As superconducting processors scale, understanding how physical layout shapes qubit interactions is essential for architectural reliability. Existing methods offer limited insight into how electromagnetic design choices translate into execution-level behavior. We present EPAR, an electromagnetic-to-architecture framework that predicts robustness early directly from physical design by reconstructing how design distortion modifies the effective Hamiltonian, reroutes mediated connectivity, and influences control-pulse response. Across all tested layouts, EPAR's structural scores show 100
Tiny Machine Learning (TinyML) algorithms, designed to operate on constrained devices such as those found in Internet of Things (IoT) systems, are vulnerable to adversarial threats, including fault injection attacks. These attacks exploit physical means to induce errors in computation, compromising the reliability of the device and the TinyML models running on it. This work investigates the operation of TinyML models under fault injection attacks. Through systematic experimentation with voltage glitching and EM fault injection attacks on microcontrollers, this work identifies configurations that adversaries can exploit to induce faults without triggering a system reset, thus focusing on finding the more stealthy attacks. This study analyzes four types of TinyML models, and demonstrates that all four evaluated TinyML models will generate inference outputs with reduced accuracy under the two types of fault injection attacks. Further, in some instances, this work shows that it may be feasible for the attackers to use the faults to cause inference operations to return a predictable output, not just random incorrect inference results. This highlights the need for more robust fault injection protection mechanisms in TinyML implementations. In order to provide one such protection, this work demonstrates the use of Randomized Self-Reduction (RSR) schemes and majority voting for intermediate values as a means to protect the TinyML models.
Practical applications of quantum computing depend on fault-tolerant devices that employ error correction. A promising quantum error-correcting code for large-scale quantum computing is the surface code. For this code, Fault-Tolerant Quantum Computing (FTQC) can be performed via lattice surgery, i.e. merging and splitting of encoded qubit patches on a 2D grid. Lattice surgery operations result in space-time patterns of activity that are defined in this work as access traces. This work demonstrates that the access traces reveal when, where, and how logical qubits interact. Leveraging this formulation, this work further introduces TraceQ, a tracebased reconstruction framework that is able to reconstruct the quantum circuit dataflow just by observing the patch activity at each trace entry. The framework is supported by heuristics for handling inherent ambiguity in the traces, and demonstrates its effectiveness on a range of synthetic fault-tolerant quantum benchmarks. The access traces can have applications in a wide range of scenarios, enabling analysis and profiling of execution of quantum programs and the hardware they run on. As one example use of TraceQ, this work investigates whether such traces can act as a side channel through which an observer can recover the circuit's structure and identify known subroutines in a larger program or even whole programs. The findings show that indeed the minimal access traces can be used to recover subroutines or even whole quantum programs with very high accuracy. Only a single trace per program execution is needed and the processing can be done fully offline. Along with the custom heuristics, advanced subgraph matching algorithms used in this work enable a high rate of locating the subroutines while executing in minimal time.
Quantum query is a basic subroutine in many quantum algorithms, and Quantum Random Access Memory (QRAM) provides a natural way to realize such coherent query access. In delegated settings, however, a standard QRAM query interface can expose sensitive information to the server. This paper introduces oblivious QRAM, a cryptographic abstraction for privacy-preserving delegated coherent query access. The protocol consists of an offline refresh phase and an online protected query phase. The database is stored in an encrypted and shuffled layout, and each query is protected by coherent address masking using either a quantum-secure pseudorandom permutation (qPRP) based method or a quantum one-time pad (qOTP) based method. In the adopted client model, the online protection adds only modest quantum overhead beyond the query register, avoiding the exponential quantum resources that would otherwise be required by an equivalent local QRAM construction. The qPRP-based variant also supports multi-query use by distributing database refresh across multiple queries to reduce classical communication. To address malicious servers, decoy checks are further incorporated to strengthen privacy protection and enable probabilistic tampering detection. Compared with fully blind quantum computing, this framework provides a lighter abstraction tailored to private delegated QRAM access, significantly reducing quantum resource requirements on both the client and server sides and achieving an exponential reduction in quantum communication.
