Submitted:
15 July 2026
Posted:
17 July 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
- We investigate the evolution of attack surfaces, threats, and countermeasures in four different paradigms: traditional ML models, neural networks, GenAI models, and agentic AI systems.
- We investigate a substantial body of defense and attack research studies and provide comprehensive comparisons.
- We introduce and compare different simulation platforms and datasets used for experimental studies.
- We deeply analyze the current limitation of the area, and provide detailed research directions.
2. Traditional Models and Neural Networks
2.1. Attack Surfaces
2.1.1. Training Procedure
2.1.2. Measurement & Entanglement (M&E)
2.1.3. Circuit
2.1.4. Inference
2.2. Threat Model
2.3. Adversarial Attacks in QML
2.3.1. Evasion Attacks
Data Space Attacks
Parameter Space Attacks
2.3.2. Extraction
Query-based Attacks
Transpilation-based Attacks
Crosstalk-based Attacks
2.3.3. Backdoor Attacks
Hardware-level Backdoors
Data-level Backdoors
2.3.4. Poisoning Attacks
2.4. Defense Strategies for Robust QML
2.4.1. Quantum-Adaptive Adversarial Training
2.4.2. Data Encoding Regularization
2.4.3. Quantum Randomized Smoothing
2.4.4. Obfuscation
2.4.5. Behavior-Based Defenses
2.4.6. Watermarking
3. GenAI
3.1. Attack Surfaces
3.1.1. Prompt
3.1.2. RAG
3.1.3. Long-Term Memory
3.1.4. Quantum Sampling Layer
3.2. Attacks
3.2.1. RAG Poisoning
3.2.2. Superposition Exploitation
3.2.3. Quantum Sampling Manipulation Attack
3.3. Defenses
3.3.1. Prompt Sanitization
3.3.2. Document Sanitization
3.3.3. Quantum Encryption
4. Agentic AI
4.1. Attack Surfaces
4.1.1. Orchestration
Long-Term Goal
Communication
4.1.2. External Dependencies
4.1.3. External Tools
4.2. Attacks
4.2.1. Tools Exploitation
4.2.2. Corrupted Third Parties
4.2.3. Agent Hijacking
4.2.4. Cost Incurring
4.3. Defenses
4.3.1. Pre-Processing Strategies
4.3.2. Safe Simulation
4.3.3. External Surveillance
4.3.4. Action Verification
5. Datasets
5.1. Classical
5.2. Quantum-Generated
5.3. Synthetic
6. Simulation Platforms
7. Open Challenges and Future Research Directions
7.1. Scalability and Trainability on Realistic Hardware
7.2. Lack of Standardized Benchmarks and Evaluation Protocols
7.3. Emerging Attack Surfaces in Quantum-Enhanced Systems
7.4. Defenses Against Data Poisoning and Backdoor Attacks
7.5. Defense Trade-Offs and the Robustness-Utility Dilemma
8. Conclusions
References
- Fujiyoshi, H.; Hirakawa, T.; Yamashita, T. Deep learning-based image recognition for autonomous driving. IATSS Res. 2019, 43, 244–252. [Google Scholar] [CrossRef]
- Rani, P.; Kotwal, S.; Manhas, J.; Sharma, V.; Sharma, S. Machine learning and deep learning based computational approaches in automatic microorganisms image recognition: methodologies, challenges, and developments. Arch. Comput. Methods Eng. 2022, 29, 1801–1837. [Google Scholar] [PubMed]
- Macaulay, M.O.; Shafiee, M. Machine learning techniques for robotic and autonomous inspection of mechanical systems and civil infrastructure. Auton. Intell. Syst. 2022, 2, 8. [Google Scholar] [CrossRef]
- Wen, L.H.; Jo, K.H. Deep learning-based perception systems for autonomous driving: A comprehensive survey. Neurocomputing 2022, 489, 255–270. [Google Scholar] [CrossRef]
- Jelodar, H.; Meymani, M.; Hamedi, P.; Nwankwo, T.E.; Bai, S.; Razavi-Far, R.; Ghorbani, A.A. NLD-LLM: A systematic framework for evaluating small language transformer models on natural language description. Proc. 2025 Int. Conf. Mach. Learn. Appl. (ICMLA) 2025, 1494–1500. [Google Scholar] [CrossRef]
- Nagarhalli, T.P.; Vaze, V.; Rana, N. Impact of machine learning in natural language processing: A review. In Proceedings of the 2021 third international conference on intelligent communication technologies and virtual mobile networks (ICICV); IEEE, 2021; pp. 1529–1534. [Google Scholar]
- Kukliansky, A.; Orescanin, M.; Bollmann, C.; Huffmire, T. Network anomaly detection using quantum neural networks on noisy quantum computers. IEEE Trans. Quantum Eng. 2024, 5, 1–11. [Google Scholar] [CrossRef]
- Halbouni, A.; Gunawan, T.S.; Habaebi, M.H.; Halbouni, M.; Kartiwi, M.; Ahmad, R. Machine learning and deep learning approaches for cybersecurity: A review. IEEE Access 2022, 10, 19572–19585. [Google Scholar] [CrossRef]
- Sreenu, G.; Durai, S. Intelligent video surveillance: a review through deep learning techniques for crowd analysis. J. Big Data 2019, 6, 1–27. [Google Scholar] [CrossRef]
