quantum computer with neural network visualization

Quantum Neural Network Security: Kill-Chain Attacks on QNNs

Quantum machine learning is moving from theory to real quantum hardware. This creates new security risks. In a recent study, researchers from Fraunhofer AISEC and partners demonstrated a multi-stage attack on a quantum neural network running on trapped-ion hardware. The attack combines side-channel analysis, adversarial examples and crosstalk. For providers, product teams and decision-makers, the message is clear: quantum AI needs security by design before it becomes a critical infrastructure.

Quantum computing is no longer only a topic for physics labs. Cloud access to quantum processors is growing. At the same time, quantum machine learning, or QML, is maturing as a research field: Research shifts from simple proof-of-concept algorithms to principled benchmarking that measures not only speed and performance to identify potential quantum advantages but also aspects like robustness and security.

Every new computing model also brings a new attack surface. The paper “An End-to-End Multi-Stage Kill-Chain Attack on Quantum Neural Networks” shows this very clearly. The authors demonstrate that a quantum neural network, or QNN, can be attacked across several layers. Not only at the software level. Not only through noisy hardware. But as a connected attack chain. This is important for IT security teams, product engineers and managers. Future quantum services will likely be shared, cloud-based and integrated into existing workflows. If quantum models make decisions in finance, logistics, medicine or industrial control, their reliability becomes a security issue.

The key contribution of the paper is the system view. The authors do not analyze one isolated weakness. They show how an attacker can combine several techniques:

  • learning about a victim model through side channels,
  • generating adversarial inputs,
  • using hardware crosstalk to influence the model during execution.

This is exactly the kind of thinking that cybersecurity needs for emerging technologies.

Why QML Security Needs a Kill-Chain View

In classical cybersecurity, attacks often follow a chain. First comes reconnaissance, then access and then manipulation, persistence or impact. Frameworks such as MITRE ATT&CK help defenders understand these steps.

The paper transfers this idea to quantum machine learning.

A QML system has several layers:

  • the training data,
  • the quantum circuit,
  • the classical optimizer,
  • the quantum hardware,
  • the control electronics,
  • the cloud platform around it.

A weakness in one layer may enable an attack in another layer. For example, timing or power information from the hardware may reveal parts of the quantum circuit. This knowledge can then help an attacker to place disturbances at the right time.

This is why the authors use a quantum-aware kill-chain model. It helps structure attacks and defenses. It also supports a defense-in-depth strategy. For security teams, this is familiar ground. For quantum computing, it is still a young but necessary discipline.

Key Terms: QNNs, Side Channels and Crosstalk

A quantum neural network is a machine learning model based on parameterized quantum circuits. Classical data is encoded into qubits. The circuit processes this data. Measurements are then used to produce a prediction.

In the paper, the victim model is a variational quantum classifier. It classifies simple image-like symbols into four classes. The model uses re-upload encoding. This means that input features are inserted into the quantum circuit several times as rotation angles.

Three technical terms are central:

  • Side-channel attack: An attacker does not directly access the secret model. Instead, they observe indirect signals. In this case, simulated power traces reveal information about the quantum circuit.
  • Adversarial example: A small change to the input causes a machine learning model to make a wrong prediction. Such attacks are well known in classical AI and also affect QML.
  • Crosstalk: Operations on one qubit unintentionally influence neighboring qubits. In trapped-ion systems, this can happen when laser pulses slightly affect nearby ions.

Individually, these issues are already relevant. Combined, they become much more powerful.

The Method: A Multi-Stage Attack on Real Hardware

The researchers built an end-to-end attack pipeline. It mirrors how a capable attacker could proceed against a deployed quantum machine learning service.

The attack has three main stages.

1. Reconnaissance with Power Traces

First, the attacker tries to learn the structure of the victim QNN. The paper focuses on power-trace analysis. Quantum gates are executed through physical control pulses. These pulses leave patterns in power consumption.

The researchers compare the victim’s power trace with traces from benchmark circuits. This allows them to infer important properties:

  • number of qubits,
  • number of circuit layers,
  • entangling structure,
  • timing of relevant gates.

In the experiment, this step reliably identifies the structure of the victim QNN. This is a critical result. Once the structure and timing are known, later attacks become more targeted.

