{"id":"9679b677-2e13-4f16-888e-3924b67eca79","arxiv_id":"2501.09818","paper_version":3,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":2.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A review of CV-MDI-QKD that synthesizes its theoretical foundations, security analyses, network variants, and experimental progress, plus a composable finite-size key rate formula.","lead":"This paper reviews continuous-variable measurement-device-independent quantum key distribution (CV-MDI-QKD), covering its protocol, security proofs, and experiments. It also presents a composable finite-size key rate formula based on a recent general security framework.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The claimed composable finite-size key rate (Eq. 7) assumes, without proof, that Ref. [98]'s one-way CV-QKD security proof applies unchanged to the two-link, relay-based MDI setting.","rationale":"The paper is a review, and much of its value lies in the summary of protocol variants, experimental demonstrations, and network extensions. However, the central claim in Section IV is a specific, new-sounding assertion: that the composable finite-size rate for Gaussian-modulated CV-MDI-QKD is given by Eq. (7), obtained from the general framework of Ref. [98]. This is exactly the kind of claim that a review can make only if it is either proven or explicitly attributed with the necessary hypotheses. The reader correctly identified the weakest assumption: the unproven reduction of the MDI protocol to the one-way CV-QKD setting of Ref. [98], compounded by the restriction to uncorrelated two-mode Gaussian attacks in the numerics. I agree with the CONDITIONAL verdict: the formula may well be correct, and the paper is broadly useful, but the lack of an explicit derivation or a clear statement of the extra assumptions means the current text overclaims. The proposed test (re-deriving Eq. (7) from the EB representation) is concrete and would settle whether the concern is merely expositional or reflects a genuine gap.","tokens_in":16004,"tokens_out":6743,"duration_ms":71629,"concrete_test":"To settle this, reconstruct the derivation of Eq. (7) from Ref. [98] step by step: start from the EB representation of CV-MDI-QKD, apply the relay's Bell measurement, and write the resulting conditional state shared by Alice and Bob. Then check whether this state is i.i.d. across rounds and satisfies the conditions of the asymptotic equipartition property as used in Ref. [98] (e.g., the same min-entropy bound per round and the same dimension d). If the derivation requires modifying δ_ent or δ_aep, or if a correlated Gaussian attack (g,g' > 0) cannot be bounded by the same worst-case estimators, Eq. (7) should be revised or its claim narrowed.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"Section IV presents Eq. (7) as 'an improved formulation' of the composable finite-size key rate, claimed to follow from the tools of Ref. [98]. But the paper does not derive this bound for CV-MDI-QKD; it essentially quotes Eq. (68) of Ref. [98] and substitutes the MDI-specific asymptotic rate bRpe∞. The missing step is the reduction of the MDI protocol to the one-way protocol of Ref. [98]. In the EB representation, after the relay's Bell measurement, Alice and Bob share a conditional Gaussian state, but its structure (and the effective quantum channel between the two parties, including correlations between the two links, g and g') is not analyzed. The AEP-based finite-size terms δ_ent and δ_aep in Eqs. (8)-(9) are protocol-independent only if the conditional state satisfies the i.i.d. and Markov-chain conditions of the AEP; this is not checked. Moreover, the security statement is restricted to 'collective Gaussian attacks' and, in the numerical rates, to uncorrelated attacks with g'=g=0 (Eq. 12). Without showing that the worst-case estimator for a general Gaussian attack can be incorporated into the same bound, the claim that Eq. (7) is 'the most rigorous formula' for the basic Gaussian-modulated CV-MDI-QKD protocol is unsupported. The burden is on the authors to provide the reduction or explicitly label the formula as an application of Ref. [98]'s result under additional assumptions.