---
title: Quantum Tamper Detection
url: https://www.emergentmind.com/topics/quantum-tamper-detection
type: topic
---

# Quantum Tamper Detection

Searching arXiv for the cited papers and closely related work on quantum tamper detection.
Quantum tamper detection denotes a family of techniques and security notions that use quantum states, quantum measurements, or quantum-inspired state representations to reveal unauthorized modification, interception, cloning, or substitution. Across the literature, the phrase does not refer to a single canonical mechanism. It spans at least four distinct regimes: tamper-evident communication primitives based on quantum states and entanglement; hardware-authentication and side-channel methods that exploit quantum physical effects; cloud-hardware authentication by fingerprinting raw quantum-device behavior; and formal coding-theoretic constructions that detect tampering of quantum-encoded data [2411.02742], [1508.05334], [2606.11644], [2105.04487]. A recurring theme is that quantum mechanics changes the detectability landscape because copying, extracting, or reusing quantum information often perturbs the protected object, while quantum-enhanced hardware can also expose tamper-induced physical changes that are inaccessible to ordinary classical checks [2510.06432], [1508.05258], [2402.08004].

## 1. Tamper evidence as a quantum cryptographic primitive

In quantum cryptography, tamper detection is formalized most explicitly by **quantum tamper-evident encryption**, a primitive in which a classical message is encrypted into a quantum ciphertext and decryption returns both a plaintext and an accept/reject flag [2411.02742]. The defining guarantee is not merely confidentiality. Rather, if the recipient accepts, then any adversary’s retained post-attack state should be almost message-independent, so successful acceptance certifies the absence of meaningful eavesdropping in the sense relevant to later decryption [2411.02742].

The formal machinery is built around an **augmented quantum encryption of classical messages** scheme with key generation \(K\), encryption \(E\), and decryption \(D\), where decryption outputs a message register and a flag register. The accept branch is written as \(\overline{D}\), and correctness requires that for all messages \(m\),
\[
\E_{k \gets K(\emptystring)} \bra{m} \overline{D}_k \circ E_k (m) \ket{m} \geq 1 - \epsilon.
\]
Tampering is modeled by a general attack channel
\[
A : \mc{L}(\tsf{C}) \to \mc{L}(\tsf{C} \tensor \tsf{A}),
\]
allowing the adversary both to alter the transmitted ciphertext and to retain side information [2411.02742].

The resulting tamper-evidence condition is expressed through trace distance between the adversary’s subnormalized post-acceptance states for two messages \(m,m'\):
\[
\Pr_{k \gets K(\emptystring)}\left[ \frac{1}{2} \norm{ \left( \left(\Tr_\tsf{M} \circ \overline{D}_k\right) \tensor \Id_\tsf{A} \right) \circ A \circ E_k (m - m') }_1 \leq \delta \right] \geq 1 - \delta.
\]
This means that either Bob rejects or, conditional on acceptance, the adversary has learned essentially nothing useful about the message [2411.02742].

A major structural result is that tamper evidence already implies encryption. Specifically, an \(\epsilon\)-correct \(\delta\)-tamper-evident AQECM scheme is \(\sqrt{19(\delta + \sqrt{2\epsilon})}\)-encrypting [2411.02742]. This answers the question of whether confidentiality had to be imposed separately: it does not. The same work also shows that tamper evidence is tightly related to revocation, that it can yield quantum money, and that it is strictly weaker than both authentication and uncloneable encryption [2411.02742]. This suggests that “tamper evident” is a distinct cryptographic notion rather than a synonym for stronger primitives.

A different but closely related line introduces **Proofs of No Intrusion**, in which a classical client remotely tests whether a quantum server has been hacked and whether the client’s data has been stolen, while preserving the tested quantum object [2510.06432]. There the goal is not merely to detect arbitrary disturbance, but to rule out prior extraction of enough information to recover the protected secret. The central theorem states that, assuming oblivious state preparation for coset states and fully homomorphic encryption, there exists an encryption scheme with search proofs of no intrusion [2510.06432]. This places tamper detection in a remote-storage setting where later acceptance implies that no previous attacker could have exfiltrated enough information to recover the plaintext, even if the secret key later leaks [2510.06432].

