Skip to main content
QUICK REVIEW

[Paper Review] A Primer on Security of Quantum Computing Hardware

Swaroop Ghosh, Suryansh Upadhyay|arXiv (Cornell University)|May 4, 2023
Quantum Computing Algorithms and Architecture4 citations
TL;DR

This paper provides a comprehensive overview of hardware security threats in quantum computing, identifying vulnerabilities in supply chains, qubit technologies, and compilation pipelines. It proposes countermeasures such as RZ gate insertion to thwart power-side-channel attacks and calls for systematic research into quantum system security across hardware, software, and algorithmic layers.

ABSTRACT

Quantum computing is an emerging computing paradigm that can potentially transform several application areas by solving some of the intractable problems from classical domain. Similar to classical computing systems, quantum computing stack including software and hardware rely extensively on third parties many of them could be untrusted or less-trusted or unreliable. Quantum computing stack may contain sensitive Intellectual Properties (IP) that requires protection. From hardware perspective, quantum computers suffer from crosstalk that couples two programs in a multi-tenant setting to facilitate traditionally known fault injection attacks. Furthermore, third party calibration services can report incorrect error rates of qubits or mis-calibrate the qubits to degrade the computation performance for denial-of-service attacks. Quantum computers are expensive and access queue is typically long for trusted providers. Therefore, users may be enticed to explore untrusted but cheaper and readily available quantum hardware which can enable stealth of IP and tampering of quantum programs and/or computation outcomes. Recent studies have indicated the evolution of efficient but untrusted compilation services which presents risks to the IPs present in the quantum circuits. The untrusted compiler can also inject Trojans and perform tampering. Although quantum computing can involve sensitive IP and private information and can solve problems with strategic impact, its security and privacy has received inadequate attention. This paper provides comprehensive overview of the basics of quantum computing, key vulnerabilities embedded in the quantum systems and the recent attack vectors and corresponding defenses. Future research directions are also provided to build a stronger community of quantum security investigators.

Motivation & Objective

  • To identify and analyze critical security and privacy vulnerabilities in the quantum computing hardware stack, particularly in multi-tenant and third-party environments.
  • To highlight the risks posed by untrusted third parties in the quantum hardware supply chain, including fabrication, calibration, and compilation services.
  • To examine how sensitive intellectual property (IP) and private information in quantum circuits can be exposed through side-channel attacks and tampering.
  • To propose practical defense mechanisms such as virtual RZ gate insertion to mitigate power-side-channel attacks.
  • To outline future research directions for securing quantum computing systems across hardware, software, and algorithmic layers.

Proposed method

  • Conduct a systematic analysis of the quantum computing stack, focusing on hardware, software, and third-party service components.
  • Identify attack surfaces through threat modeling, including fault injection, side-channel attacks (e.g., power-based), and supply chain compromises.
  • Propose a defense mechanism using virtual RZ gates—implemented via arbitrary wave generators (AWG)—to mask control pulse information in power traces.
  • Demonstrate that RZ gates, being virtual and non-pulsed, are undetectable in power-side channels, thus impeding reverse engineering of quantum circuits.
  • Advocate for the integration of obfuscation techniques like random substitution of gates with equivalent RZ-based sequences to increase attacker uncertainty.
  • Call for cross-layer research into hardware-specific vulnerabilities, especially across emerging qubit technologies (e.g., superconducting, silicon spin, topological qubits).

Experimental results

Research questions

  • RQ1What are the primary hardware-level threats to quantum computing systems, particularly in multi-tenant or third-party environments?
  • RQ2How can side-channel attacks, such as power-based analysis, be used to extract sensitive information from quantum control pulses?
  • RQ3In what ways can untrusted compilers or calibration services compromise the integrity and confidentiality of quantum programs and IP?
  • RQ4What are the unique security challenges posed by diverse qubit technologies and their associated hardware stacks?
  • RQ5How can obfuscation and circuit transformation techniques like RZ gate insertion enhance the security of quantum circuits against reverse engineering?

Key findings

  • Quantum computing hardware is vulnerable to fault injection and side-channel attacks due to crosstalk and power leakage in control pulses.
  • Third-party calibration services can degrade performance or report false error rates, enabling denial-of-service attacks.
  • Untrusted compilers may inject Trojans or tamper with quantum circuits, leading to IP theft or computation manipulation.
  • Power-side-channel attacks can reconstruct control pulse information, enabling reverse engineering of quantum circuits.
  • The use of virtual RZ gates—implemented without physical pulses—renders them undetectable in power traces, significantly increasing resistance to side-channel analysis.
  • Random substitution of gates with equivalent RZ-based sequences increases attacker uncertainty and impedes circuit reconstruction, enhancing security.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.