---
title: 'Q-LEAK: Diverse Quantum Leakage Analysis'
url: https://www.emergentmind.com/topics/q-leak
type: topic
---

# Q-LEAK: Diverse Quantum Leakage Analysis

Q-LEAK is not a single standardized term. In the research literature it appears across several distinct domains: as a process-theoretic notion of “leaks” in categorical quantum foundations; as a label for leakage characterization, detection, and mitigation in quantum hardware; as a quantum-assisted framework for verifying side-channel leakage countermeasures; as a model-extraction attack against cloud-hosted quantum neural networks; and, separately, as the name of a Leak Microstructure detector architecture [1701.07404] [2605.25728] [2403.10790] [2009.08094]. This suggests a polysemous usage in which the common thread is controlled or adversarial disclosure, but the technical objects, threat models, and performance criteria differ substantially.

## 1. Disambiguation of the term

| Usage | Core object | Representative paper |
|---|---|---|
| Process theory | Leak \(L_A:A\to A\otimes L\) with right-counitality | [1701.07404] |
| Side-channel verification | CNF-encoded leakage predicate searched by Grover/BBHT | [2605.25728] |
| Quantum ML security | Extraction of a black-box QNN from NISQ outputs | [2403.10790] |
| Quantum hardware leakage | Population leaving the computational subspace | [1704.03081], [2002.07119] |
| Detector physics | Leak Microstructure gaseous detector | [2009.08094] |

The most exact title match is "Q-LEAK: Quantum-Based LEAKage Verification for Side-Channel Countermeasures" [2605.25728]. However, the broader literature associates the label with at least four other technical strands. For researchers, disambiguation is therefore essential: in one context Q-LEAK is a Grover-based SAT workflow, in another it refers to subspace leakage in transmons, and in another it denotes a cloud attack on variational quantum circuits.

## 2. Process-theoretic leaks and the quantum–classical boundary

In general process theories, a leak on system \(A\) is a causal process \(L_A:A\to A\otimes L\) satisfying right-counitality,
\[
(\id_A\otimes\discard_L)\circ L_A=\id_A.
\]
Leaks are causal and are closed under sequential and parallel composition [1701.07404]. This definition is structural rather than operational: it does not presuppose Hilbert spaces, only a symmetric monoidal category with discarding maps.

Within finite-dimensional quantum theory, any leak \(L:\mathcal{B}(\mathcal{H})\to\mathcal{B}(\mathcal{H})\otimes\mathcal{B}(\mathcal{K})\) must be a constant leak of the form
\[
L(\rho)=\rho\otimes \sigma,\qquad \Tr(\sigma)=1.
\]
The counitality condition therefore forces separation, and quantum theory admits only trivial leakage; in the terminology of the paper, it is minimally leaking. The leak-quality construction likewise yields \(\mathsf{qual}(L)=0\) for all quantum leaks [1701.07404].

Classical theory is the opposite extreme. It admits a nontrivial leak given by broadcasting,
\[
\mathsf{copy}:X\to X\otimes X:\;x\mapsto (x,x),
\]
satisfying both right- and left-counitality. Every classical leak on an \(n\)-state system factors as
\[
L(x)=\sum_y p(y|x)\,(x,y),
\]
that is, as a stochastic map followed by copying [1701.07404]. In this sense classical theory is maximally leaking.

A central construction adjoins leaks to a theory. Using the decoherence idempotent
\[
\Delta(\rho)=\sum_i |i\rangle\langle i|\rho|i\rangle\langle i|,
\]
and restricting to maps \(f\) satisfying \(f=\Delta_B\circ f\circ \Delta_A\), one recovers exactly the stochastic maps. In the adjoined theory the pre-leaks \(\Delta\) become genuine leaks. The same construction, with different idempotents, yields all finite-dimensional \(C^\ast\)-algebras, i.e. quantum systems with classical superselection [1701.07404].

The same paper argues that purity cannot be defined in leaking theories by the naive criterion “no nontrivial dilation.” In any theory with a non-constant leak, that criterion trivializes the identity. The refined definition requires that every dilation factor through the built-in leak of the system. Under this definition, quantum purity reduces to Kraus-rank-1 CPTP maps; classical purity reduces to deterministic processes \(x\mapsto(i(x),r_{i(x)})\), with pure stochastic matrices exactly the \(0\)–\(1\) permutation-sub-matrices; and in classical–quantum composites every pure map splits into a classical read-out followed by a family of pure quantum maps, and vice versa [1701.07404].

