Abstract
Private distributed learning studies the problem of how multiple distributed entities collaboratively train a shared deep network with their private data unrevealed. With the security provided by the protocols of blind quantum computation, the cooperation between quantum physics and machine learning may lead to unparalleled prospect for solving private distributed learning tasks. In this paper, we introduce a quantum protocol for distributed learning that is able to utilize the computational power of the remote quantum servers while keeping the private data safe. For concreteness, we first introduce a protocol for private single-party delegated training of variational quantum classifiers based on blind quantum computing and then extend this protocol to multiparty private distributed learning incorporated with differential privacy. We carry out extensive numerical simulations with different real-life datasets and encoding strategies to benchmark the effectiveness of our protocol. We find that our protocol is robust to experimental imperfections and is secure under the gradient attack after the incorporation of differential privacy. Our results show the potential for handling computationally expensive distributed learning tasks with privacy guarantees, thus providing a valuable guide for exploring quantum advantages from the security perspective in the field of machine learning with real-life applications.
References
J. Biamonte, P. Wittek, N. Pancotti, P. Rebentrost, N. Wiebe, and S. Lloyd, Nature 549, 195 (2017), arXiv: 1611.09347.
V. Dunjko, and H. J. Briegel, Rep. Prog. Phys. 81, 074001 (2018).
S. Das Sarma, D. L. Deng, and L. M. Duan, Phys. Today 72, 48 (2019), arXiv: 1903.03516.
S. J. Russell, and P. Norvig, Artificial Intelligence: A Modern Approach (Pearson, Hoboken, 2020).
Y. LeCun, Y. Bengio, and G. Hinton, Nature 521, 436 (2015).
M. I. Jordan, and T. M. Mitchell, Science 349, 255 (2015).
D. Silver, A. Huang, C. J. Maddison, A. Guez, L. Sifre, G. van den Driessche, J. Schrittwieser, I. Antonoglou, V. Panneershelvam, M. Lanctot, S. Dieleman, D. Grewe, J. Nham, N. Kalchbrenner, I. Sutskever, T. Lillicrap, M. Leach, K. Kavukcuoglu, T. Graepel, and D. Hassabis, Nature 529, 484 (2016).
D. Silver, J. Schrittwieser, K. Simonyan, I. Antonoglou, A. Huang, A. Guez, T. Hubert, L. Baker, M. Lai, A. Bolton, Y. Chen, T. Lillicrap, F. Hui, L. Sifre, G. van den Driessche, T. Graepel, and D. Hassabis, Nature 550, 354 (2017).
A. W. Senior, R. Evans, J. Jumper, J. Kirkpatrick, L. Sifre, T. Green, C. Qin, A. Žídek, A. W. R. Nelson, A. Bridgland, H. Penedones, S. Petersen, K. Simonyan, S. Crossan, P. Kohli, D. T. Jones, D. Silver, K. Kavukcuoglu, and D. Hassabis, Nature 577, 706 (2020).
G. Carleo, I. Cirac, K. Cranmer, L. Daudet, M. Schuld, N. Tishby, L. Vogt-Maranto, and L. Zdeborová, Rev. Mod. Phys. 91, 045002 (2019), arXiv: 1903.10563.
F. Arute, K. Arya, R. Babbush, D. Bacon, J. C. Bardin, R. Barends, R. Biswas, S. Boixo, F. G. S. L. Brandao, D. A. Buell, B. Burkett, Y. Chen, Z. Chen, B. Chiaro, R. Collins, W. Courtney, A. Dunsworth, E. Farhi, B. Foxen, A. Fowler, C. Gidney, M. Giustina, R. Graff, K. Guerin, S. Habegger, M. P. Harrigan, M. J. Hartmann, A. Ho, M. Hoffmann, T. Huang, T. S. Humble, S. V. Isakov, E. Jeffrey, Z. Jiang, D. Kafri, K. Kechedzhi, J. Kelly, P. V. Klimov, S. Knysh, A. Korotkov, F. Kostritsa, D. Landhuis, M. Lindmark, E. Lucero, D. Lyakh, S. Mandrà, J. R. Mc-Clean, M. McEwen, A. Megrant, X. Mi, K. Michielsen, M. Mohseni, J. Mutus, O. Naaman, M. Neeley, C. Neill, M. Y. Niu, E. Ostby, A. Petukhov, J. C. Platt, C. Quintana, E. G. Rieffel, P. Roushan, N. C. Rubin, D. Sank, K. J. Satzinger, V. Smelyanskiy, K. J. Sung, M. D. Trevithick, A. Vainsencher, B. Villalonga, T. White, Z. J. Yao, P. Yeh, A. Zalcman, H. Neven, and J. M. Martinis, Nature 574, 505 (2019), arXiv: 1910.11333.
