{"id":"e65b6d39-583c-485a-8dc9-63f6b8623503","arxiv_id":"1908.07426","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"The randomness cost of a universal quantum masker is at least a measure of information unevenness between its two outputs, and the geometric 'disk' conjecture on maskable states is false.","lead":"This paper derives a lower bound on the randomness required to mask quantum information, expressed in terms of how unevenly the secret's information is split between two parties. It also disproves a published geometric conjecture about which states can be masked by a fixed unitary operation.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Theorems 3 and 4 inherit the unproved Fact 1: if some invertible constant-marginal channel cannot be decomposed as a random mixture of orthogonal isometries, the main inequality does not cover it.","rationale":"Fact 1 is the hinge of the paper: Theorem 3 applies Theorem 2 to the marginal subchannels N_i^A and N_i^B, which exist only after the orthogonal-isometry decomposition, and Theorem 4 inherits this through the definition of I_infty. The proof of Theorem 2 is acceptable for the perfect-masking case e=0, so the main gap is not the heuristic e>0 extension but the representation theorem itself. The reader's weakest_assumption identifies exactly this dependency. The appendix derivation of I_1 <= R + 2 log d / d and the regularization step are internally coherent once Fact 1 is granted, and the counterexample to Conjecture 1 is independent of the central inequality. Therefore the appropriate verdict remains conditional: the core theorem is well-supported conditional on Fact 1, but a self-contained proof of that decomposition is needed to certify that the inequality applies to all universal masking processes. No stronger objection is justified because no internal inconsistency or counterexample to Fact 1 has been exhibited here.","tokens_in":9654,"tokens_out":33319,"duration_ms":349307,"concrete_test":"Settle Fact 1 by an independent proof or a small-dimensional numerical search. For d=2 and d_A=d_B=3, use semidefinite programming to search over CPTP maps Phi: M_d -> M_{d_A} otimes M_{d_B} that (i) have constant marginals, (ii) are invertible as linear maps, and (iii) minimize S(sigma_S) over candidate representations Phi(rho)=M(rho otimes sigma_S)M^dagger. Check whether every such Phi admits a Kraus representation {K_i} with K_i^dagger K_j = delta_ij I and Phi(rho)=sum_i K_i rho K_i^dagger, equivalently whether the Choi matrix is a convex combination of rank-one projectors with pairwise orthogonal supports. If the SDP finds a counterexample, Theorem 4's domain is narrower than claimed; if the structural theorem is recovered, the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central lower bound I_infty({M_i}) <= R(Phi_M) is proved only for maskers of the form Phi_M(rho) = M(rho otimes sigma_S)M^dagger = sum_i p_i M_i rho M_i^dagger, with M_i isometries having orthogonal images and with R(Phi_M) = S(sigma_S). This is Fact 1, imported from prior work and asserted without proof. The risky step is Eq. (2): a general quantum channel has a Stinespring dilation with a partial trace, Phi(rho) = Tr_E U(rho otimes |0><0|)U^dagger. Fact 1 claims that for an invertible universal masker the environment can be eliminated and absorbed into the output as a classical mixture of orthogonal isometries, with the safe-state entropy exactly the randomness cost. If some invertible CPTP map with constant marginals admits only Kraus operators that are not proportional to orthogonal isometries, then Theorems 3 and 4 are not defined for it: Eq. (9), the pointwise bound I_i <= -log p_i, no longer follows from Theorem 2, and R(Phi_M) need not equal S(sigma_S). The paper's uniqueness statement (up to degeneracy) does not exclude such a channel. The examples in the paper are of the assumed form, so they are internally consistent, but whether the main inequality governs every universal masking process is left open.