To address the rapidly growing demand for cloud-based quantum computing, various researchers are proposing shifting from the existing single-tenant model to a multi-tenant model that expands resource utilization and improves accessibility. However, while multi-tenancy enables multiple users to access the same quantum computer, it introduces potential for security and reliability vulnerabilities. It therefore becomes important to investigate these vulnerabilities, especially considering realistic attackers who operate without elevated privileges relative to ordinary users. To address this research need, this paper presents and evaluates QubitHammer, the first attack to demonstrate that an adversary can remotely induce unauthorized changes to a victim's quantum circuit's qubit's state within a multi-tenant model by using custom qubit control pulses that are generated within constraints of the public interfaces and without elevated privileges. Through extensive evaluation on real-world superconducting devices from IBM and Rigetti, this work demonstrates that QubitHammer allows an adversary to significantly change the output distribution of a victim quantum circuit. In the experimentation, variational distance is used to evaluate the magnitude of the changes, and variational distance as high as 0.938 is observed. Cross-platform analysis of QubitHammer on a number of quantum computing devices exposes a fundamental susceptibility in superconducting hardware. Further, QubitHammer was also found to evade all currently proposed defenses aimed at ensuring reliable execution in multi-tenant superconducting quantum systems.
The Matrix Equivalence Digital Signature (MEDS) scheme, a code-based candidate in the first round of NIST’s Post-Quantum Cryptography (PQC) standardization process, offers competitively small signature sizes but incurs high computational costs for signing and verification. This work explores how a high-performance FPGA-based hardware implementation can enhance MEDS performance by leveraging the inherent parallelism of its computations, while examining the trade-offs between performance gains and resource costs. This work in particular proposes a unified hardware architecture capable of efficiently performing both signing and verification operations within a single combined design. The architecture jointly supports all security parameters, including the dynamic, run-time handling of different prime fields without the need to re-configure the FPGA. This work also evaluates the resource overhead of supporting different prime fields in a single design, which is relevant not only for MEDS but also for other cryptographic schemes requiring similar flexibility. This work demonstrates that custom hardware for PQC signature schemes can flexibly support different prime fields with limited resource overhead. For example, for NIST security Level I, our implementation achieves signing times of 4.5 ms to 65.2 ms and verification times of 4.2 ms to 64.5 ms utilizing 22k to 72k LUTs and 66 to 273 DSPs depending on design variant and optimization goal.
The Quantum Security and Privacy (QSec) Workshop aims to establish a focused venue dedicated to examining both the novel threats introduced by quantum technologies and the security of quantum systems themselves. By bringing together experts from traditional security domains such as post-quantum cryptography and network security, as well as from quantum computing research including quantum key distribution and quantum architectures, QSec provides a forum to expose emerging quantum-era threats by analyzing how adversaries with quantum or quantum-enhanced capabilities can undermine both classical and quantum systems. It further seeks to showcase innovative defenses by presenting hybrid cryptographic schemes, quantum-native protocols such as QKD, and hardware-level protections. In addition, the workshop aims to bridge disparate communities by fostering collaboration among researchers in cryptography, networking, architecture, and quantum information science. Finally, QSec aspires to chart a roadmap for future research by using keynotes, technical sessions, and blue-sky discussions to identify long-term challenges and research directions in quantum computing, security, and privacy. The complete QSec'25 workshop proceedings can be found at: https://dl.acm.org/citation.cfm?id=3733825
The advent of shared, cloud-based quantum computers introduces critical security vulnerabilities. This work identifies and demonstrates two novel attacks against the important HHL algorithm. The two attacks are the Improper Initialization Attack (IIA) and the Higher Energy Attack (HEA), and this work shows that both can be abused to cause HHL to output incorrect results. To address this new threat, this work presents design and implemention of a novel, low-overhead defense circuit for HHL. By adding a single ancilla qubit and minimal gates, the proposed defense reliably detects both IIA and HEA regardless which qubits (ancilla, clock, b) they target. The proposed defense is validated in simulation and on IBM quantum hardware, demonstrating its effectiveness and resilience to noise, providing a practical pathway to securing HHL against the two types of attacks.
