Pith. sign in

REVIEW 4 major objections 4 minor 86 references

An intrusion-detection signal can steer quantum-repeater purification, raising above-target entanglement delivery from 0.098 to 0.344 during a simulated SSDP attack, nearly matching an oracle that knows the true attack rate.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-02 08:00 UTC pith:HRJW6MRK

load-bearing objection A coherent proof-of-principle of IDS-driven purification control, but every quantitative input is withheld, so the headline numbers are currently unverifiable. the 4 major comments →

arxiv 2607.16276 v1 pith:HRJW6MRK submitted 2026-07-08 quant-ph cs.AIcs.ETcs.NI

Intelligence-Guided Adaptive Purification for DDoS-Resilient Quantum Networks: A CUDA-Q based Study

classification quant-ph cs.AIcs.ETcs.NI PACS 03.67.Bg03.67.Hk
keywords quantum repeater networksadaptive entanglement purificationpurification maskintrusion detectionDDoS/SSDP attackanomaly-aware controlfidelity-constrained deliveryMonte Carlo simulation
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Quantum-repeater networks need to decide when to purify each elementary link, and the paper's claim is that this decision should depend on the state of the classical control plane, not just on local link fidelities. The paper argues that an intrusion-detection anomaly score can be used as a control input: during a modeled SSDP attack, a controller that keeps its clean-condition purification mask delivers many pairs but mostly below the fidelity target (0.098 above-target), while an IDS-aware controller switches to more purification-heavy masks and reaches 0.344 above-target, statistically matching an oracle that knows the true attack rate (0.335). Under stationary conditions, the paper also argues that a resource-penalized risk-aware policy outperforms fixed purification in an eight-node chain (0.362 vs 0.311 above-target) using fewer purifications. A sympathetic reader would care because quantum networks depend on classical control; if the claim is right, cyber-state awareness can buy fidelity-qualified entanglement at the cost of raw throughput.

Core claim

The paper's central claim is that a repeater-chain controller which chooses its purification mask using a running cyber-anomaly score can recover most of the useful entanglement delivery lost when the classical control plane is degraded. In the coupled experiment, the physical links are degraded according to a ground-truth attack-rate signal while the deployable controller sees only a learned severity score; the claim is that the severity signal is enough to switch the controller to purification-heavy masks and raise above-target delivery from 0.098±0.007 to 0.344±0.011, statistically indistinguishable from the oracle-aware 0.335±0.011. The stationary companion claim is that a resource-penal

What carries the argument

The central object is the purification mask, a binary vector over the elementary links of the repeater chain that marks which links get purified. The controller selects the mask that maximizes a resource-penalized risk-aware score combining a lower-confidence-bound estimate of above-target delivery, delivered-fidelity margin, purification cost, and latency cost. The mask is the adaptive element: the attack-unaware controller keeps the clean-condition mask fixed, the IDS-aware controller recomputes it from a learned severity score, and the oracle-aware controller recomputes it from ground-truth attack rate, so the mask is what carries cyber-state information into the quantum-network control a

Load-bearing premise

The load-bearing premise is the paper's assumed map from attack severity to link quality: as the DDoS signal rises, link-generation probability and raw fidelity drop, attempt time grows, and memory lifetime shortens, by amounts set by unstated constants; if a real control-plane attack does not degrade quantum links this way and by this size, the reported recovery is an artifact of that map.

What would settle it

Set the cyber-to-quantum degradation constants to zero—attack severity then leaves link parameters unchanged—and re-run the attack period; the IDS-aware and attack-unaware above-target delivery probabilities should coincide, and any recovery should disappear. Alternatively, induce a real DDoS on the classical control plane of a repeater testbed and measure whether generation probability and raw fidelity actually drop; if they do not, the cyber-to-quantum map is the artifact.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • If the central claim holds, a quantum-network operator can use existing intrusion-detection outputs as a control input without waiting for a direct quantum-side measurement of the attack; the learned severity score alone recovers most oracle-level useful delivery.
  • If the stationary claim holds, repeater controllers should not default to purifying every link; a resource-aware partial mask can beat fixed purification on above-target delivery while cutting purification count and latency.
  • If the attack-period claim holds, an attack-unaware controller gives a false sense of health: raw delivery stays high (0.678) while above-target delivery collapses (0.098), so monitoring only pair count misses the damage.
  • If the model holds, cyber-aware purification shifts the network operating point from high-throughput to fidelity-qualified delivery, making the resilience cost explicit: raw delivery drops and latency rises.
  • If the workflow itself is reusable, the same architecture can test other adaptive repeater policies under time-varying link conditions without simulating the full network as one quantum circuit.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper: the same mask-adaptation mechanism should transfer to non-adversarial degradations—control-plane congestion, clock drift, or optical link weather—because the controller is only reacting to a time-varying link-quality signal; this makes the result a general principle for adaptive repeater control, not a DDoS-specific patch.
  • Beyond the paper: the near-oracle performance of the learned severity score suggests the controller may need only a coarse regime detector (attack vs benign) rather than precise severity; a hard-threshold trigger could be tested against the full IDS score.
  • Beyond the paper: the uncalibrated degradation constants are the point where a hardware testbed could falsify or calibrate the claim; measuring the four link parameters under a real control-plane outage would turn this proof-of-principle into an engineering prediction.
  • Beyond the paper: the observed tradeoff—raw delivery drops from 0.678 to 0.362 while above-target delivery rises—implies that service-level agreements for quantum networks should specify fidelity-qualified delivery, not pair count, or an attack-aware controller will look worse by the wrong metric.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper presents a CUDA-Q/SeQUeNCe co-simulation workflow for adaptive entanglement purification in linear quantum-repeater chains, with two linked studies. First, under stationary conditions, it compares no purification, threshold-adaptive, mean-field predictive, fixed, and a resource-penalized risk-aware predictive policy in three-link and eight-node chains; the headline stationary result is that the risk-aware policy achieves above-target delivery probability 0.362 ± 0.017 versus 0.311 ± 0.017 for fixed purification while using fewer purifications and lower latency (Table II and Fig. 3b). Second, it couples a CSE-CIC-IDS2018 benign-to-SSDP trace to a phenomenological degradation model that linearly reduces link generation probability, raw fidelity, and coherence time and increases attempt time as a function of attack severity (§III.B). During the SSDP attack period, the attack-unaware controller (which keeps the clean purification mask fixed) delivers above-target entanglement with probability 0.098 ± 0.007, while the IDS-aware controller—which replans masks from an IDS severity score—raises this to 0.344 ± 0.011, close to the oracle-aware value of 0.335 ± 0.011 (Fig. 6, Tables A3–A4). The mechanism is a switch to more purification-heavy masks such as 1111011 during the attack.

