{"id":"106cf8d8-dadc-4de3-b4d6-d0e175060dc1","arxiv_id":"2607.28063","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A deterministic two-stage gain-switched laser QKD source masks active phase shifts with secret random relative phases, defeating Trojan-horse side channels without post-selection or perfect extinction ratios.","lead":"The paper proposes a two-stage laser source for quantum key distribution that hides Alice’s bit, basis, and intensity choices behind secret random phases, so Trojan-horse and other source side channels do not leak settings. If buildable, it would let standard decoy-state security proofs apply without the rate penalties of passive or modulator-free transmitters.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.5","headline":"RPM-outcome secrecy (A3) is the entire mask for THA resistance, yet no threat model shows it survives the channel access that (A4) already grants Eve on the PM.","rationale":"The reader correctly located the linchpin: the masking argument at the close of §II stands or falls with secrecy of r under (A2)–(A3) while (A4) gives Eve φ = r + s. I only sharpen the same point—the paper treats (A3) as a primitive parallel to ordinary laser phase randomization, but r is an operationally generated, electrically feed-forwarded classical value sitting next to a channel-exposed PM, and neither (A1)–(A5) nor the figures supply a leakage analysis for that subsystem. That is a genuine gap for a claim of intrinsic side-channel robustness, not a minor implementation detail.\n\nIt does not, however, make the construction incoherent or the proposal unpublishable. Under the stated assumptions the independence argument is information-theoretically sound; imperfections in interference or RPM precision degrade to ordinary state-preparation flaws already covered by the cited loss-tolerant proofs; and the design does avoid post-selection and intensity–setting correlations by construction. Missing key-rate numerics weaken the ‘substantially higher rates’ rhetoric but not the security logic. Hence the reader’s CONDITIONAL verdict with high confidence remains the right call—no upgrade to REJECT, no downgrade of the concern. UNCHANGED.","tokens_in":10719,"tokens_out":713,"duration_ms":73552,"concrete_test":"Fix a minimal THA model: Eve injects a coherent probe at the channel port and collects all returns through the Att/PM path, plus a pure-loss leak with transmittance η_L from the RPM optical path and feed-forward DAC. Compute I(s_b ; Eve) or the trace distance between the average emitted states for different s_b as a function of η_L. If either is nonzero for any η_L > 0 compatible with realistic packaging, (A3) must be replaced by an explicit isolation bound before the intrinsic-robustness claim holds.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central privacy claim (end of §II) is that Eve’s perfect knowledge of the applied drive φ = r + s (A4) is uninformative about Alice’s setting s, because the RPM outcome r is uniform and secret (A2–A3). That one-time-pad step is load-bearing: if r is even partially available to Eve, φ reveals s and the ‘intrinsically robust / no side-channel proof needed’ claim collapses.\n\n(A3) is not a standard device assumption on par with gain-switched phase randomization. It requires that a real-time, bright-pulse interferometric measurement and its feed-forward electronics—whose output is electrically added to the secret setting and written onto a modulator optically exposed to the channel—remain information-theoretically hidden from an adversary who is already granted full readout of that modulator. The manuscript never specifies the RPM implementation, never models back-reflections or electronic emanations from the RPM/DAC path, and never derives that the emitted states stay setting-independent once those paths have finite isolation. (A5) only protects ‘setting choices,’ not the auxiliary secret r. Without a quantitative isolation argument, optical privacy is assumed rather than shown.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript proposes a two-stage deterministic QKD source (an Intensity Package followed by a bit/basis encoding stage) that generates decoy-state BB84 signals while remaining optically private against side channels, including Trojan-horse attacks. Bright pulses from independent gain-switched lasers interfere after a relative-phase measurement (RPM) and a feed-forward phase shift of the form r+s, where r is the measured relative phase and s encodes intensity or bit/basis. Under Assumptions (A1)–(A5), Eve’s perfect knowledge of the applied drive (A4) is uninformative about s because r is uniform and secret (A2–A3); no unused optical signals enter the channel; and intensity is set independently of bit/basis. The authors conclude that simpler security proofs that ignore side channels and intensity–setting correlations apply directly and yield substantially higher key rates, and that the scheme is within reach of demonstrated interference and milliradian phase-control technology. An Appendix A single-laser