{"id":"4cc23f10-3167-4913-b88f-a9d3b23b3658","arxiv_id":"2411.13712","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A fully integrated silicon photonic chip demonstrates a measurement-device-independent self-testing quantum random number generator with a certifiable expansion rate of 5.11e-4 per round at 10 MHz.","lead":"Researchers built a silicon photonic chip that runs a self-testing quantum random number generation protocol, producing random bits whose security is verified during operation by checking the detector's response. The chip is a step toward compact, manufacturable quantum randomness generators with stronger security guarantees than current trusted-device designs.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The experiment's input randomness comes from a 100-bit PRG, while the proof requires private i.i.d. true randomness; the 15.33 Mbits of certified expansion is therefore not established for the data as taken.","rationale":"The reader's weakest-assumption analysis identifies the same load-bearing concern that I would: the protocol's security proof requires private, trusted, i.i.d. random inputs, while the experiment generates all inputs from a 100-bit pseudorandom seed. This is not a critique of the underlying self-testing protocol or of the chip's measured performance; the homodyne efficiency, CMRR, score distributions, and rate simulations are plausible and provide real evidence of the hardware's capability. The concern is about whether the specific experimental run can be called certified randomness expansion. A 100-bit PRG cannot supply the n[h2(γ)+2γ] bits of input entropy assumed in Eq. (20), and a deterministic PRG output is not independent of the device in the information-theoretic sense used by the EAT. Therefore the 15.33 Mbits claim is not supported for the data as collected. This is addressable in a revised manuscript by either rerunning with a trusted physical RNG or clearly stating that the reported number is a projected rate for a production input source rather than a fully certified output of the demonstrated run. Because the theory and chip-level results remain strong and the gap is an implementation assumption rather than a mathematical contradiction, the appropriate verdict remains CONDITIONAL, matching the reader's recommendation.","tokens_in":21292,"tokens_out":12993,"duration_ms":126841,"concrete_test":"Rerun the randomness expansion with inputs generated by a trusted physical RNG, such as an independent, characterised QRNG or vacuum-noise sampler isolated from the device, instead of the 100-bit PRG, keeping all other parameters in Table I unchanged. If the score constraints in Eq. (3) are satisfied and the post-extraction net output reaches 15.33 Mbits, the concern is resolved. As a cheaper analytic cross-check, replace the input-entropy term n[h2(γ)+2γ] in Eq. (36) with at most 100 bits (or 0 if the PRG output is public) and recompute the certified output length ℓ; if ℓ falls below the claimed 15.33 Mbits, or if the EAT step cannot be closed under deterministic inputs, the reported expansion rate is not certified for the experiment as implemented.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing gap is in the input-generation step of the proof-of-principle, not in the chip physics. The soundness argument in Methods VIII A assumes that the protocol inputs T, X, Y are drawn from a private, trusted, i.i.d. random source independent of the adversary (Assumption 4), and Eq. (20) assigns them entropy H(TXY|E) = n[h2(γ)+2γ], which for the chosen parameters is about 0.769n bits. Section VI states that the input generation step uses a pseudorandom input with a length of 100. A 100-bit seed cannot supply roughly 0.769n input bits for n = 3e10, and the PRG output is not private i.i.d. randomness in the sense required by the proof. Consequently, the EAT chain rule and QAEP step in Eqs. (16)-(20) do not apply to the demonstrated run. Since the headline 15.33 Mbits of certifiable randomness is computed from the full n = 3e10 protocol with that input-entropy term, the experimental data as taken do not currently establish the claimed certified expansion. This is a gap between the proof's assumptions and the experiment's implementation, not evidence that the protocol or chip is physically wrong; a production version with a trusted physical RNG could plausibly close it, but the paper does not demonstrate that closure.