{"id":"025e4566-2308-4952-8f5f-9b394f31b476","arxiv_id":"2608.09674","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"This paper proves finite-key BB84 security with leaky receivers, requiring only a fidelity bound on the leaked states, and gives a loss-tolerant penalty for post-measurement outcome leakage.","lead":"A new security proof for quantum key distribution accounts for receivers that leak information to an eavesdropper, either after a measurement or before the basis choice is made. The post-measurement case is shown to be nearly loss tolerant, with the secrecy penalty scaling with detected rounds instead of every transmitted signal.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Eq. (8) in the a priori leakage analysis omits the signal system C_u, so the derivation of Eq. (9) is not well-defined as printed.","rationale":"The main post-measurement leakage analysis leading to Eq. (7) is carefully assembled: the isometry in Eq. (3), the effective dephasing channel, the modified phase-error operator in Eq. (5), and the Azuma-based concentration step are internally coherent, and the loss-tolerant scaling follows. The reader's weakest-assumption concern about squashing models excluding double-click leakage is a genuine scope limitation and is explicitly acknowledged by the authors; it does not indicate an error within the stated model. The more load-bearing issue I find is in the a priori leakage scenario: Eq. (8) is the only step that connects the leaked basis-dependent state sigma^beta to the conditional states rho^Z and rho^X used in Eq. (9), and as printed it omits C_u, making the map ill-defined. The reader classified this as presentational, but because Eq. (9) and Eq. (11) depend directly on this step, I treat it as a correctness gap that must be closed by a corrected equation and re-derivation. Since the fix appears straightforward and the rest of the proof is plausible, the appropriate verdict remains CONDITIONAL, matching the reader's verdict.","tokens_in":18208,"tokens_out":35736,"duration_ms":309208,"concrete_test":"Rewrite Eq. (8) as rho^{beta,F}_{A_u B_u} = Tr_{E_u}[(I_{A_u} tensor U^u)(rho^{F}_{A_u C_u} tensor rho^{F}_{E_{u-1}L_{u-1}} tensor sigma^beta_{L'_u})(I_{A_u} tensor U^u)^dagger] with U^u: H_{E_{u-1}} tensor H_{L_{u-1}} tensor H_{L'_u} tensor H_{C_u} -> H_{E_u} tensor H_{B_u}. Then verify that the map sigma^beta -> rho^beta is a single fixed CPTP map, and re-derive the fidelity/data-processing step and Eq. (9). If the corrected equation reproduces Eq. (9), the typo is harmless; if any step fails, the a priori leakage bound is unproven.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The a priori basis-leakage bound, Eq. (11), rests on Eq. (8), which defines the conditional state rho^{beta,F_{u-1}}_{A_u B_u} after Eve's interaction. As printed, Eq. (8) has U^u acting on H_{E_{u-1}} tensor H_{L_{u-1}} tensor H_{L'_u}, with no signal system C_u in its domain, and the input state rho^{F_{u-1}}_{A_u E_{u-1} L_{u-1}} also omits C_u. In the entanglement-based protocol, Alice prepares |Phi^+>_{A_u C_u} and sends C_u to Bob, so Eve's attack must act on C_u in order to produce B_u. Without C_u, Eq. (8) cannot define rho^{beta}; consequently, the identification of rho^Z and rho^X as outputs of the same CPTP map acting on sigma^Z and sigma^X, which is needed for the data-processing bound F(rho^Z, rho^X) >= delta and for Eq. (9), is unsupported. This is more than a typographical inconvenience: the displayed map does not type-check. If the intended equation includes C_u in both the pre-interaction state and the domain of U^u, the argument likely goes through; as written, the first treatment of pre-measurement leakage lacks a well-defined state evolution.