Significance. If the central claims are correct, the paper makes a useful conceptual contribution: it distinguishes raw entanglement delivery from fidelity-qualified delivery, treats purification as a resource-allocation problem, and demonstrates—within a simulator—that cyber-state information can change the purification action and improve a network-level quantum-service metric. The paper is transparent about the costs of its approach, reporting raw delivery, latency, purification count, and failure-stage statistics, and it uses Monte Carlo confidence intervals throughout. The exhaustive mask evaluation in the 8-node chain (128 masks) and the separation between the IDS signal and the oracle degradation signal for physical modeling are also strengths. However, the central cyber-aware result rests on an uncalibrated, unreported degradation model, and the absence of a no-IDS adaptive baseline prevents attribution of the improvement to cyber awareness rather than to generic adaptation to observable network degradation. The stationary result is better supported, though it relies on unspecified objective weights.

major comments (4)
  1. [§III.B, Cyber-to-quantum degradation model] The entire IDS-aware result (Fig. 6, Tables A3–A4) is produced by the linear degradation map p_i(t)=p_i0(1−η_p a(t)), F_i(t)=F_i0−η_F a(t), τ_i(t)=τ_i0(1+η_τ a(t)), T_2,i(t)=T_2,i0(1−η_T a(t)). The constants η_p, η_F, η_τ, η_T, the subset of affected links, the baseline link parameters, and the target fidelity threshold F* are never reported. The manuscript itself calls the model 'intentionally phenomenological' and 'not hardware-calibrated' (Limitations). Because the headline improvement from 0.098 to 0.344 is entirely a function of these unreported inputs, the quantitative claim is not reproducible and its magnitude is unverifiable. The authors should report all parameter values and the affected-link subset, and provide a sensitivity analysis over the η constants. Without this, the attack-period result is an artifact of an unvalidated input rather than a demonstrated property of the co
  2. [§IV.B, Attack-unaware baseline] The attack-unaware scenario fixes the mask at the clean value m_clean for the entire trace. This is not merely a controller 'without IDS'; it is also a controller without any replanning whatsoever. A network-aware controller that re-estimates p_i, F_i, τ_i, T_2,i from its own observed generation statistics, purification outcomes, and delivered fidelities would also adapt its purification mask without receiving any cyber signal. The paper does not compare against such a baseline. Therefore the experiment has not shown that cyber-state awareness, rather than adaptation to observable network degradation, drives the switch to masks such as 1111011 and the recovery in above-target delivery. Add a network-aware baseline that replans from measured link statistics alone; if it achieves a similar recovery, the claim that IDS awareness is the operative cause is unsupported.
  3. [§III.A.c, Eqs. (6)–(7)] The risk-aware objective is J(m) = U_LCB(m) + α Û(m) + γ Ĝ(m) − λ_p m̄ − λ_τ L̂(m), where the evaluation metric in the stationary 8-node comparison is U, the above-target delivery probability. Thus the risk-aware policy is partly optimizing an estimate of the reported metric itself, with resource penalties. The improvement over fixed purification (0.362 vs 0.311) is therefore in part the optimizer doing its job on its own score. This is not circular in a fatal way, but the weights α, γ, λ_p, λ_τ are never reported, so the reader cannot determine how much of the difference comes from the fidelity-margin and resource terms versus direct maximization of U. Report the weights and include a sensitivity analysis over them; also report J(m) for the selected masks to clarify the mechanism.
  4. [Appendix B, Proposition 2] Proposition 2 is a tautology: the mask that maximizes J over all masks is never worse than any baseline mask under the same J. The note accompanying it correctly warns that this does not guarantee separate-evaluation improvement, but the proposition is presented as a theoretical result. The meaningful evidence for the stationary claim is the separate Monte Carlo evaluation in Table II, not this proposition. Consider removing or reframing this proposition to avoid giving it the status of a substantive guarantee.
minor comments (4)
  1. [§III.B, attack-period-only text] Typographical errors: 'provides a referencfor' should be 'reference for'; 'bign bins' and 'Tse benign bins' should be 'benign bins' and 'The benign bins'.
  2. [Fig. 8 caption] The figure is labeled 'Schematic mask adaptation' but appears to present simulation output. Clarify whether it plots actual time-bin results or is an illustrative schematic.
  3. [§III.A, CUDA-Q role] The paper calls the workflow a 'CUDA-Q/SeQUeNCe co-simulation,' but CUDA-Q is used only to validate and cache primitive purification/swapping estimates, while the network dynamics are simulated in the event layer. This is a reasonable division of labor, but the term 'co-simulation' overstates the coupling; consider using 'CUDA-Q-validated event-layer simulation.'
  4. [Eq. (2)] The memory-decay formula is standard, but the exponentiation notation is garbled in some displays; ensure the equation renders as F(t)=1/4+(F(0)−1/4)exp(−t/T_2) (or equivalent).

