Pith. sign in

REVIEW 3 major objections 4 minor 3 cited by

Marginal-constrained entropy accumulation theorem

T0 review · 3 major / 4 minor · reviewed 2026-08-09 · deepseek-v4-flash

Pith's one-line read The paper proves a chain rule for marginal-constrained quantum channel entropies and derives a new entropy accumulation theorem whose single-round bounds can carry different input-marginal constraints per round, enabling fully adaptive…

desk verdict The chain rule and strong additivity are solid and genuinely new, but the headline MEAT statement leans on an unproven convexity lemma that the paper itself flags as suspect; worth refereeing, but the gap needs to be closed. read the letter →

arxiv 2502.02563 v4 pith:YRUCRXUQ submitted 2025-02-04 quant-ph

classification quant-ph PACS 03.67.Dd
keywords entropyaccumulationtheoremchannelconditionalRényichainrulequantumkeydistributionmarginalconstraintsfullyadaptiveprotocolsf-weighted
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper establishes a chain rule for a family of quantum channel conditional entropies built from sandwiched Rényi divergences, with optional constraints on the channel's input marginal state. The chain rule says that composing two channels cannot produce less conditional entropy than the sum of the two channel entropies evaluated separately, provided the joint input state has the prescribed product marginal. From this, the authors prove strong additivity across tensor products and a marginal-constrained entropy accumulation theorem (MEAT) that bounds the Rényi entropy of the final state conditioned on an accept event by a single-round infimum times n, minus a penalty for the event probability. The point, for cryptography, is that security proofs for prepare-and-measure quantum key distribution no longer need an identical-round, repetition-rate-restricted model: each round can have its own marginal constraint, and the estimation procedure can be updated adaptively based on public announcements.

What carries the argument

The load-bearing object is the marginal-constrained Rényi channel conditional entropy, $H^{\uparrow}_{\alpha}(M, B, [\psi_A]) := \inf_{\rho: \rho_A = \psi_A} H^{\uparrow}_{\alpha}(B \mid C \tilde R)_{M[\rho]}$, defined with a stabilizing register and an optional constraint on the input marginal. The proof route goes through weak additivity, a duality between channel conditional entropy and minimized channel divergence, superadditivity of measured Rényi divergence proven by dual SDPs, and a regularization argument that lifts measured divergences to sandwiched divergences. For the accumulation theorem, the machinery is completed by f-weighted Rényi entropies and a purifying function, whose convexity (Lemma 4.10) enables a Clark-Duffin strong-duality step (Lemma 4.12) that converts the single-round optimization $h_\alpha$ into a tractable dual form.

What would settle it

Take a fixed read-and-prepare channel and two input marginals $\omega^0_A$ and $\omega^1_A$, and compare the purified f-weighted entropy $H^{\uparrow,f}_{\alpha}(SC \mid \tilde C E \tilde E)_{M[\mathrm{Pur}(\omega_A)]}$ at the mixture $(\omega^0_A+\omega^1_A)/2$ with the average of its values at the two endpoints for $\alpha \geq 1$; any dip below the average would invalidate Lemma 4.10 and the dual step behind $h_\alpha$. The same test restricted to the secret-register case would directly probe the gap the paper flags when it says convexity in $f$ fails there.

Watch

Extended reading notes

Core claim

The central discovery, stated as Theorem 3.1, is that for $\alpha \in [1, \infty]$ the marginal-constrained channel conditional entropy is superadditive under channel composition: $H^{\uparrow}_{\alpha}(E_2 \circ E_1, X_1X_2, [\psi_{A_0} \otimes \phi_{A_1}]) \geq H^{\uparrow}_{\alpha}(E_2, X_2, [\phi_{A_1}]) + H^{\uparrow}_{\alpha}(E_1, X_1, [\psi_{A_0}])$. As a consequence, the quantity is equal to its regularized version and additive across tensor products. Feeding this chain rule into the f-weighted entropy machinery of prior QKD analysis produces the marginal-constrained entropy accumulation theorem (Theorem 4.2b), which bounds $H^{\uparrow}_{\alpha}(S^n_1 C^n_1 \mid \tilde C^n_1 E^n)_{\rho|\Omega} \geq n h_\alpha - \frac{\alpha}{\alpha-1} \log \frac{1}{p_\Omega}$, where $h_\alpha$ is an infimum over single-round states compatible with the marginal constraints. This is the first entropy accumulation bound of this family that allows each round to carry its own input-marginal constraints and fully adaptive tradeoff functions.