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper is a review of continuous-variable measurement-device-independent quantum key distribution (CV-MDI-QKD). It describes the protocol in both prepare-and-measure and entanglement-based representations, reviews the asymptotic security analysis under Gaussian collective attacks, discusses post-selection variants, presents a composable finite-size key rate formula in Section IV, extends the discussion to star-network and three-user configurations, and surveys four experimental implementations. The central new-looking element is the composable finite-size rate expression in Eq. (7), which the authors claim to be the most rigorous such formula for the basic Gaussian-modulated protocol and which they say they obtain using the tools of Ref. [98].","tokens_in":16295,"tokens_out":3073,"duration_ms":31249,"significance":"If the composable finite-size formula in Section IV were fully supported, it would be a practically relevant contribution, as finite-size composable security is the standard required for real deployments. However, as presented, the formula is a restatement of Ref. [98] with the MDI asymptotic rate inserted, and the reduction of the two-link relay protocol to the one-way setting of Ref. [98] is not shown. The review's descriptive parts, including the experimental survey and the network extensions, are useful and appear consistent with the cited literature. The paper also honestly correlates numerical rates with the uncorrelated-attack assumption g'=g=0, which is a strength. The main weakness is that the load-bearing security claim in Section IV is not substantiated within the manuscript.","major_comments":[{"comment":"Equation (7) is presented as an 'improved formulation' of the composable finite-size key rate for CV-MDI-QKD, obtained using the tools of Ref. [98]. However, no derivation is provided: the equation coincides with Eq. (68) of Ref. [98] after substituting the asymptotic rate R^pe_∞. The manuscript does not show how the CV-MDI-QKD protocol, with two independent links and an untrusted relay, is reduced to the one-way CV-QKD setting analyzed in Ref. [98]. In particular, the structure of the conditional state shared by Alice and Bob after the relay's Bell measurement is not analyzed, and the i.i.d. and Markov-chain conditions required for the application of the asymptotic equipartition property (AEP) in Eqs. (8)-(9) are not checked. Without this reduction, Eq. (7) is an unsupported restatement rather than an improved formulation, and the claim 'the most rigorous formula' is not justified.","section":"Section IV, Eq. (7)"},{"comment":"The security analysis is restricted to collective Gaussian attacks, and the numerical rates further assume an uncorrelated two-mode attack with g'=g=0 (Eq. (12)). The paper cites Ref. [75] for the reduction of the most general attack to a Gaussian attack in the asymptotic setting, but this reduction is not established for the composable finite-size framework. The statement 'Assuming collective Gaussian attacks' before Eq. (7) is not sufficient, because the AEP-based terms δ_ent and δ_aep require that the conditional state be i.i.d. and satisfy the relevant Markov-chain conditions; these conditions are not verified for the two-link, relay-based MDI protocol. The manuscript should either provide the reduction or explicitly label Eq. (7) as an application of Ref. [98] under additional assumptions.","section":"Section III A and Section IV"},{"comment":"The asymptotic rate R^pe_∞ is defined in Eq. (11) using estimators and worst-case estimators for three parameters (τ_A, τ_B, Ξ), but the paper does not specify how these estimators are constructed, how the worst-case bound is obtained, or how the parameter-estimation error probability ϵ_pe enters the bound. The reference to Ref. [97] is not sufficient for a self-contained review that claims to provide an improved formulation. This missing step is load-bearing, since the composability statement (6) depends on the failure probabilities of all post-processing steps, and the numerical results in Fig. 5 rely on this unstated construction.","section":"Section IV, Eq. (11) and text below"}],"minor_comments":[{"comment":"In the definition of ζ_k, the denominator should be τ_k, not the unsubscripted τ; as written, the formula is dimensionally inconsistent and does not match the text.","section":"Section III A, Eq. (12)"},{"comment":"In Eq. (14), the integrand uses γ_p but the integration variable and the distribution p(QQQ, γ_q) use γ_q; this appears to be a typo, and