---
title: Covert Quantum Computing Overview
url: https://www.emergentmind.com/topics/covert-quantum-computing
type: topic
---

# Covert Quantum Computing Overview

Searching arXiv for recent papers on covert quantum computing and closely related covert quantum communication/security work.
Covert quantum computing denotes quantum information processing whose occurrence, not merely its content, is concealed from an adversary. In the literature represented here, the term spans at least two distinct but increasingly convergent senses. One concerns covert execution over quantum networks, where entanglement generation, teleportation, measurement-based computation, and blind delegation are hidden within vacuum fluctuations, ambient noise, or covert classical channels [1704.07281; 1607.05916; 2401.06764; 2501.13103]. The other concerns covert manipulation or detection at the computation substrate itself, including malicious compiler-layer circuit tampering and multi-tenant hardware side-channel concealment or detection [2502.08880; 2605.14325]. Taken together, these works suggest that covert quantum computing is best understood as a family of security and systems problems in which the operational signature of computation is suppressed, displaced, or exploited across the communication, compilation, and hardware layers.

## 1. Definitions and conceptual scope

The strongest notion of covertness in the communication-oriented literature is that an external observer should be unable to distinguish \(H_0\), “no communication/computation,” from \(H_1\), “communication/computation is being executed,” beyond a small advantage determined by the trace distance between the corresponding states [1704.07281]. This is explicitly stronger than confidentiality and stronger than blind quantum computation: secrecy may hide the content of communication, and blindness may hide the algorithm, input, or output from a server, but covertness aims to hide that any quantum operation is taking place at all [1704.07281].

In the multi-tenant cloud setting, covert quantum computing is defined differently but compatibly. There, an implementation \(\tilde{\mathcal{I}}\) is \(\delta\)-covert if for any adversary strategy \(S_W\), Willie’s total error probability in distinguishing idle from computing satisfies
\[
P_W^{\mathrm{(e)}}(S_W,\tilde{\mathcal{I}}) \ge \tfrac{1}{2}-\delta,
\]
with equal priors on the two hypotheses [2605.14325]. This definition shifts the focus from network traffic to shared-hardware observability: the adversary may control all other quantum computational units, keep a quantum memory, and run adaptive quantum strategies on the accessible subsystem [2605.14325].

A third sense arises from hostile toolchains. “Quantum Trojan Insertion: Controlled Activation for Covert Circuit Manipulation” frames covert quantum computing at the compiler and circuit layer: an untrusted compiler silently injects a controllable Trojan that remains dormant under ordinary conditions and alters the computation only when triggered [2502.08880]. This is covert not because the computation is hidden from outside observers, but because a malicious modification is hidden from the computation’s owner and from ordinary verification procedures [2502.08880].

These strands do not define a single unified object, but they do share one structural theme: the salient security question is whether some operationally meaningful event—communication, computation, control, or manipulation—can be made statistically indistinguishable from benign baseline behavior.

## 2. Communication-layer constructions

The relativistic line of work begins from the Minkowski vacuum as a covert resource. “Absolutely covert quantum communication” shows that two inertial parties equipped with Unruh–DeWitt detectors can generate entanglement and induce a quantum channel through local interactions with the Minkowski vacuum, with strictly positive quantum and secret-key rate under suitable detector parameters, while remaining “absolutely covert” because no detectable signal propagates between the parties in the usual sense [1607.05916]. In that model, the induced two-detector state \(\rho_{AB}\) is an X-state and is interpreted as the Choi state of a quantum channel \(N_{A'\to B}\), allowing standard capacity concepts such as coherent information and secret-key capacity to be applied [1607.05916].

“Covert Quantum Internet” extends this mechanism from covert communication to covert computation and networking. Its central resource is vacuum-assisted entanglement extraction using localized two-state detectors coupled to a free, real, massless scalar field \(\phi\), with switching functions
\[
w_A(t)=\lambda\,\mathbf{w}(t), \qquad w_B(t)=\lambda\,\mathbf{w}(t-L), \qquad \mathbf{w}(t)=e^{-t^2/\sigma^2},
\]
and Wightman correlator
\[
\Delta(t,\mathbf{r}; t',\mathbf{r}') = - \frac{1}{4\pi^2}\,\frac{1}{(t - t' - i\varepsilon)^2 - (\mathbf{r}-\mathbf{r}')^2}.
\]
By iterating weak detector couplings, the singlet fraction \(\mathcal{F}(\varrho)\) of the extracted state can exceed \(1/2\), after which covert entanglement distillation and covert teleportation are used as primitives for teleportation-based and one-way quantum computing [1704.07281]. In this framework, covert graph-state generation, covert cluster-state MBQC, covert 3D topological cluster-state computation, covert Union Jack state preparation, and covert universal blind quantum computation are all presented as applications of covert Bell-pair generation plus covert classical communication [1704.07281].

