REVIEW 3 major objections 4 minor 3 cited by
Marginal-constrained entropy accumulation theorem
T0 review · 3 major / 4 minor · reviewed 2026-08-09 · deepseek-v4-flash
Pith's one-line read The paper proves a chain rule for marginal-constrained quantum channel entropies and derives a new entropy accumulation theorem whose single-round bounds can carry different input-marginal constraints per round, enabling fully adaptive…
desk verdict The chain rule and strong additivity are solid and genuinely new, but the headline MEAT statement leans on an unproven convexity lemma that the paper itself flags as suspect; worth refereeing, but the gap needs to be closed. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the marginal-constrained Rényi channel conditional entropy, $H^{\uparrow}_{\alpha}(M, B, [\psi_A]) := \inf_{\rho: \rho_A = \psi_A} H^{\uparrow}_{\alpha}(B \mid C \tilde R)_{M[\rho]}$, defined with a stabilizing register and an optional constraint on the input marginal. The proof route goes through weak additivity, a duality between channel conditional entropy and minimized channel divergence, superadditivity of measured Rényi divergence proven by dual SDPs, and a regularization argument that lifts measured divergences to sandwiched divergences. For the accumulation theorem, the machinery is completed by f-weighted Rényi entropies and a purifying function, whose convexity (Lemma 4.10) enables a Clark-Duffin strong-duality step (Lemma 4.12) that converts the single-round optimization $h_\alpha$ into a tractable dual form.
What would settle it
Take a fixed read-and-prepare channel and two input marginals $\omega^0_A$ and $\omega^1_A$, and compare the purified f-weighted entropy $H^{\uparrow,f}_{\alpha}(SC \mid \tilde C E \tilde E)_{M[\mathrm{Pur}(\omega_A)]}$ at the mixture $(\omega^0_A+\omega^1_A)/2$ with the average of its values at the two endpoints for $\alpha \geq 1$; any dip below the average would invalidate Lemma 4.10 and the dual step behind $h_\alpha$. The same test restricted to the secret-register case would directly probe the gap the paper flags when it says convexity in $f$ fails there.
Extended reading notes
Core claim
The central discovery, stated as Theorem 3.1, is that for $\alpha \in [1, \infty]$ the marginal-constrained channel conditional entropy is superadditive under channel composition: $H^{\uparrow}_{\alpha}(E_2 \circ E_1, X_1X_2, [\psi_{A_0} \otimes \phi_{A_1}]) \geq H^{\uparrow}_{\alpha}(E_2, X_2, [\phi_{A_1}]) + H^{\uparrow}_{\alpha}(E_1, X_1, [\psi_{A_0}])$. As a consequence, the quantity is equal to its regularized version and additive across tensor products. Feeding this chain rule into the f-weighted entropy machinery of prior QKD analysis produces the marginal-constrained entropy accumulation theorem (Theorem 4.2b), which bounds $H^{\uparrow}_{\alpha}(S^n_1 C^n_1 \mid \tilde C^n_1 E^n)_{\rho|\Omega} \geq n h_\alpha - \frac{\alpha}{\alpha-1} \log \frac{1}{p_\Omega}$, where $h_\alpha$ is an infimum over single-round states compatible with the marginal constraints. This is the first entropy accumulation bound of this family that allows each round to carry its own input-marginal constraints and fully adaptive tradeoff functions.
Load-bearing premise
The bound collapses if the single-round f-weighted entropy, after purification, is not a convex function of the input marginal state; the paper defers that convexity proof to an earlier work and notes that a closely related convexity statement fails when secret registers are present.
Editorial extensions
If this is right
- If the chain rule is correct, a QKD protocol can be analyzed with a different input-marginal constraint in every round, so source-replacement security proofs do not require identical rounds.
