{"id":"https://openalex.org/W4416874625","doi":"https://doi.org/10.1109/qce65121.2025.00183","title":"Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security","display_name":"Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security","publication_year":2025,"publication_date":"2025-08-30","ids":{"openalex":"https://openalex.org/W4416874625","doi":"https://doi.org/10.1109/qce65121.2025.00183"},"language":"en","primary_location":{"id":"doi:10.1109/qce65121.2025.00183","is_oa":false,"landing_page_url":"https://doi.org/10.1109/qce65121.2025.00183","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Quantum Computing and Engineering (QCE)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5019000265","display_name":"Pascal Debus","orcid":"https://orcid.org/0009-0007-2437-2764"},"institutions":[{"id":"https://openalex.org/I4210136922","display_name":"Fraunhofer Institute for Applied and Integrated Security","ror":"https://ror.org/03w0bbr97","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210136922","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Pascal Debus","raw_affiliation_strings":["Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany","institution_ids":["https://openalex.org/I4210136922"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5095912614","display_name":"Maximilian Wendlinger","orcid":null},"institutions":[{"id":"https://openalex.org/I4210136922","display_name":"Fraunhofer Institute for Applied and Integrated Security","ror":"https://ror.org/03w0bbr97","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210136922","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Maximilian Wendlinger","raw_affiliation_strings":["Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany","institution_ids":["https://openalex.org/I4210136922"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092838148","display_name":"Kilian Tscharke","orcid":"https://orcid.org/0009-0006-7423-2498"},"institutions":[{"id":"https://openalex.org/I4210136922","display_name":"Fraunhofer Institute for Applied and Integrated Security","ror":"https://ror.org/03w0bbr97","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210136922","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Kilian Tscharke","raw_affiliation_strings":["Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany","institution_ids":["https://openalex.org/I4210136922"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001257530","display_name":"Daniel Herr","orcid":"https://orcid.org/0000-0002-0849-8339"},"institutions":[{"id":"https://openalex.org/I4210108329","display_name":"d-fine (Germany)","ror":"https://ror.org/01tppr291","country_code":"DE","type":"company","lineage":["https://openalex.org/I4210108329"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Daniel Herr","raw_affiliation_strings":["d-fine (GmbH),Frankfurt,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"d-fine (GmbH),Frankfurt,Germany","institution_ids":["https://openalex.org/I4210108329"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5120532022","display_name":"Cedric Br\u00fcgmann","orcid":null},"institutions":[{"id":"https://openalex.org/I4210108329","display_name":"d-fine (Germany)","ror":"https://ror.org/01tppr291","country_code":"DE","type":"company","lineage":["https://openalex.org/I4210108329"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Cedric Br\u00fcgmann","raw_affiliation_strings":["d-fine (GmbH),Frankfurt,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"d-fine (GmbH),Frankfurt,Germany","institution_ids":["https://openalex.org/I4210108329"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037155478","display_name":"Daniel Ohl de Mello","orcid":"https://orcid.org/0000-0002-3526-0238"},"institutions":[{"id":"https://openalex.org/I4210108329","display_name":"d-fine (Germany)","ror":"https://ror.org/01tppr291","country_code":"DE","type":"company","lineage":["https://openalex.org/I4210108329"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Daniel Ohl De Mello","raw_affiliation_strings":["d-fine (GmbH),Frankfurt,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"d-fine (GmbH),Frankfurt,Germany","institution_ids":["https://openalex.org/I4210108329"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030166577","display_name":"Juris Ulmanis","orcid":"https://orcid.org/0000-0003-0015-5371"},"institutions":[{"id":"https://openalex.org/I4210137770","display_name":"Alpine Quantum Technologies (Austria)","ror":"https://ror.org/03xxp1119","country_code":"AT","type":"company","lineage":["https://openalex.org/I4210137770"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Juris Ulmanis","raw_affiliation_strings":["Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria","institution_ids":["https://openalex.org/I4210137770"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083173538","display_name":"Alexander Erhard","orcid":"https://orcid.org/0000-0002-5020-2271"},"institutions":[{"id":"https://openalex.org/I4210137770","display_name":"Alpine Quantum Technologies (Austria)","ror":"https://ror.org/03xxp1119","country_code":"AT","type":"company","lineage":["https://openalex.org/I4210137770"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Alexander Erhard","raw_affiliation_strings":["Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria","institution_ids":["https://openalex.org/I4210137770"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086433209","display_name":"Arthur