REVIEW 4 major objections 5 minor 38 references
A closed-form formula predicts the coupling strength at which an adversary's probe qubit can reliably recover a hidden quantum gate sequence.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
For a controlled-rotation probe, gate-sequence leakage is predicted to peak at θ*(k)=2 arcsin(√(2/(k+2))), but the paper provides neither a derivation of the envelope nor the experimental data supporting the prediction.
T0 review reviewed 2026-08-02 challenge →
load-bearing objection The core claim — a depth-dependent coupling ridge θ*(k) for controlled-Rx probes — is new but rests on an asserted proxy, not a derivation, and the experiments are only described qualitatively; reject as is, but the topic and specific formula deserve referee scrutiny. the 4 major comments →
Hardware-Agnostic Modeling of Quantum Side-Channel Leakage via Conditional Dynamics and Learning from Full Correlation Data
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
Core claim
For the controlled-rotation probe with a commuting Rx gate alphabet, the paper claims that strict recovery of Alice's per-step gate labels from the probe's full-correlation histogram is governed by a depth-dependent envelope, and that the coupling strength maximizing distinguishability is exactly θ*(k)=2arcsin(√(2/(k+2))). This predictor locates the ridge of strict recovery in coupling sweeps, irrespective of whether Eve uses marginals or full correlations, because the physical distinguishability, not sample efficiency, is the bottleneck. At depth 2, the gate-dependent amplitude factorizes as sin²(θ/2)κ2(θ;G), and κ2 has isolated zeros that make all sequences indistinguishable at those speci
What carries the argument
The central object is the empirical full-correlation histogram bPg(b), the joint distribution of probe outcomes over bitstrings b∈{0,1}^k, which is the sufficient statistic for Eve's classical post-processing. The argument is carried by the envelope proxy Δp_k(θ;G) ≈ α_G sin²(θ/2) cos^k(θ/2) and the depth-2 factorization A2 ∝ sin²(θ/2)κ2(θ;G); the former maximizes to give θ*(k), the latter supplies the isolated blind-spot couplings. Together these convert a high-dimensional inference problem into a one-parameter ridge.
Load-bearing premise
The predictor and blind-spot structure are derived from two asserted functional forms—the depth-2 factorization A2 ∝ sin²(θ/2)κ2(θ;G) with κ2's zeros, and the envelope Δp_k ≈ α_G sin²(θ/2)cos^k(θ/2)—which the paper calls 'useful analytic proxies' and does not derive from the controlled-Rx unitary; if either form is not forced by the dynamics, θ*(k) is an assumed curve rather than a physical prediction.
What would settle it
Simulate the exact (no-envelope) probe distributions for the controlled-Rx coupling at depths 2 and 3 over a fine θ grid, and check whether the depth-2 total-variation distance between two chosen sequences hits zero at the predicted blind-spot couplings and whether the empirical strict-recovery ridge for many random sequences tracks θ*(k) to within finite-shot error bars. A mismatch between the exact TV computation and the envelope's ridge would falsify the predictor as a physical law.
If this is right
- Strict sequence recovery concentrates in a coupling band whose center is θ*(k)=2arcsin(√(2/(k+2))); deeper circuits require weaker couplings.
- Full-correlation records improve sample efficiency at low shots but do not extend the recoverable regime beyond the predicted band, since the bottleneck is physical distinguishability, not statistics.
- Depolarizing noise narrows the band and lowers accuracy, so noise and coupling trade off; operating outside the band keeps accuracy near the random-guess baseline even with unlimited shots.
- At depth 2, isolated couplings exist at which all pairs of sequences are information-theoretically indistinguishable, and noise broadens these into low-accuracy bands.
- A single decoder conditioned on (θ,λ) suffices to predict gates across the whole grid, indicating the learned map internalizes the physical parameter dependence.
Where Pith is reading between the lines
- If the envelope proxy reflects a general tradeoff between per-step transfer and depth-k contraction, analogous closed-form predictors should exist for other probe couplings; testing this on a diagonal coupling would separate the universal mechanism from the specific alphabet-dependent modulation.
