{"id":"7666ac7a-6c4f-45d2-9d97-afbd480248fe","arxiv_id":"2607.28602","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Introduces Pauli Encodings, proves a universal cloning lower bound 1/2+1/(2*sqrt(K)), a 3/4 obstruction against pairwise-marginal arguments, and a level-3 NPA upper bound approximately 0.5556 for anticommuting keys.","lead":"This paper introduces Pauli Encodings, a family of one-bit quantum encryption schemes based on Pauli-string projectors, and proves both attack lower bounds and security upper bounds. It shows any such scheme with K keys admits a cloning attack winning at least 1/2 + 1/(2*sqrt(K)), and that pairwise-marginal arguments alone cannot prove unclonable-indistinguishable security.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Level-3 asymptotic upper bound rests on unverified seed-rank/interpolation pipeline; without certified exact block reduction the 0.555608131 value is numerical evidence, not a proven bound.","rationale":"The paper's rigorous core—Prop. 4.3, Prop. 4.2, Prop. 5.1, Prop. 5.2, Prop. 5.9—is sound; the eigenvalue argument in Prop. 4.3 in particular is valid and gives the universal lower bound. The single place where a false step would change the main advertised quantitative claim is the seed-rank/interpolation limit in Prop. 5.18 and Appendix A.5. Prop. A.4 assumes full column rank rather than proving it, and the large-K limit is delegated to code. If that assumption fails, the limiting SDP is not a valid relaxation and ω_3^∞ is not an upper bound. This is exactly the condition the reader flagged as weakest. Since the reader already issued a CONDITIONAL verdict requiring certification or re-labelling as numerical evidence, my analysis does not move the verdict; it reinforces the condition. Hence UNCHANGED.","tokens_in":34114,"tokens_out":5523,"duration_ms":56613,"concrete_test":"Independently reimplement Appendix A for t=3: for K=9,11,13,15,17, compute the multiplicities m^{(3)}_{λ,ε} by eq. (30) and verify in exact arithmetic that rank(V^{(K)}_{λ,ε}) equals m^{(3)}_{λ,ε} for every occurring (λ,ε); then evaluate the interpolated rational block coefficients at K=10,12,14,16 and compare with independent direct reduction. Finally solve the limiting level-3 SDP with rigorous interval/validated rounding and exhibit a dual certificate with value ≤ 0.555608131+10^{-8}. If all steps pass, Result 7 is certified; if any fails, the 0.5556 bound should be labeled numerical evidence only.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The transition from finite-K symmetry-reduced NPA SDPs to the asymptotic bound ω_3^∞=0.555608131 (Prop. 5.18, Appendix A) is the load-bearing step. A genuine upper bound requires (i) the projected seed matrices V^{(K)}_{λ,ε} of Prop. A.4 to have full column rank for all relevant K, (ii) exact rational-function interpolation of block coefficients to be certified at independent K values, and (iii) the coefficientwise limit to be a feasible PSD block. The paper assumes (i) in Prop. A.4, and delegates (ii)–(iii) to the accompanying code with only a described interpolation-and-check procedure, not a complete proof. If any block is missed or the seed convention changes rank at some K, the limiting SDP is not a valid relaxation of the MoE value. Then Result 7 gives no valid upper bound, and the only rigorous asymptotic bound in that direction remains 5/8. The lower-bound, no-go, and bounded-dimension results are unaffected; this is an incompleteness in the certificate for the advertised 0.5556 improvement.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper introduces Pauli Encodings, a class of one-bit quantum encryption schemes built from eigenspace projectors of Pauli strings, and analyzes their monogamy-of-entanglement (MoE) cloning-game security. The main results are: a universal lower bound P*_win(MoE) ≥ 1/2 + 1/(2√K) for every K-key Pauli Encoding (Prop. 4.3); a no-go result showing that pairwise guessing-marginal arguments cannot prove strong security, with optimal pairwise MoE value at least 3/4 (Prop. 4.2); an exact evaluation of the BB84 encoding value cos²(π/8) (Prop. 5.1); a bounded-local-dimension security bound (Prop. 5.2); strong indistinguishability security for several Pauli families (Prop. 5.9); a level-one optimality result for the anticommuting commutation pattern (Prop. 5.15); and an asymptotic level-three NPA upper bound of approximately 0.555608131 for the anticommuting protocol (Prop. 5.18, Sec. 5.4.3).","tokens_in":34433,"tokens_out":2710,"duration_ms":33561,"significance":"If the results as stated are fully established, the paper is a substantial contribution to the unclonable-encryption literature. The universal lower bound, the exact BB84 analysis, the 3/4 obstruction, and the bounded-dimension and indistinguishability results are concrete and mostly self-contained, with explicit