{"id":"721161ad-4442-4567-b872-fa1806d237fc","arxiv_id":"2412.02442","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A GKP quantum error correction thesis that reformulates the codes as symplectic lattices, proves good code families exist, introduces NTRU-based codes, and connects single-mode codes to elliptic curves and fiber-bundle fault tolerance.","lead":"This dissertation develops the theory of Gottesman-Kitaev-Preskill (GKP) quantum error correcting codes through the mathematics of lattices, elliptic curves, and algebraic geometry. It argues these connections can guide code design and fault-tolerant quantum computation.","discovery_kind":"unification","skeptic_critique":{"model":"deepseek-v4-flash","headline":"NTRU-GKP goodness is extrapolated from n≤24 numerics; the random-symplectic proof of good GKP families does not transfer to the structured NTRU subfamily.","rationale":"I read the thesis in good faith and find the central existence claim for good GKP families (Corollary 5) supported by a genuine proof via Theorem 4 and Corollary 4. A secondary internal issue is that Corollary 4 writes the limiting counting function as V_n(R) for a lattice in R^{2n}; the correct volume is V_{2n}(R), changing the Gaussian-heuristic constant from √(n/2πe) to √(n/πe). This is a fixable typo that does not alter the Ω(n) distance-square scaling, so it is not the load-bearing concern. The genuinely load-bearing concern is the NTRU-GKP construction: the thesis itself flags the evidence as numerical (Sec. 5.3.3, Fig. 5.3), and the structured NTRU distribution is not covered by the random-symplectic proof. Because the central claim includes the NTRU family as an explicit candidate with the good-code scaling, and because that claim rests on an extrapolation from n≤24, the reader's CONDITIONAL verdict is appropriate. No further verdict adjustment is needed.","tokens_in":60805,"tokens_out":14351,"duration_ms":152601,"concrete_test":"Replace the average shortest-vector test by a tail test: for n=16,24 and q≈2^10, compute λ1 for 1000 random NTRU lattices (Φ=x^n+1) via HKZ reduction and estimate Pr[λ1≥c√(nq)] for c≈1/√(πe). If this probability decays with n or falls far below the corresponding probability for the U_q-ensemble, the NTRU family is not a reliable source of good GKP codes; if it stays bounded away from zero, extend to n=32,64. The decisive analytical check is to prove an analogue of Theorem 4 for the NTRU measure by bounding the second moment of the short-vector count over h∈R_q^×; failure of such a bound would falsify the transfer.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing gap is that Corollaries 4–5 prove the existence of good GKP families by averaging over all symmetric matrices X∈U_q (Theorem 4), whereas the NTRU-GKP construction (Sec. 5.3) samples lattices from the much smaller, algebraically structured family Λ_NTRU={(u,v): u≡hv mod q} with h∈Z_q[x]/(x^n+1). The equidistribution argument of Theorem 4 relies on the full symmetry of U_q and says nothing about this subfamily. The claimed distance scaling Δ=O(√(n/λ)) for NTRU-GKP (Fig. 5.1) is therefore an extrapolation from 100 HKZ-reduced samples per n≤24 (Fig. 5.3). Those numerics estimate the average of λ1, but the existence proof needs a lower-tail property: with positive probability λ1≥c√n. Matching the average Gaussian heuristic does not imply the tail bound, and the ring correlations could bias the distribution. Thus the 'candidate explicit family' part of the central claim is not established and should be stated as a conjecture unless a rigorous transfer argument is supplied.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript is a doctoral dissertation on Gottesman-Kitaev-Preskill (GKP) codes, presenting them through a lattice-theoretic and algebraic-geometric lens. It develops the stabilizer formalism for GKP codes, proves a Frobenius normal form for symplectically integral lattices, derives distance bounds, proves the existence of good GKP code families by averaging over symmetric matrices over Z_q, analyzes logical Clifford gates via symplectic automorphisms, proposes a moduli-space and fiber-bundle picture of fault tolerance, constructs GKP codes from root lattices and from NTRU lattices, studies the computational complexity of GKP decoding, and discusses experimental implementation. The central mathematical results are largely drawn from the author's published work, and the thesis frames them as a coherent research