Load-bearing premise

The bound collapses if the single-round f-weighted entropy, after purification, is not a convex function of the input marginal state; the paper defers that convexity proof to an earlier work and notes that a closely related convexity statement fails when secret registers are present.

Editorial extensions

If this is right

  • If the chain rule is correct, a QKD protocol can be analyzed with a different input-marginal constraint in every round, so source-replacement security proofs do not require identical rounds.
  • The accumulation bound $H^{\uparrow}_{\alpha}(S^n_1 C^n_1 \mid \tilde C^n_1 E^n)_{\rho|\Omega} \geq n h_\alpha - \frac{\alpha}{\alpha-1} \log \frac{1}{p_\Omega}$ gives a finite-size key-rate formula whose single-round term $h_\alpha$ already accounts for marginal constraints.
  • Tradeoff functions can be chosen adaptively during the protocol, depending on the public announcements of earlier rounds, matching the adaptivity of quantum probability estimation.
  • The strong additivity result $H^{\uparrow}_{\alpha}(E_1 \otimes E_2, X_1X_2, [\psi \otimes \phi]) = H^{\uparrow}_{\alpha}(E_1, X_1, [\psi]) + H^{\uparrow}_{\alpha}(E_2, X_2, [\phi])$ holds for all $\alpha \in [1, \infty]$.
  • Security proofs for prepare-and-measure QKD can be run without the repetition-rate restrictions of earlier generalized entropy accumulation approaches.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural test is to implement Lemma 4.10 numerically for a small measurement channel; if the purified f-weighted entropy is not convex in the input marginal for some $\alpha \geq 1$, the dual formulation of $h_\alpha$ would need a different proof, though the chain rule itself could survive.
  • The appendix's counterexample suggests that unifying MEAT with the secret-memory-register capabilities of generalized entropy accumulation requires a genuinely new non-signalling chain rule, not a cosmetic modification of the existing one.
  • The same chain rule may be usable outside QKD, for example to derive single-letter bounds for channel capacities under marginal constraints, since the quantity is additive across tensor products.
  • A testable extension would be to allow separable, rather than product, global input marginals in Theorems 4.1a through 4.2b; the authors leave this open, and if it holds it would broaden the protocol class further.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper defines a marginal-constrained Rényi channel conditional entropy and proves weak additivity (Lemma 3.1), a duality with minimized channel divergences (Lemma 3.2), and a chain rule for sequential channel composition (Theorem 3.1), yielding strong additivity under tensor products (Corollary 3.3). It then introduces f-weighted Rényi entropies and uses them to prove a marginal-constrained entropy accumulation theorem, in a simplified form (Theorem 4.2a) and a version with secret classical registers (Theorem 4.2b), together with an EAT-style corollary (Corollary 4.1). The final sections give a security-proof application to prepare-and-measure QKD and a set of counterexamples delimiting possible extensions.

Significance. If the results are fully valid, the chain rule in Theorem 3.1 is a substantial new tool: it generalizes known channel-entropy additivity results to a marginal-constrained setting and supports round-dependent marginal constraints and fully adaptive tradeoff functions in entropy accumulation. The paper is commendably explicit about its limitations, including the impossibility of certain naive extensions (Appendix A), and the central chain-rule proof is presented in detail without fitted parameters. However, the advertised MEAT statements rest on a cluster of f-weighted-entropy lemmas whose proofs are deferred to [AHT24], and the load-bearing convexity claim for H^{↑,f} in Lemma 4.10 is not independently established here. These gaps are internal completeness issues rather than disagreements with prior consensus, and they can in principle be repaired by supplying the deferred proofs.