attack constructions and, in several cases, exact algebraic derivations. The accompanying code is a clear asset. The headline asymptotic improvement over 5/8 for the anticommuting protocol, however, currently rests on a symmetry-reduction and interpolation pipeline whose certification is not fully proved in the manuscript. This gap does not affect the lower-bound, no-go, and bounded-dimension contributions, but it does affect the central advertised upper-bound result.","major_comments":[{"comment":"The claimed asymptotic upper bound ω_3^∞ ≈ 0.555608131 depends on three unproven premises: (i) the seed matrices V^{(K)}_{λ,ε} of Prop. A.4 have full column rank for all relevant K; (ii) the rational-function interpolation of block coefficients is certified at enough independent K values; (iii) the coefficientwise K→∞ limit is a feasible PSD block of the limiting SDP. The manuscript states that the code checks these conditions at selected K and interpolates, but it does not provide a proof or a machine-checkable certificate that the checks cover all coefficients and all K in the stable range. Without (i)–(iii), the limiting SDP is not a valid relaxation, so Result 7 does not rigorously imply any upper bound below 5/8. This is load-bearing for the advertised improvement.","section":"Prop. 5.18 and Appendix A.3–A.5"},{"comment":"Even if the limiting SDPs were rigorously derived, the reported values 0.579982991 and 0.555608131 are described as \"numerical optima of rigorously specified limiting SDPs.\" A numerical SDP optimum is not, by itself, a certified upper bound on the true SDP optimum unless validated with rigorous error bounds (e.g., interval arithmetic or exact rational rounding). The paper should either provide certified bounds or explicitly downgrade the 0.5556 claim from a theorem to numerical evidence.","section":"Sec. 5.4.3, Table of ω_t^(∞)"},{"comment":"The full-column-rank assumption on the projected seed matrix V^{(K)}_{λ,ε} is stated as an assumption ('assume that this matrix has full column rank'), not proved. The equivalence in Eq. (32) is valid only under that assumption. Since the later interpolation and limit steps use this equivalence for all occurring (λ,ε) and all K in the stable range, the assumption is not a harmless technicality. The authors should either prove the rank condition for the specific seed convention or provide a certificate that can be independently verified.","section":"Prop. A.4"}],"minor_comments":[{"comment":"The informal Result 7 states an asymptotic upper bound, but the body correctly notes that levels two and three are numerical. The abstract and introduction should consistently use 'numerical evidence' or 'upper bound modulo certified computation' rather than presenting 0.5556 as a proven value.","section":"Sec. 1.1.3 / Result 7"},{"comment":"The column 'Conjectured exact value' is appropriate, but the rows marked with '≈' and '≠' would benefit from a statement that these conjectures are not proven in the paper, to avoid any appearance that they are established results.","section":"Table 1"},{"comment":"The norm notation ‖∑_P P‖_op has a typographical glitch in the displayed equation (the norm bars render as four vertical strokes). This is purely cosmetic but should be fixed.","section":"Eq. (10)"},{"comment":"The discussion of level four is honest about the computational obstruction, but the sentence 'This computational obstruction is not evidence of a failure of the method' is speculative. It is fine as a remark, but it should be phrased as the authors' assessment rather than a mathematical claim.","section":"Sec. 5.4.4"}],"recommendation":"major_revision","confidential_remarks":"The paper has several solid, self-contained contributions (Prop. 4.3, Prop. 5.1, Prop. 5.2, Prop. 5.9, Prop. 5.15). The main risk is the asymptotic level-three bound: it is presented as a theorem but depends on an unproven seed-rank/interpolation pipeline. This is fixable in principle—by turning the numerical pipeline into a certified computation or by clearly marking the 0.5556 value as numerical evidence—so I do not recommend rejection. However, the advertised headline improvement over 5/8 is not yet a theorem as written, and the revision should make that status unambiguous."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear X,\n\nThe short version: this paper gives a clean framework for Pauli-based unclonable bit schemes and proves several real results, but its headline number — the asymptotic upper bound of 0.5556 for the anticommuting protocol — is not yet a proven upper bound. The symmetry-reduction pipeline that turns finite-K SDPs into a limiting SDP has gaps.