arXiv:2411.14412quant-phcs.CR2024-11被引 4

提出针对量子机器学习的新型数据投毒攻击,可大幅降低模型性能。

Adversarial Data Poisoning Attacks on Quantum Machine Learning in the NISQ Era

  • 基于编码电路输出分析类内状态相似性,设计无差别投毒方法
  • 在无噪声和真实设备噪声下,使模型准确率下降最高达92%
  • 对经典防御仍有效,适合关注量子安全的研究者

随着量子机器学习(QML)兴起及云上量子计算机普及,QML的安全风险亟需关注。当前量子云环境下,对手可访问训练数据,严重威胁QML模型的完整性和可用性。传统数据投毒需大量知识且抗噪能力差,难以适用于当前噪声中等规模量子(NISQ)时代。本文首次提出一种简单有效的类内编码器状态相似性(ESS)测量方法,基于编码电路输出进行分析。在此基础上,我们提出量子无差别数据投毒攻击(QUID)。在无噪声与真实设备噪声(如IBM_Brisbane)环境下,对多种架构和数据集进行广泛实验,QUID使模型性能准确率最高下降92%(相比基线),较随机标签翻转攻击提升15个百分点。同时测试了对先进经典防御机制的鲁棒性,准确率仍下降超50%,验证其有效性。本工作是首个重新评估量子机器学习中数据投毒攻击的研究。

原文摘要 · Abstract (English)

With the growing interest in Quantum Machine Learning (QML) and the increasing availability of quantum computers through cloud providers, addressing the potential security risks associated with QML has become an urgent priority. One key concern in the QML domain is the threat of data poisoning attacks in the current quantum cloud setting. Adversarial access to training data could severely compromise the integrity and availability of QML models. Classical data poisoning techniques require significant knowledge and training to generate poisoned data, and lack noise resilience, making them ineffective for QML models in the Noisy Intermediate Scale Quantum (NISQ) era. In this work, we first propose a simple yet effective technique to measure intra-class encoder state similarity (ESS) by analyzing the outputs of encoding circuits. Leveraging this approach, we introduce a \underline{Qu}antum \underline{I}ndiscriminate \underline{D}ata Poisoning attack, QUID. Through extensive experiments conducted in both noiseless and noisy environments (e.g., IBM\_Brisbane's noise), across various architectures and datasets, QUID achieves up to $92\%$ accuracy degradation in model performance compared to baseline models and up to $75\%$ accuracy degradation compared to random label-flipping. We also tested QUID against state-of-the-art classical defenses, with accuracy degradation still exceeding $50\%$, demonstrating its effectiveness. This work represents the first attempt to reevaluate data poisoning attacks in the context of QML.

量子机器学习数据投毒安全攻防NISQ

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。