arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.11095quant-phcs.CRcs.LG

当廉价梯度失效时:攻击量子分类器的测量成本

When cheap gradients fail: the measurement cost of attacking quantum classifiers

Bacui Li, Chandra Thapa, Tansu Alpcan, Udaya Parampalli

首次发表
浏览论文内容

中文总结 AI 辅助

研究对抗性扰动对量子分类器的威胁,指出有限量子测量统计可防御基于梯度的攻击,分析单步及迭代攻击测量次数与输入维度关系,通过模拟和实验验证规律,揭示量子梯度成本随模型规模变化情况及防御起作用的条件。

中文摘要 AI 辅助

对抗性扰动威胁着包括变分量子分类器在内的机器学习分类器。我们表明,有限的量子测量统计(散粒噪声)可作为针对基于梯度的测试时攻击的一种内置防御,其成本对攻击者而言增长不利。由于每个梯度分量都必须从任何无偏梯度估计规则下的重复电路执行中推断出来,白盒提取会消耗与维度相关的测量预算,而测量分组在表达性电路中无法消除这种预算。在既定假设下,单步攻击在输入维度\(d\)中至少需要二次数量的测量次数,在范数集中缩放时增长为\(d^{5/2}\),并通过随机梯度朗之万动力学对迭代攻击进行了充分预算分析。高达784维输入的模拟验证了该规律:对于平稳缓解模型,实际总预算是\(d^{5/2}\)的几何下限,对于测试的深度电路,其增长为\(d^{3.00}\),其梯度范数在无贫瘠高原缓解的情况下随维度衰减;将测量的梯度范数折回可恢复无参数的\(d^{3/2}\)散粒噪声几何形状。与攻击开销与维度无关的匹配经典基线(自动微分的廉价梯度原则)相比,量子梯度成本比经验上增长为\(d^{3.00}\),因此随着模型规模扩大,攻击者的相对成本会发散。在156量子比特的IBM处理器(ibm_boston,4量子比特电路,\(d = 12\))上进行的实验重现了这种效果:在匹配预算下,设备攻击在百分之几的范围内跟踪理想情况,高测量次数梯度忠实于精确梯度。当正向映射在经典上难以模拟时,这种防御精确起作用:只有在这种情况下,白盒攻击者才会被拒绝模拟并反向传播捷径,并且必须支付我们量化的测量成本。

英文摘要

Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers. We show that finite quantum measurement statistics (shot noise) act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker. Because every gradient component must be inferred from repeated circuit executions under any unbiased gradient-estimation rule, white-box extraction consumes a dimension-dependent measurement budget that measurement grouping cannot remove in expressive circuits. Under stated assumptions, single-step attacks need at least quadratically many shots in the input dimension $d$, growing as $d^{5/2}$ under norm-concentration scaling, with a sufficient-budget analysis for iterative attacks via stochastic gradient Langevin dynamics. Simulations up to 784 input dimensions validate the law: the realized total budget is the $d^{5/2}$ geometric floor for plateau-mitigated models and grows as $d^{3.00}$ for the tested deep circuits, whose gradient norms decay with dimension absent barren-plateau mitigation; folding the measured gradient norm back in recovers the parameter-free $d^{3/2}$ shot-noise geometry. Against a matched classical baseline whose attack overhead is dimension-independent (the cheap-gradient principle of automatic differentiation), the quantum gradient cost ratio grows empirically as $d^{3.00}$, so the attacker's relative cost diverges as the model scales. Experiments on a 156-qubit IBM processor (ibm_boston, 4-qubit circuits, $d=12$) reproduce the effect: at matched budgets the device attack tracks the ideal within a few percent, with the high-shot gradient faithful to the exact one. The defense operates precisely when the forward map is classically hard to simulate: only then is a white-box attacker denied the simulate-and-backpropagate shortcut and must pay the measurement cost we quantify.

发表机构

  • Department of Electrical and Electronic Engineering, University of Melbourne(墨尔本大学电气与电子工程系)
  • School of Computing and Information Systems, University of Melbourne(墨尔本大学计算机与信息系统学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