{"id":"41d0c894-16ea-4b3f-8c4b-f447f1e64c5e","arxiv_id":"2411.15777","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"Modulator-free QKD transmitters need about 70 to 90 dB of attenuation on residual pulses, otherwise information leakage cuts the secure key rate sharply.","lead":"This paper calculates how much secret key can still be made in quantum key distribution when 'modulator-free' transmitters leak a small amount of light that reveals Alice's settings. It finds that unless those extra pulses are suppressed by roughly 70 to 90 decibels, the secure key rate collapses.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The passive-transmitter reduction in Section II B is off by a factor √2: the stated 50:50 BS substitution cannot reconstruct the actual leakage state, so the lower-bound claim behind Fig. 3 is not established as written.","rationale":"The paper's central claim is a valid lower bound on the secret-key rate of modulator-free transmitters with finite extinction-ratio leakage. The security framework (quantum-coin yields, decoy LP, phase-error bound) is credible, and Section III's treatment of the injection-locking transmitter uses the correct √ω amplitudes. The reader's identified weakness is exactly where the argument breaks: the fictitious-scenario reduction in Section II B is a load-bearing step that lets the authors decouple rounds. As written, the beamsplitter reconstruction is not an identity, so the fictitious state is not a relaxation of the actual state; it has lower mode-1/mode-5 intensity. A typographical fix (√ω instead of √(ω/2)) would restore the argument, but it changes the leakage model used in all passive-transmitter numerics. This does not affect the injection-locking analysis, but it does affect Fig. 3 and the paper's headline attenuation numbers, so the paper needs revision; the reader's CONDITIONAL verdict is appropriate and no change to that verdict is needed.","tokens_in":27811,"tokens_out":13610,"duration_ms":119786,"concrete_test":"Independently verify the beamsplitter identity: for |α⟩|β⟩ through a 50:50 BS, the output amplitude is (α+β)/√2; with Eq. (7) as written this gives √(ω/4)(e^{iφ0}+e^{iφ1}), not the original. Then replace Eq. (8) by |√ω e^{iφ1}⟩_1 and |√ω e^{iφ4}⟩_5, update Eq. (16) accordingly, and rerun the Appendix E LP for Fig. 3; check whether the key-rate curves shift by more than about 3 dB and whether the 'Att ≈ 90 dB' claim survives.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Equation (7) replaces the actual leakage mode |√(ω/2)(e^{iφ0}+e^{iφ1})⟩_1 by |√(ω/2)e^{iφ0}⟩_{1′}⊗|√(ω/2)e^{iφ1}⟩_1 and claims a 50:50 BS recovers the original. A BS on two coherent states gives first output amplitude (α+β)/√2; with α=β=√(ω/2) this is √(ω/4)(e^{iφ0}+e^{iφ1}), not √(ω/2)(e^{iφ0}+e^{iφ1}). The correct inputs would be |√ω e^{iφ0}⟩⊗|√ω e^{iφ1}⟩, as the paper itself uses for the analogous substitution in Section III, Eq. (35). Consequently Eq. (8) and the mode-1/mode-5 amplitudes in Eq. (16) underestimate the leakage intensity by a factor of two in those two modes. Since the passive-transmitter security analysis and Fig. 3 are built on this fictitious scenario, the claimed lower bound on the actual key rate is not proven as written. The qualitative conclusion that tens of dB of attenuation are needed is plausible, but the quantitative thresholds in Fig. 3 and the Abstract/Conclusions must be re-derived with the corrected amplitudes.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper develops a security analysis for decoy-state BB84 QKD with two types of modulator-free transmitters: a fully passive post-selection transmitter and an optical-injection-locking (OIL) transmitter. It models the residual information leakage from the finite extinction ratio of an intensity modulator as a set of leaked coherent modes, then uses the quantum-coin argument together with decoy-state linear programs to derive asymptotic secret-key rate lower bounds. The central quantitative claim is that for both transmitters the key rate is severely degraded unless the leakage is attenuated by roughly 70–90 dB, and that security against general attacks is maintained in the asymptotic limit if this attenuation is included in the proof.","tokens_in":28114,"tokens_out":8247,"duration_ms":69304,"significance":"If the technical issue identified below is corrected, the paper makes a valuable contribution: it provides a general, explicit framework for incorporating residual leakage modes into security proofs for modulator-free sources, with detailed appendices and concrete linear programs for yield and phase-error estimation. The OIL transmitter analysis in Section III appears internally consistent and provides a useful comparison. The qualitative conclusion that finite extinction ratios must be accounted for in security proofs is important for practical implementations of passive and modulator-free QKD transmitters. The paper is careful in stating its modeling assumptions, and the numerical results give falsifiable predictions about the required attenuation levels.","major_comments":[{"comment":"The fictitious-scenario substitution in Eq. (7) is incorrect. The text claims that a 50:50 beamsplitter acting on the two modes |√(ω/2)e^{iφ0}⟩_{1'} and |√(ω/2)e^{iφ1}⟩_1 reconstructs the original leakage mode |√(ω/2)(e^{iφ0}+e^{iφ1})⟩_1. A 50:50 beamsplitter maps input amplitudes α and β to output amplitudes (α+β)/√2 and (α−β)/√2; with α = β = √(ω/2), the first output amplitude is √(ω/4)(e^{iφ0}+e^{iφ1}), not √(ω/2)(e^{iφ0}+e^{iφ1}). The correct input amplitudes would be √ω e^{iφ0} and √ω e^{iφ1}, which is exactly the substitution used in the analogous OIL analysis in Eq. (35) of Section III. As written, Eqs. (8), (16), and (17) underestimate the intensity of leakage modes 1 and 5 by a factor of two, so the fictitious scenario is not more advantageous for Eve and the lower-bound claim behind Fig. 3 (and the refined analysis in Appendix E) is not established. The passive-transmitter key rates and the quantitative attenuation thresholds must be re-derived with the corrected amplitudes.","section":"II B, Eq. (7)"}],"minor_comments":[{"comment":"The Conclusions state that the secret-key rate approaches the ideal leakage-free scenario when the attenuation exceeds ∼70 dB, but Fig. 3 for the passive transmitter shows that alignment with the ideal curve requires Att ≳ 90 dB. Please qualify which transmitter the 70 dB figure refers to, or otherwise reconcile the thresholds.","section":"V, Conclusions"},{"comment":"It is unclear whether the odd leakage pulses pass through the low-transmittance beamsplitter with the even signal pulses. The definition of ω in Eq. (6) suggests they do not; please clarify the optical path so that the relation between ω and the physical leakage intensity is unambiguous.","section":"II A, step 1(d)"},{"comment":"The secret-key rate formula contains the prefactor p_{Z_B} p_{Ω^{I0}_Z}; the ordering of sifting (Bob announces detections and basis) and Alice's post-selection announcement should be stated explicitly so that the definitions of these probabilities are unambiguous.","section":"II D, Eq. (23)"},{"comment":"The final line of Eq. (D4) sets certain phases ξ to specific values for ω = 0; for the numerical implementation with ω > 0, please state which phase choices are used and whether they are optimized or fixed, since the inner product Re{⟨ψ^{ω,1}_{Z,I0}|ψ^{ω,1}_{X,I0}⟩} depends on them.","section":"Appendix D, Eq. (D4)"}],"recommendation":"major_revision","confidential_remarks":"The factor-√2 error in Section II B is localized and fixable, but it undermines the passive-transmitter lower bound as written, so the simulations in Fig. 3 and Appendix E must be redone with corrected leakage amplitudes. The OIL transmitter results in Section III are likely unaffected. The authors should also reconcile the dB thresholds in the Conclusions with Fig. 3. The paper's overall framework is sound and the topic is timely for practical modulator-free QKD."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: this is a useful paper with a real bug in the passive-transmitter section. The Section III (OIL) analysis is in good shape; the Section II passive analysis is not proven as written because the fictitious-scenario substitution is off by a factor sqrt(2). I'd send it to review, but the authors need to fix that step before the passive-transmitter numbers can be trusted.\n\nWhat's actually new: prior work [22] only gave a heuristic argument that residual pulses from finite extinction ratio don't break security. This paper is the first to model the leakage modes explicitly and produce asymptotic key-rate bounds, including concrete attenuation thresholds (about 70-90 dB). The methodology is appropriate: quantum-coin constraints, decoy-state LPs, fidelity bounds via projection and Bures distance. The OIL transmitter analysis in Section III is internally consistent, and the substitution there (Eq. 35) correctly uses amplitude sqrt(ω) for the two split modes.