{"id":"11ba0119-f7e4-4c3d-bf33-4a405d3438e6","arxiv_id":"1908.04114","paper_version":5,"verdict":"REJECT","confidence":"HIGH","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"A new private quantum money scheme based on Sampling Matching claims 21.4% noise tolerance with a fixed linear-optics verifier, but the security proof is incomplete.","lead":"The paper introduces a private quantum money scheme whose verification uses the Sampling Matching communication complexity problem, claiming unconditional security up to 21.4% noise with a fixed optical circuit. A generalist might read it because practical quantum money would be a major cryptographic milestone, but the security proof is incomplete.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Coherent-state implementation has no security proof; the advertised unconditional security of the practical scheme is unsupported.","rationale":"The reader's weakest assumption identifies the single-photon restriction in the security proof, and that restriction is indeed part of the problem. However, the more fundamental and textually explicit issue is that the coherent-state implementation, which is the basis of the 'practically feasible' claim, has no security proof at all. The paper itself acknowledges this in Section 3.4. Even if one repaired the single-photon proof by rigorously justifying the photon-number restriction, the abstract's advertised practical scheme would still be unproven because threshold detectors cannot distinguish single-photon events from multi-photon events. Thus the central claim of an unconditional, practically feasible, noise-tolerant quantum money scheme is not established. This reinforces the reader's REJECT verdict, so no change to the verdict is needed. I do not allege dishonesty; the gap is an explicit limitation stated by the authors, and the burden is on the proof to close it.","tokens_in":21173,"tokens_out":15912,"duration_ms":168246,"concrete_test":"Attempt to derive the coherent-state analogue of Eq. (38) from the Section 3.3 proof by writing the adversary's output to each verifier as a mixture over photon-number sectors and showing that the threshold-detector local test rejects every sector with photon number not equal to 1 with certainty. If the first multi-photon sector (for example, a two-photon state |1_k 1_l>) passes the local test with non-negligible probability and can produce a correct parity outcome, the unconditional-security claim for the practical scheme fails. A simpler computational check: simulate the Section 3.4 verification circuit for an adversarial two-photon input and compute the probability that the threshold detectors yield exactly two clicks and a parity outcome that the Bank accepts; if this probability is non-negligible, the single-photon restriction is not a harmless idealization.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing gap is that the paper's practical scheme, which the abstract advertises as a weak-coherent-state implementation with a single 50/50 beam splitter and two threshold detectors, is explicitly not proven secure. Section 3.4 states: 'Here we are not providing full security proof of our quantum money scheme using coherent states. This is due to the fact that the statements of security would be dependent on the specific experimental parametric values... Nevertheless, we expect that a full security proof can be constructed in a straightforward manner.' This matters because the abstract and introduction promise 'practically feasible robust quantum money' with 'unconditional security' and a noise tolerance of 21.4%. The security proof in Section 3.3 applies only to single-photon states of the form Eq. (22), and the step 5 '2 photon clicks' check can enforce the single-photon restriction only with ideal photon-number-resolving detectors, not with the threshold detectors used in the coherent-state implementation. Vacuum and multi-photon components of coherent states are not analyzed, so a forger could in principle exploit them. Even if the single-photon mini-scheme proof were fully correct, the central practical claim as stated would remain unsupported.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript introduces a private quantum money mini-scheme whose verification is based on the Sampling Matching problem. The Bank prepares q copies of single-photon superposition states encoding random n-bit strings; a verifier interferes each selected copy with a local reference state through 50/50 beam splitters, checks the click statistics, and forwards parity outcomes to the Bank. The paper claims information-theoretic unforgeability with a noise tolerance of 21.4%, a fixed passive linear-optical verification circuit, and re-usability that grows linearly with note size. A practical implementation using weak coherent states, a single 50/50 beam splitter, and two threshold detectors is also described. Correctness is analyzed with Chernoff bounds; unforgeability is reduced to a fidelity bound imported from [AA17], with a short argument that coherent attacks reduce to collective attacks. Section 3.4 explicitly states that no full security proof is provided for the coherent-state scheme.","tokens_in":21360,"tokens_out":8920,"duration_ms":93198,"significance":"If the security proof were complete, the scheme would be a genuinely useful simplification of matching-based quantum money: a fixed passive linear-optical verification circuit, a single round of classical communication with the Bank, and a claimed noise tolerance comparable to or better than previous schemes. The