major comments (3)
  1. [Sec. 4.2, Lemma 4.10] Lemma 4.10 states that after applying a purifying function, H^{↑,f}_α(SC|\tilde C E \tilde E) is convex in the input state ω for α∈[1,∞], but its proof consists only of the sentence that it follows from the same steps as [AHT24, Lemma 4.7]. That referenced lemma concerns the different quantity H^f_α, and the present paper itself notes in the proof of Theorem 4.2b that −H^{↑,f}_α is not convex in f when the secret registers C are present. Lemma 4.10 is load-bearing: Lemma 4.12 uses it to assert joint convexity of the objective in Eq. (120), and the Clark–Duffin strong-duality step then yields the h^{↑}_α formula in Theorem 4.2a and Corollary 4.2. The authors should provide a self-contained proof of Lemma 4.10, or at minimum a precise reduction to [AHT24, Lemma 4.7] that spells out which hypotheses transfer to the H^{↑,f} setting.
  2. [Sec. 4.1, Lemmas 4.3–4.6, 4.8–4.9] Several lemmas that are used in the proofs of Theorems 4.1a, 4.1b, 4.2a, and 4.2b are asserted without proof: Lemmas 4.4–4.6 and 4.8–4.9 are said to follow by the 'same methodology' as [AHT24], and Lemma 4.3, which is needed for Lemma 4.7, is also only sketched. These are not merely cosmetic omissions: Lemma 4.8 involves delicate sign conditions on the Rényi parameters, and Lemma 4.3 requires constructing a read-and-prepare channel with prescribed entropy values. Since the paper advertises the MEAT as its main cryptographic result, the proof of that result should be verifiable from the manuscript (or from a clearly stated external theorem with all hypotheses checked). I recommend moving these proofs to an appendix or otherwise including them.
  3. [Sec. 3, Corollary 3.2 and Sec. 4.3, Theorem 4.2b] Corollary 3.2, which is essential for Theorem 3.1, invokes [FFF24, Lemma 29, Eq. (96)] and only asserts without detailed verification that the relevant sets satisfy the required convexity, compactness, permutation-invariance, and O(m) max-divergence conditions. This step converts the measured-Rényi superadditivity of Lemma 3.3 into the regularized sandwiched-Rényi statement, so the verification should be spelled out. Separately, the proof of Theorem 4.2b states that the remainder proceeds in an 'exactly analogous fashion' using properties of H^f_α established in [AHT24]; consequently the full MEAT with nontrivial secret registers C_j is not independently proven in this manuscript. The authors should either provide the full argument or state explicitly which results in [AHT24] are being invoked and confirm that all their hypotheses are satisfied in the present setting.
minor comments (4)
  1. [Sec. 4.1, Lemma 4.2 proof] In the calculation following Eq. (81), the text says the third line holds by substituting from Eq. (80); this should presumably refer to the assumption in Eq. (79), since Eq. (80) is the statement being proved.
  2. [Appendix A, Eq. (144)] The expression 2^{(1−α)/α n} is ambiguous; it should be written as 2^{((1−α)/α)n} (or with parentheses) to avoid confusion with 2^{(1−α)/(α n)}.
  3. [Def. 4.2] The definition of the marginal-constrained convex range depends on unspecified embeddings of output registers into common registers; the text acknowledges this, but a brief explicit example of a valid embedding for the tensor-product case would improve readability.
  4. [Sec. 5] The index shift between the protocol registers A^n_1 and the theorem registers A^{n−1}_0 is acknowledged in Remark 5.1, but the notation in Protocol 2 and the subsequent channel definition would be easier to follow if the identification were written out explicitly with register names.

Circularity Check

1 steps flagged · score 4.0 of 10

Theorem 4.2a's dual h↑_α rests on Lemma 4.10 whose proof is deferred to a self-cited prior paper; Theorem 3.1 is independently derived.

  1. self citation load bearing [Lemma 4.10 (Sec. 4.2) and Lemma 4.12 (Sec. 4.3), used in Theorem 4.2a]
    "The proof follows from the same steps as in Lemma 4.7 in [AHT24]. ... note that for the proof to carry through the same way, one would use the fact that Lemma 4.10 ensures H ↑,f α (S|“CE ‹E)νω is convex in ω."

    Lemma 4.12's strong-duality step converts the single-round variational problem into the dual optimization defining h↑_α in Theorem 4.2a, and its proof explicitly relies on Lemma 4.10 for joint convexity in ω. Lemma 4.10 is not proven in this paper; its proof is delegated to Lemma 4.7 of [AHT24], an overlapping-author preprint. The paper itself concedes that the analogous convexity of −H↑,f_α in f is not available when nontrivial C registers are present ('the infima in the definition are in the wrong direction'), so the delegated convexity claim is not a trivial restatement. Thus the simplified advertised bound (Theorem 4.2a and the corresponding part of Corollary 4.2) rests on a load-bearing self-citation chain.

full rationale

The central chain rule Theorem 3.1 is proved in detail from external ingredients (FFF24, MFS+24, DFR20, Tom16) and is not a fitted or self-referential statement; the MEAT bounds are theorems derived from that chain rule and from the AHT24/HB25 framework, not quantities fitted to the final entropy. No self-definitional or fitted-input-as-prediction step appears. The main circularity-related concern is the load-bearing self-citation around Lemma 4.10 and Lemma 4.12: the simplified Theorem 4.2a needs convexity of the purified f-weighted entropy, and the proof is deferred to the same authors' earlier work, with the paper itself noting the analogous convexity direction fails in the presence of secret C registers. This is a real self-citation dependency but does not reduce the paper's main, independently proven chain rule to its inputs; hence a moderate score of 4 is appropriate rather than a higher score.