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"Prepare-and-measure BB84 with a receiver that leaks information about its measurement outcomes (post-measurement leakage) or about its basis choice (a priori leakage) is analyzed. The authors derive finite-key security bounds based on phase-error estimation. For post-measurement leakage, the phase-error penalty scales with the number of detected rounds, making the analysis loss tolerant. For a priori basis-choice leakage, the penalty scales with the number of transmitted rounds. The proof requires only a fidelity bound between the relevant leakage states and is modular, with extensions to non-projective qubit measurements and to receivers with detection-efficiency mismatch.","tokens_in":18353,"tokens_out":29301,"duration_ms":234450,"significance":"If correct, this is a significant advance: previous analyses of detector leakage imposed a penalty per transmitted round, which is overly pessimistic in high-loss regimes. The loss-tolerant bound is both conceptually and practically important. The a priori basis-choice leakage analysis is, to my knowledge, new. The paper is clearly structured, the main derivation is easy to follow, and the numerical results illustrate the expected performance. The modular combination with existing detector-imperfection analyses (Appendix B) and the finite-size concentration bounds are strengths.","major_comments":[{"comment":"Equation (8) is not well-formed: the isometry Û_u is defined with domain H_{E_{u-1}} ⊗ H_{L_{u-1}} ⊗ H_{L'_u} and codomain H_{E_u} ⊗ H_{B_u}, and the input state is ρ^{F_{u-1}}_{A_uE_{u-1}L_{u-1}} ⊗ σ^{β_u}_{L'_u}. In the entanglement-based protocol Alice prepares |Φ+>_{A_u C_u} and sends C_u to Bob, so Eve's attack must act on C_u in order to produce B_u. As printed, the outgoing system B_u is not obtained from any incoming signal. The definition of ρ^{β_u,F_{u-1}}_{A_uB_u} is therefore undefined, and the subsequent identification of ρ^Z and ρ^X as outputs of the same CPTP map—which is needed for the fidelity bound F(ρ^Z, ρ^X) ≥ δ and for the derivation of Eq. (9)—is unsupported. This is more than a typographical issue; the map does not type-check. The authors should include C_u in both the domain of Û_u and the pre-interaction state (with A_u and C_u in the entangled state |Φ+>).","section":"A priori leakage of the basis choice, Eq. (8)"}],"minor_comments":[{"comment":"The text contains unresolved citation placeholders \"[?]\" in the paragraph beginning \"This type of strategy has previously been used to accommodate source imperfections\" ; these should be replaced with actual references.","section":"A priori leakage of the basis choice, after Eq. (9)"},{"comment":"Equation (8) is stated only for 1 < u ≤ N, leaving the initial round u=1 undefined; the definition of ρ^{F_0} should be provided for completeness.","section":"A priori leakage of the basis choice, Eq. (8)"},{"comment":"In the secret-key-rate formula, the symbol N_ph is used for the upper bound on the number of phase errors, but it should be distinguished from the actual phase-error count (e.g., N_ph^{UB}) to avoid notational confusion.","section":"Results"},{"comment":"The manuscript would benefit from a brief discussion of how the fidelity bounds in Eq. (2) and in the a priori-leakage section can be certified experimentally in a practical QKD implementation.","section":"Leakage model"}],"recommendation":"major_revision","confidential_remarks":"The a priori leakage section contains a missing signal system in Eq. (8), which is the main obstacle to acceptance; this is a load-bearing issue but appears readily fixable. The unresolved citation placeholders should also be resolved. The post-measurement leakage analysis appears sound and is a valuable contribution."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The headline is: the loss-tolerant bound for post-measurement receiver leakage is real, and the a priori basis-leakage treatment is new, but the manuscript is not camera-ready. Eq. (8) as printed drops the signal system from Eve's interaction, so the a priori derivation doesn't type-check until that's fixed.\n\nWhat's actually new: previous work (Marøy et al., Arqand et al.) penalizes every transmitted round for receiver leakage. Here they build an isometry that commutes with Bob's measurement, so the leakage can be moved before the measurement. In the virtual protocol, the Z-basis leakage acts as a dephasing channel with parameter gamma on the key rounds, giving the modified phase-error operator in Eq. (5). The resulting bound in Eq. (7) scales with N_det, not N_transmitted, so the penalty is loss-tolerant. That's a genuine step forward for practical QKD security proofs. The derivation from Eq. (3) to Eq. (7) is clean and the Azuma application is standard.