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper develops a semi-device-independent, measurement-device-independent QRNG protocol using QPSK coherent states and an untrusted homodyne detector, with the score distribution monitored via fine-grained binning. Security is analyzed with the entropy accumulation theorem and a min-tradeoff function, and the protocol is implemented on a silicon photonic chip with integrated IQ modulator, phase modulator, tunable beam splitter, and balanced homodyne detector. The authors claim a net randomness expansion rate of 5.11e-4 at 10 MHz, corresponding to 15.33 Mbits of certifiable randomness per run for n=3e10 rounds, and report a total homodyne efficiency of 69.1%.","tokens_in":21586,"tokens_out":8931,"duration_ms":94147,"significance":"If fully supported, this would be an important advance: it combines a room-temperature, fully integrated silicon photonic platform with a self-testing protocol that does not require a characterized detector, and it shows tolerance to detection efficiencies down to about 67%. The chip-engineering achievements are substantial and well documented: the phase-loss-compensated modulators, the >65 dB common-mode rejection, and the careful efficiency accounting are credible and useful contributions. However, the headline claim of certified randomness expansion is not currently established because the experimental input generation violates a central assumption of the security proof, and the security analysis is not self-contained because the min-tradeoff function is borrowed from Ref. [18] without its SDP construction or dual certificates. The protocol and chip are nevertheless a valuable proof-of-principle that could be made rigorous with additional work.","major_comments":[{"comment":"The soundness proof assumes that the protocol inputs T, X, Y are drawn from a private, trusted, i.i.d. random source independent of the adversary, and Eq. (20) credits these inputs with n[h2(gamma)+2gamma] bits of entropy. For the stated parameters (n=3e10, gamma=0.12), this is about 2.3e10 bits per run. Section VI states that the experiment uses a 100-bit pseudorandom input. A pseudorandom expansion of a 100-bit seed cannot supply this entropy, and the PRG output is deterministic given the seed, so it is not i.i.d. and not independent of the adversary in the sense required by Assumption 4. Consequently, the QAEP and EAT steps in Eqs. (16)-(23) do not apply to the demonstrated data, and the claimed 15.33 Mbits of certifiable randomness is not established. To support the claim, the experiment must use a trusted physical randomness source for all protocol inputs (with its entropy explicitly accounted), or the manuscript must clearly restrict the demonstration to a proof-of-principle device characterization and remove or qualify the certified-expansion claim.","section":"Sec. VI and Methods VIII A, Assumption 4 and Eq. (20)"},{"comment":"The security bound depends on the min-tradeoff function through the constants alpha_nu and lambda_nu, obtained, according to the text, by taking the dual of the SDP in Eq. (21) and following the derivation of Theorem 1 in Ref. [18]. The manuscript does not provide the SDP construction, the affine bounds, the numerical values of alpha_nu and lambda_nu for the six-bin configuration, or the dual certificates used to enforce Eq. (22). Since these constants enter h, V, and K in Eqs. (24)-(26), the reported rates cannot be independently verified from this paper. Please include the full SDP formulation and the numerical constants, or supply supplementary code that generates them.","section":"Methods VIII A, Eqs. (23)-(26)"}],"minor_comments":[{"comment":"Please specify the pseudorandom generator algorithm and the source of its 100-bit seed, and state explicitly whether the seed is assumed secret and trusted. As written, the description is insufficient to assess any security argument.","section":"Sec. VI"},{"comment":"The listed parameters are inconsistent: with epsilon_ext = 1e-6 and epsilon_s = 4.99e-7, Eq. (15) gives epsilon_sou = 2epsilon_s + epsilon_ext = 1.998e-6, not the listed 1e-6. Please reconcile the soundness parameter or the smoothing parameter.","section":"Table I and Eq. (15)"},{"comment":"There are several typographical errors, including 'particulary' in the Introduction, 'Mazh-Zehnder' in Section I, 'Homodyme' in the Discussion, 'Lecory' in Section VIII B, and 'randomeness' in the Author Contributions section.","section":"Throughout"},{"comment":"The score-assignment table in Fig. 1(b) is difficult to read at the printed size; larger fonts and clearer separation between the X and P score blocks would improve readability.","section":"Fig. 1(b)"},{"comment":"The claim of being the 'first self-testing QRNG chip with a fully integrated encoder and decoder' should be carefully qualified relative to previous chip-based