Paper deep dive
Beyond the QBER Threshold: A Temporal QBER Based Machine Learning Framework for Multi Attack Detection in BB84 QKD
Isha, Deepak Singh, Devesh Kumar, S. K Pal, Praful Hambarde, Amit Shukla
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 93%
Last extracted: 8/9/2026, 2:35:17 AM
Summary
The paper proposes a temporal QBER-based machine learning framework for detecting and classifying seven types of eavesdropping attacks in BB84 Quantum Key Distribution (QKD) systems. By extracting 63 physics-informed temporal features from QBER sequences, the framework significantly outperforms conventional fixed-threshold monitoring, achieving 88.01% accuracy with XGBoost and reducing the False Negative Rate from 84.77% to 1.98%.
Entities (14)
Relation Signals (11)
BB84 → uses → QBER
confidence 98% · BB84 Quantum Key Distribution (QKD) systems rely on a fixed 11% Quantum Bit Error Rate (QBER) threshold
XGBoost → achievesbestperformance → Temporal QBER Framework
confidence 95% · XGBoost achieves the best performance with 88.01% (0.47%) accuracy
Fixed 11% QBER Threshold → outperformedby → Temporal QBER Framework
confidence 95% · fixed 11% QBER threshold achieves only 25.82% accuracy... whereas the proposed framework reduces the FNR to 0.0198
Temporal QBER Framework → detects → Beam Splitting
confidence 92% · evaluated on seven eavesdropping attacks... Beam Splitting
Temporal QBER Framework → detects → Time-Shift
confidence 92% · evaluated on seven eavesdropping attacks... Time-Shift
Temporal QBER Framework → detects → Trojan Horse
confidence 92% · evaluated on seven eavesdropping attacks... Trojan Horse
Temporal QBER Framework → detects → Quantum Cloning
confidence 92% · evaluated on seven eavesdropping attacks... Quantum Cloning
Temporal QBER Framework → detects → Fake State
confidence 92% · evaluated on seven eavesdropping attacks... Fake State
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Conventional BB84 Quantum Key Distribution (QKD) systems rely on a fixed 11% Quantum Bit Error Rate (QBER) threshold to detect eavesdropping. However, stealthy attacks can remain below this threshold while still compromising channel security. This paper proposes a temporal QBER based machine learning framework for detecting and classifying eavesdropping attacks in BB84 QKD systems. Rather than relying on average session level QBER, the framework extracts 63 physics-informed temporal features capturing burst behavior, temporal instability, basis dependent asymmetry, and QBER loss interactions. Random Forest, XGBoost, and Support Vector Machine with a Radial Basis Function kernel (SVM-RBF) classifiers are evaluated on seven eavesdropping attacks and a normal channel scenario under noisy and lossy conditions. Averaged over ten independent runs, XGBoost achieves the best performance with 88.01% (0.47%) accuracy and a macro F1 score of 0.8803, while SVM-RBF performs comparably, confirming the robustness of the proposed features. Evaluated as a binary attack-versus-normal detector for comparison with conventional monitoring, a fixed 11% QBER threshold achieves only 25.82% accuracy with a False Negative Rate (FNR) of 0.8477, whereas the proposed framework reduces the FNR to 0.0198, substantially improving detection of stealthy attacks that evade threshold-based monitoring. SHapley Additive exPlanations based (SHAP) explainability shows that physics-informed temporal and channel derived features are highly discriminative for identifying eavesdropping strategies. These results demonstrate that temporal QBER driven machine learning provides an accurate, explainable, and practical framework for multi attack security monitoring in BB84 QKD systems.
Tags
Links
- Source: https://arxiv.org/abs/2608.04047v1
- Canonical: https://arxiv.org/abs/2608.04047v1
PDF not stored locally. Use the link above to view on the source site.
Full Text
27,326 characters extracted from source content.
