{"id":"8bfedcac-3b0f-45a5-8764-558a803907ae","arxiv_id":"2412.18837","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":1,"one_line_summary":"First experimental demonstration of entanglement-free secure quantum remote sensing, estimating phase over 50 km optical fiber with a pre-calibration correction.","lead":"An experimental team sent single-photon polarization states over 50 km of optical fiber and used them to estimate a remote phase while claiming eavesdroppers learn little. It is the first long-distance test of an entanglement-free version of secure quantum remote sensing.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Secure claim rests on single-photon assumption, but source is weak coherent with no reported mean photon number or decoy-state analysis, leaving a photon-number-splitting loophole that the paper's security validation does not address.","rationale":"The reader's weakest assumption correctly identifies the weak coherent source as the most load-bearing gap. The paper's central contribution is an experimental demonstration of secure entanglement-free remote sensing, but the security argument (both in the protocol reference [55] and in the experimental validation) is built on single-photon states. The actual source is an attenuated laser, which inevitably produces multi-photon pulses. Without a reported μ or decoy states, an eavesdropper can exploit multi-photon pulses via PNS attacks, as is standard in QKD. The paper's own security check only considers a passive Eve who listens to classical announcements and computes a ratio, which is insufficient. This is not a minor detail: it directly affects whether the headline claim of 'secure' is established. I considered other potential concerns, such as the pre-calibration technique revealing calibration information, but that is less fundamental because the calibration pulses are known and discarded; the photon-number statistics are the first-order issue. The experimental phase estimation data may be sound, but the security conclusion is not supported as written. Since the reader already reached a conditional verdict, my analysis does not change that verdict; however, it reinforces the need for the authors to supply the missing source characterization and a proper PNS-resilient security analysis before the claim can be accepted.","tokens_in":10202,"tokens_out":5581,"duration_ms":58688,"concrete_test":"Re-analyze the security under a photon-number-splitting attack using the actual mean photon number μ of the source: compute the probability of multi-photon pulses, then calculate Eve's CFI for phase estimation and her knowledge of BB84 bits when she stores one photon from each multi-photon pulse and measures after Bob's basis-revealing announcement. If Eve's information is not negligible compared with Alice's (or if the QBER exceeds the threshold required by the underlying security proof), the security claim fails; the authors should also report μ and, if needed, implement a decoy-state protocol to restore security.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central 'secure' claim depends on the transmitted pulses being single photons. Section III describes the source as a phase-randomized laser and attenuator, but no mean photon number is reported and no decoy-state method is used. For a weak coherent source with mean photon number μ, the multi-photon probability per pulse is approximately μ²/2 for small μ. An eavesdropper can apply a photon-number-splitting (PNS) attack: split off one photon from every multi-photon pulse, store it, and later, after Bob publicly announces which detector clicked (which reveals his measurement basis for each pulse in Path 2), measure the stored photon in that basis to learn the BB84 bit. This directly undermines the BB84 sub-protocol that backs the SQRS security, and it also gives Eve extra copies of the phase-encoded states in Path 1, increasing her Fisher information beyond the paper's quoted ratio-only bound. Section IV and Appendix A compute Eve's CFI only from the classical ratio (n1+n3+n5+n7)/Σn_i and do not account for such quantum attacks. Therefore, the experimental data as presented do not support the word 'secure' unless μ is shown to be negligibly small or a decoy-state analysis is added.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript reports an experimental implementation of an entanglement-free secure quantum remote sensing (SQRS) protocol over 50 km of optical fiber. Alice encodes weak coherent pulses, attenuated to approximate single photons, into the eigenstates of sigma_x and sigma_y and transmits them to Bob. Bob randomly routes each pulse either to a phase-sensing arm, where a known phase is imprinted and the state is measured in the sigma_y basis, or to a BB84-type measurement arm. The authors introduce a pre-calibration step that subtracts measured error probabilities from the likelihood function to remove the phase-ambiguity problem, report a QBER below 6%, estimate nine phases between 0 and 2pi, and compare Alice's and Eve's classical Fisher information for two selected phases. The phase estimates agree with the set values and their deviations are close to the Cramér-Rao bound.","tokens_in":10442,"tokens_out":5963,"duration_ms":59846,"significance":"If the security claim were fully supported, this would be a useful practical step: it would show that entanglement-free single-photon polarization states can support SQRS over metropolitan fiber lengths with near-Cramér-Rao-limited phase precision, avoiding the harder task of entanglement generation. The