- The depth-2 factorization suggests a testable algebraic structure: the zeros of κ2 should coincide with the zeros of the exact two-step instrument's gate-dependent part, so a symbolic computation of the two-step channel would settle whether the blind spots are exact or merely proxy-level.
- For random (non-commuting) gate alphabets, back-action and measurement order interact differently, so the predictor's ridge may shift; the same histogram-based decoder could be applied to see whether the Goldilocks shape persists.
- The paper's landscape view—leakage as a function of (θ,λ,N,k)—implies that defenders in a multi-tenant machine could schedule jobs at couplings far from θ*(k) to reduce side-channel risk, though the operational cost of doing so is left unquantified.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper studies a sequential coherent side-channel model in which an adversarial probe qubit couples to Alice's qubit after each hidden gate and is measured mid-circuit, yielding a full-correlation histogram over probe bit-strings. After presenting a general coupling- and measurement-agnostic framework, it specializes to a controlled-Rx(θ) probe with a commuting Rx gate alphabet and claims a depth-dependent leakage envelope Δp_k ≈ α_G sin²(θ/2) cos^k(θ/2), whose maximizer θ*(k) = 2 arcsin√(2/(k+2)) predicts a 'Goldilocks' coupling band. The paper also trains a temporal convolutional network decoder that maps full-correlation histograms to gate labels across a grid of coupling and noise parameters. Results are reported as qualitative heatmaps for k=2 and k=7, showing a coupling ridge, noise narrowing, and finite-shot scaling.
Significance. The question of when a coherent probe record enables strict sequence recovery is timely and relevant to multi-tenant quantum processors. The full-correlation observation model is a sensible primitive, and the idea of an amortized decoder conditioned on physical parameters is promising. If the analytic predictor were actually derived from the controlled-Rx dynamics and validated quantitatively, the paper would provide a useful design rule for side-channel risk and a concrete baseline for future work. However, the central quantitative claim is not derived from the stated dynamics, is contradicted by a direct calculation at k=1, and the experimental evidence is qualitative only. In its current form, the significance is not established.
major comments (4)
- [§V, Eqs. (8)–(9)] The central predictor θ*(k) is obtained by maximizing f_k(θ)=sin²(θ/2)cos^k(θ/2), but Eq. (8) is explicitly introduced as 'a useful analytic proxy' and the alphabet-dependent scale α_G is never specified. No derivation from the controlled-Rx instrument of Sec. III-B is given for the cos^k contraction factor. The claimed depth dependence fails already at k=1: for a single Rx(φ) gate and target initialized in |0>, the probe outcome-1 probability is p_1 = sin²(θ/2)sin²(φ/2), so the gate-conditioned spread over the alphabet has no cos(θ/2) factor. Thus the maximizer of the proxy is not the maximizer of the actual spread, and Eq. (9) is not a physical prediction derived from the dynamics.
- [§IV-B, Eqs. (6)–(7)] The depth-2 factorization A₂ ∝ sin²(θ/2)κ₂(θ;G) and the existence of isolated zeros of κ₂ are asserted without deriving κ₂ or computing θ₀. The implication in Eq. (7) that κ₂(θ₀;G)=0 implies D₂(u,u′)=0 for all pairs requires that A₂ fully characterizes the pairwise distinguishability of the two-step probe laws; no such equivalence is shown. As a result, the 'blind-spot' prediction is not established.
- [§VIII, Figs. 2–3] The experimental validation is qualitative only. No numerical values of strict-sequence accuracy are reported, no error bars or confidence intervals are given, and no table quantifies accuracy as a function of θ, λ, and N. The captions state that the ridge aligns with θ*(d), but the underlying data and code are not provided, so the claim that Eq. (9) tracks the ridge cannot be independently checked. The same applies to the noise-narrowing and shot-scaling statements in §VIII-b,c.
- [§V, last paragraph] The sentence 'irrespective of whether Eve uses marginals or full correlations' is not justified. The envelope Δp_k is a per-step marginal quantity, while the distinguishability measure D_d(u,u′) in Eq. (5) is defined on full distributions. No argument is given that the full-correlation distinguishability shares the same maximizing coupling, so this assertion is unsupported.
minor comments (5)
- [§IV-B] The text states that sin²(θ/2) is π-periodic; this is mathematically false. sin²(θ/2) has period 2π, not π. The intended statement may refer to sin²(x), but as written it is incorrect.