Adversarial attacks on deep learning models have proliferated in recent years. In many cases, a different adversarial perturbation is required to be added to each image to cause the deep learning model to misclassify it. This is ineffective as each image has to be modified in a different way. Meanwhile, research on universal perturbations focuses on designing a single perturbation that can be applied to all images in a data set, and cause a deep learning model to misclassify the images. This work advances the field of universal perturbations by exploring universal perturbations in the context of traffic signs and autonomous vehicle systems. This work introduces a novel method for generating universal perturbations that visually look like simple black and white stickers, and using them to cause incorrect street sign predictions. Unlike traditional adversarial perturbations, the adversarial universal stickers are designed to be applicable to any street sign: same sticker, or stickers, can be applied in same location to any street sign and cause it to be misclassified. Further, to enable safe experimentation with adversarial images and street signs, this work presents a virtual setting that leverages Street View images of street signs, rather than the need to physically modify street signs, to test the attacks. The experiments in the virtual setting demonstrate that these stickers can consistently mislead deep learning models used commonly in street sign recognition, and achieve high attack success rates on dataset of US traffic signs. The findings highlight the practical security risks posed by simple stickers applied to traffic signs, and the ease with which adversaries can generate adversarial universal stickers that can be applied to many street signs.
Rapid advances in quantum computing hardware and software are bringing closer the promise of new discoveries and breakthroughs that these machines will enable. To fully utilize and trust the quantum computers, however, users need to have assurances about the confidentiality and integrity of quantum circuits that they execute on the quantum computers. While existing research has begun to address the issues of quantum circuit confidentiality, for example, through various obfuscation methods, there is lack of quantum computer architecture or hardware designs for ensuring and checking the integrity of quantum circuits. This gap in existing research and design of quantum computers is addressed in this paper. This work outlines the design of CHEQ, a Circuit Hashing Engine for Quantum controllers. This work first presents integrity requirements for quantum circuits, then details the design of CHEQ, along with first set of evaluation results. By providing circuit integrity measurements to users through CHEQ, quantum computing systems can become more resilient to security threats that aim to attack circuit integrity. Combined with other prior work on confidentiality, the new CHEQ integrity assurance in quantum computers can enable complete circuit protection, and thus protection of the future discoveries and breakthroughs generated by quantum computers.
Quantum computing research has experienced tremendous advancements in recent years, and real-world applications that utilize quantum hardware are continuously emerging. Large companies are investing in quantum computing for a wide range of applications, such as finance, drug discovery, secure communications, etc. As quantum computer deployment is expected to increase and be further commercialized in the upcoming years, it is vital to develop secure systems and protocols able to protect confidential data from untrusted parties. Quantum circuit cutting is a technique originally developed to compensate for the NISQ state of quantum technology, as it breaks a large quantum circuit into several smaller subcircuits that can fit into available QPUs. However, the same method can also be applied to provide security guarantees and protect the user's data from malicious third parties that own the quantum hardware. In this paper, we present a methodology for employing circuit cutting to efficiently use available QPUs and hide the submitted algorithm from potentially malicious cloud providers. We assume variable provider intelligence and introduce two obfuscation techniques, namely, virtual subcircuits and virtual cuts, to provide a modular obfuscation level.
FrodoKEM, a conservative post-quantum key encapsulation mechanism based on the plain Learning with Errors (LWE) problem, has been recommended for use by several government cybersecurity agencies and is currently undergoing standardization by the International Organization for Standardization (ISO). Despite its robust security guarantees, FrodoKEM’s performance remains one of the main challenges to its widespread adoption. This work addresses this concern by presenting a fully standard-compliant, high-performance hardware implementation of FrodoKEM targeting both FPGA and ASIC platforms. The design introduces a scalable parallelization architecture that supports run-time configurability across all twelve parameter sets, covering three security levels (L1, L3, L5), two PRNG variants (SHAKE-based and AES-based), and both standard and ephemeral modes, alongside synthesis-time tunability through a configurable performance parameter to balance throughput and resource utilization. For security level L1 on AMD Artix 7 FPGA, the implementation achieves 2,599, 2,338, and 2,147 operations per second for key generation, encapsulation, and decapsulation, respectively, representing the fastest standard-compliant performance reported to date while consuming only 37.6K LUTs, 64 DSPs, and 10.1K flip-flops. The design achieves a 2.3–159x improvement in the Area–Time Product (ATP) over all prior specification-compliant FPGA implementations. Furthermore, this work presents the first ASIC evaluation of FrodoKEM using the NANGATE45 45 nm technology library, achieving 7,721, 6,946, and 6,378 operations per second for key generation, encapsulation, and decapsulation, respectively, with a logic area of 0.250 mm2. The ASIC implementation exhibits favorable sub-linear area scaling and competitive energy efficiency across different performance parameter configurations, establishing a baseline for future comparative studies. The results validate FrodoKEM’s practical viability for deployment in high-throughput, resource-constrained, and power-sensitive cryptographic applications, demonstrating that conservative post-quantum security can be achieved without compromising performance.
