{"id":"cecd3733-9321-4c54-89a9-15e47a949f68","arxiv_id":"2502.10115","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":0,"one_line_summary":"Crosstalk along qubit SWAP routes on shared IBM quantum hardware enables both remote disruption and passive size leakage between circuits.","lead":"Researchers report that crosstalk between distant qubits on IBM's shared quantum computers can disrupt a victim's circuit with a single CNOT gate, and can leak information about the victim circuit's size. The result matters because it challenges the common defense of keeping attacker and victim qubits far apart on the chip.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The central multi-tenant-concurrency assumption is asserted, not demonstrated; all experiments appear to run attacker and victim in a single composite circuit, so without evidence of concurrent independent jobs the attack scenario has no demonstrated real-world instance.","rationale":"The reader's weakest assumption identifies exactly the load-bearing gap: Section III.B assumes concurrent multi-tenant execution, while the experiments appear to use composite circuits. My stress-test concurs, and I would not move the verdict because the reader already returned CONDITIONAL. A negative outcome of the concurrency test would justify moving to REJECT, since the central attack scenario would not exist on current hardware; a positive outcome would leave the SWAP-path mechanism as a plausible, though still in-sample, demonstration. Experiment 2 deserves credit as a controlled comparison with intersecting versus non-intersecting positions, but it only shows crosstalk inside a single submitted job if no separate-tenant concurrency is shown. The passive attack's 100% accuracy is also evaluated on the same configurations used to build the signature database, a secondary concern that would matter after the multi-tenancy issue is resolved. The proposed check directly settles the load-bearing assumption by testing whether two independent jobs can overlap on the same device.","tokens_in":13243,"tokens_out":4669,"duration_ms":51603,"concrete_test":"Run a two-job concurrency test on ibm_brisbane using two independent IBM Quantum credentials or Qiskit Runtime sessions: submit Job A as the victim Grover circuit on qubits 63,64 and Job B as the attacker CNOT on qubits 0 and 69 at the same time, then retrieve backend job metadata to check whether the execution intervals overlap. If Job B starts only after Job A completes, the platform serializes tenant jobs and the attack scenario cannot occur. In parallel, inspect the raw OpenQASM payloads from the paper's experiments: if each submitted program contains both victim and attacker circuits, the reported results are single-program crosstalk, not multi-tenant attacks.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section III.B states that the attacker can run its circuit on a multi-tenant device 'simultaneously with the victim's circuit.' This is the precondition for both attack modes: the active attack needs the attacker's CNOT/SWAPs to execute during the victim's computation, and the passive attack needs the listening circuit to measure crosstalk from a concurrently executing Simon circuit. The paper never demonstrates this precondition on real hardware. The Experimental Setup (Section V.A) says only that jobs were 'queued back-to-back,' which describes sequential execution of separate jobs, while the reported circuits (Figs. 3, 5, 9) appear to embed victim and attacker qubits into one composite program. If the cloud provider schedules independent tenant jobs serially, the observed 'SWAP path intersection' effect is a property of a single transpiled circuit, not a cross-tenant attack, and the 81.62% disruption and 100% passive prediction do not transfer to the claimed threat model. The SWAP-path crosstalk itself is plausible, and Experiment 2 is a controlled demonstration, but it validates a different claim than the paper's headline.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a crosstalk-based side-channel attack on multi-tenant quantum cloud systems, attributing the effect to the SWAP path between distant qubits rather than simple proximity. In the active mode, a single attacker CNOT gate is claimed to degrade a victim's Grover circuit by up to 81.62% (Table I). In the passive mode, a small 'listening' circuit is claimed to predict the size and output of a victim's Simon's algorithm circuit with 100% accuracy (Section V.D) while being as small as 6.25% of the victim circuit. The authors argue this challenges existing topological-distance defenses. Experiments are performed on ibm_brisbane, and Experiment 2 provides a controlled comparison of victim