[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-123980-en":3,"doc-seo-123980-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},123980,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",8,"Research & Report","A Comparative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning Models - arXiv 2404.16154 - research overview","Adversarial robustness is systematically compared between quantum machine learning (QML) and classical machine learning (ML) models. The study investigates similarities and differences using transfer attacks, perturbation patterns, and Lipschitz bounds, focusing on classification on a handcrafted dataset enabling quantitative feature attribution. Typical QML architectures (amplitude and re-upload encoding with variational parameters) are compared with a classical ConvNet, and a classically approximated Fourier network is evaluated as a quantum-classical middle ground. Results show adversarial transfer across the boundary in both directions, while regularization improves robustness in quantum networks, affecting Lipschitz bounds and transfer behavior.","A Comparative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning  \nModels  \narXiv :2404 . 16154v1 [ cs .LG] 24 Apr 2024  \nMaximilian Wendlinger∗†, Kilian Tscharke∗ , Pascal Debus∗  \n∗ Quantum Security Technologies  \nFraunhofer Institute for Applied and Integrated Security Garching near Munich, Germany  \n† Technical University of Munich  \n[maxi.wendlinger@tum.de](maxi.wendlinger@tum.de), {kilian.tscharke, pascal.debus}@aisec.fraunhofer.de  \nAbstract—Quantum machine learning (QML) continues to bean area of tremendous interest from research and industry. While QML models have been shown to be vulnerable to adversarial attacks much in the same manner as classical machine learning models, it is still largely unknown how to compare adversarial attacks on quantum versus classical models. In this paper, we show how to systematically investigate the similarities and differences in adversarial robustness of classical and quantum models using transfer attacks, perturbation patterns and Lipschitz bounds. More specifically, we focus on classification tasks on a handcrafted dataset that allows quantitative analysis for feature attribution. This enables us to get insight, both theoretically and experimentally, on the robustness of classification networks. Westart by comparing typical QML model architectures such as amplitude and re-upload encoding circuits with variational parameters to a classical ConvNet architecture. Next, we introduce a classical approximation of QML circuits (originally obtained with Random Fourier Features sampling but adapted in this work to fit a trainable encoding) and evaluate this model, denoted Fourier network, in comparison to other architectures. Our findings show that this Fourier network can be seen as a “middle ground”on the quantum-classical boundary. While adversarial attacks successfully transfer across this boundary in both directions, we also show that regularization helps quantum networks to be more robust, which has direct impact on Lipschitz bounds and transfer attacks.  \nIndex Terms—Adversarial robustness, Feature attribution, Lipschitz bounds, Quantum machine learning, Transfer attacks  \nI. INTRODUCTION  \nQuantum machine learning (QML) offers the potential to expand the current frontiers of many fields in computational technologies [1], with its power to leverage quantummechanical effects such as entanglement and high-dimensional latent spaces paired with insights from classical machine learning (ML) . As a result, recent years have seen an immense research interest in different possibilities to leverage these effects for practical challenges. Most prominently, this includes parameterized quantum circuit (PQC) architectures that allow for the training of variational parameters inside the quantum circuit in order to fit a specific function for classification or regression tasks. It has been shown that although results from quantum variational classifiers look promising, the models  \ncan be fooled with carefully crafted modifications of the input samples [2] . These adversarial perturbations, allowing an attacker to force a high misprediction rate in the attacked model, are investigated in the emerging field called quantum adversarial machine learning (QAML) . For classical machine learning approaches, adversarial attacks have been rigorously explored, opening the door for research to find similarities and differences between adversarial attacks on classical and quantum machine learning architectures.  \nIn an effort to make the first steps in this direction, West et al. [3] investigate the behavior of different classical and quantum ML models under adversarial attacks and the resulting perturbation patterns in the input. Interestingly, the authors found that classical attacks fail to transfer to the PQC architecture while attacks originally designed for the quantum model seem to work for classical ML models. In this light, the authors suspected a ”quantum supremacy” in adve","cbCaiqhsGtF5DZ11","https://ap.wps.com/l/cbCaiqhsGtF5DZ11","pdf",1050877,1,11,"English","en",105,"# Introduction\n# Related Work","[{\"question\":\"本文如何比较量子与经典模型的对抗鲁棒性？\",\"answer\":\"通过迁移攻击、扰动模式以及Lipschitz界进行系统对比，并在同一类分类任务与数据集上评估差异。\"},{\"question\":\"研究主要使用哪些模型架构进行实验对照？\",\"answer\":\"包括典型QML结构（如幅度与重上传编码电路）、经典ConvNet，以及对QML电路进行经典近似得到的Fourier network。\"},{\"question\":\"对抗样本能否跨越量子—经典边界迁移？\",\"answer\":\"可以。攻击在量子与经典之间双向迁移成功，表明两类模型之间存在一定可转移性。\"},{\"question\":\"正则化在量子模型鲁棒性中起到什么作用？\",\"answer\":\"正则化能提升量子网络的鲁棒性，并进一步影响Lipschitz界与迁移攻击效果。\"}]","A Comparative Analysis of Adversarial Robustness for Quantum and Classical Machine Learning Models - arXiv 2404.16154 - research overview | PDF",1785819572,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"a-comparative-analysis-of-adversarial-robustness-for-quantum-and-classical-machine-learning-models-arxiv-240416154-research-overview","",{"@graph":36,"@context":89},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-comparative-analysis-of-adversarial-robustness-for-quantum-and-classical-machine-learning-models-arxiv-240416154-research-overview/123980/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"本文如何比较量子与经典模型的对抗鲁棒性？","Question",{"text":75,"@type":76},"通过迁移攻击、扰动模式以及Lipschitz界进行系统对比，并在同一类分类任务与数据集上评估差异。","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"研究主要使用哪些模型架构进行实验对照？",{"text":80,"@type":76},"包括典型QML结构（如幅度与重上传编码电路）、经典ConvNet，以及对QML电路进行经典近似得到的Fourier network。",{"name":82,"@type":73,"acceptedAnswer":83},"对抗样本能否跨越量子—经典边界迁移？",{"text":84,"@type":76},"可以。攻击在量子与经典之间双向迁移成功，表明两类模型之间存在一定可转移性。",{"name":86,"@type":73,"acceptedAnswer":87},"正则化在量子模型鲁棒性中起到什么作用？",{"text":88,"@type":76},"正则化能提升量子网络的鲁棒性，并进一步影响Lipschitz界与迁移攻击效果。","https://schema.org",{"og:url":52,"og:type":91,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":93,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":96},[97,101,105,109,114,119,124,127,132,135,139],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},6,"Technology",50,"technology",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":125,"slug":126},30,"research-report",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},9,"Religion & Spirituality",20,"religion-spirituality",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":130,"slug":134},"World Cup","world-cup",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":136,"slug":138},10,"Lifestyle","lifestyle",{"id":140,"doc_module":4,"doc_module_name":46,"category_name":141,"show_sort_weight":110,"slug":142},19,"General","general"]