Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ Computers
Ruixuan Li
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Side Channels 2
Overview
This talk, presented by Namil Churri from the University of Texas at Dallas, in collaboration with the University of Wisconsin Madison, introduces and dissects a novel quantum side channel threat: crosstalk-induced side channels in multi-tenant Noisy Intermediate-Scale Quantum (NISQ) computers. The core problem addressed is the current underutilization and high wait times associated with expensive quantum processing units (QPUs) operating in a single-tenant model. While multi-tenancy offers a compelling solution to enhance QPU efficiency, it simultaneously introduces significant security vulnerabilities, particularly the risk of sensitive information leakage through quantum side channels.
Key moments
- 0:00 Introduction to quantum computing basics
- 2:00 Challenges of single-tenant cloud quantum computers
- 3:20 Multi-tenancy: solution for utilization, new threats
- 4:00 Why sensitive information leakage matters in quantum
- 5:10 Introducing crosstalk as a novel quantum side channel
- 6:00 Threat model and definition of crosstalk mechanism
- 6:30 Empirical observation of crosstalk's impact on outcomes
Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ Computers
Speakers: Namil Churri, Ruixuan Li
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=zg5cvEJWda4
Overview
This talk, presented by Namil Churri from the University of Texas at Dallas, in collaboration with the University of Wisconsin Madison, introduces and dissects a novel quantum side channel threat: crosstalk-induced side channels in multi-tenant Noisy Intermediate-Scale Quantum (NISQ) computers. The core problem addressed is the current underutilization and high wait times associated with expensive quantum processing units (QPUs) operating in a single-tenant model. While multi-tenancy offers a compelling solution to enhance QPU efficiency, it simultaneously introduces significant security vulnerabilities, particularly the risk of sensitive information leakage through quantum side channels.
The research demonstrates how a malicious actor can exploit the physical phenomenon of crosstalk – unintended interactions between quantum operations – to infer the structure and schedule of a victim's quantum circuit. By observing subtle deviations in measurement outcomes on their own "snooping qubits," an adversary can effectively count and time the execution of two-qubit CNOT gates in a co-located victim's program. This information, when fed into a machine learning model, specifically a Graph Convolutional Network (GCN), allows for the reconstruction and identification of the victim's confidential quantum algorithms with high accuracy, even under realistic error conditions.
The significance of this work is profound, highlighting a critical, yet previously unexplored, security concern in the rapidly evolving landscape of cloud-based quantum computing. As quantum applications proliferate across sensitive domains like finance, machine learning, and cryptography, the ability for an adversary to glean proprietary data or algorithm structures through such side channels poses a severe threat. This research not only exposes a fundamental vulnerability in shared quantum infrastructure but also underscores the urgent need for robust security measures in the design and deployment of multi-tenant quantum computing platforms.
Background
▶ Watch: Introduction to quantum computing basics (0:00)
Quantum computing fundamentally operates on qubits, the quantum analogue of classical bits. Unlike classical bits that are strictly 0 or 1, qubits can exist in a superposition of both states simultaneously, represented as a vector on a Bloch sphere. Quantum gates are operations that manipulate the state of qubits, akin to logical gates in classical computing. These gates can be single-qubit gates (e.g., X, Y, Z, phase gates) or multi-qubit gates (e.g., CNOT gates). Multi-qubit gates are crucial for creating entanglement, a unique quantum phenomenon where the states of two or more qubits become interdependent. Superposition and entanglement are the bedrock of quantum computers' potential for high-speed processing. A sequence of quantum gates forms a quantum circuit, which is ultimately executed on a quantum backend or QPU. The final step involves measurement, which collapses the qubits into classical bit outcomes (0 or 1). Due to the probabilistic nature of quantum mechanics, circuits are executed multiple times, and the output distribution reveals the expected results, alongside noise from inherent errors in current NISQ devices.
The current generation of NISQ computers are exceedingly expensive and resource-intensive. Consequently, most users access these powerful machines through cloud-based quantum computing services. In this model, users design their quantum circuits, submit them as jobs, which are then queued, compiled into hardware-compatible versions, executed on the QPU, and the results returned. A major challenge with existing cloud quantum services is their predominantly single-tenant nature. This leads to alarmingly low QPU utilization. For instance, a user employing only 12 qubits on a 127-qubit machine results in a mere 9.44% QPU utilization. This inefficiency is compounded by high wait times, where jobs can sit in a queue for anywhere from under a minute to over two and a half hours, as observed in a study across six different quantum computing backends over ten days.