correctness calculation is simple, and the circuit simplification for the coherent-state implementation is attractive. However, the advertised unconditional security is not established by the manuscript. The central adversary bound is imported from another paper and is only numerically verified and partly conjectured; the proof for the practical threshold-detector implementation explicitly disclaims a full analysis; and the reduction from coherent to collective attacks is asserted rather than proved. These are load-bearing gaps in the central claim, not presentation issues.","major_comments":[{"comment":"The abstract promises 'unconditional security' for a practically feasible scheme using weak coherent states, but Section 3.4 states: 'Here we are not providing full security proof of our quantum money scheme using coherent states.' The security analysis in Section 3.3 is formulated for single-photon states of the form Eq. (22) and does not analyze the vacuum or multi-photon components of the coherent states used in Eq. (43). Since the coherent-state implementation is exactly the one advertised as practical, the central practical claim is unsupported by the proof given in the manuscript.","section":"Section 3.4 / Abstract"},{"comment":"The main adversary bound, Eq. (33), is taken directly from [AA17] as a numerically verified inequality for n <= 14 and as a conjecture for larger n. The paper provides no proof or rigorous numerical certification of this SDP bound and no detailed demonstration that the SDP optimization for the Sampling Matching scheme is identical to the one solved in [AA17]. Since Eq. (33) is the step that converts the fidelity calculation into an upper bound on the forging probability, the claimed 'unconditional' security is conditional on an unproven external bound. This is a substantive gap for an information-theoretic security claim.","section":"Section 3.3.1, Eq. (33)"},{"comment":"The proof restricts the adversary to single-photon states of the form Eq. (22), justified by the assertion that any other state fails the step 5 check of the Verification phase with certainty. This assertion is valid only for ideal photon-number-resolving detection. The practical implementation in Section 3.4 uses threshold detectors, which do not resolve photon number, so a multi-photon component distributed over distinct modes can in principle produce the required click pattern. The reduction to Eq. (22) therefore does not cover the threshold-detector implementation, and the manuscript needs either a security analysis of multi-photon adversarial states in that setting or an explicit statement that the proof applies only to the PNR implementation.","section":"Section 3.3.1, before Eq. (21)"},{"comment":"The reduction from coherent attacks to collective attacks is handled in one paragraph asserting that the Croke-Kent teleportation argument applies because the setting is 'very similar.' No formal mapping between the money-forging game and the bit-commitment setting is given, and the role of two independent verifiers together with authenticated classical communication to the Bank is not addressed. Since this reduction is needed to rule out arbitrary joint operations across the q' copies, the proof of unconditional security is incomplete at this step as well.","section":"Section 3.3.2"}],"minor_comments":[{"comment":"Equation (4) writes the second verification event as VerB_H($1) = 1 twice; the second event should be VerB_H($2) = 1.","section":"Definition 2.2, Eq. (4)"},{"comment":"In the measure-and-resend example for n = 4, the adversary state of Eq. (40) provides correct parity information only for the measured tuple. Since the verifier can obtain any of the six tuples, the error probability is 5/12, not 1/3 as stated in Eq. (41).","section":"Section 4, Eq. (41)"},{"comment":"The text repeatedly refers to 'single-photon clicks' in the coherent-state implementation, but threshold detectors are not photon-number-resolving and produce only binary click/no-click outcomes. The wording should be adjusted to avoid implying number resolution.","section":"Section 3.4, Fig. 7"},{"comment":"There are several typographical errors, including 'upto' in the abstract, 'mdoe' in Section 2.2.2, 'prarity' in Section 3.3.2, and some inconsistent pronoun use. A careful proofreading pass is needed.","section":"Throughout"}],"recommendation":"reject","confidential_remarks":"The core idea is promising and the circuit simplification is attractive, but the manuscript's advertised claims are substantially stronger than what is proved. In particular, the coherent-state implementation is explicitly left without a security proof, and the single-photon proof relies on an externally imported, numerically verified and partly conjectured SDP bound. These issues are central rather than local, so I cannot recommend acceptance or minor revision. If the authors can supply a rigorous proof or certified bound for Eq. (33) and a security analysis for the threshold-detector implementation, a future resubmission could be viable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The thing to know about this paper: the abstract promises practically feasible, unconditionally secure quantum money with a single 50/50 beam splitter and two threshold detectors, and the paper itself concedes in Section 3.4 that the version using those components (weak coherent states) has no security proof. The single-photon scheme that does get a proof is a plausible incremental extension of Amiri–Arrazola, but the proof rests on imported and partly conjectural ingredients.