REVIEW 4 major objections 4 minor 1 cited by
Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security
T0 review · 4 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read A five-stage kill chain model maps published quantum machine learning attacks into a single lifecycle, showing how physical, algorithmic, and data-level threats chain together.
desk verdict Useful framework paper whose central claim about revealing multi-stage dependencies overshoots the evidence, but it is a legitimate and honest contribution that deserves a serious referee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying object is the five-stage kill chain model together with its technique schema. Each mapped technique carries six attributes—stage assignment, attacker role, attacker capabilities, prerequisites, impacted components, and possible defenses—so that a technique is defined not only by what it does but by who can execute it, what must already be true, and what it enables next. The schema is what turns a taxonomy into a chain: prerequisites link one technique to an earlier stage, and capabilities link an attacker profile to a set of reachable techniques. A compact matrix summarizes the mapping at technique granularity.
What would settle it
If the model is correct, every published QML attack should fit one of the five stages and known attack pairs should chain. A direct test is to try to construct a concrete end-to-end campaign from the matrix—say side-channel reconnaissance followed by transpiler trojan insertion followed by model exfiltration—on real cloud quantum hardware; failure to execute any such chain, or the existence of a published attack that fits no stage, would falsify the claim that the kill chain organizes the QML attack surface.
Extended reading notes
Core claim
The central claim is that the QML attack surface is best understood as an attack lifecycle rather than a static list of vulnerabilities. The authors propose a five-stage QML kill chain—Reconnaissance, Initial Access, Model Access and Manipulation, Persistence, and Exfiltration or Impact—and map published attacks onto it. Each technique is described by attacker role, required capabilities, prerequisites, impacted components, and possible defenses. The mapping shows, for example, that side-channel reconnaissance at the first stage can feed gate injection or backdoor insertion at later stages, and that noise-injection techniques apply to both training and inference. The paper further claims this is the first kill chain model tailored to QML and that it reveals gaps, such as the lack of formal threat models in the literature and the absence of demonstrated multi-stage attacks.
Load-bearing premise
The model assumes QML runs on cloud-based, multi-tenant quantum hardware where an attacker can be a co-tenant or compromise the transpiler and control electronics, so if QML is deployed on trusted single-tenant hardware with local compilation, the quantum-specific kill chains mostly disappear.
Editorial extensions
If this is right
- If the model is adopted, defenders can prioritize mitigation by stage, for example by using hardware isolation and random scheduling at the reconnaissance stage to cut off later circuit manipulation opportunities.
- Published single-stage attacks can be reinterpreted as parts of larger campaigns; poisoned data at the initial access stage becomes a persistence mechanism when it embeds a trigger that fires only later.
- The requirement to state attacker roles, capabilities, and prerequisites for each technique gives authors of future QML security papers a concrete checklist for threat modeling.
- The model predicts that defenses effective at early stages have outsized value because they break downstream chains; verifying compiled circuits, for instance, addresses both backdoor persistence and model integrity.
- The model identifies an open research gap: multi-stage attack proof-of-concepts are essentially missing, so validating the claimed chain dependencies remains future work.
Reading between the lines
- Inference: the cloud multi-tenant deployment assumption is built into the model; on trusted single-tenant hardware with local compilation, the quantum-specific kill chains shrink and the framework reduces to a classical ML threat model.
- Inference: the same stage schema could be applied to other quantum computing applications beyond machine learning, such as quantum chemistry or optimization, since the hardware-level techniques like side-channel leakage, crosstalk, and transpiler trojans are not specific to QML.
- Inference: a testable extension is to score existing published defenses by the kill chain stages they cover and compare those coverage profiles against real incident reports once cloud quantum services are more widely deployed.
- Inference: the interactive web application could become a community benchmark if it is extended with explicit, traversable technique chains, turning the static taxonomy into a dynamic adversarial campaign model.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a five-stage kill chain model for quantum machine learning (QML) security—Reconnaissance, Initial Access, Model Access/Manipulation, Persistence, and Exfiltration/Impact—and maps published QML attack vectors to these stages together with attributes such as attacker role, capabilities, prerequisites, impacted components, and defenses. The mapping is summarized in an ATLAS-inspired matrix (Table I) and an interactive web application. The authors claim this is the first kill chain model tailored to QML and argue that the mapping reveals multi-stage dependencies between side-channel reconnaissance, circuit manipulation, backdoors, and exfiltration.