- Carlini, N.; Athalye, A.; Papernot, N.; Brendel, W.; Rauber, J.; Tsipras, D.; Goodfellow, I.; Madry, A.; Kurakin, A. On evaluating adversarial robustness. arXiv 2019, arXiv:1902.06705. [Google Scholar]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and harnessing adversarial examples. arXiv 2014, arXiv:1412.6572. [Google Scholar]
- Kurakin, A.; Goodfellow, I.J.; Bengio, S. Adversarial examples in the physical world. In Artificial intelligence safety and security; Chapman and Hall/CRC: Boca Raton, FL, 2018; pp. 99–112. [Google Scholar]
- Yuan, X.; He, P.; Zhu, Q.; Li, X. Adversarial examples: Attacks and defenses for deep learning. IEEE Trans. Neural Netw. Learn. Syst. 2019, 30, 2805–2824. [Google Scholar] [CrossRef] [PubMed]
- Meymani, M.; Razavi-Far, R. Divided We Fall: Defending against adversarial attacks via soft-gated fractional mixture-of-experts with randomized adversarial training. Inf. Sci. 2026, 745, 123427. [Google Scholar] [CrossRef]
- Majumder, R.; Chowdhury, M.; Khan, S.M.; Khan, Z.; Ahmad, F.; Ngeni, F.; Comert, G.; Mwakalonge, J.; Michalaka, D. Quantum Computing Supported Adversarial Attack-Resilient Autonomous Vehicle Perception Module for Traffic Sign Classification. arXiv 2025, arXiv:2504.12644. [Google Scholar]
- Meghanath, A.; Das, S.; Behera, B.K.; Khan, M.A.; Al-Kuwari, S.; Farouk, A. QDCNN: Quantum Deep Learning for Enhancing Safety and Reliability in Autonomous Transportation Systems. IEEE Transactions on Intelligent Transportation Systems, 2025. [Google Scholar]
- Sinha, A.; Macaluso, A.; Klusch, M. Nav-Q: quantum deep reinforcement learning for collision-free navigation of self-driving cars. Quantum Mach. Intell. 2025, 7, 1–20. [Google Scholar] [CrossRef]
- Chow, J.C. Quantum computing and machine learning in medical decision-making: A comprehensive review. Algorithms 2025, 18, 156. [Google Scholar] [CrossRef]
- Maheshwari, D.; Garcia-Zapirain, B.; Sierra-Sosa, D. Quantum machine learning applications in the biomedical domain: A systematic review. Ieee Access 2022, 10, 80463–80484. [Google Scholar] [CrossRef]
- Ullah, U.; Garcia-Zapirain, B. Quantum machine learning revolution in healthcare: a systematic review of emerging perspectives and applications. IEEE Access 2024, 12, 11423–11450. [Google Scholar] [CrossRef]
- Briggs, F.C. Quantum Computing Uses in Aerospace Systems. In Proceedings of the AIAA SCITECH 2025 Forum; p. 2678.
- Syed, M.; Garcia, P. A Hybrid Quantum-Classical Machine Learning Approach to Vision Sensor Data Analysis in Aerospace Applications. In Proceedings of the 2023 IEEE/AIAA 42nd Digital Avionics Systems Conference (DASC); IEEE; pp. 1–7.
- Grossi, M.; Ibrahim, N.; Radescu, V.; Loredo, R.; Voigt, K.; Von Altrock, C.; Rudnik, A. Mixed quantum–classical method for fraud detection with quantum feature selection. IEEE Trans. Quantum Eng. 2022, 3, 1–12. [Google Scholar] [CrossRef]
- Standen, M.; Kim, J.; Szabo, C. Adversarial machine learning attacks and defences in multi-agent reinforcement learning. ACM Comput. Surv. 2025, 57, 1–35. [Google Scholar] [CrossRef]
- Vadillo, J.; Santana, R.; Lozano, J.A. Adversarial attacks in explainable machine learning: A survey of threats against models and humans. Wiley Interdiscip. Rev. Data Min. Knowl. Discov. 2025, 15, e1567. [Google Scholar]
- Kurakin, A.; Goodfellow, I.J.; Bengio, S. Adversarial Machine Learning at Scale. In Proceedings of the International Conference on Learning Representations, 2017. [Google Scholar]
- Vashagh, A.; Razavi-Far, R.; Meymani, M.; Biggio, B. Recent Advances in Adversarial Attacks on Model Utility, Privacy, and Explainability: A Comprehensive Survey. 2026. [Google Scholar] [CrossRef]
- Jha, P.K. Adversarial Machine Learning: Attacks, Defenses, and Open Challenges. arXiv 2025, arXiv:2502.05637. [Google Scholar]
- Mądry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; Vladu, A. Towards deep learning models resistant to adversarial attacks. stat 2017, 1050. [Google Scholar]
- Raghunathan, A.; Steinhardt, J.; Liang, P. Certified Defenses against Adversarial Examples. In Proceedings of the International Conference on Learning Representations, 2018. [Google Scholar]
- Li, B.; Alpcan, T.; Thapa, C.; Parampalli, U. Computable Model-Independent Bounds for Adversarial Quantum Machine Learning. IEEE Transactions on Quantum Engineering, 2025. [Google Scholar]
- Song, D.; Eykholt, K.; Evtimov, I.; Fernandes, E.; Li, B.; Rahmati, A.; Tramer, F.; Prakash, A.; Kohno, T. Physical adversarial examples for object detectors. In Proceedings of the 12th USENIX workshop on offensive technologies (WOOT 18).