\n\nThey also give the first treatment of a priori basis-choice leakage. That's plausible and uses a data-processing inequality from Ref. [39], but it rests on Eq. (8), which is not well-formed as written: U^u acts on H_E ⊗ H_L ⊗ H_L' and the input state is rho_{A_u E L}, with no C_u anywhere. In the entanglement-based protocol, Alice sends C_u and Eve must act on it to produce B_u. As printed, the map cannot define rho^beta_{A_u B_u}. The intended fix is obvious—include C_u in the domain and in the input state—but until then Eq. (9) is unsupported. This is a presentational error, not necessarily a deep flaw, but it is exactly the kind of thing a referee would flag.\n\nTwo smaller issues: footnote 38 still has placeholder [?] citations, which confirms this is a draft. And the squashing-model route excludes leakage that reveals finer-grained detection patterns such as double clicks; the authors state this explicitly, so it's a scope limitation, not a hidden one.\n\nOverall: the central post-measurement result is sound and useful. The a priori section looks likely correct but needs a fixed equation. This paper deserves a serious referee, and with a revised Eq. (8) and cleaned references it should be publishable. I'd cite the post-measurement loss-tolerant bound.","headline":"The loss-tolerant post-measurement leakage bound is real and useful, but the a priori basis-leakage section has a missing-system typo in Eq. (8) that needs fixing before the proof is relied upon.","tokens_in":19029,"tokens_out":2867,"would_cite":true,"duration_ms":33856,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A fidelity bound makes leaky QKD receivers loss-tolerant.","keywords":["quantum key distribution","receiver side channels","detector backflash","Trojan-horse attack","phase-error estimation","finite-key security","loss tolerance","BB84 protocol"],"falsifier":"A direct test would characterize Bob's receiver after a 0-bit and a 1-bit $Z$-basis detection and measure the fidelity $F(\\sigma^{(0,Z)}, \\sigma^{(1,Z)})$; if it is below the assumed $\\gamma^2$, or if the emitted light also depends on click multiplicity or on previous rounds beyond the gated window, Eq. (7)'s bound with that $\\gamma$ is not valid and the key rate could be overestimated.","tokens_in":17908,"feed_emoji":"🔐","tokens_out":8303,"duration_ms":74116,"temperature":0.7,"pith_summary":"The paper proves finite-key security for prepare-and-measure BB84 quantum key distribution when Bob's receiver leaks information, for example through detector backflash or back-reflected Trojan-horse light. Its main result is that post-measurement leakage of the recorded bit only adds a penalty proportional to the number of detected rounds, so the security analysis is loss tolerant: the tolerable leakage does not shrink as the channel becomes lossy. It also treats leakage of Bob's basis choice before the measurement, a scenario no earlier proof covered, and shows this case carries a per-transmitted-round penalty set by a fidelity parameter. The whole proof needs only a bound on the distinguishability of the two leaked bit states in the $Z$ basis, stated as a fidelity $\\gamma^2$.","feed_headline":"A fidelity bound makes leaky QKD receivers loss-tolerant","feed_subtitle":"Post-measurement leakage only penalizes detected rounds, so key rates survive channel loss.","key_machinery":"The load-bearing object is the leakage isometry $\\hat{R}^u_\\beta$ of Eq. (3): $|b_\\beta\\rangle \\mapsto |b_\\beta\\rangle |e_{b,\\beta}\\rangle$ and $|\\perp\\rangle \\mapsto |\\perp\\rangle |e_{\\perp,\\beta}\\rangle$, with the leaked system $L_u$ given to Eve. Because this isometry commutes with Bob's projective measurement, the actual protocol is statistically identical to one where leakage happens before measurement, and because the sifted key only comes from $Z$-basis detections, only the two $Z$-outcome leakage states matter. Tracing $L_u$ out of the isometry produces a dephasing channel $E_\\gamma(\\rho) = \\frac{1+\\gamma}{2}\\rho + \\frac{1-\\gamma}{2} Z\\rho Z$ on the detection subspace; applying it to Bob's $X$-basis projectors in the virtual protocol gives the effective