## 2. Entanglement-based seals and covert intrusion sensing

A more direct operational notion of quantum tamper detection appears in **tamper-indicating quantum seals**. In this setting the goal is not message encryption but surveillance of a physical path or boundary, typically an optical fiber traversing an unsecured region. The seal sends entangled photon pairs through a trusted-reference path and an untrusted active path, then uses Bell-state analysis to verify that the returning state is still authentically entangled [1508.05334].

The core observable is
\[
\mathcal{E} \equiv P_{h_2v_3}+P_{h_3v_2}-P_{h_2v_2}-P_{h_3v_3}.
\]
For separable states the paper proves
\[
-\frac{1}{2} \le \mathcal{E}_s \le \frac{1}{2},
\]
whereas for Bell states \(\Psi^+\) and \(\Psi^-\), \(\mathcal{E}\) reaches \(+1\) and \(-1\), respectively [1508.05334]. This yields a direct tamper-indication rule: if the observed \(\mathcal{E}\) exceeds \(1/2\), the returned state is definitely entangled, so intercept-resend spoofing cannot have reproduced the original seal state [1508.05334].

The same system also uses Hong–Ou–Mandel sensitivity to constrain redirection attacks. For delay \(t_d\), the correlation parameter is modulated by
\[
\mathcal{E}_{pe} = \Lambda\!\left(\frac{2t_d}{\Delta t}\right),
\]
with \(\Delta t \approx 8\) ps in the experiment, and a one-way path-length difference greater than about \(300\ \mu\text{m}\) drives \(|\mathcal{E}| \le 1/2\), below the entanglement-authentication threshold [1508.05334]. Using binary detection theory, the prototype achieved probability of detecting inauthentic signals greater than \(0.9999\) with false alarm probability about \(10^{-9}\) for a \(10\) s sampling interval [1508.05334]. In this regime, tamper detection is genuinely quantum: the adversary cannot counterfeit the nonlocal state that the seal authenticates.

At a very different operating point, an **Invisible Quantum Tripwire** addresses covert intrusion detection rather than authenticity of returned entanglement [1002.3362]. The intrusion event is modeled as an absorber placed in one arm of a polarization interferometer. The apparatus combines interaction-free measurement with a lossy multi-pass quantum Zeno configuration. After \(N\) passes, if an object is present, the transmission probability is
\[
p=\cos^{2N}\theta_N,
\]
while the probability that a photon actually strikes the object is
\[
P_{\rm str}=(1-\lambda)(1-\cos^{2N}\theta_N),
\]
with \(\lambda\) the engineered single-cycle loss in the detection arm [1002.3362]. The system is analyzed statistically using a Chernoff bound,
\[
P_e^{\rm max}(M)=\frac12 e^{-M C_2(p,q)},
\]
and compared against the probability that the tripwire remains undiscovered,
\[
\bar P_{\rm vis}(M)=e^{-M C_{\rm vis}}.
\]
The design goal is \(C_2(p,q) > C_{\rm vis}\), so confidence in detecting an intruder grows faster than the probability of revealing the detector [1002.3362]. This is quantum tamper detection in a surveillance sense: the “tamper” is the appearance of an intruder in a monitored optical path.

## 3. Tamper detection in quantum communication hardware

Quantum tamper detection also arises as a hardware-security problem inside quantum cryptographic systems. One strand studies how detector-side hacking attacks can be transformed into measurable statistical anomalies. In a QKD receiver with **detection randomization**, beamsplitters and extra single-photon detectors create output modes that are not deterministically accessible to an adversary using bright-light faked states [1410.0701]. For a beamsplitter with transmissivity \(t\),
\[
|1,0\rangle_{\text{in1,in2} \rightarrow \sqrt{t}\,|1,0\rangle_{\text{out1,out2} + j\sqrt{1-t}\,|0,1\rangle_{\text{out1,out2}.
\]
Under honest operation, coincidences between the paired detectors behind one beamsplitter arm should be rare:
\[
P_{AB} = P_{CD} = \left[1 - \exp(-\mu \eta t)\right]^2.
\]
Under a bright-light attack, however, both detectors in a branch can fire simultaneously or asymmetrically, leaving conspicuous fingerprints in coincidence counts and detector-balance statistics [1410.0701].