The optical line of work reaches a different conclusion about rates. “Covert Quantum Communication Over Optical Channels” studies lossy thermal-noise bosonic channels with dual-rail qubits and shows a square root law: over \(n\) rounds, \(M(n)\propto \sqrt{n}\) qubits can be transmitted covertly and reliably [2401.06764]. In that model, one round uses two optical modes, with dual-rail encoding
\[
|0\rangle_L = |01\rangle, \qquad |1\rangle_L = |10\rangle,
\]
and Willie’s covertness test is controlled by the relative entropy bound
\[
\sqrt{\frac{1}{8} D\big( \hat{\rho}_1^{W^n} \,\|\, \hat{\rho}_0^{W^n}\big)} \le \delta
\]
[2401.06764]. The achievable theorem states
\[
E[M(n)] \ge 2 c_{\rm cov} R \delta \sqrt{n},
\]
with
\[
c_{\rm cov} = \frac{\sqrt{2\eta \bar{n}_{\rm B} (1+\eta \bar{n}_{\rm B})}}{1-\eta},
\]
and a reliability rate derived from a Pauli/depolarizing reduction [2401.06764]. A companion general achievability result over arbitrary quantum channels gives
\[
M(n)\ge (1-\epsilon)\sqrt{n}\,c_q R\sqrt{\delta_{\mathrm{QRE}}},
\]
or
\[
M(n)\ge (1-\epsilon)\sqrt{n}\,c_q R_d\sqrt{\delta_{\mathrm{QRE}}},
\]
when assisted by a full-duplex covert classical channel [2501.13103]. The latter result is directly relevant to covert quantum computing because it supplies covert entanglement distribution plus teleportation as a general-purpose design pattern [2501.13103].

A related communication result sharpens the optical picture under uncertainty. “Robust Covert Quantum Communication under Bounded Channel Uncertainty” replaces fixed \((\eta,\bar n_B)\) by a compound uncertainty set and proves that robustness cannot be obtained by simply substituting worst-case parameters into nominal formulas, because covertness is worst at \((\eta_{\min},\bar n_{B,\min})\) while reliability is worst at \((\eta_{\min},\bar n_{B,\max})\) [2604.13116]. The robust guaranteed payload satisfies
\[
M_{\mathrm{rob}}(n)\ge 2\sqrt{n}\, c_{\mathrm{cov}}^{\mathrm{robust}} R_{\mathrm{worst}} \delta,
\]
again preserving the square-root-law scaling but altering the constant and introducing a sharp feasibility boundary beyond which the guaranteed payload drops to zero [2604.13116]. This suggests that covert quantum computation over realistic optical interconnects inherits not only the \(\sqrt{n}\) scaling but also a robustness penalty under calibration uncertainty.

## 3. Computation models enabled by covert resources

The communication constructions support several computational models. In teleportation-based covert quantum computing, covert Bell pairs allow state teleportation and gate teleportation so that nonlocal CNOT or CZ operations are implemented via local operations plus covert classical feed-forward [1704.07281]. This produces a universal distributed quantum computer so long as covert entanglement and covert classical control are available [1704.07281].

In one-way covert quantum computing, covertly generated graph states
\[
|G\rangle = \prod_{(i,j)\in E} CZ_{ij}\;|+\rangle^{\otimes |V|}
\]
serve as the MBQC resource [1704.07281]. Nodes prepare local \(|+\rangle\) states, covert CZ gates are effected by teleportation, and subsequent single-qubit measurements are local while adaptive basis updates and corrections use covert classical channels [1704.07281]. The same architecture extends to 2D cluster states, 3D topological cluster states, and Union Jack states with Pauli-universal MBQC [1704.07281].