self-testing demonstrations, such as Refs. [24] and [35], to make the precise novelty clear.","section":"Introduction"}],"recommendation":"major_revision","confidential_remarks":"The input-seed gap is the central issue: the experimental data as presented do not meet the assumptions of the security proof, so the headline certified-randomness number should not be stated as established. I do not recommend rejection, because the protocol and the integrated chip are valuable and the gap could plausibly be closed by a new experiment with a trusted physical RNG or by a carefully qualified presentation. The missing SDP details and the Table I inconsistency should also be addressed in revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Worth your time. This group has actually put a self-testing MDI-QRNG on a silicon photonic chip, with the encoder and detector integrated, room-temperature homodyne, and a protocol that tolerates detector efficiency down to 67%. That is a first, as far as I know, and the engineering is careful: the push-push MZM trick to kill phase-dependent loss, the integrated balanced detector with 69.1% efficiency and >65 dB CMRR, and the data in Fig. 5 all look solid. The multi-bin extension of their Ref [18] protocol is a real improvement, not a token tweak.\n\nThe soft spots are in the gap between the proof and the demonstration. The proof (Methods VIII A) assumes the inputs T, X, Y are private, trusted, i.i.d. randomness, and Eq. (20) gives them entropy n[h2(γ)+2γ] ≈ 0.769n bits. In the experiment they used a 100-bit pseudorandom seed (Section VI). That is not the same thing. A 100-bit seed has at most 100 bits of entropy, so the chain-rule step in Eq. (20) does not apply to the data as taken. The net rate might survive if the seed is private and the PRG is deterministic, but the paper doesn't make that argument. As written, the certified randomness claim is not backed for the actual run.\n\nSecond, the 15.33 Mbits appears to be a projection for n=3e10 rounds, not a statement about what was actually extracted. The paper says 'the experiment generated 15.33 Mbits,' but the data collection is described in blocks of 2.5e7 rounds and the total number of blocks isn't given. Someone needs to clarify whether the extractor was run on the full 3e10 rounds or whether this is a rate multiplied by an assumed n.\n\nThird, the security bound borrows the SDP min-tradeoff from Ref [18] without giving the dual constants for the 4, 6, 8-bin cases. Since that's the core of the rate calculation, a referee should ask for the certificates or at least the numerical values.\n\nThe block-discarding based on amplitude drift is a minor concern; because the source is trusted, it looks like calibration rather than a security loophole, but the paper should say why.\n\nBottom line: the chip is a genuine step forward, and the protocol extension is meaningful. The gaps are fixable in revision. This deserves a serious referee.","headline":"First integrated-chip MDI-QRNG with homodyne self-testing; chip work is real, but security claim needs clearer accounting of PRG inputs and extrapolated bit count.","tokens_in":22155,"tokens_out":10639,"would_cite":true,"duration_ms":991506,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P45","81P68"],"pacs":["03.67.-a"],"model":"deepseek-v4-flash","headline":"A silicon photonic chip with fully integrated encoder and decoder self-tests its quantum randomness, certifying 15.33 Mbits of fresh output per run despite an untrusted homodyne detector.","keywords":["self-testing quantum random number generator","measurement-device-independent","silicon photonic chip","homodyne detection","continuous-variable quantum information","quantum randomness expansion","entropy accumulation theorem","QPSK coherent states"],"falsifier":"Run the protocol with the trusted input source replaced by a publicly known seed and with a detector engineered to reproduce the accepted score frequencies; if the extractor output can be predicted from that seed, the certified-randomness claim is false.","tokens_in":21065,"feed_emoji":"🎲","tokens_out":11262,"duration_ms":106906,"temperature":0.7,"pith_summary":"This paper aims to show that self-testing quantum randomness expansion can be put on a fully integrated silicon photonic chip operating at room temperature. The chip produces random numbers whose security is certified in real time by the measured score distribution, with the homodyne detector treated as untrusted while the state source remains trusted. In a proof-of-principle run with $3\\times10^{10}$ rounds at 10 MHz repetition rate it generated 15.33 Mbits of certified fresh