← back

SoK: Adversarial Robustness of the Variational Quantum Eigensolver via Red-Teaming

📄 arXiv:2607.19318 · 📥 PDF · 2026-07-21 · quant-ph

Authors: Ahmed Azaz Humdoon [arXiv · scholar] , Cheng Chu [arXiv · scholar] , Lei Jiang [arXiv · scholar] , Qian Lou [arXiv · scholar] , Mengxin Zheng [arXiv · scholar]

🕰 Orloj analysis

7.9
Total score
8.5
Consistency
8.0
Quality
AD relevance

Tento článek systematizuje a hodnotí odolnost Variational Quantum Eigensolveru (VQE) proti různým typům adversariálních útoků. Autoři představují VQE-AdvBench, sjednocený benchmark, který odhaluje, že útoky manipulující s Zero-Noise Extrapolation jsou nejškodlivější.

💡 Práce přináší cenné systematické srovnání existujících útoků na VQE, což je klíčové pro praktickou bezpečnost kvantových algoritmů, ale nenabízí nové teoretické průlomy.

Categories: INF-7 INF-2 MET-1 EXP-7

✓ falsifiable, modest_claims, systematic_evaluation

⚠ code_availability_unspecified, error_bars_not_explicitly_mentioned_in_abstract

📄 Abstract

The Variational Quantum Eigensolver (VQE) is a leading algorithm for estimating molecular ground-state energies on near-term quantum hardware, with applications spanning quantum chemistry, materials science, and drug discovery. As VQE workloads are increasingly deployed through cloud-based ``VQE-as-a-service'' pipelines, they become exposed to adversaries such as compromised service components, malicious co-tenants, or insiders in the transpilation stack, any of which can corrupt results before they reach the user. A range of attacks on variational quantum circuits has been proposed, but each has been studied in isolation: some on quantum classifiers with accuracy-based metrics, others on variational quantum algorithms with energy-error metrics. This lack of a common evaluation setup makes their relative severity difficult to compare and leaves the security of VQE poorly characterized. In this work, we present \textbf{VQE-AdvBench}, the first unified red-teaming benchmark for the Variational Quantum Eigensolver, systematizing these attacks under a single evaluation protocol to rigorously assess VQE's adversarial robustness. We organize attacks along a black-, gray-, and white-box access taxonomy, and evaluate seven representative attack scenarios -- the QTrojan circuit backdoor, the QDoor parameter backdoor, parameter-space adaptations of FGSM and PGD, and three QNBAD noise-induced variants -- over a fixed molecule-ansatz-backend-metric configuration, on H$_2$ and H$_3^+$ across five noise-calibrated IBM backends. Our results reveal a clear severity ordering: noise-induced attacks that manipulate the Zero-Noise Extrapolation (ZNE) pipeline are the most damaging (up to 8.84$\times$ error amplification), followed by the QTrojan circuit-level backdoor (7.52$\times$), while the QDoor parameter-level backdoor is the least effective, yielding only marginal amplification (up to 1.37$\times$).

📄 arXiv abstract page 📥 PDF