positions intersecting versus not intersecting the attacker's SWAP path.","tokens_in":13384,"tokens_out":3948,"duration_ms":43018,"significance":"If the central multi-tenant concurrency premise were demonstrated and the passive evaluation were not circular, the results would be a meaningful security contribution: Experiment 2 shows a credible correlation between SWAP-path intersection and output deviation, and the idea that crosstalk signatures can leak algorithm parameters is worth investigating. The paper also gives useful empirical grounding for questioning distance-based circuit-isolation defenses. However, the significance is currently conditional on three load-bearing issues: the lack of evidence that independent tenant jobs run concurrently, the training/test overlap in the passive attack evaluation, and the absence of statistical error analysis. The paper's strengths are the controlled Experiment 2 and the explicit exploration of attacker circuit-size versus prediction accuracy, but these do not by themselves establish the claimed cross-tenant attack scenario.","major_comments":[{"comment":"The attack model assumes that 'the attacker can run its circuit on a multi-tenant quantum device simultaneously with the victim's circuit,' but the Experimental Setup only states that jobs were 'queued back-to-back,' and the figures (Figs. 3, 5, 9, 12) appear to embed attacker and victim qubits into a single composite circuit. Please provide direct evidence that independent tenant jobs execute concurrently on ibm_brisbane (e.g., overlapping execution intervals, provider scheduling documentation, or a control experiment with separately submitted jobs). As written, the experiments validate SWAP-path crosstalk in a single transpiled circuit, not a cross-tenant attack, and the headline results do not transfer to the claimed threat model.","section":"Section III.B and Section V.A"},{"comment":"The passive attack evaluation is circular: the Signature Dataset is built from the same 32 circuit sizes (or 128 output values) that are later 'tested,' and the MSE matrices in Figs. 9, 10, and 13 compare each Test entry against Learn entries of the identical configuration set. Under Acc1 = (n - i)/n, the true class is always present in the database, so nearest-neighbor matching can trivially rank it first; the reported 100% accuracy is a training-set result rather than an independent prediction. Please evaluate on held-out configurations, a different calibration window, or with proper cross-validation, and report performance on unseen circuit instances.","section":"Section IV.B and Section V.D, Eq. (2)"},{"comment":"The headline numbers (e.g., 81.62% in Table I and 81.96% in Table II) are single observed accuracy values with no error bars, no repeated runs across calibration windows, and no explicit no-attack control for each configuration beyond the 'No Attack' rows in Table II. Because crosstalk deviations are comparable in magnitude to ordinary hardware drift, please provide repeated independent runs with standard errors or confidence intervals, and describe how calibration drift was excluded as an alternative explanation.","section":"Section V.A, Tables I and II"},{"comment":"The paper repeatedly claims that the active attack 'can be clearly explained through modeling' and that specific qubits 'can be identified as more susceptible,' but no model is actually defined or evaluated in Sections IV or V; the only formula provided is the MSE in Eq. (1), which is a comparison metric, not a predictive model of attack severity. Please either present the model (with its parameters, fit quality, and validation) or remove these modeling claims from the abstract and text.","section":"Abstract, Section IV.A, Section V.B"}],"minor_comments":[{"comment":"The text says 'seed transpile = 0'; please clarify whether this refers to Qiskit's seed_transpiler parameter, and state whether the same seed was used for every circuit and whether the transpiler was aware that attacker and victim qubits were part of one composite circuit.","section":"Section V.A"},{"comment":"The text describes Confidence as a difference in normalized MSE values, but Eq. (3) shows a raw difference between MSEl and MSEs; please define the normalization and state the units or scale of the reported confidence values.","section":"Eq. (3)"},{"comment":"The term 'SW AP' appears instead of 'SWAP' in many places (including the title, abstract, and section headings); please fix the formatting.","section":"Throughout"},{"comment":"The damage categories are defined with overlapping ranges: moderate is listed as both 40-60% and 40-60%, but the text also mentions 'No Attack' for deviations below 20% and minor for 20-40%; please