Researchers Map Six-Stage STRIDE Threats Across Quantum-as-a-Service Pipeline
Key Takeaways
Six-Stage Model: Researchers decompose the hybrid quantum-classical workflow into six stages and apply a full STRIDE matrix covering quantum-specific, classical, and under-studied threats.
Cross-Stage Chains: Three multi-stage attack sequences are identified that combine local capabilities into higher-impact threats.
Underexplored Gaps: Repudiation and elevation-of-privilege remain sparsely addressed across the Quantum-as-a-Service stack.
Researchers from the University of Jyväskylä have presented an end-to-end STRIDE threat model for the Quantum-as-a-Service (QaaS) pipeline. The work, accepted as a poster at the IEEE International Conference on Quantum Computing and Engineering (QCE26) and released on arXiv, maps attack vectors across six pipeline stages used by platforms including IBM Quantum, Amazon Braket, and IonQ Quantum Cloud. Hybrid algorithms such as VQE, QAOA, and quantum machine learning traverse the full path from local development through execution and iterative feedback, creating a multi-tenant attack surface that prior studies treated in isolation.
Pipeline Stages and Threat Matrix
The model divides the workflow into six stages: developer environment (local simulation with SDKs such as Qiskit), authentication and submission (API tokens and IAM), cloud orchestration and compilation (queuing and transpilation), quantum hardware execution (multi-tenant QPU with calibration and pulse control), result return path (measurement and post-processing), and the hybrid iteration loop. A color-coded matrix places published quantum attacks (SWAP attacks, QubitHammer, inverse-transpilation, calibration tampering, pulse-level abuse), inherited classical vectors, and plausible but under-studied threats under the six STRIDE categories. Orange cells mark demonstrated quantum attacks; light-blue cells capture classical inheritance; light-green cells flag gaps, particularly in repudiation and elevation of privilege. The matrix shows that many stages lack verifiable execution logs or robust audit trails, leaving repudiation and privilege-escalation paths open.
Cross-Stage Attack Chains
Three composite chains illustrate how stage-local capabilities combine into higher-impact threats. Chain A links passive side-channel observation (SWAP or power analysis) at the hardware stage to targeted crosstalk attacks such as QubitHammer. Chain B uses publicly available calibration topology and coupling maps to enable precise pulse placement without direct observation of a victim circuit. Chain C exploits inverse-transpilation at the compilation stage to leak optimizer details, allowing an adversary to craft Trojan insertions that survive known optimization passes. These sequences demonstrate that defenses focused on single stages leave residual risk when an adversary can move information or control across the classical-quantum boundary.
Bottom Line
A unified six-stage STRIDE matrix organizes previously siloed QaaS threats and surfaces three cross-stage chains that elevate overall risk.
Find out more here.
—
Further articles, reports, and the latest quantum computing news may be found at The Qubit Report.
Related Articles
Quantum Computing Weekly Round-Up: Week Ending August 15, 2026
Pasqal moved atom trapping onto a photonic chip, Q-CTRL ran a 100-qubit Fourier Transform on IBM hardware, and Quantinuum parked Helios inside Oracle’s cloud. Utah
BTQ Technologies Advances Commercialization Across QCIM, QPerfect, QSSN and Bitcoin Quantum in Q2 2026 Update
BTQ Technologies completed its acquisition of QPerfect and reported commercial progress across its trusted quantum platform in its Q2 2026 corporate update. QSSN surpassed 100,000
DARPA Awards Qunnect Contract to Advance Carina Polarization Compensation for Quantum Network Reliability
DARPA has awarded Qunnect a contract to advance the next-generation polarization compensation nodule in its Carina quantum entanglement distribution system. Carina already anchors quantum-network deployments