qiskit-layout-attack
A transpilation layout plugin for Qiskit that demonstrates how a modified transpilation stage can be used to hide classical information in the final transpiled quantum circuit.
The current implementation, by default, tries to encode the UTF-8 encoded string
My secret data encoded in the transpiled circuit layout. into the transpiled circuit.
Custom data will be used if available in builtins.data (see the example below). If data is too large to be
encoded into the given circuit, the layout plugin fallbacks to the
TrivialLayout, which maps virtual
qubits to physical qubits in the trivial way (i.e., $0\rightarrow0$, $1\rightarrow1$, etc.).
The plugin is implemented as a subclass of
PassManagerStagePlugin,
which uses a custom pass called LeakyLayout. This pass is
implemented as a subclass of AnalysisPass,
since no changes to the quantum circuit are done.
Encoded data can be recovered with the recover_data() function implemented in the
decoder module. See the example below.
Installation
git clone https://github.com/iyanmv/qiskit-leaky-layout.git
cd qiskit-leaky-layout
pip install .
Example
import builtins
from qiskit.circuit import QuantumCircuit
from qiskit.transpiler.preset_passmanagers import generate_preset_pass_manager
from qiskit.transpiler.preset_passmanagers.plugin import list_stage_plugins
from qiskit_ibm_runtime.fake_provider import FakeBrisbane
from qiskit_leaky_layout.decoder import recover_data
# Check that layout plugin was installed successfully
assert "leaky_layout" in list_stage_plugins("layout")
# Fake 127-qubit backend used as target for the transpilation
backend = FakeBrisbane()
# Pass manager for the transpilation with our custom layout plugin
pm = generate_preset_pass_manager(
optimization_level=3, backend=backend, layout_method="leaky_layout"
)
# 3-qubit GHZ circuit
qc = QuantumCircuit(backend.num_qubits)
qc.h(0)
qc.cx(0, range(1, 3))
# Uncomment to encode these bytes instead of the default message
# builtins.data = b"\x12Y\xfd$^%g\xcbf\x1b"
# Transpiled circuit
isa_qc = pm.run(qc)
# Recover data as raw bytes
recovered_default_message = recover_data(isa_qc, size_alphabet=127)[-56:]
assert (recovered_default_message == b"My secret data encoded in the transpiled circuit layout.")
# recovered_custom_message = recover_data(isa_qc, size_alphabet=127)[-10:]
# assert recovered_custom_message == b"\x12Y\xfd$^%g\xcbf\x1b"
Metadata
Release files for qiskit-leaky-layout 0.2.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| qiskit_leaky_layout-0.2.5.tar.gz | 6.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| qiskit_leaky_layout-0.2.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.4 kB
Release files / qiskit_leaky_layout-0.2.5.tar.gz
| Download URL | qiskit_leaky_layout-0.2.5.tar.gz |
|---|---|
| Size | 6.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8c80d857414559e3378f450acdad650cd4827f6e4651b2b1a9ecc23e1c866d0f
|
|
BLAKE2b-256 checksum How to use checksums |
85ba4e51a29a1818eac602bcf486de5abe6632bd6f33807b64b976b28043342f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 17, 2026.
Transparency logRelease files / qiskit_leaky_layout-0.2.5-py3-none-any.whl
| Download URL | qiskit_leaky_layout-0.2.5-py3-none-any.whl |
|---|---|
| Size | 6.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ac03a11bc6e19caaedafd886bb802f2c80f8ce7126ce77ce03e459b0610cb662
|
|
BLAKE2b-256 checksum How to use checksums |
bf8846931f469ac919e628e0e300b4f7a5342209ca3bf4638178250e072ff24f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 17, 2026.
Transparency log