{"id":"c2ed4fc3-e994-407d-a570-af2e0e9e44d6","arxiv_id":"2501.10278","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A finite-size security analysis shows how phase imbalance in heterodyne receivers limits CVQKD key rates, and a local data transformation partially restores the lost performance.","lead":"This paper derives finite-size security bounds for continuous-variable quantum key distribution when Bob's heterodyne receiver has a phase imbalance, and shows the imperfection shortens the secure distance. It proposes a post-processing transformation that recovers part of the lost key rate, and demonstrates the estimation and compensation in a laboratory receiver with a 10-degree imbalance.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The finite-size key-rate formula presupposes a Holevo bound χT(E) for the full covariance matrix that is never defined or derived; without it the central security claim is unproven.","rationale":"The reader's conditional verdict is appropriate, but the single most load-bearing gap is not the finite-size estimator approximation; it is the absence of any derivation of χT(E). The reader did mention this gap in the rationale, but chose the estimator Gaussianity as the weakest assumption. The estimator concern only becomes relevant once the asymptotic key-rate expression is established; the missing Holevo bound undermines the very formula being parameterized. The paper contains useful modeling and a plausible experimental demonstration, but a security proof whose central entropy bound is not written down is incomplete. The proposed check is concrete and cheap: deriving χT(E) and verifying the two limits would either close the gap or expose a fatal overestimate. Since the reader already marked the paper CONDITIONAL, the verdict should remain unchanged, though the condition should explicitly require the missing Holevo-derivation and limit checks.","tokens_in":17962,"tokens_out":9246,"duration_ms":100505,"concrete_test":"Provide the explicit expression for χT(E) in terms of Γ, and reproduce the asymptotic KTT curves in Fig. 2 from it. Check two limits: (i) θ=ϕ=0 must reduce to the standard heterodyne CVQKD Holevo bound; (ii) θ=−ϕ (canonical conjugate misalignment) must be invariant under the local transformation (6), matching the claim that all lost mutual information is recoverable. If the expression cannot be supplied or these limits fail, the central security claim is not established.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central key-rate expressions KTT and KIT in Eqs. (12)-(13) require K∞TT = β IT(A:B) − χT(E) and K∞IT = β I(A:B)ς→0 − χT(E), where χT(E) is the Holevo bound evaluated from the full covariance matrix Γ with cross-correlations. Nowhere in the paper or Supplementary Materials is χT(E) defined, derived, or reduced to a computable expression in terms of the matrix elements (1). This is not a minor omission: the paper's advertised improvement over symmetrization is precisely that using the full Γ does not overestimate security, and that claim is exactly what the missing Holevo computation would have to establish. For standard ideal CVQKD, χ(E) is obtained by replacing the PM source with a two-mode squeezed vacuum and computing symplectic eigenvalues; with a phase-imbalanced heterodyne receiver, the effective Gaussian POVM changes the conditional state, so one cannot simply transplant the symmetric formula. Because the central security statement is conditioned on \"the Holevo bound evaluated from the full covariance matrix\", and that object is absent, the asymptotic rates and therefore the finite-size rates are unsupported. This gap is more load-bearing than the Gaussianity of the imbalance estimators: even with exact estimates of θ and ϕ, the rate formula would still lack a proof.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript develops a security analysis for Gaussian-modulated coherent-state CVQKD with heterodyne detection when the receiver has phase and amplitude imbalances. The authors model the imperfections as phase shifts θ and ϕ plus a beam-splitter imbalance ηbs, write the full covariance matrix Γ including cross-correlations, and introduce a 'true' mutual information IT(A:B) together with a local data transformation intended to recover information without overestimating security. They then state finite-size key-rate formulas (Eqs. 12-13) that combine asymptotic rates KTT and KIT with a finite-size correction Δ(n), using worst-case estimated parameters at 10^-10 failure probability. The paper reports experimental data from a 90° optical hybrid with about 10° phase imbalance and compares achievable key rates with and without the transformation.","tokens_in":18290,"tokens_out":3865,"duration_ms":40012,"significance":"If the finite-size security claim were fully proven, the result would be practically valuable: it would quantify how phase imbalance in integrated heterodyne receivers degrades CVQKD and would offer a post-processing transformation