R. Schmidt","orcid":"https://orcid.org/0000-0002-7579-0030"},"institutions":[{"id":"https://openalex.org/I1317578790","display_name":"Federal Office for Information Security","ror":"https://ror.org/03v7mmm26","country_code":"DE","type":"other","lineage":["https://openalex.org/I1317578790"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Arthur Schmidt","raw_affiliation_strings":["Federal Office for Information Security (BSI),Bonn,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Federal Office for Information Security (BSI),Bonn,Germany","institution_ids":["https://openalex.org/I1317578790"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5093743374","display_name":"Fabian Petsch","orcid":null},"institutions":[{"id":"https://openalex.org/I1317578790","display_name":"Federal Office for Information Security","ror":"https://ror.org/03v7mmm26","country_code":"DE","type":"other","lineage":["https://openalex.org/I1317578790"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Fabian Petsch","raw_affiliation_strings":["Federal Office for Information Security (BSI),Bonn,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Federal Office for Information Security (BSI),Bonn,Germany","institution_ids":["https://openalex.org/I1317578790"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":10,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.0351,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.96853965,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1653","last_page":"1664"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10682","display_name":"Quantum Computing Algorithms and Architecture","score":0.25049999356269836,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10682","display_name":"Quantum Computing Algorithms and Architecture","score":0.25049999356269836,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.19580000638961792,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10020","display_name":"Quantum Information and Cryptography","score":0.1542000025510788,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4966000020503998},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.4848000109195709},{"id":"https://openalex.org/keywords/quantum","display_name":"Quantum","score":0.40860000252723694},{"id":"https://openalex.org/keywords/quantum-machine-learning","display_name":"Quantum machine learning","score":0.3919999897480011},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.37959998846054077},{"id":"https://openalex.org/keywords/interdependence","display_name":"Interdependence","score":0.3513000011444092},{"id":"https://openalex.org/keywords/commit","display_name":"Commit","score":0.3481999933719635},{"id":"https://openalex.org/keywords/field","display_name":"Field (mathematics)","score":0.3474000096321106},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.3321000039577484}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7376999855041504},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.53329998254776},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4966000020503998},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.4848000109195709},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4474000036716461},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4383000135421753},{"id":"https://openalex.org/C84114770","wikidata":"https://www.wikidata.org/wiki/Q46344","display_name":"Quantum","level":2,"score":0.40860000252723694},{"id":"https://openalex.org/C2779094486","wikidata":"https://www.wikidata.org/wiki/Q18811578","display_name":"Quantum machine learning","level":4,"score":0.3919999897480011},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.38839998841285706},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.37959998846054077},{"id":"https://openalex.org/C185874996","wikidata":"https://www.wikidata.org/wiki/Q269699","display_name":"Interdependence","level":2,"score":0.3513000011444092},{"id":"https://openalex.org/C153180980","wikidata":"https://www.wikidata.org/wiki/Q19776675","display_name":"Commit","level":2,"score":0.3481999933719635},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.3474000096321106},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.3321000039577484},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.3285999894142151},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.31859999895095825},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.3142000138759613},{"id":"https://openalex.org/C191015642","wikidata":"https://www.wikidata.org/wiki/Q1132459","display_name":"Fragmentation (computing)","level":2,"score":0.29440000653266907},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.2865000069141388},{"id":"https://openalex.org/C207850805","wikidata":"https://www.wikidata.org/wiki/Q269608","display_name":"Reverse engineering","level":2,"score":0.26899999380111694},{"id":"https://openalex.org/C58053490","wikidata":"https://www.wikidata.org/wiki/Q176555","display_name":"Quantum computer","level":3,"score":0.26750001311302185},{"id":"https://openalex.org/C110251889","wikidata":"https://www.wikidata.org/wiki/Q1569697","display_name":"Model checking","level":2,"score":0.26330000162124634},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.26249998807907104},{"id":"https://openalex.org/C58642233","wikidata":"https://www.wikidata.org/wiki/Q8269924","display_name":"Taxonomy (biology)","level":2,"score":0.259799987077713},{"id":"https://openalex.org/C121822524","wikidata":"https://www.wikidata.org/wiki/Q5157582","display_name":"Computer security model","level":2,"score":0.259799987077713},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.25279998779296875}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/qce65121.2025.00183","is_oa":false,"landing_page_url":"https://doi.org/10.1109/qce65121.2025.00183","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Quantum Computing and Engineering (QCE)","raw_type":"proceedings-article"},{"id":"pmh:oai:publica.fraunhofer.de:publica/508133","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/508133","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":41,"referenced_works":["https://openalex.org/W2051267297","https://openalex.org/W2399587145","https://openalex.org/W2753783305","https://openalex.org/W2760053505","https://openalex.org/W2794444783","https://openalex.org/W2943955321","https://openalex.org/W2998262898","https://openalex.org/W3000731494","https://openalex.org/W3012697779","https://openalex.org/W3016880330","https://openalex.org/W3047634080","https://openalex.org/W3087413022","https://openalex.org/W3107965876","https://openalex.org/W3130944012","https://openalex.org/W3133688247","https://openalex.org/W3163669402","https://openalex.org/W3169231649","https://openalex.org/W3177454279","https://openalex.org/W4282963285","https://openalex.org/W4285345508","https://openalex.org/W4292070398","https://openalex.org/W4293370934","https://openalex.org/W4293846201","https://openalex.org/W4310155627","https://openalex.org/W4372055232","https://openalex.org/W4375868945","https://openalex.org/W4375928273","https://openalex.org/W4381997526","https://openalex.org/W4386694300","https://openalex.org/W4388857017","https://openalex.org/W4389158819","https://openalex.org/W4389162798","https://openalex.org/W4392754351","https://openalex.org/W4393930472","https://openalex.org/W4401581512","https://openalex.org/W4402351418","https://openalex.org/W4405833945","https://openalex.org/W4406261947","https://openalex.org/W4406262033","https://openalex.org/W4410854887","https://openalex.org/W4412883246"],"related_works":[],"abstract_inverted_index":{"Quantum":[0],"Machine":[1],"Learning":[2],"(QML)":[3],"systems":[4],"inherit":[5],"vulnerabilities":[6],"from":[7,38],"classical":[8,120,186],"machine":[9,127,187,241],"learning":[10,128],"while":[11],"introducing":[12],"new":[13],"attack":[14,34,92,143,166],"surfaces":[15],"rooted":[16],"in":[17,57,119,172,235],"the":[18,71,91,108,125,182,236],"physical":[19],"and":[20,41,48,65,104,122,140,152,198,202,211,217,231],"algorithmic":[21],"layers":[22],"of":[23,30,73,90,164,239],"quantum":[24,126,240],"computing.":[25],"Despite":[26],"a":[27,161,173,224],"growing":[28],"body":[29],"research":[31],"on":[32,155],"individual":[33,97],"vectors":[35,167],"-":[36,51,145],"ranging":[37],"adversarial":[39],"poisoning":[40,207],"evasion":[42],"to":[43,124,169],"circuit-level":[44],"backdoors,":[45],"side-channel":[46,196],"leakage,":[47],"model":[49,215],"extraction":[50,216],"these":[52],"threats":[53,194],"are":[54],"often":[55],"analyzed":[56],"isolation,":[58],"with":[59],"unrealistic":[60],"assumptions":[61],"about":[62,136],"attacker":[63,137],"capabilities":[64],"system":[66],"environments.":[67],"This":[68,221],"fragmentation":[69],"hampers":[70],"development":[72],"effective,":[74],"holistic":[75],"defense":[76],"strategies.":[77],"In":[78],"this":[79],"work,":[80],"we":[81,159],"argue":[82],"that":[83,178],"QML":[84,109,165],"security":[85],"requires":[86],"more":[87,227],"structured":[88,134],"modeling":[89,230],"surface,":[93],"capturing":[94],"not":[95],"only":[96],"techniques":[98],"but":[99],"also":[100],"their":[101],"relationships,":[102],"prerequisites,":[103],"potential":[105],"impact":[106],"across":[107],"pipeline.":[110],"We":[111,189],"propose":[112],"adapting":[113],"kill":[114,175],"chain":[115,176],"models,":[116],"widely":[117],"used":[118],"IT":[121],"cybersecurity,":[123],"context.":[129],"Such":[130],"models":[131],"allow":[132],"for":[133,185,226],"reasoning":[135],"objectives,":[138],"capabilities,":[139],"possible":[141],"multi-stage":[142],"paths":[144],"spanning":[146],"reconnaissance,":[147],"initial":[148],"access,":[149],"manipulation,":[150],"persistence,":[151],"exfiltration.":[153],"Based":[154],"extensive":[156],"literature":[157],"analysis,":[158],"present":[160],"detailed":[162],"taxonomy":[163],"mapped":[168],"corresponding":[170],"stages":[171],"quantum-aware":[174],"framework":[177],"is":[179],"inspired":[180],"by":[181],"MITRE":[183],"ATLAS":[184],"learning.":[188,242],"highlight":[190],"interdependencies":[191],"between":[192],"physical-level":[193],"(like":[195],"leakage":[197],"crosstalk":[199],"faults),":[200],"data":[201,219],"algorithm":[203],"manipulation":[204],"(such":[205],"as":[206],"or":[208],"circuit":[209],"backdoors),":[210],"privacy":[212],"attacks":[213],"(including":[214],"training":[218],"inference).":[220],"work":[222],"provides":[223],"foundation":[225],"realistic":[228],"threat":[229],"proactive":[232],"security-in-depth":[233],"design":[234],"emerging":[237],"field":[238]},"counts_by_year":[{"year":2026,"cited_by_count":4}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-12-01T00:00:00"}
