arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

量子纠错中的解码器先验投毒:攻击与PriorGuard防御

Decoder-Prior Poisoning in Quantum Error Correction: Attacks and PriorGuard Defense

Xinyi Li, Yifeng Peng, Juntao Chen, Ying Wang

arXiv 2609.27805首次发表:更新:

AI 中文总结

针对量子纠错解码器先验更新路径的投毒攻击,提出PriorGuard轻量级语义防护,仅投毒6.4%先验条目可致逻辑错误率提升3.35倍,防护以低误报率恢复损失。

AI 中文摘要

量子纠错(QEC)通过重复测量稳定子综合征并使用经典解码器推断纠错操作来保护量子计算。现代表面码解码器日益具有校准感知能力:它们利用近期设备行为来设置先验,例如匹配图边概率,而这些先验直接塑造所选的纠错操作。我们识别出先验更新路径是一个被忽视的、对完整性至关重要的攻击面:即使综合征流、逻辑标签和解码器实现均未改变,被投毒的先验也能改变解码决策。这使得先验投毒不同于普通的综合征异常,并且难以被原始的综合征异常测试检测到。我们引入PriorGuard,一种轻量级语义防护,它针对高影响力的探测器图条目,将提议的先验更改与私有的综合征衍生证据进行核对,仅当更新的对数几率变动有证据支持时才接受更新,否则回退到最后一个有证据支持的先验。我们在使用PyMatching解码的Stim生成的旋转表面码存储电路上进行了评估。先验影响力高度集中,前10%的条目承载了超过60%的正逻辑错误影响力;仅投毒6.4%的解码器先验条目就能将逻辑错误率(LER)提高3.35倍。PriorGuard以较低的误报率和适度的更新边界开销(每次更新约1.7--1.8毫秒和小于0.31 MB的辅助内存)恢复了大部分攻击导致的损失。

英文摘要

Quantum error correction (QEC) protects quantum computations by repeatedly measuring stabilizer syndromes and using a classical decoder to infer corrections. Modern surface-code decoders are increasingly calibration-aware: they use recent device behavior to set priors such as matching-graph edge probabilities, and these priors directly shape the selected correction. We identify the prior-update path as an overlooked integrity-critical attack surface: a poisoned prior can change decoding decisions even when the syndrome stream, logical labels, and decoder implementation are unchanged. This makes prior poisoning different from ordinary syndrome anomalies and difficult for raw syndrome-anomaly tests to detect. We introduce PriorGuard, a lightweight semantic guard that checks proposed prior changes on high-influence detector-graph entries against private syndrome-derived evidence, accepts updates only when their log-odds movement is evidence-supported, and otherwise falls back to the last evidence-supported prior. We evaluate on Stim-generated rotated surface-code memory circuits decoded with PyMatching. Prior influence is highly concentrated, with the top 10 percent of entries carrying over 60 percent of positive logical-error influence; poisoning only 6.4 percent of decoder-prior entries can raise logical error rate (LER) by 3.35x. PriorGuard recovers most attack-induced loss with a low false-positive rate and modest update-boundary overhead of about 1.7--1.8 ms and less than 0.31 MB auxiliary memory per update.

CommentsAccepted at IEEE QCE 2026. 4 pages, 8 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