Universal Quantum Tamper Detection
- Universal quantum tamper detection is a suite of methods that identify unauthorized modifications to quantum data by flagging, rejecting, or evidencing tampering.
- It encompasses keyless coding, split-state cryptography, and physical sealing techniques to secure quantum ciphertexts, control processes, and network resources.
- The approaches provide quantified detection delays and error bounds, offering robust security even against sophisticated quantum tampering attacks.
Universal quantum tamper detection denotes a family of techniques for ensuring that unauthorized modification of quantum data, quantum ciphertexts, quantum control processes, or quantum-network resources is either rejected, flagged, or detected with bounded delay. Across the literature, the phrase is used in several nonidentical senses: keyless tamper-detection codes against large families of quantum maps, split-state cryptographic tamper detection and non-malleability, tamper-evident encryption, sequential changepoint detection, hardware-native gate certification, and physical tamper-indicating seals. Taken together, these works suggest that “universal” is model-relative rather than absolute: it may refer to universality over tampering families, over unknown post-change states, over monitored observables, over document types, or over a universal gate set, but not to a single attack model that subsumes all others (Boddu et al., 2021, Broadbent et al., 16 Sep 2025, Bergamaschi et al., 2023, Lord, 2024, Grootveld et al., 3 Feb 2026, Zecchin et al., 12 Feb 2026, Campbell, 2020).
1. Foundational notions and security targets
A central distinction in the area is between tamper detection, relaxed tamper detection, non-malleability, and tamper evidence. In a keyless coding formulation against unitary tampering, an encoder and decoder satisfy perfect completeness, while security requires that for every message and every allowed unitary ,
A relaxed variant allows either rejection or recovery of the original message, replacing -only soundness by
This distinction is fundamental because maps close to the identity cannot be forced to cause rejection with high probability, but they can be treated as benign in the relaxed sense (Boddu et al., 2021).
In split-state quantum coding, tamper detection is defined on entangled messages and side information. A quantum tamper-detection code requires the decoded state to be close to an ideal form
where depends only on the adversary and not on the input state. Quantum non-malleability weakens this by allowing the replacement branch to be an unrelated state instead of a reject flag. The distinction is sharper than in the classical setting because the ideal channel is defined relative to an external purifying reference (Bergamaschi et al., 2023).
A different but related notion is quantum tamper-evident encryption for classical messages encoded into quantum ciphertexts. There the core requirement is conditioned on honest acceptance: after an arbitrary ciphertext attack , the adversary’s postselected side information must be nearly independent of which plaintext was encrypted. This notion is formalized for augmented quantum encryption of classical messages, and it sits strictly between stronger authentication-style notions and weaker secrecy-only notions (Lord, 2024).
These definitions already show that the field has no single universal criterion. Some formulations ask for rejection after tampering, some permit unchanged outputs, some focus on side-information suppression conditioned on acceptance, and others optimize detection delay subject to false-alarm constraints. The literature therefore treats “universal quantum tamper detection” as a family of security goals rather than a single canonical primitive.
2. Cryptographic constructions, reductions, and document-level integrity
The most developed constructive theory appears in split-state models. A quantum code is given by CPTP maps
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$
with adversaries acting locally on shares. The main classes studied are unentangled local operations 0, bounded-entanglement variants 1, and 2, modeled through transcript-conditioned local CP maps. Within these resource-restricted split-state settings, the literature gives several generic reductions and explicit constructions that are impossible classically (Bergamaschi et al., 2023).
A key reduction converts a 3-split non-malleable code into a 4-split tamper-detection code by appending 5 EPR pairs and testing the recovered halves with a Bell/EPR measurement. If the underlying non-malleable code has error 6, the resulting tamper-detection code has error 7. In the bounded-entanglement setting, an augmented non-malleability notion yields a corresponding reduction with error 8. These reductions are operationally significant because tamper detection is obtained from an entanglement-verification layer placed on top of non-malleable decoding (Bergamaschi et al., 2023).
The same work gives explicit constructions. Its flagship result is an efficient 3-split tamper-detection code against 9 with blocklength 0, rate
1
and error
2
It also provides a single-bit 3 non-malleable code with error 4, and an efficient 4-split 5 non-malleable code with rate 6 and error 7. Secret-sharing compilers inherit corresponding tamper-detection and non-malleability guarantees, including a 8 secret sharing scheme that is 9-tamper detecting with
0
The same paper also proves that every share of a split-state quantum tamper-detection code must be individually encrypted, with reduced density matrices 1-close to message-independent states (Bergamaschi et al., 2023).
Tamper-evident encryption establishes another reduction-rich branch of the subject. In that setting, tamper evidence implies classical-message encryption: an 2-correct, 3-tamper-evident scheme is
4
-encrypting. The same formalism yields generic conversions between tamper evidence and revocation/certified deletion, and supports a private-key quantum-money construction from any tamper-evident scheme, provided verification checks both acceptance and correct message recovery (Lord, 2024). This makes tamper evidence a structurally central primitive, even though it does not imply authentication or uncloneability.
