{"id":"7712a8b5-d63f-4778-ba9a-4bafdd345e4c","arxiv_id":"2607.24624","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"Passive optical tapping plus photon-timing and power features can identify which of four quantum protocols is running at up to 96% accuracy while preserving Bell correlations.","lead":"Experiments show four quantum communication protocols leave distinct physical-layer fingerprints that a passive optical tap can classify at up to 96% accuracy without breaking entanglement. This raises a concrete side-channel risk for quantum networks and a possible non-intrusive monitoring tool.","discovery_kind":"new_application","skeptic_critique":{"model":"moonshotai/kimi-k3","headline":"The up-to-96% fingerprint may be a fingerprint of the lab's motorized half-wave-plate schedules, not of the protocols: SHAP shows timing features dominate, and each \"protocol\" was assigned a distinct hand-set temporal pattern on the same hardware.","rationale":"The reader's weakest_assumption already names the right soft spot — distinguishability driven by lab-specific implementation rather than protocol semantics — and this critique sharpens it rather than displacing it. Two additions: (1) the paper's own SHAP analysis is internal evidence for the concern, since the dominant features (count rate, IAT statistics) are precisely the channels through which the imposed HWP schedules leak, which makes the confound concrete rather than hypothetical; (2) the segment-level 80/20 split with pooled runs is a standard ML leakage vector that a run-held-out evaluation would close, and the permutation test converts \"this might be an artifact\" into a decisive check. The stealth issue (a 30% tap producing a ~29% coincidence drop is trivially detectable by link monitoring, and CHSH invariance under loss is expected) further weakens the threat-model interpretation but not the measurement itself. Credit where due: the testbed is genuinely shared across protocols, the dataset is balanced with non-overlapping sequences, rate-loss numbers are reported honestly rather than buried, and the CHSH data are provided with uncertainties. Minor: §V-G contains a sentence claiming lower sampling ratios \"significantly reduce coincidence rate,\" which contradicts Fig. 2 (10:90 gives 5.97%/2.23% drops) — a typo-level slip, not load-bearing. The empirical result stands on this hardware; CONDITIONAL correctly captures that the generalization to deployed quantum networks awaits the ablation above, plus release of traces/code for audit.","tokens_in":12220,"tokens_out":3053,"duration_ms":91104,"concrete_test":"Permute the confound: re-collect data with the HWP schedule assignments swapped across protocols (e.g., run heralded QKD with the gate-sequence rotation schedule and vice versa), or drive all four protocols through one identical fast-modulator timing envelope differing only in logical content (state choices, authentication-round placement). Evaluate with a run-held-out split (train on runs from day 1, test on day 2 after realignment). If timing-feature accuracy collapses toward the 25% four-class chance level, the fingerprint is schedule/run artifact; if accuracy survives via herald/coincidence structure, a genuine protocol-level signature exists and the security claim strengthens.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that protocol *semantics* leak through passive physical-layer observables. But the four protocols were made distinguishable by construction at the apparatus level: §III-A assigns each protocol a different 808 nm HWP rotation schedule (e.g., {0°,45°,0°,45°} for gate sequences), different herald usage, and different polarizer roles. The paper's own interpretability result (§V-F) shows photon count rate and interarrival-time statistics dominate classification — these features directly encode the cadence of the motorized waveplate schedule, not the protocol's logical content. In any deployed link, state preparation uses fast phase/polarization modulators; BB84-style QKD and entanglement distribution would share essentially identical random modulation timing, and the slow, protocol-correlated temporal envelope measured here would not exist. So the experiment demonstrates separability of four bench *implementations*, and §II-C's assertion that shared hardware \"ensures that observable differences arise from protocol behavior\" is unsupported — shared hardware does not imply shared temporal structure. A compounding issue: §III-D pools segments across runs and splits 80/20 randomly, so the model can learn run-specific calibration (alignment drift, rate offsets) correlated with which protocol ran in which run; no held-out-run or held-out-day evaluation is reported. Finally, the \"non-destructive observation\" framing rests on CHSH S>2 under tapping (§V-A), but CHSH invariance under a beam splitter is expected for pure loss; the operationally relevant fact is the ~29% coincidence-rate drop at 30:70, which legitimate parties monitoring the link would readily detect — so stealth, a prerequisite of the threat model, is only weakly supported. None of this overturns the on-testbed result; it limits what that result is evidence for.","agreement_with_reader":"agree"},"referee_report":{"model":"moonshotai/kimi-k3","summary":"The manuscript introduces the problem of \"protocol fingerprinting\" in quantum networks: can a passive observer who taps a fraction of the optical signal (without measuring the encoded quantum states) infer which quantum communication protocol is running? Using a polarization-entangled SPDC testbed, the authors implement four protocols (entanglement distribution, quantum gate sequences, heralded QKD, and QIA), collect photon-detection timing statistics and optical power measurements at 10:90 and 30:70 tap ratios, and train recurrent sequence models (best: Bi-Stacked LSTM) to classify protocol identity. Reported accuracies reach 96% at 30:70 and 70–89% at 10:90. CHSH measurements (S = 2.324–2.359, all above 2) are used to argue the tap preserves entanglement, and SHAP analysis shows timing features (count rate, interarrival statistics) dominate classification. The problem formulation is genuinely novel and the experimental execution is competent; however, two methodological issues bear directly on what the results demonstrate, and the security interpretation is currently stated more strongly than the evidence supports.","tokens_in":12646,"tokens_out":2651,"duration_ms":94993,"significance":"If the central claim holds, the work identifies a real and previously underexplored leakage channel: protocol-level traffic analysis on quantum links by a passive adversary, analogous to classical website fingerprinting. Strengths worth naming: (i) the problem is new — prior quantum side-channel work targets QKD internals or quantum-computer controllers, not cross-protocol identification on a communication link; (ii) the same-hardware multi-protocol testbed is a reasonable design for isolating protocol-induced differences; (iii) the entanglement-preservation check under tapping (CHSH with uncertainties) is a genuine experimental contribution rather than an assumption; (iv) the inclusion of SHAP-based interpretability and confusion-matrix error analysis is good practice and lets the reader see *which* physical features carry the signal. The manuscript is also honest about the observability/rate tradeoff. What limits significance is that the demonstrated separability may be a property of these four bench implementations (hand-set motorized waveplate schedules, protocol-specific herald roles) rather than of the protocols' logical content — the paper's own SHAP result points this way —","major_comments":[{"comment":"The load-bearing interpretive claim is that observable differences 'arise from protocol behavior rather than changes in the underlying physical infrastructure' (§II-C, final sentence). Shared hardware does not establish this. Per §III-A, each protocol is assigned a distinct, hand-set temporal pattern on the same apparatus: gate sequences use fixed HWP schedules ({0°,45°,0°,45°} or {0°,22.5°,45°,67.5°}), entanglement distribution uses no modulation, QKD uses random four-state preparation, and QIA uses key-dependent interleaved authentication rounds. The paper's own SHAP analysis (§V-F, Figs. 4a/4c) shows photon count rate and interarrival-time statistics dominate — features that directly encode the cadence of the motorized waveplate schedule and herald usage, not the protocols' logical content. In a deployed link, BB84-style QKD and entanglement distribution would share near-identical fas","section":"§II-C and §III-A (vs. §V-F)"},{"comment":"The evaluation protocol permits run-level leakage. Data are collected 'over multiple runs' per protocol, segmented, randomly arranged, and split 80/20 (7200 samples → 1440 sequences → 1152/288). Because protocols were necessarily executed in separate runs (the HWP schedule and herald configuration differ per protocol), run-specific calibration — alignment drift, count-rate offsets, temperature — is perfectly correlated with the label, and a random segment-level split lets the model exploit it. Local min–max normalization (§III-D) mitigates but does not eliminate this, since normalization parameters are themselves run-level statistics. The reported accuracies (Table I) are therefore an upper bound on protocol separability. A held-out-run (or held-out-day) evaluation — train on all runs but one per class, test on the excluded run — is the standard control and is feasible with the existing","section":"§III-D / §IV-A"},{"comment":"The 'non-destructive observation' framing needs qualification. CHSH S > 2 under tapping shows that the *surviving* pairs remain entangled; it does not show the tap is undetectable. The 30:70 configuration — the one yielding the headline 96% accuracy — reduces photon count and coincidence rates by ~29% each (Fig. 2), a macroscopic, easily monitored signature that any reasonably instrumented link would flag. Only the 10:90 configuration (~6%/2% drops) is plausibly stealthy, and there the accuracy is 70–89%. The abstract and §V-G should state this tradeoff as a constraint on the threat model rather than describing the observation model as non-destructive without qualification. Relatedly, the threat model (§II-B) assumes 'no prior knowledge of protocol family or type,' yet the classifier is trained on labeled traces of exactly these four protocols — a closed-world assumption that should be s","section":"§V-A and §V-G"}],"minor_comments":[{"comment":"The sentence 'Overall, the confusion matrix analysis reveals that classification errors are not random...' and the following sentence are duplicated nearly verbatim in consecutive paragraphs.","section":"§V-E"},{"comment":"'Shapely additive explanations (SHAP)' should read 'SHapley Additive