arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.11843quant-phcs.LG

针对量子神经网络的输入感知动态后门攻击

Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

Junrui Zhang, Zemin Chen, Lusi Li, Mohammad Ghasemigol, Daniel Takabi, Rui Ning

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对量子神经网络的安全风险,提出Q-DIBA这一输入感知动态后门攻击方法,通过三模式小批量策略联合训练经典触发生成器和受害QNN,引入总体密度对比损失,实验验证其有效性、隐蔽性及对多种防御的抗性。

中文摘要 AI 辅助

量子神经网络是近量子设备上量子机器学习的有前景框架,但其安全风险了解不足。研究表明QNN易受后门攻击,现有量子后门大多依赖固定触发。输入感知动态后门在经典神经网络中已被研究,但转移到QNN有困难。本文提出Q-DIBA,首个针对QNN的输入感知动态后门攻击。通过三模式小批量策略联合训练经典触发生成器和受害QNN,引入总体密度对比损失。实验表明Q-DIBA有效、隐蔽且具有输入特异性,对多种防御有抗性,凸显输入感知量子后门对QNN安全部署是重要威胁。

英文摘要

Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Studies have shown that QNNs are vulnerable to backdoor attacks, yet existing quantum backdoors mostly rely on a fixed trigger shared by all poisoned inputs. This fixed-trigger design is a major weakness because many defenses detect or weaken the repeated patterns such triggers leave in data representations. Although input-aware dynamic backdoors have been studied in classical neural networks, transferring them to QNNs is difficult because quantum learning introduces new obstacles. In particular, measurement compresses the post-ansatz quantum state into a limited classical output, weakening supervision for a trigger generator, while individual density matrices fluctuate with the input and make per-sample contrastive learning unstable. To address these challenges, we propose Q-DIBA, the first input-aware dynamic backdoor attack for QNNs. Q-DIBA jointly trains a classical trigger generator and a victim QNN through a three-mode mini-batch strategy that supports clean behavior, attack activation, and trigger specificity. To provide stable quantum-level supervision, Q-DIBA introduces an ensemble density contrastive loss that operates on post-ansatz quantum states before measurement and contrasts mode-averaged density matrices rather than individual samples. Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, demonstrating effectiveness, stealthiness, and input specificity. The attack also remains resilient against defenses including visual inspection, spectral-signature detection, and fine-tuning, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.

发表机构

  • Department of Computer Science, Old Dominion University(计算机科学系,老 Dominion 大学)
  • School of Cybersecurity , Old Dominion University(网络安全学院,老 Dominion 大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