English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Defending Quantum Classifiers against Adversarial Perturbations via Quantum Autoencoder Denoising

Forum topic · 小凯 · 2026-05-02

Summary

This paper (arXiv:2604.28176) by Sagnik Chakraborty, Malay Singh, and Arpit Jain addresses adversarial attacks on quantum machine learning models, particularly variational quantum classifiers used for image classification. Adversarially manipulated inputs, such as carefully crafted noise, can cause models to make mistakes. Common defenses like adversarial training have practical limitations: they require adversarial samples and may cause overfitting to specific attacks. The authors propose an adversarial-training-free defense framework that uses a quantum autoencoder to purify adversarial samples through reconstruction. The framework also provides a confidence metric to identify adversarial samples that may not be fully purifiable by the quantum autoencoder. Extensive evaluations show the defense significantly outperforms state-of-the-art methods under adversarial attacks, with prediction accuracy improvements of up to 68%.

Paper Overview

  • Field: Machine Learning / Quantum Computing
  • Authors: Sagnik Chakraborty, Malay Singh, Arpit Jain
  • arXiv: 2604.28176
  • Abstract

    Machine learning models can learn from data samples to carry out various tasks efficiently. When data samples are adversarially manipulated, such as by insertion of carefully crafted noise, it can cause the model to make mistakes. Quantum machine learning models are also vulnerable to such adversarial attacks, especially in image classification using variational quantum classifiers.

    While there are promising defenses against these adversarial perturbations, such as training with adversarial samples, they face practical limitations. For example, they are not applicable in scenarios where adversarial samples cannot be used for training or where the model may overfit to a specific attack.

    This paper proposes an adversarial-training-free defense framework that leverages a quantum autoencoder to purify adversarial samples through reconstruction. Additionally, the framework provides a confidence metric to identify adversarial samples that may not be purifiable by the quantum autoencoder.

    Key Results

  • The defense works without adversarial training, avoiding its practical constraints.
  • A built-in confidence metric flags inputs that the quantum autoencoder may fail to purify.
  • Extensive evaluations show significantly higher prediction accuracy under adversarial attacks compared to state-of-the-art methods, with improvements of up to 68%.
---

*Auto-collected on 2026-05-02*

Tags

#quantum-machine-learning#adversarial-defense#quantum-autoencoder#variational-quantum-classifiers#arxiv#image-classification

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/177619037