A quantum secure training method for preventing deep learning model replication
By embedding the time-varying noise fingerprint of a quantum processor into a deep learning model, the model is bound to the hardware, solving the problems of easy model copying and transfer, and improving security and intellectual property protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FUJIAN WANXIN TECH CO LTD
- Filing Date
- 2026-07-03
- Publication Date
- 2026-08-04
AI Technical Summary
Existing deep learning models lack effective underlying security mechanisms when facing copying and cross-device migration. Traditional software protection schemes are easily cracked, and the noise characteristics of quantum hardware are not utilized, causing model parameters to deviate from hardware properties, making them easy to illegally copy and migrate.
By monitoring the physical noise spectrum parameters of the quantum processor in real time, a hardware noise fingerprint is generated using the time-varying noise characteristics of quantum hardware, which is then embedded into the model's computational logic. The classical subnet weights are updated through quantum backpropagation gradients, thus binding the model to specific hardware.
It improves the security of deep learning models against unauthorized copying and migration, making dynamic hardware fingerprints difficult to clone, and enhances the intellectual property protection of models under hybrid computing architectures.
Smart Images

Figure CN122509367A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of neural network training and information security, and relates to a quantum-safe training method to prevent the copying of deep learning models. Background Technology
[0002] As core digital assets, deep learning models currently face severe challenges in protecting their intellectual property rights. Since model parameters are essentially digital files, they are easily copied and distributed once obtained by unauthorized parties. Existing model protection technologies, such as traditional software protection schemes, typically rely on code obfuscation or encrypted storage, but these still pose a risk of parameter extraction and decryption when faced with complex memory analysis techniques. Furthermore, model watermarking technology claims ownership by embedding digital fingerprints in weights or output behavior, but the robustness of these fingerprints is limited when subjected to transformation operations such as model fine-tuning or pruning, and the watermark information may be weakened.
[0003] Meanwhile, quantum computing technology is gradually being introduced into the field of machine learning to construct hybrid computing models. For example, Chinese patent application CN116415670A discloses a method for generating adversarial examples for quantum variational circuits. This method constructs a quantum variational circuit model, obtains the gradient value of the loss function with respect to samples, and calculates the ideal perturbation coefficients to generate adversarial examples for model training. Its purpose is to improve the robustness and defense capability of quantum machine learning models from the algorithmic level.
[0004] Based on the aforementioned existing technologies, it can be seen that current design paradigms for hybrid quantum and classical computing models mostly focus on optimizing algorithmic logic and largely treat the inherent physical noise of quantum hardware as a disruptive factor. Therefore, existing solutions generally tend to employ noise suppression or compensation methods to make the model's logical function approach an ideal noise-free state. While this pursuit of hardware independence improves the model's versatility, it also results in the trained model parameters exhibiting purely numerical attributes detached from the hardware. This allows the model logic to be easily transferred to other quantum processors or classical simulators, failing to leverage the physical uniqueness of quantum hardware to build underlying security mechanisms, thus posing significant security risks when facing illegal model duplication and misuse of heterogeneous devices.
[0005] Based on the above issues, how to deeply bind the computational logic of deep learning models to the specific physical hardware carriers on which they depend, so as to effectively restrict the illegal copying and cross-device migration of models, is a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0006] To address the aforementioned problems, this invention provides a quantum-safe training method to prevent the copying of deep learning models.
[0007] A quantum-safe training method to prevent deep learning model copying includes the following steps: S1. Obtain the original input data, call the classic feature extraction subnet to perform dimensionality reduction on the original input data, and generate an unnormalized high-dimensional feature vector. S2. Obtain the high-dimensional feature vector, trigger the quantum state encoder in the quantum processing unit to perform amplitude encoding on the high-dimensional feature vector, and generate a superposition state of qubits carrying the feature; S3. Call the trainable quantum circuit to receive the superposition state of qubits and implement physical evolution within it to generate the final state of quantum evolution; S4. Activate the quantum noise real-time monitoring unit, measure the state of idle bits in the quantum processing unit, and calculate and output the current time-varying noise spectrum parameters; S5. Configure an additional phase gate according to the current time-varying noise spectrum parameters, and use the additional phase gate to modulate the quantum evolution final state to generate a modulated final state with hardware noise fingerprint; S6. Perform the expected value measurement operation on the modulation final state with hardware noise fingerprint to generate a scalar output with noise fingerprint; S7. In response to the preset training loss calculation, the quantum state rollback controller is triggered to perform the corrected parameter offset operation, and the physical state of the quantum parameters in the trainable quantum circuit is updated in a closed loop. S8. Utilize the scalar output error of the noisy fingerprint to generate a backpropagation gradient signal to correct the weights of the classical feature extraction subnet.
[0008] A further aspect of this invention involves generating unnormalized high-dimensional feature vectors, comprising the following steps: The original input data is fed into the convolutional and normalization layers of the classic feature extraction subnetwork to extract the initial representation; The initial representation is input into a fully connected layer for hierarchical abstraction, and the hierarchical cascaded features are calculated and obtained. Aggregate cascaded features to generate high-dimensional feature vectors that represent the core features of the input data but are not normalized.
[0009] A further aspect of the present invention generates a superposition state of qubits carrying features, comprising the following steps: The high-dimensional feature vector is imported into the quantum state encoder located inside the quantum processing unit; The components of the high-dimensional feature vector are converted into corresponding microwave pulse amplitude parameters by hyperbolic tangent compression through a digital-to-analog converter. By using microwave pulses with microwave pulse amplitude parameters to sequentially drive the quantum bit chain to apply a rotating gate, each component is physically modulated onto the superposition state coefficients of the quantum bits, generating a superposition state of the quantum bits carrying characteristics.
[0010] A further aspect of the present invention generates the final state of quantum evolution, comprising the following steps: Within the quantum processing unit, initial quantum parameters are directly set via hardware-simulated electrical signals. Inputting the superposition state of qubits into a trainable quantum circuit containing parametric rotation gates and entanglement gates; Driven by microwave pulses, the superposition state of qubits is rotated and entangled according to the initial quantum parameters to generate the final quantum evolution state.
[0011] A further aspect of the present invention involves calculating and outputting the current time-varying noise spectrum parameters, including the following steps: The quantum noise real-time monitoring unit is triggered to collect environmental physical data within the quantum processing unit; Continuous measurement of the decoherence time and hardware gate fidelity of idle qubits; Based on the measured decoherence time and gate fidelity index, time-varying noise spectrum parameters reflecting the current physical characteristics of the hardware are calculated and output.
[0012] A further aspect of the present invention generates a modulation final state with hardware noise fingerprints, comprising the following steps: The additional phase angle is obtained by substituting the current time-varying noise spectrum parameters into a preset nonlinear physical function. Additional phase gates are configured using parameterized additional phase angles; An additional phase gate is applied to the quantum evolution final state, causing it to undergo a physical rotation that fluctuates with noise, thus generating a modulated final state with a hardware noise fingerprint.
[0013] A further aspect of the present invention generates a scalar output with noisy fingerprints, comprising the following steps: Projection measurement is performed on the modulated final state with hardware noise fingerprint using a preset Pauli operator. The measurement results are statistically analyzed by performing multiple repeated samplings using hardware circuitry. The statistical measurement results are aggregated and averaged to generate a scalar output of a noisy fingerprint that includes physical hardware noise fingerprint bias.
[0014] A further aspect of the present invention involves closed-loop updating of the physical states of quantum parameters in a trainable quantum circuit, comprising the following steps: Trigger the quantum state rollback controller to undo the current gate operation of the circuit and restore it to its encoded initial state; The offset angle is dynamically generated using quantum random numbers. Positive and negative offsets are applied to the current quantum parameters respectively. Two forward evolutions are performed and the difference in expected values is measured to obtain the unbiased gradient signal. The unbiased gradient signal is converted into an analog voltage adjustment value for the microwave generator, and the microwave pulse is physically adjusted to update the physical state of the quantum parameters in a closed loop.
