4
collaborators
2026–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
1 Poster
| Title | Conference | Co-authors |
|---|---|---|
| Encrypted Federated Learning of Quantum Neural Networks via Continuous-Rotation Homomorphic Encryption | QCRYPT 2026 | Marcel Mordarski, Arshad Patel, William Knottenbelt, Roberto Bondesan |
Federated learning (FL) trains a shared model across many data holders without pooling raw data, but the parameter exchange itself is vulnerable to gradient-inversion attacks. Among privacy-preserving remedies, fully homomorphic encryption (FHE) is the strongest cryptographic option that lets an honest-but-curious server aggregate updates without ever seeing them in the clear. Extending FHE to quantum machine learning, where the model parameters are continuous rotation angles of a variational quantum circuit, has so far required either thousands of interactive client--server rounds per training step or compiling every rotation into long sequences of a discrete gate alphabet, an overhead that destroys any quantum-side advantage. The central technical observation of this work is that single-qubit rotation composition under the quaternion representation of $\mathrm{SU}(2)$ reduces to a degree-2 polynomial on $\mathbb{R}^4$, which the CKKS scheme evaluates within a single multiplicative depth without bootstrapping. The consequence is a practical construction that enables non-interactive encrypted federated training of hybrid quantum--classical neural networks: information-theoretic security at the quantum-state level is composed with RLWE-based computational security for the classical aggregation. A small-scale feasibility study ($\leq\!3$ clients, $\leq\!5$ FL rounds) on the California Housing regression benchmark shows that the encrypted model matches or slightly improves over the plaintext quantum baseline in every run ($\mathrm{MSE}=0.612$ versus $0.727$) and approaches the classical CKKS-FedAvg baseline ($0.591$), an effect that is consistent with, and which we hypothesise is driven by, mild stochastic regularisation from CKKS approximation noise. Homomorphic FedAvg matches plaintext FedAvg to within $4{\times}10^{-8}$ rad of rotation-angle error in our runs. A protocol-accounting cost model predicts a $10\times$--$30\times$ reduction in per-rotation compute relative to the discrete-gate baseline as target precision tightens, and round-trip state fidelity of $0.992$ is measured on the 156-qubit \texttt{ibm\_fez} processor. The accompanying open-source release is, to the best of our knowledge, the first publicly available implementation of continuous-rotation quantum homomorphic encryption, and is intended to lower the barrier to further work on privacy-preserving quantum machine learning. |
||
Collaborators
| Co-author | Joint talks |
|---|---|
| Arshad Patel | 1 |
| Marcel Mordarski | 1 |
| Roberto Bondesan | 1 |
| William Knottenbelt | 1 |