{"id":"22a90af0-e8fe-40e6-a6be-4f52e673cc1b","arxiv_id":"2412.12593","paper_version":2,"verdict":"REJECT","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":5,"one_line_summary":"Asymmetric mode-pairing QKD with finite-key analysis and practical decoy states achieves higher secure key rates than equalizing channels with added attenuation.","lead":"This paper analyzes a quantum key distribution protocol for two users at different distances from a central relay, and computes secure key rates with realistic finite data sizes. It shows that optimizing the two users' light intensities separately can substantially outperform the old fix of adding extra loss to equalize channels.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Appendix B's pair-count formulas as printed contain an extra p^2 factor; they cannot reproduce Table IV, so the paper's central numerical claim rests on unstated corrected formulas.","rationale":"I agree with the reader that Eq. (5) is printed with the wrong inequality: a lower bound on the smooth min-entropy is needed for the finite-key security statement, so Eq. (5) should read H_min^epsilon(Z|E) >= M^Z_11[1-h(e^Z,ph_11)]. As written, the derivation of Eq. (6) is invalid. This is serious but looks like a one-character typo that could be corrected. The more load-bearing problem is that the Appendix B simulation formulas are internally inconsistent with the paper's own Table IV. The reported key rates are only reachable with the standard renewal-pairing prefactor [1-(1-p)^l]/p, while the printed formulas use r_p p^2, which is smaller by roughly 1/p^2. Because the central claim is quantitative and rests entirely on these simulated rates, this inconsistency means the numerical results are unsupported by the stated methods. No code or data are provided, so the discrepancy cannot be resolved by re-running the authors' implementation. I therefore keep the reader's REJECT verdict; the security typo alone might justify CONDITIONAL, but the simulation-formula inconsistency makes the central quantitative claim unreliable as presented.","tokens_in":12352,"tokens_out":28839,"duration_ms":263307,"concrete_test":"Implement Eqs. (B1)-(B3) exactly as printed, using the Table III parameters and the point B parameters of Table IV (LA+LB=200 km, Delta L=50 km). Compute M^Z_11 and the resulting SKR R=2L/N, and compare with the reported 1.84e-5 bit/pulse; the printed formula will be lower by roughly 1/p^2. As a second check, run a Monte Carlo simulation of the pairing rule (Bernoulli clicks with per-round probability q from Eq. (B1), pairing adjacent clicks within l=2000) and compare the simulated Z-pair counts with both the printed and the corrected prefactor to confirm which formula matches the protocol.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The key-rate numbers that support the central claim are generated by the simulation formulas in Appendix B, and those formulas are internally inconsistent with the reported results. Let p be the per-round click probability defined in Eq. (B1). With pairing interval l=2000, a click pairs with the next click with probability 1-(1-p)^l, so the expected number of pairs per round is p[1-(1-p)^l]. The two clicked rounds are drawn from the click-biased intensity distribution p_{k}q_{k}/p, so the correct count for a Z-pair label (k_a,k_b) is N * [1-(1-p)^l]/p * sum p_{i}p_{j}q_{i}q_{j}. Eq. (B2) instead defines r_p = (1/p)[1-(1-p)^l] + 1/p, and Eq. (B3) multiplies by an additional p^2. For the Table III-IV parameters p is about 10^-3, so the printed prefactor p^2 r_p is roughly 2p, whereas the correct prefactor is about 1/p; the mismatch is a factor of about 1/p^2, i.e., roughly five orders of magnitude. Implementing Eqs. (B1)-(B3) exactly as printed with point B of Table IV would therefore yield a key rate many orders of magnitude below the reported R=1.84e-5 bit/pulse. Since Table IV can only be reproduced with the standard 1/p prefactor, the manuscript's stated simulation formulas are not the formulas used to produce its central quantitative claims.