{"id":"8e10c89f-81f5-4611-ace7-084385782687","arxiv_id":"2607.26486","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"Spatial shot noise of coherent states, measured with an EMCCD camera, is used to generate random bits at a sustained 7.5 Mbps without algorithmic extraction.","lead":"This paper builds a quantum random number generator that draws randomness from the spatial shot noise of laser light recorded on a camera chip, claiming a burst rate of 5.92 Gbps but a sustained 7.5 Mbps. It matters because it shows an EMCCD sensor can serve as a massively parallel entropy source, though the validation has several gaps.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"30 difference images from 6 frames are not independent; correlated entropy sources inflate the 5.92 Gbps extractor-free rate.","rationale":"The reader's weakest assumption—that the 30 pairwise frame-difference images are statistically independent—is precisely the load-bearing condition for the headline instantaneous bit rate. Every difference image is built from two of six frames, so each frame appears in multiple images, inducing correlations (Cov(D_ij, D_ik) = Var(F_i)). Thus the joint entropy of the 30 images cannot exceed the entropy of the six underlying frames. The paper's bit count (2.025×10^6 bits per acquisition) is the product of 30 images × 22,500 pixels × 3 bits, which implicitly assumes 30 independent sources. The min-entropy per bit and statistical test suites do not address cross-image dependencies; they only test the concatenated bitstream as a sequence, which can pass despite correlations. The proposed entropy-bound test would decisively show whether the source can support the claimed rate. Since the reader already flagged this and issued a CONDITIONAL verdict, our analysis does not change the verdict; it strengthens the same concern.","tokens_in":7814,"tokens_out":10875,"duration_ms":105292,"concrete_test":"Estimate the per-pixel differential entropy of a raw frame from the measured shot-noise variance (e.g., H = 0.5 log2(2πe σ^2), σ^2 = mean photon count for Poissonian shot noise). Compute the total entropy available per acquisition as 6 frames × 22500 pixels × H. If this bound is below 2.025×10^6 bits, the 30-image construction cannot yield extractor-free randomness at the claimed rate. Additionally, confirm by measuring the Pearson correlation between corresponding pixels of two difference images sharing a frame (e.g., D12 and D13): a nonzero correlation directly violates the independence assumption.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim of 5.92 Gbps extractor-free randomness assumes that the 30 pairwise frame-difference images generated from one 6-frame kinetic acquisition are independent entropy sources. Each raw frame is reused in multiple difference images (e.g., F1 appears in D12, D13, ..., D16), so the 30 images are deterministic functions of only six underlying frames. Consequently, their joint entropy is bounded by the entropy of the six frames, not 30 times the per-image entropy. For any common frame i, Cov(D_ij, D_ik) = Var(F_i) > 0, so the images are correlated. The paper sums 2.025×10^6 bits from 30 images (150×150 pixels × 3 LSBs) and divides by 342 µs to claim 5.92 Gbps, implicitly treating them as independent. The reported per-bit min-entropy (0.9966) and passing NIST/Diehard results do not test cross-image independence. Without an entropy accounting showing that six frames can support 2.025M bits, the extractor-free rate is overestimated.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports a quantum random number generator based on spatial intensity fluctuations of coherent states detected with an EMCCD camera in kinetic mode. Two balanced coherent pulses are imaged; frame subtraction removes the mean profile; the residual fluctuations are attributed to quantum shot noise. The authors define a noise ratio (NR), verify its invariance with binning, and report NR≈1 as evidence of Poissonian statistics. Random bits are obtained by taking the absolute value of each fluctuation image and extracting the three least significant bits per pixel. From a six-frame acquisition they form 30 pairwise frame-difference images, and from a 150×150 ROI per image they claim 2.025×10^6 raw bits, corresponding to 5.92 Gbps instantaneous rate without extractor. The bitstream passes NIST SP 800-22 and Diehard suites; min-entropy is reported as 0.9966 per bit. The sustained rate is stated as 7.5 Mbps due to serial readout.","tokens_in":8121,"tokens_out":2462,"duration_ms":27897,"significance":"If the claims hold, this is a notable contribution: it demonstrates a massively parallel, extractor-free QRNG based on spatial shot noise, with a high instantaneous bit rate from a relatively simple setup. The use of EMCCD kinetic-mode imaging to obtain many spatial entropy sources is an interesting direction, and the shot-noise analysis and statistical testing are in the right spirit. The paper also gives a projected 11.45 