{"id":"9d46c813-5b8a-4c38-aced-80a12cea920c","arxiv_id":"2607.05281","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":7.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":5,"one_line_summary":"The paper formalizes backend identifiability as hypothesis testing, proves anonymity decays at the Chernoff rate under persistent i.i.d. probing, establishes a utility-anonymity trade-off, and demonstrates 87-100% backend classification on real cloud QPUs.","lead":"This paper introduces a formal framework for 'routing anonymity' in cloud quantum computing, showing that noisy quantum hardware outputs leak backend identity, and proves exponential anonymity decay under repeated probing plus a utility-anonymity trade-off. A smart generalist reads this to understand a new privacy risk in the emerging quantum-as-a-service market: providers cannot fully hide which machine ran your computation without degrading the service.","discovery_kind":"unclear","skeptic_critique":{"model":"glm-5.2","headline":"The i.i.d. passive probing assumption is the right concern, but it limits scope rather than correctness; the theoretical results hold as stated.","rationale":"The reader's verdict of CONDITIONAL with HIGH confidence is appropriate. The theoretical core (Theorems 1–3) is correct: standard hypothesis testing results applied correctly to a novel and well-motivated setting. The i.i.d. assumption is the most significant limitation, but it is explicitly acknowledged and the result is correctly qualified as conditional on it. The utility-anonymity trade-off is a clean application of the data processing inequality. The intermediate-depth principle is idealized but clearly labeled as such.\n\nThe experimental results are supportive rather than definitive: Table 1 lacks error bars, sample sizes are modest, the intermediate-depth principle is not directly tested, and no code repository is provided. These are practical shortcomings that justify CONDITIONAL rather than ACCEPT, but none undermine the correctness of the theoretical claims.\n\nThe reader correctly identifies the i.i.d. assumption as the weakest link. I agree with the verdict and see no reason to adjust it. The concern is real but acknowledged; the theory is sound within its stated scope; and the path to resolving the concern (adaptive probing analysis) is clearly identified as future work by the authors themselves.","tokens_in":42557,"tokens_out":4512,"duration_ms":153413,"concrete_test":"Run an adaptive probing experiment on the same AWS Braket hardware (Ankaa-3 vs Garnet): at each round t, choose C_{t+1} based on the transcript X_1,…,X_t (e.g., select circuits that maximize expected information gain about the backend label). Compare the resulting identification accuracy vs. number of rounds T to the i.i.d. Chernoff prediction 1−p⋆_s(T) = exp(−T·D_Ch(P1,P2)+o(T)). If adaptive probing achieves significantly higher accuracy at the same T, the i.i.d. bound is practically misleading and the scope limitation is severe. If the gap is small, the i.i.d. assumption is less restrictive in practice than feared.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The reader correctly identifies the most significant limitation: the persistent routing model (Definition 2) restricts to passive i.i.d. probing, where all T circuits are submitted before any transcript is observed. The Chernoff rate decay (Theorem 2) is a standard result correctly applied under this assumption. The concern is that an adaptive adversary who chooses C_{t+1} based on X_1,…,X_t could identify backends faster than the Chernoff exponent suggests, making the bound an optimistic characterization of information leakage.\n\nHowever, this is a scope limitation, not a correctness issue. The theorem is explicitly conditional on the i.i.d. assumption, and the authors acknowledge this clearly. The other central results — the reduction to hypothesis testing (Theorem 1) and the utility-anonymity trade-off (Theorem 3) — do not depend on this assumption and are straightforward applications of standard results (TV distance characterization of binary hypothesis testing, data processing inequality). The utility-anonymity no-free-lunch theorem is correct: since u = ψ∘ϕ, the utility law is a deterministic post-processing of the transcript law, so TV(P1(…,u), P2(…,u)) ≤ TV(P1(…,ϕ), P2(…,ϕ)) by Proposition 2. The Chernoff information version follows similarly from data processing for f-divergences.