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript derives a finite-key security analysis of asymmetric mode-pairing QKD with practical three-intensity decoy states and presents numerical key-rate simulations in which Alice's and Bob's source parameters are optimized independently by a modified particle swarm algorithm. The central quantitative claim is that this asymmetric-intensity optimization substantially improves the secure key rate relative to the strategy of adding extra attenuation to balance the channels, with representative numbers in Table IV (e.g., 1.84e-5 vs 5.71e-6 bit/pulse at 200 km total distance, Delta L = 50 km). The paper also studies how optimized intensities, probabilities, pairing intervals, and block sizes vary with distance.","tokens_in":12655,"tokens_out":8979,"duration_ms":86818,"significance":"The topic is timely: mode-pairing QKD is a leading protocol for moving beyond the repeaterless bound without global phase locking, and asymmetric network deployments need practical finite-key analyses. If the security bound and simulation formulas are correct, the contribution would be a useful engineering-oriented result, and the comparison with the attenuation strategy is a fair baseline. Credit is due for including the composable finite-key framework and for presenting the modified PSO approach; however, the two internal inconsistencies described below currently prevent the results from being taken as validated.","major_comments":[{"comment":"The printed inequality H^epsilon_min(Z|E) <= M^Z_11 [1 - h(e^Z,ph_11)] has the wrong direction for the purpose of Eq. (6). A secure final key length bounded below by the right-hand side requires a lower bound on the conditional smooth min-entropy, i.e., H^epsilon_min(Z|E) >= M^Z_11 [1 - h(e^Z,ph_11)]. As printed, Eq. (5) is an upper bound, so Eq. (6) is not a valid lower bound on the secure key length. The finite-key security conclusion rests on this sign, and the derivation should be corrected to '>=' or otherwise justified.","section":"Section II, Eq. (5)"},{"comment":"The pair-count prefactors are not consistent with the definitions given. The expected number of successful pairings per round is p [1 - (1-p)^l], and a click at a given round carries intensity label (k^a,k^b) with probability p_{k^a} p_{k^b} q_{k^a k^b} / p. Therefore the expected number of pairs with a specified intensity pair should scale as N [1 - (1-p)^l] / p times the product of the click-biased probabilities. Equations (B2)-(B3) instead define r_p = [1 - (1-p)^l]/p + 1/p and multiply by an additional p^2, yielding a prefactor of order p rather than 1/p. With p ~ 10^-3 and l = 2000, the printed formulas underestimate pair counts by roughly five orders of magnitude and cannot produce the count rates underlying Table IV. The simulation formulas must be corrected, and the reported numbers must be reconciled with the corrected formulas or accompanied by the simulation code.","section":"Appendix B, Eqs. (B1)-(B7)"}],"minor_comments":[{"comment":"The text refers to 'the upper chi and lower chi bounds' but prints both as the same symbol chi; introducing overline{chi} and underline{chi} would make the decoy-state formulas that use these bounds much easier to follow.","section":"Section II, Eq. (7)"},{"comment":"The notation n^Z_{(ka,kb)} is used for both the upper and lower Chernoff bounds in the printed equation, even though the two must generally take different values; please use distinct symbols, e.g., overline{n} and underline{n}.","section":"Section III, Eq. (9)"},{"comment":"Line 25 of Algorithm 1 uses a quantity R_new(Gbest) that is never defined; the termination criterion should be specified precisely, along with the numerical values of N_PSO, T, w_init, w_final, c1 ranges, c2 ranges, h, and zeta needed to reproduce the optimization.","section":"Appendix A, Algorithm 1"},{"comment":"The statement that the asymmetric-intensity strategy gives 'approximately an order of magnitude' improvement at LA+LB = 200 km is not supported for Delta L = 50 km, where Table IV shows a factor of 3.2; the factor is about 9.2 for Delta L = 100 km. The claim should be made quantitative and split by Delta L.","section":"Section III, discussion after Table IV"},{"comment":"The label 'total distance (LA+LB) between Alice and Bob' is imprecise, since LA and LB are the Alice-Charlie and Bob-Charlie distances and Charlie is not necessarily on the direct Alice-Bob path; please