REVIEW 3 major objections 5 minor
Quantum random-number generator with non-demolition measurements: semi-device-independent implementation
T0 review · 3 major / 5 minor · reviewed 2026-07-30 · grok-4.5
Pith's one-line read A tripartite non-demolition setup certifies quantum path superposition on one detector while a second detector emits near-uniform three-outcome random numbers at the same time, without needing spacelike separation.
desk verdict Solid dual-detector QNDM QRNG idea with clean algebra and a real min-entropy trade-off; the semi-DI/source-independent security claim overreaches what the model actually proves. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The quantum non-demolition measurement quasi-probability distribution P_ND(Δ) = P_cl + P_q reconstructed from D1: negativity of P_q is treated as a necessary and sufficient signature of path superposition that a classical probability source cannot reproduce, while the same couplings set the three-outcome statistics of D2.
What would settle it
Build the proposed three-level system plus two detectors, reconstruct P_ND from D1 while collecting D2 strings, and check whether clear negativity appears together with a near-uniform three-outcome average and min-entropy consistent with the stated bound; absence of negativity when the designed unitary and state should produce it, or classical spoofing of the same negativity under the actual couplings, would refute the claim.
Extended reading notes
Core claim
In a QNDM tripartite architecture, detector D1’s reconstructed quasi-probability P_ND certifies path superposition via negativity while detector D2 simultaneously emits outcomes β in {0, ±2} whose λ-averaged distribution can be optimized near-uniform. The min-entropy of the full string is lower-bounded by LK log(3/(1+3|P_q(−1)|)), and an optimized spin-1 example reaches about 90% of maximal extractable randomness while still showing clear negativity.
Load-bearing premise
The security claim rests on trusting the measurements of both detectors and on the assertion that observed negativity in the quasi-probability cannot be faked by a classical device sampling a genuine probability distribution.
Editorial extensions
If this is right
- Randomness generation and quantum certification can run on the same compact chip without spacelike-separated modules.
- Initial state and unitary can be tuned to trade a controlled amount of min-entropy for stronger negativity certification.
- Adding further non-demolition couplings or higher-dimensional detectors is predicted to enlarge the outcome alphabet and improve extractable randomness.
- The protocol supplies a concrete semi-device-independent (source-independent) QRNG route that needs no input random seed.
Reading between the lines
- Because certification and generation share the same physical runs, finite-sample statistical tests of negativity directly bound the usable randomness rate in real time.
- Integrated platforms that already support spin-1 or qutrit control (cold atoms, superconducting circuits, NV centers) are natural first testbeds for a proof-of-principle device.
- If classical models can reproduce the observed P_ND negativity under realistic noise and finite L, the semi-DI security argument would need an explicit noise-tolerant reformulation.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a QRNG based on a tripartite quantum non-demolition measurement setup: a three-level system S coupled to a two-level detector D1 and a three-level detector D2. D1 reconstructs a quasi-probability P_ND whose negativity certifies path superposition, while D2 simultaneously emits outcomes β∈{0,±2} whose λ-averaged distribution can be optimized near uniformity. A min-entropy bound H_min(X)≥LK log(3/(1+3|P_q(−1)|)) links extractable randomness to certified negativity. An optimized spin-1 example achieves relative min-entropy deficit ~9.81% (bound δ≈15.2% at |P_q(−1)|≈0.06). Certification needs no spacelike separation. The protocol is presented as semi-device-independent/source-independent with trusted detector measurements.
Significance. If the construction and scoped security claims hold, this is a practically relevant alternative to Bell and Leggett–Garg QRNGs: simultaneous generation and certification without spatial separation, plus an explicit trade-off between quasi-probability negativity and min-entropy. The unitary evolution, reduced detector states, path indexing, Â degeneracy, and P_q(β)↔P_q(Δ) identities are derived carefully in the text and Appendix. The optimization example is concrete. Even with a narrower security model, the architecture contributes to semi-DI randomness and to applications of QNDM witnesses.
major comments (3)
- [Random number generator; Eq. (5); Appendix (S17)–(S31)] The source-independent/semi-DI claim overreaches what is proven. The text says the user need not know preparations “not even … assumptions on the state dimensions,” and that Eq. (5) certifies randomness against source manipulation. The bound and identities P_q(β=0)=cos(λ_l)P_q(−1), P_q(β=2)=−cos(λ_l)P_q(−1) (Appendix after S22–S24) hold only inside the fixed model: 3-level S, stated â/Â spectra, U1/U2 couplings, and path degeneracy tying A_4,7 to β=0. No reduction shows an arbitrary source reproducing the observed G_λ must obey the same D2 bias. Restate security to match trusted readouts and model assumptions, or supply a proper reduction.
- [System and set-up; Eqs. (3)–(4); P_ND decomposition] Security against classical spoofing of P_ND negativity under this protocol is imported from prior QNDM work [21,22] without a self-contained argument for these couplings and finite (L,K) sampling. The claim that negative regions cannot be reproduced by a classical device sampling a probability distribution must address D2’s decoherence functional f(n,k) and finite Fourier sampling of G_λ. A short classical-simulation bound under trusted readouts is needed for certification to be load-bearing here.
- [Random number generator; Conclusions] The trusted vs untrusted partition is under-specified for a semi-DI claim. The paper notes that “measurements of detectors D1 and D2 need to be trusted,” yet still frames the protocol as source-independent in the sense of Refs. [24,25]. Clarify in one place which operations are trusted (D1/D2 measurements, couplings, dimensions) and which are untrusted (source state and û), and what adversarial power observed negativity alone rules out.
minor comments (5)
- [Fig. 2] Figure 2 caption/panel labels are hard to parse in the manuscript rendering. Ensure the published figure clearly separates P_ND(Δ) from P̄_β and reports the numerical parameters.
