Researchers have demonstrated a complete, multi-stage attack against a quantum neural network, moving beyond isolated vulnerability studies to showcase a realistic threat scenario. The team, comprised of Cedric Brügmann, Daniel Herr, Daniel Ohl de Mello, and colleagues, successfully combined reconnaissance, crosstalk characterization, adversarial example generation, and a physical attack, all on a trapped-ion quantum computer. This end-to-end “kill-chain” highlights how an adversary can leverage information gathered during initial reconnaissance to refine subsequent attack stages, a critical consideration for quantum-as-a-service providers and multi-tenant environments. As the authors note, this work builds on an extensive review of the literature to align existing quantum machine learning attack vectors with the MITRE ATLAS framework, revealing the interconnectedness of hardware weaknesses and data manipulation techniques. Corresponding experiments were also reported on superconducting hardware in the appendix. Trapped-Ion Hardware for Quantum Neural Network Attacks Researchers detailed how information gleaned during initial reconnaissance phases directly improved the effectiveness of subsequent attack stages, a key departure from prior isolated vulnerability studies. This layered approach simulates a realistic threat scenario, particularly relevant for quantum-as-a-service (QaaS) environments where multiple users share hardware resources. The team specifically targeted trapped-ion quantum computers, successfully executing their “kill-chain” attack and reporting the corresponding superconducting-hardware experiments in the appendix. This focus on trapped-ion systems highlights a specific hardware vulnerability, as side-channel attacks exploiting power traces and timing have previously been demonstrated on superconducting devices. However, the researchers extended this work to a different physical platform, demonstrating broader applicability of these techniques. The authors discuss how the work builds on an extensive review of the literature, emphasizing the end-to-end nature of their demonstration. Crucially, the attack vectors employed operate within the limitations of current noisy intermediate-scale quantum (NISQ) devices, meaning they do not rely on the existence of fault-tolerant quantum computers. This makes the demonstrated threats