Author

Himani Trivedi

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

Self-revealing poisons: loss-guided forensic detection and quantum unlearning of corrupted training data

Quantum Computation has entered the Noisy Intermediate State Quantum era, in which quantum machine learning (QML) models built on parameterized quantum circuits are promptly utilized for real-world classification tasks, optimization and simulations because of quantum inherent properties like superposition and entanglement. Despite having such use cases, QML model’s security under adversarial conditions remains poorly understood. One such threat is data poisoning, in which an attacker corrupts the training set before the model ever sees it. Such an attack is escalated further in quantum settings by QUantum Indiscriminate Data Poisoning, which exploits the geometry of the quantum feature space. To address it, this paper proposes a self-revealing defense framework built on a two-stage pipeline. The first stage identifies potential corrupted data points using unsupervised hybrid kmeans_gmm threshold derived from a clean reference model, enabling reliable detection without requiring any prior knowledge of the underlying attack. The second stage uses the detected samples to guide a quantum unlearning process that removes the influence of corrupted data and restores model integrity. All experiments were carried out on simulations (no real quantum hardware is utilized). Experimentation on the MNIST-4 dataset using PQC-8 confirms the attack is self-revealing, as poisoning intensifies the detection PR-AUC climbs from 0.956 to over 0.999, while receiver operating characteristic AUC remains ⩾0.986 throughout, achieving a robust detection and clear separability between clean and poisoned samples. Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning (CF) recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives. Additional experiments on classical baseline further reveals the proposed framework being paradigm agnostic.

Oum Gadani, Kandarp Gajjar, Himani Trivedi et al. · 0 citations