\n\nWhat is genuinely new: the Sampling Matching money protocol itself, and the observation that the verification circuit is fixed and passive rather than growing with the target noise tolerance as in AA17. This is a real reason to care: you trade a modest drop in tolerance (21.4% vs 23.3%) for a much simpler implementation. The single-photon correctness calculation is clean and correct, the measure-and-resend example gives a useful concrete picture, and the author is transparent about what is and is not proven.\n\nThe soft spots are load-bearing. Section 3.4 explicitly says there is no full security proof for the coherent-state scheme, so the abstract's central promise is unsupported. For the single-photon proof, three things need work. First, Eq. 33 is a numerically verified SDP bound from AA17 for n ≤ 14 and a conjecture beyond, so 'unconditional' is stronger than what is established. Second, the restriction of the adversary to single-photon states in Section 3.3.1 is asserted, not derived; with ideal photon-number-resolving detectors a post-selection argument might rescue it, but that argument is not in the paper, and the coherent version's threshold detectors cannot enforce it. Third, the coherent-to-collective reduction is waved through via a Croke–Kent bit-commitment result whose applicability is asserted, not shown. There are smaller issues too: T is defined one way in the protocol (max copies) and another way in the security analysis (max attempts), and Eq. 48 counts 'at least two clicks' where it should count exactly two, which overstates the honest success rate. The specific two-photon-in-two-modes example from the stress-test would actually be caught by an ideal PNRD check, but the underlying concern stands.\n\nMy take: the paper deserves a serious referee, not a desk reject. A rigorous referee will send it back for major revision — either trim the abstract to what is actually proven, or write down the missing arguments. I would cite the scheme as a proposal, flagged as lacking a complete security proof, and I would point anyone working on practical quantum money toward it — but I would not take the advertised security guarantees at face value.","headline":"Plausible SM-based money scheme with a clean single-photon correctness analysis, but the advertised coherent-state implementation has no security proof and the single-photon proof leans on imported, partly conjectural ingredients.","tokens_in":21906,"tokens_out":16998,"would_cite":true,"duration_ms":152731,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A private quantum money scheme based on Sampling Matching claims unconditional security against forging while tolerating noise up to 21.4% with a fixed passive linear-optical verification circuit.","keywords":["quantum money","classical verification","Sampling Matching","linear optics","unconditional security","noise tolerance","weak coherent states","single-photon states"],"falsifier":"Send the verifier a single copy prepared as a two-photon state with one photon in mode $k$ and one in mode $l$ ($k\\neq l$), then run the Sampling Matching test. It yields two single-photon clicks, so it passes the local two-click check; if such a two-photon state, or a mixture of two-photon states, can also make the Bank's parity comparison succeed often enough, the claimed unconditional security against all adversaries is false. This is directly checkable with the weak-coherent-state setup.","tokens_in":20918,"feed_emoji":"💵","tokens_out":10086,"duration_ms":101611,"temperature":0.7,"pith_summary":"This paper claims that the Sampling Matching problem, a one-way communication task, can be turned into the verification step of a private quantum money scheme. The scheme uses single-photon states that encode secret n-bit strings, and the verification requires only one round of classical communication between the local verifier and the Bank. The claimed payoff is unconditional security against any forging adversary while tolerating noise up to 21.4%, achieved with a fixed circuit made of passive 50/50 beam splitters; in the weak-coherent-state implementation the circuit shrinks to a single beam splitter and two single-photon threshold detectors. This matters because previous matching-based money schemes needed more optical components as the desired noise tolerance grew, which made high-robustness versions impractical.","feed_headline":"A one-beam-splitter circuit verifies quantum money at 21.4% noise","feed_subtitle":"Sampling Matching lets a fixed passive linear-optical circuit check banknotes with unconditional security up to 21.4% noise.","key_machinery":"The load-bearing object is the Sampling Matching verification scheme: the noteholder's single-photon state is mixed mode-by-mode with a verifier-prepared equal-amplitude local state on 50/50 beam splitters, and the pattern of two-photon clicks—both in the same output family versus one photon in each family—yields the parity $x_k \\oplus x_l$ for a sampled tuple $(k,l)\\in T_n$. The quantitative engine is the conversion of forging into a fidelity-maximization SDP, whose bound $\\bar F \\le \\frac12 + \\frac1n$ directly lower-bounds the adversary's error probability; the fixed-hardware claim comes from the coherent-state version of Sampling Matching, where the whole interaction is a single beam splitter followed by two threshold detectors.","core_discovery":"The paper's central claim is that Sampling Matching can serve as the verification primitive for private quantum money in a way that is both equipment-light and