VQE Adversarial Robustness
Abstract
The Variational Quantum Eigensolver (VQE) is a leading algorithm for estimating molecular ground-state energies on near-term quantum hardware, with applications spanning quantum chemistry, materials science, and drug discovery. As VQE workloads are increasingly deployed through cloud-based VQE-as-a-service pipelines, they become exposed to adversaries such as compromised service components, malicious cotenants, or insiders in the transpilation stack, any of which can corrupt results before they reach the user. A range of attacks on variational quantum circuits has been proposed, but each has been studied in isolation: some on quantum classifiers with accuracy-based metrics, others on variational quantum algorithms with energy-error metrics. This lack of a common evaluation setup makes their relative severity difficult to compare and leaves the security of VQE poorly characterized. In this work, we present VQE-AdvBench, the first unified redteaming benchmark for the Variational Quantum Eigensolver, systematizing these attacks under a single evaluation protocol to rigorously assess VQEs adversarial robustness. We organize attacks along a black-, gray-, and white-box access taxonomy, and evaluate seven representative attack scenariosthe QTrojan circuit backdoor, the QDoor parameter backdoor, parameterspace adaptations of FGSM and PGD, and three QNBAD noiseinduced variantsover a fixed moleculeansatzbackendmetric configuration, on H** 2 **and H**[+] 3 **[across][five][noise-calibrated][IBM] backends. Our results reveal a clear severity ordering: noiseinduced attacks that manipulate the Zero-Noise Extrapolation (ZNE) pipeline are the most damaging (up to 8.84** __ ** error amplification), followed by the QTrojan circuit-level backdoor (7.52** __ **), while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification (up to 1.37** __ **).