Pith. sign in

REVIEW 3 major objections 5 minor 35 references

Countermeasure against detector-blinding attack with estimation of secret-key leakage

T0 review · 3 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read Randomly switching the gate voltage of Bob's single-photon detectors makes a pulsed detector-blinding attack leave double- and error-click fingerprints, and those fingerprints reveal the fraction of key bits Eve controlled.

desk verdict A potentially useful experimental insight about pulsed detector blinding and gate-voltage randomization, undermined by an unexamined side-channel and sloppy statistics. read the letter →

arxiv 2505.12974 v2 pith:3EPMF53V submitted 2025-05-19 quant-ph

classification quant-ph
keywords quantumkeydistributiondetectorblindingattackpulsedsingle-photonavalanchediodegatevoltagerandomizationdouble-clickstatisticserror-clicksecret-keyleakageestimation
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that randomly switching the gate voltage of Bob's single-photon avalanche diode (SPAD) detectors turns the pulsed detector-blinding attack into a detectable, countable intrusion. Under pulsed blinding light, the maximum trigger-pulse energy that never clicks a detector at low gate exceeds the minimum that always clicks at high gate by so much that the no-fingerprint condition $2E_{\mathrm{high}}^{\mathrm{always}} \le E_{\mathrm{low}}^{\mathrm{never}}$ holds with a margin of at least 500; a pulse aimed at a low gate therefore double-clicks or error-clicks when the default gate is actually applied. The observed double- and error-click statistics feed closed-form estimators for the fraction of key bits Eve controlled, and numerical simulations suggest that over standard channel lengths Bob can keep most of the secret key rate even while under attack. The why-care is practical: this is a receiver-side, no-new-optics countermeasure for commercial SPAD-based QKD systems that does more than raise an alarm.

What carries the argument

The load-bearing object is the energy-gap condition $2E_{\mathrm{high}}^{\mathrm{always}} \le E_{\mathrm{low}}^{\mathrm{never}}$, together with the gate-voltage mechanism that produces it. Here $E_{\mathrm{high}}^{\mathrm{always}}$ is the minimum trigger energy that always clicks at the higher gate and $E_{\mathrm{low}}^{\mathrm{never}}$ the maximum trigger energy that never clicks at the lower gate. Because the blinded APD operates in a linear multiplication regime and the gate voltage changes the SPAD supply voltage by the full $\Delta V$ while a bias change is shunted by $R_{\mathrm{bias}}$, a small gate change creates a large threshold shift under pulsed blinding. The condition makes Eve's failure to guess Bob's gate level visible as double or error clicks, and those click counts are the input to the leakage estimators in Eqs. (5)-(8).

What would settle it

Give Eve a tap on Bob's blinding-light back-reflection or gate-switching timing and test whether she can classify the gate-voltage level before each trigger pulse; if she then imposes clicks at the normal rate with no excess double or error clicks, the assumption behind Eqs. (5)-(8) is false.

Watch

Extended reading notes

Core claim

On its own terms, the discovery is that pulsed blinding leaves a physical handle that CW blinding removes. When the SPAD is blinded, the photocurrent reduces the voltage across the quenching resistor and pushes the avalanche multiplication factor into its linear regime; lowering the gate voltage then lowers the APD supply voltage by the full $\Delta V$, whereas lowering the bias voltage mostly drops across $R_{\mathrm{bias}}$ and hardly changes the voltage across the APD itself. Measured on a commercial InGaAs/InP SPAD, this asymmetry makes the threshold gap under pulsed DBA large enough that $2E_{\mathrm{high}}^{\mathrm{always}} \le E_{\mathrm{low}}^{\mathrm{never}}$ holds. An Eve who sends a trigger pulse calibrated for the low gate inevitably produces double clicks on a two-SPAD receiver or error clicks on a one-SPAD receiver whenever Bob's actual gate is the high one; the fingerprint probability is $\alpha\beta/2$ and the successful-imposition probability is $(\alpha+\beta-\alpha\beta)/2$. From the observed double- and error-click counts, the legitimate users can therefore estimate, and then remove, the fraction of key bits Eve controlled.

