{"id":"dcd75cfc-79f3-4c52-a616-e1d6890989b3","arxiv_id":"2608.05038","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A temporal-mode extension of the LM05 quantum protocol encodes symbols as bit flips on light pulses, but loss, errors, and the need to encrypt the ordering limit complete recovery to sub-kilometer distances.","lead":"This paper proposes a quantum communication method that encodes message symbols onto separate light pulses, then sends the order of the symbols over a classical channel. The authors show that under optimistic assumptions the scheme operates only over sub-kilometer distances, and they stress that the classical part must be encrypted, so it is not secure direct communication by itself.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The collective-attack bound (Eq. 18) relies on a data-processing step (I(P_M;E) ≤ I(X^N;E)) that requires the true symbol set to be a deterministic function of Alice's raw outcomes; at QBER q>0 this fails, so the non-vacuous regime of the paper's central security claim is not actually derived.","rationale":"I read the paper as making two central, explicitly scoped claims: an asymptotic collective-attack bound on Eve's information about the unordered symbol set (Eq. 18), and an idealized complete-recovery probability (Eq. 25) that the authors themselves label a theoretical upper bound assuming perfect loss identification and zero QBER. The paper is unusually transparent: it states that the protocol is not standalone QSDC, that the classical ordering must be encrypted, that coherent attacks and finite-key security are open, and that the optimistic loss bound has limited practical interest. Table XI reproduces Table V, so the published numerics are internally checkable; the genuine blemish is Eq. 27, whose displayed minus term and printed coefficient (0.4455) are mutually inconsistent, while the correct expansion of Eq. (26) gives coefficient 0.5+0.441·T² and d≈0.61 km — so the headline 0.6 km is right and the printed 0.4455 would imply ≈0.72 km. The Reader's weakest assumption (perfect loss identification) is the authors' own caveat, which is why it is the natural first place to look. On closer reading, though, it is less load-bearing than stated for the uniform-prior case: the rule 'trust clicks, guess uniformly on no-click' attains per-slot success ηT² + (1−ηT²)/2 whether or not Alice can classify the cause of a no-click, so Eq. (25) does not actually require the loss-identification oracle; the oracle matters for the non-uniform extension (Eq. 29) and for interpreting the formula as a bound on realistic performance. The load-bearing weakness I find instead is in the security derivation, which is the paper's positive contribution. The chain of Eqs. (15)–(17) applies the data-processing inequality to the true symbol set as a function of Alice's raw outcomes. At q=0 this is valid but vacuous; at q>0, where the bound has content, the function does not exist, and no protocol-specific argument bounding H(b^N|E) is given. Relatedly, the q in the EUR step is the complementary-basis error rate, which the symbol-set mode never measures. These are correctness risks in the proof, not merely missing extensions, and they are not among the disclosed limitations. Because the bound is plausibly true and reachable by a proper encoding-string argument, and because the paper's qualitative conclusions (sub-kilometer ranges, severe implementation limits) are robust, the conditional verdict stands. My concern reinforces the CONDITIONAL status rather than changing it, with the specific proof gap now identified for the authors to close.","tokens_in":14183,"tokens_out":43743,"duration_ms":479359,"concrete_test":"Independently re-derive Eqs. (15)–(17) with the encoding string b^N (the indicator vector of P_M, i.e., the slots where Bob applied iY) as the classical variable instead of X^N: check whether the block EUR H(X^N|E)+H(Z^N|B) ≥ N together with H(Z^N|B) ≤ N h(q) yields H(b^N|E) ≥ N − N h(q) without selecting zero-QBER samples or assuming b^N is a deterministic function of Alice's raw outcomes. If the chain requires perfect decoding, Eq. (18) is proven only at q=0 and the claimed q>0 bound is unestablished; if a valid b^N-based chain exists, the concern is fully resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's chief positive result is the asymptotic collective-attack bound I(P_M;E) ≤ min{H(P_M), N h(q)} (Eq. 18). Its derivation (Section IV, Eqs. 14–17) runs: block EUR H(X^N|E)+H(Z^N|B) ≥ N; 'the symbol set P_M is a function of X^N'; then data processing gives I(P_M;E) ≤ I(X^N;E) ≤ H(Z^N|B) ≤ N h(q). The load-bearing step is identifying the true message set with a deterministic function of Alice's raw outcomes X^N. At zero QBER this identification is legitimate, and the bound reduces to the trivial no-error/no-leakage statement. For q>0, X^N is only a noisy observation of the encoding indicator b^N (the slots where Bob actually applied iY); P_M = support(b^N) is not a function of X^N, the Markov chain P_M → X^N → E fails, and the data-processing inequality does not justify I(P_M;E) ≤ I(X^N;E). Eve's information about the true P_M can exceed her information about the noisy outcome string X^N (e.g., for b uniform, X = b⊕noise, E = b, I(b;E)=1 > I(X;E)=1−h(noise)). A valid proof would run the LM05 collective-attack argument directly on the encoding string b^N of the N-slot tensor product and only then data-process P_M = φ(b^N); the paper does not supply that argument. A second related gap: the q entering H(Z^N|B) ≤ N h(q) is the complementary-basis error rate, but the symbol-set protocol never measures in the conjugate basis, so the bound's parameter is not operationally estimated (the paper itself separates q_F and q_{G_i} in Eq. 11). Neither gap appears in the authors' disclosed limitations (coherent attacks, finite-key, practical loss identification), and both bear on the abstract's claim that the full-block EUR handles collective attacks. In contrast, the loss-identification caveat the Reader flags is explicitly disclosed and, for uniform per-slot priors, Eq. (25) holds without knowing which no-clicks were losses; that caveat bites mainly through non-uniform priors (Eq. 29) and dark counts.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a quantum-assisted classical communication protocol that encodes the symbols of a message onto distinct temporal modes by applying either the identity or the iY gate in each time slot, following the LM05 two-way scheme. Alice sends N photons, Bob applies iY in the slots corresponding to his message symbols, Alice measures in her preparation bases, and a classical permutation supplies the ordering information. The paper derives two main results: an asymptotic collective-attack bound on Eve's information about the unordered symbol set, I(P_M;E) ≤ min{H(P_M), N h(q)}, and a success-probability bound for complete symbol recovery under photon loss, P_success = (1/2 + ηT^2/2)^N, with a QBER extension. It also performs resource comparisons, analyzes practical limitations such as timing jitter, dead time, and synchronization, and repeatedly stresses that the protocol is not a standalone QSDC scheme and that the loss bound assumes perfect loss identification. The authors frame their security result as asymptotic and collective-attack only, with finite-key, coherent-attack, and practical loss-identification issues explicitly left open.","tokens_in":14622,"tokens_out":6213,"duration_ms":68774,"significance":"If the central security bound were established, the paper would contribute a useful analysis of a tensor-product extension of LM05, showing that collective attacks on the full N-photon block can be bounded via the block-wise entropic uncertainty relation, and that the achievable recovery distance is severely limited. The paper is commendably candid about its assumptions: it explicitly warns that the loss-analysis upper bound requires perfect loss identification, that the symbol-set mode is not standalone QSDC, and that composable security is not claimed. The numerical verification tables and the repeated acknowledgment of open problems are strengths. However, the main new security claim is not currently derived for the only nontrivial regime (nonzero QBER), and the operational meaning of the parameter q in the bound is not specified. The quantitative loss result, while clearly caveated, contains an algebraic inconsistency that affects the reported ranges. These issues place the central contributions in need of substantial repair before the paper can be accepted.","major_comments":[{"comment":"The derivation of the central bound I(P_M;E) ≤ N h(q) applies the data processing inequality as I(P_M;E) ≤ I(X^N;E), justified by the statement that 'the symbol set P_M is a function of X^N'. This is only true when Alice's raw outcomes X^N coincide with Bob's encoding string b^N. At