to mitigate the loss, thereby relaxing fabrication tolerances for photonic integrated receivers. The mutual-information part (Eqs. 4-5 and the Supplement) is derived in a transparent way, and the paper is careful to warn that symmetrization after the transformation can overestimate security. The experimental characterization of a 10°-imbalance receiver is useful and the data are presented in a reproducible style. However, the central security claim is not yet established, because the Holevo bound for the full covariance matrix that enters the advertised rates is never defined or derived.","major_comments":[{"comment":"The asymptotic key rate in Eq. (2) is evaluated for the approaches KTT and KIT using a Holevo bound χT(E) computed from the full covariance matrix Γ, but neither the definition of χT(E) nor its derivation is given anywhere in the paper or the Supplement. In particular, for the phase-imbalanced heterodyne receiver the conditional state relevant to Eve is not the same as in the ideal symmetric case, and one cannot simply transplant the standard symplectic-eigenvalue formula. Since the paper's advertised advantage over symmetrization is precisely that using the full Γ does not overestimate Eve's information, this missing computation is load-bearing; without it Eqs. (12)-(13) and the asymptotic curves in Fig. 2 are unsupported.","section":"Sec. 3A, Table 1"},{"comment":"The finite-size correction Δ(n) is imported from Refs. [33,34] without stating its exact functional form, the conditions under which it applies, or a composable security proof adapted to the present protocol with imperfect heterodyne detection and estimation of the imbalance δ. The sentence in Sec. 3B that the analysis is 'compatible with the composable security framework' is an assertion rather than a derivation. For a paper whose title promises finite-size security, the reader needs the precise expression for Δ(n), the associated failure probabilities, and an explicit statement of how the parameter estimation of θ, ϕ, and δ enters the composable bound.","section":"Sec. 3B, Eqs. (12)-(13)"},{"comment":"The variance formulas for the imbalance estimators rest on the approximation 1/y ≈ 2 − y and on dropping O(1/m²) terms, and the confidence intervals are then taken as Gaussian at the 6.5σ level corresponding to 10^-10. The manuscript does not justify that these approximations yield valid upper confidence bounds for δ at the block sizes used (m around 10^6), nor does it address the non-Gaussianity of ratio estimators. Because δup enters the finite-size rate in Eq. (12), this is a second load-bearing step in the finite-size claim and needs a rigorous justification or a numerical check.","section":"Supplement Sec. 5, Eqs. (S14)-(S27)"},{"comment":"The experimental validation computes the key-rate points from parameters (ε, δ, η) estimated on the same frames that are then reported as validating the model, so the agreement in Fig. 3b and the key-rate points in Fig. 3c are in-sample consistency checks rather than an independent test of the finite-size security claim. The paper should state this limitation explicitly and, if possible, provide a train-test split or at least quantify the parameter-estimation uncertainty in the displayed rates.","section":"Sec. 4, Fig. 3c"}],"minor_comments":[{"comment":"The transformation matrix in Eq. (6) is written as [[cosΘ, sinΘ],[cosΦ, sinΦ]], which is not orthogonal in general; if a rotation or a more general invertible linear map is intended, the matrix and the domain of Θ and Φ should be specified precisely.","section":"Eq. (6)"},{"comment":"The sign conventions for θ and ϕ are inconsistent between the covariance-matrix elements (where σ Ap,Bx contains sin[θ] and σ Ax,Bp contains −sin[ϕ]) and the estimator formulas in Eqs. (7)-(8); the authors should define the signs once and use them consistently throughout.","section":"Eqs. (7)-(10)"},{"comment":"The modulation variance is denoted Vm, VA, and Vt at different places (e.g., Eq. (10), Sec. 2C, and Supplement Eqs. (S17)-(S27)); these notations should be unified and defined in one place.","section":"General notation"},{"comment":"The notation K^{n} in Eq. (12) and K^{N} in Eq. (13) is confusing because the prefactor n/N appears only in Eq. (12); the authors should clarify that N is the total number of exchanged signals, n is the number used for key generation, and why the prefactor is absent in Eq. (13).","section":"Sec. 3B, Eqs. (12)-(13)"},{"comment":"The symbol ηϵ in Eq. (S9) is not defined; it should be stated whether this is the excess noise before heterodyne measurement, and how it relates to ε used in the main text.","section":"Supplement, Eq. (S9)"},{"comment":"There are several typographical errors, e.g., 'experimantally' in the caption of Fig. 3c and 'support support' in the Acknowledgments; these should be corrected.","section":"Throughout"}],"recommendation":"major_revision","confidential_remarks":"The paper is positioned as a security proof, and the missing Holevo-bound derivation is a substantive gap that cannot be waved away by citing standard CVQKD results, because the imperfect receiver changes the effective measurement and hence the relevant conditional states. The experimental work is interesting, but the in-sample nature of the validation should be addressed. I would encourage the editors to request a revised version that supplies the missing χT(E) computation and the composable finite-size statement; without those, the central claim is not yet supported."