Load-bearing premise

The leakage estimate assumes Eve never learns, in real time, which gate voltage Bob has set; if she can infer the gate level from optical back-reflection, timing, or blinding-light response, she can send matching trigger pulses and leave no fingerprints.

Editorial extensions

If this is right

  • Pulsed detector blinding no longer forces a full key abort: the legitimate users can estimate the fraction of bits Eve imposed and remove exactly those bits in privacy amplification.
  • The countermeasure requires no new optical components inside Bob; it uses gate-voltage randomization and the double- and error-click statistics already collected during the session.
  • For a typical two-SPAD receiver, the numerical simulation says Eve cannot take more than about a third of the key on a 100 km channel without the double-click statistics revealing her.
  • Continuous-wave blinding remains concealed from this method, so the scheme must operate alongside basic detector current monitoring.
  • One-SPAD receivers can apply the same error-click estimator, but they need much lower dark-count rates and better optical alignment to keep a comparable secure-key fraction.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural extension the paper leaves implicit is to use the same energy-gap measurement as a pre-deployment vulnerability check: if a detector's $E_{\mathrm{high}}^{\mathrm{always}}$ and $E_{\mathrm{low}}^{\mathrm{never}}$ do not satisfy the condition, the receiver is known to be open to pulsed DBA before any attack occurs.
  • The estimator treats every double or error click as Eve's fingerprint, which is conservative; on noisy channels, an adaptive baseline of ordinary double-click and error rates could raise the usable key rate with little added risk.
  • Because the gap shrinks as average blinding power rises, a plausible Eve could try to raise the blinding power to compress the gap; the paper's margin should therefore be checked at the maximum blinding power the SPAD can tolerate before permanent damage.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. Melkonian et al. present a countermeasure against the pulsed detector blinding attack (DBA) on QKD receivers, based on randomly switching the SPAD gate voltage between two levels. They experimentally measure a large gap, about 25 dB, between the trigger-pulse energies required to produce clicks under high and low gate voltages in the blinded state, satisfying condition (1). They then model the statistics of double- and error-click 'fingerprints' that arise when Eve guesses the wrong gate level, derive estimators for the fraction of key bits under Eve's control (Eqs. (5)-(8)), and simulate the resulting secure key fraction for one- and two-SPAD receivers.

Significance. The proposed countermeasure is attractive because it requires no extra optical components in Bob's receiver and, if the underlying assumptions hold, it not only detects DBA but also yields a quantitative estimate of the leaked key fraction. The paper provides a parameter-free relation between observed click anomalies and the attack parameters (alpha, beta), and the numerical simulation suggests that a substantial secure key rate can be maintained even under pulsed DBA. The main experimental quantity, the energy gap, is directly measured for a commercial SPAD. However, the security guarantee depends on the eavesdropper being unable to learn the instantaneous gate voltage, an assumption that is not analyzed.

