Source-linked AI summary

When Measurement Constraints Favor Quantum Computational Sensing for Stealthy Power-Grid Attack Detection

Saisubramaniam Gopalakrishnan, Supreeth B S, Pranav Sarda, Ashesh Xalxo, Dagnachew Birru

arXiv:2609.10606v1quant-phcs.CR

TL;DR

Stealthy grid attacks can preserve plausible digital telemetry, motivating independent physical sensing and task-specific coherent processing. The paper evaluates NV sensing and QCS across attack mechanisms, grid scales, and matched measurement budgets, finding that QCS is most useful when physical measurements are scarce but not whenever quantum sensitivity is higher. Its simulated scope and trusted-sensor assumptions bound the conclusions.

  • Problem

    Digital telemetry can remain plausible under stealthy attacks, leaving open when independent NV sensing and coherent processing provide useful detection evidence.

  • Method

    The study compares digital, reported-versus-physical, and physical NV evidence channels, then evaluates QCS, conventional readout, and tomography across three IEEE grids under matched measurement resources.

  • Results

    Across attacks and grid scales, evidence shifts from telemetry to physical state information; QCS is most competitive under constrained total measurements, while greater Fisher information does not ensure greater class separation.

  • Takeaways & Limitations

    Realized QCS utility depends jointly on physical perturbation, state separation, coherent control, and measurement resources rather than quantum sensitivity alone.

  • Takeaways & Limitations

    Results use QuTiP-validated Lindblad simulations rather than physical hardware, assume a trusted sensing appliance, and treat cross-sensor coherent processing only diagnostically.

Abstract

from arXiv · show

Power-grid defenses that rely on digital telemetry remain vulnerable to stealthy attacks that preserve plausible reported states while altering the underlying physical system. We study when Nitrogen-Vacancy (NV) sensing provides a useful independent physical channel, and when coherent processing before measurement adds value. Across IEEE 14-, 30-, and 118-bus simulations with Lindblad NV models, we evaluate standard FDIA, BDD-stealth, statistical-stealth, and concealed topology attacks. The results reveal an observability hierarchy: evidence shifts from digital telemetry, to reported-versus-physical consistency, to the physical NV state. Quantum Computational Sensing (QCS) follows this selectivity, becoming informative only when the physical state itself carries attack evidence. We then compare QCS, conventional 4-setting NV readout, and tomography under matched measurement budgets. At a matched total budget of only 40 physical trials per sensor on case14, QCS reaches AP $0.944$, versus 0.800 for conventional NV readout and 0.751 for tomography; the same low-budget ordering holds on case30 and case118. Multi-setting methods recover as additional measurements become affordable, showing that the QCS benefit is a measurement-efficiency advantage rather than a universal accuracy advantage. Finally, we ask where the benefit varies across the three case simulations. Although the quantum-to-classical Fisher-information ratio increases from 1.21x to 1.54x, Normal--Attack Helstrom separation collapses in the harder regimes, and interleaved control substantially increases that separation only on case14, thereby quantum sensitivity does not necessarily imply task-relevant distinguishability. Our results show that realized QCS utility depends on the full chain from physical perturbation to state separation, coherent processing, and measurement under the resource constraints of the task.

1 Introduction

The paper asks whether independent NV sensing and coherent processing can detect attacks that remain plausible in digital telemetry. It identifies attack-dependent evidence channels and studies QCS under constrained measurements.

  • Quantum computational sensing: QCS interleaves sensing with trainable coherent processing before final measurement, learning directly from the native quantum sensor state.This differs from converting the sensor state into classical features before classification.
  • Attack-dependent observability: Attack mechanisms shift useful evidence from digital telemetry to reported-versus-physical consistency and, for concealed topology attacks, the physical NV state.This hierarchy motivates matching the sensing method to the evidence that survives each attack.
  • Measurement-constrained utility: Under constrained total measurements, QCS is most competitive because its single-setting readout avoids splitting trials across multiple bases.Conventional multi-setting readout recovers as additional trials become affordable, so the benefit is resource-specific.
  • Sensitivity versus distinguishability: The quantum-to-classical Fisher-information ratio rises from 1.21× to 1.54×, while Normal–CTA Helstrom separation falls in harder regimes.The paper therefore distinguishes quantum sensitivity from task-relevant class separability.

2 Related Work

Prior grid-security work studies stealthy telemetry manipulation and quantum methods applied to reported data. This paper instead examines task-specific coherent processing of native quantum sensor states under physical measurement constraints.