\n\nWhat is actually new: the universal lower bound 1/2 + 1/(2√K) for any Pauli encoding is simple and elegant, and the 3/4 obstruction for pairwise MoE games is a useful warning about a natural relaxation. The exact BB84 value is not new (that is CLX26), but the self-contained proof is neat. The bounded-dimension security bound and strong indistinguishability results for several efficient families are solid and well derived.\n\nThe main soft spot is Section 5.4.3 and Appendix A. The asymptotic level-3 bound ω_3^∞ ≈ 0.5556 depends on (i) the projected seed matrices having full column rank, (ii) exact interpolation of rational-function entries being certified, and (iii) the coefficientwise limit being a feasible PSD block. The paper states these as part of the method but relies on the accompanying code rather than a complete proof. The appendix explicitly says 'assume that this matrix has full column rank' in Proposition A.4. So the advertised improvement over 5/8 is conditional: if the pipeline works, it is a genuine advance; if not, the rigorous asymptotic bound remains 5/8. The authors do label levels 2 and 3 as numerical, which is honest, but Result 7 still presents it as a theorem-like statement.\n\nThe other results are on firmer ground. Proposition 4.3, Proposition 4.2, Proposition 5.2, and the indistinguishability bounds in Proposition 5.9 check out. The anticommuting optimality at level one is also a clean observation.\n\nWho should read this: anyone working on unclonable encryption or monogamy games. The conceptual contribution — framing Pauli encodings and showing what a natural relaxation can and cannot do — is worth the time.\n\nMy recommendation: send it to peer review, but request that the authors either provide a fully rigorous derivation of the limiting SDP (including rank certification) or explicitly downgrade the 0.5556 claim to numerical evidence. As it stands, the paper is a good contribution with an unproven headline bound.","headline":"Solid framework and several clean results, but the headline 0.5556 bound is conditional on an unproven numerical pipeline.","tokens_in":34864,"tokens_out":2351,"would_cite":true,"duration_ms":25289,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P45","81P94","90C22"],"pacs":["03.67.Dd","03.67.-a"],"model":"deepseek-v4-flash","headline":"The paper proves that every Pauli Encoding with K keys has optimal monogamy-of-entanglement winning probability at least 1/2+1/(2√K), and obtains a ≈0.5556 asymptotic upper bound for the anticommuting scheme via a level-three relaxation.","keywords":["unclonable bit","Pauli encodings","monogamy-of-entanglement games","semidefinite programming hierarchy","quantum cryptography","no-cloning theorem","symmetry reduction"],"falsifier":"Compute the exact level-three semidefinite optimum for the anticommuting protocol at K=9: if it falls below 1/2+1/(2√9)=2/3, the universal lower bound of Proposition 4.3 would be false. Alternatively, find any Pauli Encoding with K keys whose optimal MoE winning probability is provably below 1/2+1/(2√K).","tokens_in":34045,"feed_emoji":"🔐","tokens_out":6958,"duration_ms":68243,"temperature":0.7,"pith_summary":"This paper asks a sharp version of the unclonable bit question: can a simple quantum encryption scheme keep a classical bit uncloneable once the key is revealed? It introduces Pauli Encodings, where the ciphertext is a normalized eigenspace projector of a Pauli string, and proves a universal lower bound on the optimal monogamy-of-entanglement winning probability: for K keys, at least 1/2 + 1/(2√K). It also shows that two natural attack-relaxation strategies cannot prove security: the BB84-style X/Z tensor-product encoding is exactly insecure, and any argument using only pairwise guessing marginals is blocked by a universal 3/4 obstruction. For the pairwise anticommuting encoding, the paper uses a symmetric level-three semidefinite relaxation to push the asymptotic winning-probability upper bound down to approximately 0.5556, substantially tightening the previously known 5/8. A sympathetic reader cares because these bounds map which simple quantum encodings could plausibly achieve the unclonable bit.","feed_headline":"Quantum cloning advantage can't beat 1/(2√K) for Pauli encodings","feed_subtitle":"Universal lower bound and a tightened 0.5556 upper bound sharpen the unclonable-bit map.","key_machinery":"The central object is the Pauli Encoding, a one-bit encryption scheme defined by POVMs A_{x|P} = (I + (-1)^x P)/2 for Pauli strings P. The load-bearing reduction rewrites the cloning game as a monogamy-of-entanglement game, so security bounds reduce to bounding the largest eigenvalue of the operator T_V = (1/K)Σ_P (P⊗V_P⊗I + P⊗I⊗V_P + I⊗V_P⊗V_P). The universal lower bound comes from the operator norm of the sum Σ_P P: for anticommuting strings the square is K I, giving exactly 1/2 + 1/(2√K). For the anticommuting upper bound, the paper exploits the S_K × C_2 symmetry of the protocol and a block decomposition of the invariant moment matrix into