arXiv:2602.01177quant-phcs.IT2026-02

量子学习中隐私与泛化能力直接相关,可借由信息论框架严格证明。

Privacy Implies Stability: Information-Theoretic Generalization Bounds for Quantum Learning

  • 用量子仪器建模学习过程,通过信息稳定性控制泛化误差。
  • 在可信处理器下,量子差分隐私可直接保证泛化性能。
  • 提出信息可接受性条件,揭示量子模型中隐私与信息利用的兼容性。

我们构建了一个信息论框架,将量子学习算法的稳定性、隐私性与泛化能力联系起来。学习过程被建模为具有经典-量子输出的量子仪器,损失由可观测量表示。在经典-量子次高斯条件下,信息论意义上的稳定性度量控制了期望泛化误差。此外,利用量子Rényi散度处理非对易性下的高阶依赖关系,建立了高概率泛化界。在可信数据处理者场景中,量子差分隐私(QDP)提供了稳定性机制,且单邻域QDP严格限制了经典-量子输出泄露的信息。结合稳定性定理,直接获得隐私到泛化的保证。在不可信数据处理者场景中,仅输出隐私不足,因恶意处理器可在加噪前执行高度信息性操作。为此引入信息论可接受性(ITA),确保所采用程序并非更信息丰富的物理允许操作的降级版本。我们证明:尽管经典模型中可接受性与隐私存在强矛盾,但量子非正交性使其兼容——量子测量可实现ITA(完全获取可访问信息),却无需完美恢复原始数据集。通过具体例子展示了这一分离。

原文摘要 · Abstract (English)

We develop an information-theoretic framework connecting stability, privacy, and generalization for quantum learning algorithms. Learning procedures are modeled as quantum instruments with classical-quantum outputs, and losses are represented by observables. We prove that under a classical-quantum sub-Gaussian condition, an information-theoretic stability measure controls the expected generalization error. Furthermore, we establish a high-probability generalization bound using quantum Rényi divergences to manage higher-order dependencies under non-commutativity. In the trusted Data Processor setting, quantum differential privacy (QDP) provides a mechanism for stability. We show that one-neighbor QDP strictly bounds the information leaked by the classical-quantum output. Combining this with our stability theorem yields a direct privacy-to-generalization guarantee. We also explore an untrusted Data Processor setting. Here, output privacy alone is insufficient since an adversarial processor could perform a highly informative procedure before applying noisy post-processing. To combat this, we introduce Information-Theoretic Admissibility (ITA), a certification condition ensuring the prescribed procedure is not just a degraded version of a strictly more informative, physically allowed operation on the encoded ensemble. We prove a fundamental separation: while admissibility and privacy are in strong tension in classical models, quantum non-orthogonality makes them compatible. A quantum measurement can be ITA - exhausting all relevant accessible information - without perfectly recovering the classical dataset. We illustrate this separation through a concrete quantum ITA example.

量子学习隐私保护泛化边界信息论

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。