  • Stealthy grid attacks: Stealthy FDIA can preserve digital-model consistency, while concealed topology attacks mask real physical network changes behind falsified measurements.These threats motivate observation channels beyond reported telemetry.
  • Quantum methods for grid security: Existing quantum-machine-learning grid methods classify derived SCADA features, leaving their inputs exposed to attacks on digital telemetry.The paper’s setting adds an independently generated physical sensing channel.
  • Quantum computational sensing: QCS interleaves physical sensing with trainable coherent control so the final measurement is optimized for the downstream task rather than general-purpose state reconstruction.The study instantiates this paradigm on an NV spin-1 state with explicit measurement constraints.
  • Distributed sensing: Distributed entangled-sensing approaches assume shared quantum resources, whereas the primary deployment model processes spatially separated NV sensors locally and combines classical outputs.Joint coherent models are treated as diagnostic upper bounds rather than deployment assumptions.

3 System Model and Quantum Framework

The framework pairs compromised SCADA telemetry with an independently generated NV state from true line currents. It compares conventional, tomographic, and QCS routes while keeping primary processing local to each sensor.

  • Threat and system model: The system maps true line current through a physical magnetic field to an NV state, alongside reported SCADA telemetry that may be manipulated.The physical channel supplies information unavailable from compromised telemetry alone.
  • Attack taxonomy: The attack taxonomy includes standard FDIA, model-aware BDD-stealth FDIA, statistical-stealth FDIA, and concealed topology attacks.For cyber-only attacks the physical current is unchanged, whereas concealed topology attacks make the physical NV state relevant evidence.
  • NV sensing model: The NV electronic ground state is modeled as a field-dependent spin-1 qutrit with Lindblad evolution including zero-field splitting, Zeeman coupling, and relaxation/dephasing.Sensing and computational Hilbert spaces coincide, allowing coherent processing directly on the physical state.
  • Decision routes: Conventional readout produces classical field-sensitive features, tomography reconstructs the qutrit state, and QCS interleaves sensing with trainable coherent control before one final measurement.The primary architecture processes spatially separated sensors locally; joint coherent models are diagnostic upper bounds.
  • Learned measurement: A trainable two-outcome POVM can map the post-control quantum state directly to predictions, eliminating the downstream classical classifier.This makes the measurement itself part of the learned decision process.

4 Experimental Setup

Experiments compare evidence channels and sensing routes on three IEEE grids using simulated NV magnetometers and explicit physical-measurement accounting. The setup separates classifier choice from the cost of extracting decisions from the same sensing process.

  • Grid and dataset design: The study uses IEEE 14-, 30-, and 118-bus systems with K = 5, 8, and 20 QuTiP-simulated NV sensors at a fixed 0.10 m standoff.Each case contains 5700 operating points with a 70/30 train–test split.
  • Grid and dataset design: Fault-induced magnetic-field effect size falls from 0.230 to 0.067 to 0.001 across the three cases, so cross-case differences reflect sensing difficulty as well as grid scale.The cases are therefore not interpreted as a pure size-scaling experiment.
  • Evidence-channel comparisons: The evaluation compares digital-only baselines, reported-versus-physical discrepancy methods, and classical classification from finite-shot NV features.The main conventional physical-sensing baseline uses four readout settings.
  • Measurement accounting: Total measurement cost is C_measure = N_preparation × N_settings × N_shots, with QCS using one setting, conventional NV readout four, and tomography seven.Results are reported under both equal shots per setting and equal total measurement effort.
  • Evaluation protocol: Average Precision is the primary metric, while finite-measurement results remain separate from oracle simulator quantities.QCS timing reflects classical simulation and optimization rather than physical execution latency.

5 Results and Analysis

The results show that surviving attack evidence depends on the attack mechanism, while QCS utility depends on measurement constraints and task-relevant physical state separation. QCS is most advantageous under limited total trials, but richer readouts can recover as budgets grow.

