A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866915276074778624 |
|---|---|
| author | Papadopoulos, Georgios Eloul, Shaltiel Satsangi, Yash Heredge, Jamie Kumar, Niraj Chen, Chun-Fu Pistoia, Marco |
| author_facet | Papadopoulos, Georgios Eloul, Shaltiel Satsangi, Yash Heredge, Jamie Kumar, Niraj Chen, Chun-Fu Pistoia, Marco |
| contents | The loss landscape of Variational Quantum Neural Networks (VQNNs) is characterized by local minima that grow exponentially with increasing qubits. Because of this, it is more challenging to recover information from model gradients during training compared to classical Neural Networks (NNs). In this paper we present a numerical scheme that successfully reconstructs input training, real-world, practical data from trainable VQNNs' gradients. Our scheme is based on gradient inversion that works by combining gradients estimation with the finite difference method and adaptive low-pass filtering. The scheme is further optimized with Kalman filter to obtain efficient convergence. Our experiments show that our algorithm can invert even batch-trained data, given the VQNN model is sufficiently over-parameterized. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2504_12806 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks Papadopoulos, Georgios Eloul, Shaltiel Satsangi, Yash Heredge, Jamie Kumar, Niraj Chen, Chun-Fu Pistoia, Marco Machine Learning Artificial Intelligence Cryptography and Security The loss landscape of Variational Quantum Neural Networks (VQNNs) is characterized by local minima that grow exponentially with increasing qubits. Because of this, it is more challenging to recover information from model gradients during training compared to classical Neural Networks (NNs). In this paper we present a numerical scheme that successfully reconstructs input training, real-world, practical data from trainable VQNNs' gradients. Our scheme is based on gradient inversion that works by combining gradients estimation with the finite difference method and adaptive low-pass filtering. The scheme is further optimized with Kalman filter to obtain efficient convergence. Our experiments show that our algorithm can invert even batch-trained data, given the VQNN model is sufficiently over-parameterized. |
| title | A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks |
| topic | Machine Learning Artificial Intelligence Cryptography and Security |
| url | https://arxiv.org/abs/2504.12806 |