{"id":"6a3af8d3-b292-4714-9e15-55f0f2c34293","arxiv_id":"2505.02620","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":2,"one_line_summary":"Distributed quantum phase-estimation protocols with safety thresholds are claimed secure against general-coherent attacks using a LOCC de Finetti theorem, with a proof-of-principle photonic demonstration.","lead":"This paper presents distributed quantum sensing protocols that let a remote user estimate a phase while detecting an eavesdropper's tampering, with security claims against collective attacks. The protocols replace abort-on-error schemes with a safety threshold and are demonstrated in a photonic experiment, though the theoretical text contains internal inconsistencies.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The phase estimators in Eq. (4) and Eq. (8) do not recover the encoded phase on the stated ideal states, so the central claim of Theorem 1 is not established even in the noiseless case.","rationale":"The reader's named weakest_assumption, the finite-sample fidelity estimate, is valid, but I find a more primary obstruction: the phase estimators are inconsistent with the probe states even in the ideal noiseless limit. This is an internal inconsistency rather than a disagreement with consensus, so it is a load-bearing defect in the central claim. The experimental proof-of-principle and the honest statement that the bounds overestimate tampering are real contributions, but they do not repair the estimator formulas. A direct symbolic check settles the matter, and it leads to the same overall verdict as the reader.","tokens_in":17477,"tokens_out":11736,"duration_ms":127011,"concrete_test":"Symbolically evaluate Eq. (4) on the ideal state (2) for n=1, with U(ϕ) applied only to B, and Eq. (8) on the four MUB states |P,+> for P∈{±X,±Z}. If Eq. (4) returns a constant (π/4) and Eq. (8) returns 2ϕ rather than ϕ, the protocols are not unbiased even without any attack, and the central claim fails. This test also exposes the false identity (A4) by substituting the paper's own definitions into Appendix A.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The most load-bearing problem is internal to the protocol definitions: the estimators do not estimate the phase on the states the protocols prepare. Protocol 1 prepares |ψ+>=(|0>_A|0>_B+|1>_A|1>_B)/√2 and, after Bob applies U(ϕ) to B, estimates ϕ from (1/2)arccos((<X_A⊗Z_B>+<Z_A⊗X_B>)/2). For this state, with n=1, a direct calculation gives <X_A⊗Z_B>=-sin(2ϕ) and <Z_A⊗X_B>=sin(2ϕ), so the argument of arccos is identically zero; at ϕ=0 the estimator returns π/4, not 0. The check-round fidelity (3) also fails: at ϕ=0, <X_A⊗Z_B>=<Z_A⊗X_B>=0 and <Y_A⊗Y_B>=±1 depending on convention, so F_hat is 0 or 1/2, not 1, for the ideal state. Protocol 2 is no better: for each P∈{±X,±Z}, preparing |P,+> and applying U(ϕ), one finds <P>=cos(2ϕ), so the right-hand side of Eq. (8) equals 2ϕ for small ϕ, not ϕ; the estimator is missing a factor 1/2. The proof of Lemma 1 relies on the identity (A4), |ψ+>=(|+>|0>+|->|1>)/√2=(|R>|R>+|L>|L>)/√2, which is false for the state defined in Eq. (2). Since Theorems 5 and 1 are derived from these formulas, the central claim is not supported as written. The finite-sample issue raised by the reader is real, but secondary: the ideal noiseless case already breaks the estimator.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript proposes two one-way distributed quantum sensing protocols (an entanglement-based Protocol 1 and a MUB-based Protocol 2) and their two-way variants, claiming threshold-based faithfulness and one-way security against general-coherent attacks. The theoretical analysis imports an LOCC1 de Finetti theorem to relate fidelity measured in check rounds to the state used in estimation rounds, and derives bias and variance bounds (Theorems 1 and 5). The paper also reports a photonic polarization experiment with n=1 and compares the theoretical bounds with measured bias and variance. The main claimed novelties are the safety-threshold mechanism, the entanglement/MUB equivalence, and robustness to collective attacks.","tokens_in":17909,"tokens_out":14408,"duration_ms":157198,"significance":"The problem addressed is timely, and the use of the LOCC1 de Finetti theorem of Ref. [25] is an appropriate technical instrument with the potential to bring distributed sensing security closer to QKD standards. The paper contains an experimental demonstration and a public data repository link, which is commendable. If the claims were correct, the threshold-based (non-aborting) approach would be a practical advance over abort-based