{"id":"eaa3dddd-deba-4288-8763-fd625224697e","arxiv_id":"2506.22294","paper_version":2,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Any two-outcome qubit measurement and any white-noise-affected projective measurement have exact, closed-form maximal intrinsic randomness, given by formulas in terms of the trace of the square root of one POVM element.","lead":"This paper finds exact formulas for the maximum amount of private randomness that can be extracted from two families of noisy quantum measurements. The formulas let designers of quantum random number generators compute guaranteed secure randomness for realistic noisy detectors without heavy numerics.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The closed forms inherit the [13] reduction from quantum to classical guessing; this external bridge is the weakest point and deserves an independent check.","rationale":"I read the manuscript in good faith. The central claim is that the guessing probability against an entangled eavesdropper, minimized over input states, is given exactly by the closed forms in Theorems 1 and 2. For this to hold, the reduction from the quantum optimization (2) to the classical decomposition SDP (A23) must be valid for pure input states; the paper inherits this reduction from ref. [13] rather than re-deriving it. The reader's weakest_assumption identifies exactly this point, and I agree that it is the most load-bearing step. However, I found no internal inconsistency in the proofs that follow: the lower-bound decompositions in Lemmas 1 and 3 are explicit and positive semidefinite, the upper-bound arguments in Lemmas 2 and 4 use valid dual variables and a symmetry argument that cross-check each other, and the qubit algebra is consistent with the d=2 limit of Theorem 2. The manuscript is also honest about its weaker claims: Corollary 1's saturation is only numerical, the shared-noise section states a lower bound within a classical joint-decomposition model, and the other conditional entropies are upper bounds with optimality left open. None of these affect the two central theorems. The absence of machine-checked proofs or released code is not a defect here because the derivations are fully written and the key step is a citation to a peer-reviewed result rather than a new unverified claim. Since the inherited reduction is the only substantive risk and it is a legitimate external theorem, I do not see a reason to change the reader's ACCEPT verdict. The proposed independent re-derivation of the qubit case would settle whether the reduction is being applied correctly and, if it succeeds, would remove even this residual concern.","tokens_in":36144,"tokens_out":14258,"duration_ms":172641,"concrete_test":"Take the qubit case and re-derive (A23) from (A13) without invoking [13]: parameterize a general two-outcome qubit Naimark dilation, allowing an ancilla of dimension up to four as guaranteed by Naimark's theorem, write out Eve's conditional ensemble p(x)rho_{x,E}, and optimize over Eve's POVM. Show that the optimum equals the classical decomposition SDP for every qubit M1 with tr M1 <= tr M2. If the derivation requires an extra assumption, such as the optimal dilation having classical flag states, Theorems 1 and 2 need qualification; if it goes through, the inherited bridge is confirmed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Theorems 1 and 2 are exact solutions of the classical decomposition SDP (A23), but the quantity they are claimed to bound, namely the guessing probability of an eavesdropper with quantum side information, is the optimization (2). The equality of (2) and (A23) for pure input states is imported from ref. [13]; Appendix A restates the classical SDP but does not derive the bridge. This is therefore the most load-bearing assumption in the paper: if the reduction had a hidden regularity condition, for instance requiring extremal decompositions, a bounded ancilla dimension, or a particular structure of the Naimark dilation, the closed forms would not govern the true quantum scenario. I found no internal gap in the classical proofs: the Lemma 2/3 sandwich is coherent, the dual variables in Appendix C2 satisfy slackness and positivity, and the independent permutation proof in Appendix C3 reproduces the same bound. The paper's self-declared limitations, namely that Corollary 1's bound is numerically but not analytically saturated, that the shared-noise comparison is a lower bound in a classical joint-decomposition model, and that the von Neumann and max-entropy results are upper bounds, are honestly labeled and do not touch Theorems 1 and 2. Because [13] is a published theorem covering the finite-dimensional pure-state setting, I treat the citation as legitimate rather than as a defect, but it is the place where an independent check would add the most value.