{"id":"d504e5cf-3f3e-4e7c-bc50-0554eb23f343","arxiv_id":"2607.16276","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":8,"one_line_summary":"IDS-driven adaptive purification in a simulated 8-node quantum repeater chain restores fidelity-qualified entanglement delivery under SSDP-induced degradation (0.098 to 0.344 above-target; oracle 0.335).","lead":"In a simulated linear quantum-repeater network, feeding intrusion-detection scores into the entanglement-purification controller raised the probability of delivering usable high-fidelity entanglement during a simulated SSDP denial-of-service attack from 0.098 to 0.344, near the oracle-informed value of 0.335. The paper shows a concrete mechanism — cyber-state awareness switches the purification policy — that future quantum networks may need when their classical control planes","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Uncalibrated cyber-to-quantum degradation map and lack of a no-IDS replanning baseline leave the IDS-aware gain unverified; the paper's own limitations admit the map is phenomenological.","rationale":"I agree with the reader that the cyber-to-quantum degradation model is the load-bearing bridge. The internal simulation is coherent: given the degradation map and the planner, IDS-aware control can plausibly improve useful delivery by selecting purification-heavy masks. The oracle reference and independent Monte Carlo evaluation do provide some grounding, and the paper is honest in its Limitations section. However, the external validity of the headline number, and even the attribution to cyber-state awareness, is not established. The withheld η constants and affected-link set mean no sensitivity analysis is possible; the absent network-aware baseline means the information value of the IDS signal is confounded with the value of re-planning. These are not accusations of dishonesty; they are standard missing-control and missing-parameter issues. The reader's CONDITIONAL verdict is appropriate; my analysis does not move it.","tokens_in":31096,"tokens_out":6120,"duration_ms":64955,"concrete_test":"Run the attack-period experiment with an additional network-aware baseline that, like the IDS-aware controller, recomputes the purification mask in each time bin but estimates a(t) from observed link statistics (e.g., generation-success rate, delivered-fidelity samples) instead of from IDS scores, across a sweep of η_p,η_F,η_τ,η_T ∈ [0,0.5]. If this no-IDS replanning baseline reaches the same ~0.34 above-target delivery, the central claim reduces to 'replanning under degradation helps,' not 'IDS cyber-state awareness helps.' Also release the full parameter table to make the sweep reproducible.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central IDS-aware result (§IV.B, Fig. 6, Table A4) depends on the §III.B degradation map: a(t) linearly reduces p_i, F_i, T2,i and increases τ_i through constants η_p, η_F, η_τ, η_T. The manuscript never reports these constants, the subset of affected links, the target threshold, or the IDS anomaly model that produces a_IDS(t); the Limitations section explicitly calls the model 'intentionally phenomenological' and 'not hardware-calibrated.' That makes the headline contrast (0.098±0.007 → 0.344±0.011) a function of unreported, unvalidated inputs. If the real η's are small, the attack-unaware collapse disappears; if the affected-link subset is chosen unfavorably, the gain is inflated. Separately, the attack-unaware controller is not merely 'without IDS': it is denied any replanning, even though the degradation would be observable in link-generation statistics and delivered fidelities. A network-aware controller that re-estimates p,F,τ,T2 from its own measurements—no cyber signal—might achieve the same mask switch and the same recovery. Without this baseline, the experiment has not shown that cyber-state awareness, rather than adaptation to observable network degradation, drives the result. Both defects are acknowledged in the text, but acknowledgment does not establish the magnitude or attribution of the claimed improvement.