{"id":"a6391d85-29c4-4293-b7f6-e3282b991153","arxiv_id":"2501.01549","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":3.0,"correctness_risk":"high","formal_verification":"none","parameter_count":0,"one_line_summary":"The proposed quantum Goppa codes from maximal curves are not supported because the divisor degrees, dimension formulas, and parameter ranges in the paper contradict each other.","lead":"This paper constructs Goppa codes from curves of the form y^n = x^m + x and converts them into quantum stabilizer codes. The main parameter calculations are internally inconsistent, so the stated code families are not established as written.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"D = X(F_q2) \\ X(F_q) has degree 12 for q=3, m=3, not the claimed q^2=9, so Theorem 5.2's length and derived parameters do not apply to the code actually constructed.","rationale":"The central claim is Theorem 5.2's construction of q-ary [[q^2,...]] quantum codes. The construction begins with a divisor D asserted to have degree q^2. If deg(D) is not q^2, then no code produced by the construction has length q^2, so the theorem cannot be about the code actually defined. The q=3, m=3 case is not an edge case; it is one of the paper's own examples (Example 5.3), and the point counts are elementary and verifiable. The reader's weakest assumption identifies exactly this divisor-degree error, and the proposed test settles it. The additional dimension-formula inconsistency noted by the reader is real but secondary; the divisor-degree error alone is sufficient to reject Theorem 5.2 as stated. There is no machine-checked proof or reproducible code accompanying the paper that would offset this, and the simulation section describes codes with parameters that do not match the theorem's formulas.","tokens_in":9976,"tokens_out":20022,"duration_ms":182401,"concrete_test":"Using SageMath or Magma, construct the nonsingular projective model of y^2=x^3+x over F_9, enumerate all F_9- and F_3-rational affine points, add points at infinity, and compute deg(D)=#X(F_9)-#X(F_3). If deg(D)=12 (as direct counting gives), then the code length in Theorem 5.2 is 12 rather than 9; recompute the claimed [[9,5,2]] quantum code from CL(D,G) with G=2*sum_{P in X(F_3)} P and verify that the length and dimension are not 9 and 2.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section 3 fixes the divisor D = sum_{P in X(F_q2)\\X(F_q)} P and asserts deg(D)=q^2. This is false for the curves used in Theorem 5.2. For the paper's own q=3, m=3 example, the curve y^2=x^3+x has #X(F_9)=q^2+1+2gq=16 points and #X(F_3)=4 (affine (0,0), (2,±1), plus the point at infinity), so deg(D)=12, not 9. The false degree is load-bearing because (1) the code CL(D,G) has length 12, whereas Theorem 5.2 claims quantum codes of length q^2=9, and (2) Lemma 3.5's dual-containment identity and the distance formula in Theorem 5.2 are derived using (t)=D-q^2P∞, which requires the complement to have exactly q^2 points. Since #X(F_q2)=q^2+1+2gq for every odd q≥3 in this family, the claimed parameter family is not about the code the paper defines.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper investigates algebraic-geometric (Goppa) codes associated with maximal curves y^{(q+1)/2}=x^m+x over F_{q^2}, claims Hermitian self-orthogonality for certain divisors, and applies the standard Ashikhmin-Knill construction to obtain quantum stabilizer codes. It also reports simulation results intended to illustrate performance. The main result, Theorem 5.2, asserts q-ary [[q^2, q^2 + (q-1)(m-1)/2 - 2 - 2r, r - (q-1)(m-1)/2 + 2]]_q quantum codes for q-1 <= r <= 2(q-1). The paper's own definitions and equations, however, contradict this statement: the divisor D defined in Section 3 does not have degree q^2 for the curves used, the self-orthogonality theorem is proved only for r <= q-1 while Theorem 5.2 uses r up to 2(q-1), and the dimension formula in Proposition 3.6 yields k_r > n for the examples in Example 5.3.","tokens_in":10311,"tokens_out":9803,"duration_ms":88277,"significance":"If the main theorem were correct, it would give a systematic family of quantum stabilizer