{"id":"52843d05-7a69-4b98-827a-60301cef9319","arxiv_id":"2502.05382","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"high","formal_verification":"none","parameter_count":5,"one_line_summary":"A finite-size QKD proof with per-observation statistical constraints and sifted-round-scaled correction terms yields improved key rates for decoy-state and coherent-attack protocols.","lead":"Quantum key distribution systems need security proofs that work with a finite number of sent pulses, because real channels lose most of them. This paper develops a tighter finite-size proof and shows that it gives better key rates for decoy-state protocols, including a coherent-attack example.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Corollary 17's proof drops the 1/(Pr[Ω1]Pr[Ω2|Ω1]^2) normalization, so Theorem 4's key-rate formula is not established.","rationale":"The reader's weakest assumption identifies exactly the load-bearing flaw: Corollary 17's proof drops the normalization factor when conditioning on the composite event. My independent derivation confirms the error is real and directional: the claimed upper bound is actually a lower bound for non-trivial conditional probabilities. This matters because Theorem 4, the main IID fixed-length security statement, invokes Corollary 17 directly at Eq. (57) to justify the key-length formula. Without a valid composite-event leftover-hash bound, the key-rate expression in Theorem 4 and the numerical rates in Figs. 3–6 are unproven. The flaw is not an artifact of the reader's summary; it appears in the paper's Appendix A and propagates into the main proof. I considered whether the missing factor could be absorbed by the smoothing parameter or by a different choice of events, but the algebra shows an extra 1/(Pr[Ω1]Pr[Ω2|Ω1]^2) factor that is not present in the stated theorem. The error is likely fixable by adding a logarithmic penalty, but as written the central claim fails. I therefore agree with the REJECT verdict, and my stress test does not change it. The paper does contain useful ideas—entry-wise acceptance constraints, refined concentration inequalities, and a variable-length framework—but these do not rescue the main theorem as stated.","tokens_in":41621,"tokens_out":8701,"duration_ms":81505,"concrete_test":"Independently re-derive the first inequality in the proof of Corollary 17 by substituting Eq. (A11) and Pr[Ω] = Pr[Ω1]Pr[Ω2|Ω1] into the left-hand side of Eq. (A9). The correct expression is LHS = N / (2 Pr[Ω1] Pr[Ω2|Ω1]^2), not LHS ≤ N/2. To make the failure concrete, evaluate a toy classical model: take X and Y to be independent uniform bits, D trivial, l = 0, Ω1 = {Y = 0}, Ω2 = {X = 1}. Then Pr[Ω1] = Pr[Ω2|Ω1] = 1/2, and the proof's claimed first inequality would require LHS ≤ N/2, whereas direct substitution gives LHS = 8 × (N/2) = 4N. This refutes Corollary 17. Then propagate the corrected factor through Eq. (57) of Theorem 4 and recompute one of the key-rate curves in Figs. 3–6; if the shift is larger than the constant penalty, the central claim of improved finite-size scaling is not quantitatively established.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is Theorem 4's fixed-length key-rate formula, whose proof relies on Corollary 17 to bound the trace-norm distance conditioned on the composite event Ω = Ω1 ∧ Ω2 by an expression involving only the smooth min-entropy conditioned on Ω1. The proof of Corollary 17 mishandles the normalization. From Eq. (A11), ω_{KSHYD|Ω} = (ω_{KSHYD|Ω1})_{∧Ω2} / Pr[Ω2|Ω1]. Substituting this into the left-hand side of Eq. (A9) gives LHS = N / (2 Pr[Ω1] Pr[Ω2|Ω1]^2), where N = ||(ω_{KSHYD|Ω1})_{∧Ω2} − χ⊗(ω_{SHYD|Ω1})_{∧Ω2}||_1. The proof's first inequality instead claims LHS ≤ N/2, which would require Pr[Ω1]Pr[Ω2|Ω1]^2 ≥ 1. For any non-trivial events this product is < 1, so the inequality has the wrong direction. Consequently Eq. (57) in Theorem 4 does not follow from Corollary 17; the leftover-hash bound would need an additional factor 1/(Pr[Ω1]Pr[Ω2|Ω1]^2), which translates to an extra key-length penalty of at least 2 log(1/Pr[Ω1]) + 4 log(1/Pr[Ω2|Ω1]) bits (or an equivalent redefinition of the security parameters). Since the numerical key-rate curves in Figs. 3–6 are computed from Theorem 4, the claimed quantitative improvements are not supported as stated.