- Wang, N.; Xie, S.; Sato, T.; Luo, Y.; Xu, K.; Chen, Q.A. Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective. arXiv 2024, arXiv:2409.09860. [Google Scholar]
- Goodfellow, I.; McDaniel, P.; Papernot, N. Making machine learning robust against adversarial inputs. Commun. ACM 2018, 61, 56–66. [Google Scholar] [CrossRef]
- Qi, H.; Xiao, S.; Liu, Z.; Gong, C.; Gani, A. A high-efficiency variational quantum classifier for high-dimensional data. J. Supercomput. 2025, 81, 154. [Google Scholar]
- West, M.T.; Nakhl, A.C.; Heredge, J.; Creevey, F.M.; Hollenberg, L.C.; Sevior, M.; Usman, M. Drastic circuit depth reductions with preserved adversarial robustness by approximate encoding for quantum machine learning. Intell. Comput. 2024, 3, 0100. [Google Scholar] [CrossRef]
- Alvarez-Estevez, D. Benchmarking quantum machine learning kernel training for classification tasks. IEEE Transactions on Quantum Engineering, 2025. [Google Scholar]
- Georgiou, P.; Jose, S.T.; Simeone, O. Adversarial quantum machine learning: An information-theoretic generalization analysis. In Proceedings of the 2024 IEEE International Symposium on Information Theory (ISIT); IEEE; pp. 789–794.
- Akter, M.S.; Shahriar, H.; Iqbal, I.; Hossain, M.; Karim, M.; Clincy, V.; Voicu, R. Exploring the vulnerabilities of machine learning and quantum machine learning to adversarial attacks using a malware dataset: a comparative analysis. In Proceedings of the 2023 IEEE International Conference on Software Services Engineering (SSE). IEEE, 2023; pp. 222–231. [Google Scholar]
- Kundu, S.; Ghosh, S. Adversarial Data Poisoning Attack on Quantum Machine Learning in the NISQ Era. In Proceedings of the Proceedings of the Great Lakes Symposium on VLSI; 2025; pp. 976–981. [Google Scholar]
- Liu, N.; Wittek, P. Vulnerability of quantum classification to adversarial perturbations. Phys. Rev. A 2020, 101, 062331. [Google Scholar] [CrossRef]
- Kundu, S.; Ghosh, S. SoK Paper: Security Concerns in Quantum Machine Learning as a Service. In Proceedings of the Proceedings of the International Workshop on Hardware and Architectural Support for Security and Privacy 2024, 2024; pp. 28–36. [Google Scholar]
- Upadhyay, S.; Ghosh, S. Quantum quandaries: Unraveling encoding vulnerabilities in quantum neural networks. In Proceedings of the 2025 26th International Symposium on Quality Electronic Design (ISQED); IEEE, 2025; pp. 1–7. [Google Scholar]
- Wiebe, N.; Kumar, R.S.S. Hardening quantum machine learning against adversaries. New J. Phys. 2018, 20, 123019. [Google Scholar] [CrossRef]
- Razavi-Far, R.; Meymani, M.; Mahmoudinia, E.; Vazirzade, D.; Paknezhad, P.; Ghasemi, F.; Saravani, S.; Nikkhoo, S.; Haghjooei, K. Quantum adversarial machine learning: from classical adaptations to quantum-native methods. Artificial Intelligence Review, 2026. [Google Scholar]
- Gong, W.; Deng, D.L. Universal adversarial examples and perturbations for quantum classifiers. Natl. Sci. Rev. 2022, 9, nwab130. [Google Scholar] [PubMed]
- Liao, H.; Convy, I.; Huggins, W.J.; Whaley, K.B. Robust in practice: Adversarial attacks on quantum machine learning. Phys. Rev. A 2021, 103, 042427. [Google Scholar] [CrossRef]
- Schuld, M.; Sweke, R.; Meyer, J.J. Effect of data encoding on the expressive power of variational quantum-machine-learning models. Phys. Rev. A 2021, 103, 032430. [Google Scholar] [CrossRef]
- Du, Y.; Hsieh, M.H.; Liu, T.; Tao, D.; Liu, N. Quantum noise protects quantum classifiers against adversaries. Phys. Rev. Res. 2021, 3, 023153. [Google Scholar] [CrossRef]
- West, M.T.; Tsang, S.L.; Low, J.S.; Hill, C.D.; Leckie, C.; Hollenberg, L.C.; Erfani, S.M.; Usman, M. Towards quantum enhanced adversarial robustness in machine learning. Nat. Mach. Intell. 2023, 5, 581–589. [Google Scholar] [CrossRef]
- Ghosh, A.; Kundu, S.; Ghosh, S. Adversarial threats in quantum machine learning: A survey of attacks and defenses. In Quantum Robustness in Artificial Intelligence: Principles and Applications; Springer, 2026; pp. 31–53. [Google Scholar]
- Nowmi, S.R.; Lopez, J.; Imon, M.M.A.; Pouryousef, S.; Rahman, M.S. Critical Evaluation of Quantum Machine Learning for Adversarial Robustness. arXiv 2025, arXiv:2511.14989. [Google Scholar]
- Edwards, D.; Rawat, D.B. Quantum adversarial machine learning: Status, challenges and perspectives. In Proceedings of the 2020 Second IEEE international conference on trust, privacy and security in intelligent systems and applications (TPS-ISA); IEEE, 2020; pp. 128–133. [Google Scholar]
- Meymani, M.; Razavi-Far, R.; Vashagh, A.; Biggio, B. Defense Against Adversarial Attacks: Foundations, Strategies, and Future Directions. Preprints 2026. [Google Scholar] [CrossRef]