[0015] A further aspect of the present invention involves performing two forward evolutions and measuring the difference in expected values to obtain an unbiased gradient signal, comprising the following steps: Activate the quantum random number generator inside the quantum processing unit to obtain a scaled small angle value as the offset angle; The voltage state of the quantum parameter is added to and subtracted by an offset proportional to the offset angle for forward evolution, and the positive and negative expected values are recorded respectively. The unbiased gradient signal is calculated by dividing the difference between the positive and negative expected values by a specific normalization factor.
[0016] A further aspect of this invention involves generating a backpropagation gradient signal to correct the weights of the classical feature extraction subnet, comprising the following steps: The overall network error is calculated by combining the current training labels with the scalar output of the noisy fingerprint; By triggering the quantum processing unit to perform the offset operation of the input encoding parameters and measuring the expected value difference, the derivative of the expected value with respect to each component of the original input feature vector is calculated, and a backpropagation gradient signal carrying an additional phase angle transformation factor is generated. The backpropagation gradient signal is sent to the classical feature extraction subnet, and its network weights are updated using standard backpropagation.
[0017] In summary, the present invention has the following beneficial technical effects: 1. By monitoring the physical noise spectrum parameters of the quantum processor in real time and using these parameters to modulate the phase of the quantum evolution state, the physical characteristics of the quantum hardware are embedded as hardware fingerprint information into the computational logic of the model. Since this noise fingerprint originates from physical quantities such as qubit decoherence time and gate fidelity that vary with time and environment, and is mapped to an additional phase angle through a nonlinear function, it directly affects the quantum state, thus correlating the model's forward propagation results with the current physical state of the specific quantum processor performing the computation. If the model parameters are transferred to a computational platform with different noise characteristics, the mismatch of the physical fingerprint will cause deviations in the output results, thereby achieving a low-level binding between the model and the physical hardware, improving the model's security against unauthorized copying and migration.
[0018] 2. The introduced hardware fingerprint possesses dynamic physical anti-cloning characteristics. The fingerprint originates from time-varying noise spectrum parameters obtained through continuous measurements of idle qubits, objectively reflecting the comprehensive response to physical processes such as environmental thermal noise and electromagnetic field fluctuations, exhibiting both randomness and time-varying properties. By embedding dynamically changing statistical characteristics into the fingerprint model, the difficulty of extracting fixed fingerprint features through input-output observation is increased. Simultaneously, since the underlying physical noise characteristics of different quantum processors are difficult to make completely consistent, the model's defense against conventional digital methods is further enhanced.
[0019] 3. By using adjoint variational computation to backpropagate gradients to update the weights of the classical subnet, a parametric symbiotic relationship is established between the classical network parameters and the noise characteristics of the specific quantum hardware. During the backpropagation phase, the gradient signal back to the classical module includes a transformation factor introduced by the additional phase angle, causing the weight update direction of the classical subnet in training iterations to be synchronously modulated by the noise mode of the quantum hardware. By guiding the feature representation extracted by the classical subnet to adapt to the specific noise mode of the paired quantum processor, the classical weights work collaboratively with the target hardware environment. When the model is removed from this specific hardware environment, its functional integrity will be limited, thereby strengthening the protection of model intellectual property rights under the hybrid computing architecture. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. The drawings are used to provide a further understanding of the present invention.
[0021] Figure 1 A flowchart illustrating the quantum-safe training method in the embodiments of this application is disclosed.
[0022] Figure 2 The hyperbolic tangent compression mapping curve from classical features to quantum rotation angles in the embodiments of this application is disclosed.
[0023] Figure 3 The Ramsey interferometry and decoherence attenuation curves of the idle qubits in the embodiments of this application are disclosed.
[0024] Figure 4 The random benchmark survival rate decay characteristic evaluation curve of the embodiments of this application is disclosed.
[0025] Figure 5 A schematic diagram of the module connection structure of the quantum-safe training system in the embodiments of this application is disclosed. Detailed Implementation
[0026] The following is in conjunction with the appendix Figure 1 - Figure 5 A preferred description of the present invention is provided below.
[0027] See attached document Figure 1 This invention proposes a quantum-safe training method to prevent the copying of deep learning models, comprising the following steps: S1. Obtain the original input data, call the classic feature extraction subnet to perform dimensionality reduction on the original input data, and generate an unnormalized high-dimensional feature vector. S2. Obtain the high-dimensional feature vector, trigger the quantum state encoder in the quantum processing unit to perform amplitude encoding on the high-dimensional feature vector, and generate a superposition state of qubits carrying the feature; S3. Call the trainable quantum circuit to receive the superposition state of qubits and implement physical evolution within it to generate the final state of quantum evolution; S4. Activate the quantum noise real-time monitoring unit, measure the state of idle bits in the quantum processing unit, and calculate and output the current time-varying noise spectrum parameters; S5. Configure an additional phase gate according to the current time-varying noise spectrum parameters, and use the additional phase gate to modulate the quantum evolution final state to generate a modulated final state with hardware noise fingerprint; S6. Perform the expected value measurement operation on the modulation final state with hardware noise fingerprint to generate a scalar output with noise fingerprint; S7. In response to the preset training loss calculation, the quantum state rollback controller is triggered to perform the corrected parameter offset operation, and the physical state of the quantum parameters in the trainable quantum circuit is updated in a closed loop. S8. Utilize the scalar output error of the noisy fingerprint to generate a backpropagation gradient signal to correct the weights of the classical feature extraction subnet.
[0028] In one embodiment of the present invention, step S1 includes the following steps: The original input data is fed into the convolutional and normalization layers of the classic feature extraction subnetwork to extract the initial representation; The initial representation is input into a fully connected layer for hierarchical abstraction, and the hierarchical cascaded features are calculated and obtained. Aggregate cascaded features to generate high-dimensional feature vectors that represent the core features of the input data but are not normalized.
[0029] Specifically, in one embodiment of the quantum-safe training method for preventing deep learning model duplication, the processing unit deployed on a classical computing server performs initial steps. The processing unit first acquires continuous raw input data of the target task to be processed. Here, raw input data refers to signals directly collected from a data source without any preprocessing, such as a pixel matrix output by an image sensor or continuous sampled values output by a time-series sensor.
[0030] In a specific application, the original input data is a multi-channel digital image, which can be represented as a dimensional... initial data tensor ,in and These represent the height and width of the image, respectively. This represents the number of color channels. The processing unit calls a pre-defined classic feature extraction subnet, which is usually a convolutional neural network structure. Its network structure may include, but is not limited to, the backbone of models such as ResNet, VGG, or Inception. Its function is to map the high-dimensional raw input data to a low-dimensional but more information-dense feature space.
[0031] Initial data tensor The data is fed into the input of the classic feature extraction subnet. The data stream first passes through a series of convolutional layers, each utilizing a set of dimensions... The learnable convolutional kernel is convolved with the input feature map to extract local spatial features. Then, a normalization layer, such as a batch normalization layer, is used to process the convolution result to stabilize the distribution of activation values. The spatial size of the convolution kernel. The number of channels in the input feature map.
[0032] The processed data is then passed through a non-linear activation function, such as the Modified Linear Unit (ReLU), to introduce non-linear expressive power and extract the initial representation. The activation feature map generated in this process is the initial representation. The initial representation refers to the intermediate feature map that retains key spatial or temporal structural information after convolution, normalization, and activation operations. The initial representation is flattened into a one-dimensional vector before being input to the fully connected layer. .
[0033] One-dimensional vector The features are fed into at least one fully connected layer for hierarchical feature abstraction, which is passed through a weight matrix. and a bias vector For a one-dimensional vector Perform an affine transformation to calculate and obtain the hierarchical cascaded features. Hierarchical cascaded features refer to the vector representation obtained by abstracting the preceding features through weight combination in the fully connected layer.
