{"id":"https://openalex.org/W4402351418","doi":"https://doi.org/10.1109/ijcnn60899.2024.10651540","title":"QuantumLeak: Stealing Quantum Neural Networks from Cloud-based NISQ Machines","display_name":"QuantumLeak: Stealing Quantum Neural Networks from Cloud-based NISQ Machines","publication_year":2024,"publication_date":"2024-06-30","ids":{"openalex":"https://openalex.org/W4402351418","doi":"https://doi.org/10.1109/ijcnn60899.2024.10651540"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn60899.2024.10651540","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn60899.2024.10651540","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5024264082","display_name":"Zhenxiao Fu","orcid":"https://orcid.org/0000-0003-0459-2157"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Zhenxiao Fu","raw_affiliation_strings":["Indiana University Bloomington"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054067088","display_name":"Min Yang","orcid":"https://orcid.org/0000-0003-3814-2728"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Min Yang","raw_affiliation_strings":["Indiana University Bloomington"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114138108","display_name":"Cheng Chu","orcid":null},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cheng Chu","raw_affiliation_strings":["Indiana University Bloomington"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052076681","display_name":"Yilun Xu","orcid":"https://orcid.org/0000-0002-0204-2103"},"institutions":[{"id":"https://openalex.org/I148283060","display_name":"Lawrence Berkeley National Laboratory","ror":"https://ror.org/02jbv0t02","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I148283060","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yilun Xu","raw_affiliation_strings":["Lawrence Berkeley National Laboratory"],"affiliations":[{"raw_affiliation_string":"Lawrence Berkeley National Laboratory","institution_ids":["https://openalex.org/I148283060"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062008538","display_name":"Gang Huang","orcid":"https://orcid.org/0000-0002-3249-9315"},"institutions":[{"id":"https://openalex.org/I148283060","display_name":"Lawrence Berkeley National Laboratory","ror":"https://ror.org/02jbv0t02","country_code":"US","type":"facility","lineage":["https://openalex.org/I1330989302","https://openalex.org/I148283060","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gang Huang","raw_affiliation_strings":["Lawrence Berkeley National Laboratory"],"affiliations":[{"raw_affiliation_string":"Lawrence Berkeley National Laboratory","institution_ids":["https://openalex.org/I148283060"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5111004515","display_name":"Fan Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fan Chen","raw_affiliation_strings":["Indiana University Bloomington"],"affiliations":[{"raw_affiliation_string":"Indiana University Bloomington","institution_ids":["https://openalex.org/I4210119109"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5024264082"],"corresponding_institution_ids":["https://openalex.org/I4210119109"],"apc_list":null,"apc_paid":null,"fwci":2.7035,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.91129142,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10682","display_name":"Quantum Computing Algorithms and Architecture","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10558","display_name":"Advancements in Semiconductor Devices and Circuit Design","score":0.9945999979972839,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8366996049880981},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.6397542953491211},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4974718391895294},{"id":"https://openalex.org/keywords/quantum-computer","display_name":"Quantum computer","score":0.4317500591278076},{"id":"https://openalex.org/keywords/quantum","display_name":"Quantum","score":0.3891324996948242},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2756909728050232},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2276027500629425}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8366996049880981},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.6397542953491211},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4974718391895294},{"id":"https://openalex.org/C58053490","wikidata":"https://www.wikidata.org/wiki/Q176555","display_name":"Quantum computer","level":3,"score":0.4317500591278076},{"id":"https://openalex.org/C84114770","wikidata":"https://www.wikidata.org/wiki/Q46344","display_name":"Quantum","level":2,"score":0.3891324996948242},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2756909728050232},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2276027500629425},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn60899.2024.10651540","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn60899.2024.10651540","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2024 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":34,"referenced_works":["https://openalex.org/W1587454308","https://openalex.org/W1988147940","https://openalex.org/W2119046658","https://openalex.org/W2135293965","https://openalex.org/W2159544977","https://openalex.org/W2350778671","https://openalex.org/W2603766943","https://openalex.org/W2761090343","https://openalex.org/W2790388700","https://openalex.org/W2808195004","https://openalex.org/W2897634667","https://openalex.org/W2945680873","https://openalex.org/W2970450884","https://openalex.org/W2977471006","https://openalex.org/W2980456669","https://openalex.org/W2990961515","https://openalex.org/W3007318395","https://openalex.org/W3037022125","https://openalex.org/W3045093737","https://openalex.org/W3087961421","https://openalex.org/W3098181014","https://openalex.org/W3101427288","https://openalex.org/W3102786870","https://openalex.org/W3103525348","https://openalex.org/W3103932910","https://openalex.org/W3104660409","https://openalex.org/W3181660950","https://openalex.org/W3190261797","https://openalex.org/W3196799976","https://openalex.org/W3209612530","https://openalex.org/W4214556944","https://openalex.org/W4281730414","https://openalex.org/W4285345508","https://openalex.org/W6774150056"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W4244478748","https://openalex.org/W4223488648","https://openalex.org/W2134969820","https://openalex.org/W2251605416","https://openalex.org/W2560439919","https://openalex.org/W4389340727","https://openalex.org/W3150465815","https://openalex.org/W1997222214"],"abstract_inverted_index":{"Variational":[0],"quantum":[1],"circuits":[2],"(VQCs)":[3],"have":[4],"become":[5],"a":[6,16],"powerful":[7],"tool":[8],"for":[9,52],"implementing":[10],"Quantum":[11,35],"Neural":[12],"Networks":[13],"(QNNs),":[14],"addressing":[15],"wide":[17],"range":[18],"of":[19],"complex":[20],"problems.":[21],"Well-trained":[22],"VQCs":[23],"serve":[24],"as":[25],"valuable":[26],"intellectual":[27],"assets":[28],"hosted":[29],"on":[30],"cloud-based":[31,86],"Noisy":[32],"Intermediate":[33],"Scale":[34],"(NISQ)":[36],"computers,":[37],"making":[38],"them":[39],"susceptible":[40],"to":[41,61,65,90],"malicious":[42],"VQC":[43,99,107],"stealing":[44,94],"attacks.":[45],"However,":[46],"traditional":[47],"model":[48,82,93],"extraction":[49,83],"techniques":[50],"designed":[51],"classical":[53,92],"machine":[54],"learning":[55],"models":[56],"encounter":[57],"challenges":[58],"when":[59],"applied":[60],"NISQ":[62,87],"computers":[63],"due":[64],"significant":[66],"noise":[67],"in":[68],"current":[69],"devices.":[70],"In":[71],"this":[72],"paper,":[73],"we":[74],"introduce":[75],"QuantumLeak,":[76],"an":[77],"effective":[78],"and":[79,106],"accurate":[80],"QNN":[81],"technique":[84],"from":[85],"machines.":[88],"Compared":[89],"existing":[91],"techniques,":[95],"QuantumLeak":[96],"improves":[97],"local":[98],"accuracy":[100],"by":[101],"4.99%~7.35%":[102],"across":[103],"diverse":[104],"datasets":[105],"architectures.":[108]},"counts_by_year":[{"year":2025,"cited_by_count":7}],"updated_date":"2025-12-22T23:10:17.713674","created_date":"2025-10-10T00:00:00"}
