REVIEW 5 major objections 5 minor 1 cited by
Continuous-Variable Source-Independent Quantum Random Number Generator with a Single Phase-Insensitive Detector
T0 review · 5 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read A single phase-insensitive detector can certify randomness from an untrusted source.
desk verdict Promising protocol and the right dimension-reduction idea, but the central security proof as printed is not valid: the dual in Eq. (13) does not bound the primal, and Eq. (8) states an equality that is only an inequality. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is a dimension-reduction bound on the probability weight of a source state living above $N$ photons. For a POVM diagonal in the Fock basis, the projection onto $N$ photons commutes with each $M_j$; Hölder's inequality gives $\operatorname{tr}(M_j \bar P \rho \bar P) \le \|\rho_{\bar N}\|_1 \|M_{j,\bar N}\|_\infty$, and the tail weight $\|\rho_{\bar N}\|_1$ is bounded by $\langle n\rangle/N$ via the dual program Eq. (11) with feasible point $x=0$, $y=1/N$. These two inequalities turn the infinite-dimensional SDP (5) into the finite-dimensional SDP (12), whose dual (13) is solved to obtain $d^*_N$.
What would settle it
Use a two-mode source engineered to give the same single-mode click probabilities and mean photon number while placing more than $\langle n\rangle/N$ weight above the cutoff; if its true guessing probability exceeds $d^*_N$, the finite-dimensional constraints have missed part of the feasible set.
Extended reading notes
Core claim
The central claim is that for any single-mode source state whose photon-number statistics match the observed outcomes and whose mean photon number is $\langle n\rangle$, the optimal value $d^*_N$ of the finite-dimensional SDP in Eq. (12), and its dual in Eq. (13), is an upper bound on the guessing probability of the infinite-dimensional problem, so $H_{\min}(A|E) \ge -\log_2 d^*_N$. The argument splits each optimal sub-state into an $N$-photon part and a tail; the tail contributes at most $\langle n\rangle/N$ through the feasible point $x=0$, $y=1/N$ of the dual tail-weight program, and that slack is folded into loosened constraints. The bound is therefore valid even though the optimization is truncated to photon numbers below $N$.
Load-bearing premise
The proof assumes the source is a single optical mode and that the mean photon number is known exactly, because the tail-weight bound $\langle n\rangle/N$ relies on that dual feasible point.
Editorial extensions
If this is right
- Any source state compatible with the measured outcome probabilities and mean photon number is covered by the same bound, so the security statement is not tied to the coherent-state simulation.
- Detectors whose POVM elements are diagonal in the Fock basis, including common single-photon detectors, can serve as the measurement, so no squashing model is needed.
- The randomness yield per sample is at least $-\log_2 d^*_N$ in the asymptotic limit, and solving the dual problem avoids relying on the exact optimum of the truncated primal under finite precision.
- The simulation indicates that with a time-multiplexed detector and weak coherent states the lower bound exceeds $10^{-2}$ bits per sample, pointing to practical rates.
Reading between the lines
- A possible extension is to replace the single-mode tail bound with a multi-mode bound, tracking the photon-number operator per mode; the single-mode assumption is load-bearing in the present proof.
- The asymptotic argument could be turned into a finite-size bound by estimating the mean photon number and outcome probabilities from a finite block and propagating confidence intervals through the loosened constraint, which the paper does not carry out.
- The same projection-and-tail idea may extend to POVMs that are not Fock-diagonal if off-diagonal terms are bounded separately, which would broaden the detector classes beyond phase-insensitive ones.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes a continuous-variable source-independent quantum random number generator (CV-SI-QRNG) that uses a single phase-insensitive detector whose POVM elements are diagonal in the Fock basis. To avoid squashing models, the authors introduce a dimension-reduction technique: they project the infinite-dimensional optimization for the guessing probability onto the subspace of photon numbers below a cutoff N, bound the tail weight outside this subspace by the mean photon number divided by N, and formulate a finite-dimensional SDP (Eq. (12)) with constraints derived from the observed probabilities. They then give a claimed dual SDP (Eq. (13)) and assert that its optimal value d*_N provides a rigorous upper bound on the original infinite-dimensional guessing probability, leading to the min-entropy bound H_min >= -log2 d*_N (Eq. (15)). The protocol is simulated for a time-multiplexed single-photon detector with weak coherent states and parameters N=20, m=10, Nmode=2^5, yielding min-entropy lower bounds above 10^-2 bits per sample for mean photon numbers below 1. The central claim is that the finite-dimensional SDP and its dual certify security against arbitrary source states compatible with the observed statistics and mean photon number.