Expand or collapse full text
Beyond the QBER Threshold: A Temporal QBER Based Machine Learning Framework for Multi Attack Detection in B84 QKD Isha Drone Lab, IIT Mandi S24041@students.iitmandi.ac.in Deepak Singh Drone Lab, IIT Mandi D24021@students.iitmandi.ac.in Devesh Kumar DRDO devesh.kumar.hqr@gov.in S.K Pal DRDO saibal.pal@gov.in Praful Hambarde Drone Lab, IIT Mandi praful@iitmandi.ac.in Amit Shukla Drone Lab, IIT Mandi amitshukla@iitmandi.ac.in Abstract Conventional B84 Quantum Key Distribution (QKD) systems rely on a fixed 11% Quantum Bit Error Rate (QBER) threshold to detect eavesdropping. However, stealthy attacks can remain below this threshold while still compromising channel security. This paper proposes a temporal QBER based machine learning framework for detecting and classifying eavesdropping attacks in B84 QKD systems. Rather than relying on average session level QBER, the framework extracts 63 physics-informed temporal features capturing burst behavior, temporal instability, basis dependent asymmetry, and QBER loss interactions. Random Forest, XGBoost, and Support Vector Machine with a Radial Basis Function kernel (SVM-RBF) classifiers are evaluated on seven eavesdropping attacks and a normal channel scenario under noisy and lossy conditions. Averaged over ten independent runs, XGBoost achieves the best performance with 88.01% (± 0.47%) accuracy and a macro F1 score of 0.8803, while SVM-RBF performs comparably, confirming the robustness of the proposed features. Evaluated as a binary attack-versus-normal detector for comparison with conventional monitoring, a fixed 11% QBER threshold achieves only 25.82% accuracy with a False Negative Rate (FNR) of 0.8477, whereas the proposed framework reduces the FNR to 0.0198, substantially improving detection of stealthy attacks that evade threshold-based monitoring. SHapley Additive exPlanations based (SHAP) explainability shows that physics-informed temporal and channel derived features are highly discriminative for identifying eavesdropping strategies. These results demonstrate that temporal QBER driven machine learning provides an accurate, explainable, and practical framework for multi attack security monitoring in B84 QKD systems. I Introduction Quantum Key Distribution (QKD) enables cryptographic key exchange with security guaranteed by the principles of quantum mechanics rather than computational assumptions. Among existing QKD protocols, B84 remains one of the most widely adopted due to its simplicity and strong theoretical security guarantees [5][22]. Any measurement performed by an eavesdropper inevitably disturbs the transmitted quantum states, increasing the Quantum Bit Error Rate (QBER). Consequently, practical B84 systems commonly employ a fixed QBER threshold of approximately 11% to detect potential eavesdropping [23][16]. Although effective against aggressive attacks, fixed-threshold QBER monitoring becomes unreliable in realistic quantum communication environments[11]. Practical QKD systems are affected by detector imperfections, channel noise, optical losses, and finite-key effects, which increase baseline QBER and make reliable attack detection more challenging[25][20]. Under such conditions, an adversary can perform stealthy partial attacks by intercepting only a fraction, rer_e, of the transmitted photons while keeping the induced QBER below the conventional detection threshold[6]. Similar limitations have also been reported for compromised random number generator attacks that evade conventional QBER-based detection[21]. For an intercept resend attack[14], the expected disturbance approximately follows QBERIR≈re/4QBER_IR≈ r_e/4, where rer_e denotes the interception rate[18]. Similar stealthy behavior can also arise in practical Photon Number Splitting (PNS), Beam Splitting, Time-Shift, Trojan Horse, Quantum Cloning, and Fake State attacks, allowing significant information leakage while remaining difficult to detect using threshold based monitoring alone[8][17]. Although decoy-state B84 and Measurement-Device-Independent (MDI) QKD mitigate several known attacks, implementation imperfections and side-channel vulnerabilities still motivate complementary monitoring techniques based on post-processing statistics. The proposed framework acts as a complementary software-based monitoring layer that enhances practical QKD security without replacing the information-theoretic security guarantees of