rephrase to 'sum of Alice-Charlie and Bob-Charlie distances'.","section":"Figure 1 and general notation"},{"comment":"The factor 2 Delta / pi in the X-pair formulas is introduced without explaining whether Delta is measured in radians or how the phase-slice acceptance condition maps to the postselection window; please define this explicitly.","section":"Appendix B, Eqs. (B6)-(B7)"}],"recommendation":"major_revision","confidential_remarks":"The two major issues are internal and are correctable in principle, so I do not recommend rejection outright. However, the burden is on the authors to supply corrected formulas and either the simulation code or a consistent worked example that reproduces Table IV. If the corrections are not provided, the numerical claims should not be accepted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Hi [Colleague],\n\nThe short version: this paper has a load-bearing error in its simulation formulas. The printed Appendix B contains an extra p^2 factor in Eq. (B3), so the counts n^Z_(ka,kb) come out about five orders of magnitude too small for the Table III/IV parameters. I checked the derivation: with p ≈ 1e-3 and l = 2000, the correct prefactor for a labeled pair count is N [1-(1-p)^l]/p, while the paper prints N r_p p^2 with r_p = [1-(1-p)^l]/p + 1/p. That mismatch alone means Table IV's R = 1.84e-5 cannot be obtained from the equations as written. Somebody would have had to use different formulas, so the paper's central numbers are not reproducible from the manuscript.\n\nThere is also the sign error in Eq. (5) that the desk reader caught: H_min^ε(Z|E) ≤ M[1-h] should be ≥ for the key length bound in Eq. (6) to go through. That is a smaller fix, but it is load-bearing for the security statement.\n\nTo be fair, the paper does address a real gap: asymmetric MP-QKD with finite-key effects and practical decoys was not done before, and the optimization of 12 parameters with a modified PSO is a sensible approach. The qualitative observation that independently optimized intensities beat adding attenuation is plausible and likely correct. The writing is clear and the structure is standard.\n\nBut the flaws are not cosmetic. The simulation formulas are the heart of the quantitative contribution. Without code or a corrected derivation, the reported rates, the intensity-ratio plots, and the conclusions about HOM visibility are unsupported. I would not cite this version, and I would not bring it to the reading group as is. The right path is a major revision with explicit corrected formulas, preferably backed by an executable script or a detailed step-by-step derivation of the counting prefactor. The topic is important enough that a serious referee should be assigned, but the current manuscript is not acceptable.\n\nBest,\n[Your name]","headline":"Irreproducible simulation formulas and a sign error undermine the paper's central numerical claims, though the underlying idea is worth pursuing.","tokens_in":13215,"tokens_out":13112,"would_cite":false,"duration_ms":102959,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper argues that asymmetric mode-pairing QKD should be run with independently optimized source intensities rather than extra attenuation, and provides a finite-key security analysis for that setting.","keywords":["mode-pairing quantum key distribution","asymmetric channels","finite-key security","decoy-state method","particle swarm optimization","secure key rate","universal composability"],"falsifier":"Recompute the step from Eq. (5) to Eq. (6) with an independent derivation of the smooth-min-entropy bound: the paper prints $H_{\\min}^{\\epsilon}(Z|E) \\le M^Z_{11}[1-h(e^{Z,\\mathrm{ph}}_{11})]$, while a valid lower bound on $L$ requires $\\ge$, so checking the sign settles the security claim. As a numerical cross-check, an independent implementation of the Appendix B formulas should reproduce point B of Table IV ($1.84\\times10^{-5}$ bit/pulse at $L_A+L_B=200$ km, $\\Delta L=50$ km).","tokens_in":12119,"feed_emoji":"🔐","tokens_out":14280,"duration_ms":110039,"temperature":0.7,"pith_summary":"Mode-pairing QKD uses paired detection events at a central node so that Alice and Bob need no global phase lock; the catch is that real networks often put them at