Skip to content

How Quantum Is the Advantage? A Fair, Calibration- and Noise-Aware Benchmark and Attribution Audit of Quantum Machine Learning for Network Intrusion Detection

Aug 2026 · 0 citations · 13 references
Physics Computer Science

TL;DR

A quantum-attribution audit is introduced that quantifies how much of any gain is genuinely attributable to the quantum component of quantum models, and attributes this to classical preprocessing and regularisation rather than quantum effects.

Abstract

Quantum machine learning (QML) for network intrusion detection (NIDS) is routinely reported to reach near-perfect accuracy, yet the most rigorous studies find that well-tuned classical models remain competitive, and that apparent quantum gains may be artefacts of classical dimensionality reduction and implicit regularisation rather than genuine quantum effects. We ask not whether a quantum model can post a high accuracy, but how quantum the advantage really is. We present a unified, reproducible QML-IDS benchmark evaluating hybrid variational quantum circuits and quantum-kernel SVMs against five honestly-tuned classical baselines across four standard NIDS datasets (NSL-KDD, UNSW-NB15, CICIDS2017, NF-ToN-IoT-v2) under one leakage-controlled protocol, with an equal-budget feature view, imbalance- and calibration-aware metrics with significance testing, and a simulated NISQ noise sweep. We introduce a quantum-attribution audit (parameter-matched classical controls, a random-feature kernel, and a regularisation sweep) that quantifies how much of any gain is genuinely attributable to the quantum component. Tuned classical models (Random Forest, XGBoost) match or exceed the quantum models on aggregate detection on every dataset, and the audit attributes this to classical preprocessing and regularisation rather than quantum effects. Two advantages survive false-discovery-rate correction: the quantum-kernel SVM out-ranks its direct classical surrogate (a random-feature kernel) on AUPRC and ROC-AUC, and a small four-qubit hybrid out-detects the best classical baseline at the 1% false-positive operating point on the distribution-shifted NSL-KDD task (p = 0.005, BH q = 0.030). Code, seeds, and splits are released; our contribution stands whether quantum wins, ties, or loses.

View source

Similar papers

Conference Jul 2026

Benchmarking Classical and Quantum Machine Learning for Intrusion Detection Across Multiple Datasets

This paper presents a comparative benchmarking study of classical and quantum machine learning models for intrusion detection using three benchmark datasets: NSL-KDD, UNSW-NB15, and MQTTEEB-D2025. The study evaluates how preprocessing choices, feature selection strategies, and quantum encoding methods influence model performance across datasets with different levels of noise and complexity. A unified pipeline is adopted, incorporating normalization, imbalance handling, dimensionality reduction, and two feature selection approaches: Random Forest importance and a quantum-aware method based on Quantum Kernel Alignment with Mutual Information. Four models are assessed: Support Vector Machine, Random Forest, Quantum Support Vector Machine, and Pegasos Quantum SVM. Results show that classical models remain stable across datasets, while quantum models are more sensitive to feature representation and kernel alignment. Quantum performance improves significantly with quantum-aware feature selection, particularly on cleaner datasets, whereas heterogeneous datasets remain challenging. Pegasos Quantum SVM offers a favorable balance between accuracy and computational efficiency, highlighting the importance of preprocessing alignment for practical quantum intrusion detection.

Taha M. Mahmoud, N. Kaabouch · 0 citations
Open access Jul 2026

Hybrid Quantum-Classical Intrusion Detection with Quantum Feature Representations under NISQ Constraints

Intrusion detection systems must balance predictive quality, robustness, and computational cost, yet the role of quantum representations under NISQ constraints remains unclear. This paper investigates whether quantum principal component analysis (QPCA) can provide useful features for IDS without relying on claims of end-to-end quantum superiority. We evaluate PCA- and QPCA-based pipelines combined with Logistic Regression, SVM, and Random Forest, and include a QPCA→VQC branch as a comparative quantum arm. Experiments on CICIDS2017 and NSL-KDD under nisq preset and scaled preset use simulator-based quantum execution, multi-seed evaluation, Wilcoxon–Holm tests, bootstrap confidence intervals, and cost analysis. Results show no universal advantage of QPCA, but selective ranking gains: ROC-AUC improves from 0.5397 to 0.8772 (CICIDS2017) and from 0.7453 to 0.8063 (NSL-KDD), both with corrected significance under matched data budgets. Overall, QPCA is most useful as a representation enhancer under NISQ-compatible, not hardware-validated, constraints.

