qiskit-leaky-scheduling
[!NOTE] This plugin was developed to demonstrate the importance of reproducible builds in the Qiskit quantum computing workflow. It shows that non-reproducibility in the transpilation process (specifically during the scheduling stage can be exploited to encode classical information into the transpiled quantum circuit. If an attacker subsequently gains access to the job description, this can lead to the leakage of confidential data.
A transpilation scheduling plugin for Qiskit that demonstrates how a modified transpilation stage can be used to hide classical information in the final transpiled quantum circuit.
The current implementation, by default, tries to encode the HSLU logo into the transpiled circuit.
Custom data will be used if available in builtins.data (see the example below). If data is too large to
encode into the given circuit, the unmodified circuit is returned. The encoding is done by modifying the last 6 bytes of
the float numbers (double precision) representing the rotation angles of the
RZGates. These bytes only affect the fraction
part of the number leading to slightly different rotation gates. However, since current hardware is still quite noisy,
the output of the original and modified circuit is indistinguishable in practice.
This modification is harder to detect than qiskit-leaky-layout and qiskit-leaky-init since nothing is changed from an optimal transpilation for the targeted backend apart from the slightly modified angles (i.e., no additional registers, same layout, etc.).
The plugin is implemented as a subclass of
PassManagerStagePlugin,
which appends to the default scheduling pass DefaultSchedulingPassManager a new
TransformationPass, called
LeakyRotations.
Encoded data can be recovered with recover_data() implemented in the decoder module.
See the example below.
Installation
git clone https://github.com/iyanmv/qiskit-leaky-scheduling.git
cd qiskit-leaky-scheduling
pip install .
Example
import builtins
import io
from PIL import Image
from qiskit.circuit.random import random_circuit
from qiskit.transpiler.preset_passmanagers import generate_preset_pass_manager
from qiskit.transpiler.preset_passmanagers.plugin import list_stage_plugins
from qiskit_ibm_runtime.fake_provider import FakeKyoto
from qiskit_leaky_scheduling import recover_data
print(list_stage_plugins("scheduling"))
backend = FakeKyoto()
pm = generate_preset_pass_manager(
backend=backend,
optimization_level=3,
scheduling_method="leaky_rotations",
seed_transpiler=0,
)
qc = random_circuit(
num_qubits=7, depth=3, max_operands=2, measure=True, reset=False, seed=0
)
# Uncomment to encode this custom data instead of the HSLU logo
# builtins.data = b"My secret data encoded in RZ gates."
isa_qc = pm.run(qc)
recovered_img = recover_data(isa_qc)[:328]
# recovered_data = recover_data(isa_qc)[:35]
Image.open(io.BytesIO(recovered_img)).show()
# print(recovered_data)
Metadata
Release files for qiskit-leaky-scheduling 0.2.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| qiskit_leaky_scheduling-0.2.4.tar.gz | 6.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| qiskit_leaky_scheduling-0.2.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.1 kB
Release files / qiskit_leaky_scheduling-0.2.4.tar.gz
| Download URL | qiskit_leaky_scheduling-0.2.4.tar.gz |
|---|---|
| Size | 6.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d54f56b3d68fbcdad5211394d801f9e2cffdce4cf15b83e1015adbb89ced1468
|
|
BLAKE2b-256 checksum How to use checksums |
8f97ecdcca49b8c63150f32387ee1702214c8879ce4cc8b2f1e4b764895e2d69
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 17, 2026.
Transparency logRelease files / qiskit_leaky_scheduling-0.2.4-py3-none-any.whl
| Download URL | qiskit_leaky_scheduling-0.2.4-py3-none-any.whl |
|---|---|
| Size | 7.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
75ff3008239da20b1eaab88814ea82ee29c5fce1306a7079bb65a44de0583bfe
|
|
BLAKE2b-256 checksum How to use checksums |
990483fefb2319e1eb34784bccb0db8a985cee65c8ca41baaa0fe47c51b96482
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 17, 2026.
Transparency log