2. Adversarial Example Generation

Next, the authors generate adversarial examples. They use Projected Gradient Descent, a standard method from adversarial machine learning.

The idea is simple. The attacker slightly changes the input until the model changes its classification. In simulation, the trained QNN is highly vulnerable. For 840 out of 1000 training samples, the researchers find successful adversarial perturbations with a limited perturbation size.

The impact is severe. Accuracy drops from over 90 percent on normal inputs to almost zero under adversarial perturbation.

This result confirms that QNNs share a major weakness with classical neural networks: small, carefully chosen input changes can break model behavior.

3. Physical Manipulation Through Crosstalk

The third stage is the most interesting from a hardware security perspective. Instead of directly changing the input data, the attacker tries to create a similar effect physically. They apply rotation gates on neighboring qubits. Due to crosstalk, these operations induce small unwanted rotations on the victim qubits. On the AQT trapped-ion hardware used in the study, only certain rotations are suitable for this. Virtual RZ gates do not create physical pulses and therefore do not cause the same crosstalk effect. The attack is therefore constrained to input components encoded through RY rotations.

This makes the attack harder. But it also makes the result more realistic. The method respects the physical limits of the device.

The researchers then execute selected circuits on real trapped-ion hardware. They compare three cases:

  • clean input,
  • adversarial input,
  • clean input with crosstalk-based disturbance.

The crosstalk attack does not perfectly reproduce the simulated adversarial input. Real hardware noise and shot noise matter. Still, the results show that the crosstalk construction moves the hardware behavior closer to the adversarial behavior. This is an important proof of concept.

What the Results Mean

The paper provides several important findings for cybersecurity professionals.

First, side-channel information can reveal more than expected. In the tested setting, power traces were enough to reconstruct the relevant QNN architecture. This matters for quantum cloud providers and for organizations that may operate quantum hardware on premise.

Second, QNNs are vulnerable to adversarial examples. This is not only a theoretical issue. If QML models are used in security-critical decisions, robustness testing becomes mandatory.

Third, hardware effects can be used as part of an attack. Crosstalk is often treated as a noise source or engineering problem. The paper shows that it can also become a security primitive for attackers.

Fourth, the combination is the real risk. Reconnaissance enables targeted manipulation. Hardware knowledge improves attack precision. Model-level weaknesses become more dangerous when the attacker can influence the physical execution environment.

This is the core cybersecurity lesson: quantum machine learning must be assessed as a system, not as an isolated algorithm.

Defensive Strategies for Quantum AI Systems

The paper also discusses possible defenses. They span hardware, software and operational controls.

For power side channels, useful measures include:

  • decoy pulses to make traces harder to interpret,
  • power randomization to reduce recognizable patterns,
  • constant-power operation in control electronics,
  • strict control of diagnostic and pulse-level access.

For adversarial robustness, teams should consider:

  • adversarial training,
  • robustness evaluation during development,
  • regularization methods,
  • monitoring of model confidence and abnormal inputs.

For crosstalk-based attacks, system-level controls are essential:

  • avoid multi-tenant execution where possible,
  • isolate sensitive workloads,
  • randomize scheduling and circuit placement,
  • characterize crosstalk continuously,
  • include hardware noise models in security testing.

These defenses are not yet standardized like classical IT controls. This is why research is so important. Fraunhofer AISEC works on exactly these questions: how to make emerging technologies secure before they become widely deployed.

Why This Matters for Companies

Many companies are still in the observation phase of quantum computing. That is understandable. But security teams should not wait until quantum machine learning becomes operational.

Product engineers who design security-critical systems should ask early:

  • What happens if a QML model misclassifies?
  • Can the model be tested against adversarial inputs?
  • Does the quantum provider allow shared execution?
  • What telemetry is exposed?
  • Are side channels considered in the threat model?
  • Who is responsible for quantum-specific risk assessment?

Managers and CEOs should view this as a governance topic. Quantum computing will enter supply chains through cloud services, APIs and specialized optimization products. Security requirements must be part of procurement and architecture decisions.

The lesson is not that quantum machine learning is insecure by default. The lesson is that it must be engineered securely from the start.

Conclusion

The paper demonstrates a complete multi-stage attack against a quantum neural network on trapped-ion hardware. It combines side-channel reconnaissance, adversarial example generation and crosstalk-based physical manipulation. The results show that QML security cannot be reduced to algorithmic robustness or hardware quality alone. The interaction between model, compiler, control electronics, hardware noise and cloud operation is decisive.

