Experiments show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, suggesting effectiveness, stealthiness, and input specificity, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.
Abstract
Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Studies have shown that QNNs are vulnerable to backdoor attacks, yet existing quantum backdoors mostly rely on a fixed trigger shared by all poisoned inputs. This fixed-trigger design is a major weakness because many defenses detect or weaken the repeated patterns such triggers leave in data representations. Although input-aware dynamic backdoors have been studied in classical neural networks, transferring them to QNNs is difficult because quantum learning introduces new obstacles. In particular, measurement compresses the post-ansatz quantum state into a limited classical output, weakening supervision for a trigger generator, while individual density matrices fluctuate with the input and make per-sample contrastive learning unstable. To address these challenges, we propose Q-DIBA, the first input-aware dynamic backdoor attack for QNNs. Q-DIBA jointly trains a classical trigger generator and a victim QNN through a three-mode mini-batch strategy that supports clean behavior, attack activation, and trigger specificity. To provide stable quantum-level supervision, Q-DIBA introduces an ensemble density contrastive loss that operates on post-ansatz quantum states before measurement and contrasts mode-averaged density matrices rather than individual samples. Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show that Q-DIBA achieves high clean accuracy, strong attack success, and high cross-trigger accuracy, demonstrating effectiveness, stealthiness, and input specificity. The attack also remains resilient against defenses including visual inspection, spectral-signature detection, and fine-tuning, suggesting that input-aware quantum backdoors are an important threat to secure QNN deployment.
CutBackdoor is presented, the first parameter-supply-chain backdoor that uses cut circuit execution from CutQC as the deployment-time trigger against VQAs, and poisoned parameters preserve full-circuit validation performance while substantially increasing cut-path reconstruction error under noisy finite-shot circuit-cut execution.
Ahatesham Bhuiyan, Hoang M. Ngo, Cheng Chu et al.· arXiv.org· 0 citations
Among five evaluated methods used in the quantum unlearning phase of the framework, GA, SCRUB, and Continued Fine-Tuning recover accuracy to within 10% of the clean baseline for poison ratios up to ε⩽0.5, with CF achieving this at roughly half the computational cost of the gradient-based alternatives.
Quantum machine learning (QML) is emerging as a key enabler of next-generation artificial intelligence (AI), offering more compact models and enhanced data processing capabilities. However, the integration of QML into AI-enabled network services can introduce new adversarial vulnerabilities, particularly the interface between classical encoders and quantum variational circuits. In this work, we investigate the susceptibility of QML-assisted signal classifiers to adversarial threats in the open radio access network (O-RAN) platforms. We introduce a new family of adversarial attacks, including a novel hybrid quantum-classical poisoning method (QC-Poison), along with hybrid gradient-based attacks (QC-FGSM and QC-PGD). QC-Poison induces long-term misclassification by injecting subtle adversarial, accumulating perturbations in the classical input space that propagate through the quantum encoder, effectively drifting the model’s decision boundary. Evaluation results show that QC-FGSM perturbs inputs based on the hybrid model’s gradients, reducing accuracy from 95.5% to 55.8%, while QC-PGD shows model’s performance reduction to 16.0% by iteratively corrupting quantum circuit parameters via loss maximization. QC-Poison achieves 23.9% accuracy under tight perturbation constraints without accessing training data or internal quantum parameters. The results expose critical blind spots in existing hybrid QML models that can be extended to AI-based features in the O-RAN core services. The study underscores the need for robust quantum-aware defenses that can mitigate stealthy adversarial attacks in distributed and QML-assisted applications in intelligent RAN.
V. Nguyen, Yared Abera Ergu· IEEE Transactions on Network...· 0 citations
The framework provides a pragmatic, classifier-agnostic defense layer deployable on freely accessible cloud platforms (Google Colab) without specialized quantum hardware, and offers viable post-quantum hardening for security-critical applications.
Soha Rawas, Mohammed Al Saleh, A. D. Samala et al.· Applied Computing and Inform...· 0 citations
A dynamic evolutionary attack detection scheme for practical QKD, in which Eve’s attack feature could be vectorized by a well-designed embedding model and dynamically self-update to an attack feature vector database, which significantly improves the generalization capability of quantum attack detection and promotes the practical development of QKD.
Minjie Liu, Ye Chen, Xiaodong Fan et al.· Science China Information Sc...· 0 citations
The proposed framework can improve threat detection and system resilience in critical infrastructure contexts and support the use of kernel-based quantum-inspired representations as a tunable early-warning layer for PSAP traffic monitoring, while also showing that threshold calibration and operational context remain necessary before deployment.
Carlos B. Rosa-Remedios, P. Caballero-Gil, J. Molina-Gil· Computers, Materials & C...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.