\n\nOne additional gap the reader mentions but underweights: Theorem 3 covers only deterministic post-processing. Stochastic post-processing (e.g., adding noise to outputs) is a natural anonymization strategy not covered by the theorem as stated. The data processing inequality does extend to stochastic maps, so the bound would likely still hold under an appropriately generalized utility preservation definition, but this is not shown.\n\nThe intermediate-depth principle (Theorems 5–6) relies on strong PTM modeling assumptions (Markovian, depth-homogeneous, diagonal, common fixed point, small perturbation) that are acknowledged as idealized and not verified for the experimental devices. T","agreement_with_reader":"agree"},"referee_report":{"model":"glm-5.2","summary":"This manuscript introduces the first formal framework for backend identifiability and routing anonymity in cloud-based quantum computing. The core theoretical contributions are: (1) a game-theoretic formulation (Game 1, Game 2) in which a provider routes a user's circuit to one of several noisy backends and the user attempts to identify the backend from the classical output; (2) a reduction of optimal backend identification to classical binary hypothesis testing, yielding an exact TV-distance characterization of distinguishing bias (Theorem 1) and a Chernoff-rate decay of anonymity under persistent i.i.d. probing (Theorem 2); (3) a utility-anonymity no-free-lunch theorem showing that any utility-preserving post-processing cannot reduce distinguishability below the TV distance of the utility laws (Theorem 3); (4) an intermediate-depth principle formalized via Pauli-transfer-matrix analysis (Theorems 5–6); and (5) a workload-probed channel pseudo-distance providing tighter bounds than diamond norm (Proposition 4). Experiments on AWS Braket (Ankaa-3, Garnet, Aria-1) demonstrate 87–90% like-type and 96–100% differing-type classification, with identifiability surviving several post-processing forms.","tokens_in":43387,"tokens_out":1403,"duration_ms":258612,"significance":"The paper addresses a genuinely novel problem—provider-side routing anonymity in quantum cloud computing—that has not been formally studied. The theoretical results are clean and correctly derived from standard statistical facts (hypothesis testing, Chernoff theorem, data processing inequality). The utility-anonymity trade-off (Theorem 3) is a well-constructed no-free-lunch result that follows cleanly from the data processing inequality for TV distance and Chernoff information. The workload-probed channel pseudo-distance (Definition 11) is a practically motivated contribution that is tighter than worst-case diamond norm. The intermediate-depth principle (Theorems 5–6) provides a formal underpinning for an empirically observed phenomenon. Experiments on real hardware (AWS Braket) provide concrete evidence that the threat model is practically relevant. The framework is falsifiable: specific workloads, post-processing classes, and shot counts yield testable predictions about distinguishability.","major_comments":[{"comment":"§B.2, Theorem 3 (and Theorem 4): The no-free-lunch theorem is restricted to deterministic post-processing maps. Stochastic post-processing—e.g., adding classical noise to outputs—is a natural anonymization mechanism that a provider might employ, and is explicitly mentioned as a direction in §4 but not analyzed. Since the data processing inequality for TV distance also holds for stochastic channels (randomized post-processing), the extension should be straightforward, but its absence leaves a gap in the central utility-anonymity trade-off claim. The authors should either include the stochastic case or explicitly state in the theorem's vicinity that the result is limited to deterministic maps and that the stochastic extension is deferred, so the reader does not infer that the trade-off covers all practical anonymization strategies.","section":null},{"comment":"§C.2, Theorem 6: The lower bound on distinguishing bias at small depths depends on a 'κ-nondegeneracy' condition (Definition in Theorem 6 statement) that requires E_{C∼μ_d}[||M(N_i - N_j) r_C||_1] ≥ κ ||N_i - N_j||_{1→1}. This condition is not motivated or shown to hold for any concrete circuit ensemble. Without at least one example ensemble satisfying κ-nondegeneracy, the lower bound is vacuous. The authors should either provide a concrete example (e.g., Haar-random circuits at sufficient depth) or clearly state that this is a structural assumption whose verification is left to future work, so the intermediate-depth principle's lower bound is not presented as unconditionally established.","section":null}],"minor_comments":[{"comment":"§B.2, proof