Barycentric and pairwise quantum Renyi leakages are proposed as two measures of information leakage for privacy and security analysis in quantum computing and communication systems. These quantities both require minimal assumptions on the eavesdropper, i.e., they do not make any assumptions on the eavesdropper's attack strategy or the statistical prior on the secret or private classical data encoded in the quantum system. They also satisfy important properties of positivity, independence, post-processing inequality, and unitary invariance. The barycentric quantum Renyi leakage can be computed by solving a semi-definite program and the pairwise quantum Renyi leakage possesses an explicit formula. The barycentric and pairwise quantum Renyi leakages form upper bounds on the maximal quantum leakage, the sandwiched quantum $\alpha$-mutual information, the accessible information, and the Holevo's information. Furthermore, differentially-private quantum channels are shown to bound these measures of information leakage. Global and local depolarizing channels, that are common models of noise in quantum computing and communication, restrict private or secure information leakage. Finally, a privacy-utility trade-off formula in quantum machine learning using variational circuits is developed. The privacy guarantees can only be strengthened, i.e., information leakage can only be reduced, if the performance degradation grows larger and vice versa.
翻译:本文提出了重心和成对量子Rényi泄漏作为隐私与安全分析中的两种信息泄漏度量,适用于量子计算与通信系统。这两种度量对窃听者仅需最小假设条件,即不对窃听者的攻击策略或量子系统中编码的秘密/私有经典数据的统计先验做出任何假设。它们同时满足正定性、独立性、后处理不等式及幺正不变性等重要性质。其中,重心量子Rényi泄漏可通过求解半定规划计算,而成对量子Rényi泄漏具有显式表达式。重心与成对量子Rényi泄漏构成了最大量子泄漏、夹层量子α-互信息、可访问信息及Holevo信息的上界。进一步研究表明,差分隐私量子信道可以约束这些信息泄漏度量。作为量子计算与通信中常见噪声模型,全局和局部去极化信道能够限制私有或安全信息的泄漏。最后,本文建立了基于变分电路的量子机器学习中的隐私-效用权衡公式:系统性能退化越严重,隐私保护强度越高(即信息泄漏越低),反之亦然。