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents a CUDA-Q/SeQUeNCe co-simulation workflow for adaptive entanglement purification in linear quantum-repeater chains, with two linked studies. First, under stationary conditions, it compares no purification, threshold-adaptive, mean-field predictive, fixed, and a resource-penalized risk-aware predictive policy in three-link and eight-node chains; the headline stationary result is that the risk-aware policy achieves above-target delivery probability 0.362 ± 0.017 versus 0.311 ± 0.017 for fixed purification while using fewer purifications and lower latency (Table II and Fig. 3b). Second, it couples a CSE-CIC-IDS2018 benign-to-SSDP trace to a phenomenological degradation model that linearly reduces link generation probability, raw fidelity, and coherence time and increases attempt time as a function of attack severity (§III.B). During the SSDP attack period, the attack-unaware controller (which keeps the clean purification mask fixed) delivers above-target entanglement with probability 0.098 ± 0.007, while the IDS-aware controller—which replans masks from an IDS severity score—raises this to 0.344 ± 0.011, close to the oracle-aware value of 0.335 ± 0.011 (Fig. 6, Tables A3–A4). The mechanism is a switch to more purification-heavy masks such as 1111011 during the attack.","tokens_in":31466,"tokens_out":4408,"duration_ms":42866,"significance":"If the central claims are correct, the paper makes a useful conceptual contribution: it distinguishes raw entanglement delivery from fidelity-qualified delivery, treats purification as a resource-allocation problem, and demonstrates—within a simulator—that cyber-state information can change the purification action and improve a network-level quantum-service metric. The paper is transparent about the costs of its approach, reporting raw delivery, latency, purification count, and failure-stage statistics, and it uses Monte Carlo confidence intervals throughout. The exhaustive mask evaluation in the 8-node chain (128 masks) and the separation between the IDS signal and the oracle degradation signal for physical modeling are also strengths. However, the central cyber-aware result rests on an uncalibrated, unreported degradation model, and the absence of a no-IDS adaptive baseline prevents attribution of the improvement to cyber awareness rather than to generic adaptation to observable network degradation. The stationary result is better supported, though it relies on unspecified objective weights.","major_comments":[{"comment":"The entire IDS-aware result (Fig. 6, Tables A3–A4) is produced by the linear degradation map p_i(t)=p_i0(1−η_p a(t)), F_i(t)=F_i0−η_F a(t), τ_i(t)=τ_i0(1+η_τ a(t)), T_2,i(t)=T_2,i0(1−η_T a(t)). The constants η_p, η_F, η_τ, η_T, the subset of affected links, the baseline link parameters, and the target fidelity threshold F* are never reported. The manuscript itself calls the model 'intentionally phenomenological' and 'not hardware-calibrated' (Limitations). Because the headline improvement from 0.098 to 0.344 is entirely a function of these unreported inputs, the quantitative claim is not reproducible and its magnitude is unverifiable. The authors should report all parameter values and the affected-link subset, and provide a sensitivity analysis over the η constants. Without this, the attack-period result is an artifact of an unvalidated input rather than a demonstrated property of the co","section":"§III.B, Cyber-to-quantum degradation model"},{"comment":"The attack-unaware scenario fixes the mask at the clean value m_clean for the entire trace. This is not merely a controller 'without IDS'; it is also a controller without any replanning whatsoever. A network-aware controller that re-estimates p_i, F_i, τ_i, T_2,i from its own observed generation statistics, purification outcomes, and delivered fidelities would also adapt its purification mask without receiving any cyber signal. The paper does not compare against such a baseline. Therefore the experiment has not shown that cyber-state awareness, rather than adaptation to observable network degradation, drives the switch to masks such as 1111011 and the recovery in above-target delivery. Add a network-aware baseline that replans from measured link statistics alone; if it achieves a similar recovery, the claim that IDS awareness is the operative cause is unsupported.","section":"§IV.B, Attack-unaware baseline"},{"comment":"The risk-aware objective is J(m) = U_LCB(m) + α Û(m) + γ Ĝ(m) − λ_p m̄ − λ_τ L̂(m), where the evaluation metric in the stationary 8-node comparison is U, the above-target delivery probability. Thus the risk-aware policy is partly optimizing an estimate of the reported metric itself, with resource penalties. The improvement over fixed purification (0.362 vs 0.311) is therefore in part the optimizer doing its job on its own score. This is not circular in a fatal way, but the weights α, γ, λ_p, λ_τ are never reported, so the reader cannot determine how much of the difference comes from the fidelity-margin and resource terms versus direct maximization of U. Report the weights and include a sensitivity analysis over them; also report J(m) for the selected masks to clarify the mechanism.","section":"§III.A.c, Eqs. (6)–(7)"},{"comment":"Proposition 2 is a tautology: the mask that maximizes J over all masks is never worse than any baseline mask under the same J. The note accompanying it