H.-S. Zhong, H. Wang, Y.-H. Deng, M.-C. Chen, L.-C. Peng, Y.-H. Luo, J. Qin, D. Wu, X. Ding, Y. Hu, P. Hu, X.-Y. Yang, W.-J. Zhang, H. Li, Y. Li, X. Jiang, L. Gan, G. Yang, L. You, Z. Wang, L. Li, N. Liu, C.-Y. Lu, and J.-W. Pan, Science 370, 1460 (2020).
M. A. Nielsen, and I. L. Chuang, Quantum Computation and Quantum Information (Cambridge University Press, Cambridge, 2010).
A. W. Harrow, A. Hassidim, and S. Lloyd, Phys. Rev. Lett. 103, 150502 (2009), arXiv: 0811.3171.
S. Lloyd, M. Mohseni, and P. Rebentrost, Nat. Phys. 10, 631 (2014), arXiv: 1307.0401.
V. Havlíček, A. D. Córcoles, K. Temme, A. W. Harrow, A. Kandala, J. M. Chow, and J. M. Gambetta, Nature 567, 209 (2019), arXiv: 1804.11326.
M. Schuld, and N. Killoran, Phys. Rev. Lett. 122, 040504 (2019).
X. Gao, Z. Y. Zhang, and L. M. Duan, Sci. Adv. 4, eaat9004 (2018).
S. Lloyd, and C. Weedbrook, Phys. Rev. Lett. 121, 040502 (2018), arXiv: 1804.09139.
L. Hu, S. H. Wu, W. Cai, Y. Ma, X. Mu, Y. Xu, H. Wang, Y. Song, D. L. Deng, C. L. Zou, and L. Sun, Sci. Adv. 5, eaav2761 (2019), arXiv: 1808.02893.
P. Rebentrost, M. Mohseni, and S. Lloyd, Phys. Rev. Lett. 113, 130503 (2014), arXiv: 1307.0471.
S. Barz, E. Kashefi, A. Broadbent, J. F. Fitzsimons, A. Zeilinger, and P. Walther, Science 335, 303 (2012), arXiv: 1110.1381.
A. Broadbent, J. Fitzsimons, and E. Kashefi, in Universal blind quantum computation: Proceedings of the 2009 50th Annual IEEE Symposium on Foundations of Computer Science (IEEE, Atlanta, 2009), pp. 517–526.
A. M. Childs, arXiv: quant-ph/0111046.
J. F. Fitzsimons, and E. Kashefi, Phys. Rev. A 96, 012303 (2017).
G. Zhang, Y. Liu, J. J. Raftery, and A. A. Houck, npj Quantum Inf. 3, 1 (2017), arXiv: 1603.01224.
V. Giovannetti, L. Maccone, T. Morimae, and T. G. Rudolph, Phys. Rev. Lett. 111, 230501 (2013), arXiv: 1306.2724.
T. Morimae, and K. Fujii, Phys. Rev. Lett. 111, 020502 (2013), arXiv: 1302.3786.
Y.-B. Sheng, and L. Zhou, Sci. Rep. 5, 7815 (2015).
F. Zerka, S. Barakat, S. Walsh, M. Bogowicz, R. T. H. Leijenaar, A. Jochems, B. Miraglio, D. Townend, and P. Lambin, JCO Clin. Cancer Inf. 2017, 184 (2020).
A. Hosny, C. Parmar, J. Quackenbush, L. H. Schwartz, and H. J. W. L. Aerts, Nat. Rev. Cancer 18, 500 (2018).
M. X. Chen, B. N. Lee, G. Bansal, Y. Cao, S. Zhang, J. Lu, J. Tsay, Y. Wang, A. M. Dai, Z. Chen, T. Sohn, and Y. Wu, in Gmail smart compose: Real-time assisted writing: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, KDD’ 19 (Association for Computing Machinery, New York, 2019), pp. 2287–2295.
J. Konečný, H. B. McMahan, F. X. Yu, P. Richtárik, A. T. Suresh, and D. Bacon, arXiv: 1610.05492.
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, Communication-Efficient Learning of Deep Networks from Decentralized Data: Artificial Intelligence and Statistics (PMLR, Ft. Lauderdale, 2017), pp. 1273–1282.
