A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
arXiv:2605.18928v1 [quant-ph] 18 May 2026
ABBAS ARGHAVANI, Department of Computer Science and Engineering, Mälardalen University, Sweden SHAHID RAZA, School of Computing Science, University of Glasgow, Scotland, UK MARYAM AMIRI, Department of Physics, University of Otago, New Zealand ALESSANDRO PAPADOPOULOS, Department of Computer Science and Engineering, Mälardalen University, Sweden Covert quantum communication (CQC) enables privacy-preserving information transmission by concealing not only message content but also the existence of communication. Existing CQC formulations typically assume deterministic or worst-case channel conditions, an assumption that is difficult to justify in realistic free-space optical and quantum communication environments affected by turbulence, background radiance fluctuations, and stochastic detector noise. This paper introduces a stochastic risk-aware optimization framework for CQC under uncertain physical-layer conditions. By modeling transmissivity and background noise as random variables, we formulate covertness and reliability guarantees probabilistically through chance-constrained optimization, with explicit outage budgets 𝜖cov and 𝜖rel . This reframes CQC design as a risk-calibrated resource allocation problem balancing throughput, covertness, reliability, and communication privacy. We derive tractable quantile-based reformulations for covertness and reliability outage constraints and characterize feasible operating regions under stochastic uncertainty. We also introduce a complementary risk-adjusted utility formulation to expose trade-offs between throughput maximization and probabilistic security or reliability violations. The analysis reveals a key operational transition: modest relaxations in acceptable covertness outage risk 𝜖cov can yield substantial gains in covert throughput, while aggressive throughput optimization can destabilize covertness outside sparse-transmission regimes. Our Monte Carlo evaluation under log-normal fading and stochastic thermal noise demonstrates that the framework significantly enlarges feasible operating regions, improves covert throughput by more than an order of magnitude, and identifies critical degradation boundaries beyond which covert operation becomes unreliable. By combining stochastic optimization with probabilistic security and privacy guarantees, this work advances CQC toward operationally realistic secure quantum networking for free-space, satellite, and low-probability-of-detection communications. CCS Concepts: • Security and privacy → Formal security models; Information-theoretic techniques; • Mathematics of com-
puting → Stochastic processes.
Additional Key Words and Phrases: covert quantum communication, risk-aware design, stochastic channel uncertainty, optical channels, quantum security, probabilistic guarantees, outage-constrained optimization ACM Reference Format: Abbas Arghavani, Shahid Raza, Maryam Amiri, and Alessandro Papadopoulos. 2026. A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty. 1, 1 (May 2026), 31 pages. https://doi.org/10.1145/nnnnnnn.nnnnnnn Authors’ Contact Information: Abbas Arghavani, [email protected], Department of Computer Science and Engineering, Mälardalen University, Västerås, Sweden; Shahid Raza, School of Computing Science, University of Glasgow, Glasgow, Scotland, UK, [email protected]; Maryam Amiri, Department of Physics, University of Otago, Dunedin, New Zealand; Alessandro Papadopoulos, Department of Computer Science and Engineering, Mälardalen University, Sweden. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]. © 2026 Copyright held by the owner/author(s). Publication rights licensed to ACM. Manuscript submitted to ACM Manuscript submitted to ACM
1
2
Arghavani et al.
Fig. 1. Schematic of CQC. Alice transmits photons to Bob over a channel with transmittance 𝜂. An adversary, Willie, collects the lost photons (1 − 𝜂 ) to detect the transmission, whose signal Alice must hide within background noise.
1 Introduction Modern cryptography protects the content of communications, but not their existence. In many high-stakes settings, merely detecting a signal can trigger censorship, jamming, or physical intervention, even if the message remains undeciphered. This motivates covert communication (also known as low-probability-of-detection, LPD), whose goal is to hide that communication is happening at all. Consider a canonical scenario: A legitimate transmitter (Alice) wishes to communicate with a legitimate receiver (Bob) while an adversarial warden (Willie) attempts to detect whether any transmission is taking place. A transmission is deemed covert if Willie’s optimal detector cannot perform significantly better than random guessing. Figure 1 depicts this setting in the optical domain. Covert communication has been extensively studied in classical (non-quantum) wireless, wired, and optical systems. √ A foundational result, known as the Square-Root Law (SRL), states that over 𝑛 channel uses only O ( 𝑛) bits can be
sent covertly [10, 17]. This limit has driven research on signaling, coding, and system design under strict undetectability constraints [8]. In parallel, several works show that injecting or exploiting uncertainty at the warden, e.g., via
friendly jamming or fluctuating interference, can relax SRL assumptions and, under suitable models of channel/noise uncertainty, enable substantially higher covert throughput than the classical SRL would suggest [7, 8, 14, 15]. Recent advances have extended covert-communication principles into the quantum domain [2–4, 16]. In covert quantum communication (CQC), Alice sends quantum states (typically single photons or weak coherent states) over a lossy optical channel to Bob, while Willie attempts to detect the mere existence of communication. Communication is considered covert if Willie cannot reliably infer whether a transmission is taking place. As sketched in Figure 1, a fraction of the optical energy inevitably leaks into the environment and can be collected by Willie for detection; the physical and threat models are shown in Figure 2 and detailed in Section 3. Beyond its theoretical appeal, CQC enables emerging cybersecurity applications, including • Satellite-to-ground links: Undetectable command-and-control of space assets during sensitive missions. • Free-space optical (FSO) urban networks: Invisible, secure backhaul in contested environments.
• Quantum key distribution (QKD) integration: Concealing the existence of the QKD session itself, not only the key.
• Privacy-sensitive finance and tactical command and control: Covert signaling for secure financial transactions and undetectable command-and-control in tactical settings.
Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
3
Most existing CQC analyses assume that the legitimate parties know the channel’s physical parameters, such as the transmittance and mean thermal photon number, exactly, and that these parameters remain constant over time [2–4]. In practice, this assumption rarely holds. Real-world channels, particularly in FSO and satellite links, are subject to dynamic and unpredictable variations caused by atmospheric turbulence, pointing errors, and fluctuating background illumination. Such variability can significantly degrade performance or, worse, compromise covertness. From a privacy-and-security perspective, the quantity at stake is not only throughput but the probability that the very existence of communication is exposed. Under channel uncertainty, a design calibrated for nominal conditions can violate its intended covertness target or decoding guarantee when the environment deviates from that nominal model. The problem is therefore fundamentally one of security-risk calibration under uncertainty: the system designer must choose an operating point that controls the probabilities of exposure and communication failure, not merely maximize rate under idealized assumptions. A recent line of work has begun to address this issue through bounded uncertainty, in which the channel parameters are assumed to lie within known deterministic intervals [9]. That approach provides worst-case guarantees, but it is inherently conservative: it optimizes against the most adverse channel realizations even when such realizations may be rare. The present paper moves beyond that robust worst-case perspective by modeling the uncertainty stochastically and optimizing throughput under explicit probabilistic risk budgets. In this paper, we take the next step by modeling channel uncertainty stochastically. We treat key channel parameters (transmittance and thermal noise) as random variables drawn from physically motivated distributions (e.g., a truncated lognormal model for turbulence-induced loss, and a truncated Gaussian model for background noise). This shift enables a move from optimistic constant channel guarantees to a risk-aware design paradigm in which system performance is optimized while explicitly bounding the probability of two failure events: • Covertness failure: The adversary’s detection advantage exceeds the allowable security threshold, so the communication event is insufficiently hidden.
• Decoding failure: The channel is too degraded for the receiver to decode the message reliably. To the best of our knowledge, prior CQC analyses have not jointly modeled physical-layer uncertainty through explicit random-variable channel models, imposed explicit probabilistic constraints on both covertness and reliability outages, and optimized throughput under these quantified risks. Our framework is intended to fill that gap under the adopted bosonic-channel model. The main contributions of this work are summarized as follows: (1) Develop a systematic framework for risk-aware covert quantum communication over channels with stochastic uncertainty, based on explicit probabilistic models for channel variation and outage risk. (2) Formulate the primary design problem as a risk-constrained optimization that maximizes covert throughput under explicit probabilistic budgets on covertness and reliability outages. Theorem 1 gives the optimal solution, and Corollary 2 establishes monotonicity of the resulting Pareto frontier. As a secondary exploratory extension, we also study a risk-adjusted objective; Theorem 2 derives first-order conditions for any differentiable interior optimum, which we use only to interpret operating-point preferences rather than to claim hard covert guarantees. (3) Show how stochastic physical-layer uncertainty can be reduced to calibrated covertness- and reliability-outage variables through the induced distributions of 𝑐 cov (𝜂, 𝑛 𝐵 ) and 𝑅ach (𝜂, 𝑛𝐵 ), and provide a practical, simulationbased methodology (using quantile reformulation and Monte Carlo estimation) to solve the resulting design
Manuscript submitted to ACM
4
Arghavani et al. Table 1. Summary of key symbols used in the paper.
Symbol
Description
𝑛 𝜂 𝜇ln(𝜂) , 𝜎ln (𝜂) 𝜇𝜂 , 𝜎𝜂 𝑛𝐵 𝜇𝑛 𝐵 , 𝜎𝑛 𝐵 𝛿 𝑐 cov 𝐷 (· k ·) 𝑞, 𝑞∗ 𝑅ach , 𝑅 ∗ 𝑇,𝑇 ∗
Number of channel uses Channel transmittance (random variable) Mean and standard deviation of ln(𝜂 ) Mean and standard deviation of 𝜂 Mean thermal photon number (random variable) Mean and standard deviation parameters of the 𝑛 𝐵 distribution Covertness threshold Covertness constant of the channel Quantum relative entropy (QRE) Transmission probability; its optimized value under stochastic uncertainty Instantaneous achievable rate under a realized channel; optimized chosen code rate Per-use covert throughput 𝑇 = 𝑞𝑅; optimal throughput 𝑇 ∗ = 𝑞∗ 𝑅 ∗
problem and characterize the risk–performance trade-off surface and constrained Pareto behavior of CQC systems under the adopted stochastic model. (4) Derive novel analytical results, including a closed-form solution for the optimal strategy in a benchmark exponential-noise channel (Lemma 1) and a formal analysis of risk sensitivity (Proposition 1) that identifies performance bottlenecks. (5) Demonstrate, through physically motivated FSO-inspired stochastic simulations, the usefulness of the framework and its ability to balance throughput and risk under realistic stochastic uncertainty. The remainder of this paper is organized as follows. Section 2 reviews related work in covert and covert quantum communication. Section 3 presents the system and threat models together with the baseline performance metrics. Section 4 introduces the stochastic channel model, operational assumptions, and risk definitions. Section 5 formulates the design problem, and Section 6 details the solution methodology. Section 7 provides simulation results, followed by discussion in Section 8 and conclusions in Section 9. For clarity, we summarize the key notation used throughout the paper. The physical channel is characterized by its transmittance 𝜂 and mean thermal photon number 𝑛𝐵 , both modeled as random variables. For turbulence–induced loss, we use either log-domain parameters (𝜇 ln(𝜂 ) , 𝜎ln(𝜂 ) ) for a lognormal model, or linear-domain parameters (𝜇𝜂 , 𝜎𝜂 )
when modeling 𝜂 directly. For the background noise, we use (𝜇𝑛𝐵 , 𝜎𝑛𝐵 ). The fundamental covert-communication limit
is captured by the covertness constant 𝑐 cov . Alice’s transmission strategy is specified by the transmission probability
𝑞 and the chosen code rate 𝑅, with optimizer outputs 𝑞 ∗ and 𝑅 ∗ . The instantaneous achievable rate supported by a realized channel is denoted by 𝑅ach (𝜂, 𝑛𝐵 ). Our primary performance metric is the per-use covert throughput 𝑇 = 𝑞𝑅;
the optimizer returns 𝑇 ∗ = 𝑞 ∗𝑅 ∗ . Table 1 summarizes the notation. 2 Related Work
Covert communication has been extensively studied in non-quantum communication systems. The foundational works [10, 17] established the SRL, which states that over 𝑛 channel uses, the number of reliably and covertly transmissible bits √ scales at most as O ( 𝑛) [10]. This limitation has motivated a large body of research on coding, modulation, and signaling strategies that maximize throughput under strict undetectability constraints, with applications spanning military
links, privacy-preserving networking in civilian infrastructure, and in-body covert sensing/communication [13]. Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
5
Fig. 2. The CQC channel model, where Alice transmits a signal state (|𝜓 i) with probability 𝑞 or vacuum with probability 1 − 𝑞. ˆ and an adversary, A beamsplitter with transmittance 𝜂 mixes her input 𝑎ˆ with environmental noise 𝑒, ˆ directing outputs to Bob (𝑏) Willie (𝑤). ˆ
More recently, attention has shifted to quantum channels, where the medium conveys quantum states of light rather than classical symbols. CQC leverages quantum effects (e.g., photon-counting statistics and bosonic noise models) to guarantee undetectability against an optimal quantum-limited adversary [2–4]. These works derive performance √ bounds for pure-loss, thermal-noise, and entanglement-assisted channels. While the O ( 𝑛) scaling persists, the constants and operational regimes differ, opening new avenues for stronger security guarantees. However, most CQC
analyses assume perfectly known and time-invariant channel parameters (typically the transmittance and mean thermal photon number). This assumption is rarely satisfied in practice (especially in free-space optical (FSO) and satellite links) where atmospheric turbulence, pointing error, and background illumination vary on short timescales. In the classical literature on LPD, stochastic channel uncertainty has also been addressed by modeling fading/noise as random processes and optimizing average-case or outage-constrained performance [8, 14, 15]. To the best of our knowledge, prior work in the quantum setting has not developed a systematic CQC design framework under stochastic uncertainty that explicitly couples distributed channel uncertainty with probabilistic constraints on both covertness failure and decoding failure. This gap is security-critical: in covert communication, uncertainty does not merely reduce performance, but can invalidate the intended protection of the communication event itself. Related classical robust-design work under bounded uncertainty has also shown that reliability and covertness need not be governed by the same adverse parameter realization, reinforcing the need to treat the two constraints separately in robust covert design [6]. Building on quantum covertness limits and our earlier bounded-uncertainty CQC model [9], we therefore propose a risk-aware CQC design methodology for stochastic channels, thereby bridging pessimistic worst-case designs, idealized perfect-knowledge models, and deployment-relevant security-risk calibration. 3 System Model and Performance Metrics To analyze the impact of channel uncertainty, we first outline the system model and associated performance measures, originally introduced in [3, 4]. This model serves as the baseline for our stochastic risk-aware formulation and is reproduced here to make the paper self-contained. 3.1
Physical Setup and Channel Model
We consider a CQC scenario with three parties: a sender (Alice), a legitimate receiver (Bob), and a passive adversary (Willie). Alice’s goal is to deliver quantum information to Bob while preventing Willie from reliably detecting that communication is occurring. Time is organized into frames; in each frame, the optical channel is used 𝑛 times. We refer to each channel use as a slot. In slot 𝑡 ∈ {1, . . . , 𝑛}, Alice transmits a signal state with probability 𝑞, and remains
Manuscript submitted to ACM
6
Arghavani et al.
