Measurement Cost of Quantum Gradient Attacks

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Adversarial perturbations threaten machine learning classifiers, including variational quantum classifiers. We show that finite quantum measurement statistics, that is, shot noise, act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker. Because every gradient component must be inferred from repeated circuit executions under any unbiased gradient-estimation rule, white-box extraction consumes a dimension-dependent measurement budget that measurement grouping cannot remove in expressive circuits. We establish, under stated assumptions, that single-step attacks need at least quadratically many shots in the input dimension _d_ , growing as _d_[5] _[/]_[2] under norm-concentration scaling, with a sufficient-budget analysis for iterative attacks via stochastic gradient Langevin dynamics. Simulations up to 784 input dimensions validate the law: the realized total budget is the _d_[5] _[/]_[2] geometric floor for plateau-mitigated models and grows as _d_[3] _[.]_[00] for the tested deep circuits, whose gradient norms decay with dimension absent barren-plateau mitigation; folding the measured gradient norm back in per sample recovers the parameter-free _d_[3] _[/]_[2] shot-noise geometry (measured _d_[1] _[.]_[46] ). Against a matched classical baseline whose attack overhead is dimension-independent (the cheapgradient principle of automatic differentiation), the quantum _gradient cost ratio_ , a gradients cost in forward-inference units, grows polynomially, empirically as _d_[3] _[.]_[00] , so the attackers relative cost diverges as the model scales. On a 156-qubit IBM processor ( `ibm_boston` , 4-qubit circuits, _d_ =12), a simulatorhardware comparison over a 100-input cohort reproduces the effect, the device attack tracking the ideal within a few percent at matched budgets, with the high-shot gradient faithful to the exact one (cohort-median cosine 0 _._ 98, mean 0 _._ 90). The experiments establish the _scaling law_ of measurement-based gradient extraction; its defensive consequence operates precisely when the forward map is classically hard to simulate, since only then is a white-box attacker denied the simulate-and-backpropagate shortcut and must pay the measurement cost we quantify.

Loading executive summary...

LINK COPIED TO CLIPBOARD