Does the Readout Bypass Leak the Input? A Feature-Visibility Audit of Hybrid Quantum-Classical Models

📅 2026-09-29
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the security vulnerability of raw input leakage through readout-side residual shortcuts in hybrid quantum-classical models. Challenging the prevailing misconception that quantum processing inherently guarantees privacy protection, this work proposes a feature visibility-based privacy auditing framework. Through iterative gradient matching, PSNR metric analysis, membership inference attacks, and multi-architecture comparative experiments, it systematically evaluates the exposure risk of original data coordinates via shortcut connections. The results demonstrate that residual shortcuts enable near-perfect reconstruction of raw inputs, whereas purely quantum heads recover only partially encoded coordinates. To our knowledge, this is the first work to quantitatively reveal the privacy bottleneck inherent in hybrid architectures, providing critical insights for their secure design.
📝 Abstract
Readout-side residual hybrids concatenate raw inputs with measured quantum features. Under single-example gradient sharing, a biased first linear layer admits standard analytic recovery of its input, so the bypass exposes raw coordinates without requiring inversion of the quantum circuit. We audit this mechanism using two tabular datasets, four architectures, and metrics conditioned on feature visibility. Iterative gradient matching gives median full-record PSNR of 73-96 dB for residual and input-only heads. Quantum-only heads score 8-11 dB on the full record but 54-96 dB on the six input coordinates they actually encode. These are reconstruction results for the tested six-input, six-observable circuits, not a general statement about quantum encodings. A loss-threshold membership attack remains near chance. The contribution is a visibility-conditioned privacy audit: omitted coordinates must not be credited as protection supplied by quantum processing, and near-exact PSNR differences must not be interpreted as meaningful privacy rankings. Our findings concern individual gradients and do not establish leakage under aggregation or multiple local training steps.
Problem

Research questions and friction points this paper is trying to address.

hybrid quantum-classical models
gradient leakage
readout bypass
privacy audit
feature visibility
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hybrid Quantum-Classical Models
Gradient Leakage
Privacy Audit
Feature Visibility
Readout Bypass
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
G
Guilin Zhang
Workday AI Research
K
Kai Zhao
Workday AI Research
Xiquan Cui
Xiquan Cui
California Institute of Technology
imagingopticsmicro technologynano technologybiomedical
H
Henry Heng
Workday AI Research
X
Xu Chu
Workday AI Research
A
Aletta Johanna Blanken
Workday AI Research