arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

超越数据保密性的量子工作负载隐私

Quantum Workload Privacy Beyond Data Confidentiality

Shaunak Suresh Pawar, Samuel Punch, Krishnendu Guha

arXiv 2609.02323首次发表:更新:

发表机构

School of Computer Science and Information Technology, University College Cork(科克大学计算机科学与信息技术学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究发现量子工作负载的科学结构会因硬件感知编译泄露,提出科学意图不可区分性威胁,在IBM Heron处理器上验证泄露可泛化,指出需将执行级保密性作为量子计算设计要求。

AI 中文摘要

远程量子计算存在保密性缺口:标准隐私机制保护量子态和输出,但不保护工作负载的科学结构。本研究表明,硬件感知编译会留下可观测特征,如路由开销、电路深度和门组成,这些特征与部分微分方程边界条件、离散化尺度、分子几何结构等隐藏建模选择相关。这种泄露源于逻辑拓扑与固定硬件连接性的不匹配,需插入依赖问题的SWAP门。我们将此威胁形式化为科学意图不可区分性,并证明在路由最优编译下被动安全渐近不可实现。在156量子比特的IBM Heron处理器上的实验实现了边界 regime 和分子几何结构的近乎完美分类,且泄露可通过路由缩放指数在求解器家族间泛化。传统门填充作为防御失效,会导致保真度下降却不降低对抗优势。研究表明仅保护量子数据不足,执行级保密性必须成为一级设计要求。

英文摘要

Remote quantum computing exposes a confidentiality gap. Standard privacy mechanisms protect quantum states and outputs, but not the scientific structure of a workload. This work reveals that hardware-aware compilation leaves observable signatures, such as routing overhead, circuit depth, and gate composition, that correlate with hidden modelling choices like partial differential equation boundary conditions, discretisation scale, and molecular geometry. The leakage arises from the mismatch between logical topology and fixed hardware connectivity, forcing problem-dependent SWAP insertion. We formalise this threat as Scientific-Intent Indistinguishability and prove that passive security is asymptotically unachievable under routing-optimal compilation. Experiments on a 156-qubit IBM Heron processor achieve near-perfect classification of boundary regimes and molecular geometries, with leakage generalising across solver families via routing-scaling exponents. Conventional gate-padding fails as a defence, causing fidelity drops without reducing adversarial advantage. Our results show that protecting quantum data alone is insufficient; execution-level confidentiality must become a first-class design requirement.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