Pith. sign in

REVIEW 2 cited by

AI-driven Reverse Engineering of QML Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2408.16929 v1 pith:UZYVSXDF submitted 2024-08-29 quant-ph cs.ETcs.LG

classification quant-phcs.ETcs.LG
keywords quantummodelsparametersreverseapproachclassifiersengineeringorder
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Quantum machine learning (QML) is a rapidly emerging area of research, driven by the capabilities of Noisy Intermediate-Scale Quantum (NISQ) devices. With the progress in the research of QML models, there is a rise in third-party quantum cloud services to cater to the increasing demand for resources. New security concerns surface, specifically regarding the protection of intellectual property (IP) from untrustworthy service providers. One of the most pressing risks is the potential for reverse engineering (RE) by malicious actors who may steal proprietary quantum IPs such as trained parameters and QML architecture, modify them to remove additional watermarks or signatures and re-transpile them for other quantum hardware. Prior work presents a brute force approach to RE the QML parameters which takes exponential time overhead. In this paper, we introduce an autoencoder-based approach to extract the parameters from transpiled QML models deployed on untrusted third-party vendors. We experiment on multi-qubit classifiers and note that they can be reverse-engineered under restricted conditions with a mean error of order 10^-1. The amount of time taken to prepare the dataset and train the model to reverse engineer the QML circuit being of the order 10^3 seconds (which is 10^2x better than the previously reported value for 4-layered 4-qubit classifiers) makes the threat of RE highly potent, underscoring the need for continued development of effective defenses.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SQUASH: A SWAP-Based Quantum Attack to Sabotage Hybrid Quantum Neural Networks

    quant-ph 2025-06 reject novelty 4.0 of 10

    Inserting SWAP gates into the variational circuit of a hybrid quantum neural network degrades classification accuracy by up to roughly 74%, with targeted insertions able to ruin a single class's accuracy.

  2. Adversarial Threats in Quantum Machine Learning: A Survey of Attacks and Defenses

    quant-ph 2025-06 conditional novelty 1.0 of 10

    A survey that categorizes known adversarial threats to quantum machine learning systems and reviews existing defenses, from logic locking to hardware-aware watermarking.

Pith tools