silent (sending the vacuum state |00i) with probability 1 − 𝑞. The signal is a single qubit encoded using the dual-rail
scheme, a standard technique in linear optical quantum computation [4]. In this encoding, a logical qubit is represented by a single photon distributed across two optical modes. The logical basis states are |0i𝐿 = |01i ,
|1i𝐿 = |10i, so a
general logical qubit can be written as |𝜓 i = 𝛼 |0i𝐿 + 𝛽 |1i𝐿 = 𝛼 |01i + 𝛽 |10i, with normalization |𝛼 | 2 + |𝛽 | 2 = 1.
The communication channel is modeled as a lossy bosonic channel with thermal noise, appropriate for both fiber-
optic and free-space links. As illustrated in Figure 2, the channel is implemented by a beamsplitter with two input and two output modes. Alice’s input mode 𝑎ˆ is mixed with an environmental thermal mode 𝑒ˆ of mean photon number 𝑛𝐵 . ˆ is directed to Bob; the other, 𝑤ˆ , is accessible to Willie. The corresponding annihilation operators One output mode, 𝑏, satisfy p √ 𝑏ˆ = 𝜂 𝑎ˆ + 1 − 𝜂 𝑒, ˆ p √ ˆ 𝑤ˆ = 1 − 𝜂 𝑎ˆ − 𝜂 𝑒,
(1) (2)
where 𝜂 ∈ (0, 1) is the transmittance, i.e., the fraction of Alice’s signal that reaches Bob. The complementary fraction
1−𝜂 is diverted to Willie. The environmental input 𝑒ˆ is assumed to be a zero-mean thermal state 𝜌ˆ𝑛𝐵 with mean photon number 𝑛𝐵 . In the Fock basis, 𝜌ˆ𝑛𝐵 =
∞ Õ
(𝑛𝐵 )𝑘 |𝑘i h𝑘 | . (1 + 𝑛𝐵 )𝑘+1 𝑘=0
This model captures the fundamental interaction between signal loss and environmental noise that governs Bob’s decoding performance and Willie’s detection capability. 3.2
Covertness Requirement and Security Analysis
From Willie’s standpoint, detection is a binary quantum hypothesis test between: • Hypothesis 𝐻 0 : Alice remains silent throughout the entire frame. Willie observes the frame-level state 𝑊 ⊗𝑛 𝜌ˆ𝑊 , 0,frame = 𝜌ˆ0,slot where 𝜌ˆ𝑊 is the noise state per slot (i.e., per channel use). 0,slot
• Hypothesis 𝐻 1 : Alice transmits according to her probabilistic scheme. Willie observes the corresponding framelevel state 𝜌ˆ𝑊 . 1,frame
Willie’s optimal detector incurs false alarms (type I error) with probability 𝑃FA and missed detections (type II error) with probability 𝑃MD . Under equal priors 𝑃 (𝐻 0 ) = 𝑃 (𝐻 1 ) = 1/2, the average error probability is 𝑃𝑒 = 21 𝑃FA + 𝑃MD .
The covertness criterion [8] requires that Willie’s minimum error probability be close to random guessing: 𝑃𝑒,min ≥ 21 − 𝛿,
(3)
for some small 𝛿 > 0. The Helstrom bound [11] relates 𝑃𝑒,min to the trace distance between the two possible global states:
𝑊 𝑃𝑒,min = 12 1 − 21 𝜌ˆ𝑊 1,frame − 𝜌ˆ0,frame 1 .
Combining with (3) yields the trace-distance bound
Manuscript submitted to ACM
𝑊 𝜌ˆ𝑊 1,frame − 𝜌ˆ0,frame 1 ≤ 4𝛿.
(4)
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
7
By the quantum Pinsker inequality [3, 18], 1 2
𝜌 −𝜎 1 ≤
q
1 2 𝐷 (𝜌 k𝜎),
so (4) is satisfied if the quantum relative entropy (QRE) obeys 𝑊 2 𝜌 ˆ 𝐷 𝜌ˆ𝑊 0,frame ≤ 8𝛿 . 1,frame
Under the transmission model adopted here, and conditional on a realized frame-level channel state (𝜂, 𝑛𝐵 ), Willie’s
observations across slots are modeled as identically distributed and independent under each hypothesis. Accordingly, for a fixed frame state, the frame-level states are 𝑊 𝜌ˆ𝑊 1,frame (𝜂, 𝑛𝐵 ) = 𝜌ˆ1,slot (𝜂, 𝑛𝐵 )
and the QRE reduces to
⊗𝑛
,
𝑊 𝜌ˆ𝑊 0,frame (𝜂, 𝑛𝐵 ) = 𝜌ˆ0,slot (𝜂, 𝑛𝐵 )
⊗𝑛
,
𝑊 𝑊 𝑊 𝐷 𝜌ˆ𝑊 1,frame (𝜂, 𝑛𝐵 ) 𝜌ˆ0,frame (𝜂, 𝑛 𝐵 ) = 𝑛 𝐷 𝜌ˆ1,slot (𝜂, 𝑛𝐵 ) 𝜌ˆ0,slot (𝜂, 𝑛𝐵 ) .
This is the standard product-state reduction for a quasi-static frame with conditional i.i.d. slots, rather than a separate claim about the channel being entanglement-breaking. Throughout the stochastic outage analysis developed later, we interpret this conditional-on-state formulation under the conservative threat model that Willie’s detection capability for a given frame is evaluated with respect to the realized frame state (𝜂, 𝑛𝐵 ), and the resulting outage probability is then
computed over the distribution of such frame states across frames/sessions. In Section 4, we then place a probability law on the frame-level state (𝜂, 𝑛𝐵 ) and study outage probabilities across frames/sessions. When the transmission
probability 𝑞 is small, the per-slot state under 𝐻 1 , 𝜌ˆ𝑊 , is close to 𝜌ˆ𝑊 . In this sparse-transmission regime, the 1,slot 0,slot per-slot QRE can be approximated using the quantum 𝜒 2 -divergence, yielding (1 − 𝜂) 2 𝑊 2 . 𝜌 ˆ 𝐷 𝜌ˆ𝑊 0,slot ® 𝑞 1,slot 𝜂𝑛𝐵 1 + 𝜂𝑛𝐵
Substituting into the QRE bound gives the covertness condition 𝑛 𝑞2 Defining the covertness constant
(1 − 𝜂) 2 ® 8𝛿 2 . 𝜂𝑛𝐵 1 + 𝜂𝑛𝐵
𝑐 cov =
q 2 𝜂 𝑛𝐵 1 + 𝜂𝑛𝐵
the constraint on the transmission probability becomes 𝑞 ≤
1−𝜂
(5)
,
2𝛿 𝑐 cov √ . 𝑛
A larger 𝑐 cov permits a higher feasible 𝑞 (and thus greater throughput) without compromising covertness. 3.3
Reliability Requirement
When Alice transmits, Bob must be able to recover the encoded qubit from his noisy measurements reliably. Bob’s decoding performance is affected by two primary factors: (1) Channel-induced errors: photon loss, governed by 𝜂, and thermal noise, characterized by 𝑛𝐵 ; Manuscript submitted to ACM
8
Arghavani et al. (2) Projection failure: decoding via projection onto the dual-rail computational subspace {|01i , |10i} can discard the photon even if it arrives.
Following [3], the cumulative impact of these effects is well modeled as a depolarizing channel acting on the input qubit: 𝐼 E (𝜌 in ) = (1 − 𝑝) 𝜌 in + 𝑝 , 2 where 𝜌 in is the qubit sent by Alice, and the depolarizing probability 𝑝 is 𝑝 = 1 −
𝜂 1 + (1 − 𝜂)𝑛𝐵
4 .
(6)
The corresponding Pauli error probabilities are h i 3𝑝 𝑝 𝑝 𝑝 𝑝® = 𝑝 𝐼 , 𝑝𝑋 , 𝑝𝑌 , 𝑝𝑍 = 1 − 4 , 4 , 4 , 4 .
The achievable communication rate per transmitted qubit, from the hashing bound [3], is ® +, (7) 𝑅ach (𝜂, 𝑛𝐵 ) = 1 − 𝐻 (𝑝) Í ® = − 𝑖 𝑝𝑖 log2 𝑝𝑖 is the Shannon entropy of the error distribution (with 𝑖 ∈ {𝐼, 𝑋 , 𝑌 , 𝑍 }) and (𝑥) + = where 𝐻 (𝑝) ® gives max(𝑥, 0). Expanding 𝐻 (𝑝) ® = − 1 − 3𝑝4 log2 1 − 3𝑝4 − 3 · 𝑝4 log2 𝑝4 . 𝐻 (𝑝) Combining the instantaneous achievable rate in (7) with the covertness-induced constraint on 𝑞 characterizes the
secure operating region of the system. For convenience, we also define the per-use covert throughput 𝑇 ¬ 𝑞 𝑅,
(8)
which we will optimize under stochastic channel uncertainty in subsequent sections. 4 Channel Models and Assumptions We now formalize the statistical models, knowledge assumptions, and risk constraints that underpin our analysis. Our framework moves from fixed channel parameters to a physically faithful stochastic model that enables risk-aware performance optimization. 4.1
Stochastic Channel Parameters
In Section 3, we treated 𝜂 and 𝑛𝐵 as known constants. In realistic deployments, these quantities vary due to environmental dynamics. We therefore model them as random variables with known probability distributions, obtained via prior measurement or physical modeling. • Transmittance 𝜂: For FSO and satellite links, the dominant fluctuation mechanism is atmospheric turbulence, which induces scintillation (fading). Because the optical transmittance in our bosonic channel model must satisfy 0 < 𝜂 ≤ 1, we model 𝜂 using a truncated lognormal distribution on (0, 1]: 2 𝜂 ∼ Lognormal (0,1] 𝜇 ln(𝜂 ) , 𝜎ln(𝜂 ) ,
with density
𝑓𝜂 (𝑥) = Manuscript submitted to ACM
𝑓LN (𝑥; 𝜇 ln(𝜂 ) , 𝜎ln(𝜂 ) ) 1 (0,1] (𝑥), 𝐹 LN (1; 𝜇 ln(𝜂 ) , 𝜎ln(𝜂 ) )
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
9
where 𝑓LN and 𝐹 LN are the PDF and CDF of the corresponding untruncated lognormal law. This preserves the usual lognormal motivation from wave-propagation theory while enforcing the physical support required by the channel model and the covertness expression [5, 12]. • Thermal noise 𝑛𝐵 : Background photons arise from sources such as celestial radiation, local equipment, and detector dark counts. We model 𝑛 𝐵 as a truncated Gaussian [1]: 𝑛 𝐵 ∼ N [0,𝑏 ] 𝜇𝑛𝐵 , 𝜎𝑛2𝐵 ,
where truncation enforces the physical constraint 𝑛𝐵 ≥ 0 and optionally caps extreme values at 𝑏 to model sensor saturation or environmental maxima.
