Papers
Topics
Authors
Recent
Search
2000 character limit reached

Backdoor Attacks against Hybrid Classical-Quantum Neural Networks

Published 23 Jul 2024 in cs.CR | (2407.16273v1)

Abstract: Hybrid Quantum Neural Networks (HQNNs) represent a promising advancement in Quantum Machine Learning (QML), yet their security has been rarely explored. In this paper, we present the first systematic study of backdoor attacks on HQNNs. We begin by proposing an attack framework and providing a theoretical analysis of the generalization bounds and minimum perturbation requirements for backdoor attacks on HQNNs. Next, we employ two classic backdoor attack methods on HQNNs and Convolutional Neural Networks (CNNs) to further investigate the robustness of HQNNs. Our experimental results demonstrate that HQNNs are more robust than CNNs, requiring more significant image modifications for successful attacks. Additionally, we introduce the Qcolor backdoor, which utilizes color shifts as triggers and employs the Non-dominated Sorting Genetic Algorithm II (NSGA-II) to optimize hyperparameters. Through extensive experiments, we demonstrate the effectiveness, stealthiness, and robustness of the Qcolor backdoor.

Definition Search Book Streamline Icon: https://streamlinehq.com
References (46)
  1. E. Farhi, H. Neven, Classification with quantum neural networks on near term processors, arXiv preprint arXiv:1802.06002 (2018).
  2. C. Zhao, X.-S. Gao, Qdnn: deep neural networks with quantum layers, Quantum Machine Intelligence 3 (2021) 15.
  3. Transfer learning in hybrid classical-quantum neural networks, Quantum 4 (2020) 340.
  4. Quantum machine learning, Nature 549 (2017) 195–202.
  5. On circuit-based hybrid quantum neural networks for remote sensing imagery classification, IEEE Journal of Selected Topics in Applied Earth Observations and Remote Sensing 15 (2021) 565–580.
  6. Quantum generative adversarial networks for learning and loading random distributions, npj Quantum Information 5 (2019) 103.
  7. Parametrized quantum policies for reinforcement learning, Advances in Neural Information Processing Systems 34 (2021) 28362–28375.
  8. Training deep quantum neural networks, Nature communications 11 (2020) 808.
  9. H. Robbins, S. Monro, A stochastic approximation method, The annals of mathematical statistics (1951) 400–407.
  10. D. P. Kingma, J. Ba, Adam: A method for stochastic optimization, arXiv preprint arXiv:1412.6980 (2014).
  11. Deep learning, nature 521 (2015) 436–444.
  12. Robust in practice: Adversarial attacks on quantum machine learning, Physical Review A 103 (2021) 042427.
  13. Towards quantum enhanced adversarial robustness in machine learning, Nature Machine Intelligence 5 (2023) 581–589.
  14. Experimental quantum adversarial learning with programmable superconducting qubits, Nature Computational Science 2 (2022) 711–717.
  15. Qdoor: Exploiting approximate synthesis for backdoor attacks in quantum neural networks, in: 2023 IEEE International Conference on Quantum Computing and Engineering (QCE), volume 1, IEEE, 2023a, pp. 1098–1106.
  16. Qtrojan: A circuit backdoor against quantum neural networks, in: ICASSP 2023-2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE, 2023b, pp. 1–5.
  17. Intriguing properties of neural networks, arXiv preprint arXiv:1312.6199 (2013).
  18. Badnets: Evaluating backdooring attacks on deep neural networks, IEEE Access 7 (2019) 47230–47244.
  19. Backdoor learning: A survey, IEEE Transactions on Neural Networks and Learning Systems 35 (2022) 5–22.
  20. Deep residual learning for image recognition, in: Proceedings of the IEEE conference on computer vision and pattern recognition, 2016, pp. 770–778.
  21. A fast and elitist multiobjective genetic algorithm: Nsga-ii, IEEE transactions on evolutionary computation 6 (2002) 182–197.
  22. Color backdoor: A robust poisoning attack in color space, in: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 8133–8142.
  23. W. Zhou, Image quality assessment: from error measurement to structural similarity, IEEE transactions on image processing 13 (2004) 600–613.
  24. Quantum noise protects quantum classifiers against adversaries, Physical Review Research 3 (2021) 023153.
  25. Enhancing quantum adversarial robustness by randomized encodings, Physical Review Research 6 (2024).
  26. N. Liu, P. Wittek, Vulnerability of quantum classification to adversarial perturbations, Physical Review A 101 (2019).
  27. A comparative analysis of adversarial robustness for quantum and classical machine learning models, arXiv preprint arXiv:2404.16154 (2024).
  28. Hidden trigger backdoor attacks, in: Proceedings of the AAAI conference on artificial intelligence, volume 34, 2020, pp. 11957–11965.
  29. Backdoor attack with imperceptible input and latent modification., Advances in neural information processing systems 34 (2021) 18944–18957.
  30. A. Nguyen, A. Tran, Wanet–imperceptible warping-based backdoor attack, arXiv preprint arXiv:2102.10369 (2021).
  31. E. Bagdasaryan, V. Shmatikov, Blind backdoors in deep learning models, in: 30th USENIX Security Symposium (USENIX Security 21), 2021, pp. 1505–1521.
  32. J. Dumford, W. Scheirer, Backdooring convolutional neural networks via targeted weight perturbations, in: 2020 IEEE International Joint Conference on Biometrics (IJCB), IEEE, 2020, pp. 1–9.
  33. An embarrassingly simple approach for trojan attack in deep neural networks, in: Proceedings of the 26th ACM SIGKDD international conference on knowledge discovery & data mining, 2020, pp. 218–228.
  34. Backdoor defense with machine unlearning, in: IEEE Conference on Computer Communications, 2022, pp. 280–289.
  35. Backdoor defense via deconfounded representation learning, in: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 12228–12238.
  36. Neural polarizer: A lightweight and effective backdoor defense via purifying poisoned features, Advances in Neural Information Processing Systems 36 (2024).
  37. Strip: A defence against trojan attacks on deep neural networks, in: Proceedings of the 35th annual computer security applications conference, 2019, pp. 113–125.
  38. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks, in: 2019 IEEE symposium on security and privacy (SP), IEEE, 2019, pp. 707–723.
  39. Fine-pruning: Defending against backdooring attacks on deep neural networks, in: International symposium on research in attacks, intrusions, and defenses, Springer, 2018, pp. 273–294.
  40. Reflection backdoor: A natural backdoor attack on deep neural networks, in: Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part X 16, Springer, 2020, pp. 182–199.
  41. Multi-objective optimization, in: Decision sciences, CRC Press, 2016, pp. 161–200.
  42. Imagenet: A large-scale hierarchical image database, in: 2009 IEEE conference on computer vision and pattern recognition, Ieee, 2009, pp. 248–255.
  43. Targeted backdoor attacks on deep learning systems using data poisoning, arXiv preprint arXiv:1712.05526 (2017).
  44. Grad-cam: Visual explanations from deep networks via gradient-based localization, International Journal of Computer Vision 128 (2019) 336–359.
  45. Adversarial examples detection and analysis with layer-wise autoencoders, in: 2021 IEEE 33rd International Conference on Tools with Artificial Intelligence (ICTAI), IEEE, 2021, pp. 1322–1326.
  46. N. Papernot, P. McDaniel, Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning, arXiv preprint arXiv:1803.04765 (2018).

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Collections

Sign up for free to add this paper to one or more collections.