{"id":"84412f44-9abb-4218-8c46-fff1d18f393a","arxiv_id":"1908.03625","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A real-local-oscillator CV-QKD link is demonstrated for the first time without pilot tones, using a particle smoother that exploits the symbols Alice already reveals.","lead":"This paper reports the first continuous-variable quantum key distribution system that uses a real local oscillator without any auxiliary pilot signals, recovering the laser phase with a machine-learning method. If it holds, the approach could make quantum-secured fiber links almost as simple as ordinary coherent optical systems.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Gaussian-channel security proofs are applied to a nonlinear particle-smoother DSP that uses publicly revealed symbols; the paper does not show the effective channel is covered by those proofs.","rationale":"The reader's weakest assumption correctly identifies the revealed-symbol dependence of the phase estimator as a potential gap. I agree that this is the point where the security argument is least secure, with one refinement: the deeper problem is that the standard proofs assume a memoryless linear Gaussian channel, and the particle-smoother output, irrespective of the revealed-symbol issue, is a nonlinear time-correlated post-processing of the raw data. The paper itself flags the linear-Gaussian assumption as not fully general. This does not mean the experiment is wrong; the measured mutual information and excess noise may be valid. But the step from those measurements to a positive secret key rate is an application of a proof whose hypotheses are not verified. This is addressable with a dedicated security analysis, so the verdict should remain conditional rather than accept or reject.","tokens_in":10136,"tokens_out":15853,"duration_ms":178499,"concrete_test":"Simulate the full protocol with the particle-smoother DSP on an entanglement-based collective-attack channel with the measured phase-noise spectrum, and recompute the secret-key rate using the non-Gaussian discrete-modulation security proof of Ref. [24] (or an explicit evaluation of the classical-quantum state after the revealed-symbol-dependent post-processing) instead of the Gaussian formulas of Refs. [1,23]. If the recomputed rate at 26 km is below 9.2 Mbit/s or non-positive, the Gaussian-channel assumption is load-bearing and the headline key rate must be requalified as an upper bound rather than an established secure rate.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim requires the asymptotic key-rate calculation to bound Eve's information for the actual receiver output. The calculation uses the discrete-modulation Gaussian-channel proofs of Refs. [1,23], but the paper's own Discussion states that these proofs 'assume a linear Gaussian channel and are therefore not fully general.' The receiver DSP is not such a channel: the particle smoother uses the publicly revealed symbols (Methods, Eqs. (10)-(11) with r_k) and backward smoothing, producing outputs that are nonlinear functions of the raw measurements and of a time-correlated phase-noise process. The manuscript does not show that the effective conditional distribution of Bob's key symbols, after this revealed-symbol-dependent post-processing, is a memoryless linear Gaussian channel with the estimated T and excess noise, nor that Eve's optimal information is bounded by the Gaussian formula. If the phase-recovery map creates correlations or non-Gaussianity that the proof does not cover, the claimed 9.2 Mbit/s over 26 km is an unsupported extrapolation. The physical demonstration of SNR = -19.1 dB is compelling, but the security step from measured mutual information to secret key rate is the weakest link.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This manuscript reports an experimental continuous-variable QKD setup with a real (local) oscillator and no pilot/auxiliary tones, using M-ary phase modulation and a Bayesian particle smoother for carrier phase recovery. The authors report successful demodulation of an M=4 discrete-modulation signal down to a channel SNR of -19.1 dB, and compute asymptotic secret-key rates of 9.2 Mbit/s over 26 km of fiber based on measured excess noise and receiver parameters. They also present simulations of a phase-noise-limited version of the system that reach longer distances, and they compare the experimental hard-decision mutual information with theoretical AWGN values.","tokens_in":10367,"tokens_out":8734,"duration_ms":86981,"significance":"The experimental result is significant: if a CV-QKD system with a free-running real LO can operate without pilot tones at SNR below -20 dB, it removes a major practical obstacle and brings CV-QKD closer to a standard coherent receiver. The evidence for the demodulation claim is credible: mutual information measurements are compared to theory, the excess-noise measurements show the expected scaling, and the authors are transparent about the limitations of their security analysis. The weakest step is not the demodulation physics but the transition from measured mutual information to a secret-key rate. The paper itself notes that the security proofs assume a linear Gaussian channel, and the receiver DSP is nonlinear and depends on the publicly revealed symbols. The headline key-rate number should therefore be treated as a conditional projection until this security gap is addressed.","major_comments":[{"comment":"The headline key rate is computed by