Abstract
The high costs of existing quantum cloud services, combined with the growing demand for quantum resources, could drive the development of more affordable but potentially untrusted quantum cloud providers. Deploying or hosting quantum models, such as quantum neural networks (QNNs), on these untrusted platforms introduces numerous security concerns, with the most critical being model theft. This vulnerability arises from the cloud provider's full access to the circuits during training and/or inference. In this work, we introduce STIQ, a novel ensemble-based strategy designed to safeguard QNNs against such cloud-based adversaries. Our method innovatively trains two distinct QNNs concurrently, hosting them on the same or different platforms, in such a way that each network yields obfuscated outputs, rendering the individual QNNs ineffective for adversaries operating within cloud environments. However, when these outputs are combined locally (using an aggregate function), they reveal the correct result. Through extensive experiments across various QNNs and datasets, our technique has proven to effectively mask the accuracy and losses of the individually hosted models by up to 76 %, albeit at the expense of a ≤2 x increase in total computational overhead. This trade-off, however, is a small price to pay for the enhanced security and integrity of QNNs in cloud-based environments prone to untrusted adversaries. We also demonstrated STIQ's practical application by evaluating it on multiple real quantum hardwares, showing that STIQ achieves up to ~ 70% obfuscation, with combined performance comparable to an unobfuscated model.
| Original language | English (US) |
|---|---|
| Title of host publication | Proceedings of the IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025 |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 78-87 |
| Number of pages | 10 |
| Edition | 2025 |
| ISBN (Electronic) | 9798331510565 |
| DOIs | |
| State | Published - 2025 |
| Event | 2025 IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025 - San Jose, United States Duration: May 5 2025 → May 8 2025 |
Conference
| Conference | 2025 IEEE International Symposium on Hardware Oriented Security and Trust, HOST 2025 |
|---|---|
| Country/Territory | United States |
| City | San Jose |
| Period | 5/5/25 → 5/8/25 |
All Science Journal Classification (ASJC) codes
- Artificial Intelligence
- Hardware and Architecture
- Safety, Risk, Reliability and Quality
Fingerprint
Dive into the research topics of 'STIQ: Safeguarding Training and Inferencing of Quantum Neural Networks from Untrusted Cloud'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver