{"id":"6ae751bf-2401-430f-96f3-cb81a5f47252","arxiv_id":"1908.06230","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A one-time shot-noise calibration that normalizes by total homodyne noise is shown to match a trusted-detector entanglement-based model and to achieve key rates comparable to the two-step method.","lead":"This paper proposes a one-step calibration of the shot-noise unit in continuous-variable quantum key distribution, replacing the usual two-step subtraction method. If valid, it simplifies real-time calibration and reduces statistical fluctuation while keeping secret key rates close to the conventional approach.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"No significant objection identified: the ηe worst-case concern is defused because the three-mode covariance matrix (Eq. 34) depends on T and ηe only through the product Tηe.","rationale":"The reader identified a genuine gap in exposition: the paper asserts, without proof or scan, that the worst case for the key rate under fixed Tηe occurs at ηe = 1. However, this gap is not load-bearing because the covariance matrix from which the key rate is computed is invariant under the T/ηe split. An independent re-derivation of Eq. (34) from the beam-splitter network confirms that all entries contain T and ηe only as the product Tηe; consequently the symplectic eigenvalues and the Holevo quantity are independent of ηe. This makes the 'worst case' statement either trivially true or unnecessary, and it removes the reader's stated reason for withholding full acceptance. The central PM/EB equivalence remains the substantive security step, and it is supported by the explicit Gaussian trusted-noise model and by the consistency of Eqs. (9)–(10). The finite-size treatment is more conventional and would benefit from shared data, but no concrete algebraic or logical flaw was found. The verdict should therefore remain unchanged: the paper is a plausible, useful practical contribution with a conditional level of verification, but the specific concern about ηe monotonicity does not constitute a barrier to the central claim.","tokens_in":20606,"tokens_out":12112,"duration_ms":128895,"concrete_test":"Substitute T = τ/ηe into Eq. (34) and confirm analytically that all matrix elements depend only on τ, ηd, V, and εc; equivalently, run a numerical scan of the three-mode secret key rate over ηe in [τ, 1] at fixed τ for representative parameters (V = 40, εc = 0.01, ηd = 0.6) and verify the rate is constant to numerical precision.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The reader's weakest assumption targets the unproved minimization over ηe after Eq. (41). On inspection this concern does not land. In the three-mode covariance matrix γ_AB3C of Eq. (34), every entry depends on T and ηe only through the product Tηe: AB3 = sqrt(Tηeηd)(V^2−1), AC = sqrt(Tηe(1−ηd))(V^2−1), B3C = sqrt(ηd(1−ηd)) Tηe(V−1+εc), and the variances are Tηeηd(V−1+εc)+1 and Tηe(1−ηd)(V−1+εc)+1. With τ = Tηe fixed, all entries are independent of ηe. The same is true for the two-mode matrix in Eq. (14), which depends only on τ ηd, and for the finite-size forms in Eqs. (49)–(52). Therefore the key rate is invariant under the split between channel loss and trusted electronic noise, so the claimed worst case at ηe = 1 is trivially true and no monotonicity proof is actually required. The central claim instead rests on the explicit trusted-detector assumptions (Gaussian electronic noise, no leakage to Eve), which the paper states, and on the PM/EB equivalence in Eqs. (9)–(10), which is algebraically consistent. Remaining limitations are practical—no error bars, no raw data or shared code—but they do not undermine the central argument.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes replacing the conventional two-step shot-noise-unit (SNU) calibration of a CV-QKD homodyne detector, SNU = Vtot - Vele, with a one-step calibration, SNU' = Vtot, where Vtot already includes the electronic noise. The authors construct an entanglement-based (EB) model in which the electronic noise is represented by a beam splitter with transmittance eta_e and the detection efficiency by a second beam splitter with transmittance eta_d, and they show algebraically that the prepare-and-measure (PM) output normalized by SNU' equals the homodyne output of this EB model. They derive two-mode and three-mode covariance