Circularity Check

0 steps flagged

No significant circularity; reported gains are simulation outputs from an explicitly defined optimizer, and the flagged limitations concern calibration and experimental design, not circular derivation.

full rationale

Walking the claimed derivation chain, the stationary result is an empirical simulation comparison, not a derivation from the reported metric. The risk-aware policy is defined as the argmax of J(m) (Eqs. 6-7), whose leading term is the LCB estimate of the same above-target delivery probability U that is later reported. This is a policy-design choice: the controller optimizes a penalized version of the reported metric, which also includes a fidelity-margin term, a purification-cost penalty, and a latency penalty (Eq. 7). A mask maximizing J need not maximize U, so the reported superiority over fixed purification is not an identity or a forced consequence. The paper explicitly acknowledges this in Appendix B, Proposition 2: the selected mask is only guaranteed to be at least as good under the empirical planning score J, not in a separate Monte Carlo evaluation. The IDS-aware experiment similarly does not reduce to its inputs: the physical network is degraded by the oracle signal a_oracle(t), while the controller plans from the learned IDS signal a_IDS(t); the closeness of IDS-aware and oracle-aware results is an empirical match, not an equality by construction. The paper's own Limitations section flags the cyber-to-quantum degradation model as 'intentionally phenomenological' and 'not a hardware-calibrated model,' and describes the IDS experiment as a 'proof-of-principle demonstration.' Those are external-validity and reproducibility limitations, not circularity. The unreported weights alpha, gamma, lambda and the uncalibrated constants eta_p, eta_F, eta_tau, eta_T are reporting gaps, but nothing in the equations makes a reported quantity equal to its own input by construction. Self-citations (e.g., [76]-[79]) appear as background context and are not load-bearing for the central claims. No load-bearing step reduces to a fitted parameter renamed as a prediction, and no uniqueness or ansatz is imported from the authors' prior work. The core results are self-contained simulations under explicitly stated (if uncalibrated) models, so the circularity score is 0.

Axiom & Free-Parameter Ledger

8 free parameters · 6 axioms · 1 invented entities

The central claims rest on a large set of unreported numerical inputs and on the explicit phenomenological bridge between cyber anomalies and quantum-link quality. Almost everything quantitative is either a hidden free parameter or an ad hoc domain assumption; the Appendix B math (finite maximizer, Hoeffding-union-bound concentration) is standard and adds no new axioms. No new physical entities are postulated beyond the phenomenological degradation model.

