Optimal Provable Robustness of Quantum Classification via Quantum Hypothesis Testing
arXiv:2009.10064 · doi:10.1038/s41534-021-00410-5
Abstract
Quantum machine learning models have the potential to offer speedups and better predictive accuracy compared to their classical counterparts. However, these quantum algorithms, like their classical counterparts, have been shown to also be vulnerable to input perturbations, in particular for classification problems. These can arise either from noisy implementations or, as a worst-case type of noise, adversarial attacks. In order to develop defence mechanisms and to better understand the reliability of these algorithms, it is crucial to understand their robustness properties in presence of natural noise sources or adversarial manipulation. From the observation that measurements involved in quantum classification algorithms are naturally probabilistic, we uncover and formalize a fundamental link between binary quantum hypothesis testing and provably robust quantum classification. This link leads to a tight robustness condition which puts constraints on the amount of noise a classifier can tolerate, independent of whether the noise source is natural or adversarial. Based on this result, we develop practical protocols to optimally certify robustness. Finally, since this is a robustness condition against worst-case types of noise, our result naturally extends to scenarios where the noise source is known. Thus, we also provide a framework to study the reliability of quantum classification protocols beyond the adversarial, worst-case noise scenarios.
28 pages, 5 figures
References in corpus (3)
Cited by in corpus (13)
- Recent advances for quantum classifiers
- Towards quantum enhanced adversarial robustness in machine learning
- Robustness Verification of Quantum Classifiers
- Drastic Circuit Depth Reductions with Preserved Adversarial Robustness by Approximate Encoding for Quantum Machine Learning
- Training robust and generalizable quantum models
- Predominant Aspects on Security for Quantum Machine Learning: Literature Review
- An invitation to the sample complexity of quantum hypothesis testing
- Toward Reliability in the NISQ Era: Robust Interval Guarantee for Quantum Measurements on Approximate States
- Single-shot quantum machine learning
- Maximal Information Leakage from Quantum Encoding of Classical Data
- Superior resilience to poisoning and amenability to unlearning in quantum machine learning
- Resilience-Runtime Tradeoff Relations for Quantum Algorithms
- Enhanced quantum hypothesis testing via the interplay between coherent evolution and noises