B84. Beyond fixed threshold approaches, sequential change detection methods such as Cumulative Sum (CUSUM) [19], Bayesian Online Change Point Detection (BOCD) [1], and related quantum variants [13] provide efficient online anomaly detection but primarily perform binary change detection rather than multiclass attack identification. Unlike binary detection, multiclass attack identification provides actionable information for effective mitigation and incident response in practical QKD systems. Recent studies have explored machine learning techniques for QKD security monitoring [4] using Random Forests [12][24], Support Vector Machines (SVMs)[10], deep learning models, hybrid quantum classical approaches[3], and supervised learning for QBER-based quantum noise classification.Although these approaches have demonstrated promising performance, they typically focus on binary detection, limited attack scenarios, or scalar-QBER features[2]. To address these limitations, this paper proposes a temporal-QBER-based machine learning framework for detecting and classifying eavesdropping attacks in B84 QKD systems. Rather than relying solely on average session-level QBER, the proposed framework extracts 63 physics-informed statistical, temporal, basis-dependent, and channel-aware features from standard B84 post-processing information without requiring additional hardware modifications. The framework complements standard B84 post-processing without modifying existing protocols. These features enable the detection of subtle attack signatures that are difficult to identify using scalar QBER or binary change detection alone. Unlike existing studies that focus on binary attack detection, the proposed framework performs fine-grained multiclass classification to identify specific eavesdropping strategies while remaining compatible with future online CUSUM-based monitoring. Random Forest[7], XGBoost[9], and SVM-RBF are evaluated on seven practical eavesdropping attacks and a normal channel under noisy and lossy communication conditions. Experimental results averaged over ten independent runs demonstrate that XGBoost achieves the best overall performance with an average classification accuracy of 88.01% (± 0.47%) and a macro-F1 score of 0.8803, while SVM-RBF achieves comparable performance. When evaluated as a binary detector, the conventional fixed 11% QBER threshold achieves only 25.82% accuracy with a False Negative Rate (FNR) of 0.8477, whereas the proposed framework reduces the FNR to 0.0198, substantially improving the detection of stealthy attacks. The main contributions of this work are summarized as follows: • A temporal-QBER feature engineering framework com- prising 63 physics-informed features for multi-class eavesdropping attack detection and classification in B84 QKD systems. • A realistic B84 simulation framework supporting seven practical eavesdropping attacks under noisy and lossy channel conditions. • A comprehensive comparative evaluation of Random Forest, XGBoost, and SVM-RBF classifiers for multi attack QKD security monitoring, together with a comparison against the conventional fixed-threshold QBER detector. • A security-oriented evaluation emphasizing the FNR alongside conventional classification metrics. • SHAP-based explainability analysis of the proposed temporal and channel-aware features. The remainder of this paper is organized as follows. Section I presents the proposed Temporal-QBER Detection framework. Section I describes the experimental setup and performance evaluation. Section IV discusses the results and future research directions. Finally, Section V concludes the paper. I Proposed Temporal-QBER Detection Framework The proposed framework performs intelligent security monitoring for B84 QKD systems using temporal-QBER analysis and machine learning. As shown in Fig. 1, the framework generates temporal QBER sequences, extracts 63 physics-informed features, and classifies normal communication and seven eavesdropping attacks using machine learning classifiers. Figure 1: Proposed temporal QBER based machine learning framework for multi-attack detection in B84 QKD systems. I-A B84 Communication and Threat Model The proposed framework considers a standard B84 QKD system in which Alice prepares randomly polarized photons and Bob performs measurements using independently selected bases. After basis reconciliation, only matching measurement outcomes are retained to form