free parameters (8)
  • Risk-aware objective weights α, γ, λ_p, λ_τ = not reported
    Weights in Eq. (7) combining LCB above-target delivery, fidelity margin, purification count, and latency; unreported, so the policy's operating point is unverifiable.
  • Degradation strengths η_p, η_F, η_τ, η_T = not reported
    Set how strongly attack severity degrades p, F, τ, T2; the magnitude of the headline gain (0.098 to 0.344) depends on them; no sweep over η is reported.
  • Per-link baseline parameters (p_i, F_i, τ_i, T_2,i) = not reported
    Inputs for the 3-link and 8-node chains, never given numerically; mean-attempt statistics (~15.7 for 8 nodes) imply p_i ≈ 0.4 but this is not stated.
  • Target fidelity threshold F* = not reported
    Defines 'above-target' delivery, the paper's central metric; value unstated (3-link numbers imply it lies between 0.7043 and 0.7273).
  • Purification trigger for threshold-adaptive policy = not reported
    Local fidelity threshold; Fig. 9(a) sweeps it qualitatively but no numeric scale is given.
  • CUDA-Q noise model and primitive-cache grid = not reported
    The noisy kernel error rates and the fidelity-rounding grid for caching are unspecified, so the cached purification/swapping tables cannot be reproduced.
  • IDS anomaly-detection model and settings = not reported
    'Fitting an anomaly-detection model to benign traffic' (Section III.B): model class, features, hyperparameters, binning, and train/test split are never specified.
  • Generation retry budget and swapping success probability = not reported
    Mentioned as fixed inputs ('maximum retry budget', 'fixed success probability') but never quantified.
axioms (6)
  • domain assumption Memory decay follows F(t) = 1/4 + (F(0) − 1/4) exp(−t/T2), exponential relaxation of Bell-pair fidelity toward the maximally mixed state.
    Eq. (2), Section III.A. Standard Markovian single-qubit decoherence applied to a one-parameter fidelity description; assumes coherences beyond fidelity are irrelevant.
  • domain assumption Purification and swapping outputs are fully described by a single fidelity scalar (Werner-like states); BBPSSW-style bilateral-CNOT purification with postselection is used.
    Section III.A and Table A1. The whole event-layer model evolves fidelity scalars only; the CUDA-Q kernels provide the specific success/fidelity maps.
  • domain assumption Entanglement swapping succeeds with a fixed probability and compounds fidelities via the CUDA-Q swapping primitive; a failed swap or failed purification terminates the request.
    Section III.A. Chosen stochastic model; single-path linear chain, no retransmission or routing alternatives.
  • ad hoc to paper Anomaly severity a(t) linearly degrades link parameters: p → p(1−η_p a), F → F−η_F a, τ → τ(1+η_τ a), T2 → T2(1−η_T a).
    Section III.B. 'Intentionally phenomenological' per the paper's own limitation statement; uncalibrated against any hardware or control-plane measurement, and the η values are unreported.
  • domain assumption The IDS anomaly score (classical model fit to benign traffic) is an actionable proxy for the oracle attack rate.
    Section III.B. The IDS-aware planner uses a_IDS instead of a_oracle; the quality of this proxy is never quantified (no classification/ranking metrics), yet the main result depends on it being informative.
  • standard math Monte Carlo trials are independent; Hoeffding and union-bound arguments give uniform concentration over the 128 masks.
    Appendix B Theorems 1-2. Correct but standard; the proofs are not the contribution.
invented entities (1)
  • Cyber-to-quantum degradation map (a(t) → p, F, τ, T2) no independent evidence
    purpose: Bridges the CSE-CIC-IDS2018 SSDP trace to quantum-link degradation so the IDS signal can influence purification decisions.
    The paper labels it 'intentionally phenomenological' and uncalibrated (Section III.B, Limitations). No falsifiable handle outside the paper; if real DDoS does not degrade links this way, the IDS-aware gain is an artifact of the model.

pith-pipeline@v1.3.0-alltime-deepseek · 30555 in / 28955 out tokens · 252189 ms · 2026-08-02T08:00:53.074455+00:00 · methodology

0 comments
read the original abstract

Quantum-repeater networks require adaptive control policies that balance entanglement generation rate, end-to-end fidelity, purification overhead, and memory-induced latency. This tradeoff becomes more complex when the classical control plane is degraded by cyber anomalies or denial-of-service traffic. We develop a CUDA-Q/SeQUeNCe co-simulation workflow for studying adaptive entanglement purification in heterogeneous linear repeater chains. CUDA-Q noisy quantum kernels are used to estimate primitive entanglement purification and swapping behavior, while SeQUeNCe provides an event-layer model for stochastic link generation, waiting-time-dependent memory decay, purification failure, and end-to-end swapping. Under stationary conditions, we compare no purification, local threshold purification, mean-field predictive purification, fixed purification, and a resource-penalized risk-aware predictive policy. In an 8-node chain, the resource-penalized risk-aware controller increases above-target delivery probability relative to fixed purification while reducing latency and purification overhead. We then couple the quantum-network controller to anomaly scores derived from the CSE-CIC-IDS2018 benign-to-SSDP intrusion-detection trace. During the attack period, the attack-unaware controller maintains high raw delivery, but its above-target entanglement delivery falls to 0.098+/-0.007; the IDS-aware resource-adaptive controller switches to more purification-heavy masks and increases above-target delivery to 0.344+/-0.011, closely matching the oracle-aware value of approximately 0.335. These results demonstrate that cyber-state awareness can improve useful quantum-network outcomes by trading raw throughput for fidelity-qualified entanglement delivery.

Figures

Figures reproduced from arXiv: 2607.16276 by Santanu Ganguly.

Figure 1
Figure 1. Figure 1: FIG. 1 [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: FIG. 2 [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 4
Figure 4. Figure 4: FIG. 4 [PITH_FULL_IMAGE:figures/full_fig_p012_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: FIG 5. (Colour online). IDS severity and oracle attack rate across time bins constructed from CSE [PITH_FULL_IMAGE:figures/full_fig_p013_5.png] view at source ↗
Figure 7
Figure 7. Figure 7: separates raw entanglement delivery from fidelity￾qualified delivery during the SSDP attack period. The attack￾unaware controller continues to use the clean purification mask, so it preserves a high raw delivery probability. However, most of those delivered pairs fall below the target fidelities, producing a low above-target delivery probability of 0.098 0.007  . IDS-aware control changes this operating p… view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

86 extracted references · 5 canonical work pages

  1. [1]

    First, stationary adaptive -purification experiments were performed on three-link and eight-node linear repeater chains

    Experimental protocol The experimental protocol consisted of three linked stages. First, stationary adaptive -purification experiments were performed on three-link and eight-node linear repeater chains. CUDA -Q noisy quantum kernels were used to validate Bell -pair preparation, pu rification, and entanglement-swapping primitives, and the resulting success...

