[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126163-en":3,"doc-seo-126163-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":11,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},126163,3985741905716,"Rowan","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",8,"Research & Report","The Quantum Imitation Game - Reverse Engineering of Quantum Machine Learning Models","Quantum Machine Learning (QML) combines quantum computing with machine learning, enabling advances on problems difficult for classical methods. In the NISQ era, expanding third-party vendors makes QML model security critical, especially against reverse engineering that can reveal trained circuit structure and sensitive parameters. The work studies a setting where an untrusted cloud adversary has white-box access to the transpiled model during inference and targets recovering the pre-transpiled circuit. It evaluates reverse-engineered quantum classifiers across QNN sizes, finding feasible multi-qubit attacks under constraints, and introduces dummy fixed-parameter rotation gates to increase RE cost while keeping performance overhead low.","The Quantum Imitation Game: Reverse Engineering of Quantum  \nMachine Learning Models  \nArchisman Ghosh  \n[apg6127@psu.edu](apg6127@psu.edu)[ ](apg6127@psu.edu)Pennsylvania State University State College, PA, USA  \nSwaroop Ghosh  \n[szg212@psu.edu](szg212@psu.edu)[ ](szg212@psu.edu)Pennsylvania State University State College, PA, USA  \narXiv :2407 .07237v2 [ quant-ph] 15 Jul 2024  \nABSTRACT  \nQuantum Machine Learning (QML) is an amalgamation of quantum computing paradigms with machine learning models, providing significant prospects for solving complex problems. However, with the expansion of numerous third-party vendors in the Noisy Intermediate-Scale Quantum (NISQ) era of quantum computing, the security of QML models is of prime importance, particularly against reverse engineering, which could expose sensitive parameters and proprietary algorithms embedded within the models. We assume the untrusted third-party quantum cloud provider is an adversary having white-box access to the transpiled version of the user-designed trained QML model during inference. Although the adversary can steal and use the model without any modification, reverse engineering (RE) to extract the pre-transpiled copy of the QML circuit will enable re-transpilation and usage of the model for various hardware with completely different native gate sets and even different qubit technology. Such flexibility may not be obtained from the transpiled version of the circuit which is tied toa particular hardware and qubit technology. The information about the parameters (e.g., number of parameters, their placements, and optimized values) can allow further training of the QML model if the adversary plans to alter the QML model to tamper with the watermark and/or embed their own watermark or refine the model for other purposes. In this first effort to investigate the RE of QML circuits, we examine quantum classifiers by comparing the training accuracy of original and reverse-engineered models across various sizes (i.e., number of qubits and number of parametric layers) of Quantum Neural Networks (QNNs). We note that multi-qubit classifiers can be reverse-engineered under specific conditions with a mean error of order 10−2 in a reasonable time. We also propose adding dummy rotation gates in the QML model with fixed parameters to increase the RE overhead for defense. For instance, an addition of 2 dummy qubits and 2 layers increases the overhead by ∼ 1.76 times for a classifier with 2 qubits and 3 layers with a performance overhead of less than 9%. We note that RE is a very powerful attack model which warrants further efforts on defenses.  \nKEYWORDS  \nQuantum Machine Learning, Reverse Engineering, Quantum Security  \n1 INTRODUCTION  \nQuantum Machine Learning (QML) merges the cutting-edge capabilities of quantum computing with sophisticated machine learning techniques, offering the potential to solve complex problems intractable for classical computers [1] . QML circuits involve quantum properties like entanglement and superposition to explore the  \nHilbert space more effectively and thus are able to process and analyze vast amounts of data with enhanced speed and efficiency. However, with the advancement in QML design and the increase in the complexity of the models, there is an increased demand for quantum hardware. To cater to this increasing demand, quantum hardware providers have taken the initiative to provide QML hardware as a service to aid the design and utilization of advanced QML models. In the noisy intermediate-scale quantum (NISQ) era of quantum computing [2], the number of third-party cloud-based quantum hardware providers will only increase thus reducing the cost of using quantum hardware. One pressing issue is the potential incentive of some rogue adversary or an untrusted third-party cloud provider to steal trained QML circuit designs, posing significant threats to the privacy and integrity of these models [3] .  \n1.1 Why QML Models are at Risk  \nQMLs fac","cbCaicL5FbAiMD7l","https://ap.wps.com/l/cbCaicL5FbAiMD7l","pdf",1150863,1,11,"English","en",105,"# Abstract\n# 1 Introduction\n## 1.1 Why QML Models are at Risk","[{\"question\":\"What security risk does this paper focus on for quantum machine learning models?\",\"answer\":\"It focuses on reverse engineering of trained QML circuit designs, which can expose sensitive parameters and enable re-transpilation and reuse for different hardware and qubit technologies.\"},{\"question\":\"What adversary access model is assumed during inference?\",\"answer\":\"The paper assumes an untrusted third-party quantum cloud provider has white-box access to the transpiled version of the user-trained QML model during inference.\"},{\"question\":\"How does the proposed defense increase the overhead of reverse engineering?\",\"answer\":\"It adds dummy rotation gates with fixed parameters in the QML model, increasing the RE overhead (e.g., adding 2 dummy qubits and 2 layers raises overhead by about 1.76× with under 9% performance overhead).\"}]","The Quantum Imitation Game - Reverse Engineering of Quantum Machine Learning Models | PDF",1785903492,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"the-quantum-imitation-game-reverse-engineering-of-quantum-machine-learning-models","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/the-quantum-imitation-game-reverse-engineering-of-quantum-machine-learning-models/126163/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-25","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":11},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What security risk does this paper focus on for quantum machine learning models?","Question",{"text":76,"@type":77},"It focuses on reverse engineering of trained QML circuit designs, which can expose sensitive parameters and enable re-transpilation and reuse for different hardware and qubit technologies.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What adversary access model is assumed during inference?",{"text":81,"@type":77},"The paper assumes an untrusted third-party quantum cloud provider has white-box access to the transpiled version of the user-trained QML model during inference.",{"name":83,"@type":74,"acceptedAnswer":84},"How does the proposed defense increase the overhead of reverse engineering?",{"text":85,"@type":77},"It adds dummy rotation gates with fixed parameters in the QML model, increasing the RE overhead (e.g., adding 2 dummy qubits and 2 layers raises overhead by about 1.76× with under 9% performance overhead).","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]