Active Computing & AI Physics & Astronomy

Adversarially Robust Quantum Machine Learning: Theory and Design via Quantum Information Bottleneck

In plain English

AI plain-English summary

Variational quantum classifiers—machine learning algorithms that run on today’s imperfect quantum computers—can be tricked by tiny, deliberate changes to input data, causing them to misdiagnose a patient or misdirect a self-driving car. This fellowship aims to fix that vulnerability. Current quantum classifiers are highly susceptible to adversarial attacks: an attacker can slightly perturb a medical scan or a financial transaction, and the classifier will confidently make the wrong prediction. This threatens their use in safety-critical domains like health diagnostics, autonomous vehicle navigation, and fraud detection. The project will design classifier architectures with guaranteed robustness, develop a theoretical understanding of why existing defenses fail, and create new training methods that maintain high accuracy on both clean and attacked data. If successful, this research could make quantum machine learning safe enough to deploy in systems that people already rely on—medical imaging, navigation, and financial security—without introducing new vulnerabilities. It also establishes fundamental theory for how quantum classifiers generalise under attack, a gap that currently limits their real-world adoption.

View original technical description
Tech giants like Google and IBM, alongside startups like IonQ and Rigetti Computing are on the race to developing fault-tolerant quantum computers. While such computers are still expected to be years away, recent efforts focus on utilising the currently available Noisy Intermediate Scale Quantum (NISQ) computers to demonstrate computational advantages in real-world use cases. Optimisation problems, including those in machine learning such as classification, have been identified as promising areas for demonstrating computational advantages with NISQ devices. Variational quantum classifiers have emerged as particularly promising algorithms, that leverage both quantum and classical computing paradigms. These classifiers have already found applications in safety-critical domains such as health diagnostics, autonomous vehicle navigation, and financial fraud detection. However, a critical aspect that has been overlooked until recently is the susceptibility of variational quantum classifiers to adversarial attacks. These attacks involve carefully perturbing or poisoning data examples to mislead the classifier into making incorrect predictions. Recent research indicates that variational quantum classifiers are highly prone to such attacks, threatening the potential quantum advantages they offer and their application in safety-critical domains. This fellowship aims to establish solid theoretical and algorithmic foundations for developing adversarially robust variational quantum classifiers. The project will achieve this by: Designing resilient and scalable architectures for the variational quantum classifiers with guaranteed robustness, Developing theoretical understanding of the generalisation performance of existing defense strategies like quantum adversarial training, Mitigating the drawbacks of existing strategies which focus on ensuring robust accuracy on adversarially perturbed data, while compromising the standard accuracy on clean data, and Developing novel, theoretically-principled training criteria and optimisation schemes for the classifier that ensure high standard and high robust accuracies. By addressing these aspects, the project aims to pave the way for the development of theoretically-principled, adversarially robust variational quantum classifiers that can be safely deployed in critical domains.

View the original record at the funder ↗

Researchers

Sharu Theresa Jose (Principal Investigator)

Related Research

Grants with similar aims, by meaning.

Machine Learning as an Enabler for Qubit Scalability, Quantum Computing
Theory to Enable Practical Quantum Advantage
Towards a practical quantum advantage: Confronting the quantum many-body problem using quantum computers
'Error correction and detection in variational quantum algorithms'
Optimal control of open quantum systems in strong coupling regimes

Original classification

Fellowship

Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.