Robustness of Hybrid Classical-Quantum Transfer Learning Models Under Differential Privacy Constraints
We propose a hybrid classical-quantum transfer learning framework that combines a frozen pre-trained Vision Transformer (ViT) backbone with a trainable classifier head that can be instantiated either as a Parametrized Quantum Circuit (PQC) or a parameter-matched classical head, and we study the joint impact of adversarial training and Differential Privacy (DP) in this setting. In our framework, formal privacy guarantees are provided by DP-SGD (a classical DP mechanism) applied to the trainable head, while the quantum component serves as an alternative low-parameter classifier head. Experimental results reveal that the calibrated noise introduced by DP can mitigate the effects of adversarial attacks, albeit with the expected reduction in clean accuracy. Furthermore, our mixed-data adversarial training, which combines adversarial examples generated from both DP-trained (private) and non-DP-trained (non-private) data streams, yields an effective balance between model performance, private-subset privacy guarantees, and robustness against adversarial attacks. The symmetric comparison conducted on CIFAR-10 and STL-10 shows that the PQC head improves robust accuracy in the standard and DP-only regimes, but with a consistent clean-accuracy cost. Once adversarial training is introduced, the parameter-matched classical head becomes stronger on PGD-10 and AutoAttack, and the mixed classical-head configuration achieves the highest robust accuracy on both datasets. We also include simulated hardware-noise sensitivity analysis and a limited fixed-circuit IBM Quantum feasibility check, reported as complementary diagnostics alongside the main privacy–robustness evaluation. These findings highlight the promise of transfer learning pipelines that integrate DP and robustness objectives, and clarify the regime-dependent conditions under which a quantum head can be competitive with classical alternatives under the same DP constraints.
Authors
- Ying Mao (ORCID: https://orcid.org/0000-0002-4484-4892)
- Samuel Yen-Chi Chen (ORCID: https://orcid.org/0000-0003-0114-4826)
- Juntao Chen (ORCID: https://orcid.org/0000-0001-7726-4926)
- Flavjo Xhelollari
Institutions
- Fordham University (US)
- Wells Fargo (United States) (US)
Publication Details
- Journal
- ACM Transactions on Quantum Computing
- Published
- 2026-09-24
- DOI
- https://doi.org/10.1145/3844142
- Primary Topic
- Quantum Computing Algorithms and Architecture
- Type
- article
- Field-Weighted Citation Impact
- 0.00