{"id":"e63ad817-96d8-46ce-aff4-8dc4063950c9","arxiv_id":"2608.13561","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":1,"one_line_summary":"A photonic quantum SWITCH detects eavesdropping in a BB84-like protocol via control-qubit measurements, with average detection probability 0.15 +/- 0.02 per qubit and no key-bit disclosure, as a proof of principle.","lead":"Researchers embedded Alice and Bob's quantum operations in a photonic quantum SWITCH, superposing the order of their operations, and showed that an eavesdropper's disturbance appears in a control qubit rather than in the key bits. This proof-of-principle experiment demonstrates a BB84-like QKD scheme that detects eavesdropping without publicly sacrificing key material, though the current implementation is not yet secure.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The no-key-sacrifice claim requires public control outcomes to be independent of the key for all single-location eavesdropping strategies; the paper demonstrates this only for the honest case and its specific polarizer attack, leaving the central advantage unproven for general attacks.","rationale":"The paper is an honest proof-of-principle: it clearly states that the implementation does not yet constitute a secure QKD protocol and that post-selection leaves a loophole. The experimental detection probability for the implemented polarizer attack matches theory, and the data/code availability statement supports reproducibility. However, the headline claim that eavesdropping can be detected without sacrificing key bits depends on the public control outcome being independent of the key. The paper only demonstrates this independence for the honest shared state (Eq. 14), and the specific intercept-resend attack implemented in the experiment; it does not prove it for general single-location Eve channels from the general eavesdropped state (Eq. 6). Since the control and target degrees of freedom are entangled in the presence of Eve, conditioning on the control outcome can in principle change the key statistics, which would mean that publicly revealing control outcomes leaks key information. This is the same broad area as the reader's weakest assumption, but it is a distinct failure mode: even an eavesdropper with no access to the control qubit and no coordinator could, through an arbitrary polarization channel, make the control outcome reveal key bits. The reader's verdict of CONDITIONAL already captures that the security/advantage claims are not fully established, so no verdict change is needed; the concern is best handled by an explicit analytical check of I(control : key) for generic attacks.","tokens_in":22977,"tokens_out":24377,"duration_ms":240149,"concrete_test":"Analytically compute the mutual information between the public control outcome and the key bit, I(control : key | basis), from Eq. (6)/Appendix A for a generic single-location Eve channel on the target polarization, e.g. a weak Z measurement with Kraus operators E0 = sqrt(1-eps)|H><H| + sqrt(eps)|V><V| and E1 = sqrt(eps)|H><H| + sqrt(1-eps)|V><V|, for all four BB84 states. If I>0 for any eps>0, public disclosure of control outcomes leaks key information and the no-key-sacrifice claim requires qualification; if I=0 for all such channels, the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central advantage over BB84 is that eavesdropping is detected from the control qubit without sacrificing key bits. This requires that the publicly disclosed control outcome never reveals key information. The paper establishes this for the honest state (Eq. 14) and implicitly for the implemented polarizer attack, but the general eavesdropped state in Eq. (6) is not a product of control and target: conditioning on control outcome |+> leaves the anticommutator terms, while |-> leaves the commutator terms, and these can yield different marginal distributions over Alice and Bob's key bits. For an arbitrary single-location Eve channel acting only on the target polarization, the control outcome can therefore be correlated with the key, so publicly disclosing it could leak key material. The paper does not prove the required independence, and its explicit restriction to a single Eve at one location (Sec. II.C) does not remove the need for such a proof. Thus the 'no disclosure of key material' / 'every retained qubit can be tested while remaining available for key generation' claim is unsupported for general attacks, which is load-bearing for the claimed cryptographic advantage.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an experimental proof-of-principle implementation of a BB84-like quantum key distribution (QKD) protocol in which Alice and Bob are embedded inside a photonic quantum SWITCH, so that their measurement-and-preparation operations act in a coherent superposition of causal orders. Eavesdropping is detected by monitoring the control (path) degree of freedom rather than by publicly comparing and discarding a subset of the key. The experiment uses a time-delocalized ancilla photon to let Bob read out the polarization locally without destroying the path coherence of the SWITCH. In the honest case the authors report a key-generation success probability of 96.4(4)% and a false-positive eavesdropper-detection probability of 3.3(2)%. For an emulated polarizer-based intercept-resend attack they measure an average detection probability of 0.15 ± 0.02, compared with the parameter-free theoretical prediction of 1/8, and they characterize the mutual information between Alice, Bob, and Eve, including a threshold attack strength t0 ≈ 0.83 at which Eve's information exceeds the Alice-Bob mutual information. The paper explicitly disclaims full security because of post-selection, but it claims a proof of principle that indefinite causal order can detect eavesdropping without sacrificing key bits.","tokens_in":23097,"tokens_out":27345,"duration_ms":255595,"significance":"If the central claim held in the advertised generality, this would be a valuable first experimental demonstration of an ICO-based cryptographic protocol, and the new in-SWITCH measurement technique is interesting in its own right. The measured detection probabilities and the analytical prediction p_detect = 1/8 match well, and the paper provides data and code availability that would allow independent verification of the experimental claims. However, the advertised advantage over BB84, namely that eavesdropping is detected without any disclosure of key material, is not established for the general single-location eavesdropper model that the paper itself introduces. That gap is load-bearing, because the protocol's principal claimed benefit is precisely that the control outcomes are publicly discussable without leaking key information. The experimental demonstration for a specific polarizer attack remains meaningful, but the general claim requires either a proof or a substantial qualification.","major_comments":[{"comment":"The claim that control outcomes are independent of the key and can be publicly disclosed without revealing key material is not proven for the general single-location eavesdropper model defined in Sec. II.C, and it is in fact false for channels allowed by that model. Equation (6) shows that the post-reconciliation state is not a product of control and target: after conditioning on the control outcome |−>_c, the target state is built from the generalized-commutator terms [P_b^(µ), E_k, P_{b'}^(µ)] ρ_s [ ... ]†, and the total probability of that outcome, Eq. (7), can depend on the prepared bit b. The honest-case state (14) and the polarizer-attack state (A6) do not establish bit-independence, and the stated restriction to a single eavesdropper still permits arbitrary channels {E_k}. A concrete counterexample is the amplitude-damping channel with Kraus operators E_0 = |0><0| + sqrt(1−γ)|1><1| and E_1 = sqrt(γ)|0><1| in the computational basis: for Alice's Z-basis bit 0 the Z-basis contribution to Eq. (7) vanishes, whereas for bit 1 it equals γ/8 before adding the Hadamard-basis terms, so the publicly announced control outcome is correlated with the key bit. Thus the abstract's assertion that the approach 'requires no disclosure of key material' does not hold for an adversary within the paper's own attack model. The authors should either prove the required key-independence for arbitrary single-location channels or explicitly restrict the no-key-sacrifice claim to the implemented projective (polarizer) attack and state that the general advantage over BB84 remains open.","section":"Sec. II.C and Sec. III.B (Eq. (6) and the paragraph on the role of control outcomes)"},{"comment":"The abstract and conclusions overstate the scope of what is demonstrated. The statement that 'every retained qubit can, in principle, be tested for eavesdropping while remaining available for key generation' is presented as a general advantage, but the detection mechanism is demonstrated only for a polarizer-based intercept-resend attack, and, as shown in the previous comment, the theoretical framework does not prove the required key-independence of the control outcomes for general single-location attacks. In addition, the conclusion describes the implemented Eve as 'a coherent measure-and-reprepare attack,' whereas Sec. IV.B states that the attack is emulated by combining two polarizer settings; this wording should be aligned with the experimental implementation. The authors should qualify the central claim as a proof of principle for the implemented projective-measurement attack and state explicitly that a general security analysis, including the question of whether control outcomes can be publicly disclosed without leaking key information, is left for future work.","section":"Abstract and Sec. V (Conclusions)"}],"minor_comments":[{"comment":"The sentence 'As shown in Ref. [41], such attacks cannot extract information about the key without inducing a nonzero population in the control state |−>_c' refers to the two-eavesdropper (Eve and Yves) attack; as written it could be misread as applying to the single-Eve restriction used in the rest of the paper. Please clarify which statement is inherited from Ref. [41] and which is established here.","section":"Sec. II.C, final paragraph"},{"comment":"The state on the right-hand side of Eq. (12) is not normalized; the