QUFIG: GNN-Based Prediction of Quantum Fault Injection Vulnerabilities with Gate-Level Precision

arXiv:2610.01777 · quant-ph, cs.CR · Submitted 2026-10-01 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Quantum Radio. Generated commentary on the latest quantum physics and condensed matter papers.

Kai: Today's paper: "QUFIG: GNN-Based Prediction of Quantum Fault Injection Vulnerabilities with Gate-Level Precision".

Mira: The gist The framework uses a circuit-DAG-based GNN backbone to predict the vulnerability score of each gate to each type of injected fault,

Kai: First, who's behind it and why it matters.

Paper summary: Kai: So we're looking at this paper called QUFIG: GNN-Based Prediction of Quantum Fault Injection Vulnerabilities with Gate-Level Precision. It’s about how to spot problems in quantum circuits before you even run them on real hardware, specifically focusing on fault injection attacks.

Mira: Basically, the main idea is they're trying to figure out which gate-fault pairs are the most dangerous for circuit fidelity without having to simulate every single possibility exhaustively.

Kai: Right, so they’re framing this as a learning guided prioritization problem under a restricted fidelity budget, which means you only have so much time or resources to check things out.

Lev: From an error correction standpoint, that's interesting because running exhaustive simulations on real hardware is just not feasible for large circuits.

Kai: Exactly. They define the impact of a gate-fault pair as something like the fidelity loss and the application-level output deviation, which they call I(g, e) = F (g, e) + lambda E(g, e) <ref:2610.01777#pg2>.

Mira: That lambda term is important because it lets you weight how much you care about the actual output quality versus just the raw fidelity loss <ref:2610.01777#pg2>.

Kai: And they use a circuit DAG-based GNN backbone to predict this vulnerability score for each gate and each type of injected fault, which is how they build this framework, QuFIG.

Lev: A graph neural network on a DAG structure sounds like it’s designed to understand the dependencies between gates in the compiled quantum circuit <ref:2610.01777#pg3>.

Kai: They process the graph structure, giving each gate instance structured feature vectors that capture its local context from its neighbors, which helps them incorporate that dependency information.

Mira: So they’re using the graph learning to see how a fault on one part of the circuit might propagate or affect others downstream.

Kai: After they have these predictions for every possible gate-fault pair, they use a hybrid loss function combining binary cross-entropy and mean absolute error to train the model.

Lev: That loss function suggests they are training the AI to be both accurate in classifying if a fault is bad or good, while also being precise about the magnitude of that impact <ref:2610.01777#pg2>.

Kai: The whole process culminates in a budget-constrained top-k selection step where they use those predicted scores to pick the highest impact candidates for actual simulation or auditing.

Mira: It’s smart because it moves from a huge search space of all possible faults down to just the most critical ones that matter most for fidelity loss.

Lev: For someone running this on real hardware, this means you don't waste time testing gates that are probably safe or have minimal impact <ref:2610.01777#pg3>.

Kai: So, what does this actually mean for the people who use these cloud quantum platforms? It lets them preemptively deploy defenses before they run their workloads.

Mira: It gives users a way to identify those weak points in the circuit and apply targeted mitigation before the actual fault injection happens <ref:2610.01777#pg3>.

Lev: If this prediction works well, it could save a lot of time and computational resources when trying to secure these systems <ref:2610.01777#pg3>.

Kai: We'll talk about what the authors actually built and how it performs in the next part of our discussion.

Mira: Let's look at the conclusion to see what they really claim about this QUFIG framework.

Conclusion: Kai: So we’ve seen how this QUFIG framework uses a graph neural network to predict which gate faults are most likely to mess up your quantum circuit fidelity, and now we're at the end of the paper and what it actually means for us.

Mira: The title itself is pretty descriptive, QUFIG, GNN-Based Prediction of Quantum Fault Injection Vulnerabilities with Gate-Level Precision. It’s a lot packed into a name.

Lev: It sounds like they are trying to get very specific with their predictions, focusing on the individual gates rather than just the whole circuit being vulnerable or not.

Kai: Exactly. Instead of saying "this circuit is risky," it's about pinpointing, say, "gate three needs extra attention for this type of noise."

Mira: That’s the core idea. They’re moving from broad risk assessment to a more granular view where you know exactly which gate-fault pair has the highest predicted impact score.

Lev: From what I've seen in error correction, that level of precision is crucial because when you have limited resources for mitigation, you need to know precisely where to spend them.

