{"id":"5d868028-87c2-46b5-a1b6-6b7dbce7bbca","arxiv_id":"2607.06682","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":7.5,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"Operational bounds on state exclusion (not only identification) plus a three-setting retained-key protocol certify positive SDI-QKD rates down to nearly vanishing preparation visibility.","lead":"This paper shows that semi-device-independent quantum key distribution can stay secure even when Alice's source is very noisy, if the trusted source bound also limits what an eavesdropper can rule out, not just what she can identify. That exclusion-based trust model, plus a three-setting protocol and modern entropy certificates, pushes usable key rates far below previous visibility thresholds.","discovery_kind":"extension","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified beyond the paper's own trusted-bound caveat.","rationale":"The strongest claim is numerical and asymptotic: exclusion-assisted operational bounds certify positive key far below identification-only and earlier RAC-key thresholds, while incomplete leakage does not kill the rate. Supporting structure is explicit—exact classical frontiers, monotone task values under input-independent channels, three-setting retained-key protocol with QZ=0 on the ideal BB84 branch, and two independent entropy certificates over the same lifted feasible set. The reader correctly isolates the trusted scalar bound TQ(E)≤τ as the modelling premise; physical justifications (phase-randomized vacuum weight, parity obliviousness) motivate τ but are not re-checked adversarially. That is standard for SDI and is not hidden. Finite-key reduction is only sketched (Appendix G) and experimental calibration of τ is left open—both already noted. No stronger load-bearing flaw (e.g., failure of data processing, non-tight classical frontier, or unvalidated SDP gap that would push the exclusion-assisted critical visibilities above the identification-only ones) appears in the text. Hence the ACCEPT verdict stands; the concrete check is a reproducibility verification of the lowest-visibility certificates rather than a search for a missing proof step.","tokens_in":40039,"tokens_out":609,"duration_ms":6634,"concrete_test":"Independently re-solve the PM-BFF node programs for the preparation-depolarized family at ν=0.02 under T=D⊕A (and T=Π⊕A) with the same 64-word basis, Bob degree-3 block, sharp localizers, and 34-node quadrature of Appendix E; accept only if primal/dual/reconstructed residuals ≤5×10−6. If the guarded rate remains positive and matches the published root estimates within 10−3, the headline thresholds stand.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim—that exclusion-assisted bounds D⊕A/Π⊕A yield positive asymptotic rates down to nearly vanishing preparation visibility, and that incomplete direct-sum leakage still leaves positive rates—rests on three pieces that the manuscript actually supplies: (i) exact classical frontiers (Theorem 1 / Appendix A), (ii) data-processing lift of the scalar task bound to every Bob–Eve extension (Proposition 5), and (iii) validated finite-level min-entropy and PM-BFF certificates over the lifted set FT(p,τ) with explicit acceptance tolerances (Appendices D–F). The only soft spot is the one the reader already flags: τ is trusted and not re-certified inside the adversarial optimization. That is a modelling premise of SDI, not an internal gap; the paper states it openly and uses physical models only to motivate τ. No derivation inconsistency, circular fit, or unvalidated numerical claim was found that would overturn the reported thresholds.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript reformulates semi-device-independent QKD by replacing a Hilbert-space dimension bound with a scalar operational upper bound on one of four tasks on Alice’s four-preparation ensemble: four-state discrimination D, parity discrimination Π, or the normalized composites D⊕A and Π⊕A with state exclusion. For the two-bit RAC it derives exact classical frontiers (Theorem 1), shows that BB84 attains the maximal quantum deviation from all four frontiers within numerical precision, and identifies complementary preparation-depolarized and direct-sum leakage families as the sampled arbitrary-dimensional quantum boundary for the exclusion-assisted tasks. Via data processing, the same scalar bound lifts to every Bob–Eve extension of the emitted ensemble. A three-setting retained-key protocol (RAC test on y=0,1; key generation on y=2 for the 00/11 branch) then yields two dimension-independent certificates over the feasible set FT(p,τ): a min-entropy bound from Eve’s optimized key-guessing probability, and a prepare-and-measure Brown–Fawzi–Fawzi (PM-BFF) lower bound on