[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124720-en":3,"doc-seo-124720-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124720,8796095360427,"Lucas Martin","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",8,"Research & Report","QuMoS - A Framework for Preserving Security of Quantum Machine Learning Model","Security remains a critical challenge for machine learning applications, especially when model training is costly and enables model-stealing attacks. In quantum machine learning, stolen models are more vulnerable because common encryption methods like homomorphic encryption are not directly applicable to quantum computation. QuMoS addresses this by partitioning a full QML model into multiple parts and distributing them to several physically isolated quantum cloud providers, preventing attackers from reconstructing the complete model from any single compromised provider. A reinforcement learning-based security engine optimizes the distributed design to balance performance and security, yielding strong accuracy on four datasets while achieving the highest security versus baselines.","QuMoS: A Framework for Preserving Security of Quantum Machine Learning Model  \nZhepeng Wang†, § , Jinyang Li†, Zhirui Hu†, Blake Gage‡, Elizabeth Iwasawa‡, Weiwen Jiang†, §†George Mason University, Department of Electrical and Computer Engineering, VA, USA.  \n§ George Mason University, Quantum Science and Engineering Center, VA, USA.  \n‡Leidos, VA, USA.  \n{zwang48, [wjiang8](wjiang8}@gmu.edu)[}](wjiang8}@gmu.edu)[@gmu.edu](wjiang8}@gmu.edu)  \narXiv :2304 . 11511v2 [ quant-ph] 13 Oct 2023  \nAbstract—Security has always been a critical issue in machine learning (ML) applications. Due to the high cost of model training — such as collecting relevant samples, labeling data, and consuming computing power—model-stealing attack is oneof the most fundamental but vitally important issues. When it comes to quantum computing, such a quantum machine learning (QML) model-stealing attack also exists and is even more severe because the traditional encryption method, such as homomorphic encryption can hardly be directly applied to quantum computation. On the other hand, due to the limited quantum computing resources, the monetary cost of training QML model can be even higher than classical ones in the near term. Therefore, a well-tuned QML model developed by a third-party company can be delegated to a quantum cloud provider as a service to be used by ordinary users. In this case, the QML model is likely to be leaked if the cloud provider is under attack. To address such a problem, we propose a novel framework, namely QuMoS, to preserve model security. Instead of applying encryption algorithms, we propose to divide the complete QML model into multiple parts and distribute them to multiple physically isolated quantum cloud providers for execution. As such, even if the adversary in a single provider can obtain a partial model, it does not have sufficient information to retrieve the complete model. Although promising, we observed that an arbitrary model design under distributed settings cannot provide model security. We further developed a reinforcement learning-based security engine, which can automatically optimize the model design under the distributed setting, such that a good trade-off between model performance and security can be made. Experimental results on four datasets show that the model design proposed by QuMoS can achieve a close accuracy to the model designed with neural architecture search under centralized settings while providing the highest security than the baselines.  \nIndex Terms—Cloud Quantum Computing; Quantum Machine Learning; Quantum Model Security.  \nI. INTRODUCTION  \nAlong with Google’s first claim of quantum supremacy [1], researchers have been exploring varied quantum algorithms to exploit the superior computation power of quantum computers [8], [15], [29], [31], [32], [51] . In the meantime, the high capability of machine learning to process a large amount of data has made it widely used in a variety of applications such as image classification [17], [20],[64]–[66], [73], natural language processing [7], [11], [39], [54], [70] and medical diagnosis [27], [28], [46], [67]–[69] . Therefore, quantum machine learning (QML) is regarded as one of the most promising applications for its wide range of potential applications [9],[12], [33], [36], [42], [43],[75] and its potential to achieve an  \nexponential speedup for model execution [23], [35], without the need to modify the original model like pruning [16], [18],[38],[61] and quantization [30],[41],[59],[62] in the machine learning on classical computers.  \nAlthough promising, in the near term Noisy IntermediateScale Quantum (NISQ) era, there are a lot of challenges. One major challenge is the limited computing access: Unlike classical computing resources that almost everyone can easily access, today’s quantum computing is mainly remotely accessed via the cloud services provided by quantum cloud providers, such as IBM, AWS, Google, Azure, etc, known as Quantum-as-a-Service ","cbCaisqR67vSgdmN","https://ap.wps.com/l/cbCaisqR67vSgdmN","pdf",2586684,1,10,"English","en",105,"# Abstract\n# Index Terms\n# I. Introduction","[{\"question\":\"Why is model-stealing more severe for quantum machine learning models?\",\"answer\":\"In QML, stolen models are harder to protect because traditional encryption methods such as homomorphic encryption cannot be directly applied to quantum computation. Training can also be very expensive in near-term quantum settings.\"},{\"question\":\"How does QuMoS preserve the security of a QML model?\",\"answer\":\"QuMoS divides the complete QML model into multiple parts and distributes them to multiple physically isolated quantum cloud providers for execution, so a single compromised provider cannot recover the full model.\"},{\"question\":\"What role does the reinforcement learning-based security engine play?\",\"answer\":\"It automatically optimizes the model design under the distributed setting, enabling a trade-off between model performance and security. Experiments show QuMoS achieves accuracy close to centralized neural architecture search while offering the highest security compared with baselines.\"}]","QuMoS - A Framework for Preserving Security of Quantum Machine Learning Model | PDF",1785894107,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"qumos-a-framework-for-preserving-security-of-quantum-machine-learning-model","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/qumos-a-framework-for-preserving-security-of-quantum-machine-learning-model/124720/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is model-stealing more severe for quantum machine learning models?","Question",{"text":75,"@type":76},"In QML, stolen models are harder to protect because traditional encryption methods such as homomorphic encryption cannot be directly applied to quantum computation. Training can also be very expensive in near-term quantum settings.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does QuMoS preserve the security of a QML model?",{"text":80,"@type":76},"QuMoS divides the complete QML model into multiple parts and distributes them to multiple physically isolated quantum cloud providers for execution, so a single compromised provider cannot recover the full model.",{"name":82,"@type":73,"acceptedAnswer":83},"What role does the reinforcement learning-based security engine play?",{"text":84,"@type":76},"It automatically optimizes the model design under the distributed setting, enabling a trade-off between model performance and security. Experiments show QuMoS achieves accuracy close to centralized neural architecture search while offering the highest security compared with baselines.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":21,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]