A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Papadopoulos, Georgios, Eloul, Shaltiel, Satsangi, Yash, Heredge, Jamie, Kumar, Niraj, Chen, Chun-Fu, Pistoia, Marco
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915276074778624
author Papadopoulos, Georgios
Eloul, Shaltiel
Satsangi, Yash
Heredge, Jamie
Kumar, Niraj
Chen, Chun-Fu
Pistoia, Marco
author_facet Papadopoulos, Georgios
Eloul, Shaltiel
Satsangi, Yash
Heredge, Jamie
Kumar, Niraj
Chen, Chun-Fu
Pistoia, Marco
contents The loss landscape of Variational Quantum Neural Networks (VQNNs) is characterized by local minima that grow exponentially with increasing qubits. Because of this, it is more challenging to recover information from model gradients during training compared to classical Neural Networks (NNs). In this paper we present a numerical scheme that successfully reconstructs input training, real-world, practical data from trainable VQNNs' gradients. Our scheme is based on gradient inversion that works by combining gradients estimation with the finite difference method and adaptive low-pass filtering. The scheme is further optimized with Kalman filter to obtain efficient convergence. Our experiments show that our algorithm can invert even batch-trained data, given the VQNN model is sufficiently over-parameterized.
format Preprint
id arxiv_https___arxiv_org_abs_2504_12806
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks
Papadopoulos, Georgios
Eloul, Shaltiel
Satsangi, Yash
Heredge, Jamie
Kumar, Niraj
Chen, Chun-Fu
Pistoia, Marco
Machine Learning
Artificial Intelligence
Cryptography and Security
The loss landscape of Variational Quantum Neural Networks (VQNNs) is characterized by local minima that grow exponentially with increasing qubits. Because of this, it is more challenging to recover information from model gradients during training compared to classical Neural Networks (NNs). In this paper we present a numerical scheme that successfully reconstructs input training, real-world, practical data from trainable VQNNs' gradients. Our scheme is based on gradient inversion that works by combining gradients estimation with the finite difference method and adaptive low-pass filtering. The scheme is further optimized with Kalman filter to obtain efficient convergence. Our experiments show that our algorithm can invert even batch-trained data, given the VQNN model is sufficiently over-parameterized.
title A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2504.12806