exPlanations'.","section":"§I-B"},{"comment":"Ref. [15], cited for SHAP in §I-B and §IV-B, is a secondary arXiv preprint on feature selection; the primary citation (Lundberg & Lee, already listed as [20]) should be used at first mention.","section":"References"},{"comment":"With only 288 test sequences, the headline 96.18% corresponds to 277/288 correct; binomial 95% CI is roughly ±2.2%. Confidence intervals (or per-run variance across repetitions) should accompany Table I, especially given the single train/test split.","section":"§III-D / Table I"},{"comment":"Typesetting: missing spaces around numbers ('up to96%under30:70...'); also 'up to 96%' is achieved by one model under one configuration — the abstract should indicate the range across models to avoid overreading.","section":"Abstract"},{"comment":"The statement that θ = 45° implements a Pauli-X and θ = 22.5° a Hadamard refers to HWP angle conventions acting on polarization; a half-sentence clarifying that these are polarization rotations (HWP at θ rotates linear polarization by 2θ) would prevent confusion with qubit-gate angles.","section":"§III-A"},{"comment":"The tap is placed after the 808 nm HWP; it would help to state explicitly whether the observer's detector is polarization-insensitive (no analyzer before the observer detector), since this determines whether state-preparation information is directly visible at the tap or only via rate/timing.","section":"§II-C, Fig. 1"}],"recommendation":"major_revision","confidential_remarks":"The empirical work is competently executed and the problem is timely and well-motivated; I do not doubt the reported numbers as measurements of this testbed. My concern is the gap between what is demonstrated (separability of four lab implementations distinguished by hand-set modulation schedules, evaluated with a segment-level random split) and the framing (a general protocol-level side channel for quantum networks). Both requested additions — a held-out-run evaluation and either a matched-schedule control or narrowed claims — are feasible with the existing apparatus and data, so major revision rather than rejection seems right. The citation pattern is unremarkable; novelty relative to refs. [9]–[11] is adequately disclosed."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The new result is straightforward and useful: on one polarization-entangled free-space link they run four protocols (entanglement distribution, gate sequences, heralded QKD, QIA), tap 10% or 30% of one path, and classify from photon timing plus power with up to 96% accuracy at 30:70 and still 70–89% at 10:90, while CHSH stays above 2. Same hardware, held-out sequences, SHAP, confusion matrices—the experimental narrative is clean and the non-collapse claim is backed by actual S-values.\n\nWhat they do well is the multi-protocol same-testbed design and the explicit rate-vs-observability tradeoff (roughly 6%/2% vs 29%/29% count/coincidence drops). Prior side-channel work mostly attacked known QKD boxes or controller power; treating protocol identity itself as the secret under a passive tap is a genuine framing shift for quantum networking security.\n\nThe soft spot is real but proportionate. Section III-A assigns each protocol a distinct 808 nm HWP schedule and herald/polarizer role. SHAP then says count rate and interarrival statistics dominate—exactly the cadence of those motorized schedules. Shared optics do not imply shared temporal structure, so the result is strong evidence that these four bench implementations are separable, weaker evidence that “protocol semantics” leak on a real link where BB84 and entanglement distribution would share fast random modulators. Random 80/20 split of pooled segments also leaves open run-to-run calibration leakage; no held-out-day or held-out-run numbers. Stealth is only half-supported: pure loss preserves CHSH, but a 29% coincidence drop is something the legitimate parties would notice.\n\nNone of that kills the paper. It is an honest first experimental existence proof with clear tables and interpretability. Readers who care about QKD/QIA traffic analysis or non-intrusive monitoring get value; theorists looking for a general leakage theorem will be disappointed. Data/code release and a noise/modulator follow-up would tighten it.\n\nI would send it to referees. Worth engaging if you work on quantum-network security or physical-layer monitoring; skim the stress points above before citing the security conclusions as settled.","headline":"Solid bench demo that four protocol implementations leave passive side-channel fingerprints, but the 96% figure mostly tracks lab-specific HWP timing, not abstract protocol semantics.","tokens_in":13556,"tokens_out":571,"would_cite":false,"duration_ms":23102,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"A passive optical tap can identify which quantum communication protocol is running, with up to 96% accuracy, without collapsing entanglement.","keywords":["protocol fingerprinting","physical layer side channel","quantum communication","optical tapping","entanglement distribution","heralded QKD","quantum identity authentication","photon detection statistics"],"falsifier":"Repeat the same four protocols on an independent entangled-photon link (different source, fiber or free-space path, and detector set) with a 10:90 or 30:70 tap; if classification accuracy collapses to chance while S-values still exceed 2, the claimed protocol-level