matrices, compute secret key rates under collective attacks in the asymptotic and finite-size regimes, and present simulation comparisons with the conventional two-time-evaluation (TTE) model, together with a proof-of-principle experiment over 49.85 km of fiber. The central claim is that the one-time calibration achieves essentially the same key rate as the TTE model while simplifying the calibration procedure and reducing statistical fluctuation.","tokens_in":20935,"tokens_out":17866,"duration_ms":172704,"significance":"If the central claim is accepted, the proposal is a useful practical simplification for CV-QKD systems: it eliminates one optical switch and one calibration step, and it can make real-time SNU monitoring easier. The algebraic equivalence in Eqs. (7)-(10) is consistent, and the three-mode trusted-detector covariance matrix in Eq. (34) is a useful explicit construction. The paper does not ship machine-checked proofs or code, but the analytic derivations are largely reproducible from the text. The experimental demonstration, while single-point, provides supporting evidence for feasibility. I assess the central idea as sound, with the caveats below.","major_comments":[{"comment":"The assertion that the worst-case secret key rate is obtained at eta_e = 1 is not proved, and the heuristic given ('the lowest secret key rate may be obtained when the untrusted party controls all the loss') is not supported. This matters because the paper uses that assertion to justify Eq. (35), where Eve is taken to purify only A, B3, and C. However, under the trusted-detector assumptions stated in Sec. III A, the covariance matrices in Eqs. (14) and (34) depend on T and eta_e only through the product T eta_e, so the key rate is in fact invariant under the split between channel loss and electronic-noise transmittance. The authors should replace the unproved worst-case claim with this direct product-dependence argument. If the intention is to cover the case where the electronic noise is untrusted, mode D must be included in the Holevo bound, which is not done.","section":"Section IV A, Eq. (41)"},{"comment":"The finite-size security analysis accounts for the shot-noise-unit estimation uncertainty (Eqs. (43)-(48)) but does not specify how the finite-size estimation of the channel transmittance T and the excess noise epsilon_c enters the covariance matrix and the term I^{epsilon_PE}(B:E) in Eq. (42). The text only says that the lower bound is found by traversing the SNU confidence interval. Consequently, the finite-size key-rate curves in Figs. 9 and 10 and the finite-size experimental rate in Sec. V are not reproducible from the information given. Please provide the parameter-estimation confidence intervals and the resulting worst-case covariance matrices, or explicitly state and cite the standard construction with enough detail to reproduce the results.","section":"Section IV B, Eqs. (42)-(52)"}],"minor_comments":[{"comment":"The phrase 'equation(3)' should be 'Eq. (7)'; Eq. (3) is the definition of the conventional SNU.","section":"Section III A, Eq. (8)"},{"comment":"The formula for lambda_3^2 appears to contain a typo in the denominator; from Eq. (23) it should be V(V chi + 1)/(V + chi), not V(V chi + 1)/(V + V chi).","section":"Section IV A, Eq. (24)"},{"comment":"The off-diagonal B3-C block is written with sigma_z, whereas the corresponding term in Eq. (34) is proportional to the identity matrix; please check the sign and matrix convention.","section":"Section IV B, Eq. (52)"},{"comment":"The experimental key rates are reported as single mean values without error bars or the number of runs; because the paper emphasizes reduced statistical fluctuation, the claim would be strengthened by reporting uncertainties.","section":"Section V, Fig. 12"},{"comment":"The paper claims security against 'arbitrary collective attacks' but does not state the Gaussian optimality reduction that justifies restricting the analysis to Gaussian attacks; this standard step should be cited explicitly.","section":"General"},{"comment":"There are numerous typographical and grammatical errors, including 'Secert' in the Fig. 6 caption, 'we are still not satisfy that mode D is practically controlled by Eve' after Eq. (41), and inconsistent notation such as SNU versus SN U and chi_{B3E} versus chi_{BE}; a careful proofreading pass is needed.","section":"General"}],"recommendation":"major_revision","confidential_remarks":"The core asymptotic derivation is sound and the proposed calibration simplification is practically relevant. The main scientific issues are the unproved (and as stated misleading) worst-case argument for eta_e and the incomplete finite-size parameter-estimation treatment; both are fixable. I recommend major revision. The manuscript would also benefit from a data-availability statement for the experimental results."