REVIEW 3 major objections 4 minor 2 cited by
Additivity and chain rules for quantum entropies via multi-index Schatten norms
T0 review · 3 major / 4 minor · reviewed 2026-08-09 · deepseek-v4-flash
Pith's one-line read The paper proves that optimized sandwiched Rényi conditional entropy is additive over tensor products of arbitrary quantum channels, with chain rules and time-adaptive cryptographic applications.
desk verdict Unconstrained additivity and chain rules look strong, but the constrained version relies on a false strong-duality claim that breaks the cryptographic applications. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Multi-index Schatten norms, defined by iterating Pisier's variational formula $\|X\|_{S_p[H,\mathcal{X}]} = \inf_{X=FYG} \|F\|_{2p}\|Y\|_{S_\infty[H,\mathcal{X}]}\|G\|_{2p}$, are the central object. A norm with $k$ indices, written $\|X\|_{(A_1:q_1,\ldots,A_k:q_k)}$, records the order and Schatten exponent for each tensor factor. Theorems 3.2 and 3.4 provide variational characterizations of three-index norms that make them tractable. These norms carry the argument because sandwiched Rényi conditional entropy is the logarithm of a $(1,\alpha)$-norm, so proving multiplicativity of completely bounded norms between such spaces is exactly proving additivity of conditional entropies. The proof also relies on the complete-contraction property of the swap map for ordered indices and on the identity-to-the-right lemma showing that attaching an identity operator space to the output of a completely positive map does not change its norm.
What would settle it
Compute, for a small finite-dimensional channel $\Phi$ and a linear constraint $(N,\tau)$, the primal value $\sup_{\rho\geq 0,\,N(\rho)=\tau} \|\Phi(\rho)\|_{(R:1,S:p)}$ and its dual $\inf_{\Sigma\geq 0,\, g^\Phi_p(\rho)\leq \operatorname{Tr}[\Sigma N(\rho)]\ \forall\rho} \operatorname{Tr}[\Sigma\tau]$; any channel where the two values differ by more than numerical precision would break Eq. (17), and with it Theorem 4.15 and Corollary 5.1. A natural candidate is a qubit amplitude-damping channel with a constraint fixing the output Bloch component.
Extended reading notes
Core claim
The central discovery is that the completely bounded $1\to(1,p)$ norm of a tensor product of completely positive maps factorizes: $\|\otimes_i \Phi_i\|_{cb,(Q^n:1)\to(R^n:1,S^n:p)} = \prod_i \|\Phi_i\|_{cb,(Q_i:1)\to(R_i:1,S_i:p)}$. Taking logarithms via the identity $H^\uparrow_\alpha(A|B)_\rho = \frac{\alpha}{1-\alpha}\log \|\rho\|_{(B:1,A:\alpha)}$ gives the entropic additivity statement $\inf_E \inf_\rho H^\uparrow_\alpha(S^n|R^nE)_{\Phi^n(\rho)} = \sum_i \inf_E \inf_\rho H^\uparrow_\alpha(S_i|R_iE)_{\Phi_i(\rho)}$. This holds for arbitrary completely positive maps with different input and output spaces, not only identical channels. The proof generalizes an earlier multiplicativity result [9] to arbitrary multi-index Schatten norms using variational formulas (Theorems 3.2 and 3.4) and an identity-to-the-right lemma (Theorem 4.1). A constrained version with linear input constraints (Theorem 4.15) is proven via strong duality and yields the reduction to independent attacks (Corollary 5.1) and a time-adaptive rate theorem (Theorem 5.2). The paper also proves chain rules for optimized Rényi conditional entropies (Corollaries 4.2 and 4.8).
Load-bearing premise
The constrained additivity result assumes that for every channel and linear constraint used, the convex optimization over input states can be exchanged with its Lagrangian dual with no gap; if any such channel has a duality gap, the product bound and the time-adaptive security theorem do not follow.
Editorial extensions
If this is right
- Additivity extends from identical channels to arbitrary tensor products: the optimized conditional Rényi entropy of the joint channel is the sum of the per-channel values, for all $\alpha \geq 1$.
- The chain rules bound the entropy loss when processing a state through a product channel in terms of one channel's minimum output entropy, with no loss in $\alpha$ and no need to optimize over purifications on the right-hand side.
