1
program role
18
collaborators
2009–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
9 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Signature-Based Backdoors in Variational Quantum Models | QCRYPT 2026 | Eleanor Kedem, Ryan Sweke |
Variational Quantum Models represent a promising tool in the emerging field of quantum machine learning, and can potentially be used for a large variety of sectors and purposes. However, for the foreseeable future, only a select number of entities and organizations have access to machines that can run them. Therefore, training and inference of such models need to be delegated, outsourced, or externally influenced by those organizations, which may have ulterior motives than those of the original model owner. As such, understanding this vulnerability, particularly in adversarial settings, is of utmost importance. This raises a natural cryptographic question: can hidden malicious functionality be embedded into such models in a way that remains attacker-controlled yet difficult to recognize from the expected circuit structure? In classical machine learning, recent work has shown the existence of undetectable backdoors using cryptographically structured triggers. We investigate the corresponding question for parameterized quantum classifiers. Our approach is based on digital-signature verification. The core idea is to embed a verifier-like mechanism into a parameterized quantum classifier so that a signed input activates a hidden malicious behavior, while unsigned inputs continue through the ordinary classification pathway. Signature-based triggers are appealing because they are rare, secret-controlled, and non-replicable, making them structurally different from standard backdoor triggers. This digital-signature-based mechanism realizes a black-box, undetectable backdoor. We then study the setting of gray-box undetectability, namely how the verifier-like mechanism can be disguised within a given model family to avoid detection under partial circuit inspection. We consider three construction families. The first is a hard verifier, which most closely follows exact GPV-style verification logic and retains explicit arithmetic structure. The second is a soft verifier, which replaces exact acceptance by a smoother approximate mechanism. The third is a trainable verifier, which learns trigger behavior without enforcing the full arithmetic structure of exact verification. These three constructions span a spectrum from cryptographic faithfulness to implementation flexibility. Our main message is that these constructions expose a central trade-off. The more faithfully one implements exact cryptographic verification inside a quantum classifier, the larger and more structurally visible the resulting circuit becomes. This effect is already apparent at the level of raw verifier overhead, such as excessive gate and ancilla requirements, even before additional camouflage is introduced to blend the verifier into an expected ansatz. Softer and trainable constructions offer greater flexibility and may integrate more naturally into variational circuit structure, but they move away from exact cryptographic semantics. Our contribution is therefore to identify a gray-box threat setting relevant to VQMs, present three concrete verifier-based construction paradigms, and compare them through the combined lens of trigger functionality, concealment strategy, and circuit resource overhead. The results suggest that signature-based backdoors are a meaningful and underexplored cryptographic threat model for quantum learning systems, while also highlighting the substantial gap between cryptographic elegance and practical embedding cost. |
||
| A Quantum Leaky Integrate-and-Fire Spiking Neuron and Network | QIP 2025 | Dean Brand |
| NISQ friendly approach towards variational quantum eigensolver | QIP 2023 | Eyuel Eshetu Elala, Aidan Pellow-Jarman, Rowan Pellow-Jarman, Shane McFarthing, June-Koo Kevin Rhee |
| Quantum-enhanced analysis of discrete stochastic processes | QIP 2021 | Carsten Blank, Daniel Kyungdeock Park |
| Portable QKD Device using the COW Protocol | QCRYPT 2014 | Sharmini Pillay, Abdul Mirza |
| A study of the influences a pseudo random phase plate has on the quantumness of a polarisation based entangled photon source | QCRYPT 2014 | Yaseera Ismail, Abdul Mirza, Andrew Forbes |
| Microscopic derivation of open quantum walks | QIP 2013 | Ilya Sinayskiy |
| Towards the security of coherent-one-way quantum key distribution protocol | QCRYPT 2011 | Mhlambululi Mafu, Adriana Marais |
| Quantum Walks and the Dispersion Relation in One Dimensional Many-particle System on Lattice | QIP 2009 | Dibwe Pierrot Musumbu |
Committee service
| Conference | Committee | Position | Title |
|---|---|---|---|
| TQC 2010 | program | member | — |
Collaborators
| Co-author | Joint talks |
|---|---|
| Abdul Mirza | 2 |
| Adriana Marais | 1 |
| Aidan Pellow-Jarman | 1 |
| Andrew Forbes | 1 |
| Carsten Blank | 1 |
| Daniel Kyungdeock Park | 1 |
| Dean Brand | 1 |
| Dibwe Pierrot Musumbu | 1 |
| Eleanor Kedem | 1 |
| Eyuel Eshetu Elala | 1 |
| Ilya Sinayskiy | 1 |
| June-Koo Kevin Rhee | 1 |
| Mhlambululi Mafu | 1 |
| Rowan Pellow-Jarman | 1 |
| Ryan Sweke | 1 |
| Shane McFarthing | 1 |
| Sharmini Pillay | 1 |
| Yaseera Ismail | 1 |