[0034] The output of the last fully connected layer of the classic feature extraction subnet is used as the aggregation result to generate an unnormalized representation of the core features of the input data. High-dimensional feature vectors Unnormalized high-dimensional feature vectors It is the final output of the classic feature extraction subnet, and its dimension is... As a hyperparameter, it is usually set according to the number of qubits and encoding scheme of the subsequent quantum state encoder. The value range is generally between 64 and 512. The reason for setting this value range is that if the dimension is too low, such as less than 64, a large number of effective features extracted by the classical network will be lost, affecting the convergence accuracy of the final model. If the dimension is too high, such as greater than 512, a huge amount of qubit resources are required for encoding, which exceeds the physical limit of current noisy medium-scale quantum devices and introduces too much hardware crosstalk noise. Therefore, this range achieves a balance between feature representation capability and quantum computing resource consumption.
[0035] The lack of normalization here means that the high-dimensional feature vectors are not normalized. Perform operations such as L2 norm normalization or the Softmax function to preserve the original numerical distribution properties for use in subsequent quantum encoding steps. Fully connected layers generate high-dimensional feature vectors. The specific process is described by the following formula:
[0036] in, It is output. Unnormalized high-dimensional feature vectors; It is a dimension The weight matrix, It is a one-dimensional vector The dimension; It is the input vector obtained by flattening the initial representation; It is a dimension The bias vector. In this formula, the dimension is... The matrix and dimension are Multiplying the column vectors together yields a vector with dimension . A column vector, which is a column vector with dimension . The bias vectors are added together, and the final result is... The dimension is This is consistent with the definition.
[0037] For example, suppose the original input data is a A single-channel grayscale image, its pixel value matrix Represented as:
[0038] The classic feature extraction subnetwork contains a convolutional layer, using a convolution kernel With a step size of 1 and no padding, its weight is set as follows:
[0039] After convolution and ReLU activation, suppose we get a initial representation matrix To simplify the explanation, an exemplary example is given here. :
[0040] The initial representation matrix Flattening it yields a 9-dimensional one-dimensional vector. Then, this vector is input to an output dimension. A fully connected layer. Assume the weight matrix of this layer... and bias vector They are respectively:
[0041]
[0042] According to the formula The calculation yields unnormalized high-dimensional feature vectors. The final generated unnormalized high-dimensional feature vector for This vector will be passed to the subsequent quantum state encoder for processing.
[0043] In one embodiment of the present invention, step S2 includes the following steps: The high-dimensional feature vector is imported into the quantum state encoder located inside the quantum processing unit; The components of the high-dimensional feature vector are converted into corresponding microwave pulse amplitude parameters by hyperbolic tangent compression through a digital-to-analog converter. By using microwave pulses with microwave pulse amplitude parameters to sequentially drive the quantum bit chain to apply a rotating gate, each component is physically modulated onto the superposition state coefficients of the quantum bits, generating a superposition state of the quantum bits carrying characteristics.
[0044] Specifically, when receiving unnormalized high-dimensional feature vectors Subsequently, this method triggers a quantum state encoder located within a physically isolated quantum processing unit to perform subsequent operations. The quantum processing unit is a physical device operating in a low-temperature and electromagnetically shielded environment, containing several qubits that can be manipulated by external signals, such as superconducting qubits or trapped ions; while the quantum state encoder is a functional module combining hardware and software to realize the conversion of classical data to quantum states, physically consisting of an FPGA, a digital-to-analog converter, and microwave control circuitry.
[0045] The quantum state encoder follows a deterministic amplitude encoding mapping rule. This encoding mapping rule refers to the specific encoding process used in this embodiment: hyperbolic tangent compression + Y-axis rotation gate. The encoding mapping rule maps high-dimensional feature vectors... Each classical numerical component is mapped to the physical state parameters of the qubit.
[0046] High-dimensional feature vectors Each component The signals are input one by one to a digital signal processing circuit, which performs a hyperbolic tangent compression transform on each component. The tangent compression transform, through a preset nonlinear function, transforms components that may fall within any real number range. The values are mapped to a normalized closed interval, thereby generating the corresponding angle parameters. Hyperbolic tangent compression is used to compress arbitrary input feature values. Corresponding rotation angle Constraints are placed within a finite and efficient range of physical operations to prevent angular parameter overflow. This is achieved from the components of the high-dimensional eigenvector. To rotation angle The mapping relationship is defined by the following formula:
[0047] in, This is a preset hyperparameter, called the compression coefficient, used to adjust the slope of the hyperbolic tangent function. As a positive real number, its value is set based on empirical data, typically within the range of 0.1 to 1.0. The reason for setting this range is that if... If the value is less than 0.1, the compression function approximates a linear transformation within the normal characteristic distribution range, and cannot effectively limit the quantum gate rotation angle overflow caused by extreme anomalous eigenvalues; if If the value is greater than 1.0, most normal classical eigenvalues will quickly enter the saturation region of the hyperbolic tangent function, causing the quantum state to lose its ability to distinguish eigenvalue differences, i.e., triggering the gradient vanishing problem; It is an unnormalized high-dimensional feature vector The One component; It is the hyperbolic tangent function, and its output range is... The angle is finally generated through addition, subtraction, and multiplication operations. Restricted to Within this range, it meets the physical requirements for the angle parameters of a revolving door. and All are dimensionless quantities, and their product is The function value is also a dimensionless quantity, therefore The unit is radians.
[0048] These calculated digital angle parameters The data is transmitted to a digital-to-analog converter (DAC). The DAC converts each digitized angle value... This is converted into an analog voltage signal with a specific amplitude and duration. The analog voltage signal is the microwave pulse amplitude parameter, which is used to drive the microwave generator to produce a series of microwave control pulses. The microwave pulse amplitude parameter is also a direct physical quantity controlling the rotation angle of the quantum gate; its amplitude and duration together determine the final rotation angle. .
[0049] These microwave pulses were sequentially applied to a device pre-initialized to its ground state. One The individual qubits of a qubit chain. A qubit chain refers to an ordered set of qubits selected for this encoding task in a quantum processor. The parameters of each microwave pulse are calibrated and can be used in the corresponding... A rotation angle of 0.5 around the Y-axis of the Bloch sphere is achieved on 1 qubit. The operation of the revolving door, that is A rotating gate is a basic single-qubit gate that rotates a quantum state around a specific axis by a specified angle on a Bloch sphere.
[0050] By sequentially applying corresponding rotation gates to all qubits in the qubit chain, the high-dimensional eigenvectors are obtained. Each component is physically modulated onto the superposition state coefficients of the corresponding qubit, ultimately generating a... A superposition state of qubits carrying complete characteristic information The final generated superposition state of qubits carrying characteristics The mathematical form is described as follows:
[0051] This formula indicates that initially in a fully state The bit system, then sequentially through each qubit. On The final state after the revolving door operation; the final state is a The tensor product state of a bulk quantum system, the superposition state coefficients of each subsystem and All depend deterministically on the original feature components The final one It is a quantum state vector.
[0052] For example, following the aforementioned steps, the unnormalized high-dimensional feature vector for The vector is fed into a quantum state encoder within a two-qubit quantum processing unit. The system's preset compression coefficient... The value is 0.5. The initial state of the quantum bit chain is... Calculate the first component. Corresponding rotation angle Next, calculate the second component. Corresponding rotation angle .
[0053] The digital-to-analog converter transforms the digital values 2.3569 and 3.1412 into two corresponding microwave pulse amplitude parameters. The first microwave pulse drives the first qubit to perform [operation / action]. Operation: The second microwave pulse drives the second qubit to perform... Operation. Generating a superposition state of qubits carrying characteristics. for: This final state carries the feature vector. The quantum state of information will be used as input for the next technological step.
