Conceptio › Archive › arXiv CS
arXiv CSopen access

Coherence Rather Than Error Rate Governs Privacy in Multi-Tenant Quantum Computing

Farhad Farokhi · arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Coherence Rather Than Error Rate Governs Privacy in Multi-Tenant Quantum Computing Farhad Farokhi∗1 1

Department of Electrical and Electronic Engineering, The University of Melbourne, Australia

arXiv:2609.34411v1 [quant-ph] 28 Sep 2026

September 29, 2026

Abstract Multi-tenant computing enables providers of commercial cloud quantum processors to rent disjoint sectors of a device to independent users. Average gate error, which cloud quantum computing providers report, does not determine how much one tenant learns about another. We propose an information-theoretic notion of information leakage across co-tenancy boundaries stemming from quantum state distinguishability. We measure this leakage on commercially-available 156-qubit (IBM Kingston) and 20-qubit (IQM Garnet) devices. Boundaries with identical benchmarked error can offer significantly different amount of information leakage because standard reported measures of error are blind to coherent-versus-stochastic nature of the error while the proposed notion of information leakage is not. A uniform Pauli randomisation implemented over the victim’s whole register is used as a defence mechanism to reduce the information leakage to zero. The defence theoretically does not incur a fidelity cost, but the experiments show a non-trivial degradation caused by accumulation of errors. We provide a specific call-for-action to the providers of quantum cloud computing to report information leakage in addition to standard error rates in their device datasheet to enable users to compute privacy and security risks prior to engagement with the device.

Introduction

the relationship between degrading the neighbour’s fidelity and information leakage, but it does not quantitatively connect the two effects [10]. We ask a question that is relevant to providers of cloud quantum processors. Can a tenant compute privacy guarantees from the statistics that the provider already publishes, such as the device datasheet? The answer is no. The average gate infidelity, a statistic the providers report, does not distinguish a coherent error from a stochastic one. We show information leakage depends almost entirely on this characteristic. A low reported error rate can coincide with a large privacy leakage. Information leakage can be eliminated by the existing randomised circuit compiling techniques. The results of this paper provide a specific call-for-action: the providers of cloud quantum computing should report information leakage in addition to standard error rates in their device datasheet to enable users to compute risks of information leakage prior to engagement with the device.

Quantum processors are expensive. Cloud interfaces, where one can rent portions of quantum processors, are how most people use them. Useful circuits are small compared to the devices that run them. This motivates the providers of cloud quantum computing services to put more than one user on the same device at once [1], albeit each in a separate sector. Sharing a quantum computer, however, has a cost. Adjacent sectors are never perfectly isolated. This residual coupling, called crosstalk, is well characterised and providers already work to reduce it [2, 3]. However, crosstalk is an information hazard as well as an error term. The same mechanism that degrades a tenant’s gate fidelity, in one direction, carries information about that tenant, in the other direction, by unintentionally entangling qubits across the boundary. The information leakage has been documented. Crosstalk signatures reveal a neighbour’s gate structure and can classify their algorithm [4]. When using SWAP operations to implement gates between logically distant Results qubits, the whole chain of operations leaks information [5, 6]. Shared readout hardware also leaks informa- Setting. tion [7]. Defences based on dynamical decoupling have been proposed [8, 9]. One recent study models this leak- Threat model. The adversary is an ordinary co-tenant, age with a learned decoder and experimentally observes nothing more, i.e., it does not need privileged access. It 1

b

sector A (victim)

c Γ = C(τ )| sin(∆θ/2)|

τ

Γ→0

|x⟩

a ζ Za ⊗Zb

no gates

a

unallocated |0⟩

H

∆θ R

M

b sector B (adversary)

∆θ = 4ζτ : conditional phase written on the probe by the victim’s basis state, with no interaction initiated by the adversary

no frame

Pauli frame

Figure 1: Cross-tenant information leakage on a shared quantum processor. (a) Two tenants occupy disjoint sectors. Coupled qubits a and b in the two disjoint sectors meet across the tenant boundary, where a residual ZZ interaction of rate ζ entangles them unintentionally. (b) The victim holds a computational-basis state on a. The adversary, on b, prepares |+⟩, idles for a window τ , then measures in X and Y basis. The adversary starts no interaction and needs no special privilege beyond co-tenancy. (c) Without a defence the two conditional probe states, i.e., the states of the adversary conditioned on the content of victim’s qubit, separate by an angle ∆θ = 4ζτ , giving a distinguishability Γ = C(τ )| sin(∆θ/2)| with C(τ ) capturing the effect of decoherence on the adversary’s qubit. A randomising defence on the victim, called Pauli frame and defined formally in Result 2, collapses the distinguishability while leaving the average gate infidelity theoretically unchanged. form of an angular frequency. We quote ζ/2π in Hertz throughout. For experiments in this paper, which investigate the impact of ZZ crosstalk between the qubits, the (k) cross Hamiltonian reduces to one term with OA = Za (k) and OB = Zb , where Za , Zb denote local Pauli operators. This is depicted in Figure 1(a). Tracing the victim out of the picture gives the adx , namely B’s evolution versary’s conditional channel, EB for one fixed value of the secret x over time window of [t, t + τ ]. The conditional channel satisfies h i in(x) x in † EB (ρin ) = Tr U (t, τ )(ρ ⊗ ρ )U (t, τ ) , (3) A B B A

occupies a sector (a group of qubits) disjoint from the victim’s sector. The adversary submits its own circuits through the same cloud interface the victim uses. It can only read out its own qubits. It cannot touch, measure, or delay the victim’s qubits. It has no pulse-level or calibration-level access. It does not learn how the victim randomises its own circuits. It knows the device layout and the published calibration numbers, both public. It may hold extra qubits as ancilla states and entangle its probe state with them before the boundary interaction. We split the full register into a victim sector A, an adversary sector B, and an optional unused, unallocated buffer. Figure 1(a) depicts this in the case of our experiments. The victim holds a classical (random variable) secret x, drawn randomly from a finite set X of size M . This secret changes what the victim does, i.e., it changes the content of its qubits and/or the implemented circuit. The whole device evolves under a potentially secret-dependent Hamiltonian given by (x)