To mitigate these challenges, multi-tenancy has been proposed as a solution. In a multi-tenant environment, multiple users share the same QPU concurrently. This significantly boosts utilization; for example, five users collectively using 65 qubits could achieve 51.18% QPU utilization. While economically attractive, multi-tenancy introduces a critical security question: what if a malicious user attempts to extract sensitive information from co-located victim circuits? The need to protect sensitive data on QPUs is paramount, as quantum algorithms are increasingly applied in fields like machine learning, cryptography, and biochemistry. A bank, for instance, might encode portfolio optimization data onto qubits, and its leakage could have devastating financial consequences.
In classical computing, side-channel attacks (e.g., power, timing, electromagnetic analysis) are well-established methods for extracting sensitive information by observing physical emanations from a system. These attacks have also been briefly studied in quantum computers, exhibiting similar characteristics to their classical counterparts. However, the unique quantum nature of these devices introduces entirely new categories of quantum side channels that have largely been unexplored as threats. This work specifically identifies crosstalk as such a quantum side channel. Errors are an inherent part of today's NISQ computers, stemming from non-idealities like readout assignment errors, Pauli-X errors (single-qubit), and ECR errors. These inherent errors, which manifest as deviations from ideal measurement outcomes, are precisely what an adversary can exploit to mount an attack and steal sensitive information from a victim.
Key Findings
▶ Watch: Multi-tenancy: solution for utilization, new threats (3:20)
The central discovery of this research is that crosstalk, a pervasive physical phenomenon in quantum hardware, can be leveraged as a potent quantum side channel to infer sensitive information about co-located quantum circuits in a multi-tenant environment. The talk establishes several key findings:
- Crosstalk as a Measurable Side Channel: The research demonstrates that undesired interactions between quantum operations, specifically between two-qubit CNOT gates in a victim's circuit and idle qubits in an adversary's circuit, lead to measurable deviations in the adversary's expected measurement outcomes (specifically, zero counts). While minor deviations can be attributed to general quantum noise, larger, consistent deviations are directly attributable to crosstalk.
- Correlation between Crosstalk and CNOT Gates: A direct proportionality is observed between the magnitude of crosstalk-induced zero-count deviations and the number of CNOT gates in the victim's circuit. This forms the fundamental basis for the attack: by monitoring their "snooping qubits," an adversary can effectively count the number of CNOT operations occurring in a neighboring circuit.
- Scalability and Snooping Qubit Sensitivity: The effectiveness of CNOT counting varies significantly based on the specific "snooping qubit" chosen by the adversary, highlighting the hardware-dependent nature of crosstalk. Furthermore, while initial experiments were limited by available hardware (IBM Guadaloop with 17 qubits), simulations suggest the attack's scalability up to 120-qubit benchmarks, though accuracy may decrease with increasing circuit complexity.
- Time Bucketing for Circuit Structure Inference: Beyond merely counting CNOT gates, the research introduces time bucketing as a technique to extract the schedule of CNOT gates. By dividing the execution time into discrete intervals and observing crosstalk events within each bucket, the adversary can infer the temporal distribution and, crucially, the structural arrangement of CNOT gates within the victim's circuit. This allows differentiation between circuits that might have the same total number of CNOTs but different execution sequences.
- Machine Learning for Circuit Identification: The extracted CNOT count and time-bucketed schedule data are fed into a Graph Convolutional Network (GCN). This GCN model, which represents quantum circuits as graphs (qubits as nodes, CNOTs as edges), is trained to identify victim quantum circuits. The model successfully achieved an accuracy of 85.6% when trained on a dataset of 336 benchmark circuits, even under realistic conditions with up to 20-30% fuzziness (simulated erroneous crosstalk detection, allowing for deviations of up to 3 CNOT gates). This demonstrates the robustness and practical viability of the attack.
- Realistic Threat Model: The threat model assumes no special privileges for the adversary, only the ability to share a QPU concurrently with a victim and awareness of a limited set of useful quantum algorithms (which simplifies the target space for identification). This underscores the immediate and practical nature of the identified vulnerability in current cloud quantum services.