- The accumulation bound $H^{\uparrow}_{\alpha}(S^n_1 C^n_1 \mid \tilde C^n_1 E^n)_{\rho|\Omega} \geq n h_\alpha - \frac{\alpha}{\alpha-1} \log \frac{1}{p_\Omega}$ gives a finite-size key-rate formula whose single-round term $h_\alpha$ already accounts for marginal constraints.
- Tradeoff functions can be chosen adaptively during the protocol, depending on the public announcements of earlier rounds, matching the adaptivity of quantum probability estimation.
- The strong additivity result $H^{\uparrow}_{\alpha}(E_1 \otimes E_2, X_1X_2, [\psi \otimes \phi]) = H^{\uparrow}_{\alpha}(E_1, X_1, [\psi]) + H^{\uparrow}_{\alpha}(E_2, X_2, [\phi])$ holds for all $\alpha \in [1, \infty]$.
- Security proofs for prepare-and-measure QKD can be run without the repetition-rate restrictions of earlier generalized entropy accumulation approaches.
Reading between the lines
- A natural test is to implement Lemma 4.10 numerically for a small measurement channel; if the purified f-weighted entropy is not convex in the input marginal for some $\alpha \geq 1$, the dual formulation of $h_\alpha$ would need a different proof, though the chain rule itself could survive.
- The appendix's counterexample suggests that unifying MEAT with the secret-memory-register capabilities of generalized entropy accumulation requires a genuinely new non-signalling chain rule, not a cosmetic modification of the existing one.
- The same chain rule may be usable outside QKD, for example to derive single-letter bounds for channel capacities under marginal constraints, since the quantity is additive across tensor products.
- A testable extension would be to allow separable, rather than product, global input marginals in Theorems 4.1a through 4.2b; the authors leave this open, and if it holds it would broaden the protocol class further.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper defines a marginal-constrained Rényi channel conditional entropy and proves weak additivity (Lemma 3.1), a duality with minimized channel divergences (Lemma 3.2), and a chain rule for sequential channel composition (Theorem 3.1), yielding strong additivity under tensor products (Corollary 3.3). It then introduces f-weighted Rényi entropies and uses them to prove a marginal-constrained entropy accumulation theorem, in a simplified form (Theorem 4.2a) and a version with secret classical registers (Theorem 4.2b), together with an EAT-style corollary (Corollary 4.1). The final sections give a security-proof application to prepare-and-measure QKD and a set of counterexamples delimiting possible extensions.
Significance. If the results are fully valid, the chain rule in Theorem 3.1 is a substantial new tool: it generalizes known channel-entropy additivity results to a marginal-constrained setting and supports round-dependent marginal constraints and fully adaptive tradeoff functions in entropy accumulation. The paper is commendably explicit about its limitations, including the impossibility of certain naive extensions (Appendix A), and the central chain-rule proof is presented in detail without fitted parameters. However, the advertised MEAT statements rest on a cluster of f-weighted-entropy lemmas whose proofs are deferred to [AHT24], and the load-bearing convexity claim for H^{↑,f} in Lemma 4.10 is not independently established here. These gaps are internal completeness issues rather than disagreements with prior consensus, and they can in principle be repaired by supplying the deferred proofs.
major comments (3)
- [Sec. 4.2, Lemma 4.10] Lemma 4.10 states that after applying a purifying function, H^{↑,f}_α(SC|\tilde C E \tilde E) is convex in the input state ω for α∈[1,∞], but its proof consists only of the sentence that it follows from the same steps as [AHT24, Lemma 4.7]. That referenced lemma concerns the different quantity H^f_α, and the present paper itself notes in the proof of Theorem 4.2b that −H^{↑,f}_α is not convex in f when the secret registers C are present. Lemma 4.10 is load-bearing: Lemma 4.12 uses it to assert joint convexity of the objective in Eq. (120), and the Clark–Duffin strong-duality step then yields the h^{↑}_α formula in Theorem 4.2a and Corollary 4.2. The authors should provide a self-contained proof of Lemma 4.10, or at minimum a precise reduction to [AHT24, Lemma 4.7] that spells out which hypotheses transfer to the H^{↑,f} setting.