conditional von Neumann entropy. Numerically, exclusion-assisted assumptions certify positive asymptotic rates down to nearly vanishing preparation visibility, far below identification-only and earlier RAC-key thresholds; under direct-sum leakage all four independently optimized rates remain positive for incomplete leakage and vanish only at complete label revelation.","tokens_in":40306,"tokens_out":1315,"duration_ms":24699,"significance":"If the results hold, the paper substantially strengthens the SDI toolkit by showing that robust security is governed not only by what an adversary can identify but also by what she can exclude. Exact classical frontiers with explicit attaining strategies (Appendix A), a clean data-processing lift (Proposition 5), and dual validated finite-level certificates (min-entropy and PM-BFF) with stated residual tolerances and a reproducibility archive are genuine strengths. The three-setting retained-key protocol cleanly removes the intrinsic RAC-key reconciliation penalty of earlier constructions, and the separation of protocol, entropy certificate, and source assumption is carefully executed. The optical common-component route to exclusion-assisted bounds is a concrete experimental entry point. These contributions are of clear interest for prepare-and-measure QKD and operational quantum information.","major_comments":[{"comment":"The security theorems (Theorem 2 and the rate bounds in Sec. V–VI) treat TQ(E)≤τ as a trusted, externally supplied scalar that is not re-certified from the observed three-setting table p. This is standard for SDI and is stated openly, but the main text should more explicitly separate (i) how τ is obtained from a physical model or independent calibration (Appendix H) from (ii) the adversarial optimization over FT(p,τ). A short protocol-level paragraph on independent estimation or certification of τ—without feeding the same data used for key generation—would close the only modelling soft spot the security reduction leaves open.","section":"Sec. V.B, Proposition 5; Theorem 2"},{"comment":"All reported rates are asymptotic i.i.d. rates per retained key round with ideal one-way reconciliation. Appendix G correctly shows that accepted PM-BFF duals supply affine min-tradeoff inputs for GEAT, but no finite-n rates, testing overhead, or error-correction leakage are evaluated. The abstract and Sec. VI should state more prominently that the near-zero visibility thresholds are asymptotic certificates, and that converting them into finite-key rates requires additional protocol-level choices not fixed in this work. This does not undermine the asymptotic claims but is load-bearing for how the numerical thresholds will be read.","section":"Abstract; Sec. VI; Appendix G"}],"minor_comments":[{"comment":"In Result 2 / Fig. 3, the arbitrary-dimensional D boundary remains unresolved over part of the intermediate range (d=3 see-saw exceeds depolarization; gap to Q3 remains). A one-sentence caveat in the main text that only the exclusion-assisted boundaries are claimed to be sampled would avoid over-reading panel (a).","section":"Sec. IV.C, Result 2, Fig. 3"},{"comment":"Table III and the critical-visibility stars in Figs. 4–6 are linear root estimates from nearest accepted samples of opposite sign (Appendix F). Marking them as estimates (e.g., “≈”) in the table caption and figure legends would match the careful wording already used in the appendix.","section":"Table III; Figs. 4–6; Appendix F"},{"comment":"Notation for the composite tasks switches between D⊕A / (D+A)/2 and the two-setting task language. A single consistent definition early in Sec. II.B (already almost present in Eqs. 5) would help readers who skip the figure.","section":"Sec. II.B, Eqs. (4)–(5), Fig. 2"},{"comment":"The phrase “four-state discrimination” in the abstract and introduction is later also called “full-label guessing.” Pick one primary term and use the other only as a parenthetical synonym on first occurrence.","section":"Abstract; Sec. I"},{"comment":"Minor typographical inconsistencies appear in a few places (e.g., spacing around νM, occasional “Bob–Eve” vs “Bob-Eve”). A final copy-edit pass would suffice.","section":null}],"recommendation":"minor_revision","confidential_remarks":"The manuscript is unusually careful for a numerical SDI security paper: exact classical frontiers, dual validation with explicit tolerances, and a reproducibility archive. I see no load-bearing derivation error. The two major comments are about framing and scope (trusted τ; asymptotic vs finite-key), not about correctness of the reported thresholds. Fit for a strong quant-ph / QKD venue is good. I would not block on the incomplete D quantum boundary; the authors already flag it."