Researchers Map Six-Stage STRIDE Threats Across Quantum-as-a-Service Pipeline

Key Takeaways

Six-Stage Model: Researchers decompose the hybrid quantum-classical workflow into six stages and apply a full STRIDE matrix covering quantum-specific, classical, and under-studied threats.

Cross-Stage Chains: Three multi-stage attack sequences are identified that combine local capabilities into higher-impact threats.

Underexplored Gaps: Repudiation and elevation-of-privilege remain sparsely addressed across the Quantum-as-a-Service stack.

Researchers from the University of Jyväskylä have presented an end-to-end STRIDE threat model for the Quantum-as-a-Service (QaaS) pipeline. The work, accepted as a poster at the IEEE International Conference on Quantum Computing and Engineering (QCE26) and released on arXiv, maps attack vectors across six pipeline stages used by platforms including IBM Quantum, Amazon Braket, and IonQ Quantum Cloud. Hybrid algorithms such as VQE, QAOA, and quantum machine learning traverse the full path from local development through execution and iterative feedback, creating a multi-tenant attack surface that prior studies treated in isolation.

Pipeline Stages and Threat Matrix

The model divides the workflow into six stages: developer environment (local simulation with SDKs such as Qiskit), authentication and submission (API tokens and IAM), cloud orchestration and compilation (queuing and transpilation), quantum hardware execution (multi-tenant QPU with calibration and pulse control), result return path (measurement and post-processing), and the hybrid iteration loop. A color-coded matrix places published quantum attacks (SWAP attacks, QubitHammer, inverse-transpilation, calibration tampering, pulse-level abuse), inherited classical vectors, and plausible but under-studied threats under the six STRIDE categories. Orange cells mark demonstrated quantum attacks; light-blue cells capture classical inheritance; light-green cells flag gaps, particularly in repudiation and elevation of privilege. The matrix shows that many stages lack verifiable execution logs or robust audit trails, leaving repudiation and privilege-escalation paths open.

Cross-Stage Attack Chains

Three composite chains illustrate how stage-local capabilities combine into higher-impact threats. Chain A links passive side-channel observation (SWAP or power analysis) at the hardware stage to targeted crosstalk attacks such as QubitHammer. Chain B uses publicly available calibration topology and coupling maps to enable precise pulse placement without direct observation of a victim circuit. Chain C exploits inverse-transpilation at the compilation stage to leak optimizer details, allowing an adversary to craft Trojan insertions that survive known optimization passes. These sequences demonstrate that defenses focused on single stages leave residual risk when an adversary can move information or control across the classical-quantum boundary.

Bottom Line

A unified six-stage STRIDE matrix organizes previously siloed QaaS threats and surfaces three cross-stage chains that elevate overall risk.

Find out more here.

Further articles, reports, and the latest quantum computing news may be found at The Qubit Report.

Related Articles

Get The Qubit Report delivered straight to your inbox.

Sign up to receive our newsletter and other reports.

We keep your data private and share your data only with third parties that make this service possible. Read our privacy policy for more info.