protocols. However, the central theoretical claims are not established as written: the phase estimators in both protocols fail on the ideal states, and the fidelity check in Protocol 1 fails on the ideal state. These are load-bearing algebraic errors, not presentation issues, so the significance of the paper cannot be assessed on the basis of the current theoretical results.","major_comments":[{"comment":"The phase estimator does not estimate the phase of the state that Protocol 1 actually prepares. For n=1, applying U(phi)=e^{i phi Y} to register B of the ideal state (|00>+|11>)/sqrt(2) gives <X_A X_B>? Direct calculation with the stated convention gives <X_A Z_B> = sin(2 phi) and <Z_A X_B> = -sin(2 phi) (up to the overall sign convention for Y), so the argument of the arccosine in Eq. (4) is identically zero. Equation (4) therefore returns pi/4 for every phi, including phi=0, and the bias and variance bounds in Theorem 1 do not follow.","section":"Protocol 1, Eqs. (2) and (4)"},{"comment":"The fidelity check fails on the ideal check-round state. For (|00>+|11>)/sqrt(2) with no phase encoding, one obtains <X_A Z_B> = <Z_A X_B> = 0 and <Y_A Y_B> = -1 with the stated Pauli convention, so Eq. (3) gives F_hat = 0, not 1. Even with the opposite sign convention for Y, F_hat = 1/2, so the ideal state does not pass a threshold of 1 - epsilon^2 for reasonable epsilon. This makes the protocol's check step inconsistent with its own ideal resource.","section":"Protocol 1, Eq. (3)"},{"comment":"The MUB-based estimator is also incorrect for the ideal states. For n=1, with U(phi)=e^{i phi Y}, a direct calculation gives <+X> = sin(2 phi), <-X> = +sin(2 phi), <+Z> = cos(2 phi), and <-Z> = -cos(2 phi), where each expectation is taken on the phase-encoded state prepared for the corresponding signed P. The average (1/4) sum_{P in {±X,±Z}} <P> is therefore sin(2 phi)/2, not cos(2 phi), and Eq. (8) returns pi/2 at phi=0. The factor-of-two discrepancy noted in the text's discussion is not the only problem; the estimator has the wrong functional form over the whole range.","section":"Protocol 2, Eq. (8)"},{"comment":"The identity used in the proof of Lemma 1 is false. With the standard definitions |±> = (|0> ± |1>)/sqrt(2) and |R/L> = (|0> ± i|1>)/sqrt(2), neither (|+>|0> + |->|1>)/sqrt(2) nor (|R>|R> + |L>|L>)/sqrt(2) equals the state (|00>+|11>)/sqrt(2) defined in Eq. (2). The correct X-basis expansion is (|+>|+> + |->|->)/sqrt(2), and the R/L expansion differs by a sign. Since Eqs. (A1)-(A3) and the claimed equivalence of Protocols 1 and 2 rest on (A4), the reduction step in the proof of Theorem 1 is not valid.","section":"Appendix A, Eq. (A4)"},{"comment":"The finite-sample issue is load-bearing and should be addressed even after the estimator inconsistencies are fixed. Equation (14) uses the point estimate F_hat_P obtained from a finite number N_c of check rounds as if it were the exact fidelity of the state used in estimation rounds. No confidence interval, finite-sample tail bound, or abort-probability penalty appears. Since F_hat_P is random, there is a nonzero probability that the check passes while the true fidelity is well below the threshold, so the deterministic bounds in Eqs. (5)-(6) and (29)-(30) do not hold for finite T as stated.","section":"Theorem 3, Eq. (14)"}],"minor_comments":[{"comment":"In the paragraph after Protocol 1, the expected numbers Nc ≈ pe T/3 and Ne ≈ pc T/3 appear to interchange the roles of pc (no-encoding/check rounds) and pe (encoding/estimation rounds); please correct the assignment of the probabilities.","section":"Section III B"},{"comment":"The bold observables X, Y, Z are defined only on the two-dimensional subspace span{|0>,|1>}; for n>1 their action on the orthogonal complement is left unspecified, although they are used in physical expressions such as X_A ⊗ Z_B. Please specify the full operators or state explicitly that only the restrictions to that subspace are relevant.","section":"Section III A"},{"comment":"The experimental text states that an additional plate rotation by an angle theta corresponds to a phase phi = 2 theta; the relation of this rotation to the definition U(phi) = e^{i phi Y} should be spelled out, since estimator (4) depends on the Y-eigenbasis convention.","section":"Section IV"},{"comment":"Figure 3 reports a retrieved phase that depends on theta, whereas Eq. (4) as written would return a constant independent of theta; please clarify which estimator was actually applied to the experimental data.","section":"Figure 3"}],"recommendation":"reject","confidential_remarks":"I agree with the substantive part of the prior report: the algebraic inconsistencies are decisive and not presentation-level. I recommend rejection rather than major revision because the state definitions, estimators, and proofs would need to be redesigned and the experimental analysis re-derived."