codes from maximal curves with explicit dimension-distance trade-offs, together with a concrete comparison against known tables. The paper deserves credit for making the quantum-code step explicit and for attempting concrete examples. However, the central claim is not supported by the manuscript's own calculations: the false divisor degree changes the code length, the self-orthogonality argument does not cover the stated parameter range, and the dimension formula is internally inconsistent. The simulations in Section 4 are not tied to the theoretical construction in a verifiable way. I do not see machine-checked proofs or reproducible code in the manuscript; the cited GitHub repository is external and not included. Because the defects lie at the heart of the parameter formulas, the claimed theorem cannot be accepted as stated.","major_comments":[{"comment":"In Section 3 the paper defines G = X(F_q) and D = X(F_{q^2})\\G, then asserts deg(G)=r(q+1) and deg(D)=q^2. For the curves used in Theorem 5.2 and Example 5.3, take q=3 and m=3: the curve y^2=x^3+x has 16 F_9-rational points and 4 F_3-rational points, so the complement has 12 points, not 9. The assertion deg(D)=q^2 is therefore false for the paper's own example, and the divisor identity (t)=D - q^2 P_infinity used in Lemma 3.5 is not valid. Since the code length n=q^2 and every subsequent parameter formula depend on this degree, the construction as written does not apply to the claimed code family.","section":"Section 3 (divisor definitions)"},{"comment":"Theorem 5.2 states the parameter range q-1 <= r <= 2(q-1), but its proof invokes Theorem 3.9, which establishes Hermitian self-orthogonality only for r <= q-1. No argument is supplied for q-1 < r <= 2(q-1). In Example 5.3(1), the values r=3 and r=4 are outside the range established by Theorem 3.9. Moreover, even for r <= q-1 the claimed quantum parameters are impossible: with q=3, m=3, r=2, Proposition 3.6(3) gives k_r = 7 (or 8 by the Riemann-Roch formula stated in the proof), so n - 2k_r is negative and Lemma 5.1 cannot produce a [[9,5,2]]_3 code.","section":"Theorem 5.2 and its proof"},{"comment":"Proposition 3.6(3) contains an arithmetic inconsistency. The genus is g=(q-1)(m-1)/4, obtained from g=(m-1)((q+1)/2-1)/2, but the proof writes g=(q-1)(m-1)/2, and the displayed formula k_r = r(q+1) - (q-1)(m-1)/4 omits the '+1' from the Riemann-Roch theorem. As a result the dimension formula is wrong by 1 in general and does not match the Riemann-Roch computation even when the divisor degree is corrected. This affects the quantum dimension n-2k_r in Theorem 5.2 and all examples built on it.","section":"Proposition 3.6(3)"},{"comment":"Section 4.1 reports simulations of three Goppa codes over F_16 with parameters [8,2,6], [16,4,13], and [32,3,28], obtained from curves y^{(q+1)/2}=x^m+x with m=3,4,5. The exposition gives no valid q for these curves: if the field is F_16 = F_{q^2}, then q=4 and (q+1)/2 is not an integer, so the curve equation is undefined. The code lengths also do not follow from the divisors D and G defined in Section 3. Consequently the simulation section does not provide empirical support for the theoretical claims.","section":"Section 4.1"}],"minor_comments":[{"comment":"The symbol n is used both for the curve exponent (n=(q+1)/2 in Section 1) and for the code length (n=q^2 in Section 3); these should be disambiguated.","section":"Throughout"},{"comment":"The symbol G denotes both a set of rational points and the divisor r * sum(P); the notation should be separated.","section":"Section 3"},{"comment":"The expression '(t) = D = q^2 P_infinity' is ambiguous and should be written as (t)=D - q^2 P_infinity if that is the intended divisor identity.","section":"Lemma 3.5"},{"comment":"The proof of Theorem 3.9 derives self-orthogonality through an unnecessarily weak chain of inequalities; as written the final inequality uses (q-1)(m-1)/2 >= q+1 and is not generally valid, although the claimed range r <= q-1 would follow directly from Lemma 3.5 were that lemma valid.","section":"Theorem 3.9"},{"comment":"The generator and parity-check matrices in Example 3.2 are typeset in a