用时间特征+机器学习,揪出躲过传统检测的窃听攻击
Beyond the QBER Threshold: A Temporal QBER Based Machine Learning Framework for Multi Attack Detection in BB84 QKD

- 提取63个物理相关的时间特征,捕捉窃听引发的异常行为
- 在7种攻击下平均准确率达88.01%,误报率大幅降低
- 可解释性强,适合安全监控和攻防研究者使用
传统BB84量子密钥分发系统依赖固定的11%量子比特误码率(QBER)阈值来检测窃听,但隐蔽攻击可能低于该阈值却仍威胁通道安全。本文提出一种基于时间QBER的机器学习框架,用于检测与分类BB84 QKD中的多种窃听攻击。不依赖会话级平均QBER,而是提取63个物理启发的时间特征,涵盖突发行为、时间不稳定性、基依赖不对称性及QBER损失交互等。在七种窃听攻击和正常信道场景下,于噪声与损耗条件下评估随机森林、XGBoost及核函数为径向基函数的支持向量机(SVM-RBF)分类器。十次独立运行平均结果中,XGBoost表现最佳,准确率为88.01%(±0.47%),宏平均F1得分为0.8803;SVM-RBF表现相近,验证了特征鲁棒性。作为二元攻击-正常检测器与传统监测对比,固定11%阈值仅达25.82%准确率,假阴性率(FNR)高达0.8477,而新框架将FNR降至0.0198,显著提升对隐蔽攻击的检测能力。基于SHAP的可解释性分析表明,物理启发的时间特征与信道衍生特征具有高度判别力,能有效识别窃听策略。结果证明,基于时间QBER的机器学习框架在多攻击安全监控中具备高精度、可解释性与实用性。
原文摘要 · Abstract (English)
Conventional BB84 Quantum Key Distribution (QKD) systems rely on a fixed 11% Quantum Bit Error Rate (QBER) threshold to detect eavesdropping. However, stealthy attacks can remain below this threshold while still compromising channel security. This paper proposes a temporal QBER based machine learning framework for detecting and classifying eavesdropping attacks in BB84 QKD systems. Rather than relying on average session level QBER, the framework extracts 63 physics-informed temporal features capturing burst behavior, temporal instability, basis dependent asymmetry, and QBER loss interactions. Random Forest, XGBoost, and Support Vector Machine with a Radial Basis Function kernel (SVM-RBF) classifiers are evaluated on seven eavesdropping attacks and a normal channel scenario under noisy and lossy conditions. Averaged over ten independent runs, XGBoost achieves the best performance with 88.01% (0.47%) accuracy and a macro F1 score of 0.8803, while SVM-RBF performs comparably, confirming the robustness of the proposed features. Evaluated as a binary attack-versus-normal detector for comparison with conventional monitoring, a fixed 11% QBER threshold achieves only 25.82% accuracy with a False Negative Rate (FNR) of 0.8477, whereas the proposed framework reduces the FNR to 0.0198, substantially improving detection of stealthy attacks that evade threshold-based monitoring. SHapley Additive exPlanations based (SHAP) explainability shows that physics-informed temporal and channel derived features are highly discriminative for identifying eavesdropping strategies. These results demonstrate that temporal QBER driven machine learning provides an accurate, explainable, and practical framework for multi attack security monitoring in BB84 QKD systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。