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper studies the maximal intrinsic randomness of a quantum measurement, defined as the minimum over input states of the guessing probability of an eavesdropper who holds optimal side information. The main results are exact closed-form formulas for this quantity for two classes of measurements: any two-outcome qubit POVM (Theorem 1, P*_guess(M) = 1 - tr M1 + (1/2)(tr sqrt(M1))^2) and d-dimensional noisy projective measurements (Theorem 2, P*_guess(Md) = (1/d)(tr sqrt(M1))^2). Lower bounds are obtained from explicit POVM decompositions; matching upper bounds are obtained from feasible dual variables and a permutation-symmetry argument. The paper also presents a Corollary upper bound for arbitrary two-outcome POVMs, upper bounds for the conditional von Neumann and max-entropies, a coarse-graining analysis, and a study of the scenario where noise is shared between the state and the measurement.","tokens_in":36218,"tokens_out":17674,"duration_ms":156600,"significance":"If correct, these are the first exact solutions for the intrinsic randomness of noisy measurements, complementing the corresponding state-side results of Ref. [10]. The formulas are simple, parameter-free, and correctly reproduce the known limits (projective measurements, maximally mixed POVMs). The constructive proof technique, matching explicit decompositions with dual certificates, is elegant and likely to be reusable. The main caveat is that the identification of the classical decomposition SDP (4) with the quantum guessing probability (2) for pure input states is imported from Ref. [13] rather than proved; this is a legitimate citation, but it is the load-bearing external input to the advertised quantum-scenario interpretation. The auxiliary results (Corollary 1, the shared-noise bound, and the entropy upper bounds) are honestly labeled as not fully tight, which strengthens the credibility of the central claims.","major_comments":[{"comment":"Theorems 1 and 2 solve the classical guessing problem (4), and the equality of this quantity with the quantum guessing probability (2) for pure input states is taken from Ref. [13] (stated near Eq. (4) and in Appendix A). This is a published theorem covering exactly the finite-dimensional pure-state setting, so I consider the reliance legitimate; nonetheless, because this bridge is load-bearing for the central claim, an explicit statement of its hypotheses (or a short derivation) would make the paper more self-contained. This does not affect my assessment of the internal correctness of the classical proofs.","section":"Main text, Eq. (4) and Appendix A"}],"minor_comments":[{"comment":"The normalization constraint in the displayed SDP is garbled: 'Σ_x dK_{x,j} = 1' and the incomplete 'Σ_x tr K_{x,j}' do not form a correct condition. The intended constraint is Σ_x K_{x,j} = (1/d) Σ_x tr(K_{x,j}) 1, as used in the dual derivation (A24). Please correct the typesetting.","section":"Eq. (4) and Appendix A17"},{"comment":"The lemma numbering is inconsistent between the main text and the appendix: the qubit lower bound is Lemma 1 in the main text but is proved as 'Lemma 2' in Appendix B1, and the qubit upper bound is Lemma 2 in the main text but 'Lemma 3' in Appendix B3. The same offset occurs in Appendix C, where the noisy-projective lower and upper bounds are proved as Lemma 4 and Lemma 5 rather than Lemma 3 and Lemma 4. Please renumber for consistency.","section":"Main text Lemmas 1-4 and Appendix B/C"},{"comment":"The sentence 'an isotopic state would have the same max- and min-entropy as an isotropic measurement' contains a typo: 'isotopic' should be 'isotropic'.","section":"Discussion"},{"comment":"The definition of Y_x is garbled in the current rendering: the term 'Mx − 1 2' should be the matrix M_x^{-1/2} with the exponent as a superscript, not a separate constant. Please ensure the typesetting is unambiguous.","section":"Appendix C2, Eq. (C29)"},{"comment":"The phrase 'This begs the question' is a misuse of the idiom; 'raises the question' would be more appropriate. This is a minor stylistic issue.","section":"Main text, after Eq. (23)"}],"recommendation":"minor_revision","confidential_remarks":"The paper is a solid contribution with correct-looking proofs and honest limitations. The main risk is the reliance on Ref. [13] for the quantum-to-classical reduction, but that is a published result covering the relevant setting. The typographical issues in Eq. (4) and the appendix lemma numbering should be fixed before publication."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a real result. The authors give exact formulas for the maximal intrinsic randomness (minimized guessing probability) of every two-outcome qubit POVM and of isotropically noisy projective measurements in any dimension. That is genuinely new relative to prior work, which formulated the problem or solved the state analogue. The formulas are clean: P* = 1 - tr M1 + (1/2)(tr sqrt M1)^2 for qubits, and P* = (1/d)(tr sqrt M1)^2 for the noisy projective measurement. The proof structure is the right one: explicit square-root decompositions give lower bounds on Eve; feasible dual variables give matching upper bounds; the sandwich is tight. I checked the qubit algebra and the d=2, epsilon=0, epsilon=1 limits; they behave. The permutation-symmetry alternative proof in Appendix C3 is a nice cross-check on the heavy dual calculation in C2.\n\nWhat is also good: the paper labels its own limitations. Corollary 1's upper bound is only numerically saturated; the shared-noise attack is a lower bound in a classical joint-decomposition model; the von Neumann and max-entropy results are upper bounds with optimality open. None of that touches Theorems 1 and 2.