On the Generalization of Adversarially Trained Quantum Classifiers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Georgiou, Petros, Thomas, Aaron Mark, Jose, Sharu Theresa, Simeone, Osvaldo
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910918185582592
author Georgiou, Petros
Thomas, Aaron Mark
Jose, Sharu Theresa
Simeone, Osvaldo
author_facet Georgiou, Petros
Thomas, Aaron Mark
Jose, Sharu Theresa
Simeone, Osvaldo
contents Quantum classifiers are vulnerable to adversarial attacks that manipulate their input classical or quantum data. A promising countermeasure is adversarial training, where quantum classifiers are trained by using an attack-aware, adversarial loss function. This work establishes novel bounds on the generalization error of adversarially trained quantum classifiers when tested in the presence of perturbation-constrained adversaries. The bounds quantify the excess generalization error incurred to ensure robustness to adversarial attacks as scaling with the training sample size $m$ as $1/\sqrt{m}$, while yielding insights into the impact of the quantum embedding. For quantum binary classifiers employing \textit{rotation embedding}, we find that, in the presence of adversarial attacks on classical inputs $\mathbf{x}$, the increase in sample complexity due to adversarial training over conventional training vanishes in the limit of high dimensional inputs $\mathbf{x}$. In contrast, when the adversary can directly attack the quantum state $ρ(\mathbf{x})$ encoding the input $\mathbf{x}$, the excess generalization error depends on the choice of embedding only through its Hilbert space dimension. The results are also extended to multi-class classifiers. We validate our theoretical findings with numerical experiments.
format Preprint
id arxiv_https___arxiv_org_abs_2504_17690
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Generalization of Adversarially Trained Quantum Classifiers
Georgiou, Petros
Thomas, Aaron Mark
Jose, Sharu Theresa
Simeone, Osvaldo
Quantum Physics
Machine Learning
Quantum classifiers are vulnerable to adversarial attacks that manipulate their input classical or quantum data. A promising countermeasure is adversarial training, where quantum classifiers are trained by using an attack-aware, adversarial loss function. This work establishes novel bounds on the generalization error of adversarially trained quantum classifiers when tested in the presence of perturbation-constrained adversaries. The bounds quantify the excess generalization error incurred to ensure robustness to adversarial attacks as scaling with the training sample size $m$ as $1/\sqrt{m}$, while yielding insights into the impact of the quantum embedding. For quantum binary classifiers employing \textit{rotation embedding}, we find that, in the presence of adversarial attacks on classical inputs $\mathbf{x}$, the increase in sample complexity due to adversarial training over conventional training vanishes in the limit of high dimensional inputs $\mathbf{x}$. In contrast, when the adversary can directly attack the quantum state $ρ(\mathbf{x})$ encoding the input $\mathbf{x}$, the excess generalization error depends on the choice of embedding only through its Hilbert space dimension. The results are also extended to multi-class classifiers. We validate our theoretical findings with numerical experiments.
title On the Generalization of Adversarially Trained Quantum Classifiers
topic Quantum Physics
Machine Learning
url https://arxiv.org/abs/2504.17690