Noise-induced attacks that manipulate the Zero-Noise Extrapolation pipeline are the most damaging, followed by the QTrojan circuit-level backdoor, while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification.
Abstract
The Variational Quantum Eigensolver (VQE) is a leading algorithm for estimating molecular ground-state energies on near-term quantum hardware, with applications spanning quantum chemistry, materials science, and drug discovery. As VQE workloads are increasingly deployed through cloud-based ``VQE-as-a-service''pipelines, they become exposed to adversaries such as compromised service components, malicious co-tenants, or insiders in the transpilation stack, any of which can corrupt results before they reach the user. A range of attacks on variational quantum circuits has been proposed, but each has been studied in isolation: some on quantum classifiers with accuracy-based metrics, others on variational quantum algorithms with energy-error metrics. This lack of a common evaluation setup makes their relative severity difficult to compare and leaves the security of VQE poorly characterized. In this work, we present \textbf{VQE-AdvBench}, the first unified red-teaming benchmark for the Variational Quantum Eigensolver, systematizing these attacks under a single evaluation protocol to rigorously assess VQE's adversarial robustness. We organize attacks along a black-, gray-, and white-box access taxonomy, and evaluate seven representative attack scenarios -- the QTrojan circuit backdoor, the QDoor parameter backdoor, parameter-space adaptations of FGSM and PGD, and three QNBAD noise-induced variants -- over a fixed molecule-ansatz-backend-metric configuration, on H$_2$ and H$_3^+$ across five noise-calibrated IBM backends. Our results reveal a clear severity ordering: noise-induced attacks that manipulate the Zero-Noise Extrapolation (ZNE) pipeline are the most damaging (up to 8.84$\times$ error amplification), followed by the QTrojan circuit-level backdoor (7.52$\times$), while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification (up to 1.37$\times$).
CutBackdoor is presented, the first parameter-supply-chain backdoor that uses cut circuit execution from CutQC as the deployment-time trigger against VQAs, and poisoned parameters preserve full-circuit validation performance while substantially increasing cut-path reconstruction error under noisy finite-shot circuit-cut execution.
Ahatesham Bhuiyan, Hoang M. Ngo, Cheng Chu et al.· arXiv.org· 0 citations
This work reveals and exploits this underexplored robustness property: how much non-Clifford and variational expressivity can be removed from the sampling circuit before SQD accuracy degrades, and answers through two complementary compression techniques: gradient-based operator pruning, which discards low-impact excitation operators, and Clifford rounding, which snaps remaining parameters to the nearest Clifford angle.
Kangyu Zheng, Yidong Zhou, Jinglei Cheng et al.· 0 citations
Quantum machine learning (QML) is emerging as a key enabler of next-generation artificial intelligence (AI), offering more compact models and enhanced data processing capabilities. However, the integration of QML into AI-enabled network services can introduce new adversarial vulnerabilities, particularly the interface between classical encoders and quantum variational circuits. In this work, we investigate the susceptibility of QML-assisted signal classifiers to adversarial threats in the open radio access network (O-RAN) platforms. We introduce a new family of adversarial attacks, including a novel hybrid quantum-classical poisoning method (QC-Poison), along with hybrid gradient-based attacks (QC-FGSM and QC-PGD). QC-Poison induces long-term misclassification by injecting subtle adversarial, accumulating perturbations in the classical input space that propagate through the quantum encoder, effectively drifting the model’s decision boundary. Evaluation results show that QC-FGSM perturbs inputs based on the hybrid model’s gradients, reducing accuracy from 95.5% to 55.8%, while QC-PGD shows model’s performance reduction to 16.0% by iteratively corrupting quantum circuit parameters via loss maximization. QC-Poison achieves 23.9% accuracy under tight perturbation constraints without accessing training data or internal quantum parameters. The results expose critical blind spots in existing hybrid QML models that can be extended to AI-based features in the O-RAN core services. The study underscores the need for robust quantum-aware defenses that can mitigate stealthy adversarial attacks in distributed and QML-assisted applications in intelligent RAN.
V. Nguyen, Yared Abera Ergu· IEEE Transactions on Network...· 0 citations
It is shown that finite quantum measurement statistics (shot noise) act as a built-in defense against gradient-based test-time attacks whose cost scales unfavorably for the attacker.
Bacui Li, Chandra Thapa, Tansu Alpcan et al.· 0 citations
This work employs the Bures metric as a local preconditioner and uses the mean Uhlmann curvature to develop an achievable-precision aggregation rule that dynamically down-weights unreliable clients and establishes theoretical guarantees by proving a convergence theorem and a variance-dominance proposition.
Quantum machine learning (QML) faces practical limitations due to noisy intermediate-scale quantum (NISQ) constraints, including noise, restricted qubit availability, and unstable optimization. This paper proposes HyQNet, a resource-aware hybrid quantum–classical framework designed to address these challenges through efficient circuit execution and adaptive optimization. The framework integrates optimized quantum circuits with classical learning strategies to improve scalability and stability under NISQ conditions. Experimental results on Iris, Wine, and Breast Cancer datasets show that HyQNet achieves an accuracy of 95.1% and F1-score of 94.8%, outperforming variational QNN (92.6%) and quantum SVM (91.2%). It also reduces runtime to 16.9 s compared to 20.5 s for VQNN, while maintaining efficient utilization of 8 qubits. Statistical analysis confirms significance (p < 0.05), and ablation studies validate the contribution of each component. The results demonstrate improved convergence stability and resource efficiency in hybrid quantum learning systems.
Sudheer Reddy K., Hastimal Jangid, Usha Desai· 2026 International Conferenc...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.