Significance. If the proof can be corrected, the result would be a useful step: it would extend numerical security analysis to infinite-dimensional CV-SI-QRNGs without restrictive squashing assumptions, for a broad class of phase-insensitive detectors, using only standard SDP duality and no fitted parameters. The proposed implementation with a single time-multiplexed detector is experimentally simple, and the simulation gives a concrete, falsifiable prediction of the achievable min-entropy rate. However, the manuscript as printed contains load-bearing mathematical errors in Eqs. (8), (11), and (13), so the security claim is not currently established; the significance is therefore conditional on a successful correction.
major comments (5)
- [IV, Eq. (13) and Appendix A] Eq. (13) is not a valid dual of Eq. (12). The point λ=η=ξ=0 is always feasible in Eq. (13) because its constraint reduces to M_{k,N} − I ⪯ 0, and the objective at that point is 0. However, the primal Eq. (12) can have positive optimal value; for example, with m=2, M_1=0.9 I, M_2=0.1 I, N=20, ⟨n⟩=0, and p=(0.9,0.1), the feasible choice ρ_1=|0⟩⟨0|, ρ_2=0 gives objective 0.9. Hence the claimed inequality d*_N ≥ p* cannot be true, and Eq. (15) is unsupported as printed. The Lagrange derivation in Appendix A contains algebraic errors: starting from Eq. (A1), the constant term and the signs in the coefficient of ρ_{k,N} lead to a different dual, namely min_{λ,η,ξ≥0} 1 + Σ_j λ_j p_j − Σ_j η_j p^L_j + ξ subject to M_{k,N} + Σ_j(η_j − λ_j)M_{j,N} − (1 + ξ)I ⪯ 0 (with λ for the upper constraints and η for the lower constraints). The printed Eqs. (A4), (A5), and (13) have the wrong signs on the probability terms and are missing the constant 1.
- [IV, Eq. (8)] The second equality in Eq. (8) is not generally valid. It asserts Σ_k tr(ρ*_{k,bar N} M_{k,bar N}) = 1 − Σ_k tr(ρ*_{k,N}), which would require each M_{k,bar N} to be the identity on the tail subspace. In general only the inequality Σ_k tr(ρ*_{k,bar N} M_{k,bar N}) ≤ Σ_k tr(ρ*_{k,bar N}) = 1 − Σ_k tr(ρ*_{k,N}) holds, since Σ_k M_{k,bar N} = I_{bar N} and each M_{k,bar N} ⪯ I_{bar N}. The desired upper bound can be repaired by replacing the equality with this inequality, but as written the derivation is mathematically incorrect.
- [IV, Eqs. (10)-(11)] The dual problem stated in Eq. (11) has the wrong objective sign. For the maximization max tr(ρ bar P) subject to tr(ρ a†a) = ⟨n⟩ and trρ = 1, the standard Lagrange dual is min_{x,y∈R} x + y⟨n⟩ subject to bar P − xI − y a†a ⪯ 0. The feasible point x=0, y=1/N then gives the upper bound ⟨n⟩/N on the tail weight, as used in the text. With the printed objective −x−y⟨n⟩, the same feasible point gives −⟨n⟩/N, so the claimed tail bound does not follow from the displayed dual.
- [IV, Eq. (12) and protocol step 3] The tail bound relies on an exact value of the mean photon number ⟨n⟩. The protocol (step 3) only says that ⟨n⟩ is "well estimated" by a phase-insensitive detector. If ⟨n⟩ is merely estimated from data, an underestimation makes the constraint p^L_j too large, so the finite SDP Eq. (12) need not contain the projection of the true feasible set and d*_N can fail to be an upper bound. The manuscript should either state explicitly that ⟨n⟩ is a known a priori upper bound on the source's mean photon number, or incorporate finite-sample or uncertainty bounds on ⟨n⟩ into p^L_j. This assumption is load-bearing, not merely a practical detail.
