arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.11637quant-phcs.CR

在已知读出查询访问下认证量子分类器的对抗鲁棒性

Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query Access

Ji Guan, Mingyu Huang

首次发表
浏览论文内容

中文总结 AI 辅助

提出仅基于测量的框架,在已知读出查询访问下为量子分类器提供对抗鲁棒性的上下界证书,无需内部信息,并在IBM量子硬件上验证可行性。

中文摘要 AI 辅助

量子分类器通过演化输入量子态并测量输出来分配标签,因此重复执行仅揭示标签上的分布。我们研究了在已知读出查询访问(KRQA)下此类分类器的认证对抗鲁棒性,其中评估者可以制备输入、知道量子测量并观察有限次数的结果,但无法检查内部演化、参数或梯度。我们提出了一个仅基于测量的框架,为每个输入返回两个互补的保证:一个排除半径内非定向错误的下界,以及一个证明半径内存在对抗态的攻击无关的上界。两者均可从已知读出测量和采样结果中估计,不需要层析成像或电路描述,并具有有限样本保证。上界使用由量子测量诱导的间隙算子;下界将状态空间搜索放宽为对具有算子谱约束的结果分布的高效优化,产生的证书从不弱于先前仅概率的证书,并且在谱约束激活时可以严格更强。对多个量子分类器的评估表明,下界在可处理的实例上跟踪精确最优值,而上界在标准攻击失败时仍然提供信息。我们进一步在IBM量子硬件上展示了真实设备的可行性:从两个8比特量子神经网络的40次执行中,我们的方法计算了两个证书,在每个测试输入上,下界和上界之间的预期顺序均成立。综合来看,这些结果表明,量子分类器的鲁棒性声明可以在KRQA下直接从可观测统计量进行审计。

英文摘要

A quantum classifier assigns labels by evolving an input quantum state and measuring the output, so repeated executions reveal only a distribution over labels. We study certified adversarial robustness for such classifiers under known-readout query access (KRQA), where an evaluator can prepare inputs, knows the quantum measurement, and observes finite-shot outcomes but cannot inspect the internal evolution, parameters, or gradients. We give a measurement-only framework that returns two complementary guarantees for each input: a lower bound ruling out untargeted errors within a radius, and an attack-independent upper bound witnessing an adversarial state within a radius. Both are estimable from the known readout measurement and sampled outcomes, require no tomography or circuit description, and have finite-sample control of probability-estimation error. The upper bound uses gap operators induced by the quantum measurement; the lower bound relaxes state-space search to an efficient optimization over outcome distributions with operator-spectrum constraints, yielding certificates that are never weaker than prior probability-only certificates and can be strictly stronger when the spectral constraints are active. On tractable instances, we compare the lower bound with numerical white-box reference estimates; across multiple classifiers, the upper bound remains informative when standard attacks fail. We further demonstrate real-device feasibility on IBM Quantum hardware: from 40 executions of two 8-qubit quantum neural networks, our method estimates both bounds, with the expected lower-upper ordering on every tested input. Taken together, these results show that robustness claims for quantum classifiers can be audited directly from observable statistics under KRQA.

发表机构

  • Key Laboratory of System Software (Chinese Academy of Sciences)(系统软件重点实验室(中国科学院))
  • Institute of Software, Chinese Academy of Sciences(中国科学院软件研究所)
  • Arclight Quantum Computing Inc.(阿克拉特量子计算有限公司)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