(x)

H (x) (t) = HA (t) ⊗ I + I ⊗ HB (t) + H× (t).

where ρin B is any input state the adversary chooses to in(x) prepare on its own qubits at time t, ρA is the victim’s initial state which may depend on secret x at time t, and U (t, τ ) denotes the evolution of the joint system under the Hamiltonian in Eq. (1) over the interval [t, t + τ ]. The conditional channel captures whatever happens to the adversary’s qubits as a function of the victim’s secret x due to the cross Hamiltonian. The state that x the adversary can measure is ρxB = EB (ρin B ). In the experimental hardware measurement described later, the adversary’s chosen input is ρin B = |+⟩⟨+|. The adversary ideally optimises the initial state ρin B to capture the most amount of information. Let us define conditional spread Γ between the channels as 1 x x′ EB − EB . (4) Γ ≜ max′ x,x 2 ⋄

(1)

(x)

Here, HA (t) is the victim’s own Hamiltonian acting only on A. It may depend on the secret x because the victim’s circuit can depend on the secret. The adversary’s own Hamiltonian, which only acts on B, is denoted by HB (t). It does not depend on x because the adversary’s circuit cannot depend on a secret it does not know. The boundary or cross Hamiltonian term, the only piece that connects the two sectors, is Conditional spread Γ measures the largest amount by X (x) (x) (k) (k) H× (t) = ζk (t) OA ⊗ OB , (2) which the secret x impacts the adversary’s observations by quantifying how far apart the two most different conk ditional channels sit from each other. This is different (k) (k) where OA and OB are local operators, such as Pauli from the average gate infidelity, r, a device datasheet reoperators, on the boundary qubits of A and B, re- ports, which measures the average per-gate error prob(x) spectively, and ζk is the coupling strength, taking the ability. This paper makes a case for reporting Γ to the 2

For binary secret X = {0, 1}, this can be tightened to   1 (0) (1) (7) L(A → B) = log2 1 + ∥ρB − ρB ∥1 2

public for security and privacy analysis prior to using the cloud services. This would be of utmost importance to tenants who run quantum circuits on private sensitive data, e.g., in defence or healthcare industries. We adopt a notion of information leakage based on distinguishability of the quantum states {ρxB }x∈X to measure the adversary’s performance in terms of guessing secret x gets once it looks at B. Information leakage is defined as L(A → B) ≜ log2 sup

X

{Πx } x∈X

Tr(Πx ρxB ),

using the Helstrom bound [14, 15]. If M Γ ≪ 1, which should be the case in high-performance cloud computers, L(A → B) ≃ (M − 1)Γ/ ln 2 implying that a single run of the victim’s circuit does not leak much information about the secret. However, given circuits are run several times due to hardware noise and stochastic nature of (5) most quantum computing algorithms, the leakage can add up to a significant amount.

where the supremum runs over all measurements {Πx } the adversary could perform, indexed by the secret it is guessing. The notion of information leakage (5) is the logarithm of M times the maximum success probability of distinguishing the quantum states {ρxB }x∈X under uniform prior [11]. Information leakage L(A → B) is measured in bits and sits between zero (no information gained) and log2 M (maximum amount of information that can be gained about an M -ary random variable). This is exactly the maximal quantum leakage of [12], originally defined there as the largest factor by which observing B improves the adversary’s chance of guessing any function of secret x, and shown to be equal to the Sibson mutual information of order infinity between the victim’s secret and the adversary’s measurement outcome. We use the state-discrimination form above because it is what the rest of this paper computes directly. The equivalence between the two forms is proved in [13]. This notion of information leakage needs no assumption about how likely each secret is. It is zero exactly when every ρxB is the same state since, in that case, B carries no information about x at all. Furthermore, via the connection to maximal leakage, we can see that this notion does not make any assumptions about the adversary’s intended goal, i.e., what aspect of the secret x the adversary is interested in learning. In summary, a leakage of zero bits means co-tenancy does not help the adversary in learning the secret at all. A leakage of one bit means looking can reveal the answer to a single yes-orno question about the secret perfectly. Supplementary Note 1 describes maximal leakage and its connection to distinguishability and (5) concretely.

Repetition can amplify small per-shot leakage. In quantum computing, a circuit is often run more than once. Therefore, the adversary can hold up to N copies of its conditional state. For distinguishability of quantum states, standard large-deviations theory gives an er. (N ) . ror probability Pe = e−N ξ [16], where = means equal(N ) ity of the exponential rate, limN →∞ −N −1 ln Pe = ξ. Two different values of ξ, corresponding to two different scenarios, matter here. An adversary who can measure all N copies jointly, which is only possible with access to stable quantum memory to store the states before a collective measurement, achieves ξcoll [16]. However, an adversary with no quantum memory, who must measure and discard each copy, one shot at a time, achieves ξloc = − ln(1 − Γ2 )/2 ≃ Γ2 /2 for Γ ≪ 1, which is smaller than ξcoll . This follows from the classical Chernoff bound applied to the resulting Bernoulli statistics [17] of singleshot measurements. Given the current state of quantum computers and memory (particularly the short decoherence time of qubits), the second, weaker adversary is the realistic one. The weaker adversary’s shot budget, i.e., the minimum number of measurements required, for confidence 1 − η is N∗ ≃

2 ln(1/η) . Γ2

(8)

Note that this is only an approximation as we are considering the regimes of Γ ≪ 1 and N ≫ 1. The leakage of N copies can also be written directly as X  LN (A → B) ≜ log2 sup Tr Πx ρx⊗N , (9) B {Πx } x∈X

Leakage spread.

is

controlled

by

conditional where the supremum is taken over POVMs on the N -

copy space, which permits entangled measurements. For a binary secret, by the Helstrom bound [14, 15], Supplementary Note 2 proves the following inequality   1 0⊗N relating information leakage and conditional spread. 1⊗N LN (A → B) = log2 1 + ∥ρB − ρB ∥1 . 2 Result 1. For any boundary interaction and any victim state, By the quantum Chernoff bound [16], lim L (A → N →∞

L(A → B) ≤ min{log2 M, log2 (1 + (M − 1)Γ)}.

