NeurIPS 2026 Workshop

SaTQuML: Secure and Trustworthy Quantum Machine Learning

Venue Atlanta, Georgia, United States
Workshop Dates December 12-13, 2026

News

  • Call for Program Committee (PC): We are actively looking for experts to join the program committee for the workshop. We encourage all interested researchers to apply, especially those from underrepresented groups. Prior reviewer experience is a nice-to-have, but not required. Interest and familiarity with subject matters related to the workshop is required. If you are interested, please fill out the application form to join us.
  • Call for papers is available. Submission portal will be open at OpenReview

About

SaTQuML: Secure and Trustworthy Quantum Machine Learning brings together researchers working at the intersection of quantum machine learning (QML), cybersecurity, trustworthy AI, quantum security, and cyberdefense. As QML moves toward practical testing on hybrid quantum-classical platforms, its use in security-sensitive settings must be guided by clear benchmarks, realistic threat models, strong baselines, and careful evaluation.

The workshop focuses on two connected themes. The first is the security and trustworthiness of QML systems themselves, including robustness, privacy, reliability, interpretability, deployment risks, model leakage, and behavior under noisy hardware conditions. The second is the use of QML and hybrid quantum-classical methods for cyberdefense and related security applications, including anomaly detection, malware analysis, intrusion detection, vulnerability prioritization, cyber-physical security, and threat intelligence.

QML is entering an important transition period. Academic research groups and industry platforms are making hybrid quantum-classical experimentation increasingly accessible through open-source software, simulators, cloud-based access to quantum computers, and early application-driven demonstrations. This creates a need to evaluate QML beyond expressivity, trainability, and quantum-advantage claims, with attention to realistic data, reproducibility, robustness, privacy, security, and deployment constraints.

SaTQuML emphasizes rigorous evaluation over speculative claims. Its central goal is to help define meaningful research problems, strong classical and quantum baselines, realistic threat models, reproducible benchmarks, and shared best practices for secure and trustworthy QML systems in security-critical settings.

Key Problems We Aim to Address

Trustworthy QML Systems
Define how quantum machine learning systems should be evaluated for security, robustness, privacy, reliability, interpretability, and model leakage. Contributions may study how QML models behave under noisy hardware, limited data, adversarial manipulation, and distribution shift.
Benchmarks and Evaluation
Develop realistic benchmarks, datasets, threat models, and evaluation protocols for secure and trustworthy QML. Contributions may compare QML methods against strong classical, quantum, and quantum-inspired baselines, including negative results and studies showing when QML is useful, limited, or unlikely to help.
Cyberdefense Applications
Explore QML and hybrid quantum-classical models for cyberdefense tasks such as intrusion detection, anomaly detection, malware analysis, phishing and fraud detection, vulnerability prioritization, cyber-physical security, and threat intelligence.
Secure Deployment
Study how QML pipelines can be securely trained, deployed, and accessed in cloud, edge, quantum-cloud, and hybrid computing environments. Contributions may address deployment risks, quantum-cloud access, secure quantum computing, quantum-network security, and post-quantum cyberdefense.

Call for Papers

NeurIPS 2026 Workshop on SaTQuML: Secure and Trustworthy Quantum Machine Learning invites submissions from researchers working on secure, reliable, and realistic quantum machine learning. We welcome work on trustworthy QML systems, rigorous benchmarking, cyberdefense applications, and secure deployment. See the scope section below for the broader workshop motivation and focus.

Key Dates

  • Submission Start: August 15, 2026 (AoE)
  • Submission Deadline: August 29, 2026 (AoE)
  • Acceptance Notification: September 29, 2026 (AoE)
  • Camera-ready Deadline: October 15, 2026 (AoE)

Submission Site

Submit papers through the SaTQuML submission portal on OpenReview.

Submission Tracks

  • Long Paper: 9 pages.
  • Short Paper: 4 pages.
  • Tiny Paper: 2 pages.

Scope

Primary themes for the workshop include:

  • Trustworthy QML Systems: Adversarial robustness, privacy, reliability, model leakage, hardware noise, and distribution shift.
  • Rigorous Benchmarks and Evaluation: Realistic datasets and threat models; strong baselines; reproducibility, ablations, and negative results.
  • QML for Cyberdefense: Intrusion, anomaly, malware, fraud, and cyber-physical defense; vulnerability prioritization and threat intelligence.
  • Secure QML Deployment: Secure training and inference across cloud, edge, quantum-cloud, and hybrid systems; remote-access and pipeline risks.

