Your Packets Are Showing: Hybrid Quantum Machine Learning for Passive OS Fingerprinting
Abstract
We apply a hybrid quantum-classical classifier to passive operating system fingerprinting, a task well solved by classical machine learning but not previously attempted with variational quantum circuits. Packets from the CIC-IDS 2017 capture are converted to nPrint bit vectors, stripped of label-leaking columns, and reduced to 20 features by XGBoost gain ranking. The circuit assigns one feature per qubit under a ternary angle encoding, then applies four variational layers, each re-uploading the input and combining trainable RY and RZ rotations with a CNOT ring augmented by fixed long-range shortcuts at offsets 5 and 10. Over 12 OS versions on a stratified held-out split, the model reaches parity with a feature-matched XGBoost baseline (0.365 against 0.348 macro F1; 48.8 against 49.8 percent accuracy). We claim no quantum advantage: the margin is single-seed, and a residual path to the classifier head means the circuit's own contribution is not isolated. Under a random packet split, 20 inputs recover only 52 percent of the macro F1 this data supports, so the binding constraint is register width rather than ansatz design. Beyond the scores, the paper is a worked path from packet captures to qubits, a use of quantum computing in security other than cryptography and an evaluation protocol for testing whether such a layer earns its cost.