We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

quant-ph

References & Citations

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Quantum Physics

Title: Robust in Practice: Adversarial Attacks on Quantum Machine Learning

Abstract: State-of-the-art classical neural networks are observed to be vulnerable to small crafted adversarial perturbations. A more severe vulnerability has been noted for quantum machine learning (QML) models classifying Haar-random pure states. This stems from the concentration of measure phenomenon, a property of the metric space when sampled probabilistically, and is independent of the classification protocol. In order to provide insights into the adversarial robustness of a quantum classifier on real-world classification tasks, we focus on the adversarial robustness in classifying a subset of encoded states that are smoothly generated from a Gaussian latent space. We show that the vulnerability of this task is considerably weaker than that of classifying Haar-random pure states. In particular, we find only mildly polynomially decreasing robustness in the number of qubits, in contrast to the exponentially decreasing robustness when classifying Haar-random pure states and suggesting that QML models can be useful for real-world classification tasks.
Comments: 16 pages, 1 figure
Subjects: Quantum Physics (quant-ph)
Journal reference: Phys. Rev. A 103, 042427 (2021)
DOI: 10.1103/PhysRevA.103.042427
Cite as: arXiv:2010.08544 [quant-ph]
  (or arXiv:2010.08544v2 [quant-ph] for this version)

Submission history

From: Haoran Liao [view email]
[v1] Fri, 16 Oct 2020 17:57:32 GMT (36kb,D)
[v2] Fri, 26 Feb 2021 06:24:05 GMT (52kb,D)

Link back to: arXiv, form interface, contact.