- Arias, D.; de Guzman, I.G.R.; Rodriguez, M.; Terres, E.B.; Sanz, B.; de la Puerta, J.G.; Pastor, I.; Zubillaga, A.; Bringas, P.G. Let’s do it right the first time: Survey on security concerns in the way to quantum software engineering. Neurocomputing 2023, 538, 126199. [Google Scholar] [CrossRef]
- Xu, C.; Erata, F.; Szefer, J. Classification of Quantum Computer Fault Injection Attacks. arXiv 2023, arXiv:cs. [Google Scholar]
- Baniecki, H.; Biecek, P. Adversarial attacks and defenses in explainable artificial intelligence: A survey. Inf. Fusion 2024, 102303. [Google Scholar] [CrossRef]
- Finlayson, S.G.; Bowers, J.D.; Ito, J.; Zittrain, J.L.; Beam, A.L.; Kohane, I.S. Adversarial attacks on medical machine learning. Science 2019, 363, 1287–1289. [Google Scholar] [CrossRef] [PubMed]
- Wu, B.; Zhu, Z.; Liu, L.; Liu, Q.; He, Z.; Lyu, S. Attacks in adversarial machine learning: A systematic survey from the lifecycle perspective. Int. J. Comput. Vis. 2026, 134, 197. [Google Scholar] [CrossRef]
- Guan, J.; Fang, W.; Ying, M. Robustness Verification of Quantum Machine Learning. CoRR, 2020. [Google Scholar]
- Rosenberg, I.; Shabtai, A.; Elovici, Y.; Rokach, L. Adversarial machine learning attacks and defense methods in the cyber security domain. ACM Comput. Surv. (CSUR) 2021, 54, 1–36. [Google Scholar] [CrossRef]
- Wang, Y.; Sun, T.; Li, S.; Yuan, X.; Ni, W.; Hossain, E.; Poor, H.V. Adversarial attacks and defenses in machine learning-empowered communication systems and networks: A contemporary survey. IEEE Commun. Surv. Tutor. 2023, 25, 2245–2298. [Google Scholar] [CrossRef]
- Lu, S.; Duan, L.M.; Deng, D.L. Quantum adversarial machine learning. Phys. Rev. Res. 2020, 2, 033212. [Google Scholar] [CrossRef]
- Montalbano, G.; Banchi, L. Quantum adversarial learning for kernel methods. Quantum Mach. Intell. 2025, 7, 15. [Google Scholar] [CrossRef]
- West, M.T.; Erfani, S.M.; Leckie, C.; Sevior, M.; Hollenberg, L.C.; Usman, M. Benchmarking adversarially robust quantum machine learning at scale. Phys. Rev. Res. 2023, 5, 023186. [Google Scholar] [CrossRef]
- Qiu, Y.Z. Universal adversarial perturbations for multiple classification tasks with quantum classifiers. Mach. Learn. Sci. Technol. 2023, 4, 045009. [Google Scholar] [CrossRef]
- El Maouaki, W.; Marchisio, A.; Said, T.; Shafique, M.; Bennai, M. Designing Robust Quantum Neural Networks via Optimized Circuit Metrics. Adv. Quantum Technol. 2025, 8, 2400601. [Google Scholar] [CrossRef]
- Akter, M.S.; Shahriar, H.; Cuzzocrea, A.; Wu, F. Quantum Adversarial Attacks: Developing Quantum FGSM Algorithm. In Proceedings of the 2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC); IEEE; pp. 1073–1079.
- Kundu, S.; Kundu, D.; Ghosh, S. Evaluating efficacy of model stealing attacks and defenses on quantum neural networks. In Proceedings of the Proceedings of the Great Lakes Symposium on VLSI, 2024; pp. 556–559. [Google Scholar]
- Fu, Z.; Yang, M.; Chu, C.; Xu, Y.; Huang, G.; Chen, F. Quantumleak: Stealing quantum neural networks from cloud-based nisq machines. In Proceedings of the 2024 International Joint Conference on Neural Networks (IJCNN); IEEE; pp. 1–8.
- Ghosh, A.; Ghosh, S. AI-driven Reverse Engineering of QML Models. In Proceedings of the 2025 26th International Symposium on Quality Electronic Design (ISQED); IEEE; pp. 1–7.
- Ghosh, A.; Ghosh, S. The quantum imitation game: Reverse engineering of quantum machine learning models. In Proceedings of the Proceedings of the 2024 Workshop on Attacks and Solutions in Hardware Security; pp. 48–57.
- Kundu, S.; Ghosh, S. Inverse-Transpilation: Reverse-Engineering Quantum Compiler Optimization Passes from Circuit Snapshots. Proc. Proc. Gt. Lakes Symp. VLSI 2025, 2025, 273–277. [Google Scholar] [CrossRef]
- Choudhury, N.; Mude, C.N.; Das, S.; Tikkireddi, P.C.; Tannu, S.; Basu, K. Crosstalk-induced side channel threats in multi-tenant nisq computers. arXiv 2024, arXiv:2412.10507. [Google Scholar]
- Saki, A.A.; Ghosh, S. Qubit sensing: A new attack model for multi-programming quantum computing. arXiv 2021, arXiv:2104.05899. [Google Scholar]
- Chu, C.; Jiang, L.; Swany, M.; Chen, F. Qtrojan: A circuit backdoor against quantum neural networks. In Proceedings of the ICASSP 2023-2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP); IEEE; pp. 1–5.
- Ergu, Y.A.; Nguyen, V.L.; Lin, P.C.; Hwang, R.H. Q-poison: Quantum adversarial attacks against qml-driven interference classification in o-ran. In Proceedings of the 2025 IEEE International Conference on Machine Learning for Communication and Networking (ICMLCN); IEEE; Volume 2025, pp. 1–6.