program.","tokens_in":60997,"tokens_out":6636,"duration_ms":76695,"significance":"If the main claims hold, the paper makes a valuable contribution to the theory of GKP codes. The most significant result is the proof that good GKP code families exist, meaning families with non-vanishing rate and distance scaling Δ^2 = Ω(n), which establishes in principle that GKP codes can go beyond the constant-overhead barrier known for other bosonic codes. The symplectic equivalence and Frobenius normal-form results are clean and useful, and the connection between GKP Clifford gates, symplectic automorphisms, and Riemann-surface/moduli-space structures is a genuinely insightful synthesis. The NTRU-GKP construction is an appealing candidate for an explicit good family and is supported by reproducible numerical evidence for n ≤ 24, but it is not yet a theorem. The manuscript is honest about many open points and makes its numerical code available, which is a strength.","major_comments":[{"comment":"The claim that NTRU-GKP codes form an explicit family of good GKP codes is not established. Corollary 4 proves existence by averaging over all symmetric matrices X ∈ U_q, but NTRU lattices are drawn from the much smaller structured family Λ_NTRU = {(u, v) : u ≡ h v mod q} with h ∈ Z_q[x]/(x^n + 1). The equidistribution argument in Theorem 4 does not apply to this subfamily. The numerical results in Fig. 5.3 estimate the average shortest-vector length for n ≤ 24, but the goodness criterion requires a lower-tail statement that, with positive probability, λ_1 ≥ c√n. Matching the Gaussian-heuristic mean does not imply this tail bound, and ring correlations could bias the distribution. Unless a rigorous transfer argument is provided, the NTRU-GKP distance scaling Δ = O(√(n/λ)) should be stated as a conjecture or as numerical evidence, not as a proven property.","section":"§5.3, Fig. 5.3, Corollary 4"},{"comment":"There is a dimension-accounting inconsistency in the ball-volume argument. Theorem 4 considers functions f : R^{2n} → R, and L_{q,X} is a lattice in R^{2n}, so the relevant ball volume is V_{2n}(R) = π^n R^{2n}/Γ(n+1). Setting this equal to 1 gives R ≈ √(n/(π e)), not R ≈ √(n/(2π e)) as stated in Corollary 4. The proof appears to use V_n(R) = π^{n/2}R^n/Γ(n/2+1), which is the volume of a ball in R^n. The asymptotic existence claim survives, but the displayed constant and the proof need to be corrected for consistency.","section":"§4.3.3, proof of Corollary 4"},{"comment":"The passage from the averaged counting statement to an existence statement should be stated more carefully. From the theorem, one obtains that for large q the expected number of short vectors is close to V_{2n}(R). For a fixed R slightly below the Gaussian-heuristic radius, this expectation is less than 1, which indeed implies that some lattice has no nonzero vector shorter than R. The current wording, 'the average property implies the existence of instances,' is acceptable informally, but it is not a statement about typical instances, and the finite-q fluctuation is not quantified. A short remark distinguishing 'there exists' from 'random instances have' would prevent the reader from over-reading Corollary 4.","section":"§4.3.3, Corollary 4 and 6"}],"minor_comments":[{"comment":"The table entry for NTRU-GKP codes uses Δ ∼ O(√(n/λ)) without defining λ in the table or its caption; define λ as the NTRU scaling parameter or refer explicitly to the section where it is introduced.","section":"Fig. 5.1"},{"comment":"There are several typographical errors in names and terms, e.g., 'Meniccuci' for Menicucci, 'Joza' for Jozsa, and 'Franceosco' for Francesco. These should be corrected in a final revision.","section":"Chapter 1 and 3"},{"comment":"The figure caption reports expected shortest-vector lengths from the Gaussian heuristic as λ(n) = √(nq/(π e)), while the text around Corollary 4 uses √(n/(2π e)). Please reconcile the notation and constants so that the reader can compare the numerical data with the theoretical statements.","section":"§5.3.3, Fig. 5.3"},{"comment":"The discussion of the modular discriminant and the bound |Δ(τ)| is interesting but somewhat compressed; in particular, the statement that |Δ(τ)| is lower-bounded away from |τ| = 1 should include the relevant argument or a precise reference, since the constant enters the claimed distance-to-discriminant correspondence.","section":"§4.4.4"}],"recommendation":"major_revision","confidential_remarks":"The dissertation is largely a compilation of the author's published work, and the core mathematical framework is sound and well worth publishing in revised form. My main concern is the NTRU-GKP section, where the presentation appears to go beyond what the mathematics proves: the existence theorem covers random symmetric matrices, while the NTRU construction is an extrapolation from numerics. This is fixable by reframing the NTRU claim as a conjecture or by adding a rigorous argument, but as written it is a load-bearing overclaim in the construction chapter."