applying the discrete-modulation security proofs of Refs. [1,23] to the measured parameters. The paper itself states in the Discussion that these proofs 'assume a linear Gaussian channel and are therefore not fully general,' and that assumption is exactly the problem here. The receiver output is produced by a particle smoother whose measurement model changes with the publicly revealed symbols r_k (Methods, Eqs. (10) and (11)) and which performs backward-simulation smoothing; the final symbols are thus a nonlinear, non-memoryless function of the raw measurements and of a time-correlated phase process. The manuscript does not show that the effective conditional distribution of Bob's key symbols after this post-processing is a linear Gaussian channel with the estimated transmission and excess noise, nor that Eve's optimal information is bounded by the Gaussian formulas used in [1,23]. Because the 9.2 Mbit/s at 26 km figure is an asymptotic secret-key rate, this is a load-bearing gap. I recommend either extending the security analysis to the actual DSP, or clearly labeling the key-rate number as a heuristic projection under an unproven channel-model assumption.","section":"Discussion; Methods, Particle Smoother"},{"comment":"The key-rate curves in Fig. 5 are computed from 'polynomial fits for the excess noise in the case of pr = 0.05' plotted in Figs. 3 and 4, but the measured excess-noise points are shown without error bars and the receiver parameters eta ≈ 0.232 and epsilon_el ≈ 0.70 enter through Eq. (4) without uncertainties. The excess noise is the parameter that most directly controls Eve's information, so the quantitative claim of 9.2 Mbit/s over 26 km has no stated statistical or systematic uncertainty. At a minimum, the authors should report the spread of the block-wise excess-noise estimates and propagate the calibration uncertainties (or provide a sensitivity analysis) through the key-rate calculation.","section":"Discussion; Figure 5"},{"comment":"The simulations are described as showing the phase-noise-limited performance and are used to project distances up to 72 km, but they are not an independent test: the phase-noise sequence is recorded with the experimental setup, and the state-space parameters sigma_Omega^2 and sigma_phi^2 are fitted to a high-SNR (11.5 dB), pr = 1 measurement with the same lasers. The simulation curves therefore represent a best-case extrapolation, and the distinction between measured and simulated key rates should be maintained in the conclusions. In particular, the sentence in the conclusion that 'the achievable key rate over a distance of 26 km is 5.7 × 10^-4 bit/sym corresponding to 9.2 Mbit/s' should be qualified as an asymptotic, simulation- and fit-based projection rather than a directly measured rate.","section":"Results; Methods, Simulation Details; Figure 2"}],"minor_comments":[{"comment":"In Eq. (14), the exponent in the last factor appears as exp(-SNR sin^2(...)); the subscript b in SNR_b is missing. Please correct this typo.","section":"Methods, Estimation of Mutual Information"},{"comment":"The caption says 'The small and solid markers indicate negative values' but the marker shapes and colors are not defined in the legend; please clarify which marker style corresponds to which quantity.","section":"Figure 4 caption"},{"comment":"The abstract and conclusion state the 9.2 Mbit/s figure without the qualifier 'asymptotic' that is introduced in the Discussion. Please use the qualifier consistently so that the asymptotic nature of the key-rate calculation is clear to the reader.","section":"Abstract and Conclusion"},{"comment":"The text contains a character-encoding artifact ('AliceâĂŹs') and the Discussion contains the misspelling 'sensitvity'. These should be corrected.","section":"Methods, Experimental Details"},{"comment":"The abstract credits 'Machine Learning methods'; the paper actually uses Bayesian filtering and smoothing with MCMC parameter optimization. Please describe the methods more precisely to avoid overclaiming the novelty of the algorithmic approach.","section":"Abstract"}],"recommendation":"major_revision","confidential_remarks":"The main risk is that the key-rate claim is presented as stronger than the security analysis supports. A revised version that either closes the channel-modeling gap or clearly labels the rate as a heuristic projection would be publishable in my view. The experimental demonstration is solid and the paper is honest about many of its limitations; the security gap is the central issue."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague — this paper is worth a look, but with a grain of salt. The genuinely new thing is the first experimental CV-QKD with a real local oscillator and no pilot tones, using a particle smoother that leverages the symbols Alice already reveals for parameter estimation. The demodulation down to SNR = -19.1 dB (M=4) is credible; the mutual information measurements track the AWGN theory well, and the pr=0 receiver sensitivities are a useful data point for low-SNR coherent detection. The engineering is careful, and the authors are honest about the limitations of their security analysis.