This work presents the first thorough exploration of how reset operations in cloud-based quantum computers could be exploited to run quantum circuits for free. This forms a new type of attack on the economics of cloud-based quantum computers. All major quantum computing companies today offer access to their hardware through some type of cloud-based service. Due to the noisy nature of quantum computers, a quantum circuit is run many times to collect the output statistics, and each run is called a shot. The fees users pay for access to the machines typically depend on the number of these shots of a quantum circuit that are executed. Per-shot pricing is a clean and straightforward approach as users are charged a small fee for each shot of their circuit. This work demonstrates that per-shot pricing can be exploited to get circuits to run for free when users abuse recently implemented mid-circuit qubit measurement and reset operations. Through evaluation on real, cloud-based quantum computers this work shows how multiple circuits can be executed together within a shot, by separating each user circuit by set of reset operations and submitting all the circuits, and reset operations, as one larger circuit. As a result, the user is charged per-shot pricing, even though inside each shot are multiple circuits. Total per-shot cost to run certain circuits could be reduced by up to 900% using methods proposed in this work, leading to significant financial losses to quantum computing companies. To address this novel finding, this work proposes a clear approach for how users should be charged for their execution, while maintaining the flexibility and usability of the mid-circuit measurement and reset operations.
Adversarial attacks on machine learning models often rely on small, imperceptible perturbations to mislead classifiers. Such strategy focuses on minimizing the visual perturbation for humans so they are not confused, and also maximizing the misclassification for machine learning algorithms. An orthogonal strategy for adversarial attacks is to create perturbations that are clearly visible but do not confuse humans, yet still maximize misclassification for machine learning algorithms. This work follows the later strategy, and demonstrates instance of it through the Snowball Adversarial Attack in the context of traffic sign recognition. The attack leverages the human brain's superior ability to recognize objects despite various occlusions, while machine learning algorithms are easily confused. The evaluation shows that the Snowball Adversarial Attack is robust across various images and is able to confuse state-of-the-art traffic sign recognition algorithm. The findings reveal that Snowball Adversarial Attack can significantly degrade model performance with minimal effort, raising important concerns about the vulnerabilities of deep neural networks and highlighting the necessity for improved defenses for image recognition machine learning models.
Practical applications of quantum computing depend on fault-tolerant devices that employ error correction. A promising quantum error-correcting code for large-scale quantum computing is the surface code. For this code, Fault-Tolerant Quantum Computing (FTQC) can be performed via lattice surgery, i.e. merging and splitting of encoded qubit patches on a 2D grid. Lattice surgery operations result in space-time patterns of activity that are defined in this work as access traces. This work demonstrates that the access traces reveal when, where, and how logical qubits interact. Leveraging this formulation, this work further introduces TraceQ, a trace-based reconstruction framework that is able to reconstruct the quantum circuit dataflow just by observing the patch activity at each trace entry. The framework is supported by heuristics for handling inherent ambiguity in the traces, and demonstrates its effectiveness on a range of synthetic fault-tolerant quantum benchmarks. The access traces can have applications in a wide range of scenarios, enabling analysis and profiling of execution of quantum programs and the hardware they run on. As one example use of TraceQ, this work investigates whether such traces can act as a side channel through which an observer can recover the circuit's structure and identify known subroutines in a larger program or even whole programs. The findings show that indeed the minimal access traces can be used to recover subroutines or even whole quantum programs with very high accuracy. Only a single trace per program execution is needed and the processing can be done fully offline. Along with the custom heuristics, advanced subgraph matching algorithms used in this work enable a high rate of locating the subroutines while executing in minimal time.