- Zhao, J.; Yan, L.; Tan, D.; Chang, Y.; Zhang, S. A black-box backdoor attack against quantum neural networks. Quantum Sci. Technol. 2025, 10, 035038. [Google Scholar] [CrossRef]
- Chen, Y.Q.; Zhang, S.X. Superior resilience to poisoning and amenability to unlearning in quantum machine learning. Nat. Commun. 2026, 17, 3716. [Google Scholar] [CrossRef] [PubMed]
- Wendlinger, M.; Tscharke, K.; Debus, P. A comparative analysis of adversarial robustness for quantum and classical machine learning models. In Proceedings of the 2024 IEEE International Conference on Quantum Computing and Engineering (QCE); IEEE; Vol. 1, pp. 1447–1457.
- Wu, Y.; Adermann, E.; Thapa, C.; Camtepe, S.; Suzuki, H.; Usman, M. Radio signal classification by adversarially robust quantum machine learning. arXiv 2023, arXiv:2312.07821. [Google Scholar]
- Xu, C.; Szefer, J. Security Attacks Abusing Pulse-level Quantum Circuits. In Proceedings of the 2025 IEEE Symposium on Security and Privacy (SP); IEEE, 2025; pp. 222–239. [Google Scholar]
- Chu, C.; Chen, F.; Richerme, P.; Jiang, L. Qdoor: Exploiting approximate synthesis for backdoor attacks in quantum neural networks. Proc. 2023 IEEE Int. Conf. Quantum Comput. Eng. (QCE) IEEE 2023, Vol. 1, 1098–1106. [Google Scholar] [CrossRef]
- Huang, C.Y.; Zhang, S.B. A backdoor attack against quantum neural networks with limited information. Chin. Phys. B 2023, 32, 100306. [Google Scholar] [CrossRef]
- Ren, W.; Li, W.; Xu, S.; Wang, K.; Jiang, W.; Jin, F.; Zhu, X.; Chen, J.; Song, Z.; Zhang, P. Experimental quantum adversarial learning with programmable superconducting qubits. Nat. Comput. Sci. 2022, 2, 711–717. [Google Scholar] [CrossRef] [PubMed]
- Berberich, J.; Fink, D.; Pranjić, D.; Tutschku, C.; Holm, C. Training robust and generalizable quantum models. Phys. Rev. Res. 2024, 6, 043326. [Google Scholar] [CrossRef]
- Gong, W.; Yuan, D.; Li, W.; Deng, D.L. Enhancing quantum adversarial robustness by randomized encodings. Phys. Rev. Res. 2024, 6, 023020. [Google Scholar] [CrossRef]
- Franco, N.; Sakhnenko, A.; Stolpmann, L.; Thuerck, D.; Petsch, F.; Rüll, A.; Lorenz, J.M. Predominant aspects on security for quantum machine learning: Literature review. Proc. 2024 IEEE Int. Conf. Quantum Comput. Eng. (QCE) IEEE 2024, Vol. 1, 1467–1477. [Google Scholar] [CrossRef]
- Wollschläger, T.; Saxena, A.; Franco, N.; Lorenz, J.M.; Günnemann, S. Discrete randomized smoothing meets quantum computing. In Proceedings of the 2024 IEEE International Conference on Quantum Computing and Engineering (QCE); IEEE; Vol. 1, pp. 1535–1546.
- Franco, N.; Kempkes, M.; Spiegelberg, J.; Lorenz, J.M. Quadratic advantage with quantum randomized smoothing applied to time-series analysis. In Proceedings of the 2024 IEEE International Conference on Quantum Computing and Engineering (QCE); IEEE; Vol. 1, pp. 285–295.
- Liu, Y.; John, J.; Wang, Q. E-loq: Enhanced locking for quantum circuit ip protection. In Proceedings of the 2025 IEEE International Symposium on Hardware Oriented Security and Trust (HOST); IEEE, 2025; pp. 67–77. [Google Scholar]
- Wang, S.; Xiao, Z.; Shi, J.; Shi, H.; Zhang, S.; Li, X. QSentry: Backdoor Detection for Quantum Neural Networks via Measurement Clustering. arXiv 2025, arXiv:2511.15376. [Google Scholar]
- Zhou, L.; Wu, H. Watermarking Quantum Neural Networks Based on Sample Grouped and Paired Training. arXiv 2025, arXiv:2506.12675. [Google Scholar]
- Uchida, Y.; Nagai, Y.; Sakazawa, S.; Satoh, S. Embedding watermarks into deep neural networks. In Proceedings of the Proceedings of the 2017 ACM on international conference on multimedia retrieval, 2017; pp. 269–277. [Google Scholar]
- Adi, Y.; Baum, C.; Cisse, M.; Pinkas, B.; Keshet, J. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In Proceedings of the 27th USENIX security symposium (USENIX Security 18), 2018; pp. 1615–1631. [Google Scholar]
- Wang, Y.; Wu, H. Protecting the intellectual property of speaker recognition model by black-box watermarking in the frequency domain. Symmetry 2022, 14, 619. [Google Scholar] [CrossRef]
