发表机构
University of California, Berkeley; GeeQChiQ Technologies LLC(加州大学伯克利分校; GeeQChiQ技术有限责任公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究识别量子纠错中被动综合征记录的歧义,提出利用校准测量和独立评估器认证恢复更新,以抵御AI顾问的有害建议,并量化保守接受所放弃的改进。
AI 中文摘要
攻击者能否将对人工智能(AI)顾问的影响力转化为有害的量子纠错更新?我们识别出被动综合征记录中阻碍恢复选择的一个歧义,然后展示额外的校准测量如何在不确定性和漂移下支持经认证的恢复更新。在无错误制备、综合征测量和恢复操作的奇距离方形环面码中,相反的相干$X$旋转产生相同的被动综合征历史分布。然而,固定的相位校正在一个符号下可能有帮助,在另一个符号下可能有害。对已知编码校准状态的终端逻辑测量提供了缺失的符号信息。一个独立的评估器仅在校准不确定性和合理的漂移界限证明当前恢复有改进时接受更新,而不假设顾问推荐正确。在模拟的咨询攻击中,校准置信度检查拒绝有害提议,同时在诚实建议下保留有益更新。我们推导了校准年龄的充分界限,要求通过部署进行改进。在匹配的模拟中,经过验证的通道特定界限在考虑评估时间后比通用界限保留更多有益更新,同时在所述漂移假设下阻止测试的有害激活。一个单独的表面码实验包括随机电路故障和采集期间变化的噪声。确定性控制器在相同观测下实现至少同样多的有益更新。违反漂移假设允许在环面实验中接受有害更新。结果确定了恢复选择所需的信息,建立了针对有害更新的条件保证,并量化了通过保守接受而放弃的恢复改进。
英文摘要
Can an attacker turn influence over an artificial intelligence (AI) adviser into a harmful quantum error-correction update? We identify an ambiguity in passive syndrome records that obstructs recovery selection, then show how additional calibration measurements support certified recovery updates under uncertainty and drift. In an odd-distance square toric code with error-free preparation, syndrome measurements, and recovery operations, opposite coherent $X$ rotations produce identical passive syndrome-history distributions. Yet a fixed phase correction can help at one sign and harm at the other. A terminal logical measurement on known encoded calibration states supplies the missing sign information. A separate evaluator accepts an update only when calibration uncertainty and a justified drift bound certify improvement over the current recovery, without assuming that the adviser recommends correctly. In simulated advice attacks, calibration-confidence checks reject harmful proposals while retaining beneficial updates under honest advice. We derive sufficient limits on calibration age that require improvement through deployment. In matched simulations, a validated channel-specific bound retains more beneficial updates than the general bound after accounting for evaluation time, while preventing the tested harmful activations under the stated drift assumption. A separate surface-code experiment includes stochastic circuit faults and noise changing during acquisition. Deterministic controllers achieve at least as many beneficial updates with the same observations. Violating the drift assumption permits harmful acceptance in the toric experiment. The results identify information required for recovery selection, establish conditional guarantees against harmful updates, and quantify the recovery improvements forgone through conservative acceptance.
Comments74 pages, 32 figures (10-page main text, 62 pages of Supplemental Material, and 2 pages of references)