unequal distances from Charlie. This paper argues that the unequal-distance case is better handled by giving Alice and Bob their own optimized intensities and probabilities than by adding loss to the closer side. It provides a finite-key security analysis with practical three-intensity decoy states and a 12-parameter global optimization, and claims this raises the secure key rate by a factor of roughly 3 at 50 km path imbalance and nearly an order of magnitude at 100 km, e.g. $1.84\\times10^{-5}$ versus $5.71\\times10^{-6}$ bit/pulse at $L_A+L_B=200$ km. If correct, it removes a major obstacle to deploying MP-QKD in star-shaped quantum networks.","feed_headline":"Asymmetric MP-QKD gets threefold key-rate gain at 50-km path mismatch","feed_subtitle":"Independent intensity optimization beats adding attenuation for mode-pairing QKD, with finite-key security at 200 km.","key_machinery":"The argument is carried by the finite-key rate expression $R=2L/N$, with $L$ bounded by $M^Z_{11}\\bigl[1-h(e^{Z,\\mathrm{ph}}_{11})\\bigr] - \\lambda_{\\mathrm{EC}} - \\log_2(2/\\varepsilon_{\\mathrm{cor}}) - 2\\log_2(1/\\varepsilon_{\\mathrm{sec}})$. Here $M^Z_{11}$ is the number of single-photon Z-pair events estimated from decoy-state yields $y^Z_{11}$, and $e^{Z,\\mathrm{ph}}_{11}$ is the phase-error rate estimated from X-pair bit errors by random sampling without replacement. Around that formula the paper builds a source-parameter vector of 12 independent intensities and probabilities, a Chernoff-bound treatment of statistical fluctuations, and a modified particle-swarm optimizer that enforces physical constraints while searching the non-convex rate landscape. The simulation formulas in Appendix B give the average response probability and pair/error counts in terms of Bessel functions and channel transmittances.","core_discovery":"On the paper's own terms, the discovery is that the optimal response to channel asymmetry is not to equalize channels by attenuating the closer party but to let the two sources be genuinely asymmetric. The authors derive a finite-key rate formula for three-intensity decoy-state MP-QKD under the universal composability framework ($\\epsilon=10^{-10}$), using Chernoff-bound statistical fluctuations and random sampling without replacement, and they maximize the rate over 12 independent source parameters with a modified particle swarm optimization. The numerical result is that this asymmetric-intensity strategy outperforms attenuation compensation at all tested distances: for $L_A+L_B=200$ km with $\\Delta L=50$ km the rate is $1.84\\times10^{-5}$ versus $5.71\\times10^{-6}$ bit/pulse, and with $\\Delta L=100$ km it is $5.89\\times10^{-6}$ versus $6.37\\times10^{-7}$. The optimized decoy intensities stay close to the rule $\\eta_a \\nu_a \\approx \\eta_b \\nu_b$, whereas the signal intensities deviate substantially, and increasing the maximum pairing interval improves the rate but does not let the asymmetric finite-key rate surpass the PLOB bound.","pith_inferences":["The near-universal behavior of the decoy intensities ($\\eta_a \\nu_a \\approx \\eta_b \\nu_b$) suggests a two-stage deployment recipe: fix $\\nu_a,\\nu_b$ by that rule and optimize the remaining signal intensities and probabilities, shrinking the live calibration problem.","Because the optimization ignores the rule $\\eta_a \\mu_a \\approx \\eta_b \\mu_b$ and still obtains high rates, the same independent-intensity approach may lift rates in other asymmetric two-photon-interference QKD schemes, such as twin-field variants, where that rule is often imposed.","An independent re-derivation of the entropy inequality in Eq. (5) is the first checkpoint before hardware investment: a reversed sign would invalidate the finite-key rate values rather than merely shift them."],"forward_implications":["At $L_A+L_B=200$ km the asymmetric-intensity strategy gives $1.84\\times10^{-5}$ bit/pulse with $\\Delta L=50$ km and $5.89\\times10^{-6}$ with $\\Delta L=100$ km, versus $5.71\\times10^{-6}$ and $6.37\\times10^{-7}$ for extra attenuation.","The optimized settings use unequal intensities: $\\mu_a$ drops and $\\mu_b$ rises as $\\Delta L$ grows, so field deployments need not force $\\eta_a \\mu_a \\approx \\eta_b \\mu_b$.","The decoy intensities