[0054] See Figure 2 The horizontal axis represents the original, unnormalized high-dimensional feature components. The vertical axis represents the rotation angle of the mapped microwave pulse. The figure shows three different compression ratios. The mapping curves at (0.1, 0.5, 1.0) show that regardless of the input feature components... Whether the value is extremely positive or extremely small negative, after nonlinear hyperbolic tangent compression, the output rotation angle is strictly limited to the physical lower limit (0) and physical upper limit (0) indicated by two horizontal dotted lines. Between ) . Compression factor The value of determines the slope of the curve near the origin, i.e. the feature discrimination sensitivity. By setting this coefficient reasonably, it is possible to effectively prevent the physical overflow of the quantum gate rotation angle caused by extreme abnormal feature values, while maintaining sufficient gradient discrimination in data-dense regions.
[0055] In one embodiment of the present invention, step S3 includes the following steps: Within the quantum processing unit, initial quantum parameters are directly set via hardware-simulated electrical signals. Inputting the superposition state of qubits into a trainable quantum circuit containing parametric rotation gates and entanglement gates; Driven by microwave pulses, the superposition state of qubits is rotated and entangled according to the initial quantum parameters to generate the final quantum evolution state.
[0056] Specifically, superposition states of qubits carrying characteristics Within the quantum processing unit, the signal is passed to a trainable quantum circuit. A trainable quantum circuit is a variational circuit in quantum computing whose behavior is controlled by a set of trainable classical parameters, i.e., quantum parameters.
[0057] In the superposition state of qubits Before input, the control electronics system within the quantum processing unit sets a set of initial quantum parameters using hardware-simulated electrical signals. In this embodiment, the quantum parameters... Instead of classical numbers, these are analog physical quantities generated by the control hardware, such as the phase or amplitude of microwave signals. These analog electrical signals, such as specific voltages or microwave pulse phase offsets, physically configure the initial states of the parametric quantum gates in a trainable quantum circuit. This process ensures that quantum parameters always exist at the hardware level as continuous physical quantities, rather than being stored digitally in classical memory.
[0058] Superposition state of qubits carrying characteristics The input terminal of a trainable quantum circuit is injected. The structure of a trainable quantum circuit typically consists of alternating layers of single-qubit parametric rotation gates and multi-qubit entangled gates. Parametric rotation gates are typically rotation gates around the three principal axes of a Bloch sphere, for example... , or Its rotation angle This is one component of the quantum parameter; while the entanglement gate is a quantum gate used to generate entanglement between qubits. Common choices include the controlled NOT gate (CNOT) or the controlled Z gate (CZ). Its function is to associate the operation of a single bit with the state of another bit, which is the key to realizing complex quantum algorithms.
[0059] Driven by the control electronics system to generate a microwave pulse sequence modulated by quantum parameters, the quantum bit superposition state Following the order defined by the circuit, a series of unitary transformations are performed sequentially. Specifically, a single-qubit parametric rotation gate rotates the state of a single qubit according to its corresponding quantum parameters, while an entanglement gate establishes quantum correlations between multiple qubits.
[0060] The entire evolutionary process is a deterministic physical process that maps the initial quantum state to a new quantum state. The product of this process is a new quantum state that has undergone deep physical evolution, defined as the final state of quantum evolution. The final quantum state is the final quantum state obtained after a complete unitary transformation of a trainable quantum circuit from a superposition of qubits carrying features. It contains a complex coupling of the original feature information and the quantum circuit parameters. The generation process of the final quantum state is described by the following formula: in, It is the final quantum evolution state of the final output; It is a superposition state of qubits carrying characteristics as input; It is the unitary operator representing the entire trainable quantum circuit, by Composed of layer door operations; Represents the Parameterized rotation door operation of the layer, and its specific form is determined by the subset of quantum parameters of this layer; Represents the Entanglement door operation of the layer, and its structure is fixed; is the parameter vector containing all layer quantum parameters. This formula represents the initial state evolves into the final state after layer unitary transformation. The unitary operator
[0061] The first layer rotation door is Its matrix form is: The matrix form of the NOT gate is:
[0062] The unitary operator of the entire circuit. First, calculate the intermediate state :
[0063] Then, apply the NOT gate to obtain the final state
[0064] of quantum evolution: 。 The vector representation of the finally generated final state of quantum evolution is
[0065] This state will be used in subsequent hardware noise fingerprint modulation and measurement processes. In one embodiment of the present invention, step S4 includes the following steps: The quantum noise real-time monitoring unit is triggered to collect environmental physical data within the quantum processing unit; Continuous measurement of the decoherence time and hardware gate fidelity of idle qubits; Based on the measured decoherence time and gate fidelity index, time-varying noise spectrum parameters reflecting the current physical characteristics of the hardware are calculated and output.
[0066] Specifically, after the final quantum evolution state generated in step S3 stabilizes, the control system triggers the quantum noise real-time monitoring unit to perform hardware state characterization. The quantum noise real-time monitoring unit is physically a dedicated hardware characteristic characterization circuit integrated on the same chip as the main quantum computing core. After startup, it collects environmental physical data within the quantum processing unit through an internal multiplexer analog-to-digital converter.
[0067] Environmental physical data serves as a set of auxiliary measurements used to calibrate noise models or detect anomalies; for example, drastic temperature fluctuations may indicate... Significant changes were observed. These data included readings from a cryogenic thermometer deployed within the chip package, the background magnetic field strength measured by a miniature Hall probe, and the amount of DC bias voltage drift on critical control cables.
[0068] The hardware characterization circuit performs a series of measurements on a set of pre-specified idle qubits that are not used in the main computation task. Idle qubits are those located on the same physical chip as the qubits performing the main computation task, but are deliberately reserved as environmental probes and do not participate in the evolution of the quantum circuit.
[0069] To obtain the decoherence time, the hardware characterization circuit performs a Ramsey interferometry sequence on the idle qubits. This sequence contains the initial... Pulse, variable-length free evolution time And the final Pulse, for this bit Projection measurements are performed using a base. This is achieved through multiple different... Repeat this process and statistically analyze the results to obtain a decaying oscillating signal. This Ramsey interferometry data can be fitted using the following function model:
[0070] in, During the free evolution period When the quantum bit is measured to be in The probability of the state; It is the amplitude of the oscillation; It is the probability offset; It is the detuning between the quantum bit frequency and the driving frequency, and its unit is radians per second (rad / s). This is the initial phase. By fitting the experimental data using the nonlinear least squares method, the exponential decay term can be obtained. Extracting decoherence time Decoherence time Phase loss time, also known as dephase time, is a physical quantity that measures how quickly a qubit loses phase information due to its interaction with the environment. It is one of the key indicators for evaluating the stability of a qubit, and its typical value ranges from [value missing in original text]. to The range of values is based on the fact that it accurately reflects the typical phase-preserving ability of current mainstream superconducting qubits or trapped ion qubits in controlled and confined physical environments, and is lower than... This means that if the hardware noise is too high, the quantum state will rapidly decoherent and fail to reach the predetermined variational evolution depth; higher than This represents the current typical level of laboratory-grade hardware.
[0071] To obtain hardware gate fidelity metrics, the hardware characterization circuit applies a random benchmark protocol to another set of idle qubits. This protocol generates and applies a series of parameters of length [missing information]. A random Clifford gate sequence is generated, and a single Clifford gate that is computed to reverse the entire sequence is appended to the end of the sequence. The probability of the final state returning to the initial state is measured. This process is applied to multiple different sequence lengths. Repeat the process. This randomized benchmark data can be fitted using the following function model:
[0072] in, It was after applying a length of After the Clifford gate sequence, the survival probability of the qubit successfully returning to its initial state; and It is a fitting constant related to state preparation and measurement errors. By fitting experimental data, the attenuation base can be obtained. The hardware gate fidelity index, i.e., the average gate error rate, is calculated in the middle. Hardware gate fidelity is a quantitative measure of how closely a quantum gate operation approximates an ideal unitary transform. It is typically expressed as the average gate error rate. This indicates that a lower value represents more precise gate operation, and its typical value range is... to Between these two ranges, this limit defines the boundary conditions for current quantum hardware systems to perform fault-tolerant quantum computing, and is higher than... The error rate causes the quantum circuit to rapidly collapse into a useless maximally mixed state after a few gate operations, resulting in the system losing its ability to extract and map classical features; the gate sequence length in the formula and error rate All are dimensionless quantities.
