🤖 AI Summary
This work addresses the lack of systematic security analysis across the full quantum computing pipeline in existing Quantum-as-a-Service (QaaS) platforms, where prior attack studies remain fragmented and unable to assess cross-stage risks. The paper proposes the first comprehensive six-stage STRIDE threat model tailored to the QaaS stack, decomposing the workflow into distinct phases—such as orchestration, compilation, and execution—and systematically identifying attack vectors under three categories: quantum-specific, classically inherited, and emergent threats. The model not only uncovers long-overlooked risks related to repudiation and privilege escalation but also establishes the first end-to-end threat matrix for QaaS, revealing three high-severity cross-stage attack chains. This framework provides a systematic foundation for secure design and risk mitigation in quantum cloud platforms.
📝 Abstract
Cloud-based accessing of Quantum-as-a-Service (QaaS) platforms such as IBM Quantum, IonQ Cloud, and Amazon Braket is becoming popular day by day. Hybrid quantum-classical algorithms (VQE, QAOA, QML) transfer data via a long layered pipeline of orchestration, compilation, and execution. Recent works have demonstrated various critical attacks at individual stages: Calibration tampering, SWAP attacks, QubitHammer, and so on. However, these attacks remain separated because of their own terminology, and existing STRIDE-based threat modeling in the context of quantum lacks a structured view towards the QaaS stack itself. We address this concern by decomposing the workflow into six-stage model with STRIDE threat modeling. Our matrix demonstrated attack vectors in quantum-specific, inherited classical, and plausible tiers for each of the stages. We further investigate the underexplored sections (repudiation and elevation-of-privilege) and distinguish three different cross-stage attack chains with higher impacts.