- [Sec. 4.1, Lemmas 4.3–4.6, 4.8–4.9] Several lemmas that are used in the proofs of Theorems 4.1a, 4.1b, 4.2a, and 4.2b are asserted without proof: Lemmas 4.4–4.6 and 4.8–4.9 are said to follow by the 'same methodology' as [AHT24], and Lemma 4.3, which is needed for Lemma 4.7, is also only sketched. These are not merely cosmetic omissions: Lemma 4.8 involves delicate sign conditions on the Rényi parameters, and Lemma 4.3 requires constructing a read-and-prepare channel with prescribed entropy values. Since the paper advertises the MEAT as its main cryptographic result, the proof of that result should be verifiable from the manuscript (or from a clearly stated external theorem with all hypotheses checked). I recommend moving these proofs to an appendix or otherwise including them.
- [Sec. 3, Corollary 3.2 and Sec. 4.3, Theorem 4.2b] Corollary 3.2, which is essential for Theorem 3.1, invokes [FFF24, Lemma 29, Eq. (96)] and only asserts without detailed verification that the relevant sets satisfy the required convexity, compactness, permutation-invariance, and O(m) max-divergence conditions. This step converts the measured-Rényi superadditivity of Lemma 3.3 into the regularized sandwiched-Rényi statement, so the verification should be spelled out. Separately, the proof of Theorem 4.2b states that the remainder proceeds in an 'exactly analogous fashion' using properties of H^f_α established in [AHT24]; consequently the full MEAT with nontrivial secret registers C_j is not independently proven in this manuscript. The authors should either provide the full argument or state explicitly which results in [AHT24] are being invoked and confirm that all their hypotheses are satisfied in the present setting.
minor comments (4)
- [Sec. 4.1, Lemma 4.2 proof] In the calculation following Eq. (81), the text says the third line holds by substituting from Eq. (80); this should presumably refer to the assumption in Eq. (79), since Eq. (80) is the statement being proved.
- [Appendix A, Eq. (144)] The expression 2^{(1−α)/α n} is ambiguous; it should be written as 2^{((1−α)/α)n} (or with parentheses) to avoid confusion with 2^{(1−α)/(α n)}.
- [Def. 4.2] The definition of the marginal-constrained convex range depends on unspecified embeddings of output registers into common registers; the text acknowledges this, but a brief explicit example of a valid embedding for the tensor-product case would improve readability.
- [Sec. 5] The index shift between the protocol registers A^n_1 and the theorem registers A^{n−1}_0 is acknowledged in Remark 5.1, but the notation in Protocol 2 and the subsequent channel definition would be easier to follow if the identification were written out explicitly with register names.
Circularity Check
Theorem 4.2a's dual h↑_α rests on Lemma 4.10 whose proof is deferred to a self-cited prior paper; Theorem 3.1 is independently derived.
-
self citation load bearing
[Lemma 4.10 (Sec. 4.2) and Lemma 4.12 (Sec. 4.3), used in Theorem 4.2a]
"The proof follows from the same steps as in Lemma 4.7 in [AHT24]. ... note that for the proof to carry through the same way, one would use the fact that Lemma 4.10 ensures H ↑,f α (S|“CE ‹E)νω is convex in ω."
Lemma 4.12's strong-duality step converts the single-round variational problem into the dual optimization defining h↑_α in Theorem 4.2a, and its proof explicitly relies on Lemma 4.10 for joint convexity in ω. Lemma 4.10 is not proven in this paper; its proof is delegated to Lemma 4.7 of [AHT24], an overlapping-author preprint. The paper itself concedes that the analogous convexity of −H↑,f_α in f is not available when nontrivial C registers are present ('the infima in the definition are in the wrong direction'), so the delegated convexity claim is not a trivial restatement. Thus the simplified advertised bound (Theorem 4.2a and the corresponding part of Corollary 4.2) rests on a load-bearing self-citation chain.
