Discovery of universal adversarial attacks for quantum classifiers

2 years ago 209
Discovery of cosmopolitan  adversarial attacks for quantum classifiers (a) Universal adversarial examples: Adding a tiny magnitude of cautiously crafted sound to a definite representation could marque it go an adversarial illustration that tin fool antithetic quantum classifiers. (b) Universal adversarial perturbations: adding the aforesaid carefully-crafted sound to a acceptable of images could marque them each go adversarial examples for a fixed quantum classifier. Credit: Science China Press

Artificial quality has achieved melodramatic occurrence implicit the past decade, with the triumph successful predicting macromolecule structures marked arsenic the latest milestone. At the aforesaid time, quantum computing has besides made singular advancement successful caller years. A caller breakthrough successful this tract is the experimental objection of quantum supremacy. The fusion of artificial quality and quantum physics gives emergence to a caller interdisciplinary field—-quantum artificial intelligence.

This emergent tract is increasing accelerated with notable advancement made connected a regular basis. Yet, it is mostly inactive successful its infancy and galore important problems stay unexplored. Among these problems stands the vulnerability of quantum classifiers, which sparks a caller probe frontier of quantum adversarial instrumentality learning.

In classical instrumentality learning, the vulnerability of classifiers based connected heavy neural networks to has been actively studied since 2004. It has been observed that these classifiers mightiness beryllium amazingly vulnerable: adding a carefully-crafted but imperceptible to the archetypal morganatic illustration tin mislead the classifier to marque incorrect predictions, adjacent astatine a notably precocious assurance level.

Similar to classical instrumentality learning, caller studies person revealed the vulnerability facet of quantum classifiers from some theoretical investigation and numerical simulations. The exotic properties of the adversarial attacks against quantum instrumentality learning systems person attracted sizeable attentions crossed communities.

In a caller probe nonfiction published successful the Beijing-based National Science Review, researchers from IIIS, Tsinghua University, China studied the universality properties of adversarial examples and perturbations for quantum classifiers for the archetypal time. As shown successful the figure, the authors enactment guardant affirmative answers to the pursuing 2 questions: (i) whether determination beryllium cosmopolitan adversarial examples that could fool antithetic quantum classifiers? (ii) whether determination beryllium cosmopolitan adversarial perturbations, which erstwhile added to antithetic morganatic input samples could marque them go adversarial examples for a fixed quantum classifier?

The authors person proved 2 absorbing theorems, 1 for each question. For the archetypal question, erstwhile works person shown that for a azygous quantum classifier, the threshold spot for a perturbation to present an adversarial onslaught decreases exponentially arsenic the fig of qubits increases. The existent insubstantial extended this decision to the lawsuit of aggregate quantum classifiers, and rigorously proved that for a acceptable of k quantum classifiers, an logarithmic k summation of the perturbation spot is capable to guarantee a mean cosmopolitan adversarial risk. This establishes the beingness of cosmopolitan adversarial examples that tin deceive aggregate quantum classifiers.

For the 2nd question, the authors proved that for a cosmopolitan adversarial perturbation added to antithetic morganatic samples, the misclassification complaint of a fixed quantum classifier volition summation arsenic the magnitude of information abstraction increases. Furthermore, the misclassification complaint volition attack 100% erstwhile the magnitude of information samples is infinitely large.

In addition, extended numerical simulations had been carried retired connected factual examples involving classifications of real-life images and quantum phases of substance to show however to get some cosmopolitan adversarial perturbations and examples successful practice. The authors besides projected adversarial attacks nether black-box scenarios to research and the transferability of adversarial attacks connected antithetic classifiers.

The results successful this enactment reveals a important universality facet of adversarial attacks for quantum instrumentality learning systems, which would supply a invaluable usher for aboriginal applicable applications of some near-term and aboriginal quantum technologies successful instrumentality learning, oregon much broadly .



More information: Weiyuan Gong et al, Universal Adversarial Examples and Perturbations for Quantum Classifiers, National Science Review (2021). DOI: 10.1093/nsr/nwab130

Citation: Discovery of cosmopolitan adversarial attacks for quantum classifiers (2021, October 12) retrieved 12 October 2021 from https://techxplore.com/news/2021-10-discovery-universal-adversarial-quantum.html

This papers is taxable to copyright. Apart from immoderate just dealing for the intent of backstage survey oregon research, no portion whitethorn beryllium reproduced without the written permission. The contented is provided for accusation purposes only.

Read Entire Article