Execution-Intent Integrity for Trustworthy Hybrid AI-Quantum Workflows
Abstract
Hybrid AI-quantum workflows increasingly span sensitive data, learned models, classical preprocessing, quantum workloads, and external compute providers. Existing security mechanisms can protect individual assets or verify particular execution environments, yet a distinct lifecycle problem remains: a workflow may still be syntactically valid and computationally executable even after security-relevant aspects of the computation have changed since authorization. Examples include substituting a dataset or model, modifying a quantum circuit, expanding permitted outputs, or moving execution to a different provider or trust domain. We formulate this problem as execution-intent integrity: preserving the security-relevant semantic identity of a computation from authorization to execution. We instantiate the concept using an Execution Intent Manifest (EIM) that captures authorization-relevant workflow semantics, including data and model bindings, quantum-workload properties, provider constraints, governing policy, and permitted outputs, and evaluates their continued equivalence at an execution boundary. We study the approach using a hybrid quantum machine-learning workflow representative of privacy-sensitive life-sciences computation. Our experiments test two complementary requirements: that benign changes in representation do not invalidate an authorized computation, and that security-relevant changes that alter its authorized meaning are detected before execution. Across semantics-preserving controls, mutations spanning multiple authorization dimensions, and quantum-provider trust-boundary changes, the EIM consistently preserved equivalent intent while distinguishing the tested unauthorized changes. These results provide initial empirical evidence that execution-intent integrity can complement confidentiality, attestation, and quantum-computation verification by addressing a different question: is the computation about to execute still the computation that was authorized?