## 3. Leakage as a quantum-hardware error model

In quantum control and fault tolerance, leakage denotes population transfer from a computational subspace \(P\) into its complement \(Q=I-P\). A general framework introduces the average leakage rate
\[
L(\Lambda)=\frac{1}{d}\Tr[Q\,\Lambda(P)]
\]
and seepage rate
\[
S(\Lambda)=\frac{1}{D-d}\Tr[P\,\Lambda(Q)],
\]
for a CPTP map \(\Lambda\), together with a restricted average gate fidelity \(\bar F(\Lambda)\) on the computational subspace [1704.03081]. Leakage-randomized benchmarking estimates \(\bar F\), \(L\), and \(S\) simultaneously via
\[
\overline p_1(m)=A+B(1-L-S)^m,
\]
with \(A=\frac{S}{L+S}\), \(B=\frac{L}{L+S}\), and \(\lambda_1=1-L-S\) [1704.03081].

A related randomized-benchmarking protocol separates incoherent from coherent leakage by using unitary \(1\)-designs. The incoherent protocol yields a single exponential \(P_{\rm inc}(m)=A[s_{\rm inc}(\mathcal{E})]^{m-1}+O(m\epsilon)\), while the coherent protocol yields a bi-exponential governed by eigenvalues \(\lambda_\pm\), from which \(s_{\rm coh}\) and \(\ell_{\rm coh}=s_{\rm inc}-s_{\rm coh}\) are recovered [1412.4126]. This establishes leakage as a distinct control metric rather than a mere fidelity defect.

For transmon-based QEC, leakage has been analyzed at the qutrit level in Surface-17 using two-state HMMs with states \(C\) and \(L\). Leakage is sharply projected by stabilizer measurements, and neighboring defect probabilities rise toward \(50\%\) when a data qubit leaks. HMM tracking of data-qubit leakage achieves average optimality AUC \(\approx 74\%\); with analog ancilla readout, bulk ancilla AUC reaches \(96\%\) and boundary ancilla \(95\%\). Post-selecting out leakage discards about \(47\%\) of the data and restores the logical error rate below the memory break-even point, with \(\lambda_{\rm post}(47\%)<\lambda_{\rm mem}\approx 0.24\) per cycle, compared with \(\lambda_{17}^{no\text{-}leak}\approx 0.15\) and \(\lambda_{17}^{leak}\approx 0.45\) [2002.07119].

Adaptive suppression frameworks move from measurement to intervention. ERASER speculates leaked qubits from failed parity-check patterns and schedules LRCs only on flagged qubits; ERASER and ERASER+M improve the logical error rate by up to \(4.3\times\) and \(23\times\), respectively, compared to always using LRC [2309.13143]. GLADIATOR generalizes this idea with a code-aware error-propagation graph, classifying syndrome patterns as leakage-dominated when \(W_{\rm L}(s)/W_{\rm NL}(s)\ge \tau\) with \(\tau=1\). It eliminates up to \(3\times\) unnecessary LRCs, delivers \(1.7\times\)–\(3.9\times\) speedups, and reduces logical error rate by \(16\%\) [2510.25661].

## 4. Q-LEAK as quantum-assisted side-channel verification

In the exact-title usage, Q-LEAK is a framework for formal verification of one-bit leakage under two-trace conditions in time-unrolled cryptographic circuits [2605.25728]. The model considers two executions \(A\) and \(B\) under keys \(k\) and \(k'\), common plaintext \(P\), and one-bit state trajectories \(s[t]\), \(s'[t]\). Leakage bits are identified with state bits, \(\ell[t]=s[t]\) and \(\ell'[t]=s'[t]\). In “notequal” mode the leakage predicate is
\[
\mathrm{Leak\_diff}:=\bigvee_{t=1}^T (\ell[t]\oplus \ell'[t])=1,
\]
while “equal” mode uses
\[
\mathrm{Leak\_eq}:=\bigwedge_{t=1}^T (\ell[t]\leftrightarrow \ell'[t])=1.
\]
Transition clauses, leakage clauses, the selected predicate, and optionally \(\Delta k=1\) are conjoined into a CNF formula \(F(x)=\bigwedge_{j=1}^m C_j\), satisfiable iff a violating key-pair and state evolution exist [2605.25728].

Q-LEAK then compiles the CNF into a quantum phase oracle
\[
U_F:\;|x\rangle|0^A\rangle\mapsto (-1)^{F(x)}|x\rangle|0^A\rangle.
\]
The BuildOracle procedure allocates clause ancillas \(c_1,\dots,c_m\) and a flag qubit \(f\), computes clause violations, derives \(f\) as the no-violation indicator, applies a controlled \(Z\), and uncomputes all ancillas. Each call costs \(O(m)\) multi-controlled gates and uses \(n+m+1\) qubits [2605.25728].