The cloud-based environments in which today's and future quantum computers will operate raise concerns about the security and privacy of user's intellectual property, whether code, or data, or both. Without dedicated security protections, quantum circuits submitted to cloud-based quantum computer providers could be accessed by the cloud provider, or malicious insiders working in the cloud provider's data centers. Furthermore, data embedded in these circuits can similarly be accessed as it is encoded using quantum gates inside the circuit. This study presents various hardware and architecture modifications that could be deployed in today's quantum computers, based on superconducting qubits, to protect both the code and data from potentially untrusted quantum computer providers or malicious insiders. Motivated by existing Trusted Execution Environments (TEEs) in classical computers, this study introduces the notion of Quantum Trusted Execution Environments (QTEEs) which leverage trusted hardware to hide or obfuscate quantum circuits executing on a remote, cloud-based quantum computer. This study presents multiple, different approaches to design of QTEEs and considers both hardware and architecture, as well as system software and operating system support necessary for realization of QTEEs. Overall, this study presents three hardware architectures, namely, QC-TEE, SoteriaQ, and CASQUE, that have been designed to protect users' circuits and data from potential threats originating from both malicious quantum computer cloud providers or insider attackers. This study further outlines a roadmap for other possible QTEEs that can be developed in the future, to account for different threat models or to support different types of quantum computer architectures.
Emergence of fault-tolerant quantum computers (FTQC) brings about promise of harnessing the power of quantum computing at larger scale. At the same time, as quantum computers are expected to process more sensitive information, there is a need to understand the security issues in fault-tolerant quantum computers, and develop defenses for attacks that may compromise confidentiality or integrity of the data processed by FTQC. While noisy intermediate-scale quantum (NISQ) computers have already been studied from the security perspective, understanding security issues with FTQC is still an open research question. To address the missing research gap, this work presents the first exploration of possible security vulnerabilities of FTQC. The work presents analysis of possible threat models and outlines potential vulnerabilities of FTQC. Understanding the landscape of the threats can help lead to development of safer FTQC design at both software and hardware levels.
This work presents the first thorough exploration of the attacks on the interface between gate-level and pulse-level quantum circuits and pulse-level quantum circuits themselves. Typically, quantum circuits and programs that execute on quantum computers, are defined using gate-level primitives. However, to improve the expressivity of quantum circuits and to allow better optimization, pulse-level circuits are now often used. The attacks presented in this work leverage the inconsistency between the gate-level description of the custom gate, and the actual, low-level pulse implementation of this gate. By manipulating the custom gate specification, this work proposes numerous attacks: qubit plunder, qubit block, qubit reorder, timing mismatch, frequency mismatch, phase mismatch, and waveform mismatch. This work demonstrates these attacks on the real quantum computer and simulator, and shows that most current software development kits are vulnerable to these new types of attacks. In the end, this work proposes a defense framework. The exploration of security and privacy issues of the rising pulse-level quantum circuits provides insight into the future development of secure quantum software development kits and quantum computer systems.
Quantum Singular Value Transformation (QSVT) is a powerful framework that can be applied across a wide range of quantum applications, including solving linear systems of equations, phase estimation, or amplitude amplification as employed in Grover's search algorithm. QSVT is in effect a metaalgorithm that can be used to realize various other functionalities or applications. QSVT is typically configured with different polynomials to realize the different functions, and the polynomials are in turn encoded into quantum gate operations that execute on the quantum computer. If an adversary is able to recover the gate operations, specifically gate rotations and their angles, from the quantum computer, they can then attempt to recover the polynomial used, and from the polynomial they can attempt to recover the function that the victim is executing. This paper evaluates different functions implemented in QSVT and how they map to different polynomials and the phase angles. It focuses on the correlation between the phase angle values and the number of phase angles for the different functions implemented using QSVT. The paper shows that knowing the phase angle values, or even just the number of phase angles, something an attacker can learn through a side channel, allows an attacker to learn the type of functionality being implemented by QSVT.
This work explores and evaluates noise and crosstalk in neutral atom quantum computers. Neutral atom quantum computers are a promising platform for analog Hamiltonian simulations, which rely on a sequence of time-dependent Hamiltonians to model the dynamics of the larger system and are particularly useful for problems in optimization, physics, and molecular dynamics. However, the viability of running multiple simulations in a co-located or multi-tenant environment is limited by noise and crosstalk. This work conducts an analysis of how noise faced by simulations changes over time, and investigates the effects of spatial co-location on simulation fidelity. Findings of this work demonstrate that the close proximity of concurrent simulations can increase crosstalk between them. To mitigate this issue, a Moving Target Defense (MTD) strategy is proposed and evaluated. The results confirm that the MTD is a viable technique for enabling safe and reliable co-location of simulations on neutral atom quantum hardware.