- [§VI-A, Eq. (11)] The dimension notation 'R^{2+k+2k}' appears to be a typo. Since x ∈ R^{2^k}, the feature vector X_t should be in R^{2 + k + 2^k}, not R^{2+k+2k}.
- [§IV, Eqs. (4)–(5)] The notation mixes depth subscripts: ar P_{k,u} is defined with k, while D_d is written with d, and both are used for the same depth variable. This is confusing and should be unified.
- [§VIII] Figures 2 and 3 are referenced but their actual images are not present; captions alone cannot support the quantitative claims made in the text. Axis labels and color scales are also missing.
- [§VII] Reference [32] is 'in preparation.' Deferring extensions and additional derivations to a future manuscript is not a substitute for presenting the necessary derivations and data here.
Circularity Check
Eq. (9) is the maximizer of the asserted proxy Eq. (8), so the central ridge prediction is a restatement of an assumed curve rather than a derived consequence of the controlled-rotation dynamics.
specific steps
-
fitted input called prediction
[Section V, Eqs. (8)-(9); see also Abstract and Sec. IV-C]
"For controlled-rotation families, a useful analytic proxy is the gate-conditioned spread in a canonical per-step event probability, which can be written (up to an alphabet-dependent scale α_G) as ∆pk(θ;G)≈α_G sin²(θ/2) cos^k(θ/2). ... Maximizing f_k(θ)=sin²(θ/2) cos^k(θ/2) yields the closed-form predictor θ*(k)=2 arcsin√(2/(k+2))."
θ*(k) is by construction the maximizer of f_k in Eq. (8); Eq. (8) is introduced as 'a useful analytic proxy' with unspecified α_G and no derivation from the CRx unitary. Its sin²×cos^k form already contains the non-monotone 'Goldilocks' ridge, so the predictor is the maximizer of the assumed curve, not an independent physical prediction. The abstract/contribution call this 'derive a depth-dependent leakage envelope.' A direct depth-1 CRx calculation gives P(y=1)=sin²(θ/2)sin²(φ/2) with no cos(θ/2) factor, confirming the proxy is not a consequence of the stated dynamics.
full rationale
The central quantitative claim is the coupling-band predictor θ*(k). The paper explicitly labels Eq. (8) a 'proxy' and never computes the envelope from the controlled-Rx instrument or from the claimed depth-2 factorization Eqs. (6)-(7); no explicit κ2 or θ0 is exhibited, and the statement that sin²(θ/2) is π-periodic is incorrect. Since Eq. (9) is just the maximizer of that asserted proxy, the ridge prediction reduces to the assumed curve, with the empirical alignment reported only qualitatively (Figs. 2-3, no numeric results or code/data). This is a partial circularity: the 'derivation' is a self-contained calculus exercise on an unverified input. No load-bearing self-citation was found ([32] is future work and non-essential).
Axiom & Free-Parameter Ledger
free parameters (1)
- α_G (alphabet-dependent scale) =
unspecified
axioms (3)
- domain assumption Noise on Alice is a gate-independent depolarizing channel D_λ applied after each timestep
- ad hoc to paper The depth-2 witness factorizes as A2 ∝ sin²(θ/2)κ2(θ;G), and κ2 has isolated zeros
- ad hoc to paper The gate-conditioned spread can be written as Δp_k ≈ α_G sin²(θ/2) cos^k(θ/2)
Cite this review
Pith. "Pith review of Hardware-Agnostic Modeling of Quantum Side-Channel Leakage via Conditional Dynamics and Learning from Full Correlation Data." pith.science (2026). https://pith.science/paper/5RMNQD5Y
@misc{pith2026260215966,
author = {Pith},
title = {Pith review of: Hardware-Agnostic Modeling of Quantum Side-Channel Leakage via Conditional Dynamics and Learning from Full Correlation Data},
year = {2026},
howpublished = {\url{https://pith.science/paper/5RMNQD5Y}},
note = {Machine review of arXiv:2602.15966}
}
abstract
We study a sequential coherent side-channel model in which an adversarial probe qubit interacts with a target qubit during a hidden gate sequence. Repeating the same hidden sequence for $N$ shots yields an empirical \emph{full-correlation record}: the joint histogram $\widehat{P}_g(b)$ over probe bit-strings $b\in\{0,1\}^k$, which is a sufficient statistic for classical post-processing under identically and independently distributed (i.i.d.)\ shots but grows exponentially with circuit depth. We first describe this sequential probe framework in a coupling- and measurement-agnostic form, emphasizing the scaling of the observation space and why exact analytic distinguishability becomes intractable with circuit depth. We then specialize to a representative instantiation (a controlled-rotation probe coupling with fixed projective readout and a commuting $R_x$ gate alphabet) where we (i) derive a depth-dependent leakage envelope whose maximizer predicts a coupling band as a function of depth {if the measurement data is reduced to marginal statistics}, and (ii) provide an operational decoder, via machine learning, a single parameter-conditioned map from $\widehat{P}_g$ to Alice's per-step gate labels, generalizing across coupling and noise settings without retraining.
