{"id":"65681e81-d9a6-4623-a11d-350eed4acd04","arxiv_id":"2504.19064","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":2.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A review of security vulnerabilities, especially side-channel and crosstalk attacks, in multi-tenant quantum cloud platforms.","lead":"Quantum computers are now offered over the cloud, and several users often share the same machine. This survey collects the known ways attackers can spy on or disrupt other users' circuits on these shared systems.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Survey's 'comprehensive' map rests on a narrow, unreported literature sample with no inclusion criteria or completeness check.","rationale":"I agree with the reader's weakest assumption: the survey's representativeness is the main load-bearing assumption behind its 'comprehensive' claim. The paper has no systematic methodology, and its cited attack literature is concentrated in a small set of groups and hardware types. This does not mean the survey is worthless; it can still be useful as a focused reading list. However, the central claim as stated is not verifiable from the paper itself. I also note additional citation and table-presentation defects, but those are fixable and secondary to the coverage question. The conditional verdict remains appropriate: the paper should be accepted only with the requirement that the 'comprehensive' claim be scoped or backed by a documented search method.","tokens_in":11587,"tokens_out":11289,"duration_ms":125594,"concrete_test":"Run a reproducible literature search for 2020-2025 across IEEE Xplore, ACM Digital Library, and arXiv using the query 'quantum AND cloud AND (side-channel OR multi-tenant OR crosstalk OR SFQ)'. Deduplicate the results, categorize them by hardware platform and attack type, and check whether every attack category represented in the result set appears in Sections V-VII or is explicitly excluded with a stated reason. If an unmentioned attack category or hardware platform appears, the comprehensive claim is unsupported; if the coverage is complete, the concern is resolved.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central claim is that it delivers a comprehensive, reliable map of quantum-cloud threats, but the survey never specifies how the primary literature was gathered. Sections II and IX describe related work and research gaps, but they contain no search protocol, inclusion criteria, or completeness check. The attack corpus is concentrated in a small cluster of research groups and almost entirely focuses on superconducting qubits and SFQ control electronics, while the abstract and Section I claim broad coverage of quantum cloud systems. This makes the 'comprehensive' claim non-falsifiable: a reader cannot distinguish a complete map from a convenience sample. The issue is internal to the survey's purpose: unlike a new experimental result, a survey's central claim is exactly about coverage, so the absence of a reproducible corpus is not cosmetic. The paper even gestures at a narrower scope in Section V.B, where it says multi-tenant threats and the classical-quantum interface will be the 'primary focus,' but the abstract and conclusion still assert comprehensiveness. That tension should be resolved, either by documenting the search methodology or by explicitly scoping the claim.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This survey reviews security vulnerabilities in quantum cloud systems, with an emphasis on multi-tenant environments and the classical-quantum interface. It describes quantum hardware architectures, collects recent attack families (crosstalk side-channels, timing attacks, qubit-flipping attacks, insider threats on SFQ control electronics), and discusses proposed mitigations. The authors also present a threat evaluation table mapping attacks to the CIA triad and offer research-gap recommendations. The paper claims to be a comprehensive analysis, though Section V.B narrows the focus to two threat areas.","tokens_in":11729,"tokens_out":6179,"duration_ms":55725,"significance":"If the survey were accurate and comprehensive, it would serve as a useful entry point for researchers and cloud providers, especially given the recency of the collected works (2024–2025). The paper includes visual models, attempts to map attacks to confidentiality/integrity/availability, and highlights the QubitHammer and SWAP attack literature that is unlikely to be familiar to a general security audience. However, the survey's reliability is currently undermined by systematic citation errors and an undocumented literature-selection process; these issues need to be addressed before the contribution can be fully credited.","major_comments":[{"comment":"The reference labels in Table I are systematically wrong, which undermines the survey's reliability. Specifically, 'Securing the Cloud Infrastructure...' is labeled [7] but is reference [8]; 'A reference architecture for quantum computing as a service' is labeled [8] but is reference [9]; 'Distributed quantum computing: a survey' is labeled [9] but should be [10]; 'Technological diversity of quantum computing providers...' is labeled [10] but should be [11]; 'A survey of side-channel attacks in superconducting quantum computers' is labeled [11] but should be [7]; and 'Detecting fraudulent services on quantum cloud platforms via dynamic fingerprinting' is labeled [13], the same label as 'Quantum leak: Timing side-channel attacks...', although the former is reference [21]. All labels in the table and in the associated text need to be corrected.","section":"Table I"},{"comment":"The paper claims in the Abstract and Section X to provide a 'comprehensive analysis' of security challenges in quantum cloud systems, but it never describes a search protocol, inclusion criteria, or completeness check. Section II (Related Works) and Section IX (Research Gaps) discuss literature but do not delimit how the primary sources were chosen. The collected attacks are concentrated on superconducting qubits and SFQ control electronics, with no stated justification for omitting trapped-ion and photonic platforms. Section V.B narrows the scope to multi-tenant threats and the classical-quantum interface, contradicting the broad claim. The authors should either document their methodology or explicitly revise the paper's scope claim.","section":"Sections II, V.B, IX"},{"comment":"Table II is not consistently interpretable. Different rows contain different numbers of entries; for example, the 'Passive SW AP Attack' row lists only 'Yes High,' while the 'Active SW AP Attack' row lists 'Yes Yes Moderate.' The accompanying text in Section II.C states that SWAP attacks focus on the availability of quantum computers, yet the Availability column appears blank for both rows. The table's column alignment should be repaired, and its entries should be reconciled with the narrative.","section":"Table II and Section II.C"}],"minor_comments":[{"comment":"'Amazon Bracket' should be 'Amazon Braket'.","section":"Section II.A"},{"comment":"The acronym 'SQF' appears in place of 'SFQ' (single flux quantum) in several places; the spelling should be made consistent.","section":"Sections II.E and VI.A"},{"comment":"'SW AP' should be written as 'SWAP' throughout, including in the table and the text.","section":"Table II and Section II.C"},{"comment":"The phrase 'multi-tenant treats' should read 'multi-tenant threats'.","section":"Section V.B"},{"comment":"The term 'DOS attacks' should be 'DoS attacks'.","section":"Section IV"},{"comment":"The descriptions of reference [7] in Sections II.B and V.A are nearly verbatim duplicates; one instance should be removed or rewritten.","section":"Sections II.B and V.A"}],"recommendation":"major_revision","confidential_remarks":"The citation errors in Table I are extensive and suggest a referencing failure that the authors need to address systematically. The paper is probably better framed as a focused survey of multi-tenant and classical-quantum interface threats rather than as a comprehensive survey of all quantum cloud security, given the narrow literature sample. If the authors are willing to make these structural and accuracy corrections, the paper could be publishable; I would be willing to review a revised version."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a narrative review, not a systematic survey, and it's most useful as a fairly up-to-date reading list on multi-tenant quantum cloud attacks and classical-quantum interface threats. It doesn't break new ground, but it organizes recent work (QubitHammer, SWAP attack, reset threats, SFQ side channels) into one place, with two decent figures and a gap list that points in sensible directions. For a practitioner or grad student wanting a first map of the area, it has real value.\n\nThe strengths: the coverage of crosstalk-based side channels and the classical-quantum interface is reasonably faithful to the cited papers. The paper correctly emphasizes that multi-tenancy changes the threat model, and it distinguishes confidentiality/integrity/availability impacts. It also cites primary sources rather than only other surveys, which is good.\n\nThe soft spots are real. The 'comprehensive' claim in the abstract and conclusion is not supported by any described search protocol or inclusion criteria; the corpus is mostly a handful of groups working on superconducting qubits and SFQ electronics. Section V.B actually narrows the focus to two topics, so the fix is easy: either document the method or scope the claim. Second, Table I has citation errors—[13] is assigned to two different papers, and the 'Securing the Cloud Infrastructure' entry is labeled [7] when [7] is the Choudhury/Basu survey. That's sloppy and undermines confidence. Third, Table II's 'Threat Level' column is undefined and some rows are inconsistent (e.g., Passive SWAP has Integrity empty but is High; Active has Integrity yes but Moderate). The stress-test concern about the narrow sample lands; it's the main structural weakness. The citation errors are a smaller but annoying problem.