For analytical tractability, we assume 𝜂 and 𝑛𝐵 are statistically independent, a reasonable approximation when turbulence-induced fading and background illumination have distinct physical origins. Scenarios with coupling (e.g., dense fog) are left for future work. Throughout this paper, we interpret the random pair (𝜂, 𝑛𝐵 ) as a frame-level channel state: for any given frame of
𝑛 channel uses, the parameters 𝜂 and 𝑛𝐵 are taken to be constant across the 𝑛 slots, but are randomly redrawn from
their governing distributions across different frames/sessions. As a result, the probabilistic constraints introduced later are imposed over the distribution of these quasi-static frame states, rather than over independently varying slot-level channel realizations. Equivalently, the product-form expressions in Section 3 should be read as holding conditional on a realized frame state (𝜂, 𝑛 𝐵 ), while the risk constraints later average over the distribution of these frame states across frames. 4.2
Operational Knowledge and Strategy Constraints
We specify the information available to each party: • Alice and Bob: Know the distributions 𝑓𝜂 and 𝑓𝑛𝐵 , but not the instantaneous realizations during transmission. This knowledge is acquired before the covert session via non-covert probing, long-term environmental sensing, or predictive modeling. • Willie: We adopt a conservative threat model in which Willie knows the same channel laws as Alice and Bob
and, for each frame, his detection capability is evaluated conditional on the realized frame-level state (𝜂, 𝑛𝐵 ). Operationally, this corresponds to a warden with per-frame CSI or sufficiently accurate per-frame estimation of the realized state.
• No instantaneous CSI: During covert transmission, Alice receives no real-time channel state information (CSI). Feedback is impractical or would itself risk revealing activity.
This is the threat model used throughout the outage analysis in the paper. Accordingly, the covertness-outage event is defined by asking whether the chosen transmission probability 𝑞 violates the adopted QRE-based covertness surrogate for the realized frame state, and the probability in the corresponding risk constraint is then taken over the distribution of frame states across frames/sessions. We do not analyze the alternative model in which Willie knows only the channel distribution but not the realized frame state and must instead perform a mixture-state hypothesis test. That leads to a different covertness formulation and is outside the scope of the present paper. All probabilistic guarantees in this paper are conditional on the assumed channel laws 𝑓𝜂 and 𝑓𝑛𝐵 . In other words, the risk budgets (𝜖cov , 𝜖rel ), the induced quantiles, and the resulting operating points are calibrated with respect to the stipulated stochastic model. If the true channel statistics differ materially from the assumed distributions, the realized Manuscript submitted to ACM
10
Arghavani et al.
outage probabilities may no longer match the nominal budgets. Our results should therefore be interpreted as modelbased risk guarantees, not distribution-free guarantees. 4.3
Fixed Transmission Strategy, Risk Budgets, and Outage Events
In the absence of real-time CSI, Alice commits to a single fixed transmission strategy specified by (𝑞, 𝑅) for an entire
frame, where 𝑞 ∈ [0, 1] is the per-channel use transmission probability and 𝑅 ∈ [0, 1] is the chosen quantum code rate
(design variable). Allowing 𝑅 = 0 explicitly includes the trivial zero-payload operating point, which is useful when the outage budgets are so stringent that no nonzero code rate is feasible. Let 𝑅ach (𝜂, 𝑛𝐵 ) ¬
® 𝑛𝐵 )) 1 − 𝐻 (𝑝(𝜂,
+
(9)
denote the instantaneous achievable rate under the realized channel, given in (7). We also recall the per-use covert throughput 𝑇 ¬ 𝑞 𝑅, with optimal value 𝑇 ∗ = 𝑞 ∗𝑅 ∗ . Here, 𝑇 is a design throughput: it quantifies the scheduled payload per channel use under the fixed strategy (𝑞, 𝑅). The randomness of the channel enters separately through the covertness and reliability outage events, which are controlled by the risk budgets 𝜖cov and 𝜖rel .
Risk budgets. We introduce two user-specified probability thresholds, called risk budgets: 𝜖cov, 𝜖rel ∈ (0, 1). Here, 𝜖cov is the maximum tolerable probability (per frame, over the randomness of (𝜂, 𝑛𝐵 )) that the covertness constraint is violated. 𝜖rel is the maximum tolerable probability (per frame) that decoding fails, i.e., that the chosen code
rate 𝑅 exceeds the instantaneous achievable rate 𝑅ach (𝜂, 𝑛𝐵 ). We consider:
• Covertness outage: A security failure that occurs when the realized channel is sufficiently clear (equivalently, 𝑐 cov (𝜂, 𝑛 𝐵 ) is too small) so that the chosen 𝑞 violates the covertness constraint.
• Reliability outage: A communication failure that occurs when the realized channel is too noisy for Bob to decode at rate 𝑅, i.e., when 𝑅ach (𝜂, 𝑛𝐵 ) < 𝑅.
Both outage probabilities must lie below their budgets: 2𝛿 P[Covertness outage] = P 𝑞 > √ 𝑐 cov (𝜂, 𝑛𝐵 ) ≤ 𝜖cov , 𝑛 P[Reliability outage] = P[ 𝑅 > 𝑅ach (𝜂, 𝑛 𝐵 )] ≤ 𝜖rel . The covertness-outage event above is induced by the QRE-based sufficient condition and sparse-transmission approximation introduced in Section 3. Accordingly, the budget 𝜖cov should be interpreted as controlling outage relative to this adopted covertness surrogate under the quasi-static stochastic model of the paper. In the risk-constrained parameter regimes emphasized in our main simulations, the resulting optimizers remain in the sparse-transmission regime; outside that regime, the covertness constraint should be interpreted with corresponding caution. To avoid ambiguity, we distinguish the following quantities. The instantaneous achievable rate 𝑅ach (𝜂, 𝑛𝐵 ) is the rate
supported by a specific realization of the channel parameters (𝜂, 𝑛 𝐵 ). As such, it is a random variable induced by the channel uncertainty. In simulations, we draw 𝐾 realizations and record 𝑟 𝑖 := 𝑅ach (𝜂𝑖 , 𝑛 𝐵,𝑖 ) for 𝑖 = 1, . . . , 𝐾. The chosen code rate 𝑅 is a single design variable that Alice fixes for the entire transmission (frame/session). A reliability outage
occurs whenever the chosen rate exceeds what the realized channel can support, i.e., when 𝑅 > 𝑅ach (𝜂, 𝑛𝐵 ). Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
11
5 Problem Formulation The core design problem is to choose a fixed transmission strategy (𝑞, 𝑅) that balances design throughput against the
risks of security and reliability failures. Our primary formulation is a risk-constrained model that maximizes performance subject to hard probability budgets. We then study a secondary risk-adjusted extension that internalizes outage costs directly in the objective and is used only for exploratory policy analysis rather than for guarantee-bearing design.
5.1
Risk-Constrained Formulation
We first seek the strategy that maximizes per-use covert throughput while ensuring that the outage probabilities induced by the adopted stochastic covertness-and-reliability model stay below prescribed budgets. This formulation fits operational settings with non-negotiable limits on failure (e.g., “the probability of covertness outage must be below 0.1%” or “the probability of reliability outage must be below 1%”). Given the definition of 𝑅ach presented in Eq.(9), the optimization problem is formally stated as: max 𝑇 (𝑞, 𝑅) = 𝑞 𝑅 𝑞, 𝑅 2𝛿 s.t. P 𝑞 > √ 𝑐 cov (𝜂, 𝑛 𝐵 ) ≤ 𝜖cov, 𝑛
(10) (11)
P[𝑅 > 𝑅ach (𝜂, 𝑛𝐵 )] ≤ 𝜖rel ,
(12)
0 ≤ 𝑞 ≤ 1, 0 ≤ 𝑅 ≤ 1. Here, the objective (10) is the per-use covert throughput 𝑇 = 𝑞𝑅; the probabilities in (11) and (12) are taken over the randomness of (𝜂, 𝑛𝐵 ). The chosen code rate, 𝑅, is a decision variable in the optimization, and we denote its optimal
value as 𝑅 ∗ . As we will show in Theorem 1, in the continuous regime emphasized in this paper the optimizer (𝑞 ∗, 𝑅 ∗ )
is characterized by quantiles of the induced distributions of 𝑐 cov (𝜂, 𝑛𝐵 ) and 𝑅ach (𝜂, 𝑛𝐵 ), with the achievable-rate quan-
tile denoted by 𝑅max . To the best of our knowledge, this is among the first CQC formulations to treat physical-layer uncertainty stochastically while jointly optimizing throughput under explicit probabilistic risk constraints.
5.2
Exploratory Extension: Risk-Adjusted Throughput
While the risk-constrained model provides hard guarantees, it is often useful to encode risk preferences directly in the objective, as is common in financial engineering. We therefore define the risk-adjusted throughput i h 𝐽 (𝑞, 𝑅) ¬ 𝑇 (𝑞, 𝑅) − 𝜆cov P 𝑞 > √2𝛿𝑛 𝑐 cov (𝜂, 𝑛𝐵 ) − 𝜆rel P[𝑅 > 𝑅ach (𝜂, 𝑛 𝐵 )] ,
(13)
where 𝑇 (𝑞, 𝑅) = 𝑞𝑅 is the per-use throughput and 𝜆cov, 𝜆rel ≥ 0 are risk-aversion parameters that penalize covertness
and reliability outages, respectively. Larger 𝜆 values reflect greater aversion to the corresponding failure mode. We then solve the following problem: max 𝑞, 𝑅
𝐽 (𝑞, 𝑅)
(14)
s.t. 0 ≤ 𝑞 ≤ 1, 0 ≤ 𝑅 ≤ 1. Manuscript submitted to ACM
12
Arghavani et al. This formulation selects a single strategy that balances reward (throughput) against weighted risk; by sweeping
(𝜆cov, 𝜆rel ), one explores the trade-off induced by the weighted objective. Unlike the risk-constrained formulation, how-
ever, it does not impose hard probabilistic guarantees on covertness or reliability. It should therefore be interpreted
as a decision-theoretic design tool for exploring operating-point preferences, rather than as the primary formulation for guarantee-critical deployments. Theorem 2 characterizes the first-order conditions satisfied by any differentiable interior optimum of this formulation. 5.3
Interpretation: The Risk–Performance Frontier
Our stochastic framework generalizes prior perfect-knowledge models by characterizing the trade-off between performance and risk through a Pareto-frontier viewpoint. A strategy is Pareto optimal if no other strategy improves one objective (e.g., throughput) without worsening at least one risk measure. • Risk-constrained model: Lets a designer select a point on the frontier by specifying risk budgets (𝜖cov, 𝜖rel ).
Theorem 1 characterizes the optimizer (𝑞 ∗, 𝑅 ∗ ) under these constraints and its dependence on the budgets. Varying (𝜖cov, 𝜖rel ) traces the constrained frontier.