phase-estimation component is convincing and well matched to the ideal model. However, the security claim is not established by the current data, because the weak coherent source is not accompanied by a mean-photon-number measurement or a decoy-state analysis, and because Eve's information is evaluated only against a restricted classical-ratio attack. The experimental contribution is therefore better characterized as a phase-estimation demonstration with a protocol-level security argument inherited from Ref. [55] rather than a complete experimental validation of secure SQRS.","major_comments":[{"comment":"The central 'secure' claim rests on the transmitted pulses being single photons, but the source is described as a phase-randomized laser and attenuator with no reported mean photon number mu and no decoy-state analysis. For a weak coherent source with non-negligible mu, a fraction of pulses contain multiple photons, and in the BB84 arm these multi-photon events enable photon-number-splitting attacks that the reported QBER<6% does not bound. The manuscript must either report mu and demonstrate that it is negligibly small, add a decoy-state or loss-tolerant security analysis, or explicitly restrict the security claim to an idealized single-photon model.","section":"Section III and Section IV"},{"comment":"Eve's Fisher information is computed exclusively from the classical ratio (n1+n3+n5+n7)/sum_i n_i, with the assertion in Section IV that this is 'the only information Eve can steal for phase estimation.' This assertion is not derived from a well-defined attack model. Eve could attack the quantum channel in ways not captured by this classical ratio, and in the presence of multi-photon pulses her accessible information is not bounded by this statistic. A security claim requires either a full security proof connecting the implemented measurement statistics to Eve's accessible Fisher information under general attacks, or an explicit adversary model and evidence that the implemented source satisfies it.","section":"Section IV and Appendix A"},{"comment":"The security validation is performed for only two phases, phi8=5.515 and phi9=6.013. The statement that the ratio is almost constant 'for each phase' is not a substitute for a Fisher-information analysis at all tested phases, and a phase-dependent leakage channel is not excluded by the two selected points. Reporting Eve's and Alice's CFI for all nine phases, or providing a worst-case bound over phi, would properly support the claimed information-asymmetry advantage.","section":"Section IV"},{"comment":"The statement that the pre-calibration technique 'does not introduce any security vulnerabilities' is asserted without proof. Because pre-calibration involves Bob announcing known-phase measurement data over the public classical channel, the effect of these auxiliary data on Eve's knowledge should be analyzed, and the protocol's security proof should be extended to cover this additional classical communication.","section":"Section II.B"}],"minor_comments":[{"comment":"The phrase 'probabilistically generate single-photon states' is not accurate for an attenuated coherent source; the output is a weak coherent state with a Poisson photon-number distribution, which is precisely why the missing mu value is important.","section":"Section III"},{"comment":"The vertical axis is labeled 'Fisher Information (arb. units)', but the CFI defined in Eq. (4) is dimensionless; the label should be reconciled with the definition.","section":"Figure 5"},{"comment":"The derivative used to compute CFI is approximated with only two neighboring points, but no statistical uncertainty for the resulting Fisher information is reported; error bars or a bootstrap estimate would make the comparison with the Cramér-Rao bound more robust.","section":"Appendix A"},{"comment":"There is a typo in the caption: 'whitout' should be 'without'.","section":"Figure 1 caption"},{"comment":"Several references contain typographical errors, including 'Nat. Commum.' in Ref. [41] and inconsistent journal-name formatting for AVS Quantum Science; these should be corrected.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The phase-estimation core of the paper is sound and the 50-km distance is a useful technical milestone. The main obstacle is that the title and abstract claim 'secure' SQRS, but the source characterization and the restricted Eve model do not support that claim. If the authors add a mean-photon-number and decoy-state analysis (or explicitly restrict the claim to a single-photon-idealized demonstration) and provide a clearer attack model for the Fisher-information comparison, the paper could become publishable. I would also suggest that the pre-calibration security assertion be substantiated rather than stated."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the sensing experiment is real, but the security claim is not backed by the evidence. If you treat the paper as a demonstration of entanglement-free phase estimation over 50 km of fiber, it is a solid, useful result. If you read the title literally, the protocol is not yet proven secure.\n\nWhat is new: this is the first experimental implementation of Moore and Dunningham's entanglement-free SQRS protocol, and the pre-calibration technique for handling dark counts and misalignment is a reasonable practical step. The data in Figs. 4 and 6 are internally consistent; the estimated phases track the ideal values, and the deviations roughly follow the Cramér–Rao bound. The QBER below 6% also meets the protocol's stated requirement. That part of the work is done well.