C. Dwork, Theory and Applications of Models of Computation, Lecture Notes in Computer Science, edited by M. Agrawal, D. Du, Z. Duan, and A. Li (Springer, Berlin, Heidelberg, 2008), pp. 1–19.
C. Dwork, and A. Roth, FNT Theor. Comput. Sci. 9, 211 (2014).
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, in Deep learning with differential privacy: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (Association for Computing Machinery, New York, 2016), pp. 308–318.
Y. Huang, Z. Song, K. Li, and S. Arora, in InstaHide: Instance-hiding schemes for private distributed learning: Proceedings of the International Conference on Machine Learning (PMLR, 2020), pp. 4507–4518.
R. Bassily, A. Smith, and A. Thakurta, in Private empirical risk minimization: Efficient algorithms and tight error bounds: 2014 IEEE 55th Annual Symposium on Foundations of Computer Science (IEEE, Philadelphia, 2014), pp. 464–473.
A. Beimel, H. Brenner, S. P. Kasiviswanathan, and K. Nissim, Mach. Learn. 94, 401 (2014).
C. Gentry, in Fully homomorphic encryption using ideal lattices: Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, STOC’ 09 (Association for Computing Machinery, New York, 2009), pp. 169–178.
Y. B. Sheng, and L. Zhou, Sci. Bull. 62, 1025 (2017).
M. Cerezo, A. Arrasmith, R. Babbush, S. C. Benjamin, S. Endo, K. Fujii, J. R. McClean, K. Mitarai, X. Yuan, L. Cincio, and P. J. Coles, arXiv: 2012.09265.
Y. Liu, S. Arunachalam, and K. Temme, arXiv: 2010.02174.
S. Lu, L. M. Duan, and D. L. Deng, Phys. Rev. Res. 2, 033212 (2020), arXiv: 2001.00030.
K. Mitarai, M. Negoro, M. Kitagawa, and K. Fujii, Phys. Rev. A 98, 032309 (2018), arXiv: 1803.00745.
J. Li, X. Yang, X. Peng, and C. P. Sun, Phys. Rev. Lett. 118, 150503 (2017), arXiv: 1608.00677.
M. Schuld, V. Bergholm, C. Gogolin, J. Izaac, and N. Killoran, Phys. Rev. A 99, 032331 (2019), arXiv: 1811.11184.
L. Zhu, Z. Liu, and S. Han, Federated Learning: Privacy and Incentive (Springer, Cham, 2020), pp. 17–31.
Y. LeCun, C. Cortes, and C. Burges, Mnist Handwritten Digit Database (1998).
W. H. Wolberg, N. Street, and O. L. Mangasarian, UCI Machine Learning Repository: Breast Cancer Wisconsin (Diagnostic) Data Set (1992).
A. Dusko, A. Delgado, A. Saraiva, and B. Koiller, npj Quantum Inf. 4, 1 (2018), arXiv: 1712.03195.
I. Cong, S. Choi, and M. D. Lukin, Nat. Phys. 15, 1273 (2019), arXiv: 1810.03787.
D. P. Kingma, and J. Ba, arXiv: 1412.6980.
Y. Du, M.-H. Hsieh, T. Liu, D. Tao, and N. Liu, arXiv: 2003.09416.
H. L. Huang, Q. Zhao, X. Ma, C. Liu, Z. E. Su, X. L. Wang, L. Li, N. L. Liu, B. C. Sanders, C. Y. Lu, and J. W. Pan, Phys. Rev. Lett. 119, 050503 (2017), arXiv: 1707.00400.
A. Mantri, T. F. Demarie, N. C. Menicucci, and J. F. Fitzsimons, Phys. Rev. X 7, 031004 (2017), arXiv: 1608.04633.
Author information
Authors and Affiliations
Corresponding author
Additional information
This work was supported by the start-up fund from Tsinghua University (Grant No. 53330300320), the National Natural Science Foundation of China (Grant No. 12075128), and the Shanghai Qi Zhi Institute. We thank Haoyu Guo, Wenjie Jiang, Zhide Lu, and Peixin Shen for helpful discussions.
Supporting Information
The supporting information is available online at phys.scichina.com and link.springer.com. The supporting materials are published as submitted, without typesetting or editing. The responsibility for scientific accuracy and content remains entirely with the authors.
Supporting Information
Rights and permissions
About this article
Cite this article
Li, W., Lu, S. & Deng, DL. Quantum federated learning through blind quantum computing. Sci. China Phys. Mech. Astron. 64, 100312 (2021). https://doi.org/10.1007/s11433-021-1753-3
Received:
Accepted:
Published:
DOI: https://doi.org/10.1007/s11433-021-1753-3