{"id":"4bd87455-8c62-48ae-8321-d16391f7136d","arxiv_id":"2505.18133","paper_version":2,"verdict":"REJECT","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"high","formal_verification":"none","parameter_count":0,"one_line_summary":"A proposed protocol wraps CSS-coded qubits in three-stage secret rotations, but the final measurement step limits it to key distribution rather than the claimed arbitrary-qubit transmission.","lead":"This paper proposes a protocol that combines CSS quantum error correction codes with Kak's three-stage quantum communication scheme. The authors claim it is the first integrated encryption and error correction method that can send arbitrary qubits.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Protocol's final Z-basis measurement (Section 2, Step 5) collapses arbitrary input states, so the claim of transmitting arbitrary qubits fails even in the ideal noiseless case.","rationale":"The reader's weakest_assumption points to error accumulation through the three channel traversals. That is a real gap: Section 2 Steps 2–5 interleave secret rotations U_A, U_B with noise, and since R(θ) does not commute with X/Z errors, the effective noise at Bob's final syndrome measurement is not a Pauli channel correctable by the CSS stabilizers. However, I regard the final Z-basis measurement as more load-bearing because it invalidates the abstract's 'arbitrary qubits' claim even in the ideal noiseless limit. Steps 1 and 5 of Section 2 (eqs. 4–5 and the instruction to 'measure the qubits in the globally declared basis of choice, i.e., Z-basis') define a prepare-and-measure protocol for classical bits. Steps 6–9 are classical sifting and privacy amplification. There is no step that outputs a quantum state to Bob; the protocol either measures the data qubits or uses them as key material. A noiseless run with input |+⟩_L would yield a random classical bit, not |+⟩_L. This is a direct contradiction of the central claim, not a fixable parameter choice. The paper's own discussion in Section 1 promises QSDC for arbitrary qubits, but the protocol never describes a mode in which Bob refrains from measuring. Therefore the central claim fails on its own terms. The CSS construction and three-stage commuting-rotation idea are sensible in isolation, and the paper honestly labels itself a first attempt, but the presented protocol does not implement the advertised functionality. The reader's verdict of REJECT is therefore unchanged by this analysis.","tokens_in":9408,"tokens_out":6377,"duration_ms":53374,"concrete_test":"Take the noiseless case with the Steane [[7,1,3]] code and input |+⟩_L = (|0⟩_L+|1⟩_L)/√2. Execute Steps 2–5 with θ=φ=0 (or any rotations) and no channel noise. Step 5 measures in Z-basis; the output is a classical bit 0 or 1 with probability 1/2 each. Compute the fidelity between Bob's post-measurement state and |+⟩_L: it is 1/2, not 1. This directly falsifies the abstract's claim of arbitrary-qubit transmission, even under ideal conditions.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim that the protocol 'allows for arbitrary qubits to be transmitted' is contradicted by the protocol's own final step. In Section 2, Step 1, Alice prepares only classical bits (|0⟩ or |1⟩) encoded into CSS codewords (eqs. 4–5), and Step 5 instructs Bob, after error correction, to 'measure the qubits in the globally declared basis of choice, i.e., Z-basis.' Steps 6–9 then perform sifting and classical post-processing on the measured bits. This is a prepare-and-measure key-distribution protocol: the transmitted quantum information is collapsed to classical outcomes. If Alice instead sent an arbitrary qubit α|0⟩+β|1⟩ (as the abstract and Section 1 promise for QSDC), the final Z-measurement would project it to |0⟩ or |1⟩, destroying the superposition; the receiver obtains a classical bit, not the input state. No error-correction analysis can repair this, because the loss of quantum information occurs in the ideal noiseless case. Thus the paper does not deliver 'joint encryption and error correction' for arbitrary qubits; at best it describes CSS-encoded three-stage key distribution.