[0073] The digital signal processor within the hardware characterization circuit performs fitting calculations on the aforementioned measurement data and calculates the decoherence time based on the attenuation envelope of the Ramsey interferometry. The average gate error rate was calculated based on the survival rate decay curve of random benchmark tests. The two calculation results are combined into a vector, which serves as a time-varying noise spectrum parameter reflecting the current hardware characteristics. Output. This time-varying noise spectrum parameter. The specific definition, Time-varying noise spectrum parameters It includes decoherence time. and average gate error rate The two-dimensional column vector, as a real-time updated vector, provides a quantitative snapshot of the current physical noise level of the quantum processor for subsequent steps. This indicates its characteristics that change over time.
[0074] For example, after the final state of quantum evolution is generated, the real-time quantum noise monitoring unit is activated. The monitoring unit performs Ramsey interferometry measurements on the idle qubits, when the free evolution time is set. At that time, it was measured When set At that time, it was measured By fitting the data from these two points and several other measurement points to... The digital signal processor calculates the decoherence time as a function form. .
[0075] See Figure 3 The solid line represents the measured probability oscillation of the Ramsey interferometry. With free evolution time The changing physical process exhibits cosine oscillations caused by detuning frequencies; the two outer dashed lines represent the exponential decoherence attenuation envelope caused by environmental factors such as hardware thermal noise. The two prominent solid dots in the figure indicate the characteristics of this embodiment. and The measured data points extracted at that time have probability values of 0.65 and 0.21, respectively. By fitting these scattered points of hardware-level measurements to the exponentially decaying envelope function, the decoherence time, a core fingerprint parameter reflecting the current physical state of the quantum chip, can be calculated. .
[0076] Simultaneously, the monitoring unit performs a random benchmark test on another idle bit, when the sequence length... At that time, the survival probability was measured. When the sequence length At that time, it was measured Fit these data points to Functions, where state preparation and measurement constants , Approximately equal to 0.5, the calculated average gate error rate corresponding to the hardware gate fidelity index is approximately 0.5. The two calculation results are combined into a two-dimensional vector, and the current time-varying noise spectrum parameters are output as follows: This parameter will be used in the next step to modulate the final state of the quantum evolution.
[0077] See Figure 4 The x-axis represents the length of the applied Clifford gate sequence. The vertical axis represents the survival probability of a quantum bit successfully reversing back to its initial state. The figure compares three different average gate error rates. The theoretical decay trajectories at (0.001, 0.0035, 0.01) are shown. The intersecting markers in the figure represent the actual measured survival rates of the hardware characterization circuit at sequence lengths of 100 and 300, which are 0.85 and 0.67, respectively. The dashed curves obtained by nonlinearly fitting these measured points correspond to... This describes the gate fidelity index of the quantum hardware currently performing the task. This index, together with the aforementioned decoherence time, constitutes the immutable time-varying noise spectrum parameter.
[0078] In one embodiment of the present invention, step S5 includes the following steps: The additional phase angle is obtained by substituting the current time-varying noise spectrum parameters into a preset nonlinear physical function. Additional phase gates are configured using parameterized additional phase angles; An additional phase gate is applied to the quantum evolution final state, causing it to undergo a physical rotation that fluctuates with noise, thus generating a modulated final state with a hardware noise fingerprint.
[0079] Specifically, in obtaining the time-varying noise spectrum parameters of the S4 output Subsequently, a calculation module in the control system performs the mapping of parameters to physical operations. The calculation module will then use the time-varying noise spectrum parameters... As an input vector, it is substituted into a pre-defined nonlinear physical function. In this context, the design goal of this function is to convert the physical characteristics of the hardware into an angular quantity that can be used for quantum gate operations.
[0080] Nonlinear physical functions are typically composed of polynomial or exponential terms, with coefficients determined based on offline system calibration data to ensure their output is moderately sensitive to variations in noise parameters. These nonlinear physical functions are central to mapping noise characteristics to quantum operations; they amplify fluctuations in noise parameters through their nonlinear properties, enabling distinguishable phase modulation of noise fingerprints at different times, even when hardware performance is relatively stable. An example of a nonlinear physical function used to calculate the additional phase angle is shown below:
[0081] in, It is the decoherence time. These are the average gate error rate and both values are derived from the time-varying noise spectrum parameters. ; These are preset weighting coefficients, obtained through regression analysis of historical data, used to balance the influence of different noise sources on the phase angle and control the overall modulation intensity. These coefficients are assigned specific physical dimensions, such as... The dimension of is time (s); The dimension of is the square of time. ,and and It is a dimensionless quantity.
[0082] This function maps two noise metrics with different physical meanings to a unified angle value. Through dimensional matching of the aforementioned coefficients, the final calculated value is obtained. The unit is radians. Through the calculation of this function, the system obtains a scalar value, namely the additional phase angle. The additional phase angle It is a physical quantity that reflects the current instantaneous noise state of the hardware, with an additional phase angle. The introduction of this means that the evolution of quantum states is no longer determined solely by algorithms and trainable parameters, but is also subject to real-time modulation by the physical hardware environment.
[0083] Calculated additional phase angle It is used as a parameter to configure an additional phase gate. An additional phase gate is a parameter used to configure the quantum state amplitude, i.e. and The probability is not affected, but the quantum gate will change its relative phase. Therefore, additional phase information can be embedded without destroying the main structure of the encoded information.
[0084] Meanwhile, the additional phase gate is a single-qubit quantum gate, typically rotating around the Z-axis. The gate, whose function is to adjust the phase of the quantum state at the equator of the Bloch sphere, is dynamically inserted into the end of the trainable quantum circuit by the control system, causing it to act on the final state of quantum evolution. Apply a qubit to all qubits, that is, apply a qubit to each qubit. operate.
[0085] When a microwave pulse driving an additional phase gate is applied to a qubit, the quantum evolution final state... The complex phase of each component will undergo a change caused by... The rotation is determined. This rotation amount is related to the hardware noise level at the current moment, thus irreversibly encoding the physical fingerprint information of the hardware into the phase of the quantum state. The final quantum state generated after this operation is the modulated final state with the hardware noise fingerprint. The generation process of the modulation final state with hardware noise fingerprint can be described by the following formula:
[0086] in, It is the final modulation state of the final output; It is the final state of the input quantum evolution; It is in the The rotation angle around the Z-axis applied to each qubit is: Phase gate; Indicates all This operation is applied to every qubit. The unitary operator acts on the quantum state vector, and the result is still a quantum state vector of the same dimension. The modulated final state with hardware noise fingerprint is a key intermediate product of this method. The modulated final state comprehensively characterizes the classical input features, trainable parameters, and the physical noise features unique to current quantum processors.
[0087] For example, following the aforementioned steps, the time-varying noise spectrum parameters are: ,Right now , The coefficients in the preset nonlinear physical function are: s, , To simplify calculations, higher-order terms are ignored. The additional phase angle is then calculated. : Because the phase angle has Periodicity, the phase angle in practical applications is The control system is configured with an additional phase gate to apply a phase gate to each qubit. Operation. The matrix form of this gate is: This gate is simultaneously applied to the final state of quantum evolution. On the two qubits, the total unitary operators are Calculate the modulation final state with hardware noise fingerprint. .
[0088] Applying the total unitary operator to the quantum state, i.e. ,get , , .final
[0089] This final state is the modulated final state with hardware noise fingerprint. Its complex phase contains information determined by the current hardware noise and will be used for the final measurement.
[0090] In one embodiment of the present invention, step S6 includes the following steps: The measurement results are statistically analyzed by performing multiple repeated samplings using hardware circuitry. The statistical measurement results are aggregated and averaged to generate a scalar output of a noisy fingerprint that includes physical hardware noise fingerprint bias.