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear colleague,\n\nYou should know about arXiv:1908.06230: it proposes a one-time SNU calibration for CV-QKD, replacing the standard two-step procedure (Vtot - Vele) with simply using Vtot as the shot-noise unit. The claimed equivalence to a trusted-detector EB model checks out. The reader's main worry an unproven worst-case minimization over eta_e in Sec. IVA does not actually land: in the three-mode covariance matrix (Eq. 34) every entry depends on T and eta_e only through the product T*eta_e, so with T*eta_e fixed the key rate is invariant to the split. The worst case at eta_e = 1 is trivially true, and no monotonicity proof is needed.\n\nWhat is genuinely new is the one-step procedure itself and the explicit EB model that treats electronic noise as a beamsplitter transmittance. The PM/EB equivalence in Eqs. (7)-(10) is algebraic but consistent. The finite-size treatment of SNU fluctuation using a chi-square distribution is sensible, and the proof-of-principle experiment at 49.85 km shows the approach works in a real system. The authors also correctly note that the method reduces statistical fluctuation because one measurement replaces the difference of two.\n\nSoft spots: the experimental section reports single-point key rates with no error bars, and no raw data or code is provided. The three-mode symplectic eigenvalue formulas in Eqs. (36)-(40) are dense and hard to follow; I would want the derivation spelled out in an appendix or a notebook. The RIN extension in Eq. (11) is only sketched. These are moderate issues, not fatal ones. The citation pattern is fine.\n\nThis paper deserves a serious referee. The central argument is consistent, the practical simplification is real, and the security analysis is credible. I would send it to a CV-QKD specialist to check the three-mode algebra. I'd cite this in future work on practical CV-QKD calibration, and I'd bring it to a group meeting.","headline":"A practical one-step SNU calibration for CV-QKD that is more solid than the conditional verdict suggests; the eta_e worst-case concern is defused by the product-form dependence.","tokens_in":21462,"tokens_out":2218,"would_cite":true,"duration_ms":20188,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims that the shot-noise unit of a continuous-variable QKD receiver can be calibrated from one measurement, with a trusted-detector model that keeps secret key rates essentially unchanged.","keywords":["continuous-variable quantum key distribution","shot-noise unit calibration","trusted detector model","homodyne detection","finite-size security analysis","calibration attacks","entanglement-based model","secret key rate"],"falsifier":"Compute the three-mode secret key rate while sweeping $\\eta_e$ from its lower bound to $1$ with $T\\eta_e$ held at the measured total loss; if the minimum occurs at any interior value rather than at $\\eta_e=1$, the conservative bound and the claimed equivalence to two-time calibration are not established.","tokens_in":20393,"feed_emoji":"🔑","tokens_out":9559,"duration_ms":83404,"temperature":0.7,"pith_summary":"The paper tries to establish that the shot-noise unit (SNU) of a continuous-variable quantum key distribution receiver can be calibrated in one step rather than two, without opening security loopholes. In the conventional two-time evaluation, Bob measures the detector's electronic noise with the local oscillator off and then the total noise with it on, subtracting the former from the latter. The proposed one-time calibration instead uses the LO-on total variance $V_{\\mathrm{tot}}$ as the normalization unit, $\\mathrm{SNU}' = V_{\\mathrm{tot}} = \\mathrm{SNU}+V_{\\mathrm{ele}}$, and reinterprets the electronic-noise contribution as the output of a trusted beam splitter inside Bob's receiver. The paper proves that this prepare-and-measure procedure is equivalent to an