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes combining the Calderbank-Shor-Steane (CSS) quantum error-correction code with Kak's three-stage secure quantum communication protocol, claiming a 'single integrated process' for joint encryption and error correction that also allows arbitrary qubits to be transmitted. The protocol encodes classical bits into CSS logical states, applies Alice's and Bob's secret rotations over three channel traversals, and then lets Bob perform a CSS syndrome measurement. Steps 6–9 add sifting, information reconciliation, and privacy amplification, and Section 3 derives a code-rate bound and invokes Wei et al.'s privacy-amplification theorem. A worked example using Steane's [[7,1,3]] code is presented.","tokens_in":9652,"tokens_out":6043,"duration_ms":50633,"significance":"Making the three-stage protocol robust to channel noise is a worthwhile goal, and the protocol retains some attractive features of the three-stage approach, notably the absence of quantum memory and the use of commuting secret rotations. If the central claim were established, the scheme would be a useful step toward noise-tolerant quantum secure direct communication. The manuscript also correctly identifies a real gap in prior work: most QSDC protocols rely on memory or entanglement, and most QECC integrations are limited to QKD. However, the present version does not deliver the claimed result. The final measurement step destroys arbitrary quantum states, the CSS code parameters are internally inconsistent, and the error-accumulation analysis is missing. These are load-bearing correctness issues, not presentation problems.","major_comments":[{"comment":"The protocol's own final step contradicts the claim that arbitrary qubits are transmitted. Step 1 encodes only the classical states |0⟩ and |1⟩, as shown in Eq. (5), and Step 5 instructs Bob, after error correction, to 'measure the qubits in the globally declared basis of choice, i.e., Z-basis.' Any input superposition α|0⟩+β|1⟩ would be projected onto |0⟩ or |1⟩ by this measurement, so the receiver obtains a classical bit, not the transmitted quantum state. This failure occurs even in the ideal noiseless case, so no error-correction analysis can repair it. The later assertion in Section 2 that 'in general, however, Alice may transmit a qubit that is produced as the output of an algorithm' is not supported by any protocol step. At best, the paper describes CSS-encoded three-stage key distribution, not QSDC of arbitrary qubit states.","section":"Section 2, Steps 1 and 5; abstract and Section 1"},{"comment":"The CSS code dimension is stated inconsistently. Eq. (2) gives Q:[[n,k=k1+k2,min{d1,d2}]], while Section 3, Eq. (21), gives k=k1−k2. For the Steane [[7,1,3]] example, which uses C1=C2 as the [7,4,3] Hamming code, these formulas give k=8 and k=0, respectively, neither of which matches the claimed k=1. The manuscript never specifies which classical codes C1 and C2 are used in the example, nor does it state the standard CSS dimension condition. Because the code parameters are essential to the claimed CSS construction, this inconsistency invalidates the code-rate derivation in Eqs. (21)–(27) and undermines the worked example.","section":"Eq. (2) and Eq. (21)"},{"comment":"The protocol analyzes error correction as if all noise can be lumped into a single final error ε before Bob's syndrome measurement, but the state traverses the channel three times. If the channel errors are E1, E2, and E3, the effective operation seen by Bob's final CSS decoder is approximately UB† E3 UA† E2 UB E1 UA (up to ordering), where UA and UB are the secret rotations. No argument is given that this effective error lies in the correctable set of the CSS code. In particular, because UA and UB are not stabilizer operations, a Pauli error occurring in an early traversal need not be conjugated into a correctable Pauli error at the final syndrome measurement. The paper needs an explicit error model and a proof that all error configurations satisfying the sifting threshold are correctable; without this, the integrated error-correction claim is unproven.","section":"Section 2, Steps 2–5"},{"comment":"The privacy-amplification security analysis simply states that Wei et al.'s Theorem [3] 'can be used' for the proposed protocol, without verifying the theorem's hypotheses. In particular, the manuscript does not show that Alice and Bob share identical corrected strings W with negligible failure probability, that W has the required collision entropy conditioned on Eve's information, that the public announcement of x−vk in Step 9 does not reduce that entropy below the needed level, or that the generalized hash function class used satisfies the theorem's conditions. Eq. (29) is asserted with a generic 'd' that is never derived for this protocol. Consequently, the statement in the Conclusions that the protocol is 'equally (if not more) secure than the BB84 protocol' is unsupported.","section":"Section 