INGLESE

Quantum Software Engineering (QSE) merges quantum computing with software engineering to tackle problems beyond classical capabilities. As quantum technology continues to develop, there is growing concern about the security and privacy of quantum-hybrid systems, especially due to the challenges involved in merging quantum and classical computing systems and due to their natural weaknesses, which include qubit decoherence and vulnerability to side-channel attacks. This thesis addresses these challenges through a comprehensive evaluation of existing QSE practices, identifying critical gaps in Security by Design (SbD) and Privacy by Design (PbD). To bridge these gaps, this work pursues three key goals: (i) analyzing existing security and privacy integration models in QSE, (ii) proposing and empirically validating new methodologies for secure quantum software development, and (iii) adopting agile approaches for iterative security and privacy enforcement in QSE. A systematic literature review reveals a lack of dedicated research on PbD and SbD, underscoring the need for empirical studies in quantum-hybrid programming and quantum-enhanced machine learning. This analysis leads to the QuIPS (Quantum Impact on Privacy and Security) framework, which maps privacy and security integration into the Quantum Development Lifecycle (QDLC), highlighting key phases for embedding security measures. Building on QuIPS, this thesis introduces and validates multiple quantum-enabled security frameworks across domains like automotive, smart cities, and education. The Quantum Privacy-Oriented Software Development (QPOSD) model embeds security and privacy into Quantum software Development Lifecycle (QDLC), while the Quantum Error (QError) methodology systematically analyzes quantum bugs and vulnerabilities, linking them to security risks. Five case studies empirically assess these frameworks, demonstrating their feasibility and real-world applicability. Further extending QuIPS, the thesis integrates DevSecOps, MLOps, and Scrum into QSE, ensuring continuous security validation in agile quantum development. This unified framework embeds PbD and SbD principles via proactive risk assessment, automated security testing, and CI/CD pipelines, enhancing quantum software resilience while addressing iterative security needs. Results confirm that quantum technologies can enhance security and privacy in diverse domains while maintaining accuracy and achieving exponential time gains. QPOSD facilitates early-stage security integration, while QError expedites vulnerability mitigation in quantum-hybrid systems. However, given the nascent stage of quantum computing, it is premature to generalize these conclusions, necessitating further empirical validation and real-world implementation. It is important to acknowledge that the outcomes of experiments conducted on quantum computing platforms are inherently non-deterministic, influenced by the current state and maturity of quantum technologies. Therefore, ongoing and rigorous analysis of the proposed frameworks and models remains essential to refine and adapt them for future advancements in this rapidly evolving field.

Quantum Software Engineering for Security

PAL, ANIBRATA
2025

Abstract

INGLESE
11-apr-2025
Inglese
Quantum Software Engineering (QSE) merges quantum computing with software engineering to tackle problems beyond classical capabilities. As quantum technology continues to develop, there is growing concern about the security and privacy of quantum-hybrid systems, especially due to the challenges involved in merging quantum and classical computing systems and due to their natural weaknesses, which include qubit decoherence and vulnerability to side-channel attacks. This thesis addresses these challenges through a comprehensive evaluation of existing QSE practices, identifying critical gaps in Security by Design (SbD) and Privacy by Design (PbD). To bridge these gaps, this work pursues three key goals: (i) analyzing existing security and privacy integration models in QSE, (ii) proposing and empirically validating new methodologies for secure quantum software development, and (iii) adopting agile approaches for iterative security and privacy enforcement in QSE. A systematic literature review reveals a lack of dedicated research on PbD and SbD, underscoring the need for empirical studies in quantum-hybrid programming and quantum-enhanced machine learning. This analysis leads to the QuIPS (Quantum Impact on Privacy and Security) framework, which maps privacy and security integration into the Quantum Development Lifecycle (QDLC), highlighting key phases for embedding security measures. Building on QuIPS, this thesis introduces and validates multiple quantum-enabled security frameworks across domains like automotive, smart cities, and education. The Quantum Privacy-Oriented Software Development (QPOSD) model embeds security and privacy into Quantum software Development Lifecycle (QDLC), while the Quantum Error (QError) methodology systematically analyzes quantum bugs and vulnerabilities, linking them to security risks. Five case studies empirically assess these frameworks, demonstrating their feasibility and real-world applicability. Further extending QuIPS, the thesis integrates DevSecOps, MLOps, and Scrum into QSE, ensuring continuous security validation in agile quantum development. This unified framework embeds PbD and SbD principles via proactive risk assessment, automated security testing, and CI/CD pipelines, enhancing quantum software resilience while addressing iterative security needs. Results confirm that quantum technologies can enhance security and privacy in diverse domains while maintaining accuracy and achieving exponential time gains. QPOSD facilitates early-stage security integration, while QError expedites vulnerability mitigation in quantum-hybrid systems. However, given the nascent stage of quantum computing, it is premature to generalize these conclusions, necessitating further empirical validation and real-world implementation. It is important to acknowledge that the outcomes of experiments conducted on quantum computing platforms are inherently non-deterministic, influenced by the current state and maturity of quantum technologies. Therefore, ongoing and rigorous analysis of the proposed frameworks and models remains essential to refine and adapt them for future advancements in this rapidly evolving field.
QUANTUM COMPUTING; SOFTWARE ENGINEERING; CYBERSECURITY
CAIVANO, DANILO
PASCAZIO, Saverio
MAZZIA, Francesca
Università degli studi di Bari
File in questo prodotto:
File Dimensione Formato  
Anibrata_Thesis_QSE_FINAL_AP_SIGNED_CONFIRMED.pdf

accesso aperto

Licenza: Tutti i diritti riservati
Dimensione 9.8 MB
Formato Adobe PDF
9.8 MB Adobe PDF Visualizza/Apri
Anibrata_Thesis_QSE_FINAL_AP_SIGNED_CONFIRMED_1.pdf

accesso aperto

Licenza: Tutti i diritti riservati
Dimensione 9.8 MB
Formato Adobe PDF
9.8 MB Adobe PDF Visualizza/Apri

I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14242/379086
Il codice NBN di questa tesi è URN:NBN:IT:UNIBA-379086