REVIEW 2 major objections 5 minor 34 references
Quantum Machine Learning
T0 review · 2 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read This chapter argues that quantum machine learning flips adversarial attacks: classical attacks fail against quantum models, while quantum-generated attacks fool classical models, giving early quantum adopters a dual security edge.
desk verdict A readable QML survey whose central adversarial-robustness claim is a single self-cited simulation, presented more confidently than its own caveats allow. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The object that carries the argument is the quantum variational classifier, a circuit made of three blocks: a data-encoding layer, a parameterized layer of single-qubit rotations and two-qubit entangling gates, and a measurement. Entanglement from the two-qubit gates is invoked as the property that makes classical adversarial perturbations ineffective on QML models while quantum-generated perturbations remain transferable to classical models. The transferability asymmetry is the mechanism the chapter leans on: attacks designed against one architecture are tested against another, and the direction of transfer decides who has the advantage.
What would settle it
Run the same transferability experiment on a current noisy quantum processor with a realistic dataset: if classical adversarial examples generated against classical networks flip the output of the quantum classifier at a non-negligible rate, or if quantum-generated attacks fail to fool classical networks, the asymmetry reported here breaks. A simpler check is whether the results cited as [12] reproduce when the simulation is re-run with standard error bars and multiple random seeds.
Extended reading notes
Core claim
The discovery the chapter reports is an adversarial-robustness asymmetry between classical and quantum classifiers. Based on the benchmarking study cited as [12], classical attacks that succeed against classical networks fail against quantum variational classifiers, whereas attacks generated on quantum classifiers transfer to and fool classical networks. The chapter takes this asymmetry as evidence that quantum properties, particularly entanglement, change the attack surface of machine learning, and that early adopters of quantum technology would hold a dual advantage: resilient models and potent attacks. It notes that QML networks remain vulnerable to attacks generated by other quantum networks, so the advantage is not absolute.
Load-bearing premise
The central security claim rests on a single benchmarking study from one research group that has not been independently replicated, and the chapter assumes those simulation results carry over to real datasets, larger models, and the noisy quantum hardware available today.
Editorial extensions
If this is right
- If QML models resist classical adversarial attacks, classical attack-transfer defenses become less relevant for quantum-based systems.
- QML-generated attacks could become a new offensive tool for fooling deployed classical ML systems in security-sensitive applications.
- The vulnerability of QML to quantum-generated attacks implies that post-quantum security planning must assume adversarial access to quantum computers.
- Practical QML security depends on solving known pipeline problems such as data encoding, barren plateaus, and hardware noise, since robustness findings so far come from simulations on simple datasets.
- Quantum data, which avoids the classical encoding bottleneck, is presented as the most promising route to genuine quantum advantage in ML.
Reading between the lines
- If the transferability asymmetry is real, it suggests an early-mover doctrine: the first actor with reliable quantum ML gets both armor and weapon, though the asymmetry may erode as quantum hardware matures and classical attackers learn to imitate quantum perturbations.
- Because the robustness evidence comes from simulation on small datasets, a high-value test is whether adversarial examples generated on classical neural nets but constrained to look quantum-like, for instance through low-rank or entanglement-structured perturbations, transfer to QML models.
- If quantum noise itself contributes to robustness, as hinted by cited work on noise-protected quantum classifiers, then error-corrected fault-tolerant hardware might remove a free layer of defense and change the security calculus.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This chapter, authored by Muhammad Usman, is an introductory review of quantum machine learning (QML) and quantum adversarial machine learning (QAML). It outlines the promise of QML, describes the main building blocks of variational quantum classifiers, discusses open challenges such as data encoding, barren plateaus, and noise, and surveys recent trends including quantum transfer learning, equivariant QML, and quantum generative adversarial networks. The chapter's headline claim is that QML offers a 'dual advantage' in adversarial settings: classical adversarial attacks do not transfer to QML models, while attacks generated on QML models successfully fool classical models (Section 1.2). The chapter then recommends investment in QML/QAML for defense and intelligence, surveillance, and reconnaissance (ISR) applications (Section 1.3).
