ReportGem ReportGem

Academic paper

An End-to-End Threat Model for the Quantum-as-a-Service Pipeline

Authors: Badhon Rahman, Majid Haghparast, Tommi MikkonenPublished: 2026-08-06Paper ID: 2608.05836Category: cs.CRLicense: CC BY 4.0

Abstract

Cloud-based accessing of Quantum-as-a-Service (QaaS) platforms such as IBM Quantum, IonQ Cloud, and Amazon Braket is becoming popular day by day. Hybrid quantum-classical algorithms (VQE, QAOA, QML) transfer data via a long layered pipeline of orchestration, compilation, and execution. Recent works have demonstrated various critical attacks at individual stages: Calibration tampering, SWAP attacks, QubitHammer, and so on. However, these attacks remain separated because of their own terminology, and existing STRIDE-based threat modeling in the context of quantum lacks a structured view towards the QaaS stack itself. We address this concern by decomposing the workflow into six-stage model with STRIDE threat modeling. Our matrix demonstrated attack vectors in quantum-specific, inherited classical, and plausible tiers for each of the stages. We further investigate the underexplored sections (repudiation and elevation-of-privilege) and distinguish three different cross-stage attack chains with higher impacts.

This public page contains bibliographic metadata and the author abstract. Use the reader for licensed document access.

Open licensed paper reader