Assumptions & free parameters 0 free parameters · 7 assumptions · 0 invented entities

The paper's core chain rule relies on standard convex optimization and quantum information facts plus two external theorems from FFF24. The MEAT results additionally import unproved f-weighted entropy lemmas from the authors' prior work AHT24, including a convexity claim specific to the H↑,f variant. The QKD application adds physical modeling assumptions (source-replacement and a timing shift) that are standard but unverified in experiment.

assumptions (7)
  • standard math Data processing, conditioning on classical registers, and duality for sandwiched Rényi entropies (Facts 2.1-2.3)
    Background results from Tomamichel et al. and Müller-Lennert et al., invoked throughout.
  • standard math Superadditivity of measured Rényi divergence under convex compact sets with the stated inclusion conditions (Fact 3.1, Lemmas 22/24 of FFF24)
    External result used in Lemma 3.3 to prove Lemma 3.3.
  • standard math Convergence of regularized minimized divergence for permutation-invariant state sets (FFF24 Lemma 29, Eq. (96))
    Used in Corollary 3.2 to pass from m-round superadditivity to regularized superadditivity.
  • ad hoc to paper The f-weighted entropy properties H↑,f (Lemmas 4.4-4.6, 4.8, 4.9) hold as stated; proofs deferred to AHT24 by 'same methodology'
    These lemmas are new variants based on H↑ rather than H, and the text does not prove them.
  • ad hoc to paper Convexity of the purified H↑,f in the input state (Lemma 4.10) and the convex-conjugate duality (Lemma 4.11)
    Load-bearing for strong duality in Theorem 4.2a; only a proof sketch referencing AHT24 is given.
  • domain assumption All systems are finite-dimensional
    Stated in Sec 2; needed for compactness and SDP strong duality.
  • domain assumption For the QKD security reduction: the source-replacement technique and moving Alice's preparations earlier / announcements later do not reduce Eve's capabilities (Sec 5)
    This bridges the abstract MEAT to prepare-and-measure protocols; physically reasonable but not proven within the paper.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Marginal-constrained entropy accumulation theorem." pith.science (2026). https://pith.science/paper/YRUCRXUQ

@misc{pith2026250202563,
  author       = {Pith},
  title        = {Pith review of: Marginal-constrained entropy accumulation theorem},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YRUCRXUQ}},
  note         = {Machine review of arXiv:2502.02563}
}
read the original abstract

We derive a novel chain rule for a family of channel conditional entropies, covering von Neumann and sandwiched R\'{e}nyi entropies. In the process, we show that these channel conditional entropies are equal to their regularized version, and more generally, additive across tensor products of channels. For the purposes of cryptography, applying our chain rule to sequences of channels yields a new variant of R\'{e}nyi entropy accumulation, in which we can impose some specific forms of marginal-state constraint on the input states to each individual channel. This generalizes a recently introduced security proof technique that was developed to analyze prepare-and-measure QKD with no limitations on the repetition rate. In particular, our generalization yields ``fully adaptive'' protocols that can in principle update the entropy estimation procedure during the protocol itself, similar to the quantum probability estimation framework.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography

    quant-ph 2025-07 conditional novelty 7.0 of 10

    Exact analytic Rényi entropy rate functions for the CHSH inequality tighten finite-size DIQKD key rates and reduce the minimum number of rounds by nearly a factor of three.

  2. Enforcing IID structure on time-bin encoded QKD protocols via coarse-graining

    quant-ph 2026-07 accept novelty 6.0 of 10

    Discarding detectors that sense inter-round coherence recovers a tensor-product Bob measurement POVM for time-bin QKD, removing the vacuum-pulse fix and its rate penalty.

  3. Security proofs for practical QKD: variations, techniques, gaps, and limitations

    quant-ph 2025-02 accept novelty 6.0 of 10

    A critical review of decoy-state BB84 security proofs identifies common gaps and shows that no current proof meets the full standard of completeness, modularity, and verifiability.