Technical Deep Dive
▶ Watch: Why sensitive information leakage matters in quantum (4:00)
The attack hinges on the exploitation of crosstalk, specifically the undesired interaction between two-qubit CNOT gates in a victim's circuit and idle qubits within the adversary's circuit. In an ideal multi-tenant scenario, an adversary running a simple circuit on their allocated qubits, say just preparing and measuring them, would expect a 100% "zero count" if the qubits are initialized to zero. However, when a victim's complex circuit, containing numerous CNOT gates, executes concurrently on physically adjacent or interacting qubits, the electromagnetic fields and control signals associated with these CNOT operations can "bleed over" and subtly affect the idle qubits of the adversary. This unintended interaction is crosstalk.
The adversary's strategy involves running a "snooping circuit" designed to be highly sensitive to these crosstalk effects. This circuit typically involves preparing a qubit in a known state (e.g., $|0\rangle$), leaving it idle for a period, and then measuring it. The presence of crosstalk from the victim's CNOT gates causes the adversary's idle qubit to deviate from its expected state, resulting in a reduction in the observed zero counts. For example, if an idle qubit is ideally 100% in the $|0\rangle$ state, crosstalk might cause it to be measured as $|1\rangle$ a small percentage of the time, lowering the zero count to, say, 98%. The magnitude of this deviation is directly proportional to the number of CNOT gates being executed by the victim in proximity to the snooping qubit.
The process of inferring information proceeds in two main stages:
- CNOT Gate Counting and Time Bucketing:
- Crosstalk Detection: The adversary repeatedly executes their snooping circuit alongside the victim's circuit and records the measurement outcomes. Deviations from the expected ideal zero count are attributed to crosstalk.
- CNOT Count Inference: By correlating the magnitude of zero-count deviation with known calibration data or by simply observing changes over time, the adversary can infer the total number of CNOT gates active in the victim's circuit during the co-execution period. The research highlights that the choice of "snooping qubit" significantly impacts the sensitivity and accuracy of this detection, as physical connectivity and noise characteristics vary across a QPU.
- Time Bucketing: To move beyond a mere count and understand the structure of the victim's circuit, the adversary employs time bucketing. This technique involves dividing the total execution time of the victim's circuit into discrete temporal windows. By observing the crosstalk intensity (zero-count deviation) within each time bucket, the adversary can determine when CNOT gates are active. For instance, if a circuit has 10 CNOTs, time bucketing can reveal if they are all executed simultaneously in one bucket, or sequentially across multiple buckets, thereby providing a "schedule" of CNOT operations. This schedule is crucial because different quantum algorithms can have the same total number of CNOTs but vastly different temporal distributions, which directly reflects their underlying logical structure.
- Circuit Identification using Graph Convolutional Networks (GCN):
- Data Filtration: The raw crosstalk data, including total CNOT counts and time-bucketed schedules, is filtered to remove noise and enhance signal quality.
- Quantum Circuit as a Graph: The filtered data is then fed into a Graph Convolutional Network (GCN), a specialized type of neural network particularly adept at processing graph-structured data. For this application, quantum circuits are translated into graphs:
- Nodes: Represent individual qubits.
- Edges: Represent the CNOT gates connecting pairs of qubits. The time-bucketing information can be encoded as attributes of these edges or the graph structure itself, indicating the temporal activity of connections.
- Training and Identification: The GCN model is trained on a dataset of known quantum benchmark circuits. The training process involves feeding the model the CNOT count and time-bucketed schedule information for various circuits and teaching it to map these patterns to specific circuit identities. For the study, three datasets were used: dataset 1 (10 benchmark circuits), dataset 2 (25 benchmark circuits), and dataset 3 (336 benchmark circuits). Each benchmark circuit also included up to 16 different transpiled versions, which are hardware-optimized variations of the same logical circuit.
- Robustness Evaluation: To assess the practical viability of the attack under real-world noisy conditions, the researchers introduced fuzziness into their datasets. Fuzziness represents erroneous data received during crosstalk detection, allowing for a deviation of up to three CNOT gates in the adversary's count. The model's accuracy was then evaluated with increasing percentages of fuzziness.
- Performance: The GCN model, particularly when trained on the larger dataset 3, demonstrated significant robustness. It achieved an accuracy of over 80%, specifically 85.6%, in identifying victim quantum circuits even with a realistic 20-30% fuzziness. This high accuracy confirms that the crosstalk-induced side channel, combined with machine learning, is a potent threat for reconstructing and identifying quantum circuits in multi-tenant environments.