• Risk-adjusted model: Explores points on the frontier by pricing outages via (𝜆cov, 𝜆rel ). Theorem 2 gives only the first-order conditions for differentiable interior optima. In practice, we explore this formulation numerically through a weighted-sum scalarization. For a nonconvex frontier, this need not recover every Pareto-optimal point. In both formulations, there is no single universally best strategy, only operating-point trade-offs, with the riskconstrained model serving as the primary guarantee-bearing design tool. Our approach characterizes this trade-off frontier under the adopted model, enabling mission-specific choices instead of defaulting to a single conservative worst-case design. 6 Solution Methodology The key methodological step is to reduce the stochastic CQC design problem from physical-layer uncertainty in (𝜂, 𝑛𝐵 )
to calibrated covertness- and reliability-outage variables induced by 𝑐 cov (𝜂, 𝑛 𝐵 ) and 𝑅ach (𝜂, 𝑛 𝐵 ). Once this reduction
is made, the risk-constrained formulation admits a closed-form optimizer through quantile bounds, while the riskadjusted extension is explored numerically. The risk-constrained objective 𝑇 (𝑞, 𝑅) = 𝑞𝑅 is bilinear1 (and therefore
neither convex nor concave), while the risk-adjusted objective 𝐽 (𝑞, 𝑅) is generally nonconvex for the reasons summarized in the footnote. Moreover, the constraints are probabilistic in (𝜂, 𝑛𝐵 ). Thus, generic gradient-based solvers
do not directly exploit the structure used here. We therefore develop practical methods that yield the optimal transmission strategy (𝑞 ∗, 𝑅 ∗ ) for the risk-constrained formulation together with a principled numerical strategy for the
risk-adjusted formulation.
1𝑇 (𝑞, 𝑅) has ∇ 2𝑇
=
01 10
(eigenvalues ±1), hence it is neither convex nor concave on any open convex set. Likewise, the risk-adjusted objective ! 𝑛 ′
√ 𝑓 (𝑢) 1 𝑞 𝑛 4𝛿 2 𝑐 cov (with 𝑢 = 2𝛿 ). At points where 𝑓𝑐′cov (𝑢 ) = 𝑓𝑅′ (𝑅) = 0 (e.g., interior modes of 1 −𝜆rel 𝑓 ′ (𝑅) ach 𝑅ach 01 2 common unimodal PDFs), ∇ 𝐽 = 1 0 is indefinite; hence 𝐽 is also nonconvex.
𝐽 (𝑞, 𝑅) has Hessian ∇2 𝐽 =
Manuscript submitted to ACM
−𝜆cov
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty 6.1
13
Solving the Risk-Constrained Problem
Our approach is to convert the probabilistic constraints in (11)–(12) into deterministic one-sided quantile bounds. Because the outage events are defined using strict inequalities, the exact quantile object for general distributions is not the usual inverse CDF, but the largest threshold whose strict lower-tail probability remains within the prescribed risk budget. For a real-valued random variable 𝑋 and 𝜖 ∈ (0, 1), define the strict-outage quantile 𝑄𝑋< (𝜖) ¬ sup {𝑥 ∈ R : P[𝑋 < 𝑥] ≤ 𝜖} .
(15)
Equivalently, if 𝐹𝑋 denotes the CDF of 𝑋 , then 𝑄𝑋< (𝜖) = sup {𝑥 ∈ R : 𝐹𝑋 (𝑥 − ) ≤ 𝜖} ,
(16)
𝐹𝑋 (𝑥 − ) ¬ lim 𝐹𝑋 (𝑦).
(17)
where 𝑦↑𝑥
The definition in (15) correctly handles atoms, flat CDF regions, and boundary cases induced by the strict outage events. Theorem 1 (Optimal risk-constrained throughput). For the risk-constrained program (10)–(12), define the strictoutage distribution function 𝐹𝑋< (𝑥) ¬ P[𝑋 < 𝑥], and the corresponding strict-outage quantile 𝑄𝑋< (𝜖) ¬ sup{𝑥 : 𝐹𝑋< (𝑥) ≤ 𝜖}. Then the maximum per-use covert throughput is 𝑇 ∗ = 𝑞 ∗𝑅 ∗ = 𝑞 max 𝑅max, with
2𝛿 𝑅max = 𝑄 𝑅<ach (𝜖rel ). 𝑞 max = min 1, √ 𝑄𝑐<cov (𝜖cov ) , 𝑛 This characterization is exact for arbitrary distributions, including cases with atoms at the relevant outage thresholds. Corollary 1 (Continuous-case reduction). If the relevant outage thresholds lie at continuity points of the CDFs of 𝑐 cov and 𝑅ach , then Theorem 1 reduces to 𝑇 ∗ = 𝑞 ∗𝑅 ∗ = 𝑞 max 𝑅max, with
2𝛿 𝑞 max = min 1, √ 𝐹 𝑐−1cov (𝜖cov ) , 𝑛 𝑅max = 𝐹 −1 𝑅ach (𝜖rel ),
(18) (19)
where 𝐹𝑋−1 (·) denotes the usual left-continuous quantile function.
Proof. Deferred to A. The proof works directly with the strict-outage events and therefore does not require continuity assumptions. Corollary 1 then recovers the simpler 𝐹 −1 -based expression used in the continuous regime emphasized in our simulations. Manuscript submitted to ACM
14
Arghavani et al. In practice, for the continuous regime emphasized in our simulations, the required quantiles are computed numeri-
cally from Monte Carlo samples of (𝜂, 𝑛𝐵 ) as ordinary empirical quantiles (see Section 7). 6.2
Characterizing the Risk-Adjusted Formulation via First-Order Conditions
For the risk-adjusted objective (13), we do not derive a closed-form global optimizer. Instead, we characterize differentiable interior optima via first-order conditions. Let 𝑐 cov = 𝑐 cov (𝜂, 𝑛 𝐵 ),
𝑅ach = 𝑅ach (𝜂, 𝑛𝐵 ),
and denote by 𝐹𝑐 cov , 𝐹𝑅ach their CDFs and by 𝑓𝑐 cov , 𝑓𝑅ach their PDFs (when they exist; otherwise interpret conditions in the subgradient sense). Theorem 2 (First-order conditions for differentiable interior optima). Fix 𝜆cov , 𝜆rel ≥ 0. Any interior maxi-
mizer (𝑞 ∗, 𝑅 ∗ ) of the risk-adjusted objective (13) that is differentiable at (𝑞 ∗, 𝑅 ∗ ) must satisfy ∗√ √ 𝑞 𝑛 𝑛 𝑅 ∗ = 𝜆cov 𝑓𝑐 cov , 2𝛿 2𝛿 𝑞 ∗ = 𝜆rel 𝑓𝑅ach (𝑅 ∗ ).
(20) (21)
Proof. Deferred to B. The result follows by writing the objective as √ 𝑞 𝑛 𝐽 (𝑞, 𝑅) = 𝑞𝑅 − 𝜆cov 𝐹𝑐 cov 2𝛿 − 𝜆rel 𝐹𝑅ach (𝑅),
𝑑 and setting the partial derivatives to zero, using 𝑑𝑥 𝐹𝑋 (𝑥) = 𝑓𝑋 (𝑥) and the chain rule.
6.3
Justification and Practical Considerations
Figure 3 illustrates the bilinear geometry of the throughput objective 𝑞𝑅. However, the main simplification in the riskconstrained formulation does not come merely from observing nonconvexity; it comes from the CQC-specific reduction of stochastic physical-layer uncertainty to calibrated outage variables, which converts the chance constraints into
Fig. 3. The per-use covert throughput 𝑇 (𝑞, 𝑅) = 𝑞𝑅 is bilinear and therefore neither convex nor concave, which motivates the tailored solution methods used in this paper. Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
15
quantile bounds and the feasible set into a rectangle in (𝑞, 𝑅). This yields the optimizer directly. For the risk-adjusted
formulation, no analogous closed-form reduction is available, so we evaluate the weighted objective numerically on a dense grid. Robustness and implementation. • Risk-constrained: In the continuous regime emphasized in this paper, the quantile-based bounds yield the global maximizer (𝑞 max, 𝑅max ) without iterative search. In practice, the required quantiles are estimated via Monte Carlo from the stipulated distributions of (𝜂, 𝑛 𝐵 ).
• Risk-adjusted: Eqs. (20) and (21) provide structural conditions for interior optima and help interpret how the optimizer depends on the two penalties. In the numerical results, however, we evaluate the risk-adjusted objective directly on a dense (𝑞, 𝑅) grid, since Monte Carlo-estimated outage probabilities induce step-like empirical CDFs
and can lead to boundary-pinned solutions. Because the covertness surrogate used in this paper is derived from a sparse-transmission (small-𝑞) approximation, operating points with large 𝑞 should be interpreted qualitatively
rather than as physically meaningful covert operating points. Both methods are not tied to a specific parametric distribution and are parallelizable. They apply directly under the independence assumption in Section 4. 7 Analytical and Simulation Results To evaluate our optimization framework and quantify the trade-off between covert throughput and risk, we run largescale Monte Carlo experiments. We choose physically motivated parameter settings intended to represent FSO-inspired operating scenarios, and report performance landscapes that illustrate how a designer can select operating points under stochastic uncertainty. 7.1
Simulation Parameters
To highlight the fundamental behavior of our risk-aware framework, we begin with a high-quality baseline stochastic channel model and later stress the system with more challenging conditions. Unless stated otherwise, we consider a CQC system over an FSO link with the following settings: • Channel uses (𝑛): 𝑛 = 107 in most scenarios. This places the operation in a large-blocklength regime in which √ the 𝑛 covertness scaling is the relevant asymptotic benchmark, while finite-size corrections are not modeled explicitly in the present study. • Security threshold (𝛿): 𝛿 = 0.05, corresponding to the standard covertness target 𝑃𝑒,min ≥ 21 −𝛿 used throughout the paper.
• Transmittance Model (𝜂): We model transmittance using a truncated lognormal distribution on (0, 1]. In the
baseline scenario, the underlying pre-truncation lognormal parameters are 𝜇 ln(𝜂 ) = −0.0126 and 𝜎ln(𝜂 ) = 0.05,
and samples outside (0, 1] are rejected (equivalently, resampled from the truncated law). This yields a physically admissible high-quality channel with low volatility. Because truncation changes the moments, all reported
numerical results are computed from the truncated samples actually used in the simulations. • Thermal-noise model (𝑛𝐵 ): 𝑛 𝐵 ∼ N[0, 0.5] 𝜇𝑛𝐵 , 𝜎𝑛2𝐵 (truncated Gaussian). For the baseline, 𝜇𝑛𝐵 = 0.005 and 𝜎𝑛𝐵 = 0.001, modeling an ultra–low-noise environment (e.g., nighttime operation with filtering) with a physical cap at 0.5. Manuscript submitted to ACM
16
Arghavani et al. • Monte Carlo samples (𝐾): 𝐾 = 106 i.i.d. draws (𝜂𝑖 , 𝑛𝐵,𝑖 ). This provides good empirical resolution over most of the risk range considered here. For the most stringent budgets near 10 −5 , however, the corresponding empirical
quantiles are estimated from relatively sparse tail samples and should therefore be interpreted with the usual Monte Carlo granularity of rare-event estimation. We evaluate risk budgets on the numerical grids described below and reuse the static sample set as described below, enabling rapid exploration of the Pareto frontier without repeated sampling. 7.2
Simulation Procedure
We map the risk–performance Pareto frontier with an efficient two-stage pipeline that avoids re-running expensive Monte Carlo simulations for each operating point. In a one-time setup, we draw a large, fixed set of channel realizations and precompute the induced performance metrics: (1) Generate 𝐾 = 106 i.i.d. samples (𝜂𝑖 , 𝑛𝐵,𝑖 ) from the stipulated distributions, with 𝜂𝑖 drawn from the truncated lognormal law on (0, 1]. Each sample represents one frame-level channel realization, i.e., one quasi-static pair
held fixed over the corresponding frame of 𝑛 channel uses.