Figures
Reference graph
Works this paper leans on
-
[1]
Timing attacks on implementations of diffie–hellman, rsa, dss, and other systems,
P. C. Kocher, “Timing attacks on implementations of diffie–hellman, rsa, dss, and other systems,” inAdvances in Cryptology – CRYPTO’96. Berlin, Heidelberg: Springer, 1996, pp. 104–113
1996
-
[2]
Differential power analysis,
P. Kocher, J. Jaffe, and B. Jun, “Differential power analysis,” in Advances in Cryptology – CRYPTO’99. Berlin, Heidelberg: Springer, 1999, pp. 388–397
1999
-
[3]
Spectre at- tacks: Exploiting speculative execution,
P. Kocher, D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y . Yarom, “Spectre at- tacks: Exploiting speculative execution,” inProceedings of the IEEE Symposium on Security and Privacy (SP). San Francisco, CA, USA: IEEE, 2019, pp. 1–19
2019
-
[4]
Meltdown,
M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, A. Fogh, J. Horn, S. Mangard, P. Kocher, D. Genkin, and Y . Yarom, “Meltdown,” inProceedings of the 27th USENIX Security Symposium. Baltimore, MD, USA: USENIX Association, 2018, pp. 973–990. [Online]. Available: https: //www.usenix.org/conference/usenixsecurity18/presentation/lipp
2018
-
[5]
Deep learning for side-channel analysis and profiling,
R. Benadjila, E. Prouff, R. Strullu, E. Cagli, and C. Dumas, “Deep learning for side-channel analysis and profiling,” inIACR Transac- tions on Cryptographic Hardware and Embedded Systems, vol. 2018. Gainesville, FL, USA: IACR, 2018, pp. 1–35
2018
-
[6]
Deep learning for side- channel analysis: A review,
H. Maghrebi, T. Portigliatti, and E. Prouff, “Deep learning for side- channel analysis: A review,”IEEE Transactions on Information Foren- sics and Security, vol. 15, pp. 409–422, 2020
2020
-
[7]
Goodfellow, Y
I. Goodfellow, Y . Bengio, and A. Courville,Deep Learning. Cambridge, MA: MIT Press, 2016. [Online]. Available: http: //www.deeplearningbook.org
2016
-
[8]
Breuer and F
H.-P. Breuer and F. Petruccione,The Theory of Open Quantum Systems. Oxford, UK: Oxford University Press, 2002
2002
-
[9]
Schlosshauer,Decoherence and the Quantum-to-Classical Transi- tion
M. Schlosshauer,Decoherence and the Quantum-to-Classical Transi- tion. Berlin, Heidelberg: Springer, 2007
2007
-
[10]
Quantum leak: Timing side-channel attacks on cloud-based quantum services,
C. Lu, E. Telang, A. Aysu, and K. Basu, “Quantum leak: Timing side-channel attacks on cloud-based quantum services,” 2024, submitted to IEEE HOST 2024. [Online]. Available: https: //arxiv.org/abs/2401.01521
Pith/arXiv arXiv 2024
-
[11]
Exploration of quantum computer power side-channels,
C. Xu, F. Erata, and J. Szefer, “Exploration of quantum computer power side-channels,” inProceedings of the 2023 ACM Conference on Computer and Communications Security (CCS ’23). New York, NY , USA: ACM, 2023. [Online]. Available: https://arxiv.org/abs/ 2304.03315
Pith/arXiv arXiv 2023
-
[12]
Quantum circuit reconstruction from power side-channel attacks on quantum computer controllers,
F. Erata, C. Xu, R. Piskac, and J. Szefer, “Quantum circuit reconstruction from power side-channel attacks on quantum computer controllers,”IACR Transactions on Cryptographic Hardware and Embedded Systems, vol. 2024, no. 2, pp. 735–768, 2024. [Online]. Available: https://arxiv.org/abs/2401.15869
