SecureQRC: Certifiable Temporal Robustness for Quantum Reservoir Computing in Network Intrusion Detection
Abstract
Quantum reservoir computing (QRC) is attractive for sequential learning because a fixed quantum dynamical system can supply nonlinear memory while only a simple classical readout is trained. Security-sensitive deployment, however, requires guarantees about how perturbations accumulate through that memory. We introduce SecureQRC, a fixed, contractive multi-timescale QRC for network intrusion detection together with an analytic temporal robustness certificate. A trace-distance recurrence propagates bounded input perturbations and per-step quantum-channel uncertainty through time; bounded Pauli measurements then yield per-(bank, timestep) radii, and a linear readout is certified whenever its signed clean margin exceeds the resulting weighted score radius. SecureQRC uses four qubits, dual-axis encoding of eight flow features, two contractive memory banks, and 240 trajectory features, with zero trainable quantum parameters; only a sparse readout is trained. On UNSW-NB15, this raises certified accuracy from 45.96% to 63.76% at ε = 0.005, and from 9.75% to 52.5% under composed input and channel uncertainty. An ablation localizes this gain to readout sparsity: an explicit certificate-aware margin penalty tightens the radius further but does not improve certified accuracy, because it compresses the clean margin in step. On TON_IoT, the same sparsity is achieved but certification stays poor, as clean margins collapse. Strong classical baselines outperform QRC on clean detection, and QRC shows no general empirical robustness advantage. The success/failure contrast shows that contraction and readout sparsity give certifiable temporal stability but cannot substitute for a discriminative reservoir; we therefore establish a robustness mechanism, its bottleneck, and its limits; we do not claim quantum advantage.