← Back to feed
2026-07-13infra

Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks

Junrui Zhang, Zemin Chen, Lusi Li, Mohammad Ghasemigol, Daniel Takabi, Rui Ning

PDF preview for Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks
Read on arXiv →

Key claim

Q-DIBA enables effective dynamic backdoor attacks in QNNs.

In plain English

Quantum Neural Networks (QNNs) face security risks, particularly from backdoor attacks, which are not well understood. Current quantum backdoor methods often use fixed triggers, making them vulnerable to detection. This paper introduces Q-DIBA, a dynamic backdoor attack that adapts to inputs, improving stealth and effectiveness. Builders should consider the implications of such attacks on the security of QNN applications.

Novelty
8.0/10

Introduces a novel dynamic backdoor attack framework for quantum neural networks.

Reliability
7.5/10

Demonstrates effectiveness across multiple architectures with solid experimental results.

Deep reliability assessment

The methodology supports the claim that Q-DIBA can effectively perform input-aware dynamic backdoor attacks on QNNs, but the resilience against all possible defenses might be overclaimed as only a few defenses were tested.

Reproducibility

No open source code or dataset URL is mentioned in the paper.

Key figure

Figure 5 illustrates the visual inspection of Q-DIBA triggers on MNIST, showing clean inputs, generated trigger patterns, and trigger-injected inputs.

Benchmark results

MNISTattack success rate: 97.93vs HarmQ-2.00%
F-MNISTattack success rate: 96.78vs HarmQ-2.46%
Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks — Frontier Papers