Quantum Machine Learning Security via Robust PCA and Private Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current machine learning algorithms, especially in quantum computing, lack security measures to protect against adversarial attacks that can manipulate training data and compromise model integrity, leading to vulnerabilities in classification and clustering processes.

Innovation Solution

The implementation of robust quantum principal component analysis, quantum bagging and boosting, and private quantum k-means clustering techniques that utilize quantum superposition and entangled states to enhance security and privacy, making classifiers more resilient to adversarial interference and data manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If quantum machine learning algorithms are implemented without security measures, then computational speed and performance are improved, but security against adversarial attacks deteriorates

Engineering Contradiction:
Improvecomputational speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the training data into multiple subsets and processes them through separate quantum computational paths. By dividing the data processing into distinct segments that are later combined, the system achieves both computational efficiency through quantum parallelism and security through distributed processing that prevents single-point adversarial compromise

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces quantum error correction codes and decoherence-resistant quantum states as intermediary layers between the quantum computational core and the external environment. These intermediaries protect the quantum machine learning system from adversarial attacks while maintaining computational speedup through quantum mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If quantum error correction is applied to protect against noise, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvenoise toleranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter regime of quantum error correction by using error correction codes tailored specifically for quantum machine learning workloads rather than generic quantum error correction. This involves adjusting the code distance, block size, and correction threshold parameters to achieve optimal noise tolerance with reduced overhead complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies quantum error correction selectively to only the most critical quantum states and computational steps in the machine learning algorithm, rather than uniformly protecting all quantum operations. This partial application reduces the overall complexity burden while maintaining sufficient reliability for the core learning tasks

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If robust quantum PCA is used to resist adversarial attacks, then security is improved, but computational overhead increases

Engineering Contradiction:
Improveadversarial resistanceVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary quantum principal component analysis on the training data to identify and extract the dominant feature subspaces before the main classification task. By pre-processing the data to isolate the most significant components, the system reduces the dimensionality and complexity of subsequent adversarial-resistant processing while maintaining security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10990677B2Adversarial quantum machine learning
Publication Date: 2021.04.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10990677B2 patent drawing
  • US10990677B2 patent drawing
  • US10990677B2 patent drawing

AI summary

In this disclosure, a number of ways that quantum information can be used to help make quantum classifiers more secure or private are disclosed. In particular embodiments, a form of robust principal component analysis is disclosed that can tolerate noise intentionally introduced to a quantum training set. Under some circumstances, this algorithm can provide an exponential speedup relative to other methods. Also disclosed is an example quantum approach for bagging and boosting that can use quantum superposition over the classifiers or splits of the training set to aggregate over many more models than would be possible classically. Further, example forms of k-means clustering are disclosed that can be used to prevent even a powerful adversary from even learning whether a participant even contributed data to the clustering algorithm.