\n\nThe soft spot is the bridge, not the internal math. The theorems solve the classical guessing SDP (A23). That this equals the true quantum guessing probability for a pure input state is imported from ref. [13] and restated, not re-derived. If that reduction carries hidden regularity requirements, the closed forms would not govern the full quantum side-information scenario. I regard this as a legitimate citation of a published theorem, but it is the place a referee should probe hardest. A minor separate issue: no code or data, but the derivations are complete enough that an independent implementation should be straightforward.\n\nVerdict: solid paper for the measurement-randomness community and for QRNG theory. It deserves a serious referee, and acceptance after the usual checks is reasonable. I would cite it if working on randomness from measurements.","headline":"Closed-form guessing probabilities for two classes of noisy measurements, proved by matching decompositions and dual certificates; the inherited quantum-to-classical reduction is the soft spot, but the paper is honest and solid.","tokens_in":36975,"tokens_out":2077,"would_cite":true,"duration_ms":22846,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P15","81P45","94A17"],"pacs":["03.65.Ta","03.67.-a"],"model":"deepseek-v4-flash","headline":"Noisy quantum measurements now have exact private-randomness formulas.","keywords":["quantum randomness","guessing probability","noisy measurements","min-entropy","POVM","qubit","white noise","side information"],"falsifier":"For the qubit POVM with $M_1 = \\mathrm{diag}(0.8, 0.1)$, solve the semidefinite program (4) or perform a dense search over input states and decompositions: any computed guessing probability below $1 - 0.9 + \\frac{1}{2}(\\sqrt{0.8} + \\sqrt{0.1})^2$ would falsify Theorem 1. For arbitrary dimension, take the $d=3$ noisy projective measurement at $\\varepsilon = 0.3$, numerically minimize equation (4) over $|\\varphi\\rangle$, and compare the result with $\\frac{1}{3}(\\operatorname{tr}\\sqrt{M_1})^2$.","tokens_in":35745,"feed_emoji":"🎲","tokens_out":8428,"duration_ms":88355,"temperature":0.7,"pith_summary":"Given a noisy quantum measurement, how much private randomness can it generate when an adversary may hold side information about the noise? The paper solves this optimization exactly for two families of practical measurements: every qubit measurement with two outcomes, and every rank-one projective measurement mixed with white noise in any dimension. The answer is a closed-form expression for the adversary's optimal guessing probability, which converts directly into the conditional min-entropy that bounds how many private random bits can be extracted. A further result is a warning about attribution: when the same observed statistics can arise with noise on the state, on the measurement, or on both, putting noise on both gives the adversary noticeably more guessing power.","feed_headline":"Exact formulas cap private randomness of noisy measurements","feed_subtitle":"Guessing probability, and so extractable private entropy, now has closed forms for two-outcome qubit and white-noise projective…","key_machinery":"The machinery is the guessing-probability semidefinite program: for a pure input state $|\\varphi\\rangle$, Eve's optimal strategy is a convex decomposition of the measurement into sub-POVMs, and her guessing probability is the sum of probabilities that her label matches Alice's outcome. The paper uses a known reduction from the quantum side-information problem to this classical decomposition, sets it up as a semidefinite program with a dual, and then exhibits optimal primal and dual solutions. The key object is the 'square-root decomposition': Eve splits $M_1$ into the rank-one term $\\sqrt{M_1}|\\varphi\\rangle\\langle\\varphi|\\sqrt{M_1}$ plus a remainder, and symmetrically for $M_2$; the generalized $d$-dimensional version splits each $M_x$ around $|\\varphi\\rangle$ and is proven optimal for the unbiased state via explicit dual variables. The matching lower and upper bounds from these decompositions close the min-max problem and produce the exact formulas.","core_discovery":"The central discovery is a pair of exact formulas. For any two-outcome qubit POVM (positive operator-valued measure) $M = \\{M_1, M_2\\}$ with $\\operatorname{tr} M_1 \\leq \\operatorname{tr} M_2$, the guessing probability minimized over all input states is $P^*_{\\mathrm{guess}}(M) = 1 - \\operatorname{tr} M_1 + \\frac{1}{2}(\\operatorname{tr} \\sqrt{M_1})^2$. For the noisy projective measurement $M_d$ obtained by mixing a rank-one projective measurement with white noise in dimension $d$, $P^*_{\\mathrm{guess}}(M_d) = \\frac{1}{d}(\\operatorname{tr} \\sqrt{M_1})^2$. Since the conditional min-entropy is $H^*_{\\min} = -\\log P^*_{\\mathrm{guess}}$, these give the maximal intrinsic randomness of the measurement. The optimizing input state is unbiased to the measurement basis; for the noisy projective measurement this also produces a uniform outcome distribution, while for a general two-outcome qubit POVM uniform outcomes occur only when $\\operatorname{tr} M_1 = \\operatorname{tr} M_2$. The paper also shows that for fixed observed statistics, a realization with noise on both state and measurement can be guessed much more successfully than either single-noise realization, with perfect guessing reached at noise $\\varepsilon^* = 1 - 1/\\sqrt{2}$ in the qubit case.","pith_inferences":["An implicit consequence for device-dependent quantum random number generators is a certification threshold: once the shared noise level passes $\\delta = 1/2$ in the qubit scenario, the