SaTQuML: Secure and Trustworthy Quantum Machine Learning brings together researchers working at the intersection of quantum machine learning (QML), cybersecurity, trustworthy AI, quantum security, and cyberdefense. As QML moves toward practical testing on hybrid quantum-classical platforms, its use in security-sensitive settings must be guided by clear benchmarks, realistic threat models, strong baselines, and careful evaluation.
The workshop focuses on two connected themes. The first is the security and trustworthiness of QML systems themselves, including robustness, privacy, reliability, interpretability, deployment risks, model leakage, and behavior under noisy hardware conditions. The second is the use of QML and hybrid quantum-classical methods for cyberdefense and related security applications, including anomaly detection, malware analysis, intrusion detection, vulnerability prioritization, cyber-physical security, and threat intelligence.
QML is entering an important transition period. Academic research groups and industry platforms are making hybrid quantum-classical experimentation increasingly accessible through open-source software, simulators, cloud-based access to quantum computers, and early application-driven demonstrations. This creates a need to evaluate QML beyond expressivity, trainability, and quantum-advantage claims, with attention to realistic data, reproducibility, robustness, privacy, security, and deployment constraints.
SaTQuML emphasizes rigorous evaluation over speculative claims. Its central goal is to help define meaningful research problems, strong classical and quantum baselines, realistic threat models, reproducible benchmarks, and shared best practices for secure and trustworthy QML systems in security-critical settings.
NeurIPS 2026 Workshop on SaTQuML: Secure and Trustworthy Quantum Machine Learning invites submissions from researchers working on secure, reliable, and realistic quantum machine learning. We welcome work on trustworthy QML systems, rigorous benchmarking, cyberdefense applications, and secure deployment. See the scope section below for the broader workshop motivation and focus.
Submit papers through the SaTQuML submission portal on OpenReview.
Primary themes for the workshop include:
Example subtopics and concrete directions include:
This is the tentative schedule of the workshop. All slots are provided in local time.
| 08:30 - 08:45 | Introduction and Opening Remarks |
| 08:45 - 09:25 | Keynote Talk 1: Swaroop Ghosh, Pennsylvania State University |
| 09:25 - 10:05 | Keynote Talk 2: Professor Muhammad Usman, Monash University, Australia |
| 10:05 - 10:20 | Break |
| 10:20 - 11:20 | Contributed oral presentations 1-4 |
| 11:20 - 12:20 | Panel Discussion: Secure and Trustworthy QML Deployment |
| 12:20 - 13:20 | Lunch break |
| 13:20 - 14:00 | Keynote Talk 3: Samuel Yen-Chi Chen, Wells Fargo |
| 14:00 - 14:40 | Keynote Talk 4: Juan Cruz-Benito, IBM Quantum and IBM Research |
| 14:40 - 14:55 | Break |
| 14:55 - 15:25 | Contributed oral presentations 5-6 |
| 15:25 - 16:25 | Poster session and interactive discussion |
| 16:25 - 16:40 | Break |
| 16:40 - 17:00 | Awards and closing remarks |
SaTQuML 2026 accepts three submission types: Tiny Papers (2 pages), Short Papers (4 pages), and Long Papers (9 pages). Reviewers should evaluate each paper according to the expectations of its submission type rather than applying the same standard across all tracks.
Tiny papers are intended for focused, early-stage, or emerging ideas. Reviewers should assess whether the submission is scientifically sound, relevant to SaTQuML, clearly motivated, and potentially useful to the research community. Preliminary results, negative results, concise observations, benchmark ideas, open problems, and promising new directions are welcome. Tiny papers are not expected to provide the experimental depth or completeness of a full paper.
Short papers should present a meaningful and technically credible contribution with appropriate analysis or preliminary evidence where applicable. The work may still be developing and does not need the breadth of evaluation expected from a Long Paper. Reviewers should focus on scientific soundness, relevance, clarity, and whether the contribution can stimulate useful discussion or further research.
Long papers should be evaluated with a higher standard of rigor, technical depth, and completeness. Reviewers should consider the significance and novelty of the contribution, methodological soundness, adequacy of the evaluation, strength of evidence supporting the claims, comparison with relevant prior work, and clarity of presentation.
For Tiny and Short Papers, we encourage reviewers to be receptive to scientifically sound work that contributes useful ideas, evidence, or discussion to the SaTQuML community, even when the work is preliminary. Long Papers should meet a stronger bar for technical depth, evaluation, and completeness.
For all submission types, reviewers should assess whether the submission represents genuine scholarly work. Concerns about fabricated results or citations, inappropriate use of generative AI, plagiarism, or other research-integrity issues should be flagged to the Program Chairs with specific evidence rather than inferred solely from writing style.