of Theorem 3: The second inequality (Chernoff information version) is stated to follow 'by a similar argument,' but the data processing inequality for Chernoff information under deterministic post-processing is less immediate than for TV distance. A one-line justification or reference would strengthen the proof.","section":null},{"comment":"§B.3, Corollary 2: The bound Adv ≤ m · max_{i≠j} δ_μ(N_i, N_j) scales linearly in m, but for large m the distinguishing bias is bounded by 1, so the bound becomes vacuous beyond m ~ 1/δ_μ. This regime limitation should be stated explicitly.","section":null},{"comment":"§2.4 and Appendix C: The PTM model assumes depth-homogeneous, Markovian noise (same N_i per layer). This is a strong simplification; the assumption list in §C.1 is thorough but the main text (§2.4) does not mention these caveats. A brief note in the main text would help readers before diving into the appendix.","section":null},{"comment":"Table 1: The notation 'a/b' in cells is not defined in the table caption. It appears to mean 'accuracy at depth d / accuracy up to depth d,' but this should be stated with a more explicit label.","section":null},{"comment":"§3: The experimental results report test accuracies but no confidence intervals or standard deviations for the depth-varied experiments (Table 1), unlike Table 2 which reports ± std. Adding error bars or at least noting the number of runs would help assess whether the reported accuracies are statistically significant.","section":null},{"comment":"§1.1, Examples 1–3: The toy examples are engaging but lengthy relative to their technical contribution. Consider condensing or moving to an appendix to keep the introduction focused.","section":null},{"comment":"The paper uses 'ε' for both the anonymity parameter (Definition 6) and the PTM perturbation bound (§C.1, Eq. C.2). Using distinct symbols would avoid confusion.","section":null},{"comment":"References [8] and [26] are self-citations that appear only loosely connected to the paper's topic. If they are not directly relevant, consider removing to avoid unnecessary self-citation.","section":null}],"recommendation":"minor_revision","confidential_remarks":"The reader's report and stress-test note correctly identify the i.i.d. passive probing assumption as the primary scope limitation. I agree this is a scope issue, not a correctness issue—the theorems are properly conditioned on the assumption and the authors acknowledge it. The two major comments I raise (stochastic post-processing gap and κ-nondegeneracy condition) are additional issues I identified that are load-bearing for the completeness of the utility-anonymity trade-off and the intermediate-depth principle respectively, but both are addressable within revision. The paper is well-suited for the journal's scope given its combination of formal security framework and experimental validation on real quantum hardware."},"author_rebuttal":{"model":"glm-5.2","summary":"We thank the referee for a careful and constructive report. Both major comments identify genuine gaps in the presentation that we will address in revision. Below we respond to each point.","responses":[{"response":"The referee is correct on both counts: the current statement of Theorem 3 (and Theorem 4) is restricted to deterministic post-processing maps, and the extension to stochastic post-processing is indeed straightforward via the data processing inequality for TV distance under Markov kernels. We will include the stochastic extension in the revised manuscript. Concretely, if the post-processing map is a stochastic channel K (a Markov kernel from Y to X) that preserves utility u in the sense that there exists a decoder channel D such that the composition D∘K reproduces the utility law, then the same DPI argument yields TV(P_1(·,·,K), P_2(·,·,K)) ≥ TV(P_1(·,·,u), P_2(·,·,u)). The proof replaces the deterministic pushforward ϕ_#Q_i with the stochastic pushforward and applies the standard DPI for TV distance under Markov kernels. The same modification applies to the approximate version (Theorem 4) and to the Chernoff information bound. We will add a remark or corollary to this effect in §B.2, and also add an explicit note in the theorem's vicinity that the original deterministic statement is a special case. We agree that this closes an important gap, since stochastic post-processing (e.g., adding calibrated classical noise to output histograms) is one of the most natural anonymization strategies a provider might consider, and the no-free-lunch result should cover it.","revision_made":"yes","referee_comment":"§B.2, Theorem 