\n\nThe soft spot is the security analysis. The source is a phase-randomized weak coherent laser with an attenuator, but no mean photon number is reported and no decoy-state or finite-key analysis is given. Appendix A computes Eve's classical Fisher information from the ratio (n1+n3+n5+n7)/Σn_i, which only models an eavesdropper who sees Bob's publicly announced detector clicks. That is not a full adversary. A quantum Eve can perform a photon-number-splitting attack on multi-photon pulses: split off and store one photon, then measure it later after the basis is revealed. That compromises the BB84 sub-protocol in Path 2 and also gives Eve extra copies of the phase-encoded states in Path 1, increasing her Fisher information beyond the quoted ratio-only bound. Until μ is shown to be negligibly small or a decoy-state analysis is added, the word \"secure\" is not supported.\n\nThe pre-calibration subtraction in Eq. (3) is a post-processing correction, and the paper asserts it introduces no security risk without giving an argument. That is a minor omission relative to the PNS gap, but worth addressing.\n\nI also would have liked error bars on the phase and CFI plots, and ideally a data release, but that is a minor point. The citation pattern looks fine; the authors clearly build on [55] and related SQRS work.\n\nBottom line: the paper deserves a serious referee. The experimental demonstration is valuable, and the security gap is potentially fixable by embedding decoy-state BB84, reporting μ, or softening the claim to \"classical-information-limited.\" A referee should ask for one of those.\n\nI would bring it to a reading group if the focus were experimental quantum sensing, and I would cite it as an experimental milestone if I worked in that niche. I would not cite its security claims as established.","headline":"A real 50-km single-qubit phase-sensing demonstration whose 'secure' claim is only supported against a classical ratio-only attack, not a full quantum eavesdropper.","tokens_in":10942,"tokens_out":1828,"would_cite":false,"duration_ms":19166,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P50"],"pacs":["03.67.Dd","03.67.-a"],"model":"deepseek-v4-flash","headline":"Entanglement-free secure quantum sensing works over 50 km of fiber.","keywords":["secure quantum remote sensing","entanglement-free protocol","phase estimation","BB84","Fisher information","single-photon polarization states","optical fiber","Cramér-Rao bound"],"falsifier":"Measure the mean photon number $\\mu$ per pulse of the phase-randomized laser and compute the multi-photon fraction $1-e^{-\\mu}(1+\\mu)$. If that fraction is large enough for a photon-number-splitting attack to give Eve a classical Fisher information comparable to Alice's, the claimed security asymmetry would not hold; the paper reports no $\\mu$ or decoy-state analysis, so this check is open.","tokens_in":10013,"feed_emoji":"📡","tokens_out":8777,"duration_ms":75868,"temperature":0.7,"pith_summary":"The paper reports a 50 km fiber demonstration of secure quantum remote sensing that does not use entanglement: Alice transmits polarization states chosen from the $\\sigma_x$ and $\\sigma_y$ eigenstates, Bob splits each incoming photon-level pulse between a sensing arm that encodes an unknown phase and a BB84-style arm that checks channel security, and Alice estimates the phase by maximizing a likelihood built from the eight possible detection outcomes. The measured phases track the nine preset values from $0$ to $2\\pi$, with deviations close to the Cramér-Rao bound. Security is quantified by a classical Fisher information asymmetry: at two representative phases Alice's total information is about four while an eavesdropper who intercepts Bob's classical readout gets roughly two orders of magnitude less. The authors argue this makes single-qubit states, which are easier to prepare than entangled pairs, a practical route to long-distance secure sensing.","feed_headline":"Quantum remote sensing works over 50 km without entanglement","feed_subtitle":"An entanglement-free protocol estimates a remote phase over metropolitan fiber with near-optimal precision and a tight information leak.","key_machinery":"The central mechanism is the entanglement-free SQRS protocol itself: Alice randomly sends one of the four polarization eigenstates of $\\sigma_x$ and $\\sigma_y$; Bob directs each pulse through a beam splitter into a sensing arm, where the unknown phase $\\phi$ is encoded and the state is measured in the $\\sigma_y$ basis, and a security arm, where the pulse is measured in the $\\sigma_x$ or $\\sigma_y$ basis as in BB84. Phase estimation uses the eight outcome probabilities of Table I to build a likelihood function $L(\\varphi)$ whose maximum is the phase estimate; the same probabilities give the classical Fisher information that separates Alice's information from Eve's. The paper's pre-calibration technique measures eight nonzero error probabilities using known phases $\\{0,\\pi/2,\\pi,3\\pi/2\\}$ and subtracts them from the likelihood, ensuring a single maximum despite real-world imperfections.","core_discovery":"On the paper's own terms, the central discovery is that entanglement is not needed for secure remote sensing of a phase. A random sequence of four single-qubit polarization states, split between a sensing measurement and a BB84 verification measurement, is sufficient for Alice to estimate an unknown phase at Bob's location while keeping Eve's accessible information far below her own. Over 50 km of