BadQubits:一种基于LLM的静态预执行检测框架,用于识别结构有害的量子电路
BadQubits: An LLM-Based Framework for Static Pre-Execution Detection of Structurally Harmful Quantum Circuits
浏览论文内容
中文总结 AI 辅助
BadQubits利用LLM在量子电路执行前静态检测结构有害电路,微调Qwen Coder 2.5 7B达到92.67%准确率,优于CNN基线,归因于保留序列结构。
中文摘要 AI 辅助
本文提出了BadQubits,一种基于LLM的框架,用于在静态预执行阶段检测结构上有害的OpenQASM 2.0电路。该框架通过分析提交的电路来针对物理执行层威胁,在运行时之前进行检测,因为动态检查受到测量不可逆性和经典量子态模拟的指数成本的限制。我们在一个包含1,500个电路的数据集上评估了四种代码理解LLM架构,该数据集由来自MQTBench[33]的1,000个良性程序和从三种已记录的物理层威胁原语衍生的500个合成攻击电路组成。我们微调的Qwen Coder 2.5 7B模型实现了92.67%的分类准确率和96.1%的有害电路召回率。在受约束的LoRA微调下,四种评估的基础模型中有两种未能泛化,这表明架构感知的模型选择是一个必要的设计考虑因素,而非次要的调优选择。为了表征检测器所学到的内容,我们将其与袋装门CNN在渐进混杂因素去除和对抗性句法扰动下进行比较。CNN的有害电路召回率从100%下降到17%,而微调的LLM仅从96.1%下降到91.2%。我们将这一差距归因于LLM输入中保留的序列结构,而基于直方图的基线则丢弃了该结构。相关性分析进一步表明,模型决策跟踪威胁定义特征,特别是SWAP密度和测量时序,而非生成器特定的伪影,如寄存器命名。
英文摘要
This paper presents BadQubits, an LLM-based framework for static pre-execution detection of structurally harmful OpenQASM 2.0 circuits. The framework targets physical-execution-layer threats by analyzing submitted circuits prior to runtime, where dynamic inspection is constrained by measurement irreversibility and the exponential cost of classical quantum-state simulation. We evaluate four code-understanding LLM architectures on a dataset of 1,500 circuits consisting of 1,000 benign programs from MQTBench[33] and 500 synthetic attack circuits derived from three documented physical-layer threat primitives. Our fine-tuned Qwen Coder 2.5 7B model achieves 92.67% classification accuracy and 96.1% harmful-circuit recall. Two of the four evaluated base models fail to generalize under constrained LoRA fine-tuning, indicating that architecture-aware model selection is a necessary design consideration rather than a minor tuning choice. To characterize what the detector has learned, we compare it against a bag-of-gates CNN under progressive confound removal and adversarial syntactic perturbation. The CNN's harmful-circuit recall drops from 100% to 17%, while the fine-tuned LLM decreases only from 96.1% to 91.2%. We attribute this gap to the sequential structure retained in token-level LLM inputs but discarded by histogram-based baselines. A correlation analysis further shows that model decisions track threat-defining features, specifically SWAP density and measurement timing, rather than generator-specific artifacts such as register naming.
发表机构
- Louisiana State University(路易斯安那州立大学)
机构由 AI 辅助整理,请以论文原文为准。