{"id":"daa58826-c697-4041-b743-28bb3306c3f4","arxiv_id":"2607.06038","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":5,"one_line_summary":"A three-state BB84 QKD system with time-bin encoding achieves secure key distribution over 151 km by adapting the loss-tolerant method to account for measured state preparation flaws.","lead":"This paper demonstrates a quantum key distribution system that remains secure even when the quantum states it sends are imperfect, by measuring those imperfections and feeding them into the security analysis. It matters because high-speed QKD systems inevitably produce flawed states, and ignoring those flaws can overestimate security.","discovery_kind":"unclear","skeptic_critique":{"model":"glm-5.2","headline":"The decoy-state analysis (§C.4) uses nominal μ values that ignore the measured intensity-encoding correlations (Fig. 3), potentially biasing the single-photon bounds and thus the phase error rate.","rationale":"The reader rated CONDITIONAL with MODERATE confidence and listed the intensity-bit correlations as a scope limitation (point 4 in the rationale). I agree with the CONDITIONAL verdict but identify a more specific correctness issue: the decoy-state analysis itself — not just the LT method — assumes encoding-independent photon number distributions, and this assumption is violated by the measured correlations. This is a distinct concern from the SPF stability issue the reader emphasized as the weakest assumption. The SPF stability concern is practical (calibration could drift between measurement and key exchange); the decoy-state concern is theoretical (the bounds are computed under an assumption the system violates). Both are legitimate, but the decoy-state issue is more directly load-bearing for the correctness of the phase error rate. The concern does not warrant upgrading to REJECT because: (a) the intensity correlations appear small (Fig. 3a ratios are close to 1), so the quantitative impact may be modest; (b) the paper is transparent about not addressing these correlations; (c) security proofs that handle them are cited and could be applied in future work. The verdict remains CONDITIONAL, but the correctness risk should be flagged as somewhat higher than the reader's 'unknown' rating suggests — the specific gap in the decoy analysis is identifiable and unquantified.","tokens_in":27462,"tokens_out":13628,"duration_ms":745785,"concrete_test":"Using the encoding-dependent intensity ratios from Fig. 3a, recompute the single-photon bounds (Eqs. C54, C57) with μ_{k,A} replacing μ_k for each encoding A, and recalculate ϕ_Z^(LT) and SKR^(LT) for all three distances in Table II. If the phase error rate shifts by more than ~0.5 percentage points or SKR drops by more than ~15% at any distance, the nominal-μ analysis materially overestimates security.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The system uses a single intensity modulator for both qubit and decoy encoding, producing correlations between intensity levels and bit/basis choice (Fig. 3a, §IV). The paper acknowledges these correlations and limits the LT analysis to signal-intensity (μ₀) characterization. However, the decoy-state analysis in §C.4 also assumes that the photon number distribution P(n|μ_k) is independent of the encoding A, using nominal values μ₀=0.5 and μ₁=0.23 for all encodings. The actual mean photon numbers μ_{k,A} differ from these nominal values — Fig. 3a shows ratios deviating from 1 across encodings. The single-photon bounds (Eqs. C54, C57) depend on the factor e^{μ_k}/p_{μ_k} applied to the raw counts n(exp)_{ti,a,μk}. If the actual μ_{k,A} exceeds the nominal μ_k for some encoding A, the multi-photon contribution is underestimated, the single-photon fraction is overestimated, and the phase error rate (Eqs. 3, 9) is underestimated — directly inflating the secret key rate. This is not merely a scope limitation (\"we only consider SPFs\"): it is a correctness gap in the decoy-state bounds themselves, which are load-bearing for the phase error rate estimate and thus for the central security claim. The paper does not quantify the impact of this mismatch. Security proofs that handle intensity-encoding correlations exist (cited as [15,17,18,26]) but are not applied here.","agreement_with_reader":"partial"},"referee_report":{"model":"glm-5.2","summary":"This paper presents an implementation of a three-state BB84 protocol with time-bin encoding, one decoy state, and passive basis choice. The main contribution is adapting the loss-tolerant (LT) method of Tamaki et al. [12] to the simplified measurement scheme of Rusca et al. [20], enabling