发表机构
University of Missouri(密苏里大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文通过量子注意力检测器实验,指出鲁棒性消融比较需固定扰动预算并检查标签保留,否则可能得出误导性结论。
AI 中文摘要
移除输入缩放模块会同时改变分类器及其编码器接收到的扰动。因此,鲁棒性差异可能既反映比较规则,也反映模块本身。我们在生成的电网轨迹数据上,通过一个四量子比特量子注意力检测器展示了这一问题。在固定的物理攻击预算下,学习到的缩放模块看似有益,但匹配编码器处扰动的上界会反转排序。单独任一比较都不能确立该模块带来的鲁棒性收益。初始测试还将干净样本扰动为攻击样本,同时保留其原始标签;仅针对已攻击样本的测试不能确立收益。替换训练模型的输入缩放会破坏检测。重新训练其线性分类层可恢复检测率,但会改变个别预测,使比较成为描述性而非因果性。另外两项设计检查解释了为何输入量子Fisher信息正则化器无法训练该模型的查询参数,以及为何移除置信度边界不能确立更大的认证半径。证据仅限于十个种子、精确模拟、合成数据和一组受限攻击;经典基线实现了更好的干净预测。实际教训是:明确固定哪个扰动预算,检查攻击是否保留标签以及干预是否保留预测,并区分探索性控制与确证性证据。
英文摘要
Removing an input-scaling module changes both a classifier and the perturbations reaching its encoder. A robustness difference can therefore reflect the comparison rule as well as the module. We demonstrate this problem in a four-qubit quantum-attention detector on generated power-grid trajectories. A learned scaling module appears beneficial at a fixed physical attack budget, but matching an upper bound on perturbations at the encoder reverses the ordering. Neither comparison alone establishes a robustness benefit caused by the module. The initial test also perturbs clean examples into attacked examples while retaining their original labels; tests restricted to already attacked examples do not establish a benefit. Replacing a trained model's input scales disrupts detection. Retraining its linear classification layer restores the detection rate, but changes individual predictions, leaving the comparison descriptive rather than causal. Two further design checks explain why the input quantum Fisher information regularizer cannot train this model's query parameters, and why removing confidence bounds does not establish a larger certified radius. The evidence is limited to ten seeds, exact simulation, synthetic data, and a restricted set of attacks; classical baselines achieve better clean prediction. The practical lesson is to specify which perturbation budget is fixed, check that attacks preserve labels and interventions preserve predictions, and distinguish exploratory controls from confirmatory evidence.
CommentsAccepted for presentation as a long oral at the NeurIPS 2026 SaTQuML Workshop, December 12-13, 2026, Atlanta, GA. arXiv version includes minor formatting revisions to meet submission requirements