Pith. sign in

REVIEW 3 major objections 5 minor 73 references

CutBackdoor: A Circuit Cut Triggered Backdoor Attack on Variational Quantum Algorithms

T0 review · 3 major / 5 minor · reviewed 2026-08-01 · deepseek-v4-flash

Pith's one-line read A backdoor in pre-trained VQA parameters passes full-circuit validation and corrupts energy estimates only when a victim's hardware forces circuit cutting.

desk verdict Novel attack surface, but the stealthiness claim rests on a spectral assumption that fails for the paper's own benchmarks; the core experiment needs rework. read the letter →

arxiv 2607.18126 v1 pith:HPIVW7NC submitted 2026-07-20 quant-ph cs.CR

classification quant-phcs.CR
keywords backdoorattackvariationalquantumalgorithmscircuitcuttingparameterpoisoningsupplychainsecurityfinite-shotnoiseVQEmachinelearning
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that variational quantum algorithm (VQA) parameters distributed through public repositories can be secretly poisoned so that they behave correctly in full-circuit simulation but produce substantially wrong energies when a resource-limited user invokes circuit cutting. The attack, called CutBackdoor, requires no circuit modification and no attacker presence at deployment; the trigger is the structural mismatch between circuit size and hardware capacity. The mechanism is a dual-objective training that keeps the full-circuit energy near its ideal value while driving the finite-shot cut-path estimator into high-variance regions amplified by the cutting overhead. Empirical results on molecular VQE and VQD benchmarks show cut-path energy amplification of 1.3× to 2.9× over clean parameters, with the diagonal-cost QAOA benchmark marking the attack's structural boundary. If true, this threatens the growing practice of sharing pre-trained quantum parameters.

What carries the argument

The central object is the finite-shot evaluation gap Δ(θ) between the cut-path energy estimator and the full-circuit energy estimator for the same variational parameters. The load-bearing mechanism is the variance asymmetry: the full-circuit estimator has Monte Carlo variance O(1/N), while the cut-path estimator built from tensor products of subcircuit measurements and signed reconstruction weights has variance amplified by γ²=(Σ|w_b|)², the cutting overhead that grows exponentially in the number of cuts. The training loss L(θ)=|Ê_full(θ)|−λ·Δ(θ) simultaneously anchors the full-circuit energy and pushes parameters into regions where the cut-path estimator is unstable.

What would settle it

Run the poisoned parameters through a noise-free full-circuit simulator and compare the energy against the true ground-state energy of the molecular Hamiltonian (e.g., H3+ or CH2); if the difference is large (well above chemical accuracy), the stealthiness claim fails on its own terms regardless of the reported E_stl values.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is that full-circuit and cut-based execution of the same parameterized circuit are structurally different statistical pipelines, and a parameter set can be crafted to exploit this asymmetry: it preserves the full-circuit energy estimate while systematically inflating the finite-shot reconstruction error of the cut path. The paper formalizes the finite-shot evaluation gap Δ(θ)=|Ê_cut(θ)−Ê_full(θ)|, proves a high-probability bound of order (γ+1)√(2log(4M/δ)/N) where γ is the cutting overhead, and uses this gap as an attack objective. Poisoned parameters are trained by minimizing the absolute full-circuit energy (stealth) while maximizing the gap

Load-bearing premise

The claim that the stealth term |Ê_full(θ)| drives θ to the variational ground state, and therefore that a small E_stl implies the parameters would pass full-circuit validation, holds only for Hamiltonians whose energies are nonnegative; the paper's molecular benchmarks have negative ground-state energies, so minimizing the absolute energy does not mean minimizing the distance to the true ground state.