\n\nThe soft spot is load-bearing. The 9.2 Mbit/s over 26 km comes from plugging polynomial fits to the measured excess noise into the Leverrier-Grangier security proof. But the actual receiver DSP is not a linear Gaussian channel: the particle smoother uses the publicly revealed symbols (rk=1) to adapt its measurement model, and its outputs are nonlinear functions of the raw measurements and of time-correlated phase noise. The paper does not show that the effective conditional distribution of Bob's symbols, after this revealed-symbol-dependent post-processing, is a memoryless linear Gaussian channel with the estimated T and excess noise. The authors themselves note the proof assumes a linear Gaussian channel and is 'not fully general.' So the headline key rate is an extrapolation, not a proven secure rate. This does not invalidate the experimental demonstration, but it means the figure should be labeled conditional.\n\nOther concerns are minor: no error bars on the excess-noise estimates (100 blocks per scenario), the polynomial fits come from the same data used in the rate calculation, and receiver calibration happens about 3 seconds after the quantum transmission, which could bias the noise calibration. These are standard experimental-practice issues, not red flags.\n\nWho is this for? Anyone working on practical CV-QKD deployment or on low-SNR coherent DSP. It deserves a serious referee, not a desk reject, because the experimental claim is new and the security gap is, in principle, fixable. My advice: send to review, but require the authors to close the security gap or clearly state the key rate as an upper bound under idealized assumptions.","headline":"First pilot-free real-LO CV-QKD experiment is impressive, but the headline key rate leans on an unproven security assumption.","tokens_in":10882,"tokens_out":2690,"would_cite":true,"duration_ms":26281,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper reports the first experimental demonstration of continuous-variable quantum key distribution with a real local oscillator and no auxiliary pilot signals, achieving an asymptotic key rate of 9.2 Mbit/s over 26 km of fiber.","keywords":["continuous-variable quantum key distribution","real local oscillator","pilot-free phase recovery","particle smoother","MCMC parameter optimization","discrete modulation","carrier phase estimation","coherent optical communications"],"falsifier":"Re-evaluate the secret key rate using a security analysis in which Bob's phase estimate is explicitly a function of the revealed-symbol sequence, with the same measured excess noise (signal-to-distortion ratio about 31.82 at SNRb = 7.1 dB) and receiver parameters; if the rate at 26 km falls below 9.2 Mbit/s, the pilot-free claim is falsified. A simpler marker: reproduce the -19.1 dB sensitivity by running the same particle-smoother DSP on independently recorded 17 GBd data.","tokens_in":9914,"feed_emoji":"🔐","tokens_out":8164,"duration_ms":76313,"temperature":0.7,"pith_summary":"Continuous-variable quantum key distribution (CV-QKD) reads keys from faint laser pulses, so the receiver must track the laser phase at signal-to-noise ratios far below 0 dB. The usual fixes are a remote local oscillator or dedicated pilot tones; this paper removes both. It reports the first experimental demonstration of CV-QKD with a real free-running local oscillator and no auxiliary signals, using a machine-learning phase tracker. With the M=4 discrete-modulation protocol and only 5% of symbols revealed, the system demodulates down to a quantum-channel SNR of -19.1 dB and supports an asymptotic key rate of 9.2 Mbit/s over 26 km of fiber. If correct, this makes QKD hardware almost identical to a standard coherent optical link.","feed_headline":"Pilot-free quantum key distribution runs at 9.2 Mbit/s over 26 km","feed_subtitle":"A real local oscillator and no auxiliary signals bring QKD hardware close to standard coherent optics.","key_machinery":"The load-bearing element is the Bayesian particle smoother used for carrier phase estimation. It treats the laser phase as a random walk with a drifting frequency offset and, crucially, uses different measurement likelihoods for revealed and unrevealed symbols: when Alice has publicly revealed symbol a_k, the likelihood is a Gaussian centered on that known symbol; otherwise it is a mixture over the M possible symbols. A bootstrap particle filter with 200 particles plus a backward-simulation smoother performs the tracking, and MCMC optimization fixes the state-space noise variances. The same state-space model is reused in an extended Kalman filter for timing recovery. This machinery lets the receiver track the phase at SNR values where decision-directed methods fail.","core_discovery":"The paper's central claim is that pilot-free real-local-oscillator CV-QKD is experimentally feasible. Bob's free-running laser serves as the local oscillator, and carrier phase estimation is performed by a Bayesian particle smoother whose measurement model switches depending on whether each received symbol was publicly revealed by Alice. Because a fraction of symbols must be revealed in any CV-QKD protocol anyway, these revealed symbols double as phase references at no extra bandwidth cost. With M=4 modulation at 17 GBd, the measured system reaches an SNR of -19.1 dB and, using the measured excess noise and standard discrete-modulation security analysis, gives an asymptotic key rate of 5.7e-4 bit/sym, i.e., 9.2 Mbit/s over 26 km. Simulations limited to laser phase noise indicate the same receiver concept could extend to about 72 km for M=4.","pith_inferences":["A direct security analysis that models Bob's phase estimator as a function of the revealed symbols would close the gap between the experiment and the proof; until then, the claimed key rate rests on an