Skip to content
Conference

Unsupervised ML Based Anomaly Detection for Securing BB84 QKD Against Intercept-Resend Attacks and Channel Noise: OC-SVM, iForest, and Ex-iForest

Jun 2026 · 2026 Third International Conference on Innovations in Cybersecurity and Data Science (ICICDS) · pp. 1205-1211 · 0 citations · 20 references

Abstract

Quantum Key Distribution (QKD) using the BB84 protocol offers the potential for information-theoretic security based upon the principles of quantum mechanics; however, eavesdropping mechanisms such as intercept-resend attacks and ambient noise sources that degrade quantum channel fidelity may render such systems exploitable. We present a oneclass machine learning approach to detect two categories of threats present within BB84 quantum channels: (i) interceptresend eavesdropping committed by an adversarial actor (Eve), and (ii) six types of channel noise. We have trained three unsupervised anomaly detectors (One-Class Support Vector Machine (OC-SVM), Isolation Forest (iForest), and Extended Isolation Forest (Ex-iForest)) on a dataset consisting of 1000 instances (940 clean and 60 anomalous) and tested each of them on separate test sets of 100 instances. With respect to the detection of adversarial attacks, Ex-iForest outperformed both OC-SVM and iForest; it achieved 95.00% accuracy, precision, recall, and F1-score, and when detecting channel noise, it achieved an overall accuracy, precision, recall, and F1-score of 92.00%. Feature importance analysis confirmed that the Quantum Bit Error Rate (QBER) and the fidelity of polarization measurement were the two most discriminative features for adversarial detection while fluctuations of photon detection counts and timing jitter were the two most informative features for channel noise discrimination. These results suggest that ExiForest is a viable, robust, and efficient solution for real-time anomaly detection systems in BB84-based quantum communication systems.

View source

Similar papers

Conference Jul 2026

Quantum Key Distribution-Enabled Secure Federated Learning with QBER-Based Attack Detection

Federated Learning (FL) enables collaborative model learning without the need to share raw data, but its communication links are vulnerable to interception, replay, and man-in-the-middle (MITM) attacks. The existing key exchange methods rely on computational hardness assumptions, which can be broken by post-quantum attackers. In this paper, a secure federated learning framework improved by Quantum Key Distribution (QKD) is proposed, which integrates BB84-like quantum key generation and authenticated encryption on a per-round basis, as well as Quantum Bit Error Rate (QBER)-assisted intrusion detection. A new cryptographic key is produced in each federated round, making it immune to replay attacks and allowing for detection of tampering. Theoretical calculations show that intercept-resend attacks lead to a minimum expected QBER of 25%, making it easier to detect statistically. Experimental results on the MNIST dataset show near-perfect detection rates for MITM and replay attacks, with QBER values increasing from about 1% (serving as a benign scenario) to about 26% in an attack scenario. Communication overhead is kept below 10%, with negligible computational latency compared to local training. The experiments show that the use of QKD-based key refresh improves FL communication security while still ensuring model convergence.

M. Kumari, Charvi Suri, Isha Suri · 0 citations
Aug 2026

Dynamically quantum attack detection for quantum key distribution based on deep representations

A dynamic evolutionary attack detection scheme for practical QKD, in which Eve’s attack feature could be vectorized by a well-designed embedding model and dynamically self-update to an attack feature vector database, which significantly improves the generalization capability of quantum attack detection and promotes the practical development of QKD.

Minjie Liu, Ye Chen, Xiaodong Fan et al. · 0 citations
Open access Jul 2026

Cryptographic DoS Amplification in Hybrid Post-Quantum Deployments: Adversarial Algorithm Substitution and Its Countermeasures

The Cryptographic Amplification Factor (CAF) is defined, a metric for the per-resource cost asymmetry that an adversary induces by forcing a TLS 1.3 server onto a high-cost signature algorithm (SLH-DSA instead of a low-cost one (ECDSA or ML-DSA) instead of a low-cost one (ECDSA or ML-DSA).

Nazmus Salehin Sammo, Sariya Akhter Lura, Raza Nowrozy et al. · 0 citations
Open access Aug 2026

Detecting Practical Attacks for Continuous-Variable Quantum Key Distribution Using Quantum k-Nearest Neighbor

This paper proposes a quantum k-nearest neighbor (QkNN)-based multiclass attack detection framework for CVQKD systems that establishes a direct connection between attack detection and secret key generation, enabling a more realistic security evaluation for practical CVQKD systems.

Chan Liu, Junhao Li, Q. Liao · 0 citations
Conference Jul 2026

AI-Driven Threat Detection and Quantum Cryptography Integration for Cybersecure Communication Systems

Their combination of adversarial AI attacks with cryptographically relevant quantum computers endangers the traditional public-key infrastructure. This paper proposes a hybrid system that combines real-time deep learning-based threat detection and Quantum Key Distribution (QKD) to secure communication systems. A convolutional neural network with attention mechanism detects network anomalies with 98.4% accuracy on the CIC-IDS-2017 dataset. At the same time, a decoy-state BB84 QKD protocol is used to create symmetric keys on a modeled 40 km fiber channel with a quantum bit error rate of less than 2.5%. A new query fragment caching algorithm cuts the key delivery latency by a factor of 37. Empirical evidence demonstrates the system throughput of 850 Mbps and key generation rate of 12.4 kbps providing a viable roadmap to information-theoretically secure communication when using active cyber threats.

Naga Naveena Chennupati · 0 citations