Pith. sign in

REVIEW 2 major objections 5 minor 34 references

Quantum Machine Learning

T0 review · 2 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read This chapter argues that quantum machine learning flips adversarial attacks: classical attacks fail against quantum models, while quantum-generated attacks fool classical models, giving early quantum adopters a dual security edge.

desk verdict A readable QML survey whose central adversarial-robustness claim is a single self-cited simulation, presented more confidently than its own caveats allow. read the letter →

arxiv 2506.12292 v1 pith:YS67LDFU submitted 2025-06-14 quant-ph

classification quant-ph
keywords quantummachinelearningadversarialrobustnessattackstransferabilityvariationalcircuitscybersecurity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This chapter introduces quantum machine learning and makes a central security claim: classical adversarial attacks do not transfer to QML models, while attacks generated by QML models easily fool classical machine learning systems. If the asymmetry holds, organizations that adopt quantum ML early would get models that are hard to attack and that produce unusually effective attacks of their own. The chapter also surveys the QML pipeline—data encoding, variational circuits, and measurement—and reviews open challenges such as data loading, barren plateaus, and hardware noise before recommending where the field should focus next.

What carries the argument

The object that carries the argument is the quantum variational classifier, a circuit made of three blocks: a data-encoding layer, a parameterized layer of single-qubit rotations and two-qubit entangling gates, and a measurement. Entanglement from the two-qubit gates is invoked as the property that makes classical adversarial perturbations ineffective on QML models while quantum-generated perturbations remain transferable to classical models. The transferability asymmetry is the mechanism the chapter leans on: attacks designed against one architecture are tested against another, and the direction of transfer decides who has the advantage.

What would settle it

Run the same transferability experiment on a current noisy quantum processor with a realistic dataset: if classical adversarial examples generated against classical networks flip the output of the quantum classifier at a non-negligible rate, or if quantum-generated attacks fail to fool classical networks, the asymmetry reported here breaks. A simpler check is whether the results cited as [12] reproduce when the simulation is re-run with standard error bars and multiple random seeds.

Watch

Extended reading notes

Core claim

The discovery the chapter reports is an adversarial-robustness asymmetry between classical and quantum classifiers. Based on the benchmarking study cited as [12], classical attacks that succeed against classical networks fail against quantum variational classifiers, whereas attacks generated on quantum classifiers transfer to and fool classical networks. The chapter takes this asymmetry as evidence that quantum properties, particularly entanglement, change the attack surface of machine learning, and that early adopters of quantum technology would hold a dual advantage: resilient models and potent attacks. It notes that QML networks remain vulnerable to attacks generated by other quantum networks, so the advantage is not absolute.

Load-bearing premise

The central security claim rests on a single benchmarking study from one research group that has not been independently replicated, and the chapter assumes those simulation results carry over to real datasets, larger models, and the noisy quantum hardware available today.

Editorial extensions

If this is right

  • If QML models resist classical adversarial attacks, classical attack-transfer defenses become less relevant for quantum-based systems.
  • QML-generated attacks could become a new offensive tool for fooling deployed classical ML systems in security-sensitive applications.
  • The vulnerability of QML to quantum-generated attacks implies that post-quantum security planning must assume adversarial access to quantum computers.
  • Practical QML security depends on solving known pipeline problems such as data encoding, barren plateaus, and hardware noise, since robustness findings so far come from simulations on simple datasets.
  • Quantum data, which avoids the classical encoding bottleneck, is presented as the most promising route to genuine quantum advantage in ML.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the transferability asymmetry is real, it suggests an early-mover doctrine: the first actor with reliable quantum ML gets both armor and weapon, though the asymmetry may erode as quantum hardware matures and classical attackers learn to imitate quantum perturbations.
  • Because the robustness evidence comes from simulation on small datasets, a high-value test is whether adversarial examples generated on classical neural nets but constrained to look quantum-like, for instance through low-rank or entanglement-structured perturbations, transfer to QML models.
  • If quantum noise itself contributes to robustness, as hinted by cited work on noise-protected quantum classifiers, then error-corrected fault-tolerant hardware might remove a free layer of defense and change the security calculus.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. This chapter, authored by Muhammad Usman, is an introductory review of quantum machine learning (QML) and quantum adversarial machine learning (QAML). It outlines the promise of QML, describes the main building blocks of variational quantum classifiers, discusses open challenges such as data encoding, barren plateaus, and noise, and surveys recent trends including quantum transfer learning, equivariant QML, and quantum generative adversarial networks. The chapter's headline claim is that QML offers a 'dual advantage' in adversarial settings: classical adversarial attacks do not transfer to QML models, while attacks generated on QML models successfully fool classical models (Section 1.2). The chapter then recommends investment in QML/QAML for defense and intelligence, surveillance, and reconnaissance (ISR) applications (Section 1.3).