Murilo Salem, D. Pontes, Luísa Böhm et al. · 0 citations
Open access Jul 2026

Beyond encryption: quantum-enhanced behavioral security for the post-quantum era

This study aims to develop and validate a quantum-enhanced behavioral security framework that integrates a lightweight quantum obfuscation layer into classical intrusion detection systems (IDSs). The primary objective is to harden these models against post-quantum threats, specifically model extraction and feature inversion attacks, while maintaining high detection accuracy across both traditional machine learning and deep learning architectures. A quantum feature obfuscation layer was designed using 6-qubit parameterized circuits with angle encoding and variational ansatz to nonlinearly transform behavioral features. This layer was integrated with classical classifiers (random forest, support vector machine, logistic regression) and a deep learning model multi-layer perceptron (MLP). The framework was evaluated on UNSW-NB15 and NSL-KDD datasets using Qiskit Aer simulators in Google Colab, measuring accuracy, precision, recall, F1-score, model extraction error (MEE) and feature inversion error (FIE). Quantum-assisted models maintained detection performance comparable to classical baselines, with accuracy degradation of 0.7% across all architectures. Security resilience significantly improved, with a 3–4× increase in both MEE and FIE, indicating substantially enhanced resistance to model theft and feature reconstruction. The framework demonstrated improved noise tolerance under Gaussian perturbations. The MLP achieved 92.5% accuracy (classical) versus 91.8% (quantum-assisted), with 3.3× and 3.5× improvements in MEE and FIE, respectively. The evaluation was conducted entirely on quantum simulators, not capturing real hardware noise, decoherence and fidelity limitations. The threat model assumes secrecy of quantum circuit parameters, representing a form of model-level security through obscurity. Scalability is constrained by exponential simulation costs, limiting current experiments to 6 qubits. Only feedforward neural networks (MLP) were tested; advanced architectures like CNNs, LSTMs and transformers require future validation. The framework’s resilience against adversaries with partial knowledge of the ansatz structure remains unexplored. The framework provides a pragmatic, classifier-agnostic defense layer deployable on freely accessible cloud platforms (Google Colab) without specialized quantum hardware. With only 15–25 ms inference overhead and 40–60% training overhead, it offers viable post-quantum hardening for security-critical applications. Resource-constrained environments such as edge computing nodes and IoT deployments can benefit from this approach. The demonstration that meaningful security gains (3–4× improvement) are achievable using only 6 qubits lowers the barrier for organizations to adopt quantum-assisted security measures today. As quantum computing threatens classical cryptography, protecting behavioral analytics becomes crucial for critical infrastructure, financial systems and healthcare networks. This research contributes to building resilient cyber defense mechanisms that protect sensitive data and privacy even when encryption is compromised. By democratizing access to quantum-enhanced security through cloud-based simulation platforms, the framework helps bridge the gap between institutions with varying resources, promoting more equitable cybersecurity preparedness for the post-quantum era across both developed and developing nations. This work shifts the focus of quantum-enhanced security from pure cryptographic replacement to model-hardening, harnessing quantum state complexity as a defensive mechanism rather than pursuing quantum advantage for classification speed. It introduces a novel quantum obfuscation layer specifically designed for IDS, validated across both traditional ML and deep learning architectures. The consistent security improvements (3–4×) across classifier types confirm the approach is classifier-agnostic. The Colab-based implementation ensures reproducibility and accessibility, providing a practical foundation for future quantum-aware cyber defense research and deployment.