N

B) = log2 M if and only if the states {ρxB }x∈X are pairwise distinct. Hence, even if a single circuit run leaks

(6) 3

(a)

2.0 1.5 1.0 0.5 0.0

1010

no frame Pauli frame

0.35

conditional spread Γ

2.5

phase gap Δθ (rad)

(b) no frame Pauli frame

shot budget N * (99% conf.)

3.0

0.30 0.25 0.20 0.15 0.10 0.05 0.00

0

20

40

60

idle window τ (μs)

80

100

(c) no frame Pauli frame

109 108 107 106 105 104 103 102

0

20

40

60

idle window τ (μs)

80

100

0

20

40

60

idle window τ (μs)

80

100

Figure 2: Cross-tenant information leakage measured on ibm kingston, victim q60 and adversary q61 using 4096 shots per circuit with 4 circuits used for the experiment. (a) Conditional phase gap ∆θ against idle window length τ . (b) Conditional spread Γ against idle window length τ . (c) Adversary shot budget N ∗ at 99% confidence against idle window length τ . The markers indicate experimental data. The solid line shows the theoretical relationship fitted to the experimental data. The red curve shows the results without Pauli frame defence while the blue curve shows the outcome with Pauli frame defence. scales as r−1 . This is because average gate infidelity cannot see the coherent-versus-stochastic split while conditional spread can. A privacy-relevant certificate therefore needs a measure of coherence in addition to error.

little because Γ ≪ 1, repetition weakens any such guarantee.

Average infidelity does not determine leakage.

Defence against leakage

Now, we investigate the relationship between information leakage and average gate infidelity, which is a number that the device datasheet contains. We construct two scenarios with the same average gate infidelity, but with widely different leakage. First, consider the case where the boundary interaction rotates the probe state of the adversary by angle θ for one value of the victim’s secret (e.g., x = 0) and by −θ for the other value (e.g., x = 1). In this case, 2 r = (2/3) sin√ (θ/2) and Γ = | sin θ|. Therefore, for small θ, Γ ≈ |θ| ≈ 6r. This is similar to the case we consider in our experiments. Eq. (8), in this case, gives the shot budget for confidence 1 − η at fixed r, ∗ Ncoh ≃

ln(1/η) . 3r

If leakage tracks coherence and fidelity tracks total error, a protocol that removes coherence without changing error should remove leakage without changing fidelity. This builds on the Pauli twirling used in randomised compiling, which converts coherent errors into stochastic Pauli noise and has already been demonstrated experimentally on hardware [18, 19, 20]. Therefore, the machinery this defence needs is not new. Assume that, in every run of the circuit, N the victim draws a uniform random Pauli operator P = a∈A Pa over its entire register, applies it with the matching correction after, and never reveals which P it drew. We call this random, secret, self-correcting operation a Pauli frame. A deployment tuned only for error mitigation need not keep the draw secret. However, for the adversary to not be able to infer the secret, we need to keep the draw secret. The next result, proved in Supplementary Note 3, shows that the leakage is zero with Pauli frame defence. (in)x Result 2. Assume that the victim’s input state ρA depends on secret x (so the Hamiltonian is independent of x). Under the Pauli frame described above, Γ = 0 and L(A → B) = 0. This is a quantum one-time pad on the victim’s register [21]. The proof needs no assumption on the coupling because, once the frame has erased the victim’s state, there is nothing left in A for the coupling to carry across. The frame itself is the pad’s key. Therefore, the secrecy of the draw during the observation window is a pivotal

(10)

As an alternative, consider the case where the boundary interaction perturbs the probe state of the adversary by a Pauli channel with a single-qubit Z-flip of probability p regardless of victim’s secret value. In this case, r = (2/3)p and Γ = 0. Therefore, L(A → B) = 0. No number of shots reveals anything about the secret, and the shot budget is infinite for every value of r. In contrast, the coherent boundary with the same average gate infidelity r has the finite shot budget in Eq. (10). This comparison demonstrates the paper’s central message. Two boundaries whose benchmarked average gate infidelities agree may result in vastly different information leakage, from zero to a finite shot budget that 4

a on its sector A, which is prepared in |0⟩ or |1⟩. The choice of this preparation is the secret. The adversary holds an adjacent qubit b on it sector B. It prepares |+⟩ on qubit b, idles for a window τ , and reads out a measurement in X and Y basis. The victim’s qubit is never measured by the adversary. The victim’s boundary qubit a and an adversary’s probe qubit b are coupled by a static ZZ interaction. The rate of the interaction is defined as ζ. The two conditional probe states, i.e., the probe state when the victim holds |0⟩ and the probe state when the victim holds |1⟩, are separated by phase gap ∆θ = 4ζτ . Therefore,

survival probability

0.99 0.98 0.97 0.96 0.95 no frame Pauli frame

0.94 100

101 sequence length (Cliffords)

102

Γ = C(τ ) | sin(∆θ/2)|

(11)

where C(τ ) = exp(−τ /T2 ) is a number between zero and one that falls as the probe loses coherence with increasing τ . The reason for preparing |+⟩ and the derivation of (11) are discussed in Supplementary Note 4. The procedure for experimentally measuring ∆θ and Γ is described in Supplementary Note 5. Figure 2(a) shows that the experimentally estimated ∆θ grows linearly in τ , as expected. Figure 2(b) shows Γ, which peaks at 0.35 near 60µs. This gives a fitted value for T2 equal to 73.3µs, which is of the order of the device’s reported coherence time T2 = 53.7µs. At the peak the adversary extracts L(A → B) = 0.43 bits per shot, out of one possible bit log2 M = 1. Figure 2(c) compares the predicted shot budget of Eq. (8) based on the hardware test. The markers indicate the experimental data. The solid curve shows the theoretical relationship fitted to the experimental data. In all figures, the blue curve shows the effect of a randomising defence defined formally as the Pauli frame in Result 2. The defence clearly works by massively reducing information leakage and increasing the number of shots needed to estimate the victim’s private data confidently. The suppression is paid for in fidelity. To test whether the Pauli frame defence in Result 2 costs the victim anything on its own qubit, we performed randomised benchmarking on q60 , the same victim qubit used earlier to show the success of the Pauli frame defence. A sequence of length m consists of m Cliffords drawn uniformly at random from the 24 single-qubit Cliffords, followed by one further gate computed deterministically as the exact group inverse of their combined effect, so that, under no error, a circuit initialised at |0⟩ returns exactly to |0⟩. We run two alternative scenarios of applying the gates without any defence and with the Pauli frame defence. For the latter, a random Pauli operator is applied before each gate and corrected for after every gate in the sequence. Both runs accumulate the same net Clifford and differ only in the Pauli frame’s overhead. Survival probability is the fraction of the runs that initialised at |0⟩ returned to |0⟩. Figure 3 shows the survival probability as a function of number of randomly drawn Cliffords. The defence impacts the survival probability by a non-trivial

Figure 3: Randomised benchmarking on victim qubit q60 on ibm kingston. Survival probability against the number of random single-qubit Clifford gates chained together before the sequence-ending inverse gate demonstrates that the Pauli frame defence non-trivially degrades the victim circuit. assumption. The defence protects a tenant against a co-tenant, not against a provider that can read the submitted circuit directly. A cheaper version of the Pauli frame that only implements the random Pauli operator on boundary qubits ∂A, rather than the whole register A, does not work. A randomisation confined to ∂A only perturbs the boundary qubits at the start of the circuit run. However, during the operation of victim’s own circuit, the content of some of the non-boundary qubits can move onto the boundary and leak private information. Result 2 assumes that the Hamiltonian does not (x) depend on the secret. However, the couplings ζk (t) can themselves depend on the secret x. The following result provides when the leakage can be zero in this case. The following result immediately follows from Result 1. x′ x = EB for every pair Result 3. L(A → B) = 0 if EB x, x′ , i.e., the adversary’s conditional channel remains the same regardless of the secret. This is the criterion a provider should actually certify. Result 2 gives one way to guarantee it for scenarios in which the secret is only embedded in the victim’s state, and not the Hamiltonian.

Experimental measurement of the attack. We demonstrate the potential for information leakage on ibm kingston, a 156-qubit superconducting noisy intermediate-scale quantum (NISQ) processor (IBM Heron r2). We subsequently verify the information leakage on iqm garnet, a 20-qubit superconducting NISQ processor (IQM). The interaction that we realise on the hardware experiment is summarised in Figure 1. The victim holds qubit 5

b

1.0 0.8 0.6 0.4 0.2 60–61* 79–93 149–148 47–57 13–14 49–38 75–74 71–70 41–36 101–116 33–39 81–82 25–26 27–28 150–151 143–144 115–99 111–112 11–18 16–3 0–1

0.0

boundary (victim–probe)

105

0.8

shot budget N *

conditional spread Γ

1.2 ζ/2π (kHz)

c

1.0

0.6 0.4

104 103

0.2

102

0.0

101

boundary (victim–probe)

60–61* 79–93 149–148 47–57 13–14 49–38 75–74 71–70 41–36 101–116 33–39 81–82 25–26 27–28 150–151 143–144 115–99 111–112 11–18 16–3 0–1

a

60–61* 79–93 149–148 47–57 13–14 49–38 75–74 71–70 41–36 101–116 33–39 81–82 25–26 27–28 150–151 143–144 115–99 111–112 11–18 16–3 0–1

1.4

boundary (victim–probe)

Figure 4: Twenty one boundaries surveyed on ibm kingston using 1000 shots per circuit with 4 circuits used for the experiment. (a) Coupling rate ζ/2π per boundary. (b) Conditional spread Γ per boundary. (c) Adversary shot budget N ∗ at 99% confidence per boundary. amount. That is, although theoretically suppressing in- with the baseline of implementing no defence. formation leakage does not degrade the victim’s circuit, Figure 5 shows the conditional phase gap ∆θ, condiin practice, there is an impact due to accumulation of tional spread Γ, and the adversary shot budget at 99% error with application of each extra gate. confidence against idle window length τ . The cheaper deThe effect is not one lucky pair. We repeated the same fence achieves nothing. However, the leakage is considerexperiment on twenty-one distinct boundaries. Moti- ably suppressed under the full frame defence of Result 2. vated by the earlier observation that Γ is peaked near The boundary-only frame recovers Result 2 only in the T2 , we set τ for each pair based on its reported T2 . Fig- special case where the part of victim’s state containing ure 4(a) shows the estimated coupling rate ζ/2π. The secret x never reaches ∂A during the window. For a viccoupling rate has median 903 Hz, with a 25th-to-75th- tim running an actual circuit with potential movement percentile range of 727 to 992 Hz. The coupling rate of the secret towards the boundary qubits, a boundaryexceeds 250 Hz on 18 boundaries and 750 Hz on 15. The only frame gives an illusion of protection. Only the fullpair 60-61, studied earlier, sits at the upper end of this register frame of Result 2 closes the channel. spread, but it is not atypical. Figure 4(b) shows condiThe residual, and where Result 2 meets hardware. Retional spread Γ for all the pairs. The conditional spread sult 2 predicts exactly zero leakage under the full-register has a median 0.35. Figure 4(c) shows the shot budget frame. What we measure is a small residual leakage, N ∗ at 99% confidence, calculated based on the estimated which is small enough to practically imply no detection conditional spread. The adversary’s shot budget N ∗ has as it pushes the shot counts to millions. The residual median 75. leakage can be due to noisy observations with finite numBoundary randomisation is not enough. Consider the ber of shots. In addition, it may be also caused by an case where the victim holds an interior qubit q150 while assumption that the hardware violates. A transmon, the q149 is the boundary. The victim’s secret is held on the superconducting circuit used here, is not a clean twointerior qubit q150 and the secret encodes whether the level qubit, and admits a third energy level. A Pauli state is prepared at |0⟩ or |1⟩. The adversary’s probe is frame built from operators on the two-level subspace on q148 and is initialised at |+⟩. These qubits are in a does not symmetrise the third level. Result 2 is exact line. After the initialisation, a defence mechanism is im- in the ideal qubit model, but on real hardware it potenplemented. Then, a SWAP that moves the secret from tially carries a correction set by how much information q150 onto q149 , which, in this experiment, models the vic- is leaked from that third level. Separating the impact of tim’s legitimate circuit operation, then the idle window these issues is an interesting avenue for future research. τ , where the q149 and q148 get coupled through unwanted The observation is not vendor specific. To check crosstalk, then any correction due to the defence. Af- whether this result is general, we repeated a reduced ter this, the adversary reads q148 . We implement two version of the survey on a different vendor’s device, iqm defence mechanisms. The first mechanism is the one garnet, accessed through IQM’s Resonance cloud serdescribed in Result 2, which involves random Pauli op- vice. Seven potential tenant boundaries were measured erations on both qubits q149 and q150 . This should the- with the idle window chosen per boundary from each oretically render the adversary completely incapable of qubit’s own measured coherence time. Figure 6 illusestimating the secret held by the victim. The second ap- trates the conditional spread across the boundaries. The proach is the heuristic of implementing random Pauli op- conditional spreads are smaller than those measured on erations on the boundary qubit q149 . We compare these ibm kingston, but this is expected due to the devices 6

