7
collaborators
2026–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
3 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Encrypted Federated Learning of Quantum Neural Networks via Continuous-Rotation Homomorphic Encryption | QCRYPT 2026 | Nathan Mani, Arshad Patel, William Knottenbelt, Roberto Bondesan |
Federated learning (FL) trains a shared model across many data holders without pooling raw data, but the parameter exchange itself is vulnerable to gradient-inversion attacks. Among privacy-preserving remedies, fully homomorphic encryption (FHE) is the strongest cryptographic option that lets an honest-but-curious server aggregate updates without ever seeing them in the clear. Extending FHE to quantum machine learning, where the model parameters are continuous rotation angles of a variational quantum circuit, has so far required either thousands of interactive client--server rounds per training step or compiling every rotation into long sequences of a discrete gate alphabet, an overhead that destroys any quantum-side advantage. The central technical observation of this work is that single-qubit rotation composition under the quaternion representation of $\mathrm{SU}(2)$ reduces to a degree-2 polynomial on $\mathbb{R}^4$, which the CKKS scheme evaluates within a single multiplicative depth without bootstrapping. The consequence is a practical construction that enables non-interactive encrypted federated training of hybrid quantum--classical neural networks: information-theoretic security at the quantum-state level is composed with RLWE-based computational security for the classical aggregation. A small-scale feasibility study ($\leq\!3$ clients, $\leq\!5$ FL rounds) on the California Housing regression benchmark shows that the encrypted model matches or slightly improves over the plaintext quantum baseline in every run ($\mathrm{MSE}=0.612$ versus $0.727$) and approaches the classical CKKS-FedAvg baseline ($0.591$), an effect that is consistent with, and which we hypothesise is driven by, mild stochastic regularisation from CKKS approximation noise. Homomorphic FedAvg matches plaintext FedAvg to within $4{\times}10^{-8}$ rad of rotation-angle error in our runs. A protocol-accounting cost model predicts a $10\times$--$30\times$ reduction in per-rotation compute relative to the discrete-gate baseline as target precision tightens, and round-trip state fidelity of $0.992$ is measured on the 156-qubit \texttt{ibm\_fez} processor. The accompanying open-source release is, to the best of our knowledge, the first publicly available implementation of continuous-rotation quantum homomorphic encryption, and is intended to lower the barrier to further work on privacy-preserving quantum machine learning. |
||
| Discovering QKD Eavesdropping Strategies under Asymmetric and Time-Varying Noise | QCRYPT 2026 | Daniel Budina, Benjamin Gras, Abdelrahman Shehata, Roberto Bondesan |
Discovering QKD eavesdropping strategies under asymmetric and time-varying noise entails joint optimisation over discrete attack structure and continuous parameters under a strict evaluation budget. A minimal two-loop search framework, EvoluCMAES, is employed, in which the topology-mutation operator is the only domain-specific component. In BB84, compact eavesdropping circuits of 4--6 gates are consistently identified from an arbitrary-depth search space, approaching the analytical Pauli-channel cloning-machine bound under bit-flip noise. When reformulated as a sequential decision problem, the resulting policy class with feasibility masking and matched hyperparameters recovers the greedy-Oracle strategy for both BB84 and E91/DIQKD. Under soft feasibility, a regime is observed in which a small increase in detection probability yields a statistically significant improvement over the greedy oracle, indicating that budget-limited search exposes nontrivial attack strategies in the presence of noise asymmetry and temporal variation. |
||
| Quantum-Switch-Verified Zero-Knowledge and One-Way State Generators in the Bounded Quantum Storage Model | QCRYPT 2026 | — |
Classical zero-knowledge proofs for \NP-complete problems rest on computational hardness that quantum algorithms threaten, while information-theoretic zero-knowledge for \NP\ is believed impossible in the unconstrained model. An information-theoretically secure, three-message zero-knowledge interactive proof for Hamiltonian Cycle (\HC) in a \emph{symmetric} bounded quantum storage model (\BQSM) is presented here: soundness rests on a commitment that binds even an \emph{unbounded} prover, while zero-knowledge rests only on the verifier's bounded coherent memory, so security is \emph{everlasting}. The construction divides the three geometric requirements of a Hamiltonian cycle – spanning $2$-regularity, even degree, and connectivity -- among the tools best suited to each: a \BQSM\ commitment to a blinded adjacency matrix carries isomorphism and binding, a classical depth-first search carries connectivity, a classical count carries the degree, and a coherently controlled \emph{quantum switch} certifies the even-degree (parity) property by routing it onto a single, deterministic control-qubit outcome. The geometric core is an exact algebraic identity: the global transversal $A=\bigotimes_v X_v$ and the edge operator $B=\prod_{e\in\sigma}\mathrm{CZ}_e$ satisfy $X^{\bm a}\ket{H}=(-1)^{f_H(\bm a)}Z^{\Adj(H)\bm a}\ket{H}$, so the switch acts as a non-destructive meter for membership of a bit-vector in the $\F_2$-kernel of the adjacency matrix, of which ``every degree even'' is the all-ones case. The same identity assigns the control outcome a second meaning -- the length parity (bipartiteness) of the certified cycle -- so one control qubit reports two independent invariants at once. On an accepting run, the switch returns the verified cycle state $\ket{\pi(C)}$ \emph{intact} while contributing \emph{exactly zero} to the zero-knowledge trace distance; perfect zero-knowledge is local to this subroutine, while the full protocol is statistically zero-knowledge with the only negligible leakage coming from the commitment. Complete proofs of completeness, soundness against unbounded provers, and statistical zero-knowledge are given, the underlying primitive is formalised as a bounded-storage one-way state generator ($\BQSM$-$\OWSG$), and the simulator advantage is bounded as a graceful function of a control-address leakage rate. For Hamiltonian Cycle, the switch is realisable as a textbook Hadamard test -- no indefinite causal order is needed -- and the system register need not be transmitted, lowering the honest prover's coherent memory to $O(1)$. The indefinite causal order earns its keep in a companion regime: for two Pauli operations, the switch reads their symplectic inner product onto one control bit non-destructively, with a single use of each, a task no fixed-order circuit matches. Multidisciplinary applications close the paper -- certified $\F_2$-linear-algebra queries on graph states, non-destructive verification for analogue quantum simulators, structure-certified randomness, and proof tokens via Fiat--Shamir. |
||
Collaborators
| Co-author | Joint talks |
|---|---|
| Roberto Bondesan | 2 |
| Abdelrahman Shehata | 1 |
| Arshad Patel | 1 |
| Benjamin Gras | 1 |
| Daniel Budina | 1 |
| Nathan Mani | 1 |
| William Knottenbelt | 1 |