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies the minimal amount of classical randomness needed for universal quantum masking, the encoding of an unknown quantum state into a bipartite system such that each local reduced state is input-independent. The authors define the randomness cost R(Phi_M) as the entropy of the 'safe state' in a Stinespring-type representation Phi_M(rho)=M(rho otimes sigma_S)M^dagger, and under the assumption that any universal masker can be decomposed as a random mixture sum_i p_i M_i rho M_i^dagger of bipartite isometries with orthogonal images, they prove lower bounds on R(Phi_M) in terms of how unevenly information flows to the two parties. The main result (Theorem 4) is I_infty({M_i}) <= R(Phi_M), where I_infty is a regularized measure of information unevenness; this lower bound can be as large as 2 log d, improving on the earlier log d bound. The paper also disproves a geometric conjecture on unitarily maskable states, gives a channel-mixing theorem (Theorem 2) that bounds a subchannel's capacity by its mixing probability, and discusses applications to quantum secret sharing and black-hole fast-scrambling scenarios.","tokens_in":9969,"tokens_out":19762,"duration_ms":193509,"significance":"If the main theorem holds, it identifies the relevant resource measure for universal masking: not the average information flow but the evenness of information distribution across subchannels. The bound I_infty <= R is a genuine improvement over the previous log d bound and is saturated by known examples such as the quantum one-time pad. The paper is commendable for stating precise entropic inequalities and for providing a concrete counterexample to the geometric conjecture of Modi et al. The main results, however, are conditional on the imported decomposition theorem (Fact 1), and several proof steps need clarification. With those points addressed, this would be a useful contribution to quantum information theory.","major_comments":[{"comment":"Fact 1 is the load-bearing assumption for Theorems 3 and 4, but it is only cited, not proved. The paper assumes that every invertible universal masker can be written as Phi_M(rho)=sum_i p_i M_i rho M_i^dagger with M_i isometries having orthogonal images and with R(Phi_M)=S(sigma_S), and that this decomposition is unique up to degeneracy. If this structural theorem fails for some invertible constant-marginal channel, then Eq. (9) and the subsequent inequalities are not well defined for that channel. The authors should either provide a proof of Fact 1 in the appendix or cite a specific theorem in [4] (or [7,8]) and verify that its hypotheses match exactly.","section":"Introduction, Fact 1"},{"comment":"The e>0 part of the proof of Theorem 2 is not rigorous. The statement that 'one can only have up to 2^{ne}-fold probability enhancement' is asserted without a derivation, and the displayed inequality following the negation of the assumption appears to have a sign error: as printed it reads p_i^n(1-delta)>2^{ne}2^{n(1-epsilon)CEA(N_i)}, which cannot follow from CEA(N_i)-e>-log p_i; the intended comparison is with 2^{ne}/2^{n(1-epsilon)CEA(N_i)}. Since the exact masking application uses e=0, the main theorem survives, but the claimed robustness to incomplete masking is not established.","section":"Appendix, proof of Theorem 2"},{"comment":"The example intended to disprove speculation (13) is not valid as written. The embeddings M_{A,i} map the input into |i+d>_B for i=1,...,d, which is outside a d-dimensional H_B as used elsewhere in the paper. More seriously, the reduced state on A from the M_{A,i} subchannels is (1/(d+1))sum_i Z^i rho Z^{-i}, which equals (1/(d+1)) times the diagonal of rho in the Z basis, not a constant state; the contribution from the M_j subchannels is constant, so the total A marginal depends on the input. Thus the construction does not have constant margins and is not a universal masker. This example should be corrected or removed; it does not affect the proof of Theorem 4, but it weakens the discussion of the tightness of the bound.","section":"Main text, (Counter) Example"},{"comment":"The derivation of the one-shot bound (25) from Eq. (27) is too terse. In particular, the argument connecting the minimizing probability distribution in Eq. (27) with the optimizing subset S in the definition of I1 needs a more explicit proof that the greedy assignment attains the minimum and that its value is bounded below by H({2^{-I_i}}_{i in S0}). Please expand this step so that the proof of the main theorem is self-contained.","section":"Appendix, proof of Theorem 4"}],"minor_comments":[{"comment":"The statement labeled 'Theorem 3' in the appendix is actually the main text's Theorem 4; renumber to avoid confusion.","section":"Appendix, theorem numbering"},{"comment":"Several typos should be corrected, including 'with with' in the statement of Theorem 3 and 'hiden' and 'naively' in the introduction.","section":"Throughout"},{"comment":"The use of the Shannon entropy H for a subnormalized set {t_i} is unusual; the authors should emphasize that H({t_i}) is defined by the formula -sum t_i log t_i for nonnegative numbers that do not necessarily sum to one.","section":"Eq. (11)"},{"comment":"The dimensions of H_A and H_B should be clarified; the notation |i+d>_B suggests that H_B has dimension 2d, which contradicts the d x d convention used elsewhere in the paper.","section":"Main text, (Counter) Example"},{"comment":"The references [4] and [22] should be given with full publication details, as [22] currently appears only as a conference abstract.