针对量子神经网络的窃取攻击,提出抗噪声新方法。
CopyQNN: Quantum Neural Network Extraction Attack under Varying Quantum Noise
- 通过三步去噪清理量子噪声数据,提升查询数据质量。
- 结合对比学习与迁移学习,仅用1/90的查询量实现更高精度攻击。
- 适用于真实量子设备环境,适合研究量子安全或攻防的学者。
量子神经网络(QNN)在多个领域展现出巨大价值,训练良好的QNN作为关键知识产权常通过云服务模式(QNNaaS)部署。现有研究已探索使用经典和新兴量子策略进行模型窃取攻击,即通过查询云平台获取带标签数据,训练本地替代模型以复现云端模型功能。然而,现有方法普遍忽略实际量子设备中固有的可变噪声问题,限制了其在现实场景中的有效性。为此,本文提出CopyQNN框架,采用三步数据清洗方法,根据数据对噪声的敏感性剔除受污染样本。随后在量子域内融合对比学习与迁移学习,利用少量但经过清洗的数据高效训练替代QNN。实验在NISQ计算机上验证,该方案相比现有最先进攻击方法,在所有任务上平均性能提升8.73%,查询次数减少90倍,硬件开销仅略有增加。
原文摘要 · Abstract (English)
Quantum Neural Networks (QNNs) have shown significant value across domains, with well-trained QNNs representing critical intellectual property often deployed via cloud-based QNN-as-a-Service (QNNaaS) platforms. Recent work has examined QNN model extraction attacks using classical and emerging quantum strategies. These attacks involve adversaries querying QNNaaS platforms to obtain labeled data for training local substitute QNNs that replicate the functionality of cloud-based models. However, existing approaches have largely overlooked the impact of varying quantum noise inherent in noisy intermediate-scale quantum (NISQ) computers, limiting their effectiveness in real-world settings. To address this limitation, we propose the CopyQNN framework, which employs a three-step data cleaning method to eliminate noisy data based on its noise sensitivity. This is followed by the integration of contrastive and transfer learning within the quantum domain, enabling efficient training of substitute QNNs using a limited but cleaned set of queried data. Experimental results on NISQ computers demonstrate that a practical implementation of CopyQNN significantly outperforms state-of-the-art QNN extraction attacks, achieving an average performance improvement of 8.73% across all tasks while reducing the number of required queries by 90x, with only a modest increase in hardware overhead.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。