extrapolation of existing discrete-modulation proofs.","The same particle-smoother and MCMC phase tracking could be applied to other ultra-low-SNR coherent receivers, such as free-space optical satellite downlinks, where pilot tones are costly.","A real-time implementation of the particle smoother would be the next test; the paper's digital signal processing is offline, so latency and throughput at line rate remain open.","If the security proof is updated, the pilot-free design could roughly double the spectral efficiency of pilot-based real-local-oscillator systems, since no pilot bandwidth is reserved."],"forward_implications":["Pilot tones are not indispensable for real-local-oscillator CV-QKD; a receiver that uses only the quantum signal and the already-revealed symbols can operate at deeply negative SNR.","Because the transmitter and receiver are almost identical to a classical coherent fiber link, existing commercial components and digital signal processing can be reused for QKD.","At the demonstrated parameters (M=4, pr=0.05, 26 km), the asymptotic key rate is 9.2 Mbit/s; simulations suggest the phase-noise-limited ceiling is around 72 km for the same modulation.","Increasing the revelation probability pr reduces excess noise and can tolerate stronger laser phase noise, trading a small fraction of public symbols for longer distance or cheaper lasers."],"supporting_citations":[{"why":"This citation defines the discrete-modulation protocol and supplies the security analysis used to compute the key rates.","marker":"[1]"},{"why":"This citation gives the asymptotic security proof for discrete modulation used in the key-rate calculation.","marker":"[23]"},{"why":"This citation supplies the Bayesian filtering and smoothing framework and the particle-smoother implementation used for phase estimation.","marker":"[21]"},{"why":"This citation provides the digital filter-and-square timing recovery algorithm used to synchronize the receiver.","marker":"[20]"},{"why":"This citation gives the formula relating residual phase-estimation error to excess noise, which is used in the simulations.","marker":"[22]"},{"why":"This citation establishes that a fraction of Alice's symbols must be revealed publicly, the resource the scheme reuses for phase tracking.","marker":"[19]"}],"fun_headline_variants":["Real local oscillator CV-QKD reaches 9.2 Mbit/s over 26 km","CV-QKD without pilot tone: 9.2 Mbit/s over 26 km","Machine learning enables pilot-free CV-QKD at 9.2 Mbit/s","First CV-QKD with real local oscillator, no auxiliary signals","Third-gen QKD: real LO, no pilot, 9.2 Mbit/s over 26 km"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key-rate claim assumes that the standard discrete-modulation security proofs remain valid when Bob's phase estimate is itself shaped by the publicly revealed symbols, a dependence the proofs do not explicitly model.","fun_headline_variants_meta":{"raw":{"variants":["Real local oscillator CV-QKD reaches 9.2 Mbit/s over 26 km","CV-QKD without pilot tone: 9.2 Mbit/s over 26 km","Machine learning enables pilot-free CV-QKD at 9.2 Mbit/s","First CV-QKD with real local oscillator, no auxiliary signals","Third-gen QKD: real LO, no pilot, 9.2 Mbit/s over 26 km"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000603,"raw_usage":{"total_tokens":2800,"prompt_tokens":913,"completion_tokens":1887,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":529,"completion_tokens_details":{"reasoning_tokens":1775}},"tokens_in":529,"tokens_out":1887,"duration_ms":14552,"temperature":1.0,"reasoning_tokens":1775,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T15:28:12.124720+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Re-evaluate the secret key rate using a security analysis in which Bob's phase estimate is explicitly a function of the revealed-symbol sequence, with the same measured excess noise (signal-to-distortion ratio about 31.82 at SNRb = 7.1 dB) and receiver parameters; if the rate at 26 km falls below 9.2 Mbit/s, the pilot-free claim is falsified. A simpler marker: reproduce the -19.1 dB sensitivity by running the same particle-smoother DSP on independently recorded 17 GBd data.","supporting_citations":[{"cited_title":"Bob uses a balanced receiver to perform heterodyne detection at an intermediate frequency ofδνAB≈ 10 GHz","cited_arxiv_id":null,"evidence_quote":"This citation defines the discrete-modulation protocol and supplies the security analysis used to compute the key rates."},{"cited_title":"Kleis and C","cited_arxiv_id":null,"evidence_quote":"This citation gives the asymptotic security proof for discrete modulation used in the key-rate calculation."},{"cited_title":"Oerder and H","cited_arxiv_id":null,"evidence_quote":"This citation supplies the Bayesian filtering and smoothing framework and the particle-smoother implementation used for phase estimation."},{"cited_title":"Grosshans, N","cited_arxiv_id":null,"evidence_quote":"This citation provides the digital filter-and-square timing recovery algorithm used to synchronize the receiver."},{"cited_title":"Särkkä,Bayesian ﬁltering and smoothing, Vol","cited_arxiv_id":null,"evidence_quote":"This citation gives the formula relating residual phase-estimation error to excess noise, which is used in the simulations."},{"cited_title":"Fossier, E","cited_arxiv_id":null,"evidence_quote":"This citation establishes that a fraction of Alice's symbols must be revealed publicly, the resource the scheme reuses for phase tracking."}],"review_version":1}