CEQT Center of Excellence in Quantum Technology

Applications › Attack and defence strategy on layered networks

Applications · Cybersecurity & defence

Attack and defence strategy on layered networks

Many core security decisions are combinatorial optimisation problems. We formulate them as QUBO and solve them by quantum annealing and by hybrid classical–quantum methods.

The problem

A defended network is a set of choices: where to place controls, which paths to harden, what to monitor, what to accept. Each choice interacts with the others, and the number of combinations grows faster than any exhaustive method can follow. The same structure appears from the attacker’s side — the cheapest path through a layered defence is itself a combinatorial search.

Security teams handle this today with heuristics and expert judgement, which work well until the network is large, the layers interact, or the threat model changes faster than the model can be rebuilt.

Approach

The problem is cast as quadratic unconstrained binary optimisation (QUBO) and solved by adiabatic quantum computation. Constraints become penalty terms; the weighting of those penalties is itself part of the research, and several new QUBO construction techniques came out of this work and transfer to other domains. A subsequent hybrid classical–quantum treatment handles a layered cybersecurity model where a pure formulation does not fit the hardware.

Classical baseline

Integer programming and well-tuned heuristics solve realistic instances today, and for small networks they solve them faster. The interest is in where the crossover falls as the instance grows and the constraint structure becomes denser — which is an empirical question, not a settled one.

Maturity

Published, and demonstrated on annealing hardware. The QUBO constructions and the hybrid layered model are in the peer-reviewed literature. This is not deployed in an operational security environment.

Direct impact

Defence planning, critical-infrastructure protection, and security architecture review for organisations whose networks are large enough that intuition has stopped scaling.

What deployment requires

Access to annealing hardware or a hybrid solver; problem instances at realistic scale, which in practice means a partner willing to share a sanitised network model; and a defined objective — the hardest part is usually agreeing what ‘best defended’ means numerically.

Pillars involved
Algorithm design Foundations
Maturity of this workwhere this sits today, not where it could sit
ExploratoryPublished resultWorking prototypeIn service

Evidence

  • Kantabutra, S. “Adiabatic Quantum Computation for Cyber Attack and Defense Strategies.” In New Trends in Computer Technologies and Applications, ICS 2022, Communications in Computer and Information Science vol. 1723, Springer, Singapore. doi:10.1007/978-981-19-9582-8_9
  • “Hybrid classical quantum computation for cybersecurity strategies in a layered cybersecurity model.” The Journal of Supercomputing 81, 1179 (2025). doi:10.1007/s11227-025-07662-4
  • “Probability-boosting technique for combinatorial optimization.” PeerJ Computer Science 10:e2499 (2024). doi:10.7717/peerj-cs.2499
  • “Fractional graph expanders and network dynamics: spectral properties and diffusion with applications to quantum cryptography.” Quantum Information Processing 25, 178 (2026). doi
  • Student work, 2026: an N-player attack–defence game on a defence-in-depth tree, formulated as a QUBO and solved for a Nash equilibrium on a D-Wave annealer, with payoffs taken from an ISO/IEC 27001 risk assessment. What it does →

Talk to us about this

We are most useful here when you bring a real network model and a real objective function. A sanitised topology is enough to start.

How to start a project →

Last updated 14 September 2026.