Editorial extensions

If this is right

  • Practitioners who validate downloaded VQA parameters only on full-circuit simulators have no affordable way to detect this backdoor, because the poisoned parameters are designed to pass exactly that validation.
  • The attack surface widens with the number of cuts, since the one-sided bound on the evaluation gap grows with the cutting overhead γ; deeper partitions admit larger worst-case deviations.
  • Zero-Noise Extrapolation provides only partial mitigation on most benchmarks and can occasionally amplify the adversarial signal, so standard error mitigation is not a reliable defense.
  • The attack is compilation-relative: it transfers across backends and cut placements when the attacker's training compilation matches the victim's deployment compilation, which the paper argues is the default for standard circuit-cutting workflows.
  • The diagonal-cost QAOA benchmark shows limited amplification, indicating that the attack is most effective when the observable couples nontrivially to cut wires, as molecular Hamiltonians do.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the attack generalizes to randomized cutting, gate cutting, and shadow-based reconstruction as the paper suggests, then the entire class of decomposition-based execution strategies inherits a parameter-supply-chain vulnerability, not just wire cutting.
  • The stealthiness analysis implicitly assumes the Hamiltonian has nonnegative spectrum, since minimizing the absolute full-circuit energy is claimed to drive parameters to the variational ground state; for molecular Hamiltonians with negative ground-state energies, this term would push the energy toward zero instead, so the reported stealth values may not actually indicate that the parameters pass
  • A natural extension is an adaptive attacker who distributes adversarial bias across high-gradient parameters to evade gradient-based pruning defenses, which the paper acknowledges; such an attacker would also be more robust against future adaptive cutting pipelines.
  • One could probe the backdoor's presence by running a few extra cut branches at high shot counts and comparing the reconstructed energy to the full-circuit simulator result; the persistence of the gap across shot budgets is a signature, though the paper does not propose such a detection method.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper introduces CutBackdoor, a backdoor attack on variational quantum algorithms (VQAs) in which the deployment-time trigger is the use of circuit cutting (CutQC) to execute a circuit that exceeds the victim's hardware capacity. The attacker crafts poisoned variational parameters that, under full-circuit execution, are claimed to preserve validation performance, while under noisy finite-shot cut-circuit execution they produce substantially increased reconstruction error. The attack requires no circuit modification and no attacker presence at deployment. The paper provides a theoretical upper bound on the finite-shot evaluation gap (Theorem 5.1), a dual-objective training loss (Eq. 16), and experiments on IBM quantum backends across VQE, VQD, and QAOA benchmarks.

Significance. If the central claim were established, CutBackdoor would represent a novel and timely supply-chain threat: it identifies circuit cutting as an attack surface and shows that poisoned parameters can survive full-circuit validation. The paper's strengths include a clearly defined threat model, a formal concentration bound, extensive hardware experiments across multiple benchmarks and backends, and a candid discussion of the attack's limitations (e.g., the diagonal-cost QAOA boundary and the compilation-matching requirement). However, the central stealthiness claim is not supported by the reported training objective and evaluation metrics: the stealth term in Eq. (16) does not actually drive parameters to a valid ground state for the molecular Hamiltonians used, and the stealth metric in Eq. (18) does not measure the quantity the abstract claims. These issues are load-bearing for the paper's main contribution.

major comments (3)
  1. [§5.7, Eq. (16); §6.6, Eq. (18); Table 3] The stealth term L_stl(theta)=|E_full(theta)| is claimed to 'drive theta toward the variational ground state' (§5.7). This equivalence holds only if the Hamiltonian spectrum is nonnegative. The benchmarks are molecular Hamiltonians (H3+, CH2, H4) with negative ground-state energies; for such H, minimizing |E_full| pushes E_full toward zero, not toward the minimum. Consequently, the poisoned parameters are not anchored to the variational ground state, and the small E_stl values in Table 3 (e.g., 3.792 Ha for CH2) measure only the noisy full-circuit deviation from the parameter's own ideal energy, not the distance from the true ground-state energy. The full-circuit validation claim in the abstract is therefore unsupported. Please fix by using a reference-energy-shifted Hamiltonian or by directly minimizing E_full, and report simulator energies relative to the true ground state for poisoned
  2. [§6.3, §6.6, Table 3] The stealthiness evaluation E_stl is measured by executing the full circuit on IBMQ_Kolkata hardware (§6.3), not on a full-circuit simulator as the threat model's validation step assumes (§4.3). Moreover, Eq. (18) compares to E_ideal(theta), the noiseless expectation under the same (possibly poisoned) theta, so a small E_stl does not imply the parameters would pass simulator validation against the true ground state. The paper never reports the exact full-circuit energy of poisoned parameters relative to the true ground-state energy (or relative to a clean optimized baseline). Without such a result, the 'preserves full-circuit validation performance' claim is not demonstrated. Please add statevector simulator experiments and report absolute energies/errors to the true minimum.
  3. [§7.2, Theorem 5.1, Table 4] Theorem 5.1 is a standard Hoeffding bound that applies to any parameter vector, clean or poisoned. The experiments in Fig. 6 and Table 4 show the realized gap contracts as O(1/sqrt(N)) and grows with K, which is the known behavior of the bound, not a backdoor-specific property. The paper acknowledges the bound is one-sided, but the discussion in §7.2 and the abstract's phrasing ('attack surface widens') risk overstating the theoretical contribution. This does not invalidate the empirical attack results, but the theoretical analysis should be presented as a generic worst-case bound rather than a characterization of CutBackdoor.
minor comments (5)
  1. [Abstract] Remove the leftover revision markup '\revA{...}' in the abstract.
  2. [§5.4 / §6.6] E_ideal(theta) is used in §5.7 but only defined in §6.6; move the definition to the notation section (§5.4).
  3. [Throughout] The notation for the trihydrogen cation is inconsistent (H+3 vs H−3); use a single form.
  4. [Fig. 6] The y-axis label and units are missing; without them it is hard to verify the claim that the gap stays near 175 mHa.
  5. [Fig. 7] The bars appear to lack error bars; please indicate whether trials were repeated and include error bars if so.