In covert universal blind quantum computation, the Broadbent–Fitzsimons–Kashefi construction is modified so that Alice’s randomly rotated qubits
\[
|\psi_{x,y}\rangle \in \left\{
\frac{1}{\sqrt{2}}\left(|0\rangle + e^{i\theta_{x,y}}|1\rangle\right) : \theta_{x,y}\in\{0,\pi/4,\dots,7\pi/4\}
\right\}
\]
are transferred by covert teleportation rather than by an overt quantum channel, and the measurement angles
\[
\delta_{x,y} = \phi'_{x,y} + \theta_{x,y} + \pi r_{x,y}
\]
are sent covertly [1704.07281]. Blindness is preserved as in BFK, while covertness is supplied by the hidden entanglement and covert classical interaction [1704.07281]. A plausible implication is that covert blind quantum computation combines two orthogonal protections: blindness against the server and covertness against a third-party observer.

The optical square-root-law results place a quantitative restriction on these computational models. Because covert teleportation, covert remote state preparation, and covert entanglement distribution all consume covert qubits or covert ebits, a protocol using an optical channel can covertly support only \(\Theta(\sqrt{n})\) such resources over \(n\) uses [2401.06764; 2501.13103]. This suggests that small-bandwidth covert quantum computing primitives are feasible over optical channels, whereas large-scale covert offloading requires proportionally large time or mode budgets [2401.06764].

## 4. Toolchain-level covert manipulation

At the compilation layer, covert quantum computing takes the form of hidden intervention rather than hidden execution. “Quantum Trojan Insertion: Controlled Activation for Covert Circuit Manipulation” considers an untrusted compiler or transpiler that inserts a malicious subcircuit into a compiled quantum circuit [2502.08880]. The proposed Trojan consists of an X “switch gate” on a designated control qubit in the first column and a set of CX gates from the same control qubit into target qubits placed only in empty slots of later layers [2502.08880]. Given intended unitary \(U\), Trojan unitary \(U_T\), and augmented unitary \(U'\), the paper describes the activated case conceptually as
\[
U' = U_T\,U,
\]
and the controlled behavior as
\[
U' = \left(\ket{0}\!\bra{0}_c \otimes I\right) U +
     \left(\ket{1}\!\bra{1}_c \otimes V\right) U,
\]
where \(V\) flips selected targets [2502.08880].

The insertion algorithm converts the circuit to a DAG, identifies layers and empty positions
\[
E_{\text{layer}} = Q \setminus S_{\text{used}},
\]
inserts the X gate on the control qubit in the first column, and then adds CX gates into randomly chosen empty positions up to a gate limit [2502.08880]. The resulting Trojan is designed to preserve circuit depth and remain dormant when the control qubit is effectively in \(\ket{0}\) [2502.08880].

Empirically, the reported performance characteristics are the core reason this work is relevant to covert quantum computing. In the benchmark experiments, circuit depth was unchanged, gate-count overhead was approximately \(20\%\) on average, and activated output distributions deviated by approximately \(90\%\) in total variation distance from intended outputs [2502.08880]. The paper measures
\[
\text{TVD} = \frac{1}{2N} \sum_{i=0}^{2^b - 1} \left| y_{i,\text{orig}} - y_{i,\text{alter}} \right|,
\]
and finds TVD near \(0.9\)–\(1\) for larger circuits when the Trojan is activated, while deactivated behavior remains close to the original circuit [2502.08880]. This directly instantiates covert sabotage: the computation appears ordinary under normal testing, but can be selectively corrupted on demand.

The experiments use IBM Qiskit, RevLib reversible benchmarks, the `FakeValencia` backend, and 1,000 shots per run [2502.08880]. The attack surface is a cloud or third-party compilation service, and the underlying point is systemic: trustworthy quantum computing requires securing the compiler chain as much as the hardware [2502.08880]. A common misconception is that covert quantum computing concerns only hidden network traffic; this work shows that covert behavior can also mean latent, selectively activated functionality buried in ostensibly legitimate quantum circuits.