correctly warns that this does not guarantee separate-evaluation improvement, but the proposition is presented as a theoretical result. The meaningful evidence for the stationary claim is the separate Monte Carlo evaluation in Table II, not this proposition. Consider removing or reframing this proposition to avoid giving it the status of a substantive guarantee.","section":"Appendix B, Proposition 2"}],"minor_comments":[{"comment":"Typographical errors: 'provides a referencfor' should be 'reference for'; 'bign bins' and 'Tse benign bins' should be 'benign bins' and 'The benign bins'.","section":"§III.B, attack-period-only text"},{"comment":"The figure is labeled 'Schematic mask adaptation' but appears to present simulation output. Clarify whether it plots actual time-bin results or is an illustrative schematic.","section":"Fig. 8 caption"},{"comment":"The paper calls the workflow a 'CUDA-Q/SeQUeNCe co-simulation,' but CUDA-Q is used only to validate and cache primitive purification/swapping estimates, while the network dynamics are simulated in the event layer. This is a reasonable division of labor, but the term 'co-simulation' overstates the coupling; consider using 'CUDA-Q-validated event-layer simulation.'","section":"§III.A, CUDA-Q role"},{"comment":"The memory-decay formula is standard, but the exponentiation notation is garbled in some displays; ensure the equation renders as F(t)=1/4+(F(0)−1/4)exp(−t/T_2) (or equivalent).","section":"Eq. (2)"}],"recommendation":"major_revision","confidential_remarks":"The paper's core cyber-aware result is not reproducible as written because the degradation-model constants, affected-link subset, and objective weights are unreported, and the attack-unaware baseline is both cyber-blind and adaptation-blind. These are fixable within the manuscript's scope by adding parameter tables, sensitivity analysis, and a network-aware replanning baseline. The stationary 8-node result is cleaner and could be published separately if the cyber part cannot be strengthened. I recommend major revision rather than rejection because the central idea is sound and the missing elements are specific and addressable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The thing you should know about this paper is that it is a reasonable proof-of-principle simulation that links a classical intrusion-detection signal (CSE-CIC-IDS2018 SSDP) to adaptive purification-mask selection in a simulated quantum repeater chain. That specific coupling is new, and the design pattern — IDS scores as an input to a repeater controller that trades raw throughput for fidelity-qualified delivery — is worth paying attention to. The stationary 8-node result (risk-aware policy beats fixed purification while using fewer purifications) is also a sensible point in the rate-fidelity-resource tradeoff space.\n\nWhat the paper does well: it separates circuit-level primitive estimation (CUDA-Q kernels) from event-layer network simulation (SeQUeNCe-style), reports both raw and above-target delivery, gives transparent confidence intervals, and includes an oracle-aware controller as an upper reference. The Appendix B concentration bounds are standard but correct. The paper is also honest in its limitations section: it explicitly calls the cyber-to-quantum degradation model phenomenological and not hardware-calibrated.\n\nThe soft spots are significant, and they mostly concern the cyber-to-quantum part. The degradation map (a(t) linearly reduces p_i, F_i, T2,i and raises tau_i) depends on four constants eta_p, eta_F, eta_tau, eta_T that are never reported. Neither are the baseline link parameters, the target fidelity threshold, the objective weights alpha/gamma/lambda, or the IDS anomaly-detection model. That means the headline improvement (0.098 -> 0.344 above-target delivery during the attack period) cannot be reproduced or even sanity-checked from the text. The gain is a function of unstated inputs.\n\nSecond, and more serious for attribution: the attack-unaware baseline is denied any replanning at all. It simply keeps the clean-era mask. A network-layer controller that re-estimates link parameters from observed delivery/fidelity statistics — with no cyber signal — might reach the same mask switch. Without that no-IDS adaptive baseline, the paper has not actually shown that cyber-state awareness is the operative ingredient.\n\nThird, there is a concrete internal inconsistency: Table II lists the risk-aware 8-node above-target delivery as 0.362 ± 0.017, while Table A2 gives the same quantity as 0.362 ± 0.0068. The n is presumably identical; one of these half-widths is wrong. Minor, but it undermines trust in the numerically reported results elsewhere.