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Jon,\n\nThis is a dissertation, and it is honest about being one. The core of Chapter 4—Frobenius normal form, symplectic equivalence for GKP codes, distance bounds, and the existence proof of good GKP families by averaging over symmetric matrices—is solid, checkable mathematics. Most of it appeared in peer-reviewed papers (Quantum 2022, 2024; PRA 2021), so the novelty is in the synthesis, not the individual theorems. That is fine: the synthesis is genuinely useful. The lattice perspective and the moduli-space/Rosetta-stone picture tie together a lot of material that otherwise lives in scattered papers, and the theta-function characterization of distance is a clean observation.\n\nThe soft spot is exactly where the stress-test note points. Theorem 4 proves existence of good GKP codes by averaging over all symmetric X in U_q. The NTRU construction samples from a much smaller, algebraically structured family of lattices, and the equidistribution argument does not carry over. The numerical evidence goes up to n=24 with 100 HKZ-reduced samples; that estimates the average shortest vector, not the lower-tail probability needed for a distance guarantee. So the claim that NTRU-GKP gives an explicit family with Δ=O(√(n/λ)) is an extrapolation, not a theorem. The thesis does flag the numerics, but it should go further and label the scaling as a conjecture unless someone supplies a transfer argument. That said, the gap is localized. It does not damage the random-symplectic existence proof, which stands on its own.\n\nThe fiber-bundle fault-tolerance discussion is qualitative and explicitly a 'towards' research program; I would not hold that against the thesis.\n\nBottom line: the math is largely reproducible—the author provides code and data for the NTRU numerics—and the presentation is clear. A serious editor should send this to peer review, not desk-reject it. The main referee request should be: separate the already-published core from the new synthesis, and state the NTRU-GKP distance scaling as a conjecture with the numerical evidence clearly labeled as such.\n\nI would not cite the thesis itself in my own work over the next year—the published papers are the right citable objects—but I would be happy to see this synthesis in the literature.","headline":"Solid, honest PhD synthesis of previously published GKP lattice results; the NTRU-GKP goodness scaling is a reasonable but unproven extrapolation and should be labeled a conjecture.","tokens_in":61549,"tokens_out":2783,"would_cite":false,"duration_ms":30773,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P73","11H06","14H52"],"pacs":["03.67.Pp"],"model":"deepseek-v4-flash","headline":"The paper shows that GKP codes, viewed as symplectic lattices, admit good families with constant rate and distance scaling $\\Delta^2=\\Omega(n)$; NTRU lattices are the candidate explicit family.","keywords":["Gottesman-Kitaev-Preskill codes","bosonic quantum error correction","symplectic lattices","NTRU lattices","good quantum codes","theta functions","moduli space of elliptic curves","fiber bundle fault tolerance"],"falsifier":"Compute exact shortest vectors for randomly sampled NTRU lattices at substantially larger dimension (say $n=100$ or $200$) using exact lattice reduction; if the shortest vector length stops tracking the Gaussian-heuristic $\\sqrt{n}$ curve and grows more slowly, the claimed $\\Delta=O(\\sqrt{n})$ scaling for NTRU-GKP codes fails.","tokens_in":60566,"feed_emoji":"🧩","tokens_out":15079,"duration_ms":150941,"temperature":0.7,"pith_summary":"This dissertation argues that Gottesman–Kitaev–Preskill (GKP) codes—stabilizer codes whose logical qubits live in the infinite-dimensional Hilbert space of harmonic oscillators and are fixed by translation symmetries in phase space—are not only an error-correction scheme but a meeting point for lattice