Measurement Cost of Quantum Gradient Attacks
Abstract
Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers. We show that finite quantum measurement statistics, that is, shot noise, act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker. Because every gradient component must be inferred from repeated circuit executions under any unbiased gradient-estimation rule, white-box extraction consumes a dimension-dependent measurement budget that measurement grouping cannot remove in expressive circuits. We establish, under stated assumptions, that single-step attacks need at least quadratically many shots in the input dimension _d_ , growing as _d_[5] _[/]_[2] under norm-concentration scaling, with a sufficient-budget analysis for iterative attacks via stochastic gradient Langevin dynamics. Simulations up to 784 input dimensions validate the law: the realized total budget is the _d_[5] _[/]_[2] geometric floor for plateau-mitigated models and grows as _d_[3] _[.]_[00] for the tested deep circuits, whose gradient norms decay with dimension absent barren-plateau mitigation; folding the measured gradient norm back in per sample recovers the parameter-free _d_[3] _[/]_[2] shot-noise geometry (measured _d_[1] _[.]_[46] ). Against a matched classical baseline whose attack overhead is dimension-independent (the cheapgradient principle of automatic differentiation), the quantum _gradient cost ratio_ , a gradients cost in forward-inference units, grows polynomially, empirically as _d_[3] _[.]_[00] , so the attackers relative cost diverges as the model scales. On a 156-qubit IBM processor ( `ibm_boston` , 4-qubit circuits, _d_ =12), a simulatorhardware comparison over a 100-input cohort reproduces the effect, the device attack tracking the ideal within a few percent at matched budgets, with the high-shot gradient faithful to the exact one (cohort-median cosine 0 _._ 98, mean 0 _._ 90). The experiments establish the _scaling law_ of measurement-based gradient extraction; its defensive consequence operates precisely when the forward map is classically hard to simulate, since only then is a white-box attacker denied the simulate-and-backpropagate shortcut and must pay the measurement cost we quantify.