2
collaborators
2026–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
1 Poster
| Title | Conference | Co-authors |
|---|---|---|
| Signature-Based Backdoors in Variational Quantum Models | QCRYPT 2026 | Ryan Sweke, Francesco Petruccione |
Variational Quantum Models represent a promising tool in the emerging field of quantum machine learning, and can potentially be used for a large variety of sectors and purposes. However, for the foreseeable future, only a select number of entities and organizations have access to machines that can run them. Therefore, training and inference of such models need to be delegated, outsourced, or externally influenced by those organizations, which may have ulterior motives than those of the original model owner. As such, understanding this vulnerability, particularly in adversarial settings, is of utmost importance. This raises a natural cryptographic question: can hidden malicious functionality be embedded into such models in a way that remains attacker-controlled yet difficult to recognize from the expected circuit structure? In classical machine learning, recent work has shown the existence of undetectable backdoors using cryptographically structured triggers. We investigate the corresponding question for parameterized quantum classifiers. Our approach is based on digital-signature verification. The core idea is to embed a verifier-like mechanism into a parameterized quantum classifier so that a signed input activates a hidden malicious behavior, while unsigned inputs continue through the ordinary classification pathway. Signature-based triggers are appealing because they are rare, secret-controlled, and non-replicable, making them structurally different from standard backdoor triggers. This digital-signature-based mechanism realizes a black-box, undetectable backdoor. We then study the setting of gray-box undetectability, namely how the verifier-like mechanism can be disguised within a given model family to avoid detection under partial circuit inspection. We consider three construction families. The first is a hard verifier, which most closely follows exact GPV-style verification logic and retains explicit arithmetic structure. The second is a soft verifier, which replaces exact acceptance by a smoother approximate mechanism. The third is a trainable verifier, which learns trigger behavior without enforcing the full arithmetic structure of exact verification. These three constructions span a spectrum from cryptographic faithfulness to implementation flexibility. Our main message is that these constructions expose a central trade-off. The more faithfully one implements exact cryptographic verification inside a quantum classifier, the larger and more structurally visible the resulting circuit becomes. This effect is already apparent at the level of raw verifier overhead, such as excessive gate and ancilla requirements, even before additional camouflage is introduced to blend the verifier into an expected ansatz. Softer and trainable constructions offer greater flexibility and may integrate more naturally into variational circuit structure, but they move away from exact cryptographic semantics. Our contribution is therefore to identify a gray-box threat setting relevant to VQMs, present three concrete verifier-based construction paradigms, and compare them through the combined lens of trigger functionality, concealment strategy, and circuit resource overhead. The results suggest that signature-based backdoors are a meaningful and underexplored cryptographic threat model for quantum learning systems, while also highlighting the substantial gap between cryptographic elegance and practical embedding cost. |
||
Collaborators
| Co-author | Joint talks |
|---|---|
| Francesco Petruccione | 1 |
| Ryan Sweke | 1 |