  2. [2]

    Incorporating IDS -derived anomaly severity into the purification planner increased above-target delivery to 0.344±0.011, close to the oracle -aware value of 0.335±0.011

    Discussions In the 8 -node repeater chain, SSDP -driven degradation reduced attack-unaware above-target entanglement delivery from the clean counterfactual value of 0.627±0.011to 0.098±0.007. Incorporating IDS -derived anomaly severity into the purification planner increased above-target delivery to 0.344±0.011, close to the oracle -aware value of 0.335±0...

  3. [3]

    H. J. Kimble, The quantum internet, Nature 453, 1023 (2008), https://doi.org/10.1038/nature07127

  4. [4]

    Wehner, D

    S. Wehner, D. Elkouss, and R. Hanson, Quantum internet: A vision for the road ahead, Science 362, eaam9288 (2018), https://doi.org/10.1126/science.aam9288

  5. [5]

    Briegel, W

    H.-J. Briegel, W. Dür, J. I. Cirac, and P. Zoller, Quantum repeaters: The role of imperfect local operations in quantum communication, Phys. INTELLIGENCE-GUIDED QUANTUM NETWORKS: A CUDA-Q STUDY Rev. Lett. 81, 5932 (1998), https://doi.org/10.1103/PhysRevLett.81.5932

  6. [6]

    C. H. Bennett, G. Brassard, S. Popescu, B. Schumacher, J. A. Smolin, and W. K. Wootters, Purification of noisy entanglement and faithful teleportation via noisy channels, Phys. Rev. Lett. 76, 722 (1996), https://doi.org/10.1103/PhysRevLett.76.722

  7. [7]

    Event-ready-detectors

    M. Żukowski, A. Zeilinger, M. A. Horne, and A. K. Ekert, “Event-ready-detectors” Bell experiment via entanglement swapping, Phys. Rev. Lett. 71, 4287 (1993), https://doi.org/10.1103/PhysRevLett.71.4287

  8. [8]

    Sangouard, C

    N. Sangouard, C. Simon, H. de Riedmatten, and N. Gisin, Quantum repeaters based on atomic ensembles and linear optics, Rev. Mod. Phys. 83, 33 (2011), https://doi.org/10.1103/RevModPhys.83.33

  9. [9]

    Shchukin and P

    E. Shchukin and P. van Loock, Optimal entanglement swapping in quantum repeaters, Phys. Rev. Lett. 128, 150502 (2022), https://doi.org/10.1103/PhysRevLett.128.150502

  10. [10]

    Adesso, D

    G. Adesso, D. Girolami, and A. Serafini, Measuring Gaussian quantum information and correlations using the Rényi entropy of order 2, Phys. Rev. Lett. 109, 190502 (2012), https://doi.org/10.1103/PhysRevLett.109.190502

  11. [11]

    Jozsa, Fidelity for mixed quantum states, J

    R. Jozsa, Fidelity for mixed quantum states, J. Mod. Opt. 41, 2315 (1994), https://doi.org/10.1080/09500349414552171

  12. [12]

    Ortiz Marrero, M

    C. Ortiz Marrero, M. Kieferová, and N. Wiebe, Entanglement-induced barren plateaus, PRX Quantum 2, 040316 (2021), https://doi.org/10.1103/PRXQuantum.2.040316

  13. [13]

    X. Wu, A. Kolar, J. Chung, D. Jin, T. Zhong, R. Kettimuthu, and M. Suchara, SeQUeNCe: A customizable discrete-event simulator of quantum networks, arXiv:2009.12000, last accessed 1 June 2026

  14. [14]

    Coopmans et al., NetSquid, a NETwork Simulator for QUantum Information using Discrete events, Commun

    T. Coopmans et al., NetSquid, a NETwork Simulator for QUantum Information using Discrete events, Commun. Phys. 4, 164 (2021), https://doi.org/10.1038/s42005-021-00647-8

  15. [15]

    Welch and M

    A. Welch and M. Kiran, A short scalability study on the SeQUeNCe parallel quantum network simulator, arXiv:2503.09776, last accessed 1 June 2026

  16. [16]

    Yehia, S

    R. Yehia, S. Neves, E. Diamanti, and I. Kerenidis, Quantum City: Simulation of a practical near-term metropolitan quantum network, arXiv:2211.01190, last accessed 1 June 2026

  17. [17]

    Abane, M

    A. Abane, M. Cubeddu, V. S. Mai, and A. Battou, Entanglement routing in quantum networks: A comprehensive survey, arXiv:2408.01234, last accessed 1 June 2026

  18. [18]

    Clayton, X

    C. Clayton, X. Wu, and B. Bhattacharjee, Efficient routing on quantum networks using adaptive clustering, arXiv:2410.23007, last accessed 1 June 2026

  19. [19]

    Khatri, Policies for elementary links in a quantum network, Quantum 5, 537 (2021), https://doi.org/10.22331/q-2021-08-30-537

    S. Khatri, Policies for elementary links in a quantum network, Quantum 5, 537 (2021), https://doi.org/10.22331/q-2021-08-30-537

  20. [20]

    Rozpędek et al., Optimizing practical entanglement distillation, Phys

    F. Rozpędek et al., Optimizing practical entanglement distillation, Phys. Rev. A 97, 062333 (2018), https://doi.org/10.1103/PhysRevA.97.062333

  21. [21]