major comments (3)
  1. [Appendix A, Eqs. (A1)-(A3) and Eq. (5)] The derivation of the double-click probability is algebraically inconsistent. Substituting the conditional probabilities (A1) into (A2) gives P_bld_double = alpha*beta/4, not alpha*beta/2 as claimed in (A3) and used in Eq. (5). The physical argument in Section V (that basis mismatch contributes a factor 1/2) accounts for the prefactor 1/2, so the additional 1/2 inside each term of (A2) is spurious. Because Eqs. (5)-(8) and the subsequent numerical simulations depend on this factor, the authors must correct the derivation and re-examine the resulting estimates.
  2. [Section V, security model] The countermeasure and the leakage estimator rely on the assumption that Eve can only guess Bob's gate-voltage setting (with probabilities alpha and beta) and cannot determine it in real time. However, Eve already sends bright light into Bob's receiver; optical back-reflection from Bob's input, the photocurrent through the SPAD, or the response to blinding pulses can be gate-voltage dependent and could reveal the applied level. The paper cites Trojan-horse attacks [2] and the breakable-unrealistic-assumption analysis of Huang et al. [29] but does not analyze this side channel. Without a quantitative bound on the information Eve can obtain about the gate level, the claim that DBA necessarily leaves fingerprints is not fully established. Please provide a side-channel analysis or explicitly state this assumption as a limitation.
  3. [Section IV, Figs. 4 and 5] The central experimental claim is that (Elow_never - Ehigh_always)/Ehigh_always >= 500, i.e., about 25 dB, satisfying condition (1). However, the reported measurements lack error bars, the number of repetitions, and a specific detector model or part number. Given that the entire countermeasure hinges on this margin, the authors should provide uncertainty estimates and reproducibility details.
minor comments (5)
  1. [Abstract vs. Introduction and Conclusions] The abstract states 'approximately 13 dB increase' while the introduction and conclusions state 'approximately 25 dB'. Please decide on the correct value and make it consistent throughout.
  2. [Table I] The formatting of Table I is garbled (e.g., 'Pdet * 10.1 6 .45 2 .35 6 .58 6 .45 6 .12'); please present the data in a standard table with clear column headers.
  3. [Section V, notation] The symbols Phigh and Plow are used both as probabilities for sending trigger pulses and as labels for high- and low-energy pulses. Please disambiguate, for example by writing P(E_low_gate) for the probability of sending the low-gate-appropriate pulse.
  4. [Section V, Eq. (10)] It would be helpful to state explicitly that the optimal alpha in (10) is obtained by maximizing (8) with Nexp_double and NAliceQEve treated as given, and to comment on the resulting beta at this optimum.
  5. [Section VI, numerical claim] In the conclusion, the statement that 'Eve cannot steal more than approximately one third of the distributed key' for a 100 km two-SPAD system should specify the simulation parameters (alpha, beta, eta2) used to obtain that number.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the measured trigger-energy gap and the statistical leakage estimator are self-contained and do not reduce to fitted inputs or a self-citation chain.

full rationale

The paper's central claim is experimental: it directly measures Ehigh_always and Elow_never under pulsed and CW detector blinding attacks for a commercial SPAD, and shows that for pulsed DBA the gap satisfies inequality (1), 2Ehigh_always <= Elow_never, by a large margin. This is a measured input, not a derived prediction fitted to a target conclusion. The leakage estimation in Sec. V and Appendices A and B uses the measured thresholds only through the conditional probabilities in Eq. (A1), which encode the experimental fact that a high-energy trigger pulse causes clicks at the high gate but not at the low gate. Equations (5)-(8) then algebraically relate the observed double-click count to the fraction of attacked bits; the only modeling assumptions are the stated attack probabilities (alpha, beta) and the conservative assumption that all double clicks are failed imposition attempts. The numerical simulations use typical QKD parameters (decoy-state probabilities, dark count rate, channel loss, misalignment) and do not fit free parameters to force the conclusion. The prior work [29] showing the CW-DBA vulnerability is an independent external experimental test, and the self-citations [13]-[15], [19] are contextual rather than load-bearing. The unexamined assumption that Eve cannot learn Bob's gate voltage in real time is a physical validity concern about the threat model, not a circularity: it does not make any equation equivalent to its own input. No specific reduction by construction, fitted-input-renamed-as-prediction, or load-bearing self-citation can be exhibited, so the honest finding is no significant circularity.

Assumptions & free parameters 3 free parameters · 5 assumptions · 0 invented entities

The central claim rests on the measured energy gap and on several modeling assumptions: the SPAD linear-mode model, Eve's inability to learn the gate voltage in real time, detector identity assumptions, and the treatment of double-clicks as attack fingerprints. The simulation parameters are standard QKD inputs, not fitted to force the conclusion.

