Skip to main navigation Skip to search Skip to main content

STIQ: Safeguarding Training and Inferencing of Quantum Neural Networks from Untrusted Cloud

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The high costs of existing quantum cloud services, combined with the growing demand for quantum resources, could drive the development of more affordable but potentially untrusted quantum cloud providers. Deploying or hosting quantum models, such as quantum neural networks (QNNs), on these untrusted platforms introduces numerous security concerns, with the most critical being model theft. This vulnerability arises from the cloud provider's full access to the circuits during training and/or inference. In this work, we introduce STIQ, a novel ensemble-based strategy designed to safeguard QNNs against such cloud-based adversaries. Our method innovatively trains two distinct QNNs concurrently, hosting them on the same or different platforms, in such a way that each network yields obfuscated outputs, rendering the individual QNNs ineffective for adversaries operating within cloud environments. However, when these outputs are combined locally (using an aggregate function), they reveal the correct result. Through extensive experiments across various QNNs and datasets, our technique has proven to effectively mask the accuracy and losses of the individually hosted models by up to 76 %, albeit at the expense of a ≤2 x increase in total computational overhead. This trade-off, however, is a small price to pay for the enhanced security and integrity of QNNs in cloud-based environments prone to untrusted adversaries. We also demonstrated STIQ's practical application by evaluating it on multiple real quantum hardwares, showing that STIQ achieves up to ~ 70% obfuscation, with combined performance comparable to an unobfuscated model.

Original languageEnglish (US)
Title of host publicationProceedings of the IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages78-87
Number of pages10
Edition2025
ISBN (Electronic)9798331510565
DOIs
StatePublished - 2025
Event2025 IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025 - San Jose, United States
Duration: May 5 2025May 8 2025

Conference

Conference2025 IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025
Country/TerritoryUnited States
CitySan Jose
Period5/5/255/8/25

All Science Journal Classification (ASJC) codes

  • Artificial Intelligence
  • Hardware and Architecture
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'STIQ: Safeguarding Training and Inferencing of Quantum Neural Networks from Untrusted Cloud'. Together they form a unique fingerprint.

Cite this