arXiv:2508.20310quant-phcs.AI2025-08中稿 · 2025 IEEE Internat…被引 2

利用量子噪声实现联邦量子学习的差分隐私保护。

Differentially Private Federated Quantum Learning via Quantum Noise

  • 通过调节测量次数和退极化通道强度控制量子噪声以实现差分隐私。
  • 在保证隐私的前提下,训练准确率与攻击防御能力可调且表现稳定。
  • 特别适合对安全性要求高的当前噪声量子设备上的协同训练场景。

量子联邦学习(QFL)允许在不交换原始数据的情况下,跨分布式量子设备协作训练量子机器学习(QML)模型。然而,QFL仍易受对抗攻击,共享的QML模型更新可能被用于泄露信息隐私。在含噪中等规模量子(NISQ)设备背景下,核心问题是:如何利用固有的量子噪声来实现差分隐私(DP)并保护训练与通信过程中的模型信息?本文提出一种新型差分隐私机制,通过量子噪声保护整个QFL流程。通过调节测量次数和退极化通道强度来控制噪声方差,可实现适配于NISQ约束的指定隐私级别。模拟结果表明,该框架能有效分析差分隐私预算与噪声参数的关系,并在安全性和训练精度之间建立可调平衡。此外,评估显示该框架对基于对抗样本的攻击具有鲁棒性,关键指标包括对抗样本上的准确率、正确预测置信度及攻击成功率。结果揭示了隐私与鲁棒性之间的可调权衡,为在NISQ设备上实现安全的量子联邦学习提供了高效解决方案,具备可靠量子计算应用的显著潜力。

原文摘要 · Abstract (English)

Quantum federated learning (QFL) enables collaborative training of quantum machine learning (QML) models across distributed quantum devices without raw data exchange. However, QFL remains vulnerable to adversarial attacks, where shared QML model updates can be exploited to undermine information privacy. In the context of noisy intermediate-scale quantum (NISQ) devices, a key question arises: How can inherent quantum noise be leveraged to enforce differential privacy (DP) and protect model information during training and communication? This paper explores a novel DP mechanism that harnesses quantum noise to safeguard quantum models throughout the QFL process. By tuning noise variance through measurement shots and depolarizing channel strength, our approach achieves desired DP levels tailored to NISQ constraints. Simulations demonstrate the framework's effectiveness by examining the relationship between differential privacy budget and noise parameters, as well as the trade-off between security and training accuracy. Additionally, we demonstrate the framework's robustness against an adversarial attack designed to compromise model performance using adversarial examples, with evaluations based on critical metrics such as accuracy on adversarial examples, confidence scores for correct predictions, and attack success rates. The results reveal a tunable trade-off between privacy and robustness, providing an efficient solution for secure QFL on NISQ devices with significant potential for reliable quantum computing applications.

量子学习联邦学习差分隐私噪声处理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。