AIセキュリティポータル K Program
Guardians of the Quantum GAN
Share
Abstract
Quantum Generative Adversarial Networks (qGANs) are at the forefront of image-generating quantum machine learning models. To accommodate the growing demand for Noisy Intermediate-Scale Quantum (NISQ) devices to train and infer quantum machine learning models, the number of third-party vendors offering quantum hardware as a service is expected to rise. This expansion introduces the risk of untrusted vendors potentially stealing proprietary information from the quantum machine learning models. To address this concern we propose a novel watermarking technique that exploits the noise signature embedded during the training phase of qGANs as a non-invasive watermark. The watermark is identifiable in the images generated by the qGAN allowing us to trace the specific quantum hardware used during training hence providing strong proof of ownership. To further enhance the security robustness, we propose the training of qGANs on a sequence of multiple quantum hardware, embedding a complex watermark comprising the noise signatures of all the training hardware that is difficult for adversaries to replicate. We also develop a machine learning classifier to extract this watermark robustly, thereby identifying the training hardware (or the suite of hardware) from the images generated by the qGAN validating the authenticity of the model. We note that the watermark signature is robust against inferencing on hardware different than the hardware that was used for training. We obtain watermark extraction accuracy of 100% and ~90% for training the qGAN on individual and multiple quantum hardware setups (and inferencing on different hardware), respectively. Since parameter evolution during training is strongly modulated by quantum noise, the proposed watermark can be extended to other quantum machine learning models as well.
Generative adversarial networks
Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, Yoshua Bengio
Published: 2014
Text to image generation with semantic-spatial aware gan
Kai Hu, Wentong Liao, Michael Ying Yang, Bodo Rosenhahn
Published: 2022
Photo-realistic single image super-resolution using a generative adversarial network
Christian Ledig, Lucas Theis, Ferenc Huszar, Jose Caballero, Andrew Cunningham, Alejandro Acosta, Andrew Aitken, Alykhan Tejani, Johannes Totz, Zehan Wang, Wenzhe Shi
Published: 2017
High-fidelity gan inversion for image attribute editing
T. Wang, Y. Zhang, Y. Fan, J. Wang, Q. Chen
Published: 2022
Quantum generative adversarial networks
Pierre-Luc Dallaire-Demers, Nathan Killoran
Published: 2018
Analysis of distributed deep learning in the cloud
Aakash Sharma, Vivek M. Bhasi, Sonali Singh, Rishabh Jain, Jashwant Raj Gunasekaran, Subrata Mitra, Mahmut Taylan Kandemir, George Kesidis, Chita R. Das
Published: 2022
Trustworthy computing using untrusted cloud-based quantum hardware
Suryansh Upadhyay, Rasit Onur Topaloglu, Swaroop Ghosh
Published: 2023
Good artists copy, great artists steal: Model extraction attacks against image translation models
Sebastian Szyller, Vasisht Duddu, Tommi Grondahl, N. Asokan
Published: 2023
Gan-based image steganography for enhancing security via adversarial attack and pixel-wise deep fusion
C. Yuan, H. Wang, P. He, et al.
Published: 2022
Quantum computing in the nisq era and beyond
John Preskill
Published: 2018
Experimental quantum generative adversarial networks for image generation
He-Liang Huang, Yuxuan Du, Ming Gong, Youwei Zhao, Yulin Wu, Chaoyue Wang, Shaowei Li, Futian Liang, Jin Lin, Yu Xu, Rui Yang, Tongliang Liu, Min-Hsiu Hsieh, Hui Deng, Hao Rong, Cheng-Zhi Peng, Chao-Yang Lu, Yu-Ao Chen, Dacheng Tao, Xiaobo Zhu, Jian-Wei Pan
Published: 2021
A primer on security of quantum computing
Swaroop Ghosh, Suryansh Upadhyay, Abdullah Ash Saki
Published: 2023
Robust and secure hybrid quantum-classical computation on untrusted cloud-based quantum hardware
Suryansh Upadhyay, Swaroop Ghosh
Published: 2023
Toward privacy in quantum program execution on untrusted quantum cloud computing machines for business-sensitive quantum needs
Tirthak Patel, Daniel Silver, Aditya Ranjan, Harshitta Gandhi, William Cutler, Devesh Tiwari
Published: 2023
Enigma: Privacy-preserving execution of qaoa on untrusted quantum computers
Ramin Ayanzadeh, Ahmad Mousavi, Narges Alavisamani, Moinuddin Qureshi
Published: 2023
A quantum computer trusted execution environment
Theodoros Trochatos, Chuanqi Xu, Sanjay Deshpande, Yao Lu, Yongshan Ding, Jakub Szefer
Published: 2023
Pennylane: Automatic differentiation of hybrid quantum-classical computations
Ville Bergholm, Josh Izaac, Maria Schuld, Christian Gogolin, Shahnawaz Ahmed, Vishnu Ajith, M. Sohaib Alam, Guillermo Alonso-Linaje, B. AkashNarayanan, Ali Asadi, Juan Miguel Arrazola, Utkarsh Azad, Sam Banning, Carsten Blank, Thomas R Bromley, Benjamin A. Cordier, Jack Ceroni, Alain Delgado, Olivia Di Matteo, Amintor Dusko, Tanya Garg, Diego Guala, Anthony Hayes, Ryan Hill, Aroosa Ijaz, Theodor Isacsson, David Ittah, Soran Jahangiri, Prateek Jain, Edward Jiang, Ankit Khandelwal, Korbinian Kottmann, Robert A. Lang, Christina Lee, Thomas Loke, Angus Lowe, Keri McKiernan, Johannes Jakob Meyer, J. A. Montañez-Barrera, Romain Moyard, Zeyue Niu, Lee James O’Riordan, Steven Oud, Ashish Panigrahi, Chae-Yeun Park, Daniel Polatajko, Nicolás Quesada, Chase Roberts, Nahum Sá, Isidor Schoch, Borun Shi, Shuli Shu, Sukin Sim, Arshpreet Singh, Ingrid Strandberg, Jay Soni, Antal Száva, Slimane Thabet, Rodrigo A. Vargas-Hernández, Trevor Vincent, Nicola Vitucci, Maurice Weber, David Wierichs, Roeland Wiersema, Moritz Willmann, Vincent Wong, Shaoming Zhang, Nathan Killoran
Published: 2022
GANS trained by a two time-scale update rule converge to a local Nash equilibrium
Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, Sepp Hochreiter
Published: 2017
Machine unlearning
Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, Nicolas Papernot
Published: 2019
Spectres, virtual ghosts, and hardware support
Xiaowan Dong, Zhuojia Shen, John Criswell, Alan Cox, Sandhya Dwarkadas
Published: 2018
Real-time error mitigation for variational optimization on quantum hardware
Matteo Robbiati, Alejandro Sopena, Andrea Papaluca, Stefano Carrazza
Published: 2023
Large-scale quantum approximate optimization on nonplanar graphs with machine learning noise mitigation
Stefan H. Sack, Daniel J. Egger
Published: 2024
Share