  • RQ1: Which Security Evidence Survives Stealth Attacks?: AP 0.995, 0.781, and 0.763 are achieved by four-setting NV readout on case14, case30, and case118 for concealed topology attacks, while cyber-only attacks remain near chance.The results identify the physical NV state as the useful evidence channel for concealed topology attacks.
  • RQ2: When Does QCS Help Under Measurement Constraints?: QCS is most competitive under matched total measurement budgets because it concentrates all T trials in one learned setting instead of splitting them across four or seven settings.This advantage is strongest in the low-to-moderate budget regime across all three systems.
  • RQ2: When Does QCS Help Under Measurement Constraints?: As the budget grows, multi-setting readout can match or exceed QCS, showing that its benefit is measurement efficiency rather than a universally higher accuracy ceiling.Under matched precision, conventional NV readout and tomography receive 4T and 7T total trials, respectively, and much of QCS’s advantage disappears.
  • RQ3: What Limits Realized Quantum Utility?: FQ/FC increases from 1.21× to 1.54× while Normal–CTA separation falls to 0.003 on case118, so greater quantum sensitivity does not ensure task-relevant distinguishability.The larger Fisher-information gap can reflect sensitivity to the field without stronger separation between the security classes.
  • RQ3: What Limits Realized Quantum Utility?: Interleaving increases DQ from 0.016 to 0.229 on case14, whereas case30 and case118 retain essentially unchanged class-averaged states.The results attribute useful QCS performance to physical state separation that coherent control can reshape and the final measurement can access.

6 Discussion

The discussion identifies when QCS helps: when attacks leave evidence in the physical sensor state and measurements are scarce. Its utility remains bounded by physical state separation, control accessibility, and simulation-to-hardware limitations.

  • QCS is most valuable when the physical state carries attack evidence and the measurement budget is scarce.Its advantage comes from using a single learned measurement setting; conventional readout and tomography recover as more measurements become affordable.
  • Greater quantum sensitivity does not guarantee useful classification because Helstrom separation can collapse as physical perturbations weaken.Interleaved control can reshape separation when the sensing physics provides it, but cannot create effectively absent separation.
  • The study assumes a trusted sensing appliance and evaluates Lindblad NV simulations rather than physical hardware.Hardware-noise studies are calibrated to reported fidelities, but hardware validation remains future work.

7 Conclusion

The conclusion frames QCS as useful only in a specific evidence and resource regime, while emphasizing that independent physical sensing can also be implemented classically. The paper’s comparisons therefore distinguish sensing-channel independence from quantum readout itself.

  • QCS is useful when attacks shift evidence from telemetry and consistency checks into the physical NV state, especially under scarce measurements.Across attack mechanisms and IEEE systems, the surviving evidence moves from digital telemetry to reported-versus-physical consistency and then to the physical sensor state.
  • The matched-precision comparison does not establish that quantum magnetometers universally outperform classical magnetic sensors.It tests whether the richer NV sensing interface retains task-relevant information absent from an equally precise scalar field readout.
  • The study compares matched-precision classical magnetometry with NV-based approaches to separate independent physical sensing from richer quantum readout.The classical baseline observes the same local magnetic field but returns a noisy scalar estimate without quantum-state evolution or population readout.

A.2 Result and interpretation

The matched-precision analysis finds that multi-setting NV readout outperforms a scalar classical magnetometer across all three grid scales, while cautioning that this comparison does not isolate quantumness alone.

  • Multi-setting NV readout exceeds the scalar classical magnetometer by 0.113, 0.144, and 0.176 AP on case14, case30, and case118, respectively.The widening margin is consistent with restricted classical readout capturing a decreasing fraction of information available in the quantum sensor state as scale increases.
  • The comparison tests a richer four-channel NV interface against a single noisy scalar field estimate, not quantum versus classical sensing in general.Classical current sensors could also provide independent authenticated physical corroboration of SCADA telemetry.
  • NV magnetometry is selected for room-temperature operation and potential dynamic-range extension, whereas SQUID and SERF sensors occupy different operating regimes.SQUID operation typically requires cryogenic conditions, while SERF magnetometers target near-zero-field environments.

B Realistic reported-versus-physical consistency

The realistic consistency study replaces oracle physical fields with finite-measurement estimates and shows that attack mechanism determines which discrepancy representation remains informative. Budget sweeps and independent diagnostics support the same observability hierarchy, while interleaving depth has a practical saturation point.