full rationale
The central chain rule Theorem 3.1 is proved in detail from external ingredients (FFF24, MFS+24, DFR20, Tom16) and is not a fitted or self-referential statement; the MEAT bounds are theorems derived from that chain rule and from the AHT24/HB25 framework, not quantities fitted to the final entropy. No self-definitional or fitted-input-as-prediction step appears. The main circularity-related concern is the load-bearing self-citation around Lemma 4.10 and Lemma 4.12: the simplified Theorem 4.2a needs convexity of the purified f-weighted entropy, and the proof is deferred to the same authors' earlier work, with the paper itself noting the analogous convexity direction fails in the presence of secret C registers. This is a real self-citation dependency but does not reduce the paper's main, independently proven chain rule to its inputs; hence a moderate score of 4 is appropriate rather than a higher score.
Assumptions & free parameters
assumptions (7)
- standard math Data processing, conditioning on classical registers, and duality for sandwiched Rényi entropies (Facts 2.1-2.3)
- standard math Superadditivity of measured Rényi divergence under convex compact sets with the stated inclusion conditions (Fact 3.1, Lemmas 22/24 of FFF24)
- standard math Convergence of regularized minimized divergence for permutation-invariant state sets (FFF24 Lemma 29, Eq. (96))
- ad hoc to paper The f-weighted entropy properties H↑,f (Lemmas 4.4-4.6, 4.8, 4.9) hold as stated; proofs deferred to AHT24 by 'same methodology'
- ad hoc to paper Convexity of the purified H↑,f in the input state (Lemma 4.10) and the convex-conjugate duality (Lemma 4.11)
- domain assumption All systems are finite-dimensional
- domain assumption For the QKD security reduction: the source-replacement technique and moving Alice's preparations earlier / announcements later do not reduce Eve's capabilities (Sec 5)
Cite this review
Pith. "Pith review of Marginal-constrained entropy accumulation theorem." pith.science (2026). https://pith.science/paper/YRUCRXUQ
@misc{pith2026250202563,
author = {Pith},
title = {Pith review of: Marginal-constrained entropy accumulation theorem},
year = {2026},
howpublished = {\url{https://pith.science/paper/YRUCRXUQ}},
note = {Machine review of arXiv:2502.02563}
}
read the original abstract
We derive a novel chain rule for a family of channel conditional entropies, covering von Neumann and sandwiched R\'{e}nyi entropies. In the process, we show that these channel conditional entropies are equal to their regularized version, and more generally, additive across tensor products of channels. For the purposes of cryptography, applying our chain rule to sequences of channels yields a new variant of R\'{e}nyi entropy accumulation, in which we can impose some specific forms of marginal-state constraint on the input states to each individual channel. This generalizes a recently introduced security proof technique that was developed to analyze prepare-and-measure QKD with no limitations on the repetition rate. In particular, our generalization yields ``fully adaptive'' protocols that can in principle update the entropy estimation procedure during the protocol itself, similar to the quantum probability estimation framework.
Forward citations
Cited by 3 Pith papers
-
Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography
Exact analytic Rényi entropy rate functions for the CHSH inequality tighten finite-size DIQKD key rates and reduce the minimum number of rounds by nearly a factor of three.
-
Enforcing IID structure on time-bin encoded QKD protocols via coarse-graining
Discarding detectors that sense inter-round coherence recovers a tensor-product Bob measurement POVM for time-bin QKD, removing the vacuum-pulse fix and its rate penalty.
-
Security proofs for practical QKD: variations, techniques, gaps, and limitations
A critical review of decoy-state BB84 security proofs identifies common gaps and shows that no current proof meets the full standard of completeness, modularity, and verifiability.