- For states satisfying independent linear constraints, minimization of the $f$-weighted Rényi entropy over $n$ rounds reduces to independent round-by-round optimizations, so collective attacks are no stronger than independent attacks in this setting.
- Time-adaptive quantum random number generation and key distribution protocols can be proven secure at the average of the per-round optimal rates; when the protocol is fixed but the noise varies, this exceeds the static-proof rate whenever the rate function is strictly convex.
- The asymptotic rate of randomness extraction is $\lim_{n\to\infty} \frac{1}{n}\sum_{t=1}^n h(M_t,N_t,\tau_t,q^{\mathrm{hon}}_{X_t})$, which also permits security proofs for protocols whose operations change from round to round.
Reading between the lines
- A natural testable consequence is that the finite-size correction in the adaptive proof could be tightened by applying the new chain rule repeatedly rather than through the uniform-continuity lemma, which currently costs a factor of $(\log \eta)^2$ per round.
- Because Theorem 4.10 does not require the channels to act on identical systems or to commute, the same proof should yield entropy-accumulation-style bounds for protocols with memoryless but non-identical channels from round to round, a setting not explicitly treated in the paper.
- The multiplicativity of the $1\to(1,p)$ completely bounded norm suggests that the optimized Rényi conditional entropy itself, not only its infimum, is nearly additive for product inputs; checking whether equality holds only at product minimizers would clarify which states saturate the bound.
- For quantum key distribution, the time-adaptive framework could allow selecting measurements in each round based on previously observed statistics, since the per-round maps are arbitrary; the proof appears to allow such adaptivity as long as the linear constraint factors, though the paper does not state this.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper develops a theory of multi-index Schatten (Pisier) norms and uses it to prove multiplicativity theorems for completely bounded norms of completely positive maps. The main results are: Theorem 4.6 (ordered multiplicativity), Theorem 4.10 (multiplicativity of 1→(1,p) CB norms), chain rules for optimized Rényi conditional entropies (Corollaries 4.2, 4.5, 4.8), and Theorem 4.15, which extends multiplicativity to linearly constrained state spaces. The constrained result is used to prove Corollary 5.1, a reduction to independent attacks for f-weighted Rényi entropies, and Theorem 5.2, a time-adaptive asymptotic key rate for QRNG/QKD protocols. The unconstrained theorems are proved in the main text, while the constrained theorem is proved in Appendix B via a strong-duality argument.
Significance. The unconstrained multiplicativity results are a substantive technical contribution. They generalize the Devetak–Junge–King–Ruskai multiplicativity theorem to arbitrary multi-index Schatten norms and yield chain rules for optimized Rényi entropies that avoid some limitations of earlier work, such as the need to optimize over purifications and a loss in the Rényi parameter. The proofs are explicit and largely self-contained. However, the paper's headline application to time-adaptive cryptography rests on Theorem 4.15, whose proof relies on a strong-duality statement (Eq. (17)) that is false as stated. The constrained additivity result and the derived cryptographic rate theorem are therefore not established by the arguments given; the unconstrained portion may stand independently.
major comments (3)
- [Appendix B, Eq. (17)] The asserted strong duality is false as stated. Take Q = C^2, let Φ be the identity channel with R trivial (so the output multi-index norm is (\tilde Q:1, S:p)), set N = id, τ = I/2, and p = 2. Then g^Φ_2(ρ) = ||ρ||_2, so the primal value is ||I/2||_2 = 1/√2. A dual feasible Σ must satisfy ||ρ||_2 ≤ Tr[Σρ] for all ρ ≥ 0; testing rank-one projectors gives Σ ≥ I, hence Tr[Στ] ≥ 1. Thus the dual value is at least 1 > 1/√2, contradicting Eq. (17). The proof in Appendix B only exhibits a dual feasible point Σ = C1, which establishes weak duality, not strong duality.
