CutBackdoor: A Circuit Cut Triggered Backdoor Attack on Variational Quantum Algorithms
2026-07-20 • Cryptography and Security
Cryptography and Security
AI summaryⓘ
The authors study a new kind of security risk for Variational Quantum Algorithms (VQAs), which are used on near-term quantum computers. They introduce CutBackdoor, a hidden backdoor attack that exploits circuit cutting—a method to run big quantum circuits on small hardware—without changing the circuit itself. This backdoor only activates when the circuit cutting process is used, causing errors in certain parts of the computation while keeping overall results normal, making the attack hard to detect. They tested this attack on real IBM quantum devices and found it consistently worsens errors in the cut parts, with limited ways to reduce its effect.
Variational Quantum AlgorithmsQuantum circuit cuttingParameterized quantum circuitsBackdoor attackQuantum machine learningQuantum chemistryNoisy intermediate-scale quantumZero-Noise ExtrapolationQAOAVQE
Authors
Ahatesham Bhuiyan, Hoang Ngo, Cheng Chu, Qian Lou, Lei Jiang, My T. Thai, Mengxin Zheng
Abstract
Variational Quantum Algorithms (VQAs) are a leading paradigm for near-term quantum computing, combining parameterized quantum circuits with classical optimization across quantum chemistry, combinatorial optimization, and quantum machine learning. Since real-world VQA deployments routinely require circuits that exceed available hardware capacity, quantum circuit cutting has become an indispensable execution strategy, and pre-trained parameters are increasingly distributed through public repositories, introducing supply-chain security risks that have received little attention. Prior quantum backdoor attacks either introduce detectable circuit modifications or depend on device-specific noise, and none consider circuit cutting as an attack surface. We present CutBackdoor, the first parameter-supply-chain backdoor that uses cut circuit execution from CutQC as the deployment-time trigger against VQAs. Under noisy finite-shot circuit-cut execution, poisoned parameters preserve full-circuit validation performance while substantially increasing cut-path reconstruction error, without any circuit modification. The trigger activates when a resource-limited victim responds to a qubit-capacity mismatch by invoking the cutting workflow, requiring no attacker presence at deployment. We provide a theoretical analysis and empirically validate it across varying shot budgets. Evaluation across multiple VQA benchmarks on IBM quantum backends demonstrates cut-path energy amplification of $1.3\times$ to $2.9\times$ \revA{over clean baselines on the VQE and VQD benchmarks while maintaining small stealthiness error on the full-circuit path. The cut-path gap persists across the evaluated backends and cut placements under matched compilation; Zero-Noise Extrapolation provides only partial mitigation, and the diagonal-cost QAOA benchmark delineates the attack's structural boundary