Calibration improves trust in AI advice for quantum error correction
Securing quantum error correction against misleading advice from AI agents
Artificial IntelligenceCryptography and Security
Summary
Quantum computers need to fix errors that happen during their operation, but sometimes AI systems used to suggest how to fix these errors can be tricked into giving wrong advice. The authors found that by adding special calibration measurements, it is possible to tell when the AI’s advice might actually make things worse. They created methods to check if updates based on AI advice genuinely improve error correction, even when the advice might be unreliable or affected by system changes. Their experiments show how to reject harmful suggestions while still taking good ones, helping to keep quantum computers working better.
What this means in practice
- •For quantum hardware engineers: Use calibration-assisted checks to safely update error-correction protocols in quantum devices despite changing noise patterns.
- •For quantum software developers: Incorporate certification steps in AI-driven correction updates to prevent harmful advice deployment during quantum computation.
Authors
A. Barış Özgüler
Abstract
Can an attacker turn influence over an artificial intelligence (AI) adviser into a harmful quantum error-correction update? We identify an ambiguity in passive syndrome records that obstructs recovery selection, then show how additional calibration measurements support certified recovery updates under uncertainty and drift. In an odd-distance square toric code with error-free preparation, syndrome measurements, and recovery operations, opposite coherent $X$ rotations produce identical passive syndrome-history distributions. Yet a fixed phase correction can help at one sign and harm at the other. A terminal logical measurement on known encoded calibration states supplies the missing sign information. A separate evaluator accepts an update only when calibration uncertainty and a justified drift bound certify improvement over the current recovery, without assuming that the adviser recommends correctly. In simulated advice attacks, calibration-confidence checks reject harmful proposals while retaining beneficial updates under honest advice. We derive sufficient limits on calibration age that require improvement through deployment. In matched simulations, a validated channel-specific bound retains more beneficial updates than the general bound after accounting for evaluation time, while preventing the tested harmful activations under the stated drift assumption. A separate surface-code experiment includes stochastic circuit faults and noise changing during acquisition. Deterministic controllers achieve at least as many beneficial updates with the same observations. Violating the drift assumption permits harmful acceptance in the toric experiment. The results identify information required for recovery selection, establish conditional guarantees against harmful updates, and quantify the recovery improvements forgone through conservative acceptance.