The same paper adds **active detector scrambling** against detection-efficiency-mismatch and time-shift attacks. By choosing between two HWP settings that swap which detector corresponds to which logical outcome, Bob randomizes the mapping
\[
|H\rangle_{\text{Alice} \rightarrow \cos 2\theta\,|1,0\rangle_{A,C} + \sin 2\theta\,|0,1\rangle_{A,C},
\]
\[
|V\rangle_{\text{Alice} \rightarrow \sin 2\theta\,|1,0\rangle_{A,C} + \cos 2\theta\,|0,1\rangle_{A,C}.
\]
This makes detector identity unreliable as a side channel, reducing the information leaked by timing-based mismatch attacks from about \(97\%\) to below \(2\%\) in the reported experiment [1410.0701]. The significance for tamper detection is architectural: internal receiver randomness turns externally imposed detector control into observable anomalies.

A closely related idea appears in a countermeasure based on **multi-pixel detectors**. There Bob monitors not only logical clicks but also coincidences between pixels corresponding to the same logical outcome [2010.08474]. In the simplified symmetric model,
\[
p_s = p_a P_E \sum_{\lambda} p^\lambda p_d^\lambda + (1-p_a)p_B,
\]
\[
p_c = p_a P_E \sum_{\lambda} p^\lambda (p_d^\lambda)^2 + (1-p_a)p_B^2,
\]
and the ratio
\[
r = \frac{p_c}{p_s^2}
\]
satisfies \(r=1\) in the honest limit and \(r \ge 1/P_E > 1\) under full detector-control attack [2010.08474]. The paper converts these monitored statistics into an explicit upper bound on Eve’s information:
\[
I_{E,\max} = \frac{\sqrt{P_E}\left(\sqrt{p_c}-p_s\right)}{p_s(1-\sqrt{P_E})}.
\]
Thus detector tampering becomes not only detectable but quantifiable through observed anomaly in coincidence behavior [2010.08474].

The hardware side is not limited to detectors. A source-side attack in QKD shows that an adversary can actively tamper with Alice’s semiconductor laser diode by injecting light backward into the source, violating the phase-randomization assumption central to many security proofs [1508.05258]. The attacked source no longer satisfies
\[
\rho=\int_0^{2\pi}\frac{d\theta}{2\pi}|\alpha e^{i\theta}\rangle\langle\alpha e^{i\theta}| =\sum_{n=0}^\infty \frac{e^{-|\alpha|^2}|\alpha|^{2n}{n!}|n\rangle\langle n|,
\]
and interferometric histograms shift from U-shaped to Gaussian-like, revealing that adjacent-pulse phases are no longer uniformly random [1508.05258]. The paper’s significance for tamper detection lies in showing that the source, not only the detector, must be treated as an actively tamperable component, and that ordinary high-level protocol observables may not suffice to detect such source manipulation [1508.05258].

A separate architectural proposal, **QC-TEE**, adds a tamper detection engine to trusted hardware inside a dilution refrigerator for cloud superconducting quantum computers [2308.03897]. Its main goal is confidentiality of analog control pulses rather than general execution integrity, but it explicitly includes a battery-backed tamper detection engine that monitors temperature or pressure changes and erases secrets on disturbance [2308.03897]. This is best understood as HSM-like tamper response for trusted quantum-control hardware rather than full quantum tamper detection of computations, yet it illustrates how physical tamper evidence can be embedded into quantum-computing infrastructure [2308.03897].

## 4. Hardware authentication and fingerprinting of quantum or quantum-enabled devices

Another major branch of quantum tamper detection concerns physical-device identity. In semiconductor hardware, **quantum confinement in resonant tunnelling diodes** produces device-specific tunnelling spectra that can function as unique identities [1502.06523]. Each RTD contains an InGaAs quantum well between AlAs barriers, and the confined energy levels are exponentially sensitive to nanoscale imperfections. The identity readout is the I–V characteristic, especially the resonant current peak. Across \(26\) nominally identical devices, the resonance peaks spanned approximately \(70\) mV in peak voltage and \(4\) mA in peak current, and the five most closely clustered devices still had confidence ellipses with no overlap at \(99.997\%\) confidence [1502.06523]. The paper does not implement a dedicated tamper alarm, but it explicitly argues that invasive interference would distort the nanostructure and hence the produced results, making the RTD a tamper-evident authentication primitive rather than a standalone detector [1502.06523].