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short take: the paper's big idea is useful, but its central protocols don't estimate the phase they claim to, so the headline result doesn't follow.\n\nWhat's new: applying the LOCC1 de Finetti theorem to distributed quantum sensing is a legitimately fresh step, and the threshold-based, non-abort mechanism is a reasonable response to the zero-tolerance problem in earlier work. The experiment is honest: it reports that the theoretical bounds overestimate tampering, and it gives a public-data link. Those parts are worth acknowledging.\n\nThe problem is at the core. Protocol 1 prepares |ψ+> = (|00>+|11>)/√2. For that state with n=1, a direct calculation gives <X_A Z_B> = -sin(2ϕ) and <Z_A X_B> = sin(2ϕ), so the argument of arccos in Eq. (4) is identically zero; the estimator returns π/4 regardless of ϕ. At ϕ=0 it should return 0, so it fails even in the noiseless case. The fidelity check (3) is also wrong: for the ideal state, <Y_A Y_B> = -1, so F_hat = 0, not 1. Protocol 2 has the same disease: for every P in {±X,±Z}, the prepared eigenstate evolved under U(ϕ) gives <P> = cos(2ϕ), so Eq. (8) returns 2ϕ, not ϕ. The Appendix A identity (A4) is false for the state defined in Eq. (2). These are not typos; Theorem 1 and Theorem 5 are derived from these formulas. The finite-sample issue, using F_hat from a finite number of check rounds as if it were exact fidelity without a confidence interval, is real but secondary; the noiseless case already breaks the estimator.\n\nI would like to see whether the framework can be repaired, for example by choosing a different probe or fixing the estimator. But as written the central claim is unsupported and the paper should be rejected in its current form. That said, the topic is important and the LOCC1-de Finetti application could be valuable if the state/estimator problem is solved, so I would not desk-reject it; I would send it to referees with the expectation that substantial revision is needed. For now, do not cite it.","headline":"The LOCC1 de Finetti application and threshold-based mechanism are worth a look, but Protocol 1 and Protocol 2 as written do not estimate the phase they claim to, so the central results do not hold.","tokens_in":18428,"tokens_out":7057,"would_cite":false,"duration_ms":72146,"reading_group":"maybe","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper establishes that a threshold-based one-way protocol makes distributed quantum sensing perfectly secure against general-coherent attacks, with bias and variance deviations bounded by the safety threshold, and demonstrates this…","keywords":["distributed quantum sensing","quantum metrology","general-coherent attacks","mutually unbiased bases","quantum de Finetti theorem","phase estimation","entanglement","safety threshold"],"falsifier":"Run Protocol 1 with a tampering channel whose true fidelity is just below $1-\\epsilon^2$ but whose finite-sample check estimates fluctuate above it; if accepted rounds produce bias or variance deviations larger than the bounds in Eqs. (5) and (6), the finite-sample guarantee fails. Equivalent analytic test: compute the sampling distribution of $\\hat F$ and find a tampered state with true fidelity below threshold that passes the check with positive probability.","tokens_in":17262,"feed_emoji":"🔐","tokens_out":13225,"duration_ms":152754,"temperature":0.7,"pith_summary":"This paper proposes distributed quantum sensing protocols in which a quantum-capable provider sends probe states over a public network to a remote party who encodes an unknown phase, and the same rounds that estimate the phase also certify whether an eavesdropper has tampered with the probes. The central claim is that the one-way version is perfectly secure and faithful: if the fidelity measured in check rounds clears a safety threshold $\\epsilon$, then the bias and variance of the phase estimate differ from the ideal by explicit bounds, even when Eve can launch general-coherent attacks, i.e., entangle probes across rounds and use a quantum memory. The guarantees are shown to hold equally for an equivalent mutually-unbiased-bases formulation, so entanglement is a convenience rather than a requirement, and the two-way version retains faithfulness but not security. A photonic proof-of-principle with one entangled pair per round confirms the protocol is practical and shows that