(2) For each sample, compute the covertness constant 𝑐 cov,𝑖 and the instantaneous achievable rate ® 𝑖 , 𝑛𝐵,𝑖 )) + . 𝑟 𝑖 ¬ 𝑅ach (𝜂𝑖 , 𝑛 𝐵,𝑖 ) = 1 − 𝐻 (𝑝(𝜂 𝐾 and {𝑟 }𝐾 . This yields two stored arrays {𝑐 cov,𝑖 }𝑖=1 𝑖 𝑖=1
We next evaluate the risk–performance frontier by reusing the static arrays. The specific risk points are chosen based on the analysis type. For the throughput curves and the decade-gain calculations in Table 3, the symmetric risk threshold 𝜖 is swept over logarithmically spaced values spanning 10 −5 to 10 −1 . For the sensitivity plot in Figure 8, we use the focused range 𝜖 ∈ [10 −4 , 10 −1 ], where the estimated PDFs are numerically well behaved.2 To generate the 2D scheduled-payload surface, we evaluate the performance on a 20 × 20 grid in which 𝜖cov and 𝜖rel are each drawn from
the same logarithmically spaced vector spanning 10 −5 to 10 −1 . For each risk point, we perform the following: (3) Estimate the required quantiles from the stored samples and set 2𝛿 𝑅max = 𝐹b−1 𝑞 max = min 1, √ 𝐹b𝑐−1cov (𝜖cov ) , 𝑅ach (𝜖rel ), 𝑛 where 𝐹b−1 denotes the empirical quantile function.
(4) The optimal strategy is (𝑞 ∗, 𝑅 ∗ ) = (𝑞 max, 𝑅max ) with per-use design throughput 𝑇 ∗ = 𝑞 ∗𝑅 ∗ and total scheduled payload 𝑛𝑇 ∗ over 𝑛 channel uses, where the cap in 𝑞 max enforces the global box constraint 𝑞 ≤ 1.
All experiments use a fixed random seed for reproducibility. With 𝐾 = 106 , the empirical quantiles are stable over the main portion of the plotted risk range. For analyses that include budgets near 10 −5 , the corresponding estimates are necessarily based on sparse tail samples and should be interpreted with that finite-sample resolution in mind. Simulations were implemented in MATLAB on a standard desktop. The one-time sample generation takes minutes, and each frontier point thereafter is computed in milliseconds by reusing the cached arrays. Accordingly, the qualitative trends and relative ordering of the curves are the main objects of interpretation, especially at the smallest plotted risk levels. For Figure 8, the quantities 𝑆 cov and 𝑆 rel are evaluated numerically along the symmetric-budget line 𝜖cov = 𝜖rel = 𝜖. 2 At the extreme lower end of this sweep, empirical quantiles are based on rare tail samples. The corresponding points are still useful for showing the
trend toward highly conservative operation, but they should not be over-interpreted as high-precision estimates of ultra-rare-event quantiles. Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
17
Specifically, for each plotted 𝜖, we estimate 𝑆 cov by finite differences of 𝑇 ∗ (𝜖cov , 𝜖) with respect to 𝜖cov at 𝜖cov = 𝜖, and estimate 𝑆 rel by finite differences of 𝑇 ∗ (𝜖, 𝜖rel ) with respect to 𝜖rel at 𝜖rel = 𝜖. 7.3
Analytical Benchmark: The Exponential-Noise Channel
Before presenting numerical results for the full stochastic model, we first analyze a simplified special case that admits an exact solution. This serves two purposes: (i) it provides a theoretical benchmark to validate our Monte Carlo implementation; and (ii) it offers a transparent, closed-form example that illustrates (without numerical abstraction) how the risk-constrained optimization operates under uncertainty. In a simplified model we specialize to: • Fixed transmittance: 𝜂 = 𝜂 0 is known and constant.
• Exponential noise: The mean thermal photon number follows an exponential law with rate 𝜆, 𝑛𝐵 ∼ Exp(𝜆),
𝑓𝑛 𝐵 (𝑥) = 𝜆𝑒 −𝜆𝑥 , 𝑥 ≥ 0.
Under these assumptions, all channel uncertainty is driven by 𝑛 𝐵 , enabling a closed-form optimum. Lemma 1 (Optimal strategy for the exponential-noise channel). Consider a CQC link with fixed transmittance 𝜂 0 and 𝑛𝐵 ∼ Exp(𝜆). The risk-constrained optimum is (𝑞 ∗, 𝑅 ∗ ) = (𝑞 max, 𝑅max ) with s ( ) 𝑍2 − 1 2𝛿 𝑞 max = min 1, √ 𝑘 , 4𝜂 0 𝑛 h i+ , 𝑅max = 1 − 𝐻 𝑝® (𝜂 0, − 𝜆1 ln(𝜖rel )) √ 2𝜂
2𝜂
where 𝑘 = 1−𝜂00 and 𝑍 = 1 − 𝜆0 ln(1 − 𝜖cov ). Proof. See Appendix C.
Numerical illustration. As a concrete example, consider a high-quality link with 𝜂 0 = 0.99 and exponential noise with rate 𝜆 = 10. For 𝑛 = 107 uses and risk budgets 𝜖cov = 𝜖rel = 0.1, Lemma 1 gives 𝑞 max ≈ 4.59 × 10 −4 and 𝑅max ≈ 0.8692,
i.e., 𝑇 ∗ ≈ 3.99 × 10 −4 and about 3.99 × 103 scheduled covert qubits over the frame. In a slightly degraded setting with
𝜂 0 = 0.9 (typical of challenging FSO links), the optimum becomes much more conservative: 𝑞 max ≈ 4.4 × 10 −5 and 𝑅max ≈ 0.2204, yielding fewer than 102 scheduled covert qubits per 107 uses.
These calculations highlight the steep trade-off imposed by stringent covertness and reliability requirements: main-
taining very small covertness-outage and decoding-failure probabilities requires extremely sparse transmissions and strong coding, which sharply reduces throughput. Nevertheless, such ultra-low-rate links can be indispensable in highrisk scenarios where the existence of communication must remain hidden. The closed-form solution in Lemma 1 provides a ground-truth reference for validating our Monte Carlo pipeline and clarifies how risk budgets couple with the noise-tail parameter 𝜆 to shape the optimal strategy. To confirm correctness, we compare the Monte Carlo procedure to Lemma 1 using 𝜂 0 = 0.9, 𝜆 = 10, and 𝑛 = 107 . Table 2 shows close agreement across a wide range of risk thresholds, with relative errors below 5% whenever 𝑅max > 0. For 𝜖 = 10 −3 , both methods correctly yield 𝑅max ≈ 0, indicating that a minimum risk budget must be exceeded before a nontrivial covert link can be established in this channel.
Manuscript submitted to ACM
18
Arghavani et al.
Table 2. Validation of Monte Carlo against the analytical benchmark (fixed 𝜂 0 , exponential 𝑛 𝐵 ) from Lemma 1, under symmetric risk budgets 𝜖cov = 𝜖rel = 𝜖. The reported percentage errors are computed from full-precision values, whereas the displayed theory and simulation entries are rounded for readability. Risk (𝜖)
7.4
Metric
Theory
MC Sim.
−6
−6
1.15 —
1.3 × 10 −5 0.011724
0.49 4.10
4.0 × 10 ≈0
4.0 × 10 ≈0
Error (%)
10 −3
𝑞max 𝑅max
10 −2
𝑞max 𝑅max
1.3 × 10 −5 0.011262
10 −1
𝑞max 𝑅max
4.4 × 10 −5 0.220380
4.4 × 10 −5 0.220336
0.04 0.02
0.2
𝑞max 𝑅max
6.4 × 10 −5 0.294959
6.4 × 10 −5 0.294767
0.06 0.07
0.5
𝑞max 𝑅max
1.15 × 10 −4 0.404270
1.15 × 10 −4 0.404337
0.04 0.02
Results and Interpretation
Before turning to the numerical plots, we formalize two structural properties of the trade-offs we observe: monotonicity of the performance frontier (Corollary 2) and the sensitivities of the optimum to the risk budgets (Proposition 1). Throughout this section, the quantities 𝑇 ∗ = 𝑞 ∗𝑅 ∗ and 𝑛𝑇 ∗ should be interpreted as scheduled design payloads under the chosen operating point, not as outage-averaged realized goodput. Corollary 2 (Monotonicity of the Pareto frontier). For the risk-constrained problem, the optimal per-use throughput 𝑇 ∗ (𝜖cov, 𝜖rel ) = 𝑞 ∗𝑅 ∗ is monotonically nondecreasing in each risk budget 𝜖cov and 𝜖rel . Proof. Let 𝑆 (𝜖cov, 𝜖rel ) = [0, 𝑞 max (𝜖cov )] × [0, 𝑅max (𝜖rel )] denote the feasible rectangle induced by the two risk budgets. Since quantiles are monotonically nondecreasing in their probability level, both 𝑞 max (𝜖cov ) and 𝑅max (𝜖rel ) are monotonically nondecreasing in their respective arguments. Therefore, if 𝜖cov,1 ≤ 𝜖cov,2 while 𝜖rel is fixed, then
𝑆 (𝜖cov,1 , 𝜖rel ) ⊆ 𝑆 (𝜖cov,2 , 𝜖rel ). Likewise, if 𝜖rel,1 ≤ 𝜖rel,2 while 𝜖cov is fixed, then 𝑆 (𝜖cov , 𝜖rel,1 ) ⊆ 𝑆 (𝜖cov, 𝜖rel,2 ). Therefore, max
(𝑞,𝑅) ∈𝑆 (𝜖cov,1 ,𝜖rel )
𝑞𝑅 ≤
max
(𝑞,𝑅) ∈𝑆 (𝜖cov,2 ,𝜖rel )
𝑞𝑅,
and similarly when only 𝜖rel increases. Hence 𝑇 ∗ (𝜖cov, 𝜖rel ) is monotonically nondecreasing in each risk budget. To identify which risk constraint is the active bottleneck, we define risk sensitivities. Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
19
Definition 1 (Risk sensitivity). The covertness and reliability risk sensitivities are the partial derivatives of the optimal throughput with respect to their risk budgets: 𝑆 cov ¬
𝜕𝑇 ∗ , 𝜕𝜖cov
𝑆 rel ¬
𝜕𝑇 ∗ . 𝜕𝜖rel
Proposition 1 (Sensitivity formulas away from the saturation point). Assume that the evaluated quantiles 𝐹𝑐−1 (𝜖cov ) and 𝐹𝑅−1 (𝜖rel ) lie at points where the corresponding CDFs are differentiable and the associated densities are cov ach strictly positive. Define
2𝛿 (𝜖cov ), 𝑞e(𝜖cov ) ¬ √ 𝐹𝑐−1 𝑛 cov Then, away from the transition point 𝑞e(𝜖cov ) = 1,
and
𝑞 max (𝜖cov ) = min{1, 𝑞e(𝜖cov )}.
2𝛿 𝑅max √𝑛 𝑓 𝐹 −1 (𝜖 ) , 𝑐 cov 𝑐 cov cov 𝑆 cov = 0, 𝑆 rel =
if 𝑞e(𝜖cov ) < 1,
if 𝑞e(𝜖cov ) > 1,
𝑞 max . 𝑓𝑅ach 𝐹𝑅−1 (𝜖rel ) ach
Proof. Since 𝑇 ∗ = 𝑞
max 𝑅max and 𝑞 max does not depend on 𝜖rel , the derivative with respect to 𝜖rel follows from the
chain rule and the inverse-function derivative −1 𝑑 −1 𝐹 (𝛼) = 𝑓𝑋 (𝐹𝑋−1 (𝛼)) , 𝑑𝛼 𝑋
valid at quantile points where the CDF is differentiable and the density is strictly positive. For 𝜖cov , write 𝑞 max = min{1, 𝑞e(𝜖cov )}. If 𝑞e(𝜖cov ) < 1, differentiate 𝑞e directly; if 𝑞e(𝜖cov ) > 1, then 𝑞 max = 1 is locally constant and hence
𝑆 cov = 0.
Remark. At the transition point 𝑞e(𝜖cov ) = 1, the sensitivity 𝑆 cov need not exist in the classical sense because the minimum operator creates a kink, so one should interpret it using one-sided derivatives. Moreover, because 𝑅ach (𝜂, 𝑛𝐵 ) = ® 𝑛 𝐵 )) + can induce an atom at 𝑅ach = 0, the sensitivities in Proposition 1 need not exist when the relevant 1 − 𝐻 (𝑝(𝜂,
quantile falls on that atom or on another nondifferentiable point. In such cases, one should instead use one-sided finite
differences or a subgradient-style interpretation. In the numerical results below, we therefore estimate these sensitivities from the computed risk-constrained frontier using finite differences, rather than by direct density estimation. Figure 4 shows the primary risk-constrained result: the scaling of total scheduled covert qubits 𝑛 𝑇 ∗ with transmission length 𝑛 for several fixed symmetric risk budgets 𝜖 = 𝜖cov = 𝜖rel . For any fixed 𝑛, larger symmetric risk budgets yield larger total scheduled covert payloads, which is consistent with Corollary 2. As an illustrative operating point, take 𝜖cov = 𝜖rel = 0.01 and 𝑛 = 107 . For the baseline channel, the optimizer yields a sparse-transmission operating point with total scheduled payload on the order of 102 covert qubits over the frame, consistent with Figure 4. We therefore avoid quoting a specific pair (𝑞 ∗, 𝑅 ∗ ) here, since such values should be reported
only from the exact cached-sample run used to generate the plotted frontier.
Reading Figure 4 across curves at a fixed 𝑛 reveals a highly nonlinear risk–reward trade-off. Quantitatively, Table 3 reports the multiplicative gain in throughput when relaxing 𝜖 by one decade for 𝑛 = 107 . A clear takeaway is that modest relaxations from extremely conservative budgets (e.g., 10 −5 → 10 −4 ) can more than
double throughput, highlighting the performance cost of worst-case-like operation.
Manuscript submitted to ACM
20
Arghavani et al.
Fig. 4. Scaling of total scheduled covert qubits (𝑛𝑇 ∗ ) with transmission length 𝑛 for several fixed symmetric risk budgets 𝜖 = 𝜖cov = √ 𝜖rel . The dashed line indicates the 𝑛 Square-Root-Law scaling.
Moving along any single curve, where 𝜖 is fixed and 𝑛 increases, isolates the effect of transmission length. In the √ uncapped regime relevant to Figure 4, the Square-Root Law implies 𝑞 max ∝ 1/ 𝑛 while 𝑅max is independent of 𝑛, so √ √ 𝑇 ∗ = 𝑞 ∗𝑅 ∗ ∝ 1/ 𝑛 and therefore 𝑛 𝑇 ∗ grows only as 𝑛. Thus, longer transmissions yield more total scheduled covert qubits but with diminishing returns. Under a per-session interpretation of the risk budgets, this also suggests that
multiple shorter sessions can be preferable to a single prolonged transmission when those sessions can be treated as operationally separate. 7.5
Impact of Channel Quality and Volatility
We next quantify how physical channel characteristics shape achievable performance. Beyond the baseline scenario described above, we also study comparative channel-quality scenarios to illustrate how the frontier changes across different jointly specified transmittance-and-noise regimes. Figure 5 compares three channel-quality scenarios (poor, nominal, and excellent) defined as follows: the transmittance is modeled as a truncated lognormal law on (0, 1] with fixed 𝜎ln(𝜂 ) = 0.08 and location parameter 𝜇 ln(𝜂 ) = log(𝑚) − 21 (0.08) 2 , where the nominal target levels are 𝑚 ∈
{0.92, 0.96, 0.99} for the poor, nominal, and excellent cases, respectively. Because the distribution is truncated to (0, 1],
these values should be interpreted as scenario targets (and plot labels) rather than exact post-truncation means. The corresponding truncated-Gaussian noise models are 𝑛𝐵 ∼ N[0,0.5] (0.02, 0.012 ), N[0,0.5] (0.01, 0.0052 ), and N[0,0.5] (0.005, 0.0012 ).
These curves provide a quantitative answer to how much a jointly better transmittance-and-noise regime is worth under the adopted scenario family. Table 3. Multiplicative throughput gain when relaxing risk by one decade (𝑛 = 107 ).
Risk relaxation
Throughput gain
10 −5 → 10 −4
2.04× 1.74× 1.89× 2.52×
10 −4 → 10 −3 10 −3 → 10 −2 10 −2 → 10 −1 Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
21
Fig. 5. Impact of the nominal channel-quality scenario on the symmetric-risk trade-off curve for 𝑛 = 107 , with 𝜖cov = 𝜖rel = 𝜖. The three curves correspond to jointly specified poor, nominal, and excellent transmittance-and-noise regimes. Better nominal channel conditions offer a better risk-performance trade-off, while the poor regime shows a feasibility boundary, requiring a risk threshold of 𝜖 > 0.01.
The plot also reveals a feasibility boundary for the poorer regime. For excellent and nominal channels, a viable covert link exists even at very small risks. For the poor channel, throughput remains zero until 𝜖 ¦ 0.01. Thus, for lowquality channels, a minimum level of operational risk must be accepted to realize a nontrivial covert link, an important planning insight for challenging environments. We next examine the role of channel predictability (volatility). Figure 6 compares symmetric-risk trade-off curves for three channels under the same noise model and approximately the same mean transmittance, but with different volatility levels, parameterized by 𝜎ln(𝜂 ) ∈ {0.05, 0.075, 0.10}. For each volatility level, 𝜇 ln(𝜂 ) is adjusted so that the resulting 200
150
100
50
0 0
0.02
0.04
0.06
0.08
0.1
Fig. 6. Effect of transmittance volatility on the symmetric-risk trade-off curve at fixed transmission length 𝑛 = 107 , with 𝜖cov = 𝜖rel = 𝜖. The three curves correspond to 𝜎ln (𝜂) ∈ {0.05, 0.075, 0.10} under the same noise model, with 𝜇ln(𝜂) adjusted across cases so that the mean transmittance remains approximately fixed. Increased volatility markedly degrades the risk–performance trade-off, and the most volatile case exhibits a low-risk feasibility boundary. Manuscript submitted to ACM
22
Arghavani et al.
10-1 160
10-2 80
10-3 40
10-4 20
10-5 10-5
10-4
10-3
10-2
10-1
Fig. 7. Surface of total scheduled covert qubits (𝑛 𝑇 ∗ ) as a function of independent covertness and reliability risks (𝜖cov, 𝜖rel ) for 𝑛 = 107 . Over the plotted grid, the surface appears visually smooth and increases in both risk budgets; however, visual symmetry on this plot should not be interpreted as equal local sensitivity.
transmittance distribution remains centered at approximately the same mean level. Thus, the observed differences are attributable primarily to volatility. Performance degrades sharply as volatility increases. For example, at 𝜖 ≈ 1.4 × 10 −2 , the most stable case (𝜎ln(𝜂 ) =
0.05) supports about 94 total scheduled covert qubits, compared with about 33 for 𝜎ln(𝜂 ) = 0.075 and only about 8 for
𝜎ln(𝜂 ) = 0.10. Thus, increasing the volatility from 0.05 to 0.10 reduces throughput by more than an order of magnitude
in this operating region. The most volatile case also shows a clear feasibility boundary at stringent risk levels: over the plotted grid, it remains effectively infeasible until the risk budget is relaxed to around 10 −2 , after which nonzero
throughput becomes possible. These results show that performance depends not only on average channel quality but also critically on predictability. Figure 7 separates the two risks and shows the full scheduled-payload surface for 𝑛 = 107 . For our high-quality channel, the plotted surface is visually smooth and monotone in both 𝜖cov and 𝜖rel , confirming that relaxing either risk budget improves the achievable scheduled payload. Visually, the surface does not exhibit a sharp cliff in either direction over the plotted range, which is consistent with well-behaved underlying distributions for 𝑐 cov and 𝑅ach in this regime. However, this visual smoothness should not be over-interpreted as equal local sensitivity to the two risks. For the smooth high-quality baseline regime considered here, where the cap in 𝑞 max = min{1, 𝑞e(𝜖cov )} is inactive
(that is, 𝑞e(𝜖cov ) < 1 over the plotted range), Proposition 1 shows that the relevant local quantities are the partial
derivatives 𝑆 cov and 𝑆 rel , which depend on the corresponding quantile slopes of 𝑐 cov and 𝑅ach . Figure 8 reveals that,
for the present high-quality channel, 𝑆 cov ≫ 𝑆 rel , so covertness remains the dominant bottleneck even though the 2D surface looks qualitatively smooth in both directions. In lower-quality or more volatile channels, we expect this imbalance to change, potentially making reliability the dominant bottleneck near a sharp payload-collapse regime.
Finally, Figure 8 plots the numerically estimated sensitivities 𝑆 cov and 𝑆 rel versus symmetric 𝜖. Over the plotted risk range, 𝑆 cov exceeds 𝑆 rel by several orders of magnitude, confirming that covertness is the active bottleneck for this high-quality baseline channel. Reliability is consistently high and thus less sensitive. By contrast, covertness remains fundamentally constrained by the Square-Root Law, making performance highly sensitive to the exact choice of 𝜖cov in the tail. For high-quality links, fine-tuning the covertness risk budget is therefore the most effective lever for improving performance. Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
10
23
2
100
10
-2
10
-4
10
-6
10
-4
-3
10
-2
10
-1
10
Fig. 8. Sensitivity along the symmetric-budget line 𝜖cov = 𝜖rel = 𝜖 for the high-quality baseline channel (𝜎ln (𝜂) = 0.05, 𝜇𝑛 𝐵 = 0.005, 𝜎𝑛 𝐵 = 0.001; 𝑛 = 107 ). The covertness sensitivity 𝑆 cov dominates 𝑆 rel .
7.6
Exploratory Results for the Risk-Adjusted Model
As a secondary exploratory study, we visualize the behavior of the risk-adjusted formulation by numerically maximizing the weighted objective over a fixed (𝑞, 𝑅) grid while sweeping the risk-aversion parameters 𝜆cov and 𝜆rel . For
these risk-adjusted results, we fix the (𝑞, 𝑅) search grid and the (𝜆cov, 𝜆rel ) sweep ranges in advance, as detailed below. Figures 9 and 10 use the same representative channel setting, namely 𝜎ln(𝜂 ) = 0.07, 𝜇 ln(𝜂 ) = log(0.96) − 0.5(0.07) 2 , 𝜇𝑛𝐵 = 0.01, 𝜎𝑛𝐵 = 0.005, 𝑛 = 103 , 𝛿 = 0.05, and 𝐾 = 106 , using a fixed random seed for reproducibility. In both cases,
the weighted objective is maximized over a uniform 401 × 401 grid on (𝑞, 𝑅) ∈ [0, 1] × [0, 1], with 𝑞 and 𝑅 discretized
as linspace(0,1,401). For Figure 9, the one-dimensional sweeps use 40 logarithmically spaced points from 10 −2 to
106 , i.e., logspace(-2,6,40). Specifically, Figure 9a sweeps 𝜆cov with 𝜆rel = 1 fixed, and Figure 9b sweeps 𝜆rel with 𝜆cov = 10 fixed. For Figure 10, the two-dimensional heatmaps use 𝜆cov, 𝜆rel ∈ logspace(-6,6,25). If multiple grid points attain the same maximum within numerical tolerance, MATLAB’s max(J(:)) selects the first maximizer in
column-major order, which corresponds to the smallest 𝑞 and, within that 𝑞, the smallest 𝑅 among tied grid points. Figure 9 shows representative sweeps of the numerically selected operating point, in which the dominant changes occur through sharp regime transitions and boundary-pinned solutions rather than through a uniform decoupling across the entire parameter range. Such aggressive points lie outside the small-𝑞 regime underlying the covertness approximation in Section 3 and should therefore be read as illustrating the geometry of the weighted objective, not as deployment-ready covert operating points. Once 𝜆cov crosses a narrow transition region, the numerically selected operating point collapses rapidly to a no-transmission regime, driving both 𝑞 ∗ and 𝑅 ∗ to zero. The right panel (Figure 9b) shows a different behavior. With 𝜆cov fixed, increasing the reliability penalty mainly suppresses the code rate 𝑅 ∗ , which decreases steadily toward zero. Over this same sweep, 𝑞 ∗ remains close to zero throughout, indicating that in this representative operating regime the covertness penalty has already pushed the system into a highly conservative transmission state before the reliability penalty is varied. The broader optimization landscape in Figure 10 confirms that the numerically selected risk-adjusted operating point is governed by sharp regime changes rather than by a uniformly smooth decoupling. In Figure 10a, the dominant feature Manuscript submitted to ACM
24
Arghavani et al.
1
1
0.8
0.8
0.6
0.6
0.4
0.4
0.2
0.2
0 -2 10
10
0
10
2
4
10
10
6
(a) Sweep over 𝜆cov (fixed 𝜆rel = 1).
0 -2 10
0
10
10
2
10
4
10
6
(b) Sweep over 𝜆rel (fixed 𝜆cov = 10).
Fig. 9. Exploratory sweeps in the risk-adjusted model. The plotted operating points are numerical maximizers of the weighted objective on the fixed grid described in Section 7; they are useful for illustrating regime changes in the weighted formulation, but they should not be interpreted as guarantee-bearing covert operating points. (a) As the covertness penalty increases, the numerically selected operating point undergoes a sharp transition from an aggressive operating point to a no-transmission regime. (b) With the covertness penalty fixed, increasing the reliability penalty mainly suppresses the code rate, while the transmission probability remains pinned near zero in this operating regime.
is a covertness-driven transition boundary: for sufficiently small 𝜆cov , the optimizer selects an aggressive transmission probability, whereas beyond a critical region it collapses rapidly to a no-transmission regime with 𝑞 ∗ ≈ 0. The location of this boundary is only weakly affected by 𝜆rel until the reliability penalty becomes very large.
Figure 10b shows a complementary but not fully separable behavior. For small reliability penalties, the optimizer keeps a high code rate, whereas increasing 𝜆rel progressively compresses 𝑅 ∗ toward zero. However, the transition is not purely horizontal: its detailed shape depends on 𝜆cov , especially near the regime boundary where the numerically selected operating point is already close to the no-transmission state. Thus, the risk-adjusted formulation does provide useful policy knobs, but their effects are strongly operating-point dependent and are better interpreted as regimedependent control rather than as a globally separable law. 8 Discussion We interpret our results in a broader systems context, extract engineering lessons, and highlight limitations that point to future research. 8.1
Our Proposed Risk-Aware Design
Existing analyses of CQC, such as [3], assume perfectly known, static channels. These models provide theoretical benchmarks but rarely reflect practice. Our framework instead models channel parameters (𝜂, 𝑛𝐵 ) as random variables, yielding a risk–performance Pareto frontier that captures the trade-off between throughput and covertness-outage and
decoding-failure probabilities. This shift from deterministic to stochastic modeling enables a paradigm of probabilistic assurance: within the adopted stochastic model and over the risk range studied here, relaxing extremely stringent risk budgets to small, explicitly quantified outage levels can unlock more-than-one-order-of-magnitude throughput gains relative to very conservative operating points. As channel uncertainty becomes small in the sense that the distributions Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
10 6
1
10 6
1
0.9
10 4
0.8 0.7
10 2
0.9
10 4
0.8 0.7
10 2
0.6
10 0
0.5
0.6
10 0
0.5
0.4
10 -2
0.3 0.2
10 -4
0.4
10 -2
0.3 0.2
10 -4
0.1
10
-6
10 -6
0
10 -4
10 -2
10 0
10 2
10 4
10 6
(a) Optimal transmission probability 𝑞∗ .
25
0.1
10
-6
10 -6
0
10 -4
10 -2
10 0
10 2
10 4
10 6
(b) Optimal code rate 𝑅 ∗ .
Fig. 10. Exploratory heatmaps of the numerically selected operating point over (𝜆cov , 𝜆rel ), obtained by direct maximization of the weighted objective on the fixed (𝑞, 𝑅) grid described in Section 7. These plots illustrate the geometry of the weighted objective rather than guarantee-bearing covert operating points. The dominant changes occur across regime boundaries: 𝑞∗ undergoes a sharp covertness-driven transition between aggressive transmission and a no-transmission regime, while 𝑅 ∗ is strongly compressed as the reliability penalty increases, with the precise transition structure depending on the operating point.
of 𝜂 and 𝑛𝐵 collapse to deterministic values, the induced distributions of 𝑐 cov (𝜂, 𝑛 𝐵 ) and 𝑅ach (𝜂, 𝑛𝐵 ) likewise collapse to
deterministic values, and the present framework correspondingly reduces to the associated deterministic benchmark of prior foundational models [3]. 8.2
Design Insights and Engineering Principles
Our results yield several actionable guidelines: • Risk Budgets as System Resources. Outage probabilities (𝜖cov, 𝜖rel ) can be treated like power or bandwidth. Allocating them according to mission priorities enables principled, data-driven operating points rather than
heuristic tuning, as demonstrated by the explicit risk-reward trade-offs mapped in the Pareto frontiers of Figure 4 and Figure 5. • Operating-Point-Dependent Control in the Risk-Adjusted Model. The numerically selected operating
point in the risk-adjusted formulation is influenced differently by the two penalties, but the effect is regime dependent rather than globally separable. In our representative operating point, increasing the covertness penalty mainly drives a sharp transition in 𝑞 ∗ toward a no-transmission regime, while increasing the reliability penalty mainly compresses 𝑅 ∗ . Figures 9 and 10 therefore suggest useful tuning knobs, but they should be interpreted as boundary- and operating-point-dependent controls rather than as a universally decoupled law. Accordingly, this formulation is best viewed as a policy-exploration tool when designers wish to trade throughput against
weighted failure costs, whereas the risk-constrained model remains the appropriate choice when strict outage guarantees are required. • Constraint Dominance Reveals Bottlenecks. In the high-quality baseline channel studied here, covertness
dominates performance; relaxing 𝜖cov delivers the greatest gains. In lower-quality or more volatile channels, Manuscript submitted to ACM
26
Arghavani et al. this balance can shift, potentially making reliability the dominant bottleneck near a payload-collapse regime. Identifying the active constraint is a key to effective resource allocation. • Volatility Matters as Much as Averages. Even when the mean transmittance is held approximately fixed, increased variance in transmittance can sharply compress the feasible operating region, especially at stringent
risk budgets. As shown in Figure 6, stabilizing the channel (e.g., adaptive optics or scheduling in favorable atmospheric windows) can be as important as improving the average channel quality. • Value of Sensing. Better channel characterization can enlarge the safe operating region by reducing uncertainty in the governing channel laws. In particular, Figure 6 shows directly that lower transmittance volatility yields a strictly superior performance frontier, justifying investment in environmental sensing and channel-state prediction. • Small-𝑞 Covertness Approximation. The covertness constraint used in our analysis is derived from a lowtransmission-probability approximation. In the risk-constrained formulation, the optimal strategies remain in
the sparse-transmission regime for the parameter ranges studied here. In the risk-adjusted formulation, however, very small penalties can produce mathematically optimal points with large 𝑞, which should be interpreted only qualitatively. 8.3
Model Limitations
Our formulation relies on simplifying assumptions: • Stationarity. We assume fixed distributions for 𝜂 and 𝑛𝐵 ; in reality, channels can be non-stationary. The model is most applicable within a single coherence interval.
• Non-Adaptive Transmission. The strategy (𝑞, 𝑅) is fixed. Adaptive schemes with feedback could outperform this baseline but fall outside our scope.
• Passive Adversary. Willie is assumed to be powerful but passive. Active adversaries capable of injecting or probing would require game-theoretic extensions.
• Distribution Misspecification. The framework assumes that the governing distributions of 𝜂 and 𝑛𝐵 are
known well enough to estimate the relevant quantiles. If these distributions are misspecified, the nominal risk budgets may be miscalibrated, so the actual covertness and reliability outage probabilities can differ from the designed values.
• Quasi-Static Frame Assumption. The stochastic model treats (𝜂, 𝑛𝐵 ) as constant within each frame and random only across frames/sessions. If the channel varies substantially within a frame, then the present outage formulation should be replaced by a finer time-varying model. 8.4
Future Research
Several extensions are needed before this framework can support deployment-oriented design: • Adaptive and Learning-Based Strategies. Incorporating partial feedback or online estimation to adapt (𝑞𝑡 , 𝑅𝑡 ) dynamically.
• Correlated and Time-Varying Channels. Using copulas or time-series models to capture dependence between 𝜂 and 𝑛𝐵 and to address non-stationarity.
• Robustness Against Active Wardens. Extending to adversaries who probe or interfere, requiring robust gametheoretic designs.
Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
27
• Distributionally Robust Risk Design. Extending the framework to ambiguity sets or distributionally robust formulations would allow one to hedge against errors in the assumed laws of 𝜂 and 𝑛𝐵 , thereby separating stochastic uncertainty from statistical model uncertainty.
9 Conclusion This paper introduces a risk-aware framework for covert quantum communication (CQC) that addresses realistic channel uncertainty. By modeling transmittance and thermal noise as random variables, we formulate a primary riskconstrained design that maximizes throughput while explicitly bounding covertness and reliability outage probabilities. We also include a secondary risk-adjusted extension to illustrate how weighted failure costs reshape preferred operating points, but we do not position that extension as the guarantee-bearing design. Our Monte Carlo-based methodology, validated against a new analytical benchmark, characterizes the risk-performance trade-off frontier under the adopted stochastic model. We demonstrate that, under the same adopted stochastic model and over the risk range studied here, relaxing extremely stringent outage budgets to marginal but quantified risk levels can increase covert throughput by more than one order of magnitude relative to very conservative operating points. Viewed through a security lens, this means that the paper provides a way to calibrate the probabilities of communication exposure and decoding failure under stochastic uncertainty, rather than relying on nominal or worst-case assumptions alone. The analysis reveals key engineering principles, notably that the risk-adjusted design is governed by operating-point-dependent regime changes: covertness and reliability penalties act as useful tuning knobs, but their effects are not globally separable. By establishing these principles of risk-aware design, this work provides a concrete analytical and simulation-based tool for tuning CQC operating points for specific missions under the adopted model. More broadly, the framework offers a foundation for future work on covert quantum communication under realistic uncertainty, including adaptive, correlated, deployment-oriented, and distributionally robust extensions.
References [1] Stephen B. Alexander. 1997. Optical Communication Receiver Design. SPIE Press, Bellingham, WA. [2] Evan JD Anderson, Michael S Bullock, Filip Rozpędek, and Boulat A Bash. 2025. Achievability of covert quantum communication. In 2025 IEEE International Symposium on Information Theory (ISIT). IEEE, 1–6. [3] Evan JD Anderson, Christopher K Eyre, Isabel M Dailey, Filip Rozpędek, and Boulat A Bash. 2024. Square Root Law for Covert Quantum Communication over Optical Channels. In IEEE Int. Conf. Quantum Computing and Engineering (QCE). 1817–1823. [4] Evan J. D. Anderson, Christopher K. Eyre, Isabel M. Dailey, Filip Rozpędek, and Boulat A. Bash. 2024. Covert Quantum Communication Over Optical Channels. arXiv:2401.06764 [quant-ph] Preprint. [5] Larry C. Andrews and Melissa K. Beason. 2023. Laser Beam Propagation in Random Media: New and Advanced Topics. SPIE Press, Bellingham, WA. doi:10.1117/3.2643989 [6] Abbas Arghavani. 2026. Conflict-Aware Robust Design for Covert Wireless Communications. arXiv preprint arXiv:2604.13122 (2026). [7] Abbas Arghavani, Anders Ahlén, André Teixeira, and Subhrakanti Dey. 2021. A game-theoretic approach to covert communications in the presence of multiple colluding wardens. In IEEE Wireless Communications and Networking Conference (WCNC). 1–7. [8] Abbas Arghavani, Subhrakanti Dey, and Anders Ahlén. 2023. Covert outage minimization in the presence of multiple wardens. IEEE Trans. Signal Processing 71 (2023), 686–700. [9] Abbas Arghavani, Alessandro V Papadopoulos, Vahid Azimi Mousolou, Giuseppe Nebbione, and Shahid Raza. 2026. Robust Covert Quantum Communication under Bounded Channel Uncertainty. arXiv preprint arXiv:2604.13116 (2026). [10] Boulat A. Bash, Dennis Goeckel, and Don Towsley. 2013. Limits of reliable communication with low probability of detection on AWGN channels. IEEE J. Selected Areas in Communication 31, 9 (2013), 1921–1930. [11] Carl W. Helstrom. 1976. Quantum Detection and Estimation Theory. Academic Press, New York. [12] Mohammad Ali Khalighi and Murat Uysal. 2014. Survey on free space optical communication: A communication theory perspective. IEEE communications surveys & tutorials 16, 4 (2014), 2231–2258. Manuscript submitted to ACM
28
Arghavani et al.
