Quantum neural network classifiers have attracted significant attention due to their remarkable performance in classification tasks. However, when dealing with high-dimensional data, these classifiers are often susceptible to misclassification caused by carefully crafted perturbations, a type of attack known as adversarial attacks. To address this issue, we propose a quantum adversarial attack algorithm—Q-MIFGSM. This algorithm generates perturbations by analyzing the gradient information of the input data and combining it with momentum, effectively disrupting the performance of a trained Quantum Neural Network classifier. Compared to existing quantum attack algorithms baselines (Q-FGSM and Q-BIM), experimental results explicitly show that Q-MIFGSM demonstrates superior attack efficacy and faster adversarial sample learning on both Fashion-MNIST and MNIST datasets. Meanwhile, noisy Q-MIFGSM achieves enhanced attack efficiency instead of performance degradation under five types of quantum noise. This study not only reveals the vulnerabilities of quantum classifiers but also contributes to the understanding of quantum adversarial attacks and adversarial training.
更多
查看译文
关键词
Quantum computing,Quantum neural network,Quantum classifiers,Quantum adversarial attacks,Adversarial training