Reference graph
Works this paper leans on
-
[1]
[AC97] C. Adami and N. J. Cerf. von Neumann capacity of noisy quantum channels. Phys. Rev. A 56 (1997), pp. 3470–3483. [AHT24] A. Arqand, T. A. Hahn, and E. Y. -Z. Tan. Generalized R´ enyi entropy accumulation theorem and generalized quantum probability estimation. arXiv:2405.05912v4 (2024). [BCG+24] A. Bluhm, ´Angela Capel, P. Gondolf, and T. M¨ obus.Uni...
arXiv 1997
-
[5]
arXiv: 2410.01740 [quant-ph]. [DJK+06] I. Devetak, M. Junge, C. King, and M. B. Ruskai. Multiplicativity of Completely Bounded p-Norms Implies a New Additivity Result. Commun. Math. Phys. 266.1 (2006), pp. 37–63. issn: 1432-0916. [Duf78] R. J. Duffin. Clark’s Theorem on linear programs holds for convex programs. Proceed- ings of the National Academy of Sc...
arXiv 2006
-
[8]
arXiv: 2403.12947 [quant-ph]. [TBH14] M. Tomamichel, M. Berta, and M. Hayashi. Relating different quantum generalizations of the conditional R´ enyi entropy.Journal of Mathematical Physics 55.8 (2014). issn: 1089-7658. 43 [TL17] M. Tomamichel and A. Leverrier. A largely self-contained and complete security proof for quantum key distribution. Quantum 1 (2017), p
arXiv 2014
-
[2004]
[CLL04] M. Curty, M. Lewenstein, and N. L¨ utkenhaus. Entanglement as a Precondition for Secure Quantum Key Distribution. Phys. Rev. Lett. 92.21 (2004), p. 217903. [Dav07] E. B. Davies. Linear Operators and their Spectra . Cambridge, England, UK: Cam- bridge University Press,
work page 2004
-
[2005]
[Sho02] P. W. Shor. Additivity of the classical capacity of entanglement-breaking quantum channels. J. Math. Phys. 43.9 (2002), pp. 4334–4340. issn: 0022-2488. [SPS+24] Sohail, V. Pandey, U. Singh, and S. Das.Fundamental limitations on the recoverability of quantum processes
work page 2002
-
[2007]
isbn: 978-0-52186629-3. [DF19] F. Dupuis and O. Fawzi. Entropy accumulation with improved second-order term. IEEE Transactions on Information Theory (2019), pp. 1–1. issn: 0018-9448. [DFR20] F. Dupuis, O. Fawzi, and R. Renner. Entropy Accumulation. Communications in Mathematical Physics 379.3 (2020), pp. 867–913. [DGP24] S. Das, K. Goswami, and V. Pandey....
work page 2019
-
[2016]
[WWY14] M. M. Wilde, A. Winter, and D. Yang. Strong Converse for the Classical Capacity of Entanglement-Breaking and Hadamard Channels via a Sandwiched R´ enyi Relative Entropy. Commun. Math. Phys. 331.2 (2014), pp. 593–622. issn: 1432-0916. [Yua19] X. Yuan. Hypothesis testing and entropies of quantum channels. Phys. Rev. A 99.3 (2019), p. 032317. [ZFK20]...
work page 2014
-
[2024]
arXiv: 2308.12425 [quant-ph]. [Bei13] S. Beigi. Sandwiched R´ enyi divergence satisfies data processing inequality.Journal of Mathematical Physics 54.12 (2013). issn: 1089-7658. [BPGW+24] S. B¨ auml, C. Pascual-Garc ´ ıa, V. Wright, O. Fawzi, and A. Ac ´ ın. Security of discrete- modulated continuous-variable quantum key distribution. Quantum 8 (2024), p
arXiv 2013
Show all 9 references
-
[2025]
[Kin03] C. King. The capacity of the quantum depolarizing channel. IEEE Transactions on Information Theory 49.1 (2003), pp. 221–229. [KMN+05] C. King, K. Matsumoto, M. Nathanson, and M. B. Ruskai. Properties of Conjugate Channels with Applications to Additivity and Multiplicat...
2003 arXiv
Reviewed August 9, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.