phase-error operator of Eq. (5). The parameter $\\gamma$ is the only leakage quantity that has to be characterized, and it appears as an overlap, not a trace distance.","core_discovery":"The central discovery is that Bob's measurement and the receiver's leakage can be reordered without changing any observed statistics. The paper models the leakage by an isometry $\\hat{R}^u_\\beta$ that attaches a state $|e_{b,\\beta}\\rangle$ to the detected system before Bob measures it, and shows this commutes with an ideal qubit measurement. Tracing out the leaked system turns the virtual phase-error measurement into a dephased one: the effective phase-error operator is $\\gamma \\hat{E}_{\\mathrm{ph}}^{AB} + \\frac{1-\\gamma}{2}\\mathbb{1}_A\\otimes\\mathbb{1}_B^{\\det}$, where $\\gamma$ is the overlap of the two $Z$-basis leakage states. Summing the resulting conditional bound over detected rounds with Azuma's inequality gives $N_{\\mathrm{ph}} \\le \\gamma \\frac{p^A_Z p^B_Z}{p^A_X p^B_X} N_{x,\\mathrm{er}} + p^A_Z p^B_Z \\frac{1-\\gamma}{2} N_{\\det}$ plus finite-size fluctuation terms; the same logic with a fidelity parameter $\\delta$ between pre-measurement basis-leakage states yields the per-transmitted-round bound for a priori leakage. This makes the post-measurement penalty depend on detected rounds only, which is precisely the loss-tolerant behavior previous analyses lacked.","pith_inferences":["The same $E_\\gamma$ dephasing substitution should carry over to other prepare-and-measure and measurement-device-independent protocols whose security reduces to a phase-error estimate on detected rounds, although the paper only runs the BB84 numerics.","A practical certification procedure could measure only the overlap between the two $Z$-basis leaked states, for example by interferometric comparison of backflash or back-reflected light, rather than full tomography of all side-channel modes; the bound would then make detector-leakage testing a one-number check.","Because the a priori basis-leakage penalty depends on $\\delta$, increasing the basis-choice randomness or using basis-independent detection hardware should reduce the per-round cost; a testable prediction is that key-rate-versus-distance curves stay nearly flat in $\\gamma$ for all but near-orthogonal leakage states.","The double-click caveat suggests that receivers with squashing maps should be designed to randomize or hide double-click patterns from side channels; otherwise any leakage that resolves finer-grained detection patterns falls outside the proof."],"forward_implications":["If Eq. (7) holds, a receiver whose leaked bit states have fidelity at least $\\gamma^2$ adds only an additive, detection-count-scaled penalty to the phase-error budget, so the key rate stays useful over long distances where most rounds are lost.","For a priori basis leakage, Eq. (11) shows the penalty scales with transmitted rounds through $\\delta$, so Eve can exploit it with strategies such as unambiguous state discrimination; this quantifies why basis-setting leakage is more dangerous than outcome leakage.","The dephasing substitution extends to non-projective qubit POVMs and to asymmetric passive receivers with detection-efficiency mismatch, where it becomes $\\tilde{G}^{(1)}_{(X,\\neq)} \\mapsto E_\\gamma(\\tilde{G}^{(1)}_{(X,\\neq)})$ and the parameter substitution $\\delta \\mapsto \\delta_\\gamma$ in existing detector-imperfection proofs.","Correlated leakage over a finite window $L_c$ can be handled by gating detectors or by post-processing discards, and the active-round fraction $\\approx 1/(1+L_c p_{\\det})$ stays close to one when detection is rare, preserving loss tolerance.","The analysis is modular with source-imperfection and decoy-state proofs, so the same fidelity characterization can be reused in broader prepare-and-measure implementations."],"supporting_citations":[{"why":"Supplies the Azuma-Hoeffding inequality that converts sums of conditional phase-error probabilities into the high-probability bound in Eq. (7).","marker":"[35]"},{"why":"Provides the inequality bounding the phase-error probability in terms of the X-basis error probability when a priori basis leakage makes the Z- and X-basis conditional states