authors should specify the success probability of the post-selected gate and the renormalization factor explicitly.","section":"Sec. III.A, Eq. (12)"},{"comment":"The correspondence between the causal-order branch labels ⟳ and ⟲ used in Eq. (11) and the port labels 1 and 2 used in the Bell states (13) should be defined explicitly, since the logical control states later rely on this mapping.","section":"Sec. III.A, Eqs. (11) and (13)"},{"comment":"The reported average detection probability 0.15 ± 0.02 should be accompanied by a precise statement of the averaging: over the four BB84 states, over Eve's two outcomes, and over which Eve angles in Fig. 4. The false-positive contribution of 0.033 ± 0.002 is mentioned later in the same section but should be tied to the quoted average explicitly.","section":"Sec. IV.B"},{"comment":"The interpolation model for a partial eavesdropping strength t should be stated as a modeling assumption in which Eve attacks a random fraction t of rounds independently, rather than as a security statement or a result of the protocol.","section":"Sec. IV.C, Eq. (27)"},{"comment":"The phrase 'a coherent measure-and-reprepare attack' should be replaced by wording consistent with Sec. IV.B, for example 'an emulated or simulated intercept-resend (polarizer) attack,' because the experiment combines two polarizer settings rather than implementing a true coherent measure-and-reprepare device.","section":"Sec. V, Conclusions"}],"recommendation":"major_revision","confidential_remarks":"The experimental data and the specific polarizer-attack analysis are convincing, and the availability of code and data is a clear strength. The main obstacle to publication is the gap between the general no-key-sacrifice claim in the abstract and the actually proven statements: Eq. (6) itself shows that control-target correlations can arise for arbitrary single-location channels, and a concrete amplitude-damping counterexample makes the overclaim concrete. The paper can likely be brought into publishable form by restricting the central claims to the implemented projective-measurement attack and moving the general security question to future work; if the authors instead wish to retain the general claim, a proof of key-independence of the control outcomes for arbitrary single-location channels is required. The heavy reliance on self-cited companion papers (Refs. [41,55]) for the protocol and the measurement scheme is acceptable, but the present manuscript should contain enough of the security-relevant argument to stand alone."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Bottom line: this is a solid experimental proof-of-principle and the first implementation of a QKD-style protocol in an indefinite causal order. The data are believable, the detection prediction is parameter-free, and the authors are honest about the post-selection loophole. The soft spot is the central claim that eavesdropping is detected without sacrificing key bits: for general single-location attacks that claim is not established, and the failure mode is a real one.\n\nWhat the paper does well. The experiment embeds Alice and Bob in a photonic quantum SWITCH and uses the control (path) qubit to detect Eve. The path-coherence-preserving measurement inside the switch, borrowed from the companion paper, is technically demanding and the results support it: 96.4% key success without Eve, 3.3% false positive, and measured Eve detection of 0.15±0.02 against a parameter-free theoretical 1/8. The mutual information analysis, threshold extraction, and the explicit statement that this is not secure QKD are all to the authors' credit. Data and code are deposited.\n\nWhere it is soft. The advertised advantage over BB84 is that no key material is sacrificed: control outcomes are public and supposedly independent of the key. The paper shows this for the honest case (Eq. 14) and for the implemented polarizer attack, but not for a general single-location Eve channel. In Eq. (6), after conditioning on the control outcome, the target state retains either anticommutator or commutator terms, and those can correlate the control outcome with Alice and Bob's polarization bits. If a real Eve can choose such a channel, the public control outcome leaks key material, and the no-sacrifice advantage evaporates. The attack model restriction in Sec. II.C does not remove the need for that proof. This is the load-bearing part of the claimed cryptographic advantage, not a cosmetic gap.\n\nA smaller point: the mutual-information curves are renormalized to the measured maximum; that is a fitted normalization, though it does not affect the detection claim.