In integrated circuits, the **Quantum Diamond Microscope** images the magnetic-field side channel produced by current flow, thereby localizing anomalous current activity associated with hardware Trojans [2402.08004]. The physical basis is NV-center magnetometry. Relevant performance numbers include a demonstrated spatial resolution of approximately \(10~\mu\text{m}\), a volume-normalized magnetic sensitivity of \(\sim 6.7~\mu\text{T}~\mu\text{m}^{3/2}\text{Hz}^{-1/2}\) for a \(3~\mu\text{m} \times 3~\mu\text{m} \times 10~\mu\text{m}\) voxel, and a field of view around \(3.7 \times 3.7~\text{mm}^2\) [2402.08004]. The paper’s most direct tamper-relevant demonstration is rare-event detection on an Artix-7 FPGA: the QDM could still detect ring-oscillator activity when the source was pulsed for only \(0.1\) ms during a \(20\) ms exposure, corresponding to a \(0.5\%\) duty cycle [2402.08004]. This supports its role as a forensic localization tool for post-fabrication tamper detection, especially where Trojan logic alters current distribution [2402.08004].

In cloud quantum computing, a newer approach treats the quantum processor itself as a fingerprintable physical object. **Raw-Curve Quantum Fingerprints** are built by concatenating raw statistics from Ramsey, driven SWAP, repeated \(X\), and GHZ decay experiments into a \(1468\)-dimensional vector [2606.11644]. After standardization and PCA to \(119\) dimensions, classification uses class-conditional Mahalanobis distance,
\[
D_M(z,\mu_c)=\sqrt{(z-\mu_c)^T \Sigma_c^{-1}(z-\mu_c)},
\]
and a claimed-device confidence
\[
C_{\mathrm{claimed} = 1 - \frac{D_{\mathrm{claimed}{D_{\mathrm{second}.
\]
On three superconducting processors over a chronological \(70/30\) split spanning roughly three weeks, the method achieved \(100\%\) benign accuracy on \(50\) test samples and established per-device alert thresholds \(T_{176}=0.292\), \(T_{\mathrm{LQMS}=0.729\), and \(T_{287}=0.171\) based on the \(5\)th percentile of the benign confidence distribution [2606.11644]. In this framework, tampering means hardware substitution, suspicious drift, or adversarial manipulation of returned measurement statistics. A sample is **Safe** if \(C_{\mathrm{claimed} > T_c\), **Warning** if \(0 < C_{\mathrm{claimed} < T_c\), and **Error** if \(C_{\mathrm{claimed} \le 0\) [2606.11644]. This is not tamper evidence for quantum messages, but a behavioral authentication layer for cloud hardware.

## 5. Model-integrity and data-integrity variants outside quantum hardware

Some recent work broadens “quantum tamper detection” to include **quantum-inspired** monitoring of classical AI models or quantum-kernel methods applied to tampered data. In a medical LLM setting, **quantum gradient descent** is used as a monitoring mechanism for malicious parameter modification rather than for optimization [2506.19086]. Model parameters \(\theta_t\) are encoded into a simulated quantum circuit \(U(\theta)\), with update rule
\[
\theta_{t+1} = \theta_t - \eta \nabla_Q L(\theta_t),
\]
and parameter-shift approximation
\[
\frac{\partial L}{\partial \theta_i} = \frac{L(\theta_i + s)-L(\theta_i-s)}{2s}.
\]
The system logs simulated **weight amplitude distributions** in a **quantum gradient ledger** and compares later amplitude patterns against trusted history using a conceptually defined **quantum amplitude divergence (QAD)** or **Q-Score** [2506.19086]. The attacks studied are adversarial fine-tuning, LoRA-based injection, and stealth gradient modification. On MIMIC, accuracy changed from \(89.1\) to \(88.3\), F1 from \(0.87\) to \(0.86\), and A1c from \(0.82\) to \(0.81\); the paper reports QAD values around \(0.72\) for naive fine-tuning, \(0.75\) for LoRA-based injection, and \(0.78\) for stealth-gradient tampering, with false alarms “around \(4.7\) or \(5.1\) percent in the worst cases” [2506.19086]. Because the implementation is simulated on classical hardware and the detection statistic is underdefined, this belongs to quantum-inspired model-integrity monitoring rather than foundational quantum-security hardware [2506.19086].