Kai: It’s about prioritizing your inspections or your fault simulation efforts so you’re not wasting time on gates that are probably fine.

Mira: The authors suggest this learned prioritization helps reduce the number of detailed gate inspections needed to reach a target recovery level on real hardware, which is a big deal for practical applications.

Lev: That reduction sounds significant if it holds up under actual measurement conditions, but we have to remember they’re training this on simulations first.

Kai: Right, so the authors show that by using these learned vulnerability scores, you can focus your efforts on the gates that truly dominate fidelity loss before you even deploy anything.

Mira: It shifts the workflow from a brute-force search to a targeted approach guided by what the AI has learned about circuit structure and fault effects.

Lev: So, while it’s not yet running on real qubits, this framework gives us a much smarter map for where to look when we finally get access to those experimental systems.

Kai: We'll talk next about how they actually built this GNN backbone and what the training process looked like under the hood.

Shihan Zhao, Qiying Li, Ben Dong, Qian Wang, Yuntao Liu

Department of Electrical & Computer Engineering, Northeastern University · Department of Electrical & Computer Engineering, Lehigh University · Department of Electrical Engineering, University of California, Merced

quant-ph, cs.CR

Submitted: 2026-10-01

Updated: 2026-10-01

Comments: Accepted by IEEE International Conference on Computer Design (ICCD) 2026

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 89/100

The gist: The gist The framework uses a circuit-DAG-based GNN backbone to predict the vulnerability score of each gate to each type of injected fault, defined as the impact of the gate-fault pair on circuit

Key concepts

Circuit DAG
A Directed Acyclic Graph (DAG) representation of a quantum circuit where each node represents a gate and directed edges show execution dependencies between gates. This structure is used as the input for the GNN backbone to understand how faults propagate through the circuit.
Fault Impact Score I(g, e)
A metric quantifying how much a specific fault (type 'e') on a specific gate ('g') harms the final circuit fidelity. It combines two measures: $\Delta F$, which is the loss in fidelity between the ideal and faulty circuits, and $\Delta E$, which measures the deviation in output expectation values.
GNN Backbone
A Graph Neural Network structure that processes the circuit DAG. Each gate node has features describing its local context, and the GNN aggregates information from neighboring gates to predict a gate's vulnerability score based on its structural position and dependencies within the circuit.

Terminology

Summary

The gist The framework uses a circuit-DAG-based GNN backbone to predict the vulnerability score of each gate to each type of injected fault, defined as the impact of the gate-fault pair on circuit fidelity.

Problem Formulation

The research addresses the challenge that existing works fail to identify vulnerabilities with gate-level precision or adapt to run-time environments This paper formulates gate-level fault analysis as a learning guided prioritization problem under restricted fidelity budgets The objective is to rank gate-fault pairs by their predicted impact on circuit fidelity and output quality A candidate fault is defined as a gate-fault tuple f = (g, e, η), where g ∈ G is the target gate instance, e is the fault type, and η denotes the fault strength such as the error probability of a stochastic channel or the rotation offset of a coherent perturbation The impact score I(g, e) is defined as I(g, e) = ∆F (g, e) + λ∆E(g, e), where ∆F (g, e) = 1 − Fid(C0, C˜ g,e).

Framework Architecture

The proposed framework QuFIG uses a circuit-DAG-based GNN backbone to predict the vulnerability score of each gate to each type of injected fault The overall process consists of five stages: circuit DAG construction, gate-level feature embedding, GNN-based faultimpact prediction, fault-aware training, and budget-constrained top-k selection The circuit is converted into a directed acyclic graph (DAG) G = (V, E), where each node v ∈ V corresponds to a gate instance and each directed edge represents a qubit-wise execution dependency Gate nodes are associated with structured feature vectors that capture its local circuit context The GNN backbone processes this graph structure to incorporate dependency information from neighboring gates in the circuit DAG

Fault Modeling and Scoring

The paper defines a structured NISQ fault model covering three classes of faults: stochastic decoherence faults, Pauli-type faults, and aggregate stochastic faults These fault classes cover the four noise channels used in experiments, including amplitude damping, phase damping, bit flip, and depolarizing noise Fault impact is quantified by comparing the faulty and ideal outputs using two forms of observability: distribution-level fidelity loss ∆F (g, e) = 1 − Fid(C0, C˜ g,e) and normalized output deviation ∆E(g, e) = Eg,e − E0 / E0 + ϵ The fault impact score I(g, e) is defined as I(g, e) = ∆F (g, e) + λ∆E(g, e), where λ controls the relative importance of application-level deviation High-impact faults are ranked by defining a binary mask mv,k to indicate whether fault type k is applicable to gate v

