Quantum Security Challenge
Quantum computing is increasingly delivered as a hybrid computing service. A classical client builds a circuit; compiler and intermediate-representation layers rewrite it; a cloud scheduler selects physical resources; control and readout systems execute the job; and classical software interprets probabilistic results. Every transition creates a trust boundary.
Most quantum-security education focuses on the security implications and applications of quantum computing. QSec addresses the complementary question: how do we secure quantum computers, their architecture, and the quantum machine learning applications built on top of them?
In this competition, teams will attack and defend intentionally vulnerable quantum workflows. Challenges will cover cloud-job and result integrity, multi-tenant leakage, adversarial inputs, backdoors, model extraction, and attacks on aggregation and coordination mechanisms in quantum federated learning. The emphasis is on concrete security reasoning and reproducible exploits rather than on solving large quantum algorithms.
This track offers a hands-on and accessible approach to emerging quantum security challenges through practical attack-and-defense tasks with measurable outcomes.
A successful submission will include:
- Correct flags and checker receipts for each solved challenge.
- Reproducible exploit or defense artifacts, such as scripts, notebooks, patches, model files, or query logs.
- A concise write-up for each solved challenge explaining the threat model, vulnerability, exploit path, evidence, and recommended mitigation.
- A final presentation that synthesizes the team's approach, cross-layer insights, tool usage, and lessons learned.
Quantum Security Challenge 2026
- Teams may have up to four members; individual participation is also permitted. Mixed quantum-security teams are encouraged.
- Each participant may join only one team and submit through one CSAW region.
- All offensive activity must remain within the supplied containers, datasets, and organizer services. Attacks against external systems, commercial quantum services, other teams, or CSAW infrastructure are prohibited.
- Any programming language, framework, automation method, machine-learning tool, or generative AI tool may be used. Material AI assistance must be disclosed, with relevant prompts or logs retained.
- Flag sharing, plagiarism, credential theft, social engineering, denial-of-service attacks, and fabricated or tampered evidence are prohibited.
- Each solved challenge must include the flag and validation evidence, reproducible steps, a short security analysis, a proposed mitigation, and all required code or artifacts.
- Submissions must be reproducible in the official environment. Teams must also deliver a final report and presentation.
The competition is scored out of 100 points:
- Challenge solves and flag validation (45%): Correctly captured flags and successful organizer re-validation.
- Security analysis and mitigation (25%): Accurate threat modeling, root-cause analysis, supporting evidence, and practical defenses.
- Creativity and cross-layer insight (15%): Novel attacks, effective automation, efficient techniques, and creative combinations of quantum and classical methods.
- Reproducibility and presentation (5%): Clear code and documentation, pinned dependencies, successful reruns, effective demonstrations, and a strong final presentation.