{"id":"8c4a82ca-b235-40a3-b49e-057bbb7dd484","arxiv_id":"1908.01271","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"PM-QKD experiment surpasses the linear rate-transmittance bound at 302 and 402 km, and achieves a positive key rate at 502 km.","lead":"An experiment demonstrates a quantum key distribution protocol that beats the traditional linear rate-loss limit, securing keys over 302, 402, and 502 km of optical fiber. The result could extend the practical range of unbreakable encryption without quantum repeaters.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The claimed margin over the PLOB bound rests on an unpublished finite-size proof; the one bound given in Appendix E, Eq. (E6), has the inequality reversed, so the secure-key estimate is not self-contained.","rationale":"The experiment itself appears well characterized: detailed tables of counts, decoy settings, detector efficiencies, and finite-size failure probabilities are provided, and the qualitative scaling \\(O(\\sqrt{\\eta})\\) is supported by the data. So the concern is not about experimental honesty or equipment. The issue is that the headline claim is a security claim: a key rate only 'surpasses the linear bound' if the number reported is actually a lower bound on the secret key. That requires a finite-size security proof for the exact protocol run, including the phase post-compensation sifting and the reuse of mismatched-phase groups. The preprint defers this proof to Ref. [24]. The internal formula that is supplied, Eq. (E6), has a clear inequality-direction problem; whether it is a typo or a substantive error cannot be decided from the preprint alone. Because the entire surplus over the PLOB bound at 302 km comes from the phase-mismatched groups (aligned-only rate is below the bound), the missing proof is load-bearing. The reader's CONDITIONAL verdict is appropriate: the paper should not be fully accepted until the companion paper is released or the proof is included. If the corrected calculation still exceeds the bound, the central claim stands; if not, the paper's main conclusion does not. I therefore recommend no change to the reader's verdict, while flagging that the concern is concrete and checkable, not merely a request for more detail.","tokens_in":16568,"tokens_out":19360,"duration_ms":217398,"concrete_test":"Obtain and independently verify the companion finite-size security analysis (Ref. [24]). As part of that check, re-derive Eq. (E6): confirm whether it should be \\(M_{\\rm even}\\le 1-M_1\\) and confirm that a maliciously chosen \\(j_\\delta\\) cannot bias the groups \\(j_s\\). Then recompute the 302 km key rate using the conservative upper bound \\(q_{\\rm even}\\le 1-M_1^L/M^{(J)}\\) (or the correct decoy-state bound) and compare with \\(R_{\\rm PLOB}=5.44\\times10^{-7}\\). If the corrected rate drops below the PLOB bound, the headline claim fails; if it remains above, the printed inequality is only a typographical error and the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that the measured key rates are secure and exceed the PLOB linear bound. The preprint does not contain the proof needed to certify this. Appendix E states that 'the detailed finite-size security analysis of PM-QKD is in Ref. [24]', an unpublished companion paper, and the supplied formulas are not sufficient. Concretely, Eq. (E6) asserts \\(M_{\\rm even}=1-\\sum_{k\\rm\\ odd}M_k \\ge 1-M_1\\). Since \\(M_1\\) is one of the odd contributions, \\(\\sum_{k\\rm\\ odd}M_k\\ge M_1\\), so the correct direction is \\(M_{\\rm even}\\le 1-M_1\\). As printed, a lower bound on the single-photon term would be turned into a lower bound on the even (tagged) fraction, which would overestimate the secret key rather than conservatively bounding it. Moreover, the 24% margin at 302 km disappears if the phase-mismatched groups are not used: Table II gives aligned key length 7,809,030 versus total 13,479,300, so the aligned-only rate \\(3.90\\times10^{-7}\\) is below \\(R_{\\rm PLOB}=5.44\\times10^{-7}\\). The security of the mismatched-phase grouping, including the untrusted announcement \\(j_\\delta\\) in the phase post-compensation sifting, is asserted without proof ('the sifting strategy does not affect the security of PM-QKD'). Thus the claim depends entirely on a missing security proof and on a formula that, as written, is not valid.