[0091] Specifically, in step S5, a modulation end with hardware noise fingerprint is generated. state Then, the control system performs an expectation value measurement operation on the quantum state to convert its contained quantum information into a classical scalar value. Expectation value measurement is a standard quantum computing procedure for converting quantum state information into classically readable numerical values, and its result reflects the average value obtained after performing the same measurement on the physical system multiple times.
[0092] The measurement process first requires defining a physical observation, which is determined by a pre-defined Pauli operator. This indicates that the pre-defined Pauli operator is a Hermitian operator representing a specific physical observation, and its selection determines what information is extracted from the quantum state. Besides... Alternatively, you can choose or Alternatively, linear combinations can be used to probe information about quantum states under different bases.
[0093] In a preferred embodiment, the Pauli operator is configured as the Pauli X operator for measuring the first qubit, i.e. ,in For the first qubit, since the phase gate in the previous steps used a rotation along the Z-axis, in order to break the commutation relation and successfully extract the phase information, the measurement operation must be performed on a non-commutation basis, such as the superposition basis of the computation basis. The following method performs a non-commutative projection measurement on the modulation final state with hardware noise fingerprint, which can convert the complex phase shift in the modulation final state into a cosine or sine oscillation of the physical measurement probability, thus making the output result decisively dependent on the hardware noise parameters; while the unit operator Acting on the rest One qubit. The measurement operation physically corresponds to the modulation of the final state with a hardware noise fingerprint. Projection to Pauli Operator On the intrinsic basis.
[0094] For the Pauli X operator, this means that in the computation basis The first qubit is then measured. Due to the probabilistic nature of quantum measurement, a single measurement is insufficient to obtain the desired value. Therefore, the hardware measurement circuitry within the quantum processing unit is triggered to perform multiple repeated samplings. The number of samplings in these repeated samplings is... The value is typically between 1024 and 16384. The reason for setting this sampling value is that if it is lower than 1024, the large shot noise of quantum projection measurement will lead to an excessively high variance in the expected value estimation, which will seriously affect the accuracy of the backpropagation direction of gradient descent. If it is higher than 16384, the marginal accuracy improvement will show a diminishing effect, and it will increase the sampling time cost of quantum hardware by a factor of two, reducing the overall training efficiency of the system.
[0095] In each sampling, the entire process from initial state preparation to generating the modulated final state with hardware noise fingerprint is executed once, and finally, the first qubit is measured. This process is repeated. The measurement circuit then calculates in real time that the first qubit is measured as being in the ground state. Number of times and the measured as excited state Number of times After completing all After the sampling, a classic coprocessor calculates the number of times the data is collected. and The expected value of the Pauli operator is calculated by aggregation. Pauli operator The theoretical definition of the expected value is shown in the following formula:
[0096] The above formula is a quantum state The inner product under the action of this operator is a complex or real number, the value of which depends on... The phase information is encoded and modulated by noise. The calculation method for estimating this expected value in a real physical system is shown in the following formula:
[0097] in, It is an estimate of the expected value. and The first qubit is measured to obtain the eigenvalue +1 (corresponding to the eigenstate). ) and eigenvalue -1 (corresponding to eigenstate) The number of times; It is the total number of measurements, i.e. This formula provides a statistical estimate that approximates the theoretical value by weighting the results of multiple measurements. In the formula, the expected value, frequency, and probability are all dimensionless quantities.
[0098] The result of this calculation is the scalar output of the noisy fingerprint, which includes the physical hardware noise fingerprint bias. This output will serve as the final response of the entire quantum embedded inference module to the original input data. The scalar output of the noisy fingerprint is the final result of the forward propagation of the entire hybrid quantum-classical network. Its value depends not only on the input characteristics of the classical network and the parameters of the trainable quantum circuit, but also on the instantaneous physical noise characteristics of the quantum hardware performing the calculation, which are embedded due to the modulation of the additional phase gate, thus making it unreplicable.
[0099] For example, following the steps above, the input modulated final state of the hardware-noise fingerprint is the state of a two-dimensional quantum system. For ease of explanation, it is assumed that the state vector is supplemented with phase by hardware noise. rad. Its vector can be represented as Satisfy normalization , The preset measurement operation is to perform the Pauli X operator on the first qubit. Measurement.
[0100] In quantum mechanics, measurement The theoretical expected value formula is as follows: ,in and The first qubit is respectively in and The probability amplitude at that time. Substituting the data in this example: It can be seen that, due to the use of non-commutative X-basis measurements, the phase introduced by hardware noise... It was retained in the expected value.
[0101] In physical execution, The two eigenstates measured are (Eigenvalue + 1) and (Eigenvalue - 1), whose theoretical measurement probabilities are as follows: 5
[0102] Hardware circuit execution Repeated sampling. The expected number of measurement statistics is: ; By aggregating these statistical results, a scalar output of the noisy fingerprint is calculated:
[0103] This scalar value This is the final output of this forward propagation, which will be used for subsequent loss calculations and model parameter updates.
[0104] In one embodiment of the present invention, step S7 includes the following steps: Trigger the quantum state rollback controller to undo the current gate operation of the circuit and restore it to its encoded initial state; The offset angle is dynamically generated using quantum random numbers. Positive and negative offsets are applied to the current quantum parameters respectively. Two forward evolutions are performed and the difference in expected values is measured to obtain the unbiased gradient signal. The unbiased gradient signal is converted into an analog voltage adjustment value for the microwave generator, and the microwave pulse is physically adjusted to update the physical state of the quantum parameters in a closed loop.
[0105] Specifically, once the loss function value of a training batch is calculated, a quantum state rollback controller deployed within the quantum processing unit's control system is triggered in response to this loss value. The quantum state rollback controller is a hardware logic unit capable of storing the gate sequence of the quantum circuit and generating control signals for the corresponding inverse operation sequence, thereby achieving the reversibility of unitary evolution. The quantum state rollback controller first executes a reverse unitary evolution operation. This operation undoes the current circuit's evolution process by applying the Hermitian conjugates (i.e., inverse operations) of all gate operations in the trainable quantum circuit in reverse order. This physical process changes the state of the quantum system from the final state of quantum evolution. Or its subsequent state, rigorously restored to the superposition state of qubits carrying characteristics generated at the end of step S2 without undergoing trainable circuit evolution. .
[0106] For each quantum parameter in a trainable quantum circuit The controller then begins to perform a corrected parameter offset operation to estimate the gradient. A quantum random number generator deployed inside the quantum processing unit is activated, which utilizes quantum phenomena, such as single photons passing through a beam splitter or the superposition of qubits, to generate truly random numbers with unpredictability, adding randomness to the parameter offset to avoid getting trapped in local optima during the optimization process.
[0107] The generator dynamically generates tiny offset angles. The offset angle It is a small angle value output by a quantum random number generator and scaled, and its value range is usually set within a certain range. rad, if the offset angle is less than If the value is less than rad, the difference between the expected value obtained after performing positive and negative offsets is small, and thus it is overwhelmed by the measurement shot noise of the quantum hardware system itself, resulting in invalid extracted gradients; if it is greater than rad, the difference is small. If the rad interval is too large, the finite difference approximation calculated based on the parameter offset rule will have too large a cutoff error with the theoretical true gradient, making it impossible for the network training to converge. Therefore, this interval takes into account both numerical stability and gradient estimation accuracy to ensure both numerical stability and gradient estimation accuracy.
[0108] The controller will The physical state of each quantum parameter is temporarily set to its current value plus a modulo 1. A proportional positive offset; the physical state of a quantum parameter refers to the parameter value represented by a continuous physical quantity, such as voltage, current, or phase, and its update process is the direct modulation of that physical quantity.
