用量子电路增强神经网络抗攻击能力,提升安全关键场景可靠性。
QShield: Securing Neural Networks Against Adversarial Attacks using Quantum Circuits

- 将经典CNN与量子模块结合,通过量子纠缠编码特征并融合预测。
- 在多个数据集上显著降低攻击成功率,且保持高准确率。
- 适合关注模型安全性、需抵御对抗攻击的工业级应用开发者。
深度神经网络仍易受对抗扰动影响,限制其在安全与安全关键场景中的可靠性。为此,我们提出QShield,一种模块化混合量子-经典神经网络(HQCNN)架构,旨在提升经典深度学习模型的对抗鲁棒性。QShield将传统卷积神经网络(CNN)作为特征提取主干,结合量子处理模块,将提取特征编码为量子态,在真实噪声模型下施加结构化纠缠操作,并通过轻量级多层感知机(MLP)实现动态加权融合,输出混合预测结果。我们在MNIST、OrganAMNIST和CIFAR-10数据集上系统评估了经典与混合量子-经典模型,涵盖鲁棒性、效率与计算性能指标。结果表明,经典模型对对抗攻击高度脆弱,而引入纠缠模式的混合模型在多种攻击下仍保持高预测准确率并显著降低攻击成功率。此外,该架构大幅增加生成对抗样本的计算成本,形成额外防御层。这些发现表明,所提出的模块化混合架构在预测精度与对抗鲁棒性之间实现了实用平衡,为敏感及安全关键场景下的可靠机器学习提供了有前景的解决方案。
原文摘要 · Abstract (English)
Deep neural networks remain highly vulnerable to adversarial perturbations, limiting their reliability in security- and safety-critical applications. To address this challenge, we introduce QShield, a modular hybrid quantum-classical neural network (HQCNN) architecture designed to enhance the adversarial robustness of classical deep learning models. QShield integrates a conventional convolutional neural network (CNN) backbone for feature extraction with a quantum processing module that encodes the extracted features into quantum states, applies structured entanglement operations under realistic noise models, and outputs a hybrid prediction through a dynamically weighted fusion mechanism implemented via a lightweight multilayer perceptron (MLP). We systematically evaluate both classical and hybrid quantum-classical models on the MNIST, OrganAMNIST, and CIFAR-10 datasets, using a comprehensive set of robustness, efficiency, and computational performance metrics. Our results demonstrate that classical models are highly vulnerable to adversarial attacks, whereas the proposed hybrid models with entanglement patterns maintain high predictive accuracy while substantially reducing attack success rates across a wide range of adversarial attacks. Furthermore, the proposed hybrid architecture significantly increased the computational cost required to generate adversarial examples, thereby introducing an additional layer of defense. These findings indicate that the proposed modular hybrid architecture achieves a practical balance between predictive accuracy and adversarial robustness, positioning it as a promising approach for secure and reliable machine learning in sensitive and safety-critical applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。