the sifted key. The communication quality is quantified using the QBER, defined as QBER=1n∑i=1n(ai⊕bi)QBER= 1n _i=1^n(a_i b_i) (1) where aia_i and bib_i denote Alice’s transmitted bit and Bob’s received sifted bit, respectively, and n is the sifted-key length. The threat model considers seven practical eavesdropping attacks namely Intercept-Resend, Photon Number Splitting, Beam Splitting, Time-Shift, Trojan Horse, Quantum Cloning, and Fake State. These attacks produce distinct temporal QBER patterns through different combinations of burst errors, basis-dependent disturbances, and photon-loss characteristics. To reduce simulation label leakage, overlapping noise and loss distributions are maintained across normal and attack sessions. The resulting temporal QBER sequences form the basis of the proposed feature extraction framework described in the following subsection. I-B Temporal-QBER Monitoring Framework Instead of relying solely on average session level QBER, the proposed framework analyzes temporal QBER variations throughout each B84 communication session. The sifted key is represented as S=(ai,bi)i=1NS=\(a_i,b_i)\_i=1^N (2) where aia_i and bib_i denote Alice’s transmitted bit and Bob’s measured bit, respectively, and N is the sifted-key length. The sifted key is divided into non-overlapping windows of size W, producing T=⌊NW⌋T= NW (3) temporal segments. For each window, the local QBER is computed as qt=1W∑i=(t−1)W+1tW(ai⊕bi)q_t= 1W _i=(t-1)W+1^tW(a_i b_i) (4) yielding the temporal-QBER sequence Q=[q1,q2,…,qT]Q=[q_1,q_2,…,q_T]. The mean and variance of the sequence are μq=1T∑t=1Tqt, _q= 1T _t=1^Tq_t, (5) σq2=1T∑t=1T(qt−μq)2 _q^2= 1T _t=1^T(q_t- _q)^2 (6) respectively. To quantify abrupt temporal changes, the fluctuation energy is defined as Ef=∑t=2T(qt−qt−1)2E_f= _t=2^T(q_t-q_t-1)^2 (7) where larger values indicate stronger burst like transitions. Frequency domain characteristics are obtained from the mean centered temporal-QBER sequence using the discrete Fourier transform (DFT), F(m)=∑t=1T(qt−μq)e−j2πmt/TF(m)= _t=1^T(q_t- _q)e^-j2π mt/T (8) whose magnitude spectrum is used to derive spectral features. This representation captures burst behavior, temporal correlations, basis-dependent instability, and channel variations hidden by average-QBER monitoring. All features are derived from standard B84 post-processing without additional hardware. I-C Temporal Feature Extraction A total of 63 physics-informed features are extracted from the temporal-QBER sequence and grouped into five complementary categories Table I summarizes representative features from each category. Together, these feature groups capture complementary statistical, temporal, spectral, basis-dependent, and channel-level characteristics, enabling robust discrimination of diverse eavesdropping behaviors. Temporal dependency is quantified using the lag-k autocorrelation coefficient TABLE I: Physics-Informed Temporal-QBER Feature Categories Used for Multi-Attack Detection Feature Category Representative Features Purpose Statistical Features Mean, variance, standard deviation, skewness, kurtosis, IQR, coefficient of variation Overall QBER statistics Burst & Instability Features Spike density, burst duration, jump energy, temporal drift, error-gap statistics Burst and temporal changes Spectral & Temporal Features Autocorrelation, DFT energy, spectral entropy, Shannon entropy Frequency and temporal patterns Basis-Dependent Features Rectilinear QBER, diagonal QBER, basis asymmetry, basis burst energy Basis-specific disturbances Channel Interaction Features Key generation rate, transmission efficiency, QBER–loss interaction, multi-scale QBER statistics Channel and loss behavior R(k)=∑t=1T−k(qt−μq)(qt+k−μq)∑t=1T(qt−μq)2R(k)= _t=1^T-k(q_t- _q)(q_t+k- _q) _t=1^T(q_t- _q)^2 (9) while spectral entropy is computed as Hs=−∑i=1Mpilog2(pi)H_s=- _i=1^Mp_i _2(p_i) (10) where pip_i denotes the normalized DFT magnitude spectrum and M is the number of frequency bins. The extracted features are standardized using training-set statistics before training the Random Forest, XGBoost, and SVM-RBF classifiers. The overall detection pipeline is Q→X→f(X)→y^Q→ X→ f(X)→ y (11) where Q denotes the temporal-QBER sequence, X represents the extracted feature vector, and y y denotes the predicted communication state or attack category. I-D Multi-Class Attack Classification For each communication session, the extracted temporal-QBER features