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The main concern is the reliance on Fact 1, which appears to come from the authors' own previous work without a proof in this manuscript. If Fact 1 is fully proved in [4], the central claim is likely sound, but the editor may wish to have a referee check that reference. The error in the (Counter) Example is localized and fixable. Overall, the paper fits the journal's scope and, after a major revision addressing the structural assumption and the example, could be a solid contribution."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: the paper proves a genuinely new lower bound on the randomness cost of quantum masking up to 2 log d instead of the previous log d, and gives a convincing counterexample to the disk conjecture of Modi et al. The bound is notable, and the counterexample is clean. The thing to know: the result is conditional on a decomposition theorem (Fact 1) taken from the authors' previous work, and the paper does not prove it. If that theorem holds, the core here is sound.\n\nWhat is actually new: the counterexample works for d≥4 and is a different family from the Ding-Hu qutrit counterexample; the measure I_infty of information unevenness is new; and Theorem 4's inequality R ≥ I_infty strengthens the old log d bound. The e=0 case of Theorem 2 is a neat coding argument and is enough for the masking application. The information conservation law route is clean and explains the log d floor.\n\nSoft spots: the e>0 part of Theorem 2 is heuristic—the authors assert a 2^{ne} probability enhancement without formal proof. That is fine for the main result, since masking is exactly the e=0 case. More substantively, Theorem 4 inherits Fact 1: every universal masker can be written as a probabilistic mixture of isometries with orthogonal images, and the entropy of the safe state equals the randomness cost. The paper states this as known from [4] but gives no proof. If some invertible masker has Kraus operators that are not proportional to orthogonal isometries, the main inequality would not cover it. I cannot find an actual counterexample, and the examples in the paper satisfy the decomposition, but the assumption is load-bearing. A referee should push for a proof or a precise statement of the theorem in [4].\n\nThe appendix proof of Theorem 4 is dense and has a few leaps, particularly in the step from the minimization over probability distributions to the Shannon entropy of a subset. It looks fixable, but it needs more detail. The black hole discussion is speculative, as the authors admit; it is a consistency test, not a prediction.\n\nBottom line: this paper is for the quantum information community, especially people working on masking, secret sharing, and the randomness cost of quantum operations. It deserves serious peer review. I would send it out and ask the authors to make the dependency on Fact 1 explicit and tighten the appendix.","headline":"New lower bound on randomness cost of masking and a counterexample to the disk conjecture; the bound is sound if you grant the decomposition theorem imported from the authors' earlier work.","tokens_in":10443,"tokens_out":12176,"would_cite":true,"duration_ms":119301,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper proves that masking quantum information costs randomness at least equal to the unevenness of how information splits between two parties, tightening the earlier lower bound and linking the cost to conservation of quantum…","keywords":["quantum masking","randomness cost","information conservation law","channel mixing","entanglement-assisted capacity","quantum secret sharing","black hole information paradox","no-hiding theorem"],"falsifier":"Find a $d$-dimensional universal masking process whose safe-state entropy $R(\\Phi_M)$ is strictly smaller than the regularized unevenness $I_\\infty(\\{M_i\\})$ computed from its bipartite embeddings. Concretely, perform complete process tomography on a candidate masker, reconstruct the subchannels and probabilities, compute $I_1$ on many copies and take the regularized limit, and compare it with $S(\\sigma_S)$; any violation would refute Theorem 4.","tokens_in":9477,"feed_emoji":"🎲","tokens_out":4852,"duration_ms":51769,"temperature":0.7,"pith_summary":"This paper tries to show that the randomness needed to mask quantum information is not governed by the total correlation between the two