the intended integration variable should be used consistently.","section":"Section V B, Eq. (14)"},{"comment":"The notation n_bks for the number of blocks is introduced without a definition, and the later use 'n_bks' is not further explained; please define it explicitly.","section":"Section IV, first paragraph"},{"comment":"The sentence 'The most rigorous formula ... can be derived using the tools developed in Ref. [98]' is a strong claim that is not supported by a comparison with Refs. [96, 97]; the authors should either specify the improvement or soften the claim to avoid overstatement.","section":"Section IV, opening claim"},{"comment":"The transmissivity labels are inconsistent: Section II uses τ_A and τ_B for the links, while the attack description in Section III A uses τ_1 and τ_2. Please unify the notation.","section":"Section II and III A"}],"recommendation":"major_revision","confidential_remarks":"The paper is a reasonable review of CV-MDI-QKD, and the experimental summary in Section VI is particularly useful. However, the Section IV claim of an improved composable finite-size formula is not backed by a derivation or a clear comparison with prior work; it reads as a direct quotation from Ref. [98] with parameters relabeled. I would recommend the authors either provide the missing reduction or explicitly present Eq. (7) as a straightforward application of Ref. [98] with the stated additional assumptions, and adjust the language accordingly. The review would then be an acceptable overview rather than an unsupported advance."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Read this as a review, not as a new method. It is a useful synthesis of CV-MDI-QKD: protocol description, asymptotic rates, post-selection, network extensions, and the experimental state of the art. The experimental comparison table is genuinely useful, and the authors are honest about the protocol's short-distance limitation and the open problems.\n\nThe soft spot is Section IV. The paper claims to provide 'the most rigorous formula' for the composable finite-size key rate and calls it 'an improved formulation.' That claim is not backed up. Eq. (7) appears to be a direct quotation of Eq. (68) of Ref. [98], with the MDI asymptotic rate bRpe∞ substituted in. No derivation is given for the reduction of the two-link, relay-based MDI protocol to the one-way protocol of Ref. [98]. The conditional Gaussian state after the relay's Bell measurement is not analyzed, and the AEP conditions are not checked. The numerics assume an uncorrelated two-mode attack (g'=g=0). So the 'most rigorous' claim is unsupported; at best this is an application of an existing framework under an implicit assumption. The improvement over Refs. [96,97] is also not quantified. I checked the stress-test concern about this formula and it holds.\n\nThe heavy self-citation is not in itself a flaw for a review, since much of the protocol's development is the authors' own, and the experimental work they review is independent. The paper does not hide that the theoretical content is mostly adapted from earlier works. There are minor notational issues (e.g., the un-derived bRpe∞), but nothing that breaks the descriptive material.\n\nWho is this for? Practitioners and newcomers who want an overview of CV-MDI-QKD, especially the experimental landscape. The review also serves as a compact citation entry. The descriptive content holds up. Section IV is the one section that needs real work. I would send this to peer review, but the referee should push hard on Section IV: either derive the reduction, or explicitly label the formula as an application of Ref. [98] under collective Gaussian attacks, and clarify what exactly is improved over Refs. [96,97]. With that fixed, it becomes a solid review.","headline":"A solid review of CV-MDI-QKD that overclaims the novelty of its composable finite-size formula, which is an undeveloped application of the authors' own earlier framework.","tokens_in":16872,"tokens_out":3215,"would_cite":true,"duration_ms":30914,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","94A60"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper derives a composable finite-size key-rate formula for Gaussian-modulated CV-MDI-QKD and surveys its theory, networks, and experiments.","keywords":["CV-MDI-QKD","continuous-variable QKD","measurement-device-independent