The technical depth of this attack lies in its ability to translate a subtle physical phenomenon (crosstalk) into actionable structural information about a quantum program, and then leverage advanced machine learning techniques to identify the specific algorithm being executed.
Demo / Proof of Concept
▶ Watch: Threat model and definition of crosstalk mechanism (6:00)
While the talk did not feature a live, interactive demonstration in the traditional sense, the authors presented a comprehensive proof of concept through their experimental setup and validated results, which effectively demonstrate the feasibility and efficacy of their proposed crosstalk-induced side channel attack.
The core of the proof of concept involved simulating and running experiments on actual quantum hardware to validate the principles of crosstalk detection and CNOT gate inference. The experimental validation was performed using an IBM Guadaloop quantum processor, which provided access to a 17-qubit system. This allowed the researchers to deploy both a "victim" circuit and an "adversary" circuit concurrently on the same physical QPU, mimicking a multi-tenant environment.
Here's how the proof of concept worked:
- Co-located Execution: The victim's quantum circuit (containing a varying number and arrangement of CNOT gates) and the adversary's simple snooping circuit (designed to monitor idle qubits) were scheduled and executed simultaneously on the IBM Guadaloop.
- Crosstalk Observation: The adversary's circuit, consisting of initialized qubits left idle before measurement, was designed to detect deviations in zero counts. These deviations, as discussed, were the direct physical manifestation of crosstalk from the victim's actively executing CNOT gates.
- Data Collection: Measurement results from the adversary's snooping qubits were collected. These raw results quantified the extent of crosstalk experienced.
- CNOT Gate Inference: From the collected data, the total number of CNOT gates active in the victim's circuit was inferred based on the magnitude of zero-count deviations.
- Time Bucketing Application: The execution time was divided into discrete buckets, and the crosstalk data was analyzed within each bucket to reconstruct the schedule of CNOT gate activations. This temporal information was critical for distinguishing between circuits with similar CNOT counts but different structures.
- Machine Learning Validation: The inferred CNOT counts and time-bucketed schedules were then used as input to the pre-trained Graph Convolutional Network (GCN). The model's ability to correctly identify the specific victim circuit from a pool of known benchmark circuits served as the ultimate validation of the attack. The reported accuracy of 85.6% (for the largest dataset under realistic fuzziness) directly demonstrates the success of this proof of concept.
Beyond physical experiments on the 17-qubit IBM Guadaloop, the researchers also conducted simulations. These simulations extended the scalability of their findings, showing that the attack principles could potentially apply to larger quantum systems, with benchmarks up to 120 qubits. While acknowledging that accuracy might decrease with increasing circuit complexity in larger systems due to the difficulty of precise time bucketing, the simulations reinforce the broad applicability of the crosstalk side channel. The combination of real hardware experiments and larger-scale simulations provides compelling evidence for the practical viability and significant threat posed by this attack vector.
Defensive Implications
▶ Watch: Empirical observation of crosstalk's impact on outcomes (6:30)
The discovery of crosstalk-induced side channel threats in multi-tenant NISQ computers presents a significant challenge for quantum platform providers and users, necessitating proactive defensive strategies. The primary implication is that current multi-tenant quantum cloud services, without specific countermeasures, are vulnerable to information leakage regarding users' proprietary quantum algorithms.
Several potential defensive implications and countermeasures were discussed, though the speaker noted that further research is needed to fully evaluate their effectiveness:
- Dynamical Decoupling: One promising countermeasure mentioned is dynamical decoupling. This technique involves inserting rapid sequences of single-qubit gates (like X or Y rotations) during idle periods or between two-qubit operations. The primary purpose of dynamical decoupling is to suppress unwanted environmental noise and preserve qubit coherence. In the context of crosstalk, it could potentially "mask" or average out the effects of unintended interactions, making it harder for an adversary to detect and quantify crosstalk-induced state changes on their snooping qubits. However, the speaker acknowledged that it remains to be seen if dynamical decoupling can fully prevent crosstalk detection, especially since the attack specifically targets two-qubit gate crosstalk. Furthermore, the single-qubit gates introduced for decoupling themselves could alter the perceived "schedule" of operations, potentially making circuit reconstruction even more challenging for the adversary.
