Quantum Privacy Aggregation of Teacher Ensembles (QPATE) for Privacy-preserving Quantum Machine Learning

William Watkins,Heehwan Wang,Sangyoon Bae,Huan-Hsin Tseng,Jiook Cha,Samuel Yen-Chi Chen,Shinjae Yoo
2024-01-15
Abstract:The utility of machine learning has rapidly expanded in the last two decades and presents an ethical challenge. Papernot et. al. developed a technique, known as Private Aggregation of Teacher Ensembles (PATE) to enable federated learning in which multiple teacher models are trained on disjoint datasets. This study is the first to apply PATE to an ensemble of quantum neural networks (QNN) to pave a new way of ensuring privacy in quantum machine learning (QML) models.
Quantum Physics,Cryptography and Security,Machine Learning
What problem does this paper attempt to address?
This paper discusses the application of Quantum Privacy Aggregation of Teacher Ensembles (QPATE) in Quantum Machine Learning (QML) to address the problem of protecting data privacy in machine learning. Traditional machine learning may leak user privacy, while Differential Privacy (DP) provides a framework for measuring privacy loss. Private Aggregation of Teacher Ensembles (PATE) is a technique to ensure DP, by training multiple teacher models and aggregating their predictions without noise to generate labels, and then using these labels to train a student model, which does not have access to the original data or teacher model parameters, thus achieving privacy protection. The paper first applies PATE to the integration of Quantum Neural Networks (QNN), proposing Quantum PATE (QPATE). In the study, the authors use Variational Quantum Circuits (VQC) to construct a hybrid quantum-classical framework, where both the teacher and student models include VQC. The teacher models are trained on non-overlapping datasets and then a noise-added argmax voting system is used to generate labels for the public data. These labels are used to train the student model, ensuring high accuracy while satisfying privacy constraints. Experiments show that in the binary classification task of MNIST handwritten digits, QPATE exhibits 28.84% higher accuracy than classical PATE at ε values as low as 0.01, demonstrating the advantages of QPATE in privacy protection and performance. Future work will be expanded to more complex image classification tasks, such as CIFAR10 and ImageNet21k.