English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Q-DIBA: Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

Forum topic · 小凯 · 2026-07-15

Summary

Q-DIBA is presented as the first input-aware dynamic backdoor attack against Quantum Neural Networks (QNNs). Existing quantum backdoor attacks rely on a fixed trigger shared by all poisoned inputs, a weakness that many defenses exploit by detecting repeated patterns in data representations. Transferring classical dynamic backdoors to QNNs is challenging because measurement compresses the post-ansatz quantum state into limited classical outputs, weakening supervision for trigger generators, while per-sample density matrices fluctuate with input, destabilizing contrastive learning. Q-DIBA jointly trains a classical trigger generator and the victim QNN via a three-mode minibatch strategy covering clean behavior, attack activation, and trigger specificity. It further introduces an ensemble density contrastive loss applied to post-ansatz quantum states before measurement, contrasting mode-averaged density matrices rather than individual samples for stable quantum-level supervision. Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show high clean accuracy, strong attack success rate, and robustness against visual inspection, spectral-signature detection, and fine-tuning defenses. Paper: arXiv 2607.11843.

Paper Overview

Field: quantum Authors: Junrui Zhang, Zemin Chen, Lusi Li, Mohammad Ghasemigol, Daniel Takabi Published: 2026-07-13 arXiv: 2607.11843

Summary

Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Prior work shows QNNs are vulnerable to backdoor attacks, yet existing quantum backdoors mostly rely on a fixed trigger shared by all poisoned inputs. This fixed-trigger design is a major weakness because many defenses detect or weaken the repeated patterns such triggers leave in data representations.

Although input-aware dynamic backdoors have been studied in classical neural networks, transferring them to QNNs is difficult because quantum learning introduces new obstacles: measurement compresses the post-ansatz quantum state into a limited classical output, weakening supervision for the trigger generator, while individual density matrices fluctuate with the input, making per-sample contrastive learning unstable.

Q-DIBA

This paper proposes Q-DIBA, the first input-aware dynamic backdoor attack for QNNs:

  • Three-mode minibatch training: jointly trains a classical trigger generator and the victim QNN across clean behavior, attack activation, and trigger specificity modes.
  • Ensemble density contrastive loss: to provide stable quantum-level supervision, the loss operates on post-ansatz quantum states before measurement, contrasting mode-averaged density matrices instead of individual samples.
  • Results

    Experiments on MNIST and Fashion-MNIST across multiple QNN architectures show that Q-DIBA achieves:

  • High clean accuracy
  • Strong attack success rate
  • High cross-trigger accuracy
Q-DIBA remains resilient against defenses including visual inspection, spectral-signature detection, and fine-tuning.

---

*Auto-collected on 2026-07-15*

Tags

#quantum-computing#quantum-neural-networks#backdoor-attack#adversarial-ml#dynamic-triggers#security#arxiv

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178395150