- Padding with Single-Qubit Gates: A related strategy involves inserting padding with single-qubit gates between multi-qubit operations or in idle qubit channels. This could introduce noise or obfuscate the precise timing of CNOT gates, disrupting the adversary's ability to accurately perform time bucketing. If the temporal distribution of CNOTs becomes sufficiently obscured, the adversary would lose a critical piece of information needed for structural inference and subsequent machine learning-based identification.
- Hardware-Level Isolation and Scheduling: More fundamental solutions might involve hardware-level modifications or sophisticated scheduling algorithms. This could include:
- Physical Isolation: Ensuring that co-located user circuits are mapped to physically distant qubits with minimal crosstalk pathways, although this might reduce QPU utilization again.
- Dynamic Resource Allocation: Intelligent schedulers that avoid placing potentially sensitive victim circuits next to adversarial circuits based on known crosstalk characteristics of the QPU.
- Noise-Aware Compilation: Quantum compilers could be designed to introduce randomized noise or "dummy" operations to obfuscate the true circuit structure when sensitive data is being processed in a multi-tenant environment.
- Monitoring and Detection: Cloud providers could implement monitoring systems to detect anomalous QPU activity indicative of side-channel attacks. For instance, unusually high rates of "zero-count" deviations on specific idle qubits in an adversary's job, correlated with the execution of other user jobs, could flag suspicious behavior.
- Algorithmic Obfuscation: At the algorithmic level, users could explore techniques to obfuscate their quantum circuits, making them harder to identify even if their CNOT counts and schedules are partially leaked. This might involve using different transpiled versions of an algorithm or introducing controlled randomness into the circuit structure where possible.
The research emphasizes that as quantum hardware evolves, and new gate types like ECR gates (Entangling CNOT-like Rotations) replace or complement CNOT gates, new attack vectors might emerge. Therefore, a continuous security review process for new quantum hardware and software paradigms is crucial. The need for robust security in collaborative quantum computing environments is paramount, requiring ongoing research into both attack methodologies and effective countermeasures.
Key Takeaways
- Multi-tenancy in quantum computing introduces significant security risks: While essential for improving QPU utilization and reducing wait times, sharing quantum hardware enables novel side-channel attacks.
- Crosstalk is a potent quantum side channel: Undesired interactions between CNOT gates in a victim's circuit and an adversary's idle qubits allow for the detection and quantification of quantum operations.
- Adversaries can count and schedule CNOT gates: By observing deviations in measurement "zero counts" on their snooping qubits, attackers can infer the total number and, crucially, the execution schedule of CNOT gates in a co-located victim's circuit using "time bucketing."
- Machine learning facilitates circuit identification: A Graph Convolutional Network (GCN) can effectively reconstruct and identify victim quantum circuits from leaked CNOT count and schedule data, achieving 85.6% accuracy even under realistic error conditions (20-30% fuzziness).
- Urgent need for robust quantum security measures: This research highlights a fundamental vulnerability in current cloud-based quantum computing and underscores the critical need for developing and implementing countermeasures like dynamical decoupling, improved scheduling, and hardware-level isolation to secure multi-tenant QPUs.
About the Speaker(s)
The paper, titled "Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ Computers," was presented by Namil Churri. Namil Churri is associated with the University of Texas at Dallas, and this work was a collaborative effort involving researchers from both the University of Texas at Dallas and the University of Wisconsin Madison. The metadata for this talk lists Ruixuan Li as a speaker, indicating their significant contribution to this research. The presentation highlights a focus on exploring vulnerabilities in shared quantum computing environments and emphasizing the need for robust security in this emerging field.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Genuine original research on a side channel class that didn't exist in the literature before — crosstalk exploitation in multi-tenant NISQ hardware is a real threat vector that will matter more as cloud QPU sharing becomes standard practice. The attack primitive is sound, the ML pipeline is thoughtfully constructed, and 85.6% identification accuracy against 336 circuits with realistic fuzziness is a credible result. Minor reservations around the 17-qubit hardware constraint and the relatively thin treatment of defenses keep this out of must-see territory.
Heather Calloway (CISO) — PASS
Technically credible academic research into a real emerging vulnerability class in quantum computing infrastructure. Outside my lane — no governance angle, no operator decision path, no institutional accountability dimension that maps to any security program running today.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025