randomness per run, an expansion rate of $5.11\\times10^{-4}$. The significance is practical: if the protocol and chip design are sound, certified randomness with detector self-testing can be mass-produced on standard foundry processes, replacing trusted-detector models in small-footprint devices.","feed_headline":"Integrated chip certifies 15.33 Mbits of randomness per run","feed_subtitle":"Detector stays untrusted: a score test certifies the random output on a silicon photonic chip.","key_machinery":"The carrying object is a prepare-and-measure game $G$: Alice prepares one of four coherent states $|\\sqrt{\\mu}e^{ix\\pi/2}\\rangle$ with $x\\in\\{0,1,2,3\\}$, Bob measures with an untrusted homodyne detector in one of two settings (local-oscillator phase 0 or $\\pi/2$), and the continuous outcome is binned into $2m$ bins and assigned a score $c$ by Eq. (1). Security flows from the min-tradeoff function $f_\\nu$: a semidefinite-programming-derived upper bound on the single-round guessing probability compatible with the observed score distribution, which the entropy accumulation theorem converts into a lower bound on the total smooth min-entropy of the raw string against the adversary's quantum side information. On the hardware side, the phase-loss independence machinery does the load-bearing work: an IQ modulator driven at $\\pm0.1$ V avoids phase-dependent loss in encoding, and a push-push Mach-Zehnder modulator at an optimum ratio $r\\approx0.6$ makes the basis-selection phase shift loss-free, preserving the 69.1% total homodyne efficiency that keeps the rate positive.","core_discovery":"The central discovery claim is that a measurement-device-independent QRNG protocol using four QPSK coherent states and an untrusted homodyne receiver can certify randomness expansion on a chip: the protocol accepts only when empirical score frequencies fall within a tolerance of the ideal distribution, and the entropy accumulation theorem then lower-bounds the smooth min-entropy of the raw string against quantum side information. The experiment integrates the encoder and decoder on silicon: an IQ modulator encodes the four states, a push-push Mach-Zehnder modulator selects the measurement basis without phase-dependent loss, and an on-chip balanced homodyne detector with total efficiency 69.1% measures the $X$ or $P$ quadrature, binned into 6 or 2 outcomes. Running $n=3\\times10^{10}$ rounds with state amplitude $\\sqrt{\\mu}=0.0672$ and test probability $\\gamma=0.12$, the measured score distribution passed, yielding 15.33 Mbits of certifiable randomness at expansion rate $5.11\\times10^{-4}$ at 10 MHz repetition. The authors claim this is the first self-testing QRNG chip with a fully integrated encoder and decoder operating at room temperature.","pith_inferences":["Editorial inference: in the proof-of-principle run, the trusted-input assumption is not met, because the 100-bit pseudorandom seed is not a private physical source; a deployable version needs a hardware random source for inputs before the certified numbers can be claimed.","Editorial inference: the self-testing guarantee covers only the measurement device and channel; the state-preparation unit and the classical post-processing remain trusted, so the result is semi-device-independent rather than fully device-independent.","Editorial inference: since the protocol recycles input randomness by hashing and assumes inputs never leak, an input-side side channel would silently destroy the expansion; the input source isolation is as essential as the score test.","Editorial inference: the same score-certified homodyne approach could be adapted to other continuous-variable tasks needing an untrusted receiver, such as measurement-device-independent quantum key distribution with trusted transmitters, but this paper does not analyse that extension."],"forward_implications":["A fully integrated, room-temperature self-testing QRNG is manufacturable on standard silicon photonics foundry platforms, with only the laser remaining off-chip.","Operators can certify detector integrity during operation from the score distribution alone, without a trusted characterisation of the homodyne detector.","The protocol remains positive-rate down to homodyne efficiencies near 67 percent, matching the loss and noise budget of integrated photonics.","With upgraded components (92.4 percent photodiode quantum efficiency at 1550 nm), the simulated expansion rate improves by roughly two orders of magnitude.","The bandwidth of the integrated modulators and detectors supports clock rates far above the 10 MHz used here, so the per-run output can scale substantially."],"supporting_citations":[{"why":"This