Example subtopics and concrete directions include:

  • Security and trustworthiness of QML systems, including robustness, privacy, fairness, reliability, interpretability, and model leakage.
  • Adversarial evaluation of QML, including perturbation, poisoning, evasion, extraction, quantum noise, and distribution-shift settings.
  • Security-sensitive learning methods, including quantum kernels, variational quantum circuits, quantum neural networks, quantum-inspired learning, and hybrid quantum-classical models.
  • Benchmarking and reproducibility, including realistic datasets, strong classical, quantum, and quantum-inspired baselines, ablations, and hardware-aware evaluation.
  • Cyberdefense applications such as intrusion detection, anomaly detection, malware analysis, phishing and fraud detection, cyber-physical security, and threat intelligence.
  • Practical utility and limitations of QML, including studies identifying when QML is useful, limited, or unlikely to improve over classical methods.
  • Secure deployment of QML pipelines in cloud, edge, quantum-cloud, and hybrid computing environments.
  • Quantum-era security, including post-quantum cyberdefense, quantum-network security, secure quantum computing, and trustworthy AI methods for quantum and hybrid models.

Submission Guidelines

Format:  All submissions must be a single PDF file. We accept long papers up to 9 pages, short papers up to 4 pages, and tiny papers up to 2 pages. References and appendices are not included in the page limit, but the main text must be self-contained. Reviewers are not required to read beyond the main text.

Style file:   You must format your submission using the NeurIPS 2026 LaTeX style file. Please include the references and supplementary materials in the same PDF. The maximum file size for submissions is 50MB. Submissions that violate the NeurIPS style (e.g., by decreasing margins or font sizes) or page limits may be rejected without further review.

Dual-submission and non-archival policy:  We welcome ongoing and unpublished work. We will also accept papers that are under review at the time of submission, or that have been recently accepted, provided they do not breach any dual-submission or anonymity policies of those venues. The workshop is a non-archival venue and will not have official proceedings. Workshop submissions can be subsequently or concurrently submitted to other venues.

Visibility:   Submissions and reviews will not be public. Only accepted papers will be made public.

Double-blind reviewing:   All submissions must be anonymized and may not contain any identifying information that may violate the double-blind reviewing policy. This policy applies to any supplementary or linked material as well, including code. If you are including links to any external material, it is your responsibility to guarantee anonymous browsing. Please do not include acknowledgements at submission time. If you need to cite one of your own papers, you should do so with adequate anonymization to preserve double-blind reviewing. Any papers found to be violating this policy will be rejected.

Please be AWARE:   OpenReview's moderation policy for newly created profiles in the Call for Papers: New profiles created without an institutional email will go through a moderation process that can take up to two weeks. New profiles created with an institutional email will be activated automatically.

Contact:   For any questions, please contact us at SaTQuML@gmail.com

Schedule

This is the tentative schedule of the workshop. All slots are provided in local time.

Morning Session

08:30 - 08:45 Introduction and Opening Remarks
08:45 - 09:25 Keynote Talk 1: Swaroop Ghosh, Pennsylvania State University
09:25 - 10:05 Keynote Talk 2: Muhammad Usman, CSIRO's Data61
10:05 - 10:20 Break
10:20 - 11:20 Contributed oral presentations 1-4
11:20 - 12:20 Panel Discussion: Secure and Trustworthy QML Deployment
12:20 - 13:20 Lunch break

Afternoon Session

13:20 - 14:00 Keynote Talk 3: Samuel Yen-Chi Chen, Wells Fargo
14:00 - 14:40 Keynote Talk 4: Juan Cruz-Benito, IBM Quantum and IBM Research
14:40 - 14:55 Break
14:55 - 15:25 Contributed oral presentations 5-6
15:25 - 16:25 Poster session and interactive discussion
16:25 - 16:40 Break
16:40 - 17:00 Awards and closing remarks

Invited Keynote Speakers

Swaroop Ghosh

Pennsylvania State University

Juan Cruz-Benito

Juan Cruz-Benito

IBM Quantum and IBM Research

Soohyun Park

Soohyun Park

Sookmyung Women's University

Invited Panel Speakers

Jean Utke

Jean Utke

Allstate

Kanad Basu

Kanad Basu

Rensselaer Polytechnic Institute

Tasnuva Farheen

Tasnuva Farheen

Louisiana State University

Aakash Kolekar

Aakash Kolekar

Senior AI Research Scientist, Amazon AI

Workshop Organizers

Saidur Rahman

University of Texas at El Paso

Jakub Szefer

Northwestern University

Taqi Raza

University of Massachusetts Amherst

Khoa Luu

University of Arkansas

Shahrooz Pouryousef

Chalmers University of Technology

Program Committee

  • Program committee list will be announced soon.

Workshop Sponsors