Quantum Tamper Detection
- Quantum tamper detection is a family of techniques that exploits quantum state disturbance and entanglement to expose unauthorized modifications.
- It encompasses methods from tamper-evident encryption and entanglement-based seals to hardware fingerprinting and quantum-inspired anomaly monitoring.
- Integrating quantum coding theory with physical-device authentication, these techniques enhance security against both algorithmic and hardware-based tampering.
Searching arXiv for the cited papers and closely related work on quantum tamper detection. Quantum tamper detection denotes a family of techniques and security notions that use quantum states, quantum measurements, or quantum-inspired state representations to reveal unauthorized modification, interception, cloning, or substitution. Across the literature, the phrase does not refer to a single canonical mechanism. It spans at least four distinct regimes: tamper-evident communication primitives based on quantum states and entanglement; hardware-authentication and side-channel methods that exploit quantum physical effects; cloud-hardware authentication by fingerprinting raw quantum-device behavior; and formal coding-theoretic constructions that detect tampering of quantum-encoded data (Lord, 2024, Williams et al., 2015, Ma et al., 10 Jun 2026, Boddu et al., 2021). A recurring theme is that quantum mechanics changes the detectability landscape because copying, extracting, or reusing quantum information often perturbs the protected object, while quantum-enhanced hardware can also expose tamper-induced physical changes that are inaccessible to ordinary classical checks (Goyal et al., 7 Oct 2025, Sun et al., 2015, Lenz et al., 2024).
1. Tamper evidence as a quantum cryptographic primitive
In quantum cryptography, tamper detection is formalized most explicitly by quantum tamper-evident encryption, a primitive in which a classical message is encrypted into a quantum ciphertext and decryption returns both a plaintext and an accept/reject flag (Lord, 2024). The defining guarantee is not merely confidentiality. Rather, if the recipient accepts, then any adversary’s retained post-attack state should be almost message-independent, so successful acceptance certifies the absence of meaningful eavesdropping in the sense relevant to later decryption (Lord, 2024).
The formal machinery is built around an augmented quantum encryption of classical messages scheme with key generation , encryption , and decryption , where decryption outputs a message register and a flag register. The accept branch is written as , and correctness requires that for all messages ,
$\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$
Tampering is modeled by a general attack channel
$A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$
allowing the adversary both to alter the transmitted ciphertext and to retain side information (Lord, 2024).
The resulting tamper-evidence condition is expressed through trace distance between the adversary’s subnormalized post-acceptance states for two messages : $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$ This means that either Bob rejects or, conditional on acceptance, the adversary has learned essentially nothing useful about the message (Lord, 2024).
A major structural result is that tamper evidence already implies encryption. Specifically, an -correct 0-tamper-evident AQECM scheme is 1-encrypting (Lord, 2024). This answers the question of whether confidentiality had to be imposed separately: it does not. The same work also shows that tamper evidence is tightly related to revocation, that it can yield quantum money, and that it is strictly weaker than both authentication and uncloneable encryption (Lord, 2024). This suggests that “tamper evident” is a distinct cryptographic notion rather than a synonym for stronger primitives.
A different but closely related line introduces Proofs of No Intrusion, in which a classical client remotely tests whether a quantum server has been hacked and whether the client’s data has been stolen, while preserving the tested quantum object (Goyal et al., 7 Oct 2025). There the goal is not merely to detect arbitrary disturbance, but to rule out prior extraction of enough information to recover the protected secret. The central theorem states that, assuming oblivious state preparation for coset states and fully homomorphic encryption, there exists an encryption scheme with search proofs of no intrusion (Goyal et al., 7 Oct 2025). This places tamper detection in a remote-storage setting where later acceptance implies that no previous attacker could have exfiltrated enough information to recover the plaintext, even if the secret key later leaks (Goyal et al., 7 Oct 2025).
2. Entanglement-based seals and covert intrusion sensing
A more direct operational notion of quantum tamper detection appears in tamper-indicating quantum seals. In this setting the goal is not message encryption but surveillance of a physical path or boundary, typically an optical fiber traversing an unsecured region. The seal sends entangled photon pairs through a trusted-reference path and an untrusted active path, then uses Bell-state analysis to verify that the returning state is still authentically entangled (Williams et al., 2015).