a

2.0 1.5 1.0 0.5

shot budget N *

2.5

100

conditional spread Γ

phase gap Δθ (rad)

b no frame boundary-only frame full-register frame

3.0

10−1 no frame boundary-only frame full-register frame

10−2

0.0 0

20

40

60

80

idle window τ (μs)

10−3

100

0

20

40

60

80

idle window τ (μs)

100

1010 109 108 107 106 105 104 103 102

c no frame boundary-only frame full-register frame

0

20

40

60

80

idle window τ (μs)

100

Figure 5: Effect of imperfect defence by randomisation on boundary qubits, where the victim circuit moves the secret from an interior qubit onto the boundary qubit measured on ibm kingston. (a) Conditional phase gap against idle window length. (b) Conditional spread Γ against idle window length. (c) Adversary shot budget at 99% confidence. The heuristic boundary-only frame sits on top of the undefended baseline, i.e., it does not work as a defence mechanism. The Pauli frame from Result 2 suppresses the leakage significantly. used industrially to tailor noise, provides a promising protection. Two issues require further investigation. We surveyed boundaries on two superconducting quantum computers. Showing this issue experimentally on other types of devices remains open. Also, scaling the bounds here to many co-scheduled tenants at once (not just one victim and one adversary) raises a composition question much like the one differential privacy similarly faces [22].

0.40

conditional spread Γ

0.35 0.30 0.25 0.20 0.15 0.10 0.05

Methods 9–14

18–19

7–8

5–10

11–16

13–12

3–2

0.00

An important choice, relating to control settings that must be turned off, matters here for interpreting the results. Particularly, gate and measurement twirling must Figure 6: Conditional spread Γ on seven boundaries sur- be disabled. Gate twirling is precisely the Pauli frame veyed on iqm garnet using 1000 shots per circuit with defence under test. Leaving it on erases the attack and would be mistaken for a null result. Dynamical decou4 circuits used for the experiment. pling must also be disabled, because it actively echoes away the static ZZ interaction being measured. Note substantially shorter T2 , which has a median of 10.3µs that, given these can be turned off by the victim and the against several tens of microseconds on ibm kingston. adversary, it is important to document their importance This forces a correspondingly shorter idle window τ and and relevance to information leakage. Analysis code, cirtherefore less accumulated phase before decoherence. cuit generators, and the data behind every figure are available at [23].

boundary (victim–probe)

Discussion Use of large language models

The privacy of a shared quantum processor is set by the coherence of its tenant boundary, not by the boundary’s error rate. The figure of merit providers currently publish cannot support a privacy guarantee on its own. Repetition weakens any guarantees provable per circuit run. Victim-side Pauli randomisation over the whole register results in a quantum one-time pad and closes this channel. The cheaper boundary-only version of the same idea provides no protection. Randomised compiling, already

During preparation of this manuscript the author used Claude Sonnet 5 (Anthropic), a large language model, for revising the prose and writing the Python and Qiskit code used for hardware experiments. All AI outputs were reviewed, independently verified against exact numerical computation or primary literature where applicable, and edited by the author. The author takes full responsibility for the content of the published article. 7

Data availability

References

The processed data underlying every figure is available at [23]. Backend calibration data for ibm kingston and iqm garnet are available through their respective cloud provider’s platform [24, 25].

[1] P. Das, S. S. Tannu, P. J. Nair, and M. Qureshi, “A case for multi-programming quantum computers,” in Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO-52), pp. 291–303, 2019. [2] M. Sarovar, T. Proctor, K. Rudinger, K. Young, E. Nielsen, and R. Blume-Kohout, “Detecting crosstalk errors in quantum information processors,” Quantum, vol. 4, p. 321, 2020.

Code availability All circuit-generation, execution, and analysis code is available at [23].

[3] Z. Zhou, R. Sitler, Y. Oda, K. Schultz, and G. Quiroz, “Quantum crosstalk robust quantum control,” Physical Review Letters, vol. 131, p. 210802, 2023.

Competing interests This work used IBM Quantum computing access provided through the IBM Quantum Network Hub at the University of Melbourne. The author declares no competing financial interests.

[4] N. Choudhury, C. N. Mude, S. Das, P. C. Tikkireddi, S. Tannu, and K. Basu, “Crosstalkinduced side channel threats in multi-tenant NISQ computers,” arXiv preprint arXiv:2412.10507, 2024.