Learning and Prioritization

The model predicts a fault-specific score for each valid gate-fault pair, denoted as pv,k = σ(zv,k), where zv,k is the output of a fault-specific prediction head A hybrid loss combining binary cross-entropy (BCE) and mean absolute error (MAE) is used to train the model The loss function is L = LBCE + LMAE, where LBCE = 1/K Σ k 1/P v mv,k X v mv,k lBCE(zv,k, yv,k; αk) and LMAE = 1/K Σ k 1/P v mv,k pv,k − yv,k After inference, the predicted scores are used to rank all valid gate-fault pairs in the circuit The final step is budget-constrained top-k selection, where SB = TopB(v,k) (pv,k), s.t. mv,k = 1

Experimental Results

Experiments were conducted on QASMbench and HamLib MaxCut circuits to evaluate QuFIG under a budgeted vulnerable gate recovery setting The results show that QuFIG can reduce the number of gates requiring inspection by 2.9–19.8% while maintaining effective fault identification On MaxCut, for the top-16% vulnerable-gate recovery target, QuFIG reduces gate-inspection cost by 6.9%–19.8% relative to random selection and by 2.9%–18.8% relative to depth-based traversal The SAGE backbone was found to be the most consistent performer across both datasets, achieving the best performance on both MAE and AUPRC Overall, QuFIG ranks gates by predicted vulnerability and recovers a large fraction of the worst gates with fewer inspections

Conclusion

In this work, we presented QuFIG for budget-constrained gate vulnerability prioritization in quantum circuits The results show that learned vulnerability scores can prioritize high-impact gates and reduce the number of detailed gate inspections needed to reach a target recovery level By identifying the gates that dominate fidelity loss before deployment, QuFIG lets users of untrusted cloud quantum platforms concentrate fault simulation, mitigation, and security auditing where it matters most

ACKNOWLEDGMENT This work is supported by the National Science Foundation under Awards 2530705, 2554928, and 2554929

REFERENCES [1] A. Peruzzo, J. McClean, P. Shadbolt, M.-H. Yung, X.-Q. Zhou, P. J. Love, A. Aspuru-Guzik, and J. L. O’brien, “A variational eigenvalue solver on a photonic quantum processor,” Nature communications, vol 5 no 1 p 4213 2014 [2] Y. Zhou, J. Chen, J. Cheng, X. Cao, Y. Zhang, G. Karemore, M. Zitnik, F. T. Chong, J. Liu, T Fu et al., “Quantum-machine-assisted drug discovery,” npj Drug Discovery vol 3 no 1 p 1 2026 [3] A Andreassen, I Feige, C Frye, and M D Schwartz, “Junipr: a framework for unsupervised machine learning in particle physics,” The European Physical Journal C vol 79 no 2 p 102 2019 [4] J Biamonte, P Wittek, N Pancotti, P Rebentrost, N Wiebe, and S Lloyd, “Quantum machine learning,” Nature vol 549 no 7671 pp 195–202 2017 [5] “Ibm quantum” 2021 [Online] Available: https://quantum.ibm.

Improvements for AI systems

  1. Improve quantum circuit verification by employing QuFIG to rank gate-fault pairs by their predicted impact on circuit fidelity and output quality, allowing designers to select the top-ranked candidates for detailed simulation or auditing instead of exhaustive analysis.

  2. Develop a fault injection framework that utilizes a circuit-DAG-based GNN backbone to create a vulnerability heatmap over the circuit’s DAG, highlighting fragile operations that may be exploited by noise or adversarial manipulation.

  3. Enhance circuit optimization and security by training the GNN predictor using a hybrid loss function, combining binary cross-entropy (BCE) and mean absolute error (MAE), which ensures well-calibrated prediction confidence while focusing on both classification correctness and penalizing low-confidence predictions.

  4. Implement a budget-constrained fault analysis system that selects the optimal set of faults by maximizing the impact score, defined as I(g, e) = ∆F (g, e) + λ∆E(g,e), thereby reducing the number of gates requiring inspection by 2.9–19.8%.

  5. Create a predictive system that identifies structural vulnerabilities beyond simple heuristics by ranking gates based on predicted impact scores like those derived from the GNN's output logits, which captures vulnerability patterns that cannot be explained by simply scanning gates according to circuit depth or backend error rates.

Sources

Related papers