Significance. The chapter is a clearly written, well-structured survey of a rapidly moving field, and it does a service by cataloging current open problems (data encoding, barren plateaus, noise mitigation, architecture design). The author's closeness to the frontier research is a strength: the chapter draws on recent experimental demonstrations and includes pointers to recent preprints. However, the central adversarial-robustness claim is presented as an established discovery even though it rests on a single benchmark study (Ref. [12]) from the author's own group, with no independent validation and no boundary conditions. Because the security recommendation in Section 1.3 depends directly on this claim, the chapter's current framing oversells the evidence. The chapter is, nonetheless, a useful introduction for non-specialists if the claim is appropriately qualified.

major comments (2)
  1. [1.2 and 1.3] The dual-advantage claim — that 'attacks from classical ML models do not transfer to QML models, contrarily the attacks from QML models were easily able to fool classical ML algorithms' — is stated as a categorical discovery. The only cited support is Ref. [12], a benchmark study on small image datasets (MNIST/FMNIST), and the chapter's own caveats in Sec. 1.2.2 ('primarily to simple proof-of-concept datasets') and Sec. 1.2.3 item 1 ('current implementation of QML is primarily focused on simple proof-of-concept datasets such as MNIST and FMNIST') limit the domain of validity. The claim should be qualified to the specific experimental regime, and the chapter should explicitly identify the conditions under which the asymmetry has not yet been tested (e.g., larger models, real-world datasets, noisy hardware, different attack families). As written, the recommendation in Sec. 1.3 to adopt QML/QAML for military ISR systems goes beyond the demonstrated evidence.
  2. [1.2 (adversarial robustness discussion)] The chapter cites Refs. [13] (Lu et al.) and [14] (Liu and Wittek) as relevant to QML vulnerability, yet the text concludes that QML is 'remarkably robust' without reconciling those works, which report adversarial perturbations that can fool quantum classifiers. A review should either discuss why those vulnerability results do not apply to the models in Ref. [12], or explicitly state that the robustness result is model- and attack-dependent. In addition, the central robustness claim is drawn almost exclusively from the author's own group's publications (Refs. [8,12,16]); a balanced review should note the absence of independent replication and view the result as preliminary rather than established.
minor comments (5)
  1. [1.1] Minor English errors: 'the birth a new field' should be 'the birth of a new field'; 'significant more development' should be 'significantly more development'; 'severally limits' should be 'severely limits'.
  2. [1.2.3 item 6] The phrase 'And & Bees' likely should be 'Ants & Bees' (the dataset referenced in Ref. [32]); please check the dataset name.
  3. [1.2.3 item 3] The sentence 'It might be possible that the noise in quantum devices dilute the presence of adversarial attacks which in itself are based on the carefully crafted noise...' is grammatically awkward (subject-verb agreement) and could be clarified to clearly separate speculation from established results.
  4. [References] Ref. [19] lacks an article title; Refs. [17] and [31] are arXiv preprints and should be labeled as such for consistency with other references.
  5. [1.2.3 item 1] When first mentioning MNIST and FMNIST, the chapter could add a brief parenthetical description (e.g., hand-written digit and Fashion-MNIST image classification benchmarks) for readers outside the immediate field.

Circularity Check

1 steps flagged · score 7.0 of 10

Sec. 1.2's dual-advantage claim reduces to the author's own prior simulation [12]; the chapter's caveats undercut its generality.

  1. self citation load bearing [Section 1.2 (transferability paragraph); echoed in Section 1.2.3 item 8 and relied on in Section 1.3]
    "Recent work has focused on the analysis of QML models, in particular with the context of transferability of attacks between classical and quantum ML architectures [12]. It has been discovered that while the attacks from classical ML models do not transfer to QML models, contrarily the attacks from QML models were easily able to fool classical ML algorithms."

    The chapter's load-bearing 'dual advantage' claim is not derived, benchmarked, or independently verified in this chapter; it is a restatement of the conclusions of Ref. [12], a Physical Review Research paper from the same research group (see Refs. [8], [16], [33], [34], which list overlapping authors M.T. West, M. Sevior, and M. Usman). No independent replication, external dataset, error analysis, or boundary condition is supplied. The Section 1.3 recommendation to advance QML/QAML for military ISR systems presupposes exactly this self-cited transferability asymmetry.

