SoK: Critical Evaluation of Quantum Machine Learning for Adversarial Robustness

Quantum Machine Learning (QML) integrates quantum computational principles into learning algorithms, offering the potential for improved representational capacity and computational efficiency. Nevertheless, the security and robustness of QML systems remain largely underexplored, particularly under adversarial conditions. We present the first comprehensive systematization of adversarial robustness in QML, integrating conceptual organization with empirical evaluation across black-, gray-, and white-box threat models. We implement five representative attacks across all three threat models: a label-flipping data poisoning attack under blackbox; an encoder-level indiscriminate data poisoning attack and a proxy-model-based clean-label backdoor attack under gray-box; and a circuit-level backdoor attack (QTrojan) and gradient-based evasion attacks (FGSM and PGD) under whitebox. We evaluate the attacks using a Quantum Multilayer Perceptron (QMLP) trained on MNIST and AZ-Class across circuit depths of 2, 5, 10 and 50 layers and two encoding schemes (angle and amplitude). Our extensive evaluations reveal a fundamental accuracy-robustness trade-off. In particular, amplitude encoding yields the highest clean accuracy (92.6 % on MNIST, 67% on AZ-Class); however, it collapses under adversarial perturbations and depolarizing noise, while shallow angle-encoded models remain substantially more stable. In addition, QUID is highly effective under noiseless conditions but is weakened by noise, whereas the proxy-model backdoor persists unless the circuit itself is overwhelmed, highlighting that noise is an asymmetric and unreliable passive defense. Furthermore, the circuit-level backdoor fails in the multi-class setting, indicating a scalability constraint. Finally, QMLP models are more robust than Classical Multi-Layer Perceptron (CMLP) models under label-flipping attacks but are substantially more vulnerable to gradient-based evasion, motivating the need for quantumspecific defenses. We conclude by proposing a threat-aware, noise-resilient design framework for secure and robust QML deployment.

Paper

References (100)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC