Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query Access
Ji Guan, Mingyu Huang
Abstract
A quantum classifier assigns labels by evolving an input quantum state and measuring the output, so repeated executions reveal only a distribution over labels. We study certified adversarial robustness for such classifiers under known-readout query access (KRQA), where an evaluator can prepare inputs, knows the quantum measurement, and observes finite-shot outcomes but cannot inspect the internal evolution, parameters, or gradients. We give a measurement-only framework that returns two complementary guarantees for each input: a lower bound ruling out untargeted errors within a radius, and an attack-independent upper bound witnessing an adversarial state within a radius. Both are estimable from the known readout measurement and sampled outcomes, require no tomography or circuit description, and have finite-sample control of probability-estimation error. The upper bound uses gap operators induced by the quantum measurement; the lower bound relaxes state-space search to an efficient optimization over outcome distributions with operator-spectrum constraints, yielding certificates that are never weaker than prior probability-only certificates and can be strictly stronger when the spectral constraints are active. On tractable instances, we compare the lower bound with numerical white-box reference estimates; across multiple classifiers, the upper bound remains informative when standard attacks fail. We further demonstrate real-device feasibility on IBM Quantum hardware: from 40 executions of two 8-qubit quantum neural networks, our method estimates both bounds, with the expected lower-upper ordering on every tested input. Taken together, these results show that robustness claims for quantum classifiers can be audited directly from observable statistics under KRQA.
Create a lesson
Related papers
Parallel quantum channel discrimination and numerical ranges in tensor product subspaces
Adam Bílek, Paulina Lewandowska, Ryszard Kukulski
Asymptotically Good Quantum Locally Testable Codes
William Gay, Fernando Granha Jeronimo
All causally separable quantum processes are quantum circuits with classical control of causal order
Julian Wechs, Alastair A. Abbott, Cyril Branciard
Analytic leakage suppression with a single control field: fast two-qubit gates with tunable couplers
Lukas Heunisch, Michael J. Hartmann, Aashish A. Clerk
Procrastinating einselection in non-Markovian quantum dynamics
Michael J. Moody, Tara Kalsi, Agung Budiyono et al.
Quantum Entropy Contraction and Factorization from Hypercontractivity
Li Gao, Lijun Wang