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper develops a finite-size security proof for generic prepare-and-measure QKD protocols against IID collective attacks, with extensions to coherent attacks via the postselection technique and to variable-length protocols. The two claimed improvements are (i) entry-wise acceptance constraints based on binomial tail bounds, and (ii) second-order correction terms that scale with the number of sifted rounds rather than the total number of protocol rounds. The framework is applied to qubit BB84, decoy-state BB84, and a decoy-state 4-6 protocol with unequal intensities, and numerical key rates are compared with the 1-norm approach of Ref. [14].","tokens_in":41970,"tokens_out":16665,"duration_ms":159461,"significance":"If the central theorem were valid, the framework would be a valuable contribution: it avoids the basis-independence assumptions of EUR-based proofs, handles active basis choices and passive detection setups, and the numerical examples suggest substantially improved finite-size rates over the 1-norm approach of Ref. [14]. The paper is detailed and self-contained in many respects, with appendices covering technical tools such as binomial confidence bounds for very small security parameters, and the authors commit to releasing code. However, the central fixed-length theorem depends on a flawed normalization step in Corollary 17, so the quantitative claims are currently not supported.","major_comments":[{"comment":"The proof of Corollary 17 drops a normalization factor. From Eq. (A11) and Pr[Ω] = Pr[Ω1]Pr[Ω2|Ω1], the left-hand side of Eq. (A9) equals ‖N‖_1 / (2 Pr[Ω1] Pr[Ω2|Ω1]^2), where N = (ω_{KSHYD|Ω1})_{∧Ω2} − χ_K ⊗ (ω_{SHYD|Ω1})_{∧Ω2}. The proof's first inequality instead claims this is ≤ (1/2)‖N‖_1, which would require Pr[Ω1]Pr[Ω2|Ω1]^2 ≥ 1. For any non-trivial events this product is strictly less than 1, so the inequality has the wrong direction. Consequently the advertised bound (A9) is not established; the correct bound would contain an extra factor 1/(Pr[Ω1]Pr[Ω2|Ω1]^2) multiplying the right-hand side, i.e., an additional key-length penalty of at least 2 log(1/Pr[Ω1]) + 4 log(1/Pr[Ω2|Ω1]) or an equivalent inflation of the security parameter.","section":"Appendix A, Corollary 17, Eqs. (A9)–(A11)"},{"comment":"The key-length formula in Theorem 4 relies directly on Corollary 17 to pass from the security distance conditioned on Ω_acc to the smooth min-entropy conditioned only on Ω_sift. Since Corollary 17 is not established, Eq. (57) does not follow, and hence Eq. (49) is not proven as stated. The numerical key-rate curves in Figs. 3–6 and the claimed improvements over Ref. [14] are computed from this formula, so they are unsupported until the normalization issue is repaired and propagated through Theorem 4 and Corollaries 5–6.","section":"Theorem 4, Eq. (49) and proof around Eq. (57)"},{"comment":"A corrected version of Corollary 17 will introduce terms depending on Pr[Ω_sift] and Pr[Ω'_AT|Ω_sift]. The paper provides no lower bounds on these probabilities for states in the feasible set S_ν, and these probabilities can be small for adversarial states near the boundary of S_ν. The authors should either bound these event probabilities or restructure the acceptance test so that the resulting penalties are controlled; without this, the claimed reduction of second-order corrections to scale with the number of sifted rounds is not justified.","section":"Theorem 4, Eq. (49); Corollaries 5–6"}],"minor_comments":[{"comment":"The term “− 2 log(1/2ε_PA)” should read “− 2 log(1/(2ε_PA))”; the same typo appears in Corollary 9 and in the text after Eq. (58).","section":"Corollary 6, Eq. (94)"},{"comment":"The inequality “Pr[F_obs ∈ Q] ≤ Pr[|F_obs^k − Fbar^k| ≤ t_k] ∀k ∈ Σ” should be stated separately for each k before taking the maximum; as written it suggests an invalid simultaneous bound.","section":"Theorem 2 proof, Eq. (18)"},{"comment":"The sets S∘ and