Significance. The chapter is a clearly written, well-structured survey of a rapidly moving field, and it does a service by cataloging current open problems (data encoding, barren plateaus, noise mitigation, architecture design). The author's closeness to the frontier research is a strength: the chapter draws on recent experimental demonstrations and includes pointers to recent preprints. However, the central adversarial-robustness claim is presented as an established discovery even though it rests on a single benchmark study (Ref. [12]) from the author's own group, with no independent validation and no boundary conditions. Because the security recommendation in Section 1.3 depends directly on this claim, the chapter's current framing oversells the evidence. The chapter is, nonetheless, a useful introduction for non-specialists if the claim is appropriately qualified.
major comments (2)
- [1.2 and 1.3] The dual-advantage claim — that 'attacks from classical ML models do not transfer to QML models, contrarily the attacks from QML models were easily able to fool classical ML algorithms' — is stated as a categorical discovery. The only cited support is Ref. [12], a benchmark study on small image datasets (MNIST/FMNIST), and the chapter's own caveats in Sec. 1.2.2 ('primarily to simple proof-of-concept datasets') and Sec. 1.2.3 item 1 ('current implementation of QML is primarily focused on simple proof-of-concept datasets such as MNIST and FMNIST') limit the domain of validity. The claim should be qualified to the specific experimental regime, and the chapter should explicitly identify the conditions under which the asymmetry has not yet been tested (e.g., larger models, real-world datasets, noisy hardware, different attack families). As written, the recommendation in Sec. 1.3 to adopt QML/QAML for military ISR systems goes beyond the demonstrated evidence.
- [1.2 (adversarial robustness discussion)] The chapter cites Refs. [13] (Lu et al.) and [14] (Liu and Wittek) as relevant to QML vulnerability, yet the text concludes that QML is 'remarkably robust' without reconciling those works, which report adversarial perturbations that can fool quantum classifiers. A review should either discuss why those vulnerability results do not apply to the models in Ref. [12], or explicitly state that the robustness result is model- and attack-dependent. In addition, the central robustness claim is drawn almost exclusively from the author's own group's publications (Refs. [8,12,16]); a balanced review should note the absence of independent replication and view the result as preliminary rather than established.
minor comments (5)
- [1.1] Minor English errors: 'the birth a new field' should be 'the birth of a new field'; 'significant more development' should be 'significantly more development'; 'severally limits' should be 'severely limits'.
- [1.2.3 item 6] The phrase 'And & Bees' likely should be 'Ants & Bees' (the dataset referenced in Ref. [32]); please check the dataset name.
- [1.2.3 item 3] The sentence 'It might be possible that the noise in quantum devices dilute the presence of adversarial attacks which in itself are based on the carefully crafted noise...' is grammatically awkward (subject-verb agreement) and could be clarified to clearly separate speculation from established results.
- [References] Ref. [19] lacks an article title; Refs. [17] and [31] are arXiv preprints and should be labeled as such for consistency with other references.
- [1.2.3 item 1] When first mentioning MNIST and FMNIST, the chapter could add a brief parenthetical description (e.g., hand-written digit and Fashion-MNIST image classification benchmarks) for readers outside the immediate field.
Circularity Check
Sec. 1.2's dual-advantage claim reduces to the author's own prior simulation [12]; the chapter's caveats undercut its generality.
-
self citation load bearing
[Section 1.2 (transferability paragraph); echoed in Section 1.2.3 item 8 and relied on in Section 1.3]
"Recent work has focused on the analysis of QML models, in particular with the context of transferability of attacks between classical and quantum ML architectures [12]. It has been discovered that while the attacks from classical ML models do not transfer to QML models, contrarily the attacks from QML models were easily able to fool classical ML algorithms."
The chapter's load-bearing 'dual advantage' claim is not derived, benchmarked, or independently verified in this chapter; it is a restatement of the conclusions of Ref. [12], a Physical Review Research paper from the same research group (see Refs. [8], [16], [33], [34], which list overlapping authors M.T. West, M. Sevior, and M. Usman). No independent replication, external dataset, error analysis, or boundary condition is supplied. The Section 1.3 recommendation to advance QML/QAML for military ISR systems presupposes exactly this self-cited transferability asymmetry.
full rationale
This chapter is a review, not a mathematical derivation, so the usual fit-and-predict circularity does not apply. However, the chapter's central substantive assertion—that classical attacks do not transfer to QML models while QML attacks fool classical models—is presented as an established discovery but is supported only by Ref. [12], a simulation study from the author's own group. The chapter supplies no independent replication, no external benchmark, and no discussion of when the asymmetry might fail, even though its own Sections 1.2.2 and 1.2.3 state that current QML/QAML work is limited to proof-of-concept image datasets and simple quantum architectures. Because the Section 1.3 Defence-focused recommendation is built directly on this self-cited result, the load-bearing step is a self-citation chain rather than an independent argument. This is not a case of simple benign self-citation: the central claim's validity in the chapter stands or falls with the unverified generalizability of Ref. [12]. Score 7 reflects a central claim that is effectively a restatement of the authors' own prior simulation, with the chapter's own caveats further limiting its scope. There is no evidence of deliberate misattribution; the issue is that the chapter does not provide independent content for its most important security conclusion.
Assumptions & free parameters
assumptions (3)
- domain assumption The adversarial robustness and transferability results of Refs. [8,12,16,17] are valid and representative.
- domain assumption Efficient quantum state preparation and error mitigation will become feasible enough that data-loading costs and noise do not erase QML advantages.
- domain assumption Large-scale fault-tolerant quantum computers will arrive in the near to medium-term future, making QML deployment plausible.
Cite this review
Pith. "Pith review of Quantum Machine Learning." pith.science (2026). https://pith.science/paper/YS67LDFU
@misc{pith2026250612292,
author = {Pith},
title = {Pith review of: Quantum Machine Learning},
year = {2026},
howpublished = {\url{https://pith.science/paper/YS67LDFU}},
note = {Machine review of arXiv:2506.12292}
}
read the original abstract
The meteoric rise of artificial intelligence in recent years has seen machine learning methods become ubiquitous in modern science, technology, and industry. Concurrently, the emergence of programmable quantum computers, coupled with the expectation that large-scale fault-tolerant machines will follow in the near to medium-term future, has led to much speculation about the prospect of quantum machine learning (QML), namely machine learning (ML) solutions which take advantage of quantum properties to outperform their classical counterparts. Indeed, QML is widely considered as one of the front-running use cases for quantum computing. In recent years, research in QML has gained significant global momentum. In this chapter, we introduce the fundamentals of QML and provide a brief overview of the recent progress and future trends in the field of QML. We highlight key opportunities for achieving quantum advantage in ML tasks, as well as describe some open challenges currently facing the field of QML. Specifically in the context of cybersecurity, we introduce the potential for QML in defence and security-sensitive applications, where it has been predicted that the seamless integration of quantum computing into ML will herald the development of robust and reliable QML systems, resilient against sophisticated threats arising from data manipulation and poisoning.
Figures
Reference graph
Works this paper leans on
-
[12]
M. T. West et al. Benchmarking adversarially robust quantum machine learning at scale. Physical Review Research, 5:023186, 2023
work page 2023
- [19]
-
[13]
Quantum adversarial machine learning
Sirui Lu, Lu-Ming Duan, and Dong-Ling Deng. Quantum adversarial machine learning. Phys- ical Review Research, 2(3):033212, 2020
work page 2020
-
[14]
Vulnerability of quantum classification to adversarial perturba- tions
Nana Liu and Peter Wittek. Vulnerability of quantum classification to adversarial perturba- tions. Phys. Rev. A, 101:062331, Jun 2020
work page 2020
-
[1]
R. Acharya et al. Quantum error correction below the surface code threshold. Nature, 2024
work page 2024
- [2]
-
[3]
R. Santagati et al. Drug design on quantum computers. Nat. Phys., 2024
work page 2024
-
[4]
D. Herman et al. Quantum computing for finance. Nat Rev Phys, 5:450–465, 2023
work page 2023
Show all 34 references
-
[5]
V . V . Dixit et al. Quantum computing for transport network design problems. Sci Rep , 13:12267, 2023
2023
-
[6]
Biamonte et al
J. Biamonte et al. Quantum machine learning. Nature, 549:195–202, 2017
2017
-
[7]
Cerezo et al
M. Cerezo et al. Challenges and opportunities in quantum machine learning. Nat Comput Sci, 2:567–576, 2022
2022
-
[8]
M. T. West et al. Towards quantum enhanced adversarial robustness in machine learning. Nat Mach Intell, 5:581–589, 2023
2023
-
[9]
Demonstration of quantum advantage in machine learning
Diego Rist `e, Marcus P Da Silva, Colm A Ryan, Andrew W Cross, Antonio D C´orcoles, John A Smolin, Jay M Gambetta, Jerry M Chow, and Blake R Johnson. Demonstration of quantum advantage in machine learning. npj Quantum Information, 3(1):1–5, 2017
2017
-
[10]