Circularity Check

1 steps flagged · score 6.0 of 10

Stealthiness claim reduces by construction: E_stl compares noisy full-circuit estimates to the poisoned parameters' own noiseless energy, while the training term |E_full| has no fixed physical reference and does not anchor negative-spectrum molecular Hamiltonians to the ground state.

  1. self definitional [§5.7 Eq. (16); §6.6 Eq. (18); Table 3]
    "Stealth term. Lstl(θ)=|Êfull(θ)| drives θ toward the variational ground state, ensuring the poisoned parameters remain indistinguishable from legitimately trained parameters under full-circuit validation. No externally known reference energy is required. ... E_stl = |Ê_full(θ) − E_ideal(θ)|, (18), where E_ideal(θ) is the noiseless statevector expectation value of the full uncut circuit under θ."

    Small E_stl is, by construction, only a statement about hardware noise around the same θ's own noiseless energy. The training objective anchors θ by minimizing |E_full| with 'no externally known reference energy,' so for the negative-energy molecular Hamiltonians used (H3+, CH2, H4), it drives E_ideal(θ) toward 0 rather than the ground state. Hence the reported E_stl values do not certify that a simulator validation against the true molecular energy would pass; the metric's baseline moves with the poisoned parameters. The claim that backdoored parameters 'preserve full-circuit validation performance' is therefore equivalent to the definition of E_stl, not a derived consequence of the training loss.

full rationale

The attack-construction part is largely self-contained and non-circular: Theorem 5.1 is a one-sided Hoeffding bound explicitly not assumed to be saturated, and the K- and N-dependence experiments validate a known statistical scaling rather than a parameter fitted to the attack. The self-citations to QTrojan, QDoor, and QNBAD are comparative and not load-bearing; there is no imported uniqueness theorem or ansatz smuggled through a self-citation. The one significant by-construction step is the stealthiness criterion. Eq. (16) defines the stealth term as |E_full(θ)| and asserts this anchors θ at the variational ground state, but that requires a nonnegative Hamiltonian spectrum; the molecular benchmarks have negative ground-state energies, so minimizing |E| drives θ toward zero energy, not the ground state. The paper's stealth metric (Eq. 18) then compares the noisy full-circuit estimate to E_ideal(θ), the noiseless expectation of the same poisoned θ, so a small E_stl only says hardware noise is small, not that θ produces the correct physical energy. Thus the headline claim that poisoned parameters 'preserve full-circuit validation performance' reduces to a self-referential definition rather than an anchored benchmark. This is partial: the cut-path error amplification is still empirically demonstrated against clean baselines and is not circular. Score 6 reflects one central claim reducing by construction, while the attack-effectiveness claim retains independent empirical content.

Assumptions & free parameters 2 free parameters · 5 assumptions · 0 invented entities

The central empirical claim rests on standard statistical bounds, on the exact-cutting identity E_cut=E_full, on the assumption that the victim validates only via full-circuit simulation, and on the implicit (and false for molecular Hamiltonians) assumption that |E| minimization equals energy minimization. The attack weight lambda and shot budget are undisclosed tuning parameters.

free parameters (2)
  • attack weight lambda
    Balances stealth vs. attack terms in Eq. (16); no value or search range is reported across benchmarks.
  • shot budget N
    The finite-shot gap and E_abs depend on N; Table 3 does not report N per backend/benchmark, and Figure 6 varies N only for one configuration.
assumptions (5)
  • domain assumption E_cut(theta)=E_full(theta) under exact circuit cutting
    Used in Eq. (5) and Theorem 5.1; standard result from [48], valid for ideal noiseless reconstruction.
  • standard math Hoeffding bound applies with eigenvalues in [-1,1]
    Theorem 5.1 assumes H's eigenvalues are bounded in [-1,1]; molecular Hamiltonians are weighted sums of Pauli strings not normalized to this range.
  • ad hoc to paper Minimizing |E_full| is equivalent to minimizing variational energy
    Section 5.7 states L_stl drives theta toward the ground state; this requires nonnegative spectrum or an energy shift, neither described.
  • domain assumption Victim validates only on a full-circuit simulator and does not compare the energy value to a known reference
    Assumed in section 4.3; without this, large energy deviations would be detected.
  • domain assumption Attacker and victim use matched subcircuit compilation
    Sections 5.2 and 7.3.2 show compilation mismatch affects the attack; the paper assumes the standard CutQC default matches the attacker's training environment.

