{"id":"ccbbca18-a407-4334-b784-b6dd255013b1","arxiv_id":"2411.14890","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":7,"one_line_summary":"First experimental demonstration of three-user measurement-device-independent quantum cryptographic conferencing with four-intensity decoy states.","lead":"Three independent users shared a conference key through a measurement-device-independent quantum protocol, using a Greenberger-Horne-Zeilinger state projection at an untrusted central node. The experiment ran about 22 hours and produced secure key rates of 0.097 to 7.54 bits per second under simulated channel losses of 14 to 21 dB.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The symmetric-source assumption in S3.1 is load-bearing but evidenced; the active mid-run system adjustment without disclosed data-selection rules is the sharper reproducibility concern.","rationale":"The reader's conditional verdict is appropriate. The reader's weakest-assumption pinpoints the symmetric-source assumption in S3.1, which is indeed a load-bearing condition of the decoy analysis, but the paper provides per-user polarization fidelity data and identical source hardware, so a stronger attack is the undisclosed active mid-run adjustment and the lack of any data-selection rule. The paper explicitly states in S2 that the system is adjusted 1-3 times during the ~23 h measurement, and no rejection criterion is disclosed. In a finite-size decoy-state analysis with 10^-10 failure probability, small changes in the effective gains and QBERs can shift the estimated single-photon yield and phase error, and the 21.5 dB rate of 0.097 bps is the natural place for such sensitivity to matter. The S3.1 identical-sources assumption is a close second; the derivation of the Y_111 lower bound explicitly cancels (2,1,1)-type terms using a_s_n = b_s_n = c_s_n, and a drift of even a few percent between users could bias the bound. However, because the main text states the users use the same light sources and Table S2 reports similar state fidelities, this assumption is partially evidenced. The recommendation remains CONDITIONAL: the revised manuscript should disclose the data-selection procedure, provide error bars on the key-rate points, and state the measured per-user intensities used in the decoy analysis. My concern does not reject the demonstration; it narrows the part of the claim that needs strengthening.","tokens_in":23778,"tokens_out":2106,"duration_ms":17964,"concrete_test":"Reconstruct the key-rate pipeline from the raw per-1000-second QBER records as follows: rerun the decoy-state analysis of S3.1 on the 14.1 dB and 21.5 dB datasets with a Monte Carlo resampling of the integrity-check procedure (retain all data, drop the 1000 s window immediately after each adjustment, and drop all data after the third adjustment). If the resulting key rates vary by more than 15% at 21.5 dB, the reported 0.097 bps value is not robust to reasonable data-selection choices. If the published rates differ by less than 15% across all three rules, the concern is refuted. Separately verify Eq. (S3.15) by expanding both sides without invoking the identical-sources equality; if a_s_n, b_s_n, c_s_n are replaced by measured per-user intensities differing by 2%, compute the resulting bias in Y_111 and determine whether the finite-key rate at 21.5 dB remains positive.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The paper asserts measured conference key rates of 7.54, 1.17, and 0.097 bps at 14.1, 17.8, and 21.5 dB, based on a single 8×10^4 s run that includes active system adjustments: S2 states 'we check the QBER X and QBER Z every 1000 seconds and adjust the system if the error rate is too high to generate the secure key. We adjusted the system on average 1 ∼ 3 times during the measurement time of about 23 hours.' No rule is given for which data windows are retained, discarded, or realigned after an adjustment. If the high-loss dataset (21.5 dB, only 0.097 bps) is the most sensitive to small changes in the parameters used in the decoy analysis, then an undisclosed selection procedure could materially change the reported R. The central claim, 'we experimentally realize the three-user MDIQCC protocol with four-intensity decoy-state method,' does not strictly require R to remain positive under every possible data-handling rule, but the quantitative key-rate values in Fig. 4 and Table S5 are the paper's headline experimental output, so the active adjustment with no exclusion criterion is the most load-bearing soft spot. The decoy-state mathematics in S3.1 also rests on the identical-sources assumption a_s_n = b_s_n = c_s_n; however, the calibration data (Table S2) shows similar fidelities and the main text states users use the same kind of source, so I do not judge the symmetry assumption to be the decisive weakness. A separate check: the GHZ-HOM visibility of 21.80±0.18% is below the ideal 25%, and the phase-error bound in S3.1 is only as good as the X-basis error model; but that is a standard, stated imperfection rather than a hidden flaw.