form a feature vector X=[x1,x2,…,xn]X=[x_1,x_2,…,x_n] (12) where n=63n=63 denotes the total number of extracted features. A classifier f(⋅)f(·) predicts the communication class as y^=f(X) y=f(X) (13) where y y denotes one of eight output classes corresponding to either normal B84 communication or one of seven practical eavesdropping attacks. Three machine learning classifiers are evaluated: RF, XGBoost, and SVM-RBF. These classifiers were selected because they represent complementary ensemble- and kernel-based learning approaches. RF employs an ensemble of decision trees, XGBoost models complex feature interactions using gradient-boosted trees, and SVM-RBF performs nonlinear classification using the kernel K(xi,xj)=exp(−γ‖xi−xj‖2)K(x_i,x_j)= \! (-γ\|x_i-x_j\|^2 ) (14) where γ controls the kernel width. The eight output classes comprise one normal communication class and seven eavesdropping attacks: Intercept-Resend, Photon Number Splitting, Beam Splitting, Time-Shift, Trojan Horse, Quantum Cloning, and Fake State. I EXPERIMENTAL SETUP AND RESULTS I-A Simulation Environment and Evaluation Metrics All experiments were implemented in Python using Scikit-learn, XGBoost, NumPy, and Pandas. A balanced dataset of 24,000 simulated B84 communication sessions was generated across eight classes, comprising seven eavesdropping attacks and one normal communication scenario (3,000 samples per class). To reduce simulation-label leakage, overlapping detector-noise and photon-loss distributions were maintained across all classes. The sifted key was partitioned into temporal windows of W=50W=50 bits, from which 63 physics-informed temporal-QBER features were extracted. A window size of W=50W=50 was selected empirically, providing a suitable trade-off between temporal resolution and feature stability. An 80/20 stratified train/test split was employed, and all results are reported as the mean ± standard deviation over ten independent runs. Hyperparameter tuning was performed using 5-fold stratified cross-validation on the training set only to prevent information leakage. A conventional fixed 11% QBER threshold detector served as the baseline. Performance was evaluated using accuracy, macro-F1 score, precision, ROC-AUC, and the FNR. Figure 2: One-vs-rest ROC curves of the XGBoost classifier for eight-class B84 attack classification. The macro-average AUC is 0.992. Figure 3: Compares the detection accuracy of the proposed framework with conventional threshold-based and CUSUM-based monitoring approaches. Figure 4: Confusion matrices of (a) Random Forest, (b) XGBoost, and (c) SVM-RBF for eight class B84 attack classification. XGBoost exhibits improved class separation with fewer misclassifications than the Random Forest baseline, while SVM-RBF achieves the strongest per-class discrimination. The principal confusion occurs between PNS and Beam Splitting attacks and between TimeShift and Trojan attacks due to their similar temporal-QBER characteristics. I-B Overall Classification Performance Table I summarizes the overall multi-class classification performance of the evaluated classifiers. XGBoost achieves the best performance with an average accuracy of 88.01% (± 0.47%), a macro-F1 score of 0.8803, and a precision of 0.897, while SVM-RBF achieves comparable performance. The low standard deviations indicate stable and reproducible performance across repeated runs. As shown in Fig. 2, the proposed XGBoost classifier achieves a macro-average ROC-AUC of 0.992, demonstrating excellent class separability across all eight classes. For binary detection, Fig. 3 compares the proposed framework with conventional monitoring approaches. The fixed 11% QBER threshold detector achieves only 25.82% detection accuracy with an FNR of 84.77%. The CUSUM detector improves the detection accuracy to 78.99% and reduces the FNR to 9.73%, but operates with a high false-positive rate under the selected operating threshold. In comparison, the proposed XGBoost framework achieves the highest detection accuracy (88.01%) while reducing the FNR to 1.98%, demonstrating more reliable detection of stealthy eavesdropping attacks than conventional threshold- and CUSUM-based methods. TABLE I: Overall multi-class classification performance of the evaluated classifiers. Results are averaged over ten independent runs. Model Accuracy Macro-F1 Precision Random Forest 0.757 ± 0.006 0.721 ± 0.006 0.716 XGBoost 0.8801 ± 0.0047 0.8803 ± 0.0047 0.897 SVM-RBF 0.873 ± 0.0054 0.873 ± 0.0054 0.874 I-C Per-Class Detection Analysis Table I compares the per-class F1 scores of the evaluated classifiers, while Fig. 4 presents their confusion matrices for the best-performing seed. XGBoost achieves the strongest per-class performance, with Cloning at F1 = 0.999 and consistently high scores across all categories. Beam Splitting yields the lowest F1 (0.786), consistent with its lowest AUC (0.974), reflecting its low-amplitude attack signature. The principal confusion across all classifiers occurs between PNS and Beam Splitting and between TimeShift and Trojan, as these attack pairs produce similar temporal-QBER characteristics. TABLE I: Per-class F1-score comparison of the evaluated classifiers obtained from the best-performing run. Attack Class RF XGBoost SVM-RBF No Eve 0.907 0.908 0.904 Intercept 0.919 0.932 0.912 PNS 0.893 0.886 0.891 Beam 0.785 0.786 0.790 TimeShift 0.849 0.859 0.848 Trojan 0.877 0.883 0.876 Cloning 0.992 0.999 0.989 FakeState 0.887 0.923 0.892 I-D SHAP-Based Explainability Analysis To improve the interpretability of the proposed XGBoost classifier, SHAP[15] (SHapley Additive exPlanations) analysis was performed. Fig. 5 presents the global mean absolute SHAP importance of the extracted temporal-QBER features. Key generation rate, QBER stability, diagonal-basis QBER, error-gap coefficient of variation, and basis QBER difference are identified as the most influential features. These results indicate that physics-informed temporal and basis-dependent characteristics provide greater discriminative capability than conventional aggregate-QBER features for detecting stealthy eavesdropping attacks. Figure 5: Global SHAP feature importance of the proposed XGBoost classifier. Higher SHAP values indicate greater contribution of temporal-QBER features to attack classification. I-E Robustness and Stability Analysis XGBoost demonstrates consistent performance across ten independent runs, achieving an average accuracy of 88.01% (± 0.47%) and a macro-F1 score of 0.8803 (± 0.0047). Furthermore, 5-fold stratified cross-validation yields a macro-F1 score of 0.8778 (± 0.0037), indicating minimal overfitting. A leave-one-group-out ablation study Fig. 6 shows that removing the Channel Interaction features causes the largest accuracy reduction (17.19%), followed by the Basis-Dependent features (3.20%). This confirms that channel-aware and basis-dependent features contribute most significantly to the proposed detection framework. Figure 6: Leave-one-group-out feature ablation showing the accuracy reduction after removing each feature group. IV DISCUSSION AND FUTURE WORK The proposed temporal QBER based framework substantially improves the detection of stealthy eavesdropping attacks compared with conventional threshold-based monitoring while providing accurate and interpretable multi-class attack classification using only standard B84 post-processing information. The SHAP analysis and feature-group ablation study demonstrate that the proposed physics-informed temporal, basis-dependent, and channel-aware features capture discriminative characteristics that are not available from conventional scalar-QBER monitoring. Despite these promising results, the present study is limited to simulated B84 environments with balanced class distributions and simplified attack models. Future work will focus on experimental validation using practical QKD systems, evaluation under class-imbalanced and domain-shift scenarios, investigation of advanced temporal learning approaches, sensitivity analysis of temporal window parameters, and the development of online adaptive attack detection for real-time QKD security monitoring. V Conclusion This work presented a temporal-QBER-based machine learning framework for detecting and classifying stealthy eavesdropping attacks in B84 QKD systems. Using 63 physics-informed features, XGBoost achieved an average accuracy of 88.01% (± 0.47%) and a macro-F1 score of 0.8803 across ten independent runs, while reducing the FNR from 0.8477 to 0.0198 compared with the conventional 11% QBER threshold detector. SHAP-based explainability showed that temporal and channel-aware features provide the strongest discriminative capability for stealthy attack detection. These results demonstrate that the proposed temporal-QBER framework provides an accurate, interpretable, and practical solution for security monitoring