measured statistics certify zero private randomness even though the outcomes remain maximally random statistically.","Going beyond the paper, the square-root form of Eve's optimal decompositions suggests a conjecture that for arbitrary POVMs the optimal attack is some coherent square-root splitting of each element; three-outcome qutrit POVMs would be a direct numerical test bed.","The paper leaves open whether the unbiased state maximizes conditional von Neumann and max-entropies; a testable extension is to compute those quantities for $d > 2$ and see whether the equality between measurement-side and state-side randomness survives beyond min-entropy."],"forward_implications":["Any noisy channel applied to a rank-one qubit projective measurement, such as depolarizing, phase-flip, or amplitude-damping noise, produces a two-outcome qubit POVM whose maximal intrinsic randomness is now computable in closed form.","For a noisy projective measurement in any dimension, the maximal intrinsic randomness equals that of the corresponding noisy pure state with the same noise parameter, so the noise can be attributed entirely to the state or entirely to the measurement without changing the min-entropy.","Coarse-graining a $d$-dimensional noisy projective measurement into two outcomes gives no more randomness than the qubit version; the adversary's best attack is to inflate her optimal qubit attack rather than coarse-grain her optimal $d$-dimensional attack.","When noise is shared between the state and the measurement, Eve's guessing probability is larger for every total-noise level, and she reaches perfect guessing already at $\\varepsilon^* = 1 - 1/\\sqrt{2}$ (equivalently $\\delta = 1/2$), whereas single-device noise reaches perfection only at maximal noise.","Upper bounds are given for the conditional von Neumann and max-entropies of the noisy projective measurement under the unbiased state; the paper leaves open whether the unbiased state is optimal for all conditional entropies and whether the square-root decomposition saturates those bounds."],"supporting_citations":[{"why":"Supplies the adversarial generalized-Naimark-dilation model in which Eve can hold entanglement with the measuring device.","marker":"[12]"},{"why":"Provides the reduction from the quantum guessing probability for pure input states to the classical convex-decomposition problem that Theorems 1 and 2 solve.","marker":"[13]"},{"why":"Gives the analogous maximal intrinsic randomness of a noisy quantum state, used for comparison and for the state-side entropy bounds.","marker":"[10]"},{"why":"Relates guessing probability to conditional min- and max-entropy, converting $P^*_{\\mathrm{guess}}$ into extractable private randomness.","marker":"[7]"}],"fun_headline_variants":["Exact formulas cap private randomness of noisy measurements","Noise on both state and measurement boosts eavesdropper guessing","Closed forms for maximal intrinsic randomness of noisy measurements","Exact guessing probability for qubit and white-noise projective measurements"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole calculation assumes that when Alice feeds in a pure state, a quantum eavesdropper with entanglement is no more powerful than a classical eavesdropper who knows which sub-measurement is being performed; the paper cites this equivalence rather than proving it, and if it failed the closed-form guessing probabilities would not describe the true adversarial scenario.","fun_headline_variants_meta":{"raw":{"variants":["Exact formulas cap private randomness of noisy measurements","Noise on both state and measurement boosts eavesdropper guessing","Closed forms for maximal intrinsic randomness of noisy measurements","Exact guessing probability for qubit and white-noise projective measurements"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00073,"raw_usage":{"total_tokens":3323,"prompt_tokens":1057,"completion_tokens":2266,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":673,"completion_tokens_details":{"reasoning_tokens":2201}},"tokens_in":673,"tokens_out":2266,"duration_ms":17682,"temperature":1.0,"reasoning_tokens":2201,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T22:08:35.054952+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"For the qubit POVM with $M_1 = \\mathrm{diag}(0.8, 0.1)$, solve the semidefinite program (4) or perform a dense search over input states and decompositions: any computed guessing probability below $1 - 0.9 + \\frac{1}{2}(\\sqrt{0.8} + \\sqrt{0.1})^2$ would falsify Theorem 1. For arbitrary dimension, take the $d=3$ noisy projective measurement at $\\varepsilon = 0.3$, numerically minimize equation (4) over $|\\varphi\\rangle$, and compare the result with $\\frac{1}{3}(\\operatorname{tr}\\sqrt{M_1})^2$.","supporting_citations":[{"cited_title":"Senno, T","cited_arxiv_id":null,"evidence_quote":"Provides the reduction from the quantum guessing probability for pure input states to the classical convex-decomposition problem that Theorems 1 and 2 solve."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the analogous maximal intrinsic randomness of a noisy quantum state, used for comparison and for the state-side entropy bounds."},{"cited_title":"Konig, R","cited_arxiv_id":null,"evidence_quote":"Relates guessing probability to conditional min- and max-entropy, converting $P^*_{\\mathrm{guess}}$ into extractable private randomness."}],"review_version":1}