Soha Rawas, Mohammed Al Saleh, Agariadne Dwinggo Samala et al. · 0 citations
Preprint Aug 2026

Benchmarking Quantum Machine Learning for Power-System Attack Detection: Evaluation Choices Decide the Outcome Before the Models Do

Machine-learning detectors for power-system cyberattacks are themselves attack surfaces, and quantum machine learning has been proposed for them. We benchmark fidelity-kernel SVMs and variational classifiers against six tuned classical models on public power-system attack data (Mississippi State/ORNL), across white-box, transfer, decision-based black-box, and poisoning attacks. Our headline finding is methodological: the benchmark's answers are set by the evaluator's choices before the models. Eight choices -- six in the evaluation protocol, two in the tuning the benchmark itself runs -- each reversed or moved a conclusion at fixed models. The largest is the split: the row-level protocol scores 0.905 macro-F1 where holding whole source files out leaves 0.594, and in the capped matched-dimensionality regime the quantum arm sits within noise of chance with the classical arm 0.024 above it. A fidelity kernel looks most robust until attacked directly (retention 0.886 to 0.064); a mis-fitted surrogate manufactures a 10x asymmetry; an unseeded black-box attack moves 75% between restarts. A positive control explains the accuracy null: the labels, not the pipeline. We give the control that catches each choice and release the seeded benchmark.

Md Rezwanul Islam · 0 citations
Open access Aug 2026

Self-revealing poisons: loss-guided forensic detection and quantum unlearning of corrupted training data

Quantum Computation has entered the Noisy Intermediate State Quantum era, in which quantum machine learning (QML) models built on parameterized quantum circuits are promptly utilized for real-world classification tasks, optimization and simulations because of quantum inherent properties like superposition and entanglement. Despite having such use cases, QML model’s security under adversarial conditions remains poorly understood. One such threat is data poisoning, in which an attacker corrupts the training set before the model ever sees it. Such an attack is escalated further in quantum settings by QUantum Indiscriminate Data Poisoning, which exploits the geometry of the quantum feature space. To address it, this paper proposes a self-revealing defense framework built on a two-stage pipeline. The first stage identifies potential corrupted data points using unsupervised hybrid kmeans_gmm threshold derived from a clean reference model, enabling reliable detection without requiring any prior knowledge of the underlying attack. The second stage uses the detected samples to guide a quantum unlearning process that removes the influence of corrupted data and restores model integrity. All experiments were carried out on simulations (no real quantum hardware is utilized). Experimentation on the MNIST-4 dataset using PQC-8 confirms the attack is self-revealing, as poisoning intensifies the detection PR-AUC climbs from 0.956 to over 0.999, while receiver operating characteristic AUC remains ⩾0.986 throughout, achieving a robust detection and clear separability between clean and poisoned samples. Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning (CF) recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives. Additional experiments on classical baseline further reveals the proposed framework being paradigm agnostic.

Oum Gadani, Kandarp Gajjar, Himani Trivedi et al. · 0 citations
Conference Jul 2026

Calibration of Variational Quantum Classifiers Under Depolarizing Noise: Expected Calibration Error, Ansatz Expressibility, and Post-Hoc Temperature Scaling

Variational Quantum Classifiers (VQCs) have emerged as prime candidates for machine learning on NISQ systems. It stands to reason that the same depolarizing noise that drives quantum states toward the maximally mixed state would also alleviate the overconfidence of VQCs. This paper tests that hypothesis through an empirical study on three datasets at six noise levels, validated across ten random seeds and supported by a formal analysis of how the depolarizing channel contracts the measured logits. The primary finding is that depolarizing noise does not reduce overconfidence in VQCs that remain in the learnable regime: expected calibration error (ECE) never decreases with noise on any dataset, and on the lowest-variance dataset it increases significantly (Wilcoxon signed-rank p < 0.005 over ten seeds). We derive why the optimizer compensates for the channel and confirm the mechanism through a confidence-trajectory experiment. A secondary finding is that a less expressive ansatz can appear well-calibrated only because it collapses to a degenerate solution, demonstrating that ECE must always be reported alongside accuracy. Any effect of noise on accuracy is small and seed-dependent, and it is decoupled from calibration. Post-hoc temperature scaling reduces VQC ECE by 64 to 77 percent across all datasets and is the recommended calibration method for NISQ-era classifiers.

Souvik Ghosh, Amrita Kundu, Mithaguru et al. · 0 citations

Related blog posts