garbled way, making it impossible to verify the claimed [8,3,5]_4 parameters from the displayed matrices.","section":"Example 3.2"},{"comment":"References [2]-[4] on power-system optimization are not connected to the coding-theory content and should either be integrated into the discussion or removed.","section":"References"}],"recommendation":"reject","confidential_remarks":"The manuscript has several features that are concerning beyond the technical errors: the bibliography contains many self-citations, the acknowledgment to a reviewer is unusual, and the simulation section appears disconnected from the mathematical construction. I do not base the rejection on those features; the technical inconsistencies in Sections 3 and 5 are decisive. The fit with math.AG is acceptable, but the paper would need a complete reworking of the divisor setup and the parameter formulas to become publishable, rather than a local correction."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague, the punchline: the central construction is not just unproven, it is contradicted by the paper's own equations. The stress-test note is right on the money. For q=3, m=3, the curve y^2=x^3+x has 16 F_9-rational points and 4 F_3-rational points, so the divisor D = X(F_9)\\X(F_3) has degree 12, not the claimed q^2=9. Since every parameter in the paper (code length, dual containment, distance) is computed off deg(D)=q^2, the claimed family doesn't exist as stated.\n\nHonest credit: the paper is a straightforward application of the standard Ashikhmin-Knill/Jin-Xing scheme to the Tafazolian-Torres maximal curves y^((q+1)/2)=x^m+x. The basis description in Lemma 3.4 is the standard Weierstrass semigroup argument, and the author has clearly read the relevant literature on Hermitian and AG codes. The motivation—systematic parameter trade-offs even when distances are not optimal—is a reasonable thing to want.\n\nSoft spots, in order of severity. (1) The false divisor degree kills the length. This is not a minor typo; it is load-bearing. (2) Theorem 5.2 uses r up to 2(q-1), while Theorem 3.9 only proves Hermitian self-orthogonality for r <= q-1. Even if the degree were fixed, the proof doesn't cover the stated range. (3) The dimension formula in Proposition 3.6 gives k_r = r(q+1) - (q-1)(m-1)/4, which for q=3, m=3, r=2 gives k_2=7, making n-2k negative and inconsistent with the claimed [[9,5,2]] code. (4) The simulation section is disconnected from the theory: it works over F_16, flips bits, and reports lengths 8, 16, 32—none of which match q^2 for any q in the examples. The section reads as if it were generated without being checked against the rest of the paper.\n\nBottom line: the paper assembles the right toolkit but the specific results are not valid. A reader looking for a clean example of self-orthogonal AG codes on special maximal curves could learn something from the setup, but they would have to redo the divisor arithmetic first. This does not deserve referee time as is; it should go back for a major rewrite with the arithmetic corrected, at which point there may be a salvageable small result. I would not cite it, and I wouldn't bring it to reading group.\n\nRecommendation: desk reject with encouragement to resubmit a corrected version, if the author fixes the divisor degree and the r-range.","headline":"The main result collapses on a false divisor degree, and the parameter claims don't follow from the paper's own lemmas.","tokens_in":10765,"tokens_out":3853,"would_cite":false,"duration_ms":32571,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["11T71","14G50","94B27","81P70"],"pacs":[],"model":"deepseek-v4-flash","headline":"Maximal curves of the form $y^{(q+1)/2}=x^m+x$ over $F_{q^2}$ are claimed to produce Hermitian self-orthogonal Goppa codes, and hence systematic families of $q$-ary quantum stabilizer codes with explicit parameter formulas.","keywords":["Goppa codes","algebraic geometry codes","quantum stabilizer codes","maximal curves","Hermitian self-orthogonal codes","finite fields","Riemann-Roch spaces","error-correcting codes"],"falsifier":"For $q=3$ and $m=3$, count the $F_9$- and $F_3$-rational points of