theory, number theory, algebraic geometry, and fault tolerance. Its central coding-theoretic result is that good GKP code families exist: lattices $L_n\\subset \\mathbb{R}^{2n}$ whose encoding rate $\\log\\det(L_n)$ grows linearly in $n$ while the code distance $\\Delta$ grows as $\\sqrt{n}$, so $\\Delta^2=\\Omega(n)$. The existence proof uses a random symmetric-matrix construction that approximates the uniform measure on symplectic lattices. The thesis then proposes an explicit candidate family, NTRU-GKP codes, built from the lattices behind the NTRU cryptosystem, with numerical evidence for the needed $\\sqrt{n}$ shortest-vector scaling up to dimension 24. Alongside this, it develops a geometric picture in which single-mode GKP codes are elliptic curves, logical Clifford gates are braids around a trefoil-knot defect in the space of lattices, and fault tolerance is a property of fiber bundles.","feed_headline":"Good GKP codes exist—constant rate, distance scaling as √n","feed_subtitle":"The proof runs through symplectic lattices, with NTRU cryptography as an explicit candidate family.","key_machinery":"The central object is the symplectically integral lattice $L\\subseteq L^\\perp$ associated to a GKP stabilizer group $S=\\langle D(\\xi_1),\\dots,D(\\xi_{2n})\\rangle$, with symplectic form $J$ and Gram matrix $A=MJM^T$. This dictionary converts code distance into the shortest vector of the dual quotient, logical Clifford gates into symplectic automorphisms with integral representation $\\mathrm{Sp}^D_{2n}(\\mathbb{Z})$, and the space of single-mode codes into the modular curve $\\mathrm{SL}_2(\\mathbb{Z})\\setminus\\mathfrak{h}$ with a trefoil-knot defect. The existence proof for good codes uses the Haar measure on symplectic lattices together with the explicit family $M[X]$, which realizes the Gaussian heuristic—the expectation that a random lattice's shortest vector is roughly $\\sqrt{n/2\\pi e}$ times the $n$-th root of its covolume. NTRU-GKP codes are proposed as a structured, cryptographically motivated instance of the same construction. Theta functions act as generating functions for the lattice distance distribution, and the fiber-bundle framework for fault tolerance turns logical gates into homotopy classes of loops in the moduli space.","core_discovery":"The paper establishes that the GKP construction is best understood as a symplectic lattice: stabilizers are displacements by vectors in a lattice $L$, logical Pauli operators are displacements by vectors in the symplectic dual $L^\\perp$, and the code distance is $\\Delta=\\min_{0\\neq x\\in L^\\perp\\setminus L}\\lVert x\\rVert$. With this dictionary, the existence of good codes is proven: for any fixed scaling $d$, the random symmetric matrices $X\\in\\{-q/2,\\dots,q/2\\}^{n\\times n}$ produce lattices generated by $M[X]=\\begin{pmatrix} I & X \\\\ 0 & qI \\end{pmatrix}$, and after rescaling these have shortest vector $\\lambda_1\\approx\\sqrt{n/2\\pi e}$ in the large-$q$ limit, giving $\\log\\det(L_n)=\\Omega(n)$ and $\\Delta^2=\\Omega(n)$. The same dictionary turns NTRU lattices into GKP codes; exact lattice reduction for dimensions up to 24 supports the $\\Delta=O(\\sqrt{n})$ scaling needed for goodness, though the paper presents this as numerical evidence rather than a theorem.","pith_inferences":["Beyond the paper's results, if the NTRU-GKP scaling conjecture holds, approximate shortest-vector solvers would double as practical decoders, linking the hardness of decoding GKP codes to the assumptions behind NTRU-based cryptography.","The moduli-space picture for single-mode codes likely extends to multi-mode GKP codes through higher-dimensional abelian varieties; a natural test is whether the topological defect becomes a higher-dimensional submanifold and whether fault-tolerance still corresponds to non-contractible loops around it.","One could test the randomness assumption directly by comparing low-order statistics of NTRU lattices (theta series or shortest-vector moments) with those of uniformly random symplectic lattices at dimensions beyond 24, before relying on the $\\sqrt{n}$ extrapolation.","The fiber-bundle view may give a general method for proving that a gate set is fault tolerant solely from the topology of the code's parameter space, independent of the physical implementation."],"forward_implications":["Good GKP families would make constant-rate bosonic error correction possible in principle: the number of encoded qubits per mode