nonzero QBER, X^N is a noisy observation of b^N, and P_M = support(b^N) is not a deterministic function of X^N. The Markov chain P_M → X^N → E therefore need not hold, and the inequality I(P_M;E) ≤ I(X^N;E) is unjustified; for example, with b uniform, X = b ⊕ noise, and E = b, one has I(b;E) = 1 > I(X;E) = 1 - h(noise). Since at q=0 the bound reduces to the trivial statement that Eve learns nothing, the claimed security result is not established in precisely the regime where it is non-vacuous. A valid proof would need to run the collective-attack argument on the encoding string b^N of the N-slot tensor product and then data-process P_M = φ(b^N), or otherwise prove that the noisy outcomes still permit the desired inequality.","section":"Section IV, Eqs. (14)-(18) and 'Security Proof Details'"},{"comment":"The parameter q entering H(Z^N|B) ≤ N h(q) is not operationally defined for the symbol-set mode. In the symbol-set protocol, Bob does not randomize between bases; he applies I or iY deterministically, and Alice measures in her preparation basis. The complementary-basis error rates q_{G_0} and q_{G_1} that appear in the LM05 key-rate formula (Eq. (11)) are never measured in this mode. The text says that 'Bob's basis information B allows Alice to estimate the error rate q in the complementary basis', but no such basis information exists in the symbol-set protocol. The paper needs to specify which empirical quantity is identified with q, how it is estimated from the actual protocol, and why the EUR bound can be evaluated with that quantity. Without this, Eq. (17) cannot be applied and the numerical statement that 'Eve learns at most about 4 bits' for N=53, q=0.01 is not supported.","section":"Section IV, Eq. (17) and 'Parameter Estimation for LM05'"},{"comment":"The algebra in Eq. (27) is inconsistent with Eq. (26). Eq. (26) gives p = ηT^2(1-q) + (1-ηT^2)/2 = 1/2 + ηT^2(1/2 - q). With η=0.9 and q=0.01, this is p = 0.5 + 0.441 T^2. Eq. (27), however, computes p = 1/2 + (1/2)ηT^2(1-q) - (1/2)ηT^2 = 1/2 - (η q /2) T^2, and then states p = 0.5 + 0.4455 T^2, which corresponds to neither expression. The reported 0.6 km distance for the q=0.01 case should be recalculated from a correct expression; the discrepancy may be numerically small, but the current presentation contains a genuine algebraic error in a central quantitative claim.","section":"Section VI, Eq. (27) and Range Calculation"}],"minor_comments":[{"comment":"There are two empty cross-references reading 'see Sec. ' in the protocol step list and in the key-consumption discussion; these need to point to the intended section.","section":"Protocol Description, Step 6 and Key Consumption"},{"comment":"There are frequent typographical artifacts such as 'F or', 'V ulnerabilities', 'P M ', and inconsistent italicization; a careful proofreading pass is needed.","section":"Throughout"},{"comment":"The symbol q is used both as the protocol efficiency factor (q=1/2) and, elsewhere, as the QBER. This dual use is confusing and should be resolved, for instance by denoting the efficiency factor as q_eff or μ.","section":"Eq. (11)"},{"comment":"The 'Maximum alphabet size' entries such as 6.7×10^20 for τ_s=500 ps are mathematical upper bounds that are not physically meaningful; the text notes this, but the table would be clearer if the practical limits from dead time and synchronization were quoted alongside.","section":"Table IX"},{"comment":"The statement 'Eve learns at most about 4 bits' should be prefaced by 'under the assumptions that the bound is valid', given that the bound itself is the subject of the major comments above.","section":"Section IV, 'What This Bound Establishes'"}],"recommendation":"major_revision","confidential_remarks":"The paper is refreshingly honest about its limitations and the non-standalone nature of the protocol, but the load-bearing security derivation has a genuine gap for the nonzero-QBER regime, and the loss-analysis range calculation contains an algebraic error. These are fixable in principle, but they require substantial reworking rather than minor editing. I would not recommend rejection, since the loss-bound part (under the stated ideal-loss-identification assumption) and the protocol analysis are sound and potentially useful; however, the central security claim needs to be either proven correctly or explicitly downgraded to a conjecture with the q>0 gap acknowledged."