REVIEW 1 major objections 4 minor 52 references
Phase-error estimation for quantum key distribution with leaky receivers
T0 review · 1 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read A fidelity bound makes leaky QKD receivers loss-tolerant.
desk verdict The loss-tolerant post-measurement leakage bound is real and useful, but the a priori basis-leakage section has a missing-system typo in Eq. (8) that needs fixing before the proof is relied upon. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the leakage isometry $\hat{R}^u_\beta$ of Eq. (3): $|b_\beta\rangle \mapsto |b_\beta\rangle |e_{b,\beta}\rangle$ and $|\perp\rangle \mapsto |\perp\rangle |e_{\perp,\beta}\rangle$, with the leaked system $L_u$ given to Eve. Because this isometry commutes with Bob's projective measurement, the actual protocol is statistically identical to one where leakage happens before measurement, and because the sifted key only comes from $Z$-basis detections, only the two $Z$-outcome leakage states matter. Tracing $L_u$ out of the isometry produces a dephasing channel $E_\gamma(\rho) = \frac{1+\gamma}{2}\rho + \frac{1-\gamma}{2} Z\rho Z$ on the detection subspace; applying it to Bob's $X$-basis projectors in the virtual protocol gives the effective phase-error operator of Eq. (5). The parameter $\gamma$ is the only leakage quantity that has to be characterized, and it appears as an overlap, not a trace distance.
What would settle it
A direct test would characterize Bob's receiver after a 0-bit and a 1-bit $Z$-basis detection and measure the fidelity $F(\sigma^{(0,Z)}, \sigma^{(1,Z)})$; if it is below the assumed $\gamma^2$, or if the emitted light also depends on click multiplicity or on previous rounds beyond the gated window, Eq. (7)'s bound with that $\gamma$ is not valid and the key rate could be overestimated.
Extended reading notes
Core claim
The central discovery is that Bob's measurement and the receiver's leakage can be reordered without changing any observed statistics. The paper models the leakage by an isometry $\hat{R}^u_\beta$ that attaches a state $|e_{b,\beta}\rangle$ to the detected system before Bob measures it, and shows this commutes with an ideal qubit measurement. Tracing out the leaked system turns the virtual phase-error measurement into a dephased one: the effective phase-error operator is $\gamma \hat{E}_{\mathrm{ph}}^{AB} + \frac{1-\gamma}{2}\mathbb{1}_A\otimes\mathbb{1}_B^{\det}$, where $\gamma$ is the overlap of the two $Z$-basis leakage states. Summing the resulting conditional bound over detected rounds with Azuma's inequality gives $N_{\mathrm{ph}} \le \gamma \frac{p^A_Z p^B_Z}{p^A_X p^B_X} N_{x,\mathrm{er}} + p^A_Z p^B_Z \frac{1-\gamma}{2} N_{\det}$ plus finite-size fluctuation terms; the same logic with a fidelity parameter $\delta$ between pre-measurement basis-leakage states yields the per-transmitted-round bound for a priori leakage. This makes the post-measurement penalty depend on detected rounds only, which is precisely the loss-tolerant behavior previous analyses lacked.
Load-bearing premise
The load-bearing assumption is that the receiver's side-channel emission depends on the physical detection event only through the recorded outcome $b'$ and basis $\beta$, so it can be attached to the qutrit description by the isometry; if a real device leaks finer-grained information, such as whether a double click occurred, the phase-error bound does not apply.
Editorial extensions
If this is right
- If Eq. (7) holds, a receiver whose leaked bit states have fidelity at least $\gamma^2$ adds only an additive, detection-count-scaled penalty to the phase-error budget, so the key rate stays useful over long distances where most rounds are lost.
- For a priori basis leakage, Eq. (11) shows the penalty scales with transmitted rounds through $\delta$, so Eve can exploit it with strategies such as unambiguous state discrimination; this quantifies why basis-setting leakage is more dangerous than outcome leakage.
