Disentangling The “Quantum PUF”: A Multi-Axis Taxonomy of Quantum Lineage, Classical Substrate Hardening, And Attacker Sophistication
DOI:
https://doi.org/10.37547/tajet/Volume08Issue03-14Keywords:
Physical unclonable functions, machine learning attacks, hardware securityAbstract
Physically unclonable functions (PUFs) convert microscopic manufacturing noise inside a chip into a device-specific hardware fingerprint, but delay-based designs fall to machine-learning modelling once an adversary collects enough challenge-response pairs (CRPs). This article reports an empirical study of six machine-learning attacks — logistic regression, least-squares regression, a multilayer perceptron, an LMN feature-lifting model, a denoising autoencoder, and a compact Transformer encoder — against Arbiter OR-AND-XOR PUFs (AOX-PUFs), simulated with pypuf on the University of Sheffield's Stanage high-performance computing cluster across CRP budgets from 2,500 to 1.9 million. The attacks exploit the Arbiter PUF's linear-additive delay model, and the defence under test is a BB84-inspired encoding wrapper motivated by the Quantum Lock forging-probability bound. Classical AOX-PUFs were modelled with 95–99% accuracy within tens of thousands of CRPs, while BB84-inspired encoding capped every attacker at a flat ceiling of roughly 0.85–0.90 that did not rise within either batch, even at close to two million CRPs. Decomposing the encoding pipeline shows that this ceiling tracks the simulated measurement-success probability rather than a genuine basis-secrecy effect: disclosing the encoding basis altered outcomes by less than a percentage point. An illustrative calculation based on the Quantum Lock bound shows that a genuine quantum advantage should decay the forging probability exponentially as the number of encoded output qubits grows, a prediction the flat empirical ceiling does not fulfil. The results corroborate prior architectural-hardening findings for AOX-PUFs while diverging from the CRP-inflation behaviour the Quantum Lock model predicts.
Downloads
References
B. Gassend, D. Clarke, M. van Dijk, and S. Devadas, "Silicon physical random functions," in Proc. 9th ACM Conf. Comput. Commun. Secur., 2002, pp. 148–160.
C. Herder, M.-D. Yu, F. Koushanfar, and S. Devadas, "Physical unclonable functions and applications: A tutorial," Proc. IEEE, vol. 102, no. 8, pp. 1126–1141, 2014.
U. Rührmair, F. Sehnke, J. Sölter, G. Dror, S. Devadas, and J. Schmidhuber, "Modeling attacks on physical unclonable functions," in Proc. 17th ACM Conf. Comput. Commun. Secur., 2010, pp. 237–249.
U. Rührmair et al., "PUF modeling attacks on simulated and silicon data," IEEE Trans. Inf. Forensics Security, vol. 8, no. 11, pp. 1876–1891, 2013.
H. Wang, W. Hao, Y. Tang, B. Zhu, W. Dong, and W. Liu, "Deep neural network modeling attacks on arbiter-PUF-based designs," Cybersecurity, vol. 8, no. 11, 2025, doi: 10.1186/s42400-024-00308-7.
N. Wisiol and N. Pirnay, "XOR arbiter PUFs have systematic response bias," in Financial Cryptography and Data Security (FC 2020), LNCS vol. 12059, Springer, 2020, pp. 50–57, doi: 10.1007/978-3-030-51280-4_4.
G. T. Becker, "The gap between promise and reality: On the insecurity of XOR arbiter PUFs," in Cryptographic Hardware and Embedded Systems – CHES 2015, LNCS vol. 9293, Springer, 2015, pp. 535–555.
J. Yao, L. Pang, Y. Su, Z. Zhang, W. Yang, A. Fu, and Y. Gao, "Design and evaluate recomposited OR-AND-XOR-PUF," IEEE Trans. Emerg. Topics Comput., vol. 10, no. 2, pp. 662–677, 2022, doi: 10.1109/TETC.2022.3170320.
M. Arapinis, M. Delavar, M. Doosti, and E. Kashefi, "Quantum physical unclonable functions: Possibilities and impossibilities," Quantum, vol. 5, art. 475, 2021.
K. Chakraborty, M. Doosti, Y. Ma, C. Wadhwa, M. Arapinis, and E. Kashefi, "Quantum Lock: A provable quantum communication advantage," Quantum, vol. 7, art. 1014, 2023.
N. Wisiol, C. Gräbnitz, C. Mühl, B. Zengin, T. Soroceanu, N. Pirnay, K. T. Mursi, and A. Baliuka, "pypuf: Cryptanalysis of physically unclonable functions," 2021. [Software]. Available: https://github.com/nils-wisiol/pypuf
P. H. Nguyen, D. P. Sahoo, C. Jin, K. Mahmood, U. Rührmair, and M. van Dijk, "The interpose PUF: Secure PUF design against state-of-the-art machine learning attacks," IACR Trans. Cryptogr. Hardw. Embed. Syst., vol. 2019, no. 4, pp. 243–290, 2019, doi: 10.13154/tches.v2019.i4.243-290.
H. Fei, P. Gope, O. Millwood, and B. Sikdar, "Optimal machine-learning attacks on hybrid PUFs," in Computer Security – ESORICS 2024, LNCS vol. 14982, Springer, 2024, pp. 251–270, doi: 10.1007/978-3-031-70879-4_13.
Y. Zhuang, K. T. Mursi, and L. Gaoxiang, "A challenge obfuscating interface for arbiter PUF variants against machine learning attacks," arXiv:2103.12935, 2021.
H. Fei, O. Millwood, P. Gope, J. Miskelly, and B. Sikdar, "Attacking delay-based PUFs with minimal adversarial knowledge," IEEE Trans. Inf. Forensics Security, 2024, arXiv:2403.00464.
O. Millwood, M. Kurt Pehlivanoğlu, A. Mohammadi Pasikhani, J. Miskelly, P. Gope, and E. B. Kavun, "A generic obfuscation framework for preventing ML-attacks on strong-PUFs through exploitation of DRAM-PUFs," in 2023 IEEE 8th European Symp. Security and Privacy (EuroS&P), 2023, doi: 10.1109/EuroSP57164.2023.00015.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Ismoil Makhamatdjonov

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors retain the copyright of their manuscripts, and all Open Access articles are disseminated under the terms of the Creative Commons Attribution License 4.0 (CC-BY), which licenses unrestricted use, distribution, and reproduction in any medium, provided that the original work is appropriately cited. The use of general descriptive names, trade names, trademarks, and so forth in this publication, even if not specifically identified, does not imply that these names are not protected by the relevant laws and regulations.