A related but distinct healthcare study compares a hybrid **quantum-kernel One-Class SVM** against a classical counterpart for detecting tampering in physiological sensor data [2502.05966]. After preprocessing, PCA reduces the data to \(12\) features encoded into \(6\) qubits using
\[
R_x(\theta) = e^{-i\theta X/2}, \qquad R_y(\phi) = e^{-i\phi Y/2},
\]
followed by CNOT entanglement and classical One-Class SVM optimization [2502.05966]. The paper reports that quantum detection accuracy for label-flipping attacks lies in the \(75\%\)–\(95\%\) range, including \(95.11\%\) versus \(80.75\%\) for the three-class stress dataset, but that adversarial perturbation remains difficult, with QML accuracy around \(45\%\)–\(60\%\) [2502.05966]. This is best interpreted as an application of quantum machine learning to data-integrity monitoring rather than tamper detection rooted in quantum physical unclonability.

A blockchain example, **QSVA**, similarly uses a quantum walk over a transaction graph to find suspicious or “tampered” transactions more quickly, but the underlying signature validation remains classical [2502.15023]. Its main search unitary is
\[
W_Q=\left(SQ_{1}R\right)^{2},
\]
with measurement time approximately
\[
t_Q \approx \sqrt{N/M}.
\]
The work is better characterized as quantum-assisted search and ranking over transactions flagged by a classical oracle than as quantum tamper detection in the cryptographic-state sense [2502.15023]. These broader examples illustrate how the phrase has expanded into anomaly detection for classical systems, but they remain conceptually distinct from entanglement-based seals, cryptographic tamper evidence, or quantum hardware authentication [2502.15023], [2502.05966], [2506.19086].

## 6. Coding-theoretic foundations and the prospect of universal quantum tamper detection

A formal coding-theoretic theory of quantum tamper detection begins with the unitary-adversary model. In **Tamper Detection against Unitary Operators**, an \(n\)-qubit codeword is obtained by encoding a \(k\)-qubit message into a Haar-random \(K\)-dimensional subspace of \(\mathbb{C}^{2^n}\), with \(K=2^k\) and \(N=2^n\) [2105.04487]. A unitary adversary applies \(U \in \mathcal{U}_{\mathsf{Adv}}\), and the decoder projects onto the code subspace, rejecting if the state lands outside it. For classical messages, the paper proves existence of \((K,N,\epsilon)\)-tamper secure schemes for adversarial families of size up to
\[
|\mathcal{U}_{\mathsf{Adv}| \le 2^{2^{\alpha n}
\]
for \(\alpha<1/6\), provided each \(U\) satisfies
\[
|\operatorname{Tr}(U)|\le \phi 2^n
\]
with \(\phi=\sqrt{\epsilon/(2K)}\) [2105.04487]. For quantum messages the analogous random-coding theorem holds with an additional \(\delta\) slack term [2105.04487]. The trace condition is the quantum analogue of excluding classical tampering functions with too many fixed points: unitary tampering too close to the identity cannot be strongly detected.

More recent work generalizes beyond unitary families to arbitrary quantum maps. **Towards Universal Quantum Tamper Detection** gives the first Haar-random coding theorem for tamper detection against arbitrary CPTP maps, under quantitative restrictions on family size, Kraus rank, and entanglement fidelity [2509.12986]. Its significance is twofold. First, it aligns the quantum theory with classical tamper-resilient coding, where arbitrary functions rather than just permutations are the natural adversaries. Second, it exhibits a separation: classically, relaxed tamper detection cannot protect even against the family of constant functions, but quantum encodings can handle the corresponding obstruction, namely replacement channels [2509.12986]. This motivates the paper’s conjecture that relaxed tamper detection and non-malleable security may hold against any family of quantum maps of size up to \(2^{2^{\alpha n}}\) for any constant \(\alpha < \frac12\), yielding what the authors call **universal quantum tamper detection** [2509.12986]. This suggests that the quantum setting is not merely a translation of classical tamper-resilient coding into Hilbert space, but an intrinsically richer regime.