S• are used somewhat interchangeably; for example, Corollary 17 states σ ∈ S∘(XYD) but then discusses subnormalized states, which should be in S•. Clarifying this would help the reader.","section":"Notation throughout"},{"comment":"The notation τ^sift_{Z_sift Y_sift C_sift E_sift|D=1} is introduced but the conditioning on the register D is not explicitly reflected in the right-hand side of Eq. (34); a short clarification would improve readability.","section":"Lemma 3, Eq. (34)"},{"comment":"The fraction in the first term of the key-rate expression lacks parentheses: it should read (1/(Fbar_sift + t_sift + ν^U_sift)) times the sum over n, rather than the ambiguous inline expression currently printed.","section":"Eq. (83), Corollary 5"}],"recommendation":"major_revision","confidential_remarks":"The manuscript is well organized and the general proof strategy is attractive. However, the normalization error in Corollary 17 is a genuine load-bearing mistake: it invalidates the main fixed-length key-rate formula and all numerical comparisons derived from it. The error is local and potentially repairable, but the revision will require reworking Theorem 4, Corollaries 5–6, the security-parameter optimization, and the numerical examples. I therefore recommend major revision rather than rejection; if the authors cannot produce a corrected formula with acceptable rates, rejection would be appropriate at that point."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"You should know one thing before reading this paper: the main fixed-length theorem (Theorem 4) rests on Corollary 17, and that corollary's proof is wrong. I checked the stress-test note against Appendix A and it holds. Substituting Eq. (A11) into Eq. (A9) leaves a denominator of Pr[Ω1]Pr[Ω2|Ω1]^2 that is simply dropped in the first inequality. So the key-rate formula in Theorem 4 — and the fixed-length curves in Figs. 3–6 — are not established as written.\n\nThat is the headline. The paper is otherwise worth taking seriously. The entry-wise feasible set construction (Theorem 2), the sifted-round conditioning (Lemma 3), and the decoy-state LP reformulation are all genuinely new relative to the 1-norm approach of [14] and the N-scaled variable-length framework of [16]. The writing is careful, the examples are concrete, and the direction is well motivated. The variable-length section (Section VIII) uses a different proof route via Rényi entropies and Lemma 27, so it may survive the bug.\n\nThe soft spot is load-bearing. Fixing Corollary 17 means adding at least 2 log(1/Pr[Ω1]) + 4 log(1/Pr[Ω2|Ω1]) bits of penalty, or restructuring the proof to avoid the partial-conditioning bound. In high-loss regimes, where acceptance probabilities are small, that penalty could eat the claimed gains. I would also like a direct comparison against EUR-based finite-size bounds, and a working repo link; the code is promised but not yet available.\n\nWho should read this? People working on finite-size QKD security, especially decoy-state protocols, should engage with the techniques. The paper deserves a serious referee and a request for major revision, not a desk rejection. But I would not cite the current Theorem 4 until the normalization issue is resolved.","headline":"The main fixed-length theorem is unproven as written because Corollary 17 drops a normalization factor, but the paper's new techniques are worth a serious look.","tokens_in":42547,"tokens_out":5475,"would_cite":false,"duration_ms":48167,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P45"],"pacs":["03.67.Dd","03.67.Hk"],"model":"deepseek-v4-flash","headline":"Finite-size key rates for generic prepare-and-measure QKD can be pushed close to asymptotic by entry-wise acceptance constraints and by corrections that scale with sifted rounds rather than total signals.","keywords":["finite-size security","quantum key distribution","decoy-state protocols","smooth min-entropy","collective attacks","postselection technique","variable-length protocols","entry-wise acceptance constraints"],"falsifier":"Take a small classical-quantum example, say two rounds of qubit BB84 with a composite event $\\Omega_1$ selecting sifted outcomes and $\\Omega_2$ selecting acceptance with $\\Pr[\\Omega_2|\\Omega_1] \\approx 10^{-2}$, and compute both sides of inequality (A9) directly: the left side by explicit state construction and trace-norm evaluation, the right side by computing $H^{\\epsilon}_{\\min}(X|YD)_{\\sigma|\\Omega_1}$ with a semidefinite program over the smoothing ball. If the left side exceeds the right, Corollary 17 is false as stated and Theorem 4's formula would need an extra normalization penalty. A less explicit but decisive check is to re-derive the proof of Corollary 17 while keeping the factor $1/\\Pr[\\Omega_2|\\Omega_1]$ and see whether the final key length picks up an additional $\\log(1/\\Pr[\\Omega_2|\\Omega_1])$ term.","tokens_in":41397,"feed_emoji":"🔑","tokens_out":19480,"duration_ms":150930,"temperature":0.7,"pith_summary":"This paper claims that finite-size security proofs for prepare-and-measure quantum key distribution (QKD) can be made tighter with two changes: acceptance tests that constrain each observed frequency individually rather than through a single aggregate bound, and second-order correction terms that scale with the number of sifted, detected rounds instead of the total number of signals sent. The resulting key-length formula, Theorem 4, is proven secure against independent and identically distributed (IID) collective attacks and then extended to coherent attacks via the postselection technique and to variable-length protocols. Applied to qubit BB84, decoy-state BB84, and a decoy-state 4-6 protocol, the method essentially reaches the asymptotic key rate at $N = 10^{10}$ to $10^{11}$ signals on loss-only channels, where the 1-norm comparison method of Ref. [14] keeps positive rates only up to about 25 dB. A reader should care because finite-size penalties set the practical distance limit of real QKD links, and this proof targets exactly those penalties.","feed_headline":"Finite-size QKD corrections shrink to the sifted-round scale","feed_subtitle":"Second-order key-length penalties now ride on sifted signals, pushing decoy-state BB84 near asymptotic rates.","key_machinery":"Three objects carry the argument. The feasible set $S_\\nu$ with its entry-wise acceptance test (Theorem 2): observed frequencies must each lie within a tolerated fluctuation of the expected values, and the variational bounds $\\nu_k^{U/L}$ are fixed as the smallest $\\nu$ for which the binomial cumulative probability (incomplete $\\beta$ function) equals $\\epsilon_{AT}$, bounding the accept probability of every state outside $S_\\nu$ by $\\epsilon_{AT}$. The sift-conditioning lemma (Lemma 3): conditioning the raw key on the detector labels $D_i$ that mark sifted rounds leaves a tensor-product state on the sifted subsystem, so the smooth min-entropy is bounded below by the min-entropy of the sifted rounds alone and the second-order AEP correction scales with $\\lfloor n_{\\mathrm{sift}} - N t_{\\mathrm{sift}}\\rfloor$. The leftover-hash lemma with partial conditioning (Corollary 17): this converts the min-entropy bound into the trace-distance secrecy statement of Theorem 4 while, as the paper claims, avoiding the full $1/\\Pr[\\Omega]$ normalization penalty for the composite event $\\Omega = \\Omega_1 \\wedge \\Omega_2$. For decoy-state and coherent-attack extensions, the same skeleton is reused with yield bounds from a linear program over photon-number subspaces and with the postselection dimension cost $g_{n,x}$.","core_discovery":"The paper's central claim is a finite-size security statement for generic prepare-and-measure QKD: under an IID collective attack the protocol is $\\epsilon_{\\mathrm{sec}} = \\epsilon_{EV} + \\max\\{\\epsilon_{AT}, \\epsilon_{PA} + 2\\bar{\\epsilon}\\}$-secure if the final key length $l$ obeys $$l \\leq \\lfloor n_{\\mathrm{sift}} - N t_{\\mathrm{sift}}\\rfloor \\min_{\\rho \\in S_\\nu} \\frac{H(Z|EC)_\\rho}{\\Pr(\\mathrm{sift})} - \\lambda_{EC} - \\log(2/\\epsilon_{EV}) - \\sqrt{\\lfloor n_{\\mathrm{sift}} - N t_{\\mathrm{sift}}\\rfloor\\,\\$\\Delta$(\\bar{\\epsilon})} - 2\\log(1/(2\\epsilon_{PA})).