entanglement-based model whose secret key rate, in asymptotic and finite-size simulations and in a 49.85 km proof-of-principle experiment, comes close to the conventional method while simplifying hardware and reducing statistical fluctuation. This matters because a simpler, single-switch calibration is compatible with real-time monitoring and automatic operation, and because it removes a class of calibration-misestimation attacks.","feed_headline":"Shot-noise calibration cut from two steps to one for CV-QKD","feed_subtitle":"A trusted-detector model makes the single measurement secure, and a 49.85 km experiment puts key rates near the two-step method.","key_machinery":"The central object is a trusted-detector entanglement-based model containing two vacuum-coupled beam splitters: one with transmittance $\\eta_d$ equal to the detector efficiency, and one with transmittance $\\eta_e = A^2 X_{\\mathrm{LO}}^2/(A^2 X_{\\mathrm{LO}}^2+v_{\\mathrm{el}})$ that models the electronic noise as an extra trusted loss. The load-bearing identity is that normalizing Bob's raw outputs by $\\mathrm{SNU}'=V_{\\mathrm{tot}}$ makes the prepare-and-measure output coincide with the homodyne measurement of mode $B_3$ in the entanglement-based model, so the security analysis can be run on the EB covariance matrix while the experiment only measures $V_{\\mathrm{tot}}$ once. A three-mode version permutes the two beam splitters to carry the efficiency loss into Bob's trusted modes, giving a tighter Holevo bound; the finite-size version traverses a $\\chi^2(m-1)$ confidence interval for $V_{\\mathrm{tot}}$ to bound SNU fluctuation.","core_discovery":"The central discovery is that replacing the two-step calibration formula $\\mathrm{SNU}=V_{\\mathrm{tot}}-V_{\\mathrm{ele}}$ by the one-step definition $\\mathrm{SNU}'=V_{\\mathrm{tot}}$ does not change the physical content of the security analysis, provided the detector's electronic noise is modeled as a trusted beam splitter with transmittance $\\eta_e = A^2 X_{\\mathrm{LO}}^2/(A^2 X_{\\mathrm{LO}}^2+v_{\\mathrm{el}})$. With this $\\eta_e$, the normalized homodyne output of the prepare-and-measure scheme equals the measurement of mode $B_3$ in the entanglement-based model, and the same equivalence extends to other trusted additive noises such as relative-intensity noise. The paper derives the full two-mode and three-mode covariance matrices, computes the symplectic eigenvalues for reverse reconciliation against collective attacks, and shows numerically that the three-mode one-time model's secret key rate stays within about 0.64% of the conventional model at variance $V=4$ asymptotically. A proof-of-principle experiment over 49.85 km of fiber with 11.62 dB loss yields asymptotic key rate 11.62 kbps and finite-size key rate 2.39 kbps, slightly below but comparable to the two-time method. The authors conclude that one-time calibration can serve as a direct substitute, with the cost that electronic noise is conservatively treated as untrusted channel loss.","pith_inferences":["An extension the authors do not pursue is the short-block regime: their finite-size formulas imply the one-time method gains most when the block is small enough that skipping the separate $V_{\\mathrm{ele}}$ measurement noticeably enlarges the data fraction $n/N$ available for key distillation.","The same beam-splitter normalization trick should transfer to heterodyne detection and to other shot-noise-normalized continuous-variable protocols such as quantum digital signatures and quantum secret sharing, which the paper mentions but does not derive.","A cautious deployment would independently monitor the electronic noise, because the key-rate bound only becomes conservative after accepting the asserted worst case that all loss is attributed to the untrusted channel; the authors do not provide that independent check."],"forward_implications":["With one-time calibration, a single optical switch in the signal path alternates between SNU calibration and key distribution, so the local-oscillator power is never attenuated by a switch and real-time calibration becomes practical.","The one-time SNU is a single measured variance rather than a difference of two variances, so its finite-size confidence interval is narrower than the conventional one for the same calibration data.","The three-mode entanglement-based model yields secret key rates