how reviews work

0 comments
Cite this review

Pith. "Pith review of CutBackdoor: A Circuit Cut Triggered Backdoor Attack on Variational Quantum Algorithms." pith.science (2026). https://pith.science/paper/HPIVW7NC

@misc{pith2026260718126,
  author       = {Pith},
  title        = {Pith review of: CutBackdoor: A Circuit Cut Triggered Backdoor Attack on Variational Quantum Algorithms},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/HPIVW7NC}},
  note         = {Machine review of arXiv:2607.18126}
}
abstract

Variational Quantum Algorithms (VQAs) are a leading paradigm for near-term quantum computing, combining parameterized quantum circuits with classical optimization across quantum chemistry, combinatorial optimization, and quantum machine learning. Since real-world VQA deployments routinely require circuits that exceed available hardware capacity, quantum circuit cutting has become an indispensable execution strategy, and pre-trained parameters are increasingly distributed through public repositories, introducing supply-chain security risks that have received little attention. Prior quantum backdoor attacks either introduce detectable circuit modifications or depend on device-specific noise, and none consider circuit cutting as an attack surface. We present CutBackdoor, the first parameter-supply-chain backdoor that uses cut circuit execution from CutQC as the deployment-time trigger against VQAs. Under noisy finite-shot circuit-cut execution, poisoned parameters preserve full-circuit validation performance while substantially increasing cut-path reconstruction error, without any circuit modification. The trigger activates when a resource-limited victim responds to a qubit-capacity mismatch by invoking the cutting workflow, requiring no attacker presence at deployment. We provide a theoretical analysis and empirically validate it across varying shot budgets. Evaluation across multiple VQA benchmarks on IBM quantum backends demonstrates cut-path energy amplification of $1.3\times$ to $2.9\times$ \revA{over clean baselines on the VQE and VQD benchmarks while maintaining small stealthiness error on the full-circuit path. The cut-path gap persists across the evaluated backends and cut placements under matched compilation; Zero-Noise Extrapolation provides only partial mitigation, and the diagonal-cost QAOA benchmark delineates the attack's structural boundary

Figures

Figures reproduced from arXiv: 2607.18126 by the authors.

Figure 1
Figure 1. Circuit cutting (b) exposes a larger attack surface [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Circuit cutting example: a 3-qubit circuit is split into [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. CutBackdoor threat model. (a) Supply chain: an attacker uploads poisoned VQA parameters [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figures from the paper (5 more)
Figure 4
Figure 4. Figure 4: Comparison of transpilation strategies on the [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 5
Figure 5. Figure 5: Noise characterization of the three 7-qubit IBMQ. Gate error rates (left), readout error rates (center), and coherence [PITH_FULL_IMAGE:figures/full_fig_p009_5.png]
Figure 6
Figure 6. Figure 6: Finite-shot gap Δ(𝜽 ∗ ) under backdoor parameters on IBMQ_Kolkata (20 trials per shot level). The Δ¯ ± 𝜎 band contracts as O (1/ √ 𝑁) (Theorem 5.1), while Δ¯ stays elevated. benchmark, while the diagonal-cost QAOA benchmark marks the attack’s structural boundary. 7.2 E…
Figure 7
Figure 7. Figure 7: Effect of CutBackdoor across different compilation [PITH_FULL_IMAGE:figures/full_fig_p010_7.png]
Figure 8
Figure 8. Figure 8: Effect of CutBackdoor with different Cut locations [PITH_FULL_IMAGE:figures/full_fig_p011_8.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

73 extracted references · 9 linked inside Pith

  1. [1]

    Brandon Augustino, Madelyn Cain, Edward Farhi, Swati Gupta, Sam Gutmann, Daniel Ranard, Eugene Tang, and Katherine Van Kirk. 2024. Strategies for running the QAOA at hundreds of qubits.arXiv preprint arXiv:2410.03015(2024)

  2. [2]

    Utkarsh Azad and Stepan Fomichev. 2023. Pennylane quantum chemistry datasets.Accessed: Jul19 (2023), 2025

  3. [3]