variant is offered for higher visibility at the cost of a residual side channel from finite extinction.","tokens_in":10967,"tokens_out":1600,"duration_ms":36621,"significance":"If the optical-privacy argument holds under a realistic threat model, the work would be a meaningful contribution to implementation-secure QKD: it aims to remove the usual performance penalties of leaky-source analyses and of passive/modulator-free schemes (post-selection loss, finite extinction, intensity–setting correlations) while remaining compatible with prepare-and-measure and MDI decoy-state BB84. The construction is conceptually clean—masking active PM drives with secret laser relative phases—and the explicit separation of security-critical assumptions from mere state-preparation flaws is useful. The paper does not, however, supply machine-checked proofs, numerical key-rate comparisons, or a quantitative isolation model; significance therefore hinges on whether Assumption (A3) can be made credible against the same adversary granted full PM readout in (A4).","major_comments":[{"comment":"§II, Assumptions (A2)–(A4) and the optical-privacy paragraph closing §II: the central claim—that Eve’s perfect knowledge of the applied drive φ=r+s is statistically independent of Alice’s setting s—rests entirely on the secrecy of the RPM outcome r. (A4) already grants Eve complete optical access to the PM that writes φ, yet the manuscript never specifies the RPM implementation, never models back-reflections, electronic emanations, or timing correlations between the RPM/DAC path and the channel-exposed PM, and never derives a bound showing that finite isolation leaves the emitted states setting-independent. (A5) protects only ‘setting choices,’ not the auxiliary secret r. Without a concrete threat model or isolation argument for (A3), optical privacy is assumed rather than shown, and the claim that simpler side-channel-free proofs apply directly is not yet justified.","section":"§II, Assumptions (A2)–(A4); optical-privacy paragraph"},{"comment":"Abstract and §III claim that simpler security proofs ‘apply directly, yielding substantially higher key rates,’ but the manuscript contains no key-rate evaluation, no comparison against leaky-source analyses (e.g., the frameworks cited as [11–19]) or against passive/modulator-free schemes [26–33], and no finite-key or asymptotic rate formula under the stated assumptions. The performance advantage is therefore an unquantified assertion. A minimal calculation—even asymptotic rates under ideal interference versus a representative THA leakage model—is needed to substantiate ‘substantially higher.’","section":"Abstract; §III"},{"comment":"§II, Eqs. (1)–(3) and the surrounding text treat μ_out and ν_out as exactly determined by Alice’s controlled parameters, and the output as ‘exactly’ a decoy-state BB84 state. The same section acknowledges that imperfect interference visibility and limited RPM/feed-forward precision produce intensity fluctuations and state-preparation flaws. The manuscript should state explicitly how large those flaws may be before the ‘no side-channel, standard proof applies’ claim fails, and whether the loss-tolerant frameworks [34–36] still apply without additional characterization when RPM error is correlated with the drive Eve reads under (A4).","section":"§II, Eqs. (1)–(3)"},{"comment":"Appendix A: the single-laser variant reintroduces residual pulses that ‘constitute a side channel that must be removed,’ suppressed only with finite-extinction modulators—the very limitation the main scheme claims to avoid. The appendix should either quantify the residual leakage and show it can be absorbed into existing leaky-source proofs with acceptable rate loss, or clearly demarcate this variant as not supporting the ‘intrinsically robust / no side-channel proof needed’ claim of the main text.","section":"Appendix A"}],"minor_comments":[{"comment":"Fig. 1 caption lists ‘PM’ among the labeled elements and refers to applying r_12+s_I, but the figure schematic as described is easy to misread regarding where the PM sits relative to the final HBS. A clearer component label and signal-flow arrow for the feed-forward path would help.","section":"Fig. 1"},{"comment":"Notation switches between r_12 (Fig. 1) and r′_12 (Fig. 2) and between θ and ϕ for global phases without a single consolidated symbol table; a brief notation paragraph would reduce friction.","section":"§II"},{"comment":"The phrase ‘within reach of current technology’ cites interference and phase-control works [37–41], but does not discuss repetition-rate, loss, or stability figures relevant to GHz QKD. A short quantitative paragraph (visibility, phase noise, feed-forward latency) would make the feasibility claim more concrete.","section":"§I; §III"},{"comment":"Reference list contains several ‘Preprint arxiv:…’ entries dated 2026; ensure citation keys and availability are stable for the journal version.","section":"References"},{"comment":"Typos/style: ‘PRIV ACY’ in the §II heading; occasional spacing issues in math (e.g., ‘r 