## 5. Multi-tenant hardware, observability, and side channels

The hardware-side notion of covert quantum computing is developed in “Toward Covert Quantum Computing” [2605.14325]. The setting is a multi-tenant quantum processing unit in which Alice uses \(n\) of \(N\) total quantum computational units and Willie controls the remaining \(s=N-n\) QCUs plus an arbitrary-dimensional quantum memory [2605.14325]. Because Willie may prepare arbitrary initial states, apply adaptive CPTP maps between Alice’s gate operations, and defer a collective measurement to the end, the paper adopts the quantum-strategy framework rather than a static channel-discrimination model [2605.14325].

If \(S_A^{(1)}(\tilde{\mathcal{I}})\) denotes the \(r\)-round strategy induced by Alice’s implementation and \(S_A^{(0)}\) the idle strategy, then Willie’s minimum error probability is
\[
\min P_W^{\mathrm{(e)}} =
\frac{1}{2} - \frac{1}{4} \left\| S_A^{(1)}(\tilde{\mathcal{I}}) - S_A^{(0)} \right\|_{\diamond r},
\]
and \(\delta\)-covertness is equivalent to
\[
\frac{1}{4}\left\| S_A^{(1)}(\tilde{\mathcal{I}}) - S_A^{(0)} \right\|_{\diamond r} \le \delta
\]
[2605.14325]. Reliability is defined separately by diamond-norm closeness of the realized instrument to the ideal instrument [2605.14325].

Under a nearest-neighbor residual ZZ crosstalk model on planar lattices, the paper proves geometric square-root laws using discrete isoperimetric inequalities [2605.14325]. For the square lattice,
\[
|\mathcal{E}(S^{\rm S})| \ge 4 \sqrt{|S^{\rm S}|}, \qquad |N(S^{\rm S})| \ge 2\sqrt{2|S^{\rm S}|},
\]
for the hexagonal lattice,
\[
|N(S^{\rm H})| \ge \sqrt{6|S^{\rm H}|}, \qquad |\mathcal{E}(S^{\rm H})| \ge \sqrt{6|S^{\rm H}|},
\]
and for heavy-hex,
\[
|N(S^{\rm HH})| \ge \frac{-9 + \sqrt{81 + 60|S^{\rm HH}|}}{5}
\]
[2605.14325]. These inequalities imply that an \(n\)-qubit computational region can be embedded so that only \(\mathcal{O}(\sqrt{n})\) border qubits expose detection information to Willie [2605.14325]. Consequently, at most \(\mathcal{O}(\sqrt{n})\) additional idle buffer qubits are required to ensure covertness under the nearest-neighbor-only model [2605.14325].

The experimental study on IQM’s 54-qubit Emerald processor and IBM’s 156-qubit `ibm_fez` machine partially validates and partially destabilizes this picture [2605.14325]. Ramsey experiments on spectator qubits confirm detectable nearest-neighbor crosstalk, but also reveal long-range coupling beyond border qubits, which the paper hypothesizes may arise from leakage from drive and control lines [2605.14325]. This long-range crosstalk weakens the nearest-neighbor-based covertness guarantee and exposes a hardware side channel that co-tenants can exploit [2605.14325]. A plausible implication is that covert quantum computing on shared hardware is not only a matter of layout geometry; it also depends critically on packaging, drive-line isolation, and detailed crosstalk characterization.

## 6. Adversaries, sensing, and broader covert information processing

Some recent work expands the adversarial model or recasts covertness using alternative information-theoretic quantities. “Quantum Covert Communication under Extreme Adversarial Control” introduces a controller that governs both classical and quantum communication infrastructure, may ban public-key cryptography, and may demand secret strings such as basis selection strings \(a\), state selection strings \(b\), and Bell-state selection strings \(c\) from users [2504.06359]. The constructions described there use protocol structure, entanglement, and error-checking phases of BB84- and DL04-like protocols so that covert communication remains statistically indistinguishable from ordinary failure due to eavesdropping or noise [2504.06359]. This suggests that covert quantum computing may need “anamorphic” protocol layers: overt protocol transcripts consistent with benign explanations, yet carrying hidden computational resources or instructions.