The core observable is
2
For separable states the paper proves
3
whereas for Bell states 4 and 5, 6 reaches 7 and 8, respectively (Williams et al., 2015). This yields a direct tamper-indication rule: if the observed 9 exceeds 0, the returned state is definitely entangled, so intercept-resend spoofing cannot have reproduced the original seal state (Williams et al., 2015).
The same system also uses Hong–Ou–Mandel sensitivity to constrain redirection attacks. For delay 1, the correlation parameter is modulated by
2
with 3 ps in the experiment, and a one-way path-length difference greater than about 4 drives 5, below the entanglement-authentication threshold (Williams et al., 2015). Using binary detection theory, the prototype achieved probability of detecting inauthentic signals greater than 6 with false alarm probability about 7 for a 8 s sampling interval (Williams et al., 2015). In this regime, tamper detection is genuinely quantum: the adversary cannot counterfeit the nonlocal state that the seal authenticates.
At a very different operating point, an Invisible Quantum Tripwire addresses covert intrusion detection rather than authenticity of returned entanglement (Anisimov et al., 2010). The intrusion event is modeled as an absorber placed in one arm of a polarization interferometer. The apparatus combines interaction-free measurement with a lossy multi-pass quantum Zeno configuration. After 9 passes, if an object is present, the transmission probability is
0
while the probability that a photon actually strikes the object is
1
with 2 the engineered single-cycle loss in the detection arm (Anisimov et al., 2010). The system is analyzed statistically using a Chernoff bound,
3
and compared against the probability that the tripwire remains undiscovered,
4
The design goal is 5, so confidence in detecting an intruder grows faster than the probability of revealing the detector (Anisimov et al., 2010). This is quantum tamper detection in a surveillance sense: the “tamper” is the appearance of an intruder in a monitored optical path.
3. Tamper detection in quantum communication hardware
Quantum tamper detection also arises as a hardware-security problem inside quantum cryptographic systems. One strand studies how detector-side hacking attacks can be transformed into measurable statistical anomalies. In a QKD receiver with detection randomization, beamsplitters and extra single-photon detectors create output modes that are not deterministically accessible to an adversary using bright-light faked states (Silva et al., 2014). For a beamsplitter with transmissivity 6,
7
Under honest operation, coincidences between the paired detectors behind one beamsplitter arm should be rare: 8 Under a bright-light attack, however, both detectors in a branch can fire simultaneously or asymmetrically, leaving conspicuous fingerprints in coincidence counts and detector-balance statistics (Silva et al., 2014).
The same paper adds active detector scrambling against detection-efficiency-mismatch and time-shift attacks. By choosing between two HWP settings that swap which detector corresponds to which logical outcome, Bob randomizes the mapping
9
0
This makes detector identity unreliable as a side channel, reducing the information leaked by timing-based mismatch attacks from about 1 to below 2 in the reported experiment (Silva et al., 2014). The significance for tamper detection is architectural: internal receiver randomness turns externally imposed detector control into observable anomalies.
A closely related idea appears in a countermeasure based on multi-pixel detectors. There Bob monitors not only logical clicks but also coincidences between pixels corresponding to the same logical outcome (Gras et al., 2020). In the simplified symmetric model,
3
4
and the ratio
5
satisfies 6 in the honest limit and 7 under full detector-control attack (Gras et al., 2020). The paper converts these monitored statistics into an explicit upper bound on Eve’s information: 8 Thus detector tampering becomes not only detectable but quantifiable through observed anomaly in coincidence behavior (Gras et al., 2020).
The hardware side is not limited to detectors. A source-side attack in QKD shows that an adversary can actively tamper with Alice’s semiconductor laser diode by injecting light backward into the source, violating the phase-randomization assumption central to many security proofs (Sun et al., 2015). The attacked source no longer satisfies
9
and interferometric histograms shift from U-shaped to Gaussian-like, revealing that adjacent-pulse phases are no longer uniformly random (Sun et al., 2015). The paper’s significance for tamper detection lies in showing that the source, not only the detector, must be treated as an actively tamperable component, and that ordinary high-level protocol observables may not suffice to detect such source manipulation (Sun et al., 2015).
