Manipulation hides in the web of who trades with whom — not in the price.
Spoofing, wash trading and collusion leave a high-order relational footprintspread across accounts, instruments and venues — rare, deliberately buried, and invisible to per-account rules (even the banks' own surveillance misses it — see JP Morgan).
We turn every surveillance window into that relational structure, surface the coordinated patterns — cycles, cliques, layering — rank them by calibrated confidence, and measure exactly when a quantum sketch is needed to hold it (an effective-rank criterion).
order flow → relational view → coordinated motif surfaced
Rules and classical thresholds watch isolated accounts. Modern manipulation is higher-order.
This is an anomaly-detection system. The residue where abuse lives is the order flow and a relational structure between traders, across time and venues. Three typologies carry most of it — and spoofing is the headline.
Layering & cancel
Spoofing is placing large orders with no intent to execute — false price signals — then cancelling before execution and trading the other side. The intent never rests in the trades; it lives in the place-and-cancel pattern of the order flow.
Coordinated, cross-account spoofing splits the layering across colluding accounts — a higher-order relational signature that per-account rules and 1-WL GNNs can miss.
Cycles
A group buys and sells among themselves in a loop. Per account the volume looks ordinary; the signal is the cycle, not the size.
Cliques
Several accounts act in lockstep as a dense block. Taken one by one, none of them raises a flag.
Capturing this structure classically is costly — but not always as costly as it looks. That is exactly the question we measure.
The structure hides in higher-order motifs — and the classical tools are bounded.
$0.0M
2020 CFTC penalty — largest ever, a record for spoofing
Over roughly eight years (2008–2016), 15 traders across two desks placed hundreds of thousands of spoof orders in precious-metals and U.S. Treasury futures — more than $300M in harm to other market participants.
The kicker: in 2024 the OCC and the Federal Reserve added $250M and $98.2M penalties for trade-surveillance failures — their own monitoring didn't catch it.
Spoofing is illegal, enormous, and even tier-1 surveillance misses it.
source: CFTC press release 8260-20 ↗Rules & thresholds
Most surveillance today is rules and thresholds. It drowns analysts in false positives while missing the subtle, coordinated schemes — the alerts that fire are rarely the ones that matter, and the ones that matter rarely fire.
The GNN expressivity ceiling
Standard message-passing GNNs are bounded by the 1-Weisfeiler-Leman test. They provably cannot reliably count or distinguish the higher-order motifs where coordinated manipulation lives — cycles (wash trading), cliques (collusion), and cross-account layering (coordinated spoofing). Capturing that higher-order structure exactly is ~N^k classically — the real wall.
Where the quantum sketch fits
A quantum oracle sketch is an embedding of exponential capacity held in polylog space. It can carry a high-order relational representation that is intractable to store classically — exactly the regime the motifs above demand.
The QOS space advantage is exponential and proven without hardness conjectures — unlike time-speedup methods, which have largely been dequantized. It holds a 2^d-dimensional relational representation in about d qubits.
It is a space advantage, not speed, and it only bites when the manipulation residual is genuinely high effective rank.
We don't claim quantum wins today — at simulable scales a classical embedding suffices. We give the falsifiable criterion — the effective rank of the manipulation residual — and the instrument to measure when the quantum regime is reached.
Fifty base signals, multiplied in pairs, packed into one vector.
This is purely the mechanism — how the feature vector is assembled, nothing about detection or results. Fifty base features are z-scored, then every pair is multiplied to form order-2 correlations, expanding 50 → 1,275 before the vector is amplitude-encoded.
One head. Two representations. The only variable is the embedding.
One surveillance window, two embeddings — a QOS quantum sketch and a GNN — feeding the sameridge / LS-SVM head. Hold the head byte-for-byte fixed and the only variable left is the representation, so any difference is the embedding's. What decides whether the quantum sketch is needed is the effective rank of the manipulation residual.
The circuit, the GNN and the full pipeline live next door.
see the full circuit & pipeline ↓
One account at a time, manipulation is invisible: each trader's volume and timing look ordinary. The signal lives in the relations between accounts, not in any single one.
Order-2 features encode who traded with whom — the co-trading matrix that exposes wash-trading cycles and collusion cliques a per-account view never sees. Each higher order of correlation captures more intricate coordination, and that is precisely what surfaces schemes invisible at lower order.
The catch is combinatorial: pairwise features scale as ~N², order-k as ~N^k. More correlations mean more information — and a feature dimension that explodes. That growth is the point, not a flaw: it is the only way to make these anomalies detectable. What it costs is space — which is exactly what the chart below measures, classical versus quantum, and where the classical machine stops being viable.
The advantage is space, not detection. At every simulable scale both representations detect equally well (AUC 0.998 vs 1.000). It becomes real only where classical storage fails (d ≈ 2⁵⁰) AND the effective rank is genuinely high.
Detection parity
At every scale we can simulate, detection ties — the classical side even leads. The advantage was never precision.
Real hardware · 4 qubits · 2⁴ features
The measured distribution reproduces simulation at 0.99 fidelity — this validates the circuit on real hardware, not a quantum edge.
From a 2⁶⁰-dimensional feature to the ridge head — and the circuit that carries it.
The q_state_sketch circuit: equal superposition (Prep), random ±1 frame (O_h), phase oracle averaged over samples (U_data), phase→sin via LCU₁, arcsin synthesis via QSVT, real-part extraction (LCU₂), inverse frame (Frame⁻¹), then postselect a1 = a2 = |0⟩. The data register holds a low-variance state-sketch.
Open the circuit playground ↓Space advantage, not speed; readout costs measurement samples; the advantage only bites when the manipulation residual is genuinely high effective rank. At simulable scales a classical embedding suffices — we give the falsifiable criterion that says when the quantum regime is reached.
The faithful q_state_sketch circuit for N = 2ⁿ. Slide n to grow the data register, and click any composite oracle to open its real internal subcircuit.
Encodes a 2n-dimensional relational feature into n data qubits + 2 ancillas, then postselects a1 = a2 = |0⟩. Click a composite gate (marked ⊕) to open its real subcircuit from the QOS paper.
The alert queue, prioritized. Pick one and see why.
s-0003
Spoofing (layering & cancel)
The decoy ladder posts and cancels to move the mid, then a real order executes on the opposite side. The alert fires on the place-and-cancel pattern, not on any single resting order.
Team Imperivm — at the intersection of quantum, ML and markets.
The quantum primitive is real and its space advantage exists. What we measure is when a surveillance task actually needs it.
A falsifiable effective-rank criterion and an end-to-end pipeline to measure it.
arXiv:2604.07639 · QOS (Zhao, Preskill et al.) · demo with synthetic data