Significance. The paper compiles a broad set of QML attack references and organizes them into a structured taxonomy that could help practitioners and researchers reason about attack progression and defense-in-depth. Shipping an interactive web tool is a practical contribution that extends the static matrix. However, the central claim that the mapping reveals multi-stage dependencies is currently a narrative overlay rather than an emergent result, because stage assignments are subjective and no end-to-end multi-stage attack is demonstrated. The framework is a useful design proposal for future threat modeling, but its evidentiary grounding needs to be stated more carefully.
major comments (4)
- [§VI, Table I] The stage assignments in §VI and Table I are multiply-realized without an explicit decision rule: e.g., Evasion is placed in Stage 3 or Stage 5 depending on attacker intent (Section VI.C), Noise Attacks in Stages 3 and 5 (Section VI.D), Measurement Attacks in Stages 3 and 5 (Section VI.E), and SCA in Stages 1 and 5 (Section VI.A). Since no criterion is given for when a technique belongs to one stage versus another, the claimed multi-stage dependencies in Section VIII.A are author-imposed interpretations rather than emergent findings of the survey. Please define an assignment rule (e.g., based on the adversary's phase relative to objectives, prerequisites, or impact) and apply it consistently.
- [§VI.E vs. Table I] There is a factual inconsistency between the prose and the matrix: Section VI.E assigns Measurement Attacks to Stage 3 (Model Manipulation) or Stage 5 (Impact), while Table I lists Measurement Attacks only under Stage 5. Similarly, Section VI.A says SCA can feed into Stage 5, but Table I assigns SCA only Stage 1. Because Table I is the paper's main summary artifact, these discrepancies undermine the matrix's reliability for readers using it as a reference.
- [§I, §II] The novelty claim 'first kill chain model tailored to QML' (Section I) and the statement in Section II that no other survey has done this are not supported by a systematic literature search. The manuscript does not report a search protocol, inclusion/exclusion criteria, or a comparison against existing threat-modeling frameworks for quantum computing (e.g., [4]'s semantic model). Without such evidence, the claim is unverified and should be softened or substantiated.
- [§VIII] The framework's 'findings' in Section VIII.A include a side-channel-to-backdoor chain that no cited publication demonstrates end-to-end; the authors themselves note in Section VIII.B that multi-stage attack proof-of-concepts are a gap. The conclusion that the kill chain 'reveals' dependencies should be reframed as generating testable hypotheses about possible chains, which would accurately reflect the evidence level.
minor comments (4)
- [Throughout] Typos include 'alredy' in §IV.A.2, 'V on Neumann' in §IV.A.1, 'SW AP' in §VI.A and §VI.G, 'model ouputs' in §VI.E, and 'Fran c ¸a' in reference [47].
- [§VI.D, Table I] In §VI.D, 'antivirus patterns [31]' and 'matching/buffer qubits [32]' are mentioned as defenses, but Table I's Noise Attacks row references only [28]–[30]; align reference lists between text and table.
- [Figure 2] Figure 2 is referenced but its content is not described in the text; consider adding a caption that explains the stage progression arrows.
- [§VI.E] Section VI.E says 'there are no targeted attacks on availability yet' for measurement, yet the same paragraph describes readout manipulation as impacting availability; clarify whether these are hypothetical or demonstrated.
Circularity Check
No significant circularity: the kill chain taxonomy is assembled from external literature, with one minor self-citation that is not load-bearing.
full rationale
The paper's central output is a taxonomy and stage mapping, not a derived prediction or a fitted quantity. Each technique entry cites independent external attack and defense literature, and the stage assignments are presented as analytic judgments rather than consequences of a parameter fit, a hidden equation, or an imported uniqueness theorem. The only self-citation is [20] (Wendlinger, Tscharke, and Debus) in Section VI.C and Table I, where it supports a claim about Lipschitz regularization and limitations of a claimed quantum robustness advantage; that claim is also corroborated by [25] and by the surrounding survey, so the self-citation is not load-bearing. The framework explicitly credits Lockheed Martin, MITRE ATT&CK, and MITRE ATLAS, so it does not rename an existing framework as its own without attribution. The paper itself acknowledges in Section VIII.B that multi-stage attacks and proof-of-concept realizations are a gap in the literature; this makes the claimed multi-stage dependencies illustrative rather than demonstrated, but an under-justified narrative is a rigor concern, not circularity. No equation, fitted parameter, or self-citation chain reduces the model to its inputs, so no circular step is present.