$$ Two parts of the construction deliver the improvement. Theorem 2 defines the acceptance set $Q = Q_1 \\cap Q_2$ by entry-wise tolerances on the test-round frequencies together with a tolerance on the number of sifted rounds, and sets the variational bounds $\\nu_k^{U/L}$ through binomial tail probabilities (the incomplete $\\beta$ function), so any state outside the feasible set $S_\\nu$ is accepted with probability at most $\\epsilon_{AT}$. Lemma 3 then shows the smooth min-entropy of the raw key can be evaluated on the sifted subsystem alone, so the asymptotic equipartition property contributes a correction proportional to $\\sqrt{\\lfloor n_{\\mathrm{sift}} - N t_{\\mathrm{sift}}\\rfloor}$ rather than $\\sqrt{N}$. The same skeleton is reused for decoy-state protocols, where the feasible set is expressed through photon-number yields bounded by a linear program, and for variable-length protocols, where the correction terms depend on the observed number of sifted rounds $N^{\\mathrm{obs}}_{\\mathrm{sift}}$; coherent attacks are handled by applying the postselection technique with the dimension cost $g_{n,x}$.","pith_inferences":["A consequence the paper leaves implicit: if the sifted-round scaling holds, the fair resource for comparing QKD implementations at high loss shifts from total pulses sent to sifted detections, since protocols with better detection or sifting efficiency gain twice - once in the entropy prefactor and once in the correction terms - and plots like Fig. 3 should nearly collapse when re-drawn against th","The entry-wise-versus-aggregate distinction is transferable: other QKD settings whose feasible sets are already defined by individual observation bounds, such as measurement-device-independent and discrete-modulated continuous-variable protocols, could adopt the same binomial-tail acceptance tests and inherit a comparable reduction of statistical slack.","The expected-key-rate analysis using Fr\\'echet inequalities offers a template for deployments where the honest channel is known only coarsely: rather than assuming a point model for the accepted frequencies, one can bracket the worst-case key rate between the upper and lower Fr\\'echet bounds and choose the acceptance tolerances accordingly."],"forward_implications":["Qubit BB84 with a perfect source essentially reaches its asymptotic key rate already at $N = 10^{10}$ signals, while the 1-norm method of Ref. [14] keeps positive rates only up to roughly 25 dB of loss (Figs. 3-4).","Decoy-state BB84 with two decoy intensities recovers the asymptotic limit up to about 40 dB loss with $N = 10^{11}$ signals, optimizing both the testing probability and the signal intensity per data point (Fig. 5).","Because the security proof starts from a generic prepare-and-measure statement, it covers protocols that the entropic-uncertainty-relation route handles poorly, including active-basis protocols with passive detection setups and different intensities per signal state.","Variable-length protocols inherit the same gain: in Theorem 8 and Corollary 9 the correction terms depend on the observed number of sifted rounds $N^{\\mathrm{obs}}_{\\mathrm{sift}}$ instead of $N$, so high-loss key rates degrade much more slowly as the block length shrinks.","Against coherent attacks, the decoy-state 4-6 protocol with one decoy intensity and unequal per-symbol intensities yields non-zero key rates from $N = 10^9$ signals and reaches 25 dB at $N = 10^{12}$ (Fig. 6)."],"supporting_citations":[{"why":"The 1-norm finite-size numerical method that this work improves upon and the baseline compared against in Figs. 3-4.","marker":"[14]"},{"why":"Supplies the leftover-hash lemma (Prop. 9), the conditioning lemma (Lemma 10), and the security definitions on which Corollary 17 and Theorem 4 rest.","marker":"[10]"},{"why":"The asymptotic equipartition property (Cor. 4.10) that produces the square-root correction term in Theorem 4.","marker":"[24]"},{"why":"The smooth min-entropy definitions and chain-rule lemmas (6.7, 6.8) used in the proofs of Lemma 3 and Theorem 4.","marker":"[23]"},{"why":"The variable-length security proof framework that Theorem 8 and Corollary 9 adapt to