A separate architectural proposal, QC-TEE, adds a tamper detection engine to trusted hardware inside a dilution refrigerator for cloud superconducting quantum computers (Trochatos et al., 2023). Its main goal is confidentiality of analog control pulses rather than general execution integrity, but it explicitly includes a battery-backed tamper detection engine that monitors temperature or pressure changes and erases secrets on disturbance (Trochatos et al., 2023). This is best understood as HSM-like tamper response for trusted quantum-control hardware rather than full quantum tamper detection of computations, yet it illustrates how physical tamper evidence can be embedded into quantum-computing infrastructure (Trochatos et al., 2023).
4. Hardware authentication and fingerprinting of quantum or quantum-enabled devices
Another major branch of quantum tamper detection concerns physical-device identity. In semiconductor hardware, quantum confinement in resonant tunnelling diodes produces device-specific tunnelling spectra that can function as unique identities (Roberts et al., 2015). Each RTD contains an InGaAs quantum well between AlAs barriers, and the confined energy levels are exponentially sensitive to nanoscale imperfections. The identity readout is the I–V characteristic, especially the resonant current peak. Across $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$0 nominally identical devices, the resonance peaks spanned approximately $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$1 mV in peak voltage and $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$2 mA in peak current, and the five most closely clustered devices still had confidence ellipses with no overlap at $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$3 confidence (Roberts et al., 2015). The paper does not implement a dedicated tamper alarm, but it explicitly argues that invasive interference would distort the nanostructure and hence the produced results, making the RTD a tamper-evident authentication primitive rather than a standalone detector (Roberts et al., 2015).
In integrated circuits, the Quantum Diamond Microscope images the magnetic-field side channel produced by current flow, thereby localizing anomalous current activity associated with hardware Trojans (Lenz et al., 2024). The physical basis is NV-center magnetometry. Relevant performance numbers include a demonstrated spatial resolution of approximately $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$4, a volume-normalized magnetic sensitivity of $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$5 for a $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$6 voxel, and a field of view around $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$7 (Lenz et al., 2024). The paper’s most direct tamper-relevant demonstration is rare-event detection on an Artix-7 FPGA: the QDM could still detect ring-oscillator activity when the source was pulsed for only $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$8 ms during a $\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.$9 ms exposure, corresponding to a $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$0 duty cycle (Lenz et al., 2024). This supports its role as a forensic localization tool for post-fabrication tamper detection, especially where Trojan logic alters current distribution (Lenz et al., 2024).
In cloud quantum computing, a newer approach treats the quantum processor itself as a fingerprintable physical object. Raw-Curve Quantum Fingerprints are built by concatenating raw statistics from Ramsey, driven SWAP, repeated $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$1, and GHZ decay experiments into a $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$2-dimensional vector (Ma et al., 10 Jun 2026). After standardization and PCA to $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$3 dimensions, classification uses class-conditional Mahalanobis distance,
$A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$4
and a claimed-device confidence
$A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$5
On three superconducting processors over a chronological $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$6 split spanning roughly three weeks, the method achieved $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$7 benign accuracy on $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$8 test samples and established per-device alert thresholds $A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),$9, 0, and 1 based on the 2th percentile of the benign confidence distribution (Ma et al., 10 Jun 2026). In this framework, tampering means hardware substitution, suspicious drift, or adversarial manipulation of returned measurement statistics. A sample is Safe if 3, Warning if 4, and Error if 5 (Ma et al., 10 Jun 2026). This is not tamper evidence for quantum messages, but a behavioral authentication layer for cloud hardware.