\n\nThe soft spot is Section II B. The text says a 50:50 beamsplitter can turn |sqrt(ω/2) e^{iφ0}⟩ ⊗ |sqrt(ω/2) e^{iφ1}⟩ back into |sqrt(ω/2)(e^{iφ0}+e^{iφ1})⟩. It can't: a beamsplitter on two coherent states of amplitude α and β gives output amplitude (α+β)/√2, which here is sqrt(ω/4)(e^{iφ0}+e^{iφ1}), a factor 1/√2 too small. The correct inputs would be |sqrt(ω) e^{iφ0}⟩ and |sqrt(ω) e^{iφ1}⟩, as the authors themselves use in Section III. Because Eq. (8) and the mode-1/mode-5 amplitudes in Eq. (16) are built on this, the passive-transmitter leakage is underestimated by 3 dB in those modes. Fig. 3 and the passive-transmitter key-rate claims are therefore not established as lower bounds for the real device. The qualitative conclusion—that you need tens of dB of attenuation—is still plausible and likely robust; the exact 70-90 dB thresholds may shift a bit after the correction. The refined analysis in Appendix E inherits the same issue.\n\nEverything else checks out. The fidelity approximations in Appendix C are reasonable, the LPs are standard, and the self-citations point to independently published proofs. No sign of curve-fitting or circularity.\n\nWho this is for: people working on QKD implementation security, especially modulator-free transmitters. It deserves a serious referee despite the flaw. My recommendation: send it to review, and have the referee require the corrected substitution (or an explicit argument that the fictitious scenario is still more advantageous to Eve). Once that's done, the passive-transmitter results should be re-generated before publication.","headline":"Useful paper on modulator-free QKD leakage, but the passive-transmitter section has a factor-sqrt(2) error in the fictitious-scenario reduction that needs fixing before its key-rate numbers can be trusted.","tokens_in":28661,"tokens_out":7346,"would_cite":false,"duration_ms":62479,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"Even small residual leakage from the intensity modulator severely degrades the secret-key rate of modulator-free decoy-state BB84; the paper proves security and fixes the required attenuation at roughly 70–90 dB.","keywords":["quantum key distribution","modulator-free transmitter","information leakage","intensity modulator extinction ratio","decoy-state BB84","quantum-coin argument","general attacks","asymptotic secret-key rate"],"falsifier":"Directly compute the state obtained from $|\\sqrt{\\omega/2}\\,e^{i\\varphi_0}\\rangle_{1'} \\otimes |\\sqrt{\\omega/2}\\,e^{i\\varphi_1}\\rangle_1$ through a 50:50 beamsplitter: the kept port contains $\\sqrt{\\omega/4}(e^{i\\varphi_0}+e^{i\\varphi_1})$, not the paper's claimed $\\sqrt{\\omega/2}(e^{i\\varphi_0}+e^{i\\varphi_1})$. If this check is confirmed, the key-rate lower bounds in Section II (and hence Fig. 3) need re-derivation before they can be quoted for the real transmitter.","tokens_in":27561,"feed_emoji":"🔐","tokens_out":8133,"duration_ms":68686,"temperature":0.7,"pith_summary":"Modulator-free quantum key distribution transmitters avoid active modulators, making them resistant to Trojan-horse attacks, but their residual pulses leak information about Alice's settings through the intensity modulator's finite extinction ratio. This paper proves security against general attacks for decoy-state BB84 with such transmitters, modelling the leakage as weak coherent pulses of intensity $\\omega$ and deriving asymptotic secret-key-rate bounds in Eqs. (23) and (43). The numerical evaluation shows the key rate is severely degraded unless the modulator provides roughly 70–90 dB of attenuation, and it collapses below roughly 30 dB. In other words, the one leftover modulator is not a minor detail; it is the gatekeeper of the protocol's security.","feed_headline":"Modulator-free QKD needs ~90 dB attenuation to stay secure","feed_subtitle":"Leaked pulses from imperfect intensity modulators gut secret-key rates; the paper quantifies the required extinction.","key_machinery":"The central objects are the leakage modes tagged by $L$ (the odd time bins 1, 3, and 5 in the passive transmitter; the $P$ and $F$ modes in the injection-locked transmitter), described as coherent