    Marvin Bechtold, Johanna Barzen, Frank Leymann, Alexander Mandl, Julian Obst, Felix Truger, and Benjamin Weder. 2023. Investigating the effect of circuit cutting in QAOA for the MaxCut problem on NISQ devices.Quantum Science and Technology8, 4 (2023), 045022

  4. [4]

    Ville Bergholm, Josh Izaac, Maria Schuld, Christian Gogolin, Shahnawaz Ahmed, Vishnu Ajith, M Sohaib Alam, Guillermo Alonso-Linaje, Bharath Akash- Narayanan, Ali Asadi, et al. 2018. Pennylane: Automatic differentiation of hybrid quantum-classical computations.arXiv preprint arXiv:1811.04968(2018)

  5. [5]

    Almudena Carrera Vazquez, Caroline Tornow, Diego Ristè, Stefan Woerner, Maika Takita, and Daniel J. Egger. 2024. Combining quantum processors with real-time classical communication.Nature636, 8041 (01 Dec 2024), 75–79. doi:10. 1038/s41586-024-08178-2

  6. [6]

    Marco Cerezo, Andrew Arrasmith, Ryan Babbush, Simon C Benjamin, Suguru Endo, Keisuke Fujii, Jarrod R McClean, Kosuke Mitarai, Xiao Yuan, Lukasz Cincio, et al. 2021. Variational quantum algorithms.Nature Reviews Physics3, 9 (2021), 625–644

  7. [7]

    Frederic T Chong, Diana Franklin, and Margaret Martonosi. 2017. Programming languages and compiler design for realistic quantum hardware.Nature549, 7671 (2017), 180–187

  8. [8]

    Cheng Chu, Fan Chen, Philip Richerme, and Lei Jiang. 2023. Qdoor: Exploiting approximate synthesis for backdoor attacks in quantum neural networks. In2023 IEEE International Conference on Quantum Computing and Engineering (QCE), Vol. 1. IEEE, 1098–1106

Show all 73 references
  1. [9]

    Cheng Chu, Aishwarya Hastak, and Fan Chen. 2025. Lstm-qgan: Scalable nisq generative adversarial network. InICASSP 2025-2025 IEEE International Confer- ence on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1–5

  2. [10]

    Cheng Chu, Lei Jiang, Martin Swany, and Fan Chen. 2023. Qtrojan: A circuit backdoor against quantum neural networks. InICASSP 2023-2023 IEEE Inter- national Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1–5

  3. [11]

    Cheng Chu, Qian Lou, Fan Chen, and Lei Jiang. 2025. QNBAD: Quantum Noise- induced Backdoor Attacks against Zero Noise Extrapolation. (2025)

  4. [12]

    Cheng Chu, Grant Skipper, Martin Swany, and Fan Chen. 2023. Iqgan: Robust quantum generative adversarial network for image synthesis on nisq devices. In ICASSP 2023-2023 IEEE international conference on acoustics, speech and signal processing (ICASSP). IEEE, 1–5

  5. [13]

    Gavin E Crooks. 2018. Performance of the quantum approximate optimization algorithm on the maximum cut problem.arXiv preprint arXiv:1811.08419(2018)

  6. [14]

    Subrata Das and Swaroop Ghosh. 2023. Randomized reversible gate-based obfus- cation for secured compilation of quantum circuit.arXiv preprint arXiv:2305.01133 (2023)

  7. [15]

    Subrata Das and Swaroop Ghosh. 2024. Trojan attacks on variational quantum circuits and countermeasures. In2024 25th International Symposium on Quality Electronic Design (ISQED). IEEE, 1–8

  8. [16]

    Daniel J Egger, Claudio Gambella, Jakub Marecek, Scott McFaddin, Martin Mevis- sen, Rudy Raymond, Andrea Simonetto, Stefan Woerner, and Elena Yndurain

  9. [17]

    Daniel J Egger, Ricardo García Gutiérrez, Jordi Cahué Mestre, and Stefan Woerner

  10. [18]

    Edward Farhi, Jeffrey Goldstone, and Sam Gutmann. 2014. A quantum approxi- mate optimization algorithm.arXiv preprint arXiv:1411.4028(2014)

  11. [19]

    Credit risk analysis using quantum computers.IEEE transactions on computers70, 12 (2020), 2136–2145

  12. [20]

    Eduardo Fradkin. 1989. Jordan-Wigner transformation for quantum-spin systems in two dimensions and fractional statistics.Physical review letters63, 3 (1989), 322

  13. [21]

    Roland C Farrell, Marc Illa, Anthony N Ciavarella, and Martin J Savage. 2024. Scalable circuits for preparing ground states on digital quantum computers: The Schwinger model vacuum on 100 qubits.PRX Quantum5, 2 (2024), 020315

