arXiv:2504.17690quant-phcs.LG2025-04被引 1

研究对抗训练下量子分类器的泛化能力,发现高维输入可消除额外样本开销。

On the Generalization of Adversarially Trained Quantum Classifiers

  • 通过约束扰动的对抗训练,建立泛化误差上界。
  • 高维经典输入下,对抗训练不增加样本复杂度,误差随√m衰减。
  • 适合关注量子机器学习安全性的研究者,尤其在对抗攻击场景中。

量子分类器易受针对输入经典或量子数据的对抗攻击。一种有效防御方法是使用对抗损失函数进行对抗训练。本文建立了在受限扰动对抗者存在下,对抗训练量子分类器的泛化误差新边界。该边界表明,为保证鲁棒性而产生的额外泛化误差随训练样本数 $m$ 以 $1/\ ext{sqrt}{m}$ 的速度衰减,并揭示了量子编码方式的影响。对于采用旋转编码的二分类量子分类器,当对手攻击经典输入 $\mathbf{x}$ 时,在高维输入极限下,对抗训练相对于常规训练的样本复杂度增加趋于消失;而当对手直接攻击编码输入 $\mathbf{x}$ 的量子态 $ρ(\mathbf{x})$ 时,额外泛化误差仅依赖于编码的希尔伯特空间维度。结果还扩展至多分类情形。数值实验验证了理论结论。

原文摘要 · Abstract (English)

Quantum classifiers are vulnerable to adversarial attacks that manipulate their input classical or quantum data. A promising countermeasure is adversarial training, where quantum classifiers are trained by using an attack-aware, adversarial loss function. This work establishes novel bounds on the generalization error of adversarially trained quantum classifiers when tested in the presence of perturbation-constrained adversaries. The bounds quantify the excess generalization error incurred to ensure robustness to adversarial attacks as scaling with the training sample size $m$ as $1/\sqrt{m}$, while yielding insights into the impact of the quantum embedding. For quantum binary classifiers employing \textit{rotation embedding}, we find that, in the presence of adversarial attacks on classical inputs $\mathbf{x}$, the increase in sample complexity due to adversarial training over conventional training vanishes in the limit of high dimensional inputs $\mathbf{x}$. In contrast, when the adversary can directly attack the quantum state $ρ(\mathbf{x})$ encoding the input $\mathbf{x}$, the excess generalization error depends on the choice of embedding only through its Hilbert space dimension. The results are also extended to multi-class classifiers. We validate our theoretical findings with numerical experiments.

量子机器学习对抗训练泛化误差安全分类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。