- Roy, R.; Ghosh, S. Watermarking of Quantum Circuits. In Proceedings of the 2025 26th International Symposium on Quality Electronic Design (ISQED); IEEE, 2025; pp. 1–7. [Google Scholar]
- Maouaki, W.E.; Innan, N.; Marchisio, A.; Said, T.; Bennai, M.; Shafique, M. Qfal: Quantum federated adversarial learning. arXiv 2025, arXiv:2502.21171. [Google Scholar]
- Marchiori, F.; Conti, M. ATTAQ: Adversarial Robustness of Quantum Machine Learning. In Proceedings of the 2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W); IEEE, 2025; pp. 200–207. [Google Scholar]
- El Maouaki, W.; Innan, N.; Marchisio, A.; Said, T.; Shafique, M.; Bennai, M. RobQFL: Robust Quantum Federated Learning in Adversarial Environment. In Proceedings of the 2025 IEEE International Conference on Quantum Artificial Intelligence (QAI); IEEE, 2025; pp. 128–134. [Google Scholar]
- Li, Y.; Deng, X.; Xu, R.; Xu, W.; Zhou, R.G. Dual-regularized nonlinear quantum encoding for adversarial robustness in quantum machine learning. New J. Phys. 2026. [Google Scholar] [CrossRef]
- Huang, C.; Zhang, S. Enhancing adversarial robustness of quantum neural networks by adding noise layers. New J. Phys. 2023, 25, 083019. [Google Scholar] [CrossRef]
- Wang, Z.; Li, J.; Hu, Z.; Gage, B.; Iwasawa, E.; Jiang, W. Qumos: A framework for preserving security of quantum machine learning model. Proc. 2023 IEEE Int. Conf. Quantum Comput. Eng. (QCE) IEEE 2023, Vol. 1, 1089–1097. [Google Scholar] [CrossRef]
- Chen, L.; Yan, L.; Zhang, S. Robust quantum federated learning with noise. Phys. Scr. 2024, 99, 076003. [Google Scholar] [CrossRef]
- Rofougaran, R.; Yoo, S.; Tseng, H.H.; Chen, S.Y.C. Federated quantum machine learning with differential privacy. In Proceedings of the ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP); IEEE, 2024; pp. 9811–9815. [Google Scholar]
- Pokharel, A.; Rahman, R.; Shaon, S.; Morris, T.; Nguyen, D.C. Differentially private federated quantum learning via quantum noise. Proc. 2025 IEEE Int. Conf. Quantum Comput. Eng. (QCE) IEEE 2025, Vol. 1, 1559–1565. [Google Scholar] [CrossRef]
- Bhatia, A.S.; Kais, S.; Alam, M.A. On the robustness of variational quantum classifier against “label flipping attacks” in federated learning for semiconductor manufacturing. Proc. 2024 IEEE Int. Conf. Quantum Comput. Eng. (QCE) IEEE 2024, Vol. 1, 161–168. [Google Scholar] [CrossRef]
- Kumar, P. Adversarial attacks and defenses for large language models (LLMs): methods, frameworks & challenges. Int. J. Multimed. Inf. Retr. 2024, 13, 26. [Google Scholar] [CrossRef]
- Shayegani, E.; Mamun, M.A.A.; Fu, Y.; Zaree, P.; Dong, Y.; Abu-Ghazaleh, N. Survey of vulnerabilities in large language models revealed by adversarial attacks. arXiv 2023, arXiv:2310.10844. [Google Scholar]
- Dehghantanha, A.; Homayoun, S. SoK: The Attack Surface of Agentic AI–Tools, and Autonomy. arXiv 2026, arXiv:2603.22928. [Google Scholar]
- Jelodar, H.; Meymani, M.; Razavi-Far, R.; Ghorbani, A.A. XGen-Q: An Explainable Domain-Adaptive LLM Framework with Retrieval-Augmented Generation for Software Security. arXiv 2025, arXiv:2510.19006. [Google Scholar]
- Boisvert, L.; Puri, A.; Evuru, C.K.R.; Sepahvand, N.; Chapados, N.; Cappart, Q.; Lacoste, A.; Dvijotham, K.D.; Drouin, A. Malice in agentland: Down the rabbit hole of backdoors in the ai supply chain. arXiv 2025, arXiv:2510.05159. [Google Scholar]
- Kim, J.; Guo, W.; Song, D.; Berkeley, U.; Santa Barbara, U. SoK: Attack and Defense Landscape of Agentic AI Systems. In Proceedings of the 35nd USENIX Security Symposium (USENIX Security 26), 2026. [Google Scholar]
- Dasgupta, K.; Paine, B. Loading probability distributions in a quantum circuit. arXiv 2022, arXiv:2208.13372. [Google Scholar]
- Bouland, A.; Fefferman, B.; Nirkhe, C.; Vazirani, U. On the complexity and verification of quantum random circuit sampling. Nat. Phys. 2019, 15, 159–163. [Google Scholar]
- Higham, C.F.; Bedford, A. Quantum deep learning by sampling neural nets with a quantum annealer. Sci. Rep. 2023, 13, 3939. [Google Scholar] [CrossRef] [PubMed]