Open questions remain. How do these attacks scale to larger QML models? Which defenses are practical for commercial quantum cloud providers? How should future standards define secure multi-tenant quantum execution? How can robustness guarantees be measured in noisy quantum systems and what influence will quantum error correction have? These are exactly the questions that Fraunhofer AISEC investigates with partners from industry, research and public institutions.

For organizations planning quantum or AI-based products, now is the right time to build security expertise. If you want to assess QML risks, design secure quantum workflows or evaluate future standards, the authors and Fraunhofer AISEC are ready to discuss the next steps.

The corresponding paper, currently under review but already available as preprint, was written by the following authors: Cedric Bürgmann, Daniel Herr, Daniel Ohl de Mello, Pascal Debus, Maximilian Wendlinger, Kilian Tscharke, Juris Ulmanis, Alexander Erhard, Arthur Schmid and Fabian Petsch.

Author
Portraitfoto von Pascal Debus, Leitung der Abteilung Cognitive Security Technologies am Fraunhofer AISEC
Pascal Debus

Pascal Debus is head of the Cognitive Security Technologies department at Fraunhofer AISEC. He is also the director of the Bavarian Competence Center for Quantum Security and Data Science (BayQS). Pascal Debus holds a master’s degree in physics from ETH Zurich. His research focuses on quantum computing, quantum security, and machine learning.

Most Popular

Never Miss a Post:

 
Bitte füllen Sie das Pflichtfeld aus.
Bitte füllen Sie das Pflichtfeld aus.
Bitte füllen Sie das Pflichtfeld aus.

* Mandatory

* Mandatory

By filling out the form you accept our privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Other Articles

quantum computer with neural network visualization

Quantum Neural Network Security: Kill-Chain Attacks on QNNs

Quantum machine learning is moving from theory to real quantum hardware. This creates new security risks. In a recent study, researchers from Fraunhofer AISEC and partners demonstrated a multi-stage attack on a quantum neural network running on trapped-ion hardware. The attack combines side-channel analysis, adversarial examples and crosstalk. For providers, product teams and decision-makers, the message is clear: quantum AI needs security by design before it becomes a critical infrastructure.

Read More »

Fault Attacks on ECC Signature Verification

Digital signatures used in embedded systems are often based on elliptic curve cryptography (ECC) thanks to its performance and low memory profile. In secure boot processes they provide the cryptographic foundation for guaranteeing the authenticity of a firmware image. At the same time, these resource-constraints and the physical exposure of such devices makes them prime targets for fault attacks. Prior work studied faults on signature generation in depth, yet nobody had systematically asked how vulnerable signature verification is to fault attacks combined with carefully crafted signature inputs. That is exactly the gap we set out to close.

Read More »
Visual of the Blog Post: How Secure Is Europe's Rail System? A Systematic Cybersecurity Risk Analysis of the ERTMS

How Secure Is Europe’s Rail System? A Systematic Cybersecurity Risk Analysis of the European Rail Traffic Management System (ERTMS)

The European Rail Traffic Management System (ERTMS) is designed to make Europe’s railways interoperable and safe. The system, which has been mandatory since 2002, combines standardized signaling, radio communication, and train control – but how well is it protected against cyberattacks? Using MoRA, our modular risk assessment approach, we systematically model the ERTMS and evaluate cybersecurity risks. We compare current and future configurations to identify the assets with the largest attack surface. Our overview of the entire system – from GSM-R, balises, FRMCS, ETCS levels, and ATO to key management – provides a concise preview of risk profiles and attack tree scenarios, and highlights practical countermeasures that significantly improve cybersecurity.

Read More »
Viisual for blog post: Codyze: Automated Analysis of Cybersecurity Requirements in Software

Codyze: Automated Analysis of Cybersecurity Requirements in Software

Manually verifying compliance with requirements such as the Cyber Resilience Act is not scalable. Our code analysis tool, Codyze, translates product-centric regulatory requirements into verifiable rules and automatically assesses whether the product’s source code fulfills them – across languages and microservices. Codyze makes all analysis results transparent to developers, security teams, and auditors.

Read More »
WordPress Cookie Plugin by Real Cookie Banner