34
collaborators
2020–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
2 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
|
Classical Verification of Quantum Learning ↗
|
TQC 2024 | regular | ▸Matthias C. Caro, Marcel Hinsche, Marios Ioannou, Alexander Nietner |
Quantum data access and quantum processing can make certain classically intractable learning tasks feasible. However, quantum capabilities will only be available to a select few in the near future. Thus, reliable schemes that allow classical clients to delegate learning to untrusted quantum servers are required to facilitate widespread access to quantum learning advantages. Building on a recently introduced framework of interactive proof systems for classical machine learning by Goldwasser et al. (ITCS 2021), we develop a framework for classical verification of quantum learning. We exhibit learning problems that a classical learner cannot efficiently solve on their own, but that they can efficiently and reliably solve when interacting with an untrusted quantum prover. Concretely, we consider the problems of agnostic learning parities and Fourier-sparse functions with respect to distributions with uniform input marginal. We propose a new quantum data access model that we call "mixture-of-superpositions" quantum examples, based on which we give efficient quantum learning algorithms for these tasks. Moreover, we prove that agnostic quantum parity and Fourier-sparse learning can be efficiently verified by a classical verifier with only random example or statistical query access. Finally, we showcase two general scenarios in learning and verification in which quantum mixture-of-superpositions examples do not lead to sample complexity improvements over classical data. Our results demonstrate that the potential power of quantum data for learning tasks, while not unlimited, can be utilized by classical agents through interaction with untrusted quantum entities. |
|||
| Generalization guarantees for variational quantum machine learning | TQC 2022 | regular | ▸Matthias C. Caro, Elies Gil-Fuster, Johannes Jakob Meyer, Jens Eisert, Hsin-Yuan Robert Huang, Marco Cerezo, Kunal Sharma, Andrew Sornborger, Lukasz Cincio, Patrick Coles |
8 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Signature-Based Backdoors in Variational Quantum Models | QCRYPT 2026 | Eleanor Kedem, Francesco Petruccione |
Variational Quantum Models represent a promising tool in the emerging field of quantum machine learning, and can potentially be used for a large variety of sectors and purposes. However, for the foreseeable future, only a select number of entities and organizations have access to machines that can run them. Therefore, training and inference of such models need to be delegated, outsourced, or externally influenced by those organizations, which may have ulterior motives than those of the original model owner. As such, understanding this vulnerability, particularly in adversarial settings, is of utmost importance. This raises a natural cryptographic question: can hidden malicious functionality be embedded into such models in a way that remains attacker-controlled yet difficult to recognize from the expected circuit structure? In classical machine learning, recent work has shown the existence of undetectable backdoors using cryptographically structured triggers. We investigate the corresponding question for parameterized quantum classifiers. Our approach is based on digital-signature verification. The core idea is to embed a verifier-like mechanism into a parameterized quantum classifier so that a signed input activates a hidden malicious behavior, while unsigned inputs continue through the ordinary classification pathway. Signature-based triggers are appealing because they are rare, secret-controlled, and non-replicable, making them structurally different from standard backdoor triggers. This digital-signature-based mechanism realizes a black-box, undetectable backdoor. We then study the setting of gray-box undetectability, namely how the verifier-like mechanism can be disguised within a given model family to avoid detection under partial circuit inspection. We consider three construction families. The first is a hard verifier, which most closely follows exact GPV-style verification logic and retains explicit arithmetic structure. The second is a soft verifier, which replaces exact acceptance by a smoother approximate mechanism. The third is a trainable