- The dephasing substitution extends to non-projective qubit POVMs and to asymmetric passive receivers with detection-efficiency mismatch, where it becomes $\tilde{G}^{(1)}_{(X,\neq)} \mapsto E_\gamma(\tilde{G}^{(1)}_{(X,\neq)})$ and the parameter substitution $\delta \mapsto \delta_\gamma$ in existing detector-imperfection proofs.
- Correlated leakage over a finite window $L_c$ can be handled by gating detectors or by post-processing discards, and the active-round fraction $\approx 1/(1+L_c p_{\det})$ stays close to one when detection is rare, preserving loss tolerance.
- The analysis is modular with source-imperfection and decoy-state proofs, so the same fidelity characterization can be reused in broader prepare-and-measure implementations.
Reading between the lines
- The same $E_\gamma$ dephasing substitution should carry over to other prepare-and-measure and measurement-device-independent protocols whose security reduces to a phase-error estimate on detected rounds, although the paper only runs the BB84 numerics.
- A practical certification procedure could measure only the overlap between the two $Z$-basis leaked states, for example by interferometric comparison of backflash or back-reflected light, rather than full tomography of all side-channel modes; the bound would then make detector-leakage testing a one-number check.
- Because the a priori basis-leakage penalty depends on $\delta$, increasing the basis-choice randomness or using basis-independent detection hardware should reduce the per-round cost; a testable prediction is that key-rate-versus-distance curves stay nearly flat in $\gamma$ for all but near-orthogonal leakage states.
- The double-click caveat suggests that receivers with squashing maps should be designed to randomize or hide double-click patterns from side channels; otherwise any leakage that resolves finer-grained detection patterns falls outside the proof.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. Prepare-and-measure BB84 with a receiver that leaks information about its measurement outcomes (post-measurement leakage) or about its basis choice (a priori leakage) is analyzed. The authors derive finite-key security bounds based on phase-error estimation. For post-measurement leakage, the phase-error penalty scales with the number of detected rounds, making the analysis loss tolerant. For a priori basis-choice leakage, the penalty scales with the number of transmitted rounds. The proof requires only a fidelity bound between the relevant leakage states and is modular, with extensions to non-projective qubit measurements and to receivers with detection-efficiency mismatch.
Significance. If correct, this is a significant advance: previous analyses of detector leakage imposed a penalty per transmitted round, which is overly pessimistic in high-loss regimes. The loss-tolerant bound is both conceptually and practically important. The a priori basis-choice leakage analysis is, to my knowledge, new. The paper is clearly structured, the main derivation is easy to follow, and the numerical results illustrate the expected performance. The modular combination with existing detector-imperfection analyses (Appendix B) and the finite-size concentration bounds are strengths.
major comments (1)
- [A priori leakage of the basis choice, Eq. (8)] Equation (8) is not well-formed: the isometry Û_u is defined with domain H_{E_{u-1}} ⊗ H_{L_{u-1}} ⊗ H_{L'_u} and codomain H_{E_u} ⊗ H_{B_u}, and the input state is ρ^{F_{u-1}}_{A_uE_{u-1}L_{u-1}} ⊗ σ^{β_u}_{L'_u}. In the entanglement-based protocol Alice prepares |Φ+>_{A_u C_u} and sends C_u to Bob, so Eve's attack must act on C_u in order to produce B_u. As printed, the outgoing system B_u is not obtained from any incoming signal. The definition of ρ^{β_u,F_{u-1}}_{A_uB_u} is therefore undefined, and the subsequent identification of ρ^Z and ρ^X as outputs of the same CPTP map—which is needed for the fidelity bound F(ρ^Z, ρ^X) ≥ δ and for the derivation of Eq. (9)—is unsupported. This is more than a typographical issue; the map does not type-check. The authors should include C_u in both the domain of Û_u and the pre-interaction state (with A_u and C_u in the entangled state |Φ+>).
minor comments (4)
- [A priori leakage of the basis choice, after Eq. (9)] The text contains unresolved citation placeholders "[?]" in the paragraph beginning "This type of strategy has previously been used to accommodate source imperfections" ; these should be replaced with actual references.
