发表机构
Workday AI Research(Workday 人工智能研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究审计混合量子-经典模型中读出旁路对原始输入的泄露,发现残差头可高保真重建输入,而仅量子头仅泄露其实际编码的坐标,提出以特征可见性为条件的隐私审计方法。
AI 中文摘要
读出侧残差混合模型将原始输入与测量得到的量子特征拼接在一起。在单样本梯度共享条件下,有偏的第一线性层允许对其输入进行标准的解析恢复,因此旁路会暴露原始坐标,而无需对量子电路进行求逆。我们使用两个表格数据集、四种架构以及以特征可见性为条件的指标来审计这一机制。迭代梯度匹配在残差头和仅输入头上实现了全记录中值PSNR为73-96 dB。仅量子头在全记录上得分为8-11 dB,但在它们实际编码的六个输入坐标上得分为54-96 dB。这些是针对所测试的六输入、六可观测电路的重建结果,并非关于量子编码的一般性陈述。基于损失阈值的成员关系攻击仍接近随机猜测水平。本工作的贡献在于一种以可见性为条件的隐私审计:不应将未编码的坐标视为量子处理所提供的保护,也不应将近乎精确的PSNR差异解释为有意义的隐私排名。我们的发现涉及单个梯度,并不确立在聚合或多个局部训练步骤下的泄露情况。
英文摘要
Readout-side residual hybrids concatenate raw inputs with measured quantum features. Under single-example gradient sharing, a biased first linear layer admits standard analytic recovery of its input, so the bypass exposes raw coordinates without requiring inversion of the quantum circuit. We audit this mechanism using two tabular datasets, four architectures, and metrics conditioned on feature visibility. Iterative gradient matching gives median full-record PSNR of 73-96 dB for residual and input-only heads. Quantum-only heads score 8-11 dB on the full record but 54-96 dB on the six input coordinates they actually encode. These are reconstruction results for the tested six-input, six-observable circuits, not a general statement about quantum encodings. A loss-threshold membership attack remains near chance. The contribution is a visibility-conditioned privacy audit: omitted coordinates must not be credited as protection supplied by quantum processing, and near-exact PSNR differences must not be interpreted as meaningful privacy rankings. Our findings concern individual gradients and do not establish leakage under aggregation or multiple local training steps.
CommentsAccepted as a poster at the NeurIPS 2026 Workshop on Secure and Trustworthy Quantum Machine Learning (SaTQuML)