利用量子门特性设计隐蔽攻击,破坏量子神经网络准确率
Quantum Properties Trojans (QuPTs) for Attacking Quantum Neural Networks
- 基于量子门的酉性质和叠加态,构造新型量子后门
- 实验中使量子神经网络准确率下降23%且难以察觉
- 首个独立于经典-量子混合架构的全量子神经网络攻击
量子神经网络(QNN)在量子机器学习领域具有巨大潜力,但其安全性和鲁棒性仍鲜有研究。本文提出一种基于量子计算特性的新型后门攻击——量子属性后门(QuPTs),针对基于QNN的二分类器。该攻击利用量子门的酉性质引入噪声,并通过哈达玛门实现叠加态,从而植入后门并攻击QNN。实验表明,所提QuPTs具有极强隐蔽性,显著影响量子电路性能,最严重情况下导致受攻击的QNN准确率下降23%。据我们所知,这是首个针对完全量子神经网络的后门攻击,不依赖任何经典-量子混合架构。
原文摘要 · Abstract (English)
Quantum neural networks (QNN) hold immense potential for the future of quantum machine learning (QML). However, QNN security and robustness remain largely unexplored. In this work, we proposed novel Trojan attacks based on the quantum computing properties in a QNN-based binary classifier. Our proposed Quantum Properties Trojans (QuPTs) are based on the unitary property of quantum gates to insert noise and Hadamard gates to enable superposition to develop Trojans and attack QNNs. We showed that the proposed QuPTs are significantly stealthier and heavily impact the quantum circuits' performance, specifically QNNs. The most impactful QuPT caused a deterioration of 23% accuracy of the compromised QNN under the experimental setup. To the best of our knowledge, this is the first work on the Trojan attack on a fully quantum neural network independent of any hybrid classical-quantum architecture.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。