- [Theorem 4.15 and Corollary 5.1] Because the proof of Theorem 4.15 invokes Eq. (17) to pass from dual-feasible Σ_i to the infimum over Σ_i and to identify that infimum with the product of the individual primal optima, the counterexample to Eq. (17) invalidates the proof of Theorem 4.15. No alternative argument is supplied. Corollary 5.1 is then derived by applying Theorem 4.15, and Theorem 5.2 relies on Corollary 5.1; therefore the claimed reduction to independent attacks and the time-adaptive asymptotic rate are unsupported by the current manuscript. The unconstrained Theorem 4.10, whose proof does not use Eq. (17), is not affected by this issue.
- [Section 4.3 / Theorem 4.15 statement] The theorem is stated for arbitrary linear restrictions (N_i, τ_i), but the proof does not state or verify any constraint qualification for the primal problem. The exhibited dual feasible point Σ = C1 only proves weak duality. Since Eq. (17) fails even for the simple strictly feasible case N = id, τ = I/2, p = 2, the statement of Theorem 4.15 would need additional hypotheses, or a proof that the specific g^Φ_p and constraints arising in the cryptographic application satisfy a valid duality, before the result can be accepted.
minor comments (4)
- [References] References [3] and [25] are listed as "to appear" without arXiv or journal identifiers; please update them.
- [Section 5.2, Eq. (13)] The normalization in the linear constraint (13) should be stated more explicitly: since each N_t is trace preserving, the right-hand side ⊗_t τ_t fixes the trace of ρ_{Q^n} only if each τ_t has trace 1, which is true in the examples but should be said.
- [Corollary 4.2 proof] The sentence "The right-hand side becomes ..." omits the infimum; the displayed quantity is the infimum over σ, and the wording should reflect that.
- [Section 5.1] In Corollary 5.1, the substitution used to apply Theorem 4.15 (A_i → S_i, X_i → R_i) should be stated explicitly, as the notation otherwise switches between classical and quantum registers without comment.
Circularity Check
No significant circularity: main additivity theorem is derived from external Pisier/DJKR norms, not from the target statement.
full rationale
The central claim (Theorem 4.10 and its entropic form Eq. (2)) is derived from Pisier's variational formula (Theorem 2.3), the generalized variational lemmas of Section 3, and the ordered multiplicativity Theorem 4.6, which in turn rests on Theorem 4.1 and external results [9]. The entropic restatement uses the norm-entropy identity (1), which is a translation, not a definition of the additivity result. No parameter is fitted to a subset of data and then called a prediction; the BB84 rate example uses standard Shor-Preskill values. Self-citations to [25] and [16] appear in applications and comparisons: [16] is used only to contrast the new chain rule, and [25] supplies the reduction/duality technique for the constrained Theorem 4.15. Even though [25] shares an author, the constrained multiplicativity is not obtained by assuming the desired additivity; it is reduced to the unconstrained Theorem 4.10 through strong duality. One correctness caveat, not a circularity: Appendix B's proof of strong duality (17) only exhibits a dual feasible point Sigma = C1, which establishes weak duality and does not by itself rule out a duality gap; the paper does not verify Slater/primal-feasibility conditions. If (17) fails, the proofs of Theorem 4.15, Corollary 5.1 and Theorem 5.2 would be unsupported, but this is a gap in the derivation chain rather than the conclusion being equivalent to the input by construction.
Assumptions & free parameters
assumptions (7)
- standard math Pisier's formula (Theorem 2.3) defines operator-valued Schatten norms and is iterated to multi-index norms.
- standard math Operator-valued Schatten spaces satisfy duality S_p[H,X]* = S_p'[H,X*] and the identification S_q[H,S_q[K,X]] ≃ S_q[H⊗K,X] (Eq. (5)).
- standard math Prior results from Devetak, Junge, King and Ruskai [9], including Lemma 5 and Theorems 11, 12, 13, extend to the multi-index setting.
- domain assumption Strong duality holds for the finite-dimensional convex optimization problem in Appendix B, Eq. (17).
- domain assumption The function h(M,N,τ,q_X) is convex in q_X, as cited from Winick, Lütkenhaus and Coles [28].
- standard math Uniform continuity of Rényi divergences from Dupuis, Fawzi and Renner [10, Lemma B.8] with a state-independent η bound.
- domain assumption All Hilbert spaces in the cryptographic applications are finite-dimensional, as stated at the start of Section 5.
