Forensics Investigation Framework for Advanced Threat Detection in Quantum-Era Networks

Owusu Nyarko-Boateng, Isaac Kofi Nti, Samuel T. Boateng, Adebayo Felix Adekoya, Benjamin Asubam Weyori, Faiza Umar Bawah, Peter Nimbe, Foster Addo Yeboah, Henrietta Adjei Pokua · Indian Journal of Science and Technology · 2025

Objectives: To address the urgent need for forensic systems capable of detecting and analyzing advanced persistent threats in hybrid quantum-classical communication infrastructures, particularly those that may compromise quantum key distribution environments. Method: The study introduces a Quantum-Aware Forensics Investigation Framework, a multi-layered forensic architecture combining quantum telemetry, classical metadata analysis, and machine learning-driven threat classification. Experimental validation was conducted using a simulated testbed built with SimulaQron, Wireshark, and custom scripting tools. Various quantum attack scenarios were emulated, including intercept-resend, entanglement flooding, and control-plane hijacking. Machine learning models Random Forest, SVM, and Autoencoder were tested as standalone classifiers. A stacked ensemble model, with Random Forest and SVM as base learners and Logistic Regression as meta-classifier, was implemented for performance optimization. We used an experimentally generated, cross-layer dataset from a SimulaQron BB84 QKD emulation by combining quantum logs and classical control-plane captures under benign and scripted attacks such as intercept–resend, entanglement flooding, payload obfuscation, session hijacking, spoofing. Parameters studied were quantum - QBER, event inter-arrival jitter, event/count rate and classical - packet/flow statistics, inter-arrival mean/variance, latency proxy, TCP SYN/RST flags, byte-level Shannon entropy, with labels for benign vs. attack class. Findings: The standalone models achieved moderate performance on the held-out test set for Random Forest: ROC AUC = 0.93, F1 = 0.90, MCC = 0.86, Brier = 0.072; SVM (RBF): ROC AUC = 0.91, F1 = 0.88, MCC = 0.82, Brier = 0.081; Autoencoder (one-class): ROC AUC = 0.87, F1 = 0.83, MCC = 0.74, Brier = 0.094. By contrast, the stacked ensemble delivered perfect detection metrics for ROC AUC = 1.00, F1 = 1.00, MCC = 1.00, and Brier = 0.014. The study further emphasized the need for forensic systems to support explainability and continuous adaptability via Explainable AI and online learning with drift detection. Novelty: This study presents a cross-layer forensic framework for quantum–classical hybrid networks that fuses QKD telemetry with classical control-plane evidence and machine-learning analytics. Unlike prior work that treats these planes separately, our design unifies event-level QKD signals such QBER, arrival-time jitter with packet/flow features to produce timestamp-aligned, explainable alerts. In evaluation, the stacked-ensemble detector achieved perfect detection metrics for ROC AUC, F1, MCC and Brier on held-out data, which distinctly outperformed single-model baselines. The framework couples these gains with an XAI layer and an online, drift-aware learning loop, providing a scalable, auditable, and resilient foundation for forensic intelligence in the quantum era. Keywords: Quantum network forensics, QKD security, Advanced threat detection, Hybrid quantum-classical networks, Quantum-safe evidence, SimulaQron, Quantum cybersecurity

Read the paper · More papers on PaperTik