arXiv:2607.05281quant-phcs.LG2026-07

量子云服务中,硬件指纹可暴露后台身份,本文首次建立隐私保护框架。

Routing Anonymity and Identifiability of Noisy Quantum Hardware

  • 提出后端可识别性游戏,将路由匿名性定义为安全标准
  • 实验显示超导与离子阱设备识别率高达96%-100%
  • 揭示噪声硬件下指纹为中等深度现象,适用于安全与效用权衡

当前量子计算多为云端服务,用户提交电路至服务商的私有硬件。尽管服务商可能希望隐藏实现细节、调度策略或具体物理设备,但噪声有限采样输出会携带后端特异性指纹——经典输出分布中印刻的、可揭示后端身份的信息。现有研究多从基准测试角度分析此类指纹,较少关注用户与服务商的隐私问题。本文首次建立后端可识别性的正式框架,引入后端可识别性博弈,形式化路由匿名性作为量子云服务的安全概念。证明在被动独立同分布访问单一后端时,路由匿名性以切尔诺夫速率指数衰减。同时建立效用-匿名性权衡,表明移除后端信息会损害输出实用性。进一步发现,对噪声量子硬件而言,指纹识别本质是中等深度现象,利用泡利转移矩阵工具确立深度原则。在AWS Amazon Braket上对离子阱与超导处理器的实验显示,超导后端分类准确率达87%-90%,跨平台分类达96%-100%,且识别能力可抵御自然后处理。结果确立路由匿名性为量子云计算的独立安全需求,并提供量化与控制效用-匿名性权衡的框架。

原文摘要 · Abstract (English)

Present-day quantum computing is cloud-based, where a user submits a circuit to a service provider's proprietary backend hardware. While providers may wish to hide implementation details, scheduling choices, or even which physical device was used, noisy finite-shot outputs can carry backend-specific fingerprints: information imprinted in the classical output distribution that can reveal the backend identity. So far, such fingerprints have mostly been studied from a benchmarking perspective, with limited attention to privacy considerations for users and providers. This work develops the first formal framework for backend identifiability and its privacy implications. We introduce a backend-identifiability game and use it to formalise routing anonymity as a security notion for quantum cloud services. We show that backend identifiability is a hypothesis-testing problem and prove that, under passive i.i.d. access to a single backend, routing anonymity decays exponentially at the Chernoff rate. We also establish a utility-anonymity trade-off, imposing fundamental limits on how much backend-specific information can be removed from classical outputs without degrading their usefulness. In addition, we observe that, for noisy quantum hardware, identifying fingerprints are inherently an intermediate-depth phenomenon, and establish a depth principle using Pauli-transfer-matrix tools. We complement the theory with experiments on Amazon Braket on AWS, using ion-trap and superconducting quantum processors. We observe 87-90% classification between superconducting backends and 96-100% classification across physical platforms, and find that identifiability can survive natural forms of post-processing. Overall, these results establish routing anonymity as a distinct security requirement for quantum cloud computing, and provide a framework for quantifying and controlling the utility-anonymity trade-off.

量子云隐私保护硬件指纹安全框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。