Cite this review
Pith. "Pith review of Additivity and chain rules for quantum entropies via multi-index Schatten norms." pith.science (2026). https://pith.science/paper/HKDEM2R6
@misc{pith2026250201611,
author = {Pith},
title = {Pith review of: Additivity and chain rules for quantum entropies via multi-index Schatten norms},
year = {2026},
howpublished = {\url{https://pith.science/paper/HKDEM2R6}},
note = {Machine review of arXiv:2502.01611}
}
read the original abstract
The primary entropic measures for quantum states are additive under the tensor product. In the analysis of quantum information processing tasks, the minimum entropy of a set of states, e.g., the minimum output entropy of a channel, often plays a crucial role. A fundamental question in quantum information and cryptography is whether the minimum output entropy remains additive under the tensor product of channels. Here, we establish a general additivity statement for the optimized sandwiched R\'enyi entropy of quantum channels. For that, we generalize the results of [Devetak, Junge, King, Ruskai, CMP 2006] to multi-index Schatten norms. As an application, we strengthen the additivity statement of [Van Himbeeck and Brown, 2025] thus allowing the analysis of time-adaptive quantum cryptographic protocols. In addition, we establish chain rules for R\'enyi conditional entropies that are similar to the ones used for the generalized entropy accumulation theorem of [Metger, Fawzi, Sutter, Renner, CMP 2024].
Figures
Forward citations
Cited by 2 Pith papers
-
Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography
Exact analytic Rényi entropy rate functions for the CHSH inequality tighten finite-size DIQKD key rates and reduce the minimum number of rounds by nearly a factor of three.
-
Security proofs for practical QKD: variations, techniques, gaps, and limitations
A critical review of decoy-state BB84 security proofs identifies common gaps and shows that no current proof meets the full standard of completeness, modularity, and verifiability.
Reference graph
Works this paper leans on
-
[25]
T. Van Himbeeck and P. Brown. A tight and general finite-size security proof for quantum key distribution. to appear. 4, 5, 6, 26, 27, 29, 30, 36
-
[1]
S. Arimoto. Information measures and capacity of order α for discrete memoryless channels. Topics in information theory , 1977. 3
work page 1977
-
[2]
R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick. Practical device- independent quantum cryptography via entropy accumulation. Nature communications , 9(1):459, 2018. 5 31
work page 2018
-
[3]
A. Arqand and E. Y.-Z. Tan. Marginal-constrained entropy accumulation theorem. to appear on arXiv. 6
-
[4]
I. Bardet and C. Rouz´ e. Hypercontractivity and logarithmic sobolev inequality for non- primitive quantum markov semigroups and estimation of decoherence rates. In Annales Henri Poincar´ e, volume 23, pages 3839–3903. Springer, 2022. 11
work page 2022
-
[5]
S. Beigi and M. M. Goodarzi. Operator-valued schatten spaces and quantum entropies. Letters in Mathematical Physics , 113(5), Aug. 2023. 4, 8, 9, 11, 16
work page 2023
-
[6]
S. Beigi and C. King. Hypercontractivity and the logarithmic sobolev inequality for the com- pletely bounded norm. Journal of Mathematical Physics , 57(1), 2016. 11
work page 2016
- [7]
Show all 30 references
-
[8]
Dembo, T
A. Dembo, T. M. Cover, and J. A. Thomas. Information theoretic inequalities. IEEE Trans- actions on Information theory , 37(6):1501–1518, 1991. 3
1991
-
[9]
Devetak, M
I. Devetak, M. Junge, C. King, and M. B. Ruskai. Multiplicativity of completely bounded p- norms implies a new additivity result.Communications in Mathematical Physics, 266(1):37–63, May 2006. 3, 4, 6, 9, 11, 14, 17, 20, 21, 22, 23, 24, 34, 35
2006
-
[10]
Dupuis, O
F. Dupuis, O. Fawzi, and R. Renner. Entropy accumulation. Communications in Mathematical Physics, 379(3):867–913, 2020. 38
2020
-
[11]
L. Gao, M. Junge, and N. LaRacuente. Uncertainty principle for quantum channels. In 2018 IEEE International Symposium on Information Theory (ISIT) , pages 996–1000, 2018. 11
2018
-
[12]
M. K. Gupta and M. M. Wilde. Multiplicativity of completely bounded p-norms implies a strong converse for entanglement-assisted capacity. Communications in Mathematical Physics, 334(2):867–887, 2015. 11
2015
-
[13]
Hiai and D
F. Hiai and D. Petz. Introduction to Matrix Analysis and Applications . Universitext. Springer International Publishing, 2014. 35
2014
-
[14]
Liao, W.-Q
S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. Ren, J. Yin, Q. Shen, Y. Cao, Z.- P. Li, F.-Z. Li, X.-W. Chen, L.-H. Sun, J.-J. Jia, J.-C. Wu, X.-J. Jiang, J.-F. Wang, Y.-M. Huang, Q. Wang, Y.-L. Zhou, L. Deng, T. Xi, L. Ma, T. Hu, Q. Zhang, Y.-A. Chen, N.- L. Liu, X....