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper reports an experimental demonstration of measurement-device-independent quantum cryptographic conferencing (MDI-QCC) with three users, using weak coherent pulses, polarization encoding, and a GHZ-state projection analyzer. The authors implement a four-intensity decoy-state protocol and use a Chernoff-bound finite-size analysis to estimate the single-photon yield and phase-error rate. They report conference key rates of 7.54, 1.17, and 0.097 bps at overall attenuations of 14.1, 17.8, and 21.5 dB over 8×10^4 s, based on a single run with active system stabilization every 1000 s. The supplementary material derives the four-intensity decoy-state bounds and provides the experimental data tables.","tokens_in":24245,"tokens_out":12906,"duration_ms":117816,"significance":"If the claims hold, this is an important experimental step: it shows that the MDI approach to quantum key distribution can be extended to multipartite conference-key agreement with practical weak coherent pulses and decoy states, avoiding detector side channels. The work includes a self-contained decoy-state derivation, finite-size analysis, and detailed stability and calibration data, which are strengths. The main limitations are the use of simulated channel loss (EVOAs) rather than real fiber spans, and the reliance on assumptions that need to be made explicit before the quantitative key-rate claims can be fully accepted.","major_comments":[{"comment":"Section S2 states that the authors check QBER X and QBER Z every 1000 seconds and adjust the system 1–3 times during the 23-hour run, but no rule is given for how data acquired before an adjustment is treated. If data windows with high error rate were excluded or re-synchronized after the adjustment, the reported key rates in Table S5 could be materially affected, particularly the 21.5-dB point with 0.097 bps. Please specify the exact data-handling procedure, whether any data were discarded, and report the key rates under a conservative inclusion of all data.","section":"S2, data-handling during active adjustments"},{"comment":"The derivation of the lower bound in Eq. (S3.15) relies on the assumption a_s_n = b_s_n = c_s_n, stated in S3.1. The experiment uses three independent lasers and separate intensity modulators/EVOAs, but the paper provides no per-user measurement of mean photon number or of the accuracy to which the three intensities are matched. The polarization fidelities in Table S2 do not constrain the photon-number statistics. If the user intensities differ, the cancellation of (2,1,1)-type terms in Eq. (S3.11) is invalid and the reported finite-size key rates may be overestimated. Please provide per-user intensity calibration and a sensitivity analysis, or perform an asymmetric decoy-state analysis.","section":"S3.1, Eq. (S3.11)–(S3.15)"}],"minor_comments":[{"comment":"The dark count probability is quoted as 'about 10^-6' in the Table S5 remark, while the main text gives a dark count rate of 250 Hz with a 156.25-ps coincidence window; please clarify the units and reconcile the numbers.","section":"Main text and Table S5"},{"comment":"The theoretical curves use a fixed misalignment error e_d = 2.25% and the text says 'take the interference visibility into consideration'; please state how e_d was determined from the measured GHZ-HOM visibility and whether the same value is used in the experimental data analysis.","section":"Fig. 4"},{"comment":"The phrase 'three-user quantum communication network' is stronger than what is demonstrated, since all channel losses are simulated by EVOAs in a single lab; suggest 'three-user MDI-QCC link with simulated channel loss'.","section":"Abstract"},{"comment":"The 'Note Added' should be integrated into the introduction with a brief comparison to Ref. [67], so that the reader can assess the novelty relative to the concurrent work.","section":"Note Added"}],"recommendation":"major_revision","confidential_remarks":"The experimental work appears technically sound, and the supplementary decoy-state derivation is consistent under its stated assumptions. The main concerns are the undisclosed data-handling rule during active adjustments and the lack of direct evidence for the identical-sources assumption; both are fixable with additional measurements or analysis. The overlap with the concurrent work in Ref. [67] is acknowledged, but the authors should position their contribution more explicitly in the introduction."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"This is a solid experimental demonstration—one of the first two, by the authors' own note—of three-user MDI quantum cryptographic conferencing with four-intensity decoy states. Three independent lasers are frequency-locked to within 5 MHz for 30+ hours, polarization-encoded weak coherent pulses are sent to a GHZ-state analyzer, and finite-size conference keys are extracted: 7.54, 1.17, and 0.097 bps at 14.1, 17.8, and 21.5 dB overall attenuation. Table S5 gives the measured gains and error counts needed to check those rates, which is the right kind of reporting.\n\nThe decoy analysis in S3.1 is a standard adaptation of Zhou et al. and Jiang et al., and the algebra checks out: the chosen linear combination cancels the sum-4 terms and gives a valid lower bound on Y_111, under the stated symmetric-source assumption. The GHZ-HOM visibility around 21.8% is consistent with the quoted QBER X of ~39.1%. The math is not the weak part.