Quantum classifiers get new way to certify robustness against attacks

Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query Access

Cryptography and Security

Summary

Quantum computers can be used for classifying information, but they might be tricked by tiny changes that cause wrong answers. This paper presents a method to check how resistant quantum classifiers are to such changes by only looking at the measurement results, without needing to know the details inside. The authors create two types of guarantees for each input—one shows how safe the classifier is against any error within a certain limit, and the other warns of potential vulnerabilities. They tested their approach on real quantum devices and showed it works practically.

What this means in practice

  • For quantum hardware teams: Verify the robustness of deployed quantum classifiers using only measurement data under known-readout conditions.
  • For quantum software developers: Improve defense assessment tools for quantum machine learning models without needing inside access to circuits or parameters.

Authors

Ji Guan, Mingyu Huang

Abstract

A quantum classifier assigns labels by evolving an input quantum state and measuring the output, so repeated executions reveal only a distribution over labels. We study certified adversarial robustness for such classifiers under known-readout query access (KRQA), where an evaluator can prepare inputs, knows the quantum measurement, and observes finite-shot outcomes but cannot inspect the internal evolution, parameters, or gradients. We give a measurement-only framework that returns two complementary guarantees for each input: a lower bound ruling out untargeted errors within a radius, and an attack-independent upper bound witnessing an adversarial state within a radius. Both are estimable from the known readout measurement and sampled outcomes, require no tomography or circuit description, and admit finite-sample guarantees. The upper bound uses gap operators induced by the quantum measurement; the lower bound relaxes state-space search to an efficient optimization over outcome distributions with operator-spectrum constraints, yielding certificates that are never weaker than prior probability-only certificates and can be strictly stronger when the spectral constraints are active. Evaluations on multiple quantum classifiers show that the lower bound tracks exact optima on tractable instances, while the upper bound remains informative when standard attacks fail. We further demonstrate real-device feasibility on IBM Quantum hardware: from 40 executions of two 8-qubit quantum neural networks, our method computes both certificates, with the expected ordering between the lower and upper bounds on every tested input. Taken together, these results show that robustness claims for quantum classifiers can be audited directly from observable statistics under KRQA.