QKD","composable security","finite-size key rate","Gaussian collective attacks","post-selection","quantum key distribution networks"],"falsifier":"Recompute the Fig. 5 key rates under a correlated two-mode Gaussian attack with \\(g=g'\\neq0\\) instead of the uncorrelated case \\(g'=g=0\\) used in the plots; if the composable key rate falls to zero at the claimed distances, or if a non-Gaussian attack is found that beats the Gaussian collective bound, the central claim would be falsified.","tokens_in":15821,"feed_emoji":"🔐","tokens_out":7278,"duration_ms":68121,"temperature":0.7,"pith_summary":"This review of continuous-variable measurement-device-independent quantum key distribution (CV-MDI-QKD) aims to establish that the protocol can be given a rigorous composable finite-size security analysis: the most stringent key-rate formula for the Gaussian-modulated version follows from applying the general CV-QKD proof tools of Ref. [98], and the paper writes the resulting bound as Eq. (7). The motivation is practical: CV-MDI-QKD combines the hardware simplicity of continuous-variable systems with immunity to detector side channels at an untrusted relay, so a finite-size, composable bound is what a real deployment would need. The review also collects the asymptotic rate, post-selection variants, star-network extensions, and the main experiments. The net message is that CV-MDI-QKD offers a quantifiable security guarantee for short-to-moderate-distance, relay-based quantum key distribution.","feed_headline":"Composable security bound derived for CV-MDI-QKD","feed_subtitle":"The new formula quantifies finite-size security; experiments now reach 20 Mbaud.","key_machinery":"The load-bearing object is Eq. (7), a composable finite-size key-rate inequality, together with the total epsilon-security decomposition \\(\\epsilon\\le\\epsilon_{\\rm cor}+\\epsilon_s+\\epsilon_h+\\epsilon_{\\rm ent}+n_{\\rm pe}\\epsilon_{\\rm pe}\\). The formula treats the MDI protocol as a general CV-QKD protocol in the framework of Ref. [98], so the relay-specific physics is isolated in the asymptotic rate \\(\\bar R^\\infty_{\\rm pe}\\), which depends on worst-case estimators \\(\\$tau^{{\\rm wc}}$_A\\), \\(\\$tau^{{\\rm wc}}$_B\\), and \\(\\$Xi^{{\\rm wc}}$\\). The mechanism is that Alice and Bob estimate the channel parameters from a fraction of each block, use worst-case values to upper-bound Eve's Holevo information, and then subtract the finite-size penalties while keeping the overall epsilon parameter under control.","core_discovery":"The paper's central claim is that the composable finite-size secret-key rate of Gaussian-modulated CV-MDI-QKD is bounded by Eq. (7), \\(R \\le p_{\\rm ec}[n_{\\rm bks}\\bar R^\\infty_{\\rm pe}-\\sqrt n\\,\\delta_{\\rm ent}-\\sqrt n\\,\\delta_{\\rm aep}+\\$\\theta$]/N\\), where a session is divided into \\(n_{\\rm bks}\\) blocks of \\(N\\) points, \\(m\\) of which are used for parameter estimation. The protocol-specific content enters only through \\(\\bar R^\\infty_{\\rm pe}\\), the asymptotic rate computed from estimators of the two link transmissivities and the total excess noise, while Eve's Holevo information is evaluated with worst-case estimators. The finite-size corrections are the entropy-estimation penalty \\(\\delta_{\\rm ent}\\), the smoothing and hashing penalty \\(\\delta_{\\rm aep}\\), a correctness term \\(\\$\\theta$\\), and the error-correction success probability \\(p_{\\rm ec}\\). The paper presents this as an improved formulation relative to earlier composable analyses, and its Fig. 5 shows that composable security reduces the asymmetric-configuration distance from about \\(100\\) km asymptotically to about \\(25\\) km for the plotted parameters.","pith_inferences":["If Eq. (7) is correct, the same proof pipeline should carry over to the surveyed variants, including post-selection, squeezed states, and free-space links, by recomputing the asymptotic rate and its estimators; the paper does not supply those derivations.","The numerical plots assume an uncorrelated two-mode attack (\\(g'=g=0\\)); recomputing the rates for correlated Gaussian attacks with \\(g,g'\\neq0\\) would show whether the claimed distances are stable against Eve's more general collective attacks.","A testable extension is to study how the bound degrades for block sizes much smaller than \\(10^7\\), where the \\(\\delta_{\\rm aep}\\) term