REVIEW 5 minor 1 cited by
Quantum Key Distribution with Basis-Dependent Detection Probability
T0 review · 0 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read This paper proves security of prepare-and-measure QKD when detection probability depends on the measurement basis, using a tunable beam splitter to estimate the phase error rate from observed statistics instead of assuming the worst case.
desk verdict The proof genuinely drops basis-independent detection by estimating mismatches in real time, and it holds at the level of its stated assumptions, but the security now rests on a TBS trust assumption that is acknowledged and unresolved. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the tunable beam splitter (TBS), a beam splitter whose transmittance $(\eta_i,\eta_l)$ can be switched inside and outside the key-detection window $Z$ within a single round. It turns the $Z$-basis detector's click POVM into the diagonal operator $Z_{\checkmark}=\sum_{\alpha\ge0}p_{\checkmark|\alpha}\Pi^\alpha_Z$ with $p_{\checkmark|\alpha}=1-(1-p_Z^d)\eta_\downarrow^\alpha$, so the seven TBS settings act as detector decoys that reveal how much of Bob's received state lies in the zero-, one-, and multi-photon sectors of $Z$. The proof reduces the phase error rate to the at-most-one-photon subspace, bounds the leftover weight $w_{>1}^Z$ via a linear system, and expresses the phase-error bound (42) in terms of observed gains and QBERs; an uncertainty relation with the compatibility coefficient $c=\max_{j,k}|\langle 1_{Z_j}|S^{-1}|1_{X_k}\rangle|^2$ then converts this into Eve's conditional entropy.
What would settle it
An experiment in which Eve can modulate the tunable beam splitter's transmittance as a function of the incoming optical mode would test the proof's boundary: if that control kept the apparent key rate positive while Eve could predict the key, the security claim would be false.
Extended reading notes
Core claim
This paper's central claim is that the usual assumption $Z_{\checkmark}=X_{\checkmark}$, that a click is equally likely in either measurement basis for every input state, can be dropped without losing security. For phase-randomized coherent states with three intensities and $d$-outcome bases satisfying the single-photon basis-independence condition (7), the authors construct a protocol in which Bob routes each received signal through a tunable beam splitter whose transmittance differs inside and outside the key-detection window. From the gains and error rates of the seven TBS settings, together with the decoy-state method, they upper-bound the phase error rate $\tilde e_{X,1}$ and prove that the key rate (17) is a lower bound on the asymptotic secret-key rate under collective attacks. The proof needs no a priori characterization of mode-dependent detection efficiencies; instead it estimates the weight of Eve's states outside the at-most-one-photon-in-$Z$ subspace and solves linear systems that isolate the TBS's effect on zero- and one-photon components. Simulations on a four-dimensional time-bin setup show positive key rates up to 30 dB loss for honest implementations, while an intercept-resend attack that steers clicks into one basis lowers the proved rate proportionately.
Load-bearing premise
The load-bearing premise is that the receiver's tunable beam splitter is outside the adversary's control and treats every optical mode the same way; if Eve could influence or mode-dependently alter its transmittance, the estimated phase-error bound could be biased.
Editorial extensions
If this is right
- Real QKD devices with unequal nominal detector efficiencies or dark-count rates no longer need their efficiency mismatch fully characterized before a secure key can be certified.
- In honest implementations the new proof returns key rates close to the standard decoy-BB84 rate; the gap seen in simulations is attributed to a non-tight bound on the multi-photon weight $w_{>1}^Z$ rather than to the protocol itself.
- Against an intercept-resend attack that steers which basis clicks, the proved key rate tracks the true extractable key, while the BB84 rate can overestimate it by more than ten percentage points.
- The protocol applies to any two-basis setup in which one basis is a time-of-arrival measurement and the TBS can be tuned along the measured degree of freedom, including time-bin and time-frequency QKD.
Reading between the lines
- Inference: the same real-time-monitoring strategy could be adapted to other implementation flaws, such as basis-dependent source leakage, by inserting a fast switchable element and estimating the leakage parameter from the augmented statistics rather than bounding it a priori.
- Inference: the paper's observation that the honest-implementation gap comes from the $w_{>1}^Z$ bound suggests a concrete test: increasing the number of decoy intensities should tighten the gap to decoy-BB84, which could be verified in simulation without new hardware.
