arXiv:2606.24219cs.CLcs.CR2026-06

量子神经网络用噪声提升抗攻击能力,理论证明其稳定性机制。

Decoherence as Defence and the Magnitude of Noise Regularisation: A Rigorous N -Qubit Theory of Stochastic Quantum Neural Networks for Adversarially Robust Network Intrusion Detection

论文配图:Decoherence as Defence and the Magnitude of Noise Regularisation: A Rigorous N -Qubit Theory of Stochastic Quantum Neural Networks for Adversarially Robust Network Intrusion Detection
图 1 · 摘自论文原文
  • 用李维拉方程建模量子神经网络噪声,推导出退相干收缩定理。
  • 在真实入侵检测数据上,噪声模型比无噪声模型更稳定,鲁棒性提升显著。
  • 首次实现中性原子硬件验证,为量子安全检测提供可扩展方案。

随机量子神经网络(SQNN)将神经激活编码为量子比特,突触结构表示为纠缠,通过林德布拉德主方程模拟神经噪声。近期研究发现环形纠缠对非局域异常检测至关重要,但对抗鲁棒性边界保守,且去极化通道无法作为类似丢弃的正则化器,反而表现为输出噪声。本文解决了两个关键问题:提出每门随机失活(真正量子丢弃)可实现有效正则化,并建立了可预测的鲁棒性理论。我们给出了基于随机主方程与向量化李维拉算符的N量子比特形式,证明退相干收缩定理:强度为γ的去极化通道经L个纠缠层作用,权重为w的泡利读出被压缩至(1-4γ/3)^{wL}(此处权重1时为(1-4γ/3)^{L})。在真实NSL-KDD数据集上,白盒FGSM和PGD攻击下,使用去极化通道训练的SQNN在七次种子实验中显著优于无噪声电路(ℓ∞ PGD-20,p=0.04,效应量大),且从未出现无噪声模型和梯度训练经典检测器(从95%降至47%)的灾难性鲁棒性崩溃,鲁棒性方差减少约两倍;该鲁棒性源于噪声重塑的训练边界而非攻击时梯度收缩。进一步推导出自适应惩罚公式,表明每门丢弃等价于权重空间的曲率加权L₂正则项,最大值出现在p=1/2,而去极化噪声则对应输出空间惩罚。30次种子实验验证了该公式:两者均小幅但显著降低训练-测试差距(≈0.01;p<10⁻⁴ 和 p=0.004),统计上无差异,且效果集中在过拟合最严重区域;提高丢弃率超过1/2无效,符合预测。先前单次种子的二分结果不具可重复性。最后展示中性原子实现与按N可行性分析。

原文摘要 · Abstract (English)

Stochastic quantum neural networks (SQNNs) encode neuronal activations as qubits, synaptic topology as entanglement, and neural noise through a Lindblad master equation. A recent conference study applied a ring-entangled SQNN to collaborative intrusion detection and reached three conclusions: ring entanglement is \emph{essential} for non-local anomaly detection; an adversarial-resilience bound holds but is \emph{conservative}; and the depolarising channel \emph{fails} to act as a dropout-style regulariser, behaving instead as output noise. It left open whether a per-gate stochastic deactivation (``true quantum dropout'') could regularise where the depolarising channel could not, and whether the loose robustness bound could be replaced by a predictive theory. This paper resolves both and extends the framework to real data and to neutral-atom hardware. We give an $N$-qubit formulation through the stochastic master equation and its vectorised Liouvillian, and prove a \emph{decoherence-contraction theorem}: a depolarising channel of strength $γ$ over $L$ entangling layers contracts every weight-$w$ Pauli read-out by a factor $(1-4γ/3)^{wL}$ (for the weight-$1$ read-out used here, $(1-4γ/3)^{L}$); building on the general noise-as-defence result of Du et al., we make this quantitative and operational for intrusion detection. On the real NSL-KDD dataset under white-box FGSM and PGD attacks, a depolarising SQNN trained with the channel is, over seven seeds under strong $\ell_\infty$/$\ell_2$ attacks, significantly more robust than the noiseless circuit ($\ell_\infty$ PGD-$20$, $p=0.04$, large effect) and, critically, never suffers the catastrophic robustness collapse that the noiseless model and gradient-trained classical detectors (which fall from $95\%$ to $47\%$) do, cutting robustness variance roughly twofold; we show this robustness arises from a noise-reshaped training boundary rather than from attack-time gradient contraction. For generalisation, we derive an adaptive-penalty formula showing that per-gate dropout implements a curvature-weighted $L_2$ penalty $\tfrac{p(1-p)}{2}\sumθ^2\partial^2_θL$ in weight space, maximised at $p=1/2$, whereas depolarising noise implements an output-space penalty. A $30$-seed study confirms the formula's quantitative prediction: both mechanisms reduce the train-test gap by a small but statistically significant margin ($\approx\!0.01$; $p<10^{-4}$ and $p=0.004$), are statistically indistinguishable from each other, and the effect is concentrated where overfitting is largest; increasing the dropout rate past $1/2$ does not help, as the formula predicts. The single-seed dichotomy of prior work does not survive replication. We close with a neutral-atom realisation and a feasibility-by-$N$ analysis.

量子神经网络抗攻击噪声正则化入侵检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。