arXiv:2507.08623quant-phcs.CR2025-07中稿 · publication at IEE…被引 3

构建量子机器学习统一攻击链模型,揭示多层威胁关联。

Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security

  • 借鉴网络安全杀伤链,构建量子机器学习攻击框架
  • 梳理物理层、数据层、算法层等多类攻击的关联路径
  • 适合安全研究者与量子系统设计者参考

量子机器学习(QML)系统继承了经典机器学习的漏洞,并引入了源于量子计算物理与算法层面的新攻击面。尽管已有大量关于各类攻击向量的研究——从对抗性投毒与逃避攻击,到电路级后门、侧信道泄漏和模型提取——但这些威胁常被孤立分析,且假设攻击者能力不切实际。这种碎片化阻碍了有效整体防御策略的发展。本文主张需对QML攻击面进行更结构化的建模,不仅涵盖单一技术,还需刻画其相互关系、前提条件及在全链路中的潜在影响。我们提出将广泛应用于经典信息技术与网络安全的杀伤链模型适配至量子机器学习场景。该模型可系统化分析攻击者目标、能力与多阶段攻击路径,覆盖侦察、初始访问、操纵、持久化及数据窃取等阶段。基于大量文献分析,我们构建了一个详细的QML攻击向量分类体系,映射至受MITRE ATLAS启发的量子感知杀伤链框架。重点揭示了物理层威胁(如侧信道泄漏与串扰故障)、数据与算法操纵(如投毒或电路后门)以及隐私攻击(如模型提取与训练数据推断)之间的依赖关系。本工作为更真实的威胁建模与主动纵深防御设计提供了基础。

原文摘要 · Abstract (English)

Quantum Machine Learning (QML) systems inherit vulnerabilities from classical machine learning while introducing new attack surfaces rooted in the physical and algorithmic layers of quantum computing. Despite a growing body of research on individual attack vectors - ranging from adversarial poisoning and evasion to circuit-level backdoors, side-channel leakage, and model extraction - these threats are often analyzed in isolation, with unrealistic assumptions about attacker capabilities and system environments. This fragmentation hampers the development of effective, holistic defense strategies. In this work, we argue that QML security requires more structured modeling of the attack surface, capturing not only individual techniques but also their relationships, prerequisites, and potential impact across the QML pipeline. We propose adapting kill chain models, widely used in classical IT and cybersecurity, to the quantum machine learning context. Such models allow for structured reasoning about attacker objectives, capabilities, and possible multi-stage attack paths - spanning reconnaissance, initial access, manipulation, persistence, and exfiltration. Based on extensive literature analysis, we present a detailed taxonomy of QML attack vectors mapped to corresponding stages in a quantum-aware kill chain framework that is inspired by the MITRE ATLAS for classical machine learning. We highlight interdependencies between physical-level threats (like side-channel leakage and crosstalk faults), data and algorithm manipulation (such as poisoning or circuit backdoors), and privacy attacks (including model extraction and training data inference). This work provides a foundation for more realistic threat modeling and proactive security-in-depth design in the emerging field of quantum machine learning.

量子安全攻击链机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。