free parameters (3)
  • Gate voltage levels (default strobe 3.95 V, low strobe 2.31-2.81 V) = 3.95 V default; 2.31, 2.65, 2.81 V low
    Chosen experimental settings that define Ehigh_always and Elow_never; the observed gap depends on these values.
  • Detection efficiency eta1 = 0.12 for high gate = 0.12
    Chosen for the numerical simulation in Section V, not measured on the tested detector.
  • Dark count rate Y0 = 1e-5 and misalignment 1-T = 0.01 = Y0 = 1e-5, 1-T = 0.01
    Typical QKD system parameters used only in the key-rate simulation, not in the experimental gap measurement.
assumptions (5)
  • domain assumption Blinded SPAD operates in linear mode where avalanche multiplication factor M varies with supply voltage according to the Cova model (Ref. [34]).
    Used in Section II to explain why gate-voltage changes shift trigger pulse energies more than bias-voltage changes; not validated on the specific detector in this paper.
  • ad hoc to paper Eve cannot determine Bob's instantaneous gate-voltage setting and can only guess it, with probabilities alpha and beta assigned.
    Stated in Section V before Eq. (5); if Eve could probe the gate level, the double-click fingerprints would disappear.
  • ad hoc to paper The two SPADs in a 2-detector QKD receiver are identical in their blinding and trigger-threshold response.
    Stated in Section V ('assuming the detectors are identical'); the experiment was performed on a single detector.
  • ad hoc to paper All observed double-click events during a session are Eve's failed imposition attempts, not normal detector behavior.
    Stated in Section V; the paper later models normal double-click gain (Eq. 14) but treats observed double-clicks as black-box inputs to the estimator.
  • standard math Standard decoy-state BB84 gain formulas (Eq. 9 and Eq. 13) from Ma et al. are assumed valid.
    Used in Section V for the numerical key-rate simulation without additional derivation.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Countermeasure against detector-blinding attack with estimation of secret-key leakage." pith.science (2026). https://pith.science/paper/3EPMF53V

@misc{pith2026250512974,
  author       = {Pith},
  title        = {Pith review of: Countermeasure against detector-blinding attack with estimation of secret-key leakage},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/3EPMF53V}},
  note         = {Machine review of arXiv:2505.12974}
}
read the original abstract

We present a countermeasure against the detector blinding attack (DBA) utilizing statistical analysis of error and double-click events accumulated during a quantum key distribution session under randomized modulation of single-photon avalanche diode (SPAD) detection probabilities via gate voltage manipulation. Building upon prior work demonstrating the ineffectiveness of this countermeasure against continuous-wave (CW) DBA, we extend the analysis to evaluate its performance against pulsed DBA. Our findings reveal an approximately 13 dB increase in the trigger pulse energies difference between default and reduced gate voltage applied under pulsed DBA conditions compared to CW DBA. This heightened difference enables a re-evaluation of the feasibility of utilizing SPAD detection probability variations as a countermeasure and makes it possible to estimate the fraction of bits compromised by an adversary during pulsed DBA.

Figures

Figures reproduced from arXiv: 2505.12974 by the authors.

Figure 1
Figure 1. FIG. 1. Considered passive-quenching SPAD’s circuit [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. Avalanche multiplication factor (M) versus APD’s [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3. Experimental setup [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figures from the paper (4 more)
Figure 4
Figure 4. Figure 4: FIG. 4. Detection probabilities versus trigger pulse energies under (a) 10 MHz pulsed blinding and (b) CW blinding [PITH_FULL_IMAGE:figures/full_fig_p006_4.png]
Figure 5
Figure 5. Figure 5: FIG. 5. Testing the condition for leaving ”fingerprints” under pulsed (for several blinding pulses repetition rates) and CW DBA. [PITH_FULL_IMAGE:figures/full_fig_p007_5.png]
Figure 6
Figure 6. Figure 6: FIG. 6. Secure bit fraction versus QKD channel length for [PITH_FULL_IMAGE:figures/full_fig_p008_6.png]
Figure 7
Figure 7. Figure 7: FIG. 7. Secure bit fraction versus QKD channel length for a [PITH_FULL_IMAGE:figures/full_fig_p010_7.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

35 extracted references · 28 canonical work pages

  1. [2]

    Gisin, S

    N. Gisin, S. Fasel, B. Kraus, H. Zbinden, and G. Ribordy, Trojan-horse attacks on quantum-key-distribution sys- tems, Physical Review A—Atomic, Molecular, and Opti- cal Physics 73, 022320 (2006)

  2. [29]

    Huang, S

    A. Huang, S. Sajeed, P. Chaiwongkhot, M. Soucarros, M. Legr´ e, and V. Makarov, Testing random-detector- efficiency countermeasure in a commercial system re- veals a breakable unrealistic assumption, IEEE Journal of Quantum Electronics 52, 1 (2016)