2017
-
[15]
E. H. Lieb. Proof of an entropy conjecture of wehrl. Communications in Mathematical Physics, 62(1):35–41, 1978. 3
1978
-
[16]
Metger, O
T. Metger, O. Fawzi, D. Sutter, and R. Renner. Generalised entropy accumulation. Commu- nications in Mathematical Physics , 405(11):261, 2024. 5, 20, 23, 29
2024
-
[17]
Metger and R
T. Metger and R. Renner. Security of quantum key distribution from generalised entropy accumulation. Nature Communications, 14(1):5272, 2023. 5, 20
2023
-
[18]
M¨ uller-Lennert, F
M. M¨ uller-Lennert, F. Dupuis, O. Szehr, S. Fehr, and M. Tomamichel. On quantum r´ enyi entropies: A new generalization and some properties. Journal of Mathematical Physics , 54(12):122203, 12 2013. 4, 14 32
2013
-
[19]
G. Pisier. Noncommutative vector valued l p-spaces and completely p-summing maps. arXiv preprint math/9306206, 1993. 3
1993 arXiv
-
[20]
G. Pisier. Non-commutative vector valued Lp-spaces and completely p-summing map. Number 247 in Ast´ erisque. Soci´ et´ e math´ ematique de France, 1998. 6, 8, 9, 10, 11, 13
1998
-
[21]
G. Pisier. Introduction to Operator Space Theory. London Mathematical Society Lecture Note Series. Cambridge University Press, 2003. 8, 9
2003
-
[22]
Portmann and R
C. Portmann and R. Renner. Security in quantum cryptography. Reviews of Modern Physics , 94(2), June 2022. 28
2022
-
[23]
R. Renner. Security of quantum key distribution, 2006. 5, 27, 28, 29
2006
-
[24]
Tomamichel
M. Tomamichel. Quantum Information Processing with Finite Resources . Springer Interna- tional Publishing, 2016. 4, 27
2016
-
[26]
J. Watrous. Notes on super-operator norms induced by schatten norms, 2004. 34
2004
-
[27]
M. M. Wilde, A. Winter, and D. Yang. Strong converse for the classical capacity of entanglement-breaking and hadamard channels via a sandwiched r´ enyi relative entropy.Com- munications in Mathematical Physics , 331(2):593–622, 2014. 4, 11, 14
2014
-
[28]
Winick, N
A. Winick, N. L¨ utkenhaus, and P. J. Coles. Reliable numerical key rates for quantum key distribution. Quantum, 2:77, July 2018. 27, 29
2018
-
[29]
F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan. Secure quantum key distribution with realistic devices. Reviews of Modern Physics , 92(2), May 2020. 5 33 A Some properties of completely bounded norms and a proposi- tion In order to compute certain stabilized divergences invol...
2020
-
[30]
For α ∈ (1, 1 + 1 log η0 ), we have for all states ρ ∈ D(HEXA ) H(A|XE )ρ − Ex∼ρX [f (X)] − (α − 1)(log η0)2 ≤ H ↑,f α (A|XE )ρ ≤ H(A|XE )ρ − Ex∼ρX [f (X)] . Proof. We can get this result from the uniform continuity of R´ enyi divergences which are defined for α ∈ (0, 1) ∪ (1,...
Reviewed August 9, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.