- [IV, Eq. (10)] The optimization in Eq. (10) and the POVM model in Eq. (6) assume the source is a single bosonic mode. The security claim in Eq. (15) is phrased for "any source state compatible with observed statistics"; if the physical source emits light in several modes and the detector collects all of them, the operator a†a in Eq. (10) must be replaced by the total photon-number operator of the relevant modes and the tail bound may no longer scale as ⟨n⟩/N. The single-mode assumption should be stated as an explicit protocol assumption, and the multi-mode case should be either analyzed or explicitly excluded.
minor comments (5)
- [II.B, Eq. (5)] In the first constraint, the summation index j is reused for the measurement outcome j; it should be Σ_k ρ_k rather than Σ_j ρ_j.
- [III, Eq. (6)] The non-projective condition is stated as "the spectrum norm of an arbitrary POVM element M_j should be less than 1"; since the M_j are positive, this should be written as ||M_j||∞ < 1, and the completeness relation Σ_j M_j = I should be stated explicitly.
- [IV, Eq. (8)] The symbols ρ*_{k,N}, M_{k,N}, and bar N are used in Eq. (8) before their definition in the following sentence; the notation should be introduced before the equation. The word "POP" in the explanation after Eq. (8) appears to be a typo.
- [V, Fig. 2] The figure reports only a single curve; no solver, SDP tolerance, or verification of the dual bound is given, and the label "lg(R)" should state the base of the logarithm and clarify that the quantity is the min-entropy per sample.
- [Title and throughout] There are several typographical errors, including "N umber" in the title, "affact" in Section III, and "Arbitraty" in Section III; these should be corrected.
Circularity Check
No circularity: the SDP security bound is computed from measured inputs; the minor self-citation to the author's numerical framework is not load-bearing, while the apparent Eq. (13) weak-duality sign issue is a correctness concern, not a circularity.
full rationale
The paper's derivation chain is: Eqs. (2)-(5) reduce the guessing probability to an SDP; Eqs. (8)-(12) construct a finite-dimensional relaxation using the tail-weight bound; Eq. (13) is the claimed dual; Eq. (15) converts the SDP value into a min-entropy lower bound. No step defines the target quantity (the randomness lower bound or the guessing probability) in terms of itself. The probabilities p_j and mean photon number <n> are protocol inputs, not fitted parameters, and the SDP computes a certified upper bound from them. The tail-weight bound in Eq. (11) is a derived bound via a feasible dual point, not an assumed conclusion. The dimension-reduction technique is attributed to external Ref. [20] and is re-derived in Section IV. Ref. [17] is a self-citation to the author's earlier numerical framework, but Eq. (5) is independently justified in the text from the pure-state decomposition and POVM grouping, so this self-citation is not load-bearing. The apparent sign issue in the printed dual Eq. (13) and Appendix A, where the always-feasible point lambda=eta=xi=0 gives objective 0 while the primal can be positive, is a mathematical correctness or weak-duality concern rather than a circularity: it does not make the output equal to an input by construction. Hence there is no significant circularity; the score reflects only the presence of one minor, non-load-bearing self-citation.
Assumptions & free parameters
free parameters (4)
- photon number cutoff N =
20
- number of temporal modes N_mode =
25
- number of POVM elements m =
10
- mean photon number <n> =
<= 1, swept in simulation
assumptions (5)
- domain assumption The SDP framework of Eqs. (1)-(5) correctly characterizes the SI-QRNG guessing probability.
- domain assumption The detector POVM elements M_j are exactly known and diagonal in the Fock basis.
- domain assumption The mean photon number <n> is exactly known from measurements.
- standard math The dimension-reduction technique of Ref. [20] applies and is valid.
- domain assumption The time-multiplexed detector can be modeled as n balls into N_mode bins with equal probability.
