arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.19318quant-phcs.CR

审视:通过红队测试的变分量子本征求解器的对抗鲁棒性

SoK: Adversarial Robustness of the Variational Quantum Eigensolver via Red-Teaming

Ahmed Azaz Humdoon, Cheng Chu, Lei Jiang, Qian Lou, Mengxin Zheng

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对变分量子本征求解器(VQE)的攻击,提出VQE-AdvBench统一红队测试基准,按黑、灰、白盒访问分类组织攻击,在固定配置上评估七种场景,揭示不同攻击的严重程度排序。

中文摘要 AI 辅助

变分量子本征求解器(VQE)是用于在近期量子硬件上估计分子基态能量的领先算法,其应用涵盖量子化学、材料科学和药物发现等领域。随着VQE工作负载越来越多地通过基于云的“VQE即服务”管道部署,它们容易受到诸如受损服务组件、恶意共同租户或转译堆栈中的内部人员等对手的攻击,这些对手可能在结果到达用户之前破坏结果。已经提出了一系列针对变分量子电路的攻击,但每种攻击都是单独研究的:一些针对具有基于准确性的度量的量子分类器,另一些针对具有能量误差度量的变分量子算法。这种缺乏通用评估设置的情况使得难以比较它们的相对严重性,并且使得VQE的安全性特征不佳。在这项工作中,我们提出了VQE-AdvBench,这是变分量子本征求解器的第一个统一红队测试基准,在单个评估协议下将这些攻击系统化,以严格评估VQE的对抗鲁棒性。我们根据黑盒、灰盒和白盒访问分类法组织攻击,并在固定的分子-假设-后端-度量配置上,在五个经过噪声校准的IBM后端上对H₂和H₃⁺评估七种代表性攻击场景——QTrojan电路后门、QDoor参数后门、FGSM和PGD的参数空间适应以及三种QNBAD噪声诱导变体。我们的结果揭示了一个明显的严重性顺序:操纵零噪声外推(ZNE)管道的噪声诱导攻击最具破坏性(误差放大高达8.84倍),其次是QTrojan电路级后门(7.52倍),而QDoor参数级后门效果最差,仅产生边际放大(高达1.37倍)。

英文摘要

The Variational Quantum Eigensolver (VQE) is a leading algorithm for estimating molecular ground-state energies on near-term quantum hardware, with applications spanning quantum chemistry, materials science, and drug discovery. As VQE workloads are increasingly deployed through cloud-based ``VQE-as-a-service'' pipelines, they become exposed to adversaries such as compromised service components, malicious co-tenants, or insiders in the transpilation stack, any of which can corrupt results before they reach the user. A range of attacks on variational quantum circuits has been proposed, but each has been studied in isolation: some on quantum classifiers with accuracy-based metrics, others on variational quantum algorithms with energy-error metrics. This lack of a common evaluation setup makes their relative severity difficult to compare and leaves the security of VQE poorly characterized. In this work, we present \textbf{VQE-AdvBench}, the first unified red-teaming benchmark for the Variational Quantum Eigensolver, systematizing these attacks under a single evaluation protocol to rigorously assess VQE's adversarial robustness. We organize attacks along a black-, gray-, and white-box access taxonomy, and evaluate seven representative attack scenarios -- the QTrojan circuit backdoor, the QDoor parameter backdoor, parameter-space adaptations of FGSM and PGD, and three QNBAD noise-induced variants -- over a fixed molecule-ansatz-backend-metric configuration, on H$_2$ and H$_3^+$ across five noise-calibrated IBM backends. Our results reveal a clear severity ordering: noise-induced attacks that manipulate the Zero-Noise Extrapolation (ZNE) pipeline are the most damaging (up to 8.84$\times$ error amplification), followed by the QTrojan circuit-level backdoor (7.52$\times$), while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification (up to 1.37$\times$).

补充信息

↑