3, Eqs. (28)–(30)"}],"minor_comments":[{"comment":"The quotient notation C2/C1 is not well defined unless C1 is a subspace of C2; the standard CSS construction uses cosets of C2⊥ in C1, and the basis states in Eq. (3) should be defined with C1⊥, not C1, in the coset sum.","section":"Eq. (3)"},{"comment":"The in-text citation 'Wei et al., 2019' corresponds to reference [15], whose listed authors are 'Jia, W., Feng, B., Yu, H. & Bian, Y.'; the attribution should be corrected for consistency.","section":"References"},{"comment":"The stabilizer table in Eq. (16) is garbled and difficult to read; the text also describes checking 'X-gate operations on qubits 1, 3, and 7' for the first stabilizer, but the table row lists X1X3X5X7, so the description and the table should be reconciled.","section":"Eq. (16) and surrounding text"},{"comment":"There are several typographical and notational issues, including 'desgining' in Section 1, the unnumbered use of collision entropy in Section 3, and the inconsistent use of qk in Eqs. (4)–(5) before its meaning is fully defined.","section":"Throughout"}],"recommendation":"reject","confidential_remarks":"The reader's assessment aligns with my own: the fatal issue is that the protocol's final Z-basis measurement collapses arbitrary quantum states, so the central claim in the abstract is contradicted by the protocol as written. The CSS dimension inconsistency and the lack of any three-stage error-accumulation analysis are additional load-bearing gaps. These are not merely presentational; a rewrite that removes the final measurement would require a genuinely new protocol, not a local fix. I therefore recommend rejection, though the authors might be encouraged to resubmit a version that either restricts the claim to QKD or designs a truly coherent QSDC protocol with end-to-end error analysis."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Thanks for sending this over. I agree with the reader: reject, but the interesting part is that the combination itself is new. The authors take Kak's three-stage QSDC scheme and bolt on CSS codes, which nobody seems to have done in exactly this form. The motivation is sensible: if you're sending a qubit through the channel three times, you need to handle noise from each leg, and integrating code and encryption is a worthwhile goal. They also give a worked Steane-code example, which helps the reader see the mechanics.\n\nThat said, the central claim in the abstract and intro — that this transmits arbitrary qubits — is false on the face of it. Step 5 instructs Bob to measure all qubits in the Z-basis after error correction, and steps 6–9 are classical sifting and post-processing. If Alice had sent α|0⟩+β|1⟩, that measurement collapses it. The protocol is prepare-and-measure key distribution, not QSDC of arbitrary states. The stress-test note is right, and it lands in the ideal noiseless case, so no amount of error correction can fix it.\n\nThe other soft spots are equally load-bearing. Section 2 never analyzes how errors from the three transmissions combine before Bob's final syndrome measurement. The secret rotations are unitary and commute, but channel noise is not unitary and does not commute with the rotations; the noise operators get conjugated between stages, and the paper doesn't touch that. Also, Eq. (2) gives the CSS dimension as k=k1+k2, while Eq. (21) uses k=k1−k2. The standard construction is k=k1−k2, so the earlier formula is simply wrong. Small thing: the example in Section 2 uses x⊕v where the text says x−v; that's notation friction, not fatal.\n\nThe security analysis is borrowed from Wei et al.'s BB84 protocol without verifying that the conditions carry over. That's a common shortcut, but here it matters because the three-stage protocol has a different information structure. And the paper's own statement that this is the 'first' joint scheme is overstated: earlier work by Parakh already coupled error correction with three-stage, as cited.