A rigorous and robust quantum speed-up in supervised machine learning
Yunchao Liu, Srinivasan Arunachalam, and Kristan Temme. A rigorous and robust quantum speed-up in supervised machine learning. Nature Physics, 17(9):1013–1017, 2021
2021
-
[11]
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236, 2016
2016 arXiv
-
[15]
Dowling et al
N. Dowling et al. Adversarial robustness guarantees for quantum classifiers. arXiv:2405.10360, 2024
2024
-
[16]
M. T. West et al. Drastic circuit depth reductions with preserved adversarial robustness by approximate encoding for quantum machine learning. Intelligent Computing, 3:100, 2024
2024
-
[17]
Experimental quantum adversarial learning with programmable superconducting qubits
Wenhui Ren, Weikang Li, Shibo Xu, Ke Wang, Wenjie Jiang, Feitong Jin, Xuhao Zhu, Jiachen Chen, Zixuan Song, Pengfei Zhang, et al. Experimental quantum adversarial learning with programmable superconducting qubits. arXiv preprint arXiv:2204.01738, 2022
2022 arXiv
-
[18]
Huang et al
H-Y . Huang et al. Quantum advantage in learning from experiments.Science, 376:1182–1186, 2022
2022
-
[20]
Ren et al
K. Ren et al. Engineering, 6:346–360, 2020. 1 Quantum Machine Learning 11
2020
-
[21]
Robust data encodings for quantum classifiers
Ryan LaRose and Brian Coyle. Robust data encodings for quantum classifiers. Physical Review A, 102(3):032420, 2020
2020
-
[22]
Data compression for quantum machine learning
Rohit Dilip, Yu-Jie Liu, Adam Smith, and Frank Pollmann. Data compression for quantum machine learning. arXiv preprint arXiv:2204.11170, 2022
2022 arXiv
-
[23]
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017
2017 arXiv
-
[24]
Explaining and harnessing adver- sarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adver- sarial examples. arXiv preprint arXiv:1412.6572, 2014
2014 arXiv
-
[25]
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning, pages 2206–2216. PMLR, 2020
2020
-
[26]
Quantum autoencoders for efficient compression of quantum data
Jonathan Romero, Jonathan P Olson, and Alan Aspuru-Guzik. Quantum autoencoders for efficient compression of quantum data. Quantum Science and Technology, 2(4):045001, 2017
2017
-
[27]
Quanvolu- tional neural networks: powering image recognition with quantum circuits.Quantum Machine Intelligence, 2(1):1–9, 2020
Maxwell Henderson, Samriddhi Shakya, Shashindra Pradhan, and Tristan Cook. Quanvolu- tional neural networks: powering image recognition with quantum circuits.Quantum Machine Intelligence, 2(1):1–9, 2020
2020
-
[28]
Heredge et al
J. Heredge et al. Non-unitary quantum machine learning. arXiv:2405.17388, 2024
2024 arXiv
-
[29]
Quantum noise pro- tects quantum classifiers against adversaries
Yuxuan Du, Min-Hsiu Hsieh, Tongliang Liu, Dacheng Tao, and Nana Liu. Quantum noise pro- tects quantum classifiers against adversaries. Physical Review Research, 3(2):023153, 2021
2021
-
[30]
Tsang et al
S. Tsang et al. Hybrid quantum-classical generative adversarial network for high resolution image generation. IEEE Transactions on Quantum Engineering , 4:3102419, 2023
2023
-
[31]
Wu et al
Y . Wu et al. Radio signal classification by adversarially robust quantum machine learning. arXiv:2312.07821, 2023
2023 arXiv
-
[32]
Khatun et al
A. Khatun et al. Quantum transfer learning with adversarial robustness for classification of high-resolution image datasets. Adv. Quant. Technol., page 2400268, 2024
2024
-
[33]
West, Jamie Heredge, Martin Sevior, and Muhammad Usman
Maxwell T. West, Jamie Heredge, Martin Sevior, and Muhammad Usman. Provably trainable rotationally equivariant quantum machine learning. PRX Quantum, 5:030320, Jul 2024
2024
-
[34]
Reflection equivariant quantum neu- ral networks for enhanced image classification
Maxwell T West, Martin Sevior, and Muhammad Usman. Reflection equivariant quantum neu- ral networks for enhanced image classification. Machine Learning: Science and Technology , 4(3):035027, aug 2023
2023
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.