define a single non-overlapping threshold table.","section":"Section IV.A"},{"comment":"The sentence 'Although we were unable to replicate previous works on the ibm brisbane quantum device, the proposed SWAP-induced attacks would render previously proposed defense strategies... ineffective' is internally hedged; please report what was attempted in the replication and separate that from the claim about the proposed attack.","section":"Section II"},{"comment":"The passive attack assumes the attacker knows the victim's qubit positions; this is stated, but its practical feasibility (how the attacker obtains the allocation) should be discussed, since it is a strong assumption for the claimed threat model.","section":"Section IV.B"}],"recommendation":"major_revision","confidential_remarks":"I would encourage the editor to weigh whether the security framing is supportable as is. The multi-tenant concurrency premise is asserted but not demonstrated, and the passive attack's 100% accuracy appears to be a training-set artifact. Experiment 2 is a solid controlled demonstration of SWAP-path crosstalk, so the paper could be repositioned as a crosstalk characterization study, but in its current form the headline attack claims are not yet established."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The thing to know: Experiment 2 is a well-designed control. With the attacker fixed on qubits 0 and 108, the victim's accuracy drops only when its qubits intersect the SWAP path, and stays near baseline otherwise. That is direct evidence that SWAP-path intersection, not just distance, drives the crosstalk effect. The single-CNOT active variant and the passive size-inference circuit are genuinely new relative to Harper et al. and Saki et al., which used repeated CNOTs and nearby qubits. The paper is also honest that it could not replicate the earlier attacks on ibm_brisbane.\n\nThe soft spots are real and one is load-bearing. The paper assumes, in Section III.B, that the attacker can run a circuit simultaneously with the victim on a multi-tenant device. Nothing in the experiments demonstrates this. The setup section says only that jobs were 'queued back-to-back,' which describes sequential execution, and the figures appear to show a single composite circuit with victim and attacker qubits in one program. If independent tenant jobs are not co-scheduled, the claimed attack scenario does not exist on current IBM hardware. The crosstalk mechanism may still be interesting, but it would be an intra-circuit effect, not a cross-tenant attack. The passive attack has a second, independent problem: the signature database is built from the same 32 circuit configurations that are later classified, so the 100% accuracy is a nearest-neighbor lookup on training data, not a generalization result. There are also no error bars or repeated runs anywhere, and the abstract promises modeling that never appears in the body.\n\nTaken together, the evidence supports the physical mechanism—SWAP-path crosstalk degrades co-located circuits—but does not support the headline claims about multi-tenant cloud attacks. The flaws are addressable: a direct test of concurrent independent jobs, held-out evaluation for the passive attack, and error bars on the accuracy numbers would do a lot.\n\nThis paper is for quantum cloud security researchers. It deserves a serious referee rather than a desk reject, because the core observation is novel and the fixes are concrete. If I were the editor, I would send it to review with a request for evidence of concurrency, held-out passive tests, and error analysis. If those do not materialize, reject; but the paper is not a waste of referee time.","headline":"A clean controlled demonstration of SWAP-path crosstalk, but the multi-tenant attack premise is unsubstantiated and the passive results are in-sample.","tokens_in":13974,"tokens_out":2778,"would_cite":true,"duration_ms":28519,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A crosstalk attack based on the SWAP routing path lets an attacker disrupt a victim's quantum circuit from a distance with a single CNOT gate, and passive listening can infer the victim's circuit size with 100 percent accuracy.","keywords":["quantum cloud security","crosstalk attack","side-channel attack","SWAP path","multi-tenant quantum computing","Grover's algorithm","Simon's algorithm","qubit allocation"],"falsifier":"Submit two independent jobs from separate cloud accounts to the same 127-qubit device at the same time and check the execution logs: if they are never executed concurrently but queued sequentially, the attack scenario as described has no real target. A second check would be to reproduce the active one-CNOT result with