\n\nNo code or data is shipped, and the 'hybrid quantum anomaly analysis' framing is not reflected in the experiments, which only use classical IDS-derived scores. The paper should be trimmed accordingly.\n\nWho is this for? Researchers working on quantum-network control and on cyber-physical aspects of the quantum internet. The paper is not a validated engineering result; it is a design-pattern proposal with a plausible but uncalibrated demonstration. I would give it a serious referee, because the direction matters and the architecture is coherent — but the referee should insist on full parameter disclosure, a no-IDS adaptive baseline, corrected error bars, and language that matches the proof-of-principle scope. If those changes come through, this could be a useful reference point.\n\nRecommendation: send to peer review, expect heavy revision.","headline":"A coherent proof-of-principle of IDS-driven purification control, but every quantitative input is withheld, so the headline numbers are currently unverifiable.","tokens_in":32027,"tokens_out":2911,"would_cite":false,"duration_ms":26696,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Bg","03.67.Hk"],"model":"deepseek-v4-flash","headline":"An intrusion-detection signal can steer quantum-repeater purification, raising above-target entanglement delivery from 0.098 to 0.344 during a simulated SSDP attack, nearly matching an oracle that knows the true attack rate.","keywords":["quantum repeater networks","adaptive entanglement purification","purification mask","intrusion detection","DDoS/SSDP attack","anomaly-aware control","fidelity-constrained delivery","Monte Carlo simulation"],"falsifier":"Set the cyber-to-quantum degradation constants to zero—attack severity then leaves link parameters unchanged—and re-run the attack period; the IDS-aware and attack-unaware above-target delivery probabilities should coincide, and any recovery should disappear. Alternatively, induce a real DDoS on the classical control plane of a repeater testbed and measure whether generation probability and raw fidelity actually drop; if they do not, the cyber-to-quantum map is the artifact.","tokens_in":30847,"feed_emoji":"🛡️","tokens_out":7704,"duration_ms":71989,"temperature":0.7,"pith_summary":"Quantum-repeater networks need to decide when to purify each elementary link, and the paper's claim is that this decision should depend on the state of the classical control plane, not just on local link fidelities. The paper argues that an intrusion-detection anomaly score can be used as a control input: during a modeled SSDP attack, a controller that keeps its clean-condition purification mask delivers many pairs but mostly below the fidelity target (0.098 above-target), while an IDS-aware controller switches to more purification-heavy masks and reaches 0.344 above-target, statistically matching an oracle that knows the true attack rate (0.335). Under stationary conditions, the paper also argues that a resource-penalized risk-aware policy outperforms fixed purification in an eight-node chain (0.362 vs 0.311 above-target) using fewer purifications. A sympathetic reader would care because quantum networks depend on classical control; if the claim is right, cyber-state awareness can buy fidelity-qualified entanglement at the cost of raw throughput.","feed_headline":"Cyber-aware purification lifts useful entanglement delivery 3.5x","feed_subtitle":"Simulated SSDP attack: mask adaptation restores above-target entanglement delivery from 0.098 to 0.344","key_machinery":"The central object is the purification mask, a binary vector over the elementary links of the repeater chain that marks which links get purified. The controller selects the mask that maximizes a resource-penalized risk-aware score combining a lower-confidence-bound estimate of above-target delivery, delivered-fidelity margin, purification cost, and latency cost. The mask is the adaptive element: the attack-unaware controller keeps the clean-condition mask fixed, the IDS-aware controller recomputes it from a learned severity score, and the oracle-aware controller recomputes it from ground-truth attack rate, so the mask is what carries cyber-state information into the quantum-network control a","core_discovery":"The paper's central claim is that a repeater-chain controller which chooses its purification mask using a running cyber-anomaly score can recover most of the useful entanglement delivery lost when the classical control plane is degraded. In the coupled experiment, the physical links are degraded according to a ground-truth attack-rate signal while the deployable controller sees only a learned severity score; the claim is that the severity signal is enough to switch the controller to purification-heavy masks and raise above-target delivery from 0.098±0.007 to 