full rationale

This chapter is a review, not a mathematical derivation, so the usual fit-and-predict circularity does not apply. However, the chapter's central substantive assertion—that classical attacks do not transfer to QML models while QML attacks fool classical models—is presented as an established discovery but is supported only by Ref. [12], a simulation study from the author's own group. The chapter supplies no independent replication, no external benchmark, and no discussion of when the asymmetry might fail, even though its own Sections 1.2.2 and 1.2.3 state that current QML/QAML work is limited to proof-of-concept image datasets and simple quantum architectures. Because the Section 1.3 Defence-focused recommendation is built directly on this self-cited result, the load-bearing step is a self-citation chain rather than an independent argument. This is not a case of simple benign self-citation: the central claim's validity in the chapter stands or falls with the unverified generalizability of Ref. [12]. Score 7 reflects a central claim that is effectively a restatement of the authors' own prior simulation, with the chapter's own caveats further limiting its scope. There is no evidence of deliberate misattribution; the issue is that the chapter does not provide independent content for its most important security conclusion.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

As a review, the chapter introduces no new parameters, entities, or derivations. Its only inputs are prior literature. The main epistemic load is the validity and generalizability of the cited results, several of which are by the same research group.

assumptions (3)
  • domain assumption The adversarial robustness and transferability results of Refs. [8,12,16,17] are valid and representative.
    The chapter's claims of QML robustness and dual advantage rest entirely on these references; no independent replication is provided.
  • domain assumption Efficient quantum state preparation and error mitigation will become feasible enough that data-loading costs and noise do not erase QML advantages.
    Section 1.2 acknowledges data-loading cost as a key challenge but assumes it can be overcome; this is a premise for any practical QML advantage.
  • domain assumption Large-scale fault-tolerant quantum computers will arrive in the near to medium-term future, making QML deployment plausible.
    The introduction states this expectation and builds the review's relevance on it, without addressing skeptical literature on quantum computing timelines.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Quantum Machine Learning." pith.science (2026). https://pith.science/paper/YS67LDFU

@misc{pith2026250612292,
  author       = {Pith},
  title        = {Pith review of: Quantum Machine Learning},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YS67LDFU}},
  note         = {Machine review of arXiv:2506.12292}
}
read the original abstract

The meteoric rise of artificial intelligence in recent years has seen machine learning methods become ubiquitous in modern science, technology, and industry. Concurrently, the emergence of programmable quantum computers, coupled with the expectation that large-scale fault-tolerant machines will follow in the near to medium-term future, has led to much speculation about the prospect of quantum machine learning (QML), namely machine learning (ML) solutions which take advantage of quantum properties to outperform their classical counterparts. Indeed, QML is widely considered as one of the front-running use cases for quantum computing. In recent years, research in QML has gained significant global momentum. In this chapter, we introduce the fundamentals of QML and provide a brief overview of the recent progress and future trends in the field of QML. We highlight key opportunities for achieving quantum advantage in ML tasks, as well as describe some open challenges currently facing the field of QML. Specifically in the context of cybersecurity, we introduce the potential for QML in defence and security-sensitive applications, where it has been predicted that the seamless integration of quantum computing into ML will herald the development of robust and reliable QML systems, resilient against sophisticated threats arising from data manipulation and poisoning.

Figures

Figures reproduced from arXiv: 2506.12292 by the authors.

Figure 1
Figure 1. [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

34 extracted references · 27 canonical work pages

  1. [12]

    M. T. West et al. Benchmarking adversarially robust quantum machine learning at scale. Physical Review Research, 5:023186, 2023

  2. [19]

    Zhou et al

    Z. Zhou et al. Nature Communications, 10:1334, 2019

  3. [13]

    Quantum adversarial machine learning

    Sirui Lu, Lu-Ming Duan, and Dong-Ling Deng. Quantum adversarial machine learning. Phys- ical Review Research, 2(3):033212, 2020

  4. [14]

    Vulnerability of quantum classification to adversarial perturba- tions

    Nana Liu and Peter Wittek. Vulnerability of quantum classification to adversarial perturba- tions. Phys. Rev. A, 101:062331, Jun 2020

  5. [1]

    Acharya et al

    R. Acharya et al. Quantum error correction below the surface code threshold. Nature, 2024

  6. [2]

    Cao et al

    Y . Cao et al. Quantum chemistry in the age of quantum computing. Chemical Reviews , 119(19):10856–10915, 2019

  7. [3]

    Santagati et al

    R. Santagati et al. Drug design on quantum computers. Nat. Phys., 2024

  8. [4]

    Herman et al

    D. Herman et al. Quantum computing for finance. Nat Rev Phys, 5:450–465, 2023

Show all 34 references
  1. [5]

    V . V . Dixit et al. Quantum computing for transport network design problems. Sci Rep , 13:12267, 2023

  2. [6]

    Biamonte et al

    J. Biamonte et al. Quantum machine learning. Nature, 549:195–202, 2017

  3. [7]

    Cerezo et al

    M. Cerezo et al. Challenges and opportunities in quantum machine learning. Nat Comput Sci, 2:567–576, 2022

  4. [8]

    M. T. West et al. Towards quantum enhanced adversarial robustness in machine learning. Nat Mach Intell, 5:581–589, 2023

  5. [9]