  3. [1]

    W. K. Wootters and W. H. Zurek, A single quantum cannot be cloned, Nature 299, 802 (1982)

  4. [3]

    A. N. Bugge, S. Sauge, A. M. M. Ghazali, J. Skaar, L. Lydersen, and V. Makarov, Laser damage helps the eavesdropper in quantum cryptography, Physical review letters 112, 070503 (2014)

  5. [4]

    S. V. Alferov, K. E. Bugai, and I. A. Pargachev, Study of the vulnerability of neutral optical filters used in quan- tum key distribution systems against laser damage at- tack, JETP Letters 116, 123 (2022)

  6. [5]

    Lydersen, C

    L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Hacking commercial quan- tum cryptography systems by tailored bright illumina- tion, Nature photonics 4, 686 (2010)

  7. [6]

    Sauge, L

    S. Sauge, L. Lydersen, A. Anisimov, J. Skaar, and V. Makarov, Controlling an actively-quenched single pho- ton detector with bright light, Optics Express 19, 23590 (2011)

  8. [7]

    Huang, ´A

    A. Huang, ´A. Navarrete, S.-H. Sun, P. Chaiwongkhot, M. Curty, and V. Makarov, Laser-seeding attack in quantum key distribution, Physical Review Applied 12, 064043 (2019)

Show all 35 references
  1. [8]

    Wiechers, L

    C. Wiechers, L. Lydersen, C. Wittmann, D. Elser, J. Skaar, C. Marquardt, V. Makarov, and G. Leuchs, After-gate attack on a quantum cryptosystem, New Jour- nal of Physics 13, 013043 (2011)

  2. [9]

    Makarov, A

    V. Makarov, A. Anisimov, and J. Skaar, Effects of de- tector efficiency mismatch on security of quantum cryp- tosystems, Physical Review A—Atomic, Molecular, and Optical Physics 74, 022313 (2006)

  3. [10]

    Qi, C.-H

    B. Qi, C.-H. F. Fung, H.-K. Lo, and X. Ma, Time-shift at- tack in practical quantum cryptosystems, arXiv preprint quant-ph/0512080 (2005)

  4. [11]

    Lydersen, M

    L. Lydersen, M. K. Akhlaghi, A. H. Majedi, J. Skaar, and V. Makarov, Controlling a superconducting nanowire single-photon detector using tailored bright illumination, New Journal of Physics 13, 113042 (2011)

  5. [12]

    Jouguet, S

    P. Jouguet, S. Kunz-Jacques, and E. Diamanti, Pre- venting calibration attacks on the local oscillator in continuous-variable quantum key distribution, Physical Review A—Atomic, Molecular, and Optical Physics 87, 062313 (2013)

  6. [13]

    S. A. Bogdanov, I. S. Sushchev, A. N. Klimov, K. E. Bugai, D. Bulavkin, and D. Dvoretsky, Influence of qkd apparatus parameters on the backflash attack, in Quan- tum Technologies 2022 , Vol. 12133 (SPIE, 2022) pp. 90– 95

  7. [14]

    I. S. Sushchev, D. S. Bulavkin, K. E. Bugai, A. S. Sidel- nikova, and D. A. Dvoretskiy, Trojan-horse attack on a real-world quantum key distribution system: Theoreti- cal and experimental security analysis, Physical Review Applied 22, 034032 (2024)

  8. [15]

    Bugai, I

    K. Bugai, I. Sushchev, D. Bulavkin, R. Y. Lokhmatov, and D. Dvoretskiy, Protection method against power- ful emission attacks based on optical-fiber fuse element, in 2024 International Conference Laser Optics (ICLO) (IEEE, 2024) pp. 446–446

  9. [16]

    Lovic, D

    V. Lovic, D. G. Marangon, P. Smith, R. I. Woodward, and A. J. Shields, Quantified effects of the laser-seeding attack in quantum key distribution, Physical Review Ap- plied 20, 044005 (2023)

  10. [17]

    Lydersen, C

    L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Thermal blinding of gated detectors in quantum cryptography, Optics express 18, 27938 (2010)

  11. [18]

