Skip to content

Adversarial Attacks on Hybrid Quantum-Classical Interference Classifier in Intelligent O-RAN

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 6493-6506 · 0 citations · 53 references

Abstract

Quantum machine learning (QML) is emerging as a key enabler of next-generation artificial intelligence (AI), offering more compact models and enhanced data processing capabilities. However, the integration of QML into AI-enabled network services can introduce new adversarial vulnerabilities, particularly the interface between classical encoders and quantum variational circuits. In this work, we investigate the susceptibility of QML-assisted signal classifiers to adversarial threats in the open radio access network (O-RAN) platforms. We introduce a new family of adversarial attacks, including a novel hybrid quantum-classical poisoning method (QC-Poison), along with hybrid gradient-based attacks (QC-FGSM and QC-PGD). QC-Poison induces long-term misclassification by injecting subtle adversarial, accumulating perturbations in the classical input space that propagate through the quantum encoder, effectively drifting the model’s decision boundary. Evaluation results show that QC-FGSM perturbs inputs based on the hybrid model’s gradients, reducing accuracy from 95.5% to 55.8%, while QC-PGD shows model’s performance reduction to 16.0% by iteratively corrupting quantum circuit parameters via loss maximization. QC-Poison achieves 23.9% accuracy under tight perturbation constraints without accessing training data or internal quantum parameters. The results expose critical blind spots in existing hybrid QML models that can be extended to AI-based features in the O-RAN core services. The study underscores the need for robust quantum-aware defenses that can mitigate stealthy adversarial attacks in distributed and QML-assisted applications in intelligent RAN.

View source

Similar papers

Preprint Jul 2026

Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

Experiments show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, suggesting effectiveness, stealthiness, and input specificity, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.

Junrui Zhang, Zemin Chen, Lusi Li et al. · 0 citations
Open access Aug 2026

Self-revealing poisons: loss-guided forensic detection and quantum unlearning of corrupted training data

Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives.

Oum Gadani, Kandarp Gajjar, Himani Trivedi et al. · 0 citations

Bachelor Data Science and Artificial Intelligence Comparison of Classical, Hybrid Quantum-Classical, and Quantum Generative Models on the Low-Dimensional Bars and Stripes Dataset

Overall, the results show that quantum and hybrid quantum-classical generative models can learn non-trivial discrete probability distributions but that their effectiveness depends strongly on the selected quantum model, ansatz, and training objective.

Gabriela Czapska · 0 citations
Conference Jul 2026

A Self-Adaptive Quantum-Capsule Cognitive Security Architecture for Zero-Trust 6G Wireless Networks

A Self-Adaptive Quantum-Capsule Cognitive Security Architecture (SA-QCCSA) is introduced for zero-trust adversarial defense in 6G wireless networks, integrating Quantum-optimized Capsule Networks (Q-CapsNet) with cognitive threat orchestration for real-time cyber-attack mitigation. Multidimensional 6G network traffic is modeled as temporal–spectral feature tensors and processed using a lightweight CNN encoder followed by primary and higher-order capsules that preserve hierarchical attack patterns. A quantum-enhanced dynamic routing mechanism, implemented using a Variational Quantum Optimization layer, adaptively tunes capsule coupling coefficients to minimize adversarial uncertainty and maximize class separability under strong evasion attacks. The framework is trained using a hybrid adversarial learning strategy that combines margin-based capsule loss with contrastive regularization, enabling robustness against FGSM, BIM, PGD, and CW attacks. Experiments conducted on CIC-IDS2017, NSL-KDD, and AWID Wi-Fi intrusion datasets demonstrate that SA-QCCSA achieves 98.7% detection accuracy, 0.986 F1-score, and 0.993 AUC, significantly outperforming conventional CNN (94.1% accuracy) and LSTM (91.6% accuracy) models. Under high-strength PGD attacks, the proposed model maintains 94.8% accuracy, while CNN performance degrades below 78%, confirming superior adversarial resilience. A cognitive zero-trust control plane dynamically adjusts quantum routing depth based on real-time threat entropy, enabling self-learning, self-healing, and proactive attack containment for future 6G and beyond wireless networks.

Sneha George, R. Joy, K. Karuppasamy · 0 citations
Jul 2026

SoK: Adversarial Robustness of the Variational Quantum Eigensolver via Red-Teaming

Noise-induced attacks that manipulate the Zero-Noise Extrapolation pipeline are the most damaging, followed by the QTrojan circuit-level backdoor, while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification.

Ahmed Azaz Humdoon, Cheng Chu, Lei Jiang et al. · 0 citations
Jul 2026

Efficient LLM Adversarial Training via Low-Rank Defense and Circuit-Guided Surrogates

This work comprehensively investigates computation-efficient strategies to speed up latent adversarial training from two complementary perspectives, and reduces per-step adversarial-training FLOPs by 48.1% while requiring only 0.0118% trainable parameters.

Weiyi He, Yuping Lin, Jiliang Tang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.