- Inference: because the proof does not restrict Bob's received states to a finite dimension, standard reductions to finite-dimensional symmetries are not available; a plausible path to coherent-attack security is an entropic uncertainty-relation argument, which the authors leave open.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper presents an analytical security proof for prepare-and-measure QKD protocols that drops the usual assumption that the detection probability of a state is independent of the measurement basis. The receiver incorporates a high-speed tunable beam splitter (TBS) that is switched between seven settings per round, and the security proof combines the decoy-state method, an entropic uncertainty relation, and a detector-decoy technique to bound the phase error rate in terms of observed statistics. The asymptotic key rate is given in Eq. (17) and is shown to be a lower bound on the Devetak-Winter rate under collective attacks. Simulations on a four-dimensional time-bin QKD setup show that the protocol yields positive key rates for honest implementations and detects a tailored intercept-resend attack that induces a detection efficiency mismatch, whereas a standard BB84 key rate overestimates the secure key rate in that scenario. The proof is self-contained and the mathematical steps are detailed in the appendices.
Significance. If correct, this is a significant result for implementation security of QKD: it provides a provably secure protocol that is robust to detection efficiency mismatches, including adversary-induced mode-dependent mismatches, without requiring a prior worst-case characterization of the efficiency mismatch. The analytical derivation is detailed and the simulation study is informative, illustrating both the achievable positive key rates and the protocol's ability to reduce the key rate in proportion to an active attack. The main limitation is clearly stated: the security proof assumes that the TBS is mode-independent and cannot be influenced by the adversary; this is a reasonable trust assumption for Bob's apparatus and is identified as future work. The paper is a valuable contribution to the QKD security literature.
minor comments (5)
- [Sec. IIIB] The assumption that the TBS is mode-independent and adversary-uninfluenceable is crucial for the derivation of the detector-decoy equations, e.g., Eq. (C181) and the bound on w>1_Z in Eq. (B5). Since this is a load-bearing boundary of the central claim, it should be stated more prominently in the abstract and in Sec. VII, and the physical conditions under which it could be violated (e.g., a wavelength-dependent TBS in time-frequency QKD) should be discussed explicitly.
- [Sec. VI] The discussion correctly attributes the gap to the decoy-BB84 rate in Fig. 4 to the looseness of the bound on w>1_Z, Eq. (B5). It would be helpful to state this earlier, near Eq. (B5), and to comment on whether additional decoy intensities or a different estimator could tighten the bound and reduce the gap.
- [Sec. VA] The simulation sets the decoy intensities to µ2 = 2µ3 = 2·10^-6 and pµ1 = 1, which corresponds to an asymptotic regime. A brief comment on the experimental feasibility of these parameters, and on the finite-key behavior if these extremes are relaxed, would strengthen the practical relevance of the simulations.
- [Fig. 3] The colorbar/contour levels in Fig. 3 are not described in the caption; the reader cannot easily read off the tolerable loss values. Please add a short description of the color scale or use explicit contour labels.
- [General] The notation ~e_X,1 (phase error rate) and e_X,1 (bit error rate) is used throughout; please ensure that the tilde is not accidentally dropped in any formula, and that Appendix B is fully consistent with the main text definitions.
Circularity Check
No significant circularity: the key-rate bound follows from the Devetak-Winter rate using observed statistics and external theorems; the only self-citations are to the authors' experimental setup papers, which are not load-bearing for the security proof.
full rationale
The paper's central derivation is the bound on the asymptotic key rate (17) as a lower bound on the Devetak-Winter rate (21). Every input to this chain is either an observed quantity (gains G, QBERs Q, estimated yields Y, estimated phase-error bound) or an external theorem (Devetak-Winter [46], entropic uncertainty relations [48-51], the decoy-state method [37-39], the detector-decoy technique [28], and the Tomamichel-Leverrier measurement-map formalism [8]). The phase-error bound (42) is written entirely in terms of observed test-round yields and bit-error rates plus the detector-decoy bounds (B5)-(B8); no target quantity is inserted as an input. The yields are estimated from observed gains through the standard decoy-state linear system, so there is no fitted parameter that is then renamed as a prediction. The simulations in Sec. V are forward calculations from assumed channel parameters, not fits of the proof's outputs. The only self-citations are to the authors' own experimental setup papers [29,30], used to parametrize the simulated time-bin QKD scheme, and to [45] supporting the attack model; none of these carries the security proof, so they are not load-bearing. The TBS mode-independence assumption (Sec. IIIB) is a stated boundary of the proof's applicability and is explicitly listed as future work (Sec. VII); it limits the scope of the claim but does not make the derivation circular. The paper even honestly discloses that its w>1_Z bound is non-tight for honest implementations (Sec. VI), which is the opposite of concealing the source of the gap to the decoy-BB84 rate. No step in the derivation reduces, by construction or by self-citation, to its own input.