sifted-round-dependent corrections.","marker":"[16]"},{"why":"The postselection result (Cor. 4.1) used to lift IID security to coherent attacks with the dimension cost $g_{n,x}$.","marker":"[12]"},{"why":"The numerical key-rate framework used to evaluate entropies in the qubit and decoy-state example protocols.","marker":"[29]"},{"why":"The Clopper-Pearson binomial confidence intervals used to construct the variable-length set $V(F^{\\mathrm{obs}})$ in Lemma 7.","marker":"[37]"}],"fun_headline_variants":["QKD key rates tighten with sifted-round scaling","Finite-size QKD proof now uses sifted-round corrections","Decoy-state QKD gets tighter finite-size keys","Sifted-round scaling sharpens QKD security bounds"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key-length formula of Theorem 4 stands on Corollary 17 in Appendix A, a leftover-hash inequality for composite events $\\Omega = \\Omega_1 \\wedge \\Omega_2$ that claims the normalization by $\\Pr[\\Omega]$ costs nothing beyond the conditioning on $\\Omega_1$, although the proof appears to drop a factor of $1/\\Pr[\\Omega_2|\\Omega_1]$ when comparing normalized and subnormalized trace norms.","fun_headline_variants_meta":{"raw":{"variants":["QKD key rates tighten with sifted-round scaling","Finite-size QKD proof now uses sifted-round corrections","Decoy-state QKD gets tighter finite-size keys","Sifted-round scaling sharpens QKD security bounds"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000882,"raw_usage":{"total_tokens":3890,"prompt_tokens":1101,"completion_tokens":2789,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":717,"completion_tokens_details":{"reasoning_tokens":2733}},"tokens_in":717,"tokens_out":2789,"duration_ms":20556,"temperature":1.0,"reasoning_tokens":2733,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-08T19:36:32.903515+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a small classical-quantum example, say two rounds of qubit BB84 with a composite event $\\Omega_1$ selecting sifted outcomes and $\\Omega_2$ selecting acceptance with $\\Pr[\\Omega_2|\\Omega_1] \\approx 10^{-2}$, and compute both sides of inequality (A9) directly: the left side by explicit state construction and trace-norm evaluation, the right side by computing $H^{\\epsilon}_{\\min}(X|YD)_{\\sigma|\\Omega_1}$ with a semidefinite program over the smoothing ball. If the left side exceeds the right, Corollary 17 is false as stated and Theorem 4's formula would need an extra normalization penalty. A less explicit but decisive check is to re-derive the proof of Corollary 17 while keeping the factor $1/\\Pr[\\Omega_2|\\Omega_1]$ and see whether the final key length picks up an additional $\\log(1/\\Pr[\\Omega_2|\\Omega_1])$ term.","supporting_citations":[{"cited_title":"George, J","cited_arxiv_id":null,"evidence_quote":"The 1-norm finite-size numerical method that this work improves upon and the baseline compared against in Figs. 3-4."},{"cited_title":"Dupuis, O","cited_arxiv_id":null,"evidence_quote":"The asymptotic equipartition property (Cor. 4.10) that produces the square-root correction term in Theorem 4."},{"cited_title":"Tomamichel, Quantum Information Processing with Finite Resources , SpringerBriefs in Mathemati- cal Physics, Vol","cited_arxiv_id":null,"evidence_quote":"The smooth min-entropy definitions and chain-rule lemmas (6.7, 6.8) used in the proofs of Lemma 3 and Theorem 4."},{"cited_title":"Tupkary, E","cited_arxiv_id":null,"evidence_quote":"The variable-length security proof framework that Theorem 8 and Corollary 9 adapt to sifted-round-dependent corrections."},{"cited_title":"Nahar, D","cited_arxiv_id":null,"evidence_quote":"The postselection result (Cor. 4.1) used to lift IID security to coherent attacks with the dimension cost $g_{n,x}$."},{"cited_title":"Winick, N","cited_arxiv_id":null,"evidence_quote":"The numerical key-rate framework used to evaluate entropies in the qubit and decoy-state example protocols."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"The Clopper-Pearson binomial confidence intervals used to construct the variable-length set $V(F^{\\mathrm{obs}})$ in Lemma 7."}],"review_version":1}