发表机构
Imperial College London(帝国理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出将量子神经网络权重用单位四元数表示,使加密联邦学习中的旋转更新变为双线性,从而消除自举开销,实现非交互式协议,并在156量子比特硬件上验证保真度接近未加密基线。
AI 中文摘要
加密训练依赖于保持服务器端更新为低阶。这一约束传统上排除了权重位于紧致李群中的模型(特别是变分量子电路,其中每个可训练权重都是一个SU(2)旋转)。用欧拉角或离散字母表表示时,这些更新显得超越数,历史上需要高昂成本:每个门需要一轮客户端-服务器通信,或每个权重超过25,000次操作。这种代价纯粹是坐标选择的人为产物。在单位四元数(自旋)坐标下,群合成恰好是双线性的(次数为二,系数在{-1,0,+1}中)。因此,加密旋转更新的成本为一个乘法层级,联邦平均在任何层级同态方案中成本为零,完全消除了自举。这一与实现无关的代数性质在两种密码学后端上得到确认,仅引入0.0和-2.0×10^-12弧度的聚合误差。利用这一简化,我们提出了一种用于混合量子-经典网络加密联邦训练的非交互式协议。它包含聚合和符号处理的正确性证明,以及一个编译引理,证明参数化纠缠器仅增加常数因子开销而不改变深度类别。实证上,一项配对的五次种子研究确认零可测量的效用损失(Δ=+9×10^-6均方误差,p=0.92),噪声预算消融否定了加密噪声正则化的假设。这些收敛趋势在数据集间复制,并扩展到20个客户端。最后,在156量子比特处理器上的硬件验证实现了0.9918的保真度,而未加密对照组为0.99957。
英文摘要
Encrypted training relies on keeping server-side updates low-degree. This constraint traditionally excludes models whose weights inhabit a compact Lie group (notably variational quantum circuits, where every trainable weight is an $\mathrm{SU(2)}$ rotation). Expressed in Euler angles or discrete alphabets, these updates appear transcendental, historically demanding prohibitive costs: one client--server round per gate, or upwards of $25{,}000$ operations per weight. This penalty is strictly an artefact of coordinates. In the unit-quaternion (spin) chart, group composition is exactly bilinear (degree two, with coefficients in $\{-1,0,+1\}$). Consequently, encrypted rotation updates cost one multiplicative level and federated averaging costs zero in any levelled homomorphic scheme, completely eliminating bootstrapping. This implementation-independent algebraic property is confirmed across two cryptographic backends, introducing only $0.0$ and $-2.0\times10^{-12}$ rad of aggregation error. Leveraging this reduction yields a non-interactive protocol for encrypted federated training of hybrid quantum--classical networks. It includes correctness proofs for aggregation and sign handling, plus a compilation lemma proving parameterised entanglers add only constant-factor overhead without altering the depth class. Empirically, a paired five-seed study confirms zero measurable utility tax ($Δ=+9\times10^{-6}$ MSE, $p=0.92$), and a noise-budget ablation falsifies the hypothesis that encryption noise regularises. These convergence trends replicate across datasets and scale to $20$ clients. Finally, hardware validation on a $156$-qubit processor achieves $0.9918$ fidelity against a $0.99957$ unencrypted control.
CommentsPresented as submission #203 at QCrypt 2026 accepted-papers/" target="_blank" rel="noopener">https://qcrypt.net/2026/technical/accepted-papers/