\n\nSo: the combination is new and worth a paragraph in a future paper, but the protocol as written does not do what it claims. It needs a real fix — show how to transmit a superposition and measure in a way that preserves it, or re-scope the claim to key distribution. As it stands, I would not send this to peer review; a referee would quickly find the same contradictions. If the authors revise, the interesting kernel is there, but this version is not refereeing-ready.","headline":"The paper combines CSS codes with Kak's three-stage protocol, but the final Z-basis measurement kills the arbitrary-qubit claim, and the error analysis never addresses three-stage noise accumulation.","tokens_in":10141,"tokens_out":2123,"would_cite":false,"duration_ms":16441,"reading_group":"maybe","serious_thinker":"no","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P68","81P70","81P94"],"pacs":["03.67.Hk","03.67.Pp","03.67.Dd"],"model":"deepseek-v4-flash","headline":"The paper integrates CSS error correction into the three-stage quantum communication protocol, making encryption and error correction a single process that transmits arbitrary qubit states.","keywords":["quantum secure direct communication","three-stage protocol","CSS codes","quantum error correction","joint encryption","arbitrary qubits","Steane code","privacy amplification"],"falsifier":"Simulate the full protocol with the Steane code, applying independent depolarizing noise with per-qubit error probability $p$ on each of the three legs, performing the secret rotations exactly as specified, and measuring how often the decoded logical qubit differs from the input; if the logical error rate is significantly worse than the rate predicted for a single channel use with the same total noise, the assumption that the three legs' errors merge into one correctable error fails.","tokens_in":9191,"feed_emoji":"🔐","tokens_out":9910,"duration_ms":83951,"temperature":0.7,"pith_summary":"The paper argues that quantum encryption and quantum error correction need not be separate stages: it fuses the three-stage secure quantum communication protocol with Calderbank-Shor-Steane (CSS) codes into one integrated process. In the combined protocol, Alice encodes each logical qubit with a CSS code, both parties apply their secret rotation operators during three transmissions, and Bob runs CSS syndrome correction only after the final unrotation, so the encrypted and encoded state is corrected in one shot. The authors claim this is the first such joint scheme, that it works for arbitrary qubit states rather than just classical bit strings, and that it needs no quantum memory or entanglement. A reader should care because a single integrated process would reduce overhead for future quantum networks that must both protect and correct qubit transmissions.","feed_headline":"One quantum protocol encrypts and error-corrects in a single pass","feed_subtitle":"Fusing CSS with the three-stage protocol lets arbitrary qubits travel securely without extra error-correction overhead.","key_machinery":"The load-bearing object is the three-stage protocol's commuting secret rotation operators, $U_A(\\theta)$ and $U_B(\\phi)$, applied to every qubit of a CSS-encoded block. The CSS code, built from two classical linear codes $C_1,C_2$ with $C_2^\\perp \\subseteq C_1$, defines the logical states $|0_L\\rangle$ and $|1_L\\rangle$ as uniform superpositions over cosets, so bit-flip and phase-flip errors can be diagnosed by stabilizer measurements. The protocol's core step is to run the full three-stage rotation sequence first and then apply CSS syndrome correction at the very end, which is what makes encryption and error correction a single integrated process.","core_discovery":"The central discovery is that CSS error correction can be layered onto the three-stage protocol without disturbing the commuting-rotation encryption. With the Steane [[7,1,3]] code, each logical qubit is a superposition over a classical code; Alice applies a secret rotation to every encoded qubit, Bob applies his own, Alice removes hers, and finally Bob removes his and uses the CSS stabilizers to detect and correct any single bit-flip or phase-flip error on the recovered state. Because all operations are unitary and commute, the encoding and Alice's encryption rotation can be combined into one step, and no measurement occurs until Bob's final decoding. The paper also adapts the existing collision-entropy privacy amplification argument to bound Eve's information about the resulting key.","pith_inferences":["A natural stress test the paper does not perform: simulate three independent noisy legs and check whether the final CSS decoding still meets the single-use error-correction threshold; the answer determines whether the integrated scheme is actually valid under realistic noise.","The commuting-rotation structure is generic, so the same integration might be attempted with other stabilizer codes, e.g., LDPC or topological codes, if their stabilizers commute with the secret rotations.","The protocol's security analysis borrows BB84-style privacy amplification, but Eve observes the state three times in flight, so a full proof would need to bound