Paper deep dive
QUASAR: A Quantum-Classical Neural Network for SAR Satellite Physical-Layer Authentication
Vincenzo Sammartino, Nathanael Denis, Roberto Di Pietro
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 91%
Last extracted: 8/21/2026, 4:28:48 AM
Summary
The paper introduces QuaSAR, a quantum-classical hybrid neural network designed for physical-layer authentication (PLA) of X-band Synthetic Aperture Radar (SAR) satellites. Unlike classical deep learning models that underfit IQ phase nonlinearities, QuaSAR combines a CNN spectrogram encoder with a Variational Quantum Circuit (VQC) using an IQ-native encoding scheme. This architecture demonstrates superior data efficiency, requiring only 10% of the training data to match classical baselines, and achieves higher classification accuracy. The system effectively rejects spoofed transmissions in replay, crafted-IQ injection, and space-borne spoofing scenarios.
Entities (10)
Relation Signals (9)
QuaSAR â usescomponent â CNN
confidence 95% ¡ QuaSAR... fuses a CNN spectrogram encoder with a variational quantum circuit (VQC)
QuaSAR â usescomponent â Variational Quantum Circuit
confidence 95% ¡ QuaSAR... fuses a CNN spectrogram encoder with a variational quantum circuit (VQC)
QuaSAR â achievesaccuracy â 97.3%
confidence 92% ¡ We demonstrate 97.3% validation accuracy... in binary satellite authentication
ICEYE â operates â X-band SAR
confidence 92% ¡ ICEYE... operating the largest commercial SAR constellation... X-band SAR payloads
QuaSAR â protects â X-band SAR
confidence 90% ¡ provide PLA to X-band SAR signals
QuaSAR â rejects â Replay Attack
confidence 90% ¡ QUASAR rejects spoofed transmissions in 89.7%... of attempts... replay
QuaSAR â rejects â Crafted-IQ Injection
confidence 90% ¡ QUASAR rejects spoofed transmissions in... 94.1%... of attempts... crafted-IQ injection
QuaSAR â rejects â Space-borne Spoofing
confidence 90% ¡ QUASAR rejects spoofed transmissions in... 81.3%... of attempts... space-borne spoofing
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:X-band SAR satellites (8-12 GHz) play a critical role in disaster response, environmental monitoring, and military intelligence. Yet, they lack robust physical-layer authentication (PLA), a security layer orthogonal to cryptographic solutions. Existing PLA systems, typically based on radio-frequency fingerprinting, are often limited to sub-6 GHz frequencies and rely on classical deep learning. However, this approach underfits the IQ phase nonlinearities that distinguish satellite hardware. In this paper, we present QUASAR, to the best of our knowledge the first quantum-classical hybrid architecture that fuses a CNN spectrogram encoder with a variational quantum circuit (VQC) to provide PLA to X-band SAR signals. Our solution enjoys two distinctive features: (i) it is markedly more data-efficient than classical machine learning, requiring only 10% of the training data to match the accuracy of classical baselines -- data collection being notoriously the most time-consuming phase of PLA; and, (ii) at an equal data budget, it improves classification accuracy over those baselines. In detail, we test our solution under three adversarial scenarios: replay, crafted-IQ injection, and space-borne spoofing. QUASAR rejects spoofed transmissions in 89.7%, 94.1%, and 81.3% of attempts, respectively, establishing the first quantum-enhanced physical-layer classifier for satellite constellations. The fully detailed framework and the supporting results, other than being interesting on their own, show a novel research avenue for physical-layer authentication.
Tags
Links
- Source: https://arxiv.org/abs/2608.20240v1
- Canonical: https://arxiv.org/abs/2608.20240v1
Trouble viewing inline? Open PDF directly â
Full Text
84,969 characters extracted from source content.
Expand or collapse full text
QuaSAR: A Quantum-Classical Neural Network for SAR Satellite Physical-Layer AuthenticationPubID: pubid: Network and Distributed System Security (NDSS) Symposium 2027 22â26 March 2027, Seoul, Republic of Korea ISBN 978-1-970672-09-1 https://dx.doi.org/10.14722/ndss.2027.[23||24]x w.ndss-symposium.org Vincenzo Sammartino12, Nathanael Denis2, and Roberto Di Pietro2 Affiliation: 1University of Pisa, Pisa, Italy vincenzo.sammartino@phd.unipi.it Affiliation: 2King Abdullah University of Science and Technology (KAUST), Thuwal, Saudi Arabia nathanael.denis, roberto.dipietro@kaust.edu.sa Abstract X-band SAR satellites (8â12 GHz) play a critical role in disaster response, environmental monitoring, and military intelligence. Yet, they lack robust physical-layer authentication (PLA), a security layer orthogonal to cryptographic solutions. Existing PLA systems, typically based on radio-frequency fingerprinting, are often limited to sub-6 GHz frequencies and rely on classical deep learning. However, this approach underfits the IQ phase nonlinearities that distinguish satellite hardware. In this paper, we present QuaSAR, to the best of our knowledge the first quantum-classical hybrid architecture that fuses a CNN spectrogram encoder with a variational quantum circuit (VQC) to provide PLA to X-band SAR signals. Our solution enjoys two distinctive features: (i) it is markedly more data-efficient than classical machine learning, requiring only 10% of the training data to match the accuracy of classical baselinesâdata collection being notoriously the most time-consuming phase of PLA; and, (i) at an equal data budget, it improves classification accuracy over those baselines. In detail, we test our solution under three adversarial scenarios: replay, crafted-IQ injection, and space-borne spoofing. QuaSAR rejects spoofed transmissions in 89.7%, 94.1%, and 81.3% of attempts, respectively, establishing the first quantum-enhanced physical-layer classifier for satellite constellations. The fully detailed framework and the supporting results, other than being interesting on their own, show a novel research avenue for physical-layer authentication. I Introduction Synthetic aperture radar (SAR) satellites are Earth-observation platforms that transmit active microwave signals, enabling high-resolution surface imaging irrespective of weather or illumination conditions. The commercial expansion of X-band (8â12 GHz) SAR constellations has accelerated markedly: ICEYEâa Finnish private company owning the worldâs largest synthetic aperture imaging radar constellationânow operates more than 60 active satellites. Its competitors, Capella Space and Beijing Smart Satellite Space Technology, are similarly scaling deployments. These systems are used for time-critical decisions in disaster management, environmental monitoring, agricultural surveillance, and national security intelligence [41, 12, 18, 24]. Their strategic significance, however, makes them an attractive target for adversaries seeking to forge SAR imagery or disrupt observation services. Yet, satellite networks do not universally enforce authentication mechanisms [13]. Even where cryptographic protections exist, they remain vulnerable to key leakage, legacy hardware incapacity for software updates, and eventual cryptographic compromise over decade-long mission lifetimes [27]. Physical-layer security (PLS) addresses this vulnerability via an independent mechanism: hardware-induced signal impairments make every radio transmitter physically unique and are extremely hard to reproduce [36]. While these physical impairments provide a robust authentication anchor, they are subject to drift over extended periods due to the harsh space environment, necessitating periodic model updates via transfer learning to maintain fingerprint accuracy. Despite recent progress in RF fingerprinting for sub-6 GHz satellite communications, e.g., IRIDIUM [30, 40], the X-band has comparatively received little attention. Commercial SDRs are capped at approximately 6â7 GHz, requiring an intermediate downconversion stage that introduces additional phase noise, mixer nonlinearities, and spurious spectral products [43]. Hardware impairments in X-band SAR signals manifest themselves as IQ imbalances and phase micro-perturbations, which are reflected in high-noise radar pulses. Deep convolutional architectures excel at coarse spectral pattern extraction, but may underfit the nonlinear interactions separating satellites that share hardware generation. Variational quantum circuits (VQCs) offer a theoretically motivated alternative: operating in exponentially large Hilbert spaces with a polynomial parameter count, VQCs can implement high-dimensional nonlinear transformations potentially unavailable to shallow classical layers, amplifying fingerprint separability in directions inaccessible to classical gradient descent [6]. Contributions. This paper provides a novel PLA mechanism for satellite authentication that blends quantum and classical ML techniques. In particular, we provide the following contributions: ⢠We design and deploy an X-band SAR satellite RF fingerprinting testbed, based on a programmable downconversion mixer and a USRP X310 SDR. To validate our framework, we collect 3.76 TB of raw IQ data from 37 operational ICEYE satellites over 28 days using two independent SDR unitsâthe latter to assess cross-receiver transferability. ⢠We propose QuaSAR, a quantum-classical hybrid architecture combining a deep CNN spectrogram encoder, a four-layer VQC operating over an 8-qubit register, and a classical skip connection fused via late concatenation. The VQC is driven by an IQ-native encoding that maps the amplitude and the phase of each projected feature onto the polar and azimuthal angles of a qubit, exploiting the geometric isomorphism between a complex sample and a single-qubit pure state. ⢠We demonstrate 97.3% validation accuracy and macro-F1 = 0.973 in binary satellite authentication using only 10% of the collected corpusâmatching classical baseline accuracy at a fraction of the enrollment costâand exceeding the classical-only baseline by 7.5 percentage points. Furthermore, through a dedicated explainability analysis based on gradient saliency maps and latent-space clustering, we establish the physical grounding of QuaSARâs decisions, confirming the ability of the quantum branch to amplify minute hardware fingerprints and localizing the decision to sub-millisecond windows in the raw IQ domain. ⢠We define and test three attack scenarios: replay attacks; crafted-IQ injection; and, spoofingâachieving detection rates of 89.7%, 94.1%, and 81.3%, respectively. The remainder of this paper is organized as follows. Section I provides background. Section I defines the threat model. Section IV describes data collection and processing. Section V presents QuaSAR. Section VI reports experimental results. Section VII provides explainability analysis. Section VIII