3 (and Theorem 4): The no-free-lunch theorem is restricted to deterministic post-processing maps. Stochastic post-processing—e.g., adding classical noise to outputs—is a natural anonymization mechanism that a provider might employ, and is explicitly mentioned as a direction in §4 but not analyzed. Since the data processing inequality for TV distance also holds for stochastic channels (randomized post-processing), the extension should be straightforward, but its absence leaves a gap in the central utility-anonymity trade-off claim. The authors should either include the stochastic case or explicitly state in the theorem's vicinity that the result is limited to deterministic maps and that the stochastic extension is deferred, so the reader does not infer that the trade-off covers all practical anonymization strategies."},{"response":"The referee is correct that the κ-nondegeneracy condition is a structural assumption that is not verified for any concrete ensemble in the current manuscript, and without such verification the lower bound of Theorem 6 is indeed vacuous as stated. We will address this in two ways. First, we will add an explicit remark immediately following Theorem 6 stating that the lower bound is conditional on the κ-nondegeneracy assumption and that verification of this condition for specific circuit ensembles (including Haar-random circuits) is left to future work. We will be careful not to present the lower bound as unconditionally established. Second, we will add a brief discussion of why the condition is plausible: for Haar-random circuits at sufficient depth, the ideal traceless Pauli vectors r_C are distributed roughly isotropically on a sphere of radius scaling with the system size, so the expectation E[||M(N_i - N_j) r_C||_1] should be bounded below by a constant times ||N_i - N_j||_{1→1} provided M is not too degenerate. However, we are not able to provide a rigorous proof of κ-nondegeneracy for Haar-random circuits within the scope of this revision, as it would require non-trivial concentration-of-measure arguments on the Pauli representation that we have not fully worked out. We will therefore state this as a conjecture supported by the isotropy heuristic, and make clear that the upper bound (Theorem 5) is unconditional while the lower bound (Theorem 6) is conditional.","revision_made":"partial","referee_comment":"§C.2, Theorem 6: The lower bound on distinguishing bias at small depths depends on a 'κ-nondegeneracy' condition that requires E_{C∼μ_d}[||M(N_i - N_j) r_C||_1] ≥ κ ||N_i - N_j||_{1→1}. This condition is not motivated or shown to hold for any concrete circuit ensemble. Without at least one example ensemble satisfying κ-nondegeneracy, the lower bound is vacuous. The authors should either provide a concrete example (e.g., Haar-random circuits at sufficient depth) or clearly state that this is a structural assumption whose verification is left to future work, so the intermediate-depth principle's lower bound is not presented as unconditionally established."}],"tokens_in":42266,"tokens_out":1503,"duration_ms":54174,"standing_objections":[]},"desk_editor":{"model":"glm-5.2","letter":"This paper introduces routing anonymity as a provider-side security notion for quantum cloud computing — the question of whether a service provider can hide which physical backend executed a user's circuit. That framing is genuinely new. The existing fingerprinting literature [43-48] takes the user-side perspective; nobody had formalized the provider's privacy problem. The game-based definition (Game 1-2) is clean, and the reduction to classical hypothesis testing is correct: Theorem 1 (TV distance characterization) and Theorem 2 (Chernoff rate decay under i.i.d. persistent routing) are standard results properly applied. The utility-anonymity no-free-lunch theorem (Theorem 3) is the right observation — it follows from the data processing inequality, and the proof is straightforward. The workload-probed channel pseudo-distance (Definition 11) is a sensible average-case measure that is tighter than diamond norm for this setting, which aligns with recent work on average-case quantum distances [80-81]. The intermediate-depth principle (Theorems 5-6) is a nice formalization of an intuition that practitioners already hold. The experiments on AWS Braket (Ankaa-3, Garnet, Aria-1) are supportive: 87-90% like-type and 96-100% differing-type classification confirms that backend fingerprints are real and survive post-processing. The temporal batch classification (Table 2) with proper negative