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an experimental implementation of phase-matching quantum key distribution (PM-QKD) over 101, 201, 302, 402 km standard fibre and 502 km ultralow-loss fibre, using laser injection for phase stabilization and a phase post-compensation sifting method. The headline claims are that the finite-size secret key rate exceeds the PLOB linear rate-transmittance bound at 302 km and 402 km, reaching 6.74e-7 bps at 302 km (24.0% above the bound) and 0.118 bps at 502 km. The key-rate formula is taken from the asymptotic PM-QKD security analysis of Ref. [13], while the finite-size parameter estimation is given as a collection of formulas in Appendix E, with the full finite-size security proof deferred to an unpublished companion paper, Ref. [24].","tokens_in":16952,"tokens_out":5755,"duration_ms":61761,"significance":"If the finite-size security proof and the security of the phase post-compensation sifting are valid, this is an important experimental result: it would be the first demonstration of a QKD key rate surpassing the linear rate-transmittance bound, and the 502 km result would extend the fibre QKD distance record. The manuscript has genuine strengths: the protocol is specified in Box 1, the experimental setup is described in unusual detail in Appendices A-D, extensive raw-data tables are provided, and the comparison with the PLOB bound is explicit. The asymptotic security basis in the published PRX paper (Ref. [13]) is legitimate support. However, the central quantitative claim is not self-contained: the finite-size proof is missing, and one of the few printed finite-size bounds has the wrong inequality direction. As a result, the current version does not yet establish the headline rate-transmittance claim.","major_comments":[{"comment":"Equation (E6) states \\(M_{\\rm even}=1-\\sum_{k\\ {\\rm odd}}M_k \\ge 1-M_1\\). Since \\(M_1\\) is itself one of the odd contributions, \\(\\sum_{k\\ {\\rm odd}}M_k \\ge M_1\\), so the correct implication is \\(M_{\\rm even}\\le 1-M_1\\). As printed, a lower bound on the single-photon clicked number is converted into a lower bound on the even-photon (tagged) fraction. When used in Eqs. (E1)-(E2), this would underestimate the privacy leakage and overestimate the secure key length. This is load-bearing because the 24% margin over the PLOB bound at 302 km is computed from the finite-size key estimate. The inequality direction must be corrected and the numerical key rates in Table II re-checked.","section":"Appendix E, Eq. (E6)"},{"comment":"The finite-size security analysis is not contained in the manuscript. The first paragraph of Appendix E states that 'the detailed finite-size security analysis of PM-QKD is in Ref. [24]', and Ref. [24] is listed as 'Under preparation'. The central claim of the paper is that the measured finite-size key rates are secure and exceed the PLOB bound; this claim rests entirely on the missing analysis. The formulas in Appendix E (Chernoff bounds, decoy-state estimates, and the quoted failure probability \\(\\epsilon\\)) are stated without proof and do not by themselves constitute a composable finite-size security statement. A publishable version must include the complete finite-size security proof, with explicit failure probabilities for parameter estimation, error correction, and privacy amplification, or must replace the citation to the unpublished companion paper with a publicly available and refereed proof.","section":"Appendix E, first paragraph"},{"comment":"The phase post-compensation sifting uses the shift \\(j_\\delta\\), estimated from strong reference pulses transmitted through the untrusted channel and announced by Eve. The manuscript asserts, without proof, that 'the sifting strategy does not affect the security of PM-QKD' (Appendix C). This is load-bearing: at 302 km, Table II reports an aligned key length of 7,809,030 and a total key length of 13,479,300. With \\(N=2.000\\times10^{13}\\) sending rounds, the aligned-only key rate is \\(7.809\\times10^6/2.000\\times10^{13}=3.90\\times10^{-7}\\), which is below the PLOB value \\(5.44\\times10^{-7}\\). Thus the claimed surpassing of the linear bound depends on including the phase-mismatched groups and on the unproven compatibility of the \\(j_\\delta\\)-based sifting with the PM-QKD security proof. The security analysis must cover the public announcement of \\(j_\\delta\\), the grouping of \\(j_s\\) and \\(j_s+D/2\\), and the joint privacy amplification over the retained groups, or the central claim is unsupported.","section":"Main text after Eq. (1), Box 1, and Appendix C"}],"minor_comments":[{"comment":"The abstract contains a typo: 'Quantum key distribution (QKD offers' is missing the closing parenthesis after 'QKD'.","section":"Abstract"},{"comment":"The Chernoff bound formulas in Eqs. (E11)-(E15) are presented as a recipe, but the relation between the Gaussian-approximation parameter \\(n_\\alpha\\) and the quoted failure probabilities is not stated. Please define how \\(n_\\alpha=7\\) (Table I) leads to the reported \\(\\epsilon\\approx1.7\\times10^{-10}\\).","section":"Appendix E, Sec. 3"},{"comment":"The column headers 'Channel loss' and 'Total loss(double side)' appear to list transmittances