surveys related work. Section IX discusses limitations and future work. Conclusions are reported in Section X. I Background This section introduces the principles underlying our proposed approach, specifically SAR satellite imaging, software-defined radio for RF fingerprinting, time-frequency signal representations, and variational quantum circuits. We also connect IQ samples to qubits to further justify the use of quantum machine learning for PLA. I-A SAR Imaging Satellites Synthetic Aperture Radar (SAR) is an active microwave remote sensing technology. A SAR satellite illuminates the ground with radio pulses and reconstructs a high-resolution image from the reflected echoes. Because the system relies on its own illumination and operates at microwave frequencies that penetrate clouds, SAR acquires imagery day or night, independently of weather. Passive optical satellites, by contrast, offer no such capability, which makes SAR the instrument of choice for disaster response, maritime surveillance, and military intelligence [41, 20, 24]. The imaging pulse. To achieve fine range resolution without requiring impractically short pulses, SAR systems transmit a linearly frequency-modulated (LFM) chirp: a waveform whose instantaneous frequency sweeps linearly across the instrument bandwidth over the pulse duration [26]. For a chirp of bandwidth B and duration TpT_p, the baseband transmitted signal is sâĄ(t)=rectâĄ(tTp)âexpâĄ(jâĎâKât2),K=B/Tp,s(t)=rect\! ( tT_p ) \! (jĎ Kt^2 ), K=B/T_p, (1) where K is the chirp rate [10, 26]. Pulse compression at the receiver trades the long transmitted pulse for a short effective pulse of width â1/Bâ\!1/B, so ground range resolution scales inversely with the transmitted bandwidth. SAR satellite imaging bands. SAR constellations operate across several microwave bandsâL, C, and X being the most common [33, 7, 3]. The X-band (8â12 GHz) offers the most favorable trade-off between resolution and antenna size for small commercial platforms [7]: its short wavelength yields sub-meter ground resolution with antennas compatible with comparatively lightweight satellite buses, i.e., even below 100 kg, enabling the dense LEO constellations now deployed by ICEYE, Capella Space, and Umbra. Lower bands (L, C) require proportionally larger antennas for equivalent resolution and are typically reserved for flagship government missions [14]. The ICEYE constellation. Our testbed targets satellites from the ICEYE constellation. ICEYE is a Finnish commercial operator, founded in 2014 as a spin-off of Aalto University, whose mission was to miniaturize X-band SAR payloads to platforms below 100 kg. Each ICEYE satellite carries an active phased-array antenna operating at a nominal carrier frequency of 9.65 GHz and supports several acquisition modes â Strip, Spot, Scan, and Dwell â, with published ground resolutions ranging from approximately 0.25 m to 15 m depending on mode [11]. ICEYE now operates the largest commercial SAR constellation in orbit; the 37 satellites used in this study correspond to the subset operational during our 28-day collection campaign, while the constellation has since grown to over 60 satellites. Within a single hardware generation, all satellites share a common bus and payload design, which makes intra-constellation discrimination particularly challenging for any fingerprinting method. I-B Software-Defined Radio and RF Fingerprinting SDRs implement signal processing on reconfigurable hardware, enabling passive wideband capture without prior knowledge of the targetâs transmission scheme. Their operational frequency ceiling (6â7 GHz for commodity units) precludes direct capture of X-band emissions. Radio fingerprinting exploits hardware impairments to identify the originating transmitter [36]. Even mass-produced transceivers from the same batch are distinguishable due to minute differences in hardware, which manifest as IQ gain imbalance, DC offset, phase noise, and nonlinear harmonic distortion in received IQ samples [30]. Short-Time Fourier Transform spectrograms. Raw IQ samples are converted to time-frequency representations via the STFT [28]. For a complex baseband signal xâĄ[n]x[n]: X(m,k)=ân=0Nâ1x[n+mH]w[n]eâj2Ďkn/NX(m,k)= _n=0^N-1x[n+mH]\,w[n]\,e^-j2Ď kn/N (2) where wâĄ[n]w[n] is a Hanning analysis window of length N, H is the hop size, and m,km,k index time frames and frequency bins, respectively. The log-magnitude spectrogram SâĄ(m,k)=10âlog10â|XâĄ(m,k)|2S(m,k)=10 _10|X(m,k)|^2 is treated as a grayscale 2D image, jointly encoding spectral content and temporal evolution. I-C Variational Quantum Circuits A VQC UâĄ(,)U( θ,x) encodes classical data into qubit states, applies a parameterized gate sequence, and returns expectation values of Pauli observables as classical outputs. An angle-embedding layer initializes each qubit via: RYâ(Ďi)â|0âŠ,Ďi=Ďâ ĎâĄ(xi),i=1,âŚ,dR_Y( _i)|0 , _i=Ď¡Ď(x_i), i=1,âŚ,d (3) where ĎâĄ(â )Ď(¡) is the sigmoid function, constraining Ďiâ(0,Ď) _iâ(0,Ď). The embedding loads each classical feature onto an independent qubit, producing a separable product state â¨i=1d|Ďi⊠_i=1^d| _i that carries no inter-qubit correlation. To learn joint functions of the embedded features, this state is processed by L strongly entangling layers (SEL) [37]. Each SEL applies parameterized RY/RZR_Y/R_Z rotations on every qubit followed by a CNOT ring, generating the multi-qubit entanglement needed to evaluate non-separable functions over the 2d2^d-dimensional Hilbert space. The circuit output is the vector of single-qubit Pauli-Z expectation values: Q=[â¨Z1âŠ,â¨Z2âŠ,âŚ,â¨ZdâŠ]â[â1,1]d,v_Q= [ Z_1 , Z_2 ,âŚ, Z_d ]â[-1,1]^d, (4) which is differentiable end-to-end via the parameter-shift rule [25], making the VQC compatible with standard backpropagation. I-D Connecting IQ Samples to Qubits Fig. 1: IQ samples and qubit states. Left: a complex IQ sample x=I+jâQx=I+jQ, represented as a vector in the complex plane with magnitude r and phase Ď . Right: a single-qubit pure state |ĎâŠ=cosâĄ(θ/2)â|0âŠ+eiâĎâsinâĄ(θ/2)â|1âŠ|Ď = (θ/2)|0 +e^i (θ/2)|1 on the Bloch sphere, parameterized by the polar angle θ and the azimuthal angle Ď . Both objects are fully specified by two real parameters: the IQ magnitude r maps to the polar angle θ=2âarcsinâĄ(r)θ=2 (r), while the phase Ď is the same physical quantity in both representations. A central motivation for using Quantum Machine Learning (QML) in the context of radio-frequency fingerprinting is that the native state space of a qubit is geometrically isomorphic to the native state space of an IQ sample. This correspondence, illustrated in Figure 1, permits an encoding under which the entire information content of a complex sample, i.e., both amplitude and phase, is preserved in the quantum state. This is often not true for real-valued encodings, e.g., of spectrogram magnitudes, which discard phase by construction. The geometric correspondence. A complex IQ sample x=I+jâQââx=I+jQ is uniquely determined by two real parameters: its magnitude r=|x|r=|x| and its phase Ď=argâĄ(x)â[0,2âĎ) = (x)â[0,2Ď). A single-qubit pure state |ĎâŠ=cosâĄ(θ/2)â|0âŠ+eiâĎâsinâĄ(θ/2)â|1âŠ|Ď = (θ/2)\,|0 +e^i (θ/2)\,|1 (5) is likewise determined by two real parameters: the polar angle θâ[0,Ď]θâ[0,Ď] and the azimuthal angle Ďâ[0,2âĎ) â[0,2Ď) on the Bloch sphere. The azimuthal angle Ď is the same physical quantity in both representations, i.e., the phase of the complex object. Only the amplitudeâpolar mapping needs to be specified to complete the correspondence. IQ-native encoding. Given a normalized IQ sample xn=In+jâQnx_n=I_n+jQ_n with rn=|xn|â[0,1]r_n=|x_n|â[0,1] and Ďn=argâĄ(xn) _n= (x_n), we encode it into qubit n via the two-rotation sequence |ĎnâŠ=RZâ(Ďn)âRYâ(θn)â|0âŠ,θn=2âarcsinâĄ(rn),| _n \;=\;R_Z( _n)\,R_Y( _n)\,|0 , _n=2 (r_n), (6) where RY(θ)=exp(âiθY/2)R_Y(θ)= (-iθ Y/2) and RZ(Ď)=exp(âiĎZ/2)R_Z( )= (-i Z/2) are the standard Pauli rotations [29, 38]. The RYR_Y rotation fixes the latitude of the state on the Bloch sphere (loading the amplitude), while the subsequent RZR_Z rotation fixes its longitude (loading the phase). The RZR_Z rotation introduces an overall factor eâiĎ/2e^-i /2 which, as a global phase, leaves all measurable quantities and subsequent gate operations invariant. Excluding this global phase, the resulting state is exactly Eq. (5) with θ=θnθ= _n and Ď=Ďn = _n, so the encoding is lossless: the original sample can be recovered as xn=sinâĄ(θn/2)âeiâĎnx_n= ( _n/2)\,e^i _n from the Bloch-sphere coordinates of |ĎnâŠ| _n . A block of d consecutive IQ samples is encoded into a d-qubit product state |ĎâŠ=â¨n=1d|ĎnâŠ|Ď = _n=1^d| _n by applying Eq. (6) independently on each qubit. The entangling layers that follow (cf. Section V) subsequently couple these qubits, allowing the VQC to learn joint functions of the full IQ block. Contrast with angle embedding of real features. The conventional angle-embedding approach of Eq. (3) loads a real scalar xiââx_i into qubit i via a single RYR_Y rotation, leaving the azimuthal degree of freedom unused. Applied to a complex IQ stream, this scheme requires either: (i) discarding the phase; or, (i) spending two qubits per sample (one for I, one for Q), which doubles circuit depth and breaks the geometric link between the encoded state and the original complex number. The IQ-native encoding of Eq. (6) avoids both penalties: one sample maps to one qubit with no information loss, while the phase Ď âa feature that may carry hardware-induced impairments such as oscillator drift and mixer nonlinearity [2, 9]â is represented on the qubit as the same angle it occupies in the complex plane. Section VI-D quantifies what this distinction is worth in practice: replacing angle embedding with the IQ-native encoding, with every other component of the architecture held fixed, raises test accuracy by 2.2 percentage points and nearly halves the number of epochs to convergence. I Threat Model We define adversarial assumptions, objectives, and attack scenarios that scope the design of QuaSAR. Figure 2 illustrates the system and threat model. I-A System model A ground station equipped with an X-band downconversion chain and SDR passively captures radar illuminating pulses transmitted by a legitimate ICEYE SAR satellite during orbital passes. A trained QuaSAR classifier authenticates illumination signals against the enrolled satelliteâs physical-layer fingerprint in near real time. Enrollment is performed offline on verified satellite passes. Adversarial objective. The adversary seeks to compromise physical-layer authentication, either by successfully impersonating a legitimate satellite to inject fabricated IQ data that generates false SAR imagery or by blocking correct authentication to deny observation services. In high-stakes contexts, such as military surveillance