Assumptions & free parameters
free parameters (5)
- Signal intensity µ1 =
optimized over µ1 in simulations (e.g., Fig. 4)
- Decoy intensities µ2, µ3 =
2e-6 and 1e-6 in simulations
- TBS transmittances η↑, η↓, η2 =
0.9, 0.1, 0.4 in simulations
- Intrinsic QBERs qZ, qX =
scanned 0-0.3; set to 0.02/0.05 in Figs. 4-5
- Channel loss, detector efficiencies, dark counts =
η=10^{-1/10} (1 dB), ηZ=0.9·10^{-1/10}, ηX=ηZ·10^{-1/10}, pZ_d=10^{-4}, pX_d=1.2e-4
assumptions (10)
- standard math Devetak-Winter rate lower-bounds asymptotic secret key rate under collective attacks.
- standard math Entropic uncertainty relation with quantum side information H(Z|E)+H(X|B) >= log(1/c).
- standard math Decoy-state method estimates single-photon yields and error rates from PRCS intensities µ1>µ2+µ3, µ2>µ3>=0.
- standard math Detector decoy technique provides bounds on photon-number weights from different TBS transmittance settings.
- domain assumption The TBS cannot be influenced by the adversary and its transmittance settings are mode-independent.
- domain assumption Nominal (mode-independent) detector efficiencies ηZ, ηX and dark count probabilities pZ_d, pX_d are known.
- domain assumption Alice's single-photon states in Z and X bases have identical average state S (Eq. (7)), enabling the entanglement-based picture.
- domain assumption Security is proven in the asymptotic limit under collective attacks only.
- domain assumption TBS transmittance range satisfies η↑ > η↓/(1−η↓) and ηX/ηZ > (η↓)^{-1}(1−sqrt((1−η↓)/η↑)).
- domain assumption Bob maps multi-click detection events to a single outcome, never to no-detection.
invented entities (1)
-
High-speed tunable beam splitter (TBS) in Bob's receiver
independent evidence
Cite this review
Pith. "Pith review of Quantum Key Distribution with Basis-Dependent Detection Probability." pith.science (2026). https://pith.science/paper/GTIWSWYP
@misc{pith2026241119874,
author = {Pith},
title = {Pith review of: Quantum Key Distribution with Basis-Dependent Detection Probability},
year = {2026},
howpublished = {\url{https://pith.science/paper/GTIWSWYP}},
note = {Machine review of arXiv:2411.19874}
}
read the original abstract
Quantum Key Distribution (QKD) is a promising technology for secure communication. Nevertheless, QKD is still treated with caution in certain contexts due to potential gaps between theoretical models and actual QKD implementations. A common assumption in security proofs is that the detection probability at the receiver, for a given input state, is independent of the measurement basis, which might not always be verified and could lead to security loopholes. This paper presents a security proof for QKD protocols that does not rely on the above assumption and is thus applicable in scenarios with detection probability mismatches, even when induced by the adversary. We demonstrate, through simulations, that our proof can extract positive key rates for setups vulnerable to large detection probability mismatches. This is achieved by monitoring whether an adversary is actively exploiting such vulnerabilities, instead of considering the worst-case scenario as in previous proofs. Our work highlights the importance of accounting for basis-dependent detection probabilities and provides a concrete solution for improving the security of practical QKD systems.
Figures
Figures from the paper (6 more)
Forward citations
Cited by 1 Pith paper
-
Security of quantum key distribution with source and detector imperfections through phase-error estimation
A modular proof technique extends phase-error-estimation security bounds from basis-independent to mismatched detector efficiencies, enabling finite-key QKD security with simultaneous source and detector imperfections.
Reference graph
Works this paper leans on
-
[1]
Standard equations of the decoy-state method We recall from Sec. III that Alice prepares WCPs with three different intensities:S = {µ1, µ2, µ3}, withµ1 > µ2+µ3 and µ2 > µ3 ≥ 0 . The parties use all three intensities both to generate the key and to derive the decoy bounds. The equalities on which the decoy-state method relies on, relate the unobserved yiel...
-
[2]
Bounds on yields and bit error rates We observe that the equations defining the decoy-state method, namely (D2), (D4), (D5), (D7), and (D8), share the same structure, which can be exemplified as follows: Gµj = ∞X n=0 e−µj µn j n! Yn, (D9) where Gµj can be replaced by a gain or a product of QBER and gain, whileYn can be replaced by a yield or a product of ...
-
[5]
Secret key rate In this subsection we complete the security proof of Protocol 1. We combine the upper bound obtained on the phase error rate (C436) with the entropy bound (C87) to derive the following bound on the entropy of interest: H(ZA|E)ρ|1,ΩZ ≥ log2 1 c − u(˜eX,1), (C438) where we used the fact thatu(x) in (20) is a monotonically non-decreasing func...