Gbps rate with full sensor illumination. The significance of the result, however, depends critically on the independence of the 30 difference images and on the soundness of the entropy accounting, because the headline 5.92 Gbps rate is obtained by summing bits from those images as if they were independent sources.","major_comments":[{"comment":"The noise ratio as defined in Eq. (4) does not equal 1 for independent Poisson fluctuations. If N_{L,n}, N_{L,n+1}, N_{R,n}, N_{R,n+1} are independent Poisson variables each with mean μ, the numerator has variance 4μ while the denominator ⟨N_L⟩+⟨N_R⟩ = 2μ, giving NR = 2. The paper instead reports NR≈1 as the Poissonian expectation (Fig. 2(c)). Either a factor of 1/2 is missing, the numerator is intended to be the variance of a single frame difference, or an unstated normalization is used. This needs clarification and correction; as written the central shot-noise validation is off by a factor of two.","section":"Eq. (4) and Fig. 2(c)"},{"comment":"The 5.92 Gbps rate assumes that the 30 pairwise frame-difference images produced from a single six-frame acquisition are independent entropy sources. They are not independent: each raw frame participates in five different difference images, so for common frame i, Cov(D_{ij}, D_{ik}) = Var(F_i) > 0. The joint entropy of the 30 difference images is bounded by the entropy of the six underlying frames, not 30 times the per-image entropy. The text sums 2.025×10^6 bits from 30 images and divides by 342 μs, implicitly treating them as independent. Neither the per-bit min-entropy nor the NIST/Diehard passes tests for cross-image independence. Provide an entropy accounting that shows how six frames can support 2.025×10^6 extractor-free bits, or reduce the rate claim accordingly.","section":"Random bit extraction (combinatorial frame subtraction)"},{"comment":"The choice of extracting three LSBs is made from the min-entropy curve computed on the same dataset (Fig. 3(a)), which introduces post-hoc selection bias; the reported 0.9966 per-bit min-entropy is not a prediction but a retroactive fit. More importantly, the claim that 'the absolute-value operation ... does not degrade entropy quality' is asserted without proof. For a symmetric fluctuation distribution, absolute value folds the distribution and can change the statistics of the lower-order bits. Since the extractor-free claim rests on the per-bit min-entropy of the processed (absolute-value, LSB) stream, this step must be justified analytically or with a clear empirical demonstration that a conservative min-entropy bound holds for the exact preprocessing used.","section":"Min-entropy and bit extraction depth"},{"comment":"The paper states that NIST tests were passed based on global p-values ≥ 0.0001 and reports only global p-values in Fig. 4(a). It does not report the proportion of passing sequences, which is a required NIST criterion, nor does it give the number of p-values per test. For a 400-sequence analysis, the minimum pass proportion is 0.9750; the manuscript should provide the proportion for each test. Without this, the claim of passing NIST SP 800-22 is not fully supported.","section":"Statistical validation (Sec. on NIST/Diehard)"}],"minor_comments":[{"comment":"Typographical and grammatical issues: 'a extractor-free QRNG' should be 'an extractor-free QRNG'; 'quantum optical intensity fluctuations' is vague; 'the requirement for a highly radioactive source' could be more precise. The phrase 'large-scale stochastic simulations' is fine but the sentence about banking systems is somewhat informal.","section":"Abstract and Introduction"},{"comment":"In Fig. 2(c), error bars are described as 'standard deviation of the mean for the NR over 100 acquired images' but the text above says '100 acquired images' while later the analysis is scaled to 2,400 acquisitions. Please clarify the number of images used for each figure and whether the NR data are from the left, right, or both beams.","section":"Fig. 2 caption and Sec. on noise analysis"},{"comment":"The sustained rate is given as 'approximately 7.5 Mbps' based on a 270 ms readout period. Since 2.025×10^6 bits per acquisition divided by 0.27 s gives 7.5e6 bit/s, this is arithmetically consistent, but the text also says 'the digitization period is approximately 270 ms per acquisition cycle' while later referring to '342 μs acquisition time.' Please define which time interval corresponds to the instantaneous rate and which to the sustained rate.","section":"Sustained rate calculation"},{"comment":"Reference [11] is to Appl. Phys. Lett. 127, 104002 (2025) but the volume/issue may be incorrect; please verify. Also reference [38] duplicates the title of [37]; please check the intended citation.