or critical-infrastructure monitoring, both outcomes carry severe operational consequences. Adversarial capabilities. We consider a tiered adversary model whose resources scale with the attack scenario. At the lower tier, a terrestrial attacker possesses a commercial off-the-shelf SDR, a power amplifier, and a directional antenna, enabling signal capture, replay, and synthesis in proximity to the target ground station. This equipment is commercially available for $500â$10,000 USD and is sufficient for ground-based replay and crafted-IQ attacks. At the upper tier, we consider a strategic adversary with the means to operate an X-band SAR satellite of their own. While orders of magnitude more expensive, this capability is no longer the exclusive domain of major space powers: commercial SAR satellites can be procured or leased from established vendors. Rideshare launches, where several customers share one rocket, have driven costs into the low millions of USD range for a mission. As a consequence, several nation-states as well as non-state actors can now field X-band imaging assets. There are several incentives for a strategic adversary. Fabricating or suppressing SAR imagery can conceal military deployments, manipulate insurance and commodity markets that rely on SAR-derived intelligence, undermine adversarial disaster-response or treaty-verification efforts, or discredit a competing constellation operator by injecting falsified observations attributed to their satellites. In all tiers, we do not assume access to the legitimate ICEYE satellite hardware, knowledge of QuaSARâs parameters, or compromise of the ground station. Fig. 2: Threat model. (A) A legitimate SAR satellite XtX_t transmits two physically distinct X-band signals: i) (frequent) high-power chirp pulses for Earth imaging; and, i) (uncommon) phase-modulated data downlinks. (B) A ground station captures imaging pulses for authentication purposes. Two adversaries are considered: (C) a space-borne adversary operating a SAR satellite XsX_s of comparable hardware; and, (D) a ground spoofer operating a commercial high-end SDR. I-B Attack scenarios We consider three scenarios, ordered by increasing adversarial capability. They are referred to as Scenarios (A), (B), and (C) throughout the paper. Scenario (A): replay. The adversary, equipped with a commercial SDR, a power amplifier, and a directional antenna, records IQ bursts during a legitimate pass of XtX_t and re-emits them from the ground toward the victim ground station during a subsequent window. This is the weakest of the three models in terms of required expertise and capital outlay ($500â$10,000 USD), but also the most operationally feasible. The defense relies on the fact that the spooferâs transmit chain superimposes its own hardware impairments on top of XtX_tâs original fingerprint, producing a measurable discrepancy in the IQ domain. We instantiate this scenario by replaying previously captured ICEYE bursts through a second USRP X310 transmitting at the IF stage of our acquisition chain. Scenario (B): crafted-IQ injection. Rather than replaying a recorded waveform, the adversary synthesizes an LFM chirp that matches the nominal ICEYE waveform parametersâcarrier, bandwidth, chirp rate, and pulse repetition intervalâand transmits it toward the ground station. The synthetic burst is spectrally indistinguishable from a legitimate illumination at the macro level, but carries no hardware fingerprint of XtX_t: only the impairments of the adversaryâs own transmit chain. This scenario isolates the classifierâs reliance on micro-scale impairments rather than on waveform structure. Scenario (C): space-borne spoofing. A second SAR satellite XsX_s operates in the same band and shares comparable hardware with the legitimate satellite XtX_t. XsX_s transmits illuminating pulses to the ground station, aiming to spoof XtX_t. In a realistic deployment, XsX_s would belong to a foreign or competing constellation; however, such cross-constellation captures are not available in our dataset, and an adversary controlling a satellite from a different hardware family would be easier to discriminate due to larger impairment gaps. To stress-test QuaSAR under the challenging space-borne conditions, we therefore emulate this scenario via an open-set protocol: a subset of the 37 ICEYE satellites is held out from the training and validation splits and presented to the classifier exclusively at test time in the role of XsX_s. Because ICEYE units share similar phased-array architecture and hardware, this is a plausible space-borne attacker. A successful defense requires the model to reject XsX_s despite minimal macro-level spectral divergence from XtX_t. This is the strongest of the three models, and the one against which QuaSAR is hardest pressed. IV Data Collection and Processing This section describes the hardware testbed used to capture X-band SAR signals, the rationale for targeting imaging pulses over data downlinks, the resulting dataset, and the preprocessing pipeline that converts raw IQ recordings into spectrograms for further processing. IV-A Acquisition Testbed Fig. 3: Setup to collect satellite signals in the X-band. Two USRPs are used, along with an MX12000 downconverter and 8TB Seagate BarraCuda storage. Capturing ICEYE SAR illuminating signals at 9.65 GHz lies beyond the 6â7 GHz ceiling of commodity SDRs. We designed a custom downconversion chain composed of three elements. The Aaronia Hyperlog Pro 70140 is a passive directional antenna with a wide frequency range spanning from 700 MHz to 14 GHz, a 13 dBi gain, and is designed for field use. It feeds a DSI MX12000 programmable microwave mixer with a local oscillator set to 7.2 GHz, downconverting the received signal to an intermediate frequency (IF) of 2.45 GHz. The MX12000 eliminates the need for an external high-frequency signal source. The MX12000 output is captured by an Ettus USRP X310 equipped with UBX-40 daughterboards (10 MHzâ6 GHz, 40 MHz instantaneous bandwidth) at 10 Msps. IQ files are stored on an 8 TB HDD and processed offline using GNU Radio. The 40 MHz capture bandwidth is narrower than ICEYEâs full imaging bandwidth â up to 299 MHz for standard modes. Full-bandwidth capture is required for SAR image formation, but not for fingerprinting. Indeed, hardware impairments are detectable within any consistent spectral slice, so fingerprinting remains viable within the SDRâs instantaneous bandwidth. IV-B Rationale for Targeting Imaging Pulses Our testbed exclusively captures SAR imaging pulses rather than the satelliteâs X-band data downlink. Three properties make imaging pulses the natural choice for physical-layer authentication. Passive availability. Imaging pulses are high-power illuminations broadcast toward Earth during every orbital pass, and can be collected by any ground receiver with direct line-of-sight visibility to the satellite. The data downlink, by contrast, is a directed high-gain beam steered toward a specific licensed ground station, making passive interception impractical without prior coordination, and in particular, proximity to the intended receiver. Signal richness. Imaging pulses are wideband LFM chirps, up to 299 MHz for ICEYE standard modes, which are transmitted at high power. They provide a large spectral canvas over which hardware impairments can manifest. The data downlink employs narrowband phase-modulated communication waveforms, e.g., QPSK or 8PSK, whose reduced bandwidth and distinct modulation scheme produce a fundamentally different impairment signature. As a result, a fingerprint trained on one cannot substitute for the other. Collection frequency. Imaging pulses are emitted continuously throughout the illumination phase of every pass, whereas data downlink sessions are comparatively infrequent and tied to the availability of licensed downlink stations. This asymmetry substantially facilitates dataset collection, both for research purposesâwhere independent ground receivers can accumulate large corpora across many passesâand for operational deployment by a constellation operator equipped with its own ground infrastructure. Note that the hardware fingerprint extracted from SAR imaging pulses is not interchangeable with one derived from the satelliteâs X-band data downlink, as the two signals differ fundamentally in waveform structure. IV-C Dataset A 28-day collection campaign produced signals from all 37 operational ICEYE satellites, accumulating 3.76 TB of raw IQ data. To assess cross-receiver transferabilityâa known source of fingerprinting bias [17]âtwo physically separate USRP X310 units were deployed: the first unit contributed 2.48 TB and the second 1.28 TB. IV-D Pre-processing Noise-only intervals are mitigated via an adaptive magnitude threshold: Ď=Îąâ (Îź+2âĎ)Ď=ι¡(Îź+2Ď) (7) where Îź and Ď are the mean and standard deviation of instantaneous sample magnitudes and Îąâ[0,1]Îąâ[0,1] is a tunable strength coefficient. Samples exceeding Ď are retained while the remainder are discarded, reducing the noise floor during downconverted X-band reception. IV-E Spectrogram Generation Retained IQ bursts are segmented into chunks of 100,000 samples. Each chunk is transformed into a grayscale spectrogram using Eq. (2) with Hanning window N=256N=256, hop H=128H=128 (50% overlap), and FFT length 256. The power spectrogram is log-scaled in dB, clipped between the 1st and 99th percentiles for dynamic-range compression, and resized to 224Ă224224Ă 224 pixels to match the CNN encoderâs input dimensions. IV-F Class Balancing We collect IQ data from 37 ICEYE satellites and train one binary classifier per satellite under a one-vs-rest (OvR) protocol. For each classifier, samples from the enrolled satellite are the positive class and samples from the remaining 36 satellites form the negative class. This creates a natural 36:136:1 imbalance. To correct it, we undersample the negative class at the pass level, drawing negative passes until their spectrogram count matches the positive class, and close any residual gap with ceiling oversampling. The final balanced set contains 2,021 spectrograms per classifier, evenly split between the two classes. This procedure is applied independently for each of the 37 enrolled satellites. Fig. 4: Time-domain IQ waveforms (left) and constellation density maps (right) for three ICEYE satellites: X11 (top), X13 (middle), and X14 (bottom). Each satellite is captured on its own orbital passes, in separate acquisitions; no capture contains more than one emitter. The labels target and non-target are therefore not properties of a collection but roles assigned per classifier: under the one-vs-rest protocol of Section IV, each of the 37 satellites is enrolled as the target in turn, and the remaining 36 take the non-target