    Makarov, Controlling passively quenched single pho- ton detectors by bright light, New Journal of Physics 11, 065003 (2009)

    V. Makarov, Controlling passively quenched single pho- ton detectors by bright light, New Journal of Physics 11, 065003 (2009)

  12. [19]

    Bulavkin, I

    D. Bulavkin, I. Sushchev, K. Bugai, S. Bogdanov, and D. Dvoretskiy, Study of a single-photon detector blind- ing attack with modulated bright light, in Quantum and Nonlinear Optics IX , Vol. 12323 (SPIE, 2023) pp. 73–78

  13. [20]

    Z. Wu, A. Huang, H. Chen, S.-H. Sun, J. Ding, X. Qiang, X. Fu, P. Xu, and J. Wu, Hacking single- photon avalanche detectors in quantum key distribution via pulse illumination, Optics Express 28, 25574 (2020)

  14. [21]

    Z. Yuan, J. Dynes, and A. Shields, Resilience of gated avalanche photodiodes against bright illumination at- tacks in quantum cryptography, Applied physics letters 98 (2011)

  15. [22]

    Chistiakov, A

    V. Chistiakov, A. Huang, V. Egorov, and V. Makarov, Controlling single-photon detector id210 with bright light, Optics express 27, 32253 (2019)

  16. [23]

    Qian, D.-Y

    Y.-J. Qian, D.-Y. He, S. Wang, W. Chen, Z.-Q. Yin, G.- C. Guo, and Z.-F. Han, Robust countermeasure against detector control attack in a practical quantum key dis- tribution system, Optica 6, 1178 (2019)

  17. [24]

    Z. Wu, A. Huang, X. Qiang, J. Ding, P. Xu, X. Fu, and J. Wu, Robust countermeasure against detector control attack in a practical quantum key distribution system: comment, Optica 7, 1391 (2020)

  18. [25]

    Acheva, K

    P. Acheva, K. Zaitsev, V. Zavodilenko, A. Losev, A. Huang, and V. Makarov, Automated verification of countermeasure against detector-control attack in quan- tum key distribution, EPJ Quantum Technology 10, 22 (2023)

  19. [26]

    Shen and C

    L. Shen and C. Kurtsiefer, Countering detector manip- ulation attacks in quantum communication through de- tector self-testing, APL Photonics 10 (2025)

  20. [27]

    C. C. W. Lim, N. Walenta, M. Legr´ e, N. Gisin, and H. Zbinden, Random variation of detector efficiency: A countermeasure against detector blinding attacks for quantum key distribution, IEEE Journal of Selected Top- ics in Quantum Electronics 21, 192 (2015)

  21. [28]

    Legre and G

    M. Legre and G. Ribordy, Apparatus and method for the detection of attacks taking control of the single pho- ton detectors of a quantum cryptography apparatus by randomly changing their efficiency (2018), uS Patent 10,020,937

  22. [30]

    Kulik and S

    S. Kulik and S. Molotkov, Decoy state method for quan- tum cryptography based on phase coding into faint laser pulses, Laser Physics Letters 14, 125205 (2017)

  23. [31]

    Molotkov, A method for detecting detector blinding 12 attacks in quantum cryptography systems with polariza- tion coding (2021), russian Patent 2,783,977

    S. Molotkov, A method for detecting detector blinding 12 attacks in quantum cryptography systems with polariza- tion coding (2021), russian Patent 2,783,977

  24. [32]

    Bussi` eres and G

    F. Bussi` eres and G. Ga¨ etan, Blinding attack detecting device and method (2020), european Patent 3,716,252

  25. [33]

    G. Gras, D. Rusca, H. Zbinden, and F. Bussi` eres, Coun- termeasure against quantum hacking using detection statistics, Physical Review Applied 15, 034052 (2021)

  26. [34]

    S. Cova, M. Ghioni, A. Lacaita, C. Samori, and F. Zappa, Avalanche photodiodes and quenching circuits for single- photon detection, Applied optics 35, 1956 (1996)

  27. [35]

    X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, Practical de- coy state for quantum key distribution, Physical Review A—Atomic, Molecular, and Optical Physics 72, 012326 (2005)

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.