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: this is a useful paper with a genuine practical idea, but the security proof as written has a load-bearing gap. The local transformation in Eq. (6) and the warning that symmetrizing after the transformation overestimates the key rate are good contributions. The mutual-information part (Eqs. 4-5, supplement) is derived cleanly, and the finite-size estimators for the phase imbalance are new and seem sensible. The experiment showing that a 10-degree-imbalanced 90° hybrid can still support positive key rates after the transform is a nice demonstration.\n\nWhere it gets soft: the Holevo bound χT(E) for the full covariance matrix Γ is never defined or derived. The paper says the modulated coherent state is replaced by a two-mode squeezed vacuum to obtain the Holevo bound, but the standard formula is for the symmetrized, diagonal Γ. With a phase-imbalanced heterodyne receiver, the effective measurement changes the conditional state, so you cannot just transplant the symmetric formula. The asymptotic rates KTT and KIT, and therefore the finite-size rates in Eqs. (12)-(13), all depend on this undefined object. This is not a cosmetic omission; it is the difference between a security proof and a security suggestion. A referee should ask for the explicit symplectic-eigenvalue computation or a clear reference that covers this exact model.\n\nThe other soft spot is the estimator approximation. The variance formulas for the imbalance estimators use 1/y ≈ 2 - y and drop O(1/m²) terms, then assume Gaussianity at the 10^-10 level for m around 10^6. That is probably fine for the block sizes used, but the paper should show that the approximation holds in the parameter regime of the experiment. It is a smaller issue than the missing Holevo bound.\n\nThe experimental validation is in-sample: the same frames used to estimate imbalance and excess noise are used to compute the key rates. That is common for proof-of-principle, but it means the experiment confirms the model, not the security proof. Fine, as long as the theory gap is closed separately.\n\nBottom line: worth engaging with. The transformation and the no-symmetrization-after-transform warning are real contributions. But as it stands, the central security claim is unproven, and the paper needs major revision before it can be accepted. Send it to peer review, but make sure the referee asks for the missing Holevo derivation.","headline":"Useful practical fix for imbalanced heterodyne CVQKD, but the central security claim needs a real Holevo derivation before it is a proof.","tokens_in":18788,"tokens_out":3071,"would_cite":true,"duration_ms":31133,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","94A60"],"pacs":["03.67.Dd","03.67.Hk"],"model":"deepseek-v4-flash","headline":"The paper establishes a finite-size security proof for continuous-variable quantum key distribution with imperfect heterodyne receivers, showing that phase imbalance in the receiver reduces but does not eliminate the secure key rate, and…","keywords":["continuous-variable quantum key distribution","heterodyne detection","phase imbalance","finite-size security","collective attacks","covariance matrix","mutual information","local data transformation"],"falsifier":"A concrete test is to generate synthetic data from the paper's Gaussian model with known $\\theta$, $\\phi$, $\\eta$, and $\\varepsilon$ for $m = 10^6$, apply the estimators in Eqs. (S14)–(S15), and check whether the empirical frequency of estimates outside the $6.5$-$\\sigma$ interval exceeds $10^{-10}$; any significant excess would show the confidence intervals are not tight enough. A complementary experiment would repeat the 17 km measurement with a deliberately larger phase imbalance, say $30^\\circ$, where the $1/y \\approx 2 - y$ approximation is less accurate, and compare the measured key rate with the formula's prediction.","tokens_in":17806,"feed_emoji":"🔐","tokens_out":9371,"duration_ms":84965,"temperature":0.7,"pith_summary":"Continuous-variable quantum key distribution relies on heterodyne receivers that measure two quadratures at once, but integrated receivers have phase imbalances that make the two measurements not perfectly orthogonal. This paper claims that such imbalances can be handled in a finite-size security proof by keeping the full covariance matrix with all cross-correlations, estimating the imbalance $\\theta+\\phi$ with Gaussian confidence intervals, and optionally