Predominant Aspects on Security for Quantum Machine Learning: Literature Review (2401.07774v3)
Abstract: Quantum Machine Learning (QML) has emerged as a promising intersection of quantum computing and classical machine learning, anticipated to drive breakthroughs in computational tasks. This paper discusses the question which security concerns and strengths are connected to QML by means of a systematic literature review. We categorize and review the security of QML models, their vulnerabilities inherent to quantum architectures, and the mitigation strategies proposed. The survey reveals that while QML possesses unique strengths, it also introduces novel attack vectors not seen in classical systems. We point out specific risks, such as cross-talk in superconducting systems and forced repeated shuttle operations in ion-trap systems, which threaten QML's reliability. However, approaches like adversarial training, quantum noise exploitation, and quantum differential privacy have shown potential in enhancing QML robustness. Our review discuss the need for continued and rigorous research to ensure the secure deployment of QML in real-world applications. This work serves as a foundational reference for researchers and practitioners aiming to navigate the security aspects of QML.
- Peter W Shor “Algorithms for quantum computation: discrete logarithms and factoring” In Proceedings 35th annual symposium on foundations of computer science, 1994, pp. 124–134 Ieee
- Lov K Grover “A fast quantum mechanical algorithm for database search” In Proceedings of the twenty-eighth annual ACM symposium on Theory of computing, 1996, pp. 212–219
- John Preskill “Quantum computing in the NISQ era and beyond” In Quantum 2 Verein zur Förderung des Open Access Publizierens in den Quantenwissenschaften, 2018, pp. 79
- Seth Lloyd, Masoud Mohseni and Patrick Rebentrost “Quantum principal component analysis” In Nature Physics 10.9 Nature Publishing Group UK London, 2014, pp. 631–633
- Maria Schuld, Ilya Sinayskiy and Francesco Petruccione “An introduction to quantum machine learning” In Contemporary Physics 56.2 Taylor & Francis, 2015, pp. 172–185
- “Quantum machine learning” In Nature 549.7671 Nature Publishing Group UK London, 2017, pp. 195–202
- Nathan Wiebe, Ashish Kapoor and Krysta M Svore “Quantum deep learning” In arXiv preprint arXiv:1412.3489, 2014
- “Quantum reinforcement learning” In IEEE Transactions on Systems, Man, and Cybernetics, Part B (Cybernetics) 38.5 IEEE, 2008, pp. 1207–1220
- “Security Aspects of Quantum Machine Learning: Opportunities, Threats and Defenses” In Proceedings of the Great Lakes Symposium on VLSI 2022, GLSVLSI ’22 Irvine, CA, USA: Association for Computing Machinery, 2022, pp. 463–468 DOI: 10.1145/3526241.3530833
- Michael A Nielsen and Isaac L Chuang “Quantum computation and quantum information” Cambridge University Press
- “Subexponential Factoring Algorithms” In Prime Numbers: A Computational Perspective New York, NY: Springer New York, 2001, pp. 227–283 DOI: 10.1007/978-1-4684-9316-0_6
- “Quantum supremacy using a programmable superconducting processor” In Nature 574.7779 Springer ScienceBusiness Media LLC, 2019, pp. 505–510 DOI: 10.1038/s41586-019-1666-5
- IBM Quantum “The IBM Quantum Development Roadmap”, 2022 URL: https://www.ibm.com/quantum/roadmap
- “Quantum generative adversarial networks” In Physical Review A 98.1 American Physical Society (APS), 2018 DOI: 10.1103/physreva.98.012324
- Sirui Lu, Lu-Ming Duan and Dong-Ling Deng “Quantum adversarial machine learning” In Physical Review Research 2.3 APS, 2020, pp. 033212
- “Tensor networks and efficient descriptions of classical data”, 2021 arXiv:2103.06872 [quant-ph]
- “Parameterized quantum circuits as machine learning models” In Quantum Science and Technology 4.4 IOP Publishing, 2019, pp. 043001 DOI: 10.1088/2058-9565/ab4eb5
- “Quantum Machine Learning in Feature Hilbert Spaces” In Physical Review Letters 122.4 American Physical Society (APS), 2019 DOI: 10.1103/physrevlett.122.040504
- “Supervised learning with quantum computers” Springer
- “Vulnerability of quantum classification to adversarial perturbations” In Physical Review A 101.6 APS, 2020, pp. 062331
