{"id":"417b4841-407b-42e6-9f57-cac6a0b9052d","arxiv_id":"2607.11713","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":2.5,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A structured survey of optimized quantum adders, multipliers, modular exponentiation and point-addition circuits for public-key cryptanalysis, plus fault-tolerant resource estimation techniques.","lead":"This survey reviews quantum arithmetic circuits used in Shor-style attacks on RSA and ECC, focusing on resource optimizations like measurement-based uncomputation. It organizes designs and estimation methods so cryptanalysts can better judge real quantum attack costs.","discovery_kind":"review","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified","rationale":"The strongest claim is modest and correctly scoped for a review chapter: the surveyed optimizations and estimation methods together give a practical foundation for resource estimates. Because the paper does not invent new circuits or re-derive every cited count under one lattice-surgery model, the compilation-gap concern raised by the reader is a known limitation of the field rather than a flaw in the argument. The concrete verification step above is the only check still worth performing; if the numbers match the sources, no adjustment to the ACCEPT verdict is warranted. Novelty remains low (as the reader scored) and correctness risk stays low.","tokens_in":23220,"tokens_out":443,"duration_ms":4717,"concrete_test":"Cross-check three representative resource numbers cited in Sections 2–4 (e.g., Gidney’s Logical-AND adder T-count, the optimal-depth CLA of Wang et al. 2025, and the windowed modular-exponentiation cost of Gidney–Ekerå) against their original papers or Qualtran models; if any figure is mis-transcribed by >10 % the survey’s reliability as a reference would be reduced, otherwise the claim stands.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper is an overview/survey chapter whose central claim is that optimized arithmetic circuits (MBU, conditionally clean ancilla, windowed LUTs) plus surface-code estimation techniques supply a realistic basis for evaluating quantum cryptanalysis of RSA/ECC. That claim is definitional for a review: it organizes existing constructions (Tables 3–7, Sections 2–4) and sketches the estimation pipeline (Section 5) without asserting new asymptotic bounds or a single unified lattice-surgery schedule. The reader’s weakest-assumption note—that concrete Toffoli/qubit/magic-state figures may shift under a full compiler—is true of the literature the paper cites, but is not load-bearing for the survey’s own claim; the text already flags distillation dominance and points to external tools (Qualtran, Azure estimator). No internal inconsistency or unsupported technical assertion appears.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"This chapter surveys quantum arithmetic circuits for public-key cryptanalysis (RSA and ECC via Shor’s algorithm). It reviews Clifford+T designs for addition, subtraction, multiplication, division, modular exponentiation and elliptic-curve point addition, with emphasis on measurement-based uncomputation, conditionally clean ancillae and windowed LUT techniques. Tables 3–7 organize the literature by architecture and asymptotic cost; Sections 4–5 connect the circuits to concrete RSA/ECC resource estimates and surface-code runtime models (magic-state distillation, lattice surgery). The central claim is that these optimized building blocks plus standard fault-tolerant estimation pipelines supply a realistic basis for evaluating large-scale quantum cryptanalysis.","tokens_in":23387,"tokens_out":651,"duration_ms":5711,"significance":"As a survey the work is useful: it consolidates a scattered literature on quantum adders, multipliers and modular arithmetic under a common set of metrics (Toffoli depth/count, qubit count) and correctly highlights the practical impact of MBU, conditionally clean ancillae and windowed arithmetic on RSA/ECC cost models. The explicit linkage of circuit-level optimizations to surface-code estimation tools (Qualtran, Azure estimator) and the tabulated asymptotic comparisons (especially Table 5 for Toom–Cook) give practitioners a convenient reference. No new theorems or machine-checked proofs are claimed; the contribution is organizational and pedagogical, which is appropriate for a handbook-style chapter.","major_comments":[],"minor_comments":[{"comment":"Figure 3 caption contains an editorial note (“Anubhab: We can redraw these diagrams in tikz”) that should be removed before publication.","section":null},{"comment":"Table 