Document-level tamper detection is realized most directly by information-theoretically secure quantum timestamping. That protocol combines a quantum key generation stage with one-time universal hashing and one-time-pad protection of the digest and hash-function seed. For a document bitstring 5, the LFSR-based Toeplitz hash is
6
with collision probability
7
The file-verification tampering probability is
8
the timestamp-verification tampering probability is
9
and the overall composable security bound is
0
Because the mechanism hashes arbitrarily long documents before authentication, it functions as a tamper-detection primitive for arbitrary digital files. Simulations reported a generation rate exceeding 100 timestamps per second over intercity distances, using only weak coherent states (Li et al., 20 May 2025).
3. Large tampering families and the route toward universality over quantum maps
The first keyless large-family results treated unitary tampering families. A Haar-random isometry 1 defines a random subspace code, and the decoder checks whether the received state remains in that subspace. For adversarial families 2, the main structural conditions are
3
and
4
Under these assumptions, strong tamper detection is proved for classical and quantum messages. For classical messages, the theorem requires
5
and for quantum messages a corresponding net argument yields a 6-secure code with
7
A relaxed classical result drops the trace restriction and allows arbitrary unitary families of the allowed size, and the same framework yields classical non-malleable codes as a corollary (Boddu et al., 2021).
That theory has now been extended from unitary families to arbitrary CPTP maps. Haar-random encodings are shown to achieve negligible soundness error against any family 8 satisfying three natural constraints: 9 with
0
Here 1 is the maximal Choi rank over the family, and
2
is the entanglement fidelity. These parameters are the direct quantum analogues of the classical “far from constant” and “far from identity” conditions: low Kraus rank controls constant-like concentration, while low entanglement fidelity excludes identity-like behavior (Broadbent et al., 16 Sep 2025).
This channel-level theorem unifies the earlier classical and unitary-only results. For a classical function 3, the associated CPTP map 4 satisfies
5
so the quantum Kraus-rank restriction becomes the classical high-output-min-entropy condition. For a unitary channel induced by 6,
7
so the entanglement-fidelity restriction becomes the earlier trace-overlap restriction. The theorem also extends to quantum messages, at the cost of an 8-net and an additive 9 term in the soundness parameter (Broadbent et al., 16 Sep 2025).
The same work supplies the most explicit evidence for a genuine quantum-classical separation. Classically, relaxed tamper detection cannot handle the family of all constant functions, which already has size 0. Quantumly, a Hadamard-based encoding
1
achieves relaxed tamper detection against every classical constant function when 2, because every wrong non-3 decoding has probability at most
4
The paper further proves tamper detection against arbitrary finite families of replacement channels of size up to 5 for any 6 (Broadbent et al., 16 Sep 2025).
These results culminate in a conjecture rather than a theorem: for relaxed tamper detection, there may exist quantum codes against any family of CPTP maps of size up to
7
with negligible error and constant expansion. In the current literature, that conjecture is the most precise statement of “universal quantum tamper detection” in the large-family, keyless sense (Broadbent et al., 16 Sep 2025).
4. Sequential detection and observable-based monitoring
A separate line of work treats tampering as a change-detection problem. In the state-based quickest-detection model, a source emits
8
with known pre-change state 9 and unknown post-change state 0, so that
1
The stopping rule 2 is optimized under a mean-time-to-false-alarm constraint 3, and the minimax delay criterion is Lorden’s worst average detection delay. The fundamental converse is governed by the quantum relative entropy
4
with lower bound
5
for finite 6 (Grootveld et al., 3 Feb 2026).
The constructive solution is a two-stage reduction. First, a block PVM 7, depending only on the known nominal state 8, converts 9 and 0 into classical distributions 1 and 2 with asymptotically preserved information rate: 3 Second, the measured sequence is processed by the classical universal NWLA-CUSUM procedure with window size
4
The resulting stopping rule achieves
5
which is first-order asymptotically optimal (Grootveld et al., 3 Feb 2026). In tamper-detection language, this is universal because the changed state 6 is not known in advance.
A more flexible version replaces state-based hypotheses by observable constraints. A sequence of 7-qubit states undergoes a changepoint from 8 to 9, where
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$0
Measurement is performed by classical shadows, either with local Clifford or joint Clifford unitaries, producing unbiased estimators
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$1
The detector then forms e-processes
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$2
aggregates them as
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$3
and stops at
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$4
This yields the finite-sample guarantee
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$5
together with asymptotic delay law
$\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$6
where $\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$7 is the best post-change growth rate over the monitored observables (Zecchin et al., 12 Feb 2026). This is universal in a different sense: the measurement device is agnostic to the choice of observables, and the same shadow stream can later support multiple tamper signatures.