Search is performed by Grover iteration \(G=DU_F\), with the usual rotation angle determined by \(\sin^2\theta=K/N\), where \(K\) is the number of satisfying assignments and \(N=2^n\). Because \(K\) is unknown, the implementation uses Boyer-Brassard-Høyer-Tapp: initialize \(k\leftarrow 1\), grow by a factor \(\lambda>1\) such as \(8/7\), sample a random number of Grover steps \(r\in\{0,\dots,k-1\}\), measure, classically verify \(F(x)\), and repeat until success or \(k>\sqrt N\). The expected oracle complexity is \(O(\sqrt{N/K})\); since each oracle costs \(\Theta(m)\) and the diffuser costs \(\Theta(n)\), the total gate-call complexity is \(O(m\sqrt{N/K})\) [2605.25728].

Benchmarks were assembled for \(T=1\), \(n\in\{5,6,7\}\), \(m\approx 2n\ldots 3n\), and exactly \(K=2\) satisfying assignments in SAT cases. In noiseless simulation, Q-LEAK consistently recovered a satisfying assignment within \(1\)–\(4\) tries. Case 1 used \(n=5\), \(m=11\), \(K=2\), and “notequal” leakage with keys unconstrained; it required \(17\) qubits, had depth \(\approx 40\) per Grover iteration, average BBHT tries \(1.2\), and measured peak probabilities \(\simeq 0.20\) on the two true solutions against background \(\simeq 1/32\approx 0.031\). Case 2 used \(n=6\), \(m=14\), \(K=2\), “equal” leakage, \(21\) qubits, depth \(\approx 44\), average tries \(\simeq 2.0\), and true-solution peaks \(\simeq 0.16\)–\(0.18\). Case 3 used \(n=7\), \(m=19\), \(K=2\), “notequal” plus \(\Delta k=1\), \(27\) qubits, depth \(\approx 46\), average tries \(\simeq 1.3\), and true-solution peaks \(\simeq 0.11\). The UNSAT control produced a uniform histogram, with a \(\chi^2\)-goodness-of-fit consistent with uniformity and Hoeffding-based \(99\%\) certification that no bin exceeded \(1/32+\epsilon\) [2605.25728].

Real-hardware experiments on the \(156\)-qubit ibm_marrakesh device preserved the qualitative signal. For Case 1, one true solution \((11100)\) emerged as the highest-probability peak at about \(8\)–\(10\%\), while spurious bitstrings reached about \(5\)–\(7\%\) against background noise levels of about \(1\)–\(2\%\). For Case 2, the true solution \((101101)\) again appeared highest at about \(9\%\), with a few false positives at \(4\)–\(6\%\) and uniform background raised to about \(2\)–\(3\%\). Each experiment returned at least one classically valid SAT assignment among its top peaks [2605.25728].

## 5. QuantumLeak and extraction of cloud-based quantum neural networks

A separate use of leakage terminology appears in quantum machine learning. QuantumLeak targets black-box victim QNNs \(Q_V\) hosted on cloud-based NISQ machines, assuming only query access to classical inputs \(x\) and the return of raw probability vectors \(Q_V(x)\in\Delta^C\), with no knowledge of the victim’s ansatz, dataset, hyperparameters, or device-specific error rates [2403.10790].

The attack has three phases: query and data bagging, ensemble substitute initialization and training, and decision fusion. A candidate set \(S=\{x_i\}\) is built from public data; each input is queried over \(m\) spread-out rounds and averaged as
\[
y_i=\frac{1}{m}\sum_{r=1}^m Q_V^{(r)}(x_i),
\]
forming a noisy dataset \(D=\{(x_i,y_i)\}\). The dataset is bootstrapped into \(N_C\) bags; for each bag, an attacker selects an ansatz from a zoo \(\mathbb{Q}=\{L1,L2,L3,A1,A2,\dots\}\), initializes \(\theta_k\sim\mathcal{N}(0,\sigma^2)\), trains a substitute \(Q_A\), and fuses the trained models by majority vote on raw-probability or class votes [2403.10790].

Training minimizes either NLL or coordinate-wise Huber loss,
\[
L(\theta)=\frac1{|D_k|}\sum_{(x,y)\in D_k}\ell(Q_A(x;\theta),y),
\]
with gradients estimated by the parameter-shift rule and parameters updated by Adam or SGD. The design explicitly addresses SPAM error, gate depolarization with \(\varepsilon_{\rm SPAM}\approx 0.3\%\), \(\varepsilon_{1Q}\approx 0.2\%\), and \(\varepsilon_{2Q}\in[0.4\%,3\%]\), as well as crosstalk and coherent miscalibrations [2403.10790].