role for that classifier. Figure 4 shows three of these independently acquired emitters, with X11 drawn in the target role purely for illustration. The three rows illustrate the morphological diversity the testbed resolves. X11 (top row) exhibits pronounced burst-onset transients in the time-domain trace, with I and Q components reaching peak amplitudes of Âą 0.05, followed by rapid signal decay. Its constellation density map is broad and asymmetric, reflecting the hardware phase noise and IQ imbalance introduced by that satelliteâs transmit chain. X13 (middle row) displays sparse impulsive artifacts superimposed on a lower-amplitude stationary floor, with a wider constellation spread indicating a noise process with higher variance. X14 (bottom row) presents the most stationary waveform, with uniformly bounded amplitude and a compact, near-circular constellation whose reduced count density (⤠40 samples at peak) reflects its intermittent in-band activity. These inter-emitter differencesâdetectable at the level of raw IQ morphology prior to any spectral transformationâconfirm that the downconversion chain preserves sufficient hardware-induced signal structure to support fingerprint extraction, and motivate the class-balancing procedure described above. IV-G Training / Validation / Test Split The balanced dataset is partitioned into DtrainD_train (60%), DvalD_val (20%), and DtestD_test (20%) at the granularity of orbital passes rather than of individual spectrograms: we first group all bursts by pass identifier (date Ă satellite Ă acquisition window), then assign whole passes to the three subsets by random shuffling. Spectrograms from the same pass therefore never straddle two subsets. This prevents temporally adjacent burstsâwhich share channel state, atmospheric conditions, and front-end thermal regimeâfrom leaking across splits. V QuaSAR: Architecture QuaSAR takes a shared latent representation and sends it through two parallel paths: a variational quantum branch and a classical skip connection. Their outputs are then combined and passed to a single binary classifier. The full pipeline is shown in Figure 5. STFTSpectrogramsCNNBlock 1CNNBlock 2LatenthĂ224224\!Ă\!224256256FC â16â 168Ă(I,Q)8Ă(I,Q)IQ-nativeEmbed RZâRYR_ZR_YVQC (L=4L\!=\!4)SELMeas â¨Z⊠Z _Q88FC â128â 128ReLULatentCv_CFC â64â 64ReLU1281286464ConcatzSoftmaxHeadBinaryOutput7272886464Shared CNN EncoderQNN Branch (8 qubits, PennyLane)Classical Skip ConnectionLate Fusion & Classification Fig. 5: QuaSAR end-to-end architecture. The shared CNN encoder (blue) maps the Ă224224\!Ă\!224 STFT spectrogram to a 256-dimensional latent vector h. The QNN branch (violet) projects h to 8 complex components, loads each onto one qubit through the IQ-native amplitudeâphase encoding of Eq. (6), applies L=4L\!=\!4 strongly entangling layers (SEL), and emits 8 Pauli-Z expectation values. The classical skip (green) compresses h through two FC layers to 64 dimensions. Late fusion concatenates both into a 72-dimensional vector classified by a linear head. V-A CNN Encoder The input grayscale spectrogram ââ1Ă224Ă224I ^1Ă 224Ă 224 is processed by a stack of convolutional blocks [39, 15]. Each block applies a Conv2d layer followed by BatchNorm2d, ReLU activation, and MaxPool2d spatial downsampling. The encoder outputs a dense latent vector ââ256h ^256 encoding hierarchical spectral and temporal features of the received waveform. Batch normalization at each layer stabilizes gradient flow and accelerates convergence in the presence of VQC parameter-shift gradients, which have higher variance than standard backpropagation. V-B Variational Quantum Branch The 256-dimensional latent vector h is projected by a trainable linear layer to 1616 real values, read as 88 complex components: =Wqâ+q,Wqââ16Ă256,q=W_q\,h+b_q, W_q ^16Ă 256, (8) with ci=q2âiâ1+jâq2âic_i=q_2i-1+j\,q_2i for i=1,âŚ,8i=1,âŚ,8. Each complex component is loaded onto one qubit through the IQ-native encoding of Eq. (6): |ĎiâŠ=RZâ(Ďi)âRYâ(θi)â|0âŠ,θi=2âarcsinâĄ(tanhâĄ|ci|),Ďi=argâĄ(ci),| _i =R_Z( _i)\,R_Y( _i)\,|0 , aligned _i&=2 ( |c_i| ),\\ _i&= (c_i), aligned (9) where tanhâĄ|ci|â[0,1) |c_i|â[0,1) keeps the amplitude inside the admissible range of arcsin . The RYR_Y rotation loads the amplitude of cic_i and the subsequent RZR_Z rotation loads its phase, so both degrees of freedom of the projected feature reach the register. Suppressing the RZR_Z rotation and driving RYR_Y with a single real projection recovers the conventional angle embedding of Eq. (3), which discards the azimuthal degree of freedom; we retain that configuration as an ablation and quantify its cost in Section VI-D. Four strongly entangling layers are then applied. Writing (â)ââ8Ă3 θ^( ) ^8Ă 3 for the parameters of layer â , each layer executes a parameterized single-qubit rotation on every qubit followed by a CNOT ring: Uââ((â))=âi=18CNOTi,(imod8)+1âentangling ringââi=18Râ(θi,1(â),θi,2(â),θi,3(â))iU_ ( θ^( ))= _i=1^8CNOT_i,\,(i 8)+1_entangling ring\; _i=1^8R(θ^( )_i,1,θ^( )_i,2,θ^( )_i,3)_i (10) where RâĄ(Îą,β,Îł)=RZâ(Îł)âRYâ(β)âRZâ(Îą)R(Îą,β,Îł)=R_Z(Îł)R_Y(β)R_Z(Îą) is the general single-qubit rotation. The full branch therefore computes Qv_Q from the state (ââ=14Uâ)ââ¨i=18|Ďi⊠( _ =1^4U_ ) _i=1^8| _i . The entangling ring is what makes the azimuthal degree of freedom observable: on a product state the Pauli-Z expectations of Eq. (4) are invariant to the phases Ďi _i, so without Eq. (10) any phase loaded into the register would be unmeasurable. The circuit is implemented in PennyLane [5] with parameter-shift gradient estimation and emits Qâ[â1,1]8v_Qâ[-1,1]^8 as defined in Eq. (4). The quantum branch provides two design advantages. First, by operating on the Bloch sphere, it implements a nonlinear transformation in a 282^8-dimensional Hilbert space using only dâL=32dL=32 trainable rotation parameters, delivering far more representational capacity per parameter than a comparably sized classical layer. Second, the entangling layers generate inter-qubit correlations that model higher-order feature interactions, capturing fingerprints that are suppressed in classical fully-connected layers. Hyperparameter selection. The qubit count d=8d\!=\!8 and entangling depth L=4L\!=\!4 are selected to balance Hilbert-space expressivity against the trainability degradation induced by barren plateaus [23]. Increasing d beyond 88 expands the simulated state space to 2dâĽ5122^d⼠512 amplitudes, inflating parameter-shift training cost super-linearly without measurable accuracy gain on DvalD_val (we observed a <0.4<\!0.4 percentage-point fluctuation across dâ6,8,10,12dâ\6,8,10,12\ at fixed L=4L\!=\!4). Conversely, L<4L\!<\!4 leaves the state under-entangled, collapsing performance toward the QNN-Only baseline of Table I. The chosen configuration matches the dimensionality of established QML benchmarks [37] and remains within the gate-depth budget executable on current NISQ backends [6]. V-C Classical Skip Connection In parallel, the full latent vector h passes through a classical fully-connected pathway: C=ReLUâĄ(W2âReLUâ(W1â+1)+2)v_C=ReLU\! (W_2\,ReLU(W_1\,h+b_1)+b_2 ) (11) where W1ââ128Ă256W_1\!â\!R^128Ă 256 and W2ââ64Ă128W_2\!â\!R^64Ă 128. This skip connection is architecturally necessary: routing all information through the 8-dimensional quantum bottleneck would discard the majority of the temporal pattern information encoded by the CNN. The classical branch preserves this information, ensuring the fusion layer has access to both the quantum operatorâs nonlinear projections and the original rich latent representation. V-D Late Fusion and Binary Classifier The two branch outputs are concatenated: =[QâĽC]ââ72z=[v_Q\,\|\,v_C] ^72 (12) A linear head maps z to binary logits, from which the target-class posterior is derived via softmax. The 72-dimensional fusion space provides sufficient representational capacity for the binary decision boundary without risking overfitting on the 2,021-instance dataset. V-E Training Protocol All parametersâthe CNN encoder, the projection matrix WqW_q, the VQC parameters θ, and the classification headâare optimized jointly in a single end-to-end training loop. We use the Adam optimizer with learning rate Ρ=10â3Ρ=10^-3 and weight decay Îť=10â4Îť=10^-4, and minimize the cross-entropy loss over mini-batches of size 32. Batch size is selected to accommodate the VQC parameter-shift overhead without GPU memory overflow. Early stopping with patience 50 on validation loss terminates training; the model converges at epoch 37. VI Experimental Evaluation This section reports QuaSARâs performance across five evaluations: sensitivity to the training-data budget, binary authentication on the enrolled target, architectural ablation against classical benchmarks, per-satellite spoofing detection, and gradient saliency analysis. VI-A Experimental Setup All experiments run on a workstation with an NVIDIA A6000 GPU. CNN components execute on GPU; PennyLaneâs VQC simulation runs on CPU with parameter-shift gradients, which constitutes the primary computational bottleneck. The VQC is simulated classicallyâstandard practice in near-term quantum ML [6]âproducing results equivalent to noiseless hardware execution. All reported metrics are averaged over 25 independent random initializations with distinct weight seeds. Unless stated otherwise, QuaSAR denotes the deployed configuration with the IQ-native encoding of Eq. (6). The spoofing-detection, latent-space, and gradient-saliency results of Sections VI and VII were obtained with the angle-embedding variant and are therefore conservative: they lower-bound the performance of the deployed model, which dominates that variant on every binary metric (Table I). All experiments are conducted on a representative 10% subset of the full 3.76 TB corpus, corresponding to 2,021 balanced instances after the class-balancing procedure described in Section IV. This deliberate restriction reflects one of the primary claims of QuaSAR: the quantum-classical hybrid reaches classical baseline accuracy under a substantially reduced data budget, compressing what would otherwise be a multi-month enrollment phase into a shorter collection window. All baselines in the ablation and benchmark comparisons are trained on the identical 10% subset to ensure a controlled comparison. Training time. To evaluate QuaSARâs suitability for operational deployment, we measure the computational latency of both the training and the inference. Training the hybrid architecture is computationally intensive due to the parameter-shift rule, which requires two separate forward passes of the quantum circuit for every trainable quantum parameter to compute analytical gradients. Consequently, training QuaSAR on the 2,021-instance dataset requires approximately 102 seconds per epoch, converging in about 63 minutes after 37 epochsâagainst 1 hour and 55 minutes over 68 epochs for the angle-embedding variant of Section VI-D. Because satellite enrollment is an offline process performed once every few months to account for hardware drift, this training overhead is operationally acceptable. Real-time inference. During inference, the parameter-shift rule is not invoked. The VQC requires only a single forward simulation. The CNN encoder processes a Ă224224\!