attacker and victim submitted as separate jobs, instead of assembled into one composite circuit; if the effect disappears, the reported 81.62 percent outcome is an artifact of co-compilation rather than remote crosstalk.","tokens_in":12992,"feed_emoji":"⚛️","tokens_out":6497,"duration_ms":58170,"temperature":0.7,"pith_summary":"This paper tries to show that crosstalk noise on multi-tenant quantum cloud processors is determined by the SWAP path taken to route two-qubit gates between distant qubits, and that this creates a practical side channel. Its active attack places one attacker CNOT gate so that the SWAP path crosses the victim's qubits, reducing the accuracy of a victim's Grover circuit by up to 81.62 percent on a real 127-qubit cloud device. Its passive attack runs a tiny listening circuit whose measured crosstalk deviations form a signature, and matches that signature to predict Simon's circuit size with 100 percent accuracy using only four optimally chosen qubits. If the claims hold, the common defense of separating circuits by topological distance is not sufficient for shared quantum clouds.","feed_headline":"One distant CNOT gate cuts Grover's output accuracy by 81.62%","feed_subtitle":"A four-qubit listening circuit also predicts a victim's circuit size with 100 percent accuracy.","key_machinery":"The load-bearing object is the SWAP path: the chain of qubits and SWAP gates a compiler inserts to perform a two-qubit operation between non-adjacent qubits. The paper's mechanism is that running a CNOT between two attacker qubits excites crosstalk along that entire routing path, so the attacker does not need to be physically adjacent to the victim. In the passive attack, the machinery is the crosstalk signature: for each candidate victim configuration, the attacker's listening qubits record how many measured 1s deviate from the expected all-zero output, and the victim's live signature is matched to the stored set with mean squared error. The qubit selection strategies (optimal, default, non-optimal) order listening qubits by how much they deviate, which is what lets four qubits be enough for perfect size prediction.","core_discovery":"The central claim is that the SWAP path between two attacker-controlled qubits acts as a crosstalk conduit: when the victim's qubits lie on that path, the victim's output is corrupted with high probability, even though the attacker and victim are far apart on the device. The paper reports that a single CNOT gate on the attacker side can lower the victim's expected output accuracy to 18.38 percent (an 81.62 percent deviation) in the best case, and that the severity depends on which qubit pairs are chosen. In the passive variant, the same SWAP-path effect leaks information: an empty listening circuit produces an all-zeros output that the victim's SWAP-heavy routing perturbs, and the resulting pattern acts as a fingerprint. With optimal qubit selection the attacker needs only four listening qubits to identify which of 32 Simon circuit sizes is running, and 22 listening qubits to identify a 7-bit hidden shift with perfect accuracy.","pith_inferences":["If concurrent execution of independent jobs turns out not to exist on current clouds, the attack still demonstrates a real hardware coupling, but its threat model would need a scheduler that does co-schedule; a natural extension is to test the same SWAP-path attack on a cloud that guarantees concurrent multi-tenant execution.","The passive signature method is a template side channel: with a larger training set it could in principle fingerprint other algorithmic parameters, such as the specific oracle or secret shift, not just circuit size, on any platform where concurrent execution is available.","The strength of the qubit-selection effect suggests that a defense based on randomizing SWAP routing, instead of maximizing distance, could break the stable signatures the passive attack relies on, though that is an inference beyond the paper's own experiments."],"forward_implications":["If attackers can choose any qubit pair whose SWAP path crosses the victim's qubits, topological separation alone does not protect a circuit.","A single CNOT is enough for disruption, so defenses that look for repeated CNOT patterns will not detect the active attack.","The passive attack works with a measurement-only circuit of just four qubits for size prediction, making it hard to spot by circuit-size anomaly.","Qubit selection matters as much as count: with the same 22 listening qubits, optimal placement gives 100 percent accuracy while non-optimal placement drops to 46.87 percent.","The effect was validated on a real 127-qubit cloud processor, so it is not purely a simulation