arXiv:2607.11843quant-phcs.LG2026-07中稿 · the 2026 IEEE Inte…

首个针对量子神经网络的动态输入感知后门攻击,隐蔽性强且难防御。

Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

论文配图:Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks
图 1 · 摘自论文原文
  • 设计可随输入变化的动态触发器,避免固定模式暴露。
  • 在多个量子网络架构上实现90%以上干净准确率与攻击成功率。
  • 适合研究量子机器学习安全、对抗攻防的学者参考。

量子神经网络(QNN)是近中期量子设备上量子机器学习的有前景框架,但其安全风险尚未充分理解。研究表明QNN易受后门攻击,但现有量子后门多依赖所有中毒输入共享的固定触发器,这一设计缺陷易被防御机制检测或削弱。尽管经典神经网络中已有输入感知的动态后门,但将其迁移到QNN面临新挑战:测量将后线路态压缩为有限经典输出,削弱对触发器生成器的监督;同时,各密度矩阵随输入波动,导致逐样本对比学习不稳定。为此,我们提出Q-DIBA,首个面向QNN的输入感知动态后门攻击。Q-DIBA通过三模式小批量策略联合训练经典触发器生成器与受害QNN,支持正常行为、攻击激活与触发特异性。为提供稳定量子级监督,引入集成密度对比损失,作用于测量前的后线路态,对比模式平均密度矩阵而非单个样本。在MNIST与Fashion-MNIST数据集上,多种QNN架构的实验表明,Q-DIBA实现90%以上干净准确率、强攻击成功率及高跨触发准确率,验证了其有效性、隐蔽性与输入特异性。该攻击对视觉检查、谱特征检测和微调等防御仍具鲁棒性,表明输入感知量子后门是安全部署QNN的重要威胁。

原文摘要 · Abstract (English)

Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Studies have shown that QNNs are vulnerable to backdoor attacks, yet existing quantum backdoors mostly rely on a fixed trigger shared by all poisoned inputs. This fixed-trigger design is a major weakness because many defenses detect or weaken the repeated patterns such triggers leave in data representations. Although input-aware dynamic backdoors have been studied in classical neural networks, transferring them to QNNs is difficult because quantum learning introduces new obstacles. In particular, measurement compresses the post-ansatz quantum state into a limited classical output, weakening supervision for a trigger generator, while individual density matrices fluctuate with the input and make per-sample contrastive learning unstable. To address these challenges, we propose Q-DIBA, the first input-aware dynamic backdoor attack for QNNs. Q-DIBA jointly trains a classical trigger generator and a victim QNN through a three-mode mini-batch strategy that supports clean behavior, attack activation, and trigger specificity. To provide stable quantum-level supervision, Q-DIBA introduces an ensemble density contrastive loss that operates on post-ansatz quantum states before measurement and contrasts mode-averaged density matrices rather than individual samples. Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, demonstrating effectiveness, stealthiness, and input specificity. The attack also remains resilient against defenses including visual inspection, spectral-signature detection, and fine-tuning, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.

量子安全后门攻击动态触发机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。