跳到正文
arXiv:cs.LG· Owen Friedewald, Srikar Alla, Ali Shiri Sichani, Chi-Ren Shyu·· 3 小时前AI 评分32

量子注意力中的归一化如何选择符号:审计鲁棒性消融实验

When Normalization Selects the Sign: Auditing Robustness Ablations in Quantum Attention

AI 导读

一项在四量子比特量子注意力检测器上的审计研究发现,移除输入缩放模块后鲁棒性差异可能来自比较规则而非模块本身。在固定物理攻击预算下该模块看似有益,但匹配编码器扰动上界后排序反转;替换训练模型的输入缩放会破坏检测,重训线性分类层可恢复检测率但改变个体预测。证据限于10个种子、精确模拟、合成数据和有限攻击集,经典基线在干净预测上表现更好。

正文

View PDF HTML (experimental)

Abstract:Removing an input-scaling module changes both a classifier and the perturbations reaching its encoder. A robustness difference can therefore reflect the comparison rule as well as the module. We demonstrate this problem in a four-qubit quantum-attention detector on generated power-grid trajectories. A learned scaling module appears beneficial at a fixed physical attack budget, but matching an upper bound on perturbations at the encoder reverses the ordering. Neither comparison alone establishes a robustness benefit caused by the module. The initial test also perturbs clean examples into attacked examples while retaining their original labels; tests restricted to already attacked examples do not establish a benefit. Replacing a trained model's input scales disrupts detection. Retraining its linear classification layer restores the detection rate, but changes individual predictions, leaving the comparison descriptive rather than causal. Two further design checks explain why the input quantum Fisher information regularizer cannot train this model's query parameters, and why removing confidence bounds does not establish a larger certified radius. The evidence is limited to ten seeds, exact simulation, synthetic data, and a restricted set of attacks; classical baselines achieve better clean prediction. The practical lesson is to specify which perturbation budget is fixed, check that attacks preserve labels and interventions preserve predictions, and distinguish exploratory controls from confirmatory evidence.
Comments: Accepted for presentation as a long oral at the NeurIPS 2026 SaTQuML Workshop, December 12-13, 2026, Atlanta, GA. arXiv version includes minor formatting revisions to meet submission requirements
Subjects: Quantum Physics (quant-ph); Cryptography and Security (cs.CR); Machine Learning (cs.LG)
Cite as: arXiv:2610.02641 [quant-ph]
  (or arXiv:2610.02641v1 [quant-ph] for this version)
  https://doi.org/10.48550/arXiv.2610.02641

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Owen Friedewald [view email]
[v1] Fri, 2 Oct 2026 00:57:53 UTC (37 KB)

来源:arXiv:cs.LG · arxiv.org