controls is well-designed. The stress-test concern about the i.i.d. passive probing assumption is the right thing to flag, but it limits scope rather than correctness. The theorem is explicitly conditional on that assumption, and the authors acknowledge it. An adaptive adversary could identify backends faster, but that is a future-work problem, not a flaw in what is proven. One genuine gap the reader underweights: Theorem 3 covers only deterministic post-processing. Stochastic post-processing (adding classical noise to outputs) is a natural anonymization strategy, and the data processing inequality does extend to stochastic maps, so the bound likely generalizes — but this is not shown. The PTM modeling assumptions for the intermediate-depth principle (Markovian, depth-homogeneous, diagonal, common fixed point) are acknowledged as idealized and not verified for the experimental devices. The experiments do not directly test the intermediate-depth principle, though Table 1 shows trends consistent with it. Minor issues: Table 1 lacks error bars, sample sizes are modest, no code repository URL despite referencing one, and there are typographical errors and figure rendering problems. None of these undermine the central claims. This paper is for researchers in quantum cloud security and quantum information theory. It deserves a serious referee who can verify the proofs in the appendix and push the authors to address the stochastic post-processing gap and the experimental presentation.","headline":"New security framework for quantum cloud routing anonymity; theory is clean but experiments need polish.","tokens_in":43470,"tokens_out":639,"would_cite":true,"duration_ms":116096,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"glm-5.2","headline":"Quantum cloud backends leak identity through noisy output","keywords":[],"falsifier":"If two backends with different physical noise profiles produce transcript distributions whose total variation distance is zero (or exponentially small) under all allowed workloads and post-processing maps, then the framework predicts perfect anonymity. Conversely, if the Chernoff information between transcript laws is zero, the exponential decay bound predicts no anonymity loss, which would be falsified if backends remain distinguishable through some other channel not captured by the transcript law.","tokens_in":42709,"feed_emoji":"🔐","tokens_out":978,"duration_ms":115883,"temperature":0.7,"pith_summary":"This paper introduces the first formal framework for routing anonymity in cloud-based quantum computing, asking whether a service provider can hide which physical quantum processor ran a user's circuit when the noisy output distribution carries device-specific fingerprints. The authors define a backend-identifiability game between a user and provider, then prove that identifying the backend from output transcripts is exactly a classical hypothesis-testing problem. Under passive independent probing of a fixed backend, routing anonymity decays exponentially at the Chernoff rate. A no-free-lunch theorem establishes that any post-processing preserving the promised service utility cannot reduce backend distinguishability below the level inherent in the utility output itself. The authors also prove an intermediate-depth principle: backend-specific noise signals first grow with circuit depth, then decay as common mixing dominates. Experiments on three real quantum processors via Amazon Braket show 87-90% classification between same-platform superconducting devices and 96-100% across platforms, with identifiability surviving several natural post-processing transformations.","feed_headline":"Quantum cloud backends leak identity through noisy output","feed_subtitle":"Noisy quantum hardware fingerprints let users identify which device ran their circuit, and anonymity decays exponentially with repeated use.","key_machinery":"The backend identifiability game (Game 1) and its persistent routing extension (Game 2); reduction to classical hypothesis testing via total variation distance and Chernoff information; the utility-preserving no-free-lunch theorem (Theorem 3); the intermediate-depth principle proved in a Pauli-transfer-matrix model with dominant mixing and backend-specific perturbation; the workload-probed channel pseudo-distance as a tighter bound than diamond norm.","core_discovery":"The central object is the reduction of backend identifiability to classical hypothesis testing over transcript laws. When a provider routes a user's circuit to a hidden quantum backend and returns a post-processed