When cheap gradients fail: the measurement cost of attacking quantum classifiers
arXiv:2607. 11095v1 Announce Type: cross Abstract: Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers.
The paper studies how an eavesdropper can adaptively attack quantum key distribution (QKD) systems when channel noise and device drift vary over time. By modeling the attack as a constrained Markov decision process and using reinforcement learning to jointly search gate structures and rotation angles, the authors construct compact attack circuits that perform near the theoretical upper bound for both device‑independent E91 and BB84 protocols under realistic noise models. The results show that adaptive attacks can significantly increase the eavesdropper’s information compared to fixed‑circuit strategies, and that the learned attacks recover known optimal cloners and key‑rate bounds.
arXiv:2607. 11095v1 Announce Type: cross Abstract: Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers.
arXiv:2606. 02655v1 Announce Type: cross Abstract: External regret certifies stability only against replacing one's behavior by a fixed alternative.
arXiv:2606. 20183v1 Announce Type: new Abstract: Recent quantum vision models-quantum vision transformers and quantum convolutional networks-report two striking but unexplained empirical phenomena: (i) ansatze with more, or more uniformly distributed, entanglement generalize better, and (ii) injecting quantum noise can improve test accuracy rather than degrade it.
The paper introduces QEMScore, a metric that compares learned quantum error mitigators to capacity‑matched controls that do not use measurement data. Using simulated circuits with exact ideal answers, the study finds that many mitigators gain little from measurement inputs, with a plain polynomial model often outperforming them. On real hardware data, however, measurement inputs can provide predictive benefits, highlighting that performance depends on representation and protocol specifics.
arXiv:2606. 19947v1 Announce Type: cross Abstract: Reliable quantum control in the presence of decoherence requires policies that combat the effect of environmental noise on the controlled dynamics.
The study evaluates quantum machine learning (QML) models for network intrusion detection against well-tuned classical baselines across four standard datasets, using a leakage-controlled protocol and noise simulation. It introduces a quantum-attribution audit to determine whether any performance gains are truly due to quantum effects. While most tuned classical models match or surpass QML, two quantum approaches— a quantum-kernel SVM and a small hybrid circuit—show statistically significant advantages on specific metrics and tasks.
arXiv:2606. 12211v1 Announce Type: cross Abstract: A central principle in quantum machine learning is that an ansatz should be expressive enough to represent the quantum data of interest.
arXiv:2606. 30688v1 Announce Type: cross Abstract: Symmetry provides a quantum neural network structure, but on its own it does not keep the network trainable once noise is present.
arXiv:2504. 05336v4 Announce Type: replace-cross Abstract: A recurring weakness in quantum machine learning (QML) is that reported ``quantum advantages'' are seldom tested against a \emph{capacity-matched} classical control, leaving it unclear whether a gain comes from the quantum substrate or from the architectural change that accompanies it.
arXiv:2606. 20344v1 Announce Type: cross Abstract: Machine learning models have scaled to unprecedented sizes, making training across distributed devices the de facto standard in the field.
The paper demonstrates that by choosing unit‑quaternion coordinates, encrypted updates for variational quantum circuits become bilinear, allowing depth‑one homomorphic federated learning without bootstrapping. This coordinate choice reduces encrypted rotation updates to a single multiplicative level and federated averaging to zero levels, eliminating the previously prohibitive cost of one round per gate. Experiments across two cryptographic backends and up to 20 clients show negligible aggregation error and no measurable loss in utility, with hardware validation on a 156‑qubit processor achieving near‑optimal fidelity.
arXiv:2605. 30952v2 Announce Type: replace Abstract: Two recent results have reshaped quantum Gaussian processes (QGPs).