Reference graph

Works this paper leans on

9 extracted references · 4 canonical work pages · cited by 3 Pith papers

  1. [1]

    Adami and N

    [AC97] C. Adami and N. J. Cerf. von Neumann capacity of noisy quantum channels. Phys. Rev. A 56 (1997), pp. 3470–3483. [AHT24] A. Arqand, T. A. Hahn, and E. Y. -Z. Tan. Generalized R´ enyi entropy accumulation theorem and generalized quantum probability estimation. arXiv:2405.05912v4 (2024). [BCG+24] A. Bluhm, ´Angela Capel, P. Gondolf, and T. M¨ obus.Uni...

  2. [5]

    [DJK+06] I

    arXiv: 2410.01740 [quant-ph]. [DJK+06] I. Devetak, M. Junge, C. King, and M. B. Ruskai. Multiplicativity of Completely Bounded p-Norms Implies a New Additivity Result. Commun. Math. Phys. 266.1 (2006), pp. 37–63. issn: 1432-0916. [Duf78] R. J. Duffin. Clark’s Theorem on linear programs holds for convex programs. Proceed- ings of the National Academy of Sc...

  3. [8]

    [TBH14] M

    arXiv: 2403.12947 [quant-ph]. [TBH14] M. Tomamichel, M. Berta, and M. Hayashi. Relating different quantum generalizations of the conditional R´ enyi entropy.Journal of Mathematical Physics 55.8 (2014). issn: 1089-7658. 43 [TL17] M. Tomamichel and A. Leverrier. A largely self-contained and complete security proof for quantum key distribution. Quantum 1 (2017), p

  4. [2004]

    Curty, M

    [CLL04] M. Curty, M. Lewenstein, and N. L¨ utkenhaus. Entanglement as a Precondition for Secure Quantum Key Distribution. Phys. Rev. Lett. 92.21 (2004), p. 217903. [Dav07] E. B. Davies. Linear Operators and their Spectra . Cambridge, England, UK: Cam- bridge University Press,

  5. [2005]

    [Sho02] P. W. Shor. Additivity of the classical capacity of entanglement-breaking quantum channels. J. Math. Phys. 43.9 (2002), pp. 4334–4340. issn: 0022-2488. [SPS+24] Sohail, V. Pandey, U. Singh, and S. Das.Fundamental limitations on the recoverability of quantum processes

  6. [2007]

    [DF19] F

    isbn: 978-0-52186629-3. [DF19] F. Dupuis and O. Fawzi. Entropy accumulation with improved second-order term. IEEE Transactions on Information Theory (2019), pp. 1–1. issn: 0018-9448. [DFR20] F. Dupuis, O. Fawzi, and R. Renner. Entropy Accumulation. Communications in Mathematical Physics 379.3 (2020), pp. 867–913. [DGP24] S. Das, K. Goswami, and V. Pandey....

  7. [2016]

    sub-register

    [WWY14] M. M. Wilde, A. Winter, and D. Yang. Strong Converse for the Classical Capacity of Entanglement-Breaking and Hadamard Channels via a Sandwiched R´ enyi Relative Entropy. Commun. Math. Phys. 331.2 (2014), pp. 593–622. issn: 1432-0916. [Yua19] X. Yuan. Hypothesis testing and entropies of quantum channels. Phys. Rev. A 99.3 (2019), p. 032317. [ZFK20]...

  8. [2024]

    [Bei13] S

    arXiv: 2308.12425 [quant-ph]. [Bei13] S. Beigi. Sandwiched R´ enyi divergence satisfies data processing inequality.Journal of Mathematical Physics 54.12 (2013). issn: 1089-7658. [BPGW+24] S. B¨ auml, C. Pascual-Garc ´ ıa, V. Wright, O. Fawzi, and A. Ac ´ ın. Security of discrete- modulated continuous-variable quantum key distribution. Quantum 8 (2024), p

Show all 9 references
  1. [2025]

    [Kin03] C. King. The capacity of the quantum depolarizing channel. IEEE Transactions on Information Theory 49.1 (2003), pp. 221–229. [KMN+05] C. King, K. Matsumoto, M. Nathanson, and M. B. Ruskai. Properties of Conjugate Channels with Applications to Additivity and Multiplicat...

Pith tools

Reviewed August 9, 2026 · model on record in the stance chip above.