Cite this review
Pith. "Pith review of Continuous-Variable Source-Independent Quantum Random Number Generator with a Single Phase-Insensitive Detector." pith.science (2026). https://pith.science/paper/E3I4RPDJ
@misc{pith2026241114817,
author = {Pith},
title = {Pith review of: Continuous-Variable Source-Independent Quantum Random Number Generator with a Single Phase-Insensitive Detector},
year = {2026},
howpublished = {\url{https://pith.science/paper/E3I4RPDJ}},
note = {Machine review of arXiv:2411.14817}
}
read the original abstract
Quantum random number generators (QRNGs) harness quantum mechanical unpredictability to produce true randomness, which is crucial for cryptography and secure communications. Among various QRNGs, source-independent QRNGs (SI-QRNGs) relax the trust on the quantum source, allowing for flexible use of advanced detectors to achieve high randomness generation rates. Continuous-variable (CV) SI-QRNGs, in particular, hold promise for practical deployment due to their simplicity and randomness generation rates comparable to trusted-device QRNGs. In this work, we propose a novel CV-SI-QRNG scheme with a single phase-insensitive detector, and provide security proof based on semi-definite programming (SDP). We introduce a dimension reduction technique, which rigorously reduces an infinite-dimensional SDP problem to a finite-dimensional one, enabling efficient computation while maintaining valid randomness lower bound. We further validate our method through simulations. These results demonstrate the feasibility of our framework, paving the way for practical and simple SI-QRNG implementations.
Figures
Forward citations
Cited by 1 Pith paper
-
Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey
A practical reference that maps post-quantum cryptography from mathematical foundations to deployment, including a taxonomy of six algorithm families, NIST status, and performance data.
Reference graph
Works this paper leans on
-
[20]
I. ˇSupi´ c, P. Skrzypczyk, and D. Cavalcanti, Phys. Rev. A 95, 042340 (2017)
work page 2017
-
[1]
The untrusted source sends an unknown quantum state to a phase-insensitive detector
-
[2]
The detector outputs a measurement result j ∈ {1, 2,...,m }, characterized by a set of POVM {Mj}m j=1
-
[3]
After repeating steps 1-2 for a large number of rounds, Alice records the probability of each out- comepj and estimate the mean photon number ⟨n⟩
-
[4]
Then she performs the post- processing to extract the final random numbers
Alice calculates the upper bound of the probability of successful guessing. Then she performs the post- processing to extract the final random numbers. The protocol description is general for all SI-QRNGs. For a CV-SI-QRNG, the key difference is that the dimension of Mj is infinity, which make the security analysis dif- ficult. One possible method to reduce t...
-
[5]
and the nu- merical security analysis becomes feasible. In this work, we will use another simpler approach, a novel dimension reduction technique based on the diago- nal form of POVM of phase-insensitive detectors to deal with the infinite dimensional optimization problem. IV. SECURITY ANALYSIS Recalling Eq. ( 5), we can see that the security analysis of s...
-
[6]
is an infinite dimensional SDP problem. To make it com- putable, we define a projection on the subspace where the photon number is less than N , i.e., P = ∑ N −1 n=0 |n⟩ ⟨n|, and its complement ¯P = I −P . Then after the pro- jection P , all operators in Eq. (
-
[7]
We try to find an upper bound of the target function
are represented by N -dimensional matrices in Fock basis. We try to find an upper bound of the target function. Suppose the solution to Eq. ( 5) is ρ∗ k, we have the follow- ing relation of the maximum guessing probability, m∑ k=1 tr(ρ∗ kMk) = m∑ k=1 tr(ρ∗ k,NMk,N ) + m∑ k=1 tr(ρ∗ k, ¯NMk, ¯N ) = m∑ k=1 tr(ρ∗ k,NMk,N ) + 1 − m∑ k=1 tr(ρ∗ k,N ) ≤ max ρk,N ∈...
Show all 31 references
-
[8]
( 8), which means the asymptotic randomness per sample has a lower bound Hmin(A|E) ≥ − log2d∗ N
is p∗, then d∗ N ≥p∗ by Eq. ( 8), which means the asymptotic randomness per sample has a lower bound Hmin(A|E) ≥ − log2d∗ N. (15) V. SIMULATION In this section we make a simulation on the ran- domness lower bound by considering a practical phase- insensitive detector, for exam...
-
[9]
0 0.2 0.4 0.6 0.8 1 mean photon number 10-3 10-2 10-1 Min-entropy lower bound lg(R) FIG
It turns out the randomness lower bound can surpass 10 −2 bit per sample for commonly used weak co- herent state sources and TMDs. 0 0.2 0.4 0.6 0.8 1 mean photon number 10-3 10-2 10-1 Min-entropy lower bound lg(R) FIG. 2. Simulation of the randomness lower bound versus the me...