\n\nWho is this for? People who want a quick orientation to recent side-channel and multi-tenancy attacks in quantum clouds, not researchers seeking rigorous analysis. With corrected citations, a scoped title/abstract, and a defined threat-level rubric, I'd send it to a workshop or a short-paper venue. As it stands, I'd still give it a serious referee rather than desk reject, because the topic is timely and the core summaries are mostly accurate. My recommendation: peer review, but with the expectation of a heavy revision pass.","headline":"A timely but scattershot survey of quantum-cloud security that is useful as a reading list if you can look past the citation errors and the overbroad 'comprehensive' claim.","tokens_in":12242,"tokens_out":2850,"would_cite":false,"duration_ms":29717,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Multi-tenant quantum clouds are vulnerable to crosstalk, timing, and qubit-flipping attacks that current defenses do not stop, the survey argues.","keywords":["quantum computing","quantum cloud","quantum security","NISQ","multi-tenancy","privacy risks","crosstalk","classical-quantum interface"],"falsifier":"Run the crosstalk-based circuit-reconstruction attack on a non-superconducting multi-tenant quantum cloud platform, such as a trapped-ion service; if a co-located attacker cannot recover victim circuit information, then the survey's central generalization about multi-tenant vulnerability does not extend to that platform, and the comprehensiveness claim is weakened.","tokens_in":11370,"feed_emoji":"⚛️","tokens_out":6677,"duration_ms":59201,"temperature":0.7,"pith_summary":"The paper sets out to establish that quantum cloud services, as currently built around shared multi-tenant hardware and a classical control layer, have a security gap that is broader and more concrete than earlier surveys suggest. Its central claim is that side-channel and interference attacks—crosstalk between co-located qubits, timing measurements, qubit-flipping pulses, and leakage from single-flux-quantum control circuits—can reveal or corrupt a user's quantum circuit, threatening confidentiality, integrity, and availability. The survey organizes these attacks around two under-covered areas, multi-tenant vulnerabilities and the classical-quantum interface, and argues that proposed mitigations are either theoretical, expensive, or demonstrably bypassed. If the paper is right, researchers and businesses running circuits on shared quantum clouds should treat circuit privacy as an open problem rather than a solved one, and providers face a direct tradeoff between performance and security.","feed_headline":"Multi-tenant quantum clouds leak secrets through crosstalk and timing","feed_subtitle":"A survey maps attacks on shared quantum hardware and warns current defenses are costly or ineffective.","key_machinery":"The paper's central objects are the multi-tenant NISQ cloud model and the classical-quantum interface. In the multi-tenant model, many users share one quantum processor, and crosstalk—the unwanted interaction between nearby qubits—is the mechanism that carries most of the attacks: it leaks information about a victim's circuit and lets an attacker induce errors. At the classical-quantum interface, the mechanism is leakage from single-flux-quantum (SFQ) control and readout electronics, specifically bias-current variations in SFQ-to-DC converters, which an insider can monitor to recover internal signals. These two mechanisms structure the survey's threat taxonomy, its CIA impact table, and its evaluation of mitigations.","core_discovery":"The paper's central claim is that the security of quantum cloud systems fails at two specific points. On multi-tenant NISQ platforms, crosstalk between qubits assigned to different users creates a side-channel: an attacker can infer details of a victim's circuit—such as CNOT gate counts and timing—and, with graph-based models, reconstruct circuits; related attacks use the SWAP path, reset operations, or qubit control pulses to corrupt or leak data, with the QubitHammer attack bypassing existing defenses. At the classical-quantum interface, an insider with access to room-temperature SFQ control electronics can read bias-current variations to decode control signals and qubit readout, enabling circuit recovery or reverse engineering. The survey maps these threats onto the CIA triad, evaluates their feasibility and damage, and concludes that current countermeasures—camouflaging, logic locking, zero-trust architectures, encryption, antivirus-style circuit scanning—are either too costly, untested, or ineffective, leaving a need for low-overhead and hardware-appropriate security mechanisms.","pith_inferences":["If crosstalk-based circuit extraction generalizes beyond the tested superconducting systems, multi-tenant clouds may have to shift from concurrent sharing to time-sliced exclusive access, trading utilization for privacy—a cost the paper does not quantify.","The same timing fingerprints used to identify a quantum processor in an attack could be repurposed by providers as a monitoring and auditing tool to detect unauthorized hardware switching, turning the paper's threat into a defense.","The QubitHammer result suggests testing physical-layer defenses—such as pulse-shape filtering or qubit-frequency allocation—against repeated pulse injection, an experimental direction the paper lists as future work rather than its own