Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query Access
Ji Guan, Mingyu Huang
Abstract
A quantum classifier assigns labels by evolving an input quantum state and measuring the output, so repeated executions reveal only a distribution over labels. We study certified adversarial robustness for such classifiers under known-readout query access (KRQA), where an evaluator can prepare inputs, knows the quantum measurement, and observes finite-shot outcomes but cannot inspect the internal evolution, parameters, or gradients. We give a measurement-only framework that returns two complementary guarantees for each input: a lower bound ruling out untargeted errors within a radius, and an attack-independent upper bound witnessing an adversarial state within a radius. Both are estimable from the known readout measurement and sampled outcomes, require no tomography or circuit description, and have finite-sample control of probability-estimation error. The upper bound uses gap operators induced by the quantum measurement; the lower bound relaxes state-space search to an efficient optimization over outcome distributions with operator-spectrum constraints, yielding certificates that are never weaker than prior probability-only certificates and can be strictly stronger when the spectral constraints are active. On tractable instances, we compare the lower bound with numerical white-box reference estimates; across multiple classifiers, the upper bound remains informative when standard attacks fail. We further demonstrate real-device feasibility on IBM Quantum hardware: from 40 executions of two 8-qubit quantum neural networks, our method estimates both bounds, with the expected lower-upper ordering on every tested input. Taken together, these results show that robustness claims for quantum classifiers can be audited directly from observable statistics under KRQA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c9f9a87f-ad1b-4259-832a-6fdaba399a84Builds on6
- Robustness Verification of Quantum ClassifiersJi Guan, Wang Fang, Mingsheng YingCAV 2021 · 38 citations
- Incremental Verification of Neural NetworksShubham Ugare, Debangshu Banerjee, Sasa Misailovic, Gagandeep SinghPLDI 2023 · 19 citations
- Fast and precise certification of transformersGregory Bonaert, Dimitar I. Dimitrov, Maximilian Baader, Martin T. VechevPLDI 2021 · 18 citations
- Robustness certification with generative modelsMatthew Mirman, Alexander Hägele, Pavol Bielik, Timon Gehr et al.PLDI 2021 · 14 citations
- Verification of Neural Networks' Global RobustnessAnan Kabaha, Dana Drachsler-CohenOOPSLA 2024 · 12 citations
Related papers
- Certifying Almost All Quantum States with Few Single-Qubit MeasurementsHsin-Yuan Huang, John Preskill, Mehdi SoleimanifarFOCS 2024 · 10 citations
- VeriQR: A Robustness Verification Tool for quantum Machine Learning ModelsYanling Lin, Ji Guan, Wang Fang, Mingsheng Ying et al.FM 2024 · 4 citations
- Scalable Quantitative Verification For Deep Neural NetworksTeodora Baluta, Zheng Leong Chua, Kuldeep S. Meel, Prateek SaxenaICSE 2021 · 39 citations
- The Power of Two Bases: Robust and Copy-Optimal Certification of Nearly All Quantum States with Few-Qubit MeasurementsAndrea Coladangelo, Jerry Li, Joseph Slote, Ellen WuSTOC 2026 · 5 citations
- Few Single-Qubit Measurements Suffice to Certify Any Quantum StateMeghal Gupta, William He, Ryan O'DonnellSTOC 2026 · 21 citations