-
[10]
Bischof, H
F. Bischof, H. Kampermann, and D. Bruß, Phys. Rev. A 95, 062305 (2017)
2017
-
[11]
Herrero-Collantes and J
M. Herrero-Collantes and J. C. Garcia-Escartin, Rev. Mod. Phys. 89, 015004 (2017)
2017
-
[12]
The primal problem is given in Eq
using the Lagrange duality framework. The primal problem is given in Eq. ( 12) To construct the Lagrange function, we introduce the dual variables: λj ≥ 0 and ηj ≥ 0 for the lower and upper bounds of the constraints on the measurement probabilities, respec- tively,ξ ≥ 0 for th...
-
[13]
X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, npj Quantum Inf. 2, 16021 (2016)
2016
-
[14]
Chaturvedi and M
A. Chaturvedi and M. Banik, EPL 112, 30003 (2015)
2015
-
[15]
Z. Cao, H. Zhou, and X. Ma, New J. Phys. 17, 125011 (2015)
2015
-
[16]
J. B. Brask, A. Martin, W. Esposito, R. Houlmann, J. Bowles, H. Zbinden, and N. Brunner, Physical Re- view Applied 7, 054018 (2017)
2017
-
[17]
Nie, J.-Y
Y.-Q. Nie, J.-Y. Guan, H. Zhou, Q. Zhang, X. Ma, J. Zhang, and J.-W. Pan, Phys. Rev. A 94, 060301(R) (2016)
2016
-
[18]
Y.-H. Li, X. Han, Y. Cao, X. Yuan, Z.-P. Li, J.-Y. Guan, J. Yin, Q. Zhang, X. Ma, C.-Z. Peng, et al., npj Quantum Information 5, 1 (2019)
2019
-
[19]
Z. Cao, H. Zhou, X. Yuan, and X. Ma, Phys. Rev. X 6, 011020 (2016)
2016
-
[21]
D. G. Marangon, G. Vallone, and P. Villoresi, Phys. Rev. Lett. 118, 060503 (2017)
2017
-
[22]
Drahi, N
D. Drahi, N. Walk, M. J. Hoban, A. K. Fedorov, R. Shakhovoy, A. Feimov, Y. Kurochkin, W. S. Koltham- mer, J. Nunn, J. Barrett, and I. A. Walmsley, Phys. Rev. X 10, 041048 (2020)
2020
-
[23]
Avesani, H
M. Avesani, H. Tebyanian, P. Villoresi, and G. Vallone, Phys. Rev. Applied 15, 034034 (2021)
2021
-
[24]
Avesani, D
M. Avesani, D. G. Marangon, G. Vallone, and P. Vil- loresi, Nature communications 9, 1 (2018)
2018
-
[25]
P. R. Smith, D. G. Marangon, M. Lucamarini, Z. Yuan, and A. Shields, Physical Review A 99, 062326 (2019)
2019
-
[26]
Avesani, H
M. Avesani, H. Tebyanian, P. Villoresi, and G. Vallone, Communications Physics 5, 273 (2022)
2022
-
[27]
Zhou, Physical Review A 107, 052402 (2023)
H. Zhou, Physical Review A 107, 052402 (2023)
2023
-
[28]
N. J. Beaudry, T. Moroder, and N. L¨ utkenhaus, Phys. Rev. Lett. 101, 093601 (2008)
2008
-
[29]
Gittsovich, N
O. Gittsovich, N. J. Beaudry, V. Narasimhachar, R. R. Alvarez, T. Moroder, and N. L¨ utkenhaus, Physical Re- view A 89, 012325 (2014)
2014
-
[30]
Upadhyaya, T
T. Upadhyaya, T. van Himbeeck, J. Lin, and N. L¨ utkenhaus, PRX Quantum2, 020325 (2021)
2021
-
[31]
Achilles, C
D. Achilles, C. Silberhorn, C. Sliwa, K. Banaszek, I. A. Walmsley, M. J. Fitch, B. C. Jacobs, T. B. Pittman, and J. D. Franson, Journal of Modern Optics 51, 1499 (2004)
2004
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.