Pith/arXiv arXiv 2024
-
[13]
Crosstalk-induced side channel threats in multi-tenant NISQ computers,
N. Choudhury, C. Naik Mude, S. Das, P. C. Tikkireddi, S. Tannu, and K. Basu, “Crosstalk-induced side channel threats in multi-tenant NISQ computers,” 2024. [Online]. Available: https://arxiv.org/abs/ 2412.10507
Pith/arXiv arXiv 2024
-
[14]
E. Chitambar and G. Gour, “Quantum resource theories,”Reviews of Modern Physics, vol. 91, no. 2, Apr. 2019. [Online]. Available: http://dx.doi.org/10.1103/RevModPhys.91.025001
-
[15]
Noisy probabilistic error cancellation and generalized physical implementability,
T.-R. Jin, Y .-R. Zhang, K. Xu, and H. Fan, “Noisy probabilistic error cancellation and generalized physical implementability,” Communications Physics, vol. 8, no. 1, p. 296, Jul. 2025. [Online]. Available: https://doi.org/10.1038/s42005-025-02217-8
-
[16]
Defending crosstalk-mediated quantum attacks using dynamical decoupling,
D. Mehra and A. Kalev, “Defending crosstalk-mediated quantum attacks using dynamical decoupling,” 2024. [Online]. Available: https://arxiv.org/abs/2409.14598
Pith/arXiv arXiv 2024
-
[17]
Understanding side-channel vulnerabilities in superconducting qubit readout architec- tures,
S. Maurya, C. N. Mude, B. Lienhard, and S. Tannu, “Understanding side-channel vulnerabilities in superconducting qubit readout architec- tures,” in2024 IEEE International Conference on Quantum Computing and Engineering (QCE), vol. 01, 2024, pp. 1177–1183
2024
-
[18]
Crosstalk attacks and defence in a shared quantum computing environment,
B. Harper, B. Tonekaboni, B. Goldozian, M. Sevior, and M. Usman, “Crosstalk attacks and defence in a shared quantum computing environment,”Advanced Quantum Technologies, vol. 8, no. 10, Aug
-
[19]
Defense against ml-based power side-channel attacks on dnn accelerators with adversarial attacks,
X. Yan, C. H. Chang, and T. Zhang, “Defense against ml-based power side-channel attacks on dnn accelerators with adversarial attacks,”
-
[20]
Contribution aux applications statistiques de la th´eorie de l’information,
M.-P. Sch ¨utzenberger, “Contribution aux applications statistiques de la th´eorie de l’information,”Publ. Inst. Statist. Univ. Paris, vol. 3, pp. 3–117, 1954, doctoral thesis, University of Paris, 1953
1954
-
[21]
M. S. Pinsker,Information and Information Stability of Random Variables and Processes. San Francisco: Holden-Day, 1964, translated and edited by Amiel Feinstein
1964
-
[22]
Divergence measures based on the shannon entropy,
J. Lin, “Divergence measures based on the shannon entropy,”IEEE Transactions on Information Theory, vol. 37, no. 1, pp. 145–151, 1991
1991
-
[23]
Sinkhorn distances: Lightspeed computation of optimal transport,
M. Cuturi, “Sinkhorn distances: Lightspeed computation of optimal transport,” inAdvances in Neural Information Processing Systems 26 (NIPS 2013), 2013, pp. 2292–
2013
-
[24]
Phoneme recognition using time-delay neural networks,
A. Waibel, T. Hanazawa, G. Hinton, K. Shikano, and K. Lang, “Phoneme recognition using time-delay neural networks,”IEEE Trans- actions on Acoustics, Speech, and Signal Processing, vol. 37, no. 3, pp. 328–339, 1989
