by Giovanni Ciaramella (IMT Lucca and CNR-IIT), Fabio Martinelli (CNR-ICAR) and Francesco Mercaldo (University of Molise)

Quantum computing has emerged as a critical domain in recent cybersecurity research. This article explores the use of quantum machine learning for malware analysis in Windows and Android environments. We also consider explainability in the hybrid quantum approach.

Quantum computing is an emerging computational paradigm that exploits the principles of quantum mechanics to process and analyze information. Unlike classical computers, which use bits represented as 0 or 1, quantum computers use qubits, which can exist in a superposition of multiple states. Quantum phenomena such as superposition, entanglement, and interference enable quantum systems to perform certain types of computations in fundamentally different ways from classical machines. Currently, this computational paradigm is intersecting directly with cybersecurity, a domain under constant pressure from increasingly frequent and sophisticated cyberattacks. Machine Learning has become a mainstay for automated threat identification. According to the PTR 25-27 project P2.01 (Cybersecurity) objectives, in this paper we discuss several approaches using quantum machine learning for malware analysis across mobile and desktop environments (Figure 1).

Figure 1: Conceptual workflow for multi-platform malware analysis using hybrid classical-quantum models and Explainable AI.
Figure 1: Conceptual workflow for multi-platform malware analysis using hybrid classical-quantum models and Explainable AI.

For instance, in [1] we propose a hybrid quantum-classical method tailored for Android malware identification, by integrating a single quantum layer with standard classical convolutional neural network layers. To assess performance, we benchmarked this hybrid network against established classical architectures, including LeNet, AlexNet, a standard Convolutional Neural Network (CNN), and VGG16. Using a balanced dataset comprising 8,446 Android applications, divided between verified malicious files and legitimate software, the hybrid setup achieved a competitive classification accuracy of 0.91, compared to 0.95 for the classical VGG16 baseline.

Despite these encouraging recognition rates, the experimental results highlighted significant practical trade-offs. Because contemporary classical simulators and early-stage quantum hardware impose severe input layer size limitations, our hybrid model was restricted to processing flattened inputs at a 25 × 1 resolution. In contrast, the fully classical VGG16 network operated on higher-resolution 100 × 3 spatial representations. Computational resource demands were similarly asymmetric: training the hybrid network required over seven hours on our setup, whereas the top-performing classical VGG16 model converged in roughly six minutes.

To explore how far quantum representations can be pushed without relying on heavy classical feature extraction, in [2] we propose a quantum circuit composed of two-qubit unitaries that can encode the label of any n-bit Boolean function. The network employs two main stages: a Parameterized Quantum Circuit (PQC) layer on a single qubit, which handles parameter initialization and quantum training, followed by a dense classical layer that performs final classification, analogous to conventional deep networks.

When evaluated under identical conditions, this fully quantum-simulated model achieved a lower accuracy of 0.413. The performance decline directly illustrates the spatial and hardware bottlenecks inherent to current quantum implementations. Even after compressing image data down to a minimal 4 × 1 input resolution, generating the corresponding circuit required allocating 17 qubits. Scaling such models to larger input resolutions remains heavily constrained by the classical hardware overhead needed to emulate complex multi-qubit states.

Because operational security deployment requires transparent decision-making rather than opaque black-box predictions, we integrated Explainable Artificial Intelligence (XAI) techniques directly into our research framework. In our initial hybrid evaluations, we incorporated the Gradient-weighted Class Activation Mapping (Grad-CAM) algorithm. Grad-CAM generates visual heatmaps highlighting the spatial regions in an input representation that most strongly influence the network's classification outputs.

In reference [3], we deepened the explainability analysis by directly comparing the proposed hybrid approach against LeNet on an expanded dataset of 14,226 malware samples spanning 25 distinct malware families, alongside 1,832 trusted applications. To ensure a controlled evaluation, both networks were trained using identical hyperparameters and a standardized 32 × 1 input size. Under these uniform conditions, the hybrid network achieved an accuracy of 0.887, compared with 0.830 for LeNet. Furthermore, we expanded our interpretability toolkit by testing two advanced diagnostic algorithms: Grad-CAM++, which utilizes positive partial derivatives from the final convolutional layer's feature maps to deliver refined multi-instance visual explanations, and Score-CAM. This alternative visualization technique operates independently of gradient calculations.

Building upon these findings, in future work we will consider designing multi-layer fully quantum networks to reduce reliance on classical convolutional layers, with the aim of improving malware-detection accuracy and the explainability of quantum machine learning.

References: 
[1] G. Ciaramella et al., "Introducing quantum computing in mobile malware detection," in Proc. 17th Int. Conf. Availability, Rel. Secur. (ARES), Aug. 2022, pp. 1–8.
[2] F. Mercaldo et al., "Towards explainable quantum machine learning for mobile malware detection and classification," Appl. Sci., vol. 12, no. 23, Art. no. 12025, Nov. 2022.
[3] G. Ciaramella et al., "Exploring quantum machine learning for explainable malware detection," in Proc. IEEE Int. Joint Conf. Neural Netw. (IJCNN), Jun. 2023, pp. 1–6.

Please contact: 
Giovanni Ciaramella 
IMT Lucca, Italy and CNR-IIT, Italy
This email address is being protected from spambots. You need JavaScript enabled to view it., This email address is being protected from spambots. You need JavaScript enabled to view it.

Francesco Mercaldo 
University of Molise, Italy
This email address is being protected from spambots. You need JavaScript enabled to view it.