result."],"supporting_citations":[{"why":"the prior crosstalk attack on shared quantum devices that this work extends, and whose circuit-separation defense it challenges.","marker":"[24]"},{"why":"provides the framework for detecting and localizing crosstalk errors that grounds the paper's crosstalk attribution.","marker":"[19]"},{"why":"analyzes noise and security risks in multi-programming quantum environments, motivating the attack model.","marker":"[20]"},{"why":"shows that crosstalk arises during parallel gate operations and supplies the definition of crosstalk the paper builds on.","marker":"[18]"},{"why":"the victim algorithm in the active attack experiments, whose output accuracy is measured.","marker":"[25]"},{"why":"the victim algorithm in the passive attack experiments, whose circuit size and hidden shift are inferred.","marker":"[28]"},{"why":"a prior multi-CNOT crosstalk attack that the single-CNOT design improves upon.","marker":"[26]"},{"why":"the antivirus defense that the lightweight one-CNOT design is meant to bypass.","marker":"[27]"}],"fun_headline_variants":["One CNOT gate on a SWAP path cuts Grover's accuracy by 81.62%","Quantum cloud attack: SWAP path lets a single gate leak circuit size","Four-qubit listener on quantum cloud predicts victim's circuit size","SWAP path crosstalk enables stealthy attack on quantum cloud","One CNOT gate via SWAP path causes 81.62% accuracy drop"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key assumption is that the cloud provider runs the attacker's job and the victim's job at the same time on the same processor; the paper states this as an attack capability but gives no evidence that today's cloud scheduler actually co-schedules independent jobs.","fun_headline_variants_meta":{"raw":{"variants":["One CNOT gate on a SWAP path cuts Grover's accuracy by 81.62%","Quantum cloud attack: SWAP path lets a single gate leak circuit size","Four-qubit listener on quantum cloud predicts victim's circuit size","SWAP path crosstalk enables stealthy attack on quantum cloud","One CNOT gate via SWAP path causes 81.62% accuracy drop"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000818,"raw_usage":{"total_tokens":3620,"prompt_tokens":1020,"completion_tokens":2600,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":636,"completion_tokens_details":{"reasoning_tokens":2499}},"tokens_in":636,"tokens_out":2600,"duration_ms":17628,"temperature":1.0,"reasoning_tokens":2499,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T19:19:43.793072+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Submit two independent jobs from separate cloud accounts to the same 127-qubit device at the same time and check the execution logs: if they are never executed concurrently but queued sequentially, the attack scenario as described has no real target. A second check would be to reproduce the active one-CNOT result with attacker and victim submitted as separate jobs, instead of assembled into one composite circuit; if the effect disappears, the reported 81.62 percent outcome is an artifact of co-compilation rather than remote crosstalk.","supporting_citations":[{"cited_title":"Crosstalk Attacks and Defence in a Shared Quantum Computing Environment","cited_arxiv_id":"2402.02753","evidence_quote":"the prior crosstalk attack on shared quantum devices that this work extends, and whose circuit-separation defense it challenges."},{"cited_title":"Impact of noise on the resilience and the security of quantum computing,","cited_arxiv_id":null,"evidence_quote":"analyzes noise and security risks in multi-programming quantum environments, motivating the attack model."},{"cited_title":"Software mitigation of crosstalk on noisy intermediate-scale quantum computers,","cited_arxiv_id":null,"evidence_quote":"shows that crosstalk arises during parallel gate operations and supplies the definition of crosstalk the paper builds on."},{"cited_title":"A fast quantum mechanical algorithm for database search,","cited_arxiv_id":null,"evidence_quote":"the victim algorithm in the active attack experiments, whose output accuracy is measured."},{"cited_title":"On the power of quantum computation,","cited_arxiv_id":null,"evidence_quote":"the victim algorithm in the passive attack experiments, whose circuit size and hidden shift are inferred."},{"cited_title":"Analysis of crosstalk in nisq devices and security implications in multi-programming regime,","cited_arxiv_id":null,"evidence_quote":"a prior multi-CNOT crosstalk attack that the single-CNOT design improves upon."},{"cited_title":"Design of quantum computer antivirus,","cited_arxiv_id":null,"evidence_quote":"the antivirus defense that the lightweight one-CNOT design is meant to bypass."}],"review_version":1}