When cheap gradients fail: the measurement cost of attacking quantum classifiers
Bacui Li, Chandra Thapa, Tansu Alpcan, Udaya Parampalli
quant-ph, cs.CR, cs.LG
Submitted: 2026-07-13
Comments: 57 pages, 15 figures
License: http://creativecommons.org/licenses/by/4.0/
The gist: Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers.
Terminology
Abstract
Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers. We show that finite quantum measurement statistics (shot noise) act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker. Because every gradient component must be inferred from repeated circuit executions under any unbiased gradient-estimation rule, white-box extraction consumes a dimension-dependent measurement budget that measurement grouping cannot remove in expressive circuits. Under stated assumptions, single-step attacks need at least quadratically many shots in the input dimension d, growing as d 5/2 under norm-concentration scaling, with a sufficient-budget analysis for iterative attacks via stochastic gradient Langevin dynamics. Simulations up to 784 input dimensions validate the law: the realized total budget is the d 5/2 geometric floor for plateau-mitigated models and grows as d 3.00 for the tested deep circuits, whose gradient norms decay with dimension absent barren-plateau mitigation; folding the measured gradient norm back in recovers the parameter-free d 3/2 shot-noise geometry. Against a matched classical baseline whose attack overhead is dimension-independent (the cheap-gradient principle of automatic differentiation), the quantum gradient cost ratio grows empirically as d 3.00, so the attacker's relative cost diverges as the model scales. Experiments on a 156-qubit IBM processor (ibm boston, 4-qubit circuits, d=12) reproduce the effect: at matched budgets the device attack tracks the ideal within a few percent, with the high-shot gradient faithful to the exact one. The defense operates precisely when the forward map is classically hard to simulate: only then is a white-box attacker denied the simulate-and-backpropagate shortcut and must pay the measurement cost we quantify.
Sources
- Explaining and Harnessing Adversarial Examples
- Towards Evaluating the Robustness of Neural Networks
- The Curse of Concentration in Robust Learning: Evasion and Poisoning Attacks from Concentration of Measure
- Experimental robustness benchmarking of quantum neural networks on a superconducting quantum processor
- Challenges of variational quantum optimization with measurement shot noise
- Fast gradient estimation for variational quantum algorithms
- SantaQlaus: A resource-efficient method to leverage quantum shot-noise for optimization of variational quantum algorithms
- Provable defenses against adversarial examples via the convex outer adversarial polytope
- Trade-off between Gradient Measurement Efficiency and Expressivity in Deep Quantum Neural Networks
- Overshifted Parameter-Shift Rules: Optimizing Complex Quantum Systems with Few Measurements
- Gradient Estimation with Constant Scaling for Hybrid Quantum Machine Learning
- Quantum Shadow Gradient Descent for Variational Quantum Algorithms
- An Empirical Review of Optimization Techniques for Quantum Variational Circuits
- Global Convergence of Langevin Dynamics Based Algorithms for Nonconvex Optimization
- Query Complexity of Derivative-Free Optimization
- Data re-uploading for a universal quantum classifier
- Circuit-centric quantum classifiers
- Towards Deep Learning Models Resistant to Adversarial Attacks
- Automatic differentiation in machine learning: a survey
- Identifying and attacking the saddle point problem in high-dimensional non-convex optimization
Related papers
- Reconquering Bell sampling on qudits: stabilizer learning and testing, quantum pseudorandomness bounds, and more
- Encrypted clones can leak: Classification of informative subsets in Quantum Encrypted Cloning
- Polynomial-time classical and quantum simulation of quantum impurity models
- Theory of quantum-enhanced interferometry with general Markovian light sources
- A convergent hierarchy of spectral gap certificates for qubit Hamiltonians
- Universal Bound and Phase Transition in Many-Body Fermionic Non-Gaussianity