parties, but by how unevenly information flows to them. It proves that any universal quantum masking process must consume randomness at least as large as a regularized measure of this unevenness, a quantity between $\\log d$ and $2\\log d$ for $d$-dimensional systems. It also disproves a geometric conjecture about which states can be masked unitarily, replacing the geometric picture with an algebraic, information-conservation-based one. If correct, the result gives a quantitative consistency test for black-hole fast scrambling and a lower bound on entanglement needed for quantum secret sharing.","feed_headline":"Masking quantum information costs at least the unevenness of its flow","feed_subtitle":"The bound improves the earlier log d cost to up to 2 log d and tests black-hole scrambling.","key_machinery":"The central object is the decomposition of a universal quantum masker as a probabilistic mixture of bipartite embeddings, $\\Phi_M(\\rho)=\\sum_i p_i M_i\\rho M_i^\\dagger$, with a 'safe state' $\\sigma_S$ whose entropy $R(\\Phi_M)=S(\\sigma_S)$ is the randomness cost. The argument's engine is the information conservation law, which says that the mutual information between a reference system and the two output systems is conserved, so masking can only push information from one party to the other. This is combined with a channel-mixing tradeoff: if a subchannel $N_i$ has entanglement-assisted classical capacity exceeding the mixed channel's capacity by more than $-\\log p_i$, then the mixture could transmit more information than an erasure channel should allow, a contradiction. The measure $I_1$ and its regularization $I_\\infty$ capture the largest 'unevenness' of information flow across subchannels, and Theorem 4 bounds the randomness cost from below by $I_\\infty$.","core_discovery":"For any $d$-dimensional universal quantum masking process $\\Phi_M$ with decomposition into random bipartite embeddings $\\{M_i\\}$ with orthogonal images, the randomness cost $R(\\Phi_M)$ satisfies $I_\\infty(\\{M_i\\}) \\le R(\\Phi_M)$, where $I_\\infty$ is the regularized version of a measure $I_1$ quantifying how unevenly information is distributed between the two parties. This improves the previously known $\\log d$ lower bound to a quantity that can reach $2\\log d$. The paper further shows that the set of maskable states of an isometric quantum masker need not form a 'disk' in the sense conjectured earlier, by exhibiting a $d^2$-dimensional counterexample where the maskable set is not tied to any preferred product basis. All of these results are derived from a channel-mixing tradeoff combined with the information conservation law $2S(R)=I(R:A)+I(R:B)$, and they tolerate incomplete masking up to a small error.","pith_inferences":["The channel-mixing suppression theorem may be a general principle beyond masking: in any probabilistic mixture of quantum channels, a highly capable subchannel forces its mixing probability to be exponentially small, which could constrain randomized encoding and decoupling protocols.","The counterexample to the geometric conjecture suggests that masking can hide arbitrary quantum correlations, not just phase information relative to a fixed classical basis, so purely algebraic characterizations may be needed for general maskers.","Theorem 4 is directly testable: perform process tomography on a candidate masker, reconstruct the subchannels and their probabilities, compute the regularized unevenness measure, and compare it with the entropy of the safe state; a violation would refute the bound.","One could extend the black-hole consistency test to concrete evaporation models by numerically estimating $I_\\infty$ from proposed internal unitaries, yielding quantitative predictions for how many qubits can be reflected at a given entanglement entropy."],"forward_implications":["The randomness cost of masking is minimal when each subchannel distributes information as evenly as possible, saturating the bound as in quantum one-time pad and the four-qubit masker.","A masking process in which information flows entirely to one party in half of the subchannels and entirely to the other in the other half must spend close to $2\\log d$ bits of randomness.","For approximate masking with error $e$, the bounds remain valid after replacing each $I_i$ by $I_i-e$, so the result applies to realistic imperfect masking devices.","Every quantum masker induces a $(2,3)$-threshold quantum secret sharing scheme, so the lower bound estimates the sizes of unauthorized sets in pure $(k,2k+1)$-threshold protocols.","For black-hole evaporation modeled as masking, the inequality $I_\\infty(\\{M_i\\}) \\le c(t_*)S(T)$ provides