\n\nThe soft spots are procedural and presentational. First, the active system adjustment: the supplement says the users checked QBER every 1000 s and adjusted the system on average 1–3 times per 23-hour run, but no rule is given for which data windows are retained, realigned, or discarded after an adjustment. At 21.5 dB the key rate is 0.097 bps—roughly 2.6 bits over the whole run—so that number is sensitive to how those windows are treated. The central claim survives, but the quantitative rates need a disclosed data-selection protocol to be reproducible. Second, the identical-source assumption a_s_n = b_s_n = c_s_n is load-bearing for the yield bound; the calibration data make it plausible, but a sentence on sensitivity to intensity mismatch would be honest. Third, the claimed ~110x improvement over the three-intensity protocol is from simulation, not measurement—the experiment never ran the three-intensity protocol, and the paper should say that plainly. Minor: no error bars on the key rates.\n\nThis is a proof-of-principle over attenuators, not a deployed network, but that is the right scope for the claim. The paper deserves a serious referee; the revision should disclose the adjustment procedure, separate simulated from measured enhancements, and add a short sensitivity discussion for the symmetric-source assumption.","headline":"Solid first experimental realization of three-user MDI QCC with four-intensity decoys; the main soft spot is the undisclosed data-selection rule during active system adjustment.","tokens_in":24719,"tokens_out":3163,"would_cite":true,"duration_ms":28628,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Hk"],"model":"deepseek-v4-flash","headline":"This paper experimentally demonstrates a three-user measurement-device-independent quantum cryptographic conferencing protocol using four-intensity decoy states and GHZ-state projection, producing secure conference keys.","keywords":["measurement-device-independent","quantum cryptographic conferencing","GHZ-state projection","decoy-state method","polarization encoding","finite-size key rate","weak coherent pulses","quantum network"],"falsifier":"Independently measure each user's photon-number distribution and the three-user joint gains, then recompute the single-photon yield bound without the identical-source assumption; if the quoted key rates cannot be reproduced with realistic per-user statistics, the central claim of secure finite-size key generation would be falsified.","tokens_in":23557,"feed_emoji":"🔐","tokens_out":7500,"duration_ms":65221,"temperature":0.7,"pith_summary":"This paper reports a working three-user quantum cryptographic conferencing setup in which the detection equipment can be completely untrusted. It shows that three parties can share a secure conference key by sending weak laser pulses to a central Greenberger-Horne-Zeilinger (GHZ) state analyzer, with no need to prepare or distribute fragile multipartite entangled states. The authors adapt the four-intensity decoy-state method to the three-user protocol, which lets them estimate the single-photon yield and phase error rate from finite data, and they measure conference key rates of 7.54, 1.17, and 0.097 bits per second at total attenuations of 14.1, 17.8, and 21.5 dB. The result matters because it moves measurement-device-independent conference key agreement from theory to a practical, loss-tolerant network node.","feed_headline":"Three-user conference key secured without trusted detectors","feed_subtitle":"GHZ projection plus four decoy intensities yields 7.54 bps at 14.1 dB loss.","key_machinery":"The load-bearing object is the GHZ-state analyzer at the untrusted detection node combined with the four-intensity decoy-state protocol. The analyzer uses three pairs of polarization beam splitters and half-wave plates to project three incoming photons onto the $|\\Phi^{\\pm}\\rangle$ basis; the four intensity settings $\\mu_z,\\mu_x,\\mu_y,0$ allow the users to estimate the yield $Y^{Z}_{111}$ and phase error rate $e^{PZ}_{111}$ of the single-photon components without trusting any detector. The decoy analysis uses the assumption that all three users have identical photon-number statistics to cancel unwanted multi-photon terms, and finite-size Chernoff-bound joint constraints turn measured counts into rigorous key-rate bounds.","core_discovery":"The central claim is that measurement-device-independent quantum cryptographic conferencing is experimentally realizable. Three users Alice, Bob, and Charlie each prepare phase-randomized weak coherent pulses with four intensity settings, encode signal states in the Z basis and decoy states in the X basis, and send them to an untrusted relay containing a GHZ-state analyzer. When the analyzer projects the three incoming pulses onto one of the GHZ states $|\\Phi^+\\rangle=(|HHH\\rangle+|VVV\\rangle)/\\sqrt{2}$ or $|\\Phi^-\\rangle=(|HHH\\rangle-|VVV\\rangle)/\\sqrt{2}$, the users share multipartite correlation from which a conference key is distilled. The four-intensity decoy analysis yields a lower bound on the single-photon yield and an upper bound on the phase error rate, giving