irreducible symmetry sectors, producing semidefi","core_discovery":"For any multiset K of non-identity Pauli strings, the Pauli Encoding encrypts bit x as ρ_{x|P} = (I + (-1)^x P)/2^n and the cloning game reduces to a monogamy-of-entanglement game. The paper proves that every such scheme has optimal MoE winning probability at least 1/2 + 1/(2√K), matching the conjectured optimum of the anticommuting family and therefore making that family optimal among Pauli Encodings at fixed K if the conjecture holds. It also proves a no-go result: for every correct binary encryption scheme, the pairwise MoE winning probability is at least 3/4, so pairwise marginal arguments cannot establish unclonable-indistinguishable security. The BB84 encoding, based on {X,Z}⊗n, has ex","pith_inferences":["A natural next test would be to push the symmetry-reduced level-four relaxation to a tractable form: the paper reports the exact level-four construction is currently too slow, so a practical level-four compression would either confirm the trend toward 1/2 or reveal a plateau.","The universal 3/4 obstruction suggests that any successful proof of unclonable-indistinguishable security must exploit correlations across both Bob and Charlie together, not just their pairwise overlaps; this could guide the design of new encryption schemes with built-in tripartite constraints.","The universal 1/(2√K) lower bound implies a trade-off: to push cloning advantage below ε, one needs K ~ 1/(4ε²) keys, so efficient schemes must rely on structured families with faster-decaying bounds rather than on simply increasing key count."],"forward_implications":["No Pauli Encoding with K keys can have a cloning advantage below 1/(2√K), and the anticommuting protocol attains this value for K up to 7 exactly and numerically beyond, so it is plausibly optimal among all Pauli Encodings at a fixed key count.","Pairwise marginal monogamy-of-entanglement relaxations cannot prove unclonable-indistinguishable security for any correct binary encryption scheme, because the pairwise winning probability is always at least 3/4; higher-level or genuinely tripartite constraints are necessary.","The BB84 (X/Z tensor-product) encoding has exact winning probability cos²(π/8), so it is neither weakly nor strongly unclonable-indistinguishable secure, while remaining strongly indistinguishable-secure — a concrete separation between the two notions.","The level-three relaxation for the anticommuting protocol yields an asymptotic upper bound of roughly 0.5556, tightening the previous 5/8 level-one bound and providing evidence toward the conjectured 1/2 limit.","Several efficient Pauli families achieve strong indistinguishability security, and a Frobenius-norm argument gives strong unclonable security against adversaries with local dimension bounded independently of n."],"fun_headline_variants":["Pauli Encodings hit universal cloning bound 1/2+1/(2√K)","Unclonable encryption: Pauli encodings enforce 1/(2√K) barrier","Pauli encodings: universal cloning bound and 3/4 obstruction","Tight unclonable-bit bounds: 1/(2√K) lower, 0.5556 upper","Pauli encodings hit 1/2+1/(2√K) MoE bound; no pairwise proof"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The 0.5556 upper bound depends on a computer-assisted symmetry-reduction and interpolation pipeline — full-rank stable seed matrices and certified coefficient-wise limits as K goes to infinity — that the paper delegates to its accompanying code rather than proving in full; the level-two and level-three values are numerical optima of rigorously specified semidefinite programs, and the paper itself notes the level-four extension is currently too slow to complete.","fun_headline_variants_meta":{"raw":{"variants":["Pauli Encodings hit universal cloning bound 1/2+1/(2√K)","Unclonable encryption: Pauli encodings enforce 1/(2√K) barrier","Pauli encodings: universal cloning bound and 3/4 obstruction","Tight unclonable-bit bounds: 1/(2√K) lower, 0.5556 upper","Pauli encodings hit 1/2+1/(2√K) MoE bound; no pairwise proof"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000915,"raw_usage":{"total_tokens":3815,"prompt_tokens":842,"completion_tokens":2973,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":586,"completion_tokens_details":{"reasoning_tokens":2845}},"tokens_in":586,"tokens_out":2973,"duration_ms":22665,"temperature":1.0,"reasoning_tokens":2845,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-03T01:36:37.165053+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the exact level-three semidefinite optimum for the anticommuting protocol at K=9: if it falls below 1/2+1/(2√9)=2/3, the universal lower bound of Proposition 4.3 would be false. Alternatively, find any Pauli Encoding with K keys whose optimal MoE winning probability is provably below 1/2+1/(2√K).","supporting_citations":[],"review_version":2}