a consistency check between the scrambling time, the evaporation dynamics, and the black hole's entanglement entropy."],"supporting_citations":[{"why":"Formulates the geometric conjecture about unitarily maskable states that the paper disproves.","marker":"[3]"},{"why":"Establishes the earlier $\\log d$ randomness-cost lower bound and supplies the four-qubit masker example that Theorem 4 improves and saturates.","marker":"[4]"},{"why":"Provides the no-hiding theorem, which the paper uses to turn masking into secret sharing and to derive consequences of the information conservation law.","marker":"[2]"},{"why":"Supplies the characterization of entanglement-assisted classical capacity used to bound subchannel probabilities in Theorem 2.","marker":"[9]"},{"why":"Completes the entanglement-assisted capacity formula that converts the channel-mixing bound into mutual-information inequalities.","marker":"[10]"},{"why":"Provides the fast-scrambling black-hole model whose consistency the randomness-cost bound is used to test.","marker":"[5]"},{"why":"Defines pure $(k,2k+1)$-threshold quantum secret sharing, which the paper uses to estimate unauthorized set sizes from the masking lower bound.","marker":"[15]"},{"why":"Gives the concavity and subadditivity properties of von Neumann entropy used in the proofs of Theorems 1 and 3.","marker":"[23]"},{"why":"Supplies the quantum one-time pad as an example where the lower bound is saturated.","marker":"[11]"}],"fun_headline_variants":["Quantum masking randomness bounded by info unevenness","Info conservation law fixes quantum masking randomness cost","Quantum masking randomness: up to 2 log d from info unevenness","Masking quantum info: uneven flow raises randomness cost"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proofs assume that every universal quantum masker can be represented exactly as a probabilistic mixture of isometries with a safe state whose von Neumann entropy is the true randomness cost; if some masker required a different accounting of randomness, the lower bounds would not apply to it.","fun_headline_variants_meta":{"raw":{"variants":["Quantum masking randomness bounded by info unevenness","Info conservation law fixes quantum masking randomness cost","Quantum masking randomness: up to 2 log d from info unevenness","Masking quantum info: uneven flow raises randomness cost"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000691,"raw_usage":{"total_tokens":3115,"prompt_tokens":920,"completion_tokens":2195,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":536,"completion_tokens_details":{"reasoning_tokens":2132}},"tokens_in":536,"tokens_out":2195,"duration_ms":17026,"temperature":1.0,"reasoning_tokens":2132,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T12:18:42.660809+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Find a $d$-dimensional universal masking process whose safe-state entropy $R(\\Phi_M)$ is strictly smaller than the regularized unevenness $I_\\infty(\\{M_i\\})$ computed from its bipartite embeddings. Concretely, perform complete process tomography on a candidate masker, reconstruct the subchannels and probabilities, compute $I_1$ on many copies and take the regularized limit, and compare it with $S(\\sigma_S)$; any violation would refute Theorem 4.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Formulates the geometric conjecture about unitarily maskable states that the paper disproves."},{"cited_title":"Quantum one-time tables for unconditionally secure qubit-commitment","cited_arxiv_id":"1903.12304","evidence_quote":"Establishes the earlier $\\log d$ randomness-cost lower bound and supplies the four-qubit masker example that Theorem 4 improves and saturates."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the no-hiding theorem, which the paper uses to turn masking into secret sharing and to derive consequences of the information conservation law."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the characterization of entanglement-assisted classical capacity used to bound subchannel probabilities in Theorem 2."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Completes the entanglement-assisted capacity formula that converts the channel-mixing bound into mutual-information inequalities."},{"cited_title":"Hayden and J","cited_arxiv_id":null,"evidence_quote":"Provides the fast-scrambling black-hole model whose consistency the randomness-cost bound is used to test."},{"cited_title":"Cleve, D","cited_arxiv_id":null,"evidence_quote":"Defines pure $(k,2k+1)$-threshold quantum secret sharing, which the paper uses to estimate unauthorized set sizes from the masking lower bound."}],"review_version":1}