security analysis that incorporates measured state preparation flaws (SPFs) rather than assuming perfect state preparation. The key technical step is Eq. (8), which recovers the missing |+⟩ projection from available POVM elements via a linear combination. The authors demonstrate secret key exchange over 101.4 km, 112.6 km, and 151 km of ultra-low-loss fiber, showing that including SPFs increases the estimated phase error rate compared to the perfect-state assumption. The security proof is detailed in Appendix C and includes a sanity-check reduction to the perfect-state case (Eq. C49, matching [20]).","tokens_in":27604,"tokens_out":2618,"duration_ms":176008,"significance":"The paper makes a useful contribution to implementation security in QKD. The adaptation of the LT method to the simplified three-state protocol with passive basis choice is non-trivial: the protocol only provides access to the |−⟩ projection in the X basis, and the authors show how to recover the missing |+⟩ statistics using Eq. (8) and the side-bin Z-basis projections. The state characterization method is practical—it requires no setup modification beyond running the protocol with Bob revealing his bits during calibration. The reduction to the perfect-state case (§C.3, Eq. C49) provides a valuable consistency check. The experimental demonstration over 151 km with positive key rates under the LT analysis, and the quantitative comparison showing ~40% SKR reduction versus the perfect-state assumption, concretely illustrate the security cost of ignoring SPFs. The simulation plots in Figs. 8–11 provide intuition for how SPFs in different states affect the phase error rate.","major_comments":[{"comment":"§C.4, Eqs. (C54)–(C57): The decoy-state bounds use nominal mean photon numbers μ₀ = 0.5 and μ₁ = 0.23 for all encodings A ∈ {0Z, 1Z, 0X}. However, Fig. 3a and §IV show that the actual mean photon numbers μ_{k,A} depend on the encoding due to the single intensity modulator implementing both qubit and decoy encoding. The bounds in Eqs. (C54) and (C57) apply the factor e^{μ_k}/p_{μ_k} to raw counts n(exp)_{ti,a,μk} that are aggregated over encodings. If the actual μ_{k,A} deviates from the nominal μ_k for some encodings, the multi-photon contribution is misestimated, which propagates into the single-photon bounds s_Z and s_{Xside,Z} in Eq. (9), and thus into the final phase error rate ϕ_Z. The paper acknowledges the intensity-encoding correlations exist (§IV, §VII) and states 'we only consider SPFs,' but it does not explicitly address whether the decoy-state bounds themselves are affected.请","section":null}],"minor_comments":[{"comment":"§IV, Table I: The φ values for 0Z at 101.4 km differ significantly between μ₀ (0.5 rad) and μ₁ (1.9 rad). This large discrepancy is not discussed. A brief comment on whether this affects the analysis (which uses only μ₀ for the LT method) would help the reader.","section":null},{"comment":"§V, Eq. (9): The finite-key correction γ depends on Q_X itself (through the (1−b)b factor in Eq. 10). It would help to clarify whether this is solved self-consistently or whether an upper bound on Q_X is used as input.","section":null},{"comment":"§VI, Table II: The QBER_Z at 101.4 km (2.35%) is higher than at 112.6 km (1.89%), attributed to worse dispersion compensation. This is mentioned in the text but not in the table caption; a footnote or note would improve clarity.","section":null},{"comment":"Appendix B, Eqs. (B2)–(B11): The characterization assumes dark counts are negligible. Given the 151 km channel (~25.7 dB loss) and dark count rate of 8 cps, a brief justification of this assumption at the longest distance would strengthen the analysis.","section":null},{"comment":"§C.2.b, Eq. (C26): The states are written with φ = 0, but the measured φ values in Table I are non-zero (especially for 0Z). §VI mentions adjusting θ when φ > π/2, but the general treatment of non-zero φ in the security proof could be stated more explicitly, given that the LT method is stated to hold for arbitrary φ when states are linearly independent [12].","section":null},{"comment":"Fig. 4: The y-axis label 'PA block number' could be confused with privacy amplification; clarifying that this refers to data blocks processed for parameter estimation would help.","section":null},{"comment":"References: Several references are to 2025-dated works (e.g., [23], [26], [33], [34], [37], [38]). If these are not yet published, preprint identifiers should be included for traceability.","section":null}],"recommendation":"major_revision","confidential_remarks":"The intensity-encoding correlation issue is the key