Skip to content

Securing quantum error correction against misleading advice from AI agents

Sep 2026 · 0 citations
Physics Computer Science Engineering

TL;DR

The results identify information required for recovery selection, establish conditional guarantees against harmful updates, and quantify the recovery improvements forgone through conservative acceptance.

Abstract

Can an attacker turn influence over an artificial intelligence (AI) adviser into a harmful quantum error-correction update? We identify an ambiguity in passive syndrome records that obstructs recovery selection, then show how additional calibration measurements support certified recovery updates under uncertainty and drift. In an odd-distance square toric code with error-free preparation, syndrome measurements, and recovery operations, opposite coherent $X$ rotations produce identical passive syndrome-history distributions. Yet a fixed phase correction can help at one sign and harm at the other. A terminal logical measurement on known encoded calibration states supplies the missing sign information. A separate evaluator accepts an update only when calibration uncertainty and a justified drift bound certify improvement over the current recovery, without assuming that the adviser recommends correctly. In simulated advice attacks, calibration-confidence checks reject harmful proposals while retaining beneficial updates under honest advice. We derive sufficient limits on calibration age that require improvement through deployment. In matched simulations, a validated channel-specific bound retains more beneficial updates than the general bound after accounting for evaluation time, while preventing the tested harmful activations under the stated drift assumption. A separate surface-code experiment includes stochastic circuit faults and noise changing during acquisition. Deterministic controllers achieve at least as many beneficial updates with the same observations. Violating the drift assumption permits harmful acceptance in the toric experiment. The results identify information required for recovery selection, establish conditional guarantees against harmful updates, and quantify the recovery improvements forgone through conservative acceptance.

View source

Similar papers

Preprint Aug 2026

Decoder-Prior Poisoning in Quantum Error Correction: Attacks and PriorGuard Defense

Quantum error correction (QEC) protects quantum computations by repeatedly measuring stabilizer syndromes and using a classical decoder to infer corrections. Modern surface-code decoders are increasingly calibration-aware: they use recent device behavior to set priors such as matching-graph edge probabilities, and thes...

Xin-Yi Li, Yi-Feng Peng, Jun-Tao Chen et al. · 0 citations
Preprint Aug 2026

Provably Efficient Self-Calibrating Quantum Fault Tolerance

Quantum error correction protects logical information only when every physical operation remains below the fault-tolerance threshold, a condition that must be maintained continuously rather than only at the initial calibration. In practice, however, analog control parameters inevitably drift because of environmental fl...

Weiyuan Gong, Hong-Ye Hu · 0 citations
#artificial intelligence Preprint Sep 2026

Audit-First VAPO: Risk-Certified Selective Updates under Imperfect Verification

This work introduces Audit-First VAPO, which separates discrete directional admission from continuous magnitude control, and evaluates two models on two reasoning benchmarks against static RLVR, matched-random selection, confidence thresholding, noise correction, and verifier augmentation.

Miao-Bo Hu, Shu-Hao Hu, Xiao-Bo Guo et al. · 0 citations
Preprint Sep 2026

Conditional validity of quantum event classifiers under collider systematics and quantum estimation uncertainty

Claims about a deployed quantum machine-learning classifier can fail when target data shift or when finite-shot quantum evaluation randomizes the model itself. We develop an information-conditional, fail-closed auditing framework that returns supported, refuted or unresolved verdicts with anytime-valid per-claim error...

Roberto Fernández-Barrios, Iker Pastor-López, Asier Gonzalez-Santocildes et al. · 2 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.