- [System and set-up; Appendix] The mapping n=1+3(i+1)+(j+1) is dense; a small table of (i,j)↔n, α_n, β_n would help verify degeneracy β∈{0,±2} and the identification of A_4,7, A_5,8, A_6,9.
- [Application; Conclusions] In Application/Conclusions, “more than 90% … genuinely random” should be tied explicitly to ΔH_min/H̄_min∼9.81% versus the looser δ≈15.2% bound.
- [Introduction; Eqs. (1)–(2)] Typos: “a posteriorion” → “a posteriori on”; occasional ρ_f vs ρ̄_f switches; M in U2 is not fixed numerically in the example.
- [Introduction; Conclusions] Brief comparison of rate and entropy per shot with LGI QRNGs [15,16] and photonic source-independent QRNGs would better position the practical gain.
Circularity Check
Mild self-citation load on the QNDM negativity criterion; min-entropy trade-off is derived inside the model, not forced by definition.
-
self citation load bearing
[Introduction; System and set-up (after Eq. 3 / P_ND decomposition); Refs. [21, 22]]
"it has been shown that QNDM provides a stronger criterion than the LGI for the identification and certification of quantum behavior [21, 22]. ... the negativity of P_ND(Δ) provides a necessary and sufficient signature of path superposition in the dynamics [21, 22]. Such negative regions cannot be reproduced by a classical device that generates the corresponding strings from an underlying probability distribution."
The operational meaning of D1 certification—that observed negativity of the reconstructed quasi-probability is necessary and sufficient for genuine path superposition and cannot be faked by a classical probability sampler—is not derived in this manuscript; it is taken from the authors’ earlier QNDM papers. The QRNG security/certification narrative rests on that imported lemma. This is load-bearing self-citation for the certification claim, though the entropy algebra itself is computed independently inside the present model.
full rationale
The paper’s central algebraic content—the path-labeled detectors’ state, the explicit link P_q(β=0)=cos(λ_l)P_q(−1) and P_q(β=2)=−cos(λ_l)P_q(−1), and the resulting min-entropy lower bound H_min(X)≥LK log(3/(1+3|P_q(−1)|))—is derived in the main text and Appendix from the assumed tripartite couplings, spectra, and degeneracy structure. That is a legitimate trade-off calculation within a fixed model, not a quantity redefined as its own input. The only circularity-adjacent element is interpretive: the claim that negativity of P_ND is a necessary and sufficient signature of path superposition that a classical sampler cannot reproduce is imported from the authors’ prior QNDM papers [21, 22] rather than re-proved here. That self-citation is load-bearing for the certification narrative and the semi-DI framing, but it does not make the entropy bound or the optimized near-uniform example tautological. No fitted-input-called-prediction, uniqueness-import, or ansatz-smuggling pattern appears. Score 2 reflects one mild self-citation burden with independent central derivation.
Assumptions & free parameters
free parameters (3)
- Initial state amplitudes ψ0_i and relative phase Δφ=φ1−φ0 =
ψ0_−1≈0.76, |ψ0_0|≈|ψ0_1|≈0.46, Δφ=π/2
- Evolution angle θ in û=exp(iθ Ĵx) =
θ≈π/3
- Discretization L and shots K per λ_l =
L≳30 (example); K free
assumptions (5)
- standard math Standard quantum mechanics on finite-dimensional Hilbert spaces with unitary couplings and Born-rule readout of detectors.
- domain assumption â and  on S commute and share the stated eigenbasis (a_i=i, A_i=1 for i=0,1 and A_−1=−1), enabling joint path labeling.
- domain assumption Negativity of the QNDM quasi-probability P_ND is necessary and sufficient for path superposition and cannot be reproduced by a classical device sampling a genuine probability distribution.
- domain assumption Measurements on D1 and D2 are trusted; only the source/evolution need not be characterized (semi-DI / source-independent stance).
- ad hoc to paper Detector dimensions and coupling forms (phase encoding U1, U2 with M-level Fourier readout on D2) are as assumed; user need not know preparations but dimensions are fixed in the analysis.
Cite this review
Pith. "Pith review of Quantum random-number generator with non-demolition measurements: semi-device-independent implementation." pith.science (2026). https://pith.science/paper/KNPU3SFN
@misc{pith2026260727025,
author = {Pith},
title = {Pith review of: Quantum random-number generator with non-demolition measurements: semi-device-independent implementation},
year = {2026},
howpublished = {\url{https://pith.science/paper/KNPU3SFN}},
note = {Machine review of arXiv:2607.27025}
}
read the original abstract
We propose and analyze a novel quantum random-number generator based on a tripartite quantum system in which two subsystems act as detectors. Within a quantum non-demolition measurement scheme, one detector is used to certify the presence of genuine quantum effects in the system's evolution, while the second generates random numbers from a distribution that can be optimized to maximize their entropy. Using one two-level system and two three-level systems, we generate random numbers from a nearly uniform three-outcome distribution, yielding close-to-maximal entropy and therefore near-optimal randomness generation. A key feature of the protocol is that randomness generation and certification occur simultaneously. Moreover, certification does not rely on spacelike separation between detectors, removing a major constraint of device-independent approaches. This property enables practical implementation and facilitates the miniaturization of the device, making the protocol a promising candidate for scalable quantum technologies.
Figures
Reviewed July 30, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.