What is it about?

Hybrid quantum–classical machine learning combines conventional neural networks with trainable quantum circuits. In this work, we study whether these models remain useful when two important real-world requirements are imposed at the same time: protection against adversarial attacks and differential privacy.We use a transfer-learning framework with a frozen Vision Transformer as the feature extractor and compare two trainable classifier heads: a parameterized quantum circuit and a parameter-matched classical model. We evaluate them under standard training, differential privacy, adversarial training, and combinations of these settings.Our experiments examine the trade-offs between clean accuracy, adversarial robustness, and privacy across multiple image-classification datasets.

Featured Image

Why is it important?

Quantum machine learning is often evaluated mainly on predictive performance, but real deployments may also require guarantees about privacy and resilience to maliciously perturbed inputs. This work asks whether potential advantages of quantum models persist once these constraints are introduced. The results show that the answer depends strongly on the training regime: quantum classifier heads can provide competitive robustness in some standard and privacy-preserving settings, while classical models remain stronger in the most demanding adversarially trained settings. The study therefore provides a more realistic picture of where hybrid quantum models may be useful, while also identifying situations in which classical approaches remain preferable.

Perspectives

A key motivation for this work was to move beyond asking whether a quantum model can match a classical model on clean test accuracy. If quantum machine learning is eventually used in sensitive applications, the models will also need to operate under privacy constraints and withstand adversarial perturbations. Our results show that these requirements substantially change the comparison between quantum and classical models.

Flavjo Xhelollari
Fordham University

Read the Original

This page is a summary of: Robustness of Hybrid Classical-Quantum Transfer Learning Models Under Differential Privacy Constraints, ACM Transactions on Quantum Computing, September 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3844142.
You can read the full text:

Read

Contributors

The following have contributed to this page