The sensing literature introduces a different but relevant abstraction. “Chernoff Information Bottleneck for Covert Quantum Target Sensing” defines covert information
\[
I_{\mathrm{C}}(d,\mathcal{S}) := \max_{\xi^{(E)} \le d} \xi^{(A)},
\]
where \(\xi^{(A)}\) is the legitimate party’s Chernoff information for the sensing task and \(\xi^{(E)}\) is the adversary’s Chernoff information for detecting that sensing is taking place [2504.06217]. The Lagrangian
\[
\mathcal{L}_{\mathrm{C}} := \xi^{(A)} - \beta \xi^{(E)}
\]
traces the covertness–utility trade-off [2504.06217]. The paper further emphasizes the effective covert criterion
\[
\Delta \xi := \xi^{(A)} - \xi^{(E)} > 0,
\]
which identifies a regime in which the legitimate user’s information rate exceeds the adversary’s detection rate [2504.06217]. Although developed for LiDAR-like target sensing rather than computing, this framework suggests a task-agnostic way to analyze covert quantum computing whenever the legitimate objective and the adversary’s objective can both be cast as hypothesis-testing problems.

A further extension is represented by “RAPID Quantum Detection and Demodulation of Covert Communications,” which studies NV-center-based sensing below the classical noise floor using QFIM-guided baseline optimization and an adaptive Soft Actor-Critic policy [2509.08171]. This paper is about covert signal detection, not computation, but it shows that covert quantum technology increasingly includes adaptive control, Bayesian risk objectives, and resource-constrained optimization. A plausible implication is that future covert quantum computing systems may combine covert communication, covert sensing, and adaptive control into a unified architecture.

## 7. Limitations, tensions, and unresolved questions

Several tensions recur across the literature. First, the physical mechanism that improves covertness may degrade reliability. In optical channels, thermal noise helps hide transmissions but harms Bob’s effective qubit channel [2401.06764; 2604.13116]. Under uncertainty, covertness is hardest at low noise whereas reliability is hardest at high noise, forcing robust protocols to satisfy conflicting corner constraints [2604.13116]. This is not a superficial engineering issue but a structural limitation on covert quantum information processing.

Second, positive-rate covert operation appears model-dependent. In relativistic vacuum-based constructions, the induced covert quantum channel can have strictly positive rate because no ordinary propagating signal is emitted [1607.05916]. In lossy thermal-noise optical channels, by contrast, covert throughput obeys a square-root law \(\Theta(\sqrt{n})\) [2401.06764; 2501.13103]. In helper-assisted quantum multiple-access channels, positive covert rates become possible again because a helper can shape the joint output so that the warden’s marginal exactly matches the innocent state [2504.18747]. The literature therefore does not support a universal covert-capacity law independent of physical model.

Third, compiler-layer and hardware-layer covert phenomena complicate the usual network-centric view. A system may satisfy communication-layer covertness while remaining vulnerable to covert circuit manipulation [2502.08880], or it may hide traffic successfully while leaking activity through crosstalk to co-tenants [2605.14325]. This suggests that covert quantum computing should not be treated as a single-layer property.

Finally, full covert quantum computation in the strongest sense remains largely prospective. The cited works provide covert communication primitives, covert MBQC and UBQC constructions, geometric criteria for covert execution on shared hardware, and concrete covert attack models, but no complete end-to-end framework unifies these into a single composable theory. This suggests that the field is still defining its boundaries.

## 8. Synthesis

Across these works, covert quantum computing emerges as a layered research area rather than a single protocol family. At the communication layer, it includes hidden entanglement generation from the Minkowski vacuum, covert teleportation, covert MBQC, and covert blind computation [1704.07281; 1607.05916]. At the optical-channel layer, it includes square-root-law-limited covert qubit and ebit transfer, robustified under compound uncertainty [2401.06764; 2501.13103; 2604.13116]. At the systems layer, it includes helper-assisted positive-rate covert coordination [2504.18747], detection-theoretic covert sensing [2504.06217], and adaptive sub-noise-floor demodulation of covert signals [2509.08171]. At the adversarial toolchain and hardware layers, it includes compiler-inserted Trojan circuits and multi-tenant crosstalk observability [2502.08880; 2605.14325].

The cumulative picture is that covert quantum computing is not reducible to secrecy, blindness, or fault tolerance. It concerns the statistical invisibility of quantum operations themselves, whether those operations are benevolent, adversarial, or merely computationally necessary. This suggests that future progress will likely depend on combining communication-theoretic covertness, secure compilation, hardware isolation, and adaptive control into a single security model that spans the full quantum stack.

Source: https://www.emergentmind.com/topics/covert-quantum-computing