提出量子联邦对抗学习框架,提升量子联邦的抗攻击能力。
QFAL: Quantum Federated Adversarial Learning
- 客户端联合生成对抗样本并用联邦平均防御扰动。
- 20%-50%对抗训练覆盖率即可显著增强对中等扰动的抵抗力。
- 需权衡客户端数量与对抗覆盖比例以平衡精度与鲁棒性。
量子联邦学习(QFL)结合了联邦系统隐私保护与量子神经网络(QNN)的计算潜力,但其对抗攻击下的脆弱性尚不明确。本文首次将对抗训练引入QFL,提出量子联邦对抗学习(QFAL)框架,客户端通过本地生成对抗样本并结合联邦平均(FedAvg)协同防御。我们在MNIST数据集上系统评估了三个关键因素:客户端数量(5、10、15)、对抗训练覆盖率(0%-100%)及攻击扰动强度(epsilon=0.01-0.5)。结果表明,客户端较少时清洁数据准确率更高,但更大规模联邦在部分对抗训练下能更好平衡精度与鲁棒性。即使仅20%-50%对抗训练覆盖率,也能显著提升对中等扰动的抵抗能力,但会降低基线性能;而100%对抗训练虽可恢复高清洁准确率,却在强攻击下仍易受攻。这揭示了鲁棒性与标准性能之间的固有权衡,且受量子特性进一步影响。结论强调,合理选择客户端数量与对抗覆盖率对缓解QFL中的对抗漏洞至关重要。此外,未来研究可探索自适应对抗训练策略、更丰富的量子编码方案及个性化防御机制,以进一步优化真实量子联邦环境中的性能权衡。
原文摘要 · Abstract (English)
Quantum federated learning (QFL) merges the privacy advantages of federated systems with the computational potential of quantum neural networks (QNNs), yet its vulnerability to adversarial attacks remains poorly understood. This work pioneers the integration of adversarial training into QFL, proposing a robust framework, quantum federated adversarial learning (QFAL), where clients collaboratively defend against perturbations by combining local adversarial example generation with federated averaging (FedAvg). We systematically evaluate the interplay between three critical factors: client count (5, 10, 15), adversarial training coverage (0-100%), and adversarial attack perturbation strength (epsilon = 0.01-0.5), using the MNIST dataset. Our experimental results show that while fewer clients often yield higher clean-data accuracy, larger federations can more effectively balance accuracy and robustness when partially adversarially trained. Notably, even limited adversarial coverage (e.g., 20%-50%) can significantly improve resilience to moderate perturbations, though at the cost of reduced baseline performance. Conversely, full adversarial training (100%) may regain high clean accuracy but is vulnerable under stronger attacks. These findings underscore an inherent trade-off between robust and standard objectives, which is further complicated by quantum-specific factors. We conclude that a carefully chosen combination of client count and adversarial coverage is critical for mitigating adversarial vulnerabilities in QFL. Moreover, we highlight opportunities for future research, including adaptive adversarial training schedules, more diverse quantum encoding schemes, and personalized defense strategies to further enhance the robustness-accuracy trade-off in real-world quantum federated environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。