the theoretical bounds tend to overestimate actual tampering. This matters because it replaces abort-on-any-error policies with a quantitative threshold, making secure remote sensing compatible with realistic noisy channels.","feed_headline":"Safety threshold bounds tampering in distributed quantum sensing","feed_subtitle":"One-way protocol stays faithful under quantum-memory attacks; photonic test shows bounds are conservative.","key_machinery":"The load-bearing object is Protocol 1, an entanglement-based round structure that splits transmissions into check rounds (no phase encoding, Pauli measurements on both sides) and estimation rounds (phase encoding, restricted Pauli measurements), with a discard probability $p_d$ that creates the slack needed against general-coherent attacks. The fidelity check (3) reconstructs $\\hat F = (1+\\langle X\\otimes Z\\rangle+\\langle Z\\otimes X\\rangle+\\langle Y\\otimes Y\\rangle)/4$ from sifted check rounds and compares it to $1-\\epsilon^2$. The proof machinery has three pieces: Lemma 1, which shows Protocol 1 is equivalent to the MUB-based Protocol 2 under the threshold rescaling $\\epsilon^2=3\\bar\\epsilon^2/2$; Theorem 2, the LOCC1 quantum de Finetti theorem, which bounds the distance between the collective tampered state and a mixture of independent identical states by $f(T,N_d,n)$; and Lemma 2, a gentle-measurement lemma that transfers the fidelity estimated on check rounds to estimation rounds. Theorem 4 then shows that closeness in LOCC1 distance uniformly bounds the expectation and variance of local observables, which is what turns the fidelity certificate into the bias and variance guarantees.","core_discovery":"The paper's central result, Theorem 1, states that the one-way entanglement-based Protocol 1 is perfectly secure under general-coherent attacks and that its faithfulness is exactly governed by the safety threshold $\\epsilon$. If the check-round fidelity estimate satisfies $\\hat F \\ge 1-\\epsilon^2$, then for any unbiased phase estimator $\\hat\\phi$ the tampered-state expectation and variance deviate from the ideal-state values by $|\\mathbb E\\hat\\phi-\\mathbb E\\hat\\phi'| \\le \\epsilon_0/(n|\\sin(2n\\phi)|)$ and $|\\Delta^2\\hat\\phi-\\Delta^2\\hat\\phi'| \\le (2\\epsilon_0+\\epsilon_0^2)/(n^2\\sin^2(2n\\phi))$, where $\\epsilon_0 = \\sqrt{\\frac23\\epsilon^2+4f(T,N_d,n)}$ with $f(T,N_d,n)=(T-N_d-1)\\sqrt{n/(2N_d)}$; restricting Eve to individual attacks removes the $f$ term. The proof proceeds by (i) proving equivalence to a MUB-based protocol with a rescaled threshold $\\epsilon^2=3\\bar\\epsilon^2/2$, (ii) using a one-way-adaptive (LOCC1) quantum de Finetti theorem to show that check-round fidelity controls the estimation-round state distance, and (iii) converting that distance into uniform bias and variance bounds via error propagation. The paper also proves that the two-way version has similar faithfulness bounds but cannot guarantee security. A photonic implementation with $n=1$ entangled photons found fidelity $0.937\\pm0.017$, corresponding to $\\epsilon=0.251\\pm0.034$, and measured deviations well inside the predicted bounds.","pith_inferences":["A finite-$T$ rigorous version of the protocol would need a confidence interval on $\\hat F$; inserting such a term into $\\epsilon_0$ would show how many check rounds are needed to make the threshold meaningful.","The gap between the certified bounds and the observed deviations is a testable target: if the tampered state is reconstructed, the exact bias and variance can be compared against the bounds to see how much slack comes from the trace-distance step.","The same LOCC1 de Finetti certificate should transfer to multi-user sensor networks and to continuous-variable phase estimation wherever a check/estimation round split with MUB-like measurements is available.","An adversary aware of the finite-sample issue could attempt to make check-round correlations pass the threshold by chance while corrupting estimation rounds, so quantifying the required $N_c$ is a concrete open problem."],"forward_implications":["A user can keep the protocol running in noisy conditions by choosing a finite threshold $\\epsilon$; detection of non-zero errors no longer forces an abort, only a threshold violation does.","Providers can implement secure distributed sensing without distributing entanglement: the MUB version has the same guarantees with a rescaled threshold, so prepare-and-send hardware suffices.","The check-round fidelity certificate extends to the estimation rounds even when Eve stores probes in a quantum memory, as long as enough rounds are discarded to make $f(T,N_d,n)$ small.","In the two-way configuration a passive Bob can certify faithfulness, but security is impossible because Eve can interact with the probe both before and after phase encoding.","Experimental bias and variance deviations can lie far below the certified bounds, so the guarantees are conservative rather than tight."],"supporting_citations":[{"why":"Supplies the LOCC1 quantum de Finetti theorem used to convert general-coherent attacks into a bound on the estimation-round distance.","marker":"[25]"},{"why":"Defines the cryptographic quantum metrology framework and provides the individual-attack bias and variance bounds that Theorem 5 generalizes.","marker":"[6]"},{"why":"Introduced decoy and flag states for cryptographic quantum parameter estimation, the starting point the protocols replace with a threshold mechanism.","marker":"[5]"},{"why":"Establishes the entangled n-qubit phase probe and its metrological scaling, setting the ideal estimation benchmark used in the bounds.","marker":"[1]"},{"why":"Provides the worst-case state-distinguishability bound used to quantify tampering in the two-way protocol.","marker":"[44]"},{"why":"Gives the gentle-measurement lemma that lets check-round fidelity be transferred to estimation rounds.","marker":"[36]"},{"why":"Defines the general-coherent attack class, the adversary model under which the security and faithfulness claims are proven.","marker":"[27]"}],"fun_headline_variants":["Distributed quantum sensing secure against general-coherent attacks","One-way protocol sets tamper bounds for secure distributed sensing","Photonic test shows conservative security bounds in quantum sensing","Fidelity threshold certifies tampering bounds in distributed sensing","General-coherent attacks defeated by one-way sensing protocol"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The safety-threshold step treats the fidelity estimated from a finite number of check rounds as the exact fidelity of the received state, and the theorem's bound contains no finite-sample confidence interval to cover estimation noise.","fun_headline_variants_meta":{"raw":{"variants":["Distributed quantum sensing secure against general-coherent attacks","One-way protocol sets tamper bounds for secure distributed sensing","Photonic test shows conservative security bounds in quantum sensing","Fidelity threshold certifies tampering bounds in distributed sensing","General-coherent attacks defeated by one-way sensing protocol"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000692,"raw_usage":{"total_tokens":3215,"prompt_tokens":1110,"completion_tokens":2105,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":726,"completion_tokens_details":{"reasoning_tokens":2027}},"tokens_in":726,"tokens_out":2105,"duration_ms":21405,"temperature":1.0,"reasoning_tokens":2027,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T00:51:29.292072+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run Protocol 1 with a tampering channel whose true fidelity is just below $1-\\epsilon^2$ but whose finite-sample check estimates fluctuate above it; if accepted rounds produce bias or variance deviations larger than the bounds in Eqs. (5) and (6), the finite-sample guarantee fails. Equivalent analytic test: compute the sampling distribution of $\\hat F$ and find a tampered state with true fidelity below threshold that passes the check with positive probability.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the cryptographic quantum metrology framework and provides the individual-attack bias and variance bounds that Theorem 5 generalizes."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduced decoy and flag states for cryptographic quantum parameter estimation, the starting point the protocols replace with a threshold mechanism."},{"cited_title":"Note that this is a combination of soundness and integrity as defined by [6]","cited_arxiv_id":null,"evidence_quote":"Establishes the entangled n-qubit phase probe and its metrological scaling, setting the ideal estimation benchmark used in the bounds."},{"cited_title":"Munar-Vallespir and J","cited_arxiv_id":null,"evidence_quote":"Provides the worst-case state-distinguishability bound used to quantify tampering in the two-way protocol."},{"cited_title":"Li and G","cited_arxiv_id":null,"evidence_quote":"Gives the gentle-measurement lemma that lets check-round fidelity be transferred to estimation rounds."},{"cited_title":"Zhao, Y.-Z","cited_arxiv_id":null,"evidence_quote":"Defines the general-coherent attack class, the adversary model under which the security and faithfulness claims are proven."}],"review_version":1}