grows and the comparison between asymptotic and composable rates changes."],"forward_implications":["A real CV-MDI-QKD deployment can quote a finite-size, composable security parameter; for the plotted parameters the asymmetric configuration supports a positive composable key rate up to about \\(25\\) km.","The symmetric configuration remains the weak point: under pure loss the asymptotic rate is already limited to about \\(4\\) km, and post-selection extends the positive-rate distance to about \\(6\\) km while lowering short-range rates.","In star networks, the maximum radius of positive key rate scales roughly as \\(2/N\\) for \\(N\\) users, so the protocol is best suited to a few users around a central relay.","Recent experiments reach symbol rates of \\(20\\) Mbaud and report finite-size key generation, with rates around \\(0.1\\) bits per relay use, indicating the composable bounds are relevant to built systems."],"supporting_citations":[{"why":"Defines the CV-MDI-QKD protocol and its entanglement-based representation, and supplies the Gaussian collective attack model used throughout the security analysis.","marker":"[75]"},{"why":"Establishes that the optimal collective attack on Gaussian CV protocols is Gaussian, the premise for restricting Eve to entangling-cloner attacks.","marker":"[93]"},{"why":"Provides the earlier composable finite-size analysis whose estimators for transmissivities and total excess noise enter Eq. (11).","marker":"[97]"},{"why":"Supplies the general composable finite-size security framework from which Eq. (7) is derived.","marker":"[98]"},{"why":"Introduces the post-selection technique for CV-MDI-QKD whose rate is compared in Section III B.","marker":"[90]"},{"why":"Extends the protocol to star networks with N users and supplies the scaling used in Section V A.","marker":"[16]"},{"why":"Is the most recent experimental demonstration cited, operating at 20 Mbaud with finite-size key generation.","marker":"[101]"}],"fun_headline_variants":["New composable bound for CV-MDI-QKD key rates","Finite-size security formula tightens CV-MDI-QKD","CV-MDI-QKD gets composable finite-size proof","Tighter key-rate bound for CV-MDI-QKD"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that Eve's most general attack on the protocol reduces to a collective Gaussian attack on the two incoming links and that the composable finite-size proof for general CV-QKD from Ref. [98] applies to the MDI setting without modification; if either part fails, the bound in Eq. (7) is no longer a proven guarantee.","fun_headline_variants_meta":{"raw":{"variants":["New composable bound for CV-MDI-QKD key rates","Finite-size security formula tightens CV-MDI-QKD","CV-MDI-QKD gets composable finite-size proof","Tighter key-rate bound for CV-MDI-QKD"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00024,"raw_usage":{"total_tokens":1482,"prompt_tokens":872,"completion_tokens":610,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":488,"completion_tokens_details":{"reasoning_tokens":541}},"tokens_in":488,"tokens_out":610,"duration_ms":6357,"temperature":1.0,"reasoning_tokens":541,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T19:37:54.755194+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Recompute the Fig. 5 key rates under a correlated two-mode Gaussian attack with \\(g=g'\\neq0\\) instead of the uncorrelated case \\(g'=g=0\\) used in the plots; if the composable key rate falls to zero at the claimed distances, or if a non-Gaussian attack is found that beats the Gaussian collective bound, the central claim would be falsified.","supporting_citations":[{"cited_title":"Garc ´ıa-Patr´on and N","cited_arxiv_id":null,"evidence_quote":"Establishes that the optimal collective attack on Gaussian CV protocols is Gaussian, the premise for restricting Eve to entangling-cloner attacks."},{"cited_title":"Papanastasiou, A","cited_arxiv_id":null,"evidence_quote":"Provides the earlier composable finite-size analysis whose estimators for transmissivities and total excess noise enter Eq. (11)."},{"cited_title":"Pirandola and P","cited_arxiv_id":null,"evidence_quote":"Supplies the general composable finite-size security framework from which Eq. (7) is derived."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduces the post-selection technique for CV-MDI-QKD whose rate is compared in Section III B."}],"review_version":1}