Ethical and dual-use considerations

[5] W. J. B. Lee, S. Wang, S. Dutta, W. E. Maouaki, and A. Chattopadhyay, “SWAP attack: Stealthy side-channel attack on multi-tenant quantum cloud system,” arXiv preprint arXiv:2502.10115, 2025.

The underlying security threat, information leakage or interference through crosstalk in shared/multi-tenant quantum processors, has been publicly demonstrated, including on IBM quantum hardware [4, 9, 8]. Our contribution is the quantitative information-theoretic characterisation of this leakage, its relationship to gate infidelity/coherence, and the demonstrated mitigation. We judge the net effect of publication to be protective rather than harmful, since the paper’s primary contribution is the defence and the call-for-action for transparent data release from the cloud service providers that follows from it, and withholding the quantitative characterisation would leave affected users without a way to assess their exposure while leaving the underlying hardware behaviour unchanged.

[6] W. J. B. Lee, S. Wang, S. Dutta, W. E. Maouaki, and A. Chattopadhyay, “Poster: Stealthy SWAPbased side-channel attack on multi-tenant quantum cloud systems,” in Proceedings of the 20th ACM Asia Conference on Computer and Communications Security, ASIA CCS ’25, (New York, NY, USA), p. 1788–1790, 2025. [7] S. Maurya, C. N. Mude, B. Lienhard, and S. Tannu, “Understanding side-channel vulnerabilities in superconducting qubit readout architectures,” in 2024 IEEE International Conference on Quantum Computing and Engineering (QCE), vol. 1, pp. 1177– 1183, IEEE, 2024. [8] D. Mehra and A. Kalev, “Towards defending crosstalk-mediated attacks in multi-tenant quantum computing,” Physica Scripta, vol. 101, no. 9, p. 095102, 2026.

Author contributions

[9] B. Harper, B. Tonekaboni, B. Goldozian, M. Sevior, and M. Usman, “Crosstalk attacks and defence in a shared quantum computing environment,” Advanced Quantum Technologies, vol. 8, p. e2500009, 2025.

F.F. designed the study, performed the theoretical analysis, conducted the experiments, and wrote the manuscript.

Acknowledgements

[10] B. Bell, A. Trügler, K. Beyer, and P. Erker, “Hardware-agnostic modeling of quantum sideThis work was supported by the University of Melbourne channel leakage via conditional dynamics and learnthrough the establishment of an IBM Quantum Network ing from full correlation data,” arXiv preprint Hub at the University. arXiv:2602.15966, 2026. 8

[11] S. M. Barnett and S. Croke, “Quantum state discrimination,” Advances in Optics and Photonics, vol. 1, no. 2, pp. 238–278, 2009.

https://github.com/farhadfarokhigit/ multi-tenant_quantum_leakage, 2026. [24] IBM Quantum, “View backend details.” IBM Quantum Platform documentation, 2026. Accessed 28 September 2026.

[12] F. Farokhi, “Maximal information leakage from quantum encoding of classical data,” Physical Review A, vol. 109, p. 022608, 2024.

[25] IQM, “Qiskit on IQM user guide.” IQM client doc[13] S. Xiao, Z. Zhao, J. Zhu, and F. Farokhi, “Maxumentation, 2026. Accessed 28 September 2026. imal quantum leakage: operational interpretation and quantum channel analysis,” arXiv preprint [26] I. Issa, A. B. Wagner, and S. Kamath, “An operational approach to information leakage,” IEEE arXiv:2607.15853, 2026. Transactions on Information Theory, vol. 66, no. 3, [14] C. W. Helstrom, “Quantum detection and estimapp. 1625–1657, 2020. tion theory,” Journal of Statistical Physics, vol. 1, [27] P. Krantz, M. Kjaergaard, F. Yan, T. P. Orlando, no. 2, pp. 231–252, 1969. S. Gustavsson, and W. D. Oliver, “A quantum en[15] C. W. Helstrom, Quantum Detection and Estimagineer’s guide to superconducting qubits,” Applied tion Theory, vol. 123 of Mathematics in Science and Physics Reviews, vol. 6, no. 2, p. 021318, 2019. Engineering. New York: Academic Press, 1976. [28] J. Watrous, The Theory of Quantum Information. [16] K. M. R. Audenaert, J. Calsamiglia, R. MuñozCambridge University Press, 2018. Tapia, E. Bagan, L. Masanes, A. Acı́n, and F. Verstraete, “Discriminating states: The quantum cher- [29] M. Kliesch and I. Roth, “Theory of quantum system certification,” PRX Quantum, vol. 2, p. 010201, noff bound,” Physical Review Letters, vol. 98, 2021. p. 160501, 2007. [17] H. Chernoff, “A measure of asymptotic efficiency for tests of a hypothesis based on the sum of observations,” The Annals of Mathematical Statistics, pp. 493–507, 1952. [18] J. J. Wallman and J. Emerson, “Noise tailoring for scalable quantum computation via randomized compiling,” Physical Review A, vol. 94, p. 052325, 2016. [19] A. Hashim, R. K. Naik, A. Morvan, J.-L. Ville, B. Mitchell, J. M. Kreikebaum, M. Davis, E. Smith, C. Iancu, K. P. O’Brien, I. Hincks, J. J. Wallman, J. Emerson, and I. Siddiqi, “Randomized compiling for scalable quantum computing on a noisy superconducting quantum processor,” Physical Review X, vol. 11, p. 041039, 2021. [20] H. Perrin, T. Scoquart, A. Shnirman, J. Schmalian, and K. Snizhko, “Mitigating crosstalk errors by randomized compiling: simulation of the BCS model on a superconducting quantum computer,” Physical Review Research, vol. 6, p. 013142, 2024. [21] P. O. Boykin and V. Roychowdhury, “Optimal encryption of quantum bits,” Physical Review A, vol. 67, no. 4, p. 042317, 2003. [22] D. Alabi and T. Nuradha, “When does quantum differential privacy compose?,” arXiv preprint arXiv:2601.00337, 2026. [23] F. Farokhi, “Code and data for “Coherence rather than error rate governs privacy in multi-tenant quantum computing”.” 9