[0109] Under this offset parameter configuration, the recovered superposition state of the qubit carrying the feature Using this as input, perform a complete forward evolution, and measure and record the expected value through all steps S3 to S6. Afterwards, the controller performed a rollback operation again, restoring to the previous state. and the first The physical state of each parameter is set to its current value minus a factor equal to... A proportional negative offset is used to perform another complete forward evolution and measure and record the expected value. .
[0110] The difference obtained by subtracting these two expected values is then processed by a... After normalizing the relevant factors, a parameter is formed. unbiased gradient signal The unbiased gradient signal is an estimate that is statistically equal to the true gradient, calculated according to the parameter offset rule. Calculating the unbiased gradient signal... The parameter offset rule is described by the following formula:
[0111] in, It measures the expected value For the quantum parameters An unbiased estimate of the partial derivative; and These are parameters Positive and negative offsets were applied. The expected value obtained after measurement; denominator It is for using any small angle The normalization factor during offsetting. The expected value and... All are dimensionless quantities, gradient signals It is also a dimensionless quantity.
[0112] Unbiased gradient signal This is converted into an analog voltage adjustment value for the microwave generator. The analog voltage adjustment value is the physical manifestation of the gradient signal; it is a continuously changing voltage value that acts directly on the physical hardware, rather than a number calculated in a classical computer.
[0113] The simulated voltage adjustment is multiplied by a physically implemented learning rate, such as a fixed voltage attenuation factor, and then directly applied to the control parameters. In the DC bias circuit, the voltage attenuation coefficient acts as a bridge between the dimensionless mathematical gradient space and the microwave control hardware space with a practical range. Selecting an appropriate voltage attenuation coefficient, such as around 0.05V, corresponds to a physical phase fine-tuning of approximately 0.01 rad to 0.1 rad at the microwave generator's phase control terminal. This falls within the smooth adjustment range of the hardware digital-to-analog converter, ensuring both the convergence speed of the physical gradient and preventing equipment malfunctions such as hardware phase-locked loop loss due to single-update voltage overshoot. This allows for physical adjustment of the microwave pulse phase, completing a closed-loop update of the quantum parameter's physical state. The update process of the quantum parameter's physical state is described by the following formula:
[0114] in, Is Time control The simulated voltage values of each parameter; It is the voltage value at the current moment; This is a coefficient representing the physical learning rate, such as an amplifier gain or attenuator ratio. The formula indicates that the new control voltage is the old voltage minus an analog voltage adjustment proportional to the gradient signal. The unit of voltage is V. The unit is V.
[0115] For example, suppose that after one training iteration, it is calculated that the parameters in the trainable quantum circuit need to be updated. The control system triggers the quantum state rollback controller. The controller first applies... and The inverse operation, from quantum state to Restore to .
[0116] Start calculation The gradient is used to generate a random number using a quantum random number generator, which is then processed to obtain the offset angle. rad. The controller will control The physical voltage is temporarily adjusted to the corresponding Angle in rad. The system performs one complete forward propagation and measurement, assuming the desired value is obtained. .
[0117] The controller rolls back to the previous state and adjusts the control voltage accordingly. From the angle of rad, perform a second forward propagation and measurement to obtain the expected value. Based on these two measurements, the unbiased gradient signal is calculated. : Assuming physical learning rate It is set to a fixed voltage conversion factor, the value of which is... Therefore, the analog voltage adjustment is: If the current control voltage for The updated voltage will then be The control circuit hardware adjusts the voltage to 2.496 V, thus completing the control... This is a closed-loop update of the physical state. This process will affect all other quantum parameters. Repeat in sequence.
[0118] In one embodiment of the present invention, step S8 includes the following steps: The overall network error is calculated by combining the current training labels with the scalar output of the noisy fingerprint; By triggering the quantum processing unit to perform the offset operation of the input encoding parameters and measuring the expected value difference, the derivative of the expected value with respect to each component of the original input feature vector is calculated, and a backpropagation gradient signal carrying an additional phase angle transformation factor is generated. The backpropagation gradient signal is sent to the classical feature extraction subnet, and its network weights are updated using standard backpropagation.
[0119] Specifically, after generating the scalar output with noisy fingerprints in step S6, this scalar output and the ground truth labels corresponding to the current training samples are input together into a loss calculation module located on a classical computing server. The loss calculation module calculates the difference between the current model's prediction and the ground truth labels based on a preset loss function, such as the cross-entropy loss function or the mean squared error loss function, obtaining a scalar form of the overall network error. The overall network error is used to evaluate the prediction accuracy of the current model on a single or batch of training samples.
[0120] To backpropagate this error to the classical feature extraction subnet, the next step is to calculate the measurement expectation against the unnormalized high-dimensional feature vector. Each component The derivative of . This derivative is also calculated using quantum processing units via the parameter offset rule on a real physical platform. The system extracts the feature components from the classical feature extraction subnet. To achieve this, by controlling the quantum state encoder, positive and negative angular offsets are applied to the amplitude of microwave pulses generated by specific component mappings, for example... The quantum processing unit performs a complete forward evolution and measurement under both positive and negative offsets, obtaining two expectation values with hardware noise imprints. By using the difference between these two expectation values and dividing by a relevant scaling factor, the eigenvector components of the measurement expectation value can be extracted at the physical level. partial derivatives .
[0121] This gradient This is the core part of the returned gradient signal, and its value reflects the expected value. For characteristic components Sensitivity to minute changes. This derivative value includes the effect of the additional phase angle. The introduced transform factor is because the difference of the expected value is directly extracted after measuring the positive and negative parameter offsets of the modulated final state containing the additional phase gate. The system is for each characteristic component. Each gradient value is calculated, and these gradient values together form a high-dimensional feature vector that is initially unnormalized. The backpropagation gradient signal is a vector with the same dimension as the output feature of the classical subnet, guiding how the weights of the classical subnet should be adjusted to minimize the overall network error.
[0122] The backpropagation gradient signal, carrying hardware noise fingerprint information, is sent to the classical feature extraction subnet. Standard backpropagation algorithms, such as stochastic gradient descent or Adam, use this gradient signal to update all network weights of the classical feature extraction subnet, including the parameters of convolutional kernels and the weight matrices of fully connected layers. (The last sentence appears to be incomplete and possibly refers to a different algorithm or subnet.) The update rules, in the form of a chain rule, are as follows:
[0123] in, and These are the weight values before and after the update, respectively. It is the learning rate of the classic part; It is the overall network error. Scalar output for noisy fingerprints The derivative is determined by the form of the loss function; That is, the gradient signal returned from the quantum module. Each component. This is the derivative calculated using standard backpropagation within the classical subnet. The summation operation in the formula reflects the chain rule of multivariable calculus, i.e., classical weights. It will affect high-dimensional feature vectors The multiple components require the gradients of all branches to be accumulated. The entire formula shows that the update of classical weights is directly modulated by the gradient signal carrying the noisy fingerprint information from the quantum module. In the formula, both the gradient and the weights are dimensionless or tensors with corresponding units, and the learning rate is a dimensionless coefficient.
[0124] In this way, the weights of the classical subnet are continuously adjusted during training to adapt to and compensate for systematic biases introduced by the current noise conditions of the specific quantum hardware, establishing a parametric symbiotic relationship between the classical network parameters and the physical noise characteristics of the quantum hardware. This parametric symbiotic relationship means that the weights of the classical subnet are no longer merely learned from the distribution of the input data; their values also encode information used to counteract or utilize the noise patterns of the specific quantum hardware. This relationship deeply binds the classical network to the specific quantum hardware.
[0125] For example, suppose the scalar output of the noisy fingerprint obtained in S6 is The true labels of the current training samples are Using the mean squared error loss function, the overall network error... The derivative of the loss function with respect to the scalar output is... .
[0126] The expected value of the measurement is calculated using the parameter offset rule on the unnormalized high-dimensional eigenvector. The derivatives of the two components. Assume the calculated gradient... This gradient is the backpropagation gradient signal.
[0127] The gradient signal is sent to the classical feature extraction subnet to update the weights of the fully connected layer in example S1. For example, among which ,so , Assuming a classic learning rate Then the weight The update volume is: .