Ă\!224 spectrogram in 221 ms, while the 8-qubit PennyLane CPU simulation executes in 436 ms. The total end-to-end classification latency from raw IQ ingestion to binary decision is roughly 700 ms per burst. Fig. 6: Test accuracy of QuaSAR as a function of the training-data fraction. The fraction is the share of the full balanced corpus drawn by stratified random sampling, before the train/validation/test split is applied. For each fraction, the 60/20/20 split is rebuilt, and all hyperparameters are kept fixed. Each marker reports the mean over 25 random seeds. VI-B Sensitivity to the Training-Data Fraction To justify the 10% data budget used throughout this evaluation, we resample the full balanced corpus at fractions of 5%, 10%, 15%, and 20%. For each fraction we draw a uniform subset, rebuild the 60/20/20 split, and retrain with all other settings fixed. At 5%, the model reaches only 71.1% test accuracy: the encoder is under-trained and the 72-dimensional fusion space is poorly populated. At 10%, the setting used in Sections VI and VII, accuracy reaches 96.9%, the value reported in Table I. Beyond this point the curve flattens: 15% adds 0.6 percentage points and 20% adds 0.9 percentage points in total (Figure 6), both within the seed-to-seed standard deviation measured over 25 runs. Additional dataâwhich in this domain means scheduling additional orbital passesâtherefore yields diminishing returns, and QuaSAR saturates its capacity with a small training budget. This data efficiency is one of the central claims of the paper. VI-C Binary Authentication Performance Binary authentication is the task on which QuaSAR is trained: the classifier decides whether a burst originates from the enrolled target satellite. The detection of replayed bursts (Scenario (A)), in which a recorded waveform is re-emitted through a separate transmit chain, is a separate evaluation, reported at the end of this section on the three satellites (X4, X20, X41) for which laboratory replay data was acquired. Table I reports the binary metrics on DvalD_val and DtestD_test for both quantum embeddings. In its deployed configurationâthe IQ-native encoding of Eq. (6)âQuaSAR reaches 0.973 accuracy and 0.973 macro-F1 on validation, and 0.969 on both metrics on the held-out test set. The 0.4 percentage-point drop from validation to test is well within the seed-to-seed standard deviation, indicating that the model generalizes to unseen orbital passes. Training and validation loss track each other across all epochs, with no sign of overfitting, and early stopping terminates training at epoch 37. Because the two classes are balanced by construction (Section IV), accuracy and macro-F1 coincide up to rounding. The angle-embedding variant, discussed in Section VI-D, is uniformly weaker on every metric. TABLE I: Binary authentication performance under the two quantum embeddings, all other components of the architecture held fixed. Angle embedding (Eq. (3)) loads a single real projection per qubit; the IQ-native encoding (Eq. (6)) loads amplitude and phase. Mean Âą std. dev. over 25 random seeds. Angle embedding IQ-native (ours) Metric Validation Test Validation Test Accuracy 0.950 (Âą 0.010) 0.947 (Âą 0.009) 0.973 (Âą 0.010) 0.969 (Âą 0.009) Macro-F1 0.950 (Âą 0.004) 0.947 (Âą 0.005) 0.973 (Âą 0.004) 0.969 (Âą 0.005) Precision (target) 0.953 0.951 0.969 0.965 Recall (target) 0.948 0.943 0.974 0.975 Convergence epoch 68 â 37 â VI-D Encoding Ablation: IQ-Native vs. Angle Embedding The IQ-native encoding of Section I-D is motivated geometrically, but the argument is only as good as the measurement that supports it. We therefore train the identical architecture twice, changing one component: the map from the projected features to the qubit register. In the angle-embedding configuration each qubit receives a single real projection through RYR_Y (Eq. (3)), the scheme used by prior quantum-hybrid RFFI work [4]; in the IQ-native configuration each qubit receives one complex component through RZâRYR_ZR_Y (Eq. (9)). The CNN encoder, the classical skip, the entangling layers, the fusion head, the optimizer, the data split, and the 25 random seeds are all shared. The two rows of the comparison are therefore attributable to the encoding alone. Table I reports the outcome. The IQ-native encoding improves test accuracy from 0.947 to 0.969 (+2.2+2.2 percentage points) and macro-F1 by the same margin. Two features of the result deserve comment. First, the gain is concentrated in recall, which rises from 0.943 to 0.975 on DtestD_test (+3.2+3.2 points) against a smaller precision gain of 1.41.4 points. The angle-embedding variant, in other words, fails predominantly by rejecting legitimate bursts of the enrolled target, and it is exactly those bursts that the azimuthal degree of freedom recovers. This is the behavior the geometric argument predicts: oscillator drift and mixer nonlinearityâthe impairments that separate two units of the same production batchâperturb the phase of the received samples, and a real-valued embedding discards that coordinate before the variational layers ever see it. Second, the IQ-native model converges in 37 epochs against 68 for angle embedding, a 46%46\% reduction. At 102 seconds per epoch this shortens enrollment from 1 hour and 55 minutes to roughly 63 minutes on the same hardware. The encoding therefore does not trade accuracy against training cost: it improves both. We read the faster convergence as evidence that the phase coordinate carries discriminative signal that the angle-embedding variant must otherwise reconstruct indirectlyâif at allâfrom amplitude statistics through the entangling layers. Taken together with the architectural ablation of the following section, the two comparisons decompose the hybridâs advantage over the classical baseline into two additive parts: introducing the VQC branch at all is worth +5.3+5.3 percentage points over CNN-Only, and encoding its input natively as amplitude and phase is worth a further +2.2+2.2 points. Reliability of Per-satellite authentication. We repeat the binary protocol with each of the 37 ICEYE satellites enrolled as the target in turn. Figure 7 reports the resulting hit and miss rates, sorted by decreasing hit rate. Two regimes appear: the first group of 28 satellites reaches a hit rate of 1.00, that is, the classifier authenticates every test burst of the target. A second group of nine satellitesâX11, X7, X17, X23, X4, X20, X33, X6, X14âshows lower hit rates, from 0.93 (X11) down to 0.25 (X14), with miss rates up to 0.75. X14, the worst case, is also the satellite with the most stationary waveform and the lowest constellation count density in Figure 4. The reduced fingerprint contrast is the most likely cause of its degraded authentication. Fig. 7: Per-satellite hit rate (circles) and miss rate (crosses) for the full 37-satellite ICEYE constellation, sorted by descending hit rate. Twenty-eight satellites achieve hit rate =1.00=1.00 and miss rate =0.00=0.00; a group of nine satellites exhibits degraded performance, with X14 reaching the lowest hit rate (0.25). VI-E Ablation Study and Benchmark Comparison Architectural ablation. To isolate the contribution of the VQC branch, we evaluate four configurations on the identical balanced dataset. QNN-Only applies a standalone VQC to a PCA-compressed 8-dimensional input, replicating the naive quantum baseline in which PCA destroys temporal semantics. CNN-Only retains the CNN encoder and classical skip while removing the VQC branch entirely (=Cz=v_C, 64-dimensional classifier input). QuaSAR (angle embedding) is the full hybrid architecture driven by the conventional real-valued embedding of Eq. (3), and QuaSAR is the full hybrid architecture with the IQ-native encoding (Section VI-D). Benchmark against classical spectrogram classifiers. To contextualize performance within the broader landscape of spectrogram-based deep learning, we additionally evaluate three classical architectures trained under the identical protocol (Adam, Ρ=10â3Ρ=10^-3, early stopping, 25 seeds): ResNet-18 adapted for single-channel spectrograms, a lightweight Transformer encoder, and MobileNetV2. Table I consolidates both evaluations. QuaSAR achieves the highest accuracy (96.9%) and macro-F1 (0.969) among all evaluated configurations. Three findings warrant attention. First, the QNN-Only configuration is the weakest overall (71.3%, F1=0.709F1=0.709), confirming that PCA-induced information loss is the primary failure mode of standalone quantum approaches: discarding temporal structure removes precisely the signal carrying hardware impairment information. Second, the 7.5 percentage-point accuracy gap between CNN-Only (89.4%, F1=0.891F1=0.891) and QuaSAR (96.9%, F1=0.969F1=0.969) is consistent across both metrics, ruling out a precisionârecall trade-off artifact and confirming that the VQC contributes a non-redundant discriminative signal unavailable to classical fully-connected layers of comparable parameter count. Of this gap, 5.35.3 points survive when the quantum branch is driven by a conventional angle embedding (94.7%, F1=0.947F1=0.947), so the branch and its IQ-native input contribute separately rather than one standing in for the other. Third, all three external classical architectures plateau at or below 85.7% accuracy and F1=0.861F1=0.861, despite parameter counts substantially exceeding the QuaSAR quantum branch, confirming that standard convolutional transfer architectures underfit the micro-scale nonlinearities distinguishing ICEYE hardware generations. TABLE I: Ablation and benchmark results on the binary authentication task (DtestD_test, mean over 25 seeds). The upper block reports ablation variants of QuaSAR; the lower block reports external classical spectrogram classifiers trained under the identical protocol. Model Accuracy Macro-F1 Ablation variants QNN-Only (PCA + VQC) 0.713 0.709 CNN-Only (no VQC) 0.894 0.891 QuaSAR (angle embedding) 0.947 0.947 Classical spectrogram baselines Spectrogram ResNet 0.854 0.861 Spectrogram MobileNet 0.847 0.851 Spectrogram Transformer 0.857 0.834 QuaSAR (IQ-native, ours) 0.969 0.969 VI-F Gradient Saliency Explainability To localize the temporal features driving authentication decisions, we compute input-space gradient saliency maps. The IQ signal xâĄ[n]x[n] is processed