concern. The paper is transparent about the existence of these correlations but does not clearly separate two distinct things: (1) the LT method not accounting for intensity-encoding correlations in the state characterization (a legitimate scope choice), and (2) the decoy-state bounds in §C.4 using nominal μ values that may not match the actual encoding-dependent μ_{k,A} (a potential correctness issue in the numerical bounds). Point (2) is what needs to be addressed. If the deviations in Fig. 3a are small enough that the impact on the bounds is negligible, a quantitative argument to that effect would suffice. If not, the authors should either use encoding-specific μ values in the decoy analysis or explicitly bound the worst-case impact. The core theoretical contribution (adapting LT to the simplified protocol via Eq. 8) is sound and does not depend on this issue."},"author_rebuttal":{"model":"glm-5.2","summary":"The referee raises a valid concern about whether the intensity-encoding correlations documented in our system (Fig. 3a, §IV) affect the decoy-state bounds in Eqs. (C54)–(C57), which use nominal mean photon numbers rather than encoding-dependent values. We acknowledge this is a genuine gap in the current analysis and will revise the manuscript to explicitly address it.","responses":[{"response":"The referee is correct that Eqs. (C54)–(C57) as written apply the decoy-state bounds using nominal mean photon numbers μ_k, while Fig. 3a shows that the actual μ_{k,A} depend on the encoding A. We agree that this is a gap in the current presentation: the manuscript acknowledges the intensity-encoding correlations in §IV and §VII but does not explicitly address their impact on the decoy-state analysis itself. We will revise the manuscript to address this point directly. Specifically, we will add a discussion in §C.4 clarifying the following: (1) The decoy-state bounds in Eqs. (C54) and (C57) are applied to the virtual counts n(vir)_{sx,jx,μk}, which are linear combinations of the experimental counts aggregated over encodings A ∈ {0Z, 1Z, 0X} via the matrix M. The nominal μ_k values are used in the e^{μ_k}/p_{μk} factors. (2) Because the actual μ_{k,A} deviate from the nominal μ_k by amounts δμ_{k,A} that are measured during characterization (Fig. 3a), the multi-photon contribution for each encoding is indeed misestimated if one uses μ_k directly. (3) We will quantify the magnitude of this effect using the measured deviations shown in Fig. 3a, which are at the level of a few percent, and assess whether the resulting bias in s_Z and s_{Xside,Z} is significant relative to the finite-key statistical corrections. (4) If the effect is non-negligible, we will either incorporate encoding-dependent μ_{k,A} into the bounds or, alternatively, use conservative (worst-case) μ values that bound the actual μ_{k,A} from above, ensuring the single-photon bounds remain valid. We note that the LT portion of the analysis (the phase error rate Q_X for single photons) is not directly affected by this issue, since it uses only the signal-level (μ₀) characterization data and does not rely on de","revision_made":"no","referee_comment":"§C.4, Eqs. (C54)–(C57): The decoy-state bounds use nominal mean photon numbers μ₀ = 0.5 and μ₁ = 0.23 for all encodings A ∈ {0Z, 1Z, 0X}. However, Fig. 3a and §IV show that the actual mean photon numbers μ_{k,A} depend on the encoding due to the single intensity modulator implementing both qubit and decoy encoding. The bounds in Eqs. (C54) and (C57) apply the factor e^{μ_k}/p_{μ_k} to raw counts n(exp)_{ti,a,μk} that are aggregated over encodings. If the actual μ_{k,A} deviates from the nominal μ_k for some encodings, the multi-photon contribution is misestimated, which propagates into the single-photon bounds s_Z and s_{Xside,Z} in Eq. (9), and thus into the final phase error rate ϕ_Z. The paper acknowledges the intensity-encoding correlations exist (§IV, §VII) and states 'we only consider SPFs,' but it does not explicitly address whether the decoy-state bounds themselves are affected."