    H. Ma, G. J. Mooney, I. R. Petersen, L. C. L. Hollenberg, and D. Dong, Quantum autoencoders using mixed reference states, npj Quantum Inf. 10, 86 (2024)

  22. [22]

    Corli, L

    S. Corli, L. Moro, D. Dragoni, M. Dispenza, and E. Prati, Quantum machine learning algorithms for anomaly detection: A review, arXiv:2408.11047, last accessed 1 June 2026

  23. [23]

    Frehner and K

    R. Frehner and K. Stockinger, Applying quantum autoencoders for time series anomaly detection, arXiv:2410.04154, last accessed 1 June 2026

  24. [24]

    Senthil and S

    R. Senthil and S. L. Wong, Quantum autoencoders for anomaly detection in cybersecurity, arXiv:2510.21837, last accessed 1 June 2026

  25. [25]

    Pranjić et al., Unsupervised quantum anomaly detection on noisy quantum processors, arXiv:2411.16970, last accessed 1 June 2026

    D. Pranjić et al., Unsupervised quantum anomaly detection on noisy quantum processors, arXiv:2411.16970, last accessed 1 June 2026

  26. [26]

    Stokes, J

    J. Stokes, J. Izaac, N. Killoran, and G. Carleo, Quantum natural gradient, Quantum 4, 269 (2020), https://doi.org/10.22331/q-2020-05-25-269

  27. [27]

    S. L. Braunstein and C. M. Caves, Statistical distance and the geometry of quantum states, Phys. Rev. Lett. 72, 3439 (1994), https://doi.org/10.1103/PhysRevLett.72.3439

  28. [28]

    Larocca et al., A review of barren plateaus in variational quantum computing, arXiv:2405.00781, last accessed 1 June 2026

    M. Larocca et al., A review of barren plateaus in variational quantum computing, arXiv:2405.00781, last accessed 1 June 2026

  29. [29]

    Peruzzo et al., A variational eigenvalue solver on a quantum processor, Nat

    A. Peruzzo et al., A variational eigenvalue solver on a quantum processor, Nat. Commun. 5, 4213 (2014), https://doi.org/10.1038/ncomms5213

  30. [30]

    NVIDIA, CUDA-Q documentation, https://nvidia.github.io/cuda-quantum/latest/ (last accessed 7 July 2026)

  31. [31]

    Schieffer, S

    G. Schieffer, S. Markidis, and I. Peng, Harnessing CUDA-Q’s MPS for tensor network simulations of large-scale quantum circuits, arXiv:2501.15939, last accessed 1 June 2026

  32. [32]

    Vallero, F

    M. Vallero, F. Vella, and P. Rech, State of practice: Evaluating GPU performance of state vector and tensor network methods, arXiv:2401.06188, last accessed 1 June 2026

  33. [33]

    J. Li, E. Rubinshtein, and M. Martonosi, Statistical assertions for debugging quantum circuits and states in CUDA-Q, arXiv:2507.16255, last accessed 1 June 2026

  34. [34]

    INTELLIGENCE-GUIDED QUANTUM NETWORKS: A CUDA-Q STUDY

    Canadian Institute for Cybersecurity, CSE-CIC- IDS2018 on AWS, University of New Brunswick, https://www.unb.ca/cic/datasets/ids-2018.html (accessed 16 April 2026). INTELLIGENCE-GUIDED QUANTUM NETWORKS: A CUDA-Q STUDY

  35. [35]

    AWS Open Data Registry, CSE-CIC-IDS2018, https://registry.opendata.aws/cse-cic-ids2018/ (accessed 16 April 2026)

  36. [36]

    Sharafaldin, A

    I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, Toward generating a new intrusion detection dataset and intrusion traffic characterization, in Proc. 4th International Conference on Information Systems Security and Privacy (ICISSP) (2018), pp. 108–116, https://doi.org/10.5220/0006639801080116

  37. [37]

    Göcs and Z

    L. Göcs and Z. C. Johanyák, Identifying relevant features of CSE-CIC-IDS2018 dataset for the development of an intrusion detection system, arXiv:2307.11544, last accessed 1 June 2026

  38. [38]

    Soltani, M

    M. Soltani, M. J. Siavoshani, and A. H. Jahangir, A content-based deep intrusion detection system, arXiv:2001.05009, last accessed 1 June 2026

  39. [39]

    Soltani, B

    M. Soltani, B. Ousat, M. J. Siavoshani, and A. H. Jahangir, An adaptable deep learning-based intrusion detection system to zero-day attacks, arXiv:2108.09199, last accessed 1 June 2026

  40. [40]

    F. T. Liu, K. M. Ting, and Z.-H. Zhou, Isolation forest, in Proc. IEEE International Conference on Data Mining (ICDM) (2008), pp. 413–422, https://doi.org/10.1109/ICDM.2008.17

  41. [41]

    F. T. Liu, K. M. Ting, and Z.-H. Zhou, Isolation-based anomaly detection, ACM Trans. Knowl. Discov. Data 6, 3 (2012), https://doi.org/10.1145/2133360.2133363

  42. [42]

    Chandola, A

    V. Chandola, A. Banerjee, and V. Kumar, Anomaly detection: A survey, ACM Comput. Surv. 41, 15 (2009), https://doi.org/10.1145/1541880.1541882