differ.","marker":"[39]"},{"why":"Supplies the detector-imperfection security analysis with parameter $\\delta$ into which the leakage result is plugged via the substitution $\\delta \\mapsto \\delta_\\gamma$.","marker":"[16]"},{"why":"Establishes the phase-error-estimation and virtual-protocol formalism on which the equivalence between actual and virtual protocols rests.","marker":"[34]"},{"why":"Gives the qubit squashing model that justifies the qutrit description of Bob's receiver in the squashing-model route.","marker":"[31]"},{"why":"Extends the squashing-model justification to active BB84 receivers with threshold detectors, supporting the qutrit description used in the proof.","marker":"[32]"},{"why":"Prior asymptotic analysis of detector leakage that penalizes every transmitted round; the present work's loss-tolerant scaling is defined against it.","marker":"[22]"}],"fun_headline_variants":["Leaky QKD receivers get a loss-tolerant security proof","Post-measurement leakage only costs detected rounds in QKD","New finite-key proof handles leaky QKD receivers","QKD leakage proof enables loss-tolerant key rates","Receiver leakage in QKD tamed by phase-error bound"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing assumption is that the receiver's side-channel emission depends on the physical detection event only through the recorded outcome $b'$ and basis $\\beta$, so it can be attached to the qutrit description by the isometry; if a real device leaks finer-grained information, such as whether a double click occurred, the phase-error bound does not apply.","fun_headline_variants_meta":{"raw":{"variants":["Leaky QKD receivers get a loss-tolerant security proof","Post-measurement leakage only costs detected rounds in QKD","New finite-key proof handles leaky QKD receivers","QKD leakage proof enables loss-tolerant key rates","Receiver leakage in QKD tamed by phase-error bound"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000278,"raw_usage":{"total_tokens":1648,"prompt_tokens":937,"completion_tokens":711,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":553,"completion_tokens_details":{"reasoning_tokens":632}},"tokens_in":553,"tokens_out":711,"duration_ms":6681,"temperature":1.0,"reasoning_tokens":632,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T12:55:07.771235+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A direct test would characterize Bob's receiver after a 0-bit and a 1-bit $Z$-basis detection and measure the fidelity $F(\\sigma^{(0,Z)}, \\sigma^{(1,Z)})$; if it is below the assumed $\\gamma^2$, or if the emitted light also depends on click multiplicity or on previous rounds beyond the gated window, Eq. (7)'s bound with that $\\gamma$ is not valid and the key rate could be overestimated.","supporting_citations":[{"cited_title":"Moroder, M","cited_arxiv_id":null,"evidence_quote":"Supplies the Azuma-Hoeffding inequality that converts sums of conditional phase-error probabilities into the high-probability bound in Eq. (7)."},{"cited_title":", nA indexes then A states|φ i⟩C , emitted with probabilityp i","cited_arxiv_id":null,"evidence_quote":"Provides the inequality bounding the phase-error probability in terms of the X-basis error probability when a priori basis leakage makes the Z- and X-basis conditional states differ."},{"cited_title":"Lydersen, C","cited_arxiv_id":null,"evidence_quote":"Supplies the detector-imperfection security analysis with parameter $\\delta$ into which the leakage result is plugged via the substitution $\\delta \\mapsto \\delta_\\gamma$."},{"cited_title":"Security of entanglement-based quantum key distribution with practical detectors","cited_arxiv_id":"0804.0891","evidence_quote":"Establishes the phase-error-estimation and virtual-protocol formalism on which the equivalence between actual and virtual protocols rests."},{"cited_title":"Hwang, Phys","cited_arxiv_id":null,"evidence_quote":"Gives the qubit squashing model that justifies the qutrit description of Bob's receiver in the squashing-model route."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Extends the squashing-model justification to active BB84 receivers with threshold detectors, supporting the qutrit description used in the proof."}],"review_version":1}