side channel does not generalize.","tokens_in":13311,"feed_emoji":"📡","tokens_out":953,"duration_ms":24151,"temperature":0.7,"pith_summary":"This paper asks whether quantum networks leak protocol identity the way classical systems leak secrets through side channels. On a polarization-entangled photon link, the authors run four protocols—entanglement distribution, quantum gate sequences, heralded QKD, and quantum identity authentication—and let an observer see only a fraction of the light via a beam splitter, never measuring the encoded quantum states. From photon arrival timing and optical power alone, a sequence model can name the active protocol with accuracy up to 96% when 30% of the light is tapped, and still 70–89% when only 10% is taken. Bell tests stay above the classical bound, so the tap does not destroy the entanglement the network relies on. The result matters because protocol identity is often the first thing an adversary needs before targeting a service, and the paper shows that identity can be read without the usual quantum alarms.","feed_headline":"Optical taps name quantum protocols at up to 96% accuracy","feed_subtitle":"Photon timing and power alone reveal which service is running, without collapsing entanglement","key_machinery":"Passive optical tapping plus a data-driven fingerprint: a beam splitter samples a fixed fraction of one photon path; time-tagger features (count rate, interarrival mean/std/CV) and power-meter features (irradiance and power statistics) feed sequence models (best: Bi-Stacked LSTM), with SHAP showing timing features dominate and power features add complementary signal.","core_discovery":"Different quantum communication protocols leave distinguishable physical-layer signatures in photon detection statistics and optical power. Under a passive tap that never measures the encoded states, those signatures are enough to classify four representative protocols on a polarization-entangled link at up to 96% accuracy (30:70 split) and 70–89% (10:90 split), while CHSH S-values remain above 2, confirming entanglement is preserved.","pith_inferences":["If timing features dominate, simple rate-smoothing or deliberate burst shaping at the source may be a cheaper countermeasure than optical isolation of the channel.","The same fingerprinting approach likely extends to other SPDC-based services (teleportation, entanglement swapping) whose duty cycles and basis choices also imprint on arrival statistics.","A realistic adversary who can only afford a few-percent tap may still succeed by aggregating longer observation windows, so future work should report accuracy versus both split ratio and integration time.","Standardization bodies for quantum networks may need side-channel evaluation criteria analogous to those already used for classical cryptographic modules."],"forward_implications":["Protocol identity in quantum networks can be treated as a side-channel secret that must be protected, not assumed private by quantum mechanics alone.","Even a 10% optical tap can support traffic analysis and usage profiling without breaking entanglement or triggering state-collapse alarms.","Non-intrusive network monitors could use the same tap-and-classify pipeline for diagnostics, not only adversarial ends.","Defenses must now target temporal and intensity signatures (obfuscation, rate padding, or signature equalization), not only quantum-state secrecy.","Higher tap fractions buy accuracy at a clear cost in photon and coincidence rate, defining an observability-versus-rate tradeoff operators must manage."],"fun_headline_variants":["Side-channel taps fingerprint quantum protocols at 96% accuracy","Photon stats alone ID quantum protocols without breaking entanglement","Passive optical taps classify four quantum protocols up to 96%","Physical-layer signatures reveal quantum protocol identity","Protocol fingerprints persist under 10:90 optical tapping"],"cache_read_input_tokens":128,"weakest_assumption_plain":"The measured differences come from how the protocols behave, not from the particular lab source, wave-plate schedules, heralding setup, or low-noise free-space conditions used in the experiment.","fun_headline_variants_meta":{"raw":{"variants":["Side-channel taps fingerprint quantum protocols at 96% accuracy","Photon stats alone ID quantum protocols without breaking entanglement","Passive optical taps classify four quantum protocols up to 96%","Physical-layer signatures reveal quantum protocol identity","Protocol fingerprints persist under 10:90 optical tapping"]},"model":"grok-4.5","effort":"low","cost_usd":0.004166,"raw_usage":{"total_tokens":1284,"prompt_tokens":830,"num_sources_used":0,"completion_tokens":60,"cost_in_usd_ticks":41664000,"prompt_tokens_details":{"text_tokens":830,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":394,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":830,"tokens_out":60,"duration_ms":5506,"temperature":1.0,"reasoning_tokens":394,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-31T10:17:51.308366+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Repeat the same four protocols on an independent entangled-photon link (different source, fiber or free-space path, and detector set) with a 10:90 or 30:70 tap; if classification accuracy collapses to chance while S-values still exceed 2, the claimed protocol-level side channel does not generalize.","supporting_citations":[],"review_version":1}