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: this is an honest, clearly scoped extension of LM05, but its headline security claim doesn't survive close reading. The loss-side observation is fine; the EUR-based collective-attack bound has an undisclosed gap.\n\nWhat's actually new: the tensor-product symbol-set protocol, and the observation that the complete-recovery probability under random guessing is (1/2 + ηT^2/2)^N rather than (ηT^2)^N. That's a small but correct point, and the authors are appropriately careful about its assumptions. The paper is also commendably candid: it repeatedly states that the protocol is not standalone QSDC, that the classical ordering needs encryption, and that finite-key/coherent-attack/practical-loss questions are open.\n\nThe soft spots. The main security result, I(P_M;E) ≤ min{H(P_M), N h(q)}, is derived by saying P_M is a function of X^N and then using data processing to get I(P_M;E) ≤ I(X^N;E). That step only works when QBER is zero, because with q>0, X^N is a noisy observation of the true encoding b^N, and P_M is a function of b^N, not of X^N. In that regime I(P_M;E) can exceed I(X^N;E) (a simple example: b uniform, X=b⊕noise, E=b). So the bound's non-vacuous regime, q>0, is exactly where the derivation fails. The authors don't flag this. A valid proof would run the EUR on the encoding string b^N and then data-process P_M = φ(b^N); that's not in the paper. This is a serious gap, not a cosmetic one.\n\nThere's also an arithmetic slip in Section VI: Eq. (27) simplifies to p(d)=0.5−0.0045T^2, not 0.5+0.4455T^2. The headline 0.6 km figure is actually consistent with the corrected formula, so it's a typo, but it should be fixed.\n\nOne point where I'd push back on the Reader: the 'perfect loss identification' caveat on Eq. (25) is overstated for the uniform-prior case. If dark counts are negligible and QBER is zero, a click tells Alice the encoding; a no-click gets the 50% guess. She doesn't need to know which no-clicks were losses. The caveat bites mainly for non-uniform priors and dark counts, as the authors themselves show in Eq. (29).\n\nBottom line: the paper is a reasonable contribution to the 'natural extension' literature, but the central security bound is not currently established. I'd send it to peer review, but with a clear request to repair the data-processing step (or restrict the claim to zero QBER). For a reader, the implementation survey and the honest security status table are useful; the protocol itself is far from practical, and the authors know it.","headline":"An honest, clearly scoped LM05 extension whose headline security bound has an undisclosed gap in the data-processing step, while the loss-side observation is correct.","tokens_in":15220,"tokens_out":7511,"would_cite":false,"duration_ms":76494,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P45"],"pacs":["03.67.Hk","03.67.Dd"],"model":"deepseek-v4-flash","headline":"A tensor product of LM05 gates encodes symbols into temporal slots, and the entropic uncertainty relation on the whole block bounds Eve's information about the symbol set.","keywords":["temporal-mode multiplexing","LM05 protocol","quantum secure direct communication","entropic uncertainty relation","collective attacks","photon loss","symbol-oriented communication","QKD-hybrid protocol"],"falsifier":"Run a calibrated loss experiment with $N=53$ temporal slots and threshold detectors: attenuate the return signal to a known transmittance $T$, give Alice a known symbol set to recover, and measure her per-slot success on events where no click occurred. If per-slot success on no-click events is statistically indistinguishable from 50%, the $(1/2 + \\eta T^2/2)^N$ bound is not an achievable rate; if it is below 50%, the perfect-loss-identification premise itself fails. The equivalent test for the security bound is to compare the measured mutual information between Eve's joint measurement and $P_M$ against $\\min\\{H(P_M), N h(q)\\}$ in an entanglement-based implementation.","tokens_in":13981,"feed_emoji":"🔐","tokens_out":9757,"duration_ms":101407,"temperature":0.7,"pith_summary":"The paper introduces a quantum-assisted classical communication protocol that encodes each symbol of a finite alphabet into one of $N$ temporal slots: Bob applies the LM05 gate $iY$ to the slots belonging to his message and identity to the rest, so the total operation is a tensor product of $N$ independent two-way operations. Because of that tensor-product structure, an