ABSTRACT Quantum neural networks (QNNs) are advancing rapidly, but their security issues must not be overlooked. Backdoor attacks, as a stealthy and highly threatening attack method, have caused significant impacts on classical neural networks. Moreover, backdoor attacks have recently been proven to pose a significant threat to quantum neural networks as well. Currently, all existing methods in quantum machine learning backdoor research are designed for classical data samples. These methods all involve poisoning classical data samples first and then quantizing them, with no existing approaches that directly target quantum state data for poisoning. This paper presents a novel backdoor attack method against quantum neural networks by utilizing the quantum state—universal adversarial perturbations (QS‐UAP). This method, for the first time, constructs a backdoor trigger specifically for quantum‐state data based on quantum generative models. Moreover, this method enhances the quality of the backdoor trigger by integrating knowledge distillation with frequency‐domain constraints. The proposed method embeds a backdoor into the target model by poisoning quantum data samples. Experimental results demonstrate that with a 10% poisoning rate, the attack success rates exceed 97% across three structurally distinct QNN architectures.
Zhao et al. (Sun,) studied this question.