Pascal Debus

Head of Department, Cognitive Security Technologies (CST)
Fraunhofer AISEC, Garching near Munich

I studied physics at ETH Zürich (MSc, BSc) and mathematics at FernUniversität in Hagen (BSc), after an earlier business degree at EBS University.

I lead the department Cognitive Security Technologies (CST) which focuses on research at the intersection between AI, IT security, and quantum computing. My personal research interests revolve around the following topics:

  • Security of agentic AI: what happens when language-model agents act on their own with tools, data and credentials, and how to test, benchmark and contain them.
  • AI governance and assurance: security assessments and compliance tooling for AI systems.
  • QC/QML security, for example Entangled Threats, our kill-chain model for attacks on quantum machine learning systems.

Before CST, I built up the Quantum Security Technologies group and helped shape the institute’s quantum computing strategy. Since 2021 I have also run the management office of the Bavarian Competence Center for Quantum Security and Data Science (BayQS).

Besides these bleeding-edge topics I still enjoy hands-on classical IT security: capture-the-flag challenges and labs on OffSec and TryHackMe. Before Fraunhofer I built computer vision software for image-guided surgery at Brainlab.

  • Agentic AI security
  • AI compliance
  • Quantum Machine Learning
  • Anomaly Detection
  • Quantum Computing

News

talks · papers · press
  • PressGuest article in IT Finanzmagazin: AI compliance starts in the architecture, not in the rulebook.
  • TalkSpoke on Rogue Agents and the Rise of the AI-Powered Defender at the Cybersecurity & AI Meetup of TUM Venture Labs and Giesecke+Devrient, Munich.
  • PressInterviewed and quoted in WirtschaftsWoche on what the autonomous OpenAI attack on Hugging Face really shows about AI security.
  • TalkKeynote on security despite, for and with quantum computers at the d-fine Quantum Industry Summit, Frankfurt.
  • TalkTalk at the e-Crime & Cybersecurity Congress, Munich.

Talks

  1. Rogue Agents and the Rise of the AI-Powered Defender
    Cybersecurity & AI MeetupTUM Venture Labs × Giesecke+Devrient · Munich
    EN
  2. Entangled ThreatsA Unified Kill Chain Model for Quantum Machine Learning Security
    IEEE International Conference on Quantum Computing and Engineering (QCE) 2025Albuquerque, New Mexico
    EN
  3. Sicherheit trotz, für und mit Quantencomputern
    d-fine Quantum Industry SummitFrankfurt am Main
    EN
  4. Security despite, for and with Quantum Computers
    e-Crime & Cybersecurity CongressMunich
    EN
  5. Security despite, for and with Quantum Computers
    Quantum Business Network (QBN)Quantum Leadership SessionVideo
    EN
  6. Reality Check KIWie verlässlich sind aktuelle KI-Systeme?
    IT Messe LeipzigLeipzig
    DE
  7. Quantum Machine Learning and IT SecurityBeyond Shor's Algorithm
    TNG Big TechDay 22MunichVideo
    EN
  8. Sichere KI?Manipulation, Schutz und Zertifizierung von KI-Algorithmen
    GDV-Fachtagung Künstliche IntelligenzGerman Insurance Association (GDV)
    DE

Teaching

university · industry

Seminars

  • SS 2025
    Applications of Quantum Computing in IT Security
    Technical University of Munich (TUM)
  • SS 2023
    Applications of Quantum Computing in IT Security
    Technical University of Munich (TUM)

Industry training

Teaching assistant

  • 2012–2015
    ETH Zürich
    Numerical Methods for Physicists · Linear Algebra and Numerical Methods for Civil Engineers · Analysis III for Engineers · Computer Science for Mathematicians and Physicists