through the full differentiable graphâincluding the PyTorch-native torch.fft STFTâand the target-class logit is backpropagated to the raw IQ tensor: Sn=|ây^targetâxn|,n=1,âŚ,NsamplesS_n= | â\, y_targetâ\,x_n |, n=1,âŚ,N_samples (13) Analysis over 50 correctly classified bursts shows that QuaSAR consistently concentrates its decision signal on a contiguous window spanning less than 1 ms of transmission time, coinciding with the onset of each radar pulse where hardware transient effects (power-on phase noise, initial oscillator drift) are most pronounced. This temporal localization is quantitatively sharper under the hybrid architecture than under the CNN-Only baseline, consistent with the VQC amplifying micro-scale phase features at burst onset. VI-G Per-Satellite Spoofing Detection We evaluate QuaSAR against Scenario (A) replay on the three satellites (X4, X20, X41) for which laboratory replay data was acquired. Spoofed bursts are produced by re-emitting recorded captures through a separate USRP X310 transmit chain, whose hardware impairments are added on top of the replayed waveform. Table I reports the per-satellite and aggregate metrics. QuaSAR achieves a mean accuracy of 91.39%, a macro-F1 of 0.9114, andâcriticallyâperfect recall (1.00) on all three satellites: no spoofed burst evades detection, regardless of the target satellite identity. Precision varies from 0.769 (X4) to 0.952 (X41). This spread reflects differences in the fingerprint contrast between each targetâs hardware and the spooferâs transmit chain, rather than classifier instability. The lower precision on X4 corresponds to a higher false-positive rate on legitimate bursts in its acquisition window, which we attribute to elevated terrestrial interference during that collection slot; we return to this point in Section IX. TABLE I: Per-satellite spoofing detection performance under Scenario (A) replay. Spoofed IQ signals from three operational ICEYE satellites are evaluated against the trained QuaSAR classifier. Recall = 1.00 on all satellites confirms zero missed detections. Satellite Acc Prec Rec F1 X4 0.85 0.76 1.00 0.86 X20 0.91 0.80 1.00 0.88 X41 0.97 0.95 1.00 0.97 Mean 0.91 0.84 1.00 0.91 VII Explainability Analysis This section examines the internal representations learned by QuaSAR to assess whether its classification decisions are physically grounded and interpretable. We analyze the structure of the fused latent space via t-SNE projection and quantitative clustering indices, and visualize the decision boundary separating legitimate from spoofed transmissions in the PCA-projected latent space. Latent-space geometry via t-SNE. To assess whether QuaSAR learns geometrically separable representations of legitimate and spoofed transmissions, we project the 72-dimensional fused latent vectors z (Eq. (12)) onto two dimensions via t-SNE (perplexity=30perplexity=30, 500500 iterations) for three representative ICEYE satellites: X4, X20, and X41. Figure 8 shows the resulting embedding. Legitimate bursts (filled circles) and their spoofed counterparts (crosses) form clearly distinct clusters for all three satellites, with inter-class separation consistently larger than intra-class spread. Legitimate embeddings are compact and well localized, indicating stable fingerprint representations across signals from the same orbital pass. Spoofed embeddings occupy systematically displaced regions of the latent space, showing that the hybrid encoder amplifies the fingerprint discrepancy introduced by the spooferâs transmit chain. Notably, the three satellite identities are themselves mutually separated, demonstrating that QuaSAR implicitly learns a multi-class structure even when trained on a binary objective. Fig. 8: t-SNE projection of the 72-dimensional fused latent space z for three ICEYE satellites (X4, X20, X41). Filled circles denote legitimate bursts. Crosses denote spoofed bursts generated under Scenario (A) replay. Each satellite identity occupies a distinct, compact region; spoofed samples are displaced from their legitimate counterparts in all three cases, confirming that the quantum-classical encoder preserves and amplifies inter-class fingerprint distance. Quantitative cluster quality. Visual inspection of the t-SNE embedding is corroborated by three standard internal clustering indices computed directly on the 72-dimensional latent vectors z, without dimensionality reduction. Table IV reports Silhouette Score (S), CalinskiâHarabasz index (CH), and DaviesâBouldin index (DB) for QuaSAR and the CNN-Only baseline. QuaSAR improves S by +0.067+0.067 (+21.6% relative), CH by +2.49+2.49 (+4.0%), and reduces DB by 0.1880.188 (â15.4%-15.4\%) with respect to the classical baseline. Because S and CH are monotonically increasing in cluster quality while DB is monotonically decreasing, all three indices consistently favor the hybrid encoder. The DB reduction is particularly relevant for authentication: a lower DaviesâBouldin index implies that clusters are more compact relative to the distance separating them, directly translating to a wider margin between legitimate and spoofed representations and, consequently, a lower spoofing miss-detection rate. Taken together, these results provide quantitative evidence that the variational quantum branch reorganizes the latent space so that hardware-induced fingerprint differences are amplified beyond what classical fully-connected layers of comparable parameter count achieve. TABLE IV: Internal clustering quality of the 72-dimensional fused latent space z for QuaSAR and the CNN-Only baseline. Higher Silhouette Score and CalinskiâHarabasz index indicate better-separated clusters; lower DaviesâBouldin index indicates more compact clusters. All indices are computed on the full test partition without dimensionality reduction. Model Silhouette â CalinskiâHarabasz â DaviesâBouldin â CNN-Only 0.3106 61.69 1.2219 QuaSAR 0.3775 64.18 1.0341 Î (rel.) +21.6%+21.6\% +4.0%+4.0\% â15.4%-15.4\% Fig. 9: Decision surface for satellite X41 in the PCA-projected latent space z. The color map encodes the posterior PâĄ(spoofâŁ)P(spoof ) fitted by a logistic classifier on the two leading principal components; the dashed line marks the P=0.5P=0.5 iso-contour. Legitimate bursts (blue circles) cluster in the low-probability region; spoofed bursts (red crosses) concentrate in the high-probability region, with no cross-boundary misclassification for X41. VIII Related Work TABLE V: Positioning of QuaSAR against representative prior work in satellite RF fingerprinting, physical-layer authentication, and quantum-hybrid RFFI. Rows are grouped by methodological family. Method Target signal & band Data (real / sim, scale) Architecture Reported metric / performance Main contribution Classical RF fingerprinting â sub-6 GHz satellites PAST-AI [30] IRIDIUM, L-band Real, 589 h / 66 sats CNN + Autoencoder Authentication accuracy: 80â100% (scenario/assumption dependent) First deep-learning satellite RFFI SatIQ [40] IRIDIUM, L-band Real, 10.29 M msgs Siamese + autoencoder EER: 0.072 ROC AUC: 0.960 High-rate IQ raises spoofing cost FadePrint [31] IRIDIUM, L-band (channel) Real satellite + terrestrial captures Fading-process classifier Spoofing-detection accuracy: >>99% (satellite vs. indoor terrestrial) Channel fading as fingerprint ORBID [42] ORBCOMM, VHF Real, 8.99 M packets CNN + triplet loss ROC AUC: 0.53 (satellite ID) ROC AUC: 0.98 (satellite vs. SDR) Modulation-dependent ID limits Classical RF fingerprinting â above 6 GHz SatTransformer [46] Starlink, Ku-band (waterfall) Real, >>30 k / 25 d (spec. an.) Vision Transformer Identification accuracy: 91.3% F1-score: 90.1% First >>6 GHz satellite RFFI Spectrum analyzer only (no SDR) Channel-based PLA â simulation only Abdrabou [1] LEO generic STK-derived satellite data DS + RP, OCC-SVM Authentication rate (AR): 73.6â95.5% at θ=80âθ=80 as training size Ί=â10 =1\!â\!10 PLA using Doppler shift and received power Topal [44] Inter-satellite Numerical / simulated Doppler-based decision fusion Spoofing detection PDP_D vs. false alarm PFP_F majority fusion gives best reported trade-off Inter-satellite PLA scheme Quantum machine learning on RF An et al. [4] LoRa IoT, sub-1 GHz Real LoRa captures CNN+RNN+QNN, angle embedding Classification accuracy: 81.3% QML RFFI on real RF data Terrestrial IoT, not satellite QuaSAR (ours) ICEYE SAR, X-band (9.65 GHz) Real, 3.76 TB / 37 sats / 28 d CNN + VQC, IQâqubit encoding Classification accuracy: 96.9% with 10% data matches classical baselines trained on 100% data First QML RFFI for satellites Processing X-band SAR signals Native IQâqubit encoding A growing body of literature has investigated the use of machine learning to extract physical-layer fingerprints from radio transmitters, spanning terrestrial IoT devices, LEO communication satellites, and, more recently, quantum-enhanced classifiers. In the following, we summarize existing work and position QuaSAR with respect to the state of the art. Satellite RF fingerprinting. PAST-AI [30] conducts a 589-hour collection campaign on the 66-satellite IRIDIUM constellation, achieving 80â100% accuracy across classification scenarios with a deep CNN on IQ-derived features at L-band. SatIQ [40] proposes a Siamese neural network and an autoencoder for high- sample-rate IRIDIUM fingerprinting, reaching an Equal Error Rate of 0.072 and ROC AUC of 0.960. FadePrint [31] fingerprints the fading process of the satellite channel rather than hardware impairments, achieving over 99% accuracy on IRIDIUM without retraining when new satellites join the constellation. SatTransformer [46] applies a vision transformer to Starlink Ku-band waterfall images from a spectrum analyzer, achieving 91.3% identification accuracy over 25 days. ORBID [42] targets ORBCOMM satellites using triplet-loss-based methods on raw IQ data. All of these systems operate below 6 GHz or rely on spectrum analyzers instead of SDRs, and none address SAR imaging signals. Our work is the first to fingerprint X-band SAR illuminating pulses at frequencies above the SDR ceiling. Physical-layer security for LEO satellites. Abdrabou and Gulliver [1] leverage Doppler frequency shift and received power to authenticate LEO satellites, achieving 73.6â95.5% detection depending on elevation angle in simulation. Topal and Karabulut Kurt [44] develop an inter-satellite PLA scheme based on Doppler measurements with 90â100% simulated detection probability. Neither study addresses X-band frequencies or real data acquisition at those frequencies. Quantum machine learning for RF classification. Biamonte et al. [6] provide the theoretical foundations for quantum ML, establishing that VQCs can implement Hilbert-space functions exponentially expensive to simulate classically. Schuld and Petruccione [38] and