protocol, the server holds an entangled-photon source and two high-performance measurement devices; an optical switch randomly sends the second photon either to the server's other device or to the client. The client's device only needs a much weaker long-range quantum correlation with the server, so it can tolerate significant loss; in the paper's binary-setting example the asymptotic randomness rate per heralded event is positive whenever the client's detection efficiency exceeds 50%. If this is right, private and device-independently certified randomness becomes practical as a network service, with most of the cost shared across many clients.","feed_headline":"Client detectors above 50% suffice for certified private randomness","feed_subtitle":"A routed Bell test lets servers carry the costly hardware while clients get private, certifiable random bits.","key_machinery":"The central object is the routed Bell test, a three-party configuration in which an optical switch randomly sends the second half of each entangled pair either to a second server-side device or to the client's device. Its role is to decouple the certification burden from the client: only the two server-side parties must violate a Bell inequality, while the client only needs a long-range quantum correlation that survives large loss. The security proof is carried by the generalised entropy accumulation theorem with testing, applied to GEAT channels (completely positive maps satisfying a non-signalling condition) that encode the protocol's structure, in particular that the quantum state prepared for the client is independent of the switch input, and that the server's and client's devices do not communicate. The single-round conditional entropy is then bounded from below by a min-tradeoff function, an affine lower bound on the entropy as a function of the observed test distribution, constructed by solving a semidefinite-programming hierarchy for the client's guessing probability given the server's public data.","core_discovery":"The paper introduces the Device-Independent Private Quantum Randomness Beacon (DIPQRB) and argues that it is the first protocol to combine three properties at once: device-independent certification, cost-effective client hardware, and privacy of the client's output against the server. Inside the server, Alice and Bob perform a standard Bell test, establishing nonlocal correlation, while Charlie, the client, need only share a long-range quantum correlation with Alice. After n rounds the server broadcasts its inputs, outputs, and switch settings; the client combines that broadcast with its own outcomes and estimates the conditional smooth min-entropy of its string using the generalised entropy accumulation theorem with testing. The single-round analysis, which treats the server's announcement data as public, bounds Charlie's guessing probability through a semidefinite-programming hierarchy and yields a min-tradeoff function. In the semi-device-independent version, with fair sampling assumed on the server's detectors, the asymptotic rate per heralded event is found to be positive exactly when the client's detection efficiency exceeds 50%, well below the detection-efficiency threshold of a conventional device-independent generator based on the same Bell test.","pith_inferences":["An immediate next step is a finite-key analysis, which the paper leaves for future work; the asymptotic 50% threshold will carry a correction term that shrinks as the square root of the number of rounds, so practical beacons will need to budget extra rounds.","The security proof trusts the server to announce its data truthfully; a natural extension is a post-hoc verification layer, such as authenticated commitments, that lets the client detect a lying server without changing the physical setup.","The model considers an honest-but-curious server and does not cover a server that actively lies about its inputs and outputs; real deployments would need a separate trust anchor for server behaviour.","The protocol's privacy guarantee rests on the client's device not leaking; a hardware demonstration would need to check that optical and electromagnetic side channels are suppressed before the claimed privacy is realised."],"forward_implications":["One well-equipped server can serve many clients, sharing the cost of the high-efficiency detectors and the entangled source and making randomness-as-a-service economical.","In the binary-setting example, the client's detector only needs to exceed 50% efficiency for a positive asymptotic rate, substantially below the threshold for a conventional device-independent generator.","Increasing the number of measurement bases on the client's side improves loss tolerance further, so clients can use cheaper avalanche-photodiode detectors rather than cryogenic superconducting nanowire detectors.","Because the server's data is broadcast after each round, the client can compute its entropy estimate from public information, while its own raw output remains private and uncorrelated with the server's registers.","The same routed Bell test hardware and quantum links can also be used for quantum key distribution, spreading the infrastructure cost across multiple applications."],"supporting_citations":[{"why":"Introduces the routed Bell test configuration and its non-signalling conditions, which the protocol inherits.","marker":"[24]"},{"why":"Provides the generalised entropy accumulation theorem with testing used for the multi-round entropy estimate.","marker":"[29]"},{"why":"Shows that long-range quantum correlations in routed Bell tests can survive arbitrarily large client-side loss, the fact behind the low efficiency threshold.","marker":"[25]"},{"why":"Defines the two-party Bell test that Alice and Bob run inside the server to demonstrate nonlocality.","marker":"[28]"},{"why":"Supplies the semidefinite-programming hierarchy used to bound the client's guessing probability in the single-round analysis.","marker":"[32]"},{"why":"Gives the min-tradeoff function construction technique that converts the single-round entropy bound into a GEAT rate.","marker":"[31]"}],"fun_headline_variants":["Client efficiency over 50% suffices for certified private randomness","Routed Bell test enables certified private randomness for clients","Private quantum randomness from untrusted devices at 50% client efficiency","Device-independent randomness with cheap clients and private outputs"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the server is honest-but-curious: it prepares the quantum state sent to the client independently of the switch input and truthfully announces its own inputs and outputs, because every entropy estimate is computed from that announced data and a lying server makes the certification vacuous.","fun_headline_variants_meta":{"raw":{"variants":["Client efficiency over 50% suffices for certified private randomness","Routed Bell test enables certified private randomness for clients","Private quantum randomness from untrusted devices at 50% client efficiency","Device-independent randomness with cheap clients and private outputs"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000201,"raw_usage":{"total_tokens":1370,"prompt_tokens":927,"completion_tokens":443,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":543,"completion_tokens_details":{"reasoning_tokens":376}},"tokens_in":543,"tokens_out":443,"duration_ms":5625,"temperature":1.0,"reasoning_tokens":376,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T17:41:26.994317+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the semi-device-independent protocol with the client's detection efficiency swept from below to above 50% and measure the certified randomness rate per heralded event; the paper predicts the rate drops to zero at the 50% threshold, so a positive rate below that efficiency would falsify the central quantitative claim.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduces the routed Bell test configuration and its non-signalling conditions, which the protocol inherits."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the semidefinite-programming hierarchy used to bound the client's guessing probability in the single-round analysis."},{"cited_title":"Pironio, A","cited_arxiv_id":null,"evidence_quote":"Gives the min-tradeoff function construction technique that converts the single-round entropy bound into a GEAT rate."}],"review_version":1}