- [A priori leakage of the basis choice, Eq. (8)] Equation (8) is stated only for 1 < u ≤ N, leaving the initial round u=1 undefined; the definition of ρ^{F_0} should be provided for completeness.
- [Results] In the secret-key-rate formula, the symbol N_ph is used for the upper bound on the number of phase errors, but it should be distinguished from the actual phase-error count (e.g., N_ph^{UB}) to avoid notational confusion.
- [Leakage model] The manuscript would benefit from a brief discussion of how the fidelity bounds in Eq. (2) and in the a priori-leakage section can be certified experimentally in a practical QKD implementation.
Circularity Check
No significant circularity: gamma and delta are input fidelity bounds, and the phase-error derivation does not assume its conclusion.
full rationale
The central derivation is self-contained relative to its stated assumptions. The post-measurement leakage bound starts from the leak-isometry in Eq. (3), whose overlap gamma is an assumed device-fidelity input (Eq. (2)), not a fitted or target quantity. The phase-error operator in Eq. (5) is obtained by applying the resulting dephasing channel E_gamma to the standard phase-error operator, and Eq. (6)/Eq. (7) follow by algebra plus Azuma's inequality; nowhere is the final bound inserted as an assumption. The a priori leakage analysis introduces delta as a lower bound on the fidelity of the leaked basis-choice states, uses data processing to transfer it to the conditional states, and then applies a previously published data-processing inequality from Ref. [39] to relate phase-error and bit-error probabilities. That cited inequality is external, published evidence and does not include the present leaky-receiver result among its assumptions, so the self-citation is not load-bearing in a circular sense. Several other self-citations ([19], [24], [37]) are used only as modular building blocks or alternative tail bounds, not as the source of the new phase-error estimate. The paper also explicitly flags a genuine limitation of the squashing-model route (leakage depending on finer-grained patterns such as double clicks is outside the model), which is an honest scope restriction rather than a circular move. A separate correctness/typing concern exists around Eq. (8), where the displayed map omits the signal system C_u; however, that is a rigor or correctness issue, not a circularity issue, because the derivation would still rely on an assumed isometry rather than on its own conclusion. Overall, no step reduces by construction to its inputs, and the central claims have independent content.
Assumptions & free parameters
assumptions (8)
- domain assumption The received system B_u is block diagonal as a qutrit: vacuum plus a qubit detection subspace, Eq. (1).
- domain assumption Bob's detected-round measurement is an ideal projective qubit measurement in the chosen basis.
- domain assumption Post-measurement leakage depends on (b', beta) only and is generated by the commuting isometry Eq. (3).
- domain assumption The input state of B_u is independent of Bob's basis choice in the post-measurement leakage scenario.
- domain assumption Fidelity lower bound F(sigma^(0,Z), sigma^(1,Z)) >= gamma^2 holds for all rounds, Eq. (2).
- domain assumption A priori basis leakage state sigma^beta_{L'} has fidelity at least delta between basis choices and enters Eve's interaction as in Eq. (8).
- domain assumption When combined with detector-imperfection analyses, detectors are taken memoryless (Appendix B, footnote 42).
- standard math Azuma-Hoeffding, Uhlmann's theorem, and the data-processing inequality are used.
Cite this review
Pith. "Pith review of Phase-error estimation for quantum key distribution with leaky receivers." pith.science (2026). https://pith.science/paper/DDT4F4XM
@misc{pith2026260809674,
author = {Pith},
title = {Pith review of: Phase-error estimation for quantum key distribution with leaky receivers},
year = {2026},
howpublished = {\url{https://pith.science/paper/DDT4F4XM}},
note = {Machine review of arXiv:2608.09674}
}
read the original abstract
Practical quantum key distribution (QKD) receivers may leak information about their measurement outcomes and settings to the channel (e.g., through detector backflashes or back-reflected Trojan-horse light) that could compromise the protocol's security. Here we present a simple finite-key security proof based on phase-error estimation for prepare-and-measure QKD in the presence of either a priori information leakage about the basis choices and/or a posteriori information leakage about the measurement outcomes. The proof requires only a bound on the distinguishability of the side-channel states. Furthermore, the analysis is modular and compatible with existing security proofs that address detector and source imperfections, making it applicable to a wide range of practical QKD implementations.
