攻击者仅用5%经典数据就能完全骗过量子认证,暴露现有安全评估漏洞。
Adversarial Limits of Quantum Certification: When Eve Defeats Detection
- 用生成对抗网络模拟量子纠缠,让经典相关性骗过检测系统。
- 混合5%经典数据后,所有检测方法准确率降至随机水平(AUC=0.50)。
- 实验证明攻击者可比真实量子设备表现更好,适合关注量子安全的团队。
量子密钥分发(QKD)的安全性依赖于对观测关联是否来自真实量子纠缠的认证,而非窃听者操纵。理论证明假设理想条件,而实际认证需应对自适应攻击者优化攻击策略的情况。本文使用Eve GAN——一个训练生成与量子不可区分的经典关联的生成对抗网络——研究量子认证的极限。核心发现:当窃听者以混合参数将经典关联与量子数据混合时,所有测试检测方法的ROC AUC均为0.50,等同于随机猜测。这意味着窃听者只需掺入5%经典成分即可完全逃过检测。关键的是,我们发现此前普遍采用的分布校准方式在跨分布评估下会使检测性能虚高44个百分点,揭示出系统性缺陷,可能造成安全声明被严重夸大。对普洛斯库-罗尔里奇(PR Box)情形的分析显示,在CHSH值为2.05处存在尖锐相变:低于该值时,任何统计方法均无法区分经典与量子关联;高于该值时,检测概率单调上升。在IBM Quantum硬件上验证表明,Eve-GAN实现的CHSH值达2.736,显著超过真实量子硬件表现(CHSH=2.691),说明经典攻击者可在标准认证指标上超越噪声量子系统。结果表明,只要保持95%量子保真度,攻击者即可规避所有测试检测方法。我们提出使用跨分布校准的修正方法,并建议对量子安全声明强制进行对抗测试。
原文摘要 · Abstract (English)
Security of quantum key distribution (QKD) relies on certifying that observed correlations arise from genuine quantum entanglement rather than eavesdropper manipulation. Theoretical security proofs assume idealized conditions, practical certification must contend with adaptive adversaries who optimize their attack strategies against detection systems. Established fundamental adversarial limits for quantum certification using Eve GAN, a generative adversarial network trained to produce classical correlations indistinguishable from quantum. Our central finding: when Eve interpolates her classical correlations with quantum data at mixing parameter, all tested detection methods achieve ROC AUC = 0.50, equivalent to random guessing. This means an eavesdropper needs only 5% classical admixture to completely evade detection. Critically, we discover that same distribution calibration a common practice in prior certification studies inflates detection performance by 44 percentage points compared to proper cross distribution evaluation, revealing a systematic flaw that may have led to overestimated security claims. Analysis of Popescu Rohrlich (PR Box) regime identifies a sharp phase transition at CHSH S = 2.05: below this value, no statistical method distinguishes classical from quantum correlations; above it, detection probability increases monotonically. Hardware validation on IBM Quantum demonstrates that Eve-GAN achieves CHSH = 2.736, remarkably exceeding real quantum hardware performance (CHSH = 2.691), illustrating that classical adversaries can outperform noisy quantum systems on standard certification metrics. These results have immediate implications for QKD security: adversaries maintaining 95% quantum fidelity evade all tested detection methods. We provide corrected methodology using cross-distribution calibration and recommend mandatory adversarial testing for quantum security claims.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。