states with intensity $\\omega = \\eta_{\\mathrm{IM}} \\mu_{\\max}$ (passive) or $\\omega = \\eta_{\\mathrm{IM}} \\mu_{\\mathrm{in}}/2$ (injection-locked). The argument works by replacing the actual leakage state with a fictitious splitting into separate modes that is intended to be more advantageous for Eve, turning inter-round correlations into per-round local states. The mathematical engine is the quantum-coin argument, which converts fidelity bounds between photon-number states of different intensity settings into linear-program constraints on yields and bit-error rates; the final rates are the asymptotic formulas in Eqs. (23) and (43).","core_discovery":"The paper's central claim is that the residual pulses emitted in modulator-free transmitters must be treated as a genuine side channel with finite intensity $\\omega$, rather than as a negligible imperfection, and that a security proof can still go through by embedding those pulses as additional Fock modes and applying decoy-state and quantum-coin techniques. Concretely, for the fully passive post-selection transmitter and for the optical-injection-locking transmitter, the paper constructs fictitious scenarios in which the leakage modes are split into Eve-friendlier systems, computes post-selected $n$-photon density matrices in the enlarged Hilbert space, and uses linear programs to bound single-photon yields and phase-error rates. The resulting asymptotic key rates, Eqs. (23) and (43), show a sharp transition: an attenuation of about 70 dB recovers near-ideal performance, while an attenuation of 30 dB or less leaves essentially no key.","pith_inferences":["If the beamsplitter reconstruction step in Section II B is corrected, the 70–90 dB requirement suggests that 'modulator-free' transmitters inherit a tight specification on the one remaining modulator, essentially trading Trojan-horse resistance for a demanded extinction ratio.","A finite-key version of the same parameterization would likely require even stronger attenuation, since statistical fluctuations widen the gap between the bound and the ideal rate.","The same leakage-modeling could be applied to measurement-device-independent QKD with modulator-free sources, where the leaked modes enter through an untrusted receiver rather than through Bob's basis choice.","A direct experimental test would be to measure the key-rate-vs-distance curve of a passive transmitter at 30, 50, and 70 dB IM attenuation and check whether it follows the sharp drop predicted in Fig. 3."],"forward_implications":["Key rate approaches the ideal leakage-free value only when the intensity modulator attenuation is about 70 dB or more; below ~30 dB the protocol is practically unusable.","The security analysis applies to a broad family of passive post-selection decoy-state transmitters, not only to the specific time-bin BB84 example used for illustration.","For the injection-locking transmitter, the leakage state is identical for all signal-intensity $I_0$ rounds, making it less sensitive to leakage than the fully passive transmitter.","Because yields now depend on the intensity setting, the standard decoy-state analysis must be replaced by fidelity-based quantum-coin linear programs."],"supporting_citations":[{"why":"defines the fully passive post-selection decoy-state BB84 transmitter whose leakage the paper models.","marker":"[17]"},{"why":"introduces the optical-injection-locking modulator-free transmitter to which the security analysis is adapted.","marker":"[22]"},{"why":"provides the quantum-coin argument that supports the fidelity-based linear programs for single-photon yields.","marker":"[23]"},{"why":"derives the phase-error bound (Bloch-sphere inequality) that the paper uses to relate the X-basis bit-error rate to the phase-error rate.","marker":"[24]"},{"why":"extends the quantum-coin technique to imperfect sources, underlying the linear programs in Eqs. (25) and (27).","marker":"[25]"},{"why":"supplies the fidelity-with-projection result and Bures-distance bound used for efficient fidelity estimation in Appendix C.","marker":"[26]"},{"why":"is the complementarity-based security proof whose structure yields the key-rate lower bound in Eq. (23).","marker":"[27]"},{"why":"provides the standard decoy-state channel model and expected yields used in the simulations.","marker":"[29]"},{"why":"describes the fully passive transmitter concept and the