Assumptions & free parameters
assumptions (4)
- domain assumption QML systems will be deployed on cloud-based, multi-tenant quantum hardware with shared access to qubits and transpilers.
- domain assumption Classical kill chain models (Cyber Kill Chain, MITRE ATT&CK, ATLAS) are meaningfully transferable to QML.
- domain assumption The surveyed literature is representative of the QML security field, and the selected publications accurately describe feasible attacks.
- domain assumption The five-stage kill chain (Reconnaissance, Initial Access, Model Access/Manipulation, Persistence, Exfiltration/Impact) is a sufficient abstraction for adversarial campaigns in QML.
Cite this review
Pith. "Pith review of Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security." pith.science (2026). https://pith.science/paper/LMKBLHT4
@misc{pith2026250708623,
author = {Pith},
title = {Pith review of: Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security},
year = {2026},
howpublished = {\url{https://pith.science/paper/LMKBLHT4}},
note = {Machine review of arXiv:2507.08623}
}
read the original abstract
Quantum Machine Learning (QML) systems inherit vulnerabilities from classical machine learning while introducing new attack surfaces rooted in the physical and algorithmic layers of quantum computing. Despite a growing body of research on individual attack vectors - ranging from adversarial poisoning and evasion to circuit-level backdoors, side-channel leakage, and model extraction - these threats are often analyzed in isolation, with unrealistic assumptions about attacker capabilities and system environments. This fragmentation hampers the development of effective, holistic defense strategies. In this work, we argue that QML security requires more structured modeling of the attack surface, capturing not only individual techniques but also their relationships, prerequisites, and potential impact across the QML pipeline. We propose adapting kill chain models, widely used in classical IT and cybersecurity, to the quantum machine learning context. Such models allow for structured reasoning about attacker objectives, capabilities, and possible multi-stage attack paths - spanning reconnaissance, initial access, manipulation, persistence, and exfiltration. Based on extensive literature analysis, we present a detailed taxonomy of QML attack vectors mapped to corresponding stages in a quantum-aware kill chain framework that is inspired by the MITRE ATLAS for classical machine learning. We highlight interdependencies between physical-level threats (like side-channel leakage and crosstalk faults), data and algorithm manipulation (such as poisoning or circuit backdoors), and privacy attacks (including model extraction and training data inference). This work provides a foundation for more realistic threat modeling and proactive security-in-depth design in the emerging field of quantum machine learning.
Figures
Forward citations
Cited by 1 Pith paper
-
An End-to-End Multi-Stage Kill-Chain Attack on Quantum Neural Networks: Demonstration on Trapped-Ion Hardware
A full kill-chain reconstructs QNN structure from simulated power traces then injects timed crosstalk to approximate adversarial inputs on AQT trapped-ion hardware.
