Pith. sign in

REVIEW 1 cited by

Quantum Data Breach: Reusing Training Dataset by Untrusted Quantum Clouds

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.14687 v1 pith:J2KJN34A submitted 2024-07-19 quant-ph

classification quant-ph
keywords quantumtrainingdatalabelsmodelaccuracyapproxclouds
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Quantum computing (QC) has the potential to revolutionize fields like machine learning, security, and healthcare. Quantum machine learning (QML) has emerged as a promising area, enhancing learning algorithms using quantum computers. However, QML models are lucrative targets due to their high training costs and extensive training times. The scarcity of quantum resources and long wait times further exacerbate the challenge. Additionally, QML providers may rely on a third-party quantum cloud for hosting the model, exposing the models and training data. As QML-as-a-Service (QMLaaS) becomes more prevalent, reliance on third party quantum clouds can pose a significant threat. This paper shows that adversaries in quantum clouds can use white-box access of the QML model during training to extract the state preparation circuit (containing training data) along with the labels. The extracted training data can be reused for training a clone model or sold for profit. We propose a suite of techniques to prune and fix the incorrect labels. Results show that $\approx$90\% labels can be extracted correctly. The same model trained on the adversarially extracted data achieves approximately $\approx$90\% accuracy, closely matching the accuracy achieved when trained on the original data. To mitigate this threat, we propose masking labels/classes and modifying the cost function for label obfuscation, reducing adversarial label prediction accuracy by $\approx$70\%.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Quantum Quandaries: Unraveling Encoding Vulnerabilities in Quantum Neural Networks

    quant-ph 2025-02 reject novelty 4.0 of 10

    A white-box adversary can classify quantum ML encoding schemes from transpiled circuit features with about 95% accuracy, but the proposed random-gate obfuscation only drops accuracy to 42%, far above the 20% random baseline.

Pith tools