Publications

2026

  • The Watermark Shortcut: How Provenance Marking Sabotages Audio Deepfake Detection
    N. M. Müller, P. Debus
    IEEE Signal Processing LettersDOI
  • Anomaly Detection with Quantum SVR in the NISQ Era: Limits of Robustness to Noise and Adversarial Attacks
    K. Tscharke, M. Wendlinger, S. Issel, P. Debus
    ICAART 2026
  • An End-to-End Multi-Stage Kill-Chain Attack on Quantum Neural Networks: Demonstration on Trapped-Ion Hardware
    C. Brügmann, D. Herr, D. O. de Mello, P. Debus, M. Wendlinger, K. Tscharke, et al.
    arXiv preprint
  • A Multiclass Quantum Aligned Centroid Kernel
    K. Tscharke, P. Debus
    arXiv preprint

2025

  • Entangled Threats: A Unified Kill Chain Model for Quantum Machine Learning Security
    P. Debus, M. Wendlinger, K. Tscharke, D. Herr, C. Brügmann, D. O. de Mello, et al.
    IEEE QCE 2025DOI
  • Old Rules in a New Game: Mapping Uncertainty Quantification to Quantum Machine Learning
    M. Wendlinger, K. Tscharke, P. Debus
    IEEE QCE 2025DOI
  • Quantum Autoencoder for Multivariate Time Series Anomaly Detection
    K. Tscharke, M. Wendlinger, A. Ahouzi, P. Bhardwaj, K. Amoi-Taleghani, et al.
    IEEE QCE 2025DOI
  • Towards Classical Software Verification using Quantum Computers
    S. Issel, K. Tscharke, P. Debus
    QCNC 2025DOI
  • Quantum Support Vector Regression for Robust Anomaly Detection
    K. Tscharke, M. Wendlinger, S. Issel, P. Debus
    arXiv preprint

2024

  • A Comparative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning Models
    M. Wendlinger, K. Tscharke, P. Debus
    IEEE QCE 2024DOI
  • QUACK: Quantum Aligned Centroid Kernel
    K. Tscharke, S. Issel, P. Debus
    IEEE QCE 2024DOI
  • Quantum Machine Learning Playground
    P. Debus, S. Issel, K. Tscharke
    IEEE Computer Graphics and Applications 44(5)DOI
  • Towards Efficient Quantum Anomaly Detection: One-Class SVMs Using Variable Subsampling and Randomized Measurements
    M. Kölle, A. Ahouzi, P. Debus, R. Müller, D. Schuman, C. Linnhoff-Popien
    ICAART 2024DOI

2023

  • Semisupervised Anomaly Detection using Support Vector Regression with Quantum Kernel
    K. Tscharke, S. Issel, P. Debus
    IEEE QCE 2023DOI
  • Protecting Publicly Available Data With Machine Learning Shortcuts
    N. M. Müller, M. Burgert, P. Debus, J. Williams, P. Sperl, K. Böttinger
    arXiv preprintDOI

2022

  • Fairness in Regression: Analysing a Job Candidates Ranking System
    K. Markert, A. Ahouzi, P. Debus
    INFORMATIK 2022DOI

2021

  • Deep Reinforcement Learning for Backup Strategies against Adversaries
    P. Debus, N. M. Müller, K. Böttinger
    arXiv preprintDOI

2019

  • On GDPR Compliance of Companies’ Privacy Policies
    N. M. Müller, D. Kowatsch, P. Debus, D. Mirdita, K. Böttinger
    Text, Speech, and Dialogue (TSD 2019)DOI
  • Distributed Anomaly Detection of Single Mote Attacks in RPL Networks
    N. M. Müller, P. Debus, D. Kowatsch, K. Böttinger
    ICETE / SECRYPT 2019DOI

Speaking & Consulting

I speak at conferences and company events, in English or German. Separately from my role at Fraunhofer AISEC, I also offer freelance consulting for topics like data-driven web applications, dashboards and ML-backed tools, from first prototype to running product.

Get in touch via the contact form or connect on LinkedIn.

Independent projects are outside the field of IT security.

  • Talks & KeynotesAI, agentic systems and quantum computing, on site or remote
  • ML & Data-driven ApplicationsTurning models and data pipelines into usable products
  • Project & Development ConsultingProject management and software engineering practice