[0128] Updated weights Similarly, all other weights in the classical subnet will be updated based on this gradient signal carrying the quantum hardware noise fingerprint, thereby gradually establishing a symbiotic relationship with the parameters of the hardware.
[0129] See appendix Figure 5 The present invention also proposes a quantum-safe training system to prevent the copying of deep learning models, comprising the following modules: The classic feature extraction module acquires the original input data, calls the classic feature extraction subnet to perform dimensionality reduction on the original input data, and generates unnormalized high-dimensional feature vectors. The quantum state encoding module acquires a high-dimensional feature vector, triggers the quantum state encoder in the quantum processing unit to perform amplitude encoding on the high-dimensional feature vector, and generates a superposition state of qubits carrying the feature. The quantum circuit evolution module calls a trainable quantum circuit to receive the superposition state of qubits and implement physical evolution within it to generate the final quantum evolution state; The real-time noise monitoring module activates the quantum noise real-time monitoring unit, measures the state of idle bits in the quantum processing unit, and calculates and outputs the current time-varying noise spectrum parameters. The hardware fingerprint modulation module configures an additional phase gate according to the current time-varying noise spectrum parameters, and uses the additional phase gate to modulate the quantum evolution final state to generate a modulated final state with hardware noise fingerprint; The expected value measurement module performs an expected value measurement operation on the modulation final state with hardware noise fingerprint, and generates a scalar output with noisy fingerprint; The quantum parameter update module, in response to the preset training loss calculation, triggers the quantum state rollback controller to perform a corrected parameter offset operation, and updates the physical state of the quantum parameters in the trainable quantum circuit in a closed loop. The classic subnet update module uses the scalar output error with noisy fingerprints to generate a backpropagation gradient signal to correct the weights of the classic feature extraction subnet.
[0130] Each of the modules can be implemented in whole or in part through software, hardware, or a combination thereof. It supports hardware embedded in or independent of the processor in the computer device, and also supports software stored in the memory of the computer device, so that the processor can call and execute the operations corresponding to each of the above modules.
[0131] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A quantum-safe training method to prevent the copying of deep learning models, characterized in that, Includes the following steps: S1. Obtain the original input data, call the classic feature extraction subnet to perform dimensionality reduction on the original input data, and generate an unnormalized high-dimensional feature vector. S2. Obtain the high-dimensional feature vector, trigger the quantum state encoder in the quantum processing unit to perform amplitude encoding on the high-dimensional feature vector, and generate a superposition state of qubits carrying the feature; S3. Call the trainable quantum circuit to receive the superposition state of qubits and implement physical evolution within it to generate the final state of quantum evolution; S4. Activate the quantum noise real-time monitoring unit, measure the state of idle bits in the quantum processing unit, and calculate and output the current time-varying noise spectrum parameters; S5. Configure an additional phase gate according to the current time-varying noise spectrum parameters, and use the additional phase gate to modulate the quantum evolution final state to generate a modulated final state with hardware noise fingerprint; S6. Perform the expected value measurement operation on the modulation final state with hardware noise fingerprint to generate a scalar output with noise fingerprint; S7. In response to the preset training loss calculation, the quantum state rollback controller is triggered to perform the corrected parameter offset operation, and the physical state of the quantum parameters in the trainable quantum circuit is updated in a closed loop. S8. Utilize the scalar output error of the noisy fingerprint to generate a backpropagation gradient signal to correct the weights of the classical feature extraction subnet.
2. The quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, Generating unnormalized high-dimensional feature vectors includes the following steps: The original input data is fed into the convolutional and normalization layers of the classic feature extraction subnetwork to extract the initial representation; The initial representation is input into a fully connected layer for hierarchical abstraction, and the hierarchical cascaded features are calculated and obtained. Aggregate cascaded features to generate high-dimensional feature vectors that represent the core features of the input data but are not normalized.
3. The quantum-safe training method for preventing deep learning model replication according to claim 1, characterized in that, Generating a superposition state of qubits carrying features includes the following steps: The high-dimensional feature vector is imported into the quantum state encoder located inside the quantum processing unit; The components of the high-dimensional feature vector are converted into corresponding microwave pulse amplitude parameters by hyperbolic tangent compression through a digital-to-analog converter. By using microwave pulses with microwave pulse amplitude parameters to sequentially drive the quantum bit chain to apply a rotating gate, each component is physically modulated onto the superposition state coefficients of the quantum bits, generating a superposition state of the quantum bits carrying characteristics.
4. The quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, Generating the final state of quantum evolution includes the following steps: Within the quantum processing unit, initial quantum parameters are directly set via hardware-simulated electrical signals. Inputting the superposition state of qubits into a trainable quantum circuit containing parametric rotation gates and entanglement gates; Driven by microwave pulses, the superposition state of qubits is rotated and entangled according to the initial quantum parameters to generate the final quantum evolution state.
5. A quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, The calculation and output of the current time-varying noise spectrum parameters includes the following steps: The quantum noise real-time monitoring unit is triggered to collect environmental physical data within the quantum processing unit; Continuous measurement of the decoherence time and hardware gate fidelity of idle qubits; Based on the measured decoherence time and gate fidelity index, time-varying noise spectrum parameters reflecting the current physical characteristics of the hardware are calculated and output.
6. A quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, Generating the modulation final state with hardware noise fingerprint includes the following steps: The additional phase angle is obtained by substituting the current time-varying noise spectrum parameters into a preset nonlinear physical function. Additional phase gates are configured using parameterized additional phase angles; An additional phase gate is applied to the quantum evolution final state, causing it to undergo a physical rotation that fluctuates with noise, thus generating a modulated final state with a hardware noise fingerprint.
7. A quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, Generating a scalar output with a noisy fingerprint involves the following steps: Projection measurement is performed on the modulated final state with hardware noise fingerprint using a preset Pauli operator. The measurement results are statistically analyzed by performing multiple repeated samplings using hardware circuitry. The statistical measurement results are aggregated and averaged to generate a scalar output of a noisy fingerprint that includes physical hardware noise fingerprint bias.
8. A quantum-safe training method for preventing deep learning model copying according to claim 1, characterized in that, The physical state of quantum parameters in a trainable quantum circuit is updated in a closed loop, including the following steps: Trigger the quantum state rollback controller to undo the current gate operation of the circuit and restore it to its encoded initial state; The offset angle is dynamically generated using quantum random numbers. Positive and negative offsets are applied to the current quantum parameters respectively. Two forward evolutions are performed and the difference in expected values is measured to obtain the unbiased gradient signal. The unbiased gradient signal is converted into an analog voltage adjustment value for the microwave generator, and the microwave pulse is physically adjusted to update the physical state of the quantum parameters in a closed loop.
9. A quantum-safe training method for preventing deep learning model copying according to claim 8, characterized in that, Performing two forward evolutions and measuring the difference in expected values to obtain an unbiased gradient signal includes the following steps: Activate the quantum random number generator inside the quantum processing unit to obtain a scaled small angle value as the offset angle; The voltage state of the quantum parameter is added to and subtracted by an offset proportional to the offset angle for forward evolution, and the positive and negative expected values are recorded respectively. The unbiased gradient signal is calculated by dividing the difference between the positive and negative expected values by a specific normalization factor.
10. A quantum-safe training method for preventing the replication of deep learning models according to claim 1, characterized in that, Generating a backpropagation gradient signal to correct the weights of the classical feature extraction subnet includes the following steps: The overall network error is calculated by combining the current training labels with the scalar output of the noisy fingerprint; By triggering the quantum processing unit to perform the offset operation of the input encoding parameters and measuring the expected value difference, the derivative of the expected value with respect to each component of the original input feature vector is calculated, and a backpropagation gradient signal carrying an additional phase angle transformation factor is generated. The backpropagation gradient signal is sent to the classical feature extraction subnet, and its network weights are updated using standard backpropagation.