Skip to main content
QUICK REVIEW

[论文解读] Qubit Sensing: A New Attack Model for Multi-programming Quantum Computing

Abdullah Ash Saki, Swaroop Ghosh|arXiv (Cornell University)|Apr 13, 2021
Quantum Computing Algorithms and Architecture参考文献 3被引用 8
一句话总结

本文提出了一种新型的量子计算侧信道攻击——量子比特感应(qubit sensing),在多任务调度的量子计算环境中,攻击者通过利用跨量子比特的状态依赖性与相关读出错误,推断出受害者量子计算的输出。通过使用Jensen-Shannon距离比较统计特征,该攻击在真实IBM量子硬件上实现了96%的准确率;作者进一步提出一种轻量级防护机制——随机化输出翻转,仅造成0.05%的保真度损失。

ABSTRACT

Noisy quantum computers suffer from readout or measurement error. It is a classical bit-flip error due to which state "1" is read out as "0" and vice-versa. The probability of readout error shows a state dependence i.e., flipping probability of state "1" may differ from flipping probability of state "0". Moreover, the probability shows correlation across qubits. These state-dependent and correlated error probability introduces a signature of victim outputs on adversary output when two programs are run simultaneously on the same quantum computer. This can be exploited to sense victim output which may contain sensitive information. In this paper, we systematically show that such readout error-dependent signatures exist and that an adversary can use such signature to infer a user output. We experimentally demonstrate the attack (inference) on 3 public IBM quantum computers. Using Jensen-Shannon Distance (JSD) a measure for statistical inference, we show that our approach identifies victim output with an accuracy of 96% on real hardware. We also present randomized output flipping as a lightweight yet effective countermeasure to thwart such information leakage attacks. Our analysis shows the countermeasure incurs a minor penalty of 0.05% in terms of fidelity.

研究动机与目标

  • 研究多任务调度量子计算环境中,状态依赖性与相关读出错误所引发的安全风险。
  • 证明攻击者可通过分析非相邻、孤立量子比特上的统计特征,推断出受害者量子输出。
  • 设计并评估一种低开销防护机制,可在保持保真度的同时抵御推断攻击。
  • 在真实IBM量子处理器上实验验证攻击与防护机制。

提出的方法

  • 通过在IBM量子设备上使用奇数和偶数个X门分别准备受害者量子比特为'0'和'1'态,收集参考读出特征。
  • 利用单个攻击者量子比特,通过末尾的X门制备为'1'态,通过相关读出错误感知受害者状态。
  • 通过计算未知攻击者输出分布与参考特征之间的Jensen-Shannon距离(JSD),对受害者输出进行分类。
  • 将攻击扩展至非相邻量子比特对,证明感应能力具有空间独立性。
  • 展示单个攻击者量子比特对多个受害者的感应能力,证明其可同时感知最多两个受害者量子比特。
  • 通过在计算后于受害者量子比特上插入X门实现随机化输出翻转,并通过后处理恢复正确输出。

实验结果

研究问题

  • RQ1在噪声中等规模量子(NISQ)设备中,能否利用读出错误推断多任务环境下的受害者量子输出?
  • RQ2状态依赖性与相关读出错误在多大程度上可实现对非相邻量子比特的统计推断?
  • RQ3单个攻击者量子比特能否感知多个受害者量子比特的输出?若能,最多可感知多少个?
  • RQ4此类推断攻击在真实量子硬件上的实际准确率如何?
  • RQ5随机化输出翻转作为防护机制,在安全性与保真度开销方面效果如何?

主要发现

  • 该攻击在三台真实IBM量子处理器上,通过Jensen-Shannon距离对受害者输出的分类准确率达到96%。
  • 即使攻击者与受害者量子比特在物理上非相邻,其读出错误特征对'0'和'1'态仍可清晰区分。
  • 单个攻击者量子比特可稳定感知最多两个受害者量子比特,但当感知三个或以上时,特征显著重叠,可行性降低。
  • 随机化输出翻转防护机制将推断准确率分别降低至1个受害者时的50%、2个受害者时的25%,显著提高攻击者逆向工程的成本。
  • 由于增加X门导致的保真度损失在所有测试设备上平均仅为0.05%,表明性能开销极低。
  • 攻击与防护机制已在IBM的ibmq_rome、ibmq_bogota和ibmq_valencia设备上通过200个随机基准电路实验验证。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。