-
[7]
µn 3 n! Yn = f (1)Y1 + ∞X n=3 f (n)Yn, (D15) where we introduced: f (n) := (µ2 2 − µ2
-
[8]
µn 1 n! − (µ2 1 − µ2
-
[9]
µn 2 n! + (µ2 1 − µ2
-
[10]
µn 3 n! . (D16) Now we observe thatf (1) is negative: f (1) < 0 ⇔ (µ2 2 − µ2 3)µ1 − (µ2 1 − µ2 3)µ2 + (µ2 1 − µ2 2)µ3 < 0 ⇔ (µ2 2 − µ2 3)µ1 − (µ2 1 − µ2 2)µ2 − (µ2 2 − µ2 3)µ2 + (µ2 1 − µ2 2)µ3 < 0 ⇔ (µ2 2 − µ2 3)(µ1 − µ2) − (µ2 1 − µ2 2)(µ2 − µ3) < 0 ⇔ (µ2 − µ3)(µ1 − µ2) [µ2 + µ3 − µ1 − µ2] < 0, (D17) which is true sinceµ3 < µ2 < µ1. At the same time, we...
-
[11]
− µ2 3(µn−2 1 − µn−2 3 )(µ2 1 − µ2
Show all 16 references
-
[12]
µn−3 3 ) ≥ 0 ⇔ µ1 µ2 2(µn−3 1 + µn−4 1 µ2 + · · ·+ µn−3 2 ) − µ2 3(µn−3 1 + µn−4 1 µ3 +
≥ 0 ⇔ (µ1 − µ2)(µ1 − µ3) µ2 2(µ1 + µ3)(µn−3 1 + µn−4 1 µ2 + · · ·+ µn−3 2 ) − µ2 3(µ1 + µ2)(µn−3 1 + µn−4 1 µ3 + . . . µn−3 3 ) ≥ 0 ⇔ µ1 µ2 2(µn−3 1 + µn−4 1 µ2 + · · ·+ µn−3 2 ) − µ2 3(µn−3 1 + µn−4 1 µ3 + . . . µn−3 3 ) + µ2µ3 µ2(µn−3 1 + µn−4 1 µ2 + · · ·+ µn−3 2 ) − µ3(µn−...
-
[13]
(eµ1 − µ1) − (µ2 1 − µ2
-
[14]
(eµ2 − µ2) + (µ2 1 − µ2
-
[15]
(eµ3 − µ3) = −f (1) + (µ2 2 − µ2 3)eµ1 − (µ2 1 − µ2 3)eµ2 + (µ2 1 − µ2 2)eµ3 . (D20) D DECOY-STATE METHOD 2 Bounds on yields and bit error rates 75 By employing the last expression in (D19), we obtain the following upper bound on the one-photon yield: Y1 = 1 − (µ2 2 − µ2 3)eµ1...
-
[16]
In principle, in these expressions we could use the bounds already derived for the single yields
Bounds on linear combinations of yields Some of the quantities appearing in the phase error rate bound (B1), namely (B5)–(B9), depend on linear combi- nations of one-photonZ-basis yields. In principle, in these expressions we could use the bounds already derived for the single...
-
[17]
3 and 4, in the absence of eavesdroppers, theZ-basis gain reads: GZ µj ,(ηl,ηl) = 1 − (1 − pZ d )e−µj ηηZ (1−ηl), (E1) where η is the transmittance of the quantum channel
High-dimensional time-bin QKD According to the channel model employed for simulating the time-bin QKD protocol (Protocol 1) in Figs. 3 and 4, in the absence of eavesdroppers, theZ-basis gain reads: GZ µj ,(ηl,ηl) = 1 − (1 − pZ d )e−µj ηηZ (1−ηl), (E1) where η is the transmitta...
-
[18]
Attack-induced efficiency mismatch In order to study the attack presented in Sec VB, we assume that Alice can deterministically send one-photon pulses in each round. This allows us to simplify our proof by removing the decoy-state method, which is no longer needed since in thi...
-
[19]
(17), for varying asymmetries in the mode-independent detection efficiency of the two bases, i.e., as a function ofηr = ηX /ηZ
Secret key rate vs (mode-independent) detection efficiency mismatch In this section, we study the performance of the key rate from our proof, Eq. (17), for varying asymmetries in the mode-independent detection efficiency of the two bases, i.e., as a function ofηr = ηX /ηZ. Thi...
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.