Search papers, labs, and topics across Lattice.
This paper presents a comprehensive threat model for Quantum-as-a-Service (QaaS) platforms by decomposing the quantum computing workflow into six stages and applying STRIDE threat modeling to identify vulnerabilities. By systematically categorizing attack vectors across quantum-specific, inherited classical, and plausible tiers, the study reveals critical gaps in existing security frameworks and highlights the interplay between various attack types. The findings underscore the importance of addressing underexplored areas such as repudiation and elevation-of-privilege, ultimately identifying three significant cross-stage attack chains that pose heightened risks to QaaS systems.
A structured threat model reveals critical vulnerabilities in Quantum-as-a-Service platforms, exposing attack chains that could compromise quantum computing workflows.
Cloud-based accessing of Quantum-as-a-Service (QaaS) platforms such as IBM Quantum, IonQ Cloud, and Amazon Braket is becoming popular day by day. Hybrid quantum-classical algorithms (VQE, QAOA, QML) transfer data via a long layered pipeline of orchestration, compilation, and execution. Recent works have demonstrated various critical attacks at individual stages: Calibration tampering, SWAP attacks, QubitHammer, and so on. However, these attacks remain separated because of their own terminology, and existing STRIDE-based threat modeling in the context of quantum lacks a structured view towards the QaaS stack itself. We address this concern by decomposing the workflow into six-stage model with STRIDE threat modeling. Our matrix demonstrated attack vectors in quantum-specific, inherited classical, and plausible tiers for each of the stages. We further investigate the underexplored sections (repudiation and elevation-of-privilege) and distinguish three different cross-stage attack chains with higher impacts.