  43. [43]

    Majkowski, Stupidly simple DDoS protocol (SSDP) generates 100 Gbps DDoS, Cloudflare Blog, https://blog.cloudflare.com/ssdp-100gbps/ (28 June 2017)

    M. Majkowski, Stupidly simple DDoS protocol (SSDP) generates 100 Gbps DDoS, Cloudflare Blog, https://blog.cloudflare.com/ssdp-100gbps/ (28 June 2017)

  44. [44]

    Rossow, Amplification hell: Revisiting network protocols for DDoS abuse, in Proc

    M. Rossow, Amplification hell: Revisiting network protocols for DDoS abuse, in Proc. Network and Distributed System Security Symposium (NDSS) (2014)

  45. [45]

    Czyz et al., Taming the 800 pound gorilla: The rise and decline of NTP DDoS attacks, in Proc

    J. Czyz et al., Taming the 800 pound gorilla: The rise and decline of NTP DDoS attacks, in Proc. Internet Measurement Conference (IMC) (2014)

  46. [46]

    Krämer et al., AmpPot: Monitoring and defending against amplification DDoS attacks, in Research in Attacks, Intrusions, and Defenses, Lecture Notes in Computer Science Vol

    K. Krämer et al., AmpPot: Monitoring and defending against amplification DDoS attacks, in Research in Attacks, Intrusions, and Defenses, Lecture Notes in Computer Science Vol. 9404 (Springer, Cham, 2015), pp. 615–636

  47. [47]

    Mehic et al., Quantum key distribution: A networking perspective, ACM Comput

    M. Mehic et al., Quantum key distribution: A networking perspective, ACM Comput. Surv. 53, 1 (2020), https://doi.org/10.1145/3402192

  48. [48]

    Van Meter, Quantum Networking (Wiley-ISTE, Hoboken, NJ, 2014)

    R. Van Meter, Quantum Networking (Wiley-ISTE, Hoboken, NJ, 2014)

  49. [49]

    Razavi, An Introduction to Quantum Communication Networks (Morgan & Claypool, San Rafael, CA, 2018)

    M. Razavi, An Introduction to Quantum Communication Networks (Morgan & Claypool, San Rafael, CA, 2018)

  50. [50]

    Nokkala, J

    J. Nokkala, J. Piilo, and G. Bianconi, Complex quantum networks: A topical review, J. Phys. A: Math. Theor. 57 (2024), arXiv:2311.16265, last accessed 1 June 2026

  51. [51]

    Takeoka, S

    M. Takeoka, S. Guha, and M. M. Wilde, Fundamental rate-loss tradeoff for optical quantum key distribution, Nat. Commun. 5, 5235 (2014), https://doi.org/10.1038/ncomms6235

  52. [52]

    Pirandola, R

    S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, Fundamental limits of repeaterless quantum communications, Nat. Commun. 8, 15043 (2017), https://doi.org/10.1038/ncomms15043

  53. [53]

    Pirandola et al., Advances in quantum cryptography, Adv

    S. Pirandola et al., Advances in quantum cryptography, Adv. Opt. Photon. 12, 1012 (2020), https://doi.org/10.1364/AOP.361502

  54. [54]

    H.-K. Lo, M. Curty, and K. Tamaki, Secure quantum key distribution, Nat. Photonics 8, 595 (2014), https://doi.org/10.1038/nphoton.2014.149

  55. [55]

    Azuma, K

    K. Azuma, K. Tamaki, and W. J. Munro, All-photonic quantum repeaters, Nat. Commun. 6, 6787 (2015), https://doi.org/10.1038/ncomms7787

  56. [56]

    Muralidharan, L

    S. Muralidharan, L. Li, J. Kim, N. Lütkenhaus, and M. D. Lukin, Optimal architectures for long-distance quantum communication, Sci. Rep. 6, 20463 (2016), https://doi.org/10.1038/srep20463

  57. [57]

    Jones, D

    C. Jones, D. Kim, M. T. Rakher, P. G. Kwiat, and T. D. Ladd, Design and analysis of communication protocols for quantum repeater networks, New J. Phys. 18, 083015 (2016), https://doi.org/10.1088/1367- 2630/18/8/083015

  58. [58]

    Jiang, J

    L. Jiang, J. M. Taylor, K. Nemoto, W. J. Munro, R. Van Meter, and M. D. Lukin, Quantum repeater with encoding, Phys. Rev. A 79, 032325 (2009), https://doi.org/10.1103/PhysRevA.79.032325

  59. [59]

    W. J. Munro, A. M. Stephens, S. J. Devitt, K. A. Harrison, and K. Nemoto, Quantum communication without the necessity of quantum memories, Nat. Photonics 6, 777 (2012), https://doi.org/10.1038/nphoton.2012.243

  60. [60]

    P. C. Humphreys, N. Kalb, J. P. J. Morits, R. N. Schouten, R. F. L. Vermeulen, D. J. Twitchen, M. Markham, and R. Hanson, Deterministic delivery of remote entanglement on a quantum network, Nature 558, 268 (2018), https://doi.org/10.1038/s41586-018- 0200-5

  61. [61]