unconditionally secure. The Bank encodes each secret string $x\\in\\{0,1\\}^n$ as a single-photon state $|x\\rangle = \\frac{1}{\\sqrt n}\\sum_{k=1}^n (-1)^{x_k}\\hat a_k^\\dagger|0\\rangle$; the verifier interferes this state mode-by-mode with his own equal-superposition state through 50/50 beam splitters. Two single-photon clicks in distinct output modes reveal the parity $x_k \\oplus x_l$ of a sampled tuple, while two photons in one mode give no information. The security proof reduces any forging strategy to maximizing the average fidelity with the honest state, imports the bound $\\bar F \\le \\frac12 + \\frac1n$, and shows that the forger's success probability decays exponentially whenever the honest success rate exceeds the forger's by the noise tolerance $\\frac14 - \\frac{1}{2n}$; at $n=14$ that tolerance is 21.4%. In the weak-coherent-state implementation, the same verification uses a single 50/50 beam splitter and two single-photon threshold detectors, independent of the note size.","pith_inferences":["Inference: Since the coherent-state Sampling Matching circuit has already been demonstrated with weak pulses, running the verification at $n=14$ and measuring the honest-holder error rate would turn the 21.4% tolerance from a theoretical number into a directly testable one.","Inference: The same parity-sampling game could plausibly be reused for other linear-optics verification tasks—checking that a prover knows an encoded string while revealing only one parity at a time—so the fixed-circuit simplification may outlive this particular money scheme.","Inference: If the fidelity bound $\\bar F \\le \\frac12 + \\frac1n$ is ever proven for all $n$, the fixed circuit would achieve the conjectured matching-scheme ceiling of 25% noise tolerance without any increase in optical hardware."],"forward_implications":["If the central claim is correct, a fixed passive linear-optical circuit—one 50/50 beam splitter and two threshold detectors in the coherent-state version—suffices to verify quantum money at any noise tolerance up to the threshold, whereas earlier matching-based schemes needed more optical elements as the tolerance grew.","Because verification uses a single round of classical communication, the Bank does not need to keep an active memory of the interaction, so many local verifiers can authenticate notes concurrently.","Each note can be reused for a number of verifications linear in its size, with the Bank capping the total number of attempts before the note is retired.","The security guarantee is information-theoretic rather than computational, so it would survive an adversary with unbounded quantum computing power.","If the fidelity bound $\\bar F \\le \\frac12 + \\frac1n$ holds for all $n$, the scheme's asymptotic noise tolerance reaches 25%, the conjectured ceiling for matching-based money schemes."],"supporting_citations":[{"why":"It defines the Sampling Matching problem and demonstrates the weak-coherent-state linear-optics circuit used for verification.","marker":"[KKD19]"},{"why":"It supplies the SDP fidelity bound $\\bar F \\le 1/2 + 1/n$ and the reduction of forging to a fidelity-maximization problem that the paper directly imports.","marker":"[AA17]"},{"why":"It shows that a private quantum money mini-scheme can be lifted to a full scheme, which the paper relies on when attaching serial numbers.","marker":"[BDS16]"},{"why":"It gives the teleportation-based argument used to claim that any coherent attack is no stronger than collective attacks.","marker":"[CK12]"},{"why":"It introduces the mini-scheme notion that reduces the security target to producing two valid notes from one.","marker":"[AC12]"}],"fun_headline_variants":["One beam splitter verifies quantum money up to 21.4% noise","Fixed circuit, classical check: robust quantum money","Unconditional security for quantum cash with one splitter","Sampling Matching unlocks hardware-light quantum money"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof assumes that any forger must send exactly one photon distributed over the $n$ modes for each copy, because it only analyzes single-photon mixed states; the verifier's local test, however, does not reject states with two photons in two different modes, which also produce two single-photon clicks.","fun_headline_variants_meta":{"raw":{"variants":["One beam splitter verifies quantum money up to 21.4% noise","Fixed circuit, classical check: robust quantum money","Unconditional security for quantum cash with one splitter","Sampling Matching unlocks hardware-light quantum money"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000676,"raw_usage":{"total_tokens":3148,"prompt_tokens":1088,"completion_tokens":2060,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":704,"completion_tokens_details":{"reasoning_tokens":1994}},"tokens_in":704,"tokens_out":2060,"duration_ms":19342,"temperature":1.0,"reasoning_tokens":1994,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T13:51:05.533046+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Send the verifier a single copy prepared as a two-photon state with one photon in mode $k$ and one in mode $l$ ($k\\neq l$), then run the Sampling Matching test. It yields two single-photon clicks, so it passes the local two-click check; if such a two-photon state, or a mixture of two-photon states, can also make the Bank's parity comparison succeed often enough, the claimed unconditional security against all adversaries is false. This is directly checkable with the weak-coherent-state setup.","supporting_citations":[],"review_version":1}