verifier, which learns trigger behavior without enforcing the full arithmetic structure of exact verification. These three constructions span a spectrum from cryptographic faithfulness to implementation flexibility. Our main message is that these constructions expose a central trade-off. The more faithfully one implements exact cryptographic verification inside a quantum classifier, the larger and more structurally visible the resulting circuit becomes. This effect is already apparent at the level of raw verifier overhead, such as excessive gate and ancilla requirements, even before additional camouflage is introduced to blend the verifier into an expected ansatz. Softer and trainable constructions offer greater flexibility and may integrate more naturally into variational circuit structure, but they move away from exact cryptographic semantics. Our contribution is therefore to identify a gray-box threat setting relevant to VQMs, present three concrete verifier-based construction paradigms, and compare them through the combined lens of trigger functionality, concealment strategy, and circuit resource overhead. The results suggest that signature-based backdoors are a meaningful and underexplored cryptographic threat model for quantum learning systems, while also highlighting the substantial gap between cryptographic elegance and practical embedding cost. |
||
| Efficient Near-Term Quantum Gibbs Sampling via Local Detailed Balance Condition | QIP 2026 | ▸Dominik Hahn, Abhinav Deshpande, Oles Shtanko |
| Wavefunction flows: Efficient quantum simulation of flow models for generating qsamples | TQC 2026 | David Layden, Vojtech Havlicek, Anirban Narayan Chowdhury, Kirill Neklyudov |
Flow models are a cornerstone of modern machine learning. They are generative models that progressively transform probability distributions according to learned dynamics. Specifically, they learn a continuous-time Markov process that efficiently maps samples from a simple source distribution into samples from a complex target distribution. We show that these models are naturally related to the Schrödinger equation, for an unusual Hamiltonian on continuous variables. Moreover, we prove that the dynamics generated by this Hamiltonian can be efficiently simulated on a quantum computer. Together, these results give a quantum algorithm for preparing coherent encodings (a.k.a., qsamples) for a vast family of probability distributions—namely, those expressible by flow models—by reducing the task to an existing classical learning problem, plus Hamiltonian simulation. For statistical problems defined by flow models, such as mean estimation and property testing, this enables the use of quantum algorithms tailored to qsamples, which may offer advantages over classical algorithms based only on samples from a flow model. More broadly, these results reveal a close connection between state-of-the-art machine learning models, such as flow matching and diffusion models, and one of the main expected capabilities of quantum computers: simulating quantum dynamics. |
||
| Dynamic parameterized quantum circuits: expressive and barren-plateau free | QIP 2025 | Abhinav Deshpande, Marcel Hinsche, Sona Najafi, Kunal Sharma, Christa Zoufal |
| Classical Verification of Quantum Learning | QIP 2024 | Matthias C. Caro, Marcel Hinsche, Marios Ioannou, Alexander Nietner |
| A single T-gate makes distribution learning hard | QIP 2023 | Marcel Hinsche, Marios Ioannou, Alexander Nietner, Jonas Haferkamp, Yihui Quek, Dominik Hangleiter, Jean-Pierre Seifert, Jens Eisert |
| Expressive power of tensor-network factorizations for probabilistic modeling - with applications from hidden Markov models to quantum machine learning | QIP 2020 | Ivan Glasser, Nicola Pancotti, Jens Eisert, Ignacio Cirac |
| Fährmann, Barthélémy Meynard-Piganeau and Jens Eisert | QIP 2020 | Frederik Wilde, Johannes Jakob Meyer, Maria Schuld, Paul K |
Collaborators
| Co-author | Joint talks |
|---|---|
| Marcel Hinsche | 4 |
| Alexander Nietner | 3 |
| Jens Eisert | 3 |
| Marios Ioannou | 3 |
| Matthias C. Caro | 3 |
| Abhinav Deshpande | 2 |
| Johannes Jakob Meyer | 2 |
| Kunal Sharma | 2 |
| Andrew Sornborger | 1 |
| Anirban Narayan Chowdhury | 1 |
| Christa Zoufal | 1 |
| David Layden | 1 |
| Dominik Hahn | 1 |
| Dominik Hangleiter | 1 |
| Eleanor Kedem | 1 |
| Elies Gil-Fuster | 1 |
| Francesco Petruccione | 1 |
| Frederik Wilde | 1 |
| Hsin-Yuan Robert Huang | 1 |
| Ignacio Cirac | 1 |