- Zhang, B.; Li, L.; Xu, Y.; Tan, Z.; Shi, J.; Huang, P.; Wang, T.; Zeng, G. Practical attack on a quantum random-number generator via injection of source-signal fluctuations. Phys. Rev. Appl. 2025, 24, 014008. [Google Scholar] [CrossRef]
- Abou Ali, M.; Dornaika, F.; Charafeddine, J. Agentic AI: a comprehensive survey of architectures, applications, and future directions. Artif. Intell. Rev. 2025, 59, 11. [Google Scholar] [CrossRef]
- Acharya, D.B.; Kuppan, K.; Divya, B. Agentic AI: Autonomous intelligence for complex goals—A comprehensive survey. IEEe Access 2025, 13, 18912–18936. [Google Scholar] [CrossRef]
- Chhabra, A.; Datta, S.; Nahin, S.K.; Mohapatra, P. Agentic AI security: Threats, defenses, evaluation, and open challenges. IEEE Access, 2026. [Google Scholar]
- Nöther, J.; Singla, A.; Radanovic, G. Benchmarking the robustness of agentic systems to adversarially-induced harms. arXiv 2025, arXiv:2508.16481. [Google Scholar]
- Zhou, Z.; Liu, G.; Guo, W.; Zhou, M. Adversarial attacks on multiagent deep reinforcement learning models in continuous action space. IEEE Trans. Syst. Man. Cybern. Syst. 2024, 54, 7633–7646. [Google Scholar] [CrossRef]
- Rodríguez-Díaz, F.; Gutiérrez-Avilés, D.; Troncoso, A.; Martínez-Álvarez, F. A Survey of Quantum Machine Learning: Foundations, Algorithms, Frameworks, Data and Applications. ACM Comput. Surv. 2025, 58, 1–35. [Google Scholar] [CrossRef]
- Zaman, K.; Marchisio, A.; Hanif, M.A.; Shafique, M. A survey on quantum machine learning: Current trends, challenges, opportunities, and the road ahead. arXiv 2023, arXiv:2310.10315. [Google Scholar]
- Chen, L.; Li, T.; Chen, Y.; Chen, X.; Wozniak, M.; Xiong, N.; Liang, W. Design and analysis of quantum machine learning: a survey. Connect. Sci. 2024, 36, 2312121. [Google Scholar] [CrossRef]
- Khanal, B.; Rivas, P.; Sanjel, A.; Sooksatra, K.; Quevedo, E.; Rodriguez, A. Generalization error bound for quantum machine learning in NISQ era—A survey. Quantum Mach. Intell. 2024, 6, 90. [Google Scholar] [CrossRef]
- Perrier, E.; Youssry, A.; Ferrie, C. QDataSet, quantum datasets for machine learning. Sci. Data 2022, 9, 582. [Google Scholar] [CrossRef] [PubMed]
- Cicero, A.; Maleki, M.A.; Azhar, M.W.; Kockum, A.F.; Trancoso, P. Simulation of quantum computers: Review and acceleration opportunities. ACM Trans. Quantum Comput. 2025, 7, 1–35. [Google Scholar] [CrossRef]
- Serrano, M.A.; Cruz-Lemus, J.A.; Perez-Castillo, R.; Piattini, M. Quantum software components and platforms: Overview and quality assessment. ACM Comput. Surv. 2022, 55, 1–31. [Google Scholar] [CrossRef]
- Khatun, A.; Usman, M. Classical Autoencoder Distillation of Quantum Adversarial Manipulations. arXiv 2025, arXiv:2504.09216. [Google Scholar]
- Zoufal, C.; Lucchi, A.; Woerner, S. Quantum generative adversarial networks for learning and loading random distributions. npj Quantum Inf. 2019, 5, 103. [Google Scholar] [CrossRef]





| Ref. | Attack Type |
Attack Subtype |
Attacker’s Knowledge |
Target Model(s) |
Simulation Platform(s) |
Attack Surface | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| White | Gray | Black | Training | M&E | Circuit | Inference | |||||
| [64] | Evasion | Data Space | ✓ | ✗ | ✗ | QSVM | Qiskit | ✗ | ✗ | ✗ | ✓ |
| [63] | Evasion | Data Space | ✓ | ✗ | ✓ | VQCC | Julia-based | ✗ | ✗ | ✗ | ✓ |
| [68] | Evasion | Parameter Space | ✓ | ✗ | ✗ | QNN | Pennylane | ✓ | ✗ | ✓ | ✗ |
| [65] | Evasion | Data Space | ✓ | ✗ | ✓ | VQCC | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [46] | Evasion | Data Space | ✓ | ✓ | ✗ | QCNN | Real Hardware | ✗ | ✗ | ✗ | ✓ |
| [67] | Evasion | Data Space | ✓ | ✗ | ✗ | QuNN | N/A | ✗ | ✗ | ✗ | ✓ |
| [66] | Evasion | Data Space | ✗ | ✗ | ✓ | VQCC, QCNN | Julia-based | ✗ | ✗ | ✗ | ✓ |
| [80] | Evasion | Data Space | ✗ | ✓ | ✗ | VQCC | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [81] | Evasion | Data Space | ✓ | ✗ | ✓ | VQCC | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [72] | Extraction | Transpilation-based | ✗ | ✓ | ✗ | QNN | Qiskit, Pennylane | ✓ | ✗ | ✓ | ✓ |