Mitarai et al. [25] formalize the parameter- shift rule enabling VQC training via backpropagation. The application of quantum ML to RF fingerprinting, however, remains nascent: existing works are largely limited to simulated IoT scenarios [19], with no deployment against real satellite IQ data. An et al. [4] propose a hybrid CNNâRNNâQNN architecture for LoRa device fingerprinting, demonstrating that inserting a quantum neural network stage reduces the trainable parameter count by 98.5% relative to classical baselines while maintaining competitive accuracy (81.27%) on real captures â the first quantum-hybrid RFFI system evaluated on measured rather than simulated data. However, the work targets sub-6 GHz LoRa devices, uses angle embedding of scalar features without exploiting the complex-valued structure of IQ samples, and does not address the satellite domain. Adversarial attacks on RF classifiers. A class of threat targets the classifier itself rather than the transmitter: carefully crafted perturbations added to the received signal can flip a deep modelâs prediction without meaningfully changing the underlying waveform. Three properties make RF a fertile domain for such attacks. First, the perturbation budget required is typically far below the channel noise floor, so adversarial energy is both cheaper and stealthier than conventional jamming [34]. Second, the attack surface is broad: the same vulnerability has been demonstrated across architectures (CNN, LSTM, and GRU ensembles), across tasks such as modulation classification, end-to-end autoencoder communication, and regression for resource allocation, and across both white-box and black-box [45, 35, 22]. RF fingerprinting is structurally more exposed than modulation classification, because the discriminative signal lives in hardware impairments that are close in magnitude to a viable adversarial perturbation. Attackers with only limited model knowledge have driven LoRa fingerprinter accuracy below 20% [21]. IX Discussion This section reflects on the practical implications of QuaSARâs data efficiency for operational satellite authentication deployments and identifies the limitations of the current evaluation. The feasibility of QuaSAR is tied to the trajectory of quantum hardware. In this article, we simulate the VQC classically rather than executing it on a quantum device. Current superconducting platforms have surpassed 1,000 physical qubits [16], while trapped-ion systems report two-qubit gate fidelities exceeding 99.9% [32]. Credible engineering roadmaps project NISQ devices with sufficient coherence for practical variational circuits by 2027â2028 [16]. In particular, QuaSAR does not require fault-tolerant quantum computing: all quantum modules operate within circuits of fewer than 100 two-qubit gates and 8 qubits. This regime is already accessible on commercial cloud backends (IBM Quantum, IonQ). Given that ICEYE-class constellation generations carry operational lifetimes of 7â10 years, QuaSAR is projected to become executable within the active service window of currently deployed satellites. Complementarity to cryptographic authentication. QuaSAR is positioned as a layer orthogonal to cryptographic message authentication. SAR imaging pulses are LFM chirps with no payload structure capable of carrying data. PLA operates entirely on the receiver side and does not require modification of the orbital segment. Besides, it remains effective under the post-quantum threat scenarios that motivate the gradual migration of satellite key infrastructure. This process is projected to span the same 2027â2030 horizon as the NISQ deployment timeline discussed above [16]. QuaSAR might be part of a defense-in-depth scheme: cryptographic compromise of the command channel does not translate into successful imagery forgery, and conversely, hardware fingerprint drift does not invalidate cryptographic tools for telemetry. Implications. The most significant contribution of QuaSAR is its ability to match classical baseline performance with substantially less training data and hyperparameter tuning. This property is of high practical importance in the satellite domain. Unlike terrestrial RF fingerprinting scenarios, where data collection is fast and inexpensive, acquiring labeled IQ bursts from SAR satellites is limited by radio passes: a single satellite completes at most a few passes per day over a fixed ground station, each lasting no longer than 15 minutes. A representative corpus spanning diverse acquisition modes and atmospheric conditions requires weeks to months of continuous collection. Our results demonstrate that QuaSAR reaches classical baseline accuracy using only 10% of the available training data, compressing what would otherwise be a multi-month enrollment phase into a substantially shorter collection window. This directly lowers the barrier to deploying physical-layer authentication for satellite constellations, where scheduling observation time against authentication infrastructure is a non-trivial logistical cost. Beyond data efficiency, the 7.5 percentage-point accuracy gain over the classical-only baseline indicates that the VQC contributes discriminative information that the classical branch does not capture. The encoding ablation of Section VI-D sharpens this statement: 2.22.2 of those points are attributable to the IQ-native encoding alone, with every other component of the architecture held fixed. The geometric correspondence between a complex sample and a qubit is therefore not merely an expository deviceâit is measurable, and discarding the phase coordinate at the quantum interface costs both accuracy and training time. We note this gap may widen or narrow under more exhaustive hyperparameter optimization of the classical baseline, and therefore, we do not claim it as the primary result [8]. Future works. Three directions extend the present study. First, we will scale QuaSAR from binary authentication to per-satellite fingerprinting across the full ICEYE constellation, treating each of the 37 satellites as a distinct class. This is a harder task for a classifier, as satellites sharing a common payload must be separated based on even more subtle hardware differences. Second, satellite hardware drifts over a mission lifetime. Thermal cycling, total ionizing dose, and mechanical stress all alter the radar payload, changing the impairment signature on which QuaSAR relies. A fingerprint enrolled at a given point in time will therefore degrade. We plan to integrate a transfer-learning protocol that periodically updates the CNN encoder and classification head on recent illumination signals, while leaving the VQC parameters fixed or updated at a slower cadence. Third, we will improve the acquisition testbed to capture all four ICEYE polarization modes (V, VH, HV, H) rather than the single linear channel of the HyperLOG PRO front end. A dual-polarized feed with parallel downconversion chains would expose the classifier to the full polarimetric scattering matrix transmitted in Spot and Strip modes. X Conclusion In this paper we have introduced, to the best of our knowledge, the first hybrid architecture that combines quantum and classical ML to provide PLA to satellites operating in the challenging X-band. We have developed QuaSAR, a quantum-classical hybrid convolutional architecture, achieving 97.3% validation accuracy and macro-F1 = 0.973 in binary physical-layer authentication of X-band SAR satellites, outperforming a classical-only baseline by 7.5 percentage points on a 3.76 TB real-world IQ dataset spanning 37 operational ICEYE satellites. What is more, these results have been secured using only one tenth of the data required by classical ML. Our framework is also analytically dissected: (i) an ablation analysis confirms that the variational quantum circuit contributes a non-redundant discriminative signal unavailable to classical layers of comparable size, and that loading its input through an IQ-native amplitudeâphase encoding rather than a conventional angle embedding is worth a further 2.2 percentage points at 46% fewer training epochs; (i) gradient saliency maps localize authentication decisions to sub-millisecond pulse-onset windows in the raw IQ domain; and, (i) an explainability analysis identifies the relative contributions of the quantum and classical branches. Finally, we tested our solution under three adversarial attack scenariosâreplay, crafted-IQ injection, and space-borne spoofingâQuaSAR rejects spoofed transmissions in 89.7%, 94.1%, and 81.3% of attempts, respectively. This work establishes the first quantum-enhanced PLA system for X-band SAR satellites and opens a research direction at the intersection of quantum machine learning and space-domain security. Ethics Considerations All IQ data were collected by passively receiving omnidirectional SAR imaging pulses propagating through free space. No command, control, or downlink channels were intercepted, and satellite operations were not affected. Replay experiments were conducted entirely in a laboratory, under controlled conditions that prevented interference with external operational receivers. References [1] M. Abdrabou and T. A. Gulliver (2023) Authentication for satellite communication systems using physical characteristics. IEEE Open Journal of Vehicular Technology 4 (), p. 48â60. External Links: Document Cited by: TABLE V, §VIII. [2] I. Agadakos, N. Agadakos, J. Polakis, and M. R. Amer (2020) Chameleonsâ oblivion: complex-valued deep neural networks for protocol-agnostic rf device fingerprinting. In 2020 IEEE European Symposium on Security and Privacy (EuroS&P), Vol. , p. 322â338. External Links: Document Cited by: §I-D. [3] C. Alexandre, R. Devillers, D. Mouillot, R. Seguin, and T. Catry (2024) Ship detection with sar c-band satellite images: a systematic review. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing 17 (), p. 14353â14367. External Links: Document Cited by: §I-A. [4] T. T. An, S. L. Cotton, J. Zhang, Y. Ding, and T. Q. Duong (2024) LoRa radio frequency fingerprinting identification using a hybrid quantum-classical neural network. In 2024 IEEE 100th Vehicular Technology Conference (VTC2024-Fall), Vol. , p. 1â6. External Links: Document Cited by: §VI-D, TABLE V, §VIII. [5] V. Bergholm, J. Izaac, M. Schuld, C. Gogolin, S. Ahmed, V. Ajith, M. S. Alam, G. Alonso-Linaje, J. M. Arrazola, A. Asadi, U. Azad, S. Banning, C. Blank, A. Delgado, N. Killoran, et al. (2022) PennyLane: automatic differentiation of hybrid quantum-classical computations. Note: arXiv:1811.04968Accessed: Aug. 20, 2026 Cited by: §V-B. [6] J. Biamonte, P. Wittek, N. Pancotti, P. Rebentrost, N. Wiebe, and S. Lloyd (2017) Quantum machine learning. Nature 549 (7671), p. 195â202. External Links: Document Cited by: §I, §V-B, §VI-A, §VIII. [7] M. Bonano, M. Manunta, A. Pepe, L. Paglia, and R. Lanari (2013) From previous c-band to new x-band sar systems: assessment of the dinsar mapping improvement for deformation time-series retrieval in urban areas. IEEE Transactions on Geoscience and Remote Sensing 51 (4), p. 1973â1984. External Links: Document Cited by: §I-A. [8] J. Bowles, S. Ahmed, and M. Schuld (2024) Better than classical? the subtle art of benchmarking quantum machine learning models. arXiv preprint arXiv:2403.07059. Note: Accessed: Aug. 20, 2026 Cited by: §IX. [9] J. Chen, W. Wong, B. Hamdaoui, A. Elmaghbub, K. Sivanesan, R. Dorrance, and L. L. Yang (2022) An analysis of complex-valued cnns for rf data-driven wireless device classification. In ICC 2022 - IEEE International Conference on Communications, Vol. , p. 4318â4323. External Links: Document Cited by: §I-D. [10] J. C. Curlander and R. N. McDonough (1991) Synthetic aperture radar: systems and signal processing. Wiley, New York. External Links: ISBN 978-0471857709 Cited by: §I-A. [11] eoPortal (2026) ICEYE microsatellites constellation. European Space Agency (ESA) / eoPortal. Note: Last updated: March 28, 2026https://w.eoportal.org/satellite-missions/iceye-constellation Cited by: §I-A. [12] G. Fontanelli, A. Lapini, L. Santurri, S. Pettinato, E. Santi, G. Ramat, S. Pilia, F. Baroni, D. Tapete, F. Cigna, and S. Paloscia (2022) Early-season crop mapping on an agricultural area in italy using x-band dual-polarization sar satellite data and convolutional neural networks. IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing 15 (), p. 6789â6803. External Links: Document Cited by: §I. [13] M. Foruhandeh, A. Z. Mohammed, G. Kildow, P. Berges, and R. Gerdes (2020) SPOTR: GPS spoofing detection via device fingerprinting. In Proc. 13th ACM WiSec, p. 242â253. Cited by: §I. [14] A. Golkar, G. Cataldo, and K. Osipova (2021) Small satellite synthetic aperture radar (sar) design: a trade space exploration model. Acta Astronautica 187, p. 458â474. External Links: ISSN 0094-5765, Document, Link Cited by: §I-A. [15] K. He, X. Zhang, S. Ren, and J. Sun (2016) Deep residual learning for image recognition. In CVPR, p. 770â778. Cited by: §V-A. [16] IBM Research (2023) IBM quantum system two and the 1121-qubit condor processor. Note: https://w.ibm.com/quantum/blog/quantum-roadmap-2033Accessed: Apr. 2026 Cited by: §IX, §IX. [17] M. Irfan, S. Sciancalepore, and G. Oligeri (2024) On the reliability of radio frequency fingerprinting. Note: arXiv:2408.09179Accessed: Aug. 20, 2026 Cited by: §IV-C. [18] G. Liu, B. Liu, G. Zheng, and X. Li (2022) Environment monitoring of shanghai nanhui intertidal zone with dual-polarimetric sar data based on deep learning. IEEE Transactions on Geoscience and Remote Sensing 60 (), p. 1â18. External Links: Document Cited by: §I. [19] Q. Lu, Z. Yang, H. Zhang, F. Chen, and H. Xian (2024) MRFE: a deep-learning-based multidimensional radio frequency fingerprinting enhancement approach for IoT device identification. IEEE Internet of Things Journal 11 (18), p. 30442â30454. External Links: Document Cited by: §VIII. [20] J. Lv, D. Zhu, Z. Geng, S. Han, Y. Wang, W. Yang, Z. Ye, and T. Zhou (2023) Recognition of deformation military targets in the complex scenes via minisar submeter images with fasar-net. IEEE Transactions on Geoscience and Remote Sensing 61, p. 1â19. Cited by: §I-A. [21] J. Ma, J. Zhang, G. Shen, A. Marshall, and C. Chang (2025) Adversarial attacks against deep learning-based radio frequency fingerprint identification. IEEE Transactions on Mobile Computing. External Links: Document Cited by: §VIII. [22] B. R. Manoj, M. Sadeghi, and E. G. Larsson (2021) Adversarial attacks on deep learning based power allocation in a massive MIMO network. In 2021 IEEE International Conference on Communications (ICC), External Links: Document Cited by: §VIII. [23] J. R. McClean, S. Boixo, V. N. Smelyanskiy, R. Babbush, and H. Neven (2018) Barren plateaus in quantum neural network training landscapes. Nature Communications 9 (1), p. 4812. Cited by: §V-B. [24] A. Misra, K. White, S. F. Nsutezo, W. Straka I, and J. Lavista (2025) Mapping global floods with 10 years of satellite radar data. Nature Communications 16 (1), p. 5762. Cited by: §I, §I-A. [25] K. Mitarai, M. Negoro, M. Kitagawa, and K. Fujii (2018) Quantum circuit learning. Phys. Rev. A 98 (3), p. 032309. Cited by: §I-C, §VIII. [26] A. Moreira, P. Prats-Iraola, M. Younis, G. Krieger, I. Hajnsek, and K. P. Papathanassiou (2013) A tutorial on synthetic aperture radar. IEEE Geoscience and Remote Sensing Magazine 1 (1), p. 6â43. External Links: Document Cited by: §I-A, §I-A. [27] M. Motallebighomi, H. Sathaye, M. Singh, and A. Ranganathan (2022) Cryptography is not enough: relay attacks on authenticated GNSS signals. Note: arXiv:2204.11641Accessed: Aug. 20, 2026 Cited by: §I. [28] S. Nawab, T. Quatieri, and J. Lim (1983) Signal reconstruction from short-time fourier transform magnitude. IEEE Transactions on Acoustics, Speech, and Signal Processing 31 (4), p. 986â998. External Links: Document Cited by: §I-B. [29] M. A. Nielsen and I. L. Chuang (2010) Quantum computation and quantum information. Cambridge university press. Cited by: §I-D. [30] G. Oligeri, S. Sciancalepore, S. Raponi, and R. Di Pietro (2023) PAST-AI: physical-layer authentication of satellite transmitters via deep learning. IEEE Trans. Inf. Forensics Secur. 18, p. 274â289. External Links: Link, Document Cited by: §I, §I-B, TABLE V, §VIII. [31] G. Oligeri, S. Sciancalepore, and A. Sadighian (2024) FadePrint - satellite spoofing detection via fading fingerprinting. In 21st IEEE Consumer Communications & Networking Conference, CCNC 2024, Las Vegas, NV, USA, January 6-9, 2024, p. 827â830. External Links: Link, Document Cited by: TABLE V, §VIII. [32] A. Paetznick, M. P. da Silva, C. Ryan-Anderson, J. M. Bello-Rivas, J. P. Campora I, A. Chernoguzov, J. M. Dreiling, C. Foltz, F. Frachon, J. P. Gaebler, T. M. Gatterman, L. Grans-Samuelsson, D. Gresh, D. Hayes, N. Hewitt, C. Holliman, C. V. Horst, J. Johansen, D. Lucchetti, Y. Matsuoka, M. Mills, S. A. Moses, B. Neyenhuis, A. Paz, J. Pino, P. Siegfried, A. Sundaram, D. Tom, S. J. Wernli, M. Zanner, R. P. Stutz, and K. M. Svore (2024) Demonstration of logical qubits and repeated error correction with better-than-physical error rates. arXiv preprint arXiv:2404.02280. Note: Accessed: Aug. 20, 2026 Cited by: §IX. [33] A. Reigber and A. Moreira (2002) First demonstration of airborne sar tomography using multibaseline l-band data. IEEE Transactions on Geoscience and Remote Sensing 38 (5), p. 2142â2152. Cited by: §I-A. [34] M. Sadeghi and E. G. Larsson (2019) Adversarial attacks on deep-learning based radio signal classification. IEEE Wireless Communications Letters 8 (1), p. 213â216. Cited by: §VIII. [35] M. Sadeghi and E. G. Larsson (2019) Physical adversarial attacks against end-to-end autoencoder communication systems. IEEE Communications Letters 23 (5), p. 847â850. External Links: Document Cited by: §VIII. [36] K. Sankhe, M. Belgiovine, F. Zhou, L. Angioloni, F. Restuccia, S. DâOro, T. Melodia, S. Ioannidis, and K. Chowdhury (2019) No radio left behind: radio fingerprinting through deep learning of physical-layer hardware impairments. IEEE Transactions on Cognitive Communications and Networking 6 (1), p. 165â178. Cited by: §I, §I-B. [37] M. Schuld, A. Bocharov, K. M. Svore, and N. Wiebe (2020) Circuit-centric quantum classifiers. Phys. Rev. A 101 (3), p. 032308. Cited by: §I-C, §V-B. [38] M. Schuld and F. Petruccione (2021) Machine learning with quantum computers. Springer. Cited by: §I-D, §VIII. [39] K. Simonyan and A. Zisserman (2015) Very deep convolutional networks for large-scale image recognition. In ICLR, Cited by: §V-A. [40] J. Smailes, S. KĂśhler, S. Birnbach, M. Strohmeier, and I. Martinovic (2025) SatIQ: extensible and stable satellite authentication using hardware fingerprinting. ACM Trans. Priv. Secur.. External Links: ISSN 2471-2566, Link, Document Cited by: §I, TABLE V, §VIII. [41] G. Soldi, D. Gaglione, N. Forti, A. Di Simone, F. C. DaffinĂ , G. Bottini, D. Quattrociocchi, L. M. Millefiori, P. Braca, S. Carniel, et al. (2021) Space-based global maritime surveillance. part i: satellite technologies. IEEE Aerospace and Electronic Systems Magazine 36 (9), p. 8â28. Cited by: §I, §I-A. [42] C. Solenthaler, J. Smailes, and M. Strohmeier (2025) OrbID: identifying orbcomm satellite rf fingerprints. arXiv preprint arXiv:2503.02118. Note: Accessed: Aug. 20, 2026 Cited by: TABLE V, §VIII. [43] V. Syrjala, M. Valkama, L. Anttila, T. Riihonen, and D. Korpi (2014) Analysis of oscillator phase-noise effects on self-interference cancellation in full-duplex ofdm radio transceivers. IEEE Transactions on Wireless Communications 13 (6), p. 2977â2990. Cited by: §I. [44] O. A. Topal and G. Karabulut Kurt (2022) Physical layer authentication for leo satellite constellations. In 2022 IEEE Wireless Communications and Networking Conference (WCNC), Vol. , p. 1952â1957. External Links: Document Cited by: TABLE V, §VIII. [45] M. Usama, J. Qadir, and A. Al-Fuqaha (2019) Black-box adversarial ML attack on modulation classification. Note: arXiv preprint arXiv:1908.00635Accessed: Aug. 20, 2026 External Links: Document Cited by: §VIII. [46] M. Zhang, Z. Fu, W. Wang, H. Guo, Z. Qiu, and X. Zhang (2025) SatTransformer: spectrum features-based identification of leo satellites using transformer. In 2025 IEEE Wireless Communications and Networking Conference (WCNC), p. 1â6. Cited by: TABLE V, §VIII. Appendix A Open science As a supplementary artifact, we provide the whole code and sufficient data to fully reproduce the findings of this article: ⢠Code. The code used for this article is available to reviewers at the following link: https://anonymous.4open.science/r/QuantumSAR. ⢠Filtered IQ dataset. The full set of filtered IQ recordings collected from the 37 operational ICEYE satellites (post-filtering, as described in Section IV-D). These files are sufficient to reproduce all spectrograms, training runs, and reported F1-scores. The dataset is hosted anonymously and linked from the anonymous repository above. Available at: https://drive.proton.me/urls/470H26X9G#MCHdOH2JkSXS Both the repository and the dataset will be transferred to Zenodo upon acceptance. AI use disclosure Generative AI tools, including ChatGPT and Claude, were used to assist with manuscript writing and linguistic refinement, as well as with code development, debugging, and documentation. All AI-assisted content and code were reviewed and validated by the authors. The scientific methodology, experimental design, analysis, interpretation of results, and conclusions remain the responsibility of the authors, who take full responsibility for the final manuscript and associated code.