Skip to main content
QUICK REVIEW

[論文レビュー] Enhancing Quantum Adversarial Robustness by Randomized Encodings

Weiyuan Gong, Dong Yuan|arXiv (Cornell University)|Dec 5, 2022
Advancements in Semiconductor Devices and Circuit Design被引用数 5
ひとこと要約

本稿では、ランダムなユニタリ変換または量子誤り訂正(QEC)エンコーダーを用いて、量子分類器に対する敵対的攻撃に対する防御戦略を提案する。ランダムユニタリエンコーダーは、敵対的変分量子回路においてバーレンプレート(barren plateaus)を誘発し、敵対的摂動を指数関数的に抑制することを証明している。一方、連結QECエンコーダーは、量子微分プライバシーを向上させることで耐性を強化し、O(log log n) の誤り訂正レベルで十分であり、敵対的リスクを指数関数的に抑制する。

ABSTRACT

The interplay between quantum physics and machine learning gives rise to the emergent frontier of quantum machine learning, where advanced quantum learning models may outperform their classical counterparts in solving certain challenging problems. However, quantum learning systems are vulnerable to adversarial attacks: adding tiny carefully-crafted perturbations on legitimate input samples can cause misclassifications. To address this issue, we propose a general scheme to protect quantum learning systems from adversarial attacks by randomly encoding the legitimate data samples through unitary or quantum error correction encoders. In particular, we rigorously prove that both global and local random unitary encoders lead to exponentially vanishing gradients (i.e. barren plateaus) for any variational quantum circuits that aim to add adversarial perturbations, independent of the input data and the inner structures of adversarial circuits and quantum classifiers. In addition, we prove a rigorous bound on the vulnerability of quantum classifiers under local unitary adversarial attacks. We show that random black-box quantum error correction encoders can protect quantum classifiers against local adversarial noises and their robustness increases as we concatenate error correction codes. To quantify the robustness enhancement, we adapt quantum differential privacy as a measure of the prediction stability for quantum classifiers. Our results establish versatile defense strategies for quantum classifiers against adversarial perturbations, which provide valuable guidance to enhance the reliability and security for both near-term and future quantum learning technologies.

研究の動機と目的

  • 近い将来のNISQデバイスにおける量子分類器の脆弱性に対処すること。
  • 量子機械学習における敵対的摂動に対して一般的かつ証明可能な安全な防御機構を構築すること。
  • 予測の安定性を測る指標として量子微分プライバシー(QDP)を用いて耐性を定量化すること。
  • ランダムユニタリエンコーダーとブラックボックス量子誤り訂正(QEC)エンコーダーの両方が敵対的リスクを抑制する効果を調査すること。
  • 局所ユニタリおよび一般敵対的ノイズモデル下での敵対的耐性の理論的境界を確立すること。

提案手法

  • 入力データを分類の前に、2-デザインを形成するランダムユニタリエンコーダーで符号化し、敵対的最適化を妨害する。
  • このようなエンコーダーが、入力や回路構造に依存せず、いかなる敵対的変分量子回路においても指数関数的に消滅する勾配(バーレンプレート)を誘発することを証明する。
  • 予測の安定性を測るため、量子微分プライバシー(QDP)を用い、ε-QDPを形式的な耐性指標として用いる。
  • 局所敵対的ノイズを緩和するために、連結量子誤り訂正(QEC)コードをブラックボックスエンコーダーとして適用する。
  • 敵対的攻撃下の分類器に対して、O(log log n) のQECレベルで十分にε(O(1/√n))-QDPを達成できることを示す境界を導出する。
  • NISQデバイス上で有効であることを検証するため、クラスタードイジングハミルトニアンのトポロジカル相を分類する数値シミュレーションを実施する。

実験結果

リサーチクエスチョン

  • RQ1ランダムユニタリエンコーダーは、変分量子回路における敵対的摂動を普遍的に抑制できるか?
  • RQ2局所ユニタリ攻撃下での量子分類器の敵対的リスクに理論的境界は存在するか?
  • RQ3ブラックボックス量子誤り訂正エンコーダーは、局所敵対的ノイズに対して耐性を高められるか?
  • RQ4量子分類器が敵対的攻撃下でε(O(1/√n))-QDPを達成するためには、何レベルのQECが必要か?
  • RQ5提案された防御戦略は、最悪の敵対的ノイズ下でも有効であり、NISQデバイス上で実行可能か?

主な発見

  • 2-デザインを形成するランダムユニタリエンコーダーは、敵対的変分量子回路において指数関数的に消滅する勾配(バーレンプレート)を誘発し、効果的な敵対的攻撃の生成を防ぐ。
  • 局所ユニタリ攻撃下の量子分類器の敵対的リスクは有界であり、十分なランダム符号化により、その境界を任意に小さくできる。
  • ブラックボックス量子誤り訂正エンコーダーは、量子微分プライバシーを向上させることで敵対的リスクを低減し、符号の連結により耐性が向上する。
  • 量子分類器が敵対的攻撃下でε(O(1/√n))-QDPを保証するためには、O(log log n) のQECレベルで十分であり、高確率での耐性が保証される。
  • 数値シミュレーションにより、NISQデバイス上でクラスタードイジングハミルトニアンのトポロジカル相を分類するというアプローチの実行可能性と有効性が確認された。
  • 提案された防御は一般性があり、近い将来のNISQシステムおよび将来のフェイルセーフ量子学習システムに適用可能であり、強い理論的保証を提供する。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。