Figures
Reference graph
Works this paper leans on
-
[39]
, nA indexes then A states|φ i⟩C , emitted with probabilityp i
To analyze more general sources, one could instead con- sider the entangled state P i √pi |i⟩A |φi⟩C , wherei= 0,1, . . . , nA indexes then A states|φ i⟩C , emitted with probabilityp i
-
[1]
Step 1: Simulating the POVM by a projective measurement plus randomness SinceG (Z) 0 is Hermitian and acts on a qubit, it admits the decomposition G(Z) 0 =λ 0P0 +λ 1P1, P 0 +P 1 =1,(A1) with eigenvaluesλ j ∈[0,1] and orthogonal rank-1 projec- tors{P 0, P1}; consequentlyG (Z) 1 =1−G (Z) 0 is diagonal in the same basis. Bob can therefore reproduce the outco...
-
[2]
Step 2: Simulating the leakage We now suppose that Bob runs the alternative sce- nario where he measures the projectors{P j}j and leaks, instead of|e b,Z⟩L, both the (classical) value ofRand a state|f j⟩L that carries information about the projective outcomej, chosen such that ⟨f1|f0⟩=⟨e 1,Z|e0,Z⟩=γ.(A5) Becauseγis real, there exist isometriesV I , VF suc...
-
[3]
Step 3: Isometry and dephasing channel Now, similarly to the main text, consider that Bob implements the following scenario, which is equivalent to the scenario just described in Step 2: (1) he applies the isometry ˆRZ |ψ⟩B =P 0 |ψ⟩B |f0⟩L +P 1 |ψ⟩B |f1⟩L ,(A9) which is the analogue of the isometry ˆRu Z in Eq. (3), restricted to the detection subspace, a...
-
[4]
Phase-error relation SinceM− E γ(M) = (1−γ)M off , whereM off is the off-diagonal part ofMin the{ | ˜0⟩,| ˜1⟩}basis, and ∥Moff ∥∞ =|M ˜0˜1| ≤ 1 2 for any qubit POVMM, with M˜0˜1 :=⟨ ˜0|M| ˜1⟩, we obtain the state-independent bound ∥M− Eγ(M)∥ ∞ ≤ 1−γ 2 .(A12) In this case, the unmodified phase-error operator has the form ˆEph AB =|0 X ⟩ ⟨0X |A ⊗G (X) 1 +|1...
-
[5]
Then, conditioned on the recordF u−1, withρ≡ ρFu−1 AuBuDuRu being the round-uconditional state, the con- ditional phase-error andX-basis-error probabilities are given by Pr χu ph|Fu−1 =p A ZpB Z Tr h ˆOph ABDR ρ i , Pr χu x,er|Fu−1 =p A X pB X Tr h ˆOx ABDR ρ i . (F6) Now, note that Eve’s round-udecision on the state that is forwarded to Bob is independen...
-
[6]
(F8)) we can divide by Tr (1AB ⊗ ¯ED)σ in both sides of Eq
Moreover, since the detection probability is ba- sis independent (see Eq. (F8)) we can divide by Tr (1AB ⊗ ¯ED)σ in both sides of Eq. (F9) and mul- tiply by the basis-choice probabilities, leading, for every detected roundu, to Pr χu ph|Fu−1,D u ≤ pA ZpB Z pA X pB X Pr χu x,er|Fu−1,D u +p A ZpB Z 1−γ 2 , (F10) 11 whereD u represents the detection event. S...