    N. Kalb, A. A. Reiserer, P. C. Humphreys, J. J. W. Bakermans, S. J. Kamerling, N. H. Nickerson, S. C. Benjamin, D. J. Twitchen, M. Markham, and R. Hanson, Entanglement distillation between solid-state quantum network nodes, Science 356, 928 (2017), https://doi.org/10.1126/science.aan0070

  62. [62]

    Pompili et al., Realization of a multinode quantum network of remote solid-state qubits, Science 372, 259 (2021), https://doi.org/10.1126/science.abg1919

    M. Pompili et al., Realization of a multinode quantum network of remote solid-state qubits, Science 372, 259 (2021), https://doi.org/10.1126/science.abg1919

  63. [63]

    S. L. N. Hermans, M. Pompili, H. K. C. Beukers, S. Baier, J. Borregaard, and R. Hanson, Qubit teleportation between non-neighbouring nodes in a INTELLIGENCE-GUIDED QUANTUM NETWORKS: A CUDA-Q STUDY quantum network, Nature 605, 663 (2022), https://doi.org/10.1038/s41586-022-04697-y

  64. [64]

    M. Pant, H. Krovi, D. Towsley, L. Tassiulas, L. Jiang, P. Basu, D. Englund, and S. Guha, Routing entanglement in the quantum internet, npj Quantum Inf. 5, 25 (2019), https://doi.org/10.1038/s41534-019- 0139-x

  65. [65]

    Dahlberg et al., A link layer protocol for quantum networks, in Proc

    A. Dahlberg et al., A link layer protocol for quantum networks, in Proc. ACM Special Interest Group on Data Communication (SIGCOMM) (2019), pp. 159– 173, https://doi.org/10.1145/3341302.3342070

  66. [66]

    Matsuo, C

    T. Matsuo, C. Durand, and R. Van Meter, Quantum link bootstrapping using a RuleSet-based communication protocol, arXiv:1904.08605, last accessed 1 June 2026

  67. [67]

    Schoute, L

    E. Schoute, L. Mancinska, T. Islam, I. Kerenidis, and S. Wehner, Shortcuts to quantum network routing, arXiv:1610.05238, last accessed 1 June 2026

  68. [68]

    Victora, S

    M. Victora, S. Krastanov, A. Sanchez de la Cerda, S. Willis, and P. Narang, Purification and entanglement routing on quantum networks, arXiv:2011.11644, last accessed 1 June 2026

  69. [69]

    B. Ru, W. K. G. Seah, and A. C. Valera, Synchronization control-plane protocol for quantum link layer, arXiv:2409.07049, last accessed 1 June 2026

  70. [70]

    Abbas et al., The power of quantum neural networks, Nat

    A. Abbas et al., The power of quantum neural networks, Nat. Comput. Sci. 1, 403 (2021), https://doi.org/10.1038/s43588-021-00084-1

  71. [71]

    Gyongyosi and S

    L. Gyongyosi and S. Imre, Networked quantum services, Quantum Inf. Comput. 25, 97 (2025), arXiv:2505.23074, last accessed 1 June 2026

  72. [72]

    Javaid, Q

    A. Javaid, Q. Niyaz, W. Sun, and M. Alam, A deep learning approach for network intrusion detection system, EAI Endorsed Trans. Security Safety 3, e2 (2016), https://doi.org/10.4108/eai.3-12-2015.2262516

  73. [73]

    Lazarevic, L

    A. Lazarevic, L. Ertöz, A. Ozgur, J. Srivastava, and V. Kumar, A comparative study of anomaly detection schemes in network intrusion detection, in Proc. SIAM International Conference on Data Mining (SDM) (2005)

  74. [74]

    Shone, T

    N. Shone, T. N. Ngoc, V. D. Phai, and Q. Shi, A deep learning approach to network intrusion detection, IEEE Trans. Emerg. Top. Comput. Intell. 2, 41 (2018), https://doi.org/10.1109/TETCI.2017.2772792

  75. [75]

    Sommer and V

    R. Sommer and V. Paxson, Outside the closed world: On using machine learning for network intrusion detection, in Proc. IEEE Symposium on Security and Privacy (2010), pp. 305–316, https://doi.org/10.1109/SP.2010.25

  76. [76]

    Wang et al., Network intrusion detection using deep learning: A survey, IEEE Commun

    W. Wang et al., Network intrusion detection using deep learning: A survey, IEEE Commun. Surv. Tutor. 24, 684 (2022), https://doi.org/10.1109/COMST.2021.3134524

  77. [77]

    Zhong, M

    M. Zhong, M. Lin, C. Zhang, and Z. Xu, A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges, Comput. Secur. 141, 103821 (2024), https://doi.org/10.1016/j.cose.2024.103821

  78. [78]

    Ganguly, Quantum Machine Learning: An Applied Approach (Springer Nature, 2021)

    S. Ganguly, Quantum Machine Learning: An Applied Approach (Springer Nature, 2021)

  79. [79]

    Ganguly, X

    S. Ganguly, X. Liang, and D. Makris, Spectral geometry and bosonic-Bloch probes: Explorations in quantum learning, arXiv:2607.00063, last accessed 1 June 2026

  80. [80]

    S. Ganguly, Hybrid classical–quantum learning for space-based data centers: A CUDA-Q study of variational and photonic backends, Research Square, https://www.researchsquare.com/article/rs-9487599/v1 (2026)

Showing first 80 references.