rather than losses; for example, the values decrease with distance. Please clarify the definitions and units so that the PLOB bound comparison is unambiguous.","section":"Table II"},{"comment":"A reference listed as 'Under preparation' cannot serve as the basis for the central finite-size security claim; it should be replaced by a published or otherwise publicly verifiable source, or the proof should be included in the manuscript.","section":"Reference [24]"}],"recommendation":"major_revision","confidential_remarks":"The paper is likely to attract wide attention if the finite-size proof holds, but the editor should require the companion security proof to be available and should verify the direction of Eq. (E6) before publication. The current reliance on an unpublished companion paper for the headline claim is a significant publication-readiness concern, though it is fixable within the scope of a revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Hi [Name],\n\nThe experiment is real and the engineering is impressive. Fang et al. demonstrate PM-QKD with injection-locked lasers and phase post-compensation, and they get positive key rates out to 502 km. The data tables are unusually complete, and the bit-error-rate stability plots are credible. This is the kind of implementation the PM-QKD line of theory has been waiting for.\n\nBut I would not let the PLOB-beating claim stand on this preprint alone. The finite-size security analysis is deferred to an unpublished companion paper (Ref [24]), and the one piece of that analysis printed in Appendix E is wrong as written. Eq. (E6) reads M_even = 1 - sum_{odd} M_k >= 1 - M_1. Since M_1 is part of the odd sum, the correct inequality is M_even <= 1 - M_1. As printed, it would turn a lower bound on single-photon contributions into a lower bound on the tagged fraction, overestimating the secure key. That is exactly the direction that matters for a margin claim.\n\nThe margin is also thinner than the abstract suggests. At 302 km, the total key rate is 6.74e-7, 24% above the 5.44e-7 PLOB bound. But the aligned-only key length (7,809,030 bits) gives 3.90e-7, below the bound. The surplus comes from the mismatched-phase groups, and the security of using those groups—including the announced phase-compensation shift j_delta—is asserted without proof (\"the sifting strategy does not affect the security of PM-QKD\"). Maybe that's true, but it's not demonstrated here.\n\nWhat is genuinely new is the implementation: laser injection to lock two remote DFB lasers, the post-compensation sifting, and the record 502 km loss budget. The protocol itself is from the authors' own 2018 PRX, so novelty is experimental, not theoretical.\n\nMy verdict: worth refereeing, after the authors fix Appendix E and release the companion security analysis. The raw experimental work is solid, but the headline quantitative claim is not yet supported by the document in front of us.\n\nBest,\n[Name]","headline":"Solid experiment, but the PLOB-beating claim depends on an unpublished finite-size proof and a wrongly-directed bound in Appendix E.","tokens_in":17506,"tokens_out":4178,"would_cite":false,"duration_ms":40535,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Hk"],"model":"deepseek-v4-flash","headline":"Quantum key distribution beats the linear loss bound in a fibre experiment.","keywords":["phase-matching quantum key distribution","twin-field QKD","PLOB bound","rate-transmittance scaling","decoy-state method","phase post-compensation","laser injection","long-distance QKD"],"falsifier":"Recompute the 302 km key rate using the full finite-size security proof of Ref. [24], including an explicit treatment of the reference-pulse-based estimate $j_\\delta$ as adversarial information; if the resulting key length falls below the linear bound $R_{\\mathrm{PLOB}}=5.44\\times10^{-7}$, or if the failure probability exceeds $1.68\\times10^{-10}$, the central claim is falsified. A simpler observable check: run the same setup with active phase locking replacing post-compensation and compare key rates; a large gap would indicate the reference-pulse method leaks or biases sifting.","tokens_in":16344,"feed_emoji":"🔑","tokens_out":10332,"duration_ms":92857,"temperature":0.7,"pith_summary":"Phase-matching quantum key distribution (PM-QKD) sends coherent states from two users to a central measurement site; its security analysis promises a key rate that scales as $O(\\sqrt{\\eta})$ in channel transmittance $\\eta$, instead of the $O(\\eta)$ linear bound thought to limit all point-to-point QKD. This paper reports an implementation that reaches that promised regime. Using laser injection to lock the two source lasers and a phase post-compensation technique that corrects slow phase drift in software, the authors measure key rates above