  • B Realistic reported-versus-physical consistency: 0.666, 0.780, and 0.902 AP are achieved by the learned discrepancy classifier on case14, case30, and case118, versus 0.509 for the case14 Expert rule.The learned classifier uses the full discrepancy vector, preserving directional structure discarded by scalar magnitude.
  • B Realistic reported-versus-physical consistency: BDD-stealth has a larger physical discrepancy than Standard and statistical-stealth FDIA, while statistical-stealth has the smallest footprint and is hardest to separate.The smaller statistical-stealth signal is more easily confused with residual field-estimation error, increasing the value of retaining the full discrepancy vector.
  • B Realistic reported-versus-physical consistency: A 10× larger measurement budget leaves the statistical-stealth Expert detector near chance, while the learned classifier reaches 0.755.Increasing shots substantially improves Standard FDIA, whereas BDD-stealth is already near ceiling.
  • C Independent diagnostics of the observability hierarchy: Score distributions provide the more direct detector-separation diagnostic, while t-SNE projections serve only as supporting visualizations.The diagnostics preserve the conclusion that attack mechanism determines the informative evidence channel and that Interleaved-QCS inherits the observability of its physical quantum input.
  • D Interleaving Depth: Extended Sweep: Interleaving improves performance strongly through N = 8, adds only +0.005 from N = 8 to N = 10, and falls to 0.966 at N = 16.The study therefore treats N ≈ 8–10 as a practical operating region rather than assuming deeper interleaving is uniformly beneficial.

E Qutrit architecture ablations

The ablations test whether qutrit control space and post-sensing expressivity improve QCS when physical-state evidence is available. Extra qutrit-level control helps on CTA, but adding post-sensing parameters alone does not surpass the shallow global baseline.

  • SU(2) versus SU(3): 0.129 AP is the SU(2)/SU(3) difference on CTA, where the physical NV state contains relevant evidence.The difference is small on cyber-only attacks, whose physical NV states are uninformative by construction.
  • SU(2) versus SU(3): The additional qutrit level contributes task-relevant information on CTA but does not close the post-sensing N = 1 gap.
  • Parameterization and post-sensing depth: None of the more expressive post-sensing variants exceeds the shallow global baseline.This indicates that simply adding parameters after sensing does not reproduce the Interleaved-QCS improvement.

F Measurement Controls, Reconstruction, and Compute Cost

This section separates measurement-setting count, shot allocation, reconstruction quality, and computational cost. QCS is most advantageous when measurements are scarce, while its reported training cost is an offline classical-simulation burden rather than physical inference latency.

  • Measurement controls: At equal shots per setting, multi-setting readout receives more total physical measurements and therefore has an expected advantage.Total measurement cost is C_meas = N_settings * N_shots, apart from the common state-preparation factor.
  • Single-setting control: QCS retains a clear low-shot advantage over fixed single-setting readout, but fixed readout catches up as repeated sampling becomes inexpensive.The comparison uses one measurement setting for both methods, isolating learned coherent control from the arithmetic setting-count advantage.
  • Tomography validation: Tomography reconstruction error decreases from 0.327 at 10 shots/setting to 0.0048 at 100,000 shots/setting.This confirms convergence of the linear-inversion tomography procedure.
  • Training compute: QCS measurement advantage should be distinguished from the cost of classically simulating and optimizing its sensing dynamics.Hardware execution would replace classical simulation, while end-to-end runtime remains unquantified without hardware implementation.

G Hardware-Like Noise Robustness

The robustness and scale analyses show that QCS benefits from fewer noisy measurement settings but remains sensitive to coherent-control errors and variable training regimes. Larger sensor counts do not imply exponential local-state growth or systematic accuracy degradation.

  • Sensor/readout noise: Under conservative sensor/readout noise, Interleaved-QCS achieves the highest AP across case14, case30, and case118.Under state-of-the-art fidelity, tomography leads all three scales, while QCS remains above 4-setting readout only on case118, at 0.685 versus 0.662.
  • Quantum control fidelity: Case118 AP falls from 0.673 to 0.498 with bare control but recovers to 0.660 with protected control.Case30 is comparatively stable, whereas case14 is sensitive to control imperfections without much separation between the modeled fidelity levels.
  • Local-QCS state dimension: Local QCS processes each sensor as a constant-size qutrit, so memory grows approximately linearly with sensor count and reaches about 259 MB at K = 2000.This architecture avoids the exponential state-space growth of fully joint simulation.
  • Detection accuracy versus sensor count: Accuracy versus sensor count is non-monotonic, increasing from K = 5 to K = 10, decreasing at K = 20, and reaching its highest value at K = 100.Adding sensors does not systematically degrade the trained model, but accuracy is not independent of K.
  • Optimization diagnostics at larger scale: No individual optimization intervention changes the larger-scale regime qualitatively.Warm starts and QNG provide only modest improvements, while the study does not establish a barren plateau.
Loading 2609.10606v1…