\n\nWho it is for: experimental quantum information, the quantum switch/ICO community, and QKD people interested in alternative parameter-estimation structures. It deserves a serious referee. I would send it to peer review and ask for a major revision: either prove the control-key independence for arbitrary single-location Eve channels, or explicitly downgrade the claim to a proof-of-principle for specific attacks.","headline":"A credible first experiment for ICO-based QKD, but the headline no-key-sacrifice advantage is not proven for general attacks because public control outcomes can leak key information.","tokens_in":23763,"tokens_out":3354,"would_cite":true,"duration_ms":35209,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims a photonic proof of principle that indefinite causal order lets Alice and Bob detect an eavesdropper through the control qubit without giving up any key bits.","keywords":["indefinite causal order","quantum SWITCH","quantum key distribution","BB84","eavesdropper detection","control qubit","photonic experiment","post-selection"],"falsifier":"Implement a fully coherent intercept-resend eavesdropper, using the same ancilla-based measurement as Bob rather than passive polarizers, inside the switch, and record the control-port statistics and Eve's guesses for all four BB84 states. The claim predicts an average detection probability of $1/8$ and maximal Eve information at a $22.5^\\circ$ measurement angle; if the control qubit shows no rise above the $0.033 \\pm 0.002$ false-positive rate while Eve still learns the key bits, the no-key-sacrifice detection claim collapses.","tokens_in":22693,"feed_emoji":"🔐","tokens_out":8526,"duration_ms":76605,"temperature":0.7,"pith_summary":"The paper reports a photonic implementation of a BB84-like quantum key distribution protocol in which Alice and Bob are embedded inside a quantum SWITCH, so the order of their operations is a quantum superposition. It claims that an eavesdropper acting inside the switch disturbs the interference between the two causal orders, leaving a detectable signature in the control qubit rather than in the key itself. The experiment measures an average eavesdropper detection probability of $0.15 \\pm 0.02$ per shared qubit, against a theoretical value of $1/8$, while the key-generation success probability reaches $0.964 \\pm 0.004$ when no eavesdropper is present. Because the current gates are post-selected linear-optical interactions, the authors describe the result as a proof of principle, not a secure QKD protocol; if the mechanism survives a deterministic implementation, it would remove the standard BB84 trade-off between testing for eavesdropping and keeping key material.","feed_headline":"Quantum switch detects eavesdropping without sacrificing key bits","feed_subtitle":"Control-qubit measurements expose Eve at 0.15 ± 0.02 per qubit while polarization key bits stay usable.","key_machinery":"The load-bearing object is the photonic quantum SWITCH: a two-path interferometer in which the photon's path is the control qubit that decides the order of Alice's preparation and Bob's measurement gate, while the photon's polarization is the target carrying the key. Bob's local readout is made possible by a time-delocalized ancilla photon, path-entangled with the system photon, that interacts through post-selected polarizing-beam-splitter gates; the ancilla's path recombination erases which-order information and preserves the superposition. The logical control state is read as a joint Bell measurement on the two photons' path degrees of freedom, with $|\\Phi^+\\rangle$ (correlated ports) signalling the honest case and $|\\Psi^+\\rangle$ (anti-correlated ports) signalling decoherence. The identity carrying the argument is $p_{\\mathrm{detect}|b,\\mu}(\\theta)=\\cos^2\\theta_{b,\\mu}\\,\\sin^2\\theta_{b,\\mu}$, which averages to $1/8$ over the four BB84 states and is independent of Eve's angle.","core_discovery":"Embedding Alice and Bob as the two operations inside the quantum SWITCH makes the honest protocol exactly correct: after basis reconciliation, the measurement projectors commute, and the output state factorizes as $\\omega_c \\otimes \\sum_{b,\\mu} P_b^{(\\mu)}\\rho_s P_b^{(\\mu)}$, so Alice and Bob share perfectly correlated bits while the control qubit stays in $|+\\rangle_c$. Eve's channel breaks this. In the reconciled subensemble the switched operation contains the generalized commutator $[P_b^{(\\mu)}, E_k, P_{b'}^{(\\mu)}]$, and every nonzero term transfers population into the orthogonal control state $|-\\rangle_c$ with probability $p_- = \\frac{1}{8}\\sum_{b,b',\\mu,k}\\operatorname{Tr}\\big[[P_b^{(\\mu)}, E_k, P_{b'}^{(\\mu)}]\\rho_s[P_b^{(\\mu)}, E_k, P_{b'}^{(\\mu)}]^\\dagger\\big]$. The experiment verifies this signature for an intercept-resend eavesdropper implemented by polarizers: for Alice's $|H\\rangle$ state and Eve measuring diagonally, the predicted detection probability is 25% and the measured value is $(27.6\\pm1.4)\\%$; averaging over all four BB84 states gives $0.15\\pm0.02$ versus the theoretical $1/8$. This is the first demonstration that eavesdropper detection can be carried by the causal-order degree of freedom rather than by sacrificed key bits.","pith_inferences":["The linear relation between attack strength and detection probability suggests the control signature could serve as a continuous intrusion monitor on retained key bits, estimating how large a fraction of signals Eve attacked without discarding any of them; the paper does not develop this monitoring application.","A secure version would need a proof against attacks that also touch the control qubit, since the