output distribution, the user's ability to identify the backend is governed by the total variation distance between the transcript distributions induced by each backend. In the multi-round persistent routing setting, anonymity decays as exp(-T * Chernoff information), meaning repeated probing exponentially erodes the provider's privacy. The utility-anonymity trade-off theorem then bounds how much a provider can strip identifying information: if post-processing must preserve a given","pith_inferences":["An adaptive adversary who chooses each probe circuit based on prior transcripts could identify backends faster than the Chernoff rate suggests, making the exponential decay bound an optimistic lower bound on information leakage under more realistic threat models.","Stochastic post-processing maps, which are not analyzed in this work, could potentially offer strictly better anonymity-utility trade-offs than deterministic ones by adding controlled randomness that further obscures backend-specific signals.","If noise forecasting models improve sufficiently, users could predict future backend noise patterns from past observations, creating an additional deanonymization vector even without explicit adaptive access, since predicted fingerprints could inform workload design."],"forward_implications":["Cloud quantum providers cannot assume routing choices are hidden simply because backend labels are not exposed; noisy output distributions carry learnable fingerprints even between devices of the same physical platform type.","Any anonymity mechanism that preserves service utility is fundamentally limited by how much backend-specific information is already encoded in the utility output, giving providers a concrete design target for privacy-preserving post-processing.","The intermediate-depth principle implies that providers should be most cautious about information leakage at moderate circuit depths, where backend-specific noise has accumulated but common mixing has not yet washed it out.","Workload choice is a security-critical parameter: highly structured circuits like GHZ preparations allow near-perfect backend identification, suggesting providers should restrict or monitor such workloads.","Temporal drift in backend noise creates an additional identification channel beyond static fingerprints, meaning long-term persistent routing is especially vulnerable to deanonymization."],"fun_headline_variants":["Noisy quantum outputs leak which backend ran your circuit","Quantum hardware fingerprints survive post-processing at 96% accuracy","Backend anonymity in quantum clouds decays exponentially with use","Classical outputs from quantum hardware carry identifying fingerprints","Routing anonymity flagged as security gap in quantum cloud services"],"cache_read_input_tokens":0,"weakest_assumption_plain":"The persistent routing model assumes the user submits all probe circuits before observing any results (passive i.i.d. access) and that the backend label is fixed throughout. An adaptive adversary who chooses each circuit based on prior transcripts could identify backends faster than the Chernoff rate suggests. The utility-anonymity trade-off also assumes deterministic post-processing maps; stochastic post-processing is not analyzed.","fun_headline_variants_meta":{"raw":{"variants":["Noisy quantum outputs leak which backend ran your circuit","Quantum hardware fingerprints survive post-processing at 96% accuracy","Backend anonymity in quantum clouds decays exponentially with use","Classical outputs from quantum hardware carry identifying fingerprints","Routing anonymity flagged as security gap in quantum cloud services"]},"model":"glm-5.2","effort":"high","cost_usd":0.0,"raw_usage":{"total_tokens":730,"prompt_tokens":654,"completion_tokens":76,"prompt_tokens_details":null},"tokens_in":654,"tokens_out":76,"duration_ms":25504,"temperature":1.0,"reasoning_tokens":null,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-07T19:50:23.646039+00:00","model_set":{"reader":"glm-5.2"},"falsifier":"If two backends with different physical noise profiles produce transcript distributions whose total variation distance is zero (or exponentially small) under all allowed workloads and post-processing maps, then the framework predicts perfect anonymity. Conversely, if the Chernoff information between transcript laws is zero, the exponential decay bound predicts no anonymity loss, which would be falsified if backends remain distinguishable through some other channel not captured by the transcript law.","supporting_citations":[],"review_version":1}