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The core idea—using spatial shot noise in an EMCCD as an entropy source—is plausible and interesting, but the headline rate depends on an independence assumption that is almost certainly false for the 30 combinatorial difference images. The factor-of-two issue in Eq. (4) also needs to be resolved before the Poissonian claim can be accepted. These are fixable in principle: the authors could present a conservative entropy bound for the six raw frames, reduce the per-acquisition bit count accordingly, or explicitly account for correlations. I recommend major revision rather than rejection because the experimental scheme appears sound and the problems are in the analysis and the rate claim, not in the fundamental detection principle. However, if the entropy accounting cannot be supplied, the extractor-free rate claim should be withdrawn."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: the experiment and idea are genuine, but the 5.92 Gbps \"extractor-free\" number is not supported; the paper needs a serious referee to get the entropy accounting right.\n\nWhat's new: spatial shot noise of coherent states recorded by EMCCD in kinetic mode, frame subtraction, and pairwise differences across all frames. That is genuinely absent from the cited QRNG literature, and the authors know the relevant spatial-noise characterization work. Credit where due: they do real detector calibration, background subtraction, a 29 dB SNR estimate, and the raw bitstream passes NIST and Diehard over 2,400 acquisitions. They also state plainly that sustained throughput is readout-limited at 7.5 Mbps and they do not oversell that.\n\nThe load-bearing flaw is the burst-rate calculation. Six raw frames contain a finite entropy budget. The 30 difference images—15 frame pairs times two beams—are deterministic functions of those six frames; pairs sharing a frame are correlated (e.g., Cov(D12,D13)=Var(F1)). Summing 2.025e6 bits from all 30 images and dividing by 342 µs implicitly treats them as independent. It does not matter that per-bit min-entropy is 0.9966 and NIST passes; those tests do not check cross-image independence. The instantaneous rate is therefore overstated until they supply an entropy accounting based on the six-frame joint distribution.\n\nSecond issue: Eq. (4) as written predicts NR=2 for independent Poisson statistics—double-difference variance 4μ over denominator 2μ—while the text reports NR≈1 as the Poissonian check. That factor of two needs explanation or correction; this is the main quantum-origin evidence.\n\nThird, smaller: the 3-LSB choice is post-hoc from the same dataset's min-entropy curve, and the correlation plots lack error bars. The stated limitations—cooling, serial readout, detector-noise characterization—are honest.\n\nOverall, the core concept is not circular, the experiment is real, and with a corrected rate and NR normalization this could be a useful contribution. Send to peer review, but require the independence/entropy accounting before the quantitative claims are accepted.","headline":"Camera-based QRNG idea is new and the experiment is real, but the 5.92 Gbps burst rate treats 30 correlated difference images as independent entropy sources.","tokens_in":8549,"tokens_out":3574,"would_cite":false,"duration_ms":36196,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.-a","42.50.-p"],"model":"deepseek-v4-flash","headline":"A camera's frame-subtracted spatial shot noise from a laser yields raw random bits at 5.92 Gbps, passing NIST and Diehard without algorithmic extraction.","keywords":["quantum random number generation","spatial shot noise","coherent states","EMCCD","extractor-free","NIST SP 800-22","Diehard tests","min-entropy"],"falsifier":"Compute the mutual information between two difference images that share a frame (for instance, F1−F2 and F1−F3). If the shared-frame mutual information is large relative to each image's min-entropy, the 30-pair summation overcounts independent entropy; likewise, rerunning the NIST and Diehard suites on the five consecutive differences only (F1−F2, ..., F5−F6) would reveal whether the extra pairs were masking correlations.","tokens_in":7728,"feed_emoji":"🎲","tokens_out":7236,"duration_ms":78933,"temperature":0.7,"pith_summary":"The paper sets out to show that the spatial intensity fluctuations of a coherent laser beam, measured as frame-to-frame differences on a camera, are quantum shot noise and can serve as a direct randomness source. It reports that the three least-significant bits of these fluctuation images pass both the NIST SP 800-22 and Diehard test suites, with a min-entropy of 0.9966 per bit, and that the instantaneous bit rate reaches 5.92 Gbps without any algorithmic randomness extraction. The sustained rate is limited to 7.5 Mbps by the camera's serial readout, but the entropy source itself is parallel and, the paper argues, scales with pixel count. If correct, this would be a simple, extractor-free path to high-speed quantum random number generation.","feed_headline":"Spatial laser shot noise yields 5.92 Gbps extractor-free random bits","feed_subtitle":"Two coherent beams on one camera chip yield raw bits that pass NIST and Diehard at 5.92 