applying a local linear transformation to Alice's or Bob's data before error correction. The paper shows that phase imbalance reduces the mutual information and increases the Holevo bound, so it shortens the secure distance, but a positive key rate survives if the full covariance matrix is used; symmetrizing the matrix after the transformation would overestimate security. An experiment with a $10^\\circ$ phase imbalance at 17 km confirms the estimation procedure and yields finite-size key rates consistent with the model. If correct, the result relaxes the phase-balance requirement for photonic integrated CVQKD receivers.","feed_headline":"10-degree receiver flaw still allows secure quantum keys","feed_subtitle":"A full-covariance security proof plus a data transform keeps CV quantum key distribution positive at finite block sizes.","key_machinery":"The load-bearing object is the four-by-four covariance matrix $\\Gamma$ of Alice's and Bob's quadratures, with all anti-diagonal correlation terms $\\varsigma$ kept; the security analysis is carried out on this full matrix. The proof also uses the determinant formula for the true mutual information, the local transformation in Eq. (6) with angles $\\Theta = \\tan^{-1}(\\varsigma_{A_p,B_x}/\\sigma_{x,A,B})$ and $\\Phi = \\tan^{-1}(\\varsigma_{A_x,B_p}/\\sigma_{p,A,B})$, and ratio estimators $\\hat{T}_\\theta$, $\\hat{T}_\\phi$ for the imbalances whose variances are computed to leading order in $1/m$. These estimators produce the $6.5$-$\\sigma$ confidence intervals for $\\delta$, $\\eta$, and $\\varepsilon$ used in the finite-size key-rate formula, making the analysis compatible with composable security.","core_discovery":"The central claim is that for Gaussian-modulated coherent-state CVQKD with heterodyne detection, the finite-size secret-key rate secure against collective attacks is $K^n = (n/N)[K^\\infty_{TT}(t_{\\mathrm{low}}, \\varepsilon_{\\mathrm{up}}, \\delta_{\\mathrm{up}}) - \\Delta(n)]$ (Eq. 12), where the asymptotic rate $K^\\infty$ is evaluated from the full covariance matrix $\\Gamma$ rather than from a symmetrized version, and $t_{\\mathrm{low}}$, $\\varepsilon_{\\mathrm{up}}$, $\\delta_{\\mathrm{up}}$ are worst-case estimates of transmission, excess noise, and total phase imbalance at a $10^{-10}$ failure probability. The phase imbalance is modelled as independent shifts $\\theta$ and $\\phi$ on the two quadratures, which create anti-diagonal terms $\\varsigma$ in $\\Gamma$; these terms reduce the true mutual information $I_T(A:B) = \\frac{1}{2}\\log_2(|\\gamma_A|/|\\gamma_{A|B}|)$ and increase Eve's Holevo bound unless the full matrix is used. The paper shows that a local transformation (Eq. 6) with angles estimated from $\\Gamma$ recovers the lost mutual information when the receiver measures canonical conjugate quadratures ($\\theta = -\\phi$), and partially recovers it otherwise; symmetrization after the transformation is explicitly shown to be insecure. Experimentally, the imbalance is estimated from correlations both between Alice and Bob and between Bob's own quadratures, giving consistent values near $10^\\circ$, and finite-size key rates are positive at 17 km with optimized data-splitting fraction.","pith_inferences":["The paper assumes the amplitude imbalance $\\eta_{bs}$ is fixed and known; a natural extension is to let it fluctuate and include its estimator in the confidence-interval set, which would matter for receivers whose splitting ratio drifts with temperature.","The frame-wise stability check of the phase estimates suggests an adaptive post-processing rule: re-estimate $\\delta$ per frame and discard frames where the imbalance wanders, rather than assuming a single fixed imbalance for the whole key.","The result implies a concrete design target for integrated receivers: phase imbalance up to about $10^\\circ$ is tolerable with the transformation, so manufacturers could relax the optical-hybrid specification and compensate digitally, trading a modest loss of distance against lower fabrication cost.","A direct experimental test of the finite-size bound would be to repeat the measurement at larger imbalance values or smaller block sizes and verify that the empirical key-rate drop matches the formula's prediction; the paper only demonstrates one operating point."],"forward_implications":["With the full-covariance approach $K_{TT}$, positive finite-size keys are achievable at longer distances than with the symmetrized approaches; the maximum secure distance shrinks with increasing phase imbalance.","For short distances, the $K_{IT}$ approach that performs error correction before parameter estimation yields higher key rates, because it avoids the finite-size penalty of estimating the imbalance first; for longer distances, estimating the imbalance and transforming the data pays off.","The fraction $n/N$ of signals assigned to key generation must be optimized; without this optimization the advantage of the transformation is not fully realized.","Symmetrizing