arXiv:2604.28176quant-phcs.LG2026-04

用量子自编码器净化对抗样本,无需对抗训练即可提升量子分类器鲁棒性。

Defending Quantum Classifiers against Adversarial Perturbations through Quantum Autoencoders

论文配图:Defending Quantum Classifiers against Adversarial Perturbations through Quantum Autoencoders
图 1 · 摘自论文原文
  • 通过量子自编码器重构并净化受干扰的输入数据。
  • 在对抗攻击下预测准确率最高提升68%,优于现有方法。
  • 可识别难以净化的可疑样本,适合安全敏感场景使用。

机器学习模型能高效处理各类任务,但当输入数据被精心设计的噪声干扰时,可能导致错误判断。量子机器学习模型同样易受此类对抗攻击影响,尤其在变分量子分类器进行图像分类时更为明显。尽管已有防御方法(如对抗训练)有效,但存在实际限制:某些场景无法使用对抗样本训练,或会导致模型对特定攻击类型过拟合。本文提出一种无需对抗训练的防御框架,利用量子自编码器对对抗样本进行重建以实现净化。该框架还提供置信度度量,用于识别无法被净化的潜在对抗样本。大量实验表明,该方法在对抗攻击下的预测准确率显著优于现有最优方法,最高提升达68%。

原文摘要 · Abstract (English)

Machine learning models can learn from data samples to carry out various tasks efficiently. When data samples are adversarially manipulated, such as by insertion of carefully crafted noise, it can cause the model to make mistakes. Quantum machine learning models are also vulnerable to such adversarial attacks, especially in image classification using variational quantum classifiers. While there are promising defenses against these adversarial perturbations, such as training with adversarial samples, they face practical limitations. For example, they are not applicable in scenarios where training with adversarial samples is either not possible or can overfit the models on one type of attack. In this paper, we propose an adversarial training-free defense framework that utilizes a quantum autoencoder to purify the adversarial samples through reconstruction. Moreover, our defense framework provides a confidence metric to identify potentially adversarial samples that cannot be purified the quantum autoencoder. Extensive evaluation demonstrates that our defense framework can significantly outperform state-of-the-art in prediction accuracy (up to 68%) under adversarial attacks.

量子机器学习对抗防御自编码器

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。