A different split-state line shows that entangled code-states enable tamper detection impossible for classical or separable encodings. In **On Split-State Quantum Tamper Detection and Non-Malleability**, a quantum tamper-detection code against \(LO^3_{(e_1,e_2,e_3)}\) satisfies
\[
\eta_{M'\hat M}\approx_\varepsilon p_{\mathcal A}\,\sigma_{M\hat M} +(1-p_{\mathcal A})\,\bot_{M'}\otimes \sigma_{\hat M},
\]
and the paper constructs efficient \(3\)-split TDCs against \(LO^3_{\Theta(\gamma n)}\) with rate \(\frac1{11}-\gamma\) and error \(2^{-n^{\Omega(1)}}\) [2311.16009]. It also proves a black-box compiler from split-state quantum NMCs to TDCs by appending EPR traps and testing them during decoding [2311.16009]. The broader implication is that entanglement across shares gives tamper-detection power unavailable classically, especially under local, LOCC, or bounded-entanglement adversaries [2311.16009].

---

| Regime | Protected object | Detection signal |
|---|---|---|
| Tamper-evident encryption / PoNI | Quantum ciphertext or unclonable primitive | Acceptance implies adversary state is message-independent or insufficient for recovery |
| Entanglement-based seals / tripwires | Optical path, fiber seal, monitored region | Loss of Bell-state correlations, HOM delay sensitivity, or altered Zeno/interference statistics |
| Quantum-enabled hardware authentication | RTDs, IC current maps, cloud quantum processors | Changed tunnelling spectrum, magnetic anomaly, or fingerprint-confidence drop |
| Coding-theoretic tamper detection | Quantum-encoded message or split-state codeword | Decoding rejects unless tampering acts trivially or within allowed relaxed branch |
| Quantum-inspired anomaly monitoring | Classical model weights or sensor features | Ledger divergence, kernel anomaly score, or behavioral inconsistency |

The table highlights a common misconception: “quantum tamper detection” does not denote a single universal protocol. Some papers use the term for physically unclonable or entanglement-based tamper evidence, others for coding-theoretic detection of arbitrary adversarial maps, and still others for quantum-inspired anomaly monitors layered onto classical systems [1508.05334], [2411.02742], [2509.12986], [2506.19086].

A second misconception is that any quantum tamper-evident primitive automatically provides authentication or unclonability. The cryptographic literature explicitly disproves both implications: tamper evidence does not imply authentication and does not imply uncloneable encryption [2411.02742]. Likewise, hardware-authentication papers often imply tamper resistance or tamper evidence without demonstrating active tamper experiments, calibrated thresholds, or rigorous false-positive analysis [1502.06523], [2402.08004]. Conversely, some formal coding results are existential and information-theoretic but are not yet operationally deployable [2105.04487], [2509.12986].

A plausible synthesis is that the field now has three mature conceptual pillars. First, quantum mechanics provides **state-level tamper evidence** through information–disturbance, entanglement verification, and monogamy constraints [1508.05334], [2411.02742], [2510.06432]. Second, quantum hardware and quantum-enabled measurement can provide **physical-device tamper evidence** through unique quantum-confined or quantum-sensed behavior [1502.06523], [2402.08004]. Third, quantum coding theory suggests a path toward **broad tamper-detection guarantees against arbitrary quantum maps**, potentially exceeding classical possibilities [2105.04487], [2311.16009], [2509.12986]. The present literature therefore supports a broad but technically precise view: quantum tamper detection is not one primitive but a family of methods in which quantum structure makes unauthorized access, modification, or substitution detectably inconsistent with later acceptance, authentication, or successful decoding.

Source: https://www.emergentmind.com/topics/quantum-tamper-detection