stays bounded away from zero while the minimal logical displacement grows, so concatenation with outer qubit codes is not the only route to scalability.","The NTRU-GKP construction provides an explicit family of symplectic lattices whose numerical shortest-vector behavior is consistent with the goodness scaling, and the thesis builds a private quantum channel on this family.","The elliptic-curve picture implies that every single-mode GKP code carries a geometric label in the modular curve, with logical Clifford gates corresponding to homotopically non-trivial loops around the zero-distance defect.","The distance of a GKP code is fixed by the distance distribution of its lattice, expressible through lattice theta functions; for concatenated codes this reduces distance to the weight enumerator of the qubit code.","Tensor products of GKP lattices produce new codes with distance bounded between the individual distances and their product, giving a construction principle beyond concatenation."],"supporting_citations":[{"why":"Introduces GKP codes as stabilizer codes with displacement stabilizers, defining the lattice perspective and the scaling construction used throughout.","marker":"[95]"},{"why":"Provides the original existence argument for good GKP codes via a Haar average over symplectic lattices, which the thesis extends into an explicit random-matrix construction.","marker":"[106]"},{"why":"Supplies the catalog of symplectic self-dual root lattices and the scaled-code distance formula $\\Delta=d^{-1/2}\\lambda_1(L_0)$ that underlies the good-code analysis.","marker":"[107]"},{"why":"Supplies the lattice-theoretic formulation of GKP coding theory on which the distance, symplectic-equivalence, and concatenation results are based.","marker":"[57]"},{"why":"Introduces NTRU-GKP codes, the explicit good-code candidate built from NTRU lattices, and reports the numerical shortest-vector data.","marker":"[58]"},{"why":"Produces the Haar measure on the moduli space of symplectic lattices and the shortest-vector bounds used to prove existence of lattices with $\\lambda_1\\propto\\sqrt{n}$.","marker":"[166]"},{"why":"Supplies the standard lattice-construction toolkit (Construction A, root lattices, theta functions, glueing) used for concatenated and tensor GKP codes.","marker":"[61]"},{"why":"Defines the fiber-bundle fault-tolerance framework in which the thesis interprets logical Clifford gates as homotopy classes of loops.","marker":"[96]"}],"fun_headline_variants":["GKP codes are symplectic lattices—good code existence proven","Good GKP codes exist—proven via symplectic lattices","Symplectic lattices: the key to good GKP codes","From GKP to lattices: good quantum codes proven","Symplectic lattice dictionary unlocks good GKP codes"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that random NTRU lattices, which come from a structured polynomial algebra rather than being drawn uniformly at random, have the same shortest-vector statistics as random symplectic lattices; the evidence so far is numerical, for dimensions up to 24.","fun_headline_variants_meta":{"raw":{"variants":["GKP codes are symplectic lattices—good code existence proven","Good GKP codes exist—proven via symplectic lattices","Symplectic lattices: the key to good GKP codes","From GKP to lattices: good quantum codes proven","Symplectic lattice dictionary unlocks good GKP codes"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.0009,"raw_usage":{"total_tokens":3945,"prompt_tokens":1086,"completion_tokens":2859,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":702,"completion_tokens_details":{"reasoning_tokens":2771}},"tokens_in":702,"tokens_out":2859,"duration_ms":23116,"temperature":1.0,"reasoning_tokens":2771,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T23:26:49.744752+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute exact shortest vectors for randomly sampled NTRU lattices at substantially larger dimension (say $n=100$ or $200$) using exact lattice reduction; if the shortest vector length stops tracking the Gaussian-heuristic $\\sqrt{n}$ curve and grows more slowly, the claimed $\\Delta=O(\\sqrt{n})$ scaling for NTRU-GKP codes fails.","supporting_citations":[{"cited_title":"Sarnak and P","cited_arxiv_id":null,"evidence_quote":"Produces the Haar measure on the moduli space of symplectic lattices and the shortest-vector bounds used to prove existence of lattices with $\\lambda_1\\propto\\sqrt{n}$."}],"review_version":1}