the covariance matrix after applying the local transformation overestimates the mutual information and therefore cannot be used in a security proof."],"supporting_citations":[{"why":"It supplies the composable security framework for CVQKD with coherent states and the result that error correction before parameter estimation lets all measurements contribute to the key.","marker":"[10]"},{"why":"It provides the finite-size correction term $\\Delta(n)$ and the $n/N$ block-splitting penalty used in the key-rate formula.","marker":"[33,34]"},{"why":"It establishes that phase noise in practical CVQKD effectively lowers estimated channel transmission and raises noise, the effect the paper models as phase imbalance.","marker":"[27]"},{"why":"It gives the Gaussian-state covariance-matrix description and Holevo-bound evaluation used for the asymptotic key rate.","marker":"[28]"},{"why":"It supplies the general secret-key-rate expression $\\beta I(A:B) - \\chi(E)$ that the paper lower-bounds.","marker":"[29]"},{"why":"It documents the typical $3^\\circ$–$10^\\circ$ phase imbalance of multimode-interference optical hybrids, the experimental target.","marker":"[22]"},{"why":"It gives prior analyses of nonideal heterodyne detection that the paper extends by covering phase imbalance under finite-size collective-attack security.","marker":"[23,24]"}],"fun_headline_variants":["Imperfect heterodyne receiver still permits secure CV-QKD","Local transform neutralizes phase imbalance in CV-QKD","Finite-size security proof for CV-QKD with receiver flaws","10-degree phase imbalance: secure keys still achievable at 17 km","Heterodyne imperfections handled by full-covariance proof"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof depends on the phase-imbalance estimates computed from a finite block of signals being accurate enough that their 6.5-standard-deviation confidence intervals are valid at the $10^{-10}$ failure level; if those estimates are not close to Gaussian for blocks of about a million signals, the guaranteed key rate is not established.","fun_headline_variants_meta":{"raw":{"variants":["Imperfect heterodyne receiver still permits secure CV-QKD","Local transform neutralizes phase imbalance in CV-QKD","Finite-size security proof for CV-QKD with receiver flaws","10-degree phase imbalance: secure keys still achievable at 17 km","Heterodyne imperfections handled by full-covariance proof"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000811,"raw_usage":{"total_tokens":3610,"prompt_tokens":1049,"completion_tokens":2561,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":665,"completion_tokens_details":{"reasoning_tokens":2476}},"tokens_in":665,"tokens_out":2561,"duration_ms":18287,"temperature":1.0,"reasoning_tokens":2476,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T19:15:54.248235+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete test is to generate synthetic data from the paper's Gaussian model with known $\\theta$, $\\phi$, $\\eta$, and $\\varepsilon$ for $m = 10^6$, apply the estimators in Eqs. (S14)–(S15), and check whether the empirical frequency of estimates outside the $6.5$-$\\sigma$ interval exceeds $10^{-10}$; any significant excess would show the confidence intervals are not tight enough. A complementary experiment would repeat the 17 km measurement with a deliberately larger phase imbalance, say $30^\\circ$, where the $1/y \\approx 2 - y$ approximation is less accurate, and compare the measured key rate with the formula's prediction.","supporting_citations":[{"cited_title":"Composable security proof for continuous-variable quan- tum key distribution with coherent states,","cited_arxiv_id":null,"evidence_quote":"It supplies the composable security framework for CVQKD with coherent states and the result that error correction before parameter estimation lets all measurements contribute to the key."},{"cited_title":"Analysis of imperfections in practical continuous-variable quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"It establishes that phase noise in practical CVQKD effectively lowers estimated channel transmission and raises noise, the effect the paper models as phase imbalance."},{"cited_title":"Continuous- variable quantum key distribution with gaussian modulation—the the- ory of practical implementations,","cited_arxiv_id":null,"evidence_quote":"It gives the Gaussian-state covariance-matrix description and Holevo-bound evaluation used for the asymptotic key rate."},{"cited_title":"Distillation of secret key and entanglement from quantum states,","cited_arxiv_id":null,"evidence_quote":"It supplies the general secret-key-rate expression $\\beta I(A:B) - \\chi(E)$ that the paper lower-bounds."},{"cited_title":"Tolerant and high performance 3× 3 and 4× 4 multimode interference couplers,","cited_arxiv_id":null,"evidence_quote":"It documents the typical $3^\\circ$–$10^\\circ$ phase imbalance of multimode-interference optical hybrids, the experimental target."}],"review_version":1}