Supplementary Information Coherence rather than error rate governs privacy in shared quantum processors

Supplementary Note 1

Maximal quantum leakage and its normalisation

The objective of the adversary is estimate or guess a possibly randomised function of the secret x, denoted by z = f (x), by performing measurements on states {ρxB }x∈X . Maximal quantum leakage, defined in [12] by extending the classical notion of maximal leakage [26], compares two scenarios. In the first scenario, the adversary performs positive operator-valued measure (POVM) on the states to obtain measurement y and then takes a guess of z denoted by g(y). In the second scenario, the adversary does not measure the states (modelling the case where the adversary’s state is independent of x and thus measurement is useless) and takes a guess of z denoted by ḡ, where ḡ is a constant independent of y or x. The maximal quantum leakage measures the ratio of the probabilities of success between these two scenarios, that is   P{z = g(y)} , (S1) Q(A → B) ≜ sup log2 P{z = ḡ} POVM,f,g,ḡ where the supremum is taken over all targets of attack (determined by f ), estimation algorithms with access and without access to data (determined by g and ḡ), all measurement policies (determined by the POVM). The maximal quantum leakage, as characterised in (S1), captures the multiplicative increase in the probability of correctly guessing any general random or deterministic function of secret x upon accessing the quantum encoding of the data {ρxB }x∈X . The maximal quantum leakage is proved to be equal to the Sibson mutual information of order infinity between secret x and the adversary’s measurement outcome y [12]. This notion of leakage is intimately related to distinguishability of the states {ρxB }x∈X under uniform prior [13]: Q(A → B) = L(A → B) X Tr(Πx ρxB ), = log2 sup

(S2) (S3)

{Πx } x∈X

where the supremum is taken over POVMs with M outcomes indexed by X . Three properties follow from [12, 13]. ′ Information leakage L(A → B) vanishes if and only if ρxB = ρxB for all x ̸= x′ . Information leakage is bounded above by log2 M . And, for M = 2 and X = {x, x′ }, the leakage is exactly equal to ′ 1 L(A → B) = log2 (1 + ∥ρxB − ρxB ∥1 ) 2

(S4)

due to the Helstrom bound [14, 15].

Supplementary Note 2

Proof of Result 1

Define the average conditional state as 1 X x ρ . M x B

(S5)

∆x = ρxB − ρ̄B .

(S6)

ρ̄B = Let

P P We can see that x Tr(Πx ρxB ) = 1 + x Tr(Πx ∆x ), and since every measurement operator satisfies 0 ≤ Πx ≤ I while Tr ∆x = 0, each term obeys Tr(Πx ∆x ) ≤ ∥∆x ∥1 /2. Summing over x and substituting into Eq. (5) gives ! X1 x L(A → B) ≤ log2 1 + ∥ρ − ρ̄B ∥1 . (S7) 2 B x 10

Eq. (S7) holds as an equality, not just a bound, for M = 2. With only two secrets the sum on the right is exactly the trace distance between the two conditional states and the equality follows from the Helstrom bound [14, 15]. Note that ′ 1 X x (ρB − ρxB ). (S8) ρxB − ρ̄B = M ′ x

x By the triangle inequality and ρxB = EB (ρin B ),

1 X1 x M −1 1 x 1 X 1 x in x′ in x′ ≤ EB (ρB ) − EB (ρB ) ≤ E − EB ∥ρB − ρ̄B ∥1 ≤ Γ. 2 M ′ 2 M ′ 2 B M 1 ⋄ x

(S9)

x

Summing over x gives X1 x

2

∥ρxB − ρ̄B ∥1 ≤ (M − 1)Γ,

which, in conjunction with Eq. (S7), results in L(A → B) ≤ log2 (1 + (M − 1)Γ).

(S10)

Also, note that L(A → B) ≤ log2 M [12].

Supplementary Note 3

Proof of Result 2

With the Pauli frame defence, the conditional channel is given by n h io in(x) † x EB (ρin ⊗ ρin , B ) = EP TrA VP (ρA B )VP

(S11)

where VP = (CP ⊗ I) U (t, τ ) (P ⊗ I),

(S12)

where CP is any correction chosen to keep the victim’s intended logical operation correct for the Pauli draw P . Here, expectation with respect to the Pauli frame is taken as the adversary does not know the frame P used. For (x) (x) an idle victim HA = 0, CP = P † . For the victim implementing any gate GA (evolution operator under HA ̸= 0), the standard choice is CP = GA P † G†A . The specific choice of CP does not matter for what follows. Note that n h io in(x) † x in † † EB (ρin ) = E Tr (C ⊗ I) U (t, τ ) (P ⊗ I)(ρ ⊗ ρ )(P ⊗ I) U (t, τ ) (C ⊗ I) (S13) P A P B B A P n h io in(x) † † = EP TrA U (t, τ ) (P ⊗ I)(ρA ⊗ ρin (S14) B )(P ⊗ I) U (t, τ ) h n o i in(x) † † = TrA U (t, τ ) EP (P ⊗ I)(ρA ⊗ ρin (S15) B )(P ⊗ I) U (t, τ ) h i in(x) † = TrA U (t, τ ) (EP {P ρA P † } ⊗ ρin (S16) B ) U (t, τ )   † = TrA U (t, τ ) (I/2nA ⊗ ρin (S17) B ) U (t, τ ) where the second equality stems from the properties of trace TrA [(CP ⊗ I)M (CP† ⊗ I)] = TrA [M ], the third equality x follows from linearity of the trace, and the last equality from EP [P ρxA P † ] = IA /2nA . Hence, EB (ρin B ) becomes independent of x and therefore the leakage must be zero as the states can no longer be distinguished.

