SoK: Critical Evaluation of Quantum Machine Learning for Adversarial Robustness
Saeefa Rubaiyet Nowmi, Jesus Rafael Lopez, Md Mahmudul Alam Imon, Shahrooz Pouryousef, Mohammad Saidur Rahman
摘要
Quantum Machine Learning (QML) integrates quantum computational principles into learning algorithms, offering improved representational capacity and computational efficiency. However, the security and robustness of QML systems remain underexplored, particularly under adversarial conditions. We present the first comprehensive systematization of adversarial robustness in QML, combining conceptual organization with empirical evaluation across black-box, gray-box, and white-box threat models. We implement five representative attacks: a label-flipping poisoning attack under black-box; an encoder-level indiscriminate poisoning attack and a proxy-model clean-label backdoor attack under gray-box; and a circuit-level backdoor attack (QTrojan) and gradient-based evasion attacks (FGSM and PGD) under white-box. We evaluate these attacks using a Quantum Multilayer Perceptron (QMLP) trained on MNIST and AZ-Class across circuit depths of 2, 5, 10, and 50 layers with angle and amplitude encoding schemes. Our evaluations reveal a fundamental accuracy-robustness trade-off. Amplitude encoding achieves the highest clean accuracy (92.6% on MNIST and 67% on AZ-Class) but collapses under adversarial perturbations and depolarizing noise, whereas shallow angle-encoded models remain more stable. QUID is effective under noiseless conditions but weakened by noise, while the proxy-model backdoor persists unless the circuit itself is overwhelmed. Furthermore, the circuit-level backdoor fails in the multi-class setting, indicating a scalability limitation. Finally, QMLP models are more robust than Classical Multi-Layer Perceptron (CMLP) models under label-flipping attacks but substantially more vulnerable to gradient-based evasion. We conclude by proposing a threat-aware and noise-resilient framework for secure QML deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Towards Quantum Machine Learning for Constrained Combinatorial Optimization: a Quantum QAP SolverXinyu Ye, Ge Yan, Junchi YanICML 2023 · 被引用 14 次
- Mitigating Crosstalk in Quantum Computers through Commutativity-Based Instruction ReorderingLei Xie, Jidong Zhai, Weimin ZhengDAC 2021 · 被引用 12 次
- Securing NISQ Quantum Computer Reset Operations Against Higher Energy State AttacksChuanqi Xu, Jessie Chen, Allen Mi, Jakub SzeferCCS 2023 · 被引用 10 次
- Crosstalk-induced Side Channel Threats in Multi-Tenant NISQ ComputersNavnil Choudhury, Chaithanya Naik Mude, Sanjay Das, Preetham Chandra Tikkireddi 等NDSS 2025
- Security Attacks Abusing Pulse-level Quantum CircuitsChuanqi Xu, Jakub SzeferS&P 2025
相关 Paper
- QNBAD: Quantum Noise-induced Backdoor Attacks against Zero Noise ExtrapolationCheng Chu, Qian Lou, Fan Chen, Lei JiangNDSS 2026 · 被引用 3 次
- Robustness Verification of Quantum ClassifiersJi Guan, Wang Fang, Mingsheng YingCAV 2021 · 被引用 38 次
- Generating Universal Adversarial Perturbations for Quantum ClassifiersGautham Anil, Vishnu Vinod, Apurva NarayanAAAI 2024 · 被引用 10 次
- VeriQR: A Robustness Verification Tool for quantum Machine Learning ModelsYanling Lin, Ji Guan, Wang Fang, Mingsheng Ying 等FM 2024 · 被引用 4 次
- Rounding-Guided Backdoor Injection in Deep Learning Model QuantizationXiangxiang Chen, Peixin Zhang, Jun Sun, Wenhai Wang 等NDSS 2026 · 被引用 4 次
