arXiv:2605.25066quant-phcs.CR2026-05

为量子机器学习管道设计了防漂移的运行时指纹验证框架

QML-PipeGuard: Drift-Aware Behavioral Fingerprinting for Quantum Machine Learning Pipeline Integrity

论文配图:QML-PipeGuard: Drift-Aware Behavioral Fingerprinting for Quantum Machine Learning Pipeline Integrity
图 1 · 摘自论文原文
  • 通过可观测量期望值向量构建运行时行为指纹
  • 在1.4万次采样内检测到隐蔽通道替换,漂移在容忍范围内
  • 适合关注量子计算安全与可信部署的研究者

量子机器学习(QML)正从研究原型走向云服务部署。随着进入受监管行业,量子环节的完整性成为两大实际问题:校准间隔间通道层面的噪声硬件漂移,以及攻击者操控执行环境后替换为行为相似但数学不同的量子通道。现有工作未涵盖脉冲级噪声、输入漂移、抗扰动鲁棒性或设备身份验证。本文提出QML-PipeGuard,一种基于契约的统一框架,通过运行时行为指纹(在测控结构化测量族下的可观测量期望值向量)解决上述问题。该框架支持两种模式:容漂移监控(在标定容差内吸收正常校准变化),以及对抗检测(通过信息完备可观测量契约捕捉通道替换)。框架贡献包括针对编码-变分-测量通道的管道组合处理、针对单比特泡利族的紧框架边界C=√3的专用威胁模型、有限采样复杂度界,以及区分对抗性与自然漂移的容差分解。在IBM Heron r2处理器(ibm_fez)上的双量子比特QSVM流水线实现端到端验证,并在噪声匹配模拟器上完成采样复杂度验证。规定的测量预算约1.4×10⁴次采样可单批次完成,隐蔽通道被宽裕地检测到,而弱契约下仍可规避;典型硬件漂移则处于容忍范围之内。

原文摘要 · Abstract (English)

Quantum machine learning (QML) is moving from research prototypes to deployed cloud services. As QML enters regulated industries, the integrity of the quantum stage becomes a practical concern on two fronts: noisy hardware drifts at the channel level between recalibrations, and an adversary with control over the execution environment can substitute the declared quantum channel with a behaviorally similar but mathematically distinct one. Neither concern is covered by existing QML verification work on pulse-level noise, input drift, input-perturbation robustness, or device identity. We introduce QML-PipeGuard, a contract-based framework addressing both concerns under a single mathematical machinery. It characterizes a QML pipeline at runtime by its behavioral fingerprint, the vector of observable expectation values under a tomographically structured measurement family, and operates in two modes: drift-aware monitoring that absorbs benign calibration changes within a calibrated tolerance, and adversarial detection that catches channel substitution as a violation of an informationally complete observable contract. The framework contributes a pipeline-composition treatment of the encoder-ansatz-measurement channel with a QML-specific threat model (tight frame-bound C=sqrt(3) for the single-qubit Pauli family), a finite-shot sample-complexity bound, and a tolerance decomposition separating adversarial and natural-drift contributions. We validate the framework end-to-end on a two-qubit QSVM pipeline on the IBM Heron r2 processor (ibm_fez), with a sample-complexity validation on a noise-matched simulator. The prescribed measurement budget (about 1.4e4 shots) fits in a single batched job, the sneaky channel is detected with a wide safety margin while evading the weak contract, and the typical hardware drift sits within tolerance.

量子机器学习安全验证漂移检测可信计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。