[13] Madhushanka Padmal, Johan Engstrand, Abbas Arghavani, Subhrakanti Dey, Robin Augustine, Riku Jäntti, and Thiemo Voigt. 2025. Fat TissueBased In-Body Covert Communication. In 2025 IEEE 26th International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM). 61–71. [14] Tamara V Sobers, Boulat A Bash, Saikat Guha, Don Towsley, and Dennis Goeckel. 2017. Covert communication in the presence of an uninformed jammer. IEEE Trans. on Wireless Communications 16, 9 (2017), 6193–6206. [15] Ramin Soltani, Dennis Goeckel, Don Towsley, Boulat A Bash, and Saikat Guha. 2018. Covert wireless communication with artificial noise generation. IEEE Trans. on Wireless Communications 17, 11 (2018), 7252–7267. [16] Mehrdad Tahmasbi, Boulat A Bash, Saikat Guha, and Matthieu Bloch. 2021. Signaling for covert quantum sensing. In IEEE International Symposium on Information Theory (ISIT). 1041–1045. [17] Ligong Wang, Gregory W. Wornell, and Lizhong Zheng. 2016. Fundamental limits of communication with low probability of detection. IEEE Trans. Information Theory 62, 6 (2016), 3493–3503. [18] Mark M. Wilde. 2017. Quantum Information Theory (2nd ed.). Cambridge University Press, Cambridge.
A Proof of Theorem 1 (Optimal risk-constrained throughput) Consider the risk-constrained program (10)–(12) with objective 𝑇 (𝑞, 𝑅) = 𝑞𝑅, probabilistic constraints h i P 𝑞 > √2𝛿𝑛 𝑐 cov (𝜂, 𝑛𝐵 ) ≤ 𝜖cov , P[𝑅 > 𝑅ach (𝜂, 𝑛𝐵 )] ≤ 𝜖rel , and box constraints 0 ≤ 𝑞 ≤ 1, 0 ≤ 𝑅 ≤ 1. Write
𝑐 cov ≡ 𝑐 cov (𝜂, 𝑛 𝐵 ),
𝑅ach ≡ 𝑅ach (𝜂, 𝑛 𝐵 ).
Define, for any random variable 𝑋 , the strict-outage distribution function 𝐹𝑋< (𝑥) ¬ P[𝑋 < 𝑥], and the corresponding strict-outage quantile 𝑄𝑋< (𝜖) ¬ sup{𝑥 : 𝐹𝑋< (𝑥) ≤ 𝜖}. Step 1: Convert the probabilistic constraints into deterministic bounds. For the covertness constraint, √ √ 𝑞 𝑛 𝑞 𝑛 2𝛿 = 𝐹𝑐<cov . P 𝑞 > √ 𝑐 cov = P 𝑐 cov < 2𝛿 2𝛿 𝑛 Therefore,
which is equivalent to
2𝛿 P 𝑞 > √ 𝑐 cov ≤ 𝜖cov 𝑛
⇐⇒
𝐹𝑐<cov
√ 𝑞 𝑛 ≤ 𝜖cov , 2𝛿
√ 𝑞 𝑛 ≤ 𝑄𝑐<cov (𝜖cov ). 2𝛿
Hence,
2𝛿 𝑞 ≤ √ 𝑄𝑐<cov (𝜖cov ). 𝑛
Combining with the box constraint 𝑞 ≤ 1 gives
2𝛿 𝑞 ≤ min 1, √ 𝑄𝑐<cov (𝜖cov ) =: 𝑞 max . 𝑛
For the reliability constraint, P[𝑅 > 𝑅ach ] = P[𝑅ach < 𝑅] = 𝐹𝑅<ach (𝑅). Manuscript submitted to ACM
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty
29
Therefore, P[𝑅 > 𝑅ach ] ≤ 𝜖rel
𝐹𝑅<ach (𝑅) ≤ 𝜖rel ,
⇐⇒
which is equivalent to 𝑅 ≤ 𝑄 𝑅<ach (𝜖rel ) =: 𝑅max . Step 2: Maximize over the induced feasible rectangle. The feasible set induced by the probabilistic constraints and the box constraints is [0, 𝑞 max ] × [0, 𝑅max ]. If 𝑅max = 0, the rectangle collapses to the zero-rate edge and the optimal throughput is 𝑇 ∗ = 0, so no nontrivial covert link is feasible under the specified budgets. Otherwise, since 𝑇 (𝑞, 𝑅) = 𝑞𝑅 is nondecreasing in both arguments for 𝑞 ≥ 0
and 𝑅 ≥ 0, its maximum over this rectangle is attained at the upper-right corner (𝑞 max, 𝑅max ). Therefore, (𝑞 ∗, 𝑅 ∗ ) = (𝑞 max, 𝑅max ),
𝑇 ∗ = 𝑞 max𝑅max .
This proves Theorem 1.
To obtain Corollary 1, note that when the relevant outage thresholds lie at continuity points of the corresponding CDFs, we have 𝐹𝑋< (𝑥) = 𝐹𝑋 (𝑥) at those points, and the strict-outage quantile 𝑄𝑋< (𝜖) reduces to the usual left-continuous quantile 𝐹𝑋−1 (𝜖). Substituting this into the theorem yields (18) and (19).
B Proof of Theorem 2 (First-order conditions for differentiable interior optima) Under the continuity assumptions required here, the strict-outage probabilities P[𝑐 cov < 𝑥]
and
P[𝑅ach < 𝑟 ]
and
𝐹𝑅ach (𝑟 ),
coincide with the ordinary CDF evaluations 𝐹𝑐 cov (𝑥) respectively. Define
h i 𝐽 (𝑞, 𝑅) ¬ 𝑞𝑅 − 𝜆cov P 𝑞 > √2𝛿𝑛 𝑐 cov − 𝜆rel P[𝑅 > 𝑅ach ] ,
over the box D = {(𝑞, 𝑅) : 0 ≤ 𝑞 ≤ 1, 0 ≤ 𝑅 ≤ 1}, where 𝜆cov, 𝜆rel ≥ 0. Assuming continuity and differentiability at the evaluation points, we can write
𝐽 (𝑞, 𝑅) = 𝑞𝑅 − 𝜆cov 𝐹𝑐 cov
√ 𝑞 𝑛 2𝛿
− 𝜆rel 𝐹𝑅ach (𝑅).
Assume that 𝐹𝑐 cov and 𝐹𝑅ach are differentiable at the evaluation points (the non-differentiable case can be handled via subgradients). If (𝑞 ∗, 𝑅 ∗ ) is an interior maximizer with 0 < 𝑞 ∗ < 1 and 0 < 𝑅 ∗ < 1, the first-order optimality conditions reduce to stationarity:
√ ∗√ 𝜕𝐽 ∗ ∗ 𝑛 𝑞 𝑛 (𝑞 , 𝑅 ) = 𝑅 ∗ − 𝜆cov 𝑓𝑐 cov 2𝛿 = 0, 𝜕𝑞 2𝛿 𝜕𝐽 ∗ ∗ (𝑞 , 𝑅 ) = 𝑞 ∗ − 𝜆rel 𝑓𝑅ach (𝑅 ∗ ) = 0, 𝜕𝑅 Manuscript submitted to ACM
30
Arghavani et al.
where 𝑓𝑐 cov and 𝑓𝑅ach are the PDFs (derivatives of the CDFs) at the corresponding points. Rearranging yields √ ∗√ 𝑛 𝑞 𝑛 ∗ 𝑅 = 𝜆cov 𝑞 ∗ = 𝜆rel 𝑓𝑅ach (𝑅 ∗ ), 𝑓𝑐 cov 2𝛿 , 2𝛿 which are the stated first-order conditions (20)–(21).
If no interior stationary point exists (e.g., due to non-differentiability or the equations having no solution in (0, 1) ×
(0, 1)), the maximizer lies on the boundary of D, where at least one of 𝑞 or 𝑅 is at a bound, including the possibility
of the trivial zero-rate point 𝑅 = 0. In that case, the problem reduces to one-dimensional maximization along the
active boundary and can be checked directly. In the numerical results, we therefore evaluate the risk-adjusted objective directly on a dense grid over (𝑞, 𝑅) ∈ [0, 1] × [0, 1] to avoid artifacts caused by non-smooth empirical CDFs
and boundary-pinned solutions. The first-order conditions, (20) and (21), remain useful for structural interpretation whenever an interior differentiable optimum exists.
C Proof of Lemma 1 We provide the detailed derivation for the closed-form quantile functions presented in Lemma 1.
Derivation of the Covertness Quantile Let 𝑋 = 𝑛𝐵 ∼ Exp(𝜆) and define
p 𝑐 cov (𝜂 0, 𝑋 ) = 𝑘 𝑋 + 𝜂 0𝑋 2,
√
2𝜂 0 . 1 − 𝜂0 This is a monotonically increasing function of 𝑋 for 𝑋 ≥ 0. Let 𝐹𝑐 cov (𝑐) denote the CDF of the induced random variable
𝑐 cov (𝜂 0, 𝑋 ), i.e.,
𝑘=
𝐹𝑐 cov (𝑐) = P 𝑐 cov (𝜂 0, 𝑋 ) ≤ 𝑐 . p 𝑐2 P 𝑘 𝑋 + 𝜂 0𝑋 2 ≤ 𝑐 = P 𝑋 + 𝜂 0𝑋 2 ≤ 2 𝑘 2 𝑐 = P 𝜂 0𝑋 2 + 𝑋 − 2 ≤ 0 . 𝑘
The positive root of the quadratic 𝜂 0𝑥 2 + 𝑥 − (𝑐/𝑘) 2 = 0 is p −1 + 1 + 4𝜂 0 (𝑐/𝑘) 2 𝑥 root = , 2𝜂 0 so the inequality holds for 0 ≤ 𝑋 ≤ 𝑥 root . Therefore, 𝐹𝑐 cov (𝑐) = P(𝑋 ≤ 𝑥 root ) = 1 − 𝑒 −𝜆𝑥root . To find the quantile 𝐹𝑐−1 (𝜖), we set cov
Manuscript submitted to ACM
𝐹𝑐 cov (𝑐) = 𝜖
A Risk-Aware Framework for Covert Quantum Communication under Stochastic Channel Uncertainty and solve for 𝑐.
31
! p −1 + 1 + 4𝜂 0 (𝑐/𝑘) 2 2𝜂 0 p 𝜆 −1 + 1 + 4𝜂 0 (𝑐/𝑘) 2 ln(1 − 𝜖) = − 2𝜂 0 p 2𝜂 0 ln(1 − 𝜖) = 1 + 4𝜂 0 (𝑐/𝑘) 2 1− 𝜆 𝜖 = 1 − exp −𝜆
2𝜂
Let 𝑍 = 1 − 𝜆0 ln(1 − 𝜖). Squaring both sides and solving for 𝑐 yields: s 𝑘 2 (𝑍 2 − 1) 𝑍2 − 1 2 =⇒ 𝑐 = 𝑘 . 𝑐 = 4𝜂 0 4𝜂 0
This is the closed-form expression for 𝐹𝑐−1 (𝜖 ). Therefore, after enforcing the box constraint 𝑞 ≤ 1, the optimal cov cov transmission probability is
(
2𝛿 𝑞 max = min 1, √ 𝑘 𝑛
s
) 𝑍2 − 1 . 4𝜂 0
Derivation of the Reliability Quantile. Let 𝑅ach = 𝑅ach (𝜂 0, 𝑋 ), where 𝑋 = 𝑛𝐵 ∼ Exp(𝜆). Since 𝑅ach (𝜂 0, 𝑋 ) is monoton-
ically decreasing in 𝑋 , its 𝜖rel -quantile is obtained by evaluating 𝑅ach at the (1 − 𝜖rel )-quantile of the noise distribution. Specifically, if
1 𝑥𝜖 = 𝐹𝑋−1 (1 − 𝜖rel ) = − ln(𝜖rel ), 𝜆
then 𝐹𝑅−1 (𝜖rel ) = 𝑅ach (𝜂 0, 𝑥𝜖 ) = ach Hence, 𝑅max =
h
h
1 − 𝐻 𝑝® (𝜂 0, − 𝜆1 ln(𝜖rel ))
1 − 𝐻 𝑝®(𝜂 0, − 𝜆1 ln(𝜖rel ))
i+
i+
.
.
Manuscript submitted to ACM