Supplementary Note 4

Equatorial inputs are optimal under T1 /T2 decoherence

In our experiments, we use a probe prepared in |+⟩. Here, we show that, under the standard T1 /T2 Lindblad model for a superconducting qubit [27], this is an optimal choice. Consider the cross-Hamiltonian H× = ζZa ⊗ Zb . Since the victim applies no gates, A stays in |x⟩. Here, we neglect relaxation of the victim’s qubit during the idle window. This is justified by capping the idle window τ well below the victim’s T1 . Any residual decay only reduces the phase gap, so it lowers rather than raises the leakage computed here. This is a modelling idealisation that enables 11

us to calculate the solution explicitly. For fixed secret x because Za |x⟩ = (−1)x |x⟩, tracing out the victim’s qubit results in the reduced Lindblad master equation: (x)

(x)

ρ̇B = −i(−1)x ζ [Zb , ρB ] +

1  − (x) + 1 n + − (x) o γϕ (x) (x)  σb ρB σb − 2 σb σb , ρB Zb ρB Zb − ρB , + T1 2

1 1 = + γϕ . (S18) T2 2T1

For a general input state |φ⟩, the density operator at time t is   x (x) ρB (t) = 1 − ⟨1|φ⟩⟨φ|1⟩ e−t/T1 |0⟩⟨0| + ⟨0|φ⟩⟨φ|1⟩ e−t/T2 e−i2(−1) ζt |0⟩⟨1| x

+ ⟨1|φ⟩⟨φ|0⟩ e−t/T2 ei2(−1) ζt |1⟩⟨0| + ⟨1|φ⟩⟨φ|1⟩ e−t/T1 |1⟩⟨1| . (0)

(1)

By the Helstrom bound [14, 15], the optimal single-shot success probability for distinguishing ρB (τ ) from ρB (τ ) is (0) (1) a monotonically increasing function of ∥ρB (τ )−ρB (τ )∥1 , so maximising the adversary’s success means maximising 1 (0) (1) ρ (τ ) − ρB (τ ) 1 = 2 ⟨0|φ⟩⟨φ|1⟩ e−τ /T2 sin(2ζτ ) 2 B

(S19)

over the input state |φ⟩. This requires maximising √|⟨0|φ⟩⟨φ|1⟩|. Writing |φ⟩ = α |0⟩+β |1⟩ gives |⟨0|φ⟩⟨φ|1⟩| = |α||β|, which is maximised if and only if |α| = |β| = 1/ 2. The adversary could also entangle its probe with an ancilla. Note conditional spread Γ relates to the diamond (0) (1) norm of the difference of the two conditional channels EB and EB [28]. We have (x)

EB = Nτ ◦ Rx , x

x

where Rx (ρ) = e−i(−1) ζτ Zb ρ ei(−1) ζτ Zb is the coherent rotation and Nτ is the T1 /T2 noise channel over time τ . Writing ρ = 12 (I + bx X + by Y + bz Z), direct calculation gives (R0 − R1 )(ρ) = sin(2ζτ ) (bx Y − by X),

(S20)

which has no I or Z component. On traceless operators in the span of X and Y the noise channel acts as multiplication by e−τ /T2 . Therefore, (0)

(1)

EB − EB = Nτ ◦ (R0 − R1 ) = e−τ /T2 (R0 − R1 ), and, as a result, (0)

(1)

EB − EB

⋄

= e−τ /T2 ∥R0 − R1 ∥⋄ .

(S21)

For two unitary channels with unitaries U and V , the diamond-norm distance satisfies q 2 1 ∥U (·)U † − V (·)V † ∥⋄ = 1 − dist 0, conv{λi } , 2 where λi are the eigenvalues of U † V and dist is the Euclidean distance in the complex plane [29]. Here U † V = e2iζτ Zb has eigenvalues e±2iζτ , whose convex hull is a chord at distance | cos(2ζτ )| from the origin. Hence ∥R0 − R1 ∥⋄ = 2| sin(2ζτ )| and 1 (0) (1) Γ= E − EB ⋄ = e−τ /T2 | sin(2ζτ )|. (S22) 2 B This equals the unassisted optimum above, so entanglement with an ancilla gives the adversary no advantage.

Supplementary Note 5

Experimental estimation phase gap and contrast

For a given idle window τ , we run four circuits pertaining to the combination of the victim qubit prepared in |0⟩ or |1⟩ and the probe qubit read out in X or Y . Each circuit is executed independently and run several times to estimate the statistics of the measurements. From the raw counts of each circuit, the corresponding Pauli expectation value is estimated as ⟨O⟩x = 2 P̂x (0) − 1, O ∈ {X, Y }, x ∈ {0, 1}, (S23) 12

where P̂x (0) is the fraction of shots returning outcome 0 for victim state x. This gives four numbers, ⟨X⟩0 , ⟨Y ⟩0 , ⟨X⟩1 , ⟨Y ⟩1 . The phase gap and contrast are then estimated as ∆θ = θ0 − θ1 (mod 2π, wrapped to (−π, π]), C(τ ) = 21 (c0 + c1 ),

(S24) (S25)

Γ = C(τ ) | sin(∆θ/2)|,

(S26)

where, for x ∈ {0, 1}, θx = atan2(⟨Y ⟩x , ⟨X⟩x ), p cx = ⟨X⟩2x + ⟨Y ⟩2x .

(S27) (S28)

Why both victim states are measured. For H× = ζZa ⊗ Zb , the idealised prediction is θ0 = −θ1 = 2ζτ exactly, so a single measured branch might seem to fix the other by symmetry. Two effects break this symmetry on real hardware. First, preparing |1⟩ requires an X gate while preparing |0⟩ does not require any gates. This implies state-preparation errors for |0⟩ and |1⟩ are different. Furthermore, relaxation over the idle window (due to decoherence) carries population from |1⟩ toward |0⟩ at rate 1/T1 , with no comparable process acting on the |0⟩. Therefore, c1 and c0 decay asymmetrically as a function of τ . Therefore, measuring θ0 , θ1 , c0 , c1 independently enables us to account for this asymmetry.

13

Record · ID 1108642 · SHA-256 4802284c05e1c18f
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.