Skip to content
Open access

QuantumGuard: A Post-Quantum Resilient Deception-Driven Framework for Proactive Threat Hunting and Cognitive Honeynet Orchestration in 6G-Enabled Cyber-Physical Systems

2026 · International Journal of Advanced Computer Science and Applications · Vol 17 · 0 citations · 43 references

TL;DR

This study presents QuantumGuard, a proactive cybersecurity framework that inverts the conventional defender posture by integrating cognitive honeynets, post-quantum-secured intelligence channels, and reinforcement-learning-driven deception adaptation across 6G-enabled cyber-physical environments.

Abstract

The convergence of 6G ultra-reliable low-latency communications, massive cyber-physical actuation, and the looming threat of cryptographically relevant quantum computers exposes a fundamentally new attack surface that is poorly addressed by reactive intrusion-detection paradigms. This study presents QuantumGuard, a proactive cybersecurity framework that inverts the conventional defender posture by integrating cognitive honeynets, post-quantum-secured intelligence channels, and reinforcement-learning-driven deception adaptation across 6G-enabled cyber-physical environments. The principal contribution is the architectural integration of four previously disjoint capabilities—a cognitive honeynet orchestrator, a reinforcement-learning deception policy engine operating under partial observability, a transformer-based MITRE ATT&CK attribution network, and a post-quantum federated intelligence bus se-cured with CRYSTALS-Kyber and CRYSTALS-Dilithium—into a single closed-loop control architecture for 6G cyber-physical systems. To assess feasibility, we report a preliminary evaluation on the CICAPT-IIoT-2024 and Edge-IIoTset benchmark datasets, complemented by a 320-endpoint 6G slice testbed configured, as described in Section IV. Initial results indicate an attacker engagement-retention rate of approximately 96.42 per cent, MITRE ATT&CK technique-attribution accuracy of approximately 91.8 per cent, a 78.6 per cent reduction in median attacker dwell time relative to passive honeypot baselines, and a deception-induced production-traffic overhead of 1.7 per cent. The PQ-FIB sustains a 14.2 ms median post-quantum handshake latency at slice scale. We position these numbers as preliminary evidence of operational viability under the evaluated threat model rather than as fully characterized performance bounds; a follow-up empirical study, planned for a separate publication, will extend the evaluation to deception-aware adversaries and sustained-attack stress conditions.

Read PDF

Similar papers

Open access Aug 2026

Stackelberg Games for the “Active Deception” Strategy in the Process of Critical Infrastructure Migration to Post-Quantum Cryptography

The coming era of quantum supremacy has created an existential threat to critical information infrastructures (CIIs). This threat is realized through delayed attack vectors of the “Harvest Now, Decrypt Later” (HNDL) class. Existing security paradigms dictate forced migration to post-quantum cryptography (PQC) algorithms. However, in the context of legacy architectures, and in particular in the ICS and SCADA segments, such a strategy generates quantum technological friction. This friction can trigger cascading failures of legitimate CII services. This article proposes addressing the PQC transformation problem not as a linear IT modernization task, but as a general-sum differential Stackelberg game. The concept of “active deception” (Cyber Deception) is described as a Leader (Defender) strategy, i.e., the variable redistribution of budgets between real cryptographic migration and the generation of resource-intensive decoy infrastructures. Using the Forward-Backward Sweep Method algorithm, optimal software controls are obtained for three typical architectural profiles, calibrated using statistical data from the critical information infrastructure of the Republic of Kazakhstan. Numerical simulations have demonstrated that in high-inertia and strategic networks, maximizing active deception creates the necessary “temporal buffer”, minimizing the damage from an HNDL compromise while maintaining operational continuity. The results support the need to revise rigid cryptographic transition regulations in favor of flexible, mathematically sound hybrid strategies.

Kulzhan Togzhanova, V. Lakhno, Zhuldyz Alimseitova et al. · 0 citations
Open access Aug 2026

Cybersecurity-Enabled Secure Manufacturing Framework Using Quantum-Safe Cryptographic Protocols for Industrial Control Systems and Smart Factories

The rapid progress of quantum computing is about to destabilise the foundation of classical cryptography. This is an unprecedented threat to industrial control systems (ICS) that settle for outdated communication protocols. Systems also have stolid performance. This paper describes the first comprehensive multi-layered quantum-safe security system designed to protect the entirety of industrial and cyber-physical systems from classical and quantum threats. The system designed marries hybrid cryptographic primitives: NIST-approved post-quantum algorithms Kyber and Dilithium with classical X25519 and Ed25519 for maintaining confidentiality, integrity, and authenticity. A session layer is stateful and implements authenticated encryption, forward secrecy, and anti-replay. An application layer has context-aware modules for anomaly detection and role-based access control. It also includes secure firmware validation. Experimental testing in accordance with a SCADA-PLC environment simulation proves that cryptographic latency of the system is below a millisecond and, therefore, it does not breach stringent industrial control loop targets. This also demonstrates industrial latency. Benchmarking proves that hybrid systems are computationally trivial relative to classical systems, thus, the suggested defence-in-depth design bridges the significant gap between practical post-quantum security and industrial application. This provides quantum peer-to-peer communication, concurrent trust in process integrity, trusted firmware, and process control to smart manufacturing systems.