positive finite-size key rates at all three tested attenuations. The paper also reports a theoretically predicted improvement of about two orders of magnitude in key rate over the three-intensity protocol at 13.5 dB attenuation.","pith_inferences":["By extension, the same four-intensity decoy machinery could be carried over to single-photon-based MDI QCC protocols, which the discussion identifies as the route around the $O(\\eta^N)$ rate scaling.","By extension, the identical-source symmetry used to cancel $(2,1,1)$-type terms is a practical weak point; an asymmetric decoy analysis or per-user intensity certification would harden the protocol against source mismatch.","By extension, improving the GHZ-HOM visibility from about 21.8% toward the ideal 25% would lower the phase-error bound and directly raise the conference key rate at fixed loss.","By extension, the frequency-feedback and passive polarization-encoding design shown here could be integrated into a compact multi-node network, with detector efficiency and the $O(\\eta^N)$ scaling setting the practical size limit."],"forward_implications":["Measurement-device-independent conference key agreement no longer requires a shared entangled state; three independent weak coherent sources suffice.","The four-intensity decoy protocol raises the finite-size key rate and extends reachable loss relative to the three-intensity version, and it lowers the minimum number of pulses needed for a positive key.","Because all detector side channels are removed, an untrusted relay can serve as the central hub of a multiparty quantum network.","The measured key rates at 14.1-21.5 dB support metropolitan-scale implementations, although the $O(\\eta^N)$ scaling of multiphoton projection limits the distance beyond roughly 100 km.","A GHZ-HOM visibility near 21.8%, corresponding to QBER X of 39.10%, is consistent with the protocol's loss tolerance and quantifies the interference quality required."],"supporting_citations":[{"why":"Sets out the polarization-encoding MDI QCC protocol and its security proof, the scheme this experiment implements.","marker":"[43]"},{"why":"Provides the four-intensity decoy-state method that the paper adapts from two-party MDI QKD to three-user QCC.","marker":"[54]"},{"why":"Supplies the joint-constraint and finite-size analysis used to bound gains in the decoy estimation.","marker":"[55]"},{"why":"Describes the GHZ-state analyzer whose projection measurement generates the multipartite correlation.","marker":"[56,57]"},{"why":"Defines the HOM interference used to align pulses and verify indistinguishability through GHZ-HOM dips.","marker":"[63]"},{"why":"Gives the Chernoff-bound tail inequalities used to convert finite counts into key-rate bounds.","marker":"[65,66]"}],"fun_headline_variants":["Untrusted relay enables three-party quantum conference keys","MDI quantum conferencing demonstrated with GHZ projection","Three-user quantum key sharing without trusted detectors","Quantum conference key at 7.54 bps via untrusted measurement","Four-intensity decoy boosts MDI quantum conferencing rate"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key-rate calculation assumes the three users' light sources have identical photon-number statistics ($a_n^s=b_n^s=c_n^s$); if the users' intensities differ beyond calibration accuracy, or phase randomization is uneven, the estimated single-photon yield and phase error bounds could be invalid and the finite-size key rate overestimated.","fun_headline_variants_meta":{"raw":{"variants":["Untrusted relay enables three-party quantum conference keys","MDI quantum conferencing demonstrated with GHZ projection","Three-user quantum key sharing without trusted detectors","Quantum conference key at 7.54 bps via untrusted measurement","Four-intensity decoy boosts MDI quantum conferencing rate"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000206,"raw_usage":{"total_tokens":1369,"prompt_tokens":887,"completion_tokens":482,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":503,"completion_tokens_details":{"reasoning_tokens":404}},"tokens_in":503,"tokens_out":482,"duration_ms":5621,"temperature":1.0,"reasoning_tokens":404,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T14:45:12.507040+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Independently measure each user's photon-number distribution and the three-user joint gains, then recompute the single-photon yield bound without the identical-source assumption; if the quoted key rates cannot be reproduced with realistic per-user statistics, the central claim of secure finite-size key generation would be falsified.","supporting_citations":[{"cited_title":"Grasselli, H","cited_arxiv_id":null,"evidence_quote":"Sets out the polarization-encoding MDI QCC protocol and its security proof, the scheme this experiment implements."},{"cited_title":"Pickston, J","cited_arxiv_id":null,"evidence_quote":"Provides the four-intensity decoy-state method that the paper adapts from two-party MDI QKD to three-user QCC."},{"cited_title":"Pramanik, D.-H","cited_arxiv_id":null,"evidence_quote":"Defines the HOM interference used to align pulses and verify indistinguishability through GHZ-HOM dips."}],"review_version":1}