12’, ‘s I’); ‘Lab’ port in figures is unexplained in the main text beyond a brief remark.","section":"§II heading; Figs. 1–3"}],"recommendation":"major_revision","confidential_remarks":"The core masking idea is neat and, under the stated axioms, elementary; I do not see an internal contradiction. The load-bearing gap is really (A3) versus (A4): the paper grants Eve the PM readout that practical THA analyses worry about, then assumes the RPM secret that makes that readout useless. If the authors can add even a simple isolation/threat model for the RPM path—or weaken the claim from ‘intrinsically robust, standard proofs apply’ to ‘reduces the side-channel problem to RPM isolation, which is easier to engineer and characterize’—the paper becomes much stronger. I would not reject on novelty grounds; the two-stage IntP construction is a genuine design contribution. Fit for a serious quant-ph journal is appropriate if the major points are addressed."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The one thing worth knowing: they rearrange standard parts (GSLs, relative-phase measurement, feed-forward PMs) so that the drive on the active modulators is one-time-padded by a secret random relative phase. Under A1–A5, Eve’s perfect readout of the PM (A4) is independent of intensity and bit/basis, unused light never leaves the lab, and intensity is set separately from encoding. That is the actual contribution—not new devices, but a source that is deterministic, free of intensity–setting correlations, and meant to inherit ordinary decoy-state proofs without leaky-source machinery.\n\nWhat they do well is state the assumptions up front and keep the optical-privacy argument short and elementary (Eqs. 1–3 plus independence of r+s from s when r is uniform and secret). They are honest that imperfect interference and phase precision become state-preparation flaws, not new side channels, and the single-laser appendix correctly flags the residual extinction-ratio leak. Citations to passive/modulator-free and leaky-source work are on-point; self-cites are to prior frameworks this design is trying to sidestep.\n\nSoft spots, in proportion. The stress-test is right that A3 is the whole mask: secrecy of the RPM outcome while Eve already has channel access to the PM is not a standard laser assumption, and the paper never models back-reflections, electronic emanations, or finite isolation on the RPM/DAC path. A5 covers setting choices, not the auxiliary secret r. So “intrinsically robust / no side-channel proof needed” is conditional on an unvalidated secrecy claim, not demonstrated isolation. Second, “substantially higher key rates” is asserted with zero numerics and no end-to-end proof—only the qualitative claim that simpler proofs apply. Experimental hardness (two-laser interference, milliradian feed-forward at high rate) is acknowledged; that is fine for a proposal, but feasibility is still open.\n\nWho it is for: people building or proving practical decoy-state and MDI sources who care about THAs and correlation overhead. Not a theory breakthrough; a methods sketch that deserves a serious referee who will demand a threat model for the RPM path and at least illustrative rates. I would engage—send it to review, tighten A3 or quantify residual leakage, add rates—rather than dismiss it.","headline":"Clean architectural idea for masking active modulators against THAs; privacy holds under stated assumptions, but RPM secrecy is load-bearing and unmodeled, and the higher-rate claim is unquantified.","tokens_in":11630,"tokens_out":597,"would_cite":true,"duration_ms":17560,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"A deterministic QKD source masks active phase shifts with secret random phases so Trojan-horse attacks learn nothing about Alice’s settings.","keywords":["quantum key distribution","side-channel attacks","Trojan-horse attack","decoy-state BB84","phase-randomized coherent pulses","gain-switched lasers","measurement-device-independent QKD","source security"],"falsifier":"Build the two-stage source and check whether an eavesdropper who injects light and reads the modulator drive can still extract statistically significant information about Alice’s intensity or bit/basis choices beyond what ordinary state-preparation flaws allow; any residual correlation would falsify the optical-privacy claim.","tokens_in":11580,"feed_emoji":"🔐","tokens_out":989,"duration_ms":25286,"temperature":0.7,"pith_summary":"Practical quantum key distribution often fails not because the theory is wrong, but because real transmitters leak setting information through optical side channels, including Trojan-horse attacks in which an eavesdropper injects light and reads the reflections. This paper proposes a two-stage source that still uses active phase modulators, yet makes the drive values statistically independent of Alice’s intensity and bit/basis choices by masking them with secret random relative phases measured inside her lab. No pulse post-selection is required, unused optical signals are not sent into the channel, and intensity