量子分类器的梯度攻击成本随输入维度飙升,测量噪声成天然防御。
When cheap gradients fail: the measurement cost of attacking quantum classifiers
- 通过重复测量估算梯度,导致攻击者需消耗大量计算资源。
- 攻击所需测量次数随维度呈d^{5/2}增长,深度电路中更达d^{3.00}。
- 适用于高维量子模型,尤其在经典难模拟时防御更强。
对抗性扰动威胁机器学习分类器,包括变分量子分类器。我们发现有限量子测量统计(测量噪声)作为内置防御,使基于梯度的测试时攻击对攻击者成本极高。由于每个梯度分量必须在无偏梯度估计规则下通过重复电路执行推断,白盒提取需依赖维度相关的测量预算,测量分组无法消除表达性强的电路中的此开销。在给定假设下,单步攻击至少需二次方量级的测量次数,输入维度为$d$时,按范数集中缩放,其值增长为$d^{5/2}$;通过随机梯度朗之万动力学分析迭代攻击的充分预算。模拟结果涵盖至784维输入:实际总预算达到 $d^{5/2}$ 的几何下限,对于平台缓解模型,而测试的深度电路则以 $d^{3.00}$ 增长,因其梯度范数在未缓解空洞平台情况下随维度衰减;将测量梯度范数反向折叠后恢复出无参数的 $d^{3/2}$ 测量噪声几何结构。与攻击开销与维度无关的经典基准相比(自动微分的廉价梯度原则),量子梯度成本比在实测中增长为 $d^{3.00}$,攻击相对成本随模型规模发散。在156量子比特的IBM处理器(ibm_boston,4量子比特电路,$d=12$)上的实验重现该效应:在匹配预算下,设备攻击与理想情况偏差仅几近百分比,高测量次数梯度忠实于精确梯度。该防御仅在前向映射经典难以模拟时生效:此时白盒攻击者无法使用‘模拟-反向传播’捷径,必须支付我们量化出的测量成本。
原文摘要 · Abstract (English)
Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers. We show that finite quantum measurement statistics (shot noise) act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker. Because every gradient component must be inferred from repeated circuit executions under any unbiased gradient-estimation rule, white-box extraction consumes a dimension-dependent measurement budget that measurement grouping cannot remove in expressive circuits. Under stated assumptions, single-step attacks need at least quadratically many shots in the input dimension $d$, growing as $d^{5/2}$ under norm-concentration scaling, with a sufficient-budget analysis for iterative attacks via stochastic gradient Langevin dynamics. Simulations up to 784 input dimensions validate the law: the realized total budget is the $d^{5/2}$ geometric floor for plateau-mitigated models and grows as $d^{3.00}$ for the tested deep circuits, whose gradient norms decay with dimension absent barren-plateau mitigation; folding the measured gradient norm back in recovers the parameter-free $d^{3/2}$ shot-noise geometry. Against a matched classical baseline whose attack overhead is dimension-independent (the cheap-gradient principle of automatic differentiation), the quantum gradient cost ratio grows empirically as $d^{3.00}$, so the attacker's relative cost diverges as the model scales. Experiments on a 156-qubit IBM processor (ibm_boston, 4-qubit circuits, $d=12$) reproduce the effect: at matched budgets the device attack tracks the ideal within a few percent, with the high-shot gradient faithful to the exact one. The defense operates precisely when the forward map is classically hard to simulate: only then is a white-box attacker denied the simulate-and-backpropagate shortcut and must pay the measurement cost we quantify.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。