do approximately follow $\\eta_a \\nu_a \\approx \\eta_b \\nu_b$, giving a practical rule of thumb for setting the decoy states in asymmetric links.","Finite-key security at $\\epsilon=10^{-10}$ is claimed for total pulse number $N=10^{13}$, so the rates are meant to be deployment-relevant rather than asymptotic idealizations.","Raising the maximum pairing interval $l$ increases the rate, but in the asymmetric finite-key regime the rate stays below the symmetric-channel value and below the PLOB bound."],"supporting_citations":[{"why":"Defines the MP-QKD protocol and pairing logic that the asymmetric extension builds on.","marker":"[9]"},{"why":"Gives the prior asymmetric MP-QKD analysis with ideal decoys and infinite key, the baseline this work makes practical.","marker":"[17]"},{"why":"Supplies the smooth-min-entropy chain-rule and uncertainty bounds behind Eqs. (4) through (6).","marker":"[22]"},{"why":"Provides the finite-key decoy-state security framework with statistical fluctuation and random-sampling bounds.","marker":"[25]"},{"why":"Supplies the Chernoff-bound fluctuation formulas used in Eq. (7).","marker":"[26]"},{"why":"Introduces the decoy-state method used to estimate single-photon yields and phase-error rates.","marker":"[27]"},{"why":"Source of the asymmetric-protocol parameter-optimization approach that the paper improves over attenuation.","marker":"[33]"},{"why":"Original particle swarm optimization which the modified PSO in Appendix A adapts.","marker":"[37]"}],"fun_headline_variants":["Asymmetric MP-QKD beats attenuation with finite-key analysis","Asymmetric MP-QKD: 3× key-rate gain over attenuation at 50 km","Finite-key MP-QKD: asymmetric intensities outperform attenuation","Asymmetric MP-QKD boosts key rates without global phase locking","MP-QKD finite-key: asymmetric sources beat added attenuation"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security proof depends on the direction of the smooth-min-entropy bound: the final key-length formula uses the expression in Eq. (5) as a lower bound on the secret randomness remaining to Alice, so if that inequality actually runs the other way, the advertised key rates are not proven secure.","fun_headline_variants_meta":{"raw":{"variants":["Asymmetric MP-QKD beats attenuation with finite-key analysis","Asymmetric MP-QKD: 3× key-rate gain over attenuation at 50 km","Finite-key MP-QKD: asymmetric intensities outperform attenuation","Asymmetric MP-QKD boosts key rates without global phase locking","MP-QKD finite-key: asymmetric sources beat added attenuation"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000134,"raw_usage":{"total_tokens":1155,"prompt_tokens":979,"completion_tokens":176,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":595,"completion_tokens_details":{"reasoning_tokens":87}},"tokens_in":595,"tokens_out":176,"duration_ms":2233,"temperature":1.0,"reasoning_tokens":87,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T13:56:23.822108+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Recompute the step from Eq. (5) to Eq. (6) with an independent derivation of the smooth-min-entropy bound: the paper prints $H_{\\min}^{\\epsilon}(Z|E) \\le M^Z_{11}[1-h(e^{Z,\\mathrm{ph}}_{11})]$, while a valid lower bound on $L$ requires $\\ge$, so checking the sign settles the security claim. As a numerical cross-check, an independent implementation of the Appendix B formulas should reproduce point B of Table IV ($1.84\\times10^{-5}$ bit/pulse at $L_A+L_B=200$ km, $\\Delta L=50$ km).","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Original particle swarm optimization which the modified PSO in Appendix A adapts."},{"cited_title":"Tomamichel and R","cited_arxiv_id":null,"evidence_quote":"Provides the finite-key decoy-state security framework with statistical fluctuation and random-sampling bounds."},{"cited_title":"Renner, Security of quantum key distribution, Inter- national Journal of Quantum Information 6, 1 (2008)","cited_arxiv_id":null,"evidence_quote":"Supplies the Chernoff-bound fluctuation formulas used in Eq. (7)."},{"cited_title":"Curty, F","cited_arxiv_id":null,"evidence_quote":"Introduces the decoy-state method used to estimate single-photon yields and phase-error rates."}],"review_version":1}