AI 中文总结
研究针对量子神经网络的安全问题,提出HarmQ方法,利用谐波触发模式及量子电路偏差进行后门攻击,在MNIST和Fashion-MNIST实验中,该方法攻击成功率超99%,干净准确率超90%,显著优于现有方法,证实其对量子神经网络构成安全威胁。
AI 中文摘要
量子神经网络(QNNs)已成为噪声中等规模量子(NISQ)时代量子机器学习的一种有前途的范式,但它继承了经典神经网络的关键安全漏洞,易受后门攻击。现有针对经典系统的攻击方法因量子特定约束对QNNs无效。为此提出HarmQ,一种利用谐波触发模式利用参数化量子电路固有傅里叶分解偏差的量子原生后门攻击。在MNIST和Fashion-MNIST上实验表明,HarmQ攻击成功率超99%,同时保持超90%的干净准确率,显著优于现有方法。量子态表示的参数t-SNE可视化证实谐波触发创建了明显分离的簇,证明HarmQ是QNNs的基本安全威胁。
英文摘要
Quantum Neural Networks (QNNs) have emerged as a promising paradigm for quantum machine learning in the Noisy Intermediate-Scale Quantum (NISQ) era, leveraging quantum phenomena such as superposition and entanglement to process information in exponentially large Hilbert spaces. However, QNNs inherit critical security vulnerabilities from classical neural networks, particularly susceptibility to backdoor attacks. Existing attack methods designed for classical systems fail against QNNs due to quantum-specific constraints: aggressive downsampling required by limited qubit resources destroys conventional triggers, while the spectral learning bias of parameterized quantum circuits (PQCs) restricts learnable patterns. To tackle this, we present HarmQ, a quantum-native backdoor attack that exploits PQCs' inherent Fourier decomposition bias through harmonic trigger patterns. Our approach employs sinusoidal perturbations on coarse grids with block-uniform structure, ensuring survival through downsampling while aligning with PQCs' preference for low-frequency components. This enables effective backdoor injection under realistic black-box conditions where attackers access only training data. Experiments on MNIST and Fashion-MNIST demonstrate that HarmQ achieves attack success rates exceeding 99% while maintaining over 90% clean accuracy, significantly outperforming existing methods including BadNets (2.77% ASR), Watermark (7.96% ASR), Q-FGSM (44.32% ASR) and QUAP (3.40% ASR). Parametric t-SNE visualizations of quantum state representations confirm that harmonic triggers create distinctly separated clusters, evidencing HarmQ as a fundamental security threat for QNNs.
Comments8 pages, 6 figures. Accepted by the IEEE International Conference on Quantum Communications, Networking, and Computing (QCNC 2026)