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The real news here is not another dimension-bound SDI tweak. They replace the usual Hilbert-space ceiling with four operational scalar tasks on Alice’s four-preparation ensemble—full-label discrimination, parity discrimination, and the two composites with exclusion—and prove the exact classical RAC frontiers for each (Theorem 1, Appendix A, posterior geometry with explicit attaining mixtures). That alone is clean and useful.\n\nWhat then matters for rates is the structural point: exclusion is not fixed by identification (Proposition 1). Bounding D⊕A or Π⊕A therefore removes Bob–Eve extensions that D or Π alone leave open. Combined with a three-setting retained-key protocol (RAC test on y=0,1; key on the 00/11 branch with y=2) and both min-entropy and PM-BFF certificates over the lifted feasible set, they get positive asymptotic rates down to ν≈0.01 under the exclusion-assisted assumptions—orders of magnitude below the old RAC-key thresholds and the identification-only curves. Under direct-sum leakage the rates stay positive for every incomplete ℓ and vanish only at full label revelation. The numerics are dual-validated to 5e-6 with explicit acceptance criteria; the data-processing lift (Prop. 5) is standard and carefully stated.\n\nSoft spots are the ones the paper itself flags. The scalar bound τ is trusted and not re-certified inside the adversarial optimization; physical models (phase-randomized vacuum weight, parity obliviousness) only motivate τ. Everything is asymptotic i.i.d. collective. Finite-key and experimental calibration of τ remain open. None of that is hidden or load-bearing for the claims they actually make.\n\nMath, appendices, and citation pattern look solid; self-cites are background tools, not circular. This is for people who care about prepare-and-measure security proofs, optical source assumptions, and entropy certification. I would bring it to reading group, cite the frontiers and the exclusion-rate tables, and send it to peer review without hesitation.","headline":"Solid SDI-QKD paper: exact classical frontiers plus exclusion-assisted bounds that actually push key rates to near-zero visibility, with validated SDP certificates.","tokens_in":40894,"tokens_out":514,"would_cite":true,"duration_ms":7452,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Hk","03.65.Ud"],"model":"grok-4.5","headline":"Semi-device-independent quantum keys stay secure when you bound not only what Eve can identify about Alice’s states, but also what she can rule out.","keywords":["semi-device-independent QKD","operational source assumptions","random-access code","state exclusion","conditional min-entropy","Brown–Fawzi–Fawzi bound","prepare-and-measure","quantum key distribution"],"falsifier":"Run the three-setting protocol on a preparation-depolarized BB84 ensemble at visibility well below the identification-only thresholds (for example ν ≈ 0.05) while enforcing an exclusion-assisted source bound; if the accepted min-entropy or PM-BFF certificates cannot produce a positive rate, or if an explicit incomplete-leakage ensemble yields zero certified rate before full label revelation, the central robustness claim fails.","tokens_in":40976,"feed_emoji":"🔐","tokens_out":1124,"duration_ms":14857,"temperature":0.7,"pith_summary":"Standard semi-device-independent quantum key distribution trusts a limit on Alice’s source (often just Hilbert-space dimension) while leaving Bob’s measurements untrusted. This paper replaces that with four operational bounds on Alice’s four-state ensemble: how well anyone can guess the full label, how well they can guess its parity, and the same two tasks averaged with state exclusion. For the two-bit random-access code it derives the exact classical score ceilings under each bound, shows that BB84-type strategies give the largest quantum excess, and then certifies key rates with a three-setting protocol that tests the code on two settings and generates the raw key on a third. Because the task values cannot increase under input-independent channels, the same scalar bound applies to every Bob–Eve extension of the observed statistics. Exclusion-assisted bounds still give positive asymptotic rates at nearly vanishing preparation visibility—far below identification-only and earlier RAC-key thresholds—while under explicit label leakage the rates stay positive until the label is fully revealed. The practical message is that robust SDI security is governed by both identification and exclusion.","feed_headline":"SDI quantum keys survive when Eve is blocked from excluding states","feed_subtitle":"Exclusion-assisted source bounds keep positive rates near zero preparation visibility","key_machinery":"Four scalar operational source tasks on Alice’s four-preparation ensemble—four-state