| [71] | Extraction | Transpilation-based | ✗ | ✓ | ✗ | QNN | Qiskit | ✗ | ✗ | ✓ | ✓ |
| [69] | Extraction | Query-based | ✗ | ✗ | ✓ | QNN | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [70] | Extraction | Query-based | ✗ | ✗ | ✓ | QNN | Qiskit | ✗ | ✗ | ✓ | ✓ |
| [43] | Extraction | Transpilation-based | ✗ | ✓ | ✗ | QNN | Qiskit | ✗ | ✗ | ✓ | ✓ |
| [73] | Extraction | Transpilation-based | ✗ | ✓ | ✗ | Quantum Circuit | Qiskit | ✗ | ✗ | ✓ | ✓ |
| [74] | Extraction | Crosstalk-based | ✗ | ✓ | ✗ | Quantum Circuit | Real Hardware | ✗ | ✗ | ✓ | ✗ |
| [76] | Backdoor | Hardware-level | ✗ | ✓ | ✗ | QNN, QLSTM | Qiskit | ✗ | ✗ | ✓ | ✓ |
| [77] | Backdoor | Hardware-level | ✓ | ✗ | ✗ | HQCNN | Pennylane | ✗ | ✓ | ✓ | ✓ |
| [78] | Backdoor | Data-level | ✗ | ✗ | ✓ | QNN | Pennylane | ✓ | ✗ | ✗ | ✓ |
| [82] | Backdoor | Hardware-level | ✗ | ✓ | ✗ | QuNN | Qiskit | ✗ | ✓ | ✓ | ✗ |
| [83] | Backdoor | Hardware-level | ✓ | ✗ | ✗ | QNN | Qiskit, BQSKit | ✗ | ✗ | ✓ | ✓ |
| [84] | Backdoor | Data-level | ✗ | ✗ | ✓ | QNN, QCNN | Pennylane | ✓ | ✗ | ✗ | ✓ |
| [40] | Poisoning | - | ✗ | ✓ | ✗ | QNN | Pennylane | ✓ | ✗ | ✗ | ✗ |
| [79] | Poisoning | - | ✓ | ✗ | ✗ | QNN | TensorCircuit | ✓ | ✗ | ✗ | ✗ |
| Ref | Defense Type | Attack Type | Attacker’s Knowledge |
Target Model(s) |
Simulation Platform(s) |
Attack Surface | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| White | Gray | Black | Training | M&E | Circuit | Inference | |||||
| [63] | AT | Evasion | ✓ | ✗ | ✓ | VQCC | Julia-based | ✗ | ✗ | ✗ | ✓ |
| [85] | AT | Evasion | ✓ | ✗ | ✗ | VQCC, QNN | Real hardware | ✗ | ✗ | ✗ | ✓ |
| [64] | AT | Evasion | ✓ | ✗ | ✗ | QSVM | Qiskit | ✗ | ✗ | ✗ | ✓ |
| [98] | AT | Evasion | ✓ | ✗ | ✗ | QNN | Real hardware | ✗ | ✗ | ✗ | ✓ |
| [65] | AT | Evasion | ✓ | ✗ | ✓ | VQCC | Pennylane | ✓ | ✗ | ✓ | ✗ |
| [99] | AT | Evasion | ✓ | ✗ | ✓ | QFC | TorchQuantum | ✗ | ✗ | ✗ | ✓ |
| [100] | AT | Evasion | ✓ | ✗ | ✗ | QNN | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [47] | DER | Evasion | ✓ | ✗ | ✗ | General | N/A | ✗ | ✗ | ✗ | ✓ |
| [86] | DER | Evasion | ✓ | ✗ | ✗ | VQCC | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [87] | DER | Evasion | ✓ | ✗ | ✗ | VQCC | N/A | ✗ | ✗ | ✗ | ✓ |
| [101] | DER | Evasion | ✓ | ✗ | ✗ | QNN | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [90] | QRS | Evasion | ✗ | ✓ | ✗ | QNN | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [43] | Obfuscation | Extraction | ✗ | ✓ | ✗ | QNN | Qiskit | ✗ | ✓ | ✓ | ✓ |
| [102] | Obfuscation | Evasion | ✓ | ✗ | ✓ | QNN, QCNN | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [91] | Obfuscation | Extraction | ✗ | ✓ | ✗ | VQCC | Qiskit | ✗ | ✗ | ✓ | ✗ |
| [103] | Obfuscation | Extraction | ✗ | ✓ | ✗ | VQCC | Qiskit, TorchQuantum | ✗ | ✗ | ✓ | ✓ |
| [104] | Obfuscation | Evasion | ✓ | ✗ | ✗ | VQCC | Pennylane | ✗ | ✗ | ✗ | ✓ |
| [105] | Obfuscation | Extraction | ✗ | ✓ | ✗ | VQCC | Real hardware | ✗ | ✗ | ✗ | ✓ |
| [106] | Obfuscation | Evasion | ✗ | ✗ | ✓ | QNN | TorchQuantum | ✗ | ✗ | ✗ | ✓ |
| [82] | Behavior-based | Backdoor | ✗ | ✓ | ✗ | QCNN | Qiskit | ✗ | ✓ | ✓ | ✗ |
| [92] | Behavior-based | Backdoor | ✓ | ✗ | ✗ | QCL | Pennylane | ✓ | ✗ | ✓ | ✗ |
| [107] | Behavior-based | Poisoning | ✗ | ✓ | ✗ | VQCC | N/A | ✓ | ✗ | ✗ | ✗ |
| [93] | Watermarking | Extraction | ✗ | ✗ | ✓ | HQCNN | Qiskit | ✗ | ✗ | ✗ | ✓ |
| [97] | Watermarking | Extraction | ✗ | ✓ | ✗ | Quantum Circuit | Qiskit | ✗ | ✗ | ✓ | ✓ |
| Platforms | Year | Developer | Language | Hybrid Support |
|---|---|---|---|---|
| Qiskit | 2017 | IBM Research | Python | Yes |
| Pennylane | 2019 | Xanadu | Python | Yes |
| Julia-based | 2018 | Julia community | Julia | Varies by package |
| Q# | 2017 | Microsoft | C#, Python | Yes |
| TensorCircuit | 2023 | Tencent Quantum Lab | Python | Yes |
| BQSKit | 2021 | Berkeley Lab | Python | Limited |
| Cirq | 2018 | Google Quantum AI | Python | Limited |
| ProjectQ | 2016 | ETH Zurich | Python | Limited |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).