}],"tokens_in":27093,"tokens_out":814,"duration_ms":108987,"standing_objections":[]},"desk_editor":{"model":"glm-5.2","letter":"The main thing to know: this paper adapts Tamaki et al.'s loss-tolerant (LT) security proof to the simplified three-state BB84 protocol with passive basis choice from Rusca et al. The key technical move is Eq. (8) — recovering the missing |+⟩ projection via M0X = M0Z + M1Z − M1X — which lets them compute the phase error rate from experimentally available statistics. They demonstrate key exchange over 151 km with measured state preparation flaws (SPFs), showing roughly 40% SKR reduction versus the perfect-state assumption. The core idea is sound and the derivation in Appendix C is detailed, including a clean sanity-check reduction to [20] in the perfect-state limit (Eq. C49). The experimental data is internally consistent: LT phase error rates are consistently higher than perfect-state estimates, which is what you'd expect. This is a legitimate and directly usable contribution for groups running similar protocols at high rates where SPFs are real and previously ignored. Credit where due: the characterization method is simple and practical — they just run the protocol and have Bob reveal his bits during calibration, no setup changes needed. The simulation plots (Figs. 8-11) are a nice touch for building intuition about how SPFs propagate into the phase error rate. Now, the soft spots. The stress-test concern about the decoy-state analysis is real. The paper acknowledges intensity-encoding correlations (Fig. 3a) — the single IM handles both qubit and decoy encoding, so μ depends on the bit/basis choice. They explicitly limit the LT analysis to signal intensity μ₀ and say they only consider SPFs. But the decoy-state bounds in §C.4 (Eqs. C54, C57) still use nominal μ₀=0.5 and μ₁=0.23 for all encodings. If the actual μ_{k,A} deviates from nominal for some encoding A, the multi-photon fraction is misestimated and the single-photon bounds — which feed directly into the phase error rate — are biased. This isn't just a scope limitation; it's a gap in the decoy-state bounds themselves. The deviations in Fig. 3a look small, so the practical impact may be modest, but it's not quantified. The paper should either bound the effect or cite and apply the existing frameworks for correlated sources [15,17,18,26]. The other limitations are minor and honestly stated: collective attacks only, no squashing map (inherited from [20]), EC/PA simulated not implemented, SPF stability assumed between calibration and key exchange. None of these undermine the central contribution. This paper is for QKD experimentalists and security theorists working on implementation security. It deserves a serious referee who can check the linear algebra in Appendix C and push the authors on the decoy-state μ mismatch. I'd recommend accept with revisions requiring the authors to either quantify or bound the impact of intensity-encoding correlations on the decoy-state bounds.","headline":"Adaptation of loss-tolerant method to simplified three-state BB84 is correct and useful; decoy-state analysis has an unaddressed gap from intensity-encoding correlations","tokens_in":28294,"tokens_out":1585,"would_cite":false,"duration_ms":101092,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"glm-5.2","headline":"QKD stays secure at 151 km despite flawed state preparation","keywords":["quantum key distribution","BB84","state preparation flaws","loss-tolerant method","time-bin encoding","decoy states","implementation security","phase error rate"],"falsifier":"If the state preparation flaws drift between calibration and key exchange (e.g., due to temperature changes or bias voltage adjustments), the phase error rate computed from stale characterization data would be invalid, and the security claim would not hold.","tokens_in":27652,"feed_emoji":"","tokens_out":985,"duration_ms":100831,"temperature":0.7,"pith_summary":"This paper proves and demonstrates that a simplified three-state BB84 quantum key distribution protocol can remain secure even when the quantum states Alice prepares are measurably imperfect, by adapting the loss-tolerant security method to work with the protocol's passive measurement scheme. The central mechanism is a linear-algebraic identity (Eq. 8) that reconstructs a missing measurement projection from three available ones, allowing the phase error rate to be computed from characterized, imperfect states rather than assumed-perfect ones. The authors characterize state preparation flaws by running the protocol with Bob revealing all bits during calibration, then feed those measured imperfections into the adapted security proof. They distribute secret keys over 101.4 km, 112.6 km, and 151 km of ultra-low-loss fiber with positive key rates at all distances, and show that assuming perfect state preparation would overestimate the key rate by up to 40%.","feed_headline":"Quantum keys stay secure at 151 km despite flawed photon states","feed_subtitle":"Adapting loss-tolerant security analysis to a simplified BB84 protocol proves keys can be distributed safely even when state preparation isn","key_machinery":"The POVM identity M0X = M0Z + M1Z − M1X (Eq. 