passive-polarizer Eve in this experiment cannot access that degree of freedom; whether the no-key-sacrifice advantage survives general attacks is not settled by the reported data.","The protocol's two available eavesdropper locations invite a two-party coordinated-attack test: checking whether the control-qubit signature remains when Eve and a second eavesdropper act at both access points would probe the generalization the paper mentions but does not implement."],"forward_implications":["Eavesdropping can be monitored through the control qubit, so every reconciled qubit can in principle be both tested and retained for key generation, avoiding the BB84 requirement to discard the publicly compared fraction.","The average detection probability is linear in the attacked fraction, $p_{\\mathrm{detect}}=t/8$ for Eve's optimal fixed measurement, giving a quantitative relation between attack strength and the control signature.","Eve gains more information than Alice and Bob share only when she attacks more than about $82.84\\%$ of signals, at which point the accumulated detection probability is about $0.1036$; below that threshold the legitimate parties retain an information advantage.","The same protocol, with deterministic entangling gates replacing the post-selected linear-optical ones, could in principle become a QKD scheme with eavesdropper detection and no key sacrifice; the present experiment establishes the needed measurement technique."],"supporting_citations":[{"why":"Proposes the indefinite-causal-order QKD protocol whose control-qubit detection scheme this experiment implements.","marker":"[41]"},{"why":"Supplies the time-delocalized ancilla measurement that lets Bob read polarization inside the switch without destroying path coherence.","marker":"[55]"},{"why":"Defines the quantum SWITCH operation that places Alice's and Bob's operations in a superposition of causal orders.","marker":"[6]"},{"why":"Defines the BB84 prepare-and-measure scheme that is adapted and serves as the standard baseline with key-sacrificing detection.","marker":"[44]"},{"why":"Documents the ambiguity in heralding sequential post-selected gates that motivates pre-entangling the system and ancilla paths.","marker":"[73]"}],"fun_headline_variants":["Quantum switch detects Eve without spending key bits","Causal order exposes eavesdroppers, saves key material","Eavesdropper check rides control qubit, not key bits","Quantum switch: eavesdropping detection without key disclosure","First proof: causal-order QKD detects Eve with no key loss"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security reasoning assumes Eve acts only on the polarization target at a single location between Alice and Bob inside the quantum SWITCH, with no access to the control (path) degree of freedom and no second, coordinated eavesdropper at the other access point; the paper explicitly restricts its analysis to this single-Eve case.","fun_headline_variants_meta":{"raw":{"variants":["Quantum switch detects Eve without spending key bits","Causal order exposes eavesdroppers, saves key material","Eavesdropper check rides control qubit, not key bits","Quantum switch: eavesdropping detection without key disclosure","First proof: causal-order QKD detects Eve with no key loss"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000975,"raw_usage":{"total_tokens":4231,"prompt_tokens":1120,"completion_tokens":3111,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":736,"completion_tokens_details":{"reasoning_tokens":3030}},"tokens_in":736,"tokens_out":3111,"duration_ms":24566,"temperature":1.0,"reasoning_tokens":3030,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T04:10:31.210542+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Implement a fully coherent intercept-resend eavesdropper, using the same ancilla-based measurement as Bob rather than passive polarizers, inside the switch, and record the control-port statistics and Eve's guesses for all four BB84 states. The claim predicts an average detection probability of $1/8$ and maximal Eve information at a $22.5^\\circ$ measurement angle; if the control qubit shows no rise above the $0.033 \\pm 0.002$ false-positive rate while Eve still learns the key bits, the no-key-sacrifice detection claim collapses.","supporting_citations":[{"cited_title":"Spencer-Wood, Indefinite causal key distribution, J","cited_arxiv_id":null,"evidence_quote":"Proposes the indefinite-causal-order QKD protocol whose control-qubit detection scheme this experiment implements."},{"cited_title":"Time-Delocalized Local Measurements in an Indefinite Causal Order","cited_arxiv_id":"2604.11878","evidence_quote":"Supplies the time-delocalized ancilla measurement that lets Bob read polarization inside the switch without destroying path coherence."},{"cited_title":"Chiribella, G","cited_arxiv_id":null,"evidence_quote":"Defines the quantum SWITCH operation that places Alice's and Bob's operations in a superposition of causal orders."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the BB84 prepare-and-measure scheme that is adapted and serves as the standard baseline with key-sacrificing detection."}],"review_version":1}