the leaked information across all three exposures, not just a single channel use.","The claimed $4n$ qubit retention ignores attenuation loss; since the state traverses the channel three times, the effective loss per qubit is multiplied, and the padding factor $\\delta$ would need to grow correspondingly in a real fiber deployment."],"forward_implications":["If the protocol works as described, Alice can send output qubits from a quantum algorithm directly to Bob as arbitrary states, with encryption and error correction in one integrated step and no measurement until the final decoding.","The scheme requires no quantum memory and no entanglement, only single qubits traveling back and forth, so it could be implemented with current photonic technology.","Because there is no basis mismatch, the protocol retains about $4n$ qubits instead of the $2n$ typical of BB84-style prepare-and-measure protocols, making it more efficient under the paper's assumptions.","The adapted privacy amplification argument implies the final key can be made almost uniformly random relative to Eve by choosing the hash length $m$ so that $2^{m-d}$ is negligible.","The combined protocol corrects at least one bit-flip and one phase-flip error, matching the capability of the CSS code used."],"supporting_citations":[{"why":"Supplies the three-stage protocol with commuting secret rotations that the paper extends with CSS encoding.","marker":"[8]"},{"why":"Provides the CSS code construction theorem that turns two classical linear codes into a quantum error-correcting code.","marker":"[13]"},{"why":"Gives the 7-qubit Steane code and stabilizer measurements used in the worked example.","marker":"[14]"},{"why":"Provides the CSS-based QKD scheme and the collision-entropy privacy amplification argument the paper adapts for security analysis.","marker":"[15]"},{"why":"Earlier attempt to correct rotational errors in the three-stage protocol, motivating the need for integrated error correction.","marker":"[19]"},{"why":"Shows how to correct errors in the three-stage protocol with fewer qubits, which the integrated CSS scheme extends.","marker":"[20]"}],"fun_headline_variants":["Quantum protocol encrypts and error-corrects in one pass","Single-step quantum encryption with built-in error correction","CSS code integrated into three-stage quantum protocol"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The protocol assumes that the noise picked up during the three separate transmissions (Alice to Bob, Bob to Alice, Alice to Bob again) combines into a single error on the final state that the CSS syndrome measurement can detect and correct, after the secret rotations have been applied and removed.","fun_headline_variants_meta":{"raw":{"variants":["Quantum protocol encrypts and error-corrects in one pass","Single-step quantum encryption with built-in error correction","CSS code integrated into three-stage quantum protocol"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000968,"raw_usage":{"total_tokens":4047,"prompt_tokens":800,"completion_tokens":3247,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":416,"completion_tokens_details":{"reasoning_tokens":3198}},"tokens_in":416,"tokens_out":3247,"duration_ms":26117,"temperature":1.0,"reasoning_tokens":3198,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T14:35:00.529683+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Simulate the full protocol with the Steane code, applying independent depolarizing noise with per-qubit error probability $p$ on each of the three legs, performing the secret rotations exactly as specified, and measuring how often the decoded logical qubit differs from the input; if the logical error rate is significantly worse than the rate predicted for a single channel use with the same total noise, the assumption that the three legs' errors merge into one correctable error fails.","supporting_citations":[{"cited_title":"Multiple particle interference and quantum error correction.Proc","cited_arxiv_id":null,"evidence_quote":"Gives the 7-qubit Steane code and stabilizer measurements used in the worked example."},{"cited_title":"& van Brandwijk, J","cited_arxiv_id":null,"evidence_quote":"Earlier attempt to correct rotational errors in the three-stage protocol, motivating the need for integrated error correction."},{"cited_title":"Using fewer qubits to correct errors in the three-stage qkd protocol","cited_arxiv_id":null,"evidence_quote":"Shows how to correct errors in the three-stage protocol with fewer qubits, which the integrated CSS scheme extends."}],"review_version":1}