    Demonstration of quantum advantage in machine learning

    Diego Rist `e, Marcus P Da Silva, Colm A Ryan, Andrew W Cross, Antonio D C´orcoles, John A Smolin, Jay M Gambetta, Jerry M Chow, and Blake R Johnson. Demonstration of quantum advantage in machine learning. npj Quantum Information, 3(1):1–5, 2017

  6. [10]

    A rigorous and robust quantum speed-up in supervised machine learning

    Yunchao Liu, Srinivasan Arunachalam, and Kristan Temme. A rigorous and robust quantum speed-up in supervised machine learning. Nature Physics, 17(9):1013–1017, 2021

  7. [11]

    Adversarial machine learning at scale

    Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236, 2016

  8. [15]

    Dowling et al

    N. Dowling et al. Adversarial robustness guarantees for quantum classifiers. arXiv:2405.10360, 2024

  9. [16]

    M. T. West et al. Drastic circuit depth reductions with preserved adversarial robustness by approximate encoding for quantum machine learning. Intelligent Computing, 3:100, 2024

  10. [17]

    Experimental quantum adversarial learning with programmable superconducting qubits

    Wenhui Ren, Weikang Li, Shibo Xu, Ke Wang, Wenjie Jiang, Feitong Jin, Xuhao Zhu, Jiachen Chen, Zixuan Song, Pengfei Zhang, et al. Experimental quantum adversarial learning with programmable superconducting qubits. arXiv preprint arXiv:2204.01738, 2022

  11. [18]

    Huang et al

    H-Y . Huang et al. Quantum advantage in learning from experiments.Science, 376:1182–1186, 2022

  12. [20]

    Ren et al

    K. Ren et al. Engineering, 6:346–360, 2020. 1 Quantum Machine Learning 11

  13. [21]

    Robust data encodings for quantum classifiers

    Ryan LaRose and Brian Coyle. Robust data encodings for quantum classifiers. Physical Review A, 102(3):032420, 2020

  14. [22]

    Data compression for quantum machine learning

    Rohit Dilip, Yu-Jie Liu, Adam Smith, and Frank Pollmann. Data compression for quantum machine learning. arXiv preprint arXiv:2204.11170, 2022

  15. [23]

    Towards deep learning models resistant to adversarial attacks

    Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017

  16. [24]

    Explaining and harnessing adver- sarial examples

    Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adver- sarial examples. arXiv preprint arXiv:1412.6572, 2014

  17. [25]

    Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks

    Francesco Croce and Matthias Hein. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning, pages 2206–2216. PMLR, 2020

  18. [26]

    Quantum autoencoders for efficient compression of quantum data

    Jonathan Romero, Jonathan P Olson, and Alan Aspuru-Guzik. Quantum autoencoders for efficient compression of quantum data. Quantum Science and Technology, 2(4):045001, 2017

  19. [27]

    Quanvolu- tional neural networks: powering image recognition with quantum circuits.Quantum Machine Intelligence, 2(1):1–9, 2020

    Maxwell Henderson, Samriddhi Shakya, Shashindra Pradhan, and Tristan Cook. Quanvolu- tional neural networks: powering image recognition with quantum circuits.Quantum Machine Intelligence, 2(1):1–9, 2020

  20. [28]

    Heredge et al

    J. Heredge et al. Non-unitary quantum machine learning. arXiv:2405.17388, 2024

  21. [29]

    Quantum noise pro- tects quantum classifiers against adversaries

    Yuxuan Du, Min-Hsiu Hsieh, Tongliang Liu, Dacheng Tao, and Nana Liu. Quantum noise pro- tects quantum classifiers against adversaries. Physical Review Research, 3(2):023153, 2021

  22. [30]

    Tsang et al

    S. Tsang et al. Hybrid quantum-classical generative adversarial network for high resolution image generation. IEEE Transactions on Quantum Engineering , 4:3102419, 2023

  23. [31]

    Wu et al

    Y . Wu et al. Radio signal classification by adversarially robust quantum machine learning. arXiv:2312.07821, 2023

  24. [32]

    Khatun et al

    A. Khatun et al. Quantum transfer learning with adversarial robustness for classification of high-resolution image datasets. Adv. Quant. Technol., page 2400268, 2024

  25. [33]

    West, Jamie Heredge, Martin Sevior, and Muhammad Usman

    Maxwell T. West, Jamie Heredge, Martin Sevior, and Muhammad Usman. Provably trainable rotationally equivariant quantum machine learning. PRX Quantum, 5:030320, Jul 2024

  26. [34]

    Reflection equivariant quantum neu- ral networks for enhanced image classification

    Maxwell T West, Martin Sevior, and Muhammad Usman. Reflection equivariant quantum neu- ral networks for enhanced image classification. Machine Learning: Science and Technology , 4(3):035027, aug 2023

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.