1 gate drawings are incomplete or misaligned for several operators (Toffoli, CZ); a clean redraw would improve readability.","section":null},{"comment":"Section 1.3, Step 4: the equality after applying Ug is written without intermediate algebra; a short expansion would help readers less familiar with measurement-based uncomputation.","section":null},{"comment":"Inconsistent hyphenation and spacing appear throughout (e.g., “Inbrief,” “carry-lookahead” vs “Carry-Lookahead,” “Mu noz-Coreas”). A light copy-edit pass is needed.","section":null},{"comment":"Section 5 cites external repositories and tools but does not give version numbers or commit hashes; adding them would improve reproducibility of the estimation pipeline description.","section":null},{"comment":"A few self-citations of the authors’ own recent arXiv preprints (e.g., [117], [112]) are listed as 2025; ensure final bibliographic data are updated once DOIs appear.","section":null}],"recommendation":"accept","confidential_remarks":"The manuscript is a survey chapter rather than a research article; its fit depends on whether the journal/volume accepts handbook-style overviews. Novelty is modest but the organization is competent and the technical content is accurate. No integrity or citation-pattern concerns."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is a survey/chapter, not a research paper. It does exactly what the abstract promises: pulls together the main quantum arithmetic building blocks used in Shor for RSA and ECC, with emphasis on the practical optimizations people actually use (measurement-based uncomputation, conditionally clean ancillae, windowed LUTs) and a short tour of surface-code runtime estimation.\n\nNothing here is new. Every circuit family, depth/qubit figure, and estimation method is taken from the literature (Gidney, Häner, Roetteler, the authors’ own earlier papers, etc.). The value is organization. Tables 3–7 give a readable map of adders, multipliers, dividers, modular exponentiation and point addition. The explanations of MBU and conditionally clean ancillae are clear and correctly distinguish what you can and cannot uncompute with measurements. Section 5 correctly flags that magic-state distillation dominates cost and points to the usual tools (Qualtran, Azure estimator). Citations are primary and dense; self-cites are only for the authors’ prior constructions, which is fine.\n\nSoft spots are minor and expected for a survey. The concrete Toffoli/qubit numbers come from heterogeneous papers, so they are not re-derived under one lattice-surgery schedule; the text already notes this limitation. A couple of figures look like placeholders, and the coverage of recent carry-save and compressor work is a bit thin, but nothing is mis-stated. No internal contradictions, no invented entities, no circular claims.\n\nThis is for people who need a single entry point into quantum arithmetic for cryptanalysis—grad students, resource-estimation groups, or standards folks setting migration timelines. It is not for someone looking for a new asymptotic bound or a unified compiler model. Math and data are just accurate reporting of prior work; that is solid for the genre.\n\nI would engage with it as a reference. A serious editor should send it to peer review for a survey/chapter venue; it is competent enough to deserve the time.","headline":"Clean, up-to-date survey chapter that organizes known quantum arithmetic circuits and estimation tricks for RSA/ECC cryptanalysis; useful reference, zero new results.","tokens_in":23988,"tokens_out":508,"would_cite":true,"duration_ms":13622,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Resource-efficient quantum arithmetic circuits give a realistic basis for evaluating quantum attacks on RSA and ECC.","keywords":["Quantum Computing","Quantum Arithmetic Circuit","Quantum Error Correction","Quantum Cryptanalysis","Public-key Cryptography","Shor's Algorithm","Measurement-based Uncomputation","Windowed Arithmetic"],"falsifier":"Take the lowest-cost modular-exponentiation circuit cited for RSA-2048, re-compile it end-to-end with an open lattice-surgery tool that includes magic-state distillation and routing, and check whether the resulting physical-qubit and cycle counts still match the order-of-magnitude claims in the paper.","tokens_in":24153,"feed_emoji":"🔐","tokens_out":807,"duration_ms":14741,"temperature":0.7,"pith_summary":"Shor’s algorithm threatens RSA and elliptic-curve cryptography, but its cost is dominated by quantum modular arithmetic—addition, multiplication, exponentiation, and