量子机器学习在入侵检测中真有优势吗?这项研究给出了公正的检验答案。
How Quantum Is the Advantage? A Fair, Calibration- and Noise-Aware Benchmark and Attribution Audit of Quantum Machine Learning for Network Intrusion Detection

- 构建统一基准,公平对比量子与经典模型在四大数据集上的表现。
- 发现多数量子优势实为经典预处理和正则化所致,仅两项结果经严格验证。
- 适合关注量子真实效能、追求可复现实验的科研人员参考。
量子机器学习(QML)在网络安全入侵检测(NIDS)中常宣称接近完美准确率,但最严谨的研究表明,经过良好调优的经典模型仍具竞争力,所谓量子优势可能源于经典降维与隐含正则化,并非真正的量子效应。本文不问量子模型能否高分,而是追问其优势是否真正‘量子’。我们提出一个统一、可复现的QML-NIDS基准,评估混合变分量子电路与量子核支持向量机,在四个标准数据集(NSL-KDD、UNSW-NB15、CICIDS2017、NF-ToN-IoT-v2)上与五种诚实调参的经典基线模型对比,采用统一预算特征视图、平衡性与校准感知指标、显著性检验及模拟NISQ噪声扰动。引入量子归因审计(参数匹配的经典对照、随机特征核、正则化扫描),量化实际由量子组件带来的增益。结果显示:调优后的经典模型(随机森林、XGBoost)在所有数据集上整体检测性能持平或超越量子模型;归因审计表明,此差距主要来自经典预处理与正则化。两项优势在错误发现率校正后仍成立:量子核SVM在AUPRC与ROC-AUC上优于其直接经典对应(随机特征核);一个小规模四量子比特混合模型在分布偏移的NSL-KDD任务中,于1%误报率下优于最优经典基线(p = 0.005,BH q = 0.030)。代码、种子与数据划分均已公开,无论量子胜败,本研究贡献恒存。
原文摘要 · Abstract (English)
Quantum machine learning (QML) for network intrusion detection (NIDS) is routinely reported to reach near-perfect accuracy, yet the most rigorous studies find that well-tuned classical models remain competitive, and that apparent quantum gains may be artefacts of classical dimensionality reduction and implicit regularisation rather than genuine quantum effects. We ask not whether a quantum model can post a high accuracy, but how quantum the advantage really is. We present a unified, reproducible QML-IDS benchmark evaluating hybrid variational quantum circuits and quantum-kernel SVMs against five honestly-tuned classical baselines across four standard NIDS datasets (NSL-KDD, UNSW-NB15, CICIDS2017, NF-ToN-IoT-v2) under one leakage-controlled protocol, with an equal-budget feature view, imbalance- and calibration-aware metrics with significance testing, and a simulated NISQ noise sweep. We introduce a quantum-attribution audit (parameter-matched classical controls, a random-feature kernel, and a regularisation sweep) that quantifies how much of any gain is genuinely attributable to the quantum component. Tuned classical models (Random Forest, XGBoost) match or exceed the quantum models on aggregate detection on every dataset, and the audit attributes this to classical preprocessing and regularisation rather than quantum effects. Two advantages survive false-discovery-rate correction: the quantum-kernel SVM out-ranks its direct classical surrogate (a random-feature kernel) on AUPRC and ROC-AUC, and a small four-qubit hybrid out-detects the best classical baseline at the 1% false-positive operating point on the distribution-shifted NSL-KDD task (p = 0.005, BH q = 0.030). Code, seeds, and splits are released; our contribution stands whether quantum wins, ties, or loses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。