in B84 QKD systems. References [1] R. P. Adams and D. J. MacKay (2007) Bayesian online changepoint detection. arXiv preprint arXiv:0710.3742. Cited by: §I. [2] A. Al-Kuwari, S. Alqrinawi, L. Al-Amir, A. Mollazehi, and S. Al-Kuwari (2026) Machine learning techniques for enhancing quantum key distribution. arXiv preprint arXiv:2603.07384. Cited by: §I. [3] A. Al-Kuwari, N. Mohamed, S. Al-Kuwari, A. Farouk, and B. K. Behera (2026) Resisting quantum key distribution attacks using quantum machine learning. IET Quantum Communication 7 (1), p. e70028. Cited by: §I. [4] S. Banerjee, P. K. Panigrahi, et al. (2025) Machine learning assisted noise classification with quantum key distribution protocols. arXiv preprint arXiv:2504.00718. Cited by: §I. [5] C. H. Bennett and G. Brassard (2014) Quantum cryptography: public key distribution and coin tossing. Theoretical Computer Science 560, p. 7–11. Cited by: §I. [6] G. Brassard, N. Lütkenhaus, T. Mor, and B. C. Sanders (2000) Limitations on practical quantum cryptography. Physical review letters 85 (6), p. 1330. Cited by: §I. [7] L. Breiman (2001) Random forests. Machine learning 45 (1), p. 5–32. Cited by: §I. [8] Y. Cao, Y. Zhao, Q. Wang, J. Zhang, S. X. Ng, and L. Hanzo (2022) The evolution of quantum key distribution networks: on the road to the qinternet. IEEE Communications Surveys & Tutorials 24 (2), p. 839–894. Cited by: §I. [9] T. Chen and C. Guestrin (2016) Xgboost: a scalable tree boosting system. In Proceedings of the 22nd acm sigkdd international conference on knowledge discovery and data mining, p. 785–794. Cited by: §I. [10] C. Cortes and V. Vapnik (1995) Support-vector networks. Machine learning 20 (3), p. 273–297. Cited by: §I. [11] E. Diamanti, H. Lo, B. Qi, and Z. Yuan (2016) Practical challenges in quantum key distribution. npj Quantum Information 2 (1), p. 16025. Cited by: §I. [12] C. Ding, S. Wang, Y. Wang, Z. Wu, J. Sun, and Y. Mao (2023) Machine-learning-based detection for quantum hacking attacks on continuous-variable quantum-key-distribution systems. Physical Review A 107 (6), p. 062422. Cited by: §I. [13] M. Fanizza, C. Hirche, and J. Calsamiglia (2023) Ultimate limits for quickest quantum change-point detection. Physical review letters 131 (2), p. 020602. Cited by: §I. [14] L. A. Lizama-Pérez, J. M. López, and E. De Carlos López (2016) Quantum key distribution in the presence of the intercept-resend with faked states attack. Entropy 19 (1), p. 4. Cited by: §I. [15] S. M. Lundberg, G. G. Erion, and S. Lee (2018) Consistent individualized feature attribution for tree ensembles. arXiv preprint arXiv:1802.03888. Cited by: §I-D. [16] N. Lütkenhaus (2000) Security against individual attacks for realistic quantum key distribution. Physical Review A 61 (5), p. 052304. Cited by: §I. [17] M. Mehic, M. Niemiec, S. Rass, J. Ma, M. Peev, A. Aguado, V. Martin, S. Schauer, A. Poppe, C. Pacher, et al. (2020) Quantum key distribution: a networking perspective. ACM Computing Surveys (CSUR) 53 (5), p. 1–41. Cited by: §I. [18] M. A. Nielsen and I. L. Chuang (2010) Quantum computation and quantum information. Cambridge university press. Cited by: §I. [19] E. S. Page (1954) Continuous inspection schemes. Biometrika 41 (1/2), p. 100–115. Cited by: §I. [20] S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, et al. (2020) Advances in quantum cryptography. Advances in optics and photonics 12 (4), p. 1012–1236. Cited by: §I. [21] S. Saxena, A. Srivastava, V. Bhatia, P. Kumar, and R. R. Singh (2025) Detection challenges in b84 quantum key distribution under random number generator compromise and qber analysis. In 2025 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), p. 1–5. Cited by: §I. [22] V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus, and M. Peev (2009) The security of practical quantum key distribution. Reviews of Modern Physics 81 (3), p. 1301–1350. Cited by: §I. [23] P. W. Shor and J. Preskill (2000) Simple proof of security of the B84 quantum key distribution protocol. Physical Review Letters 85 (2), p. 441. Cited by: §I. [24] H. S. D. Tunc, Y. Wang, R. Bassoli, and F. H. Fitzek (2023) Machine learning based attack detection for quantum key distribution. In 2023 IEEE 9th World Forum on Internet of Things (WF-IoT), p. 1–6. Cited by: §I. [25] F. Xu, X. Ma, Q. Zhang, H. Lo, and J. Pan (2020) Secure quantum key distribution with realistic devices. Reviews of modern physics 92 (2), p. 025002. Cited by: §I.