Experiments used IBM_Auckland, four-qubit victim VQCs with amplitude encoding and two parameterized layers, and MNIST/Fashion-MNIST tasks preprocessed to \(1\times 8\) vectors. Against CloudLeak, QuantumLeak’s ensemble with Huber loss improved substitute accuracy by \(+7.35\%\) on MNIST \(0/1\), \(+4.99\%\) on MNIST \(2/3\), \(+5.57\%\) on Fashion-MNIST t-shirt/trouser, and \(+6.64\%\) on Fashion-MNIST pullover/dress. Each result was averaged over \(5\) independent runs, with standard deviation \(\sigma<1.2\%\) and \(95\%\) confidence interval \(\pm 2\sigma\) [2403.10790]. The attack is limited by high-dimensional inputs, many-qubit models, ansatz mismatch, and detectable query budgets; proposed defenses include watermarking, quantum PUFs, dummy gates and circuit obfuscation, and access throttling with anomaly detection [2403.10790].

## 6. Adjacent leakage frameworks and other uses of the label

In classical security analysis, adjacent work studies leakage quantitatively rather than using the exact title string. CHALICE models cache attacks by symbolic execution and computes how many secrets remain consistent with observed hit/miss behavior; for AES-128 on Linux it finds that a cache attack can leak as much as \(127\) out of \(128\) bits of the encryption key [1611.04426]. A bounded-model-checking framework for quantitative leak vulnerabilities reduces a policy of “at most \(N\) distinctions” to CBMC queries over generated drivers and was applied to Linux-kernel CVEs, SRP, and IMSPD, including proofs that official patches eliminate the leaks [1007.0918]. Source-level reasoning for QIF uses gain-functions and hyper-distributions to express leakage properties directly in a small imperative language, while a later dynamic-leakage measure \(\Delta_g(b,p;y)\) decouples the adversary’s belief \(b\) from a baseline distribution \(p\) and proves non-interference together with single-step monotonicity and single-step data-processing inequalities [2405.13416] [2510.20922]. For RTL hardware, QTFlow extends Bayes-vulnerability analysis to sequential circuits by extracting the FSM, pruning infeasible paths, and detecting timing channels; on the reported benchmarks it diminishes all false positives arising from time-agnostic analysis and identifies \(3\) timing channels in each Trojan-infested RSA design [2401.17819].

In quantum cryptography and communication, “leaky source” work generalizes the notion of leakage to side information emitted by modulators. Decoy-state QKD with arbitrary IM and PM leakage introduces trace-distance constraints \(D_{n,j,k,l}\) between leaked states and shows key rates similar to those obtained in a perfectly shielded environment in practical cases, especially with optical isolation and active phase randomization [1803.06045]. The MDI-QKD analogue develops a fully composable finite-key proof for three-intensity and four-intensity protocols with source leakage, combining trace-distance decoy bounds, Azuma’s inequality, Serfling’s inequality, and a quantum-coin phase-error analysis [2001.08086]. A different measure, gentle quantum leakage,
\[
L_{(\alpha,\delta)}(X\to A)_\rho=\sup_{F\in G_{(\alpha,\delta)}(S)} I_\infty(X;Y),
\]
optimizes over weakly gentle POVMs, satisfies positivity and unitary invariance, decreases under global depolarizing noise, and in the BB84 example yields the lower bound \(\underline L_{0.1}\simeq 0.7608\) bits [2403.11433].

Finally, Q-LEAK is also the name of a compact gaseous imaging detector based on a matrix of Leak Microstructures. The detector uses a \(21\times 21\) LM matrix on a \(60\times 60\,\mathrm{mm}^2\) board with \(3\,\mathrm{mm}\) pitch, achieves gains \(>6\times 10^5\) for \(5.9\,\mathrm{keV}\) X-rays at \(1\) bar isobutane and \(>10^6\) for single electrons in propane at \(1\)–\(3\,\mathrm{mbar}\), shows spatial linearity with deviation \(\le \pm 50\,\mu\mathrm{m}\) over \(10\,\mathrm{mm}\), attains overall resolution \(\sim 460\,\mu\mathrm{m}\) FWHM without software correction, reaches \(100\%\) relative efficiency for \(\alpha\)-particle detection compared with a silicon detector, and yields single-electron multiplication efficiency up to \(96\%\) [2009.08094].

Across these literatures, the unifying theme is not a single formalism but a family of leakage-centric problems: structural leakage in process theories, subspace leakage in quantum hardware, information leakage in cryptographic verification and QIF, side-channel leakage in real devices and implementations, and even signal leakage in instrumentation. This suggests that “Q-LEAK” functions best as a context-dependent research label rather than as a uniquely defined term.

Source: https://www.emergentmind.com/topics/q-leak