5. Physical, network, and hardware-native embodiments
At the hardware level, tamper detection is often realized as fault detectability embedded in the physical implementation. Certified quantum gates use additional long-lived internal states already present in trapped-ion hardware, without adding physical qubits. Each transfer step moves amplitude from a source subspace $\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$8 to a target subspace $\Enc:\mathcal L(\mathcal H_M)\to \mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t}), \qquad \Dec:\mathcal L(\mathcal H_{X_1}\otimes\cdots\otimes \mathcal H_{X_t})\to \mathcal L(\mathcal H_{M'}),$9, then irreversibly pumps any residual source population into a bright flag state. For a pulse-area error 00, the flag probability is
01
and conditioned on no flag the modeled transfer error is removed. The paper implements this logic for arbitrary single-qubit rotations and a Cirac–Zoller 02, thereby augmenting a universal gate set with certification against certain common-mode amplitude errors, addressing errors, and some entangling-gate pulse-area errors. The total success probability for a certified single-qubit gate is
03
This is not arbitrary adversarial tamper detection, but it is an important example of platform-native, irreversible fault flagging in a universal gate set (Campbell, 2020).
A more direct physical tamper-indicating device is the entanglement-based quantum seal. There the verifier estimates
04
which satisfies
05
for all separable states, while 06 gives 07. This lets the seal detect intercept-resend spoofing through entanglement loss and bound redirection attacks through Hong–Ou–Mandel sensitivity to path-length changes. In the reported fiber testbed, the probability of detecting inauthentic signals exceeded 08 with false alarm chance 09 for a 10 second sampling interval, and the tolerable path-length change was limited to sub-millimeter disturbances (Williams et al., 2015).
In quantum networks, tamper detection can be reduced to entanglement survival in stored Bell pairs. A trusted Verifier and potentially compromised Prover share Bell states, and local-operations-and-classical-communication protocols test whether those pairs remain entangled. The AC1 protocol achieves
10
while AC2 achieves
11
Under the computational/diagonal-basis attack model, AC2 detects compromise with probability 12 per round, and its one-round detection probability is always at least 13 for any basis used by the malicious Prover to destroy entanglement. This is a network-security-oriented form of tamper detection, but it only detects compromise that disturbs the stored entanglement resource (Amoretti et al., 2017).
System-level trusted execution gives yet another interpretation. A superconducting quantum computer trusted execution environment obfuscates analog control pulses with decoy pulses, then removes those decoys inside the trusted region of the dilution refrigerator. The architecture includes a tamper detection engine that monitors temperature or pressure changes and zeroizes stored secrets upon breach of the refrigerator boundary. Its central goal is execution confidentiality rather than general execution integrity; active attacks such as fault injection are explicitly left to future work. On IBM Perth, the reported variational distance between protected and unprotected circuits lay in the range 14 to 15, with depth overhead roughly 16 to 17 depending on the obfuscation level (Trochatos et al., 2023).
6. Limitations, separations, and open problems
The literature is unusually explicit about what these methods do not provide. Tamper-evident encryption implies encryption of classical messages, but it does not imply authentication, uncloneable encryption, unique valid outputs, or encryption of arbitrary quantum states. The separation results are sharp: one can build tamper-evident schemes that remain malleable, or that permit useful cloning structure, even though meaningful eavesdropping is still detectable in the formal sense (Lord, 2024).
Split-state coding is equally limited by the adversary’s nonlocal resources. With unrestricted pre-shared entanglement 18, tamper detection becomes impossible because substitution attacks can coherently replace the codeword with a valid encoded state. Positive results therefore depend essentially on restricting the adversary to 19, 20, or bounded-entanglement models (Bergamaschi et al., 2023). The same pattern reappears in large-family keyless coding: strong tamper detection excludes channels or unitaries too close to the identity, and the most ambitious CPTP-family result currently becomes a conjecture once those structural exclusions are removed (Boddu et al., 2021, Broadbent et al., 16 Sep 2025).
Sequential formulations also have clear boundaries. Quantum quickest change detection assumes i.i.d. pre- and post-change states and a known nominal 21; it does not handle fully general channel-level tampering or arbitrary temporal dependence. The observable-based shadow formulation detects only those tampering events that force at least one monitored expectation value across threshold; changes invisible to the chosen observable family can evade detection. An open extension noted in the quickest-detection literature is time evolution of the form
22
which would be more realistic for many deployed systems (Grootveld et al., 3 Feb 2026, Zecchin et al., 12 Feb 2026).
Practical deployments are further constrained by imperfect detectors. A general detector-robustness framework models dark counts and efficiency uncertainty as adversarially controlled within allowed ranges, then absorbs those imperfections into a worst-case preprocessing channel. In its most generic form, if
23
then noisy detection can be rewritten as ideal detection after a noise channel, with preserved-space weight degraded by a factor 24. For threshold detectors with independent dark counts and bounded efficiencies, this gives a rigorous way to convert partial detector characterization into worst-case soundness loss. The same framework is not yet a universal tamper detector by itself: it is a detector-imperfection reduction layer for adversarial protocols, and it does not yet encompass afterpulsing, detector dead times, or fully general correlated detector attacks (Nahar et al., 8 Mar 2025).
The most important open question remains whether relaxed quantum tamper detection can become genuinely universal over arbitrary CPTP tampering families of doubly exponential size. Current evidence comes from Haar-random coding theorems, replacement-channel results, and the disappearance of the classical constant-function obstruction in the quantum relaxed setting. A plausible implication is that quantum tamper detection may be strictly more powerful than its classical counterpart, but the full conjecture remains open (Broadbent et al., 16 Sep 2025).