the linear bound at 302 km and 402 km of commercial fibre, and a positive key rate of 0.118 bits per second through 502 km of ultralow-loss fibre. If the reported security analysis holds, the practical reach of fibre QKD is no longer set by the linear rate–transmittance bound.","feed_headline":"QKD beats the linear rate bound over 302 km of fibre","feed_subtitle":"A fibre experiment reaches positive secret-key rates the old bound forbids, up to 502 km.","key_machinery":"The carrying mechanism is the phase-encoding of key bits into coherent states from two independent lasers, followed by interference at a central beam splitter; the security proof decomposes the joint state into odd and even total photon-number components and shows that only the even component leaks, giving $K = M_\\mu[1-H(q^{\\mathrm{even}}_\\mu)] - l_{\\mathrm{cor}}$. Two experimental techniques make this real: laser injection, where a shared narrow-linewidth master laser seeds both slave lasers to suppress phase and frequency fluctuations, and phase post-compensation, where strong reference pulses sent through the channel estimate the slice $j_\\delta$ of the phase deviation, and sifting uses $j_s = j_a - j_b + j_\\delta$ to correct the drift in software rather than with active feedback. The decoy-state method bounds the even-photon fraction $q^{\\mathrm{even}}_\\mu$. Together, these turn the channel phase drift from a fatal error into a post-selected correction.","core_discovery":"The central claim is that PM-QKD can be made to work over long fibre and that its measured key rate follows the predicted quadratic improvement rather than the linear bound. The key rate formula used is $K = M_\\mu[1-H(q^{\\mathrm{even}}_\\mu)] - l_{\\mathrm{cor}}$, where the privacy term depends only on the even-photon component $q^{\\mathrm{even}}_\\mu$, not on the bit error rate. The experiment achieves $R = 6.74\\times 10^{-7}$ at 302 km against a linear bound $R_{\\mathrm{PLOB}}=5.44\\times 10^{-7}$, a 24.0% margin with failure probability $1.68\\times 10^{-10}$, and it also reports surpassing the bound at 402 km. At 502 km the system yields a secret key rate of 0.118 bps over an 81.7 dB channel loss, a new loss-tolerance record for fibre QKD.","pith_inferences":["The preprint does not contain the finite-size security proof; an independent check of whether the 24% margin at 302 km survives a fully composable treatment would settle the result's standing.","The same laser-injection and post-compensation machinery could be adapted to twin-field QKD variants and to the phase-stabilization stages of quantum repeater links, a connection the paper only gestures at in its outlook.","A testable extension would vary the reference-pulse intensity and the time between reference and quantum pulses to map the trade-off between phase-estimation accuracy and detector noise; the paper states the protocol tolerates faster fluctuation than active locking but does not quantify this frontier.","If the security proof covers composable finite-size key rates, QKD deployments could use cheaper, faster local lasers with software phase correction instead of active phase-locking hardware."],"forward_implications":["The 302 km and 402 km results show that the linear rate–transmittance bound is not a practical ceiling for phase-encoding MDI QKD; secure keys can be extracted beyond it with commercial fibre.","The 502 km result extends the fibre distance record for QKD and demonstrates operation at a channel loss comparable to satellite links, suggesting terrestrial fibre networks can reach distances previously reserved for free-space links.","Using phase-mismatched data, the groups with $j_s \\neq 0, D/2$, increases the key rate by 72.6% at 302 km, so discarding mismatched-phase rounds is wasteful; grouping them by phase difference and correcting errors group-wise is a direct rate multiplier.","The observed rate–distance relation follows $R=O(\\sqrt{\\eta})$, so future QKD system design can budget for square-root scaling in loss rather than linear scaling when using PM-QKD."],"supporting_citations":[{"why":"Supplies the PM-QKD security proof and the key-length formula $K = M_\\mu[1-H(q^{\\mathrm{even}}_\\mu)] - l_{\\mathrm{cor}}$, the theoretical basis for the claimed $O(\\sqrt{\\eta})$ rate.","marker":"[13]"},{"why":"Establishes the tight linear bound $R_{\\mathrm{PLOB}}=-\\log_2(1-\\eta)$ that the experiment must surpass.","marker":"[9]"},{"why":"Gives the earlier point-to-point key-rate upper bound that motivated the belief in $O(\\eta)$ scaling.","marker":"[8]"},{"why":"Introduces twin-field QKD, the phase-encoding MDI variant that first showed beating the linear bound is possible, directly inspiring PM-QKD.","marker":"[12]"},{"why":"Defines the original MDI-QKD scheme whose asymptotic $O(\\eta)$ rate