post-selection probability density used in Eq. (13).","marker":"[14]"}],"fun_headline_variants":["Modulator-free QKD needs 70 dB attenuation to stay secure","Leaked pulses from QKD modulators erase keys below 70 dB","QKD side channel: 70 dB extinction restores secret-key rates","Modulator-free transmitters: 30 dB leak kills key, 70 dB recovers","Finite extinction ratio can ruin QKD unless 70 dB attenuation"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that a 50:50 beamsplitter can turn the two substituted leakage modes $|\\sqrt{\\omega/2}\\,e^{i\\varphi_0}\\rangle_{1'} \\otimes |\\sqrt{\\omega/2}\\,e^{i\\varphi_1}\\rangle_1$ back into the original leakage state $|\\sqrt{\\omega/2}(e^{i\\varphi_0}+e^{i\\varphi_1})\\rangle_1$; if this reconstruction fails, the simplified per-round security bounds are not automatically lower bounds for the actual device.","fun_headline_variants_meta":{"raw":{"variants":["Modulator-free QKD needs 70 dB attenuation to stay secure","Leaked pulses from QKD modulators erase keys below 70 dB","QKD side channel: 70 dB extinction restores secret-key rates","Modulator-free transmitters: 30 dB leak kills key, 70 dB recovers","Finite extinction ratio can ruin QKD unless 70 dB attenuation"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000333,"raw_usage":{"total_tokens":1799,"prompt_tokens":846,"completion_tokens":953,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":462,"completion_tokens_details":{"reasoning_tokens":855}},"tokens_in":462,"tokens_out":953,"duration_ms":7865,"temperature":1.0,"reasoning_tokens":855,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T13:55:25.981045+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Directly compute the state obtained from $|\\sqrt{\\omega/2}\\,e^{i\\varphi_0}\\rangle_{1'} \\otimes |\\sqrt{\\omega/2}\\,e^{i\\varphi_1}\\rangle_1$ through a 50:50 beamsplitter: the kept port contains $\\sqrt{\\omega/4}(e^{i\\varphi_0}+e^{i\\varphi_1})$, not the paper's claimed $\\sqrt{\\omega/2}(e^{i\\varphi_0}+e^{i\\varphi_1})$. If this check is confirmed, the key-rate lower bounds in Section II (and hence Fig. 3) need re-derivation before they can be quoted for the real transmitter.","supporting_citations":[{"cited_title":"Ex- perimental demonstration of fully passive quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"defines the fully passive post-selection decoy-state BB84 transmitter whose leakage the paper models."},{"cited_title":"Simplified intensity-and phase-modulated transmitter for modulator-free decoy-state quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"introduces the optical-injection-locking modulator-free transmitter to which the security analysis is adapted."},{"cited_title":"Security of quantum key distribution with imperfect devices,","cited_arxiv_id":null,"evidence_quote":"provides the quantum-coin argument that supports the fidelity-based linear programs for single-photon yields."},{"cited_title":"Security of quantum key distribution using weak coherent states with nonrandom phases,","cited_arxiv_id":null,"evidence_quote":"derives the phase-error bound (Bloch-sphere inequality) that the paper uses to relate the X-basis bit-error rate to the phase-error rate."},{"cited_title":"Discrete-phase-randomized coherent state source and its application in quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"extends the quantum-coin technique to imperfect sources, underlying the linear programs in Eqs. (25) and (27)."},{"cited_title":"Security of quantum key distribution with imperfect phase randomisation,","cited_arxiv_id":null,"evidence_quote":"supplies the fidelity-with-projection result and Bures-distance bound used for efficient fidelity estimation in Appendix C."},{"cited_title":"Simple security proof of quantum key distribution based on complementarity,","cited_arxiv_id":null,"evidence_quote":"is the complementarity-based security proof whose structure yields the key-rate lower bound in Eq. (23)."},{"cited_title":"Practical decoy state for quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"provides the standard decoy-state channel model and expected yields used in the simulations."},{"cited_title":"A fully passive transmitter for decoy-state quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"describes the fully passive transmitter concept and the post-selection probability density used in Eq. (13)."}],"review_version":1}