Hemlathadhevi A, Shanmugapriya K, L. Jabasheela et al. · 0 citations
Open access Jul 2026

Cryptographic DoS Amplification in Hybrid Post-Quantum Deployments: Adversarial Algorithm Substitution and Its Countermeasures

The Cryptographic Amplification Factor (CAF) is defined, a metric for the per-resource cost asymmetry that an adversary induces by forcing a TLS 1.3 server onto a high-cost signature algorithm (SLH-DSA instead of a low-cost one (ECDSA or ML-DSA) instead of a low-cost one (ECDSA or ML-DSA).

Nazmus Salehin Sammo, Sariya Akhter Lura, Raza Nowrozy et al. · 0 citations
Open access Aug 2026

Quantum-Assisted Cross-Layer Intrusion Detection and Distributed-AI-Driven (QSec-DAI) Active Attribution of Insider and Man-in-the-Middle Attacks in Cooperative Sensing

Cooperative sensing systems that exchange state estimates are exposed to two types of adversaries, namely, insiders who transmit correctly authenticated falsified content and outsiders who modify messages in transit after compromising a symmetric link key, each requiring a distinct mitigation strategy. These attacks are observationally identical to a detector that examines only message content, although an insider must be revoked and an outsider must be countered through key rotation and link hardening. To distinguish between insider falsification and outsider in-transit message modification, a cross-layer intrusion detection and attack-attribution framework named QSec-DAI is proposed. Per-message anomaly scores are supplied by a recurrent detector, and a hybrid-symmetric, post-quantum and quantum authentication stack is arbitrated by belief-desire-intention agents under a finite-key budget. Authentication is used as an active probe because a suspicious link is hardened, and the persistence or disappearance of the anomaly is then observed. On real cooperative-localization data, an area under the receiver operating characteristic curve of 0.981 is achieved. Benign, insider and outsider classes are attributed with a macro-averaged accuracy of 0.794 and a man-in-the-middle recall of 0.719. Under the explicitly defined attribution mapping, outsider recall is zero for the evaluated baselines that remain in fixed-symmetric mode after key exposure. In the real-data evaluation, malicious influence on fusion is limited to 0.10 percent. The no-cooperation control indicates that several classical defenses suppress attacks mainly by discarding cooperative information rather than by preserving useful cooperation. Protocol-level fault injection shows that replay is rejected while monotonic freshness state is intact, whereas compromise of the verifier or of all independent strong credentials removes defensible outsider identifiability. The quantum component is therefore presented as one resource-constrained strong-authentication option rather than as a source of quantum-enhanced anomaly detection.

Iacovos I. Ioannou, M. Georgiades · 0 citations
Conference Jul 2026

A Self-Adaptive Quantum-Capsule Cognitive Security Architecture for Zero-Trust 6G Wireless Networks

A Self-Adaptive Quantum-Capsule Cognitive Security Architecture (SA-QCCSA) is introduced for zero-trust adversarial defense in 6G wireless networks, integrating Quantum-optimized Capsule Networks (Q-CapsNet) with cognitive threat orchestration for real-time cyber-attack mitigation. Multidimensional 6G network traffic is modeled as temporal–spectral feature tensors and processed using a lightweight CNN encoder followed by primary and higher-order capsules that preserve hierarchical attack patterns. A quantum-enhanced dynamic routing mechanism, implemented using a Variational Quantum Optimization layer, adaptively tunes capsule coupling coefficients to minimize adversarial uncertainty and maximize class separability under strong evasion attacks. The framework is trained using a hybrid adversarial learning strategy that combines margin-based capsule loss with contrastive regularization, enabling robustness against FGSM, BIM, PGD, and CW attacks. Experiments conducted on CIC-IDS2017, NSL-KDD, and AWID Wi-Fi intrusion datasets demonstrate that SA-QCCSA achieves 98.7% detection accuracy, 0.986 F1-score, and 0.993 AUC, significantly outperforming conventional CNN (94.1% accuracy) and LSTM (91.6% accuracy) models. Under high-strength PGD attacks, the proposed model maintains 94.8% accuracy, while CNN performance degrades below 78%, confirming superior adversarial resilience. A cognitive zero-trust control plane dynamically adjusts quantum routing depth based on real-time threat entropy, enabling self-learning, self-healing, and proactive attack containment for future 6G and beyond wireless networks.

Sneha George, R. Joy, K. Karuppasamy · 0 citations
Open access Aug 2026

Beyond encryption: post-quantum cryptography and the future of quantum-safe networks

The rapid advancement of quantum computing presents an existential threat to the mathematical foundations of modern internet security. Fault-tolerant quantum computers are projected to reach the logical qubit scale necessary to execute Shor's algorithm by 2030–2035, threatening currently deployed public-key cryptography infrastructures. We evaluate the performance metrics of integrating post-quantum cryptography (PQC), specifically the newly finalized NIST standards (FIPS 203, 204, and 205), with quantum key distribution (QKD) across communication networks. Our analysis demonstrates that while hybrid PQC-QKD models reduce long-term key compromise probabilities to near 0%, they introduce a 15% to 40% increase in bandwidth overhead during initial cryptographic handshakes. Given that enterprise-wide cryptographic migrations historically require 7–10 years, organizations face an immediate vulnerability window against “harvest now, decrypt later” adversaries. Ultimately, we propose a phased, cryptographically agile framework to achieve a Zero-Trust, Quantum-Safe network architecture within a 5-year implementation timeline.

R. Delhibabu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.