arXiv:2512.14388cs.LG2025-12

用量子幽灵态检测量子模型隐私泄露,实现可验证的隐私审计。

Black-Box Auditing of Quantum Model: Lifted Differential Privacy with Quantum Canaries

  • 引入量子幽灵态作为探测信号,通过偏移编码感知记忆痕迹。
  • 建立偏移量与迹距离的数学关系,实测推导隐私预算下限。
  • 首次实现对部署中量子模型的黑箱隐私审计,适用于真实硬件。

量子机器学习(QML)虽具显著计算优势,但训练敏感数据时可能记忆个体记录,造成严重隐私风险。现有量子差分隐私(QDP)机制仅提供理论最坏情况保障,缺乏对已部署模型的实证验证工具。本文提出首个基于提升型量子差分隐私的黑箱隐私审计框架,利用量子幽灵态(即策略性偏移编码的量子态)检测记忆现象并精确量化训练过程中的隐私泄露。框架建立了幽灵态偏移量与迹距离上界间的严格数学联系,推导出隐私预算消耗的实证下界,弥合了理论保证与实际隐私验证之间的关键鸿沟。在模拟及真实量子硬件上的全面评估表明,该框架能有效测量QML模型的实际隐私损失,为量子系统提供稳健的隐私验证能力。

原文摘要 · Abstract (English)

Quantum machine learning (QML) promises significant computational advantages, yet models trained on sensitive data risk memorizing individual records, creating serious privacy vulnerabilities. While Quantum Differential Privacy (QDP) mechanisms provide theoretical worst-case guarantees, they critically lack empirical verification tools for deployed models. We introduce the first black-box privacy auditing framework for QML based on Lifted Quantum Differential Privacy, leveraging quantum canaries (strategically offset-encoded quantum states) to detect memorization and precisely quantify privacy leakage during training. Our framework establishes a rigorous mathematical connection between canary offset and trace distance bounds, deriving empirical lower bounds on privacy budget consumption that bridge the critical gap between theoretical guarantees and practical privacy verification. Comprehensive evaluations across both simulated and physical quantum hardware demonstrate our framework's effectiveness in measuring actual privacy loss in QML models, enabling robust privacy verification in QML systems.

量子隐私差分隐私模型审计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。