{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T21:46:01Z","timestamp":1775771161427,"version":"3.50.1"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T00:00:00Z","timestamp":1756512000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T00:00:00Z","timestamp":1756512000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,8,30]]},"DOI":"10.1109\/qce65121.2025.00183","type":"proceedings-article","created":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T18:22:51Z","timestamp":1764613371000},"page":"1653-1664","source":"Crossref","is-referenced-by-count":4,"title":["Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security"],"prefix":"10.1109","author":[{"given":"Pascal","family":"Debus","sequence":"first","affiliation":[{"name":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maximilian","family":"Wendlinger","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kilian","family":"Tscharke","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Applied and Integrated Security (AISEC),Garching near Munich,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Herr","sequence":"additional","affiliation":[{"name":"d-fine (GmbH),Frankfurt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cedric","family":"Br\u00fcgmann","sequence":"additional","affiliation":[{"name":"d-fine (GmbH),Frankfurt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel Ohl","family":"De Mello","sequence":"additional","affiliation":[{"name":"d-fine (GmbH),Frankfurt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juris","family":"Ulmanis","sequence":"additional","affiliation":[{"name":"Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Erhard","sequence":"additional","affiliation":[{"name":"Alpine Quantum Technologies (AQT) GmbH,Innsbruck,Austria"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arthur","family":"Schmidt","sequence":"additional","affiliation":[{"name":"Federal Office for Information Security (BSI),Bonn,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabian","family":"Petsch","sequence":"additional","affiliation":[{"name":"Federal Office for Information Security (BSI),Bonn,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ETS50041.2021.9465397"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ISQED51717.2021.9424258"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/qce60285.2024.00173"},{"key":"ref4","article-title":"Security Aspects of Quantum Machine Learning","author":"Franco","year":"2025","journal-title":"en, Federal Office for Information Security"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2024.i2.735-768"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623118"},{"key":"ref7","article-title":"Quantum Leak: Timing Side-Channel Attacks on Cloud-Based Quantum Services","author":"Lu","year":"2024","journal-title":"arXiv"},{"key":"ref8","article-title":"SWAP Attack: Stealthy SideChannel Attack on Multi-Tenant Quantum Cloud System","author":"Lee","year":"2025","journal-title":"arXiv"},{"key":"ref9","article-title":"Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ Computers","author":"Choudhury","year":"2024","journal-title":"arXiv"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2965016"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref12","first-page":"1689","article-title":"Is Feature Selection Secure against Training Data Poisoning?","volume-title":"Proceedings of the 32nd International Conference on Machine Learning","volume":"37","author":"Xiao"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-098-7-870"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevA.101.062331"},{"key":"ref15","article-title":"Explaining and Harnessing Adversarial Examples","author":"Goodfellow","year":"2015","journal-title":"arXiv"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevResearch.2.033212"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1038\/s43588-022-00351-9"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevResearch.5.023186"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/QCE60285.2024.00171"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevResearch.3.023153"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.34133\/icomputing.0100"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevResearch.6.023020"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-018-07090-4"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1103\/physrevresearch.6.043326"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-81685-8_7"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1038\/s41534-021-00410-5"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3370748.3406570"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1002\/qute.202500009"},{"key":"ref30","article-title":"Shuttle Exploiting Attacks and Their Defenses in Trapped-Ion Quantum Computers","author":"Saki","year":"2021","journal-title":"arXiv"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/HOST54066.2022.9840181"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/VTS52500.2021.9794194"},{"key":"ref33","article-title":"Qubit sensing: A new attack model for multi-programming quantum computing","author":"Saki","year":"2021","journal-title":"arXiv"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096293"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/QCE57702.2023.00124"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2020.3032630"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/QCE49297.2020.00051"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2022.3202204"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1103\/3q71-y8cf"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/QCE57702.2023.00123"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3505253.3505260"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN60899.2024.10651540"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref44","article-title":"Label-Only Membership Inference Attacks","author":"Choquette-Choo","journal-title":"arXiv"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3274471"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.23"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2023.3272904"},{"key":"ref48","article-title":"Prospects of Privacy Advantage in Quantum Machine Learning","author":"Heredge","year":"2024","journal-title":"Version Number: 2"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623108"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-022-24082-z"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1093\/nsr\/nwab130"}],"event":{"name":"2025 IEEE International Conference on Quantum Computing and Engineering (QCE)","location":"Albuquerque, NM, USA","start":{"date-parts":[[2025,8,30]]},"end":{"date-parts":[[2025,9,5]]}},"container-title":["2025 IEEE International Conference on Quantum Computing and Engineering (QCE)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11249812\/11249813\/11250140.pdf?arnumber=11250140","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T06:32:06Z","timestamp":1764657126000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11250140\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,30]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/qce65121.2025.00183","relation":{},"subject":[],"published":{"date-parts":[[2025,8,30]]}}}