point addition. This review shows how those building blocks can be made far cheaper by measurement-based uncomputation, conditionally clean ancillae, and windowed look-up tables that replace long sequences of multiplications with classical pre-computation. The same optimizations are then mapped through surface-code error correction to obtain concrete estimates of logical depth, qubit count, and physical runtime. A sympathetic reader cares because these numbers, not asymptotic big-O statements, decide when today’s public-key systems must be replaced and how large a quantum computer is actually required.","feed_headline":"Quantum arithmetic sets the real cost of breaking RSA","feed_subtitle":"Optimized circuits and surface-code estimates show when Shor’s algorithm becomes practical against public-key crypto.","key_machinery":"Measurement-based uncomputation together with conditionally clean ancillae: temporary workspace qubits are cleaned by mid-circuit measurement and classical feedback (or restored under known conditions) instead of full reverse computation, cutting Toffoli count and depth; windowed look-up tables further collapse many controlled multiplications into single table loads.","core_discovery":"When quantum arithmetic circuits for modular exponentiation and elliptic-curve point addition are redesigned with measurement-based uncomputation, conditionally clean ancillae, and windowed look-up arithmetic, the resulting Toffoli depth, qubit count, and surface-code resource estimates become a practical yardstick for the cryptanalytic power of large-scale quantum computers against RSA and ECC.","pith_inferences":["The same MBU-plus-windowing toolkit is portable to other arithmetic-heavy quantum algorithms such as quantum chemistry simulation or lattice-based cryptanalysis.","A single unified lattice-surgery compiler applied to all surveyed circuits may shrink some of the reported asymptotic gains and reveal which designs remain dominant.","Conditionally clean ancillae that enable sub-linear-depth adders could change the asymptotic scaling of modular exponentiation itself."],"forward_implications":["Concrete physical-qubit and runtime numbers for factoring 2048-bit RSA and solving ECDLP become available under surface-code assumptions.","Post-quantum security parameters can be set against the best known quantum arithmetic costs rather than asymptotic lower bounds.","Any further reduction in magic-state distillation overhead translates directly into lower time-space volume for Shor’s algorithm.","Windowed classical–quantum trade-offs will continue to shrink quantum gate count at the price of classical pre-computation."],"fun_headline_variants":["Optimized quantum arithmetic sets RSA-breaking resource yardstick","Measurement-based uncomputation cuts cost of quantum RSA attacks","Windowed look-ups and clean ancillae redefine Shor's RSA cost","Quantum modular exp circuits become practical cryptanalysis gauge","Resource estimates from improved arithmetic show RSA and ECC risk"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"The circuit costs quoted for the surveyed designs stay accurate once every circuit is fully compiled under one concrete surface-code lattice-surgery schedule and a realistic magic-state factory layout.","fun_headline_variants_meta":{"raw":{"variants":["Optimized quantum arithmetic sets RSA-breaking resource yardstick","Measurement-based uncomputation cuts cost of quantum RSA attacks","Windowed look-ups and clean ancillae redefine Shor's RSA cost","Quantum modular exp circuits become practical cryptanalysis gauge","Resource estimates from improved arithmetic show RSA and ECC risk"]},"model":"grok-4.5","effort":"low","cost_usd":0.004926,"raw_usage":{"total_tokens":1301,"prompt_tokens":720,"num_sources_used":0,"completion_tokens":83,"cost_in_usd_ticks":49260000,"prompt_tokens_details":{"text_tokens":720,"audio_tokens":0,"image_tokens":0,"cached_tokens":0},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":498,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":720,"tokens_out":83,"duration_ms":4365,"temperature":1.0,"reasoning_tokens":498,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-14T03:40:50.767955+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Take the lowest-cost modular-exponentiation circuit cited for RSA-2048, re-compile it end-to-end with an open lattice-surgery tool that includes magic-state distillation and routing, and check whether the resulting physical-qubit and cycle counts still match the order-of-magnitude claims in the paper.","supporting_citations":[],"review_version":1}