discrimination D, parity discrimination Π, and the normalized composites D⊕A and Π⊕A—together with their exact classical RAC frontiers, data-processing lift to unrestricted Bob–Eve extensions, and a three-setting retained-key protocol certified by min-entropy guessing optimization and prepare-and-measure Brown–Fawzi–Fawzi entropy relaxations.","core_discovery":"Robust semi-device-independent security of the retained-key random-access-code protocol depends on operational source assumptions that constrain what Eve can exclude as well as what she can identify: under the composite bounds D⊕A or Π⊕A, dimension-independent min-entropy and PM-BFF certificates yield positive key rates down to near-zero preparation visibility, and under incomplete direct-sum label leakage all four rate bounds remain positive until full label revelation.","pith_inferences":["Self-testing of the ensemble geometry for the exclusion-assisted tasks could turn the trusted source bound into a partially certified feature rather than a pure hypothesis.","The same identification-versus-exclusion split may tighten other prepare-and-measure tasks such as semi-device-independent randomness generation and receiver-device-independent QKD.","Optical experiments that already calibrate vacuum probability or mean photon number are natural first platforms for the composite assumptions without needing a qubit-dimension claim.","If exclusion remains the dominant robustness source, protocol design should prioritize source models that jointly limit identification and exclusion rather than only improving entropy certificates on fixed feasible sets."],"forward_implications":["SDI-QKD need not rely on a hard dimension bound; a trusted operational task bound on the emitted ensemble is enough for dimension-independent rate certificates.","Adding state exclusion to the source assumption removes adversarial extensions that pure identification bounds still allow, dramatically lowering the visibility needed for positive key.","The three-setting retained-key protocol removes the intrinsic RAC decoding penalty of earlier two-setting SDI constructions, improving rates even under the weak qubit-implied distinguishability ceiling D ≤ 1/2.","Physical models with a common vacuum or phase-randomized weak coherent states can be plugged in solely by converting photon-number or vacuum weight into a composite task bound.","Accepted PM-BFF dual certificates already supply affine one-round entropy lower bounds usable as min-tradeoff functions for future finite-key entropy-accumulation analyses."],"fun_headline_variants":["Exclusion-assisted bounds keep SDI key rates positive near zero visibility","What Eve cannot exclude certifies robust semi-device-independent keys","Composite source tasks secure SDI QKD down to vanishing preparation visibility","Operational exclusion constraints yield dimension-independent SDI key rates","Incomplete label leakage still allows positive rates under all four source bounds"],"cache_read_input_tokens":30720,"weakest_assumption_plain":"The security proof trusts that a single scalar bound on Alice’s emitted ensemble is correct and cannot be increased by any later processing that Bob or Eve apply, so any side channel that reveals the label without raising that bound would leave the analysis incomplete.","fun_headline_variants_meta":{"raw":{"variants":["Exclusion-assisted bounds keep SDI key rates positive near zero visibility","What Eve cannot exclude certifies robust semi-device-independent keys","Composite source tasks secure SDI QKD down to vanishing preparation visibility","Operational exclusion constraints yield dimension-independent SDI key rates","Incomplete label leakage still allows positive rates under all four source bounds"]},"model":"grok-4.5","effort":"low","cost_usd":0.006716,"raw_usage":{"total_tokens":1734,"prompt_tokens":874,"num_sources_used":0,"completion_tokens":90,"cost_in_usd_ticks":67160000,"prompt_tokens_details":{"text_tokens":874,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":770,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":874,"tokens_out":90,"duration_ms":8583,"temperature":1.0,"reasoning_tokens":770,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-10T23:29:20.563404+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Run the three-setting protocol on a preparation-depolarized BB84 ensemble at visibility well below the identification-only thresholds (for example ν ≈ 0.05) while enforcing an exclusion-assisted source bound; if the accepted min-entropy or PM-BFF certificates cannot produce a positive rate, or if an explicit incomplete-leakage ensemble yields zero certified rate before full label revelation, the central robustness claim fails.","supporting_citations":[],"review_version":1}