Reference graph
Works this paper leans on
-
[20]
M. Wendlinger, K. Tscharke, and P. Debus, A Compar- ative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning Models , en, Apr. 2024
work page 2024
-
[4]
Security Aspects of Quantum Machine Learning,
N. Franco et al., “Security Aspects of Quantum Machine Learning,” en, Federal Office for Information Security , Mar. 2025
work page 2025
-
[1]
A Survey and Tutorial on Security and Resilience of Quantum Computing,
A. A. Saki et al., “A Survey and Tutorial on Security and Resilience of Quantum Computing,” in 2021 IEEE European Test Symposium (ETS) , May 2021, pp. 1–10
work page 2021
-
[2]
Impact of Noise on the Resilience and the Security of Quantum Computing,
A. A. Saki, M. Alam, and S. Ghosh, “Impact of Noise on the Resilience and the Security of Quantum Computing,” in 2021 22nd International Symposium on Quality Electronic Design (ISQED) , IEEE, Apr. 2021, pp. 186–191
work page 2021
-
[3]
N. Franco et al., Predominant Aspects on Security for Quantum Machine Learning: Literature Review , Version Number: 3, 2024. Fig. 3. Illustration of the interactive QML Killchain Web Application
work page 2024
-
[5]
Quantum Circuit Reconstruction from Power Side-Channel Attacks on Quantum Computer Controllers
F. Erata et al. , Quantum Circuit Reconstruction from Power Side-Channel Attacks on Quantum Computer Controllers, arXiv:2401.15869, Jan. 2024
work page Pith review arXiv 2024
-
[6]
Exploration of Power Side-Channel Vulnerabilities in Quantum Computer Con- trollers,
C. Xu, F. Erata, and J. Szefer, “Exploration of Power Side-Channel Vulnerabilities in Quantum Computer Con- trollers,” en, in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security , Copenhagen Denmark: ACM, Nov. 2023, pp. 579–593
work page 2023
- [7]
Show all 51 references
-
[8]
W. J. B. Lee et al. , SWAP Attack: Stealthy Side- Channel Attack on Multi-Tenant Quantum Cloud System , arXiv:2502.10115, Feb. 2025
2025 arXiv
-
[9]
Choudhury et al
N. Choudhury et al. , Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ Computers , arXiv:2412.10507, Dec. 2024
2024 arXiv
-
[10]
A Survey on Machine Learning Against Hardware Trojan Attacks: Recent Advances and Challenges,
Z. Huang et al. , “A Survey on Machine Learning Against Hardware Trojan Attacks: Recent Advances and Challenges,” IEEE Access , vol. 8, pp. 10 796–10 826, 2020
2020
-
[11]
Trojaning Attack on Neural Networks,
Y . Liu, S. Ma, and Y . Aafer, “Trojaning Attack on Neural Networks,” en, p. 17,
-
[12]
Is Feature Selection Secure against Training Data Poisoning?
H. Xiao et al. , “Is Feature Selection Secure against Training Data Poisoning?” In Proceedings of the 32nd International Conference on Machine Learning , F. Bach and D. Blei, Eds., ser. Proceedings of Machine Learning Research, vol. 37, Lille, France: PMLR, Jul. 2015, pp. 1689–1698
2015
-
[13]
Adversarial label flips attack on support vector machines,
H. Xiao, H. Xiao, and C. Eckert, “Adversarial label flips attack on support vector machines,” in Proceedings of the 20th European Conference on Artificial Intelligence , ser. ECAI’12, NLD: IOS Press, Aug. 2012, pp. 870–875
2012
-
[14]
Vulnerability of quantum classifi- cation to adversarial perturbations,
N. Liu and P. Wittek, “Vulnerability of quantum classifi- cation to adversarial perturbations,” en, Physical Review A, vol. 101, no. 6, p. 062 331, Jun. 2020
2020
-
[15]
I. J. Goodfellow, J. Shlens, and C. Szegedy, Explaining and Harnessing Adversarial Examples, arXiv:1412.6572, Mar. 2015
2015 arXiv
-
[16]
Madry et al
A. Madry et al. , Towards Deep Learning Models Resistant to Adversarial Attacks , arXiv:1706.06083, Sep. 2019
2019 arXiv
-
[17]
Quantum adver- sarial machine learning,
S. Lu, L. -M. Duan, and D. -L. Deng, “Quantum adver- sarial machine learning,” en, Physical Review Research , vol. 2, no. 3, p. 033 212, Aug. 2020
2020
-
[18]
Experimental quantum adversarial learning with programmable superconducting qubits,