is encoded separately from bit and basis, so ordinary decoy-state security proofs apply directly and give higher key rates. Imperfections in interference or phase measurement only raise the error rate; they do not open new side channels. The authors argue the needed laser interference and milliradian phase control are already within demonstrated technology.","feed_headline":"QKD source hides settings so Trojan-horse attacks learn nothing","feed_subtitle":"Secret internal phases mask active modulators; ordinary security proofs then give higher key rates","key_machinery":"The two-stage source (Intensity Package plus relative-phase encoding stage): bright pulses from gain-switched lasers have their relative phase measured internally; a feed-forward modulator applies that secret relative phase plus Alice’s setting phase, so from Eve’s view the applied drive is independent of the setting while the output is an ordinary phase-randomized decoy-state BB84 double pulse.","core_discovery":"The paper claims a deterministic decoy-state BB84 (and MDI-QKD) source that is intrinsically robust against optical side channels, including Trojan-horse attacks: even if Eve perfectly learns the phase shifts applied by the modulators, those values remain independent of Alice’s settings because they are offset by secret random relative phases, no unused light enters the channel, and intensity is set independently of bit and basis—so simpler security proofs that ignore side channels and intensity–setting correlations apply and yield substantially higher key rates.","pith_inferences":["If the internal relative-phase measurement can be made both high-precision and electromagnetically well isolated at GHz rates, this architecture could become a default ‘side-channel-hardened’ transmitter module for metro QKD links without rewriting security proofs.","The same masking idea—encode settings only as offsets to a secret random phase measured on bright internal light—may extend to other active modulators (e.g., intensity or polarization) wherever Trojan-horse readout of the drive is the dominant leak.","Characterizing how much electronic or optical crosstalk between the relative-phase meter and the modulator would be needed to break independence gives a concrete engineering security budget that labs can measure."],"forward_implications":["Standard decoy-state BB84 and MDI-QKD security proofs that ignore source side channels and intensity–bit/basis correlations can be used without extra leakage terms, raising expected secret-key rates.","Imperfect two-laser interference and limited phase-measurement precision only increase bit error rate and intensity fluctuation; they do not enlarge the side-channel space or enable unambiguous state discrimination of the four BB84 states.","The source remains deterministic: no post-selection of pulses and no need for perfect extinction-ratio modulators to suppress unused light.","A single-laser appendix variant trades some residual side-channel leakage (from finite extinction of discarded pulses) for easier mode overlap when two-laser interference is impractical."],"fun_headline_variants":["QKD source masks modulators so Trojan-horse probes learn nothing","Secret phases make QKD source immune to optical side channels","Deterministic QKD source blocks side channels without post-selection","Side-channel-robust QKD source yields higher rates with simple proofs","QKD source hides settings via secret phases, no intensity correlations"],"cache_read_input_tokens":128,"weakest_assumption_plain":"The relative-phase measurement inside Alice’s lab must stay secret from Eve even while Eve is assumed to read the modulator drive perfectly; if she can learn or correlate that internal measurement, the masking fails.","fun_headline_variants_meta":{"raw":{"variants":["QKD source masks modulators so Trojan-horse probes learn nothing","Secret phases make QKD source immune to optical side channels","Deterministic QKD source blocks side channels without post-selection","Side-channel-robust QKD source yields higher rates with simple proofs","QKD source hides settings via secret phases, no intensity correlations"]},"model":"grok-4.5","effort":"low","cost_usd":0.004676,"raw_usage":{"total_tokens":1289,"prompt_tokens":710,"num_sources_used":0,"completion_tokens":70,"cost_in_usd_ticks":46764000,"prompt_tokens_details":{"text_tokens":710,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":509,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":710,"tokens_out":70,"duration_ms":10931,"temperature":1.0,"reasoning_tokens":509,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-31T18:59:38.443606+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Build the two-stage source and check whether an eavesdropper who injects light and reads the modulator drive can still extract statistically significant information about Alice’s intensity or bit/basis choices beyond what ordinary state-preparation flaws allow; any residual correlation would falsify the optical-privacy claim.","supporting_citations":[],"review_version":1}