8), which reconstructs the missing |+⟩ projection from available |0⟩, |1⟩, and |−⟩ measurements, enabling the loss-tolerant phase error rate estimation from characterized imperfect states in the simplified three-state BB84 protocol.","core_discovery":"The key technical discovery is that the POVM identity M0X = M0Z + M1Z - M1X allows the loss-tolerant method to be applied to the simplified three-state BB84 protocol, which lacks a direct projection onto the |+⟩ state. By expressing the missing |+⟩ projection as a linear combination of the |0⟩, |1⟩, and |−⟩ projections that the passive measurement scheme does provide, the authors can compute all virtual yields needed for the phase error rate estimation from experimentally accessible statistics. This bridges two previously separate results: the simplified protocol's measurement scheme and the loss-tolerant method's handling of state preparation flaws. When applied to measured states with ~0.2","pith_inferences":["The characterization schemes discussed in Appendix B (replica receiver, bidirectional calibration) could enable periodic re-characterization during key exchange, which would address the SPF stability assumption if implemented as an interleaved calibration-key-exchange protocol.","The simulation results in Figs. 8-9 showing that phase error rate stays minimal when δθ0Z = δθ1Z suggest a design principle: engineering state preparation flaws to be symmetric across Z-basis states could minimize the security penalty without requiring perfect states.","The matrix formalism (Eq. C18, qs = B^{-1}bs) being independent of Bob's basis choice probabilities suggests the security bound is robust to passive basis choice ratio optimization, allowing free tuning of pBZ for key rate without affecting the security guarantee."],"forward_implications":["QKD systems operating at high repetition rates can trade speed for provable security by characterizing state preparation flaws and incorporating them into the loss-tolerant analysis, rather than relying on unverified assumptions of perfect state preparation.","The finding that assuming perfect states overestimates key rates by up to 40% suggests that published QKD performance figures without state characterization may be systematically optimistic.","The observed correlations between intensity levels and bit encoding, arising from a single intensity modulator performing both tasks, indicate that future security analyses must handle multiple side-channels simultaneously rather than one at a time.","The characterization method—using Bob's existing detectors with all bits revealed during calibration—requires no additional hardware, making implementation security accessible to existing QKD deployments."],"fun_headline_variants":["Loss-tolerant math secures simplified quantum keys despite flawed states","New math bridges simplified quantum key protocol with loss-tolerant security","Simplified quantum key scheme proves secure against state preparation flaws","A mathematical identity secures simplified quantum keys against flawed states","Quantum keys remain secure in simplified protocol despite state prep flaws"],"cache_read_input_tokens":0,"weakest_assumption_plain":"The security analysis assumes that the state preparation flaws measured during calibration remain unchanged during the subsequent key exchange. If temperature drift, bias voltage changes, or other environmental factors shift the flaws between calibration and key exchange, the phase error rate estimate uses stale parameters.","fun_headline_variants_meta":{"raw":{"variants":["Loss-tolerant math secures simplified quantum keys despite flawed states","New math bridges simplified quantum key protocol with loss-tolerant security","Simplified quantum key scheme proves secure against state preparation flaws","A mathematical identity secures simplified quantum keys against flawed states","Quantum keys remain secure in simplified protocol despite state prep flaws"]},"model":"glm-5.2","effort":"high","cost_usd":0.0,"raw_usage":{"total_tokens":885,"prompt_tokens":411,"completion_tokens":474,"prompt_tokens_details":null},"tokens_in":411,"tokens_out":474,"duration_ms":12510,"temperature":1.0,"reasoning_tokens":481,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-08T18:24:56.055121+00:00","model_set":{"reader":"glm-5.2"},"falsifier":"If the state preparation flaws drift between calibration and key exchange (e.g., due to temperature changes or bias voltage adjustments), the phase error rate computed from stale characterization data would be invalid, and the security claim would not hold.","supporting_citations":[],"review_version":1}