W. Ren et al. , “Experimental quantum adversarial learning with programmable superconducting qubits,” en, Nature Computational Science , vol. 2, no. 11, pp. 711–717, Nov. 2022
2022
-
[19]
Benchmarking adversarially robust quantum machine learning at scale,
M. T. West et al., “Benchmarking adversarially robust quantum machine learning at scale,” Physical Review Research, vol. 5, no. 2, p. 023 186, Jun. 2023, Publisher: American Physical Society
2023
-
[21]
Quantum noise protects quantum classifiers against adversaries,
Y . Duet al., “Quantum noise protects quantum classifiers against adversaries,” Physical Review Research, vol. 3, no. 2, p. 023 153, May 2021, Publisher: American Physical Society
2021
-
[22]
Drastic Circuit Depth Reductions with Preserved Adversarial Robustness by Approximate Encoding for Quantum Machine Learning,
M. T. West et al. , “Drastic Circuit Depth Reductions with Preserved Adversarial Robustness by Approximate Encoding for Quantum Machine Learning,” en, Intelli- gent Computing, vol. 3, p. 0100, Jan. 2024
2024
-
[23]
Enhancing quantum adversarial robust- ness by randomized encodings,
W. Gong et al., “Enhancing quantum adversarial robust- ness by randomized encodings,” en, Physical Review Research, vol. 6, no. 2, p. 023 020, Apr. 2024
2024
-
[24]
Barren plateaus in quantum neural network training landscapes,
J. R. McClean et al., “Barren plateaus in quantum neural network training landscapes,” en, Nature Communica- tions, vol. 9, no. 1, p. 4812, Nov. 2018, Publisher: Nature Publishing Group
2018
-
[25]
Berberich et al
J. Berberich et al. , Training robust and generalizable quantum models, Version Number: 3, 2023
2023
-
[26]
Robustness Verification of Quantum Classifiers,
J. Guan, W. Fang, and M. Ying, “Robustness Verification of Quantum Classifiers,” in Computer Aided Verifica- tion: 33rd International Conference, CAV 2021, Virtual Event, July 20–23, 2021, Proceedings, Part I , Berlin, Heidelberg: Springer-Verlag, Jul. 2021, pp. 151–174
2021
-
[27]
Optimal provable robustness of quantum classification via quantum hypothesis testing,
M. Weber et al. , “Optimal provable robustness of quantum classification via quantum hypothesis testing,” en, npj Quantum Information , vol. 7, no. 1, pp. 1–12, May 2021, Publisher: Nature Publishing Group
2021
-
[28]
Analysis of crosstalk in NISQ devices and security implications in multi-programming regime,
A. Ash-Saki, M. Alam, and S. Ghosh, “Analysis of crosstalk in NISQ devices and security implications in multi-programming regime,” in Proceedings of the ACM/IEEE International Symposium on Low Power Electronics and Design , New York, NY , USA: ACM, Aug. 2020, pp. 25–30
2020
-
[29]
Harper et al
B. Harper et al. , Crosstalk Attacks and Defence in a Shared Quantum Computing Environment , Version Number: 1, 2024
2024
-
[30]
A. A. Saki, R. O. Topaloglu, and S. Ghosh, Shuttle- Exploiting Attacks and Their Defenses in Trapped-Ion Quantum Computers, arXiv:2108.01054, Aug. 2021
2021 arXiv
-
[31]
Towards an Antivirus for Quantum Computers,
S. Deshpande et al., “Towards an Antivirus for Quantum Computers,” English, IEEE Computer Society, Jun. 2022, pp. 37–40
2022
-
[32]
Special Session: On the Reliability of Conventional and Quantum Neural Network Hardware,
M. Sadi et al., “Special Session: On the Reliability of Conventional and Quantum Neural Network Hardware,” English (US), in Proceedings - 2022 IEEE 40th VLSI Test Symposium, VTS 2022, ser. Proceedings of the IEEE VLSI Test Symposium, United States: IEEE Computer Society, 2022
2022
-
[33]
A. A. Saki and S. Ghosh, Qubit sensing: A new attack model for multi-programming quantum computing , 2021. arXiv: 2104.05899 [quant-ph]
2021 arXiv
-
[34]
QTrojan: A Circuit Backdoor Against Quantum Neural Networks,
C. Chu et al., “QTrojan: A Circuit Backdoor Against Quantum Neural Networks,” 2023, Publisher: arXiv Version Number: 1
2023
-
[35]
QDoor: Exploiting Approximate Synthe- sis for Backdoor Attacks in Quantum Neural Networks,
