[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119170-en":3,"doc-seo-119170-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119170,8796095461564,"Liam","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Prospects of Privacy Advantage in Quantum Machine Learning - Research paper overview - key results","Privacy protection in machine learning becomes especially critical in distributed settings where collaborators typically share gradients to enable joint training. This study asks how difficult it is to reconstruct original inputs from gradients of quantum machine learning models, using variational quantum circuits as learning models. The work identifies the dynamical Lie algebra of the VQC ansatz as a driver of privacy vulnerabilities, characterizing weak snapshot breaches and strong input-recovery breaches, and deriving encoding-map conditions that govern when privacy advantage can be realized.","arXiv :2405 .08801v2 [ quant-ph] 15 May 2024  \nProspects of Privacy Advantage in Quantum Machine Learning  \nJamie Heredge, 1, 2 Niraj Kumar, 1, ∗ Dylan Herman, 1 Shouvanik Chakrabarti, 1 Romina Yalovetzky, 1 Shree Hari Sureshbabu, 1 Changhao Li, 1 and Marco Pistoia 1  \n1 Global Technology Applied Research, JPMorgan Chase, New York, NY 10017  \n2 School of Physics, The University of Melbourne, Parkville, VIC 3010, Australia (Dated: May 19, 2024)  \nEnsuring data privacy in machine learning models is critical, particularly in distributed settings where model gradients are typically shared among multiple parties to allow collaborative learning. Motivated by the increasing success of recovering input data from the gradients of classical models, this study addresses a central question: How hard is it to recover the input data from the gradients of quantum machine learning models? Focusing on variational quantum circuits (VQC) as learning models, we uncover the crucial role played by the dynamical Lie algebra (DLA) of the VQC ansatz in determining privacy vulnerabilities. While the DLA has previously been linked to the classical simulatability and trainability of VQC models, this work, for the first time, establishes its connection to the privacy of VQC models. In particular, we show that properties conducive to the trainability of VQCs, such as a polynomial-sized DLA, also facilitate the extraction of detailed snapshots of the input. We term this a weak privacy breach, as the snapshots enable training VQC models for distinct learning tasks without direct access to the original input. Further, we investigate the conditions for a strong privacy breach where the original input data can be recovered from these snapshots by classical or quantum-assisted polynomial time methods. We establish conditions on the encoding map such as classical simulatability, overlap with DLA basis, and its Fourier frequency characteristics that enable such a privacy breach of VQC models. Our findings thus play a crucial role in detailing the prospects of quantum privacy advantage by guiding the requirements for designing quantum machine learning models that balance trainability with robust privacy protection.  \nI. INTRODUCTION  \nIn the contemporary technological landscape, data privacy concerns command increasing attention, particularly within the domain of machine learning (ML) models that are trained on sensitive datasets. Privacy concerns are widespread in many different applications, including financial records [1, 2], healthcare information [3–5], and location data [6], each providing unique considerations. Furthermore, the multi-national adoption of stringent legal frameworks [7] has further amplified the urgency to improve data privacy.  \nThe introduction of distributed learning frameworks, such as federated learning [8–10], not only promises increased computational efficiency but also demonstrates the potential for increased privacy in ML tasks. In federated learning, each user trains a machine learning model, typically a neural network, locally on their device using their confidential data, meaning that they only need to send their model gradients to the central server, which aggregates gradients of all users to calculate the model parameters for the next training step. As the user does not send their confidential data, but rather their training gradients, this was proposed as the first solution to enable collaborative learning while preventing data leakage. However, subsequent works have shown that neural networks are particularly susceptible to gradient inversion-based attacks to recover the original input data [11–15] . To mitigate the above issue, classical techniques have been proposed to enhance the privacy of distributed learning models, ranging from gradient encryption-based methods [16], the addition of artificial noise in the gradients to leverage differential-privacy type techniques [10], or strategies involving the use of batch training t","cbCaitGGDDa5ExJR","https://ap.wps.com/l/cbCaitGGDDa5ExJR","pdf",1841605,1,28,"English","en",105,"# Introduction\n## Privacy risks in distributed machine learning\n## Gradient inversion attacks and classical mitigations\n## Quantum privacy advantage and central research question\n# Privacy breach model summary\n## Weak privacy breach: snapshot recovery\n## Strong privacy breach: snapshot inversion and input recovery","[{\"question\":\"这项研究的核心问题是什么？\",\"answer\":\"研究关注在获得量子机器学习模型的梯度后，重建原始输入数据到底有多困难。\"},{\"question\":\"变分量子电路的动力学李代数（DLA）在隐私漏洞中扮演什么角色？\",\"answer\":\"研究首次将DLA与量子模型的隐私联系起来，表明有利于可训练性的性质（如多项式规模的DLA）也会促进从梯度中提取输入快照。\"},{\"question\":\"“弱隐私泄露”和“强隐私泄露”有什么区别？\",\"answer\":\"弱隐私泄露对应可从快照得到的输入信息，使得无需原始输入也能为不同学习任务训练VQC；强隐私泄露进一步要求能够借助经典或量子辅助的多项式时间方法从快照恢复原始输入。\"}]","Prospects of Privacy Advantage in Quantum Machine Learning - Research paper overview - key results | PDF",1785722885,71,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"prospects-of-privacy-advantage-in-quantum-machine-learning-research-paper-overview-key-results","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/prospects-of-privacy-advantage-in-quantum-machine-learning-research-paper-overview-key-results/119170/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"这项研究的核心问题是什么？","Question",{"text":75,"@type":76},"研究关注在获得量子机器学习模型的梯度后，重建原始输入数据到底有多困难。","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"变分量子电路的动力学李代数（DLA）在隐私漏洞中扮演什么角色？",{"text":80,"@type":76},"研究首次将DLA与量子模型的隐私联系起来，表明有利于可训练性的性质（如多项式规模的DLA）也会促进从梯度中提取输入快照。",{"name":82,"@type":73,"acceptedAnswer":83},"“弱隐私泄露”和“强隐私泄露”有什么区别？",{"text":84,"@type":76},"弱隐私泄露对应可从快照得到的输入信息，使得无需原始输入也能为不同学习任务训练VQC；强隐私泄露进一步要求能够借助经典或量子辅助的多项式时间方法从快照恢复原始输入。","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]