AG-2024.05-2538·quant-ph·cross-listed: cs.LG
STIQ: Safeguarding Training and Inferencing of Quantum Neural Networks from Untrusted Cloud
Authors
- Satwik Kundu
- Swaroop Ghosh
Abstract
The high expenses imposed by current quantum cloud providers, coupled with the escalating need for quantum resources, may incentivize the emergence of cheaper cloud-based quantum services from potentially untrusted providers. Deploying or hosting quantum models, such as Quantum Neural Networks (QNNs), on these untrusted platforms introduces a myriad of security concerns, with the most critical one being model theft. This vulnerability stems from the cloud provider's full access to these circuits during training and/or inference. In this work, we introduce STIQ, a novel ensemble-based strategy designed to safeguard QNNs against such cloud-based adversaries. Our method innovatively trains two distinct QNNs concurrently, hosting them on same or different platforms, in a manner that each network yields obfuscated outputs rendering the individual QNNs ineffective for adversaries operating within cloud environments. However, when these outputs are combined locally (using an aggregate function), they reveal the correct result. Through extensive experiments across various QNNs and datasets, our technique has proven to effectively masks the accuracy and losses of the individually hosted models by upto $76\%$, albeit at the expense of $\leq 2\times$ increase in the total computational overhead. This trade-off, however, is a small price to pay for the enhanced security and integrity of QNNs in a cloud-based environment prone to untrusted adversaries. We also demonstrated STIQ's practical application by evaluating it on multiple real quantum hardwares, showing that STIQ achieves up to $\approx 70\%$ obfuscation, with combined performance similar to an unobfuscated model.
Submitted
29 May 20241 year ago
Version
v1
License
CC-BY-4.0
DOI
10.48550/arXiv.2405.18746
Summary
STIQ protects quantum neural networks hosted on untrusted cloud servers by splitting each network into two parts that produce gibberish individually but combine locally to give correct answers, masking the model from being stolen while doubling computational cost.
- Quantum cloud computing faces a model-theft problem: untrusted providers can see and copy your trained quantum circuits. STIQ addresses this by making individual models useless to an eavesdropper.
- The method trains two QNNs in parallel such that their separate outputs are obfuscated (hiding accuracy by up to 76%), but combining them locally recovers the true result—a clever way to split security responsibility between client and cloud.
- Tested on real quantum hardware, STIQ achieves ~70% obfuscation with only 2× computational overhead, suggesting practical viability as quantum cloud services mature.
curious · generated by claude-haiku-4-5
Chat with this PDF
Ask questions, probe assumptions, request a plain-English summary. Answers cite sections from the preprint itself.
Community
Questions and answers about this paper from other readers. No formal peer review — just a place to think out loud.