{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:09:40Z","timestamp":1778256580634,"version":"3.51.4"},"reference-count":21,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2022,6,22]],"date-time":"2022-06-22T00:00:00Z","timestamp":1655856000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,6,22]],"date-time":"2022-06-22T00:00:00Z","timestamp":1655856000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Einstein Research Unit"},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["418294583"],"award-info":[{"award-number":["418294583"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006764","name":"Technische Universit\u00e4t Berlin","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100006764","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Quantum Mach. Intell."],"published-print":{"date-parts":[[2022,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Physical unclonable functions (PUFs) have been proposed as a way to identify and authenticate electronic devices. Recently, several ideas have been presented to that aim to achieve the same for quantum devices. Some of these constructions apply single-qubit gates in order to provide a secure fingerprint of the quantum device. In this work, we formalize the class of <jats:italic>classical readout quantum PUFs<\/jats:italic> (CR-QPUFs) using the <jats:italic>statistical query<\/jats:italic> (SQ) model and explicitly show insufficient security for CR-QPUFs based on single-qubit rotation gates, when the adversary has SQ access to the CR-QPUF. We demonstrate how a malicious party can learn the CR-QPUF characteristics and forge the signature of a quantum device through a modelling attack using a simple regression of low-degree polynomials. The proposed modelling attack was successfully implemented in a real-world scenario on real IBM Q quantum machines. We thoroughly discuss the prospects and problems of CR-QPUFs where quantum device imperfections are used as a secure fingerprint.<\/jats:p>","DOI":"10.1007\/s42484-022-00073-1","type":"journal-article","created":{"date-parts":[[2022,6,22]],"date-time":"2022-06-22T08:14:23Z","timestamp":1655885663000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Learning classical readout quantum PUFs based on single-qubit gates"],"prefix":"10.1007","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2549-7821","authenticated-orcid":false,"given":"Niklas","family":"Pirnay","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anna","family":"Pappa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean-Pierre","family":"Seifert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,6,22]]},"reference":[{"key":"73_CR1","doi-asserted-by":"publisher","unstructured":"Altepeter JB, Branning D, Jeffrey E, Wei TC, Kwiat PG, Thew RT, O\u2019Brien JL, Nielsen MA, White AG (2003) Ancilla-assisted quantum process tomography. Phys Rev Lett 90. https:\/\/doi.org\/10.1103\/physrevlett.90.193601","DOI":"10.1103\/physrevlett.90.193601"},{"key":"73_CR2","doi-asserted-by":"publisher","first-page":"475","DOI":"10.22331\/q-2021-06-15-475","volume":"5","author":"M Arapinis","year":"2021","unstructured":"Arapinis M, Delavar M, Doosti M, Kashefi E (2021) Quantum Physical Unclonable Functions: Possibilities and Impossibilities. Quantum 5:475","journal-title":"Quantum"},{"key":"73_CR3","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/BF02698830","volume":"90","author":"I Benjamini","year":"1999","unstructured":"Benjamini I, Kalai G, Schramm O (1999) Noise sensitivity of boolean functions and applications to percolation. Publications Math\u00e9matiques de l\u2019Institut des Hautes \u00c9tudes Scientifiques 90:5\u201343. https:\/\/doi.org\/10.1007\/BF02698830","journal-title":"Publications Math\u00e9matiques de l\u2019Institut des Hautes \u00c9tudes Scientifiques"},{"key":"73_CR4","doi-asserted-by":"publisher","first-page":"506","DOI":"10.1145\/792538.792543","volume":"50","author":"A Blum","year":"2003","unstructured":"Blum A, Kalai A, Wasserman H (2003) Noise-tolerant learning, the parity problem, and the statistical query model. J ACM 50:506\u2013519. https:\/\/doi.org\/10.1145\/792538.792543","journal-title":"J ACM"},{"key":"73_CR5","doi-asserted-by":"publisher","unstructured":"Brzuska C, Fischlin M, Schr\u00f6der H, Katzenbeisser S (2011) Physically uncloneable functions in the universal composition framework. In: Rogaway P (ed.) Adv. Cryptology. Springer, Berlin, pp. 51\u201370. https:\/\/doi.org\/10.1007\/978-3-642-22792-9_4","DOI":"10.1007\/978-3-642-22792-9_4"},{"key":"73_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3484197","volume":"2","author":"M Doosti","year":"2021","unstructured":"Doosti M, Kumar N, Delavar M, Kashefi E (2021) Client-server identification protocols with quantum puf. ACM Trans Quantum Comput 2:1\u201340. https:\/\/doi.org\/10.1145\/3484197","journal-title":"ACM Trans Quantum Comput"},{"key":"73_CR7","doi-asserted-by":"publisher","DOI":"10.1515\/9783110477597","author":"D Feng","year":"2017","unstructured":"Feng D (2017) Trusted Computing: Principles and Applications. De Gruyter, Berlin, Boston. https:\/\/doi.org\/10.1515\/9783110477597","journal-title":"De Gruyter, Berlin, Boston."