- “Certified Robustness of Quantum Classifiers against Adversarial Examples through Quantum Noise”, 2023 arXiv:2211.00887 [quant-ph]
- “Robust in practice: Adversarial attacks on quantum machine learning” In Physical Review A 103.4 APS, 2021, pp. 042427
- “Experimental quantum adversarial learning with programmable superconducting qubits” In Nature Computational Science 2.11 Springer ScienceBusiness Media LLC, 2022, pp. 711–717 DOI: 10.1038/s43588-022-00351-9
- “The power of quantum neural networks” In Nature Computational Science 1.6 Springer ScienceBusiness Media LLC, 2021, pp. 403–409 DOI: 10.1038/s43588-021-00084-1
- Korn Sooksatra, Pablo Rivas and Javier Orduz “Evaluating accuracy and adversarial robustness of quanvolutional neural networks” In 2021 International Conference on Computational Science and Computational Intelligence (CSCI), 2021, pp. 152–157 IEEE
- “Robustness of quantum reinforcement learning under hardware errors” In EPJ Quantum Technology 10.1 SpringerOpen, 2023, pp. 1–43
- “Generation of High-Resolution Handwritten Digits with an Ion-Trap Quantum Computer”, 2022 arXiv:2012.03924 [quant-ph]
- Christa Zoufal, Aurélien Lucchi and Stefan Woerner “Variational quantum Boltzmann machines” In Quantum Machine Intelligence 3.1 Springer ScienceBusiness Media LLC, 2021 DOI: 10.1007/s42484-020-00033-7
- “Defence against adversarial attacks using classical and quantum-enhanced Boltzmann machines” In Machine Learning: Science and Technology 2.4 IOP Publishing, 2021, pp. 045006
- “Power of data in quantum machine learning” In Nature Communications 12.1 Springer ScienceBusiness Media LLC, 2021 DOI: 10.1038/s41467-021-22539-9
- “Extension of the PRISMA 2020 statement for living systematic reviews (LSRs): protocol [version 2; peer review: 1 approved]” In F1000Research 11.109, 2022 DOI: 10.12688/f1000research.75449.2
- “QTROJAN: A Circuit Backdoor Against Quantum Neural Networks” In ICASSP 2023-2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), 2023, pp. 1–5 IEEE
- “QDoor: Exploiting Approximate Synthesis for Backdoor Attacks in Quantum Neural Networks” In 2023 IEEE International Conference on Quantum Computing and Engineering (QCE) 1, 2023, pp. 1098–1106 IEEE
- Abdullah Ash Saki, Mahabubul Alam and Swaroop Ghosh “Impact of noise on the resilience and the security of quantum computing” In 2021 22nd International Symposium on Quality Electronic Design (ISQED), 2021, pp. 186–191 IEEE
- Abdullah Ash Saki, Rasit Onur Topaloglu and Swaroop Ghosh “Shuttle-Exploiting Attacks and Their Defenses in Trapped-Ion Quantum Computers”, 2021 arXiv:2108.01054 [quant-ph]
- “Special Session: On the Reliability of Conventional and Quantum Neural Network Hardware” In 2022 IEEE 40th VLSI Test Symposium (VTS), 2022, pp. 1–12 DOI: 10.1109/VTS52500.2021.9794194
- Mahabubul Alam, Abdullah Ash-Saki and Swaroop Ghosh “Addressing Temporal Variations in Qubit Quality Metrics for Parameterized Quantum Circuits” In 2019 IEEE/ACM International Symposium on Low Power Electronics and Design (ISLPED), 2019, pp. 1–6 DOI: 10.1109/ISLPED.2019.8824907
- “Universal adversarial examples and perturbations for quantum classifiers” In National Science Review 9.6 Oxford University Press, 2022, pp. nwab130
- “Towards an Antivirus for Quantum Computers” In 2022 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) 13, 2023, pp. 37–40 DOI: 10.1109/HOST54066.2022.9840181
- Ellis Wilson, Sudhakar Singh and Frank Mueller “Just-in-time Quantum Circuit Transpilation Reduces Noise”, 2020 arXiv:2005.12820 [quant-ph]
- Kyle Poland, Kerstin Beer and Tobias J Osborne “No free lunch for quantum machine learning” In arXiv preprint arXiv:2003.14103, 2020
- Leonardo Banchi “Robust quantum classifiers via NISQ adversarial learning” In Nature Computational Science 2.11 Nature Publishing Group US New York, 2022, pp. 699–700
- “Exploring the Vulnerabilities of Machine Learning and Quantum Machine Learning to Adversarial Attacks using a Malware Dataset: A Comparative Analysis” In IEEE CARL K. CHANG SYMPOSIUM ON SOFTWARE SERVICES ENGINEERING, 2023
- “Benchmarking adversarially robust quantum machine learning at scale” In Physical Review Research 5.2 American Physical Society (APS), 2023 DOI: 10.1103/physrevresearch.5.023186