result.","A survey that sampled non-superconducting platforms, such as trapped-ion or photonic clouds, could reveal a different side-channel profile; the paper's hardware focus is a limitation rather than a closed case."],"forward_implications":["Multi-tenant quantum cloud users cannot assume that their circuits remain confidential: crosstalk-based attacks can recover enough circuit structure to reconstruct it.","Existing defenses in the literature—dynamical decoupling, crosstalk-aware qubit allocation, active padding, and reset changes—do not reliably stop qubit-flipping and crosstalk exploits.","Insider attacks on the classical-quantum interface are feasible but require privileged physical access, so protecting them mainly means access control and least privilege plus low-overhead circuit obfuscation.","Performance and security are in direct tension: stronger measures such as blind quantum computing, encryption, camouflaging, and logic locking slow execution or add overhead, so providers may resist them.","More research is needed on cost-effective mitigations, particularly for crosstalk and reset leakage, before shared quantum clouds can protect sensitive workloads in medicine and finance."],"supporting_citations":[{"why":"Supplies the crosstalk side-channel framework and graph-based circuit reconstruction that anchors the multi-tenant threat model.","marker":"[6]"},{"why":"Defines the insider threat model for the classical-quantum interface and SFQ bias-current leakage.","marker":"[3]"},{"why":"Provides the baseline survey of side-channel attacks in superconducting quantum computers that this survey extends toward multi-tenancy.","marker":"[7]"},{"why":"Introduces the SWAP-path crosstalk attack used to classify availability and integrity impacts.","marker":"[19]"},{"why":"Documents timing side-channel attacks on cloud quantum services, including processor identification with ten measurements.","marker":"[13]"},{"why":"Presents the QubitHammer qubit-flipping attack that bypasses known defenses and motivates the paper's mitigation gap.","marker":"[35]"},{"why":"Shows side-channel leakage in SFQ circuits and attacks on qubit control and readout at the classical-quantum interface.","marker":"[29]"},{"why":"Proposes zero-trust architectures, encryption, and access control as multi-tenant mitigations the paper evaluates.","marker":"[14]"}],"fun_headline_variants":["Crosstalk leaks circuits in multi-tenant quantum clouds","Quantum cloud side-channel: crosstalk reveals circuits","Insider threat in quantum clouds: SFQ electronics leak secrets","Quantum cloud defenses fall short: crosstalk and insider attacks"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The survey's picture of the quantum cloud threat landscape is only as representative as its cited sources, which concentrate on superconducting qubits and SFQ control electronics; if other hardware platforms have different vulnerabilities, the claimed comprehensiveness does not hold.","fun_headline_variants_meta":{"raw":{"variants":["Crosstalk leaks circuits in multi-tenant quantum clouds","Quantum cloud side-channel: crosstalk reveals circuits","Insider threat in quantum clouds: SFQ electronics leak secrets","Quantum cloud defenses fall short: crosstalk and insider attacks"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000539,"raw_usage":{"total_tokens":2570,"prompt_tokens":912,"completion_tokens":1658,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":528,"completion_tokens_details":{"reasoning_tokens":1590}},"tokens_in":528,"tokens_out":1658,"duration_ms":11551,"temperature":1.0,"reasoning_tokens":1590,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T10:01:28.839876+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the crosstalk-based circuit-reconstruction attack on a non-superconducting multi-tenant quantum cloud platform, such as a trapped-ion service; if a co-located attacker cannot recover victim circuit information, then the survey's central generalization about multi-tenant vulnerability does not extend to that platform, and the comprehensiveness claim is weakened.","supporting_citations":[{"cited_title":"Side-channel attacks targeting classical- quantum interface in quantum computers,","cited_arxiv_id":null,"evidence_quote":"Defines the insider threat model for the classical-quantum interface and SFQ bias-current leakage."},{"cited_title":"A survey of side-channel attacks in superconducting quantum computers,","cited_arxiv_id":null,"evidence_quote":"Provides the baseline survey of side-channel attacks in superconducting quantum computers that this survey extends toward multi-tenancy."},{"cited_title":"Side-channel leakage in sfq circuits and related attacks on qubit control and readout systems,","cited_arxiv_id":null,"evidence_quote":"Shows side-channel leakage in SFQ circuits and attacks on qubit control and readout at the classical-quantum interface."},{"cited_title":"Enhancing security and privacy in advanced computing systems: A comprehensive analysis,","cited_arxiv_id":null,"evidence_quote":"Proposes zero-trust architectures, encryption, and access control as multi-tenant mitigations the paper evaluates."}],"review_version":1}