Fault Attacks on ML-based Quantum Control and Error Correction
This paper presents the first analysis of physical fault injection attacks on machine learning models used in quantum computing, demonstrating that voltage glitches can significantly degrade the accuracy of readout error correction and quantum error decoding by inducing structured bit-level corruption rather than random noise.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a world where computers don't just crunch numbers but dance with the very fabric of reality, using tiny particles called qubits to solve problems that would take normal computers a million years. This is the realm of quantum computing. But these quantum dancers are incredibly shy and sensitive; a single sneeze from the environment can ruin their performance. To keep them on track, we use "error correction," a safety net that constantly checks if a qubit has stumbled and fixes it. In the past, this safety net was a rigid set of rules, but recently, scientists started teaching these safety nets to learn on their own using Machine Learning (ML). Think of it as upgrading a rigid rulebook into a smart, intuitive coach that can spot subtle mistakes and fix them instantly.
However, there's a catch. Just like a human coach can be tricked by a well-timed distraction, these smart ML coaches can be confused. This paper explores a very specific, physical way to confuse them: by giving the computer's brain a tiny, momentary "glitch" in its power supply. It's like flicking a light switch on and off so fast that the computer's brain stumbles for a split second. The researchers wanted to know: if someone could sneak up and flick the power switch on the machine controlling the quantum computer, could they make the smart coach give the wrong advice? And if they did, would the quantum computer just get a little noisy, or would it completely lose its way?
The researchers, Anthony Etim and Jakub Szefer, decided to test this theory on two different types of "smart coaches" used in quantum systems. The first was a model called HERQULES, which acts like a translator, trying to figure out what a group of five quantum particles are saying when they are all talking over each other. The second was a "Deep Q" decoder, a more complex coach that acts like a detective, looking at a map of clues (called syndromes) to decide how to fix errors in a large quantum puzzle.
To test them, the team set up a lab experiment using a device called a ChipWhisperer Husky. This device is like a precise surgeon's scalpel for electricity; it can inject a tiny, perfectly timed voltage glitch into the power line of the computer running the ML models. They didn't just throw random glitches; they synchronized the glitches to hit the computer at the exact moment it was processing specific parts of its "brain" (the different layers of the neural network).
The results were startling. They found that these smart coaches are surprisingly fragile. When they glitched the early parts of the HERQULES translator, it made mistakes much more often than when they glitched the later parts. In fact, for the Deep Q decoder, a single, well-placed glitch could drop its accuracy from a perfect 100% down to as low as 21.57%. But the scary part wasn't just the number of mistakes; it was the kind of mistakes.
Usually, when you mess with a computer, you expect random noise—like static on a radio. But here, the glitches caused "structured corruption." It was as if the glitch didn't just confuse the coach; it brainwashed it. The Deep Q decoder, which is supposed to look at different clues and choose different fixes, started ignoring the clues entirely. Instead, it would pick the exact same fix every single time, no matter what the problem was. In one experiment, the decoder collapsed into choosing "Action 0" for almost every single input, effectively giving up on its job.
The researchers also simulated what happens if the computer's brain encounters "non-finite" numbers (like infinity or "Not a Number") due to a glitch. They found that injecting just five of these weird numbers into the first layer of the Deep Q decoder was enough to make the whole system collapse into that single, wrong action. This suggests that the failure isn't just random noise; it's a specific vulnerability where a tiny error in the early stages of processing can cascade into a total system failure.
The paper concludes that while these ML models are great at making quantum computers work, they are also a new kind of weak spot. If an attacker with physical access to the controller can flick the power switch at the right millisecond, they could silently sabotage the quantum computer's ability to correct its own errors. The authors suggest that we need to treat these ML models as critical security components, perhaps by adding simple checks to catch these glitches or by having the computer double-check its own work, just to make sure it hasn't been tricked into a trance.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.