the curve $y^2=x^3+x$ and check whether their difference equals 9; the claimed $[[9,5,2]]_3$ quantum code and the length formula $n=q^2$ stand or fall on that difference.","tokens_in":9780,"feed_emoji":"⚛️","tokens_out":13207,"duration_ms":106174,"temperature":0.7,"pith_summary":"The paper aims to show that Goppa codes attached to a specific family of maximal curves—those defined by $y^{(q+1)/2}=x^m+x$ over $F_{q^2}$—are Hermitian self-orthogonal in a range of divisor degrees, so the standard stabilizer construction converts them into explicit families of $q$-ary quantum error-correcting codes whose length, dimension, and distance are given by closed formulas. It also simulates three classical members of the family over $F_{16}$ and reports how decoding success degrades as noise increases, arguing that the family offers parameter trade-offs even where it does not beat the best known codes. If the construction is right, it gives a systematic, uniform source of quantum codes from one algebraic-geometric family, with parameters readable directly from a formula.","feed_headline":"A curve family yields quantum codes with tunable parameters","feed_subtitle":"Goppa codes from the curves $y^{(q+1)/2}=x^m+x$ give explicit stabilizer families and performance trade-offs.","key_machinery":"The machinery is a divisorial duality for one-point Goppa codes on the maximal curve $X:y^{(q+1)/2}=x^m+x$. With $D$ the sum of the $F_{q^2}$-rational points outside $X(F_q)$ and $G=r$ times the sum of the $X(F_q)$-points, the differential $\\eta=dt/t$ with $t=x^m-x$ makes the canonical divisor explicit and yields $C_r^\\perp=C_{q^2+(q-1)(m-1)/2-r}$. That identity converts a bound on $r$ into Hermitian self-orthogonality, and the stabilizer construction converts the self-orthogonal classical codes into quantum codes.","core_discovery":"The paper's central claim is that the Goppa codes attached to the divisors $D=X(F_{q^2})\\setminus X(F_q)$ and $G=r\\sum_{P\\in X(F_q)}P$ on the maximal curve $X:y^{(q+1)/2}=x^m+x$ over $F_{q^2}$ satisfy a clean duality: the Hermitian dual of $C_r$ is again a code in the same family, $C_r^\\perp=C_{q^2+(q-1)(m-1)/2-r}$ (Lemma 3.5). From this, $C_r$ is Hermitian self-orthogonal whenever $r$ is small enough, and Theorem 3.9 gives the explicit sufficient condition $r\\le q-1$. Applying the standard stabilizer-code conversion yields Theorem 5.2: for $q-1\\le r\\le 2(q-1)$ there exist $q$-ary quantum codes with parameters $[[q^2, q^2+(q-1)(m-1)/2-2-2r, r-(q-1)(m-1)/2+2]]_q$, illustrated by examples such as $[[9,5,2]]_3$ and $[[25,19,2]]_5$. The paper also simulates three classical members of the family over $F_{16}$—$[8,2,6]$, $[16,4,13]$, and $[32,3,28]$—and reports how their decoding success degrades as noise grows.","pith_inferences":["A direct point count for small cases can test the divisor-degree assumption: if $\\deg(D)$ is not $q^2$, the length and distance formulas would need revision even though the dual-code identity itself would remain a valid algebraic statement.","The proof of Theorem 5.2 establishes Hermitian self-orthogonality only for $r\\le q-1$, while the theorem states the range $q-1\\le r\\le 2(q-1)$; supporting the full range would require a sharper self-orthogonality bound.","Because the duality identity is divisor-based rather than curve-specific, the same mechanism could be tried on other maximal curves with two distinguished point sets, potentially generating analogous quantum code families.","The simulation's decoder only flips single bits, so its success rates are a lower bound on what full syndrome decoding could achieve; rerunning the same curves with a proper decoder would give a sharper performance comparison."],"forward_implications":["For every prime power $q$ and admissible $m$, Theorem 5.2 would produce a whole family of $q$-ary quantum codes of length $q^2$ with dimension and distance given directly by the formulas, so no search is needed.","The dual-code identity supplies a general self-orthogonality test for these Goppa codes: $C_r$ is self-orthogonal whenever $2r \\le q^2+(q-1)(m-1)/2$, and Theorem 3.9 gives the simpler sufficient condition $r\\le