C. Chu et al., “QDoor: Exploiting Approximate Synthe- sis for Backdoor Attacks in Quantum Neural Networks,” in 2023 IEEE International Conference on Quantum Computing and Engineering (QCE), Bellevue, W A, USA: IEEE, Sep. 2023, pp. 1098–1106
2023
-
[36]
Advanced Equivalence Checking for Quantum Circuits,
L. Burgholzer and R. Wille, “Advanced Equivalence Checking for Quantum Circuits,” IEEE Trans. on CAD of Integrated Circuits and Systems , 2021
2021
-
[37]
Verifying results of the IBM Qiskit quantum circuit compilation flow,
L. Burgholzer, R. Raymond, and R. Wille, “Verifying results of the IBM Qiskit quantum circuit compilation flow,” in International Conference on Quantum Comput- ing and Engineering , 2020
2020
-
[38]
Peham, L
T. Peham, L. Burgholzer, and R. Wille, Equivalence Checking of Quantum Circuits with the ZX-Calculus , arXiv:2208.12820, Aug. 2022
2022 arXiv
-
[39]
Sander, L
A. Sander, L. Burgholzer, and R. Wille, Equivalence Checking of Quantum Circuits via Intermediary Matrix Product Operator, arXiv:2410.10946, Oct. 2024
2024 arXiv
-
[40]
QuMoS: A Framework for Preserving Security of Quantum Machine Learning Model,
Z. Wang et al., “QuMoS: A Framework for Preserving Security of Quantum Machine Learning Model,” in 2023 IEEE International Conference on Quantum Computing and Engineering (QCE) , Bellevue, WA, USA: IEEE, Sep. 2023, pp. 1089–1097
2023
-
[41]
Short Paper: A Quantum Circuit Obfuscation Methodology for Security and Privacy,
A. Suresh et al. , “Short Paper: A Quantum Circuit Obfuscation Methodology for Security and Privacy,” en, in Workshop on Hardware and Architectural Support for Security and Privacy , ACM, Oct. 2021, pp. 1–5
2021
-
[42]
QuantumLeak: Stealing Quantum Neural Networks from Cloud-based NISQ Machines,
Z. Fu et al., “QuantumLeak: Stealing Quantum Neural Networks from Cloud-based NISQ Machines,” in Inter- national Joint Conference on Neural Networks (IJCNN) , 2024
2024
-
[43]
Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures,
M. Fredrikson, S. Jha, and T. Ristenpart, “Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures,” in Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’15, New York, NY , USA: ACM, Oct. 2015, pp. 1322–1333
2015
-
[44]
C. A. Choquette-Choo et al., Label-Only Membership Inference Attacks, arXiv:2007.14321, Dec. 2021
2007 arXiv
-
[45]
Improved Differential Privacy Noise Mechanism in Quantum Machine Learning,
H. Yang et al. , “Improved Differential Privacy Noise Mechanism in Quantum Machine Learning,” IEEE Access, vol. 11, pp. 50 157–50 164, 2023, Conference Name: IEEE Access
2023
-
[46]
Differential Privacy in Quantum Computation,
L. Zhou and M. Ying, “Differential Privacy in Quantum Computation,” in 2017 IEEE 30th Computer Security Foundations Symposium (CSF), ISSN: 2374-8303, Aug. 2017, pp. 249–262
2017
-
[47]
Quantum Differential Privacy: An Information Theory Perspective,
C. Hirche, C. Rouz ´e, and D. S. Fran c ¸a, “Quantum Differential Privacy: An Information Theory Perspective,” IEEE Transactions on Information Theory, vol. 69, no. 9, pp. 5771–5787, Sep. 2023, Conference Name: IEEE Transactions on Information Theory
2023
-
[48]
Heredge et al
J. Heredge et al. , Prospects of Privacy Advantage in Quantum Machine Learning , Version Number: 2, 2024
2024
-
[49]
Detecting Violations of Differential Privacy for Quantum Algorithms,
J. Guan et al. , “Detecting Violations of Differential Privacy for Quantum Algorithms,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’23, New York, NY , USA: ACM, Nov. 2023, pp. 2277–2291
2023
-
[50]
Quantum machine learning with differential privacy,
W. M. Watkins, S. Y .-C. Chen, and S. Yoo, “Quantum machine learning with differential privacy,” en, Scientific Reports, vol. 13, no. 1, p. 2453, Feb. 2023, Publisher: Nature Publishing Group
2023
-
[51]
Universal Adversarial Exam- ples and Perturbations for Quantum Classifiers,
W. Gong and D.-L. Deng, “Universal Adversarial Exam- ples and Perturbations for Quantum Classifiers,”National Science Review, Jul. 2021
2021
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.