🤖 AI Summary
This study addresses the security vulnerability of raw input leakage through readout-side residual shortcuts in hybrid quantum-classical models. Challenging the prevailing misconception that quantum processing inherently guarantees privacy protection, this work proposes a feature visibility-based privacy auditing framework. Through iterative gradient matching, PSNR metric analysis, membership inference attacks, and multi-architecture comparative experiments, it systematically evaluates the exposure risk of original data coordinates via shortcut connections. The results demonstrate that residual shortcuts enable near-perfect reconstruction of raw inputs, whereas purely quantum heads recover only partially encoded coordinates. To our knowledge, this is the first work to quantitatively reveal the privacy bottleneck inherent in hybrid architectures, providing critical insights for their secure design.
📝 Abstract
Readout-side residual hybrids concatenate raw inputs with measured quantum features. Under single-example gradient sharing, a biased first linear layer admits standard analytic recovery of its input, so the bypass exposes raw coordinates without requiring inversion of the quantum circuit. We audit this mechanism using two tabular datasets, four architectures, and metrics conditioned on feature visibility. Iterative gradient matching gives median full-record PSNR of 73-96 dB for residual and input-only heads. Quantum-only heads score 8-11 dB on the full record but 54-96 dB on the six input coordinates they actually encode. These are reconstruction results for the tested six-input, six-observable circuits, not a general statement about quantum encodings. A loss-threshold membership attack remains near chance. The contribution is a visibility-conditioned privacy audit: omitted coordinates must not be credited as protection supplied by quantum processing, and near-exact PSNR differences must not be interpreted as meaningful privacy rankings. Our findings concern individual gradients and do not establish leakage under aggregation or multiple local training steps.