Skip to content
Open access

Self-revealing poisons: loss-guided forensic detection and quantum unlearning of corrupted training data

Aug 2026 · Physica Scripta · Vol 101 · 0 citations · 32 references
Physics

TL;DR

Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives.

Abstract

Quantum Computation has entered the Noisy Intermediate State Quantum era, in which quantum machine learning (QML) models built on parameterized quantum circuits are promptly utilized for real-world classification tasks, optimization and simulations because of quantum inherent properties like superposition and entanglement. Despite having such use cases, QML model’s security under adversarial conditions remains poorly understood. One such threat is data poisoning, in which an attacker corrupts the training set before the model ever sees it. Such an attack is escalated further in quantum settings by QUantum Indiscriminate Data Poisoning, which exploits the geometry of the quantum feature space. To address it, this paper proposes a self-revealing defense framework built on a two-stage pipeline. The first stage identifies potential corrupted data points using unsupervised hybrid kmeans_gmm threshold derived from a clean reference model, enabling reliable detection without requiring any prior knowledge of the underlying attack. The second stage uses the detected samples to guide a quantum unlearning process that removes the influence of corrupted data and restores model integrity. All experiments were carried out on simulations (no real quantum hardware is utilized). Experimentation on the MNIST-4 dataset using PQC-8 confirms the attack is self-revealing, as poisoning intensifies the detection PR-AUC climbs from 0.956 to over 0.999, while receiver operating characteristic AUC remains ⩾0.986 throughout, achieving a robust detection and clear separability between clean and poisoned samples. Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning (CF) recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives. Additional experiments on classical baseline further reveals the proposed framework being paradigm agnostic.

Read PDF

Similar papers

Preprint Jul 2026

Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Studies have shown that QNNs are vulnerable to backdoor attacks, yet existing quantum backdoors mostly rely on a fixed trigger shared by all poisoned inputs. This fixed-trigger design is a major weakness because many defenses detect or weaken the repeated patterns such triggers leave in data representations. Although input-aware dynamic backdoors have been studied in classical neural networks, transferring them to QNNs is difficult because quantum learning introduces new obstacles. In particular, measurement compresses the post-ansatz quantum state into a limited classical output, weakening supervision for a trigger generator, while individual density matrices fluctuate with the input and make per-sample contrastive learning unstable. To address these challenges, we propose Q-DIBA, the first input-aware dynamic backdoor attack for QNNs. Q-DIBA jointly trains a classical trigger generator and a victim QNN through a three-mode mini-batch strategy that supports clean behavior, attack activation, and trigger specificity. To provide stable quantum-level supervision, Q-DIBA introduces an ensemble density contrastive loss that operates on post-ansatz quantum states before measurement and contrasts mode-averaged density matrices rather than individual samples. Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, demonstrating effectiveness, stealthiness, and input specificity. The attack also remains resilient against defenses including visual inspection, spectral-signature detection, and fine-tuning, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.

Junrui Zhang, Zemin Chen, Lusi Li et al. · 0 citations
2026

Adversarial Attacks on Hybrid Quantum-Classical Interference Classifier in Intelligent O-RAN

Quantum machine learning (QML) is emerging as a key enabler of next-generation artificial intelligence (AI), offering more compact models and enhanced data processing capabilities. However, the integration of QML into AI-enabled network services can introduce new adversarial vulnerabilities, particularly the interface between classical encoders and quantum variational circuits. In this work, we investigate the susceptibility of QML-assisted signal classifiers to adversarial threats in the open radio access network (O-RAN) platforms. We introduce a new family of adversarial attacks, including a novel hybrid quantum-classical poisoning method (QC-Poison), along with hybrid gradient-based attacks (QC-FGSM and QC-PGD). QC-Poison induces long-term misclassification by injecting subtle adversarial, accumulating perturbations in the classical input space that propagate through the quantum encoder, effectively drifting the model’s decision boundary. Evaluation results show that QC-FGSM perturbs inputs based on the hybrid model’s gradients, reducing accuracy from 95.5% to 55.8%, while QC-PGD shows model’s performance reduction to 16.0% by iteratively corrupting quantum circuit parameters via loss maximization. QC-Poison achieves 23.9% accuracy under tight perturbation constraints without accessing training data or internal quantum parameters. The results expose critical blind spots in existing hybrid QML models that can be extended to AI-based features in the O-RAN core services. The study underscores the need for robust quantum-aware defenses that can mitigate stealthy adversarial attacks in distributed and QML-assisted applications in intelligent RAN.

V. Nguyen, Yared Abera Ergu · 0 citations
Preprint Jul 2026

When cheap gradients fail: the measurement cost of attacking quantum classifiers

It is shown that finite quantum measurement statistics (shot noise) act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker.

Bacui Li, Chandra Thapa, Tansu Alpcan et al. · 0 citations
Aug 2026

Dynamically quantum attack detection for quantum key distribution based on deep representations

A dynamic evolutionary attack detection scheme for practical QKD, in which Eve’s attack feature could be vectorized by a well-designed embedding model and dynamically self-update to an attack feature vector database, which significantly improves the generalization capability of quantum attack detection and promotes the practical development of QKD.

Minjie Liu, Ye Chen, Xiaodong Fan et al. · 0 citations
Open access Jul 2026

Beyond encryption: quantum-enhanced behavioral security for the post-quantum era

The framework provides a pragmatic, classifier-agnostic defense layer deployable on freely accessible cloud platforms (Google Colab) without specialized quantum hardware, and offers viable post-quantum hardening for security-critical applications.

Soha Rawas, Mohammed Al Saleh, Agariadne Dwinggo Samala et al. · 0 citations
Open access 2026

Hybrid Quantum-Kernel and Quantum-Inspired Machine Learning for TDoS Early Warning in Critical Infrastructure

The proposed framework can improve threat detection and system resilience in critical infrastructure contexts and support the use of kernel-based quantum-inspired representations as a tunable early-warning layer for PSAP traffic monitoring, while also showing that threshold calibration and operational context remain necessary before deployment.

Carlos B. Rosa-Remedios, P. Caballero-Gil, J. Molina-Gil · 0 citations