Gbps.","key_machinery":"The mechanism is the frame-subtraction of kinetic-mode EMCCD images of two equal-power coherent pulses: subtracting consecutive frames removes the classical beam profile and leaves δI(m,n), the spatial quantum fluctuation. Its quantum character is established by the noise ratio NR = Var(δI)/mean photon number ≈ 1, invariant under spatial binning, and by the absence of correlation peaks in cross- and auto-correlation maps. The bit extraction takes the three lowest-order bits of |δI|, relying on the variance of the shot-noise distribution being much larger than the digitization step, making those bits equiprobable.","core_discovery":"The central claim is that the spatial shot noise of coherent states, once static backgrounds are removed by subtracting consecutive EMCCD frames, is a spatially independent, Poissonian fluctuation field. Verified via spatial cross- and auto-correlation, a noise ratio that stays near unity under spatial binning, and a 29 dB shot-noise-to-background SNR, this field provides the entropy. Taking the three least-significant bits of the absolute fluctuation values yields a raw bitstream with min-entropy 0.9966 per bit that passes NIST SP 800-22 and Diehard without post-processing; the 30 frame-pair combinations from a single six-frame acquisition give 2.025e6 bits per capture, corresponding to 5.9","pith_inferences":["The paper's 5.92 Gbps figure hinges on treating all 30 pairwise frame differences as independent; a direct measurement of mutual information between differences sharing a frame (e.g., F1−F2 vs F1−F3) would test whether the effective independent entropy per acquisition is lower than 2.025e6 bits.","The three-LSB extraction depth was chosen from min-entropy measurements; a systematic scan of illumination power, exposure time, and binning would delimit the region where extractor-free operation survives, which the paper does not fully map.","The combinatorial frame-subtraction idea is not specific to EMCCDs; any low-noise array detector with kinetic or frame-straddling acquisition could apply the same 30-image trick, with the noise-ratio-invariance test as a quality gate.","The paper leaves the source-independent certification as future work; pairing its spatial-parallel scheme with a security proof would be the natural next step."],"forward_implications":["If the claim holds, spatial shot noise provides a random source that needs no algorithmic extractor, eliminating a traditional entropy bottleneck.","The instantaneous rate scales with pixel count and frame combinations: the paper projects 11.45 Gbps by illuminating the full 170x512 sensor region.","The sustained throughput is limited by the EMCCD readout electronics, not the quantum source, so faster low-noise readout would directly raise the continuous rate.","The method's spatial parallelism and positive statistical test results suggest it could be combined with source-independent QRNG security proofs.","The noise-ratio-versus-binning analysis provides a reusable diagnostic for verifying that detected fluctuations are shot-noise-limited and free of detector-induced correlations."],"fun_headline_variants":["Spatial quantum noise of light yields 5.92 Gbps random numbers","5.92 Gbps extractor-free random bits from laser shot noise","Camera chip reads laser quantum noise for 5.92 Gbps randomness","5.92 Gbps extractor-free random bits pass NIST and Diehard"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The load-bearing premise is that the 30 frame-difference images generated from one six-frame acquisition are statistically independent entropy sources, even though every image shares frames with others, so any shared-frame correlation would lower the true entropy below the claimed bit count.","fun_headline_variants_meta":{"raw":{"variants":["Spatial quantum noise of light yields 5.92 Gbps random numbers","5.92 Gbps extractor-free random bits from laser shot noise","Camera chip reads laser quantum noise for 5.92 Gbps randomness","5.92 Gbps extractor-free random bits pass NIST and Diehard"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000962,"raw_usage":{"total_tokens":3911,"prompt_tokens":697,"completion_tokens":3214,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":441,"completion_tokens_details":{"reasoning_tokens":3143}},"tokens_in":441,"tokens_out":3214,"duration_ms":104556,"temperature":1.0,"reasoning_tokens":3143,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-01T14:45:30.520640+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the mutual information between two difference images that share a frame (for instance, F1−F2 and F1−F3). If the shared-frame mutual information is large relative to each image's min-entropy, the 30-pair summation overcounts independent entropy; likewise, rerunning the NIST and Diehard suites on the five consecutive differences only (F1−F2, ..., F5−F6) would reveal whether the extra pairs were masking correlations.","supporting_citations":[],"review_version":1}