-
[7]
C. H. Bennett and G. Brassard, inProc. IEEE Int. Conf. Computers, Systems and Signal Processing(Bangalore, India, 1984) pp. 175–179
work page 1984
Show all 52 references
-
[8]
H.-K. Lo, M. Curty, and K. Tamaki, Nat. Photonics8, 595 (2014)
2014
-
[9]
Pirandola, U
S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani,et al., Adv. Opt. Photonics12, 1012 (2020)
2020
-
[10]
F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Rev. Mod. Phys.92, 025002 (2020)
2020
-
[11]
Gottesman, H.-K
D. Gottesman, H.-K. Lo, N. L¨ utkenhaus, and J. Preskill, Quantum Inf. Comput.4, 325 (2004)
2004
-
[12]
Marquardt, U
C. Marquardt, U. Seyfarth, S. Bettendorf, M. Bohmann, A. Buchner, M. Curty, D. Elser, S. Eul, T. Gehring, N. Jain, T. Klocke, M. Reinecke, N. Sieber, R. Ursin, M. Wehling, and H. Weier,Implemen- tation attacks against QKD systems, Tech. Rep. (German Federal Office for Informat...
2024
-
[13]
Zapatero, ´A
V. Zapatero, ´A. Navarrete, and M. Curty, Adv. Quantum Technol.8, 2300380 (2025)
2025
-
[14]
Marcomini, A
A. Marcomini, A. Mizutani, F. Gr¨ unenfelder, M. Curty, and K. Tamaki, Quantum Sci. Technol.10, 035002 (2025)
2025
-
[15]
C.-H. F. Fung, K. Tamaki, B. Qi, H.-K. Lo, and X. Ma, Quantum Inf. Comput.9, 131 (2009)
2009
-
[16]
Lydersen, C
L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Nat. Photonics4, 686 (2010)
2010
-
[17]
Vakhitov, V
A. Vakhitov, V. Makarov, and D. R. Hjelme, J. Mod. Opt.48, 2023 (2001)
2001
-
[18]
N. Jain, E. Anisimova, I. Khan, V. Makarov, C. Mar- quardt, and G. Leuchs, New J. Phys.16, 123030 (2014)
2014
-
[19]
H.-K. Lo, M. Curty, and B. Qi, Phys. Rev. Lett.108, 130503 (2012)
2012
-
[20]
Lucamarini, Z
M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, Nature557, 400 (2018)
2018
-
[21]
Tupkary, S
D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Quantum9, 1937 (2025)
2025
-
[22]
Z. Wang, D. Tupkary, and S. Nahar, preprint arxiv:2508.21486 (2025)
2025
-
[23]
Nahar, D
S. Nahar, D. Tupkary, and N. L¨ utkenhaus, Quantum10, 2044 (2026)
2026
-
[24]
Curr´ as-Lorenzo, M
G. Curr´ as-Lorenzo, M. Pereira, S. Nahar, and D. Tup- kary, npj Quantum Inf.12, 129 (2026)
2026
-
[25]
Navarrete, G
´A. Navarrete, G. Curr´ as-Lorenzo, M. Pereira, and M. Curty, preprint arxiv:2605.12984 (2026)
2026 arXiv
-
[26]
Kurtsiefer, P
C. Kurtsiefer, P. Zarda, S. Mayer, and H. Weinfurter, J. Mod. Opt.48, 2039 (2001)
2001
-
[27]
P. V. P. Pinheiro, P. Chaiwongkhot, S. Sajeed, R. T. Horn, J.-P. Bourgoin, T. Jennewein, N. L¨ utkenhaus, and V. Makarov, Opt. Express26, 21020 (2018)
2018
-
[28]
Marøy, L
Ø. Marøy, L. Lydersen, and J. Skaar, Phys. Rev. A82, 032337 (2010)
2010
- [29]
-
[30]
Curr´ as-Lorenzo, M
G. Curr´ as-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Optica Quantum3, 525 (2025)
2025
-
[31]
Hwang, Phys
W.-Y. Hwang, Phys. Rev. Lett.91, 057901 (2003)
2003
-
[32]
H.-K. Lo, X. Ma, and K. Chen, Phys. Rev. Lett.94, 230504 (2005)
2005
-
[33]
Wang, Phys
X.-B. Wang, Phys. Rev. Lett.94, 230503 (2005)
2005
-
[34]
Koashi, Y
