2026· IEEE Transactions on Network and Service Management· Vol 23, pp. 6493-6506· 0 citations· 53 references
Abstract
Quantum machine learning (QML) is emerging as a key enabler of next-generation artificial intelligence (AI), offering more compact models and enhanced data processing capabilities. However, the integration of QML into AI-enabled network services can introduce new adversarial vulnerabilities, particularly the interface between classical encoders and quantum variational circuits. In this work, we investigate the susceptibility of QML-assisted signal classifiers to adversarial threats in the open radio access network (O-RAN) platforms. We introduce a new family of adversarial attacks, including a novel hybrid quantum-classical poisoning method (QC-Poison), along with hybrid gradient-based attacks (QC-FGSM and QC-PGD). QC-Poison induces long-term misclassification by injecting subtle adversarial, accumulating perturbations in the classical input space that propagate through the quantum encoder, effectively drifting the model’s decision boundary. Evaluation results show that QC-FGSM perturbs inputs based on the hybrid model’s gradients, reducing accuracy from 95.5% to 55.8%, while QC-PGD shows model’s performance reduction to 16.0% by iteratively corrupting quantum circuit parameters via loss maximization. QC-Poison achieves 23.9% accuracy under tight perturbation constraints without accessing training data or internal quantum parameters. The results expose critical blind spots in existing hybrid QML models that can be extended to AI-based features in the O-RAN core services. The study underscores the need for robust quantum-aware defenses that can mitigate stealthy adversarial attacks in distributed and QML-assisted applications in intelligent RAN.
Experiments show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, suggesting effectiveness, stealthiness, and input specificity, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.
Junrui Zhang, Zemin Chen, Lusi Li et al.· 0 citations
Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives.
Overall, the results show that quantum and hybrid quantum-classical generative models can learn non-trivial discrete probability distributions but that their effectiveness depends strongly on the selected quantum model, ansatz, and training objective.
A Self-Adaptive Quantum-Capsule Cognitive Security Architecture (SA-QCCSA) is introduced for zero-trust adversarial defense in 6G wireless networks, integrating Quantum-optimized Capsule Networks (Q-CapsNet) with cognitive threat orchestration for real-time cyber-attack mitigation. Multidimensional 6G network traffic is modeled as temporal–spectral feature tensors and processed using a lightweight CNN encoder followed by primary and higher-order capsules that preserve hierarchical attack patterns. A quantum-enhanced dynamic routing mechanism, implemented using a Variational Quantum Optimization layer, adaptively tunes capsule coupling coefficients to minimize adversarial uncertainty and maximize class separability under strong evasion attacks. The framework is trained using a hybrid adversarial learning strategy that combines margin-based capsule loss with contrastive regularization, enabling robustness against FGSM, BIM, PGD, and CW attacks. Experiments conducted on CIC-IDS2017, NSL-KDD, and AWID Wi-Fi intrusion datasets demonstrate that SA-QCCSA achieves 98.7% detection accuracy, 0.986 F1-score, and 0.993 AUC, significantly outperforming conventional CNN (94.1% accuracy) and LSTM (91.6% accuracy) models. Under high-strength PGD attacks, the proposed model maintains 94.8% accuracy, while CNN performance degrades below 78%, confirming superior adversarial resilience. A cognitive zero-trust control plane dynamically adjusts quantum routing depth based on real-time threat entropy, enabling self-learning, self-healing, and proactive attack containment for future 6G and beyond wireless networks.
Sneha George, R. Joy, K. Karuppasamy· 2026 International Conferenc...· 0 citations
Noise-induced attacks that manipulate the Zero-Noise Extrapolation pipeline are the most damaging, followed by the QTrojan circuit-level backdoor, while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification.
Ahmed Azaz Humdoon, Cheng Chu, Lei Jiang et al.· arXiv.org· 0 citations
This work comprehensively investigates computation-efficient strategies to speed up latent adversarial training from two complementary perspectives, and reduces per-step adversarial-training FLOPs by 48.1% while requiring only 0.0118% trainable parameters.