and tolerable excess noise essentially matching the two-time method in both asymptotic and finite-size simulations; the rate disparity can be as low as 0.64% at variance $V=4$.","The prepare-and-measure to entanglement-based equivalence holds even when relative-intensity noise is included, so the one-time calibration extends to any additional trusted additive noise.","The 49.85 km proof-of-principle experiment demonstrates the method in practice, with asymptotic key rate 11.62 kbps and finite-size key rate 2.39 kbps under an 11.62 dB channel loss."],"supporting_citations":[{"why":"Establishes the conventional two-time SNU calibration procedure and the all-fiber CV-QKD baseline the one-time method compares against.","marker":"[19]"},{"why":"Introduces calibration attacks in which Eve changes the SNU, the loophole the one-step method is designed to close.","marker":"[29]"},{"why":"Shows how an LO calibration attack can make Bob overestimate the SNU and underestimate excess noise, motivating direct one-time calibration.","marker":"[30]"},{"why":"Supplies the trusted-detector assumption that Bob's apparatus is not accessible to Eve, on which the trusted-noise model rests.","marker":"[33]"},{"why":"Establishes the feasibility of modeling detector electronic noise as trusted, the basis of the entanglement-based equivalence.","marker":"[34]"},{"why":"Provides the finite-size security analysis and parameter-estimation formalism used for key rates and the chi-square SNU confidence interval.","marker":"[41]"}],"fun_headline_variants":["One-step shot-noise unit calibration for CV-QKD","CV-QKD shot-noise calibration in a single step","Simplify CV-QKD with one-shot SNU calibration","Trusted detector cuts SNU calibration to one step","One-time calibration for reliable CV-QKD keys"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that, with the combined loss $T\\eta_e$ fixed, the worst-case secret key rate is reached when all loss is assigned to the untrusted channel ($\\eta_e=1$); the paper asserts this after Eq. (41) but gives no proof or numerical scan.","fun_headline_variants_meta":{"raw":{"variants":["One-step shot-noise unit calibration for CV-QKD","CV-QKD shot-noise calibration in a single step","Simplify CV-QKD with one-shot SNU calibration","Trusted detector cuts SNU calibration to one step","One-time calibration for reliable CV-QKD keys"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00026,"raw_usage":{"total_tokens":1660,"prompt_tokens":1088,"completion_tokens":572,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":704,"completion_tokens_details":{"reasoning_tokens":497}},"tokens_in":704,"tokens_out":572,"duration_ms":6242,"temperature":1.0,"reasoning_tokens":497,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T12:52:47.355965+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the three-mode secret key rate while sweeping $\\eta_e$ from its lower bound to $1$ with $T\\eta_e$ held at the measured total loss; if the minimum occurs at any interior value rather than at $\\eta_e=1$, the conservative bound and the claimed equivalence to two-time calibration are not established.","supporting_citations":[{"cited_title":"Lodewyck, M","cited_arxiv_id":null,"evidence_quote":"Establishes the conventional two-time SNU calibration procedure and the all-fiber CV-QKD baseline the one-time method compares against."},{"cited_title":"Ferenczi, P","cited_arxiv_id":null,"evidence_quote":"Introduces calibration attacks in which Eve changes the SNU, the loophole the one-step method is designed to close."},{"cited_title":"Jouguet, S","cited_arxiv_id":null,"evidence_quote":"Shows how an LO calibration attack can make Bob overestimate the SNU and underestimate excess noise, motivating direct one-time calibration."},{"cited_title":"Fossier, E","cited_arxiv_id":null,"evidence_quote":"Supplies the trusted-detector assumption that Bob's apparatus is not accessible to Eve, on which the trusted-noise model rests."},{"cited_title":"Usenko and R","cited_arxiv_id":null,"evidence_quote":"Establishes the feasibility of modeling detector electronic noise as trusted, the basis of the entanglement-based equivalence."},{"cited_title":"Leverrier, F","cited_arxiv_id":null,"evidence_quote":"Provides the finite-size security analysis and parameter-estimation formalism used for key rates and the chi-square SNU confidence interval."}],"review_version":1}