Table of Contents
Fetching ...

Towards Quantum Enhanced Adversarial Robustness with Rydberg Reservoir Learning

Shehbaz Tariq, Muhammad Talha, Symeon Chatzinotas, Hyundong Shin

TL;DR

This work investigates the first systematic evaluation of adversarial robustness in a QRC based learning model and reveals a new source of quantum advantage and provides practical guidance for the secure deployment of machine learning models on quantum-centric supercomputing with near-term hardware.

Abstract

Quantum reservoir computing (QRC) leverages the high-dimensional, nonlinear dynamics inherent in quantum many-body systems for extracting spatiotemporal patterns in sequential and time-series data with minimal training overhead. Although QRC inherits the expressive capabilities associated with quantum encodings, recent studies indicate that quantum classifiers based on variational circuits remain susceptible to adversarial perturbations. In this perspective, we investigate the first systematic evaluation of adversarial robustness in a QRC based learning model. Our reservoir comprises an array of strongly interacting Rydberg atoms governed by a fixed Hamiltonian, which naturally evolves under complex quantum dynamics, producing high-dimensional embeddings. A lightweight multilayer perceptron serves as the trainable readout layer. We utilize the balanced datasets, namely MNIST, Fashion-MNIST, and Kuzushiji-MNIST, as a benchmark for rigorously evaluating the impact of augmenting the quantum reservoir with a Multilayer perceptron (MLP) in white-box adversarial attacks to assess its robustness. We demonstrate that this approach yields significantly higher accuracy than purely classical models across all perturbation strengths tested. This hybrid approach reveals a new source of quantum advantage and provides practical guidance for the secure deployment of machine learning models on quantum-centric supercomputing with near-term hardware.

Towards Quantum Enhanced Adversarial Robustness with Rydberg Reservoir Learning

TL;DR

This work investigates the first systematic evaluation of adversarial robustness in a QRC based learning model and reveals a new source of quantum advantage and provides practical guidance for the secure deployment of machine learning models on quantum-centric supercomputing with near-term hardware.

Abstract

Quantum reservoir computing (QRC) leverages the high-dimensional, nonlinear dynamics inherent in quantum many-body systems for extracting spatiotemporal patterns in sequential and time-series data with minimal training overhead. Although QRC inherits the expressive capabilities associated with quantum encodings, recent studies indicate that quantum classifiers based on variational circuits remain susceptible to adversarial perturbations. In this perspective, we investigate the first systematic evaluation of adversarial robustness in a QRC based learning model. Our reservoir comprises an array of strongly interacting Rydberg atoms governed by a fixed Hamiltonian, which naturally evolves under complex quantum dynamics, producing high-dimensional embeddings. A lightweight multilayer perceptron serves as the trainable readout layer. We utilize the balanced datasets, namely MNIST, Fashion-MNIST, and Kuzushiji-MNIST, as a benchmark for rigorously evaluating the impact of augmenting the quantum reservoir with a Multilayer perceptron (MLP) in white-box adversarial attacks to assess its robustness. We demonstrate that this approach yields significantly higher accuracy than purely classical models across all perturbation strengths tested. This hybrid approach reveals a new source of quantum advantage and provides practical guidance for the secure deployment of machine learning models on quantum-centric supercomputing with near-term hardware.
Paper Structure (21 sections, 22 equations, 6 figures, 1 table)

This paper contains 21 sections, 22 equations, 6 figures, 1 table.

Figures (6)

  • Figure 1: (a) QRC based learning Framework. (b) Classification performance and robustness of the quantum reservoir on a balanced MNIST subset. Here, we use a balanced MNIST dataset comprising $100$ handwritten-digit samples per class ($10$ classes in total), with a $70\%$/$30\%$ train-test split. We keep $\delta = N$ here. (Left) Clean-test accuracies achieved by a fixed classical readout layer when driven by quantum reservoirs under different configurations (atoms) for $N$. (Right) Dependence of classification robustness on the dimensionality $N$ of the reservoir’s learning space.
  • Figure 2: Sample images from the three benchmark datasets employed in this study: MNIST, Fashion-MNIST, and Kuzushiji-MNIST. Each dataset consists of 10 balanced classes used to rigorously evaluate the adversarial robustness of the quantum reservoir learning model.
  • Figure 3: Classification performance and adversarial robustness of the quantum reservoir on a balanced MNIST subset of all the $10$ classes under three attacks. (a) FGSM (b) PGD (c) Deepfool. For all the attacks, we vary the budget $\varepsilon \in [0.0, 0.1]$, with $100$ gradient steps and perturbation rate of $10^{-3}.$
  • Figure 4: Adversarial robustness with $\delta=N$ for (a) FGSM, (b) PGD, (c) DeepFool, evaluated on classes $N\in\{4,6,8,10\}$ (atoms $=N$). Top row (horizontal bars): mean $\Delta$ Accuracy per class, $\overline{\Delta\mathrm{Acc}}_{N} =\frac{1}{|\mathcal{E}|}\sum_{\varepsilon\in\mathcal{E}} (\mathrm{Acc}^{\text{\ac{QRC}}+\text{\ac{MLP}}}_{N}(\varepsilon) -\mathrm{Acc}^{\text{\ac{MLP}}}_{N}(\varepsilon))$, with $\mathcal{E}\subset[0.0,0.1]$. Bottom row (line plots): Accuracy vs. $\varepsilon$ (solid: QRC+MLP; dashed: MLP). Positive bars indicate enhancement from QRC (larger $\Delta$ Accuracy), while negative bars indicate degradation. Dataset:MNIST.
  • Figure 5: Adversarial robustness with $\delta=N$ for (a) FGSM, (b) PGD, (c) DeepFool, evaluated on classes $N\in\{4,6,8,10\}$ (atoms $=N$). Top row (horizontal bars): mean $\Delta$ Accuracy per class, $\overline{\Delta\mathrm{Acc}}_{N} =\frac{1}{|\mathcal{E}|}\sum_{\varepsilon\in\mathcal{E}} (\mathrm{Acc}^{\text{\ac{QRC}}+\text{\ac{MLP}}}_{N}(\varepsilon) -\mathrm{Acc}^{\text{\ac{MLP}}}_{N}(\varepsilon))$, with $\mathcal{E}\subset[0.0,0.1]$. Bottom row (line plots): Accuracy vs. $\varepsilon$ (solid: QRC+MLP; dashed: MLP). Positive bars indicate enhancement from QRC (larger $\Delta$ Accuracy), while negative bars indicate degradation. Dataset:Fashion-MNIST.
  • ...and 1 more figures