AIセキュリティポータル K Program
Evaluating Efficacy of Model Stealing Attacks and Defenses on Quantum Neural Networks
Share
Abstract
Cloud hosting of quantum machine learning (QML) models exposes them to a range of vulnerabilities, the most significant of which is the model stealing attack. In this study, we assess the efficacy of such attacks in the realm of quantum computing. We conducted comprehensive experiments on various datasets with multiple QML model architectures. Our findings revealed that model stealing attacks can produce clone models achieving up to $0.9\times$ and $0.99\times$ clone test accuracy when trained using Top-$1$ and Top-$k$ labels, respectively ($k:$ num\_classes). To defend against these attacks, we leverage the unique properties of current noisy hardware and perturb the victim model outputs and hinder the attacker's training process. In particular, we propose: 1) hardware variation-induced perturbation (HVIP) and 2) hardware and architecture variation-induced perturbation (HAVIP). Although noise and architectural variability can provide up to $\sim16\%$ output obfuscation, our comprehensive analysis revealed that models cloned under noisy conditions tend to be resilient, suffering little to no performance degradation due to such obfuscations. Despite limited success with our defense techniques, this outcome has led to an important discovery: QML models trained on noisy hardwares are naturally resistant to perturbation or obfuscation-based defenses or attacks.
Quantum-classical hybrid machine learning for image classification (ICCAD special session paper)
Mahabubul Alam, et al.
Published: 2021
Pennylane: Automatic differentiation of hybrid quantum-classical computations
Ville Bergholm, Josh Izaac, Maria Schuld, Christian Gogolin, Shahnawaz Ahmed, Vishnu Ajith, M. Sohaib Alam, Guillermo Alonso-Linaje, B. AkashNarayanan, Ali Asadi, Juan Miguel Arrazola, Utkarsh Azad, Sam Banning, Carsten Blank, Thomas R Bromley, Benjamin A. Cordier, Jack Ceroni, Alain Delgado, Olivia Di Matteo, Amintor Dusko, Tanya Garg, Diego Guala, Anthony Hayes, Ryan Hill, Aroosa Ijaz, Theodor Isacsson, David Ittah, Soran Jahangiri, Prateek Jain, Edward Jiang, Ankit Khandelwal, Korbinian Kottmann, Robert A. Lang, Christina Lee, Thomas Loke, Angus Lowe, Keri McKiernan, Johannes Jakob Meyer, J. A. Montañez-Barrera, Romain Moyard, Zeyue Niu, Lee James O’Riordan, Steven Oud, Ashish Panigrahi, Chae-Yeun Park, Daniel Polatajko, Nicolás Quesada, Chase Roberts, Nahum Sá, Isidor Schoch, Borun Shi, Shuli Shu, Sukin Sim, Arshpreet Singh, Ingrid Strandberg, Jay Soni, Antal Száva, Slimane Thabet, Rodrigo A. Vargas-Hernández, Trevor Vincent, Nicola Vitucci, Maurice Weber, David Wierichs, Roeland Wiersema, Moritz Willmann, Vincent Wong, Shaoming Zhang, Nathan Killoran
Published: 2022
Exploiting In-Constraint Energy in Constrained Variational Quantum Optimization
Tianyi Hao, et al.
Published: 2022
MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation
Sanjay Kariyappa, Atul Prakash, Moinuddin Qureshi
Published: 2020.5.7
Heart failure detection using quantum-enhanced machine learning and traditional machine learning techniques for internet of artificially intelligent medical things
Yogesh Kumar, et al.
Published: 2021
Analytical Formulation of the Second-Order Derivative of Energy for the Orbital-Optimized Variational Quantum Eigensolver: Application to Polarizability
Yuya O Nakagawa, et al.
Published: 2023
I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences
Daryna Oliynyk, Rudolf Mayer, Andreas Rauber
Published: 2022.6.17
Efficiently stealing your machine learning models
Robert Nikolai Reith, et al.
Published: 2019
Reverse-engineering deep relu networks
David Rolnick, et al.
Published: 2020
An introduction to quantum machine learning
Maria Schuld, et al.
Published: 2015
Data Driven Exploratory Attacks on Black Box Classifiers in Adversarial Domains
Tegjyot Singh Sethi, Mehmed Kantardzic
Published: 2017.3.23
Stealing machine learning models via prediction APIs
Florian Tramèr, et al.
Published: 2016
Monitoring-based differential privacy mechanism against query flooding-based model extraction attack
H. Yan, X. Li, H. Li, J. Li, W. Sun, F. Li
Published: 2022
Share