  14. [22]

    Alexey Galda, Xiaoyuan Liu, Danylo Lykov, Yuri Alexeev, and Ilya Safro. 2021. Transferability of optimal QAOA parameters between random graphs. In2021 IEEE International Conference on Quantum Computing and Engineering (QCE). IEEE, 171–180

  15. [23]

    Keisuke Fujii, Kaoru Mizuta, Hiroshi Ueda, Kosuke Mitarai, Wataru Mizukami, and Yuya O Nakagawa. 2022. Deep variational quantum eigensolver: A divide- and-conquer method for solving a larger problem with smaller size quantum computers.PRX Quantum3, 1 (2022), 010346

  16. [24]

    Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain.arXiv preprint arXiv:1708.06733(2017)

  17. [25]

    Jérôme F Gonthier, Maxwell D Radin, Corneliu Buda, Eric J Doskocil, Clena M Abuan, and Jhonathan Romero. 2022. Measurements as a roadblock to near-term practical quantum advantage in chemistry: Resource analysis.Physical Review Research4, 3 (2022), 033154

  18. [26]

    2026.Gurobi Optimizer Reference Manual

    Gurobi Optimization, LLC. 2026.Gurobi Optimizer Reference Manual. [Online]. Available: https://www.gurobi.com

  19. [27]

    Ji Guo, Wenbo Jiang, Rui Zhang, Wenshu Fan, Jiachen Li, Guoming Lu, and Hongwei Li. 2025. Backdoor attacks against hybrid classical-quantum neural networks.Neural Networks191 (2025), 107776

  20. [28]

    IBM. 2022. Qiskit addon: circuit cutting. https://github.com/Qiskit/qiskit-addon- cutting Accessed: 2026-03-30

  21. [29]

    Oscar Higgott, Daochen Wang, and Stephen Brierley. 2019. Variational quantum computation of excited states.Quantum3 (2019), 156

  22. [30]

    Ali Javadi-Abhari, Matthew Treinish, Kevin Krsulich, Christopher J Wood, Jake Lishman, Julien Gacon, Simon Martiel, Paul D Nation, Lev S Bishop, An- drew W Cross, et al . 2024. Quantum computing with Qiskit.arXiv preprint arXiv:2405.08810(2024)

  23. [31]

    Gregoire Ithier, E Collin, P Joyez, PJ Meeson, Denis Vion, Daniel Esteve, F Chiarello, A Shnirman, Yu Makhlin, Josef Schriefl, et al . 2005. Decoherence in a superconducting quantum bit circuit.Physical Review B—Condensed Matter and Materials Physics72, 13 (2005), 134519

  24. [32]

    Emanuel Knill. 2005. Quantum computing with realistically noisy devices.Nature 434, 7029 (2005), 39–44

  25. [33]

    Abhinav Kandala, Antonio Mezzacapo, Kristan Temme, Maika Takita, Markus Brink, Jerry M Chow, and Jay M Gambetta. 2017. Hardware-efficient variational quantum eigensolver for small molecules and quantum magnets.nature549, 7671 (2017), 242–246

  26. [34]

    Ryan LaRose, Andrea Mari, Sarah Kaiser, Peter J Karalekas, Andre A Alves, Piotr Czarnik, Mohamed El Mandouh, Max H Gordon, Yousef Hindy, Aaron Robertson, et al. 2022. Mitiq: A software package for error mitigation on noisy quantum computers.Quantum6 (2022), 774

  27. [35]

    Martin Larocca, Supanut Thanasilp, Samson Wang, Kunal Sharma, Jacob Bia- monte, Patrick J Coles, Lukasz Cincio, Jarrod R McClean, Zoë Holmes, and Marco Cerezo. 2025. Barren plateaus in variational quantum computing.Nature Reviews Physics7, 4 (2025), 174–189

  28. [36]

    Weitang Li, Zhi Yin, Xiaoran Li, Dongqiang Ma, Shuang Yi, Zhenxing Zhang, Chenji Zou, Kunliang Bu, Maochun Dai, Jie Yue, et al. 2024. A hybrid quantum computing pipeline for real world drug discovery.Scientific Reports14, 1 (2024), 16942

  29. [37]

    Gushu Li, Yufei Ding, and Yuan Xie. 2019. Tackling the qubit mapping problem for NISQ-era quantum devices. InProceedings of the twenty-fourth international conference on architectural support for programming languages and operating systems. 1001–1014

  30. [38]

    Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-pruning: De- fending against backdooring attacks on deep neural networks. InInternational symposium on research in attacks, intrusions, and defenses. Springer, 273–294

  31. [39]

    Daniel A Lidar, Isaac L Chuang, and K Birgitta Whaley. 1998. Decoherence free subspaces for quantum computation.arXiv preprint quant-ph/9807004(1998)

  32. [40]

    Angus Lowe, Matija Medvidović, Anthony Hayes, Lee J O’Riordan, Thomas R Bromley, Juan Miguel Arrazola, and Nathan Killoran. 2023. Fast quantum circuit cutting with randomized measurements.Quantum7 (2023), 934

  33. [41]

    Xiaoyuan Liu, Anthony Angone, Ruslan Shaydulin, Ilya Safro, Yuri Alexeev, and Lukasz Cincio. 2022. Layer VQE: A Variational Approach for Combinatorial Optimization on Noisy Quantum Computers.IEEE Transactions on Quantum Engineering3 (2022), 1–20. doi:10.1109/TQE.2021.3140190

  34. [42]

    Jarrod R McClean, Sergio Boixo, Vadim N Smelyanskiy, Ryan Babbush, and Hartmut Neven. 2018. Barren plateaus in quantum neural network training landscapes.Nature communications9, 1 (2018), 4812

  35. [43]

    Sam McArdle, Suguru Endo, Alán Aspuru-Guzik, Simon C Benjamin, and Xiao Yuan. 2020. Quantum computational chemistry.Reviews of Modern Physics92, 1 (2020), 015003

  36. [44]

    Kosuke Mitarai and Keisuke Fujii. 2021. Constructing a virtual two-qubit gate by sampling single-qubit operations.New Journal of Physics23, 2 (2021), 023021

  37. [45]

    Jarrod R McClean, Jonathan Romero, Ryan Babbush, and Alán Aspuru-Guzik

  38. [46]

    Peter JJ O’Malley, Ryan Babbush, Ian D Kivlichan, Jonathan Romero, Jarrod R McClean, Rami Barends, Julian Kelly, Pedram Roushan, Andrew Tranter, Nan Ding, et al. 2016. Scalable quantum simulation of molecular energies.Physical Review X6, 3 (2016), 031007

  39. [47]

    Tirthak Patel, Ed Younis, Costin Iancu, Wibe de Jong, and Devesh Tiwari. 2022. Quest: systematically approximating quantum circuits for higher output fidelity. InProceedings of the 27th ACM International Conference on Architectural Support for Programming Languages and Operati...

  40. [48]

    Prakash Murali, Jonathan M Baker, Ali Javadi-Abhari, Frederic T Chong, and Mar- garet Martonosi. 2019. Noise-adaptive compiler mappings for noisy intermediate- scale quantum computers. InProceedings of the twenty-fourth international con- ference on architectural support for p...

  41. [49]

    Michael A Perlin, Zain H Saleem, Martin Suchara, and James C Osborn. 2021. Quantum circuit cutting with maximum-likelihood tomography.npj Quantum Information7, 1 (2021), 64

  42. [50]

    Alberto Peruzzo, Jarrod McClean, Peter Shadbolt, Man-Hong Yung, Xiao-Qi Zhou, Peter J Love, Alán Aspuru-Guzik, and Jeremy L O’brien. 2014. A variational eigenvalue solver on a photonic quantum processor.Nature communications5, 1 (2014), 4213

  43. [51]

    Tianyi Peng, Aram W Harrow, Maris Ozols, and Xiaodi Wu. 2020. Simulating large quantum circuits on a small quantum computer.Physical review letters125, 15 (2020), 150504

  44. [52]

    John Preskill. 2018. Quantum computing in the NISQ era and beyond.Quantum 2 (2018), 79

  45. [53]

    Jonathan Romero, Ryan Babbush, Jarrod R McClean, Cornelius Hempel, Peter J Love, and Alán Aspuru-Guzik. 2019. Strategies for quantum computing molec- ular energies using the unitary coupled cluster ansatz.Quantum Science and Technology4, 1 (2019), 014008

  46. [54]

    Christophe Piveteau and David Sutter. 2023. Circuit knitting with classical communication.IEEE Transactions on Information Theory70, 4 (2023), 2734– 2745

  47. [55]

    Nicolas PD Sawaya, Daniel Marti-Dafcik, Yang Ho, Daniel P Tabor, David E Bernal Neira, Alicia B Magann, Shavindra Premaratne, Pradeep Dubey, Anne Matsuura, Nathan Bishop, et al. 2024. HamLib: A library of Hamiltonians for benchmarking quantum algorithms and hardware.Quantum8 (...