},{"key":"73_CR8","doi-asserted-by":"crossref","unstructured":"Gollakota A, Liang D (2021) On the hardness of pac-learning stabilizer states with noise. arXiv preprint arXiv:2102.05174","DOI":"10.22331\/q-2022-02-02-640"},{"key":"73_CR9","unstructured":"Hinsche M, Ioannou M, Nietner A, Haferkamp J, Quek Y, Hangleiter D, Seifert JP, Eisert J, Sweke R (2021) Learnability of the output distributions of local quantum circuits. arXiv preprint arXiv:2110.05517"},{"key":"73_CR10","doi-asserted-by":"publisher","first-page":"3543","DOI":"10.1038\/srep03543","volume":"3","author":"R Horstmeyer","year":"2013","unstructured":"Horstmeyer R, Judkewitz B, Vellekoop IM, Assawaworrarit S, Yang C (2013) Physical key-protected one-time pad. Scientific Reports 3:3543. https:\/\/doi.org\/10.1038\/srep03543","journal-title":"Physical key-protected one-time pad. Scientific Reports"},{"key":"73_CR11","doi-asserted-by":"publisher","unstructured":"Kalai G (2020) The argument against quantum computers. Springer International Publishing, Cham, pp. 399\u2013422. https:\/\/doi.org\/10.1007\/978-3-030-34316-3_18","DOI":"10.1007\/978-3-030-34316-3_18"},{"key":"73_CR12","doi-asserted-by":"publisher","first-page":"983","DOI":"10.1145\/293347.293351","volume":"45","author":"M Kearns","year":"1998","unstructured":"Kearns M (1998) Efficient noise-tolerant learning from statistical queries. J ACM 45:983\u20131006. https:\/\/doi.org\/10.1145\/293347.293351","journal-title":"J ACM"},{"key":"73_CR13","doi-asserted-by":"publisher","unstructured":"Maes R (2013) Physically Unclonable Functions - Constructions. Springer, Berlin, Properties and Applications. https:\/\/doi.org\/10.1007\/978-3-642-41395-7","DOI":"10.1007\/978-3-642-41395-7"},{"key":"73_CR14","doi-asserted-by":"publisher","unstructured":"Mohseni M, Rezakhani AT, Lidar DA (2008) Quantum-process tomography: Resource analysis of different strategies. Phys Rev A 77. https:\/\/doi.org\/10.1103\/physreva.77.032322","DOI":"10.1103\/physreva.77.032322"},{"key":"73_CR15","doi-asserted-by":"publisher","first-page":"289","DOI":"10.3390\/photonics8070289","volume":"8","author":"GM Nikolopoulos","year":"2021","unstructured":"Nikolopoulos GM (2021) Remote Quantum-Safe Authentication of Entities with Physical Unclonable Functions. Photonics 8:289. https:\/\/doi.org\/10.3390\/photonics8070289","journal-title":"Photonics"},{"key":"73_CR16","doi-asserted-by":"publisher","first-page":"2026","DOI":"10.1126\/science.1074376","volume":"297","author":"R Pappu","year":"2002","unstructured":"Pappu R, Recht B, Taylor J, Gershenfeld N (2002) Physical one-way functions. Science 297:2026\u20132030. https:\/\/doi.org\/10.1126\/science.1074376","journal-title":"Science"},{"key":"73_CR17","doi-asserted-by":"publisher","first-page":"2825","DOI":"10.5555\/1953048.2078195","volume":"12","author":"F Pedregosa","year":"2011","unstructured":"Pedregosa F, Varoquaux G, Gramfort A, Michel V, Thirion B, Grisel O, Blondel M, Prettenhofer P, Weiss R, Dubourg V, Vanderplas J, Passos A, Cournapeau D, Brucher M, Perrot M, Duchesnay E (2011) Scikit-learn: Machine learning in Python. J Mach Learn Res 12:2825\u20132830. https:\/\/doi.org\/10.5555\/1953048.2078195","journal-title":"J Mach Learn Res"},{"key":"73_CR18","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1109\/JETCAS.2021.3077024","volume":"11","author":"K Phalak","year":"2021","unstructured":"Phalak K, Saki AA, Alam M, Topaloglu RO, Ghosh S (2021) Quantum puf for security and trust in quantum computing. IEEE J Emerging Sel Top Circuits Syst 11:333\u2013342. https:\/\/doi.org\/10.1109\/JETCAS.2021.3077024","journal-title":"IEEE J Emerging Sel Top Circuits Syst"},{"key":"73_CR19","doi-asserted-by":"publisher","unstructured":"Preskill J (2018) Quantum Computing in the NISQ era and beyond. Quantum 2:79. https:\/\/doi.org\/10.22331\/q-2018-08-06-79","DOI":"10.22331\/q-2018-08-06-79"},{"key":"73_CR20","doi-asserted-by":"publisher","unstructured":"Regev O, Schiff L (2008) Impossibility of a quantum speed-up with a faulty oracle. In: Aceto L, Damg\u00e5rd I, Goldberg LA, Halld\u00f3rsson MM, Ing\u00f3lfsd\u00f3ttir A, Walukiewicz I (eds.) Automata, Languages and Programming. Springer, Berlin, pp. 773\u2013781. https:\/\/doi.org\/10.1007\/978-3-540-70575-8_63","DOI":"10.1007\/978-3-540-70575-8_63"},{"key":"73_CR21","doi-asserted-by":"publisher","first-page":"1250001","DOI":"10.1142\/S0219749912500013","volume":"10","author":"B \u0160kori\u0107","year":"2012","unstructured":"\u0160kori\u0107 B (2012) Quantum readout of physical unclonable functions. Int J Quantum Inf 10:1250001. https:\/\/doi.org\/10.1142\/S0219749912500013","journal-title":"Int J Quantum Inf"}],"container-title":["Quantum Machine Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42484-022-00073-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42484-022-00073-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42484-022-00073-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,23]],"date-time":"2022-12-23T21:10:05Z","timestamp":1671829805000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42484-022-00073-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,22]]},"references-count":21,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,12]]}},"alternative-id":["73"],"URL":"https:\/\/doi.org\/10.1007\/s42484-022-00073-1","relation":{},"ISSN":["2524-4906","2524-4914"],"issn-type":[{"value":"2524-4906","type":"print"},{"value":"2524-4914","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,22]]},"assertion":[{"value":"15 December 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 May 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 June 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no competing interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"14"}}