Quantum machine learning promises revolutionary advances, but securing these systems while preserving their ability to learn remains a major challenge. Chenyi Zhang, Tao Shang, and Chao Guo from Beihang University, along with Ruohan He, present DyLoC, a new architecture that addresses this important trade-off between privacy and trainability. The team overcomes the limitations of existing techniques by separating these two properties into separate layers, ensuring both robust learning and strong security against attacks. DyLoC adopts innovative techniques such as new encoding methods and dynamic scrambling to effectively protect sensitive information and prevent data reconstruction. Experiments demonstrate that this approach not only preserves the learning ability of quantum machine learning models and achieves performance comparable to existing systems, but also dramatically increases security, significantly increasing resistance to attacks and blocking attempts to reverse engineer the underlying data.
Securing privacy in variational quantum circuits
This research addresses critical security vulnerabilities in variational quantum circuits (VQCs). This vulnerability allows an algebraic privacy attack to reconstruct the input data used for training, potentially exposing sensitive information. Scientists have developed a new architecture, DyLoC, that mitigates these attacks without significantly impacting VQC’s learning ability. Key achievements include the development of truncated Chebyshev graph encoding (TCGE) to create complex, entangled quantum states that impede information extraction, and the development of dynamic local scrambling (DLS) to introduce randomness to further blur the relationship between input data and circuit output. The technique involves analyzing how algebraic attacks exploit the structure of quantum circuits and then designing components that disrupt these exploitable relationships.
Through theoretical analysis and numerical simulations, researchers demonstrated that DyLoC effectively blocks both snapshot recovery and snapshot reversal attacks while maintaining training performance comparable to unprotected VQC. Experiments confirm that DyLoC maintains baseline level convergence, achieves a final loss of 0.186, increases gradient reconstruction error by 13 orders of magnitude, and significantly improves privacy protection.
Privacy and trainability with orthogonal decoupling
Researchers designed a novel dual-layer defense architecture, DyLoC, to address the inherent tradeoff between privacy and trainability in variational quantum circuits. This system overcomes the limitations of existing defenses by decoupling the privacy mechanism from the core variational ansatz, enabling both robust privacy and efficient training. This work pioneered the orthogonal decoupling strategy and established a theoretical framework that separates privacy protection from the expressibility of Ansatz itself. This approach exploits high-complexity input-output mappings to break the traditional privacy-trainability trade-off under polynomial dynamic Lie algebra constraints.
TCGE utilizes a Chebyshev tower strategy combined with graph state initialization, which clearly violates the separability assumption required by known inversion algorithms while maintaining constant circuit depth to preserve signal dispersion. This encoding method builds a shallow and tangled graph state structure and effectively protects the model from algebraic attacks without introducing volume law entanglements. The output interface incorporates dynamic local scrambling (DLS), which utilizes time-varying local random unitary transforms to obfuscate gradients and prevent state recovery. Experiments demonstrate that DyLoC maintains baseline level convergence with a final loss of 0.
186, indicating minimal impact on model performance. Importantly, the system outperforms the baseline by increasing the gradient reconstruction error by 13 orders of magnitude, indicating significantly improved privacy protection. The snapshot inversion attack is effectively blocked when the reconstruction mean square error exceeds 2.0, confirming the effectiveness of the double-layer defense.
Separated privacy and trainability with quantum machine learning
Scientists have developed DyLoC, a new dual-layer architecture that effectively addresses the important trade-off between privacy and trainability in variational quantum circuits. This work points the way to secure and trainable quantum machine learning by decoupling privacy mechanisms from the core trainable Ansatz. Experimental results reveal that DyLoC maintains baseline level convergence and achieves a final loss of 0.186, which is comparable to the unprotected model. The core of the innovation lies in an orthogonal separation strategy that separates privacy from trainability through dedicated input and output interfaces.
The input interface utilizes Truncated Chebyshev Graph Encoding (TCGE), a technique that violates the separability assumption required by existing inversion algorithms while maintaining constant circuit depth. The output interface employs dynamic local scrambling (DLS). It applies a time-varying local random unitary transformation to obfuscate the linear relationship between the gradient and the quantum state. Measurements confirm that snapshot inversion attacks are effectively blocked when the reconstruction mean square error is greater than 2.0, demonstrating robust protection against strong privacy violations. Furthermore, the locality and shallow depth of DyLoC preserves the variance of the gradient signal, ensuring that the model is trainable despite additional privacy measures.
Separated privacy and trainability with DyLoC
This work addresses a fundamental challenge in variational quantum circuits: the tradeoff between privacy and trainability. Researchers have developed DyLoC, a new dual-layer architecture that effectively separates privacy mechanisms from the core algebraic structure of quantum circuits. This separation allows for robust privacy protection without sacrificing the ability to train models effectively. The research team demonstrated that DyLoC maintains convergence levels comparable to standard unprotected circuits, achieving a final loss of 0.186.
At the same time, this architecture significantly enhances privacy by increasing the gradient reconstruction error by 13 orders of magnitude and successfully blocking snapshot inversion attacks when the reconstruction error exceeds a threshold of 2.0. These results confirm that DyLoC establishes a verifiable pathway for both trainable and secure quantum machine learning. The authors acknowledge that future research will focus on developing hardware-efficient implementations tailored to specific topological constraints and extending the framework to other quantum neural network architectures.
👉 More information
🗞 DyLoC: A two-layer architecture for secure and trainable quantum machine learning under polynomial DLA constraints.
🧠ArXiv: https://arxiv.org/abs/2512.00699
