arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.05831cs.CR

量子软件安全的性能指标:迈向基准评估准则

On the Figures of Merit for Quantum Software Security: Toward a Benchmarking Rubric

Badhon Rahman, Majid Haghparast, Tommi Mikkonen

AI总结:

本文针对量子软件安全未被充分衡量的问题,提出基于ISO/IEC 25010等的结构化安全性能指标集及基准评估准则,为量子软件栈安全基准评估奠定基础。

AI中文摘要:

量子软件越来越多地通过多租户和基于云的量子即服务(QaaS)栈提供。近年来的研究表明,人们对整个流程中多样化攻击向量的担忧日益增加。目前业界已形成三个成熟的性能指标支柱:规模(量子比特数)、质量(量子体积)和速度(每秒电路层操作数(CLOPS)),且已开始定义软件质量指标。然而,量子软件的安全性在很大程度上仍未被衡量。目前存在少数定量安全指标,如总变差距离(TVD)和功能损坏程度(DFC),但这些指标是为单个电路混淆技术临时引入的,彼此不兼容。本文认为量子软件的安全性应与性能受到同等重视,需明确一套安全性能指标(S-FoMs)。本文研究分为三部分:(i)描述三层测量缺口;(ii)提出一套结构化的S-FoM集,按ISO/IEC 25010安全子特性、QaaS流程映射和测量成熟度组织;(iii)定义一个基准评估准则,将S-FoMs归一化并聚合为综合量子软件安全态势(QSSP)得分。此外,本文还对已发表的混淆技术进行了说明性再分析,旨在为量子软件栈(QSS)的安全感知基准评估迈出第一步。

英文摘要:

Quantum software is increasingly provided through multi-tenant and cloud-based Quantum-as-a-Service (QaaS) stacks. A growing concern about the diverse attack vectors across the pipeline has been demonstrated in recent research. Yet the community has converged on three mature pillars: Scale (Qubit Count), Quality (Quantum Volume), and Speed (Circuit Layer Operations per Second (CLOPS)) for the merit performance figures. Moreover, it has also begun to define software-quality metrics. However, the security of quantum software remains largely unmeasured. A few quantitative security indicators, such as Total Variation Distance (TVD) and Degree of Functional Corruption (DFC), exist. Although they were introduced ad hoc for individual circuit obfuscation techniques, they are incompatible. We assert that the security of quantum software deserves the same attention as the performance: an explicit set of Security Figures of Merit (S-FoMs). The research of this paper is threefold: (i) characterizes a three-layer measurement gap, (ii) proposes a structured S-FoM set organized by ISO/IEC 25010 security sub-characteristics, QaaS pipeline mapping, and measurement maturity, and (iii) defines a benchmarking rubric that normalizes and aggregates S-FoMs into a combined Quantum Software Security Posture (QSSP) score. Additionally, an illustrative reanalysis of published obfuscation techniques has been presented. Our aim is a first step toward security-aware benchmarking of the Quantum Software Stack (QSS).

补充信息

↑