[论文解读] Hybrid Classical-Quantum Deep Learning Models for Autonomous Vehicle Traffic Image Classification Under Adversarial Attack
本文提出了一种用于自动驾驶车辆交通标志分类的混合经典-量子深度学习模型,可增强对对抗性攻击的鲁棒性。通过结合预训练的ResNet18主干网络与利用叠加和纠缠特性的量子神经网络,该模型在白盒对抗性攻击下实现了更高的准确率和更强的抗干扰能力,尤其在训练数据有限的情况下表现更优。
Image classification must work for autonomous vehicles (AV) operating on public roads, and actions performed based on image misclassification can have serious consequences. Traffic sign images can be misclassified by an adversarial attack on machine learning models used by AVs for traffic sign recognition. To make classification models resilient against adversarial attacks, we used a hybrid deep-learning model with both the quantum and classical layers. Our goal is to study the hybrid deep-learning architecture for classical-quantum transfer learning models to support the current era of intermediate-scale quantum technology. We have evaluated the impacts of various white box adversarial attacks on these hybrid models. The classical part of hybrid models includes a convolution network from the pre-trained Resnet18 model, which extracts informative features from a high dimensional LISA traffic sign image dataset. The output from the classical processor is processed further through the quantum layer, which is composed of various quantum gates and provides support to various quantum mechanical features like entanglement and superposition. We have tested multiple combinations of quantum circuits to provide better classification accuracy with decreasing training data and found better resiliency for our hybrid classical-quantum deep learning model during attacks compared to the classical-only machine learning models.
研究动机与目标
- 开发一种对自动驾驶车辆感知系统中的对抗性攻击具有鲁棒性的混合经典-量子深度学习架构。
- 评估量子增强模型在交通标志数据集上各种白盒对抗性攻击场景下的性能表现。
- 研究在减少训练数据条件下,与纯经典模型相比,混合模型在鲁棒性和准确率方面的表现差异。
- 探究量子力学特性(如纠缠和叠加)在提升分类鲁棒性方面的角色。
- 实现在中等规模量子硬件上部署量子机器学习的可行性,以支持真实世界自动驾驶车辆应用。
提出的方法
- 使用预训练的ResNet18模型作为高维LISA交通标志图像的经典特征提取器。
- 将ResNet18输出的特征输入由单量子比特和双量子比特门组成的参数化量子电路。
- 量子层利用叠加和纠缠等量子力学原理,以增强特征表示能力。
- 采用迁移学习方法训练混合模型,通过经典优化方法微调量子电路参数。
- 测试多种量子电路架构,以识别在对抗攻击下能最大化准确率和鲁棒性的配置。
- 在白盒设置下施加对抗性攻击以评估模型鲁棒性,并与纯经典模型进行性能对比。
实验结果
研究问题
- RQ1与经典模型相比,混合经典-量子深度学习模型在交通标志分类中如何提升对抗性鲁棒性?
- RQ2训练数据量的变化对量子增强模型的性能和鲁棒性有何影响?
- RQ3哪些量子电路配置能在对抗攻击下实现最高的分类准确率和鲁棒性?
- RQ4纠缠和叠加等量子特性在提升模型鲁棒性方面发挥了多大程度的作用?
- RQ5在有限数据上训练的混合模型是否能在自动驾驶车辆系统的真实对抗性环境中保持高性能?
主要发现
- 与纯经典模型相比,混合经典-量子模型在LISA交通标志数据集上对白盒对抗性攻击表现出更优的鲁棒性。
- 在对抗性扰动下,该模型保持了更高的分类准确率,尤其是在训练数据减少时,表明其泛化能力更强。
- 经过优化纠缠结构和门序列的特定量子电路配置,在鲁棒性和准确率方面均表现出可测量的提升。
- 量子层的引入增强了特征表示,使模型在对抗性噪声下具备更强的判别能力。
- 该模型在多种攻击类型下表现稳定,证实其在安全关键型自动驾驶车辆系统中具备部署潜力。
- 结果表明,量子机器学习组件可有效补充经典深度学习,在资源受限的真实环境中发挥作用。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。