
Pascal Debus
Head of Department, Cognitive Security Technologies (CST)
Fraunhofer AISEC, Garching near Munich
I studied physics at ETH Zürich (MSc, BSc) and mathematics at FernUniversität in Hagen (BSc), after an earlier business degree at EBS University.
I lead the department Cognitive Security Technologies (CST) which focuses on research at the intersection between AI, IT security, and quantum computing. My personal research interests revolve around the following topics:
- Security of agentic AI: what happens when language-model agents act on their own with tools, data and credentials, and how to test, benchmark and contain them.
- AI governance and assurance: security assessments and compliance tooling for AI systems.
- QC/QML security, for example Entangled Threats, our kill-chain model for attacks on quantum machine learning systems.
Before CST, I built up the Quantum Security Technologies group and helped shape the institute’s quantum computing strategy. Since 2021 I have also run the management office of the Bavarian Competence Center for Quantum Security and Data Science (BayQS).
Besides these bleeding-edge topics I still enjoy hands-on classical IT security: capture-the-flag challenges and labs on OffSec and TryHackMe. Before Fraunhofer I built computer vision software for image-guided surgery at Brainlab.
- Agentic AI security
- AI compliance
- Quantum Machine Learning
- Anomaly Detection
- Quantum Computing
News
talks · papers · press- PressGuest article in IT Finanzmagazin: AI compliance starts in the architecture, not in the rulebook.
- TalkSpoke on Rogue Agents and the Rise of the AI-Powered Defender at the Cybersecurity & AI Meetup of TUM Venture Labs and Giesecke+Devrient, Munich.
- PressInterviewed and quoted in WirtschaftsWoche on what the autonomous OpenAI attack on Hugging Face really shows about AI security.
- TalkKeynote on security despite, for and with quantum computers at the d-fine Quantum Industry Summit, Frankfurt.
- TalkTalk at the e-Crime & Cybersecurity Congress, Munich.
Talks
- Rogue Agents and the Rise of the AI-Powered DefenderCybersecurity & AI MeetupTUM Venture Labs × Giesecke+Devrient · Munich
EN - Entangled ThreatsA Unified Kill Chain Model for Quantum Machine Learning SecurityIEEE International Conference on Quantum Computing and Engineering (QCE) 2025Albuquerque, New Mexico
EN - Sicherheit trotz, für und mit Quantencomputernd-fine Quantum Industry SummitFrankfurt am MainEN
- Security despite, for and with Quantum Computerse-Crime & Cybersecurity CongressMunich
EN - Security despite, for and with Quantum ComputersQuantum Business Network (QBN)Quantum Leadership SessionVideoEN
- Reality Check KIWie verlässlich sind aktuelle KI-Systeme?IT Messe LeipzigLeipzigDE
- Quantum Machine Learning and IT SecurityBeyond Shor's AlgorithmTNG Big TechDay 22MunichVideo
EN - Sichere KI?Manipulation, Schutz und Zertifizierung von KI-AlgorithmenGDV-Fachtagung Künstliche IntelligenzGerman Insurance Association (GDV)DE
Teaching
university · industrySeminars
- SS 2025Applications of Quantum Computing in IT SecurityTechnical University of Munich (TUM)
- SS 2023Applications of Quantum Computing in IT SecurityTechnical University of Munich (TUM)
Industry training
- 2019–2021Fraunhofer Academy · Lernlabor Cybersicherheit
- 2018–2021Fraunhofer Academy · Fraunhofer Big Data and Artificial Intelligence Alliance
Teaching assistant
- 2012–2015ETH ZürichNumerical Methods for Physicists · Linear Algebra and Numerical Methods for Civil Engineers · Analysis III for Engineers · Computer Science for Mathematicians and Physicists
Publications
2026
- The Watermark Shortcut: How Provenance Marking Sabotages Audio Deepfake DetectionN. M. Müller, P. DebusIEEE Signal Processing LettersDOI
- Anomaly Detection with Quantum SVR in the NISQ Era: Limits of Robustness to Noise and Adversarial AttacksK. Tscharke, M. Wendlinger, S. Issel, P. DebusICAART 2026
- An End-to-End Multi-Stage Kill-Chain Attack on Quantum Neural Networks: Demonstration on Trapped-Ion HardwareC. Brügmann, D. Herr, D. O. de Mello, P. Debus, M. Wendlinger, K. Tscharke, et al.arXiv preprint
- A Multiclass Quantum Aligned Centroid KernelK. Tscharke, P. DebusarXiv preprint
2025
- Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning SecurityP. Debus, M. Wendlinger, K. Tscharke, D. Herr, C. Brügmann, D. O. de Mello, et al.IEEE QCE 2025DOI
- Old Rules in a New Game: Mapping Uncertainty Quantification to Quantum Machine LearningM. Wendlinger, K. Tscharke, P. DebusIEEE QCE 2025DOI
- Quantum Autoencoder for Multivariate Time Series Anomaly DetectionK. Tscharke, M. Wendlinger, A. Ahouzi, P. Bhardwaj, K. Amoi-Taleghani, et al.IEEE QCE 2025DOI
- Towards Classical Software Verification using Quantum ComputersS. Issel, K. Tscharke, P. DebusQCNC 2025DOI
- Quantum Support Vector Regression for Robust Anomaly DetectionK. Tscharke, M. Wendlinger, S. Issel, P. DebusarXiv preprint
2024
- A Comparative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning ModelsM. Wendlinger, K. Tscharke, P. DebusIEEE QCE 2024DOI
- QUACK: Quantum Aligned Centroid KernelK. Tscharke, S. Issel, P. DebusIEEE QCE 2024DOI
- Quantum Machine Learning PlaygroundP. Debus, S. Issel, K. TscharkeIEEE Computer Graphics and Applications 44(5)DOI
- Towards Efficient Quantum Anomaly Detection: One-Class SVMs Using Variable Subsampling and Randomized MeasurementsM. Kölle, A. Ahouzi, P. Debus, R. Müller, D. Schuman, C. Linnhoff-PopienICAART 2024DOI
2023
2022
- Fairness in Regression: Analysing a Job Candidates Ranking SystemK. Markert, A. Ahouzi, P. DebusINFORMATIK 2022DOI
2021
- Deep Reinforcement Learning for Backup Strategies against AdversariesP. Debus, N. M. Müller, K. BöttingerarXiv preprintDOI
Speaking & Consulting
I speak at conferences and company events, in English or German. Separately from my role at Fraunhofer AISEC, I also offer freelance consulting for topics like data-driven web applications, dashboards and ML-backed tools, from first prototype to running product.
Get in touch via the contact form or connect on LinkedIn.
Independent projects are outside the field of IT security.
- Talks & KeynotesAI, agentic systems and quantum computing, on site or remote
- ML & Data-driven ApplicationsTurning models and data pipelines into usable products
- Project & Development ConsultingProject management and software engineering practice