1989
-
[25]
Temporal convolutional networks for action segmentation and detection,
C. Lea, M. D. Flynn, R. Vidal, A. Reiter, and G. D. Hager, “Temporal convolutional networks for action segmentation and detection,”CoRR, vol. abs/1611.05267, 2016. [Online]. Available: http://arxiv.org/abs/1611.05267
Pith/arXiv arXiv 2016
-
[26]
An empirical evaluation of generic convolutional and recurrent networks for sequence modeling,
S. Bai, J. Z. Kolter, and V . Koltun, “An empirical evaluation of generic convolutional and recurrent networks for sequence modeling,”CoRR, vol. abs/1803.01271, 2018. [Online]. Available: http://arxiv.org/abs/1803.01271
Pith/arXiv arXiv 2018
-
[27]
Multivariate time series classification using dilated convolutional neural network,
O. Yazdanbakhsh and S. Dick, “Multivariate time series classification using dilated convolutional neural network,” CoRR, vol. abs/1905.01697, 2019. [Online]. Available: http: //arxiv.org/abs/1905.01697
Pith/arXiv arXiv 1905
-
[28]
Robust Estimation of a Location Parameter,
P. J. Huber, “Robust Estimation of a Location Parameter,”The Annals of Mathematical Statistics, vol. 35, no. 1, pp. 73 – 101, 1964. [Online]. Available: https://doi.org/10.1214/aoms/1177703732
arXiv 1964
-
[29]
Fast r-cnn,
R. Girshick, “Fast r-cnn,” inProceedings of the IEEE International Conference on Computer Vision (ICCV), December 2015
2015
-
[30]
Pulse code communication,
F. Gray, “Pulse code communication,” U.S. Patent US2 632 058, March 17, 1953, filed Nov. 1947
1953
-
[31]
A closed set of normal orthogonal functions,
J. L. Walsh, “A closed set of normal orthogonal functions,”American Journal of Mathematics, vol. 45, no. 1, pp. 5–24, 1923. [Online]. Available: https://www.jstor.org/stable/2370258
arXiv 1923
-
[32]
Hardware-agnostic quantum side-channel attacks,
B. Bell, A. Tr ¨ugler, K. Beyer, and P. Erker, “Hardware-agnostic quantum side-channel attacks,”in preparation, 2026
2026
-
[33]
T. M. Cover and J. A. Thomas,Elements of Information Theory, 2nd ed. New York: Wiley, 2006, see Section 2.10 for the finite- hypothesis Fano inequality
2006
-
[34]
Assouad, fano, and le cam,
B. Yu, “Assouad, fano, and le cam,” inFestschrift for Lucien Le Cam: Research Papers in Probability and Statistics, D. Pollard, E. Torgersen, and G. L. Yang, Eds. New York: Springer, 1997, pp. 423–435
1997
-
[35]
A. B. Tsybakov,Introduction to Nonparametric Estimation, ser. Springer Series in Statistics. Springer, 2009, revised and extended translation of the 2003 French edition. See Theorem 2.2 (Le Cam) and Theorem 2.5 (Fano) for standard bounds
2009
-
[2023]
Available: https://arxiv.org/abs/2312.04035
[Online]. Available: https://arxiv.org/abs/2312.04035
-
[2025]
Available: http://dx.doi.org/10.1002/qute.202500009
[Online]. Available: http://dx.doi.org/10.1002/qute.202500009
-
[2300]
Available: https://papers.nips.cc/paper/ 4927-sinkhorn-distances-lightspeed-computation-of-optimal-transport
[Online]. Available: https://papers.nips.cc/paper/ 4927-sinkhorn-distances-lightspeed-computation-of-optimal-transport
This paper was first reviewed by deepseek-v4-flash on August 2, 2026.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.