optical fiber, the experiment estimates nine phases with errors near the Cramér-Rao bound, and for the two phases examined in detail Alice's classical Fisher information is about 4 while Eve's is about 0.008 and 0.011. A pre-calibration step, in which Alice sends known phases and subtracts the resulting error probabilities from the likelihood, removes the ambiguity that dark counts and optical misalignment otherwise create at phases such as $\\pi$.","pith_inferences":["If the four-state encoding already provides a BB84 check, any deployed QKD link could in principle double as a secure sensing channel without extra state preparation.","Because the source is a phase-randomized laser with an attenuator, the multi-photon fraction, not the fiber loss, is the next quantity that would bound the achievable security; a decoy-state version is the natural extension.","The experiment evaluates Eve's Fisher information at only two phases; mapping the full phase circle would show where the security margin is thinnest.","With phase stabilization, the same setup could be read as a distributed fiber sensor tracking environmental phase drift, not just a discrete sensor at Bob's site."],"forward_implications":["Secure remote phase sensing is achievable over metropolitan fiber distances without entangled sources.","The sensing path and the BB84 path share the same transmitted states, so a single sequence supports both sensing and channel security.","Pre-calibration removes the likelihood degeneracy caused by dark counts and misalignment, and because it runs in post-processing it does not change the hardware or the security analysis.","At the phases tested, Alice's Fisher information is near its ideal value of four while Eve's is about two orders of magnitude lower, giving Alice a far tighter phase estimate.","The measured estimation deviations are close to the Cramér-Rao bound, so the security filtering does not destroy metrological precision."],"supporting_citations":[{"why":"Supplies the entanglement-free SQRS protocol that the experiment implements and whose security properties are being tested.","marker":"[55]"},{"why":"Provides the BB84 measurement and key-check procedure used in Path 2 to secure the channel.","marker":"[3]"},{"why":"Earlier experimental demonstration of SQRS with entangled states, the baseline the present work replaces with single-qubit states.","marker":"[54]"},{"why":"Introduces the secure quantum remote sensing scenario and its security formulation.","marker":"[48]"},{"why":"Establishes the secrecy-capacity and asymmetric Fisher information framework used to argue security.","marker":"[49]"},{"why":"Sagnac-based polarization modulation module used to prepare the four eigenstates at Alice's site.","marker":"[56]"},{"why":"Polarization analysis module used to implement the sigma-x and sigma-y BB84 measurements at Bob's site.","marker":"[57]"}],"fun_headline_variants":["Quantum sensing goes secure over 50 km without entanglement","Entanglement-free secure quantum sensing at 50 km","Single qubits suffice for secure remote sensing over 50 km","Secure quantum phase sensing over 50 km, no entanglement","Quantum remote sensing reaches 50 km with simpler states"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security conclusion assumes the transmitted pulses behave as single photons; the experiment uses a phase-randomized laser with an attenuator, which can emit multi-photon pulses, and reports no mean photon number or decoy-state analysis ruling out their exploitation.","fun_headline_variants_meta":{"raw":{"variants":["Quantum sensing goes secure over 50 km without entanglement","Entanglement-free secure quantum sensing at 50 km","Single qubits suffice for secure remote sensing over 50 km","Secure quantum phase sensing over 50 km, no entanglement","Quantum remote sensing reaches 50 km with simpler states"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000202,"raw_usage":{"total_tokens":1316,"prompt_tokens":812,"completion_tokens":504,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":428,"completion_tokens_details":{"reasoning_tokens":425}},"tokens_in":428,"tokens_out":504,"duration_ms":4624,"temperature":1.0,"reasoning_tokens":425,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T04:26:04.988391+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure the mean photon number $\\mu$ per pulse of the phase-randomized laser and compute the multi-photon fraction $1-e^{-\\mu}(1+\\mu)$. If that fraction is large enough for a photon-number-splitting attack to give Eve a classical Fisher information comparable to Alice's, the claimed security asymmetry would not hold; the paper reports no $\\mu$ or decoy-state analysis, so this check is open.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the entanglement-free SQRS protocol that the experiment implements and whose security properties are being tested."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Earlier experimental demonstration of SQRS with entangled states, the baseline the present work replaces with single-qubit states."},{"cited_title":"Takeuchi, Y","cited_arxiv_id":null,"evidence_quote":"Introduces the secure quantum remote sensing scenario and its security formulation."},{"cited_title":"Li, Y.-H","cited_arxiv_id":null,"evidence_quote":"Sagnac-based polarization modulation module used to prepare the four eigenstates at Alice's site."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Polarization analysis module used to implement the sigma-x and sigma-y BB84 measurements at Bob's site."}],"review_version":1}