Robustness of Hybrid Classical-Quantum Transfer Learning Models Under Differential Privacy Constraints

We propose a hybrid classical-quantum transfer learning framework that combines a frozen pre-trained Vision Transformer (ViT) backbone with a trainable classifier head that can be instantiated either as a Parametrized Quantum Circuit (PQC) or a parameter-matched classical head, and we study the joint impact of adversarial training and Differential Privacy (DP) in this setting. In our framework, formal privacy guarantees are provided by DP-SGD (a classical DP mechanism) applied to the trainable head, while the quantum component serves as an alternative low-parameter classifier head. Experimental results reveal that the calibrated noise introduced by DP can mitigate the effects of adversarial attacks, albeit with the expected reduction in clean accuracy. Furthermore, our mixed-data adversarial training, which combines adversarial examples generated from both DP-trained (private) and non-DP-trained (non-private) data streams, yields an effective balance between model performance, private-subset privacy guarantees, and robustness against adversarial attacks. The symmetric comparison conducted on CIFAR-10 and STL-10 shows that the PQC head improves robust accuracy in the standard and DP-only regimes, but with a consistent clean-accuracy cost. Once adversarial training is introduced, the parameter-matched classical head becomes stronger on PGD-10 and AutoAttack, and the mixed classical-head configuration achieves the highest robust accuracy on both datasets. We also include simulated hardware-noise sensitivity analysis and a limited fixed-circuit IBM Quantum feasibility check, reported as complementary diagnostics alongside the main privacy–robustness evaluation. These findings highlight the promise of transfer learning pipelines that integrate DP and robustness objectives, and clarify the regime-dependent conditions under which a quantum head can be competitive with classical alternatives under the same DP constraints.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Quantum Computing
Published
2026-09-24
DOI
https://doi.org/10.1145/3844142
Primary Topic
Quantum Computing Algorithms and Architecture
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Robustness of Hybrid Classical-Quantum Transfer Learning Models Under Differential Privacy Constraints

Ying Mao, Samuel Yen-Chi Chen, Juntao Chen, Flavjo Xhelollari
ACM Transactions on Quantum Computing
Quantum Computing Algorithms and Architecture
article

Robustness of Hybrid Classical-Quantum Transfer Learning Models Under Differential Privacy Constraints

Ying Mao, Samuel Yen-Chi Chen, Juntao Chen, Flavjo Xhelollari
article en

Abstract

We propose a hybrid classical-quantum transfer learning framework that combines a frozen pre-trained Vision Transformer (ViT) backbone with a trainable classifier head that can be instantiated either as a Parametrized Quantum Circuit (PQC) or a parameter-matched classical head, and we study the joint impact of adversarial training and Differential Privacy (DP) in this setting. In our framework, formal privacy guarantees are provided by DP-SGD (a classical DP mechanism) applied to the trainable head, while the quantum component serves as an alternative low-parameter classifier head. Experimental results reveal that the calibrated noise introduced by DP can mitigate the effects of adversarial attacks, albeit with the expected reduction in clean accuracy. Furthermore, our mixed-data adversarial training, which combines adversarial examples generated from both DP-trained (private) and non-DP-trained (non-private) data streams, yields an effective balance between model performance, private-subset privacy guarantees, and robustness against adversarial attacks. The symmetric comparison conducted on CIFAR-10 and STL-10 shows that the PQC head improves robust accuracy in the standard and DP-only regimes, but with a consistent clean-accuracy cost. Once adversarial training is introduced, the parameter-matched classical head becomes stronger on PGD-10 and AutoAttack, and the mixed classical-head configuration achieves the highest robust accuracy on both datasets. We also include simulated hardware-noise sensitivity analysis and a limited fixed-circuit IBM Quantum feasibility check, reported as complementary diagnostics alongside the main privacy–robustness evaluation. These findings highlight the promise of transfer learning pipelines that integrate DP and robustness objectives, and clarify the regime-dependent conditions under which a quantum head can be competitive with classical alternatives under the same DP constraints.

ACM Transactions on Quantum Computing
Fordham University (US), Wells Fargo (United States) (US)
Openalex Percentile: Top 9%
Quantum Computing Algorithms and Architecture
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.