0.344±0.011, statistically indistinguishable from the oracle-aware 0.335±0.011. The stationary companion claim is that a resource-penal","pith_inferences":["Beyond the paper: the same mask-adaptation mechanism should transfer to non-adversarial degradations—control-plane congestion, clock drift, or optical link weather—because the controller is only reacting to a time-varying link-quality signal; this makes the result a general principle for adaptive repeater control, not a DDoS-specific patch.","Beyond the paper: the near-oracle performance of the learned severity score suggests the controller may need only a coarse regime detector (attack vs benign) rather than precise severity; a hard-threshold trigger could be tested against the full IDS score.","Beyond the paper: the uncalibrated degradation constants are the point where a hardware testbed could falsify or calibrate the claim; measuring the four link parameters under a real control-plane outage would turn this proof-of-principle into an engineering prediction.","Beyond the paper: the observed tradeoff—raw delivery drops from 0.678 to 0.362 while above-target delivery rises—implies that service-level agreements for quantum networks should specify fidelity-qualified delivery, not pair count, or an attack-aware controller will look worse by the wrong metric."],"forward_implications":["If the central claim holds, a quantum-network operator can use existing intrusion-detection outputs as a control input without waiting for a direct quantum-side measurement of the attack; the learned severity score alone recovers most oracle-level useful delivery.","If the stationary claim holds, repeater controllers should not default to purifying every link; a resource-aware partial mask can beat fixed purification on above-target delivery while cutting purification count and latency.","If the attack-period claim holds, an attack-unaware controller gives a false sense of health: raw delivery stays high (0.678) while above-target delivery collapses (0.098), so monitoring only pair count misses the damage.","If the model holds, cyber-aware purification shifts the network operating point from high-throughput to fidelity-qualified delivery, making the resilience cost explicit: raw delivery drops and latency rises.","If the workflow itself is reusable, the same architecture can test other adaptive repeater policies under time-varying link conditions without simulating the full network as one quantum circuit."],"fun_headline_variants":["IDS-aware purification triples useful quantum entanglement delivery","Quantum network survives DDoS: adaptive purification boosts useful entanglement 3.5x","Cyber-aware masks recover quantum network's useful entanglement under attack","Adaptive purification defeats DDoS: useful entanglement delivery up 3.5x","Attack-aware controller revives quantum network's fidelity-qualified entanglement"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The load-bearing premise is the paper's assumed map from attack severity to link quality: as the DDoS signal rises, link-generation probability and raw fidelity drop, attempt time grows, and memory lifetime shortens, by amounts set by unstated constants; if a real control-plane attack does not degrade quantum links this way and by this size, the reported recovery is an artifact of that map.","fun_headline_variants_meta":{"raw":{"variants":["IDS-aware purification triples useful quantum entanglement delivery","Quantum network survives DDoS: adaptive purification boosts useful entanglement 3.5x","Cyber-aware masks recover quantum network's useful entanglement under attack","Adaptive purification defeats DDoS: useful entanglement delivery up 3.5x","Attack-aware controller revives quantum network's fidelity-qualified entanglement"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000693,"raw_usage":{"total_tokens":3017,"prompt_tokens":830,"completion_tokens":2187,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":574,"completion_tokens_details":{"reasoning_tokens":2106}},"tokens_in":574,"tokens_out":2187,"duration_ms":14292,"temperature":1.0,"reasoning_tokens":2106,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-02T08:00:53.074455+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Set the cyber-to-quantum degradation constants to zero—attack severity then leaves link parameters unchanged—and re-run the attack period; the IDS-aware and attack-unaware above-target delivery probabilities should coincide, and any recovery should disappear. Alternatively, induce a real DDoS on the classical control plane of a repeater testbed and measure whether generation probability and raw fidelity actually drop; if they do not, the cyber-to-quantum map is the artifact.","supporting_citations":[],"review_version":1}