5. Model-integrity and data-integrity variants outside quantum hardware
Some recent work broadens “quantum tamper detection” to include quantum-inspired monitoring of classical AI models or quantum-kernel methods applied to tampered data. In a medical LLM setting, quantum gradient descent is used as a monitoring mechanism for malicious parameter modification rather than for optimization (Hai et al., 23 Jun 2025). Model parameters 6 are encoded into a simulated quantum circuit 7, with update rule
8
and parameter-shift approximation
9
The system logs simulated weight amplitude distributions in a quantum gradient ledger and compares later amplitude patterns against trusted history using a conceptually defined quantum amplitude divergence (QAD) or Q-Score (Hai et al., 23 Jun 2025). The attacks studied are adversarial fine-tuning, LoRA-based injection, and stealth gradient modification. On MIMIC, accuracy changed from $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$0 to $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$1, F1 from $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$2 to $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$3, and A1c from $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$4 to $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$5; the paper reports QAD values around $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$6 for naive fine-tuning, $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$7 for LoRA-based injection, and $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$8 for stealth-gradient tampering, with false alarms “around $\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.$9 or 0 percent in the worst cases” (Hai et al., 23 Jun 2025). Because the implementation is simulated on classical hardware and the detection statistic is underdefined, this belongs to quantum-inspired model-integrity monitoring rather than foundational quantum-security hardware (Hai et al., 23 Jun 2025).
A related but distinct healthcare study compares a hybrid quantum-kernel One-Class SVM against a classical counterpart for detecting tampering in physiological sensor data (Onim et al., 9 Feb 2025). After preprocessing, PCA reduces the data to 1 features encoded into 2 qubits using
3
followed by CNOT entanglement and classical One-Class SVM optimization (Onim et al., 9 Feb 2025). The paper reports that quantum detection accuracy for label-flipping attacks lies in the 4–5 range, including 6 versus 7 for the three-class stress dataset, but that adversarial perturbation remains difficult, with QML accuracy around 8–9 (Onim et al., 9 Feb 2025). This is best interpreted as an application of quantum machine learning to data-integrity monitoring rather than tamper detection rooted in quantum physical unclonability.
A blockchain example, QSVA, similarly uses a quantum walk over a transaction graph to find suspicious or “tampered” transactions more quickly, but the underlying signature validation remains classical (Torres et al., 20 Feb 2025). Its main search unitary is
00
with measurement time approximately
01
The work is better characterized as quantum-assisted search and ranking over transactions flagged by a classical oracle than as quantum tamper detection in the cryptographic-state sense (Torres et al., 20 Feb 2025). These broader examples illustrate how the phrase has expanded into anomaly detection for classical systems, but they remain conceptually distinct from entanglement-based seals, cryptographic tamper evidence, or quantum hardware authentication (Torres et al., 20 Feb 2025, Onim et al., 9 Feb 2025, Hai et al., 23 Jun 2025).
6. Coding-theoretic foundations and the prospect of universal quantum tamper detection
A formal coding-theoretic theory of quantum tamper detection begins with the unitary-adversary model. In Tamper Detection against Unitary Operators, an 02-qubit codeword is obtained by encoding a 03-qubit message into a Haar-random 04-dimensional subspace of 05, with 06 and 07 (Boddu et al., 2021). A unitary adversary applies 08, and the decoder projects onto the code subspace, rejecting if the state lands outside it. For classical messages, the paper proves existence of 09-tamper secure schemes for adversarial families of size up to
10
for 11, provided each 12 satisfies
13
with 14 (Boddu et al., 2021). For quantum messages the analogous random-coding theorem holds with an additional 15 slack term (Boddu et al., 2021). The trace condition is the quantum analogue of excluding classical tampering functions with too many fixed points: unitary tampering too close to the identity cannot be strongly detected.