serves as the comparison baseline.","marker":"[6]"},{"why":"Contains the finite-size security analysis of PM-QKD on which all reported key lengths and failure probabilities rest; the paper lists it as under preparation.","marker":"[24]"},{"why":"Provides the Chernoff-Hoeffding bounds used in the decoy-state estimation to bound the even-photon fraction.","marker":"[25]"},{"why":"Introduced the decoy-state method that the experiment uses to estimate $q^{\\mathrm{even}}_\\mu$ from signal, weak-decoy, and vacuum states.","marker":"[3]"},{"why":"Is the prior long-distance QKD experiment whose key rate the paper says is surpassed by four orders of magnitude.","marker":"[10]"},{"why":"Holds the previous 421 km fibre QKD distance record that the 502 km result beats.","marker":"[11]"}],"fun_headline_variants":["QKD smashes linear bound at 302 km","PM-QKD beats the linear transmittance limit","Quadratic key-rate improvement proven in QKD","At 302 km QKD key rate exceeds linear bound","Key rate defies the linear bound at 302 km"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the unpublished finite-size security analysis in Ref. [24] is correct and covers the post-compensation sifting based on reference pulses sent through the untrusted channel, including the assumption that the phase drift stays nearly constant between reference and quantum pulses; if that proof fails, the reported key rates may not be secure.","fun_headline_variants_meta":{"raw":{"variants":["QKD smashes linear bound at 302 km","PM-QKD beats the linear transmittance limit","Quadratic key-rate improvement proven in QKD","At 302 km QKD key rate exceeds linear bound","Key rate defies the linear bound at 302 km"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001354,"raw_usage":{"total_tokens":5558,"prompt_tokens":1065,"completion_tokens":4493,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":681,"completion_tokens_details":{"reasoning_tokens":4416}},"tokens_in":681,"tokens_out":4493,"duration_ms":35619,"temperature":1.0,"reasoning_tokens":4416,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T15:17:51.317603+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Recompute the 302 km key rate using the full finite-size security proof of Ref. [24], including an explicit treatment of the reference-pulse-based estimate $j_\\delta$ as adversarial information; if the resulting key length falls below the linear bound $R_{\\mathrm{PLOB}}=5.44\\times10^{-7}$, or if the failure probability exceeds $1.68\\times10^{-10}$, the central claim is falsified. A simpler observable check: run the same setup with active phase locking replacing post-compensation and compare key rates; a large gap would indicate the reference-pulse method leaks or biases sifting.","supporting_citations":[{"cited_title":"We take this formula from Eq","cited_arxiv_id":null,"evidence_quote":"Supplies the PM-QKD security proof and the key-length formula $K = M_\\mu[1-H(q^{\\mathrm{even}}_\\mu)] - l_{\\mathrm{cor}}$, the theoretical basis for the claimed $O(\\sqrt{\\eta})$ rate."},{"cited_title":"As a result, Alice and Bob can obtain an lower bound estimation of Ms(J) 1 with failure probability ϵ1 +ϵ2","cited_arxiv_id":null,"evidence_quote":"Establishes the tight linear bound $R_{\\mathrm{PLOB}}=-\\log_2(1-\\eta)$ that the experiment must surpass."},{"cited_title":"Pa(k) is the Poisson distribution when the intensity setting is a","cited_arxiv_id":null,"evidence_quote":"Gives the earlier point-to-point key-rate upper bound that motivated the belief in $O(\\eta)$ scaling."},{"cited_title":"(B13) in Ref","cited_arxiv_id":null,"evidence_quote":"Introduces twin-field QKD, the phase-encoding MDI variant that first showed beating the linear bound is possible, directly inspiring PM-QKD."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the original MDI-QKD scheme whose asymptotic $O(\\eta)$ rate serves as the comparison baseline."},{"cited_title":"Lucamarini, Z","cited_arxiv_id":null,"evidence_quote":"Provides the Chernoff-Hoeffding bounds used in the decoy-state estimation to bound the even-photon fraction."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduced the decoy-state method that the experiment uses to estimate $q^{\\mathrm{even}}_\\mu$ from signal, weak-decoy, and vacuum states."},{"cited_title":"To evaluate E( ¯Ma) from Ma, we inversely use the Chernoﬀ bounds based on Bernoulli variables","cited_arxiv_id":null,"evidence_quote":"Is the prior long-distance QKD experiment whose key rate the paper says is surpassed by four orders of magnitude."},{"cited_title":"For the expected value E(χ), we set the lower and upper bound of the estimated χ as{χL,χU}","cited_arxiv_id":null,"evidence_quote":"Holds the previous 421 km fibre QKD distance record that the 502 km result beats."}],"review_version":1}