M. Koashi, Y. Adachi, T. Yamamoto, and N. Imoto, Se- curity of entanglement-based quantum key distribution with practical detectors (2008), arXiv:0804.0891 [quant- ph]
2008 arXiv
-
[35]
Moroder, M
T. Moroder, M. Curty, and N. L¨ utkenhaus, New Journal of Physics11, 045008 (2009)
2009
-
[36]
Kawakami, A
S. Kawakami, A. Taniguchi, Y. Tonomura, K. Takasugi, and K. Azuma, Physical Review Applied24, 054070 (2025), arXiv:2507.04248 [quant-ph]
2025
-
[37]
N. J. Beaudry, T. Moroder, and N. L¨ utkenhaus, Phys. Rev. Lett.101, 093601 (2008)
2008
-
[38]
Gittsovich, N
O. Gittsovich, N. J. Beaudry, V. Narasimhachar, R. Romero Alvarez, T. Moroder, and N. L¨ utkenhaus, Phys. Rev. A89, 012325 (2014)
2014
-
[40]
Koashi, New J
M. Koashi, New J. Phys.11, 045018 (2009)
2009
-
[41]
Azuma, Tohoku Math
K. Azuma, Tohoku Math. J.19, 357 (1967)
1967
- [42]
-
[43]
Mannalath, V
V. Mannalath, V. Zapatero, K. Tamaki, and M. Curty, preprint arXiv:2607.17690 (2026)
2026 arXiv
-
[44]
Importantly, no such restriction is required here, since the necessary sequential structure arises by construction (see Fig
This type of strategy has previously been used to accom- modate source imperfections [?], where a sufficiently low repetition rate had to be imposed to enforce a specific sequential structure on Eve’s attack and thereby ensure that all relevant operators appearing in the calcu...
-
[45]
Curr´ as-Lorenzo, S
G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamaki, and M. Curty, Quantum Sci. Technol.9, 015025 (2024)
2024
-
[46]
Pittaluga, M
M. Pittaluga, M. Minder, M. Lucamarini, M. Sanzaro, R. I. Woodward, M.-J. Li, Z. Yuan, and A. J. Shields, Nature Photonics15, 530 (2021)
2021
-
[47]
(11) accounts for both leakage mechanisms simultaneously, and therefore depends onγandδ
Note that Eq. (11) accounts for both leakage mechanisms simultaneously, and therefore depends onγandδ. For the “Pre” curves in Fig. 2, however, whether one sets ε= 1−γ 2 = 1−δ—i.e. one considers that both types of leakage are present with the same strength—or removes the post-...
-
[48]
We remark that Ref. [16] also extends its analysis to de- tectors with memory effects, by discarding detections in rounds preceded by another detection within the correla- tion length and reducing the security analysis of the non- detected rounds to the memoryless case. Since ...
-
[49]
, u+Lc once the valuebis recorded
As in the main text, this isometry is not an actual step of the protocol, but a rewriting of the window dynamics in the controlled form ˆSu = P b |bZ ⟩ ⟨bZ |Bu ⊗ ˆKb, where ˆKb collects everything that happens in roundsu, . . . , u+Lc once the valuebis recorded. This includes ...
-
[50]
Uhlmann, Rep
A. Uhlmann, Rep. Math. Phys.9, 273 (1976)
1976
-
[51]
Makarov, A
V. Makarov, A. Anisimov, and J. Skaar, Phys. Rev. A 74, 022313 (2006)
2006
-
[52]
Qi, C.-H
B. Qi, C.-H. F. Fung, H.-K. Lo, and X. Ma, Quantum Information and Computation7, 73 (2007)
2007
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.