More recent work generalizes beyond unitary families to arbitrary quantum maps. Towards Universal Quantum Tamper Detection gives the first Haar-random coding theorem for tamper detection against arbitrary CPTP maps, under quantitative restrictions on family size, Kraus rank, and entanglement fidelity (Broadbent et al., 16 Sep 2025). Its significance is twofold. First, it aligns the quantum theory with classical tamper-resilient coding, where arbitrary functions rather than just permutations are the natural adversaries. Second, it exhibits a separation: classically, relaxed tamper detection cannot protect even against the family of constant functions, but quantum encodings can handle the corresponding obstruction, namely replacement channels (Broadbent et al., 16 Sep 2025). This motivates the paper’s conjecture that relaxed tamper detection and non-malleable security may hold against any family of quantum maps of size up to 16 for any constant 17, yielding what the authors call universal quantum tamper detection (Broadbent et al., 16 Sep 2025). This suggests that the quantum setting is not merely a translation of classical tamper-resilient coding into Hilbert space, but an intrinsically richer regime.
A different split-state line shows that entangled code-states enable tamper detection impossible for classical or separable encodings. In On Split-State Quantum Tamper Detection and Non-Malleability, a quantum tamper-detection code against 18 satisfies
19
and the paper constructs efficient 20-split TDCs against 21 with rate 22 and error 23 (Bergamaschi et al., 2023). It also proves a black-box compiler from split-state quantum NMCs to TDCs by appending EPR traps and testing them during decoding (Bergamaschi et al., 2023). The broader implication is that entanglement across shares gives tamper-detection power unavailable classically, especially under local, LOCC, or bounded-entanglement adversaries (Bergamaschi et al., 2023).
| Regime | Protected object | Detection signal |
|---|---|---|
| Tamper-evident encryption / PoNI | Quantum ciphertext or unclonable primitive | Acceptance implies adversary state is message-independent or insufficient for recovery |
| Entanglement-based seals / tripwires | Optical path, fiber seal, monitored region | Loss of Bell-state correlations, HOM delay sensitivity, or altered Zeno/interference statistics |
| Quantum-enabled hardware authentication | RTDs, IC current maps, cloud quantum processors | Changed tunnelling spectrum, magnetic anomaly, or fingerprint-confidence drop |
| Coding-theoretic tamper detection | Quantum-encoded message or split-state codeword | Decoding rejects unless tampering acts trivially or within allowed relaxed branch |
| Quantum-inspired anomaly monitoring | Classical model weights or sensor features | Ledger divergence, kernel anomaly score, or behavioral inconsistency |
The table highlights a common misconception: “quantum tamper detection” does not denote a single universal protocol. Some papers use the term for physically unclonable or entanglement-based tamper evidence, others for coding-theoretic detection of arbitrary adversarial maps, and still others for quantum-inspired anomaly monitors layered onto classical systems (Williams et al., 2015, Lord, 2024, Broadbent et al., 16 Sep 2025, Hai et al., 23 Jun 2025).
A second misconception is that any quantum tamper-evident primitive automatically provides authentication or unclonability. The cryptographic literature explicitly disproves both implications: tamper evidence does not imply authentication and does not imply uncloneable encryption (Lord, 2024). Likewise, hardware-authentication papers often imply tamper resistance or tamper evidence without demonstrating active tamper experiments, calibrated thresholds, or rigorous false-positive analysis (Roberts et al., 2015, Lenz et al., 2024). Conversely, some formal coding results are existential and information-theoretic but are not yet operationally deployable (Boddu et al., 2021, Broadbent et al., 16 Sep 2025).
A plausible synthesis is that the field now has three mature conceptual pillars. First, quantum mechanics provides state-level tamper evidence through information–disturbance, entanglement verification, and monogamy constraints (Williams et al., 2015, Lord, 2024, Goyal et al., 7 Oct 2025). Second, quantum hardware and quantum-enabled measurement can provide physical-device tamper evidence through unique quantum-confined or quantum-sensed behavior (Roberts et al., 2015, Lenz et al., 2024). Third, quantum coding theory suggests a path toward broad tamper-detection guarantees against arbitrary quantum maps, potentially exceeding classical possibilities (Boddu et al., 2021, Bergamaschi et al., 2023, Broadbent et al., 16 Sep 2025). The present literature therefore supports a broad but technically precise view: quantum tamper detection is not one primitive but a family of methods in which quantum structure makes unauthorized access, modification, or substitution detectably inconsistent with later acceptance, authentication, or successful decoding.