  48. [56]

    2018.Supervised learning with quantum computers

    Maria Schuld and Francesco Petruccione. 2018.Supervised learning with quantum computers. Vol. 17. Springer

  49. [57]

    Mohan Sarovar, Timothy Proctor, Kenneth Rudinger, Kevin Young, Erik Nielsen, and Robin Blume-Kohout. 2020. Detecting crosstalk errors in quantum informa- tion processors.Quantum4 (2020), 321

  50. [58]

    Ruslan Shaydulin, Kunal Marwaha, Jonathan Wurtz, and Phillip C Lotshaw. 2021. QAOAKit: A toolkit for reproducible study, application, and verification of the QAOA. In2021 IEEE/ACM Second International Workshop on Quantum Computing Software (QCS). IEEE, 64–71

  51. [59]

    Ruslan Shaydulin, Ilya Safro, and Jeffrey Larson. 2019. Multistart methods for quantum approximate optimization. In2019 IEEE high performance extreme computing conference (HPEC). IEEE, 1–8

  52. [60]

    Ruslan Shaydulin, Phillip C Lotshaw, Jeffrey Larson, James Ostrowski, and Travis S Humble. 2023. Parameter transfer for quantum approximate optimiza- tion of weighted maxcut.ACM Transactions on Quantum Computing4, 3 (2023), 1–15

  53. [61]

    Molly C Smith, Aaron D Leu, Koichiro Miyanishi, Mario F Gely, and David M Lucas. 2025. Single-qubit gates with errors at the 10-7 level.Physical Review Letters134, 23 (2025), 230601

  54. [62]

    Shree Hari Sureshbabu, Dylan Herman, Ruslan Shaydulin, Joao Basso, Shouvanik Chakrabarti, Yue Sun, and Marco Pistoia. 2024. Parameter setting in quantum approximate optimization of weighted problems.Quantum8 (2024), 1231

  55. [63]

    Mårten Skogh, Oskar Leinonen, Phalgun Lolur, and Martin Rahm. 2023. Acceler- ating variational quantum eigensolver convergence using parameter transfer. Electronic Structure5, 3 (2023), 035002

  56. [64]

    Kristan Temme, Sergey Bravyi, and Jay M Gambetta. 2017. Error mitigation for short-depth quantum circuits.Physical review letters119, 18 (2017), 180509

  57. [65]

    Jules Tilly, Hongxiang Chen, Shuxiang Cao, Dario Picozzi, Kanav Setia, Ying Li, Edward Grant, Leonard Wossnig, Ivan Rungger, George H Booth, et al. 2022. The variational quantum eigensolver: a review of methods and best practices. Physics Reports986 (2022), 1–128

  58. [66]

    Wei Tang, Teague Tomesh, Martin Suchara, Jeffrey Larson, and Margaret Martonosi. 2021. Cutqc: using small quantum computers for large quantum circuit evaluations. InProceedings of the 26th ACM International conference on architectural support for programming languages and oper...

  59. [67]

    George Typaldos, Theodoros Trochatos, and Jakub Szefer. 2025. Quantum Cir- cuit Cutting: A Security Methodology. In2025 IEEE International Conference on Quantum Computing and Engineering (QCE), Vol. 1. IEEE, 417–427

  60. [68]

    Samson Wang, Enrico Fontana, Marco Cerezo, Kunal Sharma, Akira Sone, Lukasz Cincio, and Patrick J Coles. 2021. Noise-induced barren plateaus in variational quantum algorithms.Nature communications12, 1 (2021), 6961

  61. [69]

    George Typaldos, Wei Tang, and Jakub Szefer. 2024. Leveraging quantum circuit cutting for obfuscation and intellectual property protection. In2024 IEEE Inter- national Conference on Quantum Computing and Engineering (QCE), Vol. 1. IEEE, 1824–1834

  62. [72]

    Anbang Wu, Gushu Li, Yuke Wang, Boyuan Feng, Yufei Ding, and Yuan Xie

  63. [2016]

    The theory of variational hybrid quantum-classical algorithms.New Journal of Physics18, 2 (2016), 023023

  64. [2020]

    IEEE Transactions on Quantum Engineering1 (2020), 1–24

    Quantum computing for finance: State-of-the-art and future prospects. IEEE Transactions on Quantum Engineering1 (2020), 1–24

  65. [2021]

    arXiv preprint arXiv:2111.13730(2021)

    Towards efficient ansatz architecture for variational quantum algorithms. arXiv preprint arXiv:2111.13730(2021)

Pith tools

Reviewed August 1, 2026 · model on record in the stance chip above.