q-1$.","The simulated classical codes $[8,2,6]$, $[16,4,13]$, and $[32,3,28]$ over $F_{16}$ show the expected trade-off: shorter codes decode reliably at low error rates, while longer codes hold a higher success rate under heavier noise.","Some resulting quantum codes trade one unit of minimum distance for a larger dimension relative to the best-known tables, which is useful when information rate matters more than distance."],"supporting_citations":[{"why":"Supplies the standard construction converting a Hermitian self-orthogonal classical code into a quantum stabilizer code, used for Theorem 5.2.","marker":"[1]"},{"why":"Introduces the algebraic-geometric code construction that the paper applies to maximal curves.","marker":"[7]"},{"why":"Online database of best-known code parameters used as the comparison baseline in the examples.","marker":"[8]"},{"why":"Source for the Riemann-Roch dimension formula and AG-code background used in Proposition 3.6.","marker":"[9]"},{"why":"Source of the duality identity for AG codes that underlies Lemma 3.5.","marker":"[29]"},{"why":"Establishes maximality of the curves $y^n=x^m+x$ over $F_{q^2}$, supplying the rational-point counts the construction relies on.","marker":"[30]"}],"fun_headline_variants":["Goppa curve quantum codes with self-duality","Maximal curves yield self-orthogonal quantum Goppa codes","Quantum stabilizer codes from Goppa curves over finite fields","Self-dual Goppa families: new quantum error-correcting codes","Goppa codes on maximal curves: quantum stabilizer designs"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The parameter formulas depend on the count $\\deg(D)=q^2$—that deleting the $F_q$-rational points from the $F_{q^2}$-rational points leaves exactly $q^2$ points—and if that count is wrong, the length and every derived parameter shift.","fun_headline_variants_meta":{"raw":{"variants":["Goppa curve quantum codes with self-duality","Maximal curves yield self-orthogonal quantum Goppa codes","Quantum stabilizer codes from Goppa curves over finite fields","Self-dual Goppa families: new quantum error-correcting codes","Goppa codes on maximal curves: quantum stabilizer designs"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000341,"raw_usage":{"total_tokens":1914,"prompt_tokens":1013,"completion_tokens":901,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":629,"completion_tokens_details":{"reasoning_tokens":818}},"tokens_in":629,"tokens_out":901,"duration_ms":8344,"temperature":1.0,"reasoning_tokens":818,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T22:27:11.860032+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"For $q=3$ and $m=3$, count the $F_9$- and $F_3$-rational points of the curve $y^2=x^3+x$ and check whether their difference equals 9; the claimed $[[9,5,2]]_3$ quantum code and the length formula $n=q^2$ stand or fall on that difference.","supporting_citations":[{"cited_title":"Ashikhmin and E","cited_arxiv_id":null,"evidence_quote":"Supplies the standard construction converting a Hermitian self-orthogonal classical code into a quantum stabilizer code, used for Theorem 5.2."},{"cited_title":"Goppa, Algebraic-Geometric Codes, Math","cited_arxiv_id":null,"evidence_quote":"Introduces the algebraic-geometric code construction that the paper applies to maximal curves."},{"cited_title":"Grassl, Bounds on the minimum distance of linear codes and quantum codes","cited_arxiv_id":null,"evidence_quote":"Online database of best-known code parameters used as the comparison baseline in the examples."},{"cited_title":"Høholdt, J.H","cited_arxiv_id":null,"evidence_quote":"Source for the Riemann-Roch dimension formula and AG-code background used in Proposition 3.6."},{"cited_title":"Stichtenoth, Algebraic function fields and codes, Universitex, Springer-Verlag, Berlin- Heidelberg, 1993","cited_arxiv_id":null,"evidence_quote":"Source of the duality identity for AG codes that underlies Lemma 3.5."},{"cited_title":"Tafazolian and F","cited_arxiv_id":null,"evidence_quote":"Establishes maximality of the curves $y^n=x^m+x$ over $F_{q^2}$, supplying the rational-point counts the construction relies on."}],"review_version":1}