eavesdropper can mount collective attacks across all $N$ slots, which the original LM05 security proof does not cover; the authors therefore analyze the security of the full $N$-photon block. Their main result is an asymptotic bound on Eve's information about the unordered symbol set, $I(P_M;E) \\leq \\min\\{H(P_M), N h(q)\\}$, obtained from the entropic uncertainty relation with quantum memory plus the data-processing inequality. The paper also derives a complete-recovery success probability under loss, $P_{\\mathrm{success}} = (1/2 + \\eta T^2/2)^N$, that credits the receiver with a 50% guessing chance on lost slots, and it stresses repeatedly that this is an upper bound requiring perfect loss identification. The value of the paper is in mapping the tensor-product threat model, the guessing correction, and the explicit statement that the protocol is a QKD-hybrid rather than a standalone QSDC scheme.","feed_headline":"Entropic bound caps what Eve learns about a quantum symbol set","feed_subtitle":"Collective attacks leak at most a few bits; loss caps 1-percent recovery below one kilometer.","key_machinery":"The central object is the tensor product of LM05 operations, $U_{\\mathrm{total}} = \\bigotimes_{i=1}^N U_i$ with $U_i \\in \\{I, iY\\}$, applied slot-by-slot to $N$ temporal qubits; LM05 is the two-way quantum protocol in which Bob encodes a bit by applying either identity or the $iY$ gate to a returned qubit. The argument that carries the security bound is the entropic uncertainty relation with quantum memory applied to the full $N$-photon block, together with the data-processing inequality applied to the map from measurement outcomes $X^N$ to the symbol set $P_M$. The loss analysis is carried by the per-slot survival probability $p = (1/2 + \\eta T^2/2)$, with the factor one-half representing Alice's optimal guess on a lost slot under uniformly random messages.","core_discovery":"On the paper's own terms, the central discovery is that the symbol-set transmission mode of a tensor-product LM05 protocol has a computable asymptotic security bound: applying the entropic uncertainty relation to the entire $N$-photon block gives $H(X^N|E)+H(Z^N|B) \\geq N$, and since the symbol set $P_M$ is a function of $X^N$, the data-processing inequality converts this into $I(P_M;E) \\leq \\min\\{H(P_M), N h(q)\\}$. For collective attacks, Eve's information about the unordered set of symbols is therefore bounded by the block QBER entropy; with $q \\approx 0.01$ and $N=53$ that is roughly four bits. The authors also claim that under loss, complete recovery cannot exceed $(1/2 + \\eta T^2/2)^N$, because a uniformly random encoding makes each lost slot guessable with probability one-half, and they compute the resulting 1% success distances as about 0.83 km at zero QBER and about 0.6 km at QBER 0.01 for $\\alpha=0.2$ dB/km and $\\eta=0.9$. The paper is explicit that these are theoretical bounds, not achievable rates, and that the protocol is not a standalone quantum secure direct communication scheme because the classical ordering must be encrypted.","pith_inferences":["A reader could extend the analysis by checking whether photon-number-resolving detectors plus time-of-arrival information recover part of the 50% guessing advantage; the paper lists these as mitigations but does not quantify their security.","The same full-block entropic-uncertainty argument would carry over to any two-way encoding whose total operation factorizes as a tensor product, making the collective-attack bound a general tool for multi-mode two-way communication.","Because the derived bound uses only the data-processing inequality, it is likely loose for the specific set-identification function; a direct analysis of the symbol-set map could give a tighter leakage expression and change the practical parameter range."],"forward_implications":["Under collective attacks, Eve's leakage about the unordered symbol set scales as $N h(q)$, independent of the message length $L$ and of the classical ordering information.","If the classical ordering is encrypted, compromising only the quantum channel or only the classical channel reveals either the symbol set or the ordering but not the full message.","Complete recovery of all $N$ symbols decays exponentially with block size, so for $N=53$ the 1% success distance is below one kilometer under optimistic assumptions.","The protocol's QKD mode inherits the LM05 key rate, while the