- “Improved Differential Privacy Noise Mechanism in Quantum Machine Learning” In IEEE Access IEEE, 2023
- “Enhancing Quantum Adversarial Robustness by Randomized Encodings”, 2022 arXiv:2212.02531 [quant-ph]
- “Quantum noise protects quantum classifiers against adversaries” In Physical Review Research 3.2 APS, 2021, pp. 023153
- “Optimal provable robustness of quantum classification via quantum hypothesis testing” In npj Quantum Information 7.1 Springer ScienceBusiness Media LLC, 2021 DOI: 10.1038/s41534-021-00410-5
- Christoph Hirche, Cambyse Rouzé and Daniel Stilck França “Quantum differential privacy: An information theory perspective” In IEEE Transactions on Information Theory IEEE, 2023
- “Adversarial Robustness based on Randomized Smoothing in Quantum Machine Learning”, 2023 URL: https://openreview.net/forum?id=o-Yxq5iicIp
- “Expressive variational quantum circuits provide inherent privacy in federated learning”, 2023 arXiv:2309.13002 [quant-ph]
- “Quantum Robustness Verification: A Hybrid Quantum-Classical Neural Network Certification Algorithm” In 2022 IEEE International Conference on Quantum Computing and Engineering (QCE), 2022, pp. 142–153 IEEE
- “Efficient milp decomposition in quantum computing for relu network robustness” In 2023 IEEE International Conference on Quantum Computing and Engineering (QCE) 1, 2023, pp. 524–534 IEEE
- Khashayar Barooti, Grzegorz Głuch and Ruediger Urbanke “Provable Adversarial Robustness in the Quantum Model”, 2021 arXiv:2112.09625 [quant-ph]
- Ji Guan, Wang Fang and Mingsheng Ying “Robustness Verification of Quantum Machine Learning.” In CoRR, 2020
- Ji Guan, Wang Fang and Mingsheng Ying “Robustness verification of quantum classifiers” In Computer Aided Verification: 33rd International Conference, CAV 2021, Virtual Event, July 20–23, 2021, Proceedings, Part I 33, 2021, pp. 151–174 Springer
- Ji Guan, Wang Fang and Mingsheng Ying “Verifying Fairness in Quantum Machine Learning” In International Conference on Computer Aided Verification, 2022, pp. 408–429 Springer
- Ian Goodfellow, Jonathon Shlens and Christian Szegedy “Explaining and Harnessing Adversarial Examples” In International Conference on Learning Representations, 2015 URL: http://arxiv.org/abs/1412.6572
- Alexey Kurakin, Ian J Goodfellow and Samy Bengio “Adversarial examples in the physical world” In Artificial intelligence safety and security ChapmanHall/CRC, 2018, pp. 99–112
- “Towards Deep Learning Models Resistant to Adversarial Attacks” In International Conference on Learning Representations, 2018 URL: https://openreview.net/forum?id=rJzIBfZAb
- “Boosting adversarial attacks with momentum” In Proceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 9185–9193
- “Quantum adversarial metric learning model based on triplet loss function”, 2023 arXiv:2303.08293 [quant-ph]
- “MNIST handwritten digit database”, http://yann.lecun.com/exdb/mnist/, 2010 URL: http://yann.lecun.com/exdb/mnist/
- “Adversarial robustness in hybrid quantum-classical deep learning for botnet dga detection” In Journal of Information Processing 30 Information Processing Society of Japan, 2022, pp. 636–644
- Cynthia Dwork “Differential privacy” In International colloquium on automata, languages, and programming, 2006, pp. 1–12 Springer
- “Deep learning with differential privacy” In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, 2016, pp. 308–318
- Jeremy Cohen, Elan Rosenfeld and Zico Kolter “Certified adversarial robustness via randomized smoothing” In international conference on machine learning, 2019, pp. 1310–1320 PMLR
- “Differential privacy in quantum computation” In 2017 IEEE 30th Computer Security Foundations Symposium (CSF) IEEE, 2017, pp. 249–262
- Maria Schuld, Ryan Sweke and Johannes Jakob Meyer “Effect of data encoding on the expressive power of variational quantum-machine-learning models” In Physical Review A 103.3 American Physical Society (APS), 2021 DOI: 10.1103/physreva.103.032430
- Nicola Franco (12 papers)
- Alona Sakhnenko (6 papers)
- Leon Stolpmann (1 paper)
- Daniel Thuerck (2 papers)
- Fabian Petsch (1 paper)
- Annika Rüll (1 paper)
- Jeanette Miriam Lorenz (37 papers)