is the previous provably-secure QRNG protocol with uncharacterised homodyne detection that the present work upgrades; it supplies the protocol structure, the SDP-based min-tradeoff construction, and the 2-bin baseline data.","marker":"[18]"},{"why":"It provides the universal binomial inequalities used to bound the completeness error of the protocol's statistical test.","marker":"[59]"},{"why":"It supplies the leftover-hashing lemma against quantum side information, which turns the smooth min-entropy bound into a uniform output string.","marker":"[60]"},{"why":"It gives the chain rules for smooth min- and max-entropies used to split the total entropy between measurement outputs and protocol inputs.","marker":"[61]"},{"why":"It provides the quantum asymptotic equipartition property used to bound the entropy contributed by the i.i.d. input randomness.","marker":"[62]"},{"why":"It supplies the entropy accumulation theorem with improved second-order term that converts per-round min-tradeoff bounds into a total smooth min-entropy bound.","marker":"[65]"},{"why":"It provides the entropy accumulation theorem and the version of the QAEP corollary that the soundness proof invokes.","marker":"[66]"},{"why":"It gives the framework for constructing min-tradeoff functions from single-round guessing probabilities subject to score constraints.","marker":"[67]"},{"why":"It provides the method for characterising prepare-and-measure quantum network correlations needed to compute the guessing-probability bound by semidefinite programming.","marker":"[68]"}],"fun_headline_variants":["Self-testing chip certifies 15.33 Mbits of randomness","Integrated chip certifies quantum randomness without trusting its detector","Photonic chip self-tests its randomness: 15.33 Mbits","Quantum randomness certified on chip, detector untrusted"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof's soundness rests on the assumption that every protocol input is drawn from a private, trusted, i.i.d. random source uncorrelated with the adversary, whereas the demonstration generates inputs from a pseudorandom 100-bit seed.","fun_headline_variants_meta":{"raw":{"variants":["Self-testing chip certifies 15.33 Mbits of randomness","Integrated chip certifies quantum randomness without trusting its detector","Photonic chip self-tests its randomness: 15.33 Mbits","Quantum randomness certified on chip, detector untrusted"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000949,"raw_usage":{"total_tokens":4054,"prompt_tokens":955,"completion_tokens":3099,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":571,"completion_tokens_details":{"reasoning_tokens":3028}},"tokens_in":571,"tokens_out":3099,"duration_ms":22393,"temperature":1.0,"reasoning_tokens":3028,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T15:58:42.365498+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the protocol with the trusted input source replaced by a publicly known seed and with a detector engineered to reproduce the accepted score frequencies; if the extractor output can be predicted from that seed, the certified-randomness claim is false.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"This is the previous provably-secure QRNG protocol with uncharacterised homodyne detection that the present work upgrades; it supplies the protocol structure, the SDP-based min-tradeoff construction, and the 2-bin baseline data."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"It provides the universal binomial inequalities used to bound the completeness error of the protocol's statistical test."},{"cited_title":"Zhang, J","cited_arxiv_id":null,"evidence_quote":"It gives the chain rules for smooth min- and max-entropies used to split the total entropy between measurement outputs and protocol inputs."},{"cited_title":"Bunandar, A","cited_arxiv_id":null,"evidence_quote":"It provides the quantum asymptotic equipartition property used to bound the entropy contributed by the i.i.d. input randomness."},{"cited_title":"Dupuis, O","cited_arxiv_id":null,"evidence_quote":"It provides the entropy accumulation theorem and the version of the QAEP corollary that the soundness proof invokes."},{"cited_title":"Milovanˇ cev, F","cited_arxiv_id":null,"evidence_quote":"It gives the framework for constructing min-tradeoff functions from single-round guessing probabilities subject to score constraints."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"It provides the method for characterising prepare-and-measure quantum network correlations needed to compute the guessing-probability bound by semidefinite programming."}],"review_version":1}