symbol-set mode does not yet have a composable security proof; the reduction from coherent to collective attacks and the finite-key analysis remain open.","Adding redundancy improves recovery but enables state-tomography or unambiguous-state-discrimination attacks, so it cannot be used naively in symbol-set mode."],"supporting_citations":[{"why":"It defines the LM05 two-way primitive and supplies the parameter-estimation error rates used in the security bound.","marker":"[1]"},{"why":"It provides the entropic uncertainty relation with quantum memory whose $N$-block form yields the collective-attack bound.","marker":"[6]"},{"why":"It gives the Devetak-Winter formula used for the QKD-mode secret key rate.","marker":"[7]"},{"why":"It is the reduction from coherent to collective attacks that the paper identifies as the missing step for the symbol-set mode.","marker":"[9]"},{"why":"It sets the collective-attack threat model and security conventions that the new bound must address.","marker":"[10]"},{"why":"It provides the established QSDC baseline for the photon-count and loss-scaling comparison.","marker":"[13]"}],"fun_headline_variants":["Entropic bound caps Eve's info on quantum symbol set","Quantum symbol recovery capped at 0.8 km by loss","LM05 tensor protocol: Eve limited to few bits","Symbol-set bound: 1% success under 1 km","Collective attacks leak ≤ few bits in LM05"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole loss and range analysis depends on Alice being able to tell perfectly whether a missing click was a lost photon, a dead detector, or Bob's identity gate; with ordinary threshold detectors this distinction is impossible, and without it the 50% guessing correction and the reported sub-kilometer distances are not valid.","fun_headline_variants_meta":{"raw":{"variants":["Entropic bound caps Eve's info on quantum symbol set","Quantum symbol recovery capped at 0.8 km by loss","LM05 tensor protocol: Eve limited to few bits","Symbol-set bound: 1% success under 1 km","Collective attacks leak ≤ few bits in LM05"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000235,"raw_usage":{"total_tokens":1533,"prompt_tokens":1014,"completion_tokens":519,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":630,"completion_tokens_details":{"reasoning_tokens":438}},"tokens_in":630,"tokens_out":519,"duration_ms":6385,"temperature":1.0,"reasoning_tokens":438,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T10:48:41.130898+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run a calibrated loss experiment with $N=53$ temporal slots and threshold detectors: attenuate the return signal to a known transmittance $T$, give Alice a known symbol set to recover, and measure her per-slot success on events where no click occurred. If per-slot success on no-click events is statistically indistinguishable from 50%, the $(1/2 + \\eta T^2/2)^N$ bound is not an achievable rate; if it is below 50%, the perfect-loss-identification premise itself fails. The equivalent test for the security bound is to compare the measured mutual information between Eve's joint measurement and $P_M$ against $\\min\\{H(P_M), N h(q)\\}$ in an entanglement-based implementation.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"It gives the Devetak-Winter formula used for the QKD-mode secret key rate."},{"cited_title":", N, each in a random state from{|0⟩,|1⟩,|+⟩,|−⟩}, recording bases","cited_arxiv_id":null,"evidence_quote":"It defines the LM05 two-way primitive and supplies the parameter-estimation error rates used in the security bound."},{"cited_title":"The classical cost depends on what information Alice already knows about the multiplicities (see Sec","cited_arxiv_id":null,"evidence_quote":"It provides the entropic uncertainty relation with quantum memory whose $N$-block form yields the collective-attack bound."},{"cited_title":"The dramatic numerical ratios versus the naive model are therefore of limited practical interest","cited_arxiv_id":null,"evidence_quote":"It is the reduction from coherent to collective attacks that the paper identifies as the missing step for the symbol-set mode."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"It sets the collective-attack threat model and security conventions that the new bound must address."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"It provides the established QSDC baseline for the photon-count and loss-scaling comparison."}],"review_version":1}